Redundant SCADA Architecture for High-Availability Process Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SCADA architectures for critical industrial processes lack the capacity to manage large volumes of data and commands efficiently, limiting their suitability for high-availability and reliability requirements, especially in systems like electrical networks and power generation plants, and require additional safety systems like SPDS which are not suitable for large, critical processes.

Innovation Solution

A system with two distinct subsystems, one for control and one for assistance, utilizing asynchronous and active redundancy, unidirectional separation, and redundant communication networks to ensure cyclic and event-driven operations, providing centralized and reliable information to operator stations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a SCADA architecture is used to control critical industrial processes, then real-time data acquisition and control are achieved, but the system cannot meet high availability and reliability requirements for large-scale critical processes

Engineering Contradiction:
Improvesystem reliabilityVSAvoidcapacity to manage large volumes of data and commands
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system is divided into multiple independent control modules, each capable of handling specific data processing tasks. This segmentation allows the system to scale horizontally by adding more modules, thereby increasing capacity to manage large volumes of data and commands while maintaining reliability through modular redundancy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary layer is introduced between the data acquisition layer and the control layer, providing buffering, filtering, and preprocessing capabilities. This intermediary architecture enables the system to handle large data volumes efficiently while maintaining real-time control responsiveness and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional safety systems like SPDS are added to ensure safety, then safety requirements are met, but the system complexity increases and additional hardware is required

Engineering Contradiction:
Improvesafety requirements complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Safety functions are merged into the existing control architecture rather than being implemented as separate additional systems. The control modules incorporate built-in safety mechanisms, redundancy management, and fault tolerance capabilities, eliminating the need for separate SPDS systems and reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The control system performs self-diagnosis, self-monitoring, and automatic fault isolation. Each control module includes embedded safety checks and redundancy management that automatically detect and respond to failures without requiring external safety systems, thereby meeting safety requirements while minimizing complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If high-level safety systems with limited monitoring capacity are used, then safety functions are provided, but they cannot manage large volumes of information required for critical industrial processes

Engineering Contradiction:
Improvesafety function provisionVSAvoidmonitoring capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The monitoring capacity is segmented across multiple distributed control modules, each capable of independently processing and monitoring large volumes of data. This distributed architecture provides both the safety functions and the extensive monitoring capacity needed for critical industrial processes by combining the capabilities of multiple modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control modules are designed with multi-functional capabilities, simultaneously providing safety monitoring, data acquisition, processing, and control functions. This universal design eliminates the limitation of specialized safety systems with restricted monitoring capacity by making each module capable of handling diverse and large volumes of information.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If redundant systems are implemented to ensure high availability, then system reliability improves, but data duplication and processing overhead increase

Engineering Contradiction:
Improvehigh availabilityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Redundant control modules are pre-configured and stand by in a prepared state, requiring minimal activation overhead when primary modules fail. This preliminary preparation of redundant systems ensures high availability while minimizing the processing overhead associated with activating redundancy only when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements intelligent feedback mechanisms that monitor the health and performance of control modules in real-time, dynamically adjusting the activation and deactivation of redundant resources. This feedback-driven resource management maintains high availability while optimizing processing overhead by activating redundancy only when actually required.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4449208B1System for performing and assisting with performance of a critical industrial process and associated method
Publication Date: 2026.02.04 WORLDGRID FRANCE SAS
  • EP4449208B1 patent drawingFigure 1~2
  • EP4449208B1 patent drawingFigure 3~4
  • EP4449208B1 patent drawingFigure 5~6

AI summary

One aspect of the invention relates to a high-availability system, comprising: - a plurality of information-displaying operator stations; - a first sub-system for performing an industrial process that operates cyclically, this first sub-system comprising: - an interface module configured to collect data items each associated with one acquisition time, operating with asynchronous redundancy; - a first processing module configured to sort the received data depending on their acquisition times and to compute first information items, operating with active redundancy; - a first module for managing operator stations, which is configured to send each first information item to the operator stations; - a first duplicated communication network configured to manage exchanges in the first sub-system; - a second sub-system for assisting with performance, comprising: - a second processing module configured to compute second information items from the data items and from the first information items, operating with active redundancy; - a second module for managing operating stations, which is configured to send each second information item to the operator stations; - a second duplicated communication network configured to manage exchanges in the second sub-system; - a separating device configured to manage exchanges between the first sub-system and the second sub-system.