Redundant Automation Switchover Using Majority Output Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current redundant automation systems in automation technology face challenges in ensuring seamless failover between subsystems without causing output shocks during switchover, particularly in maintaining continuous curve profiles of process output values, which requires synchronized system states and complex self-diagnosis functionalities.

Innovation Solution

A method where the second and third subsystems send acknowledgements to the first subsystem, allowing it to forward output data only when both acknowledgements are received, and comparators cyclically compare output data to identify faulty subsystems via majority decision, transferring application relationships accordingly, enabling asynchronous data exchange and multicast-based communication for efficient synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If synchronous synchronization methods are used to ensure identical system states during failover, then shock-free switchover is achieved, but system complexity and cost increase significantly

Engineering Contradiction:
Improveshock-free switchoverVSAvoidsynchronization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses output data copying and comparison between master and slave subsystems. The slave subsystem continuously calculates output data and compares it with the master's output data. This copying approach ensures the slave has ready-to-use data for immediate takeover without complex synchronization, achieving shock-free switchover while reducing system complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The slave subsystem performs preliminary calculations of output data in advance and maintains this data ready for potential takeover. By pre-calculating and holding output data, the slave can immediately assume control without requiring complex real-time synchronization, thus achieving reliable failover with reduced system complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If complex self-diagnosis functionalities are implemented to achieve high diagnostic coverage, then system reliability improves, but device complexity and cost increase

Engineering Contradiction:
Improvediagnostic coverageVSAvoidself-diagnosis functionality complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the slave subsystem continuously compares its calculated output data with the master subsystem's output data. This simple feedback loop provides diagnostic coverage by detecting deviations between master and slave outputs, indicating potential faults without requiring complex self-diagnosis functionalities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs self-diagnosis through automatic comparison of output data between master and slave subsystems. The slave subsystem independently monitors its own output data against the master's data, providing self-service diagnostic capability that improves reliability without adding complex external diagnosis systems.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If asynchronous data exchange is used to decouple processing power from communication bandwidth, then system adaptability improves, but ensuring synchronized system states becomes more difficult

Engineering Contradiction:
Improvecommunication independenceVSAvoidsystem state synchronization
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The slave subsystem continuously copies and calculates output data independently through asynchronous data exchange. This copying mechanism ensures the slave maintains ready-to-use output data without requiring synchronized communication, achieving both communication independence and system state alignment for reliable failover.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The slave subsystem performs preliminary output data calculations asynchronously and maintains this data ready for potential takeover. This preliminary action decouples the slave's processing from communication bandwidth constraints while ensuring output data is prepared and synchronized with the master's state for reliable failover.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11914338B2Redundant automation system and method for operating the redundant automation system
Publication Date: 2024.02.27 SIEMENS AG
  • US11914338B2 patent drawing
  • US11914338B2 patent drawing
  • US11914338B2 patent drawing

AI summary

A method for operating a redundant automation system for controlling a technical process in which two-out-of-three system with three subsystems are operated, wherein a comparator is cyclically operated in each subsystem and compares the first, second and third output data with one another, and a respective comparator is operated such that, during each comparison in which the result is that all output data are approximately the same, no further action is performed, and during a comparison in which deviations between the output data are determined, that subsystem in which the deviations of its own output data from the other output data are the greatest is identified as faulty via a majority decision.