Implementation method of safe and credible intelligent decentralized control system

By expanding the DCS control layer network and adding an intelligent control layer and video layer, combined with intelligent controllers and data centers, the secure and reliable integration of the industrial control system is achieved, solving the security and intelligence issues of DCS and improving data processing efficiency.

CN121325784APending Publication Date: 2026-01-13NANJING GUODIAN NANZI WEIMEIDE AUTOMATION CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511427318.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

In existing industrial control systems, distributed control systems (DCS) have security and intelligence deficiencies, are vulnerable to network attacks, traditional protection is inadequate to deal with unknown threats, control algorithms are lagging behind, they are unable to handle massive data and complex multivariate coupling problems, data silos between subsystems are serious, and they cannot support the real-time operation of advanced intelligent applications.

Method used

Expand the redundant network of the DCS control layer, add intelligent control layer and video layer networks, establish a multi-layer network structure, adopt intelligent controllers and intelligent application servers, combine with automated intelligent data centers for data acquisition and storage, embed video linkage technology, and build a complete trust chain from hardware to application layer through trusted deployment.

Benefits of technology

It improves the security, intelligence, and data processing efficiency of industrial control systems, and enables reliable deployment and integrated management of nodes at all levels, making it suitable for industrial scenarios such as intelligent power plants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121325784A_ABST
    Figure CN121325784A_ABST
Patent Text Reader

Abstract

The invention discloses an implementation method of a safe and credible intelligent decentralized control system, and belongs to the technical field of industrial control systems. By expanding an original DCS control layer redundant network, a multi-layer structure of an intelligent control layer and a video layer independent redundant network is constructed; the intelligent controller and the intelligent application server adopt an intelligent algorithm and are combined with the automatic intelligent data center to complete data processing; a video linkage technology is embedded to realize the integration of the DCS and a video system; a complete trust chain from hardware to an application layer is constructed through the trusted computing technology, and trusted deployment and integrated management and control of nodes of all levels are achieved. The safety, the intelligent level and the data processing efficiency of the industrial control system are improved, and the system is suitable for industrial scenes such as digital intelligent power plants and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial control system technology, specifically to a method for implementing a secure and reliable intelligent distributed control system. Background Technology

[0002] In existing industrial control systems, Distributed Control Systems (DCS), as the core control unit, still suffer from security and intelligence deficiencies. The hardware and software components of DCS may contain backdoor vulnerabilities, making them susceptible to cyberattacks, and traditional static protection methods are insufficient to address unknown threats. Facing the demands of new power systems for deep peak shaving and rapid response, traditional DCS control algorithms lag behind, struggling to handle massive amounts of data and complex multivariate coupling problems, resulting in limited automation and intelligent decision-making capabilities. Intelligent applications lack efficient data acquisition, storage, and interaction mechanisms, leading to severe data silos between subsystems and hindering the real-time operation of advanced intelligent applications. The separation of DCS from functions such as video surveillance and trusted management results in delayed operation and maintenance responses, making integrated management difficult. While existing technologies have improved unit efficiency, they have not solved inherent system security issues, and mature solutions for intelligent algorithm integration and trusted computing fusion are still lacking. Therefore, there is an urgent need for a distributed control system implementation method that combines security, reliability, intelligence, efficiency, and integrated management. Summary of the Invention

[0003] The purpose of this invention is to provide a secure and reliable intelligent distributed control system implementation method to solve the problems mentioned in the background art.

[0004] To solve the above-mentioned technical problems, the present invention provides the following technical solution: A method for implementing a secure and reliable intelligent distributed control system includes the following steps: Expand the existing DCS control layer redundant network, add an independent intelligent control layer redundant network and video layer network, and establish a multi-layer network structure. In the intelligent control layer, intelligent controllers and intelligent application servers use intelligent algorithms, combined with an automated intelligent data center, to collect data, issue commands, and store data. The DCS operator station uses embedded video linkage technology to access video information from the video server. Trustworthy deployment is carried out on each node of the DCS control layer, intelligent control layer, and video layer.

[0005] As a preferred embodiment of the secure and reliable intelligent distributed control system implementation method of the present invention, the step of expanding the original DCS control layer redundant network, adding an independent intelligent control layer redundant network and a video layer network, and establishing a multi-layer network structure further includes: The DCS control layer, intelligent control layer, and video layer are physically isolated from each other in the network. The DCS control layer and the intelligent control layer are connected via redundant industrial Ethernet, and different functional areas are isolated by secure partitioning. The intelligent control layer is connected to the server via 10 Gigabit Ethernet, supporting data fragmentation transmission and breakpoint resumption. The video layer is networked independently and isolated from the control layer by a firewall, with only the video access port open.

[0006] As a preferred embodiment of the secure and reliable intelligent distributed control system of the present invention, the intelligent control layer, in which the intelligent controller and intelligent application server employ intelligent algorithms, and in conjunction with an automated intelligent data center, performs data acquisition, instruction issuance, and data storage. The specific implementation process includes: The intelligent control layer includes intelligent controllers, intelligent data centers, and intelligent application servers; The intelligent controller adopts a multi-core parallel computing architecture, runs basic control algorithms and lightweight intelligent algorithms in the algorithm module, and encapsulates the algorithm module through an algorithm container to dynamically adjust parameters; The intelligent application server deploys advanced algorithms for deep peak shaving optimization and coordinated control, generates control commands based on big data training models, and sends them to the intelligent controller after being encrypted by the national cryptographic symmetric encryption algorithm. The automated intelligent data center stores real-time data through a time-series database and distributes data on demand using a publish-subscribe model to support real-time computing for intelligent applications. The automated intelligent data center includes a sentinel server and an intelligent data center.

[0007] As a preferred embodiment of the secure and reliable intelligent distributed control system implementation method of the present invention, the data processing flow of the intelligent control layer includes: Real-time status data is acquired from field devices by conventional controllers and uploaded to intelligent controllers and intelligent data centers, triggering data transmission commands for distributed control historical stations; When the distributed control historical station receives the data transmission instruction, it transmits the stored historical status data to the intelligent data center; The intelligent controller performs intelligent logic operations based on real-time status data, and issues control commands to the conventional controller according to the operation results to regulate the field equipment; at the same time, the operation results and operation parameters are transmitted to the intelligent data center. The intelligent data center cleans and monitors the received data, and then interacts bidirectionally with the intelligent application server; based on the interaction results, it optimizes the control strategy and sends control commands or parameter optimization data to the conventional controller. The interaction result optimization control strategy includes: when the output adjustment object of the interaction result does not overlap with the calculation result of the intelligent controller, outputting the overlapping part and adjusting the parameters of the intelligent controller algorithm; and monitoring the data cleaning process and status of the intelligent data center through the sentinel server. The bidirectional interaction with the intelligent application server includes: the intelligent data center providing data acquisition services to the intelligent application server, and the intelligent application server performing in-depth analysis and processing of the data through intelligent algorithms, outputting algorithm results and feeding them back to the intelligent data center.

[0008] As a preferred embodiment of the secure and reliable intelligent distributed control system of the present invention, the intelligent data center cleans and monitors the status of the received data, and then engages in bidirectional interaction with the intelligent application server, including: Based on the received data, the search path and influencing factors of the relational data are obtained, historical working conditions are matched in the time series database, and the current output is verified to optimize the target variable; wherein, the influencing factor represents the weight used to quantify the influence of each variable on the target. Based on the priority of the search path, retrieve the operating condition range of the current output historical status data that meets the standard from the time series database; Extract the target variable for the operating condition interval and compare it with the predicted value corresponding to the current output. If the target variable for the operating condition interval is better than the current operating condition, the output verification is valid; if the target variable for the operating condition interval is not optimized, the output verification is invalid. When the verification is valid, the intelligent data center outputs control commands / parameters to the intelligent controller, driving the unit to execute the output commands; when the verification is invalid, an iterative mechanism is triggered, and intelligent calculations are re-executed by adjusting the range of output variables, optimizing algorithm parameters, and switching algorithm models until the output verification passes. After the unit executes the output command, the intelligent data center collects the real-time optimization effect and updates the relational data in reverse: if a certain variable contributes more significantly to the optimization of the target, the priority of the search path is upgraded; based on multiple regression analysis, the influence weight of the variable on the target is recalculated.

[0009] As a preferred embodiment of the secure and reliable intelligent distributed control system of the present invention, the specific implementation process of reliably deploying each node of the DCS control layer, intelligent control layer, and video layer includes: When each node starts up, based on the root of trust, it performs step-by-step measurements starting from the boot firmware to verify the static and dynamic integrity of the hardware, firmware, operating system and application system, and build a trusted chain of trust. The trusted management platform monitors the running status of each node in real time and senses the trusted status of key files. If the status is abnormal, an alarm is triggered. The key files include control algorithms and configuration parameters. Log data recording node measurement processes, policy changes, and abnormal event handling is encrypted and stored in a trusted database using the national cryptographic symmetric encryption algorithm.

[0010] As a preferred embodiment of the secure and reliable intelligent distributed control system implementation method of the present invention, the specific management process of the reliable management platform includes: Initial baseline values ​​are collected for all nodes. For critical files, the hash value is calculated by calling the national cryptographic hash algorithm through the trusted cryptographic module and then encrypted and stored in the trusted database. When each node is running, it performs periodic or real-time hash calculations on key files according to the trusted policy and compares them with the baseline value stored in the local trusted cryptographic module. If a discrepancy occurs, an abnormal event is generated, which includes the file name, the current hash value, the timestamp, and the node IP. After an abnormal event is signed by the trusted cryptography module using the national cryptographic asymmetric encryption algorithm, it is uploaded to the trusted management platform; the trusted management platform handles the event in a tiered manner according to preset rules and responds to security threats.

[0011] Compared with existing technologies, the beneficial effects achieved by this invention are as follows: In the secure and reliable intelligent distributed control system implementation method provided by this invention, a multi-layered structure is constructed by extending the original DCS control layer redundant network to build independent redundant networks for the intelligent control layer and video layer; intelligent controllers and intelligent application servers are used to implement intelligent algorithms, combined with an automated intelligent data center to complete data processing; video linkage technology is embedded to achieve the integration of DCS and video systems; and a complete trust chain from hardware to the application layer is constructed through trusted computing technology to achieve trusted deployment and integrated management of nodes at each level. This invention improves the security, intelligence level, and data processing efficiency of industrial control systems and is suitable for industrial scenarios such as intelligent power plants. Attached Figure Description

[0012] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof.

[0013] Figure 1 This is a diagram of the secure and reliable intelligent distributed control system architecture in an embodiment of the present invention; Figure 2 This is a flowchart of the data processing of the intelligent control system in an embodiment of the present invention; Figure 3 This is a flowchart of the data processing of the intelligent application server and intelligent data center in an embodiment of the present invention. Detailed Implementation

[0014] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0015] Please see Figures 1-3 In this first embodiment, a method for implementing a secure and reliable intelligent distributed control system is provided, which includes the following steps: Expand the existing DCS control layer redundant network, add an independent intelligent control layer redundant network and video layer network, and establish a multi-layer network structure. In the intelligent control layer, intelligent controllers and intelligent application servers use intelligent algorithms, combined with an automated intelligent data center, to collect data, issue commands, and store data. The DCS operator station uses embedded video linkage technology to access video information from the video server. Trustworthy deployment is carried out on each node of the DCS control layer, intelligent control layer, and video layer.

[0016] Specifically, the expansion of the existing DCS control layer redundant network, the addition of an independent intelligent control layer redundant network and a video layer network, and the establishment of a multi-layered network structure also include: The DCS control layer, intelligent control layer, and video layer are physically isolated from each other in the network. The DCS control layer and the intelligent control layer are connected via redundant industrial Ethernet, and different functional areas are isolated by secure partitioning. The intelligent control layer is connected to the server via 10 Gigabit Ethernet, supporting data fragmentation transmission and breakpoint resumption. The video layer is networked independently and isolated from the control layer by a firewall, with only the video access port open.

[0017] A multi-layered network structure is adopted, expanding the original DCS control layer redundant network and adding an independent intelligent control layer redundant network, such as the network that carries intelligent algorithms and data interaction and the video layer network, such as connecting cameras and video servers, and achieving hierarchical isolation through firewalls.

[0018] Each network node includes intelligent controllers, such as those using domestic Phytium CPUs and embedded trusted cryptographic modules; intelligent application servers, such as high-performance computing nodes; automated intelligent data centers, such as those containing redundant data servers and data sentinels; video servers, such as those connected to multiple high-definition cameras; DCS terminals, such as conventional controllers and host computers; and trusted management platforms, such as those deployed on management nodes.

[0019] Trusted terminals embed physical trust roots that support national cryptographic algorithms such as SM2, SM3, and SM4 at the hardware layer, building a trust chain foundation of "hardware root-firmware-operating system-application".

[0020] Specifically, in the intelligent control layer, the intelligent controller and intelligent application server employ intelligent algorithms, and the specific implementation process of data acquisition, instruction issuance, and data storage in conjunction with the automated intelligent data center includes: The intelligent control layer includes intelligent controllers, intelligent data centers, and intelligent application servers; The intelligent controller adopts a multi-core parallel computing architecture, runs basic control algorithms and lightweight intelligent algorithms in the algorithm module, and encapsulates the algorithm module through an algorithm container to dynamically adjust parameters; The intelligent application server deploys advanced algorithms for deep peak shaving optimization and coordinated control, generates control commands based on big data training models, and sends them to the intelligent controller after SM4 encryption; The automated intelligent data center stores real-time data through a time-series database and distributes data on demand using a publish-subscribe model to support real-time computing for intelligent applications. The automated intelligent data center includes a sentinel server and an intelligent data center.

[0021] Specifically, the data processing flow of the intelligent control layer includes: Real-time status data is acquired from field devices by conventional controllers and uploaded to intelligent controllers and intelligent data centers, triggering data transmission commands for distributed control historical stations; When the distributed control historical station receives the data transmission instruction, it transmits the stored historical status data to the intelligent data center; The intelligent controller performs intelligent logic operations based on real-time status data, and issues control commands to the conventional controller according to the operation results to regulate the field equipment; at the same time, the operation results and operation parameters are transmitted to the intelligent data center. The intelligent data center cleans and monitors the received data, and then interacts bidirectionally with the intelligent application server; based on the interaction results, it optimizes the control strategy and sends control commands or parameter optimization data to the conventional controller. The interaction result optimization control strategy includes: when the output adjustment object of the interaction result does not overlap with the calculation result of the intelligent controller, outputting the overlapping part and adjusting the parameters of the intelligent controller algorithm; and monitoring the data cleaning process and status of the intelligent data center through the sentinel server. The bidirectional interaction with the intelligent application server includes: the intelligent data center providing data acquisition services to the intelligent application server, and the intelligent application server performing in-depth analysis and processing of the data through intelligent algorithms, outputting algorithm results and feeding them back to the intelligent data center.

[0022] Specifically, the intelligent data center cleans and monitors the received data, and then engages in bidirectional interaction with the intelligent application server, including: Based on the received data, the search path and influencing factors of the relational data are obtained, historical working conditions are matched in the time series database, and the current output is verified to optimize the target variable; wherein, the influencing factor represents the weight used to quantify the influence of each variable on the target. Based on the priority of the search path, retrieve the operating condition range of the current output historical status data that meets the standard from the time series database; Extract the target variable for the operating condition interval and compare it with the predicted value corresponding to the current output. If the target variable for the operating condition interval is better than the current operating condition, the output verification is valid; if the target variable for the operating condition interval is not optimized, the output verification is invalid. When the verification is valid, the intelligent data center outputs control commands / parameters to the intelligent controller, driving the unit to execute the output commands; when the verification is invalid, an iterative mechanism is triggered, and intelligent calculations are re-executed by adjusting the range of output variables, optimizing algorithm parameters, and switching algorithm models until the output verification passes. After the unit executes the output command, the intelligent data center collects the real-time optimization effect and updates the relational data in reverse: if a certain variable contributes more significantly to the optimization of the target, the priority of the search path is upgraded; based on multiple regression analysis, the influence weight of the variable on the target is recalculated.

[0023] Specifically, the implementation process for the trusted deployment of each node in the DCS control layer, intelligent control layer, and video layer includes: When each node starts up, based on the root of trust, it performs step-by-step measurement starting from the boot firmware Uboot / BIOS to verify the static and dynamic integrity of the hardware, firmware, operating system and application system, and build a trusted chain of trust. The trusted management platform monitors the running status of each node in real time and senses the trusted status of key files. If the status is abnormal, an alarm is triggered. The key files include control algorithms and configuration parameters. Log data recording node measurement processes, policy changes, and abnormal event handling is stored in a trusted database and encrypted with SM4.

[0024] Specifically, the management process of the trusted management platform includes: Initial baseline values ​​are collected for all nodes. For critical files, the hash value is calculated by calling the SM3 national cryptographic hash algorithm through the trusted cryptographic module and then encrypted and stored in the trusted database. When each node is running, it performs periodic or real-time hash calculations on key files according to the trusted policy and compares them with the baseline value stored in the local trusted cryptographic module. If a discrepancy occurs, an abnormal event is generated, which includes the file name, the current hash value, the timestamp, and the node IP. Abnormal events are signed by the trusted cryptographic module using the national standard asymmetric encryption algorithm SM2 and then uploaded to the trusted management platform. The trusted management platform handles the events in a tiered manner according to preset rules and responds to security threats.

[0025] The overall architecture of a secure and reliable intelligent distributed control system includes a distributed control system, an intelligent control system, a video linkage system, and a reliable management system, such as... Figure 1 As shown.

[0026] The system network adopts a multi-layered architecture, divided into a DCS control layer, an intelligent control layer, and a video layer. These layers are physically isolated, ensuring the integrity of network data packets in the real-time control layer without increasing its network load. The process control layer and the intelligent control layer are connected via redundant industrial Ethernet, employing secure partitioning to isolate different functional areas. The intelligent control layer and the data center layer are connected via 10 Gigabit Ethernet, supporting data fragmentation and resume capability. The video layer operates independently, isolated from the control layer via a firewall, allowing for deep detection of industrial protocols, with only video access ports open.

[0027] A distributed control system (DCS) comprises conventional controllers, historical data stations, engineering workstations, operator workstations, and communication interface units. Conventional controllers are redundantly configured, connecting to field sensors such as temperature and pressure transmitters and actuators such as control valves via I / O modules, responsible for real-time data acquisition and basic control logic execution. Historical data stations are also redundantly configured, acquiring and storing process data in real-time through a time-series database. Multiple engineering workstations are configured, using graphical configuration software to build control logic. Multiple operator workstations are configured, displaying real-time process flow and parameters, providing interactive functions such as control command issuance, alarm viewing, and trend monitoring, and linking with a video server to achieve synchronous "data + video" monitoring. The communication interface units interact with third-party systems, such as SIS and environmental protection equipment, via standard protocols such as Modbus and OPCUA, enabling bidirectional data transmission.

[0028] The intelligent control system includes intelligent controllers, intelligent data centers, and intelligent application servers.

[0029] The intelligent controller features redundant configuration and adopts a multi-core parallel computing architecture to run basic control algorithms, such as PID and lightweight intelligent algorithms, such as adaptive control. It also supports the dynamic loading of third-party algorithms using algorithm containers, allowing the control logic to be updated without downtime, adapting to different unit characteristics and scenario requirements, such as parameter adaptive algorithms for wide-load cruise.

[0030] The intelligent application server is redundantly configured to undertake computationally intensive tasks, including mining massive amounts of operational data, such as three months of historical load data, constructing multivariate coupling models, such as boiler-turbine coordination mechanism models, and training algorithms with big data, such as LSTM neural network prediction models in deep peak shaving, to support the real-time operation of complex algorithms and realize deep peak shaving optimization of generator sets.

[0031] The intelligent data center is equipped with two redundant data center servers and one data sentinel server. It features a high-capacity, high-speed read / write time-series database, supporting the management of millions of tags. Through a high-capacity internal communication protocol, it interacts with the intelligent control system and distributed control system, receiving real-time collected field data to provide historical and real-time data support for intelligent algorithms, while also distributing processed optimization parameters. The redundant data center servers ensure real-time data synchronization and seamless failover in case of single-point failures. The data sentinel server monitors data consistency, detects anomalies such as data jumps, and triggers alarms to prevent invalid data from flowing into the intelligent application server.

[0032] The data processing flow of an intelligent control system, such as Figure 2 As shown, the division of labor and interaction in each stage are as follows: Conventional controllers acquire status data, such as temperature and pressure, from field devices. This data is used for their own logic calculations and can also be transmitted to intelligent controllers and intelligent data centers. Distributed control system (DCS) historical data stations can also transmit stored status data to the intelligent data center. To reduce the communication load on conventional controllers, the intelligent data center preferentially obtains data from the DCS historical data stations.

[0033] The intelligent controller subscribes to the status data of the conventional controller, performs intelligent logic operations based on this data, and then sends control commands to the conventional controller to regulate the field equipment. On the other hand, it transmits the current intelligent algorithm output and intelligent algorithm parameters to the intelligent data center.

[0034] The intelligent data center aggregates various data sources from conventional controllers, intelligent controllers, and historical stations in distributed control systems. It cleans the data, removing noise and outliers, and monitors its status before engaging in bidirectional interaction with the intelligent application server. The intelligent data center provides data acquisition services to the intelligent application server, while the intelligent application server feeds back the results of complex intelligent algorithms to the intelligent data center for optimizing control strategies. Simultaneously, the intelligent data center also interacts with the sentinel server, which monitors the data cleaning process and status of the intelligent data center to ensure data quality and system stability.

[0035] The intelligent application server acquires data from the intelligent data center and, with the help of massive data mining, multivariate coupling model construction, and big data training algorithms such as LSTM neural networks, performs in-depth analysis and processing of the data, outputting algorithm results. When the adjustment object of the intelligent application server's algorithm output does not overlap with the calculation of the intelligent controller, the control commands or parameter optimization data are sent to the conventional controller. For the overlapping parts of the adjustment object of the intelligent application server's algorithm output and the calculation of the intelligent controller, parameter adjustment is used to adjust the algorithm parameters of the intelligent controller. Before outputting data, the intelligent application server performs algorithm verification on the output data based on historical data from the intelligent data center.

[0036] The intelligent application server, through four stages—"complex intelligent computation → output verification → result decision → closed-loop optimization"—combines time-series data, historical operating conditions and relational data, and rule models from the intelligent data center to achieve precise output and dynamic iteration of multi-variable control commands / parameters. This enables reliability verification while simultaneously outputting intelligent algorithms. The data processing flowchart of the intelligent application server and intelligent data center is shown below. Figure 3 As stated above.

[0037] The intelligent application server performs complex intelligent calculations to obtain time-series data from the intelligent data center, such as the unit's load, steam pressure, and coal quality data for the past three months, which are recorded in seconds. It then performs complex intelligent calculations, such as LSTM prediction, genetic algorithms, and multivariate coupling models, to generate multivariate outputs, such as the combination of coal feed rate, air volume, and turbine valve opening during deep peak shaving.

[0038] Intelligent data centers use the "search path" and "influence factor" of relational data to match historical operating conditions in time series databases and verify whether the current output can optimize target variables, such as coal consumption and NOx emissions.

[0039] Define the search priority for multiple variables, such as prioritizing matching "gate opening" → "air volume" → "coal feed", reflecting the hierarchical influence of variables on the system; quantify the weight of each variable's influence on the target, define influence factors, such as 0.6 for coal feed, 0.3 for air volume, and 0.1 for gate opening, and normalize the sum.

[0040] Based on the priority of the search path, retrieve the historical operating condition range closest to the current output from the time series database, such as a continuous 10-minute data segment with an error ≤ 5%; Extract target variables from historical intervals, such as coal consumption rate and NOx concentration, and compare them with the predicted values ​​corresponding to the current output. If the target variables in the historical interval are better than the current operating conditions, such as a reduction in coal consumption of ≥2g / kWh, it indicates that the output logic is reasonable and the output validation is effective. If the target variables in the historical interval are not optimized, such as an increase in NOx, it indicates that there is a risk in the output and the output validation is invalid.

[0041] When the verification is valid, the intelligent data center outputs control commands / parameters to the intelligent controller or DCS to drive the unit to execute. When the verification is invalid, an iterative mechanism is triggered. This can be achieved by adjusting the range of output variables, such as narrowing the fluctuation range of coal feed, optimizing algorithm parameters, such as reducing the mutation rate of the genetic algorithm, or switching the algorithm model, such as switching from a genetic algorithm to a reinforcement learning model. Complex intelligent calculations are then re-executed until the output verification passes.

[0042] After the unit executes the output command, the intelligent data center collects the real-time optimization effect, such as actual coal consumption and emission data, and updates the relationship data in reverse: if a certain variable, such as air volume, contributes more significantly to the target optimization, its search priority is increased, such as from the second level to the first level; based on multiple regression analysis, the influence weight of variables on the target is recalculated, such as adjusting the coal feed rate influence factor from 0.6 to 0.55, and the air volume from 0.3 to 0.35; The complex algorithms of the intelligent application server are responsible for innovative optimization that breaks through experience, while the verification mechanism of the intelligent data center is responsible for upholding the bottom line of security through verification. By comparing the innovative intelligent output with conservative historical experience through historical mirroring of time-series data and rule constraints of relational data, the system ensures the implementation of innovative optimization while avoiding unknown risks. The dynamic adjustment of relational data allows the entire system to continuously adapt to the dynamic changes of the unit, such as equipment aging and coal quality fluctuations, ultimately achieving intelligent but not blind action and closed-loop control with evidence-based optimization. The intelligent controller of the intelligent control system focuses on real-time control, achieving millisecond-level response, while the intelligent application server is responsible for real-time optimization, achieving second-level updates. The two achieve data closed loop through the automated intelligent data center. The intelligent server trains models based on historical and real-time data to generate optimization strategies, and the controller executes precise adjustments according to the strategies, forming an intelligent control link of "perception-decision-execution".

[0043] The video linkage system employs multiple high-definition network cameras and video servers, covering key areas such as boilers, steam turbines, and environmental protection equipment. The video servers support multi-disk storage. Redundant gigabit switches with a ring network architecture are connected to the operator stations of the distributed control system via independent fiber optic links. Encrypted video signal transmission is used. Through triple protection of multi-disk storage redundancy, switch ring network redundancy, and fiber optic link redundancy, video data is ensured to be undamaged and transmission uninterrupted. Independent networks, firewalls, and encryption mechanisms isolate the control layer and the video layer, preventing network storms or attacks from affecting the security of the control system.

[0044] The video linkage system deploys multiple high-definition network cameras, accurately covering key areas such as the boiler furnace flame monitoring area, critical measuring points in the turbine shaft system, and environmental desulfurization and denitrification equipment. The video server uses a multi-bay storage server, supporting redundant array configurations such as RAID5, allowing a single server to connect to multiple camera video streams. Taking an 8-bay server as an example, it is configured with eight large-capacity enterprise-grade hard drives, utilizing RAID5 technology to ensure no data loss in the event of a single disk failure. Through distributed storage algorithms, video data is fragmented and stored on different hard drives, balancing read / write speeds with data redundancy, meeting continuous video storage requirements, and preserving complete data for accident tracing and equipment status analysis.

[0045] A ring network architecture is constructed so that when one switch experiences a port failure, link interruption, or other anomaly, the ring network automatically switches over with a switching time controlled within milliseconds, ensuring uninterrupted video stream transmission. Single-mode fiber is used as the transmission medium to establish an independent channel from the video server to the operator stations of the distributed control system. Fiber optic cables possess low attenuation, anti-interference characteristics, and long transmission distances, meeting the cross-regional transmission needs of the power plant and providing a stable, high-speed physical transmission link for video data, ensuring smooth, real-time video stream transmission.

[0046] Firewalls are deployed at the network boundary between the video and control layers, opening only specific ports required for video calls, such as RTSP video stream transmission ports, and rejecting illegal protocols and malicious access. Attacks such as network scanning and port brute-force will be blocked and alerted by the firewall, achieving logical isolation between the video and control layers and protecting the security of the control system.

[0047] The camera captures real-time video footage of key areas, which is then encoded and compressed using efficient encoding standards such as H.265 to reduce bandwidth consumption while ensuring image quality. This compressed footage is then transmitted to the video linkage server via the E2 video network. The video server receives multiple video streams and, according to a preset storage strategy, categorizes them by time, region, and device, writing the video data to the RAID array hard drives. It also supports fast retrieval by timestamp, device number, and other indexes for easy access to historical video later. The video server performs intelligent analysis of the footage, such as identifying valve open / closed states, generating structured data like "#1 Valve Fully Open," which is stored synchronously with the video stream.

[0048] When the operator station of the distributed control system triggers a video linkage request, such as automatically popping up a video link when an equipment alarms or manually retrieving footage from a specific area, the operator station sends a video call command or camera control command to the video linkage server via the video layer E1 network, such as "call camera #3" or "zoom to 10x". The commands are encrypted using SM4 before being sent. The redundant gigabit switches, based on a ring network architecture, quickly forward commands and video streams. Upon response, the video server encrypts the real-time or historical video from the corresponding camera using encryption algorithms such as AES to prevent interception and tampering during transmission, and then sends it back to the operator station for display. This achieves the linkage effect of "data alarm triggering video pop-ups and synchronous monitoring of process parameters and video footage," assisting operators in intuitively judging abnormal equipment conditions.

[0049] The video linkage system is based on high-definition acquisition, redundant transmission, and secure isolation. Through hardware redundancy configuration and intelligent linkage logic, it realizes visual monitoring of key areas.

[0050] Each device node, including the distributed control system operator station, intelligent controller, intelligent data center server, intelligent application server, and video linkage server, embeds a physical root of trust chip certified by national cryptographic algorithms and a trusted cryptographic module, supporting built-in or external deployment. As the starting point of the entire trust chain, the trusted cryptographic module integrates SM4 encryption / decryption, SM2 signature / verification, and SM3 hash operation functions, deeply collaborating with the node CPU to provide cryptographic support for end-to-end trust measurement.

[0051] Upon system startup, the hardware root of trust within the trusted cryptographic module chip is used as the initial trusted anchor point. The trusted cryptographic module then measures the integrity of the Basic Input / Output System (BIOS), calculus, and other components, calculating a hash value using SM3 and comparing it to a preset baseline value. Upon successful verification, the complete BIOS program is loaded. Simultaneously, the trusted cryptographic module performs static measurements on the BIOS code and configuration parameters, such as BIOSConfig, to ensure the BIOS has not been tampered with and to guarantee the trustworthiness of the hardware initialization process.

[0052] After the basic input / output system boots, the boot sector and OSLoader are measured sequentially. The trusted cryptography module continuously participates, calculating hashes on the GRUB program and configuration files. Upon successful verification, the operating system kernel and initial memory disk are loaded. Throughout this process, the chain of trust extends from the hardware layer to the system boot layer, ensuring a trustworthy operating system boot environment.

[0053] After the operating system loads, the built-in trusted security kernel module takes over, dynamically measuring critical system processes and files. Simultaneously, the trusted cryptography module continues to perform integrity verification on upper-layer applications, including control logic configuration software and video linkage system clients. Ultimately, the trusted chain extends to network communication, ensuring the trustworthiness of terminal nodes before data transmission.

[0054] The trusted management platform server acts as the central control hub, connecting all trusted nodes in the distributed control system, intelligent control system, intelligent data center, and video linkage system. It possesses five core capabilities: Status monitoring: Real-time collection of the status, measurement results, and process operation of trusted cryptographic module chips at each node, and display of node trustworthiness and health through a visual interface, such as presenting the benchmark value comparison pass rate and abnormal event occurrence rate of each node in the form of a dashboard.

[0055] Policy Configuration: Generates node trusted policy configuration files, including key file hash base values, process whitelists, access control rules, etc. Supports customized policies by system partition, such as control layer, video layer, device type, server, and operator station, precisely adapting to the security needs of different nodes.

[0056] Alarm Reporting: Receives abnormal events uploaded by each node and handles them according to their severity. Level I anomalies, such as tampering with control logic configuration files triggering audible and visual alarms, automatically lock related control loops to prevent malicious command execution; Level II anomalies, such as changes to non-critical log files, record detailed logs for auditing and traceability.

[0057] Two-way authentication: During communication between nodes and interaction between nodes and the platform, two-way authentication is implemented based on the SM2 algorithm. For example, before the intelligent controller communicates with the intelligent data center server, both parties exchange signature certificates through a trusted cryptographic module to verify the legitimacy of their identities and prevent counterfeit nodes from accessing the system.

[0058] Log auditing: Completely records logs of node measurement processes, policy changes, and anomaly handling. Log data is stored in a trusted database using SM4 encryption. Supports retrieval by time, event type, node name, and other dimensions, meeting the requirements for compliance with information security standards and incident tracing.

[0059] The trusted management platform collects initial baseline values ​​for all nodes. For critical files, such as control logic configuration files of distributed control systems, algorithm model files of intelligent application servers, and operating system kernel images, the platform uses the trusted cryptography module to call the SM3 algorithm to calculate hash values ​​and encrypts and stores them in a trusted database. Taking control logic configuration files as an example, the platform records the file path, version number, and hash value as the benchmark for subsequent measurements. For similar devices such as operator stations and intelligent controllers, the platform automatically compares the hash values ​​of critical files with the same function during the baseline value collection phase. For example, for control logic configuration files of multiple configuration servers, after SM3 calculation, the platform verifies whether the hash values ​​are consistent. If differences exist, a configuration verification process is triggered to investigate whether the discrepancies are due to inconsistent file versions or differences in deployment scripts, ensuring that the baseline values ​​of critical files for similar devices are of the same source and quality, thus guaranteeing the consistency and trustworthiness of core elements such as system control logic and algorithm models from the source.

[0060] During operation, each node performs periodic or real-time hash calculations on critical files according to a trusted policy, comparing the results with a baseline value stored in the local trusted cryptographic module. If a discrepancy is found, an anomaly event is generated, containing information such as the filename, current hash value, timestamp, and node IP address. The anomaly event is then signed with SM2 by the trusted cryptographic module to ensure its authenticity and integrity before being uploaded to the management platform. The platform handles these threats according to pre-defined rules, enabling rapid response to security threats.

[0061] When the system is upgraded, such as through intelligent control algorithm iteration or operating system patch updates, the administrator initiates a baseline value update request through the trusted management platform. The process follows the principle of "separation of powers": the administrator submits the update request, explaining the upgrade content and related documents → the auditor reviews the request, verifying the integrity and legality of the upgrade package and checking the compliance of the approval process → the operator executes the request, receiving the encrypted new baseline value, distributing it to the trusted cryptographic modules at each node, replacing the old baseline value, and archiving it. This ensures that the baseline value update process is traceable and auditable, preventing unauthorized tampering.

[0062] Operator and engineer workstations are embedded with trusted cryptographic module chips to provide full lifecycle trusted management of control logic configuration files, such as PID control loops and interlocking protection logic generated through graphical configuration software. A whitelist of processes running the trusted security kernel module ensures that only certified configuration software and control command issuing programs are allowed to run, preventing malicious processes from injecting and tampering with the control logic. When an engineer workstation modifies the control strategy, the hash value of the new configuration file is automatically reported to the management platform. After approval, the baseline value is updated, ensuring that changes to the control logic are trusted and controllable.

[0063] The intelligent controller and intelligent application server utilize a trusted cryptographic module to achieve trust measurement from startup to algorithm execution. Before the intelligent application server runs complex intelligent algorithms, the trusted cryptographic module performs hash verification on algorithm model files, such as LSTM neural network parameters and multivariate coupling models, to ensure that the models have not been tampered with. During algorithm execution, the trusted security kernel monitors the process status to prevent forced termination of processes, ensuring the continuous and stable operation of complex algorithms such as deep peak shaving optimization. When the intelligent controller executes control commands, it performs two-way authentication between the command source and the intelligent application server to prevent the execution of false commands.

[0064] The data center server uses a trusted cryptographic module to ensure the trustworthiness of critical files in time-series and relational databases. Real-time operational data and historical archived data are stored using SM4 encryption, combined with hash metrics from the trusted cryptographic module, to prevent unauthorized tampering or deletion. When the intelligent data center interacts with other systems, such as sending optimization parameters to the intelligent controller, two-way authentication and encrypted transmission ensure the data is secure and trustworthy in the network link, providing reliable data support for the intelligent control closed loop.

[0065] The video linkage server and camera access terminals embed trusted cryptographic modules to encrypt video stream transmission using the SM4 algorithm, preventing image capture and tampering. Historical video files stored on the video server are hashed using the trusted cryptographic module to ensure video data integrity and provide reliable evidence for incident tracing. Simultaneously, the trusted security kernel restricts the permissions of the video linkage system processes, allowing communication only with legitimate devices such as operator stations and firewalls, preventing the video layer from becoming an attack entry point and safeguarding the security of the control system network boundary.

[0066] By constructing a trusted system based on "hardware trusted root, full-link trusted chain transmission, and centralized management platform control", it covers all equipment nodes and business processes of industrial control systems, and achieves full-dimensional trusted protection from startup loading to application operation, and from data storage to network interaction.

[0067] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0068] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for implementing a secure and reliable intelligent distributed control system, characterized in that, The method includes the following steps: Expand the existing DCS control layer redundant network, add an independent intelligent control layer redundant network and video layer network, and establish a multi-layer network structure. In the intelligent control layer, intelligent controllers and intelligent application servers use intelligent algorithms, combined with an automated intelligent data center, to collect data, issue commands, and store data. The DCS operator station uses embedded video linkage technology to access video information from the video server. Trustworthy deployment is carried out on each node of the DCS control layer, intelligent control layer, and video layer.

2. The method for implementing a secure and reliable intelligent distributed control system according to claim 1, characterized in that, The expansion of the existing DCS control layer redundant network, the addition of an independent intelligent control layer redundant network and a video layer network, and the establishment of a multi-layer network structure also include: The DCS control layer, intelligent control layer, and video layer are physically isolated from each other in the network. The DCS control layer and the intelligent control layer are connected via redundant industrial Ethernet, and different functional areas are isolated by secure partitioning. The intelligent control layer is connected to the server via high-speed Ethernet, supporting data fragmentation transmission and breakpoint resumption. The video layer is networked independently and isolated from the control layer by a firewall, with only the video access port open.

3. The method for implementing a secure and reliable intelligent distributed control system according to claim 2, characterized in that, In the intelligent control layer, the intelligent controller and intelligent application server employ intelligent algorithms, and the specific implementation process of data acquisition, instruction issuance, and data storage in conjunction with the automated intelligent data center includes: The intelligent control layer includes intelligent controllers, intelligent data centers, and intelligent application servers; The intelligent controller adopts a multi-core parallel computing architecture, runs basic control algorithms and lightweight intelligent algorithms in the algorithm module, and encapsulates the algorithm module through an algorithm container to dynamically adjust parameters; The intelligent application server deploys deep peak shaving optimization and coordination control algorithms, generates control commands based on big data training models, and sends them to the intelligent controller after being encrypted by the national cryptographic symmetric encryption algorithm. The automated intelligent data center stores real-time data through a time-series database and distributes data on demand using a publish-subscribe model to support real-time computing for intelligent applications. The automated intelligent data center includes a sentinel server and an intelligent data center.

4. The method for implementing a secure and reliable intelligent distributed control system according to claim 3, characterized in that, The data processing flow of the intelligent control layer includes: Real-time status data is acquired from field devices by conventional controllers and uploaded to intelligent controllers and intelligent data centers, triggering data transmission commands for distributed control historical stations; When the distributed control historical station receives the data transmission instruction, it transmits the stored historical status data to the intelligent data center; The intelligent controller performs intelligent logic calculations based on real-time status data, and issues control commands to conventional controllers according to the calculation results to regulate the field equipment; at the same time, the calculation results and calculation parameters are transmitted to the intelligent data center. The intelligent data center cleans and monitors the received data, and then interacts bidirectionally with the intelligent application server; based on the interaction results, it optimizes the control strategy and sends control commands or parameter optimization data to the conventional controller. The interaction result optimization control strategy includes: when the output adjustment object of the interaction result does not overlap with the calculation result of the intelligent controller, outputting the overlapping part and adjusting the parameters of the intelligent controller algorithm; and monitoring the data cleaning process and status of the intelligent data center through the sentinel server. The bidirectional interaction with the intelligent application server includes: the intelligent data center providing data acquisition services to the intelligent application server, and the intelligent application server performing in-depth analysis and processing of the data through intelligent algorithms, outputting algorithm results and feeding them back to the intelligent data center.

5. The method for implementing a secure and reliable intelligent distributed control system according to claim 4, characterized in that, The intelligent data center cleans and monitors the received data, and then engages in bidirectional interaction with the intelligent application server, including: Based on the received data, the search path and influencing factors of the relational data are obtained, historical working conditions are matched in the time series database, and the current output is verified to optimize the target variable; wherein, the influencing factor represents the weight used to quantify the influence of each variable on the target. Based on the priority of the search path, retrieve the operating condition range of the current output historical status data that meets the standard from the time series database; Extract the target variable for the operating condition interval and compare it with the predicted value corresponding to the current output. If the target variable for the operating condition interval is better than the current operating condition, the output verification is valid; if the target variable for the operating condition interval is not optimized, the output verification is invalid. When the verification is valid, the intelligent data center outputs control commands / parameters to the intelligent controller, driving the unit to execute the output commands; when the verification is invalid, an iterative mechanism is triggered, and intelligent calculations are re-executed by adjusting the range of output variables, optimizing algorithm parameters, and switching algorithm models until the output verification passes. After the unit executes the output command, the intelligent data center collects the real-time optimization effect and updates the relational data in reverse: if a certain variable contributes more significantly to the optimization of the target, the priority of the search path is upgraded; based on multiple regression analysis, the influence weight of the variable on the target is recalculated.

6. The method for implementing a secure and reliable intelligent distributed control system according to claim 1, characterized in that, The specific implementation process for the trusted deployment of each node in the DCS control layer, intelligent control layer, and video layer includes: When each node starts up, based on the root of trust, it performs step-by-step measurements starting from the boot firmware to verify the static and dynamic integrity of the hardware, firmware, operating system and application system, and build a trusted chain of trust. The trusted management platform monitors the running status of each node in real time and senses the trusted status of key files. If the status is abnormal, an alarm is triggered. The key files include control algorithms and configuration parameters. Log data recording node measurement processes, policy changes, and abnormal event handling is encrypted and stored in a trusted database using the national cryptographic symmetric encryption algorithm.

7. The method for implementing a secure and reliable intelligent distributed control system according to claim 6, characterized in that, The specific management process of the trusted management platform includes: Initial baseline values ​​are collected for all nodes. For critical files, the hash value is calculated by calling the national cryptographic hash algorithm through the trusted cryptographic module and then encrypted and stored in the trusted database. When each node is running, it performs periodic or real-time hash calculations on key files according to the trusted policy and compares them with the baseline value stored in the local trusted cryptographic module. If a discrepancy occurs, an abnormal event is generated, which includes the file name, the current hash value, the timestamp, and the node IP. After an abnormal event is signed by the trusted cryptography module using the national cryptographic asymmetric encryption algorithm, it is uploaded to the trusted management platform; the trusted management platform handles the event in a tiered manner according to preset rules and responds to security threats.

Citation Information

Patent Citations

  • Deep peak regulation control system for thermal power generating unit

    CN120560018A

  • Full-link detection and trusted industrial control method and system based on domestic chip

    CN120658448A

  • Intelligent factory equipment safety management system and method

    CN120710709A

  • Automatic fire extinguishing system of wisdom power plant

    CN208654630U

  • Blockchain-based authentication system and method for authenticating electric vehicles or drones in a smart city

    US20250233743A1