Control system for a technical installation, and operating method
Patent Information
- Application Number
- EP2023777163
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-11-07
- Filing Date
- 2023-09-19
- Publication Date
- 2025-07-02
AI Technical Summary
Existing control systems for technical modules in process engineering require complex manual processes for reworking and upgrading system images, especially when integrating package units, leading to inefficiencies and increased orchestration efforts across different systems.
A control system with a container service on the operator station server that continuously receives and updates the system image from technical modules, allowing for dynamic visualization and monitoring without permanent integration into project planning software, using OPC UA standard for data exchange and incorporating a protection mechanism for identity and integrity validation.
This approach simplifies the integration and operation of technical modules by eliminating the need for error-prone system images and reducing orchestration efforts, enabling flexible and efficient operation and monitoring of technical systems with minimal integration effort, while ensuring the integrity and authenticity of system images.
Smart Images

Figure 1.1
Abstract
Description
[0001] Description
[0002] Control system for a technical plant and operating procedures
[0003] The invention relates to a control system for a technical plant, in particular a manufacturing or processing plant. Furthermore, the invention relates to the use of a control system for operating a technical plant.
[0004] Modern requirements for greater flexibility and scalability in process engineering plants lead to plant components being developed separately as small units – so-called "package units" or "technical modules." Entire process engineering plants are then created by combining individual package units. Batch systems on operator station servers, for example, are used to control and orchestrate the processes between the individual package units.
[0005] In addition to the modularity in the development of package units, they also offer advantages with regard to the dynamics of a process plant - for example, if after the production of one batch the plant is reorganized for the production of another batch (reallocation).
[0006] A package unit is a modular plant component that can be integrated into a central engineering system as a self-contained unit. Package units are more comprehensive than measuring points or technical equipment. Sometimes a package unit is even an entire sub-plant with a complete process structure that includes several technical equipment (e.g., tanks), which in turn contain several measuring points (e.g., valves, monitors, controllers, motors, etc.).
[0007] The following problem occurs with known control systems that orchestrate technical modules or package units: The plant diagrams of the orchestration are usually created when a description of the package unit is imported into an engineering environment of a control system in the respective technology for operation and monitoring of the control system. Since the descriptions of the plant diagrams are often very generic, for example when using the MTP standard VDI / VDE / NAMUR 2658 (Module Type Package), and have a smaller scope of objects than conventional control systems, complex manual reworking and upgrading is often necessary after creation. In addition, the described process must be repeated for each plant in which the package unit is to be used.
[0008] EP 3 712 730 A1 discloses a method for orchestrating individual technical modules for operating a process plant.
[0009] The invention is therefore based on the object of specifying a control system for a technical system which increases the efficiency and flexibility of operation and monitoring of a technical system operated with technical modules.
[0010] This object is achieved by a control system for a technical installation having the features of claim 1. In addition, the object is achieved by a technical system having the features of claim 5. Furthermore, the object is achieved by a technical module having the features of claim 9. In addition, the object is achieved by using a control system for operating a technical installation according to claim 13, by using a technical system for operating a technical installation according to claim 14 and by using a technical module for operating a technical installation according to claim 15. Advantageous further developments arise from the dependent claims.The control system according to the invention for a technical installation, in particular a manufacturing or process installation, comprises at least one operator station server and at least one operator station client connected to the operator station server, wherein the operator station server is designed to transmit visualization information to the operator station client, and wherein the operator station client is designed to generate a graphic representation for an operator of the technical installation by means of the visualization information.
[0011] The control system is characterized in that it has a container service implemented on the operator station server, which is designed to reference a technical module with a plant image for operating and monitoring the technical module and to continuously receive the plant image from the technical module, wherein the control system is designed to continuously add the plant image to the graphical presentation for the operator of the technical plant at a runtime of the technical plant.
[0012] The technical plant can be a plant from the process industry, such as a chemical, pharmaceutical, petrochemical plant, or a plant from the food and beverages industry. This also includes any plant from the production industry, plants in which, for example, cars or goods of all kinds are produced. Technical plants suitable for carrying out the method according to the invention can also come from the field of energy generation. Wind turbines, solar systems, or power plants for energy generation are also encompassed by the term "technical plant."
[0013] In this context, a control system is understood to be a computer-aided, technical system that includes functionalities for displaying, operating, and managing the technical plant. The control system can also include sensors for determining measured values as well as various actuators. In addition, the control system can include so-called process- or production-related components that are used to control the actuators or sensors. In addition, the control system can, among other things, have means for visualizing the process plant and for engineering. The control system can optionally also include additional processing units for more complex controls and systems for data storage and processing.
[0014] An "operator station server" is understood here to be a server that centrally records data from an operating and monitoring system, as well as usually alarm and measured value archives from a process control system of a technical plant, and makes them available to users. The operator station server usually establishes a communication connection to the automation systems of the technical plant and forwards data from the technical plant to so-called operator station clients, which are used to operate and monitor the operation of the individual functional elements of the technical plant.
[0015] The operator station server can have client functions to access the data (archives, messages, tags, variables) of other operator station servers. This allows images of the operation of the technical plant on the operator station server to be combined with variables from other operator station servers (server-to-server communication). The operator station server can be, but is not limited to, a SIMATIC PCS 7 Industrial Workstation Server from SIEMENS.
[0016] The control system is designed to visually display the plant image provided by the technical module, wherein the plant image represents the technical module for operating and monitoring the technical plant. In the case of a technical module for a process plant, such a plant image can, for example, include graphic representations of pumps, valves, tanks, pipelines, combustion chambers, or the like. The graphic representations can include current process measured values, status values, (alarm) messages, or the like.
[0017] The control system according to the invention provides a container service which provides the operator of a control system with the possibility of accessing the operation and observation of the technical module in a suitable form of representation.
[0018] In contrast to conventional control systems, the plant diagram for operating and monitoring the technical module is not (permanently) integrated into the planning software as part of the technical plant's design. Rather, the plant diagram (or diagrams) are provided on the technical module itself as a central interface for the operator to operate and monitor the technical module. This means that the associated application is executed by the technical module—and not by the control system or its operator station server.
[0019] For this purpose, the control system according to the invention provides a corresponding container (service) that references the plant image of the technical module and receives it continuously. Continuously means that the plant image is continuously updated by the technical module and transmitted, particularly in certain periods, to the container service on the operator station server. For data exchange between the technical module and the control system or its operator station server, a connection based on the OPC UA standard can be used, for example.
[0020] The invention has the advantage that plant diagrams imported into the control system, modified and possibly containing errors, can be dispensed with for the orchestration of the technical module (or modules). In particular, technical modules which, due to their structure, contain extensive automation hardware, such as operator station servers, can be integrated into a common orchestration more easily and with error-minimized integration effort using the control system according to the invention. Furthermore, the control system according to the invention can be an important building block in the implementation of so-called plug & produce solutions, in which orchestration effort in the context of integrating technical modules into a control system is to be minimized.
[0021] Preferably, the control system is designed to receive an input from the operator relating to the system image via the operator station client during a runtime of the technical system and to transmit it to the container service on the operator station server, wherein the container service is designed to transmit the operator's input to the technical module, wherein the input is designed in particular for controlling a technical functionality of the technical module.
[0022] The container service enables the operator to make an input in the graphical display provided by the Operator Station Client (i.e. the graphical interface for operating and monitoring the technical system) which affects the plant diagram of the technical module. To do this, the container service can, for example, create a window in the graphical display in which the plant diagram is shown in the usual way. The operator can then carry out all the usual operations for operating and monitoring plant diagrams - as if the plant diagram were being calculated and made available directly by the control system. The difference to previously known control systems, however, is that the operator's input, for example adjusting a controller or changing a parameter, does not affect a plant diagram generated by the operator's own control system, but rather a plant diagram generated by the technical module.
[0023] Within the scope of a preferred development of the invention, the container service is designed to receive, in addition to the system image, further information related to the system image from the technical module and, in particular upon request from the operator, to store it in a computer-implemented memory of the control system. The container service can receive the additional information via a corresponding interface and make it available to both the memory and possible other components or services of the control system for processing.
[0024] The information preferably takes the form of alarm messages, with the control system being designed to integrate the alarm messages into the control system's alarm management system. This allows the operator to easily obtain a direct overview of possible alarms occurring within the technical module. An alarm message is a message that generally requires an immediate response from an operator. A message is understood to be a report of the occurrence of an event that represents a transition from one discrete state within the technical module to another discrete state.
[0025] The previously formulated problem is additionally solved by a technical system, comprising a control system as explained above and a technical module connected to it, wherein a container application is implemented in a computing environment of the technical module and during the execution of this container application the plant image belonging to the technical module is continuously transmitted to the container service of the control system for operation and monitoring of the technical module. The plant image (or images) required for operation and monitoring is created and continuously updated on the technical module itself. A container application of the technical module makes the plant image available to the container service of the control system, for example via an OPC UA connection.
[0026] Preferably, the operator station server of the control system has a digital image of the technical plant and the technical module has a digital image of the technical module, wherein the control system and the technical module are each designed to continuously compare the respective digital images with one another, in particular in specified journals. In the case of a process plant or a technical module for a process plant, the current process measured values, status and other information of the individual process devices are shown in such digital images. The comparison enables, among other things, joint archiving or automatically coordinated orchestration via flow charts or scripts by the orchestrating operator station server of the control system.
[0027] Within the scope of a preferred development of the invention, the plant image transmitted by the technical module to the container service of the control system and the container application implemented in the computing environment of the technical module have a protection mechanism for verifying their identity, integrity, and authenticity. Preferably, the identity and integrity check of the plant image and the container application implemented in the computing environment of the technical module is performed each time the plant image is retransmitted to the container service of the control system.
[0028] The protection mechanism can comprise a private key (secret key or private key) securely stored in the technical module, an identification certificate issued by a manufacturer or a user of the technical module and made available to the container service of the control system, and a certificate chain, wherein the certificate chain comprises:
[0029] - a certificate from a certification authority that issued the identification certificate,
[0030] - a certificate from a root certification authority superior to the certification authority, and, if applicable,
[0031] - Certificates from intermediate certification authorities that lie in the certificate chain between the certification authority and the root certification authority.
[0032] One possible way the protection mechanism works is as follows: After each update of the plant image, the plant image is signed using the above-mentioned certificate. It should be noted that the above-mentioned certificate contains, in particular, the public key for the above-mentioned private key. This means that the above-mentioned signature can be validated by default (according to RFC 5280) using the above-mentioned certificate and, in particular, the public key contained in the certificate as well as the associated certificate chain. The integrity and authenticity of the plant image are checked using the signature validation. If it is determined that the signature is invalid or does not match the plant image, this indicates unauthorized tampering. In this case, the plant image is rejected as unauthorized tampering.
[0033] Each time the asset image is made available, which was signed (as explained above) using the private key stored in the technical module, the container service validates the integrity and authenticity of the asset image by validating the signature using the associated public key and certificate chain.
[0034] In addition, the identity, integrity, and authenticity of the aforementioned container application, which provides the system image to the container service, can be verified in an identical manner each time the system image is made available by the container service. Analogous to the private key used to sign the system image, a private key securely stored in the technical module is required for this purpose. The public key required for signature validation is contained in an associated certificate issued by a trusted authority (such as the manufacturer or user of the module). Furthermore, each authority that is to validate the signature must have access to the associated certificate chain.
[0035] In one possible implementation scenario, the same private key can be used to sign plant images and to sign the container application. However, other scenarios, for example, using different private keys, are also conceivable.
[0036] In another possible implementation scenario, the IDevID certificate (according to IEEE 802.1AR) can be used as the module's manufacturer-issued identification certificate to sign the plant images and / or the container application. Alternatively, in another implementation scenario, the LDevID certificate (according to IEEE 802.1AR) issued by the module's user / operator can be used for this purpose.
[0037] The previously formulated problem is also solved by a technical module having a computing environment in which a container application is implemented in an executable manner, during the execution of which a plant image belonging to the technical module for operation and monitoring of the technical module can be continuously transmitted to a container service of a control system connectable to the technical module. Preferably, the technical module is designed to transmit, in addition to the plant image, further information belonging to the plant image from the technical module to the control system. This information can be alarm messages.
[0038] Most preferably, the technical module is designed to receive an operator input relating to the system image from the control system, wherein the input is designed in particular to control the operation of a technical functionality of the technical module.
[0039] The previously formulated task is also solved by the use of a control system as previously explained for the operation of a technical plant, in particular a manufacturing or process plant.
[0040] The previously formulated task is also solved by the use of a technical system as previously explained for the operation of a technical plant, in particular a manufacturing or process plant.
[0041] The previously formulated task is also solved by using a technical module as previously explained for operating a technical plant, in particular a manufacturing or process plant.
[0042] The above-described properties, features, and advantages of this invention, as well as the manner in which they are achieved, will become clearer and more readily understandable in connection with the following description of exemplary embodiments, which are explained in more detail in connection with the drawings. FIG. 1 shows an object model of a technical module according to the invention;
[0043] FIG 2 shows an aspect of a technical system according to the invention; and
[0044] FIG 3 shows a control system according to the invention in a schematic representation.
[0045] FIG. 1 shows an object model 1 of a technical module 2. The technical module 2 has an interface definition 3 and l . . k components 4, each of which has a technical functionality. For example, a component 4 can be a stirrer with a stirring functionality, a heater with a heating functionality, or a mixer with a mixing functionality. The interface definition 3 contains, among other things, information about how data can be exchanged with the technical module 2.
[0046] In the technical module 2, l . . m plant images 5 are projected, each of which makes a partial aspect of the technical functionality of the technical module 2 operable and observable. The technical module has a container application 6 that references a plant image service 7 of the technical module 2. In previously known technical modules, the plant images 5 are transmitted to a higher-level orchestration instance (such as a control system) together with further descriptions of the technical module 2. In the present case, however, the container application 6 only creates a container, i.e. a type of empty plant image, which is provided with a reference to the plant image service 7.If the container is integrated into a control system's operation and monitoring system, the control system can access the plant image generated and continuously updated by the plant image service 7 of the technical module 2 for the operation and monitoring of the technical module 2 (cf. FIGS. 2 and 3). A certification authority 8 of the manufacturer / user / operator of the technical module 2 has provided the technical module 2 with a certificate issued using the private key securely stored in the technical module, and with the associated certificate chain. The specifications of IEEE 802.1AR may have been applied to the above-mentioned private key.
[0047] This private key can be used in combination with the public key contained in the associated certificate to protect the integrity / authenticity of the system images and / or the container application. As explained above, multiple private keys can be used for different purposes.
[0048] FIG 2 shows the interaction between the technical module 2 and a control system 11. The control system 11 has a plant image display service 9 which (among other things) provides a variable display element 10. The information received from the container application 6 of the technical module 6 is implemented in this display element 10. In concrete terms, this means that the plant image provided ("hosted") by the plant image service 7 of the technical module 2 is displayed graphically so that an operator of the control system 11 can operate and monitor the technical module 2 via this. The bidirectional connection 12 between the technical module 2 and the control system 11 can be designed according to the OPC UA standard, including bilateral authentication, i.e., a check of integrity and authenticity.
[0049] In FIG. 3, on the right-hand side of the figure, the control system 11 for operating and monitoring a technical system designed as a process plant is schematically shown. The control system 11 comprises an operator station server 13 and an operator station client 14. The operator station server 13 and the operator station client 14 are connected to one another via a terminal bus 15 and optionally to other components of the control system 11 (not shown), such as an archive server or an engineering station server.
[0050] For the purpose of operating and monitoring, a user or operator can access the operator station server 13 via the operator station client 14 using the terminal bus 15. The terminal bus 15 can, for example, be configured as an Industrial Ethernet, but is not limited to this.
[0051] On the left side of the image in FIG 3, the technical module 2 is shown. It also has a connection to the terminal bus 15. The technical module 2 has a device interface 16 which is connected to a plant bus 17. Via this device interface 16, the technical module 2 is connected to an automation device 18 and to other components of the process plant, such as peripheral devices 19, and can communicate with them. The plant bus 17 can, for example, be designed as Industrial Ethernet, without being limited thereto.
[0052] The technical module 2 and the operator station server 13 of the control system 11 have an OPC UA interface 20, 21, each of which is connected to the plant bus 17. A visualization service 22, 23, a process image 24, 25, and a memory 26, 27 are implemented (among other things) on the operator station server 13 and the technical module 2.
[0053] The visualization service 23 integrated in the operator station server 13 initiates a transmission of visualization information to the operator station client 14. The operator station client 14 is designed to display a visualization, i.e. a graphical representation, in particular of plant images, for operating and monitoring the process plant. A snapshot of the (signal) states of the connected devices and / or applications is stored in the process image 24, 25. The process images 24, 25 of the technical module 2 and the control system 11 are continuously compared with one another via the OPC UA interfaces 20, 21.
[0054] The container application 6 provides a container service 28 of the control system 11 with the empty container containing the reference to the plant image provided by the plant image service 7 of the technical module 2. The container service 28 transmits this information both to the memory 27 and to the plant image display service 9a, 9, which consists of a server part 9a and a client part 9. The plant image display service 9a, 9 then graphically displays the window application 10 with the plant image of the technical module 2 referenced therein for an operator of the control system 11.
[0055] An alarm service 29 of the control system 11 accesses the information stored in the memory 27 regarding the system image of the technical module 2 and extracts any alarm messages from it. These are then transmitted to the operator station client 14 in order to present the alarm messages associated with the technical module 2 to the operator visually and, if necessary, acoustically.
[0056] Operator inputs relating to the plant image, which the operator can enter directly in the window application 10, are transmitted via the container service 28 of the control system 1 to the container application 6 of the technical module 2. The actions requested by the operator are then carried out in the technical module 2. In particular, the operator can request the technical functionality of one of the components 4 of the technical module 2. Although the invention has been illustrated and described in detail by the preferred embodiment, the invention is not limited by the disclosed examples, and other variations can be derived therefrom by a person skilled in the art without departing from the scope of the invention.
Claims
Patent claims 1. A control system (11) for a technical plant, in particular a manufacturing or process plant, comprising at least one operator station server (13) and at least one operator station client (14) connected to the operator station server (13), wherein the operator station server (13) is designed to transmit visualization information to the operator station client (14), and wherein the operator station client (14) is designed to generate a graphical representation for an operator of the technical plant using the visualization information, characterized in that the control system (11) has a container service (28) implemented on the operator station server (13), which is designed to continuously receive a plant image provided by a technical module (2) for operating and monitoring the technical module (2), wherein the control system (11) is designed tocontinuously add the plant image to the graphical presentation (10) for the operator of the technical plant at a runtime of the technical plant., 2. Control system (11) according to claim 1, which is designed to receive an input from the operator relating to the system image via the operator station client (14) during a runtime of the technical system and to transmit it to the container service (28) on the operator station server (13), wherein the container service (28) is designed to transmit the input from the operator to the technical module (2), wherein the input is designed in particular for controlling a technical functionality of the technical module (2).
3. Control system (11) according to one of the preceding claims, in which the container service (28) is designed to receive, in addition to the system image, further information belonging to the system image from the technical module (2) and, in particular upon a request from the operator, to store it in a computer-implemented memory (27) of the control system (11).
4. Control system (11) according to claim 3, wherein the information is alarm messages, wherein the control system (11) is designed to integrate the alarm messages into an alarm management system (29) of the control system (11).
5. Technical system, comprising a control system (11) according to one of the preceding claims and a technical module (2) connected thereto, wherein a container application (6) is implemented in a computing environment of the technical module (2) in an executable manner, during the execution of which the system image belonging to the technical module (2) for the operation and observation of the technical module (2) is continuously transmitted to the container service of the control system (11).
6. Technical system according to claim 5, wherein the operator station server (13) of the control system (11) has a digital image (25) of the technical system and the technical module (2) has a digital image (24) of the technical module (2), wherein the control system (11) and the technical module (2) are each designed to continuously compare the respective digital images (24, 25) with one another, in particular in fixed periods.
7. Technical system according to claim 5 or 6, in which the plant image transmitted from the technical module (2) to the container service (28) of the control system (11) and the executable implementation in the computing environment of the technical module (2) container application (6) must have a protection mechanism to prove its identity and integrity.
8. Technical system according to claim 7, wherein the protection mechanism comprises a private key securely stored in the technical module, an identification certificate issued by a manufacturer or a user of the technical module (2) and made available to the container service of the control system (11), and an associated certificate chain, wherein the certificate chain comprises: - a certificate from a certification authority that issued the certificate, - a certificate from a root certification authority superior to the certification authority, and, if applicable, - Certificates from intermediate certification authorities that lie in the certificate chain between the certification authority and the root certification authority.
9. Technical module (2) which has a computing environment in which a container application (6) is implemented in an executable manner, during the execution of which a system image belonging to the technical module (2) for operating and monitoring the technical module (2) can be continuously transmitted to a container service (28) of a control system (11) which can be connected to the technical module (2).
10. Technical module (2) according to claim 9, which is designed to transmit, in addition to the plant image, further information belonging to the plant image from the technical module (2) to the control system (11).
11. Technical module (2) according to claim 10, wherein the information is alarm messages.
12. Technical module (2) according to one of claims 9 to 11, which is designed to be controlled by the control system (11) to receive an operator input relating to the system image, wherein the input is designed in particular to control operation of a technical functionality of the technical module (2).
13. Use of a control system (11) according to one of claims 1 to 4 for operating a technical system, in particular a manufacturing or processing system.
14. Use of a technical system according to one of claims 5 to 8 for operating a technical system, in particular a manufacturing or processing system.
15. Use of a technical module (2) according to one of claims 9 to 12 for operating a technical plant, in particular a manufacturing or processing plant.