Generator set normal splitting shutdown signal uploading scheduling method
By generating valid shutdown signals through high-precision time synchronization and multi-parameter logic verification, and by utilizing dual-channel transmission and bidirectional interactive verification mechanisms, the problems of timing deviation and transmission instability in the uploading of generator shutdown signals are solved. This achieves efficient and reliable signal transmission and full-process associated archiving, thereby improving the safety and economy of power grid operation.
Patent Information
- Application Number
- CN202511688409.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-18
- Publication Date
- 2026-02-06
AI Technical Summary
In existing methods for uploading generator shutdown signals, insufficient clock synchronization accuracy leads to timing deviations in parameter acquisition, the transmission process lacks redundancy backup and switching mechanisms, signal verification is not comprehensive enough, and the correlation between bidirectional interactive verification and data archiving after transmission is insufficient, affecting the accuracy and reliability of the signal.
Multi-dimensional operating parameters are collected synchronously using a high-precision time synchronization protocol. Valid shutdown signals are generated using multi-parameter logic and time sequence verification mechanisms. These signals are then uploaded in parallel through the main fiber optic channel and backup communication channel. The transmission status is monitored in real time, and channels are automatically switched to achieve signal transmission redundancy and bidirectional interactive verification. Finally, the shutdown signals are bound to the unit identifier and key parameters for full-process association and archiving.
It improves the accuracy and efficiency of generator shutdown signal processing, ensures the continuity and reliability of signal transmission, enhances the integrity and traceability of data, provides detailed and reliable power grid dispatch data support, and promotes the safety and economy of power grid operation.
Smart Images

Figure CN121485152A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system operation and control technology, specifically to a method for uploading and scheduling normal tripping shutdown signals of generator sets. Background Technology
[0002] In the field of power system operation and control, the accurate and efficient transmission of generator unit shutdown signals to the dispatching center is a crucial link in ensuring the safe and stable operation of the power grid. This process requires the collection of multi-dimensional operating parameters and status signals through relevant unit monitoring and control devices, which are then verified and processed before being transmitted to the dispatching center. This provides the dispatching center with an important basis for accurately grasping the unit shutdown status and rationally allocating power grid resources, directly affecting the safety and economy of power grid operation. Strict requirements are placed on the synchronization of signal acquisition, the reliability of transmission, and the integrity of data.
[0003] Currently, existing methods for uploading generator shutdown signals still have room for improvement in practical applications. In some schemes, insufficient clock synchronization accuracy of various devices during the signal acquisition phase can easily lead to timing deviations in parameter acquisition, affecting the accuracy of basic signal data. During transmission, single channels are susceptible to external interference and failure, and the lack of efficient redundancy backup and switching mechanisms may cause signal transmission interruptions. Furthermore, the signal verification mechanism is not robust enough, failing to comprehensively verify parameter validity and timing rationality. The bidirectional interactive verification and data archiving correlation after transmission are also insufficient, hindering subsequent data traceability and maintenance analysis. To address these issues, we propose a method for uploading and scheduling normal generator shutdown signals. Summary of the Invention
[0004] To address the aforementioned technical issues, a method for uploading and scheduling normal tripping shutdown signals of generator sets is provided. This technical solution resolves the problems of insufficient clock synchronization accuracy of various devices, which easily leads to parameter acquisition timing deviations; transmission mostly using a single channel, lacking redundancy backup and switching mechanisms, which is easily interrupted by interference; incomplete coverage of parameter validity and timing rationality in signal verification; and low correlation between bidirectional interactive verification and data archiving after transmission.
[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0006] A method for uploading and dispatching normal tripping shutdown signals of generator sets includes the following steps:
[0007] S1. Through the unit's DCS, excitation system, and circuit breaker monitoring and control device, synchronously collect active power, reactive power, turbine main steam valve status signal, excitation exit command, and circuit breaker tripping position signal to build a basic dataset of shutdown signals.
[0008] S2. Based on the basic dataset of shutdown signals, a multi-parameter logic and timing verification mechanism is adopted to determine whether each collected parameter meets the preset shutdown conditions, and to verify whether the execution timing of load reduction, main steam valve action, and circuit breaker tripping conforms to the standard process, thereby generating a valid shutdown signal.
[0009] S3. The effective shutdown signal is uploaded in parallel through the main fiber optic channel and the backup communication channel. The status of the transmission channel is monitored in real time. When the channel is abnormal, it is automatically switched to the backup channel to complete the redundant transmission of the shutdown signal.
[0010] S4. Receive signal confirmation receipt from the dispatcher. If no receipt is received, perform signal retransmission at a preset interval. If retransmission fails, start local signal storage to achieve two-way interactive verification of signal transmission.
[0011] S5. Bind the shutdown signal with the unit identifier, shutdown type and key operating parameters, and synchronize it to the evidence storage module shared by the power plant and dispatch center to complete the full-process association and archiving of the shutdown signal.
[0012] Preferably, S1 includes:
[0013] Select a time synchronization protocol and deploy it in the unit's DCS, excitation system, and circuit breaker monitoring and control devices;
[0014] A clock reference signal is sent to each device via a time synchronization protocol, triggering each device to initiate the alignment and calibration of its local clock with the clock reference signal.
[0015] Receive clock calibration results from each device and extract the time deviation between the local clock and the clock reference signal;
[0016] If the time deviation exceeds the preset deviation threshold, the clock calibration command is resent and the clock alignment calibration is repeated.
[0017] Once the time deviation values of all devices meet the preset deviation threshold, the signal acquisition function of each device is started synchronously to acquire active power, reactive power, turbine main steam valve status signal, excitation exit command and circuit breaker trip position signal.
[0018] Each acquired signal is timestamped with a time reference signal, and all acquired signals are integrated to form a basic dataset of shutdown signals.
[0019] Preferably, S1 further includes:
[0020] Filter and supplement status parameters, including unit speed signal, stator current signal and plant power switching status signal;
[0021] To supplement the status parameter configuration, the acquisition range and preset accuracy level are set;
[0022] The DCS, excitation system, and circuit breaker monitoring and control devices of the unit are started simultaneously to collect supplementary status parameters, so that the timing of the collection of supplementary status parameters is consistent with that of the original signals.
[0023] The collected supplementary status parameters are validated in real time, and invalid data that are out of range, have abrupt changes, or are missing signals are removed according to the preset validity validation rules.
[0024] Add a timestamp to the supplementary status parameters that have passed the verification, and synchronize them with the original acquired signals. Then classify and organize them according to signal type and acquisition sequence.
[0025] Integrate all valid acquired signals and update the basic dataset of shutdown signals.
[0026] Preferably, S2 includes:
[0027] Clearly define the preset shutdown conditions, including active power dropping to a preset low power threshold, reactive power dropping to a preset low reactive power threshold, the turbine main steam valve being fully closed, the excitation exit command being issued, and the circuit breaker trip position signal being "tripped".
[0028] Extract the real-time values and status information of each collected parameter from the basic dataset of shutdown signals, and check each parameter one by one according to the preset judgment logic to see if it meets the corresponding preset conditions. When all collected parameters meet the corresponding preset conditions, the parameter level meets the shutdown requirements.
[0029] Extract the load reduction operation completion timestamp, main steam valve action timestamp, and circuit breaker trip timestamp from the basic dataset of shutdown signals to clarify the standard process timing relationship. The standard process timing is: after the load reduction operation is completed, the main steam valve action preset window period is entered; after the main steam valve is fully closed, the circuit breaker trip preset window period is entered.
[0030] The actual timestamp is compared with the preset window period of the standard process sequence to verify whether the execution sequence of load reduction, main steam valve action and circuit breaker tripping meets the requirements. If the sequence exceeds the corresponding preset window period, a timing abnormality alarm message is generated.
[0031] If the parameters meet the shutdown requirements and the timing is normal, an initial valid shutdown signal is generated.
[0032] If the parameters meet the shutdown requirements but there is a timing anomaly, the timing anomaly alarm information will be attached to the initial valid shutdown signal to form a valid shutdown signal.
[0033] Each valid shutdown signal is uniquely identified and encapsulated, with the identification information including the signal generation timestamp and the verification result identifier.
[0034] Preferably, S2 further includes:
[0035] Set a preset anti-shake duration to confirm the anti-shake status of each parameter if it meets the preset shutdown conditions. Only when a parameter continuously meets the corresponding preset conditions within the preset anti-shake duration will the parameter status be determined to be valid.
[0036] If some collected parameters do not meet the preset shutdown conditions, the real-time status information of those parameters will be repeatedly extracted at the preset verification interval, and the verification result and timestamp will be recorded each time until the preset number of retries is reached.
[0037] If all parameters continuously meet the corresponding preset conditions within the preset number of retries, it is determined that the parameters meet the shutdown requirements.
[0038] If, after the preset number of retries, there are still parameters that do not meet the preset conditions, a parameter abnormality alarm message will be generated. The parameter abnormality alarm message includes the parameter identifier that does not meet the conditions, the verification results of each time, and the final judgment conclusion.
[0039] The parameter anomaly alarm information and the timing anomaly alarm information are classified and encapsulated to form an alarm supplementary module, which is then associated and bound with the initial valid shutdown signal;
[0040] Perform integrity verification on valid shutdown signals after associated alarm attachment modules, and check whether the signal contains parameter judgment results, timing verification results, various alarm information, signal generation timestamp and unique identifier according to the preset key field list;
[0041] If any fields are missing, generate a field missing alarm and add it to the alarm attachment module.
[0042] Preferably, S3 includes:
[0043] Select dedicated transmission protocols and deploy them on the main fiber optic channel and backup communication channel, respectively.
[0044] Based on the transmission protocol, the parallel transmission process of the main fiber optic channel and the backup communication channel is started simultaneously, and the effective shutdown signal and alarm attachment module are sent to the dispatch terminal at the same time.
[0045] The transmission status of the two channels is monitored in real time according to the preset monitoring cycle, including channel connectivity, signal transmission packet loss rate, transmission delay and data integrity.
[0046] The monitoring indicators are compared with the preset transmission quality thresholds. If all the monitoring indicators of the main fiber channel meet the preset thresholds, the main channel transmission is maintained.
[0047] If any monitoring indicator of the fiber optic main channel exceeds the preset transmission quality threshold, the main channel is determined to be abnormal, triggering an automatic channel switching command to suspend the main channel transmission and switch to the backup communication channel.
[0048] Record the main channel anomaly type, anomaly occurrence timestamp, switchover trigger condition, and switchover completion timestamp, while monitoring the transmission status of the backup channel;
[0049] If the backup channel transmission status is stable, continue transmission through the backup channel.
[0050] If the backup channel also malfunctions, a dual-malfunction alarm will be generated and reported to the power plant operation and maintenance system and dispatch terminal, while retaining the current transmission progress data.
[0051] Preferably, S3 further includes:
[0052] Encryption algorithms are used to encrypt valid shutdown signals and alarm attachment modules before transmission.
[0053] The encrypted signal is split into several data fragments according to the preset data fragmentation rules. A unique verification code is generated for each data fragment, and the sequence identifier of each fragment and the total number of fragments are recorded.
[0054] When the main fiber optic channel and the backup communication channel transmit in parallel, each data fragment and its corresponding checksum are sent synchronously.
[0055] Receive fragment verification results and retransmission requests from the scheduling end. For fragments that fail verification, perform retransmission operations through the currently valid transmission channel. The number of retransmissions shall not exceed the preset retransmission limit.
[0056] Real-time status reports of the transmission channel are pushed to the local operation and maintenance system of the power plant according to the preset feedback cycle. The report content includes the current transmission channel type, data fragmentation transmission progress, verification pass rate, retransmission records and cumulative number of channel anomalies.
[0057] If the main channel recovers to normal after an anomaly, the channel switchback determination process is initiated to switch the transmission link back to the main channel;
[0058] After all data fragments are successfully received and verified by the dispatcher, a transmission completion confirmation signal is generated and fed back to the power plant's local system.
[0059] Preferably, S4 includes:
[0060] Set the duration of the signal receipt reception window. After S3 is completed, start the reception window and listen for the signal confirmation receipt fed back by the dispatcher. The receipt includes the unique identifier of the signal, the reception completion status, and the data integrity verification result.
[0061] The received signal confirmation receipt is validated for validity. The unique identifier of the signal in the receipt is verified to be consistent with the valid shutdown signal identifier. The integrity of the receipt fields and the legality of the data signature are also verified.
[0062] If a valid confirmation receipt is received within the receiving window duration, the receipt receipt timestamp, receipt content, and interaction verification result are recorded.
[0063] If no acknowledgment is received within the receiving window period, or if the received acknowledgment is invalid, the signal retransmission operation will be performed according to the preset retransmission interval, and the signal transmission status identifier will be updated before each retransmission.
[0064] During the retransmission process, retransmission is performed through the current normal transmission channel, and the retransmission path is adjusted as the channel switches.
[0065] If no valid confirmation receipt is received after the cumulative number of retransmissions reaches the preset limit, local signal storage will be activated, and the complete data of the valid shutdown signal, transmission log, receipt monitoring log and interaction verification results will be written to the local distributed storage system.
[0066] Perform integrity verification on the stored data, and generate storage completion identifiers and data retrieval indexes;
[0067] Generate a signal transmission failure alarm, specify the alarm cause, relevant timestamps and storage path, report it to the power plant operation and maintenance system, and retain the signal retransmission interface.
[0068] Preferably, S4 further includes:
[0069] The system categorizes and determines the types of anomalies in signal confirmation receipts. These anomaly types include receipt not received, missing receipt fields, mismatched receipt identifiers, invalid receipt signatures, and failed receipt integrity verification. Corresponding anomaly codes and explanations are generated for each anomaly type.
[0070] The retransmission strategy is dynamically adjusted based on the anomaly type determination result: if the receipt identifier is mismatched or the signature is invalid, the local valid shutdown signal identifier and transmission protocol consistency are verified, and retransmission is performed after correction.
[0071] If a field is missing in the receipt or the integrity check fails, a list of field checks will be attached when resending.
[0072] Security hardening is performed on locally stored signal-related data, and a hierarchical permission management mechanism is used to divide data access permissions. At the same time, the integrity of stored data is checked regularly. If data corruption or tampering is found, a data repair process is triggered and a security alarm is generated.
[0073] Set retransmission trigger conditions, including channel abnormal recovery, retransmission request initiated by the dispatch terminal, and retransmission manually triggered by power plant operation and maintenance personnel. Before retransmission, compare the differences between the locally stored data and the data already received by the dispatch terminal, and only perform retransmission on the missing or abnormal parts.
[0074] During the retransmission process, the retransmission trigger conditions, retransmission timestamp, retransmission channel, retransmission data range, and retransmission result are recorded. After successful retransmission, the local transmission status identifier and the scheduling terminal receipt record are updated.
[0075] All interactive data generated in the S4 stage are standardized and organized according to a preset format to generate an interactive verification report;
[0076] The interactive verification report is associated with and bound to the valid shutdown signal, and then pushed to the power plant operation and maintenance management platform.
[0077] Preferably, S5 includes:
[0078] The core data dimensions of shutdown signal binding are clearly defined. The unit identification adopts a unique equipment code. The shutdown types are divided into planned shutdown, fault shutdown and test shutdown. The key operating parameters cover the peak active power, stable reactive power, critical unit speed, status data before and after the main steam valve action and circuit breaker tripping trigger condition parameters within the preset time before shutdown.
[0079] Extract the data required for binding from the basic dataset of shutdown signals, valid shutdown signals, transmission logs and interactive verification reports, and perform the binding operation according to the association logic to make the shutdown signals correspond one-to-one with the unit identifier, shutdown type and key operating parameters;
[0080] The bound data is standardized and formatted, using a unified data format, clearly defining field definitions, data types and storage precision, and adding archiving timestamps and data source identifiers to the data.
[0081] Establish a secure communication link with the power plant-dispatch shared evidence storage module. Based on the data transmission verification mechanism, transmit the standardized binding data synchronously to the evidence storage module and monitor the data transmission progress and the receipt status of the evidence storage module.
[0082] After receiving the data, the evidence storage module classifies and organizes it according to the preset archiving rules, using the unit identifier as the first-level index, the shutdown timestamp as the second-level index, and the shutdown type as the third-level index to build a multi-level archiving directory structure;
[0083] Initiate a process to prevent tampering and strengthen the evidence storage data, and use distributed ledger technology or encrypted hash chain mechanism to store the archived data in a chain, recording the person who wrote the data, the writing time, and the operation log.
[0084] The evidence storage module generates an archiving completion confirmation receipt, which is sent to the power plant's local system and dispatch terminal. The receipt includes archived data index information, integrity verification results, and shared access path.
[0085] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0086] The method for uploading and scheduling normal shutdown signals of generator sets proposed in this invention significantly improves the accuracy and efficiency of generator set shutdown signal processing. Through a highly synchronized time protocol, it ensures the timing consistency of multi-dimensional parameter acquisition, avoiding data deviations caused by clock asynchrony. Employing multi-parameter logic and a fine-grained timing verification mechanism, it comprehensively verifies the fulfillment of shutdown conditions and the compliance of operational procedures, enhancing the comprehensiveness and accuracy of signal verification. The dual-channel redundant transmission design effectively addresses the risk of single-channel failure, ensuring the continuity and reliability of signal transmission. Through real-time bidirectional interactive verification and local signal storage mechanisms, it ensures the integrity and traceability of data transmission. The deep binding and full-process associated archiving of shutdown signals and key unit information provide detailed and reliable data support for power grid dispatching, promoting the safety and economy of power grid operation. Attached Figure Description
[0087] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation
[0088] The following description is intended to disclose the invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art.
[0089] Reference Figure 1 As shown, a method for uploading and scheduling a normal trip-out signal for a generator set includes the following steps:
[0090] S1. Through the unit's DCS, excitation system, and circuit breaker monitoring and control device, synchronously collect active power, reactive power, turbine main steam valve status signal, excitation exit command, and circuit breaker tripping position signal to build a basic dataset of shutdown signals.
[0091] S1 includes:
[0092] Deploy high-precision time synchronization protocols (such as PTP or IEEE 1588) in the unit's DCS, excitation system, and circuit breaker monitoring and control devices to build a distributed acquisition clock synchronization network;
[0093] The master clock sends a microsecond-level clock reference signal to each acquisition device through the time synchronization protocol, driving each device to complete the phase and frequency alignment with the master clock and feeding back the synchronization status word.
[0094] The synchronization status words fed back by each device are analyzed. If the synchronization accuracy does not reach the preset level (such as ±1ms), a clock discipline command is automatically issued and the synchronization calibration process is executed iteratively.
[0095] Once the clock synchronization network is stable across the entire domain, a unified acquisition start command is broadcast to all acquisition devices to instantly capture the instantaneous values of active power, reactive power, turbine main steam valve status signal, excitation exit command, and circuit breaker trip position signal.
[0096] Each acquired signal is appended with a high-precision time stamp, which includes absolute time, acquisition cycle number and clock synchronization quality indicator.
[0097] Data alignment and interpolation compensation are performed on multi-source acquired signals based on time-stamped sequences to construct a basic dataset of shutdown signals with spatiotemporal correlation attributes.
[0098] S1 further includes:
[0099] Expand the dimensions of the acquired signals and add unit speed over-limit signal, stator current zero value crossing signal and plant power backup power switching success signal as key auxiliary criteria;
[0100] To extend the signal configuration, an adaptive range switching strategy and accuracy self-calibration logic are implemented to ensure data validity under dynamic operating conditions of the unit.
[0101] Initiate the synchronous acquisition task of extended signals by DCS and auxiliary measurement and control devices, and ensure strict alignment of the acquisition timing with the core signals through a hardware triggering mechanism;
[0102] Online quality assessment of the extended signal stream is performed, and outliers and invalid segments caused by electromagnetic interference and channel interruption are filtered out in real time based on sliding window statistics and mutation detection algorithms.
[0103] The extended signal injected into the time-stamp generation pipeline, which is evaluated for quality, is given a timestamp sequence based on the same reference as the core signal.
[0104] The signals are grouped in multiple dimensions according to their physical attributes and functional correlations to form a hierarchical signal organization structure, which is then dynamically updated to the basic dataset of shutdown signals.
[0105] S2. Based on the basic dataset of shutdown signals, a multi-parameter logic and timing verification mechanism is adopted to determine whether each collected parameter meets the preset shutdown conditions, and to verify whether the execution timing of load reduction, main steam valve action, and circuit breaker tripping conforms to the standard process, thereby generating a valid shutdown signal.
[0106] S2 includes:
[0107] A multi-level threshold system for defining shutdown preset conditions is defined. The active power low power threshold is set according to the percentage of unit capacity, and the reactive power low reactive power threshold introduces power factor constraints. The turbine main steam valve fully closed state is determined by combining valve position feedback and closing rate. The excitation exit command verification token and feedback signal are double matched. The circuit breaker trip position signal needs to be linked and verified with electrical quantity criteria.
[0108] The numerical trajectory and state sequence of each parameter are extracted in real time from the basic dataset of shutdown signals. This drives a multi-parameter parallel inference engine to perform item-by-item matching and cross-validation of parameters and conditions. When all parameters continuously meet the threshold requirements within a continuous decision period, a parameter verification pass flag is output.
[0109] Construct a knowledge graph of standard shutdown operation sequence. Graph nodes are defined as key events such as "load reduction completed", "main steam valve begins to close", "main steam valve fully closed", and "circuit breaker tripped". The edge attributes between nodes are the maximum / minimum allowable time interval between events based on procedures and expert experience.
[0110] Extract event timestamp sequences from the basic dataset, map them to a time-series knowledge graph, calculate the actual time difference between adjacent events and compare it with the allowed interval of the graph. If any actual time difference exceeds the tolerance range, generate an anomaly alarm with time-series deviation.
[0111] When the parameter verification passes the flag and the time-series knowledge graph traversal is error-free, an initial valid shutdown signal is synthesized.
[0112] If the parameter verification passes but there is a local deviation in the timing, the timing correction subprocess is activated to perform weight evaluation and impact analysis on the deviation event, and the evaluation conclusion is embedded into the alarm information and coupled with the initial valid shutdown signal for output.
[0113] The final valid shutdown signal is digitally signed and uniquely encoded. The encoding structure integrates the unit identifier, the hash value of the signal generation time, and the summary of the verification conclusion.
[0114] S2 further includes:
[0115] A signal state anti-shake mechanism is introduced, which sets a configurable anti-shake confirmation time window for each parameter condition. The condition is confirmed to be effective only when the parameter state continuously and stably meets the condition and there are no glitches within the time window.
[0116] For parameters that do not meet the conditions immediately, the adaptive retry scheduler is started, and state sampling is initiated at Fibonacci increment intervals, and the original value, filtered value and environmental context of each sample are recorded.
[0117] If all parameter conditions are confirmed to be effective within the maximum retry period, then update the parameter validation pass flag.
[0118] If parameters still fail to meet the standards after the retry cycle is exhausted, the parameter root cause analysis routine will be started. Combining the historical trend of parameters, the status of related parameters and equipment health data, a multi-dimensional parameter anomaly diagnosis report will be generated.
[0119] The abnormal parameter diagnosis report and the time-series abnormal alarm are feature-fused to build a traceable alarm knowledge module, and then linked with the effective shutdown signal through dynamic linking.
[0120] Perform structured integrity audits on shutdown signals carrying alarm knowledge modules, verifying the completeness of their data fields, the legality of their value fields, and the correctness of their relationships based on a predefined signal schema;
[0121] For missing fields or abnormal associations discovered during audits, trigger a data self-repair process or inject supplementary alarm metadata.
[0122] S3. The effective shutdown signal is uploaded in parallel through the main fiber optic channel and the backup communication channel. The status of the transmission channel is monitored in real time. When the channel is abnormal, it is automatically switched to the backup channel to complete the redundant transmission of the shutdown signal.
[0123] S3 includes:
[0124] Configure reliable transmission protocol stacks suitable for power control services for the main fiber optic channel and backup communication channels (such as power private networks or 5G slicing). The protocol stacks have message priority scheduling, forward error correction and connection survival maintenance functions.
[0125] The transmission session is initialized in parallel on dual channels, and link aggregation technology is used to synchronously map the effective shutdown signal and alarm knowledge module to two physical transmission paths.
[0126] Construct a digital twin of the transmission channel to perform real-time mirroring and performance evaluation of the end-to-end latency, bandwidth utilization, bit error rate, and out-of-order message rate of the dual channels;
[0127] The performance evaluation metrics are matched with the channel health model. If all key metrics of the main channel are consistently better than the health threshold, then it is set as the preferred path.
[0128] If any key indicator of the main channel degrades and reaches the degradation threshold, the seamless switching controller will be triggered instantly to freeze the main channel data flow and seamlessly migrate its business load to the backup channel.
[0129] Record a panoramic snapshot of channel switching events, including triggering factors, performance degradation curves, switching decision moments, and service recovery latency, and continuously track the load and status of the backup channel;
[0130] If the backup channel also experiences performance degradation after carrying services, the alarm will be upgraded to a dual-channel degradation event, and the power plant operation and maintenance and dispatch will be notified immediately for joint intervention, while the current transmission context will be persisted.
[0131] S3 further includes:
[0132] The transmitted payload is encrypted end-to-end using national cryptographic algorithms (such as SM4) or AES-256, and HMAC is integrated for data integrity protection.
[0133] Based on the channel MTU and transmission reliability requirements, the encrypted data payload is intelligently fragmented, and an independent CRC32 checksum and sequence number are calculated for each fragment, and a global fragmentation mapping table is maintained.
[0134] When transmitting in parallel through dual channels, the fragmented load is dynamically allocated based on the real-time quality of the channels, and fragmented data and checksum information are sent synchronously.
[0135] Receive fragment-level ACK / NACK information from the scheduling end. For fragments that fail to be verified or are lost, repair is carried out on high-quality channels based on redundant fragment replicas or active retransmission mechanisms. The retransmission strategy supports exponential backoff to avoid network congestion.
[0136] Establish a transmission dashboard for power plant operation and maintenance, and push channel performance KPIs, segment delivery rate, repetitive data and abnormal event aggregation reports according to a set period;
[0137] Design a main channel recovery and back-switch strategy. When the main channel performance recovers and runs stably for more than the observation period, the data stream will be switched back to the main channel in a business-uninterrupted manner.
[0138] After all data fragments have been confirmed to have been received intact by the scheduling terminal, a transmission task completion certificate is generated and sent back to the power plant production control area.
[0139] S4. Receive signal confirmation receipt from the dispatcher. If no receipt is received, perform signal retransmission at a preset interval. If retransmission fails, start local signal storage to achieve two-way interactive verification of signal transmission.
[0140] S4 includes:
[0141] After the signal is sent, a configurable signal receipt reception waiting timer is started to wait for the standard acknowledgment receipt returned by the dispatcher. The receipt format includes the globally unique ID of the signal, the reception status code, the data hash check value and the dispatcher timestamp.
[0142] The received receipts undergo multi-factor verification, including receipt digital signature verification, signal ID bidirectional verification, and receipt field structure and enumeration value validity check.
[0143] If a valid receipt is received before the timeout period, record the successful interaction event and archive the full receipt and verification log.
[0144] If the waiting timeout or receipt verification fails, the signal retransmission controller is activated, and retransmission is initiated according to the adaptive retransmission sequence (such as binary exponential backoff). Before each retransmission, the retransmission round number is incremented and the signal version number is refreshed.
[0145] The retransmission process is linked with the channel status awareness module, automatically selecting the current optimal transmission path for data retransmission;
[0146] If the cumulative number of retransmissions reaches the system limit and no valid receipt is obtained, the local signal persistence emergency process is initiated, and a complete copy of the signal, all transmission transaction logs, receipt interaction records and audit trail information are written to the high-availability distributed storage cluster.
[0147] Perform write verification and multi-replica consistency synchronization on persistent data, and generate data storage receipts and unique access tokens;
[0148] Issue a signal transmission interruption alarm, clarify the interruption stage, responsibility analysis and data recovery entry point, and report to the power plant alarm center. At the same time, open a standardized data retransmission service interface based on storage tokens.
[0149] S4 further includes:
[0150] Construct an anomaly classification tree for receipts and perform refined coding and attribution analysis on anomaly scenarios such as "receipt timeout", "receipt structure damage", "receipt ID mismatch", "signature verification failure", and "hash verification failure".
[0151] Based on the code-driven intelligent retransmission strategy selector for receipt exception types: if the ID mismatch or signature failure occurs, the integrity of the local signal metadata is checked and re-signed before retransmission.
[0152] If the issue is related to the receipt structure or hash verification, embed the data format specification and verification guidance information into the retransmitted data packet.
[0153] Implement zero-trust security protection for data in local emergency storage, adopt role-based access control and attribute-based encryption technology, and deploy a data integrity inspection agent to regularly scan the health of data blocks. If damage is detected, trigger a repair process based on redundant copies.
[0154] Design multiple retransmission trigger scenarios, including transmission channel performance recovery, dispatch terminal active data synchronization request, and power plant operation and maintenance emergency manual retransmission. Before retransmission, perform data difference comparison and use incremental synchronization technology to transmit only missing or erroneous data segments.
[0155] The entire link records metadata of the retransmission operation, including the trigger source, retransmission time, channel used, data version and retransmission results. After success, the local and remote transmission state machines are updated synchronously.
[0156] Format all interactions and processing data in this step into a standard transaction report and attach a data quality score;
[0157] The transaction report is associated with the original valid shutdown signal throughout its lifecycle and pushed to the power plant's smart operation and maintenance platform for visual monitoring and analysis.
[0158] S5. Bind the shutdown signal with the unit identifier, shutdown type and key operating parameters, and synchronize it to the evidence storage module shared by the power plant and dispatch center to complete the full-process association and archiving of the shutdown signal.
[0159] S5 includes:
[0160] Define a data model for holographic binding of shutdown signals. The unit identifier adopts a composite ID that integrates the power plant code, unit type and commissioning date. The shutdown type is subdivided into three dimensions according to cause, urgency and dispatching method. Key operating parameters are extended to the entire shutdown process, including power drop gradient, excitation voltage decay curve, cylinder metal temperature change rate and vibration characteristic quantity, etc.
[0161] From the signal base set, valid signals, transmission transaction logs and interaction reports, bind elements are extracted according to the data model, and a signal lifecycle data chain is constructed through the event tracing mode.
[0162] The aggregated data chain is standardized and serialized, and a unified data contract (such as JSONSchema or Apache Avro) is used to define field semantics, types, precision and constraints, and data lineage tracking tags are attached.
[0163] Establish a two-way authentication security link with the power plant-dispatch shared evidence storage module. Through breakpoint resume and data compression technology, standard data packets are efficiently synchronized to the evidence storage module, and the synchronization progress and the evidence storage terminal's entry status are monitored.
[0164] After receiving the evidence, the evidence storage module starts the intelligent archiving engine, automatically creates a hierarchical index directory according to the three-dimensional model of "unit-time-event type", and supports multi-dimensional joint queries;
[0165] Implement blockchain notarization and reinforcement for archived data, store data hash values on the chain, or use encrypted hash chains to build tamper-proof data corridors to fully record data creators, archiving time, access history and any change history.
[0166] The evidence storage module generates archived credentials that include evidence storage number, blockchain transaction ID (if applicable), and data access API, and distributes them to power plants and dispatch systems to complete the trusted closed-loop management of signal data.
[0167] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention. The scope of protection claimed by the appended claims and their equivalents is defined.
Claims
1. A method for uploading and scheduling normal tripping shutdown signals of generator sets, characterized in that, Includes the following steps: S1. Through the unit's DCS, excitation system, and circuit breaker monitoring and control device, synchronously collect active power, reactive power, turbine main steam valve status signal, excitation exit command, and circuit breaker tripping position signal to build a basic dataset of shutdown signals. S2. Based on the basic dataset of shutdown signals, a multi-parameter logic and timing verification mechanism is adopted to determine whether each collected parameter meets the preset shutdown conditions, and to verify whether the execution timing of load reduction, main steam valve action, and circuit breaker tripping conforms to the standard process, thereby generating a valid shutdown signal. S3. The effective shutdown signal is uploaded in parallel through the main fiber optic channel and the backup communication channel. The status of the transmission channel is monitored in real time. When the channel is abnormal, it is automatically switched to the backup channel to complete the redundant transmission of the shutdown signal. S4. Receive signal confirmation receipt from the dispatcher. If no receipt is received, perform signal retransmission at a preset interval. If retransmission fails, start local signal storage to achieve two-way interactive verification of signal transmission. S5. Bind the shutdown signal with the unit identifier, shutdown type and key operating parameters, and synchronize it to the evidence storage module shared by the power plant and dispatch center to complete the full-process association and archiving of the shutdown signal.
2. The method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 1, characterized in that, S1 includes: Select a time synchronization protocol and deploy it in the unit's DCS, excitation system, and circuit breaker monitoring and control devices; A clock reference signal is sent to each device via a time synchronization protocol, triggering each device to initiate the alignment and calibration of its local clock with the clock reference signal. Receive clock calibration results from each device and extract the time deviation between the local clock and the clock reference signal; If the time deviation exceeds the preset deviation threshold, the clock calibration command is resent and the clock alignment calibration is repeated. Once the time deviation values of all devices meet the preset deviation threshold, the signal acquisition function of each device is started synchronously to acquire active power, reactive power, turbine main steam valve status signal, excitation exit command and circuit breaker trip position signal. Each acquired signal is timestamped with a time reference signal, and all acquired signals are integrated to form a basic dataset of shutdown signals.
3. The method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 2, characterized in that, S1 further includes: Filter and supplement status parameters, including unit speed signal, stator current signal and plant power switching status signal; To supplement the status parameter configuration, the acquisition range and preset accuracy level are set; The DCS, excitation system, and circuit breaker monitoring and control devices of the unit are started simultaneously to collect supplementary status parameters, so that the timing of the collection of supplementary status parameters is consistent with that of the original signals. The collected supplementary status parameters are validated in real time, and invalid data that are out of range, have abrupt changes, or are missing signals are removed according to the preset validity validation rules. Add a timestamp to the supplementary status parameters that have passed the verification, and synchronize them with the original acquired signals. Then classify and organize them according to signal type and acquisition sequence. Integrate all valid acquired signals and update the basic dataset of shutdown signals.
4. The method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 3, characterized in that, S2 includes: Clearly define the preset shutdown conditions, including active power dropping to a preset low power threshold, reactive power dropping to a preset low reactive power threshold, the turbine main steam valve being fully closed, the excitation exit command being issued, and the circuit breaker trip position signal being "tripped". Extract the real-time values and status information of each collected parameter from the basic dataset of shutdown signals, and check each parameter one by one according to the preset judgment logic to see if it meets the corresponding preset conditions. When all collected parameters meet the corresponding preset conditions, the parameter level meets the shutdown requirements. Extract the load reduction operation completion timestamp, main steam valve action timestamp, and circuit breaker trip timestamp from the basic dataset of shutdown signals to clarify the standard process timing relationship. The standard process timing is: after the load reduction operation is completed, the main steam valve action preset window period is entered; after the main steam valve is fully closed, the circuit breaker trip preset window period is entered. The actual timestamp is compared with the preset window period of the standard process sequence to verify whether the execution sequence of load reduction, main steam valve action and circuit breaker tripping meets the requirements. If the sequence exceeds the corresponding preset window period, a timing abnormality alarm message is generated. If the parameters meet the shutdown requirements and the timing is normal, an initial valid shutdown signal is generated. If the parameters meet the shutdown requirements but there is a timing anomaly, the timing anomaly alarm information will be attached to the initial valid shutdown signal to form a valid shutdown signal. Each valid shutdown signal is uniquely identified and encapsulated, with the identification information including the signal generation timestamp and the verification result identifier.
5. The method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 4, characterized in that, S2 further includes: Set a preset anti-shake duration to confirm the anti-shake status of each parameter if it meets the preset shutdown conditions. Only when a parameter continuously meets the corresponding preset conditions within the preset anti-shake duration will the parameter status be determined to be valid. If some collected parameters do not meet the preset shutdown conditions, the real-time status information of those parameters will be repeatedly extracted at the preset verification interval, and the verification result and timestamp will be recorded each time until the preset number of retries is reached. If all parameters continuously meet the corresponding preset conditions within the preset number of retries, it is determined that the parameters meet the shutdown requirements. If, after the preset number of retries, there are still parameters that do not meet the preset conditions, a parameter abnormality alarm message will be generated. The parameter abnormality alarm message includes the parameter identifier that does not meet the conditions, the verification results of each time, and the final judgment conclusion. The parameter anomaly alarm information and the timing anomaly alarm information are classified and encapsulated to form an alarm supplementary module, which is then associated and bound with the initial valid shutdown signal; Perform integrity verification on valid shutdown signals after associated alarm attachment modules, and check whether the signal contains parameter judgment results, timing verification results, various alarm information, signal generation timestamp and unique identifier according to the preset key field list; If any fields are missing, generate a field missing alarm and add it to the alarm attachment module.
6. The method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 5, characterized in that, S3 includes: Select dedicated transmission protocols and deploy them on the main fiber optic channel and backup communication channel, respectively. Based on the transmission protocol, the parallel transmission process of the main fiber optic channel and the backup communication channel is started simultaneously, and the effective shutdown signal and alarm attachment module are sent to the dispatch terminal at the same time. The transmission status of the two channels is monitored in real time according to the preset monitoring cycle, including channel connectivity, signal transmission packet loss rate, transmission delay and data integrity. The monitoring indicators are compared with the preset transmission quality thresholds. If all the monitoring indicators of the main fiber channel meet the preset thresholds, the main channel transmission is maintained. If any monitoring indicator of the fiber optic main channel exceeds the preset transmission quality threshold, the main channel is determined to be abnormal, triggering an automatic channel switching command to suspend the main channel transmission and switch to the backup communication channel. Record the main channel anomaly type, anomaly occurrence timestamp, switchover trigger condition, and switchover completion timestamp, while monitoring the transmission status of the backup channel; If the backup channel transmission status is stable, continue transmission through the backup channel. If the backup channel also malfunctions, a dual-malfunction alarm will be generated and reported to the power plant operation and maintenance system and dispatch terminal, while retaining the current transmission progress data.
7. The method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 6, characterized in that, S3 further includes: Encryption algorithms are used to encrypt valid shutdown signals and alarm attachment modules before transmission. The encrypted signal is split into several data fragments according to the preset data fragmentation rules. A unique verification code is generated for each data fragment, and the sequence identifier of each fragment and the total number of fragments are recorded. When the main fiber optic channel and the backup communication channel transmit in parallel, each data fragment and its corresponding checksum are sent synchronously. Receive fragment verification results and retransmission requests from the scheduling end. For fragments that fail verification, perform retransmission operations through the currently valid transmission channel. The number of retransmissions shall not exceed the preset retransmission limit. Real-time status reports of the transmission channel are pushed to the local operation and maintenance system of the power plant according to the preset feedback cycle. The report content includes the current transmission channel type, data fragmentation transmission progress, verification pass rate, retransmission records and cumulative number of channel anomalies. If the main channel recovers to normal after an anomaly, the channel switchback determination process is initiated to switch the transmission link back to the main channel; After all data fragments are successfully received and verified by the dispatcher, a transmission completion confirmation signal is generated and fed back to the power plant's local system.
8. The method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 7, characterized in that, S4 includes: Set the duration of the signal receipt reception window. After S3 is completed, start the reception window and listen for the signal confirmation receipt fed back by the dispatcher. The receipt includes the unique identifier of the signal, the reception completion status, and the data integrity verification result. The received signal confirmation receipt is validated for validity. The unique identifier of the signal in the receipt is verified to be consistent with the valid shutdown signal identifier. The integrity of the receipt fields and the legality of the data signature are also verified. If a valid confirmation receipt is received within the receiving window duration, the receipt receipt timestamp, receipt content, and interaction verification result are recorded. If no acknowledgment is received within the receiving window period, or if the received acknowledgment is invalid, the signal retransmission operation will be performed according to the preset retransmission interval, and the signal transmission status identifier will be updated before each retransmission. During the retransmission process, retransmission is performed through the current normal transmission channel, and the retransmission path is adjusted as the channel switches. If no valid confirmation receipt is received after the cumulative number of retransmissions reaches the preset limit, local signal storage will be activated, and the complete data of the valid shutdown signal, transmission log, receipt monitoring log and interaction verification results will be written to the local distributed storage system. Perform integrity verification on the stored data, and generate storage completion identifiers and data retrieval indexes; Generate a signal transmission failure alarm, specify the alarm cause, relevant timestamps and storage path, report it to the power plant operation and maintenance system, and retain the signal retransmission interface.
9. A method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 8, characterized in that, S4 further includes: The system categorizes and determines the types of anomalies in signal confirmation receipts. These anomaly types include receipt not received, missing receipt fields, mismatched receipt identifiers, invalid receipt signatures, and failed receipt integrity verification. Corresponding anomaly codes and explanations are generated for each anomaly type. The retransmission strategy is dynamically adjusted based on the anomaly type determination result: if the receipt identifier is mismatched or the signature is invalid, the local valid shutdown signal identifier and transmission protocol consistency are verified, and retransmission is performed after correction. If a field is missing in the receipt or the integrity check fails, a list of field checks will be attached when resending. Security hardening is performed on locally stored signal-related data, and a hierarchical permission management mechanism is used to divide data access permissions. At the same time, the integrity of stored data is checked regularly. If data corruption or tampering is found, a data repair process is triggered and a security alarm is generated. Set retransmission trigger conditions, including channel abnormal recovery, retransmission request initiated by the dispatch terminal, and retransmission manually triggered by power plant operation and maintenance personnel. Before retransmission, compare the differences between the locally stored data and the data already received by the dispatch terminal, and only perform retransmission on the missing or abnormal parts. During the retransmission process, the retransmission trigger conditions, retransmission timestamp, retransmission channel, retransmission data range, and retransmission result are recorded. After successful retransmission, the local transmission status identifier and the scheduling terminal receipt record are updated. All interactive data generated in the S4 stage are standardized and organized according to a preset format to generate an interactive verification report; The interactive verification report is associated with and bound to the valid shutdown signal, and then pushed to the power plant operation and maintenance management platform.
10. A method for uploading and scheduling normal tripping shutdown signals of generator sets according to claim 9, characterized in that, S5 includes: The core data dimensions of shutdown signal binding are clearly defined. The unit identification adopts a unique equipment code. The shutdown types are divided into planned shutdown, fault shutdown and test shutdown. The key operating parameters cover the peak active power, stable reactive power, critical unit speed, status data before and after the main steam valve action and circuit breaker tripping trigger condition parameters within the preset time before shutdown. Extract the data required for binding from the basic dataset of shutdown signals, valid shutdown signals, transmission logs and interactive verification reports, and perform the binding operation according to the association logic to make the shutdown signals correspond one-to-one with the unit identifier, shutdown type and key operating parameters; The bound data is standardized and formatted, using a unified data format, clearly defining field definitions, data types and storage precision, and adding archiving timestamps and data source identifiers to the data. Establish a secure communication link with the power plant-dispatch shared evidence storage module. Based on the data transmission verification mechanism, transmit the standardized binding data synchronously to the evidence storage module and monitor the data transmission progress and the receipt status of the evidence storage module. After receiving the data, the evidence storage module classifies and organizes it according to the preset archiving rules, using the unit identifier as the first-level index, the shutdown timestamp as the second-level index, and the shutdown type as the third-level index to build a multi-level archiving directory structure; Initiate a process to prevent tampering and strengthen the evidence storage data, and use distributed ledger technology or encrypted hash chain mechanism to store the archived data in a chain, recording the person who wrote the data, the writing time, and the operation log. The evidence storage module generates an archiving completion confirmation receipt, which is sent to the power plant's local system and dispatch terminal. The receipt includes archived data index information, integrity verification results, and shared access path.