Cloud-based plant-level dcs unified monitoring system and method
By constructing a cloud-native plant-level DCS unified monitoring system, adopting a private cloud layered network architecture and service trust calculation model, and combining LSTM data analysis technology, the system solves the problems of data silos and security in smart power plants, and realizes unified, secure, and intelligent monitoring and operation and maintenance of power plants.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SOUTHWEST ELECTRIC POWER DESIGN INST OF CHINA POWER ENG CONSULTING GROUP CORP
- Filing Date
- 2026-03-24
- Publication Date
- 2026-05-22
AI Technical Summary
Existing technologies are insufficient to achieve unified processing and intelligent analysis of large-scale, multi-source heterogeneous data in smart power plants. Traditional DCS systems are closed and suffer from severe information silos. Public cloud platforms are unable to meet the needs of power plants in terms of data privacy protection and system security, and cannot support a highly secure, highly reliable, and customizable cloud platform architecture.
We build a cloud-native factory-level DCS unified monitoring system, adopting a private cloud layered network architecture and service trust calculation model, combined with LSTM data analysis technology with attention mechanism, to achieve unified and intelligent data collection, preprocessing, security monitoring and remote operation.
It enables unified access to data and secure and controllable remote monitoring in smart power plants, improving the reliability, safety and operation and maintenance efficiency of power plant operation, breaking the information silos and security limitations of traditional systems, and supporting a highly secure and efficient cloud platform architecture.
Smart Images

Figure CN121906779B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and more specifically, to a cloud-native factory-level DCS unified monitoring system and method. Background Technology
[0002] With the deepening of industrial digital transformation, smart power plants have become an important direction for the development of the power industry. Currently, smart power plants mostly rely on traditional distributed control systems (DCS) to monitor and manage the power production process. Meanwhile, to cope with data growth and processing demands, some solutions are attempting to introduce cloud computing technology, with public cloud platforms gaining attention due to their elastic scalability and cost advantages. Furthermore, related technologies such as artificial intelligence, edge computing, and virtualization are being gradually applied to data analysis, real-time response, and resource optimization to help improve the operating efficiency and automation level of power plants.
[0003] However, the aforementioned existing technical solutions still have significant shortcomings: traditional DCS systems are relatively closed in architecture, resulting in problems such as decentralized equipment management, information silos, and difficulties in data integration, making it difficult to support the unified processing and intelligent analysis of large-scale, multi-source heterogeneous data; while public cloud-based platforms offer a certain degree of flexibility and scalability, they struggle to meet power plants' requirements for controlling core production data in terms of data privacy protection, system security, and compliance. Furthermore, existing systems still have limitations in real-time performance, reliability, and cross-network layer collaboration, failing to fully support the urgent needs of smart power plants for a highly secure, highly reliable, and customizable cloud platform architecture. Therefore, there is an urgent need for a platform architecture that can deeply integrate the security advantages of private clouds with the real-time control capabilities of DCS to drive the development of smart power plants towards a safer, more efficient, and intelligent direction. Summary of the Invention
[0004] The purpose of this application is to overcome the shortcomings of existing technologies and provide a cloud-native unified monitoring system and method for plant-level DCS. By constructing a cloud-native platform that integrates a private cloud layered network architecture and a service trustworthiness calculation model, and combining it with LSTM data analysis technology with an attention mechanism, the application solves the challenges faced by smart power plants in terms of data silos, information security, and system reliability, and realizes unified, secure, and intelligent monitoring and operation and maintenance of plant-level DCS systems.
[0005] The objective of this application is achieved through the following technical solution:
[0006] Firstly, embodiments of this application propose a cloud-native, factory-level DCS unified monitoring system, including:
[0007] The data acquisition and preprocessing module is used to collect real-time operating data of power plant equipment through sensors, and to preprocess, compress and convert the acquired data.
[0008] The private cloud platform network architecture module includes a field control layer, a unit DCS network layer, and an ICS network layer connected in sequence. The field control layer is used for remote and on-site data acquisition and monitoring; the unit DCS network layer is used for real-time monitoring and management of the cloud computing center, and to realize log auditing, unified security management and network intrusion detection; the ICS network layer is used to realize intelligent advanced control, data platform, intelligent applications and one-way isolation from the intranet.
[0009] The boundary security protection module is located between the private cloud platform network architecture module and the external Internet. It is used to define the Internet boundary zone, perform attack detection and VPN access policies, and connect to the internal core zone through the firewall to deploy application servers in the isolation zone.
[0010] The data analysis and intelligent processing module is deployed in the private cloud platform network architecture module. It is used to receive and store data from the data acquisition and preprocessing module. It evaluates the credibility of the data source based on the service credibility calculation model with adaptive adjustment of reward and punishment factors, and uses a long short-term memory network with fused attention mechanism to analyze and model the credible data, obtain the operating rules and provide predictive maintenance decision support.
[0011] The unified monitoring and remote operation module provides a web user interface for operators to monitor various operating indicators and statuses of the power plant in real time, and supports remote adjustment of equipment parameters and execution of control commands through the interface. The unified monitoring and remote operation module also includes an operation command security verification unit, which is used to initiate a real-time query of data source credibility to the data analysis and intelligent processing module before executing remote operations, and can only issue commands after obtaining a credibility score higher than a preset threshold, and all commands are attached with digital signatures based on national cryptographic algorithms.
[0012] In one possible implementation, the software layer of the private cloud platform network architecture module is deployed in a cluster, and the cluster is configured with multiple fault domains, the number of fault domains being... satisfy: ,in This represents the maximum number of nodes that the cluster can tolerate failing simultaneously.
[0013] The cluster is based on Kubernetes orchestration and achieves physical isolation of fault domains through PodAntiAffinity and topology distribution constraints.
[0014] In one possible implementation, the boundary security protection module also performs:
[0015] The domain authorization mechanism performs security logic verification on access requests;
[0016] Real-time system monitoring function to track and detect data within the network;
[0017] A multi-dimensional file security analysis mechanism that uses a combination of static and dynamic methods to make security judgments;
[0018] The real-time system risk assessment function uses cloud data collection to dynamically assess the security status and automatically adjust firewall policies based on the assessment results.
[0019] In one possible implementation, the credibility calculation model used by the data analysis and intelligent processing module is as follows:
[0020]
[0021]
[0022] in As a comprehensive credibility index for the service, These are the weighting coefficients. To ensure service credibility based on historical rewards and penalties, Based on the instantaneous credibility of the current evidence, For reward parameters, For penalty parameters, For the number of qualified service sessions, The number of times the test was unsuccessful; the reward parameter. and penalty parameters Adaptive adjustments are made based on the distribution of historical data, ensuring the service maintains high reliability over a long period. Decrease to avoid overconfidence;
[0023] The data analysis and intelligent processing module is also used to evaluate the credibility of the data acquisition service using a credibility calculation model. The credibility calculation model is as follows: and ,in As a comprehensive credibility index for the service, To ensure the compatibility of new evidence with the given assumptions, Indicates time The credibility of prior services at that time Indicates the probability of evidence. The probability of the service completing the task. For reward parameters, For the qualified quantity, For penalty parameters, The quantity is non-compliant.
[0024] In one possible implementation, the data analysis and intelligent processing module uses a distributed storage system to store real-time and historical data, and establishes a hierarchical index based on the time-series characteristics of the data.
[0025] In one possible implementation, the data platform in the ICS network layer is connected to the power plant management information network through a one-way isolation shutter. The analysis results output by the data platform can only be pushed to the management network unidirectionally through the shutter, while the management network cannot initiate any reverse connection. At the same time, the data platform dynamically generates isolation strategies based on asset importance and distributes them to the one-way isolation device.
[0026] In one possible implementation, the reward and penalty parameters in the credibility calculation model are dynamically adjusted using the model gradients uploaded by each node under the federated learning framework, thereby achieving global credibility optimization while protecting data privacy.
[0027] In one possible implementation, step S1 involves acquiring real-time operating data from the device via sensors, and then performing preprocessing, compression, and format conversion.
[0028] Step S2: Construct a private cloud platform and transmit the preprocessed data to the private cloud platform. The network architecture of the private cloud platform includes the field control layer, the unit DCS network layer, and the ICS network layer.
[0029] Step S3: Implement security protection strategies at the boundary between the private cloud platform and the Internet. The security protection strategies include attack detection, access control, and deployment of isolated zones through firewalls, and dynamically adjust the strategies based on real-time risk assessments.
[0030] Step S4: The private cloud platform receives and stores data, evaluates the credibility of the data source based on the service credibility calculation model with adaptive adjustment of reward and punishment factors, and cleans, analyzes and models the credible data using an LSTM network with fusion attention mechanism, and performs operational status analysis and predictive maintenance.
[0031] Step S5: Provide a real-time unified monitoring view of the power plant's operating status through the Web interface. When a remote operation request is received, first query the data analysis and intelligent processing module for the overall credibility of the current data source. If it is higher than the threshold, the operation is allowed. At the same time, generate a national cryptographic digital signature and attach it to the instruction. Finally, issue the instruction through the secure channel and record the log.
[0032] In one possible implementation, in step S2, the private cloud platform deploys a software service cluster containing multiple fault domains. The number N of fault domains in the cluster satisfies: N ≥ 2m + 1, where m is the maximum number of nodes that the cluster can tolerate to fail simultaneously. Fault domain isolation is achieved through Kubernetes' PodAntiAffinity and topology distribution constraints.
[0033] In one possible implementation, the security protection strategy also includes: a domain name authorization mechanism to perform security logic verification on access requests; a real-time system monitoring function to track and discover data within the network; a multi-dimensional file security analysis mechanism to make security judgments using a combination of static and dynamic methods; and a real-time system risk assessment function to achieve dynamic assessment of security status through cloud data collection.
[0034] The main solution and its various further alternative solutions described above can be freely combined to form multiple solutions, all of which are solutions that can be adopted and claimed in this application.
[0035] This application discloses a cloud-native plant-level DCS unified monitoring system and method, relating to the field of cloud computing technology. The system includes a data acquisition and preprocessing module for collecting and preprocessing real-time data from power plant equipment; a private cloud platform network architecture module employing a layered architecture of field control layer, unit DCS network layer, and ICS network layer to achieve data acquisition, security monitoring, and intelligent applications; a boundary security protection module defining Internet boundary zones and isolation zones to ensure external access security; a data analysis and intelligent processing module evaluating data sources based on a service credibility calculation model with adaptive adjustment of reward and punishment factors, and using an LSTM network with an attention mechanism to analyze and model trusted data, providing predictive maintenance decisions; and a unified monitoring and remote operation module providing a web interface, where all operation commands undergo real-time credibility verification and digital signature dual verification. This invention achieves unified access, intelligent analysis, and secure and controllable remote monitoring of power plant operation data, improving the reliability, security, and operational efficiency of power plant operations. Attached Figure Description
[0036] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0037] Figure 1 A schematic diagram of the cloud-native factory-level DCS unified monitoring system architecture proposed in this application embodiment is shown. Detailed Implementation
[0038] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application.
[0039] Please refer to Figure 1 The cloud-native factory-level DCS unified monitoring system proposed in this application includes:
[0040] The data acquisition and preprocessing module is used to collect real-time operating data of power plant equipment through sensors, and to preprocess, compress and convert the acquired data.
[0041] The private cloud platform network architecture module includes a field control layer, a unit DCS network layer, and an ICS network layer connected in sequence. The field control layer is used for remote and on-site data acquisition and monitoring; the unit DCS network layer is used for real-time monitoring and management of the cloud computing center, and to realize log auditing, unified security management and network intrusion detection; the ICS network layer is used to realize intelligent advanced control, data platform, intelligent applications and one-way isolation from the intranet.
[0042] The boundary security protection module is located between the private cloud platform network architecture module and the external Internet. It is used to define the Internet boundary zone, perform attack detection and VPN access policies, and connect to the internal core zone through the firewall to deploy application servers in the isolation zone.
[0043] The data analysis and intelligent processing module is deployed in the private cloud platform network architecture module. It is used to receive and store data from the data acquisition and preprocessing module. It evaluates the credibility of the data source based on the service credibility calculation model with adaptive adjustment of reward and punishment factors, and uses a long short-term memory network with fused attention mechanism to analyze and model the credible data, obtain the operating rules and provide predictive maintenance decision support.
[0044] The unified monitoring and remote operation module provides a web user interface for operators to monitor various operating indicators and statuses of the power plant in real time, and supports remote adjustment of equipment parameters and execution of control commands through the interface. The unified monitoring and remote operation module also includes an operation command security verification unit, which is used to initiate a real-time query of data source credibility to the data analysis and intelligent processing module before executing remote operations, and can only issue commands after obtaining a credibility score higher than a preset threshold, and all commands are attached with digital signatures based on national cryptographic algorithms.
[0045] Data Acquisition and Preprocessing Module: Deployed on the field equipment side, this module acquires analog and digital signals such as temperature, pressure, and vibration via various protocols including Modbus, OPC UA, and IEC 61850. The module incorporates a data cleaning engine, employing median filtering and density-based anomaly detection algorithms to remove noise. Subsequently, it uses the LZ4 algorithm for rapid compression and converts the data to Apache Avro format to ensure compatibility with the data access specifications of the upper-layer cloud platform.
[0046] Private cloud platform network architecture module: adopts a three-layer physical isolation design:
[0047] Field control layer: Composed of RTU, PLC and edge intelligent gateway, it performs closed-loop control and data aggregation, and supports Modbus / TCP and MQTT protocol conversion.
[0048] The DCS network layer of the generator set deploys a virtualized server cluster, running a real-time database (such as the PI System) and a security management platform. The software layer of the private cloud platform network architecture module adopts a cluster deployment, with multiple fault domains configured. satisfy: ,in This represents the maximum number of nodes that the cluster can tolerate failing simultaneously.
[0049] The cluster is based on Kubernetes orchestration and achieves physical isolation of fault domains through PodAntiAffinity and topology distribution constraints.
[0050] This layer manages containerized applications using Kubernetes, and the number of fault domains N configured in the cluster satisfies N ≥ 2m + 1. For example, if it is necessary to tolerate the simultaneous failure of 2 nodes (m=2), then at least 5 fault domains must be deployed. Kubernetes' PodAntiAffinity rules ensure that replicas of the same service are distributed across different fault domains, and topology distribution constraints force Pods to be distributed across different racks or physical nodes, thereby preventing service interruptions caused by single points of failure.
[0051] The data platform in the ICS network layer is connected to the power plant management information network through a one-way isolation shutter. The analysis results output by the data platform can only be pushed to the management network in one direction through the shutter, and the management network cannot initiate any reverse connection. At the same time, the data platform dynamically generates isolation strategies based on asset importance and distributes them to the one-way isolation device.
[0052] ICS Network Layer: Deploys a data platform (based on the Hadoop / Spark ecosystem) and intelligent application containers. The data platform cleanses, correlates, and models the lower-layer data, forming data services such as asset ledgers and equipment health status. This layer connects to the power plant management information network via a physical unidirectional isolation shutter (such as FerretGuard). Any requests from the management network cannot pass through the shutter; only the data platform is allowed to proactively push reports or alarm information to the management network. Simultaneously, the data platform dynamically configures isolation policies based on asset importance (e.g., generators and transformers are primary assets), and distributes these policies to the shutter via API to achieve dynamic access control.
[0053] Boundary security protection module: Deployed at the internet egress point, employing a next-generation firewall (NGFW) and intrusion prevention system (IPS). The module implements domain-based access control, allowing only specific domains (such as...) The .dcs-monitor.plant file is approved and TLS fingerprint verification is performed; static feature scanning and dynamic sandbox execution are performed on uploaded files to identify unknown malware; by continuously collecting network traffic and logs, the system security risks are assessed using a hidden Markov model, and when the risk score exceeds the threshold, the firewall policy is automatically tightened (such as blocking high-risk IPs).
[0054] The credibility calculation model used in the data analysis and intelligent processing module is as follows:
[0055] ;
[0056] ;
[0057] in As a comprehensive credibility index for the service, These are the weighting coefficients. To ensure service credibility based on historical rewards and penalties, Based on the instantaneous credibility of the current evidence, For reward parameters, The penalty parameter is Nq, where Nq is the number of successful service attempts. The number of times the test was unsuccessful; the reward parameter. and penalty parameters Adaptive adjustments are made based on the distribution of historical data, ensuring the service maintains high reliability over a long period. Decrease to avoid overconfidence;
[0058] The data analysis and intelligent processing module is also used to evaluate the credibility of the data acquisition service using a credibility calculation model. The credibility calculation model is as follows: and ,in As a comprehensive credibility index for the service, To ensure the compatibility of new evidence with the given assumptions, Indicates time The credibility of prior services at that time Indicates the probability of evidence. The probability of the service completing the task. For reward parameters, For the qualified quantity, For penalty parameters, The quantity is non-compliant.
[0059] The data analysis and intelligent processing module uses a distributed storage system to store real-time and historical data, and establishes a hierarchical index based on the time-series characteristics of the data.
[0060] The data analysis and intelligent processing module uses the distributed time-series database InfluxDB to store raw and feature data. The credibility calculation engine receives real-time status feedback from the data acquisition service (such as response time and data integrity verification results), and calculates the credibility based on the formula... The overall credibility of each data source is dynamically updated. The update introduces a reward and penalty mechanism: for each successful data report (data passes verification and latency is less than 50ms). Add 1; for reports that fail or data is tampered with, Add 1. The initial values of the reward parameter α and the penalty parameter β are 0.1 and 0.2, respectively. After 100 consecutive successful service runs, α decays exponentially to 0.01 to avoid over-rewarding.
[0061] The reward and penalty parameters in the credibility calculation model are dynamically adjusted through the model gradients uploaded by each node under the federated learning framework, thereby achieving global credibility optimization while protecting data privacy.
[0062] Furthermore, the system introduces a federated learning framework, where each unit's DCS layer acts as a local node. Without uploading the original data, it only encrypts and uploads the gradient of the credibility model, which is then aggregated by the central parameter server and distributed for updates, thereby achieving cross-unit credibility collaborative optimization.
[0063] Instantaneous credibility The calculation involves extracting multiple quality metrics (such as timestamp deviation, rate of change of values, and residuals with predicted values) for each data packet and constructing a feature vector. Based on the distribution of historical normal data, Mahalanobis distance is used to calculate the distance between the current feature vector and the center of the normal distribution. This distance is then mapped to the [0,1] interval using the sigmoid function as the compatibility score. This method can quickly detect transient anomalies in data quality.
[0064] Before collecting data, the data analysis and intelligent processing module needs to use a credibility calculation model to assess the credibility of the data collection service. The credibility calculation model is as follows: and ,in As a comprehensive credibility index for the service, To ensure the compatibility of new evidence with the given assumptions, Indicates time The credibility of prior services at that time Indicates the probability of evidence. The probability of the service completing the task. For reward parameters, For the qualified quantity, For penalty parameters, The quantity is non-conforming. When... This indicates that the service is completely trustworthy. This indicates that the service is being used by a malicious attacker, according to... The value determines whether the service can be trusted and whether the collected data is real.
[0065] Machine learning modeling: For data with a confidence level higher than 0.85, an LSTM network is used for prediction. The network input is a sequence of key parameters from the past 24 hours (such as bearing temperature and vibration amplitude), and the output is the probability of failure in the next 4 hours. An attention mechanism is superimposed after the LSTM layer to automatically learn the contribution weights of different time steps to the prediction result. The model is trained offline using historical failure data, with cross-entropy as the loss function and Adam as the optimizer. The trained model is deployed in a containerized manner on the ICS network layer, periodically reading real-time data streams and outputting prediction results to a unified monitoring interface. For example, when the predicted failure probability of the coal mill exceeds 70%, the system highlights an alarm on the monitoring interface and provides suggested maintenance windows.
[0066] The unified monitoring and remote operation module features a responsive web interface developed using Vue.js and ECharts, communicating with the backend service in real-time via WebSocket. Operational personnel must undergo multi-factor authentication (password + hardware token + biometrics) to log in. When remote operation is required (e.g., adjusting valve opening), the operation command is first sent to the "Operation Command Security Verification Unit." This unit queries the trustworthiness calculation engine for the overall trustworthiness of the relevant data sources (e.g., the sensor and actuator corresponding to the valve). Only when the trustworthiness of all relevant sources is higher than the threshold of 0.9 is further allowed. Subsequently, the system uses the national cryptographic SM2 algorithm to digitally sign the command content (including the operation object, target value, timestamp, and operator ID), appends the signature to the command, and sends it to the field control layer via an encrypted MQTT over TLS channel. Upon receiving the command, the field control layer verifies the signature. If verification is successful, the command is executed and the result is returned. The entire process is recorded in the blockchain audit log to ensure immutability.
[0067] The boundary security protection module also performs:
[0068] The domain name authorization mechanism performs security logic verification on access requests;
[0069] Real-time system monitoring function to track and discover data within the network;
[0070] A multi-dimensional file security analysis mechanism that uses a combination of static and dynamic methods to make security judgments;
[0071] The real-time system risk assessment function uses cloud data collection to dynamically assess the security status and automatically adjust firewall policies based on the assessment results.
[0072] The boundary security protection module integrates a dynamic and precise intrinsic security system. It implements precise access control and security logic verification based on domain names, accounts, and API interfaces, and possesses real-time system monitoring capabilities for full traffic, continuously tracking and detecting anomalies in network data. Simultaneously, the module employs a multi-dimensional file security analysis mechanism combining static and dynamic metrics, significantly improving the overall accuracy of malicious file identification.
[0073] The boundary security protection module further utilizes cloud data collection and correlation analysis to achieve real-time system risk assessment and dynamically quantify the platform's security posture. Based on the assessment results, its predictive security model can automatically generate defense and response strategies, shifting the security mode from passive response to proactive early warning, effectively reducing operational complexity and costs while improving overall protection levels.
[0074] In another possible embodiment, this application also proposes a cloud-native factory-level DCS unified monitoring method, which is applied to the above-mentioned system and includes:
[0075] Step S1: Collect real-time operating data of the device through sensors, and perform preprocessing, compression and format conversion;
[0076] Step S2: Construct a private cloud platform and transmit the preprocessed data to the private cloud platform. The network architecture of the private cloud platform includes the field control layer, the unit DCS network layer, and the ICS network layer.
[0077] Step S3: Implement security protection strategies at the boundary between the private cloud platform and the Internet. The security protection strategies include attack detection, access control, and deployment of isolated zones through firewalls, and dynamically adjust the strategies based on real-time risk assessments.
[0078] Step S4: The private cloud platform receives and stores data, evaluates the credibility of the data source based on the service credibility calculation model with adaptive adjustment of reward and punishment factors, and cleans, analyzes and models the credible data using an LSTM network with fusion attention mechanism, and performs operational status analysis and predictive maintenance.
[0079] Step S5: Provide a real-time unified monitoring view of the power plant's operating status through the Web interface. When a remote operation request is received, first query the data analysis and intelligent processing module for the overall credibility of the current data source. If it is higher than the threshold, the operation is allowed. At the same time, generate a national cryptographic digital signature and attach it to the instruction. Finally, issue the instruction through the secure channel and record the log.
[0080] In one possible implementation, in step S2, the private cloud platform deploys a software service cluster containing multiple fault domains. The number N of fault domains in the cluster satisfies: N ≥ 2m + 1, where m is the maximum number of nodes that the cluster can tolerate to fail simultaneously. Fault domain isolation is achieved through Kubernetes' PodAntiAffinity and topology distribution constraints.
[0081] In one possible implementation, the security protection strategy also includes: a domain name authorization mechanism to perform security logic verification on access requests; a real-time system monitoring function to track and discover data within the network; a multi-dimensional file security analysis mechanism to make security judgments using a combination of static and dynamic methods; and a real-time system risk assessment function to achieve dynamic assessment of security status through cloud data collection.
[0082] Compared with existing technologies, this application has the following disruptive effects:
[0083] 1. For the first time, a credibility calculation model with adaptive adjustment of reward and punishment factors and federated learning optimization was introduced into the plant-level DCS, which transformed the data source evaluation from static configuration to dynamic self-learning, fundamentally solving the "dirty data" problem caused by sensor drift or attacks, and ensuring the input quality of upper-level intelligent analysis.
[0084] 2. By linking the data platform with the one-way isolation light gate, dynamic arrangement of security policies is realized, breaking the dilemma of the traditional industrial control system that "security and openness" cannot be achieved at the same time. It not only ensures the absolute isolation of the core production area, but also enables the management network to obtain analysis results in real time, providing a secure channel for intelligent decision-making.
[0085] 3. By employing an LSTM network with a fusion attention mechanism to predict trusted data, and combining real-time trust verification before operation with national cryptographic digital signatures, a complete security closed loop from data collection and analysis to remote control is constructed. This upgrades the power plant's operation and maintenance mode from passive response to proactive prediction and secure and controllable remote intervention, significantly improving the system's reliability and operation and maintenance efficiency.
[0086] In summary, this application solves a core problem in the field of industrial control through specific technical means, and has outstanding substantive features and significant progress.
Claims
1. A cloud-native, factory-level DCS unified monitoring system, characterized in that: include: The data acquisition and preprocessing module is used to collect real-time operating data of power plant equipment through sensors, and to preprocess, compress and convert the acquired data. The private cloud platform network architecture module includes a field control layer, a unit DCS network layer, and an ICS network layer connected in sequence. The field control layer is used for remote and on-site data acquisition and monitoring; the unit DCS network layer is used for real-time monitoring and management of the cloud computing center, and to realize log auditing, unified security management and network intrusion detection; the ICS network layer is used to realize intelligent advanced control, data platform, intelligent applications and one-way isolation from the intranet. The boundary security protection module is located between the private cloud platform network architecture module and the external Internet. It is used to define the Internet boundary zone, perform attack detection and VPN access policies, and connect to the internal core zone through the firewall to deploy application servers in the isolation zone. The data analysis and intelligent processing module is deployed in the private cloud platform network architecture module. It is used to receive and store data from the data acquisition and preprocessing module. It evaluates the credibility of the data source based on the service credibility calculation model with adaptive adjustment of reward and punishment factors, and uses a long short-term memory network with fused attention mechanism to analyze and model the credible data, obtain the operating rules and provide predictive maintenance decision support. The credibility calculation model used in the data analysis and intelligent processing module is as follows: in As a comprehensive credibility index for the service, These are the weighting coefficients. To ensure service credibility based on historical rewards and penalties, Based on the instantaneous credibility of the current evidence, For reward parameters, For penalty parameters, For the number of qualified service sessions, The number of times the test was unsuccessful; the reward parameter. and penalty parameters Adaptive adjustments are made based on the distribution of historical data, ensuring the service maintains high reliability over a long period. Decrease to avoid overconfidence; The data analysis and intelligent processing module is also used to evaluate the credibility of the data acquisition service using a credibility calculation model. The credibility calculation model is as follows: and ,in As a comprehensive credibility index for the service, To ensure the compatibility of new evidence with the given assumptions, Indicates time The credibility of prior services at that time Indicates the probability of evidence. The probability of the service completing the task. For reward parameters, For the qualified quantity, For penalty parameters, The quantity is non-compliant; The unified monitoring and remote operation module provides a web user interface for operators to monitor various operating indicators and statuses of the power plant in real time, and supports remote adjustment of equipment parameters and execution of control commands through the interface. The unified monitoring and remote operation module also includes an operation command security verification unit, which is used to initiate a real-time query of data source credibility to the data analysis and intelligent processing module before executing remote operations, and can only issue commands after obtaining a credibility score higher than a preset threshold, and all commands are attached with digital signatures based on national cryptographic algorithms.
2. The plant-level DCS unified monitoring system as described in claim 1, characterized in that, The software layer of the private cloud platform's network architecture module is deployed in a cluster, with multiple fault domains configured. satisfy: ,in This represents the maximum number of nodes that the cluster can tolerate failing simultaneously. The cluster is based on Kubernetes orchestration and achieves physical isolation of fault domains through PodAntiAffinity and topology distribution constraints.
3. The plant-level DCS unified monitoring system as described in claim 1, characterized in that, The boundary security protection module also performs: The domain authorization mechanism performs security logic verification on access requests; Real-time system monitoring function to track and detect data within the network; A multi-dimensional file security analysis mechanism that uses a combination of static and dynamic methods to make security judgments; The real-time system risk assessment function uses cloud data collection to dynamically assess the security status and automatically adjust firewall policies based on the assessment results.
4. The plant-level DCS unified monitoring system as described in any one of claims 1 to 3, characterized in that, The data analysis and intelligent processing module uses a distributed storage system to store real-time and historical data, and establishes a hierarchical index based on the time-series characteristics of the data.
5. The plant-level DCS unified monitoring system as described in claim 1, characterized in that, The data platform in the ICS network layer is connected to the power plant management information network through a one-way isolation shutter. The analysis results output by the data platform can only be pushed to the management network in one direction through the shutter, and the management network cannot initiate any reverse connection. At the same time, the data platform dynamically generates isolation strategies based on asset importance and distributes them to the one-way isolation device.
6. The plant-level DCS unified monitoring system as described in claim 1, characterized in that, The reward and penalty parameters in the credibility calculation model are dynamically adjusted through the model gradients uploaded by each node under the federated learning framework, thereby achieving global credibility optimization while protecting data privacy.
7. A cloud-native, factory-level DCS unified monitoring method, characterized in that, The method is applied to the system according to any one of claims 1 to 6, comprising: Step S1: Collect real-time operating data of the device through sensors, and perform preprocessing, compression and format conversion; Step S2: Construct a private cloud platform and transmit the preprocessed data to the private cloud platform. The network architecture of the private cloud platform includes the field control layer, the unit DCS network layer, and the ICS network layer. Step S3: Implement security protection strategies at the boundary between the private cloud platform and the Internet. The security protection strategies include attack detection, access control, and deployment of isolated zones through firewalls, and dynamically adjust the strategies based on real-time risk assessments. Step S4: The private cloud platform receives and stores data, evaluates the credibility of the data source based on the service credibility calculation model with adaptive adjustment of reward and punishment factors, and cleans, analyzes and models the credible data using an LSTM network with fusion attention mechanism, and performs operational status analysis and predictive maintenance. Step S5: Provide a real-time unified monitoring view of the power plant's operating status through the Web interface. When a remote operation request is received, first query the data analysis and intelligent processing module for the overall credibility of the current data source. If it is higher than the threshold, the operation is allowed. At the same time, generate a national cryptographic digital signature and attach it to the instruction. Finally, issue the instruction through the secure channel and record the log.
8. The plant-level DCS unified monitoring method as described in claim 7, characterized in that, In step S2, a software service cluster containing multiple fault domains is deployed on the private cloud platform. The number of fault domains N in the cluster satisfies: N ≥ 2m + 1, where m is the maximum number of nodes that the cluster can tolerate to fail simultaneously. Fault domain isolation is achieved through Kubernetes' PodAntiAffinity and topology distribution constraints.
9. The plant-level DCS unified monitoring method as described in claim 7, characterized in that, Security protection strategies also include: a domain name authorization mechanism to perform security logic verification on access requests; a real-time system monitoring function to track and discover data within the network; a multi-dimensional file security analysis mechanism that uses a combination of static and dynamic methods to make security judgments; and a real-time system risk assessment function that uses cloud data collection to achieve dynamic assessment of security status.