A system and method for assessing risk of incorrect action
By constructing an incorrect action risk assessment system, including the device layer, device function layer, protection element layer, risk source quantitative assessment layer, and power grid fault layer, the problem that the impact of the protection element level was not considered in the existing technology is solved, and more accurate risk assessment and reliability calculation are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD
- Filing Date
- 2022-05-27
- Publication Date
- 2026-05-19
AI Technical Summary
Existing technologies fail to fully consider the impact at the level of protection components in the fault tree model of the protection system, resulting in insufficient model accuracy. Traditional reliability calculation formulas make errors in the calculation of associated risk points and cannot effectively assess the risk of incorrect actions.
A risk assessment system for incorrect actions is constructed, comprising a device layer, a device function layer, a protection element layer, a risk source quantitative assessment layer, and a power grid fault layer. By establishing a minimum complete event group, the probability of top-level events is calculated to accurately assess the risks of different protection elements.
It improves the accuracy and effectiveness of risk assessment for incorrect protective actions, enables more detailed assessment of the risks of protective devices, and enhances the reliability calculation capabilities of the model.
Smart Images

Figure CN115983617B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of relay protection operation evaluation technology, and more specifically, to a system and method for assessing the risk of incorrect operation. Background Technology
[0002] Existing technologies for risk assessment of incorrect protective actions include the development of fault tree models for protection systems, such as... Figure 1 As shown. The problems with the existing fault tree model of the protection system include: risk factors only affect a few protection elements of the protection device. For example, the hidden dangers in the operation of the channel only affect the main protection element of the line protection at high speed, and do not affect the distance protection or zero-sequence protection. Voltage loop abnormalities do not affect protection elements such as longitudinal differential protection and zero-sequence protection that do not require voltage and power direction discrimination. Because the existing fault tree model cannot be modeled at the protection element level, the accuracy of the model is insufficient.
[0003] Furthermore, traditional reliability calculation formulas contain errors in reliability calculations involving associated risk points, such as... Figure 2 As shown in the figure, assuming the fault tree of the protection failure event is as depicted, the probabilities of risk point channel failure and power supply failure are 0.2 and 0.1, respectively. The result calculated using the traditional reliability calculation formula is 0.028. In reality, if the power supply fails, the non-delayed protection will definitely fail to operate; the probability of non-delayed protection failure should not be lower than the probability of power supply failure. The root cause of the error in the traditional reliability calculation formula lies in its failure to properly handle the impact of related basic events on the reliability calculation.
[0004] Therefore, a technology is needed to assess the risks of incorrect actions. Summary of the Invention
[0005] The present invention provides a system and method for assessing the risk of incorrect operation of different protective components, in order to solve the problem of how to assess the risk of incorrect operation of different protective components.
[0006] To address the above problems, the present invention provides an incorrect action risk assessment system, the system comprising:
[0007] Device layer, which is used to set at least two top-level events to protect against incorrect actions;
[0008] The device function layer includes device function events corresponding to different incorrect protection actions, which are used to determine the correlation between device function events and incorrect protection element action events in the protection element layer.
[0009] A protection element layer, which includes protection element malfunction events belonging to different protection malfunctions;
[0010] A quantitative risk source assessment layer, which includes risk source events that affect the incorrect operation of protection components;
[0011] The power grid fault layer includes power grid fault events that affect the malfunction of protection components.
[0012] The computation layer is used to establish a minimum complete event group based on the risk source event, the power grid fault event, and the malfunctioning protection element event, and to calculate the probability of the top-level event based on the minimum complete event group.
[0013] Preferably, the conditions that trigger an event that causes the protective element to malfunction include: a risk source event, a power grid failure event, and malfunction of other protective elements besides the one mentioned.
[0014] Preferably, it includes:
[0015] The logical relationship between multiple risk source events triggering incorrect operation of protective components is OR;
[0016] The logical relationship between multiple power grid fault events triggering incorrect operation of protection components is OR;
[0017] The logical relationship between events of incorrect operation of protection components, risk source events, power grid failure events, and events of incorrect operation of other protection components is AND;
[0018] The logical relationship between the malfunction of other protective elements and the malfunction of this protective element is AND;
[0019] The logical relationship between the top-level event and each device function event is OR.
[0020] Preferably, the device functional events include: incorrect operation of the time-limited protection and failure of the backup protection to operate;
[0021] The logical relationship between the incorrect action of the time-limitless protection and the incorrect action of multiple protection elements is OR;
[0022] The logical relationship between the backup protection failure and the plurality of protection elements is AND; and the logical relationship between each backup protection failure and the failure of the plurality of backup protection elements is AND.
[0023] The logical relationship between backup protection malfunction and multiple protection elements is OR.
[0024] Preferably, the risk source events include: channel failure risk, device aging risk, CT circuit disconnection risk, PT circuit multi-point grounding risk, power supply damage risk, CT circuit multi-point grounding risk, CT circuit insulation abnormality risk, PT circuit neutral wire disconnection risk, and pressure plate abnormality risk.
[0025] According to another aspect of the present invention, a method for calculating the probability of a top-level event is applied to the aforementioned incorrect action risk assessment system, the method comprising:
[0026] Establish a minimum complete event group based on risk source events, power grid failure events, and malfunctioning protection element events;
[0027] Calculate the probability of the top-level event based on the minimum complete event group;
[0028] The risk source event originates from the risk source quantitative assessment layer included in the incorrect action risk assessment system;
[0029] The power grid failure event originates from the power grid failure layer included in the incorrect action risk assessment system;
[0030] The malfunction events of the protection elements originate from the protection element layer included in the malfunction risk assessment system, and the malfunction events of the protection elements are attributed to different malfunctions of protection.
[0031] Preferably, a minimum complete event group is established based on risk source events, power grid fault events, and malfunctioning protection element events, including:
[0032] Based on risk source events, power grid fault events, and malfunctioning protection element events, multiple minimal complete events that trigger multiple malfunctioning protection actions are generated, and these multiple minimal complete events are combined into a minimal complete event group.
[0033] Preferably, calculating the probability of the top-level event based on the minimum complete event group includes:
[0034] The probability of the minimum complete event group is calculated based on the probability of each minimum complete event, and the probability of the minimum complete event group is used as the top-level event probability.
[0035] Preferably, the generation of multiple minimal complete events that trigger multiple incorrect protection actions includes:
[0036] Identify power grid failure events;
[0037] Multiple base events that cause the protection element to operate incorrectly under the direct or combined effects of the power grid fault event are obtained. Multiple non-repeating unions of the base events with the power grid fault event are generated, and the generated unions are used as the minimum complete event.
[0038] The present invention provides a computer-readable storage medium, characterized in that the computer-readable storage medium stores a computer program, the computer program being used to execute a method for calculating the probability of a top-level event by an incorrect action risk assessment system.
[0039] This invention provides an electronic device, characterized in that the electronic device comprises: a processor and a memory; wherein,
[0040] The memory is used to store the processor-executable instructions;
[0041] The processor is configured to read the executable instructions from the memory and execute the instructions to implement a method for calculating the probability of top-level events in an incorrect action risk assessment system.
[0042] This invention provides a system and method for assessing the risk of incorrect protection actions. The system includes: a device layer for setting at least two top-level events for incorrect protection actions; a device function layer for including device function events corresponding to different incorrect protection actions and determining the correlation between device function events and incorrect protection element action events in the protection element layer; a protection element layer for including incorrect protection element action events belonging to different incorrect protection actions; a risk source quantitative assessment layer for including risk source events affecting incorrect protection element action; a power grid fault layer for including power grid fault events affecting incorrect protection element action events; and a calculation layer for establishing a minimum complete event set based on risk source events, power grid fault events, and incorrect protection element action events, and calculating the probability of top-level events based on the minimum complete event set. This invention improves the effectiveness of existing incorrect protection action risk assessment methods. Attached Figure Description
[0043] Exemplary embodiments of the present invention can be more fully understood by referring to the following figures:
[0044] Figure 1 This is a schematic diagram illustrating the assessment of protection system failure based on existing technology.
[0045] Figure 2 This is a schematic diagram of the risk probability calculation process based on existing technology;
[0046] Figure 3 This is a structural diagram of a risk assessment system for incorrect actions according to a preferred embodiment of the present invention;
[0047] Figure 4 This is a schematic diagram of a fault tree model for risk assessment of line protection failure to operate under a 3 / 2 connection according to a preferred embodiment of the present invention;
[0048] Figure 5 This is a schematic diagram of a channel failure risk assessment according to a preferred embodiment of the present invention;
[0049] Figure 6 This is a schematic diagram of a device aging risk assessment according to a preferred embodiment of the present invention;
[0050] Figure 7 This is a schematic diagram of a multi-point grounding risk assessment for a PT circuit according to a preferred embodiment of the present invention;
[0051] Figure 8 This is a schematic diagram of a power supply damage risk assessment according to a preferred embodiment of the present invention;
[0052] Figure 9 This is a schematic diagram of a multi-point grounding risk assessment for a CT circuit according to a preferred embodiment of the present invention;
[0053] Figure 10 This is a schematic diagram of the CT circuit insulation abnormality risk assessment according to a preferred embodiment of the present invention;
[0054] Figure 11 This is a schematic diagram of a PT circuit neutral wire breakage risk assessment according to a preferred embodiment of the present invention; and
[0055] Figure 12 This is a flowchart illustrating a method for calculating the probability of top-level events in an incorrect action risk assessment system according to a preferred embodiment of the present invention. Detailed Implementation
[0056] Exemplary embodiments of the invention will now be described with reference to the accompanying drawings. However, the invention may be embodied in many different forms and is not limited to the embodiments described herein. These embodiments are provided to fully and completely disclose the invention and to fully convey its scope to those skilled in the art. The terminology used in the exemplary embodiments illustrated in the drawings is not intended to limit the invention. In the drawings, the same units / elements are referred to by the same reference numerals.
[0057] Unless otherwise stated, the terms used herein (including technical terms) have their common meaning as understood by one of ordinary skill in the art. Furthermore, it is understood that terms defined in commonly used dictionaries should be understood to have a meaning consistent with the context of their relevant field, and not to be interpreted as having an idealized or overly formal meaning.
[0058] Figure 3 This is a structural diagram of a risk assessment system for incorrect actions according to a preferred embodiment of the present invention.
[0059] This invention first constructs a fault tree for risk assessment of incorrect operation of the protection system, including:
[0060] Step 1: Constructing the Fault Tree Framework: The target of the risk assessment for incorrect protection operation is the protection device, with a granularity down to the protection element level. Considering the dual-set protection configuration, the ability of protection device functions to be categorized as primary / backup protection, and the correlation between protection actions and grid faults, the fault tree for incorrect protection operation comprises five layers: the device layer, the device function layer (functions include primary / backup protection, etc.), the protection element layer, the quantitative risk source assessment layer, and the grid fault layer. Specifically, the device layer outputs the risk of incorrect operation of the entire device; the device function layer covers the protection system as a whole and its protection elements; the protection element layer addresses the risk of incorrect operation of elements under different risk sources and grid faults; the grid fault layer determines the probability of different types of grid faults; and the quantitative risk source assessment layer determines the quantitative probability of different risk sources.
[0061] like Figure 3 As shown, the present invention provides a risk assessment system for incorrect actions, the system comprising:
[0062] Device layer 301, the device layer is used to set at least two top-level events for protecting against incorrect operation;
[0063] The device function layer 302 includes device function events corresponding to different incorrect protection actions, which are used to determine the correlation between device function events and incorrect protection element action events in the protection element layer.
[0064] The device functional layer modeling of this invention includes: dividing the protection device according to its function, organizing the protection elements using the device functional layer, and establishing the association between the device functional layer and the protection element layer. For time-limitless protection, when a primary equipment failure occurs, all protection elements should operate. There is an "OR" relationship between the failure of the time-limitless protection function and the failure of each protection element to operate. For backup protection, since the other protection elements return to normal after any protection element in the dual protection system operates, there is an "AND" relationship between the failure of the backup protection function and the failure of each protection element to operate. Furthermore, the backup protection function is considered to have failed to operate only when all backup protection elements in the dual protection system fail to operate. That is, the backup protection function of both device 1 and device 2 is considered to have failed to operate only when all backup protection elements in device 1 and device 2 fail to operate. For the protection device as a whole, the failure of the protection device is a combination of the failures of various protection functions. Therefore, there is an "OR" relationship between the various protection functions in the failure of the protection device. By bridging the functional layers of the device, the correlation between incorrect device operation and incorrect operation of protective elements can be accurately established. For example, if the distance II stage of device 1 fails to operate, but the distance II stage of device 2 operates, since other backup protective elements can return after one set of backup elements has been protected, device 1 is not considered to have failed to operate.
[0065] Protection element layer 303, the protection element layer includes protection element malfunction events belonging to different protection malfunctions;
[0066] The protection element layer modeling of this invention includes: establishing the correlation between incorrect operation of protection elements and risk sources, power grid faults, and other protection operations. The main protection failure to operate is caused by the activation of a risk source under a certain power grid fault, while the backup protection failure to operate is caused by the activation of a risk source under a certain power grid fault and the failure of both main protection systems to operate. The incorrect operation of protection elements caused by different risk sources differs. This invention solves the problem of modeling the coupling and correlation between risk sources and incorrect operation of protection elements.
[0067] Risk source quantitative assessment layer 304 includes risk source events that affect the incorrect operation of protection components;
[0068] The risk source assessment layer of this invention includes: using online monitoring and inspection information of relay protection to assess the risk level of risk sources, thereby solving the problem of quantitative assessment of risk sources.
[0069] Grid fault layer 305, the grid fault layer includes grid fault events that affect the incorrect operation of protection components;
[0070] The computation layer 306 is used to establish a minimum complete event group based on risk source events, power grid fault events, and malfunctioning protection element events, and to calculate the probability of top-level events based on the minimum complete event group.
[0071] Preferably, the conditions that trigger an event that causes the protective element to malfunction include: a risk source event, a power grid failure event, and malfunction of other protective elements besides the one mentioned.
[0072] Preferably, it includes:
[0073] The logical relationship between multiple risk source events triggering incorrect operation of protective components is OR;
[0074] The logical relationship between multiple power grid fault events triggering incorrect operation of protection components is OR;
[0075] The logical relationship between events of incorrect operation of protection components, risk source events, power grid failure events, and events of incorrect operation of other protection components is AND;
[0076] The logical relationship between the malfunction of other protective elements and the malfunction of this protective element is AND;
[0077] The logical relationship between the top-level event and each device function event is OR.
[0078] Preferably, the device functional events include: incorrect operation of the time-limited protection and failure of the backup protection to operate;
[0079] The logical relationship between incorrect operation of the time-limited protection and incorrect operation of multiple protection elements is OR;
[0080] The logical relationship between the backup protection failure and multiple protection elements is AND; and the logical relationship between each backup protection failure and multiple backup protection element failures is AND.
[0081] The logical relationship between backup protection malfunction and multiple protection elements is OR.
[0082] Preferably, the risk source events include: channel failure risk, device aging risk, CT circuit disconnection risk, PT circuit multi-point grounding risk, power supply damage risk, CT circuit multi-point grounding risk, CT circuit insulation abnormality risk, PT circuit neutral wire disconnection risk, and pressure plate abnormality risk.
[0083] The risk source event assessment formula of this invention is as follows:
[0084] Channel failure risk assessment formula:
[0085]
[0086] p 1 represents the probability of channel failure. I diff The differential current is (A). I N Rated current (A). x 1a , x 1b There are two thresholds.
[0087] Channel failure risk assessment, such as Figure 5 As shown.
[0088] Formula for assessing equipment aging risk:
[0089]
[0090] p 2 represents the probability of equipment aging risk. t For device operating time, β , τ These are reliability parameters described using the Weibull distribution.
[0091] Equipment aging risk assessment, such as Figure 6 As shown.
[0092] CT circuit disconnection risk assessment formula:
[0093]
[0094] p 3 represents the probability of CT circuit disconnection.
[0095] PT circuit multi-point grounding risk assessment formula:
[0096]
[0097] p 4 represents the probability of multiple grounding risks in the PT circuit. U 0 represents the zero-sequence voltage (V). U The phase voltage is (V). x 4a The threshold value is used.
[0098] Risk assessment of multiple grounding points in PT circuits, such as Figure 7 As shown.
[0099] Power supply failure risk assessment formula:
[0100]
[0101] p 5 represents the probability of power supply failure. V The operating voltage is DC (V). V ref This is the reference value (V) for the DC operating voltage. x 5a The threshold value is used.
[0102] Power supply failure risk assessment, such as Figure 8 As shown.
[0103] Calculation formula for risk assessment of multiple grounding points in CT circuit:
[0104]
[0105] p 6 represents the probability of multiple grounding risks in the CT circuit. I (3) The third harmonic amplitude (mA) of the branch current. I (1) This represents the fundamental amplitude (mA) of the branch current.
[0106] Risk assessment of multiple grounding points in CT circuits, such as Figure 9 As shown.
[0107] CT circuit insulation abnormality risk assessment formula:
[0108]
[0109] p 7 represents the probability of insulation abnormality in the CT circuit. I ,I ref These are the sampling current and reference current (mA) of the device for same-source comparison. I N This is the secondary rated current (mA). x 7a The threshold value is used.
[0110] Risk assessment of insulation abnormalities in CT circuits, such as Figure 10 As shown.
[0111] PT circuit neutral wire breakage risk assessment formula:
[0112]
[0113] p 8 represents the probability of a break in the neutral wire of the PT circuit. U (3) The third harmonic amplitude (V) of the bus voltage. U 1) The fundamental amplitude (V) of the bus voltage. x 8a , x 8b There are two thresholds.
[0114] Risk assessment of neutral wire breakage in PT circuit, as follows Figure 11 As shown.
[0115] Formula for assessing abnormal pressure plate risk:
[0116]
[0117] p 9 represents the probability of pressure plate malfunction.
[0118] This invention Figure 4 Fault tree for risk assessment of line protection failure to operate under 3 / 2 connection. Figure 4 The fault tree is divided into five layers: the device layer, the device function layer (functions include main protection / backup protection, etc.), the protection element layer, the risk source quantitative assessment layer, and the power grid fault layer. Among them, "Protection 1 fails to operate" and "Protection 2 fails to operate" constitute the device layer; eight events such as "Protection 1 non-time-limited protection fails to operate" and "Protection 2 non-time-limited protection fails to operate" constitute the device function layer; twelve events such as "longitudinal differential" and "distance I" constitute the protection element layer; eighteen events such as "channel fault" and "component aging and damage" constitute the risk source quantitative assessment layer; and four events such as "fault within distance I of this line" and "fault outside distance I of this line" constitute the power grid fault layer.
[0119] In the 12 protection element failure events of the protection element layer, based on the attribution of the 12 protection elements, protection elements belonging to protection 1 are designated as ①~⑥, and protection elements belonging to protection 2 are designated as ❶~❻. The risk source quantitative assessment layer has a total of 18 risk source events, corresponding to protection 1 and protection 2, designated as A~I and a~i respectively. Figure 4 Each risk source's box indicates the protection components that these risk sources can affect. For example, the box labeled "A. Channel Fault" with "①" indicates that a channel fault event in the first set of protection systems may cause protection component ①—the longitudinal differential protection—to maloperate. There are a total of four grid fault events in the grid fault layer. Figure 4 Within each grid fault event box, the protective components that these grid fault events can affect are marked.
[0120] This invention takes the risk warning of relay protection device failure to operate in a 3 / 2 connection line as an example to elaborate on the method of risk warning of relay protection failure to operate in a line. The relay protection uses two sets of protection as backups for each other. Without loss of generality, this invention elaborates on the method using the fault tree construction of the first set of protection malfunction events and the risk assessment of malfunction as an example.
[0121] Part 1: Risk Assessment of Incorrect Actions in the Protection System and Construction of the Fault Tree
[0122] The function of the 3 / 2 connection line relay protection device is to disconnect line faults and serve as backup protection for adjacent primary equipment, such as busbars, transformers, and line faults, provided that the protection of the faulty primary equipment fails to operate. When there is a fault on the busbar where the line is located, a circuit breaker failure, or a high-resistance fault, the line protection will operate and remotely trip the opposite end.
[0123] First, according to the fault tree construction method for incorrect protection operation proposed in this invention, the fault tree for incorrect protection operation comprises a five-layer structure: device layer, device function layer (functions include main protection / backup protection, etc.), protection element layer, risk source quantitative assessment layer, and power grid fault layer. Specifically, the device layer is the top-level event in the fault tree describing the consequences of incorrect protection operation; the device function layer divides the line protection devices according to their functions, with incorrect operation consequences occurring in each specific function; the protection element layer divides protection into specific elements, such as longitudinal distance elements, longitudinal differential elements, and distance I-stage elements of line protection, with events constituting incorrect operation of protection elements; the risk source quantitative assessment layer consists of risk sources that can lead to incorrect operation of protection elements; and the power grid fault layer consists of power grid events that can trigger incorrect protection operation.
[0124] Next, the relationship between the risk source quantitative assessment layer and the protection element layer is established, that is, to determine which protection elements will malfunction under the conditions of events occurring in the risk source quantitative assessment layer, as shown in Table 1. Only when a risk source event meets the conditions is the malfunctioning (in this example, failure to operate) event of a protection element enabled. Since the malfunctioning (in this example, failure to operate) event of a protection element occurs when any risk source event related to the protection element occurs, the impact of risk source events on the malfunctioning event of protection elements is expressed using an "OR" gate in the fault tree. Simultaneously, the correlation between malfunctioning protection elements and power grid faults is established, such as...
[0125] As shown in Table 2, the malfunctioning event of the protection element is only enabled when the corresponding power grid fault event meets the conditions. The occurrence of any one of the different power grid fault events provides the conditions for triggering malfunctioning protection; therefore, the impact of the power grid fault event on the malfunctioning event of the protection element is expressed using an "OR" gate in the fault tree. The interrelationship table of the protection elements is shown below.
[0126] As shown in Table 3, the meaning is that if the influencing protective element does not operate, the affected element has the condition to operate; if the influencing protective element has already operated, the affected element does not have the condition to operate. Specifically, in the case of a protective element refusing to operate, the affected element has the condition to refuse to operate only when the influencing element's refusing-to-operate event is satisfied; otherwise, the affected protective element does not have the condition to refuse to operate, and the affected element's refusing-to-operate event does not occur. An affected protective element is simultaneously influenced by multiple influencing protective elements. If any influencing protective element's refusing-to-operate event does not occur, the affected protective element's refusing-to-operate event does not have the condition to occur. Therefore, the influence of multiple influencing elements on the affected element is expressed using an AND gate in the fault tree. Risk source events, power grid fault events, and other protective element incorrect operation (refusing to operate in this example) events are all conditions for the protective element incorrect operation (refusing to operate in this example) event. There is an AND logical relationship between the protective element incorrect operation (refusing to operate in this example) event and the risk source event, power grid fault event, and other protective element incorrect operation events. (See Table 1 for details.)
[0127] Table 2
[0128] Table 3 shows the fault tree connections between the protection element layer, the quantitative risk source assessment layer, the power grid fault layer, and the protection element layers. Figure 4 As shown.
[0129] Table 1. Correlation between Risk Sources and Incorrect Protective Actions
[0130]
[0131] Table 2 Correlation between Power Grid Faults and Incorrect Protection Actions
[0132]
[0133] Table 3. Interrelationships between protective components
[0134]
[0135] Next, this invention performs device functional layer modeling, dividing the protection elements according to their protection functions. Longitudinal differential protection and longitudinal distance protection are full-line fast-acting main protections. Distance Section I is the main protection for a portion of the line length. When the power grid fault point is within Distance Section I of this line, the functions of longitudinal differential protection, longitudinal distance protection, and Distance Section I can be classified as "time-limited protection." When the power grid fault point is outside Distance Section I of this line, the functions of longitudinal differential protection and longitudinal distance protection can be classified as "time-limited protection." Distance Section II is the backup protection for this line, and its operating time is only one time period longer than time-limited protection; its function can be classified as "backup protection for this line." Distance Section III and Zero-Sequence Section III have longer operating times than Distance Section II. In addition to serving as backup protection for this line, they are also backup protection for adjacent primary equipment, such as busbars, transformers, and lines, in cases where the protection of the faulty equipment fails to operate; their function can be classified as "backup protection for external faults." Furthermore, the line protection also has remote transmission / remote tripping functions. For non-time-delay protection, all protective elements should operate when a primary equipment fault occurs. The failure of the non-time-delay protection function to operate is related to the failure of each protective element to operate ("OR" relationship). For backup protection (including "backup protection for this line" and "backup protection for external faults"), since the operation of any one protective element in the dual protection system resets the others, the failure of the backup protection function to operate is related to the failure of each protective element to operate ("AND" relationship). Therefore, the impact of the failure of the corresponding protective element in the "backup protection for this line" and "backup protection for external faults" functions on the protection function events is expressed using AND gates in the fault tree. A backup protection function is considered to have failed to operate only when all backup protective elements in the dual protection system fail to operate. Therefore, for any dual protection system, the protective elements related to its "backup protection for this line" and "backup protection for external faults" functions include not only the corresponding protective elements of the current line protection device but also the corresponding protective elements of the other line protection device. The impact of a remote transmission / trip element failure event in dual-protection systems on the failure event of the remote transmission / trip function is expressed using AND gates in the fault tree. For the protection device as a whole, a failure to operate is a combination of failures of individual protection functions; therefore, an OR relationship exists between the various protection functions in a failure to operate. Based on this, the connections between the device layer and the device function layer, and between the device function layer and the protection element layer, are constructed in the fault tree for 3 / 2 wiring line protection failure to operate. Figure 4 As shown.
[0136] like Figure 12The present invention provides a method for calculating the probability of top-level events based on an incorrect action risk assessment system, comprising:
[0137] Step 101: Establish a minimum complete event group based on risk source events, power grid fault events, and malfunctioning protection element events;
[0138] Step 102: Calculate the probability of the top-level event based on the minimum complete event group.
[0139] Among them, the risk source events originate from the quantitative risk source assessment layer included in the incorrect action risk assessment system;
[0140] Power grid failure events originate from the power grid failure layer included in the incorrect action risk assessment system;
[0141] Incorrect operation events of protection components originate from the protection component layer included in the incorrect operation risk assessment system, and are categorized into different incorrect operation of protection components.
[0142] Preferably, a minimum complete event group is established based on risk source events, power grid fault events, and malfunctioning protection element events, including:
[0143] Based on risk source events, power grid fault events, and malfunctioning protection element events, multiple minimal complete events that trigger multiple malfunctioning protection actions are generated, and these multiple minimal complete events are combined into a minimal complete event group.
[0144] Preferably, the probability of the top-level event is calculated based on the minimum complete event set, including:
[0145] The probability of the minimum complete event group is calculated based on the probability of each minimum complete event, and the probability of the minimum complete event group is used as the probability of the top-level event.
[0146] Preferably, generating multiple minimal complete events that trigger multiple incorrect protection actions includes:
[0147] Identify power grid failure events;
[0148] Multiple base events that cause incorrect operation of protection components under the direct or combined effects of power grid fault events are obtained. The union of each base event with the power grid fault event is generated separately and the resulting unions are used as the minimum complete event.
[0149] This invention performs probability calculations for events at the top level of the fault tree.
[0150] First, an equivalent calculation method for the top event probability is proposed. Then, based on this equivalent calculation method and combined with the characteristics of the fault tree of incorrect protection actions, a heuristic top-level event probability calculation method is proposed.
[0151] Assume there is a total KEach of the following is a fundamental event, and each fundamental event has two possible outcomes: it occurs or it does not occur. K Arrange and combine the occurrence or non-occurrence of each of the following 2 possible scenarios: K There are several scenarios, and the probability of each scenario is the product of the probabilities of each base event taking the values of either occurrence or non-occurrence, i.e. p i = p 1( x 1= x 1i )··· p K ( x K = x Ki If the top event corresponding to this situation does not occur, then... p i As a component of the probability of the top event occurring. It can be seen that this method is effective for 2... K In each of the following scenarios, logical operations are performed to determine whether the top event has occurred. K The operation of multiplying the probabilities of several events together and then summing them up at the end results in a large amount of computation.
[0152] Therefore, an equivalent calculation method is proposed:
[0153] Will K Each of the base events is labeled as follows: X 1, X 2,…, X K The problem is transformed into searching for a minimal complete set of events. L ={ Θ 1,…, Θ H}, each minimal complete event Θ h yes K The bottom line event X 1, X 2,…, X K A disordered combination, namely Θ { X 1, X 2,…, X K},Will X Each bottom event in the algorithm is set to 1, and the top event occurs, but when the bottom event is removed... Θ After any of the bottom events, the top event no longer occurs. Furthermore, for a complete event that satisfies the condition that the top event occurs... Φ 1. Φ 2, if Φ 1 Φ 2, then Φ 2. Non-minimum complete events. Search for all unique minimum complete events. Θ To form a minimum complete event set L The product of the probabilities of any base event in each minimal complete event is taken as the minimal complete event. Θ probability The sum of the probabilities of all minimal perfect events is the probability of the top event, i.e. .
[0154] Applying the above algorithm, the calculation of the probability of the top event of the incorrect action is transformed into searching for the minimum complete event set. L Calculate each minimal complete event Θ The probabilities are calculated and summed. For this scenario, the minimum complete event set is... L The method for determining it is:
[0155] ① Take any power grid fault event X f ;
[0156] ② Take power grid fault events X f Protective elements that can directly cause incorrect protection operation Y e1 ,…, Y eC (common C (Item), which will select one by one the underlying events that could cause these protective components to operate incorrectly, namely {{ X s These underlying events are respectively related to power grid fault events. X f Perform a union to form the minimum complete event. Θ ;
[0157] ③ Take power grid fault events X f Protective elements that require the combined action of both sides to cause incorrect protection operation Y e1 ,…, Y eD (common D (Item), these protective elements are divided into protective elements of protective device 1. Y e1 ,…, Y eE (Item E in total) and the protective elements of protection device 2 Y e1 ,…, Y eF (F items in total), minimal complete events Θ Will be caused by power grid failure events Xf A set of events that cause the protective elements of protection device 1 to malfunction. Φ 1 and the set of events that cause the protective element of protection device 2 to malfunction. Φ 2. Calculated by taking the union of the sets. For Φ 1. Firstly, searching can trigger... E Events where all protective components malfunction and were not detected in step ② Φ 11 ={{ X g Remove {{ from the underlying events related to protection device 1}} X s}}as well as Φ 11 The events in the sequence, when searched for from the remaining events, all lead to various unique combinations. Y e1 ,…, Y eE Simultaneous occurrence and removal of any one of the events in the combination. Y e1 ,…, Y eE Not all of them occur, denoted as Φ 12 , Φ 1= Φ 11 + Φ 12 Similarly, we can obtain Φ 2. It is evident that, Φ 1 and Φ 2 are both sets of sets, and will Φ 1 and Φ Perform another permutation, combination, and union operation on each set in step 2, and then merge them with { X f} constitutes the minimum complete event Θ ;
[0158] ④ The minimum complete events obtained in steps ② and ③ Θ All added to L middle;
[0159] ⑤ Select each power grid fault event and repeat steps ② to ④ in sequence to obtain... L .
[0160] The probability of protecting the top event of incorrect action is obtained by replacing each event in the minimum complete event group with the event occurrence probability. The event occurrence probabilities corresponding to each event in each minimum complete event are first multiplied together to obtain the probability value of the contribution of the minimum complete event to the occurrence of the top event. The probability values contributed by different minimum complete events are added together to obtain the probability of protecting the top event of incorrect action.
[0161] Finally, the probability of each risk source event in the risk source assessment layer is calculated, and the assessment is carried out using relay protection online monitoring and inspection information.
[0162] Part Two: Calculation of the Probability of Top-Level Events in the Fault Tree
[0163] First, based on Figure 4 The minimum complete set of events that can trigger a line protection failure is determined. The search process is as follows:
[0164] (1) Identify the power grid fault events that can cause the line protection to fail to operate, namely: faults within the distance of this line from section I. X γ The fault is located outside the range of section I of this line. X β External fault and external protection malfunction X α High-voltage / busbar fault or circuit breaker failure X δ ;
[0165] (2) For faults within the range of section I of this line X γ The protection functions that can cause line protection to fail to operate are time-delay protection functions, the line's backup protection functions, and the backup protection functions for external faults. Among these, the failure of time-delay protection functions can be caused by the failure of longitudinal differential protection or distance I stage protection. Among the risk sources, channel faults... X A It can cause longitudinal differential to fail to operate and components to age and be damaged. X B This can cause longitudinal differential or distance segment I failure to move, or CT circuit disconnection. X C This can cause the first stage of the distance circuit to fail to operate, and multiple grounding points in the PT circuit. X D This can cause the first stage of the distance to fail to operate and the power supply to be damaged. X E This can cause longitudinal differential or distance I stage malfunction, and multiple grounding points in the CT circuit. X F This can cause the first stage of the circuit to fail to operate and the CT circuit insulation to be abnormal. X G This can cause the first stage of the circuit to fail to operate, or the neutral line of the PT circuit to break. X H This can cause the first stage of the distance to fail to move and the pressure plate to malfunction. X I This can cause longitudinal differential motion or failure to move in segment I of the distance, indicating that... X γ Under the condition of superposition X A, X B , X C , X D , X E , X F , X G , X H , X I Both can lead to the failure of the time-limited protection function to operate, thereby causing the line protection to fail to operate. X γ The following events can directly cause the line protection to fail to operate: X A , X B , X C , X D , X E , X F , X G , X H , X I These bottom events are respectively compared with X γ By performing a union operation, we can obtain the minimum complete event. Θ ,include{ X γ , X A}、{ X γ , X B}、{ X γ , X C}、{ X γ , X D}、{ X γ , X E}、{ X γ , X F}、{ X γ , X G}、{ Xγ , X H}、{ X γ , X I}. remove X A , X B , X C , X D , X E , X F , X G , X H , X I Risk sources and underlying events also X a , X b , X c , X d , X e , X f , X g , X h , X i Any combination of the remaining 9 minimum events does not result in the line protection failing to operate, and therefore cannot be further expanded to include the minimum complete event set. Θ .
[0166] (3) For faults outside the range of section I of this line X β The protection functions that can cause line protection to fail to operate are time-delay protection functions, the line's backup protection functions, and backup protection functions for external faults. Among these, the failure of time-delay protection functions can be caused by the failure of longitudinal differential protection. And among the risk sources, channel faults... X A Component aging and damage X B Power supply failure X E Or the pressure plate is faulty X I This can cause the longitudinal differential protection to fail to operate, which in turn leads to the failure of the time-delay protection function and the failure of the line protection to operate. X A , XB , X E , X I respectively with X β By performing a union operation, we can obtain the minimum complete event. Θ ,include{ X β , X A}、{ X β , X B}、{ X β , X E}、{ X β , X I}. remove X A , X B , X E , X I Risk sources and underlying events also X C , X D , X F , X G , X H , X a , X b , X c , X d , X e , X f , X g , X h , X i Because the backup protection function of protection 1 for this line only occurs when all time-limited protection functions fail to operate, and the event... X A , X B , X E , X IIt can independently cause the failure of the indefinite-time protection function to operate, or the occurrence of the failure condition of the backup protection function to operate, or by... X A , X B , X E , X I Cause, or X A , X B , X E , X I This is part of the condition for the backup protection function to fail to operate. Based on the search target—the smallest set of bottom events that can cause the top event of protection failure to operate, any combination of the remaining bottom events cannot independently cause the backup protection function or even the line protection to fail to operate, and this step of the search ends.
[0167] (4) For external faults and external protection refusing to operate X α The protection function that can cause line protection to fail to operate is the backup protection function for external faults. X α The following protection components require a combined effect to cause the line protection to fail to operate: distance stage III and zero-sequence stage III of protection 1, and distance stage III and zero-sequence stage III of protection 2. For protection 1, the risk source is caused by aging or damage to the components. X B CT circuit disconnection X C Power supply failure X E CT circuit multi-point grounding X F CT circuit insulation abnormality X G Pressure plate error X I This is a risk source event that simultaneously causes both distance segment III and zero-sequence segment III to refuse to move. Φ 11 ={ X B , X C , X E , X F , X G , X I}; remove Φ 11 Subsequently, the risk sources for protection 1 include X A ,X D , X H Any combination of these elements cannot constitute the result that both the distance segment III and the zero-sequence segment III of protection 1 will fail to activate. Φ 1= Φ 11 ={ X B , X C , X E , X F , X G , X I Similarly, we obtain Φ 2={ X b , X c , X e , X f , X g , X i},Will Φ 1 and Φ Perform another permutation, combination, and union operation on each set in step 2, and then merge them together. X α This constitutes the minimum complete event { X α , X B , X b}{ X α , X B , X c}{ X α , X B , X e}{ X α , X B , X f}{ X α , X B , X g}{ X α ,X B , X i}{ X α , X C , X b}{ X α , X C , X c}{ X α , X C , X e}{ X α , X C , X f}{ X α , X C , X g}{ X α , X C , X i}{ X α , X E , X b}{ X α , X E , X c}{ X α , X E , X e}{ X α , X E , X f}{ X α , X E , X g}{ X α , XE , X i}{ X α , X F , X b}{ X α , X F , X c}{ X α , X F , X e}{ X α , X F , X f}{ X α , X F , X g}{ X α , X F , X i}{ X α , X G , X b}{ X α , X G , X c}{ X α , X G , X e}{ X α , X G , X f}{ X α , X G , X g}{ X α , X G ,X i}{ X α , X I , X b}{ X α , X I , X c}{ X α , X I , X e}{ X α , X I , X f}{ X α , X I , X g}{ X α , X I , X i This search step is now complete.
[0168] (5) For high-voltage / busbar faults or circuit breaker failures X δ The protection function that can cause the line protection to fail to operate is remote transmission / remote tripping, similar to step (4), resulting in... Φ 1={ X B , X E , X I}、 Φ 2={ X b , X e , X i}, constituting the minimum complete event { X δ , X B , X b}{ X δ , X B , X e}{X δ , X B , X i}{ X δ , X E , X b}{ X δ , X E , X e}{ X δ , X E , X i}{ X δ , X I , X b}{ X δ , X I , X e}{ X δ , X I , X i};
[0169] (6) Take the union of the minimal complete events Θ from steps (2) to (6) to obtain the minimal complete event set. L ={{ X γ , X A}{ X γ , X B}{ X γ , X C}{ X γ , X D}{ X γ , X E}{ X γ , X F}{ Xγ , X G}{ X γ , X H}{ X γ , X I}{ X β , X A}{ X β , X B}{ X β , X E}{ X β , X I}{ X α , X B , X b}{ X α , X B , X c}{ X α , X B , X e}{ X α , X B , X f}{ X α , X B , X g}{ X α , X B , X i}{ X α , X C , X b}{ X α , X C ,X c}{ X α , X C , X e}{ X α , X C , X f}{ X α , X C , X g}{ X α , X C , X i}{ X α , X E , X b}{ X α , X E , X c}{ X α , X E , X e}{ X α , X E , X f}{ X α , X E , X g}{ X α , X E , X i}{ X α , X F , X b}{ X α , X F , Xc}{ X α , X F , X e}{ X α , X F , X f}{ X α , X F , X g}{ X α , X F , X i}{ X α , X G , X b}{ X α , X G , X c}{ X α , X G , X e}{ X α , X G , X f}{ X α , X G , X g}{ X α , X G , X i}{ X α , X I , X b}{ X α , X I , X c}{X α , X I , X e}{ X α , X I , X f}{ X α , X I , X g}{ X α , X I , X i}{ X δ , X B , X b}{ X δ , X B , X e}{ X δ , X B , X i}{ X δ , X E , X b}{ X δ , X E , X e}{ X δ , X E , X i}{ X δ , X I , X b}{ X δ , X I , X e}{ Xδ , X I , X i}}.
[0170] Then, based on the minimum complete event group L And the probabilities of each base event, and the probability of the top event, i.e., p = pγpA + pγpB + pγpC + pγpD + pγpE + pγpF + pγpG + pγpH + pγpI + pβpA + pβpB + pβ p E + p β p I + p α p B p b + p α p B p c + p α p B p e + p α p B p f + p α p B p g + p α p B p i + p α p C p b + p α p C p c + p α p C p e + pα p C p f + p α p C p g + p α p C p i + p α p E p b + p α p E p c + p α p E p e + p α p E p f + p α p E p g + p α p E p i + p α p F p b + p α p F p c + p α p F p e + p α p F pf + p α p F p g + p α p F p i + p α p G p b + p α p G p c + p α p G p e + p α p G p f + p α p G p g + p α p G p i + p α p I p b + p α p I p c + p α p I p e + p α p I p f + p α pI p g + p α p I p i + p δ p B p b + p δ p B p e + p δ p B p i + p δ p E p b + p δ p E p e + p δ p E p i + p δ p I p b + p δ p I p e + p δ p I p i 。
[0171] In terms of modeling the risk assessment of incorrect protection operation, this invention proposes for the first time to model the risk of incorrect operation of protection elements. It establishes the correlation between the risk of incorrect operation of protection elements and various risk sources of the device (the risk magnitude of risk source events is assessed through online monitoring and inspection information), power grid fault conditions, and the operation of other relay protection elements. It also combines protection elements according to their functions and scientifically expresses the derivation method of incorrect operation of the same function protection element on the overall incorrect operation of the device. That is, the failure events of each protection element in the non-time-limited protection function have OR logic, while the failure events of each protection element in the backup protection function have AND logic (the input events of the AND gate take into account the case of dual protection configuration). It establishes a fault tree for the risk assessment of incorrect protection operation, which covers a five-layer structure: device layer, device function layer (functions include main protection / backup protection, etc.), protection element layer, risk source quantitative assessment layer, and power grid fault layer.
[0172] This invention equates the calculation of the probability of the top event occurrence to searching for a minimum complete event set. It proposes a method for determining the minimum complete event set in the calculation of the probability of the top event of incorrect protection operation. Each power grid fault event is selected sequentially. Starting from the protection element that can cause incorrect protection operation, the risk source that can directly cause the protection element to operate incorrectly is searched. When multiple protection elements need to operate incorrectly, the protection elements are divided according to the protection package. The minimum risk source event combination that can simultaneously cause these protection elements to operate incorrectly is searched from the remaining risk source events. The minimum risk source event combination found is combined with the power grid fault event and added to the minimum complete event set in sequence. Finally, the probability of the top event of incorrect protection operation is calculated based on the minimum complete event set.
[0173] This invention proposes a computer-readable storage medium storing a computer program for executing a method for calculating the probability of a top-level event based on an incorrect action risk assessment system.
[0174] This invention proposes an electronic device, characterized in that the electronic device comprises: a processor and a memory; wherein,
[0175] Memory, used to store processor-executable instructions;
[0176] A processor for reading executable instructions from memory and executing those instructions to implement a method for calculating the probability of top-level events based on an incorrect action risk assessment system.
[0177] The invention has been described with reference to a few embodiments. However, as will be known to those skilled in the art, and as defined in the appended claims, other embodiments besides those disclosed above fall equivalently within the scope of the invention.
[0178] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless otherwise expressly defined herein. All references to “a / / the [device, component, etc.]” are openly interpreted as at least one instance of the device, component, etc., unless otherwise expressly stated. The steps of any method disclosed herein are not necessarily to be performed in the exact order disclosed, unless explicitly stated otherwise.
Claims
1. A risk assessment system for incorrect actions, the system comprising: Device layer, which is used to set at least two top-level events to protect against incorrect actions; Conditions that trigger an event that causes a protective element to malfunction include: a risk source event, a power grid failure event, and malfunction of other protective elements besides the one mentioned. The logical relationship between multiple risk source events triggering incorrect operation of the protection element is OR; The logical relationship between multiple power grid fault events causing the protection element to malfunction is OR; The logical relationship between the malfunctioning event of the protection element, the risk source event, the power grid failure event, and other malfunctioning events of the protection element besides the protection element is AND; The logical relationship between the malfunction of other protective elements besides this protective element and the event that causes the malfunction of the protective element is AND; The logical relationship between the top-level event and each device function event is OR; The device function layer includes device function events corresponding to different incorrect protection actions, used to determine the correlation between device function events and incorrect protection element action events in the protection element layer; the device function events include: incorrect action of non-time-delay protection and failure of backup protection to operate; The logical relationship between the incorrect action of the time-limitless protection and the incorrect action of multiple protection elements is OR; The logical relationship between the backup protection failure and the plurality of protection elements is AND; and the logical relationship between each backup protection failure and the failure of the plurality of backup protection elements is AND. The logical relationship between backup protection malfunction and multiple protection elements is OR; A protection element layer, the protection element layer including protection element malfunction events belonging to different protection malfunctions; A quantitative risk source assessment layer, which includes risk source events that affect the incorrect operation of protection components; A power grid fault layer, which includes power grid fault events that affect the incorrect operation of the protection element; The calculation layer is used to establish a minimum complete event group based on the risk source event, the power grid fault event, and the malfunctioning protection element event, and to calculate the top-level event probability based on the minimum complete event group.
2. The system according to claim 1, wherein the risk source event includes: Risks include channel failure, device aging, CT circuit disconnection, PT circuit multi-point grounding, power supply damage, CT circuit multi-point grounding, CT circuit insulation abnormality, PT circuit neutral wire disconnection, and pressure plate abnormality.
3. A method for calculating the probability of a top-level event, applied to the incorrect action risk assessment system of claim 1, the method comprising: Establish a minimum complete event group based on risk source events, power grid failure events, and malfunctioning protection element events; Calculate the probability of the top-level event based on the minimum complete event group; The risk source event originates from the risk source quantitative assessment layer included in the incorrect action risk assessment system; The power grid failure event originates from the power grid failure layer included in the incorrect action risk assessment system; The malfunction events of the protection elements originate from the protection element layer included in the malfunction risk assessment system, and the malfunction events of the protection elements are attributed to different malfunctions of protection.
4. The method for calculating the probability of top-level events according to claim 3, establishing a minimum complete event group based on risk source events, power grid fault events, and the malfunctioning event of the protection element, includes: Based on risk source events, power grid fault events, and incorrect operation events of the protection elements, multiple minimal complete events are generated that trigger multiple incorrect protection operations, and these multiple minimal complete events are combined into a minimal complete event group.
5. The method for calculating the probability of a top-level event according to claim 4, wherein the probability of a top-level event is calculated based on the minimum complete event set, includes: The probability of the minimum complete event group is calculated based on the probability of each minimum complete event, and the probability of the minimum complete event group is used as the top-level event probability.
6. The method for calculating the probability of a top-level event according to claim 4, wherein generating multiple minimal complete events that trigger multiple incorrect protection actions includes: Identify power grid failure events; Multiple base events that cause the protection element to operate incorrectly under the direct or combined effects of the power grid fault event are obtained. Multiple non-repeating unions of the base events with the power grid fault event are generated, and the generated unions are used as the minimum complete event.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program for performing the method of any one of claims 3-6.
8. An electronic device, characterized in that, The electronic device includes: a processor and a memory; wherein, The memory is used to store the processor-executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method of any one of claims 3-6.