Method and system for monitoring multi-source heterogeneous data of transformer substation

Through IoT edge computing technology, the communication rules of substation equipment are automatically identified, fast-changing and slow-changing data streams are divided, equipment status threshold intervals are generated, and local abnormality decisions and spatiotemporal correlation analysis are performed, solving the problem of heterogeneous data from multi-source equipment in substations and realizing real-time monitoring and rapid fault isolation.

CN120638645AActive Publication Date: 2025-09-12ZHEJIANG SUNMEI TRANSMISSION & DISTRIBUTION CO LTD

Patent Information

Application Number
CN202510935365.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-08
Publication Date
2025-09-12
Estimated Expiration
2045-07-08

AI Technical Summary

Technical Problem

In existing technologies, the communication protocols of multi-source equipment in substations are highly heterogeneous, making it difficult to uniformly analyze and effectively integrate data, delaying abnormality judgment and failing to meet real-time monitoring requirements in complex scenarios. Traditional methods are also unable to adapt to dynamic operating condition changes, making it difficult to identify hidden fault correlations and prevent chain reactions in the system.

Method used

A method based on IoT edge computing is adopted to automatically identify device communication rules, divide fast-changing and slow-changing data streams, generate fused data packets, dynamically generate device status threshold intervals, combine local execution units and spatiotemporal correlation analysis to generate enhanced alarm signals, and select data transmission mode according to signal importance and network status.

Benefits of technology

It achieves adaptive analysis and fusion of multi-source heterogeneous data, improves the accuracy and environmental adaptability of anomaly detection, reduces cloud dependence and communication delay, and ensures the rapid isolation of power equipment faults and system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120638645A_ABST
    Figure CN120638645A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of automation control, and relates to a transformer substation multi-source heterogeneous data monitoring method and system based on Internet of Things edge computing, and the method comprises the steps: building a mapping relation between an equipment identity label and a corresponding data format; generating a fusion data packet; generating an equipment state threshold interval; triggering a local execution unit to act when the deviation amplitude exceeds a first critical value, and generating a signal to be rechecked when the deviation amplitude is lower than the first critical value but exceeds a second critical value; matching a preset processing scheme according to the equipment physical position code and the electrical connection topological relation, and generating a control instruction set; performing time-space correlation analysis on the to-be-rechecked signal and the local action event, and when the to-be-rechecked signal and the local action event occur in the same electrical loop within a preset time range, improving the event priority and generating an enhanced alarm signal; and selecting one of the complete data packet, the compressed feature data and the alarm code to perform cloud communication. The method solves the problem that in a traditional mode, an isolated analysis mode of abnormal events and equipment actions is difficult to recognize hidden fault association.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of automation control and relates to a substation multi-source heterogeneous data monitoring method and system based on Internet of Things edge computing. Background Art

[0002] In the fields of Industrial Internet of Things and power system automation, real-time monitoring and anomaly control of multi-source equipment are core requirements for ensuring safe operation. However, existing technologies utilize diverse and highly heterogeneous device communication protocols, and the data formats and acquisition frequencies of different interfaces vary significantly, making it difficult to uniformly analyze and effectively integrate data across devices. Traditional methods rely on manually configured protocol templates and static threshold settings, which are unable to adapt to dynamic operating conditions. Anomaly detection lags behind the actual status of the equipment, making it difficult to meet the real-time monitoring requirements in complex scenarios.

[0003] Traditional solutions use fixed protocol converters to interconnect devices and match anomalies using a pre-set rule base. Data fusion is achieved through hard synchronization with a unified clock source or simple time window interception, but this fails to account for the differences in timing characteristics between fast- and slow-changing data. For cloud communications, most systems use full data upload or a single compression algorithm, lacking the ability to dynamically adapt to network status and signal importance.

[0004] Based on the above problems, the traditional method of isolated analysis mode of abnormal events and equipment actions is difficult to identify hidden fault correlations and cannot prevent chain system risks. Summary of the Invention

[0005] In the first aspect, the present invention provides a substation multi-source heterogeneous data monitoring method based on IoT edge computing, which adopts the following technical solutions: The substation multi-source heterogeneous data monitoring method based on IoT edge computing includes the following steps: S1. Obtain device data from different communication interfaces, automatically identify device communication rules by comparing received signal features with pattern fragments in a pre-stored protocol template library, and establish a mapping relationship between device identity and corresponding data format; S2. Device data is divided into fast-changing data streams and slow-changing data streams according to the preset collection period. The two types of data streams are time-stamped and processed uniformly to generate a fused data packet; S3, extracting the load rate, ambient temperature, and operating mode indicators from the equipment operating parameters based on the fused data packet, and generating the equipment status threshold interval based on the dynamic relationship between the three; S4. When it is detected that the parameter value exceeds the device status threshold range, the parameter deviation amplitude is calculated, and the local execution unit action is triggered when the deviation amplitude exceeds the first critical value, and a pending review signal is generated when the deviation amplitude is lower than the first critical value but exceeds the second critical value; S5. For abnormal events that trigger the action of the local execution unit, a preset disposal plan is matched according to the physical location code and electrical connection topology of the equipment to generate a control instruction set; S6. Perform spatiotemporal correlation analysis on the signal to be reviewed and the local action event. If both occur in the same electrical circuit within a preset time range, the event priority is increased and an enhanced alarm signal is generated. S7. According to the importance of the enhanced alarm signal and the current network delay, one of the complete data packet, compressed feature data, and alarm code is selected for cloud communication.

[0006] A further solution of the present invention automatically identifies device communication rules by comparing received signal features with pattern fragments in a pre-stored protocol template library, and establishes a mapping relationship between device identity and corresponding data format, including the following steps: Get the initial data packet and split it into header segment, instruction segment and check segment according to preset rules; Extract the signature sequence of the header segment and calculate the matching degree with the pattern fragments in the pre-stored protocol template library. If the matching degree exceeds the set matching degree threshold, the communication protocol type is determined; Parse the data structure of the instruction segment according to the communication protocol type, extract the device identification code as the unique identity, and establish a mapping relationship between the device identity and the data format conversion rule; The matching threshold refers to the matching between the feature code sequence and the communication protocol, which is determined by industry experience and expert knowledge.

[0007] A further solution of the present invention is to pre-store a protocol template library, comprising the following steps: A pre-stored set of typical communication signature codes for different communication protocols, with each protocol corresponding to at least 10 sets of verified standard signature code combinations; When the signature sequence of the header segment fails to match, the signature sequence of the header segment that fails to match starts the expert annotation process for manual annotation and is expanded to the pre-stored protocol template library.

[0008] A further solution of the present invention generates a fused data packet, comprising the following steps: Obtaining a preset collection period based on the device identity, classifying device data with a collection period less than or equal to a preset time threshold as a fast-changing data flow, and classifying device data with a collection period greater than the time threshold as a slowly changing data flow; A time alignment window is generated based on the least common multiple of the fastest and slowest acquisition cycles of each device type. Fast-varying data streams use the instantaneous value at the end of the time alignment window, while slowly varying data streams use linear interpolation to calculate the equivalent value at the middle of the time alignment window. The timestamps of the two types of data streams are unified to the same basis and then merged into a fused data packet.

[0009] A further solution of the present invention generates a device status threshold interval, comprising the following steps: Analyze the load rate, ambient temperature, and operating mode indicators in the fusion data package; The load factor is calculated by converting the ratio of the device's rated capacity to its actual output current. The ambient temperature is measured by a temperature sensor installed on the device. The operating mode indicator identifies the device's current operating state. The upper and lower limits of the dynamic threshold are calculated based on the product of the load rate and the ambient temperature and the weight factor of the working mode, and the equipment status threshold range is generated.

[0010] A further solution of the present invention calculates the parameter deviation amplitude, triggers the local execution unit action based on whether the deviation amplitude exceeds a first critical value, and generates a pending review signal when the deviation amplitude is lower than the first critical value but exceeds a second critical value, including the following steps: The first critical value is determined by the maximum instantaneous deviation allowed by the equipment's safe operation standards; the second critical value is set based on the fluctuation range of the equipment's historical normal operation parameters and the manufacturer's recommended warning sensitivity. Local execution unit action refers to equipment protection or control operations automatically triggered at the substation site according to preset rules; The signal to be reviewed indicates a warning sign that requires further correlation analysis, including abnormal parameter values, device identity, and occurrence time window information.

[0011] A further solution of the present invention generates a control instruction set, comprising the following steps: Parse the abnormal device's identity and parse its physical location code, which includes the substation bay number, equipment cabinet number, and installation location coordinates; Determine upstream power supply equipment and downstream load equipment of the abnormal device based on the electrical connection topology diagram; The preset disposal plan is matched according to the physical location and topological relationship, and a control instruction set including the phased action sequence is generated.

[0012] A further solution of the present invention, which increases the event priority and generates an enhanced alarm signal, includes the following steps: Compare the device identity, abnormal parameter value, and occurrence time window contained in the acquired signal to be reviewed with the device identity, action execution time, and physical location code involved in the extracted local action event; When the time correlation and electrical circuit connectivity conditions are met, the priority of the signal to be reviewed will be increased by two levels, and an enhanced alarm signal containing a composite event code, a list of related equipment, and recommended disposal measures will be generated.

[0013] A further solution of the present invention selects one of the complete data packet, compressed feature data, and alarm code for cloud communication, including the following steps: Construct a transmission decision matrix based on the priority level of the enhanced alarm signal and the real-time network delay level; When the sum of the signal importance and the delay level reaches the preset decision value, the corresponding data transmission mode is selected; If the network delay exceeds the preset threshold for consecutive times, it will automatically switch to the compressed feature data mode until the delay is restored.

[0014] In a second aspect, the present invention provides a substation multi-source heterogeneous data monitoring system based on IoT edge computing, which adopts the following technical solutions: The substation multi-source heterogeneous data monitoring system based on IoT edge computing includes the following modules: The protocol parsing module is used to obtain device data from different communication interfaces, automatically identify device communication rules by comparing signal characteristics with pattern fragments in the pre-stored protocol template library, and establish a mapping relationship between device identity and corresponding data format; The data fusion module is used to divide the device data into fast-changing data streams and slow-changing data streams according to the preset collection cycle, and the two types of data streams are time-stamped and processed uniformly to generate a fused data packet; The threshold calculation module extracts the load rate, ambient temperature, and operating mode indicators from the equipment operating parameters based on the fused data packet, and generates the equipment status threshold interval based on the dynamic relationship between the three; The abnormal decision module calculates the parameter deviation when it detects that the parameter value exceeds the device status threshold range, triggers the local execution unit action when the deviation exceeds the first critical value, and generates a pending review signal when the deviation is lower than the first critical value but exceeds the second critical value; The control instruction generation module generates a set of control instructions based on the abnormal events that trigger the action of the local execution unit and the preset disposal plan according to the physical location code and electrical connection topology of the equipment; The spatiotemporal correlation analysis module is used to perform spatiotemporal correlation analysis on the signals to be reviewed and local action events. When both occur in the same electrical circuit within a preset time range, the event priority is increased and an enhanced alarm signal is generated. The communication scheduling module selects one of the complete data packet, compressed feature data, and alarm code for cloud communication according to the importance of the enhanced alarm signal and the current network delay.

[0015] In summary, the present invention has the following beneficial technical effects: 1. Through adaptive protocol parsing technology, it effectively integrates industrial equipment data with different interfaces and communication protocols, eliminating heterogeneous barriers to device interconnection. Combined with a dynamic threshold calculation model, it integrates multi-dimensional parameters such as load rate, ambient temperature, and operating mode in real time to generate device status threshold intervals, significantly improving the accuracy and environmental adaptability of anomaly detection and avoiding the false positives or missed positives caused by traditional static thresholds. 2. A classification and alignment mechanism for fast- and slow-changing data streams is adopted, along with dynamic time window partitioning and linear interpolation algorithms, to resolve the fusion challenge of inconsistent multi-frequency data timestamps. Combined with local abnormality decision-making and control instruction generation modules, this significantly reduces cloud dependency and communication latency, ensuring rapid isolation of power equipment faults and system security. 3. An adaptive transmission strategy based on composite event priorities and network status achieves a dynamic balance between signal importance and communication latency. Differentiated data transmission modes are selected for different alarm signal levels, ensuring the integrity of critical data while reducing bandwidth usage for non-essential data, effectively addressing congestion in traditional cloud channels. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. The drawings are used to provide a further understanding of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0017] Figure 1 A schematic diagram of the flow chart in the embodiment of the present application is disclosed.

[0018] Figure 2 The present invention discloses a schematic structural diagram in an embodiment of the present application. DETAILED DESCRIPTION

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. All other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0020] The following is combined with Figure 1-Figure 2 The preferred embodiments of the present invention are described in detail.

[0021] Refer to the attached Figure 1 , the present invention proposes a substation multi-source heterogeneous data monitoring method based on Internet of Things edge computing, which includes the following steps: S1. Obtain device data from different communication interfaces, automatically identify device communication rules by comparing received signal features with pattern fragments in a pre-stored protocol template library, and establish a mapping relationship between device identity and corresponding data format; S2. Device data is divided into fast-changing data streams and slow-changing data streams according to the preset collection period. The two types of data streams are time-stamped and processed uniformly to generate a fused data packet; S3, extracting the load rate, ambient temperature, and operating mode indicators from the equipment operating parameters based on the fused data packet, and generating the equipment status threshold interval based on the dynamic relationship between the three; S4. When it is detected that the parameter value exceeds the device status threshold range, the parameter deviation amplitude is calculated, and the local execution unit action is triggered when the deviation amplitude exceeds the first critical value, and a pending review signal is generated when the deviation amplitude is lower than the first critical value but exceeds the second critical value; S5. For abnormal events that trigger the action of the local execution unit, a preset disposal plan is matched according to the physical location code and electrical connection topology of the equipment to generate a control instruction set; S6. Perform spatiotemporal correlation analysis on the signal to be reviewed and the local action event. If both occur in the same electrical circuit within a preset time range, the event priority is increased and an enhanced alarm signal is generated. S7. According to the importance of the enhanced alarm signal and the current network delay, one of the complete data packet, compressed feature data, and alarm code is selected for cloud communication.

[0022] In one embodiment of the present invention, step S1 includes the following steps: Acquire device data from different communication interfaces, automatically identify device communication rules by comparing received signal features with pattern fragments in the pre-stored protocol template library, and establish a mapping relationship between device identity and corresponding data format.

[0023] Specifically, when the physical interface receives the initial data packet sent by the device, the initial data packet is divided into a header segment, an instruction segment, and a check segment by bytes, and the characteristic code sequence of each segment is extracted. The characteristic code sequence is composed of a combination of three consecutive bytes in each segment, for example, the start byte of the header segment, the data length byte, and the version number byte. The extracted characteristic code sequence of the header segment is matched with all protocol samples in the pre-stored protocol template library. When the matching degree exceeds the set matching degree threshold, the type of communication protocol adopted by the device is determined. The data structure of the instruction segment is parsed according to the communication protocol type, the device identification code is extracted as a unique identity, and a mapping relationship between the device identity and the corresponding data format is established.

[0024] The pre-stored protocol template library is a collection of pre-stored typical communication signatures for different communication protocols. Each protocol corresponds to at least 10 verified standard signature combinations. If a header signature sequence fails to match, the unmatched header signature sequence is manually annotated using an expert annotation process and added to the pre-stored protocol template library.

[0025] The matching threshold refers to the matching situation between the signature sequence and the communication protocol. It is determined through industry experience and expert knowledge. In the past, the matching threshold of a large number of devices was set in the range of 80%-85% to determine the type of communication protocol used by the device.

[0026] The device identity is the unique code assigned to a device at the factory. It includes the manufacturer code, device type code, and serial number. It is obtained by parsing specific bytes in the instruction segment. The data format mapping relationship refers to the conversion rules between the raw byte stream output by the device and the physical quantity.

[0027] For example, the wireless temperature sensor When the interface is connected, the initial data packet sent is "7E 000A 01 ZT-2023-045 03 01A5 2C". The initial data packet is divided into a header segment (7E 00 0A), an instruction segment (01 ZT-2023-045 03), and a check segment (01A5 2C). The extracted three-byte feature code of the header segment (7E 00 0A) is compared with the pre-stored protocol template library. 、 The typical feature combination comparison of the protocols and other protocols shows that the feature code sequence of the header segment is The match degree of the protocol start symbol (7E) and data length (00 0A) reaches 92%, which exceeds the set match degree threshold and is determined to be Protocol type.

[0028] according to The protocol type parses the data structure of the instruction segment. The 5th to 11th bytes extract the device identification code "ZT-2023-045" (manufacturer code ZT + year 2023 + serial number 045) as the unique identifier. The conversion rule between the original byte stream and the physical quantity is: the two-byte hexadecimal value is converted to decimal and multiplied by 0.1. The set temperature value is located in the 13th and 14th bytes (01A5). The conversion formula , thereby establishing a mapping relationship between device identity and corresponding data format.

[0029] In one embodiment of the present invention, step S2 includes the following steps: After step S1, the device data identified is divided into fast-changing data streams and slowly-changing data streams according to a preset collection period. A time alignment window is generated according to the device type. The timestamps of the fast-changing data streams and the slowly-changing data streams are unified to the same reference and then merged.

[0030] Specifically, based on the mapping relationship between the device identity and the corresponding data format, the collection period of each device is extracted, and the collection period is less than or equal to Seconds are classified as fast-changing data streams, including switch status and instantaneous current values; the acquisition period is greater than Seconds are classified as slowly varying data streams, including temperature measurements and oil chromatogram data. For each device type, the least common multiple of its fastest and slowest acquisition cycles is used as the time alignment window length. Within the time alignment window, fast- and slowly varying data streams are timestamp aligned. Fast- and slowly varying data streams use the instantaneous value at the end of the time alignment window, while slowly varying data streams use linear interpolation to obtain the equivalent value at the middle of the time alignment window. This ultimately generates a fused data packet with a unified time base.

[0031] The collection cycle refers to the time interval for the device to collect data, that is, how often the device collects data. It is an important indicator for measuring the frequency of device data collection. Seconds refers to the set time threshold, which is used to classify the collection cycle of the device. The specific value of seconds is determined by actual needs and application scenarios.

[0032] Fast-changing data streams are characterized by rapid data changes and contain information that can reflect instantaneous changes in the device's state. For example, the switch state (indicating whether the device switch is on or off) and the instantaneous current value (the current size of the device at a specific moment) can capture dynamic changes in the device in a timely manner.

[0033] Slowly varying data streams are characterized by relatively slow data changes. They include temperature measurements (the temperature of the equipment or environment over a period of time) and oil chromatography data (data reflecting the composition and content of dissolved gases in transformer oil). These data do not require high-frequency acquisition.

[0034] The time alignment window length determines the time range used when timestamp alignment is performed on fast- and slow-varying data streams. A fused data packet with a unified time base is a data set that combines data from both fast- and slow-varying data streams after timestamp alignment, forming a unified time base.

[0035] The equivalent value of the middle moment of the time alignment window is calculated by linear interpolation for the slowly varying data stream, which satisfies the following formula:

[0036] in, is the equivalent value after interpolation; and Indicates the timestamps of adjacent sampling points of a slowly varying data stream; The middle moment of the time alignment window; express The original measurement value at the moment, express The original measurement value at the moment, 、 Obtain historical data in real time.

[0037] In one embodiment of the present invention, step S3 includes the following steps: Based on step S2, a fusion data packet with a unified time base is generated, the load rate, ambient temperature, and working mode indicators in the equipment operation parameters are extracted, and the equipment status threshold interval is generated according to the dynamic relationship between the three.

[0038] Specifically, the physical values ​​corresponding to the device identity identifier are analyzed in the fusion data packet generated in step S2, including the load rate, ambient temperature, and operating mode index. The load rate is obtained by converting the ratio of the device's rated capacity to the actual output current. The ambient temperature is obtained from the measurement value of the temperature sensor deployed on the device body. The operating mode index refers to the classification identifier of the device's current operating state. The product of the load rate and the ambient temperature is used as the basic coefficient, and then the weight factor corresponding to the current operating mode is added. Finally, the upper and lower limits of the dynamic threshold are calculated to meet the following formula:

[0039]

[0040] in, Indicates the upper limit of the dynamic threshold; Indicates the lower limit of the dynamic threshold; Indicates the benchmark threshold, which is set by the equipment nameplate parameters or manufacturer standards; is the load factor, which is obtained by converting the ratio of the equipment's rated capacity to the actual output current; is the ambient temperature, which is measured by the temperature sensor deployed on the device body; It is the temperature condition correction value, which is dynamically adjusted based on the equipment operation mode classification. is the upper temperature limit influence coefficient, is the lower limit temperature influence coefficient, which is obtained by fitting the equipment temperature rise test data.

[0041] Among them, the operating mode index refers to the classification identification of the current operating status of the equipment, including four types: no load, light load, heavy load, and overload, and is determined based on the load rate change trend within three consecutive time windows.

[0042] For example, based on the fitting of the equipment temperature rise test data, the temperature condition correction value of no-load is 0°C, the temperature condition correction value of light load is 1°C, the temperature condition correction value of heavy load is 2°C, and the temperature condition correction value of overload is 5°C.

[0043] Assume that a transformer obtains a load rate of 85%, an ambient temperature of 32°C, and a heavy load operating mode in the fusion data packet generated in step S2, i.e., a temperature condition correction value of 2°C for heavy load is substituted into the reference threshold of 85°C; based on the equipment temperature rise test data, the temperature upper limit influence coefficient is 0.3 and the temperature upper limit influence coefficient is 0.2; the final calculation shows that the upper limit of the dynamic threshold is 95°C and the lower limit of the dynamic threshold is 65°C, and the allowable range of the oil temperature of the transformer in the current state is 65°C-95°C. If the real-time oil temperature is not within this range, an abnormal judgment is triggered.

[0044] In one embodiment of the present invention, step S4 includes the following steps: When it is detected that step S3 triggers an abnormal judgment, the abnormal situation is analyzed according to the deviation amplitude. If the deviation amplitude exceeds the first critical value, the local execution unit action is triggered. If the deviation amplitude is lower than the first critical value but exceeds the second critical value, a pending review signal is generated. If the deviation amplitude is lower than the second critical value, normal monitoring is maintained.

[0045] Specifically, based on the device status threshold interval output in step S3, the device's real-time parameter value is compared with the interval boundary. If the parameter value is not within the device status threshold interval, the ratio of the deviation amplitude to the threshold interval width is calculated. The threshold interval width is the difference between the upper dynamic threshold and the lower dynamic threshold, and satisfies the following formula:

[0046] in, is the deviation amplitude; Indicates the upper limit of the dynamic threshold; Indicates the lower limit of the dynamic threshold; Indicates the real-time measurement parameter value of the device.

[0047] If the deviation exceeds the first threshold, it is determined to be an emergency anomaly and triggers the local execution unit to take action. If the deviation is below the first threshold but exceeds the second threshold, it is determined to be a potential anomaly and a pending review signal is generated. If the deviation is below the second threshold, normal monitoring is maintained.

[0048] Local execution unit actions refer to equipment protection or control operations (such as circuit breaker opening, wind turbine startup, and protective device locking) automatically triggered at the substation site according to preset rules. These actions are used to quickly isolate faults or suppress abnormal conditions. Pending verification signals, warning markers requiring further correlation analysis, contain abnormal parameter values, device identification, and the time window in which they occurred.

[0049] The first critical value is determined by the maximum instantaneous deviation allowed by the equipment's safe operation standards. The second critical value is set based on the fluctuation range of the equipment's historical normal operating parameters and the manufacturer's recommended warning sensitivity.

[0050] For example, assume the device status threshold range for a circuit breaker's temperature, generated in step S3, is 65°C-95°C. The first threshold is set at 30% of the threshold range, and the second threshold is set at 10% of the threshold range. Based on the real-time temperature of 102°C detected by the temperature sensor deployed on the device, the deviation is calculated as (102-95) / (95-65) = 23.3%. The current deviation is lower than the first threshold but higher than the second threshold, generating a pending review signal. This pending review signal carries the device identifier "DLQ-2024-009," the temperature value of 102°C, and a timestamp for subsequent correlation analysis.

[0051] In one embodiment of the present invention, step S5 includes the following steps: Step S4 triggers an abnormal event of the local execution unit action, selects a preset disposal plan according to the device physical location coding rules and electrical connection topology relationship, and generates a control instruction set including device identification, action type, and execution sequence.

[0052] Specifically, when step S4 determines that the abnormality level has reached the level that triggers the action of the local execution unit, the physical location code is parsed from the device identity. The physical location code includes the substation interval number, equipment cabinet number, and installation location coordinates. At the same time, the pre-stored electrical connection topology diagram is retrieved to determine the upstream power supply equipment and downstream load equipment of the abnormal device. The physical location code is matched with the corresponding entry in the preset disposal solution set based on the topological relationship. In scenarios involving multi-device linkage, the action priority is determined according to the direction of the current path, and a three-stage instruction sequence is generated, which first disconnects the upstream device, then isolates the local device, and finally activates the protection device.

[0053] The physical location code refers to the unique identifier of the installation location assigned when the device is registered in step S1, and adopts a four-level structure of "substation number-interval number-cabinet number-coordinate number". For example, the device identity "ZT-2023-045" corresponds to the location code "ST-01-A12-XY34". The device identity is a factory-unique code, and the physical location code is an independent field. The device identity is mapped and associated with the corresponding physical location code.

[0054] The electrical connection topology refers to the pre-entered data on the electrical connection relationships between devices, including circuit breaker opening and closing status, busbar connection method, and relay protection related information. The control instruction set refers to a structured command combination that includes device identification, action type code, and execution time window.

[0055] A preset disposal plan set refers to a set of standardized response strategies pre-designed for abnormal scenarios of various types of equipment in a substation. It is indexed by equipment type, physical location code, and electrical topology relationship, and stores structured operation instructions such as fault isolation path selection, multi-device linkage timing logic, and protection setting adjustment parameters.

[0056] For example, assume that step S4 determines that the oil temperature of main transformer No. 1 exceeds the upper dynamic threshold, triggering a local execution unit action. Its physical location code is parsed as "ST-01-A12-XY34." The electrical topology shows that the main transformer is connected to a 10kV busbar and a 35kV busbar. Based on the physical location code and the topological relationship, the "Main Transformer Overload" entry in the preset action plan set is matched. A command sequence is generated: send a trip command to the associated 10kV circuit breaker, start the main transformer fan after a 50ms delay, and lock the 35kV backup power automatic start-up device. The control instruction set is encoded in execution order as follows: ["DLQ-2024-112: Open: 0ms", "FJ-2024-056: Start: 50ms", "BZT-2024-089: Lock: 100ms"]. Each instruction in the control instruction set carries the corresponding device identity and action time parameters.

[0057] In one embodiment of the present invention, step S6 includes the following steps: The signal to be reviewed generated in step S4 is subjected to spatiotemporal correlation analysis with the local action event triggered in step S5. When both occur in the same electrical circuit within a preset time range, the event priority is increased and an enhanced alarm signal is generated.

[0058] Specifically, step S4 obtains the device identity, abnormal parameter value and occurrence time window contained in the signal to be reviewed, and step S5 extracts the device identity, action execution time and physical location code involved in the local action event. By comparing the time window overlap between the signal to be reviewed and the local action event, if the starting time difference between the two is less than the preset time threshold, the electrical connection topology diagram stored in step S5 is retrieved to determine whether the two devices are in the same power supply circuit. When the time correlation and electrical circuit connectivity conditions are met, the priority of the signal to be reviewed is increased by two levels, and an enhanced alarm signal containing a composite event code, a list of related equipment, and recommended disposal measures is generated.

[0059] Spatiotemporal correlation analysis simultaneously verifies the dual conditions of temporal proximity of events and electrical circuit connectivity. Temporal proximity is determined by calculating whether the difference between the start times of two event time windows is less than a set difference threshold. Electrical circuit connectivity is determined by determining whether direct or indirect bus connections exist between devices in the electrical connection topology. The difference threshold is calibrated based on the statistical distribution of the maximum time intervals between associated actions in historical events.

[0060] The enhanced alarm signal refers to a composite alarm data packet containing the original alarm information and the analysis results of the associated events. Its data structure is newly added with the associated device field and the disposal suggestion code based on the signal to be reviewed in step S4.

[0061] For example, based on a comprehensive calibration based on the statistical distribution of the maximum time intervals between associated actions in historical events, a difference threshold of 30 seconds is set. When the main transformer oil temperature pending verification signal (device ID "ZT-2023-045," time window "20240520-1430 to 1432") generated in step S4 and the circuit breaker opening action (device ID "DLQ-2024-112," execution time "20240520-1431") occur, the time difference between the two is calculated to be 1 minute. This exceeds the 30-second difference threshold, so no association is triggered.

[0062] If the circuit breaker operation time is "20240520-1431" and the time window for the signal to be reviewed is "20240520-1430 to 1432", and both are confirmed to be connected to the same 35kV busbar through the electrical topology diagram, an enhanced alarm signal is generated, and it is recommended to check the busbar connection point for overheating risks.

[0063] In one embodiment of the present invention, step S7 includes the following steps: According to step S6, the importance of the alarm signal is enhanced. Combined with the current network communication quality, one of the three methods of transmitting complete data packets, compressing feature data, or only transmitting alarm codes is selected for cloud communication. The choice of communication method depends on the combined judgment of network delay and signal importance.

[0064] In one embodiment of the present invention, selecting one of a complete data packet, compressed feature data, and an alarm code for cloud communication includes the following steps: Construct a transmission decision matrix based on the priority level of the enhanced alarm signal and the real-time network delay level; When the sum of the signal importance and the delay level reaches the preset decision value, the corresponding data transmission mode is selected; If the network delay exceeds the preset number of times within the preset time period, it will automatically switch to the compressed feature data mode until the delay is restored.

[0065] Specifically, the priority tag carried in the enhanced alarm signal is obtained, and the values ​​4 to 1 corresponding to levels P0 (highest) to P3 (lowest) are used as the signal importance coefficient. At the same time, by real-time monitoring of the network round-trip delay, the delay value is divided into four levels with each level being 100ms. A transmission mode decision matrix is ​​established. When the sum of the signal importance coefficient and the delay level is greater than or equal to 5, the complete data packet transmission is selected. When it is between 3 and 4, compressed feature data is selected. When it is less than 3, only the alarm code is transmitted. Compressed feature data reduces the amount of data by retaining the extreme values ​​of abnormal parameters, device identity and key information of the time window. If the network delay exceeds 1 second three times in a row within half an hour, it will automatically switch to the compressed feature data mode until the delay is restored.

[0066] Among them, the importance of the enhanced alarm signal is combined with the probability statistics of failures caused by similar historical events, and the enhanced alarm signal is divided into four levels: P0 (network-level risk, such as main transformer overload chain tripping), P1 (regional level risk, such as busbar pressure loss), P2 (interval level abnormality, such as switch refusal to operate), and P3 (single device minor abnormality, such as sensor drift).

[0067] The transmission mode decision matrix is ​​a two-dimensional selection table with signal importance and network delay level as the coordinate axes. Each cell corresponds to a transmission mode. For example, the sum of importance level 3 (P2) and delay level 2 (200ms) is 5, which triggers full data transmission.

[0068] An alarm code is a predefined 8-digit event code. The first two digits are the device type, the middle four digits are the exception code, and the last two digits identify the site where the alarm occurred.

[0069] For example, the enhanced alarm signal generated in step S6 is at level P1 (importance coefficient 3) and the current network round-trip delay is 280ms (latency level 3), the sum of which is 6. The transmission decision matrix selects full data packet transmission mode, uploading complete data to the cloud, including the device identifier "ZT-2023-045," the abnormal oil temperature value of 95.16°C, and the associated circuit breaker operation records. If the network delay exceeds 1 second three times consecutively within 20 minutes, the system automatically switches to compressed feature data until the delay is reduced.

[0070] See attached Figure 2 , the present invention also proposes a substation multi-source heterogeneous data monitoring system based on IoT edge computing, which includes the following modules: The protocol parsing module is used to obtain device data from different communication interfaces, automatically identify device communication rules by comparing signal characteristics with pattern fragments in the pre-stored protocol template library, and establish a mapping relationship between device identity and corresponding data format; The data fusion module is used to divide the device data into fast-changing data streams and slow-changing data streams according to the preset collection cycle, and the two types of data streams are time-stamped and processed uniformly to generate a fused data packet; The threshold calculation module extracts the load rate, ambient temperature, and operating mode indicators from the equipment operating parameters based on the fused data packet, and generates the equipment status threshold interval based on the dynamic relationship between the three; The abnormal decision module calculates the parameter deviation when it detects that the parameter value exceeds the device status threshold range, triggers the local execution unit action when the deviation exceeds the first critical value, and generates a pending review signal when the deviation is lower than the first critical value but exceeds the second critical value; The control instruction generation module generates a set of control instructions based on the abnormal events that trigger the action of the local execution unit and the preset disposal plan according to the physical location code and electrical connection topology of the equipment; The spatiotemporal correlation analysis module is used to perform spatiotemporal correlation analysis on the signals to be reviewed and local action events. When both occur in the same electrical circuit within a preset time range, the event priority is increased and an enhanced alarm signal is generated. The communication scheduling module selects one of the complete data packet, compressed feature data, and alarm code for cloud communication according to the importance of the enhanced alarm signal and the current network delay.

[0071] It should be noted that the formulas described above, through the principle of dimensional consistency and mathematical standardization (e.g., normalization, dimensionless parameter conversion, or unified unit system), can translate physical quantities of different attributes into unitless standard values ​​or homogeneous, superimposable parameters. This eliminates the interference of different dimensions on operational logic, ensuring that the formulas retain the distribution characteristics of the original data while maintaining mathematical rationality and adaptability to objective laws. These are merely exemplary embodiments of the present invention and are not intended to limit the scope of the invention.

[0072] The modules can be implemented in whole or in part through software, hardware, or a combination thereof, supporting hardware embedded in or independent of a processor in a computer device, and also supporting software stored in a memory in a computer device, so that the processor can call and execute operations corresponding to the modules.

[0073] It should be noted that the human body information (including but not limited to human device information and personal information, etc.) and data (including but not limited to data used for analysis, stored data and displayed data, etc.) involved in the present invention are all information and data authorized by the human body or fully authorized by all parties. The collection, use and processing of relevant data require relevant legal standards.

[0074] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the scope of protection of the present invention.

Claims

1. A method for monitoring multi-source heterogeneous data in a substation, characterized in that: The following steps are involved: S1. Obtain device data from different communication interfaces, automatically identify device communication rules by comparing received signal features with pattern fragments in a pre-stored protocol template library, and establish a mapping relationship between device identity and corresponding data format; S2. Device data is divided into fast-changing data streams and slow-changing data streams according to the preset collection period. The two types of data streams are time-stamped and processed uniformly to generate a fused data packet; S3, extracting the load rate, ambient temperature, and operating mode indicators from the equipment operating parameters based on the fused data packet, and generating the equipment status threshold interval based on the dynamic relationship between the three; S4. When it is detected that the parameter value exceeds the device status threshold range, the parameter deviation amplitude is calculated, and the local execution unit action is triggered when the deviation amplitude exceeds the first critical value, and a pending review signal is generated when the deviation amplitude is lower than the first critical value but exceeds the second critical value; S5. For abnormal events that trigger the action of the local execution unit, a preset disposal plan is matched according to the physical location code and electrical connection topology of the equipment to generate a control instruction set; S6. Perform spatiotemporal correlation analysis on the signal to be reviewed and the local action event. If both occur in the same electrical circuit within a preset time range, the event priority is increased and an enhanced alarm signal is generated. S7. According to the importance of the enhanced alarm signal and the current network delay, one of the complete data packet, compressed feature data, and alarm code is selected for cloud communication.

2. The substation multi-source heterogeneous data monitoring method according to claim 1 is characterized in that: By comparing the received signal characteristics with the pattern fragments in the pre-stored protocol template library, the device communication rules are automatically identified and a mapping relationship between the device identity and the corresponding data format is established, including the following steps: Get the initial data packet and split it into header segment, instruction segment and check segment according to preset rules; Extract the signature sequence of the header segment and calculate the matching degree with the pattern fragments in the pre-stored protocol template library. If the matching degree exceeds the set matching degree threshold, the communication protocol type is determined; Parse the data structure of the instruction segment according to the communication protocol type, extract the device identification code as the unique identity, and establish a mapping relationship between the device identity and the data format conversion rule; The matching threshold refers to the matching between the feature code sequence and the communication protocol, which is determined by industry experience and expert knowledge.

3. The substation multi-source heterogeneous data monitoring method according to claim 2 is characterized in that: The pre-stored agreement template library includes the following steps: A pre-stored set of typical communication signature codes for different communication protocols, with each protocol corresponding to at least 10 sets of verified standard signature code combinations; When the signature sequence of the header segment fails to match, the signature sequence of the header segment that fails to match starts the expert annotation process for manual annotation and is expanded to the pre-stored protocol template library.

4. The substation multi-source heterogeneous data monitoring method according to claim 1 is characterized in that: Generating a fused data packet includes the following steps: Obtaining a preset collection period based on the device identity, classifying device data with a collection period less than or equal to a preset time threshold as a fast-changing data flow, and classifying device data with a collection period greater than the time threshold as a slowly changing data flow; A time alignment window is generated based on the least common multiple of the fastest and slowest acquisition cycles of each device type. Fast-varying data streams use the instantaneous value at the end of the time alignment window, while slowly varying data streams use linear interpolation to calculate the equivalent value at the middle of the time alignment window. The timestamps of the two types of data streams are unified to the same basis and then merged into a fused data packet.

5. The substation multi-source heterogeneous data monitoring method according to claim 1 is characterized in that: Generating a device status threshold interval includes the following steps: Analyze the load rate, ambient temperature, and operating mode indicators in the fusion data package; The load factor is calculated by converting the ratio of the device's rated capacity to its actual output current. The ambient temperature is measured by a temperature sensor installed on the device. The operating mode indicator identifies the device's current operating state. The upper and lower limits of the dynamic threshold are calculated based on the product of the load rate and the ambient temperature and the weight factor of the working mode, and the equipment status threshold range is generated.

6. The substation multi-source heterogeneous data monitoring method according to claim 1, characterized in that: Calculating the parameter deviation amplitude, triggering the local execution unit action according to whether the deviation amplitude exceeds a first critical value, and generating a pending review signal when the deviation amplitude is lower than the first critical value but exceeds a second critical value, including the following steps: The first critical value is determined by the maximum instantaneous deviation allowed by the equipment's safe operation standards; the second critical value is set based on the fluctuation range of the equipment's historical normal operation parameters and the manufacturer's recommended warning sensitivity. Local execution unit action refers to equipment protection or control operations automatically triggered at the substation site according to preset rules; The signal to be reviewed indicates a warning sign that requires further correlation analysis, including abnormal parameter values, device identity, and occurrence time window information.

7. The substation multi-source heterogeneous data monitoring method according to claim 2, characterized in that: Generating a control instruction set includes the following steps: Parse the physical location code from the abnormal device identity, which includes the substation bay number, equipment cabinet number, and installation location coordinates; Determine upstream power supply equipment and downstream load equipment of the abnormal device based on the electrical connection topology diagram; The preset disposal plan is matched according to the physical location and topological relationship, and a control instruction set including the phased action sequence is generated.

8. The substation multi-source heterogeneous data monitoring method according to claim 1 is characterized in that: Raising the event priority and generating an enhanced alarm signal includes the following steps: Compare the device identity, abnormal parameter value, and occurrence time window contained in the acquired signal to be reviewed with the device identity, action execution time, and physical location code involved in the extracted local action event; When the time correlation and electrical circuit connectivity conditions are met, the priority of the signal to be reviewed will be increased by two levels, and an enhanced alarm signal containing a composite event code, a list of related equipment, and recommended disposal measures will be generated.

9. The method for monitoring multi-source heterogeneous data of a substation according to claim 8, characterized in that: Selecting one of the complete data packet, compressed feature data, or alarm code for cloud communication includes the following steps: Construct a transmission decision matrix based on the priority level of the enhanced alarm signal and the real-time network delay level; When the sum of the signal importance and the delay level reaches the preset decision value, the corresponding data transmission mode is selected; If the network delay exceeds the preset threshold for consecutive times, it will automatically switch to the compressed feature data mode until the delay is restored.

10. The substation multi-source heterogeneous data monitoring system is characterized by: Includes the following modules: The protocol parsing module is used to obtain device data from different communication interfaces, automatically identify device communication rules by comparing signal characteristics with pattern fragments in the pre-stored protocol template library, and establish a mapping relationship between device identity and corresponding data format; The data fusion module is used to divide the device data into fast-changing data streams and slow-changing data streams according to the preset collection cycle, and the two types of data streams are time-stamped and processed uniformly to generate a fused data packet; The threshold calculation module extracts the load rate, ambient temperature, and operating mode indicators from the equipment operating parameters based on the fused data packet, and generates the equipment status threshold interval based on the dynamic relationship between the three; The abnormal decision module calculates the parameter deviation when it detects that the parameter value exceeds the device status threshold range, triggers the local execution unit action when the deviation exceeds the first critical value, and generates a pending review signal when the deviation is lower than the first critical value but exceeds the second critical value; The control instruction generation module generates a set of control instructions based on the abnormal events that trigger the action of the local execution unit and the preset disposal plan according to the physical location code and electrical connection topology of the equipment; The spatiotemporal correlation analysis module is used to perform spatiotemporal correlation analysis on the signals to be reviewed and local action events. When both occur in the same electrical circuit within a preset time range, the event priority is increased and an enhanced alarm signal is generated. The communication scheduling module selects one of the complete data packet, compressed feature data, and alarm code for cloud communication according to the importance of the enhanced alarm signal and the current network delay.

Citation Information

Patent Citations

  • Distribution line fault intelligent diagnosis method based on multi-source information fusion

    CN119986258A

  • Equipment anomaly detection method and system based on multi-source heterogeneous data

    CN120145206A

Cited By

  • Lamp language system of power station secondary system

    CN121368052A

  • Flexible gray level grading alarm method and system for substation equipment state

    CN121861844A

  • Traffic logistics key equipment management system based on identification resolution

    CN122372600A