A system and method for automatically launching and retreating a standby pressure plate based on active-active architecture

By adopting a dual-active architecture of the backup self-pressure plate automatic withdrawal system in the power system, problems such as long investment time and low switching efficiency in traditional systems are solved, and the system is high reliability and stability is achieved, and the high reliability requirements of modern power systems are met.

CN119382314BActive Publication Date: 2025-06-10GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411585853.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-08
Publication Date
2025-06-10
Estimated Expiration
2044-11-08

AI Technical Summary

Technical Problem

The traditional automatic withdrawal system of self-investment pressure plates has problems such as long investment time, low switching efficiency, easy aging of backup equipment, and low fault tolerance, which cannot meet the high reliability requirements of modern power systems.

Method used

The automatic withdrawal system of self-pressure plates based on dual active architecture is adopted. By deploying two identical active systems, data synchronization and status replication are performed to realize automatic withdrawal and rapid main and backup system switching of self-pressure plates.

Benefits of technology

It greatly improves the reliability and stability of the system, reduces the risks of manual operation and adjustment, improves the availability and reliability of the system, and ensures the high and reliable operation of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure BDA0005124263840000141
    Figure BDA0005124263840000141
Patent Text Reader

Abstract

The present invention discloses an automatic switching system and method for standby pressure plates based on a dual-active architecture, including a dual-active system, both of which have the ability to perform real-time calculations; the active system and the standby system switch seamlessly with each other; a well-designed fault detection mechanism, which monitors the communication status and operating status of the system through a heartbeat test; data synchronization of the dual-active system is the key to ensuring data consistency between systems, and measures are taken to ensure the timeliness and security of data synchronization, avoiding data errors caused by inconsistent business data; integrating a variety of autonomous judgment and self-rescue functions, and being able to automatically complete fault switching, recovery and early warning under abnormal circumstances. Improve the stability and security of the system, improve the switching efficiency of the disaster recovery system, and ensure that when the main system of the OCS system is unavailable, it can quickly switch to the standby system, minimizing the impact on the power grid dispatching and production work.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power system applications, and more particularly to an automatic switching-in and switching-out system and method for backup power supply switching plates based on a dual-active architecture. Background Art

[0002] In the operation of a power system, main transformers and lines with voltage levels of 220 kV and below usually operate in a radial power supply mode. To ensure power supply reliability, a backup power supply automatic switching device (BATS) is usually installed inside a substation. When a power grid fault causes a bus outage, the backup power supply that meets the conditions will act to supply power to the outage bus, thus greatly reducing the probability of bus outages and ensuring power supply reliability. The traditional automatic switching-in and switching-out system for backup power supply switching plates adopts a unidirectional master-slave mode design. When a system fault occurs, various key data verification tasks need to be carried out during the master-slave switchover to ensure the safety of power grid dispatching work. This operation mode has disadvantages such as long input time, low switching efficiency, easy aging of standby equipment, and low fault tolerance rate, and cannot meet the high-reliability requirements of modern power systems. In addition, when the main system exits operation and the standby system is put into operation, calculation data and operation records cannot be automatically synchronized in reverse to the main system, and the entire system will lose its backup ability, thus affecting the operation of the entire power system. In the case where the main system is unavailable and a power grid accident occurs, it will cause significant losses to the power grid. Summary of the Invention

[0003] The purpose of the present invention is to solve the above problems, and to provide an automatic switching-in and switching-out system and method for backup power supply switching plates based on a dual-active architecture. Through the design of the dual-active architecture, the automatic switching-in and switching-out of backup power supply soft switching plates is realized, and the master-slave system switching can be carried out quickly. Two completely identical active systems are deployed, and operations such as data synchronization and status replication are performed to ensure that the dual-active systems can be synchronized in real time and maintain consistent status and data. At the same time, each system can automatically calculate the switching-in and decommissioning strategies for backup power supply soft switching plates, but only one system performs remote control operations according to the strategy. The advantages and characteristics of this method are that it can greatly improve the reliability and stability of the system, reduce the risks of manual operation, adjustment, and intervention, and thus improve the availability and reliability of the system.

[0004] The technical solution adopted by the present invention to solve its technical problems is:

[0005] An automatic switching-in and switching-out system for backup power supply switching plates based on a dual-active architecture includes a system for real-time calculation, a control right switching system, a fault detection system, a data synchronization system, and a data verification system.

[0006] Furthermore, the dual-active system is a highly intelligent system developed and applied based on EMS. The steps for its real-time calculation of the switching-in and switching-out of the backup power supply of the power grid are as follows:

[0007] 1) Online switching strategy of automatic backup based on transformer oil temperature

[0008] In actual operation, the short-term overload capacity of the transformer is closely related to the oil temperature. The oil temperature of the main transformer is a key indicator reflecting the status of the equipment. Specifically, if the oil temperature of the associated transformer exceeds the preset value, the system will automatically exit the standby mode to avoid overheating risks; if the oil temperature is within a safe range, the system may consider switching on based on other conditions;

[0009] 2) N-1 verification

[0010] The N-1 fault analysis of the automatic backup pressure plate is a subset of the traditional N-1 calculation. According to the characteristics of the regional power grid, a new processing method is adopted. This method is based on the base state topology, establishes the automatic backup action model by searching the power supply key path, and uses the load transfer method to greatly shorten the processing time.

[0011] 3) Bad data processing

[0012] Since the pressure plate activation and deactivation strategy is based on the main transformer oil temperature calibration and real-time N-1 calibration, the following bad data situations need to be considered:

[0013] a) If the oil temperature of the relevant transformer is abnormal, and the standby automatic start setting takes the oil temperature factor into consideration, the current operating state of the standby automatic start pressure plate shall be maintained unchanged;

[0014] b) In the state estimation calculation, if bad data is detected in the 220kV main transformer related to the backup automatic switch, the 220kV main transformer will not be checked;

[0015] c) In the state estimation calculation, if bad data is detected in the 110kV main transformer or 110kV line, the current operating state of the backup automatic voltage board is maintained unchanged;

[0016] 4) Handling abnormal situations

[0017] During the execution of the pressure plate launch and withdrawal of the standby automatic start-up, the following abnormal situations need to be considered: 1) SCADA telemetry data is not refreshed; 2) state estimation does not converge; 3) the maximum number of remote control times per hour for the standby automatic start-up is limited; 4) the maximum number of remote control times per day for the standby automatic start-up is limited.

[0018] Furthermore, in step 1), the platen insertion and withdrawal strategy taking into account the oil temperature and the initial load rate is as follows:

[0019] 1) 220kV main transformer oil temperature and initial load rate detection;

[0020] a) For a 220kV main transformer, if the initial load rate exceeds 0.9, the corresponding standby automatic switch should be locked;

[0021] b) For a certain 220 kV main transformer, if the initial load rate exceeds 0.85 and simultaneously meets the condition that the oil temperature exceeds 85 °C or the winding temperature exceeds 105 °C, the corresponding bus transfer switch should also be blocked.

[0022] 2) Detection of oil temperature and initial load rate of 110 kV main transformer

[0023] a) For a certain 110 kV main transformer, if the initial load rate exceeds 0.85, the corresponding bus transfer switch should be blocked.

[0024] b) For a certain 110 kV main transformer, if the initial load rate exceeds 0.85 and simultaneously meets the condition that the oil temperature exceeds 85 °C (settable) or the winding temperature exceeds 105 °C, the corresponding bus transfer switch should also be blocked.

[0025] Furthermore, in step 2), the fault analysis and processing method is as follows:

[0026] 1) Determine the bus transfer switch actuated due to N - 1 fault based on power supply path search

[0027] When the bus transfer switch system meets the charging condition, if the working bus loses power while the standby power supply is energized, the bus transfer switch will be activated.

[0028] 2) Detailed processing based on power supply path search

[0029] During power supply path search, we start from the 220 kV bus and generator nodes as the root nodes. The specific logic is as follows: Simulate disconnecting the 220 kV line switch, establish the relationship between nodes and branches; Use depth - first search downward, record the power supply paths of the low - voltage buses encountered; Establish the mapping relationship between equipment and the bus transfer switch buses; Identify loop information, and loop equipment faults will not cause the bus transfer switch to act; If the equipment has mapping relationships with both the working bus and the standby bus, it is regarded as homologous equipment, and its fault will not trigger the bus transfer switch; Record the number of power supply points related to the bus transfer switch, determine the key power supply path equipment, and its fault will trigger the bus transfer switch to act.

[0030] 3) Processing of bus transfer switch enabling and disabling strategy based on multiple objectives

[0031] When a specific N - 1 fault causes N bus transfer switch actions, if all these bus transfer switch actions lead to overload of grid components, while when less than all of the bus transfer switch actions occur, there is no overload of other grid components. Obviously, in this case, blocking all bus transfer switches comprehensively is not practical. In fact, only some of the bus transfer switches need to be blocked. Therefore, set priorities for each bus transfer switch.

[0032] V pri = 10000×V run + 1000×V pid - int(V bus ) + 4000 - Vvip ×3000

[0033] Where: V pri is the calculated priority of the automatic bus transfer device (ABT), and the smaller the value, the higher the level; V run is the function enable / disable flag. When it is locally disabled, the value is 2; when it is under automatic control, the value is 1; otherwise, the value is 0; V pid is the factor value of the ABT pressure plate. When there is a pressure plate ID, the value is 1; otherwise, the value is 0; V bus is the active power of the operating bus of the ABT; V vip is the factor of important users for the ABT. When there are important users, the value is 1; otherwise, the value is 0.

[0034] Furthermore, the control right switching system realizes seamless mutual switching of the control right between the main dispatching system and the backup dispatching system;

[0035] The system is provided with two control right marking points. Each marking point has two state values, representing having the control right and not having the control right respectively, and the states of these two marking points always remain mutually exclusive. The main dispatching system is responsible for real-time monitoring of the state of the main dispatching control right marking point, while the backup dispatching system real-time detects the state of the backup dispatching control right marking point. The switching operation of the system is essentially completed by exchanging the state values of these two control right marking points, thereby realizing seamless handover of the control right;

[0036] The calculation process of the system can be divided into two major links: strategy calculation and strategy execution. The strategy calculation link is responsible for calculating the enable / disable strategies of each ABT according to the current operating conditions of the power grid, while the strategy execution link, based on the results of the strategy calculation, enables / disables the soft pressure plate of the ABT through remote control. In the main and backup dispatching systems, only the strategy execution link will detect its own control right marking point. When the marking point shows "having the control right", remote control will be executed; otherwise, it will not be executed.

[0037] Furthermore, the fault detection system is a well-designed fault detection mechanism;

[0038] The main dispatching system and the backup dispatching system adopt a heartbeat detection mechanism. These two systems will periodically send heartbeat packets to the message queue server to detect the operating state of the server;

[0039] If within the set time window, the main dispatching or backup dispatching system fails to receive the heartbeat information sent by itself or the other party, then the system will immediately determine it as a communication fault and take corresponding fault handling measures;

[0040] And when the system normally receives the heartbeat information of itself and the other party again, it indicates that the communication link has been restored and the data synchronization work can continue.

[0041] Furthermore, the steps for the data synchronization system to achieve data backup and synchronization are as follows;

[0042] 1) Pre-synchronization authentication

[0043] The control right of the system is judged and obtained through SCADA detection points. For this purpose, the platform specially provides two detection points: the main control right detection point (marked as: A1) and the standby control right detection point (marked as: B1). These two detection points are mutually exclusive within the same system, which means that at the same time, only one detection point can represent having the control right. At the same time, these two detection points are corresponding in two different systems and have the same function and meaning;

[0044] 2) Data backup

[0045] Each time the strategy is calculated, the switching status of the backup power supply automatic switching device is calculated using the current operation mode and status;

[0046] 3) Data synchronization.

[0047] Furthermore, the data synchronization steps are as follows:

[0048] 1) Data classification

[0049] It is mainly divided into the following categories:

[0050] a System interface operation data: When the user performs system parameter maintenance through the human-machine interface, the relevant maintenance information is synchronized to the other system to ensure the consistency of system parameters between the two parties;

[0051] b Backup power supply automatic switching device interface operation data: If the user modifies the status of the backup power supply automatic switching device through the human-machine interface, the corresponding control information needs to be immediately synchronized to the other system to maintain the synchronous update of the backup power supply automatic switching device status;

[0052] c System calculation data: The two systems perform strategy calculations independently, but the calculation interval is set to 10 minutes. To avoid large deviations in the strategy caused by differences in calculation time points, after the system with the control right completes the calculation, it will send the calculation time to the other system. After receiving it, the other system will compare it with its own time and directly correct the local timer when it exceeds the allowable error range;

[0053] d All system data: The ABC calculation system has a small amount of data, only including one item that records various calculation information. Currently, every 6 hours, the system with the control right will synchronize all data to the system without the control right;

[0054] e All backup power supply automatic switching device data: The ABC backup power supply automatic switching device has a moderate amount of data, about more than 2,000 records. Every 6 hours, the system with the control right will synchronize all calculation data of the backup power supply automatic switching device to the system without the control right;

[0055] f Heartbeat data: This data is sent periodically to detect whether the connection to the server is lost. When the connection is lost and then re - established successfully, it will trigger the synchronization operations of all data in different systems and all data of the backup power supply automatic switching device;

[0056] 2) Communication method

[0057] In the dual - active system, we adopt the JMS message queue to implement the mechanism of message passing and data exchange. Specifically, we establish a message queue between the primary system and the backup system, and use the APIs provided by JMS to realize message production and consumption, thus achieving two - way message passing and data exchange;

[0058] 3) Synchronization direction

[0059] Except for the heartbeat, other data synchronization always occurs from the party with permissions to the party without permissions.

[0060] Furthermore, the data verification system integrates multiple self - judgment and self - rescue functions, including the following parts:

[0061] 1) Data consistency verification

[0062] The consistency verification of dual - active data synchronization requires an independent module to execute. This module is responsible for verifying three types of data: system global parameters, backup power supply automatic switching control parameters, and backup power supply automatic switching strategies. The system will periodically export these three types of data in the form of files and send them to the comparison server for comparison. The comparison server reads the content in the file, makes a detailed comparison of the data of the two systems, and displays the comparison results in a graphical interface, including the number of data comparisons, the consistency ratio, and the specific details of differences. At the same time, according to the different data types, corresponding consistency ratio thresholds will be set. If the threshold is exceeded, the switching between the primary and backup systems is not allowed;

[0063] 2) Comprehensive parameter synchronization after communication recovery

[0064] When the heartbeat detection communication is restored, the system will perform comprehensive parameter synchronization, including global parameters and backup power supply automatic switching control parameters;

[0065] 3) Automatic restart strategy for abnormal process exit

[0066] When it is detected that the process exits abnormally, the system will immediately attempt to automatically restart the process. If the automatic startup fails, the system will continue to attempt, but the number of attempts is limited. If the process cannot be successfully started after consecutive multiple attempts, it is considered that this problem may be permanent and has a fatal impact on the system operation.

[0067] A method for automatically putting on and taking off the backup power supply automatic switching device pressure plate based on a dual - active architecture, using the above - mentioned backup power supply automatic switching device pressure plate automatic put - on and take - off system, includes the following steps;

[0068] In a dual-active system, the status of the other party and its own system is periodically monitored through heartbeat tests;

[0069] b If a system disconnection or system failure occurs, it is necessary to start the process of switching control rights, switch the control rights according to the preset strategies and mechanisms. The system control rights can also be manually switched under normal system conditions. In any switching method, only one system can have control rights;

[0070] c In a dual-active system, both have and periodically perform the functions of data collection and calculation of investment and withdrawal strategies;

[0071] d Adopt the primary and standby mechanisms, the one with control rights is the primary, and the other is the standby;

[0072] e Periodically check the integrity, correctness, and consistency of the synchronized data and their respective calculation result data, be able to detect problems earlier, and correct and update in a timely manner.

[0073] The beneficial effects of the present invention are:

[0074] 1. High reliability. The dual-active system adopts the methods of dual backup and real-time synchronization. In the case of a failure of one system, it can immediately and automatically switch to the backup system to ensure the high reliability of the system;

[0075] 2. High availability. The dual-active system has high flexibility and high scalability, and can dynamically perform operations such as distributed deployment and fault recovery of data, thus ensuring the high availability of the system;

[0076] 3. Real-time synchronization. The dual-active system adopts the method of real-time data synchronization, which can reduce the risk of data synchronization delay and data inconsistency, and ensure the real-time and consistency of data;

[0077] 4. Improve the user experience. The dual-active system can provide more stable and reliable services, and often has a shorter response time, thus improving the user experience and satisfaction. Specific implementation manners

[0078] A backup power supply automatic switching-on and off board system based on a dual-active architecture includes a dual-active system for real-time calculation, a control right switching system, a fault detection system, a data synchronization system, and a data verification system.

[0079] The dual-active system is a highly available system architecture. Its core idea is to achieve real-time synchronization of data and dual-active operation of services between two or more data centers. This architecture can significantly improve the disaster tolerance ability and business continuity of the system, ensure that when the primary data center fails, the backup data center can seamlessly take over the business, and guarantee the continuity and stability of services.

[0080] The dual-active system is a highly intelligent system developed and applied based on the EMS (Energy Management System). It not only makes full use of the real-time collected SCADA information but also comprehensively considers multiple key factors such as the initial load rate of the main transformer, the N-1 verification results of grid equipment, the priority setting of the backup power supply automatic switching, and possible data anomalies. Its real-time calculation of the input and withdrawal steps of the grid backup power supply automatic switching is as follows:

[0081] 1) Online input and withdrawal strategy of backup power supply automatic switching based on transformer oil temperature

[0082] In actual operation, the short-term overload capacity of the transformer is closely related to the oil temperature. The main transformer oil temperature is a key indicator reflecting the equipment status. Therefore, in the input and withdrawal strategy of the backup power supply automatic switching pressure plate, we can innovatively introduce the main transformer oil temperature as a control variable. Specifically, if the oil temperature of the associated transformer exceeds the preset value, to avoid overheating risks, the system will automatically withdraw the backup power supply automatic switching; if the oil temperature is within the safe range, the system may consider input according to other conditions;

[0083] 2) N-1 verification

[0084] In the processing of input and withdrawal of the backup power supply automatic switching pressure plate, we only conduct a detailed analysis of the N-1 faults that can trigger the backup power supply automatic switching, and there is no need to conduct in-depth analysis of others. Therefore, the N-1 fault analysis of the input and withdrawal of the backup power supply automatic switching pressure plate is a subset of the traditional N-1 calculation. Since the remote control of the backup power supply automatic switching pressure plate needs to run online, the operation speed requirement for N-1 faults is extremely high. When simulating the N-1 faults that may trigger the backup power supply automatic switching, it is necessary to re-conduct topology calculation and power flow analysis, which consumes a large amount of calculation time. To reduce the occupation of computing resources, we adopt a brand-new processing method according to the characteristics of the regional power grid. This method is based on the base-state topology, establishes a backup power supply automatic switching action model by searching for the key power supply path, and adopts the load transfer method to significantly shorten the processing time;

[0085] 3) Bad data processing

[0086] Since the input and withdrawal strategy of the pressure plate is based on the verification of the main transformer oil temperature and real-time N-1 verification, the following several bad data situations need to be considered:

[0087] a) If the oil temperature of the relevant transformer is abnormal and the backup power supply automatic switching setting considers the oil temperature factor, the current operating state of the backup power supply automatic switching pressure plate remains unchanged;

[0088] b) In the state estimation calculation, if bad data is detected in the 220kV main transformer related to the backup power supply automatic switching, the 220kV main transformer will not be verified;

[0089] c) In the state estimation calculation, if bad data is detected in the 110kV main transformer or 110kV line, the current operating state of the backup power supply automatic switching pressure plate also remains unchanged;

[0090] 4) Handling abnormal situations

[0091] During the execution of the pressure plate launch and withdrawal of the standby automatic start-up, the following abnormal situations need to be considered: 1) SCADA telemetry data is not refreshed; 2) state estimation does not converge; 3) the maximum number of remote control times per hour for the standby automatic start-up is limited; 4) the maximum number of remote control times per day for the standby automatic start-up is limited.

[0092] In step 1), the platen insertion and withdrawal strategy taking into account the oil temperature and initial load rate is as follows:

[0093] 1) 220kV main transformer oil temperature and initial load rate detection;

[0094] a) For a 220kV main transformer, if the initial load rate exceeds 0.9 (adjustable), the corresponding standby automatic switch should be locked;

[0095] b) For a 220kV main transformer, if the initial load rate exceeds 0.85 (adjustable), and at the same time the oil temperature exceeds 85℃ (adjustable) or the winding temperature exceeds 105℃ (adjustable), the corresponding standby automatic switch should also be locked;

[0096] The locked standby automatic switching devices refer specifically to those automatic switching devices that may transfer the load of other 220kV network segments to this segment after operation, but the automatic switching devices that will not increase the load of this transformer after automatic switching do not need to be locked;

[0097] 2) 110kV main transformer oil temperature and initial load rate detection

[0098] a) For a 110kV main transformer, if the initial load factor exceeds 0.85 (adjustable), the corresponding standby automatic switching function should be locked.

[0099] b) For a 110kV main transformer, if the initial load rate exceeds 0.85 (adjustable), and at the same time the oil temperature exceeds 85℃ (adjustable) or the winding temperature exceeds 105℃ (adjustable), the corresponding standby automatic switching should also be locked.

[0100] The locked backup automatic transfer object specifically refers to the 10kV automatic transfer device connected to this 110kV transformer, which is intended to prevent the load transfer after the backup automatic transfer action from increasing the burden on the already high-load main transformer.

[0101] In step 2), the fault analysis and processing method is as follows:

[0102] 1) Determine the backup automatic switch caused by N-1 fault based on power supply path search

[0103] When the automatic bus transfer system meets the charging conditions, if the working bus loses power while the standby power supply is energized, the automatic bus transfer will start. Therefore, the operation of the automatic bus transfer can be transformed into a problem of searching for the power supply paths of the working power supply and the standby power supply. In the regional power grid, we regard the 220 kV main transformer and the modeled generator as power supply points, search downward from these points to the power supply bus with the lowest voltage, and record the power supply paths that meet the conditions;

[0104] 2) Detailed processing based on power supply path search

[0105] For the regional power grid, the automatic bus transfer is mainly applied to voltage levels of 110 kV, 35 kV, and 10 kV. The 220 kV bus usually operates in a loop network, and its line faults generally do not cause the automatic bus transfer to operate or change the number of system nodes, and specific methods can be used for processing. When searching for the power supply path, we start from the 220 kV bus and the generator node as the root nodes. The specific logic is as follows: simulate disconnecting the 220 kV line switch, establish the relationship between nodes and branches; use depth-first search downward to record the power supply paths of the low-voltage buses encountered; establish the mapping relationship between equipment and the automatic bus transfer bus; identify loop information, and loop equipment faults will not cause the automatic bus transfer to operate; if the equipment has a mapping relationship with both the working bus and the standby bus at the same time, it is regarded as homologous equipment, and its faults will not trigger the automatic bus transfer; record the number of power supply points related to the automatic bus transfer, determine the key power supply path equipment, and its faults will trigger the automatic bus transfer operation;

[0106] 3) Processing of the automatic bus transfer input and output strategy based on multiple objectives

[0107] When a specific N - 1 fault causes N automatic bus transfer operations, if all these automatic bus transfer operations cause overload of grid components, and when less than all of the automatic bus transfer operations are performed, there is no overload of other grid components. Obviously, in this case, it is not practical to fully block all automatic bus transfers. In fact, only some of the automatic bus transfers need to be blocked. Therefore, set priorities for each automatic bus transfer;

[0108] V pri = 10000×V run + 1000×V pid - int(V bus ) + 4000 - V vip ×3000

[0109] In the formula: V pri is the calculated priority of the automatic bus transfer, and the smaller the value, the higher the level; V run is the function input and output mark, taking the value of 2 for local withdrawal, 1 for automatic control, and other values for 0; V pid is the automatic bus transfer pressure plate factor value, taking the value of 1 when there is a pressure plate ID, otherwise taking the value of 0; V bus is the active power of the operating bus of the automatic bus transfer; V vipFor the important user factor of the automatic standby power supply, it takes the value of 1 when there are important users, otherwise it takes the value of 0.

[0110] The control right switching system realizes seamless mutual switching of the control rights between the main control system and the standby control system;

[0111] 1) Switching description

[0112] The system is equipped with two control right marking points, and each marking point has two state values, which respectively represent having the control right and not having the control right, and the states of these two marking points always remain mutually exclusive. The main control system is responsible for real-time monitoring of the state of the main control right marking point, while the standby control system detects the state of the standby control right marking point in real time. The switching operation of the system is essentially completed by exchanging the state values of these two control right marking points, so as to achieve seamless handover of the control right;

[0113] The calculation process of the system can be divided into two major links: strategy calculation and strategy execution. The strategy calculation link is responsible for calculating the investment and withdrawal strategies of each automatic standby power supply according to the current operating conditions of the power grid, while the strategy execution link, based on the results of the strategy calculation, invests and withdraws the soft pressure plates of the automatic standby power supply through remote control. In the main and standby control systems, only the strategy execution link will detect its own control right marking point. When the marking point shows "having the control right", remote control will be executed, otherwise, it will not be executed. The switching operation of the system is essentially achieved by exchanging the state values of these two control right marking points to ensure smooth transition of the control right.

[0114] 2) Switching effect

[0115] Seamless handover of the control right: By exchanging the state values of the main control and standby control right marking points, the system can achieve smooth transition of the control right, ensuring that only one system has the control right over the automatic standby power supply at any time, thus avoiding conflicts and chaos of the control right.

[0116] Continuity of strategy execution: During the switching process, the strategy execution link will decide whether to execute the remote control operation according to the state of the control right marking point. This ensures that the investment and withdrawal strategies of the automatic standby power supply can be continuously executed before and after the switching, and there will be no interruption or delay due to the system switching.

[0117] The fault detection system is a well-designed fault detection mechanism;

[0118] Data synchronization between the main control system and the standby control system mainly depends on the message queue server, which plays a key role in data transmission and buffering. However, once the message queue server fails, the entire data synchronization link will be seriously affected, and the system will not be able to complete the data synchronization work normally. Therefore, ensuring the stable operation of the message queue server becomes the core task of data synchronization fault detection;

[0119] To achieve this goal, the primary dispatching system and the standby dispatching system adopt a heartbeat detection mechanism. Specifically, these two systems will periodically send heartbeat messages to the message queue server to detect the running status of the server. This kind of heartbeat message is a lightweight communication signal that will not interfere with the normal business of the system;

[0120] If within the set time window, the primary dispatching or standby dispatching system fails to receive the heartbeat information sent by itself or the other party, then the system will immediately determine it as a communication failure and take corresponding fault handling measures. This timely fault detection mechanism helps to quickly locate problems and reduce the delay and loss of data synchronization;

[0121] When the system receives the heartbeat information of itself and the other party again normally, it indicates that the communication link has been restored and the data synchronization work can continue.

[0122] The steps for the data synchronization system to achieve data backup and synchronization are as follows;

[0123] 1) Authentication before synchronization

[0124] The control right of the system is judged and obtained through SCADA detection points. For this reason, the platform specially provides two detection points: the primary dispatching control right detection point (marked as: A1) and the standby dispatching control right detection point (marked as: B1). These two detection points are mutually exclusive within the same system, which means that at the same time, only one detection point can represent having the control right. At the same time, these two detection points correspond to each other in two different systems and have the same function and meaning. This combination method of these two detection points provides a basis for the flexible switching of the system and the smooth transition of the control right:

[0125]

[0126] As can be seen from the above table, the permissions of the two sets of systems A and B are mutually exclusive. Because the programs are the same, in order to achieve the mutually exclusive method, there are two ways to achieve it. One is that the two sets of systems A and B detect different points respectively; the other is that the two sets of systems A and B detect the same point, but the detected values are different. There are problems with this, such as differences in configuration, and there will be an overwriting situation during synchronous update. To prevent this problem, dual verification is proposed;

[0127] The dual verification configuration is unitized design, and the configuration information is bound to the node name. When the system runs, it only reads the configuration belonging to this node, realizing the different requirements of effective configuration of the same file on different nodes;

[0128] 2) Data backup

[0129] Each time the strategy is calculated, the input and output states of the backup power supply automatic switching device are calculated using the current operating mode and status. Since the loss of historical status will not affect the result of the strategy calculation, there is no need to back up the historical status;

[0130] 3) Data synchronization.

[0131] The steps of data synchronization are as follows:

[0132] 1) Data classification

[0133] The system involves dual functions of calculation and operation. To effectively achieve data synchronization and reasonably utilize resources, we need to classify the data in detail. Currently, it is mainly divided into the following categories:

[0134] a System interface operation data: When the user maintains the system parameters through the human-machine interface, the relevant maintenance information needs to be synchronized to the other system to ensure the consistency of the system parameters of both parties;

[0135] b ATS interface operation data: If the user modifies the status of the ATS through the human-machine interface, the corresponding control information needs to be immediately synchronized to the other system to maintain the synchronous update of the ATS status;

[0136] c System calculation data: The two systems independently perform strategy calculations, but the calculation interval is set to 10 minutes. To avoid large deviations in strategies caused by differences in calculation time points, after the system with control rights completes the calculation, it will send the calculation time to the other system. After receiving it, the other system will compare it with its own time and directly correct the local timer when it exceeds the allowable error range;

[0137] d All system data: The data volume of the ABC calculation system is small, only including one item recording various calculation information. Considering that network or other factors may cause synchronization differences, currently, every 6 hours, the system with control rights will synchronize all data to the system without control rights;

[0138] e All ATS data: The data volume of the ABC ATS is moderate, about more than 2,000 records. Similarly, considering the possibility of synchronization differences, every 6 hours, the system with control rights will synchronize all calculation data (including strategies and statistics) of the ATS to the system without control rights;

[0139] f Heartbeat data: This data is sent periodically to detect whether the connection to the server is disconnected. When the connection is disconnected and then successfully reconnected, it will trigger the synchronization operation of all system data and all ATS data (from the system with control rights to the system without control rights);

[0140] 2) Communication method

[0141] In the dual-active system, we adopt the JMS message queue to implement the mechanism of message passing and data exchange. Specifically, we establish a message queue between the primary system and the standby system, and use the APIs provided by JMS to implement message production and consumption, thus achieving two-way message passing and data exchange;

[0142] To ensure the real-time and reliable message passing and data exchange between the OCS dual-active system and the JMS message queue, we use the message listener provided by JMS to monitor messages in real time. In this way, when new messages appear in the message queue, the listener can respond quickly, thus ensuring the timely response ability of the system.

[0143] In addition, when both the primary and standby systems have the file data channel function, the sending side of the JMS data channel needs to add the primary-standby mark to the JMS message. The receiving side needs to judge the running state of the channel according to the received mark to avoid the situation of responding to the messages sent by itself, ensuring the stability and accuracy of the system.

[0144] 3) Synchronization direction

[0145] Except for the heartbeat, other data synchronization is always from the party with permissions to the party without permissions.

[0146] The data verification system integrates multiple self-judgment and self-rescue functions including the following parts:

[0147] 1) Data consistency verification

[0148] The consistency verification of dual-active data synchronization needs to be executed by an independent module, which is responsible for verifying three types of data: system global parameters, backup power supply automatic control parameters, and backup power supply strategies. The system will periodically export these three types of data in the form of files and send them to the comparison server for comparison. The comparison server reads the content in the file, makes a detailed comparison of the data of the two systems, and displays the comparison results in the form of a graphical interface, including the number of data comparisons, the consistency ratio, and the specific difference details. At the same time, according to the different data types, corresponding consistency ratio thresholds will be set. If the threshold is exceeded, the switching between the primary and standby systems is not allowed;

[0149] 2) Comprehensive parameter synchronization after communication recovery

[0150] When the heartbeat detection communication is restored, the system will perform comprehensive parameter synchronization, including global parameters and backup power supply automatic control parameters. There is only one global parameter, and although the backup power supply automatic control parameters are synchronized according to the records of the backup power supply devices, considering that there are only more than 2,000 backup power supply devices in the Guangzhou area, the overall data volume is not large, and the total resources occupied by a single synchronization operation are only a few MB;

[0151] 3) Automatic restart policy for abnormal process exit

[0152] Completing a series of operations for active-active requires the stable operation of relevant processes on the primary and standby systems. Once these processes exit abnormally, all operations will not be able to be completed smoothly. To solve this problem, the system designs an automatic restart mechanism. When it detects that a process has exited abnormally, the system will immediately attempt to automatically restart the process. If the automatic restart fails, the system will continue to attempt, but the number of attempts is limited. If the process cannot be successfully restarted after multiple consecutive attempts, it is considered that this problem may be permanent and has a fatal impact on the system operation.

[0153] A method for automatically switching on and off the backup power supply switchboard based on an active-active architecture, using the above-mentioned automatic switching on and off system for the backup power supply switchboard, includes the following steps;

[0154] a In the active-active system, periodically monitor the status of the other party and its own system through heartbeat tests;

[0155] b If system disconnection or system failure occurs, it is necessary to start the process of switching control rights, switch the control rights according to the preset policies and mechanisms. The system control rights can also be manually switched under normal system conditions. In either switching method, only one system can have control rights;

[0156] c In the active-active system, both have and periodically perform the functions of data collection and calculation of switching-on and switching-off strategies;

[0157] d Adopt the primary and standby mechanism, the one with control rights is the primary, and the other is the standby. Only the primary system can perform data maintenance and issue policy control commands, and synchronize the maintenance information and control information to the standby system through the message bus;

[0158] e Periodically check the integrity, correctness, and consistency of the synchronized data and their respective calculation result data, be able to detect problems earlier, and correct and update in time.

[0159] The relationship between the automatic switching system of the backup pressure plate (ABC) and the active-active system can be analyzed from multiple dimensions such as functional coordination, system architecture, data synchronization and mutual backup switching. 1. Functional coordination: ABC is mainly responsible for the calculation and execution of the state strategy of the backup pressure plate in the power system. The active-active system can immediately start the other system when any system fails by realizing real-time data synchronization and mutual backup switching of the two ABC systems, so as to achieve seamless switching and ensure that business continuity is not affected. 2. System architecture; independence and complementarity: As part of the power automation control system, the ABC system focuses on the automatic switching function of the backup pressure plate. The active-active system starts from the system architecture level, deploys two independent ABC systems, and realizes data synchronization and mutual backup switching between them to improve the redundancy and reliability of the entire system. Integration and coordination: In the active-active architecture, the two ABC systems need to be effectively integrated to form a unified and highly coordinated whole. This includes the standardization of data interfaces, the unification of communication protocols, and the precise design of mutual backup switching logic. 3. Data synchronization and mutual backup switching; Data synchronization: The active-active system needs to achieve real-time data synchronization between the two ABC systems to ensure that the two systems have completely consistent data status at any time. Mutual backup switching: When an ABC system fails, the active-active system needs to be able to trigger a mutual backup switching operation to smoothly switch the business traffic to another normal ABC system.

Claims

1. A system for automatically launching and retreating a standby pressure plate based on a dual-active architecture, characterized in that: It includes active-active system for real-time computing, control switching system, fault detection system, data synchronization system, and data verification system; The active-active system is a highly intelligent system that is deeply developed and applied based on EMS; The control right switching system realizes seamless switching of control rights between the main control system and the backup control system; The system is equipped with two control right marking points, each of which has two status values, representing control right and no control right respectively, and the status of these two marking points always remain mutually exclusive. The main dispatching system is responsible for real-time monitoring of the status of the main dispatching control right marking point, while the backup dispatching system is responsible for real-time detection of the status of the backup dispatching control right marking point. The switching operation of the system is essentially completed by exchanging the status values ​​of the two control right marking points, thereby realizing seamless handover of control rights; The calculation process of the system can be divided into two major links: strategy calculation and strategy execution. The strategy calculation link is responsible for calculating the start and stop strategies of each standby automatic start-up according to the current operating conditions of the power grid, while the strategy execution link uses the results of strategy calculation to start and stop the standby automatic start-up soft pressure plate through remote control. In the main and standby dispatching systems, only the strategy execution link will detect the respective control right mark points. When the mark point shows "control right", the remote control will be executed, otherwise it will not be executed; The fault detection system is a well-designed fault detection mechanism; The main dispatching system and the backup dispatching system use a heartbeat detection mechanism. These two systems periodically send heartbeat messages to the message queue server to detect the running status of the server. If the main or backup system cannot receive the heartbeat information sent by itself or the other party within the set time window, the system will immediately determine it as a communication failure and take corresponding troubleshooting measures; When the system receives its own and the other party's heartbeat information normally again, it means that the communication link has been restored and data synchronization can continue; The steps for the data synchronization system to achieve data backup and synchronization are as follows; 1) Identity verification before synchronization; The control right of the system is determined and obtained through the SCADA detection point. For this purpose, the platform provides two detection points: the main control right detection point (marked as: A1) and the backup control right detection point (marked as: B1). These two detection points are mutually exclusive in the same system, which means that at the same time, only one detection point can indicate the control right. At the same time, these two detection points correspond to each other in two different systems and have the same function and meaning. 2) Data backup; Each strategy calculation uses the current operation mode and status to calculate the investment and withdrawal status of the standby automatic investment; 3) Data synchronization; The data verification system integrates a variety of autonomous judgment and self-rescue functions.

2. The automatic launching and retreating system of the backup pressure plate based on the active-active architecture as claimed in claim 1 is characterized in that: The active-active system calculates the power grid backup automatic input and output steps in real time as follows: 1) Online switching strategy of automatic backup based on transformer oil temperature In actual operation, the short-term overload capacity of the transformer is closely related to the oil temperature. The oil temperature of the main transformer is a key indicator reflecting the status of the equipment. Specifically, if the oil temperature of the associated transformer exceeds the preset value, the system will automatically exit the standby mode to avoid overheating risks; if the oil temperature is within a safe range, the system may consider switching on based on other conditions; 2) N-1 verification The N-1 fault analysis of the automatic backup pressure plate is a subset of the traditional N-1 calculation. According to the characteristics of the regional power grid, a new processing method is adopted. This method is based on the base state topology, establishes the automatic backup action model by searching the power supply key path, and uses the load transfer method to greatly shorten the processing time. 3) Bad data processing Since the pressure plate activation and deactivation strategy is based on the main transformer oil temperature calibration and real-time N-1 calibration, the following bad data situations need to be considered: a) If the oil temperature of the relevant transformer is abnormal, and the standby automatic start setting takes the oil temperature factor into consideration, the current operating state of the standby automatic start pressure plate shall be maintained unchanged; b) In the state estimation calculation, if bad data is detected in the 220kV main transformer related to the backup automatic switch, the 220kV main transformer will not be checked; c) In the state estimation calculation, if bad data is detected in the 110kV main transformer or 110kV line, the current operating state of the backup automatic voltage board is maintained unchanged; 4) Handling abnormal situations During the execution of the pressure plate launch and withdrawal of the standby automatic start-up, the following abnormal situations need to be considered: 1) SCADA telemetry data is not refreshed; 2) state estimation does not converge; 3) the maximum number of remote control times per hour for the standby automatic start-up is limited; 4) the maximum number of remote control times per day for the standby automatic start-up is limited.

3. The automatic launching and retreating system of the backup pressure plate based on the active-active architecture as claimed in claim 2 is characterized in that: In step 1), the platen insertion and withdrawal strategy taking into account the oil temperature and initial load rate is as follows: 1) 220kV main transformer oil temperature and initial load rate detection; a) For a 220kV main transformer, if the initial load rate exceeds 0.9, the corresponding standby automatic switch should be locked; b) For a 220kV main transformer, if the initial load rate exceeds 0.85 and the oil temperature exceeds 85℃ or the winding temperature exceeds 105℃, the corresponding standby automatic switch should also be locked; 2) 110kV main transformer oil temperature and initial load rate detection; a) For a 110kV main transformer, if the initial load rate exceeds 0.85, the corresponding standby automatic switch should be locked; b) For a 110kV main transformer, if the initial load rate exceeds 0.85, and at the same time the oil temperature exceeds 85°C (adjustable) or the winding temperature exceeds 105°C, the corresponding standby automatic switching should also be locked.

4. The automatic launching and retreating system of the backup pressure plate based on the active-active architecture as claimed in claim 2 is characterized in that: In step 2), the fault analysis and processing method is as follows: 1) Determine the backup automatic switch caused by N-1 fault based on power supply path search When the backup automatic transfer system meets the charging conditions, if the working bus loses power but the backup power supply is energized, the backup automatic transfer system will start; 2) Detailed processing based on power supply path search When searching for power supply paths, we start with the 220kV bus and generator nodes as the root nodes. The specific logic is as follows: simulate disconnecting the 220kV line switch to establish the relationship between the node and the branch; use depth-first downward search to record the low-voltage bus power supply path encountered; establish a mapping relationship between the equipment and the backup automatic re-start bus; identify loop information, and loop equipment failure will not cause the backup automatic re-start action; if the equipment has a mapping relationship with both the working bus and the backup bus, it is regarded as a homologous device, and its failure will not trigger the backup automatic re-start; record the number of power supply points related to the backup automatic re-start, and determine the key power supply path equipment, whose failure will trigger the backup automatic re-start action; 3) Processing of standby automatic investment and withdrawal strategies based on multiple objectives When a specific N-1 fault will trigger N backup automatic switching operations, if all the backup automatic switching operations lead to overload of power grid components, and when less than all the backup automatic switching operations occur, no other power grid components are overloaded, it is obviously not practical to fully block all the backup automatic switching operations in this case. In fact, only some of the backup automatic switching operations need to be blocked. Therefore, a priority is set for each backup automatic switching operation. V pri =10000×V run +1000×V pid -|int(V bus )|+4000-V vip ×3000 Where: V pri is the calculated priority of standby automatic switching, the smaller the value, the higher the priority; V run It is the function start and end mark, the local exit value is 2, the automatic control value is 1, and the other values ​​are 0; V pid It is the value of the automatic pressure plate factor. If there is a pressure plate ID, the value is 1, otherwise it is 0; V bus The active power of the automatic operation busbar; V vip To prepare for the self-investment of important user factors, the value is 1 when there is an important user, otherwise it is 0.

5. The automatic launching and retreating system of the backup pressure plate based on the active-active architecture as claimed in claim 1, characterized in that: The steps for data synchronization are as follows: 1) Data classification It is mainly divided into the following categories: a System interface operation data: After the user performs system parameter maintenance through the human-machine interface, the relevant maintenance information will be synchronized to the other party's system to ensure the consistency of the system parameters of both parties; b. Operation data of the standby automatic start interface: If the user modifies the standby automatic start status through the human-machine interface, the corresponding control information must be synchronized to the other party's system in real time to maintain the synchronous update of the standby automatic start status; c System calculation data: The two systems perform strategy calculations independently, but the calculation interval is set to 10 minutes. To avoid large deviations in strategy due to differences in calculation time points, the system with control will send the calculation time to the other system after completing the calculation. After receiving it, the other system will check it against its own time and directly correct the local timer if it exceeds the allowable error range; d. All system data: The ABC computing system has a small amount of data, which only contains one entry to record various computing information. Currently, every 6 hours, the system with control rights will synchronize all data to the system without control rights; e All data of backup self-investment: The amount of data of ABC backup self-investment is moderate, with about 2,000 records. Every 6 hours, the system with control rights will synchronize all the calculation data of backup self-investment to the system without control rights; f Heartbeat data: This data is sent periodically to detect whether the connection with the server is disconnected. When the connection is disconnected and reconnected successfully, it will trigger the synchronization of all data in different systems and all data in the backup system. 2) Communication method In the active-active system, we use JMS message queues to implement the mechanism of message transmission and data exchange. Specifically, we set up message queues between the primary system and the backup system, and use the API provided by JMS to realize message production and consumption, thereby achieving two-way message transmission and data exchange. 3) Synchronization direction Except for heartbeat, other data synchronization is always synchronized from the authorized party to the unauthorized party.

6. The automatic launching and retreating system of the backup pressure plate based on the active-active architecture as claimed in claim 1, characterized in that: The data verification system consists of the following parts: 1) Data consistency check The consistency check of active-active data synchronization requires an independent module to perform. This module is responsible for checking three types of data: system global parameters, standby automatic start-up control parameters, and standby automatic start-up strategies. The system will periodically export these three types of data in the form of files and send them to the comparison server for comparison. The comparison server reads the content in the file and makes a detailed comparison of the data of the two systems. The comparison results are displayed in a graphical interface, including the number of data comparisons, the consistency ratio, and the specific difference details. At the same time, according to different data types, a corresponding consistency ratio threshold will be set. If the threshold is exceeded, the switching of the active and standby systems is not allowed. 2) Comprehensive parameter synchronization after communication is restored When the heartbeat detection communication is restored, the system will perform comprehensive parameter synchronization, including global parameters and standby automatic control parameters; 3) Automatic restart strategy for abnormal process exit When it is detected that a process exits abnormally, the system will immediately try to automatically restart the process. If the automatic restart fails, the system will continue to try, but the number of attempts is limited. If multiple consecutive attempts fail to successfully restart the process, it is considered that the problem may be permanent and have a fatal impact on system operation.

7. A method for automatically launching and retracting a standby automatic pressure plate based on a dual-active architecture, using the automatic launching and retracting system for a standby automatic pressure plate according to any one of claims 1 to 6, characterized in that: The steps include: aIn a dual-active system, the status of the other party and its own system is periodically monitored through heartbeat testing; b. If the system loses connection or fails, the control right switching process needs to be started. The control right is switched according to the preset strategy and mechanism. The system control right can also be switched manually when the system is normal. Regardless of the switching method, only one system has control right. c In the active-active system, both have the function of periodically collecting data and calculating the activation and deactivation strategies; d. Use a master-slave mechanism, where the one with control is the master and the other is the backup; The integrity, correctness and consistency of the synchronized data and the respective calculation result data are checked periodically, so that problems can be discovered early and corrected and updated in a timely manner.

Citation Information

Patent Citations

  • Backup power automatic switching device fault identification method and system

    CN108051706A

  • Two-layer control-based spare power automatic switching enabling / disenabling method

    CN108092259A