IT and OT fused network security communication architecture under smart thermal power plant hyper-converged architecture

By building a network security communication architecture that integrates IT and OT in a smart thermal power plant, using OPC servers and hyper-converged intelligent control platform for data processing and conversion, the compatibility issues between OT and IT equipment in communication and security are solved, and efficient and secure data transmission and system stability are achieved.

CN120281525APending Publication Date: 2025-07-08XIAN TPRI THERMAL CONTROL TECH +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510396348.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

In smart power plants, the lack of communication standardization system of OT and IT equipment, incompatible networking architecture, and mismatch of security redundancy mechanisms, resulting in a systematic technical contradiction of fuzzy interaction logic, disordered protocol conversion and failure of protection strategies during the fusion process.

Method used

Build a network security communication architecture that integrates IT and OT under the hyper-converged architecture of smart thermal power plants, including OPC server area, intelligent controller area, core switch, network security management area and hyper-converged area. The network is isolated through firewalls and forward isolation gates, and the OPC server is used as a data interaction bridge, and data processing and conversion is used to use the hyper-converged intelligent control platform, combining powerful security protection functions.

Benefits of technology

It realizes efficient and secure data transmission between OT and IT equipment, ensures real-time and complete data, solves the problems of disordered protocol conversion and failure of protection strategies, improves the adaptability and flexibility of the system, and provides solid technical support for the safe operation of smart power plants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281525A_ABST
    Figure CN120281525A_ABST
Patent Text Reader

Abstract

The invention discloses a network security communication architecture and method for IT and OT fusion under a smart thermal power plant hyper-fusion architecture, and belongs to the technical field of industrial control fusion security. The architecture comprises an OPC server area, an intelligent controller area, a core switch, a network security management area and a hyper-convergence area. The OPC server area is connected with the core switch, and a firewall is arranged between the OPC server area and the core switch; the intelligent controller area is connected with the core switch, and a firewall is arranged between the intelligent controller area and the core switch; the hyper-convergence area is connected with the core switch, a firewall is arranged between the hyper-convergence area and the core switch, and the hyper-convergence area and the core switch are further connected with the three-area data center through a forward isolation gatekeeper. According to the invention, a set of standardized and highly feasible OT-IT communication architecture is constructed, the stability of the intelligent power plant production control system is improved, clear interaction logic in the fusion process is ensured, and the problem of systematic technical contradiction between disordered protocol conversion and protection strategy failure is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial control fusion security technology, and specifically to a network security communication architecture and method for IT and OT fusion under a hyper-converged architecture of a smart thermal power plant. Background Art

[0002] The construction of a smart power plant aims to achieve intelligent monitoring, automated scheduling and efficient management of the power plant production process through the deep integration of advanced information technology (IT) and operational technology (OT), thereby greatly improving power generation efficiency, reducing operating costs and reducing environmental pollution. The core of this change is to build an efficient, safe and reliable OT and IT integration system, in which OT equipment is mainly responsible for on-site data collection, equipment control and process execution, while IT equipment is responsible for data processing, information integration, decision support and remote monitoring. However, seamless communication and collaborative operation between OT and IT equipment has always been a core technical problem that needs to be solved in the process of building a smart power plant.

[0003] Traditionally, OT devices run in relatively closed industrial control networks, using proprietary communication protocols and hardware interfaces, emphasizing real-time, reliability, and stability to meet the stringent requirements of industrial sites. In contrast, IT equipment relies on open network architectures and standardized protocols, such as Ethernet, TCP / IP, etc., to achieve high-speed data transmission and extensive sharing, and pays more attention to flexibility, scalability, and information security. The fundamental differences between the two in communication mechanisms, data processing methods, and security strategies have led to the complexity of direct interconnection between OT and IT devices. Especially in the scenario of smart power plants, with the introduction of a large number of smart sensors, controllers, data servers, and analysis platforms, the demand for interaction between OT and IT systems has surged, but the lack of an effective standardized communication framework and unified connection standards has made system integration, equipment configuration, and data exchange processes extremely cumbersome and error-prone.

[0004] In terms of communication technology, OT-IT interconnection not only involves the selection and deployment of communication equipment at the hardware level (such as selecting appropriate communication cards and gateway devices to achieve protocol conversion), but also needs to consider protocol adaptation, data format conversion and network topology design at the software level. Since OT devices usually use dedicated fieldbus technology (such as PROFIBUS, MODBUS, etc.), and IT equipment is based on standard Ethernet protocols, communication between the two requires a complex protocol conversion mechanism, which not only increases the complexity of the system, but may also introduce additional delays and failure points. In addition, the reasonable allocation of IP addresses and the efficient deployment of network equipment are crucial to ensuring the stability and scalability of the communication network, but in actual operation, due to the lack of unified planning standards, the network structure is often chaotic and difficult to effectively manage and maintain.

[0005] In terms of security, there are significant differences in security requirements between OT and IT systems. OT systems focus on physical security and production continuity, and tend to adopt physical isolation and AB network architectures to prevent external threats; while IT systems focus more on information security and rely on network security devices and technologies such as firewalls, intrusion detection systems, and access control lists to ensure the secure transmission and storage of data. This incompatibility of security policies makes it a major challenge to design a comprehensive security system that can meet the real-time and reliability requirements of OT systems and effectively resist the network security threats faced by IT systems during the OT-IT integration process. Especially in the management of IP white lists and the formulation of access control policies, it is necessary to finely balance openness and security, ensuring smooth access for legitimate users while effectively preventing unauthorized access and attack behaviors.

[0006] In summary, the construction and development of smart power plants urgently require solving the communication problems between OT and IT devices, and by formulating unified communication standards, optimizing network architecture design, and strengthening security protection measures, an efficient, secure, and scalable underlying network link can be constructed. Summary of the Invention

[0007] Aiming at the problems in the prior art such as the lack of a communication standardization system, incompatible networking architectures, and mismatched security redundancy mechanisms between OT and IT devices, which lead to systematic technical contradictions such as fuzzy interaction logic, disordered protocol conversion, and ineffective protection strategies during the integration process. The present invention provides a network security communication architecture for the integration of IT and OT under the hyper-converged architecture of a smart thermal power plant, constructs a set of standardized and highly feasible OT-IT communication architectures, improves the stability of the production control system of the smart power plant, ensures clear interaction logic during the integration process, and solves the systematic technical contradictions of disordered protocol conversion and ineffective protection strategies.

[0008] To achieve the above object, the present invention provides the following technical solutions.

[0009] In a first aspect, the present invention provides a network security communication architecture for the integration of IT and OT under the hyper-converged architecture of a smart thermal power plant, including an OPC server area, an intelligent controller area, a core switch, a network security management area, and a hyper-converged area;

[0010] The OPC server area is connected to the core switch, and a firewall is provided between the OPC server area and the core switch;

[0011] The intelligent controller area is connected to the core switch, and a firewall is provided between the intelligent controller area and the core switch;

[0012] The hyper-converged zone is connected to the core switch, and a firewall is set between the hyper-converged zone and the core switch. The hyper-converged zone is also connected to the data center of Zone 3 through a forward isolation gateway;

[0013] The network security management zone is connected to the core switch.

[0014] As a further improvement of the present invention, the OPC server zone includes an OPC server; the OPC server is connected to the core switch, and a firewall is set between the OPC server and the core switch.

[0015] As a further improvement of the present invention, the intelligent controller zone includes an intelligent controller; a communication card is installed on the intelligent controller; the intelligent controller is connected to the core switch through the communication card; a firewall is set between the communication card and the core switch.

[0016] As a further improvement of the present invention, the intelligent controller is also connected to the DCS network.

[0017] As a further improvement of the present invention, the network security management zone includes an industrial control information security supervision and analysis platform, a log audit module, an account management and operation and maintenance audit module, a database audit module, and a security management host.

[0018] As a further improvement of the present invention, a number of hyper-converged nodes are set in the hyper-converged zone.

[0019] As a further improvement of the present invention, the firewall is in the HA primary and standby mode.

[0020] In a second aspect, the present invention provides a network security communication method for IT and OT integration under the hyper-converged architecture of a smart thermal power plant, including:

[0021] Data in the production control major zone is read through an OPC server;

[0022] The OPC server sends the read data to the hyper-converged zone through the core switch;

[0023] The hyper-converged zone processes the data sent by the OPC server and sends the processed data to the intelligent controller zone;

[0024] The intelligent controller zone processes the received data and then sends it to the DCS network.

[0025] As a further improvement of the present invention, the OPC server sending the read data to the hyper-converged zone through the core switch includes:

[0026] The OPC server sends the read data to the core switch through an OPC switch;

[0027] The data received by the core switch is sent to the hyper-converged area through the hyper-converged management switch.

[0028] As a further improvement of the present invention, the hyper-converged area processes the data sent by the OPC server and sends the processed data to the intelligent controller area, including:

[0029] The hyper-converged area sends the received data to the intelligent controller through the communication card, where: the IP configurations of the intelligent controller and the communication card are:

[0030] The IP of the intelligent controller is in the same network segment as the DCS controller. Among them, the second octet distinguishes between network A and network B, and the third octet distinguishes between units;

[0031] The IP of the communication card distinguishes between network A and network B through the second octet; the third octet is newly added and cannot be the same as other systems.

[0032] Compared with the prior art, the present invention has the following beneficial effects:

[0033] The present invention uses the OPC server as a bridge for data interaction to achieve accurate and efficient reading of data in the production control major area. This step not only ensures the integrity and real-time nature of the data, but also effectively reduces the loss and delay of the data during the transmission process, providing a solid data foundation for subsequent intelligent processing and decision-making. The application of the OPC server itself is an embodiment of a standardized communication protocol. It breaks the original technical barriers between OT and IT, making the data flow between different systems smoother, solving the problem of fuzzy interaction logic, and laying a solid communication foundation for the construction of a smart power plant.

[0034] Furthermore, the hyper-converged intelligent control platform designed by the present invention, as the center of data processing and forwarding, with its powerful data processing ability and flexible communication interface design, enables the data received from the OPC server to be quickly and accurately parsed, converted, and seamlessly connected to the intelligent controller through a dedicated communication card. This process not only realizes the rapid transfer of data, but more importantly, through the built-in standardized protocol conversion mechanism of the platform, effectively solves the problem of disorderly protocol conversion, ensuring the standardization and consistency of communication between different systems. In addition, the hyper-converged intelligent control platform also has high scalability and configurability, and can be customized according to the specific needs of different thermal power plants, thereby further enhancing the adaptability and flexibility of the system, and providing technical support and guarantee for the long-term development of smart power plants.

[0035] Furthermore, the intelligent controller is used to receive and process data from the hyper-converged intelligent control platform, and then securely send the processed data to the DCS network. The intelligent controller can accurately judge the operating status of the power plant based on real-time data, issue adjustment instructions in a timely manner, optimize the production process, and improve energy utilization efficiency. At the same time, the intelligent controller also has a powerful security protection function, which can implement multi-level security protection strategies during data transmission and processing, effectively resist the risks of external attacks and internal leaks, and ensure the security and reliability of the entire communication link. This design not only solves the systematic technical contradiction of the failure of the protection strategy, but also provides a solid technical support for the safe operation of the smart power plant. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The drawings described herein are for illustrative purposes only and are not intended to limit the scope of the present disclosure in any way. In the drawings:

[0037] Figure 1 is the communication topology diagram of the OT and IT fusion network in the production control area of the present invention;

[0038] Figure 2 is the communication logic diagram of the OT and IT fusion network in the production control area of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] In order to enable those skilled in the art of the present technology to better understand the technical solutions in the present invention, the technical solutions in the present invention will be clearly and completely described below in conjunction with the drawings in the present invention. The described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the scope of protection of the present invention.

[0040] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field of the present invention. The terms used in the specification of the present invention herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0041] Aiming at the problems in the prior art that there are problems such as the lack of communication standardization system, incompatible networking architecture and mismatched security redundancy mechanism between OT and IT devices, resulting in systematic technical contradictions such as fuzzy interaction logic, disordered protocol conversion and failure of protection strategies during the fusion process, the present invention provides a network security communication architecture for the integration of IT and OT under the hyper-converged architecture of a smart thermal power plant, as Figure 1As shown in the figure, the architecture includes: OPC server area, intelligent controller area, core switch, network security management area, and hyper-converged area;

[0042] The OPC server area is connected to the core switch, and a firewall is set between the OPC server area and the core switch;

[0043] The intelligent controller area is connected to the core switch, and a firewall is set between the intelligent controller area and the core switch;

[0044] The hyper-converged area is connected to the core switch, and a firewall is set between the hyper-converged area and the core switch. The hyper-converged area is also connected to the three-zone data center through a forward isolation network gateway;

[0045] The network security management area is connected to the core switch.

[0046] The present invention constructs a set of standardized and highly feasible OT-IT communication architecture, improves the stability of the production control system of the smart power plant, ensures clear interaction logic during the integration process, and solves the systematic technical contradiction problem of disordered protocol conversion and ineffective protection strategy.

[0047] As Figure 1 shown, in a smart thermal power plant, the integration of IT (information technology) and OT (operational technology) systems is the key to realizing production intelligence, improving operation efficiency, and enhancing security. The following is a network security communication architecture for the integration of IT and OT based on a hyper-converged architecture, covering detailed solutions for data transmission, network security, and control processes.

[0048] The system architecture of the present invention includes an intelligent controller, an OPC (Open Platform Communications) server, a hyper-converged platform, a switch and firewall, and a communication card.

[0049] Specifically, the intelligent controller is responsible for monitoring and controlling the production process, including communication with the DCS system, receiving data from the hyper-converged platform and processing it.

[0050] The OPC server is responsible for obtaining data from the production control area and transmitting it to the hyper-converged platform through a communication protocol.

[0051] The hyper-converged platform is a virtualization platform that integrates computing, storage, and network resources, with virtual machines deployed internally, running large models and artificial intelligence algorithms, providing decision support for the intelligent controller. And it is connected to the clock synchronization server to ensure system time synchronization.

[0052] The switch and firewall are used to provide internal network switching and security isolation. The firewall ensures the security of data flow during the process and blocks potential malicious attacks.

[0053] The communication card is responsible for data transmission between the intelligent controller and the hyper-converged platform.

[0054] The hyper-converged platform is connected to the switch through high-speed optical fibers to ensure data transmission between the IT network and the OT network. The intelligent controller is connected to the hyper-converged platform through a dedicated communication card to ensure real-time data transmission and processing. The firewall is deployed at the boundaries of the OPC area, the intelligent controller area, and the hyper-converged area to ensure network security isolation between the partitions. The OPC server exchanges data with the devices in the production control major area through industrial protocols (such as Modbus, OPC UA, etc.).

[0055] As Figure 2 shown, a network security communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant according to the present invention is as follows:

[0056] The OT network adopts the AB network architecture of DCS (Distributed Control System) and intelligent controllers, ensuring real-time performance and high reliability in the production environment. The DCS and the intelligent controller communicate through a dedicated link to ensure the real-time transmission and execution of control instructions. The IT network is connected to the core switch through the hyper-converged platform, and the IT network and the OT network are logically isolated through a three-zone isolation gateway. Under this architecture, the IT network can perform operations such as data processing and artificial intelligence analysis, while the OT network is responsible for real-time control and monitoring. The data in the production control major area is read by the OPC server and sent to the hyper-converged platform. The OPC server transfers the data to the hyper-converged platform through the core switch for further processing. The hyper-converged platform sends the processed data to the intelligent controller through the core switch and the communication card, and the intelligent controller executes production control according to the instructions. The firewall is located at the partition boundary between IT and OT to ensure the security of data flow. The firewall ensures that only authorized devices can access specific network areas through the whitelist mechanism, reducing the risk of network attacks. By designing multiple security partitions in the network architecture, IT and OT are isolated from each other. The virtual machine deployment of the hyper-converged system will also perform network isolation as needed to prevent unnecessary access.

[0057] Network security devices: including a network intrusion detection system (IDS) and an intrusion prevention system (IPS), which monitor network traffic in real time, identify and block malicious access.

[0058] In the IT section, IP addresses are assigned according to the functions of the devices to ensure interference-free communication between systems and facilitate management. The OPC server is assigned a separate IP in the IT section to ensure smooth communication with the hyper-converged platform. A whitelist mechanism is used to prevent unauthorized access. The firewall configures read and write permissions to ensure that communication between devices is limited to necessary traffic. Additionally, virtual machine protection is deployed within the hyper-converged platform to ensure that virtual machines within the system do not interfere with each other and can be effectively isolated when attacked. Meanwhile, through the clock synchronization server, all devices in the entire network are ensured to operate under the same time reference, avoiding production errors caused by clock asynchronization. The hyper-converged platform is connected to the clock synchronization server to ensure that components within the platform maintain a consistent time reference and avoid data loss or conflicts caused by time asynchronization.

[0059] Virtual machines are deployed within the hyper-converged platform to run large-scale artificial intelligence models. By obtaining data from Zone 1 in real time, production processes are predicted and optimized, providing reference for the intelligent controller to generate control instructions. The intelligent controller has functional modules such as wide-load cruising and intelligent monitoring. Through the feedback of real-time data, the production process is intelligently optimized. The hyper-converged platform uses big data analysis and AI algorithms to predict and optimize the production process and generate intelligent control instructions. Then, the instructions are transmitted to the intelligent controller through the communication card, and the controller sends the processed instructions to the DCS system to complete production control.

[0060] In summary, under the hyper-converged architecture of the intelligent thermal power plant, the integration of IT and OT realizes efficient and secure production control through the OPC server, hyper-converged platform, intelligent controller, and a carefully designed network security architecture. This solution ensures the security and real-time nature of data through advanced technologies such as network isolation, clock synchronization, and security protection, while also improving production efficiency and system reliability.

[0061] The following further explains and illustrates the present invention with specific embodiments.

[0062] Embodiment

[0063] Taking a 2×1000 MW thermal power plant as an example, this embodiment specifically introduces the OT and IT integration network and network security design in the production control area of the thermal power plant.

[0064] In terms of the communication of the OT and IT integration network in the production control area, communication for three lines, namely reading data, writing data, and transmitting data to Zone 3, is achieved.

[0065] The main purpose of data reading is to read data such as those from the DCS in the production control area through the OPC server, historical station and other upper computers. Only the data reading permission is enabled, so that the data center in the hyper-convergence can collect and store all data, and the artificial intelligence algorithm model deployed in the hyper-convergence can use this data to predict and generate the required content, and transmit it to the information management area through the one-way network isolation device.

[0066] Writing data means that the artificial intelligence algorithm model deployed in the hyper-convergence predicts and generates control instructions, which are written back to the intelligent controller through the firewall to realize functions such as intelligent control, cruise, and monitoring panel.

[0067] Transmitting data to Zone 3 is that the data platform in the hyper-convergence transmits data to the information management area through the forward isolation network isolation device. The transmitted data can be selected as needed, including the original data such as DCS data, NCS, ECS, and gateway power read from the OPC server, or the processed data output by the algorithm model in the hyper-convergence. These data can be used as models or displays in Zone 3.

[0068] Regarding the network security of the OT and IT integration in the production control area, establish network security protection strategies for intelligent controllers and communication cards. Through network topology design, firewall configuration, deployment of network security devices, etc., comprehensively ensure the network security of the production control area.

[0069] At the network topology level, construct one-way data reading and writing communication links.

[0070] For data reading of upper computers such as the OPC server and historical station, only the data reading permission is enabled. Through software methods of firewall permission settings or hardware isolation methods of configuring network isolation devices, ensure that the OPC server can only be read, and prohibit hyper-convergence data from being written back to the OPC. The control instructions predicted and generated by the artificial intelligence algorithm model in the hyper-convergence are written into the intelligent controller through the firewall to ensure the safe transmission of control instructions. The data reading and writing links are one-way.

[0071] The network segments of the OT and IT integration in the production control area are different from the AB network segments of the power plant DCS. The intelligent controller is connected across network segments through a communication card, which will not affect the original AB network communication network of the intelligent controller. A new network card is added to the OPC network segment for data reading, which will not affect the original AB network communication network of the OPC server.

[0072] Specifically, in this embodiment, the underlying physical devices are divided according to their physical locations as follows.

[0073] There are 3 IT network cabinets and 3 OT control cabinets in the No. 1 boiler electronics room. Network cabinet (width 600mm * depth 1200mm * height 2200mm), control cabinet (width 800mm * depth 600mm * height 2200mm)

[0074] The cabinet equipment in this embodiment is set as follows:

[0075] The equipment in the 3-sided IT network cabinet includes: 6 pairs (12) of firewalls, 1 pair (2) of core switches, network security equipment: industrial control information security supervision and analysis platform, log audit, account management and operation and maintenance audit system, database audit, security management host, network security management switch, 1 pair (2) of hyper-converged switches, and 5 hyper-converged nodes.

[0076] Specifically, the 6 pairs of firewalls are respectively 3 pairs of OPC boundary firewalls, 2 pairs of intelligent controller boundary firewalls, and 1 pair of hyper-converged boundary firewalls, all in HA primary and standby mode. The core switch is responsible for the core data exchange of the IT network and is in HA primary and standby mode; the hyper-converged switch is in HA primary and standby mode.

[0077] The equipment in the 3-sided OT network cabinet includes: OT Cabinet 1: 2 pairs of intelligent controllers (1 pair not connected to communication cards), 2 Modbus TCP communication cards, 1 pair (2) of aggregation switches. OT Cabinet 2: 2 pairs of intelligent controllers (1 pair not connected to communication cards), 2 Modbus TCP communication cards. OT Cabinet 3: 3 pairs of intelligent controllers, 9 Modbus TCP communication cards, 1 pair (2) of aggregation switches.

[0078] There are 3 OT control cabinets in the No. 2 boiler electronics room, which are the same as the equipment in the 3 OT control cabinets in the No. 1 boiler electronics room.

[0079] Each of the OPC servers in the #1 unit, #2 unit, and auxiliary network engineer station has two OPC servers.

[0080] OT Cabinet 1: 2 pairs of intelligent controllers (1 pair not connected to communication cards), 2 Modbus TCP communication cards, 1 pair (2) of aggregation switches.

[0081] The 2 Modbus TCP communication cards are respectively connected to a pair of intelligent controllers that need to communicate, and the communication cards are redundant with each other. 1 pair of aggregation switches are DCS aggregation switches, namely the DCS A-network aggregation switch and the DCS B-network aggregation switch respectively, which are used for the communication between all 7 pairs of intelligent controllers in the 3-sided OT cabinet and the DCS network. All A-network intelligent controllers are uniformly connected to the DCS A-network aggregation switch, and then this aggregation switch is connected to the DCS network cabinet A-network. All B-network intelligent controllers are uniformly connected to the DCS B-network aggregation switch, and then this aggregation switch is connected to the DCS network cabinet B-network. 2 pairs of intelligent controllers are connected to the DCS aggregation switch. The 2 Modbus TCP communication cards are connected to the communication card aggregation switch in OT Cabinet 3.

[0082] OT Cabinet 2: 2 pairs of intelligent controllers (1 pair not connected to communication cards), 2 Modbus TCP communication cards.

[0083] The 2 Modbus TCP communication cards are respectively connected to a pair of intelligent controllers that need to communicate, and the communication cards are redundant with each other. The 2 pairs of intelligent controllers are connected to the DCS aggregation switch in OT Cabinet 1. The 2 Modbus TCP communication cards are connected to the communication card aggregation switch in OT Cabinet 3.

[0084] OT Cabinet 3: 3 pairs of intelligent controllers, 9 Modbus TCP communication cards, 1 pair of 2 aggregation switches.

[0085] 3 Modbus TCP communication cards correspond to 1 pair of intelligent controllers, and the communication cards are redundant with each other. 1 pair of aggregation switches are communication card aggregation switches, namely the communication card A network aggregation switch and the communication card B network aggregation switch respectively, which are used for the communication between all 13 Modbus TCP communication cards of the 3 OT cabinets and the IT network (hyper-convergence). All communication card A networks are uniformly connected to the communication card A network aggregation switch, and then this aggregation switch is connected to the core network main switch of the IT cabinet. All communication card B networks are uniformly connected to the communication card B network aggregation switch, and then this aggregation switch is connected to the core network standby switch of the IT cabinet. The 3 pairs of intelligent controllers are connected to the DCS aggregation switch in OT Cabinet 1. The 9 Modbus TCP communication cards are connected to the communication card aggregation switch.

[0086] Specifically, the logical link of the OT and IT fusion network in the production control area is as follows:

[0087] The communication logical link will be described from four aspects: the OT internal network, the IT internal network, reading data from OPC, and writing data to intelligent controllers.

[0088] The OT internal network mainly refers to the link from the DCS network cabinet to the intelligent controller and then to the ModbusTCP communication card.

[0089] Specifically, DCS network cabinet - DCS aggregation switch - intelligent controller - Modbus TCP communication card, where all intelligent controllers are connected to the DCS network cabinet through the DCS aggregation switch, and the intelligent controllers that need to communicate with the hyper-convergence are connected to the corresponding ModbusTCP communication cards.

[0090] The IT internal network mainly refers to the link for the hyper-convergence to transmit data to the three-zone data center through the forward isolation gateway. Specifically, hyper-convergence - through the hyper-convergence switch - the three-zone forward isolation gateway, and sent to the three-zone data center.

[0091] The network communication link for reading data is the communication interface and method from OT to IT. Specifically, from the OPC server - through the OPC switch - core switch - through the hyper-converged management switch - hyper-convergence.

[0092] The network communication for writing data is from the hyper-convergence of the IT network core device to the intelligent controller of the OT network core device, which is the communication from IT to OT. Specifically, from hyper-convergence - through the hyper-converged switch - core switch - through the communication card aggregation switch - Modbus TCP communication card - intelligent controller.

[0093] The network security partition architecture of the production control major zone is as Figure 2 shown. In addition to the above 4 logical links of the OT-IT converged network, the OT-IT converged network architecture of the intelligent power plant production control major zone is network security partitioned, and firewalls are set at the network partition boundaries, and security zone boundary protection policies are established to achieve access control, network protocol parsing, and service policy optimization.

[0094] The production control major zone network has a total of 1 network security management center and 3 security partitions, namely the OPC server zone, the intelligent controller zone, and the hyper-converged zone. Network security devices are deployed inside the network security management center, and firewalls deployed in HA are set at the boundaries of the security partitions.

[0095] The devices in the network security management center include an industrial control information security supervision and analysis platform, log auditing, account management and operation and maintenance auditing system, database auditing, backup, security management host, etc. 6 pairs of firewalls are respectively 3 pairs of OPC boundary firewalls, 2 pairs of intelligent controller boundary firewalls, and 1 pair of hyper-converged boundary firewalls, all in the HA primary and standby mode.

[0096] In this embodiment, the IP partitioning and configuration are as follows:

[0097] The IP partitioning mainly includes the intelligent controller IP, communication card IP, OPC server IP, hyper-converged application virtual machine IP, and management IP.

[0098] ① IP configuration of the intelligent controller and Modbus TCP communication card

[0099] Among them, the first octet of the IP address is 100 for all, and the second octet is 100 for network A and 101 for network B.

[0100] The intelligent controller accesses the DCS AB network, and the third octet of the IP address is 1 for unit #1 and 2 for unit #2 respectively.

[0101] 7 pairs of intelligent controllers in 3 OT cabinets are respectively configured

[0102] #1 Unit A Network 100.100.1.61 - 100.100.1.67

[0103] #1 Unit B Network 100.101.1.61 - 100.101.1.67

[0104] #2 Unit A Network 100.100.2.61 - 100.100.2.67

[0105] #2 Unit B Network 100.101.2.61 - 100.101.2.67

[0106] Modbus TCP Communication Card Independent Network Segment, the third octet of the IP address is 13 for #1 unit and 14 for #2 unit

[0107] 13 Modbus TCP communication cards are respectively configured for 3 OT cabinets

[0108] #1 Unit A Network 100.100.13.1 - 100.100.13.13

[0109] #1 Unit B Network 100.101.13.1 - 100.101.13.13

[0110] #2 Unit A Network 100.100.14.1 - 100.100.14.13

[0111] #2 Unit B Network 100.101.14.1 - 100.101.14.13

[0112] Among them, #1 unit

[0113] OT Cabinet 1 (1 pair of intelligent controllers, 2 Modbus TCP communication cards) IP: 13.1, 13.2

[0114] OT Cabinet 2 (1 pair of intelligent controllers, 2 Modbus TCP communication cards) IP: 13.3, 13.4

[0115] OT Cabinet 3 (3 pairs of intelligent controllers, 9 Modbus TCP communication cards) IP: 13.5 - 13.13

[0116] Among them, #2 unit

[0117] OT Cabinet 1 (1 pair of intelligent controllers, 2 Modbus TCP communication cards) IP: 14.1, 14.2

[0118] OT Cabinet 2 (1 pair of intelligent controllers, 2 Modbus TCP communication cards) IP: 14.3, 14.4

[0119] OT Cabinet 3 (3 pairs of intelligent controllers, 9 Modbus TCP communication cards) IP: 14.5 - 14.13

[0120] ② OPC Server IP Configuration

[0121] Among them, for the IP address, the first octet is set to 100 for all, the second octet is set to 100 for Network A and 101 for Network B respectively, and 103 is newly added. The third octet is set to 13 for Unit #1, 14 for Unit #2, and 15 for the auxiliary network.

[0122] The original OPC servers for Unit #1 were in the 100.1 network segment (Network A) and 101.1 network segment (Network B), for Unit #2 were in the 100.2 network segment (Network A) and 101.2 network segment (Network B), and for the auxiliary network were in the 102.1 network segment (Network A) and 102.2 network segment (Network B). By adding new network cards and configuring new network segments 103 for the OPC servers of Unit #1, Unit #2, and the auxiliary network respectively, it is possible to avoid network connectivity with Networks A and B.

[0123] The IP address of the OPC server for Unit #1 is 100.103.13.150, for Unit #2 is 100.103.14.150, and for the auxiliary network is 100.103.15.150

[0124] ③ Hyper-Converged Application Virtual Machine IP Configuration

[0125] Hyper-converged application virtual machines include Modbus TCP communication card data write-back interface virtual machines, OPC data interface virtual machines, hyper-converged background algorithm virtual machines, etc.

[0126] Data Logical Link

[0127] OPC Data Interface Virtual Machine --- Hyper-Converged Background Algorithm Virtual Machines such as Artificial Intelligence --- Hyper-Converged Data Transmission Virtual Machine --- Modbus TCP Communication Card --- Corresponding Intelligent Controller

[0128] Modbus TCP Communication Card Data Write-Back Interface Virtual Machine IP Configuration

[0129] Among them, for the IP address, the first octet is 100 for all, the second octet is 100 for Network A and 101 for Network B.

[0130] The third octet of the IP address is in the same network segment as the Modbus TCP communication card, which are 13 for Unit #1 and 14 for Unit #2 respectively

[0131] There are 5 hyper-converged virtual machines with A / B dual virtual network cards for each of Unit #1 and Unit #2, used for transmitting data to the Modbus TCP

[0132] Among them, for Unit #1, Network A: 100.100.13.31 - 100.100.13.35, Network B: 100.100.13.31 - 100.100.13.35

[0133] For Unit #2, Network A: 100.101.14.31 - 100.101.14.35, Network B: 100.101.14.31 - 100.101.14.35

[0134] IP Configuration of the OPC Data Interface Virtual Machine

[0135] Corresponding to the OPC Server IP

[0136] The IP address of the data interface virtual machine of the OPC server for Unit #1 is 100.103.13.50, the IP address of the data interface virtual machine of the OPC server for Unit #2 is 100.103.14.50, and the IP address of the data interface virtual machine of the auxiliary network OPC server is 100.103.15.50

[0137] IP Configuration of the Hyper-Converged Background Algorithm Virtual Machine

[0138] 100.100.13.51 - 100.100.13.80, any idle network segment can be used for the IP network security management segment configuration of the hyper-converged background algorithm virtual machine

[0139] 10.10.10.1 - 10.10.10.11

[0140] Build a network security management center within the ICS system to achieve capabilities such as active discovery of network assets, non-destructive detection of vulnerabilities, network attack detection, security operation and maintenance, log audit analysis, and auditing of high-risk database operations.

[0141] Deploy vulnerability scanning devices in the production control area to audit important user behaviors and important security events, and achieve vulnerability security protection within the overall system; conduct security audits for important business traffic, important devices, etc., and deploy log audit and database audit devices for the security audit of all users to record information such as the date and time of events, users, event types, and whether the login is successful, and the storage should reach 6 months or more.

[0142] In summary, the present invention constructs an integrated architecture of the hyper-converged information system and the industrial control system in the first production area of the intelligent thermal power plant to achieve a collaborative working mechanism for big data processing, intelligent algorithm analysis, and control instructions. Based on this requirement, we designed a complete network and network security solution, covering a full-range architecture design from underlying physical devices to logical links and network links.

[0143] This solution involves core application devices, including intelligent controllers, OPC servers, and hyper-converged systems; communication devices such as communication cards; and network security devices such as firewalls and other security protection devices. It focuses on solving the location deployment of these devices at the physical level, the connection methods at the logical level, and their specific implementation in network communication.

[0144] Based on the physical connection of the devices, the present invention further optimizes the network architecture design to ensure an efficient and secure communication mechanism. Specifically, it includes: network segment division, IP address allocation, network security access control based on a whitelist, data read and write permission management solutions, and the roles of various network security devices in the overall protection system. Through this solution, the interoperability between the management information system and the industrial control system can be effectively improved, while enhancing the stability and security of network communication.

[0145] The second objective of the present invention is to propose a network security communication method for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant, including:

[0146] Data in the production control area is read through the OPC server;

[0147] The OPC server sends the read data to the hyper-converged area through the core switch;

[0148] The hyper-converged area processes the data sent by the OPC server and sends the processed data to the intelligent controller area;

[0149] The intelligent controller area processes the received data and then sends it to the DCS network.

[0150] By reading the above description, many embodiments and many applications other than the provided examples will be obvious to those skilled in the art. Therefore, the scope of this teaching should not be determined with reference to the above description, but should be determined with reference to the full scope of the foregoing claims and the equivalents of these claims. For the sake of comprehensiveness, all articles and references, including patent applications and published announcements, are incorporated herein by reference. The omission of any aspect of the subject matter disclosed herein in the foregoing claims is not intended to abandon such subject matter, nor should the applicant be considered not to have considered such subject matter as part of the disclosed inventive subject matter.

[0151] The above content is a further detailed description of the present invention. It cannot be determined that the specific implementation of the present invention is limited to this. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, which should all be regarded as falling within the protection scope determined by the claims submitted for the present invention.

Claims

1. A network security communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant, characterized in that It includes an OPC server area, an intelligent controller area, a core switch, a network security management area, and a hyper-converged area; The OPC server area is connected to the core switch, and a firewall is set between the OPC server area and the core switch; The intelligent controller area is connected to the core switch, and a firewall is set between the intelligent controller area and the core switch; The hyper-converged area is connected to the core switch, a firewall is set between the hyper-converged area and the core switch, and the hyper-converged area is also connected to the three-zone data center through a forward isolation network gateway; The network security management area is connected to the core switch.

2. The network security communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant according to claim 1, characterized in that The OPC server area includes an OPC server; The OPC server is connected to the core switch, and a firewall is set between the OPC server and the core switch.

3. A cybersecurity communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant, characterized in that, The intelligent controller area includes an intelligent controller; A communication card is installed on the intelligent controller; The intelligent controller is connected to the core switch through the communication card; a firewall is set between the communication card and the core switch.

4. A network security communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant according to claim 3, characterized in that, The intelligent controller is also connected to the DCS network.

5. A network security communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant, as claimed in claim 1, wherein The network security management area includes an industrial control information security supervision and analysis platform, a log audit module, an account management and operation and maintenance audit module, a database audit module, and a security management host.

6. The cybersecurity communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant according to claim 1, characterized in that, A number of hyper-converged nodes are set in the hyper-converged area.

7. A cybersecurity communication architecture for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant, characterized in that, The firewall is in the HA primary and standby mode.

8. A network security communication method for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant, as described in claims 1 to 7, characterized in that, It includes: The data in the production control major zone is read through the OPC server; The OPC server sends the read data to the hyper-converged area through the core switch; The hyper-converged area processes the data sent by the OPC server and sends the processed data to the intelligent controller area; The intelligent controller area processes the received data and then sends it to the DCS network.

9. A network security communication method for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant, as claimed in claim 8, wherein, The OPC server sends the read data to the hyper-converged area through the core switch, including: The OPC server sends the read data to the core switch through the OPC switch; The data received by the core switch is sent to the hyper-converged area through the hyper-converged management switch.

10. A network security communication method for the integration of IT and OT under the hyper-converged architecture of an intelligent thermal power plant according to claim 8, characterized in that, The hyper-converged area processes the data sent by the OPC server and sends the processed data to the intelligent controller area, including: The hyper-converged area sends the received data to the intelligent controller through the communication card, where the IP configurations of the intelligent controller and the communication card are: The IP of the intelligent controller is in the same network segment as the DCS controller. Among them, the second octet distinguishes between Network A and Network B, and the third octet distinguishes between units; The IP of the communication card distinguishes between Network A and Network B through the second octet; the third octet is newly added and cannot be the same as other systems.

Citation Information

Cited By

  • Power plant data center network security early warning management system

    CN116800474A