Control device, control method, and control program
The control device addresses the issue of unnecessary alarms from soft errors by collecting data, detecting abnormalities, and executing actions to minimize responses through masking and messaging, enhancing system efficiency.
Patent Information
- Application Number
- JP2024115916
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-19
- Publication Date
- 2026-01-29
AI Technical Summary
Existing systems fail to effectively reduce the number of responses to alarms caused by soft errors in processor and input/output modules, leading to unnecessary actions by plant site managers.
A control device that collects data, detects abnormalities in processor and input/output modules, executes appropriate actions, and notifies users only when necessary, masking or adding messages to alarms to minimize responses.
Reduces the number of responses to alarms due to soft errors by masking unnecessary alarms and providing clear messages about continued use, thereby minimizing unnecessary actions.
Smart Images

Figure 2026014617000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a control device, a control method, and a control program. [Background technology]
[0002] A soft error is a phenomenon in which, for some reason (mainly cosmic rays or radiation causing electron excitation of internal atoms in the circuits of a semiconductor chip), the positive and negative polarities of the semiconductors that control storage and operation bits are reversed, destroying internal information.Unlike physical destruction or deterioration of the device, soft errors can be restored to their original state by rewriting the data. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Patent No. 6656593 Summary of the Invention [Problem to be solved by the invention]
[0004] It is difficult to reduce the number of responses to alarms caused by soft errors. For example, when an abnormality caused by a soft error occurs in a processor module or an input / output module (IOM), an abnormality alarm (or simply "alarm" as appropriate) is issued to the plant site manager, even though no action is required. Therefore, in reality, the plant site manager must respond to the notified alarm.
[0005] The present invention has been made in view of the above, and has an object to reduce the number of times to respond to alarms due to soft errors. [Means for solving the problem]
[0006] A control device according to one embodiment of the present invention includes a collection unit that collects data from devices that constitute a system; a detection unit that detects an abnormality that has occurred in at least one of a processor module and an input / output module based on the collected data; an execution unit that, if the detected abnormality is likely to be caused by a soft error, executes an action in response to an alarm indicating the abnormality; and a notification unit that notifies a user of the alarm for which the action has been executed.
[0007] In a control method according to one embodiment of the present invention, a computer collects data from devices that constitute a system, detects an abnormality that has occurred in at least one of a processor module and an input / output module based on the collected data, and if the detected abnormality is likely to be caused by a soft error, executes an action in response to an alarm indicating the abnormality, and notifies a user of the alarm for which the action has been executed.
[0008] A control program according to one embodiment of the present invention causes a computer to collect data from devices constituting a system, detect an abnormality that has occurred in at least one of a processor module and an input / output module based on the collected data, and if the detected abnormality is likely to be caused by a soft error, execute an action in response to an alarm indicating the abnormality, and notify a user of the alarm for which the action has been executed. [Effects of the Invention]
[0009] According to the present invention, it is possible to reduce the number of times to respond to alarms caused by soft errors. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a diagram illustrating a configuration example and a processing example of an abnormality monitoring system according to an embodiment; [Figure 2] 1 is a diagram showing a specific example of an entire anomaly monitoring system according to an embodiment; [Figure 3] FIG. 1 is a diagram illustrating a specific example of a control device of an abnormality monitoring system. [Figure 4] 1 is a block diagram showing an example of the configuration of each device of an anomaly monitoring system according to an embodiment; [Figure 5] FIG. 4 is a diagram illustrating an example of a detection result storage unit of the control device according to the embodiment. [Figure 6] FIG. 4 is a diagram illustrating an example of an alarm information storage unit of the control device according to the embodiment. [Figure 7] FIG. 4 is a diagram illustrating an example of a report information storage unit of the control device according to the embodiment. [Figure 8] FIG. 2 is a diagram showing a specific example 1 of each process of the anomaly monitoring system according to the embodiment. [Figure 9] FIG. 2 is a diagram showing a specific example 2-1 of each process of the anomaly monitoring system according to the embodiment. [Figure 10] FIG. 2 is a diagram showing a specific example 2-2 of each process of the anomaly monitoring system according to the embodiment. [Figure 11] FIG. 2 is a diagram showing a specific example 2-3 of each process of the anomaly monitoring system according to the embodiment. [Figure 12] FIG. 2 is a diagram showing a specific example 2-4 of each process of the anomaly monitoring system according to the embodiment. [Figure 13] FIG. 2 is a diagram showing a specific example 2-5 of each process of the anomaly monitoring system according to the embodiment. [Figure 14] FIG. 3 is a diagram showing a specific example 3-1 of each process of the anomaly monitoring system according to the embodiment. [Figure 15] FIG. 3 is a diagram showing a specific example 3-2 of each process of the anomaly monitoring system according to the embodiment. [Figure 16] FIG. 3 is a diagram showing a specific example 3-3 of each process of the anomaly monitoring system according to the embodiment. [Figure 17] FIG. 10 is a diagram showing a specific example 4 of each process of the anomaly monitoring system according to the embodiment. [Figure 18] 10 is a flowchart showing a specific example 1-1 of the flow of each process of the anomaly monitoring system according to the embodiment. [Figure 19]10 is a flowchart showing a specific example 1-2 of the flow of each process of the anomaly monitoring system according to the embodiment. [Figure 20] 2 is a flowchart showing a specific example 2-1 of the flow of each process of the anomaly monitoring system according to the embodiment. [Figure 21] 10 is a flowchart showing a specific example 2-2 of the flow of each process of the anomaly monitoring system according to the embodiment. [Figure 22] 10 is a flowchart showing a specific example 2-3 of the flow of each process of the anomaly monitoring system according to the embodiment. [Figure 23] 10 is a flowchart showing a specific example 3 of the flow of each process of the anomaly monitoring system according to the embodiment. [Figure 24] FIG. 2 is a diagram illustrating an example of a hardware configuration according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] A control device, a control method, and a control program according to an embodiment of the present invention will be described in detail below with reference to the drawings. Note that the present invention is not limited to the embodiment described below.
[0012] Below, we will explain the configuration and processing of the anomaly monitoring system 100 related to the embodiment, the configuration and processing of each device of the anomaly monitoring system 100, specific examples of each process of the anomaly monitoring system 100, the flow of each process of the anomaly monitoring system 100, and the effects of the embodiment.
[0013] 1. Configuration and Processing of Anomaly Monitoring System 100 1 to 3, the configuration and processing of an anomaly monitoring system 100 according to an embodiment will be described. Below, an example of the overall configuration of the anomaly monitoring system 100, a specific example of the overall anomaly monitoring system 100, a specific example of the control device 10 of the anomaly monitoring system 100, an example of processing of the anomaly monitoring system 100, and the effects of the anomaly monitoring system 100 will be described. Note that in the embodiment, the control device 10 that controls a plant will be described as an example, but this does not limit the application target or field of use.
[0014] (1-1. Example of the overall configuration of the abnormality monitoring system 100) An example of the overall configuration of an anomaly monitoring system 100 will be described using Fig. 1. Fig. 1 is a diagram showing an example of the configuration and processing of the anomaly monitoring system 100 according to an embodiment. The anomaly monitoring system 100 is composed of a controller 10, an engineer terminal 20, and a plurality of field devices 30. The controller 10, the engineer terminal 20, and the field devices 30 are communicably connected via a predetermined communication network (not shown) and an input / output module M, either wired or wirelessly. The predetermined communication network can be any of various communication networks, such as the Internet or a dedicated line.
[0015] (1-1-1. Control device 10) The control device 10 is a device that controls the field devices 30 that constitute a plant and monitors abnormalities that occur in the plant. For example, the control device 10 is installed in an operator's room that monitors the plant. The abnormality monitoring system 100 shown in FIG. 1 may include multiple control devices 10. In the example of FIG. 1, the control device 10 is realized by a Field Control Station (FCS) controller or a Safety Control Station (SCS) controller, but it may also be realized by a desktop personal computer (PC), a notebook PC, a smartphone, a server device, a cloud system, or the like.
[0016] (1-1-2. Engineer Terminal 20) The engineer terminal 20 is a manager terminal used by engineer E, who is the manager of the anomaly monitoring system 100, and is realized by an HIS (Human Interface Station) or the like that has a plant operation and monitoring function. Note that the anomaly monitoring system 100 shown in FIG. 1 may include multiple engineer terminals 20.
[0017] (1-1-3. Field Device 30) The field devices 30 (30-1, 30-2, 30-3, ...) are devices that are installed in a plant and acquire various types of data. For example, the field devices 30 are measuring devices such as pressure meters, flow meters, and vibrometers, and are installed at the plant site.
[0018] (1-1-4. Input / Output Module M) The input / output module M enables transmission and reception of various data between the control device 10 and the field device 30. For example, the input / output module M may be connected between the control device 10 and the field device 30 as an independent device, or may be built into the control device 10 or the field device 30.
[0019] (1-2. Specific example of the entire abnormality monitoring system 100) A specific example of the entire anomaly monitoring system 100 will be described using Fig. 2. Fig. 2 is a diagram showing a specific example of the entire anomaly monitoring system 100 according to an embodiment. The example in Fig. 2 is configured by a control system 1 including an SCS controller, which is a safety instrumented system, and a control system 2 including an FCS controller that executes plant control. Furthermore, the devices included in the control system 1 and the control system 2 are connected by a control bus (Vnet / IP), which is a bus for real-time process control.
[0020] 2, the control system 1 is configured by, for example, an "SCS" which is a control device 10 that constitutes the SCS, and an "SENG" which is an engineer terminal 20 that implements system construction and maintenance management of the control system 1. The control system 1 shown in FIG. 2 may also include an HIS that executes the operation and monitoring function of the plant.
[0021] 2, the control system 2 is configured by, for example, an "FCS" which is a control device 10 that configures the FCS, an "ENG" which is an engineer terminal 20 that implements system construction and maintenance management of the control system 2, and an "HIS" that executes plant operation and monitoring functions. In the control system 2 shown in FIG. 2, the "ENG" and "HIS" may be integrated into one configuration.
[0022] (1-3. Specific Example of the Control Device 10 of the Anomaly Monitoring System 100) A specific example of the control device 10 of the abnormality monitoring system 100 will be described with reference to Fig. 3. Fig. 3 is a diagram showing a specific example of the control device 10 of the abnormality monitoring system 100. In the example of Fig. 3, the control device 10 is configured by a control unit and a bus node.
[0023] As shown in FIG. 3, the control unit includes, for example, a control processor module P C , standby processor module P S The system is composed of multiple ESB (Extended Serial Backboard) bus coupler modules and multiple power supply modules. The multiple ESB bus coupler modules are connected to the bus node.
[0024] As shown in FIG. 3, the bus node may include, for example, a plurality of ESB bus modules, a plurality of power supply units, and a control-side input / output module M. C , and the standby input / output module M S Furthermore, multiple ESB bus modules are connected to a control unit.
[0025] The control device 10 described above has a configuration in which both the processor module P and the input / output module M are duplicated, but a configuration in which triple or more redundancy is also possible, and there are no particular limitations on the redundancy configuration. Furthermore, the control device 10 described above has a configuration in which a bus node including the input / output module M is installed inside, but it may also be installed outside the control device 10.
[0026] (1-4. Processing Example of Anomaly Monitoring System 100) 1 again, a processing example of the anomaly monitoring system 100 will be described. Below, a data collection process (step S1), anomaly detection process (step S2), action execution process (step S3), and alarm notification process (step S4) will be described. Note that the processes of steps S1 to S4 below can be executed in a different order. Also, some of the processes of steps S1 to S4 below may be omitted.
[0027] (1-4-1. Data collection process) First, the control device 10 collects various data from the field devices 30 via the input / output module M (step S1). For example, the control device 10 collects measurement data acquired by the field device 30-1 from the field device 30-1 via the input / output module M-1. The control device 10 also collects measurement data acquired by the field device 30-2 from the field device 30-2 via the input / output module M-2. The control device 10 also collects measurement data acquired by the field device 30-3 from the field device 30-3 via the input / output module M-3.
[0028] (1-4-2. Abnormality detection processing) Second, the control device 10 detects an abnormality that has occurred in the control system (step S2). For example, the control device 10 diagnoses the collected measurement data and detects a transient abnormality that has occurred in the processor module P, an internal memory diagnosis abnormality that has occurred in the input / output module M, etc.
[0029] (1-4-3. Action execution process) Third, the control device 10 executes an action on the alarm (step S3). For example, when the control device 10 detects a transient abnormality that has occurred in the processor module P, it executes alarm masking for the system alarm of the processor module P, which hides the alarm. At this time, when the detected transient abnormality is the second or subsequent time in the same processor module P, the control device 10 does not execute alarm masking for the system alarm of the processor module P. Note that the engineer E can set whether or not to execute alarm masking.
[0030] On the other hand, when the control device 10 detects a transient abnormality that has occurred in the processor module P, it adds a message indicating that the processor module can be used continuously to the system alarm of the processor module P. Engineer E can set whether or not to add the message indicating that the processor module can be used continuously.
[0031] Furthermore, when the control device 10 detects an internal memory diagnostic abnormality that has occurred in the input / output module M, it executes alarm masking to hide the system alarm of the input / output module M. At this time, if the detected internal memory diagnostic abnormality is the second or subsequent time in the same input / output module M, the control device 10 does not execute alarm masking for the system alarm of the input / output module M. Engineer E can set whether or not to execute alarm masking.
[0032] On the other hand, when the control device 10 detects an internal memory diagnostic abnormality that has occurred in the input / output module M, it adds a message indicating that the input / output module M can continue to be used to the system alarm of the input / output module M. Engineer E can set whether or not to add the message indicating that the input / output module M can continue to be used.
[0033] (1-4-4. Alarm notification processing) Fourth, the control device 10 notifies engineer E of the alarm (step S4). For example, the control device 10 transmits the system alarm for which the action has been executed to the engineer terminal 20. At this time, the control device 10 hides the system alarm for which the alarm mask has been executed in the system alarm view of the engineer terminal 20. On the other hand, the control device 10 displays the system alarm for which the alarm mask has not been executed in the system alarm view of the engineer terminal 20. In addition, the control device 10 transmits a system report showing the history of the system alarm to the engineer terminal 20, and displays it in a historical message report window of the engineer terminal 20.
[0034] Furthermore, if the control system does not recover after an abnormality occurs, the control device 10 can re-notify the abnormality alarm to the engineer E. At this time, the control device 10 displays the re-notified abnormality alarm on the engineer terminal 20, regardless of whether an alarm mask is set or the number of abnormalities that have occurred.
[0035] (1-5. Effects of the abnormality monitoring system 100) Below, an overview and problems of the anomaly monitoring system 100P according to the reference technology will be explained, and then the effects of the anomaly monitoring system 100 will be explained.
[0036] (1-5-1. Overview and problems of the Anomaly Monitoring System 100P) The following describes the overview and problems of the anomaly monitoring system 100P according to the reference technology. In the anomaly monitoring system 100P, when a transient anomaly caused by a soft error is automatically recovered, engineer E does not need to take action. For example, first, the control device 10P according to the reference technology automatically restarts and issues an alarm when a transient anomaly occurs in the processor module P. Second, the control device 10P automatically restarts and issues an alarm when an internal memory diagnosis anomaly occurs in the input / output module M. Third, if the anomaly occurrence alarm is for a specific target code, the control device 10P automatically recovers and issues an alarm, allowing continued use.
[0037] However, the anomaly monitoring system 100P does not generate an alarm that Engineer E can immediately understand as meaning that "no action is required," which creates a problem in that an action is actually required on-site even though no action is required.
[0038] (1-5-2. Overview of the abnormality monitoring system 100) An overview of the anomaly monitoring system 100 according to the embodiment will be described below. In the anomaly monitoring system 100, when an automatic recovery is made from a transient anomaly caused by a soft error, no on-site response is required.
[0039] Specifically, the anomaly monitoring system 100 executes the following processes. First, when the control device 10 detects a transient anomaly that has occurred in the processor module P, it masks the system alarm of the processor module P, thereby hiding the system alarm on the engineer terminal 20. Second, when the control device 10 detects an internal memory diagnostic anomaly that has occurred in the input / output module M, it masks the alarm of the input / output module M, thereby hiding the system alarm on the engineer terminal 20. Third, when the control device 10 detects a transient anomaly that has occurred in the processor module P or an internal memory diagnostic anomaly that has occurred in the input / output module M, it adds a message indicating continued use to the system alarm of the processor module P or the input / output module M, thereby notifying the engineer E of an alarm with an added message that indicates that no action is required.
[0040] At this time, if the detected transient abnormality is the second or subsequent time in the same processor module P, or if the detected internal memory diagnostic abnormality is the second or subsequent time in the same input / output module M, the control device 10 displays a system alarm on the engineer terminal 20. Furthermore, if the control system does not recover after the abnormality occurs, the control device 10 displays the re-notified abnormality alarm on the engineer terminal 20, regardless of whether an alarm mask is set or the number of abnormality occurrences.
[0041] (1-5-3. Effects of the abnormality monitoring system 100) The effects of the anomaly monitoring system 100 according to the embodiment will be described below. First, when the anomaly monitoring system 100 detects a transient anomaly that has occurred in the processor module P for the first time, it hides the system alarm on the engineer terminal 20, thereby reducing the amount of response required by engineer E. Second, when the anomaly monitoring system 100 detects an internal memory diagnosis anomaly that has occurred in the input / output module M for the first time, it hides the system alarm on the engineer terminal 20, thereby reducing the amount of response required by engineer E. Third, when the anomaly occurrence alarm is for a specific target code, i.e., when an anomaly caused by a soft error is detected, the anomaly monitoring system 100 notifies engineer E of a system alarm with a message indicating continued use, thereby reducing the amount of response required by engineer E.
[0042] As described above, the anomaly monitoring system 100 can reduce the number of times to respond to alarms caused by soft errors.
[0043] 2. Configuration and Processing of Each Device in the Anomaly Monitoring System 100 The configuration and processing of each device included in the abnormality monitoring system 100 shown in Fig. 1 will be described using Fig. 4. Fig. 4 is a block diagram showing an example configuration of each device of the abnormality monitoring system 100 according to the embodiment. Below, an example configuration of the entire abnormality monitoring system 100 according to the embodiment, an example configuration and processing of the control device 10, an example configuration and processing of the engineer terminal 20, and an example configuration and processing of the field device 30 will be described.
[0044] (2-1. Example of the overall configuration of the abnormality monitoring system 100) An example of the overall configuration of the abnormality monitoring system 100 will be described. The abnormality monitoring system 100 is composed of a control device 10, an engineer terminal 20, and field devices 30 (30-1, 30-2, 30-3, ...). The control device 10, the engineer terminal 20, and the field devices 30 are communicatively connected via a communication network N, which may be the Internet or a dedicated line, and an input / output module M (not shown).
[0045] (2-2. Configuration Example and Processing Example of Control Device 10) We will now explain a configuration example and processing example of the control device 10. The control device 10 is composed of a communication unit 11, a storage unit 12, and a control unit 13. The control device 10 may also have an input unit (e.g., keyboard, mouse) that accepts various operations from the administrator of the anomaly monitoring system 100, and a display unit (e.g., liquid crystal display) that displays various information.
[0046] (2-2-1. Communications Department 11) The communication unit 11 controls data communication with other devices. For example, the communication unit 11 executes data communication with each communication device via a router or the like. The communication unit 11 can also execute data communication with a terminal (not shown).
[0047] (2-2-2. Storage section 12) The storage unit 12 stores various pieces of information that the control unit 13 references when it operates and various pieces of information that the control unit 13 acquires when it operates. The storage unit 12 includes a detection result storage unit 12a, an alarm information storage unit 12b, and a report information storage unit 12c. Here, the storage unit 12 can be realized by, for example, a semiconductor memory element such as a random access memory (RAM) or a flash memory, or a storage device such as a hard disk or an optical disk. In the example of FIG. 4, the storage unit 12 is installed inside the control device 10, but it may be installed outside the control device 10, or multiple storage units may be installed.
[0048] (2-2-2-1. Detection result storage unit 12a) The detection result storage unit 12a stores the detection results. For example, the detection result storage unit 12a stores the detection results output by a detection unit 13b of the control unit 13, which will be described later. Here, an example of data stored in the detection result storage unit 12a will be described with reference to FIG. 5. FIG. 5 is a diagram showing an example of the detection result storage unit 12a of the control device 10 according to the embodiment. In the example of FIG. 5, the detection result storage unit 12a has items such as "monitoring target," "detection date and time," "detection location," "detected abnormality," and "detection count."
[0049] The "monitoring target" indicates identification information for identifying the control system that is the monitoring target or controlled by the control device 10, such as the identification number or identification symbol of the plant control system. The "detection date and time" indicates the date and time when the detection result was output, such as the year, month, day, hour, minute, and second. The "detection location" indicates identification information for identifying the location where the abnormality was detected, such as the identification number or identification symbol of the processor module P, the identification number or identification symbol of the input / output module M, or the identification number or identification symbol of the field device 30 connected to the input / output module M. The "detected abnormality" indicates the type of abnormality detected, such as transient abnormalities, internal memory diagnosis abnormalities, and non-soft error abnormalities such as physical abnormalities and communication abnormalities. The "detection count" indicates the total number of detected abnormalities, such as the total number of transient abnormalities detected in the same processor module P, or the total number of internal memory diagnosis abnormalities detected in the same input / output module M.
[0050] That is, Figure 5 shows an example in which the following data is stored in the detection result memory unit 12a for the monitored object identified by "control system #1", including {detection date and time: "detection date and time #1", detection location: "processor module #A-1", detected abnormality: "transient abnormality", number of detections: "1st time"}, {detection date and time: "detection date and time #2", detection location: "input / output module #1-2", detected abnormality: "internal memory diagnosis abnormality", number of detections: "1st time"}, {detection date and time: "detection date and time #3", detection location: "input / output module #1-2", detected abnormality: "internal memory diagnosis abnormality", number of detections: "2nd time"}, etc.
[0051] (2-2-2-2. Alarm information storage unit 12b) The alarm information storage unit 12b stores alarm information. For example, the alarm information storage unit 12b stores alarms output by an execution unit 13c of the control unit 13, which will be described later, and alarms notified by a notification unit 13d. An example of data stored in the alarm information storage unit 12b will now be described with reference to FIG. 6. FIG. 6 is a diagram showing an example of the alarm information storage unit 12b of the control device 10 according to the embodiment. In the example of FIG. 6, the alarm information storage unit 12b has items such as "monitoring target," "detection date and time," "system alarm," "alarm mask," and "continuous use message."
[0052] The "monitoring target" indicates identification information for identifying the control system being monitored or controlled by the control device 10, such as the identification number or symbol of the plant control system. The "detection date and time" indicates the date and time when the detection result was output, such as the year, month, day, hour, minute, and second. The "system alarm" indicates a system alarm indicating an abnormality detected in the control system, such as an alarm indicating an action based on an abnormality detected by the detection unit 13b in the processor module P or the input / output module M, such as transition to the "Fail" state, transition to the "Control" side, transition to the "Standby" side, execution of a "Self Diag Error" self-diagnosis error, or execution of a "Copy" data copy. The "alarm mask" indicates whether or not a system alarm indicating an abnormality occurring in the control system is masked, such as "○" if the alarm is not displayed and "-" if the alarm is displayed. The "continuous usability message" is a message based on the abnormality added by the execution unit 13c, such as a "Recover Continuously Usable" message.
[0053] That is, Figure 6 shows an example in which the following data is stored in the alarm information storage unit 12b for the monitored object identified by "control system #1", including {Detection date and time: "Detection date and time #1", system alarm: "System alarm #A-1", alarm mask: "○", continued use message: "Continued use message #A-1"}, {Detection date and time: "Detection date and time #2", system alarm: "System alarm #1-2", alarm mask: "○", continued use message: "Continued use message #1-2"}, {Detection date and time: "Detection date and time #3", system alarm: "System alarm #1-2", alarm mask: "-", continued use message: "Continued use message #1-2"}, ...
[0054] (2-2-2-3. Report information storage unit 12c) The report information storage unit 12c stores report information. For example, the report information storage unit 12c stores a system report indicating the history of system alarms stored by the alarm information storage unit 12b described above. An example of data stored in the report information storage unit 12c will now be described with reference to FIG. 7. FIG. 7 is a diagram illustrating an example of the report information storage unit 12c of the control device 10 according to the embodiment. In the example of FIG. 7, the report information storage unit 12c has items such as "Monitoring target" and "System report."
[0055] The "monitoring target" indicates identification information for identifying the control system that is the monitoring target or controlled by the control device 10, such as the identification number or identification symbol of the plant control system. The "system report" indicates a history of system alarms indicating abnormalities that have occurred in the control system, and is a report showing, for example, a history of alarms indicating processing based on abnormalities detected by the detection unit 13b in the processor module P or the input / output module M, such as a transition to the fail state "Fail," a transition to the control side "Control," a transition to the standby side "Stand-By," a self-diagnosis error alarm "Self Diag Error," and execution of data duplication "Copy." The "system report" is also a report including, for example, a history of alarms including messages based on abnormalities added by the execution unit 13c, such as a message indicating continued use "Recover Continuously Usable."
[0056] That is, FIG. 7 shows an example in which data that is "system alarm #1" for a monitoring target identified by "control system #1" is stored in the report information storage unit 12c.
[0057] (2-2-3. Control unit 13) The control unit 13 is responsible for overall control of the control device 10. The control unit 13 is composed of a collection unit 13a, a detection unit 13b, an execution unit 13c, and a notification unit 13d. Here, the control unit 13 is, for example, one of the duplicated processor modules P that currently executes each process, and can be realized by an electronic circuit such as a CPU (Central Processing Unit) or an MPU (Micro Processing Unit), or an integrated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).
[0058] (2-2-3-1. Collection unit 13a) The collection unit 13a collects various types of information. The collection unit 13a may store the collected various types of information in the storage unit 12. The data collection process will be described below.
[0059] (Data collection and processing) The collection unit 13a executes a data collection process. For example, the collection unit 13a collects data from devices that constitute a system. In this case, the system is, for example, a plant. The devices are, for example, field devices 30 that constitute the plant. That is, the collection unit 13a collects measurement data from, for example, each field device 30 that constitutes the plant via each input / output module M.
[0060] A specific example of data collection processing will be described. The collector 13a collects "measurement data #1" as measurement data acquired by field device 30-1 in "control system #1" via "input / output module #1-1," which is input / output module M-1. The collector 13a also collects "measurement data #2" as measurement data acquired by field device 30-2 in "control system #1" via "input / output module #1-2," which is input / output module M-2. The collector 13a also collects "measurement data #3" as measurement data acquired by field device 30-3 in "control system #1" via "input / output module #1-3," which is input / output module M-3.
[0061] (2-2-3-2. Detector 15b) The detection unit 15b outputs the detection result. The detection unit 15b may store the output detection result in the storage unit 12. The abnormality detection process will be described below.
[0062] (Abnormality detection processing) The detector 13b executes an abnormality detection process. For example, the detector 13b detects an abnormality that has occurred in at least one of the processor module P and the input / output module M based on the collected data. At this time, the detector 13b detects a transient abnormality that has occurred in the processor module P. The detector 13b also detects an internal memory diagnosis abnormality that has occurred in the input / output module M.
[0063] Here, a transient abnormality is an abnormality that may be caused by a soft error occurring in the processor module P or the input / output module M of the control device 10, and is an automatically recoverable abnormality indicated by a specific object code. Also, an internal memory diagnosis abnormality is an abnormality that is caused by a soft error occurring in the input / output module M of the control device 10, and is an automatically recoverable abnormality indicated by a specific object code. Note that the internal memory diagnosis abnormality can be identified by the control device 10 executing a self-diagnosis (hardware diagnosis).
[0064] A specific example of the abnormality detection process in the processor module P will be described. First, the detector 13b acquires "measured data #1," "measured data #2," and "measured data #3" as data collected by the collector 13a in the "control system #1." Second, the detector 13b acquires the "measured data #1" from the "measured data #1" and the "measured data #2," and the "measured data #3." Second, the detector 13b acquires the "measured data #1" from the processor module P on the control side. C Third, the detection unit 13b refers to the detection result storage unit 12a and determines that the "transient abnormality" that has occurred in the "processor module #A-1" is the first. Fourth, the detection unit 13b stores, as the detection result, {detection date and time: "detection date and time #1", detected location: "processor module #A-1", detected abnormality: "transient abnormality", number of detections: "first time"} in the detection result storage unit 12a corresponding to {monitored object: "control system #1"}.
[0065] A specific example of the abnormality detection process in the input / output module M will be described. First, the detection unit 13b acquires "measured data #1," "measured data #2," and "measured data #3" as data collected by the collection unit 13a in the "control system #1." Second, the detection unit 13b detects an abnormality in the input / output module M on the control side from the "measured data #2." C Third, the detection unit 13b executes a self-diagnosis on the "input / output module #1-2" to detect whether or not there is any hardware damage, thereby identifying that the abnormality that occurred in the "input / output module #1-2" is an "internal memory diagnosis abnormality." Fourth, the detection unit 13b refers to the detection result storage unit 12a and identifies that this is the second time that the "internal memory diagnosis abnormality" has occurred in the "input / output module #1-2." Fifth, the detection unit 13b stores, as the detection result, {detection date and time: "detection date and time #3," detection location: "input / output module #1-2," detected abnormality: "internal memory diagnosis abnormality," number of detections: "second time"} in the detection result storage unit 12a corresponding to {monitored object: "control system #1"}.
[0066] (2-2-3-3. Executive Unit 13c) The execution unit 13c executes various processes. The execution unit 13c may store the output execution results in the storage unit 12. The alarm information output process, the report information output process, and the action execution process will be described below.
[0067] (Alarm information output processing) The execution unit 13c executes an alarm information output process. For example, the execution unit 13c outputs an alarm indicating a detected abnormality. At this time, if the execution unit 13c detects a transient abnormality in the processor module P, it outputs a system alarm for the transient abnormality. Furthermore, if the execution unit 13c detects an internal memory diagnosis abnormality in the input / output module M, it outputs a system alarm for the internal memory diagnosis abnormality.
[0068] A specific example of the alarm information output process in the processor module P will be described. First, the execution unit 13c refers to {detection date and time: "detection date and time #1", detected location: "processor module #A-1", detected abnormality: "transient abnormality", number of detections: "first time"} as the detection result stored in the detection result storage unit 12a. Second, the execution unit 13c refers to the storage unit 12 and outputs "system alarm #A-1" including a code corresponding to the "transient abnormality" and each process based on the "transient abnormality". Third, the execution unit 13c stores {detection date and time: "detection date and time #1", system alarm: "system alarm #A-1"} in the alarm information storage unit 12b corresponding to {monitored object: "control system #1"}.
[0069] A specific example of the alarm information output process in the input / output module M will be described. First, the execution unit 13c refers to {detection date and time: "detection date and time #1", detected location: "input / output module #1-2", detected abnormality: "internal memory diagnosis abnormality", number of detections: "second time"} as the detection result stored in the detection result storage unit 12a. Second, the execution unit 13c refers to the storage unit 12 and outputs "system alarm #1-2" including a code corresponding to the "internal memory diagnosis abnormality" and each process based on the "internal memory diagnosis abnormality". Third, {detection date and time: "detection date and time #3", system alarm: "system alarm #1-2"} is stored in the alarm information storage unit 12b corresponding to {monitored object: "control system #1"}.
[0070] (Report information output processing) The execution unit 13c executes a report information output process. For example, the execution unit 13c outputs a report indicating an alarm history. At this time, if the execution unit 13c detects a transient abnormality in the processor module P, it outputs a system report indicating a system alarm history for the transient abnormality. Furthermore, if the execution unit 13c detects an internal memory diagnosis abnormality in the input / output module M, it outputs a system report indicating a system alarm history for the internal memory diagnosis abnormality.
[0071] A specific example of the report information output process in the processor module P will be described. The execution unit 13c refers to the alarm information in the processor module P stored in the alarm information storage unit 12b, and stores {detection date and time: "detection date and time #1", system alarm: "system alarm #A-1"} in the report information storage unit 12c corresponding to {monitoring target: "control system #1"}. Similarly, the execution unit 13c refers to the alarm information in the processor module P stored in the alarm information storage unit 12b, and stores {detection date and time: "detection date and time #4", system alarm: "system alarm #B-1"} in the report information storage unit 12c corresponding to {monitoring target: "control system #1"}.
[0072] A specific example of the report information output process in the input / output module M will be described. The execution unit 13c refers to the alarm information in the input / output module M stored in the alarm information storage unit 12b, and stores {detection date and time: "detection date and time #2", system alarm: "system alarm #1-2"} in the report information storage unit 12c corresponding to {monitoring target: "control system #1"}. Similarly, the execution unit 13c refers to the alarm information in the input / output module M stored in the alarm information storage unit 12b, and stores {detection date and time: "detection date and time #3", system alarm: "system alarm #1-2"} in the report information storage unit 12c corresponding to {monitoring target: "control system #1"}.
[0073] (Action execution process) The execution unit 13c executes an action execution process. For example, if the detected abnormality is likely to be caused by a soft error, the execution unit 13c executes an action for an alarm indicating the abnormality. At this time, if the execution unit 13c detects a transient abnormality in the processor module P, it masks the alarm indicating the transient abnormality. Furthermore, if the execution unit 13c detects a transient abnormality in the processor module P, it attaches a message indicating that continued use is possible to the alarm. Furthermore, if the execution unit 13c detects an internal memory diagnostic abnormality in the input / output module M, it masks the alarm indicating the internal memory diagnostic abnormality. Furthermore, if the execution unit 13c detects an internal memory diagnostic abnormality in the input / output module M, it attaches a message indicating that continued use is possible to the alarm.
[0074] A specific example of the action execution process in the processor module P will be described. First, the execution unit 13c refers to {detection date and time: "detection date and time #1", detected location: "processor module #A-1", detected abnormality: "transient abnormality", number of detections: "first time"} as the detection result stored in the detection result storage unit 12a. Second, the execution unit 13c refers to {detection date and time: "detection date and time #1", system alarm: "system alarm #A-1"} as the alarm stored in the alarm information storage unit 12b. Third, the execution unit 13c refers to the storage unit 12 and determines that the alarm mask function set by engineer E is "enabled". Fourth, the execution unit 13c refers to the storage unit 12 and determines that the continuously usable message addition function set by engineer E is "enabled". Fifth, the execution unit 13c refers to {detection number: "first time"} and determines that "system alarm #A-1" is the target of alarm mask execution. Sixth, the execution unit 13c executes an alarm mask on "system alarm #A-1". Seventh, the execution unit 13c assigns "continuous use possible message #A-1" to "system alarm #A-1". Eighth, the execution unit 13c stores {detection date and time: "detection date and time #1", system alarm: "system alarm #A-1", alarm mask: "○", continuous use possible message: "continuous use possible message #A-1"} in the alarm information storage unit 12b.
[0075] A specific example of the action execution process in the input / output module M will be described. First, the execution unit 13c refers to {detection date and time: "detection date and time #3", detection location: "input / output module #1-2", detected abnormality: "internal memory diagnosis abnormality", number of detections: "second time"} as the detection result stored in the detection result storage unit 12a. Second, the execution unit 13c refers to {detection date and time: "detection date and time #3", system alarm: "system alarm #1-2"} as the alarm stored in the alarm information storage unit 12b. Third, the execution unit 13c refers to the storage unit 12 and determines that the alarm mask function set by engineer E is "enabled". Fourth, the execution unit 13c refers to the storage unit 12 and determines that the continuously usable message addition function set by engineer E is "enabled". Fifth, the execution unit 13c refers to {detection number: "second time"} and determines that "system alarm #1-2" is not a target for alarm masking. Sixth, the execution unit 13c assigns "Continuous use possible message #1-2" to "System alarm #1-2." Seventh, the execution unit 13c stores {Detection date and time: "Detection date and time #3", System alarm: "System alarm #1-2", Alarm mask: "-", Continuous use possible message: "Continuous use possible message #1-2"} in the alarm information storage unit 12b.
[0076] (2-2-3-4.Notification section 13d) The notification unit 13d notifies various types of information. Note that the notification unit 13d may refer to various types of information stored in the storage unit 12. The alarm information transmission process and the alarm information retransmission process will be described below.
[0077] (Alarm information transmission process) The notification unit 13d executes an alarm information transmission process. For example, the notification unit 13d notifies the user of an alarm for which an action has been executed by transmitting alarm information to a user terminal. Furthermore, when a transient abnormality that has occurred in the processor module P is detected, the notification unit 13d notifies the user of an alarm for which masking has been executed. Furthermore, when a transient abnormality that has occurred in the same processor module P is detected for the second or subsequent time, the notification unit 13d notifies the user of an alarm for which masking has been executed. Furthermore, when a transient abnormality that has occurred in the processor module P is detected, the notification unit 13d notifies the user of an alarm with a message indicating that the processor module P can continue to be used.
[0078] When an internal memory diagnostic abnormality that has occurred in the input / output module M is detected, the notification unit 13d notifies the user of an alarm for which masking has been performed. Furthermore, when an internal memory diagnostic abnormality is detected for the second or subsequent time in the same input / output module M, the notification unit 13d notifies the user of an alarm for which masking has not been performed. Furthermore, when an internal memory diagnostic abnormality that has occurred in the input / output module M is detected, the notification unit 13d notifies the user of an alarm with a message indicating that the module can continue to be used.
[0079] A specific example of the alarm information transmission process in the processor module P will be described. The notification unit 13d refers to the alarm information stored in the alarm information storage unit 12b, which is {Detection date and time: "Detection date and time #1", system alarm: "System alarm #A-1", alarm mask: "○", continued use possible message: "Continued use possible message #A-1"}, and transmits the referred alarm information to the engineer terminal 20.
[0080] A specific example of the alarm information transmission process in the input / output module M will be described below. First, the notification unit 13d refers to the alarm information stored in the alarm information storage unit 12b, which is {Detection date and time: "Detection date and time #3", system alarm: "System alarm #1-2", alarm mask: "-", continued use possible message: "continuous use possible message #1-2"}, and transmits the referred alarm information to the engineer terminal 20.
[0081] (Alarm information retransmission process) The notification unit 13d executes an alarm information retransmission process. For example, if the processor module P does not recover from a transient abnormality that has occurred, the notification unit 13d notifies the user of an alarm for which no masking is performed. Also, if the input / output module M does not recover from an internal memory diagnosis abnormality that has occurred, the notification unit 13d notifies the user of an alarm for which no masking is performed.
[0082] A specific example of the alarm information retransmission process in the processor module P will be described. When the processor module P does not recover from a transient abnormality that has occurred, the notification unit 13d refers to the alarm information stored in the alarm information storage unit 12b, which is {Detection date and time: "Detection date and time #1", system alarm: "System alarm #A-1", alarm mask: "○", continued use available message: "continuous use available message #A-1"}, and retransmits to the engineer terminal 20 the alarm information that does not include {Alarm mask: "○", continued use available message: "continuous use available message #A-1"} from the referred alarm information.
[0083] A specific example of the alarm information retransmission process in the input / output module M will be described. When the input / output module M does not recover from the internal memory diagnostic abnormality that occurred, the notification unit 13d refers to the alarm information stored in the alarm information storage unit 12b, which is {Detection date and time: "Detection date and time #3", system alarm: "System alarm #1-2", alarm mask: "-", continued use available message: "continuous use available message #1-2"}, and retransmits to the engineer terminal 20 the alarm information that does not include {Alarm mask: "-", continued use available message: "continuous use available message #1-2"} from the referred alarm information.
[0084] (2-3. Configuration and Processing Examples of Engineer Terminal 20) 4 again, a description will be given of an example of the configuration and processing of the engineer terminal 20. The engineer terminal 20 is an administrator terminal used by engineer E, who is the administrator of the anomaly monitoring system 100, and includes an input / output unit 21, a control unit 22, and a communication unit 23.
[0085] (2-3-1. Input / output section 21) The input / output unit 21 controls the input of various information to the engineer terminal 20. For example, the input / output unit 21 is realized by a mouse, a keyboard, a touch panel, or the like, and accepts input of setting information, etc. to the engineer terminal 20. The input / output unit 21 also displays various information from the engineer terminal 20. For example, the input / output unit 21 is realized by a display, etc., and displays setting information, etc. stored in the engineer terminal 20.
[0086] The input / output unit 21 displays a system alarm view, which is a screen viewed by engineer E and displays system alarms. Details of the system alarm view will be described later in [3. Specific examples of processes in the abnormality monitoring system 100]. The input / output unit 21 also displays a historical message report window, which is a screen viewed by engineer E and displays a system report. Details of the historical message report window will be described later in [3. Specific examples of processes in the abnormality monitoring system 100].
[0087] (2-3-2. Control unit 22) The control unit 22 transmits various types of information. For example, the control unit 22 transmits to the control device 10 an alarm mask function setting, which indicates whether or not an alarm is masked, a continuously usable message addition function setting, which indicates whether or not a continuously usable message is added, and the like, which are input by the engineer E.
[0088] The control unit 22 receives various types of information. For example, the control unit 22 receives alarm information, report information, etc., displayed by the input / output unit 21 from the control device 10.
[0089] (2-3-3. Communications Department 23) The communication unit 23 controls data communication with other devices. For example, the communication unit 23 performs data communication with each communication device via a router, etc. The communication unit 23 can also perform data communication with an operator's terminal (not shown).
[0090] (2-4. Example of configuration and processing of field device 30) A description will be given of a configuration example and a processing example of the field device 30. The field device 30 is a device that constitutes a system. For example, the field device 30 is a device that constitutes a plant, and is a measuring instrument such as a pressure gauge, a flow meter, or a vibrometer.
[0091] The field device 30 acquires data in the system. For example, the field device 30 acquires measurement data such as pressure, flow rate, and vibration in the plant. The field device 30 also transmits the acquired measurement data to the control device 10 via the input / output module M.
[0092] The field device 30 receives a control signal in the system. For example, the field device 30 receives a control signal transmitted by the control device 10 via the input / output module M.
[0093] 3. Specific Examples of Processes in the Anomaly Monitoring System 100 8 to 17, specific examples of the processes of the anomaly monitoring system 100 according to the embodiment will be described. Specific examples 1 to 4 of the processes of the anomaly monitoring system 100 will be described below.
[0094] (3-1. Example 1) Here, a specific example 1 of each process of the anomaly monitoring system 100 will be described with reference to Fig. 8. Fig. 8 is a diagram showing a specific example 1 of each process of the anomaly monitoring system 100 according to the embodiment. The states and transitions of the processor module P of the control device 10 will be described below.
[0095] (3-1-1. "Fail") As shown in the example of FIG. 8(1), when an abnormality is detected in the processor module P, the control device 10 indicates a "Fail" state, which is a stopped state, and notifies a "Fail" alarm to the engineer E. At this time, when an automatic restart is executed from the stopped state, the control device 10 transitions to a "Hard Ready" state, which is a state in which the hardware is ready to start up (see FIG. 8(2)).
[0096] (3-1-2. "Hard Ready") As shown in the example of FIG. 8(2), when the control device 10 is ready to start up the hardware, it indicates the "Hard Ready" state, which is the state of preparation for hardware startup, and notifies engineer E of the "Hard Ready" alarm. At this time, if an abnormality is detected in the processor module P, the control device 10 transitions to the "Fail" state, which is a stopped state (see FIG. 8(1)). Furthermore, when the processor module P transitions to the control side, the control device 10 transitions to the "Control" state, which is a control state (see FIG. 8(3)). Furthermore, when the processor module P transitions to the standby side, the control device 10 transitions to the "Stand-By" state, which is a standby state (see FIG. 8(4)).
[0097] (3-1-3. "Control") As shown in the example of FIG. 8(3), when the processor module P transitions to the control side, the control device 10 indicates the "Control" state, which is the control state, and notifies the engineer E of the "Control" alarm. At this time, if an abnormality is detected in the processor module P, the control device 10 transitions to the "Fail" state, which is the stopped state (see FIG. 8(1)).
[0098] (3-1-4. "Stand-By") As shown in the example of FIG. 8(4), when the processor module P transitions to the standby side, the control device 10 indicates the standby state "Stand-By" and notifies the engineer E of a "Stand-By" alarm. At this time, if an abnormality is detected in the processor module P, the control device 10 transitions to the stopped state "Fail" (see FIG. 8(1)). Furthermore, when the processor module P transitions to the control side, the control device 10 transitions to the control state "Control" (see FIG. 8(3)).
[0099] (3-2. Example 2) 9 to 13, a specific example 2 of each process of the abnormality monitoring system 100 will be described. Below, a system alarm view and a historical message report window for a transient abnormality in the processor module P of the control device 10 will be described.
[0100] (3-2-1. Example 2-1) A specific example 2-1 of each process of the anomaly monitoring system 100 will be described using Fig. 9. Fig. 9 is a diagram showing a specific example 2-1 of each process of the anomaly monitoring system 100 according to the embodiment. Below, a display example will be described of the display screen of the system alarm view and historical message report window in the event of a transient anomaly in the processor module P of the control device 10, in which recovery is achieved by automatic restart after the first transient anomaly occurs.
[0101] As shown in the example of the "System Alarm View" in FIG. 9(1), when an abnormality is detected in the processor module P and the alarm mask function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 9(1), the engineer terminal 20 displays alarms in the following order: "LEFT Fail..." (left CPU is in a failed state), "Control Transfer" (control CPU is being transferred), "RIGHT Control" (right CPU is in a control state), "Copy" (data duplication in progress), and "LEFT Stand-By" (left CPU is in a standby state). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Furthermore, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0102] As shown in the example of the "Historical Message Report Window" in FIG. 9(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0103] As shown in the example of the "System Alarm View" in Fig. 9(2), when an abnormality is detected in the processor module P and the alarm mask function setting is enabled, the engineer terminal 20 displays the system alarm for which the alarm mask has been executed. In the example of the "System Alarm View" in Fig. 9(2), the "System Alarm View" in Fig. 9(1) is not displayed.
[0104] As shown in the example of the "Historical Message Report Window" in FIG. 9(2), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0105] As described above, when a transient abnormality occurs for the first time in the processor module P and the alarm mask function setting is enabled, the control device 10 hides the system alarm, thereby reducing the amount of alarm response required by engineer E. Furthermore, the control device 10 enables engineer E to respond to the alarm as needed by making the system report viewable. Note that, because the control device 10 cannot determine whether a transient abnormality in the processor module P is due to a soft error, it masks all alarms when a transient abnormality occurs for the first time in the processor module P.
[0106] (3-2-2. Example 2-2) A specific example 2-2 of each process of the anomaly monitoring system 100 will be described using Fig. 10. Fig. 10 is a diagram showing a specific example 2-2 of each process of the anomaly monitoring system 100 according to the embodiment. Below, a display example 1 will be described, which is a display screen of the system alarm view and historical message report window for a transient anomaly in the processor module P of the control device 10, in which the system does not recover by automatic restart after the first transient anomaly occurs.
[0107] As shown in the example of the "System Alarm View" in FIG. 10(1), when an abnormality is detected in the processor module P and the alarm mask function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 10(1), the engineer terminal 20 displays alarms in the following order: "LEFT Fail..." (the left CPU is in a failed state), "Control Transfer" (the control CPU is being transferred), and "RIGHT Control" (the right CPU is in a controlled state). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Also, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0108] As shown in the example of the "Historical Message Report Window" in FIG. 10(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0109] As shown in the example of the "System Alarm View" in Figure 10(2), when an abnormality is detected in the processor module P, the alarm mask function setting is enabled, and the processor module does not recover by an automatic restart, the engineer terminal 20 displays the system alarm for which the alarm mask was executed, as well as the system alarm indicating the occurrence of the abnormality. In the example of the "System Alarm View" in Figure 10(2), the "System Alarm View" in Figure 10(1) is hidden, and the alarm "LEFT Fail..." (the left CPU is in a failed state) is notified again and displayed (see the dashed rectangle in the "System Alarm View" in Figure 10(2)).
[0110] As shown in the example of the "Historical Message Report Window" in Figure 10(2), the engineer terminal 20 displays a system report with the same content as the system alarm that does not execute alarm masking, and the alarm "LEFT Fail..." (the left CPU is in a failed state) is notified and displayed again (see the dashed rectangle in the "Historical Message Report Window" in Figure 10(2)).
[0111] As described above, when a first transient abnormality occurs in processor module P, the alarm mask function setting is enabled, and the processor module P does not recover by automatic restart, the control device 10 displays the system alarm for which alarm masking has been performed, as well as the system alarm indicating the occurrence of an abnormality, thereby notifying engineer E that a response to the alarm is required. In addition, the control device 10 makes the system report viewable, thereby enabling engineer E to respond to the alarm as necessary.
[0112] (3-2-3. Example 2-3) A specific example 2-3 of each process of the anomaly monitoring system 100 will be described using Fig. 11. Fig. 11 is a diagram showing a specific example 2-3 of each process of the anomaly monitoring system 100 according to the embodiment. Below, a display example 2 will be described, which is a display screen of the system alarm view and historical message report window for a transient anomaly in the processor module P of the control device 10, in which the system does not recover by automatic restart after the first transient anomaly occurs.
[0113] As shown in the example of the "System Alarm View" in FIG. 11(1), when an abnormality is detected in the processor module P and the alarm mask function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 11(1), the engineer terminal 20 displays alarms in the following order: "LEFT Fail ..." (left CPU is in a failed state), "Control Transfer" (control CPU is being transferred), "RIGHT Control" (right CPU is in a controlled state), "Copy" (data duplication in progress), and "LEFT Fail ..." (left CPU is in a failed state). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Also, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0114] As shown in the example of the "Historical Message Report Window" in FIG. 11(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0115] As shown in the example of the "System Alarm View" in Figure 11(2), when an abnormality is detected in the processor module P, the alarm mask function setting is enabled, and the processor module does not recover by an automatic restart, the engineer terminal 20 displays the system alarm for which the alarm mask was executed, as well as the system alarm indicating the occurrence of the abnormality. In the example of the "System Alarm View" in Figure 11(2), the "System Alarm View" in Figure 11(1) is hidden, and the alarm "LEFT Fail..." (the left CPU is in a failed state) is notified again and displayed (see the dashed rectangle in the "System Alarm View" in Figure 11(2)).
[0116] As shown in the example of the "Historical Message Report Window" in Figure 11(2), the engineer terminal 20 displays a system report with the same content as the system alarm that does not execute alarm masking, and the alarm "LEFT Fail..." (the left CPU is in a failed state) is notified and displayed again (see the dashed rectangle in the "Historical Message Report Window" in Figure 11(2)).
[0117] As described above, when a first transient abnormality occurs in processor module P, the alarm mask function setting is enabled, and the processor module P does not recover by automatic restart, the control device 10 displays the system alarm for which alarm masking has been performed, as well as the system alarm indicating the occurrence of an abnormality, thereby notifying engineer E that a response to the alarm is required. In addition, the control device 10 makes the system report viewable, thereby enabling engineer E to respond to the alarm as necessary.
[0118] (3-2-4. Example 2-4) A specific example 2-4 of each process of the anomaly monitoring system 100 will be described using Fig. 12. Fig. 12 is a diagram showing a specific example 2-4 of each process of the anomaly monitoring system 100 according to the embodiment. Below, a display example will be described of the display screen of the system alarm view and historical message report window in the event of a transient anomaly in the processor module P of the control device 10, in which recovery is achieved by automatic restart after the second or subsequent transient anomaly has occurred.
[0119] As shown in the example of the "System Alarm View" in FIG. 12(1), when an abnormality is detected in the processor module P and the alarm mask function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 12(1), the engineer terminal 20 displays alarms in the following order: "LEFT Fail..." (left CPU is in a failed state), "Control Transfer" (control CPU is being transferred), "RIGHT Control" (right CPU is in a control state), "Copy" (data duplication in progress), and "LEFT Stand-By" (left CPU is in a standby state). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Also, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0120] As shown in the example of the "Historical Message Report Window" in FIG. 12(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0121] As shown in the example of the "System Alarm View" in Fig. 12(2), when an abnormality is detected in the processor module P, the alarm mask function setting is enabled, the processor module P is restored by an automatic restart, and the abnormality is a transient abnormality occurring for the second or subsequent times, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in Fig. 12(2), the "System Alarm View" in Fig. 12(1) is displayed.
[0122] As shown in the example of the "Historical Message Report Window" in FIG. 12(2), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0123] As described above, when a transient abnormality occurs in the processor module P for the second or subsequent time, the control device 10 notifies the engineer E that a response to the alarm is required by displaying the system alarm, even if the processor module P is restored by an automatic restart. In addition, the control device 10 enables the engineer E to respond to the alarm as necessary by making the system report viewable.
[0124] (3-2-5. Example 2-5) A specific example 2-5 of each process of the anomaly monitoring system 100 will be described using Fig. 13. Fig. 13 is a diagram showing a specific example 2-5 of each process of the anomaly monitoring system 100 according to the embodiment. Below, a display example will be described of the display screen of the system alarm view and historical message report window in the event of a transient anomaly in the processor module P of the control device 10, in which the system does not recover by automatic restart after the second or subsequent transient anomaly has occurred.
[0125] As shown in the example of the "System Alarm View" in FIG. 13(1), when an abnormality is detected in the processor module P and the alarm mask function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 13(1), the engineer terminal 20 displays alarms in the order of "LEFT Fail..." (the left CPU is in a failed state), "Control Transfer" (the control CPU is being transferred), and "RIGHT Control" (the right CPU is in a control state). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Also, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0126] As shown in the example of the "Historical Message Report Window" in FIG. 13(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0127] As shown in the example of the "System Alarm View" in Fig. 13(2), when an abnormality is detected in the processor module P, the alarm mask function setting is enabled, the abnormality does not return to normal through an automatic restart, and the abnormality is a second or subsequent transient abnormality, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in Fig. 13(2), the "System Alarm View" in Fig. 13(1) is in a display state.
[0128] As shown in the example of the "Historical Message Report Window" in FIG. 13(2), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0129] As described above, when a transient abnormality occurs in the processor module P for the second or subsequent time and the processor module P does not recover by automatic restart, the control device 10 displays a system alarm to notify the engineer E that the alarm needs to be addressed. The control device 10 also makes the system report viewable, enabling the engineer E to address the alarm as necessary.
[0130] (3-3. Example 3) 14 to 16, a specific example 3 of each process of the abnormality monitoring system 100 will be described. Below, a system alarm view and a historical message report window for a transient abnormality in the input / output module M of the control device 10 will be described.
[0131] (3-3-1. Example 3-1) A specific example 3-1 of each process of the abnormality monitoring system 100 will be described using Fig. 14. Fig. 14 is a diagram showing a specific example 3-1 of each process of the abnormality monitoring system 100 according to the embodiment. Below, a display example will be described of the display screen of the system alarm view and historical message report window in the case of a transient abnormality in the input / output module M of the control device 10, in which recovery is achieved by automatic restart after the first internal memory diagnosis abnormality occurs.
[0132] As shown in the example of the "System Alarm View" in FIG. 14(1), when an abnormality is detected in the input / output module M and the alarm masking function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 14(1), the engineer terminal 20 displays alarms in the following order: "IOM Fail N-IO..." (bus node IOM is in a failed state), "IOM Out Service..." (IOM unavailable), "IOM In Service..." (IOM available), "N-IO Self Diag Error..." (bus node self-diagnosis error), "IOM Recover N-IO..." (bus node IOM has recovered), and "N-IO Self Diag Recover..." (bus node self-diagnosis recovery). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Furthermore, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0133] As shown in the example of the "Historical Message Report Window" in FIG. 14(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0134] As shown in the example of the "System Alarm View" in FIG. 14(2), when an abnormality is detected in the input / output module M and the alarm mask function setting is enabled, the engineer terminal 20 displays the system alarm for which the alarm mask has been executed. At this time, the control device 10 uses the self-diagnosis function to determine whether the transient abnormality is an internal memory diagnosis abnormality, and if it is an internal memory diagnosis abnormality, executes the alarm mask. In the example of the "System Alarm View" in FIG. 14(2), the "System Alarm View" in FIG. 14(1) is not displayed.
[0135] As shown in the example of the "Historical Message Report Window" in Figure 14(2), the engineer terminal 20 displays a system report with the same content as a system alarm that does not execute alarm masking. In the case of an abnormality in the input / output module M indicated by a specific code, the control device 10 delays notification of the alarm indicated by the dashed-dotted rectangle until it has completed determining whether the abnormality is due to an internal memory diagnostic abnormality.
[0136] As described above, when the first internal memory diagnosis abnormality occurs in the input / output module M and the alarm mask function setting is enabled, the control device 10 hides the system alarm, thereby reducing the amount of time that engineer E has to respond to the alarm. Furthermore, the control device 10 makes the system report viewable, thereby enabling engineer E to respond to the alarm as needed. Note that, since the control device 10 can determine whether a transient abnormality in the input / output module M is due to a soft error through hardware diagnosis, it executes alarm masking only when the first internal memory diagnosis abnormality occurs in the input / output module M, i.e., when an abnormality due to a soft error occurs.
[0137] (3-3-2. Example 3-2) A specific example 3-2 of each process of the anomaly monitoring system 100 will be described using Fig. 15. Fig. 15 is a diagram showing a specific example 3-2 of each process of the anomaly monitoring system 100 according to the embodiment. Below, a display example will be described of the display screen of the system alarm view and historical message report window in the case of a transient abnormality in the input / output module M of the control device 10, in which the system alarm view and historical message report window are displayed in the case where the first transient abnormality occurs and the system does not recover by automatic restart.
[0138] As shown in the example of the "System Alarm View" in FIG. 15(1), when an abnormality is detected in the input / output module M and the alarm mask function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 15(1), the engineer terminal 20 displays alarms in the following order: "IOM Fail N-IO..." (bus node IOM is in a failed state), "IOM Out Service..." (IOM unavailable), "IOM In Service..." (IOM available), and "N-IO Self Diag Error..." (bus node self-diagnosis error). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Also, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0139] As shown in the example of the "Historical Message Report Window" in FIG. 15(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0140] As shown in the example of the "System Alarm View" in Figure 15(2), when an abnormality is detected in the input / output module M, the alarm mask function setting is enabled, and the abnormality is not recovered by an automatic restart, the engineer terminal 20 displays the system alarm for which the alarm mask was executed, as well as the system alarm indicating the occurrence of the abnormality. In the example of the "System Alarm View" in Figure 15(2), the "System Alarm View" in Figure 15(1) is hidden, and the alarms "IOM Fail N-IO..." (bus node IOM is in a failed state) and "N-IO Self Diag Error..." (bus node self-diagnosis error) are notified and displayed again (see the dashed rectangle in the "System Alarm View" in Figure 15(2)).
[0141] As shown in the example of the "Historical Message Report Window" in Figure 15(2), the engineer terminal 20 displays a system report with the same content as a system alarm that does not execute alarm masking, and also notifies and displays the alarms "IOM Fail N-IO..." (bus node IOM is in a failed state) and "N-IO Self Diag Error..." (bus node self-diagnosis error) again (see the dashed rectangle in Figure 15(2) "Historical Message Report Window"). Note that in the case of an abnormality in the input / output module M indicated by a specific code, the control device 10 delays notification of the alarm indicated by the dashed-dotted rectangle until it has completed determining whether the abnormality is due to an internal memory diagnosis abnormality.
[0142] As described above, when the first internal memory diagnostic abnormality occurs in the input / output module M, the alarm mask function setting is enabled, and the module does not recover by automatic restart, the control device 10 displays the system alarm for which the alarm mask was executed, and also displays the system alarm indicating the occurrence of the abnormality, thereby notifying the engineer E that the alarm needs to be addressed. The control device 10 also makes the system report viewable, enabling the engineer E to address the alarm as necessary.
[0143] (3-3-3. Example 3-3) A specific example 3-3 of each process of the abnormality monitoring system 100 will be described using Fig. 16. Fig. 16 is a diagram showing a specific example 3-3 of each process of the abnormality monitoring system 100 according to the embodiment. Below, a display example will be described of the display screen of the system alarm view and historical message report window for a transient abnormality in the input / output module M of the control device 10, in which an automatic restart is not performed after the second internal memory diagnosis abnormality occurs.
[0144] As shown in the example of the "System Alarm View" in FIG. 16(1), when an abnormality is detected in the input / output module M and the alarm mask function setting is disabled, the engineer terminal 20 displays a system alarm that does not execute alarm masking. In the example of the "System Alarm View" in FIG. 16(1), the engineer terminal 20 displays alarms in the following order: "IOM Fail N-IO..." (bus node IOM is in a failed state), "IOM Out Service..." (IOM unavailable), "IOM In Service..." (IOM available), and "N-IO Self Diag Error..." (bus node self-diagnosis error). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Also, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0145] As shown in the example of the "Historical Message Report Window" in FIG. 16(1), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0146] As shown in the example of the "System Alarm View" in Fig. 16(2), when an abnormality is detected in the input / output module M, the alarm mask function setting is enabled, and the abnormality is the second or subsequent internal memory diagnosis, the engineer terminal 20 displays a system alarm that does not execute alarm masking without automatically restarting. In the example of the "System Alarm View" in Fig. 16(2), the "System Alarm View" in Fig. 16(1) is in a display state.
[0147] As shown in the example of the "Historical Message Report Window" in FIG. 16(2), the engineer terminal 20 displays a system report with the same content as a system alarm for which alarm masking is not performed.
[0148] As described above, when an internal memory diagnostic abnormality occurs for the second or subsequent times in the input / output module M, the control device 10 does not automatically restart the system, but instead displays the system alarm to notify the engineer E that the alarm needs to be addressed. In addition, the control device 10 makes the system report viewable, allowing the engineer E to address the alarm as necessary.
[0149] (3-4. Example 4) Here, a specific example 4 of each process of the anomaly monitoring system 100 will be described with reference to Fig. 17. Fig. 17 is a diagram showing a specific example 4 of each process of the anomaly monitoring system 100 according to the embodiment. Below, a system alarm view will be described to which a message indicating continued use in the case of a transient anomaly in the processor module P of the control device 10 and an internal memory diagnostic anomaly in the input / output module M has been added.
[0150] (3-4-1. Processor module P continues to be available message) As shown in the example of FIG. 17(1), when an abnormality is detected in processor module P and the continuous usability message function setting is enabled, the engineer terminal 20 displays a system alarm with an additional continuous usability message for a transient abnormality in processor module P. In the example of FIG. 17(1), the engineer terminal 20 displays the alarms in the following order: "LEFT Fail..." (left CPU is in a failed state), "Control Transfer" (control CPU is being transferred), "RIGHT Control" (right CPU is in a control state), "Copy" (data duplication in progress), and "LEFT Stand-By" (left CPU is in a standby state), along with the continuous usability message "LEFT Recover Continuously Usable" (left CPU has recovered and can be used continuously). Note that a black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. Furthermore, a white diamond at the beginning of each alarm indicates a state after recovery from a transient abnormality.
[0151] (3-4-2. Message indicating that I / O module M can continue to be used) As shown in the example of FIG. 17(2), when an abnormality is detected in the input / output module M and the continuous usability message function setting is enabled, the engineer terminal 20 displays a system alarm with an additional continuous usability message for an internal memory diagnostic abnormality in the input / output module M. In the example of FIG. 17(2), the engineer terminal 20 displays the alarms in the following order: "IOM Fail N-IO ..." (bus node IOM is in a failed state), "IOM Out Service N-IO ..." (bus node IOM is unavailable), "IOM In Service N-IO ..." (bus node IOM is available), "N-IO Self Diag Error N-IO N-IO ..." (bus node self-diagnosis error), "IOM Recover N-IO ..." (bus node IOM has recovered), and "N-IO Self Diag Recover ..." (bus node self-diagnosis recovery), as well as the continuous usability message "IOM Recover Continuously Usable" (IOM has recovered and can be used continuously). Note that the black diamond at the beginning of each alarm indicates a state before or during recovery from a transient abnormality. The white diamond at the beginning of each alarm indicates that the alarm has recovered from a transient abnormality.
[0152] As described above, when an abnormality due to a soft error occurs in the processor module P or the input / output module M and the system is restored by an automatic restart, the control device 10 notifies engineer E that there is no need to respond to the alarm by adding a message indicating continued use to the system alarm.
[0153] 4. Flow of Each Process in the Anomaly Monitoring System 100 18 to 23, the flow of each process in the anomaly monitoring system 100 according to the embodiment will be described. Specific examples 1 to 3 of the flow of each process in the anomaly monitoring system 100 will be described below.
[0154] (4-1. Example 1) 18 and 19, a specific example 1 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described. As the specific example 1, the flow of each process in the case of a transient abnormality in the processor module P of the control device 10 will be described below.
[0155] (4-1-1. Example 1-1) Specific example 1-1 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described with reference to FIG. 18. FIG. 18 is a flowchart showing specific example 1-1 of the flow of each process in the abnormality monitoring system 100 according to the embodiment. Below, the flow of the process for transmitting a system alarm when the state of the processor module P changes will be described as the flow of each process in the event of a transient abnormality in the processor module P of the control device 10. Note that the processes in steps S101 to S119 below can also be executed in a different order. Also, some of the processes in steps S101 to S119 below may be omitted.
[0156] The control device 10 transmits a message in response to a change in the state of the processor module P (e.g., left CPU, right CPU) (step S101). If the processor module P has transitioned to "Fail" (step S102: Yes), the control device 10 proceeds to processing in step S103. On the other hand, if the processor module P has not transitioned to "Fail" (step S102: No), the control device 10 proceeds to processing in step S116.
[0157] If the processor module P has failed due to a transient abnormality (step S103: Yes), the control device 10 proceeds to the process of step S104. On the other hand, if the processor module P has not failed due to a transient abnormality (step S103: No), the control device 10 proceeds to the process of step S107.
[0158] If the failed processor module P is a processor module P that was previously restarted due to a transient abnormality (step S104: Yes), the control device 10 proceeds to the process of step S107. On the other hand, if the failed processor module P is not a processor module P that was previously restarted due to a transient abnormality (step S104: No), the control device 10 proceeds to the process of step S105.
[0159] The control device 10 sets the alarm mask request flag to an ON state (step S105), and also sets a fail alarm waiting timer (step S106), and proceeds to the processing of step S109.
[0160] The control device 10 turns off the alarm mask request flag (step S107), and also resets the fail alarm waiting timer to 0 (step S108), and proceeds to the process of step S109.
[0161] If the alarm mask request flag is on (step S109: Yes), the control device 10 proceeds to the process of step S110. On the other hand, if the alarm mask request flag is not on (step S109: No), the control device 10 proceeds to the process of step S112.
[0162] If the alarm mask function is enabled (step S110: Yes), the control device 10 proceeds to the process of step S111. On the other hand, if the alarm mask function is not enabled (step S110: No), the control device 10 proceeds to the process of step S112.
[0163] The control device 10 transmits an alarm with a non-display instruction (step S111), and proceeds to the processing of step S113.
[0164] The control device 10 transmits the alarm without issuing a non-display instruction (step S112), and ends the process.
[0165] If the control device 10 decides to transmit a standby message (step S113: Yes), the process proceeds to step S114. On the other hand, if the control device 10 decides not to transmit a standby message (step S113: No), the process ends.
[0166] The control device 10 turns off the alarm mask request flag (step S114), resets the fail alarm waiting timer to 0 (step S115), and ends the process.
[0167] If the state has transitioned to "Control" (step S116: Yes), the control device 10 proceeds to the process of step S103. On the other hand, if the state has not transitioned to "Control" (step S116: No), the control device 10 proceeds to the process of step S117.
[0168] If the control device 10 has transitioned to "Stand-By" (step S117: Yes), the control device 10 proceeds to the process of step S109. On the other hand, if the control device 10 has not transitioned to "Stand-By" (step S117: No), the control device 10 proceeds to the process of step S118.
[0169] If the control device 10 has transitioned to "Hard Ready" (step S118: Yes), the control device 10 proceeds to the process of step S119. On the other hand, if the control device 10 has not transitioned to "Hard Ready" (step S118: No), the control device 10 ends the process.
[0170] The control device 10 resets the fail alarm waiting timer to 0 (step S119) and ends the process.
[0171] (4-1-2. Example 1-2) A specific example 1-2 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described using FIG. 19. FIG. 19 is a flowchart showing a specific example 1-2 of the flow of each process in the abnormality monitoring system 100 according to the embodiment. Below, as the flow of each process in the event of a transient abnormality in the processor module P of the control device 10, a process flow for transmitting a fail alarm when the processor module P does not recover after the first restart will be described. Note that the processes in steps S201 to S207 below can also be executed in a different order. Also, some of the processes in steps S201 to S207 below may be omitted.
[0172] If a failure has occurred in the processor module P (step S201: Yes), the control device 10 proceeds to the process of step S202. On the other hand, if a failure has not occurred in the processor module P (step S201: No), the control device 10 proceeds to the process of step S207.
[0173] If the fail alarm waiting timer is 0 (step S202: Yes), the control device 10 ends the process. On the other hand, if the fail alarm waiting timer is not 0 (step S202: No), the control device 10 proceeds to the process of step S203.
[0174] If the alarm mask function is enabled (step S203: Yes), the control device 10 proceeds to the process of step S204. On the other hand, if the alarm mask function is not enabled (step S203: No), the control device 10 proceeds to the process of step S207.
[0175] The control device 10 decrements the fail alarm waiting timer by 1 (step S204), and proceeds to the process of step S205.
[0176] If the fail alarm waiting timer is 0 (step S205: Yes), the control device 10 proceeds to the process of step S206. On the other hand, if the fail alarm waiting timer is not 0 (step S205: No), the control device 10 ends the process.
[0177] The control device 10 transmits a fail alarm (step S206) and ends the process.
[0178] The control device 10 sets the fail alarm waiting timer to 0 (step S207) and ends the process.
[0179] (4-2. Example 2) 20 to 22, a specific example 2 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described. As the specific example 2, the flow of each process in the case of a transient abnormality in the input / output module M of the control device 10 will be described below.
[0180] (4-2-1. Example 2-1) A specific example 2-1 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described using FIG. 20. FIG. 20 is a flowchart showing a specific example 2-1 of the flow of each process in the abnormality monitoring system 100 according to the embodiment. Below, the flow of the process of transmitting a fail alarm for the input / output module M in the first scan will be described as the flow of each process in the event of a transient abnormality in the input / output module M of the control device 10. Note that the processes in steps S301 to S307 below can also be executed in a different order. Also, some of the processes in steps S301 to S307 below may be omitted.
[0181] If a failure has occurred in the input / output module M (step S301: Yes), the control device 10 proceeds to the process of step S302. On the other hand, if a failure has not occurred in the input / output module M (step S301: No), the control device 10 proceeds to the process of step S307.
[0182] If the alarm mask function is enabled (step S302: Yes), the control device 10 proceeds to the process of step S303. On the other hand, if the alarm mask function is not enabled (step S302: No), the control device 10 proceeds to the process of step S306.
[0183] If the input / output module M of the target code has failed (step S303: Yes), the control device 10 proceeds to the process of step S304. On the other hand, if the input / output module M of the target code has not failed (step S303: No), the control device 10 proceeds to the process of step S306.
[0184] If the failed input / output module M is an input / output module M that was previously restarted due to an internal memory diagnosis abnormality (step S304: Yes), the control device 10 proceeds to the processing of step S306. On the other hand, if the failed input / output module M is not an input / output module M that was previously restarted due to an internal memory diagnosis abnormality (step S304: No), the control device 10 proceeds to the processing of step S305.
[0185] The control device 10 does not transmit a failure alarm for the input / output module M until it acquires the detailed cause of the failure (step S305), and proceeds to the processing of step S307.
[0186] The control device 10 transmits a fail alarm of the input / output module M without issuing a non-display instruction (step S306), and proceeds to the processing of step S307.
[0187] The control device 10 proceeds to the next scan (step S307) and ends the process.
[0188] (4-2-2. Example 2-2) A specific example 2-2 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described using FIG. 21. FIG. 21 is a flowchart showing a specific example 2-2 of the flow of each process in the abnormality monitoring system 100 according to the embodiment. Below, the flow of the process of transmitting a fail alarm for the input / output module M in the second scan will be described as the flow of each process in the event of a transient abnormality in the input / output module M of the control device 10. Note that the processes in steps S401 to S409 below can also be executed in a different order. Also, some of the processes in steps S401 to S409 below may be omitted.
[0189] The control device 10 acquires the detailed cause of the failure (step S401), and proceeds to the processing of step S402.
[0190] If the scanned input / output module M is a module that has not transmitted an alarm (step S402: Yes), the control device 10 proceeds to the process of step S403. On the other hand, if the scanned input / output module M is not a module that has not transmitted an alarm (step S402: No), the control device 10 proceeds to the process of step S407.
[0191] If the cause of the failure is an internal memory diagnosis abnormality (step S403: Yes), the control device 10 proceeds to the process of step S404. On the other hand, if the cause of the failure is not an internal memory diagnosis abnormality (step S403: No), the control device 10 proceeds to the process of step S406.
[0192] The control device 10 transmits a fail alarm of the input / output module M with a non-display instruction (step S404), transmits a self-diagnosis error alarm of the input / output module M with a non-display instruction (step S405), and proceeds to the processing of step S409.
[0193] The control device 10 transmits a fail alarm of the input / output module M without issuing a non-display instruction (step S406), and proceeds to the processing of step S409.
[0194] If the cause of the failure is an internal memory diagnosis abnormality (step S407: Yes), the control device 10 proceeds to the process of step S408. On the other hand, if the cause of the failure is not an internal memory diagnosis abnormality (step S407: No), the control device 10 proceeds to the process of step S409.
[0195] The control device 10 transmits a self-diagnosis error alarm of the input / output module M without issuing a non-display instruction (step S408), and proceeds to the processing of step S409.
[0196] The control device 10 proceeds to the next scan (step S409) and ends the process.
[0197] (4-2-3. Example 2-3) A specific example 2-3 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described using FIG. 22. FIG. 22 is a flowchart showing a specific example 2-3 of the flow of each process in the abnormality monitoring system 100 according to the embodiment. Below, the flow of the process of transmitting an alarm of the input / output module M after an automatic restart will be described as the flow of each process in the event of a transient abnormality in the input / output module M of the control device 10. Note that the processes of steps S501 to S505 below can also be executed in a different order. Also, some processes of steps S501 to S505 below may be omitted.
[0198] The control device 10 automatically restarts (step S501) and proceeds to the processing of step S502.
[0199] If the input / output module M has recovered from the automatic restart (step S502: Yes), the control device 10 proceeds to the processing of step S503. On the other hand, if the input / output module M has not recovered from the automatic restart (step S502: No), the control device 10 proceeds to the processing of step S504.
[0200] The control device 10 transmits a normal recovery alarm of the input / output module M with a non-display instruction (step S503), and ends the process.
[0201] If 10 seconds have passed since the automatic restart (step S504: Yes), the control device 10 proceeds to the process of step S505. On the other hand, if 10 seconds have not passed since the automatic restart (step S504: No), the control device 10 ends the process.
[0202] The control device 10 transmits an alarm indicating the occurrence of an abnormality in the input / output module M without a non-display instruction (step S505), and ends the process.
[0203] (4-3. Example 3) Specific example 3 of the flow of each process in the abnormality monitoring system 100 according to the embodiment will be described using FIG. 23. FIG. 23 is a flowchart showing specific example 3 of the flow of each process in the abnormality monitoring system 100 according to the embodiment. Below, as specific example 3, a process flow for sending an alarm to which a message indicating continued use is added will be described as a process flow for each process in the event of a transient abnormality in the processor module P or the input / output module M of the control device 10. Note that the processes in steps S601 to S605 below can also be executed in a different order. Also, some processes in steps S601 to S605 below may be omitted.
[0204] If the processor module P or the input / output module M has failed (step S601: Yes), the control device 10 proceeds to the process of step S602. On the other hand, if the processor module P or the input / output module M has not failed (step S601: No), the control device 10 ends the process.
[0205] If the continuous usable message addition function is enabled (step S602: Yes), the control device 10 proceeds to the process of step S603. On the other hand, if the continuous usable message addition function is not enabled (step S602: No), the control device 10 ends the process.
[0206] If the processor module P or the input / output module M of the target code has failed (step S603: Yes), the control device 10 proceeds to the process of step S604. On the other hand, if the processor module P or the input / output module M of the target code has not failed (step S603: No), the control device 10 ends the process.
[0207] The control device 10 adds a message indicating continued use (step S604), transmits the alarm to which the message has been added (step S605), and ends the process.
[0208] 5. Effects of the embodiment Finally, the effects of the embodiment will be described below: Effects 1 to 11 corresponding to the processing according to the embodiment will be described below.
[0209] (5-1. Effect 1) First, in the processing according to the embodiment described above, the control device 10 collects data from devices constituting the system, detects an abnormality that has occurred in at least one of the processor module P and the input / output module M based on the collected data, and if the detected abnormality is likely to be caused by a soft error, executes an action in response to an alarm indicating the abnormality and notifies the engineer E of the alarm for which the action has been executed. Therefore, this processing can reduce the number of times to respond to alarms caused by soft errors.
[0210] (5-2. Effect 2) Secondly, in the process according to the embodiment described above, the control device 10 detects a transient abnormality that has occurred in the processor module P, and when a transient abnormality is detected, masks an alarm indicating the transient abnormality and notifies the masked alarm to the engineer E. Therefore, in this process, by masking an alarm for a transient abnormality that has occurred in the processor module P, it is possible to reduce the number of times to respond to alarms caused by soft errors.
[0211] (5-3. Effect 3) Thirdly, in the process according to the embodiment described above, when the control device 10 detects a transient abnormality for the second or subsequent time in the same processor module P, it notifies the engineer E of an alarm that does not perform masking. Therefore, in this process, alarm masking is not performed for transient abnormalities that occur for the second or subsequent time in the same processor module P, making it possible to respond to alarms caused by soft errors.
[0212] (5-4. Effect 4) Fourth, in the process according to the embodiment described above, if the processor module P does not recover from a transient abnormality that has occurred, the control device 10 notifies the engineer E of an alarm that does not perform masking. Therefore, in this process, if the processor module P does not automatically recover from a transient abnormality that has occurred, the control device 10 re-notifies the alarm, thereby making it possible to respond to an alarm caused by a soft error.
[0213] (5-5. Effect 5) Fifth, in the processing according to the embodiment described above, the control device 10 detects an internal memory diagnosis abnormality that has occurred in the input / output module M, and if an internal memory diagnosis abnormality is detected, masks an alarm indicating the internal memory diagnosis abnormality and notifies the masked alarm to the engineer E. Therefore, in this processing, by masking an alarm regarding the internal memory diagnosis abnormality that has occurred in the input / output module M, it is possible to reduce the number of times to respond to alarms caused by soft errors.
[0214] (5-6. Effect 6) Sixth, in the processing according to the embodiment described above, when the control device 10 detects an internal memory diagnostic abnormality for the second or subsequent time in the same input / output module M, it notifies the engineer E of an alarm that does not perform masking. Therefore, in this processing, by not performing alarm masking for internal memory diagnostic abnormalities that occur for the second or subsequent time in the same input / output module M, it is possible to respond to alarms caused by soft errors.
[0215] (5-7. Effect 7) Seventh, in the process according to the embodiment described above, if the control device 10 does not recover from an internal memory diagnosis abnormality that has occurred in the input / output module M, the control device 10 notifies the engineer E of an alarm that does not perform masking. Therefore, in this process, if the internal memory diagnosis abnormality that has occurred in the input / output module M does not recover automatically, the alarm is re-notified, thereby making it possible to respond to an alarm caused by a soft error.
[0216] (5-8. Effect 8) Eighth, in the process according to the embodiment described above, the control device 10 detects a transient abnormality that occurs in the processor module P, and when the control device 10 detects the transient abnormality, it attaches a message indicating that the processor module can be continued to be used to an alarm, and notifies the alarm with the message indicating that the processor module can be continued to be used to an engineer E. Therefore, in this process, by notifying the message indicating that the processor module can be continued to be used when an abnormality caused by a soft error occurs in the processor module P, it is possible to reduce the number of times to respond to alarms caused by soft errors.
[0217] (5-9. Effect 9) Ninth, in the processing according to the above-described embodiment, the control device 10 detects an internal memory diagnosis abnormality that has occurred in the input / output module M, and if an internal memory diagnosis abnormality is detected, attaches a message indicating that continued use is possible to the alarm, and notifies the alarm with the message indicating continued use to the engineer E. Therefore, in this processing, by notifying the message indicating continued use is possible when an abnormality caused by a soft error occurs in the input / output module M, it is possible to reduce the number of responses to alarms caused by soft errors.
[0218] (5-10. Effect 10) Tenth, in the process according to the embodiment described above, the control device 10 notifies the engineer E of a system report indicating the history of system alarms. Therefore, in this process, when an abnormality caused by a soft error occurs in the processor module P or the input / output module M, by notifying the engineer E of a system report indicating the history of system alarms, it is possible to respond to the alarm caused by the soft error.
[0219] (5-11. Effect 11) Eleventh, in the process according to the above-described embodiment, the system is a plant, and the devices are the field devices 30 that constitute the plant. Therefore, in this process, it is possible to reduce the number of responses to alarms caused by soft errors in a plant that is constituted by field devices 30.
[0220] [6. System] The information including the processing procedures, control procedures, specific names, various data and parameters shown in the above documents and drawings can be changed arbitrarily unless otherwise specified.
[0221] Furthermore, the components of each device shown in the figure are functional concepts and do not necessarily have to be physically configured as shown. In other words, the specific form of distribution and integration of each device is not limited to that shown. In other words, all or part of them can be functionally or physically distributed and integrated in any unit depending on various loads, usage conditions, etc.
[0222] Furthermore, all or any part of the processing functions performed by each device may be realized by a CPU and a program analyzed and executed by the CPU, or may be realized as hardware using wired logic.
[0223] [7. Hardware] An example of the hardware configuration of the control device 10 will be described. Note that other devices may also have a similar hardware configuration. FIG. 24 is a diagram showing an example of the hardware configuration according to an embodiment. As shown in FIG. 24, the control device 10 includes a communication device 10a, an HDD (Hard Disk Drive) 10b, a memory 10c, and a processor 10d. The components shown in FIG. 24 are connected to each other via a bus or the like.
[0224] The communication device 10a is a network interface card or the like, and communicates with other servers. The HDD 10b stores programs and databases that operate the functions shown in FIG.
[0225] The processor 10d reads out a program that executes the same processes as the respective processing units shown in FIG. 4 from the HDD 10b or the like and loads it into the memory 10c, thereby operating a process that executes each function described in FIG. 4 or the like. For example, this process executes the same functions as the respective processing units of the control device 10. Specifically, the processor 10d reads out a program that has the same functions as the collection unit 13a, the detection unit 13b, the execution unit 13c, the notification unit 13d, or the like from the HDD 10b or the like. Then, the processor 10d executes a process that executes the same processes as the collection unit 13a, the detection unit 13b, the execution unit 13c, the notification unit 13d, or the like.
[0226] In this way, the control device 10 operates as a device that executes various processing methods by reading and executing a program. The control device 10 can also realize functions similar to those of the above-described embodiment by reading the program from a recording medium using a media reader and executing the read program. Note that the program in these other embodiments is not limited to being executed by the control device 10. For example, the present invention can also be applied in the same way to cases where another computer or server executes the program, or where these execute the program in cooperation with each other.
[0227] This program can be distributed via a network such as the Internet. In addition, this program can be recorded on a computer-readable recording medium such as a hard disk, a flexible disk (FD), a CD-ROM, a magneto-optical disk (MO), or a digital versatile disk (DVD), and can be executed by being read from the recording medium by a computer.
[0228] [8. Other] Some examples of combinations of the disclosed technical features are set out below.
[0229] (1) A control device comprising: a collection unit that collects data from devices that constitute a system; a detection unit that detects an abnormality that has occurred in at least one of a processor module and an input / output module based on the collected data; an execution unit that, if the detected abnormality is likely to be caused by a soft error, executes an action in response to an alarm indicating the abnormality; and a notification unit that notifies a user of the alarm for which the action has been executed.
[0230] (2) The control device described in (1), wherein the detection unit detects a transient abnormality that has occurred in the processor module, the execution unit, when the transient abnormality is detected, performs masking on the alarm indicating the transient abnormality, and the notification unit notifies the user of the alarm that has been masked.
[0231] (3) The control device described in (2), wherein the notification unit notifies the user of the alarm in which the masking is not performed when the transient abnormality is detected in the same processor module for a second or subsequent time.
[0232] (4) The control device according to (2) or (3), wherein the notification unit notifies the user of the alarm indicating that the masking is not performed if the processor module does not recover from the transient abnormality that occurred in the processor module.
[0233] (5) A control device described in any one of (1) to (4), wherein the detection unit detects an internal memory diagnostic abnormality that occurs in the input / output module, the execution unit, when the internal memory diagnostic abnormality is detected, performs masking on the alarm indicating the internal memory diagnostic abnormality, and the notification unit notifies the user of the alarm that has been masked.
[0234] (6) The control device described in (5), wherein the notification unit notifies the user of the alarm in which the masking is not performed when an internal memory diagnostic abnormality is detected for the second or subsequent time in the same input / output module.
[0235] (7) The control device described in (5) or (6), wherein the notification unit notifies the user of the alarm that the masking is not performed if the internal memory diagnostic abnormality that occurred in the input / output module is not recovered from.
[0236] (8) A control device described in any one of (1) to (7), wherein the detection unit detects a transient abnormality that occurs in the processor module, the execution unit, when the transient abnormality is detected, adds a message to the alarm indicating that the device can continue to be used, and the notification unit notifies the user of the alarm with the message added.
[0237] (9) A control device described in any one of (1) to (8), wherein the detection unit detects an internal memory diagnostic abnormality that occurs in the input / output module, the execution unit, when the internal memory diagnostic abnormality is detected, adds a message to the alarm indicating that the device can continue to be used, and the notification unit notifies the user of the alarm with the message added.
[0238] (10) The control device according to any one of (1) to (9), wherein the notification unit notifies the user of a report indicating a history of the alarm.
[0239] (11) The control device according to any one of (1) to (10), wherein the system is a plant, and the device is a field instrument that constitutes the plant.
[0240] (12) A control method for executing processing in which a computer collects data from devices that constitute a system, detects an abnormality that has occurred in at least one of a processor module and an input / output module based on the collected data, and if the detected abnormality is likely to be caused by a soft error, executes an action in response to an alarm indicating the abnormality, and notifies a user of the alarm for which the action has been executed.
[0241] (13) A control program that causes a computer to execute processing to collect data from devices that constitute a system, detect an abnormality that has occurred in at least one of a processor module and an input / output module based on the collected data, and if the detected abnormality is likely to be caused by a soft error, execute an action in response to an alarm indicating the abnormality, and notify a user of the alarm for which the action has been executed. [Explanation of symbols]
[0242] 10 Control device 10a Communication equipment 10b HDD 10c memory 10d processor 11 Communications Department 12 Storage section 12a Detection result storage unit 12b Alarm information storage section 12c Report information storage section 13 Control Unit 13a Collection Department 13b Detector 13c Executive Department 13d Notification Department 20 Engineer Terminal 21 Input / output section 22 Control Unit 23 Communications Department 30 Field Devices 100 Abnormality Monitoring System E Engineer M Input / Output Module N communication network P Processor Module
Claims
1. a collection unit that collects data from devices that constitute the system; a detection unit that detects an abnormality that has occurred in at least one of the processor module and the input / output module based on the collected data; an execution unit that, when the detected abnormality is likely to be caused by a soft error, executes an action in response to an alarm indicating the abnormality; a notification unit that notifies a user of the alarm for which the action has been executed; Control device provided.
2. The detection unit Detecting a transient abnormality occurring in the processor module; The execution unit: If the transient abnormality is detected, masking the alarm indicating the transient abnormality is performed; The notification unit notifying the user of the alarm for which the masking has been performed; The control device according to claim 1 .
3. The notification unit If the transient abnormality is detected for a second or subsequent time in the same processor module, the user is notified of the alarm without the masking being performed. The control device according to claim 2 .
4. The notification unit If the processor module does not recover from the transient abnormality, the user is notified of the alarm indicating that the masking is not performed. The control device according to claim 2 .
5. The detection unit Detecting an internal memory diagnostic abnormality occurring in the input / output module; The execution unit: When the internal memory diagnosis abnormality is detected, masking of the alarm indicating the internal memory diagnosis abnormality is performed; The notification unit notifying the user of the alarm for which the masking has been performed; The control device according to claim 1 .
6. The notification unit If the internal memory diagnostic abnormality is detected for the second or subsequent time in the same input / output module, the user is notified of the alarm without the masking being performed. The control device according to claim 5 .
7. The notification unit If the internal memory diagnostic abnormality occurring in the input / output module is not recovered from, the user is notified of the alarm in which the masking is not performed. The control device according to claim 5 .
8. The detection unit Detecting a transient abnormality occurring in the processor module; The execution unit: If the transient abnormality is detected, a message indicating that the device can be used continuously is added to the alarm. The notification unit notifying the user of the alarm to which the message has been added; The control device according to claim 1 .
9. The detection unit Detecting an internal memory diagnostic abnormality occurring in the input / output module; The execution unit: If an abnormality is detected in the internal memory diagnosis, a message indicating that the device can continue to be used is added to the alarm. The notification unit notifying the user of the alarm to which the message has been added; The control device according to claim 1 .
10. The notification unit notifying the user of a report showing the history of the alarm; The control device according to claim 1 .
11. the system is a plant, and the device is a field device that constitutes the plant; The control device according to any one of claims 1 to 10.
12. The computer Collect data from the devices that make up the system, Detecting an abnormality occurring in at least one of the processor module and the input / output module based on the collected data; If the detected abnormality is likely to be caused by a soft error, an action is taken in response to an alarm indicating the abnormality; notifying a user of the alarm that the action has been taken; A control method for performing a process.
13. On the computer, Collect data from the devices that make up the system, Detecting an abnormality occurring in at least one of the processor module and the input / output module based on the collected data; If the detected abnormality is likely to be caused by a soft error, an action is taken in response to an alarm indicating the abnormality; notifying a user of the alarm that the action has been taken; A control program that executes processing.
Citation Information
Patent Citations
Safety instrumentation control device and method, and safety instrumentation system
JP6656593B2