HMI Client Node Failover for PLC Communication Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SCADA systems are susceptible to high failure risk due to the reliance on a single server HMI device, which can cause the entire system to fail if it malfunctions, limiting redundancy and system reliability.

Innovation Solution

A system and method are introduced where multiple nodes are designated, with one acting as a server node and others as HMI client nodes, equipped with a failover module to detect server node failures and dynamically designate a new server node from among the HMI client nodes, ensuring continuous communication with a Programmable Logic Controller (PLC) through network switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single server HMI device is used to communicate with the PLC, then the system architecture is simple and easy to operate, but the system reliability is low because the entire system fails when the server HMI device fails

Engineering Contradiction:
Improvesystem reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent designates one HMI client node in advance as a standby server node before any failure occurs. This standby node is pre-configured and ready to assume the server role immediately upon detecting the primary server's failure, eliminating the need for complex real-time selection algorithms and ensuring continuous system operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a failover module in each HMI client node that continuously monitors the server HMI device's status. This proactive monitoring and pre-configured failover mechanism acts as a cushion against server failures, ensuring system reliability without requiring complex real-time response systems.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If multiple HMI client nodes are connected through a network switch to communicate with the server node, then system redundancy is improved, but the device complexity and network configuration complexity increase

Engineering Contradiction:
Improvesystem redundancyVSAvoidnetwork configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes each HMI client node multi-functional by equipping them with failover modules that can both monitor the server and potentially become the server themselves. This universal capability across all nodes simplifies the network architecture, as any node can serve multiple roles (client, monitor, potential server) without requiring specialized configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The failover module in each HMI client node autonomously monitors the server's status and automatically initiates failover procedures when failure is detected. This self-service mechanism eliminates the need for complex external management systems or manual intervention, reducing overall system complexity while maintaining high redundancy.

Inventive Principle:
Principle #25Self-service

3Reliability

If a failover module is implemented in each HMI client node to detect server failures and designate new server nodes, then system reliability and continuity are improved, but the device complexity and processing requirements increase

Engineering Contradiction:
Improvesystem continuityVSAvoidnode software complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The failover module is pre-configured in each HMI client node with the logic and capabilities needed to assume the server role. This preliminary preparation includes pre-established communication pathways and pre-configured identification mechanisms, allowing immediate failover without complex real-time decision-making or reconfiguration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The failover module continuously receives feedback about the server's operational status through monitoring communications. When the feedback indicates server failure, the module automatically triggers the failover process. This simple feedback-loop mechanism maintains system continuity without requiring complex control algorithms or processing power.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9280426B2System and method for server redundancy
Publication Date: 2016.03.08 SOLAR TURBINES INC
  • US9280426B2 patent drawing
  • US9280426B2 patent drawing
  • US9280426B2 patent drawing

AI summary

A system is provided. The system includes a plurality of nodes. One of the plurality of nodes is designated as a server node, and the others of the plurality of nodes are designated as Human Machine Interface (HMI) client nodes. The designated server node comprises a network interface configured to communicate with a Programmable Logic Controller (PLC) either directly or through a network switch. Each of the designated HMI client nodes includes a network interface configured to communicate with the designated server node through one or more of a network switch, and another designated HMI client node. Also, the each of the designated HMI client nodes includes a failover module configured to detect a failure of the designated server node and designate a new server node from among the designated HMI client nodes based on detecting the failure of the designated server node.