330MW generator set DCS and DEH system capable of improving reliability

By constructing a DCS and DEH system with a multi-redundancy architecture and intelligent decision-making logic, the problem of unstable control commands caused by communication network failures has been solved, achieving high reliability and fault tolerance of the generator set and ensuring stable operation of the unit under abnormal conditions.

CN121635173APending Publication Date: 2026-03-10XINJIANG TIANFU ENERGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-04
Publication Date
2026-03-10

AI Technical Summary

Technical Problem

In existing technologies, when the DCS and DEH systems of generator sets experience single-point failures in the communication network or data blockages, the real-time performance and integrity of control commands are difficult to guarantee, and there is a lack of early warning mechanisms, resulting in a high probability of unplanned shutdowns.

Method used

The system is constructed with a deeply integrated, multi-redundant architecture, including a data acquisition and communication module, a core control and decision-making module, an execution and status feedback module, and a configuration management and version synchronization unit. It adopts heterogeneous multi-channel communication, real-time status awareness, and intelligent decision-making logic to achieve data consistency verification and collaborative control strategy calculation.

Benefits of technology

It improves the reliability and fault tolerance of the coordinated control of DCS and DEH systems. Through multi-level redundancy design and intelligent decision-making mechanism, it reduces the probability of unplanned shutdowns and ensures the safe and stable operation of the unit in the event of communication abnormalities or configuration inconsistencies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121635173A_ABST
    Figure CN121635173A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of generator set automatic control, particularly discloses a 330MW generator set DCS and DEH system capable of improving reliability, and aims to solve the problems of insufficient real-time performance and integrity of a control instruction, lack of an early warning mechanism and high non-planned shutdown probability caused by single-point fault of a communication network, data congestion and inconsistent system configuration. The system comprises a data acquisition and communication module, a core control and decision module and an execution and state feedback module, and realizes communication fault tolerance, prospective early warning and system configuration consistency maintenance through a heterogeneous multi-channel communication architecture, a data two-out-of-three voting mechanism, communication link health degree dynamic evaluation and automatic degradation control mode switching. The control reliability of the generator set is obviously improved; and the non-planned shutdown risk is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of automatic control of generator sets, and particularly relates to a 330MW generator set DCS and DEH system with increased reliability. BACKGROUND

[0002] In the field of industrial automation control, distributed control systems and digital electro-hydraulic control systems, as key infrastructures, are widely used in the operation management and regulation of large-scale generator sets. These systems realize centralized monitoring and automatic regulation of generator set start-stop, load and safety parameters through the integration of sensor, actuator and controller networks, and their reliability is directly related to power grid stability and equipment safety.

[0003] Among them, the cooperative control of the generator set DCS and DEH system is the core link to ensure the efficient and stable operation of the unit. The DCS is responsible for the overall process control and logic protection of the unit, and the DEH is specialized in the precise regulation of the speed and power of the steam turbine. The two need to realize data interaction and instruction synchronization through a high-speed communication network to maintain the dynamic balance of the power generation process.

[0004] The existing technology usually adopts a single network architecture or a master-backup redundancy scheme to realize the interconnection of DCS and DEH. However, when a single point failure or data congestion occurs in the communication network, the real-time performance and integrity of key control instructions between systems are difficult to guarantee, which may easily cause unit power fluctuations or protection misoperation.

[0005] At the same time, the traditional system has limited diagnostic capability for network status and lacks a warning mechanism for abnormal communication patterns, making it difficult for maintenance personnel to timely locate potential risks. Therefore, under the harsh working conditions of long-term continuous operation of the generator set, how to improve the reliability and fault tolerance of the cooperative control of the DCS and DEH system has become a technical problem to be solved in the field. SUMMARY

[0006] The purpose of the present application is to provide a 330MW generator set DCS and DEH system with increased reliability to solve the problems of difficulty in guaranteeing the real-time performance and integrity of control instructions, lack of warning mechanisms and high probability of unplanned shutdown caused by single point failure of the communication network, data congestion and inconsistent system configuration in the prior art.

[0007] To achieve the above purpose, the technical solution adopted by the present application is to construct a system with a deep integration of multiple redundancy architectures, real-time state perception and intelligent decision-making logic.

[0008] The system comprises:

[0009] A data acquisition and communication module for acquiring real-time operating parameters and state signals from the DCS side and the DEH side of the generator set and transmitting data through a heterogeneous multi-channel communication network.

[0010] a core control and decision module for receiving data from the data acquisition and communication module, performing data consistency check, communication link health assessment and collaborative control strategy calculation;

[0011] an execution and state feedback module for driving the actuators of the DCS and DEH systems according to the final control instructions output by the core control and decision module, and collecting the execution results in real time and feeding back to the upstream module;

[0012] a configuration management and version synchronization unit deployed on an independent security management host, storing the globally unique reference version of the DCS control logic configuration, DEH control parameters and all associated communication channel configuration parameters.

[0013] Further, the data acquisition and communication module includes a parameter acquisition unit and a heterogeneous multi-channel communication unit.

[0014] The parameter acquisition unit is configured with at least three groups of independent data acquisition cards, each group of data acquisition cards being connected to the analog input points, switch input points on the DCS side of the generator set and the speed sensor, power transmitter and oil motor displacement sensor on the DEH side through an isolated signal conditioning circuit.

[0015] The heterogeneous multi-channel communication unit is composed of two high-speed industrial Ethernet channels with different physical media and one backup optical fiber reflective memory channel using different communication protocols, and the three communication channels run in parallel, each channel having an independent communication controller and data buffer.

[0016] Further, the core control and decision module includes a data fusion and check submodule, a communication link health assessment submodule and a collaborative control strategy calculation submodule.

[0017] The data fusion and check submodule performs a two-out-of-three logical voting on the same group of operating parameters sent through the three communication channels.

[0018] The communication link health assessment submodule continuously monitors the message transmission delay, packet loss rate and bit error rate of each communication channel.

[0019] The collaborative control strategy calculation submodule receives the reliable data and communication link health status information after verification and executes the collaborative control algorithm calculation.

[0020] Further, the two-out-of-three logical voting process of the data fusion and check submodule is as follows:

[0021] When the data of the three channels are completely consistent, the data is adopted;

[0022] When only 2 channels have consistent data, adopt consistent data and mark the current communication exception of inconsistent channels;

[0023] When 3 channels are inconsistent, the effective data of the last sampling period is adopted to maintain output, and a communication exception alarm is triggered.

[0024] Further, the communication link health assessment submodule is built-in delay baseline model and packet loss rate threshold model trained based on historical operation data; when the monitored real-time delay is more than 2 times the delay baseline prediction value, or the real-time packet loss rate exceeds the threshold model set value of 0.1% for 3 consecutive sampling periods, it is determined that the channel health is deteriorated, and a channel warning signal is generated.

[0025] Further, the cooperative control strategy calculation submodule executes the standard DCS and DEH cooperative control algorithm when all communication links are normal, calculates the target speed and load command of the steam turbine, and automatically switches to the degraded control mode when any communication channel is determined to be in poor health or has data inconsistency exception.

[0026] Further, the degraded control mode is specifically implemented as follows: the system first locks the current actual speed and load of the steam turbine as the control reference, and then uses the speed sensor signal and power transmitter signal on the DEH side as the main feedback to execute an independent proportional integral derivative control algorithm, and stabilizes the unit speed and power within the range of ±0.5% of the reference value at the locking time; the control output only acts on the servo system of DEH locally, and no longer depends on the remote set value from DCS.

[0027] Further, the execution and state feedback module includes an instruction distribution unit and an execution state monitoring unit;

[0028] The instruction distribution unit has two independent output ports, one of which is directly connected to the servo control card of the DEH system, and the other is connected to the key steam turbine protection electromagnetic valve through the hard-wired backup link;

[0029] The execution state monitoring unit collects the feedback current of the servo control card, the actual displacement of the oil engine, and the instantaneous value of the steam turbine speed in real time, and returns the state information to the core control and decision module through the backup optical fiber reflection memory channel of the data acquisition and communication module.

[0030] Furthermore, when the system starts up, performs periodic self-checks, or receives instructions from maintenance personnel, the configuration management and version synchronization unit actively compares the current operating configuration with that of the DCS control station, DEH controller, and various communication controllers. If an inconsistency is found, it first attempts to send the baseline version to the corresponding device for automatic synchronization via a secure communication link. If automatic synchronization fails, it immediately issues a configuration anomaly alarm and records a detailed difference report, while preventing the control strategy calculation submodule from executing control commands that may cause risks due to configuration inconsistencies.

[0031] In summary, this application includes at least one of the following beneficial technical effects:

[0032] (1): This invention, by constructing a parallel communication architecture comprising two heterogeneous industrial Ethernet channels and one backup fiber optic reflective memory channel, and combining it with a three-out-of-two data voting mechanism, fundamentally eliminates the risk of single-point failure caused by a single communication channel failure in the transmission of system control commands. Even if one or two channels experience temporary data anomalies or complete interruptions, the system can still ensure the integrity of critical control data and the controllability of the decision-making basis through the remaining healthy channels or a retention strategy based on historical data, greatly improving the system's fault tolerance and reliability at the communication level.

[0033] (2): This invention introduces a forward-looking assessment mechanism for the health of communication links based on a dynamic baseline model. This mechanism can not only diagnose the current state of the communication link in real time, but also identify potential network performance degradation risks that have not yet caused control anomalies by predicting the trends of latency and packet loss rate, and generate early warning signals. This allows maintenance personnel to gain valuable early intervention time, take measures before the fault truly affects the unit control, change from passive response to proactive maintenance, and effectively reduce the probability of unplanned downtime caused by communication problems.

[0034] (3): This invention designs a collaborative control strategy calculation logic with automatic switching function and a globally unified configuration management unit. When the communication system malfunctions, the control strategy can seamlessly switch to a degraded control mode based on the DEH local environment, ensuring the unit continues to operate under safe conditions. Simultaneously, the configuration management unit ensures the consistency of control logic and parameters between the DCS and DEH systems, eliminating systemic risks introduced by version differences or configuration errors. The combination of these two elements, from the perspectives of control logic integrity and system configuration consistency, jointly constructs a solid defense line to improve the overall operational reliability of the generator set's DCS and DEH systems. Attached Figure Description

[0035] Figure 1 This is a schematic diagram of the overall technical solution architecture of the present invention;

[0036] Figure 2This is a schematic diagram of data fusion, verification, and communication links in this invention;

[0037] Figure 3 This is a schematic diagram illustrating the automatic switching of the collaborative control strategy to the degraded control mode in this invention; Detailed Implementation

[0038] This invention relates to a DCS and DEH system for a 330MW generator set to enhance reliability. Please refer to the appendix. Figure 1 The system consists of a data acquisition and communication module, a core control and decision-making module, an execution and status feedback module, and a configuration management and version synchronization unit. Each module interacts with the other and transmits control commands through a heterogeneous multi-channel communication network, ensuring the generator set can maintain safe and stable operation even in the event of communication failures or configuration inconsistencies.

[0039] Example 1

[0040] The data acquisition and communication module is responsible for acquiring real-time operating parameters and status signals from both the distributed control system and the digital electro-hydraulic control system of the generator set. This module includes a parameter acquisition unit and a heterogeneous multi-channel communication unit.

[0041] The parameter acquisition unit is equipped with three completely independent data acquisition cards. Each data acquisition card is connected to the analog input point and the digital input point on the distributed control system side through an isolated signal conditioning circuit, and is also connected to the speed sensor, power transmitter and hydraulic displacement sensor on the digital electro-hydraulic control system side.

[0042] The isolated signal conditioning circuit employs a differential amplification design and electromagnetic shielding structure to effectively suppress common-mode interference and high-frequency noise, ensuring the accuracy and stability of the acquired signal. Each data acquisition card has a sampling frequency of 1000 times per second, a quantization accuracy of 16 bits, an analog input range covering 0 to 10 volts, and supports 24-volt DC level detection for digital inputs.

[0043] The parameter acquisition unit integrates a self-calibration circuit, which automatically performs zero-point drift and gain error correction every 30 minutes, and the correction data is stored in non-volatile memory.

[0044] The heterogeneous multi-channel communication unit consists of two high-speed industrial Ethernet channels with different physical media and one spare fiber optic reflective memory channel.

[0045] The first industrial Ethernet channel uses twisted-pair cable as the transmission medium, supports a communication rate of 1000 megabits per second, and uses the Modbus transmission control protocol and Internet Protocol version 6 architecture.

[0046] The second industrial Ethernet channel uses multimode fiber optic transmission medium and also has a communication rate of 1000 megabits per second, but it uses the Profinet real-time communication protocol stack.

[0047] The backup fiber optic reflective memory channel is based on a ring topology, with a transmission latency of less than 500 nanoseconds. It adopts a dedicated reflective memory access protocol to achieve deterministic data transmission between distributed nodes.

[0048] Each communication channel is equipped with an independent communication controller and data buffer. The communication controller integrates a 32-bit microprocessor and a hardware encryption engine, applying 128-bit Advanced Encryption Standard (AES) algorithm protection to the transmitted data. The data buffer has a capacity of 8 megabytes and uses a ping-pong storage structure to achieve non-blocking data flow.

[0049] The three communication channels operate in parallel. The parameter acquisition unit sends the same set of sampled data to the three channels simultaneously, and the core control and decision-making module performs subsequent processing.

[0050] The core control and decision-making module receives real-time data from heterogeneous multi-channel communication units and performs data consistency verification, communication link health assessment, and collaborative control strategy calculation.

[0051] This module includes a data fusion and verification submodule, a communication link health assessment submodule, and a collaborative control strategy calculation submodule. Please refer to the appendix. Figure 2 The data fusion and verification submodule performs a two-out-of-three logical vote on the same set of operating parameters delivered through the three communication channels.

[0052] The voting logic is as follows: when the difference between the speed, power or pressure parameters transmitted by the three channels is less than 0.1% of the range, the data is considered to be completely consistent, the system adopts the data and marks it as valid; when only two channels meet the consistency condition, the system adopts the consistent data and records the communication anomaly event of the inconsistent channel to the error log. Three anomalies will trigger the channel reliability degradation flag.

[0053] When all three channels exceed the allowable deviation range, the system automatically switches to the historical data hold mode, uses the valid data confirmed by voting in the previous sampling period as the current output, and immediately activates the communication abnormality alarm signal. This signal is transmitted to the audible and visual alarm device in the control room through the human-machine interface unit.

[0054] The communication link health assessment submodule continuously monitors the message transmission latency, packet loss rate, and bit error rate performance metrics of each communication channel. This submodule incorporates a dynamically updated self-learning latency baseline model and a packet loss rate threshold model. The latency baseline model uses the system CPU load rate and network port traffic as input features and employs a time series prediction algorithm to perform rolling predictions of communication latency for the next five sampling periods.

[0055] The model performs online correction of prediction parameters every 24 hours using the latest 240 sets of actual communication latency data. The correction process uses recursive least squares to optimize the weight coefficients. The packet loss rate threshold model sets a dynamic threshold based on the statistical characteristics of historical operating data. When the real-time packet loss rate exceeds the 0.1% threshold for three consecutive sampling periods, the health of the channel is determined to be degraded. Specifically, if the real-time transmission latency of a channel exceeds twice the predicted latency baseline, or the bit error rate rises to more than 10 parts per million, the system immediately generates a channel warning signal. This signal contains three types of information: channel identifier, performance degradation type, and severity level, and is forwarded to the operation and maintenance management platform through the configuration management and version synchronization unit.

[0056] The collaborative control strategy calculation submodule receives reliable data processed by the data fusion and verification submodule, as well as communication link health status information. When all communication links are functioning normally, this submodule executes the collaborative control algorithm of the standard distributed control system and the digital electro-hydraulic control system to calculate the target turbine speed and load command.

[0057] The algorithm first generates a power setpoint based on the boiler main control output and the power grid dispatching command. Combining the current actual speed of the steam turbine and the pressure compensation coefficient, it outputs the servo valve opening command of the digital electro-hydraulic control system through a multivariable decoupled control structure.

[0058] When any communication channel is determined to have deteriorated health or data inconsistency, the submodule automatically switches to degraded control mode.

[0059] Please refer to the attached document. Figure 3 The specific implementation process of the degraded control mode is as follows: The system first locks the current actual speed and load of the turbine as the control reference, and then uses the local speed sensor signal and power transmitter signal on the digital electro-hydraulic control system side as the only feedback quantity to execute an independent proportional integral derivative control algorithm.

[0060] The algorithm expression is: Where e(t) represents the error between the actual turbine speed or load and the locking control reference value, u(t) represents the control output acting on the DEH local servo system, and the proportional coefficient K p Take 0.8, K i The integration time constant is 12 seconds, K d The differential time constant is 2 seconds. The control output acts only on the local servo system of the digital electro-hydraulic control system, maintaining the unit in safe operating conditions by adjusting the flow of high-pressure fire-resistant oil.

[0061] During this process, the system sends a degraded operation status notification to the distributed control system side through the remaining health communication channel. The notification message includes the mode switching timestamp, current operating parameters, and estimated recovery time.

[0062] When the core control and decision-making module confirms that all communication channels have returned to a healthy state, and the data fusion and verification submodule outputs consistent data for 10 consecutive sampling cycles, the system automatically exits the degraded mode and smoothly transitions back to the normal collaborative control mode through the setpoint-free switching logic.

[0063] The execution and status feedback module drives the actuator based on the final control commands output by the core control and decision-making module, and monitors the execution effect in real time. This module includes a command distribution unit and an execution status monitoring unit.

[0064] The command distribution unit has two independent output ports. The first output port is connected to the servo control card of the digital electro-hydraulic control system via shielded twisted pair cable, transmitting analog voltage signals with a resolution of 12 bits. The second output port is directly connected to the turbine protection solenoid valve via a hard-wired backup link, driven by 24-volt DC pulse commands.

[0065] The instruction distribution unit integrates an output redundancy switching circuit. When an abnormality is detected in the main output channel, the backup output channel is automatically activated within 5 milliseconds.

[0066] The execution status monitoring unit collects real-time feedback current from the servo control card, actual displacement of the hydraulic actuator, and instantaneous turbine speed, with a sampling frequency of 2000 Hz. The collected data is transmitted back to the core control and decision module via a backup fiber optic reflection memory channel at 125 microsecond intervals, forming a closed-loop control and status verification.

[0067] The execution status monitoring unit is also equipped with a threshold comparator. When the displacement deviation of the hydraulic motor exceeds 2% of the full stroke or the speed fluctuation exceeds 0.5% of the rated value, it immediately sends an output suppression signal to the command distribution unit.

[0068] The configuration management and version synchronization unit is deployed on a separate security management host, storing a globally unique baseline version of the distributed control system control logic configuration, digital electro-hydraulic control system control parameters, and configuration parameters of all associated communication channels.

[0069] This unit performs initialization checks when the system starts, triggers periodic self-checks every 24 hours, and initiates a special synchronization process when it receives instructions from maintenance personnel.

[0070] During synchronization, the unit performs configuration comparisons with the distributed control system control station, the digital electro-hydraulic control system controller, and each communication controller via a secure communication link. The comparison includes three core types of data: control algorithm parameter tables, communication address mapping tables, and security permission settings.

[0071] If a version inconsistency is detected, the unit first attempts to distribute the baseline version to the corresponding device. The distribution process employs dual security measures: digital signature and cyclic redundancy check. If automatic synchronization fails due to network timeout or device unresponsiveness, the unit immediately issues a configuration anomaly alarm, preventing the collaborative control strategy calculation submodule from executing control commands that may pose risks due to configuration inconsistencies. Simultaneously, a detailed difference report is generated and recorded in the system audit log.

[0072] During system operation, the three sets of data acquisition cards in the data acquisition and communication module continuously collect the generator set's operating parameters and transmit them in parallel to the core control and decision-making module through the heterogeneous multi-channel communication unit.

[0073] The data fusion and verification submodule performs real-time voting on multi-channel data to ensure the reliability of the data input to the control algorithm. The communication link health assessment submodule dynamically monitors network status and identifies potential fault risks in advance.

[0074] The collaborative control strategy calculation submodule adaptively selects the control mode based on the system status to ensure the stable operation of the unit under various operating conditions.

[0075] The execution and status feedback module accurately executes control commands and provides real-time feedback on the execution status, forming a complete control closed loop.

[0076] The configuration management and version synchronization unit ensures the consistency of parameters for all components at the system level, eliminating systemic risks caused by configuration errors. Through multi-level redundancy design and intelligent decision-making mechanisms, the entire system significantly improves the reliability and fault tolerance of the generator set control system.

[0077] Example 2

[0078] This embodiment provides an alternative implementation scheme for a distributed generator control system and a digital electro-hydraulic control system to increase reliability. Please refer to the appendix. Figure 1 The overall system architecture is the same as in Example 1, but a distributed acquisition node design is adopted in the parameter acquisition unit of the data acquisition and communication module. Each acquisition node independently integrates signal conditioning circuitry and an analog-to-digital converter, interconnected via a local fieldbus to form an acquisition network, replacing the centralized data acquisition card structure. The acquisition nodes are functionally divided into analog acquisition nodes and digital acquisition nodes. Analog acquisition nodes support 8-channel synchronous sampling, while digital acquisition nodes support 16-channel isolated input. A time synchronization protocol is used between acquisition nodes to achieve microsecond-level alignment of sampling clocks, ensuring the timing consistency of data acquired by different nodes.

[0079] The heterogeneous multi-channel communication unit, while retaining two industrial Ethernet channels and one spare fiber optic reflective memory channel, adds a wireless spread spectrum communication channel as a fourth redundant path. The wireless spread spectrum communication channel operates in the 2.4 GHz band, employing direct sequence spread spectrum technology with a transmission rate of 54 megabits per second. This channel is equipped with an adaptive power control circuit that dynamically adjusts the transmission power based on channel quality, maintaining stable communication in complex industrial electromagnetic environments. The communication unit's data buffer has been upgraded to a dual-port memory structure, supporting simultaneous read and write operations and increasing data throughput to 12 million accesses per second.

[0080] The data fusion and verification submodule of the core control and decision-making module implements a three-out-of-four voting strategy, requiring at least three channels of data to be consistent before adopting valid data. The communication link health assessment submodule introduces a spectrum analysis algorithm to monitor the carrier-to-interference ratio (CIR) and multipath fading characteristics of wireless communication channels, triggering a channel quality warning when the CIR falls below 15 dB. The collaborative control strategy calculation submodule adds a load rate limiting function in degraded control mode. When the system switches to degraded mode, it automatically limits the load change rate to 2% of the rated value per minute to prevent drastic power fluctuations from impacting the unit.

[0081] The instruction distribution unit of the execution and status feedback module adopts a triple-redundant output architecture, with a newly added third output port connected to the auxiliary control unit of the digital electro-hydraulic control system via a fiber optic interface. The execution status monitoring unit adds a vibration sensor interface to collect bearing vibration data in real time and incorporate it into the status feedback closed loop. The configuration management and version synchronization unit adds incremental synchronization functionality, transmitting only changed configuration parameters, reducing synchronization time to 30% of the original solution. Through these optimizations, the system further enhances communication redundancy and control flexibility, making it suitable for supercritical generator set applications with extremely high reliability requirements.

[0082] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. Therefore, the embodiments should be regarded as exemplary and non-limiting in all respects.

[0083] Furthermore, it should be understood that although this specification describes embodiments, not every embodiment contains only one independent technical solution. This narrative style is merely for clarity. Those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.

Claims

1. A 330 MW power generating unit DCS, DEH system for increasing reliability, characterized in that, The application relates to a real-time cooperative control system for a generator unit, which comprises the following parts: a data acquisition and communication module for acquiring real-time operation parameters and state signals from a generator unit DCS side and a DEH side and transmitting data through a heterogeneous multi-channel communication network; a core control and decision module for receiving data from the data acquisition and communication module, performing data consistency check, communication link health assessment and cooperative control strategy calculation; an execution and state feedback module for driving the execution mechanism of the DCS and DEH systems according to the final control instruction output by the core control and decision module and collecting execution result feedback to the upstream module in real time; a configuration management and version synchronization unit arranged on a separate security management host and storing the globally unique reference version of the DCS control logic configuration, DEH control parameters and all associated communication channel configuration parameters.

2. The 330 MW power generating unit DCS, DEH system of claim 1, wherein, The data acquisition and communication module comprises a parameter acquisition unit and a heterogeneous multi-channel communication unit. The parameter acquisition unit is configured with at least three groups of independent data acquisition cards, each group of data acquisition cards is connected to the analog input point, the switch input point of the DCS side of the generator unit and the speed sensor, the power transducer and the oil motor displacement sensor of the DEH side through an isolation type signal conditioning circuit; the heterogeneous multi-channel communication unit is composed of two high-speed industrial Ethernet channels with different physical media and one backup optical fiber reflection memory channel adopting different communication protocols, the three communication channels run in parallel, and each channel has an independent communication controller and a data buffer.

3. The 330 MW generating unit DCS, DEH system with increased reliability according to claim 1, characterized in that, The core control and decision module comprises a data fusion and check submodule, a communication link health assessment submodule and a cooperative control strategy calculation submodule. The data fusion and check submodule performs a two-out-of-three logic voting on the same group of operation parameters sent through the three communication channels; the communication link health assessment submodule continuously monitors the message transmission delay, packet loss rate and bit error rate of each communication channel; the cooperative control strategy calculation submodule receives the reliable data and communication link health state information after check and executes the cooperative control algorithm calculation.

4. The 330 MW power generating unit DCS, DEH system of claim 3, wherein, The two-out-of-three logic voting process of the data fusion and check submodule is as follows: when the data of the three channels are completely consistent, the data is adopted; when only two channels have consistent data, the consistent data is adopted and the communication exception of the inconsistent channel is marked; when the data of the three channels are all inconsistent, the effective data of the last sampling period is adopted to maintain the output, and a communication exception alarm is triggered.

5. The 330 MW power generating unit DCS, DEH system of claim 3, wherein, The communication link health assessment submodule is internally provided with a delay baseline model and a packet loss rate threshold model trained based on historical operation data; when the monitored real-time delay is more than twice the delay baseline prediction value or the real-time packet loss rate continuously exceeds the threshold model set value of 0.1% for three sampling periods, it is determined that the health degree of the channel is deteriorated, and a channel warning signal is generated.

6. The 330 MW power generating unit DCS, DEH system of claim 3, wherein, The cooperative control strategy calculation submodule executes the standard DCS and DEH cooperative control algorithm when the communication link is all normal, calculates the target speed and load instruction of the steam turbine, and automatically switches to the degraded control mode when any communication channel is determined to have a deteriorated health degree or a data inconsistency exception.

7. The 330 MW power generating unit DCS, DEH system of claim 6, wherein, The degradation control mode is implemented as follows: the system first locks the current actual rotating speed of the steam turbine and the load as a control reference, then takes the rotating speed sensor signal and the power transmitter signal of the DEH side as the main feedback, executes an independent proportional integral derivative control algorithm, and stabilizes the rotating speed and the power of the unit within the range of the reference value of the locking time ±0.5%; the control output only acts on the servo system of the DEH local side, and no longer depends on the remote set value from the DCS.

8. The 330 MW power generating unit DCS, DEH system of claim 1, wherein, The execution and state feedback module comprises an instruction distribution unit and an execution state monitoring unit; The instruction distribution unit has two independent output ports, one of which is directly connected to the servo control card of the DEH system, and the other is connected to the key steam turbine protection electromagnetic valve through a hard-wired backup link; The execution state monitoring unit collects the feedback current of the servo control card, the actual displacement of the oil engine and the instantaneous value of the rotating speed of the steam turbine in real time, and returns the state information to the core control and decision module through the backup optical fiber reflection memory channel of the data acquisition and communication module.

9. The 330 MW power generating unit DCS, DEH system of claim 1, wherein, The configuration management and version synchronization unit compares the current running configuration of the DCS control station, the DEH controller and each communication controller when the system starts, periodically self-checks or receives a maintenance personnel instruction; If inconsistency is found, first try to download the reference version to the corresponding device through the safe communication link for automatic synchronization; If automatic synchronization fails, an abnormal configuration alarm is immediately issued, a detailed difference report is recorded, and the control strategy calculation submodule is prevented from executing control instructions that may cause risks due to inconsistent configurations.