Multi-cluster system and method for handing over process thereby

The multi-cluster system addresses the challenge of maintaining processing continuity in control systems by implementing a redundant system architecture that allows seamless handover of processing between gateways and application devices, ensuring low additional costs and high availability even when an existing control base becomes unusable.

JP2025088314APending Publication Date: 2025-06-11HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023202941
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-06-11

AI Technical Summary

Technical Problem

Existing control systems face challenges in maintaining processing continuity at a low additional cost when an existing control base becomes unusable, particularly due to issues with RAFT cluster malfunction and facility interface failures.

Method used

A multi-cluster system is implemented, comprising a first cluster of gateways managing bases and a second cluster of application devices managing a business system. Each cluster forms a redundant system, allowing any gateway or application device to become the main system and ensuring seamless handover of processing when a base becomes abnormal.

Benefits of technology

This solution enables the continuation of processing at a low additional cost even when an existing control base becomes unusable, by ensuring that the system can dynamically switch to alternative nodes within the clusters, maintaining system availability and determinism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025088314000001_ABST
    Figure 2025088314000001_ABST
Patent Text Reader

Abstract

To provide a system that makes it possible to continue a process at a small additional cost even when an existing control base becomes unusable.SOLUTION: A multi-cluster system comprises: a first cluster provided with a plurality of GWs for managing a plurality of bases; and a second cluster provided with a plurality of application devices (hereinafter, referred to as "app devices") for managing a business system, the GWs and the app devices each forming a redundant system, one of the app devices serving as a primary system and outputting a control output for a control device provided in the business system to the GWs, one of the GWs serving as a primary system and transmitting the control output received from the primary app device to the control device. The first cluster checks the soundness of each of the bases and excludes the primary app device from the second cluster if the base equipped with the primary app device is abnormal. The second cluster continues the process by causing an app device other than the excluded app device to serve as a primary system.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a multi-cluster system and a method for processing handover by the system.

Background Art

[0002] As a method for achieving both improved availability and guaranteed determinism required for a control system, cluster management software such as RAFT (distributed consensus algorithm) is utilized. Here, RAFT (distributed consensus algorithm) is a technology that provides a general-purpose means for distributing state machines across an entire cluster of computing systems.

[0003] Further, Patent Document 1 discloses a data synchronization method using a plurality of tracking control devices. Specifically, when a tracking control device detects an abnormality in another tracking control device, the planned data synchronization unit of the tracking control device copies planned data other than the planned data used in the most recent control of the other tracking control device stored in the auxiliary storage device of the tracking control device to the main storage device of the tracking control device to synchronize the planned data of the other tracking control device.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] When a redundant system of a main system and a slave system is configured at an existing control site, it is desirable that the number of additional devices be minimized. For example, when a system is configured from a control center having a main system and a slave system and a single system cloud, when the control center is flooded, the system will lose a majority, and the RAFT cluster will malfunction (for example, continue processing while assuming the existence of both main systems or perform a full stop for safety).

[0006] In the technology disclosed in Patent Document 1, since the area equipped with facilities and the tracking control device are linked one-to-one, when both the tracking control device and the facility interface (facility I / F) are missing, the operation cannot continue. Further, when detecting a failure through mutual monitoring between the tracking control devices and performing handover of processing, although the tracking control devices are not communicable with each other, there remains a problem that they become the two main systems when they can communicate with the facility interface (facility I / F).

[0007] Therefore, an object of the present invention is to provide a system that enables continuation of processing at a low additional cost even when an existing control base becomes unusable.

Means for Solving the Problems

[0008] In order to solve the above problems, one of the typical multi-cluster systems according to the present invention is a multi-cluster system including a first cluster including a plurality of GWs (gateways) that manage a plurality of bases, and a second cluster including a plurality of application devices that manage a business system. The GWs and the application devices each form a redundant system. Any one of the application devices becomes the main system and outputs a control output to the control device provided in the business system to the GW. Any one of the GWs becomes the main system and transmits the control output received from the main application device to the control device. The first cluster confirms the soundness of each base, and when the base including the main application device is abnormal, excludes the application device from the second cluster. The second cluster changes the main system to an application device other than the excluded application device and continues the processing.

Effects of the Invention

[0009] According to the present invention, it is possible to provide a system that enables continuation of processing at a low additional cost even when an existing control base becomes unusable. Problems, configurations, and effects other than those described above will be clarified by the description in the following embodiments for implementation.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Embodiments for Carrying Out the Invention

[0011] Hereinafter, with reference to the drawings, examples will be described as embodiments of the present invention. Note that the present invention is not limited by these examples. Also, in the description of the drawings, the same parts are denoted by the same reference numerals.

Examples

[0012] FIG. 1 is a diagram showing an example of the configuration blocks of a traffic control system centered on a traffic control center as a system for social infrastructure. As shown in FIG. 1, the traffic control system according to an embodiment of the present invention configures a redundant system to improve availability, and includes a traffic control center 1 as a main (primary system) and a cloud (secondary control) 2 as a sub (secondary system). The traffic control center 1 and the cloud (secondary control) 2 are each connected to a control network (dashed line shown in FIG. 1) that is transparently connected via a relay station 6.

[0013] The traffic control center 1 is composed of, for example, a plurality of signal control devices (signal control device A and signal control device B in FIG. 1) 4, one or more consoles 5, one or more relay stations (relay station 1 in FIG. 1) 6, and a plurality of GWs (GW-a and GW-b in FIG. 1) 7, each connected to the control network 3. Here, the signal control device 4 corresponds to an application device (application device, hereinafter referred to as "AP device").

[0014] Further, the cloud (secondary control) 2 is composed of, for example, one or more signal control devices (signal control device C in FIG. 1) 4, one or more consoles 5, one or more relay stations (relay station 2 in FIG. 1) 6, and a FW (firewall) 16 for connecting to the Internet / closed network 13. It is assumed that clients 17 such as other prefecture traffic control centers 14 and homes 15 that perform proxy operations from outside the region are connected to the Internet / closed network 13.

[0015] Connected to the control network (dashed line shown in FIG. 1) to which a plurality of relay stations 6 are transparently connected are an urban sub-center A 11 via a relay station A 6 and an urban sub-center B 12 via a relay station B 6, respectively.

[0016] The urban sub-center A 11 includes one or more consoles 5, one or more GWs (GW-c in FIG. 1) 7, and one or more terminal corresponding control devices 9. Similarly, urban sub-center B12 includes one or more consoles 5, one or more GWs (GW-d in FIG. 1) 7, and one or more terminal corresponding control devices 9.

[0017] Here, the traffic control center 1, urban sub-center A11, and urban sub-center B12 function as bases of the traffic control system. The GWs (GW-a to GW-d) 7 included in these bases are connected via a signal network 8, and the signal network 8 is connected to intersections 10 and one or more terminal corresponding control devices 9 included in each of urban sub-center A11 and urban sub-center B12. As the terminal corresponding control device 9 in this case, a device that controls various terminals handling traffic-related data such as traffic signals is assumed.

[0018] Furthermore, the GWs (GW-a to GW-d) 7 included in these bases constitute a first cluster as a base determination cluster for confirming the soundness of the bases (shown by a dotted frame in FIG. 1) and manage the bases.

[0019] Also, the traffic control center 1 and the signal control devices (signal control devices A to C) 4 included in the cloud (second control) 2 constitute a second cluster as an app cluster for confirming the soundness of the signal control device 4 which is an AP device (app device) (shown by a dashed-dotted line frame in FIG. 1) and manage the application.

[0020] FIG. 2 is a diagram showing an example of components included in the signal control device (signal control devices A to C) 4. FIG. 3 is a diagram showing an example of components included in the GW (GW-a to GW-d) 7. Each of the signal control device (signal control devices A to C) 4 and the GW (GW-a to GW-d) 7 includes at least a diagnosis unit 18 and a storage unit 19 for storing system management information.

[0021] FIG. 4 is a diagram showing a table summarizing the installation locations, roles of clusters, master-slave roles, and states of the signal control device (signal control devices A to C) 4 and the GW (GW-a to GW-d) 7 included in the traffic control system shown in FIG. 1.

[0022] Regarding the signal control devices (signal control devices A to C) 4 that constitute the second cluster (the dashed-dotted line frame shown in FIG. 1), applications are managed as an application cluster, and a master-slave redundant system is configured. Among the two signal control devices 4 provided in the traffic control center 1, signal control device A functions as the primary (master system) of the application cluster, and signal control device B functions as the secondary (slave system) of the application cluster. Also, the signal control device C provided in the cloud (second control) 2 functions as the secondary (slave system) of the application cluster.

[0023] Also, regarding the GWs (GW-a to GW-d) 7 that constitute the first cluster (the dotted line frame shown in FIG. 1), bases are monitored as a base determination cluster, and a master-slave redundant system is configured. Among the two GWs 7 provided in the traffic control center 1, GW-a functions as the primary (master system) of the base determination cluster, and GW-b functions as the secondary (slave system) of the base determination cluster. Also, GW-c provided in the urban sub-center A11 and GW-d provided in the urban sub-center B12 function as the secondary (slave system) of the base determination cluster.

[0024] Furthermore, it is also possible for the cloud (second control) 2 to have the function of a base. In that case, the priority of the bases following the traffic control center 1 may be set among the cloud (second control) 2, the urban sub-center A11, and the urban sub-center B12, and the master-slave switching may be performed based on the height of this priority. Generally, since it is expected that the number of devices provided in the cloud (second control) 2 will be larger, the priority of the cloud (second control) 2 will be higher than that of the urban sub-center A11 and the urban sub-center B12.

[0025] Regarding the state of the devices shown in FIG. 4, it indicates whether the state of the devices is normal or abnormal. FIG. 4 shows the case where all devices are normal as the normal state.

[0026] FIG. 5 is a diagram showing a flowchart (inside the dashed line frame) of cluster processing (base determination cluster processing) by each of the GWs (GW-a to GW-d) 7 that constitute the base determination cluster which is the first cluster. The execution entity of each processing step of this cluster processing is the diagnosis unit 18 provided in each of the GWs (GW-a to GW-d) 7 shown in FIG. 3, but the description of the entity is omitted below. Note that after the cluster processing by the base determination cluster, the cluster processing (inside the double-dashed line frame) by the application cluster which is the second cluster will follow.

[0027] In step S101, failure information of each GW 7 and each signal control device 4 is acquired via the control network 3 (including the transparently connected control network).

[0028] In step S102, failure information of each GW 7 is acquired via the signal network 8. Based on the failure information acquired in the previous step, in step S103, both GWs 7 provided in the traffic control center 1 determine whether both systems (GW-a and GW-b) are faulty.

[0029] If both systems (GW-a and GW-b) are faulty (Y), in step S104, each signal control device (signal control devices A to C) 4 is notified to use the information of the GW 7 of the city sub-center, for example, the information of GW-c of the city sub-center A11 (corresponding to failure 5 in FIG. 6 described later), and the process proceeds to step S105.

[0030] If at least one system of the GW 7 is normal (N) and after step S104 is executed, in step S105, both signal control devices 4 provided in the traffic control center 1 determine whether both systems (signal control device A and signal control device B) are faulty.

[0031] When both systems (signal control device A and signal control device B) are faulty (Y), in step S106, the remaining signal control device (signal control device C) 4 is notified by the signal control devices (signal control device A and signal control device B) 4 of the traffic control center 1 to exclude them from the application cluster (related to failure 1 and failure 3 in FIG. 6 described later).

[0032] When at least one of the signal control devices 4 is normal (N) and after step S106 is executed, as the next process, it proceeds to cluster processing (application cluster processing) by the signal control device 4 (application device) that constitutes the application cluster which is the second cluster.

[0033] In this application cluster processing, for example, in the previous step S106, since the signal control devices (signal control device A and signal control device B) 4 of the traffic control center 1 are excluded from the application cluster, the signal control device (signal control device C) 4 of the cloud (second control) 2 is changed to the main system (corresponding to failure 1 and failure 3 in FIG. 6 described later).

[0034] Also, when the application cluster changes the signal control device 4 (application device) to the main system, it compares the number of signal control devices 4 provided in the bases other than the excluded base, selects the base with the largest number of signal control devices 4 within the base, and changes one of the signal control devices 4 provided in the selected base to the main system. If there are multiple bases with the largest number of signal control devices 4 within the base, the one with the larger scale of the base (for example, the number of consoles 5) may be selected.

[0035] As described above, the signal output from GW7 to the signal control device 4 (application device) was conventionally output only by the main system. In the present invention, all GW7s output signals regardless of the main system or slave system, and by changing the signal control device 4 (application device) to selectively receive these signals, seamless transfer of processing from the traffic control center 1 to the cloud (second control) 2 is enabled.

[0036] Figure 6 is a diagram showing, in a table, the states or state recognitions of both systems of GWs (GW-a and GW-b) 7 provided in traffic control center 1, GW-c of urban sub-center A11, and GW-d of urban sub-center B12, for each event of each obstacle, and the final state as a system (including some post-processing).

[0037] (1) Failure 1 <Event> Both systems of the signal control devices (signal control device A and signal control device B) 4 and both systems of GWs (GW-a and GW-b) 7 in traffic control center 1 fail · GW-a system in traffic control center 1: Failure · GW-b system in traffic control center 1: Failure · GW-c of urban sub-center A11: The signal control devices (signal control device A and signal control device B) 4 and GWs (GW-a and GW-b) 7 in traffic control center 1 detect that both systems are inoperative · GW-d of urban sub-center B12: The signal control devices (signal control device A and signal control device B) 4 and GWs (GW-a and GW-b) 7 in traffic control center 1 detect that both systems are inoperative · Final state: It is determined that traffic control center 1 has lost its base, and the signal control device C in cloud 2 is changed to the main system and the process is continued <Explanation> GW-c and GW-d that make up the first cluster (base determination cluster) determine that traffic control center 1, which is one of the bases, has lost its base due to equipment failure. Since both signal control device A and signal control device B are abnormal, the signal control device C in the cloud (second control) is changed to the main system (primary), and the process is taken over

[0038] (2) Failure 2 <Event> A single system of the signal control devices (signal control device A and signal control device B) 4 in traffic control center 1 fails (the table in Figure 6 shows the case of A system failure) · GW-a system in traffic control center 1: Detect the failure of the signal control device A system in Traffic Control Center 1. · GW-b system of Traffic Control Center 1: Detect the failure of the signal control device A system in Traffic Control Center 1. · GW-c of Urban Sub-center A11: Detect the failure of the signal control device A system in Traffic Control Center 1. · GW-d of Urban Sub-center B12: Detect the failure of the signal control device A system in Traffic Control Center 1. · Final state: Change the signal control device B system in Traffic Control Center 1 to the main system. <Explanation> Since an abnormality in the signal control device A system of Traffic Control Center 1 was detected, the signal control device B system in Traffic Control Center 1 was changed to the main system (primary) and the process was taken over.

[0039] (3) Failure 3 <Event> Both systems of the signal control devices (signal control device A and signal control device B) 4 in Traffic Control Center 1 failed · GW-a system of Traffic Control Center 1: Detect the failure of both the signal control device A system and the signal control device B system in Traffic Control Center 1. · GW-b system of Traffic Control Center 1: Detect the failure of both the signal control device A system and the signal control device B system in Traffic Control Center 1. · GW-c of Urban Sub-center A11: Detect the failure of both the signal control device A system and the signal control device B system in Traffic Control Center 1. · GW-d of Urban Sub-center B12: Detect the failure of both the signal control device A system and the signal control device B system in Traffic Control Center 1. · Final state: Change the signal control device C in Cloud 2 to the main system. <Explanation> Since abnormalities in both systems of the signal control devices (signal control device A and signal control device B) 4 in Traffic Control Center 1 were detected, the signal control device C in the cloud (secondary control) was changed to the main system (primary) and the process was taken over.

[0040] (4) Failure 4 <Event> A single system of the GWs (GW-a and GW-b) 7 at Traffic Control Center 1 fails (the table in Fig. 6 shows the case of GW-a system failure). · GW-a system of Traffic Control Center 1: Failure · GW-b system of Traffic Control Center 1: The non-communication of GW-a at Traffic Control Center 1 is detected. · GW-c of Urban Sub-center A11: The non-communication of GW-a at Traffic Control Center 1 is detected. · GW-d of Urban Sub-center B12: The non-communication of GW-a at Traffic Control Center 1 is detected. · Final state: The output of GW-b at Traffic Control Center 1 is adopted. <Explanation> Since the abnormality of GW-a at Traffic Control Center 1 is detected, the output of GW-b will be adopted from Traffic Control Center 1

[0041] (5) Failure 5 <Event> Both systems of the GWs (GW-a and GW-b) 7 at Traffic Control Center 1 fail · GW-a system of Traffic Control Center 1: Failure · GW-b system of Traffic Control Center 1: Failure · GW-c of Urban Sub-center A11: The non-communication of both GW-a system and GW-b system at Traffic Control Center 1 is detected. · GW-d of Urban Sub-center B12: The non-communication of both GW-a system and GW-b system at Traffic Control Center 1 is detected. · Final state: It is determined that Traffic Control Center 1 has lost its base, and the GW-c of Urban Sub-center A is changed to the main system and updated. <Explanation> It is determined that the traffic control center 1, which is one of the bases, has lost its base due to equipment failure by GW-c and GW-d that constitute the first cluster (base determination cluster). Since both GW-a and GW-b of the traffic control center 1 are abnormal, the GW-c of the urban sub-center A11 will be changed to the main system (primary) and the process will be taken over.

[0042] (6) Failure 6 <Event> Failure in relay station 1(6) of traffic control center 1 · GW-a system of traffic control center 1: Detect the failure of the signal control device C in cloud 2. · GW-b system of traffic control center 1: Detect the failure of the signal control device C in cloud 2. · GW-c of urban sub-center A11: Detect the failure of signal control device A system and B system of traffic control center 1. · GW-d of urban sub-center B12: Detect the failure of signal control device A system and B system of traffic control center 1. · Final state: Do nothing. The signal control device C in cloud 2 will adopt the output of GW-c of urban sub-center A11. Adopt the output. <Explanation> When relay station 1(6) of traffic control center 1 fails, cloud (secondary control) 2 cannot use signal control devices (signal control device A and signal control device B) 4 and GW (GW-a and GW-b) 7 of traffic control center 1, so the output of GW-c of urban sub-center A11 will be adopted.

[0043] (7) Failure 7 <Event> Failure in GW-c of urban sub-center A11 · GW-a system of traffic control center 1: Detect the failure of GW-c of urban sub-center A11. · GW-b system of traffic control center 1: Detect the failure of GW-c of urban sub-center A11. · GW-c of Urban Sub-center A11: Failure · GW-d of Urban Sub-center B12: Detect the failure of GW-c of Urban Sub-center A11. · Final state: Do nothing. <Explanation> In case of the failure of GW-c of Urban Sub-center A11, each remaining GW7 will detect the failure of this GW-c, but ultimately do nothing.

[0044] (8) Failure 8 <Event> Failure in Repeater 2(6) of Cloud (Secondary Control) 2 · GW-a system of Traffic Control Center 1: Detect the disconnection of Signal Control Device C of Cloud 2. · GW-b system of Traffic Control Center 1: Detect the disconnection of Signal Control Device C of Cloud 2. · GW-c of Urban Sub-center A11: Detect the disconnection of Signal Control Device C of Cloud 2. · GW-d of Urban Sub-center B12: Detect the disconnection of Signal Control Device C of Cloud 2. · Final state: Do nothing. Afterward, restart Signal Control Device C of Cloud 2 by the application cluster to do so. <Explanation> In case of the failure of Repeater 2(6) of Cloud (Secondary Control) 2, each GW (GW-a~GW-d)7 will detect the disconnection of Signal Control Device C of Cloud (Secondary Control) 2, but do nothing. However, after the event, restart Signal Control Device C of Cloud 2 to eliminate the detection of the disconnection.

[0045] (9) Failure 9 <Event> Failure in Repeater A(6) of Urban Sub-center A11 · GW-a system of Traffic Control Center 1: Detect nothing. · GW-b system of Traffic Control Center 1: Detect nothing. · GW-c of Urban Sub-center A11: All signal control devices (Series A and B of the signal control device in Traffic Control Center 1 and the signal control device C in Cloud 2 detect the disconnection of 4. · GW-d of Urban Sub-center B12: Detects nothing. · Final state: Does nothing. <Explanation> In the event of a failure of the relay station A (6) in Urban Sub-center A11, GW-c in Urban Sub-center A11 will detect the disconnection of all signal control devices (signal control devices A - C) 4, but the remaining GWs will detect nothing and ultimately do nothing.

[0046] (10) Failure 10 <Event> The transmission part of the control network 3 is disconnected · GW-a series in Traffic Control Center 1: Detects the disconnection of the signal control device C in Cloud 2. · GW-b series in Traffic Control Center 1: Detects the disconnection of the signal control device C in Cloud 2. · GW-c in Urban Sub-center A11: Detects the disconnection of the signal control device C in Cloud 2. · GW-d in Urban Sub-center B12: Detects the disconnection of the signal control device C in Cloud 2. · Final state: Does nothing. Afterward, the signal control device C in Cloud 2 is restarted by the application cluster to do so. <Explanation> In the event of a disconnection in the transmission part of the control network 3, each GW (GW-a - GW-d) 7 will detect the disconnection of the signal control device C in the cloud (second control) 2, but will do nothing. However, after the fact, the signal control device C in Cloud 2 is restarted to attempt to resolve the disconnection detection.

[0047] Next, as an example of the operating state of the system, the normal state and the abnormal state will be described. In FIGS. 7 and 8, the devices provided in the traffic control center 1, the cloud (secondary control) 2, the urban sub-center A11, the urban sub-center B12, and the intersection 10 respectively indicate whether they are primary (main system), secondary (subordinate system), or inoperable, in accordance with the display mode of the legend. Also shown are a table of device lists similar to FIG. 4 and display examples of output messages.

[0048] FIG. 7 is a diagram showing the system operation state, device list, and messages in the normal state. In the normal state, the signal control device A (4) of the traffic control center 1 is primary, and the remaining signal control device B (4) and the signal control device C (4) of the cloud (secondary control) 2 are secondary (subordinate). Also, the GW-a (7) of the traffic control center 1 is primary, and the remaining GW-b (7), GW-c (7) of the urban sub-center A11, and GW-d (7) of the urban sub-center B12 are secondary (subordinate), and all are in a normal state. Also, as an example of the output message in the normal state, "Operating normally." is displayed on, for example, the console 5.

[0049] FIG. 8 is a diagram showing the system operation state, device list, and messages in the abnormal state of base loss. In the abnormal state when the traffic control center 1, which is one of the bases, loses its base, the signal control device A (4), signal control device B (4), GW-a (7), and GW-b (7) of the traffic control center 1 become inoperable. Therefore, for the signal control device 4, the signal control device C (4) of the cloud (secondary control) 2 becomes primary (main system), and for GW7, the signal control device C (4) of the cloud (secondary control) 2 becomes primary (main system), and the GW-d (7) of the urban sub-center B12 remains secondary (subordinate). Also, as an example of the output message in the abnormal state, "The traffic control center has become inoperable. Signal control is being performed in the secondary control." is displayed on, for example, the console 5.

[0050] According to the above-described embodiments, the present invention includes at least the following aspects. <Aspect 1> A multi-cluster system including a first cluster including a plurality of GWs (gateways) that manage a plurality of bases, and a second cluster including a plurality of application devices that manage a business system, wherein the GWs and the application devices each form a redundant system, and any one of the application devices becomes the main system and outputs a control output to the GW for the control device included in the business system, and any one of the GWs becomes the main system and transmits the control output received from the main application device to the control device. The first cluster checks the soundness of each base, and when the base including the main application device becomes abnormal, excludes the application device from the second cluster. The second cluster changes the application devices other than the excluded application device to the main system and continues the process.

[0051] <Aspect 2> The multi-cluster system described in Aspect 1 above, wherein when the second cluster changes an application device to the main system, it selects a base having the largest number of application devices included in the bases other than the excluded base, and changes one of the application devices included in the selected base to the main system.

[0052] <Aspect 3> The multi-cluster system described in Aspect 1 or Aspect 2 above, wherein the GW (gateway) and the application device are connected to a control network, the GW and the control device are connected to a signal network, and the GW monitors the mutual state in two systems of the control network and the signal network.

[0053] <Aspect 4> The multi-cluster system described in any one of Aspects 1 to 3 above, wherein when all the GWs included in the base having the main system of the GW (gateway) are unavailable, the first cluster notifies the application device to use information from a communicable GW.

[0054] <Aspect 5> A multi-cluster system according to any one of the above-described Aspect 1 to Aspect 4, wherein when the main GW (gateway) of the first cluster becomes inoperative, another GW of the site having the inoperative GW or one of the GWs of a site other than the site is changed to the main system.

[0055] <Aspect 6> A multi-cluster system according to any one of the above-described Aspect 1 to Aspect 5, wherein when the second cluster detects that all GWs (gateways) are inoperative with respect to an application device, the application device is restarted.

[0056] <Aspect 7> A multi-cluster system according to any one of the above-described Aspect 1 to Aspect 6, wherein the plurality of sites are composed of a control center and a sub-center that control devices and signals related to traffic control.

[0057] <Aspect 8> A multi-cluster system according to the above-described Aspect 7, wherein each site is provided with a console, and the console outputs at least a message regarding the operating status of the system.

[0058] <Aspect 9> A method for processing handover by a multi-cluster system composed of a first cluster including a plurality of GWs (gateways) that manage a plurality of bases and a second cluster including a plurality of application devices that manage a business system, wherein the GWs and the application devices are each made redundant, and control output to a control device included in the business system is output to the GWs with one of the application devices as the main system, and the control output received from the main application device with one of the GWs as the main system is transmitted to the control device. The first cluster checks the soundness of each base, and when the base including the main application device becomes abnormal, excludes the application device from the second cluster. The second cluster changes the main system to an application device other than the excluded application device and continues the process.

[0059] <Aspect 10> A method for processing handover by a multi-cluster system according to the aspect 9 described above, wherein when the second cluster changes the main system to an application device, it selects a base having the largest number of application devices included in bases other than the excluded base, and changes one of the application devices included in the selected base to the main system.

[0060] <Aspect 11> A method for processing handover by a multi-cluster system according to the aspect 9 or the aspect 10 described above, wherein when all GWs included in the base having the main GW of the first cluster are inaccessible, the first cluster notifies the application device to use information from an accessible GW.

[0061] <Aspect 12> A method for processing handover by a multi-cluster system according to any one of the aspects 9 to 11 described above, wherein when the main GW becomes inaccessible, the first cluster changes the main system to another GW included in the base having the inaccessible GW or one of the GWs included in a base other than the base having the inaccessible GW.

[0062] <Aspect 13> A method for processing handover by a multi-cluster system according to any one of the above aspects 9 to 12, wherein the second cluster restarts the application device when all GWs (gateways) detect a failure of the application device.

[0063] As described above, the embodiments of the present invention have been described. However, the present invention is not limited to the above-described embodiments, and various modifications can be made without departing from the gist of the present invention.

Explanation of Signs

[0064] 1…Traffic control center, 2…Cloud (second control), 3…Control network, 4…Signal control device (signal control devices A to C), 5…Console, 6…Relay station (relay stations 1, 2, A, B), 7…GW (GW-a to d, gateway), 8…Signal network, 9…Terminal correspondence control device, 10…Intersection, 11…Urban sub-center A, 12…Urban sub-center B, 13…Internet / closed network, 14…Traffic control center of other prefectures, 15…Home, 16…FW (firewall), 17…Client, 18…Diagnostic unit, 19…Storage unit for system management information

Claims

1. A multi-cluster system comprising a first cluster including a plurality of GWs (gateways) for managing a plurality of bases, and a second cluster including a plurality of application devices for managing a business system, wherein the GWs and the application devices each form a redundant system, any one of the application devices serves as a main system and outputs a control output to the GW for a control device included in the business system, any one of the GWs serves as a main system and transmits the control output received from the main-system application device to the control device, the first cluster checks the soundness of each of the bases, and excludes the application device from the second cluster when the base including the main-system application device is abnormal, and the second cluster changes the application device other than the excluded application device to the main system and continues the process A multi-cluster system characterized by the above.

2. The multi-cluster system according to claim 1, wherein when the second cluster changes the application device to the main system, it selects the base having the largest number of application devices included in the bases other than the excluded base, and changes one of the application devices included in the selected base to the main system A multi-cluster system characterized by the above.

3. The multi-cluster system according to claim 1, wherein the GW (gateway) and the application device are connected to a control network, the GW and the control device are connected to a signal network, and the GW monitors the mutual state in two systems of the control network and the signal network A multi-cluster system characterized by the above.

4. The multi-cluster system according to claim 1, wherein when all the GWs included in the base having the main system of the GW (gateway) are inoperative, the first cluster notifies the application device to use information from the communicable GW A multi-cluster system characterized by the above.

5. The multi-cluster system according to claim 1, When the main GW (gateway) becomes inoperative, the first cluster changes one of the other GWs of the site having the inoperative GW or a GW of a site other than the said site to the main system. A multi-cluster system characterized by the above.

6. The multi-cluster system according to claim 1, When all the GWs (gateways) detect inoperability of the application device, the second cluster restarts the application device. A multi-cluster system characterized by the above.

7. The multi-cluster system according to any one of claims 1 to 6, The plurality of sites are composed of a control center and sub-centers that control devices and signals related to traffic control. A multi-cluster system characterized by the above.

8. The multi-cluster system according to claim 7, Each of the sites is provided with a console, and the console outputs at least a message about the operating status of the system. A multi-cluster system characterized by the above.

9. A processing handover method by a multi-cluster system composed of a first cluster having a plurality of GWs (gateways) for managing a plurality of sites and a second cluster having a plurality of application devices for managing a business system, Making the GW and the application device redundant systems respectively, Using any one of the application devices as the main system and outputting the control output to the control device of the business system to the GW, Using any one of the GWs as the main system and transmitting the control output received from the main system application device to the control device, The first cluster checks the soundness of each site, and when the site having the application device that has become the main system is abnormal, excludes the application device from the second cluster, The second cluster changes the application device other than the excluded application device to the main system and continues the process. A processing handover method by a multi-cluster system characterized by the above.

10. The processing handover method by the multi-cluster system according to claim 9, When changing the application device of the second cluster to the main system, select the site with the largest number of application devices among the sites other than the excluded sites, and change one of the application devices provided by the selected site to the main system. A method for processing handover by a multi-cluster system, characterized by the above.

11. A method for processing handover by a multi-cluster system according to claim 9, When all the GWs (gateways) provided by the site having the main system of the GW are incommunicable, the first cluster notifies the application device to use information from the communicable GWs. A method for processing handover by a multi-cluster system, characterized by the above.

12. A method for processing handover by a multi-cluster system according to claim 9, When the main GW (gateway) becomes incommunicable, the first cluster changes another GW of the site having the incommunicable GW or one of the GWs provided by the site other than the site having the incommunicable GW to the main system. A method for processing handover by a multi-cluster system, characterized by the above.

13. A method for processing handover by a multi-cluster system according to claim 9, When all the GWs (gateways) detect incommunication of the application device, the second cluster restarts the application device. A method for processing handover by a multi-cluster system, characterized by the above.

Citation Information

Patent Citations

  • JP137862A