Electric power system man-machine interaction safety verification method based on Event-B model

Through the human-computer interaction safety verification method of the power system based on the Event-B model, traditional safety analysis technology cannot effectively deal with the cause problems in the human-computer interaction of the power system, and realizes a comprehensive safety analysis and risk avoidance of the human-computer interface of the power system, ensuring the safe and stable operation of the system.

CN120124042APending Publication Date: 2025-06-10YANGZHOU UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510210001.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

Traditional safety analysis technology cannot effectively deal with the causes of human-computer interaction in the power system, resulting in potential risks that are inevitable and threatening the safety of operators' lives and property.

Method used

The human-computer interaction security verification method of power system based on the Event-B model is used to analyze the security requirements of the human-computer interface, establish the Event-B model, and verify the security of the model on the Rodin platform to ensure that the system design can avoid potential risks caused by the cause.

Benefits of technology

It improves the comprehensiveness of safety analysis of the human-computer interface of the power system, can effectively identify and avoid potential risks, and ensure the safe and stable operation of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124042A_ABST
    Figure CN120124042A_ABST
Patent Text Reader

Abstract

The invention discloses an electric power system man-machine interaction safety verification method based on an Event-B model, and the method comprises the following steps: (1), determining the safety demands of a man-machine interface through the analysis of a man-machine interaction interface of an electric power system; (2) analyzing the reason for generating the danger control behavior, and determining the safety constraint of the danger control behavior by logically eliminating the reason for generating the danger control behavior; (3) determining the safety requirement of the human-computer interface according to the generation reason of the danger control behavior and the safety constraint of the danger control behavior; (4) establishing an Event-B model of the human-computer interface according to the safety requirement of the human-computer interface; (5) verifying the safety of the Event-B model based on a Rodin platform to obtain a verification result; according to the invention, the comprehensiveness of safety analysis of the human-computer interface of the electric power system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of formal methods, and particularly to a method for verifying the safety of human-machine interaction in a power system based on an Event-B model. Background Art

[0002] A power system is a complex system with high safety requirements. Thorough safety analysis and strict verification should be carried out for each link. The formal method based on Event-B provides an important way for strict verification of a trustworthy system. This method is used to establish the requirement specification of the system and quantitatively and qualitatively analyze the functional attributes of the system according to mathematical theories. Using the Event-B method can greatly reduce design defects caused by developers and is an effective means to eliminate requirement ambiguity and inconsistency, which is of great significance for ensuring the correctness of system functions.

[0003] Currently, as a typical safety-critical system, the correctness of the functional logic of human-machine interaction in a power system is not sufficient to meet safety requirements. The lack of a plan related to risk prediction in system design and implementation often implies the possibility of potential risks suddenly breaking out during operation, which poses a great threat to the life and property safety of operators. Compared with traditional mechanical equipment, human-machine interaction in a power system not only has to prevent traditional mechanical failures but also faces design errors (software defects), component interaction failures, and operator cognitive decision-making mistakes. Summary of the Invention

[0004] Object of the Invention: The object of the present invention is to provide a method for verifying the safety of human-machine interaction in a power system based on an Event-B model, to solve the causes that cannot be handled by traditional safety analysis techniques, and to ensure that the system design can avoid potential risks caused by the causes in the background art.

[0005] Technical Solution: A method for verifying the safety of human-machine interaction in a power system based on an Event-B model according to the present invention includes the following steps:

[0006] (1) Analyze the human-machine interface of the power system to determine the safety requirements of the human-machine interface;

[0007] (2) Analyze the causes of the dangerous control behavior, and determine the safety constraints of the dangerous control behavior by logically excluding the causes of the dangerous control behavior;

[0008] (3) Determine the safety requirements of the human-machine interface according to the causes of the dangerous control behavior and the safety constraints of the dangerous control behavior;

[0009] (4) Establish an Event-B model of the human-machine interface according to the safety requirements of the human-machine interface;

[0010] (5)Verify the security of the Event-B model based on the Rodin platform to obtain the verification result;

[0011] Further, step (1) is specifically as follows: Analyze the human-machine interface of the power system to determine the system-level hazards of the human-machine interface of the power system; Extract the control structure diagram for verifying the security of the human-machine interface from the control schematic diagram of the power system according to the process of the occurrence of the system-level hazards; Analyze the control structure diagram to determine the dangerous control behaviors that cause system-level hazards; Among them, the system-level hazards include that the human-machine interface does not correctly receive data from the power sensor, the human-machine interface does not correctly receive data from the disconnector, and the operating mechanism or the circuit breaker module does not correctly process the alarm of the human-machine interface.

[0012] Further, in step (2), the reasons for the generation of dangerous control behaviors include function setting defects, control algorithm defects, and environmental impacts of the power system.

[0013] Further, in step (2), the reasons for the generation of dangerous control behaviors include function setting defects, control algorithm defects, and environmental impacts of the power system.

[0014] Further, in step (4), the Event-B model includes a model layer model and a control layer model, including the following steps:

[0015] (41)Convert the actual requirements and security requirements of the human-machine interface from the natural language description form into the form required for establishing the Event-B model; Among them, the form elements required for establishing the Event-B model include constants, variables, events, and invariants;

[0016] (42)Extract the security requirements of the human-machine interface and the requirements related to the relevant ones in the actual requirements of the human-machine interface to establish a basic equipment layer model;

[0017] (43)Extract the security requirements of the human-machine interface and the requirements related to the control system in the actual requirements of the human-machine interface to establish a control system layer model.

[0018] Further, step (5) is specifically as follows: Refine the Event-B model to obtain a refined Event-B model; Automatically generate corresponding proof obligations for the invariants of the refined Event-B model through the Rodin platform.

[0019] A power system human-computer interaction security verification system based on the Event-B model described in the present invention includes:

[0020] Analysis module: Used to determine the security requirements of the human-machine interface by analyzing the human-computer interaction interface of the power system;

[0021] Constraint module: used to analyze the causes of the hazardous control behavior, and determine the safety constraints of the hazardous control behavior by logically excluding the causes of the hazardous control behavior.

[0022] Safety requirement module: used to determine the safety requirements of the human-machine interface according to the causes of the hazardous control behavior and the safety constraints of the hazardous control behavior.

[0023] Event-B module: used to establish an Event-B model of the human-machine interface according to the safety requirements of the human-machine interface.

[0024] Verification module: used to verify the security of the Event-B model based on the Rodin platform and obtain the verification result.

[0025] An electronic device according to the present invention includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the computer program is loaded into the processor, it implements any one of the methods for verifying the security of human-machine interaction in a power system based on an Event-B model.

[0026] A storage medium according to the present invention stores a computer program, and when the computer program is executed by a processor, it implements any one of the methods for verifying the security of human-machine interaction in a power system based on an Event-B model.

[0027] Advantageous effects: Compared with the prior art, the present invention has the following remarkable advantages: In the present invention, by analyzing the human-machine interface of the power system, the safety requirements of the human-machine interface are determined; an Event-B model of the human-machine interface is established according to the safety requirements of the human-machine interface; the security of the Event-B model is verified based on the Rodin platform to obtain the verification result. The present invention establishes an Event-B model based on safety requirements, improving the comprehensiveness of the safety analysis of the human-machine interface of the power system. Description of the Drawings

[0028] Figure 1 is the flowchart of the present invention;

[0029] Figure 2 is the schematic diagram of the present invention;

[0030] Figure 3 is the existing schematic diagram of the thermoelectric cooler control of the present invention;

[0031] Figure 4 is from Figure 3 the control structure diagram extracted from the thermoelectric cooler control schematic diagram of the present invention for verifying the security of the human-machine interface. Detailed Embodiments

[0032] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings.

[0033] As Figures 1 - 4 shown, an embodiment of the present invention provides a method for verifying the safety of human-machine interaction in a power system based on Event-B, including the following steps:

[0034] Step 101: Analyze the human-machine interface of the power system to determine the safety requirements of the human-machine interface; specifically as follows: Analyze the human-machine interface of the power system to determine the system-level hazards of the human-machine interface of the power system; The system-level hazards include that the human-machine interface does not correctly receive data from the power sensor, the human-machine interface does not correctly receive data of the disconnector and the operating mechanism or the circuit breaker module does not correctly process the alarm of the human-machine interface; The human-machine interface does not correctly receive data from the power sensor: including current data and voltage data; The human-machine interface does not correctly receive the status data of the disconnector and the operating mechanism: including the opening and closing status data of the disconnector, the indication status data of the disconnector and the connection status data of the disconnector; The circuit breaker module does not correctly process the alarm of the human-machine interface: including that the circuit breaker module is in an open circuit state with the device, or the alarm module is damaged. Extract the control structure diagram for verifying the safety of the human-machine interface from the control schematic diagram of the power system according to the process in which the system-level hazard occurs;

[0035] Analyze the control structure diagram to determine the dangerous control behaviors that cause system-level hazards; specifically as follows: For example: Extract the control structure diagram from the control schematic diagram of the thermoelectric cooler of the prior art; The existing control schematic diagram of the thermoelectric cooler is as Figure 3 shown, and the extracted control structure diagram for verifying the safety of the human-machine interface is as Figure 4 shown;

[0036] Analyze the reasons for the generation of the dangerous control behaviors: The reasons for the generation of the dangerous control behaviors include functional setting defects, control algorithm defects and environmental impacts in the power system; When there are functional setting defects, the response in the circuit will be delayed, and the longer the delay time, the more likely it is to cause dangerous behaviors; When the control algorithm has defects, such as when additional writing control programs are added to the control logic, the original control logic and the newly added control logic cannot be compatible, resulting in unsafe operation. When environmental impacts occur, such as temperature and humidity, it will cause damage to components, thereby causing damage to components, and thus generating dangerous control behaviors, affecting the operation of the entire system.

[0037] Determine the safety constraints of the dangerous control behaviors by logically eliminating the reasons for the generation of the dangerous control behaviors;

[0038] Determine the safety requirements of the human-machine interface according to the reasons for the generation of the dangerous control behaviors and the safety constraints of the dangerous control behaviors;

[0039] For example, when data of current or temperature sensors is lost, it may not be possible to detect device overload or overheating in a timely manner, which may lead to device damage or serious failures. To address this situation, through the event sensorDataMissing in the Event-B model, the error handling mechanism can be triggered when data is lost, automatically marking the sensor data as an error state to ensure that the system can detect problems in a timely manner and take necessary remedial measures. In this way, the human-machine interface can quickly feedback error messages, reducing potential risks brought by data loss and ensuring the safe and stable operation of the power system.

[0040]

[0041] Step 102: Establish the Event-B model of the human-machine interface according to the safety requirements of the human-machine interface;

[0042] Establishing the Event-B model of the human-machine interface according to the safety requirements of the human-machine interface also includes the following:

[0043] Transform the actual requirements and safety requirements of the human-machine interface from the form of natural language description into the form required for establishing the Event-B model. The form elements required for establishing the Event-B model include constants, variables, events, and invariants, etc.

[0044] Constants are used to represent fixed data or parameters in the system, such as the current threshold.

[0045]

[0046] Variables are used to represent the system state or values that can change, such as current data, alarm status, etc.

[0047]

[0048] Invariants are used to define the constraint conditions that must always be maintained in the system, such as the current value cannot be less than the minimum threshold or greater than the maximum threshold.

[0049]

[0050] Events represent actions or state changes that occur in the system. For example, when the current is controlled at the threshold, the sensor makes a reaction event.

[0051]

[0052] Establish an Event-B model for the human-machine interface according to the safety requirements of the human-machine interface, as follows: Extract the safety requirements of the human-machine interface and the requirements related to the basic equipment in the actual requirements of the human-machine interface, and establish a basic equipment model. Take the sensor in the basic equipment as an example: In the power system, as a part of the basic equipment, the sensor undertakes key monitoring tasks. The sensor needs to collect the operation data of power equipment in real time and transmit it accurately to the control system to ensure the safe operation of the system. To ensure the reliability and safety of the power system, the safety requirements of the sensor include data accuracy, fault detection and alarm, redundancy design, real-time performance, and anti-interference ability.

[0053] The sensor needs to give an alarm in time when a fault occurs, and at the same time ensure the accuracy and real-time performance of data collection for timely response. In Event-B modeling, these safety requirements and actual requirements of the sensor can be transformed into variables and invariants in the model. By modeling the state, data transmission, and fault handling of the sensor, it is ensured that the power system can work stably and safely under various complex operating environments.

[0054]

[0055] Extract the safety requirements of the human-machine interface and the requirements related to the control system function in the actual requirements of the human-machine interface, and establish a control system model. Take a simple control system as an example: In the power system, the function of the control system is closely related to the safety and reliability of the system. The control system processes and analyzes the sensor data and executes corresponding control decisions to maintain the stable operation of the system. The main tasks of the control system include data reception and processing, fault detection and alarm, and execution of control strategies.

[0056]

[0057] Step 103: Verify the safety of the Event-B model based on the Rodin platform to obtain the verification result; specifically: Automatically generate the corresponding proof obligations for the Event-B model through the Rodin platform, and verify the proof obligations through the automatic proof and manual proof of the Rodin platform; If the proof obligation fails to pass the verification, locate the statement in the Event-B corresponding to the proof obligation and make corresponding modifications to the statement; If all the proof obligations pass the verification, the human-machine interaction of the power system is safe.

[0058] In the Rodin platform, after modeling with Event-B, the automatic proof process can be started by clicking the verification button. The Rodin platform automatically analyzes the relationships among events, variables, and invariants in the model and attempts to infer a proof to confirm whether the model complies with all invariants and constraints. If some conditions do not match, the statements need to be modified or the constraints need to be supplemented.

[0059] Taking the example that the current data is always within the safe range, an invariant can be defined to force the current data of each sensor to always remain within a predetermined safe range. Set the minimum current threshold: MIN_CURRENT, and set the maximum current threshold: MAX_CURRENT.

[0060]

[0061] inv1: This invariant ensures that the data of each sensor is of a real number type. inv2: This invariant forces the current data of each sensor to always be between MIN_CURRENT and MAX_CURRENT, that is, the current must be within the safe range. Through inv2, it is ensured that the current data of all sensors is always within the safe range. This is a basic safety requirement to ensure that equipment damage or system instability will not be caused by excessive or too small current.

[0062]

[0063] According to the specific embodiments provided by the present invention, the following technical effects of the present invention are disclosed:

[0064] Build safety requirements based on safety analysis techniques, which include identifying system-level hazards, drawing a system control structure diagram, analyzing the control behaviors of system hazards, and identifying the causal factors of dangerous control behaviors and thus avoiding potential risks in the power system.

[0065] Based on the functional requirements of the power system and the above-obtained safety requirements, construct a formal model based on Event-B, and then gradually refine the formal model to improve the system design details to achieve strict safety verification of the power system.

Claims

1. A method for verifying the safety of human-computer interaction in a power system based on Event-B model, characterized in that: The following steps are involved: (1) Analyze the human-machine interface of the power system and determine the safety requirements of the human-machine interface; (2) analyzing the causes of the dangerous control behavior and determining the safety constraints of the dangerous control behavior by logically eliminating the causes of the dangerous control behavior; (3) Determine the safety requirements of the human-machine interface based on the causes of dangerous control behaviors and the safety constraints of dangerous control behaviors; (4) Establish the Event-B model of the human-machine interface based on the security requirements of the human-machine interface; (5) Verify the security of the Event-B model based on the Rodin platform and obtain the verification results.

2. According to claim 1, a method for verifying the safety of human-computer interaction in a power system based on an Event-B model is characterized in that: Step (1) is specifically as follows: analyzing the human-machine interface of the power system to determine the system-level hazards of the human-machine interface of the power system; extracting a control structure diagram for human-machine interface safety verification from the control schematic diagram of the power system according to the process of occurrence of the system-level hazards; analyzing the control structure diagram to determine the dangerous control behavior that produces the system-level hazards; wherein the system-level hazards include the human-machine interface not correctly receiving data from the power sensor, the human-machine interface not correctly receiving data from the isolating switch, and the operating mechanism or circuit breaker module not correctly processing the alarm of the human-machine interface.

3. According to claim 1, a method for verifying the safety of human-computer interaction in a power system based on an Event-B model is characterized in that: In step (2), the causes of dangerous control behavior include functional setting defects of the power system, control algorithm defects and environmental impacts.

4. According to claim 1, a method for verifying the safety of human-computer interaction in a power system based on an Event-B model is characterized in that: In step (2), the security constraints include: preventing illegal operations, state consistency, priority control, redundancy checking, and fault recovery.

5. According to the Event-B model-based power system human-computer interaction safety verification method of claim 1, it is characterized in that: In step (4), the Event-B model includes a model layer model and a control layer model, including the following steps: (41) Converting the actual requirements of the human-machine interface and the security requirements of the human-machine interface from the natural language description form into the form required for establishing the Event-B model; wherein the formal elements required for establishing the Event-B model include constants, variables, events, and invariants; (42) Extract the security requirements of the human-machine interface and the requirements related to the actual requirements of the human-machine interface, and establish a basic equipment layer model; (43) Extract the security requirements of the human-machine interface and the requirements related to the control system in the actual requirements of the human-machine interface, and establish a control system layer model.

6. According to the Event-B model-based power system human-computer interaction safety verification method of claim 1, it is characterized in that: Step (5) is as follows: refine the Event-B model to obtain a refined Event-B model; and automatically generate corresponding proof obligations for the invariants of the refined Event-B model through the Rodin platform.

7. A power system human-computer interaction safety verification system based on Event-B model, characterized in that: include: Analysis module: used to determine the safety requirements of the human-machine interface by analyzing the human-machine interface of the power system; Constraint module: used to analyze the causes of the dangerous control behavior, and determine the safety constraints of the dangerous control behavior by logically eliminating the causes of the dangerous control behavior; Safety requirement module: used to determine the safety requirements of the human-machine interface based on the causes of dangerous control behaviors and the safety constraints of dangerous control behaviors; Event-B module: used to establish the Event-B model of the human-machine interface according to the safety requirements of the human-machine interface; Verification module: used to verify the security of the Event-B model based on the Rodin platform and obtain verification results.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is loaded into the processor, a method for verifying the safety of human-computer interaction in a power system based on an Event-B model is implemented according to any one of claims 1 to 6.

9. A storage medium storing a computer program, characterized in that: When the computer program is executed by the processor, a method for verifying the safety of human-computer interaction in a power system based on an Event-B model is implemented according to any one of claims 1 to 6.