Multi-Secondary Controller Synchronization for Redundant Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial control systems face costly downtime and production losses due to failures, particularly when designed without fault-tolerant components that can synchronize CPU data across multiple nodes without dedicated hardware constraints.

Innovation Solution

Implementing a redundancy system with multiple nodes, where a primary controller can be backed up by concurrent secondary controllers, allowing seamless load balancing and equipment updates without disrupting synchronization, enabling control applications to float across any hardware within the automation control hive.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a 1:1 redundancy system is used to synchronize CPU data between primary and secondary controllers, then system reliability is improved, but device complexity increases and adaptability decreases

Engineering Contradiction:
Improvesystem reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a multi-synch system where a single primary controller can simultaneously synchronize with multiple secondary controllers (N secondaries). This universal approach allows any secondary controller to potentially become primary, eliminating dedicated hardware roles and reducing overall system complexity while maintaining reliability through multiple synchronized copies of the control application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the redundancy function by allowing the control application to be distributed across multiple independent controller nodes. Each controller maintains a copy of the control application and can operate independently, dividing the single-point-failure risk into multiple independent failure points that don't affect each other.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If control applications are bound to dedicated hardware in a 1:1 redundancy system, then synchronization is simplified, but adaptability and flexibility are reduced

Engineering Contradiction:
Improvesynchronization complexityVSAvoidadaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The control application is designed to be hardware-agnostic and can execute on any controller within the network. The system uses a universal synchronization protocol that allows the same control application to run on multiple different controller hardware platforms, enabling flexible reconfiguration and load balancing without being bound to dedicated hardware assignments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically assigns primary and secondary roles to controllers based on operational needs rather than fixed hardware assignments. Controllers can transition between primary and secondary roles, and the synchronization relationships can be dynamically created or removed as controllers are added or removed from the system, providing high adaptability.

Inventive Principle:
Principle #15Dynamics

3Reliability

If multiple concurrent secondary controllers are maintained for load balancing and updates, then system availability is improved, but memory synchronization complexity increases

Engineering Contradiction:
Improvesystem availabilityVSAvoidmemory synchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system creates multiple independent copies of the control application in the memory of each secondary controller. Each copy is a complete, standalone instance that can be independently synchronized with the primary controller. This copying approach simplifies memory synchronization because each secondary controller maintains its own complete copy rather than sharing or referencing common memory structures.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The secondary controllers pre-load and maintain complete copies of the control application in their memory before failover is needed. This preliminary action ensures that when a primary controller fails, any secondary controller can immediately take over without needing to transfer or reconstruct the control application, eliminating synchronization delays during critical failover events.

Inventive Principle:
Principle #10Preliminary action

4Speed

If write-through caching is used in CPUs for rapid process response, then processing speed is improved, but fault tolerance capability is reduced

Engineering Contradiction:
Improveprocessing speedVSAvoidfault tolerance capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system segments the fault tolerance function across multiple independent controller nodes, each with its own CPU and memory system. Rather than relying on a single CPU with complex fault-tolerant caching, each controller is independently fault-tolerant through the multi-synch architecture. This allows each CPU to use aggressive write-through caching for rapid processing while the overall system maintains reliability through redundancy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system provides beforehand cushioning by maintaining multiple synchronized copies of the control application in advance. If a CPU failure occurs, the system has already prepared alternate controllers with identical control applications ready to take over immediately, cushioning against the loss of any single CPU regardless of its caching configuration.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11662715B2Multi-synch of a primary automation device with multiple secondaries
Publication Date: 2023.05.30 HONEYWELL INTERNATIONAL INC
  • US11662715B2 patent drawing
  • US11662715B2 patent drawing
  • US11662715B2 patent drawing

AI summary

Methods and systems for synchronizing controllers in an automation control system, can involve arranging redundancy elements in an automation control system comprising a group of nodes, wherein the redundancy elements can include one or more primary controllers and a group of concurrent secondary controllers, and wherein a back-up to the primary controller can exist on any node. Such methods and systems can further involve backing-up of the primary controller by the one or more secondary controllers to allow the primary controller to maintain the one or more secondary controllers as a new, alternate secondary controller for a load balancing or an equipment update.