A data processing method and a safety instrumented system
By evaluating and matching safety instrumented system (SAS) design schemes through servers, the problem of customizing SAS for different factories and enterprises has been solved, enabling risk identification and accident prevention, and ensuring system safety and integrity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA ACAD OF SAFETY SCI & TECH
- Filing Date
- 2023-01-31
- Publication Date
- 2026-05-05
AI Technical Summary
Different factories and enterprises face different risks, and how to set up corresponding safety instrumented systems according to their specific needs is an urgent problem to be solved.
A data processing method is provided, which receives a safety instrumented system (SAS) design request through a server, evaluates the request, matches the design scheme with a preset SAS library, ensures that the scheme meets the enterprise's risk level standards and information security requirements, and sends the scheme to the user equipment for implementation.
It enables the design of safety instrumented systems according to the needs of different enterprises, identifies potential risks, avoids major accidents, reduces personnel losses, and ensures that the system meets safety requirements during operation.
Smart Images

Figure CN116227925B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of safety instrumented systems, and in particular to a data processing method and a safety instrumented system. Background Technology
[0002] With the advancement and implementation of the "Industrial Internet + Safe Production" action plan and the widespread application of technologies such as the Internet of Things, Internet+, and cloud services in the safety production management of industrial and commercial sectors, the Safety Instrumentation System (SIS) has become an important protective layer for industrial safety. The SIS mainly consists of the alarm and interlocking parts of the factory control system. It implements alarm actions, adjustments, or shutdown controls based on the detection results in the control system and is an important component of the automatic control of factories and enterprises.
[0003] In actual factories and enterprises, various industrial control system equipment is used. To ensure the safety of this equipment, safety instrumented systems (SAS) must be installed within the factory control system. SAS can identify potential risks and output corresponding alarm actions based on different risks, facilitating timely risk detection and mitigation, and reducing significant personnel losses. However, different factories and enterprises face different risks; therefore, determining how to set up appropriate SAS for different factories and enterprises is a pressing issue that needs to be addressed. Summary of the Invention
[0004] To address the shortcomings of related technologies, this application provides a data processing method and a safety instrumented system. This method can set up a safety instrumented system corresponding to the needs of different factories and enterprises, making it easier to identify potential risks.
[0005] The first aspect of this application provides a data processing method applied to a server, which receives a safety instrumented system (SAS) design request sent by a user equipment. The SAS design request includes any one or more of regulations, standards, laws, industry standards, and policies. The method evaluates the SAS design request to obtain a first evaluation result. Based on the first evaluation result, the method matches a corresponding SAS design scheme in a preset SAS library. The method then sends the SAS design scheme to the user equipment so that the user can implement the SAS design scheme.
[0006] By adopting the above technical solution, the design request for a safety instrumented system (SAS) sent by the factory enterprise is obtained. Based on the evaluation results, the corresponding SAS design is matched in the preset SAS library, and then the design is sent to the user, which facilitates the factory enterprise to implement the SAS design. This solves the problem in related technologies that it is impossible to implement corresponding SAS for different production enterprises, and makes it easier to use the SAS to identify potential risks.
[0007] A second aspect of this application provides a safety instrumented system (SAS). The system is a server, which includes a receiving unit, a processing unit, and a sending unit. The receiving unit is used to receive a SAS design request sent by a user equipment. The SAS design request includes any one or more of regulations, standards, laws, industry standards, and policies. The processing unit is used to evaluate the SAS design request and obtain a first evaluation result. Based on the first evaluation result, it matches the corresponding SAS design in a preset SAS library. The sending unit is used to send the SAS design to the user equipment so that the user can implement the SAS design.
[0008] By adopting the above technical solution, the design request for a safety instrumented system (SAS) sent by the factory enterprise is obtained. Based on the evaluation results, the corresponding SAS design is matched in the preset SAS library, and then the design is sent to the user, which facilitates the factory enterprise to implement the SAS design. This solves the problem in related technologies that it is impossible to implement corresponding SAS for different production enterprises, and makes it easier to use the SAS to identify potential risks.
[0009] Optionally, the processing unit is used to operate the safety instrumented system and obtain the operating results; if the operating results are not within the preset range, the safety instrumented system is modified according to the operating results to ensure that the safety instrumented system can operate normally.
[0010] By adopting the above technical solution, the user implements the design plan and starts up the safety instrumented system. The system is then tested to ensure that it is operating normally. If the test results are normal, the safety instrumented system can identify potential risks and take corresponding actions based on the risks to avoid major accidents and reduce personnel losses.
[0011] Optionally, the processing unit determines whether the first information security assessment is less than or equal to the preset risk standard. The first information security assessment is an information security assessment of the design scheme of the safety instrument system. If the first information security assessment is less than or equal to the preset risk standard, the first assessment result is obtained.
[0012] Using the above technical solution, an information security assessment is performed on the design request of the safety instrumented system. When the first information security assessment is less than or equal to the preset risk standard, it is confirmed that the sent design request meets the enterprise's risk level standard, and the first assessment result is obtained.
[0013] Optionally, the processing unit is used to improve the information security assessment based on the result of the first information security assessment if the first information security assessment is greater than the preset risk standard, and to obtain the result of the second information security assessment; if the result of the second information security assessment is less than or equal to the preset risk standard, the first assessment result is obtained.
[0014] Using the above technical solution, when the result of the first information security assessment is greater than the preset risk standard, it is confirmed that the design request sent does not meet the enterprise's risk level standard, and the risk that does not meet the enterprise needs to be improved according to the actual situation; then the improved second information security assessment is judged to ensure that the improved information security assessment meets the enterprise's risk level standard.
[0015] Optionally, the processing unit is used to determine whether the design scheme of the safety instrumented system meets the preset information security requirements specification; when the design scheme of the safety instrumented system meets the preset information security requirements specification, it confirms that the design scheme of the safety instrumented system meets the actual needs.
[0016] Using the above technical solution to determine whether the design scheme meets the preset information security requirements specification is to ensure that the design scheme records different risk levels and takes corresponding measures, to check whether the design scheme is complete, and to ensure that any omissions in the design scheme occur.
[0017] Optionally, at preset intervals, the receiving unit is used to acquire the safety instrumented system in operation; the processing unit is used to determine whether the result of the third information security assessment is less than or equal to the preset risk standard, the result of the third information security assessment is obtained by assessing the safety instrumented system; if the result of the third information security assessment is less than or equal to the preset risk standard, the safety instrumented system is confirmed to be in normal condition.
[0018] By adopting the above technical solution, the safety instrumented system will be evaluated regularly during operation. In order to ensure that there are any areas for improvement in the safety instrumented system, the measures corresponding to the risk level will be verified regularly to ensure that they are in normal working order, thereby reducing the occurrence of major failures due to the failure to inspect the safety instrumented system.
[0019] Optionally, the processing unit is used to confirm that there is a changed part in the security instrumented system if the result of the third information security assessment is greater than the preset risk standard; determine whether the first part affects the preset life cycle, wherein the first part is any part of the solution in the security instrumented system; if the first part affects the preset life cycle, disable the first part to ensure that the security instrumented system is in normal condition.
[0020] By adopting the above technical solution, when there are changes to the safety instrumented system, the parts that will affect the preset life cycle of the safety instrumented system will be deactivated, so as to avoid the safety instrumented system being unable to be used normally due to the existence of changes, which would affect the normal operation of the factory and enterprise.
[0021] A third aspect of this application provides an electronic device, which includes a processor, a memory, a user interface, and a network interface. The memory is used to store instructions, the user interface and the network interface are used to communicate with other devices, and the processor is used to execute the instructions stored in the memory, causing the electronic device to perform the method as described in any of the first aspects of this application.
[0022] The fourth aspect of this application provides a computer-readable storage medium storing instructions that, when executed, perform the method of any one of the first aspects of this application.
[0023] Compared with existing technologies, the beneficial effects of this application are as follows: It obtains safety instrumented system (SAS) design requests from factories and enterprises, matches corresponding SAS design schemes in a pre-set SAS library based on evaluation results, and then sends the design schemes to users. This solves the problem in related technologies where it is impossible to implement corresponding SAS for different production enterprises, facilitating the identification of potential risks using SAS. Users implement the design scheme, start the SAS, and further test its operation. If the operation is normal, the SAS can identify potential risks and take corresponding actions to avoid major accidents and reduce personnel losses. Before sending the design scheme to users, it is necessary to determine whether the design scheme meets the pre-set information security requirements specification, ensuring that the design scheme sent to users is complete and records the corresponding measures for different risk levels, reducing omissions in the design scheme. During the operation of the SAS, it will be evaluated regularly to ensure that there are areas for improvement and to periodically verify whether the measures corresponding to the risk levels are in normal working order, reducing the occurrence of major failures due to the lack of SAS inspection. Attached Figure Description
[0024] Figure 1This is a first flowchart illustrating a data processing method provided in an embodiment of this application;
[0025] Figure 2 This is a second flowchart illustrating a data processing method provided in an embodiment of this application;
[0026] Figure 3 This is a third flowchart illustrating a data processing method provided in an embodiment of this application;
[0027] Figure 4 This is a fourth flowchart illustrating a data processing method provided in an embodiment of this application;
[0028] Figure 5 This is a schematic diagram of the structure of a safety instrumented system provided in an embodiment of this application;
[0029] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0030] Reference numerals: 501, receiving unit; 502, processing unit; 503, transmitting unit; 600, electronic device; 601, processor; 602, communication bus; 603, user interface; 604, network interface; 605, memory. Detailed Implementation
[0031] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0032] In the description of the embodiments of this application, words such as "illustrative," "for example," or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "illustrative," "for example," or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Rather, the use of words such as "illustrative," "for example," or "for example" is intended to present the relevant concepts in a specific manner.
[0033] Furthermore, the terms "first," "second," etc., used in this application specification are used to distinguish different objects rather than to describe a specific order, and may explicitly or implicitly include one or more of the features.
[0034] With the advancement and implementation of the "Industrial Internet + Safe Production" action plan and the widespread application of technologies such as the Internet of Things, Internet+, and cloud services in the safety production management of industrial and commercial sectors, the Safety Instrumentation System (SIS) has become an important protective layer for industrial safety. The SIS mainly consists of the alarm and interlocking parts of the factory control system. It implements alarm actions, adjustments, or shutdown controls based on the detection results in the control system and is an important component of the automatic control of factories and enterprises.
[0035] A safety instrumented system is a programmable control system that takes emergency measures against potential hazards in production equipment or facilities and responds promptly to any deteriorating conditions, bringing the equipment to a predefined safe shutdown state. This minimizes hazards and losses and ensures the safety of production equipment, the environment, and personnel.
[0036] Safety instrumented systems are commonly used in process industries such as petroleum and chemical industries, but as a highly reliable safety protection facility, they are also widely used in other industries, including nuclear power, aviation, ships and high-speed rail systems.
[0037] In actual factories and enterprises, various industrial control system equipment is used. To ensure the safety of this equipment, safety instrumented systems (SAS) must be installed within the factory control system. SAS can identify potential risks and output corresponding alarm actions based on different risks, facilitating timely detection and handling of risks and reducing significant personnel losses.
[0038] However, different factories and enterprises face different risks, and how to set up corresponding safety instrumented systems (SAS) for different factories and enterprises is a problem that urgently needs to be solved. This application provides a data processing method applied to a server. This application takes designing a SAS for a factory or enterprise as an example, where the server is a third-party platform providing SAS design solutions to the factory or enterprise. Figure 1 This is a first flowchart illustrating a data processing method provided in an embodiment of this application; see reference. Figure 1 The method includes the following steps S101-S104.
[0039] Step S101: Receive the safety instrumented system design request sent by the user equipment.
[0040] In the above steps, the server receives a Safety Instrumented System (SIS) design request from a user device. The user device can include various electronic devices such as desktop computers, tablets, laptops, and smartphones. The SIS design request can include one or more of the following: regulations, standards, laws, industry standards, and policies. Regulations refer to rules established by a company and are unique to that company; for example, Company A's rules state that equipment should be shut down promptly after completing a task. Standards refer to standards that a company uses for its main business or products; different products have their own corresponding standards. For example, Company B manufactures product B, but product B sold must conform to Company B's manufacturing standards. Laws are normative documents with a legal force relatively lower than the constitution and laws. Regulations mainly take three forms: first, administrative regulations, also known as administrative rules, formulated and promulgated by the State Council and its subordinate government departments in accordance with the Constitution and laws; second, local regulations formulated and promulgated by the people's congresses and their standing committees of provinces, autonomous regions, and municipalities directly under the central government based on the specific circumstances and actual needs of their respective administrative regions; and third, local regulations formulated by the people's congresses and their standing committees of larger cities (provincial capitals, capital cities) (which must be approved by the standing committees of the provincial or autonomous regional people's congresses before implementation), such as the "Regulations on Labor Management of Sino-Foreign Joint Ventures." Industrial standards are the usage standards for industrial-related products, standards commonly used by enterprises, such as the industrial-grade temperature range of electronic components (-40-85 degrees Celsius). Policies refer to policies issued by relevant national departments concerning enterprises in different industries. The project scope is determined based on company rules, standards, regulations, industrial standards, and policies; the project scope represents the safety instrumented system design request. For any new project involving hazards in the process industry, the scope of work should be determined, and the contents to be included in the project should be detailed.
[0041] For example, Company A needs to set up a safety instrumented system (SAS). Company A sends a SAS design request to the server through user equipment. Based on company regulations and standards, and in conjunction with newly published regulations and industry standards in Province X, Company A sets up a SAS design that complies with the policies released in 2020. Determining policies and engineering practices also requires considering Company A's remote access requirements, boundary device configuration rules, and third-party link lists.
[0042] Step S102: Evaluate the safety instrumented system design request and obtain the first evaluation result.
[0043] In the above steps, the Safety Instrumented System (SIS) design request defines the project scope. The server identifies the required SIS based on the project scope, with different SIS corresponding to different project scopes. After selecting a suitable SIS, the server creates an initial system architecture diagram and catalog within the SIS. This allows for updating the system architecture diagram and catalog by identifying external facilities and supporting equipment. Based on company risk standards and pre-hazard audits, initial information security level targets are established. The server then conducts a detailed information security assessment based on these targets. This assessment includes process hazard analysis, company risk standards, audits, non-network security compensation measures, and initial area and piping diagrams. The object of the information security assessment is the SIS under consideration.
[0044] For example, if company A's project scope is h, it selects the corresponding Safety Instrumented System H based on h, and creates an initial system structure diagram and catalog in Safety Instrumented System H; then, through company A's risk standards and pre-hazard audit, it formulates initial information security level targets, and conducts an information security assessment on the initial information security level targets.
[0045] In one possible embodiment, before obtaining the first assessment result, an information security assessment is performed on the safety instrumented system (SIS) design request to obtain a first information security assessment. Then, it is determined whether the first information security assessment is less than or equal to a preset risk standard. The preset risk standard refers to the company's risk standards, namely, the company's tolerable risk guidelines, process safety risk standards, and information security risk standards. These include system failures (such as hardware / software failures, power system failures, network failures, etc.), human error (such as misoperation, unintentional damage, etc.), and deliberate sabotage (such as proactive attacks). If the first information security assessment is less than or equal to the preset risk standard, it is confirmed that the information security assessment of the SIS meets the company's risk standards, and the first assessment result is obtained. A design scheme can then be established based on the first assessment result. After obtaining the first assessment result, the assessment phase in the information security lifecycle is completed, and the next detailed design phase begins.
[0046] Furthermore, if the first information security assessment exceeds the preset risk standard, it confirms that the information security assessment of the security instrumented system does not meet the company's risk standards. Therefore, the process, non-network security protection, or measures need to be improved based on the first information assessment results. After improving the first information assessment results, a second information security assessment is obtained. It is then determined whether the second information security assessment is less than or equal to the preset risk standard. If the second information security assessment is less than or equal to the preset risk standard, the first assessment result is obtained.
[0047] For example, if the first information security assessment has 10 components and the preset risk standards have 8 components, and the number of components in the first information security assessment exceeds the preset risk standards, it indicates that the non-network security protection design in the first information security assessment is inadequate, resulting in a mismatch between the number of components in the first information security assessment and the number of risk standards in the company; the non-network security protection in the first information security assessment needs to be improved. In practice, the specific number of preset risk standards or other aspects will be considered, and no limit will be specified here.
[0048] Step S103: Match the design scheme of the corresponding safety instrumented system in the preset safety instrumented system library according to the first evaluation result.
[0049] In the above steps, the preset safety instrumented system library is a library of design schemes pre-stored based on different evaluation results. After the server obtains the first evaluation result, which includes tables such as information security implementation strategies, protective measures, enterprise requirements, and software platform operating systems, the server matches the corresponding safety instrumented system design scheme in the preset safety instrumented system library according to the first evaluation result.
[0050] For example, if the first evaluation result meets all 18 items in the table, the corresponding safety instrument design scheme is matched in the preset safety instrument system library based on the 18 items, and the 18 items match the corresponding safety instrument design scheme c.
[0051] In one possible embodiment, before sending the safety instrumented system design to the user equipment, it is also necessary to determine whether the safety instrumented system design meets the specifications, such as... Figure 2 As shown, Figure 2 This is a second flowchart of a data processing method provided in an embodiment of this application, which includes the following steps S201-S202.
[0052] Step S201: Determine whether the design scheme of the safety instrumented system meets the preset information security requirements specification.
[0053] In the above steps, the pre-defined information security requirements plan specifically discusses network security countermeasures and records the measures required to achieve and maintain the necessary information security level. The information security requirements specification should include at least: (1) a high-level description of the system under consideration, including: name, high-level description of system functions and intended use, description of controlled equipment or processes, system and related data and process descriptions. (2) an object / facility area and piping diagram. (3) a description of all conventional network security countermeasures required for all areas and piping. (4) a description of the target network security level for areas and piping that may have a potential impact on the industrial control system. (5) a list of connection types for each third-party external interface, including Modbus, Profibus; OPC; wireless (802.11, etc.) and other specific vendor system protocols. (6) a description of all network security countermeasures required for each documented third-party interface. (7) a requirement that network security countermeasures should not affect the performance of the SCAL system. (8) if network security countermeasures may affect the overall response time of security functions, the impact of network security countermeasures on response time should be included in the overall response time assessment of security functions. (9) Define the security status of the process for each identified countermeasure, such as the target security level to be achieved in each area; the expected security level (SL) risk reduction that each countermeasure can achieve based on the threat vector; network security testing requirements, such as penetration testing, vulnerability assessment, etc. (10) Frequency of network security countermeasure checks and tests. (11) Response time requirements for each countermeasure to bring the process into a secure state. (12) Manual operation requirements as part of the countermeasure, such as physical isolation between the control network and the enterprise network. (13) Disaster recovery requirements to restore full functionality after taking countermeasures. (14) Remote access requirements, such as security measures for remote access. (15) Describe the system hardening measures to be implemented. (16) Management support requirements for the countermeasures. (17) User access control policies for industrial control systems (including SIS systems). (18) Physical access restriction requirements. (19) Virus prevention and detection measures to be taken on the control network and the scanning frequency. (20) Patch policies and requirements related to industrial control systems (including SIS systems). (21) Upgrade strategies to address current mainstream and future potential threats. (22) Frequency of re-verification of detailed network risk assessments. (23) Required network communication uptime (all levels) and high reliability requirements for network equipment. The network specification should consider the frequency of network upgrades. The server determines whether the security instrumented system design meets the preset information security requirements specification in order to ensure the integrity of the design. During the integration phase based on the design, it is necessary to ensure that all parts of the security instrumented system design are configurable and can be installed and debugged.
[0054] Step S202: When the design scheme of the safety instrumented system meets the preset information security requirements specification, confirm that the design scheme of the safety instrumented system meets the actual needs.
[0055] In the above steps, when the design scheme of the safety instrumented instrument meets the preset information security requirements plan, it is confirmed that the design scheme of the safety instrumented instrument is complete, configurable, and meets the actual needs of the enterprise. For example, if the design scheme of the safety instrumented instrument is Y, and when the design scheme Y meets the preset information security requirements plan, it is confirmed that the design scheme Y is complete and can be implemented and configured.
[0056] Furthermore, when the design scheme of the safety instrument does not meet the preset information security requirements specification, it is confirmed that the design scheme of the safety instrument is incomplete. Based on the actual situation, it is necessary to find out which item in the preset information security requirements specification the design scheme of the safety instrument does not meet, and improve the item that is not met to ensure the integrity of the safety instrument design scheme.
[0057] Step S104: Send the safety instrumented system design scheme to the user equipment so that the user can implement the safety instrumented system design scheme.
[0058] In the above steps, after the server confirms that the safety instrumented system design scheme meets the preset information security requirements specification, it sends the safety instrumented system design scheme to the user equipment to facilitate the user to implement the installation according to the safety instrumented system design scheme.
[0059] For example, Company H wants to set up a Safety Instrumented System (SIS) and sends a SIS design request s to the server. The server evaluates the SIS design request s and confirms that it meets Company H's preset risk standards. Based on the evaluation results, the server matches the design scheme k corresponding to the SIS design request s in the preset SIS library. The server then determines whether the design scheme k meets the preset information security requirements specification. If the design scheme k meets the preset information security requirements specification, the server confirms the integrity of the design scheme k. The server then sends the design scheme k to the corresponding user equipment of Company H, so that relevant personnel of Company H can configure and install the SIS according to the design scheme, thereby identifying potential risks and reducing losses for relevant personnel of Company H.
[0060] In one possible implementation, after installing the safety instrumented system according to the design plan, the enterprise will maintain the safety instrumented system to ensure its normal operation. For example... Figure 3 As shown, Figure 3 This is a third flowchart of a data processing method provided in an embodiment of this application, which includes the following steps S301-S302.
[0061] Step S301: Operate the safety instrumented system and obtain the results.
[0062] The above steps involve operating the Safety Instrumented System (SIS), i.e., starting the SIS. During startup, a security review must be conducted, and corresponding risk mitigation measures must be verified to ensure that if a risk arises after startup but corresponding measures are not taken, resulting in personnel injury, the SIS will not be activated. Monitoring of the SIS includes monitoring its workflow, information security incidents, and threat assessments. The server records various SIS metrics during operation, and the results represent these metrics during the SIS's operation.
[0063] Step S302: If the running result is not within the preset range, modify the safety instrument system according to the running result to ensure that the safety instrument system can operate normally.
[0064] In the above steps, the preset range refers to the normal fault range that the safety instrumented system can withstand. When the operating results are not within the preset range, it is confirmed that the various indicators of the safety instrumented system during operation do not meet the normal range of the safety instrumented system; adjustments are made to the safety instrumented system based on the operating results to facilitate its normal operation.
[0065] For example, if the safety instrumented system (VIS) w displays a result of 1.2 during operation, while the preset range is set to 0-0.8, the result is outside the preset range. This indicates that the data for various indicators of the VIS w are inconsistent with normal operation, possibly due to human error in operating the VIS w, causing the result to deviate from the preset range. The VIS w needs to be restarted, following the correct operating procedures, to prevent malfunctions caused by human error. The preset range setting should be based on actual conditions and is not limited here.
[0066] In one possible implementation, the safety of the safety instrumented system should be checked periodically, such as... Figure 4 As shown, Figure 4 This is a fourth flowchart of a data processing method provided in an embodiment of this application, which includes the following steps S401-S403.
[0067] Step S401: At preset intervals, acquire the operating safety instrument system.
[0068] In the above steps, the design scheme is implemented to obtain a safety instrumented system (VIS). After the VIS is started, it is tested at preset intervals to determine whether its safety performance needs improvement. Regular verification of measures is conducted to ensure the safety of the VIS during operation. The preset intervals are set according to actual conditions and can be set to half a month, one month, one quarter, or half a year; no specific limit is imposed here.
[0069] For example, the preset interval is set to 30 days, starting from the first startup of the safety instrumented system; 30 days later, the operating safety instrumented system is actively acquired.
[0070] Step S402: Determine whether the result of the third information security assessment is less than the preset risk standard. The result of the third information security assessment is obtained by evaluating the safety instrumented system.
[0071] In the above steps, the server obtains the design scheme of the operating safety instrumented system, evaluates the design scheme to obtain a third information security assessment, and determines whether the third information security assessment falls within the preset risk standards. The preset risk standards refer to the company's risk standards, namely the company's tolerable risk guidelines, process safety risk standards, and information security risk standards. These include system failures (such as hardware and software failures, power system failures, network failures, etc.), human error (such as misoperation, unintentional damage, etc.), and deliberate sabotage (such as active attacks, etc.).
[0072] Step S403: If the result of the third information security assessment is less than or equal to the preset risk standard, confirm that the security instrumented system is in normal condition.
[0073] In the above steps, the server confirms that the third-party information security assessment is less than or equal to the preset risk standard, proving that the safety instrumented system (SIS) can take corresponding measures based on different risks during operation. For example, in the event of a hardware failure, it can send alarm information to the corresponding user equipment to prompt the user to repair the hardware failure in a timely manner. This further ensures that the SIS is suitable for the current scenario, requires no modification to the SIS, and is in normal working order.
[0074] Furthermore, if the third-party information security assessment exceeds the preset risk standard, it confirms that there are modified parts in the safety instrumented system (SIS). In practical applications, upgrades are performed on the SIS, primarily targeting specific procedures or risk measures. The parts being upgraded represent the modified parts. It is then determined whether the first part affects the preset lifecycle. The first part refers to any portion of the SIS solution; the preset lifecycle refers to the normal usage period of the SIS. If the first part affects the preset lifecycle, it will be deactivated. The first part refers to the portion of the facility before the improvements. It is necessary to consider whether the first part affects the preset lifecycle of the SIS. If it does, it will be treated as a new project, meaning the first part will be discontinued and removed from the facility to ensure it does not adversely affect other plants and equipment.
[0075] Using the above method, design requests for safety instrumented systems (SAS) solutions from factories are obtained. Based on the evaluation results, corresponding SAS design solutions are matched from a pre-set SAS library and then sent to the user. This addresses the issue of not being able to implement SAS solutions tailored to different production enterprises, facilitating the identification of potential risks using SAS solutions. Users implement the design solutions, start the SAS, and further test its operation. If the operation is normal, the SAS can identify potential risks and take corresponding actions to prevent major accidents and reduce personnel losses. When conducting information security assessments on SAS design requests, it's also necessary to consider whether the submitted design requests meet the enterprise's risk level standards. If they do not meet the standards, improvements are made based on the actual situation. Before sending the design solution to the user, it's necessary to determine whether the design solution meets the pre-set information security requirements specifications, ensuring the submitted design solution is complete and records the corresponding measures for different risk levels, minimizing omissions in the design solution. During the operation of the safety instrumented system, the system will be evaluated regularly to ensure that there are any areas for improvement. The measures corresponding to the risk level will be verified regularly to ensure that they are in normal working order, thereby reducing the risk of major failures due to the lack of inspection of the safety instrumented system.
[0076] This application also provides a safety instrumented system. Figure 5 This is a schematic diagram of a safety instrumented system provided in an embodiment of this application; see reference. Figure 5 The server includes a receiving unit 501, a processing unit 502, and a sending unit 503.
[0077] The receiving unit 501 is used to receive a safety instrumented system design request sent by the user equipment. The safety instrumented system design request includes any one or more of the following: regulations, standards, laws, industry standards, and policies.
[0078] The processing unit 502 is used to evaluate the safety instrumented system design request and obtain a first evaluation result; and to match the corresponding safety instrumented system design scheme in the preset safety instrumented system library according to the first evaluation result.
[0079] The sending unit 503 is used to send the design scheme of the safety instrumented system to the user equipment so that the user can implement the design scheme of the safety instrumented system.
[0080] In one possible embodiment, the processing unit 502 is used to operate the safety instrumented system and obtain the operation results; if the operation results are not within the preset range, the safety instrumented system is modified according to the operation results so that the safety instrumented system can operate normally.
[0081] In one possible embodiment, the processing unit 502 is used to determine whether the first information security assessment is less than or equal to a preset risk standard. The first information security assessment is an information security assessment of the design scheme of the safety instrument system. If the first information security assessment is less than or equal to the preset risk standard, the first assessment result is obtained.
[0082] In one possible embodiment, the processing unit 502 is used to improve the information security assessment based on the result of the first information security assessment if the first information security assessment is greater than the preset risk standard, and to obtain a second information security assessment if the second information security assessment is less than or equal to the preset risk standard, and to obtain the first assessment result.
[0083] In one possible embodiment, the processing unit 502 is used to determine whether the design scheme of the safety instrumented system meets the preset information security requirements specification; when the design scheme of the safety instrumented system meets the preset information security requirements specification, it is confirmed that the design scheme of the safety instrumented system meets the actual needs.
[0084] In one possible embodiment, at preset intervals, the receiving unit 501 is used to acquire the operating safety instrumented system; the processing unit 502 is used to determine whether the third information security assessment is less than or equal to the preset risk standard, the third information security assessment is obtained by evaluating the safety instrumented system; if the third information security assessment is less than or equal to the preset risk standard, it is confirmed that the safety instrumented system is in a normal state.
[0085] In one possible embodiment, the processing unit 502 is used to confirm that there is a changed part in the safety instrumented system if the third information security assessment is greater than the preset risk standard; determine whether the first part affects the preset life cycle, wherein the first part is any part of the solution in the safety instrumented system; if the first part affects the preset life cycle, the first part is disabled to ensure that the safety instrumented system is in a normal state.
[0086] It should be noted that the above embodiments of the apparatus are only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.
[0087] Please see Figure 6 , Figure 6 This application provides a schematic diagram of the structure of an electronic device. For example... Figure 6 As shown, the electronic device 600 may include: at least one processor 601, at least one network interface 604, user interface 603, memory 605, and at least one communication bus 602.
[0088] The communication bus 602 is used to enable communication between these components.
[0089] The user interface 603 may include a display screen and a camera. Optionally, the user interface 603 may also include a standard wired interface and a wireless interface.
[0090] The network interface 604 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0091] The processor 601 may include one or more processing cores. The processor 601 connects to various parts of the server using various interfaces and lines, and performs various server functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 605, and by calling data stored in memory 605. Optionally, the processor 601 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 601 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and application requests; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also be implemented as a separate chip without being integrated into the processor 601.
[0092] The memory 605 may include random access memory (RAM) or read-only memory. Optionally, the memory 605 may include a non-transitory computer-readable storage medium. The memory 605 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 605 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 605 may also be at least one storage device located remotely from the aforementioned processor 601.
[0093] like Figure 6 As shown, the memory 605, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and data processing applications.
[0094] exist Figure 6In the electronic device 600 shown, the user interface 603 is mainly used to provide an input interface for the user and to obtain the user input data; while the processor 601 can be used to call the application program for data processing stored in the memory 605. When executed by one or more processors, the electronic device 600 performs one or more methods as described in the above embodiments.
[0095] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0096] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0097] In the several embodiments provided in this application, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the shown or discussed mutual couplings or direct couplings or communication connections may be through some service interfaces; indirect couplings or communication connections between apparatuses or units may be electrical or other forms.
[0098] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0099] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0100] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as USB flash drives, portable hard drives, magnetic disks, or optical disks.
[0101] The above are merely exemplary embodiments of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Those skilled in the art will readily conceive of other embodiments of this disclosure upon considering the specification and the disclosure of practical truths. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure.
Claims
1. A data processing method, characterized in that, Applied to a server, the method includes: Receive a safety instrumented system design request sent by a user equipment, wherein the safety instrumented system design request includes any one or more of regulations, standards, laws and policies; The safety instrumented system design request is evaluated to obtain a first evaluation result, which specifically includes: determining whether the first information security assessment is less than or equal to a preset risk standard, wherein the first information security assessment is an information security assessment of the safety instrumented system design; if the first information security assessment is less than or equal to the preset risk standard, the first evaluation result is obtained. If the first information security assessment is greater than the preset risk standard, improvements are made based on the result of the first information security assessment to obtain the result of the second information security assessment. If the result of the second information security assessment is less than or equal to the preset risk standard, the first assessment result is obtained; Based on the first evaluation result, match the design scheme of the corresponding safety instrument system in the preset safety instrument system library; The design scheme of the safety instrumented system is sent to the user equipment so that the user can implement the design scheme of the safety instrumented system.
2. The method according to claim 1, characterized in that, After sending the design scheme of the safety instrumented system to the user equipment so that the user can implement the design scheme of the safety instrumented system, the method further includes: The safety instrumented system was operated and the operating results were obtained; If the operating result is not within the preset range, the safety instrument system is modified according to the operating result to ensure that the safety instrument system can operate normally.
3. The method according to claim 1, characterized in that, After matching the design scheme of the corresponding safety instrumented system in the preset safety instrumented system library based on the first evaluation result, the method further includes: Determine whether the design scheme of the safety instrumented system meets the preset information security requirements specification. When the design scheme of the safety instrumented system meets the preset information security requirements specification, it is confirmed that the design scheme of the safety instrumented system meets the actual needs.
4. The method according to claim 2, characterized in that, The method further includes: The safety instrumented system is acquired at preset time intervals during operation; Determine whether the result of the third information security assessment is less than or equal to the preset risk standard, wherein the result of the third information security assessment is obtained by assessing the safety instrumented system; If the result of the third information security assessment is less than or equal to the preset risk standard, the safety instrumented system is confirmed to be in normal condition.
5. The method according to claim 4, characterized in that, If the result of the third information security assessment is greater than the preset risk standard, it is confirmed that there is a modified part in the security instrument system; Determine whether the first part affects the preset lifespan, where the first part is any part of the solution in the safety instrument system; If the first part affects the preset lifespan, the first part will be deactivated to ensure that the safety instrument system is in normal condition.
6. A safety instrumented system, characterized in that, The system is a server, which includes a receiving unit (501), a processing unit (502), and a sending unit (503). The receiving unit (501) is used to receive a safety instrumented system design request sent by the user equipment. The safety instrumented system design request includes any one or more of the following: regulations, standards, laws and policies. The processing unit (502) is used to evaluate the safety instrumented system (SIS) design request and obtain a first evaluation result, specifically including: determining whether a first information security assessment is less than or equal to a preset risk standard, wherein the first information security assessment is an information security assessment of the SIS design; if the first information security assessment is less than or equal to the preset risk standard, obtaining the first evaluation result; if the first information security assessment is greater than the preset risk standard, improving the design based on the first information security assessment result to obtain a second information security assessment result; if the second information security assessment result is less than or equal to the preset risk standard, obtaining the first evaluation result. Based on the first evaluation result, match the design scheme of the corresponding safety instrument system in the preset safety instrument system library; The sending unit (503) is used to send the design scheme of the safety instrument system to the user equipment so that the user can implement the design scheme of the safety instrument system.
7. An electronic device, characterized in that, The device includes a processor (601), a memory (605), a user interface (603), and a network interface (604). The memory (605) is used to store instructions. The user interface (603) and the network interface (604) are used to communicate with other devices. The processor (601) is used to execute the instructions stored in the memory (605) to cause the electronic device (600) to perform the method as described in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed, perform the method as described in any one of claims 1-5.
Citation Information
Patent Citations
Safety automation builder
CN104007668A