Multi-stage fault diagnosis and locking linkage method of high-voltage locking device

By generating a comprehensive diagnostic code through hierarchical Bayesian and evidence fusion calculations, the electric latch, mechanical locking pin, and magnetic latching relay of the high-voltage interlocking device are driven to lock out. This solves the problems of single sampling links and fixed fault criterion thresholds in high-voltage distribution networks, and achieves accurate fault identification and reliable interlocking, thereby improving operation and maintenance resilience and information transparency.

CN121546508APending Publication Date: 2026-02-17JIANGSHAN XINYUAN ELECTRIC CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511639807.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-11
Publication Date
2026-02-17

AI Technical Summary

Technical Problem

Existing high-voltage interlocking devices in high-voltage distribution networks suffer from problems such as a single sampling link, lack of self-testing, fault judgment based on fixed thresholds, lack of coordination in the interlocking chain, low information granularity on the remote side, and loss of connection due to power outages. These issues lead to false indications, misoperations, and information loss, failing to meet the needs of distribution network automation and intelligent operation and maintenance.

Method used

By using hierarchical Bayesian and evidence fusion computing to calculate device health, circuit integrity, and energized status, a comprehensive diagnostic code is generated to drive the electric latch, mechanical locking pin, and magnetic latching relay to lock. Through passive dry contacts and encrypted NB-IoT dual-link reporting, accurate diagnosis and power-off self-holding locking linkage are achieved.

Benefits of technology

It enables accurate fault identification and reliable interlocking of high-voltage interlocking devices under multi-source sensing, ensuring continuous and secure physical isolation in any power outage scenario, improving operational resilience and information transparency, and supporting rapid deployment in multiple scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121546508A_ABST
    Figure CN121546508A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-stage fault diagnosis and locking linkage method of a high-voltage locking device, relates to the technical field of high-voltage locking, and is suitable for 3.6-40.5 kV power distribution equipment. The method comprises the following steps: firstly, synchronously sampling and self-checking bus voltage, fault current and temperature and humidity in a cabinet, and packaging a multi-source data frame; the device health degree, the loop integrity and the electrification state are calculated through hierarchical Bayesian and evidence fusion and are compressed into comprehensive diagnosis codes; a locking action sequence is generated according to the diagnosis code look-up table, and the electric lock catch, the mechanical lock pin and the magnetic latching relay are driven to be sequentially closed and self-locked after power loss; a locking completion vector and a retention margin are split into a bulletin bit frame and a state packet frame, the bulletin bit frame and the state packet frame are reported through a passive dry contact and an encrypted NB-IoT double link, communication heartbeat is automatically adjusted and power consumption is indicated according to a continuation index, accurate diagnosis, reliable locking, far-end transparency and long-time retention are realized, and the safety of a distribution network is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of high-voltage locking, in particular to a multi-stage fault diagnosis and locking linkage method of a high-voltage locking device. BACKGROUND

[0002] In the ring network cabinet, metal-enclosed switchgear and box-type substation of 3.6-4.5 kV distribution network, the high-voltage locking device undertakes the multiple safety functions of live display, fault indication, misoperation prevention interlocking and remote reporting. The existing devices often use single-channel voltage indicator light or electric mechanical locking, which lights up the LED through the sampling coil of the primary bus voltage, and realizes the door lock linkage through the normally open / normal closed contact; a few products add a primary transformer power supply or a small-capacity storage battery to maintain short-time self-power supply. However, the above-mentioned schemes generally have four limitations: first, the sampling link is single and lacks self-checking, and the saturation of the transformer or the drift of the sensor will lead to false indication; second, the fault criterion is based on a fixed threshold, which cannot distinguish between real line faults, internal device faults and misoperations; third, the locking chain usually only includes an electric lock and a door lock, and the mechanical lock pin, magnetic latching relay and other links lack cooperation, and are easy to unlock after power failure; fourth, the remote side relies on dry contacts or simple serial ports, and the reporting information has low granularity and is lost after power failure. With the advancement of distribution network automation and smart operation and maintenance, the demand for multi-stage diagnosis, hierarchical release, power failure retention and remote tracking of the operation and maintenance center is increasingly prominent, and the existing technology has been difficult to meet the requirements of intrinsic safety and visual management under the new situation.

[0003] In the high-voltage distribution scene where there is a lack of stable external power supply and the electromagnetic environment is complex, how to use the primary side voltage, current and environmental multi-source information to progressively diagnose the device health, loop integrity and live state and compress it into a unique comprehensive diagnostic code, and then drive the electric lock, mechanical lock pin and magnetic latching relay to form a power failure self-retaining locking chain, while releasing the locking results and energy continuation margin through dry contacts and low-power cellular links, to ensure millisecond-level local isolation, minute-level remote transparency and hour-level lock position persistence after a fault occurs.

[0004] If this technical problem cannot be solved, the site may mistakenly enter the live interval due to false indication or locking failure when a fault occurs, and the dispatching center cannot accurately dispatch due to lack of information; if the power outage continues, the super capacitor voltage decay or residual magnetism degradation will also cause the lock to loosen prematurely, causing secondary safety accidents and widespread power loss. SUMMARY

[0005] (I) Technical problems solved

[0006] In view of the deficiencies of the prior art, the multi-stage fault diagnosis and locking linkage method of the high-voltage locking device is provided, the health degree, the loop integrity and the live state are calculated through hierarchical Bayesian and evidence fusion, and are compressed into a comprehensive diagnostic code; the locking action sequence is generated according to the diagnostic code table, the electric lock, the mechanical lock pin and the magnetic latching relay are sequentially closed and de-energized self-locking, the locking completion vector and the holding margin are split into emergency frames and state package frames, and are reported on the passive dry contact and encrypted NB-IoT double link, and the communication heartbeat and the indication power consumption are adjusted according to the continuation index, precise diagnosis is realized, and the safety of the distribution network is improved, so that the technical problems described in the background art are solved.

[0007] (Two) Technical solutions

[0008] To achieve the above object, the following technical solutions are adopted: The multi-stage fault diagnosis and locking linkage method of the high-voltage locking device comprises the following steps: synchronously collecting primary data through a bus voltage sampling coil, a residual current transformer and an in-cabinet temperature and humidity probe, self-checking the sampling link and power supply state, and packaging the self-checking result and the primary data into a multi-source data frame according to a time stamp; The multi-source data frame is input into a hierarchical Bayesian inference network to obtain the confidence of the device health degree, the loop integrity and the live state, and a confidence vector is formed through evidence fusion, which is compressed into a comprehensive diagnostic code as a unique trigger identifier; The controller retrieves an entry in the interlocking mapping table according to the comprehensive diagnostic code, generates a locking action sequence, drives the electric lock, the mechanical lock pin and the magnetic latching relay to execute in turn according to the priority, and forms a locking completion vector; The locking completion vector and the holding parameter are packaged into emergency frames and state package frames, which are synchronously uploaded through a passive dry contact and an encrypted low-power communication; the continuation index is calculated based on the super capacitor and the residual magnetism, and the heartbeat is adaptively configured according to the continuation index.

[0009] Further, the bus voltage sampling coil and the residual current transformer are used to obtain the alternating current and rectify, the in-cabinet temperature and humidity are collected, and the primary data with a unified time stamp is synchronously generated; the controller uses a variable integral window to average the rectified waveform, the integral window is limited to half a power frequency cycle to four cycles, a direct current power voltage field is formed, and the sampling link continuity and the voltage upper and lower limit self-checking result are written into the multi-source data frame.

[0010] Further, a breathing window is set, the mean and deviation of the temperature and humidity sequence in the window are calculated to obtain the temperature drift and humidity drift, and if both exceed the threshold, a link abnormality identifier is generated; when packaging the multi-source data frame, the fields are arranged in the order of time stamp, bus voltage, direct current power voltage, fault current peak value, temperature mean value, humidity mean value, self-checking result and CRC check, and byte alignment is performed.

[0011] Furthermore, the hierarchical Bayesian inference network consists of device health nodes, loop integrity nodes, and energized state nodes, and uses directed acyclic edges to represent conditional dependencies. The nodes receive observations such as bus voltage, peak fault current, DC power supply voltage, average temperature, average humidity, and link anomaly identifiers from the multi-source data frames, update priors using expectation maximization, and output three confidence scores through marginalization inference.

[0012] Furthermore, the three confidence scores are multiplied by a weight vector that can be remotely distributed and persistently stored to obtain a comprehensive score, and a two-digit comprehensive diagnostic code is generated based on a configurable segmented Gray mapping function. The controller constructs a signature using the timestamp and random salt, hashes the comprehensive diagnostic code, and writes it together with the timestamp into a read-only memory as the unique trigger identifier output.

[0013] Furthermore, the comprehensive diagnostic code is XORed from Gray to binary to obtain the interlocking index, and the interlocking index is used to retrieve the preset interlocking mapping table; the interlocking mapping table includes the weight columns of electric latches, mechanical latches and magnetic latching relays and the operating mode adjustment coefficients. The controller calculates the priority by matrix and vector product and generates the locking action sequence, while preparing the locking completion vector field.

[0014] Furthermore, the generated locking action sequence is output by a programmable pulse width modulator. The controller integrates the DC bus voltage and actuator current in real time within each actuator pulse to obtain the injected energy and compares it with the minimum drive energy. When the current peak is detected to be continuously exceeding the limit, the pulse is segmented or retransmitted. After the action, the limit switch and Hall element are read and combined to generate the locking completion vector, and the holding energy is calculated accordingly.

[0015] Furthermore, the interlocking completion vector and holding parameters are split and encapsulated into an emergency bit frame and a status packet frame. The emergency bit frame contains a fault level bit and an interlocking index and is mapped to a passive dry contact and local bus forwarding. The status packet frame uses block encryption and carries a timestamp and counter, and performs byte alignment and CRC check and is persistently recorded. The two types of frames are sent sequentially by the low-power cellular communication module within the same session.

[0016] Furthermore, energy sustaining and decay management includes: implementing high-speed and low-speed two-stage discharge for the supercapacitor and obtaining the switching time based on energy conservation; and using a time- and temperature-coupled residual magnetism prediction model to calculate and predict residual magnetism for the magnetic latching relay. A sustaining index is constructed based on the remaining energy of the supercapacitor, the predicted residual magnetism, the reset required energy, and the reference residual magnetism. The communication heartbeat and the indication heartbeat are adaptively configured according to high and low thresholds.

[0017] (III) Beneficial Effects

[0018] This invention provides a multi-level fault diagnosis and interlocking linkage method for high-voltage interlocking devices, which has the following beneficial effects: In the multi-source sensing and self-testing stage, voltage, current and environmental quantities are uniformly encapsulated into multi-source data frames, and a unique comprehensive diagnostic code is generated by hierarchical Bayesian reasoning and evidence fusion. This eliminates the problem of false alarms and missed alarms that are common in traditional threshold-based devices, making fault identification both accurate and interpretable, and truly achieving comprehensive measurement and accurate judgment.

[0019] After the comprehensive diagnostic code is converted into a locking action sequence through the interlocking mapping table, the electric latch, mechanical locking pin and magnetic latching relay close in coordination according to the matrix priority. The pulse energy is integrated in real time to ensure that each drive is just right. After power failure, it still relies on the magnetic-electric dual holding energy to firmly lock the position, so as to maintain continuous and safe physical isolation in any power interruption scenario.

[0020] The supercapacitor segmented discharge and residual magnetism decay prediction together constitute the sustaining index adaptive model. The system can automatically adjust the communication cycle and indicator duty cycle according to the energy margin, and actively issue low energy warnings before the threshold is reached. The locking time is improved from fixed to calculable and extendable, turning passive emergency repair into proactive maintenance, and greatly improving the resilience of operation and maintenance.

[0021] The status encapsulation adopts a layered design of emergency bit frames and status packet frames. Dry contacts provide millisecond-level hard alarms. NB-IoT uploads complete data in a loop through encrypted sleep dual-state links. Any link failure can be covered by the backup channel, achieving bidirectional transparency between the field and the dispatcher. At the same time, frame alignment and block encryption take into account both narrowband resources and information security, reducing the cost of remote management and control.

[0022] The weight matrix can be refreshed online, and all conflict suppression, energy conservation, and security strategies are parameterized. It not only supports rapid deployment in multiple scenarios such as urban ring networks, underground utility tunnels, and mountain substations, but also fully demonstrates the overall advantages of this solution in terms of hardware and software decoupling, creative integration, and system collaboration. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of the multi-level fault diagnosis and interlocking linkage method of the high-voltage interlocking device of the present invention. Detailed Implementation

[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] Please seeFigure 1 This invention provides a multi-level fault diagnosis and interlocking linkage method for high-voltage interlocking devices, including: In the real-time operation and maintenance of primary high-voltage power distribution equipment, if on-site personnel want to safely approach the cabinet door, they must first know the energized status of the equipment, the integrity of the circuit, and the health of the device itself. However, in actual work, the monitoring is often distorted due to the single sampling channel and the fragile power supply chain, which in turn triggers misjudgment and misoperation.

[0026] To completely resolve this long-standing problem, this solution integrates bus voltage, residual current, and internal environmental parameters. It constructs multi-source data frames using an integrated energy harvesting and self-testing mechanism, and then progressively outputs locking commands through hierarchical reasoning and mapping decisions. This achieves triple coupling and coordination of information, energy, and logic, completely eliminating the constraints of single-point failure on safety locking, thus laying a solid foundation for subsequent progressive judgment, interlocking decisions, and status release.

[0027] Step 1 aims to achieve the first verification checkpoint of data credibility and energy reliability by synchronously acquiring and self-testing multiple raw signals, providing a unique and unambiguous multi-source data frame for subsequent diagnosis and execution.

[0028] If the device is to maintain its monitoring and interlocking capabilities in scenarios where the external power supply is unstable or completely absent, it must rely on the primary system's own energy for power extraction, while ensuring that each sensor link is free from drift and interruption and mutually verifies each other. Therefore, this step focuses on the parallel parallel operation of energy extraction and self-testing, first solidifying the energy foundation and then locking in the true value of the data, thereby providing accurate input for subsequent progressive judgments with a logically necessary sequence.

[0029] Step 101, Synchronous Acquisition and Energy Mapping: Under normal system operation or fault conditions, the bus voltage It appears in the form of a power frequency sine wave.

[0030] The device extracts the bus voltage through a high-saturation-resistant sampling coil. Then, through full-wave rectification and pulse load matching network, the periodic energy is mapped to the DC bus. To avoid the risk of not being able to extract energy under light load, a dynamic integration window strategy is introduced, as shown in the following formula: ; bus voltage : Real-time voltage of primary bus; value range is ±20 percentage points above and below the rated phase voltage; main function is energy input and energization criterion; DC power supply voltage The average voltage supplied to the device after rectification; the upper limit of the value range does not exceed the device's withstand voltage, and the lower limit is higher than the minimum holding voltage; sampling period. Dynamically adjusted integral window; automatically extended during off-peak load periods and automatically shortened during peak load periods to maintain constant power; integral start point. The start time of the current sampling period is triggered by the device clock; By using a dynamic integration window to accumulate weak energy into a sufficient DC voltage, the monitoring path can still operate normally even under light loads at night, thus ensuring that the power extraction link and the data link are from the same source and have the same base.

[0031] When a short circuit or single-phase ground fault occurs in the line, the fault current... The surge causes the current transformer to immediately output an induced voltage that enters the rectification-energy storage branch; to accurately estimate the available transient energy, a pulse equivalent energy density model is introduced: ; Where: the starting point of integration The moment when the fault current begins to rise significantly is detected by a current slope trigger; pulse duration This refers to the effective window for maintaining a high amplitude of the fault current. The upper limit can be determined by protection settings or automatically truncated from the actual waveform to limit the energy integration range. Line current during abnormal conditions; its amplitude is much greater than the rated current, used for transient energy extraction; equivalent impedance. The equivalent impedance of the secondary side of the current transformer; its magnitude determines the energy conversion efficiency; pulse energy. During the duration of the fault Energy that can be captured and stored within; When pulse energy Exceeding the self-test threshold The system triggers rapid energy harvesting, quickly raising the DC bus through transient high-energy injection, providing extra margin for subsequent self-testing and frame sealing, and preventing detection blind spots due to insufficient energy in the early stages of a fault.

[0032] Multi-source sensing and self-testing simultaneously collect voltage, current, temperature, and humidity data and immediately perform link integrity verification. This not only shields the front end from hidden faults such as transformer saturation and sampling disconnection, but also merges the self-test results with the original quantities into a single data frame output. Subsequent discrimination layers can directly call upon the data without repeating the checks, greatly reducing the number of levels and time in the fault diagnosis link. This achieves synchronous and reliable measurement and power supply, laying the first line of defense for the reliability of the entire link.

[0033] Step 102, Link Self-Test and Multi-Source Framing: Cabinet temperature With humidity The sampling accuracy can fluctuate with the seasons and workload; therefore, a breathing window needs to be set. Perform a mean-slope joint test on continuous multi-period sampling: ; ; Where: breathing window The set number of continuous sampling points has an upper limit that automatically increases when the environment is stable to filter out occasional noise, and a lower limit that shortens when there are rapid changes in temperature and humidity to improve sensitivity; cabinet temperature : No. The cabinet temperature reading at the time of the next sampling; real-time correlation with ambient temperature; average temperature. The arithmetic mean of temperature samples within the current breathing window is used as a reference baseline for temperature drift; humidity inside the cabinet. : No. The relative humidity reading inside the cabinet at the time of the first sampling; reflects the humidity content of the air. Average humidity The arithmetic mean of humidity samples within the current window serves as the benchmark for calculating humidity drift; temperature drift... This represents the average deviation of the temperature inside the cabinet relative to the mean within a breathing window; humidity drift. This indicates the average deviation of the relative mean humidity within the cabinet in the same window; both are used to determine whether the sensor is off-center. When temperature drift Humidity drift Simultaneously, an alarm is triggered if the value exceeds a threshold. A breathing window is used to monitor drift in slowly changing environmental quantities, providing early warning of sensor aging without adding extra hardware, ensuring that subsequent judgment algorithms are not skewed by environmental drift. After completing the link self-test, the local CPU timestamps... Bus voltage DC power supply voltage Fault current peak value Average temperature Average humidity and self-inspection results Write to a unified structure and add a signature. : ; Where: peak fault current The maximum amplitude of the line current detected within the pulse energy harvesting window provides a reference for the fault type and energy harvesting intensity; timestamp High-resolution local clock; ensures horizontal comparison consistency; self-test results. A Boolean identifier generated by combining link integrity verification, power supply voltage detection, and sensor drift determination is used to quickly identify the health status of the sampled link; multi-source data frames. : Unique input object; encapsulates energy supply and data together to ensure that subsequent decision layers do not need to care about energy status; Cyclic Redundancy Check Frame check code, to prevent bit flipping, is a 16-bit check value calculated by a fixed polynomial for all the aforementioned fields, ensuring the integrity and correct parsing of the frame during transmission in a strong electromagnetic environment. By merging the energy harvesting status and multi-source data into a single frame and adding a signature verification, complete information can be provided to subsequent layers at once, reducing communication overhead and improving robustness; simultaneously Verification ensures that information is not tampered with in strong electromagnetic environments.

[0034] By constructing a steady-state energy system through bus voltage sampling decoupling and transient fault current energy harvesting, and ensuring data accuracy through environmental quantity monitoring and multi-source data frame encapsulation, the energy chain and data chain are naturally coupled and mutually verify each other. Environmental drift monitoring and unified framing transform temperature and humidity deviations from passive alarms into real-time compensation and sensor aging predictions. The unified timestamp and cyclic check code design ensures that any bit flip will be identified at the frame level. The dispatch center can reconstruct the entire situation from a single frame, eliminating the need for multi-frame stitching, significantly improving fault tracing efficiency and reducing communication bandwidth usage.

[0035] The resulting multi-source data frames It carries both link health information and critical system data, becoming the sole and reliable entry point for subsequent progressive discrimination layers; when multi-source data frames... When entering the hierarchical Bayesian inference network, the device can be certain that any defects have been located or marked in the self-inspection layer, providing sufficient, clean, and traceable initial conditions for the second step of progressive discrimination and unified coding, thereby ensuring that the entire diagnostic-locked chain is logically smoothly connected without leaving any hidden dangers.

[0036] In step one, through a dual strategy of dynamic energy harvesting and transient energy replenishment, and a dual mechanism of environmental drift monitoring and multi-source data frame encapsulation, the device obtains a unique input entity—the multi-source data frame—that contains both energy reliability and link health. However, reliable data alone is insufficient to support safety interlocking; it is necessary to further transform the dispersed voltage, current, environmental, and self-test information into judgments that are truly meaningful for the interlocking chain.

[0037] Step 2 aims to leverage hierarchical probabilistic reasoning and conflict information fusion to integrate multi-source data frames. The original observations are progressively extracted to determine the health of the device. Circuit integrity With charged state The reliability is reset three times, and finally compressed to generate a comprehensive diagnostic code. It serves as the sole trigger identifier for the closed chain.

[0038] Complex conditional dependencies exist among the observations: bus voltage anomalies may originate from short circuits or transformer malfunctions; surges in fault current may be accompanied by temperature rises or sensor malfunctions. Without modeling these dependencies, any threshold-based judgment will fall into a dilemma of false negatives versus false positives. Therefore, this step first uses a Bayesian network to characterize the causal relationships, thereby obtaining three types of confidence scores. However, the Bayesian assumption of independent observations is prone to conflicts when faced with high noise and missing values. To address this, the DS evidence theory is introduced to perform a secondary fusion of the confidence scores.

[0039] After dual reasoning, the system generates a comprehensive diagnostic code based on threshold mapping and weight sorting. The mapping process is then written to a read-only table for subsequent review. Therefore, the chained process from probability extraction to codeword compression preserves the transparency of reasoning while forming a single identifier that the closed chain can directly recognize.

[0040] Step 201, Hierarchical Reasoning and Confidence Calculation: To accurately describe the conditional dependencies between the original observations, we first consider the device health of the device health nodes. The loop integrity of a loop integrity node and the charged state of the charged state node This forms a three-layer directed acyclic graph, where the upper-layer nodes pass on prior information sequentially downwards; the lower-layer observation nodes consist of multi-source data frames. The corresponding elements directly drive the process. Considering that actual measurements often contain quantization errors, the network learning phase adopts Beta-prior update EM iteration to harmonize the prior and likelihood without offline calibration. Its core posterior inference formula is: ; Where: Event Index The discrete index used to iterate through the set of observed events, increasing from 1 to the total number of observations; the event set : Composed of multi-source data frames The decomposed sequence of observed events, the first Observations obtained from decomposing multi-source data frames, such as abnormal bus voltage amplitude, increased fault current peak, and environmental drift indicators; prior probability. Device health priors are initialized based on historical fault statistics. Conditional likelihood, range of values This expresses the strength of the dependence between observation and health status, under the assumption... Under the premise that it is established, observe events Probability of occurrence; device health : Indicates the assumption that the device is in a healthy state after all observed events have been observed. The range of values ​​for the posterior probability of the statement being true The higher the value, the healthier the device; Alternative Hypothesis The set of all other hypotheses mutually exclusive with the health hypothesis, including states such as minor failures, severe failures, or sensor link failures, is used for denominator normalization to ensure that the sum of all posterior probabilities is 1; conditional probability. In the alternative hypothesis Observational events at the time of establishment The probability of occurrence; and The contrast determines how well an event can distinguish different hypotheses; circuit integrity Check if the focusing circuit is broken, short-circuited, incorrectly connected, or has poor contact; check the energized state. The determination is whether a primary busbar / circuit is energized; prior probability. The prior confidence of the alternative hypothesis set before observation, summed with It meets the normalization condition.

[0041] By using directed acyclic graphs and posterior updates, the system provides the device health in a single inference iteration. The precise values ​​are obtained by taking into account the observed environmental quantities and energy harvesting status, thus avoiding the risk of overall judgment collapse due to distortion of a single parameter.

[0042] Bayesian inference assumes that observations are independent, but when there is packet loss or interference in the sampling process, the same event may be described by multiple observations with opposite tendencies, leading to confidence oscillations. To resolve this conflict, the basic probability assignment of DS evidence theory is introduced. Treating the three confidence levels as mutually exclusive propositions, and performing a second fusion according to the following formula, the overall confidence level is obtained. : ; In the formula: , Basic probability distribution from different observation channels, with value ranges ; Propositional subsets , , which are the elements of the proposition set supported by the two sources of evidence; Proposition set Any subset of {device healthy, circuit intact, energized}; overall confidence level After fusion, the set of propositions Support; range of values ; By incorporating the conflicting parts of mutually exclusive propositions into the negation terms through DS fusion, the support for a proposition can be automatically reduced when contradictions are observed, rather than being forcibly rejected. This significantly improves the stability of confidence and provides a smooth input for subsequent encoding mapping.

[0043] Hierarchical Bayesian networks explicitly model the three implicit factors of device health, loop integrity, and energized state, and then use evidence fusion mechanisms to resolve conflicts in multi-source observations, so that stable confidence can be output even in high-noise or undersampled scenarios. The diagnostic results can be traced back to each observation node and the prior update process, which meets the compliance requirements of the power cloud platform for safe and interpretable algorithms.

[0044] Step 202, Confidence Compression and Diagnostic Code Generation: Obtain the fused confidence vector Then, based on the weight vector Construct a comprehensive score : ; Where: weight vector : Set manually by security priority; meets the requirements Overall score : Range of values A higher value indicates a lower risk. To transpose, the row vector Convert to column vector; Then follow the Gray-segmented mapping function. Generate comprehensive diagnostic code : ; Where: segmented threshold Based on the statistical settings of the actual drills; meets the requirements. Comprehensive diagnostic code Two-bit Gray code; one-to-one correspondence with the locking mapping table index; Gray code has single-bit gradient characteristics, which can avoid the risk of codeword flipping caused by threshold jitter; after being combined with weighted, priority can be quickly adjusted according to the security focus of different stations without modifying the underlying inference model.

[0045] To ensure comprehensive diagnostic codes To prevent misreading in the communication link, using timestamps and random salt Generate a one-way hash signature, that is : ; Timestamp : Continue using multi-source data frames Clock accuracy better than milliseconds; random salt Extracted from a hardware entropy source to prevent replay; signature value Fixed-length hash, used for frame-level authentication; Then The signature-mirror dual mechanism writes to the execution buffer and mirrors it into a read-only EEPROM, ensuring that the generation source can be traced even if the CPU is reset. This enables comprehensive diagnostic codes. It has both tamper-proof and traceability properties. Once the execution chain unexpectedly jumps, the link failure can be quickly located by comparing the image in the EEPROM, which greatly improves the maintainability of the system under extreme conditions.

[0046] The comprehensive diagnostic code uses two-level compression with adjustable weights and Gray encoding to reduce the three-dimensional confidence level to two-bit symbols. The execution layer only needs one table index to determine the locking strategy. Codeword signature and image solidification ensure that any tampering or mistransmission is detected instantly. Maintenance personnel can still trace the most recent legitimate diagnosis after a power failure and reset, which greatly improves information security and maintainability.

[0047] Through the Bayesian-DS two-layer inference in step 201, the multi-source data frames are... Extracted into a three-dimensional confidence vector Then, through step 202, weighted encoding, Gray encoding, and signature mirroring pipeline compression is performed to generate a comprehensive diagnostic code. Thus, step two, while ensuring transparency in reasoning, achieves multiple synergies of information compression, conflict mitigation, and secure signature, laying a solid logical foundation for the rapid, accurate, and traceable linkage of the locking device.

[0048] Step two employs a four-layer progressive mechanism—probabilistic reasoning, evidence fusion, weighted averaging, and codeword signing—to integrate the mixed data from multiple sources into the data frames. The electrical quantities, environmental quantities, and link health information are condensed into a comprehensive diagnostic code that is unique and traceable. The diagnostic code generation process retains the decomposable access to three-dimensional information on device health, circuit integrity, and energized status, while compressing the output into a minimally simplistic two-bit Gray code format. This significantly reduces the parsing burden on the execution layer and ensures link security through a signature-mirror double-insurance system.

[0049] The previous stage compressed multi-source probabilistic information into a unique and traceable two-digit Gray comprehensive diagnostic code. Simultaneously, a read-only image is written, thus accurately characterizing the fault type and risk level on both the logical and informational ends. However, to truly prevent misoperation and ensure the safety of personnel and equipment, digital identification alone is far from sufficient; this digital key must be further translated into a physical locking action that can directly affect primary equipment.

[0050] Step 3: Using the interlocking mapping table as the central point, integrate the diagnostic codes... Transform into a locking action sequence Furthermore, through energy self-sustaining and feedback self-verification, it ensures that the locked state remains reliable and visible even in the event of any single point of failure or power outage.

[0051] Although the fault risk level has been changed from the comprehensive diagnostic code It is clear that there are many operating mechanisms inside the cabinet. Without a unified mapping, there may be chain misalignment, such as the electric lock being closed but the mechanical lock pin not being released, or the magnetic latching relay flipping and then loosening. Therefore, the interlocking mapping table is first retrieved to obtain the locking matrix in a one-to-one correspondence of code and index. Then, an executable pulse sequence is generated based on the matrix and scheduled to each actuator.

[0052] Step 301, Interlocking Retrieval and Decision Scheduling: Before entering the execution layer, the comprehensive diagnostic code is first checked. Perform Gray-to-binary decoding to generate interlocking indexes. Considering the single-bit gradient characteristic of Gray codes, the index calculation uses the XOR cumulative algorithm: ; In the formula: the high digit of the comprehensive diagnostic code The first bit, the most significant bit of Gray; its value... ; Low-order part of comprehensive diagnostic code The second bit, the least significant bit of Gray; its value... XOR operation : Ensure single-bit jitter does not cross levels; interlocking index Binary index , which points to the interlocking mapping table; XOR cumulative decoding ensures that Gray code flipping only causes the index to increment or decrement by 1. Combined with the fault tolerance segment of the mapping table, minor link jitter will not directly trigger cross-level actions, thus improving the execution safety margin.

[0053] Interlocking mapping table The row index and column vector store the trigger weights of the three executors. The decision-making logic first loads weights based on the device's operating mode (maintenance / operation), and then outputs a priority vector using matrix-vector multiplication. : ; Where: weight : Corresponding to electric latches Mechanical locking pin Magnetic latching relay The importance of actions, weighting factors, are preset according to the site strategy; coefficients Operating mode adjustment factor, value Lifting under maintenance Weights; Priority Vector The larger the value, the earlier the action is executed, which drives the sequence sorting. By considering both risk level and operating mode simultaneously using a matrix-vector product approach, customized locking action sequences can be quickly generated for different sites without modifying the firmware, reflecting adaptive operation scenarios.

[0054] The combination of interlocking index and weight matrix directly maps the digital risk level to the action sequence of the electric, mechanical and magnetic latching actuators. The site can quickly switch between maintenance priority and production priority modes by updating the weights without modifying the underlying program. Gray decoding limits the range of policy jumps caused by jitter, making interlocking decisions both flexible and safe.

[0055] Step 302, Action Sequence Generation and Self-Maintaining Execution: According to the priority vector Sort to obtain a sequence list Generate locking action sequences using programmable pulse width. Let the first... Actuator pulse width With pulsed injection energy satisfy: ; Where: pulse width , for the first The upper limit of the pulse duration preset by the actuator is determined by the coil thermal capacity and power supply capability, while the lower limit must ensure that the energy is not lower than the minimum drive requirement; This represents a set of three types of actuators. The result after sorting by the current priority vector; Pulse Injection Energy Within a single drive pulse, from the DC bus to the first The actual electrical energy injected into the actuator coil; DC bus voltage The energy source is obtained from the energy harvesting chain in step one, and is monitored in real time. It must be higher than the actuator's excitation voltage. Actuator current : No. The instantaneous current of the actuator during coil energization depends on the coil resistance, inductive reactance, and power supply dynamic capability, which are sampled in real time by a Hall sensor. Minimum energy threshold : The minimum mechanical energy required for the actuator to complete its action, the minimum energy specified in the actuator specification; The drive energy is checked in real time by integral verification. If it is lower than the threshold, the pulse is automatically extended or re-transmitted to ensure that the actuator is free from jamming and half-stroke, and to avoid false locking.

[0056] After the three actuators have completed their sequential actions, the system immediately reads the status of their respective travel detection switches. and magnetic field The locking completion vector is generated by combining elements according to the unified Boolean criterion. If any element is 0, a compensation loop is triggered; if all elements are 1, the power failure retention criterion is entered, and retention energy is generated. : ; Where: supercapacitor capacity The equivalent capacitance of a supercapacitor reflects its energy storage capacity; the voltage of a supercapacitor... The real-time voltage across the supercapacitor at the calculated moment gradually decreases as it discharges, and is obtained by ADC sampling; the residual magnetic flux density of the magnetic circuit. The residual magnetic flux density of the core of a magnetic latching relay indicates the magnitude of the magnetic potential that can be continuously supplied after power loss; maintaining the magnetic field. The actual magnetic field strength of a magnetic latching relay in the latched state, together with the number of coil turns and residual magnetism, determines the latching force; proportional coefficient : Converting magnetic energy into equivalent electrical energy, magneto-electric conversion factor, obtained through experimental calibration; preserving energy This indicates the total available energy used by the device to maintain interlocking and indication after a power failure, consisting of two parts: capacitor energy storage and magnetic holding energy. The preset energy required for actuator reset is a boundary condition; the energy required to maintain the actuator is... The required power is higher than the actuator reset requirement. Only then can it be determined that the success was maintained; It should be noted that typical vector fields include: latch completion vector. : Corresponding to the positioning and energy determination positions of the electric latch, mechanical locking pin, and magnetic latching relay, respectively; priority vector : Calculated from the interlocking mapping table and operating coefficients, used to sort and generate the interlocking action sequence; weight vector : In the interlocking mapping table and Combined use; confidence vector Outputted by hierarchical reasoning, used for comprehensive scoring and coding.

[0057] By incorporating both electrical and magnetic energy into the holding energy assessment, the system can quantify the holding margin even in scenarios involving coupled capacitor and magnetic attenuation, avoiding hasty judgments of successful locking based solely on energy from one side and improving robustness under extreme conditions. Real-time integration of pulse energy ensures the actuator receives just the right amount of drive energy and limits peak current, preventing coil thermal aging. The electro-magnetic composite holding criterion can still quantify the locking margin even under conditions of supercapacitor attenuation or high-temperature demagnetization, triggering maintenance in advance rather than waiting for a loss of lock-up, thus enhancing the system's safety resilience in long-term power outage scenarios.

[0058] Step 301: Transform the comprehensive diagnostic code Parsed as an interlocking index And generate a priority vector by combining the weight matrix. Step 302 then proceeds according to the priority vector. Synthetic locking action sequence Real-time verification of driving energy And maintain energy using electro-magnetic dual energy conservation verification. .

[0059] Step 3 completes the cross-domain mapping from digital diagnosis to physical locking: Gray code XOR decoding ensures index stability, weight matrix enables scene adaptive sorting, pulse energy integration ensures that each drive output is equivalent to input, and the electro-magnetic composite energy model provides a quantitative guideline for continuous locking under power failure environment.

[0060] In the first three stages, three lines of defense have been established: multi-source energy acquisition and reliable measurement, probabilistic progression and gray code compression, and matrix interlocking and energy self-holding. This has successfully solidified the fault risk into a blocking action and locked it locally. However, most high-voltage primary equipment is distributed in a wide-area distribution network. If the real-time blocking status and remaining holding margin cannot be synchronously pushed to the dispatch center, external maintenance will still be trapped in an information silo where the site is not visible and the remote end is not transparent. At the same time, if the energy buffer after the locking action lacks dynamic management, it may also fail during long-term power outages due to supercapacitor self-discharge or residual magnetism decay, causing secondary risks.

[0061] Step four aims to encapsulate the latching action result and the holding energy dynamics into an uplink frame. Synchronized to the remote end via multi-channel robust transmission, and through continuous exponential... Adaptive control of the supercapacitor-residual magnetism dual energy pool makes the device information visible and the locking position last longer.

[0062] After the interlock is completed, the site needs a cheap and reliable channel to upload the critical status; at the same time, when the external power supply is lost, the only way to maintain the lock position and indication is to rationally schedule the energy storage components.

[0063] To this end, the field status is first segmented and encapsulated using a link priority strategy, and then published in parallel through three chains: dry contact, local bus, and NB-IoT. While the information loop is closed, a decreasing model is used to dynamically predict the supercapacitor and remanent magnetization decay to determine the sustainability index. If the value falls below the threshold, a phased compensation or early warning will be triggered.

[0064] Step 401, State Encapsulation and Multi-chain Deployment: To balance the immediacy of dry contacts with the broadband of cellular chains, the locking completion vector is... and maintain energy First, it is divided into two levels: emergency bit frames and status packets. The former only contains fault level bits. Interlocking indexes The latter then carries slow variables such as energy margin and temperature and humidity trends. Frame length Calculation formula: ; Where: frame length Total number of bits transmitted, used to estimate channel duty cycle; Frame header length : Fixed field, determines the minimum frame length, including synchronization word and frame sequence number; Valid field length : No. Field raw bits; The number of bits of the original data for each variable field, such as energy retention, temperature and humidity trends, or sustainability index, changes dynamically with the business content. Summation index traverse all frames in this frame in turn. One variable field; Alignment compensation : The padding bits generated by CRC alignment make each word aligned with the byte boundary; By layering frames and aligning fields, a publishing chain of one-bit emergency alerts and multi-word detailed reports can be formed: short frames trigger master station alarms in milliseconds on the dry contact-RTU internal bus, while long frames are uploaded in time-division multiplexing in the NB-IoT low-power time slots, which ensures timeliness and avoids narrowband congestion.

[0065] The NB-IoT module operates in two states: encrypted and sleep; the encrypted state uses an improved spreading key. Generate a symmetric encryption vector for the uplink frame. Perform block encryption to obtain ciphertext blocks. : ; Where: ciphertext block After encryption, the first Uplink data in blocks is the actual data payload sent to the NB-IoT network; uplink frame blocks : No. Plaintext blocks; the first block of an uplink frame obtained by dividing it into fixed byte segments before encryption. The block contains plaintext data, including business fields such as latch status, energy holding or environmental quantity; key stream : with session key Block counter conduct The pseudo-random bit sequence obtained after encryption is used as the key stream and XORed with the plaintext. counter The monotonically increasing count value for each block is used as... Input vector; Keystream generation function; Block encryption allows AES computation to be performed in stages when MCU resources are limited, while utilizing counters. To resist replay, the module enters a sleep state after encryption, retaining only the clock and counter, significantly reducing static current and ensuring that the NB-IoT link can maintain a periodic heartbeat during long power outages.

[0066] At the same time as generating the interlocking emergency bit frame, the fault level bit is... Direct mapping to passive contact combination The double-pole-double-throw structure of the mechanical linkage relay provides hard contact for the two SCADA channels: high-level... Normally closed terminals are disconnected, and normally open terminals are closed; the opposite applies to lower-level terminals. Because dry contacts do not require external power, even if the NB-IoT module is in sleep mode, SCADA can still obtain alarm status in milliseconds, achieving fast local-complete uplink dual-layer synchronization.

[0067] Emergency bit frames reach SCADA in milliseconds via dry contacts, and status packets are uploaded in time-division via encrypted NB-IoT. The layered frame and three-link design ensure that any link failure will be covered by the other link, maintaining remote transparency even in complex electromagnetic environments and weak signal areas. Block encryption and sleep heartbeat balance information security and ultra-low power consumption, enabling a data lifeline during long-term power outages.

[0068] As a supplementary explanation, the retention parameters are a set of fields used for encapsulation and sustainment evaluation, including previously defined quantities that were invoked in steps three and four: supercapacitor capacity. Supercapacitor voltage Residual electrical energy of capacitors Remanence or predicted remanence Maintain magnetic field feedback Equivalent coefficient Reset requires electrical energy Reset requirement for residual magnetism Maintain energy Continued Index High threshold Low threshold ; Step 402, Energy Sustainability and Decay Management: After locking, the highest power consumption sources are the NB-IoT wake-up pulse and the indicator LED heartbeat. To extend the battery life, segmented discharge control is introduced, as follows: ; Where: Fast-phase current The starting power requirement is determined to meet the initial registration needs of the cellular module; the current during the slow phase is... Low-speed sustaining current minimizes static power consumption and maintains LED heartbeat; switching timing Determined by the law of conservation of energy: From the power balance equation: ; In the formula: Supercapacitor discharge current curve; high-speed discharge current A constant, relatively large current is set during the initial discharge phase to ensure the cellular module completes network registration; supercapacitor capacity. The equivalent capacitance of a supercapacitor, which characterizes its energy storage capacity; , Initial voltage and switching threshold voltage; switching time The time point from the high-speed discharge stage to the low-power maintenance stage is calculated using the energy conservation relationship in the above equation; voltage-time function The instantaneous value of the supercapacitor terminal voltage over time during segmented discharge can be approximated as a linear decreasing curve during constant current discharge. By segmented constant current discharge, high-power startup and low-power maintenance are each used appropriately, avoiding the large amount of energy wasted in the later stages of traditional constant current strategies, significantly improving the total endurance time, and ensuring the success rate of the first NB-IoT report.

[0069] Residual magnetism in magnetic latching relay It will vary depending on the temperature inside the cabinet. and time Attenuation is predicted using an exponential-linear composite model: ; Where: initial remanence The reference residual magnetism value measured at the instant the locking action is completed is determined by the manufacturer or on-site calibration; attenuation constant. : Describes the intrinsic rate coefficient of self-demagnetization of magnetic materials over time, and the value is fitted by long-term accelerated test; Temperature drift coefficient : Describes the linear influence coefficient of ambient temperature on remanence degradation; predicts remanence : Represents the moment The residual magnetic induction intensity of the iron core of the time-magnetic latching relay provides dynamic input for calculating the electro-magnetic composite latching energy; cabinet temperature The ambient temperature inside the cabinet is detected in real time by a temperature sensor; Using temperature-time bivariate prediction of residual magnetism can help identify lock-up risks in high-temperature or long-term power outage scenarios; if residual magnetism is predicted... If the voltage drops, the system will increase the LED heartbeat flashing frequency to remind the inspection team, and simultaneously issue a residual magnetism warning field via uplink frame. (This refers to the total available power of the supercapacitor.) With predicted remanence Define the holding index : ; Among them: Continuing Index Used to quantify the safety margin that the interlock can maintain under power failure conditions; residual energy of supercapacitors The available electrical energy, calculated based on the current supercapacitor terminal voltage and capacity, is used to support LED heartbeat, communication heartbeat, and necessary logic; reset requires electrical energy. The minimum electrical energy threshold required for the actuator to complete a reliable reset is the design setpoint; reset residual magnetism. The minimum residual magnetism required for reliable actuator reset is a device specification value; equivalent coefficient. : A proportionality coefficient that converts magnetic holding energy into a quantity equivalent to electrical energy; Reset requires electrical energy With reset residual magnetism Minimum reset requirement for the actuator; scaling factor Convert magnetic energy into equivalent electrical energy. If Entering normal heartbeat mode; if Enter energy-saving heartbeat mode; if This triggers a low-energy warning and forces the LED to enter rapid flashing mode. , These represent the high threshold and the low threshold, respectively. The sustain index measures both electrical and magnetic energy and drives the adaptive adjustment of the heartbeat duty cycle. When the energy margin decreases, it actively reduces power consumption and issues an early warning, which not only extends the lock-in time but also leaves ample time for maintenance personnel to handle the situation, achieving a dual effect of life extension and warning.

[0070] The segmented discharge strategy finely separates high-power startup from low-power maintenance, significantly extending the supercapacitor power supply time; the residual magnetism decay prediction combined with real-time temperature and humidity correction exposes potential lockout risks in advance; the sustain index converts electrical energy and magnetic energy to the same evaluation coordinate and drives the communication heartbeat to adapt, forming a closed link of energy monitoring-power consumption control-early warning prompts, allowing the lockout to evolve from passive static to active dynamic management.

[0071] Step 401 establishes a multi-chain release mechanism from the locked site to the dispatch center through the three-way coordination of layered frames, encrypted cells, and dry contacts; Step 402 constructs a dynamic control system for the electro-magnetic composite energy pool through a three-link system of segmented discharge, attenuation prediction, and sustaining index.

[0072] Through the implementation of step four, the interlocking device retains the rigid safety of self-holding in the event of power failure at the physical layer, and seamlessly connects the sensing interfaces between the field and the remote location at the information layer; at the energy layer, it utilizes the sustaining index... By incorporating capacitance decay and residual magnetism drop into the same monitoring coordinate system, the safety margin becomes quantifiable, predictable, and extendable. This enables the system to sustainably provide safety interlocking, prevention of misoperation, and remote visibility even in extreme environments such as power shortages, strong interference, and prolonged power outages, laying a solid, reusable, and scalable technical foundation for the inherent safety and intelligent operation and maintenance of power distribution networks.

[0073] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0074] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0075] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0076] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0077] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A multi-level fault diagnosis and interlocking linkage method for high-voltage interlocking devices, characterized in that, include: The primary data is collected synchronously through the bus voltage sampling coil of the high-voltage interlocking device, the residual current transformer and the temperature and humidity probe in the cabinet. The sampling link and power supply status are self-checked, and the self-check results and the primary data are encapsulated into a multi-source data frame according to the timestamp. The multi-source data frames are input into a hierarchical Bayesian inference network to obtain the confidence levels of the device health, circuit integrity, and energized state of the high-voltage interlocking device. The confidence vector is formed by evidence fusion and compressed into a comprehensive diagnostic code as a unique trigger identifier. Based on the comprehensive diagnostic code, the entry is retrieved in the interlocking mapping table to generate a locking action sequence. The electric latch, mechanical locking pin, and magnetic latching relay of the high-voltage locking device are driven to execute sequentially according to priority, and a locking completion vector is formed. The latch completion vector and holding parameters are encapsulated into an emergency bit frame and a status packet frame, and synchronously transmitted via passive dry contact and encrypted low-power communication; the sustaining index is calculated based on supercapacitor and residual magnetism, and the heartbeat is adaptively configured according to the sustaining index.

2. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 1, characterized in that: The integral rectification module obtains and rectifies AC quantities through the bus voltage sampling coil and the residual current transformer, collects the temperature and humidity inside the cabinet, and synchronously generates primary data with a unified timestamp; the controller uses a variable integral window to average the rectified waveform, and the integral window is limited to the power frequency half-wave to four cycles to form a DC power supply voltage field, and writes the sampling link continuity and voltage upper and lower limit self-test results into the multi-source data frame.

3. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 2, characterized in that: A breathing window is set up, and the mean and deviation of the temperature and humidity sequence within the window are calculated to obtain the temperature drift and humidity drift. If both exceed the corresponding preset threshold, a link anomaly identifier is generated. When encapsulating the multi-source data frame, the fields are arranged in the order of timestamp, bus voltage, DC power supply voltage, fault current peak, mean temperature, mean humidity, self-test result and CRC check, and byte alignment is performed.

4. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 3, characterized in that: The hierarchical Bayesian inference network consists of nodes, including device health nodes, loop integrity nodes, and energized state nodes, and conditional dependencies are represented by directed acyclic edges. The nodes receive observations such as bus voltage, peak fault current, DC power supply voltage, average temperature, average humidity, and link anomaly indicators from the multi-source data frames, update the prior using expectation maximization, and output three confidence scores through marginalization inference.

5. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 4, characterized in that: The three confidence scores are multiplied by a weight vector that can be remotely distributed and persistently stored to obtain a comprehensive score, and a two-digit comprehensive diagnostic code is generated based on a configurable segmented Gray mapping function. The controller constructs a signature using the timestamp and random salt, hashes the comprehensive diagnostic code, and writes it together with the timestamp into a read-only memory as the unique trigger identifier output.

6. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 5, characterized in that: The comprehensive diagnostic code is XORed from Gray to binary to obtain the interlocking index, and the interlocking index is used to retrieve the preset interlocking mapping table. The interlocking mapping table includes the weight columns of electric latches, mechanical latches and magnetic latching relays and the operating mode adjustment coefficients. The controller calculates the priority by matrix and vector product and generates the locking action sequence, and prepares the locking completion vector field at the same time.

7. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 6, characterized in that: The generated lockout action sequence is output by a programmable pulse width modulator. The controller integrates the DC bus voltage and actuator current in real time within each actuator pulse to obtain the injected energy and compares it with the minimum drive energy. When the current peak is detected to be continuously exceeding the limit, the pulse will be segmented or retransmitted; after the action, the limit switch and Hall element are read, and the locking completion vector is generated by combining them, and the holding energy is calculated accordingly.

8. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 7, characterized in that: The interlocking completion vector and holding parameters are split and encapsulated into an emergency bit frame and a status packet frame. The emergency bit frame contains a fault level bit and an interlocking index and is mapped to a passive dry contact and local bus forwarding. The status packet frame uses block encryption and carries a timestamp and counter, and performs byte alignment and CRC check and is persistently recorded. The two types of frames are sent sequentially by the low-power cellular communication module within the same session.

9. The multi-level fault diagnosis and interlocking linkage method for the high-voltage interlocking device as described in claim 8, characterized in that: Energy sustaining and decay management includes: performing high-speed and low-speed two-stage discharge on the supercapacitor and obtaining the switching time based on energy conservation; calculating and predicting residual magnetism for the magnetic latching relay using a time- and temperature-coupled residual magnetism prediction model; constructing a sustaining index based on the supercapacitor's remaining energy and the predicted residual magnetism, the reset requirement energy and the reset residual magnetism, and adaptively configuring the communication heartbeat and indicator heartbeat according to high and low thresholds.