Redundant DCN Failover Using Keep-Alive and Virtual IP Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Failure of primary distributed control nodes (DCNs) in process automation facilities can lead to costly or catastrophic consequences, necessitating a redundant DCN system for quick changeover to backup DCNs.

Innovation Solution

Implementing a redundant DCN system with a private network and a keep alive process to determine primary DCN unavailability, transferring a virtual IP address and subscription data to backup DCNs, enabling seamless reassignment as new primary nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a redundant DCN system is implemented with backup nodes, then system reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesystem availabilityVSAvoidredundant system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments DCN functionality by separating primary and backup roles, allowing independent operation and failure isolation. Each DCN can function autonomously as primary or backup, enabling modular redundancy that improves reliability without requiring complete system duplication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Backup DCNs are designed with multi-functionality, capable of operating as standby units during normal conditions and automatically transitioning to primary function upon failure detection. This universal design allows the same hardware to serve multiple purposes, reducing overall system complexity while maintaining high availability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of time

If quick changeover from primary to backup DCN is implemented, then loss of time is reduced, but device complexity increases due to keep alive processes and virtual IP address management

Engineering Contradiction:
Improvechangeover timeVSAvoidfailover mechanism complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The keep alive process continuously monitors primary DCN status in advance, and subscription data is pre-configured in backup nodes before failure occurs. Virtual IP addresses are pre-assigned to backup DCNs, enabling immediate takeover without configuration delays, thus minimizing changeover time while managing complexity through automation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The keep alive mechanism implements continuous feedback monitoring of primary DCN health status. When the primary DCN fails to respond to keep alive signals, the system automatically triggers the failover process, eliminating manual intervention and reducing changeover time despite the added monitoring complexity.

Inventive Principle:
Principle #23Feedback

3Reliability

If subscription data is transmitted to backup DCNs, then reliability is improved, but loss of information and use of energy increase

Engineering Contradiction:
Improvedata availabilityVSAvoiddata transmission energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Subscription data is transmitted to backup DCNs selectively rather than continuously. The system transmits only the minimum necessary subscription information required for failover capability, avoiding redundant data transmission while ensuring sufficient data availability for quick recovery, thus balancing reliability with energy efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250298394A1Distributed control node (DCN) redundancy
Publication Date: 2025.09.25 YOKOGAWA ELECTRIC CORP
  • US20250298394A1 patent drawing
  • US20250298394A1 patent drawing
  • US20250298394A1 patent drawing

AI summary

Methods, systems, and apparatus for implementing a redundant DCN system over a process automation network. In one aspect, a redundant DCN system includes a primary DCN, a backup DCN, and a keep alive process configured to determine whether the primary DCN becomes unavailable, wherein in response to the primary DCN being determined as unavailable, the backup DCN is reassigned as a new primary DCN, and assumes functions previously executed by the former primary DCN. Each DCN in the redundant DCN system may have a unique virtual IP address or transfer a common virtual IP address. Virtual IP addresses may impact communications between DCNs and other devices.