Anti-misoperation method for electrical equipment of decentralized control system of thermal power plant
By setting up control node numbers and multi-level verification mechanisms in the thermal power plant decentralized control system, the challenge of preventing misoperation of electrical equipment in thermal power plant is solved, significantly reducing the risk of misoperation and ensuring the accuracy and safety of operation.
Patent Information
- Application Number
- CN202510134167.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-02-06
AI Technical Summary
The anti-missive operation methods of electrical equipment in thermal power plants rely on manual review and are easily affected by personnel factors. The reaction time after the operation instructions are issued is short, resulting in high risk of misoperation and endangering personal and equipment safety.
Design a method to prevent misoperation of electrical equipment in the thermal power plant's decentralized control system. By setting up control node numbers, establishing equipment number databases, generating first- and second-level control instructions, and verifying them through a multi-level verification mechanism to reduce the risk of misoperation.
The multi-level verification mechanism significantly reduces the possibility of misoperation, ensures the accuracy and safety of operations, and reduces the misoperation caused by mismatch of operator authority or improper handling of emergency situations.
Smart Images

Figure CN120029202A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to the technical field of electrical equipment control, in particular to a method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant. Background Art
[0002] At present, most of the electrical equipment in thermal power plants is remotely operated through the human-machine interaction interface of the distributed control system. The means to prevent misoperation of important electrical equipment start and stop and electrical switch opening and closing are only double-checked manually by electrical operators and supervisors. The effect of preventing misoperation is greatly affected by human factors, and electrical equipment acts quickly after the operation instructions are issued, and there is often no reaction time. Once an erroneous operation is performed, it will endanger the safety of people and equipment. Summary of the invention
[0003] The purpose of the present invention is to design a method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant, to number important electrical equipment, to distinguish between emergency and non-emergency operating states, to verify the operating object using the equipment number in the non-emergency state, to utilize the control system design, to consider a variety of possible situations in practice, to prevent misoperation of electrical equipment, and to eliminate major hidden dangers that endanger personal and equipment safety.
[0004] In order to achieve the above object, the present invention provides a method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant, comprising: A method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant, comprising: Setting the control node number based on the acquired electrical equipment information; Establish a numbering database for electrical equipment by combining the label contents of all control nodes; Generate primary control instructions based on the operating status information of the distributed control system; Verify the primary control instruction based on the first error prevention model to generate the secondary control instruction; The secondary control instructions are verified based on the second error prevention model.
[0005] In some embodiments of the present invention, the first-level error prevention model includes: Set operator categories and emergency conditions for thermal power plants; Among them, the categories of operators include: operator level and engineer level; the emergency conditions of thermal power plants include: primary operation state and secondary operation state; Obtain the current operator category and emergency status of the thermal power plant based on the operating status information of the distributed control system; Human-machine interaction interface based on operator category and emergency operation of thermal power plants; Generate secondary control instructions based on the information sent by the human-computer interaction interface.
[0006] In some embodiments of the present invention, when generating the secondary control instruction, it includes: Generating a set A of emergency situation reference values for the current thermal power plant based on the acquired historical operation status data of the current thermal power plant, A = {a1, a2... ai... an}; Wherein, ai is the i-th emergency situation reference value, and n is the number of emergency situation reference values in the set of emergency situation reference values; Judging the emergency situation of the current thermal power plant by comparing ai with the preset emergency situation value ah; If ai ≥ ah, the current thermal power plant is in the first-level operation state; If ai < ah, the current thermal power plant is in the second-level operation state; If the current user category is the operator level, then run the operator-level human-computer interaction interface; If the current user category is the engineer level, then run the engineer-level human-computer interaction interface; Combining the emergency situation of the current thermal power plant and the current human-computer interaction interface; If the current thermal power plant is in the first-level operation state and the running human-computer interaction interface is the operator-level human-computer interaction interface, directly set the first-level control instruction as the secondary control instruction; If the current thermal power plant is in the second-level operation state and the running human-computer interaction interface is the operator-level human-computer interaction interface, then perform sending verification on the first-level control instruction; If the running human-computer interaction interface is the engineer-level human-computer interaction interface, directly set the first-level control instruction as the secondary control instruction.
[0007] In some embodiments of the present invention, when performing sending verification on the first-level control instruction, it includes: Performing text verification on the numbered text input by the operator-level personnel type; The text verification includes: numbered text form verification and control point number verification; If the text verification passes, then delete the numbered text; If the text verification fails, then generate an alarm prompt message until the verification passes.
[0008] In some embodiments of the present invention, when performing the text verification, it includes: The distributed control system includes multiple partitions, and each partition includes multiple electrical devices; Setting the electrical device operation interface based on the partition; When the current operation interface performs numbered text input, the characters already input on the operation interfaces of the remaining electrical devices are automatically cleared; Set the effective time for number text character input according to the actual execution time of the electrical operation. The number text entered after the effective time is exceeded will be automatically cleared.
[0009] In some embodiments of the present invention, the second error prevention model includes: Generate a first reference value of the distributed control system and the current node based on the secondary control instruction; Generate a second reference value of the current control node by combining the acquired operation status information of the current control node device and the secondary control instruction; Classify the secondary control instructions based on historical data to generate a control type set, and generate a third reference value based on the historical data and the current secondary control instruction control type; Setting a first preset value, a second preset value, and a third preset value corresponding to the first reference value, the second reference value, and the third reference value in combination with historical data; When the first reference value, the second reference value and the third reference value all reach the corresponding first preset value, the second preset value and the third preset value, the secondary control instruction passes the verification; In some embodiments of the present invention, the generating of the first reference value of the distributed control system and the current node includes: Obtaining the number of the control node based on the secondary control instruction; Send verification data to the control node through the distributed control system and obtain verification data feedback; Set communication status judgment indicators based on historical data; A first reference value is generated by combining the communication status judgment indicator and the verification data feedback.
[0010] In some embodiments of the present invention, the generating of the second reference value of the current control node includes: Get the running status information of the current control node; Classify the operation status information based on historical data to generate a function execution reference value set B of the current control node, B={b1,b2…bj…bm}; Wherein, bj represents the jth function execution reference value of the current control node, and m represents the number of function items of the current control node; Determine the function subset B1 that the current control node needs to execute based on the secondary control instruction; Obtaining function execution reference values of all function items in function subset B1 from function execution reference value set B; Generate a second reference value by comparing the function execution reference values of all function items in the function subset B1 with the function execution preset values; In some embodiments of the present invention, the generating of the third reference value of the current control node includes: Based on historical data, the control types of the secondary control instructions are divided to generate a control type set C, C = {c1, c2…ck…cq}; Wherein, ck represents the kth control type of the secondary control instruction, and q represents the total number of control types of the secondary control instruction; Combine the control type of the current secondary instruction and the current operating status of the thermal power plant to generate a direct feasibility reference value e1 and an indirect feasibility reference value e2; The third reference value of the current control node is generated based on the direct feasibility reference value e1 and the indirect feasibility reference value e2 of the current thermal power plant operation state.
[0011] In some embodiments of the present invention, the generating of the direct feasibility reference value e1 and the indirect feasibility reference value e2 includes: The operation status of the thermal power plant is divided based on historical data to generate a thermal power plant operation status data set; Combine the control type set C and the thermal power plant operation status data set to generate the execution evaluation value of the thermal power plant operation status corresponding to the control type of each secondary control instruction; Obtain the execution evaluation value of the control type of the current secondary instruction to generate a direct feasibility reference value e1; Obtain a correlation reference value between the control node of the current secondary instruction and the abnormal control node; and generate an indirect feasibility reference value e2 based on the correlation reference value.
[0012] Compared with the prior art, the method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant provided by the embodiment of the present invention has the following beneficial effects: The possibility of misoperation is significantly reduced through a multi-level verification mechanism. Each level of verification checks the control instructions from different angles.
[0013] The corresponding human-machine interface is operated through multiple factors to generate secondary control instructions. This means that the operation is customized based on the current operating environment and personnel authority, avoiding misoperation caused by operator authority mismatch or improper handling of emergency situations.
[0014] By comparing with the preset value, it is more objective and accurate to determine whether the emergency situation is a first-level operating state or a second-level operating state, which provides a reliable basis for taking different operations according to different emergency situations, thereby improving the accuracy of instruction generation.
[0015] When sending and verifying the first-level control instructions, text verification is performed on the numbered text entered by the operator-level personnel to ensure the accuracy of the format and content of the entered instructions and reduce erroneous operations caused by input errors.
[0016] The distributed control system consists of multiple partitions, each of which has a corresponding electrical equipment operation interface. This partition setting helps operators to manage and operate electrical equipment in different areas more clearly.
[0017] The effective time for number text character input is set according to the actual execution time of the electrical operation. The number text entered after the effective time is exceeded is automatically cleared, which ensures the timeliness of the operation, prevents other operations from being affected by long-term occupation of input resources, and encourages operators to input instructions efficiently and accurately, thereby improving overall operating efficiency.
[0018] A comprehensive judgment is made by sending verification data to the control node and combining the communication status judgment indicators set with historical data; a comprehensive reference value generation method ensures that the control instructions are evaluated from multiple aspects, enhancing the reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 The present invention provides a flowchart of a method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant. DETAILED DESCRIPTION
[0020] The specific implementation of the present invention is further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0021] In the description of the present invention, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship are based on the orientation or position relationship shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention.
[0022] The terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, unless otherwise specified, "plurality" means two or more.
[0023] In the description of the present invention, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.
[0024] Embodiment 1: A method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant, such as Figure 1 As shown, including: Setting the control node number based on the acquired electrical equipment information; Establish a numbering database for electrical equipment by combining the label contents of all control nodes; Generate primary control instructions based on the operating status information of the distributed control system; Verify the primary control instruction based on the first error prevention model to generate the secondary control instruction; The secondary control instructions are verified based on the second error prevention model.
[0025] Embodiment 2: The first-level error prevention model includes: Set operator categories and emergency conditions for thermal power plants; Among them, the categories of operators include: operator level and engineer level; the emergency conditions of thermal power plants include: primary operation state and secondary operation state; Obtain the current operator category and emergency status of the thermal power plant based on the operating status information of the distributed control system; Human-machine interaction interface based on operator category and emergency operation of thermal power plants; Generate secondary control instructions based on the information sent by the human-computer interaction interface.
[0026] Operator Level: This category is mainly responsible for daily operation tasks, such as routine switching operations on electrical equipment, parameter adjustments (such as adjusting voltage, current, etc. within a certain range), etc. Their operation permissions are relatively limited, mainly based on the set operation process, and they cannot modify the key settings or complex functions of the system.
[0027] Operator-level personnel receive specialized operational training and are familiar with the basic operation of electrical equipment, but may have limited understanding of the system's in-depth technical principles and complex troubleshooting.
[0028] Engineer level: Engineer-level personnel have higher technical capabilities and broader operational permissions. They can not only perform routine operations, but also deeply configure and adjust the system. For example, when upgrading the system, diagnosing faults and repairing them, engineers can modify the control algorithms of electrical equipment, adjust the safety thresholds of the system, reprogram the control logic of the equipment, etc.
[0029] Engineers need to have profound professional knowledge, including knowledge of electrical engineering, automation control, computer technology, etc., to cope with complex system maintenance and optimization tasks.
[0030] First level operation status: When a thermal power plant is in the first-level operation state, it indicates that a more serious situation has occurred. For example, there may be a risk of failure of key components of the generator set (such as abnormal vibration of the main shaft of the steam turbine, excessive temperature of the stator winding of the generator close to the critical value, etc.), or a large fluctuation in electricity (such as a sudden drop in power output exceeding a certain percentage, which may affect the stability of the power grid).
[0031] In this state, emergency measures need to be taken immediately to ensure equipment safety and stable power supply, and some non-critical equipment may need to be shut down or adjusted urgently to ensure the normal operation of core equipment.
[0032] Secondary operating status: The second level of operation indicates that there are some situations in the thermal power plant that need attention but have not yet reached the level of emergency. For example, the operating parameters of an auxiliary device (such as the flow rate of the cooling water pump is slightly lower than the normal level, but it has not yet affected the cooling effect of the main equipment) are abnormal, or the control system detects some potential minor faults (such as the signal of some sensors has slight fluctuations, but it does not affect the accuracy of the overall operation data).
[0033] At this time, although there is no need to take large-scale emergency measures immediately, it is necessary to closely monitor the operating conditions of related equipment and systems and perform some preventive operations or adjustments.
[0034] Operator category acquisition: In a distributed control system, each operator needs to undergo identity authentication when logging into the system. The system determines whether the operator is at the operator level or engineer level based on the permission level of the login account.
[0035] At the same time, the system will monitor operating behavior in real time. If an operator-level personnel attempts to perform operations beyond his or her authority (such as modifying the control logic of key equipment), the system will issue a warning and block the operation to ensure the safety and compliance of the operation.
[0036] Emergency status of thermal power plant: The distributed control system obtains the operation status information of various equipment and systems in the thermal power plant through a large number of sensors. These sensors are distributed in various parts such as the generator set, boiler, and auxiliary equipment, and can monitor key parameters such as temperature, pressure, flow rate, and rotational speed in real time.
[0037] The system will analyze the data collected by these sensors. For example, for temperature data, the system will set different thresholds. When the temperature of a certain device exceeds the threshold of the secondary operation state but has not reached the threshold of the primary operation state, the system determines it as the secondary operation state; when the temperature exceeds the threshold of the primary operation state, it is determined as the primary operation state. At the same time, the correlation relationship between multiple parameters (such as the relationship between steam pressure and flow rate) will also be analyzed to more accurately judge the overall emergency situation.
[0038] Example 3: When generating the secondary control instruction, it includes: Generating a set A of emergency situation reference values for the current thermal power plant based on the obtained historical operation status data of the current thermal power plant, A = {a1, a2…ai…an}; Wherein, ai is the i-th emergency situation reference value, and n is the number of emergency situation reference values in the set of emergency situation reference values; Judging the emergency situation of the current thermal power plant by comparing ai with the preset emergency situation value ah; If ai≥ah, then the current thermal power plant is in the primary operation state; If ai < ah, then the current thermal power plant is in the secondary operation state; If the current user category is operator level, then run the operator-level human-computer interaction interface; If the current user category is engineer level, then run the engineer-level human-computer interaction interface; Combining the emergency situation of the current thermal power plant and the current human-computer interaction interface; If the current thermal power plant is in the primary operation state and the running human-computer interaction interface is the operator-level human-computer interaction interface, then directly set the primary control instruction as the secondary control instruction; If the current thermal power plant is in the secondary operation state and the running human-computer interaction interface is the operator-level human-computer interaction interface, then perform a sending verification on the primary control instruction; If the running human-computer interaction interface is the engineer-level human-computer interaction interface, directly set the primary control instruction as the secondary control instruction.
[0039] In this embodiment, historical operating status data are collected from various monitoring systems of the thermal power plant. These data come from a wide range of sources, including but not limited to operating parameters of generator sets (such as power output, speed, oil temperature, water temperature, etc.), operating data of boilers (such as steam pressure, steam temperature, water level, etc.), and data of auxiliary equipment (such as flow and pressure of cooling systems, air volume of ventilation systems, etc.).
[0040] The collected data is classified and sorted to remove outliers and erroneous data. For example, data points that are significantly out of the normal range are identified and corrected through data cleaning algorithms. The data is then sorted by time series for subsequent analysis.
[0041] According to different types of operating data, different calculation methods are used to determine the emergency reference value ai.
[0042] For key parameters such as power output, calculate statistical indicators such as the mean and standard deviation. For example, AI can be the sum of the mean and standard deviation of power output over a period of time (such as the past hour), reflecting the comprehensive level of power output and its fluctuations.
[0043] For temperature-related data, such as boiler water temperature, AI can be the difference between the temperature change curve fitted based on historical data and the current actual temperature. If the difference is too large, it may indicate that the water temperature control is abnormal. This difference can be used as an emergency reference value to help determine whether an emergency is approaching.
[0044] The failure frequency of equipment, such as the number of failures of an electrical device in the past period of time, can also be used as an emergency reference value. The mean time between failures of the equipment is calculated and its reciprocal is used as part of the AI to reflect the reliability of the equipment and the potential emergency risk.
[0045] The basis for determining the setting of the emergency preset value ah is: The setting of the emergency preset value ah requires comprehensive consideration of the design parameters, safety standards and previous operating experience of the thermal power plant.
[0046] For parameters related to power output, ah can be set according to the grid access requirements and the rated power of the generator set. For example, if the rated power of the generator set is 100MW, ah can be set to be considered close to an emergency when the power output is below 80MW or above 110MW. This value is determined based on the grid stability requirements and the safe operating range of the generator set itself.
[0047] For temperature parameters, ah is set based on the material properties of the equipment, the safe operating temperature range, and the temperature thresholds when failures occurred in the past. For example, for some key parts of a boiler, the safe operating temperature range is 80-120°C, and ah can be set to be considered close to an emergency when the temperature exceeds 110°C or is below 85°C.
[0048] For parameters related to failure frequency, ah is set according to the reliability index and maintenance strategy of the equipment. If the MTBF of a certain equipment is designed to be 1000 hours, when the calculated MTBF is less than 500 hours (i.e. the failure frequency is too high), it is considered to be close to an emergency.
[0049] Compare ai and ah one by one. When comparing ai and ah related to power output, if ai (such as the fluctuation value of power output) is greater than ah (the set power fluctuation threshold), it may indicate that the power supply is unstable and further judgment is needed whether it is in the first-level operation state.
[0050] For temperature-related comparisons, if ai (such as the difference between the water temperature and the fitting curve) is greater than ah (temperature deviation threshold), it may mean that there is a problem with the boiler's water temperature control, which also requires the integration of other parameters to determine the level of the emergency.
[0051] When comparing ai and ah related to fault frequency, if ai (such as the calculated value of fault frequency) is greater than ah (the set critical value of fault frequency), it means that the reliability of the equipment has decreased, which may have a serious impact on the operation of the entire thermal power plant, and it is necessary to consider raising the emergency level.
[0052] Operational characteristics of the operator-level human-machine interface (under different emergency conditions): In normal secondary operation, the operator-level human-machine interface mainly displays concise and clear operation information. For example, the basic operating parameters of each device are displayed in an intuitive chart form, such as the switch status of the device is represented by green (on) and red (off) indicator lights, and parameters such as voltage and current are displayed in real time in digital form next to the corresponding device icon.
[0053] The operation options are mainly daily operation tasks, such as starting and stopping the equipment, simple parameter adjustment (such as adjusting the voltage within the small allowable range), etc. These operation options are presented in the form of large icons or eye-catching buttons, which are convenient for operators to operate quickly.
[0054] When in the first-level operation state, the layout of the operator-level human-machine interaction interface will change. The interface will highlight the equipment or parameters in dangerous states in eye-catching colors (such as red), and give clear prompts for emergency operations. For example, for equipment that needs to be shut down urgently, an "Emergency Shutdown" button will be displayed next to the equipment icon, accompanied by a flashing warning sign. At the same time, some operations that may cause greater harm to the system (such as starting some non-critical equipment that may increase the system burden in an emergency) will be hidden or disabled to prevent operators from operating them incorrectly.
[0055] Operational characteristics of the engineer-level human-computer interaction interface (under different emergency conditions): In the secondary operation state, the engineer-level human-computer interaction interface provides more technical analysis tools. In addition to the basic equipment operation parameter display, it also displays the detailed operation curve of the equipment (such as the change trend of the power output curve in the past period of time), the health status assessment of the equipment (the potential failure risk level of the equipment based on data analysis), etc.
[0056] Engineers can perform some in-depth operations, such as fine-tuning the control algorithm of the device. The operation interface will provide a code editing area (for operations involving algorithm adjustment), and provide syntax checking and simple logic verification functions. At the same time, the interface will display links to technical documents related to the device, making it convenient for engineers to check detailed technical information.
[0057] In the first-level operation state, the engineer-level human-computer interaction interface provides more comprehensive system control. The interface will display a more detailed system architecture diagram, including the connection relationship between devices, interlocking logic, etc. Engineers can modify the interlocking relationship between devices. The operation interface will provide simulation tools to simulate the possible impact of such modifications before engineers make modifications, so that engineers can make accurate decisions. At the same time, the interface will display real-time fault alarm information of all devices, including fault codes, specific locations of faults, and possible cause analysis, to help engineers quickly locate and solve problems.
[0058] Operator-level human-machine interaction interface and secondary control instructions in the primary operating state: In this case, the first-level control instruction is directly set as the second-level control instruction. This is because in the first-level operation state, the operations at the operator level are usually some urgent and simplified operations, such as emergency shutdown of a certain equipment to avoid greater losses.
[0059] However, before converting the primary control instruction into the secondary control instruction, the human-machine interface will perform a simple format and rationality check on the primary control instruction. For example, it will ensure that the instruction format to shut down the device is correct and that the device can indeed perform the shutdown operation in its current state (such as the device is not locked by other systems or in a special state where it cannot be shut down). If the check fails, the operator will be prompted to re-enter or adjust the instruction.
[0060] Operator-level human-machine interaction interface and secondary control instructions in the secondary operation state; When in the secondary operation state and at the operator-level human-machine interaction interface, the primary control instructions are sent for verification.
[0061] First, the first-level control instructions are formatted and checked to see if they meet the required format requirements. For example, for instructions to adjust device parameters, the instruction format should include the device number, parameter name, and the value to be adjusted. Format verification ensures that these elements are complete and meet the required format requirements.
[0062] Then, permission verification is performed to ensure that the operator has the authority to execute the instruction. For example, the adjustment of certain advanced parameters may exceed the operator's authority. Permission verification will detect this and refuse to send the instruction.
[0063] Next, parameter range verification is performed to check whether the parameter value to be adjusted in the instruction is within the allowed range. For example, if the voltage of a device is to be adjusted, the verification will check whether the input voltage value is within the upper and lower limits of the device's rated voltage. Only when all verifications are passed will the primary control instruction be converted into a secondary control instruction and sent to the next level control system.
[0064] Engineer-level human-machine interaction interface and secondary control instructions (regardless of operating status); When the engineer-level human-computer interaction interface is running, the first-level control instruction is directly set as the second-level control instruction.
[0065] Before converting the primary control instructions into secondary control instructions, the human-machine interface will perform a series of complex checks. For instructions involving the modification of the device control algorithm, syntax checking, logic verification and evaluation of the overall impact on the system will be performed.
[0066] Syntax checking ensures that the algorithm code entered by the engineer complies with the syntax rules of the programming language. Logic verification checks whether the logic of the algorithm is correct. For example, when modifying the device interlocking logic, ensure that the new logic does not cause conflicts or deadlocks between devices.
[0067] The assessment of the overall impact on the system is achieved through simulation tools. For example, when modifying the power control algorithm of a certain device, the simulation tool will predict the impact of this modification on the power output, stability, etc. of the entire thermal power plant based on the current system operating status and parameters of other devices. Only when all checks are passed will the first-level control instructions be converted into second-level control instructions.
[0068] Embodiment 4: The sending verification of the first-level control instruction includes: Perform text verification on the number text input by operator-level personnel type; The text verification includes: number text form verification and control point number verification; If the text verification passes, delete the numbered text; If the text verification fails, an alarm message will be generated until the verification passes.
[0069] In this embodiment, the numbering text should follow specific formatting rules. For example, it may be in the form of a letter-number combination, where the letter part indicates the partition or type to which the device belongs, and the number part indicates the serial number of the device in the partition or type. For example, "A-001" indicates the No. 1 electrical device in partition A.
[0070] For the letter part, only specific capital letters can be used, which have a clear correspondence with the divisions or equipment types of the thermal power plant. For example, "A" may represent the power generation area, "B" represents the power transmission area, etc. The number part is required to be three digits, starting from "001" and increasing.
[0071] When the operator enters the number text, the system first checks whether the text format meets the requirements. If the input is pure numbers or a combination of letters and numbers that does not meet the requirements, such as "123" or "a - 1" (lowercase letters do not meet the requirements), the system determines that the number text format verification fails.
[0072] The system also checks whether the length of the number text is correct. If the specified number text length is a specific value (such as the above letter - three digits, a total of 5 characters), and the entered text length is not equal to this value, for example, entering "A - 1" (length is 3 characters), it will also be judged as not passing the check.
[0073] For electrical equipment within each zone, there is a predefined range of control point numbers. For example, in the power generation zone (Zone A), the control point numbers for equipment may range from 1 to 100. In the transmission zone (Zone B), the number range is 101 to 200, etc.
[0074] These ranges are determined based on the equipment layout of the thermal power plant and the design of the control system. Each control point number corresponds to a specific control function or equipment parameter.
[0075] When the operator enters the number text, the system extracts the numeric part (representing the control point number) and then checks whether the number is within the number range corresponding to the zone to which it belongs. If the number entered is "A - 150" and the number range of the power generation zone (A zone) is 1 to 100, the system determines that the control point number verification has failed.
[0076] At the same time, the system will also check whether the control point number has been assigned to a valid electrical device. If the device corresponding to the entered number has been removed or does not exist, the verification will be considered failed.
[0077] Embodiment 5: The text verification includes: The distributed control system includes multiple partitions, each of which includes multiple electrical devices; Set up the electrical equipment operation interface based on partitions; When the current operation interface is executing the number text input, the characters already input in other electrical equipment operation interfaces will be automatically cleared; Set the effective time for number text character input according to the actual execution time of the electrical operation. The number text entered after the effective time is exceeded will be automatically cleared.
[0078] In this embodiment, when both the form check of the numbering text and the control point number check are passed, the system immediately deletes the numbering text entered by the operator.
[0079] This deletion operation is to prevent the number text from being used incorrectly or causing confusion in subsequent operations. When deleting the number text, the system will record the operation request corresponding to the number text and convert it into an internal control instruction format for subsequent processing and execution.
[0080] If the number text format verification fails, the system will generate an alarm message that clearly indicates the specific content of the text format error. For example, "The number text format is incorrect. Please enter it in the format of 'letter-three digits', where the letters should be uppercase."
[0081] When the control point number verification fails, the alarm prompt message will inform the operator that the control point number is not in the valid range or the corresponding device does not exist. For example, "The input control point number 150 is not in the valid range (1 - 100) of the power generation area (Partition A), please re-enter."
[0082] The system will continue to display the alarm message until the operator re-enters the number text and passes the verification. Each time the operator re-enters the number text, the system will re-perform the complete text verification process, including the number text form verification and the control point number verification.
[0083] Each zone in the distributed control system has an independent electrical equipment operation interface. These operation interfaces are similar in design, but are customized for the equipment characteristics of each zone.
[0084] When the number text input is executed in the current operation interface, the characters already entered in the other electrical equipment operation interfaces are automatically cleared. For example, when the operator enters the number text in the operation interface of the power generation area (partition A), any characters previously entered in the operation interface of the transmission area (partition B) will be cleared. This is to avoid confusion when the operator operates between different partitions and ensure that the operation of each partition is independent and clear.
[0085] According to the actual execution time of the electrical operation, set the effective time of the number text character input. This effective time is determined by considering the timeliness and safety of the electrical equipment operation.
[0086] For example, for some equipment operations that require a quick response, such as emergency shutdown operations, the effective time may be set to 10 seconds. If the operator does not complete the number text input within 10 seconds, the system will automatically clear the entered number text.
[0087] The system will display a countdown timer on the operation interface to remind the operator of the remaining valid input time. When the countdown ends, the entered number text is automatically cleared, and if the operator wants to operate again, he needs to start over and re-check the text.
[0088] Embodiment 6: The second error prevention model includes: Generate a first reference value of the distributed control system and the current node based on the secondary control instruction; Generate a second reference value of the current control node by combining the acquired operation status information of the current control node device and the secondary control instruction; Classify the secondary control instructions based on historical data to generate a control type set, and generate a third reference value based on the historical data and the current secondary control instruction control type; Setting a first preset value, a second preset value, and a third preset value corresponding to the first reference value, the second reference value, and the third reference value in combination with historical data; When the first reference value, the second reference value and the third reference value all reach the corresponding first preset value, the second preset value and the third preset value, the secondary control instruction passes the verification; Embodiment 7: The generating of the first reference value of the distributed control system and the current node includes: Obtaining the number of the control node based on the secondary control instruction; Send verification data to the control node through the distributed control system and obtain verification data feedback; Set communication status judgment indicators based on historical data; A first reference value is generated by combining the communication status judgment indicator and the verification data feedback.
[0089] In this embodiment, after receiving the verification data, the control node processes the verification data according to its own functions and internal logic, and returns feedback information.
[0090] The feedback information may include data reception confirmation, execution results (if the verification data contains test instructions), current status information of the control node, etc.
[0091] The distributed control system will wait for feedback from the control node and set a reasonable waiting time (this time is determined according to the delay characteristics of the communication and the processing speed of the control node). If no feedback is received within the waiting time, it will be considered that the communication has failed and corresponding fault processing will be performed, such as resending verification data or marking the control node as a communication failure state.
[0092] The system collects and analyzes past communication data, which includes information such as the success rate of communication with each control node, communication delay, and data error rate.
[0093] For the communication success rate, the ratio of the number of successful communications with each control node to the total number of communication attempts in the past period of time (such as the past day, week, or month) is counted.
[0094] The communication delay data records the time interval from sending data to receiving feedback for each communication. By analyzing these historical delay data, the range of normal communication delay and the threshold of possible abnormal delay can be determined.
[0095] The data error rate is calculated by counting the number of data verification errors that occurred in historical communications and calculating the ratio of the number of errors to the total communication data volume.
[0096] According to the analysis results of historical data, set the communication status judgment index.
[0097] For example, the threshold of the communication success rate is set to 80%. If the communication success rate with a certain control node is lower than 80% within a certain period of time, it is considered that there may be a problem with the communication state of the control node.
[0098] For communication delay, set the normal delay range to [lower limit, upper limit], such as [10ms, 50ms]. If the delay of a communication exceeds this range, it may indicate a communication abnormality.
[0099] The data error rate threshold can be set to 1%. When this threshold is exceeded, it indicates that the accuracy of the data during the communication process is affected, and there may be communication failure or interference.
[0100] The first reference value is a quantitative indicator for comprehensively evaluating the communication status of the control node. Its calculation needs to consider the communication status judgment indicator and the verification data feedback.
[0101] If the communication success rate in the verification data feedback is higher than the success rate threshold in the communication status judgment indicator, it contributes positively to the first reference value. For example, if the success rate threshold is 80% and the actual success rate is 90%, the value of the first reference value will be increased according to certain calculation rules (such as proportional calculation).
[0102] For communication delay, if the delay of verification data feedback is within the normal delay range, it will also make a positive contribution to the first reference value; if the delay exceeds the range, the first reference value will be reduced according to certain rules based on the degree of excess.
[0103] In terms of data error rate, if the error rate of the verification data feedback is lower than the data error rate threshold, it has a positive impact on the first reference value; otherwise, the first reference value is reduced.
[0104] Embodiment 8: The step of generating the second reference value of the current control node includes: Get the running status information of the current control node; Classify the operation status information based on historical data to generate a function execution reference value set B of the current control node, B={b1,b2…bj…bm}; Wherein, bj represents the jth function execution reference value of the current control node, and m represents the number of function items of the current control node; Determine the function subset B1 that the current control node needs to execute based on the secondary control instruction; Obtaining function execution reference values of all function items in function subset B1 from function execution reference value set B; Generate a second reference value by comparing the function execution reference values of all function items in the function subset B1 with the function execution preset values; In this embodiment, the operation status information of the current control node is obtained from a variety of sensors and monitoring devices. These sensors can be internal sensors directly connected to the control node, used to monitor the hardware status of the control node itself, such as a temperature sensor monitoring the temperature of the control node chip, a voltage sensor monitoring the supply voltage, etc.
[0105] It can also be a sensor related to the device controlled by the control node. For example, if the control node controls a motor, then the data fed back by the motor's speed sensor, current sensor, etc. is also part of the control node's operating status information, because this data reflects the control effect of the control node on the device.
[0106] The operating status information includes but is not limited to the operating parameters of the equipment (such as power, current, voltage, speed, etc.), the health status of the equipment (such as whether there is a fault alarm, fault code, etc.), the resource utilization of the control node (such as CPU usage, memory usage, etc., if the control node is an intelligent controller), etc.
[0107] This information is collected and transmitted in a specific data format. For example, a standard industrial data protocol (such as the Modbus protocol) is used to organize the data into a data frame, which contains the data identifier, value, timestamp and other information for subsequent analysis and processing.
[0108] Analyze the historical operation data of the control node, which covers the operation status information of different time periods (such as the past hours, days, weeks, months, etc.).
[0109] Through data mining techniques, such as cluster analysis and association rule mining, we can find out the relationship pattern between the operating status information and the execution of the control node function. For example, through analysis, we found that when the temperature of the control node is within a certain range, it has a specific impact on the execution efficiency of a certain function; when the current of the controlled device is within a certain range, it is related to the stability of another function.
[0110] Take the motor start function of the control node as an example. If historical data shows that the start success rate is highest when the voltage at motor start is in the range of [220V - 230V], then this voltage range can be used as a function execution reference value b1 of the start function. If it is found that the start stability is best when the ambient temperature at motor start is in the range of [10°C - 30°C], this temperature range can also be used as another function execution reference value b2 of the start function.
[0111] For different function items j, multiple function execution reference values are determined in this way, thereby forming a function execution reference value set B = {b1, b2…bj…bm}, where m represents the number of function items of the control node.
[0112] After determining the functional subset B1, check the completeness of the functional subset to ensure that all relevant functions are correctly identified and there are no conflicts or omissions.
[0113] For example, if the control node needs to perform a complex operation that requires starting the motor and turning on the related cooling system at the same time, then the functional subset B1 should include both the motor start function and the cooling system start function. If only the motor start function is identified, the system will prompt or further analyze to ensure the integrity of the functional subset.
[0114] For each function item in the function subset B1, the function execution reference value set B is searched for the corresponding function execution reference value.
[0115] For example, if the function subset B1 includes the motor starting function, then the previously determined function execution reference values related to the motor starting are found in the function execution reference value set B, such as the voltage range, the temperature range, and the like.
[0116] In this way, the function execution reference values of all the function items in the function subset B1 are extracted, and these reference values will be used for subsequent comparison operations.
[0117] Function execution presets are set based on control node design specifications, safety standards, and best practices.
[0118] For the motor starting function, the function execution preset values may include the standard starting voltage (such as 220V), the allowed starting temperature range (such as 5°C - 40°C), etc. These preset values are the benchmarks for judging whether the control node function is executed normally.
[0119] For each function item in the function subset B1, its function execution reference value is compared with the corresponding function execution preset value.
[0120] Taking the motor starting function as an example, if the actual starting voltage function execution reference value is [210V - 230V], and the preset value is 220V, according to certain calculation rules (such as calculating the deviation ratio between the reference value and the preset value), a comparison result value corresponding to the function item is obtained.
[0121] Such a comparison calculation is performed on all the function items in the function subset B1, and then these comparison result values are combined to generate a second reference value according to a certain comprehensive calculation method (such as a weighted average method, assigning different weights according to the importance of different function items). This second reference value reflects the degree of deviation of the current control node from the ideal state when executing the specified function subset B1.
[0122] Embodiment 9: The step of generating the third reference value of the current control node includes: Based on historical data, the control types of the secondary control instructions are divided to generate a control type set C, C = {c1, c2…ck…cq}; Wherein, ck represents the kth control type of the secondary control instruction, and q represents the total number of control types of the secondary control instruction; Combine the control type of the current secondary instruction and the current operating status of the thermal power plant to generate a direct feasibility reference value e1 and an indirect feasibility reference value e2; The third reference value of the current control node is generated based on the direct feasibility reference value e1 and the indirect feasibility reference value e2 of the current thermal power plant operation state.
[0123] In this embodiment, historical records of secondary control instructions of the thermal power plant are collected, and these records contain detailed information of secondary control instructions issued at different times in the past, such as the target of the instruction, operation content, execution time, etc.
[0124] These historical instructions are classified and sorted, and the main control objectives and operation methods of each instruction are analyzed. For example, some secondary control instructions may be for power adjustment of generator sets, some may be for start and stop control of equipment, and some may be for adjustment of equipment operating parameters (such as temperature, pressure, etc.).
[0125] The control type is determined according to the control target and operation mode of the instruction. For example, all instructions related to the start and stop of the equipment are classified into a control type c1, and instructions related to power adjustment are classified into a control type c2, etc.
[0126] Each control type has its own unique characteristics. For example, for the equipment start and stop control type, its characteristic is that the instructions mainly focus on the conversion of the equipment's on and off states, and the operating parameters involved may be the equipment's switching signals, starting sequence, etc.; while the power adjustment control type focuses on the setting and adjustment of the generator set's output power, and the parameters involved may be power setting values, adjustment rates, etc.
[0127] According to this division method, a control type set C = {c1, c2…ck…cq} is constructed, where q represents the total number of control types of secondary control instructions.
[0128] Embodiment 10: The generation of the direct feasibility reference value e1 and the indirect feasibility reference value e2 includes: The operation status of the thermal power plant is divided based on historical data to generate a thermal power plant operation status data set; Combine the control type set C and the thermal power plant operation status data set to generate the execution evaluation value of the thermal power plant operation status corresponding to the control type of each secondary control instruction; Obtain the execution evaluation value of the control type of the current secondary instruction to generate a direct feasibility reference value e1; Obtain a correlation reference value between the control node of the current secondary instruction and the abnormal control node; and generate an indirect feasibility reference value e2 based on the correlation reference value.
[0129] In this embodiment, for each control type ck in the control type set C, its execution status in different operating states of the thermal power plant operating state data set is analyzed.
[0130] For example, for the equipment start-stop control type (assuming c1), in normal operation, if a standby device is to be started, the execution may be good because other devices are operating normally and there are sufficient resources to support the start of the new device. An evaluation value can be set based on various parameters in the startup process (such as startup time, impact on the power grid, etc.), assuming it is 0.8.
[0131] When some devices fail, starting a new device may be affected by the failed device, such as the failed device may occupy some resources or cause overall instability. At this time, the execution evaluation value may be reduced, assuming it is 0.4.
[0132] For the power adjustment control type (assuming c2), power adjustment may face more challenges in high-load operation. For example, if the equipment is close to the limit operation state, power adjustment may affect the stability of the equipment. The evaluation value is set according to factors such as the effect of the adjustment and the impact on the equipment, for example, 0.6. In low-load operation, power adjustment is relatively easy, and the evaluation value may be 0.9.
[0133] According to the above analysis, an execution evaluation value matrix is constructed, where the rows represent the control type ck and the columns represent the operating state of the thermal power plant. Each element in the matrix is the execution evaluation value of each control type under the corresponding operating state of the thermal power plant.
[0134] First, clarify the control type of the current secondary instruction, for example, determine whether the current secondary instruction is the equipment start-stop control type (c1).
[0135] In the previously constructed execution evaluation value matrix, find the execution evaluation value of the current control type (c1) under the current thermal power plant operation state. Assuming that the current thermal power plant is in a state of partial equipment failure, the execution evaluation value found is 0.4, which is the direct feasibility reference value e1.
[0136] Analyze the relationship between the control node of the current secondary instruction and the abnormal control node (the control node with faults or potential problems) in the thermal power plant. For example, if the current control node is the controller of a generator, and the abnormal control node is the cooling system controller connected to the generator, there is a close correlation between them because the cooling system failure will affect the normal operation of the generator.
[0137] The strength of the correlation is determined by analyzing the connection relationship between the devices, the control logic relationship, and the historical fault correlation between the two. The correlation can be represented by a quantitative value. For example, if the correlation is strong, the correlation reference value can be set to 0.8; if the correlation is weak, it can be set to 0.2.
[0138] The indirect feasibility reference value e2 is generated according to the correlation reference value. If the correlation reference value is high, it means that the operation of the current control node will be greatly affected by the abnormal control node, and the indirect feasibility is low. For example, when the correlation reference value is 0.8, the indirect feasibility reference value e2 may be set to 0.3; if the correlation reference value is 0.2, the indirect feasibility reference value e2 may be set to 0.8, indicating that the indirect impact is small and the indirect feasibility is high.
[0139] Finally, it should be noted that it is obvious that those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention and its equivalent technology, the present invention is also intended to include these modifications and variations.
[0140] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention.
Claims
1. A method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant, characterized in that: Including: Set the control node number based on the obtained electrical equipment information; Establish a number database of electrical equipment by combining the label contents of all control nodes; Generate a first-level control instruction based on the operation status information of the distributed control system; Verify the first-level control instruction based on the first anti-error model to generate a second-level control instruction; Verify the second-level control instruction based on the second anti-error model.
2. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 1, characterized in that: The first-level anti-error model includes: Set the operator category and the emergency situation of the thermal power plant; Among them, the operator category includes: operator level and engineer level; the emergency situation of the thermal power plant includes: first-level operation status and second-level operation status; Obtain the current operator category and the emergency situation of the thermal power plant based on the operation status information of the distributed control system; Run the corresponding human-machine interface based on the operator category and the emergency situation of the thermal power plant; Generate a second-level control instruction based on the information sent by the human-machine interface.
3. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 2, characterized in that: When generating the second-level control instruction, it includes: Generate a set A of emergency situation reference values for the current thermal power plant based on the obtained historical operation status data of the current thermal power plant, A={a1,a2…ai…an}; Among them, ai is the i-th emergency situation reference value, and n is the number of emergency situation reference values in the set of emergency situation reference values; Judge the emergency situation of the current thermal power plant by comparing ai with the preset emergency situation value ah; If ai≥ah, the current thermal power plant is in the first-level operation status; If ai<ah, the current thermal power plant is in the second-level operation status; If the current user category is the operator level, run the operator-level human-machine interface; If the current user category is the engineer level, run the engineer-level human-machine interface; Combine the current emergency situation of the thermal power plant and the current human-machine interface; If the current thermal power plant is in the first-level operation status and the running human-machine interface is the operator-level human-machine interface, directly set the first-level control instruction as the second-level control instruction; If the current thermal power plant is in the second-level operation status and the running human-machine interface is the operator-level human-machine interface, send and verify the first-level control instruction; If the running human-machine interface is the engineer-level human-machine interface, directly set the first-level control instruction as the second-level control instruction.
4. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 3, characterized in that: When sending and verifying the first-level control instruction, it includes: Perform text verification on the numbered text input by the operator-level personnel type; The text verification includes: numbered text form verification and control point number verification; If the text verification passes, delete the numbered text; If the text verification fails, generate an alarm prompt message until the verification passes.
5. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 4, characterized in that: When performing the text verification, it includes: The distributed control system includes multiple partitions, and each partition includes multiple electrical equipment; Set the electrical equipment operation interface based on the partition; When the current operation interface performs numbered text input, the characters already input on the operation interfaces of the remaining electrical equipment are automatically cleared; Set the valid time for numbered text character input according to the actual execution time of the electrical operation. If the valid time is exceeded, the already input numbered text is automatically cleared.
6. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 5, characterized in that: The second anti-error model includes: Generate a first reference value of the distributed control system and the current node based on the second-level control instruction; Generate a second reference value of the current control node by combining the acquired operation status information of the current control node device and the secondary control instruction; Classify the secondary control instructions based on historical data to generate a control type set, and generate a third reference value based on the historical data and the current secondary control instruction control type; Setting a first preset value, a second preset value, and a third preset value corresponding to the first reference value, the second reference value, and the third reference value in combination with historical data; When the first reference value, the second reference value and the third reference value all reach the corresponding first preset value, the second preset value and the third preset value, the secondary control instruction passes the verification.
7. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 6, characterized in that: The generating of the first reference value of the distributed control system and the current node includes: Obtaining the number of the control node based on the secondary control instruction; Send verification data to the control node through the distributed control system and obtain verification data feedback; Set communication status judgment indicators based on historical data; A first reference value is generated by combining the communication status judgment indicator and the verification data feedback.
8. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 7, characterized in that: The generating of the second reference value of the current control node comprises: Get the running status information of the current control node; Classify the operation status information based on historical data to generate a function execution reference value set B of the current control node, B={b1,b2…bj…bm}; Wherein, bj represents the jth function execution reference value of the current control node, and m represents the number of function items of the current control node; Determine the function subset B1 that the current control node needs to execute based on the secondary control instruction; Obtaining function execution reference values of all function items in function subset B1 from function execution reference value set B; The second reference value is generated by comparing the function execution reference values of all function items in the function subset B1 with the function execution preset values.
9. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 8, characterized in that: The generating of the third reference value of the current control node comprises: Based on historical data, the control types of the secondary control instructions are divided to generate a control type set C, C = {c1, c2…ck…cq}; Wherein, ck represents the kth control type of the secondary control instruction, and q represents the total number of control types of the secondary control instruction; Combine the control type of the current secondary instruction and the current operating status of the thermal power plant to generate a direct feasibility reference value e1 and an indirect feasibility reference value e2; The third reference value of the current control node is generated based on the direct feasibility reference value e1 and the indirect feasibility reference value e2 of the current thermal power plant operation state.
10. The method for preventing misoperation of electrical equipment in a distributed control system of a thermal power plant according to claim 9, characterized in that: The generation of the direct feasibility reference value e1 and the indirect feasibility reference value e2 includes: The operation status of the thermal power plant is divided based on historical data to generate a thermal power plant operation status data set; Combine the control type set C and the thermal power plant operation status data set to generate the execution evaluation value of the thermal power plant operation status corresponding to the control type of each secondary control instruction; Obtain the execution evaluation value of the control type of the current secondary instruction to generate a direct feasibility reference value e1; Obtain a correlation reference value between the control node of the current secondary instruction and the abnormal control node; and generate an indirect feasibility reference value e2 based on the correlation reference value.
Citation Information
Patent Citations
Electrical equipment operation control method and device
CN104808516A
Multi-stage collaborative anti-misoperation system and method based on one-key sequential control
CN115580015A
Information interaction security intelligent monitoring system and method based on multi-source data
CN117826768A
Decentralized control system inter-domain reference control instruction issuing method and related device
CN119270790A
System for diagnosing communication error of nuclear power plant simmulator
KR101469179B1