introduction to control engineering at power plantsalkar/sec510/introduction... · server vpn...

39
Unrestricted / © Siemens 2019. All rights reserved Introduction to Control Engineering at Power Plants Lesson 2

Upload: others

Post on 07-May-2020

10 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

Introduction to

Control Engineering

at Power Plants

Lesson 2

Page 2: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Architecture

Page 2

User Interfaces

Server

Process Interfaces

Thin Clients

I/O Devices

Application Server

Automation Server

Page 3: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Configuration

Page 3

Application Highway

Automation Highway

Thin Clients

Application Server

Automation Server

I/O systems and Intelligent field devices

CommunicationServer

Time Server

Security Server

Terminal Server

Intranet / Internet

Automation Server

Page 4: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Features

Page 4

Reliable

Easy to use

Cyber secure

Scalable

Platform for more

Page 5: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Features - Reliable

Page 5

Application Highway

Automation Highway

Thin Clients

Application Server

Automation Server

I/O systems and Intelligent field devices

CommunicationServer

Time Server

Security Server

Terminal Server

Intranet / Internet

Automation Server

Process Interfaces

I/O system with redundant

interface module and I/O modules

Networks

Fault tolerant Ethernet NetworkRedundant PROFIBUS DP and PROFINET field bus

User Interfaces

Multiple Thin Clients, parallel operation

Servers

Redundant Application Server

Redundant Automation Servers

Page 6: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Features - Easy to use

Page 6

All tasks available in the same window

All information is available at a glance

Quick and easy navigation between all views

Diagnostic View

Project ViewOperation

Trends

Reports

Engineering

All data and information available from a single source

Page 7: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Features – Cyber secure

Page 7

Configuration Change Monitoring –

detects security gaps and provides

transparency

Security Event Monitoring –

comprehensive information about

the security status

Application Whitelisting –

protection of secure plant operation

+

+

Malware Protection – protects

Windows-based computers against

malware

+

Siemens Remote Services

Firewall

PublicNetwork

Firewall

VPNRouter Terminal-

Server

VPNTunnel

IT OfficeInfrast.

ServiceInfrast.

DMZ

IntranetInternet

Customer Office Network

Application Highway

Automation Highway

Thin Clients

Application-Server

Automation-Server

Security Server

SPPA-T3000

Secure Remote Access –

separated by two firewalls

Hardening – enhanced system

protection for components

Account Management –

enforcement of password policy

Security Patch Management –

maintain the highest security level

Network Intrusion Detection

System (NIDS) – identification and

localization of potential attackers

+

+

+

+

+

+

Page 8: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Features – Scalable

Page 8

red

un

dan

t

no

n-r

ed

un

da

nt

Redundant

Application

Server

Thin Client:

up to 35

Automation

Server: up to 60

I/O Signals: max.

40.000

Non-redundant

Application

Server

Thin Client: 5

Automation Server:

up to 3

I/O-Signals: 5.000

local compact

Application Server

Thin Client:

1 integrated + 4 ext.

Automation Server:

up to 4

I/O-Signals:

max. 4.000

Compact Automation and

Application Server

Thin Client:

1 integrated + 1 ext.

Automation Server:

1 integr.

I/O-Signals:

max. 800

AS3000

lcApS3000

cAApS3000

Page 9: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Features – Platform for more

Data Sources

DCS in the

Power Plant

Data &

Security

Gateway

Firewall

Application

Servers

Terminal Server VPN

Router

Data

Agent

Digitalization

Analytics Platform

Data

Management

Data

Analytics

Result

Data Base

Analytics

Data Center (in

the cloud)

Automatic

Transfer

Manual

Upload

Raw Data

Lake

Benefits

Availability increase

Profitability

optimization

Compliance assurance

Results

visualization

Customer Portal

Digitalization with

secure transfer of

all relevant data

Page 10: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Workbench

Page 10

Page 11: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Servers and Clients

Page 11

Non - Redundant

Application Server

Local compact Application Server

+ Automation Server

(integrated Thin Client,

Terminal Server and Time

Server)

Compact Automation,

Application and Terminal Server

(integrated Thin Client,

Terminal Server and

Automation Server)Thin Clientand Monitors

Page 13: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)I/O Racks

Page 13

Mounting Rail

Bus

Adapter

Interface

Module

Carrier

module for IM

Plug-in connector

for Power supply

Carrier module

for I/O module

(behind I/O and

Terminal Block)

Server module

I/O module

Terminal Blocks

Powerbus cover

I/O Rack

Page 14: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Switches and Routers

Page 14

100 Mbit/s network switches

1 Gbit/s network switches

Media modules

Multi unit routers

Service router

Page 15: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Multi unit configuration

Page 15

unit 2 unit 10unit 1

Mulit Unit Routers

Uniform HMI over the units

....

Page 16: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

6 – Distributed Control Systems (DCS)Configuration with 3rd party communication interfaces

Page 16

Application Highway

Automation Highway

Thin Clients

Application Server

Automation Server

I/O systems and Intelligent field devicesGE GSM

DNP 3.0

TCP / serial

IEC

60870-5-101/104

IEC 61850

Modbus

TCP / serial

OPC Connect

SPPA-T2000

TELEPERM ME

CS275

S7

PCS7

Allen

Bradley

3rd party

S5 / S7

OPC

CommunicationServer

Time Server

Security Server

Terminal Server

Intranet / Internet

Black Box

S7

Automation Server

Page 17: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureFrame (Overview)

Page 17

Automation servers

Power supplies

Fuses (Circuit breakers)

Distribution terminals

Relays and others

I/O modules

I/O modules

Marshalling terminals

(For field cables)

Page 18: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureFrame (Screen connection)

Page 18

Page 19: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureFrame (Seismic design)

Page 19

Page 20: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureEnclosure (Overview)

Page 20

Page 21: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureEnclosure (Ingress Protection)

Page 21

Page 22: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureEnclosure (Cooling, heating and other peripherals)

Page 22

1- Fan&filter (cooling)

2- Air conditioning (cooling)

3-Convection heater

4-Fan heater

5-Thermostat

1

2

3 4

5

Page 23: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructurePower supply (24VDC & 230VAC)

Page 23

Page 24: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructurePower supply (24VDC & 230VAC)

Page 24

Diode Module (Redundancy Module)24VDC Power SupplyCircuit Breaker

Infeed Terminals

Distribution

Terminals

Page 25: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureCabinet monitoring

Page 25

Circuit Breaker Thermostat (left) & Hygrostat (right)

Door Limit Switch Cabinet Fault Indicator Emergency Stop Button

Page 26: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureI/O rack & Modules

Page 26

Page 27: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet Structure

I/O field interfaces (Terminals)

Page 27

Terminals Support Plate

Page 28: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureAutomation servers (S7-400 Series)

Page 28

1- Backplane rack

2- Power supply

3- Synchronization Modules

4- Fiber optic cables (for item-3)

5- CPU

6- Memory card

7- Communication processor

1

2 2

3 3

3 3

5 5 77

6 6

Page 29: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureAutomation servers (AS3000 & CS3000)

Page 29

1- Backplane rack

2- Power supply connectors

3- CPU

4- Communicaton processor (PB)

5- LAN connectors

1

2

2

3 3 4 4

5

5

AS3000: Automation server

CS3000: Communication server for 3rd party communication

Both of them has similar structure as shown above.

Page 30: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureNetwork components (Ethernet)

Page 30

Page 31: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureNetwork components (Ethernet)

Page 31

Page 32: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureNetwork components (Profibus)

Page 32

Page 33: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

7 - Cabinet StructureColor code and labeling

Page 33

Page 34: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

8 - Cabinet TypesServer & LAN

Page 34

Page 35: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

8 - Cabinet TypesI/O Cabinet

Page 35

Page 36: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

8 - Cabinet TypesRelay & Interface

Page 36

Page 37: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

8 - Cabinet TypesControl desk (Obsolete system)

Page 37

Page 38: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

8 - Cabinet TypesJunction box

Page 38

Page 39: Introduction to Control Engineering at Power Plantsalkar/SEC510/Introduction... · Server VPN Tunnel IT Office Infrast. Service Infrast. DMZ Internet Intranet Customer Office Network

Unrestricted / © Siemens 2019. All rights reserved

Page 39

Thank you