System upgrade method, device, storage medium and program product
By determining the upgrade time based on the overhaul time window in the nuclear power plant DCS, and adopting a serial upgrade method, upgrading the process control layer first and then the human-machine interface layer, and utilizing a layered architecture and virtual ring network redundancy mechanism, the problems of low efficiency and high risk in nuclear power plant DCS upgrades are solved, and efficient and safe system upgrades are achieved.
Patent Information
- Application Number
- CN202610681647.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-15
- Publication Date
- 2026-08-25
AI Technical Summary
In existing technologies, the upgrade methods for nuclear power plant DCS have problems such as low efficiency, high risk, difficulty in matching with the main overhaul schedule, and violation of nuclear safety monitoring requirements. Especially when equipment is aging and has a high failure rate, how to carry out efficient and low-risk upgrades within a limited overhaul time becomes a challenge.
The upgrade time windows for the process control layer and the human-machine interface layer are determined based on the overhaul time window. The process control layer is upgraded first, followed by the human-machine interface layer. By utilizing the layered architecture and virtual ring network redundancy mechanism of the nuclear power plant DCS, multiple cluster units are used as upgrade units to achieve serial upgrades, ensuring that the system can be upgraded within the overhaul time without violating nuclear safety requirements.
It improved system upgrade efficiency, reduced upgrade risks, ensured the safe and stable operation of the nuclear power plant, made full use of the overhaul time window, avoided system-wide shutdowns, and reduced systemic risks.
Smart Images

Figure CN122633206A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of nuclear power plant operation, maintenance and digital control technology, and in particular to a system upgrade method, equipment, storage medium and program product. Background Technology
[0002] The distributed control system (DCS) of a nuclear power plant serves as its "nerve center" and "brain," responsible for monitoring, controlling, and protecting the entire plant's process systems. Its reliability directly impacts the safe and stable operation of the nuclear power plant. However, over time, DCS systems commonly face issues such as equipment aging and malfunctions. Therefore, large-scale upgrades and renovations of the DCS in in-service nuclear power units have become an inevitable choice and a common industry requirement to ensure their long-term safe and economical operation.
[0003] Among related technologies, the "single-device replacement method" is used to upgrade the DCS. Its core principle is to upgrade all equipment one by one, using individual devices within the DCS as the modification unit, during a nuclear power plant overhaul. However, this upgrade method is time-consuming and has low efficiency. Summary of the Invention
[0004] This application provides a system upgrade method, device, storage medium, and program product, which can improve system upgrade efficiency. The technical solution is as follows: Firstly, a system upgrade method is provided for use in a nuclear power plant, the method comprising: The upgrade time windows of the human-machine interface layer and the process control layer in the nuclear power plant are determined based on the overhaul time window of the nuclear power plant, and the upgrade time window of the process control layer is earlier than the upgrade time window of the human-machine interface layer. The process control layer is defined as having multiple cluster units, each of which includes a control station and associated network interconnection devices; Upgrade the multiple cluster units within the upgrade time window of the process control layer; After the process control layer is successfully upgraded, the human-machine interface layer is upgraded during the upgrade time window of the human-machine interface layer.
[0005] In this application, the upgrade time windows for the process control layer and the human-machine interface layer are determined based on the overhaul time window of the nuclear power plant. This allows the upgrade of the nuclear power plant's DCS to be completed within the overhaul time window, making full use of the overhaul time without needing to apply for a system-wide shutdown window, thus avoiding violations of nuclear safety monitoring requirements. This improves system upgrade efficiency and ensures system operational safety. Furthermore, since the upgraded process control layer has backward compatibility, upgrading the human-machine interface layer only after the process control layer upgrade is successful reduces system risks associated with the upgrade and improves system upgrade stability.
[0006] Optionally, determining the upgrade time window for the human-machine interface layer and the upgrade time window for the process control layer of the nuclear power plant based on the overhaul time window of the nuclear power plant includes: Determine the multiple maintenance items corresponding to the overhaul time window; The upgrade time window for the human-machine interface layer and the upgrade time window for the process control layer are determined based on the maintenance time windows of the multiple maintenance items.
[0007] Optionally, the plurality of maintenance items include at least two of the following: unit downhill, low-low water level maintenance, hydrostatic test, reactor pressure vessel maintenance, containment pressure test, and unit uphill.
[0008] Optionally, determining the multiple cluster units in the process control layer includes: For any pair of redundant network interconnected devices in the process control layer, the pair of redundant network interconnected devices and all control stations connected to the pair of redundant network interconnected devices are divided into a cluster unit.
[0009] Optionally, before upgrading the plurality of cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the multiple cluster units, monitoring compensation is performed on the monitoring functions that need to be maintained in the cluster unit.
[0010] Optionally, before upgrading the plurality of cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, the control station in the cluster unit is physically isolated from the equipment controlled by the control station. The physical isolation includes one or more of the following: power off, adding mechanical latches, and locking output cards.
[0011] Optionally, before upgrading the plurality of cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, the mode is set for the equipment controlled by the control station in the cluster unit, and the mode includes maintenance mode.
[0012] Optionally, before upgrading the plurality of cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, the control station in the cluster unit is isolated from the equipment controlled by the control station.
[0013] Optionally, before upgrading the plurality of cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, an equipment impact analysis is performed on the control station in the cluster unit to obtain the impact analysis result. The impact analysis result is used to indicate one or more controlled devices affected by the control station in the cluster unit. Based on the impact analysis results, determine the type of affected device corresponding to the cluster unit; Determine multiple sub-maintenance items corresponding to the upgrade time window of the process control layer; Based on the maintenance time windows of the multiple sub-maintenance items and the affected equipment type corresponding to each of the multiple cluster units, the upgrade time window of each of the multiple cluster units is determined.
[0014] Optionally, determining the type of affected device corresponding to the cluster unit based on the impact analysis results includes: Window conditions are determined based on the impact analysis results; The affected device type is determined based on the window conditions.
[0015] Optionally, the process control layer includes a virtual ring network, which includes a main ring network and at least one sub-ring network. The main ring network includes a redundancy manager. The network interconnection devices in the plurality of cluster units are connected to the sub-ring network. Upgrading the plurality of cluster units within the upgrade time window of the process control layer includes: During the upgrade time window of the process control layer, the control stations in the plurality of cluster units are upgraded, and the network interconnection devices in the plurality of cluster units are upgraded based on the redundancy manager.
[0016] Optionally, the method further includes: After any one of the multiple cluster units completes its upgrade, the control station is subjected to step-level operation response verification, and / or, the control station is subjected to system-level diagnostic status real-time comparison verification; and / or, after any one of the multiple cluster units completes its upgrade, the cluster unit is subjected to system-level diagnostic status real-time comparison verification.
[0017] Optionally, after upgrading the plurality of cluster units within the upgrade time window of the process control layer, the process further includes: Perform system function verification and / or overall performance verification on the process control layer.
[0018] Optionally, before upgrading the human-machine interface layer within the upgrade time window of the human-machine interface layer, the method further includes: Control the master and slave devices in the human-machine interface layer to operate independently and in parallel; Upgrading the human-machine interface layer within the upgrade time window of the human-machine interface layer includes: The master device and the slave device are upgraded alternately during the upgrade time window of the human-machine interface layer.
[0019] Optionally, before upgrading the human-machine interface layer within the upgrade time window of the human-machine interface layer, the method further includes: Upgrade the target device in the human-machine interface layer within the upgrade time window of the process control layer; After the process control layer is successfully upgraded, a minimal system verification environment is constructed based on the process control layer and the target device. System verification is performed based on the minimized system verification environment described above. If the system verification is successful, the operation of upgrading the human-machine interface layer is performed within the upgrade time window of the human-machine interface layer.
[0020] Secondly, a system upgrade device is provided, the device comprising: The first determining module is used to determine the upgrade time window of the human-machine interface layer and the upgrade time window of the process control layer in the nuclear power plant based on the overhaul time window of the nuclear power plant, wherein the upgrade time window of the process control layer is earlier than the upgrade time window of the human-machine interface layer. The second determining module is used to determine multiple cluster units in the process control layer, wherein each cluster unit includes a control station and associated network interconnection devices. The first upgrade module is used to upgrade the multiple cluster units within the upgrade time window of the process control layer; The second upgrade module is used to upgrade the human-machine interface layer during the upgrade time window of the human-machine interface layer after the process control layer has been successfully upgraded.
[0021] Thirdly, a computer device is provided, the computer device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the system upgrade method described in the first aspect.
[0022] Fourthly, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program, which, when executed by a processor, implements the system upgrade method described in the first aspect.
[0023] Fifthly, a computer program product is provided that, when the computer program product is run on a computer device, causes the computer device to perform the system upgrade method described in the first aspect.
[0024] It is understood that the beneficial effects of the second, third, fourth, and fifth aspects mentioned above can be found in the relevant descriptions in the first aspect above, and will not be repeated here. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of the structure of a nuclear power plant DCS provided in an embodiment of this application; Figure 2 This is a schematic diagram of the structure of the layered virtual ring network of the nuclear power plant DCS provided in the embodiments of this application; Figure 3 This is a schematic diagram illustrating the overall hierarchical implementation phase division of a nuclear power DCS provided in an embodiment of this application; Figure 4 This is a schematic diagram of a system hierarchical upgrade provided in an embodiment of this application; Figure 5 This is a flowchart of a system upgrade method provided in an embodiment of this application; Figure 6 This is a schematic diagram of a control station cluster unit division provided in an embodiment of this application; Figure 7 This is a schematic diagram of cluster unit window matching provided in an embodiment of this application; Figure 8 This is a flowchart illustrating a cluster unit upgrade and transformation provided in an embodiment of this application; Figure 9 This is a schematic diagram of a human-machine interface layer split by column according to an embodiment of this application; Figure 10 This is a flowchart of a minimum LEVEL2 verification provided in an embodiment of this application; Figure 11 This is a schematic diagram of the structure of a minimized LEVEL2 verification platform provided in an embodiment of this application; Figure 12 This is a schematic diagram of the structure of a system upgrade device provided in an embodiment of this application; Figure 13 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0026] In the following description, specific details such as particular system architectures and technologies are set forth for illustrative purposes and not for limiting purposes, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details.
[0027] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or collections thereof. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0028] It should be understood that "one or more" as used in this application refers to one, two, or more, and "multiple" as used in this application refers to two or more. In the description of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. "And / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone.
[0029] To facilitate a clear description of the technical solutions of this application, the terms "first" and "second" are used to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and that the terms "first" and "second" do not necessarily imply that they are different.
[0030] The terms "one embodiment" or "some embodiments" used in this application mean that one or more embodiments of this application include the specific features, structures, or characteristics described in that embodiment. Therefore, the terms "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this application do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized.
[0031] The application scenarios involved in the embodiments of this application are described below.
[0032] The distributed control system (DCS) is the "nerve center" and "brain" of a nuclear power plant, responsible for monitoring, controlling, and protecting the entire plant's process systems. Its reliability is directly related to the safe and stable operation of the nuclear power plant. Currently, the first batch of nuclear power units to apply DCS have been in operation for more than ten years, and their DCS aging period is ten to fifteen years, gradually entering the end of their lifespan. They generally face problems such as equipment aging, high failure rates, spare parts outages, outdated technology, and information security vulnerabilities. For example, for pressurized water reactor nuclear power units using Siemens TXP or SPPA-T2000 digital instrumentation and control platforms, the instrumentation and control systems of the first batch of commissioned units (such as Ling'ao Nuclear Power Plant Units 3 / 4 and Taishan Units 1 / 2) have been in operation for nearly or more than ten years, and generally face the following prominent problems: 1. The central processing unit (CPU) module and its supporting input / output (I / O) cards in the AS620 control station have entered the end of their lifespan, and the failure rate is showing an upward trend. 2. The server hardware for the OM690 operation and monitoring system is no longer in production, making spare parts procurement difficult. 3. The SINEC H1 network switch is technologically outdated, has information security vulnerabilities, and fails to meet current network security regulatory requirements. Therefore, how to implement large-scale, efficient, and low-risk upgrades to the DCS of in-service nuclear power units within a limited overhaul window has become an inevitable choice and a common industry need to ensure their long-term safe and economical operation.
[0033] In related technologies, the following two schemes are usually adopted for upgrading the DCS of nuclear power plants.
[0034] The first approach, known as the "single-device replacement method," focuses on developing detailed plans for isolation, disassembly, installation, restoration, and testing of individual devices within the DCS (such as a single control station, server, or switch) during nuclear power plant overhauls. This typically follows the principle of "preparation before modification, verification one by one." This means preparing the new equipment, functionally isolating the target old equipment, physically replacing it and downloading the software, immediately testing the single device, and releasing the isolation only after confirming it functions correctly before moving on to the next device.
[0035] The second approach involves a "system-wide shutdown and replacement" solution. The core of this approach is to shut down the DCS system for a specific period and then conduct a concentrated, parallel, intensive overhaul of a single level of the DCS (such as the entire Level 1 process control layer or the entire Level 2 human-machine interface layer) within the shortest possible timeframe. This approach typically relies on a large construction team and ample spare parts resources, attempting to replace and upgrade all or most of the equipment within a relatively continuous period.
[0036] However, upgrading a nuclear power plant's DCS is extremely complex and unique, differing from conventional industrial systems. Nuclear power plant DCS typically possesses the following characteristics: 1. Uninterrupted Functionality: Even during reactor outages and major overhauls, the nuclear power plant's DCS must continuously monitor nuclear safety-related systems (such as reactor core cooling, radiation monitoring, fire suppression, and power supply). Any situation that leads to the loss or partial loss of nuclear safety monitoring functions may be defined as an operational event, seriously threatening nuclear safety.
[0037] 2. High system coupling: A nuclear power plant's DCS is a complex coupled system consisting of a process control layer, a human-machine interface layer, and a network system. There is a large amount of data exchange and logical linkage between layers, stations, and equipment. Local modifications may trigger unforeseen systemic risks.
[0038] 3. Urgency of the overhaul window: The overhaul period for nuclear power units is measured in hours and is extremely tight. Large-scale nuclear power plant DCS retrofits must be carried out in parallel with many critical overhaul activities (such as equipment maintenance and testing) on the main path, and must not have a significant impact on the main schedule.
[0039] 4. Multidimensional risks: The transformation process not only involves technical risks such as equipment damage and software failure, but also safety risks such as equipment tripping, accidental start-up, and system paralysis due to control function failure or malfunction. The risk management requirements are extremely high.
[0040] Based on the above characteristics, the first approach has the following drawbacks: 1. Extremely low efficiency: For large-scale upgrade projects involving dozens of control stations, nearly a hundred servers and switches, upgrading each one individually would generate massive amounts of repetitive isolation, testing, and recovery work. Within the limited overhaul window, it would be impossible to complete the nuclear power plant's DCS upgrade in terms of timeline.
[0041] 2. Fragmented risk management: Each equipment modification requires a separate risk plan, resulting in scattered, repetitive, and difficult-to-coordinate risk management measures. Frequent isolation and de-isolation operations themselves greatly increase the risk of human error.
[0042] 3. High systemic risk: Due to the lack of overall consideration of the coupling relationship between systems, replacing a certain device may disrupt the normal operation of other related devices or networks, which can easily trigger a chain reaction that affects the whole system, leading to local or system malfunctions.
[0043] 4. Poor compatibility with the main overhaul line: The individual equipment modification windows are scattered and difficult to effectively match and integrate with the main overhaul line windows that require specific system states (such as power supply overhaul or cold source restoration), which is prone to conflict with key overhaul activities.
[0044] The second option has the following drawbacks: 1. Violation of nuclear safety monitoring requirements: A complete shutdown of the DCS of a nuclear power plant will cause the main control room to lose the ability to monitor the key process parameters of the nuclear power plant for a long time. This violates the operating technical specifications, may directly cause operational events, and pose a threat to the nuclear safety of the nuclear power unit.
[0045] 2. It has a huge impact on the main overhaul schedule: It requires applying for a long and continuous system-wide shutdown window, which seriously conflicts with other key maintenance and testing activities that must be carried out during the overhaul, and is difficult to arrange in practice.
[0046] 3. High concentration of risks: If an unforeseen systemic failure occurs during the overall replacement process, the entire renovation project will fail and recovery will be extremely difficult, potentially causing serious delays in the overhaul period.
[0047] Therefore, this application provides a system upgrade method applicable to nuclear power plants, particularly pressurized water reactor nuclear power plants employing the Siemens TXP (TeleperMXP) or SPPA-T2000 digital instrumentation and control platform. The TXP / SPPA-T2000 platform is a widely adopted plant-wide digital instrumentation and control system solution for pressurized water reactor nuclear power plants. This platform possesses the following technical architecture features that are highly compatible with the system upgrade method provided in this application: (1) Layered network structure: The TXP / SPPA-T2000 platform follows a typical layered architecture of "process control layer (AS620 / AS620B automatic control system) - human-machine interface layer (OM690 operation and monitoring system) - terminal bus / factory bus". The AS620 control station in the process control layer communicates with the OM690 server in the human-machine interface layer through SINEC H1 industrial Ethernet. The layer boundaries are clear and the network topology is well-defined, providing a structural basis for the serial upgrade path of "LEVEL1 first and then LEVEL2" in the embodiments of this application.
[0048] (2) Virtual Ring Network Redundancy Mechanism: The process control layer network (SINEC H1 FO) of the TXP / SPPA-T2000 platform adopts a fiber optic virtual ring network structure with a built-in redundancy manager (RM). When a local switch or node in the ring network is powered down or disconnected due to upgrades, the ring network self-healing mechanism can reconstruct the communication path within milliseconds, affecting only the control station directly connected to that node, without causing the entire LEVEL1 ring network to fail. This feature makes it possible to divide the "pair of redundant switches and their downstream control stations" into a cluster unit in this embodiment of the application, achieving local isolation of risks.
[0049] (3) Network connection structure characteristics of control stations and switches: In the actual engineering configuration of the TXP / SPPA-T2000 platform, the host and slave of the control station are respectively connected to a pair of switches on the ring network. This avoids the situation where the host and slave of a control station are connected to the same switch, thus avoiding the situation where the failure of one switch causes the entire control station to lose network communication. Usually, one switch connects 3 to 5 host control stations; another switch connects the slave control stations. This physical connection relationship of "switch-control station group" is consistent with the "cluster unit" defined in the embodiments of this application, making the cluster partitioning operation intuitive and the boundaries clear.
[0050] (4) Backward compatibility design: During the evolution of the TXP / SPPA-T2000 platform, the backward communication compatibility of LEVEL1 with older versions of LEVEL2 (such as OM690) has been retained. The upgraded AS620B control station can still exchange process data, alarm information and trend data normally with the un-upgraded OM690 server. This compatibility ensures that the implementation sequence of "modifying LEVEL1 first, then LEVEL2" in the embodiments of this application will not cause the main control room monitoring function to be interrupted.
[0051] (5) LEVEL2 Dual-Column Redundancy Configuration: The OM690 server and operator station of the TXP / SPPA-T2000 platform adopt a master / standby redundancy configuration. This application modifies the redundancy software parameters to switch the master / standby hot standby mode to an independent parallel operation mode of columns A and B, thereby supporting the "rotational upgrade" of LEVEL2 devices and ensuring that the other column continues to provide complete monitoring and operation functions during the upgrade of any column.
[0052] In this method, the upgrade time windows for the human-machine interface (HMI) layer and the process control layer of the nuclear power plant are determined based on the plant's overhaul time window. The process control layer upgrade time window is earlier than the HMI layer upgrade time window. Then, multiple cluster units within the process control layer are identified. Each cluster unit includes a control station and associated network interconnection equipment. These cluster units are upgraded within the process control layer's upgrade time window. After the process control layer upgrade is successful, the HMI layer is upgraded within its own upgrade time window. Because the upgrade time windows for the process control layer and the HMI layer are determined based on the nuclear power plant's overhaul time window, the upgrade of the nuclear power plant's DCS can be completed within that window. This allows for more efficient use of the overhaul time, eliminates the need for a system-wide shutdown window, and avoids violating nuclear safety monitoring requirements, thereby improving system upgrade efficiency and ensuring system operational safety. Furthermore, since the upgraded process control layer has backward compatibility, upgrading the HMI layer only after the process control layer upgrade is successful reduces system risks and improves system upgrade stability.
[0053] The nuclear power plant DCS provided in the embodiments of this application will be described below.
[0054] Figure 1 This is a schematic diagram of the structure of a nuclear power plant DCS provided in an embodiment of this application. See also... Figure 1 The nuclear power plant DCS may include a process control layer 101 (also known as LEVEL1) and a human-machine interface layer 102 (also known as LEVEL2). For example, the nuclear power plant DCS may be applicable to the Siemens TXP / SPPA-T2000 platform DCS of a pressurized water reactor nuclear power plant.
[0055] The process control layer 101 can communicate with the human-machine interface layer 102 via a wired or wireless connection.
[0056] Process control layer 101 refers to the level in the nuclear power plant's DCS responsible for directly interacting with the controlled equipment (also known as local equipment or field equipment) and completing data acquisition, logic operations, closed-loop control, and equipment driving.
[0057] For example, such as Figure 1 As shown, the process control layer 101 can consist of control stations (including controllers), I / O modules, and corresponding cabinets and networks. For example, the process control layer 101 may include a process control layer ring network (i.e., a virtual ring network), multiple control stations, multiple I / O modules, multiple network switching devices, multiple gateways, etc., but this embodiment does not limit this. For example, as... Figure 2 As shown, for the DCS network structure of a nuclear power plant with a hierarchical virtual ring network structure, the LEVEL1 network can be divided into a main network layer and a sub-network layer. Each control station is connected to four sub-ring networks, which are then merged into the main ring network. The main ring network communicates with the LEVEL2 network (i.e., a single-layer virtual ring network) through a server.
[0058] For example, multiple control stations in the process control layer 101 can communicate with each other through a network switching device. For example, this network switching device can be a switch, a router, etc., and this embodiment of the application is not limited to this. For example, any one of the multiple control stations in the process control layer 101 can have a primary / backup dual-row redundancy configuration.
[0059] The human-machine interface layer 102 refers to the layer in the nuclear power plant's DCS that provides operators with a graphical monitoring interface and enables functions such as power plant-level data management, historical records, and advanced calculations.
[0060] For example, such as Figure 1 As shown, the human-machine interface layer 102 can consist of servers, operator stations (also known as control stations), engineer stations, and corresponding networks. For example, the human-machine interface layer 102 may include one or more of the following: a human-machine interface layer ring network, multiple operator stations, multiple engineer stations, multiple servers, and multiple network switching devices. The network system 103 may include all switches of the process control layer 101 network and the human-machine interface layer 102 network.
[0061] The operator station is a dedicated computer workstation that runs a graphical user interface for operators. It serves as the primary human-machine interface for operators to monitor the power plant's operational status and execute operational commands. Through this operator station, operators can view process flow diagrams, alarm lists, trend curves, and remotely control equipment such as valves and pumps. For example, the multiple operator stations may include one or more of the following: conventional island operator station, nuclear island operator station, and remote shutdown station; however, this application does not limit this to specific examples.
[0062] This engineering station is a dedicated workstation for instrumentation and control engineers. Its core functions include configuring, programming, debugging, maintaining, and diagnosing the nuclear power plant's DCS. Engineers can use the engineering station to modify control logic, download applications, manage databases, perform system backups, and analyze faults. For example, the multiple engineering stations may include one or more of a unit manager's operating station, a safety engineer's operating station, etc., but this application embodiment does not limit this.
[0063] For example, these multiple servers may include one or more of the following: terminal server, configuration server, process server, historical server, long-term storage server, diagnostic server, engineering server, and external interface server. This application embodiment does not limit this. The configuration server or engineering server is used for system configuration, software download, logic modification, and database management, serving as a work platform for engineers to design, maintain, and modify the DCS. The process server is a key hub connecting the process control layer and the human-machine interface layer, responsible for collecting real-time data from control stations in LEVEL1, processing and distributing it, and executing advanced control algorithms. The historical server is responsible for storing and retrieving short-term historical data (such as process data from the last few days or weeks, and event sequence records) for trend analysis, fault tracing, and daily operational evaluation. The long-term storage server is responsible for the long-term archiving and storage of historical data (such as data from several months to several years), meeting regulatory record retention requirements, and is used for long-term performance analysis and root cause analysis. The diagnostic server is used to collect and analyze the health status information of the nuclear power plant's DCS system itself, monitor the operating status and fault alarms of hardware such as networks, controllers, and servers, and serves as a tool for system maintenance personnel. This external interface server is responsible for data communication and exchange with other independent systems in the power plant (such as the plant-level monitoring information system, vibration monitoring system, radiation monitoring system, etc.).
[0064] For example, the server, operator station, and engineer station in the human-machine interface layer 102 can have a primary and backup dual-row redundancy configuration.
[0065] It should be noted that the process control layer 101 and the human-machine interface layer 102 in this embodiment can be divided based on the upgrade scope of the nuclear power plant's DCS. The upgrade scope of the process control layer 101 may include replacing the controller hardware in the old model control station with the new model, upgrading all process control software versions and application software code, and removing the old switches in the process control layer 101 network and replacing them with new models of switches. The upgrade scope of the human-machine interface layer 102 may include replacing the computing server, interface server, storage server, and the main control room human-machine interface graphics server, upgrading software, displays, clocks, and other supporting facilities, and removing the old switches in the human-machine interface layer 102 network and replacing them with new models of switches.
[0066] The following is an exemplary description of the overhaul stage of a nuclear power unit provided in the embodiments of this application.
[0067] During operation, nuclear power units require nuclear fuel replacement every first period (approximately 18 months), allowing for a routine overhaul, typically lasting 30-45 days. Every second period (approximately ten years), a "ten-year overhaul" is required. This overhaul includes large-scale modifications and maintenance, as well as significant periodic nuclear power plant tests (such as hydrostatic testing). The modifications and maintenance phases require the shutdown of some equipment within the nuclear power unit (excluding equipment or facilities maintaining nuclear safety). This ten-year overhaul has a longer timeframe than a routine overhaul, approximately 60 days. Therefore, upgrades to the nuclear power plant's DCS can be carried out during this ten-year overhaul. In some cases, this upgrade can be referred to as a modification.
[0068] The overhaul of this nuclear power unit may include multiple maintenance items. For example, such as Figure 3 As shown, the multiple maintenance items may include unit relocation, low-low water level maintenance window, hydrostatic test, reactor pressure vessel maintenance, containment pressure test, and unit relocation, etc., and this application embodiment does not limit this. For example, the maintenance sequence of these multiple maintenance items may be unit relocation > low-low water level maintenance window > hydrostatic test > reactor pressure vessel maintenance > containment pressure test > unit relocation.
[0069] The term "downward transition" refers to the entire process by which a nuclear power unit gradually reduces its power output, shuts down, unloads nuclear fuel, and eventually enters a maintainable, static state from its normal full-power operation. It is a "from operation to shutdown" process. For example, the downward transition window could be 8 days.
[0070] The low-low water level maintenance window refers to a specific state during a nuclear power unit overhaul where the water level in the reactor coolant system (i.e., the primary loop) is lowered below the bottom of the pressure vessel for maintenance. For example, this low-low water level maintenance window can be 12 days. During this window, the primary loop has been depressurized and drained, and the water level has dropped below the bottom of the pressure vessel. The system is in a static, non-high-temperature, and non-high-pressure "cold state," and most of the equipment connected to the control station in process control layer 101 (such as valves and pumps) has been isolated or taken out of service. Therefore, the risk of upgrading process control layer 101 is relatively low, and upgrades to process control layer 101 can be performed within this low-low water level maintenance window.
[0071] The hydrostatic test refers to an overpressure test conducted on the entire reactor coolant system (including pressure vessels, piping, pumps, valves, etc.) after the primary coolant loop has been overhauled. This test verifies the structural integrity and sealing performance of the primary coolant loop pressure boundaries under high pressure, ensuring no excessive plastic deformation or leakage. For example, the time window for this hydrostatic test can be 5 days. Because this hydrostatic test is an extremely special and high-risk window, the primary coolant loop is pressurized to pressures far exceeding normal operating pressures to verify its strength. At this time, the entire pressure boundary is subjected to maximum mechanical stress, and any minor accidental disturbance could lead to unpredictable consequences. Therefore, no upgrades to the nuclear power plant's DCS are carried out during this hydrostatic test time window.
[0072] The reactor pressure vessel overhaul is a specialized inspection and maintenance of the core safety equipment containing the reactor core and reactor coolant. For example, the overhaul time window can be 9 days. Since the primary loop has been completely depressurized, drained, and isolated during this overhaul time window, and most of the pumps, valves, and other equipment related to the pressure vessel have been taken out of service, even if the controlled equipment in the process control layer 101 experiences a temporary failure due to the upgrade, it will not cause a safety or operational event. Therefore, the upgrade of the process control layer 101 can be carried out within the reactor pressure vessel overhaul time window. Furthermore, the upgrade of the human-machine interface layer 102 is mainly carried out in the control room and computer room, and will not affect the equipment involved in the reactor pressure vessel overhaul. Therefore, the upgrade of the human-machine interface layer 102 can also be carried out within the reactor pressure vessel overhaul time window.
[0073] The containment pressure test is a comprehensive test of the overall strength and sealing performance of the containment. For example, the time window for this containment pressure test can be 10 days. Since the containment pressure test verifies the overall sealing performance of the containment, it primarily affects the airtight environment of the containment building. The human-machine interface layer 102, typically located in a control room or a separate electrical room, is unaffected by pressure changes within the containment. Therefore, upgrades to the human-machine interface layer 102 can be performed within the time window of this containment pressure test.
[0074] The term "upstream" refers to the entire process of a nuclear power unit being refueled, started, and gradually increased in power after all maintenance and testing work is completed, until it returns to full power operation. It is a process of "from standstill to operation." For example, the upstream time window for this unit can be 8 days.
[0075] It should be noted that, based on the architectural characteristics of the process control layer 101 and human-machine interface layer 102 in the nuclear power plant DCS system, which are relatively independent in function but tightly coupled in data, this embodiment of the application abandons parallel or reverse-order modifications and can adopt a serial, phased, centralized upgrade path. The specific upgrade implementation sequence can follow the vertical order of "LEVEL1 first, then LEVEL2".
[0076] In this scenario, because the new LEVEL 1 is typically designed with backward compatibility—meaning the upgraded process control layer 101 is compatible with the unupgraded human-machine interface layer 102 and can communicate normally with the older version—even if the upgrade of the human-machine interface layer 102 fails, it will not affect the normal operation of the nuclear power unit. Conversely, if the upgrade is performed "LEVEL 2 first, then LEVEL 1," then if the upgrade of process control layer 101 fails, the older version of process control layer 101 may be incompatible with the new version of human-machine interface layer 102, which would affect the normal operation of the nuclear power unit. This approach improves the stability of system upgrades.
[0077] For example, such as Figure 3 As shown, the process control layer 101 can be upgraded within the time window of the low-low water level maintenance during the nuclear power unit overhaul and the time window of the reactor pressure vessel maintenance, with a total upgrade time of 21 days. The human-machine interface layer 102 can be upgraded within the remaining time window of the reactor pressure vessel maintenance and the time window of the containment pressure test, with a total upgrade time of 10 days.
[0078] Optionally, such as Figure 4 As shown, the process control layer 101 can be divided into cluster units to obtain multiple cluster units, and then the multiple cluster units can be upgraded first using the cluster units as upgrade units.
[0079] In this way, large-scale, fragmented upgrade tasks can be consolidated into multiple batch tasks. When upgrading these batch tasks, repetitive work during the upgrade process can be greatly reduced, compressing what would otherwise be an infeasible large-scale upgrade into a completed overhaul period. This improves the utilization rate of the overhaul period and increases system upgrade efficiency. For example, upgrading process control layer 101 could include routine maintenance work, upgrading clusters 1-12, and LEVEL1 network modifications.
[0080] Optionally, such as Figure 4 As shown, after the process control layer 101 is upgraded, the primary and backup dual-column redundancy configuration of the human-machine interface layer 102 can be split into parallel operation modes of column A and column B, and columns A and B can be upgraded in a rotating manner.
[0081] In this way, during the upgrade of the HMI layer 102, it can be ensured that the main control room still has complete monitoring capabilities, reducing the probability of accidents that may occur due to the upgrade. For example, the upgrade of the HMI layer 102 may include routine maintenance work, upgrades to the equipment in column A of the HMI layer 102, upgrades to the equipment in column B of the HMI layer 102, and LEVEL2 network transformation.
[0082] For example, by using the above method, pressurized water reactor nuclear power plants using the Siemens TXP / SPPA-T2000 platform can make full use of the platform's original virtual ring network self-healing characteristics, AS620 control station group configuration characteristics, and LEVEL1 backward compatibility characteristics. This integrates the originally scattered and high-risk unit-by-unit replacement work into multiple orderly cluster batch operations, so that the upgrade of the entire plant's DCS can be completed within a single ten-year overhaul window (approximately 60 days) without the need to apply for an additional system-wide shutdown window.
[0083] The system upgrade method provided in the embodiments of this application will be explained in detail below.
[0084] Figure 5 This is a flowchart illustrating a system upgrade method provided in an embodiment of this application. This method can apply the methods described above. Figure 1 The nuclear power plant DCS in the embodiment. See also Figure 5 The method may include the following steps: It should be noted that the system upgrade method provided in this application embodiment has high replicability and adaptability. This strategy system is derived from engineering practice, and its methodology (such as cluster partitioning principle and window matching logic) can be applied to nuclear power units with similar technical styles.
[0085] Step 501: Based on the overhaul time window of the nuclear power plant, determine the upgrade time window of the human-machine interface layer and the upgrade time window of the process control layer in the nuclear power plant. The upgrade time window of the process control layer is earlier than the upgrade time window of the human-machine interface layer.
[0086] The upgrade time window for the process control layer and the upgrade time window for the human-machine interface layer are upgrade time windows within the overhaul time window of the nuclear power plant.
[0087] In this embodiment, the upgrade time windows for the process control layer and the human-machine interface layer are determined based on the overhaul time window of the nuclear power plant. This means the upgrade of the nuclear power plant's DCS can be completed within the overhaul time window. This not only makes full use of the overhaul time but also eliminates the need for a system-wide shutdown window, thus avoiding violations of nuclear safety monitoring requirements. This improves system upgrade efficiency and ensures system operational safety. Furthermore, since the upgraded process control layer is backward compatible, upgrading the process control layer first and then the human-machine interface layer reduces the impact of the upgrade on system operation and ensures system upgrade stability.
[0088] In some implementations, step 501 may involve: determining multiple maintenance items corresponding to the overhaul time window, including at least two of the following maintenance items: unit downhill, low-low water level maintenance, hydrostatic test, reactor pressure vessel maintenance, containment pressure test, and unit uphill; and determining the upgrade time window for the human-machine interface layer and the upgrade time window for the process control layer based on the maintenance time window of the multiple maintenance items.
[0089] Since the content of the maintenance items is different, the system operating status is different during different maintenance items, and the risks of upgrading are different, the upgrade time window of the human-machine interface layer and the upgrade time window of the process control layer can be determined based on the maintenance time window of these multiple maintenance items.
[0090] In this way, the determined upgrade time window for the human-machine interface layer and the process control layer can not only make good use of the overhaul time of the nuclear power plant, but also minimize the impact on the system (such as maintenance and monitoring) during subsequent upgrades, ensuring the stable operation of the system without affecting the normal overhaul of the nuclear power plant.
[0091] For example, during the low-low water level maintenance window, the system as a whole is in a static, "cold state" without high temperature and high pressure. Most of the equipment (such as valves and pumps) connected to the control station in the process control layer have been isolated or taken out of operation, so the upgrade risk is relatively small. Therefore, the process control layer can be upgraded within the time window of the low-low water level maintenance window.
[0092] For example, since the hydrostatic test is a high-risk window during a nuclear power plant overhaul, any interference with the test could lead to unpredictable consequences and affect the test results. Therefore, any upgrades are suspended during this hydrostatic test window.
[0093] For example, since the controlled equipment in the process control layer will not cause a safety or operational event even if it temporarily fails due to an upgrade during the reactor pressure vessel maintenance window, the process control layer upgrade can be performed during the reactor pressure vessel maintenance window. Furthermore, the upgrade of the human-machine interface layer is mainly carried out in the control room and computer room, and will not affect the equipment involved in the reactor pressure vessel maintenance; therefore, the human-machine interface layer upgrade can also be performed during the reactor pressure vessel maintenance window.
[0094] For example, since the containment pressure test mainly verifies the overall sealing performance of the containment and primarily affects the airtight environment of the containment building, while the human-machine interface layer is not affected by the containment pressure test, the upgrade of the human-machine interface layer can be carried out within the time window of the containment pressure test.
[0095] Step 502: Identify multiple cluster units in the process control layer, each of which includes a control station and associated network interconnection devices.
[0096] For example, the multiple cluster units can be determined based on the functional coupling relationship and physical connection topology between the control station and the network interconnection device, thus defining multiple cluster units in the process control layer. For example, the network interconnection device can be a switch or a router, etc., and this application embodiment does not limit this.
[0097] By clustering the devices in the process control layer, large-scale, fragmented upgrade tasks can be consolidated into multiple batch tasks. This allows subsequent upgrades to the process control layer to be elevated from the "device level" to the "system function level." Compared to related technologies that upgrade devices one by one, this significantly reduces repetitive work and upgrade time. Consequently, it improves the utilization rate of overhaul periods and increases system upgrade efficiency.
[0098] In some implementations, step 502 can be performed as follows: for any pair of redundant network interconnection devices in the process control layer, the pair of redundant network interconnection devices and all control stations connected to the pair of redundant network interconnection devices are divided into a cluster unit.
[0099] The redundant network interconnection devices refer to the network interconnection devices that are respectively connected to the host and slave devices in the control station.
[0100] Specifically, since the functions of the control station require signal transmission through network interconnection devices, upgrading these devices will affect all control stations connected to them. This means there is a functional coupling between the network interconnection devices and the affected control stations. Furthermore, since control stations typically include master and slave units, a pair of redundant network interconnection devices and all control stations connected to these redundant devices can be grouped into a single cluster unit.
[0101] This approach not only breaks down global risks into controllable local risks, but also allows subsequent upgrades to the process control layer to be moved from the "equipment level" to the "system function level," minimizing the impact of the upgrade process on the system and achieving effective risk control. Furthermore, it provides a reference for subsequent window matching.
[0102] For example, such as Figure 6 As shown, Figure 6 This is a schematic diagram of a control station cluster unit division provided in an embodiment of this application. Figure 5 It includes station 1, station 2, station 3, station 4, station 5, switch 1, switch 2, switch 3, switch 4, ... switch N, where station 1 to station 5 each include a master and a slave.
[0103] The hosts in stations 1, 2, and 3 establish connections with switch 1, and the slaves in stations 1, 2, and 3 establish connections with switch 2. The hosts in stations 4 and 5 establish connections with switch 3, and the slaves in stations 4 and 5 establish connections with switch 4. Stations 1, 2, and 3 do not establish connections with switches 3 and 4. Therefore, stations 1, 2, and 3, switches 1 and 2 can be classified as cluster unit 1, and stations 4, 5, switches 3 and 4 can be classified as cluster unit 2.
[0104] Step 503: Upgrade the multiple cluster units within the upgrade time window of the process control layer.
[0105] For example, multiple cluster units can be upgraded sequentially within the upgrade time window of the process control layer.
[0106] For example, the upgrade operation for the multiple cluster units can be as follows: For the first cluster unit, first power down the control station and network interconnection equipment in the cluster unit, then perform controller rack replacement and upgrade, switch replacement and upgrade, whisker purging or aging replacement, then power up the control station and network interconnection equipment in the cluster unit, and then download and upgrade the code software. After the upgrade is completed, identify and test the differences in equipment status before and after the upgrade, the status of control station output commands, and the timing status of internal logic modules. After confirming that there are no abnormalities, the operator removes the risk isolation measures and ends the upgrade of the cluster unit. Then, repeat the above steps until the upgrade of the remaining cluster units is completed.
[0107] In some implementations, the process control layer includes a virtual ring network, which includes a main ring network and at least one sub-ring network. The main ring network includes a redundancy manager, and the network interconnection devices in the plurality of cluster units are connected to the sub-ring network. The operation of upgrading the plurality of cluster units during the upgrade time window of the process control layer can be: upgrading the control station in the plurality of cluster units during the upgrade time window of the process control layer, and upgrading the network interconnection devices in the plurality of cluster units based on the redundancy manager.
[0108] Because virtual ring networks (VRNs) possess a self-healing mechanism, they are equipped with a Redundancy Manager (RM) mode switch responsible for managing redundant connections within the network. This switch has two fiber optic interfaces, which are disconnected by default, forming a virtual breakpoint. In the event of a link failure (such as a partial upgrade), the RM automatically closes the breakpoint, creating an alternative path. Therefore, replacing local network interconnect devices only affects the control stations associated with those network nodes, without disrupting the entire ring network. Based on this, upgrades to network interconnect devices can be performed concurrently with upgrades to their connected control stations.
[0109] In this way, the impact of upgrading a few network interconnection devices on other devices can be reduced, ensuring the normal operation of the devices as much as possible.
[0110] Optionally, after any one of the multiple cluster units has been upgraded, the control station is subjected to step-level operation response verification, and / or, the control station is subjected to system-level diagnostic status real-time comparison verification; and / or, after any one of the multiple cluster units has been upgraded, the cluster unit is subjected to system-level diagnostic status real-time comparison verification.
[0111] This step-level operation response verification refers to immediately observing and verifying the status of the device's physical indicator lights, system alarm information, and other feedback signals after each critical hardware operation or software download instruction is executed, to ensure that they are consistent with expectations and prevent the accumulation of operational deviations.
[0112] This system-level real-time diagnostic status comparison verification refers to performing self-diagnosis using the control station's system self-diagnosis tools to obtain self-diagnosis information. Then, based on this self-diagnosis information, it compares online parameters such as communication status, module fault alarm counts, and network connection topology before and after the modification to determine if the control station has any abnormalities. For example, this self-diagnosis information may include one or more of the following: network connection status, power supply status, control station status, and connection status with other control stations. This application embodiment does not limit this.
[0113] For example, the operator station can issue commands to the control station (such as disconnecting a network connection), and then the operator can verify whether the control station port signal has disappeared, whether an alarm has occurred, and whether the communication of other devices has been affected. For instance, after powering on a newly modified device, observe whether the indicator lights on the newly powered device are displaying normally and whether the device fault alarm signal has disappeared. For example, if any abnormality is found, immediately interrupt the process and conduct an investigation.
[0114] In this way, problems after equipment upgrades can be identified and addressed promptly, preventing the accumulation of operational deviations. This reduces the probability and cost of rework, and increases the success rate of system upgrades.
[0115] Optionally, after upgrading the multiple cluster units within the upgrade time window of the process control layer, system function verification and / or overall performance verification of the process control layer can be performed.
[0116] System function verification refers to verifying the system functions of the process control layer. For example, system function verification may include one or more of the following: sampling test of I / O channel accuracy, conducting remote equipment transmission tests, verifying the correctness of key alarm logic, and verifying network signal consistency. This application embodiment does not limit the specifics. Specifically, sampling test of I / O channel accuracy refers to sampling and testing the interface I / O cards of the upgraded control station to verify whether the interface I / O cards function normally and whether the accuracy meets the standards. For example, adding an analog signal to determine whether the control station acquires it and whether the display is normal. The remote equipment transmission test refers to testing whether the upgraded control station can normally operate the controlled equipment. Verifying key alarm logic refers to verifying the alarm function in the upgraded control station. For example, simulating an important parameter (such as increased pump outlet pressure), the control station automatically calculates whether an alarm is automatically generated after the pressure exceeds a certain threshold. Network signal consistency refers to verifying whether different signal values sent by the upgraded control station can be normally received by the downstream control station and whether they change normally with different signal values.
[0117] The overall performance verification refers to the overall performance verification of the devices in the process control layer. For example, the overall performance verification may include evaluating one or more of the CPU, memory load, etc. of the controller under a new model, but this application embodiment does not limit this.
[0118] In some implementations, before the process control layer upgrades the multiple cluster units, the upgrade time window of each of the multiple cluster units can be matched with the main activity window of the nuclear power unit overhaul. The matching steps may include the following steps (1) to (4).
[0119] Step (1): For any one of the multiple cluster units, perform an equipment impact analysis on the control station in the cluster unit to obtain the impact analysis results. The impact analysis results are used to indicate one or more controlled devices affected by the control station in the cluster unit.
[0120] This equipment impact analysis refers to analyzing the configuration of each control station in a cluster unit to determine the controlled equipment controlled by each control station. For example, the hardwired input / output (I / O) and network signals of each control station within each cluster unit can be analyzed one by one to assess their impact on the control of controlled equipment, parameter monitoring, and logic interlocking. For example, the configuration of a control station may include control functions and control logic.
[0121] The impact analysis results include the controlled equipment or systems affected during the cluster unit upgrade process. For example, analyzing the configuration of control station 1 in cluster 1 determines that control station 1 controls controlled equipment such as valve A and pump B. Therefore, when upgrading control station 1, control station 1 will be unable to control any controlled equipment, which may lead to equipment malfunction and serious consequences. Thus, it can be determined that control station 1 affects controlled equipment such as valve A and pump B.
[0122] By identifying one or more controlled devices corresponding to each control station in the cluster unit, a basis can be provided for subsequently determining the types of affected devices corresponding to the cluster unit.
[0123] Step (2): Based on the impact analysis results, determine the type of affected device corresponding to the cluster unit.
[0124] The affected device type is the category of controlled devices affected by the cluster unit upgrade process.
[0125] Optionally, the operation of determining the type of affected device corresponding to the cluster unit based on the impact analysis results can be: determining window conditions based on the impact analysis results; and determining the type of affected device based on the window conditions.
[0126] The window conditions define the conditions for upgrading the controlled equipment included in the impact analysis results. The affected equipment type classifies the controlled equipment included in the impact analysis results.
[0127] This method allows for more accurate classification of controlled devices, which is helpful for subsequent cluster partitioning.
[0128] For example, as shown in Table 1 below, Table 1 is a classification of control station clusters provided in the embodiments of this application. Table 1 includes the type of affected equipment, cluster, number of control stations, typical impact, window conditions, etc. Here, the typical impact refers to the controlled equipment affected by the upgrade of cluster 1, the number of control stations is the number of control stations in the cluster, and the window conditions are the conditions for cluster upgrades obtained based on typical impact analysis. For example, the type of affected equipment may include clusters affecting regular island equipment, clusters affecting equipment in operation in column A, clusters executed after cold source recovery, and clusters that do not affect important equipment in operation undergoing major repairs.
[0129] Table 1
[0130] By identifying the affected device types corresponding to the cluster units, a basis is provided for matching the upgrade time window for each cluster unit.
[0131] Step (3): Determine the multiple sub-maintenance items corresponding to the upgrade time window of the process control layer.
[0132] These multiple sub-maintenance items are sub-tasks required during the overhaul phase of a nuclear power unit. For example, such as... Figure 7 As shown, the multiple sub-maintenance items may include at least two of the following: routine island isolation, maintenance of the A-column electrical panel, restoration of the two-column electrical panel, hydrostatic test, and maintenance of the B-column electrical panel. This application embodiment does not limit this.
[0133] Step (4): Based on the maintenance time window of the multiple sub-maintenance items and the type of affected equipment corresponding to each cluster unit in the multiple cluster units, determine the upgrade time window of each cluster unit in the multiple cluster units.
[0134] For example, these multiple sub-maintenance items can be matched with the affected equipment types and window conditions corresponding to these multiple cluster units to obtain the upgrade time window for each cluster unit. For example, such as Figure 7 As shown, after isolating the conventional island equipment, the window conditions for modifying clusters 1 and 2 are met. Therefore, within the time window of the conventional island equipment isolation, the "clusters affecting conventional island equipment" are modified. During the maintenance of the power supply panel in column A, the window conditions for modifying clusters 3, 4, 5, and 6 are met. Therefore, within the time window of the power supply panel maintenance in column A, the "clusters affecting the equipment in operation in column A" are modified. When the cold sources in columns A and B are both restored, the window conditions for modifying clusters 8, 9, and 10 are met. Therefore, within the time window of the cold sources in columns A and B being restored, the "clusters affecting cold source monitoring" are modified. During the maintenance of the power supply panel in column B, the window conditions for modifying clusters 7, 11, and 12 are met. Therefore, within the time window of the power supply panel maintenance in column B, the "clusters affecting the equipment in operation in column B" are modified. Clusters that do not affect important equipment in operation during major overhauls can be flexibly scheduled in various open windows.
[0135] In this way, the timing of cluster unit upgrades can be precisely embedded into the time window of corresponding sub-maintenance items. This ensures that functional failures during cluster unit upgrades occur precisely when the monitored process systems are already isolated or under maintenance. This achieves "risk hedging," enabling precise risk isolation and effective control, forming a multi-level, three-dimensional prevention and control system from the system level to the unit level. Furthermore, window matching ensures continuous monitoring of nuclear safety-related systems by the main control room, reducing the probability of operational events caused by modifications.
[0136] In some implementations, before upgrading the multiple cluster units within the upgrade time window of the process control layer, the following four methods can be used to perform functional compensation and physical protection for the control station and the controlled equipment controlled by the control station in the process control layer.
[0137] The first approach is to perform monitoring compensation for any one of the multiple cluster units, specifically for the monitoring functions that need to be maintained within that cluster unit.
[0138] Specifically, for monitoring functions that cannot be interrupted in this cluster unit, you can switch to the redundant column of the monitoring function, or set up a local temporary monitoring point to ensure the continuous execution of the monitoring function.
[0139] The second method is to physically isolate the control station in any one of the multiple cluster units from the equipment controlled by that control station. This physical isolation includes one or more of the following: power off, adding mechanical latches, and locking output cards.
[0140] The power-off refers to the power-off of affected motors and valves associated with the cluster unit to prevent upgrade failure or safety accidents caused by accidental start-up during the upgrade process.
[0141] The installation of mechanical latches refers to the installation of mechanical latches on valves associated with the cluster unit that need to maintain their state, in order to ensure that their state changes during the upgrade process.
[0142] The locked output card refers to the component in the control station of the cluster unit used to send control signals, in order to prevent the external command signals from being sent during the upgrade, which would cause the downstream controlled equipment to start running.
[0143] The third method: For any one of the multiple cluster units, set the mode of the equipment controlled by the control station in that cluster unit, including the maintenance mode.
[0144] For example, affected equipment such as diesel engines associated with the cluster unit can be placed in "maintenance mode" to prevent the equipment from being accidentally started during the upgrade process.
[0145] The fourth method: For any one of the multiple cluster units, the control station in that cluster unit is isolated from the equipment controlled by that control station.
[0146] Signal isolation refers to physically isolating the signal lines of non-de-energized systems or equipment, such as medium-voltage equipment, within the cluster unit at the terminal cabinet. For example, physical isolation of signal lines may include disconnecting the signal lines of the controlled equipment.
[0147] In this way, targeted risk prevention and control measures can be implemented for the control stations and devices controlled by the control stations in the cluster unit, reducing the impact on cluster unit upgrades. This improves upgrade stability and security, and increases upgrade efficiency.
[0148] For example, such as Figure 8As shown, the overall transformation process of the cluster unit forms a strict closed loop of "analysis-isolation-confirmation-construction-verification-recovery". The upgrade steps are as follows: After all functional compensation and physical protection measures for the cluster unit are completed, the control station and network interconnection equipment in the cluster unit are first powered down. Then, the controller rack is replaced and upgraded, the switch is replaced and upgraded, and the whiskers are purged or aged and replaced. Next, the control station and network interconnection equipment in the cluster unit are powered up, and the code software is downloaded and upgraded. After the upgrade is completed, the differences in equipment status before and after the transformation, the status of control station output commands, and the timing status of internal logic modules are identified and tested. After confirming that there are no abnormalities, the operator removes the risk isolation measures, ends the upgrade of this cluster unit, and continues the upgrade process for the next cluster unit.
[0149] Step 504: After the process control layer is successfully upgraded, upgrade the human-machine interface layer within the upgrade time window of the human-machine interface layer.
[0150] This process control layer is backward compatible. Upgrading the process control layer first, followed by upgrading the human-machine interface layer, will not affect normal interaction between the new and old versions of the process control layer, even if the upgrade fails. This improves system upgrade stability.
[0151] The process of upgrading the human-machine interface layer network can refer to the above-described process control layer network upgrade process, and will not be repeated in this embodiment.
[0152] In some implementations, before the upgrade of the human-machine interface layer is performed within the upgrade time window, the master and slave devices in the human-machine interface layer are controlled to run independently and in parallel.
[0153] The master and slave devices in this human-machine interface layer are configured with dual-row redundancy. During normal operation of this human-machine interface layer, the master devices operate normally, while the slave devices serve as backup devices. When the master devices experience abnormalities or failures, the slave devices are activated to continue operation in order to continuously monitor the operating status of the nuclear power plant.
[0154] For example, such as Figure 9 As shown, by modifying the system software redundancy configuration, the redundancy switching function can be temporarily canceled, and the separation point between the master and slave devices in the human-machine interface layer can be found to ensure that no abnormalities occur when the master and slave devices run independently in parallel. The original master-slave hot standby operation mode can be switched to an independent parallel operation mode of columns A and B, with each column of columns A and B having complete monitoring capabilities.
[0155] This approach lays the foundation for subsequent upgrades and replacements of the human-machine interface layer.
[0156] In some implementations, step 504 can be performed by alternating upgrades of the master device and the slave device within the upgrade time window of the human-machine interface layer.
[0157] By using a rotational upgrade approach, the main control room maintains full monitoring capabilities throughout the upgrade process of the human-machine interface layer, ensuring absolute continuity of monitoring functions. This reduces the risks associated with system upgrades and guarantees system stability. Furthermore, rotational upgrades ensure continuous monitoring of nuclear safety-related systems by the main control room, lowering the probability of operational events that may be triggered by upgrades.
[0158] For example, the steps of rotating the upgrade of the master device and the slave device may include the following steps (1) to (6).
[0159] Step (1): Shut down the old B column equipment in the human-machine interface layer, and let the old A column equipment independently assume all monitoring functions.
[0160] Step (2): Physically isolate the network in column B, and replace the hardware and upgrade the software of all servers, workstations and other equipment in column B.
[0161] This physical isolation refers to disconnecting the physical connection between the A-column network and the B-column network to prevent power-on / off or restart operations performed during the upgrade of the B-column network from affecting the A-column network.
[0162] Step (3): Start the upgraded new device in column B to form a mixed state in which the old device in column A and the new device in column B run in parallel. Then, complete the testing and evaluation of column B.
[0163] Step (4): Shut down the old equipment in column A and let the new equipment in column B take over the monitoring independently.
[0164] Step (5): Upgrade the old device in column A and restore network connectivity.
[0165] Step (6): Start the new device in column A, and restore the redundant configuration between columns A and B after completing the testing and verification of column A.
[0166] In some implementations, after the single-column server in the human-machine interface layer has been upgraded, step-level operation response verification can be performed on the single-column server, and / or, system-level diagnostic status real-time comparison verification can be performed on the single-column server.
[0167] Step-by-step operation response verification for this single-column server refers to immediately observing and verifying the status of the device's physical indicator lights, system alarm information, and other feedback signals after each critical hardware operation or software download instruction is executed, to ensure that they are consistent with expectations and prevent the accumulation of operational deviations.
[0168] Real-time system-level diagnostic status comparison and verification for this single-column server refers to using an older, still stable column as a benchmark, and comparing the key parameter display values, system alarm lists, and historical data record integrity on the old and new columns online using scripts or tools to check for consistency. For example, this method can detect the vast majority of configuration or data consistency issues within minutes.
[0169] Optionally, after upgrading the human-machine interface layer within its upgrade time window, system function verification and / or overall performance verification can be performed on the human-machine interface layer.
[0170] For example, the system function verification may include checking the fluency and integrity of the human-computer interaction function, testing the server and network redundancy switching function, the backup panel switching function, and the clock synchronization performance, etc., and this application embodiment does not limit this.
[0171] For example, the overall performance verification may include evaluating one or more of the following under the new system architecture: overall network load, server response time, etc., and this application embodiment does not limit this.
[0172] It should be noted that in this embodiment, the upgrade of the human-machine interface layer follows that of the process control layer. Large-scale connections between the upgraded human-machine interface layer and the upgraded process control layer can only be implemented in the later stages of the overhaul. If systemic failures such as communication interruptions or data inconsistencies occur between the upgraded human-machine interface layer and the upgraded process control layer, there will be extremely limited time for handling these issues. This could lead to a complete rollback of the human-machine interface layer, or even the failure of the entire nuclear power plant DCS retrofit project. Therefore, a "LEVEL 2 minimal verification platform" can be implemented within the upgrade time window of the process control layer to verify the connection status and functional interactions between the upgraded human-machine interface layer and the upgraded process control layer in advance. This allows for the early detection of problems between the two layers, providing ample time for troubleshooting and resolution.
[0173] In some implementations, before upgrading the human-machine interface layer within its upgrade time window, the target device in the human-machine interface layer is upgraded within the upgrade time window of the process control layer; after the process control layer is successfully upgraded, a minimal system verification environment is constructed based on the process control layer and the target device; system verification is performed based on the minimal system verification environment; if the system verification passes, the operation of upgrading the human-machine interface layer within its upgrade time window is executed.
[0174] The minimal system verification environment refers to the system environment that constitutes the basic functions of the human-machine interface layer.
[0175] The target device is the device in the human-machine interface layer that needs to be upgraded beforehand. The target device is a device capable of implementing the basic functions of the human-machine interface layer. For example, the target device may include multiple servers, multiple workstations, etc., but this application embodiment does not limit this. For instance, such as... Figure 10 As shown, the one or more servers may include a terminal server, a history server, and a process server, and the one or more operator stations may include an operator station and an engineer station.
[0176] For example, such as Figure 10 As shown, upgrading the target equipment in the human-machine interface layer can be carried out after most of the equipment in the process control layer has been modified and before the major overhaul hydrostatic test begins. Since the upgraded equipment is compatible with the old version of the human-machine interface layer, the upgraded process control layer can communicate normally with the un-upgraded human-machine interface layer after most of the equipment in the process control layer has been modified, ensuring the normal progress of subsequent major overhaul work (such as hydrostatic testing).
[0177] For example, such as Figure 11 As shown, this LEVEL 2 minimal verification platform can be built based on the upgraded operator station, engineer station, terminal server, historical server, process server, and the un-upgraded switch and process server. It should be noted that since the process server is responsible for the interaction between the human-machine interface layer and the process control layer, the un-upgraded process server can be retained to avoid affecting the subsequent control and monitoring of the system by the human-machine interface layer due to problems with the upgraded process server.
[0178] For example, full-scale systematic verification such as data communication, screen invocation, and alarm testing can be performed on this LEVEL 2 minimal verification platform.
[0179] By conducting system verification in advance, potential problems with the human-machine interface layer after the upgrade can be identified early. This shifts the identification and resolution of the greatest technical risks from the later stages of a major overhaul to the more relaxed early to mid-stages, allowing ample time for problem investigation and handling. This, in turn, increases the upgrade success rate.
[0180] For example, if the system fails verification, you can contact the manufacturer for evaluation and resolve the problem in a timely manner.
[0181] For example, if the system passes verification, the LEVEL 2 minimal verification platform can be shut down and the old LEVEL 2 server can be started to ensure that the system still has full redundancy during the hydrostatic test, so that the verified new equipment can be reactivated when the formal LEVEL 2 upgrade window arrives.
[0182] In this embodiment, the upgrade time windows for the human-machine interface layer and the process control layer of the nuclear power plant are determined based on the overhaul time window of the nuclear power plant. The upgrade time window for the process control layer is earlier than that for the human-machine interface layer. Then, multiple cluster units within the process control layer are identified. Each cluster unit includes a control station and associated network interconnection equipment. These cluster units are upgraded within the process control layer's upgrade time window. After the process control layer upgrade is successful, the human-machine interface layer is upgraded within its upgrade time window. Because the upgrade time windows for the process control layer and the human-machine interface layer are determined based on the overhaul time window of the nuclear power plant, the upgrade of the nuclear power plant's DCS can be completed within that overhaul time window. This allows for more efficient use of the overhaul time, eliminates the need to apply for a system-wide shutdown window, and avoids violating nuclear safety monitoring requirements. This improves system upgrade efficiency and ensures system operational safety. Furthermore, since the upgraded process control layer has backward compatibility, upgrading the human-machine interface layer after the process control layer upgrade is successful reduces system risks associated with the upgrade and improves system upgrade stability.
[0183] Figure 12 This is a schematic diagram of a system upgrade device provided in an embodiment of this application. The device can be implemented as part or all of a computer device by software, hardware, or a combination of both, and this computer device can be as described below. Figure 13 The computer equipment shown. See also Figure 12 The device includes: a first determining module 1201, a second determining module 1202, a first upgrading module 1203, and a second upgrading module 1204.
[0184] The first determining module 1201 is used to determine the upgrade time window of the human-machine interface layer and the upgrade time window of the process control layer in the nuclear power plant based on the overhaul time window of the nuclear power plant. The upgrade time window of the process control layer is earlier than the upgrade time window of the human-machine interface layer. The second determining module 1202 is used to determine multiple cluster units in the process control layer, each of the multiple cluster units including a control station and associated network interconnection devices; The first upgrade module 1203 is used to upgrade the multiple cluster units within the upgrade time window of the process control layer; The second upgrade module 1204 is used to upgrade the human-machine interface layer during the upgrade time window of the human-machine interface layer after the process control layer is successfully upgraded.
[0185] Optionally, the first determining module 1201 is used for: Determine the multiple maintenance items corresponding to this major overhaul time window; Based on the maintenance time windows of these multiple maintenance items, determine the upgrade time window for the human-machine interface layer and the upgrade time window for the process control layer.
[0186] Optionally, the multiple maintenance items include at least two of the following: unit downhill, low-low water level maintenance, hydrostatic test, reactor pressure vessel maintenance, containment pressure test, and unit uphill.
[0187] Optionally, the second determining module 1202 is used for: For any pair of redundant network interconnected devices in the process control layer, the pair of redundant network interconnected devices and all control stations connected to the pair of redundant network interconnected devices are divided into a cluster unit.
[0188] Optionally, the device further includes: The monitoring compensation module is used to perform monitoring compensation for any one of the multiple cluster units, for the monitoring functions that need to be maintained in that cluster unit.
[0189] Optionally, the device further includes: The physical isolation module is used to physically isolate the control station in any one of the multiple cluster units from the equipment controlled by that control station. The physical isolation includes one or more of the following: power off, adding a mechanical latch, and locking the output card.
[0190] Optionally, the device further includes: The mode setting module is used to set the mode of the equipment controlled by the control station in any one of the multiple cluster units. The mode includes maintenance mode.
[0191] Optionally, the device further includes: The signal isolation module is used to isolate the control station in any one of the multiple cluster units from the equipment controlled by that control station.
[0192] Optionally, the device further includes: The analysis module is used to perform equipment impact analysis on the control station in any one of the multiple cluster units, and obtain the impact analysis results. The impact analysis results are used to indicate one or more controlled devices affected by the control station in the cluster unit. The third determination module is used to determine the type of affected device corresponding to the cluster unit based on the impact analysis results; The fourth determination module is used to determine multiple sub-maintenance items corresponding to the upgrade time window of the process control layer; The fifth determination module is used to determine the upgrade time window of each cluster unit in the multiple cluster units based on the maintenance time window of the multiple sub-maintenance items and the type of affected equipment corresponding to each cluster unit in the multiple cluster units.
[0193] Optionally, the third determining module is used for: Based on the results of this impact analysis, window conditions are determined; The type of device affected is determined based on the window conditions.
[0194] Optionally, the process control layer includes a virtual ring network, which includes a main ring network and at least one sub-ring network. The main ring network includes a redundancy manager, and the network interconnection devices in the plurality of cluster units are connected to the sub-ring network. The first upgrade module 1203 is used for: During the upgrade time window of this process control layer, the control stations in the multiple cluster units are upgraded, and the network interconnection devices in the multiple cluster units are upgraded based on the redundancy manager.
[0195] Optionally, the device further includes: The first verification module is used to perform step-level operation response verification on any one of the multiple cluster units after the upgrade of the control station, and / or to perform system-level diagnostic status real-time comparison verification on the control station; and / or to perform system-level diagnostic status real-time comparison verification on any one of the multiple cluster units after the upgrade of the cluster unit.
[0196] Optionally, the device further includes: The second verification module is used to perform system function verification and / or overall performance verification of the process control layer.
[0197] Optionally, the device further includes: The control module is used to control the independent and parallel operation of the master and slave devices in this human-machine interface layer.
[0198] Optionally, the second upgrade module 1204 is used for: During the upgrade time window of the human-machine interface layer, the master device and the slave device are upgraded alternately.
[0199] Optionally, the device further includes: The third upgrade module is used to upgrade the target device in the human-machine interface layer within the upgrade time window of the process control layer; The building module is used to construct a minimal system verification environment based on the process control layer and the target device after the process control layer is successfully upgraded. The third verification module is used to perform system verification based on this minimized system verification environment; The operation module is used to perform the upgrade operation of the human-machine interface layer within the upgrade time window when the system verification is successful.
[0200] In this embodiment, the upgrade time windows for the human-machine interface (HMI) layer and the process control layer of the nuclear power plant are determined based on the plant's overhaul time window. The process control layer upgrade time window is earlier than the HMI layer upgrade time window. Multiple cluster units within the process control layer are identified, each including a control station and associated network interconnection devices. These cluster units are upgraded within the process control layer's upgrade time window. After the process control layer upgrade is successful, the HMI layer is upgraded within its own upgrade time window. Because the upgrade time windows for the process control layer and the HMI layer are determined based on the nuclear power plant's overhaul time window, the upgrade of the nuclear power plant's DCS can be completed within that window. This allows for more efficient use of the overhaul time, eliminates the need for a system-wide shutdown window, and avoids violating nuclear safety monitoring requirements, thereby improving system upgrade efficiency and ensuring system operational safety. Furthermore, since the upgraded process control layer has backward compatibility, upgrading the HMI layer after the process control layer upgrade is successful reduces system risks and improves system upgrade stability.
[0201] It should be noted that the system upgrade device provided in the above embodiments is only illustrated by the division of the above functional modules when upgrading the system. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0202] The functional modules in the above embodiments can be integrated into one processing unit, or each functional module can exist as a separate physical processing unit, or two or more functional modules can be integrated into one processing unit. The processing unit can be implemented in hardware or software. Furthermore, the specific names of the functional modules are only for easy differentiation and are not intended to limit the scope of protection of the embodiments of this application.
[0203] The system upgrade device and system upgrade method provided in the above embodiments belong to the same concept. The specific working process and technical effects of the functional modules in the above embodiments can be found in the method embodiments section, and will not be repeated here.
[0204] Figure 13 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 13As shown, the computer device 13 includes a processor 130, a memory 131, and a computer program 132 stored in the memory 131 and executable on the processor 130. When the processor 130 executes the computer program 132, it implements the steps in the system upgrade method in the above embodiments.
[0205] Computer device 13 can be a general-purpose computer device or a special-purpose computer device. In specific implementations, computer device 13 can be a desktop computer, portable computer, network server, handheld computer, mobile phone, tablet computer, wireless terminal device, communication device, or embedded device. This application embodiment does not limit the type of computer device 13. Those skilled in the art will understand that... Figure 13 The computer device 13 is merely an example and does not constitute a limitation on the computer device 13. It may include more or fewer components than shown, or combine certain components, or different components, such as input / output devices, network access devices, etc.
[0206] Processor 130 can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.
[0207] In some embodiments, memory 131 may be an internal storage unit of the computer device 13, such as a hard disk or RAM of the computer device 13. In other embodiments, memory 131 may be an external storage device of the computer device 13, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device 13. Furthermore, memory 131 may include both internal and external storage units of the computer device 13. Memory 131 is used to store the operating system, applications, boot loader, data, and other programs. Memory 131 may also be used to temporarily store data that has been output or will be output.
[0208] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0209] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0210] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, can implement the steps in the various method embodiments described above.
[0211] This application provides a computer program product that, when run on a computer, causes the computer to perform the steps described in the various method embodiments above.
[0212] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above method embodiments of this application can be implemented by a computer program. This computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate form. The computer-readable storage medium can include at least: any entity or device capable of carrying computer program code to a computer device, recording media, computer memory, read-only memory (ROM), random access memory (RAM), compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage devices. The computer-readable storage medium mentioned in this application can be a non-volatile storage medium; in other words, it can be a non-transient storage medium.
[0213] It should be understood that all or part of the steps of the above embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented in whole or in part as a computer program product. The computer program product includes one or more computer instructions. The computer instructions can be stored in the above-described computer-readable storage medium.
[0214] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0215] In the embodiments provided in this application, it should be understood that the disclosed apparatus / computer devices and methods can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms. Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, i.e., they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this application according to actual needs.
[0216] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0217] The embodiments described above are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A system upgrade method, characterized in that, Applied to nuclear power plants, the method includes: The upgrade time windows of the human-machine interface layer and the process control layer in the nuclear power plant are determined based on the overhaul time window of the nuclear power plant, and the upgrade time window of the process control layer is earlier than the upgrade time window of the human-machine interface layer. The process control layer is defined as having multiple cluster units, each of which includes a control station and associated network interconnection devices; Upgrade the multiple cluster units within the upgrade time window of the process control layer; After the process control layer is successfully upgraded, the human-machine interface layer is upgraded during the upgrade time window of the human-machine interface layer.
2. The method as described in claim 1, characterized in that, The determination of the upgrade time window for the human-machine interface layer and the upgrade time window for the process control layer of the nuclear power plant based on the overhaul time window of the nuclear power plant includes: Determine the multiple maintenance items corresponding to the overhaul time window; The upgrade time window for the human-machine interface layer and the upgrade time window for the process control layer are determined based on the maintenance time windows of the multiple maintenance items.
3. The method as described in claim 2, characterized in that, The multiple maintenance items include at least two of the following: unit descent, low-low water level maintenance, hydrostatic test, reactor pressure vessel maintenance, containment pressure test, and unit ascent.
4. The method as described in claim 1, characterized in that, The determination of multiple cluster units in the process control layer includes: For any pair of redundant network interconnected devices in the process control layer, the pair of redundant network interconnected devices and all control stations connected to the pair of redundant network interconnected devices are divided into a cluster unit.
5. The method as described in claim 1, characterized in that, Before upgrading the multiple cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the multiple cluster units, monitoring compensation is performed on the monitoring functions that need to be maintained in the cluster unit.
6. The method as described in claim 1, characterized in that, Before upgrading the multiple cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, the control station in the cluster unit is physically isolated from the equipment controlled by the control station. The physical isolation includes one or more of the following: power off, adding mechanical latches, and locking output cards.
7. The method as described in claim 1, characterized in that, Before upgrading the multiple cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, the mode is set for the equipment controlled by the control station in the cluster unit, and the mode includes maintenance mode.
8. The method as described in claim 1, characterized in that, Before upgrading the multiple cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, the control station in the cluster unit is isolated from the equipment controlled by the control station.
9. The method as described in claim 1, characterized in that, Before upgrading the multiple cluster units within the upgrade time window of the process control layer, the method further includes: For any one of the plurality of cluster units, an equipment impact analysis is performed on the control station in the cluster unit to obtain the impact analysis result. The impact analysis result is used to indicate one or more controlled devices affected by the control station in the cluster unit. Based on the impact analysis results, determine the type of affected device corresponding to the cluster unit; Determine multiple sub-maintenance items corresponding to the upgrade time window of the process control layer; Based on the maintenance time windows of the multiple sub-maintenance items and the affected equipment type corresponding to each of the multiple cluster units, the upgrade time window of each of the multiple cluster units is determined.
10. The method as described in claim 9, characterized in that, The step of determining the type of affected device corresponding to the cluster unit based on the impact analysis results includes: Window conditions are determined based on the impact analysis results; The affected device type is determined based on the window conditions.
11. The method as described in claim 1, characterized in that, The process control layer includes a virtual ring network, which includes a main ring network and at least one sub-ring network. The main ring network includes a redundancy manager. The network interconnection devices in the plurality of cluster units are connected to the sub-ring network. Upgrading the plurality of cluster units within the upgrade time window of the process control layer includes: During the upgrade time window of the process control layer, the control stations in the plurality of cluster units are upgraded, and the network interconnection devices in the plurality of cluster units are upgraded based on the redundancy manager.
12. The method as described in claim 1, characterized in that, The method further includes: After any one of the multiple cluster units completes its upgrade, the control station is subjected to step-level operation response verification, and / or, the control station is subjected to system-level diagnostic status real-time comparison verification; and / or, after any one of the multiple cluster units completes its upgrade, the cluster unit is subjected to system-level diagnostic status real-time comparison verification.
13. The method as described in claim 1, characterized in that, After upgrading the multiple cluster units within the upgrade time window of the process control layer, the process further includes: Perform system function verification and / or overall performance verification on the process control layer.
14. The method as described in claim 1, characterized in that, Before upgrading the human-machine interface layer within the upgrade time window, the method further includes: Control the master and slave devices in the human-machine interface layer to operate independently and in parallel; Upgrading the human-machine interface layer within the upgrade time window of the human-machine interface layer includes: The master device and the slave device are upgraded alternately during the upgrade time window of the human-machine interface layer.
15. The method according to any one of claims 1 to 14, characterized in that, Before upgrading the human-machine interface layer within the upgrade time window, the method further includes: Upgrade the target device in the human-machine interface layer within the upgrade time window of the process control layer; After the process control layer is successfully upgraded, a minimal system verification environment is constructed based on the process control layer and the target device. System verification is performed based on the minimized system verification environment described above. If the system verification is successful, the operation of upgrading the human-machine interface layer is performed within the upgrade time window of the human-machine interface layer.
16. A computer device, characterized in that, The computer device includes a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the computer program, when executed by the processor, implements the method as described in any one of claims 1 to 15.
17. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method as described in any one of claims 1 to 15.
18. A computer program product, characterized in that, When the computer program product is run on a computer device, the computer device causes the computer device to perform the method as described in any one of claims 1 to 15.