WO2015013958A1 - 可编程逻辑控制器及其用户身份识别系统与方法 - Google Patents

可编程逻辑控制器及其用户身份识别系统与方法 Download PDF

Info

Publication number
WO2015013958A1
WO2015013958A1 PCT/CN2013/080640 CN2013080640W WO2015013958A1 WO 2015013958 A1 WO2015013958 A1 WO 2015013958A1 CN 2013080640 W CN2013080640 W CN 2013080640W WO 2015013958 A1 WO2015013958 A1 WO 2015013958A1
Authority
WO
WIPO (PCT)
Prior art keywords
programmable logic
logic controller
user
program memory
writable
Prior art date
Application number
PCT/CN2013/080640
Other languages
English (en)
French (fr)
Inventor
陈东山
郑吉化
许汝洁
王晓惠
Original Assignee
西门子公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 西门子公司 filed Critical 西门子公司
Priority to PCT/CN2013/080640 priority Critical patent/WO2015013958A1/zh
Priority to CN201380076888.0A priority patent/CN105264933A/zh
Publication of WO2015013958A1 publication Critical patent/WO2015013958A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security

Definitions

  • the present invention relates to the field of industrial electronic device technology, and in particular to a programmable logic controller and a user identification system and method thereof. Background of the invention
  • PLC Programmable Logic Controller
  • PLC systems are generally complex, requiring many devices to work in the system, and there are many users in the entire system. PLC systems usually give different identities to different users to ensure safe and efficient operation of the entire system.
  • the identification of users of PLC systems is generally controlled by the encryption program and password of the PLC system.
  • the different rights of users of different identities are generally controlled by passwords.
  • the password is lost or leaked, it will bring huge security risks to the PLC system. Summary of the invention
  • Embodiments of the present invention provide a programmable logic controller to improve the security of a programmable logic controller.
  • Embodiments of the present invention provide a user identification system for a programmable logic controller, To improve the security of the programmable logic controller.
  • Embodiments of the present invention provide a user identification method of a programmable logic controller to improve the security of a programmable logic controller.
  • a programmable logic controller comprising:
  • a near field communication unit configured to receive user identity information from the near field communication card by means of near field communication
  • a user identity unit configured to identify the received user identity information, and determine a user operation authority level corresponding to the user identity information
  • a mode switching unit configured to switch an operating mode of the programmable logic controller based on the determined user operation authority level.
  • system program memory for storing system programs
  • a mode switching unit configured to switch the working mode of the programmable logic controller to one of the following:
  • the system program memory is readable and writable
  • the system program memory is writable and unreadable
  • the system program memory is neither readable nor writable
  • the system program memory is both readable and writable.
  • a user program memory for storing a user program
  • a mode switching unit configured to switch the working mode of the programmable logic controller to one of the following:
  • the user program memory is readable and not writable
  • User program memory is writable and unreadable
  • User program memory is neither readable nor writable
  • the user program memory is both readable and writable. Further comprising a human machine interface HMI unit;
  • a mode switching unit configured to switch the working mode of the programmable logic controller to at least one of the following:
  • the screen protection password interface of the HMI unit is successfully authenticated
  • a user identification system for a programmable logic controller comprising a programmable logic controller and a near field communication card, wherein:
  • a near field communication card storing user identity information and transmitting user identity information to the programmable logic controller through near field communication;
  • a programmable logic controller configured to receive user identity information from the near field communication card by means of near field communication; identify the received user identity information and determine a user operation authority level corresponding to the user identity information; and based on the determined The user operation authority level switches the working mode of the programmable logic controller.
  • a programmable logic controller further comprising: a system program memory for storing the system program; and switching the working mode of the programmable logic controller to at least one of the following: the system program memory is readable and writable;
  • the system program memory is writable and unreadable
  • the system program memory is neither readable nor writable
  • the system program memory is both readable and writable.
  • a programmable logic controller further comprising a user program memory for storing a user program; and switching an operation mode of the programmable logic controller to at least one of: the user program memory is readable and writable;
  • User program memory is writable and unreadable; User program memory is neither readable nor writable;
  • the user program memory is both readable and writable.
  • the programmable logic controller further includes a human interface unit; and switches the working mode of the programmable logic controller to at least one of the following:
  • the screen protection password interface of the HMI unit is successfully authenticated
  • a user identification method for a programmable logic controller comprising: receiving user identity information from a near field communication card by means of near field communication;
  • the operating mode of the programmable logic controller is switched based on the determined level of user operation authority.
  • the switching the working mode of the programmable logic controller includes: switching the working mode of the programmable logic controller to at least one of the following:
  • the system program memory is readable and writable
  • the system program memory is writable and unreadable
  • the system program memory is neither readable nor writable
  • the system program memory is both readable and writable
  • the user program memory is readable and not writable
  • User program memory is writable and unreadable
  • User program memory is neither readable nor writable
  • User program memory is both readable and writable
  • the screen protection password interface of the HMI unit is successfully authenticated;
  • the screen protection password interface authentication of the HMI unit fails;
  • a near field communication unit is configured to receive user identity information from a near field communication card by means of near field communication; and a user identity recognition unit is configured to receive user identity information Identifying, and determining a user operation authority level corresponding to the user identity information; and a mode switching unit, configured to switch the working mode of the programmable logic controller based on the determined user operation authority level.
  • the identification technology for the programmable logic controller device is implemented by near field communication.
  • the near field communication identification card is difficult to be spread as a physical entity on a large scale, and even if the near field communication identification card is lost, it can be quickly found by the system administrator, and thus the prior art method of protecting by password is compared.
  • the embodiments of the present invention significantly improve the security of the programmable logic controller.
  • the programmable logic controller when the programmable logic controller needs to be operated, only the near field communication identification card needs to be close to the programmable logic controller, and the programmable logic controller can know the identity of the user and give corresponding usage rights, so the use It is not necessary to memorize various passwords, and thus the embodiment of the present invention is also very convenient.
  • FIG. 1 is a block diagram of a programmable logic controller in one embodiment.
  • FIG. 2 is a structural diagram of a user identification system of an embodiment programmable logic controller.
  • FIG. 3 is a flow chart of a user identification method of a programmable logic controller in an embodiment. Mode for carrying out the invention
  • an identification technology for a PLC device is implemented by a near field communication (NFC) method.
  • NFC near field communication
  • the user information in the near field communication identification card from outside the programmable logic controller is received by embedding a near field communication receiving unit in the programmable logic controller device.
  • a user identity identification card of a corresponding level can be written in each of the near field communication identification cards.
  • the programmable logic controller When the programmable logic controller needs to be operated, only the near field communication identification card needs to be close to the programmable logic controller, and the programmable logic controller can know the identity of the user and give corresponding usage rights.
  • FIG. 1 is a block diagram of a programmable logic controller in one embodiment.
  • the programmable logic controller 100 includes:
  • the near field communication unit 101 is configured to receive user identity information from a near field communication card located outside the programmable logic controller 100 by means of near field communication;
  • the user identification unit 102 is configured to identify the received user identity information, and determine a user operation authority level corresponding to the user identity information;
  • the mode switching unit 103 is configured to switch the working mode of the programmable logic controller 100 based on the determined user operation authority level.
  • the near field communication unit 101 can receive user identity information from a near field communication card located outside of the programmable logic controller 100 by near field communication.
  • Near field communication also known as short-range wireless communication, is a short-range, high-frequency wireless communication technology that allows electronic devices to exchange data between non-contact point-to-point data transmissions (eg, within 10 cm).
  • the near field communication card is an IC card containing user identity information, and the near field communication card There is also a near field communication unit, and the near field communication unit can transmit/receive user identity information held by the IC card.
  • the near field communication card has a significant advantage in that the near field communication card can be powered by the radio frequency signal (RF) field of the near field communication unit 101 in the contactless programmable logic controller 100, thereby enabling The near field communication card itself does not need to be powered.
  • RF radio frequency signal
  • the user identity unit 102 first identifies the received user identity information, and the identifying operation includes determining whether the user identity information is legitimate. After confirming whether the user identity information is legal, the user identity unit 102 determines the user operation authority level corresponding to the user identity information.
  • the programmable logic controller 100 of the embodiment of the present invention may also have other common components such as a power supply, a central processing unit (CPU), a memory, an input/output interface circuit, a function module, and the like.
  • a power supply a power supply, a central processing unit (CPU), a memory, an input/output interface circuit, a function module, and the like.
  • the power of the programmable logic controller plays an important role in the overall system. If a good, reliable power system is not working properly, the power supply's general AC voltage fluctuations are within +10%, and the programmable logic controller can be directly connected to the AC grid without further measures.
  • the central processing unit (CPU) of the programmable logic controller is the control center of the programmable logic controller. It receives and stores the user program and data typed from the programmer according to the functions given by the programmable logic controller system program; The status of the memory, I/O, and watchdog timers, and can diagnose syntax errors in the user program.
  • the CPU When the programmable logic controller is put into operation, the CPU first scans the status and data of each input device in the field, and stores them in the I/O image area respectively, and then reads the user program one by one from the user program memory. After the command is interpreted, the result of performing logic or arithmetic operations as specified by the instruction is sent to the I/O map area or data register. After all the user programs have been executed, the output status of the I/O image area or the data in the output register is finally transmitted. Go to the corresponding output device and cycle until it stops running.
  • the programmable logic controller of the embodiment of the present invention can also adopt a dual CPU to form a redundant system, or a three-CPU voting system. This way, even if a CPU fails, the entire system will still operate normally.
  • the programmable logic controller 100 further includes a system program memory 104 for storing system programs;
  • the mode switching unit 103 is configured to switch the working mode of the programmable logic controller to at least one of the following: the system program memory 104 is readable and writable; the system program memory 104 is writable and unreadable; the system program memory 104 is neither readable Also unwritable; system program memory 104 is both readable and writable.
  • the mode switching unit 103 can switch the working mode of the programmable logic controller 100, so that the system program memory 104 A normal guest identity is neither readable nor writable.
  • the mode switching unit 103 can switch the working mode of the programmable logic controller 100 so that the system program memory 104 is The user is readable and not writable.
  • the mode switching unit 103 can switch the working mode of the programmable logic controller 100 so that the system program memory 104 is The user is both readable and writable.
  • the programmable logic controller 100 further includes a user program for storing a user program Sequence memory 105;
  • the mode switching unit 103 is configured to switch the working mode of the programmable logic controller to one of the following: the user program memory 105 is readable and writable; the user program memory 105 is writable and unreadable; the user program memory 105 is neither readable nor Not writable; user program memory 105 is both readable and writable.
  • the mode switching unit 103 can switch the working mode of the programmable logic controller 100 so that the user program memory 105 A normal guest identity is neither readable nor writable.
  • the mode switching unit 103 can switch the working mode of the programmable logic controller 100 so that the user program memory 105 is The user is readable and not writable.
  • the mode switching unit 103 can switch the working mode of the programmable logic controller 100 so that the user program memory 105 is The user is both readable and writable.
  • the programmable logic controller 100 further includes a human machine interface (HMI) unit 106.
  • the mode switching unit 103 is configured to switch the working mode of the programmable logic controller to at least one of the following: screen protection of the HMI unit 106
  • the authentication of the password interface is successful; the authentication of the screen protection password interface of the HMI unit 106 fails; the authentication of the power-on password interface of the HMI unit 106 is successful; the authentication of the power-on password interface of the HMI unit 106 fails.
  • the mode switch The unit 103 can switch the working mode of the programmable logic controller 100 such that the screen save password interface authentication of the HMI unit 106 fails, or the power-on password interface authentication of the HMI unit 106 fails.
  • the mode switching unit 103 may be configured by the programmable logic controller 100. The working mode is switched, so that the screen protection password interface of the HMI unit 106 is successfully authenticated, or the power-on password interface authentication of the HMI unit 106 is successful.
  • the mode switching unit 103 may The working mode of the programming logic controller 100 is switched, so that the screen protection password interface of the HMI unit 106 is successfully authenticated, and the power-on password interface authentication of the HMI unit 106 is successful.
  • the programmable logic controller 100 can perform write operations on user identity information stored in the near field communication card, such as deletion, rewriting, or formatting, using a near field communication connection with the near field communication card.
  • an embodiment of the present invention also proposes an identification system of a programmable logic controller.
  • FIG. 2 is a structural diagram of a user identification system of a programmable logic controller according to an embodiment of the present invention.
  • the system includes a programmable logic controller 100 and a near field communication card 200.
  • the near field communication card 200 stores user identity information and transmits user identity information to the programmable logic controller by means of near field communication;
  • Programmable logic controller 100 for receiving from a near field communication card by near field communication User identity information; identifying the received user identity information and determining a user operation authority level corresponding to the user identity information; and switching the working mode of the programmable logic controller based on the determined user operation authority level .
  • the programmable logic controller 100 may specifically have a structure as shown in FIG.
  • the programmable logic controller 100 includes: a near field communication unit 101 configured to receive user identity information from a near field communication card located outside the programmable logic controller 100 by near field communication; the user identity identification unit 102, Identifying the received user identity information to determine a user operation authority level corresponding to the user identity information; the mode switching unit 103, configured to the programmable logic controller 100 based on the determined user operation authority level Work mode to switch.
  • the programmable logic controller 100 further includes a system program memory 104 for storing system software.
  • the mode switching unit 103 switches the working mode of the programmable logic controller to at least one of the following: the system program memory 104 is readable and writable; the system program memory 104 is writable and unreadable; the system program memory 104 is neither readable nor Write; system program memory 104 is both readable and writable.
  • the programmable logic controller 100 further includes a user program memory 105 for storing user programs.
  • the mode switching unit 103 switches the working mode of the programmable logic controller to at least one of: the user program memory is readable and writable; the user program memory is writable and unreadable; the user program memory is neither readable nor writable; the user The program memory is both readable and writable.
  • the programmable logic controller further includes a human interface unit 106.
  • the mode switching unit 103 switches the working mode of the programmable logic controller to at least one of the following: the screen protection password interface authentication of the HMI unit is successful; the screen protection password interface authentication of the HMI unit fails; the power-on password of the HMI unit The interface authentication succeeds; the authentication of the power-on password interface of the HMI unit fails.
  • the near field communication card 200 is an IC card containing user identity information, and the near field communication card 200 also has a near field communication unit, and the near field communication unit can transmit/receive user identity information held by the IC card.
  • the embodiment of the present invention also proposes a user identification method of the programmable logic controller.
  • FIG. 3 is a flow chart of a user identification method of a programmable logic controller in an embodiment.
  • the method includes:
  • Step S300 Receive user identity information from the near field communication card by using near field communication.
  • Step S310 Identify the received user identity information, and determine a user operation authority level corresponding to the user identity information.
  • Step S320 Switch the working mode of the programmable logic controller based on the determined user operation authority level.
  • switching the operating mode of the programmable logic controller includes switching the operating mode of the programmable logic controller to at least one of: a system program memory readable and writable; a system program memory Writable and unreadable; system program memory is neither readable nor writable; system program memory is both readable and writable; user program memory is readable and writable; user program memory is writable and unreadable; user program memory is neither readable nor writable
  • the user program memory is both readable and writable; the HMI unit's screen saver password interface is successfully authenticated; the HMI unit's screen saver password interface authentication fails; the HMI unit's power-on password interface is successfully authenticated; the HMI unit's power-on password interface is authenticated; The power failed.
  • a near field communication unit is configured to receive user identity information from a near field communication card by means of near field communication; and a user identity recognition unit is configured to identify the received user identity information and Determining a user operation authority level corresponding to the user identity information; and a mode switching unit, configured to switch an operation mode of the programmable logic controller based on the determined user operation authority level.
  • the identification technology for the programmable logic controller device is implemented by the near field communication method.
  • the near field communication identification card is difficult to be spread as a physical entity on a large scale, and even if the near field communication identification card is lost, it can be quickly found by the system administrator, and thus the prior art method of protecting by password is compared.
  • the embodiments of the present invention significantly improve the security of the programmable logic controller.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Programmable Controllers (AREA)

Abstract

本发明实施方式涉及一种可编程逻辑控制器及其用户身份识别系统与方法。近场通信单元,用于通过近场通信方式从近场通信卡接收用户身份信息;用户身份识别单元,用于对接收的用户身份信息进行识别并确定出对应于该用户身份信息的用户操作权限级别;模式切换单元,用于基于所确定的用户操作权限级别,对所述可编程逻辑控制器的工作模式进行切换。本发明能够提高安全性和便利性。

Description

可编程逻辑控制器及其用户身份识别系统与方法
技术领域
本发明涉及工业电子装置技术领域, 特别涉及可编程逻辑控制器及 其用户身份识别系统与方法。 发明背景
可编程逻辑控制器(PLC )是一种为工业环境应用设计的数字运算 操作电子装置。 它采用可以编制程序的存储器, 用来在其内部存储执行 逻辑运算、 顺序运算、 计时、 计数和算术运算等操作的指令, 并能通过 数字式或模拟式的输入和输出, 控制各种类型的机械或生产过程。 PLC 及其有关的外围设备通常都按照易于与工业控制系统形成一个整体、 易 于扩展其功能的原则而设计。
PLC系统一般比较复杂, 需要许多设备在系统中组网工作, 而且整 个系统中一般有很多的使用者。 PLC系统通常会赋予不同身份的使用者 以不同的权限, 以保证整个系统安全高效的工作。
目前在 PLC应用领域, 对于 PLC系统使用者的身份识别, 一般是 通过 PLC系统的加密程序以及密码来控制。不同身份的使用者的不同权 限一般由密码来控制。 然而, 如果密码丟失或者泄露, 则会给 PLC系统 带来巨大的安全隐患。 发明内容
本发明实施方式提供一种可编程逻辑控制器, 以提高可编程逻辑控 制器的安全性。
本发明实施方式提供一种可编程逻辑控制器的用户身份识别系统, 以提高可编程逻辑控制器的安全性。
本发明实施方式提供一种可编程逻辑控制器的用户身份识别方法, 以提高可编程逻辑控制器的安全性。
本发明实施方式的技术方案如下:
一种可编程逻辑控制器, 包括:
近场通信单元, 用于通过近场通信方式从近场通信卡接收用户身份 信息;
用户身份识别单元, 用于对接收的用户身份信息进行识别, 并确定 出对应于该用户身份信息的用户操作权限级别;
模式切换单元, 用于基于所确定的用户操作权限级别, 对所述可编 程逻辑控制器的工作模式进行切换。
进一步包括用于存放系统程序的系统程序存储器;
模式切换单元, 用于将该可编程逻辑控制器的工作模式切换为下列 中的一个:
系统程序存储器可读不可写;
系统程序存储器可写不可读;
系统程序存储器既不可读又不可写;
系统程序存储器既可读又可写。
进一步包括用于存放用户程序的用户程序存储器;
模式切换单元, 用于将该可编程逻辑控制器的工作模式切换为下列 中的一个:
用户程序存储器可读不可写;
用户程序存储器可写不可读;
用户程序存储器既不可读又不可写;
用户程序存储器既可读又可写。 进一步包括人机界面 HMI单元;
模式切换单元, 用于将该可编程逻辑控制器的工作模式切换为下列 中的至少一个:
HMI单元的屏幕保护密码界面鉴权成功;
HMI单元的屏幕保护密码界面鉴权失败;
HMI单元的开机密码界面鉴权成功;
HMI单元的开机密码界面鉴权失败。
一种可编程逻辑控制器的用户身份识别系统, 包括可编程逻辑控制 器和近场通信卡, 其中:
近场通信卡, 存储有用户身份信息, 并通过近场通信方式向可编程 逻辑控制器发送用户身份信息;
可编程逻辑控制器, 用于通过近场通信方式从近场通信卡接收用户 身份信息; 对接收的用户身份信息进行识别并确定出对应于该用户身份 信息的用户操作权限级别; 并基于所确定的用户操作权限级别, 对所述 可编程逻辑控制器的工作模式进行切换。
可编程逻辑控制器, 进一步包括用于存放系统程序的系统程序存储 器; 并将该可编程逻辑控制器的工作模式切换为下列中的至少一个: 系统程序存储器可读不可写;
系统程序存储器可写不可读;
系统程序存储器既不可读又不可写;
系统程序存储器既可读又可写。
可编程逻辑控制器, 进一步包括用于存放用户程序的用户程序存储 器; 并将该可编程逻辑控制器的工作模式切换为下列中的至少一个: 用户程序存储器可读不可写;
用户程序存储器可写不可读; 用户程序存储器既不可读又不可写;
用户程序存储器既可读又可写。
可编程逻辑控制器, 进一步包括人机界面单元; 并将该可编程逻辑 控制器的工作模式切换为下列中的至少一个:
HMI单元的屏幕保护密码界面鉴权成功;
HMI单元的屏幕保护密码界面鉴权失败;
HMI单元的开机密码界面鉴权成功;
HMI单元的开机密码界面鉴权失败。
一种可编程逻辑控制器的用户身份识别方法, 该方法包括: 通过近场通信方式从近场通信卡接收用户身份信息;
对接收的用户身份信息进行识别, 并确定出对应于该用户身份信息 的用户操作权限级别;
基于所确定的用户操作权限级别, 对所述可编程逻辑控制器的工作 模式进行切换。
所述对所述可编程逻辑控制器的工作模式进行切换包括, 将该可编 程逻辑控制器的工作模式切换为下列中的至少一个:
系统程序存储器可读不可写;
系统程序存储器可写不可读;
系统程序存储器既不可读又不可写;
系统程序存储器既可读又可写;
用户程序存储器可读不可写;
用户程序存储器可写不可读;
用户程序存储器既不可读又不可写;
用户程序存储器既可读又可写;
HMI单元的屏幕保护密码界面鉴权成功; HMI单元的屏幕保护密码界面鉴权失败;
HMI单元的开机密码界面鉴权成功;
HMI单元的开机密码界面鉴权失败。
从上述技术方案可以看出, 在本发明实施方式中, 近场通信单元, 用于通过近场通信方式从近场通信卡接收用户身份信息; 用户身份识别 单元, 用于对接收的用户身份信息进行识别, 并确定出对应于该用户身 份信息的用户操作权限级别; 模式切换单元, 用于基于所确定的用户操 作权限级别,对所述可编程逻辑控制器的工作模式进行切换。由此可见, 应用本发明实施方式之后, 通过近场通信方式实现针对可编程逻辑控制 器设备的身份识别技术。 不同于密码, 近场通信识别卡作为物理实体很 难被大规模扩散, 而且即使近场通信识别卡丟失, 也可以很快被系统管 理员发现, 因此相比较通过密码进行保护的现有技术方式, 本发明实施 方式显著提高了可编程逻辑控制器的安全性。
而且, 当需要对可编程逻辑控制器进行操作时, 只需要将近场通信 识别卡靠近可编程逻辑控制器, 可编程逻辑控制器即可获知使用者的身 份, 并赋予相应的使用权限, 因此使用者无需记忆各种密码, 因此本发 明实施方式还非常便利。
附图简要说明
图 1为一个实施方式中可编程逻辑控制器的结构图。
图 2为一个实施方式可编程逻辑控制器的用户身份识别系统的结构 图。
图 3为一个实施方式中可编程逻辑控制器的用户身份识别方法流程 图。 实施本发明的方式
下面结合具体的实施方式及附图对技术方案进行详细的描述。
在本发明实施方式中, 通过近场通信(NFC )方式实现针对 PLC设 备的身份识别技术。 通过在可编程逻辑控制器设备中嵌入近场通信接收 单元, 以接收来自该可编程逻辑控制器之外的近场通信识别卡中的用户 信息。
可以在各个近场通信识别卡中分别写有相对应级别的用户身份信 信识别卡。
当需要对可编程逻辑控制器进行操作时, 只需要将近场通信识别卡 靠近可编程逻辑控制器, 可编程逻辑控制器即可获知使用者的身份, 并 赋予相应的使用权限。
图 1为一个实施方式中可编程逻辑控制器的结构图。
如图 1所示, 该可编程逻辑控制器 100包括:
近场通信单元 101 , 用于通过近场通信方式从位于该可编程逻辑控 制器 100之外的近场通信卡接收用户身份信息;
用户身份识别单元 102, 用于对接收的用户身份信息进行识别, 并 确定出对应于该用户身份信息的用户操作权限级别;
模式切换单元 103 , 用于基于所确定的用户操作权限级别, 对所述 可编程逻辑控制器 100的工作模式进行切换。
近场通信单元 101可以通过近场通信方式从位于该可编程逻辑控制 器 100之外的近场通信卡接收用户身份信息。 近场通信方式又称近距离 无线通信, 是一种短距离的高频无线通信技术, 允许电子设备之间进行 非接触式点对点数据传输 (比如在 10厘米内 ) 交换数据。
近场通信卡是一种包含有用户身份信息的 IC卡,而且该近场通信卡 还具有近场通信单元, 近场通信单元可以发送 /接收 IC卡所保存的用户 身份信息。
在本发明实施方式下, 近场通信卡具有一个显著的优点, 即能够通 过非接触可编程逻辑控制器 100中近场通信单元 101的 射频信号(RF ) 域为近场通信卡供电, 从而使近场通信卡本身无需带电。
用户身份识别单元 102首先对接收的用户身份信息进行识别, 识别 操作包括确定该用户身份信息是否合法。 用户身份识别单元 102确认该 用户身份信息是否合法之后, 再确定出对应于该用户身份信息的用户操 作权限级别。
本发明实施方式的可编程逻辑控制器 100还可以具有其它常见的单 元, 比如: 电源、 中央处理单元(CPU )、 存储器、 输入输出接口电路、 功能模块等。
可编程逻辑控制器的电源在整个系统中起着十分重要的作用。 如果 没有一个良好的、 可靠的电源系统是无法正常工作的, 电源的一般交流 电压波动在 +10%范围内,可以不采取其它措施而将可编程逻辑控制器直 接连接到交流电网上去。
可编程逻辑控制器的中央处理单元 ( CPU )是可编程逻辑控制器的 控制中枢, 它按照可编程逻辑控制器系统程序赋予的功能接收并存储从 编程器键入的用户程序和数据; 检查电源、 存储器、 I/O 以及警戒定时 器的状态, 并能诊断用户程序中的语法错误。
当可编程逻辑控制器投入运行时,首先 CPU以扫描的方式接收现场 各输入装置的状态和数据, 并分别存入 I/O映象区, 然后从用户程序存 储器中逐条读取用户程序, 经过命令解译后按指令的规定执行逻辑或算 数运算的结果送入 I/O映象区或数据寄存器内。 待所有的用户程序执行 完毕之后, 最后将 I/O映象区的各输出状态或输出寄存器内的数据传送 到相应的输出装置, 如此循环运行, 直到停止运行。
本发明实施方式的可编程逻辑控制器还可以采用双 CPU构成冗余 系统, 或采用三 CPU的表决式系统。 这样, 即使某个 CPU出现故障, 整个系统仍能正常运行。
在一个实施方式中:
该可编程逻辑控制器 100, 进一步包括用于存放系统程序的系统程 序存储器 104;
模式切换单元 103 , 用于将该可编程逻辑控制器的工作模式切换为 下列中的至少一个: 系统程序存储器 104可读不可写; 系统程序存储器 104可写不可读; 系统程序存储器 104既不可读又不可写; 系统程序存 储器 104既可读又可写。
比如, 当用户身份识别单元 102确定出对应于用户身份信息的用户 操作权限级别为普通访客时, 模式切换单元 103可以对可编程逻辑控制 器 100的工作模式进行切换, 使得系统程序存储器 104对该普通访客身 份的用户既不可读且不可写。
再比如, 当用户身份识别单元 102确定出对应于用户身份信息的用 户操作权限级别为普通用户时, 模式切换单元 103可以对可编程逻辑控 制器 100的工作模式进行切换, 使得系统程序存储器 104对该用户可读 而不可写。
再比如, 当用户身份识别单元 102确定出对应于用户身份信息的用 户操作权限级别为高级用户时, 模式切换单元 103可以对可编程逻辑控 制器 100的工作模式进行切换, 使得系统程序存储器 104对该用户既可 读又可写。
在一个实施方式中:
该可编程逻辑控制器 100, 进一步包括用于存放用户程序的用户程 序存储器 105;
模式切换单元 103 , 用于将该可编程逻辑控制器的工作模式切换为 下列中的一个: 用户程序存储器 105可读不可写; 用户程序存储器 105 可写不可读; 用户程序存储器 105既不可读又不可写; 用户程序存储器 105既可读又可写。
比如, 当用户身份识别单元 102确定出对应于用户身份信息的用户 操作权限级别为普通访客时, 模式切换单元 103可以对可编程逻辑控制 器 100的工作模式进行切换, 使得用户程序存储器 105对该普通访客身 份的用户既不可读且不可写。
再比如, 当用户身份识别单元 102确定出对应于用户身份信息的用 户操作权限级别为普通用户时, 模式切换单元 103可以对可编程逻辑控 制器 100的工作模式进行切换, 使得用户程序存储器 105对该用户可读 而不可写。
再比如, 当用户身份识别单元 102确定出对应于用户身份信息的用 户操作权限级别为高级用户时, 模式切换单元 103可以对可编程逻辑控 制器 100的工作模式进行切换, 使得用户程序存储器 105对该用户既可 读又可写。
在一个实施方式中:
该可编程逻辑控制器 100, 进一步包括人机界面 (HMI )单元 106; 模式切换单元 103 , 用于将该可编程逻辑控制器的工作模式切换为 下列中的至少一个: HMI单元 106的屏幕保护密码界面鉴权成功; HMI 单元 106的屏幕保护密码界面鉴权失败; HMI单元 106的开机密码界面 鉴权成功; HMI单元 106的开机密码界面鉴权失败。
比如, 当用户身份识别单元 102确定出对应于用户身份信息的用户 操作权限级别为非法访客时 (比如, 近场通信卡为无效卡), 模式切换 单元 103可以对可编程逻辑控制器 100的工作模式进行切换,使得 HMI 单元 106的屏幕保护密码界面鉴权失败,或 HMI单元 106的开机密码界 面鉴权失败。
再比如, 当用户身份识别单元 102确定出对应于用户身份信息的用 户操作权限级别为合法访客时 (比如, 近场通信卡为有效卡), 模式切 换单元 103 可以对可编程逻辑控制器 100 的工作模式进行切换, 使得 HMI单元 106的屏幕保护密码界面鉴权成功, 或 HMI单元 106的开机 密码界面鉴权成功。
再比如, 当用户身份识别单元 102确定出对应于用户身份信息的用 户操作权限级别为合法访客时(比如, 近场通信卡为有效卡)且具有高 级用户权限时, 模式切换单元 103可以对可编程逻辑控制器 100的工作 模式进行切换,使得 HMI单元 106的屏幕保护密码界面鉴权成功, 而且 HMI单元 106的开机密码界面鉴权成功。
而且, 可编程逻辑控制器 100可以利用与近场通信卡的近场通信连 接, 对近场通信卡中所保存的用户身份信息进行写操作, 比如删除、 重 写或格式化等等。
基于上述详细分析, 本发明实施方式还提出了一种可编程逻辑控制 器的身份识别系统。
图 2为根据本发明实施方式的可编程逻辑控制器的用户身份识别系 统结构图。
如图 2所示,该系统包括可编程逻辑控制器 100和近场通信卡 200, 其巾:
近场通信卡 200, 存储有用户身份信息, 并通过近场通信方式向可 编程逻辑控制器发送用户身份信息;
可编程逻辑控制器 100, 用于通过近场通信方式从近场通信卡接收 用户身份信息; 对接收的用户身份信息进行识别并确定出对应于该用户 身份信息的用户操作权限级别; 并基于所确定的用户操作权限级别, 对 所述可编程逻辑控制器的工作模式进行切换。
可编程逻辑控制器 100具体可以具有如图 1所示的结构。 该可编程 逻辑控制器 100包括: 近场通信单元 101 , 用于通过近场通信方式从位 于该可编程逻辑控制器 100之外的近场通信卡接收用户身份信息; 用户 身份识别单元 102, 用于对接收的用户身份信息进行识别以确定出对应 于该用户身份信息的用户操作权限级别; 模式切换单元 103 , 用于基于 所确定的用户操作权限级别, 对所述可编程逻辑控制器 100的工作模式 进行切换。
在一个实施方式中:
可编程逻辑控制器 100, 进一步包括用于存放系统软件的系统程序 存储器 104。
模式切换单元 103 , 将该可编程逻辑控制器的工作模式切换为下列 中的至少一个: 系统程序存储器 104可读不可写; 系统程序存储器 104 可写不可读; 系统程序存储器 104既不可读又不可写; 系统程序存储器 104既可读又可写。
在一个实施方式中:
可编程逻辑控制器 100, 进一步包括用于存放用户程序的用户程序 存储器 105。
模式切换单元 103 , 将该可编程逻辑控制器的工作模式切换为下列 中的至少一个: 用户程序存储器可读不可写; 用户程序存储器可写不可 读;用户程序存储器既不可读又不可写;用户程序存储器既可读又可写。
在一个实施方式中:
可编程逻辑控制器进一步包括人机界面单元 106。 模式切换单元 103 , 将该可编程逻辑控制器的工作模式切换为下列 中的至少一个: HMI单元的屏幕保护密码界面鉴权成功; HMI单元的屏 幕保护密码界面鉴权失败; HMI 单元的开机密码界面鉴权成功; HMI 单元的开机密码界面鉴权失败。
近场通信卡 200是一种包含有用户身份信息的 IC卡,而且该近场通 信卡 200还具有近场通信单元, 近场通信单元可以发送 /接收 IC卡所保 存的用户身份信息。
基于上述详细分析, 本发明实施方式还提出了一种可编程逻辑控制 器的用户身份识别方法。
图 3为一个实施方式中可编程逻辑控制器的用户身份识别方法流程 图。
如图 3所示, 该方法包括:
步骤 S300: 通过近场通信方式从近场通信卡接收用户身份信息。 步骤 S310: 对接收的用户身份信息进行识别, 并确定出对应于该用 户身份信息的用户操作权限级别。
步骤 S320: 基于所确定的用户操作权限级别, 对所述可编程逻辑控 制器的工作模式进行切换。
在一个实施方式中, 对所述可编程逻辑控制器的工作模式进行切换 包括, 将该可编程逻辑控制器的工作模式切换为下列中的至少一个: 系统程序存储器可读不可写; 系统程序存储器可写不可读; 系统程 序存储器既不可读又不可写; 系统程序存储器既可读又可写; 用户程序 存储器可读不可写; 用户程序存储器可写不可读; 用户程序存储器既不 可读又不可写; 用户程序存储器既可读又可写; HMI单元的屏幕保护密 码界面鉴权成功; HMI单元的屏幕保护密码界面鉴权失败; HMI单元的 开机密码界面鉴权成功; HMI单元的开机密码界面鉴权失败。 综上所述, 在本发明实施方式中, 近场通信单元, 用于通过近场通 信方式从近场通信卡接收用户身份信息; 用户身份识别单元, 用于对接 收的用户身份信息进行识别并确定出对应于该用户身份信息的用户操 作权限级别; 模式切换单元, 用于基于所确定的用户操作权限级别, 对 所述可编程逻辑控制器的工作模式进行切换。
由此可见, 应用本发明实施方式之后, 通过近场通信方式实现针对 可编程逻辑控制器设备的身份识别技术。 不同于密码, 近场通信识别卡 作为物理实体很难被大规模扩散, 而且即使近场通信识别卡丟失, 也可 以很快被系统管理员发现, 因此相比较通过密码进行保护的现有技术方 式, 本发明实施方式显著提高了可编程逻辑控制器的安全性。
而且, 当需要对可编程逻辑控制器进行操作时, 只需要将近场通信 识别卡靠近可编程逻辑控制器, 可编程逻辑控制器即可获知使用者的身 份, 并赋予相应的使用权限, 因此使用者无需记忆各种密码, 因此本发 明实施方式非常便利。 体和详细, 但并不能因此而理解为对本发明专利范围的限制。 应当指出 的是,对于本领域的普通技术人员来说,在不脱离本发明构思的前提下, 还可以做出若干变形和改进, 这些都属于本发明的保护范围。 因此, 本 发明专利的保护范围应以所附权利要求为准。

Claims

权利要求书
1、 一种可编程逻辑控制器, 其特征在于, 包括: 信息;
用户身份识别单元, 用于对接收的用户身份信息进行识别, 并确定 出对应于该用户身份信息的用户操作权限级别;
模式切换单元, 用于基于所确定的用户操作权限级别, 对所述可编 程逻辑控制器的工作模式进行切换。
2、根据权利要求 1所述的可编程逻辑控制器, 其特征在于, 进一步 包括用于存放系统程序的系统程序存储器;
模式切换单元, 用于将该可编程逻辑控制器的工作模式切换为下列 中的一个:
系统程序存储器可读不可写;
系统程序存储器可写不可读;
系统程序存储器既不可读又不可写;
系统程序存储器既可读又可写。
3、根据权利要求 1所述的可编程逻辑控制器, 其特征在于, 进一步 包括用于存放用户程序的用户程序存储器;
模式切换单元, 用于将该可编程逻辑控制器的工作模式切换为下列 中的一个:
用户程序存储器可读不可写;
用户程序存储器可写不可读;
用户程序存储器既不可读又不可写; 用户程序存储器既可读又可写。
4、根据权利要求 1所述的可编程逻辑控制器, 其特征在于, 进一步 包括人机界面 HMI单元;
模式切换单元, 用于将该可编程逻辑控制器的工作模式切换为下列 中的至少一个:
HMI单元的屏幕保护密码界面鉴权成功;
HMI单元的屏幕保护密码界面鉴权失败;
HMI单元的开机密码界面鉴权成功;
HMI单元的开机密码界面鉴权失败。
5、 一种可编程逻辑控制器的用户身份识别系统, 其特征在于, 包括 可编程逻辑控制器和近场通信卡, 其中:
近场通信卡, 存储有用户身份信息, 并通过近场通信方式向可编程 逻辑控制器发送用户身份信息;
可编程逻辑控制器, 用于通过近场通信方式从近场通信卡接收用户 身份信息; 对接收的用户身份信息进行识别并确定出对应于该用户身份 信息的用户操作权限级别; 并基于所确定的用户操作权限级别, 对所述 可编程逻辑控制器的工作模式进行切换。
6、 根据权利要求 5所述的可编程逻辑控制器的用户身份识别系统, 其特征在于,
可编程逻辑控制器, 进一步包括用于存放系统程序的系统程序存储 器; 并将该可编程逻辑控制器的工作模式切换为下列中的至少一个: 系统程序存储器可读不可写; 系统程序存储器可写不可读;
系统程序存储器既不可读又不可写;
系统程序存储器既可读又可写。
7、 根据权利要求 5所述的可编程逻辑控制器的用户身份识别系统, 其特征在于,
可编程逻辑控制器, 进一步包括用于存放用户程序的用户程序存储 器; 并将该可编程逻辑控制器的工作模式切换为下列中的至少一个: 用户程序存储器可读不可写;
用户程序存储器可写不可读;
用户程序存储器既不可读又不可写;
用户程序存储器既可读又可写。
8、 根据权利要求 5所述的可编程逻辑控制器的用户身份识别系统, 其特征在于,
可编程逻辑控制器, 进一步包括人机界面单元; 并将该可编程逻辑 控制器的工作模式切换为下列中的至少一个:
HMI单元的屏幕保护密码界面鉴权成功;
HMI单元的屏幕保护密码界面鉴权失败;
HMI单元的开机密码界面鉴权成功;
HMI单元的开机密码界面鉴权失败。
9、 一种可编程逻辑控制器的用户身份识别方法, 其特征在于, 该方 法包括:
通过近场通信方式从近场通信卡接收用户身份信息; 对接收的用户身份信息进行识别, 并确定出对应于该用户身份信息 的用户操作权限级别;
基于所确定的用户操作权限级别, 对所述可编程逻辑控制器的工作 模式进行切换。
10、根据权利要求 9所述的可编程逻辑控制器的用户身份识别方法, 其特征在于,
所述对所述可编程逻辑控制器的工作模式进行切换包括, 将该可编 程逻辑控制器的工作模式切换为下列中的至少一个:
系统程序存储器可读不可写;
系统程序存储器可写不可读;
系统程序存储器既不可读又不可写;
系统程序存储器既可读又可写;
用户程序存储器可读不可写;
用户程序存储器可写不可读;
用户程序存储器既不可读又不可写;
用户程序存储器既可读又可写;
HMI单元的屏幕保护密码界面鉴权成功;
HMI单元的屏幕保护密码界面鉴权失败;
HMI单元的开机密码界面鉴权成功;
HMI单元的开机密码界面鉴权失败。
PCT/CN2013/080640 2013-08-01 2013-08-01 可编程逻辑控制器及其用户身份识别系统与方法 WO2015013958A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2013/080640 WO2015013958A1 (zh) 2013-08-01 2013-08-01 可编程逻辑控制器及其用户身份识别系统与方法
CN201380076888.0A CN105264933A (zh) 2013-08-01 2013-08-01 可编程逻辑控制器及其用户身份识别系统与方法

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2013/080640 WO2015013958A1 (zh) 2013-08-01 2013-08-01 可编程逻辑控制器及其用户身份识别系统与方法

Publications (1)

Publication Number Publication Date
WO2015013958A1 true WO2015013958A1 (zh) 2015-02-05

Family

ID=52430886

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2013/080640 WO2015013958A1 (zh) 2013-08-01 2013-08-01 可编程逻辑控制器及其用户身份识别系统与方法

Country Status (2)

Country Link
CN (1) CN105264933A (zh)
WO (1) WO2015013958A1 (zh)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101674109A (zh) * 2009-10-19 2010-03-17 宇龙计算机通信科技(深圳)有限公司 一种nfc监控装置、nfc通讯终端及监控系统
CN102156838A (zh) * 2011-04-02 2011-08-17 中兴通讯股份有限公司 一种终端鉴权方法及终端
US8045961B2 (en) * 2009-06-22 2011-10-25 Mourad Ben Ayed Systems for wireless authentication based on bluetooth proximity
CN102316452A (zh) * 2011-07-18 2012-01-11 辽宁国兴科技有限公司 一种基于云端利用nfc通信技术的双重鉴权登录系统
CN102833074A (zh) * 2012-08-31 2012-12-19 珠海市魅族科技有限公司 一种鉴权方法和相关设备

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8045961B2 (en) * 2009-06-22 2011-10-25 Mourad Ben Ayed Systems for wireless authentication based on bluetooth proximity
CN101674109A (zh) * 2009-10-19 2010-03-17 宇龙计算机通信科技(深圳)有限公司 一种nfc监控装置、nfc通讯终端及监控系统
CN102156838A (zh) * 2011-04-02 2011-08-17 中兴通讯股份有限公司 一种终端鉴权方法及终端
CN102316452A (zh) * 2011-07-18 2012-01-11 辽宁国兴科技有限公司 一种基于云端利用nfc通信技术的双重鉴权登录系统
CN102833074A (zh) * 2012-08-31 2012-12-19 珠海市魅族科技有限公司 一种鉴权方法和相关设备

Also Published As

Publication number Publication date
CN105264933A (zh) 2016-01-20

Similar Documents

Publication Publication Date Title
AU2008248013B2 (en) Dynamically programmable RFID transponder
CN104156642B (zh) 一种基于安全触控屏控制芯片的安全密码输入系统和方法
CN101183413B (zh) 可信平台模块tpm的体系系统及其提供服务的方法
EP2367133B1 (en) Method for checking data consistency in a system on chip
CN101373440B (zh) 一种固件升级数据处理方法和装置
JP2012100307A (ja) 通信装置
US20140359312A1 (en) Power on with near field communication
CN103198247A (zh) 一种计算机安全保护方法和系统
CN104778774A (zh) 一种蓝牙手机替代rfid卡的蓝牙一体控制机和控制方法
EP3262586B1 (en) Payment means operation supporting method and electronic device for supporting the same
CN102982265B (zh) 存取基本输入输出系统设定的认证方法
KR101601395B1 (ko) Ic 카드, 전자 장치 및 휴대 가능 전자 장치
CN113031825B (zh) 指纹事件处理装置及方法
CN115454517B (zh) 多介质安全启动的方法、系统、存储介质、设备及芯片
CN104123512A (zh) 实现智能密钥设备模式间切换的方法和装置
WO2015013958A1 (zh) 可编程逻辑控制器及其用户身份识别系统与方法
CN201387612Y (zh) 一种农畜产品流通监管装置
CN100511196C (zh) 数据处理芯片及其存储装置
CN104660419A (zh) 一种基于nfc的计算机安全管理方法
WO2021139703A1 (zh) 支付信息处理方法和装置、可穿戴设备、计算机可读存储介质
CN111758243A (zh) 移动存储设备、存储系统和存储方法
TW201723946A (zh) 一種銷售點終端模式切換方法及裝置
CN108990041B (zh) 一种进行主副卡设置的方法和设备
JP2020173772A (ja) 認証用携帯端末装置及び認証データの自己登録方法
CN214507116U (zh) 一种基于人工智能的网络安全防护系统

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 201380076888.0

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13890315

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13890315

Country of ref document: EP

Kind code of ref document: A1