Scada system

The SCADA system synchronizes alarm data across redundant servers using time-stamped generation and selection rules, ensuring consistent display and operation stability in active/active configurations.

WO2026022911A1PCT designated stage Publication Date: 2026-01-29TMEIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/026206
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-22
Publication Date
2026-01-29

AI Technical Summary

Technical Problem

In redundant SCADA systems with active/active server configurations, ensuring that alarm information time stamps are synchronized and consistent across both servers to maintain identical operator monitoring regardless of the connected server.

Method used

A SCADA system with a redundant configuration that includes a pair of SCADA servers, where each generates alarm data with a current time stamp and transmits it to the other server, and employs a predetermined rule for selecting either local or remote alarm data to equalize time stamps, using functional units like communication drivers, alarm data management units, and selection processing units to synchronize alarm data across servers.

Benefits of technology

Ensures consistent alarm occurrence/recovery times across both servers, maintaining system operation stability and identical monitoring terminal displays even when server connections are switched.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024026206_29012026_PF_FP_ABST
    Figure JP2024026206_29012026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention provides a SCADA system in which the time given to alarm information can be equalized between two redundant SCADA servers. The SCADA system includes a first SCADA server and a second SCADA server configured to be able to receive alarm-related signals from a PLC. Each of the first SCADA server and the second SCADA server, upon receiving an alarm-related signal from the PLC, generates alarm data in which the current time has been given to the alarm-related signal, and transmits the generated local alarm data to the other SCADA server. In addition, each of the SCADA servers receives remote alarm data from the other SCADA server. Furthermore, each of the SCADA servers, upon acquiring at least one of the local alarm data or the remote alarm data, selects either the local alarm data or the remote alarm data according to a predetermined rule.
Need to check novelty before this filing date? Find Prior Art

Description

SCADA system

[0001] The present disclosure relates to a SCADA system with a redundant configuration.

[0002] Patent Document 1 discloses technology related to a SCADA web HMI system. SCADA (Supervisory Control And Data Acquisition) is known as a mechanism for monitoring and controlling social infrastructure systems, such as steel rolling systems, power transmission and transformation systems, water and sewerage treatment systems, building management systems, and road systems.

[0003] SCADA is a type of industrial control system that uses computers to monitor systems and control processes. SCADA generally consists of multiple subsystems, such as a human-machine interface (HMI), a supervisory control system, a remote terminal unit (RTU), and a communications infrastructure. The HMI subsystem presents data about the target process to the operator, allowing the operator to monitor and control the process. The supervisory control system is composed of components such as a programmable logic controller (PLC), and collects process data and sends commands to the process. The remote input / output (RIO) connects to sensors installed in the process, converts the sensor signals into digital data, and sends the digital data to the supervisory control system. The communications infrastructure connects the supervisory control system and the remote supervisory control system.

[0004] International Publication No. 2021 / 070315

[0005] One method for ensuring stable operation of a SCADA system is to introduce a redundant configuration. One redundant configuration is the SCADA server, and known SCADA server redundancy methods are the active / passive method and the active / active method. Of these, the active / active method is a method in which two duplicated servers operate simultaneously, and the two redundant servers are required to operate in coordination.

[0006] Let's consider alarm information sent from a PLC to a SCADA server. The two redundant SCADA servers each independently assign a time stamp to the alarm information. However, to ensure that the operator's monitoring terminal operates identically regardless of which SCADA server it is connected to, it is undesirable for the times assigned to the alarm information to differ between the two servers. Therefore, the challenge is to equalize the times assigned to the alarm information between both SCADA servers.

[0007] The present disclosure relates to a SCADA system. The SCADA system includes a pair of a first SCADA server and a second SCADA server configured to receive an alarm-related signal from a programmable logic controller. Each of the first SCADA server and the second SCADA server performs an alarm data generation process when receiving the alarm-related signal from the programmable logic controller, generating alarm data by adding at least the current time to the alarm-related signal. Furthermore, when performing the alarm data generation process, the first SCADA server and the second SCADA server transmit the generated alarm data to the other SCADA server. Furthermore, when performing at least one of the alarm data generation process and the alarm data reception process, the first SCADA server and the second SCADA server select either the local alarm data generated by the alarm data generation process or the remote alarm data received by the alarm data reception process according to a predetermined rule.

[0008] In the above-described SCADA system, when alarm data is generated by one SCADA server, the alarm data is transmitted to the other SCADA server. Then, a process of selecting either local alarm data or remote alarm data according to a certain rule is performed in both SCADA servers. By selecting alarm data according to a unified rule, alarm data with the same time stamp can be selected in both SCADA servers, enabling the times stamped on alarms to be equalized between the two SCADA servers.

[0009] 1 is a block diagram showing a configuration of a SCADA server according to the present embodiment. FIG. 2 is a block diagram for explaining the operation of the SCADA server according to the present embodiment. FIG. 3 is a block diagram showing an example of a functional configuration of the SCADA server according to the present embodiment. FIG. 4 is a table showing attributes of alarm data. FIG. 5 is a diagram for explaining an equalization waiting list. FIG. 6 is a table showing predetermined rules in alarm data selection processing. FIG. 7 is a time chart for explaining the effect of alarm data selection processing. FIG. 8 is a time chart for explaining the effect of alarm data selection processing. FIG. 9 is a block diagram showing an example of a functional configuration related to time synchronization between SCADA servers. FIG. 10 is a table for explaining generation numbers and alarm times. FIG. 11 is a diagram for explaining retention of alarm data when switching connections in a monitoring terminal. FIG. 12 is a diagram for explaining a first condition relating to retention or discarding of alarm data. FIG. 13 is a diagram for explaining a second condition relating to retention or discarding of alarm data. FIG. 14 is a table showing values ​​included in a keep-alive message. FIG. 15 is a diagram for explaining a situation in which the second condition relating to retention or discarding of alarm data is met. FIG. 16 is a diagram for explaining a situation in which the second condition relating to retention or discarding of alarm data is met. 10 is a flowchart showing a determination as to whether to retain or discard alarm data.

[0010] Embodiments of the present disclosure will be described with reference to the accompanying drawings.

[0011] 1 is a diagram showing an example of the configuration of a system 1 according to this embodiment. The system 1 is a system that constitutes a SCADA system, particularly an HMI subsystem of the SCADA system.

[0012] As shown in FIG. 1, system 1 has a redundant configuration in which at least the SCADA server is duplicated. System 1 includes at least a pair of a first SCADA server 10 (hereinafter referred to as SCADA server 10) and a second SCADA server 20 (hereinafter referred to as SCADA server 20). The first SCADA server 10 and the second SCADA server 20 are equal to each other in system 1, and can also be considered peer servers. The first SCADA server 10 and the second SCADA server 20 are connected to a plurality of PLCs (Programmable Logic Controllers) 30-1, 30-2, ... 30-n (n is a natural number), a plurality of monitoring terminals 40-1, ... 40-l, 40-l+1, ... 40-m (l and m are natural numbers, l<m), and a history data server 50 via a network. Hereinafter, the symbols 30-1, 30-2, ... 30-n will be used to indicate a single PLC, but the symbol 30 will be used to refer to any PLC or to refer collectively. Furthermore, the symbols 40-1, ... 40-1, 40-1+1, ... 40-m will be used to indicate a single monitoring terminal, but the symbol 40 will be used to refer to any monitoring terminal or to refer collectively. The PLC 30, the monitoring terminal 40, and the history data server 50 may be included in the system 1.

[0013] The network may be duplicated in the system 1. That is, for example, the network connecting each device may include two networks, a first network and a second network, and the SCADA server 10, the SCADA server 20, the PLC 30, the monitoring terminal 40, and the history data server 50 may be connected to both networks.

[0014] Furthermore, in the system 1, the history data server 50 may be duplicated. That is, the history data server 50 may be configured by two servers.

[0015] The SCADA server 10 includes a processor (processing circuit) 101 and a memory 102 coupled to the processor 101. The processor 101 is typically a CPU. However, the processor 101 may include a GPU in addition to the CPU, or may include other processing units such as an FPGA. There may be multiple processors 101.

[0016] The memory 102 stores a program made up of a plurality of instructions INST that can be executed by the processor 101. The program made up of the instructions INST may be constructed as a web application that runs on a web browser. In this case, the system 1 may be called a web-based HMI subsystem. Alternatively, the program made up of the instructions INST may be acquired using a computer-readable non-transitory storage medium.

[0017] The memory 102 also stores specification information SPEC. The specification information SPEC includes information on predetermined rules used in the alarm data selection process described below. The specification information SPEC may be stored in the memory 102 in advance, or may be acquired via a network. The memory 102 may be built into the processor 101. There may also be multiple memories 102.

[0018] The SCADA server 20 includes a processor (processing circuit) 201 and a memory 202 coupled to the processor 201. The processor 201 is typically a CPU. However, the processor 201 may include a GPU in addition to the CPU, or may include other processing units such as an FPGA. There may be multiple processors 201.

[0019] The memory 202 stores a program that is executable by the processor 201 and is composed of a plurality of instructions INST. The program is composed of the same instructions INST as the program stored in the memory 102 of the SCADA server 10. The program composed of the instructions INST may be constructed as a web application that runs on a web browser. Alternatively, the program composed of the instructions INST may be acquired using a computer-readable non-transitory storage medium.

[0020] The memory 202 also stores specification information SPEC. The specification information SPEC includes information relating to predetermined rules used in the alarm data selection process. At least the information relating to the predetermined rules among the specification information SPEC is common between the specification information SPEC stored in the memory 102 and the specification information SPEC stored in the memory 202. The specification information SPEC may be stored in advance in the memory 202 or may be acquired via a network. The memory 202 may be built into the processor 201. There may also be multiple memories 202.

[0021] The PLC 30 receives signal data from the equipment to be monitored via the control network and transmits the received signal data to the SCADA server 10 and the SCADA server 20. The monitoring terminal 40 is a terminal (client terminal) on which an operator monitors the system and performs necessary operations. The monitoring terminal 40 includes a processor (processing circuit) (not shown) and a memory coupled to the processor. The processor is a processing unit such as a CPU. The memory stores programs executable by the processor. There may be multiple processors and memories. The monitoring terminal 40 also includes a display (not shown) that can display information to the operator.

[0022] The history data server 50 records in a database a log indicating the operating status of the system 1. The logs recorded by the history data server 50 include a log about alarm data, which will be described later.

[0023] The SCADA servers in system 1 are redundantly configured using an active / active system. That is, both SCADA server 10 and SCADA server 20 are operational while system 1 is running. A monitoring terminal 40 is connected to either SCADA server 10 or SCADA server 20, and the connected server is switched depending on the operating status of each SCADA server. The connection between the monitoring terminal 40 and the SCADA server may be controlled so that the number of monitoring terminals 40 connected to both servers is equal, for example, to equalize the load on both servers. In the example of FIG. 1, l monitoring terminals 40-1 to 40-l are connected to SCADA server 10, and m-l monitoring terminals 40-l+1 to 40-m are connected to SCADA server 20. The operation of system 1 will now be described with reference to FIG. 2.

[0024] 2. System Operation In the system 1, the PLC 30 is connected to both SCADA servers and can transmit and receive data to and from both SCADA servers. The PLC 30 transmits signal data collected from the control system network to both SCADA servers 10 and 20. The type of signal data is arbitrary. For example, the signal data from the PLC 30 may be transmitted using UDP multicast packets. Using UDP multicast packets is efficient for transmitting signals to both SCADA servers simultaneously in real time.

[0025] The SCADA servers 10 and 20 receive signal data transmitted periodically (e.g., every 200 ms) from the PLC 30 and analyze the received signal data. The signal data received by the SCADA servers 10 and 20 includes at least a signal related to an alarm indicating that some abnormality has occurred or has been recovered from in the monitored equipment.

[0026] When the SCADA server 10 and the SCADA server 20 receive an alarm-related signal, they generate alarm data based on the signal. The alarm data is generated by adding at least the current time to the alarm-related signal. If the alarm-related signal indicates an alarm occurrence, the added time becomes the alarm occurrence time, and if the signal indicates an alarm recovery, the added time becomes the alarm recovery time. The generated alarm data is transmitted to the client monitoring terminal 40 that requires the alarm data, among the monitoring terminals 40 connected to each SCADA server.

[0027] The SCADA server 10 and the SCADA server 20 may transmit data other than alarm data to the monitoring terminal 40. For example, the SCADA server 10 and the SCADA server 20 may generate product update data required to update the products displayed on the screen of the monitoring terminal 40 and transmit the product update data to the monitoring terminal 40.

[0028] Based on this data transmitted from the SCADA server 10 or 20, a screen showing the operational status of the system is displayed on the display of the monitoring terminal 40. The operator operates the screen of the monitoring terminal 40 as necessary. When the operator performs an operation, operation data indicating the content of the operation is transmitted from the monitoring terminal 40 to the SCADA server to which the monitoring terminal 40 is currently connected. The SCADA server 10 or 20 transmits a control command based on the operation data to the PLC 30 in order to control the equipment to be monitored based on the operation data.

[0029] Furthermore, the SCADA servers 10 and 20 transmit alarm data and operation data to a history data server 50. The history data server 50 records data including the alarm data and operation data as a log indicating the operating status of the system in a history database 60. The history database 60 may be a duplicated database.

[0030] Furthermore, alarm equalization communication is performed between the SCADA server 10 and the SCADA server 20. The alarm equalization communication is communication performed to equalize the alarms acquired by the SCADA server 10 and the alarms acquired by the SCADA server 20. Alarm equalization will be described below.

[0031] 3. Alarm Equalization As described above, the system 1 has a redundant configuration in which the SCADA servers are duplicated using an active / active method, and the connection destination of the monitoring terminal 40 is switched depending on the operating status of the system. Here, it is desirable that the two SCADA servers operate in the same way as if there were a single SCADA server from the perspective of the monitoring terminal 40. More specifically, it is desirable that the display on the monitoring terminal 40 does not change even if the connected server is switched. If the display on the monitoring terminal 40 were to be changed every time the connected server was switched, it would become difficult to operate the SCADA system correctly.

[0032] Consider the alarm occurrence / recovery times as one of the data displayed on the monitoring terminal 40. The alarm occurrence / recovery times are assigned by the SCADA server 10 or 20 when the SCADA server receives a signal from the PLC 30. Because the two SCADA servers operate independently, even if the PLC 30 simultaneously transmits signal data to both SCADA servers, there is a possibility that the assigned times will differ due to a difference in the timing at which the SCADA servers receive the signals or a difference in the time measured internally by the SCADA servers. If the alarm occurrence / recovery times remain different between the two servers, when the monitoring terminal 40 switches the connection between the SCADA servers, the alarm occurrence / recovery times held by the monitoring terminal 40 will differ from the alarm occurrence / recovery times held by the connected SCADA server.

[0033] Therefore, the system 1 performs alarm equalization to unify the alarm occurrence / recovery times between both servers. Fig. 3 is a block diagram showing an example of the functional configuration of the SCADA server 10 and the SCADA server 20 for realizing alarm equalization. The function of the SCADA server 10 is realized by reading an instruction INST from the memory 102 and executing it in the processor 101. The function of the SCADA server 20 is realized by reading an instruction INST from the memory 202 and executing it in the processor 201.

[0034] The SCADA server 10 includes a communication driver 11 and an alarm data management unit 12. The alarm data management unit 12 manages alarm data held by the SCADA server 10. The alarm data management unit 12 includes a local alarm data storage unit 13, a remote alarm data acquisition unit 14, an alarm data selection processing unit 15, and an alarm data transmission unit 16.

[0035] The SCADA server 20 includes a communication driver 21 and an alarm data management unit 22. The alarm data management unit 22 manages alarm data held by the SCADA server 20. The alarm data management unit 22 includes a local alarm data storage unit 23, a remote alarm data acquisition unit 24, an alarm data selection processing unit 25, and an alarm data transmission unit 26.

[0036] The communication driver 11 communicates with the PLC 30 and receives signal data including a signal related to an alarm from the PLC 30. When the communication driver 11 receives the signal data related to an alarm from the PLC 30, it transmits information about the alarm to the alarm data management unit 12.

[0037] The alarm data management unit 12 generates alarm data from the alarm information input from the communication driver 11. The alarm data is generated by adding at least the current time to the alarm information. The current time added by the alarm data management unit 12 is a time counted inside the SCADA server 10, independently of external time. When the alarm data management unit 12 receives alarm information input from the communication driver 11, it adds the current time to generate alarm data. When the alarm data management unit 12 generates alarm data, it stores the generated alarm data in the local alarm data storage unit 13.

[0038] When alarm data is stored in the local alarm data storage unit 13, the local alarm data storage unit 13 transmits the input alarm data to the alarm data selection processing unit 15 and the other party's SCADA server, i.e., the remote alarm data acquisition unit 24 of the SCADA server 20. The alarm data is transmitted to the other party's SCADA server using equalization communication between SCADA servers.

[0039] The communication driver 21 and the alarm data management unit 22 also perform the same processing as the communication driver 11 and the alarm data management unit 12, respectively. The local alarm data storage unit 23 transmits alarm data to the alarm data selection processing unit 25 and the other party's SCADA server, i.e., the remote alarm data acquisition unit 14 of the SCADA server 10.

[0040] The remote alarm data acquiring unit 14 receives and stores alarm data sent from the local alarm data storage unit 23 of the SCADA server 20. Furthermore, whenever the remote alarm data acquiring unit 14 receives alarm data from the local alarm data storage unit 23, it inputs the alarm data to the alarm data selection processing unit 15.

[0041] The alarm data selection processing unit 15 performs alarm data selection processing. When alarm data is input from at least one of the local alarm data storage unit 13 and the remote alarm data acquisition unit 14, the alarm data selection processing selects either the alarm data input from the local alarm data storage unit 13 or the alarm data input from the remote alarm data acquisition unit 14 in accordance with a predetermined data selection rule. Hereinafter, alarm data input from the local alarm data storage unit 13 to the alarm data selection processing unit 15 will be referred to as local alarm data, and alarm data input from the remote alarm data acquisition unit 14 will be referred to as remote alarm data. Note that local alarm data in the SCADA server 10 becomes remote alarm data in the destination SCADA server 20, and remote alarm data becomes local alarm data in the source SCADA server 20.

[0042] The data selection rule is a rule for causing the alarm data selection processing unit 15 and the alarm data selection processing unit 25 to select alarm data to which the same alarm occurrence / recovery times have been assigned. For example, if it is determined that the local alarm data or the remote alarm data with the later alarm occurrence / recovery time is always selected, then in both SCADA servers, the same alarm data will be selected from alarm data to which the SCADA 10 has assigned the current time for an alarm transmitted from the same PLC 30 and alarm data to which the SCADA server 20 has assigned the current time. The data selection rule is stored in memory 102.

[0043] The selected alarm data is input to the alarm data transmission unit 16. The alarm data transmission unit 16 transmits the input alarm data to the necessary monitoring terminals 40 among the monitoring terminals 40 connected to the SCADA server 10, and to the history data server 50.

[0044] Similar processing is also performed in the remote alarm data acquisition unit 24, the alarm data selection processing unit 25, and the alarm data transmission unit 26. By performing the alarm data selection processing, the occurrence / recovery times of the alarm data to be transmitted between the SCADA server 10 and the SCADA server 20 become consistent.

[0045] In this way, according to system 1, the alarm data selection process is performed in accordance with rules set for alarm equalization, so that the alarm occurrence / recovery times of the alarm data after the alarm data selection process can be unified between SCADA server 10 and SCADA server 20. Even if the SCADA server to which monitoring terminal 40 is connected is switched, the alarm occurrence / recovery times displayed before and after the switch can be made the same, and the system 1 can operate in the same way as when there is one SCADA server, as viewed from monitoring terminal 40.

[0046] 4. First Embodiment - Specific Example of Processing for Alarm Equalization 4-1. Attributes of Alarm Data The first embodiment is a specific example of more detailed processing for alarm equalization. First, alarm data generated by the SCADA server 10 or the SCADA server 20 will be described. FIG. 4 shows a table of attributes assigned to the generated alarm data. In the following description of the first embodiment, processing by the SCADA server 10 will be described as a representative of the two SCADA servers, but the same applies to processing by the SCADA server 20. With regard to processing by the SCADA server 20, the SCADA server 10, the SCADA server 20, the functional units of the SCADA server 10, and the functional units of the SCADA server 20 in the following description should be interpreted as those of the other SCADA server.

[0047] The alarm ID is an identifier for uniquely identifying an alarm. For example, a unique integer value assigned to each alarm may be used as the alarm ID.

[0048] The alarm status is a flag indicating the status of the alarm. If the signal related to the alarm indicates that an alarm has occurred, a true flag indicating the alarm occurrence status is set, and if the signal indicates that the alarm has been restored, a false flag indicating the alarm restoration status is set. The alarm status is set by the communication driver 11, reflecting the value of the signal of the PLC 30 corresponding to each alarm.

[0049] The alarm occurrence time is the time when the alarm state changes to the alarm occurrence state. The alarm recovery time is the time when the alarm state changes to the alarm recovery state. Each alarm data is assigned either the alarm occurrence time or the alarm recovery time depending on the alarm state. This time is assigned by the alarm data management unit 12.

[0050] The alarm start time indicates the time when the alarm occurred. When an alarm occurs indicating some kind of abnormality in the equipment being monitored, the alarm start time is assigned. If the alarm is resolved and then occurs again, the alarm start time is updated. The alarm start time is used to control the buzzer reset state managed by each monitoring terminal 40. When an alarm occurs, a buzzer sounds on the monitoring terminal 40, and the operator can stop the buzzer sound by pressing the buzzer reset button. If the monitoring terminal 40 is notified of an alarm with a different alarm start time, it is considered that the abnormality has reoccurred, and the buzzer will start sounding again.

[0051] The PLC connection flag indicates the communication status with the PLC 30 to which the signal corresponding to the alarm belongs. The PLC connection flag is true if the communication driver 11 is in communication with the PLC 30, and false if the communication is disconnected. For example, if signal data from the PLC 30 is transmitted using multicast packets, the communication driver 11 receives multicast packets from the PLC 30 at regular intervals (e.g., every 200 ms). In this case, if the communication driver 11 does not receive multicast packets from the PLC 30 for a certain period of time (e.g., 1000 ms), it determines that communication with the PLC 30 has been disconnected, and changes the PLC connection flag of the alarm data corresponding to the signal sent from the PLC 30 to false.

[0052] 4-2. Processing According to the State of Equalization Communication Furthermore, the alarm data management unit 12 performs the following different processing depending on the state of equalization communication with the other party's SCADA server. If equalization communication is being performed normally, and alarm data is stored in the local alarm data storage unit 13, the alarm data is immediately sent to the other party's SCADA server. If equalization communication is disconnected and alarm data cannot be sent to the other party's SCADA server, the PLC connection flags for all alarm data held by the remote alarm data acquisition unit 14 are changed to false. If the disconnected equalization communication is reconnected, all alarm data held in the local alarm data storage unit 13 is sent to the other party's SCADA server.

[0053] 4-3. Alarm Data Selection Processing The alarm data selection processing unit 15 performs alarm data selection processing when the alarm data stored in the local alarm data storage unit 13 is updated within a certain period of time and the alarm data stored in the remote alarm data acquisition unit 14 is updated, or when either one of the alarm data is updated within a certain period of time. The detailed timing of the alarm data selection processing will be explained below with a specific processing example.

[0054] The equalization waiting list is a list for managing alarms whose local or remote alarm data has been updated and which are waiting for the other to be updated, and is a list whose elements are sets of alarms, as shown in Figure 5. The indexes of this list range from 0 to 5, and an alarm whose local or remote alarm data has been updated is added to the set with index 5. If the other alarm is also updated, the added alarm is deleted from this list and alarm data selection processing is performed. At predetermined intervals (here, 200 ms), the set with index n is moved to the set with index n-1, and the set with index 0 (here, the set of alarms for which 1000 ms have passed) is considered to have timed out and is processed using one of the received data.

[0055] When alarm data stored in the local alarm data storage unit 13 is updated, the alarm data selection processing unit 15 checks whether the alarm data stored in the remote alarm data acquisition unit 14 has already been updated. If it has already been updated, the alarm data selection processing unit 15 immediately performs alarm data selection processing. If this alarm is registered in the equalization standby list, it is deleted from the equalization standby list. If the alarm data stored in the remote alarm data acquisition unit 14 has not been updated, the alarm data selection processing unit 15 checks whether the PLC connection flag of the alarm data stored in the remote alarm data acquisition unit 14 is false. If it is false, it is unlikely that the alarm data stored in the remote alarm data acquisition unit 14 will be updated in the near future, so alarm data selection processing is immediately performed. If it is registered in the equalization standby list, it is deleted from the equalization standby list. If it is true, it is likely that the alarm data stored in the remote alarm data acquisition unit 14 will also be updated in the near future, so it adds this alarm to the fifth set in the equalization standby list.

[0056] When alarm data stored in the remote alarm data acquisition unit 14 is updated, the alarm data selection processing unit 15 checks whether the alarm data stored in the local alarm data storage unit 13 has already been updated. If it has already been updated, the alarm data selection processing unit 15 immediately performs alarm data selection processing. If this alarm is registered in the equalization standby list, it is deleted from the equalization standby list. If the alarm data stored in the local alarm data storage unit 13 has not been updated, the alarm data selection processing unit 15 checks whether the PLC connection flag of the alarm data stored in the local alarm data storage unit 13 is false. If it is false, it is unlikely that the alarm data stored in the local alarm data storage unit 13 will be updated in the near future, so alarm data selection processing is immediately performed. If it is registered in the equalization standby list, it is deleted from the equalization standby list. If it is true, it is likely that the alarm data stored in the local alarm data storage unit 13 will also be updated in the near future, so it adds this alarm to the fifth set in the equalization standby list.

[0057] When the PLC connection flag of the alarm data stored in the local alarm data storage unit 13 changes to false, if the alarm data stored in the remote alarm data acquisition unit 14 has been updated, the alarm data selection process is immediately performed. If this alarm is registered in the equalization standby list, it is deleted from the equalization standby list.

[0058] Furthermore, when the PLC connection flag of the alarm data stored in the remote alarm data acquisition unit 14 changes to false, if the alarm data stored in the local alarm data storage unit 13 has been updated, the alarm data selection process is immediately performed. If this alarm is registered in the equalization standby list, it is deleted from the equalization standby list.

[0059] Next, an example of a predetermined rule when the alarm data selection processing unit 15 selects alarm data will be described. Fig. 6 shows an example of the predetermined rule for the alarm data selection process in the form of a table. The left side of the table shows the conditions when comparing local alarm data with remote alarm data, and the right side shows the alarm data selected under each condition.

[0060] If the PLC connection flags of the local alarm data and the remote alarm are different, the alarm data whose PLC connection flag is true is selected.

[0061] If the PLC connection flags for both the local alarm data and the remote alarm data are true, the alarm data selected will differ depending on the alarm state. If both alarm states are the same, the alarm data with the earlier alarm occurrence time or alarm recovery time, i.e., the older alarm data, will be selected. If both alarm states are different, the alarm data with the later alarm occurrence time or alarm recovery time, i.e., the newer alarm data, will be selected.

[0062] If the PLC connection flags for both the local alarm data and the remote alarm data are false, the alarm data selection process is not performed.

[0063] 4-4. Effect By performing the alarm data selection process according to the above rules, it is possible to equalize the alarm occurrence / recovery times of the alarm data after the alarm data selection process between SCADA server 10 and SCADA server 20. In this way, it is possible to realize the same operation of system 1 as when there is one SCADA server, as viewed from monitoring terminal 40.

[0064] The alarm data selected according to the rules of FIG. 6 will be explained below for each condition using a time chart.

[0065] FIG. 7 is a time chart showing the alarm data selection process when the PLC connection flags of both alarm data are true and the alarm states are the same. Alarm A occurs at 10:05:00, and signal data indicating the occurrence of alarm A is sent from the PLC 30 to the SCADA servers 10 and 20. There is a slight difference between the alarm occurrence times assigned by the two SCADA servers, and the alarm occurrence time assigned by the SCADA server 20 is slightly earlier. As a result of the alarm data with the earlier alarm occurrence time being selected by the alarm data selection process, the remote alarm data is selected by the SCADA server 10, and the local alarm data is selected by the SCADA server 20. The alarm occurrence times of the alarm data after the selection process are consistent between the two servers. Furthermore, the alarm occurrence time of the selected alarm data is closer to the actual occurrence time of alarm A than the alarm data that was not selected. In this way, alarm data with an alarm occurrence time closer to the actual occurrence time can be selected.

[0066] 8 is a time chart showing the selection process for alarm data when the PLC connection flags of both alarm data are true but the alarm states are different. Alarm A occurs at 10:05:00 and recovers at 10:06:00. The SCADA server 20 assigns the alarm recovery time of 10:06:00.001, but a communication delay occurs, and the SCADA server 10 receives the signal data and assigns the alarm recovery time at 10:06:02.001. Because the alarm states differ between the two servers between 10:06:00.001 and 10:06:02.001, the alarm data with the later alarm occurrence / recovery time is selected. Specifically, the alarm occurrence time 10:05:00.002 assigned by SCADA server 10 is compared with the alarm recovery time 10:06:00.001 assigned by SCADA server 20, and the alarm data with the later time is selected in both SCADA servers. In this way, the alarm data can be equalized between both servers. Furthermore, if the alarm status differs between the two servers due to a communication delay or the like, the new alarm data after the alarm status has been updated can be selected instead of the old alarm data before the alarm status was updated.

[0067] 9 is a time chart showing the alarm data selection process when the PLC connection flags of both alarm data are different. When alarm A occurs a second time due to the SCADA server 10 being disconnected and the alarm occurrence time is assigned by the SCADA server 20, the PLC connection flag assigned to the alarm data by the SCADA server 10 is false. Therefore, the alarm data assigned the alarm occurrence time by the SCADA server 20 and whose PLC connection flag is true is selected. The selected alarm data is equalized between the two servers. Furthermore, more reliable alarm data can be selected instead of alarm data whose PLC connection flag is false, which is considered to be less reliable.

[0068] 5. Second Embodiment The second embodiment relates to time synchronization between two SCADA servers. The second embodiment can be combined with the first embodiment.

[0069] The alarm occurrence / recovery times independently assigned by each of the two SCADA servers are equalized between the two SCADA servers by the alarm data selection process described above. However, it is desirable to minimize the error in the alarm occurrence / recovery times from the point before the alarm data selection process is performed, and to achieve this, it is desirable to minimize the difference in the PC time counted internally by the two servers. Therefore, in the second embodiment, time correction values ​​are calculated by periodically sending time correction packets back and forth between the two SCADA servers.

[0070] First, assume that a time correction packet is sent from the SCADA server 20 to the SCADA server 10. The SCADA server 10 returns a time correction packet with the PC time of the SCADA server 10 attached to it to the SCADA server 20. If time correction is performed based on such a time correction packet, the time correction value can be expressed by the following equation. The transmission time or reception time of the time correction packet in equation (1) represents the transmission or reception time at the second SCADA server 20.

[0071] A = (time correction packet transmission time) + ((time correction packet reception time) - (time correction packet transmission time)) / 2 ... formula (1) Time correction value = A - (time correction packet transmission time from the first SCADA server)) ... formula (2)

[0072] However, if a time difference occurs between two SCADA servers, that is, if the PC time of one of the SCADA servers is changed every time the time correction value becomes greater than 0, this may affect the operation of the entire SCADA server. Therefore, in the second embodiment, the SCADA server 20 manages the time of the SCADA server 10 as its internal time and assigns alarm occurrence / recovery times based on this time. FIG. 10 is a diagram showing an example of the functional configuration of such a SCADA server 10 and SCADA server 20. The functions of the SCADA server 10 shown in FIG. 10 are realized by reading an instruction INST from the memory 102 and executing it in the processor 101. The functions of the SCADA server 20 are realized by reading an instruction INST from the memory 202 and executing it in the processor 201.

[0073] The time management unit 17 manages the PC time of the SCADA server 10. When the time management unit 17 receives a time correction packet from the SCADA server 20, it adds the PC time of the SCADA server 10 to the received time correction packet and sends it back.

[0074] The time management unit 27 manages the PC time of the SCADA server 20. The time management unit 27 transmits and receives time correction packets to and from the SCADA server 10. When the time correction packet is received, the time managed by the internal time management unit 28 is updated based on the time correction value calculated from the time correction packet. Furthermore, if the difference between the PC time of the SCADA server 20 and the PC time of the SCADA server 10, that is, the time correction value calculated from the time correction packet, is equal to or greater than a threshold value, the time management unit 27 corrects the PC time of the SCADA server 20 to match the PC time of the SCADA server 10. Note that the time management unit 27 corrects the time of the internal time management unit 28 every time a time correction packet is received, but does not correct the PC time if the time correction value is less than the threshold value.

[0075] The internal time management unit 28 manages the PC time of the SCADA server 10 as the internal time. The internal time held by the internal time management unit 28 is managed separately from the PC time of the SCADA server 20, and therefore does not affect the overall operation of the SCADA server 20.

[0076] The alarm data management unit 12 acquires the time from the internal time management unit 28. Then, based on the time acquired from the internal time management unit 28, it assigns an alarm occurrence time / alarm recovery time to the alarm acquired from the PLC 30. The time managed by the internal time management unit 28 is updated each time a time correction packet is sent or received, so the difference between the time managed by the internal time management unit 28 and the time assigned to the alarm by the SCADA server 10 can be kept small. In this way, it is possible to reduce the impact on the operation of the entire server caused by updating the PC time, while also reducing the error in the times assigned by the two SCADA servers.

[0077] 6. Third Embodiment 6-1. Generation Number and Alarm Time The third embodiment is an embodiment related to the retention of alarm data in the monitoring terminal 40 when the connected SCADA server is switched. The third embodiment can be combined with the first and second embodiments.

[0078] In the third embodiment, the concepts of alarm time and generation number are introduced. These concepts will be explained first with reference to Fig. 11. The table in the upper left of Fig. 11 is a table showing an example of an alarm list displayed on the monitoring terminal 40. The alarm list lists alarm occurrence / recovery times, alarm IDs, and alarm states, among the attributes of alarm data.

[0079] The time assigned to alarm data by the SCADA server 10 and the SCADA server 20 is a time counted internally by each server independently of external time. Therefore, time correction is required periodically or when an error becomes large. Time correction may be performed, for example, using the time correction packet described in the second embodiment.

[0080] However, time correction may cause the times assigned to alarm data before and after the correction to appear to be swapped. In the table in Figure 11, the alarm data is arranged from bottom to top in the order in which it was generated. However, time correction was performed between ALM3 and ALM4, so the apparent times between ALM1-3 and ALM4-6 have been swapped.

[0081] In this way, when the PC time of the SCADA server is corrected, it may become impossible to sort the alarm occurrence / recovery times in the order in which they actually occurred before and after the correction. This makes the display logic of the alarm list on the monitoring terminal 40 complicated. To prevent this, the alarm occurrence / recovery times are represented by the alarm time. The alarm time is, for example, a 64-bit value defined by the table at the bottom of FIG. 11. A counter called a generation number is provided within the alarm time, and the generation number is incremented each time a time correction is performed, with an initial value of 1.

[0082] By introducing generation numbers, alarm times become numerical values ​​that are consistent with the order in which they actually occurred, making it easy to display alarms in chronological order without having to consider the timing of time correction, and facilitating the management of alarm data on the monitoring terminal 40.

[0083] 6-2. Switching of Connection Destination Server When the connection between the monitoring terminal 40 and the SCADA server to which the monitoring terminal 40 is connected is severed, the monitoring terminal 40 needs to switch the connection to the other SCADA server. A method for determining whether to switch will be described below.

[0084] The monitoring terminal 40 and the SCADA server are connected via a predetermined communication protocol. If communication between the monitoring terminal 40 and the SCADA server is interrupted, depending on the circumstances of the interruption, the monitoring terminal 40 may not be able to detect the interruption in real time. To prevent this from happening, keep-alive messages are sent and received between the monitoring terminal 40 and the SCADA server at regular intervals (e.g., every 3 seconds). If the monitoring terminal 40 does not receive a keep-alive message for a certain period of time (e.g., 10 seconds), it detects that communication with the SCADA server has been interrupted.

[0085] The keep-alive message may include information about, for example, the status of the SCADA server, the current time in the SCADA server, and the last time alarm data selection processing was performed between two SCADA servers. This information included in the keep-alive message is used to determine whether to retain alarm data when the connected server is switched in the monitoring terminal 40. Hereinafter, the last time alarm data selection processing was performed between two SCADA servers is referred to as the last alarm equalization time. Note that keep-alive messages may be sent and received not only with connected SCADA servers, but also with unconnected SCADA servers.

[0086] 6-3. Alarm Data Retention The following describes how alarm data is retained in the monitoring terminal 40 when the destination server is switched as described above. This applies not only when communication is disconnected, but also when the destination server is switched depending on the operating status of the SCADA server.

[0087] From the viewpoint of preventing an increase in communication traffic, it is desirable for the monitoring terminal 40 to continue to retain the alarm data currently held by the monitoring terminal 40 when the connection destination server is switched. This is because if all alarm data were to be retransmitted from the switched-to SCADA server to the monitoring terminal 40, the increased communication traffic could potentially cause system processing to stall. However, if the alarm data held by the two SCADA servers is different, continuing to hold the alarm data in the monitoring terminal 40 could result in the alarm data held by the monitoring terminal 40 differing from the alarm data held by the newly connected SCADA server, potentially resulting in data inconsistencies. Therefore, when the monitoring terminal 40 switches the connection destination SCADA server, it determines according to a predetermined logic whether to continue to hold or discard the alarm data.

[0088] First, referring to FIG. 12 , the alarm data held by the SCADA servers 10 and 20 and the monitoring terminal 40 will be described. Each alarm data held by the two SCADA servers is associated with an alarm state and an alarm confirmation status indicating whether the alarm has been confirmed at the respective monitoring terminal 40. The alarm state is set based on a signal from the PLC 30 and indicates whether an alarm has occurred or has been cleared. The alarm confirmation operation is performed individually at each monitoring terminal 40. When a confirmation operation is performed at the monitoring terminal 40, a signal indicating the confirmation operation is sent from the monitoring terminal 40 to the SCADA server 10 or 20, and the alarm confirmation status of the alarm data held by the SCADA server 10 or 20 is switched from unconfirmed to confirmed. If equalization communication is normally performed, the alarm confirmation status of the other server is also changed in the same way.

[0089] The monitoring terminal 40 stores alarm data that is linked to the alarm status and whether or not the alarm has been confirmed on the terminal itself. The monitoring terminal 40 displays, for each alarm data, whether the alarm has occurred or has been restored, and whether or not the alarm has already been confirmed.

[0090] In the scene shown in Figure 12, the monitoring terminal 40-a is connected to the SCADA server 10, the monitoring terminal 40-b is connected to the SCADA server 10, and the monitoring terminal 40-c is connected to the SCADA server 20. Also, in Figure 12, equalization communication is normally in progress. Therefore, the alarm data and its attributes held by the SCADA servers are consistent between the two servers.

[0091] Now, let us assume that the connection destination of the monitoring terminal 40-b has switched from SCADA server 10 to SCADA server 20. Because equalization communication between the two servers is proceeding normally, the alarm data held by the monitoring terminal 40-b matches the alarm data held by the new connection destination, SCADA server 20. In such a situation, if the monitoring terminal 40-b continues to hold the alarm data, it is possible to omit the transmission of the data indicated by the dashed arrow, thereby reducing the amount of communication traffic.

[0092] Whether the alarm data stored in the monitoring terminal 40 is retained or discarded when switching servers is determined based on two conditions. The first condition is that the last alarm equalization time must be after the alarm occurrence / recovery time of the alarm data last acquired by the monitoring terminal 40. When equalization communication between two SCADA servers is disconnected, it is not guaranteed that the alarms stored in both servers are the same. Therefore, if the monitoring terminal 40 receives alarm data from a SCADA server after the last alarm equalization time, that is, after the time when equalization between the two servers is no longer performed, it is not guaranteed that the SCADA server that is not currently connected retains the same alarm data as the monitoring terminal 40. Therefore, in such a case, it is determined that the first condition is not met, and the alarm data stored in the monitoring terminal 40 is discarded when the monitoring terminal 40 switches the SCADA server to which it is connected. On the other hand, if the first condition is met, it can be said that all of the alarm data stored in the monitoring terminal 40 was transmitted from the SCADA server while equalization communication between the two servers was being performed. Therefore, in this case, the alarm data is not immediately discarded, and the second condition is checked.

[0093] 13, (a) shows a case where the first condition is satisfied, and (b) shows a case where the first condition is not satisfied. In (a), the final alarm equalization time is after the alarm occurrence / recovery time of ALM5, so it is determined that the first condition is satisfied. In this case, a determination is further made regarding the second condition, and if the second condition is also satisfied, the alarm data held by the monitoring terminal 40 is retained as is. On the other hand, in (b), the alarm occurrence / recovery time of ALM5 is after the final alarm equalization time, so the first condition is not satisfied. In this case, the alarm data held by the monitoring terminal 40 is discarded when the server connection is switched.

[0094] Next, the second condition will be described with reference to FIG. 14 . To determine whether the second condition is met, the concept of an equalization interval ID is introduced. If the first condition is met, it is guaranteed that both SCADA servers have held the alarm data held by the monitoring terminal 40 at least until the final alarm equalization time. However, the first condition alone does not guarantee that the SCADA server at the switching destination still holds the alarm data. This is because the SCADA server may have been restarted after the final alarm equalization time, and in this case, the alarm data held by the restarted SCADA server will be cleared. Therefore, the equalization interval ID is introduced to make it possible to confirm whether the SCADA server at the switching destination still holds the same alarm data as the monitoring terminal 40.

[0095] If the equalization communication between the two servers is interrupted for some reason, the equalization communication is reconnected, and the connection and disconnection of the equalization communication are repeated. An equalization section ID is assigned to each equalization section in order to uniquely identify the section in which the two SCADA servers are equalizing, i.e., each section from the connection to the disconnection of the equalization communication. The assigned ID may be, for example, a combination of the time on the SCADA server 10 when the equalization communication between the servers is started and a hash value, as shown in the table of FIG. 14. In this way, a unique ID that can be shared between the two SCADA servers can be assigned to the same equalization section.

[0096] The two SCADA servers maintain a list of equalization interval IDs while they are operating. This list is called the equalization interval ID list. When either SCADA server is restarted, the equalization interval ID list maintained by that SCADA server is cleared. Furthermore, when equalization communication begins, information about alarm data maintained by each SCADA server is exchanged and shared between the two servers, and the equalization interval ID list is also exchanged and shared between the two servers.

[0097] When the connection is switched, the monitoring terminal 40 sends the equalization section ID used when the last equalization was performed to the newly connected SCADA server. The second condition is that the equalization section ID sent from the monitoring terminal 40 to the newly connected SCADA server is included in the equalization section ID list currently held by that SCADA server. If the second condition is met, it is determined that the monitoring terminal 40 can continue to hold the alarm data.

[0098] A keep-alive message is used to determine whether the first and second conditions are met. Specifically, the keep-alive message sent from the SCADA server to the monitoring terminal 40 at predetermined intervals (e.g., every 3 seconds) contains the last alarm equalization time and the equalization interval ID. Specific examples of these values ​​are shown in the table in FIG. 15.

[0099] When connecting to a new SCADA server after switching server connections, the monitoring terminal 40 compares the final alarm equalization time included in the last received keep-alive message with the latest alarm occurrence / recovery time of the alarm data held by the monitoring terminal 40. If the final alarm equalization time is after the latest alarm occurrence / recovery time, the first condition is met, and there is a possibility that the alarm data can continue to be held. Therefore, the monitoring terminal 40 sends the final alarm occurrence / recovery time it holds and the equalization interval ID included in the last received keep-alive message to the newly connected SCADA server.

[0100] The processing on the SCADA server side at this time will be explained using FIGS.

[0101] 16 and 17 show an example of a situation in which the second condition is satisfied. A monitoring terminal 40 connected to the SCADA server 10 is temporarily disconnected from both servers, and then the connection is switched to the SCADA server 20. At this time, an equalization interval ID is transmitted from the monitoring terminal 40 to the newly connected SCADA server 20. The equalization interval ID transmitted from the monitoring terminal 40 indicates equalization interval A, and the equalization interval ID list held by the SCADA server 20 includes equalization interval A. Therefore, the alarm data held by the monitoring terminal 40 is determined to be valid. Therefore, the SCADA server 20 accepts the alarm data held by the monitoring terminal 40 and transmits to the monitoring terminal 40 only the alarm data received from the monitoring terminal 40 after the last alarm occurrence / recovery time. Note that the reason alarm data is transmitted to the monitoring terminal 40 in this case is because a new alarm may have occurred while the monitoring terminal 40 was switching the connected server.

[0102] 18 shows an example of a situation in which the second condition is not satisfied and the monitoring terminal 40 cannot continue to hold the alarm data. The monitoring terminal 40, which had been connected to the SCADA server 10, is disconnected from the SCADA server 10 and switches its connection to the SCADA server 20. Because the SCADA server 20 has restarted by the time the monitoring terminal 40 connects to the SCADA server 20, the equalization section ID list is cleared when the monitoring terminal 40 connects. Upon connection, the monitoring terminal 40 sends an equalization section ID indicating equalization section A to the SCADA server 20, but the equalization section A is not included in the equalization section ID list of the SCADA server 20. Therefore, the SCADA server 20 determines that the alarm data held by the monitoring terminal 40 is invalid. The alarm data held by the monitoring terminal 40 is discarded, and all alarm data currently held by the SCADA server 20 is sent to the monitoring terminal 40.

[0103] FIG. 19 is a flowchart showing the flow of determining whether monitoring terminal 40 can continue to hold alarm data when the destination server is switched.

[0104] When switching of the destination server is started, first, in step S101, the last alarm occurrence / recovery time of the alarm data held in the monitoring terminal 40 is compared with the last alarm equalization time.

[0105] Step S102 is executed if the final alarm equalization time is after the final alarm occurrence / recovery time in the alarm data held by the monitoring terminal 40. In step S102, the final alarm occurrence / recovery time in the alarm data held by the monitoring terminal 40 and the equalization interval ID are sent from the monitoring terminal 40 to the newly connected SCADA server.

[0106] After the final alarm occurrence / recovery times and the equalization interval ID have been sent, a determination is made in step S103. In step S103, the newly connected SCADA server determines whether the equalization interval ID sent from the monitoring terminal 40 is included in the equalization interval ID list held by the SCADA server.

[0107] If the equalization interval ID sent from the monitoring terminal 40 is included in the equalization interval ID list held by the SCADA server, it is possible to continue to hold the alarm data held by the monitoring terminal 40. In this case, step S104 is executed. In step S104, of the alarm data held by the SCADA server, only the alarm data held by the monitoring terminal 40 after the latest alarm occurrence / recovery time is transmitted to the monitoring terminal 40.

[0108] If it is determined in step S101 that the final alarm equalization time is earlier than the final alarm occurrence / recovery time in the alarm data held by the monitoring terminal 40, or if it is determined in step S103 that the equalization section ID sent from the monitoring terminal 40 is not included in the equalization section ID list held by the SCADA server, step S105 is executed. In this case, the alarm data held by the monitoring terminal 40 cannot be continued to be held, and all alarm data in the monitoring terminal 40 is discarded. Then, all alarm data held by the SCADA server is sent from the server to the monitoring terminal 40.

[0109] 1 System, 10 First SCADA server, 11 Communication driver, 12 Alarm data management unit, 13 Local alarm data storage unit, 14 Remote alarm data acquisition unit, 15 Alarm data selection processing unit, 16 Alarm data transmission unit, 17 Time management unit, 20 Server, 21 Communication driver, 22 Alarm data management unit, 23 Local alarm data storage unit, 24 Remote alarm data acquisition unit, 25 Alarm data selection processing unit, 26 Alarm data transmission unit, 27 Time management unit, 28 Internal time management unit, 40 Monitoring terminal, 50 History data server, 60 History database, 101 Processor, 102 Memory, 201 Processor, 202 Memory, INST Instruction, SPEC Specifications information

Claims

1. A SCADA system comprising a pair of first and second SCADA servers configured to be able to receive alarm-related signals from a programmable logic controller, wherein each of the first and second SCADA servers includes processing circuitry configured to execute: an alarm data generation process for generating alarm data with at least the current time added to the alarm-related signal when the alarm-related signal is received from the programmable logic controller; an alarm data reception process for receiving alarm data from the other SCADA server; and an alarm data selection process for selecting, in accordance with a predetermined rule, either local alarm data generated by the alarm data generation process or remote alarm data received by the alarm data reception process when at least one of the alarm data generation process and the alarm data reception process is performed.

2. A SCADA system according to claim 1, wherein the alarm data generation process includes assigning to the alarm-related signal a PLC connection flag indicating the connection status between its own SCADA server and the programmable logic controller, and assigning an alarm status indicating the status of the alarm, wherein the PLC connection flag is set to true when the connection status is a status in which communication with the programmable logic controller is in progress, and set to false when the connection status is a status in which communication with the programmable logic controller is disconnected, and the alarm status is either a flag indicating the occurrence of the alarm or a flag indicating the recovery of the alarm, and wherein the predetermined rule is: when the PLC connection flags of the local alarm data and the remote alarm data are different, select the alarm data whose PLC connection flag is true; when the PLC connection flags of the local alarm data and the remote alarm data are both true and the alarm statuses of the local alarm data and the remote alarm data are the same, select the alarm data assigned at an earlier time; a SCADA system configured to select alarm data having a later assigned time when the PLC connection flags of the local alarm data and the remote alarm data are both true and the alarm states of the local alarm data and the remote alarm data are different, and to select neither alarm data when the PLC connection flags of the local alarm data and the remote alarm data are both false.

3. A SCADA system according to claim 1 or 2, wherein the first SCADA server includes a processing circuit configured to return a time correction packet to which the current time has been assigned in response to transmission of a time correction packet from the second SCADA server, and the second SCADA server includes a processing circuit configured to perform the following: transmit the time correction packet to the first SCADA server; calculate an internal time measured by the first SCADA server based on the time correction packet returned from the first SCADA server; and assign the internal time as the current time to a signal related to the alarm in the alarm data generation process based on the calculated internal time.

4. A SCADA system according to claim 1 or 2, further comprising a monitoring terminal configured to be able to receive the alarm data from the first SCADA server and the second SCADA server, wherein the processing circuit further executes the following: assigning an equalization interval ID to each period from when communication between the first SCADA server and the second SCADA server is connected to when it is disconnected; sending the equalization interval ID to the monitoring terminal; and holding an equalization interval ID list in which the equalization interval IDs are listed, wherein the monitoring terminal performs a connection switch to switch the connection destination from either the first SCADA server or the second SCADA server to the other SCADA server; and periodically receives from the first SCADA server or the second SCADA server a message including information about the time when the alarm data selection process was performed, and when the connection switch is performed, a discarding of the alarm data held by the monitoring terminal when the alarm data held by the monitoring terminal includes alarm data assigned a time later than the time when the alarm data selection process was last performed, or when a final equalization interval ID among the equalization interval IDs held by the monitoring terminal is not included in an equalization interval ID list held by the other SCADA server; and continuing to hold the alarm data held by the monitoring terminal when the alarm data held by the monitoring terminal does not include alarm data assigned a time later than the time when the alarm data selection process was last performed, and the final equalization interval ID among the equalization interval IDs held by the monitoring terminal is included in an equalization interval ID list held by the other SCADA server.

Citation Information

Patent Citations

  • Alarm history management system in transmitter monitor control system

    JP1998304021A