Intelligent anti-accident safety interlocking method for multistage closed loop test of converter valve
By constructing a multi-level active safety interlock system, the problems of low efficiency and safety hazards in manual inspection during converter valve testing have been solved, enabling rapid and reliable safety interlock inspection and improving the intelligence and standardization of test safety management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CONSTR BRANCH OF STATE GRID JIANGSU ELECTRIC POWER CO LTD
- Filing Date
- 2025-06-25
- Publication Date
- 2026-06-19
AI Technical Summary
In existing technologies, manual inspection of safety conditions for converter valve testing is inefficient, carries a high risk of misoperation, and lacks a unified verification process, resulting in safety hazards and low efficiency.
A multi-level active safety interlocking system is adopted. The structural function analysis method is used to determine the failure phenomenon of key equipment components. The system is monitored and analyzed through a multi-signal parallel judgment mechanism to identify abnormal states and trigger rapid power-off and discharge operations to achieve safety interlocking.
It enables rapid and reliable safety interlock checks, reduces human error and omissions, improves the standardization and intelligence of test safety management, and lowers the risk of accidents.
Smart Images

Figure CN120629858B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system maintenance and testing technology, specifically to an intelligent accident prevention and safety interlocking method for multi-stage closed-loop testing of converter valves. Background Technology
[0002] As a core component of high-voltage direct current transmission systems, the operating status of converter valves directly affects the safety and stability of the system. The thyristor-level unit, as the smallest structural component of the converter valve, consists of multiple functional modules, including damping circuits, voltage equalization circuits, and energy extraction circuits. It has a complex structure, numerous components, and operates under extreme conditions of high voltage and high current, making it prone to parameter drift, aging, and even failure over long-term operation.
[0003] To ensure the reliability of converter valves before commissioning and during operation and maintenance, routine testing of thyristor-level units is essential. Currently, there is a lack of a unified platform in China specifically designed for comprehensive multi-item, multi-mode testing of thyristor-level units. Traditional testing methods often rely on a single excitation signal and manual operation, limiting the types of tests available, making it difficult to cover multiple typical operating conditions, and also failing to achieve simultaneous evaluation of multiple functional modules.
[0004] Especially when dealing with the complex impedance characteristics of thyristors, particularly when analyzing the combined state of multiple frequency responses and different circuit channels, existing methods struggle to balance testing efficiency, accuracy, and engineering adaptability. There is an urgent need for a comprehensive testing system with automatic control capabilities, applicable to various test items, capable of rapid testing and performance evaluation of multiple key functional modules of the thyristor stage under high-voltage environments, thereby improving on-site maintenance efficiency and fault identification capabilities. The thyristor converter valve testing platform in a high-voltage direct current (HVDC) transmission system is a complex test environment with multi-stage closed-loop control. High voltage and high current are involved in valve performance and withstand voltage tests, making safety extremely important. Traditionally, operators need to manually verify that multiple safety interlock conditions are met before testing. This manual inspection method has significant limitations:
[0005] 1. Inefficiency: Checking multiple safety conditions one by one is time-consuming and laborious, especially when large converter valve tests require repeated entry and exit from the test area. Each time, various interlocking conditions must be rechecked, affecting the test process.
[0006] 2. Prone to omissions and misoperations: Relying solely on manual inspection procedures is unreliable. Operators may miss certain safety measures due to inexperience or negligence. When restarting testing after replacing wiring, it's easy to forget to remove the grounding wire. If the high-voltage generator is energized at this time, it can easily cause short circuits, overcurrents, blow fuses, and even endanger equipment and personal safety. If the emergency stop button is not reset or has poor contact, it will not be able to cut off the power in time in an emergency, posing a significant safety hazard.
[0007] 3. Lack of a unified verification process: Different personnel may have inconsistent understandings and implementations of safety measures, and there is a lack of a standardized, end-to-end verification mechanism on-site to ensure that safety conditions are fully verified before each test. This situation may lead to loopholes in safety management and make it impossible to ensure that every test meets the same safety standards.
[0008] In view of the above problems, the converter valve test platform urgently needs an improved safety interlock inspection method that can quickly and automatically verify the status of all related interlock signals before the test begins. Summary of the Invention
[0009] The technical problem to be solved by the present invention is to provide an intelligent anti-accident safety interlock method for multi-stage closed-loop testing of converter valves, which overcomes the shortcomings of the existing technology, such as low efficiency, high risk of misoperation, and lack of unified verification process in the manual inspection of safety conditions item by item.
[0010] To solve the above technical problems, the present invention adopts the following technical solution:
[0011] A method for intelligent accident prevention and safety interlocking for multi-stage closed-loop testing of converter valves includes the following steps:
[0012] S1. Using structural-functional analysis methods, the failure phenomena of key equipment components that occur during the testing of thyristors by the testing device are determined, and the failure phenomena are located and classified for management.
[0013] S2. Construct a multi-level active safety interlocking system. Utilize this system and a multi-signal parallel judgment mechanism to monitor and analyze the results obtained in step S1, identify abnormal states, and trigger rapid power-off and discharge operations to complete interlocking monitoring.
[0014] S3. Perform safety protection operations based on the interlocking monitoring results of step S2 to complete the safety interlocking.
[0015] Furthermore, in step S1, the test process includes a wiring preparation stage, a boost excitation stage, a trigger control stage, and a status monitoring stage. In the wiring preparation stage, the test cable is manually connected to the test port. In the boost excitation stage, a 3kV excitation signal is applied to the thyristor stage. In the trigger control stage, a conduction command is sent through fiber optic communication. In the status monitoring stage, the output voltage, current, and feedback signals are collected, and the test status is determined.
[0016] Acquire key equipment components that appear during the testing process, and obtain the corresponding failure phenomena based on the failures of key equipment components; classify and organize the failure phenomena according to three dimensions: functional stage, triggering conditions, and consequences, to form a preliminary failure mode table.
[0017] According to IEC 60812 and AIAG FMEA Manual, the failure modes in the preliminary failure mode table are assigned corresponding severity index values, occurrence probability index values, and detectability index values. The three index values are multiplied to obtain the corresponding risk priority number. Failure modes with risk priority numbers higher than the set safety threshold are selected as high-risk failure modes.
[0018] Obtain the location, timing, and role of high-risk failure modes within the physical structure, enabling the location and hierarchical management of critical equipment components.
[0019] Furthermore, key equipment components include test ports and high-voltage cables in the wiring preparation stage, boost modules and isolation transformers in the boost excitation stage, fiber optic interfaces and control chips in the trigger control stage, and voltage and current sensors and data acquisition modules in the status monitoring stage.
[0020] Furthermore, the safety threshold is set to 100.
[0021] Furthermore, in step S2, the multi-level active safety interlocking system includes a hardware protection layer, a state perception layer, a logic judgment layer, and an execution feedback layer. The hardware protection layer deploys protective components to address the failure phenomena that occurred in step S1, performing high and low voltage isolation, electrical partitioning, and physical protection. The state perception layer configures a state perception module to collect key physical signals. The Zynq-7020 programmable SoC chip in the logic judgment layer performs interlocking judgment on the key physical signals, including startup sequence verification, operating status monitoring, and abnormal interlocking trigger logic, obtaining corresponding allow / disallow signals. The execution feedback layer inputs the allow / disallow signals to the high-voltage relay control terminal and the bleeder resistor trigger terminal, driving the relay to cut off the high-voltage output path within 0.8ms, while simultaneously activating the bleeder resistor module to reduce the port voltage to the set safe potential within 50ms, completing the interlocking monitoring.
[0022] Furthermore, key physical signals include grounding status signals, emergency stop button status, foot switch status, and voltage and current sampling signals.
[0023] Furthermore, in step S3, the safety protection operation includes the test preparation stage, the test initiation stage, the test operation stage, and the test anomaly handling stage.
[0024] During the test preparation phase, if the grounding status is normal, the emergency stop button is not pressed, and the foot pedal is pressed, the test start procedure will be initiated; otherwise, the test start procedure will be prohibited and the output path will remain disconnected.
[0025] During the test start-up phase, the grounding status, emergency stop button status, and foot pedal status are checked sequentially according to a preset order. When the grounding status output is at a normal logic level, the emergency stop switch feedback is at a high level, and the foot pedal is closed, an enable / disable signal is output.
[0026] During the trial operation phase, multi-channel signal acquisition and status judgment tasks are performed. When the enable / disable signal is within the set status range, the excitation signal is input to the thyristor stage; otherwise, the interlock response action is immediately executed, including disconnecting the output, releasing the remaining energy, generating prompt information and recording the event content.
[0027] During the abnormal handling phase of the test, the output permission is automatically blocked. When the output is at a normal logic level in the grounded state, the emergency stop switch feedback is at a high level, the foot pedal is closed and the voltage and current are within the set range, the start permission is restored, and the event log data is exported and the interlocking function is verified.
[0028] Furthermore, the present invention also proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the intelligent accident prevention and safety interlock method for multi-stage closed-loop testing of the converter valve.
[0029] Furthermore, the present invention also proposes a computer-readable storage medium storing a computer program, wherein the computer program is executed by a processor to describe the intelligent accident prevention and safety interlocking method for multi-stage closed-loop testing of converter valves.
[0030] Compared with the prior art, the present invention, employing the above technical solution, has the following technical effects:
[0031] 1. This invention eliminates the need to spend a lot of time repeatedly inspecting each safety device before the test. A single operation can provide feedback on the results of all interlocking states within seconds, greatly shortening the test preparation time.
[0032] 2. This invention employs preset logic to rigorously determine safety conditions, avoiding omissions and errors caused by human factors, eliminating the risk of overlooking potential hazards during manual inspection, and significantly improving reliability.
[0033] 3. This invention highly integrates the complex security inspection process and simplifies it into a single button or instruction, making it simple and clear, and reducing the burden of human interaction and decision-making.
[0034] 4. This invention integrates safety verification into the entire test process control, automating everything from pre-test inspection to in-test monitoring, achieving closed-loop supervision of safety interlocks throughout the entire process, and greatly improving the standardization and intelligence of test safety management. Attached Figure Description
[0035] Figure 1 This is a flowchart illustrating the overall implementation of the present invention.
[0036] Figure 2 This is a schematic diagram of a device grounding alarm in an embodiment of the present invention. Detailed Implementation
[0037] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the scope of protection of the present invention.
[0038] To achieve the above objectives, this invention proposes an intelligent accident prevention and safety interlock method for multi-stage closed-loop testing of converter valves, such as... Figure 1 As shown, the specific steps are as follows:
[0039] S1. Using structural-functional analysis methods, identify failure phenomena in key equipment components during thyristor-level testing using the testing device, and locate and classify these failure phenomena; specifically:
[0040] The testing process includes a wiring preparation stage, a boost excitation stage, a trigger control stage, and a status monitoring stage. In the wiring preparation stage, the test cable is manually connected to the test port. In the boost excitation stage, a 3kV excitation signal is applied to the thyristor stage. In the trigger control stage, a conduction command is sent via fiber optic communication. In the status monitoring stage, the output voltage, current, and feedback signals are collected, and the test status is determined.
[0041] Acquire key equipment components encountered during the testing process, including test ports and high-voltage cables in the wiring preparation phase, boost modules and isolation transformers in the boost excitation phase, fiber optic interfaces and control chips in the trigger control phase, and voltage and current sensors and data acquisition modules in the status monitoring phase. Analyze the operational actions required for each phase, such as manually connecting cables, pressing the start button, sending control signals, and acquiring sensor data, to identify key triggering behaviors and human factors in the operation process.
[0042] Define the output behavior of each functional stage, including but not limited to high voltage output, current response, data recording, and fault diagnosis, and abstract the "input-processing-output" process of this stage into a functional logic chain to form a structure-function mapping table.
[0043] Based on the failure of key equipment components, obtain the corresponding failure phenomena; specifically:
[0044] When the test port is loosely connected to the high-voltage cable or has poor contact, failures such as high-resistance contact, abnormal temperature rise, or intermittent signal interruption may occur. When the insulation layer of the boost module and isolation transformer ages or the cable sheath is damaged, failures such as high-voltage end breakdown, arcing, or partial discharge may occur. When there is jitter in the fiber optic link, false triggering of the control chip, or command deviation, failures such as premature conduction of the thyristor may occur. When the parameters of the voltage and current sensors and data acquisition module are not set correctly, failures such as misjudgment of status, delayed response, or interlocking triggering errors may occur.
[0045] The failure phenomena are classified and organized according to three dimensions: functional stage, triggering conditions, and consequences, forming a preliminary failure mode table.
[0046] According to IEC 60812 and the AIAG FMEA manual, the failure modes in the preliminary failure mode table are assigned corresponding severity, probability of occurrence, and detectability values. The severity (S) value represents the degree of harm or damage to the personal safety of operators or the stable operation of equipment once a failure mode occurs, with a score range of 1 to 10, where a higher value indicates more severe consequences. The probability of occurrence (O) value represents the likelihood of a failure mode occurring in actual use, assessed based on historical data, environmental stability, and operating frequency, with a score range of 1 to 10. The detectability (D) value represents how easily a failure mode can be detected and identified, with a score range of 1 to 10, where a higher score indicates that it is more difficult to detect in a timely manner.
[0047] Multiply the three index values to obtain the corresponding Risk Priority Number (RPN). Select failure modes with a Risk Priority Number higher than the set safety threshold (100) as high-risk failure modes, which are the priority control targets for the subsequent construction of the safety interlock system.
[0048] For example, if the failure mode of grounding wire disconnection is assigned the values S=10, O=6, D=3, then RPN=180; if the failure mode of false triggering caused by fiber optic interference is assigned the values S=9, O=6, D=4, then RPN=216.
[0049] Obtain the location, timing, and role of high-risk failure modes within the physical structure, enabling the location and hierarchical management of critical equipment components.
[0050] For example, grounding failures are concentrated at the PE terminal of the power input and the grounding point of the equipment casing; fiber optic interference is mistriggered and located at the fiber optic interface and related communication modules in the control area; and output short circuits mainly occur between the test cable and the load connection port. Grounding failure usually occurs in the preparation stage before the test starts, fiber optic interference mostly occurs in the boost and triggering stages, and misoperation due to the foot pedal not being pressed is common in manual cable replacement or pre-test operation stages.
[0051] The nature of the role in the fault chain includes source faults (such as PE disconnection directly causing electric shock) and chain amplification faults (such as fiber optic mis-triggering further causing thyristor conduction and equipment damage).
[0052] For each high-risk event, suggestions are made on establishing a corresponding security system, including the types of sensing devices to be deployed (such as grounding detection modules, current and voltage sensors, button interlock devices, etc.), interlock response levels (such as microsecond-level hardware power failure or millisecond-level software prompts), and control logic design principles (such as sequence verification, interlock judgment, etc.).
[0053] S2. Construct a multi-level active safety interlocking system. Utilize this system and a multi-signal parallel judgment mechanism to monitor and analyze the results obtained in step S1, identify abnormal states, and trigger rapid power-off and discharge operations to complete interlocking monitoring; specifically:
[0054] The multi-level active safety interlocking system includes a hardware protection layer, a state perception layer, a logic judgment layer, and an execution feedback layer. The hardware protection layer provides physical isolation, protection against electric shock, and anti-interference capabilities. The state perception layer collects and identifies key physical signals in the test state. The logic judgment layer processes state data in real time, makes decisions, and generates control commands. The execution feedback layer implements response actions and transmits interlocking results and fault information back.
[0055] To address the failure phenomenon observed in step S1, a hardware protection layer is used to deploy protective components (such as insulated cables, isolation transformers, fiber optic communication interfaces, etc.) to perform high and low voltage isolation, electrical partitioning, and physical protection; specifically:
[0056] An isolation transformer is connected in series at the power input terminal to achieve electrical isolation between the mains power and the control system; 10kV insulated interfaces and silicone rubber high-voltage cables are used in the high-voltage output channel to improve the withstand voltage and anti-discharge capability; all control signal channels are converted to fiber optic transmission to cut off the common mode interference path between high and low voltage areas; an isolated grounding test port is set between the control cabinet shell and the PE ground to form a structural closed loop.
[0057] The state-aware layer is used to configure a state-aware module to detect the failure phenomena that occur in step S1 and to collect key physical signals; specifically:
[0058] A dual-path grounding detection module is installed in the equipment grounding circuit to measure the resistance between the PE line and the chassis in real time. If the resistance is greater than 0.1Ω, an interlocking disable signal is output. A voltage / current sensor is integrated in the high-voltage output path, with an ADC sampling rate of 6Msps to identify sudden short circuit, overvoltage, and overcurrent events. An emergency stop button is installed on the front panel of the equipment, and a foot switch is installed on the rear panel, with their status output as 24V logic level. All 24V signals are converted to 3.3V TTL level by a level converter and input to the main control chip through a unified interface.
[0059] The Zynq-7020 programmable SoC chip in the logic judgment layer is used to interlock and judge key physical signals, including start-up sequence verification (grounding qualified → emergency stop reset → foot pedal closed), operation status monitoring (overcurrent, voltage drop, signal interference), and abnormal interlock trigger logic, to obtain corresponding allow / disable signals, which are used to drive subsequent execution modules to complete high voltage disconnection and discharge actions; the control cycle of the above judgment logic is strictly limited to the μs range to ensure the real-time performance and reliability of fault response.
[0060] The execution feedback layer is used to input the enable / disable signal to the control terminal of the high-voltage relay and the trigger terminal of the bleeder resistor, driving the relay to cut off the high-voltage output path within 0.8ms. At the same time, the bleeder resistor module is activated to reduce the port voltage to the set safe potential (less than 60V) within 50ms, thus completing the interlock monitoring.
[0061] After the interlocking action is completed, the execution status and trigger type information are fed back to the human-machine interface, and the source of the fault is prompted in the form of a pop-up window. At the same time, the fault timestamp, waveform data and response action information are stored in the eMMC chip for subsequent traceability analysis and export operations.
[0062] The key physical signals include grounding status signal, emergency stop button status, foot switch status, and voltage and current sampling signals.
[0063] S3. Based on the interlocking monitoring results of step S2, perform safety protection operations to complete the safety interlocking; specifically:
[0064] Safety protection operations include the test preparation phase, the test initiation phase, the test operation phase, and the test anomaly handling phase.
[0065] During the test preparation phase, if the grounding status is normal, the emergency stop button is not pressed, and the foot pedal is pressed, the test start procedure will be initiated; otherwise, the test start procedure will be prohibited and the output path will remain disconnected.
[0066] During the test start-up phase, the grounding status, emergency stop button status, and foot pedal status are checked sequentially according to a preset order. When the grounding status output is at a normal logic level, the emergency stop switch feedback is at a high level, and the foot pedal is closed, an enable / disable signal is output.
[0067] During the trial operation phase, multi-channel signal acquisition and status judgment tasks are performed. When the enable / disable signal is within the set status range, the excitation signal is input to the thyristor stage; otherwise, the interlock response action is immediately executed, including disconnecting the output, releasing the remaining energy, generating prompt information and recording the event content.
[0068] During the abnormal handling phase of the test, the output permission is automatically blocked. When the output is at a normal logic level in the grounded state, the emergency stop switch feedback is at a high level, the foot pedal is closed and the voltage and current are within the set range, the start permission is restored. At the same time, the event record data is exported and the interlocking function is verified to ensure the coverage and effectiveness of the interlocking action response.
[0069] Example:
[0070] The experimental scenario is as follows:
[0071] Testing Phase: Low-voltage trigger test (output 3kV power frequency voltage). Simulated Fault: Intentionally creating a thyristor-level short circuit (simulating wiring errors). Interlocking Objective: Cut off the output and discharge within 10ms to prevent equipment damage.
[0072] The obtained experimental data are shown in Table 1.
[0073] Table 1 Experimental Data
[0074]
[0075]
[0076] During the experiment, the control unit continuously monitors the grounding detection signal, voltage and current signals, foot switch signal, and emergency stop button signal. If any of these signals is abnormal, the experiment stops, and the equipment reports a fault alarm.
[0077] After the equipment is started, it will not output anything without any operation. When the experimenter performs the test, the equipment first checks whether it is reliably grounded. If the grounding wire is missing, a pop-up window will appear indicating that the grounding wire is reliably connected. If the equipment is reliably grounded, it checks whether the emergency stop button is pressed. If the emergency stop button is pressed, a pop-up window will appear indicating that the emergency stop button is pressed. If the emergency stop button is pressed, it checks whether the foot switch is pressed. If the foot switch is not pressed, a pop-up window will appear indicating that the foot switch is pressed. If the foot switch is pressed, the equipment will output test signals according to the test items.
[0078] The internal sampling circuit of the equipment samples and monitors the output signal in real time to check for any abnormalities (abnormalities include: open circuit in the test signal line, short circuit in the test signal line, or other high-voltage backflow on the test signal line). If the output signal is abnormal, the experimental equipment will immediately stop the experimental output and pop up a warning window to warn of the abnormal test signal.
[0079] If any abnormal situation occurs during the experiment, such as the foot switch being released, the emergency stop button being pressed, or the grounding wire being detached, the equipment will immediately stop outputting and discharge; at the same time, the equipment will display a pop-up prompt or alarm.
[0080] The equipment features a one-click safety verification function. When operators need to perform this function, they simply select the safety verification button in the settings interface. They then follow the system pop-up prompts to perform related operations, such as pressing and releasing the foot switch, pressing and releasing the emergency stop button, etc. After these operations, the system determines whether there is a safety risk. If a risk is found, it will be displayed at the risk warning location, as shown in Table 2.
[0081] Table 2. Example Table of Interlocking Systems
[0082] event Detection methods Device output Influence Grounding detection real time pop-up window No testing Voltage and current signals During the experiment Alerts + Pop-ups No testing Foot pedal to open pipe real time pop-up window No testing Emergency stop button real time pop-up window No testing
[0083] Upon power-up, the equipment performs a grounding test. If the equipment is reliably grounded, a grounding fault is immediately reported. Before each test, the system checks the status of the foot switch and emergency stop button. If the status is normal, the test operation is performed. If the status is abnormal, the system reports that the foot switch is not pressed or the emergency stop button is not turned on. If the system detects an overvoltage or overcurrent signal during the test, it immediately disconnects the output and reports an overcurrent fault, and the fault alarm light remains on.
[0084] like Figure 2 The diagram shows a grounding alarm on the equipment. A red alarm window pops up on the HMI interface, displaying fault code E01: Grounding Failure and operation instructions. The alarm information includes the specific fault location (abnormal casing grounding) and handling suggestions (check the PE line connection). The interface simultaneously locks the "Start Test" button (grayed out and inoperable). Figure 2 The results show that the device's dual grounding detection mechanism (power supply end + casing) works in synergy with visual alarms to eliminate the risk of electric shock at the source, and the measured grounding anomaly blocking response time is ≤100ms.
[0085] This paper presents a "one-click" method for power testing safety interlocks, enabling operators to automatically verify the status of multiple safety interlock signals with a single command. This aims to eliminate potential oversights and delays associated with manual inspections, significantly improving the efficiency of safety checks during the test preparation phase.
[0086] In summary, this invention significantly improves the safety verification method of existing converter valve testing platforms. Balancing speed and accuracy, it increases work efficiency while minimizing accident risks, demonstrating significant practical value. In practical applications, it helps foster a "procedure-based, zero-error" safety testing culture, ensuring the safe and stable conduct of testing work on high-voltage direct current transmission equipment.
[0087] This invention also proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. It should be noted that when the processor executes the computer program, it corresponds to the specific steps of the method provided in this invention, possessing the corresponding functional modules and beneficial effects for executing the method. Technical details not described in detail in this embodiment can be found in the method provided in this invention.
[0088] This invention also proposes a computer-readable storage medium storing a computer program. It should be noted that when the computer program is executed by a processor, it corresponds to the specific steps of the method provided in this invention, possessing the corresponding functional modules and beneficial effects for executing the method. Technical details not described in detail in this embodiment can be found in the method provided in this invention.
[0089] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A multi-stage closed-loop test intelligent anti-accident safety interlocking method for a converter valve, characterized in that, include: S1. Using structural-functional analysis methods, the failure phenomena of key equipment components that occur during the testing of thyristors by the testing device are determined, and the failure phenomena are located and classified for management. S2. Construct a multi-level active safety interlocking system. Utilize this system and a multi-signal parallel judgment mechanism to monitor and analyze the results obtained in step S1, identify abnormal states, and trigger rapid power-off and discharge operations to complete interlocking monitoring; specifically: The multi-level active safety interlocking system includes a hardware protection layer, a state perception layer, a logic judgment layer, and an execution feedback layer; the hardware protection layer is used to deploy protective components for the failure phenomena that occur in step S1, and to perform high and low voltage isolation, electrical partitioning, and physical protection; The state-aware layer is used to configure a state-aware module to detect the failure phenomena that occur in step S1 and to collect key physical signals; specifically: A dual-path grounding detection module is installed in the equipment grounding circuit to measure the resistance between the PE line and the chassis in real time. If the resistance is greater than 0.1Ω, an interlocking disable signal is output. A voltage / current sensor is integrated in the high-voltage output path, with an ADC sampling rate of 6Msps to identify sudden short circuit, overvoltage, and overcurrent events. An emergency stop button is installed on the front panel of the equipment, and a foot switch is installed on the rear panel, with their status output as 24V logic level. All 24V signals are converted to 3.3VTTL level by a level converter and input to the main control chip through a unified interface. The Zynq-7020 programmable SoC chip in the logic judgment layer is used to perform interlock judgment on key physical signals, including startup sequence verification, operation status monitoring and abnormal interlock triggering logic, to obtain the corresponding allow / disable signals; The execution feedback layer is used to input the enable / disable signal to the control terminal of the high-voltage relay and the trigger terminal of the discharge resistor, driving the relay to cut off the high-voltage output path within 0.8ms. At the same time, the discharge resistor module is activated to reduce the port voltage to the set safe potential within 50ms, thus completing the interlock monitoring. S3. Perform safety protection operations based on the interlocking monitoring results of step S2 to complete the safety interlocking.
2. The multi-stage closed-loop test intelligent anti-accident safety interlock method for a commutation valve according to claim 1, characterized in that, In step S1, the test process includes the wiring preparation stage, the boost excitation stage, the trigger control stage, and the status monitoring stage; in the wiring preparation stage, the test cable is manually connected to the test port. During the boost excitation stage, a 3kV excitation signal is applied to the thyristor stage; during the trigger control stage, a turn-on command is sent via optical fiber communication. During the condition monitoring phase, the output voltage, current, and feedback signals are collected, and the test condition is determined. Acquire key equipment components that appear during the testing process, and obtain the corresponding failure phenomena based on the failures of the key equipment components; The failure phenomena are classified and organized according to three dimensions: functional stage, triggering conditions, and consequences, to form a preliminary failure mode table. According to IEC 60812 and AIAG FMEA Manual, the failure modes in the preliminary failure mode table are assigned corresponding severity index values, occurrence probability index values and detectability index values. The three index values are multiplied to obtain the corresponding risk priority number. Failure modes with risk priority numbers higher than the set safety threshold are selected as high-risk failure modes. Obtain the location, timing, and role of high-risk failure modes within the physical structure, enabling the location and hierarchical management of critical equipment components.
3. The multi-stage closed-loop test intelligent anti-accident safety interlock method for a thyristor valve according to claim 2, characterized in that, Key equipment components include test ports and high-voltage cables in the wiring preparation stage, boost modules and isolation transformers in the boost excitation stage, fiber optic interfaces and control chips in the trigger control stage, and voltage and current sensors and data acquisition modules in the status monitoring stage.
4. The intelligent accident prevention and safety interlock method for multi-stage closed-loop testing of converter valves according to claim 2, characterized in that, Set the safety threshold to 100.
5. The intelligent accident prevention and safety interlock method for multi-stage closed-loop testing of converter valves according to claim 1, characterized in that, Key physical signals include grounding status signal, emergency stop button status, foot switch status, and voltage and current sampling signals.
6. The intelligent accident prevention and safety interlock method for multi-stage closed-loop testing of converter valves according to claim 1, characterized in that, In step S3, the safety protection operation includes the test preparation stage, the test initiation stage, the test operation stage, and the test anomaly handling stage; During the test preparation phase, if the grounding status is normal, the emergency stop button is not pressed, and the foot pedal is pressed, the test start procedure will be initiated; otherwise, the test start procedure will be prohibited and the output path will remain disconnected. During the test start-up phase, the grounding status, emergency stop button status, and foot pedal status are checked sequentially according to a preset order. When the grounding status output is at a normal logic level, the emergency stop switch feedback is at a high level, and the foot pedal is closed, an enable / disable signal is output. During the trial operation phase, multi-channel signal acquisition and status judgment tasks are performed. When the enable / disable signal is within the set status range, the excitation signal is input to the thyristor stage. Conversely, if the output is not connected, an interlocking response action is immediately executed, including disconnecting the output, releasing the remaining energy, generating a prompt message, and recording the event content. During the abnormal handling phase of the test, the output permission is automatically blocked. When the output is at a normal logic level in the grounded state, the emergency stop switch feedback is at a high level, the foot pedal is closed and the voltage and current are within the set range, the start permission is restored, and the event log data is exported and the interlocking function is verified.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the intelligent accident prevention and safety interlocking method for multi-stage closed-loop testing of converter valves as described in any one of claims 1 to 6.
8. A computer-readable storage medium storing a computer program, characterized in that, The computer program, when executed by the processor, performs the intelligent accident prevention and safety interlocking method for multi-stage closed-loop testing of converter valves as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Testing system of thyristor converter valve control full link
CN115729217A
Safety interlocking method and device based on multi-level equipment configuration, electronic equipment and storage medium
CN118157313A