Hybrid Energy Integrated Management System

KR103005329B1Active Publication Date: 2026-08-14HAEAN PATENT&LAW FIRM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
KR1020250122645
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-08-29
Publication Date
2026-08-14
Estimated Expiration
2045-08-29

Smart Images

  • Figure 112025099645026-PAT00002_ABST
    Figure 112025099645026-PAT00002_ABST
Patent Text Reader

Abstract

The present invention relates to a hybrid energy management system, and more specifically, to an energy integrated management system and a control method thereof in a distributed power system comprising a plurality of new and renewable energy sources and an energy storage system, which optimizes the efficiency of energy supply during normal times based on real-time changing internal and external environmental data, intelligently switches operating modes to ensure system survivability and operational continuity in unpredictable crisis situations, and continuously improves resilience by learning from past operational experiences.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a hybrid energy management system, and more specifically, to an energy integrated management system and a control method thereof in a distributed power system comprising a plurality of new and renewable energy sources and an energy storage system, which optimizes the efficiency of energy supply during normal times based on real-time changing internal and external environmental data, intelligently switches operating modes to ensure system survivability and operational continuity in unpredictable crisis situations, and continuously improves resilience by learning from past operational experiences. Background Technology

[0002] Recently, the introduction of new and renewable energy sources such as solar and wind power has been rapidly increasing to address climate change and secure energy security. However, these new and renewable energy sources have inherent limitations, such as intermittent and highly variable power generation depending on natural conditions. To solve this problem, microgrid technology, which stores surplus power by linking with an energy storage system (ESS) and supplies it when needed, is being widely researched.

[0003] Conventional energy management systems have primarily focused on balancing power supply and demand or charging and discharging energy storage systems according to predetermined schedules. For example, it was common practice to store energy during off-peak hours when electricity rates are low and discharge it during daytime peak hours to reap economic benefits.

[0004] However, this conventional technology has several significant limitations.

[0005] It merely considers the quantity of electricity supply and demand, failing to reflect qualitative aspects such as the importance or urgency of the users receiving the power, which can lead to the inefficient allocation of limited energy.

[0006] Due to the lack of dynamic operational strategies to respond to unpredictable crisis situations, such as natural disasters like typhoons and earthquakes or failures in nearby wide-area power grids, it is vulnerable to severe damage, such as large-scale power outages or equipment failure.

[0007] It had a static structure where system operation logic or control parameters remained unchanged once set, lacking the intelligent ability to improve performance on its own by learning from past operational failures or adapting to changing environments. The problem to be solved

[0008] The present invention was devised to solve the problems of the prior art as described above, and the technical problem that the present invention aims to solve is as follows.

[0009] The first task is to provide an integrated energy management system that supplies limited energy through the most optimal path via a multi-stage hierarchical decision-making process that comprehensively considers physical constraints, economic efficiency, macroscopic stability, and dynamic urgency in a complex environment where multiple energy sources and power users with diverse characteristics coexist.

[0010] The second objective is to maximize the physical survivability and operational continuity of the system by providing a situation-adaptive control method that detects unpredictable and complex crisis situations, such as natural disasters, external power grid failures, and communication disruptions, in real time, and dynamically changes the system's control entity and level of autonomy based on the type and severity of the threat.

[0011] The third task is to provide an integrated energy management system with self-evolving resilience that strengthens itself through operational experience by implementing a learning-based feedback loop that objectively evaluates disaster response results using multifaceted key performance indicators, diagnoses the root causes of failure based on the evaluation results, and automatically optimizes control parameters to be used in future operational strategies.

[0012] The problems of the present invention are not limited to those mentioned above, and other problems not mentioned will be clearly understood by those skilled in the art from the description below. means of solving the problem

[0014] In an energy system comprising a plurality of energy sources and a plurality of power usage locations according to an embodiment of the present invention for solving the above problem,

[0015] A monitoring module for collecting internal and external status data of the above system; and

[0016] A power control module that, based on the collected data above, performs a logical processing procedure to determine the energy supply priority under normal conditions and switch the system's operating mode in the event of a crisis, and controls the energy supply of the energy source according to the result;

[0017] Includes,

[0018] The above power control module is,

[0019] In order to determine energy supply priorities in normal times,

[0020] Stage 1 filtering to exclude physically inefficient supply paths;

[0021] A two-stage static importance determination that assigns a second priority by comparing the contracted power grade of each power user for the paths that have passed the above-mentioned first-stage filtering; and

[0022] Characterized by sequentially performing a 3-step dynamic urgency determination, which determines the final priority by comparing the demand forecast deviation—the difference between the predicted power demand of each power user and the historical average power demand—within paths having the same priority in the above 2-step.

[0023] The above-mentioned first-stage filtering is,

[0024] The method is characterized by excluding from the supply candidate group a path where the remaining charge amount of the energy source is less than a preset minimum supply threshold, or where the separation distance between the energy source and the power usage location exceeds a preset maximum supply threshold.

[0025] The contracted power rating used in the above two-stage static importance assessment is,

[0026] It is characterized by being set into multiple sections by referring to the contract type classification criteria specified in the electricity supply terms and conditions or the national major power facility designation criteria, and

[0027] The above power control module is for switching the operating mode of the system in case of a crisis,

[0028] A step of receiving a plurality of risk indicators, including multiple disaster severity, grid vulnerability, and communication degradation, from the monitoring module; and

[0029] It is characterized by performing a rule-based decision to switch to an 'independent survival mode' that disconnects from the external power grid and supplies power only to essential loads when the aforementioned multiple disaster severity or the aforementioned grid vulnerability exceeds a predefined first-priority risk threshold, and to switch to a 'limited autonomous mode' in which the field edge controller operates autonomously when the aforementioned communication degradation exceeds a second-priority risk threshold without exceeding the aforementioned first-priority risk threshold.

[0030] The above grid vulnerability is,

[0031] It is determined based on the number of times the frequency of the external power grid deviates from the normal range or the duration of a low-voltage phenomenon in which the voltage of the external power grid drops below the normal range, and the criteria for the normal range and duration may be set by referring to power system reliability maintenance standards or international power quality standards. Effects of the invention

[0033] According to the present invention for solving the problem described above, the following effects can be expected.

[0034] The present invention can simultaneously maximize the efficiency and stability of energy supply by determining energy supply priorities through a multi-stage decision-making process that includes static importance, such as contracted power, and dynamic urgency, such as demand forecast deviations. This provides the effect of reducing operating costs by preferentially allocating limited energy resources to the most socially and economically important areas and preemptively suppressing the occurrence of power peaks.

[0035] The present invention can dramatically improve system survivability in unpredictable crisis situations by determining the type and severity of threats in real time and dynamically switching the system's operational architecture itself into modes such as 'central control', 'limited autonomy', and 'independent survival'. This prevents external power grid failures from spreading to the internal system and ensures operational continuity even in the event of communication interruption, thereby providing the effect of minimizing the risk of large-scale power outages and equipment damage.

[0036] The present invention includes a learning-based optimization process that objectively evaluates past disaster response performance and automatically reflects the results in subsequent operational strategies, thereby enabling the system to possess a high degree of autonomy and resilience that allows it to improve its performance over time. This allows for continuous adaptation to changing threat environments while minimizing human intervention, providing the effect of significantly enhancing the operational reliability and robustness of the system in the long term.

[0037] The effects according to the present invention are not limited to those exemplified above, and a wider variety of effects are included within the present invention. Brief explanation of the drawing

[0039] Figure 1 illustrates an overall relationship diagram according to the present invention. Figure 2 illustrates a flowchart between all components according to the present invention. Figure 3 illustrates a flowchart of the energy usage priority determination process according to the present invention. Figure 4 illustrates a flowchart of the autonomous driving mode switching process according to the present invention. Figure 5 illustrates a flowchart of the performance evaluation and learning optimization process according to the present invention. Specific details for implementing the invention

[0040] Hereinafter, various embodiments are described in more detail with reference to the attached drawings. The embodiments described in this specification may be modified in various ways. Specific embodiments may be depicted in the drawings and described in detail in the detailed description. However, specific embodiments disclosed in the attached drawings are intended only to facilitate understanding of various embodiments. Accordingly, the technical concept is not limited by specific embodiments disclosed in the attached drawings, and it should be understood that it includes all equivalents or substitutions that fall within the spirit and scope of the invention.

[0041] Terms including ordinal numbers, such as first, second, etc., may be used to describe various components, but these components are not limited by the aforementioned terms. The aforementioned terms are used solely for the purpose of distinguishing one component from another.

[0042] Functions related to artificial intelligence according to the present disclosure are operated through a processor and memory. The processor may be composed of one or more processors. In this case, the one or more processors may be general-purpose processors such as CPUs, APs, and DSPs (Digital Signal Processors), graphics-dedicated processors such as GPUs and VPUs (Vision Processing Units), or artificial intelligence-dedicated processors such as NPUs. The one or more processors control the processing of input data according to predefined operation rules or artificial intelligence models stored in memory. Alternatively, if the one or more processors are artificial intelligence-dedicated processors, the artificial intelligence-dedicated processors may be designed with a hardware structure specialized for processing a specific artificial intelligence model.

[0043] The predefined rules of operation or artificial intelligence models are characterized by being created through learning. Here, being created through learning means that a basic artificial intelligence model is trained using a number of training data by a learning algorithm, thereby creating predefined rules of operation or artificial intelligence models configured to perform desired characteristics (or objectives). Such learning may be performed on the device itself where the artificial intelligence according to the present disclosure is executed, or it may be performed through a separate server and / or system. Examples of learning algorithms include supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but are not limited to the examples described above.

[0044] An artificial intelligence model can be composed of multiple neural network layers. Each of the multiple neural network layers has multiple nodes and weight values, and performs neural network operations through calculations between the results of previous layers and the multiple weights. The multiple weights possessed by the multiple neural network layers can be optimized based on the learning results of the artificial intelligence model. For example, multiple weights can be updated so that the loss value or cost value obtained by the artificial intelligence model during the learning process is reduced or minimized. Additionally, to minimize the loss value or cost value, multiple weights can be updated in a direction that minimizes the gradient associated with the loss value or cost value. Artificial neural networks may include deep neural networks (DNNs), such as Convolutional Neural Networks (CNNs), Deep Neural Networks (DNNs), Recurrent Neural Networks (RNNs), Restricted Boltzmann Machines (RBMs), Deep Belief Networks (DBNs), Bidirectional Recurrent Deep Neural Networks (BRDNNs), or Deep Q-Networks, but are not limited to the examples mentioned above.

[0045] A network is a network that serves as a transmission path for web pages; it may be a closed network such as a LAN (Local Area Network) or WAN (Wide Area Network), but it is desirable for it to be an open network such as the Internet. The Internet refers to a global open computer network structure that provides the TCP / IP protocol and various services existing at its upper layers, namely HTTP (HyperText Transfer Protocol), Telnet, FTP (File Transfer Protocol), DNS (Domain Name System), SMTP (Simple Mail Transfer Protocol), SNMP (Simple Network Management Protocol), NFS (Network File Service), and NIS (Network Information Service).

[0046] Terminals can be implemented in various forms. For example, the terminals described in this specification may include mobile terminals such as smartphones, tablet PCs, PDAs, portable multimedia players, and MP3 players, as well as fixed terminals such as smart TVs and desktop computers.

[0047] In this specification, terms such as “comprising” or “having” are intended to specify the existence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof. When a component is described as being “connected” or “connected” to another component, it should be understood that it may be directly connected to or connected to that other component, or that there may be other components in between. On the other hand, when a component is described as being “directly connected” or “directly connected” to another component, it should be understood that there are no other components in between.

[0048] Meanwhile, a "module" or "part" for a component as used in this specification performs at least one function or operation. Furthermore, a "module" or "part" may perform a function or operation by hardware, software, or a combination of hardware and software. Additionally, a plurality of "modules" or a plurality of "parts," excluding a "module" or "part" that must be performed on specific hardware or on at least one processor, may be integrated into at least one module. A singular expression includes a plural expression unless the context clearly indicates otherwise.

[0049] In addition, power, power transmission, and control therefor for the following assembly configurations and embodiments, including "by control," follow conventional technology including terminals, applications, hardware control modules, etc., so they are omitted to avoid redundancy.

[0050] In addition, the operation embodiments and configurations described in a general manner without being explained in detail below follow the prior art and are omitted in order to focus on describing the purpose of the present invention and the resulting effects.

[0051] Furthermore, in describing the present invention, if it is determined that a detailed description of related known functions or configurations may unnecessarily obscure the essence of the invention, such detailed description is abbreviated or omitted.

[0052] A hybrid energy integrated management system according to one embodiment of the present invention may be configured to include a plurality of new and renewable energy sources, an energy storage system, a power usage location, and an energy management server (100) that controls them collectively.

[0053] The energy management server (100) described above is a central processing unit that implements the main technical concept of the present invention and may be a high-performance computer physically located within a data center or a virtual machine-based cloud server that operates by allocating multiple server resources. The energy management server (100) includes memory for storing an application program that performs the core logic of the present invention and one or more processors for executing it, and is composed of a monitoring module (110) and a power control module (120), which are logical software modules. It is preferable for the energy management server (100) of the present invention to adopt a hierarchical distributed architecture. That is, normal optimization calculations and data analysis are performed on a cloud-based central server to utilize vast computing resources, while emergency control and real-time monitoring are performed on edge computers installed at the site. This ensures that even if communication with the central server is cut off, minimal emergency response is possible, thereby simultaneously securing the real-time capability and survivability of the system.

[0054] In addition, when communication with the central server is lost, the edge computer executes a simplified version of Process 1 within limited computational resources using the latest operational parameters periodically synchronized from the cloud server and a shortened form of the prediction model. The simplified version determines priority based only on static criteria such as 'contracted power' and 'remaining charge amount,' excluding criteria such as 'demand forecast deviation,' for example, to maintain a minimum level of importance-based energy distribution function even in the event of a communication loss.

[0055] The monitoring module (110) is a specialized data processing module that performs the role of collecting, processing, and storing all data necessary for decision-making in the system. The monitoring module (110) prioritizes ensuring the accuracy and real-time nature of the data. Data is acquired using different collection protocols depending on the type and characteristics of the data. It communicates with field equipment, such as the battery management system of an energy storage system or a solar inverter, at a 1-second interval using industrial OT protocols such as Modbus TCP or DNP3 to collect data such as remaining charge amount and current power generation amount. On the other hand, it communicates with servers of external organizations, such as the Korea Meteorological Administration or the National Disaster Information Center, at a 10-minute interval via RESTful API to receive data such as weather forecasts and disaster warnings in JSON format. When the monitoring module (110) receives data from an external API, it includes a schema validity verification procedure. If the structure of the received JSON data does not match the existing schema, the system immediately discards the data and sends a 'suspicion of API schema change' warning to the administrator. In addition, the system can be designed to flexibly respond to minor key name changes, etc., through a data normalization adapter that includes multiple predefined parsing rules. The monitoring module (110) includes a security gateway composed of a data diode or an industrial firewall at the boundary between the IT network and the OT network, thereby ensuring the cyber security of the system by fundamentally blocking threats from the external IT network from propagating to the internal OT control network.

[0056] The collected raw data undergoes preprocessing steps such as validation and unit standardization. The validation involves performing multi-stage verification for each data point, including physical limit verification, rate of change verification, and cross-sensor verification. If a specific sensor continuously fails validation for a set period of time, the monitoring module (110) flags the sensor as 'unreliable' and notifies the power control module (120) to exclude the sensor value from decision-making. If the sensor in the 'unreliable' state is essential for system operation, the power control module (120) activates a state estimation algorithm to replace the value. For example, if the remaining charge sensor of the energy storage system fails, the system performs a 'virtual sensor' logic to estimate the current remaining amount by subtracting or adding the accumulated values ​​of subsequent charging and discharging power meters in real time from the last validly measured remaining amount value. This is a means of ensuring reliability that prevents the system from falling into a completely incapacitated state even in the event of an essential sensor failure, and allows operation to continue, albeit with limitations. The data that has completed the preprocessing process is stored in a time-series database along with timestamps so that it can be used for querying past data and analyzing patterns, and is transmitted in real time to the power control module (120) through the memory bus inside the server.

[0057] The power control module (120) is a module that acts as the brain of the system, performing core decision-making processes of the present invention based on data received from the monitoring module (110), converting the results into actual control commands, and transmitting them to field equipment. Normally, it executes an 'energy usage priority determination process' at a 1-minute interval to create an optimal energy supply priority queue and generates a control command to activate the supply path located at the top of the queue. To respond to crisis situations, it executes an 'autonomous operation mode switching process' at a 10-second interval to monitor multiple disasters, grid, and communication status, changes the system's operation mode when a risk threshold is exceeded, and executes emergency operation logic corresponding to that mode with the highest priority. When the end of a disaster event is detected, it sequentially executes a 'performance evaluation process' and a 'learning and optimization process' to analyze log data during the disaster period and determine a performance grade, and automatically adjusts internal control parameters to be used in the next emergency operation plan based on the results and stores them in a database.

[0058] The power control module (120) includes command execution priority control logic to prevent conflicts in control commands. Control commands generated in the 'crisis situation response process' always have a higher priority than commands generated in the 'normal operation process,' and if a command with a higher priority exists, the command with a lower priority is discarded. The generated control commands are encrypted through a security gateway and then transmitted to the RTU or PLC of the field equipment. After transmitting the control commands, the system performs a 'command execution verification' procedure to check whether a status value reflecting the execution result of the command is fed back within a set time. If there is no feedback within the time or the execution result differs from expectations, the system considers this a 'command execution failure' and performs a retry logic to retransmit the same command, and immediately sends a warning to the manager in the event of repeated failures.

[0059] The above retry logic stops retransmission if the preset maximum number of retries (e.g., 3 times) is exceeded. If it fails even after 3 retries, the power control module (120) declares the equipment in a 'uncontrollable' state, temporarily excludes the equipment from control, performs an alternative control sequence to start the backup equipment if there is backup equipment, and performs an escalation procedure to send the highest level emergency alert to the manager.

[0060] These components achieve the purpose of the present invention through the following organic interaction. Assume a situation where there is a forecast that a typhoon is moving northward. First, the monitoring module (110) receives information regarding the issuance of a 'typhoon warning' from the Meteorological Agency API, detects that the wind speed measured by the field anemometer has started to exceed 20 m / s, and transmits this data to the power control module (120). The 'autonomous operation mode switching process' of the power control module (120) determines the 'multiple disaster severity' to a 'caution' grade based on the received data and immediately switches the system's operation mode to 'independent survival mode'. Based on this decision, the power control module (120) generates control commands, such as opening external circuit breakers, disconnecting non-essential loads, and stopping wind turbines, and transmits them to the field facilities. After switching to 'Independent Survival Mode,' the power control module (120) activates and operates an 'Independent Survival Mode-specific energy allocation logic' that preserves the remaining capacity of the energy storage system as much as possible by supplying minimum power only to facilities designated as 'essential loads' in advance, instead of the normal energy allocation logic. The 'minimum power' follows the value stored in the 'essential load profile' database in advance. The profile defines the absolute minimum power (kW) required to maintain functionality and the total energy (kWh) required during the expected emergency operation time for each essential load. The power control module (120) compares the current remaining capacity of the energy storage system with the total energy required by the essential loads to calculate the optimal power supply amount in real time that maximizes the expected survival time, and controls the discharge amount of the energy storage system accordingly. After the typhoon passes, when the monitoring module (110) detects the end of the situation, the power control module (120) returns the system to normal mode and immediately thereafter executes the 'performance evaluation process' and the 'learning and optimization process.'The results of operations during the typhoon period are analyzed to determine the performance grade, and a learning process is completed to automatically adjust the next emergency operation parameters or maintain the current settings based on the results. In this way, the monitoring module (110) and the power control module (120) of the present invention perfectly perform a series of control processes through close and organic interaction to detect the changing external environment in real time, determine the optimal operation strategy accordingly, execute actual control commands, and learn from the results to improve themselves.

[0061] The power control module (120) included in the energy management server (100) of the present invention performs a method for determining the optimal energy supply priority in a complex system environment where multiple heterogeneous energy sources and heterogeneous power usage sites are mixed. In order to overcome the limitations of conventional technology that merely considers the amount of power supply and demand, the method adopts judgment criteria to achieve multidimensional goals such as system sustainability, economic efficiency, macroscopic stability, and dynamic responsiveness, and makes a final decision by organically combining these criteria.

[0062] To this end, the present invention uses four main criteria. The first criterion, 'remaining charge,' refers to the amount of available energy currently remaining in an individual energy source, and aims to ensure the sustainability of energy supply. If supply is initiated by discharging excessively without considering battery life, it may appear optimal in the short term, but it causes a rapid degradation of battery performance, resulting in a reduction of the total available energy of the entire system in the long term. Therefore, adhering to discharge depth management protocols while considering the remaining charge and protecting battery life is an essential constraint for optimally maintaining the system's energy supply capacity from a long-term perspective and preventing a situation where power is depleted during supply.

[0063] The second criterion, 'separation distance,' refers to the physical distance between the energy source and the power consumption point, aiming to ensure the economic efficiency of energy supply. By prioritizing routes that minimize transmission losses—which inevitably occur as distances increase—it reduces waste during the same power supply and lowers the overall system operating costs.

[0064] The third criterion, 'contracted power,' refers to the maximum amount of electricity that each power user has agreed to receive stably through a contract with a power supplier, and its purpose is to ensure the macroscopic stability of the power grid. Since contracted power is an objective indicator representing the importance and influence that a user holds within the power grid, large-scale loads with high contracted power—such as semiconductor factories or data centers—are prioritized for protection because a power interruption would cause massive social and economic repercussions.

[0065] The fourth criterion, 'demand forecast deviation,' refers to the difference between the predicted power demand at a specific point in time and the average power demand at the same point in the past, aiming to ensure the dynamic responsiveness of energy supply. By preemptively allocating low-cost internal energy sources to loads with large demand forecast deviations—that is, loads facing imminent peaks—it prevents situations where such loads draw on expensive external grid power to cover power shortages. In other words, it suppresses the inefficient use of external resources through the optimal allocation of internal resources.

[0066] The aforementioned four judgment criteria are applied sequentially according to a three-stage logical procedure within a hierarchical funnel structure, rather than through simple summation or averaging. This sequential structure is based on the technical necessity of enhancing computational efficiency and clarifying the judgment objectives of each stage. In the first stage, a preprocessing step is performed to reduce the complexity of the overall problem by excluding paths that are physically impossible to supply or have significantly low economic feasibility. In the second stage, the candidate pool is initially sorted based on contracted power, a macroscopic and static criterion, to prioritize the stability of the entire system. Finally, in the third stage, within the candidate pool that had the same priority in the second stage, demand forecast deviations—a microscopic and dynamic criterion—are compared to respond to real-time variability and fine-tune the final rankings. This implements a stability-oriented control philosophy that prioritizes stability before responding to real-time variability.

[0067] The values ​​of the above judgment criteria are obtained from objective and reliable data sources. 'Remaining charge amount' is collected every second via the CAN communication protocol from the battery management system of each energy storage system; for example, data is received in the form that the current remaining charge amount of energy source A is 150 kWh. 'Separation distance' is a fixed value pre-stored in a GIS database based on the GPS coordinates of each facility during system construction; for example, the separation distance between energy source A and user X is stored as 5.2 km. 'Contracted power' is a semi-fixed value retrieved from the power grid connection information database of the power users; for example, the contracted power of user X is obtained as 5,000 kW, and that of user Y as 800 kW. To calculate the 'demand forecast deviation,' 'forecasted power demand' is calculated every 15 minutes through an LSTM-based artificial intelligence forecasting module that takes past power usage patterns and external weather data as input. The above LSTM prediction module is configured to receive historical 60-minute time-series power usage data as input and predict the demand for the next 15 minutes. It is trained to minimize the mean squared error by using historical power usage data for the past year, temperature, humidity, day of the week, and holiday status at the corresponding point in time as input features, and using actual power usage as the ground truth label. For example, the predicted demand for user Y from 14:00 to 14:15 is calculated as 750kW. The 'historical average power demand' is calculated by averaging the actual usage for the same day of the week and time of day over the past 30 days from the server's operational data logs; for example, the historical average demand for user Y is calculated as 600kW. Therefore, the 'demand prediction deviation' for user Y is finally calculated as +150kW, which is the difference between the two values.

[0068] The final result derived through the above three-step processing procedure is stored in the system's memory in the form of a 'dynamic priority queue'. The power control module (120) retrieves an energy source-use pair located at the top of this priority queue during each control cycle and transmits a control command to the power conversion system to start or continue power supply to the corresponding path. When one control cycle ends, the entire priority queue is recalculated to reflect the latest data, so the system adapts to changing conditions in real time and performs optimal control.

[0069] The above processing procedure is explained in detail through a specific scenario as follows. It is assumed that the system has three energy sources (A, B, C) and three uses (X, Y, Z), and that the status of each facility is as shown in the table below.

[0070]

[0071] First, perform Stage 1 physical feasibility filtering. Assume that the 'minimum supply threshold' is set to 10 kWh and the 'maximum supply threshold' is set to 20 km. Since the remaining amount of energy source B is 8 kWh, which is below the threshold, path [B→ is eliminated from the candidate pool. The remaining paths [A→[A→[C→] all satisfy the threshold and pass, and the candidate paths are narrowed down to 3.

[0072] Next, a second priority assignment based on static importance in two stages is performed. The contracted power grade ranges are set as 'Extra Large' for 5,000kW or more and 'Medium' for 500–1,000kW. Since the contracted power of user X is 5,000kW, path [A→ is classified as 'Extra Large'. Since the contracted power of users Y and Z is both 800kW, paths [A→ and [C→] are classified as 'Medium'. Therefore, [A→, which is classified as 'Extra Large', has a clearly higher priority than the other two paths classified as 'Medium', and the second priority is sorted as 1st place [A→, tied for 2nd place [A→ and [C→).

[0073] Finally, a 3-step dynamic urgency-based final priority determination is performed. The final priority determination is conducted only for [A→ and [C→], which have the same secondary priority. The demand forecast deviation for use site Y is +150kW, and the demand forecast deviation for use site Z is +50kW. Since +150kW is greater than +50kW, it is determined that the power demand urgency of use site Y is higher, so path [A→] obtains a higher final priority than [C→]. Consequently, [A→, [A→, and [C→] are stored in the final priority queue in that order.

[0074] To ensure the reliability of this logic, an exception handling method is provided. If the 'demand forecast deviation' data of a specific user is lost due to communication errors or the like, the deviation value of that user is treated as '0'. This is a safety mechanism that prioritizes judgments based on static and highly reliable criteria, such as contracted power, rather than making hasty judgments based on uncertain information. Additionally, if the first priority path and the second priority path share the same energy source and compete for resources, the power control module (120) performs a sequential resource allocation logic in which it first fully satisfies the supply to the higher priority load, and then allocates supply to the next priority load only if there is remaining output.

[0075] The operation of the present invention shows a significant difference when compared to the prior art. While the prior art, which relies solely on simple remaining quantities, may lead to inefficient decisions due to the lack of criteria for determining which load is more critical, the present invention derives a clear and rational supply sequence by comprehensively considering static importance and dynamic urgency. This results in the simultaneous maximization of the stability and efficiency of the entire system.

[0076] All judgment rules used in the present invention are based on objectivity and necessity. Since all judgment criteria are measurable physical quantities or certified contract information, objectivity is ensured so that the same result is derived regardless of who performs it. Furthermore, as energy supply issues must simultaneously satisfy multiple goals of stability, efficiency, and real-time responsiveness, the logical processing procedure of the present invention, which establishes individual judgment criteria corresponding to each goal and combines them hierarchically, is an inevitable technical configuration for resolving this complexity.

[0077] The adoption of these components and rules brings about significant technical benefits. Hierarchical filtering rules reduce computational resources and enable faster decision-making. The introduction of the 'contracted power' criterion provides the effect of preventing cascading load outages that could lead to large-scale power outages. The introduction of the 'demand forecast deviation' criterion directly reduces operating costs by proactively responding to peak power demand and lays the foundation for generating additional revenue by participating in the demand response market.

[0078] Finally, the terms and threshold criteria used in this invention are clearly defined as follows. 'Demand surge state' refers to a state in which the predicted power demand exceeds the 'demand variability threshold ratio' relative to the historical average power demand. The 'minimum supplyable threshold' is set according to the minimum discharge limit specifications recommended by the manufacturer of each energy storage system to guarantee battery life. The 'demand variability threshold ratio' may be set to an industry-standard value during the initial stages of system operation and includes a learning function that automatically updates it to a value optimized for the system using statistical techniques once at least three months of operational data have been accumulated. This allows the threshold itself to adapt to the system environment, thereby continuously improving the accuracy of judgments.

[0079] The energy management server (100) of the present invention performs a situation-adaptive control method that dynamically changes the control subject and the level of autonomy of the system itself in accordance with real-time risk situations, unlike conventional technology that uses a fixed single control mode, in order to effectively respond to unpredictable disasters and instability of external systems. This method aims to maximize the survivability and operational continuity of the system.

[0080] To achieve the above objective, the present invention adopts three main judgment criteria for multifacetedly evaluating the nature and severity of threats facing the system. The first criterion, 'multiple hazard severity,' refers to the complex level of risk associated with natural disasters that pose a direct threat to the physical space where the system is installed, and serves as a standard for ensuring the physical survivability of the system. By detecting situations where direct physical damage, such as equipment failure or flooding, is expected, the system is isolated from the outside and preemptively switches to a survival mode that maintains only essential functions.

[0081] The second criterion, 'grid vulnerability,' indicates the possibility of deterioration in stability or collapse of the external wide-area power grid to which the system is connected, and serves as a standard for ensuring grid connection stability. To prevent failures or instability in the external power grid from spreading to the internal system and causing secondary damage, the system is rapidly disconnected from the external power grid when a risk is detected.

[0082] The third criterion, 'communication degradation,' refers to the level of quality deterioration in the data communication link between field equipment and the central control server, serving as a standard to ensure control continuity of the system. To prevent field equipment malfunctions caused by delays or loss of control commands from the central server, control authority is temporarily delegated from the central server to the field edge controller when communication quality deteriorates, allowing for continued stable operation based on autonomous judgment.

[0083] The three aforementioned judgment criteria are configured and processed by a priority-based rule system. This is based on the technical necessity of maximizing response speed in emergency situations by sequentially evaluating threats to the system starting from the most critical ones and acting immediately according to the corresponding first rule. Physical disasters or external power grid collapses that threaten the very existence of the system are evaluated as the highest priority; if any of these reach a dangerous level, other conditions are no longer evaluated, and the highest level of defensive measure, 'Independent Survival Mode,' is immediately activated. Only in safe situations where there is no first-priority threat is the quality of communication that threatens the stability of the control system evaluated; if a problem occurs in the communication network, 'Limited Autonomy Mode,' a secondary option that only changes the control entity, is selected. Determining the evaluation order based on the criticality of these threats is a rational control logic that ensures the most effective response within a limited time.

[0084] The status of each judgment criterion is determined by comparing it with predefined thresholds based on objective data. For 'Multiple Hazard Severity,' data is comprehensively acquired from the Korea Meteorological Administration's public data API, alerts from the National Disaster Information Center, and seismic accelerometer and anemometer sensors installed on-site. For example, if a typhoon warning is issued within a radius of 20 km or the maximum instantaneous wind speed measured on-site exceeds 25 m / s, it is classified as 'Alert.' For 'Grid Vulnerability,' real-time voltage and frequency data are collected via the IEC 61850 protocol from power quality analyzers installed at external power grid connection points. For instance, if the system frequency deviates from the normal range (60 Hz ± 0.2 Hz) five or more times per minute, it is classified as 'Unstable,' and if a low-voltage phenomenon where the system voltage drops below 80% of the normal range persists for 0.1 seconds or longer, it is classified as 'Dangerous.' In the case of 'communication degradation', TCP / IP Keep-Alive packet and ICMP Ping tests are performed between the central server and the field edge controller at 10-second intervals, and if the packet loss rate in the last minute exceeds 5% or the average response time exceeds 500ms, it is determined to be 'degraded'.

[0085] The identified risk level serves as a direct trigger to change the 'Current Operating Mode,' a global state variable of the system. Upon switching to 'Independent Survival Mode (Level 3),' the system automatically opens external grid circuit breakers, disconnects switches connected to non-essential loads, and the energy storage system automatically switches to discharge logic prioritizing the preservation of residual capacity. Upon switching to 'Limited Autonomy Mode (Level 2),' the central server transmits a flag granting 'autonomous operation authority' to the field edge controller; subsequently, the edge controller independently establishes and executes an operational plan for the next hour based on its internally stored predictive model and scheduling logic, without waiting for commands from the central server. Once the hazardous situation is resolved and no risk level is detected for 10 minutes, the system performs a 'Normal Return Sequence' to revert to 'Central Control Mode (Level 1).'

[0086] The above processing procedure is explained in detail through a specific scenario as follows. At 10:00, all indicators are normal, and the system operates in 'Level 1 (Central Control Mode)'. At 10:15, it is assumed that the packet loss rate increases to 8% due to a problem with a communication repeater near the site, and there are no other disasters or grid issues. Since the system's first-priority evaluation items, multi-disaster severity and grid vulnerability, are normal, it proceeds with the second-priority evaluation. As communication degradation is determined to be 'Degraded' because the packet loss rate exceeds 5%, the system switches to 'Level 2 (Limited Autonomous Mode)' and sends a command for the field edge controller to start operations based on its own judgment. Subsequently, at 10:30, it is assumed that the wind speed at the site increases to 28 m / s due to the influence of a typhoon, and communication remains in a 'Degraded' state. Since the system determines the first-priority evaluation item, multi-disaster severity, to be 'Alert' because the wind speed exceeds 25 m / s, it does not proceed with the second-priority evaluation further and immediately switches the system to 'Level 3 (Independent Survival Mode)'. In accordance with this command, the external grid is disconnected and power supply to non-essential loads is stopped. If the typhoon passes at 11:00 and communications are restored and all risk indicators remain normal for 10 minutes, the system executes the 'Return to Normal Sequence' and returns to 'Level 1 (Central Control Mode)'.

[0087] To ensure the reliability of this logic, various exception handling measures have been established. If a specific sensor value spikes abnormally or communication is lost, the system ignores that sensor value and continues to make decisions based on secondary data sources, such as the Korea Meteorological Administration API. If all data sources are lost, the system switches to the most conservative mode, 'Independent Survival Mode,' and sends a warning to the administrator. Additionally, to prevent the 'chattering' phenomenon—where the operating mode unstably keeps changing when the risk level fluctuates repeatedly for a short period near a threshold—time delay logic is applied to maintain the mode for a minimum duration once it is switched to a specific mode. However, if a situation with a risk level higher than the current mode occurs, the system immediately switches to a higher-level emergency mode regardless of the minimum duration, ensuring that the transition to the safer direction is always prioritized.

[0088] Compared to prior art, prior art is limited to passive responses such as generating an alarm or simply reducing output when wind speed exceeds a specific value, and cannot guarantee operational continuity in the event of a communication failure. On the other hand, the present invention preemptively isolates the system when a physical threat is detected to fundamentally prevent equipment damage and secondary damage, and ensures operational continuity by dynamically delegating control in the event of a communication failure. In this way, the resilience of the system is maximized by distinguishing the nature of the threat and switching to the optimal response mode accordingly.

[0089] All judgment criteria of the present invention are based on values ​​measured in clear physical units and disaster warnings announced by public institutions, thereby excluding the subjective judgment of the manager. Furthermore, since the threats faced by energy systems are multidimensional and the optimal response method for each threat differs, the approach of the present invention, which distinguishes the types and severity of threats and dynamically reconfigures the entire system architecture into the optimal response mode accordingly, is an inevitable technical solution to ensure the survival of the system in a complex threat environment.

[0090] The adoption of these components and rules brings about significant technical benefits. Priority-based rule systems reduce system response times to milliseconds and secure the golden time by eliminating unnecessary computations in emergency situations and responding immediately to the most critical threats. By integrating multiple risk criteria, it prevents false alarms or response failures caused by reliance on fragmentary information, and provides the effect of preventing unexpected cascading failures.

[0091] Finally, the terms and threshold criteria used in this invention are clearly defined. 'Independent Survival Mode (Level 3)' refers to the highest level of defense mode, in which the system is physically isolated from the external grid and non-essential loads, prioritizing the maintenance of core functions solely through internal energy sources. 'Limited Autonomy Mode (Level 2)' refers to a mode in which, when communication with the central server is unstable, the field edge controller is delegated control and continues operations based on its own judgment. The threshold values ​​presented in this specification are set as initial values ​​based on accredited technical specifications, such as international standards, domestic power grid reliability notices, and technical standards for information and communication facilities. Furthermore, the system learns operational history and includes a function that automatically corrects the threshold to one optimized for the region and facility environment through statistical analysis when frequent false alarms or response failures occur at a specific threshold, thereby continuously improving the reliability of the threshold itself.

[0092] The energy management server (100) of the present invention performs a method of evaluating, from various angles, how effectively the system maintained key functions and quickly returned to a normal state during a crisis situation, going beyond the conventional binary evaluation method that simply determines whether 'recovery is complete' after the end of a disaster event. This method aims to provide objective grounds for accurately diagnosing the actual resilience of the system and continuously improving it.

[0093] To achieve the above objective, the present invention adopts four key performance indicators as criteria for evaluation. The first criterion, "Service Continuity for Critical Load," refers to the ratio of the time during a disaster period when power supply to facilities designated as "critical load" in advance remained uninterrupted. As a standard for evaluating the system's social responsibility and ability to fulfill core missions, this measures the true value of the system's resilience by assessing how successfully critical loads—which are directly linked to maintaining essential social functions—were protected, rather than focusing solely on the total power outage time.

[0094] The second criterion, the 'equipment performance recovery rate,' is a ratio indicating the extent to which the performance of major power generation and storage facilities has recovered to a level relative to the normal state prior to the disaster, after a certain period has elapsed since the disaster situation was officially ended. This serves as a criterion for evaluating the completeness of recovery; by quantitatively measuring performance that may degrade due to minute damage or contamination remaining in the facilities even when recovery appears complete, it determines the need for additional precision inspections or maintenance and prevents potential secondary failures.

[0095] The third criterion, 'Average Recovery Time,' refers to the arithmetic mean of the time elapsed from the moment a warning or failure event occurs in individual equipment within the system due to a disaster until it is resolved through actions taken by the operations team. This serves as a standard for evaluating the organization's response speed and is utilized as an indicator to measure not only the performance of the equipment itself but also the capabilities of the operations team in detecting, analyzing, and resolving crisis situations, as well as the efficiency of the emergency response process.

[0096] The fourth criterion, the 'External Constraint Index,' represents the extent to which access to the site for maintenance personnel and materials was delayed or impossible during the disaster period due to factors such as road loss or traffic restrictions. This standard is designed to ensure fairness in evaluation by adjusting for performance indicators that can be significantly affected by external environmental factors beyond the operations team's control, such as average recovery time, and by more fairly evaluating pure internal capabilities to establish a basis for reasonable performance compensation.

[0097] The four key performance indicators mentioned above follow a two-step logical procedure in which they are calculated independently and the final performance grade is determined through a conditional performance matrix. In the first step, the vast amount of operational log data before and after a disaster event is analyzed to convert the four key performance indicators into objective numerical values, thereby establishing the factual basis for the evaluation. In the second step, the difficulty of the evaluation is adjusted by first verifying the 'external constraint index,' and then the target values ​​of the key performance indicators corresponding to the adjusted difficulty are compared with the actual values ​​to determine the final performance grade as [Excellent], [Average], or [Poor] according to predefined rules.

[0098] The values ​​for each judgment criterion are obtained from objective data sources. 'Critical Load Service Continuity' is calculated using power circuit breaker status logs and electricity meter data from the SCADA system; for example, if power supply to critical load A is interrupted for 3 minutes during a total of 120 minutes of the disaster period, the value is calculated as 97.5%. 'Equipment Performance Regression Rate' is calculated using MPPT efficiency logs of solar inverters or charge / discharge efficiency logs of energy storage systems; for example, if the average inverter efficiency was 98.5% before the disaster but the average efficiency 24 hours after the disaster is 96.5%, the value is calculated as 97.9%. 'Average Recovery Time' is calculated from the alarm / event history database of the HMI; for example, if a total of 3 failures occurred during the disaster period, taking 25 minutes, 45 minutes, and 35 minutes respectively, the value is calculated as 35 minutes. The 'external constraint index' is determined by combining records of immobility entered into the Ministry of Land, Infrastructure and Transport's traffic information API, local government disaster safety portal announcements, and the maintenance team's mobile work management app, and for example, if 'one or more major access routes are closed' is confirmed, it is determined as 'high constraint'.

[0099] The determined final performance rating does not end as a one-time report but is utilized as a key input for a technical feedback loop aimed at continuous system improvement and operational optimization. If rated 'Unsatisfactory,' the system automatically analyzes detailed diagnostic logs of equipment related to the key performance indicators that caused the rating to estimate potential causes, and automatically executes the 'creation of work order drafts and request for manager approval.' Additionally, it automatically modifies operational strategies to be more conservative, such as increasing the minimum reserve charge of the energy storage system in preparation for the next disaster. If rated 'Excellent,' the system extracts operational patterns that contributed to the success to automatically update 'Standard Emergency Response Operating Procedures' or assign positive weights to the reinforcement learning reward function of the AI ​​control model.

[0100] The above processing procedure is explained in detail through a specific scenario as follows. Assume a situation where a national highway is closed and communication failures occur in some facilities due to heavy snowfall. The performance evaluation targets are set such that for the 'Excellent' grade, critical load service continuity is 99.9% or higher, facility performance regression rate is 95% or higher, and average recovery time is within 40 minutes, while for the 'Poor' grade, critical load service continuity is set to less than 95% or facility performance regression rate is less than 80%. First, let's assume that Stage 1 KPI quantification is performed, and the log analysis results calculate critical load service continuity to 98%, facility performance regression rate to 92%, and average recovery time to 75 minutes. Simultaneously, due to the closure of the main access national highway, the 'External Constraint Index' is determined to be 'High Constraint'. Next, Stage 2 grade determination is performed. Since the 'External Constraint Index' is 'High Constraint', it is decided to apply relaxed performance evaluation targets; for example, the target for the 'Excellent' grade average recovery time is adjusted to within 90 minutes. When applying the judgment rules based on the adjusted targets, both critical load service continuity (98%) and facility performance regression rate (92%) exceed the 'Poor' standard, and the average recovery time (75 minutes) satisfies the relaxed 'Excellent' standard (90 minutes). Therefore, the final performance rating is determined to be 'Average'.

[0101] To ensure the reliability of this logic, various exception handling measures have been established. If time omissions or value outliers are found in the log data used for KPI calculation, the relevant data is excluded, and interpolation is used or KPIs are calculated using only valid data intervals to prevent evaluation distortion caused by data contamination. In the event that disaster events occur consecutively, the principle is to evaluate individual events separately; however, if they overlap to the extent that they are indistinguishable, the entire period is treated as a single event, and the 'External Constraint Index' is set to the highest level to ensure fairness in the evaluation.

[0102] Compared to prior art, which can draw unfair conclusions by evaluating only recovery time without considering external constraints, the present invention objectively identifies uncontrollable factors and reflects them in the evaluation to derive a reasonable grade. Furthermore, by focusing on qualitative indicators such as equipment performance regression rates, specific technical improvement tasks can be identified.

[0103] All evaluations of the present invention are based on quantitative data measured in clear units and public data. Furthermore, since system resilience is a multidimensional complex concept, the approach of the present invention, which evaluates various aspects such as service quality, facility soundness, and organizational responsiveness in a balanced manner and fairly corrects for the influence of the external environment, is an essential component for accurately diagnosing the actual resilience of the system and continuously improving it.

[0104] The adoption of these components and rules brings about significant technical effects. The 'Critical Load Service Continuity' standard elevates the goal of system operations from simple power supply to maintaining core social functions, thereby encouraging the concentration of limited resources on the most critical areas. The 'External Constraints Index' rule ensures fairness in evaluation, inducing operations teams to focus on improving controllable internal factors, which ultimately leads to a substantial strengthening of the organization's overall disaster response capabilities.

[0105] Finally, the terms and threshold criteria used in the present invention are clearly defined. A 'performance evaluation matrix' refers to a logical decision table that takes multiple key performance indicator values ​​and external constraints as input and outputs a final performance grade according to predefined rules. Performance evaluation targets are set based on values ​​specified in Service Level Agreements (SLAs) or industry standards concluded between the operator and the power user, ensuring that the evaluation criteria themselves have objective and contractual grounds. If there is no explicit SLA, the system may include a relative evaluation-based dynamic target setting function that automatically sets the top 10% of operational performance data from the past year as the target for an 'Excellent' grade.

[0106] The energy management server (100) of the present invention does not merely evaluate and record the results of disaster response, but performs an optimization method to self-evolve the system's operational strategy by utilizing the results as learning data to respond more effectively to the next crisis situation. This method aims to enable the system to possess self-evolving resilience that strengthens itself through experience.

[0107] To achieve the above objective, the present invention adopts two main judgment criteria to determine which parts of the system to improve and how. The first criterion, the 'final performance grade,' refers to the overall evaluation grade ([Excellent], [Average], [Poor]) of the disaster response results derived from Process 3, and serves as a criterion for determining the direction of learning. A 'Poor' grade implies that there are obvious weaknesses in the current operational strategy, thus triggering learning to change the system to be more conservative and safety-oriented. On the other hand, a 'Excellent' grade demonstrates the validity of the current strategy, thereby preventing a decline in operational efficiency due to excessive conservatism and serving as a basis for maintaining or slightly relaxing the current strategy.

[0108] The second criterion, 'Key Failure Indicators,' refers to the key performance indicators that were the most decisive cause of the 'Unsatisfactory' rating. This serves as a standard for determining the specificity of learning, aiming to perform customized parameter adjustments that directly address the cause of the failure, rather than simply making conservative system changes. For example, if recovery time was the issue, parameters related to the workforce response process are adjusted intensively; if critical load supply failure was the problem, parameters related to energy allocation policies are adjusted intensively.

[0109] Based on the two judgment criteria mentioned above, the present invention follows a clear two-step logical procedure of 'cause diagnosis and parameter adjustment.' In the first step, the final performance grade is verified, and only if the grade is 'unsatisfactory' is detailed major performance indicator data analyzed to identify which indicator was the biggest failure factor. In the second step, by referring to the identified major failure indicators and a predefined 'problem-solution parameter mapping table,' the system's operational parameters that have the most direct impact on solving the problem are identified, and their values ​​are automatically adjusted according to established rules. This procedure is an essential technical configuration for the system to maintain optimal performance and stability over a long period by continuously readjusting parameters based on actual operating results, based on the adaptive control theory of control engineering.

[0110] The value of each judgment criterion is obtained from the result of the previous process. The 'Final Performance Grade' is the final output value of Process 3; for example, the final performance grade for a specific typhoon event may be delivered as 'Unsatisfactory'. The 'Critical Failure Indicator' is identified by comparing the individual key performance indicator values ​​calculated in Process 3 with the target values. For example, if the actual value of Critical Load Service Continuity is 94.5%, falling short of the target of 95.0% and thus failing, while all other indicators satisfy the target values, the failure indicator is determined as 'Insufficient Critical Load Service Continuity'.

[0111] Operational parameters adjusted based on identified critical failure indicators are immediately saved and activated in the system's 'Next Emergency Operation Plan' database. This ensures that when the next disaster event occurs, the system operates automatically according to the improved strategy without separate administrator intervention. For example, if the 'Energy Storage System Minimum Reserve Charge' parameter is increased from 15% to 20%, the energy storage system will not discharge below 20% in normal operation mode and will always secure more emergency energy. This is a concrete technical implementation where lessons learned from past failures directly lead to changes in future behavior.

[0112] The above processing procedure is explained in detail through a specific scenario as follows. Assume that the evaluation result of Process 3 conveyed a final rating of 'Unsatisfactory' and a key indicator of 'Insufficient Service Continuity for Critical Loads'. First, a Stage 1 cause diagnosis is performed; since the final performance rating is 'Unsatisfactory', the automatic parameter adjustment procedure is initiated, and it is confirmed that the major failure indicator is 'Insufficient Service Continuity for Critical Loads'. This suggests that there was an absolute shortage of emergency energy to supply critical loads during the disaster period or that there was a problem with the energy allocation policy. Next, Stage 2 parameter adjustment is performed. The system queries the list of parameters to be adjusted that are linked to the major failure indicator of 'Insufficient Service Continuity for Critical Loads'. As a result of the query, 'Minimum Reserve Charge Amount for Energy Storage Systems', 'List of Critical Loads', and 'Independent Survival Mode Switching Threshold' are identified as parameters to be adjusted. Subsequently, rule-based automatic adjustment is executed to raise the current value of the 'Energy Storage System Minimum Reserve Charge' parameter by a preset increment, and to lower the 'Multiple Hazard Severity' threshold for switching to 'Independent Survival Mode' from the current 'Alert' level to the one-level 'Caution' level. Additionally, a 'Recommendation Alarm' is generated and sent to the administrator advising them to add loads with the next-highest contracted power level to the list that are not currently included in the 'Critical Load List'. The adjusted parameters are immediately saved and activated in the 'Next Emergency Operation Plan'.

[0113] To ensure the reliability of this logic, various exception handling measures are in place. To prevent overfitting—where parameters are changed too conservatively due to an 'inadequate' assessment of a specific type of disaster, leading to reduced response efficiency for other types—the system stores and learns individual sets of operational parameters for each type of disaster. Additionally, to prevent the system from becoming unstable due to an excessively large range of parameter adjustments, safety limit logic is applied to restrict the maximum adjustment range of parameters that can be changed in a single learning step, thereby ensuring gradual and stable improvement.

[0114] Compared to prior art, it takes a long time for personnel to manually analyze and apply corrective measures after a disaster response failure, leaving a high risk of human error. In contrast, the present invention automatically diagnoses the cause of failure within minutes of the disaster assessment and immediately and automatically reflects the most effective improvement plan into the system. This dramatically shortens the time gap between failure and improvement and enables a high degree of autonomy, allowing the system to become robust through experience.

[0115] Since the basis for parameter adjustment in this invention is objective performance ratings and key failure indicators, objectivity is ensured by making adjustments according to established rules based on clear data rather than subjective impressions. Furthermore, as the optimal operating parameters of the system constantly change due to the external environment and system aging, the learning-based optimization process of this invention, which continuously readjusts parameters based on actual operating results, is an essential technical configuration for the system to maintain optimal performance and stability over a long period.

[0116] The adoption of these components and rules brings about significant technical benefits. The 'Key Failure Indicator-Parameter Mapping Table' maximizes improvement effects by enabling precise optimization that directly addresses the root causes of failures. The 'Automatic Parameter Tuning' rule shortens the system's improvement cycle from months to minutes, providing the ability to rapidly adapt to rapidly changing external environments and disaster patterns, and delivering the technical benefit of maintaining a state of optimal readiness 24 hours a day, 365 days a year.

[0117] Finally, the terms and threshold criteria used in this invention are clearly defined. 'Learning-based optimization' refers to a series of procedures that automatically adjust the system's internal control parameters to improve future operational performance, using past operational performance evaluation results as input. The 'adjustment increment' of the parameters is not a fixed value; the system includes a meta-learning function that tracks how much performance improved in the next disaster event after a parameter change, thereby increasing or decreasing the adjustment increment itself. This optimizes the learning process itself to enable the system to autonomously find the most efficient improvement path.

[0118] Hereinafter, an embodiment of the present invention will be described in more detail with reference to the attached drawings. This embodiment applies to a smart grid microgrid system located in a specific area, and it is assumed that the system consists of a photovoltaic power plant, an energy storage system (ESS), and two power consumption points, namely a hospital and a general commercial building.

[0119] The system of the present embodiment is composed of an energy management server (100) located in a cloud data center and including a monitoring module (110) and a power control module (120) of the present invention, an edge computer for emergency control installed on-site, a solar power plant currently generating power at a maximum output of 500kW, an energy storage system with a total capacity of 1,000kWh and a current remaining charge of 600kWh, a hospital designated as a 'critical load' with a contracted power of 1,200kW and a current load of 700kW, and a commercial building with a contracted power of 400kW and a current load of 300kW. The initial system is in a 'Level 1 (Central Control Mode)' state and is determining the energy supply priority according to Process 1 of the power control module (120). Since the current solar power generation is insufficient compared to the total load, the deficit is being supplied by discharging from the energy storage system.

[0120] At 2:00 PM, Process 1 for demand forecasting and normal operation was executed. The monitoring module (110) predicted the demand 15 minutes later using an LSTM prediction model, and as a result, the demand forecast deviation for the hospital was calculated to be +200kW, and the demand forecast deviation for the building was calculated to be +20kW. The power control module (120) determined the priority based on this data. First, all supply paths passed the physical feasibility criteria. Next, it was determined that the hospital had a higher secondary priority for energy supply because the contracted power of the hospital was higher than that of the building. Finally, it was ultimately determined that the hospital had a higher level of urgency because the demand forecast deviation of the hospital was significantly larger than that of the building. Based on this judgment, the power control module (120) preemptively responded by sending a control command to the field power conversion system to increase the discharge output of the energy storage system to 700kW in preparation for a surge in the hospital's load due to the operation of surgical equipment, etc.

[0121] At 2:10 PM, Process 2 was activated in response to the detection of an external threat. The monitoring module (110) received abnormal frequency data from a power quality analyzer of the connected external power grid, and seven instances of the grid frequency deviating from the normal range were detected over the past one minute. Based on this data, the power control module (120) determined the grid vulnerability to be 'unstable', but since it was not yet at the highest risk level, it did not execute a direct mode switch. Instead, it recorded the grid instability situation in the log and sent a 'standby' command to the energy storage system to prepare to switch to 'independent survival mode'.

[0122] At 2:12 PM, as the crisis intensified, Process 2 for emergency response was activated again. The monitoring module (110) detected a low voltage phenomenon in which the grid voltage dropped sharply and lasted for 0.2 seconds. The power control module (120) immediately determined that this phenomenon satisfied the threshold for elevating the 'grid vulnerability' to a 'danger' level. Accordingly, the first priority rule was triggered, and the system's operating mode was immediately switched to 'Independent Survival Mode (Level 3)'. Along with this decision, the power control module (120) simultaneously sent a 'open' command to the circuit breaker at the external grid connection point as the highest priority, a 'shorten' command to the smart switch of the building that is not a 'critical load', and a command to the energy storage system and solar inverter to switch to 'Independent Operation Mode' to stably supply the hospital's current load.

[0123] At 3:00 PM, as the situation ended, the system returned to a normal state. When the monitoring module (110) confirmed that the external grid voltage and frequency remained stable for more than 10 minutes, the power control module (120) executed a 'normal return sequence'. After synchronizing the voltage and phase of the internal microgrid with the external grid, the circuit breaker was re-closed to restore grid connection, and the power supply to the building was also resumed, and the system returned to 'Level 1 (Central Control Mode)'.

[0124] After the event ended, processes 3 and 4 for post-analysis and learning were executed sequentially. The power control module (120) first evaluated the performance through process 3, and since the power supply to the hospital, which is a 'critical load,' was never interrupted, the critical load service continuity was calculated as 100%, and since there was no separate equipment damage, the equipment performance regression rate was also calculated as 100%. Since all key performance indicators satisfied the target values ​​for an 'excellent' grade, the final performance grade was determined to be 'excellent.' Subsequently, process 4 was executed, and since the final grade was 'excellent,' it was determined that there were no separate 'critical failure indicators.' The system concluded that the current 'grid vulnerability' judgment threshold and the 'independent survival mode' switching logic were very effective, and maintained the current settings as they were without performing separate automatic adjustments of operational parameters. This successful response case was stored as a 'success pattern' in the operation log database to be used for reinforcement learning of the artificial intelligence control model in the future. Specifically, the stored 'success pattern' is directly used to define the reward function of the reinforcement learning model. For example, if a success pattern is stored in which an agent receives an 'Excellent' rating by preemptively switching to 'Independent Survival Mode' while its 'Grid Vulnerability' is rated 'Unstable,' the system grants a high reward when the reinforcement learning agent takes the same action in a similar state in the future. By repeating this process, the AI ​​control model is trained to gradually increase the probability of making decisions similar to the success pattern.

[0125] Through this embodiment, it can be seen that the energy management server (100) of the present invention perfectly performs organic and intelligent operations, such as operating according to Process 1, which prioritizes economic efficiency and effectiveness in normal times, immediately switching to an operating mode according to Process 2, which prioritizes system survivability when an external threat is detected, and continuously strengthening resilience by evaluating and learning its own response through Processes 3 and 4 after the event ends.

[0126] Although preferred embodiments of the present invention have been illustrated and described above, the present invention is not limited to the specific embodiments described above. Various modifications are possible by those skilled in the art without departing from the essence of the invention as claimed in the claims, and such modifications should not be understood individually from the technical spirit or perspective of the present invention. Explanation of the symbols

[0127] Energy management server (100) Monitoring module (110) Power control module (120)

Claims

Claim 1 An energy system comprising multiple energy sources and multiple power consumption points includes: a monitoring module that collects internal and external status data of the system; and a power control module that, based on the collected data, performs a logical processing procedure to determine energy supply priorities in normal conditions and switch the operating mode of the system in crisis conditions, and controls the energy supply of the energy sources according to the result. The power control module comprises, in order to determine energy supply priorities in normal conditions, a first-stage filtering that excludes physically inefficient supply paths; and a second-stage static importance judgment that assigns a second priority by comparing the contracted power grade of each power consumption point with the paths that passed the first-stage filtering. The method is characterized by sequentially performing a third stage dynamic urgency determination, which determines the final priority by comparing the demand forecast deviation—which is the difference between the predicted power demand of each power user and the past average power demand—within paths having the same priority in the second stage; wherein the first stage filtering is characterized by excluding paths from the supply candidate group where the remaining charge amount of the energy source is less than a preset minimum supplyable threshold or where the separation distance between the energy source and the power user exceeds a preset maximum supplyable threshold; wherein the contract power grade used in the second stage static importance determination is characterized by being set into multiple sections by referring to the contract type classification criteria specified in the electricity supply terms and conditions or the national key power facility designation criteria; and wherein the power control module receives multiple risk indicators, including multiple disaster severity, grid vulnerability, and communication degradation, from the monitoring module in order to switch the system's operating mode in the event of a crisis.The method is characterized by performing rule-based judgments to switch to 'Independent Survival Mode,' which disconnects from the external power grid and supplies power only to essential loads, when the aforementioned multiple disaster severity or the aforementioned grid vulnerability exceeds a predefined first-priority risk threshold, and to switch to 'Limited Autonomous Mode,' in which the field edge controller operates autonomously, when the aforementioned communication degradation level exceeds the second-priority risk threshold without exceeding the aforementioned first-priority risk threshold; wherein the aforementioned grid vulnerability is determined based on the number of times the frequency of the external power grid deviates from the normal range or the duration of a low-voltage phenomenon in which the voltage of the external power grid drops below the normal range, and the criteria for the normal range and duration are set by referring to power system reliability maintenance standards or international power quality standards; and wherein, after the disaster event ends, the power control module analyzes operational log data to determine 'Critical Load Service Continuity,' which is the ratio of the time during the disaster period when power supply to facilities designated as 'Critical Loads' in advance was not interrupted, 'Facility Performance Regression Rate,' which indicates the level of performance recovery of major facilities compared to before the disaster, and individual A performance indicator calculation step for quantitatively calculating multiple key performance indicators, including an 'average recovery time' which is the arithmetic mean of the time taken to resolve an event, and an 'external constraint index' which indicates the level at which maintenance personnel could not access the site; a performance grade determination step for checking the 'external constraint index' to adjust the difficulty of the evaluation, and comparing the key performance indicator target value corresponding to the adjusted difficulty with the actual value to determine the final performance grade as one of [Excellent], [Average], or [Poor];The method is characterized by sequentially performing a learning-based parameter adjustment step, wherein, only when the final performance grade is determined to be 'inadequate', the key performance indicator that fell short of the target value is identified as a 'key failure indicator', and by referring to a previously stored 'problem-solving parameter mapping table', the system operation parameter that has the most direct impact on resolving the 'key failure indicator' is identified, and the value is automatically adjusted according to a set rule to optimize the 'next emergency operation plan'; wherein the learning-based parameter adjustment step is characterized by identifying the 'energy storage system minimum reserve charge amount', 'critical load list', and 'independent survival mode transition threshold' as parameters to be adjusted through the 'problem-solving parameter mapping table' when the 'key failure indicator' is identified as 'lack of critical load service continuity'; and wherein the learning-based parameter adjustment step is characterized by adjusting the current value of the 'energy storage system minimum reserve charge amount' parameter upward by a preset increase amount and adjusting the 'multiple disaster severity' threshold for transitioning to 'independent survival mode' downward from the current grade to a grade one level lower. Hybrid Energy Integrated Management System.; Claim 2 delete Claim 3 delete Claim 4 delete Claim 5 delete Claim 6 delete

Citation Information

Patent Citations

  • User priority classification method in large-user direct power purchase environment

    CN106447403A

  • Method for controlling power supply and microgrid system

    KR1020190050318A