Security alarm and linkage method for electricity utilization information acquisition terminal
By mapping safety alarms to the electrical and communication topology in the electricity consumption information collection terminal and combining alarm propagation fingerprinting to screen root cause nodes, the problems of false alarms and alarm storms in the existing technology are solved, achieving more accurate alarms and linkage control, and improving the reliability and operation and maintenance efficiency of the electricity consumption information collection system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-29
- Publication Date
- 2026-04-10
AI Technical Summary
In application scenarios with dense power consumption information collection terminals, complex power loads, and multiple layers of superimposed power grid electrical and communication topologies, existing technologies struggle to accurately characterize the temporal behavior of terminal operating conditions and the inter-regional correlations, leading to false alarms, invalid alarms, and alarm storms. It is also difficult to quickly identify the main root causes and the affected scope, resulting in untimely and crude operation and maintenance decisions.
By mapping safety alarm events to electrical and communication topologies at edge nodes, and combining alarm propagation fingerprints and voltage and current to filter root cause nodes, root cause results are formed. The master station selects linkage action chains in the scenario-risk-action matrix based on the root cause results, and updates the working threshold, alarm propagation fingerprint weight, and linkage action chain priority to improve the reliability of root cause and linkage.
It improves the accuracy of alarms and the reliability of linkage control, reduces false alarms and invalid alarms, and can quickly identify the main root causes and the scope of impact, enabling reasonable linkage handling and operation and maintenance decisions.
Smart Images

Figure CN121842232A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power safety control technology, specifically to a method for safety alarm and linkage of power consumption information collection terminals. Background Technology
[0002] Currently, with the continuous development of smart grids and power distribution automation, electricity information collection terminals have been widely used in urban communities, university campuses, industrial parks, commercial complexes, hospitals, data centers, and other areas. They are mainly used for remote collection of electricity metering data, power outage monitoring, and analysis of electricity anomalies. Most existing technical regulations for electricity information collection systems require the main station to have equipment alarm and data anomaly management functions, relying on over-limit alarms and power outage events sent from the terminals to assist in fault diagnosis and work order dispatch. A small number of smart electricity consumption and power distribution room monitoring products have leakage, temperature rise, and overcurrent detection functions designed on the terminal side to achieve local tripping and platform alarms.
[0003] In such systems, terminals determine limits based on fixed thresholds or simple upper and lower limits for voltage, current, and temperature. Alarms are typically sent as individual limit-breaking events or power outages. The regional side usually aggregates alarms by transformer area or concentrator, while the master station triggers appropriate actions based on alarm type and quantity. In larger-scale systems, due to the large number of terminals, diverse user types, load characteristics, multiple electrical topology layers in the power grid, and the periodic and sudden nature of electricity consumption, this single-point static threshold judgment struggles to distinguish between normal fluctuations and dangerous conditions. This can lead to a surge of alarms during seasonal changes or load switching, and may fail to reflect the development of some hidden faults in a timely manner. In particular, when there are voltage fluctuations, poor line contact, local overload, or communication link abnormalities in the distribution area, multiple terminals simultaneously send out alarms for exceeding limits, disconnection, and power outage in a short period of time, forming an alarm storm. This simple rule-based alarm handling method of summarizing and statistically analyzing alarms is not easy to establish a causal relationship between the terminal side, the area side, and the main station side. It requires maintenance personnel to detect at each level, which takes a long time to locate the problem and leads to problems such as ignoring alarms and overly rough linkage handling.
[0004] The technical problem that this invention needs to solve is: In application scenarios characterized by a high density of terminals collecting electricity consumption information, complex electricity loads, and multiple layers of superimposed electrical and communication topologies in the power grid, how can we more accurately characterize the temporal behavior of terminal operating conditions and the inter-regional correlations in the processes of terminal alarm generation, regional alarm aggregation, and alarm linkage control? This would enable the transmitted safety alarms to more intuitively reflect the real electrical risks and equipment status, reduce false alarms, invalid alarms, and alarm storms caused by single-point static thresholds, and quickly identify the main root causes and affected areas when large-scale anomalies occur, allowing for reasonable linkage handling and operation and maintenance decisions. Summary of the Invention
[0005] (a) Technical problems to be solved To address the shortcomings of existing technologies, this invention provides a safety alarm and linkage method for electricity information acquisition terminals. By mapping safety alarm events to electrical and communication topologies at edge nodes, and combining alarm propagation fingerprints and voltage / current data to filter root cause nodes, a root cause result is formed. At the master station, based on the root cause result, a linkage action chain is selected and executed from the scenario-risk-action matrix. Alarm, root cause, and linkage records are summarized according to a statistical period, and the working threshold, alarm propagation fingerprint weight, and linkage action chain priority are updated. This improves the reliability of root cause and linkage, reduces invalid alarms and mishandling, and enhances control accuracy; thus solving the technical problems described in the background art.
[0006] (II) Technical Solution To achieve the above objectives, the present invention provides the following technical solution: The method for safety alarm and linkage of power information collection terminal includes: on the terminal side, the working threshold is determined based on physical safety baseline parameters and the profiling unit is divided according to the scenario. When the parameter is close to the working threshold, the window is activated to extract dynamic fingerprints. After matching with the dangerous mode fingerprint, a safety alarm event carrying the profiling unit identifier is generated. On the edge node side, the safety alarm event is received and mapped to the electrical and communication topology. The fault mode is obtained by matching the mapping result according to the alarm propagation fingerprint database. Power flow calculation and dual topology verification are performed in combination with the electrical quantities uploaded by the terminal to determine the root cause node and generate the root cause result. The master station selects the linkage action chain corresponding to the scenario risk in the scenario-risk-action matrix based on the root cause results, issues control instructions for the root cause node and downstream terminals, and adjusts subsequent actions based on returned data and alarm changes during execution. After the statistical period ends, the master station generates terminal threshold settings, alarm propagation fingerprint database and scenario-risk-action matrix update configuration based on security alarm events, root cause results and linkage action chain execution records, and issues them to the terminal and edge nodes.
[0007] Furthermore, when dividing the user profile units, the electricity information collection terminal is based on the combination of peak, off-peak, and low-peak operating times, as well as weekdays and holidays, and the user categories of residents, apartments, hospitals, and data centers. Historical operating data is also grouped according to the location of the transformer area and branch, normal, maintenance, and power supply protection operation modes, as well as the load component fingerprints of active power, reactive power, harmonics, and three-phase imbalance. Each group corresponds to a profile unit, and the profile unit identifier is carried in the alarm event.
[0008] Furthermore, when the parameters approach the working threshold, the terminal increases the sampling frequency by setting a confirmation window to obtain short-term current, voltage or wire temperature sequences. From these sequences, it calculates local dynamic features such as the rise or fall slope, fluctuation amplitude, fluctuation frequency and duration. The local dynamic features are combined into a local dynamic fingerprint vector and compared with the fingerprints in the dangerous mode fingerprint database. An alarm event is generated only when the similarity meets the preset conditions.
[0009] Furthermore, when edge nodes map alarm events to the electrical and communication topology diagram, they establish nodes and upstream and downstream relationships in the electrical topology diagram according to the levels of transformers, switches, lines and terminals. In the communication topology diagram, establish node and link relationships according to master station, concentrator, collector and terminal, and select candidate alarm propagation fingerprints that match the current area and device type from the alarm propagation fingerprint database. Each candidate alarm propagation fingerprint describes the expected coverage and propagation order of the alarm on the dual topology.
[0010] Furthermore, when edge nodes use alarm propagation fingerprints to screen root cause nodes, they verify whether the candidate root cause nodes cover downstream nodes that have lost power or are alarmed on the electrical topology map, and verify whether the corresponding links on the communication topology map are connected. Under the root cause node assumption, power flow estimation is performed on the voltage and current of downstream nodes. The estimated values are compared with the measured values uploaded by the terminal. If the topology is consistent and the voltage and current deviations meet the tolerance, the candidate root cause node is written into the root cause results as the root cause node.
[0011] Furthermore, when mapping root cause results to the scenario-risk-action matrix, the main station determines the scenario unit based on the area or building to which the root cause node belongs, the corresponding resident, apartment, hospital or data center user type, and time period. The root cause type, root cause confidence level output by edge nodes, number of affected terminals, and number of key users among the affected terminals are used as risk coordinate parameters to retrieve candidate linkage action chains that match the risk coordinate in the scenario-risk-action matrix.
[0012] Furthermore, when the main station selects a chain of linked actions from the scenario-risk-action matrix and generates control instructions, each chain of linked actions includes atomic actions that are executed sequentially. Atomic actions include current limiting or load reduction of non-critical load switches, step-by-step power disconnection of branch switches, sending alarm notifications to on-duty and maintenance personnel, and sending linkage commands to fire protection, building automation or video surveillance systems. Electrical quantities and alarm status are recorded before and after each atomic action to control the execution of the next atomic action.
[0013] Furthermore, when the main station summarizes alarm events, root cause results, and linkage execution, it calculates the total number of alarms, the number of false alarms or subordinate alarms, and the number of events where no alarm was triggered but the potential risks were manually confirmed within the statistical period for the profile unit. The alarm propagation fingerprint is statistically analyzed to determine the number of times it is selected as a candidate pattern and confirmed as a root cause pattern. The linkage action chain is statistically analyzed to determine the number of times it is selected, terminated prematurely during execution, and manually modified by maintenance personnel. Based on this, evaluation data for evaluation profile units, alarm propagation fingerprints, and linkage action chains are formed.
[0014] Furthermore, the adjustment information for thresholds, alarm propagation fingerprint weights, and scenario-risk-action matrix parameters includes the direction and magnitude of working threshold adjustments for profile units with a high number of false alarms or subordinate alarms. Adjustments to the usage weight and similarity threshold for alarm propagation fingerprints with low matching rates in root cause results, as well as adjustments to the trigger conditions and priority in the scenario-risk-action matrix for linkage action chains that are terminated early or manually changed multiple times within the statistical period.
[0015] Furthermore, the adjustment information is uniformly distributed from the main station to the terminal, edge node and main station in the form of configuration file or parameter table. After the terminal loads the new working threshold configuration, it updates the threshold in the corresponding portrait unit. After the edge node loads the new alarm propagation fingerprint weight configuration, it sorts the candidate alarm propagation fingerprints according to this when matching alarm distribution. After the main station loads the updated scenario-risk-action matrix parameters, it generates control instructions according to the new linkage action chain priority in the next cycle.
[0016] (III) Beneficial Effects This invention provides a method for security alarm and linkage of electricity information collection terminals, which has the following beneficial effects: When the operating parameters are close to the working threshold, a confirmation window is opened to extract local dynamic fingerprints. Security alarm events are generated only when the local dynamic fingerprint matches the dangerous mode fingerprint, so that terminal alarms are more constrained by specific operating scenarios and historical behavior, reducing the triggering of non-targeted alarms.
[0017] Alarm propagation fingerprints are used to match alarm coverage and time sequence, and physical residuals are formed by combining voltage, current, active and reactive power data uploaded by terminals. Root cause nodes that meet the topological relationship and electrical quantity constraints are selected from the candidate root cause nodes, so that the root cause determination is based on the dual constraints of network structure and physical measurement, avoiding reliance on alarm quantity or simple rules alone.
[0018] On the main station side, the business scenario unit is determined based on the physical area, user type and time information of the root cause node. The root cause fault mode, root cause confidence and the set of covered terminals are mapped to the scenario-risk-action matrix. Corresponding linkage action chains are selected and sent to edge nodes and power consumption information collection terminals for execution. During the execution process, the order of subsequent linkage actions is adjusted according to the changes in load and safety alarm events, so that the linkage control decision is closely coupled with the specific power distribution scenario and risk level.
[0019] Generate parameter adjustment suggestions for terminal-side working thresholds, edge node-side alarm propagation fingerprint weights, and the priority of linkage action chains in the scenario-risk-action matrix, so that threshold settings, propagation mode selection, and linkage strategy priority can be dynamically updated as the running data evolves.
[0020] Within the statistical period, the working threshold, alarm propagation fingerprint weight, and linkage action chain priority are adjusted synchronously to form a closed loop of alarm and linkage control that coordinates the work of terminals, edge nodes, and the main station. This enables alarm generation, root cause determination, and linkage control to form a coherent overall solution under the same technical logic. Attached Figure Description
[0021] Figure 1 This is a schematic diagram of the safety alarm and linkage method of the electricity information collection terminal of the present invention. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] Please see Figure 1 This invention provides a method for security alarm and linkage of an electricity information collection terminal, including: Step 1: The electricity information collection terminal locally generates a detailed description of the current operating conditions. Based on this, it generates structured safety alarm events, providing input with time behavior information and scene identifiers for subsequent regional root cause determination and linkage strategy selection.
[0024] The electricity information acquisition terminal first obtains the physical safety baselines for the terminal in terms of current, voltage, and conductor temperature rise based on the nameplate parameters of the access equipment and the power distribution design documents. The terminal treats these baseline parameters as inviolable hard boundaries, denoted as the current baseline. Voltage baseline and temperature rise baseline It also reads the operating mode and load profile information of the station area to which this terminal belongs, so that it can be directly referenced when dividing the profile units later.
[0025] During normal operation, the terminal continuously collects power parameters and operating status data, combining active power, reactive power, voltage, current, three-phase imbalance, harmonic content, and operating mode flags for each sampling period into a raw record. The terminal accumulates records from multiple days or even weeks in chronological order on its local storage medium and groups these records during idle periods: generating time tags based on the hour, weekday or non-weekday, and season of the sampling time; generating user and topology tags based on user category identifiers and circuit numbers; and generating mode tags based on operating mode flags. These tags are then concatenated to form a profile unit key. The terminal will have the same image unit key. The records are grouped into the same image unit for storage, and the typical value range and fluctuation range of parameters such as current, voltage, and temperature under the scenario are statistically analyzed in each image unit.
[0026] When used, the terminal can organize long-term sampling data into several profile units with clear labels of time, user, topology and operation mode without relying on external servers. The obtained historical group data provides stable data support for subsequent fine-tuning of working thresholds based on profile units, making threshold adjustments in different scenarios more targeted and avoiding the distortion caused by simply using global statistics.
[0027] Based on this, a portrait intensity parameter can be defined to describe the overall load level of a portrait unit. For example, it can be characterized by the normalized energy of the active power sequence at each sampling time, i.e.: ; Among them, the image intensity parameter : Represents the average load intensity within a specific image unit; number of sample entries. The number of sampling records within this image unit; active power samples. : for the first The active power value corresponding to each record; reference power This is a reference power value selected based on the capacity of the device accessed by the terminal. (Based on image intensity parameters) This allows for the use of a dimensionless index to reflect the load level during long-term operation in a given scenario without altering the physical baseline, thus providing a unified benchmark for subsequent threshold fine-tuning.
[0028] In use, the terminal can generate image unit divisions and image intensity parameters with clear physical meaning based on long-term sampling data. This approach preserves the differences in power consumption at different times and in different scenarios, while avoiding the direct use of scattered sample values for threshold adjustment, thus reducing the impact of occasional fluctuations on threshold settings.
[0029] Furthermore, the terminal targets each image unit key. Without exceeding the current baseline Voltage baseline and temperature rise baseline Under the premise of image intensity parameters Fine-tune the working thresholds of each parameter.
[0030] The terminal sets the operating threshold for the current parameter. Set the operating threshold for the voltage parameters. Its value varies within a small range near the physical baseline and can be determined in the following form: ; Among them, the current operating threshold The upper limit of current used for limit exceedance detection within a specific image unit; current baseline. Safety baseline determined based on equipment nameplate current and conductor cross-section; adjustment coefficient : A dimensionless weight with a value between 0 and 1, used to limit the range of influence of image intensity on the threshold; Image response function For image intensity parameters A monotone bounded function, taking values Piecewise linear or smooth saturation forms can be used to ensure the working threshold when the image intensity is high. Within the current baseline The threshold should be appropriately tightened within a certain range, while the working threshold should be adjusted when the image intensity is low. Slightly relaxed, but not exceeding the design capacity. A piecewise linear function can be used, that is, when When the load is in the low load range, medium load range and high load range, three different constant values are taken respectively, and a continuous curve is obtained by interpolation at the boundary of the range.
[0031] By working threshold The settings on the terminal allow for different image unit keys. Slightly different current thresholds, all constrained by a physical safety baseline, can be used, with different sensitivities applied in high-load nighttime and light-load daytime scenarios. Similarly, the terminal can also adjust the voltage operating threshold. and temperature rise operating threshold Using the same approach, all working thresholds are centered on the physical baseline parameters and adjusted to a limited extent by adjusting the coefficients and the image response function.
[0032] When in use, the terminal can set a working threshold that matches the scene based on the load intensity characteristics of different image units, while taking into account the device's security boundaries. This avoids oversensitivity or sluggishness caused by a single fixed threshold, and also prevents the device from exceeding its design limits due to threshold adjustments.
[0033] After obtaining the working threshold corresponding to each portrait unit, the electricity information collection terminal compares the collected parameters such as current, voltage, and temperature. Once a parameter approaches or slightly exceeds the working threshold, the terminal will detect the fault. , or It enters an early warning state, but does not immediately form a final alarm. Instead, it activates a short-term confirmation window to sample and analyze the parameter and related parameters at a higher frequency to determine whether the current anomaly is an instantaneous fluctuation or a dangerous condition with an evolving trend.
[0034] Furthermore, after the terminal detects that a certain measurement value has entered the warning range, it records the trigger time and sets a confirmation window. During this time period, the sampling frequency is increased to continuously record parameters such as current, voltage, and temperature. For example, if it was originally sampled once per minute, it is set to sample once per second in the confirmation window.
[0035] The confirmation values within the confirmation window of each sample are set into a local time series in chronological order. Locally, certain dynamic features describing the changing trend are obtained according to certain rules, such as the number of consecutive upward steps, peak time, and the sign of the increment between adjacent sampling points. These dynamic features are then encoded into a local dynamic fingerprint vector. .
[0036] At this point, in order to further compare with dangerous patterns, the terminal is required to maintain some reference fingerprint vectors that represent typical dangerous evolution processes. These reference fingerprints can be derived from historical events or obtained by engineers based on experience. After the confirmation window closes, the current local dynamic fingerprint vector is... The feature-level comparison is performed with the reference fingerprint vector under the corresponding image unit to calculate the difference in the trend of change.
[0037] By automatically extracting a high-time-resolution measurement data segment before and after exceeding limits, the terminal observes the form of parameter changes, rather than simply looking at the values at each moment. This is achieved through local dynamic fingerprint vectors. This allows the terminal to observe different types of changes, such as continuous rises, periodic shocks, or instantaneous spikes, which facilitates the classification of alarm types and severity in the later stages and prevents short-term conditions from being misjudged as long-term dangers.
[0038] The terminal targets the extracted local dynamic fingerprint vector With multiple reference fingerprint vectors within the image unit By comparing each feature individually, a set of similarity indices is obtained. Similarity can be calculated using a weighted cosine similarity method to simultaneously consider the contribution of different features to the meaning of the alarm. For example, an alarm similarity metric can be defined. for: ; Among them, alarm similarity For the current local dynamic fingerprint vector With a certain reference fingerprint vector Weighted similarity between them; number of feature dimensions The number of components in the fingerprint vector; feature weights For the first The weights of local dynamic features in alarm judgment are non-negative real numbers; local feature components Local dynamic fingerprint vector The Each component; reference feature component For reference fingerprint vector The Each component.
[0039] By setting a similarity threshold, when the alarm similarity... The measured value exceeds the predetermined threshold and the measurement value within the confirmation window continues to approach or exceed the corresponding working threshold. , or When this happens, the terminal will recognize the current status as a security alarm event that needs to be sent.
[0040] When generating a security alarm event, the terminal not only provides the alarm type and severity, but also includes the corresponding profile unit key in the event description. Image intensity parameters Triggered working threshold identifier and local dynamic fingerprint vector The summary identifier allows the higher-level system to immediately understand the corresponding time scenario, load level, and trend when it receives the alarm. In the aforementioned student dormitory embodiment, during the evening self-study period, the current in a certain circuit remained close to [a certain value] for an extended period. When a continuously increasing number of localized dynamic fingerprints appear, the terminal will generate a key containing a high-load image of the apartment at night. Similarity to high alert Security alerts are reported to edge nodes.
[0041] During use, the terminal simultaneously judges the degree of numerical violation and the trend of change, and uses fingerprint similarity to determine these factors. With working threshold , , The combined conditions generate structured alarm events. The generated alarm events reflect whether the current parameters exceed the limits, and include information on changes in operating conditions and profile unit identifiers, thus avoiding false alarms caused by single instantaneous limit exceedances.
[0042] Step 2: By mapping alarm events to electrical and communication topologies, the structured alarm data generated in Step 1 is transformed into root cause results that can be used to trace the source and identify key nodes, so that subsequent scenario-based linkages are established on a clear spatial scope and propagation mechanism.
[0043] In step one, the safety alarm events generated independently by each power consumption information collection terminal have obvious correlations in time and space. However, if they are simply sorted by time or listed by terminal number on the edge node side, it is impossible to reflect the power supply relationship and communication dependency between the alarm events, and it is difficult to identify the alarm wavefront on the entire feeder or a certain communication branch.
[0044] Therefore, a unified electrical and communication topology coordinate system should first be established in the edge nodes to convert each security alarm event into a record with dual location and time identifiers, so that subsequent propagation pattern analysis can be based on evidence.
[0045] During the initialization phase, edge nodes read the electrical connections and communication links within the current transformer area or building from the power distribution design data and communication access configuration. They map the relevant transformers, switches, distribution boxes, branch circuits, and end-point electricity information collection terminals to the node set in the electrical topology, and map concentrators, aggregation devices, communication link segments, and terminal communication interfaces to the node set in the communication topology. Each edge node then assigns an electrical node index to each node in the electrical topology. Assign a communication node index to each node in the communication topology. It also records the connection relationship between the electrical edge and the communication edge.
[0046] When an edge node receives a security alarm event from a terminal, it extracts the terminal identifier and alarm timestamp from the event. The key to the corresponding image unit Alarm similarity and Local Dynamic Fingerprint Vector Summarization Find the electrical node index of the terminal in the electrical topology based on the terminal identifier. and the index of communication nodes in the communication topology The alarm event was internally logged as a triplet. and the image unit key This forms a one-to-one association with the triple. Edge nodes will associate all alarm events reported by terminals within the same statistical period with their timestamps. Sort by electrical node index and communication node index The location and sequence of alarm occurrences are marked on the dual topology to obtain a spatiotemporal alarm distribution map.
[0047] When using this method, each security alarm event is attached to a specific physical location and communication link, facilitating subsequent merging based on topology hierarchy; this is achieved by introducing timestamps. The sorting of alarms at edge nodes allows observation of their order, providing a foundation for subsequent extraction of propagation patterns; furthermore, the image unit key... This information is retained in each record at this stage, providing a basis for subsequent determinations of whether a certain type of root cause occurs frequently in a specific operational scenario.
[0048] After completing the dual-topology mapping of alarm events, edge nodes need to initially determine from the complex spatiotemporal alarm distribution which alarms belong to the same fault mode and which may be locally irrelevant events, thus focusing the analysis on a small number of possible root cause modes. The technical motivation is that if all alarm triples are directly processed... Performing traversal and combination, attempting to enumerate all possible root cause nodes, results in a rapid increase in analysis workload as the number of terminals and time duration increase, making it difficult to complete the determination of edge nodes within the specified time. Therefore, it is necessary to utilize a pre-built alarm propagation fingerprint database to compare the currently observed spatiotemporal alarm distribution with typical fault modes, quickly screening out a few candidate fault modes.
[0049] The alarm propagation fingerprint database consists of several propagation fingerprint vectors. Composition, each propagation fingerprint vector corresponds to a typical fault mode, indexed as follows: Each propagation fingerprint vector It contains two parts of information: one part is the electrical path pattern related to the electrical topology, which describes the index of downstream electrical nodes when an electrical node fails. The sequence in which alarms may occur; another part is the communication path pattern related to the communication topology, describing the index of downstream communication nodes when a communication node fails. The order in which communication alarms or offline events may occur can be determined. When configuring or updating edge nodes, typical propagation trajectories extracted from historical fault events can be organized into several... And label them according to the fault type (upper-level switch tripping, branch overload, concentrator failure, fiber optic link interruption, etc.). Each It can be automatically extracted from historical fault alarm sequences under offline conditions. For example, for multiple upper-level switch tripping events, the alarm nodes are sorted by time and their frequency of occurrence is counted to form an ordered vector of node number + sequence number, and the ordered vector is stored in the fingerprint database.
[0050] Within a certain statistical period, when edge nodes detect spatiotemporal alarm distributions exhibiting multi-node concentration and temporal wavefront characteristics, the first step is to analyze the voltage, current, temperature, communication status, and terminal operating scenario involved in the alarms (as determined by the profiling unit key). (Provide) Initial classification to determine which fault type it is closer to, and then select a small set of propagation fingerprint vectors that match the fault type from the alarm propagation fingerprint database. This forms a candidate fingerprint set.
[0051] Subsequently, the edge nodes will combine the current spatiotemporal alarm distribution across the electrical and communication topologies with the candidate propagation fingerprint vectors. The node sequences described in the diagram are aligned to exclude fingerprints that are obviously inconsistent at key nodes, and a small number of fingerprint vectors that are relatively consistent with actual observations in terms of coverage and general propagation direction are retained, thus narrowing the search range for the next step of similarity calculation and root cause candidate node selection.
[0052] By propagating fingerprint vectors Pre-screening compresses the root cause search space, which might otherwise require exhaustive searching across the entire topology, into a small set that matches the current fault type, improving the analysis efficiency of edge nodes; simultaneously, it utilizes the profiling unit key... Combining alarm types can take into account the differences in the propagation of the same type of fault in different operating scenarios, and avoid misclassifying alarms in completely different backgrounds as the same mode. The edge nodes selected several candidate propagation fingerprint vectors based on the propagation fingerprint database. However, these fingerprint vectors still only represent idealized propagation patterns. To specifically implement them as a candidate root cause node, it is necessary to combine them with the current spatiotemporal alarm distribution for quantitative matching and give a propagation similarity score for each candidate pattern.
[0053] However, relying solely on visual impressions can lead to subjective biases due to different topological systems and complex alarm combinations. By determining a similarity function, the differences in coverage, propagation direction, and temporal order of different candidate patterns can be quantified, providing numerical references for subsequent root cause screening.
[0054] For each candidate propagation fingerprint vector The edge node first derives the location of its assumed root cause node in the electrical topology and the set of downstream electrical node indices it affects, as well as its path in the communication topology, based on the described propagation path; then it indexes the electrical nodes appearing in the actual spatiotemporal alarm distribution. Compare this set to count the number and order of overlapping nodes; then compare it with alarms or disconnection events in the communication topology to see the actual alarm sequence and... Does the described communication path match?
[0055] For each candidate propagation fingerprint vector Establish dissemination similarity This comprehensively reflects the degree of matching between the fingerprint and the actual spatiotemporal distribution of alarms, and the propagation similarity. Alternatively, a combination of consistent coverage ratio and direction can be used: ; Among them, the similarity of propagation Indicates the first Propagation fingerprint vector The degree of comprehensive matching with the current spatiotemporal alarm distribution; coverage weight coefficient. and order weight coefficient Let be a non-negative real number, and let the sum of the two be denoted as . This is used to adjust the importance of coverage and sequence consistency in the scoring; quantity of electrical coverage In the electrical topology, this represents the current set of alarm nodes and the propagation fingerprint vector. The number of nodes in the intersection of the expected sets of affected nodes; the total number of expected affected nodes. To propagate fingerprint vector The number of nodes in the expected set of affected nodes; Sequential consistency score To reflect the actual alarm time sequence and propagation fingerprint vector An indicator of the degree of similarity between expected and actual time sequences can have its value range limited to [specific range]. The closer the value is to 1, the more consistent the order. This indicates that the direction of transmission is opposite to what was expected. This can be achieved by calculating the normalized longest common subsequence length or the Kendall rank correlation coefficient of the two node sequences. This application is not limited to a specific algorithm, as long as the output is within... Furthermore, the closer the order of the monotonic reflections, the higher the score.
[0056] By calculating the similarity of propagation Edge nodes can sort different candidate propagation fingerprint vectors and determine the propagation similarity. Several high-sounding patterns were selected as key candidate root cause patterns for further investigation, and these were further combined with the alarm similarity reported by each terminal in step one. and image unit key We analyzed the adaptability of these modes in different operating scenarios.
[0057] For example, in the above student apartment embodiment, if the coverage and order consistency scores of the propagation fingerprint vector describing the sequential alarms of downstream nodes caused by poor branch contact are relatively high, the propagation similarity is high. It will be significantly higher than other patterns, becoming the preferred root cause pattern.
[0058] At the same time, utilize the similarity of propagation Combining electrical coverage and temporal consistency into a single score In this context, edge nodes can select candidate root cause patterns using relatively accurate numerical standards; the range of values for the order consistency score can influence the propagation similarity. The comparability between the various patterns lays the foundation for the identification of root causes later.
[0059] After obtaining the propagation fingerprint vectors of each candidate similarity of propagation Afterwards, further screening at the specific electrical node level is still needed to determine which node(s) is more consistent with actual observations as the root cause.
[0060] Among them, the propagation fingerprint vector This describes the macroscopic propagation characteristics of a certain type of fault mode. However, the impact of the same type of fault on downstream physical quantities such as current and voltage still varies when they occur at different electrical nodes. Without combining actual measurements with physical residual analysis, relying solely on topology coverage can easily lead to situations where the mode is correct but the location is off.
[0061] Edge nodes for propagation similarity Several high-ranking candidate patterns are selected one by one from their expected root cause node sets. For each candidate node index Based on the current upstream switch status and load distribution, a simplified power flow model is used to calculate the predicted voltage and current values of downstream critical nodes when the fault assumption is valid. These are denoted as the predicted voltage and current, respectively. and predicted current Subsequently, these predicted values are compared with the voltage measurements taken at the terminal and uploaded to the edge node in steps one and two. and current measurement value Compare and construct an index of candidate root cause nodes. Physical residual index Physical residual index A weighted sum of the component differences can be used: ; Among them, physical residuals Indicates the hypothetical node index In the case of the root cause, the degree of deviation between the physical quantity predicted by the model and the actual measured physical quantity at the terminal; downstream node set : Index of candidate root cause nodes in the electrical topology The set of downstream electrical node indices that participate in residual calculation; voltage weighting coefficients. and current weighting coefficient It is a non-negative real number, reflecting the relative importance of voltage deviation and current deviation in residual evaluation; Predicted voltage : Assuming node index When a specific failure mode occurs, the node index is obtained by simplifying the power flow calculation. Predicted voltage; predicted current Node index under this fault assumption The predicted value of the current at the location; within a typical tree-like network of low-voltage power distribution, It can be estimated by accumulating the active / reactive power along the path from the root node to the downstream node using the product of the line impedance. It can be approximated by the sum of the load currents of each branch.
[0062] Voltage measurement value : Index of the corresponding node The measured voltage value and current value uploaded by the terminal. : Index of the corresponding node The measured current value uploaded by the terminal. In a typical low-voltage tree-structured distribution network, the predicted voltage can be calculated using the following approximation method: Assume the rated voltage is... In the hypothetical node After a fault occurs, the electrical topology is followed from the power source to the downstream node. The path branch set is denoted as ; Each branch road There is resistance and reactance ,node The total active power downstream is Total reactive power is (From terminal measurements or estimates); a linear approximation can be used: ; Voltage prediction value Candidate root cause nodes Under the condition, node Estimated voltage value; other symbols have the same meaning as above.
[0063] Edge nodes sequentially calculate the index of each candidate root cause node. physical residuals and physical residuals Similarity to propagation Taking all factors into consideration, such as prioritizing propagation similarity... High and physical residual Node indexes less than a preset threshold As the final root cause node. When multiple candidate nodes exist. When the above conditions are met, the image unit key can be combined. Based on the distribution of data, priority is given to nodes where downstream terminals show alarms concentrated in the same or similar image units to improve the consistency of root cause localization. Finally, the edge nodes will identify the root cause node, its corresponding fault mode, and its propagation similarity. Physical residuals The distribution of the covered terminal set and its portrait units is organized into a structured root cause result, and threshold adjustment suggestions for these portrait units or branches are sent to the main station.
[0064] Utilizing physical residuals Selecting candidate root cause nodes allows for root cause localization, applicable to alarm propagation patterns and measurements of voltage and current changes. This significantly reduces misjudgments of nodes that are close to the propagation trajectory but have shifted. (The last part, "image unit key," appears to be unrelated and likely refers to another function or feature.) Introducing the distribution of the root cause into the root cause selection process can make the final root cause node more closely associated with a specific operating scenario, making it easier for the master station to design scenario-based linkage strategies in step three.
[0065] Step 3: On the main station or cloud platform side, match the structured root cause results output by the edge nodes with the pre-set scenario-risk-action matrix, so that each root cause judgment can obtain the risk level and linkage strategy matching under a clear business scenario, establish a linkage action chain of security, power supply continuity and economic cost, and implement the linkage action chain in the control operation of power consumption information collection terminal, power distribution switch and external system.
[0066] The main station first receives the structured root cause results output by the edge nodes in step two. These structured root cause results include root cause node identifiers, failure mode identifiers, overall confidence scores, and propagation similarity scores. Consistency indicators Physical residuals The set of covered terminals and the corresponding profile unit keys of the covered terminals Image intensity parameters Distribution of [something].
[0067] The main station needs to determine the business scenario in which the current failure occurs based on this information, such as the nighttime electricity use of student dormitories, the power distribution of hospital intensive care units, the power supply of data center cabinets, or the public lighting of ordinary commercial buildings, so as to select the scenario index in the scenario-risk-action matrix.
[0068] During the configuration phase, the main station categorizes typical business locations across the entire network or in a specific region into several scenario categories, and assigns a scenario index to each category. And assign a fault category identifier to each type of root cause failure mode. For example, transformer low-voltage side faults, branch overloads, and concentrator communication anomalies are used as... The value of .
[0069] During operation, the master station determines the root cause node's distribution area, the user category bound to the power consumption information collection terminal in that distribution area, the time period (weekday / holiday, daytime / night), and the profile unit key. Based on the statistical distribution, a comprehensive judgment is made as to which the current root cause event should be attributed in the scenario index. It calls the preset scenario baseline risk coefficient function to map the scenario category and fault category to a scenario baseline risk coefficient.
[0070] In terms of processing methods, the main site can define a scenario risk score. This is used to comprehensively reflect the contribution of business scenarios, root cause uncertainties, and the scope of impact to the risk level, for example: ; Among them, scenario risk scoring The vertical coordinate of the current root cause event in the scenario-risk-action matrix represents the overall risk level of the event in the corresponding scenario. Scenario benchmark risk coefficient Regarding the scene index and fault category identifier A function, a positive real number, is used to represent the basic risk level under this scenario and this type of fault combination; for It can be configured by power companies based on the importance of power supply in various scenarios, regulatory requirements and historical accident experience, by looking up a table, without limiting specific values; Root cause uncertainty To comprehensively analyze the similarity of dissemination Consistency indicators and physical residuals The constructed dimensionless index takes values of This is used to indicate the reliability of the root cause determination, and can be described as acceptable. The value within the interval decreases as the similarity of propagation increases and increases as the physical residual increases. For example, linear normalization combination or piecewise functions can be used. Number of affected terminals : The cardinality of the set of covered terminals in the root cause results; Total number of terminals in the region : The total number of electricity consumption information collection terminals registered in this scenario or in this area, used to normalize the affected area.
[0071] Scenario risk scoring Through calculations, the main station can simplify complex root cause determination results into a risk coordinate that can be used for table lookup, while retaining the scene category. and fault category These two indexes are used for subsequent access to the scenario-risk-action matrix.
[0072] The main site uses scene indexing and scenario risk scoring The multidimensional root cause information output by edge nodes is compressed into structured matrix coordinates, enabling events from different scenarios, fault categories, and impact ranges to be compared using a unified risk scale; simultaneously, root cause uncertainty... The introduction of this feature allows the master station to consider the uncertainty of edge judgments when making coordinated decisions. For root cause events with greater uncertainty, a relatively mild action chain can be selected to reduce the risk of mishandling.
[0073] The main site is indexed by scene. and scenario risk scoring As the entry point, a set of candidate linked action chains is selected from a pre-constructed scenario-risk-action matrix. This matrix can be understood as a three-dimensional structure: the first dimension is based on the scenario index. The second dimension categorizes business locations according to their risk levels. The risk is divided into several risk zones, and the third dimension is the set of available linkage action chains under this scenario-risk combination. Each linkage action chain consists of several sequentially executed control actions and auxiliary actions, such as sending alarm notifications to on-duty personnel and maintenance personnel, reducing load on non-critical loads, step-by-step power outages on specific branches, activating backup power supplies, and linking fire protection systems or building automation systems.
[0074] The main site compares scenario risk scores. By mapping the current event to a specific risk range based on the preset risk segments, a scenario-risk binary index is obtained. ,in This indicates the risk interval number. The master station retrieves the corresponding action chain set from the matrix and records for each action chain attributes such as the expected reduction in security risk, the degree of impact on power supply continuity, and the economic and management costs required.
[0075] To prioritize multiple action chains, the main site can construct a linkage action chain priority for each action chain. For example, in the following form: ; Among them, the priority of linkage action chain : for the first The priority score for each linked action chain is positive or negative; a higher value indicates that it is more worthy of priority selection under the current scenario-risk combination; safety weight coefficient. : The weight of the reduction in security risk, a non-negative real number; Continuity weighting coefficient : Weight of the impact on power supply continuity, a non-negative real number; cost weight coefficient : a non-negative real number representing the weight of economic and management costs; the magnitude of the reduction in security risks. : for the first The amount of risk that can be reduced by the chain of actions in this scenario-risk combination can be given by historical processing results or expert evaluation, and is a non-negative real number. Degree of impact on power supply continuity : for the first The degree of impact of a chain of actions on power supply continuity, such as the proportion of load cut-off or the duration of the impact, is a non-negative real number; economic cost. : Execute the The cost of manpower, equipment, and other resources required for each linked action chain is a non-negative real number.
[0076] The main site prioritizes actions based on the chain of actions. The candidate action chains are sorted, and one or more higher-priority action chains are selected as the linkage scheme for the current event. Linkage action chain priority. With utility value They are essentially the same type of quantity; the former does not explicitly specify the scenario and root cause subscripts, while the latter is written as […] in statistical analysis. In order to distinguish different scenarios and root cause combinations; in actual implementation, a unified approach can be adopted. As the utility value of the action.
[0077] In one implementation, the fingerprint vector is propagated. Represented as an ordered sequence of nodes ; Among them: node identifier : Electrical node index or communication node index; sequence length : The expected number of nodes affected under this mode; sequence number : Indicates the expected order in which alarms will occur.
[0078] This sequence can be formed by statistically analyzing multiple alarm records under the same fault mode, sorting the alarm nodes by their first occurrence time, and then taking the mode.
[0079] In an example of a student dormitory scenario, when the scenario risk score... At a medium-to-high level, the matrix may contain two candidate action chains: one is to first limit the current of non-critical loads, then notify the building administrator, and, depending on the situation, implement layered power outages at the floor distribution boxes; the other is to immediately disconnect some branch circuits in the entire dormitory building and simultaneously notify operations and maintenance. The priority of the linked action chains of these two action chains is calculated. The main site found that the previous solution reduced security risks significantly. Significant impact and on continuity The overall score is higher when the size is smaller, so this option is preferred.
[0080] When using it, prioritize the main site's usage scenarios, risks, action matrix, and linked action chains. The linkage strategy is no longer bound by uniform rules and can be set according to scenario type, risk level, safety requirements, power supply continuity, economy and other factors. At the same time, since the matrix structure and weight parameters can be modified during operation, the feasibility of the linkage strategy can be gradually improved while ensuring safety conditions.
[0081] The abstract action descriptions are transformed into a sequence of specific control commands that can be issued to edge nodes and power consumption information acquisition terminals. Each individual action in a linkage action chain is typically described in the matrix only in terms of its control target type and execution sequence, such as reducing the power limit of non-critical loads in the transformer area, partially cutting off power to a branch downstream of the root cause node, or sending a linkage start signal to the fire protection system, but lacks information on specific nodes and terminals.
[0082] The main station must combine the root cause node identifier, the set of covered terminals, and the profile unit key to which these terminals belong, as output in step two. and image intensity parameters This allows each abstract action to be precisely located to a specific execution object.
[0083] For the selected linkage action chain, the main station analyzes the action units one by one from beginning to end, and identifies the target object category (such as root cause node, a certain type of circuit downstream of the root cause node, the terminal set corresponding to the affected profile unit) and control method (such as issuing power limit command, issuing circuit breaker opening and closing command, issuing notification or linkage instruction) for each action unit.
[0084] The master station bases its data on the root cause nodes in the electrical topology diagram. The location in the middle selects a set of nodes from its downstream nodes that conform to the current action logic. For example, the current limiting of non-critical loads is transformed into a profile unit downstream of the root cause node and whose load category does not belong to critical loads. Reduce the working threshold on the corresponding terminal set. Alternatively, by limiting the maximum power setting, the step-by-step power cut-off of branches with obvious potential hazards can be transformed into sending segmented power cut-off commands sequentially to the corresponding branch switches at the edge node.
[0085] When used, it ensures that each control operation has a clear execution target and execution order, avoiding the problem of having a strategy but the action not being implemented at the correct node; utilizing the portrait unit key and image intensity parameters With this information, the master station can distinguish loads of different importance and operating status downstream of the same root node, and adopt different control boundaries for different types of terminals, so that the linkage strategy has fine-grained adjustability.
[0086] After the master station sends the control command sequence to the edge nodes and the power consumption information collection terminal, it does not simply wait for all the preset actions to be completed. Instead, it continuously collects information such as voltage, current, active power, temperature and new safety alarm events from the terminal, compares the expected changes brought about by the linkage action chain, and assesses whether the risk status has been mitigated after each stage of action is executed. Then it decides whether to continue to execute subsequent actions or terminate early and replace the remaining part of the action chain.
[0087] For the selected linkage action chain, the main station presets an observation window and expected response for each key action during strategy configuration. For example, within a certain time window after current limiting of non-critical loads, it is expected that the current measurement value downstream of the root cause node will decrease to a certain extent, and the number of safety alarm events will no longer increase or will decrease. Within the observation window after power is cut off to a branch, it is expected that the temperature rise alarm at the end of the corresponding branch will decrease and no new anomalies will appear in other branches.
[0088] During execution, the master station compares the measurements from edge nodes and terminals with the expected responses one by one. If, within the agreed observation window, the number of key physical quantities and alarms has reached the preset improvement conditions, the current linkage action can be considered to have achieved sufficient effect. The master station can choose not to execute stronger measures in the linkage action chain, thereby reducing unnecessary load shedding. Conversely, if the risk status has not improved within the observation window, or even if a new alarm propagation trend appears, the master station can replace subsequent actions with stronger control measures according to the upgrade path pre-set for the scenario in the scenario-risk-action matrix. For example, the subsequent steps of only limiting the current of non-critical loads can be adjusted to powering off some branches on the basis of current limiting.
[0089] In an example of a high-rise commercial complex, when the root cause occurs on a busbar segment in the low-voltage distribution room, the master station first limits the current of the air conditioning load on multiple floors according to the action chain, and observes the current measurement value and the number of temperature rise alarms on that busbar segment within a specified time. If the busbar segment current decreases and the number of temperature rise alarms decreases at the end of the observation window, the master station can decide not to execute subsequent more drastic power-off actions, preserving some comfort loads within the building; if the current and temperature rise do not change significantly, the master station triggers the power outage of the corresponding floor's lighting circuits and some socket circuits according to the action chain corresponding to the higher risk level in the matrix, to prevent the fault from worsening.
[0090] When in use, the main station introduces phased judgments based on measurement feedback during the execution of the linkage action chain, enabling the linkage strategy to be dynamically adjusted according to the on-site response, thereby avoiding taking measures that have too great an impact on users at the beginning, and also avoiding missing the opportunity to deal with the situation due to overly mild measures.
[0091] Step 4: Transform the large amount of process records accumulated during the linkage execution into quantitative basis that can be used for rule updates, and make organized adjustments to the key parameters of the terminal layer, edge layer and main station layer, so that the same scenario can work with more appropriate thresholds, more robust alarm propagation fingerprints and action chains that are more in line with risk preferences in subsequent cycles.
[0092] Among them, the security alarm events output in step one, the root cause results output in step two, and the linkage action chain executed in step three have a close correspondence in terms of time and objects. However, if they are stored in isolation in the main site database in the form of alarm list, root cause list and action execution log, it is impossible to perform statistical analysis along the link of a certain alarm generation - being merged into a certain root cause - triggering a certain action chain - producing a certain consequence.
[0093] Therefore, the first step is to establish a unified event primary key for each root cause event, and then associate this event primary key with alarm records, root cause results, and linkage execution process records.
[0094] When the master station receives structured root cause results from edge nodes, it assigns an event number to each root cause result and links this event number with the root cause node identifier, fault mode identifier, and propagation similarity. Physical residual measurement The key to covering the set of terminals and the profile units to which these terminals belong. Establish a connection.
[0095] When the main station selects an action chain number from the scenario-risk-action matrix and generates a specific control instruction sequence based on the root cause result, it writes the same event number into the linked action chain execution record.
[0096] Within the statistical period, if an alarm is merged into a root cause event by an edge node, the main station will also add the event number to the alarm record.
[0097] The main station internally creates an event primary key table, where each row uses the event number as the primary key and lists the root cause node identifier, failure mode identifier, scenario number, and comprehensive risk index. The selected linkage action chain number, the sequence of action chain execution steps, and the handling conclusion at the end of the event (e.g., troubleshooting, false alarm confirmation, subordinate alarm).
[0098] Meanwhile, the event number is associated with multiple security alarm event records, one root cause result record, and multiple action execution records via foreign keys. In an example of a student dormitory, a branch circuit connector overheating event on a certain floor one night triggers multiple terminal security alarms. The edge node converges these alarms into a root cause event of a branch circuit connector failure. The master station assigns an event number and records the selected power limiting plus step-by-step power-off action chain and its execution time. At the end of the cycle, the maintenance personnel mark the event as a fault resolved in the system. All alarm records, root cause results, and action chain execution records are linked together using the same event number.
[0099] When in use, the event number, as a unified primary key, transforms the log records that were originally scattered across various modules into an event view that can be traced along a causal chain. This allows the main station to accurately count the performance of a certain type of profile unit, a certain type of alarm propagation fingerprint, and a certain linkage action chain in the corresponding event at the end of the statistical period. At the same time, the event primary key table also stores root cause determination information, scenario-risk-action matrix selection results, and final handling conclusions, providing a basic structure for the subsequent construction of alarm quality indicators and action chain effect indicators, facilitating cross-level analysis.
[0100] Step 1, same image unit key The same working threshold setting and local dynamic fingerprint matching strategy were adopted in step two, and the same alarm propagation fingerprint vector was used in step two. These profile units and propagation fingerprints are called multiple times in different events. Only by comprehensively examining the performance of these profile units and propagation fingerprints in the events at the end of the statistical period can we identify profile units that are too sensitive to alarms and propagation fingerprints that have insufficient reliability in pattern matching, so as to make targeted adjustments to the threshold and fingerprint weights in the next period.
[0101] At the end of the statistical period, the main station iterates through the event primary key table, matches the alarm records under each event number with the final handling conclusion, and identifies the corresponding profile unit key in the alarm record. and propagation fingerprint index Extract them and construct a set of alarm performance characteristics for the portrait unit and a set of propagation fingerprint matching performance characteristics respectively.
[0102] In the alarm performance set of the portrait unit, each record must include at least the portrait unit key. The event number and the classification of the alarms belonging to that profile unit in the event under the final handling conclusion (e.g., primary cause alarm, subordinate alarm, false alarm); in the propagation fingerprint matching performance set, each record includes at least a propagation fingerprint index. The event number, whether the final root cause node of the event is consistent with the propagation fingerprint prediction, and whether the root cause determination is recognized by the operations and maintenance personnel.
[0103] For each portrait unit key The main station counts the total number of alarms that appear in the event log for this profile unit within the statistical period. The number of alarms that will be marked as false alarms or identified as subordinate alarms by edge nodes is counted to construct the false alarm ratio index for the profile unit. One way to express this indicator is as follows: ; Among them, the false alarm rate of the portrait unit Within a certain statistical period, there are groups with the same profile unit key. In the alarm logs, the percentage of alarms ultimately classified as false alarms or subordinate alarms out of the total number of alarms under that profile unit; the number of false alarms in the profile unit. : Key for this image unit Of all the corresponding alarm records, the number of times that were confirmed as false alarms or subordinate alarms by manual verification or rules; the total number of alarms in the profile unit. : Key for this image unit The total number of times an alarm appears in the alarm log within the statistical period.
[0104] Similarly, for each propagation fingerprint index The main site counts the total number of events in which a pattern participates in root cause determination as a candidate pattern within the statistical period. It then counts the number of events that are confirmed as insufficient pattern matching and not recommended for continued use after the corresponding root cause determination is completed, and constructs a propagation fingerprint matching mismatch ratio index. The format can be: ; Among them, the proportion of fingerprint matching mismatches during transmission. Indicates the propagation of fingerprint index The proportion of events that failed to match or had poor results in root cause determination within the statistical period; the number of propagation fingerprint mismatch events. : Propagation of fingerprint index The number of events in which the propagation fingerprint was involved that, after correction based on root cause analysis or manual verification, were determined to be inconsistent with the propagation pattern; the total number of events in which the propagation fingerprint participated. : Propagation of fingerprint index The total number of events involved in root cause determination.
[0105] When in use, the false alarm ratio of the image unit is addressed. Fingerprint mismatch ratio The main station can quantify the performance of different profile units and different propagation fingerprints from the perspective of statistical period, identify profile units with too many alarms but insufficient effectiveness and propagation fingerprints with low reliability of pattern prediction, ensure consistent statistical standards and avoid deviations caused by cross-module statistics.
[0106] When the false alarm rate of a certain image unit A persistently high threshold indicates that the working threshold setting or local dynamic fingerprint matching conditions for that image unit are too stringent in that scenario; when a certain propagation fingerprint matching mismatch ratio... When the value is too high, it indicates that the propagation fingerprint is difficult to accurately reflect the actual fault propagation trajectory under the current power distribution structure or user behavior pattern.
[0107] If the parameters of these image units and the propagation fingerprint are not adjusted, excessive alarms or incorrect root cause pattern selection will continue to occur in subsequent cycles, increasing the burden on the entire linkage process.
[0108] The main station obtains the false alarm rate of the portrait unit. Fingerprint mismatch ratio Then, a threshold correction amount and a propagation fingerprint weight correction amount are constructed by combining a preset reference level. For a profiling unit, a target false alarm level can be preset. When a certain image unit When the target level is exceeded, the main station calculates the threshold adjustment for that profile unit and sends it to the application's electrical information collection terminal; for fingerprint propagation, when a certain index of When the preset threshold is exceeded, the main station generates a weight correction suggestion for the propagation fingerprint, which can be used by edge nodes to reduce the priority of the pattern or require a higher degree of matching in subsequent root cause determination.
[0109] The main site can provide keys for each image unit. Calculate a threshold correction amount This is used to adjust the scaling of the working threshold or the width of the warning interval for that image unit in step one, for example: ; Among them, threshold correction amount Image Unit Key The threshold adjustment amount to be applied in the next statistical period; a positive value indicates that the warning range should be appropriately widened, and a negative value indicates that it should be appropriately tightened; false alarm correction weight. Adjust the false alarm ratio of the portrait unit The coefficient affecting the threshold correction is a positive real number; the false alarm rate of the image unit. : The percentage of false alarms and subordinate alarms under the aforementioned profile unit; reference false alarm level : This represents the acceptable false positive rate for the target within the scenario of this profile unit, and its value ranges from... Interval.
[0110] The electricity information collection terminal receives a key for a specific profile unit. Threshold correction amount Then, the working threshold described in step one can be applied. , , This correction is introduced into the calculation, for example, by multiplying the original scaling factor by . Alternatively, the upper and lower limits of the warning range may be adjusted proportionally. For propagation fingerprints, the main station will match the corresponding propagation fingerprint with a mismatch ratio. Converted into weighted adjustment values, these are used by edge nodes in the root cause scoring function to propagate the fingerprint index. The score contribution is reduced so that, among multiple candidate propagation patterns, the propagation fingerprint needs to perform better in terms of coverage and order consistency to be selected as the root cause pattern.
[0111] Through threshold correction amount Fingerprint mismatch ratio By establishing feedback channels at the terminal and edge node levels, threshold settings and propagation mode priorities can be adjusted based on actual performance within the statistical period, reducing long-term deviations and helping to maintain the consistency of the overall system design.
[0112] Step 3 involves assigning a scenario number and a comprehensive risk indicator to each scenario. Preference indicators were selected A high degree of linkage in the action chain, and the effect deviation index during execution. While the response to load changes was tracked, if this information is only used for the current action adjustment and not reflected in the parameters of the scenario-risk-action matrix at the end of the statistical period, it cannot demonstrate the merits of different action chains in long-term operation. In some scenarios, a certain action chain may be frequently selected but ineffective, or effective but at too high a cost to power supply continuity, requiring correction through parameter revision.
[0113] At the end of the statistical period, the main station filters out all events that have executed a chain of linked actions from the event primary key table, and assigns the scene number and comprehensive risk index to each event. Action chain number Preference indicators And record the overall risk changes before and after execution. Overall risk changes can be recorded from the time the event began. The difference between the residual risk assessment value and the residual risk assessment value confirmed by operations and maintenance personnel after the execution of the linked action is estimated. The residual risk assessment value can be obtained by reassessing the load level, alarm status, and critical load operation status. The main station summarizes multiple execution records of the same scenario number and the same action chain number to form the average risk reduction performance and average cost performance of the action chain in the scenario.
[0114] The main site can construct motion chain deviation indicators for each scene number and motion chain number. This is used to reflect the average risk reduction effect and preset risk reduction capability of the action chain within the statistical period. The differences between them can take the form of: ; Among them, the action chain deviation index : Indicates the action chain number within a certain statistical period. The difference between the average actual risk reduction and the preset risk reduction capability in this scenario; number of event samples. : The action chain number executed in this scenario within the statistical period. Number of events; actual risk reduction : for the first Next execution action chain number Comprehensive risk indicators at the start of the event The difference between the residual risk assessment value at the end and the pre-set risk reduction capacity. The original action chain number in the scenario-risk-action matrix was... Configured risk reduction capability parameters.
[0115] When the action chain deviation index When a value is consistently negative and has a large absolute value, it indicates that the actual risk reduction capability of the action chain is lower than expected. The main site can reduce the preset risk reduction capability of the action chain in the matrix. Thus, the preference index in the next statistical period It will naturally decrease, so that the action chain is no longer frequently selected; when the action chain deviation index When the value is clearly positive, it can improve the action chain. This will enhance its priority under the same scenario and risk level.
[0116] Through the action chain deviation index The effects of a single coordinated action are incorporated into the parameters of the scenario-risk-action matrix, allowing the priority of the action chain to be gradually adjusted based on long-term operational experience. This helps to prevent unsuitable action chains from being repeatedly selected.
[0117] In one example of a mixed-use office park, maintenance personnel review statistical reports during quarterly inspections and observe deviation indicators between two action chains for a specific building scenario. There were significant differences, so the system suggestions were adopted through the main site interface to revise the corresponding risk reduction capability parameters and cost parameters. After that, the root cause events of the same scenario will select the action chain with good risk reduction performance more frequently in the new cycle, thereby reducing the scope of unnecessary power outages and improving the protection of critical loads.
[0118] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0119] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0120] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0121] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0122] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for security alarm and linkage of power utilization information acquisition terminal, characterized in that: Comprising, The terminal side determines the working threshold according to the physical security baseline parameters and the scene division portrait unit, and when the parameters approach the working threshold, it starts the window extraction dynamic fingerprint, generates a security alarm event carrying the portrait unit identification after matching with the dangerous mode fingerprint; The edge node side receives the security alarm event and maps it to the electrical and communication topology graph, matches the mapping result with the alarm propagation fingerprint library to obtain the fault mode, and combines the electrical quantity uploaded by the terminal to perform power flow calculation and double topology verification to determine the root cause node and generate the root cause result; The master station side selects the corresponding linkage action chain in the scene-risk-action matrix according to the root cause result, and issues control instructions for the root cause node and downstream terminals, and adjusts the subsequent actions according to the returned data and alarm changes during execution; The master station side generates an update configuration of the terminal threshold setting, alarm propagation fingerprint library and scene-risk-action matrix based on the security alarm event, root cause result and linkage action chain execution record at the end of the statistical period, and issues it to the terminal and edge node.
2. The power utilization information collection terminal security alarm and linkage method according to claim 1, wherein: When dividing the portrait unit, the power utilization information collection terminal groups the historical operation data according to the peak, flat, valley of the operation time, and the combination of weekdays and holidays, as well as the user categories of residents, apartments, hospitals, and data centers; It also groups the historical operation data according to the belonging transformer area, branch location, normal, maintenance, and power protection operation modes, as well as the load component fingerprints of active, reactive, harmonic, and three-phase imbalance, and each group corresponds to a portrait unit, and carries the portrait unit identification in the alarm event.
3. The power utilization information collection terminal security alarm and linkage method according to claim 2, wherein: When the parameters approach the working threshold, the terminal increases the sampling frequency to obtain short-time current, voltage or conductor temperature sequence through the setting of confirmation window, calculates the local dynamic characteristics such as rising or falling slope, fluctuation amplitude, fluctuation frequency and duration from the sequence, combines the local dynamic characteristics into a local dynamic fingerprint vector, and compares it with the fingerprints in the dangerous mode fingerprint library, and only generates an alarm event when the similarity meets the preset condition.
4. The power utilization information collection terminal security alarm and linkage method according to claim 3, wherein: When the edge node maps the alarm event to the electrical and communication topology graph, it establishes the node and upstream and downstream relationships in the electrical topology graph according to the levels of transformer, switch, line and terminal; In the communication topology graph, the node and link relationships are established according to the master station, concentrator, collector and terminal, and the candidate alarm propagation fingerprints matching the current area and device type are selected from the alarm propagation fingerprint library, and each candidate alarm propagation fingerprint describes the expected coverage range and propagation order of the alarm in the double topology.
5. The power utilization information collection terminal security alarm and linkage method according to claim 4, wherein: When the edge node uses the alarm propagation fingerprint to filter the root cause node, it checks whether the candidate root cause node covers the power-off or alarm downstream nodes in the electrical topology graph, and checks whether the corresponding link in the communication topology graph is connected; Under the root cause node assumption, the downstream node voltage and current are estimated by power flow estimation, and the estimated value is compared with the measured value uploaded by the terminal. When the topological relationship is consistent and the voltage and current deviation meets the tolerance, the candidate root cause node is written as the root cause node in the root cause result.
6. The terminal security alarm and linkage method of the power utilization information collection according to claim 5, characterized in that: When the master station maps the root cause result to the scene-risk-action matrix, the scene unit is determined according to the substation or building where the root cause node belongs, the corresponding residents, apartment, hospital or data center user type and time period; And the root cause type, the root cause confidence output by the edge node, the number of affected terminals and the number of key users in the affected terminals are taken as risk coordinate parameters to search for the candidate linkage action chain matching the risk coordinate in the scene-risk-action matrix.
7. The terminal security alarm and linkage method of the power utilization information collection according to claim 6, characterized in that: When the master station selects the linkage action chain from the scene-risk-action matrix and generates the control instruction, each linkage action chain includes sequentially executed atomic actions; The atomic actions include current limiting or load shedding for non-critical loads, step-by-step power-off for branch switches, sending alarm notifications to on-duty and operation and maintenance personnel, and sending linkage instructions to fire, building automation or video monitoring systems, and recording electrical quantities and alarm states before and after the execution of each atomic action for controlling the execution of the next atomic action.
8. The terminal security alarm and linkage method of the power utilization information collection according to claim 7, characterized in that: When the master station aggregates the alarm events, root cause results and linkage execution, the total number of alarms, the number of false alarms or dependent alarms and the number of events confirmed as hidden dangers without alarms in the profiling unit are counted within the statistical period; The number of times the alarm propagation fingerprint is confirmed as a root cause mode, the number of times the linkage action chain is selected, terminated early in execution and manually modified by operation and maintenance personnel are counted, and evaluation data for evaluating the profiling unit, alarm propagation fingerprint and linkage action chain are formed accordingly.
9. The terminal security alarm and linkage method of the power utilization information collection according to claim 8, characterized in that: The adjustment information of the threshold value, the alarm propagation fingerprint weight and the scene-risk-action matrix parameters includes the adjustment direction and amplitude of the working threshold value for the profiling unit with a high number of false alarms or dependent alarms; The use weight adjustment amount and similarity threshold correction amount for the alarm propagation fingerprint with a low matching proportion in the root cause result, and the trigger condition adjustment amount and priority adjustment amount in the scene-risk-action matrix for the linkage action chain which is terminated early or manually changed many times within the statistical period.
10. The terminal security alarm and linkage method of the power utilization information collection according to claim 9, characterized in that: The adjustment information is uniformly distributed to the terminal, edge node and master station by the master station in the form of configuration file or parameter table, and the terminal updates the threshold value in the corresponding profiling unit after loading the new working threshold value configuration. The edge node sorts the candidate alarm propagation fingerprints according to the new alarm propagation fingerprint weight configuration when matching the alarm distribution, and the master station generates the control instruction according to the new linkage action chain priority after loading the updated scene-risk-action matrix parameters in the next period.