Industrial equipment networking system and method

CN116668180BActive Publication Date: 2025-09-23SAIAN TECH (GUANGDONG) CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202310818947.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-05
Publication Date
2025-09-23
Estimated Expiration
2043-07-05

Smart Images

  • Figure CN116668180B_ABST
    Figure CN116668180B_ABST
Patent Text Reader

Abstract

The present invention relates to an industrial equipment networking system and method, comprising a control unit and several isolation units connected thereto. The isolation unit is connected to at least one industrial device to be networked, so that data from the industrial device is transmitted through the isolation unit. The isolation unit includes at least a non-IP component. When the control unit sends a first data packet containing at least verification information to the industrial device, the isolation unit reads the first data packet and confirms whether the verification information therein meets preset requirements. If the verification information meets the preset requirements, the industrial device is networked through the isolation unit. Based on a non-IP firewall, the present invention further provides verification information and time stamps that can be monitored by the control unit. This allows the control unit to determine whether production is proceeding normally based on the verification information and time stamps, promptly detect production anomalies and fault objects, and reduce early warning delays.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent manufacturing technology, and in particular to an industrial equipment networking system and method. Background Art

[0002] With the development of IoT technology and smart industry, industrial equipment within factories has gradually achieved intelligent operation and data networking. Real-time recording of production and management information, and efficient sharing of this information across different devices via the network, is an essential operating principle for smart factories. However, due to the lack of security measures for information transmission between factory equipment, this technology is vulnerable to hacker attacks or Trojan viruses, leading to the theft and leakage of confidential data such as factory operating and management data. The leakage of confidential production information, in particular, makes it easy for exclusive products to be produced by competitors, resulting in a loss of market share and a decline in competitiveness.

[0003] In existing technologies, intelligent control systems are commonly protected by security software and antivirus software, or by deploying small network security devices such as integrated gateways to protect the information security of industrial equipment networks. For example, in an intelligent automotive manufacturing production line, the manufacturing equipment includes robots with various functions. If the robot's operating and manufacturing data is stolen, it will lead to a technical breach of the production line and prevent the timely detection of robot failures.

[0004] However, current security software still has defects in protecting smart industrial systems: (1) Each device in the smart industrial system needs to be able to provide security software installation support, but the software architecture of some industrial devices currently participating in the network is relatively backward and cannot install security software, which leads to security vulnerabilities in some industrial devices during operation. If a customized operating system is used, security protection requires an adapted device model that can participate in the network, but the cost of setting up an adapted operating system for the protected device is high, and the operating system cannot be reused in other smart industrial systems, making it difficult for small factories to protect the production data of industrial equipment with insufficient software architecture capabilities. In addition, small network security devices also have problems: they require IP addresses, which makes management difficult and cannot be quickly deployed. The IP addresses of network security devices themselves can be scanned and detected, and they themselves may become targets of attack.

[0005] Based on the above defects, the present invention hopes to provide an industrial equipment networking system and method, so that smaller-scale intelligent factories and some equipment with backward software architecture can be protected in terms of security data, reducing the phenomenon of factory equipment being eliminated simply due to software architecture defects, thereby reducing the update cost of industrial equipment.

[0006] For example, Chinese patent publication number CN114980114A discloses an industrial mobile internet security monitoring device, comprising: a network signal detection module, an industrial information collection module, a central control module, a communication module, an information integrity verification module, a network fault diagnosis module, a security assessment module, and a display module. This invention improves the efficiency of industrial intelligent gateways through the communication module. By forwarding target business information according to a second information forwarding strategy, the industrial intelligent gateway can adaptively adjust the information forwarding strategy based on the operating status of industrial equipment to improve its efficiency. Furthermore, the security assessment module uses weight presetting and cost assessment to scientifically and quantitatively assess the industrial data security protection capabilities of the industrial internet, significantly improving the accuracy of industrial data security protection capability assessments and reducing security protection costs. This security monitoring device is a typical protection device with IP information and requires an IP address, which makes management difficult and prevents rapid deployment. The IP address of a network security device can be scanned and detected, making it a potential target of attack.

[0007] For another example, Chinese patent publication number CN111193727A discloses an operation monitoring system and method. The system includes: an acquisition module for acquiring the IP information of industrial equipment and, based on the IP information of the industrial equipment, scanning and determining the industrial equipment currently in operation; a determination module for sending a communication protocol data packet to the industrial equipment currently in operation, and receiving and parsing the operation information fed back by the industrial equipment in response to the communication protocol data packet; and a monitoring module for searching a pre-configured vulnerability database based on the fed-back operation information to determine the operation vulnerability of the industrial equipment. This method requires that each device has an IP address and that device security protection is performed based on the IP address.

[0008] Therefore, the present invention aims to provide a networking system and a protection method that can achieve security protection even without IP. If the monitoring and early warning of the production process are achieved based on the feature of intercepting data packets without IP, this is also a technical problem that the present invention hopes to solve.

[0009] In addition, on the one hand, there are differences in understanding among those skilled in the art; on the other hand, the applicant studied a large number of documents and patents when making the present invention, but due to space limitations, not all details and contents are listed in detail. However, this does not mean that the present invention does not have the characteristics of these prior arts. On the contrary, the present invention already has all the characteristics of the prior art, and the applicant reserves the right to add relevant prior art to the background technology. Summary of the Invention

[0010] In response to the deficiencies of the prior art, the present invention provides an industrial equipment networking system, which comprises at least a control unit and several isolation units connected thereto, wherein the isolation unit is connected to at least one industrial device to be networked, so that data transmission of the industrial device passes through the isolation unit; the isolation unit comprises at least a non-IP component, and when the control unit sends a first data packet including at least verification information to the industrial device, the isolation unit reads the first data packet and confirms whether the verification information therein meets preset requirements; when the verification information meets the preset requirements, the industrial device is networked through the isolation unit.

[0011] To address the existing inability to provide security protection for industrial equipment with outdated software architectures, the present invention proposes a new networking method that enables security protection for each industrial device without requiring a new network architecture, preventing production data from being stolen. Preferably, the control unit of the present invention can also determine whether the industrial device is faulty or abnormal based on anomalies in the second data packet reported by the isolation unit, thereby enabling timely issuance of warnings or alerts.

[0012] Preferably, when information is transmitted between the first industrial equipment and the second industrial equipment, the second data packet includes at least verification information of the receiving object; when the isolation unit to which the receiving object belongs successfully verifies the verification information, the receiving object can receive the second data packet; when the isolation unit to which the receiving object belongs fails to verify the verification information, the receiving object cannot receive the second data packet. Generally, the production process of each industrial equipment is pre-set, so the data transmission pattern between each industrial equipment is predictable. Therefore, when the control unit finds that a second data packet that does not conform to the transmission pattern appears, the control unit can focus on verifying the abnormal second data packet. The setting of the isolation unit of the present invention enables the control unit to verify the sending / receiving of the second data packet while avoiding the exposure of the IP of the industrial equipment, thereby monitoring the progress of the production process and preventing the production data from being stolen.

[0013] Preferably, the isolation unit transmits verification information in the second data packet to the control unit. Upon receipt of the verification information, the control unit monitors whether the isolation unit transmits at least one transmission signal corresponding to the second data packet to determine whether the receiving device successfully receives the second data packet. This configuration enables the control unit to promptly detect abnormal industrial equipment, thereby avoiding subsequent production losses. If the second data packet fails to be received, the control unit can focus on monitoring the receiving device and determine whether it is faulty, thereby adjusting the overall production schedule.

[0014] Preferably, the second data packet also includes a first time stamp, the isolation unit of the sending object sends the first time stamp in the second data packet to the control unit, and the isolation unit of the receiving object sends the second time stamp in the received second data packet to the control unit. In response to the reception of the second time stamp, the control unit compares the first time stamp with the second time stamp. When the first time stamp is the same as the second time stamp, the control unit confirms that the second data packet can be received by the receiving object.

[0015] The present invention can confirm whether the second data packet is normal by collecting and verifying the time stamp information. The time stamp of the present invention can prevent the second data packet from being forged and can also promptly detect abnormal second data packets. The isolation unit isolates the abnormal second data packet from the industrial equipment, preventing the forged second data packet from stealing the production data of the industrial equipment.

[0016] Preferably, the verification information includes at least the IP address and MAC address of the recipient. The present invention verifies the IP address to verify whether the recipient of the received second data packet corresponds to the industrial device, thereby avoiding the phenomenon of the industrial device ineffectively receiving and processing the erroneously sent second data packet. Furthermore, if the control unit discovers that the IP address of the recipient of the second data packet is inconsistent with the receiving industrial device, the control unit can deem the recipient of the second data packet to be abnormal and perform fault detection, thereby enabling the fault to be discovered in a shorter time than the time it takes for the industrial device to issue a fault warning.

[0017] Preferably, the control unit monitors the changing patterns of the first time stamp and / or second time stamp of the second data packet sent by the isolation unit based on preset production steps. If the first time stamp and / or second time stamp corresponding to the production process are missing and / or abnormal, the control unit transmits an abnormality message to at least one terminal. By monitoring the transmission patterns of the second data packet, the present invention can promptly screen out potentially faulty industrial equipment, allowing factory technicians to inspect the industrial equipment.

[0018] The present invention also provides an industrial equipment networking method, which at least includes: establishing a connection relationship between a control unit and several isolation units, connecting the isolation unit to at least one industrial equipment to be networked, so that data transmission of the industrial equipment passes through the isolation unit; the isolation unit includes at least a non-IP component, and when the control unit sends a first data packet including at least verification information to the industrial equipment, the isolation unit reads the first data packet and confirms whether the verification information therein meets the preset requirements; when the verification information meets the preset requirements, the industrial equipment is networked through the isolation unit.

[0019] The networking method of the present invention enables each industrial device to be securely protected without replacing a new network architecture, preventing production data from being stolen. Preferably, the control unit of the present invention can also determine whether the industrial device is faulty or abnormal based on anomalies in the second data packet fed back by the isolation unit, thereby enabling timely issuance of warning or alert information.

[0020] Preferably, the method also includes: when information is transmitted between the first industrial equipment and the second industrial equipment, the second data packet includes at least verification information of the receiving object; if the isolation unit to which the receiving object belongs successfully verifies the verification information, the receiving object can receive the second data packet; if the isolation unit to which the receiving object belongs fails to verify the verification information, the receiving object cannot receive the second data packet.

[0021] Generally, the production processes of various industrial devices are pre-set, so the data transmission patterns between the various industrial devices are predictable. Therefore, if the control unit discovers the presence of a second data packet that does not conform to the transmission pattern, the control unit can focus on verifying this abnormal second data packet. The provision of the isolation unit of the present invention enables the control unit to verify the sending / receiving of the second data packet without exposing the IP address of the industrial device, thereby monitoring the progress of the production process and preventing the theft of production data.

[0022] Preferably, the method also includes: the isolation unit sends the verification information in the second data packet to the control unit, and in response to the receipt of the verification information, the control unit monitors whether the isolation unit sends at least one transmission signal corresponding to the second data packet to determine whether the receiving object successfully receives the second data packet.

[0023] The networking method of the present invention is simple to install and can be applied to all industrial equipment that are not compatible with the software architecture, so that the control unit can perform security protection on all industrial equipment. Preferably, the control unit of the present invention can also timely detect and intercept abnormal second data packets based on the sending regularity of the second data packet, thereby realizing physical isolation of abnormal data. Not only that, the present invention can also timely detect abnormal second data packets based on the sending regularity of the second data packet, thereby quickly discovering faulty industrial equipment, or quickly discovering failed isolation components, or quickly discovering industrial equipment that is caught in data chaos and is about to fail. In the case of intelligent production, the failure of industrial equipment generally starts with difficult-to-find data anomalies, and then manifests itself in abnormal manufacturing processes of the product. Therefore, screening industrial equipment that is about to fail based on the abnormality of the second data packet can troubleshoot or solve the failure problem of industrial equipment before the production step becomes abnormal, thereby avoiding manufacturing losses of the product.

[0024] The present invention also provides a fault monitoring system for industrial equipment, comprising at least a control unit and several isolation units connected thereto, wherein the isolation unit is connected to at least one industrial device to be networked, so that data transmission of the industrial device passes through the isolation unit; the isolation unit comprises at least a non-IP component, and when the control unit sends a first data packet including at least verification information to the industrial device, the isolation unit reads the first data packet and confirms whether the verification information therein meets preset requirements; when the verification information meets the preset requirements, the industrial equipment is networked through the isolation unit; when information is transmitted between the first industrial device and the second industrial device, the second data packet includes at least the verification information and a time stamp of the receiving object; the isolation unit of the sending object sends the first time stamp in the second data packet to the control unit, and the isolation unit of the receiving object sends the second time stamp in the received second data packet to the control unit. In response to receipt of the second time stamp, the control unit compares the first time stamp with the second time stamp. When the first time stamp and the second time stamp are abnormal and / or one of them is missing, the control unit sends an abnormality message to at least one corresponding terminal.

[0025] The fault monitoring system of the present invention can promptly detect abnormal industrial equipment based on the characteristics of the isolation data of the isolation unit and the sending rules of the second data packet, reduce the delay of early warning, and promptly detect data processing anomalies before abnormalities occur in the production steps, thereby avoiding physical losses to product manufacturing caused by industrial equipment. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 This is a schematic diagram of the connection relationship of a networking system according to a preferred embodiment of the present invention;

[0027] Figure 2 This is a simplified schematic diagram of module connection relationships of a networking system according to a preferred embodiment of the present invention.

[0028] Reference Signs List

[0029] 10: Control unit; 20: Isolation unit; 30: Industrial equipment; 21: Non-IP component; 22: Packet parsing component. DETAILED DESCRIPTION

[0030] The following is a detailed description with reference to the accompanying drawings.

[0031] The present invention can provide an industrial equipment networking system and method, as well as a production fault monitoring system and method. The system can also be used for early anomaly screening and early warning of industrial production, providing early warning and processing when industrial equipment software anomalies occur, thereby maintaining normal production processes.

[0032] In the field of smart manufacturing, intelligent robots are widely used to perform assembly line operations in the production of high-tech products. Therefore, the production data of these robots contains many production technology secrets. This data can be protected through devices such as firewalls or software architectures. However, in smart manufacturing production lines, the software architecture of some early robots is not necessarily compatible with the software architecture of current protection systems, making it difficult to install and maintain data security with the latest firewall systems. How to securely protect the production data of industrial equipment that is not compatible with current firewall systems, namely early intelligent industrial equipment, remains an unresolved technical challenge.

[0033] Furthermore, for intelligent robots in smart manufacturing, production failures typically begin with data disorganization during transmission or reception, and only manifest as a production failure after the data disorganization occurs. Therefore, by the time standard monitoring equipment detects an intelligent robot malfunction, data processing may have been disrupted for several minutes or even half an hour. During this period of data processing disorganization, products may have been destroyed by an abnormal production step, or abnormal products may have already entered the next production stage. Therefore, how to detect intelligent robot anomalies through the invisible second data packet detection method, so as to prevent losses and conduct fault detection, remains an unresolved technical challenge in intelligent manufacturing.

[0034] The present invention hopes to build a new networking system to solve the above problems. While protecting the production data of low-end smart devices, it can also detect abnormalities in the second data packets of smart devices, thereby issuing timely warnings and detecting smart devices.

[0035] In the present invention, intelligent robots and other equipment are collectively referred to as industrial equipment.

[0036] The non-IP component in the present invention refers to a non-IP device. For example, a non-IP device includes at least two network ports, one network port is connected to the control unit, and the other network port is connected to the protected device. The control unit is responsible for centralized management and configuration. When the non-IP device receives data, it first identifies the data packet. If it is the first data packet, it is handed over to the detection packet processing module. If it is the second data packet, it is handed over to the security rule configuration module for processing. After the first data packet is processed, the returned data will be uploaded to the control unit through the non-IP communication module for networking. Similarly, when the non-detection second data packet is processed, the returned data will also be uploaded to the control unit through the non-IP communication module. All data packets passed to the configuration system through the firewall must pass through the non-IP communication module, otherwise communication will not be possible.

[0037] The isolation unit of the present invention includes a non-IP component and a data packet parsing component. The data packet parsing component may be, for example, a dedicated integrated circuit, a hard disk, a magnetic medium, a single-chip microcomputer, or the like, storing a data parsing program. The non-IP component and the data packet parsing component are connected via a wired and / or wireless connection. For example, a wired connection may be via optical fiber for data transmission, while a wireless connection may be via wireless signal transmission, such as a Wi-Fi communication component, a Bluetooth communication component, or a ZigBee communication component.

[0038] In the present invention, the industrial device that sends a data packet is called the sending target. The industrial device that receives the data packet is called the receiving target. The verification information of the first data packet and the second data packet in the present invention includes at least the IP address and MAC address of the receiving target.

[0039] In the present invention, the control unit is a server, cloud platform, server cluster, and / or application-specific integrated circuit (ASIC) capable of implementing the networking method and fault monitoring method of the present invention. The software architecture of the control unit of the present invention generally enables connection with a firewall system to achieve security protection, thus eliminating the need for a separate isolation unit. The control unit establishes a wired and / or wireless connection with the isolation units to transmit information.

[0040] The isolation unit of the present invention is connected to the data port of the industrial equipment, so that all data transmission of the industrial equipment passes through the isolation unit. The isolation unit parses the received data packets and sends the relevant data to the control unit so that the control unit can monitor the production process and the operation of each industrial equipment.

[0041] Example 1

[0042] like Figure 1 and Figure 2As shown, the networking system of the present invention includes at least a control unit 10 and several isolation units 20. The isolation units 20 are provided with a non-IP component 21 and a second data packet parsing component 22. The non-IP component 21 is connected to the second data packet parsing component 22, so that a second data packet is sent from the non-IP component 21 to the second data packet parsing component 22. The data parsing component 22 transmits the parsed relevant information to the control unit 10. The isolation units 20 are connected to ports of industrial devices 30 through ports, enabling data transmission between the isolation units 20 and the industrial devices 30.

[0043] In the absence of networking, the control unit 10 and several industrial devices are networked as follows: In the present invention, the first data packet refers to the detection data packet. The second data packet refers to the data packet sent by the isolation unit to the control unit 10 before and after the successful networking.

[0044] The control unit 10 sends a first data packet containing at least verification information to the communication addresses of all industrial devices 30 in the communication network. The IP-free component in the isolation unit 20, located at the front end of the industrial device 30, receives the first data packet. The data packet parsing component 22 reads the first data packet and confirms whether the verification information in the data packet meets preset requirements.

[0045] Preferably, the No-IP component 21 preferentially detects the destination port information. If the port information complies with the set rules, the No-IP component 21 proceeds to detect the application layer protocol header. If the application layer protocol header exists, the No-IP component 21 sends the first data packet to the data packet parsing component 22. The data packet parsing component 22 reads the verification information and / or time stamp information. The time stamp information refers to the time when the data packet was generated. The data packet parsing component 22 sends the verification information of successful verification to the control unit 10. The data packet parsing component 22 packages the verification information and time stamp information and adds a custom application layer protocol header to form a new first data packet, which is then sent to the control unit 10.

[0046] The control unit 10 receives and parses the first data packet sent by the isolation unit, and saves the verification information and the time stamp information.

[0047] The control unit 10 traverses all IP addresses in the communication network by sending a first data packet, and receives the first data packet to determine the IP address of the industrial device 30 equipped with the isolation unit 20 from the multiple IP addresses. If the verification information meets the preset requirements, the industrial device 30 is networked through the isolation unit 20.

[0048] Preferably, when information is transmitted between the first industrial device and the second industrial device, the second data packet includes at least verification information of the receiving device. If the isolation unit 20 to which the receiving device belongs successfully verifies the verification information, the receiving device can receive the second data packet. If the isolation unit 20 to which the receiving device belongs fails to verify the verification information, the receiving device cannot receive the second data packet.

[0049] This invention implements an isolation unit containing no IP components at the receiving end of industrial equipment, preventing attacks and theft of production data. This networking approach allows every intelligent device involved in production data to be protected, even for rudimentary intelligent industrial equipment.

[0050] Preferably, after the networking is successfully established, the control unit 10 can establish data connection with the corresponding industrial equipment 30 through each isolation unit 20 to monitor the transmission status of each production data.

[0051] In normal production processes, the production times and data packet destinations of each industrial device follow predictable patterns. For example, after the first industrial device completes the current production process, it not only sends the corresponding second data packet to the control unit, but also sends the second data packet to the industrial device in the next production process. When the intelligent production process is determined, the sender and recipient of the second data packet are both fixed. Based on the current production patterns, the changes in the second data packet's transmission frequency, transmission time, recipient, and other information follow a predictable pattern. When a second data packet appears whose time stamp information does not conform to this pattern, the appearance of this second data packet may involve several situations: first, it is an intrusion; second, the industrial device sending the second data packet has malfunctioned; third, the isolation unit receiving the second data packet has malfunctioned.

[0052] If the second time stamp information of the sending and receiving objects does not correspond to each other, the control unit can easily determine whether the isolation unit is faulty. If the isolation unit is not faulty, the control unit can promptly detect intruding second data packets and industrial equipment with software failures or data disorder. It can issue an early warning before a real failure occurs on the production line, prompting technicians to conduct inspections or restart the software program accordingly, thereby avoiding the occurrence of actual production failures. The method for the control unit of the present invention to detect anomalies is as follows.

[0053] Preferably, the isolation unit sends the verification information in the second data packet to the control unit. In response to the receipt of the verification information, the control unit monitors whether the isolation unit sends at least one transmission signal corresponding to the second data packet to determine whether the receiving object successfully receives the second data packet. For example, the second data packet also includes a first time stamp, and the isolation unit of the sending object sends the first time stamp in the second data packet to the control unit. The isolation unit of the receiving object sends the second time stamp in the received second data packet to the control unit. In response to the reception of the second time stamp, the control unit compares the first time stamp with the second time stamp. When the first time stamp and the second time stamp are the same, the control unit confirms that the second data packet can be received by the receiving object. Otherwise, the control unit 10 can determine that the reception of the second data packet failed.

[0054] If the second data packet fails to be received, the control unit 10 can issue a prompt to at least one corresponding terminal, or send an instruction to the recipient, instructing the terminal to resend the corresponding second data packet. The terminal includes at least an electronic display, a portable device, a computer, etc. Portable devices include, for example, work portable devices, smartphones, smart bracelets, VR glasses, smart glasses, etc.

[0055] The control unit 10 can establish a preliminary second data packet transmission pattern based on the initial production steps and information such as the sender and recipient of the received second data packets, and the second data packet transmission time interval. The control unit 10 can also update the second data packet transmission pattern based on changes in the production steps. Specifically, the control unit monitors the changing pattern of the time stamps of the second data packets sent by the isolation unit based on the preset production steps. If the time stamp corresponding to a production process is missing and / or abnormal, the control unit transmits an abnormality message to at least one terminal associated with the management of the faulty industrial equipment.

[0056] For example, the control unit 10 can detect whether the second data packet sent by the isolation unit 20 includes the IP address of the first industrial device, the corresponding MAC address, and the first time stamp of the industrial image sent by the first industrial device, thereby determining whether the actual transmission and reception of the industrial image is consistent with the transmission and reception expectations of the industrial image.

[0057] Preferably, if the second isolation unit 20 of the receiving object does not send a second data packet including the IP address and corresponding MAC address of the first industrial device and the second time stamp of the industrial image sent by the first industrial device to the control unit 10 within a preset time period, the control unit 10 may determine that the industrial image transmission between the first industrial device and the second industrial device has failed. In this case, the control unit 10 generates a second data packet for prompting the first industrial device to resend the industrial image to the second industrial device and satisfying the security rule of the no IP component in the first isolation unit of the sending object. Preferably, the time unit of the preset time period can be a time unit such as min (minutes), S (seconds), ms (milliseconds), ns (nanoseconds), etc.

[0058] Preferably, due to differences in communication protocols, communication ports, and other features among different industrial devices 30, the networked communication network utilizes both synchronous and asynchronous communication architectures. When a first industrial device transmits a large amount of data to a second industrial device, to reduce the data processing load for the isolation unit and control unit 10, the first industrial device and at least some of the second industrial devices in the communication network utilize a send-without-feedback mechanism. In this case, the control unit 10 and isolation unit 20 monitor the data transmission status of the first industrial device.

[0059] Specifically, the control unit 10 determines an abnormal second data packet based on a change pattern of a sending object of the second data packet of the isolation unit, and issues detection reminder information of a sending object corresponding to the abnormal second data packet based on the abnormal second data packet.

[0060] For example, the change pattern of the sending object of the second data packet received by a certain isolation unit is: industrial equipment A → industrial equipment B → industrial equipment C → industrial equipment D. The interval time between the four second data packets is predictable. When the receiving order of the second data packets changes to industrial equipment A → industrial equipment C → industrial equipment B → industrial equipment D, the isolation unit sends the verification information and the second time mark of the second data packet to the control unit, and at the same time sends the abnormal label information of the sending object C of the second data packet to the control unit 10. The isolation unit will only send the second data packet to the corresponding industrial equipment if the control unit feedbacks that there is no abnormality. The isolation unit will not receive the second data packet if the control unit feedbacks that the second data packet is abnormal. The control unit issues a detection reminder message to the industrial equipment C based on the abnormal label information. The control unit 10 stops issuing the detection reminder message to the industrial equipment C when it receives information from the detection terminal connected to it that the operation is normal.

[0061] Preferably, the control unit 10 determines that the sending object is abnormal because the time stamp does not meet the expected time interval based on the second data packet receiving regularity of the isolation unit 20, and issues a reminder message corresponding to the sending object.

[0062] For example, the pattern for receiving second data packets for a particular isolation unit is: second data packet A → second data packet B → second data packet C → second data packet D. The intervals between the four second data packets are predictable. When a second data packet appears between second data packet C and second data packet D, the isolation unit sends verification information and a second time stamp to the control unit, along with a label indicating an abnormality in the second data packet, to the control unit 10. The isolation unit only sends the second data packet to the industrial device if the control unit reports no abnormality. If the control unit reports an abnormality, the isolation unit does not receive the second data packet.

[0063] Preferably, the control unit 10 judges the production operation status based on the sending order of the time stamps of each second data packet of the isolation unit 20. When the change in the sending order of the time stamps does not conform to the preset order, it is judged that an abnormality may have occurred in the industrial equipment and a reminder message corresponding to the sending object is issued.

[0064] Under normal production conditions, the time stamps of the second data packets received by each isolation unit follow a certain pattern. For example, first industrial equipment A sends a second data packet to second industrial equipment B at regular intervals. Therefore, the time stamps of the second data packets sent to the same destination have a certain time interval. If the time stamp interval changes significantly, the control unit 10 can determine that there has been a change in the production of the first industrial equipment based on this change in the time stamp interval and promptly issue a warning message related to the first industrial equipment.

[0065] As shown above, the networking system and method of the present invention not only enables each industrial device to achieve secure production data protection, but also can determine whether the industrial device and the production process are abnormal based on the time stamp set by the isolation center on the transmission and reception of the second data packet. In other words, the networking system of the present invention not only provides security protection but also enables fault monitoring of software running on intelligent devices, issuing warnings before physical failures occur in production equipment, thereby avoiding physical losses during the production process.

[0066] It should be noted that the above-mentioned specific embodiments are exemplary, and those skilled in the art can come up with various solutions inspired by the disclosure of the present invention, and these solutions also fall within the scope of the disclosure of the present invention and fall within the scope of protection of the present invention. Those skilled in the art should understand that the present invention specification and its drawings are illustrative and do not constitute a limitation on the claims. The scope of protection of the present invention is defined by the claims and their equivalents. The present invention specification contains multiple inventive concepts, such as "preferably", "according to a preferred embodiment" or "optionally", which means that the corresponding paragraph discloses an independent concept, and the applicant reserves the right to file a divisional application based on each inventive concept.

Claims

1. An industrial equipment networking system, characterized in that: It includes a control unit and several isolation units connected to the control unit, wherein the isolation unit is connected to at least one industrial device to be networked, so that data of the industrial device is transmitted through the isolation unit; The isolation unit includes a non-IP component. When the control unit sends a first data packet including verification information to the industrial device, the isolation unit reads the first data packet and confirms whether the verification information therein meets preset requirements; When the verification information meets the preset requirements, the industrial equipment is networked through the isolation unit; When information is transmitted between the first industrial equipment and the second industrial equipment, the isolation unit sends a second data packet including verification information of the receiving object and a time stamp to the control unit and the industrial equipment of the next production process. The control unit also determines whether the industrial equipment is faulty or abnormal based on the sending order of the time stamp of the second data packet fed back by the isolation unit and the change pattern of the sending object of the second data packet, so as to issue early warning information or reminder information in time. The isolation unit sends the second data packet to the corresponding industrial equipment only when the control unit feeds back that there is no abnormality, and does not receive the second data packet when the control unit feeds back that the second data packet is abnormal. The first data packet is a detection data packet, and the second data packet is a data packet sent by the isolation unit to the control unit before and after the networking is successful; The second data packet also includes a first time marker, the isolation unit of the sending object sends the first time marker in the second data packet to the control unit, and the isolation unit of the receiving object sends the second time marker in the received second data packet to the control unit. In response to receiving the second time stamp, the control unit compares the first time stamp with the second time stamp, and when the first time stamp is the same as the second time stamp, the control unit confirms that the second data packet can be received by the receiving object.

2. The industrial equipment networking system according to claim 1, characterized in that: When the isolation unit to which the receiving object belongs successfully verifies the verification information, the receiving object is able to receive the second data packet; In a case where the isolation unit to which the receiving object belongs fails to verify the verification information, the receiving object cannot receive the second data packet.

3. The industrial equipment networking system according to claim 2, characterized in that: The isolation unit sends the verification information in the second data packet to the control unit, In response to receiving the verification information, the control unit monitors whether the isolation unit sends at least one transmission signal corresponding to the second data packet to determine whether the receiving object successfully receives the second data packet.

4. The industrial equipment networking system according to claim 1, characterized in that: The verification information includes at least the IP address and MAC address of the receiving object.

5. The industrial equipment networking system according to claim 3, characterized in that: The control unit monitors the change pattern of the first time mark and / or the second time mark of the second data packet sent by the isolation unit based on the preset production steps, In the case that the first time marker and / or the second time marker corresponding to the production process is missing and / or abnormal, the control unit sends abnormal information to at least one terminal.

6. A method for networking industrial equipment, characterized in that: The method at least comprises: Establishing a connection relationship between a control unit and a plurality of isolation units, and connecting the isolation unit to at least one industrial device to be networked, so that data of the industrial device is transmitted through the isolation unit; The isolation unit includes at least a non-IP component, and when the control unit sends a first data packet including at least verification information to the industrial device, the isolation unit reads the first data packet and confirms whether the verification information therein meets preset requirements; When the verification information meets the preset requirements, the industrial equipment is networked through the isolation unit; When information is transmitted between the first industrial equipment and the second industrial equipment, the isolation unit sends a second data packet including verification information of the receiving object and a time stamp to the control unit and the industrial equipment of the next production process. The control unit also determines whether the industrial equipment is faulty or abnormal based on the sending order of the time stamp of the second data packet fed back by the isolation unit and the change pattern of the sending object of the second data packet, so as to issue early warning information or reminder information in time. The isolation unit sends the second data packet to the corresponding industrial equipment only when the control unit feeds back that there is no abnormality, and does not receive the second data packet when the control unit feeds back that the second data packet is abnormal. The first data packet is a detection data packet, and the second data packet is a data packet sent by the isolation unit to the control unit before and after the networking is successful; The second data packet also includes a first time marker, the isolation unit of the sending object sends the first time marker in the second data packet to the control unit, and the isolation unit of the receiving object sends the second time marker in the received second data packet to the control unit, In response to receiving the second time stamp, the control unit compares the first time stamp with the second time stamp, and when the first time stamp is identical to the second time stamp, the control unit confirms that the second data packet can be received by the receiving object.

7. The method according to claim 6, characterized in that The method further includes: if the isolation unit to which the receiving object belongs successfully verifies the verification information, the receiving object is able to receive the second data packet; In a case where the isolation unit to which the receiving object belongs fails to verify the verification information, the receiving object cannot receive the second data packet.

8. The method according to claim 6 or 7, characterized in that The method further comprises: The isolation unit sends the verification information in the data packet to the control unit, In response to receiving the verification information, the control unit monitors whether the isolation unit sends at least one transmission signal corresponding to the data packet to determine whether the receiving object successfully receives the second data packet.

9. A fault monitoring system for industrial equipment, characterized in that: The system comprises at least a control unit and a plurality of isolation units connected thereto, wherein the isolation unit is connected to at least one industrial device to be networked, so that data of the industrial device is transmitted through the isolation unit; the isolation unit comprises at least a non-IP component, and when the control unit sends a first data packet including at least verification information to the industrial device, the isolation unit reads the first data packet and confirms whether the verification information therein meets preset requirements; When the verification information meets the preset requirements, the industrial equipment is networked through the isolation unit; When information is transmitted between the first industrial equipment and the second industrial equipment, the isolation unit sends a second data packet including verification information of the receiving object and a time stamp to the control unit and the industrial equipment of the next production process. The control unit also determines whether the industrial equipment is faulty or abnormal based on the sending order of the time stamp of the second data packet fed back by the isolation unit and the change pattern of the sending object of the second data packet, so as to issue early warning information or reminder information in time. The isolation unit sends the second data packet to the corresponding industrial equipment only when the control unit feeds back that there is no abnormality, and does not receive the second data packet when the control unit feeds back that the second data packet is abnormal. The first data packet is a detection data packet, and the second data packet is a data packet sent by the isolation unit to the control unit before and after the networking is successful; The second data packet also includes a first time marker, the isolation unit of the sending object sends the first time marker in the second data packet to the control unit, and the isolation unit of the receiving object sends the second time marker in the received second data packet to the control unit, In response to receiving the second time marker, the control unit compares the first time marker with the second time marker, and sends an abnormality message to at least one terminal if the first time marker and the second time marker are abnormal and / or one of them is missing.

Citation Information

Patent Citations

  • Operation monitoring system and operation monitoring method

    CN111193727A

  • Industrial mobile internet security monitoring device

    CN114980114A

  • Bidirectional authentication method of shared electricity interaction system

    CN107483415A

  • Rapid deployment management method for IP-free firewall

    CN113810361A