Energy router cascading failure defense and recovery method
By constructing a dynamic coupling matrix to assess the risk of cascaded failures in energy routers and generating control commands, the propagation of failures is actively suppressed, thus achieving safe and stable operation of the energy router system and solving the problems of inaccurate cascaded failure prediction and blind recovery in existing technologies.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- WUHAN RUICHUANG YOUNENG TECHNOLOGY CO LTD
- Filing Date
- 2026-04-29
- Publication Date
- 2026-07-21
Smart Images

Figure CN122437004A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of power electronics technology and power system stability control, and in particular to a method for fault defense and recovery of cascaded energy routers. Background Technology
[0002] As a core component of future smart grids and the energy internet, energy routers utilize integrated power electronic converters to flexibly and efficiently manage various distributed energy sources, energy storage units, and loads. With the continuous expansion of their port count and system scale, disturbances or faults at a single port can easily propagate rapidly through the shared DC bus, triggering a cascading failure of ports due to overload. Researching methods to accurately predict and proactively suppress cascading faults in energy routers is of crucial technical significance for ensuring the safe and stable operation of new power systems.
[0003] Existing protection methods for multi-port converter systems typically rely on static system models for risk assessment. For example, some methods depend on fixed physical topology and line impedance parameters to predict the distribution of fault currents and set protection thresholds accordingly. After a fault occurs, the response strategies are often limited to passively implementing overcurrent protection, undervoltage tripping, or load shedding based on preset priorities. During the recovery phase after fault clearance, the conventional operation is often to sequentially reconnect offline ports to the system according to a fixed time sequence or priority list.
[0004] However, the aforementioned existing technologies face profound technical challenges in practical applications. The existing technologies mainly suffer from the following three levels of problems: Inaccurate risk assessment. The power response characteristics of each port within an energy router are dynamically determined by the real-time control mode of its converter (such as constant voltage, droop, or constant current mode), rather than fixed physical parameters. Traditional static models struggle to effectively capture the dynamic coupling relationships dominated by control modes, leading to significant deviations in their predictions of cascading fault propagation paths and risk levels. Passive fault suppression. Due to the difficulty in accurately predicting fault evolution, existing methods can only react after fault symptoms (such as overcurrent) appear, making it difficult to achieve the goal of proactive intervention and reconstruction of the system's intrinsic stability in the early stages of fault propagation. Blind system recovery. Traditional open-loop recovery processes ignore the fact that the system's stability margin may have been significantly reduced after experiencing a fault impact. Blindly reconnecting ports may cause secondary impacts on the vulnerable system, triggering a new round of cascading faults. Summary of the Invention
[0005] The purpose of this invention is to provide a method for fault prevention and recovery of cascaded energy routers, in order to solve at least one of the aforementioned problems in the prior art.
[0006] Technical solution: A method for fault prevention and recovery in cascaded energy routers, comprising:
[0007] Obtain port operation status data for multiple ports of the energy router, which includes at least the actual power, rated power capacity, and current control mode of each port;
[0008] Based on port operating status data, the risk of system-level cascading failures is assessed, and a system cascading failure risk index is obtained.
[0009] In response to the system cascading failure risk index exceeding the preset risk threshold, or in response to the occurrence of an actual failure, control instructions are generated and executed to suppress the propagation of cascading failures.
[0010] In response to fault clearing, an orderly recovery process based on risk awareness is executed according to changes in system cascade fault risk indicators to restore normal port operation.
[0011] Optionally, assess the risk of system-level cascading failures, including:
[0012] Based on the current control mode of each port in the port operation status data, a dynamic coupling matrix on which the control mode depends is constructed, and the system cascading fault risk index is determined based on the dynamic coupling matrix.
[0013] Optional, the construction of the dynamic coupling matrix includes:
[0014] Based on the control mode configuration of the ports that are in normal operation among multiple ports, a preset calculation rule is assigned to the fault propagation coupling coefficient between any two ports to obtain the fault propagation coupling coefficient between each port.
[0015] Optional, preset calculation rules include:
[0016] In response to the presence of a port operating in constant voltage mode among the ports in normal operation, it is determined that the power deficit not shared by other mode ports shall be borne by the port operating in constant voltage mode, so as to calculate the fault propagation coupling coefficient between ports.
[0017] Optional, preset calculation rules include:
[0018] In response to the absence of ports operating in constant voltage mode and the presence of ports operating in droop mode among the ports in normal operation, the power deficit is proportionally distributed among the ports operating in droop mode based on the droop coefficient of each port operating in droop mode, in order to calculate the fault propagation coupling coefficient between each port.
[0019] The droop coefficient is derived from the port's operating status data.
[0020] Optionally, assessing the risk of system-level cascading failures may also include:
[0021] By tracing the cascading propagation chain step by step, the cascading fault propagation record is obtained.
[0022] Furthermore, at each stage of the recursion, the dynamic coupling matrix dependent on the control mode is recalculated based on the set of ports in normal operation that have changed due to port overload exit.
[0023] Optionally, generate and execute control instructions for suppressing the propagation of cascading faults, including:
[0024] The control modes of multiple ports are treated as adjustable decision variables. By solving the optimization problem, the optimal control mode configuration is determined, and control commands are generated based on the optimal control mode configuration.
[0025] Optimization issues:
[0026] The goal is to minimize the risk of cascading failures in the system.
[0027] It includes at least one constraint selected from the following: voltage support constraint and power balance constraint.
[0028] Optionally, the control instructions include a progressive strategy formed according to a preset priority, wherein the progressive strategy includes at least one of the following operations executed sequentially:
[0029] Change the current control mode of one or more ports;
[0030] Adjust the power settings of one or more ports, where the power settings are derived from port operating status data;
[0031] Cut off one or more ports.
[0032] Optional, orderly recovery processes based on risk perception include:
[0033] According to the preset recovery priority, the recovery sequence of the ports to be recovered is determined. After each port is connected in the recovery sequence, the step of assessing the risk of cascading failures at the system level is called to perform a safety check on the current system status.
[0034] If the security check result indicates that the risk does not exceed the preset security threshold, continue to access the next port in the recovery sequence;
[0035] In addition, in response to the security check result indicating that the risk exceeds the preset security threshold, the recovery of subsequent ports is suspended, or the control mode of the recovered ports is adjusted.
[0036] Optionally, the control mode-dependent dynamic coupling matrix is recalculated at each level of the recursion, including:
[0037] In response to a port operating in constant voltage mode exiting due to overload at a certain recursive level, resulting in no longer having a constant voltage mode port in the set of ports in normal operation, the fault propagation coupling mechanism is switched from a mode where a single port centrally absorbs the power deficit to a mode where multiple ports operating in droop mode proportionally distribute the power deficit, thus achieving a structural update of the dynamic coupling matrix. Beneficial effects: This invention can improve the accuracy of cascade fault risk prediction, the effectiveness of proactive fault defense, and the safety of system recovery after a fault. Attached Figure Description
[0038] Figure 1 This is a schematic diagram of the overall process of a fault defense and recovery method for cascaded energy routers provided in an embodiment of this application.
[0039] Figure 2 This is a flowchart illustrating the steps for assessing the risk of cascading failures at the system level, as provided in an embodiment of this application.
[0040] Figure 3 This is a schematic diagram of the orderly recovery process of risk perception provided in the embodiments of this application.
[0041] Figure 4 This is a schematic diagram of the process of generating and executing control instructions for suppressing the propagation of cascading faults, provided in an embodiment of this application. Detailed Implementation
[0042] Example 1 details the overall framework of a cascaded fault defense and recovery method for energy routers, such as... Figure 1 As shown. This method is applied to an energy router system managed by a central controller. The energy router has multiple ports connected via a shared DC bus, which can be connected to the power grid, distributed power sources, energy storage units, or various loads.
[0043] Step 101: Obtain port operation status data of multiple ports of the energy router. The port operation status data shall include at least the actual power, rated power capacity and current control mode of each port.
[0044] In this embodiment, this step provides the data foundation for all subsequent evaluation and control operations. The central controller periodically collects real-time operating data from the local controllers at each port via an internal communication bus. Specifically, the port operating status data includes not only the current control mode of each port, such as constant voltage mode, constant current mode, or droop mode, but also control parameters related to these modes, such as the voltage reference value in constant voltage mode, the current setpoint in constant current mode, and the droop coefficient in droop mode. In addition, the data also covers the actual transmission power, rated power capacity, operating status flags, and port type identifier for each port.
[0045] After processing the collected raw data, a structured set of port status parameters is formed. This set can be a data structure indexed by a unique port identifier. Each port corresponds to a set of parameters, specifically including: current actual power, rated power capacity, calculated absolute power margin and relative power margin, current control mode identifier, current control parameter value, port type identifier, a set of preset selectable control modes based on the port type, and a preset importance weight value based on the importance of the load or power supply connected to the port.
[0046] Step 102: Based on port operating status data, assess the system-level cascading failure risk, that is, the risk of failures in each port propagating to other ports, and obtain the system cascading failure risk index.
[0047] Based on the set of port state parameters obtained in step 101, a forward-looking assessment of system stability is made using an evaluation model that can quantify the risk of cascading overload propagation. This assessment process outputs one or more system cascading failure risk indicators to characterize the probability and severity of a large-scale cascading failure caused by a failure at any port in the current operating state. The specific implementation of this step, particularly a dynamic coupling matrix construction method based on control patterns and a dynamic recursion and risk quantification method for cascading failure propagation chains, will be described in detail in subsequent embodiments.
[0048] It should be noted that the evaluation model and the entire method proposed in this invention are based on the quasi-static assumption. That is, this method focuses on the risk when the system reaches a new stable power distribution state after each level of fault occurs and undergoes a transient process. It is suitable for making protection strategy decisions on time scales of seconds or hundreds of milliseconds, rather than replacing millisecond-level hardware transient protection.
[0049] Step 103: In response to the system cascading fault risk index exceeding a preset risk threshold, or in response to an actual fault occurring, generate and execute control instructions to suppress the propagation of cascading faults. The control instructions include adjusting the control mode and / or power reference value of at least one port to reduce the system cascading fault risk index.
[0050] This step is triggered when the system cascading fault risk index obtained from step 102 exceeds the preset warning threshold, or when the monitoring system detects that an existing port has actually failed and exited operation. The central controller will immediately execute an optimization decision process to generate control instructions that can most effectively suppress or cut off the fault propagation chain, and will send the instructions to the controllers of the relevant ports for execution. The joint optimization blocking strategy based on control mode reconstruction proposed in this step will be described in detail in the subsequent embodiment 4.
[0051] Step 104: In response to fault clearing, execute an orderly recovery process based on changes in system cascade fault risk indicators to restore normal port operation.
[0052] This step is initiated after the faulty port has been physically repaired or the fault status has been cleared, and it has been confirmed that the conditions for reconnection to the grid are met. Unlike the traditional direct intervention method, this invention adopts a risk-aware, closed-loop, step-by-step recovery strategy to ensure that the recovery process itself will not cause secondary impacts on the system or trigger new cascading risks. A specific risk-aware closed-loop recovery control method will be explained in detail in the subsequent Embodiment 5.
[0053] According to one aspect of this application, a method for fault prevention and recovery in cascaded energy routers can also be:
[0054] S1, obtain the operating status data of each port of the energy router. The operating status data includes at least the actual power, rated power capacity and current control mode of each port.
[0055] S2, based on the control mode of each port, constructs the dynamic coupling relationship between each port, and assesses the risk of faults in each port propagating to other ports based on the dynamic coupling relationship and operating status data, thereby obtaining the system cascading fault risk index;
[0056] S3, in response to the system cascading failure risk index exceeding the preset risk threshold, generates and executes defense control instructions for the relevant ports based on the operating status data and dynamic coupling relationship. The defense control instructions include adjusting the control mode and / or power reference value of at least one port to reduce the system cascading failure risk index.
[0057] S4, in response to fault clearing, gradually restores the adjusted port to the running state according to the changes in the system cascade fault risk indicators, and calls the evaluation method of step S2 to perform a safety check on the recovery process. When the check result shows that the risk indicators exceed the preset risk threshold, the recovery operation is paused or adjusted.
[0058] Example 2 elaborates on how to construct a dynamic coupling matrix that accurately reflects the fault propagation characteristics within the system at any given runtime.
[0059] Step 201: Based on the current control mode of each port in the port operation status data, construct a dynamic coupling matrix that the control mode depends on, and determine the system cascading fault risk index based on the dynamic coupling matrix.
[0060] In other words, this step can also be used to calculate the overload caused by the fault propagating from the source port to other ports through the coupling relationship, based on the dynamic coupling matrix and the operating status data of each port, and obtain the system cascading fault risk index.
[0061] In this embodiment, the control mode-dependent dynamic coupling matrix is a core mathematical tool used to quantitatively describe how power disturbances or failures at one port within the energy router will redistribute power among other healthy ports. The matrix elements, i.e., the fault propagation coupling coefficients between ports, are not determined by fixed properties such as the physical topology or line impedance between ports, but are dynamically determined by the control mode currently executed by each port converter. Specifically, the fault propagation coupling coefficient α... ij Defined as: when port i fails and generates a power deficit ΔP i At that time, the additional power ΔP that the healthy port j is forced to bear. j The proportion of the total deficit, i.e., α ij =ΔP j / ΔP i .
[0062] Before constructing the matrix, as a preferred implementation, the power margins of the ports can be standardized. Specifically, the absolute power margin of each port (the difference between its rated power capacity and the absolute value of the current actual transmission power) is divided by the port's rated power capacity to obtain a dimensionless relative power margin. This standardization step eliminates the problem of incomparable margin values caused by differences in rated capacity between different ports, laying the foundation for comparable risk calculations based on the matrix.
[0063] Step 202, the construction of the dynamic coupling matrix, includes: based on the control mode configuration of the ports in normal operation among multiple ports, assigning a preset calculation rule to the fault propagation coupling coefficient between any two ports, and obtaining the fault propagation coupling coefficient between each port.
[0064] Specifically, the process of constructing the dynamic coupling matrix begins with a snapshot analysis of the current system state. All ports currently in normal operation are identified, forming a healthy port set. This set is then traversed, and the number of ports operating in constant voltage mode, droop mode, and constant current or constant power mode, along with their respective control parameters, are counted. The overall power disturbance response mechanism of the system depends on the port configuration of these three control modes. This invention predefines calculation rules with clear physical meaning corresponding to different mode configurations to determine the fault propagation coupling coefficient between any two ports.
[0065] Step 203: In response to the presence of a port operating in constant voltage mode among the ports in normal operation, determine that the power deficit not shared by other mode ports shall be borne by the port operating in constant voltage mode, so as to calculate the fault propagation coupling coefficient between ports.
[0066] This calculation rule corresponds to the most common operating condition in the system, where a single master control port maintains a stable bus voltage. In this condition, the port operating in constant voltage mode aims to maintain a constant shared DC bus voltage. When a fault occurs at another port in the system, causing a power deficit, this constant voltage mode port will adjust its power output almost instantaneously through its control loop to compensate for the power deficit and suppress bus voltage deviation. Correspondingly, since the bus voltage is maintained at a stable level, other ports operating in droop or constant current mode will not perceive significant disturbances, and their power output remains unchanged. In this scenario, the fault propagation coupling coefficient α from any faulty port i to this constant voltage mode port j is... ij The coefficient is 1, while the coupling coefficient from the faulty port i to all other non-constant voltage mode ports is 0.
[0067] As an alternative implementation, in some redundantly designed systems, if multiple ports are operating in constant voltage mode simultaneously, the power deficit can be shared according to a preset allocation strategy, such as the ratio of their respective rated power capacities.
[0068] Step 204: In response to the absence of ports operating in constant voltage mode and the presence of ports operating in droop mode among the ports in normal operation, the power deficit is proportionally distributed among the ports operating in droop mode based on the droop coefficient of each port operating in droop mode, so as to calculate the fault propagation coupling coefficient between each port; wherein, the droop coefficient is derived from the port operating status data.
[0069] This calculation rule is typically applied to degraded operation conditions after the system loses its sole constant-voltage master control port. In this situation, the DC bus lacks a strong voltage anchor, and all power imbalances will directly cause a voltage shift in the bus. Ports operating in droop mode are designed to sense this voltage shift and adjust their power output accordingly based on their preset droop characteristic curve to collectively maintain system stability. Specifically, the power deficit will be shared by all ports in the healthy port set operating in droop mode, and the proportion shared by each port is determined by its droop coefficient. Ports with larger droop coefficients are more sensitive to voltage changes and bear a larger share of power. The fault propagation coupling coefficient between ports can be calculated using the following formula:
[0070] ;
[0071] Where, α ij Let k be the fault propagation coupling coefficient from faulty port i to healthy drooping mode port j. j Let H be the droop coefficient of port j, ∑ be the summation operator, and H be the droop coefficient of port j. D k is a subset of all ports running in droop mode in the current set of healthy ports.m Let be the droop coefficient for any port m in the subset. To eliminate ambiguity, the droop coefficient k in this invention... j It is explicitly defined as power-voltage gain, which represents the change in port power output caused by a unit bus voltage deviation.
[0072] Step 205, the preset calculation rules also include: in response to the presence of a port operating in constant current mode or constant power mode among the ports in normal operation, it is determined that the port operating in constant current mode or constant power mode does not participate in the sharing of power deficit, and its corresponding fault propagation coupling coefficient is determined to be zero.
[0073] This calculation rule reflects the inherent characteristics of constant current or constant power mode ports. Such ports, such as photovoltaic ports in maximum power point tracking mode, aim to inject a constant current or power into the system, and their output is largely unaffected by fluctuations in the bus voltage within the normal range. When other ports in the system fail, these ports will continue to maintain their original power setpoint, neither actively sharing the power deficit nor reducing their output. In other words, they act as a natural firewall in the fault propagation chain. The fault propagation coupling coefficient α from any faulty port i to any constant current or constant power mode port j... ij It remains constant at 0. It should be noted that this rule applies only if the bus voltage is maintained within the normal operating voltage range of the constant current mode port converter.
[0074] To illustrate the construction process of the coupling matrix more specifically, an exemplary calculation case is provided below. Assume an energy router system contains four ports P1, P2, P3, and P4. At a certain moment, port P1 fails, resulting in a 10kW power deficit, while ports P2, P3, and P4 are operating normally.
[0075] In the first alternative implementation, it is assumed that P2 operates in constant voltage mode, P3 operates in droop mode, and P4 operates in constant current mode. According to the rule in step 203, the 10kW power deficit will be entirely borne by the voltage-anchored P2 port. The fault propagation coupling coefficients are: α 12 =1, α 13 =0, α 14 =0. At this point, the first row of the dynamic coupling matrix representing the propagation of the fault from P1 can be represented as [-, 1, 0, 0], where - represents itself.
[0076] In the second optional implementation, assuming the system is degraded and the original constant voltage port has been deactivated, P2 and P3 both operate in droop mode with droop coefficients k2 = 300 W / V and k3 = 100 W / V, respectively, while P4 remains in constant current mode. According to step 204, the 10 kW power deficit will be shared by P2 and P3 according to their droop coefficients. The total droop coefficient is 300 + 100 = 400 W / V. The coupling coefficient α of P2... 12 =300 / 400=0.75, the coupling coefficient α of P3 13 =100 / 400=0.25. According to step 205, the coupling coefficient α of P4 is... 14 =0. Correspondingly, of the 10kW shortfall, 7.5kW is borne by P2, 2.5kW by P3, and 0kW by P4. At this time, the first row of the dynamic coupling matrix can be represented as [-, 0.75, 0.25, 0].
[0077] The comparison of the two cases above shows that the fault propagation path and intensity from the same port P1 changed simply because the control mode configuration of the health port changed. This demonstrates that the dynamic coupling matrix proposed in this invention can accurately capture the operating characteristics of the energy router.
[0078] Example 3 details how to trace the complete cascading fault propagation chain through a step-by-step recursive approach and accurately quantify the risks in this process. It reveals the mechanism by which the dynamic coupling matrix updates in real time as the system state evolves, especially the structural shift in fault propagation patterns triggered by the exit of critical control ports.
[0079] Step 301, the step of assessing the risk of system-level cascading failures, further includes: tracing the cascading propagation chain through a step-by-step recursive approach to obtain a cascading failure propagation record; and, in each stage of the recursion, recalculating the dynamic coupling matrix dependent on the control mode based on the set of ports in normal operating condition that have changed due to port overload exits, such as... Figure 2 As shown.
[0080] In this embodiment, tracing the cascading fault propagation chain is an iterative calculation process used to simulate and rehearse a series of chain reactions that may be triggered by an initial fault. Starting from the assumed initial fault port, its impact is deduced step by step until the system reaches a new stable state or a large-scale collapse occurs.
[0081] Specifically, the recursive process includes the following operations: First, a normally operating port is selected as the hypothetical initial fault port, and its resulting power deficit is defined; this is the zeroth level of the recursion. Based on the current set of healthy ports consisting of all other normally operating ports, the dynamic coupling matrix for the first level is calculated according to the method in Example 2. Using this matrix, the distribution of the initial power deficit across all healthy ports can be calculated. The additional power borne by each healthy port is compared with its own relative power margin. If one or more healthy ports become overloaded as a result, these ports are marked as first-level fault ports. Thus, the first level of the recursion is completed.
[0082] Before proceeding to the next level of recursion, the system must update its state by removing newly identified first-level faulty ports from the healthy port set. Because the members of the healthy port set and their control modes have changed, the overall response characteristics of the system also change. A completely new, second-level dynamic coupling matrix must be recalculated based on the updated, smaller healthy port set. Using the total power deficit generated by the first-level faulty ports as a new disturbance source, the second-level dynamic coupling matrix is used to calculate its distribution across the remaining healthy ports, thus identifying the second-level faulty ports.
[0083] This process repeats continuously, removing faulty ports, updating the set of healthy ports, reconstructing the coupling matrix, calculating power allocation, and identifying new faults, until no new ports become overloaded after a certain stage of recursion, indicating that the cascading fault propagation has terminated. Ultimately, this process outputs a complete record of the cascading fault propagation chain. This record can be a data structure detailing the initial faulty port, the total number of propagation stages, which ports failed at each stage, and the final set of surviving ports.
[0084] Step 302: Recalculate the dynamic coupling matrix dependent on the control mode in each recursive level. Specifically, this includes: in response to the fact that in a certain recursive level, the only port operating in constant voltage mode exits due to overload, resulting in no constant voltage mode port in the set of ports in normal operation, the coupling mechanism for fault propagation is switched from a mode in which a single port absorbs the power deficit centrally to a mode in which multiple ports operating in droop mode share the power deficit proportionally, thereby realizing a structural update of the dynamic coupling matrix.
[0085] Unlike traditional evaluation methods that use fixed coupling models, this step details the accurate capture of qualitative changes in the system's control mode. To illustrate this process more clearly, the following exemplary scenario is provided: Assume a system in its initial state, controlled by a single constant-voltage mode port P. V The main control is responsible for multiple droop mode ports P. D1 P D2Wait. When a load port P F When an initial fault occurs, in the first stage of the recursion, according to the rules of Example 2, P V Will bear the responsibility of P F The resulting full power deficit. The coupling matrix at this point will be represented as from P F To P V The strong coupling is defined as a coupling coefficient of 1, while the coupling coefficients to all other drooping ports are 0. If P F The fault power was too high, causing P to... V After absorbing the impact, it also exceeded its power margin and became overloaded. Before entering the second stage of the recursion, P V It will be removed from the health port set.
[0086] At this point, a structural change occurs in the system; the constant-voltage mode port no longer exists in the healthy port set. System control will shift, and DC bus voltage stabilization will be handled by the remaining droop-mode port P. D1 P D2 The controller must trigger a structural update to the dynamic coupling matrix, switching in real time from a single port absorbing power to a multi-port proportionally distributed power distribution mechanism. The updated second-level coupling matrix will follow the calculation rules for the constant-voltage mode in Example 2, and its matrix elements will reflect P... D1 P D2 The ports are proportionally allocated new coupling relationships for subsequent disturbances based on their respective droop coefficients.
[0087] Preferably, to ensure a smooth transition after the system loses its sole constant-voltage master control port, a master control takeover mechanism can be preset. When the sole constant-voltage mode port exits, the system can select one or more of the current droop mode ports to undertake the main voltage regulation task according to at least one of the following preset rules: Optionally, the port with the highest priority can take over based on preset port priorities; or, the port with the largest remaining relative power margin can take over based on the real-time operating status of each port; or, the port with the largest rated capacity can take over based on the inherent properties of the ports.
[0088] After completing the recursive tracing of the entire cascading propagation chain, the severity of the event needs to be quantified. Risk quantification is achieved through two core indicators. One is a single-port overload risk indicator used during the recursive process to determine whether a port is overloaded:
[0089] ;
[0090] Among them, R overload,i (l)Let ∑ be the overload risk index accumulated by health port i at the end of the l-th level recursion, and let ΔP be the summation operator. i (k) P represents the additional power borne by port i in the k-th recursion. rated,i P is the rated power capacity of port i. actual,i This represents the initial actual transmission power of port i. When this value is greater than 1, port i is considered overloaded.
[0091] For example, in the first-stage recursive case of the above five-port system, the initial actual power of port P1 is 40kW, the rated power is 60kW, and the additional power undertaken in the first-stage recursion is 40kW. Therefore, the overload risk index of P1 is:
[0092] R overload,P1 (l) =40 / (60-|40|)=40 / 20=2.0.
[0093] Since 2.0 > 1, it is determined that P1 is overloaded after the first level of recursion.
[0094] Another is a system cascading failure risk indicator used to assess the severity of the entire cascading event, calculated after recursively calculating the entire propagation chain starting with port i as the initial fault:
[0095] ;
[0096] Among them, R sys (i) represents the system cascading failure risk index when port i is the initial fault, ∑ is the summation operator, L is the total number of cascading propagation stages triggered by port i, l is the current number of cascading propagation stages, γ is a preset stage attenuation factor, its value ranges from 0 to 1, used to reflect that the relative impact of subsequent stage faults is less than that of preceding stage faults, F (l) Let j be a port in the set of faulty ports added at level l, and w be a port in the set of faulty ports. j The preset importance weight for port j.
[0097] This indicator comprehensively considers the propagation depth and breadth of cascading failures, as well as the importance of the failed ports, providing a quantitative basis for subsequent defense and recovery decisions.
[0098] To illustrate the above recursive process and matrix structural update mechanism more specifically, a complete two-level recursive numerical example is provided below. Assume an energy router system with five ports. Port P1 is an energy storage unit operating in constant voltage mode, with a current output power of 40kW and a rated power of 60kW. Port P2 is another energy storage unit operating in droop mode, with a droop coefficient k2 = 200W / V, a current output power of 30kW, and a rated power of 50kW. Port P3 is a photovoltaic array operating in droop mode, with a droop coefficient k3 = 100W / V, a current output power of 20kW, and a rated power of 30kW. Port P4 is a constant power load consuming 130kW. Port P5 is a grid interface port operating in constant power mode, with a current output power of 40kW and a rated power of 60kW. System power balance: 40 + 30 + 20 + 40 = 130kW.
[0099] Level 0: Assuming port P5 fails and disconnects from the system, its original output power of 40kW is lost, resulting in a power deficit of 40kW in the system, which needs to be compensated by other healthy ports.
[0100] The first level of recursion posits that the current set of healthy ports is {P1, P2, P3, P4}. Since P1 operates in constant voltage mode, according to the rules in the aforementioned embodiment, the entire 40kW shortfall is borne by P1. P1's new output power is 40 + 40 = 80kW, exceeding its rated power of 60kW. Calculate the overload risk index R of P1. overload,P1 =40 / (60-40)=2.0>1, P1 is determined to be overloaded and marked as the first-level fault port.
[0101] Before the second-level recursion, the state update removes P1 from the healthy port set, and the new healthy port set is {P2, P3, P4}. The set no longer contains constant-voltage mode ports. A structural update of the dynamic coupling matrix is necessary to switch the coupling mechanism from a single-port centralized absorption mode to a multi-port proportionally distributed mode.
[0102] The second-stage recursion results in a power deficit of 80kW due to P1's exit, which is the original 40kW plus the 40kW absorbed in the first stage. In the new set of healthy ports, P2 and P3 operate in droop mode, and P4 operates in constant power mode. According to the rules of the aforementioned embodiment:
[0103] α2=k2 / (k2+k3)=200 / (200+100)=0.667,
[0104] α3=k3 / (k2+k3)=100 / (200+100)=0.333,
[0105] α4=0.
[0106] P2 needs to handle an additional 0.667 × 80 = 53.3 kW, bringing its total power to 30 + 53.3 = 83.3 kW, far exceeding the rated 50 kW, thus constituting an overload. P3 needs to handle an additional 0.333 × 80 = 26.7 kW, bringing its total power to 20 + 26.7 = 46.7 kW, exceeding the rated 30 kW, thus constituting an overload.
[0107] The recursion terminates, and both P2 and P3 are determined to be overloaded. The second-level fault ports are {P2, P3}. Only {P4} remains in the healthy port set. P4 is a constant power mode port and cannot handle the power shortage. The recursion terminates again, and the system is determined to be experiencing a large-scale failure.
[0108] The final output cascading fault propagation record is as follows: initial fault port P5, total propagation stages L=2, first-stage fault port {P1}, second-stage fault ports {P2, P3}, surviving port {P4}. Assuming the importance weights of each port are w1=1.0, w2=0.8, w3=0.5, and the stage decay factor γ=0.7, then the system cascading fault risk index is:
[0109] R sys (P5)=γ 0 ×w1+γ 1 ×(w2+w3)=1.0×1.0+0.7×(0.8+0.5)=1.0+0.91=1.91.
[0110] Example 4 further refines the fault blocking and degradation handling steps in Example 1. It proposes a proactive and forward-looking defense strategy that moves beyond passively responding to faults. By solving a joint optimization problem, it proactively reconstructs the system's operating state to dismantle potential cascading fault propagation chains, achieving early blocking and source containment of risks.
[0111] Step 401: Using the control modes of multiple ports as adjustable decision variables, the optimal control mode configuration is determined by solving an optimization problem, and control commands are generated based on the optimal control mode configuration, such as... Figure 4 As shown.
[0112] In this embodiment, instead of using the traditional protection strategy that only considers the power setpoint as a single dimension of adjustment, this step introduces the adjustment dimension of the control mode. Specifically, the future control modes of all healthy ports in the system, along with their power setpoints, are collectively constructed into a high-dimensional decision variable space. Each port's control mode is a discrete decision variable, its selectable value range determined by the port's physical properties. For example, the selectable mode set for an energy storage port could be {constant voltage mode, droop mode, constant power mode}. The power setpoint of each port, on the other hand, is a continuous decision variable, its value range limited by the port's rated power capacity. By optimizing within this high-dimensional space, a completely new, globally optimal system operating state can be found, i.e., the optimal control mode configuration. This configuration not only satisfies the system's basic operating constraints but also minimizes the risk of cascading failures when facing potential disturbances. The output of this optimization process is the series of operations required to transition from the current operating state to this optimal state; these operations are combined into specific control commands.
[0113] Step 402, Optimization problem: The objective is to minimize the system cascading failure risk index; and includes at least one constraint selected from the following constraints: voltage support constraint, power balance constraint.
[0114] This step defines the mathematical form of the optimization problem, which is a well-defined and constrained optimization model that ensures the optimal control mode configuration is theoretically and practically feasible and safe. Specifically, the objective function of this optimization problem minimizes the cascading risk of the system in the worst-case scenario. In other words, the goal is to find a control mode configuration such that even if the most vulnerable port in the system fails, the resulting cascading effects are minimized. This objective function can be expressed as:
[0115] ;
[0116] Where min is the minimization operator, M is the discrete decision vector composed of the control modes of all healthy ports, P is the continuous decision vector composed of the power setpoints of all healthy ports, max is the maximization operator, i∈H represents traversing each port i in the current set of healthy ports H as the assumed initial fault, and R sys (i|M, P) is the system-level cascading failure risk index caused by port i under a given control configuration (M, P). Its specific calculation method has been described in detail in Example 3.
[0117] Meanwhile, solving this optimization problem must be done under a series of physical and engineering constraints. The voltage support constraint ensures that the system must maintain the stability of the DC bus voltage after reconfiguration. In specific implementation, this constraint can be set as follows: in the target control mode configuration, at least one port must operate in constant voltage mode, or at least two ports must operate in droop mode.
[0118] As a preferred implementation, to avoid circulating currents or control conflicts between multiple constant voltage sources, this constraint can be further limited to: in the target control mode configuration, at most one port can be assigned to constant voltage mode.
[0119] The power balance constraint ensures that under the new operating state, the total output power of all source ports and the total absorbed power of all carrier ports should be balanced, and the error should be within the preset allowable range.
[0120] In addition, the optimization problem may include other constraints, such as the power setting value of each port must not exceed its rated power capacity, and the power adjustment rate should meet the physical limitations of the port converter.
[0121] Step 403, the control command includes a progressive strategy formed according to a preset priority, the progressive strategy includes at least one of the following operations executed in sequence: changing the current control mode of one or more ports; adjusting the power setting value of one or more ports, wherein the power setting value is derived from the port operating status data; disconnecting one or more ports.
[0122] This step describes how to transform the abstract optimal control mode configuration obtained in step 401 into a series of specific, executable engineering operations that minimize system disturbance. This invention proposes a three-tiered progressive strategy, prioritizing lossless or minimally-damaged adjustment methods with the least impact on system operation, and only activating more impactful traditional methods when these methods fail to meet risk control requirements.
[0123] The first-level operation, and the preferred adjustment method of this invention, is to change the control mode of one or more ports. This is an advanced preventative control that directly mitigates risk by altering the coupling relationship between ports. For example, the system evaluation in the aforementioned embodiments revealed that a large-capacity energy storage port operating in droop mode, due to its large droop coefficient, formed a strong coupling relationship of 0.6 with a critical load port in the system, leading to a high risk of cascading overload. Traditional methods might only reduce the power output of this energy storage port to provide a margin, but this would sacrifice its power support capability for the system. This invention actively changes the control mode of the energy storage port from droop mode to constant power mode. According to the rules of Embodiment 2, after the mode change, its external coupling coefficient instantly drops to 0, cutting off the fault propagation path and eliminating the risk without changing its power output.
[0124] Level 2 operation is activated when Level 1 operation fails to eliminate the risk or when no feasible mode change plan exists. This involves adjusting the power settings of one or more ports. This is a more traditional preventative control measure, such as appropriately reducing the power output of high-risk ports or increasing their backup capacity to provide sufficient power margin to absorb potential shocks.
[0125] The third level of operation is the final defense barrier, which involves disconnecting one or more ports. This typically corresponds to traditional load shedding or power disconnection protection and is only executed when the system faces an unavoidable risk of widespread instability and the first two levels of operation have failed. It sacrifices some system functionality to ensure the safety of the core components.
[0126] In practice, after the central controller determines the optimal control mode configuration, it compares it with the current actual operating state of the system. The resulting difference constitutes the set of operation instructions to be executed. The controller will generate and issue these instructions sequentially according to the aforementioned three-level progressive priority, guiding the system to a safer and more robust operating state with minimal cost.
[0127] Optionally, to improve efficiency, the optimization problem can be solved using a two-stage mixed-integer optimization method. In the first stage, a series of candidate control mode combinations satisfying voltage support constraints are quickly generated through enumeration or heuristic search. In the second stage, for each candidate control mode combination, it is treated as a fixed parameter, and efficient algorithms such as linear programming are used to optimize the continuous power setpoint variable, calculate the minimum risk index under that combination, and finally determine the global optimal solution among all candidate combinations.
[0128] Example 5 proposes a novel closed-loop recovery strategy that differs from traditional open-loop, one-time recovery. The cascading risk assessment capability detailed in Example 3 is embedded into every stage of the recovery process. Through a feedback mechanism of single-step iterative recovery and multi-step forward-looking assessment, it ensures that the recovery process itself will not become a source of secondary failures, thereby improving the self-healing success rate and security of the system after a failure.
[0129] Step 501, the orderly recovery process of risk perception, such as Figure 3 As shown, the process includes: determining the recovery sequence of ports to be recovered according to a preset recovery priority; after each port is connected in the recovery sequence, invoking the step of assessing the risk of cascading failures at the system level to perform a security check on the current system status; in response to the result of the security check indicating that the risk does not exceed a preset security threshold, continuing to execute the connection of the next port in the recovery sequence; and in response to the result of the security check indicating that the risk exceeds the preset security threshold, pausing the recovery of subsequent ports or adjusting the control mode of the recovered ports.
[0130] In this embodiment, the recovery process is decomposed into a rigorous, sequential operation flow that includes feedback decisions. First, a recovery priority sequence needs to be planned. As a preferred implementation, this sequence planning can comprehensively consider multiple factors: the importance of the load or power supply connected to the port (e.g., ports supplying power to critical loads such as hospitals and data centers should be given the highest recovery priority); the port's contribution to system stability (e.g., energy storage ports or grid interfaces with constant voltage control capabilities should also have a higher recovery priority because they can provide critical voltage support to the system); and factors such as the port's rated capacity and the degree of improvement to the overall power balance of the system after connection.
[0131] After determining the recovery sequence, the controller will strictly follow the sequence to execute the port access operations one by one. After each port is successfully connected and its physical network connection is confirmed, the controller will not immediately start the recovery procedure for the next port. Instead, it will immediately trigger a comprehensive security check of the current new system state. Specifically, the controller will invoke a cascading fault risk assessment method, include the newly connected port in the healthy port set, and perform a complete cascading risk simulation of all possible initial fault points within the current system, calculating all corresponding system cascading fault risk indicators.
[0132] After completing the safety verification, the system enters the decision-making and feedback phase. The controller compares the maximum value of all calculated system cascading failure risk indicators with a preset safety threshold. This safety threshold is pre-set based on the system's safe operation specifications or offline simulation analysis, representing the maximum potential risk level that the system can tolerate.
[0133] If the verification results show that the maximum value of the current system cascading failure risk indicator is lower than the safety threshold, it indicates that the access of the new port does not pose a significant threat to system stability, and the recovery process is safe. At this point, the controller will authorize the continuation of the next step in the recovery sequence, namely, starting to access the port of the next priority.
[0134] However, if the security check results indicate that the risk exceeds the preset security threshold, it means that although the newly connected port is operating normally, its addition has altered the power flow distribution or dynamic coupling relationships of the system, making the overall system more vulnerable and in a critical, insecure state. In this case, the system will immediately suspend recovery operations for all subsequent ports to prevent further deterioration of the system. Simultaneously, the system will implement proactive risk intervention measures.
[0135] As an optional implementation, the controller can re-invoke the joint optimization blocking strategy, but this time the optimization target is the set of ports that have already been restored. By readjusting the control mode of the restored ports, for example, changing a port that contributed significantly to the risk from droop mode to constant power mode, its external coupling coefficient is reduced, actively lowering the current system risk level. The system will only be unsuspended and continue the subsequent recovery process once the risk level is brought back below the safety threshold through adjustment.
[0136] By implementing a closed-loop cycle of access-evaluation-decision-adjustment, this invention transforms the recovery process from a simple power-on action into a refined, intelligent process with self-sensing and dynamic adjustment capabilities, ensuring that the system always stays on a predictable and controllable safe track and gradually and steadily recovers to normal operation.
[0137] To illustrate the closed-loop recovery process more specifically, an exemplary recovery scenario is provided below. Assume an energy router system with four ports: port P1 is the grid interface, operating in constant voltage mode with a rated power of 100kW; port P2 is a photovoltaic array with a rated power of 40kW; port P3 is an energy storage unit, operating in droop mode with a droop coefficient k3 = 300W / V and a rated power of 50kW; and port P4 is a critical load with a rated power consumption of 100kW. Assume that after a cascading fault, ports P2 and P4 are offline. Currently, only ports P1 and P3 are online, and the system is in a degraded operating state. The cause of the fault has been eliminated, and P2 and P4 are ready to reconnect to the grid.
[0138] The central controller plans the recovery priority sequence according to preset rules. Since port P4 is a critical load, its importance weight w4 is the highest, and it is ranked first in the recovery sequence; port P2 is the photovoltaic array, and it is ranked second.
[0139] The central controller's control port P4 is connected to the system in constant power mode, with power consumption set to 50% of the original rated power, i.e., 50kW. After port P4 successfully connects to the grid, the controller immediately performs a safety check on the current system. Ports P1 and P3 are included in the calculation, and each online port is assumed to be faulty, and a cascading recursive evaluation is performed. The check results show that the maximum value of the current system's cascading fault risk index is 0.6, which is lower than the preset safety threshold of 0.8. The controller determines that the system is safe and authorizes the next step.
[0140] The central controller's control port P2 is connected to the system in constant power mode, with the output power set to 30kW. After port P2 successfully connects to the grid, the controller performs another safety check. This check shows that the addition of port P2 alters the system's power distribution, significantly reducing the power margin of port P1. The maximum value of the current system cascading fault risk index rises to 0.95, exceeding the preset safety threshold of 0.8. The system immediately suspends subsequent recovery operations.
[0141] The controller invokes a joint optimization strategy to adjust the control mode of the currently recovered port set. The optimization result suggests adjusting the control mode of port P3 from droop mode to constant power mode to reduce its external coupling coefficient and decrease the overall system risk. After executing this adjustment, the controller performs another safety check. At this point, the maximum value of the system cascading fault risk index has dropped to 0.65, which is below the safety threshold of 0.8. The recovery process is then unsuspended, and the system has safely completed the recovery of all ports.
[0142] Example 6 provides a specific, non-limiting system implementation scheme for the method described in the foregoing examples, and provides supplementary explanations of the key parameter configurations involved, so that those skilled in the art can fully understand and implement the present invention.
[0143] As a specific implementation, the method proposed in this invention can be deployed in a hierarchical control system. Physically, this system includes a central controller and multiple local port controllers, each bound to a power converter at a port of the energy router. The central controller is the core decision-making unit of the entire defense and recovery method, responsible for performing high-level computing tasks such as data acquisition, cascaded risk assessment, optimization decision-making, and recovery process management. It can be implemented using a powerful and stable industrial personal computer, a digital signal processor system, or a field-programmable gate array platform. As the underlying execution unit, the local port controllers are responsible for high-precision real-time control of their connected power converters, implementing specific control modes such as constant voltage, droop, and constant current. They are also responsible for collecting local port operating data and uploading it to the central controller, as well as receiving and executing control commands from the central controller.
[0144] In the system architecture of this embodiment, the central controller and all local port controllers are interconnected through a high-speed, reliable communication network. To ensure the real-time and deterministic nature of data exchange, this communication network can preferably use an industrial Ethernet protocol, such as the Ethernet control automation technology protocol EtherCAT or the process field network protocol PROFINET, or a controller area network bus, i.e., a CAN bus.
[0145] To support the effective operation of the method of this invention, the communication system needs to meet predetermined timeliness requirements. Specifically, the period for the central controller to collect operational status data from each port can be set between 50 milliseconds and 200 milliseconds. This timescale satisfies the requirements of the quasi-static evaluation model for system state snapshots while avoiding unnecessary data congestion. Correspondingly, the total delay from when the central controller detects an excessive risk or actual fault to when the generated control command is issued to the relevant port controller and executed should be controlled within several hundred milliseconds to ensure that defensive actions can effectively intervene before the cascading fault spreads widely.
[0146] It should be noted that the performance of the method of this invention depends on the proper configuration of several key preset parameters. The configuration of these parameters can be determined based on the specific design of the system or through extensive offline simulation analysis.
[0147] For example, the preset security threshold mentioned in Example 5 reflects the conservative strategy of the system operation. A lower threshold will make the recovery process more cautious, but may reduce the recovery speed; while a higher threshold has the opposite effect. Its specific value can be set according to the security level requirements of different application scenarios.
[0148] In Example 3, the cascading failure risk index is calculated using a series decay factor γ, which ranges from 0 to 1, reflecting the degree of attention paid to failures at different propagation depths. A γ value close to 1 indicates that the system is more sensitive to deep-seated, wide-ranging failure chains.
[0149] In addition, the importance weight w used in the calculation of this risk indicator j In this case, the system operator needs to manually assign a value based on the criticality of the devices or loads connected to each port. For example, a port that supplies power to a critical data center should be set to the highest importance level, while a port that supplies power to interruptible lighting can be set to a relatively lower importance level.
[0150] Furthermore, this invention involves two types of risk thresholds. The first type is a warning threshold used to trigger proactive defense procedures. This means that when the maximum value of the system cascading failure risk indicator assessed by the system in its current operating state exceeds this value, the system determines that there is a potential risk and initiates preventative control, corresponding to preset conditions. The second type is a security threshold used for security verification during the recovery process. This means that during the recovery process, the risk is reassessed after each port is connected; if the indicator exceeds this value, the recovery is paused.
[0151] As a preferred implementation, the safety threshold can be set lower than the warning threshold to ensure that the recovery process has a greater safety margin than during normal operation. For example, the warning threshold can be set to 1.5, and the safety threshold can be set to 0.8.
[0152] In one optional implementation, the threshold is determined as follows: based on the system's rated configuration parameters, offline simulation is used to pre-simulate each port's fault scenarios, the distribution of system cascading fault risk indicators under each scenario is statistically analyzed, and a corresponding quantile is set as the threshold according to the security level required by the system operator. Engineers can make adaptive adjustments according to the actual application scenario.
[0153] It is understood that the above-described system architecture, communication protocol, and parameter configuration method are merely one preferred implementation of the present invention. Those skilled in the art can make various adaptive modifications or combinations to the above scheme according to actual application needs and technical conditions, and such modifications or combinations should not depart from the core ideas and scope claimed by the present invention.
[0154] The following case study uses a proactive defense process in a high-risk operational scenario to illustrate how the system progresses from risk assessment to the final generation of control commands.
[0155] Assume an energy router system with four key ports. Port P1 is the grid interface, operating in constant voltage mode, serving as the system's voltage reference, with a current output power of 50kW and a rated power of 100kW. Port P2 is the photovoltaic array, operating in constant power mode, with a current output power of 30kW and a rated power of 40kW. Port P3 is the energy storage unit, operating in droop mode, with a droop factor k3 = 300W / V, a current output power of 20kW, and a rated power of 50kW. Port P4 is the critical load, operating in constant power mode, currently consuming 100kW of power.
[0156] At this point, the system power is balanced, i.e., 50+30+20=100, and the system is operating normally.
[0157] In this state, the central controller periodically performs risk assessments. This process simulates a failure at each port and rehearses the consequences. The focus is on analyzing a scenario where port P2, the photovoltaic array, fails, for example, when its power suddenly drops to zero due to cloud cover. In this scenario, the system would experience a 30kW power deficit.
[0158] According to the evaluation rules of this invention, since port P1 is in constant voltage mode, it will bear the entire power deficit to maintain bus voltage stability, while port P3, operating in droop mode, and port P4, operating in constant power mode, will not change their output. Port P1 requires an additional 30kW output, bringing its total output to 80kW. Although this does not exceed its 100kW rating, its power margin has dropped sharply from 50kW to 20kW.
[0159] At this point, although the system had not yet experienced a cascading failure, it had become extremely vulnerable, with the sole voltage source, P1, on the verge of heavy load. The calculated system cascading failure risk index, taking into account both the sharp decline in margin and the importance of P1 as the sole voltage source, exceeded the preset warning threshold. Based on this, the system determined that the current state posed a significant potential risk and immediately activated its active defense program.
[0160] The system initiates an optimization algorithm to find a safer operating state. The algorithm aims to minimize the risk of cascading failures when any port fails. Its solution process is constrained by a series of core constraints. For example, the voltage support constraint states that the optimized new state must guarantee that the system still has a reliable voltage source. This constraint can be quantified as follows: in the new state, at least one port must operate in constant voltage mode, or at least two ports must operate in droop mode.
[0161] Optimizer analysis revealed that the root cause of the current risk lies in the fragile structure of the single constant voltage source. Calculations yielded a better configuration: changing the system from a master-slave structure to a dual-core driven pure droop structure where ports P1 and P3 jointly handle voltage regulation and power surge. The optimized control mode configuration is as follows: port P1 changes from constant voltage to droop, with a droop coefficient set to k1 = 200W / V, and its power setpoint is reallocated to 65kW; port P2 remains unchanged; port P3 maintains droop mode with a droop coefficient of k3 = 300W / V, but its power setpoint is adjusted to 5kW; port P4 remains unchanged. This new state also satisfies power balance and voltage support constraints.
[0162] The central controller compares the optimal configuration with the initial state and generates specific control commands. These include: Command 1, sent to the P1 port controller: switch the mode from constant voltage mode to droop mode, setting the droop coefficient to k1; simultaneously, update the power reference value to 65kW. Command 2, sent to the P3 port controller: maintain the droop mode; update the power reference value to 5kW.
[0163] After executing the above instructions and the system stabilizes in the new state, the effectiveness of the proactive defense action can be verified. The controller again simulates a fault at the P2 photovoltaic port in the internal model. The system also generates a 30kW power deficit. However, under the new coupling relationship, since both P1 and P3 are in droop mode, this deficit will be automatically shared proportionally according to their respective droop coefficients. According to formula α... ij =k j / Σk m The power sharing ratio of P1 is α1 = 200 / (200+300) = 0.4, which is 40%; the power sharing ratio of P3 is α3 = 300 / (200+300) = 0.6, which is 60%. P1 bears an additional 0.4 × 30 = 12kW, and the total power becomes 77kW; P3 bears an additional 0.6 × 30 = 18kW, and the total power becomes 23kW.
[0164] As can be seen, under the new state, the impact is effectively distributed across the two ports, both of which operate within a safe range far below their rated capacity, significantly improving the system's stability margin. Through proactive reconfiguration, the system transforms from a high-risk cliff-like response mode into a resilient distributed response mode.
[0165] According to one aspect of this application, in the process of constructing the inter-port dynamic coupling matrix based on converter control modes and assessing cascaded fault risks, the calculation of the inter-port fault propagation coupling coefficient based on converter control mode classification is as follows:
[0166] Obtain the control mode identifier and control parameter value of all ports currently in normal operation from the port status parameter set, and construct the fault propagation coupling matrix between ports according to the following process.
[0167] Identify the control mode composition of the currently operating port set, determining whether there are ports operating in constant voltage mode, the number of ports operating in droop mode and their respective droop coefficients, and ports operating in constant current mode. This control mode composition directly determines the redistribution mechanism of fault power deficit among ports.
[0168] For any port that is assumed to be faulty, calculate the coupling coefficient of its power deficit propagating to each healthy port under the following two scenarios:
[0169] Scenario 1: When the set of healthy ports includes a port operating in constant voltage mode. The constant voltage mode port aims to maintain a constant DC bus voltage. When a port fault causes a power deficit, the constant voltage mode port quickly adjusts its output power to compensate for the deficit and suppress bus voltage fluctuations. Because the bus voltage is maintained at a relatively constant level by the constant voltage port, ports operating in droop mode hardly adjust their power output as they do not perceive significant voltage deviations, while ports operating in constant current mode maintain a constant current and remain completely unresponsive. In this scenario, the constant voltage mode port bears the entire power deficit, and its coupling coefficient is calculated using the following formula:
[0170] ;
[0171] Where, α ij This is the coupling coefficient for the propagation of power deficit from a faulty port to other ports. If multiple constant-voltage mode ports exist in the set of healthy ports, the deficit is shared by each constant-voltage mode port according to its rated capacity. The physical meaning of this scenario is that the constant-voltage port, as the anchor of the bus voltage, bears the fault impact alone and is the first port to face overload risk in the cascading fault propagation chain.
[0172] Scenario 2: When the set of healthy ports does not contain constant voltage mode ports, but only droop and constant current mode ports. This scenario typically occurs after the original constant voltage port has been deactivated due to overload. At this time, the DC bus lacks constant voltage regulation, causing a voltage deviation. Each droop mode port senses the voltage deviation according to its own droop characteristic curve and adjusts its power output accordingly to share the power deficit. The constant current mode port maintains a constant current and does not participate in deficit sharing. The coupling coefficient of each droop mode port is calculated proportionally to the droop coefficient; the formula has been elaborated in the previous embodiments and will not be detailed here. For ports operating in constant current mode, their coupling coefficient is zero. The physical meaning of this scenario is: without centralized regulation from constant voltage ports, the power deficit spreads to multiple droop ports proportionally to the droop coefficient, and the cascade fault changes from a concentrated impact mode to a distributed propagation mode.
[0173] After traversing all possible combinations of faulty and healthy ports to complete the above calculations, all coupling coefficients are assembled into a two-dimensional matrix with port numbers as row and column indices, forming a dynamic coupling matrix. The dynamic characteristic of this matrix is that the values of its elements are determined by the control modes and control parameters of each port in the current set of healthy ports, rather than by the physical connections or electrical topology between ports. When the control mode of the set of healthy ports or any of its ports changes, the matrix must be recalculated.
[0174] According to one aspect of this application, in the process of constructing the inter-port dynamic coupling matrix based on converter control mode and assessing cascaded fault risk, the step-by-step recursive cascaded fault propagation chain tracing and risk quantification are specifically as follows:
[0175] Obtain the dynamic coupling matrix and port power margin vector, and assume that each port of the energy router fails and goes out of operation. Then, trace and quantify the complete cascading fault propagation chain that may be caused by the following step-by-step recursive process.
[0176] A recursive initialization process is performed, marking the hypothetical faulty port as faulty; the actual transmission power of this port before it exits the state is the initial power deficit. All other normally operating ports are marked as healthy, forming the set of healthy ports for the current stage. Let the current cascade propagation stage be the first stage.
[0177] The first-level propagation calculation is performed to obtain the current dynamic coupling matrix. The coupling coefficients of the corresponding columns for each healthy port in the row corresponding to the faulty port are extracted. Each coupling coefficient is multiplied by the initial power deficit to obtain the additional power that each healthy port is forced to bear in this stage. This additional power is compared with the power margin of the port to calculate the overload risk index for each healthy port.
[0178] ;
[0179] in, α is an indicator of overload risk of the port in the first stage of propagation. ij Let ΔP be the coupling coefficient for port-to-port propagation in the current dynamic coupling matrix. i P is the power deficit caused by the failure of the port. j max P is the rated power capacity of the port. j 0 This represents the actual transmission power of the port before the fault occurred. When this value is greater than or equal to 1, the port is determined to have triggered overload protection and shut down due to power exceeding its rated capacity.
[0180] A cascading termination check is performed to examine whether any new overload exit ports have been added after the first stage of propagation. If the overload risk index of all healthy ports is less than 1, the cascading propagation terminates at the first stage, indicating that the current system has sufficient margin to absorb the impact of the fault. If the risk index of one or more ports reaches or exceeds 1, these ports constitute newly added faulty ports in this stage and need to proceed to the next stage of propagation.
[0181] Before entering the second-level propagation, the coupling matrix is dynamically updated. The following key operations are performed: ports newly added to the current level that have exited overload mode are removed from the healthy port set, and the healthy port set is updated. Since port exit changes the composition of each control mode in the system, especially when the exiting port happens to be the only constant-voltage mode port, the system's coupling mode will change from scenario one to scenario two, and the power deficit allocation mechanism will change. Therefore, the coupling coefficients of all port pairs must be recalculated based on the updated healthy port set and its current control mode, according to the method described in the previous calculation of the coupling coefficients for port fault propagation based on converter control mode classification, to generate the updated dynamic coupling matrix corresponding to this level.
[0182] The dynamic matrix update operation is the key difference between this recursive method and traditional cascaded fault calculation. In traditional power system cascaded fault analysis, line coupling is determined by network impedance, and each stage of propagation shares the same coupling matrix, or only performs topology updates after line disconnection. In this method, however, each stage of propagation generates a completely different coupling matrix due to changes in control mode caused by port exit. A typical evolution process is as follows: initially, the constant voltage port bears all the load, i.e., the coupling structure of scenario one; after the constant voltage port exits due to overload, the system transitions to a mode where the load is shared proportionally by drooping ports, i.e., the coupling structure of scenario two. The coupling matrix changes from a single-point centralized structure to a multi-point distributed structure, resulting in a qualitative change in the fault propagation path and intensity. This dynamic update mechanism allows this method to capture the cascading amplification or suppression effect of control mode reconfiguration caused by energy router port exit on subsequent cascaded propagation paths.
[0183] The propagation process continues at each subsequent level. Using the updated dynamic coupling matrix, the propagation amount of the power deficit from the newly added faulty port at this level to the remaining healthy ports is calculated. The total amount of extra power already borne by each port in previous levels is accumulated, and the overload risk index of the remaining healthy ports is recalculated to determine whether a new overloaded port has been generated. If a new overloaded port has been generated, the healthy port set and coupling matrix are updated again, and the process proceeds to the next level of propagation. This process is repeated level by level until either of the following termination conditions is met: no new overloaded ports are generated after a certain level of propagation, i.e., the cascading propagation terminates naturally, or all ports have entered the fault set, i.e., the system completely collapses.
[0184] Output the propagation chain record. For each hypothetical faulty port, record the complete recursive trajectory, including the total number of cascade propagation stages, the number of the newly added faulty port in each stage and its overload risk index value, the changes in the dynamic coupling matrix corresponding to each stage, and the final set of surviving ports and their control modes. Summarize the above information to form the cascaded fault propagation chain record for each port.
[0185] According to one aspect of this application, in the joint optimization process of cascaded fault blocking and optimal degradation operation based on control mode reconstruction, the two-stage mixed integer optimization solution and the three-level progressive blocking strategy generation are as follows:
[0186] The constructed joint optimization problem is solved using the following two-stage decomposition strategy.
[0187] The first stage involves enumerating and screening control mode combinations. Using the set of available control modes for each port in the current set of healthy ports as the search space, combination schemes for all port control mode configurations are generated. For each combination scheme, the voltage support constraint is checked sequentially to see if it is satisfied, i.e., whether it contains a constant voltage port or at least two drooping ports. Combinations that do not meet this constraint are eliminated. For each retained feasible control mode combination, a corresponding dynamic coupling matrix is generated using a coupling coefficient calculation method. A recursive method is used for rapid cascading depth estimation, calculating only one or two stages of propagation after the failure of the most vulnerable port. Combinations with cascading depths significantly exceeding safety requirements are eliminated, retaining several candidate combination schemes with the shortest cascading depths. Since the number of energy router ports is typically no more than ten, and each port typically has two to three selectable modes, even at the largest scale, the total number of combinations remains within a controllable range, and enumeration and screening can be completed in milliseconds.
[0188] The second stage involves continuous optimization of power setpoints and determination of the globally optimal solution. For each candidate control mode combination retained from the first stage, the control mode configuration remains unchanged, simplifying the optimization problem into a single-objective subproblem containing only continuous variables (power setpoints at each port). Under power balance constraints and port capacity constraints, the goal is to minimize the maximum value of the system cascading failure risk index. Linear programming or other applicable mathematical programming methods are used to optimize the allocation of power setpoints at each port. Engineers can choose an appropriate optimization algorithm based on the specific form of the objective function. For each candidate combination, its optimal objective function value and corresponding power allocation scheme are recorded. The optimal results of all candidate combinations are compared, and the scheme with the minimum global objective function value is selected as the final optimal control mode configuration scheme and power setpoints at each port.
[0189] Based on the optimization results, a three-level progressive blocking strategy is generated according to the following logic: The optimal control mode configuration is compared port-by-port with the current actual control mode to extract the ports requiring control mode changes and their target modes, forming the first-level blocking instruction, i.e., control mode reconstruction; the power setpoints of each port are compared with the current actual power to extract the ports requiring power reduction and their target power values, forming the second-level blocking instruction, i.e., power derating; if the estimated system cascading fault risk index after executing the first and second-level instructions is still higher than the safety threshold, the port with the largest contribution to cascading risk is selected for isolation and exit, forming the third-level blocking instruction, i.e., port isolation. The three-level instructions are arranged in execution priority order to form a blocking and degradation execution instruction sequence, which is then sent to the energy router control system for execution level by level.
[0190] This invention, by constructing a dynamic coupling matrix dependent on the control mode and performing cascading recursion, can accurately track fault propagation paths altered by changes in control mode. By optimizing the control mode as a decision variable, it can reduce cascading risks without changing the total system power output. Through closed-loop safety verification, it can promptly detect and suppress risk escalation during the recovery process. It should be understood that the specific risk reduction may vary depending on system size, port configuration, and parameter settings.
[0191] This application proposes a novel evaluation model that replaces the traditional static model by constructing a dynamic coupling matrix determined by the real-time control mode of the ports (such as constant voltage and droop modes). This model can accurately quantify the dynamic fault propagation path and intensity. After each stage of a cascading fault propagation, the coupling matrix can be dynamically recalculated based on the changing set of ports, enabling accurate tracking of the fault evolution process. This solves the problem of inaccurate risk assessment.
[0192] This application proposes a proactive defense strategy that uses control mode as an adjustable decision variable. By solving an optimization problem aimed at minimizing potential risks, the system configuration is proactively reconfigured before a fault occurs, preemptively severing the cascading propagation chain in an optimal manner, thus shifting the protection timing from reactive response to proactive prevention. This solves the problem of passive fault suppression.
[0193] This application designs a risk-aware closed-loop recovery process. After each step of the recovery sequence, a comprehensive security check is performed on the system, and the recovery process is dynamically adjusted based on the check results. This feedback mechanism effectively avoids secondary impacts on vulnerable systems during recovery operations, enhancing the overall resilience and self-healing capability of the system. It also solves the problem of blind system recovery.
[0194] The preferred embodiments of the present invention have been described in detail above. It should be noted that the various specific technical features described in the above embodiments can be combined in any suitable manner without contradiction. To avoid unnecessary repetition, the present invention will not describe the various possible combinations separately.
Claims
1. A method for fault prevention and recovery in cascaded energy routers, characterized in that, include: Obtain port operation status data for multiple ports of the energy router, which includes at least the actual power, rated power capacity, and current control mode of each port; Based on port operating status data, the risk of system-level cascading failures is assessed, and a system cascading failure risk index is obtained. In response to the system cascading failure risk index exceeding the preset risk threshold, or in response to the occurrence of an actual failure, control instructions are generated and executed to suppress the propagation of cascading failures. In response to fault clearing, an orderly recovery process based on risk awareness is executed according to changes in system cascade fault risk indicators to restore normal port operation.
2. The method according to claim 1, characterized in that, Assess the risk of system-level cascading failures, including: Based on the current control mode of each port in the port operation status data, a dynamic coupling matrix on which the control mode depends is constructed, and the system cascading fault risk index is determined based on the dynamic coupling matrix.
3. The method according to claim 2, characterized in that, The construction of the dynamic coupling matrix includes: Based on the control mode configuration of the ports that are in normal operation among multiple ports, a preset calculation rule is assigned to the fault propagation coupling coefficient between any two ports to obtain the fault propagation coupling coefficient between each port.
4. The method according to claim 3, characterized in that, The preset calculation rules include: In response to the presence of a port operating in constant voltage mode among the ports in normal operation, it is determined that the power deficit not shared by other mode ports shall be borne by the port operating in constant voltage mode, so as to calculate the fault propagation coupling coefficient between ports.
5. The method according to claim 3, characterized in that, The preset calculation rules include: In response to the absence of ports operating in constant voltage mode and the presence of ports operating in droop mode among the ports in normal operation, the power deficit is proportionally distributed among the ports operating in droop mode based on the droop coefficient of each port operating in droop mode, in order to calculate the fault propagation coupling coefficient between each port. The droop coefficient is derived from the port's operating status data.
6. The method according to claim 2, characterized in that, Assessing the risk of system-level cascading failures also includes: By tracing the cascading propagation chain step by step, the cascading fault propagation record is obtained. Furthermore, at each stage of the recursion, the dynamic coupling matrix dependent on the control mode is recalculated based on the set of ports in normal operation that have changed due to port overload exit.
7. The method according to claim 1, characterized in that, Generate and execute control instructions for suppressing the propagation of cascading faults, including: The control modes of multiple ports are treated as adjustable decision variables. By solving the optimization problem, the optimal control mode configuration is determined, and control commands are generated based on the optimal control mode configuration. Optimization issues: The goal is to minimize the risk of cascading failures in the system. It includes at least one constraint selected from the following: voltage support constraint and power balance constraint.
8. The method according to claim 7, characterized in that, The control instructions include a progressive strategy formed according to a preset priority, and the progressive strategy includes at least one of the following operations executed sequentially: Change the current control mode of one or more ports; Adjust the power settings of one or more ports, where the power settings are derived from port operating status data; Cut off one or more ports.
9. The method according to claim 1, characterized in that, The orderly recovery process of risk perception includes: According to the preset recovery priority, the recovery sequence of the ports to be recovered is determined. After each port is connected in the recovery sequence, the step of assessing the risk of cascading failures at the system level is called to perform a safety check on the current system status. If the security check result indicates that the risk does not exceed the preset security threshold, continue to access the next port in the recovery sequence; In addition, in response to the security check result indicating that the risk exceeds the preset security threshold, the recovery of subsequent ports is suspended, or the control mode of the recovered ports is adjusted.
10. The method according to claim 6, characterized in that, In each level of the recursion, the dynamic coupling matrix dependent on the control mode is recalculated, including: In response to a port operating in constant voltage mode exiting due to overload at a certain recursive level, resulting in no longer any constant voltage mode ports in the set of ports in normal operation, the fault propagation coupling mechanism is switched from a mode in which a single port centrally absorbs the power deficit to a mode in which multiple ports operating in droop mode proportionally distribute the power deficit, thereby realizing a structural update of the dynamic coupling matrix.