Modular control network architecture

By adopting a modular control network architecture, the problems of high complexity and insufficient security in DCS network interconnection are solved, thereby improving flexibility and security and reducing maintenance costs.

CN116679625BActive Publication Date: 2026-08-25HONEYWELL INTERNATIONAL INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310052495.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-02-23
Filing Date
2023-02-02
Publication Date
2026-08-25
Estimated Expiration
2043-02-02

AI Technical Summary

Technical Problem

Existing industrial distributed control systems (DCS) suffer from high complexity, high cost, low flexibility, and insufficient security in terms of network interconnection and security. In particular, the lack of management ports and security features in the use of Ethernet switches makes them vulnerable to malicious intrusion and misconfiguration.

Method used

It adopts a modular control network architecture, including control components, expansion components, and security components. The processor executes the operating software to realize port configuration and secure access control. Combined with built-in security and deep packet inspection protocols, it supports the modular design of various network functions.

Benefits of technology

It achieves high flexibility, low complexity, and improved security in DCS networks, reduces SKU bursts, enhances network scalability and security, and lowers maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116679625B_ABST
    Figure CN116679625B_ABST
Patent Text Reader

Abstract

An apparatus and system is disclosed that connects at least one input / output (I / O) module and at least one controller to an industrial distributed control system. The apparatus and system includes a control network module having a control component that uses a processor to execute operating software that implements an operating configuration for the control network module. At least one I / O port is connected to the control component, the at least one I / O port being configurable by the operating software to enable a port configuration to connect the at least one I / O module to the control network module. An extension component connected to the control component has at least one extension port connected to the at least one controller. The extension port connects the at least one controller to the control component for communicating data and control signals to and from the at least one controller to the at least one I / O module. A security component regulates access to the apparatus based on one or more security attributes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates generally to industrial control systems. More specifically, this disclosure relates to a modular control network architecture for industrial distributed control systems. Background Technology

[0002] The deployment of industrial process control and automation systems across geographical locations is controlled by several factors, such as distance, functionality, and environment. Distributed system architecture allows industrial distributed control systems (DCS) to be extended and distributed over long distances. Therefore, network devices (such as Ethernet switches, routers, node interfaces, gateways, firewalls, and network cables) that form the data and control networks between DCS assets become critical components of the DCS. The various network interconnect components used to connect DCS assets support the ability to send and receive data and control signals using various transmission protocols such as Ethernet, serial, or wireless. Furthermore, the network is interconnected using network cables, which consist of, for example, bundled copper or fiber optic cables, interconnecting DCS assets and network components into, for example, ring topologies, star topologies, or mesh network topologies, or combinations of wired and wireless networks, to achieve the required interconnectivity between distributed DCS assets.

[0003] In addition to the network functions mentioned above, the security and protection of data and control signals transmitted between network components and DCS assets is another important function. Various remote applications or systems often attempt to update and / or retrieve information or related equipment information via a variety of different, competing, and often incompatible or insecure network technologies. The primary concern with this type of access to the DCS typically involves the amount of security provided when sending or receiving data to or from assets of associated DCS equipment. In most factory or industrial environments, complex and sometimes hazardous operations are performed within a given manufacturing environment. Therefore, potentially harmful consequences can occur if, for example, a network-connected controller is unintentionally accessed, or even worse, if a rogue machine or individual intentionally sabotages it. Consequently, most currently known DCS deployments provide capabilities such as hardware and software firewalls that not only protect connections between networks of different vendors but also protect against traffic of a specific nature transmitted through the DCS network.

[0004] The excessive networking functions of DCS, as described earlier, have traditionally been manufactured into separate hardware network components. This has led to an explosion of stock-scale units (SKUs), ultimately resulting in inefficient and costly operations for supporting and maintaining hardware network deployments. Over the years, advancements in networking that improve scalability by providing extension capabilities have alleviated these problems to some extent. However, such extension capabilities continue to handle a small set of functions, such as data switching or routing, without the availability of both capabilities bundled together. Other advancements include the spine-leaf architecture popular in data centers. However, these architectures are not suitable for DCS deployments due to the extensive interconnections required between leaf and spine components in geographically distributed DCS systems. Summary of the Invention

[0005] This disclosure relates to a modular control network architecture for industrial distributed control systems.

[0006] In a first embodiment, an apparatus is disclosed that connects to at least one input / output (I / O) module and at least one controller of an industrial distributed control system. The apparatus includes a control unit comprising a processor that executes operating software implementing operational configuration for the apparatus. At least one I / O port is connected to the control unit and can be configured by the operating software to enable port configuration for connecting at least one I / O module to the apparatus. An expansion unit is connected to the control unit and has at least one expansion port connected to at least one controller. This expansion port connects at least one controller to the control unit for transmitting data and control signals to and from the at least one controller to at least one I / O module. A security unit regulates access to the apparatus based on one or more security attributes.

[0007] In a second embodiment, a system is disclosed that connects to at least one input / output (I / O) module and at least one controller of an industrial distributed control system. The system includes a first control network module having a control component including a processor that executes operating software implementing operational configuration for the first control network module. The system also includes at least one I / O port connected to the control component. This at least one I / O port can be configured by the operating software to enable port configuration for connecting at least one I / O module to the first control network module. An expansion component is connected to the control component and at least one expansion port connected to at least one controller, the expansion port connecting the at least one controller to the control component for transmitting data and control signals to and from the at least one controller to the at least one I / O module. The system additionally includes a configuration component for transmitting I / O port configurations to the operating software of the control component, and a security component for regulating access to the first control module based on one or more security attributes.

[0008] Other technical features will be apparent to those skilled in the art from the following figures, description and claims. Attached Figure Description

[0009] To gain a more complete understanding of this disclosure, reference is now made to the following description in conjunction with the accompanying drawings, in which:

[0010] Figure 1 An exemplary industrial process control and automation system is shown;

[0011] Figure 2 An exemplary control node for a channel-level mesh topology using I / O modules is shown;

[0012] Figure 3 The present invention illustrates a modular control network architecture. Figure 2 An exemplary control node;

[0013] Figure 4 The control network module according to the present invention is illustrated schematically;

[0014] Figure 5 The active-active deployment of two interconnected control network modules according to the present invention is illustrated schematically.

[0015] Figure 6 The active-passive deployment of two control network modules according to the present invention is illustrated schematically; and

[0016] Figure 7 The diagram schematically illustrates an active-active deployment of two control network modules, each operating independently of the other. Detailed Implementation

[0017] These figures (discussed below) and the various embodiments used to illustrate the principles of the invention in this patent document are by way of example only and should not be construed as limiting the scope of the invention in any way. Those skilled in the art will understand that the principles of the invention can be implemented in any type of suitably arranged device or system.

[0018] Industrial automation is a key characteristic of modern industrial plants. Industrial process control and automation systems require increasing flexibility in their implementation and operation. Particularly in complex DCS deployments, network interconnection between various assets and components becomes problematic. For example, a large number of unmanaged Ethernet switch SKUs adds complexity and lacks loop detection due to the absence of spanning tree detection methods. The fixed port speeds of unmanaged Ethernet switches necessitate the selection and use of different switches to provide the required network speeds. More importantly, Ethernet switches often lack security or firewall features because all ports are open. Ethernet networks and their assets are vulnerable to malicious intrusion from third parties. Furthermore, switches offer few or no opportunities for fault diagnosis or upgrades and rely on third-party vendor replacements for updates. Understandably, network complexity can lead to unintentional misconfigurations of the Ethernet network, resulting in deployment failures. By providing modules designed to support several network functions, SKU proliferation and security deficiencies in highly distributed and complex DCSs can be avoided.

[0019] Figure 1 An exemplary DCS 100 according to this disclosure is shown. (As...) Figure 1 As shown, system 100 includes various components that facilitate the production or processing of at least one product or other material. For example, system 100 is used herein to facilitate the control of components within one or more plants 101a-101n. Each plant 101a-101n represents one or more processing facilities (or one or more portions thereof), such as one or more manufacturing facilities for producing at least one product or other material. Generally, each plant 101a-101n may implement one or more processes and may be referred to individually or collectively as a process system. A process system generally refers to any system or portion thereof configured to process one or more products or other materials in a certain way.

[0020] exist Figure 1In this system 100, the Purdue model of process control is used for implementation. In the Purdue model, "Level 0" may include one or more sensors 102a and one or more actuators 102b. Sensors 102a and actuators 102b represent components in the process system that can perform any of a wide variety of functions. For example, sensor 102a may measure a wide variety of characteristics in the process system, such as temperature, pressure, or flow rate. Additionally, actuators 102b may alter a wide variety of characteristics in the process system. Sensors 102a and actuators 102b may represent any other or additional components in any suitable process system. Each sensor in sensor 102a includes any suitable structure for measuring one or more characteristics in the process system. Each actuator in actuators 102b includes any suitable structure for operating or influencing one or more conditions in the process system. Sensors and actuators are generally referred to as field devices or process instrumentation.

[0021] At least one network 104 is coupled to sensor 102a and actuator 102b. Network 104 facilitates interaction with sensor 102a and actuator 102b. For example, network 104 can transmit measurement data from sensor 102a and provide control signals to actuator 102b. Network 104 can represent any suitable network or combination of networks. As a specific example, network 104 can represent an Ethernet network, an electrical serial network (such as a HART or Foundation Fieldbus network), a pneumatic control signal network, or any other or additional type of network.

[0022] In the Purdue model, "Level 1" may include one or more controllers 106 coupled to network 104. Among other things, each controller 106 may use measurements from one or more sensors 102a to control the operation of one or more actuators 102b. For example, controller 106 may receive measurement data from one or more sensors 102a and use that measurement data to generate control signals for one or more actuators 102b. Multiple controllers 106 may also operate in a redundant configuration, such as when one controller 106 operates as a primary controller and another controller 106 operates as a backup controller (which is synchronized with the primary controller and can take over the primary controller in case of failure). Each controller 106 includes any suitable structure for interacting with one or more sensors 102a and controlling one or more actuators 102b. Each controller 106 may, for example, represent a multivariable controller, such as a Robust Multivariable Predictive Control Technique (RMPCT) controller or other types of controllers implementing Model Predictive Control (MPC) or other Advanced Predictive Control (APC). As a specific example, each controller 106 may represent a computing device running a real-time operating system.

[0023] Two networks 108 are coupled to controller 106. Networks 108 facilitate interaction with controller 106, such as by transmitting data to and from controller 106. Network 108 can represent any suitable network or combination of networks. As a specific example, network 108 can represent a pair of Ethernet networks or a pair of redundant Ethernet networks, such as a fault-tolerant Ethernet (FTE) network from Honeywell International Inc.

[0024] At least one switch / firewall 110 couples network 108 to two networks 112. The switch / firewall 110 can transmit traffic from one network to another. The switch / firewall 110 can also block traffic from one network from reaching another. The switch / firewall 110 includes any suitable construct for providing communication between networks, such as a Honeywell Control Firewall (CF9) device. Network 112 can represent any suitable network, such as a pair of Ethernet networks or an FTE network.

[0025] In the Purdue model, "Level 2" may include one or more machine-level controllers 114 coupled to network 112. Machine-level controllers 114 perform various functions to support the operation and control of controllers 106, sensors 102a, and actuators 102b that can be associated with a specific industrial device, such as a boiler or other machine. For example, machine-level controllers 114 may record information collected or generated by controller 106, such as measurement data from sensor 102a or control signals for actuator 102b. Machine-level controllers 114 may also execute applications that control the operation of controller 106, thereby controlling the operation of actuator 102b. Furthermore, machine-level controllers 114 may provide secure access to controller 106. Each machine-level controller in machine-level controllers 114 includes any suitable structure for providing access to, control of, or operation of a machine or other individual device. Each machine-level controller in machine-level controllers 114 may, for example, represent a server computing device running the Microsoft Windows operating system. Although not shown, different machine-level controllers 114 can be used to control different devices in the process system (where each device is associated with one or more controllers 106, sensors 102a and actuators 102b).

[0026] One or more operator stations 116 are coupled to network 112. Operator station 116 represents a computing or communication device that provides user access to machine-level controller 114, which in turn can provide user access to controller 106 (and possibly sensors 102a and actuators 102b). As a specific example, operator station 116 may allow a user to view the operational history of sensors 102a and actuators 102b using information collected by controller 106 and / or machine-level controller 114. Operator station 116 may also allow a user to adjust the operation of sensors 102a, actuators 102b, controller 106, or machine-level controller 114. Furthermore, operator station 116 may receive and display warnings, alerts, or other messages or displays generated by controller 106 or machine-level controller 114. Each operator station in operator station 116 includes any suitable architecture for supporting user access and control of one or more components in system 100. Each operator station in operator station 116 may, for example, represent a computing device running the Microsoft Windows operating system.

[0027] At least one router / firewall 118 couples network 112 to two networks 120. Router / firewall 118 includes any suitable structure for providing communication between the networks, such as a secure router or a combined router / firewall. Network 120 can represent any suitable network, such as a pair of Ethernet networks or an FTE network.

[0028] In the Purdue model, "Level 3" may include one or more unit-level controllers 122 coupled to network 120. Each unit-level controller 122 is typically associated with a unit in the process system, representing a collection of different machines operating together to implement at least a portion of the process. The unit-level controllers 122 perform various functions to support the operation and control of components at lower levels. For example, a unit-level controller 122 may log information collected or generated by components at lower levels, execute applications controlling components at lower levels, and provide secure access to components at lower levels. Each unit-level controller in the unit-level controllers 122 includes any suitable structure for providing access to, control of, or associated operation of one or more machines or other devices in the process unit. Each unit-level controller in the unit-level controllers 122 may, for example, represent a server computing device running the Microsoft Windows operating system. Although not shown, different unit-level controllers 122 may be used to control different units in the process system (where each unit is associated with one or more machine-level controllers 114, controllers 106, sensors 102a, and actuators 102b).

[0029] Access to the unit-level controller 122 can be provided by one or more operator stations 124. Each operator station in the operator stations 124 includes any suitable structure for supporting user access and control of one or more components in the system 100. Each operator station in the operator stations 124 may, for example, represent a computing device running the Microsoft Windows operating system.

[0030] At least one router / firewall 121 couples network 120 to two networks 128. Router / firewall 121 includes any suitable structure for providing communication between the networks, such as a secure router or a combined router / firewall. Network 128 can represent any suitable network, such as a pair of Ethernet networks or an FTE network.

[0031] In the Purdue model, "Level 4" may include one or more facility-level controllers 130 coupled to network 128. Each facility-level controller 130 is typically associated with one of the facilities 101a-101n, which may include one or more processing units implementing the same, similar, or different processes. The facility-level controllers 130 perform various functions to support the operation and control of components in lower levels. As a specific example, a facility-level controller 130 may execute one or more Manufacturing Execution System (MES) applications, scheduling applications, or other or additional facility or process control applications. Each facility-level controller 130 includes any suitable structure for providing access to, control of, or associated operation of one or more processing units in the processing facility. Each facility-level controller 130 may, for example, represent a server computing device running the Microsoft Windows operating system.

[0032] Access to the plant-level controller 130 can be provided by one or more operator stations 132. Each operator station in the operator station 132 includes any suitable architecture for supporting user access and control of one or more components in the system 100. Each operator station in the operator station 132 may, for example, represent a computing device running the Microsoft Windows operating system.

[0033] At least one router / firewall 134 couples network 128 to one or more networks 136. Router / firewall 134 includes any suitable structure for providing communication between networks, such as a secure router or a combined router / firewall. Network 136 can represent any suitable network, such as an enterprise-wide Ethernet or other network, or all or part of a larger network (such as the Internet).

[0034] In the Purdue model, "Level 5" may include one or more enterprise-level controllers 138 coupled to network 136. Each enterprise-level controller 138 is typically capable of performing planning operations for multiple plants 101a-101n and controlling various aspects of plants 101a-101n. Enterprise-level controllers 138 may also perform various functions to support the operation and control of components within plants 101a-101n. As a specific example, an enterprise-level controller 138 may execute one or more order processing applications, enterprise resource planning (ERP) applications, advanced planning and scheduling (APS) applications, or any other or additional enterprise control applications. Each enterprise-level controller in the enterprise-level controllers 138 includes any suitable structure for providing access to, control of, or related operations of one or more plants. Each enterprise-level controller in the enterprise-level controllers 138 may, for example, represent a server computing device running the Microsoft Windows operating system. In this document, the term "enterprise" refers to an organization having one or more plants or other processing facilities to manage. It should be noted that if a single plant 101a needs to be managed, the functions of the enterprise-level controller 138 can be integrated into the plant-level controller 130.

[0035] Access to the enterprise-level controller 138 can be provided by one or more operator stations 140. Each operator station in the operator stations 140 includes any suitable architecture for supporting user access and control of one or more components in the system 100. Each operator station in the operator stations 140 may, for example, represent a computing device running the Microsoft Windows operating system.

[0036] The various levels of the Purdue model may include other components, such as one or more databases. The database associated with each level may store any suitable information associated with that level or one or more other levels of system 100. For example, a historical database 141 may be coupled to network 136. Historical database 141 may represent a component storing various information about system 100. Historical database 141 may, for example, store information used during production scheduling and optimization. Historical database 141 represents any suitable structure used for storing information and facilitating information retrieval. Although shown as a single centralized component coupled to network 136, historical database 141 may be located elsewhere in system 100, or multiple historical databases may be distributed across different locations within system 100. In a particular embodiment, Figure 1 The various controllers and operator stations in the system can represent computing devices. For example, each controller in the system may include one or more processing devices 142 and one or more memories 144 for storing instructions and data used, generated, or collected by the processing devices 142.

[0037] Each controller in the controller group may also include at least one network interface 146, such as one or more Ethernet interfaces and / or Ethernet switches or wireless transceivers and routers. Additionally, each operator station in the operator station group may include one or more processing devices 148 and one or more memories 150 for storing instructions and data used, generated, or collected by the processing devices 148. Each operator station in the operator station group may also include at least one network interface 152, such as one or more Ethernet interfaces and / or Ethernet switches or wireless transceivers.

[0038] In some industrial distributed control systems, a mesh topology can be used at the channel level of the I / O modules. Figure 2 The diagram illustrates an exemplary mesh topology at the channel level of the I / O modules. Enterprise controller 138, operator station 140, historical database 141, network 136, and controller 106 are referenced above. Figure 1 The I / O module 203 has a connection to... Figure 1 Multiple channels 102 of field devices 102a and 102b. For simplicity, in Figure 2 In this diagram, the I / O interface is not shown as separate from the I / O module, but rather as a single unit. In addition to network 136, I / O network 207 is also shown. I / O network 207 is a dedicated network. Multiple controllers 203 are connected to I / O network 207, while other controllers 203 are connected to network 136.

[0039] Typically, field equipment allows for monitoring of manufacturing processes, such as physical properties (e.g., temperature, pressure, flow rate), and provides control over the processes, such as opening / closing valves, increasing / decreasing pressure, and adjusting heating or cooling units. Centralizing control and information collection is necessary to improve plant efficiency. Each process in the plant has one or more input characteristics (i.e., control characteristics) and one or more output characteristics (i.e., process conditions).

[0040] An automation system using a DCS (Distributed Control System) consists of sensors, controllers, and associated computers distributed throughout an industrial plant. DCS systems use methods such as publish / subscribe and request / response to move data from controllers to supervisory client servers and applications. DCS provides automated decision-making based on real-time data processing or by modifying data collected from ongoing processes in response to user actions.

[0041] In a DCS system, each controller can be assigned to a specific input / output module and a set of channels and field devices associated with that specific input / output module. The groups of channels and associated field devices are fixed by the type of I / O module, its physical location, or its network location. Therefore, flexibility is limited. However, in current mesh topology networks, the relationship between a controller and a set of I / O channels is no longer a constraint between a controller and a specific set of I / O channels defined by a single I / O module, but rather represents the I / O channels of multiple I / O modules meshed to a set of control nodes (i.e., controllers).

[0042] The I / O electronics have been decoupled from a specific controller. Specifically, Figure 2 I / O modules are shown, each with multiple channels at the channel level, where all channels of the I / O modules are connected in a mesh topology. Figure 2 In this approach, not only are the I / O electronics decoupled from a specific controller, but also, utilizing a mesh topology at the channel level of the I / O modules, multiple controllers can be associated with a single I / O module and its channels. Each of the multiple controllers can be connected to one or more channels of a single I / O module.

[0043] When using general-purpose I / O modules from Honeywell Process Solutions, the I / O mesh is particularly valuable for engineering efficiency. Channel types are configured in software using techniques such as general-purpose I / O modules. Available types include analog inputs, analog outputs, digital inputs, and digital outputs.

[0044] Employing a mesh topology for I / O module channels offers several advantages. I / O modules can be geographically located close to field devices, regardless of which specific controller will use which I / O signals and devices. This advantage supports current design simplification needs by removing field junction boxes and deploying more I / O in the field, compared to traditional control center and remote instrument enclosure (RIE) deployments.

[0045] Another advantage is the ability to use standard Ethernet as the remote medium, including switched and ring topologies. Adopting standard Ethernet technology allows for greater flexibility, stability and reliability, enhanced security, and greater scalability. Further Ethernet connectivity provides enhanced security at the I / O level and is ISA99 certified. However, this disclosure is not limited to Ethernet technology.

[0046] In the advanced view, Figure 2The system 200 includes multiple I / O modules 203, each of which is connected to multiple field devices 202 via a channel 102 of the I / O module 203. A channel provides data for an industrial process. Process data from field devices or process control policy instructions provided to field devices are referred to herein as a channel. Channel 102 is configured in a mesh topology. Figure 2 A representative field device 202 is shown, but even if not shown, each I / O module 203 can be connected to multiple field devices 202 via channel 102. Hundreds of field devices 202 can be connected to I / O modules 203 via channel 102. Field devices 202 are devices used to generate process information or to actuate processing units by controlling valves, regulators, or other processing devices. Exemplary field devices 202 can be sensors, actuators, or other processing devices, such as valves, flow controllers, and other devices. Mesh topology allows signals traveling to and from the channels, and thus to and from the field devices, to reach the necessary controllers, regardless of which I / O module the channel is associated with. Multiple controllers can control the outputs of different channels belonging to the same I / O module. Similarly, multiple controllers can control the inputs of different channels belonging to the same I / O module. Connectivity can be achieved via, for example, Ethernet or wireless technology.

[0047] System 200 also includes multiple controllers 106. Each controller 106 is configured to receive signals from any one of a plurality of channels 102 within a plurality of I / O modules 203 and to transmit signals to any one of those channels 102, wherein the channels 102 are connected in a mesh topology. Just as each channel 102 represents process data, this data is specified for a particular controller 106. By configuring the channels 102 in a mesh topology, specific data in a particular channel can be connected to the appropriate particular controller 106, regardless of which I / O module the channel resides in. In other words, data collected from field devices via a channel can be used for any controller via the mesh topology of the channels. Similarly, signals or commands from a controller can be used for any channel via the mesh topology of the channels.

[0048] Each controller 106 generates an information flow for further processing. In some embodiments, controller 106 may be arranged in an electronically interconnected topology, such as via Ethernet technology. Suitable topologies include, but are not limited to, ring topologies and star topologies. A ring topology involves interconnecting controllers, where each controller communicates with two other controllers. A star topology is where one or more controllers are interconnected with the remaining controllers. When using these topologies, it is not necessary to interconnect each controller to all other controllers. In one embodiment, each controller is connected to at least one or two other controllers. Using controller topologies such as these, controllers can also share information with each other. Exemplary controllers include application control systems, field device managers, remote terminal units, embedded controllers, programmable logic controllers, virtual nodes, or another device for receiving information and sending instructions to field device 202. Controller 106 may be operated via a human-machine interface or via a pre-programmed automation system.

[0049] System 200 also includes network 136, which can be a supervisory control network used to guide information flow to and from controller 106. Network 136 receives information flow from controller 106 and transmits control policy information to controller 106. When a requesting node needs data from a responding node, it sends a request for the data via the network, and the responding node then returns the data via the network. Network 136, as the supervisory control network, includes a supervisory control computer and interface hardware to enable communication and control between the client server and the industrial plant.

[0050] System 200 may also include a data center housing an enterprise controller 138, operator stations 140, and / or a historical database 141 for receiving and storing information streams from network 136. The sorted data can then be retrieved for analysis. Data storage may be local storage, remote storage, or cloud storage.

[0051] The mesh topology of the I / O module channels is used. Figure 2 The diagram illustrates that the connection between controller 106 and channels 102 of I / O module 203 can be made in several different ways. For example, connection 211 shows controller 106 connected to different channels 102 of different I / O modules 203. A controller 106 can be connected to multiple channels 102 within the same I / O module 203. I / O modules connect I / O to the system via a network. This network can be, for example, a supervisory network or a dedicated I / O network. A controller connected to network 136 can be connected to channels 102 of I / O modules that are also connected to network 136. A controller connected to network 136 can be connected to channels 102 of I / O modules connected to I / O network 207 via connection 215.

[0052] Large-scale Ethernet deployments may require a large number of managed Ethernet switch configurations, especially in DCS systems employing Fault-Tolerant Ethernet (FTE) redundant network configurations. For example, a DCS system with 150 FTE nodes would require eight pairs of Ethernet switches with 330 ports to interconnect the 150 FTE nodes. This includes an FTE network consisting of 165 primary and 165 secondary switch pairs. Furthermore, in industrial plants, it is not uncommon to see several pairs of Ethernet or fiber optic cables with lengths ranging from 100 meters to 10 kilometers used for interconnecting the various nodes in a DCS. In mesh topologies, this interconnection burden in plant equipment (such as unmanaged network switches and cables) becomes even greater, where the relationship between a controller and a set of I / O channels is no longer a constraint between a controller and a specific set of I / O channels defined by a single I / O module, but rather shows I / O channels of multiple I / O modules meshed to a set of control nodes (i.e., controllers).

[0053] Figure 3 This schematically illustrates a modular system architecture that helps achieve several functions while reducing complexity during DCS network deployment. Figure 2 The Ethernet network 207 has been replaced by a control network module 310, which includes several key architectural components. These include built-in security, including signed firmware and deep packet inspection protocols. A common platform configuration architecture operates a connectivity component that can be configured and operate multiple wired or fiber optic network ports for interconnection to devices and I / O modules, as well as the supervisory network. A mode selection feature allows users to select the default network port configuration based on the control node's application. A built-in hardware Ethernet switch provides scalability to provide network connectivity to other controllers or to other control nodes. The control network module 310 also includes a configuration component that allows users to easily access and configure new network port functions and easily introduce new connectivity features into the network served by the control network module.

[0054] The control network module 310 can be configured as a single I / O terminal assembly (IOTA) module or interconnected with another control network module 310 via the backplane of a device cabinet or frame, or connected together using data and control cables, to provide an active system IOTA that can easily interconnect multiple controllers 106 or I / O modules 203. The control network module 310 can also be interconnected in various other configurations, such as... Figure 6 The active-passive system (IOTA) deployment shown in the diagram and Figure 7 The image shows an active-active system-independent (IOTA) deployment. These various deployments will be explained in more detail below.

[0055] Figure 4The components of the control network module 310 are schematically shown. The control network module 310 includes a mode component 410, a control component 420, a configuration component 430, a security component 440, an expansion component 450 connected to multiple expansion ports 465a-n, a system connectivity port 460, and multiple I / O ports 455a-n.

[0056] The mode unit 410 acts as a rotary switch, allowing the user to select and implement pre-programmed deployment functions stored in the operating software 435, such as security policies and firewalls, virtual LANs (VLANs), and / or Quality of Service (QoS) networking. The control unit 420 is responsible for performing necessary functions via the configuration unit 430 based on the mode unit selection made by the user. The processor 432 executes the operating software 435, which runs the programmed functions of the control network module 310.

[0057] The control network module 310 can also be programmed to perform customized network functions when used in conjunction with the configuration unit 430. The configuration unit 430 consists of configurable hardware and software that enables dedicated custom port configurations to perform these dedicated network functions. The configuration unit 430 provides a separate interface to the control unit 420 to allow for rapid configuration and secure bootstrapping. For example, the configuration unit 430 may include Bluetooth or other wireless communication hardware modules operating a bidirectional wireless software protocol for establishing bidirectional communication between the control network module 310 and a remotely located handheld device (not shown) such as a smartphone, tablet, or laptop. Users of the handheld device can directly query the port configuration settings of I / O ports 455a-n and extension ports 465a-n and set customized port settings, such as port speed, Switched Port Analyzer (SPAN), and VLAN configuration.

[0058] Security component 440 includes both hardware and software applications that provide one or more security attributes, such as hardware authentication, firewall, secure boot, signed firmware, and deep packet inspection. Security component 440 is responsible for ensuring authentication when other components of the network module connect to external sources. For example, the security component will provide appropriate security authentication to external handheld devices that connect to or attempt to connect to configuration module 430. Additionally, the security component monitors I / O ports 455a-n and expansion ports 465a-n to detect any changes at the ports. Security component 440 notifies control component when an irregularity is detected. Control component can then send a status message of the detected irregularity to a supervisory controller (such as enterprise controller 138) or to operator station 140 via system connectivity port 460 and network connection 136.

[0059] Expansion unit 450 is a hardware Ethernet switch that provides a mechanism for horizontally scaling and expanding port connectivity of control network module 310. Using wired or wireless Ethernet or serial network protocols, and employing a hybrid of copper or fiber optic cables, data and control signals to and from controller 106 are connected to expansion unit 450 via expansion ports 465a-n and cables 127a-n. A software-defined internal network between expansion units separates data and control connections to data plane connection 451 and control plane connection 453. Control plane connection 453 is used to transmit firmware updates and configuration data, such as port speed, SPAN, and VLANs, to expansion units and expansion ports 465a-n. Control plane connection 453 is also used to send status messages from expansion ports 465a-n to control unit 420, such as notifications of the status and configuration of ports 465a-n and the operational status of expansion unit 450 to controller 136 or operator station 140. Since the data plane connection 451 does not have the burden of transmitting control signals between the control unit 420 and the expansion unit 450, the data signals traveling on the data plane connection 451 travel uninterrupted at a much higher rate than they would have in the case where data signals and control signals are shared.

[0060] The control network module 310 is connected to the I / O module 203 and devices of the control node via multiple connectivity ports consisting of I / O ports 455a-n, and is connected to the supervisory layer of the DCS via system connectivity port 460. Ports 455a-n and system connectivity port 460 are connected to the control unit 420. System connectivity port 460 provides an "uplink" to the supervisory layer of the DCS via network connection 136 to provide the DCS with notifications of the status and / or changes of the control network module 310. This may include, for example, cable breaks or reconnections of new devices, and any changes in port speed. Additionally, notifications may be sent to the DCS to monitor port drop rates and abnormal traffic rates of connected I / O modules 203 or other connected devices, such as attempts to connect unknown devices to I / O ports 455a-n and port shutdowns due to MAC jitter / looping. Depending on the type of I / O module 203 or other device connected to the control node, a connection to the I / O module 203 is formed using wired or wireless Ethernet or serial network protocols, a hybrid of copper or fiber optic cables, and cables 126a-n to the I / O ports 455a-n.

[0061] The above description and Figure 4The control network module 310 shown can be configured as a single I / O terminal assembly (IOTA) module or interconnected with another control network module 310 via the backplane of a cabinet or frame to provide active system IOTA that can be easily interconnected to multiple I / O modules 203 and controllers 106 in a DCS control node. Alternatively, the two network control modules 310 can be connected together using data and control cables.

[0062] Figure 5 An active-active deployment of a first interconnect control network module 310 and a second interconnect control network module 310' is schematically illustrated. The first and second control network modules 310 and 310' work together to provide network services across a larger network of I / O modules 203, devices, and controllers 106 within a control node. In this active-active deployment, the control network modules 310, 310' operate to send and receive data and control signals between each control network module 310, 310' and the I / O modules 203, devices, and controllers 106 connected to various I / O ports and extension ports. Each control network module 310, 310' operates synchronously to provide similar network characteristics to the node they are working on. Each control network module 310, 310' is interconnected using a data plane connection 451 and a control plane connection 453. Configuration and firmware updates from the system connectivity component 460 of the control network module 310 are also sent via the control plane connection 453 to the control component 420' of the control network module 310' for component and port allocation and use by the control network module 310'. Therefore, only the system connectivity component 460 of the control network module 310 is used to connect the interconnect modules 310, 310' to the supervisory network 136. The control plane connection 453 is also used to send monitoring and reporting messages from the I / O ports 455a-n of the control network module 310 and the I / O port 455'an of the control network module 310' to their respective control components 420, 420'. For example, notifications of the status and configuration of I / O ports 455a-n and 455'an, as well as the operational status of extension components 450 and 450', can be sent to the controller 138 or operator station 140.

[0063] Data and control signals traveling between the connected I / O modules 203 and devices via I / O port 455'an and cable 126'an, and to the controller 106 via expansion port 465'an and cable 127'an, are transmitted from the control unit 420' of the control network module 310' to the control unit 420' of the control network module 310' using data plane connection 451. Since data plane connection 451 does not have the burden of transmitting control signals between control units 420, 420', the data signals traveling on data plane connection 451 travel uninterrupted at a much higher rate than they would have in the case of shared data and control signals.

[0064] Figure 6 An active-passive deployment of two control network modules is schematically illustrated. In this active-passive deployment, the first control network module 310 assumes the active role, while the second expansion module 610 assumes the passive role. In this pairing, module 610 includes a security component 640 and an expansion component 650 connected to expansion ports 665a-n. This deployment pairing is typically used to extend or horizontally scale the first control node to another local or remote DCS control node. Expansion ports 665a-n can be connected via cables 627a-n to other wired controllers 106 of the remote control node or to a gateway or router of the wireless control node.

[0065] In this deployment, the second expansion module 610 does not have a control component 420 for the functions of the control module 610. The expansion component 450 of the active control network module 310 includes an extension feature that allows the connection of the expansion component 450 of the active network control module 310 to send and receive control and data signals to and from the expansion component 650 via data plane connection 651 and control plane connection 653. The security component 640 included in the expansion module 610 continues to act as an authentication agent and interacts directly with the control component 420 using connection 645 before enabling the extension functions. It should be noted that the expansion module 610 does not necessarily have to be a separately configured module with only the security component 640 and the expansion component 650, and the extension ports 665a-n. The expansion module 610 can be configured using the control network module 310 and its operating software 435 enabled, using only the security component and expansion component of the control network module 310 required to provide the extension features just described.

[0066] Figure 7The diagram schematically illustrates an active-active deployment of two control network modules, each operating independently of the other. In this deployment pairing, control network modules 310 and 310' are deployed independently of each other, but are placed side-by-side for several reasons, such as to save space and / or handle special remote situations. For example, control network module 310 uses an advanced software controller to handle wired control nodes for providing predictive control of plant operations, while control network module 310' handles wireless control nodes, monitoring and controlling the operations of another industrial plant in the same or different industrial plants. In this deployment pairing, control components 420 and 420' interact, only passing configuration and other control information to each other. Messages and other notifications as described above can be passed from control component 420' to control component 420 via control plane connection 453. Notifications are sent to supervisory controllers such as controller 138 via network connection 136. In this deployment pairing, no data sharing occurs between modules 310 and 310' to ensure the secure deployment of the two interconnected systems.

[0067] It may be advantageous to define certain words and phrases used throughout this patent document. The terms “comprising” and “including” and their derivatives mean, but are not limited to, these. The term “or” is inclusive, meaning and / or. The phrase “associated with” and its derivatives may mean, including, contained within, interconnected with, containing, contained in, connected to or connected with, coupled to or coupled with, communicable with, cooperating with, interleaved, juxtaposed, proximate with, combined with or combined with, having, possessing the properties of, having a relationship with or having a relationship with, etc. When used with a list of items, the phrase “at least one of” means that different combinations of one or more of the listed items may be used, and only one item in the list may be required. For example, “at least one of A, B, and C” includes any of the following combinations: A, B, C, A and B, A and C, B and C, and A and B and C.

[0068] The descriptions in this application should not be construed as implying that any particular element, step, or function is a fundamental or critical element that must be included within the scope of the claims. The scope of the subject matter protected by the patent is defined only by the permitted claims. Furthermore, none of the claims is intended to invoke 35 U.SC §112(f) with respect to any of the appended claims or claim elements, unless the exact words “means for…” or “steps for…” followed by a participle phrase identifying the function are used in a particular claim. The use of terms such as (but not limited to) “mechanism,” “module,” “device,” “unit,” “component,” “element,” “part,” “device,” “machine,” “system,” “processor,” or “controller” within the claims is understood to refer to structures known to a person skilled in the art, further modified or enhanced by the features of the claims themselves, and is not intended to invoke 35 U.SC §112(f).

[0069] While this disclosure has described certain embodiments and generally associated methods, variations and substitutions of these embodiments and methods will be apparent to those skilled in the art. Therefore, the foregoing description of exemplary embodiments does not limit or restrict this disclosure. Other changes, substitutions, and modifications are possible without departing from the spirit and scope of this disclosure as defined in the following claims.

Claims

1. An apparatus for connecting at least one input / output I / O module (203) and at least one controller (106) to an industrial distributed control system, the apparatus comprising a first control network module (310), the first control network module (310) comprising: The control unit (420) includes a processor (432) that executes operating software (435) that implements the operating configuration for the first control network module (310). Mode component (410) for selecting a preprogrammed operation configuration in the preprogrammed operation configuration. At least one I / O port (455) is connected to the control unit (420), and the at least one I / O port (455) can be configured by the operating software (435) to enable port configuration for connecting the at least one I / O module (203) to the first control network module (310). An expansion component (450) is connected to the control component (420) and has at least one expansion port (465) connected to the at least one controller (106). The expansion port (465) connects the at least one controller (106) to the control component (420) for transmitting data and control signals to and from the at least one controller (106) to the at least one I / O module (203). The control component (420) is connected to the expansion component (450) using a data plane connection (451) and a separate control plane connection (453). Configuration component (430) for transmitting I / O port configurations to the operating software (435) of the control component (420). and A security component (440) is used to regulate access to the first control network module (310) based on one or more security attributes.

2. A system connected to at least one input / output I / O module (203) and at least one controller (106) of an industrial distributed control system, the system comprising a first control network module (310), the first control network module (310) comprising: The control unit (420) includes a processor (432) that executes operating software (435) that implements one or more operating configurations. A mode component (410) is used to select one of the operation configurations; At least one I / O port (455) is connected to the control unit (420), and the at least one I / O port (455) can be configured by the operating software to enable port configuration for connecting the at least one I / O module (203) to the first control network module (310). An expansion component (450) is connected to the control component (420) and has at least one expansion port (465) connected to the at least one controller (106). The expansion port (465) connects the at least one controller to the control component (420) for transmitting data and control signals to and from the at least one controller (106) to the at least one I / O module (203). Configuration component (430) is used to transmit I / O port configurations to the operating software of the control component (420); and A security component (440) is used to regulate access to the first control network module (310) based on one or more security attributes.

3. The system according to claim 2, wherein the configuration component (430) includes a wireless communication module that operates using a wireless communication protocol to receive I / O port configuration from the at least one I / O port (455) and the at least one extended port (465), and load port configuration into the operating software (435) from a remotely located handheld communication device.

4. The system according to claim 2, wherein, The first control network module (310) control unit (420) is connected to the expansion unit (450) using an independent data plane connection (451) and an independent control plane connection (453), wherein data signals are transmitted between the control unit (420) and the expansion unit (450) using the data plane connection (451), and control signals are transmitted between the control unit (420) and the expansion unit (450) along the control plane connection (453).

5. The system of claim 4, wherein the system further comprises a second control network module (310') connected to the first control network module (310), wherein the control component (420) of the first control network module (310) is interconnected to the control component (420') of the second control network module (310') using the data plane connection (451) and the control plane connection (453). The first control network module (310) and the second control network module (310') operate synchronously, thereby providing a similar I / O port and expansion port configuration between the at least one I / O port (455) and the at least one expansion port (465) of the first control network module (310) and the at least one I / O port (455') and the at least one expansion port (465') of the second control network module (310').

6. The system according to claim 4, wherein the extension component (450) of the first control network module (310) is connected to the extension component (650) of the second control network module (610) using the data plane connection (651) and the control plane connection (653). The extension component (650) of the second control network module (610) operates in a passive role to extend the at least one extension port (455) of the first control network module (310) to an additional extension port (665) at the second control network module (610).

7. The system of claim 6, wherein the second control network module (610) includes a security component (640) connected to the control component (420) of the first control network module (310), wherein the security component (640) of the second control network module (610) regulates access to the additional extension port (665) of the second control network module (610) based on one or more security attributes.

8. The system of claim 4, wherein the system further comprises a second control network module (310') connected to the first control network module (310), the control component (420) of the first control network module (310) being interconnected to the control component (420') of the second control network module (310') using the control plane connection (453); and The first control network module (310) and the second control network module (310') operate independently of the other, thereby sharing at least one of configuration, messages and control information between the first control network module (310) and the second control network module (310').

Citation Information

Patent Citations

  • System and method for dynamically scalable soft hart modems

    US20190384249A1