Smart notification of field device loop warning parameters changes
By introducing a security service module into the DCS system to intercept and approve parameter change commands from the AMS, the potential destructive problems caused by the auxiliary system modifying external devices of the DCS are resolved. This enables secure verification of critical parameters and operator informed consent, thereby improving the safety and controllability of factory equipment maintenance.
Patent Information
- Application Number
- CN202011230433.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-11-06
- Filing Date
- 2020-11-06
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2040-11-06
AI Technical Summary
During the maintenance and health monitoring of plant equipment, auxiliary systems such as AMS may modify parameters of field devices outside the DCS, potentially disrupting active plant processes, and operators may not be aware of or approve these modifications in a timely manner.
The Security Service Module (SSM) is introduced to intercept write or parameter change commands from AMS. Through the approval process of DCS operators, it is ensured that modifications to critical parameters are verified and approved within the DCS system before execution.
It effectively prevents potentially disruptive modifications to active plant processes, ensures operators' right to know about all parameter changes, and improves the safety and controllability of plant equipment maintenance.
Smart Images

Figure CN112783110B_ABST
Abstract
Description
Technical Field
[0001] This disclosure generally relates to process control systems, and more specifically, to process control systems communicatively coupled to a separate auxiliary system having independent access to the equipment of the process control system, wherein write commands to the plant equipment are validated between the two systems. Background Technology
[0002] A plant's distributed control system (DCS) can include field devices, input / output (I / O) devices, controllers, and operator workstations. This DCS can include applications necessary for coordinating and controlling various processes within the plant. Other auxiliary tools and applications have been developed to support plant operations, but may not be part of direct plant control. Such functionality can include equipment maintenance and health monitoring that can be performed by an asset management system or asset maintenance system. Since maintenance and health monitoring functions traditionally require access to plant equipment (sometimes through direct physical access by instrumentation technicians), the development of asset management systems may have introduced independent access to field devices actively controlled by the DCS in real-time plant operations.
[0003] Because independent communication paths may exist between AMS and DCS applications on the same plant equipment set, the following situation exists: instrumentation technicians can issue write commands to field devices that can modify active control processes without the knowledge or approval of users on the operational side of the process control system (such as DCS operators). Since operators may have more knowledge of the currently active processes in the plant controlled by the DCS, this method and system can provide a verification process involving active inputs and information on the DCS side before the write command is executed or submitted to the plant equipment. Summary of the Invention
[0004] This disclosure describes a distributed control system including at least one controller and one field device, and a second system with independent access to the DCS's plant equipment, wherein write commands from the second system to the DCS plant equipment are intercepted for an approval process. The approval process may include sending a notification to the DCS workstation alerting the operator that a write command or parameter change command to the DCS's field device or other plant equipment has been intercepted. This process may involve the DCS workstation sending an approval decision for the parameter change command. The approval decision can then be used to release the intercepted parameter change command for execution or commit at the field device or other plant equipment, or to terminate the parameter change command.
[0005] In some embodiments, the interception of the parameter change command is performed by a security service module. This security service module may be a component of the second system, or in some embodiments, it may perform some of its functions independently of the second system. In some embodiments, a workstation of the second system may receive an approval decision from the DCS and display a message corresponding to that approval decision to a user of the second system. In some embodiments, the second system may be an asset management system or asset maintenance system for providing monitoring and maintenance of factory equipment health. Attached Figure Description
[0006] Figure 1 It is a block diagram of a distributed process control network located within a process plant or other industrial setting, which includes industrial computing devices, each with a platform using a communication architecture.
[0007] Figure 2 An asset management system (AMS) that can be coupled to a distributed process control system (DCS) is shown.
[0008] Figure 3 This illustrates a system in which the AMS can share a communication network with the DCS to communicate with factory equipment.
[0009] Figure 4 This illustrates another system in which the AMS is coupled to the DCS via a communication network, while simultaneously communicating with plant equipment using a separate communication network.
[0010] Figure 5 An exemplary warning screen for the user interface of AMS without an approval process is shown.
[0011] Figure 6 It shows the relationship with Figure 2 A similar system, which adds a security service module that enables communication coupling between the AMS workstation and the DCS operator workstation.
[0012] Figure 7A It shows Figure 3 The system adds a security service module that enables communication coupling between the AMS workstation and the DCS operator workstation.
[0013] Figure 7B It shows the relationship with Figure 7A A similar communication architecture, in which the security service module is communicatively coupled to the public network, rather than directly coupled between the AMS workstation and the DCS workstation.
[0014] Figure 7C It shows Figure 4 The system adds a security service module that enables communication coupling between the AMS workstation and the DCS operator workstation.
[0015] Figure 8 A method for verifying or adjudicating write commands or parameter change commands for plant equipment in a distributed control system is shown.
[0016] Figure 9 A graphical user interface 900 for a possible controller is shown, which displays a dashboard view of a portion of the process within the plant and has an overlay diagram of the distributed control system.
[0017] Figure 10 This shows a possible alert that can be displayed on the operator's workstation in the DCS to indicate the intercepted parameter change command.
[0018] Figure 11 The possible messages corresponding to the approval response from the DCS for the parameter change command are shown.
[0019] Figure 12 The following shows possible messages corresponding to a rejection response from the DCS for a parameter change command.
[0020] Figure 13 A specific embodiment in which AMS is implemented as a Field Device Integration (FDI) server component is shown.
[0021] Figure 14 An approved system employing a mobile computing device with wireless access to DCS and factory equipment is shown. Detailed Implementation
[0022] Figure 1 A process control system 12 in process plant 10 is shown. More specifically, process control system 12 may represent a distributed process control system or DCS. Process plant 10 also includes one or more host workstations, computers, or user interfaces 16 (which may be any type of personal computer, workstation, etc.) accessible to plant personnel (such as process control operators, maintenance personnel, configuration engineers, etc.). Figure 1 In the example shown, user interface 16 is shown connected to process control node 18 and configuration database 21 via a common communication line or bus 22. Communication network 22 can be implemented using any desired bus-based or bus-free hardware, any desired hardwired or wireless communication architecture, and any desired or suitable communication protocol (such as Ethernet).
[0023] Generally, node 18 of process plant 10 includes process control system devices connected together via a bus structure, which can be provided on a baseboard to which different devices are attached. Node 18 (which can represent multiple nodes) in Figure 1The diagram shows a process controller 24 (which may represent multiple controllers) and one or more process control system input / output (I / O) devices 28, 30, and 32. Each of the process control system I / O devices 28, 30, and 32 is communicatively connected to a set of field devices associated with the process control (in... Figure 1 (Shown as field devices 40 and 42). Workstation 16, process controller 24, I / O devices 28-32, and controller field devices 40 and 42 typically constitute... Figure 1 Distributed process control system (DCS) 12.
[0024] Process controller 24 (by way of example only, it could be DeltaV sold by Emerson Process Management) TM The controller (or any other desired type of process controller) is programmed to provide process control functions (using what are commonly referred to as control modules) using I / O devices 28, 30, and 32 and field devices 40 and 42. Specifically, controller 24 implements or supervises one or more process control routines 75 (also referred to as control modules) stored therein or otherwise associated with it and communicates with field devices 40 and 42 and workstation 16 to control process 10 or a portion thereof in any desired manner. Field devices 40 and 42 can be any desired type of field device (such as sensors, valves, transmitters, positioners, etc.) and can conform to any desired open, proprietary, or other communication or programming protocol, including, for example, HART or 4-20mA protocols (as shown for field device 40), any fieldbus protocol (such as... Fieldbus protocol (as shown for field device 42) or CAN, Profibus, AS-i protocol, etc. Similarly, I / O devices 28-32 can be any known type of process control I / O device using any suitable communication protocol.
[0025] In each of the nodes 18, a common backplane 76 (represented by dashed lines through the controller 24 and I / O devices 28-36) is used to connect the controller 24 to the process control I / O cards 28, 30, and 32. The controller 24 is also communicatively coupled to the bus 22 and acts as a bus arbiter for the bus 22, enabling each I / O device in the I / O devices 28-32 to communicate with any workstation 16 via the bus 22.
[0026] Figure 1Multiple workstations 16 are shown that can be coupled to the DCS. These workstations can be programmed to execute standard operational control applications for running the plant. These standard operational control applications can be considered part of the DCS because field devices may be needed to control and manipulate plant processes. In addition to the workstations used for plant operation, some workstations can be externally coupled to bus 22 and run applications for auxiliary functions outside of DCS operational control. In other words, some of these applications may have access to plant equipment that is not directly involved in the operational control of the plant (such as plant equipment maintenance and monitoring). One such application is an asset management system.
[0027] Figure 2 An asset management system (AMS) 200 that can be coupled to a distributed process control system (DCS) 112 is shown. Similar to... Figure 1 , Figure 2 The DCS 112 may include at least one operator workstation 116, at least one controller 124, at least one I / O device 128 and one or more field devices 140. Figure 2 It is shown that each of the factory devices (124, 128, 140) in the DCS 112 factory equipment can communicate within the DCS system using communication lines 151, 152, 153 or 154.
[0028] Figure 2 The devices shown in the DCS 112 can also be communicatively coupled to the AMS 200. The AMS 200 may include a computer or workstation 201, which may represent multiple workstations or computing devices that can be used to perform maintenance functions on plant equipment. Workstation 201 may provide a user interface to, for example, an instrumentation technician whose role is to monitor and maintain one or more devices in the DCS 112. The DCS 112 may be controlled by one or more plant operators who interact with the DCS 112 using DCS control programs through one or more operator workstations 116. The AMS computing device 201 may also represent a network of one or more workstations or servers providing monitoring and maintenance functions to multiple users.
[0029] Typically, AMS 200 manages information related to one or more devices or components within DCS 112. In some industries, the Asset Management System (AMS) 200 may also be referred to as an asset maintenance system. AMS 200 can monitor and collect information from plant equipment and perform diagnostics to identify different fault symptoms in the plant equipment. For example, the overall health and lifespan of plant equipment and assets can be determined and recorded using the functions and tools of AMS 200. In operation, AMS 200 can perform various tests on plant equipment to obtain information for calculating the health status and maintenance requirements of the plant equipment. In some embodiments, AMS 200 can perform read and write operations on plant equipment such as controller 124, I / O devices 128, field devices 140, and any other plant equipment. Based on the diagnostics performed by AMS 200 on the information extracted from the plant equipment, AMS 200 can be programmed to prompt the user to adjust or modify the parameters of the plant equipment (such as controller 124, I / O 128, or field devices 140) to improve its efficiency. A typical user of AMS 200 is an instrumentation technician. In some embodiments, AMS 200 can be programmed to automatically adjust or modify parameters of plant equipment (such as controller 124, I / O 128, or field device 140) to improve their efficiency.
[0030] like Figure 2 As shown, AMS 200 can be communicatively coupled to one or more devices 124, 128, 140 of DCS 112, and independently of DCS 112. Communication lines 251-254 can represent separate or independent communication networks, independent of the communication and control networks 151-154 of DCS 112. For example, as... Figure 2 As shown, the AMS may have separate physical communication lines 251-254 and ports (not shown) to one or more devices in the DCS, separate from the physical communication lines 151-154 and ports used by the devices in the DCS, to communicate with other components or devices in the DCS 112. In some embodiments, the AMS 200 may communicate with devices in the DCS 112 via a logical port different from the logical port used by the DCS 112 to send control signals or communicate between devices in the DCS 112. Due to the separate and independent communication paths between the AMS 200 and the DCS 112 to the plant devices 124, 128, 140, instrument technicians can make modifications to the plant devices 124, 128, 140 without the knowledge or approval of the plant operators, where such modifications may have harmful or destructive effects on the current plant processes.
[0031] Figure 3The system shown includes an AMS 200 that can share a communication network 160 with a DCS 112 to communicate with plant equipment 124, 128 and 140. Figure 3 The AMS 200 and DCS 112 can be used with Figure 2 The AMS 200 and DCS 112 are similar and similarly labeled. The shared communication network 160 can be, for example, Ethernet. Although communication between the plant equipment and the AMS and DCS can be shared to the common communication network, line, or link 160 of the controller 124, field devices 140, or other plant equipment, the AMS may be able to communicate directly with plant equipment 124, 128, 140 and send commands to change or modify the parameters of plant equipment 124, 128, 140 without first communicating with or through the DCS system 112 or operator applications (e.g., performed at workstation 116). Figure 3 In this system, both AMS 200 and DCS 112 can communicate directly with controller 124 or field devices 140 or any other devices in the plant using the common plant network 160, where AMS 200 does not need to communicate through DCS 112, but rather via a controller application running on workstation 116. More specifically, Figure 2 and Figure 3 The system demonstrates that AMS 200 can unilaterally modify parameters of factory equipment (such as controller 124, I / O 128, and field devices). For the sake of simplicity in further discussion of parameter modifications to factory equipment, where parameter modifications initiated by AMS are described as being applied to controllers or field devices, it should be understood that in any embodiment described or claimed in this application, AMS may be able to perform the same or similar parameter modifications on any or all components of the DCS (e.g., servers, workstations, controllers, I / O, field devices, etc.).
[0032] Figure 4 Another system is shown, in which the AMS is coupled to the DCS. Figure 4 In this architecture, the DCS and AMS can be communicatively coupled to each other via a communication network 160 connecting workstation 201 of AMS 200 and workstation 116 of DCS 112. In this scenario, some level of information exchange may exist between the two systems, although each system can still independently modify field devices. Despite... Figure 2-4The system may include a shared communication line between the AMS 200 and DCS 112, but problems can still arise when the actions of AMS 200 users (such as instrumentation technicians) conflict with the operation of the plant's DCS 112 controllers in a potentially destructive manner. Such conflicts occur simply because the operators currently managing these processes have a higher level of understanding and awareness of the current process activities within the plant than their instrumentation technicians, whose maintenance responsibilities are more periodic.
[0033] Typically, AMS 200 can collect information from plant equipment 124, 128, and 140 to determine the health status of various plant devices and improve equipment operation. In this way, AMS 200 can assist instrumentation technicians in providing maintenance, upkeep, and upgrades for field equipment. AMS 200 can prompt users to make adjustments based on their calculations, or in some systems, AMS 200 can automatically make a set of adjustments. In many cases, collecting the information needed to determine health status and provide recommended adjustments requires performing one or more tests on the target plant equipment (such as 124, 128, or 140). During testing, one or more equipment parameters or configuration parameters may need to be modified. Therefore, at least two situations may require parameter modifications to controllers or field equipment via AMS: during testing and during equipment calibration after testing.
[0034] However, problems may arise when the equipment is active or being commissioned by a user outside the DCS 112 operating environment (e.g., when using AMS 200). While testing equipment in DCS 112 when field device 124 is inactive or offline can ideally be performed, taking the equipment offline may be impractical or difficult. This could be the case when a critical process is currently in progress and the plant process cannot be shut down. Similarly, when instrumentation technicians need to test plant equipment, situations may arise where faults are displayed or signs of potential malfunction or functional degradation are shown when the plant equipment is operational and active.
[0035] assumed Figure 2-4Systems that allow auxiliary systems such as AMS to modify plant equipment outside the DCS can conflict when maintenance processes involving parameter modifications (e.g., write commands) to active, commissioned field equipment may cause disruptive operational changes in real-time. While instrumentation technicians can be trained to use caution to determine whether testing or writing commands to DCS field equipment might negatively impact or interfere with active plant processes, often instrumentation technicians may not be informed at the time of all processes in the plant that could be negatively affected by modifying plant equipment. In at least some cases, instrumentation engineers may not have the current state knowledge of the processes that a DCS plant operator could have. In these situations, there can be potential hazards when active plant equipment is modified without the knowledge of plant operators. Although this issue is described as existing between AMS and DCS, it can be generalized to plant systems where a separate system outside the DCS can independently modify the parameters of plant equipment within the DCS.
[0036] In some existing systems, a simple warning screen can be presented to the user at the AMS terminal or workstation to alert the user that modifications to parameters may have a negative impact on the system. Figure 5 An exemplary warning screen is shown. In this embodiment, certain key variables known to have a significant impact on active plant equipment can be categorized into a high-priority set, and a warning process can be implemented when attempts are made to modify these parameters. In some systems, this high-priority set can be designated as a set called loop_warning_variables. In some embodiments, loop_warning_variables may include parameters that can significantly change the process control loop current within a module or section of the plant. In a system with a loop_warning_variables set, a warning can be displayed whenever an attempt is made to change a parameter within the loop_warning_variable. Figure 5 The warning screen. In some embodiments, loop_warning_variable can be a set of parameters that can significantly affect the process control loop current (as defined by a threshold).
[0037] Despite having such Figure 5 The warning displayed may alert or remind the user of potential problems modifying a set of high-priority parameters (e.g., loop_warning_variable), but it may not prevent modifications or write commands from being performed on plant equipment where the operator would have more knowledge of the dangerous consequences. Specifically, a simple warning screen may not reduce conflicts with plant operations that AMS instrumentation technicians may not be aware of.
[0038] Figure 6-8 A first system (such as DCS 112) with access to plant devices 124, 128, and 140 and a second system (such as AMS 200) with access to the same plant devices 124, 128, and 140 are illustrated, which can be communicatively coupled to a Security Service Module (SSM) 300. The Security Service Module 300 can provide a change approval process between a user of an AMS workstation 201 attempting to modify plant devices 124, 128, and 140 and a plant control system operator of DCS 112 actively managing the plant devices in real-time plant operations. In these architectures, the Security Service Module (SSM) 300 can intercept write commands or parameter change commands being sent to field devices or other plant devices until the approval process is executed. In some embodiments, only write commands involving the loop_warning_variable may be sent to or intercepted by the Security Service Module for approval. In other embodiments, all write commands may first be sent to the Security Service Module for approval. For convenience, several embodiments and descriptions herein involve intercepting parameter change commands from field devices. However, it should be noted that, unless otherwise stated, the methods, processes, and systems described herein are equally applicable to intercepting parameter change commands for any plant equipment. Plant equipment may include field devices, input / output devices, process controllers, and any other equipment (including field devices, input / output devices, and process controllers) that can be modified independently of the DCS control and communication architecture. The term "process control equipment" may include field devices, input / output devices, and process controllers.
[0039] Figure 6-8 Various methods in which the SSM can be communicatively coupled to the AMS and DCS are shown. Figure 6 It shows Figure 2 The system adds a security service module 300 that communicatively couples between the AMS workstation 201 and the DCS operator workstation 116. Similar to... Figure 2 The architecture, Figure 5 The AMS 200 and DCS 112 have individual and independent access to plant equipment 124, 128, and 140. Figure 5 In such a system, SSM may be able to coordinate between AMS and DCS to intercept parameter change commands issued by AMS for further approval processing.
[0040] Figure 7A It shows Figure 3 The system adds a security service module 300 that communicatively couples between the AMS workstation 201 and the DCS operator workstation 116. Similar to... Figure 3 The architecture, Figure 7A The AMS 200 and DCS 112 share a common network link 160 for communicating with plant devices 124, 128 and 140. Both systems 200 and 112 have the ability to independently access the plant devices, but for the SSM 300, it can now intercept write commands from the AMS workstation 201 and hold or suspend those commands that are waiting for approval from the DCS workstation 116. Figure 7B It shows something similar to Figure 7A The architecture in which the security service module is communicatively coupled to the public network 160, rather than directly coupled between the AMS workstation 201 and the DCS workstation 116. Figure 7A and Figure 7B Both SSM 300 and SSM 300 can perform their function of intercepting parameter change commands and suspending those commands until the approval process is executed.
[0041] Figure 7C It shows Figure 4 The system includes a security service module 300 that is communicatively coupled to the AMS workstation 201 and the DCS operator workstation 116. It is also similar to... Figure 4 In this architecture, each of the AMS 201 workstation and DCS workstation 116 has independent physical communication line access to each of the plant equipment, but can share a public network 160 with each other. In this architecture, the SSM may be able to utilize the same public network 160 between the AMS 200 and DCS 112 to perform its interception functions. In one embodiment, as further described below, the AMS can be programmed to communicate with the SSM to seek approval before generating or sending any parameter change commands. Figure 7C In some embodiments of the architecture, the process control device (e.g., a controller or field device) can be locked to prevent write access, and a token or unlock key from the SSM is required before the process control device can receive parameter change commands.
[0042] Figure 8 A method for adjudicating or approving write commands or parameter change commands for plant equipment in a distributed control system is illustrated. A write command or parameter change command can be a request for parameter changes, a set of instructions for parameter changes, or any modification command that, when received by the plant equipment, may make the parameter changes effective, committed, or otherwise implemented.
[0043] At box 810, the system can intercept write commands for parameter changes to field devices. The security service module can perform the interception. The security service module can be a component of a server or workstation of a second system (such as AMS) different from the DCS. Alternatively, the interception function can be implemented as a program running on a server that manages a shared communication network between the second system and the DCS. At box 812, the system can determine whether the command is for a critical parameter change. If the command is not for a critical parameter change, at box 814, the system can optionally prompt the user to confirm that the parameter change command is correct and whether to allow or pass the command. If the user confirms the command, at box 816, the command can be sent and / or submitted to the plant device. In some embodiments, the DCS system can have a programmed or defined set of critical, high-priority variables (such as the loop_warning_variables set identified by the system as critical or high-priority). In these embodiments, write commands or change commands for parameters or variables outside the loop_warning_variables set can be considered non-critical, and box 812 can be used to distinguish between critical and non-critical parameter sets. If the user refuses the command, the command can be terminated at box 817.
[0044] If it is determined at box 812 that the command is for a critical parameter change, the system can suspend the command for the critical parameter change of the field device at box 818. Suspending the transmission of the command may involve placing the command in a hold state or condition. In some embodiments, suspending the change command may involve placing the command in a temporary hold queue or cache until it has been processed or approved (described further below), and then it is either released (e.g., if approved) or terminated (e.g., if rejected). It should be noted that the decision at box 812 may only apply to embodiments where critical or high-priority parameter changes are intercepted and suspended for an approval process. However, in other embodiments, the system may intercept all parameter changes from the auxiliary system to the field device. In this case, the process bypasses box 812 and proceeds directly from box 810 to box 818.
[0045] At box 820, the system can alert the DCS to intercepted write commands from auxiliary systems (e.g., systems external to the DCS). Box 820 can generate alarm or warning messages and send them to the user interface device of the distributed process control system (DCS), indicating that commands for changes to critical parameters have been intercepted. When the DCS user interface (such as workstation 116 of DCS 112) receives the alarm, the user interface can display the alarm on the existing DCS control display. Figure 9A graphical user interface 900 for a possible controller is shown, which displays a dashboard view of a portion of the process within the plant and has an overlay of the distributed control system. Figure 9 A graphical representation of a portion of a process plant 910 managed by a DCS application is shown, along with one or more field devices 940 located around activities within the plant. This graphical user interface (GUI) 900 can be represented in... Figure 1 The operator monitors aspects of the DCS running on any one or more of the workstations 16. Typically, the operator can use the GUI 900 to monitor plant processes and coordinate and schedule plant equipment (e.g., controllers and field devices) by communicating via input / output I / O devices or interface sets. Figure 9 It can display dashboard views or bird's-eye views of the plant and processes, where the controller can monitor key parameters 956 around and near the plant 910, and has the ability to obtain more detailed information about any specific part or piece of equipment. During normal plant operation, this screen may be accessed from, for example... Figure 10 The alarm message from the SSM 300 shown was interrupted.
[0046] At box 822, the system can display a message on the DCS user interface device. This message can notify the DCS user that an attempt or request to change key parameters of field devices has been placed on hold pending operator approval or operator feedback. Figure 10 The diagram illustrates possible message prompts 1010 that can be displayed on the operator workstation of the DCS. A message prompt may contain at least some of the following fields: the entity or user issuing the command or request 1012, the intended plant equipment for the command or request 1014, the node or module of the plant equipment 1016, the target parameter for modification 1018, the change made or requested to be made to the target parameter (not shown), the application or system attempting to make the change 1020, the security guidelines related to the submission of the change 1022, and a prompt for allowing or denying the command or change request 1024.
[0047] In some embodiments, additional parameter information can be provided to operators by querying an event log database. The event log database may be a database maintained by the DCS that records information about all parameter changes made by the DCS to plant equipment (such as controllers or field devices). An event log may contain records including at least some of the following fields: date, time, user ID, device ID, parameter name, parameter value change, and effect. Typically, the effect field of the event log can provide information about any changes to the process or subprocess corresponding to the plant equipment, as well as the parameter changes to the plant equipment. The effect field may additionally indicate any negative impacts or additional warnings regarding the parameter changes, such as, but not limited to, negative impacts or malfunction events caused by the parameter value change. In some embodiments, additional fields in the event log may be operator notes or comments providing specific details or operator observations regarding parameter value changes. This detail may include warnings about potential missteps or related parameter effects that need to be considered when adjusting parameter values in the future. In some embodiments, the event log may include record fields that provide warnings about parameter changes. For example, a warning may indicate that a parameter value change should not be performed at a specific time because it is related to an ongoing or scheduled event.
[0048] At box 824, the system can send a response from the DCS user interface device to the AMS user interface device, indicating whether changes to key parameters of the controller or field device are permitted, denied, or repudiated. In some embodiments, when an operator clicks on a parameter such as... Figure 10 When the approved or rejected button 1024 in the graphical user interface is displayed, a response can be sent. Once the DCS response is sent, the approval process can return to the AMS, where the AMS workstation can display the response from the DCS operator at box 826. Figure 11 The following is a possible message prompt 1110 that corresponds to the response from the DCS and is displayed on the AMS user interface.
[0049] At box 826, the AMS system can receive and process a response from the DCS. In some embodiments, processing the response at the DCS may include displaying a response or information in response to a critical parameter change command at the AMS's user interface device. In some embodiments, the process may check at box 828 whether the response from the DCS is approved and release the intercepted parameter change command at box 830, or terminate the parameter change command at box 832.
[0050] If the response to the change of key parameters is approval, then Figure 11An embodiment of a graphical user interface (GUI) that can be displayed at the user interface (e.g., a workstation) of the AMS is illustrated. Specifically, the GUI can be displayed to a user (such as an instrumentation technician) showing responses from the DCS operator. The display or GUI may include some of the following fields: identifier of the affected plant equipment 1122, identifier of the affected module 1124, and safety message 1126 related to parameter changes. The GUI may also include Figure 11 Other relevant information not shown includes, such as the parameter identifier and the requested parameter change (e.g., the parameter value), the reason for the decision, and an indication that the change request was approved or rejected. It should be noted that in some embodiments, Figure 11 The GUI can indicate approval by default, since there is no indication that a parameter request is rejected.
[0051] In some embodiments, blocks 826 and 828 may allow a user to perform additional verification or validation of parameter change commands permitted by the DCS. Figure 11 The GUI may also include fields for the AMS operator, including a reason for modification (1128) and a final verification or confirmation check button (1130) prompting the user to verify the write command or reject it. At box 828, if the user selects to allow and apply the changes, the write command can be released from the AMS to the factory device for execution or submission at box 830. If the user selects not to apply the changes, the write command can be terminated at box 832. In some embodiments, after approval, the write command can be routed to the DCS for submission to the field device. In this embodiment, the DCS can send the write command for submission.
[0052] If the response from the DCS operator to a change in a critical parameter is a rejection, the system can display, for example: Figure 12 The response message shown. Figure 12 The GUI 1200 is shown and may include the following fields: indication that a change request has been rejected 1210, identifier of the affected plant equipment 1212, identifier of the control module of the plant equipment 1214, and identifier of the parameter 1216 and / or the requested parameter change (e.g., the value of the parameter).
[0053] The AMS or Security Service Module (SSM) can terminate the critical parameter change command at box 832. This termination can be immediate and automatic upon receiving a rejection response from the DCS, or in some embodiments, it can be delayed until after the user (e.g., via an on-screen prompt) indicates or acknowledges receipt of the response message. In some embodiments, Figure 12The display may include a button for the user to confirm receipt of the message by the AMS user interface. In this embodiment, the command can only be terminated when the user clicks a button indicating that the command will be terminated or not executed. Typically, the described methods and systems can provide DCS operator priorities and permissions to terminate, permanently block, or otherwise invalidate or delete change commands from the system. In embodiments where change commands are placed in a hold state or waiting queue, the change commands can be marked, identified, or labeled at box 832 to facilitate deletion.
[0054] In some embodiments, a parameter change command may include multiple parameter changes. In some cases, multiple parameters may include changes to critical parameters (such as those in the `loop_warning_variables` set) and non-critical parameters. In some embodiments, non-critical parameters may be low-priority parameters that may have a low impact on processes controlled by plant equipment. In this embodiment, the described system may allow changes to non-critical parameters even if changes to critical `loop_warning_variables` are denied or rejected. In some embodiments, the write command is placed in a hold state, such that all parameters in the command are suspended until a decision is made regarding critical parameters. Figure 12 The GUI can indicate situations with changes to multiple parameters, including non-critical parameters. In this case, the GUI for the response message can include fields for the AMS operator to include the reason for the modification of the non-critical parameters 1228 and a final verification or confirmation check 1230. Figure 12 The GUI is shown, displaying a rejection of changes to (multiple) critical parameters, with prompt 1230 indicating that the user should decide whether to proceed with parameter change commands targeting non-critical parameters in the change command parameter set without requiring changes to critical parameters. As mentioned above, in some embodiments, even changes to non-critical parameters (such as parameters outside the loop_warning_variables set) may require approval from the DCS operator. Figure 12 The response GUI may include other information not shown, such as the reason for rejection from the DCS operator.
[0055] In some embodiments, critical parameter changes can be canceled or otherwise blocked from transmission when the set of non-critical parameters in a change command is allowed to pass or be released. In some embodiments, the AMS server can simply modify the set of change command parameters to implement parameter changes only that have not been rejected by the operator. For example, in embodiments where the change command includes instructions for the set of parameter changes, the AMS server can simply place the command in a queue at block 818, as in Figure 8In boxes 820-826, the parameter change set of the command is checked by sending a message to the DCS, and then either the command is released after approval at box 820, or the parameter set is modified to eliminate or remove critical parameters in the parameter change set when the DCS rejects those requested changes at box 832.
[0056] In cases where the DCS includes logs (such as an event log database) that capture changes made to plant equipment (such as field devices) and the resulting operational changes and the results observed by the plant operator, the AMS or other secondary system may have corresponding logs, such as audit trail logs or databases, that record test, inspection, and calibration changes made to the field devices by the AMS or AMS users. In one embodiment, a security service module may be programmed to retrieve relevant audit trail entries related to intercepted commands used for parameter changes. For example, the security service module may query the AMS's audit trail for information based on a request to modify a parameter by a change command. Audit trail log or database entries may include the date and time of the plant equipment modification made by an auxiliary system such as the AMS, the type of modification, and the reason for the modification. The security service module may include this audit trail log information when it forwards an alert message to the DCS operator. The DCS operator may find the audit trail information useful for making a more informed decision about whether to approve or reject a change command or change request. A situation may arise where a DCS operator typically blocks or rejects change requests based solely on information from the DCS side, but subsequently realizes that changes to plant equipment parameters based on audit trail information supersede the operator's initial operational considerations. This could occur, for example, when an audit trail reveals potential defects or severe degradation in plant equipment.
[0057] generally, Figure 8 The processes and functions described herein can be distributed between the AMS and DCS via any computing components (such as workstations or servers for each system). A separate computing device can be used to implement the SSM, which can perform... Figure 8 At least some of the function boxes or procedure boxes. In some embodiments, Figure 8 The process block can be divided among AMS, DCS, and SSM. In some embodiments, the SSM may have elements implemented by both AMS workstations and DCS workstations to perform the process. Figure 8 The process.
[0058] Figure 13A specific embodiment in which the AMS is implemented as a Field Device Integration (FDI) server component is shown. A Field Device Integration system is an industry-standard approach for accessing and communicating with process control devices using Electronic Device Description (EDD) files. Specifically, the Security Service Module 1308 can be programmed as a component of the FDI server 1312. A user at a workstation such as workstation 201, coupled to a public network such as network 160, can use the EDD field device interface or FDI client 1316 to send parameter change requests to field devices. The SSM 1308 at the FDI server 1312 can be programmed to intercept some or all of such parameter change commands or requests from any of the multiple FDI clients 1316 that are part of the AMS system. Figure 13 As shown, the FDI EDD server 1312 can communicate directly with field devices 1320, such as IP104A field devices (e.g., valve positioners), via the FDI communication server interface 1330, independently of DCS control functions that communicate via controller 1340, I / O devices (such as Characterization Module (CHARM) Input / Output Card (CIOC) 1342 (part of the Emerson Delta V process control implementation)), and analog output (AO) HART communication 4-20mA CHARM 1 interface 1344 from DCS workstation 1350. The SSM 1308 component of the FDI server 1312 can handle parameter change commands similar to the embodiments described above. Specifically, the FDI-EDD server can send a request message to DCS 1350 for approval of the parameter change command. Based on the response of DCS 1350, SSM 1308 can release the parameter change command for submission at field device 1320, or terminate the parameter change command. It should be noted that all the embodiments described above are applicable to... Figure 13 The implementation method.
[0059] Figure 14An embodiment of the approval system is illustrated, in which an instrumentation technician 1401 can use a mobile computing device 1410, which has wireless access to a DCS 1450 and access to field devices 1420 via a HART communication interface 1412. In some embodiments, the mobile device 1410 can be physically and directly coupled to the field devices 1420 in the process plant via the communication interface 1412. The DCS workstation 1450 can monitor and control the field devices 1420 using appropriate controllers 1440, I / O 1442, and interfaces 1444. In this embodiment, an SSM 1408 can be programmed as a component of the mobile device 1410. The SSM 1408 can use the wireless communication link to the DCS 1450 and can implement the same or similar process as the approval parameter change command as described above.
[0060] The following additional considerations apply to the foregoing discussion. Throughout this specification, actions described as being performed by any device or routine generally refer to actions or processes by which a processor manipulates or transforms data according to machine-readable instructions. Machine-readable instructions may be stored in and retrieved from a storage device communicatively coupled to the processor. That is, the methods described herein may be embodied by a set of machine-executable instructions stored on a computer-readable medium (i.e., a memory device). When executed by one or more processors of the corresponding device (e.g., a server, a user interface device, etc.), the instructions cause the processor to perform the method. Where instructions, routines, modules, procedures, services, programs, and / or applications are referred to herein as stored or stored in computer-readable storage or on a computer-readable medium, the terms “stored” and “stored” are intended to exclude transient signals.
[0061] Furthermore, while the terms “operator,” “person,” “human,” “user,” “technician,” and other terms may be used to describe persons in a process plant environment who may use or interact with the systems, apparatus, and methods described herein, these terms are not intended to be restrictive. Where a particular term is used in the specification, its use is partly due to conventional activities performed by plant personnel, but is not intended to restrict persons who may perform that particular activity.
[0062] Furthermore, throughout this specification, multiple instances can implement components, operations, or structures described as single instances. Although a single operation of one or more methods is shown and described as a separate operation, one or more of the single operations can be performed simultaneously, and the operations do not need to be performed in the order shown. Structures and functions presented as separate components in the exemplary configuration can be implemented as combined structures or components. Similarly, structures and functions presented as single components can be implemented as separate components. These and other variations, modifications, additions, and improvements fall within the scope of this document's subject matter.
[0063] Unless otherwise expressly stated, the discussion herein uses terms such as “processing,” “operation,” “computation,” “determining,” “identifying,” “presenting,” “causing to be presented,” “causing to be displayed,” and “displaying” to refer to the actions or processes of a machine (e.g., a computer) that manipulate (or convert) data represented as physical (e.g., electronic, magnetic, biological, or optical) quantities within one or more memories (e.g., volatile memory, non-volatile memory, or a combination thereof), registers, or other machine parts that receive, store, transmit, or display information.
[0064] When implemented in software, any of the applications, services, and engines described herein can be stored in any tangible, non-transitory computer-readable storage medium, such as on a disk, on a laser disk, on a solid-state storage device, on a molecular memory storage device, or on other storage media, in the RAM or ROM of a computer or processor, etc. Although the exemplary systems disclosed herein are disclosed to include software and / or firmware and other components executed on hardware, it should be noted that such systems are illustrative only and should not be considered limiting. For example, it is contemplated that any or all of these hardware, software, and firmware components may be embodied solely in hardware, solely in software, or in any combination of hardware and software. Therefore, it will be readily understood by those skilled in the art that the examples provided are not the only way to implement such a system.
[0065] Therefore, although the invention has been described with reference to specific examples which are intended to be illustrative and not limiting, it will be apparent to those skilled in the art that changes, additions or deletions may be made to the disclosed embodiments without departing from the spirit and scope of the invention.
[0066] It should also be understood that, unless the phrase “as used herein, the term ‘______’ is defined herein as…” or a similar phrase is used in this patent, it is not intended to limit the meaning of the term, whether express or implied, beyond its ordinary or general meaning, and such term should not be construed as limited in scope based on any statement made in any part of this patent (other than the language of the claims). To some extent, any term recited in a claim at the end of this patent is referred to in this patent in a manner consistent with a single meaning, done only for clarity and to avoid confusing the reader, and is not intended to limit such claim terminology to that single meaning by implication or otherwise. Finally, unless a claim element is defined by reference to the word “device” and without exemplifying the function of any structure, it is not intended to interpret the scope of any claim element based on the application of 35 USC §112(f) and / or paragraph 6 of pre-AIA 35 USC §112.
[0067] Furthermore, although the foregoing text provides detailed descriptions of many different embodiments, it should be understood that the scope of this patent is defined by the text of the claims set forth at the end of this patent. The detailed descriptions are to be construed as exemplary only and do not describe every possible embodiment, as it would be impractical to describe every possible embodiment, even if not impossible. Many alternative embodiments may be implemented using current technology or technology developed after the date of this patent application, which will still fall within the scope of the claims.
Claims
1. A method for verifying changes to key parameters of devices in a distributed process control system (DCS), the DCS comprising at least one controller and one field device, and having an asset management system (AMS) that is different from and communicatively coupled to at least one of the controller or the field device, independent of the DCS, the method comprising: Intercept parameter change commands originating from the asset management system (AMS) for process control equipment, wherein the parameter change commands include instructions for modifying at least a set of key parameters of the process control equipment; A warning message is sent to the workstation of the distributed process control system (DCS) indicating that a parameter change command for the process control equipment has been intercepted. The warning message contains a set of warning parameters, which includes at least a user identifier, a plant equipment identifier, and a set of key parameters of the process control equipment that will be modified by the parameter change command. The warning message is displayed at the workstation of the DCS; The workstation in the AMS receives a response from the workstation in the DCS, the response indicating whether the parameter change command is permitted to modify the set of key parameters of the process control equipment; The response from the DCS is displayed at the user interface device of the AMS; and If the response to modifying the set of key parameters of the process control device is a rejection response, then the instruction for modifying the set of key parameters in the parameter change command is terminated.
2. The method according to claim 1, wherein, Intercepting parameter change commands for process control equipment includes pausing the transmission of the parameter change command before the command is received by the process control equipment.
3. The method according to claim 1, further comprising: In response to the warning message, additional parameter information from the DCS is provided, and wherein displaying a response to the parameter change command at the AMS includes displaying the additional parameter information.
4. The method according to claim 3, wherein, The additional parameter information includes information about previous changes to the set of key parameters of the process control device and information about the previous effects of the previous changes on the process controlled by the process control device.
5. The method of claim 4, further comprising, once the response and the additional parameter information are displayed, prompting the user at the AMS workstation to verify the parameter change command; and When verifying the parameter change command at the user interface of the AMS, the set of key parameters is submitted to the process control device.
6. The method according to claim 3, further comprising: Additional information about the set of key parameters is sent from the AMS to the DCS for display at the DCS workstation. The additional information includes a description of a previous change initiated by the workstation of the AMS to one or more parameters that will be modified by the parameter change command, and the reason for the current change to the one or more parameters by the parameter change command.
7. The method according to claim 1, wherein, The parameter change command is used to modify multiple parameters, including the set of key parameters of the process control device and a set of non-key parameters other than the set of key parameters.
8. The method according to claim 7, wherein, If the response to modify the set of critical parameters of the process control device is a rejection response, then the modification of the set of critical parameters is terminated, while modifications to the set of non-critical parameters to be submitted to the process control device are permitted.
9. The method according to claim 1, wherein, The user interface device of the AMS is generated based on an EDD processed by an Electronic Device Description (EDD) server.
10. The method according to claim 9, wherein, The EDD server executes the action of sending warning messages to the workstations of the Distributed Process Control System (DCS).
11. A system for verifying changes to critical parameters of devices in a distributed process control system (DCS), the DCS including at least one controller and one field device, and having an asset management system (AMS) different from the DCS and communicatively coupled to at least one of the controller or the field device, the system comprising: The DCS workstation is adapted to communicate with at least one controller of the DCS and one field device; The AMS workstation is adapted to communicate independently of the DCS with at least one controller of the DCS and the field device. A security service module, communicatively coupled to the workstations of the Asset Management System (AMS) and the Distributed Process Control System (DCS), is adapted to: Intercepting parameter change commands for process control equipment originating from the workstation of the asset management system (AMS), wherein the parameter change commands include instructions for modifying at least a set of key parameters of the process control equipment; Send a warning message to the workstation of the DCS, the warning message indicating that a parameter change command for the process control equipment has been intercepted, wherein the warning message contains a set of warning parameters, the set of warning parameters including at least a user identifier, a plant equipment identifier, and a set of key parameters of the process control equipment that will be modified by the parameter change command; Receive a response from the workstation of the DCS, the response indicating whether the parameter change command is permitted to modify the set of key parameters of the process control device; If the response used to modify the set of key parameters is permitted, then the intercepted parameter change command is released; and Otherwise, terminate the instructions used to modify the set of key parameters.
12. The system according to claim 11, wherein, The security service module includes components executed on the AMS workstation and components executed on the DCS workstation, wherein the components executed on the AMS workstation are adapted to intercept the parameter change command at the AMS workstation, and wherein the components executed on the DCS workstation are adapted to receive an alarm from the components executed on the AMS workstation, the alarm indicating that the parameter change command has been intercepted.
13. The system according to claim 11, wherein, If the response for modifying the set of critical parameters is permitted, releasing the intercepted parameter change command includes sending a request to the DCS to submit a modification to the set of critical parameters of the process control equipment.
14. The system according to claim 11, wherein, The DCS workstation is adapted to display the warning message and prompt the DCS workstation user to approve the parameter change command.
15. The system according to claim 14, wherein, The AMS workstation is adapted to display the response from the DCS workstation, the response indicating whether the parameter change command is permitted to modify the set of key parameters of the process control device.
16. The system according to claim 11, wherein, The parameter change command is used for multiple parameters, including the set of critical parameters and a set of non-critical parameters outside the set of critical parameters, and wherein, although the response is from the DCS workstation, the security service module is still adapted to allow instructions for changing the non-critical parameters of the process control equipment.
17. The system of claim 11, further comprising a safety module of the distributed process control system (DCS), which is adapted to: The warning message is received, indicating that the parameter change command was intercepted; A prompt is displayed at the workstation in the DCS to verify the intercepted parameter change command; and The response is sent to the security service module, wherein, The response indicates whether the parameter change command was validated.
18. The system according to claim 17, wherein, The security module of the DCS is also adapted to query the event log database of the DCS for the history of modifications to at least one key parameter in the set of key parameters in the parameter change command, and to display at least a portion of the history of modifications to the user interface of the DCS.
19. The system according to claim 11, wherein, The security service module is adapted to query the audit trail database of the AMS for the history of previous modifications to the set of key parameters in the parameter change command, wherein the history of previous modifications includes the reasons for one or more previous parameter modifications.
20. The system of claim 11, further comprising: A Field Device Integration (FDI) Electronic Device Description (EDD) server, which executes on the workstation of the Asset Management System (AMS), is adapted to receive requests for parameter changes to process control devices from a user interface, and wherein the security service module is implemented using logic executed by the FDI EDD server.
21. A system for verifying changes to critical parameters of devices in a distributed process control system (DCS), the DCS including at least one controller and one field device, and having a second system different from the DCS and communicatively coupled to the at least one controller or the field device, the system comprising: The DCS workstation is adapted to communicate with at least one controller of the DCS and one field device, and is adapted to: Receive an alarm from the second system, the alarm indicating a parameter change command initiated by the second system for the process control equipment of the DCS; Query the event log database of the DCS for entries related to the set of parameters to be modified by the parameter change command; Display the alarm from the second system and the event log entries related to the set of parameters to be modified by the parameter change command; as well as Send a response to the alarm to the second system, the response indicating whether the parameter change command was approved; and The workstation of the second system is suitable for: It communicates independently of the DCS and with at least one process control device of the DCS; Intercepting parameter change commands from the second system, wherein the parameter change commands include instructions for at least changing a set of key parameters of the at least one process control device of the DCS; Send an alert to the workstation of the DCS, the alert including an indication that the parameter change command was intercepted; and Based on the response from the DCS workstation, the intercepted parameter change command intended for execution at the process control device is released.
22. The system according to claim 21, wherein, The workstation of the second system is also adapted to: Obtain an audit trail log corresponding to the set of key parameters of the parameter change command, the audit trail log including at least the parameter identifier, the previous parameter modification and the reason for the modification, and wherein sending the alarm to the workstation of the DCS includes sending the obtained audit trail log.
23. The system according to claim 21, wherein, The event log entry includes an identifier for the set of key parameters, previous changes to the set of key parameters, and the impact of the previous changes on the plant process.
24. A system for verifying changes to critical parameters of devices in a distributed process control system (DCS), the DCS including at least one controller and one field device, and having a second system different from the DCS and communicatively coupled to the DCS via a common communication network, the system comprising: A security service module, communicatively coupled to the second system and the DCS via the public communication network, and adapted to: Intercept parameter change commands for process control devices originating from outside the DCS, wherein the parameter change commands include instructions for changing at least a set of key parameters of the process control devices; Send a warning message to the workstation of the DCS, wherein the warning message indicates that a parameter change command for the process control equipment of the DCS has been intercepted; Receive a response from the workstation of the DCS, the response indicating whether changes to the key parameters of the process control equipment are permitted; and If the response to the change of the critical parameter is permitted, the intercepted parameter change command is released.
Citation Information
Patent Citations
Method and system for controlling mobile terminal near field payment channel to be opened and closed by means of short messages
CN103761645A
Software lockout coordination between a process control system and an asset management system
GB201208679D0