Controller Redundancy via Shared Backup Roles and I/O Mesh

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional redundant industrial control systems require dedicated backup controllers, leading to inefficiencies and potential loss of process control if both primary and backup controllers fail, necessitating a more flexible redundancy scheme.

Innovation Solution

Implementing a M:N redundancy scheme where any active process controller can serve as a backup for others, eliminating the need for explicit dedicated backup hardware and enabling flexible workload assignment through an I/O mesh network, allowing continued process control even with multiple controller faults.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated backup controllers are deployed in traditional 1:1 redundancy systems, then controller availability is improved, but hardware cost and system complexity increase

Engineering Contradiction:
Improvecontroller availabilityVSAvoidhardware configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each process controller is configured with dual functionality: it serves as both a primary controller for its own control mission and as a backup controller for another primary controller. This multi-functionality eliminates the need for dedicated backup hardware, as every controller can assume multiple roles depending on system needs

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the primary and backup controller functions into the same hardware platform. Instead of having separate dedicated backup controllers, the system combines these roles in a single controller that dynamically switches between primary and backup responsibilities based on operational requirements

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If dedicated backup controllers are used, then fault tolerance is improved, but hardware cost increases

Engineering Contradiction:
Improvefault toleranceVSAvoidhardware quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Controllers are designed to perform multiple functions simultaneously - each controller acts as a primary controller for its own process control mission while also serving as a backup controller for another primary controller, maximizing hardware utilization and minimizing total hardware requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses its own operational controllers to provide backup services rather than requiring separate dedicated backup hardware. Each controller contributes its own processing power and resources to support the overall system's fault tolerance requirements

Inventive Principle:
Principle #25Self-service

3Reliability

If traditional 1:1 redundancy is implemented, then controller failover is ensured, but system adaptability decreases

Engineering Contradiction:
Improvecontroller failoverVSAvoidredundancy configuration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The redundancy configuration is dynamic rather than static. Controllers can dynamically switch between primary and backup roles based on system conditions, allowing the system to adapt to various failure scenarios and operational requirements without being locked into a fixed redundancy architecture

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system provides universal backup capability where any controller can serve as a backup for any other primary controller, rather than being restricted to predetermined 1:1 pairings. This universal approach greatly increases system adaptability to different failure modes and operational scenarios

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If I/O gateways are configured with dedicated redundancy, then data acquisition reliability is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata acquisition reliabilityVSAvoidgateway hardware configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

I/O gateways are configured to perform dual functions: they execute their primary data acquisition and communication tasks while simultaneously serving as backup gateways for other primary gateways. This eliminates the need for separate dedicated backup gateway hardware

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The I/O gateway system uses its own operational gateways to provide backup services rather than requiring separate dedicated backup hardware. Each gateway contributes its data acquisition and communication capabilities to support overall system reliability

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11481282B2Redundant controllers or input-output gateways without dedicated hardware
Publication Date: 2022.10.25 HONEYWELL INTERNATIONAL INC
  • US11481282B2 patent drawing
  • US11481282B2 patent drawing
  • US11481282B2 patent drawing

AI summary

A method of fault-tolerant process control includes providing a network process control system in an industrial processing facility (IPF) including a plant-wide network coupling a server to computing platforms each including computing hardware and memory hosting a software application for simultaneously supporting a process controller and another process controller or an I/O gateway. The computing platforms are coupled together by a private path redundancy network for providing a hardware resource pool. At least some of the computing platforms are directly coupled by an I/O mesh network to a plurality of I/O devices to field devices that are coupled to processing equipment. Upon detecting at least one failing device in the hardware resource pool, over the private path redundancy network a backup is placed into service for the failing device from the another process controller or I/O gateway that is at another of the computing platforms in the hardware resource pool.