Redundant Automation Switchover Using Majority Output Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current redundant automation systems in automation technology face challenges in ensuring seamless failover between subsystems without causing output shocks during switchover, particularly in maintaining continuous curve profiles of process output values, which requires synchronized system states and complex self-diagnosis functionalities.
Innovation Solution
A method where the second and third subsystems send acknowledgements to the first subsystem, allowing it to forward output data only when both acknowledgements are received, and comparators cyclically compare output data to identify faulty subsystems via majority decision, transferring application relationships accordingly, enabling asynchronous data exchange and multicast-based communication for efficient synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If synchronous synchronization methods are used to ensure identical system states during failover, then shock-free switchover is achieved, but system complexity and cost increase significantly
Solution Approach 1:
The patent uses output data copying and comparison between master and slave subsystems. The slave subsystem continuously calculates output data and compares it with the master's output data. This copying approach ensures the slave has ready-to-use data for immediate takeover without complex synchronization, achieving shock-free switchover while reducing system complexity.
Solution Approach 2:
The slave subsystem performs preliminary calculations of output data in advance and maintains this data ready for potential takeover. By pre-calculating and holding output data, the slave can immediately assume control without requiring complex real-time synchronization, thus achieving reliable failover with reduced system complexity.
2Reliability
If complex self-diagnosis functionalities are implemented to achieve high diagnostic coverage, then system reliability improves, but device complexity and cost increase
Solution Approach 1:
The patent implements a feedback mechanism where the slave subsystem continuously compares its calculated output data with the master subsystem's output data. This simple feedback loop provides diagnostic coverage by detecting deviations between master and slave outputs, indicating potential faults without requiring complex self-diagnosis functionalities.
Solution Approach 2:
The system performs self-diagnosis through automatic comparison of output data between master and slave subsystems. The slave subsystem independently monitors its own output data against the master's data, providing self-service diagnostic capability that improves reliability without adding complex external diagnosis systems.
3Adaptability or versatility
If asynchronous data exchange is used to decouple processing power from communication bandwidth, then system adaptability improves, but ensuring synchronized system states becomes more difficult
Solution Approach 1:
The slave subsystem continuously copies and calculates output data independently through asynchronous data exchange. This copying mechanism ensures the slave maintains ready-to-use output data without requiring synchronized communication, achieving both communication independence and system state alignment for reliable failover.
Solution Approach 2:
The slave subsystem performs preliminary output data calculations asynchronously and maintains this data ready for potential takeover. This preliminary action decouples the slave's processing from communication bandwidth constraints while ensuring output data is prepared and synchronized with the master's state for reliable failover.
Data Source
AI summary
A method for operating a redundant automation system for controlling a technical process in which two-out-of-three system with three subsystems are operated, wherein a comparator is cyclically operated in each subsystem and compares the first, second and third output data with one another, and a respective comparator is operated such that, during each comparison in which the result is that all output data are approximately the same, no further action is performed, and during a comparison in which deviations between the output data are determined, that subsystem in which the deviations of its own output data from the other output data are the greatest is identified as faulty via a majority decision.


