Shared Redundant Controllers for Fault-Tolerant Process Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional redundant industrial control systems require dedicated backup controllers, leading to inefficiencies and potential loss of process control if both primary and backup controllers fail, necessitating the need for a more flexible redundancy scheme.

Innovation Solution

Implementing an M:N redundancy scheme where any active process controller can serve as a backup for another, eliminating the need for explicit dedicated backup hardware and enabling flexible workload assignment through an I/O mesh network, allowing controllers to share resources and maintain process control even with multiple faults.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated backup controllers are deployed in traditional 1:1 redundancy systems, then controller availability is improved, but hardware cost and system complexity increase

Engineering Contradiction:
Improvecontroller availabilityVSAvoidhardware configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each process controller is configured with dual functionality: it serves as both a primary controller for its own control mission and as a backup controller for another process controller. This multi-functionality eliminates the need for dedicated backup hardware, reducing system complexity while maintaining availability through software-based role assignment and dynamic failover capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated backup controllers are deployed in traditional 1:1 redundancy systems, then controller availability is improved, but hardware cost increases

Engineering Contradiction:
Improvecontroller availabilityVSAvoidhardware resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The backup controller function is merged into the existing process controller infrastructure. Each controller platform performs both primary control operations and backup monitoring/synchronization functions, consolidating hardware resources and eliminating the need for separate dedicated backup controller units, thereby reducing overall hardware cost while maintaining redundancy

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If M:N redundancy scheme is implemented with shared I/O mesh network, then adaptability is improved, but network complexity increases

Engineering Contradiction:
Improveworkload assignment flexibilityVSAvoidnetwork configuration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The I/O mesh network is configured to automatically enable any process controller to access and control any field I/O devices without requiring dedicated I/O assignments or manual reconfiguration. This self-service capability provides dynamic workload assignment flexibility where controllers can assume backup roles and access required I/O resources autonomously, improving adaptability while the standardized mesh topology keeps network complexity manageable

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3715970B1Redundant controllers or input-output gateways without dedicated hardware
Publication Date: 2024.05.01 HONEYWELL INTERNATIONAL INC
  • EP3715970B1 patent drawingFigure 1
  • EP3715970B1 patent drawingFigure 2
  • EP3715970B1 patent drawingFigure 3

AI summary

A method of fault-tolerant process control includes providing a network process control system (600) in an industrial processing facility (IPF) including a plant-wide network (170) coupling a server (180) to computing platforms (621-624) each including computing hardware (171) and memory (172) hosting at least one software application for simultaneously supporting at least one process controller and another process controller or an input/output (I/O) gateway. The computing platforms are coupled to one another by a private path redundancy network (260) for providing a hardware resource pool. At least some of the computing platforms are directly coupled by an I/O mesh network (240) to plurality of I/O devices (145) to field devices (150) that are coupled to processing equipment (160). Upon detecting at least one failing device in the hardware resource pool, over the private path redundancy network a backup is placed into service for the failing device from another device at another of the computing platforms in the hardware resource pool.