Operator Station Server Health Index for Stable Redundancy Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing health index calculations for operator station servers in redundant systems fail to account for the duration and severity of alarms, leading to unnecessary redundancy switching and operational interruptions due to sporadic errors, which cannot be diagnosed or rectified effectively.

Innovation Solution

An operator station server calculates a health index based on the duration and severity of generated alarms, considering a specific observation period, to determine the most reliable server for active status and prevent unnecessary switching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If health index is calculated based only on alarm severity without considering duration, then calculation simplicity is maintained, but unnecessary redundancy switching occurs due to sporadic errors

Engineering Contradiction:
Improvehealth index calculation complexityVSAvoidredundancy switching stability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent changes the parameters of health index calculation by introducing alarm duration as an additional factor alongside alarm severity. The health index is calculated as the sum of severity levels multiplied by their respective durations within an observation period, transforming the calculation from a simple severity count to a time-weighted severity assessment that prevents unnecessary switching due to transient alarms

Inventive Principle:
Principle #35Parameter changes

2Reliability

If redundancy switchover is initiated quickly upon fault detection, then system availability is improved, but operational interruptions occur during switchover period

Engineering Contradiction:
Improvesystem availabilityVSAvoidoperational interruption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by continuously monitoring and calculating the health index of both active and passive operator station servers in advance. This allows the system to proactively identify and switch to a healthier server before faults fully manifest, reducing unplanned interruptions and enabling smoother transitions by having pre-evaluated standby options ready

Inventive Principle:
Principle #10Preliminary action

3Reliability

If operator station clients re-register on other servers frequently, then connection to healthy server is maintained, but operational stability deteriorates

Engineering Contradiction:
Improveconnection to healthy serverVSAvoidoperational stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent implements feedback mechanisms where operator station clients continuously monitor the health indices of available servers and dynamically adjust their connections based on real-time health status. The health index feedback prevents clients from connecting to deteriorating servers and enables intelligent load balancing and failover decisions that maintain both connectivity to healthy servers and operational stability

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4641333A1Reliability indicators for operator station server
Publication Date: 2025.10.29 SIEMENS AG
  • EP4641333A1 patent drawingFigure 1~2
  • EP4641333A1 patent drawingFigure 3~4
  • EP4641333A1 patent drawingFigure 5

AI summary

The invention relates to an operator station server (OS 1.1, OS 1.2) for a control system (1) of a technical plant, in particular a manufacturing or process plant, which is configured for operating and monitoring the technical plant, on which at least one software component is implemented, wherein the at least one software component is configured to generate an alarm of a certain severity for the duration of an error occurring in the software component. The operator station server (OS 1.1, OS 1.2) is characterized in that it is configured to calculate a health index with respect to itself, which depends on the duration and severity of the generated alarm, and to transmit this health index to components of the control system (1) connected to the operator station server (OS 1.1, OS 1.2).