Network-Centric Control Service Redundancy for Seamless Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current process control systems lack flexible redundancy options, particularly in software and combined hardware-software redundancy, which limits their ability to provide different availability levels for various system parts, increasing costs and hardware requirements.
Innovation Solution
A network-centric process control system with separate executable control services and middleware services running in real-time operating systems, allowing for active and standby configurations, where control services synchronize and seamlessly take over in case of faults, enabling flexible hardware and software redundancy configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware redundancy is implemented for all system parts to ensure high availability, then system reliability is improved, but hardware cost increases
Solution Approach 1:
The system segments redundancy implementation by allowing different availability levels for different system parts. Critical functions can have redundant control services while non-critical functions use single instances, enabling selective redundancy that balances reliability with hardware cost.
Solution Approach 2:
A single hardware unit can host multiple control services, where one control service acts as active and another as standby. This multi-functional capability allows the same hardware to provide both primary and backup functions, reducing the need for separate redundant hardware units.
2Adaptability or versatility
If different availability levels are selected for different system parts by choosing components from different vendors, then flexibility is improved, but engineering complexity increases
Solution Approach 1:
The system uses homogeneous control services that can be deployed across different hardware units from various vendors. The control services follow a standardized architecture with separate executable control services and middleware services, allowing different availability levels to be configured without requiring different vendor components.
3Reliability
If software redundancy is added to hardware redundant controllers to achieve very high availability, then system reliability is improved, but system complexity increases
Solution Approach 1:
The system implements software redundancy by creating standby control services that are copies of active control services. These standby services replicate the functionality and state of active services, providing fault tolerance through software copying rather than complex hardware redundancy mechanisms.
Solution Approach 2:
Middleware services act as intermediaries between control services and the operating system, managing communication and coordination between active and standby control services. This intermediary layer simplifies the complexity of implementing software redundancy by providing standardized interfaces and abstraction.
Data Source
AI summary
A method for providing redundancy in a network centric process control system, where at least one node includes at least one control service as well as at least one middleware service for communicating in the process control system, where the control service and middleware service is each a separate executable running in a separate operating system process provided by a real time operating system thereof, wherein a first control service in a first node communicating via a first middleware service and implementing a first control function acts as an active control service for the first control function and a second control service communicating via a second middleware service and implementing the first control function acts as a standby control service for the first control function, the method including performing, by the first control service, the first control function through subscribing, via the first middleware service, to input process data of the first control function and publishing, via the first middleware service, output process data of the first control function, synchronizing the first control service with the second control service, and taking over, by the second control service based on a determination that a fault has occurred in the first node, the role of active control service, the taking over including publishing, by the second control service via a second middleware service provided for the second control service, the output process data of the first control function based on a subscription of the second control service to the input process data.


