Control Cloud Server

The control cloud server addresses the limitation of local data utilization by managing and reporting on multiple control systems, facilitating centralized data management and communication of system changes and failures.

JP7717555B2Active Publication Date: 2025-08-04KK TOSHIBA
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2021153440
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-09-21
Publication Date
2025-08-04
Estimated Expiration
2041-09-21

AI Technical Summary

Technical Problem

Existing control systems are limited to local utilization of information, restricting the use of data within the local control system and lacking a comprehensive management and reporting mechanism for multiple control systems.

Method used

A control cloud server that stores reporting rules and acquires information from multiple control systems, identifies change points, and transmits relevant data to designated access destinations based on a reporting rule table, generating reference information to manage and report on the status and failures of these systems.

Benefits of technology

Enables the centralized management and reporting of multiple control systems, facilitating the identification of system changes and failures, and ensuring efficient communication of critical information across a cloud environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007717555000001
    Figure 0007717555000001
  • Figure 0007717555000002
    Figure 0007717555000002
  • Figure 0007717555000003
    Figure 0007717555000003
Patent Text Reader

Abstract

To provide a control cloud server that can utilize information obtained in a control system beyond one control system.SOLUTION: A control cloud server according to an embodiment stores a reporting rule table in which a reporting rule for each of a plurality of control systems, composed of a cloud controller and a control target device of the cloud controller, is registered. The control cloud server also obtains control system information regarding a configuration and an operating state of each of the plurality of control systems from a plurality of cloud controllers included in each of the plurality of control systems. The control cloud server specifies whether or not reporting for each of the plurality of control systems is necessary referring to the reporting rule table by the control system information, an access destination when the reporting is necessary, and transmission content to the access destination, and transmits the transmission content to the specified access destination.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to a control cloud server.

Background Art

[0002] Conventionally, a control system including a controller for controlling an industrial plant (hereinafter simply referred to as a "plant") and an HMI (Human Machine Interface) etc. has been provided in the local environment of each plant.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the prior art, the utilization of information obtained within the control system has been limited to use within the local control system.

Means for Solving the Problems

[0005] The control cloud server according to the embodiment stores a reporting rule table in which reporting rules for each of a plurality of control systems composed of a cloud controller and controlled devices of the cloud controller are registered. Further, the control cloud server acquires control system information regarding the configuration and operating state of each of the plurality of control systems from a plurality of cloud controllers included in each of the plurality of control systems. The control cloud server refers to the reporting rule table based on the control system information to specify the necessity of reporting for each of the plurality of control systems, the access destination when reporting is necessary, and the transmission content to the access destination, and transmits the transmission content to the specified access destination. The control cloud server generates reference information that defines the standard state of each of the plurality of control systems from the control system information. When the control cloud server compares the newly acquired control system information with the reference information and there is a change point in the newly acquired control system information, it refers to the reporting rule table to identify the access destination associated with the control system corresponding to the control system information with the change point, and the content to be transmitted to the access destination, and transmits the transmitted content to the identified access destination. The control system information includes at least the configuration of the devices included in the plurality of control systems, the usage period of the devices, and failure information regarding the failure of the devices. When failure information is recorded in the control system information, the control cloud server generates reference information for each of the plurality of control systems that defines that devices of the same model number as the model number of the device in which the failure occurred and within a usage period range equal to or less than the specified threshold are not included, based on the model number and usage period of the device in which the failure occurred. When there is a control system that does not match the reference information among the plurality of control systems, the control cloud server refers to the reporting rule table and transmits the transmitted content to the access destination associated with the control system.

Brief Description of the Drawings

[0006]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

MODE FOR CARRYING OUT THE INVENTION

[0007] (Embodiment) FIG. 1 is a diagram showing an example of the overall configuration of a management system S according to an embodiment. As shown in FIG. 1, the management system S includes a control cloud server 12 provided in a cloud environment 1, a plurality of cloud controllers 11a to 11n, and a plurality of local I / O (Input Output) systems 2a to 2n. Further, a mail server 41 and a web-based HMI 42 are provided in the cloud environment 1. The mail server 41 and the web-based HMI 42 may or may not be included in the management system S. The web-based HMI 42 may also be referred to as a cloud HMI or an OIS (Operator Interface Station).

[0008] The number of the cloud controllers 11a to 11n and the local I / O systems 2a to 2n included in the management system S is not particularly limited. Hereinafter, when not particularly distinguishing the individual cloud controllers 11a to 11n, they are simply referred to as cloud controller 11. Also, when not particularly distinguishing the individual local I / O systems 2a to 2n, they are simply referred to as local I / O system 2. The local I / O system 2 is an example of the local system in the present embodiment.

[0009] The control cloud server 12 and the plurality of cloud controllers 11a to 11n are collectively referred to as a control cloud service 10.

[0010] The cloud controllers 11a to 11n control the local I / O systems 2a to 2n. Specifically, the cloud controller 11a controls the local I / O system 2a, and the cloud controller 11n controls the local I / O system 2n.

[0011] More specifically, the cloud controller 11 controls the remote I / Os 231a, 232a, 231n, 232n included in the local I / O system 2 by executing a POU (Program Organization Unit) which is a kind of control program.

[0012] The cloud controller 11, which is the control entity, corresponds one-to-one with the local I / O system 2, which is the control target. A combination of a set of cloud controller 11 and local I / O system 2 is called a control system 3. For example, the control system 3a includes the cloud controller 11a and the local I / O system 2a. Also, the control system 3n includes the cloud controller 11a and the local I / O system 2n.

[0013] The local I / O systems 2a to 2n are respectively provided in the local environment. The local environment is an environment physically provided within an industrial plant (hereinafter simply referred to as "plant"), which is the control target of the local I / O systems 2a to 2n. That is, various devices included in the local I / O systems 2a to 2n are physically provided within the plant.

[0014] In contrast, the cloud environment 1, which includes the cloud controllers 11a to 11n, the control cloud server 12, the mail server 41, and the web-based HMI 42, is provided not within the plant but at a remote location such as a data center as an example. The local I / O system 2 and the cloud environment 1 are connected via a network such as the Internet 5. Note that each device provided on the cloud environment 1 (the control cloud server 12, the cloud controller 11, the mail server 41, and the web-based HMI 42) may function as a plurality of devices with one computer, or a plurality of computers may function virtually as one device. The computers physically constituting the cloud environment include, for example, a control device such as a CPU, a storage device such as a ROM (Read Only Memory) and a RAM (Random Access Memory), and an external storage device such as an HDD (Hard Disk Drive), and have a hardware configuration using ordinary computers. Also, the dashed arrows in FIG. 1 indicate the communication connection relationships between the devices.

[0015] In the example shown in FIG. 1, the local I / O system 2a includes an HMI 21a, a communication module 22a, remote I / Os 231a, 232a, and a fault diagnosis module 25a. The local I / O system 2a, the HMI 21a, the communication module 22a, the remote I / Os 231a, 232a, and the fault diagnosis module 25a are connected by an I / O bus 20a. Also, the local I / O system 2n includes an HMI 21n, a communication module 22n, remote I / Os 231n, 232n, and a fault diagnosis module 25n. The local I / O system 2n, the HMI 21n, the communication module 22n, the remote I / Os 231n, 232n, and the fault diagnosis module 25n are connected by an I / O bus 90n.

[0016] In addition, the local I / O system 2 may further include an engineering tool for generating a POU executed by the cloud controller 11. The engineering tool may be, for example, a PC having a normal hardware configuration including a control device such as a CPU, a storage device such as a ROM or a RAM, and an external storage device such as an HDD, or a dedicated terminal.

[0017] The HMIs 21a, 21n are devices used for an operator to monitor the status of processes executed by the cloud controller 11. Hereinafter, when the individual HMIs 21a, 21n are not particularly distinguished, they are simply referred to as HMI 21.

[0018] The communication modules 22a, 22n are communicatively connected to the cloud controller 11 via the Internet 5. Hereinafter, when the individual communication modules 22a, 22n are not particularly distinguished, they are simply referred to as communication module 22.

[0019] Remote I / Os 231a, 232a, 231n, and 232n are interfaces for inputting and outputting signals between sensors and other devices provided in the plant. Remote I / Os 231a, 232a, 231n, and 232n are remotely controlled from the cloud controller 11 via the Internet 5 and the communication modules 22. Data input from the sensors and other devices to the remote I / Os 231a, 232a, 231n, and 232n is transmitted to the cloud controller 11 via the communication modules 22 and the Internet 5. Hereinafter, when not particularly distinguishing the individual remote I / Os 231a, 232a, 231n, and 232n, they are simply referred to as remote I / O 23.

[0020] The failure diagnosis modules 25a and 25n collect information in the local I / O system 2 and detect failures occurring in the local I / O system 2 based on the collected information. When the failure diagnosis modules 25a and 25n detect a failure, they transmit failure information regarding the failure to the control cloud server 12. Hereinafter, when not particularly distinguishing the individual failure diagnosis modules 25a and 25n, they are simply referred to as the failure diagnosis module 25. Note that the failures in the present embodiment may include software errors and malfunctions, etc., not limited to hardware failures.

[0021] The information collected by the failure diagnosis module 25 is, for example, the operation data of the local I / O system 2, alarms occurring in the local I / O system 2, and RAS (Reliability, Availability and Serviceability) information, etc. The operation data of the local I / O system 2 is, for example, the operation history of the remote I / O 23 operated by the POU executed by the cloud controller 11.

[0022] The failure diagnosis modules 25a and 25n can communicate with the control cloud server 12 without going through the communication modules 22a and 22n. Also, the failure diagnosis modules 25a and 25n may communicate with the control cloud server 12 not only via the Internet 5 but also via a telephone line (not shown).

[0023] Note that the failure diagnosis modules 25a and 25n may have functions as controllers of, for example, a PLC (Programmable Logic Controller) or a DCS (Distributed Control System). For example, when the cloud controller 11 is down or malfunctioning due to an error, the failure diagnosis modules 25a and 25n may execute the POU. In this case, the POU stored in the storage unit 120 of the cloud controller 11 is also stored in a storage unit (not shown) in the failure diagnosis modules 25a and 25n, and it is assumed that the failure diagnosis modules 25a and 25n can execute the said POU. Hereinafter, when the individual failure diagnosis modules 25a and 25n are not distinguished, they are simply referred to as the failure diagnosis module 25.

[0024] The control cloud server 12 acquires control system information regarding the configurations and operating states of the plurality of control systems 3a to 3n from the plurality of cloud controllers 11a to 11n.

[0025] The control system information 121 includes, for example, the configuration of devices included in a plurality of control systems 3a to 3n, the POU executed by a plurality of cloud controllers 11a to 11n, the usage period of devices included in the control systems 3a to 3n, the standards of I / O buses 20a to 20n used in the control systems 3a to 3n, the version of the firmware of devices included in the control systems 3a to 3n, the latest update date of the version of the firmware of devices included in the control systems 3a to 3n, the updater of the firmware of devices included in the control systems 3a to 3n, the operation data of the control systems 3a to 3n, the operation records of operators who operate the control systems 3a to 3n, alarms, failure information, RAS information, videos related to the operations of operators, and voices related to the operations of operators, and includes at least one of them. More specifically, in the present embodiment, the control system information 121 includes at least the configuration of devices included in a plurality of control systems 3a to 3n, the usage period of the devices, and the version of the firmware of devices included in the plurality of control systems 3a to 3n. When a device failure occurs in any of the plurality of control systems 3a to 3n, the control system information 121 further includes failure information including the model number and usage period of the failed device. Note that the fact that the system information 121 includes failure information may mean that the system information 121 in a specified format includes a record of the failure, or that, in addition to the system information 121 in the specified format, the failure information is separately transmitted.

[0026] In addition, the control system information 121 may be manually input by an operator, an engineer, or the like.

[0027] The standards of the I / O buses 20a to 20n are, for example, DeviceNet (registered trademark), etc., but are not limited thereto.

[0028] The operation data of the control systems 3a to 3n is, for example, data in which the execution logs of the POU and the input / output data of the remote I / O 23 are recorded in time series.

[0029] The failure information is failure information regarding the failures that occurred in the control system 3. It may mainly target the failures that occurred in the local I / O system 2.

[0030] Also, the control system information may further include various types of information generated by engineering tools.

[0031] Videos regarding the operator's operations and voices regarding the operator's operations are collected, for example, by cameras and microphones (not shown) provided in the control room used by the operator. The videos and voices may be transmitted to the control cloud server 12 via the communication module 22 of the local I / O system 2, or may be transmitted to the control cloud server 12 without passing through the local I / O system 2.

[0032] The mail server 41 sends mails to the operators of each plant, system integrators who introduced the control system 3 into each plant, etc. under the control of the control cloud server 12.

[0033] The web-based HMI 42 is a human interface for the operator to perform screen operations. The web-based HMI 42 operates in the cloud environment 1. For example, the screen generated by the web-based HMI 42 is displayed on the display of a PC or tablet device connected to the web-based HMI 42 via the Internet 5. The PC or tablet device accessing the web-based HMI 42 may be provided outside the local I / O system 2. Note that the web-based HMI 42 may be provided in the local environment instead of the cloud environment 1.

[0034] The control cloud server 12 stores the control system information 121 of each of the plurality of cloud controllers 11a to 11n obtained from the plurality of cloud controllers 11a to 11n in the storage unit 120. Also, the storage unit 120 of the control cloud server 12 stores the reference information 12 of each of the cloud controllers 11a to 11n. Further, when failure information is transmitted from any of the plurality of failure diagnosis modules 25a to 25n, the control cloud server 12 also stores the failure information in the storage unit 120. In addition, the storage unit 120 stores a reporting rule table 122 in which the reporting method and the reporting destination for each control system are registered. Note that the storage unit 120 is physically realized by an external storage device such as an HDD of a computer constituting the cloud environment 1.

[0035] In the present embodiment, the control cloud server 12 aggregates and stores the information obtained from the plurality of cloud controllers 11a to 11n and the plurality of failure diagnosis modules 25a to 25n. In the present embodiment, it is assumed that there is no direct data exchange between different control systems 3 without going through the control cloud server 12. For example, the cloud controller 11a and the cloud controller 11n do not directly transmit and receive information.

[0036] The control cloud server 12 reports when there is a change point by comparing the reference information 123 of the plurality of control systems 3a to 3n with the control system information collected from the plurality of cloud controllers 11a to 11n. As an example, the control cloud server 12 generates reference information 123 that defines the standard state of each of the plurality of control systems 3a to 3n from the control system information. Then, after generating the reference information 123, the control cloud server 12 compares the newly obtained control system information with the reference information 123. When there is a change point in the newly obtained control system information, it refers to the reporting rule table 122 described later to identify the access destination associated with the control system 3 corresponding to the control system information with the change point, and the content to be transmitted to the access destination, and transmits the content to be transmitted associated with the access destination to the identified access destination.

[0037] Reference information 123 defines the standard state of each of the plurality of control systems 3 to 3n. The standard state is a state that is not the target of transmission by the control cloud server 12. The reference information 123 is determined for each of the plurality of control systems 3a to 3n.

[0038] Specifically, the reference information 123 may be control system information in normal times. In this case, the control system information in normal times becomes the reference information.

[0039] For example, when the reference information 123 is control system information in normal times, the change point is the difference between the control system information in normal times and the collected control system information. For example, when "no alarm due to error" is the standard in normal times, if the control system information collected from any of the cloud controllers 11 includes an alarm due to error, there is a difference between the reference information 123 and the control system information 121, so the occurrence of the alarm becomes the change point. Also, the sensor value in normal times may be the reference information 123. In this case, the control cloud server 12 collects the sensor value in normal times from the sensor values included in the operation data of the control system information obtained from each of the plurality of cloud controllers 11a to 11n and registers it as the reference information 123. Then, when the sensor value included in the operation data of the newly obtained control system information is different from the sensor value registered as the reference information 123 by a specified threshold value or more, the control cloud server 12 determines that a change point has occurred in the sensor value.

[0040] In addition, the reference information 123 may be updated by an administrator or the like of the control system 3. For example, when a new version of the firmware is released, the administrator of the control system 3 adds and registers the version of the latest firmware as the reference information 123. In the present embodiment, adding new information to the reference information 123 and changing the registered content of the reference information 123 are referred to as updating the reference information 123. When the version of the firmware included in the control system information collected from the cloud controller 11 is not the latest, the difference in the firmware version becomes a change point.

[0041] Further, as the reference information 123, a threshold value or range of the operation data of the control system 3 may be defined. For example, when the data input to the remote I / O 23 included in the control system 3 exceeds the threshold value defined as the reference information 123, the occurrence of the data becomes a change point. Note that not only when the data simply exceeds the threshold value, but also conditions such as "when the threshold value is exceeded continuously n times" may be included in the reference information.

[0042] In addition, when the reference information 123 is "that there is no failure in the control system 3", when a failure occurs in any of the control systems 3, the failure becomes a change point. When the control cloud server 12 acquires failure information from the cloud controller 11 or the failure diagnosis module 25, it issues a report.

[0043] In addition, when the control cloud server 12 detects the occurrence of a failure from the operation data of the control system 3 collected from the cloud controller 11 or the failure diagnosis module 25, the detection of the occurrence of the failure becomes a change point. Also in this case, the control cloud server 12 issues a report. The method for the control cloud server 12 to detect a failure is not particularly limited, and for example, AI (Artificial Intelligence) technologies such as deep learning may be adopted. As an example, the control cloud server 12 uses AI technology to learn the past control system information in the situation where the control system 3 is operating without problems for each control system 3, thereby identifying the pattern of the reference control system information. Then, when the control system information obtained from the cloud controller 11 does not match the reference control system information obtained through learning, the control cloud server 12 detects the occurrence of a failure.

[0044] In addition, when the control cloud server 12 detects a failure in any one of the control systems 3 and there is a high possibility that the same failure will occur in other control systems 3, the prediction of the occurrence of the failure becomes a change point. In this case, the control cloud server 12 issues a report by displaying it on the HMI 21 of the other control system 3 where the failure is predicted, sending an email to the operator of the other control system 3, or displaying it on the web-based HMI 42.

[0045] More specifically, a change point is that there exists a device with the same model number as the device in which a failure has occurred in any one of the plurality of control systems 3a to 3n and with a usage period close to that of the device in which the failure has occurred. The device with a usage period close to that of the device in which the failure has occurred is, for example, a device in which the difference between the usage period of the device and the usage period of the device in which the failure has occurred is equal to or less than a threshold value. The threshold value is not particularly limited and may change according to, for example, the type of failure. Also, instead of the proximity of the usage period to the device in which the failure has occurred, devices that have been used for a specified usage period or longer may be targeted. For example, devices that have been used for a specified usage period or longer have a higher likelihood of failure due to aging deterioration. Note that the specified usage period for each device may be stored in the storage unit 120 of the control cloud server 12.

[0046] Also, when any one of the cloud controllers 11 is down, the down state becomes a change point. For example, the control cloud server 12 periodically accesses the cloud controller 11 and receives a response to confirm that the cloud controller 11 is operating. When the control cloud server 12 does not receive a response from the cloud controller 11, it determines that the cloud controller 11 is down and issues a report. Note that the determination of being down may also be made when there is no response from the cloud controller 11 continuously for a specified number of times or more.

[0047] Also, when a difference occurs between the failure information obtained from any one of the failure diagnosis modules 25 and the failure information obtained from the cloud controller 11 included in the same control system 3 as the failure diagnosis module 25, the occurrence of the difference becomes a change point.

[0048] More specifically, the control cloud server 12 compares the failure information obtained from the plurality of failure diagnosis modules 25a to 25n with the failure information obtained from the plurality of cloud controllers 11a to 11n included in the same control system 3 as the plurality of failure diagnosis modules 25a to 25n. For example, the control cloud server 12 compares the failure information obtained from the failure diagnosis module 25a with the failure information obtained from the cloud controller 11a. Also, the control cloud server 12 compares the failure information obtained from the failure diagnosis module 25n with the failure information obtained from the cloud controller 11n.

[0049] When the failure information obtained from the failure diagnosis module 25 matches the failure information obtained from the cloud controller 11 included in the same control system 3 as the failure diagnosis module 25, the reliability of the failure information is high. In this case, the control cloud server 12 issues a report based on the failure information.

[0050] Also, when the failure information obtained from the failure diagnosis module 25 does not match the failure information obtained from the cloud controller 11 included in the same control system 3 as the failure diagnosis module 25, there is a possibility that the cloud controller 11 is down or the communication between the cloud controller 11 and the local I / O system 2 has been interrupted.

[0051] When the failure information obtained from the failure diagnosis module 25 does not match the failure information obtained from the cloud controller 11 included in the same control system 3 as the failure diagnosis module 25 and the cloud controller 11 is down, the control cloud server 12 issues a report by sending an email to the operator of the control system 3 including the cloud controller 11 or by displaying it on the web-based HMI 42.

[0052] In addition, when there is a discrepancy between the failure information obtained from the failure diagnosis module 25 and the failure information included in the control system information obtained from the cloud controller 11 included in the same control system 3 as the failure diagnosis module 25, and the cloud controller 11 is not down, the control cloud server 12 sends a control signal to the cloud controller 11 to shut it down. This is a fail-safe function to prevent the cloud controller 11 from continuing to operate in a state where there may be some problem such as a communication interruption between the cloud controller 11 and the local I / O system 2. Also, in this case, the control cloud server 12 issues a report by sending an email to the operator of the control system 3 including the cloud controller 11 or by displaying it on the web-based HMI 42.

[0053] Note that the points of change are not limited to the above examples.

[0054] Whether to issue a report for any point of change can be individually set by the operator, engineer, etc. for each control system 3. The necessity of issuing a report for each control system 3 is registered in the reporting rule table 122 in the storage unit 120 of the control cloud server 12.

[0055] In this embodiment, as methods of issuing a report, there are three methods: sending an email, displaying on the HMI 21 included in the local I / O system 2, and displaying on the web-based HMI 42.

[0056] In the case of sending an email, the control cloud server 12 causes the mail server 41 to send an alert email to the destination preset in the reporting rule table 122.

[0057] Also, in the case of display by the HMI 21, the control cloud server 12 transmits the transmission content registered in the reporting rule table 122 to the cloud controller 11 included in the control system 3 to be reported. In this case, the cloud controller 11 causes the corresponding HMI 21 to display an alert based on the transmission content. Since the display operation on the HMI 21 is also under the management of the cloud controller 11, it is assumed that the HMI 21 is not directly controlled from the control cloud server 12.

[0058] Also, in the case of display by the web-based HMI 42, the control cloud server 12 transmits a control signal to the web-based HMI 42 provided in the cloud environment 1 to display an alert on the screen provided by the web-based HMI 42. As a result, the alert is displayed on the displays of the PC and tablet devices that have accessed the web-based HMI 42.

[0059] The reporting method is determined by operators, engineers, etc. for each control system 3 and for each type of change point. For example, the reporting method for each control system 3 and for each type of change point is registered in the reporting rule table 122 stored in the control cloud server 12.

[0060] FIG. 2 is a diagram showing an example of the reporting rule table 122 according to the present embodiment. The reporting rule table 122 is a table in which reporting rules for each of a plurality of control systems 3 are registered. More specifically, as shown in FIG. 2, the reporting rule table 122 is a table in which a control system number capable of identifying the control system 3, a monitoring target, a reporting necessity, an access destination, and transmission content are associated with each other.

[0061] The monitoring target is an event to be reported. In FIG. 2, failure prediction, abnormal value, error occurrence, cloud controller down, and firmware update information are illustrated as monitoring targets, but the monitoring targets are not limited thereto. The monitoring target is also referred to as the type of change point.

[0062] The necessity of notification is the setting of the necessity of notification for each monitoring target.

[0063] For example, in the control system 3 with the control system number "1", when a failure is predicted in the control system 3, when an abnormal value is detected in the control system 3, when an error occurs in the control system 3, when the cloud controller 11 included in the control system 3 goes down, and when a new version of the firmware used in the devices included in the control system 3 is released, it is set to issue a notification.

[0064] Also, in the control system 3 with the control system number "2", when an abnormal value is detected in the control system 3, when an error occurs in the control system 3, and when the cloud controller 11 included in the control system 3 goes down, it is set to issue a notification. However, when a failure is predicted in the control system 3 and when a new version of the firmware used in the devices included in the control system 3 is released, it is set not to issue a notification.

[0065] The access destination is the device that the control cloud server 12 accesses when the necessity of notification is "necessary". For example, when the notification means is email, the access destination is the mail server 41. Also, when the notification means is display by the HMI 21, the access destination is the cloud controller 11 included in the control system 3 that is the notification target. Also, when the notification means is display by the web-based HMI 42, the access destination is the web-based HMI 42.

[0066] The transmission content is what the control cloud server 12 transmits to the access destination. The transmission content varies depending on the access destination. For example, when the access destination is the mail server 41, the transmission content is the mail address of the mail recipient and the content of the message. Also, when the access destination is the cloud controller 11, the transmission content is the message for display on the HMI21. Further, when the access destination is the web-based HMI42, the content is the message for display on the web-based HMI42. Note that the transmission content shown in FIG. 2 is an example and is not limited thereto. For example, the control cloud server 12 may simply transmit the code representing the type of change point to the cloud controller 11 or the web-based HMI42, and the cloud controller 11 or the web-based HMI42 side may determine the alarm message or the like.

[0067] For example, in the control system 3 with the control system number "1", when a failure is predicted in the control system 3, when the cloud controller 11 included in the control system 3 goes down, and when a new version of the firmware used in the devices included in the control system 3 is released, the access destination is set to the mail server 41. When the cloud controller 11 included in the control system 3 goes down, it cannot be displayed on the HMI21 via the cloud controller 11 from the control cloud server 12. Therefore, when the cloud controller 11 included in the control system 3 goes down, a method other than the alarm by the HMI21 is set. Also, the mail destination address may vary depending on the type of monitoring target. For example, for failure prediction and the down of the cloud controller 11, the mail address of the operator of the control system 3 or the management person in charge of the company that is the owner of the control system 3 may be set. Also, for the firmware update information, the mail address of the engineer of the system integrator in charge of the introduction and maintenance of the control system 3 may be set. Also, in the control system 3 with the control system number "1", when an abnormal value is detected in the control system 3 and when an error occurs, the display by the HMI21 is set.

[0068] The control cloud server 12 refers to the reporting rule table 122 according to the control system information to identify the necessity of reporting for each of the plurality of control systems 3, the access destination when reporting is necessary, and the content to be transmitted to the access destination, and transmits the identified transmission content to the identified access destination.

[0069] In addition, in FIG. 2, an example in which one access destination and transmission content are set for one change point is illustrated. However, when the necessity of reporting is "necessary", at least one access destination and transmission content may be set. For example, for one monitoring target, reporting may be executed by two or more of mail, HMI 21, and web-based HMI 42.

[0070] In addition, in FIG. 2, the reporting rule table 122 is illustrated as one table. However, the necessity of reporting, the access destination, and the transmission content for each change point may be registered in different tables.

[0071] Next, specific examples of reporting will be described with reference to FIGS. 3 to 5. Each reporting shown in FIG. 3 is an example when a failure due to aging deterioration is predicted in the communication module 22 included in a certain control system 3.

[0072] FIG. 3 is a diagram showing an example of reporting by mail according to the present embodiment. The mail 411 shown in FIG. 3 is an example of a mail when a failure due to aging deterioration is predicted in the communication module 22 included in a certain control system 3. For example, a fixed sentence of the mail text for each change point is stored in the storage unit 120 of the control cloud server 12, and the control cloud server 12 adds the identification information of the control system 3 and the identification information of the communication module 22 where the change point has occurred to the fixed sentence of the mail text and causes it to be transmitted to the mail server 41.

[0073] FIG. 4 is a diagram showing an example of notification by the HMI 21 according to the present embodiment. For example, the control cloud server 12 transmits notification content to the cloud controller 11 included in the control system 3 to be notified, and the cloud controller 11 causes the notification content to be displayed on the display 211 of the HMI 21. For example, fixed sentences of messages for HMI 21 display for each change point are stored in the storage unit 120 of the control cloud server 12, and the control cloud server 12 adds the identification information of the control system 3 in which the change point has occurred and the identification information of the communication module 22 to the fixed sentence to generate a message M1. Note that the text of the message M1 may be generated by the cloud controller 11 or the HMI 21.

[0074] FIG. 5 is a diagram showing an example of notification by the web-based HMI 42 according to the present embodiment. For example, the control cloud server 12 transmits a control signal to the web-based HMI 42 to cause the notification content to be displayed on the screen provided by the web-based HMI 42. As a result, the notification content is displayed on the displays 421 of the PC and the tablet device that have accessed the web-based HMI 42. For example, fixed sentences of messages for web-based HMI 42 display for each change point are stored in the storage unit 120 of the control cloud server 12, and the control cloud server 12 adds the identification information of the communication module 22 of the control system 3 in which the change point has occurred to the fixed sentence to generate a message M2. Note that the text of the message M2 may be generated by the web-based HMI 42.

[0075] Next, the flow of the process executed by the control cloud server 12 configured as described above will be described.

[0076] FIG. 6 is a flowchart showing an example of the flow of the reference information generation process according to the present embodiment.

[0077] First, the control cloud server 12 acquires control system information 121 from each of the cloud controllers 11a to 11b (S1).

[0078] Then, the control cloud server 12 generates reference information 123 from the acquired control system information 121 (S2).

[0079] Note that the reference information 123 may be generated from the control system information 121 acquired multiple times. For example, the control cloud server 12 uses AI technology to learn the past control system information of each control system 3 in a situation where the control system 3 is operating without problems, and then identifies the pattern of the reference control system information, thereby determining the criteria for judging "abnormal values" of sensors, etc. in each control system 3, and registering them in the reference information 123. For information in the reference information 123 that is not generated from the control system information 121, such as firmware update information, it may be left blank.

[0080] FIG. 7 is a flowchart showing an example of the flow of change point detection processing according to the present embodiment.

[0081] First, the control cloud server 12 acquires control system information 121 for each control system 3 from each cloud controller 11a to 11b (S101). The control cloud server 12 stores the acquired control system information 121 in the storage unit 120.

[0082] Then, the control cloud server 12 compares the acquired control system information 121 for each control system 3 with the reference information 123 for each control system 3. If there is a control system 3 whose control system information 121 does not match any of the reference information 123 (S102 "Yes"), the control cloud server 12 refers to the alarm rule table 122 to identify the necessity of alarm corresponding to the type of change point regarding the reference information 123 that does not match the control system information 121 in the target control system 3 (S103).

[0083] In the alarm rule table 122, if the necessity of alarm in the alarm rule for the corresponding change point is "Yes" (S104 "Yes"), the control cloud server 12 searches the alarm rule table 122 for the access destination in the target control system 3 (S105).

[0084] When the access destination registered in the reporting rule table 122 is "cloud controller" (S106 "cloud controller"), the control cloud server 12 causes the HMI 21 to report by sending the HMI display message registered in the reporting rule table 122 to the cloud controller 11 included in the control system 3 to be reported (S107).

[0085] When the access destination registered in the reporting rule table 122 is "mail server" (S106 "mail server"), the control cloud server 12 causes an email to be sent to the destination email address by sending the destination email address and the message registered in the reporting rule table 122 to the mail server 41 (S108).

[0086] When the access destination registered in the reporting rule table 122 is "Web-based HMI" (S106 "Web-based HMI"), the control cloud server 12 causes the Web-based HMI 42 to report by sending the display message registered in the reporting rule table 122 to the Web-based HMI 42 (S109).

[0087] Also, when there is no control system 3 in which the control system information 121 does not match any of the reference information 123 (S102 "none"), the control cloud server 12 does not report (S110). Also, in the reporting rule table 122, when the necessity of reporting in the target control system 3 is "no" (S104 "no"), the control cloud server 12 does not report.

[0088] Next, the process flow of the reporting of the failure prediction according to the present embodiment will be described.

[0089] FIG. 8 is a flowchart showing an example of the process flow of the reporting of the failure prediction according to the present embodiment.

[0090] First, the control cloud server 12 acquires control system information 121 for each control system 3 from each cloud controller 11a - 11b (S121). The control cloud server 12 stores the acquired control system information 121 in the storage unit 120.

[0091] Then, when the acquired system information 121 contains failure information (S122 “Yes”), the control cloud server 12 adds “not including devices with the same model number as the device where the failure occurred in the failure information (for example, communication module 22) and within the range of the usage period of the device where the failure occurred and below the specified threshold value” to the reference information 123 of each control system 3 (S123).

[0092] The failure information is, for example, information indicating that the communication module 22 has failed due to aging deterioration. Specifically, the failure information includes the identification information of the control system 3 containing the failed communication module 22, the model number of the failed communication module 22, and the number of years passed. Note that when no failure has occurred in any control system 3, the system information 121 does not contain failure information.

[0093] Then, the control cloud server 12 compares the reference information 123 added in S123 with the control system information 121 of each control system 3. If there is a control system 3 whose control system information 121 does not match the reference information 123 added in S123 (S124 “Yes”), the control cloud server 12 searches the reporting rule table 122 for whether reporting of failure prediction is required in the control system 3 (S125).

[0094] In the reporting rule table 122, when the requirement for reporting failure prediction in the control system 3 is “required” (S126 “required”), the control cloud server 12 searches the reporting rule table 122 for the access destination of failure prediction in the control system 3 including the target device (S127).

[0095] When the access destination registered in the reporting rule table 122 is "cloud controller" (S128 "cloud controller"), the control cloud server 12 sends the HMI display message registered in the reporting rule table 122 to the cloud controller 11 included in the control system 3 to be reported, so as to cause the HMI 21 to display information about the failure prediction (S129).

[0096] When the access destination registered in the reporting rule table 122 is "mail server" (S128 "mail server"), the control cloud server 12 sends the destination email address and message registered in the reporting rule table 122 to the mail server 41, so as to cause the mail server 41 to send an email about the failure prediction to the email address (S130).

[0097] When the access destination registered in the reporting rule table 122 is "Web-based HMI" (S128 "Web-based HMI"), the control cloud server 12 sends the display message registered in the reporting rule table 122 to the Web-based HMI 42, so as to cause the screen provided by the Web-based HMI 42 to display information about the failure prediction (S131).

[0098] Also, when the control system information 121 of any control system 3 matches the reference information 123 added in S123 (S124 "none"), the control cloud server 12 does not perform reporting (S132). Also, in the reporting rule table 122, when the necessity of reporting the failure prediction in the control system 3 is "no" (S126 "no"), the control cloud server 12 also does not perform reporting.

[0099] Here, the processing of this flowchart ends.

[0100] In FIG. 8, the failure information is included in the control system information 121. However, the failure information may be transmitted from the failure diagnosis module 25 to the control cloud server 12. Alternatively, an operator or a quality control person in charge of the control system 3 may input failure information indicating that the communication module 22 has failed due to aging deterioration into the control cloud server 12.

[0101] Next, the process flow executed by the control cloud server 12 in the case of transmitting update information will be described.

[0102] FIG. 9 is a flowchart showing an example of the process flow of transmitting update information according to the present embodiment.

[0103] First, the control cloud server 12 receives an input of a new version of the firmware from the user (S141). The user of the control cloud server 12 is, for example, a technical person in charge of the development and operation company of the control cloud server 12 and the cloud controller 11. Specifically, when a new version of the firmware of a device included in any of the control systems 3a to 3n is released, a technical person in charge of the development and operation company of the control cloud server 12 and the cloud controller 11 inputs module information such as the model number of the device to be updated with the firmware and the latest version of the firmware into the control cloud server 12.

[0104] In this case, the control cloud server 12 adds the input new version of the firmware to the reference information 123 of each control system (S142). Thereby, the input new version of the firmware is defined as the standard state of each of the plurality of control systems 3.

[0105] Then, the control cloud server 12 refers to the control system information 121 stored in the storage unit 120, and compares the control system information 121 with the reference information 123 added in S142. For example, if there is a device among the devices included in the control system information 121 registered in the control system information 121 whose firmware version is different from the latest version registered in the reference information 123 (S143 "Yes"), the control cloud server 12 searches the reporting rule table 122 for whether it is necessary to report the firmware update information in the control system 3 including the device (S144). Hereinafter, a device whose firmware version is different from the latest version registered in the reference information 123 is referred to as a device to be updated.

[0106] In the reporting rule table 122, if it is necessary to report the firmware update information in the control system 3 (S145 "Yes"), the control cloud server 12 searches the reporting rule table 122 for the access destination of the firmware update information in the control system 3 including the device to be updated (S146). The reporting processes of S147 to S150 are the same as the processes of S106 to S109 described in FIG. 7.

[0107] Also, if there is no device to be updated (S143 "No"), the control cloud server 12 does not report (S151). Also, if it is not necessary to report the firmware update information in the control system 3 in the reporting rule table 122 (S145 "No"), the control cloud server 12 does not report.

[0108] Here, the processing of this flowchart ends.

[0109] Next, the relationship between the failure diagnosis module 25 and the control cloud server 12 will be described with reference to FIGS. 10 to 12.

[0110] FIG. 10 is a diagram showing an example of communication between the control cloud server 12 and the local I / O system 2a during normal operation in this embodiment. In FIG. 10, no failure has occurred in the local I / O system 2a, and the communication of the Internet 5 between the local I / O system 2a and the cloud environment 1 has not been interrupted. In this case, the cloud controller 11a and the communication module 22a of the local I / O system 2a transmit and receive data via the Internet 5.

[0111] Specifically, the cloud controller 11a transmits a control signal to the remote I / Os 231a, 232a to the communication module 22a via the Internet 5 by executing a POU. Further, the communication module 22a transmits sensor data input to the remote I / Os 231a, 232a to the cloud controller 11a via the Internet 5.

[0112] Here, assume that a failure has occurred in the local I / O system 2a, or the communication of the Internet 5 between the local I / O system 2a and the cloud environment 1 has been interrupted.

[0113] FIG. 11 is a diagram showing an example of communication between the control cloud server 12 and the local I / O system 2a during abnormal operation in this embodiment. In the example shown in FIG. 11, the communication between the control cloud server 12 and the local I / O system 2a has been interrupted, and a failure has occurred in the local I / O system 2a.

[0114] In this case, since the control signal and sensor data cannot be transmitted and received between the cloud controller 11a and the communication module 22a, the failure of the local I / O system 2a is not detected on the cloud controller 11a side.

[0115] In this case, the failure diagnosis module 25a transmits failure information to the control cloud server 12 without passing through the communication module 22a. The failure diagnosis module 25a may communicate with the control cloud server 12 via a telephone line (not shown).

[0116] In this case, the control cloud server 12 compares the failure information acquired from the failure diagnosis module 25a with the control system information acquired from the cloud controller 11a. Since no failure of the local I / O system 2a is detected on the cloud controller 11a side, no failure information is transmitted from the cloud controller 11a. For this reason, a difference occurs between the failure information acquired by the control cloud server 12 from the failure diagnosis module 25a and the control system information acquired from the cloud controller 11a.

[0117] In this case, the control cloud server 12 stops the control system 3a by transmitting a control signal for shutting down the cloud controller 11a. Also, if the local I / O system 2a does not stop even when the cloud controller 11a shuts down due to the communication between the control cloud server 12 and the local I / O system 2a being interrupted, the control cloud server 12 transmits a control signal for stopping the local I / O system 2a to the failure diagnosis module 25a. In this case, the failure diagnosis module 25a controls the remote I / Os 231a and 232a to stop the local I / O system 2a.

[0118] Here, an error occurring in the local I / O system 2a will be described with reference to FIG. 12.

[0119] FIG. 12 is an example of a graph showing the values of sensor data input to the remote I / O 23a according to the present embodiment in time series. The sensor data is, for example, an analog value, but is not limited thereto.

[0120] In FIG. 12, for the sake of explanation, the error criterion is simplified. For example, the cloud controller 11a and the failure diagnosis module 25a determine that an error (failure) has occurred when the sensor data input by the remote I / O 23a every 10 ms exceeds the upper limit value (B) continuously 100 times.

[0121] Here, assume that during the time period from time t0 to t1, the communication between the cloud controller 11a and the communication module 22a is interrupted. When the communication between the cloud controller 11a and the communication module 22a is interrupted, even if the sensor data exceeds the upper limit value (B) during the interruption, the abnormal value is not transmitted to the cloud controller 11a.

[0122] For example, assume that during the time period from time t0 to t1, the sensor data exceeds the upper limit value (B) for 1.5 seconds. In this case, the sensor data exceeds the upper limit value (B) continuously 150 times. Since the fault diagnosis module 25a is included in the local I / O system 2a, the collection of sensor data continues even if the communication between the cloud controller 11a and the communication module 22a is interrupted. Therefore, the fault diagnosis module 25a detects an error when the sensor data exceeds the upper limit value (B) continuously 100 times, that is, at the time point when 1 second has elapsed since the sensor data first exceeded the upper limit value (B). In this case, the fault diagnosis module 25a transmits fault information indicating the detected error to the cloud controller 11a.

[0123] Also, even if the communication between the cloud controller 11a and the communication module 22a resumes at time t1, since the sensor data has already become equal to or less than the upper limit value (B), the cloud controller 11a does not detect an error even after the communication resumes. In such a case, there is a discrepancy between the fault information transmitted from the fault diagnosis module 25a to the cloud controller 11a and the control system information transmitted from the cloud controller 11a to the cloud controller 11a.

[0124] Note that the situation where a discrepancy in fault information occurs is not limited to the above example. For example, when both the cloud controller 11a and the fault diagnosis module 25a transmit fault information to the control cloud server 12, there may be a difference between the content of the fault information transmitted by the cloud controller 11a and the content of the fault information transmitted by the fault diagnosis module 25a. In this case, the control cloud server 12 transmits a control signal to the cloud controller 11a to shut down the cloud controller 11a.

[0125] In this way, the control cloud server 12 of the present embodiment acquires control system information 121 regarding the configurations and operating states of a plurality of control systems 3a to 3n from a plurality of cloud controllers 11a to 11n, generates reference information 123 for each of the plurality of control systems 3a to 3n based on the acquired control system information 121, compares the control system information 121 collected from the plurality of acquired cloud controllers 11a to 11n with the reference information 123, and when there are change points, reports to the reporting destinations for each control system information 121 by the reporting method registered in the reporting rule table 122. Therefore, according to the control cloud server 12 of the present embodiment, by centrally managing the control system information of the plurality of cloud controllers 11a to 11n in the control cloud server 12 provided in the cloud environment 1 and performing reporting, the information obtained within the control system 3 can be effectively utilized for reporting to the relevant parties of the control system 3.

[0126] For example, conventionally, since the local environment of the plant to be controlled by the control system was generally closed, when a problem occurred in the controller provided in the local environment itself, it might become difficult to analyze and manage the system information of the control system. On the other hand, since the control cloud server 12 of the present embodiment centrally manages the control system information of the plurality of cloud controllers 11a to 11n in the cloud environment 1, it can contribute to BCP (Business Continuity Planning) countermeasures.

[0127] In addition, when the local environment of the plant to be controlled by the control system is closed, it may be time-consuming for the operator of the control system and the engineer of the system integrator responsible for the development and maintenance of the control system to grasp the firmware update information released by the manufacturer of the firmware of the devices included in the control system. On the other hand, since the control cloud server 12 of the present embodiment also manages the firmware update information in the cloud environment 1, the operator and the engineer can easily grasp the firmware update information.

[0128] In addition, compared with the case where a function server similar to the control cloud server 12 of the present embodiment is physically installed in the local environment of an individual plant, it contributes to reducing the initial introduction and update costs.

[0129] In addition, when a failure occurs in any one of the plurality of control systems 3a to 3n, the control cloud server 12 of the present embodiment predicts the occurrence of a failure in another control system 3 and issues a report to the operator or engineer of the control system 3 in which the occurrence of the failure is predicted. Therefore, according to the control cloud server 12 of the present embodiment, by collectively managing the information of the plurality of control systems 3a to 3n in the control cloud server 12, the information on the failure that has occurred in a certain control system 3 can be utilized for providing information on the prediction of a failure in another control system 3.

[0130] In addition, when there is a discrepancy between the failure information acquired from the failure diagnosis module 25 by the control cloud server 12 of the present embodiment and the failure information included in the control system information acquired from the cloud controller 11 included in the same control system 3 as the failure diagnosis module 25, and when the cloud controller 11 is not down, a control signal is transmitted to the cloud controller 11 to cause it to go down. Therefore, according to the control cloud server 12 of the present embodiment, it is possible to reduce the possibility that the cloud controller 11 continues to operate in a state where a problem may have occurred. Further, the control cloud server 12 of the present embodiment can improve the reliability of the failure information by acquiring the failure information from both the failure diagnosis module 25 and the cloud controller 11.

[0131] In the present embodiment, when a new version of the firmware of the devices included in the control system 3 is released, it is assumed that the control cloud server 12 issues a report. However, the processing when a new version of the firmware is released is not limited to this. For example, when a new version of the firmware of the devices included in the control system 3 is released, the control cloud server 12 may report it to the cloud controller 11, and the cloud controller 11 may automatically update the new version of the firmware to the target devices.

[0132] The program executed by the control cloud server 12 of the present embodiment is provided by being recorded on a computer-readable recording medium such as a CD-ROM, a flexible disk (FD), a CD-R, or a DVD (Digital Versatile Disk) in a file in an installable format or an executable format.

[0133] Alternatively, the program executed by the control cloud server 12 of the present embodiment may be stored on a computer connected to a network such as the Internet and provided by downloading it via the network. Further, the program executed by the control cloud server 12 of the present embodiment may be configured to be provided or distributed via a network such as the Internet. Alternatively, the program executed by the control cloud server 12 of the present embodiment may be configured to be provided by being pre - incorporated into a ROM or the like.

[0134] The program executed by the control cloud server 12 of the present embodiment has a module configuration capable of executing each of the above - described processes. Examples of each process include an acquisition step, a reporting step, a search step, a comparison step, and an output step. As actual hardware, the CPU (processor) reads the program executed by the control cloud server 12 of the present embodiment from the above - mentioned storage medium and executes it, so that each of the above - mentioned units is loaded onto the main storage device, and a module capable of executing each process is generated on the main storage device.

[0135] Although the embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These novel embodiments can be implemented in various other forms, and various omissions, replacements, and changes can be made without departing from the gist of the invention. These embodiments and their modifications are included in the scope and gist of the invention and are included in the invention described in the claims and its equivalent scope.

Description of Reference Numerals

[0136] 1 Cloud environment 2, 2a~2n Local I / O system 3, 3a~3n Control system 5 Internet 10 Control cloud service 11, 11a~11n Cloud controller Communication modules 22, 22a to 22n Fault diagnosis modules 25, 25a to 25n Mail server 41 Memory unit 120 Control system information 121 Reporting rule table 122 Reference information 123 Display 211 Mail 411 Display 421 Remote I / O 23, 231a, 232a, 231n, 232n Messages M1, M2 POU concerned Management system S

Claims

1. stores a reporting rule table in which reporting rules for each of a plurality of control systems composed of a cloud controller and devices to be controlled by the cloud controller are registered; acquires control system information regarding the configuration and operating state of each of the plurality of control systems from a plurality of cloud controllers included in each of the plurality of control systems; refers to the reporting rule table based on the control system information to specify the necessity of reporting for each of the plurality of control systems, the access destination when reporting is required, and the content to be transmitted to the access destination, and transmits the transmission content to the specified access destination; generates reference information that defines the standard state of each of the plurality of control systems from the control system information; compares the newly acquired control system information with the reference information, and if there is a change point in the newly acquired control system information, refers to the reporting rule table to specify the access destination associated with the control system corresponding to the control system information having the change point, and the content to be transmitted to the access destination, and transmits the transmission content to the specified access destination; the control system information includes at least the configuration of devices included in the plurality of control systems, the usage period of the devices, and failure information regarding failures of the devices; when failure information is recorded in the control system information, reference information for each of the plurality of control systems is generated to define that devices of the same model number as the device in which the failure included in the failure information occurred and having a usage period within a range not exceeding a specified threshold from the usage period are not included; when there is a control system that does not match the reference information among the plurality of control systems, the transmission content is transmitted to the access destination associated with the control system by referring to the reporting rule table; A control cloud server.

2. Stores a reporting rule table in which reporting rules for each of a plurality of control systems composed of a cloud controller and devices to be controlled by the cloud controller are registered; Acquires control system information regarding the configuration and operating state of each of the plurality of control systems from a plurality of cloud controllers included in each of the plurality of control systems; Referring to the reporting rule table based on the control system information, determine the necessity of reporting for each of the plurality of control systems, the access destination when reporting is necessary, and the content to be transmitted to the access destination, and transmit the transmitted content to the identified access destination. Each of the plurality of control systems includes a fault diagnosis module provided outside the cloud environment that transmits fault information to the control cloud server when a fault occurs in the plurality of control systems. When obtaining fault information from the fault diagnosis module included in any of the plurality of control systems, and the control information obtained from the cloud controller included in the same control system as the fault diagnosis module does not include fault information, or there is a difference between the fault information included in the control information obtained from the cloud controller included in the same control system as the fault diagnosis module and the fault information obtained from the fault diagnosis module. Output a control signal to shut down the cloud controller included in the same control system as the fault diagnosis module. Referring to the reporting rule table, identify the reporting method and reporting destination associated with the control system including the cloud controller. Report to the identified reporting destination by the identified reporting method. Control cloud server.

3. The control system information includes at least the version of the firmware of the devices included in the plurality of control systems. Accept an input of a new version of the firmware. Referring to the reporting rule table, transmit the transmitted content associated with the control system to the access destination associated with the control system in which the version of the firmware of the device included in the control system information does not match the input new version. The control cloud server according to claim 1 or 2.

4. Generate reference information that defines the standard state of each of the plurality of control systems from the control system information. If there is a change point in the newly acquired control system information compared with the reference information, refer to the reporting rule table to identify the access destination associated with the control system corresponding to the control system information with the change point, and the content to be transmitted to the access destination, and transmit the transmitted content to the identified access destination. The control cloud server according to claim 2. **Claim 5** The control system information includes at least the configuration of the devices included in the plurality of control systems, the usage period of the devices, and failure information regarding the failure of the devices. When failure information is recorded in the control system information, generate the reference information for each of the plurality of control systems that defines that devices of the same model number as the device in which the failure occurred and within a usage period range equal to or less than the specified threshold from the model number and usage period included in the failure information are not included. If there is a control system that does not match the reference information among the plurality of control systems, transmit the transmitted content to the access destination associated with the control system by referring to the reporting rule table. The control cloud server according to claim 4.

Citation Information

Patent Citations

  • Printing abnormality displaying notifying device

    JP1989125695A

  • Plant alarm monitoring control system

    JP2011215832A

  • Cloud operation management system

    JP2013077247A

  • Control server

    JP2018084996A

  • Cloud service control device, cloud service control system, cloud service control method, cloud service control program and recording medium

    JP2018112829A