System and method for preventing misoperation of electrical equipment based on synchronization of upper and lower computers
By using a synchronized upper and lower computer operating system for preventing electrical equipment malfunctions and constructing an interlocking logic model using the HCON graphical configuration tool, reliable error prevention and efficient fault diagnosis of electrical equipment operation are achieved. This solves the problems of limited interlocking range, poor adaptability, and insufficient real-time performance in existing technologies, thereby improving the operational safety and fault diagnosis efficiency of electrical equipment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHANGDIAN NEW ENERGY CO LTD
- Filing Date
- 2026-02-24
- Publication Date
- 2026-06-23
AI Technical Summary
Existing technologies for preventing misoperation of electrical equipment suffer from limited interlocking range, poor adaptability, insufficient real-time performance, compatibility issues, and low fault diagnosis efficiency, making it impossible to comprehensively and reliably prevent electrical misoperation.
An electrical equipment anti-misoperation operating system based on upper and lower computer synchronization is adopted. The interlocking logic model is constructed through the HCON graphical configuration tool. The upper computer interlocking module, compilation module, real-time database and human-machine interface are used to realize the real-time acquisition and display of equipment status data. The lower computer execution unit performs logic verification and hard-wired control. The dual verification mechanism ensures the reliability of operation.
It achieves reliable error prevention in the operation of electrical equipment, improves operational safety and fault diagnosis efficiency, adapts to rapid iteration of complex logical relationships, supports multiple operation control methods, and is suitable for different electrical equipment and environments.
Smart Images

Figure CN122260993A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of electrical equipment monitoring technology, specifically to an electrical equipment anti-misoperation operating system and method based on upper and lower computer synchronization, applicable to the operation interlocking control of electrical equipment in scenarios such as hydropower stations and substations. Background Technology
[0002] Existing technologies for preventing misoperation of electrical equipment have numerous problems. Mechanical interlocking is only applicable to local equipment (such as disconnectors and grounding switches) and cannot achieve cross-equipment interlocking; hard-wiring interlocking of electrical secondary circuits requires complex wiring, signals are susceptible to interference, and it is difficult to adapt to dynamic logic adjustments; microcomputer-based five-prevention systems have non-real-time issues, and changes in equipment status during operation may cause interlocking failure; integrated automatic interlocking systems are incompatible with pumped storage power station monitoring systems due to protocol differences. In addition, existing technologies cannot display specific reasons when the upper-level computer interlocking conditions are not met, making it impossible for maintenance personnel to make intuitive judgments, resulting in low fault diagnosis efficiency.
[0003] Electrical misoperation accidents occur frequently during power system operation, and traditional methods for preventing such accidents have other shortcomings. Methods using interlocking relationships between locks (or key exchange) represent the relationships between equipment through locks, resulting in poor flexibility. When there are many devices with complex logical relationships, a large number of locks need to be installed, the key exchange process is cumbersome, and physical locks are susceptible to damage from natural factors such as corrosion, leading to a high failure rate. While microcomputer-based anti-misoperation methods embed the equipment operation sequence into the control terminal, there is a lack of effective status information exchange between the locks and the control terminal. The control terminal struggles to accurately obtain the current status of the equipment, making it prone to missing equipment operations in the sequence, thus causing misoperation. Furthermore, existing technologies are inadequate in preventing the opening and closing of isolating switches under load, failing to comprehensively and reliably eliminate electrical misoperation. Summary of the Invention
[0004] The present invention aims to provide an electrical equipment anti-misoperation operating system and method based on upper and lower computer synchronization, which solves the problems of limited interlocking range, poor adaptability, insufficient real-time performance, compatibility issues, and low fault diagnosis efficiency in the prior art, so as to achieve reliable anti-misoperation of electrical equipment operation and improve operational safety and fault diagnosis efficiency.
[0005] To solve the above problems, the technical solution of the present invention is as follows: An electrical equipment anti-misoperation operating system based on upper and lower computer synchronization includes an upper computer interlocking module, a lower computer execution unit, a compilation module, a real-time database, and a human-machine interface; The host computer interlocking module is connected to the compilation module, the real-time database, and the human-machine interface respectively. It is used to build the interlocking logic model and transmit it to the compilation module, obtain equipment status data from the real-time database, and transmit interlocking information to the human-machine interface. The lower-level execution unit is connected to the compilation module (to receive the locking logic) and to the upper-level locking module via the control bus (to receive operation instructions and provide feedback on the status). It is used to receive the locking logic issued by the compilation module and to receive the operation instructions from the upper-level computer and provide feedback on the execution status. The compilation module connects the host computer and the slave computer, and is used to compile the host computer logic and synchronize it to both. The real-time database is connected to the host computer and the slave computer respectively, and is used to store and provide device status data; The human-machine interface is only connected to the host computer and is used to display the lockout status and the reason for operation failure.
[0006] Furthermore, the host computer interlocking module constructs an interlocking logic model based on the HCON graphical configuration tool.
[0007] Furthermore, the lower-level execution unit is a PLC or a local control unit (LCU) with a built-in interlocking logic program consistent with that of the upper-level unit.
[0008] The method for preventing misoperation of electrical equipment based on upper and lower computer synchronization includes the following steps: Step 1: Logic Modeling. Construct the interlocking logic model using the HCON configuration tool. Input conditions include device status signals (IN). ) and custom Chinese description (Str ); Step 2: Logic synchronization. Use the PCC compiler to compile the model into a unified latch program and generate a latch file name; embed the latch program synchronously into the host computer command module, and set the same latch logic on the slave computer through programming software. Step 3: Operation control. Before the host computer issues the operation command, the anti-misoperation control process (PDC) calls the interlocking program to verify the condition satisfaction in real time. If the condition is satisfied, the command is transmitted to the lower computer via the control bus. The lower computer performs a second verification of the interlocking logic and then triggers the hard-wired control loop. If the condition is not satisfied, the OIX interface pops up the HCON interlocking screen and displays a Chinese description of the unsatisfied condition. Step 4: Operation Confirmation and Air Raid Travel. After each actual operation, press the confirmation key in sequence on the control terminal of the operating equipment for the system to recognize the operation as complete. When operating switches or disconnectors, the system adds a prompt operation after the switching operation item and transmits it to the control terminal. The operator must verify that it is correct before proceeding to the next step. When using air raid lock type settings, the control terminal automatically requires checking the code after the operation. Only after verification can the operation continue. Step 5: Troubleshooting. Maintenance personnel can directly locate the fault point through the HCON screen.
[0009] Furthermore, step 4 also includes software measures to prevent "empty travel". The software measures are as follows: during the pre-operation of switches and disconnectors, the system adds prompting operations after the switching operation items and transmits them to the control terminal. If the operation sequence is found to be missing during the pre-operation, the operator is prompted to supplement and improve it.
[0010] Furthermore, step 4 also includes hardware measures to prevent "empty travel". The hardware measures are as follows: for padlock-type locks, status identifiers are installed at the open and closed positions of the knife switch, and with the help of accessories, the control terminal can only read the code of one status identifier at one position; when the lock is not locked, the internal blocking device pops out to prevent the control terminal operating component from being inserted. Only when the lock is locked can the control terminal operating component be inserted to read the code, unlock and perform the current operation, and then proceed to the next operation.
[0011] Furthermore, in the logic modeling process in step 1, logic modules are dragged and dropped using the HCON configuration tool, and input conditions are configured to complete the construction of the logic model.
[0012] Furthermore, in step 2, during the logic synchronization process, the lower-level machine obtains a program through programming software that is completely identical to the locking logic program compiled by the PCC compiler on the upper-level machine, thereby realizing the synchronous deployment of the locking logic between the upper and lower-level machines.
[0013] Furthermore, in step 3, the operation control adopts a dual closed-loop verification method of upper computer prediction and lower computer execution. After the upper computer PDC process calls the interlocking program for verification and passes, the instruction is transmitted to the lower computer, and the lower computer verifies the interlocking logic again. Only after the dual verification passes will the hard-wired control loop be triggered.
[0014] Furthermore, during the exception handling in step 5, the Chinese description of the unmet conditions displayed on the HCON screen includes the status of the associated device and the interlocking logic path. The maintenance personnel can directly locate the fault point based on this description.
[0015] The beneficial effects of this invention are as follows: 1. By generating a unified interlocking program through configuration tools, the logic of the upper and lower computers is fully synchronized, avoiding logical conflicts and solving the problem of misoperation caused by inconsistency in logic.
[0016] 2. The upper computer predicts and the lower computer executes a dual closed-loop verification, which improves operational reliability and enhances the real-time performance and accuracy of preventing misoperation.
[0017] 3. The Chinese description of the interlocking conditions is directly fed back to the operation interface, which shortens the troubleshooting time, improves the efficiency of fault diagnosis, and makes it easier for maintenance personnel to quickly handle problems.
[0018] 4. Supports custom model libraries, adapting to rapid iteration of complex locking logic, solving the problem of poor adaptability of traditional locking methods.
[0019] 5. The HCON graphical configuration tool generates interlocking logic through data configuration, which changes the limitations of traditional program lock logic relationships that rely on structure. It simplifies the setting of complex logic relationships and allows for flexible modification of logic according to actual needs.
[0020] 6. The system encompasses a variety of operation control methods and error prevention measures, adapting to the needs of different electrical equipment and operating environments. It has wide applicability and can play a good role in preventing misoperation, whether in conventional substation operation or special power equipment maintenance scenarios. Attached Figure Description
[0021] The invention will be further described below with reference to the accompanying drawings: Figure 1 This is a flowchart illustrating the process of preventing misoperation of electrical equipment according to the present invention. Figure 2 This is a flowchart of the HCON configuration tool's interlocking logic modeling process according to the present invention; Figure 3 This is a flowchart of the dual-verification operation control for upper and lower computers in this invention; Figure 4 This is a schematic diagram illustrating the HCON screen anomaly handling and fault location in this invention. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] An electrical equipment anti-misoperation operating system based on upper and lower computer synchronization includes an upper computer interlocking module, a lower computer execution unit, a compilation module, a real-time database, and a human-machine interface; The host computer interlocking module: Based on the HCON graphical configuration tool, it builds the interlocking logic model, supports visual drag and drop, logic condition configuration and AND / OR / NOT operations. It has data interaction connections with the compilation module (PCC), real-time database and human-machine interface (OIX). It can transmit the constructed interlocking logic model to the compilation module, obtain device status data from the real-time database, and transmit interlocking status information to the human-machine interface.
[0024] Lower-level execution unit: This is a PLC or local control unit (LCU) with built-in interlocking logic program consistent with the upper-level computer. It is connected to the compilation module and control bus. It receives the same interlocking logic processed by the compilation module through programming software, and receives operation instructions issued by the upper-level computer through the control bus and feeds back the execution status.
[0025] Compiler Module (PCC): Compiles the HCON configuration logic into binary code. It is connected to the host computer's interlocking module and the lower computer's execution unit, respectively. It deploys the compiled binary code to the host computer and provides a basis for the lower computer to set the same interlocking logic through programming software.
[0026] Real-time database: Stores device status data (such as circuit breaker position and control mode signals), and has data connections with both the host computer interlocking module and the slave computer execution unit, enabling it to provide real-time device status data to both the host computer and the slave computer.
[0027] Human-Machine Interface (OIX): Displays the status of interlocking conditions being met and the reasons for operation failures in real time. It connects only to the host computer's interlocking module, receives relevant information transmitted from the host computer, and displays it.
[0028] The construction and initialization of an electrical equipment anti-misoperation operating system based on upper and lower computer synchronization includes the following steps: Step 1. Install and configure the host computer interlocking module, build a development environment based on the HCON graphical configuration tool, and ensure that it can interact normally with the compilation module, real-time database and human-machine interface.
[0029] Step 2. Deploy the lower-level execution unit (PLC or LCU), ensuring a stable connection between it and the compilation module and control bus, and prepare it to receive the interlocking logic program through programming software.
[0030] Step 3. Configure the compilation module (PCC) to receive the HCON configuration logic transmitted by the host computer's interlocking module and complete the compilation process, while also providing support for setting the same interlocking logic for the slave computer.
[0031] Step 4. Initialize the real-time database, establish the relevant data table structure for storing device status data, ensure that status information from the device can be received and stored in real time, and provide data support to the host computer and the slave computer.
[0032] Step 5. Debug the human-machine interface (OIX) to ensure that it can correctly receive the information transmitted by the host computer's interlocking module and accurately display the interlocking condition status and the reason for operation failure.
[0033] The logical modeling and synchronization process of an electrical equipment anti-misoperation operating system based on upper and lower computer synchronization includes the following steps: S1. Operators design interlocking logic models using the HCON configuration tool. Based on the operating rules and logical relationships of the electrical equipment, they drag and drop corresponding logic modules and configure input conditions, including equipment status signals (IN). ) and custom Chinese description (Str ), to complete the construction of the logical model.
[0034] S2. Use the PCC compiler to compile the constructed HCON configuration logic into binary code and generate the corresponding latch file name (such as GRAPHICAL_DEFAULT_ES5117_CLOSE).
[0035] S3. The compiled latch program is synchronously embedded into the host computer command module, and the slave computer obtains the same latch logic program through the programming software to complete the synchronization setting of the latch logic between the upper and lower computers.
[0036] The method for preventing misoperation of electrical equipment based on upper and lower computer synchronization includes the following steps: Taking the closing of the grounding switch on the 3 / 2 connection busbar of the switch station as an example: Step 1. Drag and drop the INTLK interlocking module in HCON and configure the input conditions (such as associating circuit breaker tamper signals and disconnector switch position signals).
[0037] Step 2. Compile and generate the latch program and deploy it to the host computer. The slave computer creates the same latch logic using programming software.
[0038] Step 3. When the operator clicks the closing command on the OIX interface, the PDC process of the host computer calls the interlocking program to determine in real time whether the conditions are met.
[0039] Step 4. If satisfied, the instruction is transmitted to the lower-level LCU via the control bus. After the lower-level LCU performs a secondary verification of the interlocking logic, it closes the relay contacts in the hard-wired control circuit to complete the closing operation.
[0040] Step 5. If the conditions are not met, the HCON screen will display a message such as "Circuit breaker not tripped," guiding maintenance personnel to handle the issue on-site.
[0041] Regarding exception handling: 1. When an operation anomaly occurs, maintenance personnel can view the Chinese description of the unmet conditions displayed on the HCON screen to directly locate the fault point and carry out targeted handling, reducing the time spent on traditional PLC online debugging.
[0042] 2. Implementation of measures to prevent "empty trips" Software Measures: After each manual operation of the equipment, the operator must press the "Continue" and "Execute" buttons sequentially on the control terminal for the system to recognize the operation as complete. During the pre-operation simulation of switches and disconnectors, the system adds a prompt after the switching operation item and transmits it to the control terminal. After the actual operation is completed and confirmed according to the above steps, the control terminal displays the prompt. The operator verifies that everything is correct and then presses the "Continue" and "Execute" buttons again to proceed to the next step. An air raid interlock type setting is used, and the control terminal automatically requests a check of the actual position. Only after the code following the operation is checked can subsequent operations proceed.
[0043] Hardware measures: For padlocks, accurately install the status identifier in the open and closed positions of the switch, and use accessories to ensure that the control terminal can accurately read the unique status identifier code in the corresponding position. For fixed locks, ensure that they are securely installed, and that the blocking device should pop out normally when the lock is not locked to prevent the relevant operating parts of the control terminal from being inserted. Only when the lock is locked can the relevant operating parts of the control terminal be inserted to read the code and perform operations.
[0044] The embodiments described in this specification are merely examples of implementations of the inventive concept. The scope of protection of this invention should not be considered as limited to the specific forms stated in the embodiments. The scope of protection of this invention also extends to equivalent technical means that can be conceived by those skilled in the art based on the inventive concept.
Claims
1. An electrical equipment anti-misoperation operating system based on upper and lower computer synchronization, characterized in that, It includes a host computer interlocking module, a slave computer execution unit, a compilation module, a real-time database, and a human-machine interface; The host computer interlocking module is connected to the compilation module, the real-time database, and the human-machine interface respectively. It is used to build the interlocking logic model and transmit it to the compilation module, obtain equipment status data from the real-time database, and transmit interlocking information to the human-machine interface. The lower-level execution unit is connected to the compilation module and the upper-level interlocking module respectively, and is used to receive the interlocking logic issued by the compilation module, receive the upper-level operation instructions and feedback the execution status. The compilation module connects the host computer and the slave computer, and is used to compile the host computer logic and synchronize it to both. The real-time database is connected to the host computer and the slave computer respectively, and is used to store and provide device status data; The human-machine interface is only connected to the host computer and is used to display the lockout status and the reason for operation failure.
2. The electrical equipment anti-misoperation operating system based on upper and lower computer synchronization according to claim 1, characterized in that, The host computer interlocking module constructs an interlocking logic model based on the HCON graphical configuration tool.
3. The electrical equipment anti-misoperation operating system based on upper and lower computer synchronization according to claim 1, characterized in that, The lower-level execution unit is a PLC or a local control unit (LCU), which has a built-in interlocking logic program consistent with that of the upper-level unit.
4. A method for preventing misoperation of electrical equipment using the upper and lower computer synchronization-based operating system according to any one of claims 1 to 3, characterized in that, Includes the following steps: Step 1: Logic Modeling. Construct the interlocking logic model using the HCON configuration tool. Input conditions include device status signals (IN). ) and custom Chinese description (Str ); Step 2: Logic synchronization. Use the PCC compiler to compile the model into a unified latch program and generate a latch file name; embed the latch program synchronously into the host computer command module, and set the same latch logic on the slave computer through programming software. Step 3: Operation control. Before the host computer issues an operation command, the PDC process calls the interlocking program to verify the condition satisfaction in real time. If the condition is satisfied, the command is transmitted to the lower computer via the control bus. The lower computer then triggers the hard-wired control loop after verifying the interlocking logic a second time. If the condition is not satisfied, the OIX interface pops up the HCON interlocking screen and displays a Chinese description of the unsatisfied condition. Step 4: Operation Confirmation and Air Raid Travel. After each actual operation, press the confirmation key in sequence on the control terminal of the operating equipment for the system to recognize the operation as complete. When operating switches or disconnectors, the system adds a prompt operation after the switching operation item and transmits it to the control terminal. The operator must verify that it is correct before proceeding to the next step. When using air raid lock type settings, the control terminal automatically requires checking the code after the operation. Only after verification can the operation continue. Step 5: Troubleshooting. Maintenance personnel can directly locate the fault point through the HCON screen.
5. The method for preventing misoperation of electrical equipment based on synchronization between upper and lower computers according to claim 4, characterized in that, Step 4 also includes software measures to prevent "empty travel". The software measures are as follows: when the switch and disconnector are rehearsed, the system adds prompting operations after the switching operation items and transmits them to the control terminal. If the operation sequence is found to be missing during the rehearsal, the operator is prompted to supplement and improve it.
6. The method for preventing misoperation of electrical equipment based on synchronization between upper and lower computers according to claim 4, characterized in that, Step 4 also includes hardware measures to prevent "empty travel". The hardware measures are as follows: for padlock type locks, status identifiers are installed at the open and closed positions of the knife switch, and with the help of accessories, the control terminal can only read the code of one status identifier at one position. When the lock is not locked, the internal blocking device pops out to prevent the control terminal operating component from being inserted. Only when the lock is locked can the control terminal operating component be inserted to read the code, unlock and perform the current operation, and then proceed to the next operation.
7. The method for preventing misoperation of electrical equipment based on synchronization between upper and lower computers according to claim 4, characterized in that, In step 1, during the logic modeling process, logic modules are dragged and dropped using the HCON configuration tool, and input conditions are configured to complete the construction of the logic model.
8. The method for preventing misoperation of electrical equipment based on synchronization between upper and lower computers according to claim 4, characterized in that, In step 2, during the logic synchronization process, the lower-level machine obtains a program through programming software that is completely identical to the locking logic program compiled by the PCC compiler on the upper-level machine, thereby realizing the synchronous deployment of the locking logic between the upper and lower-level machines.
9. The method for preventing misoperation of electrical equipment based on synchronization between upper and lower computers according to claim 4, characterized in that, In step 3, the operation control adopts a dual closed-loop verification method of upper computer prediction and lower computer execution. After the upper computer PDC process calls the interlocking program and passes the verification, the instruction is transmitted to the lower computer, and the lower computer verifies the interlocking logic again. Only after the dual verification is passed will the hard-wired control loop be triggered.
10. The method for preventing misoperation of electrical equipment based on synchronization between upper and lower computers according to claim 4, characterized in that, During the exception handling in step 5, the Chinese description of the unmet conditions displayed on the HCON screen includes the status of the associated device and the interlocking logic path. The maintenance personnel can directly locate the fault point based on this description.