Autonomous controllable substation multi-mode sensing operation and maintenance system and method
By adopting a multimodal sensing operation and maintenance system in the substation operation and maintenance system, and using encryption and decryption algorithms and large models in the power grid field for data processing and fault identification, the problems of data acquisition and poor security of information interaction in the substation operation and maintenance system are solved, and the independent and controllable whole-domain operation and maintenance of the substation is realized.
Patent Information
- Application Number
- CN202510428449.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-08
AI Technical Summary
The existing substation operation and maintenance systems have problems such as data acquisition that is not synchronous, poor information interaction security, long time to identify faults and high computing power costs, making it difficult to achieve independent and controllable full-domain operation and maintenance of substations.
The multi-modal perception operation and maintenance system of the independent controllable substation is adopted. The real-time data of the substation equipment is collected simultaneously through the acquisition module. The communication module uses an encryption and decryption algorithm to process the data, and uses a large model in the power grid field to identify faults and retrieve solutions to query the timeliness of the wave recording file.
It improves the security of substation information interaction, realizes the independent and controllable whole-domain operation and maintenance of substations, and reduces the time and cost of fault identification and processing.
Smart Images

Figure CN119944979A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of substations, and in particular relates to a multi-modal perception operation and maintenance system and method for an autonomous and controllable substation. Background Art
[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.
[0003] In order to achieve more comprehensive monitoring and operation and maintenance of substations, the current substation operation and maintenance system is connected to a large number of intelligent devices, but there are the following problems: (1) Data collection between multiple substations is not synchronized, which leads to complex network at the process layer, tight coupling of SCD (Substation Configuration Description) files, repeated configuration of similar devices, insufficient data sharing, and waste of resources, resulting in poor security of substation information interaction and inability to achieve autonomous and controllable full-domain operation and maintenance of substations. (2) During the data synchronization process of multiple substations, the LAN and external network isolation technology within the substation is adopted, and data is transmitted in plain text in the LAN, but there are still security risks in the data transmission of the LAN; (3) In the process of fault identification and processing, large model training is time-consuming and computationally expensive, and the current large model training and reasoning fusion does not retain more effective quantitative information, and achieve the effect of balancing training efficiency and quantization. Summary of the invention
[0004] In order to solve the technical problems existing in the above-mentioned background technology, the present invention provides a multimodal perception operation and maintenance system and method for an autonomous and controllable substation, which can improve the poor security of information interaction in the substation and realize autonomous and controllable full-area operation and maintenance of the substation.
[0005] In order to achieve the above object, the present invention adopts the following technical solution: A first aspect of the present invention provides a multi-modal perception operation and maintenance system for an autonomous and controllable substation.
[0006] An autonomous and controllable substation multi-modal sensing operation and maintenance system, comprising: a collection module, a communication module, a data analysis module and a display module; The acquisition module is used to synchronously acquire the real-time operation data of each electrical device in the substation host and the substation standby machine, or / and transmit the recording files of the substation host and the substation standby machine to the communication module; The communication module is used to transmit the received operation synchronization data and / or recording files of each substation to the data analysis module after being processed by encryption and decryption algorithms; The data analysis module is used to: use the large model of the power grid field to identify faults in the synchronous data of each substation operation, and retrieve matching solutions from the solution database according to the fault type; and query whether the recording file exists in a pre-created hash table that associates multiple recording files of different formats with the fault object, thereby determining the timeliness of the recording file; The display module is used to display the fault identification results and the corresponding solutions and the timeliness analysis results of the recording files.
[0007] As an implementation mode, in the data analysis module, when there is no solution corresponding to the identified fault type in the solution database, the solution corresponding to the fault type with the greatest similarity to the fault type description is searched from the solution database and transmitted to the display module for display.
[0008] As an implementation mode, in the data analysis module, when there is no solution corresponding to the identified fault type in the solution database, the finalized solution and the matching fault type are stored in the solution database, and the solution database is updated.
[0009] As an implementation method, the acquisition module includes: A real-time database construction module is used to establish real-time databases for the main substation and the standby substation respectively; Multi-machine interaction module, used to use encrypted and authenticated secure bus for communication connection between substation host and substation standby; The communication link determination module determines the communication link between the substation host and the substation standby based on the communication connection and the real-time database, so that the substation host and the substation standby send their own communication device lists to each other through the security bus to achieve real-time data synchronization.
[0010] As an implementation mode, in the multi-machine interaction module, the substation host periodically sends its own communication equipment list to the corresponding substation standby machine, and the standby machine obtains the standby machine's global equipment list in combination with the substation host's collection equipment list; the substation standby machine marks and monitors the relevant equipment in the obtained host equipment list, and the substation standby machine does not communicate with the marked relevant equipment; at the same time, the substation standby machine periodically sends its own collection equipment list to the substation host, and the host obtains the host's global equipment list in combination with the substation standby machine's communication equipment list, and the substation host marks and monitors the relevant equipment in the obtained standby equipment list, and the substation host does not communicate with the marked relevant equipment.
[0011] As an implementation mode, in the multi-machine interaction module, when the substation host fails, the substation host is disconnected from the safety bus, and the substation standby machine cannot receive the communication equipment list sent by the substation host. The substation standby machine will take over the data communication in the communication equipment list to achieve uninterrupted data collection; at the same time, a substation host failure alarm prompt is issued, and at this time, the substation standby machine enters a single-machine operation state.
[0012] As an implementation mode, in the multi-machine interaction module, when the substation host recovers from a fault, it immediately sends a data synchronization request to the substation standby machine, and the substation standby machine sends the cached data to the substation host; after receiving the cached data, the substation host resumes sending the communication equipment list; after receiving the communication equipment list, the substation standby machine performs difference processing with the standby machine's global equipment list, and restores the global communication list to the standby machine's own collection equipment list, and the substation host and the substation standby machine resume the parallel state of downward collection.
[0013] As an implementation mode, in the communication module, before data transmission, the debugging tool and the gateway machine perform key negotiation to generate their own public key and private key respectively; the debugging tool and the gateway machine transmit their own public keys to each other through public key exchange, and calculate the shared session key by using the other party's public key and their own private key; During data communication, the debugging tool and the gateway machine encrypt and decrypt the power data to be transmitted based on the generated session key and the constructed encryption and decryption algorithm; wherein the construction process of the encryption and decryption algorithm includes: On the basis of the standard SM4 algorithm, additional rounds are added to expand the key to generate round keys, which are stored in the first array; Encrypt the data block based on the round key, generate a hash message authentication code based on a given HMAC key, merge the encrypted data and the hash message authentication code, and store them in a second array; The hash message authentication code in the array is verified, the data block is decrypted, and the generated state value is stored in the third array.
[0014] As an implementation mode, in the communication module, the debugging tool and the gateway machine transmit their respective public keys to each other by means of public key exchange, and calculate a shared session key using the other party's public key and their own private key, including: The key pair generated by the debugging tool includes a first public key and a first private key, and the key pair generated by the gateway includes a second public key and a second private key; The debugging tool sends the first public key to the gateway machine, and the gateway machine sends the second public key to the debugging tool; After receiving the first public key of the debugging tool, the gateway machine calculates the session key using the first public key of the debugging tool and the second private key of the gateway machine; After receiving the first public key of the gateway machine, the debugging tool calculates a session key using the first public key of the gateway machine and the second private key of the debugging tool.
[0015] As an implementation mode, in the communication module, based on the standard SM4 algorithm, an additional round is added to expand the key to generate a round key, and the round key is stored in the first array, including: defining a first array of a preset size for storing the expanded key; Customize the key data information, read the key data information byte by byte, and store them in the first array respectively; Through a preset number of iterations, a new key value is generated each time using the previous key value and stored in the first array. In each iteration, linear transformation and nonlinear transformation are applied to increase the complexity of the key, and the generated round key is stored in the first array.
[0016] As an implementation mode, in the communication module, encrypting the data block based on the round key and generating a hash message authentication code based on a given HMAC (Hash-based Message Authentication Code) key includes: A second array of a preset size is defined for storing intermediate data in the encryption process; Read the input plaintext data byte by byte and store them into the array respectively; Through a preset number of iterations, the current state value and round key are used for encryption transformation each time to generate a new state value; Convert the final state value back to a byte array and store it in a temporary variable; Hash the encrypted data using the given HMAC key to generate a hashed message authentication code.
[0017] As an implementation manner, in the communication module, verifying the hash message authentication code in the array, decrypting the data block, and storing the generated state value in the third array includes: A third array of a preset size is defined to store intermediate data in the decryption process; Extract data and hash message authentication codes; Use the given hash message authentication code key to perform a hash operation on the extracted encrypted data to generate a new hash message authentication code; compare the generated hash message authentication code with the extracted hash message authentication code, and if they do not match, return verification failure; Through iterative operations, the current state value and the round key are used each time for decryption transformation to generate a new state value, and the final state value is converted back into a byte array and stored in the third array.
[0018] As an implementation method, in the data analysis module, the deployment process of the large model in the power grid field is: Based on the relationship between the memory overhead of a single parameter, a single gradient, a single optimizer state, the number of model parameters, and the number of working nodes in data parallelism and the memory overhead of the storage-cooperative parallel decomposition strategy, the parallel decomposition strategy for large models in the power grid field is determined with the storage-cooperative parallel decomposition strategy having the smallest memory overhead. Based on the parallel decomposition strategy of the large model in the power grid field, the hardware equipment information and deep learning framework are input using hyperparameters to automatically allocate hardware resources. Then, the deep learning model structure is set and the parallel decomposition scheme is configured using guided statements. The code is automatically translated to achieve automatic conversion and training of the deep learning model.
[0019] As an implementation, in the data analysis module, the memory overhead of a single parameter , single gradient memory overhead , memory overhead of a single optimizer state , model parameter quantity and the number of worker nodes in data parallelism These parameters are combined with the memory overhead of the parallel decomposition strategy to store The relationship between them is: .
[0020] As an implementation mode, in the data analysis module, the model parameter quantity for: ;in, The precision of floating point numbers.
[0021] As an implementation mode, in the data analysis module, the parallel decomposition strategy of the large model in the power grid domain includes inter-group data parallelism, intra-group model parallelism, pipeline parallelism and optimizer parallelism strategies.
[0022] As an implementation mode, in the data analysis module, the intra-group model parallel strategy is: ;in, The memory cost of storing the coordinated parallel decomposition strategy, is the memory limit of a single device, Allocate quantities for devices within the group; The data parallel strategy between groups is: ;in, Allocate quantities for devices in the group. Allocate quantities for devices between groups, The total number of available devices.
[0023] As an implementation mode, in the data analysis module, the training process of the large power grid domain model is: Get the configuration parameter information of the large model to be trained; Based on the acquired configuration parameter information, the loss function of the large model is constructed, the gradient norm is calculated, and the first-order gradient information perception score of the large model is obtained; Add disturbance to the large model, construct the perturbation loss function of the large model, calculate the Hessian matrix, and obtain the Hessian gradient information perception score of the large model; Adaptively weight the first-order gradient information perception score and the Hessian gradient information perception score of the large model to obtain a quantitative perception score of the large model; According to the obtained large model quantization perception score, the large model quantization perception training samples are determined to complete the distributed quantization perception training of the large model.
[0024] As an implementation mode, in the data analysis module, in the process of determining the large model quantitative perception training samples, the weights in the obtained large model quantitative perception scores are sorted by size, the training samples are determined according to the sorting, and the determined samples are processed in data parallel to complete the distributed quantitative perception training of the large model.
[0025] As an implementation method, in the data analysis module, in the process of adaptive weighted combination, after the obtained first-order gradient information perception score and Hessian gradient information perception score are standardized, the first-order gradient information perception score weight and the Hessian gradient information perception score weight are calculated, and the sample scores are adaptively weighted combined to obtain the quantitative perception score of the large model, and the sample data suitable for the quantitative perception training of the large model is determined according to the quantitative perception score of the large model.
[0026] As an implementation method, in the data analysis module, during the distributed quantization perception training of the large model, the determined large model quantization perception training samples are divided into several subsets, the divided subsets are processed and the subset gradients are calculated, and all subset gradients are aggregated in combination with the communication protocol to complete the update of the global model parameters; the distributed quantization perception training of the large model is completed according to the updated model parameters.
[0027] As an implementation mode, in the data analysis module, the obtained large model loss function is back-propagated, and the partial derivatives of the loss function after back-propagation processing with respect to the model parameters are calculated to obtain the model gradient; the sum of the squares of all the obtained model gradients is used as the gradient norm, and the square root of the gradient norm is removed to obtain the first-order gradient information perception score of the large model.
[0028] As an implementation method, in the data analysis module, the second-order partial derivatives of the constructed large model containing the perturbation loss function with respect to the model parameters are calculated, the obtained second-order partial derivatives are used as the diagonal elements of the Hessian matrix, and the sum of the squares of all the diagonal elements is calculated to obtain the Hessian gradient information perception score of the large model.
[0029] As an implementation mode, in the data analysis module, the process of determining the timeliness of the recording file is: In a preset hash table, it is judged whether there is a currently received wave recording file. If so, the fault object associated with the currently received wave recording file in the hash table is determined, otherwise the query is terminated; wherein the hash table is a hash table in which multiple wave recording files of different formats are associated with the fault object, and multiple wave recording files of different formats are associated with a same fault object; Deleting the key-value pair of the recording file and the fault object in the hash table; If the associated fault object is empty or fault analysis is in progress, the query is terminated. Otherwise, it is determined whether there are multiple fault recording files of all preset different formats in the currently received recording file; if there are fault recording files of all preset types, the fault processing thread is executed, otherwise the recording files continue to be obtained.
[0030] As an implementation manner, in the data analysis module, it further includes: comparing the SCD file of each substation with the reference SCD file, and the process is as follows: Read the contents of each subnode in the two SCD files to be compared; Compare the contents of each subnode in the two SCD files to be compared, and store the comparison results in a data structure; wherein the comparison process of the contents of each subnode in the two SCD files to be compared includes: The first SCD file is used as a reference file, and the specified nodes of the first SCD file are traversed. According to the unique attribute identifier of the node and the check code calculated based on the node content, the corresponding node and the node data with differences are searched in the second SCD file, and the node data with differences are stored as a change item in the data structure. The second SCD file is used as a reference file, the designated nodes of the second SCD file are traversed, the corresponding nodes are searched in the first SCD file, and the node data that are not searched are stored as new items in the data structure.
[0031] As an implementation mode, the data analysis module is further configured with an intelligent alarm module, and the process of automatic modeling of the intelligent alarm module is as follows: Constructing an initial basic information database; wherein the initial basic information database includes a characteristic signal database, a characteristic device database and a fault alarm information expert database; According to the set rules, the initial basic information library is expanded; the process is as follows: based on the preset rules, the signals in the substation are classified, the required signal types are abstracted and stored in the characteristic signal library; based on the preset rules, the primary and secondary equipment are classified, the required primary and secondary equipment types are abstracted and stored in the characteristic equipment library; based on the preset conditions for the occurrence of typical faults and the sequence of signal occurrence, fault alarm information is formed, and the corresponding solutions for various types of fault alarm information are stored in the fault alarm information expert library; According to the expanded characteristic signal library and characteristic device library, the signals / devices contained in the selected actual interval / device are classified, and then according to the expanded fault alarm information expert library, the examples of fault distribution and alarm inference are generated and the intelligent alarm configuration information file is formed; Publish the intelligent alarm configuration information file to the intelligent alarm module to obtain the final basic information library.
[0032] As an implementation manner, the data analysis module is further configured with a multi-thread management module, and the multi-thread management module is configured as follows: Use multiple threads to perform hardware monitoring, alarm information monitoring and control operations of the substation respectively; Adopt autonomous collection method and set sampling frequency to obtain hardware monitoring information and alarm information monitoring information of substation monitoring system platform in real time; Obtain the issued control operation items, perform corresponding control, manipulation and detection on the substation monitoring system, and obtain monitoring results; the control operation items are adaptively selected and determined based on the monitoring information obtained by autonomous collection.
[0033] A second aspect of the present invention provides a working method of a multi-modal perception operation and maintenance system for an autonomous and controllable substation.
[0034] A working method of a multi-modal sensing operation and maintenance system for an autonomous and controllable substation, comprising: Synchronously collect the real-time operation data of each electrical equipment in the main substation and the standby substation, or / and transmit the recording files of the main substation and the standby substation together with encryption and decryption algorithms; Obtain the decrypted synchronous operation data and / or recording files of each substation; Use the large-scale model in the power grid field to identify faults in the synchronous data of each substation operation, and retrieve matching solutions from the solution database according to the fault type; and query whether the recording file exists in the pre-created hash table that associates multiple recording files of different formats with the fault object, and then determine the timeliness of the recording file; Displays the fault identification results and their corresponding solutions as well as the timeliness analysis results of the recording files.
[0035] The beneficial effects of the present invention are: (1) The present invention provides an autonomous and controllable substation multimodal perception operation and maintenance system, which synchronously collects the real-time operation data of each electrical equipment in the substation host and the substation standby machine, or / and transmits the recording files of the substation host and the substation standby machine together through an encryption and decryption algorithm, uses a large model in the power grid field to identify faults in the synchronous operation data of each substation and retrieve matching solutions, and determines the timeliness of the recording files by querying a hash table that associates multiple recording files in different formats with fault objects created in advance. While ensuring the interaction of substation safety information, autonomous and controllable full-domain operation and maintenance of substations is achieved.
[0036] (2) The present invention provides a real-time data synchronization method for a multi-machine substation based on a security bus, which sends its own communication equipment list to the other party through the security bus, thereby reducing the investment in the digital infrastructure of the substation; at the same time, the present invention fully considers the disaster recovery processing when a monitoring host fails, and issues an alarm prompt, thereby minimizing the data loss caused by the failure.
[0037] (3) The present invention adopts the fusion encryption method of SM2 and SM4 for encryption, improves and re-implements the standard SM4 algorithm, and adds the HMAC data authentication function for communication, thereby ensuring the security and efficiency of data transmission.
[0038] (4) The present invention proposes a parallel decomposition strategy for the coordination of computing and storage resources. According to the computing power and storage capacity limitations of the available computing resources, a series of appropriate parallel decomposition strategies are selected to ultimately construct the optimal large-model distributed training strategy, thereby improving training efficiency and reducing training costs. The present invention also proposes an automatic generation technology for large-model training in the power grid field, which automatically converts the currently used traditional artificial intelligence models into large models that can be used for distributed training, and completes the automatic configuration of hardware resources, thereby achieving elastic expansion and agile deployment of large-model functions.
[0039] (5) The present invention combines the gradient criterion and the Hessian matrix, considers the first-order gradient information perception and the Hessian gradient information perception, and reasonably sets the weight of the scoring function through an adaptive weighting mechanism, selects the sample data that is most sensitive to quantization perception training, and implements distributed training in the core sample selection and quantization perception process, so as to achieve parallel acceleration of large models while improving the quantization training efficiency and quantization effect of large models.
[0040] Advantages of additional aspects of the present invention will be given in part in the following description, and in part will become obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings in the specification, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.
[0042] Figure 1 Schematic diagram of the structure of a multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to an embodiment of the present invention; Figure 2 is a schematic diagram of the structure of a collection module according to an embodiment of the present invention; Figure 3 is a diagram of a secure communication process according to an embodiment of the present invention; Figure 4 This is the deployment process of the large power grid model in the embodiment of the present invention; Figure 5 This is the training process of the large power grid model in the embodiment of the present invention; Figure 6 It is the process of automatic modeling of the intelligent alarm module in the embodiment of the present invention; Figure 7 is a schematic diagram of Communication data of a communication service model according to an embodiment of the present invention; Figure 8 is a schematic diagram of IED data of a communication service model of an embodiment of the present invention; Fig. 9 It is a schematic diagram of Data Type Templates data of a communication service model according to an embodiment of the present invention; Fig.10 It is a flow chart of the working method of the multi-modal perception operation and maintenance system of the autonomous and controllable substation according to an embodiment of the present invention. DETAILED DESCRIPTION
[0043] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0044] It should be noted that the following detailed descriptions are all illustrative and intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meanings as those commonly understood by those skilled in the art to which the present invention belongs.
[0045] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit exemplary embodiments according to the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprising" and / or "including" are used in this specification, it indicates the presence of features, steps, operations, devices, components and / or combinations thereof.
[0046] according to Figure 1, an embodiment of the present invention provides a multi-modal perception operation and maintenance system for an autonomous and controllable substation, which includes: a collection module 101, a communication module 102, a data analysis module 103 and a display module 104; The acquisition module 101 is used to synchronously acquire the real-time operation data of each electrical device in the substation host and the substation standby machine, or / and transmit the recording files of the substation host and the substation standby machine to the communication module; The communication module 102 is used to transmit the received operation synchronization data and / or recording files of each substation to the data analysis module after being processed by encryption and decryption algorithms; The data analysis module 103 is used to: use the large model of the power grid field to identify faults in the synchronous data of each substation operation, and retrieve matching solutions from the solution database according to the fault type; and query whether the recording file exists in a pre-created hash table that associates multiple recording files of different formats with the fault object, thereby determining the timeliness of the recording file; The display module 104 is used to display the fault identification results and the corresponding solutions and the timeliness analysis results of the recording files.
[0047] In one or more embodiments, in the data analysis module 103, when there is no solution corresponding to the identified fault type in the solution database, the solution corresponding to the fault type with the greatest similarity to the fault type description is searched from the solution database and transmitted to the display module for display.
[0048] The similarity here can be achieved by using the distance between two vectors, which will not be described in detail here.
[0049] In the data analysis module 103, when there is no solution corresponding to the identified fault type in the solution database, the finally determined solution and the matching fault type are stored in the solution database, and the solution database is updated.
[0050] Figure 2 Schematic diagram of the structure of the acquisition module of the embodiment of the present invention. Figure 2 As shown, the acquisition module 101 includes: A real-time database building module 1011 is used to build real-time databases for the main substation and the standby substation respectively; The multi-machine interaction module 1012 is used to use an encrypted and authenticated secure bus to establish a communication connection between the main substation machine and the standby substation machine; The communication link determination module 1013 determines the communication link between the substation host and the substation standby based on the communication connection and the real-time database, so that the substation host and the substation standby send their own communication device lists to each other through the security bus respectively to achieve real-time data synchronization.
[0051] The real-time database here is used to store real-time, dynamic, and changing data. The real-time database exists in the computer memory and is volatile storage. Commonly, shared memory, Redis, etc. can be used as the real-time database. The historical database stores various statistics, historical values, events, and other non-volatile and persistent information. Commonly, relational databases such as mysql and sqllite can be used as historical databases.
[0052] IPC (Inter-Process Communication, data bus) service, that is, IPC is used to send data and commands of this node to other nodes through network TCP or UDP to realize data transmission and command transmission.
[0053] In this embodiment, "real-time data" includes analog quantities (such as current and voltage), state quantities (signals), and measurement data transmitted through communication messages, as well as indirect data and related alarm event information generated after processing the original data (such as logical operations, filtering, etc.). By serializing these data, they can be transmitted between each node through the bus, thereby achieving the purpose of data synchronization.
[0054] In this embodiment, SCADA (Supervisory Control And Data Acquisition) and communication pre-programs are deployed in both the main substation and the standby substation. The communication device program is used to communicate with various protection and control devices, protocol conversion devices, online monitoring devices and other devices with network communication capabilities in the substation. The unprocessed data collected through data communication is the original data. The SCADA system performs arithmetic operations, inversion, dead zone judgment, mutation filtering and other processing on the original data according to the preset thresholds, coefficients, flags, etc., and converts it into engineering data that can be displayed, alarmed, and manually identified. At the same time, after processing, the original data and engineering data are stored in the real-time library for use by other subsystems (or modules), and the non-real-time and statistically significant engineering data are stored in the historical library.
[0055] Before performing security bus encryption authentication, the substation host is started, and reliable connection between each substation host is achieved based on the security bus. At the same time, the substation standby initiates a connection to the substation host; the substation standby initiates a registration request message to the substation host. Based on time authentication, the substation host authentication is passed if and only if the certificates match, completing the successful authentication of the security bus. The substation host and the substation standby can receive data messages from each other.
[0056] It should be noted that secure bus encryption can also use the ssh encrypted tunnel method, so that the bus itself does not need to perform data authentication and encryption, and the ssh tunnel provides authentication and encryption services.
[0057] In the multi-machine interaction module 1012, the substation host periodically sends its own communication equipment list to the corresponding substation standby machine, and the standby machine obtains the standby machine's global equipment list in combination with the substation host's collection equipment list; the substation standby machine marks and monitors the relevant equipment in the obtained host equipment list, and the substation standby machine does not communicate with the marked relevant equipment; at the same time, the substation standby machine periodically sends its own collection equipment list to the substation host, and the host obtains the host's global equipment list in combination with the substation standby machine's communication equipment list, and the substation host marks and monitors the relevant equipment in the obtained standby equipment list, and the substation host does not communicate with the marked relevant equipment.
[0058] In the multi-machine interaction module 1012, in this embodiment, the total data size is set to S. When the substation host and the substation standby are started, a real-time library of size S is fully established. The substation host and the substation standby are responsible for the communication links of the next S / N devices / modules according to the pre-configured data communication ratio (in this embodiment, N=2).
[0059] After the communication link is established, the substation host and substation standby communicate with each other for the device / module they are responsible for. In the substation, communication protocols such as DLT / 860 mms, CMS, modbus, cdt, 103, etc. are generally used. The substation host and substation standby process the S / N scale data respectively. The data processing includes but is not limited to data storage real-time library, storage history library, statistical processing, inversion processing, coefficient processing, change dead zone processing, associated telesignaling error and other business processing.
[0060] After the real-time database is established, the substation host and substation standby machines send their own communication equipment lists to the bus respectively; that is, each machine records the equipment lists L1, L2, ..., LN of all nodes responsible for communication. Generally, when N=2, each machine stores two equipment lists, L1 and L2.
[0061] In this embodiment, after processing the data of S / N scale, the substation host sends the processed results to the substation standby machine through the security bus. To ensure performance, the real-time library address offset method is adopted to transmit only necessary information. Before synchronizing the data, the real-time library determines the data attributes that need to be synchronized according to the pre-configuration of the real-time library, which usually includes the real-time library address, value, time, quality and other related attributes, referred to as the data synchronization packet (SyncPacket, SP). The substation host only needs to send the SP to the standby machine. Taking into account the length limit of the data message processed by the security bus or the operating system, it can be sent in frames. Generally, 500 data packets can be sent as one frame. At the same time, the substation standby machine also uses the same mechanism to send to the substation host.
[0062] After the substation host and substation standby machines are responsible for the S / N data respectively after processing, they only need to parse the processed message sent by the other party into a single SP data and immediately store it in the real-time library and historical library according to the address without the need to process the data again. Although each machine is only responsible for processing the S / N scale data, the data stored in the real-time library and historical database of each machine is the full amount of data S. Data storage redundancy is achieved, but data collection and processing are parallel.
[0063] The substation host will regularly send its own communication equipment list L1 to the standby machine. The data communication list structure includes the address, IP, and communication status of the communication to the lower level. After receiving the list L1, the substation standby machine will merge its own collection equipment list L2 into a global equipment list LG. In LG, all devices from L1 are marked, and the substation standby machine only monitors the status of these devices and does not perform communication processing. Similarly, the substation standby machine also regularly sends the equipment list L2 to the host, and the host also performs corresponding merging and monitoring work.
[0064] When the main substation machine fails, the standby substation machine will not be able to receive the communication equipment list L1 sent by the other party because the main substation machine is disconnected from the bus. Therefore, the standby substation machine will take over the communication of the data in the equipment list L1 to ensure uninterrupted data collection, and display the alarm on the interface to remind the duty personnel to deal with it immediately to restore the fault. At this time, the standby substation machine enters the single machine operation state.
[0065] When the substation standby machine takes over the equipment list L1, it will immediately classify the data from the equipment list L1 and the data from the equipment list L2, and cache the event information SOE and the historical library information HIS; the cache size is determined by the preset. If the host does not recover for a long time, a cache overflow alarm will be reported; the cache size can be set by the average fault handling time * average data load.
[0066] When the substation host recovers from a fault, it immediately makes a data synchronization request to the substation standby machine; the substation standby machine sends the cached data to the host machine; after receiving the cached data, the substation host machine resumes sending the equipment list L1; after receiving the equipment list L1, the substation standby machine performs a difference set processing on the equipment list L1 and its own global list LG, and the communication list is restored to the equipment list L2, and the substation host and the substation standby machine resume the parallel state of downward collection.
[0067] After this embodiment uses the security bus for data distribution, assuming that the accessed data scale is S and the number of monitoring computer nodes is N, the amount of data accessed by each monitoring host can be reduced to S / N. According to the typical configuration of general 220kV and above substations, N=2, the amount of data accessed by each monitoring host is reduced to S / 2, and each monitoring host can retain half of the CPU computing power, reducing the investment in the digital infrastructure of the substation; at the same time, the present invention fully considers the disaster recovery processing when a certain monitoring host fails, and provides an alarm prompt, which minimizes the data loss caused by the failure.
[0068] This embodiment utilizes the secure bus technology to connect multiple monitoring hosts in parallel into a large data processing center, and provides end-to-end encryption authentication technology to ensure that the computer nodes connected to the secure bus have legal authorization.
[0069] In the communication module, Figure 3 The secure communication process shown is: Before data transmission, the debugging tool and the gateway machine conduct key negotiation and generate their own public key and private key respectively; the debugging tool and the gateway machine pass their respective public keys to each other through public key exchange, and use the other party's public key and their own private key to calculate the shared session key.
[0070] Specifically, in the communication module, the debugging tool and the gateway machine transmit their respective public keys to each other through public key exchange, and use the other party's public key and their own private key to calculate a shared session key, including: The key pair generated by the debugging tool includes a first public key and a first private key, and the key pair generated by the gateway includes a second public key and a second private key; The debugging tool sends the first public key to the gateway machine, and the gateway machine sends the second public key to the debugging tool; After receiving the first public key of the debugging tool, the gateway machine calculates the session key using the first public key of the debugging tool and the second private key of the gateway machine; After receiving the first public key of the gateway machine, the debugging tool calculates a session key using the first public key of the gateway machine and the second private key of the debugging tool.
[0071] This embodiment takes the debugging tool and the gateway as the communicating parties as an example to illustrate that a secure key exchange needs to be performed before data transmission begins.
[0072] The key exchange process is as follows: Step 001: Generate a key pair: The debugging tool and the gateway machine generate their own key pairs, including public keys and private keys. Assume that the key pair generated by the debugging tool is (public key T, private key t), and the key pair generated by the gateway machine is (public key G, private key g); Step 002: Public key exchange: The debugging tool sends its public key T to the gateway machine, and the gateway machine sends its public key G to the debugging tool.
[0073] Step 003: Calculate the session key: After the gateway receives the public key T of the debugging tool, it uses the public key T of the debugging tool and its own private key g to calculate the session key K. Similarly, after the debugging tool receives the public key G of the gateway, it uses the public key G of the gateway and its own private key t to calculate the same session key K.
[0074] Step 004: Confirm the session key: The debugging tool and the gateway machine confirm that the session key K has been successfully generated and only the two of them know this session key.
[0075] Through the above key exchange process, the debugging tool and the gateway successfully generate a shared session key K for subsequent data encryption and decryption operations. In this way, even in a public network environment, data security transmission can be ensured.
[0076] During data communication, the debugging tool and the gateway machine encrypt and decrypt the power data to be transmitted based on the generated session key and the constructed encryption and decryption algorithm; wherein the construction process of the encryption and decryption algorithm includes: On the basis of the standard SM4 algorithm, additional rounds are added to expand the key to generate round keys, which are stored in the first array; Encrypt the data block based on the round key, generate a hash message authentication code based on a given HMAC key, merge the encrypted data and the hash message authentication code, and store them in a second array; The hash message authentication code in the array is verified, the data block is decrypted, and the generated state value is stored in the third array.
[0077] The encryption process includes: Once the session key is generated, the communicating parties can use the session key in combination with the ours-sm4-hmac algorithm to encrypt the data to be transmitted.
[0078] The debugging tool encrypts the plaintext data M to be transmitted using the session key K and the constructed encryption algorithm to generate the ciphertext C, which is expressed as: ; The debugging tool sends ciphertext C to the gateway.
[0079] The decryption process includes: After receiving the ciphertext C, the gateway uses the shared session key K and the ours-sm4-hmac algorithm to decrypt it and restore the original plaintext data M, which is expressed as: ; Assume that the debugging tool needs to send an encrypted message to the gateway. First, the debugging tool uses the shared session key K and the ours-sm4-hmac algorithm to encrypt the plaintext message "Hello, Gateway!" to generate ciphertext C. Then, the debugging tool sends ciphertext C to the gateway. After receiving ciphertext C, the gateway uses the same session key K and the ours-sm4-hmac algorithm to decrypt it and restore the original plaintext message "Hello, Gateway!".
[0080] In one or more embodiments, in the communication module, adding additional rounds based on the standard SM4 algorithm, expanding the key to generate round keys, and storing them in the first array includes: defining a first array of a preset size for storing the expanded key; Customize the key data information, read the key data information byte by byte, and store them in the first array respectively; Through a preset number of iterations, a new key value is generated each time using the previous key value and stored in the first array. In each iteration, linear transformation and nonlinear transformation are applied to increase the complexity of the key, and the generated round key is stored in the first array.
[0081] This embodiment takes the generation of 64 round keys through the round key generation function based on the original sm4_key_schedule as an example, and specifically includes the following steps: Step 011, initialize the array and define an array K of size 68 to store the expanded key.
[0082] Step 012, key loading and initial transformation: Customize key data information. In this embodiment, a 128-bit key (16 bytes) is selected. Four 32-bit integers are read byte by byte from the input 128-bit key (16 bytes) and stored in K[0] to K[3] respectively. These four integers are XORed and mixed with the fixed parameter FK.
[0083] Step 013, generate round keys: through 32 iterations, each time using the previous 4 key values to generate a new key value, and store it in K. In each iteration, linear transformation and nonlinear transformation are applied to increase the complexity of the key.
[0084] Step 014, output round keys: store the generated 64 round keys into the output array rk.
[0085] The round key is generated by the above function and is used for subsequent encryption and decryption processes.
[0086] Wherein, in the communication module, encrypting the data block based on the round key and generating a hash message authentication code based on a given HMAC key includes: A second array of a preset size is defined for storing intermediate data in the encryption process; Read the input plaintext data byte by byte and store them into the array respectively; Through a preset number of iterations, the current state value and round key are used for encryption transformation each time to generate a new state value; Convert the final state value back to a byte array and store it in a temporary variable; Hash the encrypted data using the given HMAC key to generate a hashed message authentication code.
[0087] Modify the encryption function to support 64 rounds of encryption. Encrypt the data block through the encryption function and generate HMAC to ensure the integrity and authenticity of the data. The specific steps include the following: Step 021: Initialize array: define an array X of size 68 to store intermediate data in the encryption process; Step 022: Data loading: read 4 32-bit integers byte by byte from the input 128-bit plaintext data and store them in X[0] to X[3] respectively; Step 023: Round key encryption: through 64 iterations, each time using the current state value and round key for encryption transformation, a new state value is generated; Step 024: Data output: Convert the final state value back into a byte array and store it in the temporary variable encrypted_data.
[0088] Step 025: Generate HMAC: Use the given HMAC key to perform a hash operation on the encrypted data to generate a 32-byte HMAC value.
[0089] Step 026: Combine output: Combine the encrypted data and HMAC value and store them in the output array output.
[0090] In the communication module, verifying the hash message authentication code in the array, decrypting the data block, and storing the generated state value in the third array includes: A third array of a preset size is defined to store intermediate data in the decryption process; Extract data and hash message authentication codes; Use the given hash message authentication code key to perform a hash operation on the extracted encrypted data to generate a new hash message authentication code; compare the generated hash message authentication code with the extracted hash message authentication code, and if they do not match, return verification failure; Through iterative operations, the current state value and the round key are used each time for decryption transformation to generate a new state value, and the final state value is converted back into a byte array and stored in the third array.
[0091] For example, modify the decryption function to support 64 rounds of decryption, including: Step 031: Initialize array: define an array X of size 68 to store intermediate data in the decryption process; Step 032: Extract data and HMAC, extract the first 16 bytes from the input data as encrypted data, and the last 32 bytes as the HMAC value.
[0092] Step 033: Verify HMAC, including: Hash the extracted encrypted data using the given HMAC key to generate a new HMAC value; compare the generated HMAC value with the extracted HMAC value, and return verification failure if they do not match.
[0093] Step 034: Round key decryption: Through 64 iterative operations, each time using the current state value and round key to perform decryption transformation, a new state value is generated.
[0094] Step 035: Data output: Convert the final state value back into a byte array and store it in the output array output.
[0095] This embodiment adopts the fusion encryption method of SM2 and SM4 for encryption, improves and re-implements the standard SM4 algorithm, and adds the HMAC data authentication function for communication, thereby ensuring the security and efficiency of the data transmission process.
[0096] In one or more embodiments, in the data analysis module, as Figure 4 As shown in the figure, the deployment process of the large model in the power grid field is: S401: Based on the relationship between the memory overhead of a single parameter, the memory overhead of a single gradient, the memory overhead of a single optimizer state, the number of model parameters, and the number of working nodes in data parallelism and the memory overhead of the storage-coordinated parallel decomposition strategy, the parallel decomposition strategy of the power grid domain is determined with the memory overhead of the storage-coordinated parallel decomposition strategy being the smallest; S402: Based on the parallel decomposition strategy of the large model in the power grid field, the hardware equipment information and deep learning framework are input using hyperparameters to automatically allocate hardware resources. Then, the deep learning model structure is set and the parallel decomposition scheme is configured using guided statements. The code is automatically translated to achieve automatic conversion and training of the deep learning model.
[0097] Specifically, in the data analysis module, during the current large model training process, due to the significant increase in data such as model parameters, gradients, and optimizer states, the memory overhead limit is much greater than the computational overhead limit. Therefore, a parallel decomposition strategy of computing and storage collaboration is proposed. From the perspective of limited memory, on the premise of improving model training efficiency, based on the model parameter, gradient, and optimizer state sharding technology, the parallel decomposition strategy of the large model in the power grid field of this embodiment adopts a parallel decomposition strategy of storage collaboration.
[0098] Single parameter memory overhead , single gradient memory overhead , memory overhead of a single optimizer state , model parameter quantity and the number of worker nodes in data parallelism These parameters are combined with the memory overhead of the parallel decomposition strategy to store The relationship between them is: .
[0099] This embodiment is based on the model sharding strategy, combines the model forward and backward propagation calculation time, communication time and model structure, and designs an optimal pipeline to improve the model training efficiency.
[0100] Among them, the model parameters for: ;in, The precision of floating point numbers.
[0101] The number of model parameters is automatically obtained by the deep learning framework.
[0102] In this embodiment, the parallel decomposition strategy of the large power grid domain model includes inter-group data parallelism, intra-group model parallelism, pipeline parallelism and optimizer parallelism strategies.
[0103] Among them, the intra-group model parallel strategy is: ;in, The memory cost of storing the coordinated parallel decomposition strategy, is the memory limit of a single device, Allocate amounts for devices in the group.
[0104] The data parallel strategy between groups is: ;in, Allocate quantities for devices in the group. Allocate quantities for devices between groups, The total number of available devices.
[0105] In order to solve the problems of elastic expansion and agile iterative updating of large model functions in the power grid field, the automatic generation technology of large model training in the power grid field was studied. It can automatically convert the artificial intelligence model trained and run in the traditional single-machine single-card environment in the power grid field into a large model in a multi-machine and multi-card environment, and can complete automatic hardware resource configuration and training. It currently supports deep learning frameworks PyTorch and Tensorflow, and is implemented through hyperparameter input and guided statements.
[0106] Hyperparameter input is mainly used for framework selection and hardware resource configuration. It supports inputting framework name, computing resource information, and network transmission information through hyperparameters.
[0107] Guidance statements are simple guidance statements inserted into the traditional AI model code to implement the parallel decomposition strategy of computing and storage collaboration. Guidance statements identify the parallel decomposition strategy adopted by the model, the specific number of devices for each strategy, and the model structure, so that the small model code in a single-machine single-card environment can be automatically translated into a large model code in a multi-machine multi-card environment.
[0108] Finally, the hyperparameter input and code translation results are used to achieve automatic configuration and execution of the hardware environment.
[0109] This embodiment adopts a parallel decomposition strategy of computing and storage collaboration, which can make full use of computing and storage resources. When using multiple (for example, 4) GPUs to complete distributed training of large models, memory overhead can be reduced by 50% compared with before applying this strategy, and the computing time can achieve an acceleration ratio of more than 5.4 times compared with a single GPU. Therefore, the comprehensive cost calculation can be reduced by about 52%.
[0110] This embodiment uses the automatic generation technology of large-scale model training in the power grid field, which can realize the agile iterative update of large models and the elastic expansion of functions, shortening the large-scale model development cycle. Assuming that an experienced large-scale model development engineer needs to go through five stages of building a data set, designing a domain model, adapting computing resources, fine-tuning a general large model, and tuning parameters to carry out the research and development of a domain large model, which takes a total of 3 months, the automatic generation technology proposed in this project can greatly reduce the process of domain model design, computing resource adaptation, and fine-tuning of a general large model, and the research and development cycle can be shortened by more than 50%.
[0111] In some other embodiments, in the data analysis module, Figure 5 As shown, the training process of the large power grid model is as follows: S501: Obtain configuration parameter information of the large model to be trained; S502: Based on the acquired configuration parameter information, construct a loss function of the large model, calculate the gradient norm, and obtain a first-order gradient information perception score of the large model; S503: adding disturbance to the large model, constructing the perturbation loss function of the large model, calculating the Hessian matrix, and obtaining the Hessian gradient information perception score of the large model; S504: performing an adaptive weighted combination on the obtained first-order gradient information perception score and Hessian gradient information perception score of the large model to obtain a quantitative perception score of the large model; S505: Determine the large model quantization perception training samples according to the obtained large model quantization perception score, and complete the distributed quantization perception training of the large model.
[0112] During the specific implementation process, in the data analysis module, in the process of determining the large model quantitative perception training samples, the weights in the obtained large model quantitative perception scores are sorted by size, the training samples are determined according to the sorting, and the determined samples are processed in parallel to complete the distributed quantitative perception training of the large model.
[0113] In the data analysis module, in the process of adaptive weighted combination, after standardization processing is performed on the obtained first-order gradient information perception score and Hessian gradient information perception score, the first-order gradient information perception score weight and the Hessian gradient information perception score weight are calculated, and the sample scores are adaptively weighted combined to obtain the quantitative perception score of the large model, and the sample data suitable for the quantitative perception training of the large model is determined according to the quantitative perception score of the large model.
[0114] In the data analysis module, during the distributed quantization perception training of the large model, the determined large model quantization perception training samples are divided into several subsets, the divided subsets are processed and the subset gradients are calculated, and all subset gradients are aggregated in combination with the communication protocol to complete the update of the global model parameters; the distributed quantization perception training of the large model is completed according to the updated model parameters.
[0115] In the data analysis module, the obtained large model loss function is back-propagated, and the partial derivatives of the loss function after back-propagation processing with respect to the model parameters are calculated to obtain the model gradient; the sum of the squares of all the obtained model gradients is used as the gradient norm, and the square root of the gradient norm is removed to obtain the first-order gradient information perception score of the large model.
[0116] This embodiment uses the first-order gradient to reflect the loss function, that is, the speed of change of the model parameters. When calculating the gradient of an input sample, it is actually evaluating the sensitivity of the model parameters to the loss changes caused by the sample; if the gradient norm of the sample is large, it means that the sample has a more significant impact on the model parameters, indicating that the model is more sensitive to the sample.
[0117] In this embodiment, the loss function Perform back propagation and calculate gradients ;in, represents the parameters of the model, i An index representing a model parameter.
[0118] Calculate the sum of squared gradients as the gradient norm: ; Taking the square root, we get: .
[0119] In the data analysis module, the second-order partial derivatives of the constructed large model containing the perturbation loss function with respect to the model parameters are calculated, the obtained second-order partial derivatives are used as the diagonal elements of the Hessian matrix, the sum of the squares of all the diagonal elements is calculated, and the Hessian gradient information perception score of the large model is obtained.
[0120] During quantization-aware training (QAT), the model needs to adapt to quantization errors. By calculating and analyzing the gradient norm, the top K samples are selected to identify the samples that have the greatest impact on the results in quantization-aware training. The obtained samples are used as a subset and re-involved in the model training process so that the model can still maintain a high accuracy after quantization.
[0121] This example perturbs the parameter weights and observes the increase in training loss.
[0122] Assuming given parameter perturbations, a second-order Taylor approximation of the training loss is used. Assuming given parameters , applying a small perturbation , so that , the change in training loss can be expressed as:
[0123] in, , represents the loss function Relative parameters The expectation of the gradient, and The ith value of the Hessian matrix representing the loss, is the loss function Relative parameters The second-order derivatives of (i.e., the diagonal elements of the Hessian matrix).
[0124] Since the target model is a convergent model, assuming ;get:
[0125] therefore, Quantifies the impact of perturbations caused by training samples on the model training loss. The larger the value, the more sensitive the sample is to the full-precision model and the richer the information contained in the sample, so the greater the possibility of selecting it as a core sample.
[0126] In actual calculations, directly obtaining the Hessian matrix score is very complex and computationally intensive, which will undoubtedly increase the additional computational cost in the quantization process. Therefore, this embodiment uses the Fisher information matrix (F) as an effective approximation; that is, the square sum of the gradients is used to approximate the square sum of the diagonal elements of the Hessian matrix.
[0127] Since H is the Hessian matrix of the negative log-likelihood loss, H is equivalent to the Fisher information matrix, that is:
[0128] In this embodiment, the score based on the Hessian matrix is recorded as:
[0129] The weighted combination of gradient score and Hessian matrix score can make the core sample selection method more reasonable. Different weights can reflect the different importance of gradient information and Hessian information in sample selection.
[0130] This embodiment introduces a weighting coefficient to adjust the relative importance of the two scores, and standardizes the gradient score and the Hessian matrix score respectively:
[0131]
[0132] in, is the mean of the first-order gradient scores, is the standard deviation of the first-order gradient information score, is the mean of the Hessian scores, is the standard deviation of the first-order gradient score; the variances of the first-order gradient score and the Hessian matrix score are:
[0133]
[0134] Get the weights of the gradient and Hessian scores:
[0135]
[0136] Combining the first-order gradient weight and the Hessian matrix weight, we get the final total score: .
[0137] This embodiment balances the influence of various types of samples and comprehensively selects the samples with the highest scores as the selected core samples.
[0138] In some other embodiments, in the data analysis module, the process of determining the timeliness of the recording file is: In a preset hash table, it is judged whether there is a currently received wave recording file. If so, the fault object associated with the currently received wave recording file in the hash table is determined, otherwise the query is terminated; wherein the hash table is a hash table in which multiple wave recording files of different formats are associated with the fault object, and multiple wave recording files of different formats are associated with a same fault object; Deleting the key-value pair of the recording file and the fault object in the hash table; If the associated fault object is empty or fault analysis is in progress, the query is terminated. Otherwise, it is determined whether there are multiple fault recording files of all preset different formats in the currently received recording file; if there are fault recording files of all preset types, the fault processing thread is executed, otherwise the recording files continue to be obtained.
[0139] In some embodiments, after receiving a list of fault recording files including a dat file, a cfg file, and an hdr file, a fault object is created, and then a hash table associating three file names with the fault objects is created. The three file names are all associated with the same fault object. Finally, the platform is requested for these three files in turn, and the platform is waited for to push the requested files to the App.
[0140] After receiving the file pushed by the platform, obtain the fault object corresponding to the file in the hash table. If the fault object obtained is not empty and has not started running, then verify that if all three files are received, start the analysis process of the fault object. It has strong timeliness and can meet the high real-time requirements of fault analysis of the smart alarm App.
[0141] For example, the process of determining the timeliness of a recording file may include: S1. The intelligent alarm app subscribes to the fault information of related devices from the main and auxiliary integrated platform.
[0142] Optionally, the smart alarm app is an app client with functions such as data processing and transmission; the main and auxiliary integrated platform is the integrated monitoring platform for main and auxiliary equipment of smart substations and other equipment; subscription can be understood as the smart alarm app receiving information from the main and auxiliary integrated platform. The relevant devices and fault information are all related equipment and fault information in the substation. The specific equipment and information content can be determined according to monitoring needs or other needs, and will not be described in detail.
[0143] S2. After a fault occurs, the protection or recording device will generate a recording signal and file. After the background collects the recording file of the device, it pushes the file list to the smart alarm App.
[0144] S3. The smart alarm App processes the received file list and divides it into one or more fault groups, and determines in turn whether the fault has been processed. If it has been processed, the data processing ends; if it has not been processed, proceed to step S4.
[0145] It can be understood that the smart alarm App processes the received file list and divides it into one or more fault groups. During the grouping process, a member that records the fault time is created for the fault group. A map is set in the App. The map records the fault groups that have been processed. The map is a key-value pair that associates the fault time with the grouping time. Whether the fault has been processed is determined based on whether the map contains the fault time of the fault. If the map contains the time, it means that it has been processed. If the map does not contain the time, it means that it has not been processed, and the time of the fault should be added to the map.
[0146] S4. Create a fault object according to the file list of each fault.
[0147] S5. Check whether the fault object is valid. If it is valid, proceed to step S6, otherwise terminate the process.
[0148] Optionally, the criterion for whether the fault object is valid is that the name must conform to the naming convention of the fault file, conform to the subscribed fault, and the list must contain at least three files; optionally, the naming convention ends with -_F or _f, and the three files are dat file, cfg file and hdr file.
[0149] S6. Associate the fault timeout signal and the processing function; the purpose of step S6 is to delete the created fault object if the smart alarm App has not received the file sent by the primary and secondary integrated platform for a long time, for example, if the file sent by the primary and secondary integrated platform has not been received for 10 minutes or more.
[0150] S7. The intelligent alarm app asynchronously requests fault files from the primary and secondary integrated platforms in sequence according to the file list, that is, requests dat files, cfg files, and hdr files in sequence.
[0151] S8. Add all requested files to a hash table, which is composed of file name-fault object key-value pairs; optionally, create dat file-fault object key-value pairs, cfg file-fault object key-value pairs, and hdr file-fault object key-value pairs in sequence.
[0152] S9. The smart alarm App receives the request file sent back by the platform and parses it. It first determines whether the hash table includes the file name. If not, the process ends. If included, the fault object associated with the file in the hash table is obtained, and then the file-fault object key-value pair is deleted from the hash table. If the fault object is empty or fault analysis is in progress, the process ends, otherwise step S10.
[0153] S10, check whether the three files of the fault object have all been summoned, that is, have all been received; if all have been received, start the fault processing thread, otherwise continue to wait for the request file sent by the platform.
[0154] This embodiment can complete the transmission of the fault recording file from the main and auxiliary integrated platform to the intelligent alarm App, and perform fault analysis in a timely manner, which can improve the time efficiency of fault analysis and meet the high real-time requirements of high-reliability substations.
[0155] In some other embodiments, the data analysis module further includes: comparing the SCD file of each substation with the reference SCD file, the process of which is: 1) Read the content of each subnode in the two SCD files to be compared; wherein the content of each subnode in the two SCD files to be compared includes: Substation, Communication, IED, DataTypeTemplates node and all subnodes under it.
[0156] 2) Compare the contents of each subnode in the two SCD files to be compared, and store the comparison results in a data structure; wherein the comparison process of the contents of each subnode in the two SCD files to be compared includes: The first SCD file is used as a reference file, and the specified nodes of the first SCD file are traversed. According to the unique attribute identifier of the node and the check code calculated based on the node content, the corresponding node and the node data with differences are searched in the second SCD file, and the node data with differences are stored as a change item in the data structure. The second SCD file is used as a reference file, the designated nodes of the second SCD file are traversed, the corresponding nodes are searched in the first SCD file, and the node data that are not searched are stored as new items in the data structure.
[0157] The following takes two SCD files A and B to be compared as examples to illustrate the specific comparison method. File A is used as the benchmark file, and the specified nodes of file A are traversed. One of the nodes to be compared, a, is used as an example to illustrate the method, including the following steps: Step a: Determine whether the node a to be compared has a unique identification attribute; Step b: If yes, search for the node b corresponding to the node a to be compared in the B file according to the unique identification attribute value of the node a to be compared. If yes, compare the attribute values of the node b corresponding to the node a to be compared. If there is a difference in the attribute value, store it in the change item of the data structure. If no difference exists, it means that the corresponding node b in the B file has been deleted, and store it in the deletion item of the data structure. Step c: If not, first delete all attributes of the node a to be compared, and calculate the check code C1 of the node a to be compared, then traverse the corresponding nodes in the B file, use the same method to calculate the check code C2, compare C1 and C2, and determine whether C1 and C2 are equal. If they are equal, they are the same node. Further compare the attribute values of the nodes. If there are differences in the attribute values of the nodes, store them in the change item of the data structure. Otherwise, there is no node with the same check code C1 in the B file, indicating that the node with the same check code C1 in the B file has been deleted and stored in the deletion item of the data structure. In this embodiment, the calculation method of the check code C1 and the check code C2 of the node a to be compared is: extracting the content sequence used to calculate the CRC check code, and the calculation rules include: (1) Delete spaces, line breaks, carriage returns, and list characters between elements and attributes; (2) Arrange all extracted element attributes in alphabetical order az; (3) Elements without child elements or assigned values end with " / >"; (4) Convert the sequence to a UTF-8 sequence and calculate the four-byte CRC-32 checksum. If the number is less than four bytes, the high byte is filled with 0x0. CRC calculation parameters: bit number Width = 32; generated item Poly = 04C11DB7; initialization value Init = FFFFFFFF; whether the data to be tested is reversed RefIn = True; whether the calculated value is reversed RefOut = True; output data XOR item XorOut = FFFFFFFF.
[0158] Step d: Repeat steps a to c until all the specified nodes of file A are compared.
[0159] Finally, file B is used as the reference file, the specified node is traversed, and the corresponding node is searched in file A. If it does not exist, it means that the node does not exist in file A. It is a new node, and it is stored as a new item in the data structure.
[0160] It should be noted that, in this embodiment, the check code may be a CRC (Cyclic Redundancy Check) check code, a parity check, MD5, SHA1, etc., which is not specifically limited in this embodiment and may be selected according to actual conditions.
[0161] In one or more embodiments, the data analysis module is further configured with an intelligent alarm module, such as Figure 6 As shown, the process of automatic modeling of the intelligent alarm module is: S601: constructing an initial basic information database; wherein the initial basic information database includes a characteristic signal database, a characteristic device database and a fault alarm information expert database; S602: Expand the initial basic information library according to the set rules; the process is as follows: classify the signals in the substation based on the preset rules, abstract the required signal types and store them in the characteristic signal library; classify the primary and secondary equipment based on the preset rules, abstract the required primary and secondary equipment types and store them in the characteristic equipment library; form fault alarm information based on the preset conditions for the occurrence of typical faults and the sequence of signal occurrence, and store the solutions corresponding to each type of fault alarm information in the fault alarm information expert library.
[0162] In step S602: the signals in the substation are classified according to the fault alarm discrimination conditions.
[0163] In the feature signal library, the classification rules of type signals are filtered by name keywords or reference signals, where the filtering rules support logical operations and priorities.
[0164] S603: Classify the signals / equipment contained in the selected actual interval / device according to the expanded characteristic signal library and characteristic equipment library, and then generate instances of fault distribution and alarm inference according to the expanded fault alarm information expert library and form an intelligent alarm configuration information file.
[0165] In step S603, the measuring points included in the interval are automatically classified according to the characteristic signal library, and then the judgment signal is instantiated depending on the fault analysis type associated with the interval.
[0166] The generated instance is the model required by the intelligent alarm analysis module, which is used to monitor the actual faults or abnormalities in real time.
[0167] In the specific implementation process, after classifying the equipment or signals, the signal type required for fault or alarm judgment can be bound to the actual equipment and signals contained in the interval or device based on the fault alarm information expert database to generate instances of fault distribution and alarm inference.
[0168] In one or more embodiments, users can also add or delete fault and alarm types automatically bound to intervals or devices, support personalized customization, and also support interval or device intelligent alarm modeling and copying operations. The alarm module of the interval or device can be copied, and then the device can be replaced to form a new interval or device alarm configuration.
[0169] The basic information database supports user extension and one-click import and export operations. It can be used as the initial information database for subsequent projects, reducing the workload of on-site implementation.
[0170] In the smart alarm configuration tool, create a smart alarm virtual interval and bind it to the actual physical interval. The actual physical interval refers to the interval within the substation, which is a combination of actual electrical equipment in the substation; the smart alarm virtual interval is a processing unit established in the smart alarm analysis module for advanced applications such as fault judgment and abnormal analysis. It can be bound to the actual physical interval or transformer or busbar. In addition, it also needs to be bound to other information required for advanced application analysis, such as interval or associated collection device information.
[0171] According to the primary devices contained in the interval and the measuring points bound to the primary devices, the IEDs where these measuring points are located are identified and automatically bound to the intelligent alarm virtual interval.
[0172] According to the IED bound to the bay and the voltage level and other information of the bay, the fault alarm type associated with the bay of this type is found in the fault alarm information library, and the alarm type that needs to be processed by the bay is constructed. The measuring points contained in the interval are automatically classified according to the characteristic signal library, and then the judgment signal is instantiated based on the fault analysis type associated with the interval.
[0173] By binding device type, fault type and signal, the modeling of intelligent alarm analysis is completed.
[0174] S604: Publish the intelligent alarm configuration information file to the intelligent alarm module to obtain the final basic information library.
[0175] This embodiment classifies the signals / equipment contained in the selected actual interval / device according to the expanded feature signal library and feature equipment library, and then generates instances of fault distribution and alarm inference according to the expanded fault alarm information expert library and forms an intelligent alarm configuration information file, which is then published to the intelligent alarm module to obtain the final basic information library, which supports rapid modeling and reduces the workload of on-site construction personnel; improves the actual utilization rate of intelligent alarms and reduces the workload of monitoring personnel; supports the import and export of the basic information library, improves the iteration rate of the basic information library, and is conducive to expanding the types of fault analysis and alarm reasoning processing.
[0176] In one or more embodiments, the data analysis module is further configured with a multi-thread management module, and the multi-thread management module is configured to: Use multiple threads to perform hardware monitoring, alarm information monitoring and control operations of the substation respectively; Adopt autonomous collection method and set sampling frequency to obtain hardware monitoring information and alarm information monitoring information of substation monitoring system platform in real time; Obtain the issued control operation items, perform corresponding control, manipulation and detection on the substation monitoring system, and obtain monitoring results; the control operation items are adaptively selected and determined based on the monitoring information obtained by autonomous collection.
[0177] In this embodiment, multithreading is used to perform hardware monitoring, alarm information monitoring and control operations in parallel, thereby improving the operating efficiency of the system. Each thread works independently and will not block each other, so that the system can respond to and process various monitoring tasks in real time; the multithreading has a clear division of labor and each performs its own duties. Even if a thread fails, other threads can continue to run, ensuring the overall stability and reliability of the system.
[0178] The autonomous collection method is: actively monitor and upload the hardware status and alarm information; Optionally, hardware status monitoring includes data collection of CPU load and main memory, physical memory and virtual memory, hard disk usage, network card usage, motherboard temperature, optical drive usage, and USB device status to ensure the health of the substation monitoring background hardware status; Optionally, alarm information monitoring includes local and remote login information, operation input echo, logout operation, screen unlock, abnormal network access, illegal port external connection, key directory / file changes, and user permission changes; In actual devices, there will be multiple IPs and ports enabled, but not all of them need to be monitored and alarmed. Adding normally used IPs and ports to the whitelist can eliminate the corresponding IP and port alarms.
[0179] A further technical solution is to configure a network and port whitelist when monitoring data is automatically collected and uploaded to achieve flexible monitoring. In order to achieve flexible monitoring, the configuration of the network and port whitelist can be dynamically managed through a configuration file or a management interface, including the following steps: Step a1, define a configuration file containing allowed network and port information; Specifically, the monitoring software is equipped with a configuration tool that can graphically configure device information including local or remote IP, port and network whitelist, and the switch options of various monitoring functions, which are ultimately stored in the configuration file.
[0180] Step a2: After the first monitoring software starts monitoring, it reads the configuration file and dynamically sets the firewall rules according to the configuration file; Specifically, different firewall rules are set according to different services provided in the configuration file, the confidentiality security level of the corresponding port transmission information, and other information to provide fine-grained access control.
[0181] In the above solution, configuring the network and setting the port whitelist to restrict data transmission to only specific network addresses and ports can improve the security and reliability of data transmission and prevent unauthorized access or data transmission.
[0182] Monitoring data is automatically collected and uploaded, and the TCP / IP protocol can be used to ensure reliable data transmission. The confirmation and retransmission mechanism can effectively avoid packet loss. Furthermore, the monitoring data is automatically collected and uploaded, including the following steps: Step b1, set the trigger mechanism for monitoring data collection to collect hardware status and alarm information; Step b2: Pack and compress the data, and prioritize the data transmission; Specifically, the data is divided into packets according to the set size to facilitate network transmission and retransmission; each packet contains a sequence number and a checksum to ensure data integrity; and the divided data is further compressed to reduce the amount of data transmitted, thereby increasing the transmission speed; Optionally, different priorities can be set according to the importance and real-time requirements of the data, and high-priority data such as alarm information can be transmitted first to ensure the real-time performance of key data; In this embodiment, data with high real-time requirements are scheduled first to ensure that they can be transmitted at the first time; Step b3, setting buffers at the sending end and the receiving end respectively, placing the data packets to be sent in the buffers according to the priority, and sending the data in the sending end buffer to the receiving end; In this step, buffers are used at the sending and receiving ends to manage the sending and receiving of data, which can prevent data loss caused by instantaneous network jitter.
[0183] Step b4: After receiving the data packet, the receiving end sends a confirmation message, and the sending end determines whether retransmission is required based on the confirmation message; Step b5: Set a timeout period. If no confirmation message is received within the specified time, the sender resends the data packet. In the above steps b4 to b5, data packet loss is avoided and the accuracy of data transmission is improved through the retransmission mechanism and the timeout retransmission mechanism.
[0184] A further technical solution is to dynamically adjust the data transmission rate according to the network bandwidth during data transmission to ensure that good real-time performance can be maintained when the network bandwidth fluctuates.
[0185] In order to achieve smooth data transmission, flow control mechanisms are further set up at the sending and receiving ends to prevent network congestion caused by excessively fast data transmission rates; The adaptive selection process is implemented in the network security master station, which automatically selects the optimal control operation item according to the current monitoring data and preset rules, and issues corresponding control commands for operation.
[0186] The terminal of the monitoring software of this embodiment is set to interact with the network security main station to perform control operations. The terminal of the monitoring software itself, as a client, may not actively perform control operations. The main station selects and sends control operation items through adaptive selection. After the monitoring software receives the corresponding message, the monitoring software performs the corresponding operation and returns the corresponding operation result.
[0187] For example, if a hardware indicator is detected to exceed a preset threshold, the network security master station chooses to perform corresponding control operations, such as parameter viewing or vulnerability scanning, and sends it to the monitoring software. The monitoring software performs the parameter viewing or vulnerability scanning process to obtain the detection result; Among them, the control operation items include parameter viewing, parameter setting, baseline verification, vulnerability scanning and active network disconnection operations; The adaptive selection is based on a preset rule base, which contains the optimal control operation items corresponding to different monitoring information. Specifically, the adaptive selection process is as follows: Step c1, data collection and preprocessing: collect hardware monitoring information and alarm information of the substation monitoring system and perform data preprocessing; Step c2, feature extraction: extract key features from the preprocessed monitoring data and perform standardization; Step c3, construction of rule base: constructing a rule base containing different monitoring information and optimal control operation items; Optionally, the rule base contains a series of predefined rules, each rule corresponding to specific monitoring information and optimal control operation items; Optionally, the rule format can be: IF <monitoring condition> THEN <control operation> For example: IF CPU usage > 90% AND memory usage > 80% THEN Execute the parameter view operation.
[0188] The rule base is continuously updated and optimized based on historical data and expert experience to ensure the effectiveness and accuracy of the rules Step c4, rule matching: check each rule in the rule base in turn according to the current feature set, perform rule matching, and determine whether the monitoring conditions are met; Step c5, selecting the optimal operation: selecting the optimal control operation item in the rule that meets the conditions based on the priority; Step c6, command issuance: Generate and issue control commands to execute corresponding control operations.
[0189] In one achievable implementation method, in step c4, the rule matching step in the adaptive selection process includes using a decision tree algorithm to sequentially check the monitoring conditions of each rule, find matching leaf nodes and execute corresponding control operation items; An alternative technical solution is that in step c4, the rule matching step may also include using a Bayesian network to calculate the posterior probability according to the current feature set, and selecting the control operation item with the highest probability for execution.
[0190] Another alternative technical solution is that in step c4, the rule matching step may also include using fuzzy logic to calculate the fuzzy membership based on the current feature set through a fuzzy inference system, and selecting the control operation item with the highest membership.
[0191] The monitoring method of this embodiment strengthens the self-security monitoring of the substation monitoring system, and monitors the software and hardware of the substation monitoring system in real time, which helps to warn of potential risks in advance and reduce the probability of safety accidents.
[0192] Further technical solutions, the monitoring software of this embodiment is written in C++, and the cross-platform development of the monitoring software has significant advantages and can run on multiple platforms. Secondly, it supports multiple compilers and has good support for different operating systems. For different hardware, 80% of the functions can be used normally, and only a small number of devices with different drivers and hardware interfaces need to be further adapted. Functional modularization, flexible and efficient development, high adaptation efficiency, solves the compatibility problem of different hardware products. It can solve the compatibility of software and hardware and adapt to equipment and systems from different manufacturers and different periods.
[0193] In one or more embodiments, the acquisition module 101 may be implemented using a CMS client, the data analysis module 103 may be implemented using a CMS server, and the CMS encrypted remote control communication process of the communication module 102 includes: Step A: Set the encrypted transmission mode on both the CMS server and the CMS client, and load the corresponding database for configuration. The encrypted transmission mode can be set specifically according to the actual situation.
[0194] Step B: The CMS client determines whether a connection is established with the CMS service port. If so, a remote control command is sent to the CMS server.
[0195] If the CMS client fails to establish a connection with the CMS service port, test the network connection with the CMS server (for example, ping the CMS server IP) and periodically detect the CMS service port. If the CMS server is detected, connect to the CMS server.
[0196] It should be noted here that, in other embodiments, the network connection amount with the CMS server may also be tested by using other existing command operations.
[0197] If the TCP / IP port is not monitored, the main process of the CMS server module will be exited.
[0198] In this embodiment, the remote control message structure includes a reference (reference), a controlled value (ctlVal), a remote control service operation time (operTm), a request origin (origin_orCat), an identity of the request initiator (origin_orIdent), a remote control sequence number (ctlNum), a change time (t), a test status (test), a check condition (check), and an attachment reason (AddCause).
[0199] Step C: The CMS server monitors the TCP / IP port to determine whether a remote control command is received. If so, continue to determine the positive response. If so, sign the remote control message and put the signature content into the remote control structure. Encode the remote control message and send it, and then forward the remote control success response to the CMS client.
[0200] If the CMS server responds positively, the remote control message is signed using the SM2 algorithm to generate a 64-bit hash value, and the 64-bit hash value is placed in the remote control structure.
[0201] Specifically, the 64-bit hash value is placed in the origin_orident field in the remote control structure.
[0202] If the CMS server responds negatively, the remote control responds negatively.
[0203] The remote control commands include: remote control selection, remote control execution and remote control cancellation.
[0204] Step D: After the CMS client receives the remote control response, it verifies the signature of the remote control message and determines whether the signature verification is successful. If so, the remote control is successful, otherwise the remote control fails.
[0205] When the remote control is successful, the CMS server performs a corresponding response operation according to the actual request operation corresponding to the remote control command.
[0206] After the signature verification is passed, the CMS server performs a positive (negative) response operation based on the actual remote control request. If the response is positive, the knife switch is closed or open, and the remote control ends. Otherwise, a negative response is directly replied, and the remote control ends.
[0207] This embodiment implements the remote control encrypted communication process during CMS communication of the substation monitoring system, encrypts the application layer, and transmits the remote control communication process in ciphertext, so that after intercepting the message, the message cannot be replayed to attack the equipment in the substation, which greatly improves the security and reliability in the substation.
[0208] In some optional embodiments, when the data analysis module 103 is implemented using a CMS server, the SylixOS operating system may be used to construct the CMS server.
[0209] The following is the specific process of using the SylixOS operating system to build a CMS server, including: Step 01, pre-build an SCL model, the SCL model includes Communication data, IED data, and DataTypeTemplates data; Step 02, using a configuration file in the SylixOS operating system to configure CMS server parameters, wherein the configuration file includes the file name of the SCL model; Step 03, based on the file name of the SCL model in the configuration file, the SCL model is parsed, and the parsed content is stored in a tree form; Step 04, apply for the space required for the CMS server to run, and execute the initialization and registration procedures; Step 05: Start the CMS service by calling the service interface and perform service configuration on the CMS service.
[0210] To facilitate understanding of the present invention, the following is a further description of the CMS protocol server-side construction method based on the SylixOS operating system provided by the present invention based on the principle of the CMS protocol server-side construction method based on the SylixOS operating system, combined with the process of establishing a CMS service for a protection measurement and control device using the SylixOS operating system in the embodiment.
[0211] The CMS protocol is a core communication protocol for substations with completely independent intellectual property rights, and is widely used in substation secondary systems and equipment. Taking the configurable hierarchical distributed heterogeneous protection and measurement and control device as an example, the substation configuration description language (SCL) is used as a model language to interact with the data of the protection and measurement and control device and the gateway. Specifically, the method for building a CMS protocol server based on the SylixOS operating system includes: Specifically, the SCL model structure includes: <header>Section: This section is used to identify the SCL file and its historical version information. Each entry in the historical version information can record its version, revision, reason for modification, modifier, modification time and modification content, etc.
[0212] <header> <history> <hitem revision="1.5" version="6.7" when="2021-07-12 10:26:49" who="" why="" what="" / > < / history> < / header> <substation>Part: It is used to describe the functional structure of the substation. This part is not considered by the protection and control device. Substation is not a necessary content and does not need to be constructed.
[0213] <communication>Part, such as Figure 7 As shown: It mainly includes the configuration of IP, MAC, IP-SUBNET and other communications. The station control layer and process layer subnet need to be configured in the protection and control device. The station control layer contains the basic information of A and B networks, and the process layer subnet needs to configure the MAC address, VLAN-ID, VLAN-PRIORITY, APPID, physical connection and other information of GOOSE, where the physical connection corresponds to the board number and port number in the protection and control device.
[0214] <ied>Part, such as Figure 8 As shown in the figure: It describes the basic information of the protection and control device. The logical devices and logical nodes are all included in the node AccessPoint. The logical devices include common LD, protection, wave recording, measurement and control. The logical device LD includes LLN0, general LPHD, alarm signal, GOOSE alarm, device temperature, power supply voltage monitoring, protection function blocking, and time synchronization status self-checking and other logical nodes.
[0215] <Data Type Templates> Part, such as Fig. 9 As shown: This part mainly describes the logical node type, including data type and data composition. It can be referenced by the logical node in the IED, provides a basis for the organization of data in the data set, and thus affects the content of data sent in the report. The logical node types include general LLN0, protection LLN0, measurement LLN0, protection and control LPHD, overcurrent protection, line overcurrent protection, protection tripping, etc.
[0216] The CMS protocol server of the protection and control device based on the SylixOS operating system is guided by the DL / T860 substation secondary system communication message (CMS) protocol specification, and directly maps the communication service model to TCP / IP to handle the operation request from the client in a monitoring manner, process the corresponding data according to the standard, and decide whether to send the message according to the specific operation. In the SylixOS operating system, the server call is called in the form of a library.
[0217] The specific process of step 02 includes: Step 021, pre-configure the server using a configuration file in the SylixOS operating system, wherein the configuration file includes information such as ASDU, APDU, whitelist, SCL file name, whether to enable Log, the maximum number of Logs, and file root path.
[0218] Step 022: According to the SCL file name in the configuration file, the data model is parsed and stored in a tree format. The parsed content includes: Communication parameters such as the local IP address must be consistent with the local content to start normally, otherwise the startup will fail.
[0219] The basic content of the data set includes the information of telesignaling and telemetering points.
[0220] Report control block information, including the dataset referenced by the report control block, trigger mode, whether it is urcb or brcb, etc.
[0221] Control information, including basic information of control points and control modes, etc.
[0222] Basic information of other control blocks except report control block.
[0223] Replacement information, including replacement point, replacement value, etc.
[0224] In the protection and control device based on the SylixOS operating system, only one CPU core is allocated to the server. Therefore, when starting the analysis, the number of threads opened will be reduced to avoid resource exhaustion caused by too many threads, making the CPU utilization rate as high as 100%.
[0225] Step 023, when SylixOS is initialized, it is necessary to apply for the space used by the server when it is running, and initialize the variables used; at the same time, it is necessary to register the user information callback, data information callback, and association callback; the user information callback is used for the registration of the user initialization callback, service startup and exit; the data information callback is used for the callback when data is read and written; the association callback is used for the callback when the client connection is disconnected. At the same time, during initialization, the corresponding interface can be used to obtain whether the startup is successful. The device returns information through the interface to perform the next operation. If it fails, the fault light needs to be lit to prompt. The device can obtain the IEDname through the corresponding interface. When there is a recording file, the recording file needs to be named. The device can obtain / write the information corresponding to a ref (a reference mechanism) by using the read-write interface, read data definition interface, etc.
[0226] Step 024, call the service interface, start the CMS service, start the listening service in the service, and listen to the connected client; when the client comes to connect, the basic information of the client needs to be judged in detail to determine whether it is in the whitelist and whether the maximum number of connections has been exceeded. The server starts all basic services, including association services, read and write services, definition acquisition services, report services, log services, control services, fixed value services, replacement services, file services, and remote procedure call services. For example, in the report service, the server stores the triggering method of the client and sends a report to the client when the established conditions are met. If the data triggering method is data change, and the client turns on the corresponding report control block, a report is sent to the client when the data changes. In the control service, the server saves and judges the client control mode and control sequence, and when the operation sequence corresponds to the control mode, the corresponding command is issued to the protection and measurement and control device. During the service process, the log information is printed and output to the file. In the protection and measurement and control device based on the SylixOS operating system, the information printing should not be output too much to the terminal.
[0227] Step 025, exit the service and release the space applied for by the server in sequence.
[0228] like Fig.10 As shown, this embodiment provides a working method of a multi-modal perception operation and maintenance system for an autonomous and controllable substation, including: S701: synchronously collect the real-time operation data of each electrical equipment in the substation host and the substation standby, or / and transmit the recording files of the substation host and the substation standby together through encryption and decryption algorithms; S702: Obtaining the decrypted operation synchronization data and / or recording files of each substation; S703: Use the large model of the power grid field to identify faults in the operation synchronization data of each substation, and retrieve matching solutions from the solution database according to the fault type; and query whether the recording file exists in a pre-created hash table that associates multiple recording files of different formats with the fault object, thereby determining the timeliness of the recording file; S704: Display the fault identification result and its corresponding solution and the timeliness analysis result of the recording file.
[0229] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.< / ied> < / communication> < / substation> < / header>
Claims
1. An autonomous and controllable substation multi-modal sensing operation and maintenance system, characterized in that: include: Acquisition module, communication module, data analysis module and display module; The acquisition module is used to synchronously acquire the real-time operation data of each electrical device in the substation host and the substation standby machine, or / and transmit the recording files of the substation host and the substation standby machine to the communication module; The communication module is used to transmit the received operation synchronization data and / or recording files of each substation to the data analysis module after being processed by encryption and decryption algorithms; The data analysis module is used to: use the large model of the power grid field to identify faults in the synchronous data of each substation operation, and retrieve matching solutions from the solution database according to the fault type; and query whether the recording file exists in a pre-created hash table that associates multiple recording files of different formats with the fault object, thereby determining the timeliness of the recording file; The display module is used to display the fault identification results and the corresponding solutions and the timeliness analysis results of the recording files.
2. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: In the data analysis module, when there is no solution corresponding to the identified fault type in the solution database, the solution corresponding to the fault type with the greatest similarity to the fault type description is searched from the solution database and transmitted to the display module for display.
3. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: In the data analysis module, when there is no solution corresponding to the identified fault type in the solution database, the finally determined solution and the matching fault type are stored in the solution database, and the solution database is updated.
4. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: The acquisition module comprises: A real-time database construction module is used to establish real-time databases for the main substation and the standby substation respectively; Multi-machine interaction module, used to use encrypted and authenticated secure bus for communication connection between substation host and substation standby; The communication link determination module determines the communication link between the substation host and the substation standby based on the communication connection and the real-time database, so that the substation host and the substation standby send their own communication device lists to each other through the security bus to achieve real-time data synchronization.
5. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 4, characterized in that: In the multi-machine interaction module, the substation host regularly sends its own communication equipment list to the corresponding substation standby machine, and the standby machine obtains the standby machine's global equipment list in combination with the substation host's collection equipment list; the substation standby machine marks and monitors the relevant equipment in the obtained host equipment list, and the substation standby machine does not communicate with the marked relevant equipment; at the same time, the substation standby machine regularly sends its own collection equipment list to the substation host, and the host obtains the host's global equipment list in combination with the substation standby machine's communication equipment list, and the substation host marks and monitors the relevant equipment in the obtained standby equipment list, and the substation host does not communicate with the marked relevant equipment.
6. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 5, characterized in that: In the multi-machine interaction module, when the substation host fails, the substation host is disconnected from the safety bus, and the substation standby machine cannot receive the communication equipment list sent by the substation host. The substation standby machine will take over the data communication in the communication equipment list to achieve uninterrupted data collection; at the same time, a substation host failure alarm prompt is issued, and at this time, the substation standby machine enters a single-machine operation state.
7. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 5, characterized in that: In the multi-machine interaction module, when the substation host recovers from a fault, it immediately sends a data synchronization request to the substation standby machine, and the substation standby machine sends the cached data to the substation host; after receiving the cached data, the substation host resumes sending the communication equipment list; after receiving the communication equipment list, the substation standby machine performs difference processing with the standby machine's global equipment list, and restores the global communication list to the standby machine's own collection equipment list, and the substation host and the substation standby machine resume the parallel state of downward collection.
8. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: In the communication module, before data transmission, the debugging tool and the gateway machine perform key negotiation to generate their own public key and private key respectively; the debugging tool and the gateway machine transmit their own public keys to each other through public key exchange, and calculate the shared session key by using the other party's public key and their own private key; During data communication, the debugging tool and the gateway machine encrypt and decrypt the power data to be transmitted based on the generated session key and the constructed encryption and decryption algorithm; wherein the construction process of the encryption and decryption algorithm includes: On the basis of the standard SM4 algorithm, additional rounds are added to expand the key to generate round keys, which are stored in the first array; Encrypt the data block based on the round key, generate a hash message authentication code based on a given HMAC key, merge the encrypted data and the hash message authentication code, and store them in a second array; The hash message authentication code in the array is verified, the data block is decrypted, and the generated state value is stored in the third array.
9. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 8, characterized in that: In the communication module, the debugging tool and the gateway machine transmit their respective public keys to each other through public key exchange, and use the other party's public key and their own private key to calculate a shared session key, including: The key pair generated by the debugging tool includes a first public key and a first private key, and the key pair generated by the gateway includes a second public key and a second private key; The debugging tool sends the first public key to the gateway machine, and the gateway machine sends the second public key to the debugging tool; After receiving the first public key of the debugging tool, the gateway machine calculates the session key using the first public key of the debugging tool and the second private key of the gateway machine; After receiving the first public key of the gateway machine, the debugging tool calculates a session key using the first public key of the gateway machine and the second private key of the debugging tool.
10. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 8, characterized in that: In the communication module, on the basis of the standard SM4 algorithm, an additional round is added to expand the key to generate a round key, which is stored in the first array, including: defining a first array of a preset size for storing the expanded key; Customize the key data information, read the key data information byte by byte, and store them in the first array respectively; Through a preset number of iterations, a new key value is generated each time using the previous key value and stored in the first array. In each iteration, linear transformation and nonlinear transformation are applied to increase the complexity of the key, and the generated round key is stored in the first array.
11. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 8, characterized in that: In the communication module, the data block is encrypted based on the round key, and a hash message authentication code is generated based on a given HMAC key, including: A second array of a preset size is defined for storing intermediate data in the encryption process; Read the input plaintext data byte by byte and store them into the array respectively; Through a preset number of iterations, the current state value and round key are used for encryption transformation each time to generate a new state value; Convert the final state value back to a byte array and store it in a temporary variable; Hash the encrypted data using the given HMAC key to generate a hashed message authentication code.
12. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 8, characterized in that: In the communication module, verifying the hash message authentication code in the array, decrypting the data block, and storing the generated state value in the third array includes: A third array of a preset size is defined to store intermediate data in the decryption process; Extract data and hash message authentication codes; Use the given hash message authentication code key to perform a hash operation on the extracted encrypted data to generate a new hash message authentication code; compare the generated hash message authentication code with the extracted hash message authentication code, and if they do not match, return verification failure; Through iterative operations, the current state value and the round key are used each time for decryption transformation to generate a new state value, and the final state value is converted back into a byte array and stored in the third array.
13. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: In the data analysis module, the deployment process of the large model in the power grid field is: Based on the relationship between the memory overhead of a single parameter, a single gradient, a single optimizer state, the number of model parameters, and the number of working nodes in data parallelism and the memory overhead of the storage-cooperative parallel decomposition strategy, the parallel decomposition strategy for large models in the power grid field is determined with the storage-cooperative parallel decomposition strategy having the smallest memory overhead. Based on the parallel decomposition strategy of the large model in the power grid field, the hardware equipment information and deep learning framework are input using hyperparameters to automatically allocate hardware resources. Then, the deep learning model structure is set and the parallel decomposition scheme is configured using guided statements. The code is automatically translated to achieve automatic conversion and training of the deep learning model.
14. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 13, characterized in that: In the data analysis module, the memory overhead of a single parameter is , single gradient memory overhead , memory overhead of a single optimizer state , model parameter quantity and the number of worker nodes in data parallelism These parameters are combined with the memory overhead of the parallel decomposition strategy to store The relationship between them is: .
15. The multi-modal sensing operation and maintenance system for autonomous controllable substation according to claim 14, characterized in that: In the data analysis module, the model parameter quantity for: ;in, The precision of floating point numbers.
16. The multi-modal sensing operation and maintenance system for autonomous controllable substation according to claim 13, characterized in that: In the data analysis module, the parallel decomposition strategy of the large model in the power grid field includes inter-group data parallelism, intra-group model parallelism, pipeline parallelism and optimizer parallelism strategies.
17. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 16, characterized in that: In the data analysis module, the intra-group model parallel strategy is: ;in, The memory cost of storing the coordinated parallel decomposition strategy, is the memory limit of a single device, Allocate quantities for devices within the group; The data parallel strategy between groups is: ;in, Allocate quantities for devices in the group. Allocate quantities for devices between groups, The total number of available devices.
18. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: In the data analysis module, the training process of the large power grid domain model is as follows: Get the configuration parameter information of the large model to be trained; Based on the acquired configuration parameter information, the loss function of the large model is constructed, the gradient norm is calculated, and the first-order gradient information perception score of the large model is obtained; Add disturbance to the large model, construct the perturbation loss function of the large model, calculate the Hessian matrix, and obtain the Hessian gradient information perception score of the large model; Adaptively weight the first-order gradient information perception score and the Hessian gradient information perception score of the large model to obtain a quantitative perception score of the large model; According to the obtained large model quantization perception score, the large model quantization perception training samples are determined to complete the distributed quantization perception training of the large model.
19. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 18, characterized in that: In the data analysis module, in the process of determining the large model quantitative perception training samples, the weights in the obtained large model quantitative perception scores are sorted, the training samples are determined according to the sorting, and the determined samples are processed in parallel to complete the distributed quantitative perception training of the large model.
20. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 18, characterized in that: In the data analysis module, in the process of adaptive weighted combination, after standardization processing is performed on the obtained first-order gradient information perception score and Hessian gradient information perception score, the first-order gradient information perception score weight and the Hessian gradient information perception score weight are calculated, and the sample scores are adaptively weighted combined to obtain the quantitative perception score of the large model, and the sample data suitable for the quantitative perception training of the large model is determined according to the quantitative perception score of the large model.
21. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 18, characterized in that: In the data analysis module, during the distributed quantization perception training of the large model, the determined large model quantization perception training samples are divided into several subsets, the divided subsets are processed and the subset gradients are calculated, and all subset gradients are aggregated in combination with the communication protocol to complete the update of the global model parameters; the distributed quantization perception training of the large model is completed according to the updated model parameters.
22. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 18, characterized in that: In the data analysis module, the obtained large model loss function is back-propagated, and the partial derivatives of the loss function after back-propagation processing with respect to the model parameters are calculated to obtain the model gradient; the sum of the squares of all the obtained model gradients is used as the gradient norm, and the square root of the gradient norm is removed to obtain the first-order gradient information perception score of the large model.
23. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 18, characterized in that: In the data analysis module, the second-order partial derivatives of the constructed large model containing the perturbation loss function with respect to the model parameters are calculated, the obtained second-order partial derivatives are used as the diagonal elements of the Hessian matrix, the sum of the squares of all the diagonal elements is calculated, and the Hessian gradient information perception score of the large model is obtained.
24. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: In the data analysis module, the process of determining the timeliness of the recording file is as follows: In a preset hash table, it is judged whether there is a currently received wave recording file. If so, the fault object associated with the currently received wave recording file in the hash table is determined, otherwise the query is terminated; wherein the hash table is a hash table in which multiple wave recording files of different formats are associated with the fault object, and multiple wave recording files of different formats are associated with a same fault object; Deleting the key-value pair of the recording file and the fault object in the hash table; If the associated fault object is empty or fault analysis is in progress, the query is terminated. Otherwise, it is determined whether there are multiple fault recording files of all preset different formats in the currently received recording file; if there are fault recording files of all preset types, the fault processing thread is executed, otherwise the recording files continue to be obtained.
25. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: The data analysis module also includes: comparing the SCD file of each substation with the benchmark SCD file, the process of which is: Read the contents of each subnode in the two SCD files to be compared; Compare the contents of each subnode in the two SCD files to be compared, and store the comparison results in a data structure; wherein the comparison process of the contents of each subnode in the two SCD files to be compared includes: The first SCD file is used as a reference file, and the specified nodes of the first SCD file are traversed. According to the unique attribute identifier of the node and the check code calculated based on the node content, the corresponding node and the node data with differences are searched in the second SCD file, and the node data with differences are stored as a change item in the data structure. The second SCD file is used as a reference file, the designated nodes of the second SCD file are traversed, the corresponding nodes are searched in the first SCD file, and the node data that are not searched are stored as new items in the data structure.
26. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: The data analysis module is also configured with an intelligent alarm module, and the process of automatic modeling of the intelligent alarm module is as follows: Constructing an initial basic information database; wherein the initial basic information database includes a characteristic signal database, a characteristic device database and a fault alarm information expert database; According to the set rules, the initial basic information library is expanded; the process is as follows: based on the preset rules, the signals in the substation are classified, the required signal types are abstracted and stored in the characteristic signal library; based on the preset rules, the primary and secondary equipment are classified, the required primary and secondary equipment types are abstracted and stored in the characteristic equipment library; based on the preset conditions for the occurrence of typical faults and the sequence of signal occurrence, fault alarm information is formed, and the corresponding solutions for various types of fault alarm information are stored in the fault alarm information expert library; According to the expanded characteristic signal library and characteristic device library, the signals / devices contained in the selected actual interval / device are classified, and then according to the expanded fault alarm information expert library, the examples of fault distribution and alarm inference are generated and the intelligent alarm configuration information file is formed; Publish the intelligent alarm configuration information file to the intelligent alarm module to obtain the final basic information library.
27. The multi-modal sensing operation and maintenance system for an autonomous and controllable substation according to claim 1, characterized in that: The data analysis module is further configured with a multi-thread management module, and the multi-thread management module is configured as follows: Use multiple threads to perform hardware monitoring, alarm information monitoring and control operations of the substation respectively; Adopt autonomous collection method and set sampling frequency to obtain hardware monitoring information and alarm information monitoring information of substation monitoring system platform in real time; Obtain the issued control operation items, perform corresponding control, manipulation and detection on the substation monitoring system, and obtain monitoring results; the control operation items are adaptively selected and determined based on the monitoring information obtained by autonomous collection.
28. A working method of a multi-modal sensing operation and maintenance system for an autonomous controllable substation according to any one of claims 1 to 27, characterized in that: include: Synchronously collect the real-time operation data of each electrical equipment in the main substation and the standby substation, or / and transmit the recording files of the main substation and the standby substation together with encryption and decryption algorithms; Obtain the decrypted synchronous operation data and / or recording files of each substation; Use the large-scale model in the power grid field to identify faults in the synchronous data of each substation operation, and retrieve matching solutions from the solution database according to the fault type; and query whether the recording file exists in the pre-created hash table that associates multiple recording files of different formats with the fault object, and then determine the timeliness of the recording file; Displays the fault identification results and their corresponding solutions as well as the timeliness analysis results of the recording files.
Citation Information
Patent Citations
Graphical comparing method for SCD (substation configuration description) files of intelligent substation
CN104636490A
Intelligent substation data management and decision-making system and method and terminal device
CN110175204A
Data penetration retrieval method and system for autonomous controllable transformer substation in centralized control mode
CN115442413A
Large model assembly line parallel training method and system based on gradient sensing parameter freezing
CN118568499A
Software security development method based on large model
CN118761066A