A wind turbine hardware safety chain system

By directly receiving sensor signals through a hardware security chain system and reducing communication protocol conversions, the problem of susceptibility to interference and accidental shutdown in traditional wind turbine software logic control is solved, achieving efficient and reliable emergency shutdown functions and reducing operation and maintenance costs.

CN120426171BActive Publication Date: 2026-07-24CHINA RESOURCES POWER TECH RES INST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA RESOURCES POWER TECH RES INST CO LTD
Filing Date
2025-05-20
Publication Date
2026-07-24

Smart Images

  • Figure CN120426171B_ABST
    Figure CN120426171B_ABST
Patent Text Reader

Abstract

The application specifically relates to a wind turbine hardware safety chain system, which comprises a safety relay, a main control input module, an emergency stop switch, an overspeed switch, a cable twisting switch, a vibration switch, a variable pitch safety chain switch, a converter safety chain switch, a main control disconnection safety chain relay switch, a control module, a main control output module and a disconnection safety connection relay, wherein the emergency stop switch, the cable twisting switch, the overspeed switch, the vibration switch, the variable pitch safety chain switch, the converter safety chain switch and the main control disconnection safety chain switch are connected in series to the input port of the safety relay, A1 and A2 of the safety relay are connected to the two ends of a power supply, the safety chains are connected to the main control input module, the safety chain state information is collected by the main control input module and fed back to the control module, and the coil of the disconnection safety connection relay is connected to the port of the main control output module, so that the effect of avoiding the interference and false triggering of the software safety chain is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wind turbine technology, and more specifically to a hardware security chain system for wind turbine generator sets. Background Technology

[0002] The safety chain system of a wind turbine generator is a critical protection mechanism, consisting of multiple key components connected in series to form a loop. When a wind turbine generator experiences a fault or abnormal situation such as overspeed, excessive vibration, or triggering of the emergency stop button, the safety chain system will act quickly, causing the generator to execute an emergency shutdown procedure, cut off the power supply, and brake the blades to prevent the fault from escalating further and avoid serious damage to equipment and personnel. This ensures the safety and reliability of the entire wind power generation system under extreme conditions.

[0003] Currently, the safety chain system of traditional wind turbine generators is mostly based on software logic control, which connects various protection nodes of the wind turbine generator in a software logic manner to monitor the operating status of the unit in real time. When any node has a problem, such as overspeed or excessive vibration, the software logic will trigger an emergency shutdown procedure to safely stop the unit from operating.

[0004] However, the safety chain controlled by software logic has a high software dependency. The safety chain logic is implemented through the controller program, which is susceptible to communication delays and program errors, resulting in delays or failures of shutdown commands. The modules communicate through a bus, and the signals are susceptible to electromagnetic interference, which can trigger false shutdowns. The stability of old hardware safety modules is insufficient, and frequent software upgrades are required, which increases operation and maintenance costs. At the same time, false shutdowns lead to a decrease in the unit's power generation efficiency and impose a large fatigue load on the unit.

[0005] Therefore, this invention proposes a hardware security chain system for wind turbine generators that integrates hardware security chains, offering strong compatibility, fast response speed, and excellent anti-interference capabilities. Summary of the Invention

[0006] Based on the aforementioned problems in the existing technology, the purpose of this invention is to provide a hardware safety chain system for wind turbine generator sets that ensures feathering safety and prevents runaway accidents when all three blades are deployed simultaneously.

[0007] To achieve the above objectives, in one aspect, the present invention provides a hardware security chain system for wind turbine generator sets, comprising:

[0008] Safety relays, main control input modules, emergency stop switches, overspeed switches, cable twist switches, vibration switches, pitch safety chain switches, converter safety chain switches, main control disconnect safety chain relay switches, control modules, main control output modules, and disconnect safety connection relays;

[0009] The safety relay is electrically connected to the nacelle reset button and the tower base reset button. One end of the emergency stop switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the emergency stop signal is triggered. One end of the overspeed switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the overspeed signal is triggered. One end of the cable twisting switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the cable twisting signal is triggered. One end of the vibration switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the vibration signal is triggered.

[0010] One end of the pitch safety chain switch is electrically connected to a safety relay, and the other end is electrically connected to the main control input module. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when a fault is triggered in the pitch system. One end of the converter safety chain switch is electrically connected to a safety relay, and the other end is electrically connected to the main control input module. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when a fault occurs in the converter system. One end of the main control disconnect safety chain relay switch is electrically connected to a safety relay, and the other end is electrically connected to the main control input module. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when the main control is disconnected.

[0011] The other end of the main control input module is electrically connected to the control module, and is used to feed back the status of each safety chain node to the control module for interaction. The other end of the control module is electrically connected to the main control output module, and is used to send pulses to the main control output module. The other end of the main control output module is electrically connected to the disconnect safety connection relay, and is used to send pulses to the disconnect safety connection relay through the main control output module to energize the relay, thereby disconnecting the contacts and breaking the safety chain.

[0012] Furthermore, the safety relay directly receives safety chain node signals from sensors or various electrical components, including overspeed, vibration, emergency stop, cable twist, over-limit, pitch system fault, converter fault, and main control disconnection signals.

[0013] Furthermore, the control module integrates the original main control software and the new safety chain software. The new safety chain software interacts with the original main control program and supports direct signal connection between the cabin and the tower base.

[0014] Furthermore, the emergency stop, reset, and converter emergency stop signals between the nacelle and the tower base are directly connected via cables, reducing communication protocol conversion steps.

[0015] Furthermore, the emergency stop switch, overspeed switch, cable twist switch, vibration switch, pitch safety chain switch, converter safety chain switch, tower base emergency stop, and nacelle emergency stop constitute a primary safety chain. The normally open circuit of the safety relay is connected in series with a secondary safety chain, and the control module controls the secondary safety chain.

[0016] Furthermore, the secondary safety chain includes a master control disconnect safety chain relay switch.

[0017] Furthermore, the primary and secondary security chain nodes are connected to the input port of the security relay in series.

[0018] Furthermore, the main control input module has a built-in signal acquisition and feedback module, which is used to acquire the status of the security chain nodes and transmit it to the new security chain software.

[0019] Furthermore, the main control input module feeds back the status of each security chain node to the new security chain software for interaction, enabling fault diagnosis and dynamic configuration.

[0020] Furthermore, the primary security chain and the secondary security chain operate together, and each security chain node is triggered through hardware signal transmission. Triggering any security chain node can achieve an emergency shutdown.

[0021] The beneficial effects of this invention are as follows: The hardware safety chain system for wind turbine generator sets of this invention includes: connecting various levels of safety chains, such as emergency stop switch, cable twisting switch, overspeed switch, vibration switch, pitch safety chain switch, converter safety chain switch, and main control disconnect safety chain switch, in series to the input port of a safety relay. The A1 and A2 terminals of the safety relay are respectively connected to the two ends of the power supply. The various levels of safety chains are connected to the main control input module, and the safety chain status information is collected by the main control input module and fed back to the control module. The coil of the disconnect safety connection relay is connected to the port of the main control output module, thereby achieving the effect of avoiding the software safety chain from being accidentally triggered by interference. Attached Figure Description

[0022] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0023] In the picture:

[0024] Figure 1 This is a schematic diagram of the overall structure of a hardware security chain system for a wind turbine generator set according to the present invention.

[0025] Figure 2 This is a schematic diagram of the overall structure of the existing technology.

[0026] The component names and their numbers in the diagram are as follows:

[0027] Disconnect safety connection relay 1, main control output module 2, control module 3, main control input module 4, emergency stop switch 5, overspeed switch 6, cable twist switch 7, vibration switch 8, pitch safety chain switch 9, converter safety chain switch 10, main control disconnect safety chain relay switch 11, safety relay 12, nacelle reset button 13, tower base reset button 14, original main control software 15, original safety chain software 16, safety chain module 17, original disconnect safety chain relay 18. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] The following details the implementation of the wind turbine generator hardware security chain system in this embodiment. The following content is for ease of understanding and is not essential for implementing this solution. The specific process of this embodiment is as follows: Figure 1 As shown.

[0030] See Figure 2 In the existing technology, the original main control software 15 interacts with the original safety chain software 16 to transmit information, and the original safety chain software 16 interacts with the safety chain module 17. The original disconnect safety chain relay 18 is connected to the safety chain module 17. The existing software safety chain system also includes an emergency stop switch 5, an overspeed switch 6, a cable twist switch 7, a vibration switch 8, a pitch safety chain switch 9, and a converter safety chain switch 10. One end of the above switches is connected to the safety chain module 17, and the other end is connected to a 24V power supply.

[0031] The original software-based safety chain system collects information from each safety chain node through the original safety chain software 16. Modules communicate with each other via bus to collect tower base emergency stop, tower base reset, and converter emergency stop signals from the tower base cabinet and transmit them to the nacelle cabinet. The original safety chain software 16 directly processes the information from each safety chain node before interacting with the original main control software 15. Furthermore, the software-based safety chain system uses multiple communication protocol conversions, resulting in lower reliability and the safety chain faults being falsely triggered due to the sensitive protection logic of the safety control mode itself.

[0032] Traditional wind turbine safety chain systems rely on software logic control, which has several key drawbacks: high software dependency (the safety chain logic is implemented through the controller program, making it susceptible to communication delays and program errors, leading to delayed or invalid shutdown commands); frequent false triggers (communication between modules via a bus makes signals vulnerable to electromagnetic interference, triggering false shutdowns); and complex maintenance (outdated hardware safety modules lack stability and require frequent software upgrades, increasing maintenance costs; false shutdowns also reduce generator efficiency and impose significant fatigue loads on the turbine).

[0033] See Figure 1 The present invention provides a hardware safety chain system for wind turbine generator sets, including: a safety relay 12, a main control input module 4, an emergency stop switch 5, an overspeed switch 6, a cable twist switch 7, a vibration switch 8, a pitch safety chain switch 9, a converter safety chain switch 10, a main control disconnect safety chain relay switch 11, a control module 3, a main control output module 2, and a disconnect safety connection relay 1;

[0034] Safety relay 12 is powered on and connected to nacelle reset button 13 and tower base reset button 14. One end of emergency stop switch 5 is electrically connected to safety relay 12 and the other end is electrically connected to main control input module 4. It is used to realize the emergency shutdown of the unit when the emergency stop signal is triggered. One end of overspeed switch 6 is electrically connected to safety relay 12 and the other end is electrically connected to main control input module 4. It is used to realize the emergency shutdown of the unit when the overspeed signal is triggered. One end of cable twisting switch 7 is electrically connected to safety relay 12 and the other end is electrically connected to main control input module 4. It is used to realize the emergency shutdown of the unit when the cable twisting signal is triggered. One end of vibration switch 8 is electrically connected to safety relay 12 and the other end is electrically connected to main control input module 4. It is used to realize the emergency shutdown of the unit when the vibration signal is triggered.

[0035] One end of the pitch safety chain switch 9 is electrically connected to the safety relay 12, and the other end is electrically connected to the main control input module 4. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when a fault is triggered in the pitch system. One end of the converter safety chain switch 10 is electrically connected to the safety relay 12, and the other end is electrically connected to the main control input module 4. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when a fault occurs in the converter system. One end of the main control disconnect safety chain relay switch 11 is electrically connected to the safety relay 12, and the other end is electrically connected to the main control input module 4. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when the main control is disconnected.

[0036] The safety chains involved in this invention are: tower base emergency stop, nacelle emergency stop, converter emergency stop, impeller overspeed, cable torsion over-limit, vibration over-frequency, pitch safety chain, and yaw safety chain. The above safety chains are presented in the system in the form of switches, and each node in the safety chain is connected in series to the input port of the safety relay 12. The tower base reset button 14 and the nacelle reset button 13 are connected to the reset circuit of the safety relay 12. At the same time, all safety chain hardware nodes are led out and input to the main control input module 4.

[0037] By constructing a pure hardware safety chain using safety relay 12, main control output module 2, and main control input module 4, a direct connection to sensors or actuators is achieved, eliminating software dependency. The safety relay 12 directly receives safety chain node signals from sensors or various electrical components, thus achieving the effect of hardware signal reception and transmission.

[0038] The other end of the main control input module 4 is electrically connected to the control module 3, and is used to feed back the status of each safety chain node to the control module 3 for interaction. The other end of the control module 3 is electrically connected to the main control output module 2, and is used to send pulses to the main control output module 2. The other end of the main control output module 2 is electrically connected to the disconnect safety connection relay 1, and is used to send pulses to the disconnect safety connection relay 1 through the main control output module 2 to energize the relay, thereby disconnecting the contacts and disconnecting the safety chain.

[0039] Safety relay 12 directly receives safety chain node signals from sensors or various electrical components, including overspeed, vibration, emergency stop, cable twist, over-limit, pitch system fault, converter fault and main control disconnection signals. A1 and A2 of safety relay 12 are respectively connected to the two ends of the power supply.

[0040] The control module 3 integrates the original main control software 15 and the new safety chain software. The new safety chain software interacts with the original main control program and supports direct signal connection between the cabin and the tower. The interaction between the new safety chain software and the original main control software 15 is consistent, and the hardware safety chain nodes are interlocked with the original software safety chain logic to ensure seamless compatibility between shutdown commands and the original main control program.

[0041] By interacting with the original main control program through a data interface, the new security chain software system enables security chain status monitoring and logic configuration without modifying the original unit monitoring system, thus improving anti-interference capabilities. Due to the reduced hardware module maintenance costs and compatibility with the retrofitting of older units, there is no need to replace the main control system, achieving the goal of saving resources.

[0042] Emergency stop, reset, and converter emergency stop signals between the nacelle and the tower base are directly connected via cables, reducing communication protocol conversion steps. This direct cable connection forms a direct communication structure, in which the terminals of the tower base cabinet and the nacelle cabinet are connected one-to-one via shielded cables. The transmitted signals include tower base emergency stop, reset, converter emergency stop, and safety chain feedback signals.

[0043] Emergency stop switch 5, overspeed switch 6, cable twist switch 7, vibration switch 8, pitch safety chain switch 9, converter safety chain switch 10, tower base emergency stop and nacelle emergency stop together form a primary safety chain. The normally open circuit of safety relay 12 is connected in series with a secondary safety chain. Control module 3 controls the secondary safety chain.

[0044] The secondary safety chain includes the main control disconnecting the safety chain relay switch 11 and other fault conditions of the wind turbine.

[0045] The primary and secondary safety chain nodes are connected in series to the input port of the safety relay 12. The primary and secondary safety chains operate together, and each safety chain node is triggered by hardware signal transmission. Triggering any safety chain node can achieve an emergency stop. When any node in the safety chain is triggered, the safety relay 12 is activated, and the pitch system, converter system, and yaw system are stopped in an emergency through the contacts. When the safety chain is broken and needs to be reset, the safety chain is reset by connecting the reset button to the reset port of the safety relay 12.

[0046] The main control input module 4 has a built-in signal acquisition and feedback module, which is used to collect the status of safety chain nodes and transmit them to the new safety chain software. The main control input module 4 feeds back the status of each safety chain node to the new safety chain software for interaction, realizing fault diagnosis and dynamic configuration. The new safety chain software interacts seamlessly with the original main control software 15, ensuring that the transformation process does not affect the original functions of the unit.

[0047] When any node in the safety chain is triggered, the safety relay 12 activates, performing an emergency shutdown of the pitch system, converter system, and yaw system via contacts. When all nodes recover, the safety chain is reset via the safety chain reset button. The original main control software 15 can actively disconnect the safety chain via the main control disconnect safety chain relay switch 11.

[0048] The new safety chain software collects signals from each node through the main control input module 4 and communicates with the original main control software 15 internally. In the safety chain reset phase, the wind turbine determines the status of the unit based on the output of the safety relay 12 and gives a control strategy based on this status. In the safety relay 12, the safety relay 12 can only issue a normal output signal after all safety chain nodes have been reset and the safety relay 12 detects that its own input signal is normal.

[0049] The wind turbine generator hardware safety chain system includes a manual reset circuit, which resets the safety chain through physical reset buttons on the tower base and nacelle. The reset operation requires all safety nodes to return to normal status simultaneously, and a reset command is sent by the new safety chain software.

[0050] This invention connects various safety chains, including emergency stop switch 5, cable twist switch 7, overspeed switch 6, vibration switch 8, pitch safety chain switch 9, converter safety chain switch 10, and main control disconnect safety chain switch, in series to the input port of safety relay 12. Safety relay 12's A1 and A2 are connected to the two ends of the power supply, respectively. Each safety chain is connected to the main control input module 4, and the main control input module 4 collects safety chain status information and feeds it back to the control module 3. The coil of the disconnect safety connection relay 1 is connected to the port of the main control output module 2, thus preventing the software safety chain from being accidentally triggered by interference.

[0051] The above descriptions are merely embodiments of the present invention. Commonly known structures and characteristics are not described in detail here. Those skilled in the art are aware of all common technical knowledge in the field prior to the application date or priority date, are aware of all existing technologies in that field, and have the ability to apply conventional experimental methods prior to that date. Those skilled in the art can, based on the guidance provided in this application, improve and implement this solution in combination with their own capabilities. Some typical known structures or methods should not be obstacles for those skilled in the art to implement this application. It should be noted that those skilled in the art can make several modifications and improvements without departing from the structure of the present invention. These should also be considered within the scope of protection of the present invention, and will not affect the effectiveness of the implementation of the present invention or the practicality of the patent. The scope of protection claimed in this application should be determined by the content of its claims, and the specific embodiments described in the specification can be used to interpret the content of the claims.

[0052] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A hardware security chain system for wind turbine generator sets, characterized in that, include: Safety relays, main control input modules, emergency stop switches, overspeed switches, cable twist switches, vibration switches, pitch safety chain switches, converter safety chain switches, main control disconnect safety chain relay switches, control modules, main control output modules, and disconnect safety connection relays; The control module integrates the original main control software and the new safety chain software. The new safety chain software interacts with the original main control program and supports direct signal connection between the cabin and the tower base. The emergency stop switch, overspeed switch, cable twist switch, vibration switch, pitch safety chain switch, converter safety chain switch, tower base emergency stop, and nacelle emergency stop constitute the primary safety chain. The normally open circuit of the safety relay is connected in series with the secondary safety chain. The control module controls the secondary safety chain. The secondary safety chain includes the main control disconnect safety chain relay switch. The primary and secondary safety chains operate together. The triggering of each safety chain node is transmitted through hardware signals. The triggering of any safety chain node can realize emergency shutdown. The safety relay is electrically connected to the nacelle reset button and the tower base reset button. One end of the emergency stop switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the emergency stop signal is triggered. One end of the overspeed switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the overspeed signal is triggered. One end of the cable twisting switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the cable twisting signal is triggered. One end of the vibration switch is electrically connected to the safety relay, and the other end is electrically connected to the main control input module. It is used to realize the emergency shutdown of the unit when the vibration signal is triggered. One end of the pitch safety chain switch is electrically connected to a safety relay, and the other end is electrically connected to the main control input module. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when a fault is triggered in the pitch system. One end of the converter safety chain switch is electrically connected to a safety relay, and the other end is electrically connected to the main control input module. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when a fault occurs in the converter system. One end of the main control disconnect safety chain relay switch is electrically connected to a safety relay, and the other end is electrically connected to the main control input module. It is used to actively disconnect the safety chain to cause an emergency shutdown of the unit when the main control is disconnected. The other end of the main control input module is electrically connected to the control module, and is used to feed back the status of each safety chain node to the control module for interaction. The other end of the control module is electrically connected to the main control output module, and is used to send pulses to the main control output module. The other end of the main control output module is electrically connected to the disconnect safety connection relay, and is used to send pulses to the disconnect safety connection relay through the main control output module to energize the relay, thereby disconnecting the contacts and breaking the safety chain.

2. The wind turbine generator hardware security chain system according to claim 1, characterized in that, The safety relay directly receives safety chain node signals from sensors or various electrical components, including overspeed, vibration, emergency stop, cable twist, over-limit, pitch system fault, converter fault, and main control disconnection signals.

3. The wind turbine generator hardware security chain system according to claim 1, characterized in that, The emergency stop, reset, and converter emergency stop signals between the nacelle and the tower base are directly connected by cables, reducing communication protocol conversion steps.

4. The wind turbine generator hardware security chain system according to claim 1, characterized in that, The primary and secondary security chain nodes are connected in series to the input port of the security relay.

5. The wind turbine generator hardware security chain system according to claim 2, characterized in that, The main control input module has a built-in signal acquisition and feedback module, which is used to acquire the status of the security chain nodes and transmit it to the new security chain software.

6. The wind turbine generator hardware security chain system according to claim 1, characterized in that, The main control input module feeds back the status of each security chain node to the new security chain software for interaction, enabling fault diagnosis and dynamic configuration.

Citation Information

Patent Citations

  • Safety chain system of wind generating set and fault rapid identification method thereof

    CN102748215A

  • Safety chain control system suitable for wind generating set

    CN204344372U