Fault detection method

The error detection method improves functional safety in control systems by using AI and predefined standards to identify abnormal communication patterns in virtualized safety controllers, addressing the challenge of single-channel architectures without additional hardware, thus ensuring reliable operation.

WO2025171960A1PCT designated stage Publication Date: 2025-08-21PHOENIX CONTACT GMBH & CO KG
View PDF 19 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/050516
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-13
Filing Date
2025-01-10
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing error detection methods in control systems, particularly in operational technology, struggle to meet functional safety requirements when implementing virtualized safety controllers using single-channel hardware and firmware architectures, lacking sufficient diagnostic coverage and safe failure fraction without additional hardware expansion.

Method used

An error detection method that utilizes diagnostic signals generated from common control communication instances, leveraging state values of control components to determine behavioral characteristics, and employs artificial intelligence or predefined communication standards to identify abnormal communication patterns, enabling self-diagnosis and error detection without additional hardware.

Benefits of technology

Enhances diagnostic coverage and safe failure fraction in virtualized safety controllers, ensuring functional safety without the need for additional hardware, allowing virtualization on IT servers and meeting SIL and PL requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025050516_21082025_PF_FP_ABST
    Figure EP2025050516_21082025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a fault detection method during operation of a control program, which method involves controlling communication of a number of control components (100-1,100-2,100-n) with a common control communication instance (100), and for the purpose of monitoring controlling generates diagnostic signals using state values of a behaviour criterion common to the number of control components transmitted during the communication, said state values representing current behaviour states of the number of control components. Using these behaviour states, a behaviour characteristic of each control component is determined and these determined behaviour characteristics are then checked overall to determine whether they indicate an abnormal communication characteristic. If they indicate an abnormal communication characteristic, a fault detection signal is generated as the diagnostic signal, wherein for the purpose of checking, at least one communication standard characteristic is defined on the basis of a plurality of different behaviour characteristics and / or artificial intelligence is used and is trained on at least one communication characteristic valid as a pattern on the basis of a plurality of different behaviour characteristics and / or is trained, during ongoing operation, to check the determined behaviour characteristics overall for a deviating and thus abnormal communication characteristic.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Error detection procedures

[0002] The invention relates to an error detection method when operating a control program and to a control system which additionally operates such an error detection method when operating a control program.

[0003] Today, it is often already a common practice in IT domains (i.e., information technology domains) to virtualize the physical hardware of a real or even hypothetical computer architecture, e.g., a control system for running a control program. This type of abstraction of physical hardware can often optimize the agility, flexibility, and scalability of resources, save costs, and increase availability. These advantages are to be increasingly utilized in OT (i.e., operational technology), i.e., in production facilities. One of the major technological challenges here is the implementation of functional safety requirements.

[0004] In this context, various standards such as IEC 61508, IEC 62061 and Directive 2006 / 42 / EC, the so-called Machinery Directive, particularly in the version valid at the time of registration, describe the framework for technical implementation in the design of safety control systems which, starting from a specific target to be achieved, such as SIL (“safety integrity level”, i.e. a level which is used to assess electrical / electronic / programmable electronic (E / E / PE) systems with regard to the reliability of safety functions) or PL (“performance level”, i.e. a level or value which specifies the ability of safety-related parts of a control system to carry out a safety function under foreseeable conditions), are based on a dedicated multi-channel hardware and firmware architecture.

[0005] There are also isolated approaches to solutions that show how the desired reduction in the probability of undetected errors can be achieved by switching from physical multi-channel hardware to logical multi-channel software.

[0006] Prior art documents dealing with this topic include, for example, EP 1043641 A2, US 2021278816 A1, US 20220244995 A1, DE 102020115439 A1, DE 102020115456 A1, US 2022318046 A1, US2022318047A1, US 9304872 B2, US 8880827 B2, US 2023288881 A1 and CN 103676836 A, US 5742624 A, US 8285513 B2, US 2018101383 A1, US 10591886 B2, US 11048249 B2, EP 3674823 B1 , US 11422536 B2, WO 2019028269 A2 and US 2020404014 A1.

[0007] The object of the invention is to further improve the error-detecting measures of a controller during communication between several communication participants, in particular so that they meet current requirements for use in functional safety applications and preferably with regard to diagnostic coverage ("DC" diagnostic coverage) and safe failure fraction SFF, in such a way that the corresponding controller can be virtualized in a functionally safe manner, i.e. can be implemented as a virtual machine in a functionally safe manner, even on the basis of a single-channel hardware and firmware architecture.

[0008] To achieve this object, the invention proposes an error detection method having the features of claim 1 and a control system having the features of claim 8. Appropriate refinements and developments are the subject of the respective further dependent claims.

[0009] Accordingly, the invention proposes an error detection method when operating a control program, which includes controlling communication between a number of control components and a common control communication instance, wherein the control program generates diagnostic signals for monitoring the control using state values ​​of a behavior criterion common to the number of control components, which values ​​are transmitted during communication and each represent current behavior states of the number of control components, wherein

[0010] - within the framework of the error detection method, using these respective current behavioral states, in particular over a predeterminable period of time, a behavioral characteristic of each of the number of control components is determined and these determined behavioral characteristics are then checked as a whole to determine whether they indicate an abnormal communication characteristic, in particular in connection with the common control communication instance (100), and an error detection signal* is generated as a diagnostic signal if the determined behavioral characteristics indicate an abnormal communication characteristic, wherein

[0011] - in order to check whether the determined behavioural characteristics indicate an abnormal communication characteristic, at least one communication standard characteristic is defined on the basis of a large number of different behavioural characteristics and / or an artificial intelligence is used and trained on the basis of a large number of different behavioural characteristics in such a way that at least one communication characteristic that is valid as a model and / or is taught during operation to check the determined behavioural characteristics as a whole for a deviating and therefore abnormal communication characteristic, in particular to check for a communication characteristic that deviates from each communication characteristic that is valid as a model and is therefore abnormal.

[0012] A significant advantage can therefore be seen in the fact that the error-detecting measures, in particular for self-diagnosis, i.e. in connection with the common control communication instance, can also be improved within the operating software of a standard controller as a common control communication instance, without the need for additional hardware expansion for this purpose, even when implementing functional safety. In the areas of functional safety, using the invention, safety controllers can also be operated as a common control communication instance, i.e. in particular, they can be virtualized and thus designed as a virtual machine and operated on any IT server, without the probability of an unnoticed error occurring in such controllers that could endanger the safe operation of a machine or system increasing.In summary, when used in functional safety applications, the requirements for diagnostic coverage (DC) and safe failure fraction (SFF) of a standard or safety controller as a common control communication instance are met without the use of specific and dedicated additional hardware.

[0013] The above-mentioned and further features and advantages of the invention will become apparent from the following description of some preferred embodiments with reference to the accompanying drawings, in which:

[0014] Fig. 1 shows a highly simplified view of an exemplary embodiment of a preferred control system within the scope of the invention,

[0015] Fig. 2 shows in a highly simplified and schematic view an exemplary embodiment of a calibration for a fault detection method according to the invention,

[0016] Fig. 3 shows, in a highly simplified and schematic view, an exemplary embodiment of the use of respective current behavioral states over a period of time for determining and checking a first behavioral characteristic within the framework of an error detection method according to the invention, and

[0017] Fig. 4 shows, in a highly simplified and schematic view, another exemplary embodiment of the use of respective current behavioral states over a period of time to determine and verify a first behavioral characteristic within the framework of an error detection method according to the invention. Fig. 1 shows, in a highly simplified view, an exemplary embodiment of a preferred control system within the framework of the invention.

[0018] The control system shown in Fig. 1 has a number of control components 100-1, 100-2, 100-n and a common control communication instance 100, between which communication is to be controlled. Communication takes place using a communication connection 101, which, as is known to a person skilled in the art, can be designed application-specifically, but is generally based on a transmission path with a standardized communication protocol, in particular on a standardized fieldbus, such as Profibus, or a standardized communication network, such as PROFINET, Ethernet IP, Ethercat, or even on an internal device bus.

[0019] As shown, the number of control components 100-1, 100-2 and 100-3 provided for communication with the common or central control communication instance 100 preferably includes more than just one control component, but rather a plurality of different control components, e.g., according to the exemplary embodiment, a number of at least three control components.

[0020] In practical implementation, a control program is provided to control communication, which can expediently be housed in the control communication instance 100 of the control system. Within the scope of the invention, such a control program can also comprise a plurality of control programs, in particular control subprograms. When operating the control program, the invention further provides for an error detection method, which is described in more detail below.

[0021] Similar to the control program, the error-detecting measures for implementing the error detection method can also be conveniently located in the control communication instance 100, e.g., embedded within the control program. Thus, the control communication instance 100 can be configured as a standard or safety controller, or even simply be included within it. In both cases, the operating software of the standard or safety controller is then conveniently supplemented with the corresponding error-detecting measures. Consequently, controllers for functional safety can also be implemented within the scope of the invention.

[0022] In detail, within the scope of the invention, it is initially provided that the control program generates diagnostic signals for monitoring the control using state values ​​of a behavior criterion common to the number of control components 100-1, 100-2, 100-n, which are transmitted during communication between the number of control components 100-1, 100-2, 100-n and the common control communication instance 100 and which each represent current behavior states of the number of control components.

[0023] According to the invention, however, it is now further provided within the framework of the error detection method that, using these respective current behavioral states, in particular over a predefinable period of time, a behavioral characteristic of each of the number of control components 100-1, 100-2, 100-n is determined and these determined behavioral characteristics are then checked as a whole to determine whether they indicate an abnormal communication characteristic. Subsequently, an error detection signal is generated as a diagnostic signal if the determined behavioral characteristics indicate an undesired communication characteristic. Based on the error detection signal, it is then possible, for example, to activate a specific alarm model, which initially includes signaling a pre-warning and / or triggering an error reaction, for example assuming a safe state or slowing down a process flow.To check whether the behavioral characteristics identified indicate an abnormality.

[0024] In order to indicate a communication characteristic, at least one communication standard characteristic can be defined according to the invention on the basis of a large number of different behavioral characteristics and / or an artificial intelligence can be used which is then trained on the basis of a large number of different behavioral characteristics in such a way for at least one communication characteristic that is valid as a model and / or is also taught during operation to check the determined behavioral characteristics as a whole for a deviating and therefore abnormal communication characteristic, in particular to check for a communication characteristic that deviates from each communication characteristic that is valid as a model and is therefore abnormal.

[0025] To ensure that the respectively transmitted state values ​​of the behavioral criterion common to the number of control components 100-1, 100-2, 100-n actually represent the respective current behavioral states of the number of control components 100-1, 100-2, 100-n, these control components 100-1, 100-2, 100-n are expediently designed as fail-safe components, and the transmission of the respective state values ​​is also expediently carried out using a fail-safe protocol. However, it should be noted that the control components 100-1, 100-2, 100-n and also the protocol do not necessarily have to be fail-safe in order to be able to draw conclusions from an abnormal communication characteristic determined according to the invention and to improve error detection.

[0026] As will be obvious to the person skilled in the art, fail-safe in this context means that suitable measures are taken to ensure that errors occurring in data acquisition, processing, and / or transmission up to a certain safety integrity level or performance level can be detected immediately after their occurrence or within a short time interval thereafter. Suitable measures can include, in a manner known per se, multi-channel and / or redundant architectures, the protocol-specific composition of data to be transmitted during communication, including data intended to secure the transmission, predetermined response and / or tolerance times, the use of time stamps, and / or sequence numbers, to name just a few examples that can be used within the scope of the invention.Thus, in a preferred embodiment of the invention, in particular the control components 100-1, 100-2, 100-n can be equipped with secure time bases, which are expediently monitored by means of watchdog functionalities, indicated in Fig. 1 by doubly housed "timer" symbols. The control communication instance 100, however, then requires, for example, no secure time base and / or can also be designed with only one channel, indicated in Fig. 1 by the only single-housed "timer" symbol, and yet can monitor at least its own non-secure time base for errors in the sense of self-diagnosis.In other words, in this example, based on the state values ​​which, since generated using the secure time bases, actually represent current behavioral states, a behavioral characteristic of each of the number of control components can be determined and these determined behavioral characteristics can then be checked as a whole, so that deviations from a predefined standard characteristic can then be determined in connection with the common control communication instance 100 itself and / or anomalies with regard to trained and / or learned behavioral characteristics during operation can be determined, which indicate an abnormal communication characteristic with regard to the control communication instance 100 itself.

[0027] In order to detect an abnormal communication characteristic, the data records sent by the number, in particular a plurality, of control components 100-1, 100-2, 100-n during communication to the common control communication instance 100 are expediently analyzed over a predeterminable period of time with regard to the state values ​​contained therein or further state values ​​derived therefrom, wherein the contained and / or derived further state values ​​are expediently also compared with one another over the predeterminable period of time.For example, the derived state values ​​may be time values ​​that are not transmitted by the control components 100-1, 100-2, 100-n themselves and then merely compared or checked for plausibility by the control communication instance 100, but are derived from the data (state values) contained in the protocol by the control communication instance 100 itself, e.g., measured using the single-channel time base. If the determined behavioral characteristics of a plurality of these control components 100-1, 100-2, 100-n change, then checking the determined behavioral characteristics will subsequently indicate an abnormal communication characteristic, particularly in connection with the shared control communication instance, and in this case, in particular an abnormal communication characteristic based on insufficient hardware or firmware integrity.

[0028] In order to avoid identifying individual deviations and / or outliers, which may be non-specific but also have an impact on the entire system, as an abnormal communication characteristic of a common network infrastructure component within the scope of a self-diagnosis according to the invention, in preferred embodiments within the scope of the invention the error detection is expediently set, trained and / or taught during operation in such a way that the changing behavior characteristics determined on the basis of the analyzed state values ​​for each of the number of control components only indicate an abnormal communication characteristic when this exceeds a previously defined anomaly threshold and / or the majority of the number of control components 100-1, 100-2, 100-n exceeds a predetermined number.

[0029] According to preferred embodiments, the detection therefore relates primarily to an increased number of CRC errors, in particular within a fail-safe communication, and / or to an increased number of fluctuations / drifts in measured response times of the control components 100-1, 100-2, 100-n.

[0030] For example, in an application-based specific embodiment, the error detection can be set and / or trained in such a way that upon detection of a change in transmission error rates, in particular upon an increase in the transmission error rates, with respect to each of the number of different control components 100-1, 100-2, 100-n, this can also indicate an error in a memory assigned to the common control communication instance 100 or a CPU of the common control communication instance 100.

[0031] Additionally or alternatively, the error detection can also be set, trained and / or learned during operation in such a way that the simultaneous drifting of response times of the control components 100-1, 100-2, 100-n can also indicate an error, in particular the drifting of a timer of this common control communication instance 100, in addition to a deterioration of the common control communication instance 100.

[0032] Preferably, for each control component of the number of different control components 100-1, 100-2, 100-n, a desired behavior characteristic is set with respect to communication with the common control communication instance 100, and / or a threshold value is specified for the change in the respective behavior characteristic that must be passed in order to be included in the review. Upon careful consideration of the description, this setting and / or specification is thus obviously not made at the control components 100-1, 100-2, 100-n themselves, but rather at the common control communication instance 100 with respect to its settings and / or specifications for each of the control components.

[0033] In this way, influences of a common cause in the control components 100-1, 100-2, 100-n can be expediently filtered out from the error detection according to the invention, ie in particular anomaly detection, or the data sets used for this purpose, so that only certain error sources in connection with the common control communication instance 100, such as RAM, CPU, quartz, can be considered as possible error causes within the scope of the invention.

[0034] Based on the above and the following description, it is clear that for the error detection method within the scope of the invention, the control communication instance 100 and / or the control program can also be operated at least partially on a virtual machine. Additionally or alternatively, however, a control program of a safety controller comprising the common control communication instance can also be operated at least partially as the control program. In other words, the control program can therefore at least partially comprise a control program of a safety controller, which in turn comprises the common control communication instance. In this context, the control communication instance can thus form merely part of a safety controller or even be implemented as a safety controller itself.

[0035] Since, in particular in contrast to solutions according to the state of the art, which have so far achieved a target SIL and the diagnostic coverage required for this essentially only by using special additional hardware, such as local plug-in cards, locally or via safety components or timers connected to the network, the procedure according to the invention can be implemented essentially independently of the hardware used in each case and usually also firmware, the applicability and application-based specific design of the error detection method according to the invention is based on a very high degree of flexibility.

[0036] With reference to Fig. 2, which outlines, in a highly simplified and schematic view, an exemplary embodiment of setting a desired behavior characteristic for an error detection method according to the invention using the example of a calibration based on PROFIsafe, it is assumed below that several control components 100-1, 100-2, 100-n are connected to a control communication instance 100 as described above. The control communication instance 100 is preferably embodied at least as part of a safety controller. In a particularly preferred embodiment, the control communication instance 100 is virtual and, in particular, embodied as a virtual safety controller and thus designed as a virtual machine and is operated on essentially any IT server.The communication protocol used for the communication connection 101 between the control components 100-1, 100-2, 100-n and the common control communication instance 100 for data transmission is preferably one for the transmission of data in safety-critical automation applications, such as PROFIsafe, which is known to be a standard for a communication protocol for the transmission of safety-relevant data in automation applications with functional safety and defines how safety-related devices (e.g. emergency stop buttons, light curtains, overfill protection, ...) communicate safely with safety controllers via Profinet, Profibus or a backplane so that they can be used in safety-related automation tasks up to SIL3 (Safety Integrity Level).

[0037] As mentioned above, in a preferred embodiment, a desired behavior characteristic is first set on the side of the common control communication instance 100 for at least the various control components 100-1, 100-2, 100-n with regard to communicating with the common control communication instance 100.

[0038] When PROFIsafe is used as a basis, this can therefore be equated with a corresponding parameterization of at least the connected control components 100-1, 100-2, 100-n, whereby in this case, after such a calibration, particularly during a start-up phase, it can generally be assumed that fail-safe cyclic communication usually starts and data is transmitted bidirectionally in a fail-safe manner.

[0039] As outlined in Fig. 2, when setting a desired behavior characteristic, a respective data record for transmitting a specific state value of each control component 100-1, 100-2, 100-n preferably receives a defined time specification WD, which specifies when a respective control component 100-1, 100-2, 100-n must have received a corresponding new data record, ie using PROFIsafe as an example, in particular for each F-parameter data record a parameterized F_WD time, after which each PROFIsafe slave, ie according to the figures each control component, must have received a new telegram at the latest, or after which time the PROFIsafe master, ie according to the figures the control communication instance, must have received the corresponding response telegram after sending a PROFIsafe telegram from the respective PROFIsafe slave.

[0040] Following a corresponding specification in the control communication instance 100, the generation of new respective data records is then stopped or interrupted, for example, starting at a defined point in time, i.e., according to the underlying example, the generation of new safe output telegrams is stopped in the virtual safety controller. At this point in time, a measurement of the time until feedback from the respective control component regarding the arrival of the last new data record is preferably started for each connected control component 100-1, 100-2, and 100-n, i.e., in particular, a maximum measurement of the time until the parameterized watchdog "F_WD" expires and thus the fail-safe communication is terminated.

[0041] In this measured feedback or reaction time, designated T react in Fig. 2, in addition to the time of arrival, usually both an (error) reaction time of the respective control component and the time for the retransmission are included.

[0042] As mentioned, such a measurement preferably takes place per control component, ie for each control component individually, whereby the different control components can of course be set or parameterized with different target behavior characteristics, ie in the present case with different time specifications WD.

[0043] For each control component 100-1, 100-2, and 100-n, at least one initial calibration process of the timer of the control communication instance 100 is possible by comparing the measured with the set target behavior characteristic, thus enabling the determination of at least one respective difference value. Using such a difference value or several such difference values, previously defined threshold values, e.g., a previously defined anomaly threshold, can then be specified or preset, which must first be passed during a subsequent change in the respective behavior characteristic in order to be included in a corresponding check.

[0044] In a practical implementation, the accuracy of a calibration or determination of respective difference values ​​can be increased, for example, by multiple measurements, minimum value formation and / or by back-calculating time jumps caused by cyclic calling.

[0045] Figures 3 and 4 now outline, in a highly simplified and schematic view, exemplary embodiments of the use of respective current behavioral states over a period of time for determining and checking behavioral characteristics within the framework of an error detection method according to the invention.

[0046] Similar to the explanations for Fig.2, it is also assumed below that several control components 100-1, 100-2, 100-n are connected to a control communication instance 100 as described above and that the control communication instance 100 is preferably designed as a virtual safety controller.

[0047] It is now also assumed that at least one communication norm characteristic has been defined on the basis of a large number of different behavioral characteristics and / or that an artificial intelligence is used and has been trained and / or taught during operation on the basis of a large number of different behavioral characteristics in such a way that the determined behavioral characteristics as a whole can be checked for an undesirable communication characteristic.

[0048] As a basis for this, in a preferred embodiment, a calibration described as an example in Fig. 2 can be used.

[0049] As a result, during the subsequent communication between the number of control components 100-1, 100-2, 100-n and the common control communication instance 100 in this control communication instance 100, the response times can be measured and recorded for each of the control components 100-1, 100-2, 100-n, in particular cyclically, based on the communication protocol used for data transmission. Depending on the communication protocol used, mechanisms such as so-called "switching bits" or "toggle bits" can usually be used to uniquely assign a message received by a control component 100-1, 100-2, 100-n to a message sent to it, and thus the time interval can be measured using the timer of the control communication instance 100. This also applies to PROFIsafe, for example.so-called toggel bits are included, which, when sent by the control communication instance 100, must be answered by a respective one of the control components 100-1, 100-2, 100-n.

[0050] As described above, particularly with reference to Fig. 2, thresholds can consequently also be set and / or the training and / or the learning during operation can be carried out in such a way that isolated outliers, for example also with regard to response times, are not included in the check, in particular if it can be assumed that these are systemically caused by unsynchronized transfers of the telegrams in various other infrastructure components of a black channel and / or such outliers are generally constant over time and distributed across all control components 100-1, 100-2, 100-n, as outlined in Fig. 3. In this case, therefore, these are generally not anomalies within the scope of the invention and would therefore also not indicate an undesirable communication characteristic, in particular in connection with the common communication instance 100, iein particular, it does not lead to an increase / improvement in self-diagnosis according to the invention.

[0051] However, if, as outlined in Fig. 4, the measured reaction times of all control components 100-1, 100-2, 100-n, or at least of a majority of the plurality of control components, in particular of a majority exceeding a predetermined number, drift in the same direction to the same or at least a similar extent, then it is not to be assumed that there is a distributed error in the control components 100-1, 100-2, 100-n, but in the measuring device itself, i.e. in the control communication instance 100. From the above description of the invention, it is clear that the anomaly detection system preferably used can be essentially as intelligent as desired and can also include essentially as many data, including historical data.

[0052] For example, due to appropriate data training and / or teaching during operation, in the embodiment according to Fig. 4, everything can be recognized as correct up to cycle 4, whereas in cycle 5 the determined behavioral characteristics, ie according to Fig. 4 the determined reaction times of all control components 100-1, 100-2, 100-n, have all drifted in an identical direction for the first time, which can therefore already indicate an undesired communication characteristic.

[0053] In other words, according to the present embodiment, in cycle 4 according to Fig. 4 the values ​​can still be recognized as correct and thus still be within the permissible range despite a possible drift in the same direction, i.e. in particular that a previously defined threshold value for the change in the respective behavioral characteristic has not yet been passed in order to be included in the check. In cycle 5 according to Fig. 4, for example, all of the determined behavioral characteristics have then made a further jump simultaneously, which can subsequently lead, for example, to the generation of an error detection signal relating to a possible advance warning and possibly even without an error reaction. Cycle 5 according to Fig.Figure 4 thus illustrates, by way of example, a cycle in which a parameterized warning level may have been reached, but no error response has yet been initiated, for example, to cause a safe state or a slowdown in a process sequence. In cycle x, however, a threshold value is exceeded, for example, resulting in an error detection signal being generated that should result in an error response, such as, in particular, the adoption of a safe state or the slowdown in a process sequence.

[0054] As described above, different threshold values, in particular for generating different error detection signals, e.g. also for advance warning, marked with “W” in Fig. 4, and for triggering an error reaction, marked with “F” in Fig. 4, can be set or parameterized, trained and / or learned during operation.

Claims

Patent claims 1. Error detection method when operating a control program, which includes controlling a communication of a number of control components (100-1, 100-2, 100-n) with a common control communication instance (100), wherein the control program generates diagnostic signals for monitoring the control using state values ​​transmitted during the communication of a behavior criterion common to the number of control components, which respectively represent current behavior states of the number of control components, wherein - within the framework of the error detection method, using these respective current behavioral states, in particular over a predeterminable period of time, a behavioral characteristic of each of the number of control components is determined and these determined behavioral characteristics are then checked as a whole to determine whether they indicate an abnormal communication characteristic, in particular in connection with the common communication instance (100) with the control system, and an error detection signal is generated as a diagnostic signal if the determined Behavioral characteristics indicate an undesirable communication characteristici where - to check whether the determined behavioural characteristics indicate an abnormal communication characteristic, at least one communication norm characteristic is defined on the basis of a large number of different behavioural characteristics and / or an artificial intelligence is used and trained on the basis of a large number of different behavioural characteristics in such a way for at least one communication characteristic that is valid as a model and / or is taught during operation to check the determined behavioural characteristics as a whole for a deviating and therefore abnormal communication characteristic, in particular for a communication characteristic that is different from each valid as a model Communication characteristics deviating and therefore abnormal To check communication characteristics.

2. Error detection method according to claim 1, wherein the number of control components includes a plurality of different control components and wherein data records which are sent by this plurality of control components (100-1, 100-2, 100-n) during communication to the common control communication instance (100) are analyzed over a predeterminable period of time with regard to the state values ​​contained therein or further state values ​​derived therefrom, and in the event of changing, determined behavioral characteristics of a plurality of the plurality of control components, the review of the determined behavioral characteristics as a result indicates an undesired communication characteristic in connection with the common control communication instance, in particular based on insufficient hardware or firmware integrity.

3. Error detection method according to the preceding claim, wherein the changing behavior characteristics determined on the basis of the analyzed state values ​​of each of the plurality of control components only indicate an abnormal communication characteristic when said communication characteristic passes a previously defined anomaly threshold and / or the plurality of the number of control components exceeds a predetermined number.

4. Error detection method according to one of the preceding claims, wherein the control program is operated at least partially on a virtual machine, and / or wherein a control program of a safety controller comprising the common control communication instance is operated at least partially as the control program.

5. Error detection method according to one of the preceding claims, wherein upon detection of a change in transmission error rates, in particular upon increase in the transmission error rates, with respect to each of the number of different control components, an error is detected in a memory or a CPU assigned to the common control communication instance.

6. Error detection method according to one of the preceding claims, wherein upon detection of a simultaneous change in response times with respect to each of the number of different control components, an error is detected in a timer associated with the common control communication instance (100).

7. Error detection method according to one of the preceding claims, wherein for each control component of the number of different control components with respect to communicating with the common control communication instance, a desired behavior characteristic is set and / or a threshold value for the change in the respective behavior characteristic is specified and must be passed in order to be included in the check.

8. Control system which, when operating a control program, additionally operates an error detection method according to one of the preceding claims.

9. Control system according to the preceding claim, which has a plurality of different control components (100-1, 100-2, 100-n) and at least one common control communication instance, and wherein at least the one common control communication instance is designed as part of a virtual machine and / or wherein the Control components (100-1, 100-2, 100-n) are designed as fail-safe components.

Citation Information

Patent Citations

  • Online safe operation guiding method

    CN103676836A

  • INDUSTRIAL CONTROL SYSTEM ARCHITECTURE FOR REAL-TIME SIMULATION AND PROCESS CONTROL

    DE102020115439A1

  • DENTIFIED VIRTUALIZATION MANAGEMENT NODE IN PROCESS CONTROL SYSTEMS

    DE102020115456A1

  • Failsafe automationsystem with standard-CPU and method for a failsafe automationsystem

    EP1043641A2

  • Method and apparatus for detecting the anomalies of an infrastructure

    EP3674823B1