×

Automatic fault detection and recovery system which provides stability and continuity of operation in an industrial multiprocessor control

  • US 4,377,000 A
  • Filed: 06/18/1980
  • Issued: 03/15/1983
  • Est. Priority Date: 05/05/1980
  • Status: Expired due to Term
First Claim
Patent Images

1. A multiprocessor computer control system comprising at least a first central processor and a second central processor, a plurality of sensors coupled to equipment in a production system, means for connecting said sensors to first and second process input/output systems, a plurality of controllable devices for operating the production system equipment, switch means including at least first switch means for coupling said first process input/output system to said first central processor and second switch means for coupling said second process input/output system to said second central processor, and means for detecting control system faults and providing control system recovery in reconfigured form as necessary with substantially no process disturbance, said fault detecting and recovery means including a system bootstrap microprocessor controller coupled to each said central processor, means forming a part of said microprocessor controller and said central processors for sensing any of a plurality of control system failures and for thereby triggering said microprocessor controller into a recovery mode of operation, means for stopping said central processors and placing process control signals in a hold state upon command by said microprocessor controller, means for detecting the integrity of each central processor, said central processors including means for defining reconfigured central processor hardware so that process control duties are loaded only on operational central processor hardware, means including said microprocessor controller for operating said switch means as required so that only operational central processor hardware is coupled to the process equipment, means for restarting said system after completion of control system reconfiguration if any, and means for returning said microprocessor controller to a monitor mode after completion of the fault detection and recovery mode.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×