EP0478291A2

Method for enacting failover of a 1:1 redundant pair of slave processors.

Abstract

A primary slave IOP, upon detecting an error, verifies the availability of a secondary slave IOP, then requests backup and takes itself out of being the primary. A secondary slave IOP assumes the role of the primary slave IOP. A master controller, detecting an error with the primary slave IOP, interrogates the primary and secondary slave IOPs for a status input, and then arbitrates between the first and second IOP to determine the IOP that is to take on the primary role. Finally the master controller awards the more operational IOP the role of the primary slave IOP, thereby completing the failover operation. A primary slave IOP which fails sets the output control signal as part of its failure handling and watchdog timeout function. The output control signal is also set to indicate backup for an unpowered IOP.

EP0478291A2, drawing sheet 1
Sheet 1 of 13

Term

Term ended

Projected expiry passed 25 September 2011, 15 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

18 claims: 8 independent, 10 dependent

  1. 1
    A method of operating a process control system having a master controller operatively connected to a communication link, and at least one pair of slave input/output processors (IOPs), each IOP being operatively connected to the communication link, wherein a first IOP of the pair is a primary slave IOP and a second IOP of the pair is a secondary slave IOP, the first and second IOP having a first and second data base, respectively, the first and second IOP each executing the same tasks utilizing a first and second clocking system, respectively, and further wherein the data bases of the first and second IOPs are synchronized, communications by the master controller being made only to the first IOP including communications which modify the first data base, the first and second IOPs being unable to communicate with each other, and further wherein the first and second IOPs are each operatively connected to an output switching device such that control of said output switch device is coordinated between said first and second IOP, and wherein each of said first and second IOP can sense a state of an output control signal from the other IOP to said output switching device, the method characterized by accomplishing a failover, comprising the steps of:the primary slave IOP - a) upon detecting an error, verifying the availability of a secondary slave IOP;b) setting the output control signal to indicate backup is being requested;c) taking itself out of being the primary slave IOP;the secondary slave IOP - d) sensing that the output control signal from the other IOP of the pair of IOPs has been set indicating that the primary slave IOP has detected a failure;e) assuming the role of the primary slave IOP;the master controller - f) detecting an error with the primary slave IOP;g) interrogating the primary and secondary slave IOPs for a status input;h) arbitrating between the first and second IOP to determine the IOP that is to take on the primary role;and i) awarding the more operational IOP the role of the primary slave IOP, thereby completing the failover operation.
  2. 2
    A method according to Claim 1 characterised in the step of verifying comprises:sensing the state of the output control signal of the secondary IOP to said switching device.
  3. 3
    A method according to Claim 1 or 2 characterised in that the step of taking comprises:clearing a flag internal to the IOP which is utilized internally to the IOP to indicate that it is in a primary role.
  4. 10
    A process control system having a master controller operatively connected to a communication link, and at least one pair of slave input/output processors (IOPs), each IOP being operatively connected to the communication link, wherein a first IOP of the pair is a primary slave IOP and a second IOP of the pair is a secondary slave IOP, the first and second IOP having a first and second data base, respectively, the first and second IOP each executing the same tasks utilizing a first and second clocking system, respectively, and further wherein the data bases of the first and second IOPs are synchronized, communications by the master controller being made only to the first IOP including communications which modify the first data base, the first and second IOPs being unable to communicate with each other, and further wherein the first and second IOPs are each operatively connected to an output switching device such that control of said output switch device is coordinated between said first and second IOP, and wherein each of said first and second IOP can sense a state of an output control signal from the other IOP to said output switching device, the system characterised by means for accomplishing a failover, wherein the primary slave IOP comprises a) upon detecting an error, means to verify the availability of a secondary slave IOP;b) means to set the output control signal to indicate backup is being requested;c) means to take itself out of being the primary slave IOP;and the secondary slave IOP comprises d) means to sense that the output control signal from the other IOP of the pair of IOPs has been set indicating that the primary slave IOP has detected a failure;e) means to assume the role of the primary slave IOP;the master controller comprises f) means to detect an error with the primary slave IOP;g) means to interrogate the primary and secondary slave IOPs for a status input;h) means to arbitrate between the first and second IOP to determine the IOP that is to take on the primary role;and i) means to award the more operational IOP the role of the primary slave IOP, thereby completing the failover operation.
  5. 11
    A system according to Claim 10, characterised by means, in the step of verifying, to sense the state of the output control signal of the secondary IOP to said switching device.
  6. 12
    A system according to Claim 10 or 11 characterised by means, in the step of taking, to clear a flag internal to the IOP which is utilized internally to the IOP to indicate that it is in a primary role.
  7. 13
    A system according to any of 10 to 12 characterised by means, in the step of clearing, to clear a flag internal to the IOP which is utilized internally to the IOP to indicate that it is in a primary role, the flag including the value of the logical address assigned by the master controller to the IOP.
  8. 14
    A system according to any of Claims 10 to 13 characterised by means, in the step of assuming, to set a flag internal to the secondary slave IOP to indicate to the master controller that the secondary slave IOP is operational and is ready to accept the role of primary slave IOP in the failover operation.
  9. 15
    A system according to any of Claims 10 to 14, characterised by means, in the step of detecting, to a) send a message to the primary slave IOP;and b) monitor for no acknowledgement response received within a predetermined time.
  10. 16
    A system according to any of Claims 10 to 15, characterised by means, in the step of sending a message to the primary address, to address the primary slave IOP by logical address.
  11. 17
    A system according to any of Claims 10 to 16, characterised by means, in the step of interrogating the primary and secondary slave IOP, to transmit a message requesting status information addressing each IOP by physical address.
  12. 18
    A system according to any of Claims 10 to 17 characterised by means, in the step of awarding, to send a message to the selected IOP from step (h) which is to be given the primary role, the message including the logical address chosen by the master controller, the logical address being partially utilized as the primary flag by the IOP.