Dual redundant process controller
Abstract
This record has no abstract on file.
Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
11 claims: 6 independent, 5 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A dual redundant process controller (109) comprising:a first processor (102a);first memory (122a);1. Podwójny nadmiarowy sterownik (109) procesu zawierający: pierwszy procesor (102a);pierwszą pamięć (122a);first instance of multi-task real-time operating system (RTOS);pierwsza instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym (RTOS);pierwszą instancję aplikacji sterującej procesem zapisaną w pierwszej pamięci;drugi procesor (102b);drugą pamięć (122b);the first instance of the process control application saved in the first memory;a second processor (102b);a second memory (122b);a second instance of the multi-task operating system in real time;and a second instance of the process control application stored in the second memory (122b), wherein, after being executed by the first processor (102a) in the context provided by the first instance of the multi-task operating system in real time, the first instance of the process control application: drugą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym;i drugą instancję aplikacji sterującej procesem zapisaną w drugiej pamięci (122b), przy czym, po wykonaniu przez pierwszy procesor (102a) w kontekście zapewnionym przez pierwszą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym, pierwsza instancja aplikacji sterują cej procesem: saves the first synchronization information in the second memory (122b) using the synchronization function provided by the first instance of the multi-task operating system in real time, reads the second synchronization information from the first memory (122a), performs the resynchronization function when the second synchronization information does not match the first information synchronization after a specified time past due, and calls the synchronization function provided by the first instance of the multitasking operating system in real time before calling the specified event function provided by the first instance of the multitasking operating system in real time, and wherein, after the second processor (102b) has executed, the second instance of the process control application: zapisuje pierwszą informację synchronizacyjną w drugiej pamięci (122b) za pomocą funkcji synchronizacji zapewnionej przez pierwszą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym, odczytuje drugą informację synchronizacyjną z pierwszej pamięci (122a), przeprowadza funkcję resynchronizacji, gdy druga informacja synchronizacyjna nie zgadza się z pierwszą informacją synchronizacyjną po upływie określonego czasu przeterminowania, i wywołuje funkcję synchronizacji zapewnioną przez pierwszą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym przed wywołaniem określonej funkcji zdarzeń zapewnionej przez pierwszą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym, i przy czym, po wykonaniu przez drugi procesor (102b), druga instancja aplikacji sterującej procesem: writes the second synchronization information to the first memory (122a) using the synchronization function provided by the second instance of the multi-task operating system in real time, reads the first synchronization information from the second memory (122b), and zapisuje drugą informację synchronizacyjną w pierwszej pamięci (122a) za pomocą funkcji synchronizacji zapewnionej przez drugą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym, odczytuje pierwszą informację synchronizacyjną z drugiej pamięci (122b), i -26przeprowadza funkcję resynchronizacji, gdy pierwsza informacja synchronizacyjna nie zgadza się z drugą informacją synchronizacyjną po upływie wcześniej określonego czasu przeterminowania, znamienny tym, że pierwsza informacja synchronizacyjna zawiera jedną spośród wielu wartości stanów zapewniających wskazanie, które instrukcje aplikacji sterującej procesem pierwszy procesor (102a) ostatnio wykonał, a druga informacja synchronizacyjna zawiera jedną spośród wielu wartości stanów zapewniających wskazanie, które instrukcje aplikacji sterującej procesem drugi procesor (102b) ostatnio wykonał. Performs resynchronization function when the first synchronization information does not match the second synchronization information after a predetermined time period has elapsed, characterized in that the first synchronization information contains one of many state values providing an indication which instructions of the first processor control application (102a) last made, and the second synchronization information includes one of a plurality of state values that provide an indication of which process instructions of the process control application the second processor has recently performed.
- 3The dual redundant process controller (109) according to any one of the preceding claims, wherein the process control application includes a state sequencer, wherein the first instance of the process control application implements the first state sequencer that tracks the implementation status of the first instance of the process control application, and wherein the second instance of the application process control implements the second state sequencer, which tracks the implementation status of the second instance of the process control application. 3. Podwójny nadmiarowy sterownik (109) procesu według któregokolwiek z poprzednich zastrzeżeń, w którym aplikacja sterująca procesem zawiera sekwenser stanów, przy czym pierwsza instancja aplikacji sterowania procesem realizuje pierwszy sekwenser stanów, który śledzi stan realizacji pierwszej instancji aplikacji sterującej procesem, i przy czym druga instancja aplikacji sterującej procesem realizuje drugi sekwenser stanów, który śledzi stan realizacji drugiej instancji aplikacji sterowania procesem.
- 5The dual redundant process controller (109) according to any one of the preceding claims, wherein the synchronization function provided by the first instance of the multi-task operating system promotes the synchronization of clock cycles generated by the first instance of the multi-task operating system in real time. 5. Podwójny nadmiarowy sterownik (109) procesu według któregokolwiek z poprzednich zastrzeżeń, w którym funkcja synchronizacji zapewniona przez pierwszą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym promuje synchronizację taktów zegara wygenerowanych przez pierwszą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym.
- 7The dual redundant process controller (109) of any one of the preceding claims, further comprising an HDLC type communication controller (128a) coupled to the first processor (102a), the first instance of the multi-task operating system in real time further:7. Podwójny nadmiarowy sterownik (109) procesu według któregokolwiek z poprzednich zastrzeżeń, zawierający ponadto sterownik komunikacyjny (128a) typu HDLC sprzężony z pierwszym procesorem (102a), przy czym pierwsza instancja wielozadaniowego systemu operacyjnego w czasie rzeczywistym ponadto: creates the first message containing the first payload and the first cyclic redundancy check (CRC), and sends the first message to the HDLC communication controller, and wherein the HDLC communication controller (128a) is configured to: tworzy pierwszy komunikat zawierający pierwszy ładunek użyteczny i pierwszą cykliczną kontrolę nadmiarowości (CRC), i przesyła pierwszy komunikat do sterownika komunikacyjnego typu HDLC, i przy czym sterownik komunikacyjny (128a) typu HDLC jest skonfigurowany do: odbierania pierwszego komunikatu, przesyłania pierwszego komunikatu do urządzenia polowego, odbierania pierwszego przesłanego komunikatu, obliczania drugiej cyklicznej kontroli nadmiarowości w oparciu o odebranie pierwszego przesłanego komunikatu, i przesyłania komunikatu o błędzie do pierwszego procesora (102a), gdy druga cykliczna kontrola nadmiarowości będzie się różniła od pierwszej cyklicznej kontroli nadmiarowości. receiving the first message, sending the first message to the field device, receiving the first message sent, calculating the second cyclic redundancy check based on receiving the first message sent, and sending the error message to the first processor (102a) when the second cyclic redundancy check differs from first cyclic redundancy check.
- 8The dual redundant process controller (109) according to any one of the preceding claims, wherein, after the first processor (102a) has executed in the context provided by the first instance of the multi-task operating system in real time, the first instance of the process control application:8. Podwójny nadmiarowy sterownik (109) procesu według któregokolwiek z poprzednich zastrzeżeń, w którym, po wykonaniu przez pierwszy procesor (102a) w kontekście zapewnionym przez pierwszą instancję wielozadaniowego systemu operacyjnego w czasie rzeczywistym, pierwsza instancja aplikacji sterującej procesem: saves the second synchronization information in the second memory (122b) using the synchronization function provided by the multi-task operating system in real time, reads the third synchronization information from the first memory (122a), and performs the resynchronization function when the third synchronization information does not match the second synchronization information after the specified expiry time. zapisuje drugą informację synchronizacyjną w drugiej pamięci (122b) za pomocą funkcji synchronizacji zapewnionej przez wielozadaniowy system operacyjny w czasie rzeczywistym, odczytuje trzecią informację synchronizacyjną z pierwszej pamięci (122a), i przeprowadza funkcję resynchronizacji, gdy trzecia informacja synchronizacyjna nie zgadza się z drugą informacją synchronizacyjną po upływie określonego czasu przeterminowania.
- 11The dual redundant process controller (109) according to any one of the preceding claims, wherein the first synchronization information is stored in the second memory (122b) via an Ethernet link from the first processor (102a) to the second processor (102b). 11. Podwójny nadmiarowy sterownik (109) procesu według któregokolwiek z poprzednich zastrzeżeń, w którym pierwsza informacja synchronizacyjna zapisywana jest w drugiej pamięci (122b) za pośrednictwem łącza Ethernet z pierwszego procesora (102a) do drugiego procesora (102b). Prepared and verified Sporządziła i zweryfikowała Anna Stenzel Anna Stenzel Patent Attorney Rzecznik patentowy -29J lQ? B "T^ ......... Ί Ί -29J lQ?b ”T^.........Ί Ί 1D2ii 1D2ii HC4U prCCMM · HC4U prCCMM· Γ.1 :cul fK-eecłB Γ.1: cul fK-eecłB 119S ii «& 119S ii«& 113b 113b CPU CPU .. RLJ ... RLJ 1203 120b 1203 120b Jeef [- * Jeąfr [- * -NG> -ng> and? 2a-8Γ izL i?2a-8Γ izL Kiriiac Kiriiac 174-b J? 4r = -.-. 1 and? Ba1? 6b 174-ł J?4r =-.-.1 i?Ba1?6b And F'fW I F'fW 178 b 178 b L'ie ·: in · L’ie· : w · ILjCJ "Jut, ILjCJ "Jut, Łfł-n Ę E Łfł-n Ę E 1Κ.Ί 1Κ.Ί · Łdyl » Łdyl·» OA i06b OA i06b JrZ * S ™ W "LJ DC-CWt JrZ*S™W"L J DC-CWt FIG. 1 FIG. 1 Komctrtit 'ncs Komctrtit' ncs -31Komet -31Komet FIG. 3 FIG. 3 Υ-ΐ Υ-ΐ Face of the second ohwmiJ & seHC message! second payload and cyclical date kruTIrale radrriarDwsrta by the second prosecutor of the double r and th Twarzene drugega komunikatu ohwmiJ&seHC! drugi ładunek użyteczny i dnin cykliczna kruTIrale radrriarDwsrta przez drugi prosesor pa dwoi nego ri ud miarowe ho slerownifca procesu 206 206 -e * ON pftMBtr: κχϋι * ηι.κ ae ^ wŁta u / l · n ^ -a «art-cnc naa-na-uwAti with i-LjqJ tyfciiLćl a ksrrlroli -sdn a-cii / ri 21 -e*WŁ£y pftMBtr :κχϋι*ηι.κ ae^wŁta u/l· n^-a «art-cnc naa-na-uwAti z i-LjqJ tyfciiLćl a ksrrlroli -sdn a-cii/ri 21 20C 20C 202 202 The face is full of eccentricity and longevity, and is a cyclical partner for the first time through the first work of the undermined redundant process Twarzene pnenYszegc-kcirriurikaluobeniuEKega perwnzy radunek użylecizny i perń-tza cyklczna toartrote nednnarowoKi przez pierwszy pracesar podwainego nadmiarowego sierawnka procesu X J π-πγμ<, pmner pj«łvU i. i iun j1 XJ π-πγμ <, pmner pj«ŁvU i. Iun j1 212 ^ GinecjcLm daancłlpk 212 ^GinecjcLm daancłlpk -32Kari te -32Kari te FIG, 4 FIG, 4 256 256 ΊΖΓΓΗΊ1Ζ3Ζ | 3 2 "ΙΓ7ΓΠ ΠΚΚ ΙΙΜΓΠ prOQt! 5DTL ·. ΊΖΓΓΗΊ1Ζ3Ζ|3 2 "ΙΓ7ΓΠ ΠΚΚ ΙΙΜΓΠ prOQt!5DTL·. 25β 25β Ochrona p'£eu .cdrtacznnym dostępem ud q'Lpv zmrzen Protect p'£ eu. With access by thighs q'Lpv space 260 260 AkLia izacja uiEzaeyr" *aq zdarzeń w q-Lpie jcarzun AkLia ization uiEzaeyr "* aq events in q-Lpie jcarzun 250 250 252 252 Przsłaczene do liybu nadzoru Screening for supervision 254 254 PtzeuuΊΚ fłwazr ka weiszoweno gruby zcarzen ud «rcfcaznka wewne.znega PtzeuuΊΚ vaginal fold thick thigh root thigh internal rnfcaznka.
Independent claims6
123 paragraphs, as filed
[0001] Process control systems can be implemented to automatically control industrial processes based on pre-defined logic circuits and / or rules. Industrial processes can be implemented with the help of engines, valves, heaters, pumps and the like, which may be called process devices or field devices in production plants, refineries, food factories and other plants. Process control systems can monitor the parameters and / or properties of ongoing processes by receiving signals generated by process-related sensors, e.g. temperature sensors, pressure sensors, motion sensors, weight sensors, density sensors, flow sensors and other sensors. Automated control devices, e.g. controllers, can regulate and control process devices based on detected parameters and properties based on pre-defined logic circuits and / or commands received, e.g. from an interface.
[0002] Current methodologies used in redundant control systems often use triple modular redundancy (TMR) with voting on all interfaces and / or various types of Hot Swap methods in which the active module controls all processes and the standby module is ready to take over tasks in the event of any fault. TMR approaches usually allow all three branches of the controller to participate in a voted change at the end stations, each of which has an equal vote, and the prevalence of 2 out of 3 votes means that the selection is made. TMR can verify votes at the system endpoints. This may involve the need to triple some components in the controller, which translates into increased costs, and personalized voting at the endpoints increases the complexity of the endpoint. Hot Swap methods rely on active auto-diagnostics of the device, which allows you to detect a fault and allows shutdown to allow the armed module to start working. Hot Swap methods can introduce incorrect values into processes until diagnostics detect a faulty active module, which is then turned off and the armed module starts.
[0003] Other current systems may use a dual-active approach that does not require endpoint voting. For example, two control modules can perform the same sequence of operations and generate the same settings and / or process commands. Settings and / or commands generated by two control modules can be verified as compatible by means of a communication device before being forwarded to other devices, e.g. to controlled process devices. In an embodiment, this approach may necessitate the use of devices for state synchronization, clock synchronization and message content comparison.
[0004] Current systems as well as those described in this document can be implemented in a processor that is part of a computer. Those skilled in the art will recognize that computers and computer systems may have different shapes, sizes and implementations. At the same time, computers and / or computer systems may contain common elements and have common optional elements. For example, a computer system may include a processor (which is called a central processing unit or CPU) that is connected to memory devices including auxiliary memory, read only memory (ROM), and operational memory (random access memory, RAM), input / output devices (I / O) and network communication devices. The processor can be implemented in the form of one or more CPU chips.
[0005] It is understood that by programming and / or loading executable instructions into a computer system, there is a change in at least in the CPU, RAM and ROM, partially transforming the computer system into a particular type of machine or device having the new functions described in the disclosure. The fundamental issue of electrical and IT engineering sciences is that the function that can be implemented by introducing executable software into a computer can be transformed into hardware implementation on the basis of well-known design rules. Decisions about whether to introduce a concept in the sphere of software or devices depend mainly on the conditions of project stability and the number of units that need to be carried out, not on the issues of translating the program domain into hardware. In general, a project that will be subject to frequent changes is better implemented in software, because the implementation of the device is more expensive than rewriting the software design. In general, a project that is stable and will be produced in large quantities is better to implement in hardware, for example an ASIC (application specific integrated circuit), because for large production batches, hardware implementation can prove to be less expensive than programmatic. Often, projects can be developed and tested in software form, and then, using well-known design rules, converted to an ASIC hardware equivalent that takes into account program instructions. Just as in the case where the machine controlled by the new ASIC is a special machine or device, so can a computer that has been programmed and / or to which possible instructions have been entered can be seen as a specific machine or device.
[0006] Auxiliary memory typically includes one or more drives in the form of disks or tapes and is used as a non-volatile memory and as an additional storage device if the RAM is not large enough to contain all operating data. The auxiliary memory can be used to store programs that are loaded into RAM, when selected, for execution. The ROM stores instructions and possibly data that is read during program execution. ROM is a non-volatile memory device that usually has a small capacity relative to the larger capacity of the auxiliary memory. RAM is used to store non-persistent data and possibly instructions. Access to both ROM and RAM is usually provided
-3 faster than to auxiliary memory. Auxiliary memories, RAM and / or ROM may sometimes be referred to as computer storage media and / or permanent computer storage media.
[0007] I / O devices may include printers, video monitors, liquid crystal displays (LCDs), touch screens, keyboards, switches, knobs, mice, track ball devices, voice recognition devices, card readers, paper tape readers and other well known input devices.
[0008] Internet communication devices can be in the form of modems, modem banks, Ethernet cards, USB cards (universal serial bus), serial interfaces, token ring cards, FDDI cards (fiber distributed data interface, interface) fiber optic data transmission), WLAN cards (wireless local area network), radio cards such as CDMA ( code division multiple access, GSM system (Global System for Mobile Communications), LTE (long-term evolution), WiMAX (worldwide interoperability for microwave access, Global Interoperability for Microwave Access) and / or other wireless transceivers and other known network devices. These network devices allow the processor to communicate with the Internet and one or more intranets. In the case of a network connection, it is believed that the processor may receive information from the network or may send information to the network during the implementation of the method steps described above. Such information, which is often in the form of a sequence of instructions implemented by the processor, can be received from and sent to the network, for example in the form of a computer data signal contained in a carrier wave.
[0009] Such information, which for example may include data or instructions implemented by the processor, may be received from and sent to the network, for example in the form of a computer data signal in the baseband or a signal contained in a carrier wave. A signal in the baseband or a signal contained in a carrier wave generated by network communication devices may propagate in or on the surface of electrical conductors in coaxial cables, waveguides, optical cables, for example optical fibers or in free space. The information contained in a baseband signal or a signal embedded in a carrier wave can be arranged in different orders depending on whether it is necessary to process or generate information or to send or receive information. A baseband signal or a signal embedded in a carrier wave, or other types of signals that are currently used or will be developed in the future, may be generated according to various methods well known to those skilled in the art. A baseband signal and / or a signal embedded in a carrier wave may sometimes be called a transition signal.
[0010] The processor carries out instructions, codes, computer programs, scripts, which it accesses from a hard disk, floppy disks, optical disk (such disk systems can generally be called auxiliary memory), ROM, RAM or network communication devices. Although only one processor is shown, many may be present
-4nich. Thus, while instructions may be discussed as being implemented by a processor, the instructions may be executed simultaneously, in series, or otherwise by one or more processors. Instructions, codes, computer programs, scripts and / or data on auxiliary memory, such as hard disks, floppy disks, optical disks, and / or other devices, ROMs, and / or RAMs may sometimes be called persistent instructions and / or persistent information .
[0011] In an embodiment, the computer system may include two or more computers connected to each other that cooperate to perform a task. For example, but not for limitation, an application may be split to allow concurrent and / or parallel processing of application instructions. Alternatively, the application's data processing may be split to allow concurrent and / or parallel processing of different parts of the data set by two or more computers. In an embodiment, the computer may use virtualization software to provide the functionality of several servers that are not directly connected to computers in the computer system. For example, virtualization software can provide twenty virtual servers on four physical computers. In an embodiment, the above disclosed functionality may be provided by executing an application and / or applications in a cloud computing environment. Cloud computing can include providing computing services over a network connection using dynamically scalable computing resources. Cloud computing can be supported, at least in part, by virtualization programs. The cloud computing environment can be prepared by the company and / or rented when needed from an external supplier. Some cloud computing environments may include computing resources owned and operated by the company as well as computing resources rented and / or leased from an external provider.
[0012] In an embodiment, some or all of the functionalities disclosed above may be provided in the form of a computer program product. The computer program product may include one or more storage media having the program code used by the computer to implement the functionality disclosed above. A computer program product may include data structures, executable instructions, and other program codes used by the computer. The computer program product may be placed on removable storage media and / or non-removable storage media. Removable storage media may include, but are not limited to, paper tape, magnetic tape, magnetic disk, optical disk, semiconductor memory, e.g., analog magnetic tape, readable compact discs (CD-ROMs), USB sticks, digital cards, multimedia cards and other. The computer program product may allow at least a portion of the content of the computer program product to be inserted into the add-on memory, ROM, RAM and / or other non-volatile memory of the computer system using a computer system. The processor can process executable instructions and / or data structures directly by gaining access to a computer program product on
-5 example reading from a CD-ROM inserted into the external disk drive of a computer system. Alternatively, the processor can process executable instructions and / or data structures by gaining remote access to a computer program product, e.g., downloading executable instructions and / or data structures from remote servers through network connectivity devices. A computer program product may include instructions that promote the introduction and / or copying of data, data structures, files, and / or executable instructions to additional memory, to ROM, RAM, and / or other types of non-volatile memory of the computer system.
[0013] In some cases, a baseband signal and / or a signal embedded in a carrier wave may be called a transient signal. In some cases, the auxiliary memory, ROM, and RAM may be called permanent computer storage media or computer storage media. An example of dynamic RAM implementation may also be called a permanent computer storage medium in that dynamic RAM consumes electrical power and works according to its construction, for example, while the computer is turned on and running, dynamic RAM stores information that is saved with it. Similarly, the processor may contain internal RAM, internal ROM, cache memory and / or other internal blocks, sections or elements of non-volatile memory, which may sometimes be called permanent computer storage media or computer storage media.
[0014] EP 1 426 862 A2 relates to synchronization of data processing in the processing elements of a redundant data processing system.
[0015] EP 1 283 468 A2 discloses an apparatus according to the introduction to claim 1.
[0016] The object of the invention is to improve synchronization between dual redundant processors implementing a common process control application.
[0017] The object of the invention is achieved thanks to a double redundant process controller according to the features of the independent claims. Preferred embodiments are disclosed in the dependent claims.
SUMMARY [0018] In the embodiment, a dual redundant process controller is disclosed. The process controller includes a first processor, a first memory, and a first instance of the process control application stored in the first memory. The process controller further includes a second processor, a second memory, and a second instance of the process control application stored in the second memory. After the first processor executes, the first instance of the process control application writes the first synchronization information to the second memory, reads the second synchronization information from the first memory, and if the second synchronization information does not match the first synchronization information after a predetermined amount of time, it performs the resynchronization function. After the second processor executes, the second instance of the process control application writes the second synchronization information in the first memory, reads the first synchronization information from the second memory and if the first
-6 synchronization information does not match the second synchronization information after a specified amount of time has elapsed, it performs the resynchronization function.
[0019] In a non-claimed embodiment, a method of transmitting data messages is disclosed. The method includes creating a first payload and first cyclic redundancy check (CRC) by the first dual redundant process controller processor and creating a second payload and second cyclic redundancy check by the second dual redundant process controller. The method further includes comparing the first cyclic redundancy check with the second cyclic redundancy check by the first processor, and when the first cyclic redundancy check and the second cyclic redundancy check match, sending a data message containing the first payload and the first cyclic redundancy check.
[0020] In an embodiment, a process controller is disclosed. The process controller contains the first module. The first module contains the first processor implementing a multi-task operating system in real time and an HDLC (high-level data link control) communication driver coupled with the first processor. The first processor creates the first message including the first payload and the first cyclic redundancy check (CRC) and sends the first message to the HDLC communication controller. The HDLC communication driver receives the first message, sends the first message to the field device ( field device), calculates the second cyclic redundancy check based on the message, and when the second cyclic redundancy check differs from the first cyclic redundancy check, it sends an error message to the first processor.
[0021] In an embodiment, a dual redundant process controller is disclosed. The controller includes a first processor, a first memory, a first instance of a real-time operating system (RTOS), and a first instance of a process control application stored in the first memory. The controller further includes a second processor, a second memory, a second instance of the multi-task operating system in real time, and a second instance of the process control application stored in the second memory. After the first processor executes in the context provided by the first instance of the multi-task operating system in real time, the first instance of the process control application saves the first synchronization information in the second memory using the synchronization function provided by the first instance of the multi-task operating system in real time, reads the second synchronization information from first memory, performs the synchronization function, when the second synchronization information does not match the first synchronization information after a predetermined amount of time has elapsed and calls the synchronization function provided by the first instance of the multi-task operating system in real time before calling the fixed event function provided by the first instance of the multi-task operating system in real time. After executed by the second processor, the second instance of the control application
Process records the second synchronization information in the first memory using the synchronization function provided by the second instance of the multi-task operating system in real time, reads the first synchronization information from the second memory and performs the resynchronization function when the first synchronization information does not match the second synchronization information after expiration a certain amount of time is characterized by that the first synchronization information includes one of a plurality of state values providing an indication of what process control application instruction the first processor has performed and the second synchronization information includes one of the many state values providing an indication of what process control application instruction a second processor has implemented (102b).
[0022] In a non-claimed embodiment, a dual redundant process controller is disclosed. The controller includes the first processor, the first memory and the first instance of the process control application stored in the first memory. The controller further includes a second processor, a second memory, and a second instance of the process control application stored in the second memory. After the first processor executes, the first instance of the process control application creates the first payload and the first cyclic redundancy check (CRC), compares the first cyclic redundancy check with the second cyclic redundancy check specified by the second instance of the process control application based on the second payload created by the second an instance of the process control application, which is implemented on the second processor and sends the first payload and the first cyclic redundancy check when the first cyclic redundancy check is compared with the second redundancy check.
[0023] In another non-claimed embodiment, a dual redundant process controller is disclosed. The controller includes a first processor, a first memory, a first instance of a real-time multi-task operating system (RTOS), and a first instance of a process control application stored in the first memory. The controller further includes a second processor, a second memory, a clock, a second instance of the multi-task operating system in real time, and a second instance of the process control application stored in the second memory. After the first processor executes in the context provided by the first instance of the multi-task operating system in real time, the first instance of the process control application saves the first synchronization information indicating the synchronization of clock cycles in the second memory using the synchronization function provided by the first instance of the multi-task operating system in real time. After being executed by the second processor, the second instance of the process control application sets the clock based on the first synchronization information stored in the second memory.
[0024] These and other features will be easier to understand after reading the following detailed description in connection with the accompanying drawings and claims. BRIEF DESCRIPTION OF THE FIGURES
[0025] For a full understanding of the disclosure, reference should be made to the following general description, together with the accompanying drawings and detailed description, in which the same reference numerals refer to the same parts.
[0026] FIG. 1 is a block diagram of a process control system according to an embodiment of the disclosure.
[0027] FIG. 2 is a block diagram of a portion of a processor module according to an embodiment of the disclosure.
[0028] FIG. 3 is a flowchart of an embodiment of the disclosure.
[0029] FIG. 4 is a flowchart of an embodiment of the disclosure.
DETAILED DESCRIPTION [0030] It should be understood that although the following exemplary implementations of one or more embodiments are shown, the disclosed systems and methods can be implemented using any other techniques that are already known or are yet to be developed. The disclosure should not be limited to exemplary embodiments of the drawings and techniques below, but may be modified within the scope of the appended claims and the full scope of their equivalents.
[0031] A dual redundant process controller has been described. In an embodiment, the process controller is suitable for use in a real-time process control environment. The process controller can be used to monitor and control various process devices or field devices such as valves, pumps, motors, heaters and other devices. The process controller can be used in manufacturing plants, refineries, chemical plants, food processing plants and other plants. In the event of a failure, process controllers can cause significant damage. Faulty process controllers can cause injury to factory personnel. Faulty process controllers can damage machines or material. It should also be noted that process controllers receive command signals, receive detected parameter values and / or properties, determine the appropriate control signals and send these control signals at the right time and at the set time.
[0032] The process controller comprises two modules, each suitable for providing process control functions. During operation, the first module acts as a master module that receives sensor signals from process devices, sends control signals to process devices and sends messages to the HMI, workstations and / or automated higher-order control devices in accordance with the control application and / or controlling computer program. The second module acts as a shadow module that receives the same sensor signals from the control devices, determines but does not send control signals to process devices and defines but does not send messages to HMIs, workstations and / or higher-level automated control devices, according to the same control application. The first module and the second module can implement separate instances of the same control application. If a fault occurs or an error occurs in
- first module, it is desirable that such a fault be detected and the second module immediately assumes the role of the main module.
[0033] To support uninterrupted role change in the event of failure, it is further desirable that the first and second modules execute the same instructions in the control application at substantially the same time and follow the same implementation path in the control application, except for the selective instructions that it implements only main module or shadow module. Two modules execute synchronization instructions at specific points in the control application instruction sequence. By implementing synchronization instructions, the first module saves information in a pre-defined memory location associated with the second module, identifying the synchronization status of the first module, and the second module saves information in a previously defined memory location related to the first module, identifying the synchronization status of the second module. If the synchronization status of the sister module does not match the synchronization status of the subject module at a predetermined time, the subject module generates a synchronization error and performs the procedure of restoring to the correct state. If the synchronization states match, each module continues executing control instructions. By entering synchronization instructions in specific places in the code, separate implementation of the same control application by two modules can be synchronized in specific design constraints.
[0034] Each module includes a clock that manages the rate at which the module executes the instruction. In an embodiment, the control application implemented by the module as a shadow determines the time difference between the shadow module and the main module based on the synchronization operation and sets the shadow module clock relative to the main module clock. This clock setting allows you to define the synchronization deadline time to be shorter and helps to reduce the synchronization waiting time, and thus increases the processing efficiency of at least one of the modules.
[0035] By sending information to the HMI, workstations and / or higher-level automated control devices, the main module and the shadow module form a payload of data and calculate cyclic redundancy control (CRC) relative to payload of data. In some cases, the useful payload may be called a message set. The shadow module sends the CRC value it has calculated to the main module. If the CRC value calculated by the shadow module matches the CRC value calculated by the main module, the main module sends to the HMI, workstations and / or higher-order automated control devices a message containing both the payload and the CRC value. If the CRC values do not match, the master module performs the recovery procedure.
[0036] In the embodiment, the main module and the shadow module contain a complex programmable logic device (CPLD) that implements the control application and HDLC controller (high level data link control), which can receive and send messages to control devices, for example, when the subject module performs the role of the main module. The CPLD determines the payload of data and the first CRC on payload of data and sends a payload message
-10 data loading and CRC to HDLC controller. The HDLC controller sends the message to the appropriate control device and simultaneously receives the same message. The HDLC controller calculates the second CRC on the payload data it sent and if the first CRC and the second CRC do not match, the HDLC controller sends the error message to the CPLD. This procedure may lead to the CPLD identifying the error in the message sent to the control device and again, sending the message faster than if the HDLC driver is normally overdue when the controller does not return confirmation to the HDLC controller in due time.
[0037] The disclosure recommends a synchronization function that does not depend on dedicated state hardware-based machines. Instead, a message-based synchronization method is used so that all operations in two separate operating system environments are the same, for example, in modules with two separate processors. Two-processor modules exchange a synchronization step based on a message that can be performed at critical contact points in the Operating System and Application Code using a standard Gigabit Ethernet link between two modules.
[0038] The disclosure further recommends implementing synchronization functionality using software that provides exchange of information about the CRC stack level prior to sending the message, for example sending the message to a higher level control and / or field device. This allows the software to detect differences in process settings without comparing hardware. These CRCs may form an integral part of the common methodology, but in this case they are used to verify the application layer. Disclosure recommends using CRC to check content matching in dual active drivers. Both members in a pair of modules verify the correct context by checking the CRC (which express the content) of other transmissions, which allows generic equipment to obtain the same functionality as dedicated equipment with a comparative logic circuit. The applicability of generic equipment can provide many benefits under certain circumstances, for example promoting more flexible and easy-to-maintain hardware designs and the use of various types of publicly available components and other benefits.
[0039] The disclosure further recommends dynamically adjustable clocks to reduce accumulated time discrepancies. Maintaining synchronization of two modules when the Operating System Clocks expire at another time, in accordance with the internal clock settings, may prove to be basically difficult to do. Previous systems created specialized clock systems to generate the operating system clock from both modules and interrupt the signal from one source to eliminate asymmetry. The methodology proposed in this case dynamically sets the clock past fault on one of the processor modules to match the period of the second processor module. This is due to the deterministic modification of expiration by means of synchronization messages.
[0040] In Figure 1, system 100 is described. System 100 includes a first processor module 102a, a second processor module 102b, field device 104, an IO process bus 106, a IO process bus 106b and a motherboard 108. In some cases, the first processor module 102a and the second processor module 102b and motherboard 108 may be called a dual redundant process controller 109 and / or a dual redundant processor. Alternatively, processor modules 102 and motherboard 108 may be called a control processor, unit controller, or controller. In an embodiment, the processor modules 102 communicate with the distributed control system (DCS) 112 via network 110. DCS 112 may include one or more workstations 114 and a computer system 116. While, in Fig. 1 the dual redundant process controller 109 and DCS 112 are shown separately to facilitate understanding and focus on the dual redundant process controller 109, it is understood that DCS 112 could alternatively be omitted to include the dual redundant process controller 109.
[0041] In the embodiment, the network 110 provides dual communication paths from the first processor module 102a to DCS 112 so that when one of the communication paths is not available for any reason, for example, due to a fault, the first processor module 102a may still communicate with DCS 112 using a second communication path. Network 110 may also provide dual communication paths from the second processor module 102b to DCS 112. In an embodiment, the network 110 may provide dual communication paths at least partially using a plurality of switches to provide a switch grid and / or a communication path grid. The network 110 may further include one or more signal splitters to ensure that the message sent to the processor module 102 in the main mode is also sent to the processor module 102 in the shadow mode. Network 110 may connect processor modules 102 to DCS 112 via wireless links, wired links, and / or optical links. In an embodiment, network 110 may be a public, private, and / or a combination thereof.
[0042] Processor modules 102 control the field device 104 and monitor one or more parameters of the field device 104 via process IO buses 106. Process IO buses 106 provide dual communication paths from processor modules 102 to field device 104 so that when one of the communication paths is not available for any reason, for example due to lost connection, cut wire or cable or interference on a wireless link, modules 102 the processor will still be able to communicate with the field device 104 via the second communication path. The processor module 102 in the main mode both monitors one or more field device parameters 104 and sends control commands to the field device 104 via IO 106 process buses. The shadow processor module 102 monitors one or more field device 104 parameters and also monitors control commands sent by the processor module 102 operating in
-12 main mode. In an embodiment, the processor module 102 operating in shadow mode does not send control commands to the field device 104.
[0043] Although one field device 104 is shown in Fig. 1, it is understood that processor modules 102 can control and monitor multiple field devices 104. Field devices 104 include various types of factory equipment, processing, production and other equipment. In some cases, field devices 104 may be called process devices and / or devices. Field devices 104 may include a logic component coupled to one or more electromechanical devices, e.g., a valve, pump, motor, heater, conveyor and other devices. The field device logic element 104 may further be coupled to one or more sensors to detect the operating parameters of the electromechanical device or the physical parameter with which the electromechanical device interacts, e.g. pressure, temperature, density or other characteristics or properties. In some cases, field devices 104 may include a logic component coupled to one or more sensors, but not to any electromechanical device.
[0044] In the case of a combination of processor modules 102 and DCS 112, field devices 104 may jointly provide an automated process, e.g. a chemical production process, a petroleum refining process, a glass production process, a food production process, an energy production process and / or other processes. In an embodiment, the processor modules 102 control field devices 104 according to the commands provided by the computer system 116 and send parameter values to the computer 116 and optionally to workstations 114. The computer system 116 may implement a high level process control application or monitor and control multiple double redundant processors that in turn control and monitor many field devices 104. In some cases, the computer system 116 may be called a higher level automated control device.
[0045] Each of the processors 102 implements a copy of the same computer program and / or control application. In other words, each of the processors 102 implements the case of the same computer program. In run mode, one of the processors 102 is in main mode and the other of the processors 102 is in shadow mode. The following description assumes that the first processor module 102a is in main mode and the second processor module 102b is in shadow mode, but it is understood that the roles of processor modules 102 can be swapped. Particularly, in the event of an error, the program implemented by the processor modules 102 may identify the fault and coordinate the change of main / shadow roles between the processor modules 102, which will be discussed later.
[0046] The processor module 102 that operates in the main mode sends commands to the field device 104 and sends the parameter values to the DCS 112. The processor module 102 working in the shadow mode receives the commands sent by the module module 102 working in the main mode and receives the parameter values sent by processor module 102
-13 working in main mode. Both processor modules 102 receive commands sent by DCS 112 and receive parameter values sent by field device 104.
[0047] The computer system 116 may include one or more computers that implement a high level process control application that works with the dual redundant process controller 109. Computer systems will be discussed in detail later. The computer system 116 may provide high level control input signals to a dual redundant process controller 109, e.g., an input signal controlling a furnace temperature setpoint. The dual redundant process controller 109 can control the field device 104, e.g., several thermistors that modulate the energy consumed by the resistance heating elements, and thus the heat emitted by the resistance heating elements, based on the high level input signal controlling the furnace setting and based on sensor values oven temperatures received from the field device 104. In an embodiment, the computer system 116 may be a high reliability computer system, and the communication connection between the computer system 116 and the network 110 may be provided through dual communication paths.
[0048] Workstations 114 may also be implemented in the form of computers. One of the 114 workstations can provide HMI (human machine interface) functionality. Workstations 114 allow monitoring of controlled processes and / or processes by users and / or plant operators. Workstations 114 may further enable plant users and / or operators transmitting input signals to the computer system 116 to select the operating modes of the controlled processes or processes and / or the entered command values of some process parameters. One or more workstations 114 may communicate with the dual redundant process controller 109 independent of the computer system 116, e.g., in the maintenance mode of operation and / or in the mode of operation test.
[0049] Processor modules 102 preferably execute the same control program instructions substantially simultaneously, for example at a particular time difference of execution. This can be called synchronous execution of instructions by the processor modules 102 and / or synchronous operation of the processor modules 102. It is understood that in spite of the fact that in some cases "synchronous" may mean exactly simultaneous occurrence of events, in this case "synchronous" means essentially simultaneously, within a specified time difference threshold, for example about 2 ms time difference or with an error time. By executing the same instructions synchronously, i.e. within a certain time difference threshold, you can reduce the difficulty of returning to normal operation after an error occurs by the main processor and / or swapping roles between the processor modules 102.
[0050] To promote synchronous operation, the control program contains a plurality of synchronous instructions distributed among the instructions of the control program. When one of the processor modules 102 executes the synchronous instructions of the control program - that is, both processor modules 102 implement this case of the same control program - it stores the synchronization message in the memory of the other processor module 102 and waits for
Read the corresponding synchronization message stored in its own memory by the second processor module 102 before proceeding with further instruction processing. If one of the processor modules 102 does not read the expected synchronization message from its memory within a specified time, e.g. 2 ms, the said processor module 102 performs actions to restore correctness after a fault. In some cases, a certain amount of time may be called a predetermined expiry date.
[0051] In an embodiment, the first processor module 102a includes a first central processor unit 118a, a first connection 119a, a first clock 120a, a first memory 122a and a first FPGA (field programmable gate array) , gate matrix programmable by electromagnetic field) 126a. The first FPGA 126a circuit includes and / or includes the first HDLC 128a controller. It is understood that the FPGA is a type of CPLD device complex programmable logic device, complex programmable electronic circuits). In another embodiment, instead of the first FPGA 126a, another type of CPLD may be used that is not FPGA. Alternatively, a logic device other than CPLD may be used instead of FPGA 126a, for example an ASIC (application specific integrated circuit), microcontroller, microprocessor or other electronic component of the logic. In an embodiment, the functionality of FPGA 126a and HDLC 128a controller can be implemented in separate components in exchange for integration as described herein. The first memory 122a may include a first synchronous state memory location 124a. The first processor module 102a can be implemented on one printed circuit board, on two printed circuit boards or on more printed circuit boards, and these boards can be included in the package, for example in an electronic equipment housing.
[0052] In an embodiment, the second processor module 102b includes a second central processing unit 118b, a second connection 119b, a second clock 120b and a second memory 122b, a second FPGA 126b and a second HDLC controller 128b. Second memory 122b may include a second state memory synchronous location 124b. The second processor module 102b can be implemented on any number of printed circuit boards that can be encapsulated in a package such as electronic equipment housing. Comments on the implementation of alternative embodiments of the first processor module 102a are equally applicable to the second processor module 102b and are not repeated for the sake of brevity. In an embodiment, the motherboard 108 may provide a mechanical structure for attaching processor modules 102, for attaching connectors and support elements, for example, a power supply or other components.
[0053] In an embodiment, both processor modules 102 implement a real-time multi-task operating system (RTOS), and the control application that is implemented by both processor modules 102 is executed in the context provided by RTOS. For example, central processing units 118 implement instances of the control application in a multi-task operating system in real time, which also
- works on central processing units 118. Some commercially available RTOS include Nucleus RTOS from the Embedded Systems Division from Mentor Graphics of Wilsonville, Oregon; VxWorks from Wind River Systems in Alameda, California; one or more RTOS from Green Hills Software from Santa Barbara, California; and other. RTOS can also be developed independently by the company when developing the control application and the dual redundant process controller 109. In a non-limiting manner, multi-task RTOS can generally provide deterministic scheduling of priority tasks so that a higher priority task is read, for processing it will not wait for the lower priority task to be completed. In an embodiment, commercially available RTOS can be extended to provide call synchronization instructions used by the control program. Alternatively, a software procedure may be developed that promotes synchronous message generation and transfer functionality, possibly using one or more RTOS system calls to complete synchronous message transmission. This procedure can be saved so that it can be called in any of many tasks, subroutines, modules and / or other elements of the control application.
[0054] When the first processor module 102a performs the synchronous instruction, it stores the first synchronous message in the second synchronous memory location 124b of the second memory 122b associated with the second processor module 102b. The first synchronous message identifies the synchronization state of the first processor module 102a, said value corresponding to one of several different synchronization state values. In some cases, the synchronization state value may be called the state value and the synchronization state may be the state. In some cases, the value of synchronization states and possibly other data may be called synchronization information.
[0055] Other data may include a synchronous instruction sequence number or identification number. Because the control application may contain many synchronous instructions, such as hundreds of synchronous instructions or thousands of synchronous instructions, simply identifying state values may not be enough to locate the control application processing point. Information that combines the value of states and the sequence number or other identification information may prove useful to uniquely identify the place of implementation in the control application.
[0056] The state value that the first processor module 102a stores in the second state memory synchronous location 124b provides an indication of what instructions of the joint control application the first control module 102a has recently implemented, and the second processor module 102b can analyze such indication to determine whether the modules 102 processor are synchronous. In an embodiment, a synchronous message may be sent when RTOS clock cycle events occur, and in that case, the synchronization information may identify an RTOS clock cycle event rather than a synchronization state. In another embodiment, the RTOS clock tact event may be handled and / or treated as one of many synchronization state values.
[0057] In the embodiment, eight different state values or synchronous values are shown, but in another embodiment there may be both more or less other state values. The first state value may correspond to clock interference, e.g. clock interference generated by clock 120 and / or RTOS clock tact event. It may also be called the operating system measure time or the OS measure state values. The second state value may correspond to a process input / output bus disturbance, e.g., associated with an interference or receiving an input from a field device 104. The third state value may correspond to a real-time operating system task switch. The fourth state value may correspond to a message being sent from the main processor module 102 to DCS 112 and / or the computer system 116. The fifth state value may correspond to external time synchronization. The sixth state value may correspond to a message receiving event from DCS 112. The seventh state value may correspond to a message exchange. The eighth state value may correspond to a request to resynchronize the processor modules 102, which may be referred to as an association request.
[0058] When the second processor module 102b performs synchronization instructions, similarly, it stores a second synchronization message identifying the synchronization state of the second processor module 102b in the first synchronous memory location 124a of the first memory state 122a associated with the first processor module 102a. The state value that the second processor module 102b stores at the first synchronous state memory location 124a provides an indication of what instructions of the common control application the second processor module 102b has recently implemented, and the first processor module 102a can analyze such information to determine if the processor modules 102 are in sync.
[0059] After the synchronization message is written by each of the processor modules 102 in the state memory synchronous location 124 of the correlated processor module 102, it waits a certain amount of time to check that the state value stored in its own state memory synchronous location 124 corresponds to the one it has stored. If the matching of state values is not determined before a specified amount of time or expiration time has elapsed, the subject processor module 102 may declare that the correlated processor module 102 is not operating synchronously and may begin a recovery procedure to re-synchronize the two processor modules 102. The expiration of a specific time or expiration period may in some cases be called synchronization expiration or expiration.
[0060] The code example shown below shows a synchronization call that may look like this (ftsync_i ()) before the operating system performs a specific OS event call. In an embodiment, the ftsync_i () function provides the synchronization operation described herein. Those skilled in the art will recognize that the code in question can be written in any programming language. In addition, those skilled in the art will readily recognize that code can be written in a variety of ways, departing from the code example below.
STATUS EVC_Set_Events (NU_EVENT_GROUP
-17 * event_group_ptr, UNSIGNED events,
OPTION operation) {
R1 EV_GCB * event_group; / * Event control block ptr * /
R2 EV_SUSPEND * suspend_ptr; / *
Pointer to suspension blk * /
R3 EV_SUSPEND * next_ptr; / *
Pointer to next suspend * /
R4 EV_SUSPEND * last_ptr; / * Last suspension block ptr * /
UNSIGNED consume; / * Event flags to consume * /
UNSIGNED compare; / * Event comparison variable * /
INT preempt; / * Preemption required flag * /
NU_SUPERV_USER_VARIABLES / * Switch to supervisor mode * /
NU_SUPERVISOR_MODE ();
/ * Move input event group pointer into internal pointer. * / event_group = (EV_GCB *) event_group_ptr;
/ * Synchronize with FT Partner if married and disable interrupts. * / ftsync_i (OS_SID);
/ * Protect against simultaneous access to the event group. * /
TCT_System_Protect ();
/ * Perform the specified operation on the current event flags in the
-18group. * / if (operation & EV_AND) / * AND the specified events with the current events. * / event_group -> ev_current_events = event_group -> ev_current_events & events;
else / * OR the specified events with the current events. * / event_group -> ev_current_events = event_group -> ev_current events | events;
[0061] In Fig. 4, method 250 is described. Method 250 briefly illustrates the exemplary code described above. In an embodiment, the method 250 is called or implemented when the EVC_Set_Events () method described above is called. In an embodiment, method 250 may be called before the EVC_Set_Events () method and / or before calling the EVC_Set_Events () method. In block 252, switching to supervision mode has been carried out. In block 254, the event group pointer has been moved to an internal pointer, for example, to the event group pointer (event_group). In block 256, another processor module has been synchronized by calling a subroutine or synchronization function. In an embodiment, the synchronization subroutine may be called ftsync_i (). At block 258, simultaneous access to the event group is protected against, e.g., the use of an exclusive access mechanism, e.g., a semaphore or other mechanism. In block 260, the current event flags in the event group are updated. Method 250 then comes to an end. As shown in fig. 4 and in method 250, synchronization between processor modules may be performed before an operating system call signal is generated, e.g., before updating current event flags or other activities, e.g., sending a command to field device 104.
[0062] Again, referring to Fig. 1, when the first processor module 102a reaches the specified synchronization instruction in the common control application before the second processor module 102b, the first processor module 102a writes a synchronization message containing its state value at the second state memory synchronous location 124b, reads the state value stored at the first synchronous memory location 124a states, it determines whether the state values at the state memory synchronous locations 124 do not match and wait for the state value stored in the first state memory synchronous location 124a to be checked to match the state values that it stored at the second state memory synchronous location 124b. The first processor module 102a may repeat reading from the first synchronous memory location 124a
-19 states and carry out a comparison. Alternatively, the first processor module 102a may periodically read from the first state memory synchronous location, e.g., co
100 μs, every 500 μs, every 1 ms or other periods and carry out a comparison.
[0063] If the state value stored by the first processor module 102a and the state value read by the first processor module 102a from the first state memory synchronous location 124a will match before a specified amount of time has elapsed, the first processor module 102a continues to execute the subsequent control application instructions. However, if synchronization expires in the first processor module 102a, the first processor module 102a may begin a procedure to resume synchronization with the second processor module 102b. The recovery procedure may in some cases be called the resynchronization procedure or resynchronization function. Otherwise, the second processor module 102b may achieve the specific synchronization instruction in the common control application before the first processor module 102a, and in that case the behavior of the first processor module 102a, as described above, will be accomplished by the second processor module 102b.
[0064] In an embodiment, the resynchronization procedure or resynchronization function may include stopping the control process briefly and copying the entire content of the first processor module 102a to the second processor module 102b, which in some cases may be called re-pairing. The context may include register values and / or stack values maintained by the first processor module 102a. Alternatively or additionally, the resynchronization procedure may involve swapping roles between the first processor module 102a and the second processor module 102b, such that the processor module 102 previously operating in the main mode switches to shadow mode and the processor module 102 previously operating in the shadow mode switches to work in main mode.
[0065] It can be said that the sharing of the above-described state values implements the state sequencer of the dual redundant processor. In some cases, the control application may be considered to include or implement a state sequencer. The state sequencer function of the control application tracks the state of the subject processor module 102 and promotes maintaining synchronization with the respective processor module 102.
[0066] In an embodiment, the first processor module 102a writes the first synchronization message to the second synchronous state memory location 124b in the second memory 122b, and the second processor module 102b writes the second synchronization message to the first synchronous state memory location 124a in the first memory 122a via the link Ethernet Gigabit (1G) communication, which is provided by the system 100 between the processor modules 102. For example, the first connection 119a in the first processor module 102a provides a first standard communication port that couples to the second standard communication port in the second connection 119b in the second processor module 102b to provide a communication connection between the processor modules 102 to promote the synchronization function. In another embodiment, the transmission of synchronous messages is provided
-20 thanks to another communication link. In an embodiment, synchronous messages can be in the form of Ethernet frames about 13 bytes in length. The communication connection can be accomplished through a transformer link to provide electrical isolation between two processor modules 102.
[0067] In an embodiment, the specific amount of time or a defined time-out period, which may also be referred to as the synchronization-time-out period, may be in the range of 50 μs to 50 ms. Alternatively, in an embodiment, the synchronization deadline may be in the range of 500 μs to 10 ms. In an embodiment, the synchronization deadline may be about 2 ms. Alternatively, a different synchronization deadline may be used. In conjunction with the disclosure, those skilled in the art will be able to easily select a specific time for effective synchronization of control program instruction execution between processor modules 102. One of the parameters when determining the time period of synchronization may be the frequency or scale of the 120 clocks and / or the offset between the 120 clocks.
[0068] It is understood that the clocks 120 are expected to have an offset relative to each other: one clock 120 may work faster than the other clock 120, even if only slightly faster. Because the processor modules 102 execute instructions at a rate determined by the respective clocks 120, the implementation of the instructions of the processor module 102 having a slower clock 120 will be more and more delayed relative to the instructions of the second processor module 102, until synchronization expires. One of the results of the resynchronization of the processor modules 102 may be to reset the time delay between the instructions of the two processor modules 102 to zero. However, after the resynchronization procedure is completed, the processor module 102 having a slower clock 120 will be more and more delayed relative to the instructions of the other processor module 102 until the synchronization deadline occurs again and this cycle will repeat. In general, it is undesirable for resynchronization to occur periodically in the absence of real error conditions, because during resynchronization, the dual redundant control processor does not control the field devices 104. This is analogous to a vehicle rolling down the road when the driver is not holding his hands on steering wheel for a limited time.
[0069] In an embodiment, if resynchronization occurs too often, two processor modules 102 perform a restore procedure, for example, establishing a processor module 102 that has been in shadow mode to the main mode until now, and establishing a processor module 102 that has worked until that pores in main mode to shadow mode. The recovery procedure may further include performing a diagnostic of the processor module 102 clock which is not working accurately. The control program can call the restore procedure if a specified number of resynchronization occurs in the specified time window. For example, the control program may invoke the restore procedure if more than 5 resynchronization occurs within one minute.
[0070] In an embodiment, the dual redundant control processor 109 automatically compensates for the clock offset by forcing the processor module 102 which
- works in shadow mode so that it periodically sets its clock 120 relative to the clock 120 of the processor module 102 working in the main mode, for example, adjusting its clock 120 so as to compensate for the time delay between the shadow 120 clock and the main clock 120 or adjusting the clock 120, so that it compensates for the time advance between the 120 shadow clock and the 120 main clock.
[0071] Automatic clock offset compensation may limit the resynchronization frequency. In addition, clock offset compensation may allow a reduction in the synchronization timeout period. For example, if a clock shift occurs, the synchronization deadline can be set to long to limit the frequency of resynchronization. As a result, the faster clock 120 in the processor module 102 wastes more and more time. By limiting the synchronization delay period, processor module 102 having a faster clock 120 wastes less time. Also, if a problem occurs that causes processor module 102 to be out of sync, the non-synchronization condition can be detected and repaired more quickly.
[0072] In an embodiment, the processor module 102 operating in shadow mode determines the average clock shift speed between two processor modules 102 and prophylactically corrects its own clock 120 to minimize clock shift. In some cases, this operation may be referred to as advance time clock speed control or delay time clock speed control. It is understood that control application instructions may include clock offset compensation instructions that are selectively implemented by the processor module 102 operating in shadow mode and not implemented by the processor module 102 operating in the main mode. In an embodiment, the control application may implement synchronization instructions that promote the determination of a clock offset. In some cases, the synchronization instruction may be called clock clock synchronization. In other words, the synchronization for determining the clock offset between the two processor modules 102 may be called clock tact synchronization.
[0073] In the embodiment, when the message is to be sent from the dual redundant process controller 109 to DCS 112, both processor modules 102, which are assumed to execute control application instructions in a synchronous manner, as described above, generate a set of messages and the cyclic redundancy check (CRC) value calculated for the message set. The synchronization message is exchanged between the processor modules 102 indicating that the transmission is in progress, and the processor module 102 operating in shadow mode includes the CRC value calculated in the synchronization message which sends to the synchronous location 124 of the state memory 124 of the processor module 102 operating in main mode.
[0074] The processor module 102 operating in the main mode compares the CRC which it has calculated with the CRC calculated by the processor module 102 operating in the shadow mode. If the CRCs match, the main module processor 102 sends the message set and CRC to the DSC 112 and / or computer system 116. If the CRCs do not match, module 102
The main processor does not send to DCS 112 or computer system 116 at this time, and instead performs a diagnostic procedure to determine why the two processor modules 102 have calculated different CRCs. This may indicate a certain error, and this functionality promotes error correction before the error goes beyond the dual redundant process controller 109. It is understood that the message set and CRC sent by processor module 102 may be included in the message set by a communication node in network 110, and the CRC calculated by that communication node attached to the new message to allow reliable communication between that network node and other network nodes on network 110. The CRC defined by the processor module 102 may be used by DCS 112 and / or the computer system 116 to detect errors introduced into the message set generated by the processor module 102, since this message set is sent over network 110.
[0075] In an embodiment, messages sent from the dual redundant process controller 109 to DCS 112 and / or computer system 116 may be sent from the message queue at processor module 102. Messages that have passed the CRC comparison test may accumulate in the message queue in processor module 102, and processor modules 102 may be able to resume processing control application instructions instead of waiting for each message to be sent. Messages can be sent via a communication link between the processor module 102 in the main mode to the network 110 if the single-band communication connection allows this, for example, by a task with a lower priority of the control application and / or by means of a transmitter chip and a receiver providing a message queue.
[0076] In Fig. 2, an embodiment of the FPGA 126 and HDLC 128 controller is discussed in detail. When the processor module 102 in the main mode processes the output signal sent to the field device 104, the FPGA 126 creates the message set and the CRC calculated for the message set and sends the set messages and CRC is the HDLC 128 controller. The HDLC 128 controller formats the set of messages and CRC into the HDLC frame, which then sends the process IO bus 106 to the field device 104. In an embodiment, the HDLC 128 controller simultaneously receives the same HDLC frame that it has sent and compares the CRC value in the received HDLC frame with the CRC value received from the FPGA 126. If the CRC values do not match, the HDLC 128 controller alerts the FPGA 126 and the FPGA 126 can carry out the error repair process. This CRC control of the HDLC frame can speed up error correction and faster restoration of normal communication with the field device 104.
[0077] It is understood that many of the innovations described above can contribute to promoting damage tolerance calculations. In addition, the specific features and techniques described do not depend on specialized equipment and can be implemented on publicly available components that may be called general equipment. Although in the embodiment, each of the innovations discussed can be implemented in a dual redundant process controller 109, it can be understood that other embodiments of a dual redundant process controller 109 are also possible, which
Implement one or reduced selection of the described innovations also considered in the disclosure.
[0078] In Figure 3, method 200 is discussed. At block 202, the first message sent from the dual redundant process controller 109 to DCS 112 and / or computer system 116 is created and / or assembled by the first processor module 102a operating in the main mode. The first message contains the first payload and the first cyclic redundancy check (CRC). The first CRC is calculated for the first payload by the first processor module 102a. At block 204, the second message is created and / or assembled by the second processor module 102b operating in shadow mode. The second message contains the second payload and the second cyclic redundancy check (CRC). The second CRC is calculated for the second payload by the second processor module 102b. In an embodiment, the second processor module 102b may send the second CRC to the first processor module 102a, e.g., in a synchronous message sent to the synchronous location 124a of the state memory of the first processor module 102a. It is understood that processing of blocks 202 and 204 may occur substantially simultaneously or processing of block 204 may occur slightly before processing of block 202.
[0079] In block 206, the first processor module 102a compares the first CRC with the second CRC. At block 208, the implementation of the first processor module 102a is divided into one of two processing paths based on the result of the CRC comparison. After the CRC comparison, processing proceeds to block 210, in which the first processor module 102a sends the first payload and the first CRC to DCS 112 and / or computer system 116. If the CRCs are not compared, processing proceeds to block 212, where the first processor module 102a begins diagnostics. It is understood that the term payload used for the description of method 200 corresponds to the term message set used in the above description with reference to Fig. 1.
[0080] Although several embodiments are provided in the disclosure, it should be understood that the disclosed systems and methods can be made in other forms without departing from the scope of the disclosure. Examples should be seen only as illustrating the given solutions, and not limited to the details described here. For example, different elements or components can be combined or integrated in other systems, or some features may be missed or unrealized.
[0081] Also, the techniques, systems, subsystems and methods described and illustrated in various embodiments as discontinuous or separate can be combined or integrated with other systems, modules, techniques or methods without departing from the scope of the disclosure. Other elements that have been presented or discussed as directly coupled or communicating with each other can be indirectly coupled or communicated via appropriate interfaces, devices or intermediate elements, whether electrical, mechanical or other. Other examples of changes, substitutions and modifications will be appreciated by those skilled in the art and may be made without departing from the scope of the description disclosed herein.
[0082] Accordingly, the invention also relates to a dual redundant process controller. The controller may contain a process control application that is implemented on the first and second modules. After the first module executes, the first instance of the application writes the first synchronization information in the second module, reads the second synchronization information from the first module, and when the second information does not match the first synchronization information after the expiration period, it performs the resynchronization function; and in which, after being executed by the second module, the second instance of the application writes the second synchronization information on the first module, reads the first synchronization information from the second module, and when the first does not agree with the second synchronization information after the expiration period, performs the resynchronization function. The first instance of the application calls the synchronization function provided by the multitasking operating system in real time before calling the specific event function provided by the multitasking operating system in real time.
Prepared and verified
Anna Stenzel
Patent Attorney
15 members in 4 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 201113029102 | United States of America | A | |
| 12155519 | European Patent Office (EPO) | A | |
| EP20120155519 | – | – | – |
| US201113029102 | – | – | – |
Members15
| Document | Office | Kind | |
|---|---|---|---|
| US2012210198A1 | United States of America | A1 | |
| US2012210199A1 | United States of America | A1 | |
| EP2490124A2 | European Patent Office (EPO) | A2 | |
| EP2490124A3 | European Patent Office (EPO) | A3 | |
| US8516355B2 | United States of America | B2 | |
| US2013339788A1 | United States of America | A1 | |
| US8732556B2 | United States of America | B2 | |
| US8745467B2 | United States of America | B2 | |
| US2014237328A1 | United States of America | A1 | |
| EP2490124B1 | European Patent Office (EPO) | B1 | |
| ES2523129T3 | Spain | T3 | |
| US8966340B2 | United States of America | B2 | |
| EP2843554A1 | European Patent Office (EPO) | A1 | |
| PL2490124T3This record | Poland | T3 | |
| EP2843554B1 | European Patent Office (EPO) | B1 |
Numbers
- Publication, DOCDB
- 2490124
- Publication, EPODOC
- PL2490124T
- Application
- 155519
- Application, DOCDB
- 12155519
- Application, EPODOC
- PL20120155519T
Titles2
- English
- Dual redundant process controller
- Polish
- Podwójny nadmiarowy sterownik procesów
Classification
- CPC, 8
- G06F11/1679
- G06F11/1402
- G06F11/1658
- G06F11/1004
- G06F11/1633
- G06F11/1683
- G06F11/2038
- G05B9/03
- IPC, 4
- G06F11 10
- G05B9 03
- G06F11 16
- G06F11 20