I/O Module Firmware Migration via Dual-Processor Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial process control systems with single-microprocessor I/O modules face challenges during firmware upgrades, leading to loss of control over field devices and potential shutdowns, as they cannot enforce failsafe actions or maintain view/control during boot failures, resulting in production losses and increased complexity/cost with redundant systems.
Innovation Solution
Implementing a dual-processing architecture within I/O modules, where a field controller independent of the processing device can hold and manage output signals during firmware upgrades and reboots, allowing the system to maintain control and prevent shutdowns without requiring redundant controllers or modules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single-microprocessor I/O module is used, then device complexity is reduced, but reliability deteriorates during firmware upgrades causing complete loss of control over field devices
Solution Approach 1:
The I/O module is segmented into two independent processing devices: a first processing device responsible for firmware management and a second processing device responsible for maintaining field device control. This segmentation allows the second device to continue holding output signals and maintaining communication with field devices while the first device undergoes firmware upgrades, thereby maintaining reliability without significantly increasing overall device complexity.
Solution Approach 2:
The second processing device acts as an intermediary that maintains the control connection between the I/O module and field devices during firmware upgrades. It holds output signals and manages communication while the first processing device is upgraded, preventing complete loss of control and ensuring reliability during the upgrade process.
2Reliability
If redundant process controllers or I/O modules are incorporated, then reliability during firmware upgrades is improved, but device complexity and cost increase
Solution Approach 1:
The functionality of a redundant I/O module is merged into a single I/O module by implementing two processing devices within one module. The second processing device performs the role that would traditionally be fulfilled by a standby redundant module, allowing the system to achieve the same reliability benefits without the complexity and cost of multiple separate modules.
Solution Approach 2:
The second processing device serves multiple functions: it maintains field device control during normal operation, holds output signals during firmware upgrades, and ensures continuous communication with field devices. This multi-functionality replaces the need for dedicated redundant components while maintaining reliability.
3Reliability
If firmware upgrade causes microprocessor reboot, then new firmware is loaded, but productivity deteriorates due to complete shutdown of industrial process
Solution Approach 1:
The second processing device ensures continuous control of field devices during the firmware upgrade and reboot of the first processing device. It holds output signals and maintains communication, preventing any interruption in the industrial process and ensuring productivity continues uninterrupted while the firmware upgrade occurs.
4Reliability
If firmware upgrade is performed, then system functionality is improved, but loss of time occurs during shutdown and reboot period
Solution Approach 1:
While the first processing device undergoes firmware upgrade and reboot, the second processing device continuously maintains control of field devices and holds output signals. This eliminates any downtime in the industrial process, allowing firmware updates to occur without production interruption and preventing any loss of productive time.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method includes receiving, at a first processing device (206) of an input/output module (IOM) (154), new firmware data (408, 508) for the IOM. The method also includes sending an output hold command (418, 518) from the first processing device to a second processing device (212) of the IOM. The method further includes upgrading (422, 522) firmware of the IOM with the new firmware data using the first processing device and attempting (422, 522) a reboot of the first processing device. In addition, the method includes, in response to the output hold command and during the upgrading of the firmware and the rebooting of the first processing device, using (424, 524) the second processing device to cause a field circuit (202) of the IOM to hold at least one previous output signal for one or more external devices (102a, 102b).