SCADA Web HMI System
The browser-based SCADA HMI system addresses the need for location and job-based operation rights by setting permissions for each HMI screen, enhancing safety in industrial plants by ensuring only authorized operators can access and control specific parts.
Patent Information
- Application Number
- JP2024549742
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-08-04
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2043-08-04
AI Technical Summary
Existing SCADA HMI systems require multiple screens to be displayed on a single client device, but lack sufficient mechanisms to set operation rights based on the location and job of the operator, posing a risk to the safety of industrial plants.
A browser-based SCADA HMI system that sets operation rights for each HMI screen based on the operation location and job of the operator, using a web server to transmit image and operation right information to web browsers, allowing detailed control over specific parts of the HMI screen.
Enables more detailed operation rights for each HMI screen, preventing safety compromises in industrial plants by ensuring that only authorized operators can access and control specific parts of the HMI screens.
Smart Images

Figure 0007736209000001 
Figure 0007736209000002 
Figure 0007736209000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a SCADA web HMI system. [Background technology]
[0002] SCADA (Supervisory Control And Data Acquisition) is known as a system for monitoring and controlling social infrastructure systems, such as steel rolling systems, power transmission and transformation systems, water and sewage treatment systems, building management systems, and road systems.
[0003] SCADA is a type of industrial control system that uses computers to monitor systems, control processes, and collect data. SCADA requires responsiveness (real-time performance) that matches the system's processing capabilities.
[0004] SCADA includes the following subsystems: HMI (Human Machine Interface), a monitoring and control system, remote input / output devices (RIO), and a communications infrastructure.
[0005] HMI is a mechanism that presents data from monitored devices to operators, allowing them to monitor and control the devices. Monitoring and control systems are composed of components such as programmable logic controllers (PLCs). Monitoring and control systems collect data from monitored devices and send control commands to the devices. Remote input / output devices connect to sensors installed in the monitored devices, convert sensor signals into digital data, and send that digital data to the monitoring and control system. The communications infrastructure connects the monitoring and control system to the remote input / output devices.
[0006] As an example of a SCADA HMI subsystem, Patent Document 1 discloses a system including an HMI client device and an HMI server device. In conventional SCADA such as that disclosed in Patent Document 1, the HMI server device transmits data received from a PLC to the HMI client device. The HMI client device has a computer main body, input devices such as a keyboard and mouse, and a monitor, and displays one HMI screen on the monitor. The applicant also recognizes Patent Document 2 below as being related to the present disclosure.
[0007] In the HMI subsystem disclosed in Patent Document 1, one HMI client device is required to display one HMI screen. From the viewpoint of reducing costs, installation space, failure rates, and communication load, it is desirable to be able to use multiple HMI screens simultaneously on one HMI client device. [Prior art documents] [Patent documents]
[0008] [Patent Document 1] Japanese Patent Publication No. 2017-27211 [Patent Document 2] Japanese Patent Publication No. 2019-114090 Summary of the Invention [Problem to be solved by the invention]
[0009] As a result of extensive research, the inventors of this application have developed a browser-based SCADA HMI subsystem. This subsystem allows HMI screens to be implemented as web applications running on a web browser. This allows multiple web browsers to be run on a single HMI client device, and HMI screens to be displayed on each web browser.
[0010] We will consider applying such a browser-based SCADA HMI subsystem to an industrial plant production line. In large-scale plants such as industrial plants, the production line is divided into multiple sections, each with its own operator's cab (pulpit). Each operator's cab is equipped with an HMI client device that runs a web browser that displays the HMI screen. An HMI server device that runs a web server that communicates with each web browser is installed in the electrical room.
[0011] The web browser of the HMI client device in Section 1 should be able to operate HMI screens related to the equipment in Section 1, and the web browser of the HMI client device in Section 2 should be able to operate HMI screens related to the equipment in Section 2. For this reason, the basic principle is to set operation rights for each HMI screen displayed in the web browser of each HMI client device according to the operating location of the HMI client device, i.e., according to the section in which the HMI client device is installed.
[0012] However, it has been found that simply setting the operation permission for each HMI screen depending on the operating location of the HMI client device is not sufficient, and there is a risk that the safety of the monitored equipment and ultimately the industrial plant may be compromised. For example, multiple operators operating HMI screens may not necessarily have the same job, but may have different jobs. In this case, it is necessary to allow some operation parts (specific operation parts) of the multiple operation parts on the HMI screen to be operated by, for example, an operator, but not be operated by an equipment operator. To meet this requirement, it is necessary to set more detailed operation rights for each HMI screen.
[0013] The present disclosure has been made to solve the above-mentioned problems, and aims to provide a SCADA web HMI system that is based on the function of setting operation rights for each HMI screen depending on the operation location of the HMI client device, and that is capable of setting operation rights for each HMI screen depending on the operator's job. [Means for solving the problem]
[0014] The first aspect relates to a SCADA web HMI system. The SCADA web HMI system includes an HMI server device that runs a web server and multiple HMI client devices that run at least one web browser that communicates with the web server. The HMI server device includes a server processor and a server memory. The server memory stores image data of an HMI screen for monitoring an industrial plant, screen operation right information, and part operation right information. The screen operation right information determines whether or not an HMI screen can be operated for each HMI screen displayed in the web browser depending on the operating location of the HMI client device. The part operation right information determines whether or not a specific operation part, which is a part of multiple operation parts on the HMI screen, can be operated for each HMI screen displayed in the web browser depending on the job of the operator of the HMI client device. Sakupa The server processor is configured to execute the web server capable of transmitting image data, screen operation right information, and part operation right information to a web browser. The HMI client device comprises a client processor, a client memory, and a monitor. The client memory stores the image data, screen operation right information, and part operation right information received from the web server. The client processor is configured to execute a web browser displayed on the monitor and a screen drawing process. The screen drawing process applies the operation rights determined in the screen operation right information to multiple operation parts on the HMI screen, and also applies the operation rights determined in the part operation right information according to job duties to specific operation parts on the HMI screen, thereby drawing the HMI screen on the web browser.
[0015] The second aspect has the following characteristics in addition to the first aspect: The screen operation right information further determines whether an HMI screen can be operated for each HMI screen displayed in the web browser depending on the job of the operator of the HMI client device. The part operation right information further determines whether specific operation parts, which are some of the operation parts on the HMI screen, can be operated for each HMI screen displayed in the web browser depending on the operation location of the HMI client device.
[0016] The third aspect has the following feature in addition to the first or second aspect: When the screen operation right information permits operation of the HMI screen by the web browser and the part operation right information does not permit operation of the specific operation part by the web browser, the screen drawing process draws the specific operation part in the web browser in an inoperable state, and draws operation parts other than the specific operation part among the multiple operation parts in the web browser in an operable state.
[0017] The fourth aspect has the following feature in addition to the first or second aspect: When the screen operation right information does not permit operation of the HMI screen by the web browser and the part operation right information permits operation of a specific operation part by the web browser, the screen drawing process draws the specific operation part in the web browser in an operable state, and draws operation parts other than the specific operation part among the multiple operation parts in an inoperable state. [Effects of the Invention]
[0018] According to the present disclosure, when an HMI screen is rendered in a web browser, the operation permissions defined in the screen operation authority information are applied to multiple operation parts on the HMI screen, and the operation permissions defined in the part operation authority information according to the operator's job are applied preferentially to specific operation parts on the HMI screen. Therefore, operation rights are set for each HMI screen according to the operation location of the HMI client device, and operation rights for specific operation parts on the HMI screen are set preferentially for each HMI screen according to the operator's job. This allows more detailed operation rights to be set for each HMI screen, preventing the safety of the monitored plant from being compromised. [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a diagram for explaining a configuration example of a hot rolling line to which a SCADA web HMI system according to an embodiment is applied; [Figure 2] 1 is a block diagram illustrating an example of an overview of the functions of an HMI server device and an HMI client device that constitute a SCADA web HMI system. [Figure 3] FIG. 1(a) is a diagram showing an example of an HMI screen related to a roughing mill, and FIG. 1(b) is a diagram showing an example of an HMI screen related to a finishing mill. [Figure 4] FIG. 10 is a diagram showing an example of a screen operation authority (operation location) table. [Figure 5] FIG. 10 is a diagram showing an example of a screen operation authority (job) table. [Figure 6] FIG. 10 is a diagram showing an example of a parts operating right (operating location) table. [Figure 7] FIG. 10 is a diagram showing an example of a parts operation authority (job) table. [Figure 8] 10 is a flowchart illustrating a screen drawing process according to an embodiment. [Figure 9] 1 is a block diagram showing an example of a hardware configuration of a SCADA web HMI system according to an embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0020] Hereinafter, with reference to the drawings, a SCADA web HMI system according to an embodiment of the present disclosure will be described using an example in which it is applied to a hot rolling line RL. The hot rolling line RL is an example of a production line in an industrial system. Note that common elements in each drawing are assigned the same reference numerals and redundant explanations will be omitted.
[0021] Fig. 1 is a diagram illustrating an example of the configuration of a hot rolling line RL to which a SCADA web HMI system 1 according to an embodiment is applied. Fig. 2 is a block diagram illustrating an example of the outline of functions possessed by an HMI server device and an HMI client device constituting the SCADA web HMI system. Fig. 3(a) is a diagram showing an example of an HMI screen related to a roughing mill, and Fig. 3(b) is a diagram showing an example of an HMI screen related to a finishing mill.
[0022] The hot rolling line RL rolls a material to be rolled, such as a metal material, Mr, to a desired thickness and width. The hot rolling line RL includes, as equipment, a heating furnace 2, a roughing mill 3, intermediate equipment 4, a finishing mill 5, a water cooling device 6, a coiler 7, and a roller table (not shown) that transports the material to be rolled Mr between them.
[0023] The heating furnace 2 raises the temperature of the rolled material Mr. Mr is extracted onto a roller table. The extracted rolled material Mr is a shaped block of metal called a slab. The roughing mill 3 is provided downstream of the heating furnace 2. The roughing mill 3 includes a single rolling stand or multiple rolling stands (two in this embodiment). The roughing mill 3 rolls the rolled material Mr multiple times in the forward direction (from upstream to downstream) and in the reverse direction (from downstream to upstream).
[0024] The intermediate equipment 4 is provided between the roughing mill 3 and the finishing mill 5. The intermediate equipment 4 includes an edge heater, a bar heater, a coil box, etc. The finishing mill 5 is provided downstream of the intermediate equipment 4. The finishing mill 5 has a plurality of rolling stands (eight in this embodiment). The finishing mill 5 rolls the material Mr to be rolled in one direction from upstream to downstream.
[0025] The water cooler 6 is provided downstream of the finishing rolling mill 5. The water cooler 6 injects water into the rolled material Mr to cool it to a target temperature. The coiler 7 is provided downstream of the water cooler 6. The rolled material Mr cooled by the water cooler 6 is wound around the coiler 7 to form a coiled product.
[0026] Each of the equipment 2 to 7 described above has an actuator such as an electric motor or a drive device. In addition, various sensors (not shown) serving as measuring devices are provided at key points in the rolling line RL. The various sensors sequentially measure the state of the material to be rolled Mr and the equipment 2 to 7. These actuators and sensors are connected to a PLC 8 via a control LAN 91. The PLC 8 is connected to a computer 10 located in a computer room via the control LAN 91. The computer 10 calculates setting values for each of the equipment 2 to 7 based on a rolling plan for the material to be rolled Mr and transmits the setting values to the PLC 8. The PLC 8 controls the actuators of the equipment 2 to 7 based on the setting values received from the computer 10 and control signals received from an HMI client device 12 (described later) via an HMI server device 11.
[0027] The SCADA web HMI system 1 includes the PLC 8, an HMI server device 11 located in an electrical room, and an HMI client device 12. The PLC 8, HMI server device 11, and HMI client device 12 are connected via an information LAN 92 such as Ethernet (registered trademark).
[0028] The PLC 8 periodically transmits packets containing block data to the information LAN 92 by multicast or broadcast. Block data is a collection of PLC signals. One block data contains tens to hundreds of PLC signals. The PLC signals include input / output signals and alarm signals. The input / output signals are generated by operation of the HMI client device 12 and include control signals for controlling the actuators of the facility devices 2 to 7 (hereinafter also referred to as "actuator control signals") and detection signals measured by each sensor (hereinafter also referred to as "sensor detection signals"). The PLC 8 receives the control signals generated by operation of operation parts on an HMI screen 17 (described later) of the HMI client device 12 from the HMI server device 11.
[0029] The hot rolling line RL is divided into a plurality of sections (two in this embodiment) corresponding to the equipment 2 to 7. Each section has an operator's cab (pulpit). The section having the roughing mill 3 has an RM (Roughering Mills) operator's cab 13. The section having the finishing mill 5 has an FM (Finishing Mills) operator's cab 14. The number of sections and operator's cabs may each be three or more.
[0030] Each operator's cab 13, 14 is equipped with an HMI client device 12a, 12b having a monitor 15a, 15b, respectively. The monitors 15a, 15b of the HMI client devices 12a, 12b display web browsers 16a, 16b, and HMI screens 17a, 17b are displayed on the displayed web browsers 16a, 16b. In this specification, when there is no need to distinguish between the reference numerals 12a, 15a to 17a and the reference numerals 12b, 15b to 17b, they will simply be referred to as 12, 15 to 17.
[0031] The HMI client device 12a in the RM operator's cab 13 displays an HMI screen 17a related to the roughing mill 3 on a web browser 16a, and makes the displayed HMI screen 17a (specifically, at least one part displayed on the HMI screen 17a) operable. This HMI client device 12a can execute a web browser 16b and display other HMI screens 17b on the web browser 16b, but in principle, it is required that the HMI screen 17b be inoperable. Similarly, the HMI client device 12b in the FM operator's cab 14 displays an HMI screen 17b related to the finishing mill 5 on the web browser 16b, and makes the displayed HMI screen 17b operable. This HMI client device 12b can execute a web browser 16a and display other HMI screens 17a on the web browser 16a, but in principle, it is required that the HMI screen 17a be inoperable. Therefore, in this embodiment, the screen operation authority (operation location) table 25 shown in Figure 4, which will be described later, is used to set the screen operation authority for each HMI screen 17 (G10, G11, G11) depending on the operation location of the HMI client device 12.
[0032] However, the roles of the multiple operators who operate the HMI client device 12 are not necessarily the same, and the roles of the multiple operators may be different. Roles include an operator who performs manual operations (manual intervention) on facility equipment, and a facility technician who performs maintenance, including repairing facility equipment and replacing components. Among the multiple HMI screens 17 (G10, G11, G12) displayed on the HMI client device 12, there is a case where it is required that the HMI screen 17 (G10) can be operated by an operator but not by a facility technician. Therefore, in this embodiment, a screen operation authority (role) table 26 shown in FIG. 5 (described later) is used to set the screen operation authority for each HMI screen 17 (G10, G11, G11) according to the role of the operator who has logged in to the HMI client device 12.
[0033] In addition, there are cases where it is required that specific operation parts (described later) displayed on the HMI screen 17 can be operated from the HMI client device 12 that does not have the screen operation right depending on the operation location. Operational rights In some cases, it may be required to disable operation from an HMI client device 12 having a specific operation part. Therefore, in this embodiment, the operation right (operation possibility) of a specific operation part is set by the operation location using a part operation right (operation location) table 27 shown in Fig. 6, which will be described later.
[0034] Furthermore, there are cases where different operators operate the same HMI screen 17. For example, there are cases where it is required that a specific operation part for performing manual operation can be operated by an operator but not by an equipment technician. For example, there are cases where it is required that a specific operation part for performing maintenance such as roll replacement can be operated by an equipment technician but not by an operator. Therefore, in this embodiment, the operation rights (operability) of specific operation parts by job are set using a part operation rights (job) table 28 shown in FIG. 7, which will be described later.
[0035] The HMI server device 11 shown in Figure 2 transmits and receives PLC signals to and from the PLC 8, and also runs a web server. As shown in Figure 9, which will be described later, the HMI server device 11 includes a processor 111 that executes various processes and a memory 112 that stores various information. The processor 111 and the memory 112 correspond to the server processor and server memory, respectively, in the claims. The processor 111 executes a program stored in the memory 112, causing the processor 111 to function as a PLC signal processing unit 21 and a web server processing unit 22. The PLC signal processing unit 21 and the web server processing unit 22 can transmit and receive data to and from each other through inter-process communication.
[0036] The PLC signal processing unit 21 periodically receives a PLC signal including a sensor detection signal from the PLC 8 and transmits the received PLC signal to the web browser processing unit 31 (each web browser 16) via the web server processing unit 22. The PLC signal processing unit 21 also receives a PLC signal including an actuator control signal from each web browser 16 of the HMI client device 12 via the web server processing unit 22 and transmits the received PLC signal to the PLC 8.
[0037] The web server processing unit 22 can communicate with the web browser 16 (web browser processing unit 31) of each HMI client device 12 using HTTP (Hypertext Transfer Protocol), HTTPS (Hypertext Transfer Protocol Secure), and WebSocket. The web server processing unit 22 transmits all or part of content in response to a request from each web browser 16 (web browser processing unit 31). The content includes an HTML file (not shown), an SVG (Scalable Vector Graphics) file 23 which is image data for each HMI screen 17, a parts library 24, a screen operation authority (operation location) table 25, a screen operation authority (job) table 26, a part operation authority (operation location) table 27, and a part operation authority (job) table 28.
[0038] The parts library 24 includes a collection of scripts that describe the operation for each type of part (hereinafter referred to as "part type") displayed on the HMI screen 17. The scripts are JavaScript (registered trademark) programs defined for each part type. The scripts are given parameter values as necessary and can be executed on each web browser 16. The parameter values include, for example, the presence or absence of screen operation rights defined in the screen operation rights (operation location) table 25 and the screen operation rights (job) table 26, and the presence or absence of specific part operation rights defined in the part operation rights (operation location) table 27 and the part operation rights (job) table 28.
[0039] 4 is a diagram showing an example of the screen operation authority (operation location) table 25. The screen operation authority (operation location) table 25 includes screen operation authority (operation location) information that defines whether or not each HMI screen 17 has screen operation authority (whether or not operation is permitted) depending on the operation locations of the HMI client devices 12a and 12b, specifically, depending on the RM operator's cab 13 and FM operator's cab 14 where the HMI client devices 12a and 12b are installed. "G10" to "G12" are the screen names of the HMI screens 17 displayed on the web browser 16 executed by each HMI client device 12. "G10" is the screen name of the HMI screen 17a shown in FIG. 3(a), and "G11" is the screen name of the HMI screen 17b shown in FIG. 3(b). 4, the HMI client device 12a operated in the RM operator's cab 13 has the screen operation right to operate the HMI screen 17a (G10) on the web browser 16a, but does not have the screen operation right to operate the HMI screen 17 (G11, G12) on the web browser 16. Also, the HMI client device 12b operated in the FM operator's cab 14 has the screen operation right to operate the HMI screen 17b (G11) on the web browser 16b, but does not have the operation right to operate the HMI screen 17 (G10, G12) on the web browser 16.
[0040] 5 is a diagram showing an example of the screen operation authority (job) table 26. The screen operation authority (job) table 26 includes screen operation authority (job) information that defines whether or not the operator has screen operation authority for each HMI screen 17 (whether or not operation is permitted) according to the job of the operator who has logged in to the HMI client device 12, specifically, according to the operator and equipment manager. In the example shown in FIG. 5, when an operator logs in, he or she has screen operation authority to operate all HMI screens 17 (G10, G11, G12). When an equipment manager logs in, he or she has screen operation authority to operate HMI screen 17 (G11) but does not have screen operation authority to operate HMI screens 17 (G10, G12).
[0041] 6 is a diagram showing an example of the part operation right (operation location) table 27. The part operation right (operation location) table 27 includes part operation right (operation location) information that defines whether or not a specific part displayed on each HMI screen 17 has operation rights (operation possibility) depending on the operation locations of the HMI client devices 12a and 12b, specifically, depending on the RM driver's cab 13 and the FM driver's cab 14 where the HMI client devices 12a and 12b are installed. In the example shown in FIG. 6, for the HMI client device 12a operated in the RM driver's cab 13, the specific operation part (1_PL) on the HMI screen 17 (G10) is designated as inoperable, and the specific operation part (3_PL) on the HMI screen 17 (G11) is designated as operable. In addition, the HMI client device 12b operated in the FM driver's cab 14 has a specific operation part (1_PL) on the HMI screen 17 (G10) designated as operable, and a specific operation part (2_PL) on the HMI screen 17 (G11) designated as inoperable.
[0042] FIG. 7 is a diagram showing an example of the part operation right (job) table 28. The part operation right (job) table 28 includes part operation right (job) information that defines whether an operator who has logged in to the HMI client device 12 has operation rights (operability) for specific parts displayed on each HMI screen 17, depending on the job of the operator, specifically, the operator and the equipment technician. In the example shown in FIG. 7, when an operator logs in, the specific operation part (1_PL) on the HMI screen 17 (G11) is designated as operable, and the specific operation parts (4_PL, 5_PL) are designated as inoperable. The specific operation part (1_PL) is, for example, an operation part for performing manual operation (manual intervention). Furthermore, when an equipment technician logs in, the specific operation part (1_PL) on the HMI screen 17 (G11) is designated as inoperable, and the specific operation parts (4_PL, 5_PL) are designated as operable. The specific operation parts (4_PL, 5_PL) are, for example, operation parts for performing maintenance.
[0043] The HMI client device 12 (12a, 12b) includes a processing circuit 30 (30a, 30b) and a monitor 15 (15a, 15b). As shown in FIG. 9 (described later), the processing circuit 30 includes a processor 121 that executes various processes and a memory 122 that stores various information. The processor 121 and the memory 122 correspond to the client processor and client memory, respectively, in the claims. The processor 121 executes a program stored in the memory 122, causing the processor 121 to function as a web browser processing unit 31 (31a, 31b). In this specification, when there is no need to distinguish between the reference numerals 30a-31a and 30b-31b, they will simply be referred to as 30-31.
[0044] The web browser processing unit 31 is executed for each web browser 16. The web browser 16 renders an HMI screen 17 for monitoring and controlling the hot rolling line RL. The HMI screen 17 is switched to another HMI screen 17 by an operator's operation. A plurality of parts are arranged on the HMI screen 17. The parts include, for example, operation parts (1_PL, 2_PL, 3_PL,...) for sending control signals to the PLC 8 in response to an operator's operation, display parts whose display state (numeric values, characters, colors, shapes) changes in response to received PLC signals, and screen transition parts for switching to another HMI screen. The operation parts include specific operation parts (1_PL, 2_PL, 3_PL,..., 5_PL) whose operatability is determined in the part operation authority (operation location) table 27 and the part operation authority (job) table 28, as described above.
[0045] When each web browser 16 is started, the web browser processing unit 31 receives the HTML file, the SVG file 23, and the part library 22 from the web server processing unit 22. 4、The web browser 16 receives a screen operation authority (operation location) table 25, a screen operation authority (job) table 26, a part operation authority (operation location) table 27, a part operation authority (job) table 28, and the like, and stores them in memory 122. Each web browser 16 (web browser processing unit 31) also acquires the job of the operator who logged in to the HMI client device 12 and stores it in memory 122. The operator's job can be acquired, for example, by referencing a group user list that collectively registers the login IDs and jobs of multiple operators. Based on this, the web browser 16 renders an HMI screen 17 on which multiple parts, including operation parts (including specific operation parts) and display parts, are arranged. Each web browser 16 also runs in a mode that does not use a cache, so that it always acquires the latest files from the web server processing unit 22 when it starts up.
[0046] The web browser processing unit 31 reads the screen operation authority (operation location) table 25 received from the HMI server device 11, and determines whether each HMI screen 17 can be operated (whether or not the operation authority exists) based on the operation location for each web browser 16. The web browser processing unit 31 also reads the screen operation authority (job) table 26 received from the HMI server device 11, and determines whether each HMI screen 17 can be operated (whether or not the operation authority exists) based on the job for each web browser 16.
[0047] At the same time, the web browser processing unit 31 reads the part operation right (operation location) table 27 received from the HMI server device 11 and determines whether specific operation parts (1_PL, 2_PL, 3_PL, . . . , 5_PL) on the HMI screen 17 (for example, G11) can be operated according to the operation location for each web browser 16. The web browser processing unit 31 also reads the part operation right (job) table 28 received from the HMI server device 11 and determines whether specific operation parts (1_PL, 2_PL, 3_PL, . . . , 5_PL) on the HMI screen 17 (G11) can be operated according to the job of the operator who has logged in to the HMI client device 12.
[0048] Furthermore, the web browser processing unit 31 executes screen drawing processing 32. The screen drawing processing 32 preferentially applies the operation rights (operation possibility) according to the operation location and the operator's job defined in the part operation right (operation location) table 27 and the part operation right (job) table 28 to the specific operation parts (1_PL, 2_PL, 3_PL, . . . , 5_PL) on the HMI screen 17 (G11), and applies the screen operation rights (operation possibility) defined in the screen operation right (operation location) table 25 and the screen operation right (job) table 26 to the operation parts (6_PL, . . . ) on the HMI screen 17 other than the specific operation parts, thereby drawing the HMI screen 17 (G11) on the web browser 16.
[0049] Specifically, the web browser processing unit 31 executes the script for each part type included in the above-mentioned part library 24 according to the part type of the part arranged on the HMI screen 17 (G11). Here, we will explain operation parts, among the part types, whose behavior changes depending on the presence or absence (parameter value) of screen operation rights and part operation rights passed to the script.
[0050] For operation parts (1_PL, 2_PL, 3_PL, 4_PL, ...), if the web browser 16 is not permitted to operate the HMI screen 17 in the screen operation authority (operation location) table 25 and the screen operation authority (job) table 26, then, in principle, all operation parts arranged on the HMI screen 17 of the web browser 16 are drawn in an inoperable state. Also, if the web browser 16 is permitted to operate the HMI screen 17 in the screen operation authority (operation location) table 25 and the screen operation authority (job) table 26, then, in principle, all operation parts arranged on the HMI screen 17 of the web browser 16 are drawn in an operable state.
[0051] In addition, when operation rights are defined in the part operation right (operation location) table 27 and the part operation right (job) table 28 for specific operation parts (1_PL, 2_PL, 3_PL, . . . , 5_PL) of the HMI screen 17 according to the operation location or the job of the operator, the operation rights defined in the part operation right (operation location) table 27 and the part operation right (job) table 28 are applied preferentially to the specific operation parts. For operation parts not defined in the part operation right (operation location) table 27 and the part operation right (job) table 28, the operation rights defined in the screen operation right (operation location) table 25 and the screen operation right (job) table 26 are applied.
[0052] In the inoperable state, the operation parts do not accept operations (e.g., mouse clicks) by operators, including operators in charge of operations and equipment personnel. In the operable state, the operation parts accept operations by operators and transmit control signals corresponding to the operations to the HMI server device 11.
[0053] Furthermore, when HMI client device 12 receives a PLC signal from HMI server device 11, web browser processing unit 31 dynamically sets screen operation rights and part operation rights for each HMI screen 17 displayed on each web browser 16 in accordance with the received PLC signal. In this case as well, as described above, screen operation rights (operation location) table 25, screen operation rights (job) table 26, part operation rights (operation location) table 27, and part operation rights (job) table 28 are referenced, and therefore detailed description thereof will be omitted.
[0054] Next, the drawing of the HMI screen 17 in each web browser 16 depending on whether or not the operation right is present will be specifically described with reference to Fig. 8. Fig. 8 is a flowchart for explaining an example of the drawing process of the HMI client device 12.
[0055] When an operator logs in to HMI client device 12, the routine shown in Figure 8 is started. The operator's job is either an operator or a facility manager. In step S1, HMI client device 12 executes (launches) web browser 16. Web browser processing unit 31 displays web browser 16 on default monitor 15 at a predetermined initial position and size, regardless of the position and size of web browser 16 when it is closed.
[0056] In step S2, each web browser 16 acquires the role of the logged-in operator from the operator's login ID, and also acquires the role of the HMI server device 11 The contents include the above-mentioned HTML file, SVG file 23, part library 24, screen operation authority (operation location) table 25, screen operation authority (job) table 26, part operation authority (operation location) table 27, and part operation authority (job) table 28. Note that it is sufficient to obtain the part library 24 and each of the tables 25 to 28 only when the web browser 16 is started up.
[0057] In steps S3 to S12, the web browser processing unit 31 draws the HMI screen 17 specified in the web browser 16 in accordance with the screen operation authority (operation location) table 25, screen operation authority (job) table 26, part operation authority (operation location) table 27 and part operation authority (job) table 28 obtained in step S2 above.
[0058] The web browser processing unit 31 refers to the screen operation authority (operation location) table 25 and determines whether or not the operation location of the HMI client device 12 has screen operation authority for the HMI screen 17 (step S3). If the operation location does not have screen operation authority, the process proceeds to step S9. On the other hand, if the operation location has screen operation authority, the process proceeds to step S4.
[0059] In step S4, the screen operation authority (job) table 26 is referenced to determine whether or not the job acquired in step S2 has screen operation authority for the HMI screen 17. If the job does not have screen operation authority, the process proceeds to step S9. On the other hand, if the job does have screen operation authority, the process proceeds to step S5.
[0060] In step S5, the part operation right (operation location) table 27 is referenced to determine whether or not there is a specific operation part designated as inoperable by the operation location. If there is a specific operation part designated as inoperable by the operation location, the process proceeds to step S8. On the other hand, if there is no specific operation part designated as inoperable by the operation location, the process proceeds to step S6.
[0061] In step S6, the part operation right (job) table 28 is referenced to determine whether there are any specific operation parts designated as inoperable by the job. If there are any specific operation parts designated as inoperable by the job, the process proceeds to step S8. On the other hand, if there are no specific operation parts designated as inoperable by the job, the web browser processing unit 31 renders all operation parts on the HMI screen 17 in an operable state (step S7). After that, this routine is temporarily terminated.
[0062] In step S8, the specific operation part on the HMI screen 17 is drawn in an inoperable state, and the operation parts other than the specific operation part are drawn in an operable state (step S8). After that, this routine is temporarily ended.
[0063] In step S9, the part operation right (operation location) table 27 is referenced to determine whether or not there is a specific operation part designated as operable by the operation location. If there is a specific operation part designated as operable by the operation location, the process proceeds to step S12. On the other hand, if there is no specific operation part designated as operable by the operation location, the process proceeds to step S10.
[0064] In step S10, the part operation right (job) table 28 is referenced to determine whether or not there is a specific operation part designated as operable by the job. If there is a specific operation part designated as operable by the job, the process proceeds to step S12. On the other hand, if there is no specific operation part designated as operable by the job, the process proceeds to step S11.
[0065] In step S11, the web browser processing unit 31 renders all operation parts on the HMI screen 17 in an inoperable state (step S11), and then ends this routine for the time being.
[0066] In step S12, the web browser processing unit 31 renders the specific operation part on the HMI screen 17 in an operable state, and renders operation parts other than the specific operation part in an inoperable state (step S12). After that, this routine is temporarily terminated.
[0067] The processing of steps S1 to S12 is performed every time the operator logs in to the HMI client device 12 and starts up the web browser 16.
[0068] According to the routine described above, if the screen operation authority (operation location) table 25 allows operation of the HMI screen 17 by the operation location, but the part operation authority (job) table 28 does not allow operation of a specific operation part by the job, the web browser processing unit 31 draws the specific operation part in the web browser 16 in an inoperable state and draws operation parts other than the specific operation part in the web browser 16 in an operable state.
[0069] The flowchart in FIG. 8 described above describes the drawing of the HMI screen 17 when the web browser 16 is started. This makes it possible to statically set the presence or absence of screen operation rights and operation rights for operation parts on the HMI screen 17 for each HMI screen 17. In a logged-in state, an operator may press a screen transition button on the HMI screen 17 to transition to another HMI screen 17. In this case, the web browser processing unit 31 executes the process of the HMI server device 11By newly acquiring the HTML file and SVG file 23 related to the other HMI screen 17 from the HMI screen 17 and executing the processes from step S3 onwards, the presence or absence of screen operation rights and part operation rights is statically set for each HMI screen 17.
[0070] After the screen operation rights and part operation rights are statically set in this manner, when the HMI client device 12 receives a PLC signal from the HMI server device 11, the presence or absence of screen operation rights and part operation rights is statically set for each HMI screen 17 by executing the processing of steps S2 to S12.
[0071] As described above, according to this embodiment, when the HMI screen 17 is rendered on the web browser 16, the operation permissions defined in the screen operation authority (operation location) table 25 are applied to multiple operation parts on the HMI screen 17, and the operation permissions defined according to the job in the part operation authority (job) table 28 are applied preferentially to specific operation parts on the HMI screen 17. Therefore, operation rights are set for each HMI screen 17 according to the operation location of the HMI client device 12, and operation rights for specific operation parts are set preferentially for each HMI screen 17 according to the job of the operator. This allows more detailed operation rights to be set for each HMI screen 17, making it possible to prevent the safety of the equipment 2 to 7 being monitored and ultimately the hot rolling line RL from being compromised.
[0072] FIG. 9 is a block diagram showing an example of the hardware configuration of the HMI server device 11 and the HMI client device 12. As shown in FIG.
[0073] Each process of the HMI server device 11 described above is realized by a processing circuit. The processing circuit is configured by connecting a processor 111, a memory 112, and a network interface 113. The processor 111, which serves as a server processor, realizes each function of the HMI server device 11 by executing various programs stored in the memory 112, which serves as a server memory. The memory 112 includes a main storage device and an auxiliary storage device. The memory 112 pre-stores the HTML file, SVG file 23, part library 24, screen operation authority (operation location) table 25, screen operation authority (job) table 26, part operation authority (operation location) table 27, and part operation authority (job) table 28 described above. The network interface 113 is connected via the information LAN 92 to be able to communicate with other devices within the same network.
[0074] Each process of the HMI client device 12 described above is realized by a processing circuit 30. The processing circuit 30 is configured by connecting a processor 121, a memory 122, a network interface 123, an input interface 124, and a monitor 125. The processor 121 realizes each function of the HMI client device 12 by executing various programs stored in the memory 122. The memory 122 includes a main storage device and an auxiliary storage device. The network interface 123 is connected to other devices within the same network via the information LAN 92 so as to be able to communicate with them. The input interface 124 is a set of input devices including a keyboard, a mouse, a touch panel, etc.
[0075] Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above embodiments and can be modified in various ways without departing from the spirit and scope of the present disclosure. For example, in the above embodiments, an example was described in which the operator's job duties include an operator and an equipment manager. However, in addition to the operator and equipment manager, the job duties can also include a safety manager who is authorized to operate all specific operation parts. Furthermore, operators may be divided into multiple groups based on their level of proficiency in manual operation. For example, operators may be divided into senior operators (senior operators) who are highly skilled in manual operation and junior operators (junior operators) who are less skilled than the senior operators. The present disclosure can be applied, for example, to cases in which the operator's job duties include senior operators, junior operators, equipment managers, and safety managers.
[0076] Furthermore, for example, when the HMI client device 12 is not operated by an operator in charge of the equipment, the duties of the operators can be configured to include senior operators who are highly skilled in manual operations and junior operators who are less skilled than the senior operators. In this case, too, it is possible to restrict the operation of specific operation parts by junior operators, and as a result, it is possible to prevent the safety of the equipment being monitored, and ultimately the hot rolling line RL, from being impaired, as in the above embodiment.
[0077] Furthermore, in the above embodiment, the case where the equipment of the hot rolling line RL is monitored has been described as an example, but the present invention can also be applied to the case where the equipment of other industrial plants is monitored.
[0078] Furthermore, when the number, quantity, amount, range, etc. of each element is mentioned in the above embodiments, the present disclosure is not limited to the mentioned numbers unless otherwise specified or clearly specified in principle. Furthermore, the structures, etc. described in the above embodiments are not necessarily essential to the present disclosure unless otherwise specified or clearly specified in principle. [Explanation of symbols]
[0079] 1...SCADA web HMI system, 2...heating furnace, 3...roughing mill, 4...intermediate equipment, 5...finishing mill, 6...water cooling device, 7...coiler, 8...PLC, 91...control LAN, 92...information LAN, 10...computer, 11...HMI server device, 12, 12a, 12b...HMI client device, 13...RM operator's cab, 14...FM operator's cab, 15, 15a, 15b...monitor, 16, 16a, 16b...web browser, 17, 17a, 17b...HMI screen, 21...PLC signal processing unit, 22...web server processing unit, 23...SVG file, 24... Parts library, 25...screen operation authority (operation location) table, 26...screen operation authority (job) table, 27...part operation authority (operation location) table, 28...part operation authority (job) table, 30, 30a, 30b...processing circuit, 31, 31a, 31b...web browser processing unit, 32, 32a, 32b...screen drawing process, 111, 121...processor, 112, 122...memory, 113, 123...network interface, 124...input interface, RL...hot rolling line, Mr...rolled material, G10, G11, G12...screen given name, 1_PL,2_PL,3_PL,4_PL,5_P L… Operation parts, 1_PL, 2_PL, 3_PL, 4_PL, 5_PL...specific operation parts
Claims
1. 1. A SCADA web HMI system comprising: an HMI server device running a web server; and a plurality of HMI client devices running at least one web browser communicating with the web server, The HMI server device includes a server processor and a server memory, the server memory stores image data of an HMI screen for monitoring an industrial plant, screen operation authority information, and part operation authority information; the screen operation right information determines whether or not an HMI screen can be operated for each HMI screen displayed on a web browser depending on the operation location of the HMI client device; The part operation right information determines whether or not a specific operation part, which is a part of a plurality of operation parts on an HMI screen, can be operated for each HMI screen displayed on a web browser according to the job of the operator of the HMI client device, and the server processor is configured to execute the web server capable of transmitting the image data, the screen operation authority information, and the part operation authority information to the web browser; the HMI client device comprises a client processor, a client memory, and a monitor; the client memory stores the image data, the screen operation right information, and the part operation right information received from the web server; The client processor: Execute the web browser displayed on the monitor; a SCADA web HMI system configured to apply the operation permissions defined in the screen operation authority information to the plurality of operation parts on the HMI screen, and to apply the operation permissions defined in the part operation authority information according to the job function to the specific operation parts on the HMI screen with priority, and to execute a screen drawing process to draw the HMI screen on the web browser.
2. The screen operation authority information further defines whether or not an operator of the HMI client device can operate each HMI screen displayed in a web browser according to the job of the operator of the HMI client device, 2. The SCADA web HMI system of claim 1, wherein the part operation right information further determines whether or not specific operation parts, which are some of the operation parts on the HMI screen, can be operated for each HMI screen displayed in a web browser, depending on the operation location of the HMI client device.
3. The screen drawing process includes: When the screen operation right information permits the operation of the HMI screen by the web browser, and the part operation right information does not permit the operation of the specific operation part by the web browser, The specific operation part is rendered in an inoperable state on the web browser; 3. The SCADA web HMI system according to claim 1, wherein operation parts other than the specific operation part among the plurality of operation parts are rendered in an operable state on the web browser.
4. The screen drawing process includes: When the screen operation right information does not permit the operation of the HMI screen by the web browser, and the part operation right information permits the operation of the specific operation part by the web browser, drawing the specific operation part in the web browser in an operable state; 3. The SCADA web HMI system according to claim 1, wherein operation parts other than the specific operation part among the plurality of operation parts are rendered in an inoperable state on the web browser.
Citation Information
Patent Citations
Method and apparatus for controlling process plant with location aware mobile control devices
JP2014225234A
Plant control system
JP2017027211A
Monitoring control system
JP2019114090A
Securing access to SCADA networks from remote terminal units
JP2020518903A
Scada web HMI client device and scada web HMI system
WO2023127040A1