Event-related loading limits for servers of control systems of technical installations
By allowing the operator station server to refuse automated configuration loading under interruption conditions, synchronization issues are resolved, overload is prevented, the operational and monitoring availability of technical facilities is improved, and the continuity of critical tasks is ensured.
Patent Information
- Application Number
- CN202210079226.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2021-01-26
- Filing Date
- 2022-01-24
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2042-01-24
AI Technical Summary
In the control system of technical facilities, when operators and project engineers are not synchronized, automation data may fail to be loaded into the operator station server in a coordinated manner, leading to erroneous operations or facility damage. Furthermore, the operator station server may be overloaded, affecting the operation and monitoring availability of the facility.
When an interruption condition is detected, the operator station server refuses to receive or process automated configurations, sets load limits for a specific duration, creates and transmits automated configurations using computer design tools, and generates alarm messages when necessary to avoid overload.
It improves the operational and monitoring availability of technical facilities, prevents overload, ensures uninterrupted facility operation during critical missions, and enhances system stability and reliability.
Smart Images

Figure CN114791725B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a control system for a technical facility, particularly a process or manufacturing facility, the control system having an operator station server and an engineer station server, wherein the engineer station server includes computer-implemented design tools capable of creating automated configurations for automating the technical facility, and wherein the engineer station server is configured to transmit automated configurations for operating and monitoring the technical facility to the operator station server. The invention also relates to a method for operating a technical facility with a control system. Background Technology
[0002] The control system of a technical facility comprises numerous components that must be planned, loaded, and updated throughout the facility's lifespan. When plans change, components of the control system (automation devices, operator station servers, etc.) are loaded, for example, from an engineer station server to an operator station server. Such a control system is disclosed, for example, in EP 3 623 891 A1.
[0003] In this context, a control system is understood as a computer-aided technical system that includes functions for displaying, operating, and controlling technical systems such as manufacturing or production facilities. In addition to operator station servers and operator station clients, a control system may also include, for example, so-called process or manufacturing-related components used to drive actuators or sensors.
[0004] Technical facilities can be facilities in process industries (i.e., chemical, pharmaceutical, petrochemical), or facilities in food and confectionery industries. Therefore, it also includes any facility in manufacturing industries (e.g., factories producing automobiles or various types of goods). Technical facilities suitable for carrying out the methods according to the invention can also originate from the energy production sector. Wind turbines, solar energy facilities, or power plants used for generating electricity are also included in the term "technical facility."
[0005] If operators and project engineers of a control system or technical facility are not "synchronized" because they are unable to contact each other, for example, due to being in different locations or for other reasons, the following can happen: operators lose control of the operation and monitoring of the technical facility during erroneous operations or critical optimization processes due to uncoordinated loading of automation data onto the operator station server, and the facility may thus be damaged. Furthermore, it is possible that the operator station server itself is in a situation where loading would cause problems (e.g., when the operator station server is about to be overloaded or exceed its processing capacity).
[0006] Currently, an "operator station server" is understood as a server that centrally detects data from the operation and monitoring systems of a technical facility, as well as alarm and measurement value archives from the facility's control systems, and provides this information to users. Operator station servers typically establish communication connections to the facility's automation systems (e.g., automated equipment) and forward the facility's data to so-called "operator station clients," which are used to operate and monitor the various functional components of the facility.
[0007] The operator station server itself can have client functionality to access data (files, messages, tags, variables) from other operator station servers. Thus, the image of the technical facility running on this operator station server can be combined with variables from other operator station servers (server-to-server combination). The operator station server can be a Siemens SIMATIC PCS 7 industrial workstation server, but is not limited to this. Summary of the Invention
[0008] The purpose of this invention is to provide a control system for technical facilities, which enables the operation and monitoring of technical facilities with high availability.
[0009] The objective is achieved by a control system for a technical facility (particularly a process or manufacturing facility) having the features of the invention. Furthermore, the objective is achieved by a method according to the invention for operating a technical facility (particularly a process or manufacturing facility) having a control system. Advantageous improvements are derived from the various embodiments.
[0010] According to the present invention, the control system of the type described at the beginning is characterized in that the operator station server is configured to refuse to receive or process automated configurations for operating and monitoring technical facilities for a specific duration in the event of an interruption.
[0011] Computer-based design tools can be used to create automated configurations for operating and monitoring technical facilities on an operator station server. These automated configurations can include, for example, facility images, which the operator station server can transmit to individual operator station clients for visual display by the facility's operators. Here, facility images are typically operational images used to control the system; these images include graphical representations of the various components of the technical facility and display the status of each component, the relationships between components (e.g., methodological relationships), etc.
[0012] Here, the facility image can include alarm message notifications. For example, alarm message notifications can provide an overview of alarm messages generated in the control system in a tabular list. Alarm message notifications are also known as message sequence notifications.
[0013] According to the present invention, the operator station server is configured to: interrupt the reception of new or updated automation configurations from the engineer station server, or interrupt the processing of automation configurations, for a specific duration in the event of an interruption. This prevents overload and / or interruption of the operation and monitoring of the technical facility from affecting the operator station server. Consequently, the availability of operation and monitoring of the technical facility can be advantageously improved.
[0014] The operator station server is preferably configured to: inform the engineer station server to refuse to receive or process automated configurations. For example, the operator station server can report to the engineer station server that the operator station cannot receive or process automated configurations for a specific duration of 10 minutes. The operator station server can also report that the size of the automated configuration must not exceed a specific value, etc.
[0015] The operator station server is particularly preferably configured to inform the operator of the technical facility that it refuses to receive or process automation configurations. Here, the operator station server may also be able to report to the operator, for example, that the operator station server is unable to receive and process automation configurations for a specific duration of 10 minutes.
[0016] Within the scope of a favorable improvement to the control system, an operator station server is configured to generate alarm messages that include information regarding the refusal to receive or process automation configurations via the operator station server. The alarm messages are presented in the control system's alarm message announcements (through message sequences) to all stakeholders involved in the disruption (project engineers, operators, etc.). The alarm messages are preferably presented visually to the operators of the technical facility via operator station clients, who use these alarm messages to operate and monitor the technical facility.
[0017] The operator station server is preferably configured to automatically (i.e., without operator or other personnel intervention) determine the existence of interruption conditions. This is preferably achieved by identifying potential overloads of the operator station server due to receiving or processing automated configurations from the engineer station server. Here, the operator station server is able to compare its current load or its current idle resources with the anticipated additional load from receiving (or processing) new or updated automated configurations in order to create a prediction of potential overloads.
[0018] Here, the operator station server is particularly preferably configured to automatically determine the end of a specific duration. This is preferably achieved by eliminating potential overloads of the operator station server due to receiving automated configurations from the engineer station server or by processing automated configurations.
[0019] In an advantageous improvement of the invention, the operator station server is configured to allow operators of the technical facility to report interruption conditions while operating and monitoring the facility. For example, if an operator is performing optimization, error handling, or an operation that should not be interrupted until completion, the operator can manually determine processing or loading limits (temporarily rejecting access) on the operator station server. The operator can then remove the limits after finishing their work.
[0020] Within the scope of a favorable improvement scheme, since operator station clients, which operators can use to operate and monitor technical facilities, can log in at different operator station servers, it is possible to deduce from the operator station servers which (additional) operator server stations must be restricted. For example, if an operator logs in at a first operator station server using an operator station client and changes the parameters of a regulator located in a process image on a second operator station server, then both the first and second operator station servers must be included in the restrictions.
[0021] The operator station server is preferably configured to: allow operators of the technical facility to report the end of a specific duration while operating and monitoring the technical facility.
[0022] The aforementioned objective is also achieved by a method for operating a technical facility (particularly a process or manufacturing facility) with a control system having an operator station server and an engineer station server, wherein the engineer station server includes computer-implemented design tools that enable the creation of automated configurations for the automation of the technical facility, and wherein the engineer station server is configured to: transmit automated configurations for operating and monitoring the technical facility to the operator station server, wherein the operator station server, in the event of an interruption, refuses to receive or process the automated configurations for operating and monitoring the technical facility for a specific duration. Attached Figure Description
[0023] The above-described features, characteristics, and advantages of the present invention, as well as the ways and methods of implementing them, will be explained more clearly from the following description of embodiments in conjunction with the accompanying drawings. It shows that:
[0024] Figure 1 A schematic diagram of the control system according to the present invention is shown;
[0025] Figure 2 A diagram of the facilities for operation and monitoring, according to the first aspect, is shown; and
[0026] Figure 3 Showing according to the second aspect Figure 2 A diagram of the facilities. Detailed Implementation
[0027] Figure 1 This diagram illustrates a portion of a control system 1 according to the invention, which is a technical facility constructed as a process facility, i.e., a facility constructed as a method technology. The control system 1 includes a first operator station server 2 and an engineer station server 3. Furthermore, the control system 1 includes a second operator station server 4, an operator station client 5, and an engineer station client 6.
[0028] The first operator station server 2, the engineer station server 3, the second operator station server 4, the operator station client 5, and the engineer station client 6 are interconnected via a terminal bus 7 and optionally connected to other components of the control system (not shown), such as process data files.
[0029] For operation and monitoring purposes, users or operators can access the first operator station server 2 or the second operator station server 4 via operator station client 5 through terminal bus 7. Project engineers can access engineering station server 3 via engineering station client 6 through terminal bus 7 during the engineering or planning process of automating the process facility. Terminal bus 7 can be configured as, for example, industrial Ethernet, but is not limited to this.
[0030] The first operator station server 2 has a device interface 8 connected to the facility bus 9. Through the device interface 8, the first operator station server 2 can communicate with the automation equipment 10 and other optional components of the process facility. The facility bus 9 can be configured as, for example, an industrial Ethernet, but is not limited thereto. The automation equipment 10 can connect to any number of subsystems (not shown). The engineer station server 3 also has a device interface 11 connected to the facility bus 9 and the components connected thereto, namely the automation equipment 10.
[0031] Data management service 12, visualization service 13, and process image 14 are implemented on the first operator station server 2. Additionally, load limiting service 15 and distribution service 16 are implemented on the first operator station server 2. Design tools 17 and compilation service 18 are implemented on the engineer station server 3.
[0032] The following describes the flow of the method according to the present invention: Project engineers use design tools implemented on a computer on an engineering station server 3 to create an automation configuration 19 for automating process facilities. Here, the automation configuration 19 is primarily used to: automatically perform measurements using each process component; and to control and regulate each process component. Communication between the process components can also be determined through the automation configuration. The automation configuration 19 is formatted by the compilation service 18 of the engineering station server 3, and this format can be processed by the first operator station server 2 or the automation device 10.
[0033] Then, the automation configuration 19 is transferred from the engineer station server 3 to the first operator station server 2. Furthermore, the transfer of the automation device 10 will not be discussed further. Here, the loading management service 12 checks whether the automation configuration 19 should be received by the first operator station server 2, or whether it should be rejected for a specific duration. Alternatively, the loading management service 12 can also initially allow the automation configuration 19 to be transferred to the first operator station server 2, but block the processing of the automation configuration 19 for a specific duration. Thus, although the automation configuration 19 is physically located on the operator station server 2, it is not used and therefore has no effect.
[0034] According to the instructions of the load restriction service 15, the load management service 12 executes to prevent the reception or processing of the automated configuration 19. This is triggered by the load management service 12 when an interruption condition exists. The existence of the interruption condition can be automatically determined by the first operator station server 2 itself. To this end, the first operator station server can, for example, check whether the reception and / or processing of the automated configuration will cause a potential overload for the first operator station server 2.
[0035] However, interruption conditions can also be preset by the operator. To this end, the operator can submit a corresponding request to the load restriction service 15 of the first operator station server 2 via the operator station client 5. For example, the operator can preset that the first operator station server 2 should not process any (new / updated) automation configurations 19 within a 30-minute period, so as not to interrupt the operator, for example, when performing critical tasks.
[0036] The end of the duration can not only be preset by the operator. More precisely, the first operator station server 2 can determine the end of the duration itself, i.e., automatically, by creating or being able to create a prediction of the loading of its resources, and taking that prediction into account when the duration is determined to end. The load limiting service 15 can also access diagnostic messages from the computing unit (CPU) of the operator station server 2, which are stored in the process image 14. An interruption condition can also be that there are a large number of process alarms (i.e., active) in the process image 14, making it currently meaningless to process or receive automated configuration.
[0037] If the load management service 12 is required to interrupt the receiving or processing process for a specific duration, the load restriction service 15 generates an alarm message in parallel. This alarm message is stored in the process image 14 of the first operator station server 2. Project engineers and operators can access the alarm message (in the form of message sequence notifications on operator station clients 5).
[0038] exist Figure 2Facility image 20 is shown and displayed to the operator via operator station client 5. In the lower right area of facility image 20, an open lock symbol 21 indicates to the operator that there are currently no restrictions on receiving or processing new or updated automation configurations 19. Figure 3 For the opposite situation (i.e., when a restriction occurs), a closed lock symbol 22 is shown.
[0039] Because operator station client 5 can log in to different operator station servers 2 and 4 and still access all process objects for operation and monitoring via distribution, a restriction location service 23 is also implemented on the first operator station server 2. The restriction location service determines which operator station servers 2 and 4 are associated with receiving / processing restrictions. For example, if an operator logs in to the first operator station server 2 via operator station client 5 and changes the regulator's parameters, then both the first operator station server 2 and the second operator station server 4 must be included in the restriction, where the regulator is located in the process image (not shown) of the second operator station server 4. The restriction location service 23 transmits the information to the load restriction service 15. The load restriction service now prompts the data management service 12 of the first operator station server 2 and the data management service of the second operator station server 4 (not shown) to execute the requested restriction until the restriction is lifted, thereby enabling, for example, the operator to complete the critical task.
[0040] Overall, the present invention can contribute to greater availability of technical facilities, especially in the case of using a network-based control system (1).
Claims
1. A control system (1) for a technical installation, the control system having an operator station server and an engineer station server (3), wherein The engineer station server (3) comprises a computer-implemented design tool (17) with which an automation configuration (19) for the automation of the technical facility can be created, and wherein the engineer station server (3) is configured to transmit the automation configuration (19) for operating and monitoring the technical facility to the operator station server, characterized in that the operator station server is configured to reject receiving or processing the automation configuration (19) for operating and monitoring the technical facility for a specific duration in the event of an interruption condition, wherein the operator station server is further configured to automatically derive the presence of the interruption condition by recognizing a possible overload of the operator station server as a result of receiving the automation configuration (19) from the engineer station server (3) or as a result of processing the automation configuration (19) by the operator station server.
2. The control system (1) according to claim 1, wherein The technical facility is a process or manufacturing facility.
3. The control system (1) according to claim 1 or 2, wherein The operator station server is configured to inform the engineer station server (3) of the rejection of receiving or processing the automation configuration (19).
4. The control system (1) according to claim 1 or 2, wherein The operator station server is configured to inform an operator of the technical facility of the rejection of receiving or processing the automation configuration (19).
5. The control system (1) according to claim 1 or 2, wherein The operator station server is configured to generate an alarm message comprising information about the rejection of receiving or processing the automation configuration (19) by the operator station server.
6. The control system (1) according to claim 5, wherein The operator station server is configured to present the alarm message in a message sequence display for an operator of the technical facility and to present the alarm message by means of an operator station client (5) configured for the presentation.
7. The control system (1) according to claim 1 or 2, wherein The operator station server is configured to automatically derive the end of the specific duration by recognizing the elimination of a possible overload of the operator station server as a result of receiving the automation configuration (19) from the engineer station server (3) or as a result of processing the automation configuration (19).
8. The control system (1) according to claim 1 or 2, wherein The operator station server is configured to learn of the presence of the interruption condition from an operator of the technical facility when operating and monitoring the technical facility.
9. The control system (1) according to claim 8, wherein The operator station server is configured to report the end of the specific duration by an operator of the technical facility when operating and monitoring the technical facility.
10. A method for operating a technical facility having a control system (1) with an operator station server and an engineer station server (3), wherein The engineer station server (3) comprises a computer-implemented design tool (17) with which an automation configuration (19) for the automation of the technical facility can be created, and wherein the engineer station server (3) is configured to transmit the automation configuration (19) for operating and monitoring the technical facility to the operator station server, wherein the operator station server rejects receiving or processing the automation configuration (19) for operating and monitoring the technical installation for a certain duration in case of a presence of an interruption condition, wherein the presence of the interruption condition is automatically derived by the operator station server by recognizing a possible overload of the operator station server due to receiving the automation configuration (19) from the engineer station server (3) or due to processing the automation configuration (19) by the operator station server.
11. The method of claim 10, wherein, The technical installation is a process or manufacturing installation.
Citation Information
Patent Citations
Individualised image hierarchies for a control system of a technical installation
EP3623891A1
Systems and methods for remotely modifying software on a work machine
US20050262498A1