Method and arrangement for performing a software update in a system formed from a plurality of entities, in particular machines and / or devices, in particular in the industrial environment

EP4732134A1Pending Publication Date: 2026-04-29SIEMENS AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
SIEMENS AG
Filing Date
2024-07-03
Publication Date
2026-04-29

AI Technical Summary

Technical Problem

Software updates in complex industrial systems with multiple devices often require significant downtime and effort due to dependencies between devices, leading to high costs and inefficiencies, as existing methods typically update devices only when the production system is stopped.

Method used

A procedure for coordinated software updates that considers local installation parameters and entity-specific variables, allowing for interruption-free updates by activating software updates at optimal times, with synchronization and activation managed through a central entity using protocols like Precision Timing Protocol (PTP) to ensure minimal disruption and efficient system-wide activation.

Benefits of technology

Enables seamless software updates without interrupting production, reducing overall downtime and costs by allowing individual entity updates, optimizing update duration, and ensuring accurate system-wide activation, while minimizing the risk of failed installations through feedback mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024068747_06022025_PF_FP_ABST
    Figure EP2024068747_06022025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for performing a software update in a system formed from a plurality of entities, in particular machines and / or devices, in particular in the industrial environment, in which a software update is distributed to the entities and the software update is locally installed on the entities in a manner coordinated with one another in terms of time such that the respective local software updates are at least started, run and / or activated in a system-wide manner on the basis of at least one parameter correlated with at least the particular entity at times individually assigned to the entities. The invention further relates to an arrangement for carrying out the method.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Method and arrangement for carrying out a software update in a system formed by several entities, in particular machines and / or devices, in particular in an industrial environment

[0003] The invention relates to a method for carrying out a software update in a system formed from a plurality of entities, in particular machines and / or devices, in particular in an industrial environment, according to the preamble of claim 1, and to an arrangement for carrying out a software update in a system formed from a plurality of entities, in particular machines and / or devices, in an industrial environment according to the preamble of claim 13.

[0004] It is known that software updates, i.e. the installation and commissioning of software upgrades and software updates (used synonymously within the scope of this disclosure), of complex systems consisting of multiple devices or machines, for example in an industrial environment, represent a greater challenge than would be the case with simple systems consisting of one or a few devices. This is due, among other things, to the fact that in a networked production unit, as found in an industrial environment, there are always dependencies between the devices due to their interactions during the manufacturing process, and in particular more general dependencies, for example as to whether and how these devices communicate with one another.

[0005] As a rule, a new software version contains either bug fixes and / or enhancements, which very often do not only relate to one device, but affect an entire group of devices.

[0006] If devices in an industrial environment are sequentially updated with a new software version, the entire system or production usually has to be completely shut down. This is especially the case if the new software version results in changes in the interaction with the environment or other (production) devices.

[0007] Since this is essentially the norm, there is the disadvantage that, according to the current state of the art, it is common practice to update the relevant devices only when operations are at a standstill, for example, when the production plant is at a standstill. This involves considerable effort, can take a long time, and incur high costs.

[0008] The object underlying the invention is therefore to provide a technical solution with which the disadvantage of the prior art is overcome, in particular the object of the invention is to provide a technical solution in which software updates can be carried out largely without interruption during ongoing processes in the industrial environment.

[0009] Method for carrying out a software update in a system formed from several entities, in particular machines and / or devices, in an industrial environment, based on the features according to the preamble of claim 1, by its features and by the arrangement based on the features of the preamble of claim 11, by its characterizing features.

[0010] In the method for carrying out a software update in a system formed from several entities, in particular machines and / or devices, in particular in an industrial environment, a software update is distributed to the entities and the software update is installed locally on the entities in a time-coordinated manner such that at least the start, execution and / or system-wide activation of the respective local software updates takes place as a function of at least one parameter correlating with at least the respective entity at times individually assigned to the entities.

[0011] The invention enables uninterrupted installation of software updates or upgrades, particularly in industrial environments, by allowing the start, execution, and / or system-wide activation to be carried out at an optimal time for each entity individually. This is because the correlating parameters of the respective local installations can be taken into account in such a way that no disruption causing an interruption is necessary. Based on this consideration, further optimizations are also possible. For example, the total time until system-wide activation can be shortened.

[0012] The arrangement for carrying out a software update in a system formed from several entities, in particular machines and / or devices, in particular in an industrial environment, is characterized by means for carrying out the method and / or one of its further developments.

[0013] The arrangement according to the invention enables the implementation of the method according to the invention and / or its further developments and thus mutatis mutandis also the realization of the advantages of the method and / or its further developments.

[0014] Advantageous embodiments and further developments of the invention are specified in the subclaims.

[0015] According to a development of the method according to the invention, at least one entity-related variable influencing process times, such as latency, switching time, effects on the entity of the embedding in the overall system, device type, success of the software update and other, in particular time-critical, variables, is taken into account as a correlating parameter for the coordination. By taking one or more entity-related variables into account, the invention can also incorporate individual characteristics of the entities into the coordination that brings about the optimization and, in doing so, can take into account both dynamic physical variables, i.e. physical variables that change during operation, and / or fixed variables, such as those that can be given by the type, mode of operation, operating parameters such as physical properties of the operating environment, and / or settings of the device or machine.The failure of an installation on the entity can be at least time-critical, even leading to a total blockage due to the failure of the system-wide update. This can also be addressed with this training because, for example, system-wide activation is only carried out after confirmation of success has been received and / or the specification of individual activation times for coordinating / orchestrating the activation process only occurs after such confirmation has been received. A previously negative response can, for example, be followed by a positive response after an error procedure has been executed.

[0016] Alternatively or preferably additionally, the method according to the invention can be developed in such a way that at least one system-related variable influencing process times, such as system utilization, system dimension, system complexity, system components and other variables, in particular those with a time-critical impact, is taken into account as a correlating parameter for the coordination. This enables a holistic approach which takes into account the mutual interaction of the entities in a system and its consequences, so that by incorporating one or more of the physical influencing variables existing through the system into the coordination, optimization is further improved. Both dynamic and fixed physical variables can also be used here.

[0017] The method according to the invention is preferably further developed in such a way that the at least one variable influencing process times is provided, in particular, by a central entity, retrievable by manual input and / or automated recording. This ensures that the method according to the invention always makes current values ​​available for optimization, which can supplement or replace the basic possibility of correlating parameters predefined once for each entity for the method.

[0018] As a rule, a system, particularly one used in an industrial environment, contains one or more control devices, for example entities that provide a controlling and / or master function in the sense of a master / slave functionality for the other entities of the system. Therefore, the development of the method according to the invention such that a control device functionally connected to the system, in particular integrated in the control device of the system, is operated as the central point, is a possibility for implementing the method according to the invention in a simple manner while largely avoiding changes to known structures in the system.

[0019] One of the values ​​for tuning that is particularly suitable for optimization is achieved when the method according to the invention is further developed such that, for tuning purposes, the central location synchronizes the local time of the entities to a value, in particular within a maximum deviation of + / - 100 ns. This can include one or several actions, in particular periodically repeated actions, that bring about the synchronization, so that synchronization is always guaranteed.

[0020] The effect of this value on the optimization is further improved if the method according to the invention is developed in such a way that the entities are operated for the coordination in such a way that their time base, known as the "clock", is guaranteed with a system-adapted accuracy, in particular in the range of 1 ppm to 10 ppm, in particular by operating suitable hardware. System-adapted accuracy means that this development can vary depending on the type of system, which can differ, for example, depending on the area of ​​use / application. Guaranteeing means that the accurate compliance with the value is to be achieved, and the value is specified as an individual target value for each system.This enables flexible use of the invention, for example in power plants, in industrial environments and / or uses with a seismic aspect, such as raw material extraction in the upstream sector, such as oil production or mining. An application with a seismic aspect will, for example, generally require an accuracy in the range of 1ppm, whereas for use in an industrial environment, for example, the invention could generally be implemented with a lower accuracy, for example in the range of 100 ppm. In the “range of” here means that the value of the accuracy according to the invention, which is sufficient, is ultimately determined by the correlating parameter and / or the system adaptability. The range limits or their values ​​should therefore not be seen as hard limits and the actually implemented value can certainly exceed or exceed the limits, particularly taking into account the hardware used.However, for the actual values ​​lying within the stated range, particularly in the stated applications, optimal results can be expected when using the invention.

[0021] A further advantageous development of the method according to the invention is provided if an absolute time, in particular a "Global Positioning System" time, GPS time, and / or an absolute time specified by highly accurate, in particular satellite-based, time reference systems, as well as the local time, are transmitted to the entities for synchronization at least once. As a result, the devices are enabled, at one or, in particular, periodically repeating, times, to always have a basis for at least partially individual implementation times within the scope of the start, expiration and / or system-wide activation, which basis ensures a time delta between the entities at a minimum value, in particular "zero".

[0022] An implementation particularly suitable for implementing the invention is achieved when the method according to the invention is operated in such a way that the system, in particular the entities, are operated for coordination according to the so-called "Precision Timing Protocol" (PTP), specified in particular according to IEEE 1588-2008. This protocol offers a series of functionalities that the invention can use to implement its method. These functionalities are also tried and tested, easy to implement, and have a low level of complexity. Therefore, existing hardware can be converted to carry out the method according to the invention by suitable modifications of, for example, driver software. There is also inexpensive hardware available, in the form of an Ethernet PHY chip, which already uses this protocol and which can be used in the arrangements according to the invention or which implements them.

[0023] Freedom from disruption can be achieved in particular if the method according to the invention is further developed in such a way that a) a software update is distributed to the entities forming the system, b) the entities store the respective software update locally on the entities, c) a time for the local implementation of the software update on the entity is specified for each entity, d) a synchronization of the respective local time of the entities is brought about, e) the installation of the local software updates takes place on the basis of the time specification until the software update is completed for all entities that have saved the software update, f) a system-wide activation of the software updated by the software update takes place at individually specified times after completion of all locally implemented software updates.This ensures that the new software is used simultaneously on all entities, taking into account latencies, which are compensated according to the invention by the individual points in time with regard to any interference, etc.

[0024] "After completion" here means that the installations on the respective device have been successfully completed. This means that the individual activation times within the framework of the system-wide activation are advantageously available after completion, i.e. only when this condition is met, so that uncontrolled states of the overall system due to individual failed installations are avoided. This can, for example, be implemented in such a way that the planning of individual times only takes place after completion and / or implemented in such a way that the system-wide update at pre-distributed individual activation times is only started after confirmation of the completion of the installation and / or is suspended until success has been confirmed.

[0025] In particular, this development makes the multi-stage nature of the method according to the invention clear, which can be seen in the fact that

[0026] • an early installation of the new software version is possible, especially during the run of the old version and especially alongside the previous SW version, for example, to have enough time to collect data and build up states according to the new software without being able to influence expenses / environment, and

[0027] • enables activation or transfer of control, for example over the output / control, to the new software version at a precisely defined and, if necessary, device-specific time of the coordinated system-wide switchover (activation) and still allows coordinated interaction of the devices during the switchover.

[0028] This approach ensures that the new version can take over control reliably, seamlessly and without any significant interruption.

[0029] Alternatively or additionally, the method according to the invention can be further developed such that the entities are operated in such a way that, until the time of a system-wide activation of the updated software on the entities that have completed the installation of the software update, the updated software is put into operation in such a way that parallel operation of the updated software and the previous software version on the entity is decoupled in such a way that the actually detectable mode of operation, in particular states and functions, of the entity is determined by the previous software version during the time of parallel operation and by the updated software after commissioning. This can improve the aforementioned compensation even further, since the new software basically runs but, according to the invention, is operated in a type of sandbox so that it has no external effect.The switchover can thus be carried out practically immediately and seamlessly for the respective entity as well as the system.

[0030] An advantageous development of the method according to the invention is provided in that the activation, in particular triggered by the control device upon completion of all locally performed software updates, is triggered on the entities by sending a message, upon reaching the predetermined start time and / or a time that can at least be derived from the sequence of events of the entities. In this way, the switching can be carried out in a controlled manner and contributes to optimization. Further advantages and details of the invention are explained based on the exemplary embodiments of the invention shown or indicated in the single FIGURE.

[0031] FIGURE schematically shows an embodiment of the method according to the invention, which is explained together with the features of an embodiment of the arrangement according to the invention.

[0032] The exemplary embodiments explained below in the FIGURE are preferred embodiments and developments of the invention.

[0033] In the embodiments, the described components of the embodiments each represent individual features of the invention that are to be considered independently of one another, which also further develop the invention independently of one another and are therefore to be regarded as part of the invention, either individually or in a combination other than that shown.

[0034] Furthermore, the described embodiments can also be supplemented by further features of the invention already described.

[0035] The FIGURE schematically illustrates an exemplary embodiment of the method according to the invention in the form of a flowchart. The sequence of the method according to the invention requires an arrangement designed according to the invention, so that, for an understanding of the exemplary embodiment of the invention, features of an exemplary embodiment are explained in advance and together with the method features.

[0036] According to the exemplary embodiment of the arrangement according to the invention, all machines, i.e. all devices, of a system in which a software update carried out according to the invention is to be possible, have, among other things, the features specified below.

[0037] For example, according to the exemplary embodiment of the arrangement, the devices involved have a mechanism for upgrading / updating during operation.

[0038] This can be implemented, for example, in the form of a "seamless upgrade" pattern, which enables parallel execution of the old and new versions and controlled switching between them with a known latency. This can be done using the existing controllers or processors, so that it acts like a module providing the aforementioned functionalities (parallel execution, coordinated switching) or represents a variant thereof.

[0039] Since processors / controllers will usually be present in such a system, it can also be brought into the system as a computer program product and executed in a controlled manner.

[0040] As a further feature of the exemplary embodiment of the arrangement according to the invention, the time value is set equal or predetermined on all machines. "Equal" means, within the scope of the invention, or in systems that have runtimes and latencies, that even the smallest deviations are permissible as a tolerance. For example, according to the exemplary embodiment of the invention, the time on all devices is synchronized with a deviation of approximately + / - 100 ns.

[0041] The embodiment of the invention provides that all devices support the PTP (Precision Timing Protocol, IEEE 1588-2008), which according to the embodiment is supplied with an exact time by a central instance using a precise clock, the so-called GPS and a "miniature atomic clock", MAC. The DTP has the advantage that, in contrast to the well-known NTP (Network Timing Protocol), it takes the runtimes in the network (Internet) into account and is able to take different signal runtimes into account.

[0042] According to the embodiment of the inventive method, each machine uses the PTP protocol on the one hand by carrying out the method steps according to this or based on the protocol, i.e. as implemented software, but on the other hand is also based on a platform that supports this hardware (example: Ethernet Phy: "Broadcom BCM5421").

[0043] With the embodiments of the method according to the invention and the embodiments of the arrangement according to the invention that support PTP on the software and hardware side, the invention can enable the transmission and coordination of precise time information between different devices, in particular in a network such as that formed in an industrial environment, in a simple and efficient manner and can thereby use one or more functionalities of the PTP, such as time stamping, delay compensation, periodic updating and measures to ensure accurate precision and compensation.

[0044] Time stamping can be achieved by the central device periodically generating timing messages, which can be configured as so-called sync and follow-up frames, which are sent to the devices. These frames contain time stamps that reflect the time of transmission, thus providing a reference value at regular intervals.

[0045] This can be implemented, for example, using the PTP protocol in conjunction with a Linux driver, and must then be incorporated into an application on the entities. Delay compensation can be implemented in such a way that the devices that receive the timing messages from the central instance via timestamps calculate the transmission delays and compensate accordingly to achieve more precise synchronization.

[0046] This is done, for example, at the hardware level, in particular the so-called physical layer, for example by the PHY chip.

[0047] According to the PTP, it is possible to determine the central instance. For example, the device with the most accurate internal clock can be selected as the central location, either alternatively or additionally. Particularly in industrial environments, the use of an immutable instance, such as an existing control device, will have advantageous effects, for example, because it can be implemented into the existing structure in a less complex and / or effort-minimizing manner.

[0048] For accurate accuracy and compensation, the PTP can also use algorithms to calculate the accuracy of the devices' internal clocks and to compensate for interfering factors, such as network delays and jitter, to achieve more precise synchronization.

[0049] The PTP protocol - as a further development of the invention - enables periodic updates of the synchronization information, which have the advantage of compensating for deviations in the internal clocks of the nodes and ensuring continuous accuracy.

[0050] Hardware support, which could be advantageously used as a further development of the arrangement according to the invention in the exemplary embodiment, would be provided, for example, by the use of the "Ethernet PHY Broadcom BCM5421", which is located, for example, on the "Raspberry, Compute Module 4 Platform, "CM4". Alternatively or additionally, a so-called AS IC, for example, can also be used as suitable hardware for this purpose, which is merely modified as supporting hardware with driver software implementing the method according to the invention.

[0051] In addition to the synchronization of the devices, the embodiment of the arrangement according to the invention also realizes a time accuracy required for carrying out the method according to the invention.

[0052] According to the exemplary embodiment, the local time of the devices (i.e., the clock) is provided with sufficient accuracy, which in the exemplary embodiment is approximately 10 Oppm. Based on experience at the time of invention, this generally ensures in an industrial environment that no significant time drift can occur, even during a lengthy upgrade. In other words, any possible downtime of the DTP protocol is appropriately measured or taken into account.

[0053] In other applications of the inventions, other accuracy values ​​may be used.

[0054] However, the invention is not limited to this. If the devices have a local time base accuracy of approximately 1 Oppm, for example, in a so-called "temperature-compensated oscillator," sufficient accuracy is already inherent in the system, so that individual or all of the refinements to accuracy mentioned in the disclosure can be omitted or alternatively designed, and fall within the scope of the invention, insofar as they are covered by the scope of the claims.

[0055] According to a further development of the invention, the system adaptability has the effect that the value depends on the application, i.e. on variables given by the system which are also given by the correlating parameter or determine it, and / or the demands on the system due to the specific application. In the seismic industry, the Glocks used have an accuracy of 1ppm in a temperature range of -40 ° C to 80 ° C. According to experience at the time of the invention, values ​​in the range of 1ppm are not necessary for most industrial plants, but one can of course still specify a more precise value in order to make the method particularly robust.

[0056] The invention ensures that the switching times at which the respective device in the system switches to the new software version are known and / or coordinated for all participating devices to enable a coordinated switchover. This can be determined, for example, by system tests before specifying the times.

[0057] In a first embodiment of the invention, however, this can also be achieved relatively easily, particularly for simple systems, for example by switching all devices simultaneously. Alternatively or additionally, the invention can also be further developed such that the switching is based on knowledge of the overall system, its processes, its communication patterns, and its components, in particular partially offset in time.

[0058] The invention, in particular the exemplary embodiments explained, can be further developed in such a way that this knowledge is provided manually or, if necessary, also determined automatically.

[0059] The invention, in particular the exemplary embodiments and further developments presented, enable a coordinated and synchronous upgrade (or update) of all devices or machines involved, which can be centrally controlled and initiated, whereby "synchronous" means that the upgrade takes place at coordinated times, which are partially time-shifted depending on the correlating parameter.

[0060] The simplified, schematically illustrated simple embodiment of the method according to the invention can be implemented in such a way that, starting from a first state ZI in which a system with multiple entities, i.e., devices or machines on which software is running, is in operation, a first step S1 detects that a software update is present. The terms "update" and "upgrade" in the document always mean the other, and vice versa, even if not explicitly mentioned. The same applies to "machine(s)" and "device(s).

[0061] This can be achieved, for example, by actively querying system parameters, as shown in the FIGURE, or by triggering signals directly. If, upon detection in the first step S1, it is determined that a software update is present, according to an exemplary embodiment of the method according to the invention, the software update is distributed to the devices in a second step and is stored locally by each device. Software updates are understood to mean the data required for installation on a device, such as an executable file and / or other data required as part of an update, in particular data organized as files.

[0062] Such data can be, for example, configuration parameters, such as for programmable hardware, for example a so-called "field-programmable gate array", compiled code, so-called "source-interpreting" code, for example Python code, images and / or other data with which the function of the device can be updated. In the first state ZI, based on the functions of the FTP, as already explained, synchronization and a local time of the devices are set in such a way that the illustrated embodiment for exactly coordinated time setting of at least the devices for which an update / upgrade is being considered is ensured. The measures provided for this purpose, preferably in accordance with PTP, are thus carried out, in particular also periodically during ongoing operation.

[0063] However, the software updates distributed in this way are not yet installed or executed.

[0064] If no software update is available, the system remains in ongoing operation without the additional steps of the exemplary embodiment, which is symbolically represented by the change to the first state ZI. Symbolically, this means that even if an update is detected, ongoing operation is maintained, i.e., the system is always in the first state, but in this state, the inventive steps are additionally performed.

[0065] In a third step S3, the central instance distributes to each machine a precise and, if necessary, individual first time for installing the update and a precise, individual second time for subsequently activating the new version. As explained above, this can be advantageously accomplished using the PTP protocol.

[0066] These times can be the same for several devices, but they can also differ depending on the device type, upgrade behavior (switching latency) and the embedding of the device in the overall system.

[0067] In a fourth step S4, activation is now initiated, for example, by the central instance, in particular through a message and / or another type of signaling. This means that the machines addressed during distribution will now begin installing the upgrade independently and at their individual first points in time and / or, in a fifth step S5, will activate the new version upon reaching the respective second points in time after the successful completion of the installation. Alternatively or additionally, it is also conceivable that at least some of the addressed devices do this without external triggering, or that one of these two stages, the installation stage and the update stage, requires a trigger. Furthermore, it is also conceivable that the central instance that carries out the distribution is a different entity in the system than the one that sets the trigger. Thus, for one or more of the second to fourth steps S2...S4 Entities particularly suited or specialised to carry out the task act as a central authority.

[0068] The installation times simply have to be before the activation times, and the respective installations must have been successfully completed. By specifying the second time, the new version is given sufficient time to start, for example, to establish or adopt its own state. This multi-stage approach, provided by individual installation and the possibility of precisely timed individual activation, supports the inventive software update during ongoing operation in a particularly effective way.

[0069] With the procedure described, in particular the suspension of the activation switching until optimal individual times in the fifth step S5, it can be ensured that the behavior of all devices, for example all processes, functions, features and also non-functional properties, is always compatible, since the system according to the invention is orchestrated in such a way that the installed software update is operated on the respective device, in particular in parallel with the old software version, that its behavior for other devices is still in accordance with the old software version and only when the predetermined inventive, in particular individually different, times are reached, does this appear different, i.e. from these times onwards the behavior according to the updated software also becomes visible for the other devices.

[0070] The invention can also be further developed in such a way that changes which have an impact on other devices, in particular non-addressed devices, can be taken into account accordingly with this further development.

[0071] As a further step (not shown), feedback can be provided after successful installation / start, either alternatively or in addition, so that if individual installations fail, the update can be suspended until the problem is resolved. It is also conceivable to further develop the invention so that the second time points are precisely determined only after the successful completion of all installations, taking into account the correlating parameters, and are planned and specified individually for each device.

[0072] The feedback allows for reaction to error conditions and for these to be rectified before activation using an error correction procedure.

[0073] One of the main advantages of the invention is the possibility of distributing coordinated upgrades to several devices (of the same or different types) during operation.

[0074] According to an advantageous embodiment of the exemplary embodiment, the above-mentioned central clock or time generator distributes the GPS time, i.e., the absolute time, and the relative time via the MAC using the PTP protocol with an accuracy of approximately + / - 100 ns. The invention also takes into account that, depending on the runtime, it can take several minutes for all devices to be synchronized. Implementing this distributed and coordinated upgrade according to the exemplary embodiments ensures that the switching times of all devices are precisely coordinated.

[0075] This ensures that the new software versions start operating at the right time, but not necessarily at the same time as described in the example, and that the behavior of all devices in the overall system during and after the switchover is correct and coordinated with one another.

[0076] A further advantage of the invention and all of its further developments and combinations falling within the scope of the claims is that this method makes it possible to minimize the frequency of complete system or plant downtimes, since the simplified and cost-effective update / upgrade process according to the invention, on the other hand, enables more frequent updates during ongoing operation.

[0077] The aforementioned advantage has a further advantageous side effect: simultaneous installation and switching between software versions also minimizes critical time periods during which power interruptions or other incidents, particularly those caused by partial or full power-on and power-offs, could lead to the upgrade failing. Without appropriate precautions, such as support for automatic version rollbacks, the devices involved could be rendered completely unusable. However, as a further development, the aforementioned rollback can nevertheless advantageously complement the invention and thus counteract unforeseen conditions and their negative consequences.

[0078] To the extent that expressions have been used above which indicate, imply or can be perceived as a grammatical gender and / or other characteristics suitable for distinguishing people, it is understood that these expressions have not been used in a divisive but inclusive manner, i.e. that all people - regardless of given, self-assumed or presumed individual characteristics - are considered to be of equal value.

Claims

Patent claims 1. A method for carrying out a software update in a system formed from a plurality of entities, in particular machines and / or devices, in particular in an industrial environment, characterized in that a software update is distributed to the entities and the software update is installed locally on the entities in a time-coordinated manner such that at least the start, execution and / or system-wide activation of the respective local software updates takes place as a function of at least one parameter correlating with at least the respective entity at times individually assigned to the entities.

2. Method according to the preceding claim, characterized in that at least one entity-related variable influencing process times, such as latency time, switching time, effects on the entity of the embedding in the overall system, device type, success of the installation of the software update and other variables having a particularly time-critical effect, is taken into account for the coordination as a correlating parameter.

3. Method according to one of the two preceding claims, characterized in that at least one system-related variable influencing process times, such as system utilization, system dimension, system complexity, system components and other variables having a particularly time-critical effect, is taken into account as a correlating parameter for the coordination. 4 . Method according to one of the two preceding claims, characterized in that the at least one variable influencing process times is provided, in particular by a central entity, retrievable by manual input and / or automated recording.

5. Method according to the preceding claim, characterized in that a control device which is functionally connected to the system, in particular integrated in the control device of the system, is operated as the central point.

6. Method according to one of the preceding claims, characterized in that for the coordination by the central point a synchronization of the local time of the entities to a value, in particular in the range of + / - 100ns maximum deviation, is brought about.

7. Method according to one of the preceding claims, characterized in that for the coordination the entities are operated in such a way that their time base, known as the so-called "clock", is ensured with a system-adapted accuracy, in particular in the range of 1 ppm to 10 ppm.

8. Method according to one of the two preceding claims, characterized in that an absolute time, in particular a "Global Positioning System" time, GPS time and / or an absolute time specified by highly accurate, in particular satellite-based, time reference systems, as well as the local time, is transmitted to the entities for synchronization at least once.

9. Method according to one of the preceding claims, characterized in that for the coordination the system, in particular the entities, are operated according to the so-called "Precision Timing Protocol", PTP, specified in particular according to IEEE 1588-2008.

10. Method according to one of the preceding claims, characterized in that a) a software update is distributed to the entities forming the system, b) the entities store the respective software updates locally on the entities, c) a time is specified for each entity for the local implementation of the software update on the entity, d) the synchronization of the respective local time of the entities is brought about, e) the installation of the local software updates takes place on the basis of the specified time until the software update is completed for all entities that have saved the software update, f) a system-wide activation of the software updated by the software update takes place at individually specified times after completion of all locally implemented software updates.

11. Method according to one of the preceding claims, characterized in that the entities are operated in such a way that, up to the time of a system-wide activation of the updated software, on the entities which have completed the installation of the software update, the updated software is put into operation in such a way that parallel operation of the updated software and the previous software version on the entity is decoupled in such a way that the actually detectable mode of operation, in particular states and functions, of the entity is determined by the previous software version during the time of parallel operation and by the updated software after commissioning.

12. Method according to one of the preceding claims, characterized in that the activation, in particular triggered by the control device upon completion of all locally carried out software updates, is triggered on the entities by sending a message, by reaching the predetermined start time and / or a time that can at least be derived from the expiration of the entities. 13 . Arrangement for carrying out a software update in a system consisting of several entities, in particular machines and / or devices, in particular in industrial rial environment, characterized by means for carrying out the method according to one of the preceding claims.