Uninterrupted Firmware Update via Dual-Instance Switchover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for updating firmware in protection and automation systems of electrical energy transmission and distribution require system interruption, leading to operational downtime and increased costs due to redundant system designs.
Innovation Solution
A method where an updated version of the program is started alongside the existing one, with data transfer and status messages facilitating a seamless switchover to the new instance, allowing uninterrupted firmware updates by using an application software to manage the transition without halting system operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If firmware update is performed by transferring new programs and resuming operation, then firmware can be updated, but system operation must be interrupted
Solution Approach 1:
The updated program instance is started and initialized before the switchover to the new firmware version. All necessary data transfer, configuration loading, and system initialization are performed in advance while the old system is still running, so that when the switchover occurs, the new instance is already ready to take over operation immediately without interruption.
Solution Approach 2:
An intermediary mechanism is introduced to coordinate the switchover process between the old and new program instances. The intermediary manages the transition by coordinating data transfer, validating the new instance's readiness, and orchestrating the switchover timing to minimize or eliminate system operation interruption.
2Reliability
If redundant protection and automation systems are used, then firmware can be updated without interruption, but costs increase
Solution Approach 1:
The protection and automation system is segmented into multiple independent program instances that can run simultaneously. The old program instance and new program instance are separated as distinct entities, each capable of independent operation. This segmentation allows the new instance to be prepared and tested while the old instance continues to serve the system, eliminating the need for complete system redundancy.
Solution Approach 2:
The system transitions from a static single-instance operation mode to a dynamic multi-instance mode where program instances can be started, stopped, and switched between as needed. The system dynamically manages multiple instances during the update process and then consolidates to a single active instance after successful switchover, reducing complexity compared to permanent redundancy.
3Productivity
If updated program instance is started during ongoing operation, then uninterrupted update is enabled, but data transfer complexity increases
Solution Approach 1:
The data transfer process is broken down into preliminary actions performed before the actual switchover. Configuration data, system state information, and operational parameters are transferred and validated in advance while the system remains stable. This preliminary data transfer reduces the complexity of the critical switchover moment and ensures continuous operation.
Solution Approach 2:
A feedback mechanism is implemented to monitor the status of both program instances and coordinate data transfer. The system continuously exchanges status information between the old and new instances, allowing the intermediary to adjust data transfer timing and scope based on real-time system state, thereby simplifying the coordination of complex data transfer during continuous operation.
Data Source
AI summary
The invention relates to a method (1) for updating at least one program (2) of a firmware of a protection or automation system in the field of electrical power transmission or distribution, in which: - in addition to the program (2) to be updated, which is in operation, an updated version or configuration of the program is started as a new instance (4); - the new instance (4) informs an update program (3) by means of a first status message (12) that it is ready to transfer operation from the program (2) to be updated to itself (4); - subsequently, the program (2) to be updated transfers operating data and parameters (16) to the new instance (4); - the new instance (4) informs itself by means of a second status message (17) and the program (2) to be updated informs itself by means of a third status message (18) that they are ready to switch operation to the new instance (4).and - subsequently, the switchover of the operation from the program to be updated (2) to the new instance (4) takes place.


