Method and device for optimizing the robustness of a digital twin

EP4689812A1Pending Publication Date: 2026-02-11SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
EP2024718090
Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-05-12
Filing Date
2024-04-03
Publication Date
2026-02-11

AI Technical Summary

Technical Problem

Existing digital twins of drive systems lack robustness assessment, which is crucial for risk evaluation and cost estimation during design and operation, as their project planning is inadequately defined in terms of resilience and requires separate securing processes.

Method used

A computer-aided method optimizes the digital twin's robustness by simulating disturbances and their effects using a behavior model and environment model, generating simulation data to determine expected effects and guide user actions, thereby enhancing resilience and reducing error scenarios and calculation time.

Benefits of technology

The method significantly improves the robustness of digital twins by quantifying the impact of disturbances, allowing for proactive measures to mitigate risks and reduce maintenance costs, leading to a more comprehensive assessment of system reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024058986_21112024_PF_FP_ABST
    Figure EP2024058986_21112024_PF_FP_ABST
Patent Text Reader

Abstract

Optimizing the robustness of a system twin (101), wherein the system twin (101) comprises a behaviour model (104) which describes both an undisrupted behaviour of the system (102) and a behaviour of the system (102) that can be expected under the influence of one or more predefined disruptions (105, 107, 108), wherein a model of an environment (113) is provided in the method, wherein the system (102) is designed to interact with the environment (113) in such a manner that the environment (113) supplies at least one input signal (106) to the system (102) and receives at least one output signal (109) from the system (102), wherein the system (102) forms, together with the environment (113), an overall system (115), the system twin (101) and the environment model (114) are combined to form an overall model (116), the overall model (116) is executed at least twice in order to obtain simulation data (119), wherein the overall model (116) is used in an undisrupted state when executed for a first time and at least one disruption (105, 107, 108) of the system (102) is also simulated when the overall model (116) is executed for a second time in order to simulate the behaviour of the overall system (115) under the influence of the disruption (105, 107, 108) acting on the system (102), simulation data (119) are analysed in order to determine an expected effect (121) of the at least one disruption (105, 107, 108) on the overall system (115) from a comparison of data determined when the overall model (116) is executed for a first time with data determined when the overall model (116) is executed for a second time, at least one action is determined on the basis of the expected effect (121) and is communicated to a user.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Method and device for optimizing a digital twin with regard to its robustness

[0003] The present disclosure relates to a computer-aided method, a device and a computer program product in which an already existing digital twin of a drive system is optimized with regard to its robustness and using such a digital twin for designing a drive system.

[0004] During the design phase and during operation of a system, the question arises of examining the robustness of this system and the objects it contains. The goal of such an investigation is to assess the risk and the associated costs.

[0005] The classic design of a complex system is usually insufficiently defined in terms of robustness and must be secured in a separate process.

[0006] To counter this problem, a computer-aided method of the type mentioned above is proposed, in which a digital twin of a system - a system twin - is optimized with regard to its robustness and thus becomes more resilient, in particular more resistant or robust. The system twin comprises a behavior model which describes both undisturbed behavior and behavior of the system which is to be expected under the influence of one or more predefined disturbances. The disturbances preferably occur with a certain probability in the real production cycle and can be simulated, for example, by applying a disturbance variable, a disturbance function in the system twin, deactivating a component in the system twin because it fails and breaks down in the real production cycle, etc. The method provides a model of an environment - an environment model.The system is designed to interact with the environment in such a way that the environment feeds at least one input signal (preferably all input signals) to the system and receives at least one output signal (preferably all input signals) from the system, the system and the environment together forming an overall system. The system twin and the environment model are linked (for example in a simulation tool) to form an overall model - a model of the overall system. The overall model is executed at least twice to obtain simulation data, with the overall model being used in an undisturbed state during a first execution and at least one disturbance (disturbance behavior / reaction of the real system, behavior to an internal and / or external disturbance) of the system being simulated during a second execution of the overall model in order to simulate the behavior of the overall system under the influence of the disturbance acting on the system.The simulation data is analyzed to determine the expected effect of at least one disturbance on the overall system by comparing the data obtained during the first execution of the overall model with the data obtained during the second execution of the overall model. Subsequently, depending on the expected effect, at least one action is determined and communicated to a user.

[0007] In the context of the present disclosure, simulation is understood to mean the execution of a model in a specific configuration and parameterization. One or more simulations with the same model but with different configurations and / or parameterizations form a simulation set.

[0008] In summary, a ruggedizing process for a digital twin is disclosed, in which the resilience, in particular the robustness of the digital twin with regard to disturbances known from the real production cycle and occurring with a certain frequency in the production cycle, is increased.

[0009] In one embodiment, it can be provided that, when determining the at least one action, a situation is determined based on the expected effect of the at least one disturbance on the overall system, and an assessment of the situation is carried out. Preferably, a risk-based assessment of the situation is performed in the overall model in order to reduce the number of relevant error scenarios and the calculation time based on the determined risk. For example, the dangerousness of the resulting overall situation can be used for the assessment.

[0010] In one embodiment, a third simulation sequence may be provided, through which the expected effect is quantified.

[0011] In one embodiment, it may be provided that at least one action is evaluated with respect to predefined parameters. It may be useful to communicate the result of this evaluation to the user. The parameters may include costs, effort, risks associated with failing to perform the action, and so on.

[0012] In one embodiment, it may be provided that two or more disturbances of the system are simulated in order to simulate the behavior of the overall system under the influence of the two or more disturbances acting on the system and to obtain simulation data for several disturbance scenarios.

[0013] It may be useful to determine the expected impact for each disruption scenario and to identify at least one action for one or more of the expected impacts and communicate this to the user. Thus, one action can affect multiple disruption scenarios simultaneously.

[0014] In one embodiment, it can be provided that the at least one action is validated on the overall model, for example the action is implemented in the overall model and the overall model is simulated at least twice - without and with disturbance(s), it being understood that the disturbance(s) is (are) the same that was (were) simulated when determining the at least one action. The expected effect determined in this way can preferably be evaluated, for example on a risk-based basis. The actions can also be ranked according to various parameters, such as cost, effort, efficiency and so on.

[0015] Each disturbance or disturbance scenario may be a disturbance of the following three disturbance types or, in the case of a disturbance scenario, may include a combination of the disturbances of these disturbance types:

[0016] - disturbance on an input or input signal (also results from a disturbance in the environment model, also noise);

[0017] - disturbance as a separate "non-functional" input (e.g. radiation, temperature);

[0018] - Fault as a separate logical input (a component fails).

[0019] In one embodiment, it may be intended that the expected effect includes one or more errors within the overall system—that is, that the disturbance(s) lead to one or more errors. In this case, one can speak of error scenarios.

[0020] In one embodiment, the action may include changing the behavioral model of the system twin in such a way that the expected effect is reduced. Changing the behavioral model may include one or more remedial measures to reduce the expected disruptive effect or disruptive influence.

[0021] Preferably, the expected effect can be reduced by at least partial compensation or by at least partial balancing of the influence of the disturbance(s) or by eliminating one or more errors.

[0022] When considering the implementation of a specific compensation measure, one of the following factors or a combination of them can be considered: risk assessment of impact, costs, and probability. A risk assessment is preferably based on one or more factors, e.g., probability, consequences, costs of mitigation, or even remediation.

[0023] For example, a possible compensation could include a monitor that detects the failure of an element of the twin and, in response, switches to a more robust state in which "nothing bad happens."

[0024] If, for example, the disturbance causes subsequent disturbances, the system twin preferably simulates the disturbance itself but also its consequences - a disturbance cascade.

[0025] In other words, the system twin is enriched with data generated using a disturbance simulation, thereby extending the system twin with robustness aspects relevant to the application scenario (environment).

[0026] The quality of a statement about the robustness of a complex system is made higher and more comprehensive by the proposed .

[0027] The system is preferably a drive system. A drive system preferably comprises an electronic control unit, for example a converter, in particular a frequency converter. In particular, the system is designed as a control unit, for example as a converter, in particular as a frequency converter.

[0028] DC applications, for example, are considered as an environment. The environment can include one or a combination of (large) meshed DC links, battery applications, DC switches, and fuses.

[0029] In one embodiment, it can be provided that the drive system additionally comprises an electric rotary machine, preferably an electric motor, for example an asynchronous motor.

[0030] The electronic control unit can be connected to the electric rotating machine in order to supply it with current and voltage with certain adjustable characteristics (amplitude, frequency, etc.) and thus, for example, to reduce or increase its torque to the required level in order to meet the requirements of the application.

[0031] Such drive systems can, for example, drive the axes of a machine tool or a robot arm, pumps (hydraulic drive), conveyor belts, etc., which is why they are often referred to as drives or drive trains.

[0032] A digital twin of a system is essentially a virtual representation of the real system, which can preferably be updated using data from various data sources, such as historical data, measurement data, etc. A digital twin can initially be created from static data (nameplates, catalog information, manufacturer data sheets and / or characteristic curves, etc.) and then updated, for example, during operation. A digital twin created from the static data can be used particularly in the design phase.

[0033] In other words, a digital twin is a replica of a physical object of a physical system in software, which in particular replicates an input-output behavior and / or the internal function (e.g. by means of a transfer function) and enables internal parameters (e.g. switching speed, max. frequency) of the system to be adapted without having to make changes to the real system.

[0034] It is useful if a digital twin can be updated in real time, e.g. during operation, using sensor data provided by the sensors assigned to the system.

[0035] The historical data may include, for example, operating data, design drawings and models, maintenance histories and other information collected over the lifetime of the drive system.

[0036] The digital twin can provide a variety of functions, such as monitoring, simulating, and predicting system performance and health. It can also serve as a digital model for optimizing maintenance processes and improving performance. Furthermore, it can help reduce downtime and maintenance costs by detecting potential problems early and recommending appropriate actions. It can also improve system efficiency by suggesting optimal operating conditions and monitoring performance over time.

[0037] Overall, a digital twin of the system offers a powerful opportunity to optimize the performance and efficiency of the drive system while reducing maintenance costs. In particular, a digital twin can enable failure experiments and / or physical design improvements without experimenting on the real system.

[0038] In particular, the digital twin of a system is understood within the context of this disclosure to be a simulation model of the system. Such a simulation model can, for example, be in the form of an FMU model (EMU = Functional Mock-up Unit). The simulation model can be modular, with each module of the simulation model describing a specific domain of the drive system (thermal, electrical, etc.).

[0039] The FMUs can be linked together via so-called Functional Mock-up Interfaces, or FMIs for short. FMI is a standard interface for exchanging model-based simulations between different simulation tools and environments. In other words, the FMU is a manifestation of the FMI standard.

[0040] The system twin and the environment model can also be designed as modules of the overall model, which can be implemented, for example, as software, and linked within this overall model. The link can be configured, for example, via a user interface of the overall model. The system twin and the environment model do not have to be designed as independently manageable components, such as FMUs. The link therefore does not have to comply with the FMI standard.

[0041] FMI defines a standardized data format for model-based simulations, which can be based on XML and binary files, for example. It enables the exchange of model components and their connections between different simulation environments and tools. It enables the creation of complex systems from different components and models that can be embedded in different simulation environments and tools. In one embodiment, it can be provided that, based on the changed behavior model, at least one corresponding change to the system is proposed and preferably implemented. It may be appropriate to conduct a risk analysis before adopting a proposed change.

[0042] In one embodiment, it can be provided that, if the expected effect comprises one or more errors within the overall system, at least one solution is determined within the system twin, wherein the at least one solution at least reduces and preferably partially compensates or balances the one or more errors.

[0043] In one embodiment, it can be provided that the overall model is changed in such a way that it includes the environment model and the system twin with the changed behavior model, the changed overall model is executed, wherein the (same) disturbance of the system is also simulated when the changed overall model is executed, and the changed simulation results obtained thereby are validated on the overall system.

[0044] It may be useful to perform a ranking of the changes made to the behavior model of the system twin during validation.

[0045] Preferably, the ranking includes a weighting with regard to the efficiency of the change or the remedial measure taken and / or the effort required to implement the change to the system and / or the costs of implementing the change to the system.

[0046] In one embodiment, it may be provided that the system twin has fault inputs corresponding to the predefined faults. In one embodiment, it may be provided that, when analyzing the simulation data, a risk-based assessment of a situation expected due to the expected effect of at least one fault on the overall system is performed and, for example, reported to a user.

[0047] This can be done based on the safety-relevant parameters and / or the expected state of the overall system or similar.

[0048] Preferably, the evaluation comprises an assessment of the dangerousness or criticality of the situation to be expected due to the expected effect of the at least one disturbance on the overall system.

[0049] In one embodiment, it can be provided that a simulation of the entire system in an undisturbed state is used when analyzing the simulation data. The real system in the environment is simulated both in the undisturbed state and under the influence of at least one disturbance. The results of the simulation of the system without disturbance are compared with the results of the simulation of the system under the influence of the disturbance and analyzed.

[0050] In one embodiment, it may be provided that two or more disturbances are simulated in order to simulate the behavior of the overall system under the influence of the two or more disturbances acting on the system and to obtain simulation data.

[0051] The disturbances can be of different or the same type, or can occur according to different or the same disturbance mechanisms. This means, for example, that two disturbances can be simulated in which two components fail, or two different disturbances are applied to the input signal. These are different disturbance scenarios that can be simulated in the overall model.In one embodiment, the method comprises a simulation of the undisturbed overall model, a simulation of the overall model taking into account one or more disturbances - singly or k-fold perturbed simulation, where k is the number of simulated disturbances, where each disturbance can be assigned to a specific disturbance mechanism, a subsequent preferably risk-based assessment of the expected effect of the disturbance(s), a proposal of one or more remedial measures which, for example, affect the behavioral model, where the number of remedial measures can be smaller than the number of disturbances, a simulation of the overall model taking into account the disturbance(s) and the remedial measure(s), an assessment of the remedial measure(s), where a justification for the remedial measure(s), preferably with an indication of a weighting (according to cost, effort...), can be generated, for example by the user.

[0052] If a change is made to the behavior model, the user is preferably informed that there is now a more robust digital twin and that corresponding changes should be made to the real drive system.

[0053] In summary, the method disclosed here enables, among other things, to map errors in the objects themselves and thus to create a system twin that is fully - i.e. in each of its components - centered on robustness aspects.

[0054] On the basis of these findings, design decisions (dimensioning of objects, safety factors) as well as monitoring and error control algorithms can be developed or measures (redundancy...) can be derived.

[0055] The invention is explained in more detail below using exemplary embodiments. FIG. 1 shows a device 100 for developing a digital twin.

[0056] The reference symbols used in the figures are intended solely to improve readability and are not to be interpreted as limiting. The same reference symbols in different figures designate essentially the same elements or objects.

[0057] FIG 1 shows a device 100 for optimizing and further developing a digital twin 101 of a (real) drive 102 - a drive twin - and illustrates a computer-aided method for optimizing the drive twin 101 and further developing it based on the optimization carried out.

[0058] In an advantageous embodiment, the drive twin 101 and preferably each of its components and / or models (mechanical, thermal, electrical model, etc.), which may be designed as modules of a software program, can be configurable with regard to their level of detail.

[0059] Such a device 100 and such a method can be used, for example, during a design phase or a configuration of the drive 102, in which the robustness of the drive 102 or its configuration and the objects contained therein are examined. The goal of such an examination can, for example, be to estimate the risk and the associated costs and to determine load limits and / or breaking points of components of the drive 102.

[0060] The device 100 comprises a computing system 103, which can be configured, for example, as one or more distributed computing units or platforms (not shown here). For example, the computing system 103 can be configured as a cloud. In principle, such a computing system comprises operatively coupled means for carrying out the necessary steps of the method presented here, such as databases, memories, processors, data lines, etc.

[0061] The drive twin 101 is stored in the device 100. The drive twin 101 includes a behavior model 104 that describes both an undisturbed behavior and a behavior of the drive 102 that is to be expected under the influence of one or more predefined disturbances that occur with a non-negligible probability during operation of the drive 102.

[0062] A disturbance can occur, for example, as a disturbance 105 on the input signal 106 and / or as an internal disturbance 107 and / or as an external disturbance 108.

[0063] The disturbance is defined in that it is preferably directly measurable. In other words, in the context of the present disclosure, known disturbances are generally considered.

[0064] The internal faults 107 include, for example, errors that can occur in a real component of the drive 102 (short circuit, shaft breakage, solder joint problems, failing semiconductors that impair the input-output transfer function and are not visible from the outside).

[0065] External stimuli of the drive 102 may also be faulty during operation (e.g. setpoint and / or ambient temperature is outside the valid range; security breaches, if e.g. the input signal has been compromised, have occurred) and the response to this can be investigated.

[0066] The disturbances 105 at the input signal 106 can include, for example, noise. Disturbances of this type are visible at the output signal 109. Alternatively or additionally, disturbances can also include disturbances on a side channel (radiation, vibration on the housing).

[0067] In other words, the drive twin 101 makes it possible to simulate one of the aforementioned faults 105, 107, 108 or a combination thereof. This simulation can consist, for example, in one or more fault functions 110, 111 being switched on, or in a component of the drive twin 101 (which corresponds to a real component of the drive 102) being deleted or deactivated 112 because this corresponds to a failure of the real component. This can be, for example, partial or complete failures in a motor, in an encoder, in the sensors, in the power electronics. Specifically, the behavior model 104 can be used to simulate, for example, an IGBT failure (IGBT stands for Insulated-Gate Bipolar Transistor), which occurs with an associated probability depending on load cycles ("cycle counter").

[0068] In summary, three disturbance mechanisms or a combination of them can be simulated in the drive twin 101:

[0069] - disturbance on an input (also results from a disturbance of the environment model, also noise);

[0070] - disturbance as a separate "non-functional" input (e.g. radiation, temperature);

[0071] - Fault as a separate logical input (component fails).

[0072] Therefore, it may be provided that the entire drive twin 101 and / or one or more of its components are provided with failure probabilities. The failure probabilities are usually independent static parameters and not a time-dependent input.

[0073] Using failure probabilities, it is possible, for example, to achieve a result equivalent to an EMEA (e.g., assessment of the weak points and criticality of a system's components). Furthermore, it can be provided that disturbance transfer functions are additionally mapped in the drive twin.

[0074] Furthermore, a model of an environment 113—an environment model 114—in which the drive 102 is or would be used is stored in the computing system 103. In other words, the environment 113 corresponds to the application scenario of the drive 102.

[0075] The drive 102 is thus designed to interact with the environment such that the environment 113 supplies at least one, preferably all, input signals 106 to the drive 102 and receives at least one, preferably all, output signals 109 from the drive 102. Together with the environment 113, the drive 102 thus forms an overall system 115.

[0076] The environment 113 of the drive 102 can be configured in different ways. For example, the environment 113 can be configured as a large meshed DC network, in which, for example, a DC link can short-circuit or a fuse can blow.

[0077] Furthermore, the environment 113 can be configured as a higher-level controller of the drive 102 and can include one or more programmable logic controllers (PLCs). For example, in the manner described below, the control design within the drive 102 can be improved in terms of its robustness with the aid of the drive twin 101.

[0078] The drive twin 101 can, for example, be designed as an EMU.

[0079] For the fault simulation 110, 111, 112, fault inputs can be provided in the drive twin 101. Each fault input corresponds to one of the faults 110, 111, 112. In other words, interfaces can be provided in the drive twin 101 to trigger potential fault events contained in the drive twin 101. Parameters corresponding to the fault inputs / interfaces, and preferably also their tolerances, can be set via fault inputs / interfaces.

[0080] If the drive twin 101 comprises multiple models, each model can have its own interfaces. When multiple models are coupled / aggregated to form a larger drive twin 101, the external interfaces (of the models) automatically become internal interfaces via which the propagation of the corresponding fault 105, 107, 108 and / or the subsequent fault can be simulated. The type of external interface defines from the outset which fault can and should be simulated or which faults can and should be injected, in order to support the user in determining which scenarios should expediently be taken into account in the fault simulation.

[0081] To support the user, the drive twin 101 can also have an API (English for Application Programming Interfaces or in German: programming interface).

[0082] For example, the API can be designed in such a way that it can include surrounding systems in the calculation of the failure probability (and its intermediate results).

[0083] In a practical version, the drive twin 101 is equipped with an algorithm that enables the determination of the failure probability and all associated intermediate results (component load, lifetime consumption, ...).

[0084] The drive twin 101 and the environment model 114 are linked, for example, in a simulation tool included in the computing system 103 to form an overall model 116—a model of the overall system 115. The overall model 116 is then executed (by the computing system 103) to simulate the behavior of the overall system 115. The computing system 103 can also be designed such that the overall model 116 is divided or calculated in parallel (see EMI Spec: Distributed co-simulation infrastructure). Simulation input signals 117 are specified, and simulation output signals 118 are observed and analyzed.

[0085] In addition, when executing the overall model 116, at least one disturbance 105, 107, 108 of the drive 102 is simulated in order to simulate the behavior of the overall system 115 under the influence of the disturbance 105, 107, 108 acting on the drive 102 and to obtain simulation data.

[0086] In other words, the disturbance behavior of the real overall system 115 is investigated.

[0087] In order to examine the reaction of the real overall system 115 to one or more predetermined disturbances 105, 107, 108, the simulation input signals 117 of the drive twin 101 can be subjected to a disturbance function 110, the external disturbance functions 111 can be triggered, the internal disturbance functions 112 can be triggered, or any combination of these disturbance simulations can be activated - this leads to a comprehensive investigation of the possible disturbances.

[0088] For this purpose, one or more of the aforementioned disturbance inputs of the drive twin 101 can be used.

[0089] During the simulation, simulation data 119 are generated. These data 119 are subsequently analyzed 120 to determine an expected effect 121 of the disturbance 105, 107, 108 on the overall system 115.

[0090] In this case, detailed analysis data on the effective path 121 of the simulated fault 122 can be derived from the simulation data 119. In other words, the effect 121 is determined along the path along which the fault propagates and can include both individual faults in components and subsequent faults in other components or in the drive twin 101. In other words, in simulation, a fault cascade i), ii), iii) which includes several faults and subsequent faults can be investigated. In this case, the analysis data on the effective path 121 can enable an estimation of fault interactions, subsequent faults, or fault cascades.

[0091] Thus, troubleshooting in the field can be supported with the help of the (same) drive twin 101. Faults from the field (due to faults 105, 107, 108) are simulated with the drive twin 101 (by applying the simulated faults 110, 111, 112). This can be used to determine whether field experience matches the simulation behavior of the drive twin 101. For example, an assignment of the faults to the database with probabilities and / or replacement of components can be suggested using KL.

[0092] The error states and mechanisms to be included can be identified, for example, using one or more of the standards, empirical values, over-dimensioning, safety factors and FMEA, which can be present in a data memory of the computing system 103.

[0093] Because the drive twin 101 can have one or more fault inputs, error states in the drive twin 101 (and in its individual components) can be controlled separately.

[0094] When analyzing the simulation data 119, an assessment can be made regarding the dangerousness or criticality of a situation that is to be expected due to the expected effect 121 of the disturbance 105, 107, 108 on the overall system 115. This can be done based on the safety-relevant parameters and / or the expected state of the overall system 115, or similar. The result of the assessment can, for example, be reported to a user.

[0095] In other words, the simulation data 119 are examined for dangerous errors, dangerous scenarios and also measures to avoid such scenarios are identified.

[0096] For example, when analyzing the simulation data 119, a simulation of the entire system 115 in an undisturbed state can be used. The drive 102 is simulated in the environment 113 both in the undisturbed state and under the influence of the disturbance 105, 107, 108. The results of the simulation of the drive 102 without disturbance are compared with the results of the simulation of the drive under the influence of the disturbance 105, 107, 108 and analyzed.

[0097] This can be done, for example, as part of post-processing and / or feature extraction of the simulation data. This can be used to check, for example, whether an output of drive twin 101 has reached its limit and whether this caused, for example, a critical error.

[0098] The danger or criticality of the fault circuit can be determined by means of several simulation runs.

[0099] During each run, different fault scenarios 123 can be simulated. A fault scenario is defined as a specific simulated fault 110, 111, 112 or a specific combination of the simulated faults 110, 111, 112.

[0100] For example, with three described failure mechanisms, there can be n failure scenarios 123, where n depends on ni, where ni is the number of possible failures of the i-th mechanism, e.g., the number of components that can fail. If two components fail, this is a double failure of the failure mechanism "failure", etc. Each simulated failure 122 (selected from n failure scenarios 123) can cause a fault condition. In this respect, the introduction of a failure 110, 111, 112 can be referred to as fault injection.

[0101] Drive Twin 101 can have different levels of detail regarding error states, so that not all interfaces / parameters have to be accessed externally. The selected model in Drive Twin 101 can, for example, be communicated to the user via the API, which can be provided as an alternative to FMI.

[0102] For example, it is possible that different data is available during the design process than during the operating phase (for example, current or voltage harmonics above half the sampling rate of the current or voltage sensors cannot be identified during operation without a separate measuring system (Shannon's theorem), but can be identified during the design phase). If necessary, parts of the drive twin 101 can be used to infer fault-relevant variables (virtual sensor for disturbance transfer function).

[0103] It can be provided that selected error states of subcomponents of one of the drive twin 101 influence each other and allow a detailing of a subsystem even without targeted selection from outside in order to be able to determine subsequent errors.

[0104] The drive twin 101 is preferably designed so that, depending on the problem, the level of detail of the subcomponents can be selected automatically, or so that the manually specified level of detail of a subcomponent influences its neighboring components, thereby ensuring consistency with regard to the accuracy of the representation of a fault. By "trying out" various fault scenarios 123, knowledge about the faults' causal pathways 121 and thus about the possible fault mechanisms is generated and stored, for example, in a memory 124 provided for this purpose.

[0105] If a fault scenario 123 results in a failure, it is a failure scenario.

[0106] Based on the determined, expected effect 121 of the at least one disturbance 105, 107, 108 on the overall system 115, or on the generated knowledge about the disturbance mechanisms, one or more measures or modi fi cations are determined which can be carried out within the drive twin 101 and make it possible to at least partially compensate for the expected effect 121.

[0107] For example, in the case of an internal error 107, which includes the failure of an internal component of the drive 102 and is simulated by deletion or deactivation at runtime 112 of a corresponding component in the drive twin 101, the modification can provide a monitoring mechanism which detects the failure of the component and transfers the drive twin 101 to a more robust state in which the effect 121 is at least partially compensated, for example no output of the drive twin 101 goes to the stop.

[0108] In an advantageous embodiment, if the expected effect 121 comprises one or more errors within the overall model 116, the computing system 103 determines a solution within the drive twin 101 based on the simulation data 119 and in particular based on the detailed analysis data 121 for the effective path, wherein the one solution transfers the overall model 116 (or its simulation) to a safer state, for example by at least partially compensating for the one or more errors, in particular in such a way that one or more subsequent errors are avoided or their dangerousness or criticality is reduced. Accordingly, the behavior model 104 of the drive twin 101 can be adapted 125 by such a measure or with such a modification.

[0109] In other words, the modification may aim to reduce the consequences of a simulated disturbance 110, 111, 112, or a simulated disturbance scenario 123 and thus avoid subsequent disturbances.

[0110] A solution or solution scenario may affect one or more of the disruption scenarios 123.

[0111] For example, for n fault scenarios, 123 m solution scenarios can be determined, and m < n. The solution scenarios can include one or a combination of the following measures: compensation of the expected effect, transition to a safe state, emergency shutdown, adjustment of maintenance intervals, etc.

[0112] These m solution alternatives can then be tested, with a score of 130 being introduced during the verification of the solution alternatives if the corresponding solution appears to be sufficiently effective. Evaluation factors such as cost-relatedness, greater security, feasibility, etc., can be considered.

[0113] In scoring 130, for example, a solution scenario can be assigned a metric that quantifies its robustness. This can be done, for example, based on a distance measure to the undisturbed signal and characterize the suppression of the disturbance, etc.

[0114] Preferably, a single (optimal) solution is transferred or validated into the real system.

[0115] In particular, the measure can consist of reducing the danger of the situation arising in the selected disruption scenario. The modification can be transferred to the drive twin 101. This results in a drive twin 126 with a modified behavior model 127 that is improved in terms of its robustness compared to the known disruption scenarios mentioned above.

[0116] The modified drive twin 126 is more robust than the drive twin 101.

[0117] The modified drive twin 126 can, for example, be stored in the memory 124.

[0118] In a useful embodiment of the device 100, the computing system 103 proposes a change to the drive 102 based on the modified drive twin 126 and in particular on the modified behavior model 127 128.

[0119] The determined measure can then be verified on the overall system 115. For this purpose, the overall model 116 is modified by including the (old) environment model 114 and the modified drive twin 126. The computing system 103 then executes the modified overall model, simulating the (same) fault in the drive 102 that led to the aforementioned modification of the drive twin 101. The obtained simulation results are validated on the overall system 129.

[0120] The device 100 described above can thus also be used to test the drive 102 in the environment 113.

[0121] The knowledge 124 about various disturbance mechanisms obtained in the simulation described above and solutions derived from this knowledge 124 can be used to modify the drive 102.

[0122] This is particularly important when designing the drive

[0123] 102 is useful for this purpose. The aforementioned simulation tool in the computing system 103 can be a component of a design tool or can be designed as a design tool.

[0124] It is understood that the simulation design tool may interact with the memory 124 and with other components of the computing system 103 not shown here for simplicity in a conventional manner.

[0125] In summary, the methods and systems disclosed here are aimed in particular at determining design and / or control-related (e.g. limitation of rise times, controller factors, limiters, etc.) and / or monitoring-related interventions in the event of failure of the drive system 102, or in other words at error analysis and control in the drive system 102. In this case, reactions are defined which are implemented in the event of failure of the drive system 102 in order to avoid fatal errors, with the advantage that these reactions can initially be simulated in the drive twin 101. Examples of this are: if a sensor signal is missing, then a support brake is applied, adjustment of a service interval, e.g. in the event of premature failure, or similar.

[0126] The purpose of this description is merely to provide illustrative examples and to indicate further advantages and special features of this invention. Thus, it cannot be interpreted as a limitation of the field of application of the invention or of the patent rights claimed in the claims. In particular, the features disclosed in connection with the methods described herein can be usefully used to further develop the systems described herein, and vice versa.

Claims

Patent claims 1. Computer-aided method for optimizing a digital twin of a system (102) - a system twin (101) - with regard to its robustness, wherein the system twin (101) comprises a behavior model (104) which represents both an undisturbed behavior and a behavior of the system (102) which is to be expected under the influence of one or more predefined disturbances (105, 107, 108), wherein in the method a model of an environment (113) - an environment model (114) - is provided, wherein the system (102) is designed to interact with the environment (113) in such a way that the environment (113) supplies at least one input signal (106) to the system (102) and receives at least one output signal (109) from the system (102), wherein the system (102) together with the environment (113) form an overall system (115), the system twin (101) and the environment model (114) are linked to form an overall model (116) - a model of the overall system - the overall model (116) is executed at least twice to obtain simulation data (119), wherein in a first execution the overall model (116) is in a undisturbed state is used and in a second execution of the overall model (116) at least one disturbance (105, 107,108) of the system (102) is also simulated in order to simulate the behavior of the entire system (115) under the influence of the disturbance (105, 107, 108) acting on the system (102), Simulation data (119) are analyzed in order to determine an expected effect (121) of the at least one disturbance (105, 107, 108) on the overall system (115) from a comparison of data determined during the first execution of the overall model (116) with data determined during the second execution of the overall model (116), depending on the expected effect (121) at least one action is determined and communicated to a user.

2. Method according to claim 1, wherein in determining the at least one action a by the expected effect (121) the situation expected to have at least one disturbance (105, 107, 108) on the overall system (115) is determined and a risk-based assessment of the situation is carried out, for example.

3. Method according to claim 1 or 2, wherein the at least one action is evaluated with regard to predeterminable parameters.

4. The method according to any one of claims 1 to 3, wherein two or more disturbances (105, 107, 108) of the system (102) are also simulated in order to simulate the behavior of the overall system (115) under the influence of the two or more disturbances (105, 107, 108) acting on the system (102) and to obtain simulation data (119) for a plurality of disturbance scenarios.

5. The method according to claim 4, wherein the expected effect (121) is determined for each disturbance scenario, wherein at least one action for one or more of the expected effects (121) is determined and communicated to the user.

6. The method according to any one of claims 1 to 5, wherein the action comprises changing the behavior model (114) of the system twin (101) in such a way that the expected effect (121) is reduced.

7. The method according to claim 6, wherein based on the changed behavior model (127) at least one corresponding change to the system (102) is proposed.

8. The method according to claim 6 or 7, wherein the overall model (116) is modified to include the environment model (114) and the system twin (126) with the modified behavior model (127), the modified overall model is executed, wherein the disturbance of the system is also simulated (110, 111, 112) when the modified overall model is executed, and modified simulation results obtained thereby are validated on the overall system (129).

9. The method according to claim 8, wherein during validation a ranking of the behavior model (114) of the system twin (101) is implemented.

10. The method according to claim 9, wherein the ranking comprises a weighting with respect to an efficiency of the change and / or the effort of implementing the change to the system (102) and / or the cost of implementing the change to the system (102).

11. Method according to one of claims 1 to 10, wherein the system twin is provided with disturbance inputs corresponding to the predefined disturbances.

12. Method for designing at least one drive system (102), wherein a digital twin of the drive system - a drive twin (101) is optimized according to a method according to one of claims 1 to 11 and the drive system (102) is designed according to the optimized drive twin (126).

13. Device for optimizing a digital twin of a system (102) - a system twin (101) - with regard to its robustness, wherein the device (100) comprises the system (102), an environment (113) of the system (102) and a computing system (103), wherein the computing system (103) is designed and configured to carry out a method according to one of claims 1 to 11.

14. A computer program product for a device according to claim 13, wherein the computer program product comprises instructions which, when executed by a computing system (103) of the device (101) are carried out, causing the device (101) to carry out the method according to one of claims 1 to 11 or 12.