WO2016144296A1 - Bump-less control upgrade - Google Patents

Bump-less control upgrade Download PDF

Info

Publication number
WO2016144296A1
WO2016144296A1 PCT/US2015/019207 US2015019207W WO2016144296A1 WO 2016144296 A1 WO2016144296 A1 WO 2016144296A1 US 2015019207 W US2015019207 W US 2015019207W WO 2016144296 A1 WO2016144296 A1 WO 2016144296A1
Authority
WO
WIPO (PCT)
Prior art keywords
control code
control
industrial asset
output
processor
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2015/019207
Other languages
French (fr)
Inventor
Wesley Michael SKEFFINGTON
Jr. Austars Raymond Schnore
Daniel White Sexton
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
General Electric Co
Original Assignee
General Electric Co
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by General Electric Co filed Critical General Electric Co
Priority to PCT/US2015/019207 priority Critical patent/WO2016144296A1/en
Publication of WO2016144296A1 publication Critical patent/WO2016144296A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F8/00Arrangements for software engineering
    • G06F8/60Software deployment
    • G06F8/65Updates
    • G06F8/656Updates while running

Definitions

  • the subject matter disclosed herein generally relates to providing updates to industrial assets, and more specifically automatically managing system updates to industrial assets while maintaining system operation.
  • the process of updating industrial assets may require an operator to be physically present at the industrial asset to apply the update.
  • the industrial asset may be controlled individually, there may be a number of different interfaces and tools which have no relation to interfaces and/or tools of other industrial assets.
  • an operator must be knowledgeable in a number of interfaces to properly apply updates to the industrial asset.
  • the required training may be exceedingly costly and time consuming.
  • current systems often must be shut down for software upgrades, which is costly for customers which are leveraging industrial control systems in particular environments such as, for example, power generation, oil and gas, or similar industries.
  • the approaches described herein provide a scalable mechanism which remotely and automatically upgrades, commissions, requisitions, and/or maintains an industrial control system.
  • the approaches are based on a local agent interacting with a web-based server such as a cloud or on-site server backend that provide safe deployment of control and/or other system software based components.
  • systems may be managed at a virtual machine level and may be upgraded without having to cause the system controller to shut down. Further, these approaches may allow for control functionality to be moved to different locations without causing the industrial asset to be bumped or temporarily offline. Further, these approaches may allow a common manner to deploy and maintain security credentials for a number of functions and virtual machines on a given controls platform.
  • the approaches described herein may be used to reduce or eliminate the need for human interaction when performing updates as well as the need to disrupt the process being controlled. Further, these approaches may provide reduced commissioning and maintenance time and expenses to end users and system developers, and reduce costs over the lifecycle of a given asset and control system. By providing updates to the industrial assets, enhanced integrity and security of the system results as the updates improve the correctness of the potentially complex system deployment while allowing up to date security patches as they become available. These approaches may be scaled to upgrade systems at a fleet level as opposed to a single device level.
  • an apparatus for upgrading an industrial asset includes an interface having a programming input and an output and at least one processor coupled to the interface.
  • the at least one processor is configured to control the operation of the industrial asset through the output at least partially by a first control code.
  • the processor executed the first and second control codes in parallel such that the inputs and the outputs of the first and second control code are in communication and synchronized with each other.
  • the processor further is configured to switch control of the industrial asset such that the second control at least partially controls the industrial asset.
  • the processor is further configured to remove the first control code such that the second control code is the only control code present.
  • the processor may alternatively maintain the first control code to act as a backup control code in the event that the first control code experiences an operational failure.
  • the processor may switch control of the industrial asset without interruption of operation of the industrial asset. In other words, the asset may continue to operate without requiring a bump, or temporarily halting operation of the asset to complete the upgrade.
  • the processor further may switch control of the industrial asset such that the second control code at least partially controls the industrial asset through the output.
  • the industrial asset may be at least one of gas turbines, steam turbines, generators, power plants, compressors, locomotives, energy storage devices, and/or generators. Other examples are possible.
  • the first and second control code are stored on a number of remote computing devices having different locations.
  • the first and second control codes may be implemented at any location while still providing control over the industrial asset.
  • an operator is not required to be physically present at the asset to provide the upgrade, as the updates may be managed at any number of locations.
  • a first control code which controls the operation of an industrial asset is executed via a first output.
  • the operation of a second control code is then synchronized with the first control code.
  • control of the industrial asset is switched from the first control code to the second control code via a second output.
  • executing and switching to the second output of the second control code includes upgrading operation of the industrial asset to function via the second control code.
  • the output of the second control code may be applied to the industrial asset without halting operation thereof.
  • the first and second control codes are executed via at least one processor configured to execute the first and the second control codes simultaneously. Further in some examples, at least one input from the industrial asset is synchronized to the first and second control code.
  • an industrial asset is at least partially controlled by executing a first control code via a first output.
  • a second control code is then introduced to the industrial asset, and the first and second control codes are executed in parallel such that the inputs and the outputs of the first and the second control codes are in communication and synchronized with each other.
  • control of the industrial asset is switched such that the second control code at least partially controls the industrial asset via the second output.
  • the first control code is removed. In other examples, the first control code is operated in parallel with the operation of the second control code to provide a layer of redundancy and/or security.
  • FIG. 1 comprises a flow chart illustrating an exemplary bump-less control upgrade approach according to various embodiments of the present invention
  • FIG. 2 comprises a flow chart illustrating an exemplary bump-less control upgrade approach according to various embodiments of the present invention
  • FIG. 3 comprises a block flow diagram further illustrating the exemplary bump- less control upgrade approach of FIG. 2 according to various embodiments of the present invention.
  • FIG. 4 comprises a block diagram illustrating an exemplary bump-less control upgrade approach according to various embodiments of the present invention.
  • a control circuit or agent function operates as an integral part of a system for security and management purposes such as a system and security agent is responsible for initiating communication to various components of the control system, establishing and ensuring secure data connections, and/or identifying available updates.
  • hypervisor By introducing a hypervisor in combination with synchronized networking technologies, system update functions may be synchronously performed with the underlying control process, thus allowing an update without disrupting the main functionality of the process in the control system.
  • hypervisor and as used herein it is meant a virtual machine manager or management apparatus that provides isolation and coordination of virtual machines within an embedded control system.
  • buddy-less as used herein is meant to describe the ability to create an additional control code instance to control an industrial asset and switch to this control code instance without causing an interrupt to the industrial asset.
  • the hypervisor By functionally partitioning a multi-core computer device, the hypervisor causes individual partitions to act as unique devices which perform different tasks. Thus, the hypervisor may implement one partition to control the asset using the first control code, and a second partition to control the asset using the second, updated control code. It is understood that the hypervisor may partition a multi-core computer device in any manner or combination, for example a quad core computer device may be partitioned to two dual-core partitions, a mutli- core partition with the first having three cores and the second having a single core, and so on. Other examples are possible.
  • an edge device may be integral to or communicatively coupled with an industrial asset to provide the industrial asset with control functionalities.
  • a hypervisor to create an additional control code running in parallel with the first control code
  • time sensitive networking the inputs from the industrial asset may be synchronized between the two control codes, and these mechanisms may allow for the outputs from the control codes to be synchronized.
  • the system Upon determining that the inputs, outputs, and intermediate state information are synchronized, the system instructs the additional control code to transmit subsequent controls to the industrial asset, thus effectively replacing the first control code for the industrial asset.
  • the system agent monitors the output of both control codes to ensure they are both synchronized.
  • a first control code is executed. This first control code controls operation of an industrial asset via a first output.
  • the operation of a second control code is synchronized with the first control code.
  • a second output of the second control code is executed and applied to control the industrial asset.
  • the second control code may include upgrades to the control of the industrial asset. Upon executing and switching to the second output of the second control code, the industrial asset may be updated to function via the second control code. It is understood that the second control code may include any number of upgrades or updates used to improve operation and/or functionality of the industrial asset.
  • the second output of the second control code is applied in a bump-less fashion, that is, without halting the operation of the industrial asset.
  • the second control code is instructed to begin providing or transmitting outputs to the industrial asset at a predetermined time in a coordinated manner with the first control code.
  • the first and second control code may be executed via at least one processor that is configured to execute the first and second control codes simultaneously.
  • this processor may be a hypervisor capable of executing multiple instances of control code and performing various additional tasks related to the operation of the industrial asset and the corresponding system. It is understood that any number of processors may be used to
  • first and the second control code may be located centrally or remotely from one another.
  • first and the second control code may be located on a single computational device or located in remote locations.
  • individuals at remote locations may provide upgrades and updates to industrial assets as required.
  • an alternate approach 200 for a bump-less control upgrade is described.
  • an industrial asset is at least partially controlled by executing a first control code via a first output.
  • the first control code may control the entire operation of the industrial asset.
  • a second control code is introduced to the industrial asset.
  • the first and the second control codes are executed in parallel or simultaneously.
  • the first and the second control code may be in communication and synchronized with each other.
  • control of the industrial asset is switched such that the second control code at least partially controls the industrial asset via a second output.
  • the first control code is subsequently removed for various reasons such as to free up memory or to reduce the possibility of reverting operation to the previous control code version.
  • the first control code may be operated in parallel with the operation of the second control code, but outputs from the first control code are not sent to the industrial asset.
  • the first control code may act as a redundant or backup code should the second control code incur a failure or other issue.
  • the step 208 of switching control of the industrial asset may occur without interruption of operation thereof.
  • the approach 200 may include a system having a system agent, an I/O synchronization mechanism, system partitioning functionality, a multi-core controller or a synchronized network, and a number of control codes or applications.
  • the system agent is responsible for interfacing with a back-end server in a secure manner and managing the introduction, coordination, and removal of virtual machines or VMs.
  • the I/O synchronization performs the task of ensuring various versions of the control application are synchronized in order to ensure the transition between control applications will be bump-less.
  • the system partitioning functionality is responsible for partitioning the multi-core controller, processing device, or synchronized network to properly control multiple control applications.
  • the control applications are responsible for providing controls to the industrial or critical asset.
  • the approach 200 is running using the first or current version of the control application.
  • the approach 200 introduces a new version of the control application and it is in an inactive state while the first control application remains active.
  • the first and second versions of the control application run in parallel due to the system agent synchronizing the first and second version of the control application. Necessary data is synced between the control applications.
  • the system switches the control application that actively controls the asset, making the first version of the control application inactive.
  • the first version of the control application is removed from the system.
  • the first version of the control application may remain as a shadow application to act as a redundant or fall-back version.
  • the system is thereby upgraded without disrupting the industrial asset.
  • the bump-less upgrade system 400 includes an interface 402 having a programming input 404 and an output 406, a controller or processor 408, and a memory 410.
  • the system 400 may also include any number of industrial assets 412.
  • the interface 402 is a computer-based program and/or hardware configured to accept controller activity or a signal or communication from a computing device such as a personal computer, a mobile computing device, a control system or server at the programming input 404 and transmit the generated communication at the output 406 to the industrial asset 412, which may be any number of components in an industrial environment, for example, wind turbines, distributed power generators, power plants, and the like. Other examples are possible.
  • the function of the interface 402 is to allow the processor 408 to communicate with the industrial asset 412.
  • the processor 408 is any combination of hardware devices and/or software selectively chosen to process controller activity related to a control system and perform appropriate functions to be sent to the industrial asset 412 via the output 406.
  • the processor 408 includes instructions that determine functionalities and operation of the control codes store on the memory 410. It is understood that any number of processors may be used in the system 400 and may be located either centrally or remotely within the system 400.
  • the memory 410 may be any data storage medium capable of storing data thereto.
  • the memory 410 may be an integral unit of the system 400, it may be physically coupled to the interface 402 and the processor 408 through a data connection (e.g., an Ethernet connection), or it may communicate with the system 400 through any number of wireless communications protocols.
  • the memory 410 includes the first and the second control codes (not shown). These control codes may be any type of data file capable of storing a plurality of variables and instructions thereto. It is understood that any number of control codes may be used, and that any number of individual memory modules may be used which either may be centrally or remotely located. [0039] It will be appreciated that the various components described herein may be implemented using a general purpose processing device executing computer instructions stored in memory. Further, it is understood that the processor 408 may be a standalone component or may be incorporated into the interface 402.
  • the industrial asset 412 may include any number of components which receive instructions or commands from the system 400.
  • the industrial asset may include wind turbines, distributed power generators, power plants, and the like, or any number of these components grouped together. Other examples are possible.
  • the processor 408 is configured to at least partially control operation of the industrial asset 412 through the output 406 using a first control code.
  • the processor 408 Upon receiving a second control code through the programming input 404, the processor 408 is configured to execute the first and the second control codes in parallel such that the inputs and the outputs of the first and second control codes are in communication and synchronized with each other.
  • the processor 408 is further configured to switch control of the industrial asset 412 such that the second control code at least partially controls the industrial asset 412 via the output 406.
  • the processor 408 is configured to switch control of the industrial asset 412 without interruption of operation of the industrial asset 412
  • the processor may receive the second control code or notification of its existence via any number of known methods. For example, a user or operator may generate an update to the control code and transmit it to downstream systems, at which point it may be received by the processor 408. Other examples are possible.
  • the processor 408 is configured to remove the first control code from the memory 410. However, in some approaches, the processor 408 is configured to retain the first control code in the memory 410 should a backup or redundancy be desired.
  • the first and the second control code are stored on memory 410 on a plurality of remote computing devices having different locations.

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Stored Programmes (AREA)

Abstract

A bump-less control upgrade system and approaches are provided where a first control code is executed which controls the operation of an industrial asset. The operation of a second control code is synchronized with the operation of the first control code. Upon the second control code becoming synchronized with the first control code, the system executes and switches from the first control code to the second control code to control the industrial asset.

Description

BUMP-LESS CONTROL UPGRADE
Background of the Invention Field of the Invention
[0001 ] The subject matter disclosed herein generally relates to providing updates to industrial assets, and more specifically automatically managing system updates to industrial assets while maintaining system operation.
Brief Description of the Related Art
[0002] A variety of approaches have been used to manage and update industrial assets
(e.g., power plants, gas turbines, gas compressors, steam turbines, wind turbines, generators, locomotives, and energy storage devices, to name a few examples), including the use of manually updating the industrial assets using physical connections and/or components. System integrators and complex system owners must deploy and maintain industrial control systems for their industrial assets. Industrial assets may be controlled on a one-by-one basis in which individual assets are configured or managed separately from other assets.
[0003] In some circumstances, the process of updating industrial assets may require an operator to be physically present at the industrial asset to apply the update. Because the industrial asset may be controlled individually, there may be a number of different interfaces and tools which have no relation to interfaces and/or tools of other industrial assets. Thus, an operator must be knowledgeable in a number of interfaces to properly apply updates to the industrial asset. The required training may be exceedingly costly and time consuming. Further, current systems often must be shut down for software upgrades, which is costly for customers which are leveraging industrial control systems in particular environments such as, for example, power generation, oil and gas, or similar industries. [0004] The above-mentioned problems have resulted in some user dissatisfaction with previous approaches.
Brief Description of the Invention
[0005] The approaches described herein provide a scalable mechanism which remotely and automatically upgrades, commissions, requisitions, and/or maintains an industrial control system. The approaches are based on a local agent interacting with a web-based server such as a cloud or on-site server backend that provide safe deployment of control and/or other system software based components.
[0006] By building the system on top of a hypervisor based platform in combination with time synchronized networks, systems may be managed at a virtual machine level and may be upgraded without having to cause the system controller to shut down. Further, these approaches may allow for control functionality to be moved to different locations without causing the industrial asset to be bumped or temporarily offline. Further, these approaches may allow a common manner to deploy and maintain security credentials for a number of functions and virtual machines on a given controls platform.
[0007] So configured, the approaches described herein may be used to reduce or eliminate the need for human interaction when performing updates as well as the need to disrupt the process being controlled. Further, these approaches may provide reduced commissioning and maintenance time and expenses to end users and system developers, and reduce costs over the lifecycle of a given asset and control system. By providing updates to the industrial assets, enhanced integrity and security of the system results as the updates improve the correctness of the potentially complex system deployment while allowing up to date security patches as they become available. These approaches may be scaled to upgrade systems at a fleet level as opposed to a single device level.
[0008] In some approaches, an apparatus for upgrading an industrial asset is provided and includes an interface having a programming input and an output and at least one processor coupled to the interface. The at least one processor is configured to control the operation of the industrial asset through the output at least partially by a first control code. Upon the apparatus receiving a second control code via the programming input, the processor executed the first and second control codes in parallel such that the inputs and the outputs of the first and second control code are in communication and synchronized with each other. The processor further is configured to switch control of the industrial asset such that the second control at least partially controls the industrial asset.
[0009] In some approaches, the processor is further configured to remove the first control code such that the second control code is the only control code present. The processor may alternatively maintain the first control code to act as a backup control code in the event that the first control code experiences an operational failure. In many approaches, the processor may switch control of the industrial asset without interruption of operation of the industrial asset. In other words, the asset may continue to operate without requiring a bump, or temporarily halting operation of the asset to complete the upgrade. The processor further may switch control of the industrial asset such that the second control code at least partially controls the industrial asset through the output.
[0010] In many of these approaches, the industrial asset may be at least one of gas turbines, steam turbines, generators, power plants, compressors, locomotives, energy storage devices, and/or generators. Other examples are possible.
[0011] In some examples, the first and second control code are stored on a number of remote computing devices having different locations. Thus, the first and second control codes may be implemented at any location while still providing control over the industrial asset. Thus, an operator is not required to be physically present at the asset to provide the upgrade, as the updates may be managed at any number of locations.
[0012] In many of these approaches, a first control code which controls the operation of an industrial asset is executed via a first output. The operation of a second control code is then synchronized with the first control code. Upon the second control code becoming synchronized with the first control code, control of the industrial asset is switched from the first control code to the second control code via a second output. [0013] In some of these approaches, executing and switching to the second output of the second control code includes upgrading operation of the industrial asset to function via the second control code. The output of the second control code may be applied to the industrial asset without halting operation thereof. In numerous approaches, the first and second control codes are executed via at least one processor configured to execute the first and the second control codes simultaneously. Further in some examples, at least one input from the industrial asset is synchronized to the first and second control code.
[0014] In other examples, an industrial asset is at least partially controlled by executing a first control code via a first output. A second control code is then introduced to the industrial asset, and the first and second control codes are executed in parallel such that the inputs and the outputs of the first and the second control codes are in communication and synchronized with each other. Upon synchronizing the first and the second control codes, control of the industrial asset is switched such that the second control code at least partially controls the industrial asset via the second output. In many of these approaches, the control of the industrial asset occurs without interruption of operation thereof.
[0015] In some of these examples, the first control code is removed. In other examples, the first control code is operated in parallel with the operation of the second control code to provide a layer of redundancy and/or security.
Brief Description of the Drawings
[0016] For a more complete understanding of the disclosure, reference should be made to the following detailed description and accompanying drawings wherein:
[0017] FIG. 1 comprises a flow chart illustrating an exemplary bump-less control upgrade approach according to various embodiments of the present invention;
[0018] FIG. 2 comprises a flow chart illustrating an exemplary bump-less control upgrade approach according to various embodiments of the present invention; [0019] FIG. 3 comprises a block flow diagram further illustrating the exemplary bump- less control upgrade approach of FIG. 2 according to various embodiments of the present invention; and
[0020] FIG. 4 comprises a block diagram illustrating an exemplary bump-less control upgrade approach according to various embodiments of the present invention.
[0021] Skilled artisans will appreciate that elements in the figures are illustrated for simplicity and clarity. It will further be appreciated that certain actions and/or steps may be described or depicted in a particular order of occurrence while those skilled in the art will understand that such specificity with respect to sequence is not actually required. It will also be understood that the terms and expressions used herein have the ordinary meaning as is accorded to such terms and expressions with respect to their corresponding respective areas of inquiry and study except where specific meanings have otherwise been set forth herein.
Detailed Description of the Invention
[0022] Approaches are provided that overcome the need to take an industrial asset offline to apply upgrades to its control system or systems. As such, commissioning times associated with upgrade may be reduced, and problems and system analysis may occur with a minimal amount of downtime, which may assist an end user in determining statuses of industrial assets and their surrounding environment. In one aspect, a control circuit or agent function operates as an integral part of a system for security and management purposes such as a system and security agent is responsible for initiating communication to various components of the control system, establishing and ensuring secure data connections, and/or identifying available updates. By introducing a hypervisor in combination with synchronized networking technologies, system update functions may be synchronously performed with the underlying control process, thus allowing an update without disrupting the main functionality of the process in the control system. By "hypervisor" and as used herein it is meant a virtual machine manager or management apparatus that provides isolation and coordination of virtual machines within an embedded control system. Further, it is understood that the term "bump-less" as used herein is meant to describe the ability to create an additional control code instance to control an industrial asset and switch to this control code instance without causing an interrupt to the industrial asset.
[0023] By functionally partitioning a multi-core computer device, the hypervisor causes individual partitions to act as unique devices which perform different tasks. Thus, the hypervisor may implement one partition to control the asset using the first control code, and a second partition to control the asset using the second, updated control code. It is understood that the hypervisor may partition a multi-core computer device in any manner or combination, for example a quad core computer device may be partitioned to two dual-core partitions, a mutli- core partition with the first having three cores and the second having a single core, and so on. Other examples are possible.
[0024] In one specific example, an edge device may be integral to or communicatively coupled with an industrial asset to provide the industrial asset with control functionalities. By using a hypervisor to create an additional control code running in parallel with the first control code, using time sensitive networking, the inputs from the industrial asset may be synchronized between the two control codes, and these mechanisms may allow for the outputs from the control codes to be synchronized. Upon determining that the inputs, outputs, and intermediate state information are synchronized, the system instructs the additional control code to transmit subsequent controls to the industrial asset, thus effectively replacing the first control code for the industrial asset. The system agent then monitors the output of both control codes to ensure they are both synchronized.
[0025] Referring now to FIG. 1, one example of a bump-less control upgrade approach
100 is described. First, at step 102, a first control code is executed. This first control code controls operation of an industrial asset via a first output. At step 104, the operation of a second control code is synchronized with the first control code. At step 106, upon synchronizing the operation of the first and the second control codes, a second output of the second control code is executed and applied to control the industrial asset.
[0026] It is understood that by "synchronized" and as used herein, it is meant the first and the second control codes perform the same functions at the same time. Further all of the internal state information required to run the control is effectively the same between first and second control codes, or they are similar enough such that upon transitioning from the first control code to the second control code, there is little to no interruption of the control of the industrial asset.
[0027] In some examples, the second control code may include upgrades to the control of the industrial asset. Upon executing and switching to the second output of the second control code, the industrial asset may be updated to function via the second control code. It is understood that the second control code may include any number of upgrades or updates used to improve operation and/or functionality of the industrial asset.
[0028] In many approaches, the second output of the second control code is applied in a bump-less fashion, that is, without halting the operation of the industrial asset. To do so, the second control code is instructed to begin providing or transmitting outputs to the industrial asset at a predetermined time in a coordinated manner with the first control code.
[0029] The first and second control code may be executed via at least one processor that is configured to execute the first and second control codes simultaneously. In one example, this processor may be a hypervisor capable of executing multiple instances of control code and performing various additional tasks related to the operation of the industrial asset and the corresponding system. It is understood that any number of processors may be used to
synchronize the first and the second control code, and these processors may be located centrally or remotely from one another. Similarly, the first and the second control code may be located on a single computational device or located in remote locations. As such, individuals at remote locations may provide upgrades and updates to industrial assets as required.
[0030] Referring now to FIG. 2, an alternate approach 200 for a bump-less control upgrade is described. First, at step 202, an industrial asset is at least partially controlled by executing a first control code via a first output. It is understood that in some examples, the first control code may control the entire operation of the industrial asset. At step 204, a second control code is introduced to the industrial asset. Next, at step 206, the first and the second control codes are executed in parallel or simultaneously. The first and the second control code may be in communication and synchronized with each other. Finally, at step 208, control of the industrial asset is switched such that the second control code at least partially controls the industrial asset via a second output. [0031] In many of these approaches, the first control code is subsequently removed for various reasons such as to free up memory or to reduce the possibility of reverting operation to the previous control code version. However, in some approaches, the first control code may be operated in parallel with the operation of the second control code, but outputs from the first control code are not sent to the industrial asset. As such, the first control code may act as a redundant or backup code should the second control code incur a failure or other issue. As with other approaches, the step 208 of switching control of the industrial asset may occur without interruption of operation thereof.
[0032] Referring now to FIG. 3, the approach 200 of FIG. 2 is further described. The approach 200 may include a system having a system agent, an I/O synchronization mechanism, system partitioning functionality, a multi-core controller or a synchronized network, and a number of control codes or applications.
[0033] The system agent is responsible for interfacing with a back-end server in a secure manner and managing the introduction, coordination, and removal of virtual machines or VMs. The I/O synchronization performs the task of ensuring various versions of the control application are synchronized in order to ensure the transition between control applications will be bump-less. The system partitioning functionality is responsible for partitioning the multi-core controller, processing device, or synchronized network to properly control multiple control applications. The control applications are responsible for providing controls to the industrial or critical asset.
[0034] As illustrated in step 302, the approach 200 is running using the first or current version of the control application. At step 304, the approach 200 introduces a new version of the control application and it is in an inactive state while the first control application remains active. In step 306, the first and second versions of the control application run in parallel due to the system agent synchronizing the first and second version of the control application. Necessary data is synced between the control applications. At step 308, the system switches the control application that actively controls the asset, making the first version of the control application inactive.
[0035] At the optional step 310, the first version of the control application is removed from the system. Alternatively, the first version of the control application may remain as a shadow application to act as a redundant or fall-back version. At step 312, the system is thereby upgraded without disrupting the industrial asset.
[0036] Referring now to FIG. 4, one example of a bump-less upgrade system 400 is described. The bump-less upgrade system 400 includes an interface 402 having a programming input 404 and an output 406, a controller or processor 408, and a memory 410. The system 400 may also include any number of industrial assets 412. The interface 402 is a computer-based program and/or hardware configured to accept controller activity or a signal or communication from a computing device such as a personal computer, a mobile computing device, a control system or server at the programming input 404 and transmit the generated communication at the output 406 to the industrial asset 412, which may be any number of components in an industrial environment, for example, wind turbines, distributed power generators, power plants, and the like. Other examples are possible. The function of the interface 402 is to allow the processor 408 to communicate with the industrial asset 412.
[0037] The processor 408 is any combination of hardware devices and/or software selectively chosen to process controller activity related to a control system and perform appropriate functions to be sent to the industrial asset 412 via the output 406. The processor 408 includes instructions that determine functionalities and operation of the control codes store on the memory 410. It is understood that any number of processors may be used in the system 400 and may be located either centrally or remotely within the system 400.
[0038] The memory 410 may be any data storage medium capable of storing data thereto.
The memory 410 may be an integral unit of the system 400, it may be physically coupled to the interface 402 and the processor 408 through a data connection (e.g., an Ethernet connection), or it may communicate with the system 400 through any number of wireless communications protocols. The memory 410 includes the first and the second control codes (not shown). These control codes may be any type of data file capable of storing a plurality of variables and instructions thereto. It is understood that any number of control codes may be used, and that any number of individual memory modules may be used which either may be centrally or remotely located. [0039] It will be appreciated that the various components described herein may be implemented using a general purpose processing device executing computer instructions stored in memory. Further, it is understood that the processor 408 may be a standalone component or may be incorporated into the interface 402.
[0040] The industrial asset 412 may include any number of components which receive instructions or commands from the system 400. For example, the industrial asset may include wind turbines, distributed power generators, power plants, and the like, or any number of these components grouped together. Other examples are possible.
[0041] In operation, the processor 408 is configured to at least partially control operation of the industrial asset 412 through the output 406 using a first control code. Upon receiving a second control code through the programming input 404, the processor 408 is configured to execute the first and the second control codes in parallel such that the inputs and the outputs of the first and second control codes are in communication and synchronized with each other. The processor 408 is further configured to switch control of the industrial asset 412 such that the second control code at least partially controls the industrial asset 412 via the output 406. In many of these approaches, the processor 408 is configured to switch control of the industrial asset 412 without interruption of operation of the industrial asset 412
[0042] It is understood that the processor may receive the second control code or notification of its existence via any number of known methods. For example, a user or operator may generate an update to the control code and transmit it to downstream systems, at which point it may be received by the processor 408. Other examples are possible.
[0043] In some examples, the processor 408 is configured to remove the first control code from the memory 410. However, in some approaches, the processor 408 is configured to retain the first control code in the memory 410 should a backup or redundancy be desired.
[0044] In some forms, the first and the second control code are stored on memory 410 on a plurality of remote computing devices having different locations.
[0045] It will be understood that the functionality of the components described may be provided on a single, physical chip or on multiple chips (or other components) disposed at multiple locations. The system described herein may be retrofitted on an existing control system without the need for substantial system redesign.
[0046] It will be appreciated by those skilled in the art that modifications to the foregoing embodiments may be made in various aspects. Other variations clearly would also work, and are within the scope and spirit of the invention. The present invention is set forth with particularity in the appended claims. It is deemed that the spirit and scope of that invention encompasses such modifications and alterations to the embodiments herein as would be apparent to one of ordinary skill in the art and familiar with the teachings of the present application.

Claims

What is claimed is:
1. A method, comprising:
executing a first control code, the first control code controlling an operation of an industrial asset via a first output;
synchronizing the operation of a second control code with the first control code;
upon the second control code becoming synchronized with the first control code, executing and switching from the first control code to the second control code via a second output of the second control code to control the operation of the industrial asset.
2. The method of claim 1, wherein the step of executing and switching to the second output of the second control code comprises upgrading operation of the industrial asset to function via the second control code.
3. The method of claim 1, wherein the step of executing and switching to the second output of the second control code occurs without halting operation of the industrial asset.
4. The method of claim 1, wherein the first control code and the second control code are executed via at least one processor configured to execute the first control code and the second control code simultaneously.
5. The method of claim 1, further comprising synchronizing at least one input from the industrial asset to the first control code and the second control code.
6. A method for upgrading an industrial asset comprising:
at least partially controlling the industrial asset by executing a first control code having a first output and an input via the first output;
introducing a second control code having a second output and an input to the industrial asset; executing the first control code and the second control code in parallel such that the inputs and the outputs of the first control code and the second control code are in communication and synchronized with each other;
when synchronized, switching control of the industrial asset such that the second control code at least partially controls the industrial asset via the second output.
7. The method of claim 6, further comprising the step of removing the first control code.
8. The method of claim 6, further comprising the step of operating the first control code in parallel with the operation of the second control code.
9. The method of claim 6, wherein the step of switching the control of the industrial asset occurs without interruption of operation of the industrial asset.
10. An apparatus for upgrading an industrial asset comprising:
an interface having a programming input and an output; and
at least one processor coupled to the interface;
wherein the at least one processor is configured to control an operation of the industrial asset via the output at least partially by a first control code, wherein upon receiving a second control code via the programming input, the at least one processor configured to execute the first control code and the second control code in parallel such that the inputs and the outputs of the first control code and the second control code are in communication and synchronized with each other, the at least one processor further configured to switch control of the industrial asset such that the second control code at least partially controls the operation of the industrial asset via the output.
11. The apparatus of claim 10, wherein the at least one processor is further configured to remove the first control code.
12. The apparatus of claim 10, wherein the processor is configured to switch control of the industrial asset without interruption of operation of the industrial asset.
13. The apparatus of claim 10, wherein the industrial asset comprises at least one of a power plant, a gas turbine, a gas compressor, a steam turbine, a wind turbine, a generator, a locomotive, an energy storage device, a water processor, and an electric distribution system.
14. The apparatus of claim 10, wherein the first control code and the second control code are stored on a plurality of remote computing devices having different locations.
15. The apparatus of claim 10, further comprising a plurality of processors configured to control operation of the industrial asset and synchronize the first and the second control codes.
PCT/US2015/019207 2015-03-06 2015-03-06 Bump-less control upgrade Ceased WO2016144296A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
PCT/US2015/019207 WO2016144296A1 (en) 2015-03-06 2015-03-06 Bump-less control upgrade

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/US2015/019207 WO2016144296A1 (en) 2015-03-06 2015-03-06 Bump-less control upgrade

Publications (1)

Publication Number Publication Date
WO2016144296A1 true WO2016144296A1 (en) 2016-09-15

Family

ID=56878714

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2015/019207 Ceased WO2016144296A1 (en) 2015-03-06 2015-03-06 Bump-less control upgrade

Country Status (1)

Country Link
WO (1) WO2016144296A1 (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10310837B2 (en) 2016-08-25 2019-06-04 General Electric Company Method and apparatus for updating industrial assets

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6237091B1 (en) * 1998-10-29 2001-05-22 Hewlett-Packard Company Method of updating firmware without affecting initialization information
US20030140150A1 (en) * 2002-01-14 2003-07-24 Dean Kemp Self-monitoring service system with reporting of asset changes by time and category
US20050028001A1 (en) * 2003-07-29 2005-02-03 Jian Huang Secured software patching and upgrade method for densely deployed networks having spanning-tree topology
US7823147B2 (en) * 2000-09-22 2010-10-26 Lumension Security, Inc. Non-invasive automatic offsite patch fingerprinting and updating system and method
US20120239224A1 (en) * 2011-03-18 2012-09-20 Mccabe Paul P Integration of an autonomous industrial vehicle into an asset management system
US20140130033A1 (en) * 2012-11-06 2014-05-08 General Electric Company Method and system for use in facilitating patch change management of industrial control systems

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6237091B1 (en) * 1998-10-29 2001-05-22 Hewlett-Packard Company Method of updating firmware without affecting initialization information
US7823147B2 (en) * 2000-09-22 2010-10-26 Lumension Security, Inc. Non-invasive automatic offsite patch fingerprinting and updating system and method
US20030140150A1 (en) * 2002-01-14 2003-07-24 Dean Kemp Self-monitoring service system with reporting of asset changes by time and category
US20050028001A1 (en) * 2003-07-29 2005-02-03 Jian Huang Secured software patching and upgrade method for densely deployed networks having spanning-tree topology
US20120239224A1 (en) * 2011-03-18 2012-09-20 Mccabe Paul P Integration of an autonomous industrial vehicle into an asset management system
US20140130033A1 (en) * 2012-11-06 2014-05-08 General Electric Company Method and system for use in facilitating patch change management of industrial control systems

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10310837B2 (en) 2016-08-25 2019-06-04 General Electric Company Method and apparatus for updating industrial assets

Similar Documents

Publication Publication Date Title
EP2790101B1 (en) System and method for automated virtual commissioning of an industrial automation system
EP3757701B1 (en) High availability for container based control execution
US11477083B2 (en) Industrial internet connected control system
CN108513655B (en) Software defined automation system and architecture thereof
US20160299497A1 (en) Methods for on-process migration from one type of process control device to different type of process control device
US10520935B2 (en) Distributed control system, control device, control method, and computer program product
EP3419793B1 (en) Robot controller system, robot arrangement, computer program and method therefor
CN112477919B (en) Dynamic redundancy backup method and system suitable for train control system platform
JP2009076072A5 (en)
CN102608965A (en) Methods and apparatus to upgrade and provide control redundancy in process plants
EP2508954A1 (en) System and method for the configuration of a clustered simulation network
US20140032172A1 (en) Systems and methods for health assessment of a human-machine interface (hmi) device
US20160274930A1 (en) Method and apparatus for an on-process migration in a virtual environment within an industrial process control and automation system
EP4193225B1 (en) Method and system for providing engineering of an industrial device in a cloud computing environment
JP6053637B2 (en) Method for upgrading virtual host and network device
CN112714022A (en) Control processing method and device for multiple clusters and computer equipment
CN109643231A (en) It is migrated during nonredundancy input/output (I/O) firmware
WO2016144296A1 (en) Bump-less control upgrade
CN114610440B (en) Methods and systems for constructing the operating environment of simulator systems
CN105849699B (en) Method for controlling data center architecture equipment
CN214851313U (en) Upper computer virtualization system
Ravenel et al. Architecture of WEST plasma control system
EP3719599B1 (en) Network-distributed process control system and method for managing redundancy thereof
US10924345B2 (en) Method for changing the configuration of connected networks
EP2688019A1 (en) Configuration of an industrial control system

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15884826

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15884826

Country of ref document: EP

Kind code of ref document: A1