Distributed Control Network Redundancy for No Single Point of Failure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed control systems in industrial automation environments face challenges with single points of failure, leading to potential loss of visibility and control when hardware or software components fail, resulting in downtime and operational disruptions.
Innovation Solution
A redundant infrastructure configuration is implemented, utilizing Stratix hardware, Cisco network hardware, and FactoryTalk View software, with features like Etherchannel, LACP, PRP, and HSRP, to create a fully redundant system that ensures no single point of failure, allowing the system to maintain operation even with multiple hardware and software failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single server connection is used to the enterprise switch stack, then the device complexity is reduced, but the reliability deteriorates due to single point of failure
Solution Approach 1:
The network infrastructure is segmented into multiple independent paths: dual connections to enterprise switch stack 191, redundancy switches 1101 and 1102, and separate LANs (141f and 142f). This segmentation ensures that a failure in one segment does not propagate to the entire system, resolving the contradiction by distributing risk across multiple segments while maintaining manageable complexity through modular design.
Solution Approach 2:
Redundancy switches 1101 and 1102 are configured beforehand with parallel redundancy protocol (PRP) to provide cushioning against potential failures. The system pre-establishes backup paths and failsafe mechanisms before failures occur, allowing seamless failover without disrupting controller 1003 operations, thus improving reliability without requiring complex real-time decision-making during failures.
2Reliability
If redundant hardware components are implemented, then the reliability is improved, but the loss of time for system configuration and setup increases
Solution Approach 1:
The redundant network infrastructure is pre-configured with standardized connections and protocols before deployment. Enterprise switch stack 191, redundancy switches 1101 and 1102, and LANs 141f and 142f are established with predetermined roles and configurations, allowing rapid deployment without extensive on-site configuration work, thus reducing configuration time while maintaining high reliability.
Solution Approach 2:
The system uses non-swapping IP addresses for redundant controllers 1001 and 1002, maintaining consistent network parameters across failures. This parameter stability eliminates the need for reconfiguration during failover events, reducing operational time loss while maintaining reliability through redundant hardware components.
3Reliability
If multiple redundant controllers are used, then the reliability is improved, but the difficulty of detecting and measuring system state increases
Solution Approach 1:
The HMI application on application server 181a continuously monitors the operational state of controllers 1001 and 1002 through the redundant network infrastructure. Real-time feedback mechanisms track controller status, IP address assignments, and failover events, providing operators with clear visibility into system state despite the complexity of multiple redundant components, thus resolving the contradiction between reliability and monitoring difficulty.
Data Source
AI summary
To facilitate redundancy in a distributed control system architecture used in an industrial automation environment, a user workstation is connected to multiple enterprise access switches. Separate physical connections established between an application server and the enterprise access switches are configured into a single virtual interface for the application server to provide physical media redundancy between the application server and the enterprise access switches. Redundancy switches are connected to the enterprise access switches and to a first LAN and a second LAN, and are assigned unique IP addresses but communicate using a same default gateway IP address to serve as redundant default gateways. The redundancy switches are configured with a redundancy protocol that enables transmission of duplicate data packets over the first LAN and the second LAN. Redundant industrial controllers are connected to both the first LAN and the second LAN, wherein the redundant industrial controllers utilize non-swapping IP addresses.


