Transformer substation anti-misoperation control method, background and system based on robot
By introducing transit equipment and intelligent mechanical locks into old substations, combined with robotic autonomous navigation and phased verification, the problem of high one-click sequence operation cost of old substations is solved, and safe and reliable low-cost transformation is achieved.
Patent Information
- Application Number
- CN202510962395.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-14
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-07-14
AI Technical Summary
Due to the outdated equipment and lack of communication systems, old substations cannot realize the dual anti-miss verification of traditional robot operation background and anti-missile host, resulting in high cost of one-click sequence operation and lack of low-cost alternatives.
By introducing transit devices (such as communication pre-hosts or edge computing devices) to achieve data isolation transmission in the secure interval, the robot obtains operation task instructions generated by the intelligent anti-error host, performs phased verification and unlocking, and uses robots' autonomous navigation and intelligent mechanical locks to eliminate the needs of traditional hardware deployment.
It realizes one-click sequence operation of old substations, reduces the transformation cost, eliminates the risk of human operation errors, improves the standardization level of instruction, and avoids hardware transformation costs and high overheads for communication links.
Smart Images

Figure CN120454327A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of intelligent control and relates to a robot-based misoperation prevention control method, background and system for a substation. Background Art
[0002] Traditional substation one-button sequential control operations rely on a comprehensive communications infrastructure (such as forward and reverse isolation devices and convergence terminals) to build a secure partitioning architecture and deploy real-time communication links between the intelligent anti-error host and the robotic operation backend to achieve dual anti-error verification of operating instructions (primary logic verification and secondary equipment status verification) to ensure operational compliance.
[0003] Due to outdated equipment and missing or outdated communication systems, older substations cannot afford the deployment costs of complex communication equipment (such as convergence terminals and forward and reverse isolation devices) required by traditional solutions, nor can they establish real-time interactive links within safety zones. This results in a lack of collaboration between the robot operation backend and the error prevention host to complete device status collection and secondary verification. With the lack of low-cost alternatives, the dual error prevention safety requirements of one-button sequential control cannot be met, hindering the automation upgrade of older substations. Summary of the Invention
[0004] The present application provides a robot-based substation anti-misoperation control method, background and system, which can solve the problem of high cost of one-button sequential control operation transformation of old substations in the prior art.
[0005] To achieve the above objectives, in a first aspect, the present invention provides a robot-based control method for preventing misoperation of a substation, which is applicable to a robot operation background. The control method for preventing misoperation of a substation comprises: Obtaining an operation task instruction; wherein the operation task instruction is generated by the intelligent anti-error host performing a first anti-error check on the operation task created by the centralized control center; According to the operation task instruction, confirm the location of the target device and send a corresponding movement instruction to the robot, so that the robot moves to the location of the target device and activates the smart mechanical lock of the target device, and returns an unlock request and status information of the target device; Sending the unlock request and status information to the intelligent anti-error host, so that the intelligent anti-error host performs a second anti-error check according to the status information, and returns the unlock key after the second anti-error check passes; Sending the unlocking key to the robot, so that the robot unlocks the smart mechanical lock according to the unlocking key; After the intelligent mechanical lock is unlocked, the operation task instruction is sent to the robot, so that the robot performs the corresponding instruction operation according to the operation task instruction.
[0006] Compared to the prior art, the embodiments of the present application have the following beneficial effects: by obtaining the operation task instructions generated by the initial anti-error verification of the intelligent anti-error host, the manual creation and review of operation tickets is replaced, eliminating the risk of human error and improving the standardization of instructions; the robot's movement path is planned and movement instructions are issued according to the operation task instructions, utilizing the robot's autonomous navigation capabilities to replace traditional manual inspection and positioning, reducing reliance on fixed positioning base stations or high-precision sensors, and avoiding the cost of retrofitting old substations with new hardware deployment. Furthermore, by activating the intelligent mechanical lock and collecting the device's status information after moving to the target device location, the manual on-site verification of device status is transformed into an automated process, avoiding the shortcomings of the lack of online device status monitoring interfaces in old substations, as well as the inefficiency and safety risks of manual verification; At the same time, the device status information is bound to the unlock request and sent to the intelligent anti-error host, enhancing operational security through a phased verification mechanism and avoiding the vulnerabilities of single verification. Furthermore, by having the robot receive the unlock key and control the intelligent mechanical lock, the deployment of a converged terminal or dedicated server in traditional solutions is eliminated, reducing the cost of hardware and communication link modification in the intermediate links. Through the architecture of "automated operation + hierarchical verification + localized execution", this solution enables old substations to complete one-click sequential control transformation with only a small deployment cost, without the need for major modifications to existing equipment or communication facilities, directly addressing the core issue of high transformation costs.
[0007] In some embodiments of the first aspect of the present application, obtaining the operation task instruction includes: Receive operation task instructions sent by the transfer device; wherein the intelligent anti-error host is deployed in the safety zone 1, the transfer device and the robot operation background are deployed in the safety zone 2, and the intelligent anti-error host and the robot operation background are communicated through the transfer device; The transfer device includes a communication front-end host or an edge computing device; When the transfer device is a communication front host, the intelligent anti-error host communicates with the robot operation background through the forward and reverse isolation device and the communication front host; When the transfer device is an edge computing device, the intelligent anti-error host communicates with the robot operation background through a one-way optical gate and the edge computing device.
[0008] Compared with the existing technology, the above embodiment has the following beneficial effects: by introducing a transfer device (communication front-end host or edge computing device) as the communication hub between the safety zone 1 (intelligent anti-error host) and the safety zone 2 (robot operation background), the forward and reverse isolation device or the one-way optical gate is used to realize the isolated transmission of data across the safety zone, thereby avoiding the direct exposure of the intelligent anti-error host to the low-security zone and reducing the risk of external attacks; when the communication front-end host is used, the two-way communication traffic is limited by the forward and reverse isolation device to meet the compliance requirements of the power grid security zoning; when the edge computing device is used, the one-way communication is realized by the one-way optical gate, while avoiding the high cost of deploying two-way isolation equipment. The above design flexibly adapts to the communication conditions of different old substations (such as whether they have forward and reverse isolation devices) to achieve secure communication and low-cost transformation across safety zones without replanning the network architecture.
[0009] In some embodiments of the first aspect of the present application, sending the unlock request and status information to the intelligent anti-error host includes: When the transfer device is a communication front host, the unlocking request and status information are sent to the communication front host, so that the communication front host sends the unlocking request and status information to the intelligent anti-error host.
[0010] Compared with the existing technology, the above embodiment has the following beneficial effects: the unlocking request and device status information are forwarded to the intelligent anti-error host through the communication front host, and the one-way transmission characteristics of the forward and reverse isolation devices are utilized (such as only allowing data from the low security zone to the high security zone) to prevent data leakage in the high security zone, and reliable communication across security zones is achieved under the existing network architecture of old substations, avoiding the high costs caused by deploying dedicated communication gateways or upgrading network facilities.
[0011] In some embodiments of the first aspect of the present application, sending the unlocking key to the robot includes: When the transfer device is a communication front-end host, after the intelligent anti-error host returns the unlocking key, the unlocking key is sent to the robot; wherein, the unlocking key is generated by the intelligent anti-error host after the second anti-error check is passed, and is sent to the robot operation background through the communication front-end host.
[0012] Compared with the existing technology, the above embodiment has the following beneficial effects: after the intelligent anti-error host generates the unlocking key, the key is transmitted to the robot operation background through the communication front host, and then sent to the robot, thereby realizing the secure transmission of the key across security zones, while avoiding the modification costs caused by deploying a dedicated key server.
[0013] In some embodiments of the first aspect of the present application, after receiving the unlock request and the status information of the target device and before sending the unlock key to the robot, the method further includes: When the transfer device is an edge computing device, the unlocking request and status information are sent to the edge computing device, so that the edge computing device performs a second anti-error check based on the status information, and returns the unlocking key after the second anti-error check passes.
[0014] Compared to existing technologies, the above embodiment offers the following advantages: Edge computing devices directly perform secondary error-proofing checks based on device status information, replacing the remote verification process of intelligent error-proofing hosts and reducing delays and failure risks in cross-security zone communications. Furthermore, the unidirectional data flow characteristics of the one-way optical gate (which only allows data to flow from high-security zones to low-security zones) replace traditional bidirectional isolation devices, reducing equipment deployment costs. Through this "edge-based verification" mechanism, the above architecture effectively balances safety zone compliance with retrofit costs in legacy substations with weak communication infrastructure.
[0015] In a second aspect, the present invention further provides a robot operation background, the robot operation background comprising: an instruction acquisition module, a movement control module, an unlock request module, a key sending module and an execution control module; The instruction acquisition module is used to acquire the operation task instruction; wherein the operation task instruction is generated by the intelligent anti-error host performing the first anti-error check on the operation task created by the centralized control center; The movement control module is used to confirm the location of the target device according to the operation task instruction and send a corresponding movement instruction to the robot, so that the robot moves to the location of the target device, activates the intelligent mechanical lock of the target device, and returns an unlock request and status information of the target device; The unlock request module is configured to send the unlock request and status information to the intelligent anti-error host, so that the intelligent anti-error host performs a second anti-error check based on the status information and returns the unlock key after the second anti-error check passes; The key sending module is used to send the unlocking key to the robot, so that the robot unlocks the smart mechanical lock according to the unlocking key; The execution control module is used to send the operation task instruction to the robot after the intelligent mechanical lock completes unlocking, so that the robot performs the corresponding instruction operation according to the operation task instruction.
[0016] Compared to existing technologies, the above embodiment has the following advantages: the instruction acquisition module standardizes the reception of operational task instructions, eliminating errors caused by manual transmission; the mobile control module drives the robot to autonomously navigate to the target device, eliminating the time-consuming and safety-related risks of manual inspections; the collaboration between the unlock request module and the key transmission module ensures strict synchronization between secondary verification and key transmission, avoiding operational interruptions; and the execution control module directly issues operational instructions after unlocking, forming a closed-loop control process. This modular design improves overall system efficiency through functional decoupling and automated execution, while also reducing reliance on legacy substation communication facilities.
[0017] In a third aspect, the present invention also provides a robot-based substation misoperation prevention control system, comprising: a centralized control center, an intelligent misoperation prevention host, a robot operation background, a robot, an intelligent mechanical lock, and various target devices; The intelligent anti-error host is connected to the centralized control center for communication; The robot operation backend is in communication with the intelligent anti-error host, and is used to execute any of the above-mentioned robot-based substation anti-error operation control methods; The robot is connected to the robot operation background through wireless communication; Each of the target devices is equipped with the intelligent mechanical lock; The intelligent mechanical lock is connected to the robot via Bluetooth.
[0018] Compared to existing technologies, the above embodiments of this application have the following beneficial effects: standardized operational tasks are generated collaboratively between the centralized control center and the intelligent error prevention host, ensuring compliance with the source of instructions; wireless communication between the robot operation backend and the robot can easily adapt to the weak network environment of old substations; and the intelligent mechanical lock directly connects to the robot via Bluetooth, eliminating the cost of deploying a converged terminal. Through the "centralized control-layered verification-local execution" model, the above system architecture can achieve one-button sequential control operations with minimal modification to existing old facilities, directly overcoming the problem of high renovation costs for old substations.
[0019] In some embodiments of the third aspect of the present application, the target device is configured with a sensor and a ZigBee communication module, and the robot is configured with a ZigBee terminal; wherein the ZigBee terminal and the ZigBee communication module of the target device form a Mesh network, the sensor is used to collect the status information of the target device itself, and the ZigBee communication module is used to send the status information to the robot through the Mesh network.
[0020] Compared with the existing technology, the above embodiment has the following beneficial effects: by configuring sensors and ZigBee communication modules on the target device, and using ZigBee terminals and device modules to form a Mesh network, self-organized collection and transmission of device status information can be achieved, replacing the defects of traditional solutions that rely on wired sensor networks or manual on-site transcription; sensors directly collect target device status data and transmit it to the robot through multiple hops of the Mesh network, avoiding the renovation difficulties caused by aging cables or missing communication interfaces in old substations; the self-organizing networking characteristics of the Mesh network support dynamic coverage and multi-path redundancy, adapting to scenarios with complex equipment distribution or severe obstruction in old substations, and improving data collection reliability; the robot receives device status information through the ZigBee terminal and integrates the data into the secondary anti-error verification process, avoiding the additional deployment of data collection gateways or relay equipment, and further reducing renovation costs.
[0021] In some embodiments of the third aspect of the present application, the robot is configured with a camera and a visual recognition module; wherein the camera and the visual recognition module are used to collect status information of the target device.
[0022] Compared with the existing technology, the above embodiment has the following beneficial effects: by configuring a camera and a visual recognition module for the robot, machine vision technology is used to automatically identify the number and status information of the target equipment, replacing the inefficient mode of relying on physical sensors or manual on-site verification in the traditional solution; the visual recognition module circumvents the limitations of missing sensor interfaces or difficult modification in old substations through real-time analysis of equipment status; at the same time, the coordination of visual recognition and robot mobile operations integrates inspection and operation functions into a single carrier, avoiding the deployment of inspection robots or fixed cameras separately for status monitoring, and significantly reducing hardware deployment costs.
[0023] In some embodiments of the third aspect of the present application, the robot and the robot operation background are configured with a LoRa gateway; wherein, the LoRa gateway is used to wirelessly connect the robot and the robot operation background.
[0024] Compared with the existing technology, the above embodiment has the following beneficial effects: by configuring a LoRa gateway for the robot and the robot operation background, the long-distance and low-power consumption characteristics of LoRa technology are used to establish a wireless communication link, replacing the high-cost communication transformation that relies on optical fiber or Wi-Fi base stations in traditional solutions; the wide-area coverage capability of the LoRa gateway supports the cross-regional mobile operation of the robot in the complex environment of the substation, avoiding operation interruptions caused by signal blind spots; through the low-bandwidth data transmission characteristics of the LoRa protocol, the communication requirements of the robot's operation instructions and status feedback are adapted, reducing the load pressure on the existing network facilities of the old substation; at the same time, the collaboration between LoRa and the robot's local control logic realizes the reliable transmission of operation instructions and real-time feedback of execution status, ensuring strict synchronization between anti-error verification and operation execution, and improving the overall stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 : A flow chart of a robot-based substation anti-misoperation control method provided in some embodiments of the present invention.
[0026] Figure 2 : A schematic structural diagram of a robot-based substation anti-misoperation control system provided in some embodiments of the present invention.
[0027] Figure 3 : A complete architectural diagram of a one-button sequential control remote control operation of a substation provided in some embodiments of the present invention.
[0028] Figure 4 : A simplified flow chart of a one-button sequential remote control operation method provided in some embodiments of the present invention.
[0029] Figure 5 : is a complete flow chart of a one-button sequential remote control operation method provided in some embodiments of the present invention.
[0030] Figure 6 : A simplified flowchart of another one-button sequential remote control operation method provided in some embodiments of the present invention.
[0031] Figure 7 : A complete flow chart of another one-button sequential remote control operation method provided in some embodiments of the present invention.
[0032] Figure 8 : A simplified flowchart of another one-button sequential remote control operation method provided in some embodiments of the present invention.
[0033] Figure 9 : A complete flow chart of another one-button sequential remote control operation method provided in some embodiments of the present invention. DETAILED DESCRIPTION
[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0035] In existing substations with complete communication infrastructure, Figure 3 The following diagram shows a complete architecture for a one-button sequential control remote control system for a substation, enabling interaction between the robot and the anti-error host. Specifically, the isolation between Safety Zone I and Safety Zone IV is achieved through forward and reverse isolation. A front-end server, robot backend, and convergence terminal are added to Safety Zone IV. The convergence terminal communicates with the five-protection computer key and intelligent mechanical lock to perform opening and closing operations, as well as issue operation tickets to the five-protection computer key. The front-end server communicates with the intelligent anti-error host and sequential control host in Safety Zone I to receive trolley operation instructions; the robot backend sends operation instructions to the robot.
[0036] The specific process involves the following: the sequential control host creates a task for operating a cart (i.e., the target device) and requests permission from the anti-error host. After the anti-error host performs an anti-error logic check on the task and passes it, it sends the cart operation instruction (i.e., the operation task instruction) to the front-end server. The front-end server sends the cart operation instruction to the robot backend. The robot backend controls the robot to move to the desired cart device location and then requests the anti-error host to unlock the intelligent mechanical lock through the front-end server. Upon receiving the unlock request, the anti-error host performs an anti-error logic check. If it passes, the front-end server sends the unlock instruction to the intelligent mechanical lock via the convergence terminal. Once unlocked, it sends a successful unlock message to the robot backend. Upon receiving the successful unlock message, the robot backend sends the cart operation instruction to the robot, which then operates the cart according to the instruction. The aforementioned equipment and process enable communication between the robot and the anti-error host.
[0037] However, in some older substations, incomplete communication infrastructure, outdated equipment, and high renovation costs make it difficult to deploy these devices and meet inter-device communication requirements. Consequently, robots in these substations are often completely independent and unable to communicate with the anti-error control host, making it difficult to implement error-prevention operations and promote one-button sequential control.
[0038] Example 1: Please refer to Figure 1To address the high cost of retrofitting one-button sequential control operations in old substations in the prior art, an embodiment of the present invention provides a robot-based substation misoperation prevention control method, which is applicable to a robot operation backend. The substation misoperation prevention control method includes steps S1 to S5: Step S1: Acquire an operation task instruction; wherein, the operation task instruction is generated by the intelligent anti-error host performing the first anti-error check on the operation task created by the centralized control center.
[0039] Step S2: According to the operation task instruction, confirm the location of the target device and send a corresponding movement instruction to the robot, so that the robot moves to the location of the target device and activates the smart mechanical lock of the target device, and returns an unlock request and the status information of the target device.
[0040] Step S3: Send the unlock request and status information to the intelligent anti-error host, so that the intelligent anti-error host performs a second anti-error check according to the status information, and returns the unlock key after the second anti-error check passes.
[0041] Step S4: Send the unlocking key to the robot, so that the robot unlocks the smart mechanical lock according to the unlocking key.
[0042] Step S5: After the intelligent mechanical lock is unlocked, the operation task instruction is sent to the robot, so that the robot performs the corresponding instruction operation according to the operation task instruction.
[0043] In specific implementation, Figure 4 A simple flow chart of a one-button sequential remote control operation method and the corresponding Figure 5 The following is a complete flowchart of a one-button sequence control remote control method. To promote one-button sequence control in older substations without online error prevention systems, these substations can be equipped with an intelligent error prevention host, a robot, and a robot operation backend. The intelligent error prevention host is the device that runs the error prevention system. The error prevention system is pre-configured with the substation's error prevention logic (such as the five error prevention rules), meeting the one-button sequence control requirement for an independent error prevention host. Updates to the error prevention logic can be made via a USB flash drive or mobile device.
[0044] The robot's backend serves as the robot's control platform. It connects to the intelligent anti-error control host via a wired connection and communicates wirelessly with the robot using the HTTP protocol. Given the inadequate communication infrastructure and high retrofit costs of older substations, a LoRa gateway (such as the optional SX1276 LoRa module) can be added to the backend to facilitate easy communication. This gateway covers key substation areas and enables wireless communication between the backend and the robot. The backend can also transmit aggregated local data (such as device status and operation logs) to the centralized control center via wired transmission, addressing remote communication needs in areas without network coverage.
[0045] In addition, in some old substations, the equipment is outdated and there are no sensors installed to automatically detect the status of these devices. Before the switching operation, it may be necessary to manually check the status of these devices. In order to implement error-proof verification in the one-button sequential control operation, two methods can be used: First, these primary and secondary devices are equipped with external ZigBee communication modules (such as wireless transparent transmission modules based on the CC2530). The robot is equipped with a ZigBee terminal (such as the CC2530 chipset) that supports a mesh protocol stack (such as the Z-Stack), acting as a ZigBee node and forming a mesh network with these devices. The ZigBee communication module connects to the primary and secondary devices or corresponding sensors via wired interfaces (such as UART and GPIO), collects device status data, and sends it to the mesh network. The robot collects this device status data and transmits it to the robot operation backend via LoRa. The robot operation backend then sends this data to the intelligent anti-error host for real-time logic verification (i.e., the second anti-error verification). The anti-error host then sends the logic verification results to the robot operation backend. If the logic verification passes, the robot operation backend sends instructions to the robot based on the operation ticket (i.e., the operation task instruction) to perform the switching operation. If existing sensors support other protocols (such as Modbus), they can also be connected to the ZigBee network through a protocol converter or adapter. The converter encapsulates sensor data (such as RS-485 or analog signals) into ZigBee protocol packets and wirelessly transmits them to a mesh network, such as an ESP32 + ZigBee module, where protocol conversion is implemented programmatically. In this solution, the ZigBee network can be deployed wirelessly, avoiding damage to old cables or equipment. The robot's mobility can extend network coverage and fill in blind spots of fixed nodes. Furthermore, the robot can activate the ZigBee module only when collecting device or sensor data, entering a low-power mode when idle.
[0046] Second, the robot is equipped with a high-definition camera and AI visual recognition module to automatically identify the number and status of primary and secondary equipment. The collected data is transmitted to the robot's operation background via LoRa, and then a real-time logic verification is performed as in Method 1. In this case, the robot is equivalent to an inspection robot and an operation robot. Before performing the switching operation, it is an inspection robot, collecting the status of relevant equipment in the substation and sending it to the anti-error host for anti-error verification. After the anti-error verification passes, the robot transforms into an operation robot and performs the switching operation.
[0047] Furthermore, in older substations, robots are unable to operate the existing anti-error locking devices. If the switchgear is adapted for robot-controlled trolleys, the existing anti-error locking devices must be removed. However, removing the existing five-protection locking devices renders the anti-error locking function ineffective under manual operation, resulting in non-compliance with relevant safety regulations. Without removing the existing anti-error locking devices, the locks can only be opened on-site by staff carrying a specific anti-error computer key, rendering remote operation impossible. To address this issue, the existing trolley anti-error locking devices can be replaced with intelligent mechanical locks, which support both one-button sequential control of robot trolley remote control and on-site manual operation. Substations with established communication infrastructure typically have a convergence terminal. Intelligent mechanical locks communicate with a front-end server via the convergence terminal, which then issues unlocking and unlocking commands to the intelligent mechanical locks. However, older substations lack the necessary unlocking and unlocking servers for intelligent mechanical locks. To reduce retrofit costs, this solution allows robots to directly control the intelligent mechanical locks via Bluetooth. After the robot operation background receives the information that the intelligent anti-error host has passed the anti-error verification, it requests the unlocking key of the handcart device (i.e., the target device) to be operated from the centralized control center and then sends it to the robot. After the robot obtains the key, it sends it to the intelligent mechanical lock via Bluetooth to unlock it. This eliminates the need to deploy a convergence terminal and saves costs. Therefore, after the transformation is completed according to the above solution, all devices are deployed in the same security zone. Specifically, when the robot moves to the device to be operated and performs a secondary anti-error verification process, the following steps are performed: Figure 4 As shown: the robot moves to the front of the equipment, the robot operation background checks the robot's position, the operation task starts, and then the robot activates the smart mechanical lock and requests operation from the smart anti-error host through the robot operation background (that is, the smart anti-error host performs a secondary anti-error check before the robot operates). After the anti-error check of the smart anti-error host passes, the robot operation background sends the operation permission and unlocking key to the robot through the robot operation background. After the robot obtains the key, it sends it to the smart mechanical lock via Bluetooth to unlock it, and then the robot operates the target equipment to perform various command operations such as switching. After the operation is completed, the smart mechanical lock is locked by Bluetooth, and then the robot operation background reports the results to the smart anti-error host or the centralized control center.
[0048] Compared to the prior art, the above embodiments of the present application have the following beneficial effects: by obtaining the operation task instructions generated by the initial anti-error verification of the intelligent anti-error host, the manual creation and review of operation tickets is replaced, eliminating the risk of human error and improving the standardization of instructions. The robot's movement path is planned and movement instructions are issued based on the operation task instructions, leveraging the robot's autonomous navigation capabilities to replace traditional manual inspection and positioning, reducing reliance on fixed positioning base stations or high-precision sensors and avoiding the cost of retrofitting new hardware in older substations. Furthermore, by activating the intelligent mechanical lock and collecting device status information after moving to the target device location, the manual on-site verification of device status is transformed into an automated process, avoiding the shortcomings of the lack of online device status monitoring interfaces in older substations, as well as the inefficiency and safety risks of manual verification. Furthermore, the device status information is bound to the unlock request and sent to the intelligent anti-error host, enhancing operational security through a phased verification mechanism and avoiding the vulnerabilities of single verification. Furthermore, by having the robot receive the unlock key and control the intelligent mechanical lock, the deployment of a converged terminal or dedicated server in traditional solutions is eliminated, reducing the cost of hardware and communication link modification in the intermediate links. Through the architecture of "automated operation + hierarchical verification + localized execution", this solution enables old substations to complete one-click sequential control transformation with only a small deployment cost, without the need for major modifications to existing equipment or communication facilities, directly addressing the core issue of high transformation costs.
[0049] Furthermore, step S1 can be implemented by the following preferred implementations, specifically: Receive operation task instructions sent by the transfer device; wherein the intelligent anti-error host is deployed in the safety zone 1, the transfer device and the robot operation background are deployed in the safety zone 2, and the intelligent anti-error host and the robot operation background are communicated through the transfer device; The transfer device includes a communication front-end host or an edge computing device; When the transfer device is a communication front host, the intelligent anti-error host communicates with the robot operation background through the forward and reverse isolation device and the communication front host; When the transfer device is an edge computing device, the intelligent anti-error host communicates with the robot operation background through a one-way optical gate and the edge computing device.
[0050] In this preferred embodiment, by introducing a transfer device (communication front-end host or edge computing device) as the communication hub between security zone 1 (intelligent anti-error host) and security zone 2 (robot operation background), forward and reverse isolation devices or one-way optical gates are used to achieve cross-security zone data isolation transmission, avoiding direct exposure of the intelligent anti-error host to the low-security zone and reducing the risk of external attacks; when a communication front-end host is used, the forward and reverse isolation devices are used to limit the two-way communication traffic to meet the compliance requirements of the power grid security zoning; when an edge computing device is used, one-way communication is achieved through a one-way optical gate, while avoiding the high cost of deploying two-way isolation devices. The above design flexibly adapts to the communication conditions of different old substations (such as whether they have forward and reverse isolation devices) to achieve secure communication and low-cost transformation across security zones without replanning the network architecture.
[0051] Furthermore, when the transfer device is a communication front host, step S3 sends the unlock request and status information to the intelligent anti-error host, which can be implemented by the following preferred implementations, specifically: The unlocking request and status information are sent to the communication front host, so that the communication front host sends the unlocking request and status information to the intelligent anti-error host.
[0052] In this preferred embodiment, the unlocking request and device status information are forwarded to the intelligent anti-error host through the communication front host, and the one-way transmission characteristics of the forward and reverse isolation devices (such as only allowing data from the low security zone to the high security zone) are used to prevent data leakage in the high security zone, thereby achieving reliable communication across security zones under the existing network architecture of old substations, avoiding the high costs caused by deploying dedicated communication gateways or upgrading network facilities.
[0053] Furthermore, when the transfer device is a communication front-end host, after the intelligent anti-error host returns the unlocking key, the unlocking key is sent to the robot; wherein, the unlocking key is generated by the intelligent anti-error host after the second anti-error check is passed, and is sent to the robot operation background through the communication front-end host.
[0054] In this preferred embodiment, after the intelligent anti-error host generates the unlocking key, the key is transmitted to the robot operation background through the communication front host, and then sent to the robot, realizing the secure transmission of the key across security zones, while avoiding the modification costs caused by deploying a dedicated key server.
[0055] In practice, some older substations have in-house online error prevention systems that intelligently generate operation tickets, store them in a five-protection computer key, and demarcate safety zones using forward and reverse isolation devices or firewalls. Operators, armed with the five-protection computer key, perform switching operations step by step according to the information in the operation ticket. However, when implementing one-button sequential control in these substations, the network architecture cannot be redesigned, and robots still cannot directly communicate with the error prevention host for error verification and prevent operation errors.
[0056] In this case, if Figure 6 Another simple flow chart of one-button sequence remote control operation method and the corresponding Figure 7 The complete flow chart of another one-button sequential remote control operation method is shown. The centralized control center (or the monitoring host in the existing system) and the intelligent anti-error host are deployed in the safety zone 1, and a communication front host, a robot operation background and a robot are deployed in the safety zone 2. There is a positive and negative isolation device between the safety zone 1 and the safety zone 2. The communication front host and the intelligent anti-error host are connected by wire and communicate through an encryption protocol. The robot operation background is connected by wire to the communication front host and communicates using the HTTP protocol. The robot operation background also runs a LoRa gateway. The robot communicates wirelessly with the robot operation background through the LoRa protocol. The robot communicates with the smart mechanical lock through Bluetooth, and the smart mechanical lock is unlocked and locked through a key. In this case, the specific process of performing a secondary anti-error check when the robot moves to the device that needs to be operated is as follows. Figure 6 As shown, specifically: the robot moves to the front of the equipment, the robot operation background checks the robot's position, the operation task starts, and then the robot activates the smart mechanical lock, and requests the smart anti-error host to perform a secondary anti-error check through the robot operation background and the communication front host. After the anti-error check passes, the operation permission and unlocking key are sent to the robot operation background through the communication front host. After the robot obtains the key, it sends it to the smart mechanical lock via Bluetooth to unlock it, and operates the equipment to perform various command operations such as switching. After the operation is completed, the smart mechanical lock is locked by Bluetooth.
[0057] Preferably, when the transfer device is an edge computing device, after receiving the unlock request and the status information of the target device, and before sending the unlock key to the robot, a second anti-error check can be performed to obtain the unlock key through the following preferred implementation, specifically: The unlock request and status information are sent to the edge computing device, so that the edge computing device performs a second anti-error check according to the status information, and returns the unlock key after the second anti-error check passes.
[0058] In the specific implementation, in some old substations, due to the early construction time, the network equipment of the substation is too old, the communication system is relatively simple, and modern forward and reverse isolation devices or firewall technology are not used, resulting in the inability to effectively isolate different security zones.
[0059] In this case, if Figure 8 A simple flow chart of another one-button sequential remote control operation method and the corresponding Figure 9 The complete flowchart of another one-button sequential control remote control operation method shown in the figure uses edge computing equipment as the anti-error host, which is isolated from the centralized control center and the intelligent anti-error host. It is equivalent to the centralized control center and the intelligent anti-error host being deployed in the safe zone 1, and the edge computing equipment being deployed in the safe zone 2. The data of the existing intelligent anti-error host in zone 1 is mirrored to the non-real-time database of the edge computing device in zone 2 through a one-way optical gate (i.e., the one-way optical axis in the figure), thereby mirroring the anti-error operation rules of zone 1. The one-way optical gate is used to achieve unidirectional data flow, avoiding the deployment cost of complex bidirectional isolation equipment (such as forward and reverse isolation devices). In order to achieve a balance between safety zoning compliance, functional scalability and transformation costs in old substations, in this solution, the specific operation method flow is as shown in the corresponding method embodiments and Figure 8 and Figure 9 As shown in, no further details are given.
[0060] In this preferred embodiment, edge computing devices directly perform secondary error-proofing checks based on device status information, replacing the remote verification process of intelligent error-proofing hosts. This reduces delays and the risk of failure in cross-security zone communications. Furthermore, the unidirectional data flow characteristics of one-way optical switches (allowing data only from high-security zones to low-security zones) replace traditional bidirectional isolation devices, reducing equipment deployment costs. This "edge-based verification" architecture effectively balances safety zone compliance with retrofit costs in older substations with weak communication infrastructure.
[0061] Example 2: Please refer to Figure 2 Based on the same inventive concept, an embodiment of the present invention discloses a robot operation background, which includes: an instruction acquisition module M1, a movement control module M2, an unlock request module M3, a key sending module M4 and an execution control module M5; The instruction acquisition module M1 is used to acquire the operation task instruction; wherein the operation task instruction is generated by the intelligent anti-error host performing the first anti-error check on the operation task created by the centralized control center; The movement control module M2 is used to confirm the location of the target device according to the operation task instruction and send a corresponding movement instruction to the robot, so that the robot moves to the location of the target device, activates the intelligent mechanical lock of the target device, and returns an unlock request and status information of the target device; The unlocking request module M3 is used to send the unlocking request and status information to the intelligent anti-error host, so that the intelligent anti-error host performs a second anti-error verification according to the status information and returns the unlocking key after the second anti-error verification passes; The key sending module M4 is used to send the unlocking key to the robot, so that the robot unlocks the smart mechanical lock according to the unlocking key; The execution control module M5 is used to send the operation task instruction to the robot after the intelligent mechanical lock completes unlocking, so that the robot performs the corresponding instruction operation according to the operation task instruction.
[0062] Furthermore, the instruction acquisition module M1 includes: a first instruction acquisition unit; The first instruction acquisition unit is configured to receive an operation task instruction sent by a transfer device; the intelligent anti-error host is deployed in a safety zone 1, the transfer device and the robot operation background are deployed in a safety zone 2, and the intelligent anti-error host and the robot operation background are communicated through the transfer device; The transfer device includes a communication front-end host or an edge computing device; When the transfer device is a communication front host, the intelligent anti-error host communicates with the robot operation background through the forward and reverse isolation device and the communication front host; When the transfer device is an edge computing device, the intelligent anti-error host communicates with the robot operation background through a one-way optical gate and the edge computing device.
[0063] In this preferred embodiment, the instruction acquisition module M1 introduces a transfer device (a communication front-end host or an edge computing device) as a communication hub between the first safety zone (the intelligent anti-error host) and the second safety zone (the robot operation background), and uses a forward and reverse isolation device or a one-way optical gate to achieve cross-safety zone data isolation transmission, preventing the intelligent anti-error host from being directly exposed to the low-security zone and reducing the risk of external attacks. When a communication front-end host is used, the forward and reverse isolation device is used to limit the two-way communication traffic to meet the compliance requirements of the power grid security zoning. When an edge computing device is used, the one-way optical gate is used to achieve one-way communication, while avoiding the high cost of deploying two-way isolation equipment. The above design flexibly adapts to the communication conditions of different old substations (such as whether they have forward and reverse isolation devices) to achieve secure communication and low-cost transformation across safety zones without replanning the network architecture.
[0064] Further, the unlock request module M3 includes a first unlock request unit; Among them, the first unlocking request unit is used to send the unlocking request and status information to the communication pre-host when the transfer device is a communication pre-host, so that the communication pre-host sends the unlocking request and status information to the intelligent anti-error host.
[0065] In this preferred embodiment, the unlocking request module M3 forwards the unlocking request and device status information to the intelligent anti-error host through the communication front host, and utilizes the one-way transmission characteristics of the forward and reverse isolation devices (such as only allowing data from the low security zone to the high security zone) to prevent data leakage in the high security zone, thereby achieving reliable communication across security zones under the existing network architecture of the old substation, avoiding the high costs caused by deploying dedicated communication gateways or upgrading network facilities.
[0066] Furthermore, the key sending module M4 includes: a first key sending unit; Among them, the first key sending unit is used to send the unlocking key to the robot after the intelligent anti-error host returns the unlocking key when the transfer device is a communication front-end host; wherein, the unlocking key is generated by the intelligent anti-error host after the second anti-error check is passed, and is sent to the robot operation background through the communication front-end host.
[0067] In this preferred embodiment, after the intelligent anti-error host generates the unlocking key, the key sending module M4 transmits the key to the robot operation background through the communication front host, and then sends it to the robot, thereby realizing the secure transmission of the key across security zones and avoiding the modification costs caused by deploying a dedicated key server.
[0068] Furthermore, the unlock request module M3 further includes a second unlock request unit; The second unlock request unit is used to send the unlock request and status information to the edge computing device after receiving the unlock request and the status information of the target device and before sending the unlock key to the robot when the transfer device is an edge computing device, so that the edge computing device performs a second anti-error check based on the status information and returns the unlock key after the second anti-error check passes.
[0069] In this preferred embodiment, edge computing devices directly perform secondary error-proofing checks based on device status information, replacing the remote verification process of intelligent error-proofing hosts. This reduces delays and the risk of failure in cross-security zone communications. Furthermore, the unidirectional data flow characteristics of one-way optical switches (allowing data only from high-security zones to low-security zones) replace traditional bidirectional isolation devices, reducing equipment deployment costs. This "edge-based verification" architecture effectively balances safety zone compliance with retrofit costs in older substations with weak communication infrastructure.
[0070] Specifically, the more detailed working principle and step flow of the robot operation background can be found in, but not limited to, the relevant records of Example 1.
[0071] In this embodiment, the instruction acquisition module standardizes the reception of operational task instructions, eliminating errors associated with manual transmission. The motion control module drives the robot to autonomously navigate to the target device, eliminating the time-consuming and safety-related risks of manual inspections. The unlock request module and key transmission module collaborate to ensure strict synchronization between secondary verification and key transmission, avoiding operational interruptions. The execution control module directly issues operational instructions after unlocking, forming a closed-loop control process. This modular design improves overall system efficiency through functional decoupling and automated execution, while also reducing reliance on legacy substation communication infrastructure.
[0072] Example 3: Please refer to Figure 4 Based on the same inventive concept, an embodiment of the present invention discloses a robot-based substation anti-misoperation control system, comprising: a centralized control center, an intelligent anti-misoperation host, a robot operation background, a robot, an intelligent mechanical lock, and various target devices; Wherein, the intelligent anti-error host is in communication connection with the centralized control center; The robot operation backend is in communication with the intelligent anti-error host, and is used to execute the robot-based substation anti-error operation control method as described in any one of the first embodiments; The robot is connected to the robot operation background through wireless communication; Each of the target devices (not shown in the figure) is equipped with the smart mechanical lock; The intelligent mechanical lock is connected to the robot via Bluetooth.
[0073] In this embodiment, standardized operational tasks are generated collaboratively between the centralized control center and the intelligent error prevention host, ensuring source compliance. Wireless communication between the robot's operating backend and the robot easily adapts to the weak network environment of older substations. Intelligent mechanical locks connect directly to the robot via Bluetooth, eliminating the cost of deploying a converged terminal. This system architecture, through a "centralized control - hierarchical verification - local execution" model, enables one-click sequential control with minimal modification to existing facilities, directly addressing the high cost of retrofitting older substations.
[0074] Furthermore, the target device is configured with a sensor and a ZigBee communication module, and the robot is configured with a ZigBee terminal; wherein the ZigBee terminal and the ZigBee communication module of the target device form a Mesh network, the sensor is used to collect the status information of the target device itself, and the ZigBee communication module is used to send the status information to the robot through the Mesh network.
[0075] In this preferred embodiment, by configuring sensors and ZigBee communication modules on the target device, and using ZigBee terminals and device modules to form a Mesh network, self-organized collection and transmission of device status information is achieved, replacing the defects of traditional solutions that rely on wired sensor networks or manual on-site transcription; sensors directly collect target device status data and transmit it to the robot through multiple hops of the Mesh network, avoiding the renovation difficulties caused by aging cables or missing communication interfaces in old substations; the self-organizing networking characteristics of the Mesh network support dynamic coverage and multi-path redundancy, adapting to scenarios with complex equipment distribution or severe obstruction in old substations, and improving data collection reliability; the robot receives device status information through the ZigBee terminal and integrates the data into the secondary anti-error verification process, avoiding the additional deployment of data acquisition gateways or relay equipment, and further reducing renovation costs.
[0076] Furthermore, the robot is equipped with a camera and a visual recognition module; wherein, the camera and the visual recognition module are used to collect status information of the target device.
[0077] In this preferred embodiment, by configuring the robot with a camera and a visual recognition module, machine vision technology is used to automatically identify the number and status information of the target device, replacing the inefficient mode of relying on physical sensors or manual on-site verification in traditional solutions; the visual recognition module circumvents the limitations of missing sensor interfaces or difficult modifications in old substations through real-time analysis of equipment status; at the same time, the coordination of visual recognition and robot mobile operations integrates inspection and operation functions into a single carrier, avoiding the deployment of separate inspection robots or fixed cameras for status monitoring, and significantly reducing hardware deployment costs.
[0078] Furthermore, the robot and the robot operation background are configured with a LoRa gateway; wherein, the LoRa gateway is used to wirelessly connect the robot and the robot operation background.
[0079] In this preferred embodiment, by configuring a LoRa gateway for the robot and the robot operation background, the long-distance, low-power consumption characteristics of LoRa technology are used to establish a wireless communication link, replacing the high-cost communication transformation that relies on optical fiber or Wi-Fi base stations in traditional solutions; the wide-area coverage capability of the LoRa gateway supports the cross-regional mobile operation of the robot in the complex environment of the substation, avoiding operation interruptions caused by signal blind spots; through the low-bandwidth data transmission characteristics of the LoRa protocol, the communication requirements of the robot's operation instructions and status feedback are adapted, reducing the load pressure on the existing network facilities of the old substation; at the same time, the collaboration between LoRa and the robot's local control logic realizes the reliable transmission of operation instructions and real-time feedback of execution status, ensuring strict synchronization between anti-error verification and operation execution, and improving the overall stability of the system.
[0080] The specific working process of each module described above can refer to the corresponding process in the aforementioned method embodiment and will not be repeated here. The division of the modules is only a logical function division. In actual implementation, there may be other division methods, such as combining multiple modules or integrating them into another system.
[0081] The specific embodiments described above further illustrate the objectives, technical solutions, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A robot-based control method for preventing misoperation of a substation, characterized in that: Applicable to robot operation background; The substation misoperation prevention control method includes: Obtaining an operation task instruction; wherein the operation task instruction is generated by the intelligent anti-error host performing a first anti-error check on the operation task created by the centralized control center; According to the operation task instruction, confirm the location of the target device and send a corresponding movement instruction to the robot, so that the robot moves to the location of the target device and activates the smart mechanical lock of the target device, and returns an unlock request and status information of the target device; Sending the unlock request and status information to the intelligent anti-error host, so that the intelligent anti-error host performs a second anti-error check according to the status information, and returns the unlock key after the second anti-error check passes; Sending the unlocking key to the robot, so that the robot unlocks the smart mechanical lock according to the unlocking key; After the intelligent mechanical lock is unlocked, the operation task instruction is sent to the robot, so that the robot performs the corresponding instruction operation according to the operation task instruction.
2. A robot-based substation misoperation prevention control method according to claim 1, characterized in that: The obtaining of the operation task instruction includes: Receive operation task instructions sent by the transfer device; wherein the intelligent anti-error host is deployed in the safety zone 1, the transfer device and the robot operation background are deployed in the safety zone 2, and the intelligent anti-error host and the robot operation background are communicated through the transfer device; The transfer device includes a communication front-end host or an edge computing device; When the transfer device is a communication front host, the intelligent anti-error host communicates with the robot operation background through the forward and reverse isolation device and the communication front host; When the transfer device is an edge computing device, the intelligent anti-error host communicates with the robot operation background through a one-way optical gate and the edge computing device.
3. A robot-based control method for preventing misoperation of a substation according to claim 2, characterized in that: The step of sending the unlock request and status information to the intelligent anti-error host comprises: When the transfer device is a communication front host, the unlocking request and status information are sent to the communication front host, so that the communication front host sends the unlocking request and status information to the intelligent anti-error host.
4. A robot-based substation misoperation prevention control method according to claim 2, characterized in that: The sending the unlocking key to the robot comprises: When the transfer device is a communication front-end host, after the intelligent anti-error host returns the unlocking key, the unlocking key is sent to the robot; wherein, the unlocking key is generated by the intelligent anti-error host after the second anti-error check is passed, and is sent to the robot operation background through the communication front-end host.
5. The robot-based control method for preventing misoperation of a substation according to claim 2, characterized in that: After receiving the unlock request and the status information of the target device, and before sending the unlock key to the robot, the method further includes: When the transfer device is an edge computing device, the unlocking request and status information are sent to the edge computing device, so that the edge computing device performs a second anti-error check based on the status information, and returns the unlocking key after the second anti-error check passes.
6. A robot operation background, characterized in that: The robot operation background includes: an instruction acquisition module, a movement control module, an unlock request module, a key sending module and an execution control module; The instruction acquisition module is used to acquire the operation task instruction; wherein the operation task instruction is generated by the intelligent anti-error host performing the first anti-error check on the operation task created by the centralized control center; The movement control module is used to confirm the location of the target device according to the operation task instruction and send a corresponding movement instruction to the robot, so that the robot moves to the location of the target device, activates the intelligent mechanical lock of the target device, and returns an unlock request and status information of the target device; The unlock request module is configured to send the unlock request and status information to the intelligent anti-error host, so that the intelligent anti-error host performs a second anti-error check based on the status information and returns the unlock key after the second anti-error check passes; The key sending module is used to send the unlocking key to the robot, so that the robot unlocks the smart mechanical lock according to the unlocking key; The execution control module is used to send the operation task instruction to the robot after the intelligent mechanical lock completes unlocking, so that the robot performs the corresponding instruction operation according to the operation task instruction.
7. A robot-based substation anti-misoperation control system, characterized in that: include: Centralized control center, intelligent anti-error host, robot operation background, robots, intelligent mechanical locks and various target devices; Wherein, the intelligent anti-error host is in communication connection with the centralized control center; The robot operation background is in communication with the intelligent anti-error host, and is used to execute the robot-based substation anti-error operation control method according to any one of claims 1 to 5; The robot is connected to the robot operation background through wireless communication; Each of the target devices is equipped with the intelligent mechanical lock; The intelligent mechanical lock is connected to the robot via Bluetooth.
8. The robot-based substation misoperation prevention control system according to claim 7, characterized in that: The target device is configured with a sensor and a ZigBee communication module, and the robot is configured with a ZigBee terminal; wherein the ZigBee terminal and the ZigBee communication module of the target device form a Mesh network, the sensor is used to collect the status information of the target device itself, and the ZigBee communication module is used to send the status information to the robot through the Mesh network.
9. The robot-based substation misoperation prevention control system according to claim 7, characterized in that: The robot is equipped with a camera and a visual recognition module, wherein the camera and the visual recognition module are used to collect status information of the target device.
10. A robot-based substation anti-misoperation control system according to any one of claims 7 to 9, characterized in that: The robot and the robot operation background are configured with a LoRa gateway; wherein, the LoRa gateway is used to wirelessly connect the robot and the robot operation background.
Citation Information
Patent Citations
Power transformation switching on-site anti-error method and system
CN112215570A
Robot system, robot control method, and storage medium
CN112757308A
Unlocking result sending method and device, storage medium and electronic device
CN116580485A
Industrial internet security supervision system
CN117997572A
Transformer substation robot anti-misoperation control method and system
CN118672117A