A non-interference method for gateway communication between DCS systems of different security levels
By constructing a non-disruptive download method between the DCS systems of a nuclear power plant, the communication interruption problem caused by the upgrade of safety-level and non-safety-level gateways was solved, realizing a non-disruptive gateway upgrade between safety-level and non-safety-level DCS systems and ensuring the safe and stable operation of the nuclear power plant.
Patent Information
- Application Number
- CN202310154850.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-10
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2043-02-10
AI Technical Summary
In existing technologies, separate upgrades and downloads of safety-grade and non-safety-grade DCS system gateways can lead to communication interruptions, affecting the safe and stable operation of nuclear power units. Furthermore, during the construction, commissioning, and normal operation phases of nuclear power plants, the plant's status needs to be lowered to avoid control signal disturbances, causing adverse effects.
A non-disruptive download method for gateway communication between DCS systems with different security levels is constructed. By acquiring and downloading a new communication point table and a new software project, switching communication links, performing status judgment and fault alarm, the method ensures uninterrupted communication during gateway upgrades.
It enables seamless gateway upgrades between safety-grade and non-safety-grade DCS systems in nuclear power plants, avoiding the impact of communication interruptions on unit operation and control, and ensuring the safety and stability of nuclear power plants.
Smart Images

Figure CN116232714B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of DCS control system design and operation and maintenance, and more specifically, to a non-intrusive download method for gateway communication between DCS systems with different security levels. Background Technology
[0002] Nuclear power plant DCS control systems are typically classified into safety-level DCS systems and non-safety-level DCS systems according to their safety classification. Network data communication exists between safety-level and non-safety-level DCS systems. To prevent interference from the non-safety-level DCS system to the safety-level DCS system via the network, the safety-level DCS system sends control signals unidirectionally to the non-safety-level DCS system through a gateway.
[0003] When changes or upgrades occur to the DCS control system of a nuclear power plant during installation, commissioning, and normal operation, the network communication signals may be deleted, added, or their types adjusted. In such cases, it is necessary to upgrade the gateways on both the safety-level and non-safety-level sides.
[0004] In existing technologies, upgrading and downloading communication point lists separately for safety-grade and non-safety-grade DCS gateways can cause communication interruptions between DCS systems. Furthermore, during the construction and commissioning phase of a nuclear power plant, to reduce the risk of communication gateway downloads, the nuclear power plant typically needs to be placed in a safe and stable state. At the same time, to avoid control signal disturbances, hundreds of related system devices need to be placed in a safe isolation state. However, during the normal operation of the nuclear power unit, for reasons of nuclear power plant operation safety and nuclear safety, it is prohibited to download communication gateways that cause disturbances. The power plant must be downgraded to a fully unloaded mode before the upgrade can be performed, which has a significant adverse impact on the safe and stable operation of the nuclear power unit. Summary of the Invention
[0005] The technical problem to be solved by this invention is to address the impact of communication interruptions on nuclear power units caused by separate upgrades and downloads of safety-level gateways and non-safety-level gateways in the prior art. This invention provides a non-disruptive download method for gateway communication between DCS systems of different safety levels.
[0006] The technical solution adopted by this invention to solve its technical problem is: to construct a non-intrusive download method for gateway communication between DCS systems with different security levels.
[0007] In the non-intrusive download method for gateway communication between DCS systems of different security levels described in this invention, the method includes a download operation, which includes the following steps:
[0008] S1: Obtain and download the new communication point table to the second non-security level gateway, and download the new overall project to the second security level gateway; the new overall project includes the new communication point table and the new software project.
[0009] S2: The first communication link between the first security-level gateway and the first non-security-level gateway is switched to the second communication link between the second security-level gateway and the second non-security-level gateway for communication;
[0010] S3: Download the new communication point table to the first non-security level gateway and download the new overall project to the first security level gateway;
[0011] S4: Switch from the second communication link to the first communication link for communication.
[0012] In the non-intrusive download method for gateway communication between DCS systems of different security levels described in this invention, the method further includes:
[0013] Get the current communication status of the communication link;
[0014] Determine if the communication status is normal; if yes, allow the download operation; if no, issue a fault alarm signal.
[0015] The current communication link includes the first communication link and the second communication link.
[0016] Furthermore, the new communication point table includes a new sender point table and a new receiver communication point table, and step S1 includes:
[0017] S11: The new software project is compiled by the security-level gateway to obtain the new sender communication point table; wherein, the security-level gateway includes the first security-level gateway and the second security-level gateway;
[0018] S12: The second non-security level gateway obtains and creates the new receiver communication point table according to the new sender communication point table;
[0019] S13: Download the new receiver communication point table to the second non-security level gateway and restart it, and download the new overall project to the second security level gateway.
[0020] Further, step S12 includes:
[0021] Obtain the offset address of the new sender's communication point table;
[0022] The corresponding data is parsed based on the offset address and assigned to the receiving communication point to create the new receiving communication point table.
[0023] Furthermore, the method also includes: acquiring and determining whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal; if yes, then allowing the download operation to be executed; if no, then stopping the execution of the download operation and issuing an alarm signal.
[0024] Furthermore, the step of acquiring and determining whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal also includes:
[0025] Obtain the software engineering versions of the second non-security level gateway and the first non-security level gateway;
[0026] Determine whether the software engineering versions are the same; if yes, determine that the monitoring status is normal; if no, determine that the monitoring status is abnormal.
[0027] Furthermore, before performing step S2, the following is also included:
[0028] Obtain the running status of the second security-level gateway and the second non-security-level gateway after the download is completed;
[0029] Determine whether the operating status is normal; if yes, continue to execute step S2; if no, issue an alarm signal.
[0030] Further, step S2 includes:
[0031] Obtain the communication status of the second communication link after the handover is completed;
[0032] According to the newly sent communication point table, transmit network data points to the second non-security level gateway;
[0033] The network data point is acquired and it is determined whether it matches the receiver's communication point table. If it does, the second non-security level gateway communication signal reception is determined to be normal, and the download operation is continued. If not, a fault alarm signal is issued.
[0034] Further, step S3 includes:
[0035] S31: The first non-security level gateway obtains and creates the new receiver communication point table based on the sender communication point table;
[0036] S32: Download the new receiver communication point table to the first non-security level gateway and restart it, and at the same time download the new overall project to the first security level gateway.
[0037] Furthermore, the download operation also includes:
[0038] After step S3 is completed, the new software project is simultaneously downloaded to both the first non-security-level gateway and the second non-security-level gateway; or...
[0039] After step S4 is completed, the new software project is simultaneously downloaded to the first non-security level gateway and the second non-security level gateway.
[0040] Further, step S4 includes:
[0041] Obtain the communication status of the first communication link after the handover is completed;
[0042] According to the newly sent communication point table, transmit network data points to the first non-security level gateway;
[0043] The network data point is acquired and it is determined whether it matches the receiver's communication point table. If it does, the communication signal reception of the first non-security gateway is determined to be normal, and the download operation is continued. If not, a fault alarm signal is issued.
[0044] The method for seamless downloading of gateway communication between DCS systems of different safety levels according to the present invention has the following advantages: it can achieve seamless downloading of one-way communication gateways between safety-level and non-safety-level DCS systems in nuclear power plants, and avoids the impact on the safety of unit operation control caused by the interruption of the original gateway communication function between safety-level and non-safety-level DCS systems during gateway download. Attached Figure Description
[0045] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings:
[0046] Figure 1 This is a flowchart of the non-intrusive download method for gateway communication between DCS systems with different security levels provided in this embodiment of the invention;
[0047] Figure 2 This is a schematic diagram of the gateway download status after step S1 is completed in the non-intrusive download method provided in this embodiment of the invention;
[0048] Figure 3 This is a schematic diagram of the gateway download status after step S3 is completed in the non-intrusive download method provided in this embodiment of the invention;
[0049] Figure 4 This is a schematic diagram showing the complete download status of the gateway in the non-disruptive download method provided in this embodiment of the invention. Detailed Implementation
[0050] To provide a clearer understanding of the technical features, objectives, and effects of the present invention, specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0051] DCS (Distributed Control System) is a digital instrumentation and control system, which is a distributed control system based on computer network communication; the instrumentation and control system of a nuclear power plant can generally be divided into 4 layers.
[0052] Level 0: Field control layer, mainly including field devices such as actuators and transmitters.
[0053] Level 1: Process control layer, mainly including reactor protection system, power control system, T / G control system, in-core measurement and other control and acquisition systems.
[0054] Level 2: Operation and control layer (operation and information management layer), mainly includes power plant computer information and control systems, backup panels and other human-machine interaction equipment and related data processing equipment placed in control rooms such as the main control room, remote shutdown station, and technical support center.
[0055] Level 3: Management layer, which includes third-party control interfaces and management layers, mainly including power plant information systems, emergency response systems, etc.
[0056] Nuclear power plant DCS control systems generally refer to Level 1 and Level 2. Based on their safety classification, they are typically divided into safety-level DCS systems and non-safety-level DCS systems. Safety-level DCS systems mainly include Level 1 reactor protection systems, in-core measurement systems, and other safety-level control and data acquisition systems. The remaining systems at Level 1 and almost all of Level 2 constitute non-safety-level DCS systems. Network data communication exists between safety-level and non-safety-level DCS systems. To prevent non-safety-level DCS from interfering with safety-level DCS through the network, data transmission is completed using a one-way communication gateway. That is, the safety-level DCS sends network data signals unidirectionally to the non-safety-level DCS system through the gateway; this typically includes display information sent to Level 2 or control signals sent to the Level 1 non-safety-level DCS system.
[0057] The communication point table is primarily responsible for parsing data from security-level gateways, while software engineering performs corresponding calculations based on the parsed data. The key to communication between security-level and non-security-level gateways lies in the matching of their communication point tables. That is, only when the receiving and sending communication point tables match can the security-level gateway correctly parse network data sent to the non-security-level gateway for parsing, thus enabling gateway communication between DCS systems. Furthermore, the communication point table is indexed by point names; in a new communication point table, points with unchanged names can still communicate with existing software engineering.
[0058] like Figure 1 As shown, Figure 1 This invention provides a method for seamless downloading between gateways of DCS systems with different security levels. The method includes a download operation, and the download operation includes the following steps:
[0059] S1: Obtain and download the new communication point table to the second non-security level gateway, and download the new overall project to the second security level gateway; the new overall project includes the new communication point table and the new software project.
[0060] S2: The first communication link between the first security-level gateway and the first non-security-level gateway is switched to the second communication link between the second security-level gateway and the second non-security-level gateway for communication;
[0061] S3: Download the new communication point list to the first non-security level gateway and download the new overall project to the first security level gateway;
[0062] S4: Switch from the second communication link to the first communication link for communication.
[0063] It should be noted that the communication between the safety-level DCS gateway and the non-safety-level DCS gateway in the nuclear power plant adopts a redundant structure. That is, in the implementation of this invention, the safety-level DCS gateway includes a first safety-level gateway and a second safety-level gateway. The two gateways work independently, sending the safety-level DCS network signal communication list to the non-safety-level gateway, only performing data forwarding. The two gateways have completely identical functions and do not require data interaction. The non-safety-level DCS gateway includes a first non-safety-level gateway and a second non-safety-level gateway, which respectively receive network data sent by the corresponding safety-level gateway. The first safety-level gateway is connected to the first non-safety-level gateway, and the second safety-level gateway is connected to the second non-safety-level gateway. The first non-safety-level gateway and the second non-safety-level gateway monitor each other's working status.
[0064] Under normal circumstances, the first non-security-level gateway receives and parses the data signals from the first security-level gateway it communicates with, and performs software engineering calculations. In this case, the first communication link serves as the main communication link to complete the gateway communication between DCS systems. Meanwhile, the second non-security-level gateway is in hot standby mode and does not accept data signals sent by the second security-level gateway connected to it.
[0065] When a fault signal occurs, if the second non-security-level gateway detects that the first non-security-level gateway is malfunctioning and unable to parse the signal, the second non-security-level gateway will synchronize the software engineering operation status of the first non-security-level gateway and complete the communication link switch. The second communication link will then complete the inter-DCS system gateway communication, receive the data signals sent by the second security-level gateway, parse the data, and complete the software engineering operation to achieve system gateway communication. At this time, the first non-security-level gateway switches from normal operation to hot standby, and the second non-security-level gateway switches from hot standby to normal operation.
[0066] In an embodiment of the present invention, the new communication point table includes a new sender communication point table and a new receiver communication point table. Step S1 includes: S11: The security-level gateway compiles a new software project to obtain the new sender communication point table; the security-level gateway includes a first security-level gateway and a second security-level gateway; S12: The second non-security-level gateway obtains and creates a new receiver communication point table corresponding to the new sender communication point table; S13: The new receiver communication point table is downloaded to the second non-security-level gateway and restarted, and the new overall project is downloaded to the second security-level gateway. Wherein, if the new software project compiled by the first security-level gateway and the second security-level gateway is the same, then the resulting new sender communication point table is also the same.
[0067] Specifically, since the inter-DCS system gateway communication link is currently the first communication link, the second communication link does not yet complete the inter-DCS system gateway communication, thus achieving the technical effect of uninterrupted DCS system gateway communication during the download process. Therefore, the new communication point table can be downloaded simultaneously to the second security-level gateway and the second non-security-level gateway; or, the new sender communication point table and the new software project can be downloaded to the second security-level gateway first, followed by the new receiver communication point table to the second non-security-level gateway; or, the new receiver communication point table can be downloaded to the second non-security-level gateway first, followed by the new sender communication point table and the new software project to the second security-level gateway. Figure 2 As shown, Figure 2 This is a schematic diagram of the gateway download status after step S1 is completed in the non-disruptive download method provided in this embodiment of the invention.
[0068] Before downloading, it is necessary to obtain the new sender communication point table after the new software project is compiled by the first security level gateway or the second security level gateway. At this time, the new software project and the new sender communication point table have not yet been downloaded to the gateway. In step S12, it is also necessary to obtain the offset address of the new sender communication point table; parse the corresponding data according to the offset address and assign it to the receiver communication point of the first non-security level gateway and the second non-security level gateway to create the new receiver communication point table.
[0069] As shown in Table 1, Table 1 is an example of the sender communication point table for a security-level gateway and the receiver communication point table for a non-security-level gateway. Communication between the security-level and non-security-level gateways uses a specific communication protocol. The sender packages communication points into data groups according to their offset addresses, and the receiver parses and assigns the corresponding data to the communication points based on the offset addresses. The correspondence between the sender and receiver for communication is commonly referred to as the communication point table. If the sender and receiver gateway communication point tables do not correspond, communication functionality cannot be achieved.
[0070]
[0071] Table 1
[0072] In an embodiment of the present invention, the method further includes: acquiring and determining whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal; if yes, then allowing the download operation; if no, then stopping the download operation and issuing an alarm signal. Acquiring and determining whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal further includes: acquiring the software engineering versions of the second non-security level gateway and the first non-security level gateway; determining whether the software engineering versions are the same; if yes, then determining that the monitoring status is normal; if no, then determining that the monitoring status is abnormal.
[0073] Specifically, during the download process for gateway upgrade, it is necessary to verify the software engineering versions of the second non-security level gateway and the first non-security level gateway to ensure that when the first or second non-security level gateway fails, the communication link can be switched in a timely manner, thereby achieving uninterrupted gateway communication between DCS systems.
[0074] The software engineering version verification process involves a non-security-level gateway in hot standby mode acquiring information from a working non-security-level gateway during monitoring. This information includes version identifiers generated after compiling the old or new software engineering project. The software engineering version is determined by comparing the version identifiers of the first and second non-security-level gateways. Different software versions will have different version identifiers. If the software engineering versions are the same, the monitoring status is normal, and the download operation can continue, reducing the risk of gateway failure during subsequent download operations. Otherwise, the non-security-level gateway in hot standby mode will report an error and become unusable, requiring immediate termination of the download operation.
[0075] In embodiments of the present invention, the method further includes: obtaining the communication status of the current communication link; determining whether the communication status is normal; if so, allowing the download operation; if not, issuing a fault alarm signal; wherein the current communication link includes a first communication link and a second communication link. Specifically, during the download operation for gateway upgrade, in order to ensure uninterrupted communication between the security-level gateway and the non-security-level gateway, communication function verification is required, and the download operation can only be allowed to continue only when the communication status of the current communication link is normal.
[0076] In an embodiment of the present invention, step S2 includes: switching the first communication link from communication between the first security-level gateway and the first non-security-level gateway to a second communication link from communication between the second security-level gateway and the second non-security-level gateway; obtaining the communication status of the second communication link after the switch is completed; transmitting network data points to the second non-security-level gateway according to the newly sent communication point table; obtaining the network data points and determining whether they match the receiver's communication point table; if yes, it is determined that the second non-security-level gateway's communication signal reception is normal, and the download operation continues; if no, a fault alarm signal is issued.
[0077] At this point, the current communication link is the second communication link. During the gateway upgrade download operation, in order to ensure uninterrupted communication between the security-level gateway and the non-security-level gateway, communication function verification is required. The download operation can only continue if the communication status of the second communication link is determined to be normal.
[0078] In an embodiment of the present invention, step S3 includes: S31: obtaining and creating a new receiver communication point table based on the sender communication point table from the first non-security level gateway; S32: downloading the new receiver communication point table to the first non-security level gateway and restarting it, and downloading the new overall project to the first security level gateway.
[0079] Specifically, at this time, the inter-DCS system gateway communication link is the second communication link, and the first communication link does not complete the inter-DCS system gateway communication temporarily, achieving the technical effect of uninterrupted DCS system gateway communication during the download process. Therefore, the new communication point table can be downloaded to the first security-level gateway and the first non-security-level gateway simultaneously; or, the new sender communication point table and the new software project can be downloaded to the first security-level gateway first, and then the new receiver communication point table can be downloaded to the first non-security-level gateway; or, the new receiver communication point table can be downloaded to the first non-security-level gateway first, and then the new sender communication point table and the new software project can be downloaded to the first security-level gateway. Figure 3 As shown, Figure 3 This is a schematic diagram of the gateway download status after step S3 is completed in the non-disruptive download method provided in this embodiment of the invention.
[0080] In an embodiment of the present invention, before executing step S4, the method further includes: obtaining the operating status of the first security-level gateway and the first non-security-level gateway after the download is completed; determining whether the operating status is normal; if yes, then continuing to execute step S4; if no, then issuing an alarm signal.
[0081] In embodiments of the present invention, the method further includes: obtaining the communication status of the current communication link; determining whether the communication status is normal; if so, allowing the download operation; if not, issuing a fault alarm signal; wherein the current communication link includes a first communication link and a second communication link. Specifically, during the download operation for gateway upgrade, in order to ensure uninterrupted communication between the security-level gateway and the non-security-level gateway, communication function verification is required, and the download operation can only be allowed to continue only when the communication status of the current communication link is normal.
[0082] In an embodiment of the present invention, step S4 further includes: obtaining the communication status of the first communication link after the switchover is completed; transmitting network data points to the first non-security-level gateway according to the newly sent communication point table; obtaining the network data points and determining whether they match the receiver's communication point table; if so, it is determined that the communication signal reception of the first non-security-level gateway is normal, and the download operation continues; if not, a fault alarm signal is issued. Specifically, at this time, the current communication link is the first communication link. During the download operation of the gateway upgrade, in order to ensure uninterrupted communication between the security-level gateway and the non-security-level gateway, communication function verification is required. The download operation can only be allowed to proceed when the communication status of the first communication link is normal.
[0083] In embodiments of the present invention, the download operation further includes: downloading the new software project to the first non-security level gateway and the second non-security level gateway after step S3 is completed; or, downloading the new software project to the first non-security level gateway and the second non-security level gateway after step S4 is completed. Figure 4 As shown, Figure 4 This is a schematic diagram showing the complete download status of the gateway in the non-disruptive download method provided in this embodiment of the invention.
[0084] Specifically, since the communication point table is primarily responsible for parsing data from security-level gateways, and software engineering involves performing corresponding calculations based on the parsed data from the communication point table, the key to communication between security-level and non-security-level gateways lies in the matching of their communication point tables. That is, only when the receiving communication point table matches the sending communication point table can the security-level gateway correctly parse network data sent to the non-security-level gateway for parsing, thus enabling gateway communication between DCS systems. Therefore, the download of the new software engineering for the non-security-level gateway can be performed after the new receiving communication point table has been downloaded to the first and second non-security-level gateways and is currently in communication on the first communication link; or after the new receiving communication point table has been downloaded to the first non-security-level gateway and is still in communication on the second communication link.
[0085] The download of the new software project for the non-security-level gateway is performed after the download of the new receiver's communication point table to the first and second non-security-level gateways is completed and communication is taking place on the first communication link; a specific embodiment of the present invention is as follows:
[0086] Step A11: The new sender communication point table is generated after the first security level gateway and the second security level gateway compile the new software engineering.
[0087] Step A12: The second non-security level gateway obtains and creates the receiver's communication point table according to the sender's communication point table;
[0088] Step A13: Obtain and determine whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal; if yes, allow the download operation; if no, stop the download operation and issue an alarm signal to confirm that the gateway is working normally.
[0089] Step A14: Download the new receiver communication point table to the second non-security level gateway and restart it, and download the new sender communication point table and the new software project to the second security level gateway;
[0090] Step A21: Obtain the running status of the second security-level gateway and the second non-security-level gateway after the download is completed, and determine whether the running status is normal; if yes, continue to perform the download operation; if no, issue an alarm signal.
[0091] Step A22: The first communication link between the first security-level gateway and the first non-security-level gateway is switched to the second communication link between the second security-level gateway and the second non-security-level gateway for communication;
[0092] Step A23: Obtain the communication status of the second communication link after the switchover is completed; transmit the network data points to the second non-security level gateway according to the newly sent communication point table;
[0093] Step A24: Obtain network data points and determine if they match the receiver's communication point table; if yes, determine that the second non-security level gateway communication signal reception is normal and continue the download operation; if no, issue a fault alarm signal.
[0094] Step A31: Obtain and create a new receiver communication point table from the first non-security level gateway based on the new sender communication point table;
[0095] Step A32: Download the new receiver communication point table to the first non-security level gateway and restart it. At the same time, download the new sender communication point table and the new software project to the first security level gateway.
[0096] Step A33: Obtain the running status of the first security-level gateway and the first non-security-level gateway after the download is completed, and determine whether the running status is normal; if yes, continue to perform the download operation; if no, issue an alarm signal.
[0097] Step A41: Switch from the second communication link to the first communication link for communication;
[0098] Step A42: Obtain the communication status of the first communication link after the switchover is completed; transmit the network data points to the first non-security level gateway according to the newly sent communication point table;
[0099] Step A43: Obtain network data points and determine whether they match the receiver's communication point table; if yes, determine that the first non-security level gateway communication signal reception is normal and continue the download operation; if no, issue a fault alarm signal.
[0100] Step A5: Simultaneously download the new software project to both the first non-security level gateway and the second non-security level gateway; complete the download and upgrade work for both the security level and non-security level gateways.
[0101] The download occurs when the download of the new software project of the non-security-level gateway is completed after the download of the new receiver's communication point table to the first non-security-level gateway is completed and communication is still taking place on the second communication link. Another specific embodiment of the present invention is as follows:
[0102] Step B11: The new sender communication point table is generated after the first security level gateway and the second security level gateway compile the new software engineering.
[0103] Step B12: The second non-security level gateway obtains and creates the receiver's communication point table according to the sender's communication point table;
[0104] Step B13: Obtain and determine whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal; if yes, allow the download operation; if no, stop the download operation and issue an alarm signal to confirm that the gateway is working normally.
[0105] Step B14: Download the new receiver communication point table to the second non-security level gateway and restart it, and download the new sender communication point table and the new software project to the second security level gateway;
[0106] Step B21: Obtain the running status of the second security-level gateway and the second non-security-level gateway after the download is completed, and determine whether the running status is normal; if yes, continue to perform the download operation; if no, issue an alarm signal.
[0107] Step B22: The first communication link between the first security-level gateway and the first non-security-level gateway is switched to the second communication link between the second security-level gateway and the second non-security-level gateway for communication;
[0108] Step B23: Obtain the communication status of the second communication link after the switchover is completed; transmit the network data points to the second non-security level gateway according to the newly sent communication point table;
[0109] Step B24: Obtain network data points and determine if they match the receiver's communication point table; if yes, determine that the second non-security level gateway communication signal reception is normal and continue the download operation; if no, issue a fault alarm signal.
[0110] Step B31: Obtain and create a new receiver communication point table from the first non-security level gateway based on the new sender communication point table;
[0111] Step B32: Download the new receiver communication point table to the first non-security level gateway and restart it. At the same time, download the new sender communication point table and the new software project to the first security level gateway.
[0112] Step B33: Obtain the running status of the first security-level gateway and the first non-security-level gateway after the download is completed, and determine whether the running status is normal; if yes, continue to execute the download operation; if no, issue an alarm signal.
[0113] Step B34: Simultaneously download the new software project to the first non-security level gateway and the second non-security level gateway; complete the download and upgrade of the new software project for the non-security level gateway.
[0114] Step B41: Switch from the second communication link to the first communication link for communication;
[0115] Step B42: Obtain the communication status of the first communication link after the switchover is completed; transmit the network data points to the first non-security level gateway according to the newly sent communication point table;
[0116] Step B43: Obtain network data points and determine if they match the receiver's communication point table; if yes, determine that the first non-security level gateway communication signal reception is normal and continue the download operation; if no, issue a fault alarm signal.
[0117] Step B5: Confirm that the download and upgrade of the new overall project for both security-level and non-security-level gateways is now complete.
[0118] The method for seamless downloading gateway communication between DCS systems of different safety levels according to the present invention can achieve seamless downloading of one-way communication gateways between safety-level and non-safety-level DCS systems in nuclear power plants. This avoids the impact on the safety of unit operation and control caused by the interruption of the original gateway communication function between the safety-level and non-safety-level DCS systems due to the mismatch between the new and old communication point tables during the gateway upgrade download process.
[0119] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.
[0120] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0121] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0122] The above embodiments are only for illustrating the technical concept and features of the present invention, and are intended to enable those skilled in the art to understand the content of the present invention and implement it accordingly. They do not limit the scope of protection of the present invention. All equivalent changes and modifications made within the scope of the claims of the present invention should fall within the scope of the claims of the present invention.
Claims
1. A method for seamless downloading data between gateways of DCS systems with different security levels, characterized in that, The method includes a download operation, which includes the following steps: S1: Obtain and download the new communication point table to the second non-security level gateway, and download the new overall project to the second security level gateway; the new overall project includes the new communication point table and the new software project. S2: The first communication link between the first security-level gateway and the first non-security-level gateway is switched to the second communication link between the second security-level gateway and the second non-security-level gateway for communication; S3: Download the new communication point table to the first non-security level gateway and download the new overall project to the first security level gateway; S4: Switch from the second communication link to the first communication link for communication; The first security-level gateway is connected to the first non-security gateway, and the second security gateway is connected to the second non-security-level gateway. The two gateways work independently and do not require data interaction.
2. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 1, characterized in that, The method also includes: Get the current communication status of the communication link; Determine if the communication status is normal; if yes, allow the download operation; if no, issue a fault alarm signal. The current communication link includes the first communication link and the second communication link.
3. The method for seamless downloading of data between DCS systems of different security levels according to claim 2, characterized in that, The new communication point table includes a new sender communication point table and a new receiver communication point table, and step S1 includes: S11: The new software project is compiled by the security-level gateway to obtain the new sender communication point table; wherein, the security-level gateway includes the first security-level gateway and the second security-level gateway; S12: The second non-security level gateway obtains and creates the new receiver communication point table according to the new sender communication point table; S13: Download the new receiver communication point table to the second non-security level gateway and restart it, and download the new overall project to the second security level gateway.
4. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 3, characterized in that, Step S12 includes: Obtain the offset address of the new sender's communication point table; The corresponding data is parsed from the offset address and assigned to the receiving communication point to create the new receiving communication point table.
5. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 4, characterized in that, The method also includes: The system acquires and determines whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal; if so, the download operation is allowed; if not, the download operation is stopped and an alarm signal is issued.
6. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 5, characterized in that, The step of acquiring and determining whether the monitoring status of the second non-security level gateway and the first non-security level gateway is normal also includes: Obtain the software engineering versions of the second non-security level gateway and the first non-security level gateway; Determine whether the software engineering versions are the same; if yes, determine that the monitoring status is normal; if no, determine that the monitoring status is abnormal.
7. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 6, characterized in that, Before performing step S2, the following also applies: Obtain the running status of the second security-level gateway and the second non-security-level gateway after the download is completed; Determine whether the operating status is normal; if yes, continue to execute step S2; if no, issue an alarm signal.
8. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 7, characterized in that, Step S2 includes: Obtain the communication status of the second communication link after the handover is completed; According to the new sender communication point table, the network data point is transmitted to the second non-security level gateway; The network data point is acquired and it is determined whether it matches the new receiver communication point table; if yes, it is determined that the second non-security level gateway communication signal reception is normal, and the download operation continues; if no, a fault alarm signal is issued.
9. The method for seamless downloading of data between DCS systems of different security levels according to claim 8, characterized in that, Step S3 includes: S31: The first non-security level gateway obtains and creates the new receiver communication point table based on the new sender communication point table; S32: Download the new receiver communication point table to the first non-security level gateway and restart it, and download the new overall project to the first security level gateway.
10. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 9, characterized in that, The download operation also includes: After step S3 is completed, the new software project is downloaded to the first non-security level gateway and the second non-security level gateway; or... After step S4 is completed, the new software project is downloaded to the first non-security level gateway and the second non-security level gateway.
11. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 10, characterized in that, Before performing step S4, the following also applies: Obtain the running status of the first security-level gateway and the first non-security-level gateway after the download is completed; Determine whether the operating status is normal; if yes, continue to execute step S4; if no, issue an alarm signal.
12. The non-intrusive download method for gateway communication between DCS systems of different security levels according to claim 11, characterized in that, Step S4 includes: Obtain the communication status of the first communication link after the handover is completed; According to the new sender communication point table, the network data point is transmitted to the first non-security level gateway; The network data point is acquired and it is determined whether it matches the receiver's communication point table. If it does, the communication signal reception of the first non-security gateway is determined to be normal, and the download operation is continued. If not, a fault alarm signal is issued.
Citation Information
Patent Citations
Nuclear safety level hot standby redundant control station undisturbed downloading method and system
CN109448880A