Operator Station Alarm Tagging for Partial Plant Image Failure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In process control systems, operator station server failures lead to partial restriction of operation and monitoring, with unclear effects on plant images and process objects, causing operators to only recognize limited control when attempting to operate, leading to potential dangerous situations due to unclear system image availability.

Innovation Solution

A method that identifies and alerts operators to partially restricted system images by using an alarm management component to update a display alarm status tag, which is displayed on the graphical user interface, ensuring operators are informed of affected plant images and their restricted operability, allowing for reliable and safe operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If process objects are distributed across multiple operator station servers to enable flexible operation and monitoring, then system versatility and operational flexibility are improved, but system reliability deteriorates when a server fails because affected plant images become partially inoperable without clear indication to operators

Engineering Contradiction:
Improveoperational flexibilityVSAvoidsystem reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by proactively detecting server failures and updating display alarm status tags before operators attempt to use affected plant images. The alarm management component continuously monitors server status and pre-identifies which plant images will be affected by failures, updating their alarm status tags in advance to prevent operators from encountering unexpected operational restrictions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring server status and dynamically updating the display alarm status tags of affected plant images. When a server failure is detected, the alarm management component feeds back this information by updating the alarm status tags of all plant images that reference process objects from the failed server, ensuring operators receive real-time feedback about system state and operational restrictions.

Inventive Principle:
Principle #23Feedback

2Loss of information

If diagnostic information is provided to indicate server failures, then information availability is improved, but ease of operation deteriorates because operators cannot determine which plant images are affected and require manual checking

Engineering Contradiction:
Improveinformation availabilityVSAvoidease of operation
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system applies self-service by automatically performing the entire process of detecting server failures, identifying affected plant images, updating their alarm status tags, and displaying this information to operators. The alarm management component autonomously monitors server status, determines which plant images are affected by failures, updates their display alarm status tags, and presents this information through the graphical user interface without requiring any manual intervention from operators.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The display alarm status tag serves as an intermediary that mediates between the complex backend system state and the operator interface. Instead of requiring operators to manually check server status and cross-reference with plant images, the alarm status tag automatically translates server failure information into a visible indicator on the plant image display, serving as an intermediary that simplifies information presentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If plant images are removed from navigation hierarchies when their server fails, then system safety is improved by preventing access to inoperable images, but loss of time increases because operators cannot access any plant images from failed servers including those that might still be partially functional

Engineering Contradiction:
Improvesystem safetyVSAvoidaccess time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies local quality by differentiating the operational status of individual plant images based on their specific dependencies on process objects from failed servers. Instead of removing all plant images from a failed server from navigation hierarchies, the system selectively updates only those plant images that have process objects from the failed server, allowing operators to access plant images that remain fully functional while being alerted to restrictions on affected images.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4099114B1Method for detecting a restricted operation and observation of a technical installation, operating and monitoring system and process control system
Publication Date: 2023.07.19 SIEMENS AG
  • EP4099114B1 patent drawingFigure 1

AI summary

The invention relates to a method for detecting and monitoring restricted operation of a technical system in which a process is controlled by a process control system. The process control system comprises at least two operator station servers and at least one operator station client, wherein process objects associated with the process are distributed across process images of different operator station servers of the process control system. For process monitoring, a graphical user interface is provided on the operator station client for displaying system images with symbols belonging to the process objects. The invention is characterized by the following method steps: A component of a first operator station server determines whether another operator station server of the process control system has failed.A failure of this server is reported to an alarm management component of the first Operator Station Server. This component checks whether plant images containing process objects from the failed server's process image are stored on the first Operator Station Server and identifies which plant images are affected by the server failure. If so, an operator alarm is triggered, informing the user that the affected plant image is only partially functional. A component that manages the alarm status of plant images updates the alarm status tag of the affected plant image in the first server's process image, and the operator alarm is displayed in conjunction with the affected plant image on the Operator Station Client's graphical user interface.