A DCS system safe starting method and system based on output signal checking
By pre-setting safe startup parameters in the DCS system, verifying and writing them into the forced table, the problem of mismatch between the output signal and the device status when the DCS system is powered on is solved, realizing safe startup and synchronization of the device, and improving the safety and reliability of the system.
Patent Information
- Application Number
- CN202310117773.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-15
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2043-02-15
AI Technical Summary
When the DCS system is powered on for the first time or after a power-on, the output signal may not match the status of the field equipment, which may lead to equipment malfunctions and pose safety hazards. Existing verification methods are inefficient and cannot effectively eliminate the risks.
By presetting safe startup parameters, the consistency between the output signal and the safe startup parameters is compared, and a forced table is written into the DCS historical station and the DPU local ROM. The forced signal channel is used to ensure the safety of the output signal, thereby realizing the verification and synchronization of the output signal.
When the DCS system is powered on, verification and synchronization output signals are used to ensure safe startup of the equipment, avoid equipment malfunctions, and improve the safety and reliability of the system.
Smart Images

Figure CN116300722B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of automatic control of thermal power plants, and particularly relates to a DCS system safe starting method and system based on output signal verification. BACKGROUND
[0002] As a control system of the production process of a thermal power plant, the DCS collects analog signals or switch signals output by sensors and operating equipment, automatically processes them through internal logic configuration, or manually judges and intervenes, and outputs control signals to an executing mechanism. When the field equipment is normally working and a reliable communication is established with the DCS, the change of the DCS output signal will directly affect the valve opening degree, the motor speed, the switch closing and other equipment states.
[0003] When the DCS is powered on for the first time or needs to be powered on again due to maintenance, reconstruction, tripping and other reasons, because of the discontinuity of the working conditions and the disappearance of part of the data stored in the RAM, the DCS has a probability to output unverified signals to the equipment. When the initialized output signal does not match the state of the field equipment, it is easy to cause the misoperation of the equipment, which may lead to the damage of the equipment and even personal injury, and has certain safety hazards. The traditional verification method is for engineers to judge the rationality of the output signal after power-on combined with experience and logic configuration, or to shield all outputs at the physical layer. Such methods are low in efficiency and cannot eliminate risks from the perspective of ensuring the safety of the unit and personnel, and there is room for optimization. SUMMARY
[0004] The purpose of the present application is to overcome the shortcomings of the prior art, and to provide a DCS system safe starting method and system based on output signal verification, so as to solve the problems of the mismatch between the output signal of the DCS and the state of the field equipment, the existence of errors, the risk of equipment operation and personnel safety in the prior art.
[0005] To achieve the above purpose, the following technical solutions are adopted:
[0006] A DCS system safe starting method based on output signal verification, comprising the following steps:
[0007] Step 1, presetting a safe starting parameter, comparing whether the output signal is consistent with the safe starting parameter, if yes, executing step 3, otherwise executing step 2; the safe starting parameter is preset and stored in the DCS history station and the DPU local ROM;
[0008] Step 2, writing the safe starting parameter into a forced table, setting the signal output by the DCS as the safe starting parameter through a forced signal channel; the forced table includes a DCS history station forced table and a DPU local ROM forced table;
[0009] Step 3, outputting the output signal or the safe starting parameter.
[0010] The further improvement of the present application is:
[0011] Preferably, in step 1, when the DCS history station and the DPU are in normal communication, the output signal is compared with the safety start parameter in the DCS history station; when the DCS history station and the DPU cannot communicate, the output signal is compared with the safety start parameter in the local ROM of the DPU.
[0012] Preferably, in step 2, when the DCS history station and the DPU are in normal communication, the safety start parameter is written into the forced table of the DCS history station.
[0013] Preferably, in step 2, when the DCS history station and the DPU cannot communicate, the safety start parameter is written into the forced table of the local ROM of the DPU.
[0014] Preferably, after step 3, when the DCS is in normal operation and the DCS and the DPU are in normal communication, the DCS history station and the DPU compare the data generation time through the log file, and respectively overwrite the data to the memory of the other party.
[0015] Preferably, after step 3, when the DCS history station and the DPU are in normal communication, the safety start parameter, the output signal and the safety start parameter consistency information, and the data of the forced table are stored in the DCS history station.
[0016] Preferably, after step 3, when the DCS history station and the DPU cannot establish communication, the safety start parameter, the output signal and the safety start parameter consistency information, and the data of the forced table are stored in the local ROM of the DPU.
[0017] Preferably, the output signal includes DO and AO.
[0018] Preferably, the output signal is generated by logic configuration and output by the board card downstream of the DPU.
[0019] A DCS system safety start system based on output signal verification, comprising:
[0020] A comparison module for presetting a safety start parameter, comparing whether the output signal is consistent with the safety start parameter, and if so, executing an output module, otherwise executing a forced writing module; the safety start parameter is preset to be stored in the DCS history station and the local ROM of the DPU;
[0021] A forced writing module for writing the safety start parameter into a forced table, and setting the signal output by the DCS as the safety start parameter through a forced signal channel; the forced table includes a forced table of the DCS history station and a forced table of the local ROM of the DPU;
[0022] An output module is configured to output an output signal or a safety start parameter.
[0023] Compared with the prior art, the present application has the following beneficial effects:
[0024] The application discloses a DCS system safety start method based on output signal verification, and comprises the following steps: firstly, setting the DPU output signal in the DCS system history station as a safety value that should be kept when powered on; secondly, according to the communication state of the history station and the DPU, verifying the consistency of the safety start parameter of the history station or the DPU local ROM and the output signal respectively, and recording the verification result; thirdly, recording the verification result as inconsistent, and writing the safety start parameter into the history station forced table or the DPU forced table according to the communication state; fourthly, taking the forced table as the basis, realizing that the signal sent by the card when powered on corresponds to the preset safety start parameter through the forced signal channel; and finally, synchronizing the history station safety start related data with the DPU local ROM. The method can verify the output signal when the DCS is powered on by setting the safety start parameter, and guarantees the safety start of the system. When the history station and the DPU cannot communicate, the DPU local ROM data can be called to execute the verification and the storage of related data. The method synchronizes the related data stored in the history station and the DPU local ROM after the output signal takes effect, and guarantees the real-time and redundancy of the data.
[0025] The application further discloses a DCS system safety start system based on output signal verification, which comprises a comparison module, a forced writing module and an output module. Firstly, the comparison module and the forced writing module are used to compare whether the output signal is consistent with the safety start parameter; if yes, the output signal can be normally output; if not, the safety start parameter is output through the forced table. The method considers both the normal communication and the abnormal communication of the DCS and the DPU, and guarantees the safety of the output signal. BRIEF DESCRIPTION OF DRAWINGS
[0026] Figure 1 The method flowchart is shown in the figure. DETAILED DESCRIPTION
[0027] The application will be further described in detail in combination with the drawings:
[0028] In the description of the present application, it should be noted that the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer" and the like indicate the orientation or positional relationship shown in the drawings, which are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application; the terms "first", "second", "third" are only for the purpose of description, and cannot be understood as indicating or implying relative importance; in addition, unless otherwise explicitly specified and limited, the terms "mounting", "connection", "connection" should be understood broadly, for example, it can be fixed connection, or detachable connection; it can be directly connected, or indirectly connected through an intermediate medium; it can be the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0029] The application discloses a DCS system safe starting method based on output signal checking, which firstly initializes the safe starting parameters in the DCS history station, that is, sets the safe values of all output signals such as DO and AO in the DCS system to be kept when the DCS is powered on, to ensure that the values will not cause equipment misoperation; then the host computer judges whether the communication between the history station and each DPU is normal, when the communication is normal, the safe starting parameters in the history station are checked with the output signals after the logic configuration is taken effect, and the consistency is judged, when the history station and the DPU cannot establish communication, the safe starting parameters in the local ROM of the DPU are checked with the output signals after the logic configuration is taken effect, and the consistency is judged; when the output signals and the safe starting parameters are inconsistent, the latter is used as the standard, and is written into the forced table one by one; then the safe starting parameters are used as the actual output signals, and are transmitted to the card through the DPU to send instructions to the controlled object; finally, when the DCS is normally operated, the safe starting related data in the history station is synchronized with the local ROM of the DPU, and the local and host computer redundant storage of data is realized. The method avoids the influence caused by communication abnormity by presetting the safe starting parameters, using the DPU and the history station redundant storage, checking the output signals when the power is turned on, realizing the safe starting of the DCS system, and ensuring the safety of the unit equipment and personnel.
[0030] The DPU of the present application is a distributed processing unit, which belongs to the DCS system together with the DCS history station, and is part of the DCS system, and a plurality of card plates are connected downstream of the DPU for output signals.
[0031] A DCS system safe starting method based on output signal checking, referring to Figure 1 , comprising the following steps:
[0032] Step 1: safe starting parameter initialization.
[0033] The safe starting parameter is a safe value of an output signal of the DCS system when the DCS system is powered on, and the value cannot cause the output instruction to jump or the controlled equipment to malfunction. The safe starting parameter corresponding to all output signals is manually set in the DCS history station by engineers according to the production process and the specific analysis of the site conditions, and is saved after being confirmed to complete the initialization. When the history station and the DPU communicate normally, the history station automatically synchronizes the safe starting parameter to the local ROM of the DPU.
[0034] Step 2, it is judged whether the history station and the DPU communicate normally, if yes, step 3 is executed, if not, step 4 is executed.
[0035] Step 3, the DCS system generates output signals according to the logic configuration, and the output signals are output from the card board downstream of the DPU; when the DCS history station and the DPU communicate normally, the consistency of the output signals generated by the logic configuration and the safe starting parameter in the history station is checked one by one, and the consistent check record is recorded; when the consistency is consistent, the output signals are output from the card board downstream of the DPU; when the consistency is inconsistent, the safe starting parameter is written into the forced table record of the DCS history station, and then step 5 is executed.
[0036] Step 4, when the DCS history station and the DPU cannot establish communication, the consistency of the output signals generated by the logic configuration and the safe starting parameter stored in the local ROM of the DPU is checked one by one, and the consistent check record is recorded; when the consistency is consistent, the output signals of the card board downstream of the DPU; when the consistency is inconsistent, the safe starting information is written into the local ROM forced table, and then step 5 is executed.
[0037] Step 5, according to the DCS history station forced table or the local ROM forced table, the safe starting parameter is realized as an actual output signal through a forced signal channel, and the electrical signal sent by the card when the DCS is powered on corresponds to the preset safe starting parameter.
[0038] Step 6, the history station and the DPU data are synchronized.
[0039] The safe starting parameter, the output signal, the safe starting parameter consistency information and the related data of the forced table are stored in the history station or the DPU according to different communication conditions. When the DCS normally operates and the communication is normal, the history station and the DPU compare the data generation time through the log file to overwrite the latest data to the storage of the other party.
[0040] In order to realize the above process, the application further discloses a system for realizing the above process, and the system comprises:
[0041] A comparison module is used for presetting a safe starting parameter, comparing whether the output signal is consistent with the safe starting parameter, executing an output module if the output signal is consistent with the safe starting parameter, or executing a forced writing module if the output signal is inconsistent with the safe starting parameter; the safe starting parameter is preset to be stored in the DCS history station and the local ROM of the DPU.
[0042] Forcing writing module, for writing the safe start parameter into the forcing table, setting the signal of DCS output through the forcing signal channel as the safe start parameter; the forcing table includes DCS history station forcing table and DPU local ROM forcing table;
[0043] Output module, for outputting the output signal or the safe start parameter.
[0044] The working principle of the present application is as follows:
[0045] The internal logic configuration of the DCS system is effective when power on, and the output card sends control signals to the equipment through the cable, at this time, the output signal is difficult to check one by one and the rationality is highly dependent on the current working condition. The engineers set the safe start parameter in the history station from the safety point of view, and compare and check the output signal in batch with the logic configuration, to realize the safe start of DCS and unit in the way of forcing channel.
[0046] When the DPU is powered on and the history station and the DPU communicate normally, the consistency of the output signal and the safe start parameter is checked, and the parameter writing into the forcing table is completed in the history station, and the consistency record and the forcing table are stored in the history station; when the DPU is powered on and the history station and the DPU cannot establish communication, only the consistency check and the forcing work are performed by the DPU, and the consistency record and the forcing table are temporarily stored in the local ROM of the DPU. After the above work is completed, the output card and each channel send signals to the equipment based on the forcing table and the safe start parameter.
[0047] After the power-on process is completed, the data in the history station and the local ROM of the DPU may be out of synchronization due to communication problems, and the related data of the DCS system safe start process needs to consider the timeliness, when the communication is established, the data in the history station and the local ROM of the DPU need to be synchronized periodically automatically or manually, so that the latest safe start parameter, consistency information and forcing table can be queried by engineers in the human-computer interaction interface, to provide data support for the next power-on DCS system safe start.
[0048] The above only describes the preferred embodiments of the present application and does not limit the present application, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A safe startup method for a DCS system based on output signal verification, characterized in that, Includes the following steps: Step 1: Preset the safe boot parameters, compare the output signal with the safe boot parameters. If they match, proceed to Step 3; otherwise, proceed to Step 2. The safe boot parameters are preset and stored in the DCS historical station and the DPU local ROM. In step 1, when the DCS historical station and DPU communicate normally, the output signal is compared with the safe boot parameters in the DCS historical station; when the DCS historical station and DPU cannot communicate, the output signal is compared with the safe boot parameters in the DPU's local ROM. Step 2: Write the safe startup parameters into the forced table, and set the signal output by DCS as the safe startup parameters through the forced signal channel; the forced table includes the DCS historical station forced table and the DPU local ROM forced table; Step 3: Output the output signal or safety start parameters; After step 3, when the DCS is running normally and the communication between the DCS and DPU is normal, the DCS historical station and the DPU compare the data generation time through the log file and write the data to each other's memory respectively.
2. The DCS system safe startup method based on output signal verification according to claim 1, characterized in that, In step 2, when the DCS historical station and DPU communicate normally, the safe startup parameters are written to the DCS historical station forced table.
3. The DCS system safe startup method based on output signal verification according to claim 1, characterized in that, In step 2, when the DCS historical station and DPU cannot communicate, the safe boot parameters are written to the DPU local ROM forced table.
4. The DCS system safe startup method based on output signal verification according to claim 1, characterized in that, After step 3, when the DCS historical station and DPU communicate normally, the safety start parameters, the consistency information between the output signal and the safety start parameters, and the data of the forced table are stored in the DCS historical station.
5. A DCS system safe startup method based on output signal verification according to claim 1, characterized in that, After step 3, when the DCS historical station and DPU cannot establish communication, the safety startup parameters, the consistency information between the output signal and the safety startup parameters, and the data of the forced table are stored in the DPU's local ROM.
6. A DCS system safe startup method based on output signal verification according to claim 1, characterized in that, The output signals include DO and AO.
7. The DCS system safe startup method based on output signal verification according to any one of claims 1-6, characterized in that, The output signal is generated by the logic configuration and output by the board downstream of the DPU.
8. A DCS system safe startup system based on output signal verification for implementing the method of claim 1, characterized in that, include: The comparison module is used to preset the safe boot parameters and compare the output signal with the safe boot parameters. If they are consistent, the output module is executed; otherwise, the forced write module is executed. The secure boot parameters are preset and stored in the DCS historical station and the DPU local ROM; The forced write module is used to write the safe boot parameters into the forced table and set the signal output by DCS as the safe boot parameters through the forced signal channel; the forced table includes the DCS historical station forced table and the DPU local ROM forced table; Output module, used to output output signals or safety start parameters.
Citation Information
Patent Citations
Black-start self-excitation checking device and method
CN112505544A
Safety device and safety method for monitoring system startup
JP2020173806A