The Architecture of Uninterruptibility
A black screen at a gate at Vienna Airport or a frozen display in the control centre of an ÖBB hub is not a technical failure, but a systemic risk. In the world of digital infrastructure, we distinguish sharply between "standard signage" for retail and "mission-critical systems". While in retail a restart after ten minutes is annoying, a failure in safety-critical areas leads to massive disruptions of passenger flows and regulatory consequences. True resilience in visual infrastructure requires a design that consistently isolates and eliminates the single point of failure.
The Chain of Reliability: From Source to Pixel
Redundancy is not an isolated feature, but a chain of decisions that begins with the choice of CMS and ends with the cabling of the LED modules. In practice, we consider three levels of failover:
- Content Failover (Software): The CMS detects a stream interruption and switches locally to emergency content.
- Signal Failover (Hardware): Two media players send signals synchronously; a switch (e.g. Kramer or Lightware) performs a hard switch in the event of signal loss.
- Hardware Redundancy (Infrastructure): Dual power supplies, redundant controller cards and loop-back cabling for LED walls.
Hardware Strategies in Detail
Controller Redundancy with NovaStar and Brompton
In large-scale LED installations (e.g. Absen Polaris or Alfalite Modularpix), the controller is the brain of the system. If it fails, the entire wall remains dark. Modern architectures rely on the COEX series from NovaStar, especially the MX40 Pro. Through a primary/backup configuration, two identical controllers are synchronised via an external switch or directly via the network.
"Closed Loop Redundancy" is a decisive standard here. In this process, the signal from the last panel in a chain is fed back into a backup port on the controller. Should a network cable break within the wall, the signal is instantaneously fed in from the other side. The switching time for systems like the Brompton Tessera S8 is in the millisecond range – invisible to the human eye.
Media Players: The BrightSign Series 5 Logic
In the field of LCD totems and kiosk systems, the BrightSign Series 5 (XC4055 or XD1035) has established itself as the industry standard. Redundancy is often solved here via "partner mode" or via dedicated failover URLs in the CMS. When we use easescreen Crossfire, the player permanently monitors the integrity of the local database. If the system detects an inconsistency in the cache or a hardware error of the primary player, a secondary player takes over via HDMI input switching.
| Component | Redundancy Level | Technology/Product | Goal |
|---|---|---|---|
| Signal Source | L1 (Software) | CMS Failover URL | Content continuity |
| Media Player | L2 (Hardware) | BrightSign XC4055 / Kramer Switch | Hardware fail-safety |
| Transmission | L3 (Cable) | STP Cat6a / Fibre Optic | Protection against signal interference |
| Controller | L4 (Processing) | NovaStar MX40 Pro (Primary/Backup) | Panel control |
| Display | L5 (Power) | Dual PSUs (Samsung The Wall) | Protection against PSU defect |
Practical Example: Information Systems in the Terminal Area
Let us consider a concrete scenario: passenger information in front of security control at an international airport. Portrait-mounted 75-inch displays are used here (e.g. LG 75UH5F-H, designed for 24/7 operation).
Setting:
- Location: High-traffic transition zone, IP5X-certified environment to protect against dust.
- Hardware: LG MAGNIT MicroLED or high-brightness LCDs.
- Redundancy Architecture: Each display is fed by two synchronised media players. An automatic HDMI switcher checks the TMDS sync status.
- Monitoring: Simple Network Management Protocol (SNMP) is used to query not only the operating status, but also the temperature of the panels and the fan speed.
Should the primary player freeze due to a memory error, the switch switches to the backup signal within 0.5 seconds. At the same time, the system sends an API call to Technical Facility Management (TFM) to initiate the replacement of the affected module before the backup system is also jeopardised.
Thermal Management and Power Supply
It is often forgotten that thermal stress is the primary cause of hardware failure. In mission-critical environments, displays must comply with the EN 60598 standard and have intelligent heat management. Samsung The Wall (IWA series), for example, uses a structure that dissipates heat more efficiently than standard COB modules.
In addition, power redundancy is essential. High-quality LED cabinets have two independent power supply units (PSU). These are dimensioned so that a single power supply unit can carry the entire load of the cabinet (N+1 redundancy). For distribution, we rely on separate circuits, each backed up by a UPS (Uninterruptible Power Supply). This protects not only against power failure, but also against voltage peaks that could destroy sensitive controller cards.
Regulatory Framework: BFSG 2025
From June 2025, the Accessibility Reinforcement Act (BFSG) comes into force, implementing EU Directive 2019/882. For operators of information infrastructure, this means that systems must not only function, but must also offer accessible alternatives in the event of a fault. Failover strategies are no longer optional here, but a legal obligation. If an info terminal for people with disabilities fails, redundancy must ensure that the information continues to be available in the same quality. At Lumexo, we are already integrating these requirements into the planning of hardware backbones today.
What we see in practice
In recent years, we have overseen numerous complex installations. The same patterns appear time and again:
- Insufficient Synchronisation: Many systems have two players but no mechanism to ensure that both play exactly the same frame. This leads to visible jumps when switching.
- Neglecting Cable Paths: The best redundancy is useless if both signal cables are routed through the same narrow shaft and are severed simultaneously during construction work.
- Lack of Failover Tests: Redundancy systems are often installed but never tested under load. A "simulated power failure" should be part of every acceptance test (FAT/SAT).
- The "Last Mile" to the Display: Often the controller is redundant, but the ribbon cable to the LED module itself is the weak point. Only high-quality mechanical connectors help here.
- Monitoring Overload: Too many error messages lead to real critical errors getting lost in the mass. Intelligent aggregation of alarms is necessary.
- Blind Trust in Software Failover: A software watchdog can restart a crashed process, but it cannot cure a hardware defect on the HDMI port.
Sustainability and Efficiency (EU 2021/341)
Redundancy often means more hardware, which initially seems to contradict sustainability. However, EU Regulation 2021/341 (Eco-design requirements) demands the repairability and longevity of displays. A resiliently planned system uses active monitoring to prevent components from ageing prematurely due to heat or overload. The Mean Time Between Failures (MTBF) is significantly increased, which reduces the ecological footprint over the entire service life (TCO).
Recommendation from Lumexo
To raise the operational safety of your visual infrastructure to a mission-critical level, we recommend the following steps:
- Physical Separation: Route primary and secondary signal paths via different routes and ideally use a different transmission technology for the backup path (e.g. primary fibre optic, secondary copper).
- Hardware-based Switching: Do not rely on software failover alone for critical information. Use dedicated hardware switchers or controllers with native redundancy support (e.g. Brompton Tessera).
- Holistic Monitoring: Implement a system that goes beyond "online/offline" status. Monitor temperatures, voltages and signal quality in real-time.
- Regular Stress Audits: Perform a controlled failover test once a quarter to ensure that the backup chain responds within the defined Service Level Agreements (SLA) in an emergency.