Method, field device system and instruction set for reducing downtimes when updating individually executable software packages
Patent Information
- Application Number
- EP2024710364
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-14
- Filing Date
- 2024-03-06
- Publication Date
- 2026-01-21
AI Technical Summary
Current methods for updating software packages in field devices, such as control valves, in process engineering systems often result in significant downtime, leading to economic inefficiencies and increased risk of failure due to the complexity and frequency of updates, especially with the integration of network-capable devices and advanced communication technologies like APL technology.
A method that involves announcing upcoming software updates, categorizing them based on defined conditions, and determining the optimal time for the update or implementing bridging functions to minimize downtime, utilizing Ethernet APL connections to prioritize and manage updates efficiently across multiple devices and systems.
This approach reduces unnecessary downtime by allowing updates to be performed without shutting down the process engineering system, enabling simultaneous updates of critical functions and extending the time available for non-critical updates, thereby enhancing the operational efficiency and reliability of field devices.
Smart Images

Figure EP2024055893_19092024_PF_FP_ABST
Abstract
Description
[0001] Procedure, field device system and instruction set for reducing downtime when updating individually executable software packages
[0002] The invention relates to a method for reducing downtimes when updating individually executable software packages for controlling and / or monitoring a field device of a process plant, such as a chemical plant, for example a refinery, a power plant, for example a nuclear power plant, a food processing plant, or the like, a field device system, and an instruction set. The field device is designed in particular as a control valve.
[0003] Various data transmission technologies are used in process plants. Many control valves use a combined two-wire connection for signal and power transmission. A 4-20 mA signal is transmitted from a central processing unit, such as a central control room in a process plant, to the control valve via the two-wire connection. For example, a 4 mA control signal can cause the control valve to move to a closed position, whereas a 20 mA signal can cause the control valve to move to a fully open position. Signals in the range between 4 and 20 mA can cause the control valve to assume a predetermined intermediate position between the closed position and the fully open position, which can be proportional to the current signal, for example. A passive field device in the form of a sensor can provide an analog 4-...A 20 mA signal can be transmitted to a central processing unit to report information about a process in the process plant, for example, a part or component of the process plant or a process fluid. For example, a current signal proportional to a specific pressure range can be transmitted from a pressure sensor to a central processing unit. The transmission of information or data using a 4..20 mA signal is limited to very small data volumes.
[0004] The HART protocol, the FOUNDATION Fieldbus protocol, the PROFIBUS protocol, and a number of other digital communication technologies are also commonly used to transmit data in process plants. HART has been part of the fieldbus standard IEC 61158 since 2007. For data transmission according to the HART protocol, a high-frequency oscillation, for example, ± 0.5 mA, is superimposed on an analog signal, such as a 4-20 mA signal. This can represent a digital 1 with a frequency of 1.2 kHz and a digital "0" with a frequency of 2.2 kHz. HART allows the transmission of process and diagnostic information as well as control signals between control valves and a higher-level processing unit, such as a central control room.
[0005] In some process plants, data is transmitted from a central processing unit to control valves using so-called "Power over Ethernet" technology. Power over Ethernet (PoE) is a technology that supplies network-capable devices with power via an 8-wire Ethernet cable. Data transmission using PoE is carried out in accordance with the IEEE standard 8o2.3af (July 2003). Power over Ethernet systems are intended to eliminate the need for power supply cables and to supply network-capable devices with power in hard-to-reach or confined spaces. According to the IEEE standard 8o2.3af, the devices involved can be divided into power sourcing equipment (PSE) and power devices (PD). The supply voltage for the devices is 48 V during operation. The maximum current consumption of the devices is 350 mA, although up to 400 mA is permitted, resulting in a maximum power consumption per device of 14.5 W.Free wires and / or signal-carrying wires of the Ethernet cable can be used to transmit power. PoE enables the rapid transmission of large amounts of data. The power density of PoE technology precludes its use in potentially explosive atmospheres. The use of PoE technology requires a much higher investment than analog 4-20 mA communication. Retrofitting existing process plants with PoE technology also requires enormous investments, which are often uneconomical. A control valve powered via an Ethernet connection (Power over Ethernet) and an associated commissioning procedure are described in DE 10 2006 036 770 Ai.
[0006] One approach to linking data transmission via Ethernet on the one hand and established and widely used communication technologies in process engineering plants on the other is implemented using so-called Advanced Physical Layer (APL) technology, particularly in accordance with the IEEE P802.3cg (2016) standard. In contrast to PoE technology, APL technology is particularly suitable for incorporating network-capable devices in potentially explosive atmospheres (Zone 0 and 1 / Division 1). Zone 0 describes an area in which an explosive gas-air mixture is present permanently or for long periods of time. Zone 1 describes an area in which flammable or conductive dust particles are present, as well as areas in which an explosive gas-air mixture can be present briefly under normal operating conditions. APL technology should also make it possible to design field devices to be intrinsically safe.Using twisted-pair wiring (twisted-pair wiring according to 10BASE-T1L), data transmission rates of 10 Mbps up to 100 Mbps and more can be achieved. Process engineering systems with APL technology can be equipped with a so-called trunk data and power transmission line, from a central processing unit to an APL field switch (APL switch), particularly with a length of up to 1000 m. The so-called trunk lines should be designed to transmit power of up to 54 W. Several field devices can be connected to the APL field switch using so-called spur data and power transmission lines, particularly with a length of up to 200 m (spur line). The spur lines are designed to provide a power output of typically no more than 500 mW.An IEC 61158 Type A fieldbus cable, which consists of twisted pairs and an electrically shielded jacket (also called a shield), is typically used for data and power transmission. Such cables are referred to simply as Ethernet APL connections. According to the APL standard IEEE P8o2.3cg (2016), electrically shielded cables must be used to connect the APL field switch to each individual field device. Up to five field devices can be connected to a spur line. Several APL field switches, for example, a maximum of five to a maximum of ten, can be connected to a trunk line. APL technology is compatible with the operation of field devices in potentially explosive atmospheres.For this purpose, a low power density can be provided to prevent the electrical and / or thermal energy present in a field device from exceeding an ignition threshold, even under abnormal operating conditions. The APL field switches and field devices are designed to be ignition-proof (explosion-proof) according to protection class "Ex i."
[0007] APL technology allows the transmission of large data volumes and is characterized by compatibility with existing two-wire communication systems. However, many users of APL technology also complain about the high investment costs for upgrading or converting an entire system. To reduce the costs and space requirements of APL technology, WO 2022 / 043103 Ai proposes positioning an APL field switch together with a connected positioner in a common explosion-proof housing. This housing is designed separately and spaced apart from a control valve whose actuator is controlled by the positioner.
[0008] However, the solution from WO 2022 / 043103 Ai does not fully exploit the potential of APL technology. APL technology enables high-speed data transmission and power supply lines to be laid over distances of up to 200 meters in potentially explosive atmospheres of Zone 1 or 0 via two-wire stub lines. This makes it possible to equip the control valves themselves with processing units, such as those of the positioner and / or a sensor. This allows the control valves to be designed as network-capable devices, which increases the functionality and flexibility of the control valves and simplifies the cabling effort for control valves with multiple functions.
[0009] It is expected that the use of network-capable control valves, especially in conjunction with APL technology, will result in new functionalities and security measures, particularly against unauthorized access to the control valves via the network, at ever shorter intervals. This will result in an increase in the frequency of updates on the one hand and the risk of failure due to the increased complexity on the other. Both the failure and the update of field devices currently result in downtime for the control valve and, in the worst case, the process plant, resulting in high costs.
[0010] It is therefore an object of the invention to overcome the disadvantages of the prior art, in particular to provide a method, a control valve system and an instruction set with which downtimes of field devices, in particular control valves, and / or process engineering systems with field devices, in particular control valves, can be reduced.
[0011] The problem is solved by the subject matter of the independent claims.
[0012] One aspect of the invention relates to a method for reducing downtime during the updating of individually executable software packages for controlling and / or monitoring a field device, in particular a control valve and / or an accessory for a control valve, of a process plant. The method comprises the following steps: a) announcing an impending update of at least one of the software packages; b) categorizing the update depending on defined conditions; c) determining the time of the update and / or bridging functions to be executed during the update depending on the categorization.
[0013] The software packages preferably include software packages for controlling positioners, in particular positioners for control valves. Positioners for control valves in particular require frequent updates to update control parameters, communication protocols and / or parameters, limit values of various parameters, or the firmware of the actuator. The use of Ethernet APL or the connection of field devices in process plants with Ethernet APL and / or the modernization of process plants with modern technologies and, if necessary, additional sensor technology will lead to a further increase in the frequency of field device updates.
[0014] In the current state of the art, field devices are briefly deactivated before updates or placed into an operating mode in which the field device and / or the process plant must be paused. The resulting downtime can significantly reduce the profitability of process plants.
[0015] The software packages can be stored and / or executed on at least one processing unit. The processing unit can be designed to perform one or more of the functions described above and below. In particular, the processing unit can be or comprise a controller for communication between field devices, in particular with another field device, such as a control valve, attachment, switch, a diagnostic box and / or a higher-level system. However, the processing unit can also be responsible for other functions, for example of the field device or other field devices. The at least one processing unit can be arranged on the field device, in particular the control valve, or arranged at a distance from the field device.The arrangement on the field device can be achieved by integrating the computing unit into the field device, in particular into the position controller of a field device designed as a control valve, or via an add-on device to be attached to the field device. The spaced-apart arrangement can be achieved by integrating the at least one computing unit into another field device, in particular a control valve, diagnostic box, a switch, in particular an APL switch, and / or a higher-level system, in particular a safety controller, a control system or a diagnostic system. However, it is also conceivable for the software packages to be distributed across different devices, in particular selected from one or more field devices, add-on devices, diagnostic boxes and / or higher-level systems, of the process plant.For example, the process plant can have a plurality of field devices, in particular control valves, add-on devices, in particular sensors, at least one diagnostic box and / or at least one higher-level system, which are preferably connected to one another via Ethernet, in particular Ethernet APL.
[0016] Preferably, the at least one field device, in particular a control valve and / or an accessory device for a control valve, is designed for use in potentially explosive atmospheres, in particular Zone 0, 1, or 2. Preferably, the field device is connected via Ethernet, in particular Ethernet APL, to a higher-level unit, in particular a diagnostic box and / or a switch, which is arranged in a less potentially explosive atmosphere than the field devices. For example, the field devices can be arranged in Zone 0 and the higher-level unit in Zone 1 or Zone 2. Alternatively, the field devices can be arranged in Zone 1 and the higher-level unit in Zone 2.
[0017] It can be provided that the field device has firmware, which in turn has a plurality of software packages. Preferably, the software packages to be updated, in particular a firmware, can be updated separately. In particular, the software packages to be updated can be software packages for controlling and / or monitoring different functions of the field device, in particular a control valve, an accessory for a control valve, a control device for a measuring device, a pump, an actuator, and / or a sensor, such as a camera and / or a sensor. Alternatively or additionally, the software packages to be updated can be software packages for controlling and / or monitoring a plurality of, in particular identical or different, field devices, in particular control valves, accessory devices for a control valve, control devices for a measuring device, pumps, actuators, and / or sensors.In particular, the software packages to be updated can be different software packages or several identical software packages.
[0018] It can be provided that the field device has a plurality of functions, each of which can be executed via individual software packages. For example, the field device can each comprise individual software packages for executing functions relating to communication via a bus, a user interface, error diagnostics, pneumatics, in particular an air power amplifier, and / or control and / or position detection of a valve position of a field device designed as a control valve. It is conceivable that the field device comprises a plurality of computing units, such as microcontrollers or the like, each of which is provided for executing one or more of these software packages. Preferably, exactly one computing unit is provided for executing an individual software package. However, it is also conceivable for one computing unit to take over a function of another computing unit, for example during updating.For example, it is conceivable that the processing unit to be updated or its software package can be temporarily replaced, for example, by a second processing unit within the field device of the process plant. The second processing unit can be used to perform a bridging function. For example, the second processing unit can at least partially or completely assume the function of a software package on the first processing unit while the software package on the first processing unit is being updated. After the update, the first processing unit can then resume the respective function.
[0019] Individually executable software packages can be understood, in particular, as individually executable program blocks. The individually executable software packages can preferably also be individually updated. The individually executable software packages can be part of a software package that comprises further software packages. The software packages can preferably be individually updated in such a way that, when one software package is updated, the functionality of the other software packages of the software is at least partially, preferably completely, retained. In particular, the individually executable software packages are function-oriented software packages. This is to be understood, in particular, that each software package is responsible for at least, in particular precisely, one function of the field device.
[0020] Updating software packages can, in particular, mean adapting control parameters, communication parameters and / or protocols, for example, bus operating settings, Ethernet or APL communication protocols, or the like, and / or updating software packages, especially firmware packages. In embodiments in which field devices use Ethernet APL connections, in particular to connect them to other field devices, diagnostic boxes, switches, and / or higher-level systems, the update preferably changes and / or updates limit values, communication parameters, and / or communication protocols.
[0021] It can be provided that the updates are announced by means of computing units. In particular, the updates can be announced by one or more devices, in particular selected from one or more field devices, attachments, diagnostic boxes, switches, and / or higher-level systems, such as a safety controller and / or a process control system, of the process plant. In particular, the updates can be announced by at least one computing unit of the device. Preferably, the update is announced by a device selected from a diagnostic box, a switch, and / or a higher-level system, in particular a computing unit installed therein.
[0022] The announcement of an impending update of at least one software package in step a) can be triggered by one or more of the causes selected from the presence of a new version of the software package, a failure or malfunction of a function, a malfunction of a field device, a security gap and / or an adjustment of at least one control parameter. In particular, step a) can be triggered by querying possible causes, in particular from one or more of the previously described device(s) / processing unit(s), and announcing an update if these causes are present. For example, a diagnostic box can query the presence of one of the previously described causes, in particular at regular intervals, and announce an update if it is present.Alternatively or additionally, an update can be carried out by informing a device, in particular a higher-level system, of the presence of a cause, for example a malfunction of a function, and the device then announces an update. For example, a device monitoring the process fluid flow, in particular a diagnostic box, can announce an update of the control parameters of a software package, in particular of a control valve influencing the process fluid flow, upon detecting a flow that is too large or too small in relation to a set valve position. Alternatively or additionally, for example, when a new version of a software package is available, a higher-level system can announce the update of this software package, in particular by announcing it to a diagnostic box.
[0023] It is conceivable that in step a), the announcement of several updates takes place, in particular simultaneously or at different times. In particular, it can be provided that in the method in step a), before categorizing an announced update in step b), a predetermined period of time, in particular from 1 to 300 seconds, preferably from 5 to 180 seconds, particularly preferably from 10 to 60 seconds, is waited to see whether one or more further updates are announced, so that the categorization in step b) can take place taking into account several announced updates.
[0024] The defined conditions, depending on which the updates are categorized in step, include in particular a query of the function of the software package to be updated, in particular its relevance for operation of the field device, the type of update, in particular its importance for the respective function, the presence of an error, a state of the field device within an operation in the process plant, for example the position of a field device designed as a control valve, the reason for the update, an urgency of a parameter of a field device to be changed and / or the possible reaction to a short-term failure of the computing unit assigned to the respective software package.Preferably, updates in step b) are categorized based on at least two, preferably three, categories, which are selected in particular from: function-critical or non-function-critical, failure-critical or non-failure-critical, and / or time-critical or non-time-critical. The categorization is preferably carried out based on the predetermined conditions described below.
[0025] Depending on the categorization, in particular the prioritization, performed in step b), updates are preferably prioritized differently, particularly in step c), or treated differently during the update. If multiple updates are announced in step a), the categorizations of the other updates are preferably taken into account when determining the time of an update and / or bridging functions to be executed during the update in step c). For example, if an update is categorized as time-critical and another as non-time-critical, the update categorized as time-critical can be prioritized over the update categorized as non-time-critical.Alternatively or additionally, if an update is categorized as function-critical and the other as non-function-critical, the update categorized as function-critical can be prioritized over the update categorized as non-function-critical. Alternatively or additionally, if two updates are categorized as failure-critical, a common time can be set for the execution of both updates, for example, at which the process plant is shut down or field devices designed as control valves are moved to a safety position.
[0026] Furthermore, it can be provided that, for one or more updates categorized as non-failure-critical, a bridging function is initiated before the respective update is carried out. A bridging function is understood, in particular, to be a function that at least partially assumes the function of the software package to be updated. The bridging function can be executed by the same device, in particular a field device, on which the update is being performed or by a different device, in particular an attachment or diagnostic box.
[0027] The method according to the invention can reduce downtimes when updating field devices in a process plant. In particular, by determining the time of the update based on the previously performed categorization, unnecessary downtimes can be avoided, for example by specifying a time for the update at which the update can be performed without downtime of the process plant. For example, updates categorized as non-functionally critical can be performed without shutting down the process plant, so that no downtime occurs for such updates. Furthermore, downtimes can be avoided for updates categorized as non-failure-critical by initiating bridging functions that take over the function of the software package during the update.In addition, for updates categorized as time-critical, longer downtimes can be avoided by performing the update as promptly as possible. Furthermore, downtimes can be reduced by considering the categorization of multiple updates, for example, by performing several critical updates simultaneously. Especially when combined with a connection of multiple devices, especially control valves, accessories, switches, diagnostic boxes, and / or higher-level systems, via Ethernet APL, the increased data transmission rate of Ethernet APL enables rapid categorization of multiple updates and efficient comparison of the categorization of different updates. Furthermore, Ethernet APL particularly enables the implementation of bridging functions.In particular, thanks to Ethernet APL technology, a wide variety of devices, in particular accessory devices, control valves, diagnostic boxes, switches, and / or higher-level systems, can be used to perform bridging functions. For example, an accessory device for a control valve or a diagnostic box connected to the control valve can have software packages, in particular on corresponding processing units, which can perform bridging functions for the control valve, for example for the positioner, while its software packages are being updated. Alternatively or additionally, in process plants with multiple control valves, each control valve can provide a bridging function for another control valve. The control valves can be connected to one another either directly or via a switch or a diagnostic box, in particular using Ethernet APL.
[0028] It may be provided that, in step b), updates to software packages whose function is defined as the primary function of the field device, in particular the control valve and / or accessory device, and / or the process plant, are categorized as function-critical updates, with updates that do not meet this condition being categorized as non-function-critical updates. It may be provided that functions that are defined as important for the operation and / or safety of the field device and / or the process plant are defined as primary functions.
[0029] It may be provided that functions for controlling the control valve position of a field device designed as a control valve, for providing safety functions, in particular the response to a spontaneous pressure loss in the field device, for communication of the field device with a safety controller and / or a process control system, and / or for the pneumatics of pneumatically driven field devices, in particular control valves, are defined as primary functions. Alternatively or additionally, it may be provided that functions relating to a user interface and / or diagnostic functions are not defined as primary functions, in particular as secondary functions.It can be provided that for functions defined as primary functions, in particular for functions for reacting to a spontaneous pressure loss in the field device, such as functions for setting a control valve designed as a field device into a safety position, in particular via a safety controller, an update is only carried out if a bridging function is available for the period of the update or if the field device or the process plant is in a maintenance state, in particular switched off. Alternatively or additionally, it can be provided that for functions that are not categorized as primary functions, the functions are deactivated for the period of the update, in particular without a bridging function. In particular, functions not categorized as primary functions can be deactivated and / or updated individually, one after the other or together.In particular, it can be provided that, when computing capacity is limited, updates to functions categorized as primary functions are prioritized over functions not categorized as primary functions. For example, if in step a) the update of two software packages is announced, one of which executes a function categorized as a primary function and one of which executes a function categorized as a secondary function, and updating both software packages would lead to excessive utilization of computing capacity, only the update of the software package with the function defined as the primary function can be executed.
[0030] The inventors have recognized that, in particular, the functions previously defined as primary functions are of great importance for the reliable and safe operation of field devices, so that appropriate prioritization of these functions in step c) leads to a reduction of downtimes.
[0031] It may be provided that in step c) for updates categorised as non-functionally critical, a time for the update is set at which computing capacities required for the update are not needed for updates categorised as functionally critical.
[0032] It may be provided that, in step b), updates to software packages whose functions are defined as compensable during the update are categorized as non-failure-critical, with updates that do not meet this condition being categorized as failure-critical updates. Alternatively or additionally, it may be provided that, in step b), updates to software packages whose functions are defined as compensable in the event of an unplanned failure of a device or control unit on which the software package is installed are categorized as non-failure-critical, with updates that do not meet this condition being categorized as failure-critical updates.It can be provided that functions for which a bridging function is available, in particular functions which can be taken over at least partially, in particular in the form of a rudimentary basic function or a control routine, or completely, in particular by a second software package with the same function, during an update, are defined as compensable, wherein preferably functions defined as primary functions of the field device can be taken over at least partially or completely during an update, preferably are taken over.
[0033] It may be provided that in step c) for updates categorised as non-failure-critical, bridging functions are initiated before the update is carried out to compensate for the function affected by the update during the update.
[0034] It may be provided that the bridging functions are selected from one or more of the following bridging functions:
[0035] 1. Complete takeover of the affected function during the update, in particular by a second software package, which is preferably stored on a second computing unit, in particular within the field device, another field device of the process plant or a diagnostic box;
[0036] 2. Partial compensation by a, in particular autonomous, control routine during the update, which is provided in particular by a second software package, which is preferably stored on a second computing unit, in particular within the field device, another field device of the process plant or a diagnostic box;
[0037] 3. Partial compensation by a rudimentary basic function during the update, in particular wherein, when updating a software package for controlling the control valve position of a field device designed as a control valve, a setpoint for maintaining the control valve position is maintained, in particular by a process control system.
[0038] It is conceivable that, depending on the categorization in step b), a bridging function is selected, in particular to avoid a total failure of the field device and / or the process plant. For example, it is conceivable that, when a software package is due to be updated, a rudimentary basic function is provided for external communication between a control valve or position controller, in particular with the process control system, and in particular a setpoint is maintained for controlling the valve position. This means that the valve position cannot be controlled during the update, but the control valve can continue to operate without moving to a safety position. It is also conceivable that, in particular in applications where a field device, in particular a control valve, frequently performs a certain control function, a control routine is stored, for example in another software package oranother processing unit or analog control logic. During the update, this control routine can then be executed automatically / autonomously until communication is enabled again. This is essentially also conceivable for updating a package for controlling a valve position.
[0039] It may be intended that the function will be taken over again by the updated software package after the update. In particular, the bridging function can be terminated as soon as the function is taken over again by the updated software package.
[0040] It may be provided that in step c) for updates categorised as non-failure-critical, a time for the update is set at which the computing capacity required for the update is not needed for updates categorised as failure-critical.
[0041] It can be provided that in step c) a time is specified for the update for updates categorized as non-functional and failure-critical, at which time the computing capacity required for the update is not needed for updates categorized as non-functional and failure-critical. Preferably, a time can be specified for the update at which a field device designed as a control valve is in a safety position. For this purpose, it can preferably be checked whether an anticipated time in which the control valve is in a safety position is sufficient for the update. In particular, a comparison can be carried out between the anticipated time required for the update and the time in which the control valve is, in particular as planned, in a safety position.Preferably, the update is only performed if the expected time for the update is less than the time during which the control valve is in a fail-safe position.
[0042] It may be provided that in step c) for updates categorised as function-critical and non-failure-critical, a time for the update is set at which sufficient computing capacity is available for the update and for the bridging function.
[0043] It can be provided that in step c) for updates categorized as failure-critical, the time of the update is determined depending on a current or future planned operation of the field device and / or the process plant, wherein in particular a process-noncritical time is determined. Preferably, a process-noncritical time is defined as a time at which no change in the position of a control valve, no change in a fluid, no change in the flow through the field device, in particular the control valve, and / or generally no flow of fluid through the field device, in particular the control valve, is planned. For this purpose, a query can be made, in particular to a higher-level system, preferably a process control system, after a process-noncritical time.
[0044] The time for the update can be determined depending on the current or future planned operation of the field device and / or the process plant, in particular if no bridging function is available for this function.
[0045] It can be provided that the time of the update is determined depending on a control signal of the process control system, a state of the computing unit and / or a state of the safety controller.
[0046] It can be provided that the time of the update is set within a time window in which no changes to the control valve position of a field device designed as a control valve are planned. In particular, during updates to software packages relating to the control of the control valve position, a bridging function, in particular one of the bridging functions described above, is performed in step c). This allows a software package to be updated without having to accept any downtime of the control valve.
[0047] It may be provided that in step b) updates that are announced as a result of a cause defined as urgent are categorized as time-critical updates, with updates that do not meet this condition being categorized as non-time-critical updates.
[0048] It can be provided that the failure or malfunction of a function defined as a primary function, a malfunction of a field device and / or security gaps, in particular with regard to external access to the field device, to other field devices of the process plant, or to the entire process plant, are defined as urgent causes, whereby, in particular, the adjustment of control parameters or the failure of functions not defined as primary functions are not defined as urgent causes. It can be provided that in step c), for updates categorized as non-time-critical, a time for the update is specified at which the computing capacity required for the update is not needed for updates categorized as time-critical.
[0049] It may be provided that, for updates categorized as both function-critical and / or time-critical and failure-critical in step c), a decision is made using an algorithm based on weighting factors as to whether a downtime of the field device and / or the process plant is to be accepted in favor of a timely update, or whether the update is postponed to a time at which the update can be performed without, with less downtime, or during a planned downtime. It may be provided that such an algorithm is executed via a higher-level processing unit or within a processing unit of a field device, in particular the field device on which the software package is to be updated, or on another field device.
[0050] Downtime within the meaning of the present invention can be understood as downtimes resulting from scheduled downtimes, for example due to an update or maintenance to be carried out, of the process plant and / or unscheduled downtimes, for example due to a failure of a device, in particular a control valve.
[0051] It may be provided that the field device, in particular the control valve, is placed in a safety position, in particular a closed position, in step c) before an update categorized as failure-critical and / or function-critical is carried out. In particular, it is conceivable that for functions of software packages for which no override function is available, one or more valves affected by the update are placed in a safety position or another predefined basic position, in particular a safety position.
[0052] It can be provided that updates in step c) are blocked if they would lead to excessive utilization of computing capacity and / or if the computing capacity of the computing unit on which the software package to be updated is executed and / or stored already has excessive utilization of computing capacity. Excessive utilization of computing capacity can in particular mean a utilization of more than 50%, 60%, 70%, 75%, 80%, 85% or 90%, preferably more than 80%, of the computing capacity. The inventors have recognized that, in particular, excessive utilization of computing capacity, in particular of more than 80%, significantly increases the risk of slowdown and, in the worst case, total failure, especially of functions defined as primary functions. By blocking updates in such situations, downtimes can be significantly reduced.
[0053] It can be provided that the software packages are distributed across a plurality of computing units and / or devices, in particular field devices, add-on devices, a diagnostic box and / or higher-level systems, of the process plant, which are preferably connected to one another via Ethernet, in particular Ethernet APL, and / or a switch, in particular APL switch. The method is preferably applied to a process plant with at least one field device, in particular a control valve, and / or at least one add-on device, in particular a sensor, which is connected, in particular via Ethernet APL, to at least one further field device, in particular a control valve, and / or at least one further add-on device, in particular a sensor, in particular via Ethernet, preferably Ethernet APL. The connection can be made directly or indirectly, for example via a switch, in particular an APL switch.
[0054] In particular, by connecting multiple computing units and / or multiple devices via Ethernet APL, the software packages can be distributed across the various computing units and / or devices. The high bandwidth of Ethernet APL provides high time resolution with sufficiently large data volumes. This allows the method to categorize updates in step b) particularly efficiently, taking into account as many conditions as possible, such as the function of the software packages, the compensability of the software packages, the urgency of the update, and / or the cause of the update. This allows the timing and / or bridging functions to be executed during the update in step c) to be determined particularly efficiently, thereby reducing downtimes of the field device and / or the process plant.
[0055] It can be provided that, to determine the time of the update in step c), coordination takes place between devices of the process plant, in particular, the time of the update of a software package of a first device depends on an upcoming maintenance or update on a second device. Alternatively or additionally, the update of software packages of multiple devices, in particular for communication between the devices, can take place simultaneously for all devices, in particular of a node or system.
[0056] If multiple devices and / or multiple computing units are present, steps a) to c) can be performed individually or jointly for each device and / or computing unit, in particular to determine a suitable time for an update. For example, if multiple updates are planned, the categorizations of the individual updates in step b) can be compared with each other in order to determine suitable times and / or suitable bridging functions for the individual updates in step c).
[0057] It can be provided that when executing a bridging function, in particular by means of a control routine, in step c), the bridging function is communicated to other devices, in particular devices in the respective part of the process plant, and / or these devices take the bridging function into account in their behavior, in particular with regard to their own updates. For example, in a field device designed as a control valve, the bridging function can be a control routine that replaces the control function of the control valve, whereby the control routine is communicated to other devices and / or these devices take the control routine into account in their behavior.
[0058] A further aspect of the invention relates to a field device system, in particular a control valve system, for adjusting a process fluid flow in a process plant, such as a chemical plant, a power plant, a food processing plant, or the like. The field device system comprises at least one, preferably at least two, three, four, or five, individually executable software package(s) for controlling and / or monitoring a field device, in particular a control valve, and at least one computing unit designed, upon announcement of an impending update of a software package, to categorize the update depending on defined conditions and, depending on the categorization, to determine a time of the update and / or to execute bridging functions to be executed during the update, in particular according to the method described above.
[0059] In particular, the field device system comprises at least one, preferably at least two, three or four, particularly preferably at least five, eight or ten, field devices. A field device within the meaning of the present invention can be, for example, a control device, a measuring device or an actuator. A field device can be, for example, a control valve for adjusting a branch of the process fluid flow. For example, the field device is a control valve or a pump. For example, the control valve can be operated pneumatically, electrically or hydraulically. The field device can be operated with auxiliary energy, such as pneumatic auxiliary energy, wherein in particular a preferably pneumatic drive can be actuated via a particularly electropneumatic position controller.The field device system, and in particular the field device, can be a field device that is either unmounted or integrated into the system and is capable of operating the fluids generated during processing in the process plant under explosion protection. In general, control valves and pumps, in particular, are intended to influence the process fluid flow in the process plant, in particular to control and / or regulate it.
[0060] In addition to the at least one field device, the field device system can have at least one, preferably at least two, three or four, particularly preferably at least five, eight or ten, further device(s), in particular selected from attachments, in particular sensors, diagnostic boxes, switches and / or higher-level systems, in particular a safety controller, a control system and / or a diagnostic system.
[0061] Preferably, a plurality of field devices, in particular control valves, are interconnected, in particular via Ethernet APL. The connection can be established directly between the field devices. However, the field devices are preferably interconnected via at least one switch and / or a diagnostic box. Preferably, the field devices are connected to at least one switch, which in turn is connected to a diagnostic box. Particularly preferably, all of these connections are implemented via Ethernet APL. Particularly preferably, the field device lines are connected to the switch via spur lines. Preferably, the switch is in turn connected to a diagnostic box and / or a higher-level system via a trunk line.
[0062] Particularly preferably, the field device system has a first group of field devices that are connected to one another via a first switch, in particular an APL switch, and at least a second, third, fourth, or fifth group of field devices that are in turn connected to one another via a second, third, fourth, or fifth switch, in particular an APL switch. The field devices are preferably connected to the respective switch via trace lines. The switches are preferably connected to one another via a trunk line. Furthermore, the switches are preferably connected to a diagnostic box and / or a higher-level system via the trunk line. Particularly preferably, the switches are connected to at least two, in particular three, higher-level systems via the trunk line, in particular selected from a safety controller, a control system, and / or a diagnostic system.Preferably, a power switch is provided between the higher-level systems and the at least one switch or diagnostic box. The power switch is preferably connected, in particular via Ethernet APL, to the higher-level systems on the one hand and to the at least one switch or diagnostic box on the other hand.
[0063] In addition, the field device system in particular has at least one, preferably at least two, three or four, particularly preferably at least five, eight or ten, attachment(s), in particular sensor(s). Preferably, the at least one attachment is connected via Ethernet, particularly preferably via Ethernet APL, to the field device, a switch, a diagnostic box and / or a higher-level system. Particularly preferably, the attachment is connected directly to the at least one field device, in particular via an Ethernet APL connection, preferably a spur line. Preferably, the at least one field device is in turn connected via a spur line to a switch, which in turn is preferably connected via a trunk line to a diagnostic box and / or a higher-level system.For example, the at least one accessory device can be connected directly to the at least one positioner, in particular to a processing unit of the positioner, in particular via Ethernet APL. This can, in particular, save cable length and simultaneously provide direct communication between the accessory device and the control valve. However, it is conceivable that the at least one accessory device is connected directly to a switch or a diagnostic box, in particular via Ethernet APL.
[0064] Furthermore, the field device system can have a process controller that controls at least one device, in particular a control valve, attachment, diagnostic box and / or switch. The process controller can be connected to the at least one device by means of a communications network, in particular via Ethernet-APL. The connection of the at least one device to the higher-level process controller can also be established via a bus connection, for example via HART, Profibus, FOUNDATION Fieldbus or the like. By linking the process controller with the device, information about the process plant or its field devices can be exchanged and used globally for process control on the one hand, and fed back into the device for evaluation processes and / or direct control set up by the control unit itself, on the other hand.In this respect, a very flexible and efficient diagnostic option is provided for the process plant.
[0065] Furthermore, the field device system can include a safety network for the safety-related switching on and / or off of field devices, in particular switching on and / or off devices. The safety network can comprise an actuator of a field device, the sensor, and a safety controller, wherein the safety controller can be connected to the field devices via a diagnostic box and / or a switch, in particular via Ethernet-APL. In an exemplary embodiment, the field devices and / or sensors are also connected to a switch and / or a diagnostic box via an Ethernet-APL connection, for example a cable. It is also conceivable for the field devices and / or sensors to be connected to the switch and / or the diagnostic box exclusively or additionally via another bus connection, for example via HART, PROFIBUS, FOUNDATION Fieldbus, or the like.Alternatively or additionally, it is possible for the field devices to be directly connected to one another, in particular via Ethernet-APL. The at least one sensor can be designed as part of a field device or separately. The sensors and / or the field devices can be supplied with electrical power entirely or partially via Ethernet-APL connections. For example, the power supply can also be provided separately via a switch or a diagnostic box. For example, it is possible for only a single connection to run between the multiple field devices and the safety controller or the higher-level process controller, namely via the switch or the diagnostic box. The other connection in each case can be designed separately.
[0066] In one embodiment, the process plant has potentially explosive areas, in particular in Zone 2, Zone 1 and / or Zone 0. For example, the process plant can have a potentially explosive area in Zone 2. Higher-level systems, in particular a safety controller (safety network), a control system (process control) and / or a diagnostic system, of the process plant are preferably arranged outside of Zone 2. If Zone 1 and Zone 2 are also present in the process plant, the higher-level systems are preferably also arranged outside this zone. Alternatively or additionally, the process plant preferably has control devices with explosion protection for at least Zone 2, which are arranged in Zone 2. The field devices can be connected, in particular via Ethernet APL, to the higher-level systems arranged outside of Zone 2.Furthermore, the process plant or the control valve system can have at least one switch to which, in particular as described above, a plurality of field devices are connected, in particular via Ethernet APL. The switch can also be arranged in Zone 2. Alternatively or additionally, the process plant can have a diagnostic box, which can also be arranged in Zone 2. The at least one field device can either be connected directly to the diagnostic box or via the switch described above. Preferably, the process plant has both the at least one switch described above and the diagnostic box described above, which are preferably each arranged in Zone 2 and preferably connected to one another via Ethernet APL. Furthermore, the process plant orthe field device system has a power switch to which the at least one field device, and preferably the at least one switch and / or the diagnostic box are connected, in particular via Ethernet APL. The power switch can be connected to a power supply and supply the at least one field device, the at least one switch and / or the diagnostic box with power, in particular via Ethernet APL. The power switch can be arranged in Zone 2. Furthermore, the process plant can have at least one potentially explosive area in Zone 1. Preferably, at least one field device and / or a switch can have explosion protection for Zone 1. Particularly preferably, several field devices can be equipped with explosion protection for Zone 1 and connected to a switch with explosion protection for Zone 1, in particular via Ethernet APL.For example, the plurality of field devices and the switch can be arranged in Zone 1 and, in particular via Ethernet APL, with a switch, a diagnostic box and / or a power switch, in particular as described above, in Zone 2 or outside of Zone 0, 1 and 2.
[0067] Furthermore, the at least one field device can have areas, in particular in the area of the actuator of a field device designed as a control valve, which have explosion protection for Zone 0. These areas of the control valves can then be arranged in an explosion-hazardous area of Zone 0.
[0068] The inventors have recognized that, particularly in conjunction with Ethernet APL technology, field devices, in particular control valves, their attachments, switches and diagnostic boxes can be integrated into potentially explosive areas with particularly little cabling effort without having to forego computing units and electrical supply of the field devices, their attachments, switches and diagnostic boxes, so that in particular the method according to the invention can be carried out particularly efficiently and comprehensively.
[0069] The field device system may comprise a communication network configured to connect the at least one sensor to a diagnostic box for receiving and processing the image and / or sound data from the sensor for signal transmission via Ethernet-APL.
[0070] A diagnostic box within the meaning of the present invention is, in particular, a device having at least one computing unit. The diagnostic box is, in particular, designed to receive data, in particular measured values, from the at least one field device and / or a higher-level system and / or to send them to the field device and / or a higher-level system. For example, the diagnostic box can be designed to receive data, in particular measured values, from the at least one field device. In particular, the diagnostic box can be designed to filter and / or pre-evaluate received data and to forward the filtered and / or pre-evaluated data to a higher-level system. The filtering can, in particular, comprise the comparison of received data, in particular measured values, with stored tolerance ranges and / or comprise a selective forwarding of certain data.For example, a sensor can be configured to continuously measure the position of a valve element of a field device configured as a control valve, while the diagnostic box only transmits changes in the position of the valve element to the higher-level system. Alternatively or additionally, the diagnostic box can be configured to perform an evaluation for error causes in the event of deviations from a tolerance range and, upon identification of a potential error, either directly correct the error on the field device, for example, by updating software packages, or to communicate the error to a higher-level system.
[0071] Alternatively or additionally, the diagnostic box can also be configured to receive notifications of updates, in particular centrally, from a higher-level system and forward them to the at least one field device, attachment, and / or switch. However, the categorization of updates is preferably performed centrally via the diagnostic box. For this purpose, the diagnostic box can be configured to check for the presence of defined conditions based on information about the updates provided with the announced updates and / or by querying data, in particular measurement data, from the at least one field device, attachment, and / or switch.Alternatively or additionally, the diagnostic box can be designed to store data received from the at least one field device, attachment and / or switch, in particular data that could be relevant for categorizing possible future updates, and to use this data for categorization in the event of an announced update. Furthermore, the diagnostic box can be designed to determine the time of the update and / or bridging functions to be executed during the update depending on the categorization. For this purpose, the diagnostic box can in particular be designed to issue corresponding instructions to the at least one field device and / or switch. The functionalities previously explained in connection with the diagnostic box can alternatively or additionally also be provided on a switch, an attachment, a field device or a higher-level system of the process plant.
[0072] In one embodiment, the field device system comprises a control valve for adjusting a process fluid flow in a process plant, such as a chemical plant, a power plant, a food processing plant, or the like. The control valve comprises a first processing unit for controlling the control valve and a second processing unit designed to assume at least one function of the first processing unit in the event of a failure and / or update of the first processing unit. The control valve can be operated with auxiliary energy, such as pneumatic auxiliary energy. In particular, the control valve can comprise a position controller, in particular a pneumatically and / or electropneumatically operated position controller. Furthermore, the control valve can comprise a valve member that can be adjusted via the position controller, in particular to open and / or close or partially close a fluid passage opening.Furthermore, the control valve can have a drive, in particular an electric or pneumatic drive, to adjust the valve member. The drive can be connected to the valve member via an actuating rod. Furthermore, the control valve can have a housing. The housing can have a valve member housing, a valve rod housing and / or a drive housing. The control valve preferably has a position controller. The position controller is preferably attached to the housing, in particular attached to the valve rod housing. In particular, the position controller is arranged, in particular attached, in the region of the valve rod. Configurations are also possible in which the position controller is attached via the drive or a structure of the drive.
[0073] According to this embodiment, the first and second computing units are part of the control valve. The first and second computing units can be arranged, for example, attached, to different areas of the control valve. For example, one computing unit can be arranged in the positioner and another computing unit in the actuator. However, the first and second computing units can also be arranged adjacent to one another (in particular in a common component of the control valve). For example, the first and second computing units can be arranged in the positioner.
[0074] The computing unit is preferably a computing unit of the position controller. The first computing unit is particularly preferably designed to control, in particular to regulate, the position of the valve member. In a preferred embodiment, the second computing unit is preferably also part of the position controller. The second computing unit is preferably designed to completely assume at least the function of controlling, in particular regulating, the valve member in the event of a failure and / or an update of the first computing unit. The second computing unit is preferably designed to at least partially, preferably completely, assume all functions of the computing unit in the event of a failure and / or an update of the first computing unit.
[0075] The inventors have recognized that by integrating the first and second processing units into the control valve, downtimes of the control valve, particularly due to a failure of the first processing unit and / or an update of the first processing unit, can be significantly reduced. In particular, by integrating both processing units into the control valve, the cabling effort can be significantly reduced compared to solutions in which the second processing unit and / or the first processing unit are located outside the control valve. At the same time, the at least one function can be performed more reliably because direct communication between the two processing units is enabled.In contrast, for example in embodiments in which at least one of the two processing units is connected to each other via a switch outside the control valve, an overload or failure of the switch can result in the second processing unit being unable to take over the function of the first processing unit. If the data transmission between the two processing units via a switch is overloaded, the takeover of the function by the second processing unit (bridging function) can be disrupted, in particular prevented. Furthermore, by integrating the first and second processing units into the control valve, the number of connections for connecting the control valve to a switch, a higher-level system or a diagnostic box can be reduced. By reducing the number of connections, the risk of sparking or critical currents in the area of the connections can also be reduced, thus reducing the risk of explosion.
[0076] Preferably, the first and second processing units are mounted in an explosion-proof area of the control valve. For example, the first and second processing units can be arranged in an explosion-proof housing of the control valve, for example, in a housing of the position controller. In particular, the housing can have explosion protection for Zone 2, preferably Zone 1, particularly preferably Zone 0. Preferably, at least one explosion-proof connection is also provided on the housing, via which the control valve can be connected to another device, in particular a control valve, switch, diagnostic box, and / or higher-level system, preferably via an Ethernet APL cable.
[0077] The first computing unit and / or the second computing unit can be designed to monitor the functionality and / or upcoming updates of the first computing unit (preferably of the other computing unit). Alternatively or additionally, the functionality and / or upcoming updates of the first computing unit can be monitored by another control valve, an attachment, a diagnostic box, a switch, or a higher-level system. If a failure or an upcoming update of the first computing unit is detected, the monitoring of the device can be designed to initiate the takeover of the function by the second computing unit. Preferably, the first computing unit, the second computing unit, and / or one of the other devices described above can be designed to carry out one or more of steps a), b), and c) of the method according to the invention.
[0078] In a further embodiment, which can be combined with the previous embodiment and vice versa, the control valve system comprises an attachment for a control valve for adjusting a process fluid flow in a process plant, such as a chemical plant, a power plant, a food processing plant, or the like. The attachment comprises a second processing unit, which is designed to assume at least one function of the first processing unit in the event of a failure and / or an update of a first processing unit of the control valve.
[0079] The attachment can be designed to be attached to a control valve. In particular, the attachment can have a connection for mounting on a control valve. Particularly preferably, the attachment is designed to be attached to a housing, in particular a control rod housing, of the control valve. The second computing unit can be arranged in the housing of the attachment. The housing of the attachment can be explosion-proof, in particular with regard to potentially explosive areas of zone 2, preferably zone 1, particularly preferably zone 0. The housing can seal the second computing unit, in particular hermetically, from the environment. The housing can be designed to communicate with the control valve. Communication with the control valve can take place wirelessly or via cable.In addition, communication with the control valve can be established directly, for example, through a direct connection to the control valve, or through a connection via another device, such as a switch, a higher-level unit, and / or a diagnostic box. Preferably, the accessory is connected directly to the control valve, particularly preferably directly to a positioner of the control valve. The connection between the accessory and the control valve is preferably established via Ethernet, particularly preferably Ethernet-APL.
[0080] The attachment can have further devices, such as a further processing unit and / or a sensor. The attachment preferably has a sensor. The sensor can be designed to measure process variables, in particular temperature, volume flow and / or pressure, of the process fluid flow. Alternatively or additionally, the attachment can have a further processing unit for operating the sensor. It can be provided that the second processing unit, in addition to assuming the functions of the first processing unit, can be designed to control the further device, such as the sensor, of the attachment. The inventors have recognized that the attachment can represent an alternative to the embodiment with a first and second processing unit in the control valve. A particular advantage of this embodiment is that the attachment can be retrofitted to existing control valves and process engineering systems.This allows for a reduction in downtime, particularly in existing, and especially older, systems, particularly due to failure and / or updates of control valve software packages. Mounting the accessory in the area of the valve stem, particularly on the valve stem housing, significantly reduces the amount of cabling required, particularly for the connection between the accessory and the processing unit.
[0081] A further embodiment of the control valve system, which can be designed like the two previously described embodiments and vice versa, comprises a control valve with a first processing unit for controlling the control valve and a second processing unit, which is designed to take over at least one function of the first processing unit in the event of a failure and / or an update of the first processing unit. In this embodiment, the first processing unit is part of the control valve. The positioning, fastening and / or connection of the first processing unit to further devices, in particular the second processing unit, another control valve, an attachment, a switch, a diagnostic box and / or a higher-level system, can be implemented as in connection with the two previously described embodiments. The second processing unit can
[0082] It can be part of the control valve. However, it can be designed independently of the control valve. In particular, the second processing unit can be designed in an accessory device, in particular for a control valve. However, the second processing unit can also be designed in other devices, for example in another control valve, a switch, a diagnostic box, or a higher-level system.
[0083] For example, the control valve system can have at least one further control valve, wherein the second processing unit is part of the further control valve. In such an embodiment, the second processing unit can be a processing unit that is designed to control the second control valve. Particularly preferably, the first processing unit is designed to take over at least one function of the second processing unit in the event of a failure and / or an update of the second processing unit. In this embodiment, the first and second processing units each provide bridging functions for one another. This can reduce downtimes without having to provide additional processing units. For this purpose, the first and second control valves are preferably connected to one another, in particular via Ethernet, particularly preferably via Ethernet-APL. The connection can be direct or indirect.An indirect connection can be established, for example, by connecting further control valves, in particular their processing units, to a common switch. The control valve system preferably further comprises a diagnostic box which is connected to the second control valve via Ethernet, in particular via Ethernet-APL. The connection can be direct or indirect. An indirect connection can be realized, for example, by connecting the diagnostic box to the two control valves via a common switch. Furthermore, the diagnostic box and / or the two control valves can be connected to at least one higher-level system, preferably at least two or three, in particular as described above. The connection can be direct or indirect. The connection to the higher-level system is preferably made via a common switch (indirect).Particularly preferably, the control valve system comprises a power switch that supplies the previously described switch with power. The diagnostic box can be arranged between the switch and the power switch and, in particular, is connected, in particular directly, to the switch and the power switch via Ethernet, preferably via Ethernet-APL. The higher-level system can be connected to the other components via the power switch.
[0084] Alternatively, the second computing unit can be arranged in a diagnostic box of the control valve. The diagnostic box can be connected directly or indirectly to the control valve. Preferably, the diagnostic box is connected indirectly, in particular via a switch, to the control valve. Particularly preferably, the connection between the diagnostic box, the switch, and the control valve is via Ethernet, in particular Ethernet-APL. In addition, the system preferably has a power switch, which supplies the switch with power, in particular via Ethernet-APL. Preferably, the diagnostic box is arranged between the switch and the power switch and is preferably connected to the switch and the power switch via Ethernet-APL. The control valve system can have further control valves that are connected to the switch and the diagnostic box and / or the first control valve.
[0085] Alternatively, the second computing unit can be part of a higher-level system of the control valve system, for example a safety controller, a control system and / or a diagnostic system. The higher-level system can be connected to the control valve, preferably via Ethernet-APL. In this embodiment, the control valve system preferably also has a diagnostic box and / or a switch, via which the higher-level system is connected to the control valve, and preferably to further control valves. The field device system described above can be designed to carry out the method according to the invention. The method according to the invention can be carried out with the field device system according to the invention, in particular can be carried out in such a way that it can be carried out with such a field device system.The embodiments and / or configurations described in connection with the respective aspects of the invention can be designed and / or carried out individually or jointly in the different aspects of the invention.
[0086] The invention further relates to an instruction set comprising commands which, when the instruction set is executed by a field device, in particular a control valve and / or an attachment for a field device, in particular a control valve, a field device system, in particular a control valve system, or a process plant, cause the latter to carry out the method described above.
[0087] Preferred embodiments are specified in the dependent claims.
[0088] Further features, characteristics and advantages of the invention will become clear from the following description of preferred embodiments, in which:
[0089] Figure 1 is a schematic flow diagram of a method according to the invention;
[0090] Figure 2 shows an embodiment of a field device system according to the invention; and
[0091] Figure 3 is a schematic representation of a process plant.
[0092] To simplify readability, the same or similar reference numerals are used in the following description of preferred embodiments for the same or similar components.
[0093] Figure 1 schematically shows a flow diagram of a method according to the invention. Steps a) (announcement of an impending update of at least one of the software packages) and b) (categorization of the update depending on defined conditions) are schematically indicated therein. For step c) (specifying the time of the update and / or bridging functions to be executed during the update depending on the categorization), three exemplary sequences are outlined above the dashed boxes, which can occur in the method according to the invention depending on the categorization in step b). The three sequences can occur simultaneously or sequentially. It should be understood that the sequences shown are merely exemplary. Thus, more or fewer sequences can occur simultaneously or sequentially. Furthermore, the sequences can comprise additional, different, and / or fewer steps.
[0094] The left-hand box shows an example sequence of step c) for an update that was categorized as a non-failure-critical update in step b). For example, this could be the update of a software package for controlling the position of a valve element of a field device designed as a control valve. Such an update can be classified as non-failure-critical in step b) if the function of the software package to be updated is defined as compensable. For example, a position controller of the control valve can have two identical software packages that are independently suitable for controlling the control valve position. In such cases, the update can be categorized as non-failure-critical in step b) in that the second software package can provide a bridging function with which the function affected by the update can be fully taken over.In step c), a first sub-step can be used to check whether the bridging function is available. If the bridging function is not available, for example because the software package responsible for it is currently being updated or is taking over the function of another positioner, a second check can be initiated at a later time. If the bridging function is available, the function of the software package to be updated can be taken over by the redundant software package in a second sub-step. Once the function has been taken over, the function of the software package to be updated can be deactivated in a third sub-step and a time for the update can then be set. Finally, the update can be carried out. After the update, the updated software package can take over the function again.
[0095] The middle box shows an example sequence of step c) for an update that was categorized as a function-critical update in step b). For example, this could involve updating a software package for controlling the position of a valve element of a field device designed as a control valve. Updates concerning such software packages are preferably categorized as function-critical. If no bridging function is available for such software packages, they can be categorized as function-critical and failure-critical. In such cases, it may be intended to determine the position of the valve element in a first sub-step of step c).If the valve element is not in a safety position, the valve element can be moved to the safety position in a second sub-step and then the time for the update (e.g. immediately after the safety position is assumed) can be specified in a third sub-step. The update can then be carried out. The box on the right shows an example sequence of step c) for an update that was categorized as a non-functional update in step b). For example, updates that affect software packages with functions for a user interface can be categorized as non-functional in step b). Such functions can generally be updated at any time without having to provide a bridging function or having to shut down the process plant or directly affected field devices or put them into a safety position.Since the failure of an update categorized as non-functionally critical does not usually result in a failure of the entire system or part of the system, such categorizations do not necessarily have to take place immediately. In this respect, for such updates, a first sub-step can be provided to check whether and how much computing capacity is available for updates. In a second step, a check can then be made as to whether the generally available computing capacity is required for function-critical or other prioritized updates. If this is the case, the update categorized as non-functionally critical can be delayed until sufficient computing capacity is available that is not required for other purposes. If the computing capacity is not required for other purposes, the time for the update can be set to immediate in a further sub-step.Finally, the update can be carried out.
[0096] Figure 2 shows an embodiment of a field device system 2 according to the invention in the form of a control valve system 2. The control valve system 2 has a field device designed as a control valve 9. The control valve 9 has a position controller 6 with a computing unit 8 on which an individually executable software package for controlling the valve member position is installed. The computing unit 8 is designed, upon announcement of an impending update of a software package, to categorize the update depending on defined conditions and, depending on the categorization, to execute a time of the update and / or bridging functions to be executed during the update, in particular according to the method according to the invention.Alternatively or additionally, other computing units of the control valve system, for example in one or more of the attachments 24, 28 described below, the switch 35 described below, the diagnostic box 7 described below, the higher-level system 3 described below or the further field device 36 described below, can be designed accordingly.
[0097] Furthermore, the control valve 9 has a valve member 10, a drive 12 for adjusting the valve member, and a valve rod 14 that connects the valve member 10 to the valve drive 12. Furthermore, the control valve has a housing 16 that has a valve member housing 18, a valve rod housing 20, and a drive housing 22.
[0098] Furthermore, the control valve system 1 has an attachment 24 for a redundant processing unit (not shown), which is designed to provide a bridging function for the software package installed on the processing unit 8 of the position controller 6. In the present case, the attachment is attached to the valve rod housing 20. However, it can also be arranged in other areas of the control valve 9, for example, on the drive housing 22 or on the valve member housing 28, or at a distance from the control valve 9. The processing unit in the attachment 24 can be designed to perform a bridging function, for example, when updating a software package from one of the other processing units, for example, the attachment 28 and / or the position controller 6.The computing unit of the attachment 24 can be connected directly to the computing unit 8 or to another device, for example the switch 35 shown in Figure 2, in particular via Ethernet APL.
[0099] Furthermore, the control valve system 1 has a sensor 11 for measuring process variables, in particular volume flow, temperature and / or pressure, of a fluid, in particular fluid flow, in the valve member housing 18. Furthermore, the control valve system 2 in this case has a further attachment 28 with a computing unit (not shown) for the sensor 11. The computing unit can be designed to read out, process and / or forward the process variables measured by the sensor. Alternatively or additionally, the computing unit in the attachment 28 can be designed to perform a bridging function, for example when updating a software package from one of the other computing units, for example the attachment 24 and / or the position controller 6. The computing unit of the attachment 28 can be connected directly to the computing unit 8 or another device, for example the switch 35 shown in Figure 2, in particular via Ethernet APL.
[0100] Furthermore, the control valve system 2 has a switch 35, via which the control valve 9 is connected to a diagnostic box 7 of the control valve system 2, in particular via Ethernet APL. Computing units of the add-on devices 24 and 28 can be connected to the switch 35 via the position controller 6 or directly to the switch 35. The diagnostic box 7 can be designed to announce updates of software packages via the switch 29 to the corresponding computing units, for example of the position controller 6 and / or one or more of the add-on devices 24 and 28. Alternatively or additionally, the diagnostic box 7 can be designed to receive, evaluate, filter and / or forward data, for example measurement data from the sensor 11 or the control valve position from the position controller 6, for example to another higher-level system (not shown).
[0101] Furthermore, the control valve system 2 in this case has a higher-level system 3 directly connected to the position controller 6. This can be used, for example, to communicate updates directly to the position controller, in particular by bypassing the diagnostic box 7. However, it can also be provided that the higher-level system 3 and / or other higher-level systems are connected to the position controller 6 via the diagnostic box 7 and / or the switch 35.
[0102] In the present case, the control valve system 2 further comprises a further, schematically illustrated control valve 40. In this case, the further control valve 40 is connected directly to the position controller 6 of the control valve 9. This allows the control valves 9 and 40 to perform bridging functions for one another when software packages of one control valve are updated. Furthermore, this allows the control valves 9 and 40 to be coordinated with one another when determining the time for an update. However, it is also conceivable that the further control valve 40 and, if applicable, other control valves not shown, are connected to one another via the switch 35 or a power switch not shown.
[0103] Figure 3 shows an exemplary process plant 1. The process plant 1 can be, for example, a chemical plant, a power plant, a food processing plant, or the like.
[0104] The process plant 1 comprises a process controller 3, a safety controller 5, a diagnostic box 7, and a plurality of field devices 9. The field devices 9 can be used to adjust a process fluid flow in the process plant 1. The field devices 9 can be control valves, for example. The process plant 1 also has a plurality of sensors for acquiring measurement data. The sensors can either be directly assigned to a field device 9, such as sensor 11 in Figure 3, or acquire data independently of the individual field devices 9, such as sensor 13 in Figure 3.
[0105] The process controller 3 is used to control the process plant 1 and includes, for example, an engineering system 15, a controller 17, and an asset management system 19. The process controller 3 is connected to the diagnostic box 7 via a line 21. The line 21 can be used simultaneously to provide power or current and for data transmission. In other words, the line 21 allows the simultaneous transmission of multiple signals. In particular, the line 21 is an Ethernet APL line. An APL power switch 23 is interposed between the process controller 3 and the diagnostic box 7, which serves to provide power.
[0106] The safety controller 5 is part of a safety circuit that includes the safety controller 5 and all devices of the process control system 1. The safety controller 5 is capable of controlling the devices independently of the process control system 3. The safety controller 5 is also connected to the diagnostic box 7 via a cable 25, which can also be an Ethernet-APL cable. The process control system 3 and the safety controller 5 form higher-level systems for controlling and / or regulating the process control system 1. The diagnostic box 7 can also be connected to a cloud (not shown in Figure 3), which can then also be a higher-level system of the process control system 1 and / or via which access to the recorded data and / or the system control system 3 can be possible.
[0107] In the embodiment shown in Figure 3, the field devices 9 are arranged in three clusters 27, 29, 31, each having a plurality of field devices 9. Data transmission is possible between the field devices 9 of a cluster 27, 29, 31; in other words, the field devices 9 of a cluster are connected to one another via a communications network. Furthermore, in the embodiment shown in Figure 3, data transmission between the clusters 27, 29, 31 and the diagnostic box 7 is possible. For this purpose, the field devices 9 are connected to one another and to the diagnostic box 7 by means of spur data lines 33, which are preferably Ethernet APL lines. In order to collectively connect the lines 33 of the individual field devices 9 to the diagnostic box 7, an APL switch 35 for merging the lines 33 is arranged between each cluster 27, 29, 31 and the diagnostic box 7.
[0108] The cables 33 also provide electrical shielding, ensuring that no explosive energy is generated, but rather that the energy reliably remains below an explosive level. This allows the field devices 9 and the APL switches 35 to be used in potentially explosive areas of Zones 1 and 2. In Figure 3, the field device cluster 29 is located in Zone 1, indicated by reference numeral 37, and the field device cluster 31 is located in Zone 2, indicated by reference numeral 39.
[0109] A connection between the field device clusters 27, 29, 31 and the process controller 3 and / or a connection between the field device clusters 27, 29, 31 and the safety controller 5 is also possible via an additional parallel line. In Figure 1, for example, the field device cluster 27 is connected directly to the process controller 3 via a line 41 and an APL switch 35, so that the process controller 3 is also directly connected to the field device cluster 27 in parallel to the connection via the diagnostic box 7. Similarly, the field device cluster 27 in Figure 1 is also directly connected to the safety controller 5 via an additional line 43, although no additional APL switch is provided; instead, the line 43 connects the safety controller 5 to the APL switch 35, which is provided between the field device cluster 27 and the diagnostic box 7.It should be understood that, alternatively, line 43 can also have an additional APL switch, and that, alternatively, line 41 can also be connected to the APL switch 35 between the field device cluster 27 and the diagnostic box 7. It should also be understood that additional lines can also be provided for the other field device clusters 29, 31, connecting the respective field device cluster 29, 31 directly to the process controller 3 and / or the safety controller 5, as exemplified by line 45 between the safety controller 5 and the other field device clusters 29, 31.
[0110] The features disclosed in the above description, the figures and the claims may be important both individually and in any combination for the realization of the invention in the various embodiments.
[0111] List of reference symbols
[0112] 1 process plant
[0113] 2 control valve system
[0114] 3 Process control
[0115] 5 Safety control
[0116] 6 positioners
[0117] 7 Diagnostic box
[0118] 8 computing unit
[0119] 9 Control valve io Valve element ii Sensor
[0120] 12 Drive
[0121] 13 Sensor
[0122] 14 Valve rod
[0123] 15 Engineering System
[0124] 16 Enclosure
[0125] 17 Control
[0126] 18 valve body housing
[0127] 19 Management System
[0128] 20 valve rod housing
[0129] 21 Line
[0130] 22 drive housing
[0131] 23 APL power switch
[0132] 24 attachments
[0133] 25 Line
[0134] 27 clusters
[0135] 28 valve body housing
[0136] 29 clusters
[0137] 31 clusters
[0138] 33 Line
[0139] 35 APL Switch
[0140] 36 field device
[0141] 37 Zone 1
[0142] 39 Zone 2
[0143] 40 control valve
[0144] 41, 43, 45 line
Claims
Claims 1. A method for reducing downtimes when updating individually executable software packages for controlling and / or monitoring a field device, in particular a control valve and / or an accessory device for a control valve, of a process plant, comprising the following steps: a) announcing an impending update of at least one of the software packages; b) categorizing the update depending on defined conditions; c) determining the time of the update and / or bridging functions to be executed during the update depending on the categorization.
2. The method according to claim 1, wherein in step b) updates of software packages whose function is defined as the primary function of the field device, in particular control valve and / or accessory device, and / or the process plant, are categorized as function-critical updates, wherein in particular updates that do not fulfill this condition are categorized as function-non-critical updates.
3. Method according to claim 2, wherein functions for controlling the control valve position, for providing safety functions, in particular the reaction to a spontaneous pressure loss in the control valve, and / or for communication of the field device with a safety controller and / or a process control system are defined as a primary function, and / or wherein functions relating to a user interface and / or diagnostic functions are not defined as a primary function.
4. The method according to claim 2 or 3, wherein in step c) for updates categorized as non-functionally critical, a time for the update is determined at which computing capacities required for the update are not needed for updates categorized as functionally critical.
5. The method according to any one of claims 1 to 4, wherein in step b) updates of software packages whose function is defined as being compensable during the update are categorized as non-failure-critical, wherein in particular updates that do not satisfy this condition are categorized as failure-critical updates.
6. The method according to claim 5, wherein functions which can be taken over at least partially, in particular in the form of a rudimentary basic function or a control routine, or completely, in particular by a second software package with the same function, during an update are defined as compensable, wherein preferably functions defined as primary functions of the field device, in particular according to one of claims 2 to 4, can be taken over at least partially or completely during an update.
7. The method according to claim 5 or 6, wherein in step c) for updates categorized as non-failure-critical, bridging functions are initiated before the update is carried out to compensate for the function affected by the update during the update is carried out.
8. The method according to claim 7, wherein the bridging functions are selected from the complete takeover of the affected function during the update, in particular by a second software package, which is preferably stored on a second computing unit, in particular within the control valve, another field device of the process plant or a diagnostic box, the partial compensation by an autonomous control routine during the update, which is provided in particular by a second software package, which is preferably stored on a second computing unit, in particular within the control valve, another field device of the process plant or a diagnostic box, and / or the partial compensation by a rudimentary basic function during the update,in particular, wherein, when updating a software package for controlling the control valve position of the control valve, a setpoint for maintaining the control valve position is maintained, in particular by a process control system.
9. The method according to claim 7 or 8, wherein after the update the function is again taken over by the updated software package.
10. The method according to any one of claims 5 to 9, wherein in step c) for updates categorized as non-failure-critical, a time for the update is determined at which computing capacity required for the update is not needed for updates categorized as failure-critical.
11. Method according to one of claims 2 to 4 and according to one of claims 5 to 9, wherein in step c) for components categorised as non-functional and as failure-critical Updates specify a time for the update at which the computing capacity required for the update is not needed for updates categorized as function-critical and non-failure-critical.
12. Method according to one of claims 2 to 4 and according to one of claims 7 to 11, wherein in step c) for updates categorized as function-critical and as non-failure-critical, a time for the update is determined at which sufficient computing capacity is available for the update and for the bridging function.
13. Method according to one of the preceding claims, wherein in step c), in particular for updates categorized as failure-critical in a method according to one of claims 5 to 12, the time of the update is determined as a function of a current or future planned operation of the control valve and / or the process plant, wherein in particular a process-non-critical time is determined.
14. The method according to claim 13, wherein the time is determined as a function of a control signal of the process control system, a state of the computing unit and / or a state of the safety controller.
15. Method according to one of claims 13 to 14, wherein in step c) the time of the update is set in a time window in which no changes to the control valve position are planned, in particular wherein in the case of updates to software packages which relate to the control of the control valve position, one of the bridging functions according to one of claims 7 to 9 is carried out in step c).
16. Method according to one of the preceding claims, wherein in step b) updates which are announced as a result of a cause defined as urgent are categorised as time-critical updates, wherein in particular updates which do not fulfil this condition are categorised as non-time-critical updates.
17. The method according to claim 14, wherein the failure or malfunction of a function defined as a primary function and / or security gaps with regard to external access to the control valve, to other field devices of the process plant or to the entire process plant are defined as an urgent cause, and wherein in particular the adjustment of control parameters or the failure of functions not defined as a primary function are not defined as an urgent cause.
18. The method according to claim 16 or 17, wherein in step c) for updates categorized as time-non-critical, a time for the update is determined at which computing capacity required for the update is not needed for updates categorized as time-critical.
19. Method according to one of the preceding claims, wherein for updates categorised as both function-critical and / or time-critical and also as failure-critical, a decision is made in step c) by means of an algorithm based on weighting factors as to whether a downtime of the field device and / or the process plant is accepted in favour of a timely update, or whether the update is postponed to a time, in particular according to one of claims 13 to 15, at which the update can be carried out without, with lesser or during a planned downtime.
20. Method according to one of the preceding claims, wherein the field device, in particular control valve, is brought into a safety position, in particular a closed position, in step c) before carrying out an update categorized as failure-critical and / or as function-critical.
21. Method according to one of the preceding claims, wherein updates in step c) are blocked if they would lead to excessive utilization of computing capacity.
22. Method according to one of the preceding claims, wherein the software packages are distributed across a plurality of computing units and / or devices, in particular field devices, add-on devices, a diagnostic box and / or higher-level systems, of the process plant, which are preferably connected to one another via Ethernet, in particular Ethernet APL, and / or a switch, in particular APL Switch.
23. Method according to one of the preceding claims, wherein in order to determine the time of the update in step c), coordination takes place between devices of the process plant, in particular wherein the time of the updates of a software package of a first device is dependent on an upcoming maintenance or update on a second device and / or wherein software packages of several devices, in particular for communication between the devices, are carried out simultaneously for all devices, in particular of a node or system.
24. Method according to one of the preceding claims, wherein when carrying out a bridging function by means of a control routine, in particular according to claim 8, in Step c) the control routine is communicated to other devices, in particular devices in the respective part of the process plant, and / or they take the control routine into account in their behavior.
25. Field device system (2), in particular a control valve system, for adjusting a process fluid flow of a process plant (1), such as a chemical plant, a power plant, a food processing plant, or the like, comprising: - at least one individually executable software package for controlling and / or monitoring a field device, in particular a control valve (9); and - at least one computing unit (8) which is designed, upon announcement of an impending update of a software package, to categorize the update depending on defined conditions and, depending on the categorization, to execute a time of the update and / or bridging functions to be executed during the update, in particular according to the method according to one of claims 1 to 24.
26. Instruction set comprising commands which, when the instruction set is executed by a field device (3), an attachment (23, 27) for a field device, a field device system (1), in particular according to claim 25, or a process plant, cause the latter to carry out the method according to one of claims 1 to 24.