Integrated control system
By integrating conventional control systems and safety protection systems into long-distance oil and gas pipelines, and adopting an internal high-speed bus and electrical isolation design, the problem of high hardware costs has been solved, achieving the effects of cost reduction and improved space utilization.
Patent Information
- Application Number
- CN202310535017.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-12
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2043-05-12
AI Technical Summary
In existing long-distance oil and gas pipelines, the heterogeneous integration of conventional control systems and safety protection systems leads to high hardware costs and increased installation space costs.
Design an integrated control system that integrates conventional control systems and safety protection systems on the same rack, exchanges data through an internal high-speed bus, and employs electrical isolation and redundancy configuration to achieve electrical and data isolation of the system, thereby reducing the overall design cost.
This has enabled the reduction of hardware costs, improved utilization of rack installation space, ensured stable system operation, prevented the spread of single faults, and improved system reliability and security.
Smart Images

Figure CN116661346B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of automatic control technology, and more specifically, to an integrated control system. Background Technology
[0002] In long-distance pipeline applications such as oil and gas pipelines, conventional control systems (such as PLC systems) are generally the primary approach. These systems are characterized by small installation size and high volumetric efficiency. Additionally, safety protection systems are essential in these applications to ensure the safe operation of long-distance pipelines like oil and gas pipelines. Currently, these applications typically employ a heterogeneous integration scheme between the conventional control system and the safety protection system. This scheme uses a separately configured safety protection system, resulting in higher hardware costs and significantly increased installation space costs. Summary of the Invention
[0003] In view of this, this application provides an integrated control system for integrating a safety protection system while meeting the requirements of conventional PLC control, so as to reduce the overall design cost and improve the utilization rate of cabinet installation space.
[0004] To achieve the above objectives, the following solution is proposed:
[0005] An integrated control system, applied to long-distance pipeline scenarios, comprises a conventional control system and a safety protection system mounted on a local rack and N remote I / O racks, where N is an integer greater than or equal to 1.
[0006] The conventional control system is connected to a host computer and includes a conventional logic control unit, a first conventional communication interface module connected to the conventional logic control unit, N second conventional communication interface modules connected to the first conventional communication interface module, and N conventional I / O modules connected to the second conventional communication interface modules.
[0007] The conventional logic control unit and the first conventional communication interface module are mounted on the local rack, and each of the remote I / O racks is equipped with a second conventional communication interface module and a conventional I / O module;
[0008] The security protection system includes a security logic control unit connected to the conventional logic control unit, a first security communication interface module connected to the security logic control unit, N second security communication interface modules connected to the first security communication interface module, and N security I / O modules connected to the second security communication interface modules.
[0009] The security logic control unit and the first security communication interface module are mounted on the local rack, and the remote I / O rack is equipped with a second security communication interface module and the security I / O module.
[0010] Optionally, the conventional I / O module and the secure I / O module are located on the same remote I / O rack or on different remote I / O racks.
[0011] Optionally, the conventional logic control unit and the security logic control unit can interact with each other via an internal high-speed bus.
[0012] Optionally, the conventional logic control unit includes a conventional communication core and a conventional control core, wherein:
[0013] The conventional communication core is used to receive control commands issued by the host computer and to pass the control commands through to the conventional control core and the security logic control unit.
[0014] Optionally, the security logic control unit includes a secure communication core, a first security control core, and a second security control core.
[0015] Optionally, the secure communication core and the first secure control core are packaged in one microprocessor, and the second secure control core is packaged in another microprocessor.
[0016] Optionally, the secure communication core is used to detect control commands sent by the conventional control system and to remove data packets with excessive data flow, abnormal data frames, or abnormal protocol integrity.
[0017] Optionally, the local rack is equipped with redundant power protection modules.
[0018] Optionally, the power protection module is equipped with a voltage detection unit.
[0019] Optionally, each unit on the local rack is equipped with a DC-DC isolation conversion unit at its input, wherein:
[0020] The DC-DC isolation conversion unit is used to supply power to each of the units.
[0021] As can be seen from the above technical solution, this application discloses an integrated control system, including a conventional control system and a safety protection system mounted on a local rack and N remote I / O racks. The conventional control system is connected to a host computer and includes a conventional logic control unit, a first conventional communication interface module connected to the conventional logic control unit, N second conventional communication interface modules connected to the first conventional communication interface module, and N conventional I / O modules connected to the second conventional communication interface modules. The safety protection system includes a safety logic control unit connected to the conventional logic control unit, a first safety communication interface module connected to the safety logic control unit, N second safety communication interface modules connected to the first safety communication interface module, and N safety I / O modules connected to the second safety communication interface modules. This solution proposes an integrated design scheme for the conventional control system and the safety protection system, thereby reducing the overall design cost of the integrated control system. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a schematic diagram of an integrated control system according to an embodiment of this application;
[0024] Figure 2 This is a diagram illustrating the redundant configuration architecture of the integrated control system according to an embodiment of this application.
[0025] Figure 3 This is a schematic diagram of the electrical isolation design of the integrated control system according to an embodiment of this application.
[0026] Figure 4 This is a block diagram of a power protection module according to an embodiment of this application;
[0027] Figure 5 This is a schematic diagram of the communication interface between the conventional logic control unit and the security logic control unit in an embodiment of this application;
[0028] Figure 6 This is a flowchart illustrating the data packet detection process for the secure communication core of this application. Detailed Implementation
[0029] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0030] Example 1
[0031] Figure 1 This is a schematic diagram of an integrated control system according to an embodiment of this application.
[0032] like Figure 1 As shown, the integrated control system provided in this embodiment is applied to long-distance pipelines such as oil and gas pipelines. The integrated control system is applied to the corresponding control cabinet, which includes a local rack 100 and a remote IO rack 200 connected to the local rack via a communication cable. The remote IO rack in this application can be one or more.
[0033] The integrated control system specifically includes a conventional control system connected to a host PC and a safety protection system connected to the conventional control system via an internal high-speed bus. The conventional control system 10 includes a conventional logic control unit 11, a first conventional communication interface module GIM1, a second conventional communication interface module GIM2, and a conventional I / O module GI / O; the safety protection system 20 includes a safety logic control unit 21, a first safety communication interface module SIM1, a second safety communication interface module SIMS2, and a safety I / O module SI / O.
[0034] The conventional logic control unit 11, the first conventional communication interface module GIM1, the security logic control unit 21, and the first security communication interface module SIM1 are installed on the aforementioned local rack. The second conventional communication interface module GIM2, the conventional I / O module GI / O, the second security communication interface module SIMS2, and the security I / O module SI / O are located on the aforementioned remote I / O rack.
[0035] The remote I / O rack in this application is not limited to a single one, but can be expanded to multiple remote I / O racks according to application needs; the regular I / O module and the security I / O module can be installed in different remote I / O racks to achieve rack isolation between GIO and SIO.
[0036] The functions of the first conventional communication interface module, the second conventional communication interface module, the first secure communication interface module, and the second secure communication interface module of this application can also be implemented through an IM (interface module) module to save hardware costs and further improve the system's volumetric efficiency. The IM module can achieve rack interconnection via RJ / 45 or long-distance cross-regional rack interconnection via optical fiber.
[0037] In this application, the conventional modules of the conventional control system communicate with each other via a conventional bus G-Bus in the same rack, and the modules of the safety protection system communicate with each other via a safety bus S-Bus in the same rack. The conventional bus G-Bus and the safety bus S-Bus have different communication encoding rules.
[0038] The conventional bus G-Bus and the security bus S-Bus should use different physical communication links to support data bus isolation.
[0039] In this application, the conventional logic control unit (GCU) and the safety logic control unit (SCU) exchange data via an internal high-speed bus to ensure real-time data processing and rapid command response.
[0040] The General Logic Control Unit (GCU) and the Safety Logic Control Unit (SCU) are designed based on a multi-core CPU architecture. The GCU is a dual-core CPU architecture, comprising a general communication core (GCU-COM) and a general control core (GCU-CON). The general communication core receives control commands from the host PC and transmits them to both the general control core and the safety communication core of the safety logic control unit, while simultaneously sending real-time information from the integrated control system. The general control core parses control commands, executes routine control tasks, and transmits collected routine equipment operation data to the general communication core.
[0041] The Security Logic Control Unit (SCU) adopts a multi-core architecture, including a security communication core (SCU-COM) and two physically independent security control cores (SCU-CON), referred to as the first security control core (SCU-CON1) and the second security control core (SCU-CON2). The security communication core receives control commands distributed by the conventional communication core (GCU-COM) and distributes them to the two security control cores. The security control core parses the control commands and executes secure control tasks while simultaneously transmitting collected security device operation data to the security communication core. The two security control cores are capacitively isolated and enable high-speed real-time data exchange.
[0042] In this application, the secure communication core SCU-COM and the first security control core SCU-CON1 are packaged in one microprocessor, while the second security control core SCU-CON2 is packaged in another microprocessor. In this scheme, the two security control cores are located in different microprocessors to achieve better isolation and availability. Alternatively, the secure communication core and the first security control core can also be packaged in different microprocessors, omitting the second security control core to reduce hardware resources and cost.
[0043] This application achieves unified control and independent operation. Specifically, it uses a host PC software platform to uniformly monitor the operation of the integrated control system. Simultaneously, the communication cores (COM) of the conventional control system and the safety protection system distribute interactive data without parsing control commands. Control commands are parsed by the control core (CON), and each control core (CON) executes its respective task. The operation of the control cores does not interfere with each other. This application allows for redundant system configuration, specifically as follows: Figure 2 As shown.
[0044] As can be seen from the above technical solution, this embodiment provides an integrated control system, including a conventional control system and a safety protection system mounted on a local rack and N remote I / O racks. The conventional control system is connected to a host computer and includes a conventional logic control unit, a first conventional communication interface module connected to the conventional logic control unit, N second conventional communication interface modules connected to the first conventional communication interface module, and N conventional I / O modules connected to the second conventional communication interface modules. The safety protection system includes a safety logic control unit connected to the conventional logic control unit, a first safety communication interface module connected to the safety logic control unit, N second safety communication interface modules connected to the first safety communication interface module, and N safety I / O modules connected to the second safety communication interface modules. This solution proposes an integrated design scheme for the conventional control system and the safety protection system, thereby reducing the overall design cost of the integrated control system.
[0045] One risk in the practical implementation of the integrated control system in this application is that a failure in the conventional control system can propagate to the safety protection system, causing the safety protection system to malfunction. Therefore, this solution introduces an isolation scheme to prevent the propagation of a single fault. For example... Figure 3 As shown, the conventional control system and safety protection system are integrated and installed on the same rack, so electrical isolation design is required to prevent electrical failures (such as short circuits) in one system from affecting the normal operation of the other independent system.
[0046] like Figure 4As shown, the local rack in this application is equipped with a redundant power protection module, which is used to monitor and protect the AC / DC power supply voltage. This can prevent the integrated system from failing due to AC / DC power supply surges or high voltage faults, and enable the integrated system to operate stably in the power supply network.
[0047] The voltage detection unit within the power protection module supports overvoltage / undervoltage detection for the 24V on the main circuit. When such faults are detected, it can safely shut down the output fault voltage. The power protection module has redundant voltage detection units. Even if a single switch or detection unit fails to shut down correctly due to stick-at, the redundant voltage detection units can still perform the safe shutdown action, ensuring that the integrated system always operates stably in the power supply network.
[0048] Each unit on the local rack is equipped with a DC-DC isolation converter at its input terminal. This DC-DC isolation converter has isolation characteristics and is used to convert the input power into a secondary power supply to power the internal circuits of each unit. Units with external communication ports (such as GCU and IM units) use network transformers to protect their internal circuits and prevent high voltage from entering the ports when connecting to third-party devices. I / O units that connect to field devices are protected by isolation units between the system-side circuits and the field-side circuits to prevent electrostatic discharge, surges, and pulse interference from the field signal side from entering the integrated system and causing fault propagation. DIN rail mounting protection modules provide independent power to field devices to achieve isolation between the power supply networks of system devices and instrumentation devices.
[0049] In this application, in addition to electrical connections, the various modules are interconnected via an internal communication bus, such as the conventional logic control unit (GCU) and the safety logic control unit (SCU). Figure 5 As shown, the Safety Logic Control Unit (SCU) adopts a dual-channel architecture with capacitor isolation between channels to isolate DC error signals caused by electrical faults. When the CPU on the safety communication core side fails due to an electrical fault, the Safety Logic Control Unit can degrade from the original dual-channel architecture to a single-channel architecture and continue operating.
[0050] In addition, the secure communication core has a detection function for data packets transmitted by the regular communication core, such as... Figure 6 As shown, the system sequentially diagnoses the data flow, data frame anomalies, and protocol integrity of input control commands, and transmits the detection results to the security control core for further processing. Abnormal data packets that fail the detection are discarded, effectively isolating abnormal communication data or abnormal communication states and their effects outside the security control core.
[0051] The input data traffic of the secure communication core is limited to a normal level, such as a threshold of 500 frames per second. If the traffic limit is exceeded, the excess packets will be dropped.
[0052] It also verifies the header information of received data frames, such as checksum and data packet header information. If the verification fails, the erroneous data packet is discarded.
[0053] Protocol integrity detection uses a communication protocol whitelist mechanism to check the protocol integrity of received data commands; data commands not in the communication protocol whitelist will be discarded.
[0054] The units described in the embodiments of this disclosure can be implemented in software or in hardware. The name of a unit does not necessarily limit the unit itself; for example, the first acquisition unit can also be described as "a unit that acquires at least two Internet Protocol addresses".
[0055] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0056] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0057] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.
[0058] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0059] The technical solution provided by the present invention has been described in detail above. Specific examples have been used to illustrate the principle and implementation of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core idea of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation and application scope based on the idea of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. An integrated control system applicable to long-distance pipelines that require both control and safety protection functions while demanding a high degree of system integration, characterized in that: The integrated control system includes a conventional control system and a safety protection system installed on a local rack and N remote I / O racks, where N is an integer greater than or equal to 1. The conventional control system is connected to a host computer and includes a conventional logic control unit, a first conventional communication interface module connected to the conventional logic control unit, N second conventional communication interface modules connected to the first conventional communication interface module, and N conventional I / O modules connected to the second conventional communication interface modules. The conventional logic control unit and the first conventional communication interface module are mounted on the local rack, and each of the remote I / O racks is equipped with a second conventional communication interface module and a conventional I / O module; The security protection system includes a security logic control unit connected to the conventional logic control unit, a first security communication interface module connected to the security logic control unit, N second security communication interface modules connected to the first security communication interface module, and N security I / O modules connected to the second security communication interface modules. The security logic control unit and the first security communication interface module are mounted on the local rack, and the remote I / O rack is equipped with a second security communication interface module and the security I / O module.
2. The integrated control system as described in claim 1, characterized in that, The conventional I / O module and the secure I / O module are located on the same remote I / O rack or on different remote I / O racks.
3. The integrated control system as described in claim 1, characterized in that, The conventional logic control unit and the security logic control unit exchange data via an internal high-speed bus.
4. The integrated control system as described in claim 1, characterized in that, The conventional logic control unit includes a conventional communication core and a conventional control core, wherein: The conventional communication core is used to receive control commands issued by the host computer and to pass the control commands through to the conventional control core and the security logic control unit.
5. The integrated control system as described in claim 1, characterized in that, The security logic control unit includes a secure communication core, a first security control core, and a second security control core.
6. The integrated control system as described in claim 5, characterized in that, The secure communication core and the first secure control core are packaged in one microprocessor, and the second secure control core is packaged in another microprocessor.
7. The integrated control system as described in claim 5, characterized in that, The secure communication core is used to detect control commands sent by the conventional control system. The detection includes, but is not limited to, data traffic limiting, data frame detection, and protocol integrity detection, and it will remove any abnormal data packets detected.
8. The integrated control system according to any one of claims 1 to 7, characterized in that, The local rack is equipped with redundant power protection modules.
9. The integrated control system as described in claim 8, characterized in that, The power protection module is equipped with a voltage detection and protection unit.
10. The integrated control system as described in claim 8, characterized in that, Each unit on the local rack is equipped with a DC-DC isolated converter at its input, wherein: The DC-DC isolation conversion unit is used to supply power to each of the units.
Citation Information
Patent Citations
Power distribution edge server system based on centralized protection control system architecture
CN114006804A
Advanced logic system
US7870299B1