Supervisory control and data acquisition (SCADA) system based on private cloud technology
Through the SCADA system architecture based on private cloud technology, the connection of cloud host and gate is used to deploy the SCADA system of the oil and gas regulation center, the problems of high construction costs and insufficient security in traditional systems are solved, and cost reduction and system reliability are improved.
Patent Information
- Application Number
- CN202510930785.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-08-15
AI Technical Summary
The SCADA system of the traditional oil and gas regulation center is costly and has insufficient safety and reliability. The existing system lacks effective fault tolerance mechanism and resource monitoring, resulting in insufficient overall system reliability.
Adopt the SCADA system architecture based on private cloud technology, through the combination of private cloud platforms A and B, use cloud hosts and network gates to achieve secure connections, deploy SCADA systems and industrial software, realize real-time data collection and monitoring, and promote physical servers through a virtual server to reduce the number of physical devices, combine resource isolation and secure communication mechanisms to improve system security and reliability.
It effectively reduces the construction cost of the oil and gas regulation center, improves the safety and reliability of the system, realizes cross-regional resource monitoring and flexible deployment, and enhances the maintenance and resource utilization of the system.
Smart Images

Figure CN120499232A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of SCADA system construction for oil and gas control centers, and in particular to a SCADA system based on private cloud technology. Background Art
[0002] In the operation and maintenance of oil and gas extraction and storage and transportation, it is generally required to have no one or few people on duty on site. Therefore, large oil and gas fields, long-distance oil and gas pipelines, oil depots, and gas storage facilities need to achieve centralized operation, unified scheduling, and optimized operation. Based on the above needs, each oil field, long-distance oil and gas pipeline, gas storage facility group, etc. must build a large-scale oil and gas control center.
[0003] A traditional supervisory control and data acquisition (SCADA) system in an oil and gas control center typically requires four SCADA data servers, multiple data acquisition servers, multiple operator stations (typically one of which serves as an engineer station), multiple network security servers, and servers for industrial software. These servers and operator stations are connected via a central industrial switch, resulting in an oil and gas control center typically containing more than ten or even dozens of servers and a few to dozens of operator stations.
[0004] However, the existing SCADA system architecture of the control center has high construction costs and lacks security and reliability. Summary of the Invention
[0005] In view of this, this application provides a SCADA system based on private cloud technology, which builds the SCADA system architecture of the oil and gas control center through private cloud technology, effectively reducing the construction cost of the oil and gas control center on the basis of improving system security and reliability.
[0006] To solve the above problems, the technical solutions provided by this application are as follows:
[0007] On the one hand, the present application provides a SCADA system based on private cloud technology, the system including a private cloud platform A and a private cloud platform B, wherein the private cloud platform A and the private cloud platform B are connected via a network gatekeeper:
[0008] The private cloud platform A includes M cloud hosts, which are used to deploy the SCADA system of the oil and gas control center and software for network security of the SCADA system;
[0009] The private cloud platform B includes N cloud hosts, and the N cloud hosts are used to deploy industrial software and an intermediate database used in conjunction with the SCADA system.
[0010] In one possible implementation, the M cloud hosts include two SCADA real-time data servers, two SCADA historical data servers, one log audit and analysis server, one antivirus server, a operator stations, and 2b communication servers, where the a operator stations include a local operator station and a remote operator station, and a and b are integers not less than 1.
[0011] The N cloud hosts include 2 intermediate database servers, 1 advanced alarm management server and 1 remote diagnosis server.
[0012] In a possible implementation, the private cloud platform A and the private cloud platform B are respectively built by three high-performance servers.
[0013] In a possible implementation, the private cloud platform A and the private cloud platform B respectively include two switches, and each of the two switches is divided into multiple virtual local area networks (VLANs) for different business management of the SCADA system.
[0014] In a possible implementation, the multiple VLANs include VLANs used for network management, service data communication, server hardware management, and storage system communication.
[0015] In a possible implementation, the port corresponding to the storage VLAN is connected to the three high-performance servers of the private cloud platform through a high-speed cable.
[0016] In one possible implementation, the software on the private cloud platform A and the private cloud platform B are respectively authorized through a server-client model, and the server is one of the three high-performance servers of the private cloud platform.
[0017] In a possible implementation, the server authorizes the software by means of the IP address of the cloud host + the software ID.
[0018] In a possible implementation, the two SCADA real-time data servers, the two SCADA historical data servers, and the two intermediate database servers have an online migration function.
[0019] In a possible implementation, the three high-performance servers are servers with redundant hardware architectures.
[0020] It can be seen from the above technical solution that the technical solution provides a SCADA system based on private cloud technology, including private cloud platform A and private cloud platform B, and realizes secure connection through a network gateway, wherein private cloud platform A includes M cloud hosts for deploying the SCADA system of the oil and gas control center, and software for the network security of the SCADA system, realizing real-time data collection and monitoring, and effectively ensuring the network security of the system; private cloud platform B includes N cloud hosts for deploying industrial software and intermediate databases used in conjunction with the SCADA system, realizing centralized management of data and equipment resources, thereby reducing the number of physical devices of servers and operator stations and the construction cost of the oil and gas control center by deploying two private cloud platforms and using virtual servers to replace the operation nodes of physical servers, and reducing the construction cost of the oil and gas control center. In addition, relying on the resource isolation and secure communication mechanism of private cloud technology, the security and reliability of the system are effectively improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 A SCADA system architecture diagram based on private cloud technology provided in an embodiment of the present application;
[0023] Figure 2 A schematic diagram of VLAN division of a 10G switch provided in an embodiment of the present application;
[0024] Figure 3 A schematic diagram of a network port connection provided in an embodiment of the present application;
[0025] Figure 4 A schematic diagram of the hardware structure of a high-performance server provided in an embodiment of the present application;
[0026] Figure 5 This is a diagram of the SCADA system architecture for an oil and gas control center based on private cloud technology provided in an embodiment of the present application. DETAILED DESCRIPTION
[0027] In order to help those skilled in the art better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.
[0028] As mentioned in the background, a traditional oil and gas control center typically requires four SCADA data servers, multiple data acquisition servers, multiple operator stations (typically one of which serves as an engineer station), multiple network security servers, and servers for industrial software. These servers and operator stations are connected via a central industrial switch, resulting in an oil and gas control center typically housing more than ten or even dozens of servers of various types and a few to dozens of operator stations.
[0029] As a result, the existing control center SCADA system architecture has the following shortcomings:
[0030] 1. There is no monitoring of the resources used by each server and operator station, and no early warning of server and operator station overload, resulting in insufficient overall system reliability.
[0031] 2. Regarding the monitoring needs of various management offices and operating areas, many manufacturers' SCADA systems do not support deployment across complex networks or deploying operation nodes across complex networks will increase the instability of the SCADA system. Therefore, management of various regions is generally achieved by establishing a SCADA regional control center, resulting in excessively high construction costs and a complex implementation process.
[0032] 3. When a node in the SCADA system fails, except for the SCADA system's own redundancy mechanism (the SCADA system's redundancy mechanism is mainly for the SCADA system's data server), there is no other fault-tolerant mechanism, resulting in low system security.
[0033] 4. The data capacity of a single SCADA system is limited. Once the database of the SCADA system exceeds the upper limit, deploying another SCADA system requires re-setting up the corresponding server and its ancillary equipment, which is costly and time-consuming.
[0034] Based on the problems of insufficient security and reliability and high construction cost of the above-mentioned SCADA system, this application provides a SCADA system for an oil and gas control center. The solution provided in the embodiment of this application relates to the technical field of construction of SCADA system for an oil and gas control center, and is specifically explained through the following embodiments.
[0035] See also Figure 1As shown, it is an architectural diagram of a SCADA system based on private cloud technology provided in an embodiment of the present application.
[0036] The system includes a private cloud platform A and a private cloud platform B, which are connected via a network gateway.
[0037] Private cloud platform A includes M cloud hosts, which are used to deploy the SCADA system of the oil and gas control center and software for the network security of the SCADA system.
[0038] Private cloud platform B includes N cloud hosts, which are used to deploy industrial software and intermediate databases used in conjunction with the SCADA system.
[0039] A cloud host is a virtual server with its own operating system, IP address, and other resources. Based on the server nodes required for the SCADA system, cloud hosts can be planned on a private cloud platform built on physical servers, replacing physical servers with virtual servers to deploy the SCADA system.
[0040] As an example, private cloud platform A may include servers responsible for real-time data processing, servers responsible for historical data storage, antivirus servers, multiple operator stations, etc., and private cloud platform B may include servers responsible for process data processing, servers responsible for alarm management, and servers for managing industrial equipment, etc.
[0041] In one possible implementation, the M cloud hosts include 2 SCADA real-time data servers, 2 SCADA historical data servers, 1 log audit and analysis server, 1 antivirus server, a operator station, and 2b communication servers.
[0042] The a operator stations include local operator stations and remote operator stations, where a and b are integers not less than 1. All servers and local operator stations only allow local clients from the control center to log in. Remote operator stations can be set up to allow clients from various work areas, management offices, and other locations that require monitoring to log in, thereby achieving cross-regional resource monitoring.
[0043] SCADA database software is deployed on real-time SCADA data servers, responsible for the real-time collection, processing, storage, and distribution of process data. SCADA historical data servers are deployed with SCADA database software, responsible for storing process data and providing data support for historical data controls such as SCADA historical trends and reports. SCADA monitoring software is deployed on operator stations, primarily providing the human-computer interface for the SCADA system. Data acquisition software is deployed on data acquisition servers, collecting system data from various control units and pushing it to the SCADA real-time database. Log auditing and antivirus servers ensure the network security of the SCADA system.
[0044] The N cloud hosts include 2 intermediate database servers, 1 advanced alarm management server and 1 remote diagnosis server.
[0045] The intermediate database server deploys intermediate database software, reads data from servers such as the SCADA system, alarm management server, and remote diagnostic server, processes the data, and pushes it to other information platforms. The advanced alarm management server deploys alarm management software, reads alarm information from the SCADA system, and performs screening, statistical analysis, and other on-site monitoring. The remote diagnostic server provides online management of key equipment such as flow computers, control systems, pumps, and compressors.
[0046] All cloud hosts can be established by following the steps below, but the required resource sizes vary.
[0047] 1. Enter the cloud host management interface of the private cloud platform, where you can see the resources that can be used to create a cloud host. Then set the cloud host type, click Create Cloud Host, set the cloud host name, number of CPU cores, memory size, hard disk size, and click Create.
[0048] 2. Set the cloud host startup path and associated operating system files (can be Windows, UNIX, Liunx), click Start, and install the cloud host operating system.
[0049] 3. Partition the cloud host's disk, set the virtual network card connection method, set the network card IP address and other cloud host parameters, and set the cloud host's importance level.
[0050] 4. Restart the created cloud host and check whether the running status of the cloud host is normal on the cloud platform.
[0051] Virtual servers on each private cloud platform can be established according to actual production and monitoring needs, so that each virtual server can assume its own functional tasks, thereby realizing centralized management and dynamic allocation of resources, effectively improving the system's maintainability and resource utilization.
[0052] The private cloud platform needs to be built based on physical servers. In one possible implementation, private cloud platform A and private cloud platform B are built with three high-performance servers respectively.
[0053] The performance of high-performance servers can be selected based on the actual situation of the oil and gas control center. Each high-performance server is equipped with a Redundant Array of Independent Disks (RAID), generally configured as RAID1 or RAID5, to improve data storage efficiency and security. Each high-performance server also has a Baseboard Management Controller (BMC) configuration and management to achieve remote management and monitoring.
[0054] Therefore, the private cloud platform built with high-performance servers meets the actual operation needs of the SCADA system. At the same time, combined with RAID and BMC management and control functions, it ensures the security and reliability of the system.
[0055] In a possible implementation, private cloud platform A and private cloud platform B each include two switches, and each switch is divided into multiple virtual local area networks (VLANs) for different business management of the SCADA system.
[0056] SCADA systems typically include multiple business types, such as real-time data acquisition, historical data storage, industrial control, alarm management, etc., and each type of business has different requirements for network performance and security.
[0057] Divide the physical switch into multiple VLANs to achieve logical isolation of different network services, enabling separate management and optimization, thereby improving network security and management efficiency.
[0058] In one possible implementation, the multiple VLANs include VLANs for network management, service data communication, server hardware management, and storage system communication.
[0059] Among them, the VLAN used for network management can transmit network management-related data and support the configuration and monitoring of network devices (such as switches and routers). The VLAN used for business data communication carries the core business data flow of the SCADA system, including real-time data acquisition, control command transmission, etc. The VLAN used for server hardware management is dedicated to BMC communication. The VLAN used for storage system communication is responsible for data reading and writing between servers and storage devices, and supports data storage and backup operations.
[0060] By dividing management, business, BMC and storage VLANs, the actual business needs of the SCADA system are met, and the logical isolation and security management of different network services are achieved.
[0061] In a possible implementation, the port corresponding to the storage VLAN is connected to the three high-performance servers of the private cloud platform through a high-speed cable.
[0062] Storage networks transmit large amounts of data frequently, requiring high-speed, stable transmission links to avoid bottlenecks.
[0063] High-speed cables improve communication efficiency between servers and storage VLANs, meeting the SCADA system's high requirements for real-time performance and data throughput, and further improving the system's overall performance and reliability.
[0064] The construction process of the two private cloud platforms is the same. The following describes the construction process of one private cloud platform to help understand the architecture of the SCADA system based on private cloud technology. The details of the construction process are as follows:
[0065] 1. Plan the network IP address of the entire control center, including the IP segments of the three physical servers, the IP segment of the cloud host, and the IP segment of the business network VLAN.
[0066] 2. Prepare three high-performance servers and two 10G interactive machines. The high-performance servers require four 10GE electrical ports and two 10GE optical ports. Each server is pre-installed with Linux as the operating system. The two 10G interactive machines are required to be configured with 16 SFP+ ports and 24 Gigabit electrical ports.
[0067] 3. Configure RAID on the server: After starting the server, enter the RAID configuration interface. Generally, you can choose to configure it as RAID1 or RAID5. The purpose of configuring RAID is to improve data storage efficiency and security.
[0068] 4. Server BMC configuration and management: Select the root account, set the root account username and password, enter the server remote management module to set relevant permissions, and set the IP address according to the network planning of the control center.
[0069] 5. The first 24 ports of the two 10G switches are Gigabit electrical ports, and the last 16 ports are SFP+ ports. Figure 2A VLAN division diagram of a 10 Gigabit switch provided in an embodiment of the present application is provided. For each 10 Gigabit switch in private cloud platform A and private cloud platform B, it is divided into four VLANs, where switch ports 1-8 are 1 VLAN, serving as the management network of the cloud platform, switch ports 9-16 are 1 VLAN, serving as the cloud platform business network, switch ports 17-24 are 1 VLAN, serving as the cloud platform BMC network, switch ports 25-32 are 1 VLAN, serving as the cloud platform storage network, and switch port 40 is a Trunk port, serving as the data interaction port between the two switches. The difference is that the VLAN numbers divided into the management network and the business network in the two private cloud platforms are inconsistent to avoid cross-platform access to the management network and the business network.
[0070] 6. Cloud platform hardware connection: Connect the management network port, business network port, BMC network port, and storage network port of the three high-performance servers to the corresponding ports of the two switches respectively. The storage network port and the switch Trunk port are connected using 10 Gigabit SFP+DAC high-speed cables, and the other business network ports are connected using network cables. Figure 3 This is a schematic diagram of a network port connection provided by an embodiment of the present application. In the diagram, node01, node01, and node03 are used to identify three high-performance servers. Figure 4 A schematic diagram of the hardware structure of a high-performance server provided in an embodiment of the present application, according to Figure 3 The corresponding relationship between each VLAN and the electrical port or optical port of the high-performance server is used to connect the network cable. For example, the management network port (1-8 electrical ports) in the private cloud platform A is connected to the C port of each server in the three high-performance servers. Figure 4 Connect to the 10G network interface-1 in the .
[0071] 7. Install cloud platform related software on a high-performance server. After checking that the service and connection are normal, log in to the cloud platform management interface through the web to check whether the cloud platform resources are normal and place the required operating system files on the cloud platform.
[0072] Since SCADA systems and industrial software have licensing restrictions, it is usually necessary to use a licensed software dog to authorize the software. Generally, the software dog comes with the corresponding software license and is plugged into the USB port of each server and workstation. Since it is impossible to achieve a one-to-one relationship between the software dog and each cloud host on the cloud platform, it is impossible to use the traditional software authorization model to authorize the SCADA system and various industrial software.
[0073] In one possible implementation, the software on private cloud platform A and private cloud platform B are authorized respectively through a server-client model.
[0074] The server is one of the three high-performance servers of the private cloud platform.
[0075] The server is responsible for unified control of the authorization allocation and verification of all software in the private cloud platform, thereby realizing authorization management through communication between the client software on the cloud host and the server.
[0076] In a possible implementation, the server authorizes the software by means of the IP address of the cloud host + the software ID.
[0077] For example, if a cloud host with an IP address of 172.20.1.100 requires a software license with ID 02, you need to configure the license with ID 02 on the server used for software license allocation to allow only network access to the cloud host at 172.20.1.100.
[0078] The server performs authorization management on the deployed software by binding the IP address of the cloud host and the software ID, ensuring that the software runs legally only in the designated cloud host environment, effectively preventing unauthorized use.
[0079] Based on the above, the steps for software authorization on the same private cloud platform include:
[0080] 1. All software licenses on a cloud platform are on a software dongle, and each software license is given a unique ID.
[0081] 2. Select a high-performance server as the software authorization distribution server, install the software authorization distribution software, and install the software dog client plug-in on all cloud hosts that require authorization.
[0082] 3. Authorize each cloud host in the software authorization allocation software. The specific authorization allocation method is IP address + software ID.
[0083] 4. On the software dog client plug-in installed on the cloud host, configure authorization to allow access to the software authorization server through the network.
[0084] 5. Check whether the software authorization of the cloud host is normal.
[0085] Existing technologies lack fault-tolerance mechanisms other than redundancy mechanisms for SCADA system data servers. Compared to traditional oil and gas control center SCADA system architectures, the oil and gas control center SCADA system based on private cloud technology can leverage cloud platform software to provide real-time monitoring and over-limit alarms for key operating parameters such as CPU load, temperature, network traffic, and memory usage of high-performance servers and cloud hosts, ensuring visualization of system maintenance information.
[0086] In a possible implementation, two SCADA real-time data servers, two SCADA historical data servers, and two intermediate database servers have an online migration function.
[0087] The SCADA system regularly mirrors these cloud hosts (with image files automatically overwritten based on timelines). If a cloud host's resources are damaged, they can be migrated to other cloud hosts, preventing resource loss and business interruption, effectively ensuring system security and reliability. The system also regularly mirrors historical SCADA data and intermediate database data to facilitate post-disaster data recovery.
[0088] In a possible implementation, the three high-performance servers are servers with redundant hardware architectures.
[0089] The SCADA system uses high-performance servers with fault-tolerant mechanisms, including redundant power supplies and redundant CPUs, which can increase the fault tolerance rate at the hardware level and further improve the security and reliability of the system.
[0090] refer to Figure 5 The figure shows an architecture diagram of a SCADA system for an oil and gas control center based on private cloud technology, provided in an embodiment of the present application. The SCADA system includes two private cloud platforms connected by a network gateway to ensure the isolation and security of system resources. Each private cloud platform includes three high-performance servers and two 10G switches, and the switch networks are divided using VLAN technology to achieve resource or business isolation. In addition to virtual servers for deploying the SCADA system and its ancillary systems or software, each private cloud platform also includes n backup servers, ready to take over critical tasks at any time to ensure the normal operation of the system.
[0091] This SCADA system overcomes some technical pain points of the existing SCADA system in the control center:
[0092] 1. Relying on the centralized management and unified configuration of private cloud technology, the number of physical devices of servers and operator stations is reduced, effectively reducing the construction cost of the control center.
[0093] 2. By increasing the number of cloud hosts on a private cloud platform, you can achieve flexible deployment of multiple SCADA systems without having to purchase servers repeatedly. The cloud hosts support multiple operating system environments and can adapt to the compatibility of different SCADA systems or industrial software, thereby enhancing the flexibility of business expansion and the convenience of system maintenance.
[0094] 3. Cloud platform software can be used to monitor and warn the operation of resources such as cloud hosts and hardware servers online. When a failure occurs, the cloud platform's fault-tolerant mechanism can be used to maximize the normal operation of the control center's SCADA system, industrial software platform, and intermediate database, thereby improving safety and reliability.
[0095] 4. In response to the monitoring needs of each operation area or management office for its jurisdiction, remote access can be achieved through the operation nodes deployed on the cloud host, without the need to build a corresponding regional control center, further saving costs.
[0096] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems or devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the method description.
[0097] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A SCADA system based on private cloud technology, characterized in that: The system includes a private cloud platform A and a private cloud platform B, wherein the private cloud platform A and the private cloud platform B are connected via a network gateway: The private cloud platform A includes M cloud hosts, which are used to deploy the SCADA system of the oil and gas control center and software for network security of the SCADA system; The private cloud platform B includes N cloud hosts, and the N cloud hosts are used to deploy industrial software and an intermediate database used in conjunction with the SCADA system.
2. The system according to claim 1, wherein: The M cloud hosts include two SCADA real-time data servers, two SCADA historical data servers, one log audit and analysis server, one antivirus server, a operator station, and 2b communication servers, wherein the a operator station includes a local operator station and a remote operator station, and a and b are integers not less than 1; The N cloud hosts include 2 intermediate database servers, 1 advanced alarm management server and 1 remote diagnosis server.
3. The system according to claim 1, wherein: The private cloud platform A and the private cloud platform B are respectively built by three high-performance servers.
4. The system according to claim 3, characterized in that The private cloud platform A and the private cloud platform B respectively include two switches, and each of the two switches is divided into multiple virtual local area networks (VLANs) for different business management of the SCADA system.
5. The system according to claim 4, characterized in that The multiple VLANs include VLANs for network management, business data communication, server hardware management, and storage system communication.
6. The system according to claim 5, characterized in that The ports corresponding to the storage VLAN are connected to the three high-performance servers of the private cloud platform through high-speed cables.
7. The system according to claim 3, wherein: The software on the private cloud platform A and the private cloud platform B are respectively authorized through the server-client mode, and the server is one of the three high-performance servers of the private cloud platform.
8. The system according to claim 7, characterized in that The server authorizes the software by means of the IP address of the cloud host + software ID.
9. The system according to claim 2, wherein: The two SCADA real-time data servers, the two SCADA historical data servers and the two intermediate database servers have an online migration function.
10. The system according to claim 3, wherein: The three high-performance servers are servers with redundant hardware architecture.