Digital intelligent debugging method for automatic business of transformer substation
By constructing a time reliability scoring mechanism, the problem of SOE event sequencing disorder caused by IED device time drift in substation automation system was solved, realizing efficient and accurate equipment status monitoring and protection action control, and improving the stability and security of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-03-31
AI Technical Summary
In substation automation systems, time inconsistencies caused by system time drift of IED devices can lead to disordered SOE event sequencing, resulting in misjudgments of equipment status by the monitoring system and even erroneous tripping or reclosing commands during protection actions, posing a risk of electrical fault propagation.
By acquiring system clock data, synchronization method information, and SOE record information from secondary equipment, the time deviation volatility and action logic anomaly are calculated, a time reliability score is constructed, the SOE event sequencing strategy is adjusted, and secondary verification and protection delay strategies are applied during relay protection commissioning to ensure that the time reliability meets the threshold.
It significantly improves the ability to identify equipment time anomalies and the accuracy of system action judgment, provides stable and controllable debugging support, reduces the risk of malfunctions, and enhances the stability and security of the system.
Smart Images

Figure CN121770185A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secondary equipment commissioning and control technology, specifically to a digital and intelligent commissioning method for substation automation services. Background Technology
[0002] Digital and intelligent commissioning of substation automation refers to the efficient and precise commissioning and verification of equipment, systems, and functions during the construction and operation of substation automation systems, utilizing digital and intelligent technologies (such as artificial intelligence, big data, and the Internet of Things). Through digital models, remote commissioning platforms, and intelligent algorithms, it provides intelligent assistance for the joint commissioning, functional verification, and fault diagnosis between primary equipment and secondary systems, significantly improving commissioning efficiency, reducing labor costs, and enhancing system stability and security.
[0003] In the digital commissioning of substation automation systems, although clock synchronization methods such as GPS, NTP, and IRIG-B are commonly used to ensure the time consistency between primary operations and secondary system responses, some IED devices may experience slow system time drift due to clock source failures or inconsistent synchronization mechanisms. This time drift often does not trigger equipment alarms, but it can cause SOE event sequencing errors, leading to misjudgments of equipment status by the monitoring system, and even erroneous tripping or reclosing commands during protection actions due to distorted time conditions. For example, during a disconnector switch opening operation, due to millisecond-level differences in the system times of multiple IEDs, events are incorrectly sequenced, and the backend mistakenly interprets it as abnormal equipment operation, triggering an erroneous alarm. More seriously, if the protection logic contains time threshold judgments, such as "reclosing is prohibited within 10 seconds after tripping," time drift may lead to logical misjudgments, premature closing, and consequently, the expansion of electrical faults. Summary of the Invention
[0004] The purpose of this invention is to provide a digital and intelligent commissioning method for substation automation services to address the shortcomings in the prior art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for intelligent commissioning of substation automation services, comprising:
[0006] Acquire system clock data, synchronization method information, and SOE record information of multiple secondary devices in the substation, and establish corresponding secondary device time datasets;
[0007] Based on the secondary device time dataset, the time deviation fluctuation rate of each secondary device relative to the master clock is calculated according to a set time window.
[0008] Extract the protection action sequence of the secondary equipment during the debugging process, compare it with the preset protection logic action chain, and calculate the action logic anomaly degree;
[0009] Based on the time deviation volatility, action logic anomaly degree, and the time synchronization method level parameters used by the equipment, a time reliability score is constructed for each secondary device:
[0010] Based on the time reliability score, the sorting strategy for SOE events is adjusted, including removing device events with a time reliability score below a set threshold, using reliability-weighted sorting, and compensating for the sorting by combining the causal relationship between events between secondary devices.
[0011] During the relay protection commissioning process, the protection action logic is adjusted based on the time reliability score. This includes applying secondary verification, protection delay strategy, or action shielding when the trigger signal comes from a device with a time reliability score lower than the set threshold.
[0012] Preferably, the method for obtaining the time deviation volatility is as follows: for each sampling time t_i, the system time T_device(t_i) of a certain secondary device is subtracted from the master clock time T_master(t_i) to obtain the time deviation ΔT_i at this time. This calculation is performed once at each sampling point to obtain a set of time deviation sequences; the time deviation volatility TDV refers to the standard deviation of the time deviation sequence.
[0013] Preferably, the calculation of the action logic anomaly degree includes:
[0014] Extract the actual protection action sequence of each secondary device within a set debugging cycle. The protection action sequence includes event type, trigger timestamp, action device identifier and logical channel number.
[0015] Obtain the corresponding standard protection action chain from the preset configuration file. The action chain defines the action sequence, time dependency, and logical conditions.
[0016] A sequence matching algorithm is used to compare the similarity between the actual action sequence and the standard action chain, and the sequence structure deviation is calculated.
[0017] Calculate the abnormality degree of action logic based on sequence structure deviation.
[0018] Preferably, the calculation of action logic anomaly degree based on sequence structure deviation includes:
[0019] The actual protection action sequence and the standard protection action chain are respectively converted into event coding sequences, and a unique identifier is generated based on the type and logical position of each action event;
[0020] The matching distance between two sequences is calculated using a dynamic time warping algorithm or an edit distance algorithm. The matching distance reflects the degree of offset between the order of actions and logical dependencies.
[0021] Divide the matching distance by the total number of events in the standard action chain to obtain the standardized deviation value;
[0022] The standardized deviation value is used as the degree of abnormality of the action logic.
[0023] Preferably, the reliability score for the construction time of each secondary device includes:
[0024] The time deviation volatility and action logic anomaly of each device are normalized and mapped to standardized values between 0 and 1.
[0025] Synchronization level scores are assigned based on the time synchronization method used by the equipment, with IRIG-B synchronization method scoring 1.0, PTP method scoring 0.9, NTP method scoring 0.7, and SNTP or no synchronization method scoring 0.5.
[0026] Set weighting coefficients, construct a weighted scoring function, sum the weighted values, and calculate the time reliability score for each device.
[0027] The time credibility score is compared with a set threshold to identify credible, suspicious or untrustworthy time sources.
[0028] Preferably, the sorting strategy for adjusting SOE events includes:
[0029] Set a threshold for time reliability score and filter SOE events from all devices, removing events from secondary devices whose time reliability score is lower than the set threshold.
[0030] The retained SOE events are sorted by time reliability score of the device to which they belong, with the timestamp of each event being corrected to a combination of the original time and the reliability weighting offset.
[0031] For event pairs that have overlapping times or conflicting ordering, further logical compensation and sorting are performed based on preset secondary device logical relationships or event causal graphs.
[0032] Preferably, the logic for adjusting the protection action based on the time reliability score includes:
[0033] Determine whether the control signal that triggers the protection action originates from a secondary device with a time reliability score lower than a preset threshold. If so, mark it as a low-reliability action source.
[0034] For protection-triggered events marked as low-confidence action sources, a secondary verification process is performed. The verification methods include cross-device redundant signal comparison or protection action chain integrity verification.
[0035] When the secondary verification fails, extend the tripping waiting time of the protection device or add condition judgment logic;
[0036] When the signal reliability is low and the verification cannot be completed, the action is prohibited from triggering the relay protection trip, the action shielding process is entered, and the abnormal event is recorded.
[0037] The technical effects and advantages provided by the present invention in the above technical solution are as follows:
[0038] 1. This invention introduces a time reliability scoring mechanism, integrating multiple indicators such as time deviation volatility, action logic anomaly degree, and synchronization mode level to establish a quantitative time reliability assessment model. Based on this model, the system can dynamically adjust the SOE event sequencing and intelligently fault-tolerant control of protection action logic, significantly improving the ability to identify equipment time anomalies and the accuracy of system action judgment during commissioning.
[0039] 2. Compared to traditional debugging methods that rely on fixed timestamp sorting and static protection configurations, this invention offers greater adaptability and robustness. It provides stable, controllable, and highly reliable debugging support in complex scenarios involving multi-source heterogeneous devices, fluctuating synchronization links, or disordered data timing. This solution requires no hardware modifications to existing equipment structures and possesses excellent engineering feasibility. Attached Figure Description
[0040] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.
[0041] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation
[0042] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0043] For examples, please refer to Figure 1 As shown in this embodiment, a method for intelligent commissioning of substation automation services includes:
[0044] Acquire system clock data, synchronization method information, and SOE record information of multiple secondary devices in the substation, and establish corresponding secondary device time datasets;
[0045] Based on the secondary device time dataset, the time deviation fluctuation rate of each secondary device relative to the master clock is calculated according to a set time window.
[0046] Extract the protection action sequence of the secondary equipment during the debugging process, compare it with the preset protection logic action chain, and calculate the action logic anomaly degree;
[0047] Based on the time deviation volatility, action logic anomaly degree, and the time synchronization method level parameters used by the equipment, a time reliability score is constructed for each secondary device:
[0048] Based on the time reliability score, the sorting strategy for SOE events is adjusted, including removing device events with a time reliability score below a set threshold, using reliability-weighted sorting, and compensating for the sorting by combining the causal relationship between events between secondary devices.
[0049] During the relay protection commissioning process, the protection action logic is adjusted based on the time reliability score. This includes applying secondary verification, protection delay strategy, or action shielding when the trigger signal comes from a device with a time reliability score lower than the set threshold.
[0050] In this invention, data is first collected uniformly from multiple secondary devices deployed within the substation to establish a data foundation for subsequent time reliability calculations. This step mainly includes the following:
[0051] The system clock information is read in real time from various intelligent electronic devices (IEDs), measurement and control devices, protection devices, remote control units (RTUs), and other secondary devices. The system clock data includes, but is not limited to: the current system time value, timestamp source identifier, clock status identifier (such as normal, drift, out of synchronization), and the last synchronization time.
[0052] The time synchronization configuration of each device is identified, and the time synchronization mechanism it employs is extracted, including but not limited to IRIG-B, IEEE 1588 PTP, NTP, SNTP, and GPS direct time synchronization. Simultaneously, the current status of its synchronization link is collected, such as clock source signal quality, synchronization delay, and clock master-slave configuration. Synchronization method information is used for subsequent rating of the device's time source.
[0053] Acquire the Sequence of Events (SOE) records for each device during operation or commissioning. These records include: event timestamp, event type (e.g., switch opening / closing, protection action, remote control execution), channel number, unique device identifier, and the logical interval unit to which it belongs. All SOE data includes a local timestamp for the device.
[0054] The data from the three dimensions mentioned above are structured and organized to form a device time dataset. In the dataset, each record corresponds to a specific device instance, recording its unique device identifier (such as IED number), current system clock value, synchronization mode type, time synchronization status, and its SOE event record list.
[0055] In this invention, the time deviation volatility refers to the statistical fluctuation of the deviation between the system time and the master clock time of a secondary device within a set time window. This parameter is used to identify whether the device exhibits time instability phenomena such as abnormal drift, intermittent synchronization failure, or system clock jumps.
[0056] Based on the debugging task cycle and equipment performance, a uniform time sampling period is set, preferably once every 10 seconds, with the sampling period configured between 5 and 60 seconds.
[0057] Define a sliding time analysis window, preferably 10 minutes. This time window is used to statistically analyze the time deviation samples of each device within this time period. Each window contains multiple equally spaced sampling points; for example, within a 10-minute time window, with a sampling period of 10 seconds, there are a total of 60 sampling points.
[0058] The master clock time can be provided through the IRIG-B module, PTP master station equipment, or GPS reference source connected to the station control system. The master clock time serves as the reference for all time deviation calculations.
[0059] For each sampling time t_i, the time deviation ΔT_i is obtained by subtracting the system time T_device(t_i) of a certain secondary device from the master clock time T_master(t_i). The calculation method is as follows: The calculation is performed once at each sampling point, resulting in a time deviation sequence {ΔT_1, ΔT_2, ..., ΔT_n}, where n is the total number of sampling times.
[0060] Time Deviation Volatility (TDV) refers to the statistical standard deviation of a time deviation series, used to measure the volatility of its offset. The standard deviation is calculated as follows: Calculate the arithmetic mean of all ΔT_i, i.e., the average deviation; square the difference between each ΔT_i and the mean; sum all the squared differences and divide by the number of sampling points; take the square root of the result to obtain the TDV value, in milliseconds (ms).
[0061] Taking a specific device as an example, assuming 60 time deviation points were collected within a 10-minute window, with an average deviation of 20 milliseconds and a standard deviation of 5 milliseconds for the time deviation (TDV), this indicates that the device's time fluctuates relatively little compared to the master clock, classifying it as a stable device.
[0062] To achieve automated identification of devices with drift risk, this invention sets multi-level volatility judgment thresholds, as follows:
[0063]
[0064] The above thresholds can be adjusted based on actual engineering operation experience and system fault tolerance requirements.
[0065] Within a set commissioning cycle (e.g., 5 minutes, 10 minutes, or the entire commissioning process cycle), extract the protection action sequence for each secondary device from the device time dataset. The protection action sequence includes the following fields:
[0066] Event types (e.g., trip initiation, successful tripping, reclosing command, fault confirmation, etc.);
[0067] Trigger timestamp (time recorded by the device);
[0068] Identification of operating equipment (such as IED number, protection device model);
[0069] Logical channel number (indicates the protection function module to which the event belongs, such as 21, 50, 51, 79, etc.).
[0070] After extraction, the system sorts the events according to timestamp order and generates the actual protection action sequence of the device. This sequence is used for comparison and analysis with standard logic.
[0071] A standard protection action chain is a pre-defined sequence of expected action logic derived from system engineering configuration files, relay protection setting sheets, or protocol libraries. This standard chain is defined as follows:
[0072] Sequence of actions (e.g.: fault detection → tripping → trip confirmation → reclosing);
[0073] Time-dependent relationships (e.g., tripping action should be completed within 300 milliseconds after fault identification);
[0074] Logical condition constraints (such as the requirement that the blocking condition must be met before reclosing is allowed).
[0075] The standard protection action chain can be represented as an ordered set of events, with each event having an action identifier and logical position code, forming a "reference template" for the device's action behavior.
[0076] To achieve efficient sequence comparison analysis, the actual protection action sequence and the standard action chain are both converted into event-coded sequences in a unified format. The coding rules are as follows:
[0077] Each event consists of "event type code + channel number + logical position"; for example, the "trip start event" is located in channel 21, logical position 1, and is encoded as E21_1; the actual sequence and the standard chain are encoded as sequence A and sequence B, respectively. This encoding format is compatible with logical judgments and time information, which is beneficial for subsequent matching calculations and deviation analysis.
[0078] In this invention, two optional algorithms are used to perform similarity analysis on event-encoded sequences A and B to calculate the action logic anomaly index:
[0079] The Edit Distance algorithm is used to calculate the minimum number of edit operations required to transform the actual sequence A into the standard sequence B. Edit operations include insertion, deletion, and replacement.
[0080] Let: Sequence A have length m; Sequence B have length m; Edit distance be D(A,B). Then the Action Logic Exceptionality (PLCI) is defined as: Where m is the number of events in the standard action chain. PLCI ranges from 0 to 1, with higher values indicating greater deviation.
[0081] For action sequences containing complex logical delays, the Dynamic Time Warping (DTW) algorithm can be used to non-linearly align two event sequences, calculate the optimal matching path cost as the matching distance, and substitute it into the same PLCI calculation formula.
[0082] To achieve automatic judgment and alarm during the debugging process, this invention sets an anomaly classification judgment threshold based on PLCI:
[0083]
[0084] This threshold can be parameterized and adjusted according to differences in different sites or protection strategies.
[0085] The Time Credibility Rating (TCR) ranges from 0 to 1. A higher TCR indicates that the timestamp of the device is more reliable and has a higher weight in sorting and protection decisions. Conversely, a lower TCR indicates a greater risk of time anomalies.
[0086] The Time Reliability Rating (TCR) consists of three core indicators: Time Deviation Volatility (TDV), which represents the standard deviation of the system clock relative to the master clock within a specified time window, measured in milliseconds (ms), reflecting the stability of the system time; Action Logic Anomaly Index (PLCI), which represents the degree of deviation of the device's protection action sequence from the standard action chain, ranging from 0 to 1, reflecting the actual impact of device time on protection logic; and Time Synchronization Method Level Rating (Q), which represents the stability score of the time synchronization method used by the device, a fixed constant, specifically assigned as follows:
[0087]
[0088] To ensure a unified evaluation scale for the three indicators, TDV and PLCI must first be normalized and mapped to standardized values (between 0 and 1). The normalization method is as follows: Set a maximum acceptable fluctuation limit for TDV (e.g., 100ms), divide the actual TDV_i by the limit, and set any excess to 1; PLCI does not require conversion as it is itself a standardized indicator. The standardized values are denoted as: Standardized Time Volatility is TDV_norm; Standardized Action Logic Abnormality is PLCI_norm.
[0089] Subsequently, a weighted scoring function is constructed to calculate the Time Credibility Rating (TCR). The specific calculation method is as follows: Time Credibility Rating Among them, w1, w2, and w3 are weighting coefficients used to control the degree of influence of the three indicators on the scoring results. The preferred settings are as follows: w1 = 0.4 (time stability accounts for 40% weight); w2 = 0.4 (logical consistency accounts for 40% weight); w3 = 0.2 (synchronization method accounts for 20% weight).
[0090] Taking a certain device as an example, its time deviation volatility (TDV) is 25ms, and its maximum tolerance is 100ms, so TDV_norm = 0.25; its action logic exception degree (PLCI) is 0.3, which is directly used as PLCI_norm; its time synchronization method is PTP, corresponding to Q = 0.9.
[0091] Substituting into the scoring function, we calculate: TCR = 0.4 × (1 − 0.25) + 0.4 × (1 − 0.3) + 0.2 × 0.9; TCR = 0.4 × 0.75 + 0.4 × 0.7 + 0.18; TCR = 0.3 + 0.28 + 0.18 = 0.76. This indicates that the device's time reliability is 0.76, belonging to the "reliable" level.
[0092] To achieve automatic control and response strategy adjustment during subsequent debugging, this invention establishes the following reliability grading standard:
[0093]
[0094] Using the time reliability score of each device as the basis for event ranking weight, the SOE event sequence is optimized for reliable ranking through three steps: event filtering, time correction, and causal compensation.
[0095] For all events in the SOE dataset, they are filtered according to the time reliability score (TCR) of the device to which the event originates. If the TCR score of the device from which an event originates is less than 0.6, the event is removed and will not be included in subsequent ranking and causal analysis.
[0096] In the SOE event set after filtering, this invention performs a credibility-weighted correction on the sorting timestamp of each event to construct a weighted timestamp model. The core idea is: the higher the time credibility of a device, the more trusted its original timestamp is, and the greater its weight in the sorting; while for devices with low credibility, their original timestamps should be "time-stretched" to reduce their priority in the sorting.
[0097] For the i-th SOE event, let its original timestamp be T_i, and the time reliability score of the corresponding device be C_i (range 0~1). Then, the weighted sorted timestamp T_i' is calculated as follows: Where: Δ_max represents the maximum allowable time offset adjustment value, in milliseconds, preferably set to 200 milliseconds; (1 − C_i) represents the inverse index of time reliability, used to calculate the offset coefficient.
[0098] If the device TCR for an event is 1.0, its timestamp remains unchanged; if the TCR is 0.5, its sorting time will be delayed by 100 milliseconds; if the TCR is 0, the sorting time will be delayed by 200 milliseconds, thus naturally reducing the sorting priority. All events are sorted in ascending order based on their weighted timestamps T_i' to generate a preliminary list of reliable event sequences.
[0099] Even with weighted timestamp sorting, in scenarios where events occur at similar times or overlap logically, the order of critical events may still be incorrect, especially in protection action chains (such as a trip signal appearing after a fault signal). To address this, this invention further introduces an event causal graph compensation mechanism to ensure the final sorting logic is reasonable.
[0100] Establish a standard event cause-effect graph through station control configuration files, relay protection logic diagrams, or rule engines to define logical dependencies between devices and events, such as: fault identification → trip command → circuit breaker open position confirmation → reclosing; event A must be triggered before event B (e.g., logical dependency); if event B occurs first, the order should be forcibly adjusted.
[0101] For any event pair (E_i, E_j) in the sorted sequence, if its temporal order conflicts with the preset causal relationship (e.g., E_j should precede E_i), a local swap adjustment is performed to ensure global causal consistency with minimum cost. This process can be implemented using a heuristic sorting algorithm or a constrained topological sorting algorithm, prioritizing the adjustment of low TCR events while maintaining the sorting stability of high TCR events.
[0102] For protection trigger signals determined to be low-confidence action sources, this invention performs a secondary verification mechanism, specifically including:
[0103] Redundant equipment comparison and verification: Locate other secondary equipment in the station with the same protection function or monitoring channel; compare whether the same fault phenomenon (such as overcurrent, grounding, etc.) is also detected within the same time window; if two or more devices produce consistent judgments, the action is considered a valid signal.
[0104] Action chain integrity verification: Checks whether the current protection action conforms to a complete protection action chain structure; for example, before tripping, there should be a process of fault identification → startup → lockout release → output command, etc.; if a key step is missing, the action is determined to be "abnormally triggered". Secondary verification is completed through the built-in logic rule engine of the debugging platform, which can be implemented based on standard protection process templates or user-defined logic.
[0105] When the verification result of a low-confidence action source is "failed" or "pending confirmation," the system will automatically apply a protection delay strategy to prevent erroneous actions. The specific method is as follows:
[0106] The corresponding action command enters a delayed execution process, with the delay duration preferably between 300ms and 800ms, depending on the protection type. During the delay, if another trusted device triggers the same action, the delay is immediately terminated and normal execution resumes. If no other supporting signal is received at the end of the delay, the action is terminated, and the shielding process begins. This mechanism ensures that during the commissioning phase, even if the protection device receives an error or drift signal, it will not immediately trip, improving the safety of system commissioning.
[0107] If a trigger signal is a low-reliability time source and cannot pass any secondary verification or redundancy verification, the signal will be directly blocked, prohibiting it from triggering critical operations such as tripping, closing, or blocking by the protection device. Simultaneously, the system automatically records this event in the commissioning anomaly log, including: event type and time; triggering device number and TCR value; reason for verification failure; type of blocked action and target device. This log can be used for commissioning review, commissioning acceptance, or subsequent protection strategy optimization.
[0108] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.
Claims
1. A method for digitalization commissioning of substation automation services, characterized in that: The method comprises the following steps: Obtain system clock data, synchronization mode information and SOE record information of a plurality of secondary devices in a substation, and establish a corresponding secondary device time data set; Based on the secondary device time data set, calculate the time deviation fluctuation rate of each secondary device relative to the master clock according to a set time window; Extract the protection action sequence of the secondary device during the debugging process, compare it with the preset protection logic action chain, and calculate the action logic abnormality degree; Based on the time deviation fluctuation rate, the action logic abnormality degree and the time synchronization mode level parameter used by the device, construct a time credibility score for each secondary device; Based on the time credibility score, adjust the sorting strategy of the SOE event, including eliminating device events with a time credibility score below a set threshold, using a credibility weighted sorting, and combining the event causal relationship between secondary devices for compensation sorting; In the relay protection debugging link, adjust the protection action logic according to the time credibility score, including applying secondary verification, protection delay strategy or action shielding processing when the trigger signal comes from a device with a time credibility score below a set threshold.
2. The method of claim 1, wherein the method further comprises: The method for obtaining the time deviation fluctuation rate is as follows: for each sampling time t_i, the system time T_device(t_i) of a certain secondary device is subtracted from the master clock time T_master(t_i) to obtain the time deviation ΔT_i at this time; the calculation is performed at each sampling point to obtain a sequence of time deviations; the time deviation fluctuation rate TDV refers to the standard deviation of the sequence of time deviations.
3. The method of claim 1, wherein the method further comprises: The method for calculating the action logic abnormality degree comprises the following steps: Extract the actual protection action sequence of each secondary device within a set debugging period, which includes event type, trigger timestamp, action device identifier and logic channel number; Obtain the corresponding standard protection action chain from a preset configuration file, which defines the action sequence, time dependency and logic condition; Use a sequence matching algorithm to compare the similarity of the actual action sequence and the standard action chain, and calculate the sequence structure deviation; Calculate the action logic abnormality degree based on the sequence structure deviation. The method for calculating the action logic abnormality degree based on the sequence structure deviation comprises the following steps:
4. The method of claim 3, wherein the method further comprises: Convert the actual protection action sequence and the standard protection action chain into event code sequences respectively to generate a unique identifier for each action event type and logic position; Use a dynamic time warping algorithm or an edit distance algorithm to calculate the matching distance between the two sequences, which reflects the offset degree of the action sequence and logic dependency; Divide the matching distance by the total number of events in the standard action chain to obtain a standardized deviation value; Use the standardized deviation value as the action logic abnormality degree. The method for constructing a time credibility score for each secondary device comprises the following steps: Normalize the time deviation fluctuation rate and the action logic abnormality degree of each device to map them to standardized values between 0 and 1; 5. The method of claim 1, wherein the method further comprises: According to the time synchronization mode used by the device, assign a synchronization level score, where the IRIG-B synchronization mode scores 1.0, the PTP mode scores 0.9, the NTP mode scores 0.7, and the SNTP or no synchronization mode scores 0.5; A weighting coefficient is set, a weighted scoring function is constructed, a weighted sum is performed, and a time credibility score of each device is calculated; The time credibility score is compared with a set threshold value, and is used to identify a credible, suspicious, or non-credible time source.
6. The method of claim 1, wherein: In the formula, The adjustment of the ordering strategy of the SOE event includes: A threshold value of the time credibility score is set, and SOE events of all devices are screened, and events from secondary devices with a time credibility score lower than the set threshold value are removed; The retained SOE events are weighted and ordered according to the time credibility score of the device to which the event belongs, wherein the timestamp of each event is corrected to a combined value of the original time and a credibility weighted offset; For event pairs with time overlap or ordering conflict, further logical compensation ordering is performed according to a preset secondary device logical relationship or event causal graph.
7. The method of claim 1, wherein: In the formula, The adjustment of the protection action logic according to the time credibility score includes: It is judged whether a control signal triggering a protection action is from a secondary device with a time credibility score lower than a preset threshold value, and if yes, the control signal is marked as a low-credibility action source; For a protection triggering event marked as a low-credibility action source, secondary verification processing is performed, and the verification mode includes cross-device redundant signal comparison or protection action chain integrity verification; When the secondary verification fails, the trip waiting time of the protection device is extended, or the conditional judgment logic is increased; When the signal credibility is low and the verification cannot be completed, the action triggering relay protection tripping is prohibited, an action shielding process is entered, and an abnormal event is recorded.