Redundant link switching control method and system for DCS control cycle
Patent Information
- Application Number
- CN202611036267.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-13
- Publication Date
- 2026-09-11
AI Technical Summary
[0004]本发明的目的在于提供一种面向DCS控制周期的冗余链路切换控制方法及系统,旨在解决现有技术在冗余链路切换过程中存在的“切换耗时缺乏上界约束、会话关键状态不连续或迁移不完整、切换后序号/判重/乱序容忍/策略状态错配、缺乏一致性校验与回退降级策略、以及审计追溯能力不足”等问题的问题
本发明将切换过程纳入控制周期的刚性约束框架,通过状态可迁移、迁移可校验、失败可降级、成功可确认的四重保障机制,显著提升了DCS系统在链路异常时的切换确定性、业务连续性与运行可靠性。具体为:首先,本方法在切换触发阶段综合判断丢包率、时延、抖动、链路中断及安全异常事件等多种链路运行状态,能够精准识别链路质量劣化或安全攻击,避免单一阈值误判或漏判,确保切换时机准确可靠。其次,以DCS固有控制周期为核心参数,将切换窗口上界严格限定,并对切换过程中引入的额外时延和抖动增量施加明确约束,使切换耗时具有确定性上界,从根本上解决了传统切换方案中耗时不可控、可能超出控制周期容忍范围的问题,保障了实时控制回路的稳定性。在切换执行过程中,通过设置冻结时刻并生成关键运行状态的快照记录,将会话标识、发送序号、接收序号等核心状态完整迁移至目标链路,避免了切换后出现序号错配、重复控制或判重窗口断裂等业务异常;迁移完成后,通过状态摘要生成与比对机制对迁移结果进行一致性校验,确保迁移状态的完整性与正确性,防止错误状态继续运行的风险。当校验失败时,采用有限次重试与降级为只读模式的逐级容错策略,既避免了无限重试导致的长时间中断,又通过只读模式保障了控制类报文的监视能力,同时限制非关键操作,实现了故障情况下的可控收敛。此外,本方法在切换完成后还设置了连续N个控制周期的观测验证机制,通过确认业务报文正常处理、无重复控制指令、抗重放窗口连续更新三个条件,确保切换真正生效并稳定运行;若观测异常则可触发重新切换或回退原链路,形成了完整的闭环验证与恢复能力。综上,本发明在满足DCS强实时约束的前提下,实现了冗余链路切换的窗口上界可控制、会话状态可迁移、迁移结果可验证、失败后可降级收敛、成功后可确认稳定的全流程可靠性保障,适用于电厂等对控制周期和业务连续性要求严苛的工业场景。
Smart Images

Figure CN122741433A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of industrial control system network communication and information security technology, and in particular to a redundant link switching control method and system for DCS control cycles. Background Technology
[0002] As power plant control system network structures become increasingly complex, services within the DCS control area, such as control command issuance, measurement point sampling and transmission, status monitoring, and operation and maintenance configuration, typically rely on multi-link, redundant network architectures to improve reliability. DCS control services are characterized by strong real-time performance, with control cycles typically ranging from milliseconds to hundreds of milliseconds, and strict upper bounds exist for end-to-end latency and jitter. Therefore, when the primary link experiences increased packet loss, a sudden increase in latency and jitter, or a link interruption, it is necessary to switch to a backup link within a very short time to maintain service continuity and control loop stability.
[0003] Existing redundancy switching schemes mostly employ link detection or simple threshold-triggered primary / backup switching mechanisms. However, in actual control area scenarios, the following problems still exist: First, the switching process lacks time upper bound constraints coupled with the control cycle, making switching time uncontrollable and potentially introducing instantaneous interruptions, jitter spikes, or concentrated packet loss, affecting control stability. Second, switching often only focuses on link-layer or routing-layer redirection, lacking synchronization and migration mechanisms for critical business session states, leading to issues such as sequence number mismatches, discontinuous deduplication windows, lost policy states, or duplicate control after switching. Third, the lack of consistency verification and rollback strategies during switching makes it easy for "errors to continue running" or "repeated switching" to occur when state migration is incomplete or erroneous, making timely convergence difficult. Fourth, the switching trigger, migration process, and results lack systematic audit records and evidence chains, making it difficult to meet the needs of security auditing and fault tracing. Especially when services simultaneously incorporate security label verification, anti-replay windows, and out-of-order tolerance mechanisms, failure to maintain the continuity of these states during switching will further amplify the risks of business anomalies and malfunctions. Summary of the Invention
[0004] The purpose of this invention is to provide a redundant link switching control method and system for DCS control cycles, aiming to solve the problems existing in the redundant link switching process, such as "lack of upper bound constraints on switching time, discontinuous or incomplete transition of key session states, mismatch of sequence number / duplicate / out-of-order tolerance / policy state after switching, lack of consistency verification and fallback degradation strategies, and insufficient audit traceability capabilities".
[0005] In a first aspect, the present invention provides a redundant link switching control method for DCS control cycles, the method comprising: Establish service sessions at both ends of the DCS communication link, assign a unique session identifier (SID) to the service session, and obtain the control cycle of the DCS system; Configure one primary link and at least one backup link, obtain the operating status of the primary link every first preset time interval, and determine whether the primary link needs to be switched based on the operating status; If the main link needs to be switched, the control cycle of the DCS system is obtained, and the upper limit of the switching window is calculated according to the control cycle. Within the upper limit of the switching window, the key operating status of the service session is migrated from the main link to the selected target link. The key operating status includes at least the session identifier SID, the current sending sequence number, and the current receiving sequence number assigned to the current session. After the migration is completed, a consistency check is performed on the migrated session state on the target link side; If the consistency check passes, the service message will be switched from the main link to the target link for continued transmission. If the consistency check fails, the switch will be abandoned and a degradation processing strategy will be implemented.
[0006] In some embodiments, the step of acquiring the operating status of the main link every first preset time interval and determining whether the main link needs to be switched based on the operating status includes: The system determines whether the packet loss rate of the main link is greater than a preset packet loss rate threshold, and / or whether the transmission delay of the main link is greater than a preset delay threshold, and / or whether the delay jitter of the main link is greater than a preset jitter threshold, and / or whether the number of consecutive link probe failures of the main link is greater than a preset interruption threshold, and / or whether the number of security anomalies of the main link is greater than a preset security threshold. The security anomalies include authentication failure, signature verification failure, or replay attack. If the packet loss rate of the main link is greater than a preset packet loss rate threshold, and / or the transmission delay of the main link is greater than a preset delay threshold, and / or the delay jitter of the main link is greater than a preset jitter threshold, and / or the number of consecutive link probe failures of the main link is greater than a preset interruption threshold, and / or the number of security anomalies of the main link is greater than a preset security threshold, then it is determined that the main link needs to be switched.
[0007] In some embodiments, the step of obtaining the control cycle of the DCS system and calculating the upper bound of the switching window based on the control cycle includes: The upper bound of the switching window and the control cycle satisfy the following: ; in, To switch the upper bound of the window, To control the cycle.
[0008] In some embodiments, the step of migrating the critical operational state of the service session from the primary link to the selected target link within the upper bound of the switching window includes: A freeze time is set at the start of the switchover to pause the status update of the current service session on the main link; At the time of the freeze, a snapshot of the key operating state of the current business session is recorded. The snapshot record includes at least the session identifier (SID), the current sent sequence number, and the current received sequence number. The snapshot record is sent from the main link to the selected target link.
[0009] In some embodiments, the step of performing consistency verification on the migrated session state on the target link side includes: Obtain the key operational states that have been migrated, and generate a status summary based on the key operational states; The status digest is sent to the target link side along with the key operational status, so that the target link side can recalculate a check digest based on the received key operational status. The verification digest is compared with the status digest. If they match, the verification is deemed successful; otherwise, the verification is deemed unsuccessful.
[0010] In some embodiments, the step of abandoning the switch and implementing a degradation processing strategy if the consistency check fails includes: Determine if the current number of retries has reached the preset maximum number of retries; If the maximum number of retries has not been reached, the migration from the main link to the target link will be re-executed, and the number of retries will be incremented by 1. If the maximum number of retries has been reached, the service session will be downgraded to read-only mode.
[0011] In some embodiments, after the step of migrating the critical operational state of the service session from the primary link to the selected target link within the upper bound of the switching window, the method further includes: Observe N control cycles continuously on the target link side, and verify whether the following three conditions are met simultaneously in each control cycle: The business message was processed normally, no duplicate control commands were issued, and the anti-replay window was able to be continuously updated; If the conditions are met simultaneously for N consecutive control cycles, the switching status will be marked as switching complete. If any condition is not met, the handover is deemed abnormal, and a new handover or rollback to the original main link will be performed.
[0012] Secondly, the present invention provides a redundant link switching control system oriented towards DCS control cycle, the system comprising: The session establishment module is used to establish a service session at both ends of the DCS communication link, assign a unique session identifier (SID) to the service session, and obtain the control cycle of the DCS system. The switching detection module is used to configure a primary link and at least one backup link, acquire the operating status of the primary link every first preset time, and determine whether the primary link needs to be switched based on the operating status. The switching execution module is used to obtain the control cycle of the DCS system if the main link needs to be switched, calculate the upper bound of the switching window according to the control cycle, and migrate the key operating status of the service session from the main link to the selected target link within the upper bound of the switching window. The key operating status includes at least the session identifier SID, the current sending sequence number, and the current receiving sequence number assigned to the current session. The verification module is used to perform consistency verification of the migrated session state on the target link side after the migration is completed; The degradation module is used to switch the service packets from the main link to the target link for continued transmission if the consistency check passes, and to abandon the switch and execute the degradation processing strategy if the consistency check fails.
[0013] Thirdly, the present invention provides a storage medium that stores one or more programs, which, when executed by a processor, implement the aforementioned redundant link switching control method oriented towards the DCS control cycle.
[0014] Fourthly, the present invention provides an electronic device, the electronic device comprising a memory and a processor, wherein: The memory is used to store computer programs; When the processor executes the computer program stored in the memory, it implements the aforementioned redundant link switching control method oriented towards the DCS control cycle.
[0015] Compared with the prior art, the present invention has the following advantages: This invention incorporates the handover process into a rigid constraint framework of the control cycle. Through a four-fold guarantee mechanism—state transferability, transfer verifiability, failure degradation, and success confirmation—it significantly improves the handover determinism, service continuity, and operational reliability of the DCS system during link anomalies. Specifically: First, this method comprehensively judges various link operating states, such as packet loss rate, latency, jitter, link interruption, and security anomalies, during the handover trigger phase. This enables accurate identification of link quality degradation or security attacks, avoiding misjudgment or omission of single thresholds and ensuring accurate and reliable handover timing. Second, using the inherent control cycle of the DCS as the core parameter, it strictly limits the upper bound of the handover window and imposes explicit constraints on the additional latency and jitter increments introduced during the handover process. This gives the handover time a deterministic upper bound, fundamentally solving the problem of uncontrollable time consumption and potential exceeding the tolerance range of the control cycle in traditional handover schemes, thus ensuring the stability of the real-time control loop. During the handover process, by setting a freeze time and generating snapshots of key operational states, core states such as session identifiers, sent sequence numbers, and received sequence numbers are completely migrated to the target link. This avoids service anomalies such as sequence number mismatches, duplicate control, or broken deduplication windows after the handover. After the migration is completed, a consistency verification mechanism is used to generate and compare state summaries to ensure the integrity and correctness of the migrated states and prevent the risk of erroneous states continuing to operate. When verification fails, a step-by-step fault tolerance strategy of limited retries and downgrading to read-only mode is adopted. This avoids long-term interruptions caused by infinite retries, ensures the monitoring capability of control messages through read-only mode, and restricts non-critical operations, achieving controllable convergence under fault conditions. In addition, this method also sets up an observation and verification mechanism for N consecutive control cycles after the handover is completed. By confirming three conditions—normal processing of service messages, no duplicate control commands, and continuous updating of the anti-replay window—the handover is ensured to be truly effective and run stably. If an anomaly is observed, a re-handover or rollback to the original link can be triggered, forming a complete closed-loop verification and recovery capability. In summary, under the premise of meeting the strong real-time constraints of DCS, this invention achieves full-process reliability assurance, including controllable upper bound of the redundant link switching window, transferable session state, verifiable migration results, degraded convergence after failure, and confirmed stability after success. It is suitable for industrial scenarios such as power plants with stringent requirements for control cycle and business continuity. Attached Figure Description
[0016] Figure 1 This is a flowchart of a redundant link switching control method for DCS control cycle according to an embodiment of the present invention. Figure 2 This is a schematic diagram of the structure of a redundant link switching control system oriented to DCS control cycle in one embodiment of the present invention.
[0017] The following detailed description, in conjunction with the accompanying drawings, will further illustrate the present invention. Detailed Implementation
[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Unless otherwise defined, the technical or scientific terms used herein should have the ordinary meaning understood by those skilled in the art. The terms "comprising" and similar expressions used herein mean that the element or object preceding the word covers the element or object listed after the word and its equivalents, but does not exclude other elements or objects.
[0019] Example 1 like Figure 1 As shown, an embodiment of the present invention proposes a redundant link switching control method for DCS control cycles, the method including steps S101 to S105, wherein: Step S101: Establish a service session at both ends of the DCS communication link, assign a unique session identifier (SID) to the service session, and obtain the control cycle of the DCS system; In a DCS system, services such as control command issuance and measurement point data transmission all rely on the session channel between the two ends of the communication link. This step first establishes a service session between the two communicating parties and assigns a globally unique session identifier (SID) to this session. This SID is used to uniquely identify the service flow throughout the handover process, avoiding confusion between multiple sessions. Simultaneously, the control cycle of the DCS system is obtained. This cycle is the core time reference for the DCS system to issue control commands, typically ranging from milliseconds to hundreds of milliseconds. The purpose of obtaining the control cycle is to provide a basis for calculating the upper bound of the subsequent handover window, coupling the delay constraints of the handover process with the control cycle, thereby ensuring that the handover operation does not exceed the real-time performance range tolerated by the DCS system.
[0020] Step S102: Configure a primary link and at least one backup link, obtain the operating status of the primary link every first preset time, and determine whether the primary link needs to be switched based on the operating status; It should be noted that, to improve the reliability of the DCS control area network, a primary link must be pre-configured to carry current service sessions, while at least one backup link must be configured as a failover channel in case of primary link failure. The system actively acquires the operating status of the primary link at preset time intervals (e.g., every one or more control cycles). These operating statuses include, but are not limited to, packet loss rate, transmission latency, latency jitter, number of consecutive link probe failures, and number of security anomalies. By comparing these operating statuses with their respective preset thresholds, the system can determine in real time whether the primary link has experienced quality degradation, interruption, or security attacks, thereby deciding whether to trigger link switching. This multi-dimensional, periodic status monitoring mechanism avoids misjudgment or omission based on a single indicator, ensuring the accuracy and timeliness of switching decisions.
[0021] Specifically, in some embodiments, it is determined whether the packet loss rate of the main link is greater than a preset packet loss rate threshold, and / or whether the transmission delay of the main link is greater than a preset delay threshold, and / or whether the delay jitter of the main link is greater than a preset jitter threshold, and / or whether the number of consecutive link probe failures of the main link is greater than a preset interruption threshold, and / or whether the number of security anomalies of the main link is greater than a preset security threshold, wherein the security anomalies include authentication failure, signature verification failure, or replay attack; If the packet loss rate of the main link is greater than a preset packet loss rate threshold, and / or the transmission delay of the main link is greater than a preset delay threshold, and / or the delay jitter of the main link is greater than a preset jitter threshold, and / or the number of consecutive link probe failures of the main link is greater than a preset interruption threshold, and / or the number of security anomalies of the main link is greater than a preset security threshold, then it is determined that the main link needs to be switched.
[0022] For example, a preset packet loss rate threshold is used. Set the latency threshold to 1%–10%. Pick to Preset jitter threshold Pick to Preset interruption threshold Take 1–5.
[0023] Step S103: If the main link needs to be switched, the control cycle of the DCS system is obtained, and the upper limit of the switching window is calculated according to the control cycle. Within the upper limit of the switching window, the key operating status of the service session is migrated from the main link to the selected target link. The key operating status includes at least the session identifier SID, the current sending sequence number, and the current receiving sequence number assigned to the current session. It should be noted that the upper bound of this switching window and the control cycle satisfy the following: ; in, To switch the upper bound of the window, To control the cycle.
[0024] Furthermore, the key steps of the switchover process—"state freeze, migration, consistency confirmation, and effective switchover"—are all within... Completed within the specified time.
[0025] Furthermore, the upper bound of the handover window specifies the maximum allowed time from handover triggering to handover completion, ensuring that the entire handover process is completed within a defined time window coordinated with the control cycle, thereby avoiding the impact of uncontrollable handover time on the stability of the control loop. Subsequently, within the upper bound of the handover window, one of at least one backup link is selected as the target link, and the critical operating states of the current service session are migrated from the primary link to the target link. These critical operating states include at least the Session Identifier (SID), the current transmitted sequence number, and the current received sequence number, where the transmitted and received sequence numbers are used to ensure the orderliness and replay resistance of packets after the handover. By migrating these core states, the session after the handover can continue the operating state before the handover, avoiding service anomalies such as sequence number mismatch, duplicate control, or broken deduplication windows.
[0026] In addition, in some embodiments, a freeze time needs to be set at the start of the handover to suspend the status update of the current service session on the main link; and at the freeze time, a snapshot of the key operating status of the current service session is recorded, the snapshot record including at least the session identifier SID, the current sending sequence number, and the current receiving sequence number; and the snapshot record is sent from the main link to the selected target link.
[0027] Furthermore, in some embodiments, the handover process includes a preparation phase, which at least includes: performing reachability detection and capability assessment on the backup link; and pre-establishing session contexts or pre-allocating session contexts on the backup link side. Mapping; pre-synchronizing at least a portion of the session migration set without affecting existing network services. This session migration set session identifier Key version or session version (If a security tag or tunnel key version exists), transmission sequence number With the received sequence number Anti-replay window parameters or its configuration parameters Disorder tolerance Business priority or queue status Strategy level or handling status (If risk-driven measures exist). To ensure the continuity and effectiveness of deduplication, fault tolerance, and handling strategies after the switchover.
[0028] In addition, in some embodiments, after migration, it is necessary to continuously observe N control cycles on the target link side and verify whether the following three conditions are met simultaneously in each control cycle: the service message is processed normally, no duplicate control instructions appear, and the anti-replay window can be continuously updated; if they are met simultaneously in N consecutive control cycles, the switching status is marked as switching complete; if any condition is not met, the switching is determined to be abnormal, and the switching is re-performed or the user is pushed back to the original main link.
[0029] Step S104: After the migration is completed, perform a consistency check on the migrated session state on the target link side; After the state transition is complete, a consistency check must be performed on the target link side to verify the completeness and correctness of the transition process, preventing the risk of "continued operation in an erroneous state" due to transition errors. Specifically, the target link side recalculates a checksum based on the received key operational state and compares this checksum with the state digest carried during the transition. If they match, it indicates that the state has not been tampered with, lost, or damaged during the transition, and the transition result is reliable; if they do not match, it indicates that there is an error in the transition, and subsequent exception handling procedures need to be triggered. This verification mechanism ensures that the session state after the switch remains strictly consistent with the state before the switch, laying a reliable foundation for the correct processing of subsequent business messages.
[0030] In some embodiments, the migrated key operating status is first obtained, and a status summary is generated based on the key operating status; then the status summary is sent to the target link side along with the key operating status, so that the target link side can recalculate a verification summary based on the received key operating status; then the verification summary is compared with the status summary, and if the two are consistent, the verification is determined to be successful, and if they are inconsistent, the verification is determined to be unsuccessful.
[0031] Specifically, state summary Generate as follows:
[0032] in, Metadata, including at least one of the following: freeze point timestamp, link identifier, or policy profile, is used to improve the interpretability and tamper resistance of consistency verification. It is the national cryptographic hash algorithm. For session identification, This refers to either the key version or the session version, used if a security tag or tunnel key version exists. The sequence number is used to identify the sequence number of messages that have been sent in the current session. The received sequence number identifies the sequence number of the message that has been received in the current session. For anti-replay window parameters, For out-of-order tolerance, Metadata, including at least one of the following: freeze point timestamp, link identifier, or policy profile, is used to improve the interpretability and tamper resistance of consistency verification.
[0033] Furthermore, in some embodiments, consistency verification includes at least: the target link side based on the received... Recalculate state summary and the original state summary Compare; if they match, the migration is considered successful and the switch is activated; otherwise, the migration is considered a failure and a rollback / downgrade strategy is triggered.
[0034] In addition, the rollback strategy includes at least one of the following: rolling back to the original main link and restoring the state before the freeze point; re-performing the state transition and limiting the number of retries. ,in Select 1–3; downgrade the service to monitoring-only or read-only mode and issue an alert.
[0035] Degradation strategies should include at least the following: prioritizing the processing and bandwidth of control-related services, limiting the frequency of operation and maintenance-related or non-critical write operations, suspending or transferring high-risk write operations to manual confirmation, and recording the reasons for degradation and recovery conditions in the audit.
[0036] In addition, successful handover confirmation includes: continuous connection on the target link side. Once the conditions of "processable service messages + no duplicate control + continuous update of anti-replay window" are met within a control cycle, the switching state will be set to complete. Take values from 1 to 10.
[0037] Furthermore, in some embodiments, a short-term overlap window is configured to reduce the risk of transient handover interruptions. ,exist The system allows the primary link and the backup link (target link) to receive the same service flow in parallel, and:
[0038] The receiving end selects and deduplicates based on "unrepeated sequence number + version that has passed consistency".
[0039] Deduplication and selective acceptance should include at least the following: To remove duplicate primary keys; when two links receive the same... Prioritize the one with the shorter latency; when a version field exists. The system prioritizes newer versions of messages that have passed consistency checks.
[0040] In addition, in some embodiments, a version compatibility set is set to support short-term compatibility during the handover period. Compatible windows ,in And satisfy:
[0041] exist It allows parallel processing of old and new versions, exceeding [a certain limit]. Only newer versions will be accepted from now on.
[0042] Step S105: If the consistency check passes, the service message is switched from the main link to the target link for continued transmission. If the consistency check fails, the switch is abandoned and a downgrade processing strategy is executed.
[0043] If the verification passes, it indicates that the session state on the target link is consistent with the primary link. At this point, the system switches the service packets from the primary link to the target link for continued transmission. All subsequent packets belonging to this session are sent and received through the target link, thus achieving the dual goals of link redundancy switching and service continuity. If the verification fails, the switch is abandoned to avoid unpredictable service errors caused by continuing to switch under inconsistent states. Simultaneously, the system executes degradation handling strategies, such as limiting the number of retries and downgrading the service session to read-only mode. In read-only mode, the system only allows viewing data and does not allow issuing control commands, thereby preventing the security risks of writing operations under fault conditions while ensuring monitoring capabilities, achieving controllable convergence in fault situations.
[0044] In addition, in some embodiments, if the consistency check fails, it is determined whether the current number of retries has reached the preset maximum number of retries; if the maximum number of retries has not been reached, the migration from the main link to the target link is re-executed and the number of retries is incremented by 1; if the maximum number of retries has been reached, the service session is downgraded to read-only mode.
[0045] In summary, this invention will optimize the DCS control cycle. Introduce a redundant handover process and define an upper bound for the handover window. Furthermore, it constrains key handover processes to complete within a defined time window, giving handover time an upper bound, thereby reducing the risk of uncontrollable latency and jitter caused by handover; and it migrates a clearly defined set of session states. And generate a state summary Consistency checks are performed to ensure the continuity and effectiveness of session identifiers, sequence numbers, anti-replay windows, out-of-order tolerance, and policy states after handover, avoiding service anomalies caused by sequence number mismatches, duplicate control, or broken deduplication windows. When migration fails, convergent handling is achieved through rollback and degradation strategies to prevent erroneous operation or frequent oscillating handovers, and priority is given to ensuring the stability of control services during degradation. The optional short-term overlapping window mechanism supports parallel reception of primary and backup and deduplication selection, further reducing the impact of handover interruptions and concentrated packet loss on the control loop. At the same time, this invention forms traceable audit records and evidence chains for the processes of triggering, migration, verification, rollback / degradation, and completion, facilitating operation and maintenance audits and fault location, thereby comprehensively improving the real-time guarantee capability, service continuity, and operational reliability of redundant network handover in the power plant's DCS control area.
[0046] like Figure 2 As shown, an embodiment of the present invention proposes a redundant link switching control system oriented to DCS control cycle, characterized in that the system includes: Session establishment module 10 is used to establish a service session at both ends of the DCS communication link, assign a unique session identifier (SID) to the service session, and obtain the control cycle of the DCS system. The switching detection module 20 is used to configure a main link and at least one backup link, acquire the operating status of the main link every first preset time, and determine whether the main link needs to be switched based on the operating status. The switching execution module 30 is used to obtain the control cycle of the DCS system if the main link needs to be switched, calculate the upper bound of the switching window according to the control cycle, and migrate the key operating status of the service session from the main link to the selected target link within the upper bound of the switching window. The key operating status includes at least the session identifier SID, the current sending sequence number, and the current receiving sequence number assigned to the current session. The verification module 40 is used to perform consistency verification on the migrated session state on the target link side after the migration is completed. The degradation module 50 is used to switch the service message from the main link to the target link for continued transmission if the consistency check passes, and to abandon the switch and execute the degradation processing strategy if the consistency check fails.
[0047] Example 3 An embodiment of the present invention also proposes a storage medium on which one or more programs are stored, which, when executed by a processor, implement the above-described redundant link switching control method for DCS control cycles.
[0048] Example 4 An embodiment of the present invention also proposes an electronic device, including a memory and a processor, wherein the memory is used to store a computer program, and the processor is used to execute the computer program stored in the memory to implement the above-mentioned redundant link switching control method oriented to DCS control cycle.
[0049] Those skilled in the art will understand that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can mean any means that can contain stored, communicated, propagated, or transmitted programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0050] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0051] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0052] While embodiments of the present invention have been described in detail above, it will be apparent to those skilled in the art that various modifications and variations can be made to these embodiments. However, it should be understood that such modifications and variations fall within the scope and spirit of the invention as set forth in the claims. Furthermore, the invention described herein may have other embodiments and can be implemented or carried out in various ways.
Claims
1. A redundant link switching control method oriented towards DCS control cycle, characterized in that, The method includes: Establish service sessions at both ends of the DCS communication link, assign a unique session identifier (SID) to the service session, and obtain the control cycle of the DCS system; Configure one primary link and at least one backup link, obtain the operating status of the primary link every first preset time interval, and determine whether the primary link needs to be switched based on the operating status; If the main link needs to be switched, the control cycle of the DCS system is obtained, and the upper limit of the switching window is calculated according to the control cycle. Within the upper limit of the switching window, the key operating status of the service session is migrated from the main link to the selected target link. The key operating status includes at least the session identifier SID, the current sending sequence number, and the current receiving sequence number assigned to the current session. After the migration is completed, a consistency check is performed on the migrated session state on the target link side; If the consistency check passes, the service message will be switched from the main link to the target link for continued transmission. If the consistency check fails, the switch will be abandoned and a degradation processing strategy will be implemented.
2. The redundant link switching control method for DCS control cycle according to claim 1, characterized in that, The step of acquiring the operating status of the main link every first preset time interval and determining whether the main link needs to be switched based on the operating status includes: The system determines whether the packet loss rate of the main link is greater than a preset packet loss rate threshold, and / or whether the transmission delay of the main link is greater than a preset delay threshold, and / or whether the delay jitter of the main link is greater than a preset jitter threshold, and / or whether the number of consecutive link probe failures of the main link is greater than a preset interruption threshold, and / or whether the number of security anomalies of the main link is greater than a preset security threshold. The security anomalies include authentication failure, signature verification failure, or replay attack. If the packet loss rate of the main link is greater than a preset packet loss rate threshold, and / or the transmission delay of the main link is greater than a preset delay threshold, and / or the delay jitter of the main link is greater than a preset jitter threshold, and / or the number of consecutive link probe failures of the main link is greater than a preset interruption threshold, and / or the number of security anomalies of the main link is greater than a preset security threshold, then it is determined that the main link needs to be switched.
3. The redundant link switching control method for DCS control cycle according to claim 2, characterized in that, The steps of obtaining the control cycle of the DCS system and calculating the upper bound of the switching window based on the control cycle include: The upper bound of the switching window and the control cycle satisfy the following: ; in, To switch the upper bound of the window, To control the cycle.
4. The redundant link switching control method for DCS control cycle according to claim 2, characterized in that, The step of migrating the critical operating state of the service session from the main link to the selected target link within the upper bound of the switching window includes: A freeze time is set at the start of the switchover to pause the status update of the current service session on the main link; At the time of the freeze, a snapshot of the key operating state of the current business session is recorded. The snapshot record includes at least the session identifier (SID), the current sent sequence number, and the current received sequence number. The snapshot record is sent from the main link to the selected target link.
5. The redundant link switching control method for DCS control cycle according to claim 1, characterized in that, The steps for performing consistency verification of the migrated session state on the target link side include: Obtain the key operational states that have been migrated, and generate a status summary based on the key operational states; The status digest is sent to the target link side along with the key operational status, so that the target link side can recalculate a check digest based on the received key operational status. The verification digest is compared with the status digest. If they match, the verification is deemed successful; otherwise, the verification is deemed unsuccessful.
6. The redundant link switching control method for DCS control cycle according to claim 1, characterized in that, The steps for abandoning the switch and implementing a degradation processing strategy if the consistency check fails include: Determine if the current number of retries has reached the preset maximum number of retries; If the maximum number of retries has not been reached, the migration from the main link to the target link will be re-executed, and the number of retries will be incremented by 1. If the maximum number of retries has been reached, the service session will be downgraded to read-only mode.
7. The redundant link switching control method for DCS control cycle according to claim 2, characterized in that, The step of migrating the critical operational state of the service session from the main link to the selected target link within the upper bound of the switching window further includes: Observe N control cycles continuously on the target link side, and verify whether the following three conditions are met simultaneously in each control cycle: The business message was processed normally, no duplicate control commands were issued, and the anti-replay window was able to be continuously updated; If the conditions are met simultaneously for N consecutive control cycles, the switching status will be marked as switching complete. If any condition is not met, the handover is deemed abnormal, and a new handover or rollback to the original main link will be performed.
8. A redundant link switching control system oriented towards DCS control cycle, characterized in that, The system includes: The session establishment module is used to establish a service session at both ends of the DCS communication link, assign a unique session identifier (SID) to the service session, and obtain the control cycle of the DCS system. The switching detection module is used to configure a primary link and at least one backup link, acquire the operating status of the primary link every first preset time, and determine whether the primary link needs to be switched based on the operating status. The switching execution module is used to obtain the control cycle of the DCS system if the main link needs to be switched, calculate the upper bound of the switching window according to the control cycle, and migrate the key operating status of the service session from the main link to the selected target link within the upper bound of the switching window. The key operating status includes at least the session identifier SID, the current sending sequence number, and the current receiving sequence number assigned to the current session. The verification module is used to perform consistency verification of the migrated session state on the target link side after the migration is completed; The degradation module is used to switch the service packets from the main link to the target link for continued transmission if the consistency check passes, and to abandon the switch and execute the degradation processing strategy if the consistency check fails.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, wherein: The memory is used to store computer programs; When the processor executes the computer program stored in the memory, it implements the redundant link switching control method for DCS control cycle as described in any one of claims 1-7.
10. A storage medium, characterized in that, The storage medium stores one or more programs that, when executed by a processor, implement the redundant link switching control method for DCS control cycles as described in any one of claims 1-7.