2oo3 Automation Switchover Using Asynchronous Output Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current redundant automation systems in automation technology face challenges in seamless failover and minimizing downtime, particularly in maintaining continuous process output values without disruptive changes during subsystem switching, which is costly and complex to implement.

Innovation Solution

The system employs a '2 of 3' architecture where the second and third subsystems lag behind the first subsystem, with asynchronous data exchange and multicast-based communication for synchronization, allowing only validated output data to be written, and shifting application relationships based on output data comparisons to ensure seamless switchover and efficient bandwidth use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If synchronous synchronization between subsystems is implemented to ensure seamless failover, then system reliability is improved, but communication bandwidth requirements increase and system complexity increases

Engineering Contradiction:
Improvesystem availabilityVSAvoidsynchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary synchronization actions where the first subsystem proactively sends synchronization data to the second and third subsystems before any failover event occurs. This allows the standby subsystems to maintain updated state information in advance, ensuring they can immediately take over without disruption when needed, thereby improving reliability while managing complexity through scheduled rather than reactive synchronization.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a communication network as an intermediary that facilitates data exchange between subsystems. The first subsystem uses this intermediary to distribute synchronization data to the second and third subsystems, and the subsystems use the same intermediary to send output acknowledgments back to the first subsystem. This centralized communication medium simplifies the synchronization architecture compared to direct peer-to-peer connections between all subsystems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If frequent synchronization between subsystems is performed to maintain identical system states, then failover smoothness is improved, but communication bandwidth consumption increases

Engineering Contradiction:
Improvefailover smoothnessVSAvoidcommunication bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements a self-service mechanism where the first subsystem monitors its own output data and only initiates synchronization transmissions when its output data changes. The second and third subsystems similarly monitor their own states and only send output acknowledgments when their received data differs from their current state. This event-driven approach eliminates unnecessary periodic communications, reducing bandwidth consumption while maintaining synchronization accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs periodic synchronization actions triggered by program cycles rather than continuous communication. The first subsystem synchronizes its output data to the second and third subsystems at regular program cycle intervals, and the standby subsystems periodically send output acknowledgments back. This structured periodic action ensures synchronization occurs frequently enough for smooth failover while avoiding the excessive bandwidth consumption of continuous real-time communication.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If output data validation from multiple subsystems is required before forwarding, then output accuracy is improved, but processing time increases

Engineering Contradiction:
Improveoutput data accuracyVSAvoiddata validation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary validation by having the second and third subsystems continuously monitor and acknowledge the receipt of output data from the first subsystem before it is forwarded to the output device. This advance validation ensures data accuracy is verified in advance, allowing the first subsystem to forward output data with confidence that the standby subsystems have validated and acknowledged the data state, reducing actual forwarding delay.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If a 2 of 3 system architecture is used instead of 1 of 2, then diagnostic coverage is improved, but system complexity increases

Engineering Contradiction:
Improvediagnostic coverageVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the functional roles of multiple subsystems into a unified 2 of 3 architecture where the first subsystem acts as the active controller, while the second and third subsystems serve as standby units with identical capabilities. This merging of redundant functional roles allows the system to achieve enhanced diagnostic coverage through multiple independent validation paths while managing architectural complexity through standardized, interchangeable subsystem designs that follow the same communication and synchronization protocols.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4133343B1Redundant automation system and method for operating a redundant automation system
Publication Date: 2024.03.13 SIEMENS AG
  • EP4133343B1 patent drawingFigure 1
  • EP4133343B1 patent drawingFigure 2
  • EP4133343B1 patent drawingFigure 3~4

AI summary

In order to provide a method for operating a redundant automation system (100) for controlling a technical process, it is proposed to operate a two-out-of-three system with three subsystems, wherein - a comparison means (V1, V2, V3) is cyclically operated in each subsystem (1, 2, 3) and compares the first, second and third output data (A1, A2, A3) with one another, and the respective comparison means (V1, V2, V3) are operated in such a manner that - during each comparison in which the result is that all output data (A1, A2, A3) are approximately the same, no further action is carried out, and - during a comparison in which deviations between the output data are determined, that subsystem (1, 2, 3) in which the deviations of its own output data (A1, A2, A3) from the other output data (A1, A2, A3) are the greatest is identified as faulty by means of a majority decision (ME).