Process Control Redundancy With Active-Standby Service Failover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current process control systems lack flexible redundancy options, particularly in software and combined software-hardware redundancy, which limits their ability to provide different availability levels for various system parts, increasing costs and hardware requirements.
Innovation Solution
A network-centric process control system with separate executable control services and middleware services running in real-time operating systems, allowing for active and standby configurations, where control services can synchronize and seamlessly take over in case of faults, enabling flexible hardware and software redundancy configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware redundancy is implemented for all system parts to ensure high availability, then system reliability is improved, but hardware cost increases
Solution Approach 1:
The system segments redundancy implementation by allowing different availability levels for different system parts. Critical components can have redundant configurations while non-critical components use single instances, enabling selective redundancy that balances reliability requirements with hardware cost reduction.
Solution Approach 2:
The patent implements a universal redundancy management framework that can handle multiple redundancy types (hardware, software, combined) through a common architecture. The system can dynamically allocate redundant resources based on real-time requirements, allowing the same hardware pool to serve multiple redundancy purposes across different system components.
2Adaptability or versatility
If different availability levels are selected for different system parts using components from different vendors, then flexibility is improved, but engineering complexity increases
Solution Approach 1:
The patent introduces a vendor-agnostic redundancy management layer that acts as an intermediary between diverse hardware components and the control system. This layer provides standardized interfaces and abstraction, allowing different vendors' components to be integrated without increasing engineering complexity, as the redundancy management framework handles vendor-specific details uniformly.
Solution Approach 2:
The system allows dynamic configuration of availability levels by changing operational parameters rather than physical reconfiguration. Engineers can adjust redundancy levels, switch between active-standby and active-active modes, and modify failover policies through software parameters, avoiding complex physical reengineering while maintaining flexibility.
3Reliability
If software redundancy is added to hardware redundant controllers to increase availability, then system reliability is improved, but system complexity increases
Solution Approach 1:
The patent merges hardware redundancy and software redundancy into a unified redundancy framework. The system can combine redundant hardware controllers with redundant software instances, creating a layered redundancy approach where software redundancy operates within the hardware redundant architecture. This integration provides comprehensive fault tolerance while managing complexity through a single management interface.
Solution Approach 2:
The system performs preliminary synchronization of software redundancy instances during normal operation before failures occur. Standby software instances are pre-configured and kept synchronized with active instances, so that when hardware failure occurs, the software redundancy is already prepared to take over immediately, reducing the complexity of real-time failover decision-making.
Data Source
AI summary
A method for providing redundancy in a network centric process control system, where at least one node includes at least one control service as well as at least one middleware service for communicating in the process control system, where the control service and middleware service is each a separate executable running in a separate operating system process provided by a real time operating system thereof, wherein a first control service in a first node communicating via a first middleware service and implementing a first control function acts as an active control service for the first control function and a second control service communicating via a second middleware service and implementing the first control function acts as a standby control service for the first control function, the method including performing, by the first control service, the first control function through subscribing, via the first middleware service, to input process data of the first control function and publishing via the first middleware service, output process data of the first control function, synchronizing the first control service with the second control service, and taking over, by the second control service based on a determination that a fault has occurred in the first node, the role of active control service, the taking over including publishing, by the second control service via a second middleware service provided for the second control service, the output process data of the first control function based on a subscription of the second control service to the input process data.


