DCS controller trusted measurement consistency method and system, electronic device, and storage medium

By pushing the status to the host computer background program and the lower-level I/O card in real time through the DCS controller, untrusted status can be detected and cut off in real time, which solves the problem of weak security of DCS controller and realizes the trust enhancement and network security protection of DCS system.

WO2026157095A1PCT designated stage Publication Date: 2026-07-30XIAN THERMAL POWER RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
XIAN THERMAL POWER RES INST CO LTD
Filing Date
2025-05-30
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

DCS controllers in thermal power plants have weak security, are difficult to update in real time, and traditional anti-virus methods are insufficient to ensure the long-term safe operation of the system.

Method used

The DCS controller pushes its own status to the DCS host computer background program and the lower-level I/O card in real time, so as to detect and cut off untrusted status in real time, realize master-slave switching and alarm, and restore data interaction after restoring the trusted status.

Benefits of technology

Effectively prevents unauthorized tampering, ensures the trusted status of DCS controllers, promptly removes untrusted controllers, prevents the scope of impact from expanding, and safeguards network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025098318_30072026_PF_FP_ABST
    Figure CN2025098318_30072026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of thermal power plant intelligent control, and specifically relates to a DCS controller trusted measurement consistency method and system, an electronic device, and a storage medium. The method comprises: a DCS controller pushing a state thereof to a DCS host computer background process and a DCS field station I / O card in real time; the DCS host computer background process and the DCS field station I / O card sensing the state of the DCS controller in real time; when the state of the DCS controller changes from a trusted state to an untrusted state, interrupting communication between the DCS controller and other nodes within the DCS by means of the DCS host computer background process and issuing an alert to a user, and at the same time, the DCS field station I / O card cutting off a path of a control signal and stopping data interaction with the DCS controller; after the DCS controller transitions from the untrusted state back to the trusted state, the DCS host computer background process restores the trusted state of the DCS controller, and the DCS host computer background process and the DCS field station I / O card resume all data interaction with the DCS controller. The present application improves accuracy of real-time verification and sensing of DCS controller trusted states.
Need to check novelty before this filing date? Find Prior Art

Description

A method and system for trust measurement consistency of DCS controller, electronic device, and storage medium.

[0001] Cross-references to related applications

[0002] This application claims priority to Chinese Patent Application No. 202510110026.X, filed on January 23, 2025, entitled "A Method and System for Reliability Measurement of DCS Controllers", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of intelligent control technology for thermal power plants, and in particular to a DCS controller reliability measurement consistency method and system, electronic equipment, and storage medium. Background Technology

[0004] With the increasing demand for energy, the scale of thermal power plant units is also gradually expanding. Among these expansions, the role of control system automation in thermal power plants is becoming increasingly important. Control system automation improves the efficiency of electricity production and effectively controls costs. Simultaneously, the role of control system automation in maintaining the safety and stability of thermal power plant operations is also very significant. Currently, DCS (Distributed Control System) controllers are the most commonly used automated control systems in thermal power plants. This system mainly consists of multiple computers controlling multiple control loops in the production process, providing centralized data acquisition, management, and control. Utilizing advanced communication technologies, it achieves accurate and reliable information exchange and real-time sharing, providing scientific guidance for the operation of coal-fired units.

[0005] Most DCS systems prioritize real-time performance, resulting in significant limitations in basic functionality and a lack of security considerations during design. This leads to weak security protection during actual operation. Furthermore, the demands of continuous production make real-time system and software updates difficult, and traditional patching-based antivirus and detection methods are insufficient to guarantee long-term system security. As a critical device in the core layer of DCS, the DCS controller is a key research area for DCS trust enhancement. Therefore, ensuring real-time updates and reliable status awareness of the DCS controller is a pressing issue that needs to be addressed. Summary of the Invention

[0006] This application provides a DCS controller trusted measurement consistency method and system, electronic device, and storage medium to solve existing problems.

[0007] The objective of this application can be achieved through the following technical solutions:

[0008] The first aspect of this application is to provide a method for consistency measurement of trusted DCS controllers, including:

[0009] The DCS controller pushes its own status to the DCS host computer background program in real time, and the DCS controller also pushes its own status to the DCS slave computer IO card in real time.

[0010] The DCS host computer background program senses the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, it first determines whether the DCS controller needs to perform a master-slave switch based on the status of the DCS controller. Then, the DCS host computer background program interrupts the communication between the DCS controller and other nodes in the DCS and sends an alarm to the user.

[0011] The DCS lower-level I / O card senses the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS lower-level I / O card cuts off the path of the control signal and stops interacting with the DCS controller with other data except for trusted status notification.

[0012] When the DCS controller recovers from an untrusted state to a trusted state, the DCS host computer background program restores the DCS controller to a trusted state, and the DCS host computer background program and DCS slave I / O cards resume all data interaction with the DCS controller.

[0013] Optionally, the DCS controller pushes its own status to the DCS host computer background program in real time, including:

[0014] The DCS controller uses Ethernet packets to push its status to the DCS host computer background program in real time.

[0015] Optionally, the DCS controller pushes its own status to the DCS lower-level I / O card in real time, including:

[0016] The DCS controller uses a proprietary bus protocol, a general bus protocol, or Ethernet message communication to push its status to the DCS lower-level I / O card in real time.

[0017] Optionally, the specific process by which the DCS controller pushes its own status to the DCS host computer background program in real time is as follows:

[0018] The DCS controller obtains the trusted state of the DCS controller in each scan cycle from its own trusted components; and determines the trusted state of the DCS controller in the current scan cycle.

[0019] If the DCS controller is in a trusted state in the current scan cycle, then check whether the DCS controller was trusted in the previous scan cycle. If it was trusted in the previous scan cycle, then push the trusted state message to the DCS host computer background program. After completion, continue to obtain the state of the DCS controller in the next scan cycle. If it was untrusted in the previous scan cycle, then restore the DCS controller to a trusted state, generate a fault recovery alarm message and push it to the DCS host computer background program through a trusted state message. After completion, continue to obtain the state of the DCS controller in the next scan cycle.

[0020] If the DCS controller is in an untrusted state in the current scan cycle, the system checks whether the DCS controller was trusted in the previous scan cycle. If it was trusted in the previous scan cycle, the system detects a trusted state failure in the DCS controller, generates a fault alarm, and sends it to the DCS host computer background program via a trusted state message. After completion, the system continues to obtain the trusted state of the DCS controller for the next scan cycle. If the DCS controller was in an untrusted state in the previous scan cycle, the system sends a master / slave switchover message to the DCS controller and cuts off the interaction of service data messages with the DCS controller.

[0021] Optionally, the specific process by which the DCS controller pushes its own status to the DCS lower-level I / O card in real time is as follows:

[0022] The DCS controller obtains the trusted state of the DCS controller in the current scan cycle from its own trusted components.

[0023] If the trusted status of the DCS controller is normal in the current scanning cycle, the DCS controller and the DCS lower-level I / O card will interact normally and push the trusted status message to the DCS lower-level I / O card. After completion, the trusted status of the DCS controller in the next scanning cycle will be obtained.

[0024] If the trusted status of the DCS controller is abnormal in the current scan cycle, the DCS controller will stop all data interaction with the DCS lower-level I / O card except for trusted status notification, and will push trusted status messages to the DCS lower-level I / O card. After completion, it will continue to obtain the trusted status of the DCS controller in the next scan cycle.

[0025] Optionally, determining whether the DCS controller needs to perform a master / slave switch based on the status of the DCS controller includes:

[0026] The DCS host computer background program determines the master / standby status of the DCS controller.

[0027] If the DCS controller in an untrusted state is the master controller, the DCS host computer background program sends a master-slave switchover message to notify the DCS controller to perform a master-slave switchover.

[0028] If the DCS controller in an untrusted state is a backup controller, the DCS host computer background program will change the trusted state of the DCS controller to an untrusted state, and no switching is required; the next step can be directly performed.

[0029] Optionally, the DCS lower-level I / O card resumes all data interaction with the DCS controller, including:

[0030] The data from the DCS lower-level I / O card is transmitted back to the DCS controller or the output signals from the I / O board issued by the DCS controller are received.

[0031] A second aspect of this application is to provide a DCS controller trusted measurement consistency system, comprising:

[0032] The trusted status real-time push module is used for the DCS controller to push its own status to the DCS host computer background program and the DCS slave computer IO card in real time.

[0033] The DCS host computer background program real-time sensing module is used to sense the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS host computer background program interrupts the communication between the DCS controller and other nodes in the DCS and issues an alarm to the user.

[0034] The DCS lower-level machine IO card real-time sensing module is used to sense the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS lower-level machine IO card cuts off the control signal path and stops data interaction with the DCS controller except for trusted state notification.

[0035] The trusted state recovery module is used to restore the trusted state of the DCS controller when the DCS controller is restored from an untrusted state to a trusted state. The DCS host computer background program restores the trusted state of the DCS controller, and the DCS slave computer I / O card resumes all data interaction with the DCS controller.

[0036] A third aspect of this application is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the DCS controller trusted measurement consistency method.

[0037] A fourth aspect of this application is to provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the DCS controller trusted measurement consistency method.

[0038] Compared with existing technologies, the beneficial effects of this application are as follows: By adding a real-time push mechanism for the trusted status of the DCS controller, based on the existing up-down communication of the DCS controller, the trusted status of the DCS controller is periodically sent to the DCS host computer background program and the DCS lower-level I / O cards. Through real-time perception of the trusted status of the DCS controller, the DCS lower-level I / O cards can promptly cut off the control signal path, preventing illegal tampering of local device input and output signals, which could reduce the security of the field control layer. Simultaneously, the DCS host computer can detect the trusted status of the DCS controller in real time, promptly disconnecting untrusted DCS controllers from the entire system, interrupting communication between the DCS controller and other nodes in the DCS, and promptly issuing alarms to users to prevent the spread of the impact. This embodiment can effectively ensure the network security status of the entire DCS and realize trusted enhancement of the DCS controller based on trusted computing. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 is a flowchart illustrating the DCS controller trust measurement consistency method provided in this application;

[0041] Figure 2 is a block flowchart of a DCS controller trusted measurement consistency system provided in this application;

[0042] Figure 3 is a schematic diagram of the trusted status update process of the DCS host computer background controller in this application.

[0043] Figure 4 is a schematic diagram of the trusted status update process of the DCS lower-level machine IO card controller in this application. Detailed Implementation

[0044] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0045] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0046] To address the problems existing in the background technology, a method, system, electronic device, and storage medium for reliable measurement consistency of DCS controllers are designed and researched, which has important practical significance.

[0047] As shown in Figure 1, the first aspect of this application provides a DCS controller trust measurement consistency method, which includes the following steps:

[0048] Step S001: The DCS controller pushes its own trusted status.

[0049] The trusted state of the DCS controller is obtained from its own trusted components through the DCS controller.

[0050] The trusted status is then pushed to the DCS host computer background program and the DCS slave computer I / O card, respectively.

[0051] Specifically, the push notification method reuses the original communication method. Push notifications to the DCS host computer background program use Ethernet message communication, while push notifications to the DCS slave computer IO card use a private bus protocol, a general bus protocol, or Ethernet messages.

[0052] Step S002: The reliable status of the controller is sensed and control adjustments are made through the DCS host computer background program.

[0053] It should be noted that by sensing the trusted status of the DCS controller in real time, the DCS host computer can detect the trusted status of the DCS controller in real time, promptly disconnect untrusted DCS controllers from the entire system, interrupt communication between untrusted DCS controllers and other nodes in the DCS, and promptly issue alarms to users to prevent the scope of impact from expanding.

[0054] Specifically, the DCS controller obtains the trusted state of the DCS controller in each scan cycle from its own trusted components;

[0055] Determine the trusted state of the DCS controller during the current scan cycle;

[0056] If the DCS controller is in a trusted state in the current scan cycle, then check whether the DCS controller was trusted in the previous scan cycle. If it was trusted in the previous scan cycle, then push the trusted state message to the DCS host computer background program. After completion, continue to obtain the state of the DCS controller in the next scan cycle. If it was untrusted in the previous scan cycle, then restore the DCS controller to a trusted state, generate a fault recovery alarm message and push it to the DCS host computer background program through a trusted state message. After completion, continue to obtain the state of the DCS controller in the next scan cycle.

[0057] If the DCS controller is in an untrusted state in the current scan cycle, the system checks whether the DCS controller was trusted in the previous scan cycle. If it was trusted in the previous scan cycle, the system detects a trusted state failure in the DCS controller, generates a fault alarm, and sends it to the DCS host computer background program via a trusted state message. After completion, the system continues to obtain the trusted state of the DCS controller for the next scan cycle. If the DCS controller was in an untrusted state in the previous scan cycle, the system sends a master / slave switchover message to the DCS controller and cuts off the interaction of service data messages with the DCS controller.

[0058] Before the DCS host computer background program interrupts communication between the DCS controller and other nodes in the DCS and sends an alarm to the user, it needs to determine whether the DCS controller needs to perform a master / slave switch based on the DCS controller's status. The specific process of this determination is as follows:

[0059] The DCS host computer background program determines the master / standby status of the DCS controller.

[0060] If the DCS controller in an untrusted state is the master controller, the DCS host computer background program sends a master-slave switchover message to notify the DCS controller to perform a master-slave switchover.

[0061] If the DCS controller in an untrusted state is a backup controller, the DCS host computer background program will change the trusted state of the DCS controller to an untrusted state, and no switching is required; the next step can be directly performed.

[0062] As shown in Figure 3, the real-time sensing of the trusted status of the controller by the DCS host computer includes two processes: the real-time notification process of the trusted status of the DCS controller and the update process of the trusted status of the DCS controller by the DCS host computer program.

[0063] The specific process of the DCS controller trusted status real-time notification procedure is as follows:

[0064] Step 1: The DCS controller obtains the DCS controller status from the trusted component of the DCS controller. If the DCS controller is in a trusted state in the current scan cycle, proceed to step 2. If the DCS controller is in an untrusted state in the current scan cycle, proceed to step 4.

[0065] Step 2: Determine whether the DCS controller status in the previous scan cycle is reliable. If not, proceed to step 3; if yes, proceed to step 6.

[0066] Step 3: The DCS controller's trusted state is restored, corresponding fault recovery alarm information is generated and sent to the DCS host computer background program, then jump to step 6;

[0067] Step 4: Determine whether the DCS controller status in the previous scan cycle is reliable. If yes, proceed to step 5; otherwise, proceed to step 6.

[0068] Step 5: DCS controller trusted status failure, generate fault alarm information and send it to DCS host computer background program, jump to step 6;

[0069] Step 6: Send a trusted status message to the DCS host computer background program. After completion, jump to step 1 and repeat.

[0070] The specific process of updating the trusted state of the DCS controller by the DCS host computer background program is as follows:

[0071] Step 1: The DCS host computer background program application obtains the trusted status of the DCS controller in the current scan cycle from the trusted status message. If the DCS controller is in a trusted state in the current scan cycle, jump to step 2; if the DCS controller is in an untrusted state in the current scan cycle, jump to step 4.

[0072] Step 2: Determine whether the DCS controller status in the previous scan cycle is reliable. If not, proceed to step 3; if yes, proceed to step 7.

[0073] Step 3: Restore the trusted state of the DCS controller, generate a trusted recovery alarm message, restore all business data message interaction with the DCS controller, update the state of the DCS controller to a trusted state, and proceed to step 7.

[0074] Step 4: Determine whether the DCS controller status in the previous scan cycle is reliable. If yes, proceed to step 5; otherwise, proceed to step 7.

[0075] Step 5: Determine the primary / standby status of the untrusted controller. If it is the primary controller, proceed to step 6; if it is the standby controller, proceed to step 7.

[0076] Step 6: Send a primary / standby switchover message to the DCS controller, cut off the service data message interaction with the DCS controller, and proceed to step 7;

[0077] Step 7: Update the trusted state of the DCS controller.

[0078] Step S003: The DCS lower-level I / O card senses the trusted status of the controller and makes control adjustments.

[0079] It should be noted that by sensing the trusted status of the DCS controller in real time, the DCS lower-level I / O card can cut off the control signal path in a timely manner to prevent illegal tampering of the input and output signals of local devices.

[0080] Specifically, the DCS controller obtains the trusted state of the DCS controller in the current scan cycle from its own trusted components;

[0081] If the trusted status of the DCS controller is normal in the current scanning cycle, the DCS controller and the DCS lower-level I / O card will interact normally and push the trusted status message to the DCS lower-level I / O card. After completion, the trusted status of the DCS controller in the next scanning cycle will be obtained.

[0082] If the trusted status of the DCS controller is abnormal in the current scan cycle, the DCS controller will stop all data interaction with the DCS lower-level I / O card except for trusted status notification, and will push trusted status messages to the DCS lower-level I / O card. After completion, it will continue to obtain the trusted status of the DCS controller in the next scan cycle.

[0083] As shown in Figure 4, the real-time sensing of the trusted status of the controller by the DCS host computer includes two processes: the real-time notification process of the trusted status of the DCS controller and the update process of the trusted status of the DCS controller by the DCS slave computer IO card.

[0084] The specific process of the DCS controller trusted status real-time notification procedure is as follows:

[0085] Step 1: The DCS controller application obtains the controller's trusted status from the DCS controller's trusted component. If the DCS controller is in a trusted state, proceed to Step 2; if the DCS controller is in an untrusted state, proceed to Step 4.

[0086] Step 2: Is the DCS controller status reliable in the previous scan cycle? If not, proceed to step 3; if yes, proceed to step 6.

[0087] Step 3: The DCS controller's trusted state is restored, corresponding fault recovery alarm information is generated and sent to the DCS host computer background program, then jump to step 6;

[0088] Step 4: Is the DCS controller status reliable in the previous scan cycle? If yes, proceed to step 5; otherwise, proceed to step 8.

[0089] Step 5: DCS controller trusted status failure, generate fault alarm information and send it to DCS host computer background program, jump to step 7;

[0090] Step 6: The DCS controller is in a normal trusted state and interacts with the DCS lower-level I / O card normally. Proceed to step 8.

[0091] Step 7: The DCS controller is in an abnormal trusted state. Stop all data interaction with the DCS lower-level I / O card except for trusted state notification, and proceed to step 8.

[0092] Step 8: Notify the DCS lower-level I / O card of the trusted status of the DCS controller. After completion, jump to step 1 and repeat.

[0093] The specific process of updating the trusted state of the DCS controller via the DCS lower-level I / O card is as follows:

[0094] Step 1: The DCS lower-level I / O card obtains the trusted status of the DCS controller from the trusted status notified by the DCS controller. If the DCS controller is in a trusted state, proceed to step 2; if the DCS controller is in an untrusted state, proceed to step 3.

[0095] Step 2: Normal data interaction with the DCS controller, then jump to Step 1 and repeat;

[0096] Step 3: Stop all data interaction with the DCS controller except for trusted status notifications, and go back to Step 1 and repeat.

[0097] The recovery of all data interaction between the DCS lower-level I / O card and the DCS controller includes: transmitting data from the DCS lower-level I / O card back to the DCS controller or receiving output signals from the I / O board issued by the DCS controller.

[0098] Figure 2 illustrates a DCS controller trusted measurement consistency system provided by the second aspect of this application, which includes the following modules: a trusted state real-time push module 101, a DCS host computer background program real-time sensing module 102, a DCS slave computer IO card real-time sensing module 103, and a trusted state recovery module 104.

[0099] The trusted status real-time push module 101 is used for the DCS controller to push its own status to the DCS host computer background program and the DCS slave computer IO card in real time.

[0100] The DCS host computer background program real-time sensing module 102 is used to sense the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS host computer background program interrupts the communication between the DCS controller and other nodes in the DCS and sends an alarm to the user.

[0101] The DCS lower-level machine IO card real-time sensing module 103 is used for the DCS lower-level machine IO card to sense the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS lower-level machine IO card cuts off the path of the control signal and stops interacting with the DCS controller with other data except for trusted state notification.

[0102] The trusted state recovery module 104 is used to restore the trusted state of the DCS controller by the DCS host computer background program after the DCS controller is restored from an untrusted state to a trusted state, and the DCS host computer background program and DCS slave I / O card resume all data interaction with the DCS controller.

[0103] A third aspect of this application is to provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the steps of a DCS controller trusted measurement consistency method.

[0104] The fourth aspect of this application is to provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of a DCS controller trusted measurement consistency method.

[0105] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0106] This application is described with reference to flowchart illustrations and / or block diagrams of methods, systems, and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.

[0107] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0108] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0109] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application and not to limit them. Although this application has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation methods of this application. Any modifications or equivalent substitutions that do not depart from the spirit and scope of this application should be covered within the protection scope of this application.

Claims

1. A method for consistency measurement of trustworthiness in a DCS controller, characterized in that, include: The DCS controller pushes its own status to the DCS host computer background program in real time, and the DCS controller also pushes its own status to the DCS slave computer IO card in real time. The DCS host computer background program senses the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, it first determines whether the DCS controller needs to perform a master-slave switch based on the status of the DCS controller. Then, the DCS host computer background program interrupts the communication between the DCS controller and other nodes in the DCS and sends an alarm to the user. The DCS lower-level I / O card senses the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS lower-level I / O card cuts off the path of the control signal and stops interacting with the DCS controller with other data except for trusted status notification. When the DCS controller recovers from an untrusted state to a trusted state, the DCS host computer background program restores the DCS controller to a trusted state, and the DCS host computer background program and DCS slave I / O cards resume all data interaction with the DCS controller.

2. The DCS controller trust measurement consistency method according to claim 1, characterized in that, The DCS controller pushes its own status to the DCS host computer background program in real time, including: The DCS controller uses Ethernet packets to push its status to the DCS host computer background program in real time.

3. The DCS controller trust measurement consistency method according to claim 1, characterized in that, The DCS controller pushes its trusted status to the DCS lower-level I / O card in real time, including: The DCS controller uses a proprietary bus protocol, a general bus protocol, or Ethernet message communication to push its status to the DCS lower-level I / O card in real time.

4. The DCS controller trust measurement consistency method according to claim 2, characterized in that, The specific process by which the DCS controller pushes its own status to the DCS host computer background program in real time is as follows: The DCS controller obtains the trusted state of the DCS controller in each scan cycle from its own trusted components; and determines the trusted state of the DCS controller in the current scan cycle. If the DCS controller is in a trusted state in the current scan cycle, then check whether the DCS controller was trusted in the previous scan cycle. If it was trusted in the previous scan cycle, then push the trusted state message to the DCS host computer background program. After completion, continue to obtain the state of the DCS controller in the next scan cycle. If the previous scan cycle was in an untrusted state, the DCS controller is restored to a trusted state, a fault recovery alarm is generated and pushed to the DCS host computer background program through a trusted state message. After completion, the status of the DCS controller in the next scan cycle is obtained. If the DCS controller is in an untrusted state in the current scan cycle, the system checks whether the DCS controller was trusted in the previous scan cycle. If it was trusted in the previous scan cycle, the system detects a trusted state failure in the DCS controller, generates a fault alarm, and sends it to the DCS host computer background program via a trusted state message. After completion, the system continues to obtain the trusted state of the DCS controller for the next scan cycle. If the DCS controller was in an untrusted state in the previous scan cycle, the system sends a master / slave switchover message to the DCS controller and cuts off the interaction of service data messages with the DCS controller.

5. The DCS controller trust measurement consistency method according to claim 3, characterized in that, The specific process by which the DCS controller pushes its trusted state to the DCS lower-level I / O card in real time is as follows: The DCS controller obtains the trusted state of the DCS controller in the current scan cycle from its own trusted components. If the trusted status of the DCS controller is normal in the current scanning cycle, the DCS controller and the DCS lower-level I / O card will interact normally and push the trusted status message to the DCS lower-level I / O card. After completion, the trusted status of the DCS controller in the next scanning cycle will be obtained. If the trusted status of the DCS controller is abnormal in the current scan cycle, the DCS controller will stop all data interaction with the DCS lower-level I / O card except for trusted status notification, and will push trusted status messages to the DCS lower-level I / O card. After completion, it will continue to obtain the trusted status of the DCS controller in the next scan cycle.

6. The DCS controller trust measurement consistency method according to claim 1, characterized in that, The step of determining whether the DCS controller needs to perform a master / slave switch based on the status of the DCS controller includes: The DCS host computer background program determines the master / standby status of the DCS controller. If the DCS controller in an untrusted state is the master controller, the DCS host computer background program sends a master-slave switchover message to notify the DCS controller to perform a master-slave switchover. If the DCS controller in an untrusted state is a standby controller, the DCS host computer background program will change the trusted state of the DCS controller to an untrusted state without needing to perform a master-slave switchover, and proceed directly to the next step of processing.

7. The DCS controller trust measurement consistency method according to claim 1, characterized in that, The DCS lower-level I / O card resumes all data interaction with the DCS controller, including: The data from the DCS lower-level I / O card is transmitted back to the DCS controller or the output signals from the I / O board issued by the DCS controller are received.

8. A DCS controller trusted measurement consistency system, characterized in that, include: The trusted status real-time push module is used for the DCS controller to push its own status to the DCS host computer background program and the DCS slave computer IO card in real time. The DCS host computer background program real-time sensing module is used to sense the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS host computer background program interrupts the communication between the DCS controller and other nodes in the DCS and issues an alarm to the user. The DCS lower-level machine IO card real-time sensing module is used to sense the status of the DCS controller in real time. When the status of the DCS controller changes from a trusted state to an untrusted state, the DCS lower-level machine IO card cuts off the control signal path and stops data interaction with the DCS controller except for trusted state notification. The trusted state recovery module is used to restore the trusted state of the DCS controller when the DCS controller is restored from an untrusted state to a trusted state. The DCS host computer background program restores the trusted state of the DCS controller, and the DCS slave computer I / O card resumes all data interaction with the DCS controller.

9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the DCS controller trusted measurement consistency method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the DCS controller trusted measurement consistency method according to any one of claims 1-7.