Safety control method and system for emerging control main body
By enabling bidirectional data interaction and multiple verifications between the master station AGC and the field station AGC, the safety control problem of emerging control entities has been solved, the safety and reliability of power grid frequency operation have been achieved, and the safety control capability of the power grid has been improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-06
- Publication Date
- 2026-04-07
AI Technical Summary
With the integration of large-scale energy storage and distributed new energy sources into the grid, existing technologies pose risks to the rapid response and safe control of grid regulation resources. A single abnormal command may cause sudden changes in reverse power flow, or instantaneous exceedances of frequency or power flow limits. Communication/software errors amplify the system's exposure surface, and existing error prevention strategies have not yet been widely applied in practical systems.
Through bidirectional data interaction between the master station AGC and the field station AGC, a collaborative safety interlocking logic, multiple verification and simulation verification methods are adopted, including three-layer redundant storage, real-time data interaction, rationality verification of control commands and effect simulation, to ensure the safety of the emerging control subject.
This significantly enhances AGC's safety control capabilities over emerging control entities, ensures the safe operation of power grid frequencies, and improves the power grid's safe and reliable power supply capabilities.
Smart Images

Figure CN121806408A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a safety control method and system for emerging control subjects, belonging to the field of active power control technology in power systems. Background Technology
[0002] With the integration of large-scale energy storage and distributed renewable energy sources, grid regulation resources are exhibiting new characteristics of "fast response, large quantity, and wide distribution," bringing new security risks to the dispatch and control level: a single abnormal command can be executed simultaneously by a large number of inverters or batteries, leading to sudden changes in reverse power flow, instantaneous exceedances of frequency or power flow limits, and communication / software errors or misoperations amplify the system's exposure surface. To address these risks, systematic research has been conducted both domestically and internationally on pre-emptive verification, in-process protection, and post-event rollback of control commands, resulting in several technical routes and governance models, mainly including: First, a systematic architecture of "layered and zoned, master station-field station collaboration" has become mainstream. To avoid single-point commands from the master station triggering batch synchronous responses, the international standard is to decentralize the entire network target into regional / field station executable operation units. The master station is responsible for issuing macro-level targets and policies, while the field stations or aggregation layers are responsible for localized rapid protection and secondary confirmation. This architecture can utilize the millisecond-level local response capabilities of the field stations and avoid the risk of network-wide cascading through regional coordination, achieving a defense-in-depth approach of "local identification first, then execution or blocking".
[0003] Second, the "aggregation and rate limiting" technology is widely used. Through virtual power plants or aggregators, numerous small-capacity adjustable resources are aggregated into adjustable consortia, reporting controlled aggregate output curves and response ranges externally; internally, rate limiting, batch triggering, and randomized execution strategies are implemented to avoid synchronous peaks. Many practices have shown that distributing response actions across different time windows and introducing random / segmented triggering can significantly reduce the probability of transient impacts.
[0004] Third, "multi-factor verification + intelligent error prevention" has become a basic requirement for command issuance. Before issuing commands, the master station conducts mandatory checks through a rule engine, physical consistency verification (power flow / frequency boundaries), and scenario-based simulation. After receiving the command, the field station performs over-limit checks and equipment capability matching. At the same time, an abnormal command identifier based on historical data and machine learning is introduced, which can issue risk alarms and automatically block non-compliant or abnormal commands. This "verification-secondary confirmation-blocking" strategy has been piloted in some dispatch centers and pilot projects abroad.
[0005] However, the above research is mainly at the technical research level, and there is still a certain distance to go before the specific master-slave station collaboration, multi-verification mechanism and intelligent error prevention strategy are incorporated into the actual system application. Summary of the Invention
[0006] The purpose of this invention is to overcome the shortcomings of the prior art and provide a safety control method and system for emerging control subjects, which can significantly improve the safety control capability of AGC for emerging control subjects, ensure the safe operation of power grid frequency, and improve the safe and reliable power supply capability of the power grid.
[0007] To achieve the above objectives, the present invention is implemented using the following technical solution: In a first aspect, the present invention provides a security control method for emerging control entities, comprising: The main station's automatic power generation control system (AGC) interacts with the power station's AGC in two directions to obtain the results of the two-way data interaction. Based on the results of two-way data interaction and pre-configured collaborative error prevention parameters, the collaborative safety interlocking logic determines in real time whether the emerging control subject is in a controllable state. Acquire the active power measurement data of the emerging control subject, and perform jump detection and multi-source verification on the active power measurement data; Once the active power measurement data passes verification, a pre-control command is generated based on the control strategy. The rationality of the pre-control command is verified, including verification of the control command adjustment range and step size, verification of the magnitude of the deviation between two commands, and verification of the safety of the total adjustment deviation of the control command. The control effect of the pre-control commands that have passed the rationality check is simulated and verified; this includes sending the pre-control commands to the mirror system for simulated execution, and performing cross-sectional safety verification, frequency safety verification, and emerging control subject power safety verification based on the simulation results. Once the control effect simulation verification is successful, the pre-control instruction will be issued as the final control instruction to the emerging control entity for execution.
[0008] Furthermore, before bidirectional data interaction between the master station's automatic generation control system (AGC) and the power station's AGC, the method also includes error prevention verification of the control model of the emerging control entity, specifically: A three-layer library redundancy storage and security verification method is adopted, wherein the three-layer library includes a model verification library and a real-time runtime library; When the AGC control model is modified through manual operation via the interface or by model modification tools, the modified parameters and model are verified based on the model verification library. Only after the verification is successful will the control parameters and model be imported into the real-time runtime library; otherwise, a model anomaly alarm will be issued.
[0009] Furthermore, the bidirectional data interaction between the master station automatic generation control system (AGC) and the power plant AGC includes: the master station AGC sending first collaborative anti-misoperation real-time operation data to the power plant AGC, and the power plant AGC sending second collaborative anti-misoperation real-time operation data to the master station AGC; the first collaborative anti-misoperation real-time operation data includes one or more of the following: master station AGC operating status, renewable energy curtailment status, control time scale, master station AGC control mode, adjustment direction, and power plant control mode; the second collaborative anti-misoperation real-time operation data includes one or more of the following: substation AGC operating status, control indicators, substation AGC control mode, and renewable energy power plant operating status.
[0010] Furthermore, the pre-configured collaborative anti-misoperation parameters are configured through master-slave station collaborative parameters. These collaborative anti-misoperation parameters include: upper and lower limits of station regulation, maximum station regulation step size, maximum single power change of station, maximum regulation step size in unrestricted power state, maximum regulation step size in restricted power state, and one or more of the primary and secondary frequency regulation collaborative modes.
[0011] Furthermore, the determination criteria for the cooperative safety interlocking logic include at least one of the following: Inconsistent parameters for AGC collaboration between master and slave stations will cause the following issues: For parameters affecting real-time control safety, such as the upper and lower limits of station adjustment and the maximum single power change of the station, if they are inconsistent, the station control will be immediately locked and an alarm will be issued. For parameters that do not affect real-time control safety, such as the primary and secondary frequency modulation collaboration mode and the maximum adjustment step size under no power limitation, if they are inconsistent, only an alarm for abnormal parameter configuration will be issued. An anomaly exists in the two-level data interaction between the master station AGC and the field station AGC; Data interaction between the two levels is normal, but the timing of the AGC control at the master and slave stations is abnormal; The two-level data interaction is normal, but the substation AGC control status is abnormal, the substation exits AGC control, or the new energy power station operation status is abnormal; The two-level data interaction is normal, but the instructions received by the substation AGC from the master station AGC are inconsistent with the actual instructions issued. The two-level data interaction is normal, but the control commands issued by the master station AGC exceed the normal operating range of the substation AGC, or the deviation from the actual output of the station exceeds the threshold value.
[0012] Furthermore, the step change detection of the active power measurement data includes: Based on the active power values of the current control cycle and the previous control cycle of the emerging control subject, the change in active power value is calculated. If the change exceeds the set threshold, the active power measurement is suspected of jumping. Acquire power plant and bus measurement data related to the grid connection of the emerging control entity; If the active power measurement data changes, and the power plant measurement data changes while the bus measurement data remains balanced, then it is determined to be a normal change; otherwise, it is determined to be an abnormal change.
[0013] Furthermore, multi-source verification is performed on the active power measurement data, including: Configure at least two measurement points for the active power measurement data of the emerging control entity, including the active power measurement value sent by the station itself as the primary measurement point, and the line measurement value of the power grid dispatch terminal as the backup measurement point. When both the primary and backup measuring points are normal, the measurement deviation between the two measuring points is calculated. If the deviation exceeds a reasonable threshold, the active power measurement is judged to be abnormal. When the primary measuring point is determined to have an abnormal jump, the system automatically switches to using the backup measuring point for control. If the backup measuring point also experiences an abnormal jump, the active power measurement of the station is determined to be abnormal, and the cooperative safety interlocking logic is triggered to lock the station control.
[0014] Furthermore, the rationality verification of the pre-control command includes: The adjustment range and step size of the control command are verified. If the pre-control command exceeds the adjustment range of the control body, the command is determined to be abnormal and invalid. If the deviation between the pre-control command and the actual current power exceeds the command adjustment step size, the command is determined to be abnormal and invalid. The deviation between two consecutive commands is checked. If the deviation between the current control command and the previous control command exceeds a specified threshold, the current control command is determined to be abnormal and invalid. The total control deviation of the control commands is checked for safety. If the total control deviation of all commands in the current control cycle exceeds the specified threshold, all control commands are judged to be abnormal and invalid.
[0015] Furthermore, the step of performing control effect simulation verification on the pre-control instructions that have passed the rationality check includes: The pre-control instructions that have passed the rationality verification are sent to the mirror system of the scheduling system. The mirror system has an operating environment and control functions that are completely consistent with the actual operating system. In the mirror system, the control objectives of the emerging control subject are simulated and executed by the simulation platform, and the grid frequency and power flow are recalculated; Based on the power grid frequency, active power of the control entity, and power flow power calculated by the simulation platform, cross-section safety verification, frequency safety verification, and emerging control entity power safety verification are carried out. If the cross-sectional safety verification, frequency safety verification, and emerging control main body power safety verification all pass, the control command is considered normal; if the grid frequency safety verification or the control main body active power verification fails, the control command is considered abnormal and the control command is determined to be invalid.
[0016] Furthermore, if the collaborative security interlocking logic determines that the emerging control subject is in an uncontrollable state, then the real-time control of the emerging control subject is interlocked.
[0017] In a second aspect, the present invention provides a system for implementing the security control method for emerging control subjects as described in any of the foregoing claims, the system comprising: The master station AGC module, deployed in the power grid dispatch and control center, is used to perform the following steps: Generate and send the first collaborative anti-misoperation real-time operation data to the station side; Receive and process the second collaborative anti-misoperation real-time operation data sent from the station side; Store and manage collaborative error prevention parameters; Based on two-way data interaction and collaborative error prevention parameters, the judgment of collaborative safety interlocking logic is executed; When the situation is determined to be controllable, a pre-control command is generated; Verify the rationality of executing the pre-control instructions and perform simulation verification of the control effect; After all verifications are passed, the final control command is sent to the station side; The site AGC module, deployed at one or more new energy or energy storage sites, is used to perform the following steps: Receive and process the first collaborative anti-misoperation real-time operation data sent from the main station; Collect and transmit the second collaborative anti-misoperation real-time operation data to the main station; Execute the final control commands issued by the master station; A data interaction network connects the master station AGC module and the field station AGC module, and is used to establish a communication channel between the master station AGC module and the field station AGC module to transmit the collaborative anti-misoperation real-time operation data and the control commands; The mirror simulation system, connected to the main station AGC module, is used to perform the following steps: Receive pre-control commands from the master station AGC module; In a mirror system with an environment consistent with the actual operating system, the pre-control commands are simulated and executed, and the grid frequency and power flow are recalculated. Based on the simulation results, cross-sectional safety verification, frequency safety verification, and emerging control main power safety verification are performed, and the verification results are returned to the main station AGC module.
[0018] Compared with the prior art, the beneficial effects achieved by the present invention are as follows: This invention provides a safety control method and system for emerging control entities, targeting new energy sources, energy storage, and other emerging control entities. Addressing the dual constraints of control risks and the rapid regulation requirements of the power grid, this invention proposes a safety control method for emerging control entities. The method is designed from three dimensions: master station AGC-field station AGC collaboration, control command security generation-virtual control effect simulation collaboration, and control parameter setting-control scenario switching collaboration. This significantly improves the AGC's safety control capabilities for emerging control entities, ensures the safe operation of the power grid frequency, and enhances the power grid's safe and reliable power supply capabilities. Attached Figure Description
[0019] Figure 1 This is a flowchart of a security control method for emerging control subjects provided by an embodiment of the present invention. Detailed Implementation
[0020] The present invention will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and should not be used to limit the scope of protection of the present invention.
[0021] Example 1: This example introduces a security control method for emerging control subjects, including: The main station's automatic power generation control system (AGC) interacts with the power station's AGC in two directions to obtain the results of the two-way data interaction. Based on the results of two-way data interaction and pre-configured collaborative error prevention parameters, the collaborative safety interlocking logic determines in real time whether the emerging control subject is in a controllable state. Acquire the active power measurement data of the emerging control subject, and perform jump detection and multi-source verification on the active power measurement data; Once the active power measurement data passes verification, a pre-control command is generated based on the control strategy. The rationality of the pre-control command is verified, including verification of the control command adjustment range and step size, verification of the magnitude of the deviation between two commands, and verification of the safety of the total adjustment deviation of the control command. The control effect of the pre-control commands that have passed the rationality check is simulated and verified; this includes sending the pre-control commands to the mirror system for simulated execution, and performing cross-sectional safety verification, frequency safety verification, and emerging control subject power safety verification based on the simulation results. Once the control effect simulation verification is successful, the pre-control instruction will be issued as the final control instruction to the emerging control entity for execution.
[0022] The security control method for emerging control entities provided in this embodiment involves the following steps in its application process: (1) In response to the frequency and tie-line control requirements of high-proportion new energy power grids, an AGC control area is generally established in the power grid dispatch control center, which is mainly responsible for implementing closed-loop control of conventional thermal power units, centralized and distributed new energy power plants, and various types of energy storage and other emerging control entities within the dispatch control area.
[0023] (2) First, the control model of the emerging control subject is checked for error prevention in the automatic power generation control function. The check mechanism adopts a three-layer library redundant storage and security check method. When the control parameters are modified manually in the interface or the AGC control model is modified using the model modification tool provided by the scheduling system platform, the modified parameters and model are checked based on the model check library. Only control parameters and models that pass the check can be introduced into the real-time operation library. Otherwise, a model abnormality alarm is given to ensure that erroneous control models and parameters are not introduced into the AGC real-time control.
[0024] (3) In response to the safety control needs of emerging control entities, a safety control architecture for collaborative prevention of errors between master station AGC and field station AGC is established, including collaborative safety control interaction information between master station AGC and field station AGC, collaborative parameter configuration and collaborative safety interlocking measures.
[0025] (4) When the master station AGC and the field station AGC work together to prevent errors, the master-slave station collaborative error prevention data exchange information should be determined first, including: (41) The master station AGC sends the first collaborative anti-misoperation real-time operation data to the sub-station AGC, including: master station AGC operation status, new energy power restriction status, control time scale, master station AGC control mode, adjustment direction, and station control mode, etc. (42) The substation AGC sends the second collaborative anti-misoperation real-time operation data to the master station AGC, including: substation AGC operation status, control indicators, substation AGC control mode, new energy station operation status, etc.; (5) When the master station AGC and the field station AGC are in coordination, it is also necessary to configure the master-slave station coordination anti-misoperation parameters, including: the upper and lower limits of field station adjustment, the maximum adjustment step size of the field station, the maximum change of field station power in a single operation, the maximum adjustment step size in the unrestricted state, the maximum adjustment step size in the restricted state, and the coordination mode of primary frequency regulation and secondary frequency regulation, etc. (6) Based on the collaborative data interaction and collaborative error prevention parameter configuration between the master station AGC and the sub-station AGC, formulate the collaborative safety interlocking logic between the master station AGC and the sub-station AGC, including: (61) Anti-misoperation parameters of master station AGC collaboration are inconsistent. For anti-misoperation parameters that affect the safety of real-time control, such as (the upper and lower limits of station adjustment, the maximum change of station power in a single operation), the station control will be immediately blocked and an abnormal configuration alarm will be issued when they are inconsistent. For anti-misoperation parameters that do not affect the safety of real-time control, such as the coordination mode of primary frequency regulation and secondary frequency regulation, the maximum adjustment step size in the power-free state, etc., only an abnormal alarm for the configuration of anti-misoperation parameters can be issued. (62) If the data interaction between the two levels of AGC is abnormal, the AGC of the new energy station is determined to be abnormal, and the real-time control of the station is directly locked. (63) If the data interaction between the two levels of AGC is normal, but the timing of the AGC control of the master station is abnormal, then the AGC of the new energy power station is determined to be abnormal, and the real-time control of the power station is directly blocked. (63) If the data interaction between the two levels of AGC is normal, but the timing of the AGC control of the master station is abnormal, then the AGC of the new energy power station is determined to be abnormal, and the real-time control of the power station is directly blocked. (64) If the two-level AGC data interaction is normal, but the substation AGC control status is abnormal, the substation exits AGC control, or the new energy power station operation status is abnormal, the real-time control of the power station shall be directly locked. (65) If the data interaction between the two levels of AGC is normal, and the instruction received by the substation AGC from the master station AGC is inconsistent with the actual instruction, the operation of the new energy power station is determined to be abnormal, and the real-time control of the power station is directly locked. (66) If the data interaction between the two AGCs is normal, and the control command issued by the master station AGC exceeds the normal operating range of the substation AGC or the deviation from the actual output of the station exceeds the threshold value, it is determined that the control command of the master station AGC is abnormal, and the real-time control of the station is locked.
[0026] (67) Only when none of the above (61) to (66) blocking conditions are triggered will the emerging control subject be determined to be in a controllable state and allowed to enter the subsequent control command generation and verification process; otherwise, the real-time control of the station will be continuously blocked.
[0027] (7) After the emerging control subject participates in the main station AGC closed-loop control, a safe control architecture is established to coordinate the safe generation of control instructions and the simulation of virtual control effects. This includes: multi-source configuration of active power measurement of emerging subject, power jump verification of emerging control subject, reasonable range verification of control instructions of emerging control subject, and rapid simulation verification of control instructions. (8) When calculating the control objectives of emerging control subjects, first carry out safety and error prevention on the measurement data of emerging control subjects, including jump detection and multi-source verification of active power measurement data. The specific methods are as follows: (81) First, based on the active power value of the emerging control subject in the current control cycle and the previous control cycle, and according to the change in the active power value of the control subject in the two cycles, if the change exceeds the set threshold (e.g., 20MW), then it is judged that the active power measurement of the emerging control subject is suspected of jumping. Then, further obtain the plant and substation measurement data and the bus measurement data connected to the grid related to the emerging control subject. Next, carry out the measurement data balance verification. If the active power measurement data jumps and the plant and substation measurement jumps and the bus measurement data are balanced, then it is judged that the data of the emerging control subject jumps normally; otherwise, it is considered that the active power measurement data jumps abnormally.
[0028] (82) For the key active power measurement data of the emerging control subject, at least two measurement points shall be configured, including the active power measurement value sent by the emerging control subject station itself, and the line measurement of the power grid dispatch terminal as the active power measurement value of the emerging control subject. Among them, the active power measurement value sent by the station itself shall be the primary measurement point, and the line measurement of the power grid dispatch terminal shall be the backup measurement point.
[0029] (83) When both the main and backup measurement points of the active power measurement of the emerging control subject are normal, the active power measurement is judged to be abnormal if the deviation of the measurement point exceeds the reasonable threshold. (84) When the main measuring point of the active power measurement of the emerging control subject detects an abnormal jump, the backup measuring point is automatically used for control. If the backup measuring point also shows an abnormal jump, the active power measurement of the station is judged to be abnormal, and the control of the station is blocked.
[0030] (9) After the active power measurement data of the emerging control subject is verified, a pre-control command of the control subject is generated through a certain control strategy. Then, the rationality of the control command of the emerging control subject is verified, including: (91) Control command adjustment range and step size verification: If the control command exceeds the adjustment range of the control body, the control command is deemed abnormal and invalid. If the deviation between the control command and the actual current power exceeds the command adjustment step size, the control command is deemed abnormal and invalid.
[0031] (92) Check the deviation between two consecutive commands. If the deviation between the current control command and the previous control command exceeds the specified threshold, the current control command is deemed abnormal and invalid. (93) Safety check of total control command deviation: If the total control deviation of all commands in this control cycle exceeds the specified threshold, then all control commands are judged to be abnormal and all control commands are invalid.
[0032] (10) After the control instructions of the emerging control subject have been verified for rationality, they still need to be verified by control effect simulation before they are officially issued. The specific steps are as follows: (101) The generated control system is sent to the mirror system of the scheduling system. The mirror system has the same operating environment and control functions as the actual operating system. (102) In the mirror system, the control objectives of the emerging control subject are simulated and executed by the simulation platform, and the grid frequency and power flow are recalculated. (103) Based on the power grid frequency, active power of the control body and power flow obtained by simulation platform, carry out section safety verification, frequency safety verification and emerging control body power safety verification; (104) If the power grid frequency, active power of the control body and power flow are all verified, the control command is considered normal; if the power grid frequency and active power of the control body fail to be verified, the control command is considered abnormal and the control command is deemed invalid.
[0033] (11) After the control instructions of the emerging control subject are verified to be correct through multiple checks, they are then issued to the control subject for execution to ensure that the control instructions are safe and reliable.
[0034] The following description, in conjunction with a preferred embodiment, illustrates the content involved in the above embodiments.
[0035] like Figure 1 As shown, in response to the frequency and tie-line control requirements of a high proportion of renewable energy power grids, the preferred approach is to establish an AGC control area in the dispatch center, which is mainly responsible for implementing closed-loop control of conventional thermal power units, centralized and distributed renewable energy power plants, and various types of energy storage and other emerging control entities within the dispatch and management scope.
[0036] When developing new control entities, the first step is to perform error prevention verification on the control model of the new control entity in the automatic generation control function. The verification mechanism adopts a three-layer redundant storage and security verification method. When the control parameters are modified manually in the interface or the AGC control model is modified using the model modification tool provided by the scheduling system platform, the modified parameters and model are verified based on the model verification library. Only control parameters and models that pass the verification can be introduced into the real-time operation library; otherwise, a model anomaly alarm is given to ensure that erroneous control models and parameters are not introduced into the AGC real-time control.
[0037] Then, in response to the safety control needs of emerging control entities, a collaborative safety control architecture for preventing errors between the master station AGC and the field station AGC is established, including collaborative safety control interaction information between the master station AGC and the field station AGC, collaborative parameter configuration, and collaborative safety interlocking measures.
[0038] Then, when carrying out collaborative anti-misoperation between the master station AGC and the substation AGC, the data interaction information for collaborative anti-misoperation between the master and substations is first determined. The master station AGC and the substation AGC conduct bidirectional data interaction. The master station AGC sends the first collaborative anti-misoperation real-time operation data to the substation AGC, including: master station AGC operation status, renewable energy power curtailment status, control time scale, master station AGC control mode, adjustment direction, substation control mode, etc. The substation AGC sends the second collaborative anti-misoperation real-time operation data to the master station AGC, including: substation AGC operation status, control indicators, substation AGC control mode, renewable energy substation operation status, etc. At the same time, in addition to real-time data interaction between the main station AGC and the sub-station AGC, it is also necessary to configure the main-sub-station collaborative anti-misoperation parameters, including: the upper and lower limits of the station adjustment, the maximum adjustment step size of the station, the maximum change in the station power in a single operation, the maximum adjustment step size in the unrestricted state, the maximum adjustment step size in the restricted state, and the coordination mode of primary frequency regulation and secondary frequency regulation, etc. Then, based on the collaborative data interaction between the master station AGC and the sub-station AGC and the configuration of collaborative anti-misoperation parameters, a collaborative safety interlocking logic between the master station AGC and the sub-station AGC is formulated and executed in real time. This includes anti-misoperation measures for inconsistent anti-misoperation parameters between the master and sub-station AGCs. For anti-misoperation parameters that affect real-time control safety, such as (station adjustment upper and lower limits, maximum single power change of the station), if inconsistent, the station control is immediately locked and an abnormal configuration alarm is issued. For anti-misoperation parameters that do not affect real-time control safety, such as the primary and secondary frequency regulation coordination mode, the maximum adjustment step size in the unrestricted power state, etc., only an abnormal anti-misoperation parameter configuration alarm can be issued. If the data interaction between the two levels of AGCs is abnormal, the AGC of the new energy station is determined to be abnormal, and the real-time control of the station is directly locked. If the data interaction between the C and D stations is normal, but the timing of the AGC control at the master and slave stations is abnormal, the AGC at the new energy power station is determined to be abnormal, and the real-time control of the power station is directly locked. If the data interaction between the two levels of AGC is normal, but the slave station's AGC control status is abnormal, the slave station exits AGC control, or the new energy power station is in operation, the real-time control of the power station is directly locked. If the data interaction between the two levels of AGC is normal, but the instructions received by the slave station AGC from the master station AGC are inconsistent with the actual instructions issued, the new energy power station is determined to be in operation abnormal, and the real-time control of the power station is directly locked. If the data interaction between the two levels of AGC is normal, but the control instructions issued by the master station AGC exceed the normal operating range of the slave station AGC or the deviation from the actual output of the power station exceeds a threshold value, the master station AGC control instructions are determined to be abnormal, and the real-time control of the power station is locked. Only when all locking conditions are not met and the power station is determined to be in a controllable state will subsequent steps be executed.
[0039] Under the premise that the emerging control subject is in a controllable state based on the collaborative safety interlocking logic, a collaborative safety control architecture for control command security generation and virtual control effect simulation is further established, including: multi-source configuration of active power measurement of emerging subject, power jump verification of emerging control subject, reasonable range verification of control command of emerging control subject, and rapid simulation verification of control command. First, in calculating the control objectives of the emerging control entity, safety and error prevention measures are implemented for its measurement data. This includes active power measurement data jump detection and multi-source verification. Specifically, based on the active power values of the emerging control entity in the current and previous control cycles, the change in active power value between the two cycles is analyzed. If the change exceeds a predetermined threshold (e.g., 20MW), the active power measurement of the emerging control entity is suspected of jumping. Next, the relevant substation and bus measurement data connected to the grid are obtained. The next step is to assess the risk of measurement data balancing. If an active power measurement data jump occurs and both the substation and bus measurement data are balanced, the data jump is considered normal; otherwise, the active power measurement data is considered abnormal. For key active power measurement data of emerging control entities, at least two measurement points should be configured: the active power measurement value transmitted by the emerging control entity's own power station and the line measurement value from the power grid dispatching terminal. The active power measurement value transmitted by the power station itself serves as the primary measurement point, while the line measurement value from the power grid dispatching terminal serves as the backup measurement point. When both the primary and backup measurement points for the active power measurement of the emerging control entity are normal, an active power measurement anomaly is determined by calculating whether the deviation of the measurement points exceeds a reasonable threshold. If an abnormal jump is detected in the primary measurement point of the emerging control entity's active power measurement, the backup measurement point is automatically used for control. If the backup measurement point also experiences an abnormal jump, the active power measurement of the power station is determined to be abnormal, and the control of that power station is blocked.
[0040] Then, after the active power measurement data of the emerging control subject is verified, a pre-control command is generated for the control subject through a certain control strategy. Then, the rationality of the control command of the emerging control subject is verified, including: verification of the control command adjustment range and step size, verification of the magnitude of the deviation between the two commands, and verification of the safety of the total adjustment deviation of the control command.
[0041] Then, after the control commands of the emerging control entity undergo rationality verification, a control effect simulation verification is performed before they are officially issued. Specifically, the generated control system is first sent to the mirror system of the dispatching system. The mirror system has an operating environment and control functions completely consistent with the actual operating system. In the mirror system, the simulation platform simulates the execution of the emerging control entity's control objectives and recalculates the grid frequency and power flow. Based on the grid frequency, active power of the control entity, and power flow calculated by the simulation platform, section safety verification, frequency safety verification, and emerging control entity power safety verification are performed. If the grid frequency, active power of the control entity, and power flow safety verification all pass, the control command is considered normal; if the grid frequency and active power verification fail, the control command is considered abnormal and invalid.
[0042] Finally, the control commands of the emerging control entity are verified through multiple checks before being issued to the control entity for execution, ensuring the safety and reliability of the control commands.
[0043] Example 2: This example provides a system for implementing the security control method for emerging control subjects as described in any one of Examples 1. The system includes: The master station AGC module, deployed in the power grid dispatch and control center, is used to perform the following steps: Generate and send the first collaborative anti-misoperation real-time operation data to the station side; Receive and process the second collaborative anti-misoperation real-time operation data sent from the station side; Store and manage collaborative error prevention parameters; Based on two-way data interaction and collaborative error prevention parameters, the judgment of collaborative safety interlocking logic is executed; When the situation is determined to be controllable, a pre-control command is generated; Verify the rationality of executing the pre-control instructions and perform simulation verification of the control effect; After all verifications are passed, the final control command is sent to the station side; The site AGC module, deployed at one or more new energy or energy storage sites, is used to perform the following steps: Receive and process the first collaborative anti-misoperation real-time operation data sent from the main station; Collect and transmit the second collaborative anti-misoperation real-time operation data to the main station; Execute the final control commands issued by the master station; A data interaction network connects the master station AGC module and the field station AGC module, and is used to establish a communication channel between the master station AGC module and the field station AGC module to transmit the collaborative anti-misoperation real-time operation data and the control commands; The mirror simulation system, connected to the main station AGC module, is used to perform the following steps: Receive pre-control commands from the master station AGC module; In a mirror system with an environment consistent with the actual operating system, the pre-control commands are simulated and executed, and the grid frequency and power flow are recalculated. Based on the simulation results, cross-sectional safety verification, frequency safety verification, and emerging control main power safety verification are performed, and the verification results are returned to the main station AGC module.
[0044] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
[0045] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, systems, or computer program products. Therefore, this disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this disclosure can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0046] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0047] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0048] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0049] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this disclosure and not to limit its protection scope. Although this disclosure has been described in detail with reference to the above embodiments, those skilled in the art should understand that after reading this disclosure, they can still make various changes, modifications or equivalent substitutions to the specific implementation of the invention, but these changes, modifications or equivalent substitutions are all within the protection scope of the pending claims.
Claims
1. A security control method for emerging control entities, characterized in that, include: The main station's automatic power generation control system (AGC) interacts with the power station's AGC in two directions to obtain the results of the two-way data interaction. Based on the results of two-way data interaction and pre-configured collaborative error prevention parameters, the collaborative safety interlocking logic determines in real time whether the emerging control subject is in a controllable state. Acquire the active power measurement data of the emerging control subject, and perform jump detection and multi-source verification on the active power measurement data; Once the active power measurement data passes verification, a pre-control command is generated based on the control strategy. The rationality of the pre-control command is verified, including verification of the control command adjustment range and step size, verification of the magnitude of the deviation between two commands, and verification of the safety of the total adjustment deviation of the control command. The control effect of the pre-control commands that have passed the rationality check is simulated and verified; this includes sending the pre-control commands to the mirror system for simulated execution, and performing cross-sectional safety verification, frequency safety verification, and emerging control subject power safety verification based on the simulation results. Once the control effect simulation verification is successful, the pre-control instruction will be issued as the final control instruction to the emerging control entity for execution.
2. The security control method for emerging control subjects according to claim 1, characterized in that, Before bidirectional data interaction between the master station's automatic generation control system (AGC) and the power plant's AGC, the method also includes error prevention verification of the control model of the emerging control subject, specifically: A three-layer library redundancy storage and security verification method is adopted, wherein the three-layer library includes a model verification library and a real-time runtime library; When the AGC control model is modified through manual operation via the interface or by model modification tools, the modified parameters and model are verified based on the model verification library. Only after the verification is successful will the control parameters and model be imported into the real-time runtime library; otherwise, a model anomaly alarm will be issued.
3. The security control method for emerging control subjects according to claim 1, characterized in that, The bidirectional data interaction between the master station automatic generator control system (AGC) and the power plant AGC includes: the master station AGC sending first collaborative anti-misoperation real-time operation data to the power plant AGC, and the power plant AGC sending second collaborative anti-misoperation real-time operation data to the master station AGC; the first collaborative anti-misoperation real-time operation data includes one or more of the following: master station AGC operating status, renewable energy curtailment status, control time scale, master station AGC control mode, adjustment direction, and power plant control mode; the second collaborative anti-misoperation real-time operation data includes one or more of the following: substation AGC operating status, control indicators, substation AGC control mode, and renewable energy power plant operating status.
4. The security control method for emerging control subjects according to claim 1, characterized in that, The pre-configured collaborative anti-misoperation parameters are configured through master-slave station collaborative parameters. The collaborative anti-misoperation parameters include: upper and lower limits of station regulation, maximum station regulation step size, maximum single power change of station, maximum regulation step size in unrestricted power state, maximum regulation step size in restricted power state, and one or more of the primary and secondary frequency regulation collaborative modes.
5. The security control method for emerging control subjects according to claim 1, characterized in that, The determination criteria for the cooperative safety interlocking logic include at least one of the following: Inconsistent parameters for AGC collaboration between master and slave stations will cause the following issues: For parameters affecting real-time control safety, such as the upper and lower limits of station adjustment and the maximum single power change of the station, if they are inconsistent, the station control will be immediately locked and an alarm will be issued. For parameters that do not affect real-time control safety, such as the primary and secondary frequency modulation collaboration mode and the maximum adjustment step size under no power limitation, if they are inconsistent, only an alarm for abnormal parameter configuration will be issued. An anomaly exists in the two-level data interaction between the master station AGC and the field station AGC; Data interaction between the two levels is normal, but the timing of the AGC control at the master and slave stations is abnormal; The two-level data interaction is normal, but the substation AGC control status is abnormal, the substation exits AGC control, or the new energy power station operation status is abnormal; The two-level data interaction is normal, but the instructions received by the substation AGC from the master station AGC are inconsistent with the actual instructions issued. The two-level data interaction is normal, but the control commands issued by the master station AGC exceed the normal operating range of the substation AGC, or the deviation from the actual output of the station exceeds the threshold value.
6. The security control method for emerging control subjects according to claim 1, characterized in that, The step change detection of active power measurement data includes: Based on the active power values of the current control cycle and the previous control cycle of the emerging control subject, the change in active power value is calculated. If the change exceeds the set threshold, the active power measurement is suspected of jumping. Acquire power plant and bus measurement data related to the grid connection of the emerging control entity; If the active power measurement data changes, and the power plant measurement data changes while the bus measurement data remains balanced, then it is determined to be a normal change; otherwise, it is determined to be an abnormal change.
7. The security control method for emerging control subjects according to claim 1, characterized in that, Multi-source verification of active power measurement data, including: Configure at least two measurement points for the active power measurement data of the emerging control entity, including the active power measurement value sent by the station itself as the primary measurement point, and the line measurement value of the power grid dispatch terminal as the backup measurement point. When both the primary and backup measuring points are normal, the measurement deviation between the two measuring points is calculated. If the deviation exceeds a reasonable threshold, the active power measurement is judged to be abnormal. When the primary measuring point is determined to have an abnormal jump, the system automatically switches to using the backup measuring point for control. If the backup measuring point also experiences an abnormal jump, the active power measurement of the station is determined to be abnormal, and the cooperative safety interlocking logic is triggered to lock the station control.
8. The security control method for emerging control subjects according to claim 1, characterized in that, The rationality verification of the pre-control command includes: The adjustment range and step size of the control command are verified. If the pre-control command exceeds the adjustment range of the control body, the command is determined to be abnormal and invalid. If the deviation between the pre-control command and the actual current power exceeds the command adjustment step size, the command is determined to be abnormal and invalid. The deviation between two consecutive commands is checked. If the deviation between the current control command and the previous control command exceeds a specified threshold, the current control command is determined to be abnormal and invalid. The total control deviation of the control commands is checked for safety. If the total control deviation of all commands in the current control cycle exceeds the specified threshold, all control commands are judged to be abnormal and invalid.
9. The security control method for emerging control subjects according to claim 1, characterized in that, The simulation verification of the control effect of the pre-control instructions that have passed the rationality check includes: The pre-control instructions that have passed the rationality verification are sent to the mirror system of the scheduling system. The mirror system has an operating environment and control functions that are completely consistent with the actual operating system. In the mirror system, the control objectives of the emerging control subject are simulated and executed by the simulation platform, and the grid frequency and power flow are recalculated; Based on the power grid frequency, active power of the control entity, and power flow power calculated by the simulation platform, cross-section safety verification, frequency safety verification, and emerging control entity power safety verification are carried out. If the cross-sectional safety verification, frequency safety verification, and emerging control main body power safety verification all pass, the control command is considered normal; if the grid frequency safety verification or the control main body active power verification fails, the control command is considered abnormal and the control command is determined to be invalid.
10. The security control method for emerging control subjects according to claim 1, characterized in that, If the collaborative security interlocking logic determines that the emerging control subject is in an uncontrollable state, then it interlocks the real-time control of the emerging control subject.
11. A system for implementing the security control method for emerging control subjects according to any one of claims 1-10, characterized in that, The system includes: The master station AGC module, deployed in the power grid dispatch and control center, is used to perform the following steps: Generate and send the first collaborative anti-misoperation real-time operation data to the station side; Receive and process the second collaborative anti-misoperation real-time operation data sent from the station side; Store and manage collaborative error prevention parameters; Based on two-way data interaction and collaborative error prevention parameters, the judgment of collaborative safety interlocking logic is executed; When the situation is determined to be controllable, a pre-control command is generated; Verify the rationality of executing the pre-control instructions and perform simulation verification of the control effect; After all verifications are passed, the final control command is sent to the station side; The site AGC module, deployed at one or more new energy or energy storage sites, is used to perform the following steps: Receive and process the first collaborative anti-misoperation real-time operation data sent from the main station; Collect and transmit the second collaborative anti-misoperation real-time operation data to the main station; Execute the final control commands issued by the master station; A data interaction network connects the master station AGC module and the field station AGC module, and is used to establish a communication channel between the master station AGC module and the field station AGC module to transmit the collaborative anti-misoperation real-time operation data and the control commands; The mirror simulation system, connected to the main station AGC module, is used to perform the following steps: Receive pre-control commands from the master station AGC module; In a mirror system with an environment consistent with the actual operating system, the pre-control commands are simulated and executed, and the grid frequency and power flow are recalculated. Based on the simulation results, cross-sectional safety verification, frequency safety verification, and emerging control main power safety verification are performed, and the verification results are returned to the main station AGC module.
Citation Information
Cited By
Safety control method and system for load storage resources to participate in master station power control
CN122001032A
Safety control method and system for power control of host station by load storage resource
CN122001032B