Fail-back Software Release in Redundant Process Controllers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional process control systems face challenges in software migration, as updating software can disrupt facility operations and there is a need to preserve functionality and behavior between software releases, while allowing for a fail-back to a prior release if issues arise.
Innovation Solution
The method and apparatus enable a fail-back to a prior software release in a process control system by allowing users to evaluate a new software release on a secondary controller before installing it on a primary controller, with the option to revert to the previous release if problems are detected, maintaining continuous control of the process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software is updated in a process control system, then the system can benefit from new features and improvements, but operational disruptions may occur and functionality may be compromised
Solution Approach 1:
The control system is divided into primary and secondary controllers, each capable of running different software releases. This segmentation allows the secondary controller to be updated without affecting the primary controller's operation, enabling software updates while maintaining continuous reliable operation through the primary controller.
Solution Approach 2:
A controller swap mechanism acts as an intermediary, allowing seamless transition between primary and secondary controllers. This intermediary enables the system to switch to the secondary controller for evaluation and back to the primary controller if issues arise, resolving the contradiction between updating software and maintaining operational reliability.
2Adaptability or versatility
If new software is installed on the primary controller, then the system gains updated functionality, but any issues may disrupt process control
Solution Approach 1:
The secondary controller is updated with the new software release before being activated. This preliminary action allows the new software to be fully installed and prepared on the secondary controller, enabling evaluation without disrupting the primary controller's ongoing process control operations.
Solution Approach 2:
The system dynamically switches between primary and secondary controllers based on evaluation results. The controller roles are not fixed but can be swapped, allowing the system to adapt its operational configuration to maintain ease of operation while evaluating new software functionality.
3Adaptability or versatility
If software updates are performed, then system capabilities are enhanced, but the complexity of managing multiple software versions increases
Solution Approach 1:
The secondary controller serves as a copy of the primary controller's functionality, allowing software to be tested in a replicated environment. This copying approach simplifies management by providing an identical operational counterpart that can run different software versions without affecting the primary system's simplicity.
Solution Approach 2:
If the new software on the secondary controller proves problematic, the system can discard the updated software configuration and recover by swapping back to the primary controller with the original software. This principle reduces management complexity by providing a straightforward rollback mechanism without requiring complex version control procedures.
Data Source
AI summary
A method includes receiving a request to install a software release, where the software release is to be installed on a first device and/or a second device. The method also includes initiating installation of the software release on the second device and determining whether or not a user wishes to continue with the installation of the software release. The method further includes initiating installation of the software release on the first device if the user wishes to continue. In addition, the method includes restoring a second software release on the second device if the user does not wish to continue. The first and second devices may represent redundant devices, such as a redundant set of controllers in a process control system or a redundant set of I/O modules that facilitate communication between one or more controllers and one or more process elements in the process control system.


