Intelligent substation safety measure verification and operation and maintenance management and control method and system

By using a cloud-edge-device collaborative architecture and augmented reality technology, the problems of difficult real-time perception of configuration status, lack of verification of security measures, data isolation, and lack of operation closed loop in smart substations have been solved, achieving efficient and secure operation and maintenance management.

CN121689501APending Publication Date: 2026-03-17GUANGZHOU BUREAU CSG EHV POWER TRANSMISSION
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511888158.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-15
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing technologies in smart substations suffer from problems such as difficulty in real-time perception and verification of configuration status, lack of prior simulation and collaborative verification of safety measures, isolated data value, unintuitive interaction, and lack of operational closed loop, resulting in low operation and maintenance efficiency and safety hazards.

Method used

Adopting a cloud-edge-device collaborative architecture, it provides intuitive on-site operation guidance and intelligent closed-loop feedback by combining edge intelligent preprocessing, digital twin simulation and lightweight AI real-time verification with augmented reality technology, thus building a full-process operation and maintenance management system.

Benefits of technology

It enables precise global perception and collaborative decision-making regarding operational status, improving operational efficiency and reliability, reducing the risk of misoperation, and enhancing the reliability and accuracy of security measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121689501A_ABST
    Figure CN121689501A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent substation safety measure verification and operation and maintenance management and control method and system and a storage medium, and relates to operation and maintenance automation and intelligentization of an intelligent substation. According to the invention, a cloud-edge-end collaborative architecture is constructed; edge equipment is responsible for collecting data and carrying out local intelligent preprocessing; the cloud constructs and dynamically updates a high-fidelity digital twinborn model based on the processed data, performs simulation verification on security measures, and performs real-time auxiliary verification on an edge side by using a lightweight AI model to form dual security verification; finally, the verified instruction is converted into virtual-real superposition operation guidance synchronized with the digital twinning in real time through the mobile AR terminal, and field operation is visually guided. According to the scheme, the fundamental transformation of an operation and maintenance mode from artificial experience driving to data intelligent driving is realized, the decision-making efficiency is optimized through cooperative processing, a safety defense line is constructed by utilizing dual verification, the misoperation risk is remarkably reduced by virtue of AR visual guidance, and a complete intelligent operation and maintenance closed loop is formed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of operation and maintenance automation and intelligentization of smart substations, and particularly relates to a method and system for verifying and operating and maintaining safety measures of a smart substation based on digital twinning and augmented reality. BACKGROUND

[0002] With the rapid construction of smart substations, the power secondary system based on the IEC 61850 standard has realized high networkization and digitization, but the traditional "virtual loop" technology has also made the logical connection relationship between devices "invisible", bringing new challenges to operation and maintenance safety and efficiency. At present, the operation and maintenance management mode in this field mainly has the following key problems to be solved: (1) The configuration state is difficult to perceive and check in real time. Existing tools mainly focus on static checking before the configuration file is downloaded, and cannot perform online and real-time checking on the configuration file of the device in operation. The correctness, completeness and uniqueness of the configuration file depend on manual guarantee, and there is a lack of ability to continuously perceive and verify the running state from the system level, which poses a safety hazard.

[0003] (2) Safety measures lack pre-simulation and collaborative verification. The operation work highly depends on typical safety measure templates and personnel experience, and lacks pre-simulation and feasibility verification of the safety measures to be executed. The logical correctness of the measures, the rationality of the execution sequence and the potential impact on the system cannot be preformed and double-checked in a virtual environment, and the high risk of misoperation caused by manual judgment.

[0004] (3) Data value is isolated, and intelligent analysis capability is insufficient. The station operation and maintenance data is scattered in each independent system, forming a "data island", and lacks unified data governance and deep mining. At the same time, the operation and maintenance management generally lacks effective embedding of intelligent analysis means such as artificial intelligence, and it is difficult to realize predictive early warning and decision optimization of faults, and the operation and maintenance mode is passive.

[0005] (4) The on-site human-computer interaction is not intuitive and low in efficiency. The on-site operation relies on two-dimensional drawings, screen lists and traditional keys, the information presentation is not intuitive, the operation personnel need to compare repeatedly, and immersive and augmented reality intuitive operation guidance cannot be obtained, resulting in low operation efficiency and high probability of misoperation.

[0006] (5) The operation execution process lacks precise closed-loop feedback. The existing technology for verifying the operation result often stops at simple state signal confirmation, lacks precise and intelligent comparison and feedback on the operation process itself (such as action trajectory and sequence), and cannot form a complete operation closed loop that can be traced and audited, which is not conducive to strict execution of safety regulations and experience accumulation.

[0007] In summary, existing technologies have not yet systematically solved the aforementioned problems. Therefore, there is an urgent need in this field for an intelligent operation and maintenance management method and system that can deeply integrate cloud-edge collaborative computing, digital twin simulation, artificial intelligence analysis, and augmented reality interaction, in order to achieve end-to-end innovation from data perception, intelligent decision-making, intuitive interaction to closed-loop verification. Summary of the Invention

[0008] To address the problems existing in current technologies, the main objective of this invention is to provide a method and system for verifying and managing safety measures in smart substations based on digital twins and augmented reality. This aims to solve problems such as difficulty in perceiving configuration status, lack of verification of safety measures, isolated data value, unintuitive interaction, and missing operational loops in the operation and maintenance of smart substations. By constructing a "cloud-edge-device" collaborative architecture, integrating edge intelligent preprocessing, digital twin simulation, and lightweight AI real-time verification, dual security verification and intelligent decision-making are formed. Furthermore, leveraging AR technology synchronized in real-time with the digital twin, intuitive on-site operation guidance and intelligent closed-loop feedback are provided. This constructs a complete operation and maintenance management system from intelligent early warning, simulation verification, intuitive interaction to closed-loop feedback, comprehensively improving the safety, accuracy, and efficiency of operation and maintenance tasks.

[0009] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a method for verifying and managing the safety measures of intelligent substations, characterized by comprising the following steps: S1. Real-time acquisition of operating data of the power secondary system through edge devices deployed in smart substations; and local preprocessing and real-time verification of the operating data to generate preprocessed data; S2. The preprocessed data is uploaded to the cloud management center via the cloud-edge collaboration protocol, and a digital twin model corresponding to the smart substation containing the power secondary system is constructed and maintained in the cloud management center; wherein, the digital twin model is dynamically updated based on the preprocessed data and historical operation and maintenance data, and is kept in data synchronization with the edge device through the cloud-edge collaboration protocol; S3. In the cloud-based control center, the proposed security measures are simulated and verified based on the digital twin model, and verified security measure instructions are generated. At the same time, the edge device performs real-time auxiliary verification of the security measures based on a locally deployed lightweight AI model, and compares the auxiliary verification results with the cloud-based simulation verification results. S4. The verified security measure instructions are sent to the mobile interactive terminal through the cloud-edge collaboration protocol; the mobile interactive terminal uses an augmented reality (AR) interface and real-time environmental data obtained from the edge device to overlay virtual operation guidance information onto the real physical device to guide on-site operation and maintenance; wherein, the AR interface is synchronized with the digital twin model in real time.

[0010] Optionally, step S3 in the above method includes: if the deviation between the auxiliary verification result and the cloud simulation verification result exceeds a preset threshold, then a fusion decision process is triggered; the fusion decision process includes: The cloud-based control center performs hotspot re-simulation based on real-time data snapshots uploaded by the edge devices; Search historical databases for cases similar to the current scenario and perform matching analysis; Based on the combined results of the hotspot resimulation and case matching analysis, recommended decisions with confidence scores are generated and issued.

[0011] Optionally, in the above method, step S3 includes: a lightweight AI model deployed on an edge device acquires safety measure instructions and operational data collected in real time from the power secondary system, calculates and outputs an assessment result characterizing the operational risk level as the auxiliary verification result; wherein, The lightweight AI model is a TCN model or a GRU model, and is constructed in the following way: In the cloud, the risk discrimination knowledge in the pre-trained complex teacher model is transferred to the lightweight TCN or GRU student model framework; then, the student model is subjected to quantitative perception training, its weight parameters are converted from floating-point precision to fixed-point integer precision, and structured pruning is performed simultaneously to remove redundant neural connections, forming a preliminary compressed TCN or GRU model that can be deployed on edge devices. The pre-compressed TCN model or GRU model is trained using a specially constructed training dataset. The dataset consists of historical safety measure operation tickets and pairs of changes in key state variables in the power secondary system before and after the execution of each historical safety measure operation ticket. This dataset is used to enable the model to learn the mapping relationship between safety measures and system state disturbances.

[0012] Optionally, in step S4, the real-time environmental data acquired by the mobile interactive terminal includes visual identifiers and spatial positioning data of on-site equipment obtained by scanning with the terminal camera. The real-time synchronization of the AR interface and the digital twin model includes: the mobile interactive terminal uploading the visual identifier and the spatial positioning data; the edge device or the cloud control center matching the corresponding device 3D model and status information from the digital twin model accordingly, and sending the posture adjustment matrix of the device 3D model to the mobile interactive terminal; the mobile interactive terminal combining the local SLAM positioning information and the posture adjustment matrix to render and generate virtual operation guidance superimposed on the real device.

[0013] Optionally, the above method further includes step S5: During the operation performed by maintenance personnel, the mobile interactive terminal collects the trajectory of the operation actions through sensors; The operation trajectory is transmitted back to the edge device and compared with the pre-stored standard compliant operation trajectory model using the Dynamic Time Warping (DTW) algorithm to generate trajectory similarity. If the trajectory similarity exceeds a preset threshold and the operation target state meets the security measure instructions, the operation verification is determined to be successful, and the verification result is synchronously updated to the digital twin model.

[0014] Optionally, step S1 in the above method includes: The operational data includes device configuration files, network communication status, and physical connection status. Perform a syntax and semantic consistency check on the device configuration file; Based on preset physical connection rules, the collected physical connection status is logically verified; The verified running data is encapsulated into standardized data packets, and a timestamp and device identifier are added to each standardized data packet.

[0015] Optionally, in the above method, the cloud-edge collaboration protocol in step S2 adopts an application layer protocol based on MQTT or HTTP / 2. The cloud-edge collaboration protocol includes: Uplink synchronization mechanism: The edge device synchronizes the preprocessed data and device status heartbeat to the cloud management center at a fixed period or by an event-triggered method; Downlink command and model synchronization mechanism: The cloud control center sends the verified security measure command and the incremental update data packet of the digital twin model to the edge device.

[0016] Optionally, in the above method, the wireless communication link between the edge device and the mobile interactive terminal is established based on the Wireless Local Area Network Authentication and Security Infrastructure (WAPI). The WAPI adopts a three-element peer-to-peer authentication mechanism, requiring both the edge device and the mobile interactive terminal to hold digital certificates issued by a legitimate authentication server to complete two-way identity authentication. After authentication, the transmitted real-time environmental data, the operation trajectory, and the security measure instructions are encrypted using the national cryptographic algorithm SM4.

[0017] In a second aspect, the present invention provides a smart substation safety measure verification and operation and maintenance management system, characterized in that it includes: edge devices, a cloud management and control center, and a mobile interactive terminal; The edge device is configured to collect real-time operating data of the power secondary system, and perform local preprocessing and real-time verification of the operating data to generate preprocessed data; The cloud-based control center, which communicates with the edge devices via a cloud-edge collaboration protocol, is configured to: receive the preprocessed data, and construct and dynamically maintain a digital twin model corresponding to the power secondary system; wherein the digital twin model is used to dynamically update based on the preprocessed data and historical operation and maintenance data, and to maintain data synchronization with the edge devices through the cloud-edge collaboration protocol; The cloud-based control center is configured to simulate and verify the security measures to be implemented based on the digital twin model, and generate verified security measure instructions; the edge device is configured to perform real-time auxiliary verification of the security measures based on a locally deployed lightweight AI model, and compare the auxiliary verification results with the cloud-based simulation verification results. The mobile interactive terminal, which is communicatively connected to the edge device and the cloud control center, is configured to: receive the security measure instructions, and overlay virtual operation guidance information onto the real physical device through an augmented reality (AR) interface, combined with real-time environmental data obtained from the edge device, to guide on-site operation and maintenance; wherein the AR interface is synchronized in real time with the digital twin model.

[0018] Optionally, the edge device in the above system includes: a data acquisition module, a local processing unit, an edge intelligent verification module, an operation verification module, and a first communication module; The data acquisition module is used to collect device configuration files, network communication status, and physical connection status. The local processing unit is used to perform syntax and semantic consistency checks and logical checks based on physical connection rules on the collected running data, and encapsulate the checked data into a standardized data packet with timestamp and device identifier to generate the preprocessed data. The edge intelligent verification module integrates a lightweight AI model, which is used to calculate the received safety measure instructions and real-time operation data, and output an assessment result representing the level of operational risk. The lightweight AI model is a TCN or GRU model transformed from a complex teacher model through knowledge distillation, quantitative perception training and structured pruning, and is trained using a paired dataset consisting of historical operation tickets and system state mutation sequences. The operation verification module is used to receive the operation action trajectory transmitted back by the mobile interactive terminal, compare it with the pre-stored standard compliant operation trajectory model using the Dynamic Time Warping (DTW) algorithm, and generate trajectory similarity. The first communication module is used to interact with the cloud control center through the cloud-edge collaboration protocol and communicate with the mobile interactive terminal through a secure wireless link based on WAPI; the WAPI link uses ternary peer authentication and digital certificates to complete two-way authentication and uses the national cryptographic algorithm SM4 to encrypt data transmission. The cloud-based control center includes: a model management engine, a simulation verification engine, a collaborative service module, and a fusion decision-making module; The model management engine is used to build, run, and dynamically update the digital twin model based on the preprocessed data; The simulation verification engine is used to load and simulate the execution of security measures in the digital twin model, and to verify their logical correctness and impact on the system. The collaborative service module is used to run the cloud-edge collaboration protocol and process the uplink reception of preprocessed data, the issuance of security measure instructions, and the incremental update data synchronization of the digital twin model according to a fixed period or event triggering method; the cloud-edge collaboration protocol adopts an application layer protocol based on MQTT or HTTP / 2. The fusion decision module is used to trigger and execute the fusion decision process when the deviation between the edge-assisted verification result and the cloud simulation verification result exceeds a preset threshold: drive the digital twin model to perform hotspot resimulation based on real-time data snapshots, search the historical case library for matching analysis, and generate decision suggestions with confidence scores by combining the results of the two. The mobile interactive terminal is AR glasses or augmented reality tablet device, including: a perception module, an AR rendering engine, an operation capture module, and a second communication module; The sensing module is used to scan and identify visual identifiers of field equipment and acquire spatial positioning data; The AR rendering engine is used to call the corresponding device 3D model, status information and posture adjustment matrix from the digital twin model according to the visual identifier and spatial positioning data, and combine the terminal's local SLAM positioning information to generate and render virtual operation guidance superimposed on the real scene, so as to realize real-time synchronization between the AR interface and the digital twin model. The operation capture module is used to collect the operation action trajectory of the operation personnel when performing operations through sensors; The second communication module is used to acquire real-time environmental data from the edge device, receive synchronized status and guidance information from the cloud control center or the edge device, and transmit back the operation trajectory.

[0019] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The technical solution proposed in this invention, based on cloud-edge-device collaboration and digital twin-driven technology, effectively improves data quality and processing timeliness by performing local preprocessing and real-time verification with intelligent analysis on edge devices, providing a high-reliability data foundation for upper-level decision-making. At the same time, by leveraging the cloud-edge collaboration protocol to achieve high-fidelity, low-latency synchronization of the digital twin model, a virtual sandbox that is mapped in real time to the physical substation is constructed, thereby realizing global and accurate perception and collaborative decision-making of the operation and maintenance status, and improving the overall operation and maintenance efficiency and reliability.

[0020] (2) This invention constructs a dual verification mechanism by combining high-fidelity logic simulation of a cloud-based digital twin model with real-time operational risk assessment of a lightweight AI model at the station. This mechanism can perform forward-looking verification from two dimensions—system logic correctness and on-site equipment real-time status compliance—before safety measures are implemented, effectively identifying and intercepting potential misoperations caused by design flaws or inconsistent status. When the dual verification results conflict, the system-triggered fusion decision-making process further provides fault tolerance and arbitration capabilities, significantly enhancing the reliability and security of safety measure implementation decisions.

[0021] (3) This invention, through the real-time data synchronization between the augmented reality (AR) interface of the mobile interactive terminal and the digital twin model, transforms abstract security measure instructions and virtual loop logic into a three-dimensional, visualized operation guide that is precisely superimposed on the real physical equipment. This guide can be dynamically adjusted according to the real-time status of the equipment fed back by the digital twin model (such as marking locked equipment as prohibited from operation), thereby reducing the complexity and understanding threshold of on-site operations and improving the accuracy and compliance of operations. In addition, by collecting operation feedback and updating the digital twin model, the system forms a complete digital closed loop of instruction issuance - on-site guidance - operation execution - status feedback, providing technical support for realizing the transformation from a post-event response relying on human experience to a pre-event warning and precise execution operation and maintenance model based on data and models.

[0022] The invention will now be further described with reference to the accompanying drawings. Attached Figure Description

[0023] Figure 1 A flowchart illustrating the intelligent substation safety measure verification and operation and maintenance management method according to the present invention; Figure 2 Functional block diagram of the intelligent substation safety measure verification and operation and maintenance management system according to the present invention. Detailed Implementation

[0024] To better illustrate the objectives, technical solutions, and advantages of the present invention, the specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and are not intended to limit the scope of the invention. Example

[0025] like Figure 1 As shown, an embodiment of the present invention relates to a method for verifying and managing the operation and maintenance of safety measures in intelligent substations based on digital twins and augmented reality. This method adopts a three-layer collaborative architecture of cloud-edge-device, specifically including edge devices, a cloud-based control center, and mobile interactive terminals. It aims to achieve pre-simulation verification of safety measures and intuitive on-site guidance. Its core process and specific implementation are as follows.

[0026] Step S1: Real-time acquisition of operating data of the power secondary system through edge devices deployed in the smart substation; and local preprocessing and real-time verification of the operating data to generate preprocessed data; Step S2: Upload the preprocessed data to the cloud management center via the cloud-edge collaboration protocol, and build and maintain a digital twin model corresponding to the smart substation containing the power secondary system in the cloud management center; wherein, the digital twin model is dynamically updated based on the preprocessed data and historical operation and maintenance data, and keeps data synchronized with the edge device through the cloud-edge collaboration protocol; Step S3: In the cloud-based control center, the proposed security measures are simulated and verified based on the digital twin model, and verified security measure instructions are generated. At the same time, the edge device performs real-time auxiliary verification of the security measures based on a locally deployed lightweight AI model, and compares the auxiliary verification results with the cloud-based simulation verification results. Step S4: The verified security measure instructions are sent to the mobile interactive terminal through the cloud-edge collaboration protocol; the mobile interactive terminal uses an augmented reality (AR) interface, combined with real-time environmental data obtained from the edge device, to overlay virtual operation guidance information onto the real physical device to guide on-site operation and maintenance; wherein, the AR interface is synchronized with the digital twin model in real time.

[0027] Specifically, step S1 is real-time data perception and preprocessing based on edge intelligence. By deploying edge devices (e.g., intelligent edge computing units based on Huawei Atlas 500 series) in the secondary equipment room of the smart substation, multi-dimensional and heterogeneous operating data of the power secondary system are collected in real time. This includes: (1) device configuration files (such as CID files) and real-time sampled status quantities exported from each intelligent electronic device (IED) through the IEC61850 MMS service; (2) the deep communication status of the process layer network, obtaining the original messages through port mirroring or network splitter, and then parsing the application identifier (APPID), message length, timing stability of the sending interval, and specific values ​​based on the manufacturing message specification (MMS) of GOOSE and SV messages, and statistically analyzing the traffic peak and packet loss rate; (3) the physical connection status and logical association relationship obtained through IoT sensors (such as optical fiber port optical power monitoring sensors) or automatic parsing of the whole station SCD file, such as the complete link mapping of optical fiber-port-switch, switch VLAN configuration status, etc.

[0028] The massive, high-speed raw data streams collected are immediately preprocessed and verified locally on edge devices in real time. Preprocessing is a multi-stage pipeline process: the first stage involves protocol parsing and data cleaning, stripping communication packet headers and converting data into internally unified time-series data objects; the second stage involves rule and logic verification, which includes not only checking the consistency of CID files according to IEC 61850-6 specifications in terms of syntax and semantics (such as the naming and type of logical nodes LN and data objects DO), and performing topology logic verification of physical connection status based on preset substation primary wiring diagrams and fiber optic cable lists, but also integrating a high-performance rule engine (e.g., based on Drools or a self-developed DSL) that can dynamically load rule sets. This engine performs millisecond-level, deterministic business logic judgments, such as: verifying whether the current setting of the protection device is within the safety range jointly determined by the dispatch command and the equipment ledger; and determining whether the circuit breaker position status transmitted in the GOOSE message, combined with the associated disconnector position status, conforms to the electrical five-prevention logic. The third level is intelligent feature extraction and initial screening. On edge devices with AI capabilities, a very lightweight anomaly detection model (such as a single-class SVM or a micro autoencoder) can be run simultaneously to learn the temporal patterns of network traffic or device status online and provide instantaneous deviation alarms.

[0029] All data units that have undergone the multi-level processing described above are encapsulated into standardized data packets. The encapsulation employs efficient data serialization formats (such as Protocol Buffers or MessagePack), and each data packet embeds a microsecond-level timestamp generated by local high-precision clock synchronization on the edge device, a globally unique device identifier conforming to unified encoding rules, and an identifier of the processing result the data packet has undergone (such as verification passed, rule alarm, AI anomaly prompt). Thus, the raw data is transformed into high-quality, structured preprocessed data with rich contextual semantics. This design filters out invalid and redundant data at the source and strictly controls the closed-loop delay of key anomaly event perception-preliminary decision-making through localized parallel processing, thereby providing high-value, low-noise, and highly timely data input for the cloud-based digital twin model.

[0030] Specifically, step S2 involves the dynamic construction and synchronization of a digital twin based on cloud-edge collaboration. Edge devices upload pre-processed data to a cloud-based control center deployed in the power data center via a cloud-edge collaboration protocol optimized for the Industrial Internet of Things (IIoT). This protocol employs a layered and decoupled design: at the application layer, it uses either the MQTT protocol based on a publish / subscribe model or the HTTP / 2 protocol supporting header compression and multiplexing to efficiently encapsulate structured pre-processed data, instructions, and model update packets. The message body can use efficient serialization formats such as Protocol Buffers to reduce bandwidth consumption. At the network and security layer, to address wireless interaction scenarios such as mobile inspections, transmission can be based on a secure link built on the Wireless LAN Authentication and Privacy Infrastructure (WAPI). WAPI, through a Tripartite Peer Authentication (TePA) mechanism, requires the edge device, mobile interactive terminal, and the Authentication Server (ASU) in the network to complete two-way identity authentication using digital certificates issued by a legitimate certificate authority. After successful authentication, both communicating parties encrypt the transmitted payload using the national cryptographic algorithm SM4 and perform integrity verification using the SM3 algorithm, thereby constructing a reliable transmission channel that is resistant to eavesdropping, tampering, and impersonation. The protocol stack also defines Quality of Service (QoS) levels, message priorities (e.g., alarm data is the highest), and automatic reconnection and message caching mechanisms to adapt to potential network fluctuations at the substation site.

[0031] After receiving the spatiotemporally aligned preprocessed data stream, the cloud-based control center, driven by the model management engine, constructs and dynamically maintains a high-fidelity digital twin model corresponding to the physical smart substation (including its secondary power systems). This model is a complex system mirror image that integrates multi-level and multi-domain models. (1) Geometric and physical layer: Based on laser point cloud scanning, CAD drawings and equipment model library, a three-dimensional model including equipment shape, cabinet layout and cable trench is constructed.

[0032] (2) Status data layer: Real-time mapping and association of various types of data from the edge, such as logical node attributes of IED such as Pos (plate status), Mod (running mode), Beh (behavior status), and real-time traffic matrix of network packets.

[0033] (3) Logic / Functional Layer: By parsing the entire SCD file, the virtual loop connection relationship is automatically constructed and visualized, that is, the subscription and publication topology between the inputs and outputs of GOOSE / SV, and the functional logic diagram of the protection device is embedded.

[0034] (4) Rule knowledge layer: In the form of a computable model, the nameplate parameters, protection settings, action characteristic curves, five-prevention interlocking rules and operation and maintenance procedures of the equipment are integrated.

[0035] The model management engine uses data fusion algorithms (such as Kalman filtering for continuous states and evidence reasoning for discrete events) to process multi-source asynchronous data in order to correct the model state, and may make forward-looking inferences about equipment degradation trends based on predictive models trained on historical big data.

[0036] To achieve efficient synchronization, the cloud-edge collaboration protocol defines a fine-grained bidirectional incremental synchronization mechanism. Uplink synchronization not only supports timed polling but also immediate event-driven reporting triggered by edge devices upon detecting abrupt state changes (such as a change in the Tr (trip) signal) or local rule engine alarms. The core of downlink synchronization lies in incremental updates: after a change in the state of the digital twin, the cloud does not download the entire model but instead generates an incremental update data packet containing only the changed elements by comparing the previous and current state versions (e.g., device A's Pos attribute changes from split to merge). Simultaneously, lightweight AI model parameters trained and optimized in the cloud are also distributed to the edge in the form of model difference packets. Edge devices maintain a lightweight local model image and achieve eventual consistency with the cloud-based digital twin master model by applying these incremental packets. This mechanism significantly reduces network bandwidth consumption and ensures the consistency of the system's cognitive baseline in weak network environments, providing a unified, accurate, and real-time digital image foundation for subsequent simulation, decision-making, and interaction.

[0037] Specifically, step S3 is a dual security verification of cloud simulation and edge AI collaboration. When the maintenance personnel formulate a security measure in the system (such as changing the Pos.ptoc[1].stVal (a section of overcurrent protection soft pressure plate) of line protection device A from '1' (in) to '0' (out)), the system starts two mechanisms in parallel: cloud deep simulation and edge real-time evaluation.

[0038] In the cloud, upon receiving instructions, the simulation verification engine loads them into a high-fidelity digital twin model, initiating a full-cycle, multi-scenario simulation. This simulation is not a simple state reversal, but rather a simulation of a complete operation-response timing process in a virtual environment based on the embedded mathematical models of power components (such as protection action characteristic curves and circuit breaker tripping times), power grid topology connections, and IEC 61850 service and logic constraints. The engine simulates the following in millisecond time steps: change of pressure plate state → associated protection logic blocking → simulation of a preset intra- or extra-zone fault (such as injecting fault current waveforms using the superposition principle) → verification of whether the protection action behavior meets expectations (such as whether the backup protection operates correctly and promptly after the pressure plate is deactivated). Simultaneously, it assesses the potential impact of this operation on system-level non-functional indicators, such as analyzing whether changes in GOOSE packet traffic in relevant network segments might trigger switch buffer overflow risks. After the simulation is completed, the engine generates a structured post-verification safety measure instruction, which not only includes the pass / fail conclusion, but also a detailed simulation process record, a list of key node state variables, and identified potential risk points.

[0039] Simultaneously, on edge devices, a dedicated lightweight AI model deployed in the edge intelligent verification module is activated. This model is a Temporal Convolutional Network (TCN) deeply optimized for resource-constrained environments. Its lightweight nature is achieved through a systematic model compression process: First, knowledge distillation is used in the cloud to allow a large, high-precision teacher model (such as a Transformer-based sequence model) to guide a streamlined TCN student model in learning the knowledge distribution for risk assessment. Subsequently, the student model undergoes quantized perceptual training, quantizing its weights and activation values ​​from FP32 precision to INT8 precision, and combining this with structured pruning to remove low-contribution filters from the convolutional layers. The optimized model size can be reduced by more than 70%, and the single inference latency on the edge NPU is less than 50 milliseconds. The core of this model lies in its specialized training dataset, which consists of massive historical security measure operation tickets precisely aligned with corresponding high-dimensional system state change sequences. The state sequence includes not only electrical quantities (current, voltage RMS values) but also diverse time-series data such as protection activation signals, communication interruption alarms, and switch port utilization, enabling the model to learn the complex mapping relationship between operational behavior and multidimensional system disturbances. During validation, the model receives two core inputs: first, a real-time multidimensional operational data stream within the current time window (serving as the system context); and second, vectorized safety measure instructions (representing operational intent). The model extracts features through its temporal convolutional layers and ultimately outputs a quantified risk assessment result, typically a risk probability value between 0 and 1, which may include the most relevant risk feature identifier (such as high network load).

[0040] Within a second-level time window, the system compares the risk probability value output by the edge AI with the logic verification conclusion and risk label obtained from cloud simulation based on rules and thresholds. If a significant deviation of more than a preset level occurs (e.g., the edge AI risk probability > 0.8 [high risk], while the cloud simulation conclusion is "logic passed, no risk"), the multi-source information fusion decision-making process is immediately triggered. This process is tiered and traceable. Hotspot Resimulation: The cloud-based simulation engine immediately launches a rapid simulation focused on the conflict zone. It utilizes edge-uploaded data snapshots containing finer-grained real-time states as initial conditions and may adjust simulation boundaries to perform high-precision, accelerated simulations only on local secondary system links directly affected by the security measure.

[0041] Historical Case Matching and Retrieval: The system searches the historical decision case database in parallel, using current operation characteristics, device type, and edge AI alarm characteristics as composite keys to retrieve similar edge-cloud conclusion conflict cases. Vector similarity calculations (such as cosine similarity) or more advanced graph matching algorithms are employed to identify historical handling records and final results.

[0042] Confidence Synthesis and Decision Generation: A decision fusion engine (e.g., based on DS evidence theory or a Bayesian network model) receives information from three evidence sources: initial simulation, hotspot resimulation, and historical case statistics. It assigns dynamic weights to each evidence source (e.g., resimulation has a higher weight for real-time performance), performs quantitative synthesis of uncertainty, and finally outputs a final recommended decision with a confidence score (e.g., 0-100%). For example: Decision: Recommend pausing, request manual review; Confidence: 88%; Basis: Local resimulation indicates a critical risk in the protection coordination timing, and one of two similar cases in the past three months resulted in erroneous protection activation. This deep fusion mechanism combines deep logical deduction based on physical models with data-driven real-time pattern intuition, constructing a deep intelligent security defense line with self-questioning and multi-source verification capabilities, significantly improving the robustness of security decisions under complex and uncertain operating conditions.

[0043] Specifically, step S4 involves precise AR guidance synchronized in real-time with the digital twin. Verified safety measures are transmitted via a cloud-edge collaboration protocol to the mobile interactive terminal (such as AR glasses) worn by on-site maintenance personnel. The terminal scans and perceives the on-site environment through its perception modules—typically including a high-resolution RGB camera, a depth sensor (such as structured light or ToF), and a six-axis or nine-axis inertial measurement unit (IMU). Visual identifiers can be high-contrast QR codes or April Tags pre-attached to the device, or inherent device features directly identified using computer vision technology (such as the unique outline of a specific switch or nameplate characters). Spatial positioning data acquisition is a fusion process: the terminal uses visual SLAM (Simultaneous Localization and Mapping) technology to extract ORB or SIFT feature points from continuous camera frames, constructing a sparse environmental point cloud map and estimating its own displacement; simultaneously, the IMU provides high-frequency acceleration and angular velocity data to compensate for SLAM drift errors during rapid movement or when visual features are missing. The two are tightly coupled through Kalman filtering or factor graph optimization, and finally output the six-degree-of-freedom pose of the terminal in the indoor coordinate system of the substation in real time.

[0044] To achieve high real-time, centimeter-level precision overlay between the AR interface and the digital twin model, the terminal uploads its unique device identifier and rough pose via a low-latency link (such as on-site Wi-Fi 6 or a 5G private network). Upon receiving the request, the edge device or cloud control center uses this identifier as an index to quickly retrieve and match within the digital twin model. The 3D model of the device in the digital twin is a lightweight mesh model generated from high-precision point cloud data acquired in advance using a laser point cloud scanner and then manually or automatically registered. Based on the terminal's pose, the system calculates the precise pose transformation matrix of the device model in the digital twin relative to the terminal's current viewport. To minimize transmission latency and data volume, instead of sending the complete 3D model file, only a lightweight 4x4 homogeneous coordinate transformation matrix is ​​sent, or further compressed into a pose adjustment data packet containing translation vectors and quaternion rotations.

[0045] Upon receiving this data packet, the terminal's AR rendering engine (such as one based on ARKit, ARCore, or a self-developed engine) fuses it with the local SLAM positioning results continuously optimized internally via Visual-Inertial Odometry (VIO). The engine utilizes a graphics API (such as OpenGL ES or Vulkan) to render virtual operation guidance elements from the digital twin model (such as a highlighted, flashing 3D arrow pointing to the pressure plate to be operated, or a floating text prompt "Please check the 'distant / local' handle position") in real-time at the correct 3D spatial location based on the fused matrix. The guidance information can dynamically change according to the real-time device status feedback from the digital twin; for example, when the model indicates the pressure plate is in an exited state, the AR guidance will automatically switch to the next step. Through the aforementioned closed-loop technology of identifier recognition, pose request, matrix distribution, and local fusion rendering, stable and accurate anchoring of virtual information and physical devices is achieved, thus providing maintenance personnel with intuitive, step-by-step 3D operation guidance.

[0046] Specifically, in the embodiments of the present invention, the method for verifying and managing the safety measures of intelligent substations based on digital twins and augmented reality further includes step S5. This step is a closed-loop verification based on intelligent comparison of operation trajectories.

[0047] To establish a quantifiable and auditable verification loop at the physical operation level, when maintenance personnel perform specific operations based on AR guidance (such as manually rotating knobs, pressing buttons, or engaging / disengaging pressure plates), the mobile interactive terminal activates its multimodal sensors for collaborative data acquisition. The terminal's built-in high-precision six-axis IMU captures the acceleration and angular velocity time-series sequences of the macroscopic movements of the hand or tool, while the front-facing camera, facing the operating area, combines computer vision algorithms (such as a MediaPipeHands-based 21-keypoint hand detection model) to track the two-dimensional pixel coordinates of the fingertips or the end of the operating tool in real time. These two heterogeneous and asynchronous sensor data streams are aligned using hardware timestamps and fused into a unified local coordinate system on the terminal, reconstructing the time-series sequence of the motion trajectory of the operating object in three-dimensional space, i.e., a data point set {P(t), V(t), O(t)} containing multiple dimensions such as position, velocity, and orientation.

[0048] The acquired raw trajectory sequences are first preprocessed and feature extracted on the terminal or edge device, including noise reduction filtering (such as using a Kalman filter), resampling to unify the time interval, and calculating derived features such as trajectory curvature, velocity profile, and operation stop points to form a more discriminative feature trajectory vector.

[0049] The characteristic trajectory is transmitted back to the edge device in real time. The edge device stores a library of rigorously calibrated standard compliant operation trajectory models. Each standard model corresponds to a specific standard operation (such as "activating or deactivating the XX model protection pressure plate"). It is generated by collecting data from multiple experts performing standardized operations in a safe environment, and then processing it through noise reduction, alignment (usually using the physical contact point of the operation as the time anchor point) and averaging. The desired trajectory template also exists in the form of a feature vector.

[0050] The core of trajectory comparison lies in the engineering application of the Dynamic Time Warping (DTW) algorithm. Instead of simply comparing the original coordinate sequences, the system calculates the minimum cumulative distance between the feature vector of the trajectory to be verified and the feature vector of the standard model. This distance metric is specifically designed to potentially assign higher weights to the order of operations (e.g., rotation before pressing) and key postures (e.g., wrist angle). The algorithm outputs a normalized trajectory similarity score, with a value between 0 and 1, quantifying the consistency between the current operation and the standard procedure in the spatiotemporal dimensions.

[0051] The verification decision is a multi-condition judgment process: if the calculated trajectory similarity exceeds a preset strict threshold (e.g., threshold ≥ 0.95), and the final state change is confirmed to be completely consistent with the security measure instruction requirements through independent query of the target device status by the edge device (e.g., directly reading the Pos.stVal attribute of the IED), then the system determines that the operation verification is successful.

[0052] The successful verification result, along with complete associated data (timestamp, operator, trajectory data, similarity score, and snapshots of the device's state before and after), is immediately encapsulated into an immutable verification event and synchronously updated to the cloud-based digital twin model via a cloud-edge collaboration protocol. In the digital twin, this event is not only recorded in the logs but also actively drives model state updates. For example, it switches the state of the corresponding pressure plate in the virtual device from the engaged state to the disengaged state and associates the record of this operation with the device's 3D model. Thus, every critical operation in the physical world leaves a precise, traceable, and auditable mirror record in the digital world, truly completing a closed-loop data-driven and intelligent management system from perception to decision-making to execution to feedback.

[0053] In this embodiment, the lightweight AI model, specifically the AI ​​model used for real-time auxiliary verification at the edge, achieves its "lightweight" characteristic through a series of cutting-edge model compression and acceleration technologies. This aims to ensure high reliability while meeting the stringent constraints of the edge environment. Specifically, it includes: A lightweight TCN model implementation for real-time risk assessment of substation safety measures. Step 1: Problem Definition and Model Selection (1) Input: Multi-dimensional real-time time-series data from the power secondary system of the smart substation. Specifically, it includes: protection device status (such as pressure plate on / off status, setting zone number), communication network status (such as GOOSE / SV message traffic, packet loss rate, switch port utilization), and status of associated devices synchronized from the digital twin.

[0054] (2) Output target: For a proposed safety measure operation instruction (e.g., "withdraw the overcurrent section I soft pressure plate of line protection A"), the model needs to output a comprehensive risk assessment result.

[0055] (3) Model selection: Temporal Convolutional Network (TCN) is selected. Because it can efficiently process the above-mentioned input temporal data and capture the long-term dependencies of the system state before and after the operation, it is suitable for deployment on edge devices.

[0056] Step 2: Model Building and End-to-End Optimization This step defines the entire data flow from model training to deployment.

[0057] (1) Knowledge distillation training stage ① Input: Training data: Sample pairs (operation instructions, state mutation sequences) constructed in step three.

[0058] Teacher model: A high-precision but parameter-intensive Transformer temporal model trained in the cloud, responsible for providing "soft labels" and intermediate layer feature maps as supervision signals.

[0059] ② Process and Output: The student model (TCN) learns the discriminative ability of the teacher model through a three-stage distillation process (basic ability transfer, intermediate feature alignment, and domain fine-tuning) and a dynamic training strategy (adjusting the temperature parameter T and loss weights). The output is a pre-trained TCN model that is not yet compressed but already possesses strong risk discrimination capabilities.

[0060] (2) Quantification and pruning optimization stage ① Input: The above "pre-trained TCN model".

[0061] ② Process and Output: Quantization-Aware Training (QAT): The model simulates INT8 computation during training, outputting a TCN model adapted to low-precision computation.

[0062] Iterative structured pruning: After multiple rounds of "evaluation-pruning-fine-tuning", a TCN model with sparse structure and significantly reduced parameters is output.

[0063] ③ The final output of this stage: a lightweight optimized TCN model file (such as .pth or .onnx format).

[0064] (3) Hardware deployment phase ① Input: Lightweight optimized TCN model file (usually in .onnx format).

[0065] The process and output: Utilize dedicated toolchains (such as Ascend CANN) on edge hardware (such as Huawei Atlas 500) for compilation optimization, output a highly optimized offline model (such as .om format) that can be efficiently executed on the edge NPU, and complete the deployment.

[0066] Step 3: Training Data Construction and Augmentation This step provides the data foundation for core capabilities, and the data samples constructed therein are the main inputs for the training phase in step two.

[0067] (1) Definition of core samples: ① Input (X): A structured vector, composed of two concatenated parts: Operation instruction encoding: Vectorize the security action ticket (e.g., using one-hot or embedded representation).

[0068] System state sequence: a time-series data matrix of multiple key state variables within a time window before and after the operation (e.g., from 1 second before the operation to 5 seconds after the operation).

[0069] ② Output (Y) / Label: The actual risk level label resulting from this operation (e.g., "high risk", "medium risk", "low risk" or corresponding values ​​0, 1, 2) and / or the specific risk category (e.g., "may cause protection failure", "may cause network congestion").

[0070] (2) Data augmentation: By adding noise and time shifting to the time series data in X, and by performing digital twin simulation synthesis on rare risk scenarios, more samples are generated, enabling the model to gain "risk intuition".

[0071] Step 4: Model Inference and Performance Verification This step describes the workflow of the model in practical applications and verifies its effectiveness.

[0072] (1) Online reasoning ① Input: Real-time data in the same format as the training samples: [current operation command vector to be verified, current real-time system state sequence].

[0073] ② Output: After the model is deployed on an edge device, it performs forward inference on the above inputs, and the results typically include: Main output: Risk level (e.g., "high risk") and corresponding confidence level (e.g., 0.92).

[0074] Optional auxiliary output: Risk source characteristics, indicating key dimensions leading to high risk (such as "sudden increase in network latency" or "abnormal associated protection device").

[0075] (2) Performance verification results The optimized model was evaluated on a dedicated test set (containing historical real-world cases and simulation boundary cases), and the performance comparison is as follows:

[0076] In this embodiment, the fusion decision specifically refers to the following: when the edge AI-assisted verification result and the cloud digital twin simulation verification result conflict at a preset level (for example, the edge AI outputs a risk level of "high risk" with a confidence level of >85%, while the cloud simulation conclusion is "logically passed"), the system will not simply adopt or reject either result, but will automatically trigger a three-level fusion decision process that verifies multi-source information and progresses step by step.

[0077] Step 1: Hotspot resimulation based on real-time snapshots (1) Input and trigger: The system immediately freezes the state at the moment of conflict, and the edge device uploads real-time data snapshots containing finer-grained data (such as millisecond-level traffic of a specific network link and precise mode status of associated devices) to the cloud.

[0078] (2) Process: The cloud simulation engine uses the snapshot as a high-precision initial condition, dynamically defines the simulation boundary, focuses on the "hot" devices and logic links that are directly related to the current security measures, and starts a fast re-simulation with a higher frequency and shorter simulation duration.

[0079] (3) Output: Generate a re-simulation report, focusing on whether the operation under micro-timing causes anomalies (such as excessive message delay or logic race), and give the conclusion of "local verification passed / failed" and key timing evidence.

[0080] Step 2: Matching historical contexts based on the case library (1) Input: The system extracts the feature vector of the current conflict in parallel, including: the type of operating device, the risk characteristics of edge AI warning (such as "high network load"), and the context information of the initial simulation in the cloud.

[0081] (2) Process: Using this vector as the query condition, retrieve all similar cases in the historical case database that are "edge warning but ultimately successful" or "edge warning and ultimately an anomaly occurs". Use a hybrid similarity algorithm (such as cosine similarity combined with dynamic time warping DTW) for matching and calculate the matching degree.

[0082] (3) Output: Generate a case matching analysis report, including the Top-K similar cases, the final result (success / failure) of each case, the handling measures, and calculate an empirical risk probability based on case statistics (e.g., 90% of similar cases are ultimately safe).

[0083] Step 3: Multi-evidence fusion and confidence level synthesis (1) Input: The output of the first three steps serves as four sources of evidence: E1: Initial simulation result in the cloud (“Pass”).

[0084] E2: Edge AI risk assessment results (“High Risk” and confidence level).

[0085] E3: Hotspot resimulation results ("Local pass" or "Local anomaly").

[0086] E4: Historical case experience risk probability (e.g., 90% safe).

[0087] (2) Process: The decision fusion unit (which may use DS evidence theory or Bayesian network model) performs uncertainty quantification and synthesis on the four evidence sources. The system assigns dynamic weights to different evidence (for example, E3 re-simulation has the highest weight because the data is the most recent, while E4 historical cases have different weights depending on the sample size).

[0088] (3) Output: Final decision recommendations: for example, "suggest suspension and request manual review" (when the composite confidence level is below the safety threshold), or "risk is manageable, approve execution but initiate enhanced monitoring" (when the composite confidence level is in the middle range).

[0089] Decision confidence: a quantified percentage score (e.g., 78%).

[0090] Summary of decision-making basis: The main conflict points are presented in a structured manner, the key findings from the re-simulation are presented, and the main reference cases are presented.

[0091] Interconnected feedback and closed-loop presentation The final output of this decision-making process will be seamlessly integrated into the system's interactive closed loop: (1) Instruction issuance: If the decision is "permit to execute", the system will automatically attach a monitoring mark to the original security measure instruction before issuing it. (2) AR interface prompts: The decision result, core basis (such as "according to the re-simulation, the network latency is close to the critical value") and confidence level will be prominently pushed to the AR glasses interface of the operation and maintenance personnel in the form of augmented reality labels, serving as the authoritative reference for their final operation. (3) Closed-loop learning: Regardless of the final operation result, all data, processes and results of this event will be stored in the historical database as a new case after being desensitized and labeled, for continuous optimization of the model and decision rules.

[0092] Application example: Suppose a conflict is triggered when "the soft pressure plate of overcurrent section I of line protection A is deactivated": Edge AI, based on real-time data, detected that the CPU utilization of a certain switch in the process layer was consistently above 85%, assessed as "high-risk" (90% confidence level), raising concerns about potential network congestion caused by the instantaneous traffic fluctuations resulting from the removal of the pressure plate. Initial cloud simulation, based on standard network parameters, concluded "logic passed." The fusion decision-making process consisted of three levels: Level 1 Re-simulation: Using real-time high-load data uploaded from the edge, the system accurately simulated the packet surge at the moment of pressure plate removal in a digital twin, confirming that network latency did indeed briefly exceed the safety threshold. Level 2 Case Matching: Three similar "high-load operation" cases were retrieved, two of which were successful, and one triggered a brief alarm. Level 3 Fusion: The decision model integrated high-weighted evidence such as "risk detected by re-simulation" and "failure precedents in historical cases," determining that the overall risk was controllable but caution was necessary. The final output was a decision recommendation of "risk controllable, execution permitted, but enhanced monitoring initiated," with a 75% confidence level. The AR interface, while guiding the operation, also provided an additional prompt: "Note: The network is under high load; please confirm no new communication alarms after the operation."

[0093] In this embodiment, the AR interface is synchronized with the digital twin in real time. Specifically, a dedicated data channel based on the User Datagram Protocol (UDP) is established between the mobile terminal and the station edge device. This channel is dedicated to transmitting extremely lightweight spatial coordinate data and device identification codes, abandoning traditional, heavy-load communication methods and fundamentally reducing network transmission latency and jitter.

[0094] To achieve precise anchoring between virtual and physical spaces, the system's foundation lies in high-precision calibration of the device's 3D model in the digital twin with the physical world. Specifically, during the deployment phase, a high-precision laser point cloud scanner is used to acquire the actual spatial point cloud data of the equipment within the site. This data is then rigorously aligned and bound to the corresponding 3D model in the digital twin, ensuring centimeter-level consistency between the virtual model and the physical equipment in geometric space.

[0095] During runtime, the synchronization mechanism works as follows: When the mobile terminal's camera recognizes the device identifier and estimates its coarse spatial pose using its own Simultaneous Localization and Mapping (SLAM) technology, it only uploads this identifier and coarse pose to the station-side edge device via the aforementioned UDP channel. Upon receiving the information, the edge device does not transmit a large, complete 3D model file. Instead, it retrieves the corresponding, pre-calibrated twin model based on the device identifier and calculates in real-time an "attitude adjustment matrix" describing the spatial transformation required for the model relative to its calibration origin. This matrix is ​​an extremely lightweight data packet (typically only tens of bytes) and is rapidly sent back to the mobile terminal.

[0096] Ultimately, the mobile terminal fuses the received "attitude adjustment matrix" with the higher-frequency visual positioning compensation information provided in real time by the local SLAM technology, efficiently completing the final alignment and rendering of the virtual and real spaces on the terminal side. Through this series of technical solutions built on lightweight transmission, high-precision pre-calibration, and edge-end collaborative computing, the system can reliably achieve accurate and real-time virtual-real overlay in the bandwidth-constrained field network environment of substations, providing stable and intuitive augmented reality guidance for operation and maintenance.

[0097] In this embodiment, the operation feedback verification specifically refers to the implementation of a complete operation and maintenance management closed loop, encompassing command issuance, on-site guidance, operation execution, and intelligent verification. This system, through collaboration between mobile terminals and station-level edge devices, establishes an operation verification mechanism based on multimodal perception and intelligent algorithm comparison. The core of this mechanism lies in not only verifying the final state result of the operation but also conducting high-precision, multi-dimensional quantitative evaluation and judgment of the standardization of the operation process itself.

[0098] Step 1: Capture, Fusion, and Reconstruction of Multimodal Operation Trajectories Operational verification begins with the precise digitization of the physical operation process. When maintenance personnel perform specific operations (such as rotating a knob or engaging / disengaging a pressure plate) according to AR guidance, mobile terminals (such as AR glasses or industrial tablets equipped with cameras) simultaneously activate their multimodal sensors for collaborative data acquisition. The terminal's high-precision inertial measurement unit (IMU) captures the raw time-series sequences of acceleration and angular velocity of the operator's hand or tool's macroscopic movements in real time at a frequency of several hundred hertz. Simultaneously, a front-facing camera facing the operation area, combined with lightweight computer vision algorithms (such as a 21-keypoint detection model for the hand based on the MediaPipe framework), continuously tracks the pixel coordinates of the operator's fingertips or tool ends in a two-dimensional image at video frame rate.

[0099] These heterogeneous data streams from different sensors, with different timestamps and coordinate systems, are first precisely aligned using hardware timestamps. Then, through a sensor fusion algorithm (e.g., using an extended Kalman filter), the displacement trend obtained by integrating the IMU data is tightly coupled with the 3D spatial position calculated from the visual data (estimated through camera intrinsics and depth information). In the terminal's local coordinate system, a refined temporal sequence of the operator's motion trajectory in 3D space is reconstructed in real time. This trajectory data not only includes a sequence of position points but also allows for the derivation of multi-dimensional features such as velocity, acceleration, direction of motion, and key joint angles, forming a "motion feature vector" describing a complete operation.

[0100] Step 2: Establishment of a Standard Compliance Operation Trajectory Model High-reliability comparisons rely on a high-standard reference system. During system deployment or training, we construct a "standard compliant operation trajectory model" by collecting data from multiple senior experts who repeatedly perform the same standard operation in a safe and compliant environment. Specifically, experts wear the same sensors on simulated equipment or verified safe real equipment and repeatedly perform standard operating procedures (such as "correctly engaging or disengaging the XX model protection plate"). The collected sets of raw trajectory data undergo rigorous noise reduction, time alignment (usually using the physical contact point of the operation as a time anchor for sequence alignment), and averaging or the establishment of a probability distribution model to generate the expected trajectory template for the operation. This template also exists in the form of an "action feature vector" and serves as a searchable standard operation digital fingerprint, pre-stored in the rule base of the station edge device or cloud-based digital twin system.

[0101] Step 3: Intelligent Similarity Comparison Based on Dynamic Time Warping (DTW) Once the edge device at the station receives the real-time operation trajectory feature vector to be verified from the mobile terminal, the core verification algorithm is immediately activated. Instead of simply comparing endpoint coordinates or final state, the system uses a dynamic time warping algorithm to process two time-series data points that may differ in length and exhibit natural fluctuations in execution speed.

[0102] The core of the DTW algorithm is to calculate the minimum cumulative distance between all corresponding points of the trajectory to be verified and the standard model trajectory. In this process, the system can assign different weights to different feature dimensions. For example, the logical order of operations (e.g., unlocking must precede operation) is given extremely high weight; the spatial accuracy of critical path points (e.g., the final positioning point of the finger approaching the pressure plate) is also considered; while the execution speed on non-critical paths is allowed to have greater flexibility. Through DTW calculation, the system finally outputs a normalized trajectory similarity score, which quantifies the degree of consistency between the current actual operation and the standard procedure in the spatiotemporal and action dimensions. The score typically ranges from 0 to 1.

[0103] Step 4: Multi-condition decision and closed-loop feedback The final validity of the operation is determined by a multi-condition decision logic. The system sets a strict preset threshold (e.g., trajectory similarity ≥ 0.95). The system determines that the operation is successfully verified only if both of the following conditions are met simultaneously: First, the calculated trajectory similarity score exceeds the preset threshold; second, through independent querying of the target device's status by edge devices (e.g., directly reading the corresponding status attributes of the smart electronic device via the IEC 61850 protocol), it is confirmed that its final status change is completely consistent with the requirements of the safety measure instructions.

[0104] The verification result is immediately encapsulated into a structured, auditable verification event containing a timestamp, operator and device identifier, trajectory data, similarity score, and before-and-after state snapshots. This event is synchronously updated to the cloud-based digital twin model via a cloud-edge collaboration protocol, driving real-time updates to the corresponding device's status in the virtual world and creating an immutable record in the logs. Simultaneously, a "verification successful" signal and key comparison information (such as "trajectory conformity: 97%)" are instantly fed back to the AR interface, alerting maintenance personnel. If verification fails, an alarm is triggered, and subsequent operational procedures are locked, awaiting manual review.

[0105] Through the complete technical chain of trajectory perception, model building, intelligent comparison and judgment feedback, the present invention realizes quantifiable and auditable in-depth verification of the on-site operation process itself, and elevates the operation and maintenance safety from the traditional "result verification" to a higher level of "dual verification of process and result", significantly enhancing the intelligence level and safety error prevention capability of the entire system.

[0106] In this embodiment, the cloud-edge collaboration protocol is specifically a comprehensive technical solution that covers application layer message format and underlying transmission security. Its design follows the layered principle to balance the efficiency and reliability of data transmission with the extremely high security requirements in industrial environments.

[0107] Step 1, Application Layer Protocol: Responsible for efficient business data encapsulation As described in the claims, the cloud-edge collaboration protocol can employ lightweight protocols such as MQTT or HTTP / 2 at the application layer. MQTT, based on a publish / subscribe model, is well-suited for scenarios where edge devices report data to cloud topics and the cloud issues commands to multiple edge devices, with minimal protocol header overhead. HTTP / 2 supports multiplexing and header compression, effectively reducing latency from frequent interactions. These protocols are responsible for encapsulating preprocessed data, security measure commands, and incremental update packets for digital twin models into structured application-layer messages (the message body can further employ efficient serialization formats such as Protocol Buffers), and defining the semantics of business interactions such as data reporting, command issuance, and heartbeat maintenance.

[0108] Step 2, Transport Security Layer Protocol: Building a Trusted Wireless Communication Foundation (Focusing on WAPI) It is important to clarify and emphasize that the messages in the aforementioned application layer protocols must be exchanged within a secure and reliable transmission channel. Especially in areas involving mobile inspection and wireless access, security at the link layer / network layer is a fundamental prerequisite.

[0109] Therefore, in a preferred and crucial embodiment of the present invention, to meet the mandatory security compliance requirements of smart substations for wireless communication (such as resisting man-in-the-middle attacks and preventing unauthorized access), the wireless transmission of all application layer data is implemented based on my country's independently controllable Wireless Local Area Network Authentication and Privacy Infrastructure (WAPI). The specific implementation method is as follows: Secure Access and Identity Authentication: When edge devices and mobile interactive terminals (AR glasses / tablets) access the WAPI network deployed within the access station, they must complete two-way identity authentication with the authentication server (ASU) through its core Three-Part Peer Authentication (TePA) mechanism. Both terminals and network devices (such as access points) must hold digital certificates issued by a legitimate certificate authority, fundamentally eliminating the risk of counterfeit devices accessing the network.

[0110] Data Encryption and Integrity Protection: After successful authentication, both communicating parties will use the national cryptographic algorithm SM4 to encrypt the transmitted application layer data payload, ensuring that the data is protected against eavesdropping during air interface transmission. Simultaneously, the national cryptographic algorithm SM3 is used to generate a message authentication code, guaranteeing the data's tamper-proof characteristics.

[0111] Complete protocol stack collaboration: Ultimately, the top-down encapsulation and transmission process of business data flow is as follows: application data (JSON / Protobuf) to application layer protocol frames (MQTT / HTTP / 2) to secure encapsulation (WAPI encryption and integrity protection) to wireless physical transmission. WAPI constructs a wireless security tunnel with security strength equivalent to or even superior to that of wired network physical isolation, allowing application protocols such as MQTT / HTTP / 2 running on it to focus on business logic in a trusted environment.

[0112] It's worth noting that WAPI is the preferred implementation solution for high-security wireless scenarios such as substations. In other network environments, such as wired networks with physical isolation, other mature secure transmission technologies such as IPSec VPN and TLS (Transport Layer Security) can be used to ensure the data security of application layer protocols. The core invention lies in achieving efficient, flexible, and robustly reliable data interaction between the cloud, edge, and device through this layered and collaborative protocol design, providing dual protection—both the "blood vessels" and the "immunity"—for the entire intelligent operation and maintenance management system.

[0113] like Figure 2 As shown, based on the same concept, this embodiment can also relate to a smart substation safety measure verification and operation and maintenance management system based on digital twins and augmented reality. This system adopts a cloud-edge-device collaborative architecture, specifically including edge devices, a cloud control center, and mobile interactive terminals.

[0114] Edge devices are deployed within smart substations. Their core function is to collect real-time operational data from secondary systems, perform local preprocessing and real-time verification of this data, and generate preprocessed data. In one specific implementation, the device further includes a data acquisition module, a local processing unit, an edge intelligent verification module, and a first communication module. The data acquisition module is responsible for collecting device configuration files, network communication status, and physical connection status. The local processing unit performs syntax and semantic consistency checks, as well as logical checks based on physical connection rules, on the collected operational data. It then encapsulates the verified data into standardized data packets with timestamps and device identifiers, thereby generating the preprocessed data. The edge intelligent verification module integrates a lightweight AI model for rapid local risk assessment of received security measure instructions. The first communication module is responsible for data interaction with the cloud control center and mobile interactive terminals via a cloud-edge collaboration protocol.

[0115] The cloud-based control center and edge devices establish a communication connection via a cloud-edge collaboration protocol. This connection receives pre-processed data uploaded from the substation and uses it to construct and dynamically maintain a digital twin model corresponding to the physical substation's secondary system. Simultaneously, the cloud-based control center uses this digital twin model to simulate and verify the proposed safety measures, generating verified safety measure instructions. In one specific implementation, the cloud-based control center includes a model management engine, a simulation verification engine, and a collaboration service module. The model management engine is responsible for constructing, running, and dynamically updating the digital twin model based on the pre-processed data. The simulation verification engine loads and simulates the execution of safety measures within the digital twin model, verifying their logical correctness and impact on the system. The collaboration service module runs the cloud-edge collaboration protocol, handling the uplink reception of pre-processed data, the issuance of safety measure instructions, and the synchronization of incremental update data for the digital twin model.

[0116] The mobile interactive terminal communicates with edge devices and the cloud control center. It receives verified security instructions and, through an augmented reality (AR) interface, overlays virtual operation guidance information onto the real physical devices using real-time environmental data acquired from the edge devices to guide on-site maintenance operations. In one specific implementation, the terminal is AR glasses or an augmented reality tablet device, including a perception module, an AR rendering engine, and a second communication module. The perception module scans and identifies visual identifiers on the on-site devices and acquires spatial positioning data. The AR rendering engine, based on the visual identifiers and spatial positioning data, calls the corresponding device 3D model, virtual loop logic, and status information to generate and render virtual operation guidance overlaid on the real scene. The second communication module acquires real-time environmental data from the edge devices and receives synchronized status and guidance information from the cloud control center or edge devices.

[0117] This system, through a cloud-edge-device collaborative architecture and modular design, deeply integrates edge intelligent preprocessing, cloud-based digital twin simulation, and intuitive augmented reality guidance, achieving a fundamental shift in operation and maintenance from "human experience-driven" to "data intelligence-driven." This improves data quality and processing efficiency at the source, constructs a deep security defense through a dual verification mechanism, and greatly reduces the complexity of on-site operations and the risk of misoperation through synchronous virtual and real AR interaction, ultimately forming an efficient, reliable, and traceable intelligent operation and maintenance closed loop.

[0118] Furthermore, this embodiment also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements the intelligent substation safety measure verification and operation and maintenance management method as described above.

[0119] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0120] The above is a detailed description of the preferred embodiments of this application. However, this application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this application. All such equivalent modifications or substitutions are included within the scope defined by the claims of this application.

[0121] The above embodiments mainly describe the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the present invention. Various changes and modifications can be made to the present invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed.

Claims

1. A method for verifying and operating and maintaining control of security measures of a smart substation, characterized in that, The method comprises the steps of: S1, collecting operation data of a power secondary system in real time through an edge device deployed in a smart substation; and performing local preprocessing and real-time checking on the operation data to generate preprocessed data; S2, uploading the preprocessed data to a cloud management center through a cloud-edge collaboration protocol, and constructing and maintaining a digital twin model corresponding to the smart substation comprising the power secondary system in the cloud management center; wherein the digital twin model is dynamically updated based on the preprocessed data and historical operation and maintenance data, and is kept in data synchronization with the edge device through the cloud-edge collaboration protocol; S3, in the cloud management center, simulating and verifying a to-be-executed safety measure based on the digital twin model to generate a verified safety measure instruction; at the same time, the edge device performs real-time auxiliary verification on the safety measure based on a locally deployed lightweight AI model, and compares the auxiliary verification result with the cloud simulation verification result; S4, issuing the verified safety measure instruction to a mobile interaction terminal through the cloud-edge collaboration protocol; the mobile interaction terminal superimposes virtual operation guidance information on real physical equipment through an augmented reality (AR) interface, in combination with real-time environmental data obtained from the edge device, to guide on-site operation and maintenance; wherein the AR interface is in real-time synchronization with the digital twin model. 2.The smart substation safety measure verification and operation management and control method according to claim 1, characterized in that, The step S3 comprises: if the deviation between the auxiliary verification result and the cloud simulation verification result exceeds a preset threshold, triggering a fusion decision-making process; the fusion decision-making process comprises: The cloud management center performs hot spot re-simulation based on the real-time data snapshot uploaded by the edge device; Retrieving similar cases in the historical database for matching analysis; Comprehensive analysis of the results of the hot spot re-simulation and the case matching analysis, generating a suggested decision with a confidence score and issuing it. 3.The smart substation safety measure verification and operation management and control method of claim 1, wherein, The step S3 comprises: a lightweight AI model deployed on the edge device obtains the safety measure instruction and the operation data collected in real time from the power secondary system, calculates and outputs an evaluation result representing the operation risk level as the auxiliary verification result; wherein, The lightweight AI model is a TCN model or a GRU model, and is constructed in the following way: In the cloud, the risk discrimination knowledge in a pre-trained complex teacher model is transferred to a lightweight TCN or GRU student model framework; then, the student model is subjected to quantization perception training to convert its weight parameters from floating-point precision to fixed-point integer precision, and is simultaneously subjected to structured pruning to remove redundant neuron connections, forming a preliminary compressed TCN model or GRU model that can be deployed on the edge device; The preliminary compressed TCN model or GRU model is trained using a specially constructed training data set, which is composed of historical safety measure operation tickets and the change sequence of key state variables in the power secondary system before and after the execution of each historical safety measure operation ticket, for the model to learn the mapping relationship between safety measures and system state disturbances. 4.The smart substation safety measure verification and operation management and control method of claim 1, wherein, In the step S4, the real-time environment data acquired by the mobile interactive terminal includes the visual identifier and the spatial positioning data of the on-site device acquired by scanning through the terminal camera; The real-time synchronization of the AR interface and the digital twin model includes: the mobile interactive terminal uploads the visual identifier and the spatial positioning data, the edge device or the cloud control center matches the corresponding device three-dimensional model and state information from the digital twin model, and delivers the posture adjustment matrix of the device three-dimensional model to the mobile interactive terminal; the mobile interactive terminal combines the local SLAM positioning information and the posture adjustment matrix to render and generate a virtual operation guide superimposed on the real device. 5.The smart substation safety measure verification and operation management and control method of claim 1, wherein, The method further includes a step S5: During the operation process of the operation personnel, the mobile interactive terminal collects operation action trajectories through sensors; The operation action trajectories are returned to the edge device, and a dynamic time warping (DTW) algorithm comparison is performed with a pre-stored standard compliant operation trajectory model to generate a trajectory similarity; If the trajectory similarity exceeds a preset threshold and the operation target state meets the safety measure instruction, it is determined that the operation verification is successful, and the verification result is updated to the digital twin model. 6.The smart substation safety measure verification and operation management and control method according to claim 5, characterized in that, The step S1 includes: The running data includes device configuration files, network communication states, and physical connection states; The device configuration files are checked for syntax and semantic consistency; Based on a preset physical connection rule, the collected physical connection states are logically verified; The verified running data is packaged into standardized data packets, and a timestamp and a device identifier are added to each standardized data packet. 7.The smart substation safety measure verification and operation management and control method of claim 1, wherein, The cloud-edge collaboration protocol in the step S2 adopts an application layer protocol based on MQTT or HTTP / 2; The cloud-edge collaboration protocol includes: An uplink synchronization mechanism: the edge device synchronizes the preprocessed data and device state heartbeat to the cloud control center in a fixed cycle or event triggered manner; A downlink instruction and model synchronization mechanism: the cloud control center delivers the verified safety measure instruction and the incremental update data packet of the digital twin model to the edge device. 8.The smart substation safety measure verification and operation management and control method of claim 1, wherein, The wireless communication link between the edge device and the mobile interactive terminal is established based on a wireless local area network authentication and privacy infrastructure (WAPI); the WAPI adopts a three-way peer authentication mechanism, and both the edge device and the mobile interactive terminal need to hold a digital certificate issued by a legal authentication server to complete two-way identity authentication, and after authentication, the real-time environment data, operation action trajectories, and safety measure instructions are encrypted using a SM4 algorithm.

9. A smart substation security measure verification and operation and maintenance management system, characterized in that, It includes: An edge device, a cloud control center, and a mobile interactive terminal; The edge device is configured to acquire running data of a power secondary system in real time, and to perform local preprocessing and real-time checking on the running data to generate preprocessed data; The method further includes a step S5: During the operation process of the operation personnel, the mobile interactive terminal collects operation action trajectories through sensors; The operation action trajectories are returned to the edge device, and a dynamic time warping (DTW) algorithm comparison is performed with a pre-stored standard compliant operation trajectory model to generate a trajectory similarity; If the trajectory similarity exceeds a preset threshold and the operation target state meets the safety measure instruction, it is determined that the operation verification is successful, and the verification result is updated to the digital twin model. The step S1 includes: The running data includes device configuration files, network communication states, and physical connection states; The device configuration files are checked for syntax and semantic consistency; Based on a preset physical connection rule, the collected physical connection states are logically verified; The verified running data is packaged into standardized data packets, and a timestamp and a device identifier are added to each standardized data packet. The cloud-edge collaboration protocol in the step S2 adopts an application layer protocol based on MQTT or HTTP / 2; The cloud-edge collaboration protocol includes: An uplink synchronization mechanism: the edge device synchronizes the preprocessed data and device state heartbeat to the cloud control center in a fixed cycle or event triggered manner; A downlink instruction and model synchronization mechanism: the cloud control center delivers the verified safety measure instruction and the incremental update data packet of the digital twin model to the edge device. The wireless communication link between the edge device and the mobile interactive terminal is established based on a wireless local area network authentication and privacy infrastructure (WAPI); the WAPI adopts a three-way peer authentication mechanism, and both the edge device and the mobile interactive terminal need to hold a digital certificate issued by a legal authentication server to complete two-way identity authentication, and after authentication, the real-time environment data, operation action trajectories, and safety measure instructions are encrypted using a SM4 algorithm. The cloud management center is configured to simulate and verify the to-be-executed safety measures based on the digital twin model, and generate verified safety measure instructions; the edge device is configured to perform real-time auxiliary verification on the safety measures based on a locally deployed lightweight AI model, and compare the auxiliary verification result with the cloud simulation verification result; The mobile interaction terminal is in communication connection with the edge device and the cloud management center, and is configured to receive the safety measure instructions, and superimpose virtual operation guidance information on real physical devices through an augmented reality (AR) interface in combination with real-time environment data obtained from the edge device, to guide on-site operation and maintenance; the AR interface is in real-time synchronization with the digital twin model.

10. The intelligent substation safety measure verification and operation and maintenance management system according to claim 9, characterized in that: The edge device comprises a data acquisition module, a local processing unit, an edge intelligent verification module, an operation verification module, and a first communication module; The data acquisition module is configured to acquire device configuration files, network communication states, and physical connection states; The local processing unit is configured to perform syntax and semantic consistency verification and logic verification based on physical connection rules on the acquired operation data, and encapsulate the verified data into standardized data packets with time stamps and device identifiers to generate the preprocessed data; The edge intelligent verification module integrates a lightweight AI model, which is configured to calculate the received safety measure instructions and real-time operation data, and output an evaluation result representing an operation risk level; the lightweight AI model is a TCN or GRU model converted from a complex teacher model through knowledge distillation, quantitative perception training, and structured pruning, and is trained using a paired data set composed of historical operation tickets and system state mutation sequences; The operation verification module is configured to receive operation action trajectories returned by the mobile interaction terminal, and perform dynamic time warping (DTW) algorithm comparison with a pre-stored standard compliant operation trajectory model to generate a trajectory similarity; The first communication module is configured to perform data interaction with the cloud management center through the cloud-edge collaboration protocol, and communicate with the mobile interaction terminal through a WAPI-based secure wireless link; the WAPI link adopts three-way peer-to-peer authentication and digital certificates to complete bidirectional authentication, and uses a SM4 algorithm for data encryption transmission; The cloud management center comprises a model management engine, a simulation verification engine, a collaboration service module, and a fusion decision module; The model management engine is configured to construct, run, and dynamically update the digital twin model based on the preprocessed data; ​ The simulation verification engine is configured to load and simulate execution of the safety measures in the digital twin model, verify logical correctness of the safety measures, and verify influence of the safety measures on the system. The collaborative service module is configured to run the cloud-edge collaboration protocol, and process uplink reception of the preprocessed data, downlink transmission of the safety measure instructions, and synchronization of incremental update data of the digital twin model in a fixed period or an event triggering manner. The cloud-edge collaboration protocol adopts an application layer protocol based on MQTT or HTTP / 2. The fusion decision module is configured to trigger and execute a fusion decision process when deviation between the edge auxiliary verification result and the cloud simulation verification result exceeds a preset threshold value, drive the digital twin model to perform hot spot re-simulation based on a real-time data snapshot, search a historical case library for matching analysis, and generate a decision suggestion with a confidence score based on a result of the two. The mobile interaction terminal is AR glasses or an augmented reality tablet device, and includes a perception module, an AR presentation engine, an operation capture module, and a second communication module. The perception module is configured to scan and identify a visual identifier of a field device, and acquire spatial positioning data. The AR presentation engine is configured to call a corresponding device three-dimensional model, state information, and a posture adjustment matrix from the digital twin model according to the visual identifier and the spatial positioning data, generate and render virtual operation guidance superimposed on a real scene in combination with local SLAM positioning information of the terminal, and realize real-time synchronization of an AR interface and the digital twin model. The operation capture module is configured to collect an operation action track of an operation performed by an operation and maintenance personnel through a sensor. The second communication module is configured to acquire real-time environment data from the edge device, receive synchronized state and guidance information from the cloud control center or the edge device, and return the operation action track.

Citation Information

Cited By

  • Substation intelligent inspection auxiliary control scheduling system and method based on cloud-edge collaboration

    CN122247027A