A remote spare power source automatic throw-in linkage protection setting value area dynamic switching system and switching method

CN122393850APending Publication Date: 2026-07-14STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID HUNAN ELECTRIC POWER COMPANY LIMITED
Filing Date
2026-04-20
Publication Date
2026-07-14

AI Technical Summary

Technical Problem

In existing technologies, the switching of protection setting zones after the operation of remote backup automatic transfer devices relies on manual operation, resulting in long time delays, poor adaptability, affecting the grid recovery efficiency and increasing the operation and maintenance pressure. It is also difficult to adapt to the complex and ever-changing grid operation modes after the integration of new energy sources.

Method used

Design a remote backup automatic transfer linkage protection setpoint zone dynamic switching system, including a perception and execution layer, a data transmission layer, and a scheduling automation system. Through an intelligent verification engine, a hierarchical dynamic security interlocking strategy, and an access control module, the system enables automatic and rapid switching of the setpoint zone, ensuring that the switching command is triggered at the correct time and under safe conditions.

Benefits of technology

It enables automatic, rapid, and accurate switching of line protection settings after successful remote backup automatic transfer, eliminating manual delays, reducing switching time from minutes to seconds, eliminating the risk of malfunctions, and improving the transparency and reliability of power grid operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122393850A_ABST
    Figure CN122393850A_ABST
Patent Text Reader

Abstract

The application discloses a kind of remote spare power automatic switching linkage protection fixed value area dynamic switching system and switching method, system includes: perception execution layer, deployment is in substation side, including intelligent remote spare power automatic switching device, protection information management substation and line protection device;Data transmission layer is the communication network based on electric power dispatching data network, and there is security I area and security II area, and longitudinal encryption authentication device is deployed, for realizing the encryption authentication and safe transmission of cross security area data;Data acquisition and monitoring system is deployed in dispatching main station security I area, for realizing power grid real-time data acquisition, transmission and basic monitoring;Dispatching automation system is deployed in dispatching main station, and integrated with multidimensional intelligent checking engine, instruction linkage control module, authority management module, man-machine interaction module, risk early warning module and whole-process log archiving module.The application has the advantages of high automation, intelligentization, safety and reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention mainly relates to the field of power system relay protection and automation technology, specifically to a remote backup automatic transfer linkage protection setting zone dynamic switching system and switching method. Background Technology

[0002] With the large-scale integration of distributed photovoltaic, wind power, and other new energy sources into the power grid, the power flow direction, short-circuit current level, and operating mode of the distribution network and even some transmission networks have become increasingly complex and variable, placing higher demands on the reliability of power supply and the accuracy of protection coordination. Remote automatic transfer switches (ATS), as core equipment for improving power supply reliability, have been widely used in the power grid. Their core function is to quickly close the backup power supply line or tie switch of the adjacent substation after a failure of the main power supply at the local station, thereby achieving load transfer and power restoration.

[0003] The protection devices for tie lines or feeders connecting two substations must be adapted to both "main power supply operation mode" and "standby power supply operation mode," typically with at least two setting zones. Under these two operating modes, the system equivalent impedance, short-circuit current level, and protection coordination relationships differ significantly. The corresponding protection settings (including overcurrent settings, distance settings, protection delays for each section, reclosing methods, etc.) must be adjusted accordingly; otherwise, the protection devices will become incompatible with the current operating mode.

[0004] Currently, the switching of protection setting zones after remote automatic transfer switch operation relies entirely on manual operation. Specifically: after the remote automatic transfer switch activates and sends an alarm signal, the dispatcher assesses the situation using the D5000 system and then notifies the maintenance personnel at the substations on both sides of the tie line or feeder by telephone. Upon receiving the instruction, the maintenance personnel rush to the site and manually complete the setting zone switching on the protection device. This traditional mode has the following significant drawbacks: First, the long time delay affects restoration efficiency and poses significant risks. From the occurrence of the automatic transfer switch action, dispatch judgment, and instruction issuance to the completion of on-site operations on both sides, the entire process takes 30-60 minutes or even longer. During this period, the protection device operates under settings that are incompatible with the current operating mode, making it highly susceptible to maloperation or failure to operate due to changes in short-circuit current or reversal of power flow direction, leading to secondary faults and expanding the power outage area.

[0005] Secondly, it suffers from poor adaptability and high operation and maintenance costs and pressure. After the integration of new energy sources, the power grid operation mode changes frequently. The manual switching mode cannot meet the needs of rapid response and is difficult to adapt to the complex and ever-changing power grid conditions. The frequent need for manual operation brings huge pressure and labor costs to the operation and maintenance team.

[0006] Therefore, there is an urgent need to design a system and method that can realize the automatic linkage switching of remote backup automatic transfer devices and protection device setting zones, break down the data barriers between existing systems, replace manual operation, improve switching efficiency and reliability, and adapt to the grid operation requirements after the integration of new energy sources. Summary of the Invention

[0007] To address the technical problems existing in the prior art, this invention provides a highly automated, intelligent, safe and reliable remote backup automatic transfer linkage protection setpoint dynamic switching system and switching method.

[0008] To solve the above-mentioned technical problems, the technical solution proposed by this invention is as follows: A remote backup automatic transfer linkage protection setting zone dynamic switching system includes: The perception and execution layer, deployed on the substation side, includes an intelligent remote automatic transfer switch, a protection information management substation, and a line protection device. The intelligent remote automatic transfer switch generates and uploads a closing event identifier carrying an encrypted identifier after a successful remote automatic transfer operation. The protection information management substation receives setting zone switching instructions and forwards them to the line protection device. The line protection device is configured with at least two setting zones corresponding to different power supply operating modes and embeds a hierarchical dynamic safety interlocking strategy execution unit for receiving and safely executing setting zone switching instructions. The data transmission layer is a communication network based on the power dispatch data network. It is divided into Security Zone I and Security Zone II, and a vertical encryption and authentication device is deployed to realize the encryption authentication and secure transmission of data across security zones. The data acquisition and monitoring system is deployed in Security Zone I of the dispatch master station to realize real-time data acquisition, transmission and basic monitoring of the power grid. The dispatch automation system, deployed at the dispatch master station, integrates a multi-dimensional intelligent verification engine, a command linkage control module, a permission management module, a human-machine interaction module, a risk warning module, and a full-process log archiving module. The multi-dimensional intelligent verification engine performs progressive security verification on received closing event identifiers. The command linkage control module generates switching commands for the target backup setpoint area. The permission management module allocates and verifies operation permissions. The human-machine interaction module provides an integrated interface for dispatchers to operate and monitor. The risk warning module pushes alarms and risk alerts. The full-process log archiving module generates, synchronizes, and archives operation records.

[0009] Preferably, the multi-dimensional intelligent verification engine embedded in the dispatch automation system integrates a basic information integrity verification module, a power grid real-time topology and status verification module, a trigger event uniqueness and purity verification module, and a setpoint area pre-matching and risk assessment module, which are executed sequentially. This module is used to perform a four-level progressive security verification on the received closing event identifier. After the verification is passed, the result is pushed to the human-machine interaction module.

[0010] Preferably, the intelligent remote backup automatic transfer device further includes: The event ID generation unit is used to generate a unique event ID based on the line ID, action timestamp, and random number using the national cryptographic SM3 hash algorithm, and embed it into the closing event identifier; The spatiotemporal correlation analysis unit is used to verify the time synchronization accuracy of the trigger source through the PTP precision clock protocol and to verify the interconnection status of the line by calling the CIM model API interface, and to comprehensively determine that the trigger source is a legitimate remote backup automatic transfer action.

[0011] Preferably, the real-time power grid topology and status verification module directly calls the real-time database and acquisition service of the data acquisition and monitoring system to perform the following verifications: The protection device status monitoring unit is used to detect the communication status and alarm signals of the target protection device through the protection information system interface, requiring normal communication and no serious abnormalities. The topology status judgment unit is used to combine the CIM model with the real-time switch position collected by the data acquisition and monitoring system to confirm that the line is in the standby automatic transfer closed state.

[0012] Preferably, the trigger event uniqueness and purity verification module includes: The time window event retrieval unit is used to retrieve all historical event records of the same line within the most recent preset time period from the historical event database of the data acquisition and monitoring system; The event type matching unit is used to verify the retrieved event records, ensure that the current triggering event is a valid remote backup automatic transfer action, and exclude reclosing after protection tripping and manual remote control interference signals.

[0013] Preferably, the setting area pre-matching and risk assessment module includes a setting area data retrieval unit, which is used to retrieve the preset numerical and logical setting values ​​of the backup setting area of ​​the line protection device from the protection information management substation through a standard interface, and after completing the pre-matching, form a backup setting area switching suggestion, which is pushed to the human-machine interaction module of the dispatch automation system for the dispatcher to confirm.

[0014] Preferably, the hierarchical dynamic safety interlocking strategy execution unit embedded in the line protection device includes: The pre-locking stage unit is used to lock out the protection function and reclosing output by modifying the internal data attributes to a prohibited state after receiving a switching command. The core switching phase unit is used to perform the setting area switching operation, retain the setting value reading and writing, parameter verification, and event logging functions, and performs CRC verification on the new setting area parameters after the switching is completed; The interlock release phase unit is used to prioritize restoring the delayed protection function with the data attribute set to the allowed state after the switching is completed and the verification is passed. After short delay monitoring, the protection and reclosing functions are then restored.

[0015] Preferably, the full-process log archiving module of the scheduling automation system includes: The operation log generation unit is used to automatically generate an operation log ledger that includes the time of backup automatic transfer action, action type, set value verification result, dispatcher confirmer, switch execution time, switch result and device status. The data archiving unit is used to synchronize the operation record ledger to the protection information management substation and the historical database of the dispatch automation system itself for archiving.

[0016] This invention also discloses a switching method based on the remote backup automatic transfer linkage protection setting zone dynamic switching system as described above, comprising the following steps: S1. After the intelligent remote backup automatic transfer device completes the load transfer, it generates a closing event identifier carrying a unique event ID. After being filtered by the measurement and control device through the GOOSE protocol, it is uploaded to the dispatch automation system of the dispatch master station. S2. The dispatch automation system performs a four-level progressive verification through its embedded multi-dimensional intelligent verification engine: first, it performs a basic information integrity verification; second, it performs a real-time power grid topology and status verification; third, it performs a trigger event uniqueness and purity verification; and finally, it performs a setting area pre-matching and risk assessment. After all verifications are passed, the dispatch automation system generates a verification report and a backup setting area switching suggestion, and pushes it to the integrated interface of its human-machine interaction module. S3. The dispatcher views the verification report and suggestions through the integrated interface of the dispatch automation system and executes the dual-person dual-confirmation mechanism. Two authorized dispatchers complete the operation confirmation and monitoring confirmation in turn. The confirmation instructions and identity information are sent to the permission management module embedded in the dispatch automation system for verification. S4. After the permission verification is passed, the instruction linkage control module of the dispatch automation system generates a switching instruction containing the target setpoint area number, event ID and verification pass identifier, and sends it to the protection information management substation on the substation side through the power dispatch data network encrypted with the national cryptographic SM2 / SM4 algorithm. S5. After receiving the switching command, the protection information management substation forwards it to the line protection device via the IEC 61850 MMS protocol; S6. After receiving the command, the line protection device synchronously starts the embedded hierarchical dynamic safety interlocking strategy: first, it enters the pre-interlocking stage, interlocking the protection and reclosing output; then it enters the core switching stage, performing setting area index switching and parameter loading. After the switching is completed, CRC verification is performed on all parameters in the new setting area; after the verification is passed, it enters the interlocking release stage, restoring all protection and reclosing functions. S7. After a successful or unsuccessful handover, the line protection device will send a feedback signal containing the CRC check result, handover status, and timestamp to the protection information management substation via the GOOSE protocol. S8. After the protection information management substation collects and feeds back the feedback signals, it transmits them back to the dispatch automation system through the encrypted power dispatch data network; S9. The dispatch automation system receives feedback signals, updates the status display of the setting area of ​​the relevant line protection device through the human-machine interaction module, and pushes the switching result notification through the risk warning module. S10. The full-process log archiving module of the dispatch automation system automatically generates a structured operation record ledger and archives the ledger synchronously to the historical database of the protection information management substation and the historical database of the dispatch automation system itself.

[0017] Preferably, in step S2, the basic information integrity verification requires that the event identifier format be compliant, the timestamp error be ≤5ms, the line ID exist in the CIM model, and it is a dual-power interconnection structure; the real-time topology and status verification of the power grid verifies that the communication status of the protection device is normal and there are no serious abnormal alarms through the protection information management substation, and confirms that the line is in the "backup automatic transfer action closing" state; the uniqueness and purity verification of the trigger event confirms that there are no protection tripping or manual remote control interference operation records for the same line in the historical event database of the data acquisition and monitoring system within the last 30 seconds; the setting area pre-matching and risk assessment retrieves the numerical and logical setting values ​​of the backup setting area preset by the line protection device from the protection information management substation through the standard interface for integrity check. If there are null values, an error risk alarm for the setting area is generated.

[0018] Compared with the prior art, the advantages of the present invention are as follows: This invention enables automatic, rapid, and accurate switching of line protection setting zones after a successful remote backup automatic transfer, eliminating manual delays and reducing switching time to minutes or even seconds. By enhancing and reconstructing the underlying dispatch automation system (D5000), an embedded multi-dimensional intelligent verification mechanism is established to ensure that switching commands are triggered only at the correct time, on the correct equipment, and under safe grid conditions, fundamentally eliminating false triggering. A hierarchical dynamic safety interlocking logic is designed and implemented in the line protection device to ensure the safety of the protection device's behavior during setting zone switching, effectively preventing protection malfunctions caused by switching disturbances. A traceable architecture covering the entire process of perception, transmission, decision-making, execution, and feedback is constructed, with the enhanced D5000 system at its core, achieving closed-loop management from event triggering, intelligent decision-making, safe execution to result archiving, significantly improving the transparency, reliability, and intelligence level of power grid operations. Attached Figure Description

[0019] Figure 1 This is a block diagram of the remote backup automatic transfer linkage protection setting zone dynamic switching system according to an embodiment of the present invention.

[0020] Figure 2 This is a flowchart of the method for dynamic switching of remote backup automatic transfer linkage protection setting zone according to an embodiment of the present invention. Detailed Implementation

[0021] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.

[0022] like Figure 1 As shown, the remote backup automatic transfer linkage protection setting zone dynamic switching system provided in this embodiment of the invention includes: The sensing and execution layer, deployed on the substation side, includes intelligent remote automatic transfer switch (ATS), protection information management substation (PES substation), and line protection devices (including protection devices for substations A and B). The intelligent remote automatic transfer switch generates and sends a closing event identifier carrying an encrypted identifier after the remote automatic transfer operation is successful. The PES substation receives setting zone switching instructions via the IEC 61850 MMS protocol and forwards them to the protection devices for substations A and B. The line protection devices are equipped with at least two setting zones corresponding to different power supply operation modes and have embedded hierarchical dynamic safety interlocking strategy execution units for receiving and safely executing setting zone switching instructions. The data transmission layer is a communication network based on the power dispatch data network. It is divided into security zone I and security zone II, and a vertical encryption authentication device using the national cryptographic SM2 / SM4 algorithm is deployed to realize the encryption authentication and secure transmission of data across security zones, and support the encrypted distribution link of switching instructions. The Supervisory Control and Data Acquisition (SCADA) system is deployed in Security Zone I of the dispatch master station to realize real-time data acquisition, transmission and basic monitoring of the power grid, and to provide data support for upper-level processing. The D5000 dispatch automation system, deployed at the dispatch master station, enhances its functionality through an embedded dedicated processing architecture. It integrates a multi-dimensional intelligent verification engine, a command linkage control module, a permission management module, a human-machine interaction module, a risk warning module, and a full-process log archiving module, serving as the core processing and interaction carrier of the system. Specifically, the multi-dimensional intelligent verification engine performs progressive security verification on received closing event identifiers; the command linkage control module generates switching instructions for the target standby setpoint area after dispatcher confirmation; the permission management module allocates and verifies operating permissions; the human-machine interaction module provides an integrated interface for dispatcher operation and monitoring; the risk warning module pushes various alarms and risk alerts; and the full-process log archiving module generates, synchronizes, and archives operation records.

[0023] Specifically, the multi-dimensional intelligent verification engine embedded in the D5000 system serves as the core decision-making component. It integrates a basic information integrity verification module, a real-time power grid topology and status verification module, a trigger event uniqueness and purity verification module, and a setting area pre-matching and risk assessment module, which are executed sequentially. This module performs a four-level progressive security verification on the received closing event identifier. After the verification is passed, the result is pushed to the human-machine interaction module for the dispatcher to confirm whether to switch to the corresponding backup setting area.

[0024] Specifically, the intelligent remote backup automatic transfer device also includes: The event ID generation unit is used to generate a unique event ID based on the line ID, action timestamp and random number using the national cryptographic SM3 hash algorithm, and embed it into the closing event identifier to ensure that the trigger source cannot be tampered with. The spatiotemporal correlation analysis unit is used to verify the time synchronization accuracy of the trigger source through the PTP precision clock protocol, requiring an error of ≤1ms. It also verifies the interconnection status of the line by calling the CIM model API interface, and comprehensively determines that the trigger source is a legitimate "remote backup automatic transfer" action.

[0025] Specifically, the real-time topology and status verification module of the power grid directly calls the real-time database and acquisition service of the SCADA system to perform the following verifications: The protection device status monitoring unit is used to detect the communication status and alarm signals of the target protection device through the protection information system interface, requiring normal communication and no serious abnormalities. The topology status judgment unit is used to combine the CIM model with the real-time switch position collected by SCADA to confirm that the line is in the "backup automatic transfer operation closed" state.

[0026] Specifically, the uniqueness and purity verification module for triggering events includes: The time window event retrieval unit is used to retrieve all historical event records of the same line within the last 30 seconds from the SCADA system's historical event database. The event type matching unit is used to verify the retrieved event records, ensure that the current triggering event is a valid remote backup automatic transfer action, and exclude other types of interference signals such as reclosing after protection tripping and manual remote control.

[0027] Specifically, the setting area pre-matching and risk assessment module includes a setting area data retrieval unit, which is used to retrieve the preset numerical and logical setting values ​​of the backup setting area of ​​the line protection device from the protection information substation through a standard interface. After completing the pre-matching, a backup setting area switching suggestion is generated and pushed to the human-machine interaction module of the D5000 system for the dispatcher to confirm.

[0028] Specifically, the hierarchical dynamic safety interlocking strategy execution unit embedded in the line protection device includes: The pre-locking stage unit is used to lock out the protection function and reclosing output by modifying the internal data attribute to "prohibited" state within ≤10ms after receiving the switching command. The core switching phase unit is used to perform the setting area switching operation, retain the setting value reading and writing, parameter verification, and event logging functions, and performs CRC verification on the new setting area parameters after the switching is completed; The interlock release phase unit is used to prioritize restoring the delayed protection function with the data attribute set to "allowed" after the switching is completed and the verification is passed. After a short delay of 20ms monitoring to ensure that the system transient process is stable, the protection and reclosing functions are then restored.

[0029] Specifically, the core switching phase unit also includes switching failure rollback logic. When the CRC check fails or the switching times out, it automatically rolls back to the original value area, triggers the highest level local alarm and reports it to the D5000 system, and records the reason for the switching failure.

[0030] Specifically, the permission management module embedded in the D5000 system sets up three levels of operation permissions for dispatchers, maintenance personnel, and administrators, and is integrated into its human-machine interaction module. Only authorized dispatchers can issue switching confirmation commands. The "dual-person dual-confirmation" mechanism requires two authorized dispatchers to complete the operation and monitoring confirmation through the D5000 system integration interface. Only after the confirmation is passed can the command linkage control module be triggered to generate a switching command.

[0031] Specifically, the full-process log archiving module of the D5000 system includes: The operation log generation unit is used to automatically generate an operation log ledger that includes the time of backup automatic transfer action, action type, set value verification result, dispatcher confirmer, switch execution time, switch result and device status. The data archiving unit is used to synchronize the operation record ledger to the Baoxin substation and the D5000 system's own historical database for archiving.

[0032] The system of this invention deeply relies on and reuses the existing power dispatching data network and the architecture of the master station and station-end equipment. Its core innovation lies in the underlying enhancement and functional reconstruction of the dispatching automation system (D5000) of the dispatching master station. By embedding a dedicated processing architecture and core software modules, it deeply integrates core capabilities such as multi-dimensional intelligent verification, security policy control, access management and application interaction into the D5000 system, making it the "intelligent decision and control center" of the entire linkage switching scheme.

[0033] Specifically, this invention can be divided into a perception and execution layer, a data transmission layer, and a core processing and application layer, with the three layers working collaboratively from top to bottom. The technical requirements and functions of each layer's components are as follows: 1. Perception and Execution Layer 1.1 Intelligent remote backup automatic transfer device Action detection: Local / remote action detection logic needs to be integrated. Subsequent linkage processes can only be triggered when the "remote backup self-connection" action is confirmed to be successful.

[0034] 1.2 Line protection devices (including protection devices for stations A and B) Setting area management: At least two setting areas must be pre-configured (such as "main power supply setting area" and "standby power supply setting area"), with complete parameters for each area, and settings completed for different operating modes.

[0035] Safety interlocking logic: A hierarchical dynamic safety interlocking strategy execution unit (software function module) must be embedded.

[0036] 1.3 Baoxin Sub-site As a key connecting component between the perception execution layer and the data transmission layer, it is responsible for receiving the encrypted setting area switching command issued by the D5000 system, and forwarding the command accurately and reliably to the designated line protection devices of station A and station B through the IEC 61850 MMS protocol; at the same time, it receives the switching result feedback signal returned by the protection device, summarizes it and sends it back to the D5000 system, and synchronously stores the relevant operation log data to support subsequent query.

[0037] 2. Data transmission layer The existing power dispatch data network must be utilized, and its security zoning principle must be clearly followed. At key gateways for cross-regional communication, vertical encryption authentication devices that meet the security requirements of the National Energy Administration and the industry must be deployed.

[0038] 3. Core Processing and Application Layer 3.1 Embedded multi-dimensional intelligent verification engine: As the core decision-making component of the dedicated processing architecture within the D5000 system, this engine exists as a kernel service or a deeply integrated high-level application module. It calls the SCADA system's real-time database, historical event database, and external system resources (such as the security information system) through standardized interfaces. The engine must serially execute four levels of progressive security checks; if any check fails, the process immediately terminates and triggers a detailed alarm.

[0039] 3.2 Embedded command linkage control module: This module, as the core control output component of the dedicated processing architecture within the D5000 system, works in conjunction with the multi-dimensional intelligent verification engine and the access control module. It receives a "all four levels of verification passed" signal and a complete verification report from the intelligent verification engine. It also receives the dispatcher's final confirmation instruction, verified by the access control module. Furthermore, it generates strictly formatted and complete remote control instructions for setting zone switching. These switching instructions are then securely and reliably transmitted to the substation's information protection substation via a dedicated power dispatch data network channel encrypted with national cryptographic algorithms.

[0040] 3.3 Embedded access control and auditing module: This module serves as the core of security and auditing within the dedicated processing architecture of the D5000 system, deeply integrated into its human-computer interaction and business process system. It implements three-tiered, fine-grained management based on users, roles, and permissions, defining three roles: "Dispatcher," "Operation and Maintenance Monitor," and "System Administrator." When the system handles the switching process of critical or important lines, it is mandatory for two users, both with "Dispatcher" permissions, to sequentially and independently complete the confirmation operation through the D5000 system interface.

[0041] The system automatically records and immutably associates and stores data across the entire chain, from receiving closing event identifiers, logs of verification processes at all levels, dispatcher confirmation records, instruction generation and issuance logs, and execution and feedback results of protection devices, forming a complete and legally binding electronic operation ticket that supports full post-event traceability and liability determination.

[0042] 3.4 Embedded human-computer interaction and full-process log archiving module: The D5000 system interface provides a dedicated human-machine interaction view for "intelligent linkage switching of setpoint areas". It receives and prominently displays pop-up windows of "setpoint area switching requests" pushed by the multi-dimensional intelligent verification engine, complete reports containing verification details at all levels, and setpoint area pre-matching results and risk warning information in real time; it provides operation buttons such as "confirm execution" and "reject", and the operation instructions and operator identity information are directly passed to the permission management module for real-time verification.

[0043] After each complete linkage switchover process is completed, the system automatically generates a structured and detailed operation record ledger.

[0044] like Figure 2 As shown, this embodiment of the invention also provides a method for dynamic switching of the remote backup automatic transfer linkage protection setting area based on the system described above, realizing automatic, safe, and rapid linkage switching of the protection device setting area after the remote backup automatic transfer action, including the following steps: S1: After the remote intelligent backup automatic transfer device completes the load transfer, it generates a closing event identifier carrying a unique event ID. The event ID is generated by the national cryptographic SM3 hash algorithm and includes the line ID, action timestamp and random number. After being filtered by the measurement and control device for 200ms anti-jitter through the GOOSE protocol, it is uploaded to the D5000 system of the dispatch master station. S2: After receiving the event identifier, the D5000 system immediately activates its embedded multi-dimensional intelligent verification engine, serially executing a four-level progressive security verification: (i) Perform basic information integrity verification: parse the format of each field of the closing event identifier, verify that the time stamp and the time error of the master station are ≤5ms, verify that the line ID exists in the CIM model and its equipment type is "AC line segment" and the number of associated substations is 2.

[0045] (ii) Perform real-time power grid topology and status verification: Verify the target protection device's communication status is normal and there are no serious alarm signals such as "device abnormality" through real-time calls via the protection information substation interface. Combine the CIM model with the real-time switch positions collected by SCADA to confirm that the line is in the "backup automatic transfer closed" state.

[0046] (iii) Perform uniqueness and purity verification of the trigger event: Search the historical event database of the SCADA system, query all event records within the most recent 30-second time window with the target line ID as the condition, and verify that the currently received closing event identifier is unique on the line within the window period and the event type clearly matches "remote backup automatic transfer action", effectively eliminating other interference signals such as protection tripping reclosing and manual remote control.

[0047] (iv) Perform setting area pre-matching and risk assessment: retrieve all numerical and logical settings in the preset backup setting area of ​​the line protection device from the Baoxin substation through a standardized interface, and perform integrity checks and pre-matching analysis; if null values ​​or illegal parameters are found, generate detailed setting area error risk alarms.

[0048] When any level of verification fails, the D5000 system pushes an alarm containing detailed conflict event information to its own integrated interface through its risk warning module, and provides intervention options such as "ignore and continue", "terminate process" or "transfer to manual judgment" for the dispatcher to operate.

[0049] S3. After all four levels of verification pass, the D5000 system proactively pushes a switching reminder to the dispatcher through its human-machine interaction module. This reminder can be sent via audible and visual alarms or a dedicated pop-up window, clearly displaying the "Setting Area Switching Request," a complete verification report summary, and setting pre-matching details. The dispatcher then logs into the D5000 system's dedicated integrated interface to perform the operation. The operation request and the dispatcher's identity information are transmitted in real-time to the D5000's embedded access control module for verification. All lines require two authorized dispatchers to perform a double-confirmation process. After the dispatcher completes the confirmation, the D5000 system automatically records the confirmation time, operator account, IP address, and terminal information, and archives this data along with the final generated operation log.

[0050] S4. After the confirmation command passes the verification by the access control module, the command linkage control module embedded in the D5000 system is immediately triggered. This module generates a standardized setting zone switching command, which includes the target setting zone number, event ID, etc., and is encrypted by a vertical encryption device that enables the national cryptographic SM2 / SM4 algorithm before being securely sent to the information protection substation of the target substation via the power dispatch data network; S5. After receiving the encrypted switching command, the security information substation decrypts and parses it, and then forwards the switching command accurately and reliably to the corresponding line protection devices of station A and station B through the IEC 61850 MMS protocol. The protection devices at stations S6.A and B receive the switching command almost simultaneously and immediately activate the embedded hierarchical dynamic safety interlocking strategy execution unit, executing them sequentially: (i) Pre-locking stage: After the command arrives, the device sets the data attributes of the relevant fast-acting protection and reclosing functions to the "prohibited" state through software logic, thereby blocking the output of protection and reclosing.

[0051] (ii) Core Switching Phase: The device enters a "switching" safe state (lasting approximately 10-20ms). During this period, management functions such as setting area read / write, parameter verification, and event logging operate normally. The device performs setting area index switching and new parameter loading operations. During the core switching phase, the total time for the protection device to perform setting area switching and parameter loading should be controlled within 10-20ms, and CRC32 verification should be performed on the new parameters to ensure integrity.

[0052] (iii) Lockout release stage: After the setting zone switching operation is completed and the CRC check of the newly loaded parameters passes, the device restores the output functions of all protection and reclosing functions.

[0053] (iv) Failure rollback handling: If a CRC check failure or a timeout is detected during the core switching phase, the system will immediately and automatically roll back to the original value area before the switch, trigger the highest level alarm on the device, and generate an alarm message with a reason code and send it up.

[0054] S7. After a successful or failed switch, the protection device will generate a feedback signal containing information such as "switching result status", "CRC check result", and "timestamp", and upload it to the security information substation of this station via the GOOSE protocol; S8. After receiving the feedback signals from the protection devices of stations A and B, the protection information substation packages them and transmits them back to the D5000 system of the dispatch master station through the encrypted dispatch data network. After receiving the feedback signal, the S9.D5000 system analyzes the result and updates the status of the protection device setting area to "switching complete" or "switching failed" in the relevant monitoring screen through its human-machine interaction module. At the same time, it pushes the final result notification to the dispatcher through the risk warning module. The S10.D5000 system's full-process log archiving module automatically triggers, generating a detailed and structured record of the entire operation process, covering information from all key stages. The system then synchronously archives this record to the substation's information protection substation's historical database and the D5000 system's own historical database, completing a full closed-loop management process of "event triggering - intelligent decision-making - safe execution - feedback archiving".

[0055] The present invention relates to a dynamic switching system and method for remote backup automatic transfer linkage protection setting zone based on multi-dimensional intelligent verification. It is applicable to distribution networks and transmission networks with voltage levels of 35kV and above that include distributed photovoltaic, wind power and other new energy sources. It is especially suitable for dual power supply interconnection lines with frequent switching of main and backup power supply operation modes.

[0056] This invention addresses the low efficiency and high risk of false triggering caused by manual switching of protection settings after remote automatic transfer switching (ATS) in the context of renewable energy integration. It enhances and reconstructs the underlying functions of the D5000 dispatch automation system. Through an embedded dedicated processing architecture, it deeply integrates a multi-dimensional intelligent verification engine, access control, and command control modules, internalizing core decision-making and safety control capabilities. The line protection devices adopt a hierarchical dynamic safety interlocking strategy, achieving zero-disturbance switching and reducing the switching time of the setting area from the traditional 30-60 minutes to 2-3 minutes, fundamentally eliminating the risk of false triggering. The system is built upon the existing power dispatch data network, adding only a safety interlocking logic unit at the substation side. Coordinated by the enhanced D5000 system, it works in conjunction with the SCADA system, is compatible with mainstream protection devices, and achieves full-link automation from "accurate identification of ATS actions—multi-dimensional verification and decision-making by the D5000 system—safe switching of protection devices—closed-loop archiving of the entire process," providing technical support for the safe and stable operation of distribution networks with a high proportion of renewable energy.

[0057] This invention enables automatic, rapid, and accurate switching of line protection setting zones after a successful remote backup automatic transfer, eliminating manual delays and reducing switching time to minutes or even seconds. By enhancing and reconstructing the underlying dispatch automation system (D5000), an embedded multi-dimensional intelligent verification mechanism is established to ensure that switching commands are triggered only at the correct time, on the correct equipment, and under safe grid conditions, fundamentally eliminating false triggering. A hierarchical dynamic safety interlocking logic is designed and implemented in the line protection device to ensure the safety of the protection device's behavior during setting zone switching, effectively preventing protection malfunctions caused by switching disturbances. A traceable architecture covering the entire process of perception, transmission, decision-making, execution, and feedback is constructed, with the enhanced D5000 system at its core, achieving closed-loop management from event triggering, intelligent decision-making, safe execution to result archiving, significantly improving the transparency, reliability, and intelligence level of power grid operations.

[0058] To better understand the above technical solutions, the system and method described in this invention will be described in detail below with reference to a specific 35kV power grid embodiment that includes distributed photovoltaic access.

[0059] In this embodiment of the invention, the power grid includes two 35kV substations, A and B, interconnected by a tie line L. Line protection devices are installed on both sides of the tie line L (A side and B side). To accommodate switching between primary and backup power sources, each protection device has two preset setting zones, for example: Protection devices at Station A: Setting Zone 1 (corresponding to Station A as the main power supply): Overcurrent Stage I setting 2800A / 0s, Stage II 1120A / 1s, Stage III 380A / 1.5s; reclosing mode is "Check line voltage, bus voltage" and "Check synchronization". Setting Zone 2 (corresponding to Station B as the main power supply): Overcurrent Stage I setting 2800A / 0s, Stage II 1120A / 1.8s, Stage III 380A / 2.1s; reclosing mode is "Check line voltage, bus voltage" and "Check synchronization".

[0060] Station B protection device: Setting zone 1 (corresponding to Station A as the main power supply): Overcurrent stage I setting 2800A / 0s, stage II 1120A / 1.8s, stage III 380A / 2.1s, reclosing mode is "check line voltage, bus voltage", "check synchronization". Setting zone 2 (corresponding to Station B as the main power supply): Overcurrent stage I setting 2800A / 0s, stage II 1120A / 1s, stage III 380A / 1.5s, reclosing mode is "check line voltage, bus voltage", "check synchronization".

[0061] The LA-side circuit breaker of the tie line is in the closed position, and the LB-side circuit breaker of the tie line is in the open position. Both stations A and B are equipped with intelligent remote backup automatic transfer devices that support the present invention. The dispatch center is equipped with the D5000 system, which has been enhanced and reconstructed according to the present invention, as well as the information protection substation that communicates with each station. All systems are securely interconnected through the existing power dispatch data network.

[0062] Implementation process: 1. Action triggering and signal acquisition and transmission stage: 1.1 Assume that the 35kV incoming line mainly supplied by station A loses power due to a fault. The intelligent remote backup automatic transfer device of station A detects the bus voltage loss, and after judgment by its built-in logic, confirms that the "remote backup automatic transfer" action needs to be executed. It then sends a closing command to station B and executes it successfully, completing the transfer of load from station A to station B.

[0063] 1.2 Upon successful operation, the A-station intelligent remote backup automatic transfer device immediately activates the event ID generation unit, inputting the following parameters: Line ID = L, Action timestamp = 14:32:15.123, and Random number = 123456789. Using the national cryptographic SM3 algorithm, a unique event ID (e.g., a 256-bit hash value) is generated. Subsequently, a standardized closing event identifier containing this event ID, line ID, timestamp, and action type code is generated.

[0064] 1.3 The closing event identifier is sent to the A-station monitoring and control device via the GOOSE protocol. The monitoring and control device performs anti-jitter filtering on the signal, and after confirming that the signal is a valid non-jitter signal, it converts it into a digital signal that can be transmitted through the dispatch data network, and uploads it to the dispatch master station through the power dispatch data network.

[0065] 1.4 The SCADA system in the main station's security zone I receives the digital signal and, according to the established forwarding rules, sends the event identification information to the D5000 system deployed at the main station.

[0066] 2. Intelligent Verification and Decision-Making Stage: 2.1 After receiving the closing event flag, the D5000 system automatically triggers its embedded multi-dimensional intelligent verification engine, which begins to serially execute four levels of verification: (i) Basic information verification: Check that the message format is complete; calculate that the error between the timestamp 14:32:15.123 in the event identifier and the D5000 system master station time 14:32:15.125 is 2ms (≤5ms), which passes; query the CIM model to confirm that line L exists, is of type AC line, and is associated with station A and station B at both ends respectively (dual power supply structure), which passes.

[0067] (ii) Real-time power grid status verification: The status of protection devices at stations A and B is checked via the information exchange interface. If "communication is normal" or "operation is normal" is returned, and there are no serious alarms, the verification is successful. Based on the CIM model, the SCADA-collected change in the switch position of the circuit breaker on the tie line LB station side from open to closed confirms that the line is in the "standby automatic transfer closed" state, thus the verification is successful. (iii) Event Purity Verification: The SCADA historical event database was searched to retrieve all events related to line L within 30 seconds prior to 14:32:15.123. The search results only displayed records related to this event, including "Overcurrent Stage II Protection Trip on Line XX of Station A" at 14:32:02.23, "Reclosing Action on Line XX of Station A" at 14:32:05.23, "Overcurrent Acceleration Protection Switch Trip on Line XX of Station A" at 14:32:05.323, "Remote Automatic Transfer Switch Action on Station A" at 14:32:14.100, and "Close of Switch L on Tie Line of Station B" at 14:32:15.100. This confirmed a main power supply failure at Station A and no manual remote control records. The current closing event was a pure automatic transfer switch action, and the verification passed.

[0068] (iv) Setting Area Pre-matching and Risk Assessment: The D5000 system requests all parameters of the setting areas (i.e., setting area 2 at station A and setting area 2 at station B) corresponding to the preset "backup power supply operation mode" of the protection devices on both sides of line L from the Baoxin substation via the standard service interface. The Baoxin substation returns a parameter list. Upon inspection, all numerical setting values ​​(current, time) and logical setting values ​​(control words) are completely filled, with no empty or illegal values, and the risk assessment is "low risk".

[0069] 2.2 All four levels of verification passed. The D5000 system's human-machine interface module immediately displayed a prominent "Setting Area Linkage Switching Request" pop-up window on the dispatcher's monitoring workstation, accompanied by an audio prompt. The pop-up window clearly displayed: the triggering event (line L remote backup automatic transfer action), the verification conclusion (passed), the suggested target setting area for switching (A station setting area 2, B station setting area 2), and the setting preview.

[0070] 3. Dispatcher confirmation and instruction generation and issuance stage: 3.1 Dispatcher A sees the alarm pop-up and logs into the D5000 system's dedicated operation interface. The system interface prompts that switching line L to the setpoint zone requires "double confirmation by both people".

[0071] 3.2 After reviewing the verification report and setpoint information in the pop-up window, dispatcher A clicks the "Operation Confirmation" button. The system records the operation account, time (14:32:20.001), and terminal IP (192.168.1.100).

[0072] 3.3 Dispatcher B logs into the system on another authorized terminal and receives a monitoring confirmation request. After reviewing the same information, he clicks the "Monitoring Confirmation" button. The system records the operation account, time (14:32:20.100), and terminal IP (192.168.1.101).

[0073] 3.4. The D5000 system's embedded access control module verifies that both operators are valid "dispatchers" and confirms that the operation conforms to the procedure. After successful verification, the command linkage control module is triggered.

[0074] 3.5 The command linkage control module generates the final remote control command for setting zone switching, which includes: target equipment (A-station protection and B-station protection of line L), target setting zone number, and trigger event ID. This command is submitted to the vertical encryption device.

[0075] 3.6 The vertical encryption device uses the SM2 algorithm to sign and authenticate the instructions, encrypts the instruction content, and then sends the encrypted instruction packet to the information protection substations of stations A and B through the power dispatch data network.

[0076] 4. Safe execution phase of station-side setting area switching: 4.1 The security sub-sites of Station A and Station B received the encrypted instructions almost simultaneously. After decryption and identity verification, the plaintext instructions were parsed out.

[0077] 4.2 The Baoxin substation sends the switching command to the line L protection device of the station through the station network.

[0078] 4.3 Taking the protection device of station A as an example, a graded dynamic safety interlocking strategy is implemented: (i) Pre-locking (time T0, <10ms after receiving the instruction): The soft pressure plate or logic output of the device's internal software for protection and reclosing functions is immediately set to "disabled".

[0079] (ii) Core Switching (Time T0+10ms to T0+30ms): The device enters "Switching Mode" and performs the following operations: Changes the index of the current running setting area from "1" to "2"; Loads all protection settings and control word parameters of "Setting Area 2" from the internal memory into the running memory. After loading, immediately performs CRC32 verification on all parameter blocks of the new setting area in the running memory, and compares the calculated checksum with the preset checksum.

[0080] (iii) Lockout Release (after T0+30ms): Assuming CRC check passes (checksum match), the device restores all protection and reclosing output functions. At this point, the protection device at station A has safely and smoothly switched to setting zone 2 operation adapted to the power supply mode of station B.

[0081] (iv) Feedback: After the switch is completed, the protection device of station A generates a feedback signal of "successful switch of the set value area, new area number = 2, CRC check passed", and sends it to the information protection substation of station A through the GOOSE protocol.

[0082] 4.4 The Bilibili protection device synchronously executes almost the exact same process (switching to its setpoint area 2) and generates a success feedback signal to send to the Bilibili protection substation.

[0083] 4.5 In an extreme case, if a device fails the CRC check during the core switching phase, the device will immediately and automatically revert to the set value zone 1, illuminate the red alarm light on the device panel and sound an alarm, and simultaneously generate and send an alarm signal of "Set value zone switching failed, reason: CRC check error".

[0084] 5. Results Feedback and Full Process Archiving Stage: 5.1 The protection and information substations of stations A and B will summarize the feedback signals received from the protection devices.

[0085] 5.2 The Baoxin substation will transmit the aggregated feedback signal (in this example, both sides are successful) back to the D5000 system of the dispatch master station through the encrypted dispatch data network.

[0086] 5.3 The D5000 system received the feedback signal and confirmed that the switching on both sides was successful. Subsequently, the human-machine interface module updated the identification of the protection devices on both sides of line L to "Setting Zone 2" (green) on the power grid single-line diagram, automatically closed the previous request pop-up window, and pushed a brief result notification that "Line L protection setting zone linkage switching successful".

[0087] 5.4 The full-process log archiving module of the D5000 system runs automatically, generating an unalterable detailed ledger of this operation.

[0088] 5.5 The system automatically synchronizes this operation log to the D5000 system's own historical database and sends a copy to the Baoxin substations at stations A and B for off-site archiving. This record can be queried, audited, or used for incident analysis at any time in the future.

[0089] The above are merely preferred embodiments of the present invention. The scope of protection of the present invention is not limited to the above embodiments. All technical solutions falling within the scope of the present invention's concept are within the scope of protection of the present invention. It should be noted that for those skilled in the art, any improvements and modifications made without departing from the principles of the present invention should be considered within the scope of protection of the present invention.

Claims

1. A remote backup automatic transfer linkage protection setting zone dynamic switching system, characterized in that, include: The perception and execution layer, deployed on the substation side, includes intelligent remote automatic transfer switch, protection information management substation, and line protection device; The intelligent remote backup automatic transfer device is used to generate and send a closing event identifier carrying an encrypted identifier after the remote backup automatic transfer action is successful; the protection information management substation is used to receive the setting zone switching instruction and forward it to the line protection device; the line protection device is configured with at least two setting zones corresponding to different power supply operation modes, and has an embedded hierarchical dynamic safety interlocking strategy execution unit for receiving and safely executing the setting zone switching instruction. The data transmission layer is a communication network based on the power dispatch data network. It is divided into Security Zone I and Security Zone II, and a vertical encryption and authentication device is deployed to realize the encryption authentication and secure transmission of data across security zones. The data acquisition and monitoring system is deployed in Security Zone I of the dispatch master station to realize real-time data acquisition, transmission and basic monitoring of the power grid. The dispatch automation system, deployed at the dispatch master station, integrates a multi-dimensional intelligent verification engine, a command linkage control module, a permission management module, a human-machine interaction module, a risk warning module, and a full-process log archiving module; the multi-dimensional intelligent verification engine is used to perform progressive security verification on the received closing event identifier; The instruction linkage control module is used to generate switching instructions for the target backup setpoint area; the permission management module is used to allocate and verify operation permissions; the human-machine interaction module provides an integrated interface for dispatchers to operate and monitor; the risk warning module is used to push alarms and risk prompts. The full-process log archiving module is used for the generation, synchronization, and archiving of operation records.

2. The remote backup automatic transfer linkage protection setting zone dynamic switching system according to claim 1, characterized in that, The multi-dimensional intelligent verification engine embedded in the dispatch automation system integrates a basic information integrity verification module, a power grid real-time topology and status verification module, a trigger event uniqueness and purity verification module, and a setpoint area pre-matching and risk assessment module, which are executed sequentially. It is used to perform a four-level progressive security verification on the received closing event identifier. After the verification is passed, the result is pushed to the human-machine interaction module.

3. The remote backup automatic transfer linkage protection setting zone dynamic switching system according to claim 2, characterized in that, The intelligent remote backup automatic transfer device also includes: The event ID generation unit is used to generate a unique event ID based on the line ID, action timestamp, and random number using the national cryptographic SM3 hash algorithm, and embed it into the closing event identifier; The spatiotemporal correlation analysis unit is used to verify the time synchronization accuracy of the trigger source through the PTP precision clock protocol and to verify the interconnection status of the line by calling the CIM model API interface, and to comprehensively determine that the trigger source is a legitimate remote backup automatic transfer action.

4. The remote backup automatic transfer linkage protection setting zone dynamic switching system according to claim 2, characterized in that, The real-time power grid topology and status verification module directly calls the real-time database and acquisition service of the data acquisition and monitoring system to perform the following verifications: The protection device status monitoring unit is used to detect the communication status and alarm signals of the target protection device through the protection information system interface, requiring normal communication and no serious abnormalities. The topology status judgment unit is used to combine the CIM model with the real-time switch position collected by the data acquisition and monitoring system to confirm that the line is in the standby automatic transfer closed state.

5. The remote backup automatic transfer linkage protection setting zone dynamic switching system according to claim 2, characterized in that, The uniqueness and purity verification module for the triggering event includes: The time window event retrieval unit is used to retrieve all historical event records of the same line within the most recent preset time period from the historical event database of the data acquisition and monitoring system; The event type matching unit is used to verify the retrieved event records, ensure that the current triggering event is a valid remote backup automatic transfer action, and exclude reclosing after protection tripping and manual remote control interference signals.

6. The remote backup automatic transfer linkage protection setting zone dynamic switching system according to claim 2, characterized in that, The setting area pre-matching and risk assessment module includes a setting area data retrieval unit, which is used to retrieve the preset numerical and logical setting values ​​of the backup setting area of ​​the line protection device from the protection information management substation through a standard interface. After completing the pre-matching, a backup setting area switching suggestion is generated and pushed to the human-machine interaction module of the dispatch automation system for the dispatcher to confirm.

7. The remote backup automatic transfer linkage protection setting zone dynamic switching system according to any one of claims 1-6, characterized in that, The hierarchical dynamic safety interlocking strategy execution unit embedded in the line protection device includes: The pre-locking stage unit is used to lock out the protection function and reclosing output by modifying the internal data attributes to a prohibited state after receiving a switching command. The core switching phase unit is used to perform the setting area switching operation, retain the setting value reading and writing, parameter verification, and event logging functions, and performs CRC verification on the new setting area parameters after the switching is completed; The interlock release phase unit is used to prioritize restoring the delayed protection function with the data attribute set to the allowed state after the switching is completed and the verification is passed. After short delay monitoring, the protection and reclosing functions are then restored.

8. The remote backup automatic transfer linkage protection setting zone dynamic switching system according to any one of claims 1-6, characterized in that, The full-process log archiving module of the scheduling automation system includes: The operation log generation unit is used to automatically generate an operation log ledger that includes the time of backup automatic transfer action, action type, set value verification result, dispatcher confirmer, switch execution time, switch result and device status. The data archiving unit is used to synchronize the operation record ledger to the protection information management substation and the historical database of the dispatch automation system itself for archiving.

9. A switching method for a remote backup automatic transfer linkage protection setting zone dynamic switching system based on any one of claims 1-8, characterized in that, Including the following steps: S1. After the intelligent remote backup automatic transfer device completes the load transfer, it generates a closing event identifier carrying a unique event ID. After being filtered by the measurement and control device through the GOOSE protocol, it is uploaded to the dispatch automation system of the dispatch master station. S2. The dispatch automation system performs a four-level progressive verification through its embedded multi-dimensional intelligent verification engine: first, it performs a basic information integrity verification; second, it performs a real-time power grid topology and status verification; third, it performs a trigger event uniqueness and purity verification; and finally, it performs a setpoint pre-matching and risk assessment. After all verifications pass, the dispatch automation system generates a verification report and a suggestion for switching the backup setpoint area, and pushes it to the integrated interface of its human-machine interaction module. S3. The dispatcher views the verification report and suggestions through the integrated interface of the dispatch automation system and executes the dual-person dual-confirmation mechanism. Two authorized dispatchers complete the operation confirmation and monitoring confirmation in turn. The confirmation instructions and identity information are sent to the permission management module embedded in the dispatch automation system for verification. S4. After the permission verification is passed, the instruction linkage control module of the dispatch automation system generates a switching instruction containing the target setpoint area number, event ID and verification pass identifier, and sends it to the protection information management substation on the substation side through the power dispatch data network encrypted with the national cryptographic SM2 / SM4 algorithm. S5. After receiving the switching command, the protection information management substation forwards it to the line protection device via the IEC 61850 MMS protocol; S6. After receiving the command, the line protection device synchronously starts the embedded hierarchical dynamic safety interlocking strategy: first, it enters the pre-interlocking stage, interlocking the protection and reclosing output; then it enters the core switching stage, performing setting area index switching and parameter loading. After the switching is completed, CRC verification is performed on all parameters in the new setting area; after the verification is passed, it enters the interlocking release stage, restoring all protection and reclosing functions. S7. After a successful or unsuccessful handover, the line protection device will send a feedback signal containing the CRC check result, handover status, and timestamp to the protection information management substation via the GOOSE protocol. S8. After the protection information management substation collects and feeds back the feedback signals, it transmits them back to the dispatch automation system through the encrypted power dispatch data network; S9. The dispatch automation system receives feedback signals, updates the status display of the setting area of ​​the relevant line protection device through the human-machine interaction module, and pushes the switching result notification through the risk warning module. S10. The full-process log archiving module of the dispatch automation system automatically generates a structured operation record ledger and archives the ledger synchronously to the historical database of the protection information management substation and the historical database of the dispatch automation system itself.

10. The switching method according to claim 9, characterized in that, In step S2, the basic information integrity verification requires that the event identifier format be compliant, the timestamp error be ≤5ms, the line ID exist in the CIM model, and the line is a dual-power interconnection structure. The real-time topology and status verification of the power grid verifies that the communication status of the protection device is normal and there are no serious abnormal alarms through the protection information management substation, and confirms that the line is in the "backup automatic transfer closing" state. The uniqueness and purity verification of the trigger event confirms that there are no protection tripping or manual remote control interference operation records for the same line in the historical event database of the data acquisition and monitoring system within the last 30 seconds. The setting area pre-matching and risk assessment retrieves the numerical and logical setting values ​​of the backup setting area preset by the line protection device from the protection information management substation through the standard interface for integrity check. If there are null values, an error risk alarm for the setting area is generated.