Cloud Redundant Control Paths for Fail-Safe Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current redundant automation systems, especially those in cloud environments, face high downtime risks due to shared communication nodes and energy dependencies, which are not sufficient for maintaining continuous operation in automation technology.

Innovation Solution

A method for creating a redundant automation system with control applications in a cloud computing structure, where computing resources are located in different, energy-independent data centers connected via separate communication paths with no common nodes, ensuring that one control application can seamlessly take over in case of failure, thereby improving Mean Time To Failure (MTTF).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If control applications are moved to cloud computing infrastructure, then accessibility and scalability are improved, but availability and reliability deteriorate due to shared communication nodes and annual downtimes

Engineering Contradiction:
Improvecloud accessibilityVSAvoidsystem availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the redundant control applications into separate physical locations (different data centers) with independent communication paths. Each control application instance operates independently with its own dedicated network infrastructure, preventing single points of failure from affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (separate communication paths through different network infrastructure) between the control applications and the automation system. This intermediary layer isolates the applications from common failure points while maintaining their functional connection to the controlled system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If redundant control applications use shared communication infrastructure, then device complexity is reduced, but reliability deteriorates due to common failure points

Engineering Contradiction:
Improvecommunication infrastructureVSAvoidfailure independence
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The communication infrastructure is segmented into separate, independent paths for each control application instance. Rather than sharing a common network backbone, each application has its own dedicated communication route to the automation system, eliminating common failure points.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each control application instance is provided with locally optimized, independent communication resources tailored to its specific needs. This local quality approach ensures that failures in one application's communication path do not propagate to other applications.

Inventive Principle:
Principle #3Local quality

3Device complexity

If control applications are located in the same data center, then synchronization is simplified, but reliability deteriorates due to energy supply dependencies

Engineering Contradiction:
Improvesynchronization setupVSAvoidenergy supply independence
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces synchronous Ethernet as an intermediary synchronization mechanism that enables precise time coordination between geographically distributed control applications. This intermediary protocol allows applications in different data centers to maintain synchronization without requiring physical proximity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3800517B1Method for providing a redundant automation system, computer program and computer-readable medium
Publication Date: 2024.08.14 SIEMENS AG
  • EP3800517B1 patent drawingFigure 1
  • EP3800517B1 patent drawingFigure 2
  • EP3800517B1 patent drawingFigure 3

AI summary

A redundant automation system (1) comprises an automation system (2) located at a plant site and two control applications (7) that are interconnected via a synchronization path (8) and are configured to control the automation system (2). These control applications form part of a cloud computing structure, and their computing resources are located at different sites. The control applications are connected to the automation system (2) via the internet or a comparable computer network that has communication nodes (4) and communication paths (5) connecting them. One of the control applications (7) operates as the master, and the other as the backup. If the master control application (7) fails, the backup control application (7) takes over its function.The locations of the computing resources for the control applications (7) are chosen such that the control applications (7) are connected to the automation system (2) via two different communication paths (5). Furthermore, the invention relates to a method for creating such an automation system, a computer program, and a computer-readable medium.