Programmable Controller, Control Task Data Processing Method, Medium and Product for Protecting Discrete Manufacturing Processes
By designing a programmable controller with a multi-processor architecture in PLC, deploying real-time and non-real-time virtual machines, and achieving parallel operation of data acquisition and control tasks through asynchronous interrupt signal mechanism, the problems of poor real-time and low security in discrete manufacturing process automation control are solved, and a control system with high real-time and high security is realized.
Patent Information
- Application Number
- CN202510293959.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-13
AI Technical Summary
When existing PLCs realize automated control of discrete manufacturing processes, there are problems such as poor real-time control and low safety.
Design a programmable controller for discrete manufacturing process protection, adopt a multiprocessor architecture, deploy real-time and non-real-time domain virtual machines, and realize data sharing through shared memory. The real-time control task module and the data acquisition task module operate in parallel through the asynchronous interrupt signal mechanism, periodically collect on-site data and store it in shared memory, and the abnormality detection module performs abnormal analysis and processing to improve security.
Through this solution, the security of the discrete manufacturing process control system is improved without affecting the real-time nature of the control task, and data access conflicts between data acquisition instructions and control instructions are avoided.
Smart Images

Figure CN119806941B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of manufacturing processes, specifically to the technical field of discrete manufacturing process control, and particularly to a programmable controller, a control task data processing method, a medium, and a product for discrete manufacturing process protection. Background Art
[0002] The discrete manufacturing industry is undergoing rapid technological innovation. As the core of production line automation, the programmable logic controller (PLC) is responsible for monitoring and controlling key equipment and operations in the manufacturing process. The real-time control tasks in the PLC regularly go through three stages: input sampling, execution of the user control program, and output update according to the scan cycle.
[0003] The inventors found that in the prior art, the process of using a PLC to achieve automated control of industrial processes in discrete manufacturing includes: the PLC reads the status signals of external input devices and writes them into the PLC memory. Then, the PLC reads the data in the memory according to a pre-written program for processing, and finally generates corresponding control instructions and writes them into the memory. Finally, the PLC reads the control instructions in the memory and performs signal conversion to control the actions of external output devices, thereby achieving automated control.
[0004] However, the inventors found that there are still problems of poor control real-time performance and low security in the above prior art. Summary of the Invention
[0005] Embodiments of this application provide a programmable controller, a control task data processing method, a medium, and a product for discrete manufacturing process protection, so as to achieve the effect of ensuring the real-time performance of task control while improving security.
[0006] In a first aspect, embodiments of this application provide a programmable controller for discrete manufacturing process protection. The programmable controller includes multiple processors, and a real-time domain virtual machine, a non-real-time domain virtual machine, and a shared memory are deployed in the programmable controller;
[0007] Data sharing is achieved between the real-time domain virtual machine and the non-real-time domain virtual machine through the shared memory;
[0008] Wherein the real-time domain virtual machine includes a real-time control task module and a data acquisition task module, the non-real-time domain virtual machine includes an anomaly detection module, the real-time control task module is connected to one of the multiple processors, the data acquisition task module is connected to another one of the multiple processors, the anomaly detection module is connected to other processors among the multiple processors, and any two processors among the multiple processors are independent of each other.
[0009] Second aspect, an embodiment of the present application provides a method for controlling task data processing, which is applied to the programmable controller described in the first aspect. The method includes:
[0010] The real-time control task module cyclically executes control tasks according to a preset period, where the preset period includes the time used in the input sampling stage, the time used in the program execution stage, and the time used in the output update stage;
[0011] At the start of the time used in the input sampling stage, the real-time control task module sends a first asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the output image table data of the previous preset period;
[0012] At the start of the time used in the output update stage, the real-time control task module sends a second asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the input image table data of the preset period;
[0013] The output image table data of the previous preset period and the input image table data of the preset period are stored in the shared memory as on-site data to obtain a buffer queue;
[0014] The anomaly detection module reads the on-site data from the buffer queue according to a preset reading strategy, and performs anomaly analysis and processing on the on-site data to obtain an anomaly detection result.
[0015] In a possible implementation manner, in the step of cyclically executing control tasks by the real-time control task module according to a preset period and the step of sending a first asynchronous interrupt signal to the data acquisition task module by the real-time control task module at the start of the time used in the input sampling stage, so that the data acquisition task module reads the output image table data of the previous preset period and generates the cumulative number of received signals, the computing resource scheduling of the processors corresponding to the real-time control task module and the data acquisition task module does not interfere with each other.
[0016] In a possible implementation manner, the step of storing the output image table data of the previous preset period and the input image table data of the preset period in the shared memory as on-site data to obtain a buffer queue includes: storing the output image table data of the previous preset period and the input image table data of the preset period in the shared memory as on-site data and using a fixed-size lock-free circular queue to obtain a buffer queue.
[0017] In a possible implementation manner, when the starting point of the time used in the input sampling stage sends a first asynchronous interrupt signal from the real-time control task module to the data acquisition task module, such that when the data acquisition task module reads the output image table data of the previous preset period, it further includes: performing a counting process through the data acquisition task module to accumulate the number of times recorded each time the data acquisition task module receives a first asynchronous interrupt signal, obtaining an accumulated number of received signals; when storing the output image table data and the input mapping table data read by the data acquisition task module within the preset period corresponding to the first asynchronous interrupt signal as on-site data into the shared memory, attaching a first cycle label to the input image table data and attaching a second cycle label to the output image table data, where the difference between the first cycle label and the second cycle label is 1.
[0018] In a possible implementation manner, it further includes: obtaining on-site training data during the execution of multiple training control tasks; constructing a training input-output correlation weight table according to the on-site training data.
[0019] In a possible implementation manner, the on-site data includes the input image table data and the output image table data read from the buffer queue by the anomaly detection module according to a preset reading strategy within a detection sampling period, where the detection sampling period is at least two of the preset periods; correspondingly, the anomaly analysis process on the on-site data to obtain an anomaly detection result includes: constructing a runtime input-output correlation weight table according to the input image table data and the output image table data read from the buffer queue by the anomaly detection module according to the preset reading strategy within the detection sampling period; performing a weight coefficient comparison process according to the runtime input-output correlation weight table and the training input-output correlation weight table to obtain a plurality of weight coefficient differences; when it is detected that the weight coefficient differences exceed a preset threshold range, obtaining an anomaly detection result of abnormal execution of the control task corresponding to the weight coefficient differences.
[0020] In a possible implementation manner, it further includes: when it is detected that the anomaly detection result triggers an alarm condition, sending it to the host computer through the anomaly detection module, such that the host computer performs an alarm operation.
[0021] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer execution instructions are stored, and when the computer execution instructions are executed by a processor, they are used to implement the above second aspect and / or various possible implementation manners of the second aspect.
[0022] Fourthly, an embodiment of the present application provides a computer program product, including a computer program which, when executed by a processor, implements the above second aspect and / or various possible implementation manners of the second aspect.
[0023] The programmable controller, control task data processing method, medium and product provided by the embodiments of the present application for discrete manufacturing process protection. Among them, the method first executes control tasks in a loop by a real-time control task module according to a preset cycle, where the preset cycle includes the time used in the input sampling stage, the time used in the program execution stage, and the time used in the output update stage. Then, at the start point of the time used in the input sampling stage, the real-time control task module sends a first asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the output image table data of the previous preset cycle. Then, at the start point of the time used in the output update stage, the real-time control task module sends a second asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the input image table data of the preset cycle. Then, the output image table data of the previous preset cycle and the input image table data of the preset cycle are stored in the shared memory as field data to obtain a buffer queue. Finally, the anomaly detection module reads the field data from the buffer queue according to a preset reading strategy and performs anomaly analysis and processing on the field data to obtain an anomaly detection result. This periodic use of field data for anomaly detection improves security during anomaly detection without affecting the execution of control tasks, and then completely avoids data access conflicts between data acquisition instructions and control instructions through the asynchronous interrupt signal mechanism to ensure the real-time performance of control tasks. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] The drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.
[0025] Figure 1 It is a schematic structural diagram of a programmable controller for discrete manufacturing process protection provided by an embodiment of the present application;
[0026] Figure 2 It is a schematic flowchart of a control task data processing method provided by the present application;
[0027] Figure 3 It is a schematic diagram of the relationship between the scan cycle and the execution process of control tasks provided by an embodiment of the present application;
[0028] Figure 4 It is a schematic diagram of the sending nodes of the first asynchronous interrupt signal and the second asynchronous interrupt signal provided by an embodiment of the present application;
[0029] Figure 5 It is a schematic diagram of reading data between a real-time domain virtual machine and a non-real-time domain virtual machine through shared memory provided by an embodiment of the present application.
[0030] Through the above-mentioned accompanying drawings, specific embodiments of the present application have been shown, and there will be a more detailed description hereinafter. These drawings and the written description are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Description of the Embodiments
[0031] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numerals in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0032] In the prior art, the real-time control tasks in a programmable logic controller (PLC) are regularly carried out in three stages: input sampling, execution of the user control program, and output update, according to the scan cycle. In the input sampling stage, the PLC reads the status signals of external input devices (such as sensors, switches, etc.), converts these status signals into binary data that can be processed internally, and writes them into the input image table located in the PLC memory; in the user program execution stage, the PLC reads the data in the input image table according to the pre-written user program, performs logical operations, sequence control, etc., and finally writes the calculated control commands into the output image table; in the output update stage, the PLC reads the values in the output image table, performs signal conversion to control the actions of external output devices (such as actuators, motors, etc.), thereby realizing the automatic control of the industrial process.
[0033] However, the inventors have found that during the execution of real-time control tasks of existing PLCs, although PLCs have greatly improved production efficiency and flexibility, they are also exposed to increasingly complex cybersecurity threats, including attacks such as tampering with malicious firmware / control programs, unauthorized access, and data leakage. If an attack intrudes into the PLC to tamper with discrete manufacturing process parameters and related control variables, and at the same time forges normal operation field data acquisition messages and transmits them back to the SCADA (Supervisory Control and Data Acquisition System) and HMI (Human Machine Interface) layers through the network, it will cause the operators and even the anomaly detection systems deployed on the network side to be unable to detect that the PLC has been attacked, which will affect the production process of discrete manufacturing and has low security. Moreover, when deploying the PLC anomaly detection function on the industrial network side devices (such as the PLC host computer) where the PLC is located, it performs anomaly detection on the PLC based on the network traffic interacting with the PLC. Such network-side anomaly detection modules are far from the field data on the IO side of the PLC, and due to the network communication delay, there is a detection delay, resulting in a low real-time performance problem; at the same time, if an attack intrudes into the PLC to tamper with process parameters and related control variables, and forges normal operation field status information and transmits it to the upper-layer network, since the detection has been based on the forged data, the network-side anomaly detection module cannot identify that the PLC has been attacked. Therefore, there is a problem of low security.
[0034] Combined with the above scenarios, in the prior art, by dividing the PLC into a real-time domain and a non-real-time domain, then deploying anomaly detection in the internal non-real-time domain of the PLC, and then using the data acquisition task module deployed in the real-time domain to run in parallel with the real-time task, and periodically collecting the field data of the PLC real-time domain. Then send it to the non-real-time domain anomaly detection payload, and at the same time use the asynchronous interrupt signal mechanism to completely avoid the data access conflict between the data acquisition task and the control task to ensure real-time performance. Also, use the lightweight anomaly detection payload deployed in the non-real-time domain, which directly provides protection for the process parameters and related control variables involved in the discrete manufacturing industrial control task through the IO data of the PLC site, improving security.
[0035] The following uses specific embodiments to elaborate in detail on the technical solutions of the present application and how the technical solutions of the present application solve the above technical problems. These several specific embodiments below can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The following will describe the embodiments of the present application in conjunction with the accompanying drawings.
[0036] Figure 1 It is a schematic structural diagram of a programmable logic controller for discrete manufacturing process protection provided by an embodiment of the present application.
[0037] As Figure 1As shown in the figure, the programmable logic controller provided by the embodiment of the present application for discrete manufacturing process protection includes multiple processors. A real-time domain virtual machine, a non-real-time domain virtual machine, and shared memory are deployed in the programmable logic controller;
[0038] Data sharing is achieved between the real-time domain virtual machine and the non-real-time domain virtual machine through shared memory;
[0039] Among them, the real-time domain virtual machine includes a real-time control task module and a data acquisition task module, the non-real-time domain virtual machine includes an anomaly detection module, the real-time control task module is connected to one of the multiple processors, the data acquisition task module is connected to another one of the multiple processors, the anomaly detection module is connected to other processors among the multiple processors, and any two processors among the multiple processors are independent of each other.
[0040] As Figure 1 shown in the figure, in this embodiment, the embedded virtualization technology can be used to divide the real-time domain virtual machine and the non-real-time domain virtual machine for the programmable logic controller PLC to realize the local deployment of the anomaly detection load. Among them, the real-time domain virtual machine RTVM can adopt real-time systems such as RT-Linux, Vxworks, QNX, etc. to run industrial control tasks with strict real-time requirements. The non-real-time domain virtual machine (GPVM) runs non-real-time systems such as Linux, Windows, etc., deploys the anomaly detection load, and collects, analyzes, makes decisions, and triggers security response measures for the on-site data in the process of industrial control tasks with real-time requirements. The local deployment of the anomaly detection load can cope with spoofing attacks caused by the monitoring / detection system being far from the on-site data source. In addition, in order to cope with covert attacks on the process parameters in the PLC.
[0041] In this embodiment, two processor CPU cores can be allocated to the real-time domain virtual machine running on the programmable logic controller by using a static allocation virtualization manager. These two processor cores are both exclusive processors. One exclusive processor is exclusively occupied by the real-time control task module, and the other exclusive processor is exclusively occupied by the data acquisition task module. Moreover, when the real-time control task module and the data acquisition task module run control tasks on their respective processor cores, the computing resource scheduling does not affect each other, and the real-time performance of industrial control tasks can be guaranteed.
[0042] As Figure 1 shown in the figure, in this embodiment, the multiple processors include a central processing unit CPU0, a central processing unit CPU1, a central processing unit CPU2, a central processing unit CPU3, and a graphics processing unit GPU0. Among them, the central processing unit CPU0, the central processing unit CPU1, and the graphics processing unit GPU0 correspond to the non-real-time domain virtual machine, and the central processing unit CPU2 and the central processing unit CPU3 correspond to the real-time domain virtual machine.
[0043] In summary, the programmable logic controller provided by the embodiments of the present application for discrete manufacturing process protection can enable the data acquisition task module to run in parallel with the real-time control task, periodically acquire the on-site data generated by the real-time domain virtual machine of the programmable logic controller PLC, and send it to the non-real-time domain anomaly detection payload through shared memory to ensure the security of the control task. At the same time, by means of the asynchronous interrupt signal mechanism, the data access conflict between the data acquisition task and the control task is completely avoided to ensure the real-time performance of industrial control.
[0044] Figure 2 It is a schematic flowchart of the control task data processing method provided by the present application.
[0045] The following will combine Figure 1 and Figure 2 to elaborate on the control task data processing method provided by the embodiments of the present application. The execution subject of this method can be Figure 1 the programmable logic controller PLC shown in Figure 1 and Figure 2 shown. This method includes:
[0046] S201: Execute the control task in a loop according to a preset period through the real-time control task module, where the preset period includes the time used in the input sampling stage, the program execution stage, and the output update stage.
[0047] In this embodiment, the preset period can be the duration of the entire process from the start to the end of a control task. In this embodiment, the input sampling stage refers to the process in which the programmable logic controller PLC reads the status signals of external input devices (such as sensors, switches, etc.) through the real-time control task module, converts these status signals into binary data that can be processed internally, and writes them into the input image table located in the shared memory of the PLC. The program execution stage refers to the process in which the PLC reads the data in the input image table according to the pre-written user program, performs logical operations, sequential control, etc., and finally writes the calculated control commands into the output image table. The output update stage refers to the process in which the programmable logic controller PLC reads the values in the output image table through the real-time control task module, performs signal conversion to control the actions of external output devices (such as actuators, motors, etc.), thereby realizing the automatic control of the industrial process.
[0048] Figure 3 It is a schematic diagram of the relationship between the scan cycle and the control task execution process provided by the embodiments of the present application.
[0049] As Figure 3 shown, the i-th scan cycle includes the time used in the input sampling stage, the program execution stage, and the output update stage.
[0050] S202: At the starting point of the time used in the input sampling stage, the real-time control task module sends a first asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the output image table data of the previous preset cycle.
[0051] In this embodiment, the first asynchronous interrupt signal can be a non-blocking interrupt signal to ensure that the real-time control task module can execute the next instruction without waiting for interrupt processing after sending the first asynchronous interrupt signal, ensuring the normal execution of the control task. After receiving the first asynchronous interrupt signal, the data acquisition task module starts to read the output image table data of the previous preset cycle of the current moment.
[0052] S203: At the starting point of the time used in the output update stage, the real-time control task module sends a second asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the input image table data of the preset cycle.
[0053] In this embodiment, the second asynchronous interrupt signal can be a non-blocking interrupt signal to ensure that the real-time control task module can execute the next instruction without waiting for interrupt processing after sending the first asynchronous interrupt signal, ensuring the normal execution of the control task. After receiving the second asynchronous interrupt signal, the data acquisition task module starts to read the input image table data of the preset cycle corresponding to the current moment.
[0054] Figure 4 It is a schematic diagram of the sending nodes of the first asynchronous interrupt signal and the second asynchronous interrupt signal provided by the embodiment of the present application.
[0055] As Figure 4 shown, at the starting point of the time used in the input sampling stage of the (i + 1)-th preset cycle, the real-time control task module sends a first asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module acquires the output image table data of the i-th preset cycle. At the starting point of the time used in the output update stage of the (i + 1)-th preset cycle, the real-time control task module sends a second asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module acquires the input image table data of the (i + 1)-th cycle.
[0056] In an optional embodiment of the present application, in the steps of the real-time control task module executing the control task in a preset cycle and at the starting point of the time used in the input sampling stage, the real-time control task module sends a first asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the output image table data of the previous preset cycle and generates the step of accumulating the number of received signals, the computing resource scheduling of the processors corresponding to the real-time control task module and the data acquisition task module does not interfere with each other.
[0057] In this embodiment, the principle that the computing resource scheduling of the processors corresponding to the control task module and the data acquisition task module does not interfere with each other has been inFigure 1 It has been elaborated in the illustrated embodiment, so it will not be repeated here in this embodiment.
[0058] S204: Store the output image table data of the previous preset cycle and the input image table data of the preset cycle as on-site data into the shared memory to obtain a buffer queue.
[0059] In this embodiment, after each control task is executed within a preset cycle, this preset cycle is recorded as the current preset cycle, and then the output image table data of the previous preset cycle and the input image table data of the current preset cycle of the current preset cycle are stored as the on-site data of the current preset cycle into the shared memory. The way of storing into the shared memory can be in the form of a queue, writing from the write start pointer to the write end pointer into the shared memory to form a queue, so as to obtain the final buffer queue.
[0060] In an alternative embodiment of the present application, step S204 includes:
[0061] Store the output image table data of the previous preset cycle and the input image table data of the preset cycle as on-site data and store them into the shared memory using a lock-free circular queue of a fixed size to obtain a buffer queue.
[0062] In this embodiment, a lock-free circular queue of a fixed size refers to a concurrent data structure that can efficiently store and read data in a multi-threaded environment without using traditional lock mechanisms. It avoids the performance bottleneck and potential deadlock problems brought by locks and improves the efficiency of data storage and reading. In this embodiment, the buffer queue is a lock-free circular queue.
[0063] S205: Read the on-site data from the buffer queue by the anomaly detection module according to a preset reading strategy, and perform anomaly analysis and processing on the on-site data to obtain an anomaly detection result.
[0064] In this embodiment, the preset reading strategy can be to periodically read the on-site data from the buffer queue in the shared memory, and these on-site data can include sensor status and commands of control tasks. At this time, the anomaly detection module, as a queue consumer, fetches the on-site data from the buffer queue in the shared memory for processing and analysis.
[0065] In this embodiment, due to the use of a lock-free circular queue, the data acquisition task module in the real-time domain virtual machine RTVM, which is the queue producer, and the anomaly detection module of the non-real-time domain virtual machine GPVM, which is the queue consumer, will not conflict in queue operations and affect real-time performance.
[0066] Based on the above embodiment, in an alternative embodiment of the present application, when step S202 is executed, it further includes:
[0067] Step A: Perform counting processing through the data acquisition task module to accumulate the number of times recorded each time the data acquisition task module receives a first asynchronous interrupt signal, obtaining the accumulated received signal count.
[0068] Step B: When storing the output image table data and input mapping table data read by the data acquisition task module within the preset cycle corresponding to the first asynchronous interrupt signal as on-site data into the shared memory, attach a first cycle label to the input image table data and a second cycle label to the output image table data, where the difference between the first cycle label and the second cycle label is 1.
[0069] In this embodiment, to support the correlation analysis of the anomaly detection module based on the data correlation characteristics within the same preset cycle after step S202. The data acquisition task module also identifies the on-site data within the same preset cycle.
[0070] Specifically, a counter for counting the preset cycle can be deployed in the data acquisition task module. When the data acquisition task module receives a first asynchronous interrupt signal, the counter is incremented by 1. At the same time, each time the on-site data is stored in the shared memory, a cycle label is attached to the on-site data based on the value generated by the counter.
[0071] Figure 5 It is a schematic diagram for the real-time domain virtual machine and the non-real-time domain virtual machine in the embodiment of the present application to read data through the shared memory.
[0072] As Figure 5 shown, the real-time domain virtual machine RTVM, as a queue producer, writes the input mapping table data into the shared memory according to the write queue pointer, the accumulated received signal count, and the first cycle label to generate an input mapping table queue. The real-time domain virtual machine RTVM, as a queue producer, writes the output mapping table data into the shared memory according to the write queue pointer, the accumulated received signal count, and the second cycle label to generate an output mapping table queue. Conversely, the non-real-time domain virtual machine GPVM, as a queue consumer, reads the input mapping table data from the input mapping table queue in the shared memory according to the write queue pointer, the accumulated received signal count, and the first cycle label. The non-real-time domain virtual machine GPVM, as a queue consumer, can also read the output mapping table data from the output mapping table queue in the shared memory according to the write queue pointer, the accumulated received signal count, and the second cycle label.
[0073] For example: when the counter counts to i, the first cycle label of the input image table data in the i-th preset cycle is i, and the corresponding second cycle label of the output image table data is i - 1.
[0074] In an optional embodiment of the present application, before the programmable controller is put into use for discrete manufacturing processes, the control task data processing method provided by the embodiments of the present application further includes:
[0075] Step C: Obtain training on-site data during the execution of multiple training control tasks.
[0076] Step D: Construct a training input-output correlation weight table based on the training on-site data.
[0077] In this embodiment, multiple training control tasks correspond to multiple training cycles. For example, the training sampling time for obtaining training on-site data by training sampling is T1 = XT, where X is a sufficiently large value, and T is a training cycle, which can be the same as the preset cycle. Read the on-site data stored in the shared memory within T1, and the value of X should ensure that the training on-site data obtained within T1 can cover all the input mapping table data and output mapping table data during the production use of the programmable controller.
[0078] In this embodiment, with the help of the first cycle tag and the second cycle tag, the input mapping table and the output mapping table data within the same training cycle can be made to correspond one by one. Thus, the weight w from a specific input to a specific output within the training sampling time T1 can be calculated. The finally constructed training input-output correlation weight table is shown in Table 1 below:
[0079] Table 1
[0080]
[0081] Based on the above embodiments, as a control task data processing method provided by an optional embodiment of the present application, the on-site data includes input image table data and output image table data read from the buffer queue by the anomaly detection module according to a preset reading strategy within the detection sampling period, where the detection sampling period is at least two preset cycles. Correspondingly, in step S205, anomaly analysis and processing are performed on the on-site data to obtain an anomaly detection result, including:
[0082] S205a: Construct a runtime input-output correlation weight table based on the input image table data and output image table data read from the buffer queue by the anomaly detection module according to a preset reading strategy within the detection sampling period.
[0083] S205b: Perform weight coefficient comparison processing based on the runtime input-output correlation weight table and the training input-output correlation weight table to obtain multiple weight coefficient differences.
[0084] S205c: When it is detected that the weight coefficient difference exceeds the preset threshold range, obtain an anomaly detection result of abnormal execution of the control task corresponding to the weight coefficient difference.
[0085] In this embodiment, when the programmable logic controller is officially put into use in the discrete manufacturing process, the detection sampling period is much smaller than the training sampling period. At this time, the process of constructing the runtime input-output correlation weight table is similar to the principle of constructing the training input-output correlation weight table in the above embodiment, so it will not be elaborated here.
[0086] Exemplarily, assume that the detection sampling period T2 = YT, where Y << X and Y is an integer. The constructed runtime input-output correlation weight table is shown in Table 2 below:
[0087] Table 2
[0088]
[0089] Among them, p ≤ m, q ≤ n. By comparing the weight coefficients at the same positions in Table 1 and Table 2, the weight coefficient difference is obtained, such as the comparison between w11 in Table 1 and w11 in Table 2 to get the weight coefficient difference of w11. When the weight coefficient difference of w11 exceeds the preset threshold range, an abnormal detection result indicating abnormal execution of the control task can be generated; otherwise, a detection result indicating normal execution of the control task can be generated.
[0090] In this embodiment, for the stealthy attack on process parameters in discrete manufacturing, if the attacker makes a slight tampering with the relevant control variables related to the production line process parameters in the programmable logic controller, although it will not cause the production line to stop, and the parameter change at a single observation time point does not reach the preset stop threshold, it will be misjudged as a change caused by normal system disturbances and cannot trigger emergency response measures. However, as the time of discrete manufacturing increases, long-term accumulation will easily cause greater and even immeasurable impacts. Therefore, in the embodiments of the present application, an abnormal detection is performed for each execution of the control task, and the weight coefficients of the runtime input-output correlation weight table and the training input-output correlation weight table constructed during the execution of the control task are compared to obtain the weight coefficient difference, which makes the result of the abnormal detection more accurate, avoids the stealthy attack on the fine-tuning of process parameters for discrete manufacturing processes, and improves security.
[0091] Based on the above embodiment, as a control task data processing method provided in an optional embodiment of the present application, it further includes: when it is detected that the abnormal detection result triggers an alarm condition, it is sent to the host computer through the abnormal detection module so that the host computer performs an alarm operation.
[0092] In this embodiment, the alarm condition may be relevant information or parameters indicating abnormal execution of the control task in the abnormal detection result. For example: 0 indicates abnormal execution of the control task.
[0093] In summary, for the control task data processing method provided in the embodiments of the present application, the real-time control task module first executes control tasks in a loop according to a preset period, where the preset period includes the time used in the input sampling stage, the program execution stage, and the output update stage. Then, at the start of the time used in the input sampling stage, the real-time control task module sends a first asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the output image table data of the previous preset period. Then, at the start of the time used in the output update stage, the real-time control task module sends a second asynchronous interrupt signal to the data acquisition task module, so that the data acquisition task module reads the input image table data of the preset period. Next, the output image table data of the previous preset period and the input image table data of the preset period are used as on-site data and stored in the shared memory to obtain a buffer queue. Finally, the anomaly detection module reads the on-site data from the buffer queue according to a preset reading strategy and performs anomaly analysis and processing on the on-site data to obtain an anomaly detection result. This periodic use of on-site data for anomaly detection improves security during anomaly detection without affecting the execution of control tasks, and then completely avoids data access conflicts between data acquisition instructions and control instructions through the asynchronous interrupt signal mechanism to ensure the real-time performance of control tasks.
[0094] The embodiments of the present application further provide a computer-readable storage medium, in which computer-executable instructions are stored. When the processor executes the computer-executable instructions, the above control task data processing method is implemented.
[0095] The embodiments of the present application further provide a computer program product, including a computer program, which implements the above control task data processing method when executed by a processor.
[0096] In the above embodiments, it should be understood that the processor may be a central processing unit (Central Processing Unit, CPU for short), or other general-purpose processors, digital signal processors (Digital Signal Processor, DSP for short), application-specific integrated circuits (Application Specific Integrated Circuit, ASIC for short), etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the invention can be directly implemented by the execution of the hardware processor, or implemented by the combination of hardware and software modules in the processor.
[0097] The memory may include high-speed memory (Random Access Memory, RAM), and may also include non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0098] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience in representation, the buses in the attached drawings of this application are not limited to only one bus or one type of bus.
[0099] This application also provides a computer program product, including a computer program which, when executed by a processor, implements the above-mentioned method.
[0100] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-mentioned method.
[0101] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a Static Random Access Memory (SRAM), an Electrically Erasable Programmable Read-Only Memory (EEPROM), an Erasable Programmable Read-Only Memory (EPROM), a Programmable Read-Only Memory (PROM), a Read-Only Memory (ROM), a magnetic memory, a flash memory, a magnetic disk or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0102] An exemplary readable storage medium is coupled to the processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in a device.
[0103] The division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0104] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0105] In addition, in each embodiment of the present invention, each functional unit may be integrated in a processing unit, may exist physically separately for each unit, or two or more units may be integrated in one unit.
[0106] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0107] Those of ordinary skill in the art can understand that all or part of the steps to implement the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: various media such as ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0108] Finally, it should be noted that: after considering the specification and practicing the invention disclosed herein, those skilled in the art will easily think of other implementation schemes of the present invention. The present invention aims to cover any variations, uses, or adaptive changes of the present invention. These variations, uses, or adaptive changes follow the general principles of the present invention and include the common general knowledge or conventional technical means in the technical field not disclosed in the present invention. It is not limited to the precise structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A control task data processing method, applied to a programmable controller, the programmable controller includes multiple processors, a real-time domain virtual machine, a non-real-time domain virtual machine and a shared memory are deployed in the programmable controller, the real-time domain virtual machine and the non-real-time domain virtual machine share data through the shared memory, wherein the real-time domain virtual machine includes a real-time control task module and a data acquisition task module, the non-real-time domain virtual machine includes an abnormality detection module, the real-time control task module is connected to one of the multiple processors, the data acquisition task module is connected to another processor of the multiple processors, the abnormality detection module is connected to other processors of the multiple processors, and any two processors of the multiple processors are independent of each other, characterized in that The method comprises: Execute the control task cyclically according to a preset period by the real-time control task module, wherein the preset period includes the time of the input sampling phase, the time of the program execution phase and the time of the output update phase; At the starting point of the input sampling phase, a first asynchronous interrupt signal is sent to the data acquisition task module through the real-time control task module, so that the data acquisition task module reads the output image table data of the previous preset cycle; At the starting point of the output update phase, a second asynchronous interrupt signal is sent to the data acquisition task module through the real-time control task module, so that the data acquisition task module reads the input image table data of the preset period; The output image table data of the previous preset cycle and the input image table data of the preset cycle are stored as field data in the shared memory to obtain a buffer queue; The abnormality detection module reads the field data from the cache queue according to a preset reading strategy, and performs abnormality analysis on the field data to obtain an abnormality detection result; the preset reading strategy refers to periodically reading the field data from the cache queue.
2. The method according to claim 1, characterized in that In the step of cyclically executing the control task according to a preset period through the real-time control task module and the step of sending a first asynchronous interrupt signal to the data acquisition task module through the real-time control task module at the starting point of the input sampling phase so that the data acquisition task module reads the output image table data of the previous preset period and generates the accumulated number of received signals, the computing resource scheduling of the processors corresponding to the real-time control task module and the data acquisition task module do not interfere with each other.
3. The method according to claim 1, characterized in that The step of storing the output image table data of the previous preset cycle and the input image table data of the preset cycle as field data into the shared memory to obtain a buffer queue includes: The output image table data of the previous preset cycle and the input image table data of the preset cycle are used as field data and stored in the shared memory in a fixed-size lock-free circular queue to obtain a cache queue.
4. The method according to claim 1, characterized in that: The starting point of the input sampling phase sends a first asynchronous interrupt signal to the data acquisition task module through the real-time control task module so that the data acquisition task module reads the output image table data of the previous preset cycle, and also includes: The data acquisition task module performs counting processing to accumulate the number of times recorded each time the data acquisition task module receives the first asynchronous interrupt signal, thereby obtaining an accumulated number of received signals; When the output image table data and input mapping table data read by the data acquisition task module within the preset period corresponding to the first asynchronous interrupt signal are stored as field data in the shared memory, a first cycle label is attached to the input image table data, and a second cycle label is attached to the output image table data, wherein the difference between the first cycle label and the second cycle label is 1.
5. The method according to claim 1, characterized in that: Also includes: Acquire training site data during the execution of multiple training control tasks; A training input-output relevance weight table is constructed based on the training field data.
6. The method according to claim 5, characterized in that The field data includes the input image table data and the output image table data read from the cache queue by the abnormality detection module according to a preset reading strategy within a detection sampling period, wherein the detection sampling period is at least two of the preset periods; Accordingly, performing abnormal analysis on the field data to obtain an abnormal detection result includes: Constructing a runtime input-output relevance weight table according to the input image table data and the output image table data read from the cache queue by the abnormality detection module according to a preset reading strategy within the detection sampling period; Performing a weight coefficient comparison process according to the runtime input-output relevance weight table and the training input-output relevance weight table to obtain a plurality of weight coefficient differences; When it is detected that the weight coefficient difference exceeds a preset threshold range, an abnormality detection result of abnormal execution of the control task corresponding to the weight coefficient difference is obtained.
7. The method according to any one of claims 1 to 6, characterized in that Also includes: When it is detected that the abnormal detection result triggers an alarm condition, it is sent to the host computer through the abnormal detection module so that the host computer performs an alarm operation.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 7 when executed by a processor.
9. A computer program product, characterized in that The invention comprises a computer program, which implements the method according to any one of claims 1 to 7 when being executed by a processor.
Citation Information
Patent Citations
Industrial internet operating system-based heterogeneous field equipment control management system
CN106941516A
Control system and control method
CN119513857A