JPH0327923B2 - - Google Patents
Info
- Publication number
- JPH0327923B2 JPH0327923B2 JP57117571A JP11757182A JPH0327923B2 JP H0327923 B2 JPH0327923 B2 JP H0327923B2 JP 57117571 A JP57117571 A JP 57117571A JP 11757182 A JP11757182 A JP 11757182A JP H0327923 B2 JPH0327923 B2 JP H0327923B2
- Authority
- JP
- Japan
- Prior art keywords
- process control
- control unit
- database
- unit
- redundant
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Expired - Lifetime
Links
Classifications
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B9/00—Safety arrangements
- G05B9/02—Safety arrangements electric
- G05B9/03—Safety arrangements electric with multiple-channel loop, i.e. redundant control systems
Landscapes
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Engineering & Computer Science (AREA)
- Automation & Control Theory (AREA)
- Hardware Redundancy (AREA)
- Safety Devices In Control Systems (AREA)
Description
【発明の詳細な説明】
本発明は、n+1冗長化制御装置の改良に関す
るものである。DETAILED DESCRIPTION OF THE INVENTION The present invention relates to an improvement of an n+1 redundant control device.
分散形制御装置は、インテリジエンスを有する
複数の制御ステーシヨンを制御対象の各所に分散
配置して通信線で結び、各制御のステーシヨンに
それぞれの区域を分担制御させるようにしたもの
である。このような装置は危険分散形の制御装置
であり、システムとしての信頼性は高いが、個々
の制御ステーシヨンについては、分散形だからと
いつて信頼性が高まつたことにはならない。そこ
で個々の制御ステーシヨンごとに高い信頼性が要
求されるときは、個々の制御ステーシヨンの冗長
化が必要になる。 A distributed control device is a system in which a plurality of intelligent control stations are distributed at various locations to be controlled and connected through communication lines, so that each control station is assigned control over its own area. Such a device is a risk-distributed control device and has high reliability as a system, but just because the individual control stations are distributed does not mean that the reliability is increased. Therefore, when high reliability is required for each individual control station, redundancy of each control station is required.
冗長化の手法としては、経済性の見地から、所
定の複数の制御ステーシヨンに対して1つの待機
用の制御ステーシヨンを設け、実働側の制御ステ
ーシヨンのどれか1つが故障したとき、待機側の
制御ステーシヨンでバツクアツプするようにし
た、いわゆるn+1冗長化が採用される。その場
合、バツクアツプ時およびバツクアツプ解除時の
制御の引き継ぎを円滑にするために、入出力信号
と制御用のデータベースを、実働側の制御ステー
シヨンと待機側の制御ステーシヨンとの間に継承
させることが必要になる。 From an economic point of view, the redundancy method is to provide one standby control station for a given number of control stations, and when one of the control stations on the active side fails, the control station on the standby side is activated. So-called n+1 redundancy, in which backup is performed at the station, is employed. In that case, it is necessary to inherit input/output signals and control databases between the production-side control station and the standby-side control station in order to ensure smooth handover of control during backup and release. become.
制御ステーシヨンについてn+1冗長化を行な
つた分散形制御装置の従来例としては、各制御ス
テーシヨンのプロセス入出力信号線を実働側の制
御ステーシヨンと待機側の制御ステーシヨンの間
で授受するための専用の接続手段を設けたものが
ある。このような従来例においては、多数の入出
力信号線の切り換えが必要になるので、切り換え
手段はさくそうしたものとなつて信頼性が低下す
る欠点があり、また、待機側の制御ステーシヨン
は、実働側の制御ステーシヨンの入出力部と同一
のものをすべて持つていなければならないので、
経済的でない。あるいは、逆に、実働側の制御ス
テーシヨンの持ちうる入出力部は、待機側の制御
ステーシヨンの入出力部によつて限定される。ま
た、冗長化関係にあるn+1個の制御ステーシヨ
ン間に、データベース授受用の専用の接続線が必
要になるのも不経済である。さらに、バツクアツ
プ時に、待機側の制御ステーシヨンがデータベー
スを引き継ぐとき、実働側の制御ステーシヨンは
その前に故障しているのであるから、インテリジ
エンスの暴走などによつて、データベースが損傷
を受けている可能性がある。損傷を受けたデータ
ベースによつては、正しい制御ができないので、
そのようなおそれのないデータベースを引き継ぐ
ようにする必要がある。 A conventional example of a distributed control device with n+1 redundancy for control stations is a dedicated system for transmitting and receiving process input/output signal lines for each control station between the active control station and the standby control station. Some are equipped with connection means. In such a conventional example, since it is necessary to switch a large number of input/output signal lines, the switching means becomes complicated and reliability decreases.Furthermore, the control station on the standby side is It must have all the same input and output parts as the control station on the side, so
Not economical. Or, conversely, the possible input/output units of the control station on the active side are limited by the input/output units of the control station on the standby side. Furthermore, it is uneconomical that a dedicated connection line for transmitting and receiving the database is required between the n+1 control stations in a redundant relationship. Furthermore, when the standby control station takes over the database during backup, the production control station has already failed, so the database may have been damaged due to runaway intelligence. There is sex. Correct control may not be possible depending on the damaged database, so
It is necessary to inherit a database that does not pose such a risk.
本発明の目的は、冗長化関係にあるn+1個の
制御機構の間において、制御引き継ぎ時のプロセ
ス入出力線の切り換えを必要とせず、データベー
ス授受用の専用の接続線が不要で、かつ、実働側
の故障にもかからわず、正常性の保証されたデー
タベースを引き継ぐことができる冗長換分散形制
御装置を提供することにある。 An object of the present invention is to eliminate the need for switching process input/output lines when taking over control between n+1 control mechanisms in a redundant relationship, eliminate the need for a dedicated connection line for database exchange, and eliminate the need for actual connection between n+1 control mechanisms. To provide a redundant distributed control device capable of taking over a database whose normality is guaranteed even in the event of a failure on the side.
本発明は、
インテリジエンスと入出力部を持つ複数のプロ
セス制御ユニツトと、インテリジンエスを持つ冗
長ユニツトを通信線によつて接続した構成を有す
るn+1冗長化制御装置であつて、
各プロセス制御ユニツトは、ウオツチドツグ・
タイマのタイムアツプに従つて故障を表示する手
段を有し、
冗長ユニツトは、プロセス制御ユニツトからア
ツプロードされるデータベースの記憶手段とし
て、通信線に繋る全てのプロセス制御ユニツトの
データベースを記憶できる容量よりも、少くとも
プロセス制御ユニツトのウオツチドツグ・タイマ
の時限値に相当する時間にアツプロードされるデ
ータベースを記憶できる容量だけ大きい容量を持
つ記憶手段と、この記憶手段に、通信線に繋る全
てのプロセス制御ユニツトのデータベースを周期
的に順番にかつ循環的に記憶させるアツプロード
手段と、プロセス制御ユニツトのいずれかが故障
を表示したとき、その時点よりもプロセス制御ユ
ニツトのウオツチドツグ・タイマの時限値以上前
にアツプロードされたそのプロセス制御ユニツト
のデータベースを用いてそのプロセス制御ユニツ
トのインテリジエンスの代りにそのプロセス制御
ユニツトの入出力部を駆使してプロセス制御を行
なう手段とを有する、
n+1冗長化制御装置
によつて上記の目的を達成したものである。 The present invention is an n+1 redundant control device having a configuration in which a plurality of process control units having intelligence and input/output units and a redundant unit having intelligence are connected by communication lines, and each process control unit is a watchdog.
The redundant unit has a means for indicating a failure according to the time-up of the timer, and as a storage means for the database uploaded from the process control unit, the redundant unit has a capacity larger than that for storing the databases of all the process control units connected to the communication line. , a storage means with a capacity large enough to store at least the database uploaded at a time corresponding to the time limit of the watchdog timer of the process control unit, and all process control units connected to the communication line to this storage means. uploading means for periodically and sequentially and circularly storing a database of the process control unit; and means for controlling the process by making full use of the input/output section of the process control unit instead of the intelligence of the process control unit using the database of the process control unit. This goal has been achieved.
以下、実施例によつて本発明を詳細に説明す
る。第1図は、本発明が適用される分散制御装置
の概念的構成図である。第1図において、11〜
1Kは制御ステーシヨンであつて、それぞれイン
テリジエンスを有し制御対象の各部を分担して制
御するものである。21〜2nはマスタステーシヨ
ンであつて、オペレータまたは上位計算機による
システム全体の監視・操作用として設けられる。
3は通信線路であつて、制御ステーシヨン11〜
1Kとマスタステーシヨン21〜2nを接続し、分
散形制御装置を形成するものである。 Hereinafter, the present invention will be explained in detail with reference to Examples. FIG. 1 is a conceptual configuration diagram of a distributed control device to which the present invention is applied. In Figure 1, 1 1 ~
1K is a control station, each of which has intelligence and controls each part of the object to be controlled. Master stations 2 1 to 2 n are provided for monitoring and operating the entire system by an operator or a host computer.
3 is a communication line, which connects control stations 1 1 to
1 K and master stations 2 1 to 2 n are connected to form a distributed control device.
制御ステーシヨン1i(i=1〜k)の詳細な
構成を第2図に示す。第2図において、41〜4
nはプロセス制御ユニツト、5はクラスタ制御ユ
ニツト、6は冗長ユニツト、7は内部通信線であ
る。プロセス制御ユニツト41〜4nとクラスタ
制御ユニツト5と冗長ユニツト6は、内部通信線
7によつて相互接続され、1つの制御ステーシヨ
ンを構成する。このような制御ステーシヨンをそ
の形態に因んでクラスタ(房)と呼ぶ。各クラス
タは、クラスタ制御ユニツト5を通じて通信線路
3に接続される。 The detailed configuration of the control station 1 i (i=1 to k) is shown in FIG. In Figure 2, 4 1 to 4
n is a process control unit, 5 is a cluster control unit, 6 is a redundant unit, and 7 is an internal communication line. The process control units 4 1 -4n, the cluster control unit 5 and the redundancy unit 6 are interconnected by an internal communication line 7 and constitute one control station. Such control stations are called clusters due to their shape. Each cluster is connected to a communication line 3 through a cluster control unit 5.
プロセス制御ユニツト41〜4n、クラスタ制
御ユニツト5および冗長ユニツト6はいずれもイ
ンテリジエンスを持つており、例えば、第3図、
4図および第5図のようにそれぞれ構成される。 The process control units 4 1 to 4n, the cluster control unit 5 and the redundancy unit 6 all have intelligence, for example, as shown in FIG.
They are constructed as shown in FIGS. 4 and 5, respectively.
第3図において、プロセス制御ユニツト4j
(j=1〜n)は、内部通信制御器NCMと、プ
ロセツサNPUと、メモリNMUと、入出力器
I/Oを持つている。これらの各コンポーネント
はデータバスDBSによつて相互に接続されて、
インテリジエントなプロセス制御ユニツトを形成
している。プセツサNPUとメモリNMUがイン
テリジエンスの中枢をなす。入出力データはメモ
リNMUに記憶され、プロセツサNPUによつて、
プロセス制御用のデータ処理がなされる。データ
処理に際しては、メモリNMU中のデータベース
が用いられ、このユニツトが担当しているプロセ
スに適したデータ処理が行なわれる。 In FIG. 3, the process control unit 4 j
(j=1 to n) has an internal communication controller NCM, a processor NPU, a memory NMU, and an input/output device I/O. Each of these components is interconnected by a data bus DBS,
It forms an intelligent process control unit. The Pusetsa NPU and memory NMU form the core of intelligence. Input/output data is stored in the memory NMU, and processed by the processor NPU.
Data processing for process control is performed. When processing data, the database in the memory NMU is used, and data processing appropriate for the process that this unit is in charge of is performed.
内部通信制御器NCMは、内部通信線7に対す
る通信を制御するとともに、ダイレクト・メモリ
アクセス(DMA)によつてメモリNMUと入出
力器I/Oにアクセスする機能を持つている。こ
のような機能は、通信制御器NCMに内蔵された
マイクロプログラムによつて実現される。 The internal communication controller NCM has a function of controlling communication to the internal communication line 7 and accessing the memory NMU and the input/output device I/O by direct memory access (DMA). Such functions are realized by a microprogram built into the communication controller NCM.
第4図のクラスタ制御ユニツト5も、同様な内
部通信制御器NCM、プロセツサNPU、およびメ
モリNMUを持つており、さらにその他に外部通
信制御器FCAを持つている。外部通信制御器
FCAもDMA機能を持つものである。これらの各
コンポーネントもデータバスDBSによつて相互
接続されて、インテリジエントなクラスタ制御ユ
ニツトを形成している。このクラスタ制御ユニツ
トは、そのインテリジエンスによつて、クラスタ
内の各ユニツトの動作を制御する。制御の種類
は、大別して2種類あり、1つは、マスタステー
シヨン21〜2nから通信線路3を通じて与えられ
る指令に基づいて、クラスタ内の各ユニツトを制
御することであり、もう1つは、プロセス制御ユ
ニツト4jから通信される故障通信信号に基づい
て、冗長ユニツト6に故障したプロセス制御ユニ
ツト4jのバツクアツプを行なわせることである。
これらの制御は、いずれも内部通信線7を利用し
た通信によつて行なわれる。その場合、プロセツ
サNPUは、制御用のデータ処理を行ない、内部
通信制御器NCMは、内部通信線7に対する通信
を制御し、外部通信制御器FCAは外部通信線3
に対する通信を制御する。 The cluster control unit 5 in FIG. 4 also has a similar internal communication controller NCM, processor NPU, and memory NMU, and also has an external communication controller FCA. External communication controller
FCA also has a DMA function. Each of these components is also interconnected by a data bus DBS to form an intelligent cluster control unit. This cluster control unit uses its intelligence to control the operation of each unit within the cluster. There are two types of control: one is to control each unit in the cluster based on commands given from the master stations 2 1 to 2 n through the communication line 3, and the other is to , to cause the redundant unit 6 to back up the failed process control unit 4j based on the failure communication signal communicated from the process control unit 4j .
All of these controls are performed through communication using the internal communication line 7. In that case, the processor NPU processes data for control, the internal communication controller NCM controls communication to the internal communication line 7, and the external communication controller FCA controls the communication to the external communication line 3.
Control communication to.
第5図の冗長ユニツト6も、同様な内部通信制
御器NCMとプロセツサNPUとメモリNMUを持
つており、さらにその他にアツプロードメモリ
NMUUを持つている。これら各コンポーネント
もデータバスDBSによつて相互接続されて、イ
ンテリジエントな冗長ユニツト6を形成してい
る。この冗長ユニツト6は、そのインテリジエン
スにより、クラスタ内の全プロセス制御ユニツト
41〜4nのデータベースを、通信を介して周期
的に読み出してアツプロードメモリNMUUに記
憶しており、これによつて、各プロセス制御ユニ
ツト4jの最新のデータベースが常にアツプロー
ドメモリNMUUに存在するようになつている。
データベースの収集は、冗長ユニツト6と各プロ
セス制御ユニツト4jにおける内部通信制御器
NCMのDMA機能によつて周期的に行なわれる。
データベースの収集時の冗長ユニツト6の挙動
を、マスタ制御ユニツト5によつて監視すること
により、待機状態における冗長ユニツト6の健全
性が確認できる。したがつて、バツクアツプは健
全性がが保証された冗長ユニツトで行なえる。 The redundant unit 6 in Fig. 5 also has a similar internal communication controller NCM, processor NPU, and memory NMU, and also has an upload memory.
Have NMUU. These components are also interconnected by a data bus DBS to form an intelligent redundancy unit 6. This redundant unit 6 uses its intelligence to periodically read out the database of all process control units 4 1 to 4n in the cluster via communication and store it in the upload memory NMUU. The latest database of each process control unit 4j always exists in the upload memory NMUU.
The database is collected by the internal communication controller in the redundant unit 6 and each process control unit 4j .
This is done periodically by the NCM's DMA function.
By monitoring the behavior of the redundant unit 6 during database collection by the master control unit 5, the health of the redundant unit 6 in the standby state can be confirmed. Therefore, backup can be performed in a redundant unit whose integrity is guaranteed.
アツプロードメモリNMUUには、プロセス制
御ユニツト4jのそれぞれに対応したアツプロー
ド領域が設けられている。これらアツプロード領
域は、プロセス制御ユニツト4jの数よりも多く
設けられる。いま、たとえばプロセス制御ユニツ
トの数nを8とすると、アツプロード領域は第6
図のように構成される。 The upload memory NMUU is provided with upload areas corresponding to each of the process control units 4j . The number of upload areas is greater than the number of process control units 4j . For example, if the number n of process control units is 8, the upload area is the 6th one.
It is configured as shown in the figure.
第6図においては、アツプロード領域がプロセ
ス制御ユニツト数の2倍だけ設けられ、各領域
に、それぞれ対応するプロセス制御ユニツトのデ
ータベースがアツプロードされるようになつてい
る。アツプロードは順番に行なわれ、現時点t0に
おいては、プロセス制御ユニツト45のデータベ
ースがアツプロードされている。その他の領域の
データベースは、全てそれ以前にアツプロードさ
れたものであつて、時点を示す記号の負数の添字
が現時点からの溯りの程度を表す。データベース
の1回あたりのアツプロード所要時間をtとする
と、各領域のデータベースは、tの添字倍だけ過
去のものである。アツプロードの所要時間tはた
とえば1.5秒程度である。領域の数がプロセス制
御ユニツト数の2倍であることにより、各プロセ
ス制御ユニツト4jのデータベースは収集時点の
一周期異なるものが2つ存在する。 In FIG. 6, upload areas are provided twice as many as the number of process control units, and databases for the corresponding process control units are uploaded to each area. Uploading is performed in order, and at the current time t0 , the database of the process control unit 45 has been uploaded. The databases in other areas were all uploaded before that time, and the negative subscript of the symbol indicating the point in time indicates the degree of backwardness from the current point. If the time required to upload a database per time is t, then the database in each area is older than the index times t. The required time t for uploading is, for example, about 1.5 seconds. Since the number of areas is twice the number of process control units, there are two databases for each process control unit 4j that differ by one period at the time of collection.
各プロセス制御ユニツト4jの故障は、それぞ
れに内蔵されたウオツチドツグ・タイマのタイム
アツプによつて検出され、それに基づく故障報知
が通信によつてクラスタ制御ユニツト5に伝達さ
れる。ウオツチドツグ・タイマの時限値Tは、全
てのプロセス制御ユニツト41〜4nに対して同
一の値が定められ、たとえば4秒程度とされる。 A failure in each process control unit 4j is detected by the time-up of a watchdog timer built in each, and a failure notification based on the time-up is transmitted to the cluster control unit 5 by communication. The time limit T of the watchdog timer is set to the same value for all process control units 4 1 -4n, for example, about 4 seconds.
クラスタ制御ユニツト5は、プロセス制御ユニ
ツトの故障を確認すると、冗長ユニツト6にその
バツクアツプを指令する。 When cluster control unit 5 confirms that a process control unit has failed, it instructs redundant unit 6 to back it up.
冗長ユニツト6は、クラスタ制御ユニツト5か
らの指令に従つて、故障したプロセス制御ユニツ
トのバツクアツプを行なう。 The redundant unit 6 performs backup of a failed process control unit according to instructions from the cluster control unit 5.
バツクアツプ時のデータ処理に使用されるデー
タベースは、予めアツプロードされているものの
中から次のようにした選ばれ、メインメモリに移
送して利用される。 The database used for data processing during backup is selected from those previously uploaded as follows, and is transferred to the main memory for use.
いま、プロセス制御ユニツト42が故障し、そ
のバツクアツプが第6図のt0時点で指令され、こ
のとき、冗長ユニツト6は、たまたまプロセス制
御ユニツト45のデータベースをアツプロード中
であるとすると、冗長ユニツト6は、プロセス制
御ユニツト42のデータベースとしては、t0時点
からウオツチドツグ・タイマの時限値T以上に過
去のものを採用する。いま、プロセス制御ユニツ
ト42のデータベースは、t-3時点とt-11時点の2
つがアツプロードされているが、t-3時点がウオ
ツチドツグ・タイマの時限値T以上の位置にある
とすると、t-11時点のデータベースが採用され
る。 Now, suppose that the process control unit 42 has failed and its backup is ordered at time t0 in FIG. 6, and at this time the redundant unit 6 happens to be uploading the database of the process control unit 45 . The unit 6 employs, as the database of the process control unit 42 , a database that is past the time limit T of the watchdog timer from time t0 . Now, the database of the process control unit 42 has two data at time t -3 and time t -11 .
is uploaded, but if time t -3 is at a position equal to or greater than the time limit T of the watchdog timer, then the database at time t -11 is adopted.
ウオツチドツグ・タイマの時限値以内の位置
t-3にデータベースがあるということは、それが
アツプロードされた時点では、すでにプロセス制
御ユニツト42の故障が発生しているということ
であり、そのため、その時点のデータベースは、
プロセツサの暴走によつて破壊されている可能性
がある。そこで、そのようなおそれのあるデータ
ベースは避けて、正しいことが確実な、もつと過
去のデータベースを採用する。なお、t=1.5、
T=4の場合は、t=-3時点は−4.5秒であり、
ウオツチドツグ・タイマの時点値をわずかに外れ
ているが、きわどい時点なので採用は避けたほう
がよい。現実的には、ウツオチドツグ・タイマの
時限値の1.5倍以上離すのが妥当である。 Position within watchdog timer time limit value
The fact that there is a database at t -3 means that a failure has already occurred in the process control unit 42 when it is uploaded, so the database at that point is
It may have been destroyed by a runaway processor. Therefore, avoid databases that pose such a risk, and use databases that are certain to be correct, preferably from the past. Note that t=1.5,
In the case of T = 4, the time of t = -3 is -4.5 seconds,
Although it is slightly outside the point value of the watchdog timer, it is a critical point so it is better to avoid using it. In reality, it is appropriate to set the distance at least 1.5 times the time limit value of the waiting timer.
以上のことを可能にするために、アツプロード
領域の数をプロセス制御ユニツト4jの数よりも
多く設けたのであるが、その数が、第6図のよう
に、プロセス制御ユニツト数の2倍とは限らず
に、ウオツチドツグ・タイマの時限値Tあるいは
それよりもある程度余裕をみた値と同じ時間内に
アツプロードされる複数のデータベースを受け入
れられるだけ、プロセス制御ユニツト4jの数よ
りも多ければよい。ウオツチドツグ・タイマの時
限値Tと同じ時間歌にアツプロードされるデータ
ベースの数はT/tとなるから、アツプロード領
域の数はn+T/t以上の整数であればよい。 In order to make the above possible, the number of upload areas is greater than the number of process control units 4j , but as shown in Figure 6, the number of upload areas is twice the number of process control units. However, it is sufficient that the number of databases is greater than the number of process control units 4j and can accept a plurality of databases uploaded within the same time as the watchdog timer's time limit T or a value with some margin above it. Since the number of databases uploaded to a song for the same time as the time limit T of the watchdog timer is T/t, the number of upload areas may be an integer greater than or equal to n+T/t.
第6図の例でいえば、n=8、T/t=2.7で
あるから、アツプロード領域数は11あればよいこ
とになるが余裕をみて12とする。そうすると、ア
ツプロード領域0および13〜15は本来不要と
なる。しかし、この部分があると、アツプロード
領域数がプロセス制御ユニツト数の2倍となり、
各アツプロード領域が各プロセス制御ユニツトに
固定的に対応するので都合がよい。これに対し
て、アツプロード領域数を12とすると、第7図の
ように、各領域にアツプロードされるデータベー
スはアツプロードの周期に従つてサイクリツクに
変化する。 In the example shown in FIG. 6, since n=8 and T/t=2.7, the number of upload areas should be 11, but it is set to 12 to provide a margin. In this case, upload areas 0 and 13 to 15 are essentially unnecessary. However, with this part, the number of upload areas is twice the number of process control units,
Advantageously, each upload area corresponds fixedly to each process control unit. On the other hand, if the number of upload areas is 12, the database uploaded to each area changes cyclically in accordance with the upload cycle, as shown in FIG.
バツクアツプは、上記のようにして採用したデ
ータベースを用いて、冗長ユニツト6のインテリ
ジエンスが、通信を介してプロセス制御ユニツト
42の入出力器I/Oを駆使することによつて行
なう。すなわち、冗長ユニツト6のインテリジエ
ンスが、プロセス制御ユニツト42のインテリジ
エンスにとつて代つた形でバツクアツプを行な
う。プロセス制御ユニツト42は、DMA機能を有
する内部通信制御器NCMを持つているので、そ
のような入出力器I/Oの駆使が可能となる。す
なわち、入出力器I/Oの信号線の切り換えを全
く必要とせずに、バツクアツプが行なえる。この
ため、冗長ユニツト6はプロセス制御ユニツト4
2の入出力器I/Oと同一のものを持つ必要がな
く、したがつて、プロセス制御ユニツト42は、
自己にとつて必要な入出力器I/Oを自由に持つ
ことを妨げられない。 Backup is performed by the intelligence of the redundant unit 6 making full use of the input/output device I/O of the process control unit 42 via communication using the database adopted as described above. That is, the intelligence of the redundant unit 6 performs the backup in place of the intelligence of the process control unit 42 . Since the process control unit 42 has an internal communication controller NCM having a DMA function, it is possible to make full use of such input/output devices I/O. In other words, backup can be performed without any need to switch the input/output device I/O signal lines. For this reason, the redundant unit 6 is connected to the process control unit 4.
It is not necessary to have the same input/output device I/O as that of process control unit 42 .
You are not prevented from freely having the input/output device I/O that you need.
バツクアツプ中は、プロセス制御ユニツト42
以外のものに対するデータベース収集が、周期的
に行なわれる。データベースの収集、クラスタの
内部制御用の内部通信線7を共用して通信によつ
て行なわれるので、専用の接続線は不要となる。
またデータベースは、プロセス制御ユニツト42
が正常な間に読み出しておいたものを採用するか
ら、データベースの正常性は保証されている。し
たがつて、故障したプロセス制御ユニツト42か
ら異常なデータベースを引き継いで、バツクアツ
プそのものも異常になるという、いわゆる共倒れ
現象は容易に防止される。 During backup, process control unit 4 2
Database collection for other items is performed periodically. Since the collection of the database and the internal communication line 7 for internal control of the cluster are carried out through communication, a dedicated connection line is not required.
The database also includes process control unit 4 2
Since the data read while the database is normal is used, the normality of the database is guaranteed. Therefore, the so-called co-collapse phenomenon in which an abnormal database is taken over from the failed process control unit 42 and the backup itself becomes abnormal can be easily prevented.
バツクアツプ中に、プロセス制御ユニツト42
の故障したインテリジエンスの修理あるいは交換
が行なわれる。修理あるいは交換により正常な機
能を回復したインテリジエンスは、機能回復信号
(レデイ信号)を発生する。この信号が通信され
ると、クラスタ制御ユニツト6は、プロセス制御
ユニツト42のインテリジエンスの機能回復を認
識し、自動的にあるいはオペレータの手動操作に
従つて、冗長ユニツト6にバツクアツプの解除を
指令する。 During backup, process control unit 4 2
Repair or replacement of faulty intelligence will be carried out. The intelligence, which has recovered its normal function through repair or replacement, generates a function recovery signal (ready signal). When this signal is communicated, the cluster control unit 6 recognizes the functional recovery of the intelligence of the process control unit 42 and instructs the redundant unit 6 to release the backup, either automatically or according to the manual operation of the operator. do.
この指令に従つて、冗長ユニツト6は、アツプ
ロードメモリNMU中のプロセス制御ユニツト4
2用のデータベースを、通信を介してプロセス制
御ユニツト42のメモリNMUのデータベース領
域に写しかえ、次いで、そのインテリジエンスを
起動してバツクアツプからぬけだす。 According to this command, the redundant unit 6 replaces the process control unit 4 in the uploaded memory NMU.
2 is copied to the database area of the memory NMU of the process control unit 42 via communication, and then the intelligence is activated to escape from the backup.
第8図に、本発明の他の実施例を示す。この実
施例は、クラスタの内外の通信系統を冗長化し、
信頼性をさらに高めたものである。すなわち、外
部通信線路は31,32の2系統設けられ、内部通
信線も71,72の2系統設けられ、かつ、これら
に対応して、クラスタ制御ユニツト5には、外部
通信制御器FCAと内部通信制御器NCMがいずれ
も2系統ずつ設けられ、プロセス制御ユニツト4
1〜4nと冗長ユニツト6には、内部通信制御器
NCMが2系統設けられる。 FIG. 8 shows another embodiment of the invention. This embodiment makes communication systems inside and outside the cluster redundant,
This further increases reliability. That is, two external communication lines 3 1 and 3 2 are provided, and two internal communication lines 7 1 and 7 2 are provided, and correspondingly, the cluster control unit 5 has an external communication control line. There are two systems each for the controller FCA and the internal communication controller NCM, and the process control unit 4
1 to 4n and the redundant unit 6 have an internal communication controller.
Two NCM systems will be provided.
以上、本発明を好ましい実施例について説明し
たが、本発明は特許請求の範囲内において様々な
実施態様がありうる。 Although the present invention has been described above with reference to preferred embodiments, the present invention may have various embodiments within the scope of the claims.
第1図は、本発明が適用される分散形制御装置
の概念的構成図、第2図は、本発明実施例の概念
的構成図、第3図、第4図および第5図は、それ
ぞれ第2図の一部の詳細構成図、第6図および第
7図は、アツプロード・メモリの概念的構成図、
第8図は、本発明の他の実施例の概念的構成図で
ある。
11〜1k……制御ステーシヨン、21〜2n……
マスタステーシヨン、3……通信線路、41〜4
n……プロセス制御ユニツト、5……クラスタ制
御ユニツト、6……冗長ユニツト、7……内部通
信線。
FIG. 1 is a conceptual block diagram of a distributed control device to which the present invention is applied, FIG. 2 is a conceptual block diagram of an embodiment of the present invention, and FIGS. 3, 4, and 5 are respectively A detailed configuration diagram of a part of FIG. 2, FIGS. 6 and 7 are conceptual configuration diagrams of upload memory,
FIG. 8 is a conceptual block diagram of another embodiment of the present invention. 1 1 to 1 k ...control station, 2 1 to 2 n ...
Master station, 3...Communication line, 4 1 to 4
n...Process control unit, 5...Cluster control unit, 6...Redundant unit, 7...Internal communication line.
Claims (1)
ロセス制御ユニツトと、インテリジンエスを持つ
冗長ユニツトとを通信線によつて接続した構成を
有するn+1冗長化制御装置であつて、 各プロセス制御ユニツトは、ウオツチドツグ・
タイマのタイムアツプに従つて故障を表示する手
段を有し、 冗長ユニツトは、プロセス制御ユニツトからア
ツプロードされるデータベースの記憶手段とし
て、通信線に繋る全てのプロセス制御ユニツトの
データベースを記憶できる容量よりも、少くとも
プロセス制御ユニツトのウオツチドツグ・タイマ
の時限値に相当する時間にアツプロードされるデ
ータベースを記憶できる容量だけ大きい容量を持
つ記憶手段と、この記憶手段に、通信線に繋る全
てのプロセス制御ユニツトのデータベースを周期
的に順番にかつ循環的に記憶させるアツプロード
手段と、プロセス制御ユニツトのいずれかが故障
を表示したとき、その時点よりもプロセス制御ユ
ニツトのウオツチドツグ・タイマの時限値以上前
にアツプロードされたそのプロセス制御ユニツト
のデータベースを用いてそのプロセス制御ユニツ
トのインテリジエンスの代りにそのプロセス制御
ユニツトの入出力部を駆使してプロセス制御を行
なう手段とを有する、 n+1冗長化制御装置。[Scope of Claims] 1. An n+1 redundant control device having a configuration in which a plurality of process control units having intelligence and input/output units and a redundant unit having intelligence are connected by a communication line, Each process control unit has a watchdog
The redundant unit has a means for indicating a failure according to the time-up of the timer, and as a storage means for the database uploaded from the process control unit, the redundant unit has a capacity larger than that for storing the databases of all the process control units connected to the communication line. , a storage means with a capacity large enough to store at least the database uploaded at a time corresponding to the time limit of the watchdog timer of the process control unit, and all process control units connected to the communication line to this storage means. uploading means for periodically and sequentially and circularly storing a database of the process control unit; An n+1 redundant control device, comprising means for controlling a process by making full use of the input/output section of the process control unit instead of the intelligence of the process control unit using the database of the process control unit.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP57117571A JPS598006A (en) | 1982-07-06 | 1982-07-06 | Contrller for n+1 redundancy |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP57117571A JPS598006A (en) | 1982-07-06 | 1982-07-06 | Contrller for n+1 redundancy |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JPS598006A JPS598006A (en) | 1984-01-17 |
| JPH0327923B2 true JPH0327923B2 (en) | 1991-04-17 |
Family
ID=14715110
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP57117571A Granted JPS598006A (en) | 1982-07-06 | 1982-07-06 | Contrller for n+1 redundancy |
Country Status (1)
| Country | Link |
|---|---|
| JP (1) | JPS598006A (en) |
-
1982
- 1982-07-06 JP JP57117571A patent/JPS598006A/en active Granted
Also Published As
| Publication number | Publication date |
|---|---|
| JPS598006A (en) | 1984-01-17 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US4941087A (en) | System for bumpless changeover between active units and backup units by establishing rollback points and logging write and read operations | |
| US4484273A (en) | Modular computer system | |
| US20040153727A1 (en) | Method and apparatus for recovering redundant cache data of a failed controller and reestablishing redundancy | |
| EP0476962B1 (en) | System for configuring a shared storage | |
| JPS6310462B2 (en) | ||
| US4631661A (en) | Fail-safe data processing system | |
| JPS6321929B2 (en) | ||
| CN113946532B (en) | A method for protecting satellite-borne 1553B control bus from failure | |
| JPS5868104A (en) | Redundant decentralized controller | |
| JPS5816497B2 (en) | Data processing system with system common parts | |
| JPS5917467B2 (en) | Control computer backup method | |
| JPS5911401A (en) | (n+1)redundancy controller | |
| JPS598006A (en) | Contrller for n+1 redundancy | |
| JPS6333839B2 (en) | ||
| JPS5868102A (en) | Redundant decentralized controller | |
| JPS5941002A (en) | Redundancy dispersion type controlling device | |
| JPS6116646A (en) | Decentralized control system | |
| JPS6113627B2 (en) | ||
| JPS60159902A (en) | Duplex system programmable controller | |
| JPS5832424B2 (en) | Dual hierarchy system | |
| JPS5868103A (en) | Redundant decentralized controller | |
| JPS595302A (en) | Plant distributed control method | |
| JPH0147810B2 (en) | ||
| JPH05265662A (en) | Backup device for secondary storage device | |
| JPS58127263A (en) | Switching device |