Redundant Controller Channel Restart for Fast Fault Discrimination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing fault-tolerant device control systems face a trade-off between sensitive fault detection and a low rate of false positive fault diagnoses, with higher sensitivity leading to undetected minor faults and lower sensitivity allowing false positives.
Innovation Solution
A method for operating a fault-tolerant device control system with redundant channels and a diagnostic unit that monitors signal processing, temporarily switching channels to a safe state upon threshold exceedance, and restarting signal processing after a selectable period if the exceedance persists, distinguishing between genuine and false positive faults based on the frequency of threshold exceedance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the threshold for evaluating deviations is set high to minimize false positive fault diagnoses, then the number of false positives is reduced, but the sensitivity of the diagnostic device decreases and minor genuine faults cannot be detected
Solution Approach 1:
The system dynamically adjusts the threshold value based on the operational state and historical data of the device controller. The threshold is not fixed but adapts to different operating conditions, allowing high sensitivity during normal operation while maintaining reliability during transient states. This resolves the contradiction by making the threshold parameter dynamic rather than static.
Solution Approach 2:
The patent changes the parameter of threshold evaluation from a single fixed value to multiple adaptive threshold levels. The diagnostic device uses different threshold values depending on the operational context, such as normal operation, transient states, or maintenance modes. This parameter change allows the system to maintain both high sensitivity and low false positive rates by selecting appropriate threshold levels for different situations.
2Measurement precision
If the threshold is set low to increase sensitivity and detect minor faults, then fault detection sensitivity improves, but false positive fault diagnoses increase
Solution Approach 1:
The system uses dynamic threshold adjustment to maintain high sensitivity without increasing false positives. When the diagnostic device detects patterns consistent with genuine faults rather than random deviations, it lowers the threshold to capture minor faults. Conversely, during periods of normal operational variation, the threshold is raised to prevent false alarms. This dynamic behavior resolves the contradiction between sensitivity and false positive rate.
Solution Approach 2:
The diagnostic device incorporates feedback mechanisms that learn from historical fault patterns and operational data. When genuine faults are detected, the system adjusts its sensitivity parameters to maintain detection capability. When false positives occur, the feedback loop adjusts the threshold upward. This continuous feedback allows the system to optimize both sensitivity and reliability based on actual performance.
3Reliability
If the device controller switches to a safe state upon detecting a deviation to ensure safety, then safety is ensured, but latency is introduced and normal operation is interrupted
Solution Approach 1:
The system performs preliminary diagnostic actions before switching to safe state. Instead of immediately transitioning to safe state upon any threshold exceedance, the diagnostic device first evaluates the nature and persistence of the deviation. This preliminary assessment action allows the system to distinguish between transient anomalies requiring safe state transition and genuine faults, thereby reducing unnecessary latency while maintaining safety.
Solution Approach 2:
The patent applies partial action by selectively transitioning only the affected channel to safe state rather than the entire device controller. When a deviation is detected, the system isolates and switches only the specific channel experiencing the fault, allowing other channels to continue normal operation. This partial action reduces the time loss associated with complete system shutdown while maintaining safety for the affected component.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to a method for operating a fault-tolerant device controller (10) comprising at least two channels (11, 12) for calculating control signals (13) on the basis of input signals (14), wherein the channels (11, 12) are redundant in relation to one another, and comprising at least one diagnostic device (15) for monitoring the signal processing (16) in the channels (11, 12), wherein the method comprises the following steps of: a) calculating (30, 40) the control signals (13) on the basis of the input signals (14) in the channels (11, 12), b) determining (31, 41) a control variable (18) and a deviation of the control variable from a reference specification (19) on the basis of the input signals (14) and the control signals (13) in the diagnostic device (15), c) comparing (32, 42) the deviation with a selectable threshold value, wherein the following steps are carried out provided that the deviation exceeds a selectable threshold value: d) changing (34, 44) a selected channel (11; 12) of the channels (11, 12) into a safe operating state and adapting (35, 45) a count value assigned to the selected channel (11; 12), e) after expiry (36, 46) of a selectable period and provided that the count value assigned to the selected channel (11; 12) has not yet reached a selectable final value: restarting (38, 48) the signal processing (16) in the selected channel (11; 12) in a normal mode, wherein the steps of the method are cyclically carried out repeatedly during operation of the device controller, and to a device controller (10) for carrying out the method.