PLC instruction real-time communication system, method, device and equipment in virtual environment
By configuring a real-time operating system and optimizing the transmission path in a virtual environment, the problem of low efficiency of PLC instruction communication in the virtual environment is solved, and efficient communication in hard real-time and strong real-time scenarios is achieved.
Patent Information
- Application Number
- CN202410774796.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-17
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2044-06-17
Smart Images

Figure CN118732600B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present disclosure relate to the field of real-time communication technology, and in particular, to a system, method, apparatus, and device for real-time communication of PLC instructions in a virtual environment. Background Art
[0002] PLC (Programmable Logic Controller) can be used for sequential control and logic control. As the demand for control applications increases, PLC manufacturers have gradually added more practical functions, such as PID control and analog conversion.
[0003] Industrial control security scenarios often involve hard and strict real-time requirements. Therefore, the soft PLC in a virtual environment must meet not only the requirements of soft real-time scenarios, but also those of hard and strict real-time scenarios. Typically, PLC real-time control is performed within a fixed cycle. From a traditional control perspective, the efficiency of control algorithms executed by soft PLCs in virtual environments is unpredictable, thus reducing the communication efficiency of PLC instructions. Summary of the Invention
[0004] The embodiments described herein provide a system, method, apparatus, and device for real-time communication of PLC instructions in a virtual environment, which overcome the above-mentioned problems.
[0005] In a first aspect, according to the present disclosure, a PLC instruction real-time communication system in a virtual environment is provided, comprising: an instruction cache module, a resource binding module, an instruction forwarding module, and a transmission path optimization module;
[0006] The instruction cache module is configured to store the generated virtual PLC instruction in a real-time operation space, and to send the virtual PLC instruction stored in the real-time operation space to the instruction forwarding module when the virtual PLC instruction meets an instruction sending condition, wherein the real-time operation space is obtained by dividing the virtual operating system;
[0007] The resource binding module is used to bind the resource mapping relationship between the virtual machine corresponding to the virtual operating system and the host machine, so that the instruction forwarding module forwards the virtual PLC instruction based on the data transmission resources of the host machine;
[0008] The instruction forwarding module is configured to receive the virtual PLC instruction sent by the instruction cache module, and forward the virtual PLC instruction to the transmission path optimization module based on the data transmission resources of the host machine;
[0009] The transmission path optimization module is configured to receive the virtual PLC instruction forwarded by the instruction forwarding module and optimize the instruction transmission path so as to transmit the virtual PLC instruction to the industrial control device based on the instruction transmission path.
[0010] In a second aspect, according to the present disclosure, a method for real-time communication of PLC instructions in a virtual environment is provided, comprising:
[0011] Storing the generated virtual PLC instructions in a real-time operation space, wherein the real-time operation space is obtained by dividing the virtual operating system;
[0012] Optimize instruction transmission path;
[0013] The virtual PLC instruction is read from the real-time operation space, and the virtual PLC instruction is transmitted to the industrial control device based on the instruction transmission path.
[0014] In a third aspect, according to the present disclosure, a device for real-time communication of PLC instructions in a virtual environment is provided, comprising:
[0015] A storage module, configured to store the generated virtual PLC instructions in a real-time operation space, wherein the real-time operation space is obtained by dividing the virtual operating system;
[0016] Optimization module, used to optimize the instruction transmission path;
[0017] A transmission module is used to read the virtual PLC instruction from the real-time operation space and transmit the virtual PLC instruction to the industrial control device based on the instruction transmission path.
[0018] In a fourth aspect, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps of the real-time communication method of PLC instructions in a virtual environment are implemented as in any of the above embodiments.
[0019] In a fifth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of the real-time communication method of PLC instructions in a virtual environment are implemented as in any of the above embodiments.
[0020] The embodiment of the present application provides a real-time communication system for PLC instructions in a virtual environment, comprising: an instruction cache module, a resource binding module, an instruction forwarding module, and a transmission path optimization module; the instruction cache module is used to store generated virtual PLC instructions in a real-time operation space, and when the virtual PLC instructions meet the instruction sending conditions, send the virtual PLC instructions stored in the real-time operation space to the instruction forwarding module, where the real-time operation space is obtained by dividing the virtual operating system; the resource binding module is used to bind the resource mapping relationship between the virtual machine corresponding to the virtual operating system and the host machine, so that the instruction forwarding module forwards the virtual PLC instructions based on the data transmission resources of the host machine; the instruction forwarding module is used to receive the virtual PLC instructions sent by the instruction cache module, and forward the virtual PLC instructions to the transmission path optimization module based on the data transmission resources of the host machine; the transmission path optimization module is used to receive the virtual PLC instructions forwarded by the instruction forwarding module, and optimize the instruction transmission path to transmit the virtual PLC instructions to the industrial control equipment based on the instruction transmission path. In this way, by configuring the real-time operating system in the virtual machine, it is convenient to process PLC instructions, and by binding the resource mapping between the virtual machine and the host machine, the virtual machine and the host machine achieve a one-to-one correspondence of resources, effectively improving the communication efficiency of PLC instructions in the virtual environment.
[0021] The above description is only an overview of the technical solutions of the embodiments of the present application. In order to more clearly understand the technical means of the embodiments of the present application, they can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the embodiments of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the drawings of the embodiments will be briefly described below. It should be noted that the drawings described below only relate to some embodiments of the present disclosure and are not intended to limit the present disclosure.
[0023] Figure 1 This is a structural diagram of a real-time communication system for PLC instructions in a virtual environment provided by the present disclosure.
[0024] Figure 2A It is a schematic diagram of the framework of a soft PLC provided by the present disclosure.
[0025] Figure 2B This is a RTAI / Linux dual-kernel architecture design diagram provided by the present invention.
[0026] Figure 3 This is a flow chart of a real-time communication method for PLC instructions in a virtual environment provided by the present disclosure.
[0027] Figure 4This is a structural diagram of a PLC instruction real-time communication device in a virtual environment provided by the present disclosure.
[0028] Figure 5 It is a structural diagram of a computer device provided by the present disclosure.
[0029] It should be noted that the elements in the drawings are schematic and not drawn to scale. DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solutions and advantages of the embodiments of the present disclosure more clear, the technical solutions of the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the described embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative work also fall within the scope of protection of the present disclosure.
[0031] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present disclosure belongs. It will be further understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the specification and the relevant art, and will not be interpreted in an idealized or overly formal manner unless otherwise explicitly defined herein. As used herein, a statement that two or more parts are "connected" or "coupled" together shall mean that the parts are joined together either directly or through one or more intermediate components.
[0032] References to "embodiments" herein mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase "embodiment" in various places in the specification does not necessarily refer to the same embodiment, nor does it necessarily refer to independent or alternative embodiments that are mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0033] The term "and / or" in this document simply describes an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can mean: A exists, A and B exist simultaneously, and B exists. Additionally, the character " / " in this document generally indicates that the related objects are in an "or" relationship. Terms such as "first" and "second" are used solely to distinguish one component (or portion of a component) from another component (or portion of a component).
[0034] In the description of this application, unless otherwise specified, "plurality" means more than two (including two), and similarly, "multiple groups" means more than two (including two).
[0035] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.
[0036] Figure 1 This is a structural diagram of a PLC instruction real-time communication system in a virtual environment provided by an embodiment of the present disclosure. Figure 1 As shown, the PLC instruction real-time communication system 10 in a virtual environment includes: an instruction cache module 110 , a resource binding module 120 , an instruction forwarding module 130 and a transmission path optimization module 140 .
[0037] The instruction cache module 110 is used to store the generated virtual PLC instructions in the real-time running space, and send the virtual PLC instructions stored in the real-time running space to the instruction forwarding module 130 when the virtual PLC instructions meet the instruction sending conditions. The real-time running space is obtained by dividing the virtual operating system.
[0038] The instruction cache module 110 realizes the soft PLC function by dividing a real-time operating system (ie, real-time operating space) on the Windows operating system to complete logical functions such as input processing, program execution, and output processing.
[0039] like Figure 2A As shown, the Windows development system includes configuration software 2101, human-machine interface 2102, communication interface 2103, and Windows hardware expansion interface 2104, and communicates with the soft PLC CPU 2106 in the real-time running system through the PLC communication interface 2105, and the soft PLC CPU 2106 is connected to the real-time hardware expansion interface 2107.
[0040] In this embodiment, the soft PLC combines the functions of both computers and PLCs, including on-off control, analog control, mathematical operations, numerical processing, network communication, and PID (Proportional Integral Derivative) regulation. Through a multi-tasking control core, it provides a powerful instruction set, fast and accurate scan cycles, reliable operation, and an open architecture that can connect to various I / O (Input / Output) systems and networks. This allows the soft PLC to provide the same functionality as a hard PLC while also offering the advantages of a PC (Personal Computer) environment.
[0041] A virtual PLC encapsulates the functionality of a traditional PLC within software. Virtual PLC system functionality is based on traditional PLCs, and therefore they share similar operating principles. After the user completes the program, the soft PLC system cyclically scans the program, storing the scanned data in a buffer area. When an output command is executed, the data is output. Because virtual PLCs possess the functional features of traditional PLCs while inheriting the advantages of PCs, they offer high-speed data processing and powerful network communication capabilities.
[0042] The virtual PLC instruction is a control instruction compiled by the virtual PLC based on the control requirements, and the virtual PLC instruction is added to the real-time operation space and waits for being sent.
[0043] In this embodiment, the instruction cache module 110 is used to divide a real-time running space (for example, a process with the highest execution priority) on the Windows operating system in the virtual machine, which can ensure efficient communication of virtual PLC instructions at the software control level.
[0044] The resource binding module 120 is used to bind the resource mapping relationship between the virtual machine corresponding to the virtual operating system and the host machine, so that the instruction forwarding module 130 forwards the virtual PLC instruction based on the data transmission resources of the host machine.
[0045] Among them, the resource binding module 120 binds the virtual machine CPU and the host machine physical CPU to each other based on the Openstack NUMA virtual machine CPU (Central Processing Unit) binding technology, and designs large page memory and other methods to improve the efficiency of the virtual machine to ensure the normal operation of the RTAI-Linux real-time operating system.
[0046] OpenstackNUMA virtual machine CPU binding design, such as: view the NUMA topology of the current physical server; view the idle status of the logical CPU; enable NUMATopologyFilter; create NovaFlavor; configure the virtual machine NUMA topology; configure the virtual machine CPU binding policy; start the test virtual machine; view the CPU binding status of the virtual machine.
[0047] The instruction forwarding module 130 is configured to receive the virtual PLC instruction sent by the instruction cache module 110 and forward the virtual PLC instruction to the transmission path optimization module 140 based on the data transmission resources of the host machine.
[0048] Among them, the virtual machine uses the RTAI-Linux real-time operating system to ensure that the internal processes of the virtual machine meet the hard real-time requirements. The RTAI-Linux real-time operating system transmits the PLC virtual instructions to the virtual bridge in the host operating system, and the virtual bridge is responsible for forwarding the virtual instructions.
[0049] The instruction forwarding module 130 enables the operating system in the virtual machine to achieve hard real-time performance when receiving and forwarding virtual PLC instructions.
[0050] The instruction forwarding module 130 adopts RTAI / Linux dual-core structure design, the design structure is as follows Figure 2B shown. Figure 2B It includes: Linux user space 2201, kernel space 2202, Linux task 2203, Linux task 2204, real-time task 2205, real-time task 2206, Linux domain 2207, RTAI domain 2208, scheduling service 2209, domain initialization 2210, interrupt 2211, ADEOS (Adaptive Domain Environment for Operating System) 2212, and hardware platform 2213.
[0051] RTAI Design Principle: RTAI manages the Linux kernel as a subtask by abstracting it from the Linux kernel. RTAI possesses the basic features of a real-time operating system, extending them with new functionality. Currently, RTAI supports processors such as MIPS, PowerPC, X86, CRIS, ARM, and M68K. The hardware abstraction resource layer (HAL) retrieves underlying hardware information and requests and passes them to the upper kernel. In a dual-core architecture, Linux functions can be fully mapped to the RTAI kernel through system redirection, allowing most tasks previously performed in Linux to be completed in the RTAI kernel. The key benefit of this approach is minimal modification to the native system, facilitating portability between different systems. RTAI is a microkernel with real-time processing capabilities, featuring preemptive kernel functionality and real-time properties such as microsecond-level timing. As a fully preemptive kernel, high-priority tasks can be preempted immediately without waiting for the next clock interrupt. Since the RTAI kernel runs the Linux system as a low-priority task, the prerequisite for the Linux system to obtain CPU control is that there are no urgent tasks in the RTAI kernel.
[0052] In some embodiments, the instruction forwarding module 130 includes: a task processing unit, a real-time scheduling unit, a message queue, and a first-in-first-out unit. The task processing unit is configured to receive virtual PLC instructions sent by the instruction cache module 110; the real-time scheduling unit is configured to perform task scheduling on the virtual PLC instructions and send the virtual PLC instructions to the message queue based on the scheduling results; the message queue is configured to store the virtual PLC instructions at a target location based on the sending time of the virtual PLC instructions; and the first-in-first-out unit is configured to forward the virtual PLC instructions to the transmission path optimization module 140 based on the data transmission resources of the host machine when the current message sending location is detected to be the target location.
[0053] Among them, the task processing unit implements the hardware abstraction layer and completes the acquisition and transmission of hardware information; the real-time scheduling unit completes the scheduling and distribution of external tasks; the message queue can store multiple real-time tasks; the first-in-first-out unit uses a first-in-first-out method to receive and output messages in the pipeline.
[0054] In some embodiments, the instruction forwarding module 130 further includes: a memory sharing unit connected to the message queue; a memory sharing unit for storing virtual control instructions in the message queue and sharing the stored virtual control instructions in the message queue in response to a process asynchronous access request.
[0055] Among them, the memory sharing unit is responsible for the asynchronous access of each process to the shared memory area, so as to meet the data access requirements of different asynchronous processes.
[0056] In some embodiments, the instruction forwarding module 130 also includes: a queue management unit, which is connected to the message queue; the queue management unit is used to perform security rule constraints on the virtual control instructions stored in the message queue based on the security group rules corresponding to the virtual operating system to obtain virtual control instructions that meet the security rule constraints, and send the virtual control instructions that meet the security rule constraints to the message queue; the message queue is also used to update the stored virtual control instructions based on the virtual control instructions that meet the security rule constraints.
[0057] The system security rules are screened securely by the queue management unit, so that the message queue can impose security constraints on the virtual control instructions stored therein, thereby effectively ensuring the secure transmission of the virtual control instructions.
[0058] In addition, the instruction forwarding module 130 may also include a function mapping unit, a hard real-time thread unit, and a tool unit. The function mapping unit is used to map Linux user space and kernel space functions to RTAI user space; the hard real-time thread unit is responsible for completing the management of each hard real-time thread; and the tool unit is used to manage the tools required for task execution.
[0059] The specific implementation mechanism of the instruction forwarding module 130 is as follows.
[0060] In terms of interrupt management, the original Linux management method uses the interrupt switch function to directly use assembly language to complete the hardware switch interrupt operation; while the RTAI task core module provides an interrupt flag specifically for interrupt management, and completes the hardware switch interrupt behavior by setting int_flag to 0 or 1.
[0061] For clock timing, periodic timing is used. Two timing modes are designed: one-shot time and periodic time, respectively, for handling single-cycle tasks and cyclic tasks. The processor's time stamp counter (TSC) replaces the original timing method for high-precision timing. This timestamp number is read using a machine instruction (RTSC, such as Read Time Stamp Counter) and stored in the EDX:EAX register pair.
[0062] A custom hardware abstraction layer (HAL) sits between the hardware layer and the kernel, generating a set of system interfaces through which the two interact. This reduces the amount of code required to modify the Linux kernel. A proprietary real-time kernel is also added. The two kernels work together to ensure the high responsiveness of real-time tasks while preventing non-real-time tasks from being left waiting.
[0063] In some embodiments, the real-time scheduling unit is specifically configured to:
[0064] Obtain the domain space type to which the virtual PLC instruction belongs, which domain space types include: a first system operation class and a second system operation class; perform task scheduling on the virtual PLC instruction based on the priority level of the domain space type to which the virtual PLC instruction belongs, and task scheduling is used to describe the storage order of the virtual PLC instruction determined based on the priority level of the domain space type to which the virtual PLC instruction belongs.
[0065] The first system operation class may be, for example, a Linux kernel class, and the second system operation class may be, for example, an RTAI kernel class. Specifically, it may be predefined that the priority of the second system operation class is higher than the priority of the first system operation class, so as to achieve real-time scheduling of tasks of different priorities.
[0066] In addition, this embodiment designs a hardware abstraction layer responsible for storing and transmitting important parameters of system functions and information related to hardware interrupts. It also designs a structured data structure responsible for tracking and collecting all data related to kernel functions, including internal interrupts, external interrupts, function calls, and high-precision clock timing information. The specific design method is as follows.
[0067] The hardware abstraction layer manages the order in which different domains access shared resources by using event pipeline technology, and sets an unchangeable priority for each domain, which is set when the system is initialized.
[0068] When an event arrives, it is arranged in order based on the domain's priority, with earlier domains receiving the right to handle the event before later domains. When an event is passed to a domain, the domain can choose to accept, discard, or terminate. The default state for a domain is to accept; however, if a domain chooses to discard, the event is passed along the pipeline to the next domain. If the event is terminated, it means that the current domain is the last domain, and event delivery stops. When the event is completed, the system calls a special hardware resource abstraction layer service to hand over the CPU to the next domain. The system checks each domain in turn to see if it is in sleep mode. If so, the domain with the lowest priority starts executing the idle event. The idle task is not terminated until the next event arrives. The data structure describing the domain's state and the domain's entry function constitute the interface through which the hardware abstraction layer accesses the domain.
[0069] RTAI User Space Design: The RTAI User Space Design provides a complete set of APIs that map RTAI user space programming to Linux user space. Real-time applications developed in the RTAI environment can not only access Linux system resources but also benefit from the Linux kernel's security protection mechanisms.
[0070] The real-time scheduling unit and the function mapping unit provide support for the implementation of this mapping mechanism. The real-time scheduling unit can schedule tasks under Linux as well as tasks in the RTAI kernel, while the function mapping unit can only schedule tasks in the RTAI user space.
[0071] RTAI / LINUX integration method design: The integration of RTAI and LINUX environment includes three parts: interrupt control integration, fine-grained clock integration, and memory management integration.
[0072] Interrupt control integration primarily focuses on the integration of an interrupt virtualizer. The specific design scheme is as follows: The interrupt virtualizer, serving as the interface between the upper-level operating system and the lower-level hardware layer, controls all hardware interrupts. Interrupt response time is a crucial factor in real-time performance, so interrupt pipeline distribution and soft interrupts are simulated as two interrupt control mechanisms within the RTAI kernel. An optimized interrupt protection scheme is designed within the hardware abstraction layer, with a no-interrupt region established for each domain. This region blocks pipeline segments in any domain. When an interrupt arrives, the current domain's pipeline is blocked and forwarded to lower-priority domains. Interrupts are stored in the interrupt log in the order they arrive. When a domain is executed, a synchronization operation retrieves the pending interrupt request from the interrupt log and executes it. This prevents the protected critical section from being preempted by unexpected interrupts, preventing errors. The interrupt virtualizer is introduced to handle commands in upper-level systems that would normally be executed directly through hardware operations. For lower layers, received interrupts are placed in the interrupt pipeline and distributed along the pipeline using a suitable interrupt distribution strategy.
[0073] The design is based on fine-grained clock integration, including timer integration, which reduces the Linux system's time granularity from milliseconds to microseconds, thereby enhancing the system's real-time performance. In addition to existing timekeeping capabilities, the timer adds periodic and non-periodic modes to enable precise task timing. The RTAI kernel features two timing modes: periodic mode and one-shot mode. Periodic mode is suitable for periodic tasks. Time setting is completed during task initialization, after which the system enters cyclic timing mode. The CPU performs a check each time the timer completes a cycle. One-shot mode is suitable for non-periodic tasks. Time starts at the earliest expiration time of the timer. Once the timer reaches its expiration time, the real-time kernel immediately proceeds with task processing. Accurate clock timing and timer initialization are two key aspects of the one-shot mode. A programmable counter timer emulates the time stamp counter (TSC) to achieve precise timing. The timer's initial value is set by calling the real-time clock's management interface functions, addressing the initialization issues of the single-cycle timer.
[0074] Memory management integration: Memory management integration must be integrated with the memory management mechanisms of the relevant hardware platform. These mechanisms include cache locking, dynamic memory, and shared memory. Dynamic allocation and deallocation strategies are key memory management methods for the real-time kernel. Users utilize the kernel-provided memory management interfaces to perform dynamic memory management for the real-time kernel. This effectively addresses many issues caused by the Linux kernel's existing kernel management mechanisms. By partitioning real-time tasks and userspace tasks, both are allowed to share the same memory. In specific implementations, all real-time processes are allowed to access the contents of the same address space. The overhead of switching memory protection levels can be avoided by using a unified kernel address space, effectively reducing the difficulty of real-time kernel development.
[0075] The transmission path optimization module 140 is configured to receive the virtual PLC instruction forwarded by the instruction forwarding module 130 and optimize the instruction transmission path so as to transmit the virtual PLC instruction to the industrial control device based on the instruction transmission path.
[0076] In some embodiments, the transmission path optimization module 140 includes: an instruction transfer interface, a bridge, and a switch controller; the instruction transfer interface is used to receive virtual PLC instructions forwarded by the instruction forwarding module and send the virtual PLC instructions to the bridge; the bridge is used to send the virtual PLC instructions to the switch controller through the DPDK PMD component; the switch controller is used to optimize the instruction transmission path and transmit the virtual PLC instructions to the industrial control equipment based on the instruction transmission path.
[0077] For example, the virtual network design for a compute node uses the br-int bridge to implement each tenant network, and the br-eth bridge to provide data paths between tenant networks. The dpdkr interface (instruction transfer interface) is used as the interface for attaching the network card to br-eth, and the vhost-user interface is selected as the interface between the virtual machine and br-int. The dpdkr interface sends data packets sent to the eth1 network card to br-eth via shared memory. br-eth then passes the data packets directly to the Openvswitch controller (the switch controller) through the DPDKPMD module for flow table matching and routing. This avoids memory copies and CPU interrupt processing from the network card to br-eth.
[0078] Using the vhost-user interface, data packets from br-int to the virtual machine are stored in shared memory. When Qemu needs to read these data packets, it can directly read them through the mapped address, reducing the number of data packet copies and the number of CPU interrupts.
[0079] The PLC instruction real-time communication system in a virtual environment in this embodiment includes: an instruction cache module, a resource binding module, an instruction forwarding module, and a transmission path optimization module; the instruction cache module is used to store the generated virtual PLC instruction in a real-time operation space, and when the virtual PLC instruction meets the instruction sending condition, send the virtual PLC instruction stored in the real-time operation space to the instruction forwarding module, where the real-time operation space is obtained by dividing the virtual operating system; the resource binding module is used to bind the resource mapping relationship between the virtual machine corresponding to the virtual operating system and the host machine, so that the instruction forwarding module forwards the virtual PLC instruction based on the data transmission resources of the host machine; the instruction forwarding module is used to receive the virtual PLC instruction sent by the instruction cache module and forward the virtual PLC instruction to the transmission path optimization module based on the data transmission resources of the host machine; the transmission path optimization module is used to receive the virtual PLC instruction forwarded by the instruction forwarding module and optimize the instruction transmission path to transmit the virtual PLC instruction to the industrial control equipment based on the instruction transmission path. In this way, by configuring the real-time operating system in the virtual machine, it is convenient to process PLC instructions, and by binding the resource mapping between the virtual machine and the host machine, the virtual machine and the host machine achieve a one-to-one correspondence of resources, effectively improving the communication efficiency of PLC instructions in the virtual environment.
[0080] In some embodiments, it also includes: a rule update module; the rule update module is used to respond to user rule operation requests and perform at least one of the following rule processing operations on the security group rules corresponding to the virtual operating system: security group rule addition, security group rule deletion, security group rule search and security group rule modification.
[0081] When users manipulate security group rules, the agent can add, delete, modify, and query these rules. For example, adding a rule for accessing a virtual machine can be implemented. By modifying the security group implementation, the security group's functionality can be retained while optimizing the network performance of the compute nodes.
[0082] In addition, use the Openflow flow table in Openvswitch as the security group implementation. In the neutron.conf file, change the firewall_driver in the SECURITYGROUP section to use OVSFirewallDriver, and install the ovs_dpdk_firewall.py file on the compute nodes.
[0083] The security group function process is implemented through Openflow based on the design of ovs_dpdk_firewall.py: Establish a basic security group: After creating a security group, two basic security group rules will be generated. First, block data packets entering the virtual machine from the outside. Second, allow all data packets from the virtual machine to the outside. When there is a DHCP (Dynamic Host Configuration Protocol) service in the tenant, add a rule to allow DHCP flow so that the virtual machines in the tenant can obtain IP (Internet Protocol) addresses through DHCP. Set up operations on the agent side to implement the addition, deletion, modification and query of security groups. For example, obtain the port information where the security group is located.
[0084] Optimized design of OpenStack network nodes: br-int is used to isolate tenant networks within the network node design. br-ex is used to connect the OpenStack network to the external network, and each tenant's own virtual router is implemented through the qrouter namespace. The interfaces connecting br-eth and br-ex to the network cards have been optimized to the dpdkr interface program, eliminating the need for kernel-mode Netfilter / Iptables for packets. This reduces the number of memory copies and user-mode / kernel-mode handoffs required when packets are transferred from the network card to the virtual switches br-eth and br-ex, thus optimizing the network performance of OpenStack network nodes.
[0085] The DPDK settings are as follows:
[0086] The server uses an x86 architecture 64-bit processor, the operating system uses the Linux 64-bit operating system, and uses GCC (GNU Compiler Collection) as the compiler.
[0087] The defconfig_x86_64-native-linuxapp-gcc configuration file is used for configuration. The common_linuxapp configuration file also contains configuration items common to the Linux operating system.
[0088] Change CONFIG_RTE_BUILD_COMBINE_LIBS in common_linuxapp to y so that DPDK uses only a single library file, thereby ensuring the implementation of IVSHMEM technology and avoiding multiple memory copies of data packets from the physical network card to the virtual machine's network card.
[0089] Change CONFIG_RTE_EAL_IGB_UIO in common_linuxapp to y. This configuration item ensures that DPDK interface devices can be used in openvswitch.
[0090] Because this article uses the Intel Corporation 82599ES10-Gigabit network card, keep CONFIG_RTE_LIBRTE_IXGBE_PMD = y and configure the PMD drivers of other physical network cards such as CONFIG_RTE_LIBRTE_EM_PMD, CONFIG_RTE_LIBRTE_IGB_PMD, CONFIG_RTE_LIBRTE_I40E_PMD, and CONFIG_RTE_LIBRTE_FM10K_PMD in common_linuxapp to n to reduce the impact of other physical network card drivers.
[0091] Configure CONFIG_RTE_LIBRTE_IXGBE_DEBUG_INIT, CONFIG_RTE_LIBRTE_IXGBE_DEBUG_RX, CONFIG_RTE_LIBRTE_IXGBE_DEBUG_TX, CONFIG_RTE_LIBRTE_IXGBE_DEBUG_TX_FREE, and CONFIG_RTE_LIBRTE_IXGBE_DEBUG_DRIVER in common_linuxapp to n to maximize the performance of the network card.
[0092] Ensure that CONFIG_RTE_LIBRTE_VHOST_USER is configured to y in common_linuxapp to ensure that the system can use the vhost-user interface.
[0093] After modifying the above configuration items, compile and run DPDK and mount the huge page memory using the mount-thugetlbfsnone / mnt / huge / command. This completes the DPDK installation. After installing DPDK, add the DPDK option to the Openvswitch startup command and bind the CPU logical cores reserved in the kernel configuration to the Openvswitch process.
[0094] Adjust the server's network performance to maximum performance. For BIOS settings: Disable all power-saving modes in the BIOS to prevent network forwarding performance from being affected when the system switches to power-saving mode. Select the maximum performance configuration in the CPU Power Management and Performance Management options to fully unleash the CPU's performance and maximize the forwarding performance of the system and virtualization software. Because Turbo Boost is designed to automatically overclock Intel processors to save energy and power, this option should also be disabled in the BIOS. To maximize CPU performance, set the CPU frequency to the highest supported frequency and avoid using the Auto option.
[0095] Configure huge page memory technology and CPU affinity. Configure the Linux kernel as follows: Reserve 1GB of huge page memory in the Linux kernel for use by the virtualization software. Add the following configuration items: default_hugepagesz = 1G hugepagesz = 1G hugepages = 8 to the kernel startup file. Reserve some CPU logical cores for use by the virtualization software. Add the following configuration items: isolcpus = 2, 3, 4, 5, 6, 7, 8 to the kernel startup file. These CPU logical cores will be used during subsequent CPU binding.
[0096] In summary, this embodiment ensures that processes within the virtual machine meet hard real-time requirements by using the RTAI-Linux real-time operating system within the virtual machine. A virtualization platform is constructed based on OPENSTACK technology, and modifications are made to the OPENSTACK network architecture to design a combined soft-hard network to better ensure the communication quality between soft PLC instructions and physical industrial control equipment. After evaluating the factors that cause performance bottlenecks at each node on the NUMA platform in a virtual machine environment, the NUMA platform is optimized from the perspective of vCPU scheduling in the virtual machine environment, including VCPU isolation and physical CPU binding methods, to maximize the operating speed of the soft PLC, thereby achieving real-time communication of PLC instructions in the virtual environment.
[0097] Figure 3 This embodiment provides a flow chart of a method for real-time communication of PLC instructions in a virtual environment. The method for real-time communication of PLC instructions in a virtual environment includes:
[0098] S310: Store the generated virtual PLC instructions in the real-time operation space.
[0099] The real-time runtime space is created by partitioning the virtual operating system. By partitioning a real-time runtime system (i.e., the real-time runtime space) on the Windows operating system to complete logical functions such as input processing, program execution, and output processing, the soft PLC function is realized.
[0100] S320: Optimize the instruction transmission path.
[0101] Among them, by optimizing the OpenStack network components, the data path for virtual instruction forwarding is rebuilt to speed up forwarding efficiency.
[0102] S330: Read the virtual PLC instruction from the real-time operation space, and transmit the virtual PLC instruction to the industrial control device based on the instruction transmission path.
[0103] Therefore, by configuring a real-time operating system in a virtual machine, it is easier to process PLC instructions and effectively improve the communication efficiency of PLC instructions in a virtual environment.
[0104] In some embodiments, it may also include: in response to a user rule operation request, performing at least one of the following rule processing operations on the security group rules corresponding to the virtual operating system: security group rule addition, security group rule deletion, security group rule search, and security group rule modification.
[0105] Figure 4 This is a structural diagram of a PLC instruction real-time communication device in a virtual environment provided by this embodiment. The PLC instruction real-time communication device in the virtual environment includes: a storage module 410, an optimization module 420 and a transmission module 430.
[0106] The storage module 410 is used to store the generated virtual PLC instructions in the real-time operation space. The real-time operation space is obtained by dividing the virtual operating system.
[0107] The optimization module 420 is used to optimize the instruction transmission path.
[0108] The transmission module 430 is configured to read the virtual PLC instructions from the real-time operation space and transmit the virtual PLC instructions to the industrial control device based on the instruction transmission path.
[0109] The real-time communication device for PLC instructions in a virtual environment provided by the present disclosure can execute the above method embodiments. Its specific implementation principles and technical effects can be found in the above method embodiments, and the present disclosure will not repeat them here.
[0110] The present application also provides a computer device. Figure 5 , Figure 5 This is a basic structural block diagram of the computer device in this embodiment.
[0111] The computer device includes a memory 510 and a processor 520 that are interconnected and communicate with each other via a system bus. It should be noted that the figure only shows a computer device with a memory 510 and a processor 520, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to a microprocessor, an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), an embedded device, etc.
[0112] Computer devices can be desktop computers, laptops, PDAs, cloud servers, etc. Computer devices can interact with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.
[0113] The memory 510 includes at least one type of readable storage medium, including non-volatile memory or volatile memory, such as flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic storage, magnetic disk, optical disk, etc. RAM may include static RAM or dynamic RAM. In some embodiments, the memory 510 may be an internal storage unit of a computer device, such as a hard disk or memory of the computer device. In other embodiments, the memory 510 may also be an external storage device of the computer device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, or a Flash Card equipped on the computer device. Of course, the memory 510 may also include both the internal storage unit of the computer device and its external storage device. In this embodiment, the memory 510 is generally used to store the operating system and various application software installed on the computer device, such as the program code of the above-mentioned method. In addition, the memory 510 may also be used to temporarily store various types of data that have been output or are about to be output.
[0114] The processor 520 is generally used to perform the overall operation of the computer device. In this embodiment, the memory 510 is used to store program code or instructions, which include computer operating instructions. The processor 520 is used to execute the program code or instructions stored in the memory 510 or process data, such as the program code for running the above method.
[0115] In this document, a bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. This bus system can be divided into address buses, data buses, and control buses. For ease of illustration, the figure uses only one thick line, but this does not mean that there is only one bus or only one type of bus.
[0116] Another embodiment of the present application further provides a computer-readable medium, which may be a computer-readable signal medium or a computer-readable medium. A processor in a computer reads the computer-readable program code stored in the computer-readable medium, enabling the processor to execute the functional actions specified in each step or combination of steps in the above method, and to generate a device that implements the functional actions specified in each block or combination of blocks in the block diagram.
[0117] Computer-readable media include but are not limited to electronic, magnetic, optical, electromagnetic, infrared memory or semiconductor systems, devices or apparatuses, or any appropriate combination of the foregoing, the memory is used to store program codes or instructions, the program codes include computer operating instructions, and the processor is used to execute the program codes or instructions of the above-mentioned methods stored in the memory.
[0118] For the definitions of memory and processor, please refer to the description of the aforementioned computer device embodiment and will not be repeated here.
[0119] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0120] Each functional unit or module in each embodiment of the present application may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The above-mentioned integrated units may be implemented in the form of hardware or software functional units.
[0121] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.
[0122] In the claims, any reference signs placed between brackets shall not be construed as limiting the claims. The word "comprising" described in the present application does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application can be implemented with the aid of hardware comprising several different elements and with the aid of a suitably programmed computer. In a unit claim that lists several means, several units of these means may be embodied by the same hardware item. The use of first, second, and third etc. does not indicate any order and these words may be interpreted as names. The steps in the above embodiments should not be understood as limiting the order of execution unless otherwise specified.
[0123] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A real-time communication system for PLC instructions in a virtual environment, characterized in that: include: Instruction cache module, resource binding module, instruction forwarding module and transmission path optimization module; The instruction cache module is configured to store the generated virtual PLC instruction in a real-time operation space, and to send the virtual PLC instruction stored in the real-time operation space to the instruction forwarding module when the virtual PLC instruction meets an instruction sending condition. The real-time operation space is obtained by dividing the virtual operating system. The virtual PLC instruction is a control instruction compiled by the virtual PLC based on control requirements. The resource binding module is used to bind the resource mapping relationship between the virtual machine corresponding to the virtual operating system and the host machine, so that the instruction forwarding module forwards the virtual PLC instruction based on the data transmission resources of the host machine; The instruction forwarding module is configured to receive the virtual PLC instruction sent by the instruction cache module, and forward the virtual PLC instruction to the transmission path optimization module based on the data transmission resources of the host machine; The transmission path optimization module is configured to receive the virtual PLC instruction forwarded by the instruction forwarding module and optimize the instruction transmission path so as to transmit the virtual PLC instruction to the industrial control device based on the instruction transmission path; Wherein, the transmission path optimization module includes: an instruction transfer interface, a network bridge and a switch controller; The instruction transfer interface is used to receive the virtual PLC instruction forwarded by the instruction forwarding module and send the virtual PLC instruction to the network bridge; The network bridge is configured to send the virtual PLC instruction to the switch controller through a DPDK PMD component; The switch controller is configured to optimize an instruction transmission path and transmit the virtual PLC instruction to the industrial control device based on the instruction transmission path. The instruction transmission path optimization process is to reconstruct a data path for forwarding the virtual PLC instruction by optimizing OpenStack network components.
2. The system according to claim 1, wherein: The instruction forwarding module includes: a task processing unit, a real-time scheduling unit, a message queue and a first-in first-out unit; The task processing unit is configured to receive the virtual PLC instruction sent by the instruction cache module; The real-time scheduling unit is used to perform task scheduling on the virtual PLC instruction and send the virtual PLC instruction to the message queue based on the scheduling result; The message queue is used to store the virtual PLC instruction at a target location based on the sending time of the virtual PLC instruction; The first-in-first-out unit is configured to forward the virtual PLC instruction to the transmission path optimization module based on the data transmission resources of the host machine when detecting that the current message sending location is the target location.
3. The system according to claim 2, characterized in that The real-time scheduling unit is specifically used to: Acquire the domain space type to which the virtual PLC instruction belongs, where the domain space type includes: a first system operation class and a second system operation class; Based on the priority level of the domain space type to which the virtual PLC instruction belongs, the virtual PLC instruction is task scheduled, and the task scheduling is used to describe the storage order of the virtual PLC instruction determined based on the priority level of the domain space type to which the virtual PLC instruction belongs.
4. The system according to claim 1, wherein: Also includes: rule update module; The rule updating module is configured to perform at least one of the following rule processing operations on the security group rules corresponding to the virtual operating system in response to a user rule operation request: Add, delete, search, and modify security group rules.
5. The system according to claim 2, wherein: The instruction forwarding module further includes: a memory sharing unit, wherein the memory sharing unit is connected to the message queue; The memory sharing unit is used to store the virtual control instructions in the message queue and share the stored virtual control instructions in the message queue in response to a process asynchronous access request.
6. The system according to claim 5, characterized in that The instruction forwarding module further includes: a queue management unit, the queue management unit being connected to the message queue; The queue management unit is configured to perform security rule constraints on the virtual control instructions stored in the message queue based on the security group rules corresponding to the virtual operating system to obtain virtual control instructions that meet the security rule constraints, and send the virtual control instructions that meet the security rule constraints to the message queue; The message queue is further used to update the stored virtual control instructions based on the virtual control instructions that meet the security rule constraints.
7. A method for real-time communication of PLC instructions in a virtual environment, characterized in that: A PLC instruction real-time communication system in a virtual environment applied to any one of claims 1 to 6, comprising: Storing the generated virtual PLC instructions in a real-time operation space, wherein the real-time operation space is obtained by dividing the virtual operating system; the virtual PLC instructions are control instructions compiled by the virtual PLC based on control requirements; Optimizing the instruction transmission path; the instruction transmission path optimization process is to reconstruct the data path for forwarding the virtual PLC instructions by optimizing the OpenStack network components; The virtual PLC instruction is read from the real-time operation space, and the virtual PLC instruction is transmitted to the industrial control device based on the instruction transmission path.
8. A real-time communication device for PLC instructions in a virtual environment, characterized in that: A PLC instruction real-time communication system in a virtual environment applied to any one of claims 1 to 6, comprising: A storage module is configured to store the generated virtual PLC instructions in a real-time operation space, wherein the real-time operation space is obtained by dividing the virtual operating system; the virtual PLC instructions are control instructions compiled by the virtual PLC based on control requirements; An optimization module, configured to optimize an instruction transmission path; wherein the instruction transmission path optimization process is to reconstruct a data path for forwarding instructions of the virtual PLC by optimizing OpenStack network components; A transmission module is used to read the virtual PLC instruction from the real-time operation space and transmit the virtual PLC instruction to the industrial control device based on the instruction transmission path.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the method for real-time communication of PLC instructions in a virtual environment as claimed in claim 7 is implemented.
Citation Information
Patent Citations
Method and apparatus for forwarding data of virtual switching device, and computer device
CN109379269A