Method and system for managing technical equipment during an error condition in a controller.

JP7927144B2Active Publication Date: 2026-09-30SIEMENS AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2025511357
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-08-23
Filing Date
2023-08-23
Publication Date
2026-09-30
Estimated Expiration
2043-08-23

Smart Images

  • Figure 0007927144000001
    Figure 0007927144000001
  • Figure 0007927144000002
    Figure 0007927144000002
  • Figure 0007927144000003
    Figure 0007927144000003
Patent Text Reader

Abstract

The present invention provides a method and system for a technical installation during the occurrence of an error condition in a controller device of the technical installation. The method includes receiving, by a processing unit (202), a plurality of program execution parameters from each of a plurality of controller devices in the technical installation. The method further includes determining an error condition in a first controller device of the plurality of controller devices. The method further includes determining, based on the determination of the error condition in the first controller device, a fail-safe logic associated with the first controller device from a plurality of fail-safe logics. The method further includes initiating, by the processing unit (202), execution of the fail-safe logic associated with the first controller device in a second controller device of the plurality of controller devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial automation, and more specifically, to a method and system for managing technical equipment during the occurrence of an error condition in a controller device of the technical equipment.

[0002] Technical equipment such as industrial plants comprises a plurality of field devices controlled by a plurality of controller devices such as programmable logic controllers, edge devices, and edge controllers. Examples of the plurality of field devices include, but are not limited to, control valves, motors, pumps, and actuators. Each of the plurality of controller devices is configured to control one or more of the plurality of field devices. When one controller device among the plurality of controller devices enters an error state, the function of the controller device is impaired. Accordingly, the function of the one or more field devices controlled by the controller device is also impaired, resulting in downtime of the industrial plant.

[0003] In view of the above, there is a need for an efficient and cost-effective method and system for managing technical equipment during the occurrence of an error condition in a controller device of the technical equipment. Accordingly, it is an object of the present invention to provide a method and system for managing technical equipment during the occurrence of an error condition in a controller device of the technical equipment.

[0004] The object of the present invention is achieved by a method and system for managing a technical facility during the occurrence of an error condition in the controller device of the technical facility. The technical facility comprises a plurality of field devices and a plurality of controller devices. Examples of the plurality of controller devices include edge devices, programmable logic controller devices, microprocessors, or processing units. Each of the plurality of controller devices is configured to execute an engineering program for controlling the plurality of field devices in the technical facility. In one example, the plurality of controller devices consists of one or more edge controllers. Examples of the plurality of field devices include, but are not limited to, control valves, motors, pumps, robots, lathes, sensors, and actuators. The plurality of field devices further consist of pressure sensors, temperature sensors, and vibration sensors. Further examples of the plurality of field devices include human-machine interfaces such as keyboards, mice, and touchscreens, and a plurality of client devices such as smartphones, desktop computers, and tablet computers that are networked to the plurality of controller devices. Examples of technical facilities include manufacturing plants, power plants, and chemical processing plants.

[0005] In a preferred embodiment, the method includes a processing unit receiving a plurality of program execution parameters from each of a plurality of controller devices in the technical equipment. The plurality of program execution parameters received from the controller devices consist of information relating to the runtime execution of the engineering program in the controller devices. For example, the plurality of program execution parameters consist of runtime information such as information relating to the memory fragmentation, scan cycleability, system resource utilization, and memory utilization of the controller devices during the execution of the engineering program in the controller devices. The engineering program consists of a plurality of programming blocks, each programming block consisting of one or more programming instructions. In one example, the engineering program is a graphic program consisting of program logic. The engineering program consists of a set of programmable instructions or statements corresponding to the program logic. Each programming block of the plurality of programming blocks corresponds to a functional block in the engineering design of the technical equipment.

[0006] In a preferred embodiment, the method includes a processing unit determining an error state in a first controller device among a plurality of controller devices. The error state is determined based on an analysis of a plurality of received program execution parameters. The first controller device is determined to be in an error state if it has paused the execution of the engineering program. In one example, the processing unit is configured to compare one or more program execution parameters among the plurality of received program execution parameters with one or more thresholds stored in memory. One or more program execution parameters are received from the first controller device during the execution of the engineering program in the first programmable logic controller. If one or more program execution parameters exceed one or more thresholds, the first controller device is determined to be in an error state. In another example, the processing unit is configured to determine an error state in the first controller device by applying a pattern recognition machine learning model to one or more program execution parameters. To train the pattern recognition machine learning model, the processing unit analyzes historical data consisting of sets of program execution parameters received from a plurality of controller devices during a specific time interval. The processing unit is further configured to identify multiple patterns in a set of program execution parameters based on the analysis. Furthermore, the processing unit is further configured to identify multiple relationships between the set of program execution parameters and one or more error states among multiple controller devices. Thus, the pattern recognition machine learning model is configured to recognize multiple patterns in multiple program execution parameters and to determine that a first controller device is in an error state. Examples of pattern recognition machine learning models include, but are not limited to, supervised and unsupervised learning models.

[0007] In a preferred embodiment, the method includes a processing unit determining, based on the determination of an error state in the first controller device, which fail-safe logic is associated with the first controller device from a plurality of fail-safe logics. In one example, each of the plurality of fail-safe logics has an identification number indicating the controller device associated with the fail-safe logic. Thus, the processing unit is configured to determine the fail-safe logic based on the identification number of the fail-safe logic that matches the identification number of the first controller device. In one example, the plurality of fail-safe logics consist of a plurality of programming instructions configured to manage a plurality of field devices in a technical installation. Each of the plurality of fail-safe logics is associated with a specific controller device among the plurality of controller devices. The fail-safe logic associated with the first controller device consists of a set of programming instructions configured to manage one or more field devices controlled by the first programming logic controller. The fail-safe logic can be executed by any of the plurality of controller devices to manage one or more field devices.

[0008] In a preferred embodiment, the method further includes the processing unit determining, based on the analysis of received program execution parameters, that the second controller device is not in an error state. For example, if one or more program execution parameters of the second controller device do not exceed one or more thresholds, the second controller device is determined to be not in an error state. In another example, the second controller device is determined to be not in an error state by a pattern recognition machine learning model.

[0009] In a preferred embodiment, the method further includes the processing unit sending fail-safe logic to the second controller device based on the determination that the second controller device is not in an error state. The processing unit is configured to send the determined fail-safe logic to the second controller device over a network.

[0010] In a preferred embodiment, the method includes a processing unit (202) establishing a connection path between a second controller device and one or more field devices associated with the first controller device. In one example, the processing unit is configured to establish the connection path over a network.

[0011] In a preferred embodiment, the method includes a processing unit initiating the execution of fail-safe logic associated with the first controller device in a second controller device among a plurality of controller devices. For example, the processing unit is configured to send a request to the second controller device over a network. The request is for initiating the execution of fail-safe logic in the second programmable controller. This causes the second programmable controller to execute the fail-safe logic and control one or more field devices associated with the first controller device. Advantageously, the one or more field devices are controlled and managed even when the first controller device is in an error state. Thus, the processing unit 202 smoothly transfers control of one or more field devices from the first controller device to the second controller device, avoiding downtime in the technical equipment.

[0012] In a preferred embodiment, the method includes a processing unit suspending the runtime of the first controller device based on a determination of an error state of the first controller device. In one example, the processing unit is configured to suspend the runtime of the first controller device by sending a suspend command to the first controller device. In one example, when the first controller device is suspended, the first controller device terminates the execution of the engineering program. Advantageously, the first controller device suspends the transmission of erroneous outputs to one or more field devices.

[0013] In a preferred embodiment, the method includes a processing unit (202) suspending one or more field devices based on the determination of an error condition in the first controller device. In one example, when one or more field devices are suspended, the functionality of one or more field devices is stopped. The processing unit is also configured to notify the user that the first controller device is in an error condition. Furthermore, the user can resolve the error condition of the first controller device by debugging an engineering program.

[0014] In a preferred embodiment, the method includes a processing unit determining, based on an analysis of a plurality of received program execution parameters, that an error condition in the first controller device has been resolved. To determine that an error condition has been resolved, the processing unit is configured to determine that the plurality of received program execution parameters are within a plurality of thresholds. Advantageously, once one or more errors in the engineering program have been resolved, the first controller device resumes execution of the engineering program.

[0015] In a preferred embodiment, the method further includes the processing unit restarting the runtime of the first controller device based on its determination that the error condition of the first controller device has been resolved. If it is determined that the error condition has been resolved, the processing unit is configured to send a trigger to the first controller device to restart the runtime execution of the engineering program.

[0016] In a preferred embodiment, the method further includes the processing unit determining the number of times an error condition was detected in the first controller device during a time interval. In a preferred embodiment, the method further includes the processing unit notifying the user of the number of detections. Advantageously, the user can evaluate the performance of the first controller device.

[0017] In one example, the plurality of program execution parameters consist of information relating to programming blocks of an engineering program to be executed by a first controller device at a specific time interval. In a preferred embodiment, the method further includes a processing unit determining, based on an analysis of the plurality of program execution parameters, the programming blocks of an engineering program to be executed by the first controller device at a specific time interval.

[0018] In a preferred embodiment, the method further includes the processing unit determining whether an error condition has occurred in the first controller device during the execution of a determined programming block. In a preferred embodiment, the method further includes the processing unit notifying the user that an error condition has occurred in the first controller device during the execution of a programming block determined by the first controller device.

[0019] In a preferred embodiment, the method further includes the processing unit (202) executing handling logic for controlling one or more field devices when an error condition is determined in the first programmable logic controller. The handling logic consists of a set of programming instructions configured to manage one or more field devices controlled by the first programming logic controller. The handling logic is executable by the processing unit.

[0020] The object of the present invention is also achieved by an industrial control system for managing technical equipment during the occurrence of an error condition in a controller device. The industrial control system comprises a processing unit and a memory coupled to the processing unit. The memory comprises a plant safety manager module stored in the form of machine-readable instructions executable by the processor. The plant safety manager module is configured to perform the method described above.

[0021] The object of the present invention can also be achieved by an industrial environment. The industrial environment comprises an industrial control system, a technical facility having one or more physical components, and a plurality of human-machine interfaces communicatively coupled to the industrial control system and the technical facility. The industrial control system is configured to perform the method steps described above.

[0022] The object of the present invention can also be achieved by a computer program product having internally stored machine-readable instructions for causing one or more processors to perform the method steps described above when executed by one or more processors.

[0023] Next, the above-mentioned features and other features of the present invention will be described with reference to the accompanying drawings. The embodiments shown are illustrative of the present invention and do not limit it.

[0024] Hereinafter, the present invention will be further described with reference to the illustrated embodiments shown in the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] [Figure 1] FIG. 1 is a block diagram of an industrial environment in which technical equipment can be managed during the occurrence of an error state in a controller device of the technical equipment, according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram of an industrial control system as shown in FIG. 1, in which an embodiment of the present invention can be implemented. [Figure 3] FIG. 3 is a block diagram of a plant safety manager module as shown in FIG. 2, in which an embodiment of the present invention can be implemented. [Figure 4A] FIG. 4 is a process flowchart showing an exemplary method for managing technical equipment during the occurrence of an error state in a controller device of the technical equipment, according to an embodiment of the present invention. [Figure 4B] FIG. 5 is a process flowchart showing an exemplary method for managing technical equipment during the occurrence of an error state in a controller device of the technical equipment, according to an embodiment of the present invention. [Figure 4C] FIG. 6 is a process flowchart showing an exemplary method for managing technical equipment during the occurrence of an error state in a controller device of the technical equipment, according to an embodiment of the present invention. [Figure 4D] FIG. 7 is a process flowchart showing an exemplary method for managing technical equipment during the occurrence of an error state in a controller device of the technical equipment, according to an embodiment of the present invention.

[0026] Various embodiments will be described with reference to the drawings, wherein like reference numerals are used for reference, and like reference numerals are used throughout to refer to like elements. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of one or more embodiments. It is apparent that each embodiment may be practiced without these specific details.

[0027] FIG. 1 is a block diagram of an industrial environment 100 capable of managing a technical installation 106 during the occurrence of an error condition in a controller device of the technical installation 106 according to an embodiment of the present invention. In FIG. 1, the industrial environment 100 includes an industrial control system 102, a technical installation 106, and a plurality of human-machine interfaces 120A to 120N. As used herein, the "industrial environment" refers to a processing environment comprising configurable physical and logical computing resources, such as networks, servers, storages, applications and services, and data distributed on a platform such as a cloud computing platform. The industrial environment 100 provides on-demand network access to a shared pool of configurable physical and logical computing resources. The industrial control system 102 is communicatively connected to the technical installation 106 via a network connection 104 (such as a local area network (LAN), a wide area network (WAN), Wi-Fi, the Internet, any short-range communication or long-range communication). The industrial control system 102 is also connected to the plurality of human-machine interfaces 120A to 120N via the network connection 104.

[0028] The industrial control system 102 is connected to a plurality of field devices 126A-126N in the technical equipment 106 via a network connection 104. Examples of the plurality of field devices 126A-126N include servers, robots, switches, automation devices, programmable logic controllers (PLCs), human-machine interfaces (HMIs), motors, valves, pumps, actuators, sensors, and other industrial equipment. The plurality of field devices 126A-126N can be connected to each other or to multiple other components (not shown in Figure 1) via physical connections. Physical connections can be via wiring between the plurality of field devices 126A-126N. Alternatively, the plurality of field devices 126A-126N can also be connected via non-physical connections (such as the Internet of Things (IoT)) and 5G networks. While Figure 1 shows the industrial control system 102 connected to one technical equipment 106, those skilled in the art can envision that the industrial control system 102 may be connected to multiple technical equipment located in different geographical locations via the network connection 104. Multiple field devices 126A to 126N further include sensors such as pressure sensors, voltage sensors, temperature sensors, and vibration sensors. In such cases, multiple field devices 126A to 126N obtain one or more measurements from the technical equipment 106. One or more measurements consist of temperature measurements, pressure measurements, and vibration measurements.

[0029] The technical equipment 106 further comprises a plurality of controller devices 108A to 108N. Examples of the plurality of controller devices 108A to 108N include, but are not limited to, controller devices such as controller devices, microprocessors, and other processing units. The plurality of controller devices 108A to 108N are configured to execute engineering programs stored in the industrial control system 102 over a plurality of scan cycles. The plurality of controller devices 108A to 108N are configured to receive a plurality of input parameter values ​​from a plurality of field devices 126A to 126N. The plurality of controller devices 108A to 108N are further configured to transmit a plurality of output parameter values ​​to the plurality of field devices 126A to 126N. Each of the plurality of field devices 126A to 126N is connected to one or more of the plurality of controller devices 108A to 108N via a network connection 104. Each of the plurality of controller devices 108A to 108N is configured to control one or more of the plurality of field devices 126A to 126N. For example, the first controller device 108A is configured to control the first field device 126A and the second field device 126N among a plurality of field devices 126A to 126N.

[0030] The multiple human-machine interfaces 120A to 120N can be desktop computers, laptop computers, tablets, smartphones, etc. Each of the multiple human-machine interfaces 120A to 120N is provided with engineering tools 122A to N for generating and / or editing engineering programs. The multiple human-machine interfaces 120A to 120N can access the industrial control system 102 to automatically generate engineering programs. The multiple human-machine interfaces 120A to 120N can access cloud applications (such as providing visualization of the performance of multiple field devices 126A to 126N via a web browser). Throughout this specification, the terms “human-machine interface,” “client device,” and “user device” are used interchangeably. One or more of the multiple human-machine interfaces 120A to 120N are further configured to receive multiple user actions from multiple users. Multiple user actions consist of user input, user commands, user gestures, programming instructions, and user passwords. Multiple user actions are entered by multiple users to execute one or more tasks using multiple controller devices 108A-108N and multiple field devices 126A-126N.

[0031] It should be noted that the industrial control system 102 is connected to a controller device 124. An example of the controller device 124 is a controller device, a microprocessor, and other processing units, but is not limited to these. The controller device 124 is configured to execute the engineering program generated by the industrial control system 102 over multiple scan cycles. The controller device 124 is configured to receive multiple input parameter values ​​from multiple sensor devices 126A-126N and multiple human-machine interfaces 120A-120N. The controller device 124 is further configured to transmit multiple output parameter values ​​to multiple field devices 108A-108N and multiple human-machine interfaces.

[0032] The industrial control system 102 may be a standalone server installed at a control station or a remote server on a cloud computing platform. In one preferred embodiment, the industrial control system 102 may be a cloud-based industrial control system. The industrial control system 102 may provide an application (such as a cloud application) for managing a technical facility 106 comprising multiple field devices 108A to 108N. The industrial control system 102 may comprise a digitalization platform 110 (such as a cloud computing platform), a plant safety manager module 112, a server 114 including hardware resources and an operating system (OS), a network interface 116, and a database 118. The network interface 116 enables communication between the industrial control system 102, the technical facility 106, multiple human-machine interfaces 120A to 120N, multiple field devices 126A to 126N, and multiple controller devices 108A to 108N. Interfaces, such as a cloud interface (not shown in Figure 1), can enable engineers to access multiple controller devices 108A to 108N in multiple field devices 126A to 126N and perform multiple user actions on controller device 124 and plant safety manager module 112.

[0033] Server 114 may include one or more servers on which an OS is installed. Server 114 may include one or more processors, one or more storage devices for storing data and machine-readable instructions, such as memory units, applications and application programming interfaces (APIs), and other peripherals necessary to provide computing (such as cloud computing) functionality. In one example, the digitization platform 110 may be implemented on Server 114. The digitization platform 110 uses the hardware resources and OS of Server 114 to realize functionalities such as data reception, data processing, data rendering, and data communication, and provides the aforementioned services using an internally implemented application programming interface. The digitization platform 110 may consist of a combination of dedicated hardware and software built on the hardware and OS. In one exemplary embodiment, the digitization platform 110 may support an integrated development environment (IDE) with a program editor and compiler that enables users of multiple human-machine interfaces 120A to 120N to generate engineering programs. The digital platform 110 may further include a plant safety manager module 112 configured to enable management of the technical equipment 106 during an error condition in at least one of the multiple controller devices 108A to 108N. Details of the plant safety manager module 112 will be described with reference to Figure 3.

[0034] Database 118 stores information related to technical equipment 106, multiple controller devices 108A-108N, multiple field devices 126A-126N, and multiple human-machine interfaces 120A-120N. Database 118 is, for example, a Structured Query Language (SQL) data store or a NoSQL (NoSQL) data store. In one exemplary embodiment, database 118 can be configured as a cloud-based database implemented in an industrial environment 100, with computing resources provided as a service on platform 110. According to another embodiment of the present invention, database 118 is a location on a file system that is directly accessible by the plant safety manager module 112.

[0035] In one example, the plant safety manager module 112 is implemented in a controller device 124 configured to manage the technical equipment 106 during an error condition in the first controller device 108A. The controller device 124 is communicatively coupled to multiple controller devices 108A-108N, multiple field devices 126A-126N, and an industrial control system 102. In one example, a user can write programming code to the controller device 124 using multiple human-machine interfaces 120A-120N.

[0036] Figure 2 is a block diagram of the industrial control system 102 shown in Figure 1, which can implement one embodiment of the present invention. In Figure 2, the industrial control system 102 includes a processing unit 202, an accessible memory 204, a storage unit 206, a communication interface 208, an input / output unit 210, a network interface 212, and a bus 214.

[0037] As used herein, processing unit 202 means any type of computing circuit, such as a microprocessor unit, microcontroller, complex instruction set computing microprocessor unit, reduced instruction set computing microprocessor unit, extra-long instruction word microprocessor unit, explicit parallel instruction computing microprocessor unit, graphics processing unit, digital signal processing unit, or any other type of processing circuit. Processing unit 202 may also include embedded controllers such as general-purpose or programmable logic devices or arrays, application-specific integrated circuits, and single-chip computers.

[0038] Memory 204 can be non-transient volatile memory and non-volatile memory. Memory 204 can be coupled for communication with the processing unit 202, such as as a computer-readable storage medium. The processing unit 202 can execute machine-readable instructions and / or source code stored in memory 204. Various machine-readable instructions can be stored in and accessed from memory 204. Examples of memory 204 include read-only memory, random-access memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, removable media drives for handling hard drives, compact disks, digital video disks, floppy disks, magnetic tape cartridges, memory cards, etc., and any other suitable element for storing data and machine-readable instructions. In this embodiment, memory 204 includes an integrated development environment (IDE) 216. The IDE 216 includes a data acquisition and analysis module 112 stored in the form of machine-readable instructions in one of the above-mentioned storage media, which communicates with and can be executed by the processor 202.

[0039] When executed by the processing unit 202, the plant safety manager module 112 causes the processing unit 202 to receive multiple program execution parameters from each of the multiple controller devices 108A to 108N in the technical equipment. The multiple program execution parameters received from the controller devices consist of information regarding the runtime execution of the engineering program in the controller devices. For example, the multiple program execution parameters consist of runtime information such as information regarding the memory fragmentation, scan cycleability, system resource utilization, and memory utilization of the controller devices during the execution of the engineering program in the controller devices. The engineering program consists of multiple programming blocks, each programming block consisting of one or more programming instructions. In one example, the engineering program is a graphic program consisting of program logic such as the engineering program. The engineering program consists of a set of programmable instructions or statements corresponding to the program logic. Each programming block of the multiple programming blocks corresponds to a functional block in the engineering design of the technical equipment 106.

[0040] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine the error state of the first controller device 108A among the multiple controller devices 108A to 108N. The error state is determined based on the analysis of multiple received program execution parameters. The first controller device 108A is determined to be in an error state if it has paused the execution of the engineering program. In one example, the processing unit 202 is configured to compare one or more of the received program execution parameters with one or more thresholds stored in memory, such as the accessible memory 204. One or more program execution parameters are received from the first controller device 108A while the engineering program is being executed in the first programmable logic controller 108A. If one or more program execution parameters exceed one or more thresholds, the first controller device 108A is determined to be in an error state. In another example, the processing unit 202 is configured to apply a pattern recognition machine learning model to one or more program execution parameters to determine an error state in the first controller device 108A. To train the pattern recognition machine learning model, historical data consisting of sets of program execution parameters received from multiple controller devices during a specific time interval is analyzed by the processing unit 202. Based on the analysis, the processing unit 202 is further configured to identify multiple patterns in the set of program execution parameters. Furthermore, the processing unit 202 is further configured to identify multiple relationships between the set of program execution parameters and the error state of one or more of the multiple controller devices 108A to 108N. Thus, the pattern recognition machine learning model is configured to recognize multiple patterns in the multiple program execution parameters and to determine that the first controller device 108A is in an error state.Examples of pattern recognition machine learning models include, but are not limited to, supervised and unsupervised learning models.

[0041] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine which failsafe logic is associated with the first controller device from among a plurality of failsafe logics based on the determination of an error state in the first controller device. In one example, each of the plurality of failsafe logics has an identification number that indicates the controller device associated with the failsafe logic. Thus, the processing unit 202 is configured to determine the failsafe logic based on the identification number of the failsafe logic that matches the identification number of the first controller device. In one example, the plurality of failsafe logics consist of a plurality of programming instructions configured to manage a plurality of field devices 126A to 126N in the technical equipment 106. Each of the plurality of failsafe logics is associated with a specific controller device among the plurality of controller devices 108A to 108N. The failsafe logic associated with the first controller device 108A consists of a set of programming instructions configured to manage one or more field devices (126A and 126B) controlled by the first programming logic controller 108A. Fail-safe logic can be implemented by one of several controller devices 108A to 108N to manage one or more field devices 126A and 126B.

[0042] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine, based on the analysis of the received program execution parameters, that the second controller device 108B among the multiple controller devices 108A to 108N is not in an error state. For example, if one or more program execution parameters of the second controller device 108B do not exceed one or more thresholds, the second controller device 108B is determined to be not in an error state. In another example, the second controller device 108B is determined to be not in an error state by a pattern recognition machine learning model.

[0043] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to send fail-safe logic to the second controller device 108B based on its determination that the second controller device 108B is not in an error state. The processing unit 202 is configured to send the determined fail-safe logic to the second controller device 108B via the network 104.

[0044] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to establish a connection path between the second controller device 108B and one or more field devices (126A and 126B) associated with the first controller device 108A. In one example, the processing unit 202 is configured to establish the connection path via the network 104.

[0045] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to initiate the execution of the fail-safe logic associated with the first controller device 108A in the second controller device 108B among the multiple controller devices 108A to 108N. For example, the processing unit 202 is configured to send a request to the second controller device 108B via the network 104. The request is to initiate the execution of the fail-safe logic in the second programmable controller 108B.

[0046] When executed by the processing unit 202, the plant safety manager module 112 further instructs the processing unit 202 to suspend the execution of the engineering program by the first controller device 108A based on the determination of the error state of the first controller device 108A. In one example, the processing unit is configured to send a pause command to the first controller device 108A in order to suspend the runtime of the first controller device 108A. In one example, when the first controller device 108A is paused, the first controller device 108A terminates the execution of the engineering program.

[0047] When executed by the processing unit 202, the plant safety manager module 112 further instructs the processing unit 202 to temporarily suspend one or more field devices (126A and 126B) based on the determination of an error state in the first controller device 108A. In one example, when one or more field devices (126A and 126B) are temporarily suspended, the functionality of one or more field devices (126A and 126B) is stopped. Furthermore, the processing unit 202 is further configured to notify the user that the first controller device 108A is in an error state. Furthermore, the user can resolve the error state of the first controller device 108A by debugging the engineering program.

[0048] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine, based on the analysis of the received program execution parameters, that the error condition of the first controller device has been resolved. In order to determine that the error condition has been resolved, the processing unit 202 is configured to determine that the received program execution parameters are within a certain threshold.

[0049] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to restart the runtime of the first controller device 108A based on its determination that the error condition of the first controller device 108A has been resolved. If it is determined that the error condition has been resolved, the processing unit 202 is configured to send a trigger to the first controller device 108A to restart the runtime execution of the engineering program.

[0050] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine the number of times an error state was detected in the first controller device 108A during a time interval. When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to notify the user of the number of detections via a plurality of human-machine interfaces 120A to 120N.

[0051] In one example, the multiple program execution parameters consist of information about programming blocks of an engineering program that are executed by the first controller device 108A at specific time intervals. When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine, based on the analysis of the multiple program execution parameters, the programming blocks of the engineering program that are executed by the first controller device 108A at specific time intervals.

[0052] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to determine whether an error condition has occurred in the first controller device 108A during the execution of the determined programming block. When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to notify the user that an error condition has occurred in the first controller device during the execution of the programming block determined by the first controller device 108A.

[0053] When executed by the processing unit 202, the plant safety manager module 112 further causes the processing unit 202 to execute handling logic for controlling one or more field devices 126A~B when an error condition is detected in the first programmable logic controller 108A. The handling logic consists of a set of programming instructions configured to manage one or more field devices controlled by the first programming logic controller. The handling logic is executable by the processing unit 202.

[0054] The communication interface 208 is configured to establish a communication session between multiple human-machine interfaces 120A-120N, an industrial control system 102, and a controller device 124. The communication interface 208 enables one or more engineering applications running on the multiple human-machine interfaces 120A-120N to import / export engineering programs to the controller device 124. In one embodiment, the communication interface 208 interacts with interfaces in the multiple human-machine interfaces 120A-120N to enable an engineer to access an engineering program associated with an engineering project file and perform one or more actions on the engineering program stored in the industrial control system 102.

[0055] The I / O unit 210 may include input devices such as a keypad, a touch-sensitive display, or a camera (such as a camera that receives gesture-based input) that can receive one or more input signals, such as user commands for processing engineering project files. The I / O unit 210 may also be a display unit for displaying a graphical user interface that visualizes the behavioral model associated with the modified engineering program and displays status information related to each set of actions performed on the graphical user interface. Examples of action sets include running predefined tests, downloading, compiling, and deploying the graphical program. The bus 214 functions as an interconnection between the processor 202, memory 204, and the I / O unit 210.

[0056] The network interface 212 can be configured to handle network connectivity, bandwidth, and network traffic between the industrial control system 102, the multiple human-machine interfaces 120A to 120N, and the technical equipment 106.

[0057] Those skilled in the art will understand that the hardware depicted in Figure 2 may differ for individual implementations. For example, other peripheral devices such as optical disc drives, local area network (LAN), wide area network (WAN), wireless (Wi-Fi, etc.) adapters, graphics adapters, disk controllers, and input / output (I / O) adapters may be used in addition to or instead of the depicted hardware. The examples depicted are provided for illustrative purposes only and do not constitute an architectural limitation of this disclosure.

[0058] Those skilled in the art will recognize that, for the sake of simplification and clarity, the complete structure and operation of all data processing systems suitable for use with this disclosure are not described or explained herein. Instead, only many parts of the industrial control system 102 specific to or necessary for understanding this disclosure are described and explained. The remaining parts of the structure and operation of the industrial control system 102 can be adapted to any of the various current implementations and embodiments known in the art.

[0059] Figure 3 is a block diagram of a plant safety manager module 112, as shown in Figure 2, which can implement one embodiment of the present invention. In Figure 3, the plant safety manager module 112 comprises a request handler module 302, a controller device selector module 304, an analysis module 306, a modification module 308, an engineering object database 310, a verification module 312, and an implementation module 314. Figure 3 is described in conjunction with Figures 1 and 2.

[0060] The request handler module 302 is configured to receive requests for managing the technical equipment 106. For example, requests are received via a network from one or more users outside the industrial environment 100. In an alternative embodiment, requests are received via a network from one or more human-machine interfaces 120A to 120N. The request handler module 302 is further configured to take in multiple program execution parameters sent by multiple controller devices 108A to 108N.

[0061] The controller device selector module 304 is configured to determine the second controller device 108B in order to execute the fail-safe logic associated with the first controller device.

[0062] The analysis module 306 is configured to analyze multiple program execution parameters in order to determine an error state in the first controller device.

[0063] The correction module 308 is configured to correct the failsafe logic before sending it to the second programmable logic control 108B.

[0064] The engineering object database 310 is configured to generate an engineering object library that includes multiple fail-safe logics, information about multiple field devices 126A-126N, and physical connections between the multiple field devices 126A-126N and the multiple controller devices 108A-108N.

[0065] The verification module 312 is configured to verify engineering programs executed by multiple controller devices 108A to 108N. The verification module 312 is configured to simulate the execution of multiple controller devices 108A to 108N.

[0066] The deployment module 314 is configured to deploy the fail-safe logic associated with the first controller device 108A to the second controller device 108B.

[0067] Figures 4A to 4E show process flowcharts illustrating an exemplary method 400 for managing technical equipment during an error condition of a controller device, according to one embodiment of the present invention. Figures 4A to 4E are described in conjunction with Figures 1 to 3.

[0068] In 402, the plant safety manager module 112 causes the processing unit 202 to receive multiple program execution parameters from each of the multiple controller devices 108A to 108N in the technical equipment. The multiple program execution parameters received from the controller devices consist of information regarding the runtime execution of the engineering program in the controller devices. For example, the multiple program execution parameters consist of runtime information such as information regarding the memory fragmentation, scan cycleability, system resource utilization, and memory utilization of the controller devices during the execution of the engineering program in the controller devices. The engineering program consists of multiple programming blocks, each programming block consisting of one or more programming instructions. In one example, the engineering program is a graphic program consisting of program logic. The engineering program consists of a set of programmable instructions or statements corresponding to the program logic. Each programming block in the multiple programming blocks corresponds to a functional block in the engineering design of the technical equipment 106.

[0069] In 404, the plant safety manager module 112 further causes the processing unit 202 to determine the error state of the first controller device 108A among the multiple controller devices 108A to 108N. The error state is determined based on the analysis of multiple received program execution parameters. The first controller device 108A is determined to be in an error state if it has temporarily suspended the execution of the engineering program. In one example, the processing unit 202 is configured to compare one or more of the received program execution parameters with one or more thresholds stored in a memory such as an accessible memory 204. One or more program execution parameters are received from the first controller device 108A while the engineering program is being executed in the first programmable logic controller 108A. If one or more program execution parameters exceed one or more thresholds, the first controller device 108A is determined to be in an error state. In another example, the processing unit 202 is configured to apply a pattern recognition machine learning model to one or more program execution parameters to determine the error state of the first controller device 108A. To train the pattern recognition machine learning model, historical data consisting of sets of program execution parameters received from multiple controller devices during a specific time interval is analyzed by the processing unit 202. The processing unit 202 is further configured to identify multiple patterns in the set of program execution parameters based on the analysis. Furthermore, the processing unit 202 is further configured to identify multiple relationships between the set of program execution parameters and the error state of one or more of the multiple controller devices 108A to 108N. Thus, the pattern recognition machine learning model is configured to recognize multiple patterns in the multiple program execution parameters and to determine that the first controller device 108A is in an error state.Examples of pattern recognition machine learning models include, but are not limited to, supervised and unsupervised learning models.

[0070] In 406, the plant safety manager module 112 further causes the processing unit 202 to determine the failsafe logic associated with the first controller device from among a plurality of failsafe logics based on the determination of an error state in the first controller device. In one example, each of the plurality of failsafe logics has an identification number indicating the controller device associated with the failsafe logic. Therefore, the processing unit 202 is configured to determine the failsafe logic based on the identification number of the failsafe logic that matches the identification number of the first controller device. In one example, the plurality of failsafe logics consist of a plurality of programming instructions configured to manage a plurality of field devices 126A to 126N in the technical equipment 106. Each of the plurality of failsafe logics is associated with a specific controller device among the plurality of controller devices 108A to 108N. The failsafe logic associated with the first controller device 108A consists of a set of programming instructions configured to manage one or more field devices (126A and 126B) controlled by the first programming logic controller 108A. Fail-safe logic can be implemented by one of several controller devices 108A to 108N to manage one or more field devices 126A and 126B.

[0071] In 408, the plant safety manager module 112 further causes the processing unit 202 to determine that the second controller device 108B is not in an error state based on the analysis of the received program execution parameters. For example, if one or more program execution parameters of the second controller device 108B do not exceed one or more thresholds, the second controller device 108B is determined to be not in an error state. In another example, the second controller device 108B is determined to be not in an error state by a pattern recognition machine learning model.

[0072] In 410, the plant safety manager module 112 further causes the processing unit 202 to send fail-safe logic to the second controller device 108B based on its determination that the second controller device 108B is not in an error state. The processing unit 202 is configured to send the determined fail-safe logic to the second controller device 108B via the network 104.

[0073] In 412, the plant safety manager module 112 further causes the processing unit 202 to establish a connection path between the second controller device 108B and one or more field devices (126A and 126B) associated with the first controller device 108A. In one example, the processing unit 202 is configured to establish the connection path via the network 104.

[0074] In 414, the plant safety manager module 112 further instructs the processing unit 202 to initiate the execution of the fail-safe logic associated with the first controller device 108A in the second controller device 108B among the multiple controller devices 108A to 108N. For example, the processing unit 202 is configured to send a request to the second controller device 108B via the network 104. The request is to initiate the execution of the fail-safe logic in the second programmable controller 108B.

[0075] In 416, the plant safety manager module 112 further instructs the processing unit 202 to suspend the runtime of the first controller device 108A based on the determination of the error state of the first controller device 108A. In one example, the processing unit is configured to send a pause command to the first controller device 108A in order to suspend the runtime of the first controller device 108A. In one example, when the first controller device 108A is paused, the first controller device 108A terminates the execution of the engineering program.

[0076] In 418, the plant safety manager module 112 further instructs the processing unit 202 to temporarily suspend one or more field devices (126A and 126B) based on the determination of an error state in the first controller device 108A. For example, when one or more field devices (126A and 126B) are temporarily suspended, the functions of one or more field devices (126A and 126B) are stopped. The processing unit 202 is also configured to notify the user that the first controller device 108A is in an error state. Furthermore, the user can resolve the error state of the first controller device 108A by debugging the engineering program.

[0077] In 420, the plant safety manager module 112 further causes the processing unit 202 to determine, based on the analysis of the received program execution parameters, that the error state of the first controller device has been resolved. To determine that the error state has been resolved, the processing unit 202 is configured to determine that the received program execution parameters are within a range of thresholds.

[0078] In 422, the plant safety manager module 112 further instructs the processing unit 202 to restart the runtime of the first controller device 108A based on its determination that the error condition of the first controller device 108A has been resolved. If it is determined that the error condition has been resolved, the processing unit 202 is configured to send a trigger to the first controller device 108A to restart the runtime execution of the engineering program.

[0079] In step 424, the plant safety manager module 112 further causes the processing unit 202 to determine the number of times an error condition was detected in the first controller device 108A during the time interval. In step 426, the plant safety manager module 112 further causes the processing unit 202 to notify the user of the number of detections via a plurality of human-machine interfaces 120A to 120N.

[0080] In one example, the multiple program execution parameters consist of information about programming blocks of an engineering program to be executed by the first controller device 108A at a specific time interval. In 428, the plant safety manager module 112 further causes the processing unit 202 to determine the programming blocks of the engineering program to be executed by the first controller device 108A at a specific time interval based on the analysis of the multiple program execution parameters.

[0081] In step 430, the plant safety manager module 112 further causes the processing unit 202 to determine whether an error condition has occurred in the first controller device 108A during the execution of the determined programming block. In step 432, the plant safety manager module 112 further causes the processing unit 202 to notify the user that an error condition has occurred in the first controller device during the execution of the programming block determined by the first controller device 108A.

[0082] In 434, the plant safety manager module 112 further causes the processing unit 202 to execute handling logic for controlling one or more field devices 126A to 126B when an error condition is detected in the first programmable logic controller 108A. The handling logic consists of a set of programming instructions configured to manage one or more field devices controlled by the first programming logic controller. The handling logic is executable by the processing unit 202.

[0083] The present invention may take the form of a computer program product comprising program modules accessible from a computer-available or computer-readable medium storing program code used by or in connection with one or more computers, processors, or instruction execution systems. For the purposes of this description, the computer-available or computer-readable medium may be any device capable of storing, storing, communicating, propagating, or transferring programs used by or in connection with instruction execution systems, apparatus, or devices. The medium may be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system (or apparatus or device), and the definition of a physical computer-readable medium does not include the propagation medium itself as a signal carrier, but includes semiconductors or solid-state memory, magnetic tape, removable computer diskettes, random-access memory (RAM), read-only memory (ROM), rigid magnetic disks, and optical discs such as compact disc read-only memory (CD-ROM), compact disc read / write, and DVD. Both the processor and program code for implementing each aspect of the present technology may be centralized, distributed (or a combination thereof), as is known to those skilled in the art.

[0084] While the present invention has been described in detail with reference to specific embodiments, it should be understood that the present invention is not limited to these embodiments. In view of this disclosure, many modifications and variations will exist for those skilled in the art without departing from the scope of the various embodiments of the present invention described herein. Accordingly, the scope of the present invention is indicated not by the foregoing description but by the following claims. All modifications, variations, and variations that fall within the meaning and scope of the claims and their equivalents are considered to be within that scope. All advantageous embodiments described in the method claims may also be applied to system / apparatus claims.

Claims

1. A method for managing a technical device (106) while an error condition occurs in the controller device (108A) of the technical device (106), wherein the technical device comprises one or more field devices (126A to 126B) controlled by a first controller device (108A), and the method is The processing unit (202) receives a plurality of program execution parameters from each of the plurality of controller devices (108A to 108N) in the technical equipment (106), wherein the plurality of program execution parameters associated with each controller device consist of runtime information of the controller device during runtime execution of the engineering program in the controller device. The processing unit (202) determines the error state of the first controller device (108A) among the plurality of controller devices (108A to 108N), wherein the error state is determined based on the analysis of the plurality of received program execution parameters. The processing unit (202) determines, based on the determination of the error state in the first controller device (108A), the fail-safe logic associated with the first controller device (108A) from among a plurality of fail-safe logics, The processing unit (202) initiates the execution of the fail-safe logic associated with the first controller device (108A) in the second controller device (108B) among the plurality of controller devices (108-108N). Includes, The execution of the aforementioned fail-safe logic is initiated. The processing unit (202) determines, based on the analysis of the received program execution parameters, that the second controller device (108B) is not in an error state, Based on the determination that the second controller device is not in the error state, the processing unit (202) transmits the failsafe logic to the second controller device (108B), The processing unit (202) establishes a connection between the second controller device (108B) and the one or more field devices associated with the first controller device. Methods that include...

2. The method according to claim 1, further comprising the processing unit (202) temporarily suspending the execution of the engineering program in the first controller device (108A) based on the determination of the error state of the first controller device (108A).

3. The method according to claim 2, further comprising the processing unit (202) temporarily suspending the execution of the first controller device (108A) based on the determination of the error state of the first controller device (108A).

4. The above method further, The processing unit (202) temporarily pauses one or more field devices (126A to 126B) based on the determination of the error state in the first controller device (108A), The processing unit (202) determines that the error state of the first controller device (108A) has been resolved, and the resolution of the error state is determined based on the analysis of the received plurality of program execution parameters. Based on the determination by the processing unit (202) that the error state of the first controller device (108A) has been resolved, the runtime of the first controller device (108A) is restarted. The method according to claim 3, including the method described in claim 3.

5. The above method further, The processing unit (202) determines the number of times the error state was detected in the first controller device (108A) during the time interval, The processing unit (202) notifies the user of the number of times the determination has been made. The method according to claim 1, including the method described in claim 1.

6. The above method further, The processing unit (202) determines the programming block of the engineering program to be executed by the first controller device (108A) based on the analysis of the program execution parameters, The processing unit (202) determines whether the error state was detected in the first controller device during the execution of the programming block determined by the processing unit (202), The processing unit (202) notifies the user that the first controller device (108A) has determined the error state during the execution of the programming block determined by the first controller device (108A). The method according to claim 1, including the method described in claim 1.

7. The above method further, When the error state in the first controller device (108A) is determined by the processing unit (202), it executes handling logic for controlling one or more field devices (126A to 126B). The method according to claim 1, including the method described in claim 1.

8. An industrial control system (102) for managing technical equipment during an error condition in a controller device, Processing unit (202), The memory (204) is coupled to the processing unit (202) and Equipped with, The memory comprises a plant safety manager module (112) in which machine-readable instructions that can be executed by one or more processors are stored, and the plant safety manager module can perform the method according to any one of claims 1 to 7. Industrial control system (102).

9. Industrial environment (100), The industrial control system (102) according to claim 8, A technical facility (106) comprising one or more physical components, Multiple human-machine interfaces (120A to 120N) are communicably connected to the industrial control system (102) via a network (104) and Equipped with, Industrial environment (100).

10. A computer program product having internally stored machine-readable instructions for causing a processor to execute the method described in any one of claims 1 to 7 when executed by a processing unit (202).

Citation Information

Patent Citations

  • Fail-safe system in integrated control of vehicle

    JP2002221075A

  • Monitoring system of automatic door and accounting system

    JP2003090169A

  • PLC system and backup method therefor

    JP2004362133A

  • Equipment element maintenance analysis system and facility element maintenance analysis method

    JP2019021008A