Method and system for determining device update sequences
By interacting with the SCADA system and the FLM system, the device update sequence is determined, which solves the problems of untimed firmware updates and human error in the existing technology, and realizes a safe and efficient automated update process.
Patent Information
- Application Number
- CN202480046723.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-07-13
- Filing Date
- 2024-07-13
- Publication Date
- 2026-02-13
AI Technical Summary
In existing automated control systems, firmware updates require stopping site functions and rely on human experts, which carries the risk of errors and fails to effectively consider the criticality and operational status of the equipment, resulting in untimely updates that compromise system security.
By interacting with the SCADA system and the FLM system, the equipment update sequence is determined, the criticality and operating status of the equipment are considered, an update schedule is generated, and control actions are coordinated to ensure that the update process does not affect system safety.
It enables automated firmware updates without compromising system security, reducing the risk of update errors caused by human error and inappropriate timing, and improving operational safety.
Smart Images

Figure CN121532748A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the invention relate to systems and methods associated with updates of machine-readable data processed by devices communicatively coupled to supervisory control and data acquisition (SCADA) systems. Embodiments of the invention relate, in particular, to methods and systems that can be used to determine a schedule for updates of machine-readable data, such as firmware, of devices. Embodiments of the invention also relate to techniques that perform control actions related to infrastructure systems, such as power systems. BACKGROUND
[0002] Systems that include devices and supervisory control and data acquisition (SCADA) systems for monitoring and coordinating the devices are widely used. Such devices and SCADA systems can be implemented in an automation control system, such as an automation control system for industrial automation, power system automation (e.g., substation automation systems), or other infrastructure automation systems. Automation control systems have been widely used. Automation control systems provide improved control and operation of infrastructure systems, such as power systems, or industrial systems. Given the capabilities provided by automation control systems and their devices, it is expected that the use of automation control systems will further increase.
[0003] Each device can be associated with a component of an electrical power system to perform one or more functions, such as one or more protection functions. The devices can be communicatively coupled to each other and to the SCADA system.
[0004] The devices can also be coupled to a fleet management (FLM) system. The FLM system can be operable to maintain and monitor operational characteristics of the devices, such as processor load, memory or storage usage, firmware version data, or other data related to the manner in which the individual devices perform their intended functions.
[0005] After the devices coupled to the SCADA system have been configured and commissioned for field use and are operating in field use, it can be necessary to update the machine-readable data processed by the devices. For example, it can be necessary to implement updates to machine-readable instruction code that can be processed by the devices to perform control, protection, and / or communication functions after the devices begin operating in field use. The FLM system can also be operable to initiate an update process to perform firmware or software updates to the machine-readable code executed by the devices.
[0006] Updating machine-readable data of a fleet of devices is an important function that can become even more important in the future. Updating procedures can be needed to ensure that the latest security patches, features, and / or performance improvements are deployed to devices in a timely and efficient manner. Accelerated digitalization processes in the power system industry or other critical infrastructures and cyber-security challenges increase the need to support frequent firmware updates of power system devices.
[0007] Traditionally, firmware updates in power systems or other critical infrastructures or industrial systems require stopping site functionality and distributing and installing new firmware on devices under control of human experts.
[0008] US 8 892 699 B2 discloses a method of automatically updating an existing firmware file stored in a memory of an intelligent electronic device (IED) coupled in network communication with a monitoring system, wherein the update is performed in response to the IED verifying that a first criterion, such as that the update interoperates with the existing firmware file, is satisfied.
[0009] EP 3 631 745 A1 discloses software update techniques intended to be performed by equipment of a power distribution network.
[0010] There is a need for further improvements of automatically performing updates for various reasons. For example, it is desirable to perform such updates in a way that enables performing the updates based on objective criteria, in a way that reduces or eliminates errors caused by human experts, or in a way that further enhances digitalization and further reduces cyber-security risks.
[0011] One approach to further improve firmware update installation is to use FLM systems. However, using FLM systems to trigger updates of machine-readable code can have drawbacks when implemented in a native way. For example, such implementations of the update procedure can sometimes fail to sufficiently reduce the risk that a device to be updated is prevented from performing its regular and intended functions, or is hindered from performing its regular and intended functions, due to the installation of the update, while the device is not available for its intended functions at that time is not appropriate. Native use of FLM systems can also fail to take into account the overall functional state of multiple devices, which can include redundant functional implementations.
[0012] Therefore, there is still a need for techniques associated with updating machine-readable data in devices coupled with SCADA systems, such as installing software or firmware updates. SUMMARY
[0013] The object of this invention is to provide systems and methods that provide enhanced techniques for determining update sequences for devices coupled to a Supervisory Control and Data Acquisition (SCADA) system. An optional object of this invention is to provide methods and systems that mitigate the risk of updates being performed incorrectly or incompletely due to inappropriate timing of update installations. An optional object of this invention is to provide methods and systems that mitigate the risk of incorrect or incomplete update installations due to errors caused by human scheduling.
[0014] According to exemplary embodiments, the method and system described in the claims are provided.
[0015] According to one aspect of the invention, a method is provided for determining an update sequence for updating machine-readable data processed by devices interfaced with a Supervisory and Data Acquisition (SCADA) system. The method includes: receiving data from a Cluster Management (FLM) system by the SCADA system, the received data defining a set of devices including devices to be updated; determining an update sequence for the devices included in the device set by the SCADA system; and generating and providing an output defining the update sequence for the devices to be updated by the SCADA system.
[0016] This method offers several advantages and benefits. Through an interface communicating with the FLM system, the SCADA system and the FLM system can interact to determine the update sequence for installation updates. Based on the interaction between the FLM and SCADA systems, the SCADA system can determine the update sequence for multiple devices in a device set, taking into account the criticality and / or operational status information of the devices and / or primary systems during firmware updates. This is achieved while maintaining the FLM and SCADA systems as independent systems, which is beneficial for operational safety.
[0017] The data received from the FLM system may also include duration data, which defines the expected update duration for at least some of the devices to be updated.
[0018] This allows the SCADA system to consider the expected update duration when determining which devices will enter maintenance mode without affecting system safety and / or what changes need to be made to the primary system associated with the devices (e.g., by controlling one or more of the following: switchgear, transformer, tap changer, energy storage system (ESS), distributed energy system (DER), inverter setpoint).
[0019] SCADA systems can determine update sequences based on the expected update duration.
[0020] This allows SCADA systems to consider the expected update duration when determining which devices will enter maintenance mode without affecting system safety and / or what changes need to be made to the system at one time.
[0021] SCADA systems can determine update sequences based on the criticality of devices defined by the received data, for use in the operation of automated control systems.
[0022] This improves operational safety.
[0023] SCADA systems can determine update sequences based on the presence of redundant functions implemented by devices defined by the device set and / or device status and / or primary system status (such as current or power flow, switch status, generator or inverter setpoint, etc.).
[0024] Therefore, SCADA systems that interface with FLM systems can consider the criticality and / or operational status of the devices to be updated, thus improving operational safety.
[0025] The SCADA system can determine the update sequence, such that the first subset of the device set to be updated includes devices whose device states are different from the fully operational state, as well as devices with redundant functions implemented by the devices.
[0026] Therefore, devices that can be placed in maintenance mode to install updates without affecting system security can be identified and updated.
[0027] The method may also include a sequence of control actions determined by the SCADA system to be executed in a manner coordinated with the update sequence.
[0028] Therefore, the SCADA system can control the equipment in a manner coordinated with the FLM system's triggered update process.
[0029] The sequence of control actions may include commands that put at least one device into maintenance mode.
[0030] Therefore, the SCADA system can control the equipment in a manner coordinated with the FLM system's triggered update process.
[0031] The sequence of control actions may include commands that change the state of primary system components, such as power system components, like switchgear, transformers, and / or other primary system components.
[0032] Therefore, a system may be affected in a way that allows SCADA system-controlled devices to be securely updated.
[0033] The method may also include a sequence of control actions executed by the SCADA system to allow the device to be updated.
[0034] Therefore, primary systems (e.g., power systems) and / or secondary systems, including equipment, can be coordinated and controlled by the SCADA system and the FLM system so that updates can be installed without adversely affecting operational safety.
[0035] The sequence of control actions may include control actions that change the state of primary system equipment in the power system, wherein the equipment is the equipment of an automated control system associated with the primary system equipment.
[0036] Therefore, a system may be affected in a way that allows SCADA system-controlled devices to be securely updated.
[0037] The data received from the FLM system may include the identifiers of all devices to be updated.
[0038] Therefore, the SCADA system can be notified of the set of devices for which an update is required. This set can include all devices for which a newer firmware version is available based on firmware data maintained by the FLM system.
[0039] The output can define an ordered list of multiple subsets of the device set to define the update sequence.
[0040] Therefore, update sequences can be efficiently specified for use by the FLM system.
[0041] The output may include multiple messages provided by the SCADA system to the FLM system, where each message defines a subset.
[0042] Therefore, the SCADA system efficiently notifies the FLM system of the subset of devices that need to be updated during the update cycle.
[0043] The method may also include the SCADA system receiving update reports from the FLM system.
[0044] This allows the SCADA system to stay informed about update progress, especially updates that have been successfully completed, resulting in some devices running with different firmware.
[0045] These devices can include equipment used in automated control systems.
[0046] Therefore, the effects obtained by determining the update sequence have been utilized in the field of automated control systems, where it is particularly important that the update process does not compromise operational safety.
[0047] Automation control systems may include power system automation control systems. These devices may include equipment used in power system automation control systems.
[0048] Therefore, updates to equipment in power system automation control systems can be automatically controlled, and firmware updates or other updates are particularly important for these devices.
[0049] Updates can include firmware updates.
[0050] Therefore, the techniques disclosed in this article can be used to install firmware updates.
[0051] The method may also include the transmission of machine-readable data updates to multiple devices by an FLM system or distribution server according to a determined update sequence. The machine-readable data may be transmitted to each of the multiple devices at a time determined according to the determined update sequence.
[0052] Therefore, update transmission to multiple devices can be achieved based on the update sequence automatically determined by the collaboration between the SCADA system and the FLM system.
[0053] The method may also include the FLM system triggering the installation of updates on multiple devices according to a determined update sequence.
[0054] Therefore, updates for multiple devices can be installed based on an update sequence automatically determined by the collaboration between the SCADA system and the FLM system.
[0055] The method may further include: processing the transmitted updates by each of a plurality of devices at a time determined according to the determined update sequence.
[0056] Thus, the update was installed according to the update sequence.
[0057] Determining the update sequence can include determining the schedule for update distribution and the schedule for update installation.
[0058] Therefore, the transmission and installation of machine-readable data updates can be based on and performed according to a schedule determined by the collaboration between the SCADA system and the FLM system.
[0059] Updates may include executable instruction code or updates to executable instruction code. Executable instruction code can be software or firmware persistently stored in the device being updated. Different types of devices may store different types of executable instruction code. The techniques disclosed herein are applicable accordingly to each of these different types of executable instruction code. That is, not all devices need to receive the same updates.
[0060] Therefore, firmware or software updates for a device can be performed collaboratively, optionally taking into account the past, present, and / or predicted future states of a primary system associated with the device.
[0061] The method may also include updating software or firmware performed by the device based on an update.
[0062] Therefore, these technologies can be used to modify device operation by performing software or firmware updates.
[0063] Updating software or firmware may include updating at least one protection function logic associated with a primary system (e.g., a power system). This protection function logic may include, but is not limited to, distance protection or time-domain protection.
[0064] Therefore, these technologies can be used to modify the decision logic executed by the device to perform protection functions related to the primary system.
[0065] Transmitting an update may include transmitting the update via a packet communication link or a communication network. Alternatively or additionally, transmitting an update may include transmitting the update via a communication link in accordance with IEC 61850.
[0066] Therefore, updates can be transmitted to the equipment using communication links or other communication infrastructure for communication within or between substations according to IEC 61850.
[0067] The equipment may include protective relays or other intelligent electronic devices (IEDs) that perform protective or other functions on infrastructure systems, particularly power systems.
[0068] Therefore, the upgrading of such protective equipment, which is particularly critical to ensuring the safe operation of the power system, can be carried out in a manner that mitigates the risk of upgrading at an inappropriate time considering the safety of the power system.
[0069] Multiple devices may include distance protection devices and / or time domain protection devices.
[0070] Therefore, the upgrading of such protective equipment, which is particularly critical to ensuring the safe operation of the power system, can be carried out in a manner that mitigates the risk of performing the upgrade at an inappropriate time considering the safety of the power system.
[0071] According to another aspect, a method is provided for controlling the operation of an automated control system comprising multiple devices. The method includes having the devices of the automated control system execute instruction codes to perform functions related to an infrastructure system (e.g., a power system), and performing a method for determining an update sequence based on any aspect or embodiment of updating the devices of the automated control system during field use.
[0072] This reduces the risk of unintended disruptions to the safe operation of infrastructure systems during the update process of automated control systems, thereby improving the operational safety of infrastructure systems.
[0073] According to another aspect, a method for controlling an infrastructure system is provided. The method includes controlling the equipment of the infrastructure system by devices of an automated control system, and performing a method for determining an update sequence based on any aspect or embodiment of the devices used to update the automated control system during field use.
[0074] This reduces the risk of unintended disruptions to the safe operation of infrastructure systems during the update process of automated control systems, thereby improving the operational safety of infrastructure systems.
[0075] Infrastructure systems can include power systems.
[0076] This reduces the risk of unintended disruptions to the safe operation of the power system during the update process of the automated control system, thereby improving the operational safety of the power system.
[0077] A power system may include one or more of a power generation system, a transmission system, and a distribution system. A power system may include renewable energy sources coupled to at least some buses of the power grid.
[0078] This improves the operational safety of the power system.
[0079] According to another aspect of the invention, an instruction code is provided that, when executed by at least one processing circuit, causes the execution of a method according to any aspect or embodiment.
[0080] The resulting effect corresponds to the effects and advantages disclosed in connection with the method.
[0081] According to another aspect of the invention, a non-transient storage medium is provided, on which instructions are stored, which, when executed by at least one processing circuit, cause the execution of a method according to one aspect or embodiment.
[0082] The resulting effect corresponds to the effects and advantages disclosed in connection with the method.
[0083] According to another aspect of the invention, a Supervisory Control and Data Acquisition (SCADA) system is provided for determining an update sequence of machine-readable data processed by a device that communicatively interfaces with the SCADA system. The SCADA system includes at least one SCADA data interface operable to receive data from a Cluster Management (FLM) system, the received data defining a set of devices including the devices to be updated. The SCADA system includes at least one SCADA processing circuitry operable to determine an update sequence of devices included in the device set, generate an output defining the update sequence, and control the at least one SCADA data interface to provide the output to the FLM system.
[0084] SCADA systems offer numerous benefits and advantages. Through an interface communicating with the FLM system, the SCADA and FLM systems can interact to determine the update sequence for installation updates. Based on the interaction between the FLM and SCADA systems, the SCADA system can determine the update sequence for multiple devices in a device set during firmware updates, taking into account the criticality and / or operational status information of the devices. This is achieved while maintaining the FLM and SCADA systems as independent systems, which is beneficial for operational safety.
[0085] The SCADA system is operable to perform the methods of any aspect or embodiment disclosed herein. Therefore, optional features of the SCADA system correspond to optional features of the methods disclosed herein, wherein processing operations are performed by or using at least one SCADA processing circuitry of the SCADA system.
[0086] According to another aspect of the invention, an electric power system is provided. The electric power system includes an automated control system comprising a plurality of devices operable to process machine-readable data. The electric power system includes a Supervisory Control and Data Acquisition (SCADA) system according to one aspect or embodiment, the SCADA system being operable to be communicatively coupled to the plurality of devices. The electric power system includes an FLM system operable to be communicatively coupled to the SCADA system and the plurality of devices.
[0087] Therefore, the system obtains the advantages and effects disclosed in connection with SCADA systems and methods according to various embodiments.
[0088] The FLM system is operable to generate first data including information about the devices to be updated included in the device set, send the first data to the SCADA system, receive second data including output from the SCADA system, the second data including information about multiple subsets of the device set, and establish an update sequence based on the second data.
[0089] Therefore, the FLM system can specify the devices to be updated. The set of devices specified by the first data can consist of devices to be updated. The FLM system can use information provided by the SCADA system to trigger the update process, which takes into account the criticality and / or operational status of the devices. Therefore, the update process can be implemented under the control of the FLM system, but must take into account data such as the criticality and / or operational status of devices that are available to the SCADA system but not to the FLM system (unless the FLM system interfaces with the SCADA system).
[0090] The SCADA system is operable to receive first data, retrieve at least the device status data of the device to be updated based on the information about the device to be updated included in the first data, determine several subsets of the device set based on the device status data to specify an update sequence, generate second data including output based on the determined subsets, and send the second data to the FLM system.
[0091] Therefore, the FLM system can efficiently determine the start time of triggering the update process. When the receipt of a message triggers an update process for the device specified by one of the messages, timing information may, but is not always, required to be included in the second data.
[0092] The FLM system is operable to retrieve device status data of devices contained in the device set from the storage system of the SCADA system or a storage system accessible to the SCADA system.
[0093] Therefore, the FLM system can retrieve data from the SCADA storage system that defines the criticality and / or operational status of the device to be updated. The FLM system can explicitly consider the criticality and / or operational status of the device when determining the update sequence.
[0094] The FLM system can be operated to establish an update sequence based on retrieved device status data.
[0095] Therefore, the FLM system can retrieve data from the SCADA storage system that defines the criticality and / or operational status of the device to be updated.
[0096] The FLM system is operable to interface with the SCADA system to perform the following operations: generating first data by the FLM system, the first data including information about a device to be updated, which is included in a device set; outputting the first data by the FLM system via at least one data interface; receiving second data by the FLM system from the SCADA system via at least one data interface, the second data including output from the SCADA system including information about at least one subset of the device set; and establishing an update sequence by the FLM system based on the second data.
[0097] Therefore, the FLM system can specify which devices in the system need to be updated. The set of devices specified by the first data can consist of devices to be updated. The FLM system can use information provided by the SCADA system to trigger the update process, which takes into account the criticality and / or operational status of the devices. Therefore, the update process can be implemented under the control of the FLM system, but data such as the criticality and / or operational status of devices available to the SCADA system but not to the FLM system must be considered.
[0098] The first data may include the identifiers of all devices to be updated.
[0099] Therefore, the FLM system can specify the set of devices to be updated. This set of devices can include all devices for which updated firmware versions are available based on firmware data maintained by the FLM system.
[0100] The first piece of data may include the expected update duration.
[0101] This allows SCADA systems to consider the estimated update duration when determining whether and which devices can enter maintenance mode without compromising system safety. Therefore, FLM systems can force SCADA systems to consider the estimated update duration when determining the update sequence in which devices are to be updated.
[0102] An FLM system is operable to determine the expected update duration based on the data or metadata defining the update to be performed and historical update reports. The FLM system may include a storage system that stores historical update reports. The FLM system can access these historical update reports to determine the expected update duration and generate initial data.
[0103] Therefore, SCADA systems are able to take into account the expected update duration when determining the update sequence in which devices are updated.
[0104] The second set of data can define several subsets of the devices to be updated.
[0105] This allows for grouping updates, with one subset being updated after another.
[0106] The second set of data can define an ordered list of several subsets of devices to be updated, in order to define the update sequence.
[0107] Therefore, at least a portion of the update sequence can be specified efficiently.
[0108] The second data (i.e., the output provided by the SCADA system to the FLM system) may include multiple messages received from the SCADA system, where each message defines a subset.
[0109] Therefore, at least a portion of the update sequence can be specified efficiently.
[0110] The FLM system is operable such that receiving one of a plurality of messages may cause the FLM system to trigger an update process for a subset of the message definition.
[0111] Therefore, the FLM system can efficiently determine the start time of triggering the update process. When the receipt of a message triggers the update process of the device specified by one of the messages, timing information may, but is not always necessary, be included in the second data.
[0112] The FLM system is operable to perform the following operations to interface with the SCADA system and establish an update sequence: the FLM system retrieves device status data of devices included in the device set from the SCADA system's storage system or a storage system accessible to the SCADA system.
[0113] Therefore, the FLM system can retrieve data from the SCADA storage system defining the criticality and / or operational status of the devices to be updated. When determining the update sequence, the FLM system can explicitly consider the criticality and / or operational status of the devices and / or primary system equipment.
[0114] The FLM system can be operated to create an update sequence based on the retrieved data.
[0115] Therefore, the FLM system can use retrieved data that defines the criticality and / or operational status of the device and / or primary system to be updated to establish an update sequence and trigger the update process.
[0116] The SCADA system is operable such that determining the update sequence may include determining which devices are currently set to an invalid state. The SCADA system is also operable such that determining the update sequence may optionally include determining which devices will remain invalid for the expected update duration. Such devices may be included in a subset of the devices to trigger the update process.
[0117] Therefore, devices that are not currently critical to the operation of the security system can be updated. Devices that are critical to the operation of the system are prevented from being updated.
[0118] The SCADA system is operable such that determining the update sequence may include identifying devices with redundant implementations of all safety-critical functions performed by the individual devices. Such devices may be included in a subset of those that triggered the update process.
[0119] Therefore, devices with redundant implementations of all safety-critical functions can be updated without adversely affecting system security. Devices lacking redundant implementations of at least one safety-critical function can be prevented from being updated, thereby improving operational safety.
[0120] SCADA systems are operable such that determining update sequences may include identifying which devices are associated with primary system equipment of the power system that do not carry or carry little current or power flow.
[0121] Therefore, devices that can exit full operational status can be updated without affecting system security, thus avoiding adverse effects on the system.
[0122] The SCADA system is operable such that determining the update sequence may include identifying which devices are associated with primary system equipment of the power system that carry current or power flows that meet a threshold criterion (below the threshold).
[0123] Therefore, devices that can exit full operational status can be updated without affecting system security, thus avoiding adverse effects on the system.
[0124] The FLM system is operable to receive update reports from the device via at least one data interface.
[0125] Therefore, the FLM system can monitor and record the update progress.
[0126] The FLM system is operable to generate an aggregated update report from the received update reports and provide the aggregated update report to the SCADA system via at least one SCADA data interface.
[0127] This allows the FLM system to notify the SCADA system of update progress, especially updates that have been successfully completed and have resulted in some devices using different firmware operations.
[0128] The system may also include a communication system through which devices, an FLM system, and a SCADA system are communicatively coupled. The SCADA system is operable to determine update sequences based on bandwidth usage within the communication system, and optionally based on the bandwidth usage of each device.
[0129] Therefore, the update sequence can be determined in a way that avoids the risk of consuming communication benefits when they need to be used for other purposes.
[0130] The communication system may include a communication system operating in accordance with IEC 61850.
[0131] Therefore, in terms of communication implementation, high requirements are ensured for the automated control systems associated with critical infrastructure systems.
[0132] An automated control system can be operated as a primary system component of a control infrastructure system.
[0133] Therefore, the effects and advantages achieved by the techniques disclosed herein are used to provide enhanced control and operation of infrastructure systems.
[0134] The system may also include a source clock. The FLM system, SCADA system, and devices are operable such that updates are performed at a timing established with reference to the time provided by the source clock.
[0135] Therefore, consistency with the reference time was ensured, and at least one schedule was determined and implemented relative to that reference time.
[0136] Embodiments of the present invention achieve various effects and advantages. For example, the systems and methods according to the embodiments provide enhanced techniques for determining update sequences for devices communicatively coupled to a SCADA system. The interoperability of the FLM system and the SCADA system allows for automated update installation while considering the criticality and / or operational status of the devices when determining the update sequence. The methods and / or systems reduce the risk of erroneous or incomplete update execution due to incorrect timing. These methods and systems also reduce the risk of erroneous or incomplete update execution due to errors caused by human scheduling.
[0137] These systems and methods can be used in conjunction with the power grid or its subsystems, such as power system substations, but are not limited to this. Attached Figure Description
[0138] Embodiments of the invention will be described with reference to the accompanying drawings, wherein similar or identical reference numerals indicate elements having similar or identical configurations and / or functions.
[0139] Figure 1 It is a schematic diagram of a system that includes a cluster management system for controlling equipment updates, as well as a monitoring and data acquisition system.
[0140] Figure 2 This is a block diagram of a cluster management system.
[0141] Figure 3 This is a block diagram of a monitoring and data acquisition system.
[0142] Figure 4 It is a block diagram of the processing functions performed by the cluster management system and / or monitoring and data acquisition system.
[0143] Figure 5 It is a flowchart of a method.
[0144] Figure 6 It is a flowchart of a method.
[0145] Figure 7 It is a block diagram of an automated control system device.
[0146] Figure 8 It is a schematic representation of a set of devices and a subset of devices.
[0147] Figure 9 It is a system signaling diagram.
[0148] Figure 10 It's a flowchart.
[0149] Figure 11 This is a block diagram of another cluster management system.
[0150] Figure 12This is another signaling diagram of a system.
[0151] Figure 13 It's a flowchart.
[0152] Figure 14 It is a block diagram of the processes performed by the cluster management system and / or monitoring and data acquisition system.
[0153] Figure 15 It is a schematic diagram of a system that includes a processing system operable to determine one or more schedules.
[0154] Figure 16 It is a flowchart of a method. Detailed Implementation
[0155] Embodiments of the invention will be described with reference to the accompanying drawings. In the drawings, similar or identical reference numerals indicate elements having similar or identical configurations and / or functions.
[0156] The embodiments relate to methods and systems for updating devices that are communicatively coupled to a control and monitoring and data acquisition (SCADA) system.
[0157] While embodiments will be described in detail primarily in conjunction with automated control systems for power systems, the embodiments disclosed herein are not limited thereto. Embodiments are operable to control updates of devices in various systems, including devices coupled to a SCADA system.
[0158] While examples of machine-readable data updates being software or firmware updates for a device will be described in detail, these examples can also be applied to other types of data.
[0159] The methods and systems disclosed herein are used to control the updating of machine-readable code, particularly firmware updates, of devices communicatively coupled to a SCADA system. The update process is triggered by a cluster management (FLM) system separate from the SCADA system. The FLM system and the SCADA system are operable as a communicative interface to determine the order (optionally timing) of performing the update process on devices communicatively coupled to the SCADA system.
[0160] As used herein, the control update process includes at least controlling (e.g., triggering or otherwise scheduling) the installation time of the update. The control update process may also include controlling (e.g., triggering or otherwise scheduling) the transmission of update data to the device.
[0161] As used herein, the term SCADA system refers to a computing system operable to control the operation of equipment to coordinate, control, or otherwise support the functions possessed by the equipment, such as when operating primary equipment in an infrastructure system (such as a power system). A SCADA system is operable to receive and store records of the equipment states (such as invalid states, e.g., maintenance states and operating states) of multiple (preferably all) devices in an automated control system. A SCADA system is operable to transition equipment from a fully operating state to a maintenance state and vice versa.
[0162] As used herein, the term FLM system refers to a computing system operable to maintain data related to the firmware of devices currently deployed and communicatively coupled to a SCADA system. These devices are also typically communicatively coupled to the FLM system to allow the FLM system to record data related to, for example, the device's hardware usage, installed firmware, and (optionally) previous firmware updates. The FLM system is operable to trigger devices to perform update processes, particularly firmware updates. The FLM system can generate and issue commands to trigger update processes. The FLM system is also operable to control the distribution of update data to devices.
[0163] These devices can be devices of an automated control system. As used herein, an automated control system includes an automated control system that operates in a manner compatible with or in accordance with IEC 62443 (particularly the version of IEC 62443 effective as of the priority date or filing date of this application).
[0164] As used herein, the equipment of an automated control system may specifically include intelligent electronic devices (IEDs), such as IEDs operating in accordance with IEC 61850 (particularly the version of IEC 61850 effective at the priority or filing date of this application).
[0165] As used herein, terms such as “modification” or “alteration” of a device include modifications to the device by updating the software or firmware code executed by the device. Updates may affect the control logic executed by the device to perform protection or other functions, and / or may affect other aspects of the device’s operation, such as network security-related functions.
[0166] These devices are operable to process measurements captured using measuring instruments and perform one or more protection or other control functions. In power systems, examples of such devices include protective relays. These devices may include at least some of the primary equipment (such as switching devices) operable to trigger or otherwise operate the infrastructure system.
[0167] As used herein, the term "infrastructure system" includes critical infrastructure systems such as power generation, transmission, and / or distribution systems, such as power grids or portions thereof. Other examples of such infrastructure systems include freshwater supply or natural gas or oil storage, transmission, and / or distribution systems.
[0168] As used herein, the term "power grid" includes transmission and / or distribution networks. A power grid may include both transmission and distribution networks.
[0169] As used herein, unless otherwise expressly stated, the term "power" refers to electricity.
[0170] The techniques disclosed herein are operable to reduce the risk of communicationally coupled devices to a SCADA system being taken out of full operational status to install updates when the device is critical to safe operation. As used herein, the term “critical” or “critical” means that the device is essential to ensuring the safe operation of the automation control system and / or the primary system associated with the automation control system. Examples of non-critical devices are devices with redundant implementations of all safety-critical functions and devices associated with currently unused or rarely used portions of the primary system (such as a part of a power system with no current or power flow or very little current or power flow).
[0171] This invention provides a method and system for controlling the updating of machine-readable data processed by equipment in an automated control system. The invention provides communication interaction between an FLM (Fluorescent Lamp) system and a SCADA (Supervisory Control and Automated Guided Vehicle) system to utilize the interaction between the FLM and SCADA systems to include critical and / or operational status information of the device during firmware updates.
[0172] Therefore, embodiments of the present invention address the need for improved techniques for updating devices coupled to SCADA systems.
[0173] Figure 1 This is a schematic representation of system 10 according to an embodiment. System 10 includes a primary system 20. The primary system 20 may be or may include an electrical system, such as a power generation, transmission, and / or distribution system. The primary system 20 may include at least a portion of a power grid.
[0174] System 10 includes an automation control system 40. The automation control system 40 includes a plurality of devices 41 to 46. At least some of the devices of the automation control system 40 are operable to perform protection functions or other functions involving the control of components of the primary system 20, such as switchgear 22 or transformer 21. At least some of the devices of the automation control system 40 are operable to perform decision logic based on measured values, such as those received from measuring instruments, which may include current transformer 11, voltage transformer 12, and / or phasor measurement units. Examples of devices in the automation control system include protective relays or other IEDs operable to perform distance protection, time protection, or other protection functions.
[0175] System 10 includes a redundancy system 50 that provides redundant implementation for at least some functions performed by the devices of the automation control system 40. The redundancy system 50 can be implemented in various ways. For example, there may be dedicated redundant devices corresponding one-to-one with each device of the automation control system 40. Other implementations are also possible. For example, there may be a centralized redundancy system that can be provided at the substation level and can provide redundancy for the functions performed by several devices in the substation automation (SA) system.
[0176] System 10 includes a communication system 47. Communication system 47 may be or may include a communication network. Communication system 47 may include multiple communication links through which devices of the automation control system 40 communicate with each other and / or with a central system (such as SCADA system 60 and FLM system 80). Communication may be performed using communication devices such as gateway device 48.
[0177] As will be described in more detail below, system 10 includes SCADA system 60 and FLM system 80. FLM system 80 and SCADA system 60 are operable to cooperate with each other to determine the order in which devices of automation control system 40 will be updated when updates become available.
[0178] The interaction between FLM system 80 and SCADA system 60 can be achieved in various ways.
[0179] In one implementation, FLM system 80 can provide SCADA system 60 with information about the equipment to be updated. SCADA system 60 can use the available information and consider the criticality and / or operational status of the equipment to determine the order in which the update process can be initiated. This can be ongoing, with SCADA system 60 determining at each of several time points which equipment is in an operational state that allows updates without affecting system safety and / or which equipment can enter maintenance mode because all critical functions performed by the equipment have operable redundancy. SCADA system 60 can then provide FLM system 80 with information about a subset of the equipment to be updated, and FLM system 80 can trigger the update process (e.g., by instructing the equipment to install the update and / or distributing the update prior to installation). SCADA system 60 can determine and execute control operations that can be interleaved with actions performed by FLM system 80, such as instructing the equipment to enter maintenance mode and instructing the equipment to return to full operational mode after successful update. Control operations (also referred to as control actions) can also include control operations affecting primary switching equipment, such as activating a redundant (or backup) portion of the power system while simultaneously placing another portion of the power system in a mode that allows for at least partial power outage and updates to equipment associated with its primary equipment.
[0180] In another implementation, which can be implemented alone or in combination with previous methods, the FLM system 80 can request data from the SCADA system 60 related to the criticality and / or operational status of the device to be updated. For example, the FLM system 80 can request the SCADA system 60 to provide the operational status (operation / maintenance mode) of the device to be updated, the operational status (operation / maintenance mode) of redundant functional implementations running the functions of the device to be updated, and / or information about whether the redundant functional implementations are currently active. The FLM system 80 can use this data, considering both criticality and / or operational status, to determine which devices can be updated and can trigger the update process. The FLM system 80 can collaborate with the SCADA system 60 to ensure that the SCADA system 60 sets the device to maintenance mode when an update is required.
[0181] In another implementation, which can be implemented independently or in combination with previous implementations, one of the SCADA system 60 or FLM system 80 can determine a schedule defining which subset of devices will be updated and when, and transmit this schedule to the other of the SCADA system 60 or FLM system 80. To ensure that the devices of the SCADA system 60, FLM system 80, and automation control system 40 use a consistent timing reference, updates can be made based on the time provided by source clock 49. Source clock 49 can be the source clock used by the devices of automation control system 40 during normal field operation (i.e., performing protection or other functions). Source clock 49 can operate according to the precision time protocol IEEE 1588.
[0182] As will be described in more detail below, the SCADA system 60 and the FLM system 80 are operable to interact with each other to mitigate the risk of triggering an update process for equipment that is critical to the operation of the equipment (e.g., in a sense, (a) it is in an operating state different from the maintenance mode, and (b) it performs at least one function that is critical to a single system operation and has no redundant function implementation).
[0183] By using the communication coupling between SCADA system 60 and FLM system 80, in a manner further described in detail herein, the timing of the update installation triggered by FLM system 80 may take into account data available to SCADA system 60 (such as the presence and / or operational status of redundant function implementations), which FLM system 80 may utilize using the techniques disclosed herein.
[0184] As described above, the application field of the technology disclosed herein is for automated control systems of a primary system 20, which is or includes a power system, such as a power grid or a sub-part thereof. For example, as Figure 1 As illustrated schematically, the power system may include primary components such as power transformer 21, switching device 22 (such as circuit breaker or switch), renewable energy sources 24, 25 (which can be connected to the power system bus via an inverter), energy storage system (such as battery energy storage system 23), or time-coupled equipment (such as charging station 26).
[0185] However, the techniques disclosed herein are not limited to power systems and can also be applied to automated control systems used in conjunction with other infrastructure systems, such as hydraulic or pneumatic systems. The techniques disclosed herein can also be used in conjunction with industrial automation control.
[0186] Figure 2A block diagram representation of an FLM system 80 is shown. The FLM system 80 includes at least one (i.e., one or more) FLM system interfaces 81. At least one FLM system interface 81 is operable to output first data 88 defining a set of devices to be updated. The first data 88 may optionally include an estimated update duration. The FLM system 80 is operable to send the first data to a SCADA system 60. At least one FLM system interface 81 is operable to receive second data 69, and the FLM system 80 is operable to use the second data 69 to establish a sequence (and optionally a specific time) in which devices communicatively coupled to the SCADA system 60 will be updated. At least one FLM system interface 81 is operable to receive the second data 69 from the SCADA system 60. At least one FLM system interface 81 is operable to generate and output a command 89 to trigger devices communicatively coupled to the SCADA system 60 (and communicatively coupled to the FLM system 80) to perform updates, for example by retrieving firmware updates and / or initiating a firmware update installation process.
[0187] The FLM system 80 may optionally include a human-machine interface (HMI). The FLM system 80 is operable to allow information generated based on second data to also be output via the HMI.
[0188] FLM system 80 may include FLM storage system 82. FLM storage system 82 may store data or metadata related to available updates (such as metadata defining the size of each update), data specifying the currently installed firmware version on each device, and / or data specifying the device's hardware configuration and / or hardware usage. FLM storage system 82 may also store data about historical update processes (such as historical update durations stored in association with the update data size and / or hardware configuration of the device where the update was installed), which FLM system 80 can use to determine the expected update duration using techniques such as regression (such as multiple regression). FLM system 80 is also operable to store data related to the update progress of initiated updates in FLM storage system 82. FLM system 80 is operable to provide SCADA system 60 with information related to triggered update processes, for example, by notifying SCADA system 60 of completed update processes and / or newly installed firmware versions.
[0189] The FLM system 80 includes one or more FLM processing circuits 83.
[0190] One or more FLM processing circuits 83 are operable to perform device identification 84. Device identification 84 is operable to determine a set of devices to be updated. Therefore, at least one FLM processing circuit 83 is operable to determine either the devices to be updated or a set of devices comprising those communicatively coupled to the SCADA system 60. At least one FLM processing circuit 83 is operable to access data stored in the FLM or storage system 82, such as data defining the currently installed firmware version and data defining available firmware updates, to determine the set of devices. At least one FLM processing circuit 83 is optionally operable to use historical information stored on the FLM storage system 82 to determine the expected update duration.
[0191] One or more FLM processing circuits 83 are operable to execute FLM interface control 86. FLM interface control 86 can operate in response to the result of device identification 84. FLM interface control 86 is operable to control at least one FLM system interface 81 to generate first data 88, which includes identifiers of all devices in the identified device set (i.e., for the device to be updated) or other information defining the devices in the identified device set. FLM interface control 86 can control at least one FLM system interface 81 such that the first data 88 additionally includes the expected update duration. The expected update duration may vary for different device types, device hardware configurations, or currently installed firmware versions. The expected update duration can be determined using regression techniques (such as multiple regression) or other techniques based on the size of the update to be installed, the hardware configuration of the device to which the update is to be installed, and the update duration, update size, and hardware configuration of historical updates that have been successfully completed.
[0192] The FLM interface control 86 is also operable to control at least one FLM interface 81 to receive and process second data 69 from the SCADA system 60. At least one FLM processing circuit 83 is operable to process the second data 69 to establish a sequence of devices included in the updated device set. This may include ongoing processes in which different subsets of the device set are identified when a new message is received from the SCADA system 60 among multiple messages included in the second data 69.
[0193] At least one FLM processing circuit 83 is operable to execute an update trigger 85 to trigger an update of a device to be updated, such as triggering the retrieval of update data and / or the installation of an update. The update trigger 85 may be implemented in response to second data 69 received from the SCADA system. For example, the update trigger 85 may generate a command to trigger an update process for a subset of the device set, defined by the second data 69 (such as messages among the multiple messages forming the second data 69). The update trigger 85 may control the FLM interface control 86, which in turn may cause the FLM system interface or interface 81 to output command 89 to trigger an update process in at least one subset of the device set.
[0194] At least one FLM processing circuit 83 is optionally operable to perform update monitoring 87. Update monitoring 87 may be based on progress reports received from the device to be updated. Update monitoring 87 may include checking and confirming the successful completion of the update installation and / or recording the update duration. This information may be aggregated by the FLM system 80. At least a portion of the aggregated information, i.e., data derived from the received set of reports, may be stored in the FLM storage system 82 for later use. The FLM system 80 may use the update reports to notify the SCADA system 60 of successfully implemented firmware updates and / or to improve the model used to estimate the installation duration of future updates.
[0195] At least one FLM processing circuit 83 may include, but is not limited to, any or any combination of integrated circuits, integrated semiconductor circuits, processors, controllers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), circuits including qubits and / or quantum gates.
[0196] Figure 3 A block diagram representation of SCADA system 60 is shown.
[0197] SCADA system 60 includes at least one SCADA system interface 61. The at least one SCADA system interface 61 is operable to receive first data 88 defining a set of devices to be updated. The first data 88 may optionally include an estimated update duration. SCADA system 60 is operable to receive the first data 88 from FLM system 80. The at least one SCADA system interface 61 is operable to output second data 69 to FLM system 80. The second data 69 may define a subset of devices to be updated, for example, in the form of an ordered list. The ordered list may be included in several messages contained in the second data 69 and output by SCADA system 60 in chronological order.
[0198] SCADA system 60 may optionally include human-machine interface (HMI) 62. SCADA system 60 is operable such that information related to an update sequence, such as information about devices updated as a group within a given time interval, can be output via HMI 62.
[0199] SCADA system 60 may include SCADA storage system 63. SCADA storage system 63 may store the operating status of devices communicatively coupled to SCADA system 60. SCADA storage system 63 may store information about redundant implementations of functions performed by the devices (if any) and their operating status (i.e., whether the redundant implementation is running). SCADA storage system 63 may also store information about primary equipment, such as the status of switching devices (e.g., circuit breaker status), the position of (one or more) tap changers, transformer status, etc. Such data can be obtained from measuring instruments or inferred from measurement results or IEC 61850 compliance messages.
[0200] SCADA system 60 includes one or more processing circuits 64. The one or more processing circuits 64 are operable to perform at least one update sequence determination 70 to determine, based on received first data 88 and operational data available to the SCADA system (such as data in SCADA storage system 63), which devices, specified by the first data 88, will be updated at what time. In determining which devices, specified by the first data 88, will be updated at what time, SCADA system 60 may consider one or both of the device's criticality to system safety and the device's operational status. For example, SCADA system 60 may define a subset of devices based on whether the devices are in a field operation state that is not fully operational (such as a maintenance mode that is significantly different from a fully operational field operation state) and / or whether all safety-critical functions performed by the devices have redundant implementations, where the redundant implementations are operational (i.e., not in a state where there is no guarantee that they will be successfully put into operation as needed). Devices in maintenance mode and devices with redundant implementations of all safety-critical functions may be included in the subset of devices for which FLM system 80 can initiate an update process. The update sequence determination 70 enables the SCADA interface control 65 to generate and output a message of second data 69 via at least one SCADA system interface 61, which defines a subset that can trigger the update process.
[0201] The SCADA system 60 can use additional or alternative technologies to determine which devices will be updated and when. The SCADA system 60 is specifically operable to perform processing associated with the processing system disclosed in Hitachi Energy Switzerland's patent application EP23177537.0, filed June 6, 2023, entitled "METHOD AND PROCESSING SYSTEM FOR CONTROLLING A TRANSFER AND / OR AMODIFICATION OF MACHINE-READABLE DATA PROCESSED BY DEVICES OF AN AUTOMATIONCONTROL SYSTEM, AND METHOD OF CONTROLLING AN INFRASTRUCTURE SYSTEM".
[0202] For example, the update sequence determination 70 is operable to process time series of generator unit commitment and load data to predict generator unit commitment and load power within a predicted time range. Based on the predicted generator unit commitment and load power, the update sequence determination 70 can determine the timing of modifications to various devices in a manner that performs modifications (e.g., software or firmware updates) at regular intervals, wherein the generator unit commitment and load power predicted at those intervals within the predicted time range indicate that the corresponding devices can be decommissioned from their normal full operating state without compromising the operational safety of the primary system 20.
[0203] The updated sequence determination 70 is operable to perform forecasting using at least one trained machine learning (ML) model. Relevant techniques for processing time series of observations into time series of forecast values are available to those skilled in the art. For example, a recurrent neural network architecture can be used. The ML model may include one or more units, such as Long Short-Term Memory (LSTM) units (e.g., a stack of LSTM units), to process time series of observations into time series of forecast values for generator unit combinations and / or load power.
[0204] One or more SCADA processing circuits 64 are operable to perform SCADA interface control 65 in response to a determined update sequence. SCADA interface control 65 is operable to control at least one SCADA system interface 61 based on the determined update sequence and / or the command sequence determined by command sequence determination 75.
[0205] One or more SCADA processing circuits 64 are operable to perform command sequence determination 75 based on received first data 69 and system operations of the automation control system 40 available to the SCADA system 60 (e.g., in the SCADA storage system 63). Command sequence determination 75 may include determining a sequence of control actions to be performed by the SCADA system 60 in a manner coordinated with an update process triggered by the FLM system 80. The sequence of control actions may include commands to place the device in maintenance mode, allow firmware updates to be installed on the device if the device is determined to be non-critical (e.g., because all safety-related functions have redundant implementations), and return the device to its normal full operating mode after a successful firmware update (this may be reported to the SCADA system 60 by the FLM system 80). The sequence of control actions may include control actions affecting the primary system (i.e., not limited to the secondary system).
[0206] At least one processing circuit 64 is operable to store a report on the updated performance in the SCADA system storage device 63 for future use. For example, during field use of the SCADA system 70, the update sequence determination 70 can be continuously updated based on the performance reports received and stored in the SCADA system storage device 63. The performance reports can be received from the FLM system 80.
[0207] At least one processing circuit 64 may include, but is not limited to, any one or any combination of integrated circuits, integrated semiconductor circuits, processors, controllers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), circuits including qubits and / or quantum gates.
[0208] Figure 4 This is a block diagram representation of the implementation of update sequence determination 70. Update sequence determination can be implemented such that the device to be updated is identified based on the device's operational state (e.g., whether the device is currently in maintenance mode) and / or based on whether there are redundant implementations of the device's safety-critical functions (for devices that are not critical to system safety operation in other respects at a given time). Update sequence determination may include device status check 71. Device status check 71 is operable to access the device operational states of those devices included in the device set of devices to be updated determined by FLM system 80.
[0209] The update sequence determination may include a criticality check 72. The criticality check 72 may determine which devices among those designated by the FLM system 80 as devices to be updated are considered non-safety critical. The criticality check 72 may be implemented by checking whether all safety-critical functions of the devices have redundant implementations in other devices, or may include checking these functions.
[0210] The update sequence determination may include a scheduler 73 that determines which devices among those identified as pending updates will be updated and at what time. Scheduler 73 may include a grouping process 74 that groups devices into subsets. For example, when scheduler 73 is invoked, grouping process 74 may identify all devices currently in maintenance mode or not currently safety-critical. Information regarding subsets including these identified devices may be provided to trigger the update process. Scheduler 73 may be invoked repeatedly, for example, intermittently (periodically or aperiodically), until all devices specified in the first data 88 have been processed.
[0211] Figure 5 This is a flowchart of method 90. Method 90 can be executed automatically by the FLM system 80.
[0212] In process block 91, the FLM system 90 determines a set of devices, or a set of devices comprising all devices for which firmware updates (or other machine-readable code updates) are available. Process block 91 may also include the FLM system 90 determining the expected update duration for the devices.
[0213] In process block 92, the FLM system 90 generates first data for all devices in the defined device set and provides the first data to the SCADA system 60. The first data may also include an indicator of the expected update duration.
[0214] In process block 93, FLM system 90 receives second data from SCADA system 60. The second data may include one or more messages, each defining at least a subset of the device. Optionally, the second data may also include timing information specifying when to initiate the update process.
[0215] In process block 94, FLM system 90 establishes a time series (in which various devices of the device set will be updated) and initiates the update process according to the established sequence.
[0216] Figure 6 This is a flowchart of method 100. Method 100 can be executed automatically by the SCADA system 60.
[0217] In process block 101, SCADA system 60 receives first data from FLM system. The first data indicates all devices to be updated included in the device set determined by FLM system 80. The first data may also optionally include the expected update duration for the devices included in the device set.
[0218] In process block 102, the SCADA system 60 determines the sequence of equipment updates. The SCADA system can also determine a sequence of control actions to be executed in an interleaved manner with the update process. The determination at process block 102 can be performed based on equipment status information, such as the equipment's operating status and / or the presence of any running redundant functions. The determination at process block 102 can also be performed based on primary equipment data, such as, but not limited to, one or more of, current, voltage, or PMU measurements, circuit breaker and / or other switchgear status, tap changer position, transformer conditions, generator unit configuration, and load level.
[0219] In process block 103, SCADA system 60 generates at least one message. The at least one message is sent to FLM system 80. This at least one message identifies at least one subset of the device set specified by the first data.
[0220] In process block 104, the SCADA system 60 coordinates with the update process of at least one device specified in a message to execute control actions. Control actions may include controlling some or all of a subset of devices to enter maintenance mode. Control actions may include, after a successful update installation, controlling some or all of the subset of devices to return from maintenance mode to full operation mode. Control actions may include commands to change the state of primary system components, such as power system components, e.g., switchgear, transformers, and / or other primary system components. Therefore, the primary system may be affected, allowing the devices controlled by the SCADA system to be safely updated.
[0221] In process block 105, the SCADA system determines whether any devices have not yet been addressed. This may include comparing the union of all identified subsets with the device set specified by the first data. If all devices have been addressed, the method ends in process block 106. Otherwise, the method may return to process block 103.
[0222] Figure 7 This is a block diagram of device 110. The configuration of device 110 can be used for some or all of the devices in the automation control system 40.
[0223] Device 110 includes a device interface 111 operable to receive machine-readable data. The machine-readable data may include software or firmware updates persistently stored in device memory 112 of device 110. Instruction code 113 may be stored in device memory 112.
[0224] Device 110 includes one or more device circuits 114. The one or more device circuits 114 are operable to perform control and / or monitoring functions associated with primary system components of primary system 20. The one or more device circuits 114 are operable to cause the control and / or monitoring functions to process measured values (such as measured values of electrical characteristics or quantities derived therefrom) to determine control actions to be performed on the primary system components. In one implementation, the control and / or monitoring functions may include protection functions, such as distance protection functions. In this case, the control action may include switching device tripping, such as circuit breaker tripping or switch tripping. In another implementation, the control and / or monitoring functions are operable to control a tap changer. In the latter case, the control action may include changing the position of the tap changer.
[0225] Typically, device 110 can execute logic to process measurements obtained from primary system 20 into control actions for primary system 20 or one of its components. This logic can be defined by instruction code 113 stored in device memory 112.
[0226] One or more device circuits 114 are operable to execute updater 116. Updater 116 is operable to modify instruction code 113 based on received machine-readable data. Updater 116 is operable to trigger an update process according to an update sequence determined by SCADA system 60 communicating with FLM system 80. Device 110 is operable to receive command 89 from FLM system 80. Updater 116 is operable to retrieve firmware update data and / or install firmware update data in response to command 89. Command 89 may also include a start time, at which updater 116 is operable to begin the update process. Therefore, the start time is controlled by FLM system 80 communicating with SCADA system 60.
[0227] One or more device circuits 114 may include any or any combination of the following: integrated circuits, integrated semiconductor circuits, processors, controllers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), circuits including qubits and / or quantum gates, but not limited thereto.
[0228] Figure 8This is a schematic diagram further explaining and illustrating the operation of the method and system according to the embodiments. Multiple devices 120 are communicatively coupled to SCADA system 60. FLM system 80 determines a device set 121 of devices to be updated. This determination may include checking which devices are eligible for an updated firmware version. SCADA system 60 or FLM system 80 may determine different subsets 122, 123, 124 of devices, where all devices in any subset are operational and / or have criticality allowing them to be jointly updated. SCADA system 60 may provide messages to FLM system 80, each message relating to one (and only one) subset. FLM system may trigger an update process for the corresponding device subset in response to the receipt of a message.
[0229] The communication interaction between the FLM system 80 and the SCADA system 60 ensures the availability of critical and operational status information as input to the firmware update process. The techniques disclosed herein integrate firmware updates with operations performed by the SCADA system 60. This process can be implemented in several ways. In one implementation, the FLM system 80 sends the set of devices S requiring firmware updates to the SCADA system 60, along with an estimated duration for which the update will be applied to each device. The SCADA system 60 determines the update sequence and a list of control actions. For example, low-criticality devices (such as standby and idle relays) are updated first. The update sequence can be or may include a list of device subsets S1, S2, ..., Sn, which are partitions of the device set S. The list of control actions C1, C2, ..., Cn may include or consist of operations performed by the SCADA system 60 and interleaved with the update process. For example, the FLM system 80 and the SCADA system 60 can be operated such that the entire process will first update the devices in the device subset S1, then the SCADA system 60 executes command C1, then the devices in the device subset S2 are updated, and so on. SCADA system 60 can send a command to the devices in the currently updated subset Si to enter maintenance mode, where i is between 1 and n. This is not necessary for devices already in maintenance mode. SCADA notifies FLM system 80 what subset Si of devices is ready for update in the current cycle. FLM system 80 triggers firmware updates for these devices. The devices apply the firmware update (e.g., by retrieval and / or installation). These devices report the update results to FLM system 80. FLM system 80 can collect the update results from the updated devices. FLM system 80 can report to SCADA system 60 that the current update cycle has been successfully completed. SCADA system 60 can send commands to the updated devices and set them to active mode. Finally, SCADA system 60 can execute command Ci on the system to enable the updated devices and disable the devices to be updated in the next cycle. Commands can also trigger control actions that act on the system.
[0230] This technology ensures that the device receiving the firmware update does not affect the operation of the power system during the update process. Furthermore, the functional separation between the FLM system 80 and the SCADA system 60 is maintained, which is beneficial from a safety perspective.
[0231] Figure 9 It is a signaling diagram of a system 130 that includes a SCADA system 60, an FLM system 80, and a device 120 that is communicatively coupled to the SCADA system 60.
[0232] The technology disclosed in this article utilizes the following aspects of various components: The SCADA system 60 can be operated to control critical equipment and set the equipment to maintenance / activity mode. In maintenance mode, the SCADA system 60 recognizes that the equipment may be unresponsive or unfunctional for a period of time due to the installation of firmware updates.
[0233] The FLM system 80 is operable to provide initial data defining a list of devices requiring firmware updates, and an estimate of the update duration for each device. The FLM system 80 is operable to trigger an update process. The FLM system 80 is operable to monitor and collect the results of the update process.
[0234] The device 120 is operable to be controlled by the SCADA system 60 and to receive firmware updates from the FLM system 80.
[0235] System 130 can be operated as follows: FLM system 80 sends first data 131 to SCADA system 60, including the set S of devices to be updated and the estimated update duration for each device. The estimated duration may simply be the time required to switch from the old version to the new version, or it may include the time required to download the new version to the device.
[0236] At point 132, considering the set S of target devices to be updated and the estimated update duration, the SCADA system 60 determines the update sequence. The update sequence may include, or may be, a list of subsets S1, S2, ..., Sn and a list of control actions C1, C2, ..., Cn. The actions explained in references 133-141 are executed n times (i is between 1 and n), meaning these actions are performed for each subset of devices.
[0237] The SCADA system 60 sends command 133 to the devices in subset Si to put them into maintenance mode. Such commands must not be sent to devices already in maintenance mode.
[0238] The SCADA system 60 sends a message of second data 134 or second data to the FLM system 80, which defines the subset of devices Si that are ready to be updated in this cycle.
[0239] FLM system 80 receives a subset of devices Si that can be used for this cycle and triggers a firmware update process. This may include the transmission of command 135.
[0240] The target device receives trigger command 135 from FLM system 80 and performs the update installation at process block 136.
[0241] These devices can report the status and results of their update process to the FLM system 80. This may include receiving reports 137 from a subset of devices that are updating in the current cycle.
[0242] In process block 138, the FLM system 80 can collect update results from devices that are updated in the current cycle. The FLM system 80 can aggregate reports for further use, such as storing them in history and / or estimating update times.
[0243] If all devices have successfully completed the firmware update, the FLM system 80 sends message 139 to the SCADA system 60, indicating that the devices in this cycle have successfully completed the update.
[0244] The SCADA system 60 sends command 140 to the updated device and sets it back to active mode.
[0245] The SCADA system 60 executes a control action Ci (e.g., opening / closing a circuit breaker), which enables the operation of the updated device in Si and disables the operation of the device in the next cycle (Si+1).
[0246] SCADA system 60 can determine the device subset and update sequence in various ways. SCADA system 60 is operable to determine the update sequence based on the set of devices to be updated and the expected update duration for each device. The update sequence defines the devices to be updated in each update cycle. The update sequence may also accompany or include a list of commands executed by SCADA system 60 after each update cycle. Commands are not limited to those operating on the devices to be updated, but may also include commands affecting the primary system (such as those by operating switchgear, transformers, energy storage systems (ESS), tap changers).
[0247] The technologies that SCADA systems can implement are as follows: SCADA system 60 is operable to utilize redundancy (e.g., dual busbars) in the power system. SCADA system 60 can decide to first update devices in backup mode (e.g., S1 is the set of devices in backup mode). Next, SCADA system 60 is operable to switch the busbar to redundant mode and allow updates to devices in primary mode (e.g., C1 activates backup mode and disables primary mode, S2 is the set of devices in primary mode). Finally, SCADA system 60 is operable to change back to operating primary mode (e.g., C2 activates primary mode and disables backup mode). Generating a redundancy-based update sequence can be performed automatically using a SCADA model. Generating a redundancy-based update sequence may include control HMI 62 enabling operator input to determine the redundancy-based update sequence.
[0248] Alternatively or additionally, the SCADA system 60 is operable to monitor the operating status of equipment. The SCADA system 60 is operable to allow currently inactive equipment (e.g., with zero current) to be included in the first update cycle (i.e., S1). The SCADA system 60 is operable to allow remaining equipment to be sorted based on current and to define a threshold for the current. Once the current of equipment falls below the threshold, it will be considered for the next update cycle. For equipment that never falls below the threshold, the SCADA system 60 can define the maintenance interval (using an update duration estimate) when these devices are updated.
[0249] Alternatively or additionally, the SCADA system 60 may operate such that, for at least some devices, the SCADA system 60 decides not to proactively execute control actions to disable these devices, but instead waits for certain planned control actions (e.g., planned maintenance). Once these planned control actions disable the target devices, the SCADA system 60 puts these devices into maintenance mode and notifies the FLM system 80 that these devices are ready for an update (e.g., as in a regular update cycle). The advantage of this approach is that it reduces the number of control actions required to update the entire fleet by utilizing planned control actions. This technique is suitable for situations where firmware updates for the entire fleet are not time-critical for all devices and for some devices, they can be postponed until planned control actions.
[0250] Figure 10 This is a flowchart of method 150, which can be automatically executed by the FLM system 80. Figure 10 In the second data 89 received by the FLM system from the SCADA system, there are individual messages received in chronological order, each message being associated with a subset of devices.
[0251] Process blocks 91 and 92 can be combined as follows Figure 5 The aforementioned implementation.
[0252] In process block 151, FLM system 80 receives a message from SCADA system 60 that notifies FLM system 80 that the device subset is ready for updating.
[0253] In process block 152, the FLM system 80 initiates an update process for the devices of the subset of devices specified by the received message. This may include generating and issuing commands that cause the devices of the subset to retrieve and / or install update data.
[0254] In process block 153, FLM system 80 determines whether all devices in the device set identified at 91 have been updated. If all devices in the device set have been updated, the method ends in process block 154. Otherwise, FLM system 80 continues to monitor for further messages from SCADA system 60, which notify FLM system 80 of at least one further subset of devices from which the update process can begin.
[0255] In combination Figures 2 to 10 In the discussed techniques, the FLM system 80 and the SCADA system 60 interact, allowing the SCADA system 60 to use device status and / or criticality to determine an appropriate update sequence based on data available to or at the SCADA system 60. In other implementations, the FLM system 80 and SCADA system 60 may interact in such a manner that the FLM system 80 retrieves data from the SCADA system suitable for determining the update sequence. This will refer to... Figures 11 to 13 To provide a more detailed explanation.
[0256] Figure 11 A variant of the FLM system 80 is shown. Components operable as previously described are indicated by the same reference numerals. The FLM system 80 is operable to perform at least update sequence determination 70. To determine the update sequence (which may include determining an ordered list of subsets of devices in a set of devices to be updated), the FLM system 80 may request second data 159 from the SCADA system 60, which includes SCADA data related to the operational status and / or criticality of the devices. Update sequence determination 70 may use this SCADA system data as previously described (e.g., by organizing the device set into subsets based on criticality and / or operational status). Optionally, although... Figure 11 Although not shown, the FLM processing circuit 83 is operable to execute at least a portion of the command sequence determination 75. The FLM system 80 is operable to generate and output at least one message to notify the SCADA system of the determined update sequence, and, if determined by the FLM system 80, to notify the determined command / control action sequence. In another implementation, the command sequence determination 75 can still be executed by the SCADA system 60 using the update sequence determined by the FLM system 80.
[0257] Figure 12 This is the signaling diagram for system 160, which includes SCADA system 60, FLM system 80, and device 120 communicatively coupled to SCADA system 60. When at least one update sequence is determined to be performed by FLM system 80 using SCADA data retrieved from SCADA system 60, Figure 12 The signaling diagram is applicable. Then, system 130 can operate as follows: The FLM system 80 sends first data 161, which includes the set of devices S to be updated, to the SCADA system 60. The estimated update duration for each device can be included in the first data 131, but is not required.
[0258] The FLM system 80 receives second data 163 from the SCADA system 60, which includes operational status and / or other relevant information, such as information about the implementation of critical or redundant functions of the equipment. The SCADA system 60 may provide the second data in response to the first data 161.
[0259] In step 163, considering the set S of target devices to be updated and the estimated update duration, the FLM system 80 determines the update sequence. The update sequence may include or may be a list of subsets S1, S2, ..., Sn.
[0260] The FLM system 80 provides at least one update sequence 164 to the SCADA system 60. The FLM system, or preferably the SCADA system 60, can determine a list of control actions C1, C2, ..., Cn.
[0261] Then, the actions explained earlier regarding 133-141 can be executed n times (i is between 1 and n), that is, these actions are performed for each subset of devices. For the implementation of these processing and signaling operations, please refer to the explanation provided above.
[0262] Figure 13 This is a flowchart of method 170, which can be automatically executed by the FLM system 80. Figure 13 In the process, the second data 89 received by the FLM system from the SCADA system includes SCADA system data, and then the FLM system 80 uses the SCADA system data to determine the update sequence.
[0263] Process blocks 91 and 92 can be combined as follows Figure 5 To achieve it as described.
[0264] In process block 93, FLM system 80 receives second data from SCADA system 60, which includes SCADA data for determining the update sequence. The SCADA data may include the operational status of the device to be updated and / or primary system components associated with the device.
[0265] In process block 171, the FLM system 80 uses SCADA system data received from the SCADA system 60 to determine the update sequence. The determined update sequence may take into account system criticality, such as the redundancy that may exist in the automation control system and / or primary system. Criticality may also depend on the status of primary equipment (such as current, power flow, switch status, tap changer status).
[0266] In process block 172, the FLM system 80 provides at least the determined update sequence to the SCADA system 60. The SCADA system 60 can use the update sequence determined by the FLM system 80 to determine the control actions to be performed to modify equipment and optional primary system components, such as switching devices.
[0267] In process block 94, the FLM system 80 initiates the device update process according to the determined update sequence. This may include generating and issuing commands that cause a subset of devices to retrieve and / or install update data.
[0268] In any of the implementations discussed herein, the FLM system 80 and / or SCADA system 60 are operable such that logic (such as update sequence determination 70 and / or command sequence determination 75) can be adjusted during field operation of the FLM system 80 and SCADA system 60. This allows for modification of the logic based on field observations related to the update process, thereby further improving update control and system operation.
[0269] Figure 12 This is a schematic representation of one or more processing circuits that can be implemented in the FLM system 80 and / or the SCADA system 60. One or more processing circuits 64, 83 are operable to execute at least one piece of logic to control the update process of a device communicatively interfaced with the SCADA system 60. The at least one piece of logic may include update sequence determination 70 and / or command sequence determination 75.
[0270] At least one processing circuit 64, 83 is operable to perform update performance monitoring 127 to monitor update performance. Update performance monitoring may include monitoring the update duration for installing the update.
[0271] At least one processing circuitry 64, 83 is operable to execute a scheduler logic modification 128 that modifies the logic executed to determine the update sequence and / or command sequence. For example, the scheduler logic modification is operable to retrain an artificial intelligence (AI) model using update performance data associated with update metadata (such as update data size), which is logically used to predict the update duration. The AI model may have inputs operable to receive update metadata and device hardware data (such as CPU-related data), and outputs operable to provide the predicted update duration.
[0272] This logic can process measurements 180 obtained in system 20 to determine update sequences and / or command sequences. Measurements may include measurements of electrical characteristics. Measurements can be obtained using measuring instruments such as one or more phasor measurement units (PMUs) 181, one or more current transformers 11, and / or one or more voltage transformers 12. In one specific implementation already discussed, current measurements obtained by the phasor measurement units 181 and / or current transformers 11 can be used to determine the sequence of devices to be updated.
[0273] While these methods and systems have been described in detail above with reference to automated control systems for power systems, these technologies are not limited thereto. For example, these methods and systems can also be applied to other infrastructure systems, including other critical infrastructure systems such as freshwater supply, heating fluid distribution, natural gas or oil distribution, or other distribution networks.
[0274] Figure 15 System 190 is schematically shown, which includes an infrastructure system that includes hydraulic components such as a pump 191 driven by an electric motor 192 and a controllable valve 193.
[0275] The automated control system includes several devices 194 and 196 associated with the primary system equipment. The SCADA system 60 and the FLM system 80 are operable to control the updates of devices 194 and 196 in a manner that takes into account the operating status and / or criticality.
[0276] The techniques disclosed herein are generally operable to improve the process of updating devices that are communicatively coupled to and controlled by a SCADA system. Therefore, updates can be achieved in a more secure and timely manner. This also improves the operation of the devices and the primary systems associated with them. Therefore, the techniques disclosed herein also extend to methods and systems for operating infrastructure systems or other primary systems with the aid of automated control systems that include the devices.
[0277] Figure 16 This is a flowchart of method 200 according to an embodiment. Method 200 can be executed automatically by a system including SCADA system 60, FLM system 80, and device 120.
[0278] In process block 201, the FLM system 80 and the SCADA system 60 interface with each other to determine the timing of the update process that triggers device 120.
[0279] In process block 202, the FLM system 80 controls the update process. The SCADA system 60 can operate in conjunction with the FLM system 80 by setting the device 120 to maintenance mode and / or controlling switching devices or other primary system equipment.
[0280] In process block 203, the device that updates according to the received and installed updates performs protection functions or other control functions related to the primary system. This may include controlling primary system components, such as switching devices.
[0281] According to an embodiment, a processing system is provided that allows the FLM system 80 to interact with the SCADA system 60 to handle firmware or software update processes for distributed and fault-tolerant systems in safety-critical applications such as power substations and power systems.
[0282] Various effects and advantages are achieved through the systems and methods according to the embodiments. These systems and methods provide enhanced techniques for updating devices communicatively coupled to SCADA systems. Therefore, the systems and methods according to the embodiments address the need for automated update processes for potentially large fleets of equipment in the context of digitalization and cybersecurity risks, a critical function for the future power systems industry. These systems and methods help ensure that the latest security patches and features are deployed to field devices in a timely and effective manner.
[0283] Although embodiments have been described in detail with reference to the accompanying drawings, various modifications may be made in other embodiments. This is for illustrative purposes and not for limitation: • While an embodiment in which the device may be an IED operating according to IEC 61850 has been described, the techniques disclosed herein can be used in conjunction with a fleet of other devices in an automated control system.
[0284] • While embodiments in which devices can be operated to perform protective functions such as distance protection have been described, these technologies can also be used in conjunction with a fleet of devices that perform other functions, such as control functions other than distance protection. Examples include energy management systems (EMS) or power management systems (PMS) associated with a power grid with renewable energy sources.
[0285] • While embodiments of updating firmware or software in a device have been described, these techniques can also be used to adjust other settings that affect device operation. For example, these techniques can be used to control the transmission and / or modification of setpoints of the EMS and / or PMS or the logic performed by them.
[0286] The embodiments can be used in conjunction with grids that have renewable energy penetration, such as grids that include renewable energy systems (such as DER), but are not limited thereto.
[0287] This specification and the accompanying drawings illustrating aspects and embodiments of the invention should not be construed as limiting the scope of the claims. In other words, while the invention has been detailed and described in the accompanying drawings and the foregoing description, such description should be considered illustrative rather than restrictive. Various mechanical, compositional, structural, electrical, and operational changes may be made without departing from the spirit and scope of this specification and the claims. In some cases, well-known circuits, structures, and techniques have not been shown in detail so as not to obscure the invention. Therefore, it should be understood that those skilled in the art can make changes and modifications within the scope and spirit of the appended claims. In particular, the invention covers other embodiments having any combination of features of the different embodiments described above and below.
[0288] This disclosure also covers all other features shown individually in the accompanying drawings, although they may not be described in the preceding or following description. Furthermore, individual alternatives to the embodiments described in the drawings, and the descriptions of their features, may be excluded from the subject matter of this invention or the disclosed subject matter. This disclosure includes the subject matter consisting of the features defined in the claims or embodiments, as well as the subject matter including said features.
[0289] The term "comprising" does not exclude other elements or process blocks, and the indefinite articles "a" or "an" do not exclude multiple. A single unit or process block can perform the functions of several features described in the claims. The fact that certain measures are referenced in mutually different dependent claims does not mean that a combination of these measures cannot be advantageous. Components described as coupled or connected can be directly electrically or mechanically coupled, or indirectly coupled through one or more intermediate components. Any reference signs in the claims should not be construed as limiting the scope.
[0290] Machine-readable instruction code can be stored / distributed on suitable media, such as optical storage media or solid-state media provided with or as part of other hardware, but can also be distributed in other forms, such as via wide area networks or other wired or wireless telecommunications systems. Furthermore, machine-readable instruction code can also be a data structure product or a signal used to embody a particular method, such as the method according to an embodiment.
Claims
1. A method of determining an update sequence for updating machine-readable data processed by devices (41-46; 120) that interface with a supervisory control and data acquisition, SCADA, system (60), the method comprising: receiving, by the SCADA system (60), data from a fleet management, FLM, system (80), the received data defining a set of devices (121) including devices to be updated; determining, by the SCADA system (60), an update sequence for devices included in the set of devices (121); and generating and providing, by the SCADA system (60), an output defining the update sequence for the devices to be updated.
2. The method of claim 1, wherein, The data received from the FLM system (80) further includes duration data defining an estimated update duration for at least some of the devices to be updated, wherein the SCADA system (60) determines the update sequence based on the estimated update duration.
3. The method of claim 1 or 2, wherein, The SCADA system (60) determines the update sequence based on criticality of devices included by the set of devices (121) defined by the received data.
4. The method according to any of the preceding claims, wherein, The SCADA system (60) determines the update sequence based on one or both of: a redundant implementation of a function performed by devices defined by the set of devices (121); a device state.
5. The method of claim 4, wherein, The SCADA system (60) determines the update sequence such that a subset (122-124) of the set of devices (121) to be updated first includes devices having a device state different from a fully operational state and devices having a redundant implementation of a device function performed by devices.
6. The method of any preceding claim, further comprising: determining, by the SCADA system (60), a sequence of control actions to be performed in a manner coordinated with the update sequence; and performing, by the SCADA system (60), the sequence of control actions to allow the devices to be updated.
7. The method of claim 6, wherein, The sequence of control actions includes a command causing at least one of the devices to enter a maintenance mode prior to an update process triggered by the FLM system (80).
8. The method of claim 6 or 7, wherein, The sequence of control actions includes a command causing a system component to change its state such that the system is affected in a manner that allows devices controlled by the SCADA system to be safely updated.
9. The method of claim 6 or 7, wherein, The sequence of control actions includes a control action changing a state of primary system equipment of an electric power system, wherein the devices (41-46; 120) are devices (41-46; 120) of an automation control system (40) associated with the primary system equipment.
10. The method of any of the preceding claims, wherein, The SCADA system operates such that determining the update sequence includes determining which of the devices are associated with primary system equipment of an electric power system carrying a current or power flow satisfying a threshold criterion.
11. The method of any of the preceding claims, wherein, The received data from the FLM system (80) includes identifiers of all devices to be updated.
12. The method of any of the preceding claims, wherein, The output defines an ordered list of a plurality of subsets (122-124) of the set of devices (121) to define the update sequence.
13. The method of claim 12, wherein, The output comprises a plurality of messages provided by the SCADA system (60) to the FLM system (80), wherein each message defines one of the subsets (122-124).
14. The method of any of the preceding claims, further comprising: An update report is received by the SCADA system (60) from the FLM system (80).
15. The method of any of the preceding claims, wherein, The devices (41-46; 120) comprise devices (41-46; 120) of an automation control system (40).
16. The method of any of the preceding claims, wherein, The update comprises a firmware update.
17. A supervisory control and data acquisition (SCADA) system for determining an update sequence for updating machine-readable data processed by devices (41-46; 120) that interface with the SCADA system (60), the SCADA system (60) comprising: at least one SCADA data interface (61) operative to receive data from a fleet management (FLM) system (80), the received data defining a set of devices (121) including devices to be updated; and at least one SCADA processing circuit (64) operative to: determine an update sequence for devices included in the set of devices (121); generate an output defining the update sequence; and control the at least one SCADA data interface (61) to provide the output to the FLM system (80).
18. The SCADA system (60) of claim 17, wherein, The SCADA system (60) is operative to perform the method of any one of claims 1 to 16.
19. An electrical power system comprising: an automation control system (40) comprising a plurality of devices (41-46; 120) operative to process machine-readable data; a SCADA system (60) according to claim 17 or 18 operative to communicatively couple to the plurality of devices (41-46; 120); and a fleet management (FLM) system (80) operative to communicatively couple to the SCADA system (60) and the plurality of devices (41-46; 120), the FLM system (80) operative to trigger an update process with a timing based on an output of the SCADA system (60).
Citation Information
Patent Citations
Updating of trade software and / or of configurations of equipment of an electrical distribution network
EP3631745A1
Automatic firmware updates for intelligent electronic devices
US8892699B2