A fault-tolerant stable control method of a power monitoring system based on dual-link redundancy

By constructing a power monitoring system with dual control links, the problem of faults in digital output modules and relays in the power monitoring system was solved, achieving zero-delay response and high fault-tolerant operation, ensuring the safety and stability of the power system, and reducing the failure rate.

CN122137102APending Publication Date: 2026-06-02HUANENG LANCANG RIVER HYDROPOWER CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUANENG LANCANG RIVER HYDROPOWER CO LTD
Filing Date
2026-01-19
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Failures in digital output modules and relays in power monitoring systems due to aging, contact wear, and other issues can prevent the transmission of control signals, potentially leading to serious consequences such as failure to start and stop hydropower units or failure of emergency shutdown commands. Existing technologies cannot effectively prevent sudden and common-cause failures during dynamic operation.

Method used

A dual control link is constructed, including a PLC, a digital output module, and relays. Auxiliary measurement points are connected to the PLC's digital input points. The PLC program logic is reconstructed to divide the control instructions into two output instructions, which are encapsulated as atomic operations. The dual links work simultaneously to monitor equipment faults in real time and issue alarms, ensuring the reliable execution of control instructions.

Benefits of technology

To achieve zero-latency response and high fault-tolerant operation, avoid safety accidents, reduce failure rate, ensure the safe and stable operation of the power system, reduce resource waste, and improve system reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137102A_ABST
    Figure CN122137102A_ABST
Patent Text Reader

Abstract

This application proposes a fault-tolerant and stable control method for a power monitoring system based on dual-link redundancy, relating to the field of power monitoring system technology. The method includes: constructing dual control links for controlling the controlled equipment, wherein each control link includes a PLC, a digital output module, and a relay, with the relay connected to the corresponding PLC digital input point via an auxiliary measuring point; reconstructing the PLC program logic, dividing the control command into two output commands, which are simultaneously sent by the two PLCs to the corresponding digital output module and relay, with the two output commands encapsulated into an atomic operation; each PLC receiving a feedback signal sent through the auxiliary measuring point after the corresponding relay executes the command; if no feedback signal is received, it is determined that the relay has not acted, and the abnormal information is recorded and an alarm is issued. This invention, employing the above scheme, effectively ensures the safe and stable operation of the power monitoring system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power monitoring system technology, and in particular to a fault-tolerant and stable control method for a power monitoring system based on dual-link redundancy. Background Technology

[0002] In the power monitoring system LCU, when the digital output module and relay malfunction or intermittently fail to operate due to aging, contact wear, electromagnetic interference, or other problems, the control signal cannot be transmitted and the control command cannot be executed.

[0003] The aforementioned problems may lead to serious consequences such as failure to start or stop hydropower units, failure of emergency shutdown orders, etc., affecting the safe and stable operation of the power system, and may even cause safety accidents and huge economic losses.

[0004] To address the above problems, existing technical solutions include: Regular inspection, calibration, and cleaning: This work is usually carried out in conjunction with unit maintenance, checking key parameters such as relay operating voltage, return voltage, and contact resistance. If the calibration results do not meet the requirements, the corresponding relay is replaced. For example, during the annual spring maintenance of hydropower stations, all relays undergo comprehensive testing.

[0005] Regular replacement: The replacement cycle is determined based on the relay's expected lifespan and actual usage frequency. When the replacement cycle is reached, the relays are replaced in batches to prevent damage caused by aging. Relays that operate frequently may be scheduled for replacement every six months, while those with lower operating frequency may be replaced once a year.

[0006] Signal verification: A signal verification mechanism is added to the control program to immediately verify the relay feedback signal after sending the control command. If an anomaly is detected, the control program will attempt to resend the command or report an error. For example, after the PLC sends a power-on command, it will wait for the relay feedback signal. If no correct feedback is received within a specified time, the command will be resent.

[0007] Automatic module fault isolation: When a fault is detected in a digital output module, the system can automatically isolate it to prevent the fault from spreading further. However, control commands on the isolated module will be unexecutable, affecting the normal operation of related equipment. For example, if a digital output module controls a valve on a water turbine, the valve will be unable to open or close properly after the module is isolated due to a fault.

[0008] The disadvantages of existing technologies include: Limitations of regular maintenance: Traditional maintenance relies on manual verification of relay operating voltage (e.g., the standard operating voltage of a DC220V relay must be ≤70% of the rated value, and the contact resistance must be ≤50mΩ), but it cannot avoid sudden failures during dynamic operation and cannot fundamentally prevent relay and digital output module failures.

[0009] Relay replacement time is difficult to estimate accurately: the operating frequency of relays varies greatly depending on the control command, making it difficult to accurately predict the replacement time. This can lead to delayed replacement, failing to prevent malfunctions in time; or premature replacement, resulting in a significant waste of resources. For example, some relays used for emergency shutdown may only operate once or twice a year; while relays used for routine regulation may operate hundreds or thousands of times a day.

[0010] I / O module failures are difficult to predict effectively: I / O modules, especially digital output modules, are prone to failure due to their highly random nature. Existing technologies cannot effectively predict them, making it difficult to take targeted measures in advance.

[0011] The backup link has a risk of "pseudo-redundancy": In the traditional primary-backup redundancy design, the backup link is inactive for a long time. Its relay contacts and other components may age due to oxidation and other environmental factors, which may cause the backup link to fail to work properly when switching is required, resulting in "pseudo-redundancy" and greatly reducing the actual switching success rate.

[0012] There is a risk of "common cause failure": In traditional single-link designs, if the power supply of the digital output module fails or the heat dissipation of the same cabinet is poor, multiple components in a single link may fail simultaneously, and existing technologies do not protect against this risk. Summary of the Invention

[0013] This application aims to at least partially address one of the technical problems in the related art.

[0014] Therefore, the purpose of this application is to propose a fault-tolerant and stable control method for a power monitoring system based on dual-link redundancy, which ensures the safe and stable operation of the power monitoring system.

[0015] To achieve the above objectives, this application proposes a fault-tolerant stability control method for a power monitoring system based on dual-link redundancy, comprising: A dual control link is constructed to control the controlled equipment. Each control link includes a PLC, a digital output module, and a relay. The relay is connected to the corresponding PLC digital input point through auxiliary measuring points. The PLC program logic is restructured, and the control instructions are divided into two output instructions, which are simultaneously sent by two PLCs to the corresponding digital output modules and relays. The two output instructions are encapsulated into an atomic operation. Each PLC receives a feedback signal sent through an auxiliary measuring point after executing the command of the corresponding relay. If no feedback signal is received, it is determined that the relay has not acted, the abnormal information is recorded, and an alarm is triggered.

[0016] The power monitoring system and its fault-tolerant and stable control method based on dual-link redundancy in this application construct independent and parallel dual control links. By having two control links work simultaneously, even if either control link fails, the healthy control link can still complete the command issuance normally without switching logic, thus playing a role in fault shielding. This embodiment does not require master-slave switching or rely on complex switching logic, and can achieve zero-latency response and high fault-tolerant operation, ensuring the reliable execution of control commands. By establishing a process mechanism of command-execution-feedback-verification-abnormal alarm for dual control links, equipment faults are monitored and alarms are issued in real time to avoid the occurrence of safety accidents.

[0017] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0018] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein: Figure 1 This is a flowchart illustrating a fault-tolerant stability control method for a power monitoring system based on dual-link redundancy, as provided in Embodiment 1 of this application. Figure 2 This is a schematic diagram of the dual control link structure according to an embodiment of this application; Figure 3 This is a schematic diagram of the cross-arrangement of measuring points according to an embodiment of this application; Figure 4 This is a code diagram illustrating the use of the STL language in an embodiment of this application; Figure 5 This is a schematic diagram of the fault detection mechanism in an embodiment of this application. Detailed Implementation

[0019] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application.

[0020] The following describes a fault-tolerant stability control method for a power monitoring system based on dual-link redundancy, according to an embodiment of this application, with reference to the accompanying drawings.

[0021] Figure 1This is a flowchart illustrating a fault-tolerant stability control method for a power monitoring system based on dual-link redundancy, as provided in Embodiment 1 of this application.

[0022] like Figure 1 As shown, the fault-tolerant stability control method for a power monitoring system based on dual-link redundancy includes the following steps: Step 101: Construct a dual control link for controlling the controlled device. Each control link includes a PLC, a digital output module, and a relay. The relay is connected to the corresponding PLC digital input point through an auxiliary measuring point. Specifically, in this embodiment, based on the original digital output module and intermediate relay, a digital output module, relay and control circuit of the same model are added to form an independent and completely parallel dual control link, and zero-delay synchronous output is achieved through synchronous drive.

[0023] Figure 2 This is a schematic diagram of a dual control link structure, as shown below. Figure 2 As shown, it includes a dual control link and a controlled device. The dual control link includes a main PLC, a digital output module 1, a relay K1, a backup PLC, a digital output module 2, and a relay K2.

[0024] Furthermore, in this embodiment, a relay with multiple auxiliary contacts is selected. The relay feedback signal is connected to the PLC digital input point through the auxiliary contacts. A high-speed input module is used to ensure that the feedback signal is captured for monitoring the relay operation.

[0025] Specifically, in this embodiment, the measuring points are arranged in a cross manner: the two output points of the same control command should avoid being located in the same digital output module to prevent the two output points from failing to output signals normally due to the abnormality of one output module; the two sets of relay output circuits are independently connected to different terminal blocks to reduce the risk of common cause failures. Figure 3 This is a schematic diagram of the intersection of measuring points.

[0026] Step 102: Reconstruct the PLC program logic, divide the control instructions into two output instructions, and send them simultaneously from the two PLCs to the corresponding digital output modules and relays. The two output instructions are encapsulated into an atomic operation. Furthermore, in this embodiment, a synchronization driving mechanism is established, including: Reconstruct the PLC program logic to simultaneously send control commands to the original relay and the parallel redundant relay through two different digital output modules. Encapsulating two output instructions into an atomic operation ensures that the execution process will not be interrupted by other tasks, guarantees that control instructions are issued simultaneously, and avoids duplicate instruction issuance due to instruction issuance time differences, which could affect the stable operation of the system. Figure 4This is a code diagram using the STL language.

[0027] Step 103: Each PLC receives the feedback signal sent through the auxiliary measuring point after receiving the corresponding relay execution instruction. If no feedback signal is received, it is determined that the relay has not acted, the abnormal information is recorded and an alarm is triggered.

[0028] Specifically, in this embodiment, such as Figure 5 As shown, through the mechanism of "command-execution-feedback-verification-anomaly alarm", fault monitoring capability is added on the basis of synchronous control. When a component on a single control link fails, causing one of the relays corresponding to a certain command to not operate, the abnormal information is recorded and an alarm is triggered, so that the operation and maintenance personnel can check and handle it at an opportune time. This plays the role of fault detection and alarm, and allows the operation and maintenance personnel to handle it in a timely manner.

[0029] Meanwhile, the health control link completes the instruction issuance normally, unaffected by the fault control link, without needing to switch logic, thus playing a role in fault shielding (either of the two can be used).

[0030] The power monitoring system and its fault-tolerant and stable control method based on dual-link redundancy in this application construct independent and parallel dual control links. By having two control links work simultaneously, even if either control link fails, the healthy control link can still complete the command issuance normally without switching logic, thus playing a role in fault shielding. This embodiment does not require master-slave switching or rely on complex switching logic, and can achieve zero-latency response and high fault-tolerant operation, ensuring the reliable execution of control commands. By establishing a process mechanism of command-execution-feedback-verification-abnormal alarm for dual control links, equipment faults are monitored and alarms are issued in real time to avoid the occurrence of safety accidents.

[0031] An analysis of the dual-link redundancy system proposed in this application is performed, and the failure probability is calculated, including: 1) System failure conditions are clearly defined In a dual-link redundancy system, if one link fails, the other link can still ensure normal system operation. Therefore, the entire system will only fail if both links fail simultaneously. Furthermore, since the two links are independent of each other, there is no common cause of failure; their failures are mutually independent.

[0032] 2) Formula for failure rate of dual-link redundant system Based on the above conditions, the failure rate of a dual-link redundant system is... The probability of two single links failing simultaneously is expressed as:

[0033] Based on the above analysis, it can be seen that compared with the single-link system, the dual-link redundant power monitoring system proposed in this application has a significantly reduced failure rate and greatly enhances the reliability of the system. Moreover, this application only requires optimization and upgrading of the existing monitoring system architecture, which is easy to implement, highly adaptable to the existing system, and does not require large-scale replacement of equipment or system modification. It has high operability and wide application value.

[0034] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0035] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "multiple" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0036] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.

[0037] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0038] It should be understood that various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0039] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0040] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0041] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.

Claims

1. A fault-tolerant stability control method for a power monitoring system based on dual-link redundancy, characterized in that, include: A dual control link is constructed to control the controlled equipment. Each control link includes a PLC, a digital output module, and a relay. The relay is connected to the corresponding PLC digital input point through an auxiliary measuring point. The PLC program logic is reconstructed, and the control instructions are divided into two output instructions, which are simultaneously sent by two PLCs to the corresponding digital output modules and relays. The two output instructions are encapsulated into an atomic operation. Each PLC receives a feedback signal sent through an auxiliary measuring point after executing the command of the corresponding relay. If no feedback signal is received, it is determined that the relay has not acted, the abnormal information is recorded, and an alarm is triggered.

2. The method as described in claim 1, characterized in that, The dual control link includes a first control link and a second control link. The first control link includes a main PLC, a digital output module 1, a relay K1, and the controlled device. The relay K1 is connected to the digital input point of the main PLC through an auxiliary measuring point. The second control link includes a backup PLC, a digital output module 2, a relay K2, and the controlled device. The relay K2 is connected to the digital input point of the backup PLC through an auxiliary measuring point.

3. The method as described in claim 1, characterized in that, The lack of received feedback signal includes: If the PLC does not receive a feedback signal from the relay within the set delay time after issuing the instruction, it is determined that the relay has not activated.

4. The method as described in claim 1, characterized in that, The method further includes: If an alarm message is received from the PLC, it is determined that the corresponding control link has failed. The command is then issued through the control link that is not faulty, and the equipment fault is detected manually.