A controller self-preservation method and system in a trusted configuration mode
By introducing a self-preservation function block in the controller to monitor and respond to abnormal conditions in real time, the compatibility and stability issues that may be introduced after the integration of the trusted protection system are resolved, the self-protection and recovery of the controller is realized, and the stability and security of the system are improved.
Patent Information
- Application Number
- CN202411494582.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-24
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2044-10-24
AI Technical Summary
When integrating trusted protection systems into traditional distributed control systems, compatibility and stability issues may be introduced, leading to serious consequences such as system crashes. Existing technologies lack effective keep-alive mechanisms to ensure the safe and stable operation of power systems.
Introduce a self-keep alive function block and configure the controller self-keep alive function block to monitor and respond to abnormal conditions in real time. Through self-protection measures such as restarting the controller, clearing memory, and terminating abnormal processes, the stable operation of the controller is ensured, and the keep alive method is selected through collaboration with the host computer.
The controller's self-protection and recovery capabilities in trusted configuration mode are significantly enhanced, improving system stability and reliability, reducing the risk of system crashes, and improving human-computer interaction and system security.
Smart Images

Figure CN119356983B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of industrial automation control, and in particular to a controller self-preservation method and system in a trusted configuration mode. Background Art
[0002] With the rapid development and widespread adoption of internet technology, network security issues have become increasingly prominent. Malicious attacks such as computer viruses, Trojans, and hackers are not only frequent but also increasingly sophisticated and covert, posing a significant challenge to the stable operation of power systems. As a vital component of national critical infrastructure, the security of power systems is directly linked to the stable operation of the nation's economy and society, as well as the daily lives of the general public. Trusted protection systems, as an emerging security measure, offer enhanced safety and reliability. Therefore, their application in power systems can better ensure their safe and stable operation.
[0003] However, in actual applications, integrating the trusted protection system into the traditional distributed control system may introduce new risks and challenges. These risks and challenges mainly come from compatibility issues between the two systems and stability issues of the trusted protection system itself. If not handled properly, it may have a negative impact on the stability and reliability of the original system, and may even lead to serious consequences such as system crashes. In order to ensure that when the trusted protection system is unstable, it will not affect the safe operation of the original distributed system, it is necessary to design a complete keep-alive mechanism. This keep-alive mechanism needs to have real-time monitoring, alarm, and recovery functions, and can quickly take corresponding measures to ensure the stable operation of the original distributed system when anomalies occur in the trusted protection system.
[0004] In summary, designing a keep-alive method for a trusted protection system is of great significance for ensuring the safe and stable operation of the power system. Summary of the Invention
[0005] In view of the problems existing in the prior art, the present invention provides a method and system for self-preservation of a controller in a trusted configuration mode, which significantly enhances the self-protection and recovery capabilities of the controller in the trusted configuration mode.
[0006] The present invention is achieved through the following technical solutions:
[0007] 1. A controller self-keep alive method in a trusted configuration mode, comprising the following steps:
[0008] Step 1: Configure the controller self-keep alive function block and download the self-keep alive function block to the controller;
[0009] Step 2: The controller executes the self-keep alive function block function according to the configuration items of the self-keep alive function block;
[0010] Step 3: The controller sends the execution result to the host computer in real time. If the execution result is abnormal, the keep-alive mode is selected and sent to the controller;
[0011] Step 4: The controller performs the corresponding keep-alive operation according to the selected keep-alive method and sends the keep-alive result.
[0012] Preferably, the configuration process of the self-keep alive functional block is as follows:
[0013] Configure the input items, parameter items and output items of the self-keep alive function block;
[0014] Input items include the keep-alive enable of the self-keep alive function block, the controller total load threshold, and the controller memory growth rate threshold pin;
[0015] The parameters include the total load that the controller can bear, the abnormal time of process running memory, and the keep-alive option of the self-keep function block;
[0016] The output items include trusted chip operating status output, controller total load output, corresponding important task sub-load output, controller process running memory ratio output, controller process running memory ratio growth rate output, controller load abnormality alarm output, controller memory abnormality alarm output and controller keep-alive execution result output.
[0017] Preferably, the keep-alive option of the self-keep-alive function block is a process that can be killed when performing a keep-alive operation.
[0018] Preferably, the controller executes the self-keep alive function block function periodically according to the configuration item of the self-keep alive function block.
[0019] Preferably, the configuration item periodically executes the self-keep alive function block function in the following order:
[0020] Get the link status between the application process and the trusted chip. If the link is normal, the output item of the self-keep alive function block - the trusted chip running status value is incremented by 1.
[0021] Obtain the total load of the controller's task execution, the corresponding important task execution load, and the process execution memory ratio, and output them to the total load output pin, important task sub-load output pin, and execution memory ratio output pin of the controller's self-keep alive function block;
[0022] Determine whether the controller is in an abnormal state based on the configured input items and parameter items:
[0023] When the controller total load exceeds the controller total load threshold continuously within the abnormal time but the corresponding important task sub-load value is normal, the controller load abnormal alarm output value is set to TRUE;
[0024] When the controller total load is continuously lower than the controller total load threshold within the abnormal time and the corresponding important task sub-load value is normal, the controller load abnormal alarm output value is set to FALSE;
[0025] If the controller process running memory usage growth rate continuously exceeds the controller memory growth rate threshold within an abnormal period of time, the controller memory abnormality alarm output value is set to TRUE; otherwise, it is set to FALSE.
[0026] Determine the load abnormality alarm output value and the memory abnormality alarm output value. If one of them is TRUE, set the quality of this self-preservation function block to "OVERFLOW", otherwise it is "GOOD".
[0027] Preferably, the controller sends the execution result to the host computer in real time. When the execution result is abnormal, a keep-alive mode is selected and sent to the controller, including:
[0028] The controller sends the execution results to the host computer in real time. When the host computer detects that the self-keep alive function block is in an abnormal state, it changes the mark of the self-keep alive function block, which serves as a warning signal.
[0029] The controller selects the keep-alive mode and sets the keep-alive enable input to a pulse and sends it to the controller.
[0030] Preferably, the mark is to change the color of the self-keep alive function block.
[0031] Preferably, the controller performs corresponding keep-alive operations according to the selected keep-alive mode and sends the keep-alive results, including:
[0032] The controller periodically executes the self-keep alive function block. When the running state is abnormal, it detects the keep alive enable input item of the self-keep alive function block. If a pulse is detected, the keep alive operation is performed according to the keep alive mode. After the execution is completed, the execution result is output to the keep alive execution result output item. If the execution is successful, the quality of the self-keep alive function block is set to "GOOD", otherwise it remains "OVERFLOW".
[0033] At the same time, returning to step 2, the controller periodically executes the self-keep alive function block function according to the configuration item of the self-keep alive function block.
[0034] Preferably, when the keep-alive operation is executed and the controller operation state is still abnormal, the execution result is sent to the controller in real time and the controller fault is checked.
[0035] A controller self-preservation system in a trusted configuration mode includes:
[0036] A configuration module, used for configuring a controller self-keep alive function block and downloading the self-keep alive function block to the controller;
[0037] A keep-alive execution module is used for the controller to execute the self-keep-alive function block function according to the configuration items of the self-keep-alive function block;
[0038] The diagnostic module is used for the controller to send the execution results to the host computer in real time. When the execution results are abnormal, the keep-alive mode is selected and sent to the controller;
[0039] The keep-alive module is used for the controller to perform corresponding keep-alive operations according to the selected keep-alive mode and send the keep-alive results.
[0040] Compared with the prior art, the present invention has the following beneficial technical effects:
[0041] The present invention introduces a self-preservation function block, which significantly enhances the self-protection and recovery capabilities of the controller in the trusted configuration mode. During the operation of the controller, once any abnormal condition is detected, the self-preservation function block can respond quickly and initiate the corresponding preservation measures, thereby ensuring the continuous and stable operation of the controller application, effectively reducing the potential impact of the trusted configuration on the controller's original application, and greatly improving the overall stability of the system. In addition, the present invention also takes advantage of the visual display of the function block to present the controller's operating status and self-protection results in an intuitive manner. This design enhances the system's human-computer interaction capabilities, ensuring that engineering personnel can quickly perceive changes in the controller's operating status and make timely responses. Furthermore, through the collaborative work of the host computer and the controller, the controller's operating status is promptly notified to the control personnel, who can then choose a preservation method based on experience, thereby further improving the reliability and safety of the control system. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0043] Figure 1 This is a flow chart of a controller self-preservation method in a trusted configuration mode of the present invention. DETAILED DESCRIPTION
[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0045] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0046] See Figure 1 A controller self-preservation method in a trusted configuration mode includes the following steps:
[0047] Step 1: Configure the controller self-keep alive function block and download the self-keep alive function block to the controller.
[0048] The self-preservation function block is a preventative mechanism that monitors the controller's operating status and automatically restores or maintains normal operation when potential issues are detected. In embedded systems, industrial automation, and similar fields, controllers often need to operate stably for extended periods of time. The self-preservation function block monitors the controller's operating status and performance parameters to promptly detect and address potential anomalies. When the controller encounters issues such as overload, memory overflow, or program errors, the function block automatically triggers appropriate protective measures, such as restarting the controller, clearing memory, terminating abnormal processes, and restoring default configurations, to prevent controller crashes or system downtime.
[0049] The configuration method of the self-keep alive function block is as follows:
[0050] My keep-alive function block contains the following pins: input items, parameter items and output items;
[0051] 1. Configure the input items of the self-keep alive function block: self-keep alive function block keep alive enable, controller total load threshold, and controller memory growth rate threshold pin;
[0052] Self-Keep Alive Function Block Keep Alive Enable is a specific setting or instruction that allows or enables the self-keep alive function of the controller.
[0053] 2. Configure the parameters of the self-keep alive function block: the total load that the controller can withstand, the abnormal time of process running memory, the self-keep alive function block keep alive options (that is, the processes that can be killed when the keep alive operation is executed), that is, the list of trusted processes that the controller needs to terminate;
[0054] The trusted process list contains all processes in the controller that need to be monitored by the self-keep function block. When these processes experience abnormal conditions, the self-keep function block selects and terminates them to prevent them from causing further damage to the controller. When setting up the trusted process list, you need to carefully consider which processes are critical, which processes are likely to cause problems, and which processes will have the least impact on the system if terminated. Each process in the list should have a unique identifier (such as a process ID or name) so that the self-keep function block can accurately identify and terminate them.
[0055] 3. Configure the output items of the self-keep alive function block:
[0056] Output of trusted chip operating status; output of total controller load; output of corresponding important task sub-load; output of controller process running memory ratio; output of controller process running memory ratio growth rate; output of controller load abnormality alarm; output of controller memory abnormality alarm; output of controller keep-alive execution result.
[0057] Configuring the self-keep alive function block at the host computer is to set the values of the input items and parameter items of the self-keep alive function block at the host computer side, wherein the values of the input items may be derived from a section of logic output.
[0058] Step 2: The controller periodically executes the self-keep alive function block function according to the configuration item of the self-keep alive function block;
[0059] The keep-alive enable controller receives the keep-alive function block and starts the operation according to the configured input and parameter values:
[0060] If the controller application process and the trusted chip heartbeat link are established normally, the trusted chip operation status output value of the self-keep alive function block will be incremented by 1 in each operation cycle;
[0061] The self-preservation function block periodically obtains the total load of the controller, the corresponding important task sub-load and the process running memory ratio, and outputs these operating parameters to the total load output pin, important task sub-load output pin and running memory ratio output pin of the controller self-preservation function block.
[0062] Compare the operating parameters with the parameter thresholds to determine whether the controller is in an abnormal state and output the corresponding alarm signal and quality:
[0063] When the controller total load exceeds the controller total load threshold continuously within the abnormal time, but the corresponding important task sub-load value is normal, the controller load abnormal alarm output value is set to TRUE (correct);
[0064] When the controller total load is continuously lower than the controller total load threshold within the abnormal time, and the corresponding important task sub-load value is normal, the controller load abnormal alarm output value is set to FALSE (error);
[0065] If the controller process running memory usage growth rate continuously exceeds the controller memory growth rate threshold within an abnormal period of time, the controller memory abnormality alarm output value is set to TRUE (correct).
[0066] The self-preservation function block determines whether the load abnormality alarm output value and the memory abnormality alarm output value are TRUE. If one of them is TRUE, the quality of the self-preservation function block is set to "OVERFLOW", otherwise it is set to "GOOD".
[0067] Step 3: The controller sends the execution result to the host computer in real time. If the execution result is abnormal, the controller will be reminded to select the keep-alive mode and send it to the controller;
[0068] The controller sends these operating results to the host computer in real time. When the host computer detects that the operating status of the self-preservation function block is abnormal (the quality of the function block is "OVERFLOW"), it changes the display color of the self-preservation function block to prompt the control personnel (abnormal is "red", normal is "green").
[0069] When the self-keep alive function block is operating abnormally, the control personnel will choose whether to keep the controller alive based on the actual situation on site. If keep alive is necessary, the control personnel will select the keep alive method based on engineering experience, and at the same time set the pulse value of the enable pin (keep alive instruction) and send it to the controller.
[0070] Step 4: The controller performs the corresponding keep-alive operation according to the selected keep-alive method and sends the keep-alive result.
[0071] When the controller receives a keepalive command, it performs the corresponding keepalive operation based on the keepalive parameters, such as killing trusted processes and restoring the controller to the default configuration. If the keepalive operation is successful, the controller keepsalive execution result output is set to TRUE; otherwise, it is set to FALSE. The execution result and output value are fed back to the host computer in real time, allowing the controller to determine whether the keepalive operation is successful and whether the controller's operating status has improved.
[0072] Controller self-preservation function block related alarms and quality recovery conditions: When the controller total load is continuously lower than the controller total load threshold within the abnormal time and the corresponding important task sub-load value is normal, the controller load abnormal alarm output value is set to FALSE; when the controller process running memory ratio growth rate is continuously lower than the controller memory growth rate threshold within the abnormal time, the controller memory abnormal alarm output value is set to FALSE.
[0073] When the controller load abnormality alarm output value and the controller process running memory ratio growth rate are both FALSE, the quality of the self-preservation function block is set to "GOOD".
[0074] By introducing a self-preservation function block, this application enables the controller to respond quickly when an abnormal condition is detected and initiate corresponding preservation measures, thereby ensuring the continuous and stable operation of the application. This greatly reduces the risk of system crashes and data loss due to system failures or incorrect operations. Secondly, in the trusted configuration mode, the design of the self-preservation function block fully considers the impact on the controller's original application, ensuring that the normal operation of the application will not be interfered with or interrupted when the preservation measures are initiated. In addition, because the self-preservation function block can respond to and handle abnormal conditions in a timely manner, the overall stability of the system is significantly improved. This helps to reduce production stoppages and maintenance costs caused by system instability.
[0075] Through the visual display of function blocks, the operating status and self-protection results of the controller can be presented to engineering personnel in an intuitive manner. This enables engineering personnel to quickly perceive the state changes of the controller and make timely responses and adjustments. Through the collaborative work of the host computer and the controller, the control personnel can obtain the operating status information of the controller in real time and select the appropriate keep-alive method based on experience. This design not only improves the reliability of the control system, but also enhances the security of the system and reduces the risks caused by human operational errors. In addition, the design of the self-preservation function block has certain flexibility and scalability, and can be customized and optimized according to different application scenarios and requirements. This enables the technical solution to adapt to a wider range of control system requirements and improve the adaptability and competitiveness of the system. Through the introduction of the self-preservation function block, the controller can achieve self-repair and recovery to a certain extent, reducing the downtime and maintenance costs caused by system failures. This is of great significance for improving production efficiency and reducing operating costs.
[0076] To sum up, the technical solution of this application significantly enhances the self-protection and recovery capability, stability and human-computer interaction capability of the control system by introducing the self-preservation function block, while improving the reliability and safety of the control system and reducing maintenance costs. It has broad application prospects and market potential.
[0077] Correspondingly, the present application also provides a controller self-keep alive system in a trusted configuration mode, including:
[0078] A configuration module, used for configuring a controller self-keep alive function block and downloading the self-keep alive function block to the controller;
[0079] A keep-alive execution module is used for the controller to execute the self-keep-alive function block function according to the configuration items of the self-keep-alive function block;
[0080] The diagnostic module is used for the controller to send the execution results to the host computer in real time. When the execution results are abnormal, the keep-alive mode is selected and sent to the controller;
[0081] The keep-alive module is used for the controller to perform corresponding keep-alive operations according to the selected keep-alive mode and send the keep-alive results.
[0082] It should be noted that in the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of each module is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules can be combined or integrated into another device, or some features can be ignored or not executed. The modules described as separate components may or may not be physically separated. The components displayed as modules may be one physical unit or multiple physical units, that is, they may be located in one place, or they may be distributed in multiple different places. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment.
[0083] In addition, the modules in the various embodiments of the present invention may be integrated into a single processing unit, each module may exist physically separately, or two or more modules may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0084] An electronic device provided in an embodiment of the present application includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the steps of the controller self-preservation method in the trusted configuration mode described in any of the above embodiments are implemented.
[0085] Another electronic device provided in an embodiment of the present application may further include: an input port connected to the processor for transmitting multimodal data collected by an external acquisition device to the processor; a display unit connected to the processor for displaying the processing results of the processor to the outside world; and a communication module connected to the processor for enabling communication between the electronic device and the outside world. The display unit may be a display panel, a laser scanning display, etc.; the communication method adopted by the communication module includes but is not limited to mobile high-definition link technology (HML), universal serial bus (USB), high-definition multimedia interface (HDMI), wireless connection (including wireless fidelity technology (WiFi), Bluetooth communication technology, low-power Bluetooth communication technology, and communication technology based on IEEE802.11s).
[0086] An embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the controller self-preservation method in the trusted configuration mode described in any of the above embodiments are implemented.
[0087] The computer-readable storage medium involved in this application includes random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium known in the technical field.
[0088] For the description of the relevant parts of the controller self-preservation system, electronic device, and computer-readable storage medium in the trusted configuration mode provided in the embodiments of this application, please refer to the detailed description of the corresponding parts of the controller self-preservation method in the trusted configuration mode provided in the embodiments of this application, and will not be repeated here. In addition, the parts of the above-mentioned technical solutions provided in the embodiments of this application that are consistent with the implementation principles of the corresponding technical solutions in the prior art are not described in detail to avoid excessive elaboration.
[0089] The above content is only for explaining the technical idea of the present invention and cannot be used to limit the protection scope of the present invention. Any changes made on the basis of the technical solution in accordance with the technical idea proposed by the present invention shall fall within the protection scope of the claims of the present invention.
Claims
1. A controller self-preservation method in a trusted configuration mode, characterized in that: The following processes are included: Step 1: Configure the controller self-keep alive function block and download the self-keep alive function block to the controller; The configuration process of the self-keep alive function block is as follows: Configure the input items, parameter items and output items of the self-keep alive function block; Input items include the keep-alive enable of the self-keep alive function block, the controller total load threshold, and the controller memory growth rate threshold pin; The parameters include the total load that the controller can bear, the abnormal time of process running memory, and the keep-alive option of the self-keep function block; Output items include trusted chip operating status output, controller total load output, corresponding important task sub-load output, controller process running memory ratio output, controller process running memory ratio growth rate output, controller load abnormality alarm output, controller memory abnormality alarm output, and controller keep-alive execution result output; Step 2: The controller executes the self-keep alive function block function according to the configuration item period item of the self-keep alive function block; The configuration item periodically executes the self-keep alive function block function in the following order: Get the link status between the application process and the trusted chip. If the link is normal, the output item of the self-keep alive function block - the trusted chip running status value is incremented by 1. Obtain the total load of the controller's task execution, the corresponding important task execution load, and the process execution memory ratio, and output them to the total load output pin, important task sub-load output pin, and execution memory ratio output pin of the controller's self-keep alive function block; Determine whether the controller is in an abnormal state based on the configured input items and parameter items: When the controller total load exceeds the controller total load threshold continuously within the abnormal time but the corresponding important task sub-load value is normal, the controller load abnormal alarm output value is set to TRUE; When the controller total load is continuously lower than the controller total load threshold within the abnormal time and the corresponding important task sub-load value is normal, the controller load abnormal alarm output value is set to FALSE; If the controller process running memory usage growth rate continuously exceeds the controller memory growth rate threshold within an abnormal period of time, the controller memory abnormality alarm output value is set to TRUE; otherwise, it is set to FALSE. Determine the load abnormality alarm output value and the memory abnormality alarm output value. If either one is TRUE, set the quality of this self-keep alive function block to "OVERFLOW", otherwise to "GOOD". Step 3: The controller sends the execution result to the host computer in real time. If the execution result is abnormal, the keep-alive mode is selected and sent to the controller; The controller sends the execution results to the host computer in real time. When the host computer detects that the self-keep alive function block is in an abnormal state, it changes the mark of the self-keep alive function block, which serves as a warning signal. The controller selects the keep-alive mode and sets the keep-alive enable input to a pulse and sends it to the controller. Step 4: The controller performs the corresponding keep-alive operation according to the selected keep-alive mode and sends the keep-alive result, including: The controller periodically executes the self-keep alive function block. When the operating state is abnormal, it checks the keep alive enable input of the self-keep alive function block. If a pulse is detected, the keep alive operation is performed according to the keep alive mode. After the execution is completed, the execution result is output to the keep alive execution result output item. If the execution is successful, the quality of the self-keep alive function block is set to "GOOD", otherwise it remains "OVERFLOW". At the same time, returning to step 2, the controller periodically executes the self-keep alive function block function according to the configuration item of the self-keep alive function block.
2. The controller self-preservation method in a trusted configuration mode according to claim 1, characterized in that: The self-keep alive function block keep alive option is a process that can be killed when performing a keep alive operation.
3. The controller self-preservation method in a trusted configuration mode according to claim 1, characterized in that: The mark is to change the color of the self-keep alive function block.
4. The controller self-preservation method in a trusted configuration mode according to claim 1, characterized in that: If the controller is still in an abnormal state after a keep-alive operation is executed, the execution result is uploaded in real time and the controller fault is checked.
5. A system for executing the controller self-preservation method in the trusted configuration mode according to any one of claims 1 to 4, characterized in that: include: A configuration module, used for configuring a controller self-keep alive function block and downloading the self-keep alive function block to the controller; A keep-alive execution module is used for the controller to execute the self-keep-alive function block function according to the configuration items of the self-keep-alive function block; The diagnostic module is used for the controller to send the execution results to the host computer in real time. When the execution results are abnormal, the keep-alive mode is selected and sent to the controller; The keep-alive module is used for the controller to perform corresponding keep-alive operations according to the selected keep-alive mode and send the keep-alive results.
Citation Information
Patent Citations
System application program keep-alive method and device, equipment, server and medium
CN115567960A
Monitoring method and system of vehicle domain controller system
CN117348459A