Electrolytic hydrogen safe operation boundary construction and application method and system based on dynamic feature identification, and electronic equipment
By acquiring measured dynamic response data of electrochemical devices, identifying and embedding high-fidelity safety models, the safety boundary deviation problem of electrolyzers under fluctuating power sources in existing technologies is solved, and precise dynamic safety control of electrochemical devices is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ELECTRIC POWER RES INST OF STATE GRID ZHEJIANG ELECTRIC POWER COMAPNY
- Filing Date
- 2026-04-23
- Publication Date
- 2026-05-22
AI Technical Summary
In existing electrochemical devices such as electrolyzers, physical models built based on idealized conditions are difficult to accurately simulate the internal physical limits during rapid power changes, leading to deviations in the calculation of safe operating boundaries. Furthermore, the lack of a dynamic closed-loop control mechanism makes it difficult to cope with safety risks under fluctuating power sources.
By acquiring measured dynamic response data of the electrochemical device, identifying real dynamic characteristic parameters, embedding them into a multiphysics model, constructing a high-fidelity safety model, and comparing operating parameters in real time to generate power limiting commands, closed-loop control is achieved.
It enables precise safety limiting and closed-loop management of electrochemical devices under dynamic operating conditions, improves the dynamic operation safety level of the device, and avoids safety risks caused by underestimating transient peak values.
Smart Images

Figure CN122073136A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of hydrogen electrolysis control technology, specifically relating to a method, system, and electronic device for constructing and applying safe operation boundaries for hydrogen electrolysis based on dynamic feature identification. Background Technology
[0002] Electrochemical devices such as electrolyzers typically operate under fluctuating power sources such as wind and solar power. Under these conditions, the temperature, pressure, and gas composition within the system will fluctuate significantly with changes in the external input load. To ensure the safe operation of the electrolyzer, it is usually necessary to establish operating boundaries for key internal safety parameters for risk monitoring.
[0003] In existing technologies, steady-state or quasi-steady-state models based on thermodynamics or mass transfer laws are typically used to estimate safety-related parameters such as internal temperature and pressure difference, and to provide a certain safe operating range. However, in actual operating scenarios, such physical models built based on idealized conditions are difficult to accurately reflect the internal physical limits during rapid power changes.
[0004] Specifically, existing steady-state or quasi-steady-state models often assume that auxiliary devices such as cooling systems and water supply systems can respond instantly to changes in external load, and assume that the adjustment capabilities of these auxiliary systems are unlimited or can be linearly expanded. They fail to realistically consider the actual dynamic delays of system components and the physical constraints on the upper limits of adjustment capabilities. This idealized assumption about equipment characteristics makes it difficult for existing models to accurately simulate the actual adjustment process of the system under rapid power disturbances. Under extreme operating conditions, they are prone to underestimating the transient peak values of key internal parameters, resulting in significant deviations in the calculated safe operating boundaries and making it difficult to promptly reveal transient over-limit risks.
[0005] Meanwhile, existing operating systems mostly use fixed power limits or basic over-limit power-off protection logic, lacking a comprehensive mechanism to effectively couple accurate safe operating boundaries with actual power control commands, resulting in a disconnect between safety assessment and real-time status management.
[0006] Therefore, there is an urgent need for a solution that can accurately construct a physical model under dynamic fluctuation conditions to obtain the real operational safety boundary, and can realize dynamic closed-loop control of the input power of electrochemical devices based on this boundary. Summary of the Invention
[0007] One of the objectives of this invention is to at least solve one or more of the aforementioned problems existing in the prior art. In other words, one of the objectives of this invention is to provide a method, system, or electronic device for constructing and applying a safe operating boundary for hydrogen electrolysis based on dynamic feature identification that meets one or more of the aforementioned requirements.
[0008] To achieve the above-mentioned objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a method for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification, including: Acquire measured dynamic response data of the electrochemical device under dynamic excitation conditions; Based on measured dynamic response data, the actual dynamic characteristic parameters of the electrochemical device are identified through a system identification algorithm; By embedding real dynamic characteristic parameters into the multiphysics model of the electrochemical device, the idealized dynamic settings of safety-related dynamic links in the multiphysics model are replaced, and a high-fidelity safety model characterizing the actual dynamic behavior of the electrochemical device is constructed. The high-fidelity safety model includes an electrochemical sub-model, a thermodynamic sub-model, and a gas permeation sub-model, which are coupled to each other through key state variables. Simulation calculations were performed based on a high-fidelity safety model to obtain the high-fidelity safety boundary of the electrochemical device under dynamic operating conditions. Real-time acquisition of operating parameters of the electrochemical device during operation; The operating parameters are compared with the high-fidelity safety boundary to calculate the instantaneous risk component that characterizes the current risk level; Determine whether the instantaneous risk component exceeds the preset safety control threshold; if so, generate a power limiting command and send it to the power control unit of the electrochemical device to perform closed-loop limiting on the input power of the electrochemical device.
[0009] As a preferred implementation, based on measured dynamic response data, the actual dynamic characteristic parameters of the electrochemical device are identified using a system identification algorithm, including: The safety-related dynamic elements in the multiphysics model are parameterized, and an identification model is constructed with time delay constant and saturation upper limit as the variables to be identified. The measured dynamic response data is used as the true value, and the simulation output data of the model to be identified is used as the predicted value. A system identification algorithm is used to solve the problem by minimizing the residual between the true value and the predicted value, so as to obtain the true dynamic feature parameters.
[0010] As a preferred implementation, the real dynamic characteristic parameters include the time delay constant and the saturation upper limit, which are embedded in the safety-related dynamic links of the high-fidelity safety model; Among them, the upper limit of saturation is used to constrain the cooling and heat dissipation terms in the thermodynamic sub-model, and the time delay constant is used to characterize the dynamic response process of the safety-related auxiliary adjustment link to power changes; The thermodynamic sub-model, electrochemical sub-model, and gas permeation sub-model are coupled to allow the time delay constant and saturation upper limit to influence the overall dynamic response of the multiphysics model.
[0011] As a preferred implementation, the high-fidelity safety boundary includes: the internal temperature boundary of the electrolyte membrane, the transmembrane pressure difference boundary, and the gas cross-permeation boundary.
[0012] As a preferred implementation, the operating parameters are compared with the high-fidelity safety boundary to calculate the instantaneous risk component characterizing the current risk level, including: By using a piecewise linear normalization function, operating parameters with different physical dimensions are mapped to dimensionless instantaneous risk components. When the operating parameters reach the safe operating limit corresponding to the high-fidelity safety boundary, the value of the instantaneous risk component is normalized to a preset extreme value.
[0013] As a preferred implementation method, determining whether the instantaneous risk component exceeds a preset safety control threshold specifically includes: The instantaneous risk components of multiple dimensions are weighted and summed using preset weighting coefficients to obtain a comprehensive transient risk index. Determine whether the comprehensive transient risk index exceeds the preset risk threshold.
[0014] In one preferred embodiment, the power limiting command includes: a power limiting command for reducing the power setpoint; and / or a ramp rate limiting command for slowing down the rate of power increase.
[0015] As a preferred implementation, the dynamic excitation conditions include at least one of the following: power step condition, power ramp condition, and sudden shutdown condition.
[0016] On the other hand, the present invention also provides a system for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification, comprising: The data acquisition module is used to acquire measured dynamic response data of the electrochemical device under dynamic excitation conditions, and to acquire the operating parameters of the electrochemical device in real time during operation. The real dynamic characteristic parameter identification module is used to identify the real dynamic characteristic parameters of the electrochemical device based on measured dynamic response data and through the system identification algorithm. The model building module is used to embed real dynamic characteristic parameters into the multiphysics model of the electrochemical device to replace the idealized dynamic settings of safety-related dynamic links in the multiphysics model, and to build a high-fidelity safety model that characterizes the actual dynamic behavior of the electrochemical device. The high-fidelity safety model includes an electrochemical sub-model, a thermodynamic sub-model, and a gas permeation sub-model, which are coupled to each other through key state variables. The high-fidelity safety boundary calculation module is used to perform simulation calculations based on the high-fidelity safety model to obtain the high-fidelity safety boundary of the electrochemical device under dynamic operating conditions. The operation control module is used to compare the operating parameters with the high-fidelity safety boundary, calculate the instantaneous risk component that represents the current risk level, determine whether the instantaneous risk component exceeds the preset safety control threshold, and if so, generate a power limiting command and send it to the power control unit of the electrochemical device to limit the input power of the electrochemical device in a closed loop.
[0017] On the other hand, the present invention also provides an electronic device, comprising: Processor; and Memory, used to store computer programs; Among them, when the processor executes the computer program, it implements any one of the above-mentioned methods for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification.
[0018] Compared with existing technologies, the method, system, and electronic equipment for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification provided by this invention have the following advantages: This invention embeds real dynamic characteristic parameters, including time delay constants and saturation upper limits, into a high-fidelity safety model. This enables the thermodynamic sub-model to physically constrain the cooling and heat dissipation terms based on the saturation upper limit, and the dynamic auxiliary machine response sub-model to characterize the real dynamic response process of auxiliary machine components to power changes based on the time delay constant. This effectively overcomes the defect in the prior art that underestimates the transient peak value of the system due to the use of idealized parameter assumptions, and obtains a high-fidelity safety boundary that closely matches the actual dynamic operating conditions.
[0019] Furthermore, this invention calculates instantaneous risk components by real-time acquisition of operating parameters and comparison and mapping them with the aforementioned high-fidelity safety boundary. When the component exceeds the safety control threshold, a power limiting command is directly generated and applied to the power control unit. This enables the construction of the safety boundary of the physical model and the underlying real-time control of the electrochemical device to form a closed-loop response mechanism, thereby effectively solving the defect in the prior art where the safety boundary model is disconnected from the actual operating command. Ultimately, it achieves accurate safety limiting and closed-loop management of the input power of the electrochemical device under frequent fluctuation conditions, significantly improving the dynamic operation safety level of the device. Attached Figure Description
[0020] Figure 1 This is a flowchart of the method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification according to the present invention; Figure 2This is a flowchart of the implementation process of steps S600-S700 in the method for constructing and applying safe operation boundary of hydrogen electrolysis based on dynamic feature identification of the present invention; Figure 3 This is a comparison chart of the comprehensive transient risk index of the verification embodiment of the present invention. Detailed Implementation
[0021] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0022] The following description provides examples and does not limit the scope, applicability, or examples set forth in the claims. Changes may be made to the function and arrangement of the described elements without departing from the scope of the invention. Various processes or components may be appropriately omitted, substituted, or added to the various examples. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Furthermore, features described with respect to some examples may be combined into other examples.
[0023] Embodiments of the present invention provide a method for constructing and applying a safe operating boundary for hydrogen electrolysis based on dynamic feature identification, the flowchart of which is shown below. Figure 1 As shown, steps S100-S700 are included: S100. Obtain the measured dynamic response data of the electrochemical device under dynamic excitation conditions.
[0024] Specifically, when the electrochemical device is in a stable operating state, a preset dynamic excitation command is applied to it, and multi-dimensional measured dynamic response data are collected and acquired throughout the entire dynamic response process.
[0025] Among them, dynamic excitation conditions refer to the input disturbance conditions applied to stimulate the dynamic response characteristics of electrochemical devices. These conditions are used to cause the electrochemical devices to deviate from their original steady-state operating points, thereby characterizing their actual dynamic behavior under external disturbances.
[0026] In some feasible examples, dynamic excitation conditions include power step conditions, power ramp conditions, sudden shutdown conditions, and / or other disturbance conditions that can cause significant changes in the critical state response.
[0027] Furthermore, it should be noted that this invention is applied to hydrogen electrolysis systems. Accordingly, the electrochemical device is not limited to a specific structural form. Any electrochemical device capable of achieving the function of producing hydrogen through electrolysis can be applied to this invention. As a preferred example, the electrochemical device can specifically be an electrolyzer, such as a proton exchange membrane (PEM) electrolyzer, an alkaline electrolyzer (AEC), or a solid oxide electrolyzer (SOEC), among other types of electrolyzer equipment.
[0028] In one specific embodiment of the present invention, the above-mentioned acquisition of measured dynamic response data of the electrochemical device under dynamic excitation conditions may specifically include: acquiring measured dynamic response data of the electrochemical device under at least one dynamic excitation condition including power step condition, power ramp condition and sudden shutdown condition.
[0029] In other embodiments, the measured dynamic response data also includes measured dynamic response data under dynamic input conditions corresponding to typical shock conditions, power grid disturbance conditions, and / or changes in combinations of control parameters.
[0030] Considering that when electrochemical devices such as electrolyzers are driven by fluctuating power sources such as wind and photovoltaics, the internal state of the system will fluctuate significantly with load changes. Therefore, by introducing typical transient dynamic excitation conditions such as power step, power ramp or sudden shutdown, it is beneficial to obtain a full life cycle dataset covering extreme transient characteristics, which will provide more realistic and reliable data support for the subsequent construction of a high-fidelity safety model.
[0031] Specifically, taking the power step condition as an example, the process of obtaining measured dynamic response data may include: At a preset trigger time, the input power command of the electrochemical device is stepped from a first preset power value to a second preset power value, and the device status parameters of the electrochemical device are collected simultaneously throughout the power step process; the device status parameters include, but are not limited to, the cooling water pump speed, the cooling circuit inlet temperature, the cooling circuit outlet temperature, the stack average temperature, the transmembrane pressure difference, and the data sequence of at least one of the gas components changing over time. The data sequence of the collected equipment status parameters is determined as the measured dynamic response data.
[0032] The first preset power value is 100kW, and the second preset power value is 150kW.
[0033] S200: Based on measured dynamic response data, the system identification algorithm identifies the true dynamic characteristic parameters of the electrochemical device.
[0034] Specifically, the measured dynamic response data obtained in the above steps are input into the preset system identification algorithm framework to calculate the real dynamic characteristic parameters of the electrochemical device and its auxiliary system.
[0035] The purpose of step S200 is not to uniformly identify all the mechanistic parameters in the multiphysics model of the electrochemical device, but to identify the real dynamic characteristic parameters that can characterize the actual dynamic behavior of the electrochemical device for safety-related dynamic links that affect the authenticity of the dynamic safety boundary.
[0036] Among them, the true dynamic characteristic parameters include at least the time delay constant reflecting the system response delay and the saturation upper limit reflecting the upper limit of the system's regulation capability.
[0037] In a specific embodiment of the present invention, step S200 may specifically include: constructing a physical model to be identified with time delay constant and saturation upper limit as unknown variables; using measured dynamic response data as the true value and simulation output data of the physical model to be identified as the predicted value; and using a system identification algorithm to solve the problem with the goal of minimizing the residual between the true value and the predicted value to obtain the true dynamic characteristic parameters.
[0038] Specifically, in step S200, a preset input perturbation is applied to the electrochemical device under dynamic excitation conditions, and the measured dynamic response data of the device during the perturbation process is collected simultaneously. The measured dynamic response data is used as the observed true value in the identification process. Then, for safety-related dynamic links that affect the accuracy of the dynamic safety boundary, a dynamic response model to be identified, including time delay constant and saturation upper limit parameter, is constructed, and the dynamic response model to be identified is coupled with a conventional safety analysis model. Given a set of candidate parameters, numerical simulation is performed using the coupled model to obtain the corresponding critical state response prediction value. Then, the deviation between the critical state response prediction value and the observed true value is calculated to construct the residual objective function. Finally, the system identification algorithm is used to iteratively update the variable to be identified, so that the residual objective function gradually decreases until the preset convergence condition is met, thereby obtaining the true dynamic characteristic parameters.
[0039] In a specific example, let the parameter vector to be identified be... Given a parameter vector In this case, the critical state response prediction value obtained after coupling the dynamic response model to be identified with the conventional safety analysis model is denoted as... The corresponding measured dynamic response data is denoted as Then the prediction residual at the k-th sampling time is expressed as: .
[0040] Accordingly, the identification objective function is expressed as: .
[0041] in, The number of sampling points. These are the weighting coefficients corresponding to each sampling point. When taking... At this point, the objective function degenerates into ordinary least squares form. The parameter vector is then analyzed using a system identification algorithm. Perform iterative updates to find the objective function. Minimum optimal parameter vector and the optimal parameter vector The corresponding time delay constant and saturation upper limit parameter are determined as the true dynamic characteristic parameters.
[0042] Furthermore, the system identification algorithm can employ gradient descent, recursive least squares, least squares optimization, swarm intelligence optimization, or a combination thereof; the residual objective function can employ L2 norm, weighted L2 norm, mean square error, or other forms that can characterize the difference between predicted and measured values, to comprehensively evaluate the degree of matching between the model output and the measured dynamic response data under different candidate parameters.
[0043] It should be noted that the time delay constant and saturation upper limit identified in step S200 are not used to replace all the mechanism parameters in the conventional electrochemical sub-model, thermodynamic sub-model and gas permeation sub-model. Instead, they will be embedded in the multiphysics safety analysis model in subsequent steps to replace the idealized dynamic settings in the safety-related dynamic links, thereby constructing a high-fidelity safety model that characterizes the actual dynamic behavior of the electrochemical device.
[0044] By identifying real dynamic characteristic parameters and idealizing the dynamic settings of safety-related dynamic links in the subsequent replacement of multiphysics models, we can retain the original mechanism structure and physical interpretability of conventional safety analysis models on the one hand, and enhance the dynamic representation ability of the model to respond to critical states under fluctuating inputs and rapid disturbance scenarios on the other hand. This provides a more realistic and reliable parameter basis for the subsequent construction of high-fidelity safety models and the analysis of safety operation boundaries.
[0045] S300. Embed real dynamic characteristic parameters into the multiphysics model of the electrochemical device to replace the idealized dynamic settings of safety-related dynamic links in the multiphysics model, and construct a high-fidelity safety model that characterizes the actual dynamic behavior of the electrochemical device. The high-fidelity security model includes an electrochemical sub-model, a thermodynamic sub-model, and a gas permeation sub-model, which are coupled together through key state variables.
[0046] The electrochemical sub-model describes the stack voltage and / or representative cell voltage response; the thermodynamic sub-model describes the thermal state evolution processes such as core temperature and water channel temperature; and the gas permeation sub-model describes the gas cross-permeation and gas composition changes under pressure differential. The multiphysics safety analysis model framework, formed by the coupling of these sub-models, establishes a fundamental mapping relationship from input operating conditions to critical state response outputs.
[0047] While conventional safety analysis models can establish a basic mapping relationship between "input conditions and critical state response outputs", they typically employ idealized dynamic parameter settings during dynamic condition analysis.
[0048] Specifically, for cooling systems, water supply systems, and other safety-related auxiliary dynamic components, conventional models typically assume that the relevant state inputs can change in real time with external commands, and that their adjustment capabilities are not constrained by physical limits.
[0049] Unlike conventional models, the method of this invention does not use each physical sub-model as an independent static mapping relationship. Instead, it uses real dynamic characteristic parameters to make realistic corrections to the dynamic links that are directly related to the safety boundary analysis. This makes the key state responses output by the sub-model under dynamic conditions closer to the behavior of the actual device, and further couples them with other sub-models, so that the final output results have high fidelity characteristics.
[0050] To facilitate understanding of the high-fidelity security model constructed in this invention, the following will compare and explain the high-fidelity security model constructed in this invention with the structure and parameter settings of conventional models.
[0051] For example, in conventional models, when using this type of idealized dynamic processing, the actual response can be simplified to the target response, i.e.: ; And the relevant adjustment amount can be directly taken as the command adjustment amount, for example: ; in, Input for the target, For actual response, For instruction adjustment amount, This represents the actual adjustment amount.
[0052] The above idealization can meet general analysis needs under steady-state or slowly changing operating conditions, but under rapid current fluctuations, typical impact conditions, power grid disturbance conditions, or other fluctuating input scenarios, it can easily lead to distortion in the model's prediction of transient processes in response to key states such as stack voltage, stack temperature, anode-cathode pressure difference, and gas composition. In particular, it can easily underestimate transient peak values and dynamic lags, thereby affecting the authenticity of the subsequent construction of safe operating boundaries.
[0053] Therefore, the focus of this invention is not on uniformly identifying all the mechanistic parameters in the above-mentioned multiphysics model, but on identifying real dynamic characteristic parameters based on measured dynamic response data for safety-related dynamic links that affect the accuracy of dynamic safety boundaries, and embedding the real dynamic characteristic parameters into the framework of the multiphysics safety analysis model to replace the idealized dynamic parameter settings, thereby forming a high-fidelity safety model that is closer to the dynamic behavior of actual devices.
[0054] As an example, the real dynamic characteristic parameters are embedded in the dynamic response and regulation constraint links directly related to the safety boundary analysis in the following ways: the time delay constant is used to correct the mechanical, electrical or fluid inertial hysteresis between the relevant auxiliary dynamic links receiving the target command and the actual action on the electrochemical device; the saturation upper limit parameter is used to correct the maximum capacity boundary of the relevant regulation in actual operation.
[0055] Accordingly, the saturation upper limit parameter is embedded in the relevant adjustment constraint in the thermodynamic sub-model. This replaces the idealized dynamic condition of "actual adjustment equals commanded adjustment" with the actual adjustment constrained by the upper limit, thus characterizing the maximum adjustment capability boundary of the system in actual operation. For example, for cooling-related dynamic components, the actual heat dissipation capacity is expressed as: ; in, This represents the reference adjustment amount for cooling-related dynamic processes. Indicates the actual adjustment amount. This indicates the upper limit of the maximum adjustment capability of this dynamic link.
[0056] This avoids underestimating the risks of core temperature rise, pressure difference changes, or gas permeation due to overestimating cooling capacity under rapid dynamic operating conditions.
[0057] Furthermore, in one embodiment, the time delay constant is embedded in a relevant dynamic response mechanism to correct the dynamic process of the auxiliary system from receiving the target command to its actual action on the electrochemical device. Accordingly, the relevant dynamic response process is expressed as: ; Wherein, y(t) can be the actual dynamic response quantity related to the safety boundary analysis. For the corresponding target input. This is achieved by introducing... It can more realistically characterize the mechanical, electrical, or fluid inertial hysteresis between the auxiliary link receiving the command and acting on the electrochemical device, thereby improving the dynamic prediction accuracy of the model for critical state response under typical shock conditions, power grid disturbance conditions, and rapid fluctuation input conditions.
[0058] Furthermore, because the sub-models in the high-fidelity safety model are interconnected, the realism corrections formed in local sub-models are not limited to that sub-model but can be transmitted to the entire high-fidelity safety model through the coupling between sub-models. That is, the realistic dynamic characteristic parameters first establish a dynamic input-output relationship more consistent with the actual device in the corresponding sub-model, and then influence the critical state response process of the entire model through the coupling relationship between the sub-models. This makes the safety-related responses such as temperature, voltage, pressure difference, and gas composition output by the entire high-fidelity safety model under the same dynamic operating conditions closer to the dynamic behavior of the actual device.
[0059] Therefore, compared with conventional models that employ idealized dynamic settings, the high-fidelity safety model constructed in this application can provide an effective comparison of differences in critical state responses under the same input conditions. The high-fidelity safety model can reflect the response hysteresis and capability boundaries of real devices under dynamic operating conditions, while conventional models still exhibit idealized responses.
[0060] This comparison not only more clearly reflects the limitations of idealized models in dynamic safety boundary analysis, but also provides a more realistic and reliable model foundation for the subsequent construction of safety operation boundaries and the control of operational risks.
[0061] Furthermore, the thermodynamic sub-model, gas permeation sub-model, and electrochemical sub-model in the high-fidelity security model are coupled to each other through key state variables.
[0062] As a feasible example, the core temperature output by the thermodynamic sub-model can be used as input to the electrochemical sub-model and the gas permeation sub-model to influence the voltage response and gas cross-permeation process; the stack voltage output by the electrochemical sub-model can be further used in the electrochemical heat generation calculation and fed back to the thermodynamic sub-model; and the operating status inputs such as pressure difference and flow rate can further influence the gas composition changes output by the gas permeation sub-model.
[0063] Embodiments of the present invention also provide exemplary structural settings for the electrochemical sub-model, the thermodynamic sub-model, and the gas permeation sub-model. In some feasible examples, the electrochemical sub-model is represented by a mechanistic partial voltage structure as follows: ; ; in, The voltage of a representative single electrolytic cell is shown. This represents the total voltage of the stack. The number of electrolysis chambers, , , and Let represent the reversible voltage, activation polarization voltage, ohmic polarization voltage, and concentration polarization voltage, respectively. The reversible voltage, activation polarization, and ohmic polarization can be further written as functions of temperature, pressure, and current density, thus allowing the electrochemical sub-model to output the voltage response under given current input, temperature input, and anode / cathode pressure input conditions.
[0064] The thermodynamic sub-model can be represented using a stack-level lumped-parameter thermodynamic sub-model. Preferably, the thermodynamic sub-model can employ a two-node thermal structure to characterize the thermal states of the solid and fluid portions of the stack, respectively. Accordingly, the solid nodes and fluid nodes satisfy the following conditions: ; ; in, This refers to the core or solid node temperature. For waterway or fluid node temperature, and These are the equivalent heat capacities of the corresponding nodes. For electrochemical heat generation, For solid-liquid heat exchange, To dissipate heat to the environment, The heat carried away by the fluid.
[0065] Furthermore, electrochemical heat generation is expressed as: ; in, I This is the operating current of the electrolytic cell. This represents the total voltage of the stack. The number of electrolysis chambers, The thermal neutral voltage for a single electrolysis chamber. This represents the sum of the thermal neutral voltages corresponding to the stack.
[0066] Solid-liquid heat exchange is expressed as: ; in, h The equivalent heat transfer coefficient is used to characterize the heat transfer capacity between solid nodes and fluid nodes. A The equivalent area for solid-liquid heat transfer. hA This parameter represents the overall heat transfer capacity between the solid and liquid phases.
[0067] The fluid heat term is expressed as a function of inlet water temperature, flow rate, and fluid node temperature. Therefore, the thermodynamic sub-model can output the core temperature, water path temperature, and externally observable temperature response under conditions such as current input, inlet water temperature, and inlet water flow rate.
[0068] The gas permeation sub-model is used to characterize the gas cross-permeation and gas composition changes under input conditions such as temperature, pressure difference, and flow rate. Preferably, the gas cross-permeation rate is expressed as the sum of the diffusion permeation term and the pressure difference-driven permeation term, i.e.: ; The diffusion-permeability term is expressed as: ; The pressure differential-driven permeation term is represented as: ; in, For the effective diffusion coefficient, The effective area of the diaphragm. For the diaphragm thickness, and These represent the hydrogen concentrations on the cathode side and the anode side, respectively. The pressure difference drives the permeability coefficient. This represents the transmembrane pressure difference.
[0069] Furthermore, to reflect the effect of temperature on gas permeation behavior, the effective diffusion coefficient is expressed as: ; in, Pre-diffusion factor, R is the diffusion activation energy, R is the gas constant, and T(t) is the electrolyzer operating temperature or core temperature.
[0070] Based on the total permeation rate, the dynamic change of impurity gas on the anode side is expressed as: ; in, This represents the amount of impurity gas on the anode side. This represents the mole fraction of impurities at the anode outlet. The total gas flow rate at the anode outlet is denoted as .
[0071] Accordingly, the real-time hydrogen-oxygen penetration concentration or the hydrogen content in oxygen is expressed as: ; in, This represents the total amount of gaseous matter on the anode side.
[0072] In some embodiments of the present invention, the electrochemical sub-model in the high-fidelity safety model adopts a mechanistic partial voltage structure to output stack voltage and / or representative cell voltage based on current, temperature and pressure conditions; the thermodynamic sub-model adopts a stack-level lumped parameter thermodynamic sub-model to output core temperature and water circuit temperature based on electrochemical heat generation, heat transfer and heating processes; and the gas permeation sub-model is used to output gas cross-permeability and gas composition based on temperature, pressure difference and flow conditions.
[0073] S400: Based on a high-fidelity safety model, simulation calculations are performed to obtain the high-fidelity safety boundary of the electrochemical device under dynamic operating conditions.
[0074] Once the high-fidelity safety model is established, the time history of various key safety variables can be calculated by running the model under different operating conditions.
[0075] Specifically, transient simulation calculations can be performed by inputting multiple sets of simulated dynamic operating condition data into a high-fidelity safety model. The dynamic operating condition data preferably includes dynamic input conditions corresponding to typical impact conditions, grid disturbance conditions, and / or combinations of control parameters, thereby obtaining the time series of key physical state variables. Key physical state variables preferably include one or more of the following: stack voltage and / or representative cell voltage, core temperature, water circuit temperature, transmembrane pressure difference, and gas composition.
[0076] Furthermore, by combining preset operational safety constraints such as material tolerance temperature, design allowable differential pressure, gas flammability limits, and allowable voltage operating range, thermal safety thresholds, differential pressure safety thresholds, chemical safety thresholds, and voltage safety thresholds can be determined, thereby obtaining safety boundary curves, limit values, and / or corresponding boundary criterion sets for each key safety quantity. Among these, the voltage safety threshold is used to constrain the stack voltage and / or representative cell voltage within a preset allowable operating range, to avoid operational risks arising from abnormal local voltage increases, overall voltage exceeding limits, or deterioration of polarization state in the electrochemical device under dynamic operating conditions.
[0077] In one specific embodiment of the present invention, after the high-fidelity safety model is established, the internal temperature boundary, transmembrane pressure difference boundary, and gas cross-permeation boundary of the electrolyte membrane can be calculated by running the model under different dynamic operating conditions; and joint boundary constraints oriented to multidimensional critical state responses can be further formed as needed.
[0078] It should be noted that the high-fidelity safety boundary is determined based on a high-fidelity safety model embedded with real dynamic characteristic parameters. This model is used to simulate and calculate the response to critical states under dynamic operating conditions, combined with corresponding safety constraints. Compared to conventional models using idealized dynamic parameters, the high-fidelity safety boundary obtained by this invention can more realistically reflect the boundary change characteristics of electrochemical devices under fluctuating input conditions, thus providing a more reliable basis for subsequent online risk assessment and power limitation control.
[0079] S500: Real-time acquisition of operating parameters of the electrochemical device during operation.
[0080] During the operation of the electrolyzer, the control system collects key macroscopic operating variables at a predetermined sampling period, including but not limited to: stack outlet temperature, cooling circuit temperature, anode and cathode pressure, transmembrane pressure difference, gas purity or oxygen-side hydrogen content, etc.
[0081] Meanwhile, by performing appropriate filtering and signal processing on key macroscopic operating variables, the real-time state vector can be obtained. Its different components correspond to different safety-related physical quantities, such as , and wait.
[0082] in, Indicates time t Temperature inside the lower electrolyte membrane; Indicates time t The transmembrane pressure difference across the lower electrolyte membrane; Indicates time t Lower hydrogen-oxygen penetration concentration.
[0083] S600 compares the operating parameters with the high-fidelity safety boundary and calculates the instantaneous risk component that characterizes the current risk level.
[0084] Specifically, step S600 can respond to the continuous input of the operating parameter sequence by performing deviation comparison logic on the real-time operating parameters and their corresponding high-fidelity safety boundaries under the same dimensions to obtain the instantaneous risk component used to quantify the safety margin.
[0085] Considering that safety variables such as stack temperature, gas concentration, and fluid pressure difference have heterogeneous physical dimensions, it is difficult to make unified decisions directly at the control layer. In an optional implementation, step S600 can be implemented by mapping the operating parameters with different physical dimensions to dimensionless instantaneous risk components through a piecewise linear normalization function.
[0086] When the operating parameters reach the safe operating limit corresponding to the high-fidelity safety boundary, the value of the instantaneous risk component is normalized to a preset extreme value.
[0087] In one specific embodiment of the present invention, the piecewise linear normalization function is: .
[0088] in, The corresponding safe operating threshold is the safe operating threshold. For high-fidelity security boundaries. When When the value is close to 1, it indicates that the corresponding physical quantity is approaching or has reached its safety limit.
[0089] Using piecewise linear normalization functions for dimensionless spatial mapping is beneficial for establishing a unified security metric across physical fields and dimensions, and provides a standardized data interface for the system.
[0090] Considering that deterioration in actual operating conditions is often the result of the synergistic coupling of multiple physical fields such as heat, force, and chemistry, in a further specific embodiment of the present invention, when multiple safety dimensions need to be comprehensively considered, a comprehensive transient risk index can be constructed by using preset weighting coefficients to perform weighted summation calculations on the instantaneous risk components of multiple dimensions. : .
[0091] in, The weighting coefficients for each security dimension satisfy... and .
[0092] Constructing a comprehensive transient risk index at the macro level through weighted summation logic facilitates comprehensive risk tracking from a global perspective, avoids blind spots in monitoring single variables, and greatly enhances the completeness and fault tolerance of the risk assessment mechanism.
[0093] S700: Determine whether the instantaneous risk component exceeds the preset safety control threshold; if so, generate a power limiting command and send it to the power control unit of the electrochemical device to perform closed-loop limiting on the input power of the electrochemical device.
[0094] In one specific embodiment of the present invention, after obtaining the risk components of each dimension... Then, step S700 compares it with a preset risk threshold. Compare. When satisfied... When a safety risk is detected in the current operating condition, a power limiting command is generated, and the output of the power conversion device is adjusted so that the risk index falls back to the safe range.
[0095] Figure 2 A flowchart is provided for the process from step S600 to step 700, which includes real-time state estimation, real-time risk quantification, and safety closed-loop control.
[0096] In a further embodiment, generating a power limiting command may specifically include: generating a power limiting command to reduce the power setpoint; and / or, generating a ramp rate limiting command to slow down the rate of power increase.
[0097] Specifically, the power limiting command can be:
[0098] in, For raw power commands, This is the upper limit of safe power calculated based on the risk assessment results.
[0099] By repeatedly executing the above steps S400-S700, dynamic safety constraints on the electrolytic cell can be achieved throughout the entire operation.
[0100] Corresponding to the above construction of a comprehensive transient risk index In the implementation method, step S700 will integrate the risk index. With risk threshold Compare, when satisfied If a safety risk is detected in the current operating condition, the control system generates a power limiting command or a ramp rate limiting command.
[0101] In one specific embodiment of the present invention, the above-mentioned generation of power limiting instructions may specifically include: generating a power limiting instruction for reducing the power setting value; and / or, generating a ramp rate limiting instruction for slowing down the power rise rate.
[0102] Furthermore, in order to verify the effectiveness of the method for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification, this invention also provides a verification embodiment for verification.
[0103] like Figure 3 As shown, under the same fluctuating power input conditions, compared with the traditional steady-state model constructed using idealized parameters, the high-fidelity safety model obtained by dynamic feature identification in this embodiment can provide more sensitive internal state prediction when the power changes rapidly, thus showing obvious instantaneous peak values on the risk assessment curve.
[0104] When the external input power spikes at a certain moment, the risk curve obtained by the traditional method changes smoothly and fails to exceed the safety threshold. However, the risk curve of this embodiment can briefly exceed the threshold at that moment, triggering a power limiting command. Therefore, the safe operating boundary construction and application method of this embodiment has higher accuracy and sensitivity under dynamic operating conditions, and can promptly identify transient over-limit risks and perform closed-loop control.
[0105] This invention also provides a system for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification. Specifically, the system includes: The data acquisition module is used to acquire measured dynamic response data of the electrochemical device under dynamic excitation conditions, and to acquire the operating parameters of the electrochemical device in real time during operation. The real dynamic characteristic parameter identification module is used to identify the real dynamic characteristic parameters of the electrochemical device based on measured dynamic response data and through the system identification algorithm. The model building module is used to embed real dynamic characteristic parameters into the multiphysics model of the electrochemical device to replace the idealized dynamic settings of safety-related dynamic links in the multiphysics model, and to build a high-fidelity safety model that characterizes the actual dynamic behavior of the electrochemical device. The high-fidelity safety model includes an electrochemical sub-model, a thermodynamic sub-model, and a gas permeation sub-model, which are coupled to each other through key state variables. The high-fidelity safety boundary calculation module is used to perform simulation calculations based on the high-fidelity safety model to obtain the high-fidelity safety boundary of the electrochemical device under dynamic operating conditions. The operation control module is used to compare the operating parameters with the high-fidelity safety boundary, calculate the instantaneous risk component that represents the current risk level, determine whether the instantaneous risk component exceeds the preset safety control threshold, and if so, generate a power limiting command and send it to the power control unit of the electrochemical device to limit the input power of the electrochemical device in a closed loop.
[0106] It is understood that the specific execution logic, mathematical formulas and parameter limitations of each module in the above embodiments can be referred to the execution methods of each step in the method for constructing and applying safe operating boundaries of electrolytic hydrogen based on dynamic feature identification in the aforementioned embodiments.
[0107] This invention also provides an electronic device, which may include, but is not limited to, a processor 101, a memory 102, and optional communication interfaces 103 and input / output interfaces 104.
[0108] The processor can be a central processing unit (CPU), a digital signal processor (DSP), a programmable logic device (FPGA), an application-specific integrated circuit (ASIC), or other processing core capable of executing instructions. In this embodiment, the processor 101 is the control center of the electronic device, responsible for running the computer program stored in the memory 102 to execute one or more steps in the above embodiment of the method for constructing and applying safe operating boundaries for electrolytic hydrogen based on dynamic feature identification.
[0109] Memory can be any type of volatile or non-volatile storage medium, such as random access memory (RAM), read-only memory (ROM), flash memory, hard disk drive (HDD), solid-state drive (SSD), etc. Memory is used to store operating systems, various data, and computer programs.
[0110] When the instructions of a computer program stored in memory are executed by a processor, the electronic device performs the method for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification as described in the above embodiments.
[0111] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0112] The foregoing description is merely an exemplary embodiment of this application and should not be construed as limiting the scope of this application. Any equivalent changes and modifications made in accordance with the teachings of this application shall still fall within the scope of this application. Those skilled in the art will readily conceive of other embodiments of this application upon considering the specification and practicing the disclosure herein. This invention is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application. The specification and embodiments are to be considered exemplary only, and the scope and spirit of this application are defined by the claims.
Claims
1. A method for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification, characterized in that, Includes the following steps: Acquire measured dynamic response data of the electrochemical device under dynamic excitation conditions; Based on the measured dynamic response data, the actual dynamic characteristic parameters of the electrochemical device are identified by the system identification algorithm; The real dynamic characteristic parameters are embedded into the multiphysics model of the electrochemical device to replace the idealized dynamic settings of the safety-related dynamic links in the multiphysics model, thereby constructing a high-fidelity safety model that characterizes the actual dynamic behavior of the electrochemical device. The high-fidelity security model includes an electrochemical sub-model, a thermodynamic sub-model, and a gas permeation sub-model, which are coupled to each other through key state variables. Simulation calculations were performed based on the high-fidelity safety model to obtain the high-fidelity safety boundary of the electrochemical device under dynamic operating conditions. Real-time acquisition of operating parameters of the electrochemical device during operation; The operating parameters are compared with the high-fidelity safety boundary to calculate the instantaneous risk component that characterizes the current risk level; Determine whether the instantaneous risk component exceeds a preset safety control threshold; If so, a power limiting command is generated and sent to the power control unit of the electrochemical device to perform closed-loop limiting of the input power of the electrochemical device.
2. The method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification as described in claim 1, characterized in that, Based on the measured dynamic response data, the true dynamic characteristic parameters of the electrochemical device are identified using a system identification algorithm, including: The safety-related dynamic elements in the multiphysics model are parameterized to construct an identification model with time delay constant and saturation upper limit as the variables to be identified. The measured dynamic response data is used as the true value, and the simulation output data of the model to be identified is used as the predicted value. The system identification algorithm is used to solve the problem by minimizing the residual between the true value and the predicted value, thereby obtaining the true dynamic feature parameters.
3. The method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification as described in claim 1, characterized in that, The real dynamic feature parameters include time delay constant and saturation upper limit, which are embedded in the safety-related dynamic links of the high-fidelity security model; The saturation upper limit is used to constrain the cooling and heat dissipation terms in the thermodynamic sub-model, and the time delay constant is used to characterize the dynamic response process of the safety-related auxiliary adjustment link to power changes. The thermodynamic sub-model, the electrochemical sub-model, and the gas permeation sub-model are coupled to allow the time delay constant and the saturation upper limit to influence the overall dynamic response of the multiphysics model.
4. The method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification as described in claim 1, characterized in that, The high-fidelity safety boundaries include: the internal temperature boundary of the electrolyte membrane, the transmembrane pressure difference boundary, and the gas cross-permeation boundary.
5. The method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification as described in claim 1, characterized in that, The operating parameters are compared with the high-fidelity safety boundary to calculate the instantaneous risk component characterizing the current risk level, including: By using a piecewise linear normalization function, the operating parameters with different physical dimensions are mapped to dimensionless instantaneous risk components. When the operating parameters reach the safe operation limit corresponding to the high-fidelity safety boundary, the value of the instantaneous risk component is normalized to a preset extreme value.
6. The method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification as described in claim 5, characterized in that, Determining whether the instantaneous risk component exceeds a preset safety control threshold specifically includes: The instantaneous risk components of multiple dimensions are weighted and summed using preset weighting coefficients to obtain a comprehensive transient risk index. Determine whether the comprehensive transient risk index exceeds a preset risk threshold.
7. The method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification as described in claim 1, characterized in that, The power limiting instructions include: a power limiting instruction for reducing the power setpoint; and / or a ramp rate limiting instruction for slowing down the rate of power increase.
8. The method for constructing and applying the safe operation boundary of hydrogen electrolysis based on dynamic feature identification as described in claim 1, characterized in that, The dynamic excitation conditions include at least one of the following: power step condition, power ramp condition, and sudden shutdown condition.
9. A system for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification, characterized in that, include: The acquisition module is used to acquire measured dynamic response data of the electrochemical device under dynamic excitation conditions, and to acquire the operating parameters of the electrochemical device in real time during operation. The real dynamic characteristic parameter identification module is used to identify the real dynamic characteristic parameters of the electrochemical device based on the measured dynamic response data and through the system identification algorithm. The model building module is used to embed the real dynamic characteristic parameters into the multiphysics model of the electrochemical device to replace the idealized dynamic settings of the safety-related dynamic links in the multiphysics model, and to build a high-fidelity safety model characterizing the actual dynamic behavior of the electrochemical device. The high-fidelity security model includes an electrochemical sub-model, a thermodynamic sub-model, and a gas permeation sub-model, which are coupled to each other through key state variables. The high-fidelity safety boundary calculation module is used to perform simulation calculations based on the high-fidelity safety model to obtain the high-fidelity safety boundary of the electrochemical device under dynamic operating conditions. The operation control module is used to compare the operation parameters with the high-fidelity security boundary, calculate the instantaneous risk component representing the current risk level, and determine whether the instantaneous risk component exceeds the preset security control threshold. If so, a power limiting command is generated and sent to the power control unit of the electrochemical device to perform closed-loop limiting of the input power of the electrochemical device.
10. An electronic device, characterized in that, include: processor; as well as Memory, used to store computer programs; When the processor executes the computer program, it implements the method for constructing and applying safe operating boundaries for hydrogen electrolysis based on dynamic feature identification as described in any one of claims 1 to 8.