A substation secondary system communication network reliability analysis method
By combining the top-level fault tree model with the partitioned subtree model, the problem of multi-partition cross-regional coupling relationship in the communication network of an independently controllable substation was solved, enabling accurate identification and reliability assessment of key weak links and providing a scientific basis for network optimization design.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-16
- Publication Date
- 2026-04-17
AI Technical Summary
Existing methods for analyzing the reliability of substation communication networks are not adequately adapted to the multi-security zone and cross-regional coupling relationships of independently controllable substations. They cannot accurately describe the fault propagation modes of dual-network redundancy switching and equipment dual backup, resulting in significant deviations in assessment results and making it difficult to identify key weak links.
By combining a top-level fault tree model with a partitioned subtree model, network failure events are constructed through logical OR gate relationships. These events are then standardized using engineering statistical data to calculate the overall availability of the system and identify key weak links.
It achieves precise mapping of multi-zone nesting and cross-zone fault propagation in independently controllable substations, ensuring data consistency and calculation accuracy, and providing a scientific basis for network optimization design.
Smart Images

Figure CN121357050B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of substations, and in particular to a method for reliability analysis of communication networks in substation secondary systems. Background Technology
[0002] As the power system undergoes a profound transformation towards digitalization, informatization, and intelligence, substations, as the core hubs of power grid dispatch and operation, rely heavily on the real-time performance, security, and reliability of their communication networks to ensure stable power grid operation. Against this backdrop, domestically developed and controllable substations, leveraging their core advantages of localized key equipment, independent software and hardware platforms, and secure network systems, have become the core foundational units for the construction of new power systems and are widely used in various power engineering scenarios. These substations employ advanced technical architectures such as security zoning, layered isolation, dual-network redundancy, equipment duplication, and separation of primary and secondary services, significantly improving the system's fault tolerance and security isolation levels. However, this also leads to complex network structures with multi-zone nesting, tightly coupled equipment logic, and extended cross-zone fault propagation chains, placing higher demands on the reliability analysis of communication networks.
[0003] Existing reliability analysis methods for substation communication networks mostly focus on traditional substations or conventional smart substations based on the IEC 61850 standard. Their research objects are largely limited to communication links at the single bay and process layers, and their evaluation methods emphasize single network topology modeling or critical link failure analysis, failing to fully adapt to the core characteristics of domestically controlled substations. Specifically, existing methods do not systematically model the cross-zone coupling relationships of multiple security zones, and cannot accurately describe fault propagation modes in scenarios of dual-network redundancy switching and dual equipment backup. Furthermore, they lack a unified standard for defining bottom-level events, and their parameter acquisition and quantitative calculation systems are incomplete, leading to significant deviations in reliability assessment results. This makes it difficult to identify key weak points in the communication networks of domestically controlled substations, and fails to provide a scientific basis for network optimization design and operation and maintenance enhancement.
[0004] Therefore, existing technologies still need improvement and development. Summary of the Invention
[0005] The purpose of this invention is to provide a reliability analysis method for the communication network of a substation secondary system. This method aims to solve the technical problem that the analysis method does not systematically model the cross-regional coupling relationship of multiple safety zones, making it difficult to accurately describe the fault propagation mode of dual-network redundancy switching and equipment dual backup.
[0006] To achieve the above objectives, the solution provided by the present invention is as follows:
[0007] A method for reliability analysis of a substation secondary system communication network includes: taking the overall failure of the substation communication network as the top event, and based on the safety partitioning architecture of an independently controllable substation, decomposing the direct cause of the top event into multiple intermediate events, and constructing a top-level fault tree model between the top event and the multiple intermediate events using logical OR gates; recursively expanding each intermediate event hierarchically to form an initial subtree model, and combining the dual-network redundancy and equipment dual configuration characteristics of the independently controllable substation, equating the redundancy mechanism to the logical structure corresponding to the fault tree, and supplementing it into the initial subtree model to obtain a partitioned subtree model; extracting equipment-level faults as bottom events from the partitioned subtree model, and standardizing all extracted bottom events to obtain multiple standardized bottom events; obtaining engineering statistical data, determining the failure rate and repair rate of each standardized bottom event based on the engineering statistical data, and calculating the unavailability of each standardized bottom event based on the failure rate and repair rate of each standardized bottom event; and performing probability calculations from bottom to top based on the unavailability of the standardized bottom events, the partitioned subtree model, and the top-level fault tree model to obtain the overall system availability.
[0008] Preferably, the step of taking the overall failure of the substation communication network as the top event, decomposing the direct cause of the top event into multiple intermediate events based on the safety partitioning architecture of the autonomous and controllable substation, and constructing a top-level fault tree model between the top event and the multiple intermediate events using logical OR gates, includes: obtaining the safety partitioning architecture of the autonomous and controllable substation, which includes safety zone I, safety zone II, and safety zone III; taking the overall failure of the substation communication network as the top event, decomposing the direct cause of the top event into multiple intermediate events based on the safety zone I, the safety zone II, and the safety zone III; and constructing a top-level fault tree model between the top event and the multiple intermediate events using logical OR gates.
[0009] Preferably, the intermediate events include network failure events in Security Zone I, Security Zone II, Security Zone III, firewall failure events, forward and reverse isolation device failure events, integrated power system failure events, and time synchronization system failure events.
[0010] Preferably, the step of recursively expanding each intermediate event hierarchically to form an initial subtree model, and combining the dual-network redundancy and equipment dualization configuration characteristics of the autonomous and controllable substation, equates the redundancy mechanism to the logical structure corresponding to the fault tree, and supplements it into the initial subtree model to obtain a partitioned subtree model, including: recursively decomposing each intermediate event from top to bottom according to the expansion dimensions of intermediate events, subsystem levels, and equipment to form an initial subtree model; for the redundant objects of dual-network redundancy and equipment dualization in the initial subtree, according to the rule that all redundant units fail simultaneously, it is equivalent to the AND gate logic structure of the fault tree; the equivalent AND gate logic structure is embedded into the initial subtree model according to the redundancy action hierarchy to obtain the partitioned subtree model.
[0011] Preferably, the step of extracting device-level faults as base events from the partitioned subtree model and standardizing all extracted base events to obtain multiple standardized base events includes: extracting all device-level faults as base events from the lowest level node of the partitioned subtree model; and standardizing all extracted base events from three dimensions: fault type definition, coding rules, and parameter dimensions to obtain multiple standardized base events.
[0012] Preferably, the standardization process for all extracted base events from three dimensions—fault type definition, coding rules, and parameter dimensions—results in multiple standardized base events. This includes: classifying each base event into one of three categories based on the common characteristics of communication equipment faults: equipment hardware failure, communication link interruption, and functional interface anomaly; encoding each classified base event using a coding structure of security zone, level, equipment type, fault type, and sequence number to obtain coded base events; and unifying the failure rate and repair rate statistics of each coded base event to obtain multiple standardized base events.
[0013] Preferably, the step of acquiring engineering statistical data, determining the failure rate and repair rate of each standardized baseline event based on the engineering statistical data, and calculating the unavailability of each standardized baseline event based on the failure rate and repair rate of each standardized baseline event, includes: acquiring engineering statistical data, wherein the engineering statistical data is derived from equipment operation logs, fault maintenance records, equipment factory inspection reports, and power industry equipment reliability standard data of the autonomous and controllable substation; performing data cleaning and normalization on the engineering statistical data to obtain processed engineering statistical data; calculating the failure rate and repair rate of each standardized baseline event using a weighted average method based on the processed engineering statistical data; and calculating the unavailability of each standardized baseline event based on the failure rate and repair rate of each standardized baseline event.
[0014] Preferably, the unavailability of the standardized bottom event is defined as follows: ,but Represented as:
[0015]
[0016] In the formula, To standardize the failure rate of the bottom event. This represents the repair rate of standardized bottom events.
[0017] Preferably, the method of calculating the overall system availability from bottom to top based on the unavailability of the standardized base events, the partitioned subtree model, and the top-level fault tree model includes: calculating the availability of each standardized base event based on the unavailability of each standardized base event; aggregating upwards along the partitioned subtree model to calculate the availability of each intermediate event in the top-level fault tree model; and calculating the overall system availability based on the product of the availability of each intermediate event.
[0018] Preferably, the unavailability based on standardized bottom events, the partitioned subtree model, and the top-level fault tree model are used to perform probability calculations from bottom to top to obtain the overall system availability. This further includes: generating multiple minimum cut sets, where each minimum cut set is a set of the minimum number of bottom events that cause a top event to occur, and each minimum cut set represents a system failure mode; calculating the occurrence probability of each minimum cut set using the top-level fault tree model and the partitioned subtree model, employing a downlink or uplink method; selecting the minimum cut set with the highest occurrence probability, and identifying the equipment or communication link corresponding to the bottom events included in the minimum cut set with the highest occurrence probability as a key weak link in the substation secondary system communication network.
[0019] This solution employs a hierarchical design that combines top-level fault tree modeling with embedded redundant logic in partitioned subtrees. This effectively maps complex architectures such as multi-partition nesting and cross-regional fault propagation in autonomous and controllable substations. Furthermore, it precisely quantifies the fault tolerance of dual-network redundancy and dual-configuration of equipment using AND gate logic. Simultaneously, it uses engineering statistical data as the core driver to determine bottom-event parameters, and standardization further ensures data consistency and calculation accuracy. Finally, through bottom-up, full-level probability calculations, a complete quantitative evaluation system from the equipment level to the system level is constructed. This system not only accurately outputs the overall availability of the substation's secondary system communication network but also provides a scientific and practical decision-making basis for network optimization design and strengthening of key weak links. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the structures shown in these drawings without creative effort.
[0021] Figure 1 This is a flowchart of the substation secondary system communication network reliability analysis method provided in the embodiments of the present invention;
[0022] Figure 2 This is a schematic diagram of the 220kV line bay network configuration provided in an embodiment of the present invention. Detailed Implementation
[0023] The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" or "having" and any variations thereof are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] For ease of understanding, the specific process of the embodiments of the present invention is described below. Please refer to [link / reference]. Figure 1 In this embodiment of the invention, a method for reliability analysis of a substation secondary system communication network includes:
[0025] S101. Taking the overall failure of the substation communication network as the top event, based on the safety partitioning architecture of the autonomous and controllable substation, the direct cause of the top event is decomposed into multiple intermediate events, and a top-level fault tree model between the top event and multiple intermediate events is constructed using logical OR gate relationships.
[0026] S102. For each intermediate event, expand the hierarchy recursively to form an initial subtree model. Combine the dual-network redundancy and dual-configuration characteristics of the autonomous and controllable substation, and convert the redundancy mechanism into the logical structure corresponding to the fault tree, and add it to the initial subtree model to obtain the partitioned subtree model.
[0027] S103. Extract device-level faults as base events from the partitioned subtree model, and standardize all extracted base events to obtain multiple standardized base events.
[0028] S104. Obtain engineering statistics data, determine the failure rate and repair rate of each standardized base event based on the engineering statistics data, and calculate the unavailability of each standardized base event based on the failure rate and repair rate of each standardized base event.
[0029] S105. Based on the unavailability of standardized bottom events, the partitioned subtree model, and the top-level fault tree model, probability calculations are performed from bottom to top to obtain the overall system availability.
[0030] In this embodiment, through the hierarchical design of top-level fault tree modeling and partitioned subtree redundancy logic embedding, it effectively achieves accurate mapping of complex architectures such as multi-partition nesting and cross-regional fault propagation in autonomous and controllable substations. It also accurately quantifies the fault resistance effect of dual-network redundancy and equipment dualization configuration with the help of AND gate logic. At the same time, it uses engineering statistical data as the core driver to determine bottom event parameters, and combines standardized processing to further ensure data consistency and calculation accuracy. Finally, through bottom-up full-level probability calculation, a complete quantitative evaluation system from the equipment level to the system level is constructed. This system can not only accurately output the overall availability of the substation secondary system communication network, but also provide scientific and feasible decision-making basis for network optimization design and strengthening of key weak links.
[0031] In this embodiment, step S101, taking the overall failure of the substation communication network as the top event, and based on the safety partitioning architecture of the autonomous and controllable substation, decomposes the direct cause of the top event into multiple intermediate events, and constructs a top-level fault tree model between the top event and the multiple intermediate events using logical OR gate relationships. This includes: obtaining the safety partitioning architecture of the autonomous and controllable substation, which includes safety zone I, safety zone II, and safety zone III; taking the overall failure of the substation communication network as the top event, and based on safety zone I, safety zone II, and safety zone III, decomposing the direct cause of the top event into multiple intermediate events; and constructing a top-level fault tree model between the top event and the multiple intermediate events using logical OR gate relationships.
[0032] In this embodiment, the direct causes of the top event are divided into the following three categories.
[0033] Category 1: Partition network failure events refer to network failures within a partition that handles communication functions, including failures of all redundant communication links or critical switching equipment within the partition. Specifically, this includes network failure events in Security Zone I, Security Zone II, and Security Zone III.
[0034] The second category is: Inter-section isolation device failure events, which refer to communication disruptions or network security incidents between sections, thereby affecting the overall communication reliability of the station. These include firewall failures and forward / reverse isolation device failures, specifically firewall failure events and forward / reverse isolation device failure events.
[0035] The third category: Support system failure events. The reliable operation of a communication network depends on a stable power supply and unified time synchronization. If a failure occurs, causing communication equipment to lose power or devices to lose unified time, it will significantly affect network availability. Specifically, this includes integrated power system failure events and time synchronization system failure events.
[0036] Therefore, the intermediate events include network failure events in Security Zone I, Security Zone II, Security Zone III, firewall failure events, forward and reverse isolation device failure events, integrated power system failure events, and time synchronization system failure events.
[0037] The intermediate events mentioned above are logically related by an "OR" relationship due to the partitioning and isolation strategy. That is, the occurrence of any one of these events will trigger the top event of a complete communication network failure. Therefore, at the top level of the fault tree model, the top event can be described by connecting the intermediate events with an OR gate, thus defining the overall communication network failure event T.
[0038]
[0039] In the formula, These represent network failure events in Security Zone I, Security Zone II, and Security Zone III, respectively. These represent firewall failure events, forward and reverse isolation device failure events, integrated power system failure events, and time synchronization system failure events, respectively.
[0040] In this embodiment, in step S102, each intermediate event is recursively expanded hierarchically to form an initial subtree model. Combining the dual-network redundancy and dual-configuration characteristics of the autonomous and controllable substation, the redundancy mechanism is equivalent to the logical structure corresponding to the fault tree and added to the initial subtree model to obtain a partitioned subtree model. Specifically, this includes: recursively decomposing each intermediate event from top to bottom according to the expansion dimensions of intermediate events, subsystem levels, and equipment to form an initial subtree model; for the redundant objects of dual-network redundancy and dual-configuration equipment in the initial subtree, according to the rule that failure only occurs when all redundant units fail simultaneously, it is equivalent to the AND gate logic structure of the fault tree; the equivalent AND gate logic structure is embedded into the initial subtree model according to the redundancy action hierarchy to obtain the partitioned subtree model.
[0041] In this embodiment, combining the dual-network redundancy and equipment dualization configuration of the autonomous and controllable substation, the redundancy mechanism is equivalent to a fault tree logic structure. For example, dual-network redundancy (network I and network II) is modeled as a logical AND gate, indicating that the partitioned network only fails when both networks fail simultaneously; equipment dualization configuration (set A and set B) is modeled as a logical OR gate, indicating that the failure of any set of equipment will lead to functional failure.
[0042] In this embodiment, in step S103, device-level faults are extracted from the partitioned subtree model as base events, and all extracted base events are standardized to obtain multiple standardized base events. Specifically, this includes: extracting all device-level faults from the lowest level node of the partitioned subtree model as base events; and standardizing all extracted base events from three dimensions: fault type definition, encoding rules, and parameter dimensions to obtain multiple standardized base events.
[0043] In this embodiment, taking Security Zone I as an example, it realizes the monitoring, operation, protection, and control of the main equipment, and deploys a main and auxiliary integrated monitoring host, intelligent anti-misoperation host, real-time gateway, measurement and control device, acquisition and execution unit, clock system, etc. Device-level faults are extracted from the partition subtree model as base events (such as switch faults, acquisition unit faults) and standardized (unified naming, normalized failure rate).
[0044] Furthermore, all extracted baseline events are standardized from three dimensions: fault type definition, coding rules, and parameter dimensions, resulting in multiple standardized baseline events. These include: classifying the fault types of each baseline event into one of three categories based on the common characteristics of communication equipment faults: equipment hardware failure, communication link interruption, and functional interface anomaly; encoding each classified baseline event using a coding structure of security zone, level, equipment type, fault type, and sequence number to obtain coded baseline events; and unifying the failure rate and repair rate statistical dimensions of each coded baseline event to obtain multiple standardized baseline events.
[0045] In this embodiment, step S104 involves obtaining engineering statistical data, determining the failure rate and repair rate of each standardized baseline event based on the engineering statistical data, and calculating the unavailability of the standardized baseline events based on the failure rate and repair rate of the standardized baseline events. This includes: obtaining engineering statistical data, which is derived from equipment operation logs, fault maintenance records, equipment factory inspection reports, and power industry equipment reliability standard data of the autonomous and controllable substation; performing data cleaning and normalization on the engineering statistical data to obtain processed engineering statistical data; calculating the failure rate and repair rate of each standardized baseline event using a weighted average method based on the processed engineering statistical data; and calculating the unavailability of each standardized baseline event based on the failure rate and repair rate of each standardized baseline event.
[0046] Define the unavailability of the standardized bottom event as ,but Represented as:
[0047]
[0048] In the formula, This is the failure rate of the standard base event (the probability of a failure occurring per unit time). This represents the repair rate of standardized bottom events.
[0049] In this embodiment, in step S105, based on the unavailability of standardized bottom events, the partitioned subtree model, and the top-level fault tree model, probability calculations are performed from bottom to top to obtain the overall system availability, including:
[0050] The availability of each standardized base event is calculated based on its unavailability; the availability of each intermediate event in the top-level fault tree model is calculated by aggregating upwards along the partitioned subtree model; and the overall system availability is calculated based on the product of the availability of each intermediate event.
[0051] In this embodiment, starting from the bottom layer (bottom event) of the partitioned subtree model, probability calculations are performed strictly according to the logic gates (AND gates, OR gates) defined in the partitioned subtree, aggregating upwards layer by layer. For an OR gate (serialized system), the availability of the gate's output event (parent event) is equal to the product of the availability of all input events (child events). For a system consisting of multiple components connected in series to function properly, all components must function properly simultaneously. For example, the availability of a communication path (acquisition unit → switch → protection device) is the product of the availability of all devices along the path.
[0052] For an AND gate (parallel / redundant system), the unavailability of the gate's output event (parent event) is equal to the product of the unavailability of all input events (child events). Its availability is calculated using complementary methods. For a redundant system (such as a dual-network system) to fail, all redundant units (network I and network II) must fail simultaneously. Therefore, the system availability is 1 minus the probability of all units failing simultaneously.
[0053] Based on the cascading characteristics of OR gates, for the entire communication network system to function properly, the subsystem represented by each intermediate event must also function properly (i.e., security zone I is functioning properly, security zone II is functioning properly, and the firewall is functioning properly, etc.). Therefore, the overall system availability is equal to the product of the availability of all intermediate subsystems.
[0054] In this embodiment, based on the unavailability of standardized bottom events, the partitioned subtree model, and the top-level fault tree model, probability calculations are performed from bottom to top to obtain the overall system availability. The process then includes: generating multiple minimum cut sets, where each minimum cut set is the set of the minimum number of bottom events that cause the top event to occur, and each minimum cut set represents a system failure mode; calculating the occurrence probability of each minimum cut set using the top-level fault tree model and the partitioned subtree model, employing either a downlink or uplink method; selecting the minimum cut set with the highest occurrence probability, and identifying the equipment or communication link corresponding to the bottom events included in the minimum cut set with the highest occurrence probability as a key weak link in the substation secondary system communication network.
[0055] These devices can be included in the key inspection list, their condition can be monitored more closely, and sufficient spare parts can be stockpiled.
[0056] In this embodiment, a 220kV line bay of a smart substation is selected as a typical modeling object to systematically construct its communication function fault path model. The communication system of this bay adopts a dual configuration, operating in network I and network II respectively through communication links A and B, forming a logically independent and physically isolated dual-path structure. Based on the equipment topology, network switching structure, and functional redundancy configuration of the communication system, a schematic diagram of the communication network structure of this bay can be established, as detailed in [link to diagram]. Figure 2 Structurally, the A / B set of acquisition and execution units respectively undertake data acquisition and action control functions. The acquired data is uploaded to the line protection device (A / B set) and the single-set multi-functional measurement and control unit. The communication link is deployed in a layered manner through the station control layer switches, bay isolation switches, and central switching equipment of the I and II networks to achieve reliable information transmission and aggregation processing. Due to differences in equipment configuration and network layering strategies, the transmission paths of different communication services under the I / II network are significantly different. Specifically, the combination of switching nodes traversed between source and destination node pairs is different, resulting in asymmetry in the network link dependency and failure impact path.
[0057] Table 1 lists the complete transmission path information of various typical communication flows under different network conditions, including key links such as the acquisition and execution unit to the protection device, the protection device to the switch, and GOOSE communication between switches.
[0058] Table 1 Network transmission paths under different device communication conditions
[0059]
[0060] The top event T is defined as "the overall failure of the secondary system communication network of a 220kV line bay in a certain autonomous and controllable substation". The system boundary covers the communication equipment in Safety Zone I, the associated equipment in Safety Zone II / III, the boundary isolation devices (firewalls, forward and reverse isolation), and the supporting systems (integrated power supply, time synchronization) involved in the line bay. Based on the safety zoning architecture of the substation, the direct cause of the top event T is decomposed into 7 types of intermediate events, as follows:
[0061] E1: Network fault in Safety Zone I (core communication area of 220kV line bay, responsible for protection control and real-time data transmission);
[0062] E2: Security Zone II network failure (non-real-time monitoring zone, data transmission of associated line interval status monitoring).
[0063] E3: Security Zone III network failure (management information zone, related interval device operation and maintenance data transmission);
[0064] E4: Firewall failure (border communication device between Security Zone I and Security Zone II).
[0065] E5: Failure of forward and reverse isolation device (boundary isolation device between safety zone II and zone III);
[0066] E6: Integrated power system failure (provides DC power to all communication devices);
[0067] E7: Time synchronization system failure (provides a unified time base for the device to ensure the consistency of data transmission timing).
[0068] Taking intermediate event E1 (security zone I network failure event) as an example, this paper elaborates on the construction of the partition subtree model and the process of embedding redundant logic (other intermediate events are explained in the same way).
[0069] First, construct the initial subtree model by recursively expanding E1 according to the dimensions of intermediate events-network layers-devices to form the initial subtree.
[0070] Network splitting: E1→I network overall failure (E11), II network overall failure (E12) (the two networks are physically isolated, and will be discussed separately);
[0071] Hierarchical breakdown: E11 → I-network station control layer fault (E111), I-network bay layer fault (E112), I-network process layer fault (E113) (corresponding to the hierarchical architecture of "station control layer - bay layer - process layer" of an independently controllable substation);
[0072] Equipment cluster splitting: E112 → I network A set of bay layer equipment failure (E1121), I network B set of bay layer equipment failure (E1122) (equipment dual configuration);
[0073] Equipment breakdown: E1121 → DA fault (X1, A set of acquisition and execution unit), PA fault (X3, A set of protection device), SWA1 fault (X6, I network A set of station control layer switch), ISW1 fault (X8, I network bay layer isolation switch), CSW1 fault (X9, I network central switch).
[0074] The initial subtree model contains only device-level nodes and has no redundant logic.
[0075] Next, combining the dual-network redundancy and device dualization characteristics, the redundancy mechanism is equivalent to AND gate logic and embedded into the initial subtree model to obtain the partitioned subtree model.
[0076] Dualization of equipment and embedding of gates: Add an AND gate under E112 (I network interval layer failure) to connect E1121 (I network A set failure) and E1122 (I network B set failure), that is, E112=E1121∧E1122. The I network interval layer only fails when both A set and B set fail simultaneously.
[0077] Dual-network redundancy AND gate embedding: Add an AND gate under E1 (security zone I network failure) to connect E11 (overall failure of I network) and E12 (overall failure of II network), that is, E1=E11∧E12. The security zone I network will only fail when both I network and II network fail simultaneously.
[0078] Logical labeling: Label the redundancy type next to the AND gate, such as equipment duplication (set A / B) or dual network redundancy (set I / II). Label the network and set to which the device node belongs next to it, such as X1: Set A, Set I, acquisition and execution unit.
[0079] In this embodiment, for example, the partitioned subtree model extracts device-level faults as bottom events, totaling 12 items. The core bottom events include:
[0080] X1: DA fault (I network A set of acquisition and execution unit);
[0081] X2: DB failure (I network B set acquisition execution unit);
[0082] X3: PA fault (I network A set protection device);
[0083] X4: PB fault (I network B set protection device);
[0084] X6: SWA1 fault (I network A set station control layer switch);
[0085] X7: SWB1 fault (I network B set station control layer switch);
[0086] X9: CSW1 fault (I-Network Center Switch);
[0087] X10: CSW2 fault (II network center switch).
[0088] In this embodiment, a coding structure of security zone, level, device type, fault type, and sequence number is used to encode each categorized basic event. For example, X1 is coded as I-process layer-acquisition execution unit-HW-01, X6 is coded as I-station control layer-switch-LN-01, and X9 is coded as I-station control layer-central switch-HW-01.
[0089] In this embodiment, the failure rate is measured in units of 1 / year, and the repair rate is measured in units of 1 / day. For example, the standardized baseline event parameters are shown in Table 2.
[0090] Table 2 Standardized Base Event Parameters
[0091]
[0092] In this embodiment, the equipment operation log (2021-2023), fault repair records (12 valid fault data records), equipment factory inspection report (λ reference value provided by a domestic manufacturer), and industry standard data in the "DL / T544-2012 Power Communication Operation Management Regulations" of the substation are obtained. After the data is denoised (one data record of human error is removed) and normalized, the weighted average method is used to calculate the λ and μ of the standardized base event (equipment operation data weight 0.6, industry standard data weight 0.4).
[0093] Taking the standard base event X1 (DA) as an example: , Then the unavailability of the standard bottom event X1 Represented as:
[0094]
[0095] The unavailability calculation results for other core bottom events are shown in Table 3.
[0096] Table 3. Unavailability of other core bottom events
[0097]
[0098] In this embodiment, the overall system availability is calculated using a bottom-up hierarchical aggregation method, combined with the logical relationships (series / parallel) of the partitioned subtree model.
[0099] For example, device-level → link-level availability
[0100] The I-network A-set interval layer links (DA→PA→SWA1→ISW1→CSW1) are in series logic, and the availability is the product of the availability of each device.
[0101] A I-A链路 =A1×A3×A6×A8×A9≈0.99966
[0102] Similarly, the availability of I network B set links A I-B链路 ≈0.99968.
[0103] Link-level availability → Network-level availability
[0104] The I-network interval layer consists of A / B sets of parallel logic (AND gates correspond to parallel availability).
[0105] A I-间隔层 =1-(1-A I-A链路)×(1-A I-B链路 )≈0.999999884
[0106] Similarly, the overall availability of the I-network A I网 ≈0.99999988, Overall availability of II network A II网 ≈0.99999987; Availability A of Security Zone I Network (I / II Network in Parallel) E1 =1-(1-A I网 )×(1-A II网 )≈0.9999999997.
[0107] The availability calculation results for other intermediate events are as follows:
[0108] A E2 ≈0.9999999995 (Safety Zone II), A E3 ≈0.9999999996 (Safety Zone III), A E4 ≈0.9999999999 (firewall), A E5 ≈0.9999999998 (forward and reverse isolation), A E6 ≈0.99999999 (integrated power supply), A E7 ≈0.99999999 (time synchronization).
[0109] Based on the OR gate logic of the top-level fault tree model, the overall system availability is:
[0110] A 总 =1-(1-A E1 )×(1-A E2 )×(1-A E3 )×(1-A E4 )×(1-A E5 )×(1-A E6 )×(1-A E7 A was calculated. 总 ≈0.9999995.
[0111] In this embodiment, for the identification of key weak links, a downlink method is used to solve the top-level fault tree model and the partitioned subtree model, generating the core minimum cut set as follows:
[0112] C1: {X9} (I-Network Center Switch CSW1 Fault);
[0113] C2: {X10} (II network center switch CSW2 failure);
[0114] C3: {X6,X7} (Simultaneous failure of I network A set / SWB1 set station control layer switches);
[0115] C4: {E6} (Integrated power system failure).
[0116] Next, the occurrence probability of each minimal cut set is calculated based on the unavailability of the normalized base event.
[0117] P(C1) = Q9 ≈ 0.000044;
[0118] P(C2) = Q10 ≈ 0.000045;
[0119] P(C3)=Q6×Q7≈0.000055×0.000056≈3.08×10 -9 ;
[0120] P(C4)=QE6≈0.00000001.
[0121] Based on the above calculation results, it can be seen that C1 and C2 have the highest probability of occurrence. Therefore, the I-network central switch (CSW1) and the II-network central switch (CSW2) are the key weak links in the 220kV line bay communication network. It is recommended to strengthen their reliability by adding redundancy to the equipment or by performing regular preventive maintenance.
[0122] The above description is merely a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural transformations made using the contents of the present invention's specification and drawings under the inventive concept of the present invention, or direct / indirect applications in other related technical fields, are included within the patent protection scope of the present invention.
Claims
1. A method of substation secondary system communication network reliability analysis, characterized in that, include: Taking the overall failure of the substation communication network as the top event, and based on the safety partitioning architecture of the autonomous and controllable substation, the direct cause of the top event is decomposed into multiple intermediate events, and a top-level fault tree model between the top event and multiple intermediate events is constructed using logical OR gates. For each intermediate event, the initial subtree model is formed by hierarchical recursion. Combining the dual-network redundancy and dual-configuration characteristics of the autonomous and controllable substation, the redundancy mechanism is equivalent to the logical structure corresponding to the fault tree and added to the initial subtree model to obtain the partitioned subtree model. Device-level faults are extracted as base events from the partitioned subtree model, and all extracted base events are standardized to obtain multiple standardized base events. Obtain engineering statistics data, determine the failure rate and repair rate of each standardized base event based on the engineering statistics data, and calculate the unavailability of each standardized base event based on the failure rate and repair rate of each standardized base event; Based on the unavailability of the standardized bottom event, the partitioned subtree model, and the top-level fault tree model, probability calculations are performed from bottom to top to obtain the overall system availability.
2. The substation secondary system communication network reliability analysis method as claimed in claim 1, wherein, The method uses the overall failure of the substation communication network as the top event. Based on the safety partitioning architecture of the autonomous and controllable substation, the direct cause leading to the top event is decomposed into multiple intermediate events. A top-level fault tree model is constructed using logical OR gates to connect the top event and the multiple intermediate events, including: Obtain the security partitioning architecture of an independently controllable substation, which includes Security Zone I, Security Zone II, and Security Zone III; Taking the overall failure of the substation communication network as the top event, and based on the security zone I, security zone II, and security zone III, the direct cause of the top event is decomposed into multiple intermediate events; A top-level fault tree model is constructed using logical OR gates to connect the top event with multiple intermediate events.
3. The substation secondary system communication network reliability analysis method as recited in claim 2 wherein, The intermediate events include network failure events in Security Zone I, Security Zone II, and Security Zone III, firewall failure events, forward and reverse isolation device failure events, integrated power system failure events, and time synchronization system failure events.
4. The substation secondary system communication network reliability analysis method as recited in claim 1, wherein, The process of recursively expanding each intermediate event hierarchically to form an initial subtree model, and combining the dual-network redundancy and equipment dual configuration characteristics of the autonomous and controllable substation, equates the redundancy mechanism to the logical structure corresponding to the fault tree, and supplements it to the initial subtree model, resulting in a partitioned subtree model, including: Based on the expansion dimensions of intermediate events, subsystem levels, and devices, each intermediate event is recursively decomposed from top to bottom to form an initial subtree model. For the redundant objects with dual network redundancy and redundant objects with dual device redundancy in the initial subtree, according to the rule that failure only occurs when all redundant units fail simultaneously, it is equivalent to the AND gate logic structure of the fault tree. The equivalent AND gate logic structure is embedded into the initial subtree model according to the redundancy level to obtain the partitioned subtree model.
5. The method for reliability analysis of substation secondary system communication networks as described in claim 1, characterized in that, The process involves extracting device-level faults as base events from the partitioned subtree model and standardizing all extracted base events to obtain multiple standardized base events, including: Extract all device-level faults as bottom events from the lowest-level node of the partitioned subtree model; All extracted base events are standardized from three dimensions: fault type definition, coding rules, and parameter dimension, resulting in multiple standardized base events.
6. The method for reliability analysis of substation secondary system communication networks as described in claim 5, characterized in that, The extracted basic events are standardized from three dimensions: fault type definition, coding rules, and parameter dimensions, resulting in multiple standardized basic events, including: Based on the common characteristics of communication equipment failures, the failure types of each basic event are classified into one of three categories: equipment hardware failure, communication link interruption, and functional interface abnormality. Using a coding structure of safety zone, level, equipment type, fault type, and sequence number, each categorized base event is encoded to obtain coded base events; By unifying the statistical dimensions of failure rate and repair rate for each encoded base event, multiple standardized base events are obtained.
7. The method for reliability analysis of substation secondary system communication network as described in claim 1, characterized in that, The process of acquiring engineering statistics, determining the failure rate and repair rate of each standardized baseline event based on the engineering statistics, and calculating the unavailability of each standardized baseline event based on the failure rate and repair rate of each standardized baseline event includes: Obtain engineering statistics data, which are derived from equipment operation logs, fault repair records, equipment factory inspection reports, and power industry equipment reliability standard data of the independently controllable substation; The engineering statistics data are cleaned and normalized to obtain the processed engineering statistics data. Based on the processed engineering statistics, the failure rate and repair rate of each standardized baseline event are calculated using a weighted average method. The unavailability of each standardized base event is calculated based on the failure rate and repair rate of each standardized base event.
8. The method for reliability analysis of substation secondary system communication network as described in claim 6, characterized in that, Define the unavailability of the standardized bottom event as ,but Represented as: In the formula, To standardize the failure rate of the bottom event. This represents the repair rate of standardized bottom events.
9. The method for reliability analysis of substation secondary system communication networks as described in claim 1, characterized in that, The unavailability based on the standardized bottom event, the partitioned subtree model, and the top-level fault tree model are used to perform probability calculations from bottom to top to obtain the overall system availability, including: The availability of each standardized base event is calculated based on the unavailability of each standardized base event; Aggregate upwards along the partitioned subtree model to calculate the availability of each intermediate event in the top-level fault tree model; The overall system availability is calculated by multiplying the availability of each intermediate event.
10. The method for reliability analysis of substation secondary system communication network as described in claim 1, characterized in that, The unavailability based on the standardized bottom-event model, the partitioned subtree model, and the top-level fault tree model are used to perform probability calculations from bottom to top to obtain the overall system availability. This is followed by: Generate multiple minimal cut sets, each of which is the set of the minimum number of bottom events that cause the top event to occur, and each minimal cut set represents a mode of system failure. Using the top-level fault tree model and the partitioned subtree model, the probability of occurrence of each minimal cut set is calculated by applying the downlink or uplink method. The minimum cut set with the highest probability of occurrence is selected, and the equipment or communication link corresponding to the bottom event included in the minimum cut set with the highest probability of occurrence is identified as the key weak link in the substation secondary system communication network.
Citation Information
Patent Citations
Reliability assessment method for secondary system of intelligent substation
CN102723775A
Autonomous controllable new generation secondary system on-line monitoring structure and configuration scheme
CN117277560A