Microsoft Word - 825 Network Redundant DCS Configuration Management Adv Syst Sci Appl 2020; 01; 83-90 Published online at http://ijassa.ipu.ru/index.php/ijassa/article/view/825 Network Redundant DCS Configuration Management N.A. Zakharov1, V.I. Klepikov1, D.S. Podkhvatilin1 1) “Dozor” subdivision JSC “KEMZ” Moscow, Russia E-mail: nazakharov@npp-dozor.ru Abstract: An approach to the configuration management of a distributed control system with redundant components is proposed. The approach is based on a formalized vector-matrix representation of sets of system components, possible system configurations and functional relationships between them. Keywords: distributed control system, configuration, configuration management, configuration supervisor, redundancy, fault detection 1. INTRODUCTION The evolution of distributed control systems (DCS) at the present stage leads to the creation of models of complex automation of processes and production with automatic reconfiguration of their structure without the participation of personnel in order to continue normal operation in the event of failure in their components. DCS with digital communication channels can be represented as a set of jointly and purposefully functioning distributed dynamic objects and, in accordance with the modern theory of systems, is classified as a complex dynamic system. Currently, a promising concept for the construction of DCS based is on maintenance-free modular electronics [1, 2]. Such a DCS consists of redundant equipment and redundant communication network. This concept implies that the DCS possesses comprehensive system of collection and generalization information about equipment functioning. It uses high- performance algorithms for detection and isolation observable and unobservable failures. The key feature of the DCS under consideration is its capability of deep system reconfiguration based on component redundancy of functional systems and communication network. 2. REDUNDANCY The most promising way to parry failures in DCS is to use the redundancy of system resources. In general, there are the following types of redundancy:  system - redundancy of individual components and subsystems;  structural (architectural) – adaptive reconfiguration of the system structure;  information - addition to the main signal information on which it is possible to check its reliability (the checksum in the communication channel, estimates on model in dynamic control systems);  communication - use of duplicated and different types of communication channels;  algorithmic - using different algorithms to complete the same tasks;  software – use of different software tools;  technological - use of a variety of software, information and other technologies; 84 N.A. ZAKHAROV, V.I. KLEPIKOV, D.S. PODKHVATILIN Copyright ©2020 ASSA Adv. in Systems Science and Appl. (2020)  time - re-execution of operations with subsequent processing of results;  semantic - use of redundant semantic structures, digital images of controlled parameters;  organizational - use of additional systems or subsystems that duplicate functions or information flows of the main system. 3. SCHEDULE-TRIGGERED PROTOCOL A promising solution to build a communication network is the use of the Schedule- Triggered Protocol (STP) [3, 4]. The network distributed architecture of the control system based on the STP provides a high level of hardware, software, time, communication and information redundancy. This redundancy can be used not only to improve the reliability and fault tolerance of the control system, but also to improve the accuracy and quality of regulation and control. The large bandwidth of the STP channel allows to organize a single information space for all nodes of the distributed system. It allows several nodes to simultaneously perform calculations of control algorithms and transmit the results to the schemes of majority voting or data aggregation. 4. CONFIGURATION SUPERVISOR METHOD To control DCS redundancy a modified method for configuration supervisor (CS) is offered. In the initial method [5], CS refers to software and hardware modules used to monitor the operability of its configuration, participate in inter-service arbitration to activate its configuration either in case of winning the arbitration, or for parallel work together with other configurations on a common actuator. In the proposed modified CS method, the determination of the integrity of the configuration based on the information about the operability of its components is supplemented with estimates of the integrity of the configurations, formed on the basis of the analysis of the configurations output data. The obtained estimates of the integrity of the configurations are used as feedback to obtain estimates of the operability of the components forming the configuration. Let’s consider DCS based on STP. The DCS has an excessive number of hardware, software, communication and software components (resources). Resources in the general are:  sensors and input devices;  actuators and signal output devices;  computing nodes (controllers);  communication lines between the nodes and interconnecting systems;  built-in mathematical models. In this system, n variants of the sets of the available m components can be organized to perform the specified system functions. Each such variant of the set will be called a configuration. Different configurations can implement either different or the same system functions, configurations can have completely disjoint component sets, or they can share resources. The designed approach to management of redundancy of the distributed system is providing:  formalized representation in vector-matrix form of all components, used configurations and sets of components involved in each configuration;  formalized method for working configurations vector y direct calculation based on the original vector x component of operability;  calculation of the vector ŷ configurations integrities estimates based on configurations operation results;  formalized the procedure of reverse computations of the vector of estimated components operability based on vector serviceable configurations estimates ŷ; NETWORK REDUNDANT DCS CONFIGURATION MANAGEMENT 85 Copyright ©2020 ASSA. Adv. in Systems Science and Appl. (2020)  replacement of existing faulty configurations by new or replacement in existing configuration of the failed components by the same serviceable. 5. GAS TURBINE UNIT DISTRIBUTED CONTROL SYSTEM Let’s consider operation of the proposed method on the example of configuration management of a gas turbine unit drive distributed control system (GTU DCS). The block diagram of the GTU DCS is shown in Fig. 1. The system contains k=46 components ci, i=1...46, which have the following functionality:  c1...c5 – U1...U5 – GTU DCS controllers;  c6, c12 – L1, L2 – redundant STP-bus;  c7...c11 – L11...L15 – controllers U1...U5 STP-bus L1 ports;  c13...c17 – L21...L25 – controllers U1...U5 STP-bus L2 ports;  c18 – L3 –controller U5 with the upper level control system communication channel;  c19, c32 – N11, N12 – main and backup speed sensors of the low-pressure compressor (LPC);  c20, c33 – N21, N22 – main and backup speed sensors of the high-pressure compressor (HPC);  c21, c34 – N31, N32 – main and backup speed sensors of the free power turbine (FPT);  c22, c35 – T11, T12 – main and backup air temperature sensors;  c23, c36 – P11, P12 – main and backup air pressure gauges;  c24, c37 – T41, T42 – main and backup temperature sensors of the gas before FPT;  c25, c38 – P21, P22 – main and backup combustion chamber pressure sensors;  c26, c39 – Q11, Q12 – fuel control valve position main and backup sensors;  c27, c40 – Q21, Q22 – LPC guide vanes position main and backup sensors;  c28, c41 – Q31, Q32 – HPC guide vanes main and backup position sensors;  c29, c42 – Z11, Z12 – main and backup control signals to the fuel control valve;  c30, c43 – Z21, Z22 – main and backup control signals to the LPC guide vanes;  c31, c44 – Z31, Z32 – main and backup control signals to the HPC guide vanes;  c45 – T13, P13, Ns3 – information from the upper level control system: air temperature and pressure, set point to the free power turbine speed controller;  c46 – N14, N24, N34, T44, P24 – built-in engine model that produces real-time estimates of speed, gas temperature and pressure in the combustion chamber. The GTU DCS must provide:  depending on the current free turbine speed setpoint (ns) and the actual values of inlet temperature (t1) and air pressure (p1), by regulating the fuel consumption (q1) by the control signal (z1), ensure that the required value of the free turbine speed (n3) is maintained, while preventing the output of the combustion chamber pressure (p2) and gas temperature (t4) parameters for permissible values, which are also functions of temperature (t1) and air pressure (p1).  depending on the actual values of the engine rotor speeds (n1, n2) and the pressure in the combustion chamber (p2) adjust by means of control signals (z2, z3), the guide vanes position (q2, q3), which provides the required margin of gas-dynamic stability of the engine. The control system operation can be described by three functions: f1 – fuel consumption control, f2 – LPC guide vanes position control and f3 – HPC guide vanes position control: 86 N.A. ZAKHAROV, V.I. KLEPIKOV, D.S. PODKHVATILIN Copyright ©2020 ASSA Adv. in Systems Science and Appl. (2020) z1 = f1(ns, n1, n2, n3, t1, p1, p2, t4, q1), z2 = f2(n1, p2, q2), (1) z3 = f3(n2, p2, q3). Analysis of the GTU DCS block diagram (Fig. 1) indicates that the values of the arguments of the functions f1, f2 and f3 can be obtained from various sources (redundant sensors, model, information links with the upper level system). Calculation of functions values can be performed on one or several processors of various controllers, in-system information exchange can be carried out via one of two or simultaneously via both buses of the STP duplicated channel. Issue of control signals both to the fuel control valve and to the guide vanes drives can be made via any of two or simultaneously on both control channels. During GTU DCS operation failures of individual components may occur, there may be failures in the processes of measurement, calculation, data transmission. Due to the hardware, computing, information and time redundancy of the DCS, the GTU can continue operation using remaining serviceable components. Fig. 1. DCS block diagram 6. CONFIGURATIONS Let's call configuration a set of components of the system C = {c1, c2, ..., cm}, providing execution of a certain function. The configuration can provide both the execution of the object control function, i.e. end with the calculation of the output value of the system, and perform intermediate calculations that determine the values of the parameters necessary for other configurations, for example, to calculate the most reliable values of the input parameters of the DCS based on the readings of several sensors. The same function in the control system can be implemented in different configurations depending on which components are currently in good condition. In complex objects distributed control systems can consist of hundreds of components, which, depending on their current state can be combined into dozens of different configurations to perform certain functional tasks. The formation of such configurations must be performed either in advance at the design stage of the system, or generated automatically in real time, depending on the current situation. Without the use of formal design methods, both approaches are very time-consuming, require a lot of "manual" work at the stages of design and testing of the system. For this reason there is a need to develop analytical methods for representing the sets of configurations of available resources and managing these configurations in real time. NETWORK REDUNDANT DCS CONFIGURATION MANAGEMENT 87 Copyright ©2020 ASSA. Adv. in Systems Science and Appl. (2020) The value of the fi function formed in some j-th configuration of Cij will be denoted as zij. In the given system, for the functions f1, f2 and f3 can be formed, for example, three different variants of the calculation of the output values: z1 1 = f1(Ns3, N11, N21, N31, T11, P11, P21, T41, Q11), z1 2 = f1(Ns3, N12, N22, N32, T12, P12, P22, T42, Q12), z1 3 = f1(Ns3, N14, N21, N32, T13, P13, P24, T44, Q11), z2 4 = f2(N11, P21, Q21), z2 5 = f2(N12, P22, Q22), (2) z2 6 = f2(N14, P24, Q21), z3 7 = f3(N21, P21, Q31), z3 8 = f3(N24, P22, Q32), z3 9 = f3(N22, P24, Q31). In terms of the functional designation of the component, these variants can be implemented in the following configurations: C1 1 = {Ns3, N11, N21, N31, T11, P11, P21, T41, Q11, U1, U2, L1, L11, L12, L3, Z11}, C1 2 = {Ns3, N12, N22, N32, T12, P12, P22, T42, Q12, U3, U4, L2, L23, L24, L3, Z12}, C1 3 = {Ns3, N14, N22, N32, T13, P13, P24, T44, Q11, U1, U2, U5, L1, L15, L12, L2, L25, L22, L3, Z11}, C2 4 = {N11, P21, Q21, U1, U2, L1, L11, L12, Z21}, C2 5 = {N12, P22, Q22, U3, U4, L13, L14, L2, L23, L24, Z22}, (3) C2 6 = {N14, P24, Q21, U2, U5, L1, L15, L12, L25, L22, Z21}, C3 7 = {N21, P21, Q31, U1, U2, L1, L11, L12, Z31}, C3 8 = {N24, P22, Q32, U3, U4, U5, L2, L23, L24, Z32}, C3 9 = {N22, P24, Q31, U2, U3, U5, L1, L12, L13, L15, L2, L25, L22, Z31}. The same configurations in terms of component numbers can be written as: C1 1 = {c45, c19, c20, c21, c22, c23, c25, c24, c26, c1, c2, c6, c7, c8, c18, c31}, C1 2 = {c45, c32, c33, c34, c35, c36, c38, c37, c39, c3, c4, c12, c15, c16, c18, c42}, C1 3 = {c45, c46, c33, c34, c26, c1, c2, c5, c7, c11, c8, c12, c17, c14, c18, c31}, C2 4 = {c19, c25, c27, c1, c2, c6, c7, c8, c30}, C2 5 = {c32, c38, c40, c3, c4, c9, c10, c12, c15, c16, c43}, (4) C2 6 = {c46, c27, c2, c5, c6, c11, c8, c17, c14, c30}, C3 7 = {c20, c25, c28, c1, c2, c6, c7, c8, c31}, C3 8 = {c46, c38, c41, c3, c4, c5, c12, c15, c16, c44}, C3 9 = {c33, c46, c28, c2, c3, c5, c6, c8, c9, c11, c12, c17, c14, c31}. Components in formulas (3, 4) can be written in arbitrary order because these formulas are intermediate. They are used to clarify formal representation of configurations. Expressions (4) for sets of ck components present in Ci j configurations can be written as a matrix of K dimension (n×m), where n is the number of all configurations considered in the system, m is the number of all components of the system involved in the formation of configurations. The kij element of the matrix K is 1 if the i-th configuration uses the cj DCS component (see Fig. 1). 7. STATE AND AVAILABILITY VECTORS We define a vector x that characterizes the current state of all components of the DCS. If all components of the DCS are operable, the components of the vector x are represented as: 88 N.A. ZAKHAROV, V.I. KLEPIKOV, D.S. PODKHVATILIN Copyright ©2020 ASSA Adv. in Systems Science and Appl. (2020) xs = 1, s = 1…m. (5) Note that all components involved in the configuration are equally involved in the implementation of the system function, regardless of their physical nature and indicators of their own availability. For the example under consideration, m = 46. If there are faulty components in the system, the corresponding components of the vector x are zero. The value of this vector is formed in real time according to the results of the functioning of DCS software and hardware self-diagnostics. Next, we define the availability vector of configurations y, which characterizes the readiness for operation of all considered configurations. yi = 1 if the i-th configuration is healthy, otherwise yi = 0, i = 1...n. Configurations availability is a function of the components involved in configurations and their operability. y = F1(K, x), (6) where F1 is defined by the expression:   m s ssj xkF 1 ,1   , (7) the symbol  denotes the logical "And" function, the symbol  denotes the implication function. The meaning of the expression (7) is that each j-th element of the vector y will be equal to 1, i.e. the j-th configuration will work if only serviceable components are used in this configuration. In the STP-based DCS, several or all configurations can be executed in parallel or sequentially, which allows you to parry the failures of its components. The number of executable configurations is limited by the computing power of the DCS. If at execution of several configurations different values of the same output parameter are received, it is required to solve two problems: 1) reject incorrect results and mark the configurations which have formed them as faulty; 2) on the basis of the results obtained from the recognized working configurations to form the final agreed output value. 8. DCS COMPONENTS DIAGNOSTICS An effective way to diagnose the DCS components operability is the inclusion in its composition of the built-in real time model of the object under control [6]. This allows you to get a number of additional features to improve the quality and reliability of control, improve the performance of the system: - noise and fault filtering; - the recovery of unmeasured parameters for the diagnosis and management; - detection of abnormal states of the object and the control system; - diagnostics of the state and parametric degradation of the object. Some methods of rejection of incorrect values are considered in [7, 8]. Next, consider the analysis of configurations based on tolerance control. Let's write down the vector of output values obtained from the results of all n configurations operation. z = [z1, …zj, …zn] T (8) (upper indexes are omitted for clarity) and the initial configuration availability vector y = [y1, …yj, …yn] T. (9) NETWORK REDUNDANT DCS CONFIGURATION MANAGEMENT 89 Copyright ©2020 ASSA. Adv. in Systems Science and Appl. (2020) Using the vectors zmin and zmax, we set the minimum and maximum output values for each configuration, respectively. Let’s define a tolerance control function as F2(y, z, zmin, zmax) = 1, if (yj=1) & (zmin j ≤ zj ≤ zmax j); (10) else 0. The evaluation of the configurations availability vector ŷ is defined by the function F2: ŷ = F2(y, z, zmin, zmax), (11) The zero value of any component of the configuration availability vector indicates that there is one or more failed components of the DCS in the corresponding configuration. Next, we define the function F3 as   n j isj ykF 1 ,3 ˆ   , (12) the symbol  denotes a logical OR function; the symbol  denotes an implication function. For the vector that characterizes the serviceability evaluation of the DCS components, we can write:  yKFx ˆ,ˆ 3 , (13) The meaning of the expression (13) is that for each s-th element of the state vector, the operability of all j = 1...n configurations, in which it is involved, is checked. If at least one configuration in which this component is involved, i.e. the condition cj,s ≤ ŷj is satisfied for at least one j = 1...n, then the s-th component is identified as serviceable. If all configurations in which this component is involved are found to be faulty, the component is identified as failed. 9. CONFIGURATION MANAGEMENT ALGORITHM Configuration management algorithm is the following. The algorithm is executed cyclically. The first step of the algorithm is the formation of the initial vector x of the DCS components serviceability. The vector ν of dimension m formed by the built-in DCS components self-diagnostics means and the vector x̂ of components serviceability estimates calculated on the previous cycle are used. At the initial cycle, all components of the vector x̂ are assumed to be equal 1. In the second step, based on the original serviceability vector x and the configuration matrix K the vector of configurations availability y is formed. Next, according to the configurations availability verification method (in this example – tolerance control) configurations availability evaluations vector ŷ is formed. In the fourth step the DCS components serviceability evaluations vector x̂ is calculated. In case of faulty configurations detection, a new configurations matrix K is formed by replacing the used faulty configurations with new ones or replacing the faulty components with serviceable ones in the existing DCS configurations. 90 N.A. ZAKHAROV, V.I. KLEPIKOV, D.S. PODKHVATILIN Copyright ©2020 ASSA Adv. in Systems Science and Appl. (2020) 10. CONCLUSION In conclusion it should be noted that both of configurations set and their component composition can be optimized according to various criteria, such as the DCS computing and communication resources load, results interpretation unambiguity. In particular, it is obvious that if each of the system components will be involved in only one specific configuration and absent in all the others, its fault is clearly detected when recognizing this configuration failed. If two or more components are present in only one configuration (or a group of configurations) and are not present in all the others, it is not possible to distinguish their failures due to the failure of this configuration. Optimization of the number and component composition of DCS configurations should be performed taking into account the depth and reliability of the built-in software and hardware self-diagnostics of DCS components. REFERENCES 1. Jin, H. Lee S., Han S., Jo, H. Kim D. (2012). WiP Abstract: Challenges and Strategies for Exploiting Integrated Modular Avionics on Unmanned Aerial Vehicles. IEEE/ACM Third International Conference on Cyber-Physical Systems, Beijing, China, 211-211. https://doi.org/10.1109/ICCPS.2012.34. 2. Wang, L. Sun Y., Guo P., Zhang Y. (2015). An Enhanced Reconfiguration Method for the Second Generation Integrated Modular Avionics, 11th International Conference on Computational Intelligence and Security (CIS), Shenzhen, China, 433-436. https://doi.org/10.1109/CIS.2015.110. 3. Kopetz, H. (2011) Real-time systems. Design Principles for Distributed Embedded Applications. Heidelberg, Germany: Springer. https://doi.org/10.1007/978-1-4419- 8237-7. 4. Zakharov, N.A., Klepikov, V.I., Podkhvatilin, D.S. (2013) Sinkhronno-vremennoj protokol dlja raspredelennykh sistem upravlenia [Schedule triggered protocol for distributed control systems], Avtomatizatsiya v promyshlennosti, 2, 37-39. [in Russian]. 5. Ageev, A.M., Bronnikov, A.M., Bukov, V.N., Gamayunov, I.F. (2017). Supervisory control method for redundant technical systems, Journal of computer and systems sciences international, 56 (3), 410-419. https://doi.org/10.1134/S1064230717030029. 6. Klepikov, V.I., Kalin, S.V., Zakharov, N.A., Podkhvatilin, D.S. (2008). Algoritmicheskoe obespechenie otkazoustojchivosti raspredelennykh system upravlenia [Algorithmic provision of distributed control systems fault tolerance], Radioelektronni i komp'uterni sistemi, 34 (7), 43–48. [in Russian]. 7. Klepikov, V.I., Podkhvatilin, D.S., Dudorov, Y.N. Sharapov, G.V., Zakharov, N.A. (2011). Information-measuring diagnostics complex for technical maintenance. Autom Remote Control, 72 (5), 1089-1094. https://doi.org/10.1134/S0005117911050171. 8. Klepikov, V.I. (2014) Otkazoustoychivost' raspredelennykh sistem upravleniya [Fault tolerance of distributed control systems]. Moscow, Russia: Zolotoe sechenie [in Russian].