Method and system for controlling device updates

By coordinating the FLM system with the SCADA system, the equipment update sequence was optimized, which solved the error problem caused by incorrect timing or manual scheduling during the firmware update process, and improved the safety and reliability of the automated control system.

CN121532749APending Publication Date: 2026-02-13HITACHI ENERGY LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202480046909.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-07-13
Filing Date
2024-07-13
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

In existing automated control systems, firmware updates are prone to errors or incompleteness due to incorrect timing or human intervention, and fail to effectively consider the criticality and operational status of the equipment, thus affecting the safe operation of the system.

Method used

By using the communication interface between the Cluster Management (FLM) system and the SCADA system, the equipment update sequence is determined collaboratively, taking into account the criticality and operational status of the equipment, optimizing the update schedule and process, and ensuring that the equipment is updated in a safe state.

Benefits of technology

It reduces update errors caused by incorrect timing or human error, improves the operational safety of automated control systems, and ensures that equipment does not affect system safety at critical moments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121532749A_ABST
    Figure CN121532749A_ABST
Patent Text Reader

Abstract

In order to control updates of machine-readable data processed by devices communicatively coupled to a monitoring and data acquisition system (60), a fleet management system (80) communicatively interfaces with the monitoring and data acquisition system (60).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to systems and methods for operating to control updates of machine-readable data processed by devices communicatively coupled to a monitoring and data acquisition (SCADA) system. In particular, embodiments of the present invention relate to methods and systems for determining a schedule for updates to machine-readable data (such as firmware) of a device. Embodiments of the present invention also relate to techniques for performing control actions associated with infrastructure systems (such as power systems). Background Technology

[0002] Systems including equipment and Supervisory Control and Data Acquisition (SCADA) systems for monitoring and coordinating these devices are widely used. Such equipment and SCADA systems enable automation control systems, such as those used for industrial automation, power system automation (e.g., substation automation systems), or other infrastructure automation systems. Automation control systems are already widely used. They provide improved control and operation of infrastructure systems (such as power systems) or industrial systems. Given the capabilities offered by automation control systems and their equipment, their use is expected to increase further.

[0003] Each device can be associated with a component of a primary system (such as a power system) to perform one or more functions, such as one or more protection functions. These devices can be communicatively coupled to each other or to a SCADA system.

[0004] These devices can also be coupled to a fleet management (FLM) system. An FLM system can be configured to maintain and monitor the operational characteristics of the devices, such as processor load, memory or storage device usage, firmware version data, or other data related to how each device performs its intended function.

[0005] After devices coupled to a SCADA system have been configured, commissioned, and are operating in the field, it may be necessary to update the machine-readable data processed by these devices. For example, it may be necessary to update machine-readable instruction code that can be processed by the device to perform control, protection, and / or communication functions after the device begins operating in the field. The FLM system can also be configured to initiate an update process to perform firmware or software updates to the machine-readable code executed by the device.

[0006] Updating machine-readable data across a fleet of devices is a critical function and is likely to become even more critical in the future. Update processes may be necessary to ensure the timely and efficient deployment of the latest security patches, features, and / or performance improvements to the devices. Accelerated digitization processes in the power system industry and other critical infrastructure, along with cybersecurity challenges, have increased the need for frequent firmware updates to support power system equipment.

[0007] Traditionally, firmware updates in power systems or other critical infrastructure or industrial systems require stopping site functionality and distributing and installing new firmware on devices under the control of human experts.

[0008] US 8,892,699 B2 discloses a method for automatically updating existing firmware files stored in the memory of an intelligent electronic device (IED) coupled to network communication with a monitoring system, wherein the update is performed in response to the IED verifying that a first criterion (such as the interoperability of the update with the existing firmware file) is met.

[0009] EP 3 631 745 A1 discloses software update techniques intended to be performed by equipment in a power distribution network.

[0010] For various reasons, there is a need to further improve the automated execution of updates. For example, there is a desire to perform such updates in a way that is based on objective criteria, in a way that reduces or eliminates errors caused by human experts, or in a way that further enhances digitalization and further reduces cybersecurity risks.

[0011] One approach to further improve firmware update installation is to use an FLM system. However, when implemented natively, using an FLM system to trigger updates of machine-readable code can have drawbacks. For example, this implementation of the update process may sometimes fail to adequately mitigate the risk that the device being updated may be prevented from performing its normal and intended functions due to update installation, or that its normal and intended functions may be impaired, making it inappropriate for the device to be unusable for its intended functions. The native use of an FLM system may also be insufficient to consider the overall functional state of multiple devices, potentially including redundant function implementations.

[0012] Therefore, there is still a need for improved techniques for updating machine-readable data (such as installing software or firmware updates) of devices coupled to SCADA systems. Summary of the Invention

[0013] The object of this invention is to provide systems and methods that provide enhancement techniques for updating machine-readable data of devices coupled with Supervisory Control and Data Acquisition (SCADA) systems. An optional object of the invention is to provide methods and systems that mitigate the risk of updates being performed incorrectly or incompletely due to inappropriate timing of update installations. An optional object of the invention is to provide methods and systems that mitigate the risk of incorrect or incomplete update installations due to errors caused by human scheduling.

[0014] According to exemplary embodiments, the method and system described in the claims are provided.

[0015] According to one aspect of the present invention, a method is provided for controlling the updating of machine-readable data processed by devices communicatively coupled to a Supervisory and Data Acquisition (SCADA) system. The method includes: determining a set of devices by a Cluster Management (FLM) system, wherein the set of devices includes devices to be updated. The method includes communicatively interfaced between the FLM system and the SCADA system to establish an update sequence for the devices included in the set of devices. The method includes triggering an update process for the devices included in the set of devices by the FLM system based on the established update sequence.

[0016] This method offers several advantages and benefits. Through its interface with the SCADA system, the FLM system can perform update operations on multiple devices within a device set based on the interaction between the FLM and SCADA systems, taking into account the criticality and / or operational status information of the devices during the firmware update process.

[0017] The process of establishing an update sequence by communicating with the SCADA system via the FLM system may include: the FLM system generating first data including information about the device to be updated (which is included in the device set); the FLM system outputting the first data through at least one data interface; the FLM system receiving second data from the SCADA system through at least one data interface, the second data including information about at least one subset of the device set; and the FLM system establishing an update sequence based on the second data.

[0018] Therefore, the FLM system can specify which devices in the system need to be updated. The set of devices specified by the first data can consist of devices to be updated. The FLM system can use information provided by the SCADA system to trigger the update process, which takes into account the criticality and / or operational status of the devices. Therefore, the update process can be implemented under the control of the FLM system, but data such as the criticality and / or operational status of devices available to the SCADA system but not to the FLM system must be considered.

[0019] The first data may include the identifiers of all devices to be updated.

[0020] Therefore, the FLM system can specify the set of devices to be updated. This set of devices can include all devices for which updated firmware versions are available based on firmware data maintained by the FLM system.

[0021] The first piece of data may include the expected update duration.

[0022] This allows SCADA systems to consider the anticipated update duration when determining whether and which devices can enter maintenance mode without compromising system safety. Therefore, FLM systems can enforce the consideration of the anticipated update duration when establishing a sequence of devices to be updated.

[0023] An FLM system is operable to determine the expected update duration based on the data or metadata defining the update to be performed and historical update reports. An FLM system may include a storage system that stores historical update reports. The FLM system can access these historical update reports to determine the expected update duration and generate initial data.

[0024] Therefore, the FLM system can force the expected update duration to be taken into account when establishing the sequence of devices to be updated.

[0025] The second set of data can define several subsets of the devices to be updated.

[0026] This allows for grouping updates, with one subset being updated after another.

[0027] The second set of data can define an ordered list of several subsets of devices to be updated, in order to define the update sequence.

[0028] Therefore, at least a portion of the update sequence can be specified efficiently.

[0029] The second data may include multiple messages received from the SCADA system, where each message defines a subset.

[0030] Therefore, at least a portion of the update sequence can be specified efficiently.

[0031] Receiving one of multiple messages can cause the FLM system to trigger an update process for the subset defined by that message.

[0032] Therefore, the FLM system can efficiently determine the start time to trigger the update process. When a message is received and an update process for the device specified by one of the messages is triggered, the second data may contain (but is not absolutely required) time information.

[0033] Determining update sequences through the communication interface between the FLM system and the SCADA system may include: retrieving device status data of devices contained in the device set from the SCADA system's storage system or a storage system accessible to the SCADA system by the FLM system.

[0034] Therefore, the FLM system can retrieve data from the SCADA storage system that defines the criticality and / or operational status of the device to be updated. When determining the update sequence, the FLM system can explicitly consider the criticality and / or operational status of the device.

[0035] The FLM system can establish an update sequence based on the retrieved device status data.

[0036] Therefore, the FLM system is able to retrieve data from the SCADA storage system that defines the criticality and / or operational status of the device to be updated.

[0037] Determining the update sequence may include identifying which devices are currently in an inactive state (such as maintenance mode). Determining the update sequence may optionally include identifying which devices will remain in an inactive state (such as maintenance mode) for at least one expected update duration. Such devices may be included in a subset of the devices to trigger the update process.

[0038] Therefore, devices that are not currently critical to the operation of the security system can be updated. Devices that are critical to the operation of the system are prevented from being updated.

[0039] Determining the update sequence may include identifying devices with redundant implementations of all safety-critical functions performed by the individual devices. Such devices may be included in a subset of those that triggered the update process.

[0040] Therefore, devices with redundant implementations of all safety-critical functions can be updated without adversely affecting system security. Devices lacking redundant implementations of at least one safety-critical function can be prevented from being updated, thereby improving operational safety.

[0041] The method may further include: receiving an update report by the FLM system through at least one data interface.

[0042] Therefore, the FLM system can monitor and record the update progress.

[0043] The method may further include: the FLM system providing the SCADA system with an aggregated update report, which is composed of received update reports, through at least one data interface.

[0044] This allows the FLM system to report update progress to the SCADA system, especially updates that have been successfully completed, which causes some devices to operate using different firmware.

[0045] These devices can include equipment used in automated control systems.

[0046] Therefore, for equipment in automated control systems, updates can be controlled automatically, and firmware updates or other updates are particularly important for these devices.

[0047] Automation control systems may include power system automation control systems. These devices may include equipment used in power system automation control systems.

[0048] Therefore, updates to equipment in power system automation control systems can be automatically controlled, and firmware updates or other updates are particularly important for these devices.

[0049] Updates can include firmware updates.

[0050] Therefore, the techniques disclosed in this article can be used to install firmware updates.

[0051] The method may also include the transmission of machine-readable data updates to multiple devices by an FLM system or distribution server according to an update sequence. The machine-readable data updates can be transmitted to each of the multiple devices at a time determined according to the update sequence.

[0052] Therefore, machine-readable data can be transferred to multiple devices based on an update sequence automatically determined by the collaboration between the FLM system and the SCADA system.

[0053] The method may further include: at a time determined according to the determined update sequence, each of the plurality of devices processing the update of the transmitted machine-readable data.

[0054] Thus, the update was installed according to the update sequence.

[0055] Determining the update sequence can include determining the schedule for update distribution and the schedule for update installation.

[0056] Therefore, the transmission and installation of machine-readable data updates can be based on and performed according to a schedule determined by the collaboration between the FLM system and the SCADA system.

[0057] Updates may include updated executable code or updates to executable code. Updates to executable code can be software or firmware persistently stored in the device being updated. Different types of devices may store different types of executable code. The techniques disclosed herein are applicable to each of these different types of executable code accordingly. That is, not all devices need to receive the same updates.

[0058] Therefore, firmware or software updates for a device can be performed collaboratively, optionally taking into account the past, present, and / or predicted future states of a primary system associated with the device.

[0059] The method may also include updating software or firmware performed by the device based on an update.

[0060] Therefore, these technologies can be used to modify device operation by performing software or firmware updates.

[0061] Updating software or firmware may include updating at least one protection function logic associated with a primary system (e.g., a power system). This protection function logic may include, but is not limited to, distance protection or time-domain protection.

[0062] Therefore, these technologies can be used to modify the decision logic executed by the device to perform protection functions related to the primary system.

[0063] Transmitting an update may include transmitting the update via a packet communication link or a communication network. Alternatively or additionally, transmitting an update may include transmitting the update via a communication link in accordance with IEC 61850.

[0064] Therefore, updates can be transmitted to the equipment using communication links or other communication infrastructure for communication within or between substations according to IEC 61850.

[0065] The equipment may include protective relays or other intelligent electronic devices (IEDs) that perform protective or other functions on infrastructure systems, particularly power systems.

[0066] Therefore, the upgrading of such protective equipment, which is particularly critical to ensuring the safe operation of the power system, can be carried out in a manner that mitigates the risk of upgrading at an inappropriate time considering the safety of the power system.

[0067] According to another aspect, a method is provided for controlling the operation of an automated control system comprising multiple devices. The method includes having the devices of the automated control system execute instruction codes to perform functions related to an infrastructure system (e.g., a power system), and performing a method for updating machine-readable control data based on any aspect or embodiment of updating the devices of the automated control system during field operation of the automated control system.

[0068] This reduces the risk of unintended disruptions to the safe operation of infrastructure systems during the update process of automated control systems, thereby improving the operational safety of infrastructure systems.

[0069] According to another aspect, a method for controlling an infrastructure system is provided. The method includes controlling the equipment of the infrastructure system by devices of an automated control system, and performing a method for updating machine-readable control data according to any aspect or embodiment of updating the devices of the automated control system during field use of the automated control system.

[0070] This reduces the risk of unintended disruptions to the safe operation of infrastructure systems during the update process of automated control systems, thereby improving the operational safety of infrastructure systems.

[0071] Infrastructure systems can include power systems.

[0072] This reduces the risk of unintended disruptions to the safe operation of the power system during the update process of the automated control system, thereby improving the operational safety of the power system.

[0073] A power system may include one or more of a power generation system, a transmission system, and a distribution system. A power system may include renewable energy sources coupled to at least some buses of the power grid.

[0074] This improves the operational safety of the power system.

[0075] According to another aspect of the invention, an instruction code is provided that, when executed by at least one processing circuit, causes the execution of a method according to any aspect or embodiment.

[0076] The resulting effect corresponds to the effects and advantages disclosed in connection with the method.

[0077] According to another aspect of the invention, a non-transient storage medium is provided, on which instructions are stored, which, when executed by at least one processing circuit, cause the execution of a method according to one aspect or embodiment.

[0078] The resulting effect corresponds to the effects and advantages disclosed in connection with the method.

[0079] According to another aspect of the invention, a cluster management (FLM) system is provided for controlling the updating of machine-readable data processed by equipment of an automated control system. The equipment is communicatively coupled to a monitoring and data acquisition (SCADA) system. The FLM system includes at least one data interface. The FLM system includes at least one processing circuitry operable to determine a set of devices, wherein the set of devices includes devices to be updated. The at least one processing circuitry is operable to control the at least one data interface to communicatively interface the FLM system with the SCADA system, thereby establishing an update sequence for devices included in the set of devices. The at least one processing circuitry is operable to trigger an update process for devices in the set of devices based on the established update sequence.

[0080] The FLM system achieves a variety of effects and advantages. Through its communication interface with the SCADA system, the FLM system can perform updates to multiple devices in a device set during firmware updates, taking into account the criticality and / or operational status information of the devices, based on the interaction between the FLM and the SCADA system.

[0081] The FLM system is operable to perform the methods of any aspect or embodiment disclosed herein. Therefore, optional features of the FLM system correspond to optional features of the methods disclosed herein, wherein processing operations are performed by or using at least one processing circuitry of the FLM system.

[0082] According to another aspect of the present invention, an electric power system is provided. The electric power system includes an automated control system comprising a plurality of devices operable to process machine-readable data. The electric power system includes a monitoring and data acquisition (SCADA) system operable to be communicatively coupled to the plurality of devices. The electric power system includes an FLM system according to one aspect or embodiment and is communicatively coupled to the SCADA system.

[0083] Therefore, the system achieves the advantages and effects disclosed in connection with the FLM system and method according to various embodiments.

[0084] The FLM system is operable to generate first data including information about the devices to be updated included in the device set, send the first data to the SCADA system, receive second data from the SCADA system, the second data including information about multiple subsets of the device set, and establish an update sequence based on the second data.

[0085] Therefore, the FLM system can specify the devices to be updated. The set of devices specified by the first data can consist of devices to be updated. The FLM system can use information provided by the SCADA system to trigger the update process, which takes into account the criticality and / or operational status of the devices. Therefore, the update process can be implemented under the control of the FLM system, but must take into account data such as the criticality and / or operational status of devices that are available to the SCADA system but not to the FLM system (unless the FLM system interfaces with the SCADA system for communication).

[0086] The SCADA system is operable to receive first data, retrieve at least the device status data of the device to be updated based on the information about the device to be updated included in the first data, determine several subsets of the device set based on the device status data to specify an update sequence, generate second data based on the determined subsets, and send the second data to the FLM system.

[0087] Therefore, the FLM system can efficiently determine the start time of triggering the update process. When the receipt of a message triggers an update process for the device specified by one of the messages, timing information may, but is not always, required to be included in the second data.

[0088] The FLM system is operable to retrieve device status data of devices contained in the device set from the storage system of the SCADA system or a storage system accessible to the SCADA system.

[0089] Therefore, the FLM system can retrieve data from the SCADA storage system that defines the criticality and / or operational status of the device to be updated. The FLM system can explicitly consider the criticality and / or operational status of the device when determining the update sequence.

[0090] The FLM system can be operated to establish an update sequence based on retrieved device status data.

[0091] Therefore, the FLM system can retrieve data from the SCADA storage system that defines the criticality and / or operational status of the device to be updated.

[0092] The SCADA system is operable to receive first data from the FLM system, determine the update sequence of devices included in the device set, and generate and provide second data that defines the update sequence of the devices to be updated.

[0093] Therefore, the collaboration between the SCADA system and the FLM system ensures that the criticality and / or operational status of the devices to be updated are taken into account when determining the update sequence.

[0094] SCADA systems can determine update sequences based on the criticality of devices defined by the received data, for use in the operation of automated control systems.

[0095] This improves operational safety.

[0096] The SCADA system is operable to include duration data in the first data received from the FLM system, the duration data defining the expected update duration for at least some of the devices to be updated, wherein the SCADA system is operable to determine the update sequence based on the expected update duration.

[0097] This allows SCADA systems to take into account the estimated update duration when determining whether and which devices will enter maintenance mode without affecting system safety. Therefore, FLM systems can enforce the estimated update duration when creating update sequences for devices to be updated.

[0098] A SCADA system is operable to determine an update sequence based on one or both of the following: whether there is redundant functionality implemented by the devices defined by the device set and / or the device status.

[0099] Therefore, the SCADA system that collaborates with the FLM system ensures that the criticality and / or operational status of the equipment to be updated is taken into account, thereby improving operational safety.

[0100] The SCADA system can be operated such that the SCADA system determines an update sequence such that a subset of the set of devices to be updated first includes devices whose device status is inactive, as well as devices with redundant functions implemented by the devices.

[0101] This allows for the identification and updating of devices that are in maintenance mode or can enter maintenance mode to install updates without compromising system security.

[0102] The SCADA system can be operated to determine the sequence of control actions to be performed in a manner coordinated with the update sequence, and to execute the sequence of control actions to update the equipment.

[0103] Therefore, control actions can be performed under the control of the SCADA system in a manner coordinated with the update triggering process handled by the FLM system.

[0104] The sequence of control actions may include commands that put at least one device into maintenance mode.

[0105] Therefore, the SCADA system can control the equipment in a manner coordinated with the FLM system's triggered update process.

[0106] The sequence of control actions may include commands that change the state of components of a primary system, such as power system components, such as switching devices, transformers, tap changers, and / or other primary system components.

[0107] Therefore, a primary system can be affected in a way that allows devices controlled by the SCADA system to be safely updated.

[0108] The SCADA system is operable such that the first data includes the identifiers of all devices to be updated.

[0109] Therefore, the FLM system can specify a set of devices for which updates are to be performed. This set can include all devices for which updated firmware versions are available based on firmware data maintained by the FLM system.

[0110] The SCADA system is operable to allow the second data to define an ordered list of multiple subsets of the device set to define an update sequence.

[0111] Therefore, the sequence can be specified efficiently.

[0112] The SCADA system is operable such that the second data includes multiple messages provided by the SCADA system to the FLM system, wherein each message defines a subset.

[0113] Therefore, the FLM system can efficiently determine the start time of the update process to be triggered. When the reception of second data triggers the update process of the device specified by one of the messages, timing information may, but is not always necessary, be included in the second data.

[0114] The SCADA system is operable to receive update reports from the FLM system.

[0115] This allows the SCADA system to stay informed about update progress, especially updates that have been successfully completed and have resulted in some devices operating with different firmware.

[0116] The SCADA system can adjust the control of the equipment based on the received update reports.

[0117] This allows the current firmware version to be taken into account when the SCADA system interacts with the device.

[0118] The system may also include a communication system through which devices, an FLM system, and a SCADA system are communicatively coupled. The FLM system can be operated to establish update sequences based on bandwidth usage within the communication system, and optionally based on the bandwidth usage of each device.

[0119] Therefore, the update sequence can be determined in such a way that there is no risk of consuming the communication benefits when they need to be used for other purposes.

[0120] The communication system may include a communication system operating in accordance with IEC 61850.

[0121] Therefore, in terms of communication implementation, high requirements are ensured for the automated control systems associated with critical infrastructure systems.

[0122] The system may also include infrastructure systems (such as power systems). Equipment may be associated with infrastructure systems. Equipment may perform protection and / or other control functions associated with primary equipment in the infrastructure system (such as primary components of a power grid).

[0123] Therefore, the effects and advantages of the technology disclosed herein are applied to the automated control systems of infrastructure systems.

[0124] An automated control system can be operated as a primary system component of a control infrastructure system.

[0125] Therefore, the effects and advantages achieved by the techniques disclosed herein are used to provide enhanced control and operation of infrastructure systems.

[0126] Infrastructure systems can include power systems, such as a portion of a power grid. For example, infrastructure systems can include power transmission systems and / or power distribution systems and / or power generation systems.

[0127] Therefore, the techniques disclosed herein, along with their effects and advantages, are used to improve the operation of infrastructure systems, such as power systems (as an example of critical infrastructure systems).

[0128] The system may also include a source clock. The FLM system, SCADA system, and devices are operable such that updates are performed at a timing established with reference to the time provided by the source clock.

[0129] Therefore, consistency with the reference time is ensured, and at least one schedule is determined and implemented relative to that reference time.

[0130] Embodiments of the present invention achieve various effects and advantages. For example, the systems and methods according to the embodiments provide enhanced techniques for controlling updates of devices communicatively coupled to a SCADA system. The interoperability of the FLM system and the SCADA system allows for automatic update installation while considering the criticality and / or operational status of the devices when determining the update sequence. The methods and / or systems reduce the risk of erroneous or incomplete update execution due to incorrect timing. These methods and systems also reduce the risk of erroneous or incomplete update execution due to errors caused by human scheduling.

[0131] These systems and methods can be used in conjunction with the power grid or its subsystems, such as power system substations, but are not limited to this. Attached Figure Description

[0132] Embodiments of the invention will be described with reference to the accompanying drawings, wherein similar or identical reference numerals indicate elements having similar or identical configurations and / or functions.

[0133] Figure 1 It is a schematic diagram of a system that includes a monitoring and data acquisition system for controlling equipment updates and a cluster management system.

[0134] Figure 2 This is a block diagram of a cluster management system.

[0135] Figure 3 This is a block diagram of a monitoring and data acquisition system.

[0136] Figure 4 It is a block diagram of the processing functions performed by the cluster management system and / or monitoring and data acquisition system.

[0137] Figure 5 It is a flowchart of a method.

[0138] Figure 6 It is a flowchart of a method.

[0139] Figure 7 It is a block diagram of an automated control system device.

[0140] Figure 8 It is a schematic representation of a set of devices and a subset of devices.

[0141] Figure 9 It is a system signaling diagram.

[0142] Figure 10 It's a flowchart.

[0143] Figure 11 This is a block diagram of another cluster management system.

[0144] Figure 12 This is another signaling diagram of a system.

[0145] Figure 13 It's a flowchart.

[0146] Figure 14 It is a block diagram of the processes performed by the cluster management system and / or monitoring and data acquisition system.

[0147] Figure 15 It is a schematic diagram of a system that includes a processing system operable to determine one or more schedules.

[0148] Figure 16 It is a flowchart of a method. Detailed Implementation

[0149] Embodiments of the invention will be described with reference to the accompanying drawings. In the drawings, similar or identical reference numerals indicate elements having similar or identical configurations and / or functions.

[0150] The embodiments relate to methods and systems for updating devices that are communicatively coupled to a control and monitoring and data acquisition (SCADA) system.

[0151] While embodiments will be described in detail primarily in conjunction with automated control systems for power systems, the embodiments disclosed herein are not limited thereto. Embodiments are operable to control updates of devices in various systems, including devices coupled to a SCADA system.

[0152] While examples of machine-readable data updates being software or firmware updates for a device will be described in detail, these examples can also be applied to other types of data.

[0153] The methods and systems disclosed herein are used to control the updating of machine-readable code, particularly firmware updates, of devices communicatively coupled to a SCADA system. The update process is triggered by a cluster management (FLM) system separate from the SCADA system. The FLM system and the SCADA system are operable as a communicative interface to determine the order (optionally timing) of performing the update process on devices communicatively coupled to the SCADA system.

[0154] As used herein, the control update process includes at least controlling (e.g., triggering or otherwise scheduling) the installation time of the update. The control update process may also include controlling (e.g., triggering or otherwise scheduling) the transmission of update data to the device.

[0155] As used herein, the term SCADA system refers to a computing system operable to control the operation of equipment to coordinate, control, or otherwise support the functions possessed by the equipment, such as when operating primary equipment in an infrastructure system (such as a power system). A SCADA system is operable to receive and store records of the equipment states (such as invalid states, e.g., maintenance states and operating states) of multiple (preferably all) devices in an automated control system. A SCADA system is operable to transition equipment from a fully operating state to a maintenance state and vice versa.

[0156] As used herein, the term FLM system refers to a computing system operable to maintain data related to the firmware of devices currently deployed and communicatively coupled to a SCADA system. These devices are also typically communicatively coupled to the FLM system to allow the FLM system to record data related to, for example, the device's hardware usage, installed firmware, and (optionally) previous firmware updates. The FLM system is operable to trigger devices to perform update processes, particularly firmware updates. The FLM system can generate and issue commands to trigger update processes. The FLM system is also operable to control the distribution of update data to devices.

[0157] These devices can be devices of an automated control system. As used herein, an automated control system includes an automated control system that operates in a manner compatible with or in accordance with IEC 62443 (particularly the version of IEC 62443 effective as of the priority date or filing date of this application).

[0158] As used herein, the equipment of an automated control system may specifically include intelligent electronic devices (IEDs), such as IEDs operating in accordance with IEC 61850 (particularly the version of IEC 61850 effective at the priority or filing date of this application).

[0159] As used herein, terms such as “modification” or “alteration” of a device include modifications to the device by updating the software or firmware code executed by the device. Updates may affect the control logic executed by the device to perform protection or other functions, and / or may affect other aspects of the device’s operation, such as network security-related functions.

[0160] These devices are operable to process measurements captured using measuring instruments and perform one or more protection or other control functions. In power systems, examples of such devices include protective relays. These devices may include at least some of the primary equipment (such as switching devices) operable to trigger or otherwise operate the infrastructure system.

[0161] As used herein, the term "infrastructure system" includes critical infrastructure systems such as power generation, transmission, and / or distribution systems, such as power grids or portions thereof. Other examples of such infrastructure systems include freshwater supply or natural gas or oil storage, transmission, and / or distribution systems.

[0162] As used herein, the term "power grid" includes transmission and / or distribution networks. A power grid may include both transmission and distribution networks.

[0163] As used herein, unless otherwise expressly stated, the term "power" refers to electricity.

[0164] The techniques disclosed herein are operable to reduce the risk of communicationally coupled devices to a SCADA system being taken out of full operational status to install updates when the device is critical to safe operation. As used herein, the term “critical” or “critical” means that the device is essential to ensuring the safe operation of the automation control system and / or the primary system associated with the automation control system. Examples of non-critical devices are devices with redundant implementations of all safety-critical functions and devices associated with currently unused or rarely used portions of the primary system (such as a part of a power system with no current or power flow or very little current or power flow).

[0165] This invention provides a method and system for controlling the updating of machine-readable data processed by equipment in an automated control system. The invention provides communication interaction between an FLM (Fluorescent Lamp) system and a SCADA (Supervisory Control and Automated Guided Vehicle) system to utilize the interaction between the FLM and SCADA systems to include critical and / or operational status information of the device during firmware updates.

[0166] Therefore, embodiments of the present invention address the need for improved techniques for updating devices coupled to SCADA systems.

[0167] Figure 1This is a schematic representation of system 10 according to an embodiment. System 10 includes a primary system 20. The primary system 20 may be or may include an electrical system, such as a power generation, transmission, and / or distribution system. The primary system 20 may include at least a portion of a power grid.

[0168] System 10 includes an automation control system 40. The automation control system 40 includes a plurality of devices 41 to 46. At least some of the devices of the automation control system 40 are operable to perform protection functions or other functions involving the control of components of the primary system 20, such as switchgear 22 or transformer 21. At least some of the devices of the automation control system 40 are operable to perform decision logic based on measured values, such as those received from measuring instruments, which may include current transformer 11, voltage transformer 12, and / or phasor measurement units. Examples of devices in the automation control system include protective relays or other IEDs operable to perform distance protection, time protection, or other protection functions.

[0169] System 10 includes a redundancy system 50 that provides redundant implementation for at least some functions performed by the devices of the automation control system 40. The redundancy system 50 can be implemented in various ways. For example, there may be dedicated redundant devices corresponding one-to-one with each device of the automation control system 40. Other implementations are also possible. For example, there may be a centralized redundancy system that can be provided at the substation level and can provide redundancy for the functions performed by several devices in the substation automation (SA) system.

[0170] System 10 includes a communication system 47. Communication system 47 may be or may include a communication network. Communication system 47 may include multiple communication links through which devices of the automation control system 40 communicate with each other and / or with a central system (such as SCADA system 60 and FLM system 80). Communication may be performed using communication devices such as gateway device 48.

[0171] As will be described in more detail below, system 10 includes SCADA system 60 and FLM system 80. FLM system 80 and SCADA system 60 are operable to cooperate with each other to determine the order in which devices of automation control system 40 will be updated when updates become available.

[0172] The interaction between FLM system 80 and SCADA system 60 can be achieved in various ways.

[0173] In one implementation, FLM system 80 can provide SCADA system 60 with information about the equipment to be updated. SCADA system 60 can use the available information and consider the criticality and / or operational status of the equipment to determine the order in which the update process can be initiated. This can be ongoing, with SCADA system 60 determining at each of several time points which equipment is in an operational state that allows updates without affecting system safety and / or which equipment can enter maintenance mode because all critical functions performed by the equipment have operable redundancy. SCADA system 60 can then provide FLM system 80 with information about a subset of the equipment to be updated, and FLM system 80 can trigger the update process (e.g., by instructing the equipment to install the update and / or distributing the update prior to installation). SCADA system 60 can determine and execute control operations that can be interleaved with actions performed by FLM system 80, such as instructing the equipment to enter maintenance mode and instructing the equipment to return to full operational mode after successful update. Control operations (also referred to as control actions) can also include control operations affecting primary switching equipment, such as activating a redundant (or backup) portion of the power system while simultaneously placing another portion of the power system in a mode that allows for at least partial power outage and updates to equipment associated with its primary equipment.

[0174] In another implementation, which can be implemented alone or in combination with previous methods, the FLM system 80 can request data from the SCADA system 60 related to the criticality and / or operational status of the device to be updated. For example, the FLM system 80 can request the SCADA system 60 to provide the operational status (operation / maintenance mode) of the device to be updated, the operational status (operation / maintenance mode) of redundant functional implementations running the functions of the device to be updated, and / or information about whether the redundant functional implementations are currently active. The FLM system 80 can use this data, considering both criticality and / or operational status, to determine which devices can be updated and can trigger the update process. The FLM system 80 can collaborate with the SCADA system 60 to ensure that the SCADA system 60 sets the device to maintenance mode when an update is required.

[0175] In another implementation, which can be implemented independently or in combination with previous implementations, one of the SCADA system 60 or FLM system 80 can determine a schedule defining which subset of devices will be updated and when, and transmit this schedule to the other of the SCADA system 60 or FLM system 80. To ensure that the devices of the SCADA system 60, FLM system 80, and automation control system 40 use a consistent timing reference, updates can be made based on the time provided by source clock 49. Source clock 49 can be the source clock used by the devices of automation control system 40 during normal field operation (i.e., performing protection or other functions). Source clock 49 can operate according to the precision time protocol IEEE 1588.

[0176] As will be described in more detail below, the SCADA system 60 and the FLM system 80 are operable to interact with each other to mitigate the risk of triggering an update process for equipment that is critical to the operation of the equipment (e.g., in a sense, (a) it is in an operating state different from the maintenance mode, and (b) it performs at least one function that is critical to a single system operation and has no redundant function implementation).

[0177] By using the communication coupling between SCADA system 60 and FLM system 80, in a manner further described in detail herein, the timing of the update installation triggered by FLM system 80 may take into account data available to SCADA system 60 (such as the presence and / or operational status of redundant function implementations), which FLM system 80 may utilize using the techniques disclosed herein.

[0178] As described above, the application field of the technology disclosed herein is for automated control systems of a primary system 20, which is or includes a power system, such as a power grid or a sub-part thereof. For example, as Figure 1 As illustrated schematically, the power system may include primary components such as power transformer 21, switching device 22 (such as circuit breaker or switch), renewable energy sources 24, 25 (which can be connected to the power system bus via an inverter), energy storage system (such as battery energy storage system 23), or time-coupled equipment (such as charging station 26).

[0179] However, the techniques disclosed herein are not limited to power systems and can also be applied to automated control systems used in conjunction with other infrastructure systems, such as hydraulic or pneumatic systems. The techniques disclosed herein can also be used in conjunction with industrial automation control.

[0180] Figure 2A block diagram representation of an FLM system 80 is shown. The FLM system 80 includes at least one (i.e., one or more) FLM system interfaces 81. At least one FLM system interface 81 is operable to output first data 88 defining a set of devices to be updated. The first data 88 may optionally include an estimated update duration. The FLM system 80 is operable to send the first data to a SCADA system 60. At least one FLM system interface 81 is operable to receive second data 69, and the FLM system 80 is operable to use the second data 69 to establish a sequence (and optionally a specific time) in which devices communicatively coupled to the SCADA system 60 will be updated. At least one FLM system interface 81 is operable to receive the second data 69 from the SCADA system 60. At least one FLM system interface 81 is operable to generate and output a command 89 to trigger devices communicatively coupled to the SCADA system 60 (and communicatively coupled to the FLM system 80) to perform updates, for example by retrieving firmware updates and / or initiating a firmware update installation process.

[0181] The FLM system 80 may optionally include a human-machine interface (HMI). The FLM system 80 is operable to allow information generated based on second data to also be output via the HMI.

[0182] FLM system 80 may include FLM storage system 82. FLM storage system 82 may store data or metadata related to available updates (such as metadata defining the size of each update), data specifying the currently installed firmware version on each device, and / or data specifying the device's hardware configuration and / or hardware usage. FLM storage system 82 may also store data about historical update processes (such as historical update durations stored in association with the update data size and / or hardware configuration of the device where the update was installed), which FLM system 80 can use to determine the expected update duration using techniques such as regression (such as multiple regression). FLM system 80 is also operable to store data related to the update progress of initiated updates in FLM storage system 82. FLM system 80 is operable to provide SCADA system 60 with information related to triggered update processes, for example, by notifying SCADA system 60 of completed update processes and / or newly installed firmware versions.

[0183] The FLM system 80 includes one or more FLM processing circuits 83.

[0184] One or more FLM processing circuits 83 are operable to perform device identification 84. Device identification 84 is operable to determine a set of devices to be updated. Therefore, at least one FLM processing circuit 83 is operable to determine either the devices to be updated or a set of devices comprising those communicatively coupled to the SCADA system 60. At least one FLM processing circuit 83 is operable to access data stored in the FLM or storage system 82, such as data defining the currently installed firmware version and data defining available firmware updates, to determine the set of devices. At least one FLM processing circuit 83 is optionally operable to use historical information stored on the FLM storage system 82 to determine the expected update duration.

[0185] One or more FLM processing circuits 83 are operable to execute FLM interface control 86. FLM interface control 86 can operate in response to the result of device identification 84. FLM interface control 86 is operable to control at least one FLM system interface 81 to generate first data 88, which includes identifiers of all devices in the identified device set (i.e., for the device to be updated) or other information defining the devices in the identified device set. FLM interface control 86 can control at least one FLM system interface 81 such that the first data 88 additionally includes the expected update duration. The expected update duration may vary for different device types, device hardware configurations, or currently installed firmware versions. The expected update duration can be determined using regression techniques (such as multiple regression) or other techniques based on the size of the update to be installed, the hardware configuration of the device to which the update is to be installed, and the update duration, update size, and hardware configuration of historical updates that have been successfully completed.

[0186] The FLM interface control 86 is also operable to control at least one FLM interface 81 to receive and process second data 69 from the SCADA system 60. At least one FLM processing circuit 83 is operable to process the second data 69 to establish a sequence of devices included in the updated device set. This may include ongoing processes in which different subsets of the device set are identified when a new message is received from the SCADA system 60 among multiple messages included in the second data 69.

[0187] At least one FLM processing circuit 83 is operable to execute an update trigger 85 to trigger an update of a device to be updated, such as triggering the retrieval of update data and / or the installation of an update. The update trigger 85 may be implemented in response to second data 69 received from the SCADA system. For example, the update trigger 85 may generate a command to trigger an update process for a subset of the device set, defined by the second data 69 (such as messages among the multiple messages forming the second data 69). The update trigger 85 may control the FLM interface control 86, which in turn may cause the FLM system interface or interface 81 to output command 89 to trigger an update process in at least one subset of the device set.

[0188] At least one FLM processing circuit 83 is optionally operable to perform update monitoring 87. Update monitoring 87 may be based on progress reports received from the device to be updated. Update monitoring 87 may include checking and confirming the successful completion of the update installation and / or recording the update duration. This information may be aggregated by the FLM system 80. At least a portion of the aggregated information, i.e., data derived from the received set of reports, may be stored in the FLM storage system 82 for later use. The FLM system 80 may use the update reports to notify the SCADA system 60 of successfully implemented firmware updates and / or to improve the model for predicting the installation duration of future updates.

[0189] At least one FLM processing circuit 83 may include, but is not limited to, any or any combination of integrated circuits, integrated semiconductor circuits, processors, controllers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), circuits including qubits and / or quantum gates.

[0190] Figure 3 A block diagram representation of SCADA system 60 is shown.

[0191] SCADA system 60 includes at least one SCADA system interface 61. The at least one SCADA system interface 61 is operable to receive first data 88 defining a set of devices to be updated. The first data 88 may optionally include an estimated update duration. SCADA system 60 is operable to receive the first data 88 from FLM system 80. The at least one SCADA system interface 61 is operable to output second data 69 to FLM system 80. The second data 69 may define a subset of devices to be updated, for example, in the form of an ordered list. The ordered list may be included in several messages contained in the second data 69 and output by SCADA system 60 in chronological order.

[0192] SCADA system 60 may optionally include human-machine interface (HMI) 62. SCADA system 60 is operable such that information related to an update sequence, such as information about devices updated as a group within a given time interval, can be output via HMI 62.

[0193] SCADA system 60 may include SCADA storage system 63. SCADA storage system 63 may store the operating status of devices communicatively coupled to SCADA system 60. SCADA storage system 63 may store information about redundant implementations of functions performed by the devices (if any) and their operating status (i.e., whether the redundant implementation is running). SCADA storage system 63 may also store information about primary equipment, such as the status of switching devices (e.g., circuit breaker status), the position of (one or more) tap changers, transformer status, etc. Such data can be obtained from measuring instruments or inferred from measurement results or IEC 61850 compliance messages.

[0194] SCADA system 60 includes one or more processing circuits 64. The one or more processing circuits 64 are operable to perform at least one update sequence determination 70 to determine, based on received first data 88 and operational data available to the SCADA system (such as data in SCADA storage system 63), which devices, specified by the first data 88, will be updated at what time. In determining which devices, specified by the first data 88, will be updated at what time, SCADA system 60 may consider one or both of the device's criticality to system safety and the device's operational status. For example, SCADA system 60 may define a subset of devices based on whether the devices are in a field operation state that is not fully operational (such as a maintenance mode that is significantly different from a fully operational field operation state) and / or whether all safety-critical functions performed by the devices have redundant implementations, where the redundant implementations are operational (i.e., not in a state where there is no guarantee that they will be successfully put into operation as needed). Devices in maintenance mode and devices with redundant implementations of all safety-critical functions may be included in the subset of devices for which FLM system 80 can initiate an update process. The update sequence determination 70 enables the SCADA interface control 65 to generate and output a message of second data 69 via at least one SCADA system interface 61, which defines a subset that can trigger the update process.

[0195] The SCADA system 60 can use additional or alternative technologies to determine which devices will be updated and when. The SCADA system 60 is specifically operable to perform processing associated with the processing system disclosed in Hitachi Energy Switzerland's patent application EP23177537.0, filed June 6, 2023, entitled "METHOD AND PROCESSING SYSTEM FOR CONTROLLING A TRANSFER AND / OR AMODIFICATION OF MACHINE-READABLE DATA PROCESSED BY DEVICES OF AN AUTOMATIONCONTROL SYSTEM, AND METHOD OF CONTROLLING AN INFRASTRUCTURE SYSTEM".

[0196] For example, the update sequence determination 70 is operable to process time series of generator unit commitment and load data to predict generator unit commitment and load power within a predicted time range. Based on the predicted generator unit commitment and load power, the update sequence determination 70 can determine the timing of modifications to various devices in a manner that performs modifications (e.g., software or firmware updates) at regular intervals, wherein the generator unit commitment and load power predicted at those intervals within the predicted time range indicate that the corresponding devices can be decommissioned from their normal full operating state without compromising the operational safety of the primary system 20.

[0197] The updated sequence determination 70 is operable to perform forecasting using at least one trained machine learning (ML) model. Relevant techniques for processing time series of observations into time series of forecast values ​​are available to those skilled in the art. For example, a recurrent neural network architecture can be used. The ML model may include one or more units, such as Long Short-Term Memory (LSTM) units (e.g., a stack of LSTM units), to process time series of observations into time series of forecast values ​​for generator unit combinations and / or load power.

[0198] One or more SCADA processing circuits 64 are operable to perform SCADA interface control 65 in response to a determined update sequence. SCADA interface control 65 is operable to control at least one SCADA system interface 61 based on the determined update sequence and / or the command sequence determined by command sequence determination 75.

[0199] One or more SCADA processing circuits 64 are operable to perform command sequence determination 75 based on received first data 69 and system operations of the automation control system 40 available to the SCADA system 60 (e.g., in the SCADA storage system 63). Command sequence determination 75 may include determining a sequence of control actions to be performed by the SCADA system 60 in a manner coordinated with an update process triggered by the FLM system 80. The sequence of control actions may include commands to place the device in maintenance mode, allow firmware updates to be installed on the device if the device is determined to be non-critical (e.g., because all safety-related functions have redundant implementations), and return the device to its normal full operating mode after a successful firmware update (this may be reported to the SCADA system 60 by the FLM system 80). The sequence of control actions may include control actions affecting the primary system (i.e., not limited to the secondary system).

[0200] At least one processing circuit 64 is operable to store a report on the updated performance in the SCADA system storage device 63 for future use. For example, during field use of the SCADA system 70, the update sequence determination 70 can be continuously updated based on the performance reports received and stored in the SCADA system storage device 63. The performance reports can be received from the FLM system 80.

[0201] At least one processing circuit 64 may include, but is not limited to, any one or any combination of integrated circuits, integrated semiconductor circuits, processors, controllers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), circuits including qubits and / or quantum gates.

[0202] Figure 4 This is a block diagram representation of the implementation of update sequence determination 70. Update sequence determination can be implemented such that the device to be updated is identified based on the device's operational state (e.g., whether the device is currently in maintenance mode) and / or based on whether there are redundant implementations of the device's safety-critical functions (for devices that are not critical to system safety operation in other respects at a given time). Update sequence determination may include device status check 71. Device status check 71 is operable to access the device operational states of those devices included in the device set of devices to be updated determined by FLM system 80.

[0203] The update sequence determination may include a criticality check 72. The criticality check 72 may determine which devices among those designated by the FLM system 80 as devices to be updated are considered non-safety critical. The criticality check 72 may be implemented by checking whether all safety-critical functions of the devices have redundant implementations in other devices, or may include checking these functions.

[0204] The update sequence determination may include a scheduler 73 that determines which devices among those identified as pending updates will be updated and at what time. Scheduler 73 may include a grouping process 74 that groups devices into subsets. For example, when scheduler 73 is invoked, grouping process 74 may identify all devices currently in maintenance mode or not currently safety-critical. Information about subsets including these identified devices may be provided to trigger the update process. Scheduler 73 may be invoked repeatedly, for example, intermittently (periodically or aperiodically), until all devices specified in the first data 88 have been processed.

[0205] Figure 5 This is a flowchart of method 90. Method 90 can be executed automatically by the FLM system 80.

[0206] In process block 91, the FLM system 90 determines a set of devices, or a set of devices comprising all devices for which firmware updates (or other machine-readable code updates) are available. Process block 91 may also include the FLM system 90 determining the expected update duration for the devices.

[0207] In process block 92, the FLM system 90 generates first data for all devices in the defined device set and provides the first data to the SCADA system 60. The first data may also include an indicator of the expected update duration.

[0208] In process block 93, FLM system 90 receives second data from SCADA system 60. The second data may include one or more messages, each defining at least a subset of the device. Optionally, the second data may also include timing information specifying when to initiate the update process.

[0209] In process block 94, FLM system 90 establishes a time series (in which various devices of the device set will be updated) and initiates the update process according to the established sequence.

[0210] Figure 6 This is a flowchart of method 100. Method 100 can be executed automatically by the SCADA system 60.

[0211] In process block 101, SCADA system 60 receives first data from FLM system. The first data indicates all devices to be updated included in the device set determined by FLM system 80. The first data may also optionally include the expected update duration for the devices included in the device set.

[0212] In process block 102, the SCADA system 60 determines the sequence of equipment updates. The SCADA system can also determine a sequence of control actions to be executed in an interleaved manner with the update process. The determination at process block 102 can be performed based on equipment status information, such as the equipment's operating status and / or the presence of any running redundant functions. The determination at process block 102 can also be performed based on primary equipment data, such as, but not limited to, one or more of, current, voltage, or PMU measurements, circuit breaker and / or other switchgear status, tap changer position, transformer conditions, generator unit configuration, and load level.

[0213] In process block 103, SCADA system 60 generates at least one message. The at least one message is sent to FLM system 80. This at least one message identifies at least one subset of the device set specified by the first data.

[0214] In process block 104, the SCADA system 60 coordinates with the update process of at least one device specified in a message to execute control actions. Control actions may include controlling some or all of a subset of devices to enter maintenance mode. Control actions may include, after a successful update installation, controlling some or all of the subset of devices to return from maintenance mode to full operation mode. Control actions may include commands to change the state of primary system components, such as power system components, e.g., switchgear, transformers, and / or other primary system components. Therefore, the primary system may be affected, allowing the devices controlled by the SCADA system to be safely updated.

[0215] In process block 105, the SCADA system determines whether any devices have not yet been addressed. This may include comparing the union of all identified subsets with the device set specified by the first data. If all devices have been addressed, the method ends in process block 106. Otherwise, the method may return to process block 103.

[0216] Figure 7 This is a block diagram of device 110. The configuration of device 110 can be used for some or all of the devices in the automation control system 40.

[0217] Device 110 includes a device interface 111 operable to receive machine-readable data. The machine-readable data may include software or firmware updates persistently stored in device memory 112 of device 110. Instruction code 113 may be stored in device memory 112.

[0218] Device 110 includes one or more device circuits 114. The one or more device circuits 114 are operable to perform control and / or monitoring functions associated with primary system components of primary system 20. The one or more device circuits 114 are operable to cause the control and / or monitoring functions to process measured values ​​(such as measured values ​​of electrical characteristics or quantities derived therefrom) to determine control actions to be performed on the primary system components. In one implementation, the control and / or monitoring functions may include protection functions, such as distance protection functions. In this case, the control action may include switching device tripping, such as circuit breaker tripping or switch tripping. In another implementation, the control and / or monitoring functions are operable to control a tap changer. In the latter case, the control action may include changing the position of the tap changer.

[0219] Typically, device 110 can execute logic to process measurements obtained from primary system 20 into control actions for primary system 20 or one of its components. This logic can be defined by instruction code 113 stored in device memory 112.

[0220] One or more device circuits 114 are operable to execute updater 116. Updater 116 is operable to modify instruction code 113 based on received machine-readable data. Updater 116 is operable to trigger an update process according to an update sequence determined by SCADA system 60 communicating with FLM system 80. Device 110 is operable to receive command 89 from FLM system 80. Updater 116 is operable to retrieve firmware update data and / or install firmware update data in response to command 89. Command 89 may also include a start time, at which updater 116 is operable to begin the update process. Therefore, the start time is controlled by FLM system 80 communicating with SCADA system 60.

[0221] One or more device circuits 114 may include any or any combination of the following: integrated circuits, integrated semiconductor circuits, processors, controllers, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), circuits including qubits and / or quantum gates, but not limited thereto.

[0222] Figure 8This is a schematic diagram further explaining and illustrating the operation of the method and system according to the embodiments. Multiple devices 120 are communicatively coupled to SCADA system 60. FLM system 80 determines a device set 121 of devices to be updated. This determination may include checking which devices are eligible for an updated firmware version. SCADA system 60 or FLM system 80 may determine different subsets 122, 123, 124 of devices, where all devices in any subset are operational and / or have criticality allowing them to be jointly updated. SCADA system 60 may provide messages to FLM system 80, each message relating to one (and only one) subset. FLM system may trigger an update process for the corresponding device subset in response to the receipt of a message.

[0223] The communication interaction between the FLM system 80 and the SCADA system 60 ensures the availability of critical and operational status information as input to the firmware update process. The techniques disclosed herein integrate firmware updates with operations performed by the SCADA system 60. This process can be implemented in several ways. In one implementation, the FLM system 80 sends the set of devices S requiring firmware updates to the SCADA system 60, along with the estimated duration for which the updates will be applied to each device. The SCADA system 60 determines the update sequence and a list of control actions. For example, low-criticality devices (such as standby and idle relays) are updated first. The update sequence can be or may include a list of device subsets S1, S2, ..., Sn, which are partitions of the device set S. The list of control actions C1, C2, ..., Cn may include or consist of operations performed by the SCADA system 60 and interleaved with the update process. For example, the FLM system 80 and the SCADA system 60 can be operated such that the entire process will first update the devices in the device subset S1, then the SCADA system 60 executes command C1, then the devices in the device subset S2 are updated, and so on. SCADA system 60 can send a command to the devices in the currently updated subset Si to enter maintenance mode, where i is between 1 and n. This is not necessary for devices already in maintenance mode. SCADA notifies FLM system 80 what subset Si of devices is ready for update in the current cycle. FLM system 80 triggers firmware updates for these devices. The devices apply the firmware update (e.g., by retrieval and / or installation). These devices report the update results to FLM system 80. FLM system 80 can collect the update results from the updated devices. FLM system 80 can report to SCADA system 60 that the current update cycle has been successfully completed. SCADA system 60 can send commands to the updated devices and set them to active mode. Finally, SCADA system 60 can execute command Ci on the system to enable the updated devices and disable the devices to be updated in the next cycle. Commands can also trigger control actions that act on the system.

[0224] This technology ensures that the device receiving the firmware update does not affect the operation of the power system during the update process. Furthermore, the functional separation between the FLM system 80 and the SCADA system 60 is maintained, which is beneficial from a safety perspective.

[0225] Figure 9 It is a signaling diagram of a system 130 that includes a SCADA system 60, an FLM system 80, and a device 120 that is communicatively coupled to the SCADA system 60.

[0226] The technology disclosed in this article utilizes the following aspects of various components: The SCADA system 60 can be operated to control critical equipment and set the equipment to maintenance / activity mode. In maintenance mode, the SCADA system 60 recognizes that the equipment may be unresponsive or unfunctional for a period of time due to the installation of firmware updates.

[0227] The FLM system 80 is operable to provide initial data defining a list of devices requiring firmware updates, and an estimate of the update duration for each device. The FLM system 80 is operable to trigger an update process. The FLM system 80 is operable to monitor and collect the results of the update process.

[0228] Device 120 is operable to be controlled by SCADA system 60 and to receive firmware updates from FLM system 80.

[0229] System 130 can be operated as follows: FLM system 80 sends first data 131 to SCADA system 60, including the set S of devices to be updated and the estimated update duration for each device. The estimated duration may simply be the time required to switch from the old version to the new version, or it may include the time required to download the new version to the device.

[0230] At point 132, considering the set S of target devices to be updated and the estimated update duration, the SCADA system 60 determines the update sequence. The update sequence may include, or may be, a list of subsets S1, S2, ..., Sn and a list of control actions C1, C2, ..., Cn. The actions explained in references 133-141 are executed n times (i is between 1 and n), meaning these actions are performed for each subset of devices.

[0231] The SCADA system 60 sends command 133 to the devices in subset Si to put them into maintenance mode. Such commands must not be sent to devices already in maintenance mode.

[0232] The SCADA system 60 sends a message of second data 134 or second data to the FLM system 80, which defines the subset of devices Si that are ready to be updated in this cycle.

[0233] FLM system 80 receives a subset of devices Si available for this cycle and triggers a firmware update process. This may include the transmission of command 135.

[0234] The target device receives trigger command 135 from FLM system 80 and performs the update installation at process block 136.

[0235] These devices can report the status and results of their update process to the FLM system 80. This may include receiving reports 137 from a subset of devices that are updating in the current cycle.

[0236] In process block 138, the FLM system 80 can collect update results from devices that are updated in the current cycle. The FLM system 80 can aggregate reports for further use, such as storing them in history and / or predicting update times.

[0237] If all devices have successfully completed the firmware update, the FLM system 80 sends message 139 to the SCADA system 60, indicating that the devices in this cycle have successfully completed the update.

[0238] The SCADA system 60 sends command 140 to the updated device and sets it back to active mode.

[0239] The SCADA system 60 executes a control action Ci (e.g., opening / closing a circuit breaker), which enables the operation of the updated device in Si and disables the operation of the device in the next cycle (Si+1).

[0240] SCADA system 60 can determine the device subset and update sequence in various ways. SCADA system 60 is operable to determine the update sequence based on the set of devices to be updated and the expected update duration for each device. The update sequence defines the devices to be updated in each update cycle. The update sequence may also accompany or include a list of commands executed by SCADA system 60 after each update cycle. Commands are not limited to those operating on the devices to be updated, but may also include commands affecting the primary system (such as those by operating switchgear, transformers, energy storage systems (ESS), tap changers).

[0241] The technologies that SCADA systems can implement are as follows: SCADA system 60 is operable to utilize redundancy (e.g., dual busbars) in the power system. SCADA system 60 can decide to first update devices in backup mode (e.g., S1 is the set of devices in backup mode). Next, SCADA system 60 is operable to switch the busbar to redundant mode and allow updates to devices in primary mode (e.g., C1 activates backup mode and disables primary mode, S2 is the set of devices in primary mode). Finally, SCADA system 60 is operable to change back to operating primary mode (e.g., C2 activates primary mode and disables backup mode). Generating a redundancy-based update sequence can be performed automatically using a SCADA model. Generating a redundancy-based update sequence may include control HMI 62 enabling operator input to determine the redundancy-based update sequence.

[0242] Alternatively or additionally, the SCADA system 60 is operable to monitor the operating status of equipment. The SCADA system 60 is operable to allow currently inactive equipment (e.g., with zero current) to be included in the first update cycle (i.e., S1). The SCADA system 60 is operable to allow remaining equipment to be sorted based on current and to define a threshold for the current. Once the current of equipment falls below the threshold, it will be considered for the next update cycle. For equipment that never falls below the threshold, the SCADA system 60 can define the maintenance interval (using an update duration estimate) when these devices are updated.

[0243] Alternatively or additionally, the SCADA system 60 may operate such that, for at least some devices, the SCADA system 60 decides not to proactively execute control actions to disable these devices, but instead waits for certain planned control actions (e.g., planned maintenance). Once these planned control actions disable the target devices, the SCADA system 60 puts these devices into maintenance mode and notifies the FLM system 80 that these devices are ready for an update (e.g., as in a regular update cycle). The advantage of this approach is that it reduces the number of control actions required to update the entire fleet by utilizing planned control actions. This technique is suitable for situations where firmware updates for the entire fleet are not time-critical for all devices and for some devices, they can be postponed until planned control actions.

[0244] Figure 10 This is a flowchart of method 150, which can be automatically executed by the FLM system 80. Figure 10 In the second data 89 received by the FLM system from the SCADA system, there are individual messages received in chronological order, each message being associated with a subset of devices.

[0245] Process blocks 91 and 92 can be combined as follows Figure 5 The aforementioned implementation.

[0246] In process block 151, FLM system 80 receives a message from SCADA system 60 that notifies FLM system 80 that the device subset is ready for updating.

[0247] In process block 152, the FLM system 80 initiates an update process for the devices of the subset of devices specified by the received message. This may include generating and issuing commands that cause the devices of the subset to retrieve and / or install update data.

[0248] In process block 153, FLM system 80 determines whether all devices in the device set identified at 91 have been updated. If all devices in the device set have been updated, the method ends in process block 154. Otherwise, FLM system 80 continues to monitor for further messages from SCADA system 60, which notify FLM system 80 of at least one further subset of devices from which the update process can begin.

[0249] In combination Figures 2 to 10 In the discussed techniques, the FLM system 80 and the SCADA system 60 interact, allowing the SCADA system 60 to use device status and / or criticality to determine an appropriate update sequence based on data available to or at the SCADA system 60. In other implementations, the FLM system 80 and SCADA system 60 may interact in such a manner that the FLM system 80 retrieves data from the SCADA system suitable for determining the update sequence. This will refer to... Figures 11 to 13 To provide a more detailed explanation.

[0250] Figure 11 A variant of the FLM system 80 is shown. Components operable as previously described are indicated by the same reference numerals. The FLM system 80 is operable to perform at least update sequence determination 70. To determine the update sequence (which may include determining an ordered list of subsets of devices in a set of devices to be updated), the FLM system 80 may request second data 159 from the SCADA system 60, which includes SCADA data related to the operational status and / or criticality of the devices. Update sequence determination 70 may use this SCADA system data as previously described (e.g., by organizing the device set into subsets based on criticality and / or operational status). Optionally, although... Figure 11 Although not shown, the FLM processing circuit 83 is operable to execute at least a portion of the command sequence determination 75. The FLM system 80 is operable to generate and output at least one message to notify the SCADA system of the determined update sequence, and, if determined by the FLM system 80, to notify the determined command / control action sequence. In another implementation, the command sequence determination 75 can still be executed by the SCADA system 60 using the update sequence determined by the FLM system 80.

[0251] Figure 12 This is the signaling diagram for system 160, which includes SCADA system 60, FLM system 80, and device 120 communicatively coupled to SCADA system 60. When the minimum update sequence is determined to be performed by FLM system 80 using SCADA data retrieved from SCADA system 60, Figure 12 The signaling diagram is applicable. Then, system 130 can operate as follows: The FLM system 80 sends first data 161, which includes the set of devices S to be updated, to the SCADA system 60. The estimated update duration for each device can be included in the first data 131, but is not required.

[0252] The FLM system 80 receives second data 163 from the SCADA system 60, which includes operational status and / or other relevant information, such as information about the implementation of critical or redundant functions of the equipment. The SCADA system 60 may provide the second data in response to the first data 161.

[0253] In step 163, considering the set S of target devices to be updated and the estimated update duration, the FLM system 80 determines the update sequence. The update sequence may include or may be a list of subsets S1, S2, ..., Sn.

[0254] The FLM system 80 provides at least one update sequence 164 to the SCADA system 60. The FLM system, or preferably the SCADA system 60, can determine a list of control actions C1, C2, ..., Cn.

[0255] Then, the actions explained earlier regarding 133-141 can be executed n times (i is between 1 and n), that is, these actions are performed for each subset of devices. For the implementation of these processing and signaling operations, please refer to the explanation provided above.

[0256] Figure 13 This is a flowchart of method 170, which can be automatically executed by the FLM system 80. Figure 13 In the process, the second data 89 received by the FLM system from the SCADA system includes SCADA system data, and then the FLM system 80 uses the SCADA system data to determine the update sequence.

[0257] Process blocks 91 and 92 can be combined as follows Figure 5 To achieve it as described.

[0258] In process block 93, FLM system 80 receives second data from SCADA system 60, which includes SCADA data for determining the update sequence. The SCADA data may include the operational status of the device to be updated and / or primary system components associated with the device.

[0259] In process block 171, the FLM system 80 uses SCADA system data received from the SCADA system 60 to determine the update sequence. The determined update sequence may take into account system criticality, such as the redundancy that may exist in the automation control system and / or primary system. Criticality may also depend on the status of primary equipment (such as current, power flow, switch status, tap changer status).

[0260] In process block 172, the FLM system 80 provides at least the determined update sequence to the SCADA system 60. The SCADA system 60 can use the update sequence determined by the FLM system 80 to determine the control actions to be performed to modify equipment and optional primary system components, such as switching devices.

[0261] In process block 94, the FLM system 80 initiates the device update process according to the determined update sequence. This may include generating and issuing commands that cause a subset of devices to retrieve and / or install update data.

[0262] In any of the implementations discussed herein, the FLM system 80 and / or SCADA system 60 are operable such that logic (such as update sequence determination 70 and / or command sequence determination 75) can be adjusted during field operation of the FLM system 80 and SCADA system 60. This allows for modification of the logic based on field observations related to the update process, thereby further improving update control and system operation.

[0263] Figure 12 This is a schematic representation of one or more processing circuits that can be implemented in the FLM system 80 and / or the SCADA system 60. One or more processing circuits 64, 83 are operable to execute at least one piece of logic to control the update process of a device communicatively interfaced with the SCADA system 60. The at least one piece of logic may include update sequence determination 70 and / or command sequence determination 75.

[0264] At least one processing circuit 64, 83 is operable to perform update performance monitoring 127 to monitor update performance. Update performance monitoring may include monitoring the update duration for installing the update.

[0265] At least one processing circuitry 64, 83 is operable to execute a scheduler logic modification 128, which modifies the logic executed to determine the update sequence and / or command sequence. For example, the scheduler logic modification is operable to retrain an artificial intelligence (AI) model using update performance data associated with update metadata (such as update data size), the model being logically used to predict update duration. The AI ​​model may have inputs operable to receive update metadata and device hardware data (such as CPU-related data), and outputs operable to provide the predicted update duration.

[0266] This logic can process measurements 180 obtained in system 20 to determine update sequences and / or command sequences. Measurements may include measurements of electrical characteristics. Measurements can be obtained using measuring instruments such as one or more phasor measurement units (PMUs) 181, one or more current transformers 11, and / or one or more voltage transformers 12. In one specific implementation already discussed, current measurements obtained by the phasor measurement units 181 and / or current transformers 11 can be used to determine the sequence of devices to be updated.

[0267] While these methods and systems have been described in detail above with reference to automated control systems for power systems, these technologies are not limited thereto. For example, these methods and systems can also be applied to other infrastructure systems, including other critical infrastructure systems such as freshwater supply, heating fluid distribution, natural gas or oil distribution, or other distribution networks.

[0268] Figure 15 System 190 is schematically shown, which includes an infrastructure system that includes hydraulic components such as a pump 191 driven by an electric motor 192 and a controllable valve 193.

[0269] The automated control system includes several devices 194 and 196 associated with the primary system equipment. The SCADA system 60 and the FLM system 80 are operable to control the updates of devices 194 and 196 in a manner that takes into account the operating status and / or criticality.

[0270] The techniques disclosed herein are generally operable to improve the process of updating devices that are communicatively coupled to and controlled by a SCADA system. Therefore, updates can be achieved in a more secure and timely manner. This also improves the operation of the devices and the primary systems associated with them. Therefore, the techniques disclosed herein also extend to methods and systems for operating infrastructure systems or other primary systems with the aid of automated control systems that include the devices.

[0271] Figure 16 This is a flowchart of method 200 according to an embodiment. Method 200 can be executed automatically by a system including SCADA system 60, FLM system 80, and device 120.

[0272] In process block 201, the FLM system 80 and the SCADA system 60 interface with each other to determine the timing of the update process that triggers device 120.

[0273] In process block 202, the FLM system 80 controls the update process. The SCADA system 60 can operate in conjunction with the FLM system 80 by setting device 120 to maintenance mode and / or controlling switching devices or other primary system equipment.

[0274] In process block 203, the device that updates according to the received and installed updates performs protection functions or other control functions related to the primary system. This may include controlling primary system components, such as switching devices.

[0275] According to an embodiment, a processing system is provided that allows the FLM system 80 to interact with the SCADA system 60 to handle firmware or software update processes for distributed and fault-tolerant systems in safety-critical applications such as power substations and power systems.

[0276] Various effects and advantages are achieved through the systems and methods according to the embodiments. These systems and methods provide enhanced techniques for updating devices communicatively coupled to SCADA systems. Therefore, the systems and methods according to the embodiments address the need for automated update processes for potentially large fleets of equipment in the context of digitalization and cybersecurity risks, a critical function for the future power systems industry. These systems and methods help ensure that the latest security patches and features are deployed to field devices in a timely and effective manner.

[0277] Although embodiments have been described in detail with reference to the accompanying drawings, various modifications may be made in other embodiments. This is for illustrative purposes and not for limitation: • While an embodiment in which the device may be an IED operating according to IEC 61850 has been described, the techniques disclosed herein can be used in conjunction with a fleet of other devices in an automated control system.

[0278] • While embodiments in which devices can be operated to perform protective functions such as distance protection have been described, these technologies can also be used in conjunction with a fleet of devices that perform other functions, such as control functions other than distance protection. Examples include energy management systems (EMS) or power management systems (PMS) associated with a power grid with renewable energy sources.

[0279] • While embodiments of updating firmware or software in a device have been described, these techniques can also be used to adjust other settings that affect device operation. For example, these techniques can be used to control the transmission and / or modification of setpoints of the EMS and / or PMS or the logic performed by them.

[0280] The embodiments can be used in conjunction with grids that have renewable energy penetration, such as grids that include renewable energy systems (such as DER), but are not limited thereto.

[0281] This specification and the accompanying drawings illustrating aspects and embodiments of the invention should not be construed as limiting the scope of the claims. In other words, while the invention has been detailed and described in the accompanying drawings and the foregoing description, such description should be considered illustrative rather than restrictive. Various mechanical, compositional, structural, electrical, and operational changes may be made without departing from the spirit and scope of this specification and the claims. In some cases, well-known circuits, structures, and techniques have not been shown in detail so as not to obscure the invention. Therefore, it should be understood that those skilled in the art can make changes and modifications within the scope and spirit of the appended claims. In particular, the invention covers other embodiments having any combination of features of the different embodiments described above and below.

[0282] This disclosure also covers all other features shown individually in the accompanying drawings, although they may not be described in the preceding or following description. Furthermore, individual alternatives to the embodiments described in the drawings, and the descriptions of their features, may be excluded from the subject matter of this invention or the disclosed subject matter. This disclosure includes the subject matter consisting of the features defined in the claims or embodiments, as well as the subject matter including said features.

[0283] The term "comprising" does not exclude other elements or process blocks, and the indefinite articles "a" or "an" do not exclude multiple. A single unit or process block can perform the functions of several features described in the claims. The fact that certain measures are referenced in mutually different dependent claims does not mean that a combination of these measures cannot be advantageous. Components described as coupled or connected can be directly electrically or mechanically coupled, or indirectly coupled through one or more intermediate components. Any reference signs in the claims should not be construed as limiting the scope.

[0284] Machine-readable instruction code can be stored / distributed on suitable media, such as optical storage media or solid-state media provided with or as part of other hardware, but can also be distributed in other forms, such as via wide area networks or other wired or wireless telecommunications systems. Furthermore, machine-readable instruction code can also be a data structure product or a signal used to embody a particular method, such as the method according to an embodiment.

Claims

1. A method for controlling the updating of machine-readable data processed by a device (41-46; 120), the device being communicatively coupled to a monitoring and data acquisition SCADA system (60), the method comprising: The device set (121) of the device is determined by the cluster management FLM system (80), wherein the device set (121) includes the device to be updated; The FLM system (80) interfaces with the SCADA system (60) to establish an update sequence for devices included in the device set (121); Based on the established update sequence, the FLM system (80) triggers an update process for devices included in the device set (121).

2. The method according to claim 1, wherein, The update sequence is established by the FLM system (80) communicating with the SCADA system (60), including: The FLM system (80) generates first data including information about the device to be updated, which is included in the device set (121); The first data is output by the FLM system (80) through at least one data interface; The FLM system (80) receives second data from the SCADA system (60) through the at least one data interface, the second data including information about at least one subset (122-124) of the device set (121); and The update sequence is established by the FLM system (80) based on the second data.

3. The method according to claim 2, wherein, The first data includes identifiers for all devices to be updated.

4. The method according to claim 2 or 3, wherein, The first data includes the expected update duration.

5. The method according to any one of claims 2 to 4, wherein, The second data defines an ordered list of several subsets (122-124) of the devices to be updated to determine the update sequence.

6. The method according to claim 5, wherein, The second data includes multiple messages received from the SCADA system (60), wherein each message defines a subset of the subsets (122-124).

7. The method according to claim 6, wherein, Receiving one of the multiple messages causes the FLM system (80) to trigger an update process for a subset (122-124) defined by the message.

8. The method according to any one of the preceding claims, wherein, The update sequence is determined by the FLM system (80) which communicates with the SCADA system (60), including determining which of the devices to be updated will remain in maintenance mode for at least one expected update duration.

9. The method according to any one of the preceding claims, wherein, The update sequence is determined by the FLM system (80) which communicates with the SCADA system (60), including determining which of the devices to be updated have redundant implementations of all safety-critical functions performed by the respective devices.

10. The method according to any one of the preceding claims, wherein, The update sequence is established through the communication interface between the FLM system (80) and the SCADA system (60), including: The FLM system (80) retrieves device status data for devices included in the device set (121) from the storage system of the SCADA system (60) or from a storage system accessible to the SCADA system (60). The FLM system (80) establishes the update sequence based on the retrieved device status data.

11. The method according to any one of the preceding claims, further comprising: The FLM system (80) receives the update report through the at least one data interface; as well as The FLM system (80) provides the SCADA system (60) with an aggregated update report, which is formed by aggregating the received update reports.

12. The method according to any one of the preceding claims, wherein, The update sequence is automatically determined by the FLM system (80) that cooperates with the SCADA system (60).

13. The method according to any one of the preceding claims, wherein, The equipment includes an automated control system (40).

14. The method according to claim 13, wherein, The automated control system (40) includes a power system automated control system, and wherein the equipment includes the equipment of the power system automated control system.

15. The method according to any one of the preceding claims, wherein, The update includes a firmware update.

16. A cluster management FLM system (80) for controlling updates of machine-readable data processed by devices (41-46; 120), said devices being communicatively coupled to a monitoring and data acquisition SCADA system (60), said FLM system (80) comprising: At least one data interface (81); as well as At least one processing circuit (83) operates as follows: Determine the device set (121) of the device, wherein the device set (121) includes the device to be updated; Control the at least one data interface (81) to communicate between the FLM system (80) and the SCADA system (60) to establish an update sequence for the devices included in the device set (121); The update process for devices included in the device set (121) is triggered according to the established update sequence.

17. The FLM system (80) according to claim 16, configured to perform the method as described in any one of claims 1 to 15.

18. An electric power system, comprising: An automated control system (40) includes multiple devices (41-46) that operate to process machine-readable data; 120); The monitoring and data acquisition SCADA system (60) is communicatively coupled to the plurality of devices (41-46; 120); and The FLM system (80) according to claim 16 or 17 is configured to be communicatively coupled to the SCADA system (60).

19. The power system according to claim 18, in, The FLM system (80) operates as follows: Generate first data including information about the device to be updated, which is included in the device set (121). The first data is transmitted to the SCADA system (60). Receive second data from the SCADA system (60), the second data including information about several subsets (122-124) of the device set (121), and The update sequence is established based on the second data; and The SCADA system (60) operates as follows: Receive the first data, Based on the information about the device to be updated contained in the first data, device status data for at least the device to be updated is retrieved. Based on the device status data, several subsets (122-124) of the device set (121) are determined to specify the update sequence. Based on the determined subsets (122-124), the second data is generated, and, The second data is transmitted to the FLM system (80).

Citation Information

Patent Citations

  • Updating of trade software and / or of configurations of equipment of an electrical distribution network

    EP3631745A1

  • Automatic firmware updates for intelligent electronic devices

    US8892699B2