Multi-cluster system and method for handing over process thereby

The multiple cluster system with redundant gateways and application devices ensures continuous processing by seamlessly switching to backup systems upon detecting abnormalities, addressing the challenge of maintaining availability and determinism in control systems.

WO2025115410A1PCT designated stage expired Publication Date: 2025-06-05HITACHI LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/035953
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-30
Filing Date
2024-10-08
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Existing control systems face challenges in maintaining availability and determinism when a control center becomes unusable, leading to system dysfunction or shutdown, and fail to seamlessly continue processing due to one-to-one linking of tracking control devices and equipment interfaces.

Method used

A multiple cluster system comprising a first cluster of gateways managing multiple bases and a second cluster of application devices, where each forms a redundant system, allowing seamless handover of processing by changing application devices and gateways to primary systems upon detecting abnormalities.

Benefits of technology

Enables continuous processing with minimal additional cost even if the control center becomes unusable, ensuring high availability and determinism by implementing a redundant system with seamless handover mechanisms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024035953_05062025_PF_FP_ABST
    Figure JP2024035953_05062025_PF_FP_ABST
Patent Text Reader

Abstract

In order to provide a system that makes it possible to continue a process at a small additional cost even when an existing control base becomes unusable, the present invention provides a multi-cluster system comprising: a first cluster provided with a plurality of GWs for managing a plurality of bases; and a second cluster provided with a plurality of application devices (hereinafter, referred to as "app devices") for managing a business system, wherein the GWs and the app devices each form a redundant system, one of the app devices serves as a main system and outputs a control output for a control device provided in the business system to the GWs, one of the GWs serves as a main system and transmits the control output received from the app device serving as the main system to the control device, the first cluster checks the soundness of each of the bases and excludes the app device serving as the main system from the second cluster if the base provided with the app device serving as the main system is abnormal, and the second cluster continues the process by changing the main system to an app device other than the excluded app device.
Need to check novelty before this filing date? Find Prior Art

Description

Multiple cluster system and method for taking over processing using said system

[0001] The present invention relates to a multiple cluster system and a method for taking over processing using the system.

[0002] Cluster management software such as RAFT (Repeat Algorithm for Tracking and Forwarding) is utilized as a way to achieve both improved availability and the guaranteed determinism required for control systems. RAFT (Repeat Algorithm for Tracking and Forwarding) is a technology that provides a general-purpose means of distributing state machines across a cluster of computing systems.

[0003] Furthermore, Patent Document 1 discloses a data synchronization method for multiple tracking control devices. Specifically, when a tracking control device detects an abnormality in another tracking control device, the plan data synchronization unit of the tracking control device copies plan data other than the plan data used in the most recent control of the other tracking control device, which is stored in the auxiliary storage device of the tracking control device, to the main storage device of the tracking control device to synchronize the plan data of the other tracking control device.

[0004] JP 2016-137862 A

[0005] When a redundant system of primary and secondary systems is configured at an existing control base, it is desirable to add as few devices as possible. For example, if the system is configured from a control center with primary and secondary systems and a single-system cloud, if the control center is submerged, the majority of the systems will be lost, and the RAFT cluster will become dysfunctional (for example, there is a problem in that processing will have to continue while accepting that both primary systems will be present, or the entire system will be shut down to ensure safety).

[0006] Furthermore, in the technology disclosed in Patent Document 1, since the area equipped with the equipment and the tracking control device are linked one-to-one, if both the tracking control device and the equipment interface (equipment I / F) are lost, operation cannot continue. Also, when the tracking control devices detect a fault through mutual monitoring between them and take over processing, the tracking control devices are out of communication with each other, but if they can communicate with the equipment interface (equipment I / F), the problem remains that both systems will be the main systems.

[0007] Therefore, an object of the present invention is to provide a system that allows processing to continue at little additional cost even when an existing control center becomes unusable.

[0008] In order to solve the above problems, one representative multi-cluster system according to the present invention is a multi-cluster system consisting of a first cluster having multiple GWs (gateways) that manage multiple bases, and a second cluster having multiple application devices that manage a business system, in which the GWs and application devices each form a redundant system, one of the application devices acts as a primary system and outputs a control output to the GW for a control device equipped in the business system, and one of the GWs acts as a primary system and transmits a control output received from the application device of the primary system to the control device, the first cluster checks the health of each base, and if the base that has the application device that has become the primary system is abnormal, it excludes that application device from the second cluster, and the second cluster changes an application device other than the excluded application device to the primary system and continues processing.

[0009] According to the present invention, it is possible to provide a system that allows processing to continue at a small additional cost even when an existing control center becomes unavailable. Problems, configurations, and effects other than those described above will become clear from the description of the following embodiments.

[0010] 1 is a diagram showing an example of the configuration blocks of a traffic control system including a redundant system centered around a traffic control center. FIG. 2 is a diagram showing an example of the components provided in a signal control device. FIG. 3 is a diagram showing an example of the components provided in a GW. FIG. 4 is a diagram showing a table summarizing the installation locations, cluster roles, master / slave roles, and device statuses for the signal control device and GW. FIG. 5 is a diagram showing a flowchart of cluster processing by each GW that constitutes a base determination cluster. FIG. 6 is a diagram showing, in a table, the status or status recognition of each of the GWs of both systems provided in the traffic control center 1, and each GW provided in city sub-center A and city sub-center B, and the final status of the system, for each failure event. FIG. 7 is a diagram showing the system operating status, device list, and messages in a normal state. FIG. 8 is a diagram showing the system operating status, device list, and messages in the event of a base loss, which is an abnormal state.

[0011] Hereinafter, examples of the present invention will be described with reference to the drawings. Note that the present invention is not limited to these examples. In addition, in the description of the drawings, the same parts are designated by the same reference numerals.

[0012] 1 is a diagram showing an example of the configuration blocks of a traffic control system centered on a traffic control center as a system for social infrastructure. As shown in FIG. 1, the traffic control system according to the embodiment of the present invention configures a redundant system to increase availability, and has a main (primary system) traffic control center 1 and a sub (secondary system) cloud (secondary control) 2. The traffic control center 1 and the cloud (secondary control) 2 are each connected to a transparently connected control network (shown by the dashed line in FIG. 1) via a relay station 6.

[0013] The traffic control center 1 is composed of, for example, a plurality of signal control devices (signal control device A and signal control device B in FIG. 1) 4, one or more consoles 5, one or more relay stations (relay station 1 in FIG. 1) 6, and a plurality of GWs (GW-a and GW-b in FIG. 1) 7, each connected to a control network 3. Here, the signal control device 4 corresponds to an application device (application device, hereinafter referred to as an "AP device").

[0014] The cloud (second control) 2 is composed of, for example, one or more signal control devices (signal control device C in FIG. 1) 4, one or more consoles 5, one or more relay stations (relay station 2 in FIG. 1) 6, and a firewall (FW) 16 for connecting to the Internet / closed network 13. It is assumed that clients 17, such as other prefecture traffic control centers 14 that perform operations on behalf of the users from outside the region and homes 15, are connected to the Internet / closed network 13.

[0015] A control network (dotted line shown in FIG. 1) in which a plurality of relay stations 6 are transparently connected is connected to an urban sub-center A11 via a relay station A6 and an urban sub-center B12 via a relay station B6.

[0016] The city sub-center A11 includes one or more consoles 5, one or more GWs (GW-c in FIG. 1) 7, and one or more terminal-compatible control devices 9. Similarly, the city sub-center B12 includes one or more consoles 5, one or more GWs (GW-d in FIG. 1) 7, and one or more terminal-compatible control devices 9.

[0017] Here, the traffic control center 1, city subcenter A11, and city subcenter B12 function as bases of the traffic control system. GWs (GW-a to GW-d) 7 provided at these bases are connected via a signal network 8, and intersections 10 and one or more terminal-compatible control devices 9 provided at each of city subcenter A11 and city subcenter B12 are also connected to the signal network 8. In this case, the terminal-compatible control devices 9 are assumed to be devices that control various terminals that handle traffic-related data such as traffic signals.

[0018] Furthermore, the GWs (GW-a to GW-d) 7 provided at these bases constitute a first cluster (shown in the dotted line frame in FIG. 1) as a base determination cluster for checking the health of the bases, and manage the bases.

[0019] In addition, the traffic control center 1 and the cloud (second control) 2 have signal control devices (signal control devices A to C) 4, which form a second cluster (shown in the dashed-dotted line frame in Figure 1) as an application cluster that checks the health of the signal control device 4, which is an AP device (application device), and manages applications.

[0020] Fig. 2 is a diagram showing an example of components included in the signal control device (signal control devices A to C) 4. Fig. 3 is a diagram showing an example of components included in the GW (GW-a to GW-d) 7. Each of the signal control device (signal control devices A to C) 4 and the GW (GW-a to GW-d) 7 includes at least a diagnosis unit 18 and a storage unit 19 that stores system management information.

[0021] FIG. 4 is a table summarizing the installation locations, cluster roles, master / slave roles, and device statuses of the signal control devices (signal control devices A to C) 4 and GWs (GW-a to GW-d) 7 provided in the traffic control system shown in FIG. 1.

[0022] The signal control devices (signal control devices A to C) 4 that make up the second cluster (shown in FIG. 1 with a dashed-dotted line frame) manage applications as an application cluster, forming a master-slave redundant system. Of the two signal control devices 4 provided in the traffic control center 1, signal control device A functions as the primary (main system) of the application cluster, and signal control device B functions as the secondary (slave system) of the application cluster. Furthermore, signal control device C provided in the cloud (second control) 2 functions as the secondary (slave system) of the application cluster.

[0023] Furthermore, the GWs (GW-a to GW-d) 7 that make up the first cluster (shown in the dotted line frame in FIG. 1) monitor the bases as a base determination cluster, forming a master-slave redundant system. Of the two GWs 7 provided in the traffic control center 1, GW-a functions as the primary (main system) of the base determination cluster, and GW-b functions as the secondary (slave system) of the base determination cluster. Furthermore, GW-c provided in the city sub-center A11 and GW-d provided in the city sub-center B12 function as the secondary (slave system) of the base determination cluster.

[0024] Furthermore, the cloud (second control) 2 can also function as a base, in which case a priority of bases subsequent to the traffic control center 1 can be set between the cloud (second control) 2, the city sub-center A11, and the city sub-center B12, and switching between the primary and secondary systems can be performed based on this priority. In general, since the cloud (second control) 2 is expected to have a larger number of devices, the priority of the cloud (second control) 2 will be higher than that of the city sub-center A11 and the city sub-center B12.

[0025] The device status shown in FIG. 4 indicates whether the device status is normal or abnormal, and FIG. 4 shows the normal state in which all devices are normal.

[0026] 5 is a flowchart (shown in the dashed-dotted line frame) of cluster processing (base determination cluster processing) by each of the GWs (GW-a to GW-d) 7 that make up the base determination cluster, which is the first cluster. The entity that executes each processing step of this cluster processing is the diagnosis unit 18 provided in each of the GWs (GW-a to GW-d) 7 shown in FIG. 3, but the description of the entity will be omitted below. Note that the cluster processing by the base determination cluster is followed by cluster processing (shown in the dashed-dotted line frame) by the application cluster, which is the second cluster.

[0027] In step S101, failure information of each GW 7 and each signal control device 4 is acquired via the control network 3 (including transparently connected control networks).

[0028] In step S102, failure information of each GW 7 is acquired via the signaling network 8. Based on the failure information acquired in the previous step, in step S103, it is determined whether or not both of the GWs 7 of both systems (GW-a and GW-b) provided in the traffic control center 1 are in failure.

[0029] If both systems (GW-a and GW-b) are faulty (Y), in step S104, each signal control device (signal control devices A to C) 4 is notified to use the information of GW7 of the city sub-center, for example, the information of GW-c of city sub-center A11 (this corresponds to failure 5 in Figure 6, which will be described later), and the process proceeds to step S105.

[0030] If at least one of the GW7 systems is normal (N) and after step S104 is executed, step S105 determines whether the signal control devices 4 of both systems provided in the traffic control center 1 (signal control device A and signal control device B) are both faulty.

[0031] If both systems (signal control device A and signal control device B) are faulty (Y), in step S106, the remaining signal control device (signal control device C) 4 is notified to exclude the signal control devices (signal control device A and signal control device B) 4 of the traffic control center 1 from the application cluster (this is related to failure 1 and failure 3 in Figure 6, which will be described later).

[0032] If at least one of the signal control devices 4 is normal (N) and after step S106 is executed, the next process is to move to cluster processing (application cluster processing) by the signal control device 4 (application device) that constitutes the second cluster, the application cluster.

[0033] In this application cluster processing, for example, in the previous step S106, the signal control devices (signal control device A and signal control device B) 4 of the traffic control center 1 are excluded from the application cluster, and therefore the signal control device (signal control device C) 4 of the cloud (second control) 2 is changed to the primary system (corresponding to failure 1 and failure 3 in Figure 6, which will be described later).

[0034] Furthermore, when the application cluster changes a signal control device 4 (application device) to the primary system, it compares the numbers of signal control devices 4 provided at bases other than the excluded base, selects the base with the largest number of signal control devices 4 among the bases, and changes one of the signal control devices 4 provided at the selected base to the primary system. If there are multiple bases with the largest number of signal control devices 4 among the bases, it is sufficient to select the base with the largest size (for example, the number of desks (consoles) 5).

[0035] As described above, in the past, signals were output from the GW7 to the signal control device 4 (application device) only by the primary system, but in the present invention, all GW7s output signals regardless of whether they are primary or secondary systems, and the signal control device 4 (application device) selectively receives these signals, thereby enabling seamless handover of processing from the traffic control center 1 to the cloud (second control) 2.

[0036] FIG. 6 is a table showing the status or status recognition of each of the two gateways (GW-a and GW-b) 7 of the traffic control center 1, the gateways (GW-c) of the city subcenter A11 and the gateways (GW-d) of the city subcenter B12, and the final status of the system (including some post-processing) for each failure event.

[0037] (1) Fault 1 <Event> Both systems of the traffic control center 1's signal control devices (signal control device A and signal control device B) 4 and GW (GW-a and GW-b) 7 fail. ・GW-a system of traffic control center 1: Failure ・GW-b system of traffic control center 1: Failure ・GW-c of city subcenter A11: Detects that both systems of the traffic control center 1's signal control devices (signal control device A and signal control device B) 4 and GW (GW-a and GW-b) 7 are out of service. ・GW-d of city subcenter B12: Detects that both systems of the traffic control center 1's signal control devices (signal control device A and signal control device B) 4 and GW (GW-a and GW-b) 7 are out of service. ・Final state: Traffic control center 1 is determined to have lost its base, and signal control device C of cloud 2 is changed to the primary system. <Explanation> GW-c and GW-d, which make up the first cluster (base determination cluster), determine that one of the bases, traffic control center 1, has lost its base due to an equipment abnormality, and since both signal control device A and signal control device B are abnormal, signal control device C in the cloud (second control) is changed to the primary system and processing is taken over.

[0038] (2) Fault 2 <Event> Failure in one of the systems of the signal control devices (signal control device A and signal control device B) 4 of the traffic control center 1 (the table in Figure 6 shows the case of a failure in system A) ・GW-a system of traffic control center 1: Detects the interruption of signal control device system A of the traffic control center 1. ・GW-b system of traffic control center 1: Detects the interruption of signal control device system A of the traffic control center 1. ・GW-c of city subcenter A11: Detects the interruption of signal control device system A of the traffic control center 1. ・GW-d of city subcenter B12: Detects the interruption of signal control device system A of the traffic control center 1. ・Final state: Signal control device system B of the traffic control center 1 is changed to the primary system. <Explanation> Because an abnormality has been detected in the signal control device A system of the traffic control center 1, the signal control device B system of the traffic control center 1 is changed to the primary system and processing is taken over.

[0039] (3) Fault 3 <Event> Failure in both systems of the signal control devices (signal control device A and signal control device B) 4 of the traffic control center 1 ・GW-a system of traffic control center 1: Detects the interruption of signal control devices A and B systems of the traffic control center 1. ・GW-b system of traffic control center 1: Detects the interruption of signal control devices A and B systems of the traffic control center 1. ・GW-c of city subcenter A11: Detects the interruption of signal control devices A and B systems of the traffic control center 1. ・GW-d of city subcenter B12: Detects the interruption of signal control devices A and B systems of the traffic control center 1. ・Final state: Signal control device C of cloud 2 is changed to the primary system. <Explanation> Because an abnormality was detected in both signal control devices (signal control device A and signal control device B) 4 in the traffic control center 1, signal control device C in the cloud (second control) will be changed to the main system (primary) and will take over processing.

[0040] (4) Fault 4 <Event> Failure in one of the systems of GW (GW-a and GW-b) 7 of traffic control center 1 (the table in Figure 6 shows the case of a GW-a system failure) ・GW-a system of traffic control center 1: Failure ・GW-b system of traffic control center 1: Detects the interruption of GW-a of traffic control center 1. ・GW-c of city subcenter A11: Detects the interruption of GW-a of traffic control center 1. ・GW-d of city subcenter B12: Detects the interruption of GW-a of traffic control center 1. ・Final state: The output of GW-b of traffic control center 1 is adopted. <Explanation> Because an abnormality has been detected in GW-a of traffic control center 1, the output of GW-b will be adopted from traffic control center 1.

[0041] (5) Fault 5 <Event> Both systems of GW (GW-a and GW-b) 7 of traffic control center 1 fail. ・GW-a system of traffic control center 1: Failure ・GW-b system of traffic control center 1: Failure ・GW-c of city subcenter A11: Detects a disruption in the GW-a and GW-b systems of traffic control center 1. ・GW-d of city subcenter B12: Detects a disruption in the GW-a and GW-b systems of traffic control center 1. ・Final status: Traffic control center 1 is determined to have lost its base, and GW-c of city subcenter A is changed to the primary system. <Explanation> GW-c and GW-d, which make up the first cluster (base determination cluster), determine that one of the bases, traffic control center 1, has been lost due to an equipment malfunction, and since both GW-a and GW-b of traffic control center 1 are abnormal, GW-c of urban sub-center A11 is changed to the primary system and takes over processing.

[0042] (6) Fault 6 <Event> Failure in relay station 1 (6) of traffic control center 1 ・GW-a system of traffic control center 1: Detects the interruption of signal control device C of cloud 2. ・GW-b system of traffic control center 1: Detects the interruption of signal control device C of cloud 2. ・GW-c of city subcenter A11: Detects the interruption of signal control device A system and B system of traffic control center 1. ・GW-d of city subcenter B12: Detects the interruption of signal control device A system and B system of traffic control center 1. ・Final state: Do nothing. Signal control device C of cloud 2 adopts the output of GW-c of city subcenter A11. <Explanation> If relay station 1 (6) of traffic control center 1 fails, cloud (second control) 2 will not be able to use traffic control center 1's signal control devices (signal control device A and signal control device B) 4 and GW (GW-a and GW-b) 7, and will instead adopt the output of GW-c of urban subcenter A11.

[0043] (7) Fault 7 <Event> Failure in GW-c of city subcenter A11 ・GW-a system of traffic control center 1: Detects the failure of GW-c of city subcenter A11. ・GW-b system of traffic control center 1: Detects the failure of GW-c of city subcenter A11. ・GW-c of city subcenter A11: Failure ・GW-d of city subcenter B12: Detects the failure of GW-c of city subcenter A11. ・Final state: Do nothing. <Explanation> In the event of a failure in GW-c of city subcenter A11, each of the remaining GWs 7 will detect the failure of this GW-c, but ultimately will do nothing.

[0044] (8) Fault 8 <Event> Failure in relay station 2 (6) of cloud (second control) 2 ・GW-a system of traffic control center 1: Detects the outage of signal control device C of cloud 2. ・GW-b system of traffic control center 1: Detects the outage of signal control device C of cloud 2. ・GW-c of city subcenter A11: Detects the outage of signal control device C of cloud 2. ・GW-d of city subcenter B12: Detects the outage of signal control device C of cloud 2. ・Final state: Do nothing. Afterwards, the application cluster restarts signal control device C of cloud 2. <Explanation> In the event of a failure in relay station 2 (6) of cloud (second control) 2, each GW (GW-a to GW-d) 7 will detect the outage of signal control device C of cloud (second control) 2, but will do nothing. However, after the fact, the signal control device C of the cloud 2 is restarted to resolve the interruption detection.

[0045] (9) Fault 9 <Event> Failure in relay station A (6) of city subcenter A11 ・GW-a system of traffic control center 1: Detects nothing. ・GW-b system of traffic control center 1: Detects nothing. ・GW-c of city subcenter A11: Detects the interruption of all signal control devices (signal control devices A and B systems of traffic control center 1 and signal control device C of cloud 2) 4. ・GW-d of city subcenter B12: Detects nothing. ・Final state: Does nothing. <Explanation> In the event of a failure in relay station A (6) of city subcenter A11, GW-c of city subcenter A11 will detect the interruption of all signal control devices (signal control devices A to C) 4, but the remaining GWs will not detect anything and will ultimately do nothing.

[0046] (10) Fault 10 <Event> The transparent portion of the control network 3 is out of service. - GW-a system of traffic control center 1: Detects the outage of signal control device C of cloud 2. - GW-b system of traffic control center 1: Detects the outage of signal control device C of cloud 2. - GW-c of city subcenter A11: Detects the outage of signal control device C of cloud 2. - GW-d of city subcenter B12: Detects the outage of signal control device C of cloud 2. - Final state: Do nothing. Afterwards, the application cluster will restart the signal control device C of cloud 2. <Explanation> When the transparent portion of the control network 3 is out of service, each GW (GW-a to GW-d) 7 detects the outage of signal control device C of cloud (second control) 2, but does nothing. However, afterwards, the signal control device C of cloud 2 is restarted to resolve the outage detection.

[0047] Next, as an example of the system's operating state, a normal state and an abnormal state will be described. Figures 7 and 8 show, in accordance with the display mode of a legend, whether the devices provided in the traffic control center 1, the cloud (second control) 2, the urban subcenter A11, the urban subcenter B12, and the intersection 10 are primary (main system), secondary (subordinate system), or inoperable. Also shown are a table listing the devices similar to Figure 4, and examples of output messages.

[0048] 7 shows the system operating status, device list, and messages during normal operation. During normal operation, signal control device A (4) in traffic control center 1 is the primary, while the remaining signal control device B (4) and signal control device C (4) in cloud (second control) 2 are secondary (backup). GW-a (7) in traffic control center 1 is the primary, while the remaining GW-b (7), GW-c (7) in city subcenter A11, and GW-d (7) in city subcenter B12 are secondary (backup), and all are in normal operation. An example of an output message during normal operation is "Operating normally," displayed on console 5, for example.

[0049] FIG. 8 shows the system operating status, device list, and message when a base is lost as an abnormal state. In the event of an abnormal state where traffic control center 1, one of the bases, is lost, traffic control center 1's signal control device A (4), signal control device B (4), GW-a (7), and GW-b (7) become inoperable. Therefore, for signal control device 4, signal control device C (4) in cloud (second control) 2 becomes the primary (main system). For GW-7, signal control device C (4) in cloud (second control) 2 becomes the primary (main system), while GW-d (7) in urban subcenter B 12 remains the secondary (subsidiary system). An example of an output message during an abnormal state is, "The traffic control center has become inoperable. Signal control is being performed by the second control center.", displayed on console 5, for example.

[0050] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and various modifications are possible within the scope of the gist of the present invention.

[0051] 1...Traffic control center, 2...Cloud (second control), 3...Control network, 4...Signal control device (signal control device A to C), 5...Console, 6...Relay station (relay station 1, 2, A, B), 7...GW (GW-a to d, gateway), 8...Signal network, 9...Terminal corresponding control device, 10...Intersection, 11...Urban subcenter A, 12...Urban subcenter B, 13...Internet / closed network, 14...Traffic control center of other prefecture, 15...Home, 16...FW (firewall), 17...Client, 18...Diagnosis unit, 19...System management information storage unit

Claims

1. A multiple cluster system comprising a first cluster having a plurality of GWs (gateways) managing a plurality of bases, and a second cluster having a plurality of application devices managing a business system, wherein the GWs and the application devices each form a redundant system, one of the application devices becomes a primary system and outputs a control output for a control device equipped in the business system to the GW, one of the GWs becomes a primary system and transmits the control output received from the application device of the primary system to the control device, the first cluster checks the health of each of the bases, and in the event of an abnormality in the base equipped with the application device that has become the primary system, excludes that application device from the second cluster, and the second cluster changes an application device other than the excluded application device to the primary system and continues processing.

2. A multiple cluster system as described in claim 1, characterized in that, when changing the application device to the primary system, the second cluster selects the base other than the excluded base that has the largest number of application devices, and changes one of the application devices equipped at the selected base to the primary system.

3. A multiple cluster system as described in claim 1 or 2, characterized in that the GW (gateway) and the application device are connected to a control network, the GW and the control device are connected to a signal network, and the GW monitors the mutual status of the two networks, the control network and the signal network.

4. A multiple cluster system as claimed in any one of claims 1 to 3, characterized in that, when all of the GWs (gateway) equipped at the base having the main system of the GW are out of service, the first cluster notifies the application device to use information from the GW with which it is able to communicate.

5. A multiple cluster system as described in any one of claims 1 to 4, characterized in that, when the GW (gateway) that is the main system becomes unavailable, the first cluster changes another GW at the base that has the unavailable GW or one of the GWs at a base other than the main system to the main system.

6. A multiple cluster system according to any one of claims 1 to 5, characterized in that the second cluster restarts the application device when all of the GWs (gateways) detect an interruption in communication with the application device.

7. A multiple cluster system according to any one of claims 1 to 6, characterized in that the multiple bases are composed of a control center and a subcenter that control devices and signals related to traffic control.

8. A multiple cluster system according to claim 7, wherein each of said bases is provided with a console, and said console outputs messages regarding at least the operating status of said system.

9. A process handover method using a multiple cluster system comprising a first cluster having a plurality of GWs (gateways) managing a plurality of bases, and a second cluster having a plurality of application devices managing a business system, comprising: making the GWs and the application devices each a redundant system; making one of the application devices a primary system and outputting a control output for a control device equipped in the business system to the GW; making one of the GWs a primary system and transmitting the control output received from the application device of the primary system to the control device; the first cluster confirms the health of each of the bases, and when an abnormality occurs in the base equipped with the application device that has become the primary system, excludes the application device from the second cluster; and the second cluster changes an application device other than the excluded application device to the primary system and continues processing.

10. A method of process handover using a multiple cluster system as described in claim 9, characterized in that, when changing the application device to the primary system, the second cluster selects the base other than the excluded base that has the largest number of application devices, and changes one of the application devices at the selected base to the primary system.

11. A processing handover method using a multiple cluster system as described in claim 9 or 10, characterized in that, when all of the GWs (gateways) provided at the base having the main system of the GW are out of service, the first cluster notifies the application device to use information from the GW that is capable of communication.

12. A processing handover method using a multiple cluster system as described in any one of claims 9 to 11, characterized in that, when the GW (gateway) that is the main system becomes unavailable, the first cluster changes another GW at the base that has the unavailable GW or one of the GWs at a base other than the main system to the main system.

13. A processing takeover method using a multiple cluster system according to any one of claims 9 to 12, characterized in that the second cluster restarts the application device when all of the GWs (gateways) detect a disconnection of the application device.

Citation Information

Patent Citations

  • Duplex system

    JP2001356927A

  • Information processing system, disaster recovery method, and disaster recovery program

    JP2010198404A

  • Control system switching method, program, and control system

    JP2017027219A

  • Electronic equipment, reactivation method, and program

    JP2018092571A