Intelligent operation management method for primary and secondary fusion ring main unit
By generating runtime contexts, determining data availability levels, and verifying status, the safety verification problem of remote control sequences in primary and secondary integrated ring network boxes is solved, improving the safe and stable operation of the distribution network and the effect of rapid power restoration.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TIANMEI ELECTRIC CO LTD
- Filing Date
- 2026-01-20
- Publication Date
- 2026-05-01
AI Technical Summary
The existing intelligent operation and management methods for integrated primary and secondary ring network boxes lack a safety verification mechanism for remote control sequences. This leads to control suggestions becoming unexecutable or erroneous in the event of communication jitter, state variable conflicts, and data loss, affecting the safe and stable operation of the distribution network and the effectiveness of rapid power restoration.
By receiving service triggers to generate an operational context, determining the data availability level based on freshness, missing data, and conflict rules, setting the decision conservatism level and segmentation granularity, performing isolation and interlocking checks, protection coordination and operation sequence checks, transfer load boundary and reliability checks, receipt and timing alignment checks, arranging remote control sequences and configuring segment preconditions, and ensuring the verifiability and security of the verification status.
It improves the operational safety and rapid power restoration stability of the distribution network, reduces the probability of misoperation, realizes verifiable safety verification and executability of remote control suggestions, and ensures the safe and stable operation of the power supply network.
Smart Images

Figure CN121966017A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power supply and operation control technology for power distribution networks, specifically to an intelligent operation management method for a primary and secondary integrated ring network box. Background Technology
[0002] As a crucial node in medium-voltage distribution networks, ring main units have increasingly adopted a primary and secondary integrated approach in recent years. This approach combines primary switchgear, sensors, secondary monitoring and control protection terminals, and communication and edge processing units to achieve operational management functions such as status monitoring, fault alarms, remote control, and power restoration. Existing operational management platforms typically generate control suggestions for fault handling or power restoration based on monitoring results and alarm status. These suggestions then form remote control sequences to guide or execute switch opening and closing operations, achieving fault isolation and power restoration. Some existing authorized patents focus on online monitoring and defect early warning for ring main units or switchgear. For example, the published invention patent application CN105425129B discloses a portable device for online partial discharge monitoring of high-voltage switchgear. It is applicable to online partial discharge monitoring of high-voltage switchgear and ring main units and can realize insulation status monitoring and alarm information output. However, it is mainly used for monitoring and identification and does not verify the network security constraints of power supply and distribution networks in the process of generating control suggestions and issuing remote control sequences. It also lacks the ability to integrate primary isolation and interlocking states, protection coordination and operation sequence, and load boundaries of transfer paths. The mechanism of linking remote signaling receipts with event timing for verification has serious flaws. In addition, there are authorized patents for the implementation of remote operation and protection devices for distribution cabinets. For example, the published invention patent application CN106602438B discloses a distribution cabinet protection device with remote control function, which can realize the monitoring and remote control of the cabinet status. However, the control logic is limited to the remote control and local protection of a single cabinet or a single device. It does not propose a feasible remote control sequence safety verification framework for ring network power supply scenarios, and cannot provide verifiable conclusions and degradation strategies for the feasibility and safety when data is missing or the status is inconsistent. Therefore, in the existing intelligent operation and management of integrated primary and secondary ring network enclosures, there are still technical problems such as the inability of existing integrated primary and secondary ring network enclosure control suggestions to generate fault handling or power transfer restoration based on monitoring data and alarm information. Furthermore, the generation and distribution of remote control sequences lack verifiable verification for network security constraints in the power supply and distribution network. These security constraints include at least verification of the actual isolation and interlocking states of primary equipment, verification of the coordination between protection settings and operation sequences, verification of load boundaries and power supply reliability constraints of power transfer paths, and verification of the alignment between remote signaling receipts and event timing. Due to the lack of these verification mechanisms, in the event of communication jitter, state quantity conflicts, and data loss, control suggestions may become unexecutable or lead to maloperation risks. Fault isolation and power restoration cannot simultaneously meet the requirements of safety and timeliness, ultimately resulting in poor safe and stable operation of the distribution network and poor rapid power restoration performance. Summary of the Invention
[0003] To address the shortcomings of existing technologies, this invention provides an intelligent operation and management method for primary and secondary integrated ring network boxes, which solves the problems of poor safe and stable operation of distribution networks and poor rapid power restoration in traditional methods.
[0004] To achieve the above objectives, the present invention provides the following technical solution: A method for intelligent operation and management of integrated primary and secondary ring main units includes: S1: Receive service triggers, read topology version and policy version, aggregate remote signaling, telemetry, event receipts and alarms within a preset time window, and generate a runtime context; S2: Determine the data usability level based on freshness, missing data, and conflict rules, and set the decision-making conservatism level and segmentation granularity; S3: Sequentially perform isolation and interlocking verification, protection coordination and operation sequence verification, transfer load boundary and reliability verification, and receipt and timing alignment verification; S4: Arrange remote control sequences based on the verification status, configure segment preconditions, confirmation points and rollback actions, and send them out segment by segment after authorization verification; S5: Monitor and confirm the execution process of each segment. When timeout, conflict increment, boundary crossing, lockout anomaly or protection action is triggered, enter the anomaly handling and rollback or termination, and archive the execution trajectory.
[0005] Furthermore, upon receiving service triggers, the topology and policy versions are read, and within a preset time window, remote signaling, telemetry, event receipts, and alarms are aggregated to generate a runtime context, including: Trigger the generation of a business number; Freeze the topology version and policy version freeze window, and update the context number of the hit rebuild entry; Set up sampling time windows and event time windows to collect and normalize evidence, and record collection timestamps, reception timestamps, quality codes and time synchronization markers; The template hierarchy generates missing and conflicting entries, writes them into the operation scope and prohibited operation list, and outputs context snapshots and entry tags.
[0006] Furthermore, data usability levels are determined based on freshness, missing data, and conflict rules, including: Read the policy version's determination parameters and generate a parameter snapshot; Load key points and layer them according to device type template; Freshness is generated based on the acquisition time difference threshold and the reception delay fluctuation limit, and missing entries and alternative source candidate lists are generated based on the continuous missing threshold. Conflict entries are generated based on the event-aligned tolerance window and conflict stability count, and their interpretability is marked. Data availability level and risk level are written into the data.
[0007] Furthermore, the decision-making conservatism level and segmentation granularity are set, including: The decision-making conservatism level, segmentation granularity, confirmation point stabilization period, and receipt waiting limit are determined based on the data availability level, risk level, and business type, and written into the runtime context. Based on the location stratification and conflict interpretability, determine the permission marks for automatic closing, automatic opening, and power transfer closing, and generate a list of items requiring manual confirmation, a list of items that must be supplemented, a list of recommended degraded actions, a set of permitted operations, and generate the next step entry mark.
[0008] Furthermore, the following checks are performed sequentially: isolation and interlocking verification, protection coordination and operation sequence verification, load transfer boundary and reliability verification, and receipt and timing alignment verification, including: Prune candidate operations and candidate paths and record the reason code and hit entry key; The verification is conducted according to the necessary and prohibited conditions for isolation and locking, the rules index for protection coordination and operation sequence, the conservative boundary and reliability of the transfer path, and the rules for receipt and time sequence alignment evidence. Converge and verify the overall state, and fill in the constraint list to determine the sequence skeleton key, preferred path identifier, confirmation point type, and rollback trigger condition.
[0009] Furthermore, the overall state is converged and verified, and the constraint list is filled in to determine the sequence skeleton key, preferred path identifier, confirmation point type, and rollback trigger condition, including: Generate a list of constraints, preferred path identifiers, confirmation point types, and rollback trigger conditions; The constraint list is output in the form of entries: the reason code for failure, the additional conditions for passing the condition, and the key of the entry that was hit. The sequential skeleton key serves as the index key for segment sequence generation, the preferred path identifier serves as the transfer range limitation key, and the confirmation point type and rollback trigger condition serve as the configuration key for segment-level monitoring and judgment criteria.
[0010] Furthermore, the remote control sequence is arranged based on the verification status, including: Generate a remote control plan package based on the overall verification status, constraint list, recommended order skeleton reference key, and preferred path identifier; Add parameters such as snapshot reference key to the plan package to determine the alignment tolerance window, the upper limit of the receipt wait, and the segmentation granularity; Configure the allowed operation set pruning plan package command, and record the filter reason code, hit entry key, and evidence summary key.
[0011] Furthermore, the configuration segment's preconditions, confirmation points, and rollback actions are distributed segment by segment after authorization verification, including: Generate a list of segments and commands within segments based on the maximum number of commands and command types specified in the segment template, and compatibility constraints. For each segment, a segment precondition table is generated, which is linked to the confirmation status of the previous segment, additional constraint entries, and execution-period dynamic conditions. Set confirmation points and rollback trigger conditions. Confirmation points are combined according to evidence type and are subject to alignment tolerance window and stability period constraints. After completing global authorization verification and segment-level authorization verification, the status is issued segment by segment.
[0012] Furthermore, the execution process of each segment is monitored and confirmed, including: Define the acknowledgment wait limit, event alignment tolerance window, and confirmation point stabilization period based on the plan package and parameter snapshot; The segment evidence buffer is used for state transitions based on a segment state machine. Consistency determination is performed on evidence from multiple sources based on the definition of confirmation points, and confirmation records are obtained. Once the confirmation records meet the conditions, the next step of precondition verification is performed.
[0013] Furthermore, when timeouts, conflict increments, boundary violations, locking anomalies, or protection actions are triggered, exception handling is initiated and the process rolls back or terminates, and the execution trajectory is archived, including: When a timeout, conflict increment, boundary violation, lockout anomaly, or protection action occurs, the system will suspend supplementary sampling, rollback, or terminate the process based on the anomaly dictionary and priority, combined with the conservatism level. The process includes confirming the rollback action, creating a temporary prohibited operation list, and imposing constraints on subsequent segments. When a business transaction is completed, an archived record package is generated, which records segment-level evidence and reason codes.
[0014] Compared with existing technologies, this invention provides an intelligent operation and management method for primary and secondary integrated ring network boxes, which has the following beneficial effects: 1. This invention, by freezing the topology version and strategy version after a service trigger, as well as the runtime context snapshots of sampling time windows and event time windows, aggregates remote signaling, telemetry, receipts, and alarms under a semantic and temporal standard. Based on freshness, missing, and conflict rules, it hierarchically classifies points to obtain reproducible judgment criteria such as availability level, risk level, conservative adjudication level, and segmented granularity. Then, it verifies and converges the isolation interlocking, protection coordination and operation sequence, transfer path load boundary and reliability, and receipt and timing alignment items into a constraint list in a fixed order. Based on the constraint list, it arranges and distributes plan packages segment by segment, binding segment preconditions, multi-source confirmation points, rollback trigger conditions, and temporary disabling update rules. During the execution phase, it monitors and confirms based on the freeze threshold and handles abnormal branches. Finally, it solidifies and archives segment-level evidence, cause codes, and execution trajectories. This solves problems such as the lack of verifiable security constraints in remote control suggestion generation and distribution, communication jitter, and the difficulty in balancing executability and security under missing and conflicting conditions, thereby improving the operational safety and rapid power restoration stability of the distribution network.
[0015] 2. This invention transforms the ring main unit's operation control from experience-based alarm linkage to rule-based closed-loop control. It establishes entry keys and reason codes for candidate operations, power transfer paths, and remote control links, along with combined constraints for permitted operation boundaries, prohibited operation lists, and authorized validity period verification. The entry conditions, rejection reasons, and alternative suggestions for each action are recordable and traceable. By employing segmented execution and segment-level confirmation, it incorporates multi-source evidence such as location changes, event receipts, and electrical parameter boundaries into consistency judgments. Combined with anomaly priority and tiered handling rules, it forms a pause, downgrade, and rollback handling path, thereby reducing the probability of erroneous closing and power transfer, and improving the controllability and traceability of the power restoration process under complex operating conditions. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of the intelligent operation and management method for a primary and secondary integrated ring network box according to the present invention. Detailed Implementation
[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0018] Example 1: Figure 1 A method for intelligent operation and management of integrated primary and secondary ring network enclosures is presented, including: S1: Receive service triggers, read topology and policy versions, aggregate remote signaling, telemetry, event receipts, and alarms within a preset time window, and generate a runtime context. The specific implementation is as follows: When a business is triggered, it enters the intelligent operation management process, generates an operation context snapshot, and subsequent data availability level judgment, security constraint verification, remote control sequence arrangement, and segment execution are limited to the same topology version boundary, the same policy version boundary, and the same evidence time window boundary. All subsequent processing uses the operation context snapshot as the sole input carrier. Service triggers are limited to a set of trigger types directly related to the operation and control of the power supply and distribution network. The set of trigger types is fixed in the policy version by enumeration. Examples of trigger types include feeder undervoltage events, protection action events, fault indication combination alarms, dispatch command triggers, maintenance work order triggers, and preset automatic handling triggers. Upon receiving a trigger, a service number is generated, and the trigger source, trigger time, trigger location, service severity, and trigger credibility are recorded. The service severity is used to characterize the handling priority, and the trigger credibility is used to characterize the reliability of the evidence. The two serve as reference inputs for subsequent conservative level and segmented granularity settings and do not replace each other. The trigger credibility value range is 1 to 5, and the value is based on the reliability and repeatability consistency of the trigger source. For example, when protection action and feeder undervoltage occur simultaneously within the event time window, the value is 5; when there is a single alarm and there are signs of jitter, the value is 2 or 3. The trigger credibility is also output along with the operating context. Upon triggering reception, the currently effective topology version and policy version are locked and written into the runtime context. The locked record includes at least the version number, version effective time, remaining version validity period, and version verification summary. The topology version is used to limit the connectivity between the current isolation boundary and the transfer path. The candidate set generates a basic mapping. The topology version includes at least the port mapping between the ring network box interval and adjacent switch nodes, power supply point mapping, tie point mapping, and critical load mapping. The policy version is used to limit interlocking, interlocking rules, operation sequence rules, load boundary and reliability constraints, authorization conditions, and the default caliber of conflict resolution conservatism and segmentation granularity. The version verification summary uses a fixed set of fields to generate a digest code and writes it into the runtime context. The topology version's digest field set includes the number of nodes, the number of branches, a summary of the critical tie point list, and a summary of the power supply point list. The policy version's digest field set includes a summary of the interlocking rule table, a summary of the operation sequence rules, and a summary of the load boundary rules. The digest code is used in subsequent steps to quickly determine whether the version has changed or the digest is inconsistent, providing a verifiable basis for rebuilding the context. To ensure version and evidence consistency within this business cycle, a freeze window is set for the runtime context. The freeze window does not exceed the remaining validity period of the version and does not exceed the business execution window. An example freeze window is 30 to 300 seconds. The value is based on the fact that rapid isolation and rapid power restoration services usually need to be completed in a short time, and it is necessary to avoid version switching or evidence drift caused by long-term operation. When the freeze window expires or the context reconstruction trigger condition is met, context reconstruction is triggered and a new context number is generated. At the same time, the trigger entry and trigger time are recorded. The context reconstruction trigger condition adopts a fixed set of entries. The set of entries includes at least the following: priority 1 key point status change lasts for more than 2 refresh cycles within the sampling time window; one new key conflict entry is added; the receipt channel status is continuously unavailable for more than one receipt waiting limit; the prohibited operation list is added or removed and involves devices in the candidate set; the remaining validity period of the version is less than the lower limit of the freeze window; and the topology version number or strategy version number changes. The key point status change is based on the normalized status class field, and the change is required to meet the persistence condition to exclude false triggers caused by single back-jump. After version locking, evidence time windows are constructed and data is aggregated. The evidence time window adopts a dual-window structure, consisting of a sampling time window and an event time window, and is written into the runtime context. The sampling time window is used to carry stability evidence of remote signaling and telemetry. An example of the sampling time window is the most recent 10 to 30 seconds, and the value is determined based on covering at least 2 to 5 refresh cycles to support the continuous judgment of jitter, bounce, and missing events. The event time window is used to carry the alignment and verification of receipts and action chain events. An example of the event time window is the most recent 60 to 180 seconds, and the value is determined based on covering the key event chain before and after the trigger, and accommodating communication delays and out-of-order events. The dual-window structure allows subsequent stages to reference the evidence sequences of the sampling window and the event window respectively, and the evidence attribution time window is fixedly recorded to avoid evidence being mixed into different time boundaries and affecting the judgment criteria. Data aggregation is completed by merging data using device identifiers and interval identifiers as alignment keys. Remote signaling, telemetry, event receipts, and alarms are written into the evidence set aggregated by device. Metadata fields are added to each piece of evidence. These metadata fields include at least the collection timestamp, reception timestamp, data source identifier, device identifier, interval identifier, location identifier, location value, unit, quality code, refresh cycle, link status, link delay estimate and fluctuation range, clock offset estimate, and confidence level. The refresh cycle is 1 to 10 seconds, based on the common transmission cycle of power distribution terminals. The quality code uses a fixed dictionary bound to the policy version. Examples of quality codes include valid, suspicious, invalid, expired, and inferred. Inferred codes are used to mark alternative references generated by placeholder rules during the missing data handling stage to distinguish them from actual sampled values. Data freshness is not judged at this stage; only the most recent valid time, refresh cycle, and reception delay fluctuation summary are output to form a freshness summary. Threshold determination is performed in the subsequent data availability level determination stage. Link delay estimation and its fluctuation range are determined by the statistical summary of the received timestamp sequence of the receipt channel, or by the link quality mark sent by the terminal. The number of statistical samples is 10 to 50 times, and the value is determined to cover short-cycle jitter and reduce the impact of single anomalies on the results. Clock offset estimation and its reliability are jointly determined by the terminal's time status mark and the platform alignment consistency summary, and are normalized into three levels of high, medium and low according to the mapping rules and written into the running context. The mapping rules are bound to the policy version to ensure site consistency. When the terminal does not provide an alignment status mark, the platform alignment consistency summary is used as the sole basis, and the reliability is marked as low by default. At the same time, a supplementary sampling prompt or manual confirmation prompt is written for subsequent alignment verification to adopt a more conservative standard. To enable multi-source data to be directly used for power supply and distribution network operation control, field normalization is performed synchronously during data aggregation, and the normalization rules are bound to the policy version. The normalization version number and normalization time are recorded in the operation context. Field normalization is divided into state-type enumeration mapping and numerical-type unit unification. State-type enumeration mapping unifies switch position to open or closed, lockout status to locked or unlocked, local or remote to local or remote, and alarm severity to high, medium, and low levels. Numerical-type unit unification unifies voltage to volts or kilovolts and current to amperes or kiloamperes, and associates the unit rules with the point range, recording the range version number. The normalization mapping table is fixed by table item. The table item fields include at least the original enumeration value, unified enumeration value, applicable point range, mapping effective version number, and mapping update time, which facilitates subsequent verification of the normalization caliber. When the runtime context is generated, a list of key points is established, and missing and conflicting placeholder records are generated accordingly. The statistical caliber of missing and conflicting points is formed based on the evidence sequence within the sampling time window and event time window and written into the placeholder records. The list of key points is fixed by equipment type template and bound to the policy version. Template examples include ring network box bay template, connection point template, and feeder template. Key points are divided into three levels according to the judgment rules: priority 1 are status and interlocking points that directly affect the safety of closing; priority 2 are measurement and auxiliary status points related to load boundary and reliability judgment; priority 3 are non-critical alarm points for risk warning. The missing placeholder record establishes entries for key fields. The entry fields include field name, field priority, missing judgment threshold, current missing count, last valid time, alternative source candidate list, and closing participation flag. The threshold is set for consecutive missing values for 2 to 5 refresh cycles, chosen to avoid misjudgment due to occasional packet loss while also considering real-time performance. The alternative source candidate list is given with a fixed priority, with priority examples including historical valid values from the same source, synonymous point values from different sources, historical summary values, and manually confirmed values. Historical valid values from the same source require a valid record within the sampling time window or the most recent context snapshot, while synonymous point values from different sources require semantic consistency confirmed through a normalized mapping table. Conflict placeholder records are used for conflict classification. Conflict entries must at least cover contradictions between location and action events, contradictions between locking and authorization, contradictions between live display and voltage telemetry, and contradictions between successful receipt and unchanged state. The record includes the conflict source point, conflict occurrence time, event alignment tolerance window reference value, and conflict stability count. The stability count is set for 1 to 5 times, based on the number of repeated contradictions occurring within the event time window. After the evidence set is formed, the operating context is written into the target operation range and the prohibited operation list. The target operation range is trimmed according to the trigger type and the topology version basic mapping to obtain the boundary. The boundary must at least cover the candidate switch and the candidate contact point of the fault section boundary. If necessary, the candidate power supply path of the critical load is added for subsequent transfer selection. When the feeder undervoltage or protection action is triggered, the boundary is preferentially included with the upstream and downstream switches associated with the fault indication. When the dispatch instruction or work order is triggered, the boundary is generated according to the specified range and the policy restricted area constraint is superimposed. The prohibited operation list is generated by the work order status, maintenance mark, policy blacklist and dispatch prohibition mark. The entries must at least include the equipment identifier, prohibition reason code, remaining prohibition validity period and release condition summary. The reason code can be under maintenance, forced block, dispatch prohibition, risk isolation or authorization missing. The release condition summary is used for subsequent manual review or release processing after supplementary collection. The runtime context object is output in a one-time format, and the context snapshot is written as the state to be graded. The data availability level determination process pointed to by the next entry marker is written into the context snapshot. The context snapshot is written into the verification digest. The verification digest should include a complete bitmap of key fields, the number of missing entries, the number of conflicting entries, the freshness summary, the link fluctuation summary, and the clock offset credibility summary as a set of reference fields for subsequent grading stages.
[0019] S2: Determine the data usability level based on freshness, missing data, and conflict rules, and set the conservatism level and segmentation granularity for adjudication. The specific implementation is as follows: After the runtime context snapshot is generated and the version is frozen, the data availability level determination and adjudication parameter setting stage begins. This stage takes the runtime context snapshot as input and inputs the data availability level, risk level, adjudication conservatism level, segmentation granularity, and permission boundary fields in the same context. The entry marker for the next step is then updated to enter the security constraint verification process. At the start of this phase, the decision parameters in the policy version are read and written to the parameter snapshot field. The parameter snapshot is used to identify the freshness, missing data, conflicts, and adjudication criteria for this business cycle. Afterwards, only the snapshot is referenced, and the policy configuration is not read. The parameter snapshot includes at least the data freshness threshold, receive latency fluctuation threshold, missing data threshold, event alignment tolerance window, receipt wait limit, conflict stability count threshold, default value for conflict adjudication conservatism level, default value for segment granularity, confirmation point stability cycle range, and retry count limit. An example of the data freshness threshold is 3 to 15 seconds, determined by the refresh cycle and link jitter. For emergency power restoration or triggering high reliability, 3 to 5 seconds are used; for planned power outages or work order triggers, 10 to 15 seconds are used. An example of the receive latency fluctuation threshold is 100 milliseconds to 1500 milliseconds, determined by the link type and receipt channel statistical summary. The runtime context provides a link fluctuation upper bound field; the decision criterion uses the smaller value between this value and the link fluctuation upper bound. The upper bound of the path fluctuation is generated from the summary of the intervals between the most recent 10 to 50 receipts; the missing threshold example is the refresh cycle of consecutive missing key points, and the value is determined to avoid misjudgment of occasional packet loss and real-time performance; the event alignment tolerance window example is 200 milliseconds to 2000 milliseconds, and the value is determined based on the timing accuracy and link latency fluctuation; when the clock offset confidence is low, it is taken as 1000 milliseconds to 2000 milliseconds, and the conflict resolution conservatism level is increased by one level by default; the upper limit of receipt waiting is 2 seconds to 20 seconds, and the value is determined based on the mechanism action time and link round-trip delay; the conflict stability count threshold example is 2 to 3 times, and the value is determined based on transient and persistent conflicts; the confirmation point stability cycle range example is 2 to 5 refresh cycles, and the value is determined based on jitter and bounce suppression; the upper limit of retry times is 0 to 2 times, and the value is determined based on the business urgency and channel stability, with high conservatism taking 0 or 1 times, medium conservatism taking 1 to 2 times, and low conservatism taking 2 times when the planned switchover and link are stable; Load the list of key points fixed in the strategy version and write it into the point layering results; the list of key points is bound to the strategy version according to the equipment type template, and the template example is ring network box bay, tie point and feeder; the key points should at least cover switch position, interlock status, grounding status, local and remote status, cabinet door status, live display or voltage telemetry, feeder current, receipt channel status, protection action status and setting effective status; the priority is divided into 1 to 3, priority 1 is the status and interlocking type points that directly affect the closing safety, priority 2 is the measurement and auxiliary status type points that affect the transfer boundary and load risk, and priority 3 is the auxiliary judgment and risk warning points; the layering results are written into the context as permission and action boundary constraints, priority 1 missing or continuously stale points prohibit automatic closing, priority 2 missing or continuously stale points prohibit automatic transfer closing but allow isolation opening, priority 3 missing points only increase the risk level. After the data points are stratified, the freshness determination process begins. For each key data point, the collection timestamp, reception timestamp, context generation time, link fluctuation upper limit, and quality code are read, and freshness is determined using a dual-condition approach. If the difference between the collection timestamp and the context generation time exceeds the data freshness threshold, or if the reception delay fluctuation exceeds the current criterion determined by the parameter snapshot, the data point is marked as not fresh and a reason code is written. The reason code uses a fixed dictionary and includes collection expired, reception delay abnormal, link jitter, unreliable time synchronization, and invalid quality code. The not-fresh entry is simultaneously written with the most recent valid time and the number of consecutive not-fresh entries. An example of the consecutive number threshold is a refresh cycle of 2 to 3 times. When the consecutive not-freshness threshold is reached for priority 1 data points, the automatic closing permission flag is set to no and the data is added to the list of items that must be re-collected. When the consecutive not-freshness threshold is reached for priority 2 data points, the transfer closing permission flag is set to no while the isolation tripping permission flag is retained. After the freshness determination is completed, the missing data determination process begins. Missing data determination uses the missing placeholder entry as the entry point, reads the missing count and last time for each point, refreshes the cycle-calculated consecutive missing period count and compares it with the missing threshold. When a priority 1 point is missing, automatic closing is prohibited, and a suggested degraded action list is written. Suggested degraded actions are written to a fixed template, such as only performing isolation tripping, pausing and waiting for supplementary data collection, switching communication channels, or requesting manual confirmation. When a priority 2 point is missing, automatic closing is prohibited, and a list of items requiring manual confirmation is written, while candidate paths are reserved for execution after manual confirmation. When a priority 3 point is missing, a risk warning entry is written. Missing data determination only generates a candidate list of alternative sources, not alternative values. Examples of candidate list items include redundant points on the same equipment, adjacent mutual verification points, or indirect evidence points from event receipts, which will be used as evidence admission criteria and condition pass determination criteria during future verification. After freshness and missing information determination, conflict determination follows. Conflict determination checks the consistency of multi-source evidence for the same object from the conflict placeholder entry entry and writes it into the conflict entry and conflict stability count. Conflict types include at least inconsistencies between switch position and action completion event, inconsistencies between locked state and authorized state, inconsistencies between live display and voltage telemetry, and inconsistencies between successful receipt and status not updated. Conflict checking is limited to the event alignment tolerance window: if the action completion event appears in the tolerance window but the position telemetry is not updated within the confirmation point stability period, it is considered position non-following; the direction of position change and the movement... Opposite actions constitute a directional conflict; if authorization is valid, the interlock remains locked, and the interlock release evidence is satisfied, it constitutes an authorization-interlock conflict; live display and voltage telemetry crossing the upper and lower limits of the voltage threshold set by the strategy version constitute an electrical state conflict. The voltage threshold is configured by the strategy version, and the lower and upper limits are 90% to 110% of the rated voltage in examples; if the receipt is successful but no action starts, action is completed, or position changes within the receipt waiting upper limit, it constitutes a receipt isolation; critical conflicts are written into the context according to a fixed dictionary, including at least electrical state conflicts, authorization-interlock conflicts, directional conflicts, and receipt isolation. After a conflict entry is generated, an interpretable conflict flag is written according to the criteria, and the hit entry number is recorded. Interpretable criteria include at least low clock offset confidence, link fluctuation upper bound greater than parameter snapshot criteria, intermittent unavailability flag in the acknowledgment channel, conflict stability count less than the threshold, and no continuous occurrence within the event time window. Inexplainable criteria include at least high clock offset confidence and critical conflicts still occur when link fluctuation does not exceed the threshold, or conflict stability count greater than or exceeding the threshold and recurring, or conflict inconsistent with changes in authorization status and latching status and cannot be explained by the event alignment tolerance window. When an interpretable criterion is hit, the conflict is marked as interpretable, the default value of the decision conservatism level is increased, and the default value of the segment granularity is decreased. When an inexplainable criterion is hit, the conflict is marked as inexplainable and written into the list of items that must be manually confirmed. After the three types of rules are determined, the data availability level and risk level are written into the context object. The data availability level is divided into high availability, medium availability, low availability, and unavailability by a fixed dictionary. High availability means that all priority 1 points are fresh and there are no missing or critical conflicts. Medium availability means that priority 3 points are not fresh and there are no missing, but priority 1 meets the above conditions. Low availability means that there is an explainable conflict or that priority 2 points are not fresh and there are no missing, and the minimum evidence of isolation and disconnection is retained. Unavailability means that priority 1 key fields are missing or there is an unexplainable key conflict. The risk level is written into the context according to three levels: low, medium, and high. The generated rules are stored in the entry library. There are at least trigger type range, data availability level range, key conflict type range, link fluctuation level range, output risk level, and entry priority. The first rule hit in the priority from high to low is recorded and the entry number is recorded. The risk level is high when there is an electrical state contradiction. After the data availability level and risk level are generated, the adjudication parameter settings are entered and written to the context object. The adjudication parameters consist of the adjudication conservatism level, segment granularity, confirmation point stabilization period, acknowledgment waiting limit, retry count limit, and allowed action boundaries. The adjudication conservatism level is determined based on the data availability level, risk level, and business type. When high availability is required and it is a planned switching operation, it is set to medium conservatism. When high availability is required and it is an emergency power restoration operation with high trigger reliability, it is set to medium conservatism. When low availability is required or the risk level is high, it is set to high conservatism. The action boundaries are defined as isolation tripping or single-step testing. Explore; the values of each parameter are limited to the parameter snapshot range and written to the last value field. High conservatism means 1 command per segment, double evidence confirmation, confirmation point stability period is taken from the high conservatism range, and the number of retries is taken from the low value range; medium conservatism means no more than 2 commands per segment, double evidence confirmation at the end of the segment, confirmation point stability period is taken from the medium conservatism range, and the number of retries is taken from the median range; low conservatism means no more than 3 commands per segment and retains key confirmation points when the planned outage is not in conflict and the link fluctuation meets the threshold; the segment granularity and confirmation point stability period are written into the context as rigid constraints for subsequent sequence arrangement; The executability pre-judgment field generates a context, which includes automatic closing permission flag, automatic opening permission flag, transfer closing permission flag, a list of items requiring manual confirmation, a list of items requiring supplementary data collection, a list of suggested degraded actions, and the maximum set of operations allowed to be executed. The automatic closing permission flag is judged based on a combination of priority 1 points being complete, fresh, free of inexplicable critical conflicts, and valid authorized related points; if these conditions are not met, it is set to negative and a reason code is recorded. The automatic opening permission flag allows isolation opening when some non-critical points are missing, but requires that the remote status be valid, the blocking allow opening, and the prohibition of opening alarm be disabled. The list of items requiring manual confirmation is arranged in fixed entries. Example of entries: missing load estimation basis, unresolved electrical status contradictions, incomplete evidence of interlock release, uncertain authorization of contact points; the list of items that must be supplemented lists the points to be supplemented and the suggested supplementation methods. Examples of supplementation methods are switching to backup channels, extending the sampling time window, or requesting on-site verification; the maximum set of operations allowed to be executed is executed according to hard rules. When the data availability level is low or the risk level is high, only isolation-related tripping and necessary status verification are retained, and contact point closing and branch restoration are excluded; when the data availability level is high or the risk level is not high, contact point closing and branch restoration are included, but priority 1 points must be fresh and missing 0 points and critical conflicts 0 points, and be subject to the prohibited operation list; When this stage ends, the status of the object to be classified is changed to classified, and the classification completion time, classification basis summary identifier and adjudication parameter snapshot summary identifier are written. The next step entry mark is changed to the security constraint verification time. After that, the verification and constraint output can be performed directly based on the classification field and adjudication parameter field.
[0020] S3: Sequentially perform isolation and interlock verification, protection coordination and operation sequence verification, load transfer boundary and reliability verification, and receipt and timing alignment verification. The specific implementation is as follows: After the data availability level is determined and the decision conservatism level, segment granularity, confirmation point stability period, permission mark and other lists are written into the running context, the safety constraint verifiable verification stage begins. Isolation and interlock verification, protection coordination and operation sequence verification, transfer load boundary and reliability verification, and receipt and timing alignment verification are performed in a fixed sequence. The verification conclusions are summarized into a total verification status and constraint list as the sequential arrangement of the remote control sequence and the access and constraint inputs for the stage issuance. At the start, the candidate operation set and candidate transfer path set are read from the runtime context. The maximum operation set and prohibited operation list are pruned to remove devices and actions that are not allowed or are not on the prohibited list. The removal results are written to the runtime context, recording at least the removed object identifier, action type, trigger field, trigger time, removal reason code, hit entry key, and evidence summary reference key. The reason code uses a fixed dictionary based on the policy version, and the entry key is bound to it. When the availability level is unavailable, the set of reason codes for the overall verification status of failure is written, and the existing list of items that must be supplemented and the list of items that must be manually confirmed are referenced as input for subsequent branches. When the data unavailability level is unavailable, isolation and interlock verification are performed. Isolation and interlock verification corresponds to the equipment and action type of the switch to be operated and the contact point switch. The verification input is a snapshot of the operating context, including remote status, cabinet door status, grounding status, interlock status, interlock release evidence satisfaction mark, interlock authorization status, remaining validity period, work order safety measure confirmation status, live display, voltage telemetry, alarm for refusal to operate or prohibition of operation, point freshness and missing mark, equipment risk status mark, and decision conservative level reference value. The verification rules are divided into two levels of items: necessary and prohibited, and the operation is based on the item index to match the item key. For a closing action, the necessary conditions are at least that the remote state is valid and located remotely, the cabinet door is closed, the grounding state is not grounded, the interlocking state is not interlocked or the interlocking release evidence is satisfied, the interlocking authorization is valid, the work order safety measures are confirmed, the live display shows voltage telemetry and falls within the allowable deviation range, and there are no fault interlocking or failure to operate alarms in the event window; the allowable voltage deviation range uses the parameter snapshot field, the contradiction criterion uses the key conflict dictionary entry key, and the alarm reset criterion uses the strategy version alarm reset entry key and the event window access conditions; the prohibition conditions are at least that the grounding is closed, the cabinet door is open, the device is located locally, the interlock cannot be released, or the device hits the prohibited operation list. When the conservatism is high, the electrical state contradiction entry is used as the prohibition condition. If any necessary condition is not met or any prohibition condition is hit, the closing verification is judged as failing, and the unmet entry, prohibition entry, reason code, evidence summary reference key, and hit entry key are recorded for review. For circuit breaker tripping, the verification conditions are: the remote status is valid and there is a remote connection; the interlock allows tripping; and there are no alarms prohibiting tripping within the event time window. When the service trigger is emergency isolation and the policy allows forced tripping, additional verification is required: the superior authorization is valid; the fallback channel is valid; and the number of retries has not exceeded the limit. Whether the tripping action is restricted by the energized state depends on the interlocking policy. If the energized state is a prohibited condition in the interlocking policy, the prohibition condition is adjudicated. The verification results are written into the runtime context to form a device-level verification status table with the device as the granularity. All fields must include at least the device identifier, action type, verification conclusion, satisfied or prohibited items, evidence summary reference key, adjudication conservative level reference value, and hit item key to obtain the convergence reference of the isolation interlocking constraint item set. After isolation and interlock verification, the protection coordination and operation sequence verification proceeds. Based on the protection setting area number, activation / deactivation status, reclosing strategy, standby automatic transfer strategy, and operation sequence rules fixed in the strategy version, rule matching is performed on the candidate operation set, outputting the recommended sequence skeleton, the set of mandatory preceding actions, and the set of prohibited actions. Rule matching is indexed by the rule table, and the index key field should at least include the service type, network structure type, ring network operation mode, contact point type, non-reset protection action flag, setting area number switching requirement flag, and activation / deactivation inconsistency flag. Before verification, the protection action and reset status are checked. If a protection action exists in the event window but there is no reset evidence, the closing and reclosing action is marked as prohibited, and the reason code and hit entry key are recorded. The reset evidence admission criteria are still fixed in the strategy version. The establishment of reset evidence requires protection notification. The alarm recovery event and the self-check normal event must occur sequentially within the event alignment tolerance window and conform to the event window's entry criteria. The event alignment tolerance window introduces a parameter snapshot field to ensure that the criteria are reproducible. Then, the set value area number and the activation / deactivation status are checked. When the connection closing or power transfer switching involves area number adjustment or activation / deactivation switching, the switching action is treated as a necessary prerequisite action and written into the additional condition set. The closing can only proceed after there is evidence of the set value taking effect and evidence of activation / deactivation taking effect. When the business intent conflicts with the sequence rules, the verification fails and an alternative sequence suggestion item is generated. The alternative sequence suggestion is recorded according to a fixed template and must include at least the recommended sequence skeleton, the necessary prerequisite actions, the set of necessary confirmation point types, and the set of prohibited actions. The recommended sequence skeleton reference key and the hit item key are written into the running context and included in the constraint list. Subsequent sequence arrangement will directly call the reference key. After completing the protection coordination and operation sequence verification, the transfer load boundary and reliability verification are performed. Taking the transfer path as the granularity, the availability of each candidate path is determined to form a path-level verification status table. The verification input comes from the strategy version and operating context, and includes at least the load boundary rule entry key, load boundary safety factor, current margin range, voltage allowable deviation range field, critical load constraint entry key, reliability threshold entry key, rated current of path equipment, current effective current measurement value, historical summary caliber reference key, historical summary value, and equipment risk status summary. The load estimation basis adopts a fixed value caliber and reference key, giving priority to the most recent effective current measurement value of the feeder to be restored. If it is missing, the maximum value of the historical summary or the upper quantile summary value is used. The historical summary caliber is fixed in the strategy version. If the load estimation basis is missing, the quality code is questionable, or the critical rated parameters of the path are missing, the path is marked as requiring manual confirmation and removed from the automatic closing range. It is written into the list of items requiring manual confirmation and the reason code and hit entry key are written. Boundary determination adopts a conservative boundary standard. The conservative boundary is based on the weakest equipment in the path, determined by subtracting the current margin from its rated current and combining it with the load boundary safety factor. The safety factor ranges from 1.10 to 1.30, and the current margin ranges from 10% to 30% of the rated current, based on load fluctuations and measurement error margins. The weakest equipment is determined according to the reproducibility rule as the equipment with the smallest rated current in the path. When there are two equipments with the smallest rated current, the equipment with the higher risk status is selected first. If the rated current field is missing, it is handled according to the exit rule that requires manual confirmation. If the expected load exceeds the conservative boundary, the path verification result is recorded as failing and a reason code is written. If the expected load is within the boundary, the voltage constraint and reliability constraint are checked again. If the voltage estimation basis is missing, the path is not directly rejected, but it is recorded as conditionally passing and an additional constraint is written. Additional constraints include setting voltage confirmation point types during subsequent monitoring phases; reliability constraints are executed according to policy version itemized thresholds, with an example of an item being that critical load power supply paths must not pass through high-risk alarm devices or that switchable redundant contact points must be retained after power transfer; if power supply is sufficient but reliability is below the threshold, the path is marked as condition passed and written into the additional constraint list, which may include reference keys for subsequent operation suggestions for limiting duration and restoring normal structure; the path-level verification status table must at least include path identifier, weak device identifier, conservative boundary reference value, load estimation reference key, verification result, failure reason code, condition passed additional constraint set, manual confirmation required flag, hit item key, and preferred path sorting field, and be written into the runtime context as the basis for path selection and confirmation point configuration in subsequent sequence orchestration; After completing the path verification, a receipt and timing alignment verification is performed. The verification target is the command execution link. Input runtime context parameters, snapshots, and link status fields are used, including the event alignment tolerance window, receipt waiting limit, clock offset estimation and confidence level, link delay estimation and fluctuation range, receipt channel availability, and receipts, action start, action completion, position change, and protection actions. Alignment judgment is divided into positive evidence and negative evidence. Positive evidence is a successful receipt, action start, action completion, or position change towards the target with freshness. Negative evidence is a negative receipt, protection action, position reversal, and timestamp anomalies that cannot be explained by clock offset. When there is less than one piece of positive evidence and no contrary evidence within the upper limit of the receipt waiting period, the alignment is considered successful; when there is only a successful receipt and no action evidence, an execution uncertainty entry is written and the reason code and hit entry key are recorded; when the clock offset confidence is low, the relative order of the received timestamps is used to assist alignment and a time-limited flag is written; when execution uncertainty triggers conservative updates and is written to the running context, the segmented granularity converges to one command per segment, the confirmation point stability period takes the upper limit of the parameter snapshot, and the confirmation point type set is updated to prioritize dual evidence confirmation; the output timing alignment availability status and execution uncertainty list are verified and used as the reference for later convergence and constraint list generation. After the four types of verifications are completed, convergence begins and a unified constraint list is generated. Convergence is composed of equipment-level verification results, sequence rule verification results, path-level verification results, and timing alignment verification results. The unified role of the overall verification status is written into the overall verification status field and verification completion time field of the running context. The overall verification status is sorted by fixed priority, with failure taking precedence over success, and conditional success taking precedence over success. Any device with priority 1 fails to close, there is an unexplainable critical conflict, or the protection coordination does not meet the conditions; isolation action is available but the transfer path meets the conditions for success, or additional constraints such as missing voltage confirmation or failure to meet the reliability threshold but temporary recovery is allowed are considered to be conditional success. If there are no failure conditions or additional constraints, success is considered. The constraint list is generated and written to the runtime context during the convergence phase. Fields include at least the set of failure reason codes, the set of conditional pass additional conditions, the maximum set of allowed operations, the set of items requiring manual confirmation, the set of items requiring supplementary sampling, the recommended sequence skeleton reference key, the list of available paths and the preferred path identifier, the set of confirmation point types, the set of rollback trigger conditions, and the set of hit entry keys. The maximum set of allowed operations is formed by shrinking the initial boundary based on device-level failure items, sequence rule prohibited items, path-level failure items, and timing alignment restricted items, while recording the shrinkage reason code and hit entry key. The set of conditional pass additional conditions formalizes constraint items such as voltage confirmation, current boundary confirmation, setting effect confirmation, and regression evidence confirmation, and provides reference keys. The list of available paths and the preferred path identifier limit the transfer candidate range, while the set of confirmation point types and the set of rollback trigger conditions limit the monitoring and confirmation configuration for segmented execution. The verification output can be directly used as constraint input for sequence orchestration and execution monitoring.
[0021] S4: Arrange remote control sequences based on verification status, configure segment preconditions, confirmation points, and rollback actions, and distribute them segment by segment after authorization verification. The specific implementation is as follows: When the safety constraint verification stage outputs a verification status that passes or the conditions pass, after inputting the constraint list, recommended sequence skeleton reference key, preferred path identifier, confirmation point type set, and rollback trigger condition set in the runtime context, the remote control sequence arrangement and segment-by-segment distribution stage begins. In this stage, a remote control sequence plan package is generated based on the above inputs and distributed segment by segment. At least the segment list, segment commands, segment preconditions, confirmation point definitions, and rollback definitions are fixed. The plan number and segment status are input in the runtime context. Upon entering this stage, the final programmable range is first determined. The final programmable range uses the maximum set of executable operations as a hard constraint. Items from the prohibited operation list, the set of items requiring manual confirmation, and the set of items requiring supplementary sampling are removed. The set of commands available in the plan package is also removed, and filter records are generated and written to the runtime context. The filter records must at least contain the command point number, device identifier, removal reason code, key to the constraint item hit, and evidence summary reference key. During auditing or manual review, the reasons for not being included are located. The removal reason code is written to a fixed dictionary and corresponds to the constraint item key. It must at least include: lockout not released, authorization missing, protection not restored, sequence rule prohibited, path to be confirmed, load boundary not met, timing alignment restricted, and prohibited list hit. It must be verifiable and traceable. After the final programmable range is determined, the segmentation parameters are loaded and a segmentation template is selected. The segmentation parameters are derived from the parameter snapshot field of the runtime context and include at least the adjudication conservatism level, segmentation granularity, confirmation point stabilization period, event alignment tolerance window, receipt waiting limit, trigger duration period, lockout authorization remaining validity threshold, and execution window length. The plan package references and freezes this parameter snapshot when entering this stage, and the parameters are not regenerated in this stage. The confirmation point stabilization period is an example of 2 to 5 refresh cycles, with the value determined based on remote signal jitter and bounce suppression; 3 to 5 cycles are preferred for conservative scenarios. The event alignment tolerance window is an example of 200 milliseconds to 2000 milliseconds, with the value determined based on time synchronization accuracy and link latency fluctuations; 1000 to 2000 milliseconds are used when time synchronization reliability is low. The receipt waiting limit is an example of 2 to 20 seconds, with the value determined based on mechanism action time and link round-trip latency. The trigger duration period is an example of 1 to 3 stabilization cycles, with the value determined to avoid accidental triggering due to instantaneous fluctuations and to ensure the accessibility of risk events. Stop loss in time; the threshold for the remaining validity period of the lockout authorization is 60 to 600 seconds, which is based on preventing the authorization from being suspended for a long time and covering the expected execution time of this segment; the execution window length is 30 to 300 seconds, which is based on the need for isolation and power restoration to be completed in a short time to reduce state drift; the strategy version has a pre-set segment template and is bound to the conservative level. The segment template is referenced by the plan package as an entry key. At least the upper limit of the number of commands allowed in the segment, the combination constraints of command types in the segment, the default set of segment preconditions, the default set of confirmation points, the default set of rollback actions, and the default set of rollback trigger conditions are defined; the combination constraints of command types in the segment distinguish between opening, closing, adjustment, and verification waiting, and incompatible combinations are clearly defined by rule entries, so that the segment is simultaneously constrained by the number of commands and the compatibility of command types; if the constraint list hits the execution uncertainty, timing alignment is limited, or the additional constraints related to closing are not met, then a more conservative template is selected according to the template switching rules and the automatic closing segment is disabled until the running context writes a release flag or a manual confirmation flag; The segment type sequence is generated according to the recommended order skeleton, and the segment-level equipment set is assembled within the range of the preferred path identifier. The segment type sequence satisfies the sequential constraints of isolation segment before, adjustment segment in the middle, transfer and closing segment after, and recovery segment at the end. If the condition passes the scenario, the verification segment or waiting segment is inserted with additional constraint entries. According to the operating context, the segment-level equipment set selects fault boundary switches and necessary switch points for isolation segment, assembles setting zone number switching or commissioning / discharging adjustment commands for adjustment segment, assembles connection points and related switches for transfer and closing segment, and assembles non-critical branch recovery commands within the allowed range for recovery segment. When the preferred path identifier is empty, the path needs manual confirmation, or the additional constraints of the path are not met, the automatic transfer and closing segment is not generated, the plan package status is pending confirmation or pending supplementary sampling, and the isolation segment and necessary verification waiting segment are retained to form a conservative executable plan. After the segment type sequence and segment-level device set are determined, segment preconditions and segment precondition tables are generated sequentially. The segment precondition table consists of the previous segment confirmation status, additional constraint entries, and execution-period dynamic conditions. The previous segment confirmation status is a hard constraint, requiring all confirmation points of the previous segment to be met and the confirmation status to be valid. Additional constraint entries reference conditions based on the additional condition set and the sequence rule precondition action set, adding entry reference keys and checkpoints or check event sets. Execution-period dynamic conditions are written with fixed key values, at least meeting the requirements of key point freshness, prohibition operation list not affecting the update of this segment, and lock control authorization remaining validity period covering the future expected execution window of this segment. The segment precondition table fields at least include condition name, threshold or entry reference key, checkpoint or check event set, failure reason code, and failure handling suggestions. Failure handling suggestions are based on a fixed template and at least include pause and wait, request re-sampling, downgrade to isolation only, and termination and manual review. After the precondition table for a segment is fixed, confirmation points are configured for each segment and fixed as a confirmation point definition table. Confirmation points must include at least location stability confirmation and acknowledgment event confirmation. In conservative templates or condition-passing scenarios, one or more of the following can be added as additional constraint entries: voltage confirmation, current boundary confirmation, latch-up status confirmation, setting effect confirmation, or regression evidence confirmation. Confirmation point thresholds are linked to parameter snapshot fields or path-level verification status table fields via reference keys. Voltage confirmation uses the allowable voltage deviation range, for example, 90% to 110% of the rated voltage, based on the allowable voltage quality range. The current boundary confirmation references the conservative boundary field. The conservative boundary is formed by subtracting the current margin from the rated current of the weak path equipment and combining it with the load boundary safety factor. The current margin is 10% to 30% of the rated current, and the safety factor is 1.10 to 1.30. The values are based on the load fluctuation and measurement error margin. The confirmation point definition table writes the evidence source type and distinguishes between remote signaling, telemetry and event receipt. Dual evidence confirmation points require at least two different sources to match and be consistent within the event alignment tolerance window. The location stability confirmation also meets the confirmation point stability period requirement. After the confirmation point is defined, the rollback action is bound, generating a rollback action definition table and a rollback trigger condition definition table. Rollback actions are set according to segment type and command type and bound to segment commands. Rollback actions must be executable and monitorable, and cannot exceed the final programmable range and interlocking strategy entries. The rollback trigger condition definition table must record at least the trigger event type, trigger threshold reference key, trigger duration reference key, action type after triggering, post-trigger prohibition update rule, and temporary prohibition validity period field. The temporary prohibition validity period is, for example, 300 seconds to 1800 seconds, and the value is set to avoid equipment impact caused by short-term repeated attempts. The prohibition update rule is used to add the contact point or related equipment to the temporary prohibition operation list after rollback, recording the reason code and validity period. The execution boundary is immediately converged and traceable. The trigger event type must include at least current overrun, protection action, receipt negation, timeout, interlocking abnormality, and position reverse change, and must match the segment type. Closing segments are given priority for configuring opening rollback, adjustment segments are given priority for configuring restoration of original configuration rollback, and isolation segments are given priority for configuring stop and risk locking or switching alternative isolation points. Load the segment template to generate a segment precondition table, confirmation point definition table, rollback action definition table, and rollback trigger condition definition table. Generate a remote control sequence plan package and field structure. The plan package includes at least the plan number, service number, topology version number, strategy version number, parameter snapshot reference key, constraint list reference key, recommended sequence skeleton reference key, preferred path identifier, execution window, authorization validity period, segment list, segment command list, filter record reference key, and plan package status, along with the corresponding segment precondition table, confirmation point definition table, rollback action definition table, and rollback trigger condition definition table for each segment. The plan number is generated by combining the context number and sequence serial number. The plan package summary includes at least the number of segments, the number of devices involved, the number of closing segments, the number of mandatory confirmation points, and the number of rollback actions, for rapid uploading in bandwidth-constrained scenarios. After the plan package is generated, authorization verification is performed to determine whether it should be issued in segments. Authorization verification is divided into two aspects: global verification and segment-level verification. Global verification at least involves the remaining validity period threshold of the lock authorization, the confirmation status of the work order security measures, the consistency of the prohibited operation list, the consistency between the plan package version number and the effective version number, and the validity of the execution window. The status and lock release are not repeatedly deduced, and the consistency is directly verified by the isolation lock verification conclusion and the hit item key. For plan packages that fail the global verification, the unexecutable reason code and the repair suggestion reference key are filled in. The repair suggestion is a fixed template, which at least involves supplementing key points, reapplying for authorization, rebuilding the context after the lock is released, and retrying after the protection returns to normal. No remote control command is issued. After global authorization verification passes, commands are issued segment by segment. Before issuing a segment, verification is performed according to the segment precondition table. If the conditions are not met, the segment status is paused, and a pause reason code and suggested action reference key are written. If the conditions are met, the command for this segment is issued, and the issuance time, command point number, command sequence number, command type, and confirmation point reference key are recorded. The segment status is in execution, and the monitoring input set for this segment is generated. The monitoring input set for this segment is a set of monitoring points and a set of monitoring events extracted from the confirmation point definition table and the rollback trigger condition definition table. After the confirmation point criteria are met and the confirmation status is valid, the confirmation time and evidence summary reference key are written. The evidence summary must at least include the confirmation point name, evidence source type, evidence timestamp summary, and consistency flag. The next segment is then issued. If a rollback trigger condition is triggered during this period, the segment status is rollback pending execution, and the trigger condition identifier and rollback action reference key are written for subsequent rollback or termination. After this stage of processing, the remote control sequence becomes the deliverable of the plan package. The plan package records the programmable range filtering results, segment template entry keys, segment precondition tables, confirmation point definition tables, rollback action and rollback trigger condition definition tables in the fields. The parameter snapshot references the threshold calibers such as the frozen confirmation point stability period, event alignment tolerance window, and acknowledgment waiting upper limit. The filter records and hit entry keys are associated with the reason codes and constraint entry sources for each removal or shrinkage. The segment status field records the execution status of the segment issuance process, including execution in progress, paused, and rollback pending execution status, which can be reviewed and traced.
[0022] S5: Monitor and confirm the execution process of each segment. When timeout, conflict increment, boundary violation, lockout exception, or protection action is triggered, enter the exception handling and rollback or termination, and archive the execution trajectory. The specific implementation is as follows: After the plan package is issued, the monitoring, confirmation and anomaly handling phase begins. The plan package and segment status are the inputs. The sequence and path are not recalculated. The execution is based on the parameter snapshot reference key, and the thresholds such as the upper limit of the acknowledgment waiting, the event alignment tolerance window and the confirmation point stability period are used. During the execution, the threshold entries are not modified. The boundary of allowed actions and the confirmation requirements are converged only through the conflict resolution conservatism level and the subsequent segment constraint reference key. At the start of this phase, an execution parameter snapshot will be locked and associated with the plan package number. The execution parameter snapshot must include at least the following reference keys: acknowledgment wait upper limit, event alignment tolerance window, confirmation point stabilization period, monitoring period, retry limit, conflict resolution conservatism level, temporary operation prohibition validity period, and rollback trigger threshold. The acknowledgment wait upper limit is 2 to 20 seconds, with values based on the mechanism action time and the upper bound of the link round-trip delay. The event alignment tolerance window is 200 milliseconds to 2000 milliseconds, with values based on time synchronization accuracy and link delay. The upper limit of the dynamic boundary; the example of the confirmation point stability cycle is 2 to 5 refresh cycles, and the value is based on remote signal jitter, bounce and short-term disorder suppression; the example of the monitoring cycle is 1 second to 10 seconds, and the value is based on the refresh cycle of the key point and the link bandwidth; the example of the validity period of the temporary prohibition operation is 300 seconds to 1800 seconds, and the value is based on avoiding short-term repeated attempts to cause impact after abnormal rollback; the temporary prohibition operation list item sets the rollback action blocking flag, which does not block the tripping type rollback action by default, and only blocks it when the local state, cabinet door is open, grounding is abnormal or the blocking strategy prohibits the tripping rollback; Segment execution uses a segment state machine, with state machine entries permanently stored in the policy version and the running context written into the entry key. Each segment is configured with states such as pending monitoring, monitoring, pending confirmation, confirmed, paused, rollback pending execution, rollback monitoring, rollback confirmed, terminated, and completed. It also sets segment-level timers, segment evidence buffer indexes, anomaly counters, and subsequent segment constraint reference keys. Segment types include isolation segments, adjustment segments, closing segments, and recovery segments. Segment types determine mandatory confirmation point items and anomaly handling priorities. Closing segments prioritize handling boundary violations and protection anomalies; isolation segments prioritize handling failure to operate and timeouts; adjustment segments prioritize handling missing setting effects and directional contradictions; and recovery segments prioritize handling load boundary violations and voltage anomalies, achieving differentiated handling criteria. After entering monitoring mode, continuous evidence is collected for this segment and written into the segment's evidence buffer to form a collection summary. The monitored objects are determined by merging the confirmation point definition table and the backoff trigger condition definition table, and must include at least command receipts, action start and finish, position changes, lockout status changes, protection action alarms, and changes in key voltage and current quantities. The monitoring point set is a two-level list. The required point set is the minimum evidence chain for segment confirmation, and the condition point set is for additional confirmation and backoff trigger judgment. Both levels of lists are written into the operating context and segment sequence number with point identifier sets. The collection record includes the collection timestamp, reception timestamp, point identifier, point value, quality code, data source identifier, and link status summary, and is associated with the hit confirmation point identifier and backoff trigger condition identifier. The segment evidence buffer has a window length that is not less than the sum of the upper limit window of the receipt waiting window and the confirmation point stable cycle window length, and reserves at least one monitoring cycle alignment margin. Evidence alignment is performed according to the event alignment tolerance window reference key, generating an alignment summary. The alignment summary includes at least an alignment method marker, an alignment deviation marker, an over-window marker, and an alignment confidence marker. The alignment caliber uses the acquisition timestamp. When the runtime context has low time synchronization confidence or missing clock offset estimation, offset interpretation is not used, and the relative order of received timestamps is no longer used for auxiliary alignment, and the alignment confidence will remain low. When the time synchronization confidence is medium or high, the upper bound of the clock offset estimation can be used to explain the alignment deviation. If the absolute value of the alignment deviation is greater than the sum of the upper bound of the clock offset estimation and the event alignment tolerance window, it is interpretable; otherwise, it is ininterpretable. When an over-window occurs and it is determined to be ininterpretable, an alignment restriction marker is written and the anomaly sensitivity of this segment is increased. Subsequent anomaly branches will prioritize more conservative handling paths, such as changing from waiting for confirmation to pausing re-acquisition or directly rolling back, to avoid false confirmations due to unreliable alignment. After the segment evidence buffer is updated and an aligned summary is generated, it enters the confirmation judgment stage. Segment confirmation is performed according to the confirmation point definition table in the plan package. The confirmation point combination meets the requirements of multi-evidence consistency and confirmation point stability cycle. The dual-evidence confirmation point meets the combination of each evidence source type specified in the plan package. The position stability confirmation judgment determines that the position has reached the target and remains stable within 2 to 5 consecutive refresh cycles, and the quality code is valid or acceptable. The receipt event confirmation judgment determines that the receipt or action in place event and the position change are consistent in the event alignment tolerance window and the receipt channel quality code is not invalid or acceptable. The current boundary confirmation judgment determines that the current does not exceed the conservative boundary reference key and continuously meets the stability cycle. Voltage confirmation determines that the voltage is within the allowable deviation range and the stable cycle is continuously met; Lockout confirmation determines that the lockout state is consistent with the strategy and there are no lockout anomalies within the stable cycle; For each confirmation point, a confirmation record is generated and written into the running context. The confirmation record includes at least the confirmation point name, evidence source type combination, evidence timestamp summary, evidence consistency flag, stability count, confirmation conclusion, and threshold caliber reference key; When all confirmation point combinations are met, the segment status is set to confirmed and the segment completion time and evidence summary are written. The evidence summary includes at least the confirmation record reference key, alignment summary reference key, and segment evidence buffer summary; Proceed to the next segment's precondition table adjudication process; When the confirmation point combination does not meet the upper limit of the receipt waiting period, or when there is a rollback trigger condition during the confirmation period, the exception identification and exception handling branch is entered. Exception identification uses an exception dictionary and priority, both of which are entry key reference strategies written into the runtime context. Exception types include at least timeout, conflict increment, out-of-bounds, locking exception, protection exception, negative receipt, direction contradiction, refusal to act, and alignment unavailable. Concurrent exceptions are adjudicated according to a fixed priority: protection exceptions and locking exceptions take precedence over out-of-bounds, out-of-bounds takes precedence over conflict increment, negative receipt takes precedence over timeout, and alignment unavailable takes precedence over continuing to wait for confirmation. Exception handling results are written into the runtime context for unified recording. Record fields include at least exception type, trigger time, trigger evidence reference key, handling action type, handling result, reason code, subsequent segment constraint update reference key, and temporary prohibition list update reference key. The reason code is a fixed dictionary to support project implementation and audit review. When a timeout occurs because the upper limit of the receipt waiting period has been met but the key confirmation point has not been met, or the command receipt is missing and no action evidence has been collected, the action is to stop the segment advancement. The decision is made between reversal and pause based on the segment type and the definition of the reversal action. The closing segment enters the reversal pending execution stage, and the opening segment enters the reversal stage. When the opening segment is not confirmed, the isolation segment enters the pause stage, the equipment is marked as risk, added to the temporary prohibited operation list and written with the validity period, and the output of the alternative isolation suggestion reference key and the reference key of the item requiring manual confirmation is provided. When a refusal to operate occurs because the timeout is continuous and the position remains unchanged, the action is to stop and generate an alternative isolation suggestion. The equipment is added to the risk disabled list. The list entries record a summary of the release conditions and the reference key of the minimum supplementary collection item list to facilitate subsequent manual review and execution. Conflict increment anomalies are triggered when a prominent conflict item is added during the execution of a segment, or when an interpretable conflict becomes an inexplainable conflict. The handling is to refer to the conflict resolution conservatism level key. High conservatism means direct termination and manual review. Medium conservatism means suspension of supplementary sampling, and the number of commands in subsequent segments converges to 1 per segment, and the confirmation point stability cycle key is increased. Low conservatism means execution can continue, but before the next segment begins, only the lockout consistency review and alignment reliability review of the conflict-related equipment are performed. If the review fails, it will be suspended or terminated. Alignment unavailability anomalies are triggered when the alignment exceeds the window and the alignment reliability remains low, making it impossible to form reliable confirmation. The handling is to suspend supplementary sampling or switch channels, increase the conflict resolution conservatism level key, and prohibit closing actions. Out-of-boundary anomalies are triggered after the closing or transfer section ends. The triggering conditions are that the current exceeds the conservative boundary threshold and meets the stability period, or the voltage exceeds the allowable deviation threshold and meets the stability period. After triggering, the most recent closing is first reversed, and the contact point is added to the temporary prohibited operation list. The out-of-boundary type cause code and boundary threshold reference key are saved. After the out-of-boundary handling is completed, the conservative recovery suggestion set reference key is output. The suggestion set is generated from the recovery section candidate set in the plan package. The allowed recovery set, prohibited recovery set and cause code are fixed to avoid adding new derivation criteria during the out-of-boundary handling process. Interlocking anomaly triggering conditions: The interlocking state does not meet the strategy requirements, the interlocking alarm event or the interlocking release evidence is invalid; Interlocking anomaly triggering conditions: After the interlocking anomaly, the subsequent closing and transfer sections are immediately terminated, the relevant equipment is added to the prohibited operation list, and the safety measure item list reference key is output. The safety measures include at least reapplying for interlocking authorization, confirming the grounding status, confirming the cabinet door status, and confirming the local and remote status; Protection anomaly triggering conditions: Protection action event, protection alarm changes from zero to present or protection failure to reset is detected; Protection anomaly handling conditions are to handle with the highest priority, stop immediately, execute backtracking or stop according to the plan package backtracking definition, write the protection evidence reference key, action time summary and associated equipment set into the handling record, and mark the subsequent section as prohibited from execution; Negative receipt anomaly and directional contradiction anomaly corresponding to clear failure of the receipt and opposite state change direction both stop and enter backtracking judgment; When backtracking is unreachable, the risk state is terminated; After a branch triggers a rollback, all subsequent states are rolled back to pending execution and enter rollback monitoring. The rollback action calls rollback confirmation according to the rollback definition in the plan package. Rollback confirmation uses a confirmation point mechanism, with the rollback target as the confirmation target. After the rollback is completed, the temporary prohibited operation list is updated by the trigger condition definition. By default, contact points that trigger out-of-bounds or repeated rollbacks are added to the temporary prohibited list, and the validity period and condition summary are recorded. Rollback involving tripping actions are not automatically added to the prohibited conditions. Execution is restricted only when safety conditions are insufficient or the blocking strategy explicitly prohibits it, to ensure that the rollback path is reachable and visible. After handling anomalies, the execution status converges, the entry marker is updated, and if rollback confirmation and policy allow continued execution, the entry marker points to the conservative execution path, carrying the updated maximum allowed set of operations reference key and the segment constraint reference key. The conservative execution path is limited to performing only isolation tripping or segment-by-segment single-step probing operations, and mandatory dual-evidence confirmation is enforced. Upon termination, the entry marker points to manual review and carries the termination reason code set and the set of items that must be manually confirmed. When all segments have been confirmed, the entry marker points to the archiving entry point. The entry marker and segment status are written back to solidify the final state of the stage to ensure the traceability of subsequent archiving. Upon completion of the operation, an execution trajectory archive package is generated and permanently saved using the runtime context. The archive package fields should include: operation number, trigger reason, start and end times, topology version number, strategy version number, parameter snapshot reference key, plan package number, segment list, command issuance time for each segment, summary of receipts and event times for each segment, summary of confirmation results for each segment, alignment summary reference key, exception type and reason code, rollback execution status, temporary prohibited operation list update record, final switch status summary, final power supply range summary, load boundary and voltage constraint reference summary, critical load recovery summary, and subsequent recommended actions. The archive granularity... The granularity can be selected as standard or enhanced. Standard granularity saves segment-level summaries and key evidence citation keys, while enhanced granularity adds branch judgment condition snapshots, evidence field value indexes, and key fragment indexes in the evidence buffer. Enhanced granularity triggers use segment-level counting. The same segment and the same anomaly type are triggered once within the same receipt waiting upper limit window. Repeated triggers within the same window are counted by the number of times within the window and the start and end times of the window are recorded. Enhanced granularity is activated when the risk level is high, a protection anomaly occurs, or the anomaly count reaches a preset threshold. The preset threshold is 2 or 3 times, chosen because high-risk and high-fluctuation scenarios require stronger traceability to support review and responsibility determination. Through segmented monitoring and confirmation, abnormal branch handling and archiving, the plan package, under the threshold freezing, has the ability to be verified, rolled back, terminated and audited, and the segment-level evidence, handling reason codes and status are converged and solidified as the basis for manual review and accountability.
[0023] The technical solution of this embodiment firstly receives a fast isolation and power restoration service when a feeder undervoltage alarm or protection action event occurs on the line where the ring network box is located. After receiving the service trigger, the platform generates a service number and records the trigger source, severity, and reliability. It locks the topology version and policy version, writes a verification digest, builds a sampling time window and an event time window within the freeze window, collects remote signaling, telemetry, receipts, and alarms, and completes point normalization and metadata completion, generating a runtime context snapshot. Based on the parameter snapshot, it performs freshness, missing data, and conflict judgment on important points, obtains data availability level and risk level, sets the decision conservatism level and segmentation granularity, generates closing, opening, and power transfer permission tags and a list of supplementary sampling, manual confirmation, and degradation actions, and limits the maximum set of operations allowed to be executed. After meeting the access conditions, The system performs isolation and interlocking checks, protection coordination and sequence checks, load transfer boundary and reliability checks, and acknowledgment timing alignment checks in a fixed sequence, converging to form a constraint list and providing a recommended sequence skeleton and optimal path. Based on the constraint list, a plan package is generated, filtering prohibited or non-compliant commands, binding segment preconditions, dual evidence confirmation points, and rollback actions by segment, and issuing the package after authorization verification. During execution, the system monitors the location, acknowledgments, action events, voltage, current, and protection, and performs alignment. If the stable cycle is met within the waiting limit, the system enters the next stage. When timeouts, conflict increments, boundary violations, interlocking anomalies, or protection failures are triggered, the system suspends supplementary sampling, rollbacks, or terminates the update of the temporary prohibition list according to the conservative level. The system completes the archiving of versions, parameter snapshots, plan packages, segment-level evidence, cause codes, and power supply ranges to obtain an auditable trajectory.
[0024] It should be noted that this invention can be deployed on the device itself to realize embedded applications, or it can run on a PC or other terminal with a user interface, thereby meeting various hardware environments and usage requirements.
[0025] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wireless or wired transmission; wired transmission methods include optical fiber, twisted pair, coaxial cable, etc.; wireless transmission includes infrared, microwave, etc. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center containing one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.
[0026] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0027] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.
[0028] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0029] In addition, the functional modules in the embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0030] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0031] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0032] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for intelligent operation and management of a primary and secondary integrated ring main unit, characterized in that, include: S1: Receive service triggers, read topology version and policy version, aggregate remote signaling, telemetry, event receipts and alarms within a preset time window, and generate a runtime context; S2: Determine the data usability level based on freshness, missing data, and conflict rules, and set the decision-making conservatism level and segmentation granularity; S3: Sequentially perform isolation and interlocking verification, protection coordination and operation sequence verification, transfer load boundary and reliability verification, and receipt and timing alignment verification; S4: Arrange remote control sequences based on the verification status, configure segment preconditions, confirmation points and rollback actions, and send them out segment by segment after authorization verification; S5: Monitor and confirm the execution process of each segment. When timeout, conflict increment, boundary crossing, lockout anomaly or protection action is triggered, enter the anomaly handling and rollback or termination, and archive the execution trajectory.
2. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, Upon receiving a service trigger, the system reads the topology and policy versions, aggregates remote signaling, telemetry, event receipts, and alarms within a preset time window, and generates a runtime context, including: Trigger the generation of a business number; Freeze the topology version and policy version freeze window, and update the context number of the hit rebuild entry; Set up sampling time windows and event time windows to collect and normalize evidence, and record collection timestamps, reception timestamps, quality codes and time synchronization markers; The template hierarchy generates missing and conflicting entries, writes them into the operation scope and prohibited operation list, and outputs context snapshots and entry tags.
3. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, Data usability levels are determined based on freshness, missing data, and conflict rules, including: Read the policy version's determination parameters and generate a parameter snapshot; Load key points and layer them according to device type template; Freshness is generated based on the acquisition time difference threshold and the reception delay fluctuation limit, and missing entries and alternative source candidate lists are generated based on the continuous missing threshold. Conflict entries are generated based on the event-aligned tolerance window and conflict stability count, and their interpretability is marked. Data availability level and risk level are written into the data.
4. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, Set the level of conservatism and the granularity of the ruling, including: The decision-making conservatism level, segmentation granularity, confirmation point stabilization period, and receipt waiting limit are determined based on the data availability level, risk level, and business type, and written into the runtime context. Based on the location stratification and conflict interpretability, determine the permission marks for automatic closing, automatic opening, and power transfer closing, and generate a list of items requiring manual confirmation, a list of items that must be supplemented, a list of recommended degraded actions, a set of permitted operations, and generate the next step entry mark.
5. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, The following checks are performed sequentially: isolation and interlocking verification, protection coordination and operation sequence verification, load transfer boundary and reliability verification, and receipt and timing alignment verification, including: Prune candidate operations and candidate paths and record the reason code and hit entry key; The verification is conducted according to the necessary and prohibited conditions for isolation and locking, the rules index for protection coordination and operation sequence, the conservative boundary and reliability of the transfer path, and the rules for receipt and time sequence alignment evidence. Converge and verify the overall state, and fill in the constraint list to determine the sequence skeleton key, preferred path identifier, confirmation point type, and rollback trigger condition.
6. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 5, characterized in that, Convergence verification of the overall state, filling in the constraint list to determine the sequence skeleton key, preferred path identifier, confirmation point type, and rollback trigger conditions, including: Generate a list of constraints, preferred path identifiers, confirmation point types, and rollback trigger conditions; The constraint list is output in the form of entries: the reason code for failure, the additional conditions for passing the condition, and the key of the entry that was hit. The sequential skeleton key serves as the index key for segment sequence generation, the preferred path identifier serves as the transfer range limitation key, and the confirmation point type and rollback trigger condition serve as the configuration key for segment-level monitoring and judgment criteria.
7. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, Remote control sequences are arranged based on the verification status, including: Generate a remote control plan package based on the overall verification status, constraint list, recommended order skeleton reference key, and preferred path identifier; Add parameters such as snapshot reference key to the plan package to determine the alignment tolerance window, the upper limit of the receipt wait, and the segmentation granularity; Configure the allowed operation set pruning plan package command, and record the filter reason code, hit entry key, and evidence summary key.
8. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, Configure the preconditions, confirmation points, and rollback actions for each segment, and distribute them segment by segment after authorization verification, including: Generate a list of segments and commands within segments based on the maximum number of commands and command types specified in the segment template, and compatibility constraints. For each segment, a segment precondition table is generated, which is linked to the confirmation status of the previous segment, additional constraint entries, and execution-period dynamic conditions. Set confirmation points and rollback trigger conditions. Confirmation points are combined according to evidence type and are subject to alignment tolerance window and stability period constraints. After completing global authorization verification and segment-level authorization verification, the status is issued segment by segment.
9. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, Monitor and confirm the execution process of each segment, including: Define the acknowledgment wait limit, event alignment tolerance window, and confirmation point stabilization period based on the plan package and parameter snapshot; The segment evidence buffer is used for state transitions based on a segment state machine. Consistency determination is performed on evidence from multiple sources based on the definition of confirmation points, and confirmation records are obtained. Once the confirmation records meet the conditions, the next step of precondition verification is performed.
10. The intelligent operation and management method for a primary and secondary integrated ring network box according to claim 1, characterized in that, When a timeout, conflict increment, boundary violation, locking exception, or protection action is triggered, the exception handling process is initiated and either rolled back or terminated, and the execution trajectory is archived, including: When a timeout, conflict increment, boundary violation, lockout anomaly, or protection action occurs, the system will suspend supplementary sampling, rollback, or terminate the process based on the anomaly dictionary and priority, combined with the conservatism level. The process includes confirming the rollback action, creating a temporary prohibited operation list, and imposing constraints on subsequent segments. When a business transaction is completed, an archived record package is generated, which records segment-level evidence and reason codes.
Citation Information
Patent Citations
A portable device for on-line partial discharge monitoring of high-voltage switchgear
CN105425129B
Power distribution cabinet protection device with remote control function
CN106602438B