Method and system for managing technical installations during an error condition in a controller - Patents.com
The method and system analyze program execution parameters to implement fail-safe logic, ensuring continuous operation of field devices by transferring control during controller device errors, addressing downtime issues in industrial installations.
Patent Information
- Application Number
- JP2025511357
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-23
- Filing Date
- 2023-08-23
- Publication Date
- 2025-08-15
AI Technical Summary
Existing industrial control systems face downtime and inefficiencies when a controller device enters an error state, disrupting the function of field devices and leading to operational disruptions in technical installations such as manufacturing plants and chemical processing plants.
A method and system utilizing a processing unit to analyze program execution parameters, determine error conditions in controller devices, and implement fail-safe logic on a secondary controller device to manage field devices, thereby maintaining operation during errors.
Ensures continuous operation of field devices by transferring control from an error-stricken controller to a functional secondary controller, minimizing downtime and enabling efficient error resolution.
Smart Images

Figure 2025526969000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to the field of industrial automation, and more particularly to a method and system for managing technical installations during the occurrence of an error condition in a controller device of the technical installation.
[0002] A technical installation, such as an industrial plant, includes a plurality of field devices controlled by a plurality of controller devices, such as programmable logic controllers, edge devices, and edge controllers. Examples of the plurality of field devices include, but are not limited to, control valves, motors, pumps, and actuators. Each of the plurality of controller devices is configured to control one or more of the plurality of field devices. When one of the plurality of controller devices enters an error state, the function of the controller device is disrupted. Accordingly, the function of one or more field devices controlled by the controller device is also disrupted, resulting in downtime of the industrial plant.
[0003] In view of the above, there is a need for an efficient and cost-effective method and system for managing a technical installation during the occurrence of an error condition in a controller device of the technical installation. It is therefore an object of the present invention to provide a method and system for managing a technical installation during the occurrence of an error condition in a controller device of the technical installation.
[0004] The object of the present invention is achieved by a method and system for managing a technical facility during the occurrence of an error condition in a controller device of the technical facility. The technical facility comprises a plurality of field devices and a plurality of controller devices. Examples of the plurality of controller devices include edge devices, programmable logic controller devices, microprocessors, or processing units. Each of the plurality of controller devices is configured to execute an engineering program for controlling a plurality of field devices in the technical facility. In one example, the plurality of controller devices comprises one or more edge controllers. Examples of the plurality of field devices include, but are not limited to, field devices such as control valves, motors, pumps, robots, lathes, sensors, and actuators. The plurality of field devices further comprises pressure sensors, temperature sensors, and vibration sensors. Further examples of the plurality of field devices include human-machine interfaces such as keyboards, mice, and touchscreens, and a plurality of client devices such as smartphones, desktop computers, and tablet computers networked to the plurality of controller devices. Examples of technical facilities include manufacturing plants, power generation plants, and chemical processing plants.
[0005] In a preferred embodiment, the method includes receiving, by a processing unit, a plurality of program execution parameters from each of a plurality of controller devices in the technical equipment. The plurality of program execution parameters received from the controller devices comprise information regarding runtime execution of an engineering program in the controller devices. For example, the plurality of program execution parameters comprise runtime information such as information regarding memory fragmentation, scan cycle characteristics, system resource utilization, and memory utilization of the controller device during execution of the engineering program in the controller device. The engineering program comprises a plurality of programming blocks, each of which comprises one or more programming instructions. In one example, the engineering program is a graphics program comprising program logic. The engineering program comprises a set of programmable instructions or statements corresponding to the program logic. Each programming block of the plurality of programming blocks corresponds to a function block in an engineering design of the technical equipment.
[0006] In a preferred embodiment, the method includes determining, by a processing unit, an error condition in a first controller device of the plurality of controller devices. The error condition is determined based on analysis of a plurality of received program execution parameters. The first controller device is determined to be in an error state if the first controller device pauses execution of an engineering program. In one example, the processing unit is configured to compare one or more program execution parameters of the received plurality of program execution parameters with one or more thresholds stored in memory. The one or more program execution parameters are received from the first controller device during execution of the engineering program in the first programmable logic controller. The first controller device is determined to be in an error state if the one or more program execution parameters exceed one or more thresholds. In another example, the processing unit is configured to apply a pattern recognition machine learning model to the one or more program execution parameters to determine the error condition in the first controller device. To train the pattern recognition machine learning model, historical data consisting of sets of program execution parameters received from the plurality of controller devices during a specific time interval is analyzed by the processing unit. The processing unit is further configured to identify, based on the analysis, a plurality of patterns in the set of program execution parameters. Furthermore, the processing unit is further configured to identify a plurality of relationships between the set of program execution parameters and one or more error states of the plurality of controller devices. Thus, the pattern recognition machine learning model is configured to recognize the plurality of patterns in the plurality of program execution parameters and determine that the first controller device is in an error state. Examples of pattern recognition machine learning models include, but are not limited to, supervised learning models and unsupervised learning models.
[0007] In a preferred embodiment, the method includes, by a processing unit, determining, based on a determination of an error condition in the first controller device, a fail-safe logic associated with the first controller device from a plurality of fail-safe logics. In one example, each fail-safe logic of the plurality of fail-safe logics has an identification number indicating a controller device associated with the fail-safe logic. Thus, the processing unit is configured to determine the fail-safe logic based on an identification number of the fail-safe logic matching the identification number of the first controller device. In one example, the plurality of fail-safe logics comprises a plurality of programming instructions configured to manage a plurality of field devices in the technical installation. Each fail-safe logic of the plurality of fail-safe logics is associated with a specific controller device of the plurality of controller devices. The fail-safe logic associated with the first controller device comprises a set of programming instructions configured to manage one or more field devices controlled by the first programming logic controller. The fail-safe logic is executable by any of the plurality of controller devices to manage the one or more field devices.
[0008] In a preferred embodiment, the method further includes determining, by the processing unit, that the second controller device is not in an error state based on analysis of the received program execution parameters. For example, the second controller device is determined to be not in an error state if one or more program execution parameters of the second controller device do not exceed one or more thresholds. In another example, the second controller device is determined to be not in an error state by a pattern recognition machine learning model.
[0009] In a preferred embodiment, the method further includes transmitting, by the processing unit, the fail-safe logic to the second controller device based on determining that the second controller device is not in an error state. The processing unit is configured to transmit the determined fail-safe logic to the second controller device over the network.
[0010] In a preferred embodiment, the method includes establishing, by a processing unit (202), a connection path between the second controller device and one or more field devices associated with the first controller device. In one example, the processing unit is configured to establish the connection path over a network.
[0011] In a preferred embodiment, the method includes initiating, by a processing unit, execution of a fail-safe logic associated with a first controller device in a second controller device of the plurality of controller devices. For example, the processing unit is configured to send a request to the second controller device over a network. The request is for initiating execution of the fail-safe logic in the second programmable controller. The second programmable controller then executes the fail-safe logic to control one or more field devices associated with the first controller device. Advantageously, the one or more field devices are controlled and managed even when the first controller device is in an error state. Thus, the processing unit 202 smoothly transfers control of the one or more field devices from the first controller device to the second controller device, avoiding downtime in the technical equipment.
[0012] In a preferred embodiment, the method includes, by a processing unit, pausing runtime of the first controller device based on determining an error condition of the first controller device. In one example, the processing unit is configured to send a pause command to the first controller device to pause runtime of the first controller device. In one example, when the first controller device is paused, the first controller device terminates execution of an engineering program. Advantageously, the first controller device pauses sending erroneous outputs to one or more field devices.
[0013] In a preferred embodiment, the method includes suspending, by a processing unit (202), one or more field devices based on determining an error condition in the first controller device. In one example, suspending the one or more field devices causes the one or more field devices to stop functioning. The processing unit is further configured to notify a user that the first controller device is in an error condition. The user can then resolve the error condition in the first controller device by debugging the engineering program.
[0014] In a preferred embodiment, the method includes determining, by a processing unit, that an error condition of the first controller device has been resolved based on analysis of the received plurality of program execution parameters. To determine that the error condition has been resolved, the processing unit is configured to determine that the received plurality of program execution parameters are within a plurality of thresholds. Advantageously, the first controller device resumes execution of the engineering program once the one or more errors in the engineering program have been resolved.
[0015] In a preferred embodiment, the method further includes, by the processing unit, resuming runtime of the first controller device based on determining that the error condition of the first controller device has been cleared, wherein if the error condition is determined to have been cleared, the processing unit is configured to send a trigger to the first controller device to resume runtime execution of the engineering program.
[0016] In a preferred embodiment, the method further includes determining, by the processing unit, a number of times an error condition is determined in the first controller device during the time interval. In a preferred embodiment, the method further includes, by the processing unit, notifying a user of the number of determinations. Advantageously, the user is enabled to evaluate the performance of the first controller device.
[0017] In one example, the plurality of program execution parameters comprises information regarding programming blocks of the engineering program to be executed by the first controller device in a particular time interval. In a preferred embodiment, the method further includes determining, by the processing unit, programming blocks of the engineering program to be executed by the first controller device in a particular time interval based on analysis of the plurality of program execution parameters.
[0018] In a preferred embodiment, the method further includes determining, by the processing unit, whether an error condition occurs in the first controller device during execution of the determined programming block. In a preferred embodiment, the method further includes, by the processing unit, notifying a user that an error condition occurs in the first controller device during execution of the determined programming block by the first controller device.
[0019] In a preferred embodiment, the method further includes executing, by the processing unit (202), handling logic for controlling one or more field devices when an error condition is determined in the first programmable logic controller. The handling logic comprises a set of programming instructions configured to manage one or more field devices controlled by the first programmable logic controller. The handling logic is executable by the processing unit.
[0020] The object of the present invention is also achieved by an industrial control system for managing technical equipment during the occurrence of an error condition in a controller device, the industrial control system comprising a processing unit and a memory coupled to the processing unit, the memory comprising a plant safety manager module having stored therein machine-readable instructions executable by a processor, the plant safety manager module being configured to perform the method described above.
[0021] The object of the invention is also achieved by an industrial environment comprising an industrial control system, a technical installation with one or more physical components, and a plurality of human-machine interfaces communicatively coupled to the industrial control system and the technical installation, the industrial control system being configured to perform the method steps described above.
[0022] The objects of the present invention are also achieved by a computer program product having machine-readable instructions stored therein which, when executed by one or more processors, cause the one or more processors to perform the method steps set out above.
[0023] These and other features of the present invention will now be described with reference to the accompanying drawings, in which the illustrated embodiments are illustrative of the invention and not limiting.
[0024] The invention will now be further described with reference to illustrative embodiments shown in the accompanying drawings. [Brief explanation of the drawings]
[0025] [Figure 1] 1 is a block diagram of an industrial environment in which technical equipment can be managed during the occurrence of an error condition in a controller device of the technical equipment according to an embodiment of the present invention; [Figure 2] 2 is a block diagram of an industrial control system, such as that shown in FIG. 1, in which an embodiment of the present invention may be implemented. [Figure 3] FIG. 3 is a block diagram of a plant safety manager module, as shown in FIG. 2, in which an embodiment of the present invention may be implemented. [Figure 4A] 1 is a process flow diagram illustrating an exemplary method for managing technical equipment during the occurrence of an error condition in a controller device of the technical equipment, according to an embodiment of the present invention. [Figure 4B] 1 is a process flow diagram illustrating an exemplary method for managing technical equipment during the occurrence of an error condition in a controller device of the technical equipment, according to an embodiment of the present invention. [Figure 4C] 1 is a process flow diagram illustrating an exemplary method for managing technical equipment during the occurrence of an error condition in a controller device of the technical equipment, according to an embodiment of the present invention. [Figure 4D] 1 is a process flow diagram illustrating an exemplary method for managing technical equipment during the occurrence of an error condition in a controller device of the technical equipment, according to an embodiment of the present invention.
[0026] Various embodiments are described with reference to the drawings, wherein like reference numerals are used to refer to like elements throughout. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of one or more embodiments. It will be apparent that embodiments may be practiced without such specific details.
[0027] FIG. 1 is a block diagram of an industrial environment 100 capable of managing technical equipment 106 during an error condition in a controller device of the technical equipment 106, according to one embodiment of the present invention. In FIG. 1, the industrial environment 100 includes an industrial control system 102, the technical equipment 106, and multiple human-machine interfaces 120A-120N. As used herein, "industrial environment" refers to a processing environment comprising configurable physical and logical computing resources, such as networks, servers, storage, applications, and services, and data distributed across a platform, such as a cloud computing platform. The industrial environment 100 provides on-demand network access to a shared pool of configurable physical and logical computing resources. The industrial control system 102 is communicatively connected to the technical equipment 106 via a network connection 104 (e.g., a local area network (LAN), a wide area network (WAN), Wi-Fi, the Internet, any short-range or wide-area communication, etc.). The industrial control system 102 is also connected to multiple human-machine interfaces 120A-120N via the network connection 104.
[0028] The industrial control system 102 is connected to multiple field devices 126A-126N in a technical installation 106 via a network connection 104. The multiple field devices 126A-126N may include servers, robots, switches, automation devices, programmable logic controllers (PLCs), human-machine interfaces (HMIs), motors, valves, pumps, actuators, sensors, and other industrial equipment. The multiple field devices 126A-126N may be connected to each other or to multiple other components (not shown in FIG. 1 ) via physical connections. The physical connections may be via wiring between the multiple field devices 126A-126N. Alternatively, the multiple field devices 126A-126N may be connected via non-physical connections (such as the Internet of Things (IoT)) and 5G networks. While FIG. 1 illustrates the industrial control system 102 connected to one technical installation 106, those skilled in the art can envision the industrial control system 102 being connected to multiple technical installations located in different geographic locations via the network connection 104. The plurality of field devices 126A-126N further comprises sensors such as pressure sensors, voltage sensors, temperature sensors, and vibration sensors. In such a case, the plurality of field devices 126A-126N obtain one or more measurements from the technical equipment 106. The one or more measurements consist of a temperature measurement, a pressure measurement, and a vibration measurement.
[0029] The technical equipment 106 further comprises a plurality of controller devices 108A-108N. Examples of the plurality of controller devices 108A-108N include, but are not limited to, controller devices, such as microprocessors and other processing units. The plurality of controller devices 108A-108N are configured to execute an engineering program stored in the industrial control system 102 over a plurality of scan cycles. The plurality of controller devices 108A-108N are configured to receive a plurality of input parameter values from a plurality of field devices 126A-126N. The plurality of controller devices 108A-108N are further configured to transmit a plurality of output parameter values to the plurality of field devices 126A-126N. Each of the plurality of field devices 126A-126N is connected to one or more of the plurality of controller devices 108A-108N via the network connection 104. Each of the plurality of controller devices 108A-108N is configured to control one or more field devices of the plurality of field devices 126A-126N. For example, the first controller device 108A is configured to control a first field device 126A and a second field device 126N among the plurality of field devices 126A to 126N.
[0030] The human machine interfaces 120A-120N can be desktop computers, laptop computers, tablets, smartphones, etc. Each of the human machine interfaces 120A-120N is provided with an engineering tool 122A-N for creating and / or editing an engineering program. The human machine interfaces 120A-120N can access the industrial control system 102 to automatically create an engineering program. The human machine interfaces 120A-120N can access a cloud application (such as one that provides visualization of the performance of the field devices 126A-126N via a web browser). Throughout this specification, the terms "human machine interface," "client device," and "user device" are used interchangeably. One or more of the human machine interfaces 120A-120N are further configured to receive user actions from a plurality of users. The user actions consist of user inputs, user commands, user gestures, programming instructions, and user passwords. The user actions are input by multiple users to perform one or more tasks using the controller devices 108A-108N and the field devices 126A-126N.
[0031] It should be noted that the industrial control system 102 is connected to a controller device 124. Examples of the controller device 124 include, but are not limited to, controller devices, microprocessors, and other processing units. The controller device 124 is configured to execute an engineering program generated by the industrial control system 102 over multiple scan cycles. The controller device 124 is configured to receive multiple input parameter values from the multiple sensor devices 126A-126N and the multiple human-machine interfaces 120A-120N. The controller device 124 is further configured to transmit multiple output parameter values to the multiple field devices 108A-108N and the multiple human-machine interfaces.
[0032] The industrial control system 102 may be a standalone server installed in a control station or a remote server on a cloud computing platform. In a preferred embodiment, the industrial control system 102 is a cloud-based industrial control system. The industrial control system 102 may provide an application (e.g., a cloud application) for managing a technical installation 106 including multiple field devices 108A-108N. The industrial control system 102 may include a digitization platform 110 (e.g., a cloud computing platform), a plant safety manager module 112, a server 114 including hardware resources and an operating system (OS), a network interface 116, and a database 118. The network interface 116 enables communication between the industrial control system 102, the technical installation 106, multiple human-machine interfaces 120A-120N, multiple field devices 126A-126N, and multiple controller devices 108A-108N. An interface, for example, a cloud interface (not shown in FIG. 1 ), can enable engineers at multiple field devices 126A-126N to access multiple controller devices 108A-108N and perform multiple user actions on the controller device 124 and the plant safety manager module 112.
[0033] The server 114 may include one or more servers on which an OS is installed. The server 114 may include one or more processors, one or more storage devices, such as memory units, for storing data and machine-readable instructions, applications, and application programming interfaces (APIs), as well as other peripherals necessary to provide computing (e.g., cloud computing) functionality. In one example, the digitization platform 110 may be implemented on the server 114. The digitization platform 110 uses the hardware resources and OS of the server 114 to realize functionality such as data reception, data processing, data rendering, and data communication, and provides the aforementioned services using an application programming interface installed therein. The digitization platform 110 may be composed of a combination of dedicated hardware and software built on the hardware and OS. In an exemplary embodiment, the digitization platform 110 may support an integrated development environment (IDE) equipped with a program editor and compiler that enables users of multiple human-machine interfaces 120A-120N to create engineering programs. The digitization platform 110 may further comprise a plant safety manager module 112 configured to enable management of the technical installation 106 during an error state of at least one controller device of the plurality of controller devices 108A-108N. Details of the plant safety manager module 112 are described with reference to FIG. 3.
[0034] The database 118 stores information related to the technical equipment 106, the plurality of controller devices 108A-108N, the plurality of field devices 126A-126N, and the plurality of human-machine interfaces 120A-120N. The database 118 may be, for example, a Structured Query Language (SQL) data store or a non-SQL-only (NoSQL) data store. In an exemplary embodiment, the database 118 may be configured as a cloud-based database implemented in the industrial environment 100, with computing resources provided as a service on the platform 110. The database 118, according to another embodiment of the present invention, is a location on a file system directly accessible by the plant safety manager module 112.
[0035] In one example, the plant safety manager module 112 is implemented in a controller device 124 configured to manage the technical equipment 106 during the occurrence of an error condition in a first controller device 108A. The controller device 124 is communicatively coupled to a plurality of controller devices 108A-108N, a plurality of field devices 126A-126N, and the industrial control system 102. In one example, a user can write programming code into the controller device 124 using a plurality of human machine interfaces 120A-120N.
[0036] Figure 2 is a block diagram of the industrial control system 102 shown in Figure 1, in which an embodiment of the present invention may be implemented. In Figure 2, the industrial control system 102 includes a processing unit 202, an accessible memory 204, a storage unit 206, a communication interface 208, an input / output unit 210, a network interface 212, and a bus 214.
[0037] As used herein, processing unit 202 refers to any type of computational circuit, such as, but not limited to, a microprocessor unit, a microcontroller, a complex instruction set computing microprocessor unit, a reduced instruction set computing microprocessor unit, a very long instruction word microprocessor unit, an explicitly parallel instruction computing microprocessor unit, a graphics processing unit, a digital signal processing unit, or any other type of processing circuit. Processing unit 202 can also include embedded controllers such as general purpose or programmable logic devices or arrays, application specific integrated circuits, single chip computers, and the like.
[0038] The memory 204 can be non-transitory volatile memory and non-volatile memory. The memory 204 can be coupled for communication with the processing unit 202, such as as a computer-readable storage medium. The processing unit 202 can execute machine-readable instructions and / or source code stored in the memory 204. Various machine-readable instructions can be stored in and accessed from the memory 204. The memory 204 can include any suitable element for storing data and machine-readable instructions, such as read-only memory, random-access memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, a hard drive, a removable media drive for handling compact discs, digital video discs, diskettes, magnetic tape cartridges, memory cards, etc. In this embodiment, the memory 204 includes an integrated development environment (IDE) 216. The IDE 216 includes the data acquisition and analysis module 112, which is stored in the form of machine-readable instructions on any of the storage media mentioned above, and is in communication with and executable by the processor 202.
[0039] When executed by the processing unit 202, the plant safety manager module 112 causes the processing unit 202 to receive a plurality of program execution parameters from each of a plurality of controller devices 108A-108N in the technical facility. The plurality of program execution parameters received from the controller devices comprise information regarding runtime execution of the engineering program in the controller devices. For example, the plurality of program execution parameters comprise runtime information such as information regarding memory fragmentation, scan cycle characteristics, system resource utilization, and memory utilization of the controller devices during execution of the engineering program in the controller devices. The engineering program comprises a plurality of programming blocks, each of which comprises one or more programming instructions. In one example, the engineering program is a graphics program comprising program logic, such as an engineering program. The engineering program comprises a set of programmable instructions or statements corresponding to the program logic. Each programming block of the plurality of programming blocks corresponds to a function block in the engineering design of the technical facility 106.
[0040] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine an error condition in a first controller device 108A of the plurality of controller devices 108A-108N. The error condition is determined based on an analysis of the received plurality of program execution parameters. The first controller device 108A is determined to be in an error condition if the first controller device 108A pauses execution of the engineering program. In one example, the processing unit 202 is configured to compare one or more program execution parameters of the received plurality of program execution parameters with one or more threshold values stored in a memory, such as the accessible memory 204. The one or more program execution parameters are received from the first controller device 108A during execution of the engineering program in the first programmable logic controller 108A. If the one or more program execution parameters exceed one or more threshold values, the first controller device 108A is determined to be in an error condition. In another example, the processing unit 202 is configured to apply a pattern recognition machine learning model to one or more program execution parameters to determine an error state in the first controller device 108A. To train the pattern recognition machine learning model, historical data consisting of sets of program execution parameters received from multiple controller devices during a specific time interval is analyzed by the processing unit 202. The processing unit 202 is further configured to identify multiple patterns in the sets of program execution parameters based on the analysis. Furthermore, the processing unit 202 is further configured to identify multiple relationships between the sets of program execution parameters and the error state of one or more controller devices among the multiple controller devices 108A-108N. Thus, the pattern recognition machine learning model is configured to recognize multiple patterns in the multiple program execution parameters and determine that the first controller device 108A is in an error state.Examples of pattern recognition machine learning models include, but are not limited to, supervised learning models and unsupervised learning models.
[0041] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine a fail-safe logic associated with the first controller device from the plurality of fail-safe logics based on the determination of the error condition in the first controller device. In one example, each fail-safe logic of the plurality of fail-safe logics has an identification number indicating the controller device associated with the fail-safe logic. Thus, the processing unit 202 is configured to determine the fail-safe logic based on the identification number of the fail-safe logic matching the identification number of the first controller device. In one example, the plurality of fail-safe logics comprises a plurality of programming instructions configured to manage the plurality of field devices 126A-126N in the technical equipment 106. Each fail-safe logic of the plurality of fail-safe logics is associated with a specific controller device of the plurality of controller devices 108A-108N. The fail-safe logic associated with the first controller device 108A comprises a set of programming instructions configured to manage one or more field devices (126A and 126B) controlled by the first programming logic controller 108A. The fail-safe logic can be executed by any of the multiple controller devices 108A-108N to manage one or more field devices 126A and 126B.
[0042] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine that a second controller device 108B of the plurality of controller devices 108A-108N is not in an error state based on an analysis of the received plurality of program execution parameters. For example, the second controller device 108B is determined to be not in an error state if one or more program execution parameters of the second controller device 108B do not exceed one or more thresholds. In another example, the second controller device 108B is determined to be not in an error state by a pattern recognition machine learning model.
[0043] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to transmit the fail-safe logic to the second controller device 108B based on determining that the second controller device 108B is not in an error state. The processing unit 202 is configured to transmit the determined fail-safe logic to the second controller device 108B over the network 104.
[0044] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to establish a connection path between the second controller device 108B and one or more field devices (126A and 126B) associated with the first controller device 108A. In one example, the processing unit 202 is configured to establish the connection path over the network 104.
[0045] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to initiate execution of fail-safe logic associated with the first controller device 108A in a second controller device 108B of the plurality of controller devices 108A-108N. For example, the processing unit 202 is configured to send a request to the second controller device 108B over the network 104. The request is to initiate execution of the fail-safe logic in the second programmable controller device 108B.
[0046] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to pause execution of the engineering program by the first controller device 108A based on the determination of the error state of the first controller device 108A. In one example, the processing unit is configured to send a pause command to the first controller device 108A to pause the runtime of the first controller device 108A. In one example, when the first controller device 108A is paused, the first controller device 108A terminates execution of the engineering program.
[0047] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to suspend one or more field devices (126A and 126B) based on determining an error state in the first controller device 108A. In one example, suspending the one or more field devices (126A and 126B) causes the one or more field devices (126A and 126B) to stop functioning. Furthermore, the processing unit 202 is further configured to notify a user that the first controller device 108A is in an error state. Furthermore, the user is enabled to resolve the error state of the first controller device 108A by debugging the engineering program.
[0048] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine that the error condition of the first controller device has been cleared based on an analysis of the received program execution parameters. To determine that the error condition has been cleared, the processing unit 202 is configured to determine that the received program execution parameters are within a plurality of thresholds.
[0049] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to resume runtime of the first controller device 108A based on determining that the error condition of the first controller device 108A has been cleared. If it is determined that the error condition has been cleared, the processing unit 202 is configured to send a trigger to the first controller device 108A to resume runtime execution of the engineering program.
[0050] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine the number of times an error condition was determined in the first controller device 108A during the time interval. When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to notify a user via the plurality of human machine interfaces 120A-120N of the number of determinations.
[0051] In one example, the plurality of program execution parameters comprises information regarding programming blocks of the engineering program to be executed by the first controller device 108A in a particular time interval. When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine, based on an analysis of the plurality of program execution parameters, the programming blocks of the engineering program to be executed by the first controller device 108A in the particular time interval.
[0052] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine whether an error condition occurs in the first controller device 108A during execution of the determined programming block. When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to notify a user that an error condition occurs in the first controller device 108A during execution of the programming block determined by the first controller device 108A.
[0053] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to execute handling logic for controlling one or more field devices 126A-B when an error condition is determined in the first programmable logic controller 108A. The handling logic comprises a set of programming instructions configured to manage one or more field devices controlled by the first programmable logic controller. The handling logic is executable by the processing unit 202.
[0054] The communication interface 208 is configured to establish communication sessions between the plurality of human machine interfaces 120A-120N, the industrial control system 102, and the controller device 124. The communication interface 208 enables one or more engineering applications executing on the plurality of human machine interfaces 120A-120N to import / export engineering programs to the controller device 124. In one embodiment, the communication interface 208 interacts with interfaces in the plurality of human machine interfaces 120A-120N to enable an engineer to access an engineering program associated with an engineering project file and perform one or more actions on the engineering program stored in the industrial control system 102.
[0055] The input / output unit 210 may include input devices such as a keypad, a touch-sensitive display, a camera (e.g., a camera that receives gesture-based input), etc., that can receive one or more input signals, such as user commands for processing an engineering project file. The input / output unit 210 may also be a display unit for displaying a graphic user interface for visualizing a behavioral model associated with a modified engineering program and displaying status information associated with each set of actions performed on the graphic user interface. The sets of actions may include running predefined tests, downloading, compiling, and deploying a graphic program. The bus 214 serves as an interconnect between the processor 202, the memory 204, and the input / output unit 210.
[0056] The network interface 212 may be configured to handle network connectivity, bandwidth and network traffic between the industrial control system 102, the plurality of human machine interfaces 120A-120N and the technical equipment 106.
[0057] Those skilled in the art will appreciate that the hardware depicted in Figure 2 may vary in particular implementations. For example, other peripheral devices such as optical disk drives, local area networks (LANs), wide area networks (WANs), wireless (e.g., Wi-Fi) adapters, graphics adapters, disk controllers, and input / output (I / O) adapters may be used in addition to or in place of the depicted hardware. The depicted examples are provided for purposes of explanation only and are not intended to imply architectural limitations with respect to the present disclosure.
[0058] Those skilled in the art will recognize that, for simplicity and clarity, the complete structure and operation of every data processing system suitable for use with the present disclosure has not been depicted or described herein. Instead, only those portions of the industrial control system 102 that are unique to or necessary for an understanding of the present disclosure have been depicted and described. The remainder of the structure and operation of the industrial control system 102 may be adapted to any of a variety of current implementations and embodiments known in the art.
[0059] Figure 3 is a block diagram of the plant safety manager module 112, as shown in Figure 2, in which one embodiment of the present invention may be implemented. In Figure 3, the plant safety manager module 112 includes a request handler module 302, a controller device selector module 304, an analysis module 306, a modification module 308, an engineering object database 310, a validation module 312, and a deployment module 314. Figure 3 will be described in conjunction with Figures 1 and 2.
[0060] The request handler module 302 is configured to receive a request for managing the technical equipment 106. For example, the request is received from one of one or more users external to the industrial environment 100 via a network. In an alternative embodiment, the request is received from one or more human machine interfaces 120A-120N via a network. The request handler module 302 is further configured to retrieve a plurality of program execution parameters sent by the plurality of controller devices 108A-108N.
[0061] The controller device selector module 304 is configured to determine a second controller device 108B to execute the failsafe logic associated with the first controller device.
[0062] The analysis module 306 is configured to analyze a plurality of program execution parameters to determine an error condition in the first controller device.
[0063] The correction module 308 is configured to correct the fail-safe logic before sending the fail-safe logic to the second programmable logic control 108B.
[0064] The engineering object database 310 is configured to generate an engineering object library that includes multiple fail-safe logics, information about multiple field devices 126A-126N, and physical connections between the multiple field devices 126A-126N and multiple controller devices 108A-108N.
[0065] The verification module 312 is configured to verify the engineering program executed by the plurality of controller devices 108A-108N. The verification module 312 is configured to simulate the execution of the plurality of controller devices 108A-108N.
[0066] The deployment module 314 is configured to deploy fail-safe logic associated with the first controller device 108A to the second controller device 108B.
[0067] 4A-4E are process flow diagrams illustrating an exemplary method 400 for managing technical equipment during an error condition of a controller device, according to one embodiment of the present invention. Figures 4A-4E will be described in conjunction with Figures 1-3.
[0068] In 402, the plant safety manager module 112 causes the processing unit 202 to receive a plurality of program execution parameters from each of a plurality of controller devices 108A-108N in the technical facility. The plurality of program execution parameters received from the controller devices comprise information regarding runtime execution of an engineering program in the controller devices. For example, the plurality of program execution parameters comprise runtime information such as information regarding memory fragmentation, scan cycle characteristics, system resource utilization, and memory utilization of the controller devices during execution of the engineering program in the controller devices. The engineering program comprises a plurality of programming blocks, each of which comprises one or more programming instructions. In one example, the engineering program is a graphics program comprising program logic. The engineering program comprises a set of programmable instructions or statements corresponding to the program logic. Each programming block of the plurality of programming blocks corresponds to a function block in the engineering design of the technical facility 106.
[0069] At 404, the plant safety manager module 112 further causes the processing unit 202 to determine an error condition in a first controller device 108A of the plurality of controller devices 108A-108N. The error condition is determined based on an analysis of the received plurality of program execution parameters. The first controller device 108A is determined to be in an error condition if the first controller device 108A pauses execution of the engineering program. In one example, the processing unit 202 is configured to compare one or more program execution parameters of the received plurality of program execution parameters to one or more threshold values stored in a memory, such as the accessible memory 204. The one or more program execution parameters are received from the first controller device 108A during execution of the engineering program in the first programmable logic controller 108A. If the one or more program execution parameters exceed one or more threshold values, the first controller device 108A is determined to be in an error condition. In another example, the processing unit 202 is configured to apply a pattern recognition machine learning model to one or more program execution parameters to determine an error state of the first controller device 108A. To train the pattern recognition machine learning model, historical data consisting of sets of program execution parameters received from multiple controller devices during a specific time interval is analyzed by the processing unit 202. The processing unit 202 is further configured to identify multiple patterns in the sets of program execution parameters based on the analysis. The processing unit 202 is further configured to identify multiple relationships between the sets of program execution parameters and the error state of one or more controller devices among the multiple controller devices 108A-108N. Thus, the pattern recognition machine learning model is configured to recognize multiple patterns in the multiple program execution parameters and determine that the first controller device 108A is in an error state.Examples of pattern recognition machine learning models include, but are not limited to, supervised learning models and unsupervised learning models.
[0070] At 406, the plant safety manager module 112 further causes the processing unit 202 to determine a fail-safe logic associated with the first controller device from the plurality of fail-safe logics based on the determination of the error condition in the first controller device. In one example, each fail-safe logic of the plurality of fail-safe logics has an identification number indicating the controller device associated with the fail-safe logic. Thus, the processing unit 202 is configured to determine the fail-safe logic based on the identification number of the fail-safe logic matching the identification number of the first controller device. In one example, the plurality of fail-safe logics comprises a plurality of programming instructions configured to manage the plurality of field devices 126A-126N in the technical equipment 106. Each fail-safe logic of the plurality of fail-safe logics is associated with a particular controller device of the plurality of controller devices 108A-108N. The fail-safe logic associated with the first controller device 108A comprises a set of programming instructions configured to manage one or more field devices (126A and 126B) controlled by the first programming logic controller 108A. The fail-safe logic can be executed by any of the multiple controller devices 108A-108N to manage one or more field devices 126A and 126B.
[0071] At 408, the plant safety manager module 112 further causes the processing unit 202 to determine that the second controller device 108B is not in an error state based on an analysis of the received program execution parameters. For example, the second controller device 108B is determined to be not in an error state if one or more program execution parameters of the second controller device 108B do not exceed one or more thresholds. In another example, the second controller device 108B is determined to be not in an error state by a pattern recognition machine learning model.
[0072] At 410, the plant safety manager module 112 further causes the processing unit 202 to transmit the fail-safe logic to the second controller device 108B based on determining that the second controller device 108B is not in an error state. The processing unit 202 is configured to transmit the determined fail-safe logic to the second controller device 108B via the network 104.
[0073] At 412, the plant safety manager module 112 further causes the processing unit 202 to establish a connection path between the second controller device 108B and one or more field devices (126A and 126B) associated with the first controller device 108A. In one example, the processing unit 202 is configured to establish the connection path via the network 104.
[0074] At 414, the plant safety manager module 112 further causes the processing unit 202 to initiate execution of the fail-safe logic associated with the first controller device 108A in a second controller device 108B of the plurality of controller devices 108A-108N. For example, the processing unit 202 is configured to send a request to the second controller device 108B over the network 104. The request is for initiating execution of the fail-safe logic in the second programmable controller device 108B.
[0075] At 416, the plant safety manager module 112 further causes the processing unit 202 to pause runtime of the first controller device 108A based on the determination of the error condition of the first controller device 108A. In one example, the processing unit is configured to send a pause command to the first controller device 108A to pause runtime of the first controller device 108A. In one example, when the first controller device 108A is paused, the first controller device 108A terminates execution of the engineering program.
[0076] At 418, the plant safety manager module 112 further causes the processing unit 202 to suspend one or more field devices (126A and 126B) based on the determination of the error state in the first controller device 108A. In one example, suspending the one or more field devices (126A and 126B) causes the one or more field devices (126A and 126B) to stop functioning. Note that the processing unit 202 is further configured to notify a user that the first controller device 108A is in an error state. Furthermore, the user can resolve the error state of the first controller device 108A by debugging the engineering program.
[0077] At 420, the plant safety manager module 112 further causes the processing unit 202 to determine that the error condition of the first controller device has been cleared based on analysis of the received plurality of program execution parameters. To determine that the error condition has been cleared, the processing unit 202 is configured to determine that the received plurality of program execution parameters are within a plurality of thresholds.
[0078] At 422, the plant safety manager module 112 further causes the processing unit 202 to resume runtime of the first controller device 108A based on determining that the error condition of the first controller device 108A has been cleared. If it is determined that the error condition has been cleared, the processing unit 202 is configured to send a trigger to the first controller device 108A to resume runtime execution of the engineering program.
[0079] At 424, the plant safety manager module 112 further causes the processing unit 202 to determine the number of times an error condition was determined in the first controller device 108A during the time interval. At 426, the plant safety manager module 112 further causes the processing unit 202 to notify a user of the number of determinations via the plurality of human machine interfaces 120A-120N.
[0080] In one example, the plurality of program execution parameters comprises information regarding programming blocks of the engineering program to be executed by the first controller device 108A in a particular time interval. At 428, the plant safety manager module 112 further causes the processing unit 202 to determine, based on the analysis of the plurality of program execution parameters, the programming blocks of the engineering program to be executed by the first controller device 108A in the particular time interval.
[0081] At 430, the plant safety manager module 112 further causes the processing unit 202 to determine whether an error condition occurs in the first controller device 108A during execution of the determined programming block. At 432, the plant safety manager module 112 further causes the processing unit 202 to notify a user that an error condition occurs in the first controller device 108A during execution of the programming block determined by the first controller device 108A.
[0082] At 434, the plant safety manager module 112 further causes the processing unit 202 to execute handling logic for controlling one or more field devices 126A-126B when an error condition is determined in the first programmable logic controller 108A. The handling logic comprises a set of programming instructions configured to manage one or more field devices controlled by the first programmable logic controller. The handling logic is executable by the processing unit 202.
[0083] The present invention may take the form of a computer program product comprising program modules accessible from a computer-usable or computer-readable medium storing program code for use by or in connection with one or more computers, processors, or instruction execution systems. For purposes of this description, a computer-usable or computer-readable medium can be any apparatus that can store, store, communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device. The medium can be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system (or apparatus or device), and the definition of physical computer-readable medium does not include propagation media per se as signal carriers, but includes semiconductor or solid-state memory, magnetic tape, removable computer diskettes, random access memory (RAM), read-only memory (ROM), rigid magnetic disks, and optical discs such as compact disc read-only memory (CD-ROM), compact disc read / write, and DVD. Both the processor and the program code for implementing aspects of the present technology may be centralized or distributed (or a combination thereof), as known to those skilled in the art.
[0084] Although the present invention has been described in detail with reference to specific embodiments, it should be understood that the present invention is not limited to these embodiments. In light of this disclosure, many modifications and variations will occur to those skilled in the art without departing from the scope of the various embodiments of the present invention described herein. Accordingly, the scope of the present invention is indicated by the following claims, rather than by the foregoing description. All changes, modifications, and variations that come within the meaning and range of equivalency of the claims are deemed to be within their scope. All advantageous embodiments described in the method claims may also be applied to the system / apparatus claims.
Claims
1. 1. A method for managing a technical installation (106) during the occurrence of an error condition in a controller device (108A) of said technical installation (106), said method comprising: receiving, by a processing unit (202), a plurality of program execution parameters from each controller device of a plurality of controller devices (108A-108N) in said technical installation (106), said plurality of program execution parameters associated with each controller device comprising runtime information of said controller device during runtime execution of an engineering program in said controller device; determining, by the processing unit (202), an error condition in the first controller device (108A) of the plurality of controller devices (108A-108N), the error condition being determined based on analysis of the plurality of received program execution parameters; determining, by the processing unit (202), a fail-safe logic associated with the first controller device (108A) from a plurality of fail-safe logics based on the determination of the error condition in the first controller device (108A); initiating, by the processing unit (202), execution of the fail-safe logic associated with the first controller device (108A) at a second controller device (108B) of the plurality of controller devices (108-108N); A method comprising:
2. The method of claim 1, wherein the technical installation further comprises one or more field devices (126A-126B) controlled by the first controller device.
3. initiating, by the processing unit (202), execution of the fail-safe logic in the second controller device (108B); determining, by the processing unit (202), based on analysis of the received program execution parameters, that the second controller device (108B) is not in an error state; transmitting, by the processing unit (202), the fail-safe logic to the second controller device (108B) based on determining that the second controller device is not in the error state; establishing, by the processing unit (202), a connection between the second controller device (108B) and the one or more field devices associated with the first controller device; 3. The method of claim 1 or 2, comprising:
4. The method of any one of claims 1 to 3, further comprising causing the processing unit (202) to suspend execution of an engineering program in the first controller device (108A) based on determining the error state of the first controller device (108A).
5. The method of any one of claims 2 to 4, further comprising causing the processing unit (202) to suspend execution of the first controller device (108A) based on determining the error state of the first controller device (108A).
6. The method further comprises: suspending, by the processing unit (202), the one or more field devices (126A-B) based on determining the error condition at the first controller device (108A); determining, by the processing unit (202), that the error condition of the first controller device (108A) has been resolved, wherein the resolution of the error condition is determined based on analysis of the received plurality of program execution parameters; resuming the runtime of the first controller device (108A) based on determining, by the processing unit (202), that the error condition of the first controller device (108A) has been resolved; 6. The method of claim 5, comprising:
7. The method further comprises: determining, by the processing unit (202), the number of times the error condition is determined in the first controller device (108A) during a time interval; The processing unit (202) notifies the user of the number of determinations.
7. The method of any one of claims 1 to 6, comprising:
8. The method further comprises: determining, by the processing unit (202), programming blocks of an engineering program to be executed by the first controller device (108A) based on the analysis of the program execution parameters; determining, by the processing unit (202), whether the error condition was determined in the first controller device during execution of the determined programming block; notifying a user, by the processing unit (202), that the error condition was determined in the first controller device (108A) during execution of the programming block determined by the first controller device (108A); and 8. The method of any one of claims 1 to 7, comprising:
9. The method further comprises: executing handling logic for controlling the one or more field devices (126A-126B) when the processing unit (202) determines the error condition in the first programmable logic controller (108A); 9. The method of any one of claims 1 to 8, comprising:
10. An industrial control system (102) for managing technical equipment during the occurrence of an error condition in a controller device, comprising: a processing unit (202); a memory (204) coupled to the processing unit (202); and wherein the memory (204) comprises a plant safety manager module (112) having stored therein machine-readable instructions executable by one or more processors, the plant safety manager module being capable of performing the method of any one of claims 1 to 9. An industrial control system (102).
11. An industrial environment (100), comprising: The industrial control system (102) of claim 10; a technical installation (106) comprising one or more physical components; a plurality of human machine interfaces (120A-120N) communicatively coupled to the industrial control system (102) via a network (104); wherein the industrial control system (102) is configured to perform the method of any one of claims 1 to 9. Industrial environment (100).
12. 10. A computer program product having machine-readable instructions stored therein which, when executed by a processing unit (202), cause a processor to perform the method of any one of claims 1 to 9.
Citation Information
Patent Citations
Fail-safe system in integrated control of vehicle
JP2002221075A
Monitoring system of automatic door and accounting system
JP2003090169A
PLC system and backup method therefor
JP2004362133A
Equipment element maintenance analysis system and facility element maintenance analysis method
JP2019021008A