controller
By separating the execution and virtual environments within the controller and using Docker for virtualization, the controller effectively prevents interference between first and second programs, ensuring stable operation even under abnormal conditions.
Patent Information
- Application Number
- JP2021080863
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-05-12
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-05-12
AI Technical Summary
Conventional controllers face challenges in isolating and managing the execution of first and second programs, where the first program and the second program share the same memory space, leading to potential interference and instability.
The controller employs a configuration with separate execution and virtual environments, where the first program is executed in the execution environment and the second program is executed in a virtual environment with limited resources, using frameworks and Docker for virtualization to prevent interference.
This configuration effectively suppresses mutual interference between the first and second programs, ensuring that the first program can continue execution even if the second program is in an abnormal state, and that resource constraints in the virtual environment prevent overload from affecting the first program.
Smart Images

Figure 0007678702000001 
Figure 0007678702000002
Abstract
Description
[Technical field]
[0001] The present invention relates to a controller that executes an installed program. [Background technology]
[0002] Generally, programs created to realize various functions are installed in the controller. The controller executes the installed programs to realize various functions according to the contents of the programs.
[0003] The programs installed in the controller include, for example, a program describing a predetermined function (hereinafter referred to as a first program) and a program describing a function other than the function described in the first program (hereinafter referred to as a second program). The second program is, for example, a program describing a function that is difficult to realize by only executing the first program, and is created separately from the first program and installed additionally into the controller in which the first program is installed.
[0004] However, in conventional controllers, the above-mentioned first program and the additionally installed second program are designed to be deployed and executed in the same memory of the controller. Therefore, for example, when the functions of the first program are expanded, the second program may be affected, and the second program may not operate. On the other hand, if a fault occurs in the second program, the controller may enter an abnormal state, which may affect the first program.
[0005] Therefore, the controller is required to have a design specification that, when a first program and a second program are installed, these programs do not affect each other. Specifically, it is necessary to satisfy the following requirements: (a) even if the second program goes into an abnormal state, the execution of the first program can be continued, (b) even if the load of the second program increases, the first program is not affected, (c) even if the function of the second program is expanded, the first program is not affected, and (d) even if the controller is upgraded, the second program is not affected (even if the function of the first program is expanded, the second program can operate normally).
[0006] One technology that may satisfy such demands is virtualization technology. Virtualization technology is a technology that allows one computer to behave like multiple computers. As an example, for example, Patent Document 1 discloses an application of virtualization technology to an air conditioning control system. In Patent Document 1, an indoor unit control unit that controls an indoor unit and an outdoor unit control unit that controls an outdoor unit are mounted on a control device as virtualized control units. The indoor unit control unit and the outdoor unit control unit acquire information from sensors and the like via a common bus, and generate control commands for various devices that constitute the indoor unit and the outdoor unit by executing their respective control programs. In this way, by having the indoor unit control unit and the outdoor unit control unit exist independently of the indoor unit and the outdoor unit, there is no need to mount advanced programs on the indoor unit and the outdoor unit, and the outdoor unit and the indoor unit can be easily replaced. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Patent Publication 2015-141014 Summary of the Invention [Problem to be solved by the invention]
[0008] However, in Patent Document 1, if the control program executed by the indoor unit control unit and the outdoor unit control unit corresponds to either the first program or the second program described above, it is not necessarily clear whether the other program will be executed. Even if a program corresponding to the other program is executed, it is assumed that the subject is the indoor unit control unit and the outdoor unit control unit described above. In that case, it is assumed that these programs are deployed in the same memory that can be referenced by the indoor unit control unit and the outdoor unit control unit.
[0009] Therefore, even if the technology of Patent Document 1 is adapted for use in a controller, it is expected that it will still be difficult to satisfy the requirements (a) to (d) mentioned above, particularly those required during the execution of the first program and the second program, namely, (a) that the execution of the first program can be continued even if the second program enters an abnormal state, and (b) that the first program is not affected even if the load on the second program becomes high.
[0010] The present invention has been made to solve the above-mentioned problems, and has an object to provide a controller capable of suppressing mutual interference between a first program and a second program. [Means for solving the problem]
[0011] The controller according to the present invention includes an execution environment in which a first program is executed, and a virtual environment in which a second program that describes a function other than a function described in the first program is executed, and resources available in the virtual environment are limited to a portion of the resources of the controller itself. The execution environment includes a first framework and a second framework that operates on the first framework and causes the first program and a second program executed in the virtual environment to operate in cooperation with each other. It is characterized by: Effect of the Invention
[0012] According to the present invention, with the above-mentioned configuration, it is possible to suppress mutual interference between the first program and the second program. [Brief description of the drawings]
[0013] [Figure 1] 1 is a diagram illustrating a configuration example of a monitoring system including a controller according to a first embodiment. [Diagram 2] FIG. 2 is a diagram illustrating an example of the configuration of a controller according to the first embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0014] Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. Embodiment 1 1 is a diagram showing a configuration example of a monitoring system including a controller according to embodiment 1. In the following, an example in which the controller according to embodiment 1 is applied to a monitoring system will be described.
[0015] As shown in Fig. 1, the monitoring system includes one or more monitored devices 1 (hereinafter referred to as monitoring points 1), one or more controllers 2, and a monitoring device 3. The monitoring point 1 is connected to the controller 2 via a communication line. In addition, the controller 2 is connected to the monitoring device 3 via a communication line. Fig. 1 shows one monitoring point 1 and one controller 2.
[0016] The monitoring point 1 is a device that is a target of monitoring in the monitoring system. The monitoring point 1 is composed of various sensors such as a temperature sensor and a humidity sensor, air conditioning equipment, lighting equipment, and the like.
[0017] The controller 2 monitors and controls the target monitoring point 1. The above-mentioned first program and second program are installed in the controller 2, and the controller 2 executes these programs to monitor and control the monitoring point 1. For example, if the monitoring point 1 is a temperature sensor, the controller 2 receives data from the temperature sensor and acquires the temperature indicated by the data. If the monitoring point 1 is a humidity sensor, the controller 2 receives data from the humidity sensor and acquires the humidity indicated by the data. Then, the controller 2 transmits data indicating the temperature or humidity acquired from the monitoring point 1 to the monitoring device 3 in response to an acquisition request from the monitoring device 3, for example, by communication such as BACnet (Building Automation and Control Network). A specific configuration example of the controller 2 will be described later.
[0018] For ease of understanding, the following description will be given by taking as an example a case where the above-mentioned first program is a "standard function program" and the second program is a "control program." The standard function program is a program for realizing functions (hereinafter referred to as standard functions) that are used in many buildings in which a monitoring system is installed. Examples of the standard functions include a schedule control function, an optimal start / stop control function, and a power demand control function.
[0019] The schedule control function is a function that outputs set values and instructs the monitoring points to start and stop according to a preset schedule. The optimal start / stop control function is a function that starts and stops air conditioning-related monitoring points at an optimal time. For example, by starting the air conditioner before the user arrives in the room, the optimal indoor environment is provided when the user arrives in the room. For example, by stopping the air conditioner shortly before the user leaves the room, unnecessary energy consumption is suppressed. The power demand control function is a function that predicts power consumption and controls monitoring points such as air conditioners and lighting to keep power consumption within a target value. Programs that realize these functions are used relatively frequently in monitoring systems, and are therefore prepared as standard function programs, for example, and installed in the controller 2.
[0020] On the other hand, the control program is a program describing functions that are required in a specific building among the buildings in which the surveillance system is installed, and that are difficult to realize by only executing the standard function program by the controller 2. Such a control program is created separately from the standard function program, and is additionally installed in the controller 2.
[0021] The monitoring device 3 monitors and controls the target monitoring point 1 via the controller 2. For example, when the monitoring device 3 receives data from the controller 2, it displays the value (temperature, humidity, etc.) indicated by the received data on a display unit (not shown) such as a monitor to present to an administrator. Furthermore, if there is an abnormality in the value indicated by the data received from the controller 2, the monitoring device 3 issues an alarm to notify the administrator.
[0022] Incidentally, as the monitoring point 1 and the monitoring device 3, an existing monitoring point and monitoring device can be used.
[0023] Next, a configuration example of the controller 2 according to the first embodiment will be described with reference to Fig. 2. In the following, for the sake of specificity, it is assumed that the controller 2 according to the first embodiment is equipped with Linux (registered trademark) as an operating system (OS). The operating system is omitted in Fig. 2. In the first embodiment, it is assumed that the program language of the control program 253 described later is Python, and that Docker is used as the virtualization technology for constructing the virtual environment 23 described later.
[0024] As shown in FIG. 2, the controller 2 according to the first embodiment has two environments (an execution environment 21 and a virtual environment 23) built on the operating system.
[0025] (Execution environment 21) The execution environment 21 includes a main framework 211 of the controller 2, a control program framework 212, a standard function program 213 (standard function programs 213A and 213B), and a database 214. The database 214 stores various data used by the execution environment 21 (for example, the standard function program 213).
[0026] The main framework 211 of the controller 2 (hereinafter simply referred to as the main framework 211) is software that runs on the operating system and functions as a foundation for operating (executing) the control program framework 212 and the standard function program 213. The main framework 211 can access the database 214.
[0027] The standard function program 213 (standard function programs 213A and 213B) is a program describing standard functions. For example, the standard function program 213A is a program describing a schedule control function, which is one of the standard functions, and the standard function program 213B is a program describing an optimal start / stop control function, which is also one of the standard functions. The standard function program 213 is executed (started) according to, for example, a preset execution schedule. The standard function program 213 constitutes the "first program" of claim 1.
[0028] The control program framework 212 (hereinafter referred to as the sub-framework 212) is software that runs on the main framework 211 and causes the standard function program 213 and a control program 233 executed in the virtual environment 23 described below to operate in cooperation with each other. An identifier (e.g., a program ID) for uniquely identifying the control program 233 is registered in the sub-framework 212, and the sub-framework 212 causes the standard function program 213 and the control program 233 to operate in cooperation with each other while identifying the control program 233 using this identifier.
[0029] For example, when the standard function program 213 acquires data indicating the temperature and humidity of a room and the control program 233 wants to use the acquired data, the sub-framework 212 transfers the data between the two programs. Also, when the control program 233 wants to be executed based on the operation result of the standard function program 213, the sub-framework 212 makes the two programs work in cooperation with each other.
[0030] The sub-framework 212 can also operate in cooperation with the main framework 211. Therefore, the control program 233 can also access the database 214 via the sub-framework 212 and the main framework 211. For example, when the control program 233 wants to use data stored in the database 214, the control program 233 accesses the database 214 via the sub-framework 212 and the main framework 211. In this case as well, the sub-framework 212 identifies the control program 233 by using the identifier described above.
[0031] Furthermore, when some abnormality occurs in the control program 233, the sub-framework 212 can grasp which control program the abnormality occurred in. For example, when some abnormality occurs in the control program 233, the control program 233 transmits a message notifying the occurrence of the abnormality to the sub-framework 212. By receiving this message, the sub-framework 212 grasps that some abnormality has occurred in the control program 233. In this case, the sub-framework 212 continues processing by excluding the control program 233 in which the abnormality has occurred from the target of the cooperative operation with the standard function program 213. This allows the standard function program 213 to continue processing even if some abnormality occurs in the control program 233. Note that the sub-framework 212 transmits information on the control program 233 in which the abnormality has occurred to the monitoring device 3, and notifies the administrator of the abnormality.
[0032] (Virtual Environment 23) The virtual environment 23 is a virtual execution environment for executing the control program 233, which is constructed in the controller 2 by using Docker, which is one of the virtualization technologies. In Docker, virtualization is realized by a mechanism called container-based virtualization. In the example of Fig. 2, the virtual environment 23 corresponds to a container, and the control program 233 is executed in this virtual environment 23. Although the example in FIG. 2 shows a case where there is one control program 233, there may be a plurality of control programs 233.
[0033] As already mentioned, the control program 233 is a program describing functions that are required in a specific building among buildings in which a surveillance system is installed, and that are difficult to realize by simply executing the standard function program. The control program 233 may be executed according to a preset schedule, or may be executed in response to the operation result of the standard function program 213. The timing at which the control program 233 is executed is preset in the above-mentioned sub-framework 212, and the control program 233 is executed by being called by the sub-framework 212 according to this timing. The control program 233 constitutes the "second program describing functions other than those described in the first program" of claim 1.
[0034] In addition, in Docker, the resources (e.g., CPU and memory) available for each virtual environment can be limited. Also in the first embodiment, the resources (e.g., CPU and memory) available in the virtual environment 23 are limited to a part of the resources of the controller 2. For example, the usage rate of the CPU (virtual CPU) available in the virtual environment 23 and the usage amount of the memory (virtual memory) available in the virtual environment 23 are limited to a predetermined usage rate and a predetermined usage amount, respectively.
[0035] Here, if there is no limit to the resources available in the virtual environment 23, the load on the control programs 233 increases due to the execution of many control programs 233 or a large-scale control program 233, and many resources may be used in the virtual environment 23. As a result, the resources available in the execution environment 21 may decrease, which may affect the execution of the standard function program 213 in the execution environment 21. Therefore, as described above, the controller 2 limits the resources (e.g., CPU and memory) available in the virtual environment 23 to a portion of the resources provided in the controller 2. As a result, the controller 2 secures the resources required in the execution environment 21, and even if the control program 233 goes into an abnormal state or the load on the control program 233 increases, the controller 2 can continue processing the standard function program 213 without affecting the standard function program 213.
[0036] Furthermore, the controller 2 according to the first embodiment also provides the following effects when the controller 2 is upgraded.
[0037] For example, when an engineer upgrades the controller 2, the engineer updates the main framework 211 and the database 214 included in the execution environment 21. At this time, since the execution environment 21 and the virtual environment 23 are constructed as separate environments in the controller 2, the engineer does not need to update the control program 233 executed in the virtual environment 23, and does not need to check the operation of the control program 233.
[0038] In this regard, in conventional controllers, the execution environment and the virtual environment were not constructed as separate environments, so when the controller (main framework and database) was upgraded, an engineer had to check whether the control program created up to that point still operated normally after the upgrade. However, in the controller 2 according to the first embodiment, the execution environment 21 and the virtual environment 23 are constructed as separate environments, so even when the controller 2 is upgraded, an engineer does not need to check the operation of the control program 233 as described above. As a result, in the controller 2 according to the first embodiment, the number of steps required for maintaining the control program 233 can be reduced compared to conventional controllers, and it is also easy to reuse the control program 233 created in the past.
[0039] Furthermore, when updating (expanding functions of) the control program 233, the engineer updates the control program 233, and adds a library to the virtual environment 23 along with updating the control program 233, if necessary.
[0040] For example, various libraries necessary for executing the control program 233 are registered in the virtual environment 23, but if a library for realizing a function newly added to the control program 233 is not registered in the virtual environment 23, the engineer updates (extends the function of) the control program 233 by newly adding the necessary library to the virtual environment 23. In this case, too, since the virtual environment 23 and the execution environment 21 are constructed as separate environments in the controller 2, the engineer can update the control program 233 without stopping the standard function program 213.
[0041] In particular, the engineer who creates the standard function program 213 and the engineer who creates the control program 233 are often different engineers, and therefore it is often difficult to predict the effect that an update to the control program 233 will have on the operation of the standard function program 213. On the other hand, in the monitoring system, there is also a demand that the operation of the standard function program 213 not be stopped even if there is a defect in the update to the control program 233.
[0042] In this regard, in the controller 2 according to the first embodiment, the execution environment 21 and the virtual environment 23 are constructed as separate environments, so that an engineer can update the control program 233 without affecting the operation of the standard function program 213 while allowing the standard function program 213 to continue operating.
[0043] As described above, according to the first embodiment, the controller 2 includes the execution environment 21 in which the first program (standard function program 213) is executed, and the virtual environment 23 in which the second program (control program 233) describing functions other than those described in the first program is executed, and the resources available in the virtual environment 23 are limited to a part of the resources of the own device. This ensures that the resources required in the execution environment 21 are secured, and even if the control program 233 goes into an abnormal state or the load of the control program 233 becomes high, the processing of the standard function program 213 can be continued without affecting the standard function program 213. In other words, it is possible to suppress mutual interference between the standard function program 213 and the control program 233.
[0044] Moreover, the execution environment 21 has a first framework (main framework 211) and a second framework (sub-framework 212) that operates on the first framework and causes the standard function program 213 and the control program 233 executed in the virtual environment 23 to operate in cooperation with each other. As a result, in the controller 2, the standard function program 213 and the control program 233 can operate in cooperation with each other.
[0045] Furthermore, when an abnormality occurs in the control program 233 executed in the virtual environment 23, the sub-framework 212 can identify the control program 233 in which the abnormality occurred, and excludes the control program 233 that has been identified as having the abnormality from the targets of collaboration. This allows the standard function program 213 to continue processing even if some abnormality occurs in the control program 233.
[0046] Furthermore, the sub-framework 212 operates in cooperation with the main framework 211, the execution environment 21 has a database 214 that records data used in the execution environment 21 and is accessible by the main framework 211, and the control program 233 can access the database 214 via the sub-framework 212 and the main framework 211. As a result, in the controller 2, the control program 233 can access the database 214 provided in the execution environment 21 to perform processing.
[0047] In addition, within the scope of the present invention, any of the components of the embodiment may be modified or any of the components of the embodiment may be omitted. For example, in the above description, the controller 2 is equipped with Linux (registered trademark) as the operating system (OS), the control program 233 is written in Python, and Docker (container-based virtualization) is used as the virtualization technology for constructing the virtual environment 23. However, these are merely examples and are not limited to the configurations exemplified here. In addition, in the above description, the first program is a standard function program and the second program is a control program. However, the first program and the second program are not limited to the programs exemplified above, and the second program may be a program that describes a function other than the function described in the first program. [Explanation of symbols]
[0048] 1. Monitored equipment (monitoring points) 2. Controller 3 Monitoring device 21 Execution environment 23 Virtual Environment 211 Main Framework (First Framework) 212 Control program framework (sub-framework, second framework) 213 Standard Function Program (First Program) 214 Database 233 Control Program (Second Program)
Claims
1. an execution environment in which a first program is executed; a virtual environment in which a second program that describes a function other than the function described in the first program is executed; The resources available in the virtual environment are limited to a portion of the resources of the host computer; The execution environment includes: A first framework; a second framework that operates on the first framework and causes the first program and a second program executed in the virtual environment to operate in cooperation with each other.
2. The second framework comprises: The controller according to claim 1, characterized in that when an abnormality occurs in a second program executed in the virtual environment, the second program in which the abnormality has occurred can be identified, and the second program in which the occurrence of the abnormality has been identified is excluded from the targets of the collaboration.
3. The second framework operates in cooperation with the first framework; the execution environment has a database accessible by the first framework, the database storing data used in the execution environment; 3. The controller according to claim 1, wherein the second program is capable of accessing the database via the second framework and the first framework.
4. An execution environment in which a first program is executed; a virtual environment in which a second program that describes a function other than the function described in the first program is executed; The resources available in the virtual environment are limited to a portion of the resources of the host computer; the first program is a standard function program describing a standard function provided as a standard by the monitoring system, The second program is a control program describing a specific function other than the standard function described in the standard function program.
Citation Information
Patent Citations
Air conditioning system and control method of the same
JP2015141014A
Control device
JP2019175375A
Control device
JP2021022242A