Reliability indicators for an operator station server
By calculating a health index that considers both severity and duration of alarms, the operator station server addresses inefficiencies in redundancy switching and operational interruptions, enhancing reliability and enabling proactive maintenance in technical plant control systems.
Patent Information
- Application Number
- PCT/EP2025/058328
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-26
- Filing Date
- 2025-03-26
- Publication Date
- 2025-10-30
AI Technical Summary
Existing operator station servers in control systems for technical plants suffer from inefficient health index calculations that lead to frequent redundancy switching and operational interruptions due to sporadic errors, which are not adequately addressed by current diagnostic methods, leading to potential failures in operation and monitoring.
The operator station server calculates a health index based on both the severity and duration of alarms generated by its software components, allowing for a more meaningful assessment of server health and enabling informed decisions on active and passive roles in redundant configurations, thereby reducing unnecessary switching and improving diagnostics.
This approach enhances operational efficiency and flexibility by minimizing redundancy switching, ensuring reliable operation, and facilitating proactive maintenance through improved health index calculations that consider both severity and duration of alarms.
Smart Images

Figure EP2025058328_30102025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] Reliability indicators for Operator Station Server
[0003] The invention relates to an operator station server for a control system of a technical plant, in particular a manufacturing or process plant, which is configured for operating and monitoring the technical plant and on which at least one software component is implemented, wherein the at least one software component is configured to generate an alarm of a specific severity level for the duration of an error occurring in the software component. The invention also relates to a control system for a technical plant, in particular a manufacturing or process plant. Furthermore, the invention relates to a method for operating a technical plant, in particular a manufacturing or process plant.
[0004] For the operation and monitoring of process engineering plants, symbolic plant diagrams are created that abstractly represent the process engineering relationships – especially between individual process objects. Plant diagrams consist of static symbols (e.g., pipes, rectangles, etc.), dynamic symbols (e.g., pipes changing color depending on process values, rectangles showing fill levels, etc.), block symbols (for the dynamic visualization of process engineering objects), complex controls (e.g., trend indicators, message sequence indicators, etc.), and containers to visualize content from independent and autonomous sources (e.g., webcams, plant images of modular plant components, or applications such as a controller optimizer or KPI calculations).
[0005] Plant images are visualized in Operator Station Clients, and the process values and process alarms necessary for dynamic operation are provided by Operator Station Servers via their process images. For improved availability and scalability, Operator Station Servers are often configured not only redundantly but also in a distributed, networked manner. With redundant Operator Station Servers, operation and monitoring take place on the active Operator Station Server, while the passive Operator Station Server is in "hot standby" to take over in the event of a functional limitation (loss of connection to the automation system, crash of a software component, etc.) of the active Operator Station Server by becoming active itself. With redundant Operator Station Servers, the Operator Station Client is always connected to the active Operator Station Server.If a redundancy switchover is initiated due to a detected error (the active Operator Station Server becomes passive and vice versa), the Operator Station Client connects to the now active Operator Station Server. No operation or monitoring is possible during the switchover period, which is why this period must be kept as short as possible and unnecessary switchovers by the Operator Station Client should be avoided.
[0006] An Operator Station Server comprises numerous modular software components, such as the process image, the visualization service, the archiving service, various drivers for communication between the Operator Station Servers and the automation level, the alarm service, and others. These functionalities are designed for operation and monitoring via an Operator Station Client.
[0007] A health index can be calculated for an operator station server using state-of-the-art technology. This calculation can be based on alarms reported by the individual software components of the operator station server, along with their respective severity levels. The health index can be used for several applications:
[0008] With redundant Operator Station Servers, the one with the best health index can be active. If both health indices are the same (either because there are no active alarms on either Operator Station Server or because both have alarms of the same severity), it is ultimately a matter of chance which Operator Station Server becomes active and which becomes passive.
[0009] Operator Station Clients used the health index of the different Operator Station Servers in distributed systems to connect to the Operator Station Server with the best health index when alternatives were available.
[0010] Diagnosis of operator station servers with regard to necessary maintenance and operational readiness
[0011] Since the health index is a real-time value, not all use cases can be adequately addressed. For example, if an operator station server has a sporadically recurring problem or is generally more frequently affected by outages, the current state of the art in the health index leads to more frequent redundancy switching between operator station server pairs or to operator station clients re-registering on other operator station servers, which in both cases results in interruptions in operation and monitoring.
[0012] Furthermore, if diagnoses or maintenance are carried out solely on the basis of a state-of-the-art health index, the causes of sporadic errors may neither be identified nor rectified, potentially leading to serious failures in operation and monitoring.
[0013] From EP 3 276 437 A1, an automation system is known in which a health index of an operator station server is determined and evaluated for communication within the automation system.
[0014] The invention is based on the objective of providing a control system for a technical plant which increases the efficiency and flexibility of the operation and monitoring of the technical plant.
[0015] This problem is solved by an operator station server with the features of claim 1. Furthermore, the problem is solved by a control system according to claim 6 and by a method for operating a technical plant according to claim 9. Advantageous embodiments are described in the dependent claims.
[0016] The operator station server according to the invention for a control system of a technical plant, in particular a manufacturing or process plant, which is designed for operating and monitoring the technical plant, on which at least one software component is implemented, wherein the at least one software component is designed to generate an alarm with a certain severity level for the duration of an error occurring in the software component, wherein the severity level of the alarm reflects a severity level of the error, is characterized in that it is designed to calculate a health index with respect to itself, which depends on the duration and severity of the generated alarm, and to transmit this health index to components of the control system connected to the operator station server.
[0017] The technical installation can be a plant from the process industry, such as a chemical, pharmaceutical, petrochemical, or food and beverage plant. This also includes any plant from the manufacturing industry, such as factories where cars or goods of all kinds are produced. Technical installations suitable for carrying out the process according to the invention can also originate from the energy generation sector. Wind turbines, solar power plants, or power plants for energy generation are likewise included in the term "technical installation."
[0018] In this context, a control system is understood to be a computer-aided, technical system that includes functionalities for displaying, operating, and controlling the technical plant. The control system can also include sensors for acquiring measured values as well as various actuators. Furthermore, the control system can include so-called process- or production-related components that serve to control the actuators or sensors. In addition, the control system can include, among other things, means for visualizing the process plant and for engineering purposes. Optionally, the control system can also include additional computing units for more complex control systems and systems for data storage and processing.
[0019] In this context, an "Operator Station Server" is understood to be a server that centrally collects data from an operator control and monitoring system, as well as typically alarm and measurement archives from a control system of a technical plant, and makes this data available to users. The Operator Station Server usually establishes a communication link to the automation systems of the technical plant and forwards data from the plant to so-called Operator Station Clients, which are used to operate and monitor the operation of the individual functional elements of the technical plant. The Operator Station Server can have client functions to access the data (archives, messages, tags, variables) of other Operator Station Servers. This allows images of the operation of the technical plant on the Operator Station Server to be combined with variables from other Operator Station Servers (server-to-server communication).The Operator Station Server can be, but is not limited to, a SIMATIC PCS 7 Industrial Workstation Server from SIEMENS.
[0020] It is assumed that the Operator Station Server includes at least one software component capable of generating an alarm of a specific severity level for the duration of an error occurring within that software component. Such a software component could be, for example, a process imaging service, a visualization service, an archiving service, or a communication service implemented on the Operator Station Server, providing various functionalities for operating and monitoring the technical system. For the purposes of this document, an error is generally defined as a deviation of the actual state of the software component from its intended state.
[0021] The alarm generated by the software component is issued for a specific period of time and has a defined severity level. This provides information about the presence of the error, its duration, and its severity.
[0022] In a particularly inventive further development of the prior art, the operator station server is configured to calculate a health index for itself, which depends on the duration and severity of the generated alarm. In other words, in addition to the severity of the generated alarm (which reflects the severity of the fault), the duration for which the alarm (and thus the underlying fault) occurs is taken into account. This results in a more meaningful health index, which is then made available for further use than with previously known operator station servers.
[0023] Preferably, at least one further software component is implemented on the operator station server, wherein the at least one further software component is configured to generate an alarm of a specific severity level for the duration of a fault occurring in the at least one further software component, wherein the operator station server is configured to calculate a health index with respect to itself, which depends on the duration and severity of the alarms generated by the software component and the at least one further software component, and wherein the operator station server is configured to transmit this health index to components of the control system that are connected to the operator station server. The health index therefore takes into account not just a single software component, but rather a plurality of software components.The Operator Station Server is specifically designed to sum the individual severity levels of the numerous alarms in order to meaningfully determine the health index.
[0024] In a preferred embodiment of the invention, the operator station server is configured to consider the alarm(s) generated by the software component for calculating the health index only for a specific period of time. This period represents a kind of observation period during which the operator station server must "prove itself" before the previously reported alarms are no longer considered. The specified period is one hour, 12 hours, or 24 hours.
[0025] The previously formulated task is also solved by a control system for a technical plant, in particular a manufacturing or process plant, which has a first operator station server that is designed as explained above.
[0026] The control system can have a second operator station server, which is also configured as previously explained.
[0027] Preferably, the two operator station servers are configured redundantly for operating and monitoring the technical system. The two operator station servers are configured to determine, through repeated comparisons of their respective health indices, which operator station server should be active and which should be passive. During the negotiation of the active and passive roles, the two health indices are compared. With the control system according to the invention, the decision can now also take into account which operator station server exhibits the highest level of reliability within a given timeframe, in order to prevent unnecessary redundancy switching. If the operator station servers temporarily lose their connection to each other, both assume an active role until they can re-establish a connection.Here too, the health index can be advantageously used to assign the active role to the Operator Station Server that has demonstrated the best reliability in retrospect, in order to prevent future redundancy switching.
[0028] The previously formulated task is also solved by a method for operating a technical plant, in particular a manufacturing or process plant, with a control system designed as previously explained.
[0029] The previously formulated task is also solved by a method for operating a technical plant, in particular a manufacturing or process plant, with a control system configured as previously described. In this system, an operator station client wishing to log on to one of the two operator station servers queries the respective health index from both servers and, based on a comparison of the two health indices, selects one of the two operator station servers for login. If multiple operator station servers are available, the operator station client can also retrospectively evaluate which of the available operator station servers exhibits the highest level of reliability within a given time period. This prevents the operator station client from logging on to operator station servers that experience occasional errors. This, in turn, avoids unnecessary operator station client switching.If an Operator Station Client encounters an active / active Operator Station Server, it can use the invention to determine which of the two Operator Station Servers should preferably be chosen, namely the one that remains active after a merger of the two Operator Station Servers because it has the best health index.
[0030] The respective health index can be used by a computer-implemented maintenance service of the control system to identify maintenance needs for the operator station servers and trigger corresponding maintenance. The health index provides a simple yet efficient KPI (Key Performance Indicator) for identifying less reliable operator station servers. This enables improved diagnostics and, above all, preventative maintenance.
[0031] The properties, features, and advantages of this invention described above, as well as the manner in which they are achieved, will become clearer and more readily understandable in connection with the following description of exemplary embodiments, which are explained in more detail in conjunction with the drawings. The drawings show:
[0032] FIG 1 shows a time course of alarms with varying degrees of severity;
[0033] FIG 2 shows a time course of a calculated alarm based on the alarms from FIG 1
[0034] Health index;
[0035] FIG 3 shows a further time course of alarms with varying degrees of severity;
[0036] FIG 4 shows a time course of a health index calculated using the alarms from FIG 3; and
[0037] FIG 5 shows a guidance system in a schematic representation.
[0038] Figure 1 shows a time series of alarms generated by different software programs.
[0039] Components of an Operator Station Server (see FIG. 5) were generated. The horizontal axis represents time in arbitrary units (e.g., 1 hour), and the vertical axis represents the severity level (SEV) of the respective alarms. For the first time period from t=1 to t=3, a first software component detected an error, which was assigned a severity level of Sev=3. Accordingly, between t=1 and t=3, there is one alarm with a severity level of Sev=3. For the second time period from t=5 to t=6, there is one alarm with a severity level of Sev=2 and two alarms with a severity level of Sev=1.
[0040] According to the current state of the art, the Operator Station Server, on which the alarms are reported, is error-free between t=3 and t=5 and after t=6 and is therefore suitable for Operator Station Client logins or configured to switch to an active role in a redundant Operator Station Server pair. Although the Operator Station Server is under considerable load, its alarms have no lasting effect. If a maintenance check were due, the diagnosis would show that the Operator Station Server is completely fine and no repairs are necessary. This is especially true for alarms relating to recurring problems (e.g., loose connections in the network interface, bit flips in processors, thermal failures of components).), can be particularly problematic in this regard, as this can also lead to recurring redundancy switching of the operator station servers or to switching of the operator station clients to other operator station servers, or to failures of operation and monitoring.
[0041] Figure 2 shows the health index (Gl), which the Operator Station Server calculates from the alarms provided to it (see Figure 1). A health index of Gl=0 represents optimal health. The higher the health index, the worse the health of the Operator Station Server. The Operator Station Server queries the software components for potential alarms at discrete time intervals (t=1, t=2, t=3, etc.). The observation period is set to ten time units.
[0042] At time t=1, the first alarm begins with a severity level of Sev=3 and is not yet included in the calculation of the health index, which is why it has a value of GI=0. At time t=2, the alarm is included in the calculation of the health index, which is why its value changes to Gl=3. The alarm is still active until time t=3, which is why the health index changes to Gl=6 at this point. Therefore, the calculation of the health index Gl takes into account not only the severity but also the duration (here for two time units) during which an alarm is active. The health index remains constant at a value of Gl=6 between t=3 and t=6 because no further alarm is active and the time interval of 10 time units since the occurrence of the first alarm has not yet elapsed.At time t=6, three alarms are present for one time unit, summing to a severity level of Sev=4. Therefore, the health index changes from Gl=6 to Gl=10 at time t=6. The health index remains constant at Gl=10 until time t=12, as no further alarms occur. At t=12, 10 time units have elapsed since the first increase in the health index at t=2. This change is then reversed, and the health index is reduced by three units from Gl=10 to Gl=7. At time t=13, the second increase caused by the first alarm at t=3 is also reversed, and the health index changes from Gl=7 to Gl=4. At t=16, the increase caused by the alarms at t=6 is also reversed, and the health index changes from Gl=4 to GI=0. The Operator Station Server shows no negative health index impairments from this point onwards (t=16).
[0043] Figure 3 shows the severity levels of incoming alarms for two Operator Station Servers, OS 1.1 and OS 1.2, in a chronological sequence. The first Operator Station Server, 1.1, and its alarms correspond to the Operator Station Servers in Figures 1 and 2. The second Operator Station Server, OS 1.2, has an alarm with a severity level of 3 between t=1 and t=2. The resulting health indices (G) are shown in Figure 4. The health index curve of the first Operator Station Server, OS 1.1, marked with circles, corresponds to the curve in Figure 2. The health index of the second Operator Station Server, OS 1.2, increases from GI=0 to GI=3 at t=2, due to the alarm that occurred from t=1 onwards. The health index of the second Operator Station Server, OS 1.2, remains at this value until the expiration of ten time units, i.e., until time t=12. From this point on, the health index of the second Operator Station Server OS is 1.2 again GI=0.
[0044] This embodiment demonstrates that, except for the period between t=2 and t=3, the second Operator Station Server OS 1.2 is in a better state of health than the first Operator Station Server OS 1.1 at all times. Therefore, the second Operator Station Server OS 1.2 would be preferable for logins from Operator Station Clients or when exercising a master role (active role) in a redundant operation of the two Operator Station Servers OS 1.1 and OS 1.2. Figure 5 schematically depicts a control system 1 for the operation and monitoring of a technical plant configured as a process plant. The control system 1 comprises a first Operator Station Server OS 1.1, a second Operator Station Server OS 1.2, and an Operator Station Client 2.2 and the Operator Station Client 2 are connected to each other via a terminal bus 3 and optionally to other components of the control system 1 not shown, such as an archive server or an engineering station server.
[0045] A user or operator can access the Operator Station Server OS 1.1 and OS 1.2 via the Terminal Bus 3 using the Operator Station Client 2 for operation and monitoring purposes. Similarly, a project engineer can access the Engineering Station Server (not shown in FIG 5) via an Engineering Station Client to create an automation design for the process plant. The Terminal Bus 3 can be configured as, for example, Industrial Ethernet, but is not limited to this.
[0046] The first Operator Station Server OS 1.1 and the second Operator Station Server OS 1.2 are essentially identical in design; therefore, the following description focuses solely on the first Operator Station Server OS 1.1. The first Operator Station Server OS 1.1 has a device interface 4, which is connected to a plant bus 5. Through this device interface 4, the first Operator Station Server OS 1.1 is connected to an automation device 6 and to other components of the process plant, such as peripheral devices 7, 8, and 9, and can communicate with them. The plant bus 5 can be configured as, for example, Industrial Ethernet, but this is not the only possible configuration.
[0047] The first Operator Station Server OS 1.1 implements (among other things) a visualization service 10, a process image 11, and a configuration memory 12. The visualization service 10 integrated into the first Operator Station Server OS 1.1 initiates the transmission of visualization information to the Operator Station Client 2. The Operator Station Client 2 is configured to display a visualization, i.e., a graphical representation 13, in particular of plant images, measured value trends, operating elements, and similar elements, for operating and monitoring the process plant. The process image 11 of the first Operator Station Server OS 1.1 contains a snapshot of the (signal) states of devices and / or applications connected to the first Operator Station Server OS 1.1. In this embodiment, these are transmitted from the automation device e to the first Operator Station Server OS 1.1.
[0048] Once the automation system for the process plant is complete, it is compiled by an Engineering Station Server service into a data format understandable to the automation device 6 and the first Operator Station Server OS 1.1, and then transferred to both devices. The portion of the automation data intended for operating and monitoring the process plant is stored in configuration memory 12 of the first Operator Station Server OS 1.1.
[0049] A health index service 14 of the first Operator Station Server OS 1.1 determines the health index of the first Operator Station Server OS 1.1 according to the procedure explained with reference to Figures 1-4. The basis for this calculation is the alarms (system messages) of the individual software components of the first Operator Station Server OS 1.1 with their respective severity levels and durations. The health index calculated for the Operator Station Server is stored in the process image 11. A diagnostic service 15 of the visualization service 10 accesses the health index from the process image 11 and makes it available to a corresponding client diagnostic service 16 of the Operator Station Client 2. Furthermore, the health index is made available to a redundancy service 17, which uses it to determine the active or passive role of the redundantly configured Operator Station Servers OS 1.1 and OS 1.2.
[0050] The health index can also be made available to other components of the control system 1, such as a maintenance service.
[0051] Although the invention has been illustrated and described in detail by the preferred embodiment, the invention is not limited by the disclosed examples and other variations can be derived by a person skilled in the art without departing from the scope of protection of the invention. List of reference numerals
[0052] 1 Guidance system
[0053] 2 Operator Station Client
[0054] 3 Terminal bus
[0055] 4 Device interface
[0056] 5 plant bus
[0057] 6 Automation device
[0058] 7 Peripheral device
[0059] 8 Peripheral device
[0060] 9 Peripheral device
[0061] 10 Visualization service
[0062] 11 Process diagram
[0063] 12 configuration memories
[0064] 13 Visualization
[0065] 14 Health Index Service
[0066] 15 Diagnostic Service
[0067] 16 Client Diagnostic Service
[0068] 17 Redundancy service
[0069] OS 1.1 First Operator Station Server
[0070] OS 1.2 Second Operator Station Server
Claims
Patent claims 1. Operator Station Server (OS 1.1 , OS 1.2) for a control system (1) of a technical plant, in particular a manufacturing or process plant, which is configured for operating and monitoring the technical plant, on which at least one software component is implemented, wherein the at least one software component is configured to generate an alarm of a certain severity for the duration of a fault occurring in the software component, wherein the severity of the alarm reflects the severity of the fault, characterized in that the Operator Station Server (OS 1.1 , OS 1.2) is configured to calculate a health index with respect to itself, which depends on the duration and severity of the generated alarm, and to transmit this health index to components of the control system (1) connected to the Operator Station Server (OS 1.1 , OS 1.2).
2. Operator Station Server (OS 1.1, OS 1.2) according to claim 1, on which at least one further software component is implemented, wherein the at least one further software component is configured to generate an alarm of a certain severity for a duration of an error occurring in the at least one further software component, wherein the Operator Station Server (OS 1.1, OS 1.2) is configured to calculate a health index with respect to itself, which depends on the duration and severity of the alarms generated by the software component and the at least one further software component, and wherein the Operator Station Server (OS 1.1, OS 1.2) is configured to transmit this health index to components of the control system (1) connected to the Operator Station Server (OS 1.1, OS 1.2).
3. Operator Station Server (OS 1.1 , OS 1.2) according to claim 2, which is configured to sum the respective severity levels of the alarms within the framework of calculating the health index.
4. Operator Station Server(OS 1.1 , OS 1 .2) according to one of the preceding claims, which is configured to consider the alarm or alarms generated by the software component for the calculation of the health index only for a specific period of time.
5. Operator Station Server (OS 1.1 , OS 1 .2) according to claim 4, wherein the specified time period is one hour, 12 hours or 24 hours.
6. Control system (1) for a technical plant, in particular a manufacturing or process plant, which has a first operator station server (OS 1.1, OS 1.2) configured according to one of claims 1 to 5.
7. Control system (1) according to claim 6, which comprises a second operator station server (OS 1.1, OS 1.2) configured according to any one of claims 1 to 5.
8. Control system (1) according to claim 7, wherein the two operator station servers (OS 1.1 , OS 1.2) are configured redundantly for the operation and monitoring of the technical system, wherein the two operator station servers (OS 1.1 , OS 1.2) are configured to determine, by repeatedly comparing their respective health index, which operator station server (OS 1.1 , OS 1 .2) should be active and which operator station server (OS 1.1 , OS 1.2) should be passive.
9. Method for operating a technical plant, in particular a manufacturing or process plant, with a control system (1) according to one of claims 6 to 8.
10. Method for operating a technical plant, in particular a manufacturing or process plant, with a control system (1) according to one of claims 7 or 8, in which an Operator Station Client (2), which wishes to log on to one of the two Operator Station Servers (OS 1.1 , OS 1.2), queries the respective health index from both Operator Station Servers (OS 1.1 , OS 1.2) and selects one of the two Operator Station Servers (OS 1.1, OS 1.2) for the login based on a comparison of the two health indexes.
11. Method according to claim 9 or 10, wherein the respective health index is used by a computer-implemented maintenance service of the control system (1) to determine a maintenance requirement of the operator station server (OS 1.1, OS 1.2) and to trigger corresponding maintenance.
Citation Information
Patent Citations
Method for operating an automation system, operator and monitoring system and automation system
EP3276437A1
Control System and Method for Fine-Grained Reconciliation of Local Archives in Master / Master Scenarios of Servers of a Technical Installation
US20230058281A1