A method and system for remotely accessing a plurality of field sites of an oil rig

CN122718331APending Publication Date: 2026-09-08SICHUAN HONGHUA ELECTRIC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610887342.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-18
Publication Date
2026-09-08

AI Technical Summary

Technical Problem

[0005]本发明提供一种石油钻机多现场远程控制接入方法及系统,以至少解决多个石油钻机现场采用相同网段或相同设备地址时,在云端远程控制接入过程中容易产生地址冲突、设备身份冲突和访问路径混淆的问题

Benefits of technology

[0008] The beneficial effects of this invention are as follows: It proposes a method and system for remote control access to multiple oil drilling rig sites. By acquiring site access information of multiple oil drilling rig sites, a unique VPN identifier is assigned to each site. Based on the site identifier, VPN identifier, and real local address, a virtual logical address is generated in the cloud to form a cloud mapping table. After the remote control terminal sends an access request, the cloud performs a reverse mapping based on the target site identifier and the target virtual logical address to determine the target VPN identifier and the target real local address, and forwards the request to the target device through the corresponding VPN link. This invention can achieve parallel access, unified identification, unified access, and on-demand remote control of multiple sites on the same network segment while keeping the original site address planning and control procedures basically unchanged.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122718331A_ABST
    Figure CN122718331A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of remote control of oil drilling rigs, and discloses a multi-site remote control access method and system for oil drilling rigs, which obtains site access information of multiple oil drilling rig sites, allocates a unique VPN identifier to each site, generates a virtual logical address in the cloud based on the site identifier, the VPN identifier and the real local address, and forms a cloud mapping table; after a remote control end sends an access request, the cloud performs reverse mapping according to the target site identifier and the target virtual logical address, determines the target VPN identifier and the target real local address, and forwards the request to the target device through the corresponding VPN link; the present application can realize parallel access, unified identification, unified access and on-demand remote control of multiple sites in the same network segment while keeping the original address planning and control program of the site unchanged.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of remote control technology for oil drilling rigs, and in particular to a method and system for multi-site remote control access of oil drilling rigs. Background Technology

[0002] Oil drilling rig sites typically include a variety of equipment such as drilling rig electrical control systems, PLC controllers, frequency converters, remote I / O, sensors, actuators, video monitoring devices, industrial control computers, and field switching equipment. During drilling operations, these devices need to perform functions such as hoisting, rotation, circulation, solids control, alarms, status acquisition, and safety interlocking according to the field control program. With the increasing demand for centralized monitoring, remote diagnostics, remote debugging, and remote operation and maintenance of drilling operations, multiple oil drilling rig sites need to be connected to a remote control platform simultaneously, enabling the remote control center to uniformly monitor, access, and take over different well sites or drilling rig sites as needed. In actual engineering deployments, different oil drilling rig sites often use the same or similar network segment planning, equipment addresses, and program structures due to reasons such as project replication, standardized implementation, on-site maintenance habits, and control program reuse. For example, PLC master stations in different well sites may all use 192.168.1.10 as their local address, and frequency converters, remote I / O, or industrial control computers in different sites may also use the same address range. While this deployment method facilitates on-site debugging, spare parts replacement, and program reuse, it can easily lead to network address conflicts, device identity conflicts, and remote access confusion at the cloud access level when multiple sites are connected to the remote control platform simultaneously.

[0003] In existing technologies, to avoid address conflicts when multiple sites connect, common methods include replanning site network addresses, modifying communication addresses in the PLC program, reconfiguring site routing devices, or significantly altering the site network structure. However, these methods significantly increase site deployment costs and debugging workload, and may affect the stable operation of the existing control system. Especially in oil drilling rig sites, site network addresses are often associated with PLC programs, industrial computer configurations, inverter communication parameters, HMI screen variables, and alarm logic. Frequent modifications to the local address system for remote access can easily lead to inconsistent program parameters, communication anomalies, or disruption of on-site personnel's operating habits. Furthermore, while some remote access solutions can achieve connection between a single site and the remote terminal via VPN, it remains difficult to uniformly identify devices with the same address across different sites when multiple sites share the same network segment or device address. If the remote terminal directly accesses the device using the actual local address, it cannot reliably distinguish which oil drilling rig site the address corresponds to, easily leading to access errors or confusion of controlled objects. For access scenarios that only require monitoring, this problem may manifest as misreading of status data; for online downloads or remote control scenarios, this problem may lead to higher risks.

[0004] Therefore, how to achieve parallel access, unified identification, unified access and on-demand remote control of multiple sites on the same network segment while keeping the original site address planning and control procedures basically unchanged is a technical problem that urgently needs to be solved in the field of remote control access for oil drilling rigs. Summary of the Invention

[0005] This invention provides a method and system for remote control access to multiple oil drilling rigs at multiple sites, which at least solves the problems of address conflicts, device identity conflicts and access path confusion that easily occur during remote control access in the cloud when multiple oil drilling rigs use the same network segment or the same device address.

[0006] To achieve the above objectives, the present invention provides a method for remote control access to multiple sites of an oil drilling rig, the method comprising the following steps: Obtain field access information for multiple oil drilling rig sites; wherein, the field access information includes at least the site identifier, the actual local address of the equipment within the site, and the field access link information; Based on the field access information, a unique VPN identifier is assigned to each oil drilling rig site, and a binding relationship is established between the site identifier and the corresponding VPN identifier. Based on the site identifier, the VPN identifier, and the real local address, a virtual logical address corresponding to the device in the site is generated in the cloud, and a cloud mapping table is formed to describe the correspondence between the site identifier, the VPN identifier, the virtual logical address, and the real local address. Receive a remote access request sent by a remote control terminal, and determine the corresponding target VPN identifier and target real local address from the cloud mapping table based on the target site identifier and target virtual logical address in the remote access request; Based on the target VPN identifier, the remote access request is forwarded via the corresponding VPN link to the target device with the target's real local address at the target oil drilling rig site, and the response data of the target device is sent back to the remote control terminal.

[0007] To achieve the above objectives, the present invention also provides a multi-site remote control access system for oil drilling rigs, comprising: The acquisition module is used to acquire field access information of multiple oil drilling rig sites; wherein, the field access information includes at least the site identifier, the real local address of the equipment in the site, and the field access link information; A module is established to assign a unique VPN identifier to each oil drilling rig site based on the site access information, and to establish a binding relationship between the site identifier and the corresponding VPN identifier. The forming module is used to generate a virtual logical address corresponding to the device in the field in the cloud based on the field identifier, the VPN identifier and the real local address, and to form a cloud mapping table for describing the correspondence between the field identifier, the VPN identifier and the virtual logical address and the real local address; The determination module is used to receive remote access requests sent by the remote control terminal, and determine the corresponding target VPN identifier and target real local address from the cloud mapping table based on the target site identifier and target virtual logical address in the remote access request. The forwarding module is used to forward remote access requests via the corresponding VPN link to the target device with the target's real local address at the target oil drilling rig site based on the target VPN identifier, and to send the target device's response data back to the remote control terminal.

[0008] The beneficial effects of this invention are as follows: It proposes a method and system for remote control access to multiple oil drilling rig sites. By acquiring site access information of multiple oil drilling rig sites, a unique VPN identifier is assigned to each site. Based on the site identifier, VPN identifier, and real local address, a virtual logical address is generated in the cloud to form a cloud mapping table. After the remote control terminal sends an access request, the cloud performs a reverse mapping based on the target site identifier and the target virtual logical address to determine the target VPN identifier and the target real local address, and forwards the request to the target device through the corresponding VPN link. This invention can achieve parallel access, unified identification, unified access, and on-demand remote control of multiple sites on the same network segment while keeping the original site address planning and control procedures basically unchanged. Attached Figure Description

[0009] Figure 1 This is a flowchart illustrating the multi-site remote control access method for oil drilling rigs proposed in this embodiment of the invention. Figure 2 This is a schematic diagram of the data flow for performing reverse mapping of remote access requests in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of the multi-site remote control access system for oil drilling rigs proposed in this embodiment of the invention. Detailed Implementation

[0010] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0011] This invention provides a method for remote control access to multiple sites of an oil drilling rig, referring to... Figure 1 In this embodiment, a method for remote control access to multiple sites of an oil drilling rig includes the following steps: S1: Obtain field access information for multiple oil drilling rig sites; wherein, the field access information includes at least the site identifier, the actual local address of the equipment within the site, and the field access link information.

[0012] Specifically, the field access information includes at least a field identifier, the actual local address of the equipment within the field, and field access link information. The field identifier is used to distinguish different oil drilling rig sites on the cloud side; it can be a well site number, drilling rig number, project number, site number, or a unique logical number generated by the cloud access platform during the initial registration at the site. The actual local address represents the actual communication address of the equipment within the internal network of its respective oil drilling rig site, such as the local IP address of a PLC, the communication address of a frequency converter, the address of a remote I / O module, the address of an industrial control computer, or other industrial communication node addresses. The field access link information indicates the link status, link number, connection time, and link availability when the site accesses the cloud via VPN.

[0013] In this embodiment of the invention, it is readily understood that an oil drilling rig site can be an independent well site, a drilling operation site, the site where a drilling rig electrical control system is located, or a site area with an independent local control network. Different oil drilling rig sites can use the exact same local network segment, or they can only have some of the same device addresses. For example, both the first and second oil drilling rig sites use the 192.168.1.0 / 24 network segment, and the PLC master station address in both sites is 192.168.1.10, and the industrial control computer address is 192.168.1.20. For on-site personnel, this address planning is beneficial for project replication and standardized debugging; however, for the cloud-based remote control platform, without adding an additional differentiation mechanism, the same address will lead to the inability to uniquely identify the access object.

[0014] In practical applications, field access information can be proactively reported by the field access gateway, or obtained by the cloud access platform after the VPN link is established by reading the field access gateway. The field access gateway can be deployed between the oil drilling rig's field control network and the external communication network. One side connects to field industrial switches, PLCs, industrial control computers, or other field devices, while the other side connects to the cloud via a wired network, wireless private network, satellite link, or other communication network. When connecting to the cloud, the field access gateway can carry field identification, device list, real local address table, communication protocol type, and current link status, enabling the cloud to obtain complete field access information.

[0015] It should be noted that the true local address in this invention is not limited to an IPv4 address. In different industrial control environments, the true local address can also be a protocol station number, device node number, bus address, or other addressable identifier defined by the field control network. As long as the address can locate the target device in the corresponding oil drilling rig's internal field network, it can be used as the true local address described in this invention.

[0016] S2: Based on the field access information, assign a unique VPN identifier to each oil drilling rig site and establish a binding relationship between the site identifier and the corresponding VPN identifier.

[0017] Specifically, after obtaining access information from multiple oil drilling rig sites, the cloud assigns a unique VPN identifier to each site. This VPN identifier represents the logical identity of the corresponding oil drilling rig site within the cloud's access layer. Unlike a physical local address, the VPN identifier does not represent a specific device within the site, but rather an independent access domain and link identity after the site connects to the cloud. By assigning a unique VPN identifier to each site, even if multiple sites share the same physical local address, the cloud can first distinguish between different sites based on the VPN identifier, and then access devices within the corresponding site based on the physical local address.

[0018] In one executable implementation, let the set of on-site oil drilling rigs accessed from the cloud be: ; The corresponding VPN identifier set is:

[0019] And satisfy: ; in, This represents the collection of oil drilling rigs currently connected to or managed in the cloud. This indicates the site marker for the i-th oil drilling rig. Indicates the number of oil drilling rigs on site; This represents the set of VPN identifiers assigned by the cloud to each oil drilling rig site. This represents the VPN identifier corresponding to the i-th oil drilling rig site; This represents the VPN identifier corresponding to the k-th oil drilling rig site; This indicates two different oil drilling rig sites.

[0020] In practice, when any oil drilling rig connects to the cloud for the first time, the cloud generates a site registration record based on the site's site identifier and assigns an unused VPN identifier to the site according to the VPN identifier allocation of currently connected sites. If the site has previously connected to the cloud and retains historical registration records, the cloud can restore its original VPN identifier binding relationship based on the site identifier, so that the remote control terminal can still use the existing virtual logical access objects. This method can reduce the reconfiguration costs when sites repeatedly connect, reconnect after disconnection, or migrate for deployment.

[0021] In this embodiment of the invention, the binding relationship between the site identifier and the VPN identifier can be recorded in the cloud access record. The cloud access record may include information such as the site identifier, VPN identifier, access time, link status, site access gateway number, device inventory version, and mapping table version. Through these records, the cloud can quickly determine the corresponding VPN identifier based on the target site identifier when a subsequent remote access request arrives, and restrict the access request to the logical access domain of the corresponding site.

[0022] S3: Based on the site identifier, the VPN identifier, and the real local address, generate a virtual logical address for the corresponding device in the site in the cloud, and form a cloud mapping table to describe the correspondence between the site identifier, the VPN identifier, the virtual logical address, and the real local address.

[0023] Specifically, after acquiring on-site access information and assigning VPN identifiers, the cloud further generates a virtual logical address for the corresponding device based on the on-site identifier, VPN identifier, and real local address. This virtual logical address is the logical access object used by the remote control terminal and the unified cloud access platform; it is not equivalent to the device's real local address within the on-site network. When the remote control terminal accesses the target device, it can identify the access object through the target on-site identifier and the target virtual logical address; however, the target device retains its original real local address within the on-site environment.

[0024] In this embodiment of the invention, a cloud mapping table is used to describe the correspondence between site identifiers, VPN identifiers, virtual logical addresses, and real local addresses. Specifically, for any device within any oil drilling rig site, the cloud reads the site identifier, the corresponding VPN identifier, and the device's real local address, and generates a mapping record by combining device type information and communication service information. This mapping record may include fields such as site identifier, VPN identifier, virtual logical address, real local address, device type, service port, communication protocol, mapping status, address conflict identifier, and last update time. During subsequent remote access request processing, the cloud can complete the conversion from virtual logical address to real local address by querying this mapping record.

[0025] In one executable implementation, the cloud mapping relationship can be represented as: ; in, Indicates the first The first oil drilling rig site The virtual logical address corresponding to each device on the cloud side; Indicates a cloud mapping function; Indicates the first Site signage for an oil drilling rig; Indicates the first The VPN identifier corresponding to each oil drilling rig site; Indicates the first The first oil drilling rig site The actual local address of each device; Indicates the site sequence number; This represents the serial number of the device within the site. It should be noted that the above formula describes the cloud-to-device mapping relationship and does not limit the virtual logical address to be calculated using a specific algorithm.

[0026] Specifically, if site A's site identifier is S1, VPN identifier is P1, and its PLC's real local address is 192.168.1.10, the cloud can generate a virtual logical address V11 for this PLC. Similarly, if site B's site identifier is S2, VPN identifier is P2, and its PLC's real local address is also 192.168.1.10, the cloud can generate a virtual logical address V21 for this PLC. When the remote control terminal accesses the PLC at site A, it accesses S1 and V11; when accessing the PLC at site B, it accesses S2 and V21. Therefore, even if the two PLCs have the same real local address within their respective sites, the cloud side can still distinguish them as two different logical access objects.

[0027] Furthermore, before or during the generation of virtual logical addresses in the cloud, the cloud can compare the real local addresses of multiple oil drilling rig sites to identify whether different sites share the same network segment or the same real local address. If at least two sites are identified as sharing the same network segment or the same real local address, an address conflict identifier is generated, and the different sites with address conflicts are assigned to different site logical domains. The site logical domain represents the logical isolation relationship between different sites on the cloud side, and it can correspond one-to-one with a VPN identifier, or it can be determined jointly by the site identifier, the VPN identifier, and the address conflict identifier.

[0028] In one executable implementation, if the same real local address exists at different oil drilling rig sites, it can be represented as: ; in, Indicates the first The first oil drilling rig site The actual local address of each device; Indicates the first The actual local address of the corresponding equipment within the site of an oil drilling rig; This indicates that the two devices belong to different oil drilling sites.

[0029] After cloud mapping, the corresponding virtual logical address satisfies: ; in, Indicates the first The virtual logical address of the corresponding equipment on the cloud side within the site of an oil drilling rig; Indicates the first Each oil drilling rig has a corresponding virtual logical address on the cloud side for its equipment. Therefore, even if equipment at different sites has the same physical local address, the cloud can logically distinguish them using different virtual logical addresses.

[0030] Furthermore, in an optional implementation, after identifying at least two oil drilling rig sites sharing the same network segment or the same real local address, the cloud performs conflict profiling on the conflicting address resources to generate an address conflict fingerprint characterizing the source and nature of the conflict. Specifically, for each real local address, the cloud can extract its site identifier, corresponding VPN identifier, device type information, communication service information, protocol port information, read / write attribute information, access frequency information, and request type association information, and generate an address conflict fingerprint based on the above information. The address conflict fingerprint is used to indicate the reuse status of the same real local address in different oil drilling rig sites, and serves as an auxiliary basis for site logical domain partitioning, virtual logical address generation, and subsequent reverse mapping and traffic splitting on the cloud side.

[0031] In this embodiment of the invention, the cloud further distinguishes between homogeneous and heterogeneous conflicts based on the address conflict fingerprint. Homogeneous conflicts refer to situations where the same real local address in different oil drilling rig sites corresponds to the same or similar device type, communication service, and access purpose. For example, multiple PLC master stations in different sites may all use 192.168.1.10 and are all used for monitoring, status reading, or online downloading of the same control program. For homogeneous conflicts, the cloud merges multiple mapping records with the same conflict characteristics into the same conflict cluster and generates a conflict cluster number and mapping template for this cluster. The mapping template may include standard device roles, standard communication services, standard access modes, a real local address field, virtual logical address generation rules, and a range of allowed request types. When generating virtual logical addresses for different oil drilling rig sites within the same conflict cluster, the cloud no longer generates mapping rules completely independently for each site. Instead, it uses the mapping template as a basis, superimposing the site identifier, VPN identifier, and site logical domain number to form virtual logical addresses with the same access semantics but isolated from each other. In this way, mapping templates can be reused when similar sites are accessed in batches, reducing the workload of manual configuration. Furthermore, when the access rules for a certain type of standard device need to be adjusted, the cloud can perform consistency verification and batch updates on similar mapping records based on the conflict cluster number, thereby improving the mapping maintenance efficiency in multi-site replication deployment scenarios.

[0032] For heterogeneous conflicts, the cloud does not simply treat the same real local address as the same type of conflict object, but further establishes address reuse slots. These address reuse slots represent different communication services or access purposes carried by the same real local address under different sites or different device roles. For example, in one site, 192.168.1.10 may correspond to a PLC controller; in another site, 192.168.1.10 may correspond to an industrial control computer or video equipment. Even if the two have the same real local address, due to differences in device type, protocol port, or access purpose, the cloud divides them into different address reuse slots. Specifically, the cloud can establish multiple service slots for the same real local address based on device type information, communication service information, protocol port information, and request type information, and introduce service slot identifiers when generating virtual logical addresses. This allows the virtual logical address to not only distinguish between sites but also the corresponding device role and service purpose under that real local address. When a remote control terminal initiates an access request, the cloud matches the corresponding service slot based on the target site identifier, target virtual logical address, and request type in the access context, and then determines the target VPN identifier, target real local address, and target communication service, thereby avoiding the incorrect merging of different device roles or different service purposes under the same address into the same access object.

[0033] Furthermore, in one executable implementation, the cloud can set different verification strategies for homogeneous and heterogeneous conflicts. For homogeneous conflicts, the cloud focuses on verifying whether the device type, communication service, and access mode of each site within the same conflict cluster are consistent with the mapping template. When the device list or communication service of a site changes, the cloud can mark the corresponding mapping record of that site as pending verification to prevent it from continuing to use the original conflict cluster template and causing access deviations. For heterogeneous conflicts, the cloud focuses on verifying whether there are overlapping request types, abnormal port reuse, or overlapping access permissions between different service slots under the same real local address. When it is detected that two service slots under the same real local address are both configured for remote control access mode, the cloud can require further differentiation based on device type or access source information, or mark one of the service slots as restricted access. Through the above-mentioned differentiated processing, the cloud can not only achieve address-level isolation when multiple sites access the same network segment, but also achieve fine-grained differentiation based on device role, communication service and access purpose. Compared with the traditional method of isolation by simply changing the network segment, static NAT or fixed VPN routing, it can reduce the cost of on-site modification, improve the maintainability of mapping rules, and enhance the accuracy and security of remote access target identification.

[0034] It should be noted that the virtual logical address can take various forms. For example, it can use a unified cloud-based numbering system, such as "V-S1-PLC01"; it can also use a virtual IP address, such as 10.100.1.10 corresponding to the PLC in site A, and 10.100.2.10 corresponding to the PLC in site B; or it can use an internal platform resource path, such as "site / S1 / device / PLC01". The above examples are only used to illustrate possible implementations of the virtual logical address and do not constitute a limitation on the scope of protection of this invention. As long as the virtual logical address can uniquely represent the target device in the corresponding site on the cloud side, and can be converted to the target VPN identifier and the target real local address through a cloud mapping table, it can be applied to this invention.

[0035] In this embodiment of the invention, the cloud mapping table can be stored in a cloud database, configuration center, memory cache, or other data structures that support fast querying. To ensure the stability of the remote access process, the cloud can set a mapping status field for the cloud mapping table. The mapping status field can include states such as available, unavailable, link abnormal, pending verification, and access in use. By maintaining this mapping status, the cloud can determine whether the target device is reachable and whether to allow the current access request to continue before or during the access process initiated by the remote control terminal.

[0036] S4: Receive a remote access request sent by the remote control terminal, and determine the corresponding target VPN identifier and target real local address from the cloud mapping table based on the target site identifier and target virtual logical address in the remote access request.

[0037] Specifically, the remote control terminal can be a remote monitoring center, a remote operation and maintenance terminal, an engineering workstation, a debugging terminal, a mobile operation and maintenance terminal, or other control devices with access permissions. When accessing a target device, the remote control terminal does not directly target the target device's real local address. Instead, it generates a remote access request based on the target site identifier and the target virtual logical address. The reason for this configuration is that different oil drilling rig sites may have the same real local address. If the remote control terminal directly inputs the real local address, it will be difficult to determine which site the accessed object belongs to. However, by using the combination of the target site identifier and the target virtual logical address to represent the accessed object, a unique access entry point can be formed on the cloud side.

[0038] In this embodiment of the invention, the remote access request includes at least a target site identifier, a target virtual logical address, a request type, access source information, and a timestamp. The target site identifier indicates the oil drilling rig site to be accessed; the target virtual logical address indicates the target equipment within the site to be accessed; the request type indicates whether the access is for monitoring, status reading, online downloading, program maintenance, remote control, or other access types; the access source information indicates the remote control terminal initiating the access, the user's identity, terminal number, or authorized role; and the timestamp records the time the access request was generated, facilitating subsequent access auditing and anomaly tracing.

[0039] In one executable implementation, a remote access request can be represented as: ; in, Indicates a remote access request; Site markings indicating the location of the target oil drilling rig; This represents the virtual logical address of the target device on the cloud side; Indicates the request type; This represents the timestamp. It should be noted that the access source information can be included as an additional field in the request, forming a complete request object along with the parameters mentioned above. The formula is only used to represent the main access location parameters in a remote access request.

[0040] Specifically, upon receiving a remote access request, the cloud first performs access permission verification on the remote control terminal based on the access source information. Access permission verification can include user identity verification, terminal authorization verification, target site access permission verification, and request type permission verification. For example, a remote maintenance user might only have monitoring permissions for site A, but not control permissions for site B; an engineering workstation might be able to read PLC status, but not perform online downloads. By performing permission verification on the cloud side, unauthorized remote access requests can be prevented from entering the field control network.

[0041] If the access permission verification passes, the cloud determines the access mode corresponding to the remote access request based on the request type. The access modes can include monitoring access mode, status reading access mode, online download access mode, and remote control access mode. Monitoring access mode is mainly used to read on-site status, alarm information, operating parameters, or video-related status; status reading access mode is mainly used to obtain equipment diagnostic information, communication status, or operating data; online download access mode is mainly used to download programs, configurations, or parameters to PLCs, industrial control computers, or related control equipment; and remote control access mode is mainly used to issue control commands to the target equipment or perform operational takeover. Different access modes have different requirements for access permissions, concurrent access, and control occupancy, therefore, they need to be differentiated on the cloud side.

[0042] Specifically, in monitoring or status reading access modes, the cloud can allow different remote control terminals to access different oil drilling rig sites in parallel based on their corresponding permissions, or access different devices at the same site. Since this type of access typically does not directly change the site control status, its main function is data reading and status monitoring; therefore, multiple remote terminals can be allowed to access simultaneously according to the permission policy. Correspondingly, in online download or remote control access modes, the cloud can generate a control occupancy record based on the target site identifier, target virtual logical address, and access source information. This control occupancy record indicates that a remote control terminal has an operational occupancy status over the target device within a certain time range, thus preventing multiple remote terminals from simultaneously performing conflicting operations on the same controlled object.

[0043] It should be noted that the access context in this invention refers to the set of context data formed by the cloud when processing a remote access request. This context may include the target site identifier, target virtual logical address, request type, access source information, access mode, permission verification result, timestamp, and subsequently queried target VPN identifier and target real local address. By forming an access context, the cloud can maintain data consistency during subsequent reverse mapping, link selection, site-side access data generation, response data feedback, and log recording, avoiding inconsistencies in target objects between processing stages.

[0044] In practical applications, control occupancy records can include occupancy start time, occupancy duration, occupancy source, request type, and occupancy status. For example, when engineer station A initiates an online download request to the PLC virtual logic address V11 in field S1, the cloud can generate a control occupancy record corresponding to S1 and V11. During the validity period of this control occupancy record, if engineer station B initiates a remote control request to the same target, the cloud can restrict, queue, or reject the request according to policies. When the control occupancy record meets the release conditions, the cloud removes the access restriction on the target device. Release conditions can include operation completion, remote terminal active release, access timeout, VPN link disconnection, or administrator forced release, etc.

[0045] Specifically, such as Figure 2 As shown, after the access context is generated, the cloud queries the cloud mapping table based on the target site identifier and target virtual logical address in the access context. Since the cloud mapping table already records the correspondence between site identifiers, VPN identifiers, virtual logical addresses, and real local addresses, the cloud can locate a unique mapping record based on the target site identifier and target virtual logical address, and extract the target VPN identifier and target real local address from that mapping record. This process can be understood as the cloud performing a reverse mapping on the remote access request.

[0046] In one executable implementation, the cloud-to-inverse mapping relationship can be represented as:

[0047] in, This represents the inverse mapping process corresponding to the cloud mapping function; Site markings indicating the location of the target oil drilling rig; This represents the virtual logical address of the target device on the cloud side; This indicates the VPN identifier corresponding to the target oil drilling rig site; This indicates the target device's actual local address within the internal network of its respective oil drilling rig. Therefore, the cloud can determine the corresponding VPN identifier and actual local address based on the target site identifier and the virtual logical address.

[0048] Specifically, when querying the cloud mapping table, the cloud can simultaneously check the availability status of the mapping record, the VPN link status, and the control occupancy status. If a mapping record is marked as unavailable, it indicates that the target site may be offline, the VPN link may be abnormal, or the mapping relationship may be pending verification. In this case, the cloud can terminate forwarding and return information about the target being unreachable or the link being unavailable to the remote control terminal. If the mapping record is available and the current access mode meets the control occupancy policy, the cloud determines the target VPN link based on the target VPN identifier and generates on-site access data for the target device based on the target's real local address, device type information, and communication service information.

[0049] In practical applications, the field-side access data can be organized according to device type and communication service information. For example, when the target device is a PLC, the field-side access data may include the PLC communication protocol type, the target's real local address, service port, and read / write instruction type; when the target device is a frequency converter, the field-side access data may include the target address, parameter read or parameter write requests; when the target device is a video device, the field-side access data may include the video stream access address or status query request. It should be noted that the above examples are only used to illustrate that field-side access data can take different forms under different device types, and this invention does not limit specific industrial communication protocols.

[0050] S5: Based on the target VPN identifier, forward the remote access request through the corresponding VPN link to the target device with the target's real local address at the target oil drilling rig site, and send the target device's response data back to the remote control terminal.

[0051] After identifying the target VPN link, the cloud sends the on-site access data to the target oil drilling rig via the corresponding VPN link. Upon entering the target site, the on-site access gateway or on-site network device forwards the data to the target device based on the target's real local address. Because the target device still uses its original real local address, the PLC program, equipment communication parameters, and on-site personnel operating habits can remain largely unchanged. The cloud's function is to establish a logical mapping and access conversion between the remote control terminal and the on-site real address, rather than requiring the on-site internal network to re-address for remote access.

[0052] After receiving the access data, the target device returns response data based on the request type. Response data can be status data, monitoring data, alarm data, communication responses, control execution results, or online download results. The field device sends the response data back to the cloud via the corresponding VPN link. The cloud associates the response data with the original remote access request based on the access context and sends it back to the remote control terminal. For the remote control terminal, the received response result can still identify the target object using the target site identifier and virtual logical address, thus avoiding confusion caused by displaying multiple identical real local addresses on the remote platform.

[0053] In this embodiment of the invention, the VPN link can be a software VPN link, an industrial gateway VPN link, a cloud VPN access service link, or other secure tunnel communication links. The specific implementation of the VPN link does not constitute a limitation of the invention; as long as a distinguishable secure communication path can be established between the cloud side and different oil drilling rig sites, and access routing based on VPN identifiers is supported, it can be applied to the invention. Furthermore, the VPN identifier can correspond one-to-one with a physical VPN connection, or it can correspond to a logical tunnel, routing domain, or cloud access domain.

[0054] Therefore, this invention realizes the conversion of remote access requests from target site identifier and target virtual logical address to target VPN identifier and target real local address. This conversion allows the remote control terminal to no longer directly rely on the real local address of the site, but instead the cloud completes the target location based on the mapping table and VPN identifier, thereby solving the problem of remote access path confusion when multiple sites use the same network segment.

[0055] Specifically, after a remote access request is processed, the cloud continuously collects the online status information of the corresponding VPN links at each oil drilling rig site and updates the VPN link status in the cloud mapping table based on this online status information. VPN link status can include online, offline, connection error, communication delay error, pending verification, or recovery status, among others. By continuously maintaining the VPN link status, the remote control terminal can obtain a basis for determining whether the target site is reachable before initiating an access request or during the access request processing.

[0056] In this embodiment of the invention, when any oil drilling rig site goes offline or the corresponding VPN link is abnormal, the cloud marks the mapping record corresponding to that oil drilling rig site as unavailable. After the mapping record is marked as unavailable, the cloud can prevent subsequent forwarding operations to that site, or return prompts such as the target site being offline, the link being unavailable, or the device being unreachable to the remote control terminal. This can prevent the remote control terminal from continuing to send control requests when the target site is unreachable, and can also prevent unpredictable access results due to uncertain link status.

[0057] When any oil drilling rig reconnects to the cloud, the cloud restores the corresponding VPN identifier binding relationship based on the site identifier of that oil drilling rig and performs a consistency check on the cloud mapping table. This consistency check can include whether the site identifier matches historical records, whether the VPN identifier matches the site binding relationship, whether the real local address matches the original device list, whether the virtual logical address needs to remain unchanged, whether the device type information has changed, and whether the mapping status can be restored to a usable state. Through consistency checks, problems such as mapping misalignment, incorrect access paths, or significant changes in virtual logical addresses that could cause remote configuration failures after the site reconnects can be avoided.

[0058] In practical applications, if the field device S1 briefly loses connection and then reconnects to the cloud, the cloud can find the historical registration record based on the field identifier S1 and restore its original VPN identifier P1 and original set of virtual logical addresses. If the field device list remains unchanged, the cloud can directly restore the corresponding mapping record to an available state. If the field device list changes, such as adding a new sensor acquisition module, the cloud can generate a new virtual logical address for the new device and supplement the cloud mapping table with the new mapping record. If a significant difference is found between the real local address list corresponding to the same field identifier and the historical records, the cloud can mark the mapping table version as pending verification and prompt for manual confirmation or automatic verification.

[0059] Furthermore, the cloud records the target site identifier, target virtual logical address, request type, access source information, forwarding result, and response status corresponding to the remote access request, forming a multi-site remote control access log. This access log can be used for remote operation and maintenance tracing, access auditing, fault diagnosis, and access policy optimization. For example, when a remote control terminal initiates a remote control request to the virtual logical address V21 in site S2, the cloud can record the request time, user identity, target site, target virtual logical address, mapped VPN identifier, mapped real local address, whether forwarding was successful, and whether the target device responded. If subsequent control or communication anomalies occur, the location can be determined based on these logs.

[0060] It should be noted that the access status maintenance in this invention is not limited to execution after the access ends; it can also be continuously executed during on-site access, mapping generation, request parsing, reverse mapping forwarding, and response feedback. Its purpose is to enable the cloud mapping table to reflect the on-site access status and device access status, providing a stable data foundation for multi-site remote control access. Through this method, this invention can adapt to various application scenarios such as long-term network connectivity of multiple local sites, unified monitoring of multiple sites by a remote control center, separate access to different sites by multiple remote terminals, and coexistence of video / status / control access.

[0061] Reference Figure 3 , Figure 3 This is a schematic diagram of the structure of the multi-site remote control access system for oil drilling rigs according to an embodiment of the present invention.

[0062] like Figure 3 As shown, the multi-site remote control access system for oil drilling rigs proposed in this embodiment of the invention includes: The acquisition module 10 is used to acquire field access information of multiple oil drilling rig sites; wherein, the field access information includes at least the site identifier, the real local address of the equipment in the site, and the field access link information; Module 20 is used to assign a unique VPN identifier to each oil drilling rig site based on the site access information, and to establish a binding relationship between the site identifier and the corresponding VPN identifier. The forming module 30 is used to generate a virtual logical address corresponding to the device in the field in the cloud based on the field identifier, the VPN identifier and the real local address, and form a cloud mapping table to describe the correspondence between the field identifier, the VPN identifier and the virtual logical address and the real local address. The determination module 40 is used to receive a remote access request sent by the remote control terminal, and determine the corresponding target VPN identifier and target real local address from the cloud mapping table based on the target site identifier and target virtual logical address in the remote access request. The forwarding module 50 is used to forward remote access requests via the corresponding VPN link to the target device with the target real local address at the target oil drilling rig site based on the target VPN identifier, and to send the response data of the target device back to the remote control terminal.

[0063] Other embodiments or specific implementations of the multi-site remote control access system for oil drilling rigs of the present invention can be referred to the above-described method embodiments, and will not be repeated here.

[0064] It is understood that in the description of this specification, references to terms such as "one embodiment," "another embodiment," "other embodiments," or "first embodiment to Nth embodiment," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0065] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or system that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or system. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or system that includes that element.

[0066] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A method for multi-site remote control access of an oil drilling rig, characterized in that, The method includes the following steps: Obtain field access information for multiple oil drilling rig sites; wherein, the field access information includes at least the site identifier, the actual local address of the equipment within the site, and the field access link information; Based on the field access information, a unique VPN identifier is assigned to each oil drilling rig site, and a binding relationship is established between the site identifier and the corresponding VPN identifier. Based on the site identifier, the VPN identifier, and the real local address, a virtual logical address corresponding to the device in the site is generated in the cloud, and a cloud mapping table is formed to describe the correspondence between the site identifier, the VPN identifier, the virtual logical address, and the real local address. Receive a remote access request sent by a remote control terminal, and determine the corresponding target VPN identifier and target real local address from the cloud mapping table based on the target site identifier and target virtual logical address in the remote access request; Based on the target VPN identifier, the remote access request is forwarded via the corresponding VPN link to the target device with the target's real local address at the target oil drilling rig site, and the response data of the target device is sent back to the remote control terminal.

2. The multi-site remote control access method for oil drilling rigs as described in claim 1, characterized in that, Obtain on-site access information for multiple oil drilling rigs, specifically including: Obtain the site identification corresponding to each oil drilling rig site to distinguish between different oil drilling rig sites; Obtain the real local address, equipment type information, and communication service information of each oil drilling rig on-site, and associate the real local address, equipment type information, and communication service information with the corresponding on-site identifier; Obtain the field access link information of each oil drilling rig site, including the VPN link status information used when the corresponding site accesses the cloud; The site identifier, the real local address, the device type information, the communication service information, and the VPN link status information are used as the site access information.

3. The multi-site remote control access method for oil drilling rigs as described in claim 1, characterized in that, Based on the aforementioned field access information, a unique VPN identifier is assigned to each oil drilling rig site, and a binding relationship is established between the site identifier and the corresponding VPN identifier, specifically including: When any oil drilling rig connects to the cloud, a site registration record is generated based on the site identifier of that oil drilling rig site; Based on the on-site registration record, assign a VPN identifier to the oil drilling rig site that is different from other oil drilling rig sites that have been connected, and record the on-site identifier of the oil drilling rig site, the VPN identifier, and the VPN link status information to the cloud access record; A binding relationship is established between the on-site identifier and the VPN identifier based on the cloud access record.

4. The multi-site remote control access method for oil drilling rigs as described in claim 1, characterized in that, Based on the site identifier, the VPN identifier, and the real local address, a virtual logical address corresponding to the device within the site is generated in the cloud, and a cloud mapping table is formed to describe the correspondence between the site identifier, the VPN identifier, the virtual logical address, and the real local address, specifically including: For any device within any oil drilling rig site, read the site identifier of the oil drilling rig site to which the device belongs, the corresponding VPN identifier, and the device's real local address; The virtual logical address used by the device on the cloud side is generated based on the site identifier, the VPN identifier, and the real local address. The site identifier, the VPN identifier, the virtual logical address, the real local address, the device type information, and the communication service information are recorded as a mapping record in the cloud mapping table.

5. The multi-site remote control access method for oil drilling rigs as described in claim 4, characterized in that, Before generating the corresponding virtual logical address of the device in the field on the cloud, the method further includes: The real local addresses of multiple oil drilling rig sites are compared to identify whether there are the same network segments or the same real local addresses between different oil drilling rig sites. If at least two oil drilling rig sites are identified to have the same network segment or the same real local address, an address conflict identifier is generated, and the different oil drilling rig sites with address conflicts are divided into different site logical domains. Virtual logical addresses are generated in different field logical domains so that the remote control terminal can access the target device based on the virtual logical addresses.

6. The multi-site remote control access method for oil drilling rigs as described in claim 1, characterized in that, Receive remote access requests sent by the remote control terminal, specifically including: Receive a remote access request generated by a remote control terminal based on the target site identifier and the target virtual logical address; wherein, the remote access request includes at least the target site identifier, the target virtual logical address, the request type, the access source information, and the timestamp; Based on the access source information, perform access permission verification on the remote control terminal; If the access permission verification passes, the access mode corresponding to the remote access request is determined based on the request type; wherein, the access mode includes monitoring access mode, online download access mode, status reading access mode, or remote control access mode. The target site identifier, the target virtual logical address, the request type, and the access mode are used to form an access context, and the access context is stored in association.

7. The multi-site remote control access method for oil drilling rigs as described in claim 6, characterized in that, Based on the target site identifier and target virtual logical address in the remote access request, the corresponding target VPN identifier and target real local address are determined from the cloud mapping table, specifically including: Query the cloud mapping table based on the target site identifier and target virtual logical address in the access context; In the cloud mapping table, determine the mapping record that matches the target site identifier and the target virtual logical address, and extract the target VPN identifier, target real local address, device type information and communication service information from the mapping record; The target VPN link is determined based on the target VPN identifier, and on-site access data for the target device is generated based on the target's real local address, the device type information, and the communication service information.

8. The multi-site remote control access method for oil drilling rigs as described in claim 6, characterized in that, After determining the access mode corresponding to the remote access request based on the request type, the method further includes: When the access mode is monitoring access mode or status reading access mode, different remote control terminals are allowed to access different oil drilling rig sites or different equipment at the same oil drilling rig site in parallel based on their corresponding permissions. When the access mode is online download access mode or remote control access mode, a control occupancy record is generated based on the target site identifier, the target virtual logical address and the access source information; If a valid control occupancy record exists corresponding to the target site identifier and the target virtual logical address, subsequent conflicting access requests will be restricted. When the control occupancy record meets the release conditions, the access restrictions on the target site identifier and the target device corresponding to the target virtual logical address are lifted.

9. The multi-site remote control access method for oil drilling rigs as described in claim 1, characterized in that, After forwarding the remote access request via the corresponding VPN link to the target device with the target's real local address at the target oil drilling rig site based on the target VPN identifier, and then transmitting the target device's response data back to the remote control terminal, the method further includes: Collect online status information of the VPN links corresponding to each oil drilling rig on-site, and update the VPN link status in the cloud mapping table based on the online status information; If any oil drilling rig site is offline or the corresponding VPN link is abnormal, mark the mapping record corresponding to the oil drilling rig site as unavailable. When any oil drilling rig reconnects to the cloud, the corresponding VPN identifier binding relationship is restored based on the site identifier of the oil drilling rig, and the consistency of the cloud mapping table is verified. Record the target site identifier, target virtual logical address, request type, forwarding result, and response status corresponding to the remote access request to form a multi-site remote control access log.

10. A multi-site remote control access system for oil drilling rigs, characterized in that, The system includes: The acquisition module is used to acquire field access information of multiple oil drilling rig sites; wherein, the field access information includes at least the site identifier, the real local address of the equipment in the site, and the field access link information; A module is established to assign a unique VPN identifier to each oil drilling rig site based on the site access information, and to establish a binding relationship between the site identifier and the corresponding VPN identifier. The forming module is used to generate a virtual logical address corresponding to the device in the field in the cloud based on the field identifier, the VPN identifier and the real local address, and to form a cloud mapping table for describing the correspondence between the field identifier, the VPN identifier and the virtual logical address and the real local address; The determination module is used to receive remote access requests sent by the remote control terminal, and determine the corresponding target VPN identifier and target real local address from the cloud mapping table based on the target site identifier and target virtual logical address in the remote access request. The forwarding module is used to forward remote access requests via the corresponding VPN link to the target device with the target's real local address at the target oil drilling rig site based on the target VPN identifier, and to send the target device's response data back to the remote control terminal.