Modularized redundancy health management system of flexible direct current power transmission system
By using state monitoring and graphical model quantitative evaluation of the modular redundant health management system, the time coupling problem between health management and main power control in flexible DC transmission systems was solved, realizing the real-time control performance of the system and the accuracy of fault feature capture, thereby improving the system's operational safety and equipment maintenance capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUADIAN (DANDONG) OFFSHORE WIND POWER CO LTD
- Filing Date
- 2026-02-05
- Publication Date
- 2026-04-28
AI Technical Summary
In existing flexible DC transmission systems, the status assessment of the health management system and the rapid response process of the main power control system are time-coupled, which affects the real-time control performance of the system and the accuracy of fault characteristic determination, making it difficult to balance the contradiction between power transmission dynamic quality and health management.
A modular redundant health management system is adopted, which realizes real-time evaluation of the main power control system and intelligent triggering of health management tasks through a state monitoring module, a steady-state judgment module, a path analysis module, a graph model construction module, and a risk calculation module. Based on the graph model, the system performs cascade failure risk quantification assessment and optimizes the execution strategy of health management tasks.
Optimizing the execution of health management tasks in both time and space dimensions avoids interference with power grid regulation, improves the real-time control performance and the accuracy of fault feature capture, and enhances the system's operational safety and equipment maintenance capabilities under complex operating conditions.
Smart Images

Figure CN121939495A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of control technology for flexible DC transmission systems, and more specifically, to a modular redundancy health management system for flexible DC transmission systems. Background Technology
[0002] Flexible DC transmission systems, based on modular multilevel converter topologies, are widely used in applications such as offshore wind power grid connection. Their distributed control architecture enhances system reliability and scalability by deploying local controllers in each submodule. To ensure long-term operational safety, existing technologies typically incorporate independent health management systems to monitor submodule status, diagnose faults, and control the switching of redundant modules. This system works in conjunction with the main power control system to maintain transmission stability.
[0003] In existing technologies, the status assessment process of the health management system and the rapid response process of the main power control system to grid commands are inherently coupled in time. The periodic detection or event-triggered diagnosis required for health management may temporarily change the electrical characteristics of the system or occupy control resources, which may interfere with the real-time performance and dynamic performance of power control. At the same time, drastic electrical changes during the power control process may also mask early fault characteristics and affect the accuracy of health status determination. This mutual interference makes it difficult for the system to balance ensuring the dynamic quality of power transmission and performing effective health management, becoming a key defect restricting the operational efficiency of flexible DC transmission systems. Summary of the Invention
[0004] To overcome the aforementioned deficiencies of the prior art, the present invention provides a modular redundancy health management system for a flexible DC transmission system to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: A modular redundancy health management system for a flexible DC transmission system includes: Status monitoring module: monitors the real-time operating status of the main power control system and obtains the health management tasks to be executed by the health management system; Steady-state judgment module: Determines whether the main power control system is in a stable power state based on the real-time operating status; Path Analysis Module: When in a stable power state, analyze the spatial distribution characteristics of each redundant submodule in the flexible DC transmission system and the propagation path of electrical disturbances expected to be caused by the health management task to be performed in the system topology. Graph Model Construction Module: Based on the propagation path and the spatial distribution characteristics of redundant sub-modules, a graph model is constructed to describe the relationship between the electrical connection and disturbance propagation of the system, and the diffusion process of the disturbance caused by the health management task to be performed along the propagation path is simulated in the graph model; Risk calculation module: Calculates the cascading failure risk index corresponding to the health management task to be performed as the degree of disturbance based on the simulated diffusion process; Task Decision Module: Compares the level of disturbance with a preset risk threshold, determines and executes the health management task to be performed.
[0006] Furthermore, monitoring the real-time operating status of the main power control system includes collecting the instantaneous values of AC side active power, DC bus voltage, and current of each bridge arm; Obtaining pending health management tasks from the health management system includes receiving periodic detection tasks or event-triggered diagnostic tasks generated by the health management system based on a preset task list and system operation history.
[0007] Furthermore, determining whether the main power control system is in a stable power state based on real-time operating status includes: Based on the collected AC-side active power, DC bus voltage, and bridge arm current, their fluctuation rates within a set time period are calculated respectively. When the fluctuation rate of AC active power, the fluctuation rate of DC bus voltage, and the fluctuation rate of bridge arm current are all continuously lower than the corresponding set threshold for multiple consecutive time windows, the main power control system is determined to be in a power stable state.
[0008] Furthermore, the analysis of the spatial distribution characteristics of each redundant submodule in the flexible DC transmission system includes determining the positional distribution relationship of each redundant submodule between phase units and within bridge arms.
[0009] Furthermore, the analysis of the propagation path of electrical disturbances expected to be generated by the health management task to be performed in the system topology includes determining the electrical nodes into which the disturbances are injected based on the type of health management task, and determining the direction and range of the path that the disturbances may spread from the injection node along the electrical connections based on the topological connection relationship and impedance network of the system.
[0010] Furthermore, based on the propagation path and the spatial distribution characteristics of redundant submodules, a graphical model describing the relationship between electrical connections and disturbance propagation in the system is constructed, including: The key electrical nodes in the system topology and the locations of each redundant submodule are defined together as nodes in the graph model, and directed edges are established based on the topological connection relationship between nodes and the direction of the propagation path. The weights of the directed edges are determined based on the electrical coupling strength between nodes, and the nodes of the corresponding redundant sub-modules are marked as interception nodes with preset interception efficiency attributes.
[0011] Furthermore, simulating the diffusion process of disturbances caused by the health management task to be performed along the propagation path in the graph model includes: The disturbance state is activated with the electrical node injected by the disturbance as the initial source, and the propagation of the disturbance state along the directed edge to the adjacent node is simulated according to the weight of the directed edge. When a disturbance state is transmitted to a marked interception node, the node determines whether the disturbance state is completely intercepted, partially weakened, or continues to be transmitted to subsequent nodes based on the node's preset interception efficiency, and records the transmission process until the stopping condition is met.
[0012] Furthermore, based on the simulated diffusion process, the cascading failure risk index corresponding to the health management task to be performed is calculated as the degree of perturbation, including: Based on the perturbation state transmission process recorded in the simulation, the proportion of the number of nodes affected by the perturbation state to the total number of nodes in the graph model at the end of the simulation is used as the first factor. The average of the shortest weighted path distances from the electrical node where the disturbance is injected to each affected node is calculated as the second factor; The third factor is obtained by statistically analyzing the proportion of times that the marked interception node successfully intercepted the perturbation state transmission during the simulation out of the total number of transmission attempts. The cascading failure risk index is calculated by substituting the first, second, and third factors into the preset risk index synthesis formula.
[0013] Furthermore, the risk index synthesis formula is configured to perform a weighted product operation on the first factor and the second factor, and then perform an exponential weighted sum operation on the result and the third factor to output the cascading failure risk index.
[0014] Furthermore, the level of disturbance is compared with a preset risk threshold to determine and execute the health management tasks to be performed, including: Compare the calculated cascade failure risk index with the preset risk threshold; When the cascading failure risk index is lower than the preset risk threshold, it is determined that the pending health management task can be executed, and the health management system is controlled to execute the pending health management task. When the cascading failure risk index is not lower than the preset risk threshold, the execution of the pending health management task is postponed or canceled, and the pending health management task is re-included in the pending execution queue.
[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This system uses a steady-state judgment module to perform real-time evaluation and window filtering of the main power control system's operating status. It establishes an intelligent triggering mechanism for the execution of health management tasks in the time dimension. Only when the system is in a stable power state with continuously stable electrical quantities is the subsequent path analysis and risk assessment process allowed to start. This avoids interference with dynamic processes such as rapid power adjustment of the power grid during the execution of health management tasks. This not only ensures the real-time control performance of the transmission system, but also creates a low-noise, high-reliability detection environment for health status assessment, making the capture of early fault characteristics more accurate and resolving the timing conflict between health management and power control.
[0016] 2. This system employs a graph model-based cascading failure risk quantification assessment method. This method enables collaborative analysis and forward-looking prediction of disturbance propagation and redundant resource allocation in the spatial dimension. By constructing a graph model that integrates electrical topology, propagation paths, and redundant resource distribution characteristics, and simulating the dynamic process of disturbance diffusion and redundancy interception within the model, a cascading failure risk index reflecting the potential risks of a task can be calculated. This allows task decisions to no longer rely on experience or fixed cycles, but rather on in-depth simulation and quantitative analysis of the internal coupling relationships of the distributed control system. This enables differentiated and precise control over the execution risks of various health management tasks, significantly improving the system's ability to coordinate operational safety and equipment maintenance needs under complex operating conditions. Attached Figure Description
[0017] Figure 1 This is a schematic diagram of the modular redundancy health management system for a flexible DC transmission system according to the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Example: Figure 1 A schematic diagram of a modular redundancy health management system for a flexible DC transmission system is provided according to the present invention. The modular redundancy health management system for a flexible DC transmission system includes: Status monitoring module: monitors the real-time operating status of the main power control system and obtains the health management tasks to be executed by the health management system; Steady-state judgment module: Determines whether the main power control system is in a stable power state based on the real-time operating status; Path Analysis Module: When in a stable power state, analyze the spatial distribution characteristics of each redundant submodule in the flexible DC transmission system and the propagation path of electrical disturbances expected to be caused by the health management task to be performed in the system topology. Graph Model Construction Module: Based on the propagation path and the spatial distribution characteristics of redundant sub-modules, a graph model is constructed to describe the relationship between the electrical connection and disturbance propagation of the system, and the diffusion process of the disturbance caused by the health management task to be performed along the propagation path is simulated in the graph model; Risk calculation module: Calculates the cascading failure risk index corresponding to the health management task to be performed as the degree of disturbance based on the simulated diffusion process; Task Decision Module: Compares the level of disturbance with a preset risk threshold, determines and executes the health management task to be performed.
[0020] The real-time operating status of the main power control system is monitored, and the health management tasks to be executed by the health management system are obtained. Specifically, this is implemented as follows: The real-time operating status of the main power control system is monitored through sensors and measurement units deployed at key measurement points in the flexible DC transmission system. Voltage and current transformers are installed at the AC-side connection points of the converter station. These transformers synchronously acquire the instantaneous values of the three-phase AC voltage and current at a sampling frequency of 10 kHz. The acquired instantaneous values of the three-phase AC voltage and current are transmitted to the signal processing unit in real time. The signal processing unit performs a Clarke transform on the instantaneous values of the three-phase AC voltage and current, converting them to a two-phase stationary coordinate system, obtaining the voltage and current components in this system. Based on instantaneous power theory, the signal processing unit calculates the instantaneous value of the instantaneous active power on the AC side using these components in the two-phase stationary coordinate system. The instantaneous active power on the AC side is updated and stored in the system's real-time database as a continuous data stream at 1-millisecond intervals. A first DC voltage divider is installed between the positive terminal of the DC bus and ground, and a second DC voltage divider is installed between the negative terminal of the DC bus and ground. The first and second DC voltage dividers synchronously acquire the instantaneous values of the DC bus positive-to-ground voltage and the DC bus negative-to-ground voltage at a sampling frequency of 10 kHz. The instantaneous values of the DC bus positive-to-ground voltage and the DC bus negative-to-ground voltage are subtracted, and the difference is recorded and stored as the instantaneous value of the DC bus voltage. A zero-flux DC current sensor is installed on the line side of the reactor in each bridge arm. The zero-flux DC current sensor directly measures the current flowing through the corresponding bridge arm to obtain the instantaneous value of the current in each bridge arm. All the instantaneous values of AC-side active power, DC bus voltage, and each bridge arm current collected are synchronized and aligned using a unified timestamp, forming a complete data set describing the real-time operating status of the main power control system.
[0021] The acquisition of pending health management tasks from the health management system is accomplished through a standalone health management task scheduler. This scheduler maintains a pre-configured task list. This list is a table pre-configured according to the maintenance procedures and reliability requirements of the flexible DC transmission system. The table records various mandatory health management tasks and their corresponding basic attributes. These basic attributes include the task identifier, task type, default execution cycle, estimated execution time, specific equipment identification required for execution, and characteristics of any detection signals that may be injected during execution. The scheduler also continuously records and stores the system's historical operational data. This data includes the cumulative running time of each submodule, historical fault records for each submodule, and the execution time and result of the most recent similar health management task. The process by which the scheduler generates periodic detection tasks involves reading the default execution cycle for each health management task in the pre-configured task list and querying the timestamp of the most recent successful execution of the health management task from the system's historical operational data. The health management task scheduler calculates the next planned execution time for a health management task by adding the timestamp of the most recent successful execution to the task's default execution cycle. When the system real-time clock reaches the next planned execution time, the scheduler marks the task as pending execution and generates a pending health management task object containing all its basic attributes. The process of generating event-triggered diagnostic tasks is as follows: the scheduler monitors preset event flags and status parameters in the system in real time. Event flags include flags indicating specific types of warning messages in the system log. Status parameters include submodule heatsink temperature parameters. Diagnostic task generation is triggered when an event flag is set or the rate of change of a status parameter exceeds a preset warning threshold. The preset warning threshold is an upper limit for the rate of temperature change, set based on the device thermal characteristics parameters provided by the equipment manufacturer and considering safety margins, for example, a temperature increase of 5 degrees Celsius per minute. Once a trigger condition is detected, the health management task scheduler matches the corresponding diagnostic task from the preset task list based on the triggered event type or abnormal status parameter pattern, and immediately generates a health management task object to be executed, containing all the basic attributes of the diagnostic task. The health management task scheduler places the generated health management task objects corresponding to periodic detection tasks and those corresponding to event-triggered diagnostic tasks in the same task queue. The status monitoring module accesses the health management task scheduler's task queue at a fixed query period of 500 milliseconds. Based on the generation time of each health management task object in the task queue and a preset priority rule, the status monitoring module selects one health management task object to retrieve.The status monitoring module completes the process of acquiring the health management tasks to be executed. The acquired health management task object contains all the information required to execute the health management task.
[0022] Determining whether the main power control system is in a stable power state based on real-time operating status is specifically implemented as follows: Based on the collected instantaneous values of AC-side active power, DC bus voltage, and bridge arm current, their volatility within a set time period is calculated. The set time period is a pre-configured time length parameter used to define the data window range upon which the volatility calculation is based. The set time period must be greater than the time constant of a typical dynamic adjustment process of the main power control system; for example, the set time period can be configured to 60 seconds. The process of calculating the volatility of AC-side active power within the set time period involves: extracting the latest sequence of instantaneous AC-side active power values of the set time period from the real-time database or data stream; identifying the maximum and minimum values from the sequence; and calculating the arithmetic mean of all data in the sequence. The fluctuation rate of AC-side active power is calculated as follows: the difference between the maximum and minimum values of the instantaneous AC-side active power value sequence is divided by the arithmetic mean of the instantaneous AC-side active power value sequence, and then the quotient is multiplied by 100% to obtain a percentage value. This percentage value is the fluctuation rate of AC-side active power within the current set time period. The process for calculating the fluctuation rate of DC bus voltage within the set time period is as follows: the latest DC bus voltage instantaneous value sequence of the set time period is extracted from the stored records. The maximum and minimum values are found from the DC bus voltage instantaneous value sequence. The arithmetic mean of all data in the DC bus voltage instantaneous value sequence is calculated. The fluctuation rate of DC bus voltage is calculated as follows: the difference between the maximum and minimum values of the DC bus voltage instantaneous value sequence is divided by the arithmetic mean of the DC bus voltage instantaneous value sequence, and then the quotient is multiplied by 100% to obtain a percentage value. This percentage value is the fluctuation rate of DC bus voltage within the current set time period. When calculating the fluctuation rate of the arm current within a set time period, the calculation is performed for each arm separately. For each arm, the latest instantaneous value sequence of the arm current with a length of the set time is extracted from the stored records. The maximum and minimum values are found from the instantaneous value sequence of the arm current. The arithmetic mean of all data in the instantaneous value sequence of the arm current is calculated. The fluctuation rate of the arm current is calculated as follows: the difference between the maximum and minimum values of the instantaneous value sequence of the arm current is divided by the arithmetic mean of the instantaneous value sequence of the arm current, and then the quotient is multiplied by 100% to obtain a percentage value. This percentage value is the fluctuation rate of the arm current within the current set time period. If the flexible DC transmission system has N arms, N arm current fluctuation rate values will be obtained. In subsequent judgments, the maximum value among the N arm current fluctuation rate values is used as the representative of the arm current fluctuation rate of the entire system. All volatility calculations are repeated on a fixed calculation cycle, which is shorter than the set duration. For example, the calculation cycle can be set to 10 seconds. This means that every 10 seconds, the volatility of AC active power, DC bus voltage, and the volatility of each bridge arm current are recalculated based on the new data from the past 60 seconds.
[0023] When the fluctuation rates of AC-side active power, DC bus voltage, and bridge arm current are all consistently below their corresponding set thresholds for multiple consecutive time windows, the main power control system is considered to be in a stable power state. The set threshold for AC-side active power fluctuation rate is a predetermined percentage value, determined based on the grid dispatch requirements for active power control accuracy during steady-state operation of the flexible DC transmission system. For example, according to the grid connection agreement, the system should control the deviation of transmitted active power within ±2% of the rated power during steady-state operation; therefore, the set threshold for AC-side active power fluctuation rate can be configured as 2%. The set threshold for DC bus voltage fluctuation rate is also a predetermined percentage value, determined based on the technical specifications for stable DC voltage operation of the flexible DC transmission system. For example, according to the converter station design specifications, the allowable fluctuation range of DC bus voltage during steady-state operation is ±1.5% of the rated voltage; therefore, the set threshold for DC bus voltage fluctuation rate can be configured as 1.5%. The volatility threshold for the arm current is a predetermined percentage value, determined based on the control performance indicators of balanced arm current operation in the modular multilevel converter. For example, according to the control objective, the ripple content of each arm current should be less than 3% of the rated arm current in steady state; therefore, the volatility threshold for the arm current can be configured to 3%. A time window is a concept related to the volatility calculation cycle. The length of a time window equals the time period covered by a complete volatility calculation and update, i.e., equal to the calculation cycle. Multiple consecutive time windows refer to a fixed number of consecutive and uninterrupted calculation cycles. The number of consecutive time windows is a pre-configured integer value; for example, six consecutive time windows can be configured. The judgment process is performed in units of one time window. At the end of each time window, a set of judgments is performed: checking whether the fluctuation rate of the AC-side active power calculated within the current time window is lower than the set threshold for AC-side active power fluctuation; checking whether the fluctuation rate of the DC bus voltage calculated within the current time window is lower than the set threshold for DC bus voltage fluctuation; and checking whether the fluctuation rate of the bridge arm current calculated within the current time window is lower than the set threshold for bridge arm current fluctuation. Only when all three conditions are met simultaneously within the current time window is the current time window considered to satisfy the local power stability condition. The system maintains a state counter to record the number of time windows that continuously satisfy the local power stability condition. The state counter increments by one whenever a time window is determined to satisfy the local power stability condition; if the judgment result for a time window is that the local power stability condition is not met, the state counter is immediately reset to zero.When the state counter value reaches or exceeds the value of multiple consecutive time windows, for example, when the state counter reaches 6, a determination is triggered that the main power control system is in a power stable state. Once the main power control system is determined to be in a power stable state, this determination result will be output as a logic signal to allow subsequent path analysis steps to be initiated. If the determination result of a subsequent time window during the power stable state does not meet the local conditions for power stability, the state counter will be cleared and the determination that the main power control system is in a power stable state will be immediately revoked. Subsequent path analysis steps will also stop until the state counter accumulates again to the value requirement of multiple consecutive time windows. This process of determining whether the main power control system is in a power stable state relies on a rigorous assessment of the persistence and consistency of the fluctuation rate of AC side active power, DC bus voltage, and bridge arm current over multiple time windows. This ensures that health management tasks that may introduce disturbances are only initiated after the system has undergone a sufficiently long period of highly stable electrical operation.
[0024] When the power is in a stable state, the spatial distribution characteristics of each redundant submodule in the flexible DC transmission system and the propagation path of the electrical disturbances expected to be caused by the health management task to be performed in the system topology are analyzed. Specifically, the implementation is as follows: When the main power control system is in a stable power state, the spatial distribution characteristics of each redundant submodule in the flexible DC transmission system are analyzed. The flexible DC transmission system is based on a modular multilevel converter (MMC) topology. This topology consists of multiple phase units, each containing an upper arm and a lower arm. Each arm is composed of multiple power submodules connected in series. Some of these power submodules are configured as online master submodules, while others are configured as redundant submodules in hot standby mode. The process of analyzing the spatial distribution characteristics of each redundant submodule is as follows: The system controller accesses the internally stored converter configuration database. This database records the physical identifier, phase unit number, arm type, and preset role (master or redundant) of each power submodule. Based on the converter configuration database, the system controller extracts a list of all power submodules marked as redundant. For each redundant submodule in the list, the system controller reads its phase unit number and arm type to determine its positional distribution among phase units and within arms. The location distribution relationship specifically refers to which particular phase unit the redundant submodule belongs to, such as the redundant submodule belonging to phase unit A, and its location on the upper arm of that phase unit. Further, the system controller determines the specific electrical location of the redundant submodule within its respective arm based on its series sequence number within that arm; for example, the redundant submodule is located at the position of the first submodule closest to the arm's connection point. By summarizing the location distribution relationships of all redundant submodules, the system controller constructs a characteristic map of the spatial distribution of redundant resources. This characteristic map clarifies the allocation of available redundant capacity in the current system across different phase units and different arm types. Determining the location distribution relationship of each redundant submodule between phase units and within arms is the core result of analyzing spatial distribution characteristics.
[0025] The propagation path of electrical disturbances expected to be generated by the health management task to be performed is analyzed within the system topology. The health management task object contains a task type attribute, indicating the specific technical action category of the health management task, such as a capacitor voltage calibration task or a power device junction temperature monitoring task. Based on the type of health management task, the initial electrical nodes directly applied to or primarily affected by the action effect of the health management task during execution can be determined. An electrical node is an abstract representation of a critical connection point or device port in the electrical topology of the flexible DC transmission system. For example, for a capacitor voltage calibration task targeting a specific submodule in a particular arm, the action involves injecting a small test current into the capacitor of the submodule; therefore, the two ends of the capacitor of this submodule are identified as the injection electrical nodes from which the electrical disturbance caused by the health management task occurs. The system controller maintains a topology connection relationship database describing the complete primary wiring and electrical connection relationships of the flexible DC transmission system. The topology connection relationship database defines the connection relationships between all electrical nodes in a node-edge manner; for example, the topology connection relationship database defines the connection relationships between the DC positive bus nodes and the upper arm inlet nodes of each phase unit. Simultaneously, the system calculates an equivalent impedance network model for small-signal analysis offline based on the topological connections and known parameters of each component. This model reflects the electrical coupling strength of signal propagation between nodes. Determining the direction and range of the possible propagation path of a disturbance from the injection node along the electrical connection is based on circuit analysis using the system's topological connections and impedance network. Starting from the injection electrical node, the system controller sequentially accesses all adjacent nodes reachable directly from the injection electrical node via direct electrical connections, according to the topological connection database. These adjacent nodes constitute the first hop range of disturbance propagation. From each node in the first hop range, the system continues to access the next hop node reachable directly via electrical connections, but the influence of the impedance network must be considered. The impedance network reflects the ease of signal transmission between nodes. The system controller sets an impedance threshold, which serves as a reference for determining whether an electrical connection is the primary propagation path of a disturbance. The impedance threshold is set as a percentage of the typical branch impedance value at the system's rated operating point; for example, the impedance threshold is set to 20% of the system's DC-side equivalent impedance. The system controller only considers connections with equivalent series impedance below an impedance threshold on the path from the current node to the next hop node as the primary direction in which disturbances may propagate. Through this hop-by-hop, impedance-constrained topology access, the system controller outlines the possible propagation paths and ultimate impact boundaries of disturbance energy or signals within the system's electrical network, starting from the injected electrical node. The propagation path direction refers to the directed sequence of paths from the injection point to other parts of the system. The propagation range refers to the set of all electrical nodes that may be affected by the disturbance.
[0026] Based on the propagation path and the spatial distribution characteristics of redundant submodules, a graphical model is constructed to describe the relationship between the electrical connections and disturbance propagation in the system. The propagation process of disturbances caused by the health management task to be performed along the propagation path is simulated within the graphical model. Specifically, the implementation is as follows: A graph model describing the relationship between electrical connections and disturbance propagation in a system is constructed based on the propagation path and the spatial distribution characteristics of redundant submodules. A graph model is a data structure consisting of a set of nodes and a set of edges connecting those nodes. The process of constructing the graph model begins with defining the nodes. Key electrical nodes in the system topology refer to electrical connection points identified in the propagation path analysis and topology connection relationship database that are significant for describing disturbance propagation. The location of each redundant submodule refers to the specific position of each redundant submodule in the electrical topology, obtained by analyzing its spatial distribution characteristics. Defining the key electrical nodes and the locations of each redundant submodule together as nodes in the graph model means creating a node list containing all key electrical nodes and special nodes representing the locations of each redundant submodule, assigning a unique node identifier to each node. Directed edges are established based on the topology connection relationships between nodes and the propagation path direction. The topology connection relationships are derived from the topology connection relationship database. The propagation path direction is derived from the information on the possible propagation paths of disturbances. For any two nodes A and B with a direct electrical connection, if the propagation path direction information indicates that a disturbance can propagate from node A to node B, a directed edge from node A to node B is established in the graph model. The weight of the directed edge is determined based on the electrical coupling strength between the nodes. The electrical coupling strength between nodes is a quantitative indicator reflecting the ease with which electrical energy or signals can be transmitted between two nodes. The determination of the electrical coupling strength is based on the system's equivalent impedance network model. For the directed edge connecting node A and node B, its weight is obtained by calculating the reciprocal of the equivalent impedance from node A to node B. The equivalent impedance is calculated using circuit analysis methods based on circuit topology and component parameters, such as using the node voltage method to calculate the Thevenin equivalent impedance between node A and node B. The calculated reciprocal of the equivalent impedance is normalized so that the weight value is between 0 and 1; a larger weight value indicates a stronger electrical coupling strength. Nodes corresponding to redundant submodules are marked as interception nodes with a preset interception efficiency attribute. The preset interception efficiency attribute is an attribute parameter assigned to a special node representing the location of a redundant submodule. The preset interception efficiency attribute value is a number between 0 and 1, such as 0.9. The preset interception efficiency attribute is determined based on a comprehensive evaluation of the redundant submodule's hardware reliability indicators, historical handover success rate data, and controller response speed. The marking process involves setting a dedicated attribute field for nodes representing redundant submodules in the graph model's node data structure and storing the preset interception efficiency attribute value in that field.
[0027] The simulation uses a graph model to model the propagation of a disturbance caused by a health management task along a propagation path. The simulation begins with initialization. The disturbance state is activated using the electrical node that injected the disturbance as the initial source. This means that the node in the graph model that matches the electrical node that injected the disturbance corresponding to the health management task is set to active. The propagation of the disturbance state along directed edges to adjacent nodes is simulated based on the weights of the directed edges. Adjacent nodes are other nodes directly connected to the current node via a directed edge. The propagation process is an iterative step. In each simulation iteration, all nodes currently in an active state are traversed. For each active node, all directed edges originating from that node are checked. For each directed edge, a random number between 0 and 1 is generated. This random number is compared to the weight of the directed edge. If the random number is less than or equal to the weight of the directed edge, the disturbance is considered successfully propagated through this directed edge, and the state of the adjacent node pointed to by this directed edge is marked as pending activation. If the random number is greater than the weight of the directed edge, the propagation is considered to have failed. After the propagation check of all activated nodes is completed in an iteration, all nodes marked as pending activation are officially changed to the activated state. When a perturbation state is propagated to a marked interceptor node, the perturbation state is completely intercepted, partially weakened, or continues to be propagated to subsequent nodes based on the preset interception efficiency of that interceptor node. In the simulation iteration, when a node marked as an interceptor node is attempted to propagate a perturbation state from other nodes, an interception decision is triggered. A random number between 0 and 1 is generated. This random number is compared with the value of the preset interception efficiency attribute of the interceptor node. If the random number is less than or equal to the value of the preset interception efficiency attribute, the interception is considered successful, the state of the interceptor node remains inactive, and the perturbation state cannot continue to be propagated from this node to its neighboring nodes. If the random number is greater than the value of the preset interception efficiency attribute, the interception is considered to have failed, and the interceptor node is normally activated to the activated state. The propagation process is recorded until the stopping condition is met. During the simulation, the state changes of all nodes and the path of perturbation propagation are recorded after each iteration. The stopping condition is a rule used to terminate the simulation iteration. The stopping condition includes the first case, that is, the number of iterations reaches a preset maximum iteration threshold, such as 50 iterations. The stopping conditions include the second case, where no new nodes are generated in a complete iteration. The stopping conditions also include the third case, where the number of activated nodes reaches a preset percentage threshold of the total number of nodes in the graph model, for example, the number of activated nodes exceeds 80% of the total number of nodes. When the simulation ends due to meeting the stopping conditions, the entire transfer process is fully recorded.
[0028] The maximum number of iterations threshold is set based on the longest possible propagation time of the disturbance in the physical system divided by the actual time step represented by each iteration in the simulation. The time step is determined based on the system's electrical time constant; for example, each iteration represents one microsecond of actual time. The preset proportion threshold is set based on the maximum allowable impact range for safe system operation. This range is determined by the system designer according to protection coordination principles; for example, no more than 80% of nodes should be affected.
[0029] The cascading failure risk index corresponding to the health management task to be performed is calculated as the degree of perturbation based on the simulated diffusion process. The specific implementation is as follows: The calculation process is based on complete data of the perturbation state transmission process recorded by the simulation. This data is stored in a structured form, including the state markers of each graph model node after each simulation iteration, the success or failure records of the perturbation state transmission along the directed edges, and the interception judgment results when the interception node is reached each time.
[0030] Based on the perturbation state propagation process recorded in the simulation, the proportion of the number of nodes affected by the perturbation state at the time of simulation termination to the total number of nodes in the graph model is used as the first factor. Simulation termination refers to the moment when the simulation ends due to the fulfillment of the stopping condition. Nodes affected by the perturbation state refer to all graph model nodes whose node state is marked as active at the time of simulation termination. The method for counting the number of nodes affected by the perturbation state is to retrieve all nodes in the active state from the simulation records and calculate the total number of these nodes. The total number of nodes in the graph model refers to the total number of all nodes included in the node list defined when constructing the graph model. The specific process for calculating the first factor is to divide the statistically obtained number of nodes affected by the perturbation state by the total number of nodes in the graph model; the quotient is a proportion value between 0 and 1, and this proportion value is defined as the first factor.
[0031] The average of the shortest weighted path distances from the perturbation-injected electrical node to each affected node is calculated as a second factor. The perturbation-injected electrical node is set as the initial source at the start of the simulation, and its corresponding node in the graph model is known. Each affected node is an active node obtained from the above statistics. For each affected node, the shortest weighted path distance from the graph model node corresponding to the perturbation-injected electrical node to that affected node needs to be calculated. The weighted path distance is the sum of the weights of all directed edges traversed along the directed edges from the starting node to the target node in the graph model. The shortest weighted path distance is the minimum weighted path distance calculated among all possible paths from the starting node to the target node. The shortest weighted path distance is calculated using Dijkstra's algorithm in graph theory. The input to Dijkstra's algorithm is the topology of the graph model, including all nodes, all directed edges, and the weight of each directed edge. Dijkstra's algorithm outputs the shortest weighted path distance from a given starting node to all other nodes in the graph. The specific computation steps of Dijkstra's algorithm are as follows: First, initialize the distance information. Set the distance value of the starting node to 0, and set the distance values of all other nodes to a very large number, such as 1 multiplied by 10 to the power of 10. Place all nodes into a container called the unprocessed set. Next, enter the main loop. Find the node with the smallest current distance value in the unprocessed set and set it as the current node. For each directed edge emanating from the current node, check if the distance from the current node to the adjacent node pointed to by the directed edge is shorter than the currently recorded distance value of the adjacent node. The new distance value is calculated by adding the weight value of the directed edge to the current node's distance value. If the calculated new distance value is less than the currently recorded distance value of the adjacent node, update the adjacent node's distance value with the new distance value. Finally, mark the current node as processed and remove it from the unprocessed set. The Dijkstra algorithm repeatedly executes the steps in the main loop: finding the node with the smallest current distance value, updating the distance values of adjacent nodes, and removing the current node, until the target node is marked as processed or the unprocessed set becomes empty. At this point, the Dijkstra algorithm terminates. The distance value recorded by the target node after the Dijkstra algorithm terminates is the shortest weighted path distance from the starting node to the target node. For each affected node, the Dijkstra algorithm is executed to obtain the shortest weighted path distance from the graph model node corresponding to the electrical node injected by the disturbance to the affected node. The specific process for calculating the second factor is to first sum the shortest weighted path distances corresponding to all affected nodes, and then divide the sum by the total number of affected nodes to obtain the average of the shortest weighted path distances. This average is defined as the second factor.
[0032] The third factor is derived by statistically analyzing the proportion of successfully intercepted perturbation state transmissions by marked interceptor nodes out of the total number of transmission attempts during the simulation. The simulation recorded the interception decision events triggered each time a perturbation state was transmitted to a marked interceptor node. Each interception decision event contained two key pieces of information: whether the transmission attempt occurred and whether the interception was successful. The total number of transmission attempts refers to the total number of events in the simulation where the perturbation state was transmitted to a marked interceptor node. The number of successful interceptions refers to the number of times the interception decision was successful out of all transmission attempt events. The total number of transmission attempts is calculated by iterating through the simulation records and counting all events involving interceptor nodes. The number of successful interceptions is calculated by iterating through the simulation records and counting the events where the interception decision was successful. The specific process for calculating the third factor is to divide the statistically obtained number of successful interceptions by the total number of transmission attempts; the quotient is a proportion between 0 and 1, and this proportion is defined as the third factor.
[0033] The cascading failure risk index is calculated by substituting the first, second, and third factors into a preset risk index synthesis formula. The preset risk index synthesis formula is a predefined mathematical expression. This formula is configured to perform a weighted product operation on the first and second factors, and then perform an exponentially weighted sum operation on the result with the third factor to output the cascading failure risk index. The specific calculation process consists of two steps. The first step is to perform a weighted product operation. A first weight coefficient is assigned to the first factor. A second weight coefficient is assigned to the second factor. The first and second weight coefficients are pre-set positive real numbers. The specific values of the first and second weight coefficients are determined by the system designers based on their focus on the two risk dimensions of disturbance propagation range and propagation depth; for example, the first weight coefficient can be 0.6, and the second weight coefficient can be 0.4. The weighted product operation is performed by multiplying the first factor by the first weight coefficient to obtain a weighted first factor, multiplying the second factor by the second weight coefficient to obtain a weighted second factor, and then multiplying the weighted first factor and the weighted second factor together to obtain an intermediate product value. The second step is to perform an exponential weighted sum operation. An exponential weight coefficient is assigned to the third factor. This exponential weight coefficient is a pre-defined real number. The exponential weighted sum operation is calculated by multiplying the third factor by the exponential weight coefficient to obtain a product value, which is then used as the power of the exponent. Next, the exponential function of the natural constant e is calculated, and the power of this exponential function is the product value. The natural constant e is a mathematical constant with a value of approximately 2.71828. Finally, the intermediate product value obtained in the first step is multiplied by the exponential function of the natural constant e to obtain the final cascading failure risk index. The entire calculation process can be expressed as: the cascading failure risk index equals the first factor multiplied by the first weight coefficient, then the second factor multiplied by the second weight coefficient, and finally multiplied by the third factor (the natural constant e) raised to the power of the exponential weight coefficient. The cascading failure risk index is obtained through this composite formula.
[0034] The disturbance level is compared with a preset risk threshold to determine and execute the health management task to be performed. The specific implementation is as follows: The process receives the cascading failure risk index output from the risk calculation module, compares the cascading failure risk index with a pre-set benchmark value, and generates explicit control instructions based on the comparison results to operate the actuators of the health management system.
[0035] The calculated cascade failure risk index is compared with a preset risk threshold. The preset risk threshold is a pre-determined value stored in the system configuration file or database. The preset risk threshold is set based on the maximum risk level of disturbances caused by health management tasks that the flexible DC transmission system can tolerate under current operating conditions. The determination of the maximum risk level considers several factors. The first factor is the current grid transmission power level the system is handling. At higher power levels, the system's tolerance for any additional disturbances decreases, therefore the preset risk threshold should be set lower. The second factor is the current health status assessment results of critical equipment in the system. Critical equipment includes insulated-gate bipolar transistors (IGBTs) and DC support capacitors. If the health status assessment results of critical equipment indicate that the equipment's health status is approaching the end of its lifespan or shows signs of early degradation, the preset risk threshold should be set lower to mitigate risk. The third factor is the real-time stability margin of the grid. The real-time stability margin of the grid can be assessed by monitoring grid frequency and voltage deviations. If the grid frequency or voltage deviation is large, it indicates a low grid stability margin, and the preset risk threshold should be lowered accordingly. The specific value of the preset risk threshold is calculated through offline safety analysis. The offline safety analysis and calculation process involves constructing a detailed model of the flexible DC transmission system in a simulation environment. Numerous simulations are run to demonstrate operating conditions under different grid transmission power levels, key equipment health states, and grid stability margin combinations. Different types of health management tasks are simulated under each operating condition, recording the cascading failure risk index generated in each simulation and whether any unsafe conditions occur during the simulation. Statistical analysis of the simulation data identifies the upper limits of the cascading failure risk index that ensure system safety under different operating conditions. These upper limits are stored as preset risk thresholds for the corresponding operating conditions in a lookup table. In online applications, the system matches or interpolates the corresponding preset risk threshold values from the lookup table based on the current grid transmission power level, key equipment health status assessment results, and grid stability margin. The comparison operation mathematically determines whether the specific value of the cascading failure risk index is less than or equal to the specific value of the preset risk threshold.
[0036] When the cascading failure risk index is lower than a preset risk threshold, the execution of the pending health management task is permitted, and the health management system is controlled to execute the task. The logical decision-making process for permitting execution outputs a binary permit signal. Controlling the health management system to execute the pending health management task means sending the permit signal along with the complete pending health management task object to the task executor of the health management system. The task executor of the health management system is an independent software process. After receiving the permit signal and the pending health management task object, the task executor parses the specific operation instructions in the pending health management task object. The specific operation instructions include sending specific test signals to the designated submodule controller, switching measurement channels, or starting a self-diagnostic program. For example, for a capacitor voltage calibration task, the pending health management task object specifies the identifier of the target submodule. Based on the identifier of the target submodule, the task executor sends an instruction to enter calibration mode to the controller of the target submodule through the communication network. After receiving the instruction, the controller of the target submodule controls its internal circuitry to discharge the capacitor through a precision resistor of known resistance. The task executor simultaneously starts a high-speed data acquisition card to acquire the voltage change curve over time during the capacitor discharge process. Based on the acquired voltage curve and the known resistance value, the task executor calculates the actual capacitance value by determining the time constant of the voltage drop. The execution process is performed in real time. Upon completion of the task, the task executor generates an execution result report. This report includes the task's success or failure status, as well as the acquired diagnostic data. The task executor then returns the execution result report to the health management task scheduler to update the system's operational history data.
[0037] When the cascading failure risk index is not lower than a preset risk threshold, the execution of the pending health management task is postponed or canceled, and the task is re-added to the execution queue. The logical decision-making process for postponing or canceling execution outputs a rejection signal along with an action strategy. The action strategy is selected based on preset rules. The preset rule is that if the cascading failure risk index exceeds the preset risk threshold by a small percentage, such as no more than 20%, the action strategy is to postpone execution. If the cascading failure risk index exceeds the preset risk threshold by a large margin, the action strategy is to cancel the current execution. Postponing execution means not immediately executing the pending health management task, but retaining its eligibility for future re-evaluation. Canceling execution means abandoning the current execution attempt. The specific operation of re-adding the pending health management task to the execution queue depends on the action strategy. In the case of postponement, the health management task scheduler modifies the attributes of the pending health management task object, adding a timestamp attribute. The timestamp attribute indicates the earliest time when it can be re-evaluated. The timestamp value is the current system time plus a fixed delay interval, which can be 5 minutes or 1 hour. The health management task scheduler puts the modified pending health management task object back to the tail of the pending task queue. For cancelled tasks, the health management task scheduler marks the pending health management task as cancelled, moves it to a history queue, and generates an alarm log. Re-inclusion in the pending queue ensures the closed loop of task management.
[0038] All calculations involved in the embodiments are dimensionless numerical calculations, and the preset parameters and thresholds in the calculations are set by those skilled in the art according to the actual situation.
[0039] It should be noted that this invention can be deployed on the device itself to realize embedded applications, or it can run on a PC or other terminal with a user interface, thereby meeting various hardware environments and usage requirements.
[0040] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions according to the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wireless or wired transmission; wired transmission methods include optical fiber, twisted pair, coaxial cable, etc.; wireless transmission includes infrared, microwave, etc. Computer-readable storage media can be any available medium that a computer can access or a data storage device such as a server or data center that contains one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.
[0041] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0042] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.
[0043] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0044] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0045] If a function is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0046] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0047] In conclusion, the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A modular redundancy health management system for a flexible DC transmission system, characterized in that, include: Status monitoring module: monitors the real-time operating status of the main power control system and obtains the health management tasks to be executed by the health management system; Steady-state judgment module: Determines whether the main power control system is in a stable power state based on the real-time operating status; Path Analysis Module: When in a stable power state, analyze the spatial distribution characteristics of each redundant submodule in the flexible DC transmission system and the propagation path of electrical disturbances expected to be caused by the health management task to be performed in the system topology. Graph Model Construction Module: Based on the propagation path and the spatial distribution characteristics of redundant sub-modules, a graph model is constructed to describe the relationship between the electrical connection and disturbance propagation of the system, and the diffusion process of the disturbance caused by the health management task to be performed along the propagation path is simulated in the graph model; Risk calculation module: Calculates the cascading failure risk index corresponding to the health management task to be performed as the degree of disturbance based on the simulated diffusion process; Task Decision Module: Compares the level of disturbance with a preset risk threshold, determines and executes the health management task to be performed.
2. The modular redundancy health management system for a flexible DC transmission system according to claim 1, characterized in that, Monitoring the real-time operating status of the main power control system includes collecting the instantaneous values of AC side active power, DC bus voltage, and current of each bridge arm; Obtaining pending health management tasks from the health management system includes receiving periodic detection tasks or event-triggered diagnostic tasks generated by the health management system based on a preset task list and system operation history.
3. The modular redundancy health management system for a flexible DC transmission system according to claim 2, characterized in that, Determining whether the main power control system is in a stable power state based on real-time operating status includes: Based on the collected AC-side active power, DC bus voltage, and bridge arm current, their fluctuation rates within a set time period are calculated respectively. When the fluctuation rate of AC active power, the fluctuation rate of DC bus voltage, and the fluctuation rate of bridge arm current are all continuously lower than the corresponding set threshold for multiple consecutive time windows, the main power control system is determined to be in a power stable state.
4. The modular redundancy health management system for a flexible DC transmission system according to claim 3, characterized in that, Analyzing the spatial distribution characteristics of each redundant submodule in a flexible DC transmission system includes determining the positional distribution relationship of each redundant submodule between phase units and within bridge arms.
5. The modular redundancy health management system for a flexible DC transmission system according to claim 4, characterized in that, Analyzing the propagation path of electrical disturbances expected to be generated by the health management task to be performed in the system topology includes determining the electrical nodes into which the disturbances are injected based on the type of health management task, and determining the direction and range of the path from the injection node along the electrical connection based on the system's topological connection relationship and impedance network.
6. The modular redundancy health management system for a flexible DC transmission system according to claim 5, characterized in that, Based on the propagation path and the spatial distribution characteristics of redundant submodules, a graphical model describing the relationship between electrical connections and disturbance propagation in the system is constructed, including: The key electrical nodes in the system topology and the locations of each redundant submodule are defined together as nodes in the graph model, and directed edges are established based on the topological connection relationship between nodes and the direction of the propagation path. The weights of the directed edges are determined based on the electrical coupling strength between nodes, and the nodes of the corresponding redundant sub-modules are marked as interception nodes with preset interception efficiency attributes.
7. The modular redundancy health management system for a flexible DC transmission system according to claim 6, characterized in that, The process of simulating the diffusion of disturbances caused by the health management task to be performed along the propagation path in the graphical model includes: The disturbance state is activated with the electrical node injected by the disturbance as the initial source, and the propagation of the disturbance state along the directed edge to the adjacent node is simulated according to the weight of the directed edge. When a disturbance state is transmitted to a marked interception node, the node determines whether the disturbance state is completely intercepted, partially weakened, or continues to be transmitted to subsequent nodes based on the node's preset interception efficiency, and records the transmission process until the stopping condition is met.
8. The modular redundancy health management system for a flexible DC transmission system according to claim 7, characterized in that, The cascading failure risk index corresponding to the health management task to be performed is calculated based on the simulated diffusion process as the degree of perturbation, including: Based on the perturbation state transmission process recorded in the simulation, the proportion of the number of nodes affected by the perturbation state to the total number of nodes in the graph model at the end of the simulation is used as the first factor. The average of the shortest weighted path distances from the electrical node where the disturbance is injected to each affected node is calculated as the second factor; The third factor is obtained by statistically analyzing the proportion of times that the marked interception node successfully intercepted the perturbation state transmission during the simulation out of the total number of transmission attempts. The cascading failure risk index is calculated by substituting the first, second, and third factors into the preset risk index synthesis formula.
9. The modular redundancy health management system for a flexible DC transmission system according to claim 8, characterized in that, The risk index synthesis formula is configured to perform a weighted product operation on the first factor and the second factor, and then perform an exponential weighted sum operation on the result with the third factor to output the cascading failure risk index.
10. A modular redundancy health management system for a flexible DC transmission system according to claim 8, characterized in that, The level of disturbance is compared with a preset risk threshold to determine and execute the health management tasks to be performed, including: Compare the calculated cascade failure risk index with the preset risk threshold; When the cascading failure risk index is lower than the preset risk threshold, it is determined that the pending health management task can be executed, and the health management system is controlled to execute the pending health management task. When the cascading failure risk index is not lower than the preset risk threshold, the execution of the pending health management task is postponed or canceled, and the pending health management task is re-included in the pending execution queue.