Cooperative stability control method for micro-grid power distribution network
By quantifying communication quality and state machine switching, combined with weak network hierarchical adaptive tuning and fault ride-through current limiting, the problem of communication quality sensitivity in distribution networks with a high proportion of distributed power sources is solved, achieving system stability and auditability, and improving recovery success rate and operation and maintenance efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING LEISHI TECH CO LTD
- Filing Date
- 2025-12-30
- Publication Date
- 2026-04-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In distribution networks with a high proportion of distributed power sources and energy storage, existing technologies suffer from problems such as communication quality sensitivity, cross-layer command catching up and secondary excitation, and difficulty in auditing and reproducing events. These issues lead to reduced system stability margin, increased risk of controller malfunction/failure to operate, and difficulty in reviewing field events and solidifying strategies.
By quantifying the communication quality index Q_comm, using structured command messages for version consistency verification, establishing a collaborative control state machine, and combining weak network hierarchical adaptive tuning and fault crossing rate limiting, the evidence chain is recorded to achieve auditable and reproducible collaborative stable control.
It improves system stability margin and engineering robustness, reduces controller coupling oscillation risk, enhances grid connection recovery success rate and operational safety, and supports policy versioning iteration and operational efficiency.
Abstract
Description
Technical Field
[0001] This invention belongs to the field of distribution network automation and microgrid control technology, and relates to the cross-boundary collaborative stability control of microgrid-distribution network in active distribution network scenarios with high proportion of distributed power sources and energy storage access. Background Technology
[0002] With the high proportion of distributed photovoltaic, wind power, energy storage, and charging / swapping facilities integrated into the distribution side, the distribution network is exhibiting characteristics of active operation, weakened network connectivity, and dense controllers. Existing projects typically employ a hierarchical architecture of "slow dispatch / optimization from the master station + rapid local control of the microgrid," or on this basis, superimposed event-triggered coordination, adaptive tuning of weak network parameters, inverter fault ride-through, and current-limiting strategies to improve voltage, frequency, and power balance capabilities. However, in actual operation, the above solutions still reveal problems such as sensitivity to communication quality, cross-layer command catching-up and secondary excitation, and difficulty in auditing and reproducing events.
[0003] Specifically, when the communication link between the master station and the microgrid experiences increased latency, jitter, packet loss, out-of-order delivery, or short-term interruptions, the upper-level collaborative setpoints and local control loops are prone to forming a closed-loop behavior of "catching up and repeatedly correcting," leading to setpoint flipping, high-frequency jitter in control output, and even inducing secondary excitation, thereby reducing the system stability margin. At the same time, weak-grid adaptive tuning may misjudge and frequently jump gears under conditions of measurement noise, frequent topology changes, or insufficient identification reliability, and parameter jumps may further trigger new oscillation risks.
[0004] Furthermore, inverter current limiting / ride-through strategies significantly alter fault current and dynamic support characteristics. If these strategies lack consistent coordination with traditional protection, switching actions, reclosing windows, and synchronous grid connection conditions, surges, secondary limit exceedances, or grid connection failures can easily occur during the post-fault recovery phase, increasing the risk of maloperation / failure to operate. For large-scale multi-microgrid integration scenarios, centralized, detailed control also puts pressure on communication and computing power, and the execution order of authority boundaries, emergency limiting, and recovery links remains unclear. More importantly, field events often lack auditable evidence chains and replayable evaluation mechanisms, making it difficult to review events, assign responsibility, and solidify strategies, thus limiting engineering promotion and continuous iteration.
[0005] To address this, we propose a collaborative stable control method, system, and storage medium that performs validity period and version consistency checks, communication quality tiered gating, and state machine switching on collaborative control commands under adverse communication conditions such as communication latency, packet loss, out-of-order delivery, and interruption. This is combined with weak network tiered adaptive tuning, fault crossing rate limiting and tiered degradation recovery, and evidence chain recording and playback reproduction evaluation. Summary of the Invention
[0006] The purpose of this invention is to address the shortcomings of existing technologies as described in the background section by proposing a collaborative stability control method for microgrid distribution networks.
[0007] To achieve the above objectives, the present invention adopts the following technical solution: A microgrid distribution network collaborative stability control method is applied to cross-boundary collaborative control between the distribution network master station and at least one microgrid controller. The method includes: S1. Obtain communication quality parameters such as latency, packet loss rate, jitter and / or continuous interruption duration of the communication link between the master station and the microgrid controller. Normalize and weight the communication quality parameters to obtain the communication quality index Q_comm, and map Q_comm to communication levels C0 to C3, so as to serve as the gating basis for receiving and executing cooperative control commands, switching cooperative state machines and / or selecting recovery strategies. S2. The master station encapsulates the collaborative control command into a structured command message containing command identifier, event identifier, timestamp, validity period, retention time, priority, strategy / parameter version information, and signature / verification information. The microgrid controller performs communication level permission verification, validity period verification, version consistency verification, and signature / verification verification on the structured command message. If the verification passes, it enters the execution link. If the verification fails, it enters the hold-freeze or rollback local autonomous control and records the reason code. S3. Establish a collaborative control state machine on the microgrid controller side. The collaborative control state machine includes at least a normal collaborative state, an event-enhanced state, a frozen state, a rollback local autonomous state, and a resynchronization recovery state. It switches between states based on changes in communication level, command verification results, and / or event triggering. In the frozen state, only boundary constraint commands are allowed and rapid changes in setpoints are suppressed. Furthermore, command validity period and version consistency constraints, setpoint change rate limits, and output hold / integral anti-saturation suppression commands are used to catch up during the frozen period. S4. Based on the equivalent short-circuit ratio, equivalent impedance characteristics, frequency change rate and / or voltage frequency disturbance response, construct weak network indicators and output weak network classification levels L0 to L3. At the same time, calculate the weak network identification confidence level mc. When mc is lower than the preset threshold, freeze the weak network classification level and the corresponding control parameter shaping set. When the level is allowed to be changed, the parameter shaping set is interpolated and smoothly switched according to the preset smoothing time to reduce the risk of oscillation caused by misjudgment and frequent level jumping. S5. When events such as undervoltage, overcurrent, frequency over-limit, protection action and / or switch quantity change are detected, the inverter current limiting and fault ride-through control is executed and the graded degradation level G0 to G3 is entered. The recovery path is selected in combination with the reclosing window and the synchronous grid connection permission conditions. When the synchronization conditions are met, the resynchronization recovery state is entered and the recovery is carried out in an orderly manner according to the preset smooth time. The circulating current and secondary over-limit are suppressed and constrained in the recovery process. S6. The microgrid controller or its aggregator periodically sends out capability packages. The capability packages include at least active / reactive power availability boundaries, ramping constraints, set of permissible control modes, stability level / risk indication and / or islanding / networking capability information. The master station forms a set of control commands that can be sent out based on the capability packages and generates coordinated control commands within the set of control commands to avoid over-capacity commands. S7. When events such as exceeding limits, protection actions, switch changes, communication level changes, weak network level changes, and / or downgrade level changes are detected, an evidence chain package is generated. The evidence chain package includes at least the triggering condition, snapshot window, instruction sequence and parameter sequence, communication level, reason code, version information, and signature / verification information. After performing multi-source time alignment and cross-consistency verification on the evidence chain package and passing the trusted gating, a trusted evidence chain package is formed. The trusted evidence chain package is replayed and reproduced, and a replay consistency score is output. Based on the replay consistency score, the strategy parameters, thresholds, and / or adjustment sets are solidified into the database or rolled back for management.
[0008] As a further step in this application, the communication quality index Q_comm is obtained by weighting latency score, packet loss score, jitter score, and continuous interruption duration score, and the communication levels C0 to C3 include at least: C0 indicates excellent communication, allowing regular coordination and optimization; C1 indicates good communication, allowing regular coordination and optimization but limiting the sending frequency; C2 indicates poor communication, entering a frozen state and only allowing low-frequency boundary constraint commands; and C3 indicates communication interruption or unavailability, triggering a rollback to local autonomous control.
[0009] As a further aspect of this application, the validity period of the structured instruction message is used to limit the execution time window of the instruction, and the microgrid controller deduplicates and discards out-of-order, duplicate, or expired structured instruction messages, and writes the reason for the discard in the event log and evidence chain package in the form of a reason code.
[0010] As a further step in this application, the state switching of the collaborative control state machine satisfies at least one of the following rules: when the communication level drops to C2 or version consistency verification fails, it enters a frozen state; when the communication level drops to C3 or validity period verification / signature verification fails, it enters a rollback local autonomous state; when the communication level recovers and continues to meet the preset retention time and passes the instruction verification, it enters a resynchronization recovery state, and in the resynchronization recovery state, the set value and key parameters are gradually merged according to the preset smoothing time before returning to the normal collaborative state.
[0011] As a further step in this application, the weak network identification confidence level mc is calculated from the identification residual, measurement inconsistency, and / or fitting quality. When mc is below a threshold, the upshift or downshift action is frozen, and shifting is only allowed after mc recovers and continues to meet the preset holding time. The parameter shaping set includes at least one or more of the following: phase-locked loop bandwidth, virtual impedance parameter, damping parameter, power change limit, and / or network-connected / network-following control mode priority strategy.
[0012] As a further step in this application, the graded degradation levels G0 to G3 correspond to different sets of current limiting and stability support strategies, and the degradation level increases with the severity of the event, thereby limiting active power output, increasing voltage / frequency support priority and / or entering more stringent safety boundary control, and limiting the rate of change of cooperative setpoints during the degradation level maintenance period.
[0013] As a further step in this application, the recovery path selection includes: determining whether the synchronization conditions are met within the reclosing window, wherein the synchronization conditions include at least one or more of the frequency difference threshold, voltage difference threshold, and phase angle difference threshold; maintaining a higher degradation level and extending the recovery holding time when the synchronization conditions are not met; and entering the resynchronization recovery state to perform orderly recovery according to a preset smoothing time when the synchronization conditions are met.
[0014] As a further step in this application, the capability package also includes a reclosing blocking flag and / or grid connection permission constraint information. The master station calculates the intersection or union boundary of the capability packages of multiple microgrids to form a control set that can be issued, and adopts different issuance gating strategies for emergency boundary type commands and recovery optimization type commands. Emergency boundary type commands are allowed to be issued when the communication level is C2, while recovery optimization type commands are only issued when the communication level is C0 or C1 and the versions are consistent.
[0015] As a further step in this application, the multi-source time alignment includes alignment based on unified time synchronization or alignment based on event anchors, and the cross-consistency verification includes at least command-response consistency, protection / switch event consistency, and physical boundary rationality verification; and a hash digest is generated for the trusted evidence chain packet through trusted gating and signature / verification information is attached for storage in an append-only manner, thereby achieving tamper-proof auditing.
[0016] As a further step in this application, the evidence chain package and / or credible evidence chain package further includes a waste energy vector and an energy consistency verification result T_energy. The waste energy vector includes at least the energy of energy curtailment / limited generation, energy storage overflow, network loss estimation, ineffective regulation energy caused by command catch-up, and / or energy storage cycle cost. Within the degradation and recovery window of degradation levels G0 to G3, power reallocation is performed without exceeding the hard constraints of voltage / frequency boundaries, capacity package boundaries and ramp limits, upper and lower limits of energy storage state of charge (SOC), line / transformer capacity, and communication level gating. The output includes a reallocation command containing active / reactive power reallocation amount, ramp limit, priority, and validity period. The restricted information is fed back to the local controller to suppress integral saturation and command catch-up.
[0017] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. By quantizing communication quality Q_comm and using graded gating from C0 to C3, and combining the freeze / rollback / resynchronization mechanism of the cooperative state machine, communication degradation is explicitly incorporated into the switching conditions of the cooperative closed loop. This suppresses high-frequency jitter and secondary excitation caused by out-of-order, expired, and catch-up instructions from the root, thereby improving the system's stability margin and engineering robustness.
[0018] 2. By freezing the weak network classification L0 to L3 and the confidence level mc, and smoothly switching the parameter shaping set within t_blend, the risk of controller coupling oscillation caused by weak network identification misjudgment and frequent level jumps is reduced, thereby improving the stability and controllability in weak network scenarios.
[0019] 3. By linking current limiting / crossover with downgrade levels G0 to G3, reclosing windows, and synchronous grid connection permit conditions, and by constraining the recovery rhythm with a recovery path selector, the risk of protection coordination maloperation / failure to operate can be effectively reduced, and the sudden surge and secondary over-limit during post-fault recovery can be avoided, thereby improving the success rate of grid connection recovery and operational safety.
[0020] 4. By aggregating CapabilityPackages and constraining permission boundaries, the collaborative deployments from the main station fall within the executable set, and emergency boundaries are directly reached to restore optimized order. This reduces communication and computing pressure in multi-microgrid expansion scenarios, avoids over-capability instructions, and clarifies responsibility boundaries.
[0021] 5. Through multi-source verification of evidence chains and trusted evidence chains, trusted gating, signature sealing and playback consistency scoring mechanism, events can be audited, reproduced, quantified and evaluated and solidified into the database, supporting policy version iteration, canary release and rollback, significantly improving the efficiency of project promotion and operation and maintenance review.
[0022] 6. By using WasteEnergyVector, energy consistency verification T_energy, and power redistribution mechanism during degradation, stable control and energy saving are evaluated and optimized in a coordinated manner without exceeding safety boundaries. This reduces energy consumption from energy curtailment and ineffective regulation, and improves the overall economic efficiency of the system. Detailed Implementation
[0023] The following description, in conjunction with preferred embodiments of the present invention, further illustrates "a method for coordinated stability control of microgrid distribution networks." It should be understood that the following embodiments are used to explain the present invention and not to limit the scope of protection of the present invention. Without departing from the concept of the present invention, those skilled in the art can make equivalent substitutions or modifications to the parameters, structured fields, thresholds, and process sequences, all of which should fall within the scope of protection of the present invention.
[0024] The purpose of this invention is to provide a microgrid-distribution network collaborative stability control method, system, and storage medium that is communication robust and auditable and replayable, in order to solve technical problems such as easy oscillation and command chasing in collaborative closed loop under communication delay / packet loss / interruption conditions, easy misadjustment in weak network adaptation, increased recovery risk due to inconsistency between current limiting crossing and protection / reclosing / synchronous grid connection actions, and difficulty in auditing, reproducing, and solidifying field events.
[0025] To achieve the above objectives, this invention proposes a cross-boundary collaborative closed loop of "communication gating - weak network classification - traversal degradation - recovery and resynchronization - evidence chain playback and solidification".
[0026] First, a communication quality quantification index Q_comm is established, and the latency, packet loss, jitter and continuous interruption duration of the communication link are normalized and scored and mapped to communication levels C0 to C3. The communication level is used not only as a gating condition for whether the cooperative instruction can be received and executed, but also as a selection of switching and recovery strategies for the cooperative control state machine. To avoid out-of-order and expired instructions triggering catch-up, this invention uses a structured message CommandPacket for collaborative instructions issued by the master station. The message carries at least the instruction identifier, event identifier, timestamp, validity period (ts_valid), hold time (hold_time), priority, policy version (version), and signature / verification field. The microgrid side only accepts and executes instructions that meet the requirements of communication level, validity period not expired, version consistency verification passed, and signature verification correct. Otherwise, it enters the hold-freeze or rollback policy and records the reason code for auditing.
[0027] Secondly, this invention constructs a collaborative control state machine (State) to constrain the execution mode and setpoint change rhythm of the collaborative link under different communication and event conditions; The state machine includes at least a normal cooperative state (State-N), an event-enhanced state (State-E), a frozen state (State-H), a rollback to local autonomy state (State-R), and a resynchronization recovery state (State-S). When communication is good, it allows regular cooperative optimization and slow setpoint updates. When an event is triggered, it allows emergency boundary-type instructions and increases the sampling / issuance frequency. When communication deteriorates or versions are inconsistent, it enters a frozen state, allowing only boundary constraint-type instructions and suppressing rapid changes in setpoints. When communication is interrupted or verification fails, it rolls back to local autonomous stable control. After communication is restored and the resynchronization conditions are met, it smoothly merges the cooperative setpoints and key parameters according to a preset smoothing time t_blend to complete the recovery. This forms a unified logic of "cooperative when available, frozen when deteriorating, rollback when failing, and resynchronization when recovering" to reduce the risk of catch-up oscillations and secondary excitations.
[0028] Thirdly, this invention introduces a weak network classification level L0 to L3 and a confidence level mc freezing mechanism. The weak network level can be determined based on weak network indicators such as equivalent short-circuit ratio, equivalent impedance characteristics, frequency change rate, and voltage / frequency disturbance response, and a corresponding set of control parameter shaping is configured for different levels. At the same time, the weak network identification confidence level mc is calculated. When mc is lower than the threshold mc_min, the level and parameter shaping are frozen, and frequent level switching is prohibited. Switching is only allowed after mc has been held for a certain period of time. The switching process uses interpolation or S-curve to smoothly transition within t_blend to avoid oscillations induced by parameter jumps.
[0029] Fourth, this invention models the fault ride-through / current limiting process and the graded degradation recovery mechanism in a unified manner, sets degradation levels G0 to G3 and links the reclosing window with the synchronous grid connection permit conditions to construct a recovery path selector; When events such as undervoltage, overcurrent, frequency over-limit, or protection action occur, the system executes current limiting / through-pass strategy and enters the corresponding degraded level. If the synchronization conditions (such as frequency difference, voltage difference, phase angle difference, etc.) are not met within the reclosing window, the higher degraded level is maintained and the recovery holding time is extended to suppress rapid grid connection recovery and avoid surges and secondary over-limits. Once the synchronization conditions are met, the system enters the resynchronization recovery state, smoothly recovers using t_blend, and suppresses and constrains the circulation and secondary over-limits, thereby improving the recovery success rate and the consistency of protection coordination.
[0030] Fifth, to enhance the expansion capabilities and clarity of authority boundaries of multi-microgrid systems, this invention adopts a CapabilityPackage aggregation mechanism. Each microgrid / aggregator periodically transmits available active / reactive power boundaries, ramping constraints, permitted mode sets, stability level / risk indicators, and islanding / networking capabilities as well as reclosing blocking flags. The master station generates and issues collaborative instructions only within the capability package constraint set (intersection / union boundary). Emergency boundary instructions are allowed to be delivered directly with low bandwidth under poor communication conditions, while recovery and optimization instructions are issued in an orderly manner only when communication is good and the versions are consistent. For out-of-boundary or unauthorized instructions, the microgrid side refuses to execute and records the reason code, forming an auditable authority boundary.
[0031] Sixth, this invention establishes a closed-loop mechanism of "Evidence ChainPack — Trusted Evidence ChainPack — Replay Reproduction Consistency Score (score_replay) — Policy Solidification and Storage"; when an event is triggered, an Evidence ChainPack is generated, which records at least the triggering conditions, snapshot window, instruction sequence and parameter sequence, communication level, reason code, version information and signature field. Before the evidence chain enters replay and solidification, multi-source time alignment and cross-consistency verification are performed to form a trusted evidence chain and calculate the trust score T_score to implement "verify before use" gating. Only the evidence chain that passes the gating is replay scored and parameters are solidified.
[0032] Furthermore, this invention introduces power waste / consumption data collection and WasteEnergyVector construction into the evidence chain, and adds energy consistency verification to obtain T_energy gating during the generation of credible evidence chain, so that the evidence chain can not only be "similar" at the waveform level, but also "correct" at the energy account level; in addition to peak error, duration error, attenuation characteristic error and integral error, the playback consistency score expands the dimension of waste consumption consistency error, thereby supporting the quantifiable evaluation and traceable solidification of strategy iteration.
[0033] Furthermore, to simultaneously collect "power waste / consumption" data during the downgrade and recovery process for verification and optimization, this implementation constructs a waste / consumption vector (WasteEnergyVector) and a total consumption index (T_energy). WasteEnergyVector includes at least two of the following components: abandoned energy (the portion of available generation or available output that is not utilized is obtained by integrating over time), overflow / unacceptable energy (the portion that cannot be transmitted due to distribution network acceptance boundaries or back-transmission restrictions is obtained by integrating over time), estimated energy of network loss or transformation loss (estimated by the equivalent loss model of the line / transformer or the measured power difference and accumulated over time), ineffective regulation energy (the difference energy caused by command changes not being actually executed or being cut off by limiting), and cycle / switching costs (obtained by accumulating the number of switching actions, the number of mode switching, the ramp rate, etc., according to the conversion factor).
[0034] Furthermore, T_energy is used to perform weighted summation of each component, and the weights can be configured according to the scenario: increase the weight of energy curtailment in scenarios sensitive to energy curtailment, increase the weight of loss in scenarios sensitive to network loss, and increase the weight of switching cost in scenarios sensitive to equipment lifespan.
[0035] Furthermore, WasteEnergyVector and T_energy, along with the replay score, downgrade level, and boundary trigger record, are written into the evidence chain and trusted evidence chain for subsequent recovery route selection, power redistribution evaluation, and strategy grayscale verification.
[0036] In some preferred embodiments, the present invention also introduces a power redistribution mechanism within the degradation and recovery window. Under the premise of not exceeding voltage / frequency boundaries, capacity package boundaries and ramping limits, energy storage SOC constraints, line / transformer capacity, reclosing windows and synchronization permissions, and communication gating conditions, the active / reactive power sharing of each microgrid is dynamically adjusted, redistribution instructions are output, and the restricted information is fed back to the local controller to suppress integral saturation and catch-up. After meeting the safety hard constraints, the optimization goal is to reduce the energy and loss costs of energy curtailment, overflow, and ineffective catch-up, so as to achieve coordinated rescheduling with "safety first, while taking into account energy conservation and consumption reduction".
[0037] Based on the above method, the present invention also provides a corresponding system, which may consist of a master station collaborative control device, a microgrid collaborative control device, and a field execution and measurement device, including at least a communication quality assessment module, a collaborative state machine and command gating module, a weak network classification and setting module, a cross-current limiting and degradation recovery module, a capability packet aggregation and permission boundary module, an evidence chain recording and playback module, a waste consumption accounting and power redistribution module, and an interface and security module; at the same time, the present invention also provides a computer-readable storage medium, on which a program stored implements the above method when executed by a processor.
[0038] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0039] Example 1: Overall Collaborative Architecture and Data Objects In this embodiment, the system consists of a distribution network master station (DMS / ADMS or dispatch control platform), a communication link, at least one microgrid controller (MGCC / EMS), and inverter control units, energy storage management units, and measurement and switching quantity acquisition units within the microgrid. The master station is responsible for cross-microgrid collaborative boundary management, event linkage, and policy issuance, while the microgrid controller is responsible for local fast and stable control, command gating execution, and evidence chain recording and playback evaluation. The master station and the microgrid controller interact via structured messages, and both the master station and the microgrid controller maintain unified policy version numbers and parameter version numbers for version consistency verification.
[0040] In this embodiment, the following key data objects are defined: ① Communication quality index Q_comm and communication levels C0~C3: The master station or microgrid controller collects communication quality parameters such as one-way delay, packet loss rate, jitter, and outage duration in real time from the communication link, and normalizes and weights each parameter to obtain Q_comm; for example, Q_comm can be expressed as Q_comm=w1·f1(Delay)+w2·f2(Loss)+w3·f3(Jitter)+w4·f4(Outage), where w1~w4 are weights and f1~f4 are monotonic scoring functions; then Q_comm is mapped to communication levels C0~C3: C0 is excellent, C1 is good, C2 is poor, and C3 is interrupted / unavailable. The communication level is used for subsequent command reception gating, state machine switching, and recovery path selection; Furthermore, to ensure that the communication status is quantifiable, categorizable, and can trigger corresponding degradation strategies, the communication quality score Q_comm is obtained by integrating multi-dimensional observations. The observations include at least two or more of the following: end-to-end instruction latency, packet loss rate, jitter amplitude, and out-of-order / repeated ratio. Each observation is normalized into a sub-score according to the method of "below the lower limit is considered good, above the upper limit is considered unusable, and the score decreases linearly or piecewise within the interval". Then, the scores are weighted and summed according to configurable weights to obtain Q_comm.
[0041] Furthermore, based on Q_comm, communication capabilities are divided into levels C0 to C3, and a hold time t_hold and a rise hysteresis are set: an upgrade is allowed only when Q_comm continuously and stably reaches the high-level threshold and holds for t_hold, and a downgrade is allowed only when Q_comm falls below the low-level threshold and continues for several sampling cycles, in order to avoid level jitter.
[0042] For example: C0 indicates reliable communication, allowing full updates of boundary / recovery / optimization commands; C1 indicates mild degradation, allowing boundary and recovery commands, and reducing or limiting the frequency of optimization commands; C2 indicates moderate degradation, allowing only boundary and critical recovery commands, and freezing optimization commands or allowing only conservative strategies; C3 indicates severe degradation, entering local safety control, and only accepting emergency blocking / unblocking commands.
[0043] Furthermore, the command package's expiration time (TTL) is used for discarding expired packages; idempotent keys are used for deduplication; and for cases of out-of-order delivery, duplication, expiration, or verification failure, the system generates a reason code and writes it into the evidence chain to support review and auditing.
[0044] ② Structured CommandPacket: The master station encapsulates collaborative control commands into a structured packet containing command identifier cmd_id, event identifier event_id, timestamp ts, validity period ts_valid, hold time, priority, mode token mode_token, policy / parameter version version_info, and signature / verification field signature; where validity period is used to limit the executable time window of the command, hold time is used to suppress frequent switching and catch-up, and priority is used to distinguish between emergency boundary commands and recovery optimization commands; Furthermore, to ensure that concepts such as "boundary constraint instructions" and "recovery optimization instructions" have an operable and auditable implementation, this implementation method encapsulates the control instructions issued by the master station / aggregator to the microgrid side into a unified command packet. The command packet includes at least: instruction timestamp, sequence number, source identifier, target identifier, instruction type field cmd_type, priority field priority, validity period ttl, idempotent key idempotent_key, digest / signature field, and parameter payload. The cmd_type is used to explicitly distinguish the command type, which can be divided into at least the following three categories: One type is "boundary constraint instructions", which are used to issue or update hard boundary and safety constraint information on the distribution network side. The payload includes at least grid connection permission / prohibition flags, grid connection / disconnection windows, power / current limits, ramp limits, reactive power / voltage support boundaries, and blocking duration after protection action. The second is "recovery strategy instructions", which are used to issue grid connection recovery paths and synchronization strategies. The payload includes at least the reclosing window, synchronization criterion threshold (frequency difference, voltage difference, phase angle difference, etc.), smooth transition duration t_blend, recovery stage objectives (voltage stabilization first / frequency stabilization first / current limiting first), etc. The third is "optimized scheduling instructions", which are used to perform objectives such as power redistribution, peak shaving and valley filling, and energy curtailment reduction under the premise of meeting boundary constraints. The payload includes at least the target weight, critical load list and minimum guarantee, adjustable resource set and action budget, scheduling cycle, etc. Furthermore, the priority is defined using a range-based convention: boundary constraint instructions have the highest priority and are forcibly overridden by recovery and optimization; recovery strategy instructions have the second highest priority; and optimization scheduling instructions have the lowest priority. This allows the principle of "safety boundary takes precedence over recovery and optimization" to be directly expressed by the field and to be reproduced in the evidence chain.
[0045] ③ Cooperative control state machine: The microgrid controller side is equipped with at least the following states: normal cooperative state (State-N), event-enhanced state (State-E), frozen state (State-H), rollback local autonomy state (State-R), and resynchronization recovery state (State-S). The entry and exit of each state are driven by the communication level, command verification results, event triggering, and hold timer.
[0046] ④ Weak network classification L0~L3 and confidence level mc: The microgrid controller calculates weak network indicators based on equivalent short-circuit ratio (SCR), equivalent impedance characteristics (R / X, etc.), rate of change of frequency (ROCOF), voltage / frequency disturbance response, etc., and maps them to weak network classification levels L0~L3. At the same time, it calculates and identifies the confidence level mc. When mc is lower than the threshold mc_min, the level and parameter shaping set are frozen to avoid misjudgment and frequent level switching.
[0047] ⑤ Degradation level G0~G3 and recovery path selection: For events such as undervoltage, overcurrent, frequency over-limit, protection action, and switch quantity change, the microgrid controller enters the corresponding degradation level G0~G3 to execute current limiting / cross-through and stability support strategies, and selects a recovery path in combination with the reclosing window and synchronous grid connection permission conditions. After the synchronization conditions are met, it enters resynchronization recovery and smooth return.
[0048] ⑥ Capability Package: The microgrid controller or its aggregator periodically sends out a capability package, which includes at least P / Q availability boundaries, ramp constraints, set of allowed control modes, stability level / risk indication, islanding / grid connection capability information, grid connection permission / reclosing blocking flag, etc. The master station generates executable coordination instructions within the constraint set of the capability package to avoid over-capacity instructions.
[0049] ⑦ EvidenceChainPack and TrustedEvidenceChainPack: An evidence chain packet is generated when an event is triggered. It contains at least the triggering condition, snapshot window, instruction sequence cmd_seq, parameter sequence param_seq, communication level, reason code, version information, and signature field. Then, a trusted evidence chain is formed through multi-source time alignment and cross-consistency verification, and a trust score T_score is given. Only when T_score meets the gating conditions will the playback evaluation and parameter solidification process begin.
[0050] ⑧ WasteEnergyVector and Energy Consistency Verification T_energy: The evidence chain can further include abandoned / limited energy, energy storage overflow, network loss estimation, ineffective regulation energy and energy storage cycle cost, etc., and output T_energy through energy consistency verification to ensure that the playback is not only "waveform similar" but also "energy account correct".
[0051] In this embodiment, when the microgrid controller receives instructions from the master station, it performs the following checks in sequence: First, it checks whether the communication level allows it (e.g., C0 / C1 allows all collaborative instructions, C2 only allows boundary constraint instructions, and C3 rejects all upper-layer instructions and rolls back to local autonomy); second, it checks the validity period, and instructions whose ts exceeds ts_valid are directly discarded and the reason code is recorded; third, it checks the version consistency, and if there is an inconsistency, it enters a frozen state and triggers the resynchronization process; finally, it checks the signature / verification, and if it fails, it enters a rollback to local autonomy state. When all checks pass, the instruction enters the execution link.
[0052] In this embodiment, an anti-chasing suppression mechanism is adopted under the frozen State-H state: the rate of change and step limit are implemented for changes in the set value; the last effective collaborative set value is maintained during the freeze period and rapid repeated correction is prohibited; anti-saturation processing is implemented for the local controller integral term to avoid the upper layer being restricted, which causes the integral to accumulate and cause a "rush" during recovery; at the same time, deduplication is performed on out-of-order and duplicate messages to ensure that the execution sequence is monotonically consistent.
[0053] Example 2: Collaborative Operation under Normal Communication and Event Triggering (State-N / State-E) In this embodiment, when the communication level is C0 or C1 and the strategy version is consistent, the microgrid controller is in the normal coordination state (State-N). The master station generates coordination instructions based on the capability packet boundaries (e.g., P / Q upper limit, ramp constraint, set of allowed modes) sent by each microgrid. These instructions include, but are not limited to, active / reactive targets, selection of droop / virtual impedance setting parameters, emergency boundary constraints, or recovery optimization instructions. The master station encapsulates these instructions into a CommandPacket and sends them out. After the microgrid controller verifies the instructions, it writes the upper-level targets into the local coordination layer at low frequency. The local fast control loop then completes the rapid adjustment of voltage, frequency, and power.
[0054] When events such as exceeding limits, protection action warnings, switch quantity changes, or reclosing window entry are detected, the microgrid controller enters the event-enhanced state, State-E. In State-E, emergency boundary commands and safety constraints (such as current limiting, voltage limiting, and frequency support strategy switching) are executed first, and the evidence chain sampling density and snapshot window recording granularity are increased. At the same time, stricter change rate limits are set for upper-level recovery optimization commands to prevent secondary excitation caused by "rushing" in the early stage of the event.
[0055] Example 3: Freeze-down and resynchronization under communication degradation / interruption (State-H / State-R / State-S) In this embodiment, when communication quality degrades and Q_comm is mapped to C2, the microgrid controller switches from State-N or State-E to the frozen state State-H. At this time, only emergency boundary commands (such as amplitude limiting commands, grid connection prohibition commands, or reclosing blocking commands) are allowed to enter the execution link, while recovery and optimization commands are gated and rejected. The microgrid controller maintains the most recent effective cooperative setpoint and feeds back the upper-level restricted information to the local controller to implement anti-saturation and rate limiting, thereby suppressing the oscillation caused by setpoint catch-up.
[0056] When communication deteriorates further to C3 or when signature verification or validity period verification fails, the microgrid controller enters the local autonomous state (State-R). In State-R, the microgrid controller ignores upper-level collaborative optimization and adopts a local autonomous stability control strategy to maintain voltage, frequency, and power balance. If it is operating in grid-connected mode, it performs voltage / frequency support and current limiting protection according to the local strategy. If it is in islanded mode or has grid-connection capability, it maintains islanded stability according to the local grid-connection control strategy and continuously records the rollback reason code, communication status, and local key quantities into the evidence chain.
[0057] Once communication is restored and stabilizes at C0 or C1 for a duration exceeding the preset holding time, the microgrid controller enters the resynchronization recovery state, State-S. In State-S, the microgrid controller first performs a re-consistency check on the strategy version and parameter version. If inconsistencies exist, a version alignment process is triggered and the system remains frozen. If consistent, the collaborative targets, boundaries, and tuning parameters issued by the master station are progressively merged over a preset smoothing time t_blend. For example, linear interpolation or an S-curve is used to transition the setpoint from the frozen value to the new target. Change rate limits and circulating current / secondary limit suppression constraints are set for the transition process. After the transition is complete, the system returns to the normal collaborative state, State-N. This process avoids the sudden surge of "catching up" after communication restoration and secondary excitation caused by out-of-order commands.
[0058] Example 4: Adaptive Tuning of Weak Network Classification and Confidence Freezing (L0~L3 and mc) In this embodiment, the microgrid controller periodically calculates weak grid indicators and outputs weak grid levels L0 to L3, while simultaneously calculating the identification confidence level mc. Taking control parameter shaping as an example, under L0 / L1, a higher bandwidth phase-locked loop and a smaller virtual impedance can be used to obtain fast following capability; under L2 / L3, the phase-locked loop bandwidth is reduced, the virtual impedance or damping is increased, and the power change limit is tightened to improve weak grid stability. To avoid misjudgment, if mc is lower than the threshold mc_min, the current level and parameter set are frozen, and the level change is not performed. Level change is only allowed when mc recovers and continuously meets the holding time t_mc_hold, and the level change process is smooth within t_blend. This implementation can significantly reduce the risk of frequent topology changes, measurement noise, and frequent level skipping under missing measurement conditions, thereby reducing the probability of controller coupling oscillation. Furthermore, in order to make the weak network strength classification and network parameter shaping feasible, the weak network levels L0 to L3 are obtained by mapping the weak network index set, which includes at least two or more of the following: short-circuit ratio, equivalent R / X, frequency change rate, or voltage / frequency recovery characteristics after disturbance.
[0059] All indicators are statistically analyzed within a unified window and synthesized into a weak network strength criterion according to the mapping rule of "the weaker the network, the higher the level," thus corresponding to levels L0 to L3. Furthermore, a confidence level `mc` is set to characterize the reliability of the "weak network level determination and synchronization control strategy." `mc` can be constructed based on the model fitting residuals and multi-source consistency errors; when the disturbance response fitting error is large, or the estimation results at different measurement points differ significantly, `mc` decreases; when the fitting and consistency are good, `mc` increases.
[0060] Furthermore, when mc is lower than the threshold mc_min, the weak network level and key network parameters (such as PLL bandwidth, virtual impedance, damping, current limiting curve, etc.) are frozen, and the level can only be changed and unfrozen after mc is continuously higher than mc_min and maintained at t_hold, in order to avoid misjudgment that causes frequent fluctuations in network parameters or secondary over-limits.
[0061] Example 5: Fault-crossing current limiting, degradation level and reclosing / synchronization linkage recovery (G0~G3) In this embodiment, when events such as undervoltage, overcurrent, frequency over-limit, or protection action are detected, the microgrid controller immediately executes the current limiting / fault ride-through strategy and enters the degradation level G0 to G3. Taking a set of examples: G1 can be defined as mild limiting and increased damping support; G2 can be defined as further limiting active power output, prioritizing voltage and frequency stabilization, and implementing stricter speed limits on the recovery rate; G3 can be defined as entering the most stringent safety boundary control or islanding / backup power supply strategy. A hold time is set for both entering and exiting the degradation level to avoid jittery switching.
[0062] In this embodiment, the microgrid controller selects the recovery path by combining the reclosing window and the synchronous grid connection permission conditions. After entering the reclosing window, the microgrid controller calculates the synchronization conditions in real time, such as frequency difference Δf, voltage difference ΔV, and phase angle difference Δθ, and compares them with preset thresholds. If the synchronization conditions are not met, a higher degradation level is maintained and the recovery holding time is extended, and rapid grid connection recovery is prohibited. When the synchronization conditions are met, the controller enters State-S to perform resynchronization recovery. During the recovery process, the controller implements suppression constraints on circulating current and secondary over-limits (e.g., setting grid connection current upper limit, phase angle change speed limit, and power ramp-up limit), thereby improving the grid connection recovery success rate and reducing the risk of secondary over-limits.
[0063] Furthermore, in order to enable the "recovery route selection and power redistribution under downgrade levels G0 to G3" to have an executable minimum implementation, this implementation adopts a hierarchical rule of "hard boundary priority, critical load guarantee, allocation based on cost improvement, conflict backoff, speed limit and anti-catch-up". First, based on the CapabilityPackage, hard constraints such as grid connection permission, allowed power transmission / receiving boundaries, power / current limits, ramp limits, and voltage / reactive power boundaries are read to form the instantaneous feasible range of each adjustable resource; when the communication level is C2 / C3 or the downgrade level is G2 / G3, the feasible range is further tightened and some actions are prohibited (e.g., spatial migration is prohibited, and only time migration or local backup is retained). Secondly, prioritize meeting the minimum guarantee for hard boundaries and critical loads: if this is still not feasible, directly trigger the rollback mechanism (increase the degradation level, perform load shedding / power limiting and other backup actions), and record the reason code and invalid segment marker; Secondly, under the premise of meeting the minimum requirement, incremental allocation is performed on the remaining schedulable capacity: with the goal of reducing T_energy, priority is given to actions that contribute the most to reducing energy wastage, overflow, loss, ineffective adjustment, or switching frequency, and allocation is performed step by step in the order of "prioritizing those with greater marginal improvement" until the boundary is reached; if a constraint conflict or secondary limit violation occurs, the most recent action is revoked and the resource is frozen for a hold time window, while the cause of the conflict and the rollback trajectory are recorded in the evidence chain; Finally, the "limited information" is fed back to the lower-level controller, including the current effective power limit, ramp limit, freeze flag and hold time, to suppress integral saturation and "catch-up" adjustment; when the recovery window is open, the limit is gradually relaxed only within the smooth transition time t_blend to avoid secondary limit overruns caused by sudden shocks; Furthermore, the system will append each redistribution result (resource list, allocation amount, trigger constraints, T_energy change, downgrade level, replay score and trusted gating result) to the evidence chain to support offline reproduction, canary release and automatic rollback.
[0064] Example 6: Capability Package Aggregation and Multi-Microgrid Coordinated Deployment In this embodiment, multiple microgrids exist and are connected to the same distribution network feeder or area. Each microgrid controller periodically sends a CapabilityPackage, which includes at least P / Q availability boundaries, ramp constraints, allowed mode sets, stability level / risk indicators, islanding / networking capabilities, and reclosing blocking flags. The master station aggregates multiple capability packages, and can determine the intersection boundary as needed to ensure all are executable, or determine the union boundary to support hierarchical and zoned scheduling. Different gating strategies are adopted for different types of instructions: emergency boundary instructions are still allowed to be sent with low bandwidth when the communication level is C2, while recovery and optimization instructions are only sent when the C0 or C1 level is consistent. After receiving the instruction, the microgrid controller performs local capability boundary verification again. If the boundary is exceeded, execution is rejected and the reason code is recorded, thus forming a dual constraint of "generated by the master station within the set and executed on-site within the boundary," ensuring executability and auditability.
[0065] Example 7: Solidification of Evidence Chain, Credible Evidence Chain, and Replay Scoring In this embodiment, when any event occurs, such as exceeding limits, protection action, switch change, communication level change, weak network level change, or downgrade level change, the microgrid controller generates an EvidenceChainPack, recording the triggering conditions, snapshot window, command sequence and parameter sequence, communication level, cause code, version information, and signature field. Subsequently, multi-source time alignment and cross-consistency verification are performed on the evidence chain: time alignment can preferably use a unified time synchronization method; if time synchronization is unavailable, the voltage drop start point, protection SOE timestamp, or frequency mutation inflection point can be used as anchor points, and alignment residuals are obtained through cross-correlation or minimum residual alignment. Cross-consistency verification can at least include command-response consistency, protection / switch event consistency, and physical boundary rationality, outputting conflict flags and residual reports.
[0066] In this embodiment, the evidence chain is marked as a Trusted Evidence ChainPack and enters the replay reproduction evaluation only when the trust score T_score meets the gating condition. The replay consistency score score_replay can be calculated based on peak error, duration error, decay characteristic error, and integral error. At the same time, to improve the credibility of the economic evaluation, the evidence chain can also include a waste energy vector, and the output T_energy is gated through energy consistency verification. Only when T_energy passes the gating is the waste energy evaluation included in the replay score. For event samples that meet the trust gating and score_replay reaches the threshold, the corresponding strategy parameters, thresholds, or tuning sets can be solidified into the version library, and can be supported for canary release and rollback management to achieve a closed-loop iteration of "replayable - evaluable - solidifiable".
[0067] Furthermore, to ensure that the "evidence chain package / credible evidence chain / replay score" has a reproducible judgment criterion, the system records key quantity curves, action sequences and boundary triggering conditions for each control window, and forms a replay consistency score score_replay based on multi-dimensional error terms.
[0068] The multidimensional error terms include at least: peak error of key variables (such as peak deviation of voltage, frequency, current, and power), over-limit duration error (such as duration deviation of current limiting, undervoltage / overvoltage, and frequency deviation), integral error (such as difference in area of power / energy curves), and action sequence error (such as misalignment, omission, and repeated execution of switching action / command sequence).
[0069] After the above error terms are normalized according to a unified standard, they are summed according to configurable weights to obtain score_replay; the higher the score_replay, the more consistent the playback is with the actual situation. Furthermore, the system sets a trusted gating T_score as a unified threshold for "solidification and release". T_score can comprehensively consider factors such as playback consistency, communication quality and weak network confidence: when score_replay is low, or Q_comm is poor, or mc is insufficient, T_score decreases.
[0070] Furthermore, when T_score is lower than the threshold T_min or fails to meet the standard for several consecutive windows, the system prohibits the release or fixation of optimization strategies, and instead adopts a conservative parameter set or triggers a rollback; and appends the trigger reason code, window identifier and evidence chain summary to achieve "traceability, replayability, grayscale capability and rollback capability".
[0071] Example 8: Power reallocation within the degradation / recovery window In this embodiment, within the degradation and recovery window of degradation levels G0 to G3, the master station or microgrid aggregator performs power reallocation under the premise of meeting hard safety constraints. Hard constraints include at least voltage / frequency boundaries, capacity package P / Q boundaries and ramp limits, energy storage SOC upper and lower limits, line / transformer capacity, reclosing window and synchronization permit conditions, and communication level gating. After meeting the hard constraints, objectives such as reducing energy curtailment, reducing energy storage overflow, reducing ineffective regulation energy, and reducing network losses can be introduced into the objective function. The output includes a reallocation command containing active / reactive power reallocation amounts, ramp limits, priorities, and validity periods. After receiving the reallocation command, the microgrid controller feeds back the constraint information to the local controller for anti-integral saturation and rate limiting, ensuring that the coordinated control effect of "safety first, while also considering energy saving and consumption reduction" can still be achieved under communication and safety boundary constraints.
[0072] The above embodiments illustrate the implementation of the present invention, but the present invention is not limited to the above embodiments. For those skilled in the art, any equivalent substitutions or combinations made to the communication level classification threshold, state machine switching conditions, weak network index composition, degradation level definition, capability packet fields, and replay scoring index system without departing from the concept of the present invention should be considered as falling within the protection scope of the present invention.
Claims
1. A method for coordinated stability control of microgrid distribution networks, characterized in that, The method includes: S1. Obtain communication quality parameters such as latency, packet loss rate, jitter and / or continuous interruption duration of the communication link between the master station and the microgrid controller. Normalize and weight the communication quality parameters to obtain the communication quality index Q_comm, and map Q_comm to communication levels C0 to C3, so as to serve as the gating basis for receiving and executing cooperative control commands, switching cooperative state machines and / or selecting recovery strategies. S2. The master station encapsulates the collaborative control command into a structured command message containing command identifier, event identifier, timestamp, validity period, retention time, priority, strategy / parameter version information, and signature / verification information. The microgrid controller performs communication level permission verification, validity period verification, version consistency verification, and signature / verification verification on the structured command message. If the verification passes, it enters the execution link. If the verification fails, it enters the hold-freeze or rollback local autonomous control and records the reason code. S3. Establish a collaborative control state machine on the microgrid controller side. The collaborative control state machine includes at least a normal collaborative state, an event-enhanced state, a frozen state, a rollback local autonomous state, and a resynchronization recovery state. It switches between states based on changes in communication level, command verification results, and / or event triggering. In the frozen state, only boundary constraint commands are allowed and rapid changes in setpoints are suppressed. Furthermore, command validity period and version consistency constraints, setpoint change rate limits, and output hold / integral anti-saturation suppression commands are used to catch up during the frozen period. S4. Based on the equivalent short-circuit ratio, equivalent impedance characteristics, frequency change rate and / or voltage frequency disturbance response, construct weak network indicators and output weak network classification levels L0 to L3. At the same time, calculate the weak network identification confidence level mc. When mc is lower than the preset threshold, freeze the weak network classification level and the corresponding control parameter shaping set. When the level is allowed to be changed, the parameter shaping set is interpolated and smoothly switched according to the preset smoothing time to reduce the risk of oscillation caused by misjudgment and frequent level jumping. S5. When events such as undervoltage, overcurrent, frequency over-limit, protection action and / or switch quantity change are detected, the inverter current limiting and fault ride-through control is executed and the graded degradation level G0 to G3 is entered. The recovery path is selected in combination with the reclosing window and the synchronous grid connection permission conditions. When the synchronization conditions are met, the resynchronization recovery state is entered and the recovery is carried out in an orderly manner according to the preset smooth time. The circulating current and secondary over-limit are suppressed and constrained in the recovery process. S6. The microgrid controller or its aggregator periodically sends out capability packages. The capability packages include at least active / reactive power availability boundaries, ramping constraints, set of permissible control modes, stability level / risk indication and / or islanding / networking capability information. The master station forms a set of control commands that can be sent out based on the capability packages and generates coordinated control commands within the set of control commands to avoid over-capacity commands. S7. When events such as exceeding limits, protection actions, switch changes, communication level changes, weak network level changes, and / or downgrade level changes are detected, an evidence chain package is generated. The evidence chain package includes at least the triggering condition, snapshot window, instruction sequence and parameter sequence, communication level, reason code, version information, and signature / verification information. After performing multi-source time alignment and cross-consistency verification on the evidence chain package and passing the trusted gating, a trusted evidence chain package is formed. The trusted evidence chain package is replayed and reproduced, and a replay consistency score is output. Based on the replay consistency score, the strategy parameters, thresholds, and / or adjustment sets are solidified into the database or rolled back for management.
2. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, The communication quality index Q_comm is obtained by weighting latency score, packet loss score, jitter score, and continuous interruption duration score. The communication levels C0 to C3 include at least the following: C0 indicates excellent communication, allowing regular coordination and optimization; C1 indicates good communication, allowing regular coordination and optimization but limiting the sending frequency; C2 indicates poor communication, entering a frozen state and only allowing low-frequency boundary constraint commands; and C3 indicates communication interruption or unavailability, triggering a rollback to local autonomous control.
3. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, The validity period of the structured instruction message is used to limit the time window in which the instruction can be executed. The microgrid controller deduplicates and discards out-of-order, duplicate, or expired structured instruction messages, and writes the reason for the discard into the event log and evidence chain package in the form of a reason code.
4. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, The state transitions of the cooperative control state machine satisfy at least one of the following rules: When the communication level drops to C2 or version consistency verification fails, it enters a frozen state; when the communication level drops to C3 or validity period verification fails / signature verification fails, it enters a rollback to local autonomy state. When the communication level is restored and the preset retention time is met and the command is verified, it enters the resynchronization recovery state. In the resynchronization recovery state, the set values and key parameters are gradually integrated according to the preset smoothing time before returning to the normal collaborative state.
5. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, The weak network identification confidence level mc is calculated from the identification residual, measurement inconsistency and / or fitting quality. When mc is lower than the threshold, the upshift or downshift action is frozen, and shifting is only allowed after mc recovers and continues to meet the preset holding time. The parameter shaping set includes at least one or more of the following: phase-locked loop bandwidth, virtual impedance parameter, damping parameter, power variation limit, and / or grid-connected / grid-following control mode priority strategy.
6. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, The graded degradation levels G0 to G3 correspond to different sets of current limiting and stability support strategies. As the severity of the event increases, the degradation level gradually restricts active power output, increases the priority of voltage / frequency support, and / or enters more stringent safety boundary control. During the degradation level maintenance period, the rate of change of the cooperative setpoint is limited.
7. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, Within the reclosing window, it is determined whether the synchronization conditions are met. The synchronization conditions include at least one or more of the frequency difference threshold, voltage difference threshold, and phase angle difference threshold. If the synchronization conditions are not met, maintain a higher downgrade level and extend the recovery holding time. When the synchronization conditions are met, enter the resynchronization recovery state and perform orderly recovery according to the preset smoothing time.
8. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, The capability package also includes reclosing blocking flags and / or grid connection permission constraint information. The master station calculates the intersection or union boundary of multiple microgrid capability packages to form a control set that can be issued. Different issuance gating strategies are adopted for emergency boundary type commands and recovery optimization type commands. Emergency boundary type commands are allowed to be issued when the communication level is C2, while recovery optimization type commands are only issued when the communication level is C0 or C1 and the versions are consistent.
9. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, When generating a trusted chain of evidence, the multi-source time alignment includes alignment based on unified time synchronization or alignment based on event anchors, and the cross-consistency verification includes at least command-response consistency, protection / switch event consistency, and physical boundary rationality verification. Furthermore, a hash digest is generated for the trusted evidence chain packet that has passed the trusted gating and a signature / verification information is attached for storage using an append-only method, thereby achieving tamper-proof auditing.
10. The microgrid distribution network coordinated stability control method according to claim 1, characterized in that, The evidence chain package and / or trusted evidence chain package further include a waste energy vector (WasteEnergyVector) and an energy consistency verification result (T_energy). The waste energy vector includes at least the energy of energy curtailment / limited generation, energy of energy storage overflow, network loss estimation, energy of ineffective regulation caused by command catch-up, and / or energy storage cycle cost. Furthermore, within the degradation and recovery window of degradation levels G0 to G3, power redistribution is performed without exceeding the hard constraints of voltage / frequency boundaries, capacity package boundaries and ramp limits, upper and lower limits of energy storage state of charge (SOC), line / transformer capacity, and communication level gating. The output includes redistribution instructions containing active / reactive redistribution amounts, ramp limits, priorities, and validity periods, and the constraint information is fed back to the local controller to suppress integral saturation and instruction catch-up.