Heavy-duty gas engine control and protection system and method
By working in concert with the control platform, protection platform and dedicated protection devices, the problems of poor versatility and common mode failure risk of the control and protection platform for heavy-duty gas turbines have been solved, achieving the effects of rapid migration and stable operation.
Patent Information
- Application Number
- CN202511438858.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-10
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2045-10-10
AI Technical Summary
Existing heavy-duty gas turbine control and protection platforms rely on hardware platforms, have poor versatility, are difficult to migrate quickly, and are subject to common-mode failure risks, affecting the stable operation of the unit.
The system employs a control platform, a protection platform, and dedicated protection devices working in tandem. It outputs control and protection commands through logic operations and hard-wiring or communication methods, enabling rapid migration and maintaining normal system operation even in the event of a failure of any platform or device.
It enables rapid migration and high versatility of the control and protection system for heavy-duty gas turbines, reduces the risk of common-mode failures, and ensures stable operation of the unit.
Smart Images

Figure CN120889667B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of combustion engine protection, in particular to a heavy-duty combustion engine control and protection system, method and storage medium. BACKGROUND
[0002] The control and protection platform of the heavy-duty gas turbine is the core to ensure the safe and efficient operation of the unit. However, in the related art, the control and protection platform of the heavy-duty gas turbine relies on a hardware platform, and needs to be customized and developed for different hardware platforms, which has poor universality. When the hardware platform is switched, due to differences in bottom layer implementation (such as interrupt response mechanism, communication protocol and redundancy architecture), the hardware platform needs to be re-adapted, so that it is difficult to realize the rapid migration of the control and protection platform design across hardware platforms, and if a module in the hardware platform fails, the entire hardware platform may not work, which has a common mode failure risk and cannot ensure the stable operation of the unit. SUMMARY
[0003] The present application provides a heavy-duty combustion engine control and protection system, method and storage medium to solve the technical problems of poor universality, inability to quickly migrate and common mode failure risk in the prior art.
[0004] To this end, the present application provides a heavy-duty combustion engine control and protection system, which can protect and control the heavy-duty combustion engine through the cooperation of the control platform, the protection platform and the special protection device, does not rely on the hardware platform, can realize rapid migration, and when any platform or device fails, does not affect the normal operation of the heavy-duty combustion engine control and protection system, reduces the common mode risk, and has strong universality.
[0005] Another object of the present application is to provide a heavy-duty combustion engine control and protection method.
[0006] To achieve the above object, the present application provides a heavy-duty combustion engine control and protection system, which comprises a control platform, a protection platform, a special protection device and a protection link.
[0007] The control platform is used to output the control instruction and / or the first protection instruction of the heavy-duty combustion engine based on the control requirement of the heavy-duty combustion engine.
[0008] The protection platform is used to output the first protection control instruction of the heavy-duty combustion engine based on the first protection requirement of the heavy-duty combustion engine, wherein the first protection requirement comprises an overspeed protection requirement and a normal cycle requirement.
[0009] The special protection device is used to output the first special protection control instruction of the heavy-duty combustion engine based on the second protection requirement of the heavy-duty combustion engine, wherein the second protection requirement comprises the overspeed protection requirement and an ultra-fast cycle requirement.
[0010] The protection link is configured to receive instructions sent by the control platform and / or the protection platform and / or the special protection device, and perform corresponding safety protection actions based on the instructions.
[0011] The heavy-duty gas turbine control and protection system according to the embodiments of the present application can further have the following additional technical features.
[0012] In an embodiment of the present application, the control requirements include first control requirements and second control requirements; and the control platform includes a slow cycle processing module and a fast cycle processing module.
[0013] The slow cycle processing module is configured to process the first control requirements.
[0014] The fast cycle processing module is configured to process the second control requirements.
[0015] In an embodiment of the present application, the system further includes an execution mechanism connected to the control platform.
[0016] The execution mechanism is configured to perform corresponding control actions based on the control instructions.
[0017] In an embodiment of the present application, the control platform is further configured to:
[0018] send a first interlocking signal to the protection platform based on the first protection instructions;
[0019] send a second interlocking signal to the special protection device based on the first protection instructions; and / or
[0020] receive a first state feedback signal sent by the protection platform, and output second protection instructions based on the first state feedback signal;
[0021] receive a second state feedback signal sent by the special protection device, and output third protection instructions based on the second state feedback signal.
[0022] In an embodiment of the present application, the protection platform is further configured to:
[0023] send the first state feedback signal to the control platform;
[0024] send a third interlocking signal to the special protection device based on the first protection control instructions; and / or
[0025] receive the first interlocking signal sent by the control platform, and output second protection control instructions based on the first interlocking signal;
[0026] receive the fourth interlocking signal sent by the dedicated protection device, and output a third protection control instruction based on the fourth interlocking signal.
[0027] In an embodiment of the present application, the dedicated protection device is further configured to:
[0028] send the second state feedback signal to the control platform;
[0029] send the fourth interlocking signal to the protection platform based on the first dedicated protection control instruction; and / or
[0030] receive the second interlocking signal sent by the control platform, and output a second dedicated protection control instruction based on the second interlocking signal;
[0031] receive the third interlocking signal sent by the protection platform, and output a third dedicated protection control instruction based on the third interlocking signal.
[0032] In an embodiment of the present application, the system further comprises an emergency manual device, configured to determine the operating state of the heavy-duty gas turbine, and trigger a gas turbine protection action based on the obtained determination result.
[0033] In an embodiment of the present application, the system further comprises an adjustment platform, configured to determine a redundancy adjustment suggestion of the heavy-duty gas turbine control and protection system based on an input requirement, wherein the input requirement comprises the control requirement or the first protection requirement or the second protection requirement.
[0034] In an embodiment of the present application, the determination of the redundancy adjustment suggestion of the heavy-duty gas turbine control and protection system based on the input requirement comprises:
[0035] determining a target barrier for processing the input requirement, wherein the target barrier is at least one of the control platform, the protection platform, the dedicated protection device, and the emergency manual device;
[0036] determining a first reliability of the input requirement based on the number of the target barriers;
[0037] determining a second reliability of each barrier in the target barriers;
[0038] determining a third reliability of the input requirement based on the first reliability and the second reliability;
[0039] determining the redundancy adjustment suggestion of the heavy-duty gas turbine control and protection system based on the third reliability.
[0040] In an embodiment of the present application, the determination of the second reliability of each barrier in the target barriers comprises:
[0041] determine input reliability corresponding to the barrier;
[0042] determine processing reliability corresponding to the barrier;
[0043] determine output reliability corresponding to the barrier;
[0044] determine second reliability of each of the barriers based on the input reliability, the processing reliability and the output reliability.
[0045] In an embodiment of the present application, the determining the redundancy adjustment suggestion of the heavy-duty gas turbine control and protection system based on the third reliability comprises:
[0046] determining whether the redundancy needs to be adjusted based on the third reliability;
[0047] if it is determined that the redundancy needs to be adjusted, determining the redundancy adjustment suggestion of the heavy-duty gas turbine control and protection system.
[0048] In an embodiment of the present application, the protection link comprises a first execution unit, a second execution unit and a third execution unit, wherein,
[0049] the first execution unit is configured to receive the first protection instruction sent by the control platform and perform corresponding safety protection actions based on the first protection instruction;
[0050] the second execution unit is configured to receive the first protection control instruction sent by the protection platform and perform corresponding safety protection actions based on the first protection control instruction;
[0051] the third execution unit is configured to receive the first special protection control instruction sent by the special protection device and perform corresponding safety protection actions based on the first special protection control instruction.
[0052] To achieve the above-mentioned purposes, another aspect of the present application provides a heavy-duty gas turbine control and protection method applied to a heavy-duty gas turbine control and protection system, and the method comprises:
[0053] outputting, by a control platform, a control instruction and / or a first protection instruction of the heavy-duty gas turbine based on a control requirement of the heavy-duty gas turbine;
[0054] outputting, by a protection platform, a first protection control instruction of the heavy-duty gas turbine based on a first protection requirement of the heavy-duty gas turbine, wherein the first protection requirement comprises an overspeed protection requirement and a normal cycle requirement;
[0055] The dedicated protection device outputs a first dedicated protection control instruction of the heavy-duty gas turbine based on a second protection requirement of the heavy-duty gas turbine, wherein the second protection requirement includes the overspeed protection requirement and the ultra-fast cycle requirement.
[0056] The protection link receives the instruction sent by the control platform and / or the protection platform and / or the dedicated protection device, and performs a corresponding safety protection action based on the instruction.
[0057] Another object of the present application is to provide an electronic device comprising:
[0058] at least one processor; and
[0059] a memory in communication with the at least one processor; wherein
[0060] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of the preceding aspects.
[0061] Another object of the present application is to provide a computer storage medium, wherein the computer storage medium stores computer executable instructions; the computer executable instructions are executed by a processor to enable the computer to perform the method of any one of the preceding aspects.
[0062] The heavy-duty gas turbine control and protection system and method of the embodiments of the present application, the system comprises a control platform, a protection platform, a dedicated protection device and a protection link, the control platform is used for outputting a control instruction and / or a first protection instruction of a heavy-duty gas turbine based on a control requirement of the heavy-duty gas turbine; the protection platform is used for outputting a first protection control instruction of the heavy-duty gas turbine based on a first protection requirement of the heavy-duty gas turbine; the dedicated protection device is used for outputting a first dedicated protection control instruction of the heavy-duty gas turbine based on a second protection requirement of the heavy-duty gas turbine; and the protection link is used for receiving an instruction sent by the control platform and / or the protection platform and / or the dedicated protection device, and performing a corresponding safety protection action based on the instruction. Thus, the present application protects and controls the heavy-duty gas turbine through the cooperation of the control platform, the protection platform and the dedicated protection device, does not depend on a hardware platform, can realize rapid migration, and when any platform or device fails, does not affect the normal operation of the heavy-duty gas turbine control and protection system, reduces common mode risk, and has strong versatility.
[0063] Additional aspects and advantages of the present application will be given in part in the following description, will become apparent from the following description, or will be learned by practice of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0064] The above and / or additional aspects and advantages of the present application will become apparent and more readily appreciated from the following description, taken in conjunction with the following drawings of exemplary embodiments of the present application, wherein:
[0065] Figure 1 is a structural schematic diagram of a heavy-duty combustion engine control and protection system according to an embodiment of the present application;
[0066] Figure 2 is a flow schematic diagram of a heavy-duty combustion engine control and protection method according to an embodiment of the present application. DETAILED DESCRIPTION
[0067] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0068] In order to enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work should fall within the protection scope of the present application.
[0069] The heavy-duty combustion engine control and protection system and method according to the embodiments of the present application will be described below with reference to the accompanying drawings.
[0070] Figure 1 is a structural schematic diagram of a heavy-duty combustion engine control and protection system according to an embodiment of the present application.
[0071] As shown in Figure 1 , the system includes a control platform, a protection platform, a special protection device, and a protection link.
[0072] The control platform is configured to output a control instruction and / or a first protection instruction of the heavy-duty combustion engine based on a control requirement of the heavy-duty combustion engine.
[0073] The protection platform is configured to output a first protection control instruction of the heavy-duty combustion engine based on a first protection requirement of the heavy-duty combustion engine.
[0074] The special protection device is configured to output a first special protection control instruction of the heavy-duty combustion engine based on a second protection requirement of the heavy-duty combustion engine.
[0075] The protection link is configured to receive the instructions sent by the control platform and / or the protection platform and / or the special protection device, and perform a corresponding safety protection action based on the instructions.
[0076] In an embodiment of the present application, the control requirements can include a first control requirement, a second control requirement, and an overspeed protection requirement, wherein the first control requirement corresponds to a "slow cycle" processing task (such as engine parameter monitoring), and the second control requirement corresponds to a "fast cycle" processing task (such as fuel system P2 pressure control).
[0077] In an embodiment of the present application, the control platform can adopt a software and hardware architecture A, and an integrated processing module is used to process the first control requirement and the second control requirement.
[0078] Specifically, in an embodiment of the present application, the control platform can include a slow cycle processing module and a fast cycle processing module. The slow cycle processing module is used to process the first control requirement and generate a control instruction, and the fast cycle processing module is used to process the second control requirement and generate a control instruction, so that accurate control of the engine can be achieved, the requirements of fast control and protection can be met, engine protection functions are provided, and response timeliness is improved.
[0079] In addition, in an embodiment of the present application, the system can further include an execution mechanism connected with the control platform, and the execution mechanism is used to execute a corresponding control action based on the control instruction.
[0080] In an embodiment of the present application, the first protection requirement can include an overspeed protection requirement and a normal cycle requirement (such as engine bearing temperature protection and shaft vibration protection).
[0081] In an embodiment of the present application, the protection platform can adopt a software and hardware architecture B meeting the SIL3 safety level to process the overspeed protection requirement and the normal cycle requirement of engine protection from the perspective of safety and harm.
[0082] In an embodiment of the present application, the second protection requirement can include an overspeed protection requirement and an ultrafast cycle requirement (such as a surge requirement).
[0083] In addition, in an embodiment of the present application, the special protection device can adopt a pure hardware architecture meeting the SIL3 safety level, so that a protection action can be triggered by pure hardware, software interference can be avoided, and engine protection actions can be independently executed.
[0084] Further, in an embodiment of the present application, the protection link can be composed of first execution units, second execution units, and third execution units corresponding to the control platform, the protection platform, and the special protection device respectively, so that instructions sent by the control platform and / or the protection platform and / or the special protection device can be received, any set of corresponding safety protection actions can be executed based on the instructions, and the protection function can be realized to make the engine enter a safe state.
[0085] In one embodiment of the present invention, overspeed protection requirements can be processed simultaneously through a control platform, a protection platform, and a dedicated protection device, thereby ensuring timely processing of overspeed protection requirements and guaranteeing the stable operation of the unit.
[0086] Furthermore, in one embodiment of the present invention, the control platform, protection platform, and dedicated protection device all adopt a "fail-safe power failure action" mechanism. That is, when any platform or device experiences an abnormal power failure, a fail-safe power failure command will be forcibly sent to the protection link, so that the protection link can trigger a safety protection action based on the fail-safe power failure command, thereby ensuring that the gas turbine enters a safe state.
[0087] Furthermore, in one embodiment of the present invention, after receiving a control request, the control platform can collect signals from field measuring devices, perform logical operations based on the operation control requirements, and send the resulting control commands to the actuators via hardwiring or communication to control corresponding components (such as servo valves, solenoid valves, switches, valve positioners, and valve electric actuators), thereby achieving control of the gas turbine. In one embodiment of the present invention, the aforementioned logical operations are pre-defined.
[0088] Furthermore, in one embodiment of the present invention, the control platform may also obtain a first protection command (such as protection of systems such as compressor, combustion chamber, turbine, secondary air, and auxiliary equipment) based on control requirements or protection triggers, and trigger the first execution unit corresponding to the control platform in the protection link to execute the first protection command.
[0089] Furthermore, in one embodiment of the present invention, while the control platform outputs the first protection command, the control platform can also send an interlock signal to the protection platform and the dedicated protection device based on the first protection command, so as to prevent the execution unit corresponding to the control platform from refusing to operate. Specifically, in one embodiment of the present invention, the control platform can also be used to: send a first interlock signal to the protection platform and a second interlock signal to the dedicated protection device based on the first protection command.
[0090] In one embodiment of the present invention, the protection platform can also be used to receive a first interlock signal sent by the control platform, and can output a corresponding second protection control command based on the first interlock signal. The output second protection control command is sent to the protection link through hard-wiring or communication. The second protection control command is executed by the corresponding second execution unit in the protection link. The first interlock signal may include a first protection command, and the first protection command and the second protection control command may be the same, thereby preventing the execution unit corresponding to the control platform from refusing to operate and ensuring the stable operation of the unit.
[0091] Furthermore, in one embodiment of the present invention, the aforementioned dedicated protection device can also be used to receive a second interlock signal sent by the control platform, and can output a corresponding second dedicated protection control command based on the second interlock signal. The output second dedicated protection control command is then sent to the protection link via hardwiring or communication. The second dedicated protection control command is executed by the corresponding third execution unit in the protection link. The second interlock signal may include a first protection command, and the first protection command and the second dedicated protection control command may be the same, thereby preventing the execution unit corresponding to the control platform from refusing to operate and ensuring the stable operation of the unit.
[0092] Furthermore, in one embodiment of the present invention, the safety protection action triggered by the control platform through the first protection command can achieve the protection function through the coordinated action of three automatic protection barriers: the control platform, the protection platform, and the dedicated protection device. This ensures that the failure of the execution unit corresponding to any two of them will not affect the execution of the protection action, thereby reducing the risk of common mode and ensuring the stable operation of the unit.
[0093] Furthermore, in one embodiment of the present invention, after receiving the first protection request, the protection platform can generate a corresponding first protection control command based on the first protection request, and send the first protection control command to the protection link through hard wiring or communication. The second execution unit in the protection link executes the first protection control command to perform the corresponding safety protection action (such as temperature protection of each bearing of the gas turbine and vibration protection of the shaft system), thereby realizing the protection of the gas turbine.
[0094] Furthermore, in one embodiment of the present invention, while the protection platform outputs the first protection control command, the protection platform can also send corresponding signals to the control platform and the dedicated protection device to prevent the execution unit corresponding to the protection platform from refusing to operate. Specifically, in one embodiment of the present invention, the protection platform can also be used to: send a first status feedback signal to the control platform, and based on the first protection control command, send a third interlock signal to the dedicated protection device.
[0095] In one embodiment of the present invention, the control platform can also be used to receive a first status feedback signal sent by the protection platform and output a second protection command based on the first status feedback signal. Specifically, in one embodiment of the present invention, the method of outputting a second protection command based on the first status feedback signal may include: acquiring the current operating signal of the measuring device, determining whether the gas turbine is in a safe and protected state based on the operating signal; if it is determined that the gas turbine is in a safe and protected state, no processing is required; if it is determined that the gas turbine is not in a safe and protected state, the control system outputs a second protection command based on the operating signal and sends the second protection command to the protection link through hardwiring or communication, and executes the second protection command using the corresponding execution unit in the protection link, thereby realizing a protection closed loop.
[0096] For example, in one embodiment of the present invention, assuming that the current actual speed signal of the acquisition and measurement device is collected, if the actual speed exceeds the trip limit and the protection link has not been disconnected, it indicates that the gas turbine is not in a safe and protected state; if the actual speed exceeds the trip limit and the protection link has been disconnected, it indicates that the gas turbine is in a safe and protected state.
[0097] In one embodiment of the present invention, the control platform can perform the above-mentioned anomaly judgment by setting a fast cycle processing module, so as to shorten the judgment time (e.g., 15ms) and thereby improve the responsiveness of the integrated hardware platform.
[0098] Furthermore, in one embodiment of the present invention, the aforementioned dedicated protection device can also be used to receive a third interlock signal sent by the protection platform, and can output a corresponding third dedicated protection control command based on the third interlock signal. The output third dedicated protection control command is then sent to the protection link via hardwiring or communication. The third dedicated protection control command is executed by the corresponding third execution unit in the protection link. The third interlock signal may include a first protection control command, and the first protection control command and the third dedicated protection control command may be the same, thereby preventing the execution unit corresponding to the protection platform from refusing to operate and ensuring the stable operation of the unit.
[0099] Furthermore, in one embodiment of the present invention, the protection action triggered by the protection platform through the first protection control command can achieve the protection function through the coordinated action of three automatic protection barriers: the control platform, the protection platform, and the dedicated protection device. This ensures that the failure of the execution unit corresponding to any two of them will not affect the execution of the protection action, thereby reducing the common mode risk and ensuring the stable operation of the unit.
[0100] Furthermore, in one embodiment of the present invention, the protection platform can also receive analog signals, thereby covering more control and protection needs, making the integrated hardware platform more adaptable and applicable to more situations, and improving its applicability.
[0101] In one embodiment of the present invention, after receiving a second protection request, the dedicated protection device can generate a corresponding first dedicated protection control command based on the second protection request, and send the first dedicated protection control command to the protection link through hard wiring or communication. The third execution unit in the protection link executes the first dedicated protection control command to perform the corresponding safety protection action (such as overspeed protection and surge protection), thereby realizing the protection of the gas turbine.
[0102] Furthermore, in one embodiment of the present invention, while the dedicated protection device outputs the first dedicated protection control command, the dedicated protection device can also send corresponding signals to the control platform and the protection platform to prevent the execution unit corresponding to the dedicated protection device from refusing to operate. Specifically, in one embodiment of the present invention, the dedicated protection device can also be used to: send a second status feedback signal to the control platform, and send a fourth interlock signal to the protection platform based on the first dedicated protection control command.
[0103] In one embodiment of the present invention, the control platform can also be used to receive a second status feedback signal sent by a dedicated protection device and output a third protection command based on the second status feedback signal. Specifically, in one embodiment of the present invention, the method of outputting a third protection command based on the second status feedback signal may include: acquiring the current operating signal of the measuring device, determining whether the gas turbine is in a safe and protected state based on the operating signal; if it is determined that the gas turbine is in a safe and protected state, no processing is required; if it is determined that the gas turbine is not in a safe and protected state, the control system outputs a third protection command based on the operating signal and sends the third protection command to the protection link through hardwiring or communication, and executes the third protection command using the corresponding first execution unit in the protection link, thereby realizing a protection closed loop.
[0104] Furthermore, in one embodiment of the present invention, the aforementioned protection platform can also be used to receive a fourth interlock signal sent by a dedicated protection device, and can output a corresponding third protection control command based on the fourth interlock signal. The output third protection control command is then sent to the protection link via hardwiring or communication. The third protection control command is executed by the corresponding second execution unit in the protection link. The fourth interlock signal may include a first dedicated protection control command, and the third protection control command may be the same as the first dedicated protection control command, thereby preventing the execution unit corresponding to the dedicated protection device from refusing to operate and ensuring the stable operation of the unit.
[0105] Furthermore, in one embodiment of the present invention, the safety protection action triggered by the dedicated protection device through the first dedicated protection control command can achieve the protection function through the coordinated action of three automatic protection barriers: the control platform, the protection platform, and the dedicated protection device. This ensures that the failure of the execution unit corresponding to any two of them will not affect the execution of the protection action, thereby reducing the common mode risk and ensuring the stable operation of the unit.
[0106] In one embodiment of the present invention, the above-mentioned heavy-duty gas turbine control and protection system may further include an emergency manual device, which is used to determine the operating status of the heavy-duty gas turbine and trigger gas turbine protection actions based on the obtained determination result.
[0107] In one embodiment of the present invention, the emergency manual device can adopt a pure hardware architecture and manually judge the operating status of the heavy-duty gas turbine. Based on the judgment result, the fourth execution unit in the protection link is directly triggered to perform safety protection actions for the gas turbine, so as to serve as the final protection barrier under extreme operating conditions.
[0108] Furthermore, in one embodiment of the present invention, while the emergency manual device triggers the protection link to perform a safety protection action, a fifth interlock signal can be output to the protection platform to prevent the emergency manual protection device actuator from refusing to operate.
[0109] Furthermore, in one embodiment of the present invention, the protection platform can also be used to receive the fifth interlock signal sent by the emergency manual device, and can output the corresponding fourth protection control command based on the fifth interlock signal, and send the output fourth protection control command to the protection link through hard wiring or communication, and use the corresponding second execution unit in the protection link to execute the fourth protection control command, thereby preventing the execution unit corresponding to the emergency manual device from refusing to operate and ensuring the stable operation of the unit.
[0110] In one embodiment of the present invention, the above-mentioned heavy-duty gas turbine control and protection system may further include an adjustment platform, which is used to determine a redundancy adjustment suggestion for the heavy-duty gas turbine control and protection system based on input requirements, including control requirements, first protection requirements, or second protection requirements.
[0111] In one embodiment of the present invention, the control platform, protection platform, dedicated protection device and emergency manual device in the heavy-duty gas turbine control and protection system can be used as each barrier to determine the reliability of the heavy-duty gas turbine control and protection system.
[0112] Specifically, in one embodiment of the present invention, the method for determining the redundancy adjustment recommendations of the heavy-duty gas turbine control and protection system based on input requirements may include the following steps:
[0113] Step 1: Identify the target barrier for processing input requirements, wherein the target barrier is at least one of the following: control platform, protection platform, dedicated protection device, and emergency manual device;
[0114] Step 2: Determine the first reliability of the input requirement based on the number of target barriers;
[0115] Step 3: Determine the second reliability of each barrier in the target barrier;
[0116] Step 4: Based on the first and second reliability levels, determine the third reliability level of the input requirements;
[0117] Step 5: Determine the redundancy adjustment recommendations for the heavy-duty gas turbine control and protection system based on the third reliability.
[0118] In one embodiment of the present invention, the target barriers corresponding to different input requirements may also be different. For example, assuming the input requirement is an overspeed protection requirement, the target barrier corresponding to this input requirement may be a control platform, a protection platform, or a dedicated protection device.
[0119] In one embodiment of the present invention, the target barrier for processing the input requirement can be determined by the relationship between the input requirement and the corresponding barrier.
[0120] In one embodiment of the present invention, after determining the target barriers for processing input requests, a first reliability of the input request can be determined based on the number of target barriers. In one embodiment of the present invention, the method for determining the first reliability of the input request based on the number of target barriers may include: determining the first reliability of the input request based on the number of target barriers using a first formula, wherein the first formula is:
[0121]
[0122] Where λ is the mean failure rate, which is a constant, such as 1.0e. -5 That is, the reciprocal of the mean time between failures τ; n is the number of barriers corresponding to the input requirement. For example, for overspeed protection requirements, parallel redundancy spans four barriers, so n is 4; t is time, in seconds (s); for the j-th input requirement, the above first reliability can be denoted as R0sysj.
[0123] In one embodiment of the present invention, each of the above barriers includes a corresponding input unit, a combination processing unit, and an output unit. The input unit may include actual sensors, other components, and wiring, but excludes those components that first combine signals through voting or other processing. The combination processing unit includes components that combine signals and all other components that transmit the final signal to the output unit. The output unit includes all components and wiring for processing the final signal from the processing unit, and also includes an execution unit in the protection link.
[0124] In one embodiment of the present invention, the input unit, the combination processing unit, and the output unit may include a redundant voting structure. Based on this, in one embodiment of the present invention, the method for determining the second reliability of each barrier in the target barrier may include the following steps:
[0125] Step 31: Determine the input reliability corresponding to the barrier;
[0126] Step 32: Determine the processing reliability corresponding to the barrier;
[0127] Step 33: Determine the output reliability corresponding to the barrier;
[0128] Step 34: Determine the second reliability of each barrier based on the input reliability, processing reliability, and output reliability.
[0129] In one embodiment of the present invention, the method for determining the input reliability corresponding to the barrier may include: determining the input reliability corresponding to the barrier using a second formula, wherein the second formula is:
[0130]
[0131]
[0132] Where r is the reliability of a single unit in the input unit, n is the number of barriers corresponding to the input requirement, and m is the redundant voting in the input unit, that is, the number of effective units required for normal operation in the redundant voting; for the j-th input requirement, the above input reliability can be denoted as Rsj.
[0133] In one embodiment of the present invention, the reliability of the aforementioned individual unit can refer to the probability that a product, system, service, or process will perform its intended function under specified conditions and within a specified time. Reliability is a core indicator for measuring quality and performance stability and is widely used in engineering, manufacturing, information technology, medical, and other fields.
[0134] For example, in one embodiment of the present invention, assuming m=2, it means that at least two units in the input unit need to output the same value for the result to be considered valid.
[0135] Furthermore, in one embodiment of the present invention, the processing reliability and output reliability corresponding to the barrier can be determined by the second formula described above. Specifically, when determining the processing reliability corresponding to the barrier using the second formula, m represents redundant voting in the processing unit, and for the j-th input requirement, the processing reliability can be denoted as Raj; when determining the output reliability corresponding to the barrier using the second formula, m represents redundant voting in the output unit, and for the j-th input requirement, the output reliability can be denoted as Rej.
[0136] Furthermore, in one embodiment of the present invention, after obtaining the input reliability, processing reliability, and output reliability through the above steps, the second reliability of the corresponding barrier can be determined by a third formula, wherein the third formula is:
[0137] =Rsj+ Raj+ Rej
[0138] in, This represents the second reliability of the z-th barrier in the j-th input requirement.
[0139] Furthermore, in one embodiment of the present invention, after obtaining the first reliability and the second reliability of each barrier through the above steps, a third reliability of the input requirement can be determined based on the first reliability and the second reliability. Specifically, in one embodiment of the present invention, the method for determining the third reliability of the input requirement based on the first reliability and the second reliability may include: determining the third reliability of the input requirement based on the first reliability and the second reliability using a fourth formula, wherein the fourth formula is:
[0140] Rfsysj= ×R0sysj
[0141] Where Rfsysj is the third reliability corresponding to the j-th input requirement.
[0142] Furthermore, in one embodiment of the present invention, after obtaining the third reliability of the input requirements through the above steps, a redundancy adjustment recommendation for the heavy-duty gas turbine control and protection system can be determined based on the third reliability.
[0143] Specifically, in one embodiment of the present invention, the method for determining the redundancy adjustment recommendations of the heavy-duty gas turbine control and protection system based on a third reliability may include the following steps:
[0144] Step 51: Based on the third level of reliability, determine whether redundancy needs to be adjusted;
[0145] Step 52: If it is determined that redundancy needs to be adjusted, then determine the redundancy adjustment recommendations for the heavy-duty gas turbine control and protection system.
[0146] In one embodiment of the present invention, the method for determining whether redundancy needs to be adjusted based on the third reliability may include: obtaining the target reliability threshold range corresponding to the input requirement; if the third reliability is within the target reliability threshold range, then it is determined that redundancy does not need to be adjusted; if the third reliability is outside the target reliability threshold range, then it is determined that redundancy needs to be adjusted.
[0147] Furthermore, in one embodiment of the present invention, if it is determined that redundancy adjustment is necessary, a redundancy adjustment recommendation for the heavy-duty gas turbine control and protection system can be determined. In another embodiment of the present invention, the redundancy adjustment recommendation for the heavy-duty gas turbine control and protection system can be determined based on experience.
[0148] Specifically, in one embodiment of the present invention, the redundancy adjustment suggestion for the above-mentioned heavy-duty gas turbine control and protection system may include at least one of the following:
[0149] Adjust the redundancy within a single barrier;
[0150] Adjust the hierarchy of parallel redundancy across barriers;
[0151] Decrease λ.
[0152] In one embodiment of the present invention, the aforementioned adjustment of the level of parallel redundancy across barriers can specifically be an adjustment of the number of barriers that process input requirements.
[0153] Furthermore, in one embodiment of the present invention, the aforementioned λ represents the average failure rate of the barrier, which can be a constant and is the reciprocal of the mean time between failures (MTBF) τ. In another embodiment of the present invention, the reduction of the average failure rate λ needs to be implemented throughout the entire process of "design-material selection-manufacturing-use-maintenance," by reducing failure sources (simplified design, high-quality materials) → reducing the probability of failure triggering (derating usage, environmental control) → mitigating the impact of failures (reliable design, maintenance strategies) → continuous iterative optimization (failure analysis).
[0154] In one embodiment of the present invention, through the above-described multi-barrier design, the control platform, protection platform, dedicated protection device, and emergency manual device creatively establish a collaborative working mechanism to achieve in-depth defense for gas turbine protection, greatly improving the reliability of gas turbine protection. Furthermore, by determining the redundancy adjustment recommendations for the heavy-duty gas turbine control and protection system through the above steps, the method of improving the barrier diagnostic coverage rate can further enhance the reliability of the system.
[0155] In one embodiment of the present invention, a unified and standardized system hierarchical architecture is established through the above-described system. This architecture clarifies the hierarchical relationships and data flows of modules such as the control platform, protection platform, dedicated protection devices, emergency manual devices, and tripping links, forming a reusable architecture template. This facilitates system expansion and maintenance, reduces the cost of adapting to new scenarios, and reduces the strong dependence of the control system design on specific hardware platforms. Simultaneously, both the control platform and protection platform adopt a hardware-software architecture, with the protection platform meeting SIL3 safety level requirements. Both the dedicated protection devices and emergency manual devices adopt a pure hardware architecture, with the dedicated protection devices also meeting SIL3 safety level requirements. Based on this, whether it's a hardware-software architecture or a pure hardware architecture, at least one set meets the SIL3 safety level, forming a multi-layered security and anti-common-mode scheme of hardware-software architecture, hardware-software architecture (SIL3), pure hardware architecture, and pure hardware architecture (SIL3). The modules interact and collaborate through interlocking signals and status feedback signals, forming an organic whole and achieving integrated defense-in-depth.
[0156] The heavy-duty gas turbine control and protection system proposed in this invention includes a control platform, a protection platform, a dedicated protection device, and a protection link. The control platform outputs control commands for the heavy-duty gas turbine based on its control requirements. The protection platform outputs a first protection control command for the heavy-duty gas turbine based on its first protection requirement. The dedicated protection device outputs a first dedicated protection control command for the heavy-duty gas turbine based on its second protection requirement. The protection link receives commands from the control platform and / or the protection platform and / or the dedicated protection device, and executes corresponding safety protection actions based on these commands. Therefore, this invention protects and controls the heavy-duty gas turbine collaboratively through the control platform, protection platform, and dedicated protection device. It is independent of hardware platforms, enables rapid migration, and ensures that a failure in one system does not affect the normal operation of the heavy-duty gas turbine control and protection system, reducing common-mode risk and demonstrating strong versatility.
[0157] To achieve the above embodiments, such as Figure 2 As shown, this embodiment also provides a heavy-duty gas turbine control and protection method, applied to a heavy-duty gas turbine control and protection system. The method includes the following steps:
[0158] Step 201: Based on the control requirements of the heavy-duty gas turbine, the control platform outputs control commands and / or first protection commands for the heavy-duty gas turbine.
[0159] Step 202: Based on the first protection requirements of the heavy-duty gas turbine, the protection platform outputs the first protection control command for the heavy-duty gas turbine, wherein the first protection requirements include overspeed protection requirements and normal cycle requirements.
[0160] Step 203: Based on the second protection requirements of the heavy-duty gas turbine, output the first dedicated protection control command for the heavy-duty gas turbine through the dedicated protection device. The second protection requirements include overspeed protection requirements and ultra-fast cycle requirements.
[0161] Step 204: Receive instructions sent by the control platform and / or protection platform and / or dedicated protection device through the protection link, and execute corresponding security protection actions based on the instructions.
[0162] For a detailed description of steps 201 to 204 above, please refer to the detailed description in the above embodiments. This disclosure will not repeat the details here.
[0163] In one embodiment of the present invention, the above method may include: determining redundancy adjustment recommendations for the heavy-duty gas turbine control and protection system based on input requirements by adjusting the platform.
[0164] The heavy-duty gas turbine control and protection method proposed in this invention includes: outputting control commands and / or first protection commands for the heavy-duty gas turbine based on the control requirements of the gas turbine via a control platform; outputting first protection control commands for the heavy-duty gas turbine based on the first protection requirements of the gas turbine via a protection platform, wherein the first protection requirements include overspeed protection requirements and normal cycle requirements; outputting first dedicated protection control commands for the heavy-duty gas turbine based on second protection requirements of the gas turbine via a dedicated protection device, wherein the second protection requirements include overspeed protection requirements and ultra-fast cycle requirements; and receiving commands sent by the control platform and / or the protection platform and / or the dedicated protection device via a protection link, and executing corresponding safety protection actions based on the commands. Therefore, this invention protects and controls the heavy-duty gas turbine collaboratively through the control platform, protection platform, and dedicated protection device, without relying on a hardware platform, achieving rapid migration, and ensuring that the normal operation of the heavy-duty gas turbine control and protection system is not affected when a certain system fails, reducing common-mode risk and demonstrating strong versatility.
[0165] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this disclosure can be achieved, and this is not limited herein.
[0166] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A heavy-duty gas turbine control and protection system, characterized in that, The system includes a control platform, a protection platform, dedicated protection devices, and protection links; The control platform is used to output control commands and / or first protection commands for the heavy-duty gas turbine based on the control requirements of the heavy-duty gas turbine. The protection platform is used to output a first protection control command for the heavy-duty gas turbine based on a first protection requirement of the heavy-duty gas turbine, wherein the first protection requirement includes an overspeed protection requirement and a normal cycle requirement. The dedicated protection device is used to output a first dedicated protection control command for the heavy-duty gas turbine based on the second protection requirement of the heavy-duty gas turbine, wherein the second protection requirement includes the overspeed protection requirement and the ultra-fast cycle requirement; The protection link is used to receive instructions sent by the control platform and / or the protection platform and / or the dedicated protection device, and to execute corresponding security protection actions based on the instructions.
2. The system according to claim 1, characterized in that, The control requirements include a first control requirement and a second control requirement; the control platform includes a slow-cycle processing module and a fast-cycle processing module. The slow-cycle processing module is used to process the first control requirement. The fast-cycle processing module is used to process the second control requirement.
3. The system according to claim 1, characterized in that, The system also includes an actuator connected to the control platform; The actuator is used to execute corresponding control actions based on the control instructions.
4. The system according to claim 1, characterized in that, The control platform is also used for: Based on the first protection instruction, a first interlock signal is sent to the protection platform; Based on the first protection command, a second interlock signal is sent to the dedicated protection device; and / or Receive the first status feedback signal sent by the protection platform, and output the second protection command based on the first status feedback signal; It receives the second status feedback signal sent by the dedicated protection device and outputs a third protection command based on the second status feedback signal.
5. The system according to claim 4, characterized in that, The protection platform is also used for: Send the first status feedback signal to the control platform; Based on the first protection control command, a third interlock signal is sent to the dedicated protection device; and / or Receive the first interlock signal sent by the control platform, and output a second protection control command based on the first interlock signal; It receives the fourth interlock signal sent by the dedicated protection device and outputs the third protection control command based on the fourth interlock signal.
6. The system according to claim 5, characterized in that, The dedicated protection device is also used for: Send the second status feedback signal to the control platform; Based on the first dedicated protection control command, the fourth interlock signal is sent to the protection platform; and / or Receive the second interlock signal sent by the control platform, and output a second dedicated protection control command based on the second interlock signal; The system receives the third interlock signal sent by the protection platform and outputs a third dedicated protection control command based on the third interlock signal.
7. The system according to claim 1, characterized in that, The system also includes an emergency manual device, which is used to determine the operating status of the heavy-duty gas turbine and trigger the gas turbine protection action based on the determination result.
8. The system according to claim 7, characterized in that, The system also includes an adjustment platform, which is used to determine redundancy adjustment suggestions for the heavy-duty gas turbine control and protection system based on input requirements, including the control requirements, the first protection requirements, or the second protection requirements.
9. The system according to claim 8, characterized in that, The redundancy adjustment recommendations for the heavy-duty gas turbine control and protection system based on input requirements include: Identify a target barrier for processing the input request, wherein the target barrier is at least one of the control platform, the protection platform, the dedicated protection device, and the emergency manual device; Based on the number of the target barriers, a first reliability of the input requirement is determined; Determine the second reliability of each barrier in the target barrier; Based on the first reliability and the second reliability, a third reliability of the input requirement is determined; Based on the third reliability, a redundancy adjustment recommendation for the heavy-duty gas turbine control and protection system is determined.
10. The system according to claim 9, characterized in that, Determining the second reliability of each barrier in the target barrier includes: Determine the input reliability corresponding to the barrier; Determine the processing reliability corresponding to the barrier; Determine the output reliability corresponding to the barrier; Based on the input reliability, the processing reliability, and the output reliability, a second reliability of each barrier is determined.
11. The system according to claim 9, characterized in that, The redundancy adjustment recommendations for the heavy-duty gas turbine control and protection system based on the third reliability include: Based on the aforementioned third reliability, determine whether redundancy needs to be adjusted; If it is determined that redundancy adjustment is necessary, then a redundancy adjustment recommendation for the heavy-duty gas turbine control and protection system is determined.
12. The system according to claim 1, characterized in that, The protection link includes a first execution unit, a second execution unit, and a third execution unit, wherein, The first execution unit is configured to receive the first protection instruction sent by the control platform and execute the corresponding security protection action based on the first protection instruction; The second execution unit is used to receive the first protection control command sent by the protection platform, and to execute the corresponding security protection action based on the first protection control command; The third execution unit is used to receive the first dedicated protection control command sent by the dedicated protection device, and to execute the corresponding safety protection action based on the first dedicated protection control command.
13. A method for controlling and protecting a heavy-duty gas turbine, characterized in that, The method, applied to the control and protection system of heavy-duty gas turbines, includes: Based on the control requirements of the heavy-duty gas turbine, the control platform outputs control commands and / or first protection commands for the heavy-duty gas turbine. Based on the first protection requirement of the heavy-duty gas turbine, the protection platform outputs the first protection control command of the heavy-duty gas turbine, wherein the first protection requirement includes overspeed protection requirement and normal cycle requirement; Based on the second protection requirement of the heavy-duty gas turbine, a first dedicated protection control command for the heavy-duty gas turbine is output through a dedicated protection device, wherein the second protection requirement includes the overspeed protection requirement and the ultra-fast cycle requirement; The system receives instructions from the control platform and / or the protection platform and / or the dedicated protection device via the protection link, and performs corresponding security protection actions based on the instructions.
Citation Information
Patent Citations
Heavy-duty gas turbine control method, device and equipment and storage medium
CN113719358A
Heavy-duty gas turbine safety protection monitoring method and device fused with fuzzy evaluation
CN120725469A