Plant monitoring control system and control method of plant monitoring control system

The system determines abnormality causes by analyzing operation history, distinguishing between external factors and malicious operators, ensuring safe and effective plant operation.

JP2025144690APending Publication Date: 2025-10-03MITSUBISHI ELECTRIC CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024044492
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-21
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Existing plant monitoring and control systems cannot differentiate between abnormalities caused by equipment failures, natural disasters, or malicious operators, and may inadvertently grant operation authority to malicious individuals.

Method used

A system that includes operator authentication, operation history storage, and emergency authority determination units to identify whether abnormalities are caused by external factors or malicious actors by analyzing operation history before the abnormality occurred.

Benefits of technology

Enables accurate determination of abnormality causes, allowing appropriate response based on the cause, preventing malicious operations and ensuring safe system operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025144690000001_ABST
    Figure 2025144690000001_ABST
Patent Text Reader

Abstract

To solve a problem that it cannot be determined whether abnormality is due to natural disaster or due to a malicious operator, when the abnormality occurs in a plant, conventionally.SOLUTION: A plant monitoring control system determines whether or not abnormality is due to operation from an operation history based on an operation request during a previously determined period, and notifies a worker having operation authority of an emergency state, when it is determined that the abnormality is not due to the operation.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a plant monitoring and control system and a control method for a plant monitoring and control system. [Background technology]

[0002] In a plant monitoring and control system, workers monitor the plant by monitoring numerical information from sensors and video information from inside or outside the plant on a screen, and as needed, control the pressure or temperature within the plant using input devices such as a mouse, touch panel, or keyboard. In recent years, due to heightened security awareness, an increasing number of monitoring and control systems have been equipped with functions for managing workers who use the monitoring and control system and managing the operations that each worker can perform. For example, a monitoring and control system is known that allows a worker to temporarily change the operating authority or the range of equipment that the worker can operate at their discretion, enabling the worker to respond to disasters or emergencies (see Patent Document 1). Another known system is one in which, when a fault is detected, the control system identifies a person capable of dealing with the fault, temporarily grants the person operating the faulty equipment, and notifies the identified person of the fault (see Patent Document 2). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-231473 [Patent Document 2] Japanese Patent Application Laid-Open No. 2011-210190 Summary of the Invention [Problem to be solved by the invention]

[0004] In the above-described system, when an abnormality occurs due to a failure or the like, it is impossible to determine whether the abnormality is due to a breakdown of equipment within the facility, a natural disaster, or the result of intentional operation by a malicious operator. Furthermore, if an operation is intentionally performed to cause an abnormality, allowing the operator to temporarily change the operation authority at their discretion as in Patent Document 1, there is a risk that a malicious operator who has been authenticated with operation authority could further expand the scope of the abnormality. Furthermore, even if the control system automatically identifies and grants operation authority to an operator who is capable of responding, rather than leaving the change of operation authority up to the operator as in Patent Document 2, it is impossible to identify a malicious operator who encourages abnormal operation, and the possibility of operation authority being granted to a malicious operator cannot be denied.

[0005] The present disclosure has been made to solve the above-mentioned problems, and aims to provide a plant monitoring and control system and a control method for a plant monitoring system that can determine whether an abnormality in the system is caused by an external factor such as a disaster or by a malicious actor by referring to the operation history before the abnormality occurred. [Means for solving the problem]

[0006] The monitoring and control system disclosed herein includes an operator authentication unit that authenticates operators based on authentication information input by an input device and information recorded in an operator information storage unit; an operation authority management unit that determines the operation authority of an operation request of an operator authenticated by the operator authentication unit; an operation history storage unit that stores an operation history based on an operation request made to operate plant equipment based on the determined operation authority; an emergency authority condition determination unit that, when an abnormality is detected in the plant equipment, determines whether the abnormality is caused by an operation based on the operation history for a predetermined period in the operation history storage unit; and an emergency state notification unit that, when the emergency authority condition determination unit determines that the abnormality is not caused by an operation, notifies an operator with operation authority that an emergency state exists. [Effects of the Invention]

[0007] According to the monitoring and control system of the present disclosure, by referring to the operation history before the abnormality occurred, it is possible to determine whether the abnormality in the system was caused by an external factor such as a disaster or by a malicious individual, and the abnormality can be appropriately resolved depending on the cause of the abnormality. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a block diagram of a monitoring and control system according to a first embodiment. [Figure 2] 4 is a flowchart illustrating a procedure up to the execution of an operation process in the monitoring and control system according to the first embodiment. [Figure 3] 3 is a diagram illustrating information on an operation request of the monitoring and control system according to the first embodiment. FIG. [Figure 4] 3 is a diagram illustrating an operation authority setting file of the monitoring and control system according to the first embodiment. FIG. [Figure 5] 5 is a flowchart illustrating a determination procedure in an emergency authority condition determination unit of the monitoring and control system according to the first embodiment. [Figure 6] 3 is a diagram showing an example of detection values ​​of sensors arranged in plant equipment of the monitoring and control system according to the first embodiment. FIG. [Figure 7] FIG. 3 is a diagram showing an example of an operation history of the monitoring and control system according to the first embodiment. [Figure 8] FIG. 3 is a diagram showing an example of an operation history of the monitoring and control system according to the first embodiment. [Figure 9] 10 is a diagram illustrating information of an operation request that has been rewritten to satisfy the emergency authority granting conditions of the monitoring and control system according to the first embodiment. FIG. [Figure 10] 10 is a diagram illustrating an operation authority setting file that has been rewritten to satisfy the emergency authority granting conditions of the monitoring and control system according to the first embodiment. FIG. [Figure 11] 1 is a diagram illustrating an example of a hardware configuration of a monitoring and control system according to a first embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] Hereinafter, preferred embodiments of the monitoring and control system according to the present invention will be described with reference to the drawings. Note that the same reference numerals are used to designate the same contents and corresponding parts, and detailed description thereof will be omitted.

[0010] Embodiment 1 FIG. 1 is a block diagram of a monitoring and control system according to a first embodiment. FIG. 2 is a flowchart illustrating the procedure up to the execution of operation processing. In FIG. 1, arrows indicate the flow of signals, and arrows extending in both directions indicate that signals are transmitted and received in both directions. An input device 101 is provided for input to the monitoring and control system 100. Types of input device 101 include control input devices used mainly for control, such as an operation keyboard, mouse, or touch panel dedicated to the monitoring and control system, and authentication input devices used to authenticate workers, such as biometric authentication devices that input worker biometric information such as finger vein, voiceprint, or iris, IC card readers, RF tag readers, and cameras that capture images of the worker's face, physique, clothing, etc. The input device is connected to an input processing unit 102.

[0011] The output of the input processing unit 102 is input to the operator authentication unit 103 and the operation authority management unit 104. Information on operation requests from a control input device for plant control undergoes necessary processing, such as decoding or conversion, in the input processing unit 102, and is then sent to the operation authority management unit 104. Information from an authentication input device used for operator authentication also undergoes necessary processing, such as data extraction or decoding, in the input processing unit, and is then sent to the operator authentication unit 103. Operator authentication is performed, for example, using a combination of at least a user ID and, if necessary, a password and biometric information. As will be described later, in order to identify malicious operators, it is desirable to incorporate biometric information that can clearly identify individual operators into the authentication process. In addition to the user ID, a group ID and a section ID that identify the group and section to which the operator belongs may also be included in the authentication information. The group and section are often determined by the model or equipment to which the operator is responsible for the operation, and therefore serve as a reference for the authenticated operation authority.

[0012] In this embodiment, authentication using a user ID will be described as an example. The user ID extracted from the input device by the input processing unit 102 and sent to the worker authentication unit 103 is compared by the worker authentication unit 103 with the user ID registered in the worker information storage unit 105, thereby authenticating the worker (step S01 in FIG. 2).

[0013] After the worker is successfully authenticated, the operation request of the worker transmitted to the operation authority management unit 104 is compared in the operation authority management unit 104 with the operation authority setting file of the authenticated worker stored in the worker information storage unit 105 to determine whether the operation can be performed (step S02). If the operation authority management unit 104 determines that the operation request of the authenticated worker is permitted, information on the operation request is transmitted from the operation authority management unit 104 to the operation processing unit 106 (step S03). This information on the operation request includes, for example, the user ID, the operation content in the operation authority, and the operation date and time shown in FIG. 3.

[0014] Among these, the relevant operation content within the operation authority is, for example, an operation item for which an authenticated worker has authority, as described in an operation authority setting file such as that shown in Fig. 4. For example, in the case of an item called "change facility A setting value" in Fig. 4, the setting file includes up to the specific setting value entered by the worker via an input device. Whether or not the worker has operation authority is determined by a "valid" or "invalid" flag attached to each item. Information on operation requests is accumulated as operation history in operation history storage unit 107.

[0015] The operation history may store all operations as history, or may store only a portion of the operation history depending on the storage capacity. That is, as will be described later, the history may be stored for the time from when the operation result is reflected in the equipment, and if it is confirmed that there is no abnormality in the equipment as a result of the operation, the history may be deleted.

[0016] The operation processing unit 106, which has received the information on the operation content, transmits an operation execution signal requested based on the information on the operation content to the plant equipment signal input / output unit 108. For example, if the change value in the above-mentioned "change setting value of equipment A" is +100, the operation processing unit 106 transmits an operation execution signal to the plant equipment signal input / output unit 108 stating "change setting value of equipment A by +100."

[0017] Upon receiving the operation execution signal, the plant equipment signal input / output unit 108 outputs to the plant equipment 109 a signal required to change the set value of equipment A in the plant equipment 109 by +100. For example, one or a combination of signals may be transmitted from among a valve open / close signal, a heater on / off signal, a motor rotation increase / decrease signal, a pressure increase / decrease signal, etc. Furthermore, the transmitted signal may be either a digital signal, an analog signal, or both, depending on the equipment. Furthermore, equipment A may be a valve, a heater, a motor, or a pressure device itself. In this case, the set value may be the valve open / close angle, the heater temperature, the motor rotation speed, the pressure of the pressure device, etc. The operation requested by the signal output to the plant equipment 109 is executed (step S04).

[0018] From the plant equipment 109, values ​​detected from sensors installed in each facility are constantly input to the plant equipment signal input / output unit 108, which detects the facility status. The types of sensors include, for example, ammeters, voltmeters, watt-hour meters, angle sensors, temperature sensors, and pressure sensors. If these detected values ​​exceed predetermined thresholds stored in the plant equipment signal input / output unit 108, it is determined that an abnormality has occurred in the facility. The emergency authority condition determination unit 110 determines whether the abnormality is due to a natural disaster or a malfunction in the facility itself, or whether it has been caused intentionally by a malicious worker or the like.

[0019] The emergency authority condition determination unit 110 reads from the operation history storage unit 107 the operation history of the equipment (here, equipment A) to which the sensor showing the abnormal value is attached, and checks whether there is anything suspicious about the operation. The operation history may be read not only for equipment A that was directly operated, but also for another equipment (here, equipment B) connected to equipment A, because the sensor value of equipment A may exceed the threshold due to the operation of equipment B, and the determination may be made by reading the operation history up to the operation of equipment B. The period of the operation history to be read may be determined by storing in advance for each equipment the average period from when the operation was performed until the operation is reflected in the equipment and detected as a sensor value, and reading all operation history within this fixed period. Alternatively, the system administrator may arbitrarily set the read period.

[0020] The emergency state notification unit 111 has the function of notifying the relevant worker who has the operating authority that an emergency state has occurred, and notifies the worker by wireless communication, displaying the information on the display of the terminal at the worker's seat or on the screen of a mobile terminal held by the worker, and by making an audio announcement.

[0021] The specific determination procedure of the emergency authority condition determination unit 110 is as follows, as shown in the flowchart of FIG. As described above, the plant equipment signal input / output unit 108 monitors the detection signals (plant equipment signals) of the sensors set in the equipment in order to monitor the status of the equipment (step S11). If the detection signals of the sensors indicate an abnormal value (step S12), it displays, for example, on a large display in the control room, that an abnormality is estimated to exist in the equipment (step S13).

[0022] The emergency authority condition determination unit 110 acquires the operation history of facility A for a certain period going back from the time t when the abnormality occurred (step S14). For example, as shown in Fig. 6, an abnormal value of 500 exceeding the threshold value of 200 for facility A was detected at 10:01. If the average time from when an operation is performed on facility A until it is reflected as a detected value in the sensor is one minute, the operation history from 10:00 to 10:01 for facility A and facility B connected to facility A is read from the operation history storage unit 107 to refer to the operation history.

[0023] As shown in FIG. 7, if the read operation history does not contain any history of operations that cause abnormal values, the abnormality in equipment A is due to an external factor such as a disaster, and the emergency authority condition determination unit 110 determines that the emergency authority condition is satisfied (step S16).

[0024] However, as shown in FIG. 8, if the read operation history shows that equipment A was operated by operator X at 10:00:30 with a setting value of 500, it is determined that the abnormal value of equipment A was due to an intentional operation by operator X (user ID is 10000X), and that the emergency authority condition is not met (step S18).

[0025] If it is determined that the emergency authority conditions are met (step S16), the operation request information shown in FIG. 3 is rewritten as the operation authority of worker Y to the operation request information at the time of emergency login, as shown in FIG. 9. That is, the operation authority is set as "emergency authority" and the normal operation authority is expanded. For example, as shown in FIG. 10, in addition to operations on equipment A in the operation authority setting file, operations on equipment B are also enabled. At the same time, a notification is sent to the authenticated worker Y to make an emergency login to the system and operate equipment A and equipment B (step S17). Worker Y does not need to be a single person; emergency operation authority may be granted to multiple workers with the same group ID or section ID, or to all workers. Alternatively, notification may be sent sequentially from the group and section administrator to the workers belonging to the group and section at regular intervals. Note that the "emergency authority" is valid only for the period counted by a timer, such as the "set time of 60 seconds" shown in FIG. 9, and after the period has elapsed, the operation authority returns to normal.

[0026] On the other hand, if it is determined that the emergency authority conditions are not met (step S18), the operation authority management unit 104 revokes the operation authority of worker X, who operated equipment A to an abnormal value, and notifies the administrator of the group or section to which worker X belongs to log in to the system and perform operations to return the setting value of equipment A to the normal value (step S19).

[0027] In addition, to avoid a situation where equipment values ​​become abnormal as a result of an incorrect operation due to negligence, even if it is not intentional, the operator may be asked to confirm the operation instructions he or she has entered after giving the instructions.

[0028] FIG. 11 is a diagram illustrating an example of the hardware configuration of the input processing unit 102, the operation authority management unit 104, the operation processing unit 106, the plant equipment signal input / output unit 108, the emergency authority condition determination unit 110, and the emergency state notification unit 111. The system includes one or more processors 10 and one or more storage devices 20. Although not shown, the storage device 20 includes a volatile storage device such as a random access memory and a nonvolatile auxiliary storage device such as a flash memory. Alternatively, a hard disk auxiliary storage device may be used instead of the flash memory. The processor 10 executes the above-described flowchart using a program input from the storage device 20. In this case, the program is input from the auxiliary storage device to the processor 10 via the volatile storage device. The processor 10 may output data such as calculation results to the volatile storage device of the storage device 20, or may store the data in the auxiliary storage device via the volatile storage device.

[0029] The input processing unit 102, the operation authority management unit 104, the operation processing unit 106, the plant equipment signal input / output unit 108, and the emergency authority condition determination unit 110 may be executed as functions by a program, and each may have a separate processor 10 and memory device 20, and may be connected by a transmission / reception circuit 30.

[0030] As described above, according to this embodiment, by referring to the operation history before the abnormality occurred, it is possible to determine whether the abnormality in the system was caused by an external factor such as a disaster, or by a malicious individual, and the abnormality can be appropriately resolved depending on the cause of the abnormality.

[0031] Although the present disclosure describes exemplary embodiments, the various features, aspects, and functions described in the embodiments are not limited to application to a particular embodiment, but may be applied to the embodiments alone or in various combinations. Therefore, countless variations not illustrated are contemplated within the scope of the technology disclosed in this specification, including, for example, the modification, addition, or omission of at least one component. [Explanation of symbols]

[0032] 10: Processor, 20: Storage device, 100: Monitoring and control system, 101: Input device, 102: Input processing unit, 103: Worker authentication unit, 104: Operation authority management unit, 105: Worker information storage unit, 106: Operation processing unit, 107: Operation history storage unit, 108: Plant equipment signal input / output unit, 109: Plant equipment, 110: Emergency authority condition determination unit, 111: Emergency state notification unit.

Claims

1. a worker authentication unit that authenticates a worker based on authentication information input by an input device and information recorded in a worker information storage unit; an operation authority management unit that determines the operation authority of an operation request made by a worker authenticated by the worker authentication unit; an operation history storage unit that stores an operation history based on the operation request made to operate plant equipment based on the determined operation authority; an emergency authority condition determination unit that, when an abnormality is detected in the plant equipment, determines whether the abnormality is caused by an operation based on the operation history for a predetermined period in the operation history storage unit; and an emergency state notification unit that, when the emergency authority condition determination unit determines that the abnormality is not caused by an operation, notifies an operator with operation authority that an emergency state exists.

2. 2. The plant monitoring and control system according to claim 1, wherein the operation request includes at least identification information for identifying the worker, the operation content, and the operation date and time.

3. 3. The plant monitoring and control system according to claim 1, wherein the determination of the operation authority is performed based on a comparison between the operation items of the operation authority setting file stored in the worker information storage unit and the operation items of the operation request.

4. A control method for a plant monitoring and control system that operates plant equipment in response to an operation request from a worker whose operating authority has been authenticated, and when an abnormality occurs in the plant equipment, determines whether the abnormality is caused by the operation based on an operation history based on the operation requests for a predetermined period, and if it is determined that the abnormality is not caused by the operation, notifies the worker who has the operating authority that an emergency situation exists, and if the abnormality is caused by the operation, invalidates the operating authority of the worker who performed the operation that caused the abnormality.

Citation Information

Patent Citations

  • Monitoring control system

    JP2010231473A

  • System, method and program for control of authority

    JP2011210190A