A method and system for safe switching of a utility system

By introducing a two-level safety control mechanism into the public system, the problem of control command conflicts caused by the simultaneous operation of multiple unit units was solved, thereby improving the system's safety and control accuracy.

CN116628678BActive Publication Date: 2025-12-12NANJING GUODIAN NANZI WEIMEIDE AUTOMATION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310420034.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-19
Publication Date
2025-12-12
Estimated Expiration
2043-04-19

AI Technical Summary

Technical Problem

The simultaneous operation of public system equipment by multiple unit machines at the same time increases the probability of misoperation, leading to control command conflicts and affecting the safety of equipment or unit operation.

Method used

A two-level security control mechanism is adopted, with the HMI security module and the controller security module respectively judging and verifying the operator's identity and permissions to ensure that only the unit with the security access password can issue control commands.

Benefits of technology

It improves the security and control precision of public systems, reduces the probability of misoperation, and ensures efficient and accurate equipment control in emergency situations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116628678B_ABST
    Figure CN116628678B_ABST
Patent Text Reader

Abstract

The application discloses a public system safety switching method and system, and the method comprises the following steps: instantiating a total safety switching order application plug-in in all public system pictures in a unit generator set; the total safety switching order application plug-in judges whether the public system has a safety switching order by triggering a first safety application rule; the first safety application rule judges by associating picture attributes; instantiating a sub-safety switching order application plug-in in a public system picture in the unit generator set; the sub-safety switching order application plug-in judges whether the picture has a safety switching order by triggering a second safety application rule; and the second safety application rule judges by associating signal attributes. The application applies and releases the safety switching order in a two-stage control mode, adds two safety barriers for the public system, and improves the safety; and the combination of the total control and the sub-control makes the control more accurate.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of power monitoring, in particular to a public system safe switching method and system. BACKGROUND

[0002] With the development of enterprises and economic life, higher requirements are put forward for the self-control level of power production in the field of power monitoring, and the monitoring system is a comprehensive system for data acquisition, monitoring and control of equipment distributed over a long distance and scattered in production. In the monitoring system, in addition to the independent configuration of the furnace, machine, and electric system and the unit set of equipment, in order to save costs, public systems that serve two unit sets or multiple unit sets at the same time are also divided. The public system also has its own furnace, machine, and electric system and equipment, and the difference between the unit and the public system is that the equipment in the unit set can only be operated by the unit set, while the equipment of the public system can be operated by multiple sets according to the specific configuration.

[0003] However, the simultaneous operation of a device of the public system by multiple unit sets at the same time increases the probability of misoperation, thereby increasing the risk of the system. In the prior art, each unit has control authority over the public system equipment, and each unit has the authority to operate the equipment at any time. If there is no communication between the two units, it is likely that the control instructions for the public system equipment will conflict, causing the equipment to move frequently and affecting the operation of the equipment or the unit. In particular, in the case of special operation of the unit or the need for emergency operation of the equipment, the determination of control authority is particularly important. If the authority of the unit is not allocated and there is no automatic locking, the current equipment may be operated and controlled by other units, resulting in conflicts in operation and poor safety. SUMMARY

[0004] In view of the above existing problems, the present application is proposed.

[0005] Therefore, the present application provides a public system safe switching method to solve the problem that a device of the public system is simultaneously operated by multiple unit sets at the same time, increasing the probability of misoperation, causing conflicts in control instructions for the public system equipment, and causing the equipment to move frequently, thereby affecting the operation of the equipment or the unit.

[0006] To solve the above technical problems, the present application provides the following technical solutions:

[0007] In a first aspect, the present application provides a public system safe switching method, comprising:

[0008] Instantiating a total safety access request plug-in in all public system pictures in the unit set;

[0009] The total safety access order enables the application plug-in to judge whether the public system safety access order is available by triggering the first safety application rule;

[0010] The first safety application rule judges by associating the picture attribute;

[0011] A sub-safety access order application plug-in is instantiated in a public system picture in a unit set;

[0012] The sub-safety access order application plug-in judges whether the picture has the public system safety access order by triggering the second safety application rule;

[0013] The second safety application rule judges by associating the signal attribute.

[0014] As a preferred scheme of the public system safety switching method, the first safety application rule judges by associating the picture attribute, including,

[0015] Triggering a safety access order application signal;

[0016] Obtaining parent window information, judging whether it is a bottom picture by the parent window type; if not, obtaining the parent window information of the parent window again and obtaining the window type thereof; if it is a bottom picture, obtaining the bottom picture object number;

[0017] Obtaining all information in the exclusion list by the bottom picture object number and the exclusion list attribute type;

[0018] Judging whether the exclusion list contains the safety access order, if yes, the application is successful, and "the safety access order is available" is displayed; if not, the application fails, and "the safety access order is not available" is displayed;

[0019] The safety order application process occurs on a workstation, and after a certain monitoring picture application or discards the safety access order of the public system, other workstations of the unit set are also effective.

[0020] As a preferred scheme of the public system safety switching method, the first safety application rule judges by associating the picture attribute, including,

[0021] An analog quantity function block is established in each controller, a label name tId is set, and two attributes InCtl and Out are created;

[0022] The tId.InCtl attribute is associated with a remote point in a configuration library as a storage quantity, and the tId.Out attribute is associated with a remote point; the tId.Out attribute takes a value of [0, m], and m>=1, wherein 0 represents that all units do not have a safety entry order, and m represents that the mth unit has a safety entry order;

[0023] A global unit number tNo is configured, and each communication unit of the public system is configured with two system reserved variables with fixed names.

[0024] As a preferred scheme of the public system safety switching method, the second safety application rule is judged by associating a signal attribute, including,

[0025] A safety order application signal is triggered, and the tId.Out value of the controller and the current unit number tNo are read from a real-time library;

[0026] When the tId.Out of all public system controllers is 0, the safety order application plug-in displays "no unit occupies the safety entry order of the public system controller".

[0027] If the tId.Out is 0, the safety entry order is allowed to be obtained, and the tId.InCtl value is set to the current unit number, so that the safety entry order of the unit is obtained, and it is judged that the order application is successful; otherwise, "the public system safety entry order cannot be obtained" is displayed, and the safety order application signal is invalid at this time;

[0028] If the tId.Out is not 0, it is judged whether the tId.Out value is equal to the unit number tNo value;

[0029] If the tId.Out value of the controller is consistent with the current unit number tNo, the safety order application is successful, "the safety entry order is possessed" is displayed, the safety order application signal is triggered again, and the value of tId.InCtl is set to 0, at this time, the safety entry order of the unit is discarded;

[0030] If the tId.Out value of the controller is not consistent with the current unit number tNo, "the safety entry order is not possessed" is displayed.

[0031] As a preferred scheme of the public system safety switching method, the second safety application rule is judged by associating a signal attribute, including,

[0032] The instruction output includes a first instruction output, and the first instruction output is applied to a total safety entry order application plug-in.

[0033] The first instruction output comprises starting an instruction issuing operation after triggering a first safety application rule, and if the exclusion list contains a public system safety switching instruction, the instruction issuing is allowed; otherwise, the instruction issuing is prohibited.

[0034] As a preferred scheme of the public system safety switching method, the method further comprises, after judging that the public system safety switching instruction is available, performing an instruction output, wherein the instruction output further comprises a second instruction output, and the second instruction output is applied to a safety switching instruction application plug-in.

[0035] The second instruction output comprises, after triggering a second safety application rule,

[0036] The instruction issuing operation is started, and the value of tId.Out of the controller is read from a real-time library.

[0037] If tId.Out is 0, the safety switching instruction is unavailable, and the instruction issuing is prohibited.

[0038] If tId.Out is not 0, the current unit number tNo of the controller is read from the real-time library.

[0039] The value of tId.Out of the controller is compared with the current unit number tNo, if the value of tId.Out is inconsistent with tNo, the safety switching instruction is unavailable, and the instruction issuing is prohibited.

[0040] If the value of tId.Out of the controller is consistent with the current unit number tNo, the instruction issuing can be performed.

[0041] As a preferred scheme of the public system safety switching method, the safety switching instruction comprises an operator, a key, a unit number and a safety level.

[0042] When the safety switching instruction application signal is triggered, the operator is subjected to a first verification, and the first verification comprises that when the key and the operator are matched and the safety switching instruction application authority is in the authority list of the operator, the application is allowed.

[0043] When the instruction issuing operation is started, the associated control type is acquired, and then the second verification of the instruction issuer is performed, and the second verification comprises that when the key and the instruction issuer are matched, the authority list of the instruction issuer is acquired, if the control type is in the authority list of the instruction issuer, the instruction issuing is performed.

[0044] The unit number is a unique identification code of each unit.

[0045] The security level is the security level of each unit machine group when controlling the public system, each unit machine group has one and different security level, when the security access order conflicts, the conflict is solved by the additional security level information, the valid applicant is selected, and the other applicants will fail.

[0046] In a second aspect, the present application provides a public system security switching system, comprising,

[0047] The first instruction instantiation module is configured to instantiate a total security access order application plug-in in all public system screens in the unit machine group.

[0048] The first order application module is configured to determine whether the public system security access order is available by triggering the first security application rule through the total security access order application plug-in.

[0049] The HMI security module is configured to determine by the first security application rule through the associated screen attribute.

[0050] The second instruction instantiation module is configured to instantiate a sub-security access order application plug-in in one public system screen in the unit machine group.

[0051] The second order application module is configured to determine whether the screen has the public system security access order by triggering the second security application rule through the sub-security access order application plug-in.

[0052] The controller security module is configured to determine by the second security application rule through the associated signal attribute.

[0053] In a third aspect, the present application provides a computing device, comprising:

[0054] A memory and a processor.

[0055] The memory is configured to store computer executable instructions, and the processor is configured to execute the computer executable instructions, so as to realize the steps of the public system security switching method.

[0056] In a fourth aspect, the present application provides a computer readable storage medium, which stores computer executable instructions, and the computer executable instructions are executed by the processor to realize the steps of the public system security switching method.

[0057] Compared with the prior art, the application has the beneficial effects that: by means of two-stage control of the HMI safety module and the controller safety module, the HMI safety module and the controller safety module both need to apply for and release a safety password, two safety barriers are added for device monitoring and control of the public system, and the safety of the whole system is improved; by means of combination of the master control and the sub-control, the control is more accurate, and the accuracy of the control is improved as a whole through different operation resolutions; the safety password application logic and the control instruction issuing logic reduce the coupling with the system. BRIEF DESCRIPTION OF DRAWINGS

[0058] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort on the basis of these drawings.

[0059] Figure 1 The whole flowchart of the public system safety switching method according to an embodiment of the present application;

[0060] Figure 2 The first safety application rule flowchart in the public system safety switching method according to an embodiment of the present application;

[0061] Figure 3 The first instruction output flowchart in the public system safety switching method according to an embodiment of the present application;

[0062] Figure 4 The second safety application rule flowchart in the public system safety switching method according to an embodiment of the present application;

[0063] Figure 5 The second instruction output flowchart in the public system safety switching method according to an embodiment of the present application;

[0064] Figure 6 The system module schematic diagram in the public system safety switching method according to an embodiment of the present application. DETAILED DESCRIPTION

[0065] In order to make the above purposes, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings in the specification. Obviously, the described embodiments are only some embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort should be within the protection scope of the present application.

[0066] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present application. However, it will be apparent to one skilled in the art that the present application can be practiced without the specific details set forth in this description. In other instances, well-known methods, procedures, components, and circuits have not been described in detail so as not to unnecessarily obscure aspects of the present application.

[0067] Secondly, the "one embodiment" or "an embodiment" referred to herein means containing a specific feature, structure, or characteristic in at least one implementation of the present application. The "in one embodiment" appearing in different places in the specification does not mean the same embodiment, nor is it an embodiment that is independent of or mutually exclusive with other embodiments.

[0068] The present application is described in detail below in conjunction with the schematic drawings, and in the detailed description of the embodiments of the present application, the sectional view of the device structure is partially enlarged without the general proportion for the convenience of illustration, and the schematic drawings are only examples, which should not limit the scope of protection of the present application herein. In addition, the three-dimensional spatial dimensions of length, width and depth should be included in actual production.

[0069] Meanwhile, in the description of the present application, it should be noted that the orientation or position relationship indicated by the terms "up, down, inner and outer" is based on the orientation or position relationship shown in the drawings, and is only for the convenience of describing the present application and simplifying the description, and does not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. In addition, the terms "first, second or third" are only for descriptive purposes and cannot be understood as indicating or implying relative importance.

[0070] In the present application, unless otherwise explicitly specified and limited, the terms "mounting, connection, and connection" should be understood broadly, for example: it can be fixed connection, detachable connection or integral connection; it can also be mechanical connection, electrical connection or direct connection, it can also be indirectly connected through an intermediate medium, or it can be the communication between two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0071] Embodiment 1

[0072] Reference Figures 1-6 For an embodiment of the present application, a public system safety switching method is provided, comprising:

[0073] The first kind is:

[0074] The total safety access order application plug-in is instantiated in all public system screens in the unit set;

[0075] The total safety access order application plug-in determines whether the public system safety access order is available by triggering the first safety application rule.

[0076] The first security application rule judges by associating the picture attribute;

[0077] Further, the first security application rule judges by associating the picture attribute, comprising,

[0078] Triggering the security access portal order application signal;

[0079] Obtaining the parent window information, judging whether it is a bottom picture by the parent window type; if not, obtaining the parent window information of the parent window again and obtaining the window type thereof; if it is a bottom picture, obtaining the bottom picture object number;

[0080] Obtaining all information in the exclusion list by the bottom picture object number and the exclusion list attribute type;

[0081] Judging whether the exclusion list contains the security access portal order, if yes, the application is successful, and “possessing the security access portal order” is displayed; if not, the application fails, and “not possessing the security access portal order” is displayed;

[0082] The security order application process occurs on a workstation, and after a certain monitoring picture applies or discards the security access portal order of the public system, other workstations of the unit machine group are also effective.

[0083] Further, it also includes, after judging that the public system security access portal order is possessed, performing the instruction output;

[0084] The instruction output includes the first instruction output, and the first instruction output is applied to the total security access portal order application plug-in;

[0085] The first instruction output includes, after triggering the first security application rule, starting the instruction issuing operation, if the exclusion list contains the public system security access portal order, allowing the instruction issuing; otherwise, prohibiting the instruction issuing.

[0086] It should be noted that when the security access portal order of all public system pictures or controllers needs to be obtained, the first security application rule is triggered, and after the application is successful, all monitoring pictures and controllers of the public system in the local machine group can be operated to achieve the purpose of one-key control of the whole system, so as to efficiently apply the security access portal order and control instruction issuing in an emergency.

[0087] The second kind:

[0088] Instantiating a sub-security access portal order application plug-in in a public system picture in the unit machine group;

[0089] Further, the first security application rule judges by associating the picture attribute, comprising,

[0090] An analog function block is established in each controller, a tag name tId is set, and two attributes InCtl and Out are created;

[0091] The tId.InCtl attribute is associated with a remote point in the configuration library as a storage quantity, and the tId.Out attribute is associated with a remote measurement point; the tId.Out attribute takes a value of [0, m], m≥1, wherein 0 indicates that all units do not have a safety access order, and m indicates that the mth unit has a safety access order;

[0092] A global unit number tNo is configured, and each communication unit of the public system is configured with two system reserved variables with fixed names.

[0093] The safety access order application plug-in determines whether the screen has a public system safety access order by triggering the second safety application rule;

[0094] The second safety application rule is determined by associating a signal attribute.

[0095] Further, the second safety application rule is determined by associating a signal attribute, including,

[0096] The safety order application signal is triggered, and the tId.Out value of the controller and the current unit number tNo are read from the real-time library;

[0097] When the tId.Out of all public system controllers is 0, the safety order application plug-in displays “no unit occupies the safety access order of the public system controller”;

[0098] If tId.Out is 0, the safety access order is allowed to be obtained, and the tId.InCtl value is set to the current unit number, so that the safety access order of the unit is obtained, and it is determined that the order application is successful; otherwise, “the public system safety access order cannot be obtained” is displayed, and the safety order application signal is invalid at this time;

[0099] If tId.Out is not 0, it is determined whether the tId.Out value is equal to the unit number tNo value;

[0100] If the tId.Out value of the controller is consistent with the current unit number tNo, the safety order application is successful, “has a safety access order” is displayed, and the safety order application signal is triggered again, the value of tId.InCtl is set to 0, and at this time the unit discards the safety access order;

[0101] If the tId.Out value of the controller is not consistent with the current unit number tNo, “does not have a safety access order” is displayed.

[0102] Further, the method further comprises, after determining that the public system safety access password is correct, outputting a command, wherein the outputting the command comprises outputting a second command, and the second command is applied to the safety access password application plug-in of the sub-controller;

[0103] The second command comprises, after triggering a second safety application rule,

[0104] The starting command is sent, and the value of tId.Out of the controller is read from the real-time library;

[0105] If tId.Out is 0, the safety access password is not correct, and the sending of the command is prohibited;

[0106] If tId.Out is not 0, the current unit number tNo of the controller is read from the real-time library;

[0107] The value of tId.Out of the controller is compared with the current unit number tNo, if the value of tId.Out is inconsistent with tNo, the safety access password is not correct, and the sending of the command is prohibited;

[0108] If the value of tId.Out of the controller is consistent with the current unit number tNo, the sending of the command is allowed.

[0109] It should be noted that the second command is output in the editing state to configure a certain picture or controller as a controlled object, and after triggering an application signal in the running state, the corresponding picture or controller is operated according to the bound control object, so that the control is more accurate; after the password application is successful, the control plug-in allows the sending of the command.

[0110] It should be noted that two safety application rules are used to implement the unit group access and removal of the public system, and two safety barriers are added for the monitoring and control of the devices of the public system, thereby improving the safety of the whole system.

[0111] The combination of the master control and the sub-control is used, the total safety access password application plug-in is responsible for the permission and interruption of the sending of the command of the controller command output plug-in, and the sub-safety access password application plug-in is responsible for the permission and interruption of the sending of the command of the controller command output module. When the safety access password of all public system pictures or controllers is needed, the total safety access password application plug-in is triggered, and after the application is successful, the unit group can operate all the monitoring pictures and controllers of the public system to achieve the purpose of one-key control of the whole system, thereby facilitating the efficient application of the safety access password and the sending of the control command in an emergency. In the editing state, the sub-safety access password application plug-in configures a certain picture or controller as a controlled object, and in the running state, the corresponding picture or controller is operated according to the bound control object after triggering an application signal, so that the control is more accurate, and the accuracy of the control is improved through different operation resolutions.

[0112] Further, in the above two ways:

[0113] All security access codes include operators, keys, unit numbers and security levels;

[0114] When triggering the security access code application signal, the first verification of the operator is performed, which includes allowing the application when the key and the operator match and the security access code application permission is in the operator's permission list;

[0115] When starting the instruction issuing operation, the associated control type is first obtained, and then the second verification of the instruction issuer is performed, which includes obtaining the permission list of the instruction issuer when the key and the instruction issuer match, and if the control type is in the permission list of the instruction issuer, the instruction issuing is run.

[0116] The unit number is the unique identification code of each unit;

[0117] The security level is the security level of each unit when controlling the public system, and each unit has one and different security level. When the security access code application conflicts, the conflict is solved by sending additional security level information to select the valid applicant, and the other applicants will fail.

[0118] If the password application fails or is released and is in the tripped state, the instruction cannot be issued, and at this time it is in the locked state.

[0119] It should be noted that the security password application logic and the instruction issuing logic use the plugin design mode, which flexibly selects the preset information machine and function, reduces the coupling with the system, decouples the plugin code and the system code in engineering, can be developed independently, and isolates the complexity of the internal logic of the framework from the developer; The unique design of the security access code uses a user key and a unit number security level double identity verification strategy. When triggering the security access code application, the identity of the operator needs to be verified first, the key and the operator match, and the security access code application permission is in the operator's permission list, then the application is allowed, and under the condition of allowing the application, when the security password application flow control instruction issuing operation is executed, the associated control type needs to be obtained first, the control type is pre-configured in the editing state, then the identity of the instruction issuer is verified, the key and the instruction issuer match, the permission list of the instruction issuer is obtained, and if the above control type is in the permission list of the instruction issuer, the instruction issuing is run; When the security access code application conflicts, the conflict is solved by sending additional security level information to select the valid applicant.

[0120] As a preferred mode, further comprising, after the password application is successful, performing picture configuration, and the picture configuration is to select whether to enable the public system controller safety switching function in the control instruction output plug-in editing state in the interactive interface.

[0121] The public system safety switching system in the embodiment comprises:

[0122] The first instruction instantiation module is configured to instantiate a total safety throw password application plug-in in all public system pictures in the unit machine group.

[0123] The first password application module is configured to enable the total safety throw password application plug-in to determine whether the public system safety throw password is available by triggering the first safety application rule.

[0124] The HMI safety module is configured to enable the first safety application rule to determine by associating picture attributes.

[0125] The second instruction instantiation module is configured to instantiate a separate safety throw password application plug-in in one public system picture in the unit machine group.

[0126] The second password application module is configured to enable the separate safety throw password application plug-in to determine whether the picture has the public system safety throw password by triggering the second safety application rule.

[0127] The controller safety module is configured to enable the second safety application rule to determine by associating signal attributes.

[0128] It should be noted that the first password application module and the second password application module can only be instantiated in the public system HMI, and the first password application module after instantiation comprises an editing state and a running state,

[0129] The total safety password application plug-in comprises all controller settings of control objects, password state description information configuration in the editing state.

[0130] The total safety password application plug-in comprises all controller password acquisition and information display functions in the running state.

[0131] The second password application module comprises selection of a single control object controller, password state description information setting in the editing state.

[0132] The second password application module comprises single controller password acquisition and information display in the running state.

[0133] As an implementable mode, the instruction output module can further comprise a first instruction output module configured to perform first instruction output after determining that the public system safety throw password is available, and a second instruction output module configured to perform second instruction output after determining that the public system safety throw password is available.

[0134] The instruction output module is responsible for the capture and display of remote signaling and telemetry signals, and the issuing of remote control and remote control instructions. The instruction output module is divided into an editing mode and a running mode. In the editing mode, configuration can be performed, including the description of the issued instructions, whether to perform secondary confirmation, the setting of background colors and feedback signal colors, the association of control device measurement points and feedback signal points, and the association of device measurement points and four-remote points. The device measurement points are divided into model points and four-remote points. The model points are used for indirect transmission of information on the pop-up screen of the HMI.

[0135] As a preferred mode, the controller execution module can also be included, which is a logic algorithm execution component that completes the logic operation and processing function of the device through the simulation of the measurement points.

[0136] As a preferred mode, the measurement point device can also be included, which is a sensor that converts the measured information on site into a usable signal according to a certain rule, and a movable actuator, and the like.

[0137] It should be noted that the logic block diagram of the two safety input ports in the embodiment is as shown in Figure 5 The functions are realized by the first password application module, the second password application module, the first instruction instantiation module, the second instruction instantiation module, the first instruction output module, the second instruction output module, the HMI safety module, the controller safety module, and the controller execution module.

[0138] The first password application module is responsible for the permission and cutting off of the issuing of instructions by the first instruction instantiation module of all controllers. The second password application module is responsible for the permission and cutting off of the issuing of instructions by the second instruction instantiation module of each controller.

[0139] The embodiment also provides a computing device suitable for the safety switching of public systems, which comprises:

[0140] The memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize the method for implementing the safety switching of public systems proposed in the above embodiment.

[0141] The embodiment also provides a storage medium having a computer program stored thereon. When the program is executed by a processor, the method for implementing the safety switching of public systems proposed in the above embodiment is realized.

[0142] The storage medium proposed in the embodiment belongs to the same inventive concept as the method for implementing the safety switching of public systems proposed in the above embodiment. Technical details not described in detail in the embodiment can be referred to the above embodiment, and the embodiment has the same beneficial effects as the above embodiment.

[0143] Through the above description of the embodiments, those skilled in the art can clearly understand that the present application can be realized by means of software and necessary general hardware, and of course can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, and the computer software product can be stored in a computer readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a FLASH memory, a hard disk, or an optical disc, etc., and includes a number of instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods of various embodiments of the present application.

[0144] Embodiment 2

[0145] Referring to Table 1, a public system safety switching method is provided for an embodiment of the present application, and in order to verify the beneficial effects, the comparison results of two schemes are provided.

[0146] Table 1 Comparison test

[0147]

[0148] As can be seen from the above Table 1, the traditional scheme has fewer control levels, which is difficult to adapt to different control requirements, and the password logic is simple and the security is insufficient. By using the scheme of the present application, the controllable granularity is reduced to one screen and one controller on the basis of increasing the security by 50%, so that the control range is reduced while the non-conflict control is achieved, and the precise control is achieved.

[0149] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not limited. Although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present application, and all should be covered in the scope of the claims of the present application.

Claims

1. A method for safe switching of a utility system, characterized in that The application relates to a total safety access password application plug-in, a sub-safety access password application plug-in and a safety password application process. The total safety access password application plug-in is instantiated in all common system pictures in a unit group, and judges whether the common system safety access password is applicable by triggering a first safety application rule. The first safety application rule judges by associating picture attributes, including: Triggering a safety access password application signal; Obtaining parent window information, judging whether the parent window is a bottom picture by the parent window type; if not, obtaining the parent window information of the parent window again and obtaining the window type; if yes, obtaining the bottom picture object number; Obtaining all information in an exclusion list by the bottom picture object number and the exclusion list attribute type; Judging whether the exclusion list contains the safety access password; if yes, the application is successful, and "safety access password is applicable" is displayed; if not, the application fails, and "safety access password is not applicable" is displayed; The safety password application process occurs on a workstation, and after a certain monitoring picture applies or discards the safety access password of the common system, other workstations in the current unit group are also effective; A sub-safety access password application plug-in is instantiated in a common system picture in a unit group, including: A simulated quantity function block is established in each controller, a label name tId is set, and two attributes InCtl and Out are created; A global unit group number tNo is configured, and two system reserved variables are configured in each common system communication unit, and the names are fixed; The sub-safety access password application plug-in judges whether the current picture has the safety access password of the common system by triggering a second safety application rule. The second safety application rule judges by associating signal attributes, including: Triggering a safety password application signal, reading the tId.Out value of the controller and the current unit group number tNo from a real-time library; When the tId.Out of the safety password application plug-in in all common system controllers is 0, "no unit occupies the safety access password of the common system controller" is displayed; If the tId.Out is 0, the safety access password is allowed to be obtained, the tId.InCtl value is set as the current unit group number, the safety access password of the current unit group is obtained, and the password application is judged to be successful; otherwise, "the safety access password of the common system cannot be obtained" is displayed, and the safety password application signal is invalid; If the tId.Out is not 0, it is judged whether the tId.Out value is equal to the unit group number tNo value; If the tId.Out value of the controller is consistent with the current unit group number tNo, the safety password application is successful, "safety access password is applicable" is displayed, and the safety password application signal is triggered again, and the tId.InCtl value is set as 0, so that the current unit group discards the safety access password; If the tId.Out value of the controller is not consistent with the current unit group number tNo, "safety access password is not applicable" is displayed; After judging that the common system safety access password is applicable, an instruction output is performed. The instruction output includes a first instruction output, and the first instruction output is applied to the total safety access password application plug-in. ​ The first instruction output includes starting an instruction issuing operation after triggering a first safety application rule, and if the exclusion list contains a public system safety entry instruction, allowing instruction issuing; otherwise, prohibiting instruction issuing.

2. The method of claim 1, wherein the public system is a power system. The instantiation of the safety entry instruction application plug-in in the public system picture in the unit machine group includes, The tId.InCtl attribute is associated with a remote control point in the configuration library as a storage quantity, and the tId.Out attribute is associated with a remote measurement point; The tId.Out attribute has a value of [0, m], and m is greater than or equal to 1, where 0 indicates that none of the machine groups has a safety entry instruction, and m indicates that the mth machine group has a safety entry instruction.

3. The method of claim 2, wherein the public system is a power system. The method further includes, after judging that the public system safety entry instruction is available, performing instruction output, and the instruction output further includes second instruction output applied to the safety entry instruction application plug-in. The second instruction output includes, after triggering a second safety application rule, Starting an instruction issuing operation to read the value of tId.Out of the controller from the real-time library; If tId.Out is 0, the safety entry instruction is not available, and instruction issuing is prohibited; If tId.Out is not 0, the current machine group number tNo of the controller is further read from the real-time library; Comparing the value of tId.Out of the controller with the current machine group number tNo, if the value of tId.Out is inconsistent with tNo, the safety entry instruction is not available, and instruction issuing is prohibited; If the value of tId.Out of the controller is consistent with the current machine group number tNo, instruction issuing can be performed.

4. The method of claim 3, wherein the public system is a power system. The safety entry instruction includes an operator, a key, a machine group number, and a safety level; When the safety entry instruction application signal is triggered, the operator is subjected to first verification, and the first verification includes that when the key and the operator match and the safety entry instruction application authority is in the authority list of the operator, the application is allowed; When the instruction issuing operation is started, the associated control type is acquired first, and then the second verification of the instruction issuer is performed, and the second verification includes that when the key and the instruction issuer match, the authority list of the instruction issuer is acquired, and if the control type is in the authority list of the instruction issuer, the instruction issuing is performed; The machine group number is a unique identification code of each unit machine group; The safety level is a safety level of each unit machine group when controlling the public system, and each unit machine group has one and different safety level, and when the safety entry instruction application conflicts, the conflict is solved by additional sending of safety level information to select an effective applicant, and other applicants will fail to acquire.

5. A utility system safety switching system applying the utility system safety switching method according to any one of claims 1 to 4, characterized by The method further includes, A first instruction instantiation module is configured to instantiate a total safety entry instruction application plug-in in all public system pictures in the unit machine group; A first instruction application module is configured to determine whether the public system safety entry instruction is available by triggering a first safety application rule through the total safety entry instruction application plug-in; An HMI safety module is configured to determine the first safety application rule by associating picture attributes, and the HMI safety module includes: Triggering a safety entry instruction application signal; Acquiring parent window information, judging whether it is a background picture through the parent window type; if not, acquiring the parent window information of the parent window again and acquiring the window type thereof; if it is a background picture, acquiring a background picture object number; Acquiring all information in the exclusion list through the background picture object number and the exclusion list attribute type; Judging whether the exclusion list contains a safe entry password, if yes, the application is successful, and "with safe entry password" is displayed; if not, the application fails, and "without safe entry password" is displayed; The safe password application process occurs on a workstation, and after a certain monitoring picture applies or discards the safe entry password of a public system, other workstations of the current unit group are also effective; The second instruction instantiation module is used for instantiating a sub-safe entry password application plug-in in a public system picture in a unit group, and comprises: An analog function block is established in each controller, a tag name tId is set, and two attributes InCtl and Out are created; A global unit number tNo is configured, and two system reserved variables are configured in each communication unit of the public system, and the names are fixed; The second password application module is used for the sub-safe entry password application plug-in to judge whether the current picture has the safe entry password of the public system by triggering the second safety application rule; The controller safety module is used for the second safety application rule to judge through the associated signal attribute, and comprises: Triggering a safe password application signal, reading the tId.Out value of the controller and the current unit number tNo from the real-time library; When the tId.Out of all public system controllers is 0, the safe password application plug-in displays "no unit occupies the safe entry password of the public system controller"; If the tId.Out is 0, the safe entry password is allowed to be acquired, and the tId.InCtl value is set as the current unit number, so that the safe entry password of the current unit is acquired, and the password application is judged to be successful; otherwise, "the public system safe entry password cannot be acquired" is displayed, and the safe password application signal is invalid at this time; If the tId.Out is not 0, it is judged whether the tId.Out value is equal to the unit number tNo value; If the tId.Out value of the controller is consistent with the current unit number tNo, the safe password application is successful, "with safe entry password" is displayed, and the safe password application signal is triggered again, and the value of tId.InCtl is set to 0, so that the current unit discards the safe entry password; If the tId.Out value of the controller is not consistent with the current unit number tNo, "without safe entry password" is displayed; After judging that the public system safe entry password is possessed, instruction output is performed; The instruction output comprises a first instruction output, and the first instruction output is applied to a total safe entry password application plug-in; The first instruction output comprises, after triggering the first safety application rule, starting an instruction issuing operation, and if the exclusion list contains the safe entry password of the public system, the instruction issuing is allowed; otherwise, the instruction issuing is prohibited.

6. An electronic device comprising: a memory and a processor; The memory is configured to store computer-executable instructions, and the processor is configured to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method for safely switching a utility system according to any one of claims 1 to 4. 7.A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the method for safely switching a utility system according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Nuclear power station DCS controller updating method, system, terminal equipment and storage medium

    CN111477372A

  • Unit debugging method, device, system and equipment and storage medium

    CN112392688A