Peer-to-Peer Controller Redundancy for High Availability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing redundancy schemes in control systems require additional technical resources, such as power consumption and maintenance efforts, to achieve high availability, which increases costs and complexity.

Innovation Solution

A peer-to-peer redundancy scheme where controllers dynamically switch between primary and secondary modes, leveraging modern controller capacity to distribute tasks and reduce the need for additional redundant controllers, allowing non-availability risks to be distributed across multiple controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional redundancy schemes (hot standby or N-modular) are used to achieve high availability, then system reliability is improved, but technical resources (power consumption, maintenance efforts, device complexity) increase

Engineering Contradiction:
Improvesystem availabilityVSAvoidcontroller configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Controllers in the peer-to-peer redundancy system perform multiple functions: they execute their own primary tasks while simultaneously serving as backup controllers for peer tasks. This multi-functionality eliminates the need for dedicated standby controllers, reducing overall system complexity while maintaining high availability through dynamic task takeover capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The redundancy configuration is dynamic rather than static. Controllers can dynamically switch between executing primary tasks and providing backup capacity for peer tasks based on system conditions and peer availability. This dynamic allocation optimizes resource utilization and reduces the permanent overhead associated with traditional static redundancy schemes

Inventive Principle:
Principle #15Dynamics

2Reliability

If additional redundant controllers are provisioned to maintain system operation during failures, then system reliability is improved, but power consumption and maintenance efforts increase

Engineering Contradiction:
Improvesystem availabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system implements self-service redundancy where existing controllers provide backup capacity for their peers without requiring additional dedicated redundant hardware. Each controller monitors its peers and can autonomously take over peer tasks when needed, eliminating the power consumption and maintenance overhead of separate standby controllers while ensuring continuous system operation

Inventive Principle:
Principle #25Self-service

3Reliability

If N-modular redundancy with voting schemes is implemented to detect and disregard malfunctioning controller output, then system reliability is improved, but computing overhead increases

Engineering Contradiction:
Improvefault detection capabilityVSAvoidcomputing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the fault detection function from the task execution process. Instead of requiring continuous voting schemes that compute and compare outputs from multiple redundant controllers, the system separately monitors controller health status and task execution states. This separation eliminates the computationally expensive real-time voting process while maintaining effective fault detection and isolation capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2930623B1Controller system with peer-to-peer redundancy, and method to operate the system
Publication Date: 2017.08.02 ABB (SCHWEIZ) AG
  • EP2930623B1 patent drawingFigure 1
  • EP2930623B1 patent drawingFigure 2
  • EP2930623B1 patent drawingFigure 3

AI summary

Controllers (110-1, 110-2, 110-3) in a system (100) are associated with technical entities and are adapted to selectively execute tasks (A, B, C) in a primary mode (101) when the controllers interact with the associated technical entities with respect to the tasks, and to execute tasks (A, B, C) in a secondary mode (102) when the controllers do not interact with the associated technical entities with respect to the task. The system distributes task instructions of a first task (A) to a first controller (110-1) that is configured to execute the first task in the primary mode (101), and to distribute the task instructions of the first task to a second controller (110-2) that is configured to execute the first task in the secondary mode (102). The system distributes task instructions of a second task (B) to the second controller that is configured to execute the second task in the primary mode. The system is further configured - upon non-availability of the first controller - to switch the second controller from the secondary mode for the first task to the primary mode for the first task, while the second controller is adapted to continue executing the second task in primary mode.