Debugging system and debugging method for secondary equipment of smart substation
By using a bypass injection device between the merging unit and the switch in a smart substation, fingerprint functions and closure verification technology are employed to solve the problem of difficulty in distinguishing data sources under multiple sources with the same key. This enables the verifiability and auditability of commissioning conclusions, thereby improving the security and standardization of the smart substation.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD
- Filing Date
- 2026-03-10
- Publication Date
- 2026-07-21
AI Technical Summary
In the scenario of live commissioning of smart substations, the test injection flow and the background flow in operation have the same key and multiple sources, which makes it impossible to distinguish the data source, audit the evidence chain, and verify the commissioning conclusions, thus posing a safety hazard.
By using a bypass injection device between the merging unit and the switch, and employing primary and secondary fingerprint functions with different parameters, the packet sequence is mapped and filtered to construct a set of injected clean flows. The completeness of the evidence chain is then verified using covering closure metrics and mutually exclusive closure metrics, ultimately generating an immutable digital digest.
It enables accurate identification of test data and background interference without relying on network layer identifiers, ensuring the verifiability and auditability of debugging conclusions, and improving the safety and standardization of smart substation operation and maintenance.
Smart Images

Figure CN122437267A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of substation secondary equipment commissioning technology, specifically to a commissioning system and method for secondary equipment in intelligent substations. Background Technology
[0002] With the rapid development of smart grid technology, smart substations have gradually become the mainstream form of power system construction. Smart substations utilize a fully digital process layer network to replace traditional analog cables, publishing sampled values through merging units and transmitting information via switches to support protection logic such as bus differential and circuit breaker failure. For digital substations in operation, their process layer network is usually a fully digital link and lacks redundant references from conventional instrument transformers. When performing non-power-off routine inspections, troubleshooting, or upgrades and commissioning of relay protection devices or measurement and control devices, commissioning personnel need to use testing instruments to inject analog sampled values into the process layer network to verify the device behavior. As a result, the background flow published by the merging unit in operation and the injected flow generated by the testing equipment will be transmitted concurrently with time-interleaved signals in the same communication link.
[0003] In such uninterrupted power supply commissioning scenarios, to ensure the device under test (DUT) responds correctly to test signals, engineering requirements dictate that the injected packets generated by the test equipment must maintain consistency with the operational merging unit in key protocol fields. This means both share the same flow key, including the VLAN identifier, destination MAC address, and SV application identifier. Due to this situation of multiple sources sharing the same key, existing subscription logic based on Layer 2 or Layer 3 network headers in switches, packet analyzers, or intelligent electronic devices struggles to operate effectively, unable to distinguish between test injected frames and real background frames mixed in the same link solely based on protocol header information. Furthermore, the lack of deep identification and traffic auditing methods for packet payload content in current technology makes it difficult for the system to prove whether a sampled frame originated from the field merging unit or the test instrument. This makes it difficult to accurately trace the cause of protection malfunctions or failures, and the commissioning conclusions lack verifiable and auditable objective evidence, posing potential risks to the safe operation and maintenance of substations. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention proposes a commissioning system and method for secondary equipment in intelligent substations, solving the problems of indistinguishable data sources, unauditable evidence chains, and difficulty in verifying commissioning conclusions caused by the existence of multiple sources with the same key between the test injection flow and the operating background flow in live commissioning scenarios.
[0005] To achieve the above objectives, the present invention provides the following technical solution:
[0006] By using a bypass injection device connected in series between the merging unit (MU) and the switch, the original message sequence on the MU side, the mixed frame sequence on the switch side, and the injected message record sequence can be obtained synchronously within the same time window.
[0007] Using primary and secondary fingerprint functions with different parameters, the frames in the original message sequence on the MU side and the injected message record sequence are mapped to generate primary and secondary fingerprint sets on the MU side, as well as primary and secondary fingerprint sets of the injection source.
[0008] Using the first-level fingerprint function and the second-level fingerprint function, the first-level fingerprint value and the second-level fingerprint value of the hybrid frame sequence on the switch side are calculated frame by frame. Frames in the hybrid frame sequence on the switch side whose first-level fingerprint value and second-level fingerprint value both exist in the first-level fingerprint set and the second-level fingerprint set of the injection source are selected to construct the injection clean stream set.
[0009] Verify whether the set of primary and secondary fingerprint values of the hybrid frame sequence on the switch side is completely covered by the fingerprint set on the MU side and the fingerprint set of the injection source, and whether the intersection of the fingerprint set on the MU side and the fingerprint set of the injection source is empty. Generate coverage closure index and mutual exclusion closure index. The fingerprint set on the MU side includes the primary and secondary fingerprint sets on the MU side, and the fingerprint set of the injection source includes the primary and secondary fingerprint sets of the injection source.
[0010] When the coverage closure metric and the mutual exclusion closure metric indicate complete data, a consistency evaluation value is calculated based on the comparison results between the injected pure stream set and the preset reference sequence, and a delivery summary is generated.
[0011] Furthermore, a commissioning system for secondary equipment in intelligent substations is proposed to implement the commissioning method for secondary equipment in intelligent substations as described above, including:
[0012] The data acquisition module is used to synchronously acquire the original message sequence on the MU side, the mixed frame sequence on the switch side, and the injected message record sequence within the same time window through a bypass injection device connected in series between the merging unit (MU) and the switch.
[0013] The fingerprint generation module is used to map the frames in the original message sequence on the MU side and the injected message record sequence using primary fingerprint functions and secondary fingerprint functions with different parameters, so as to generate a primary fingerprint set and a secondary fingerprint set on the MU side, as well as a primary fingerprint set and a secondary fingerprint set of the injection source.
[0014] The source identification module is used to calculate the primary fingerprint value and the secondary fingerprint value in the hybrid frame sequence on the switch side frame by frame using the primary fingerprint function and the secondary fingerprint function, and to filter out frames in the hybrid frame sequence on the switch side where both the primary fingerprint value and the secondary fingerprint value exist in the primary fingerprint set and the secondary fingerprint set of the injection source, and to construct a pure injection stream set.
[0015] The closure verification module is used to verify whether the set of primary and secondary fingerprint values of the hybrid frame sequence on the switch side is completely covered by the fingerprint set on the MU side and the fingerprint set of the injection source, and whether the intersection of the fingerprint set on the MU side and the fingerprint set of the injection source is empty. It generates a coverage closure index and a mutual exclusion closure index. The fingerprint set on the MU side includes the primary and secondary fingerprint sets on the MU side, and the fingerprint set of the injection source includes the primary and secondary fingerprint sets of the injection source.
[0016] The evaluation delivery module is used to calculate a consistency evaluation value and generate a delivery summary based on the comparison results between the injected pure stream set and the preset reference sequence when the coverage closure index and the mutual exclusion closure index indicate that the data are complete.
[0017] Compared with existing technologies, it has the following advantages:
[0018] This solution proposes a commissioning system and method for secondary equipment in smart substations, fundamentally overcoming the limitations of traditional network devices that rely solely on protocol header information for traffic identification. It solves the technical challenge of separating injected test flows from background load flows under multi-source conditions with the same flow key. Unlike existing technologies that distinguish data using VLANs or MAC addresses, this solution constructs a dual orthogonal mapping mechanism based on payload content. By introducing mathematical transformation algorithms with distinct parameters, it maps variable-length sampled value packets into unique deterministic fingerprints in a two-dimensional space. This achieves accurate identification of each frame of data in a hybrid link without relying on any network layer identifier. By leveraging the inherent differences in packet content to establish a strong mapping relationship between fingerprints and sources, even under extreme conditions where the flow keys are completely identical, the system can still deterministically separate test data from complex background interference, eliminating the uncertainty caused by manual comparison or probabilistic guessing.
[0019] This invention transforms traditional qualitative commissioning into a rigorous, logically consistent quantitative auditing process by constructing a closure verification system and an energy quantification evaluation model. The solution introduces a dual logical gating mechanism of coverage and mutual exclusion to automatically calculate the completeness and uniqueness of the data stream, ensuring that the dataset entering the evaluation stage is free from external interference and internal conflicts. Simultaneously, combined with normalized deviation energy calculation and digital digest binding technology incorporating timing information, this invention can not only quantitatively evaluate the waveform restoration accuracy of the tested equipment but also identify key elements throughout the commissioning process, forming an irrefutable electronic evidence package. This design ensures that the conclusions of live-line commissioning no longer rely on the operator's subjective experience but are based on a verifiable and tamper-proof data chain, significantly improving the safety and standardization of smart substation operation and maintenance. Attached Figure Description
[0020] Figure 1 This is a schematic diagram of the method flow of the present invention;
[0021] Figure 2 This is a schematic diagram of the system framework of the present invention. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] Please see Figure 1 This application provides a commissioning method for secondary equipment in intelligent substations;
[0024] The method specifically includes the following steps:
[0025] Step 1: This step utilizes physical layer intervention devices to establish a physical cutoff point between the merging unit and the switch. Through synchronous mirroring of bidirectional data capture and injection behavior at the hardware level, a raw dataset for subsequent tracing is constructed. The specific process is as follows:
[0026] This embodiment provides a fiber optic process bus live-line debugging bypass injection device. In a specific preferred embodiment, the injection device can take the form of a fiber optic process bus live-line debugging bypass injection box.
[0027] Disconnect the existing fiber optic connection between the output port of the merging unit (MU) and the input port of the switch in the substation process layer. Connect the fiber optic process bus power-on debugging bypass injection device in series to the fiber optic communication link between the merging unit (MU) and the switch. The connection method is as follows: connect the output fiber of the merging unit to the uplink input interface of the injection device, and connect the downlink output interface of the injection device to the input port of the switch via fiber optic cable. The injection device is internally configured in transparent transmission mode, maintaining the original VLAN configuration and transmission rate of the link.
[0028] Specifically, this step establishes a topology node with full traffic observation permissions through serial connection. Compared with the traditional switch port mirroring method, the physical cut-off point is located before the switch switching architecture, which can intercept the original packet timing and content before entering the switch. Moreover, the injection device adopts nanosecond-level low-latency hardware pass-through technology to ensure that the real-time sampling value transmission of the relay protection device by the in-operation merging unit is not affected while the observation point is established, thereby ensuring the safety of live commissioning.
[0029] It should be noted that the fiber optic process bus live-line debugging bypass injection device is a hardware device based on FPGA (Field Programmable Gate Array) or dedicated network processor. It has physical layer pass-through forwarding capability, that is, data packets are forwarded directly from the input PHY chip to the output PHY chip via FIFO queue without going through the operating system protocol stack inside the device, thereby ensuring the continuity and low latency of the data flow at the physical layer.
[0030] Set up a first and a second acquisition point on the forwarding path inside the injection device. Start the acquisition function and copy all Ethernet frames flowing through the first and second acquisition points in real time via the parallel data bus inside the injection device.
[0031] Specifically, the first acquisition point is located after the physical layer decoding module of the uplink input interface of the injection device and before any injected data merging logic, used to capture the pure raw output stream of the merging unit; the second acquisition point is located after the injected data merging logic and before the physical layer encoding module of the downlink output interface, used to capture the mixed stream containing transparent data and injected data. This setup utilizes the sequence of hardware data pipelines, ensuring that within the same time window, the data from the first acquisition point is a proper subset (in the absence of injection) or a fundamental set (in the presence of injection) of the data from the second acquisition point, providing physically independent data for subsequent determination of the injection source through differential or set operations.
[0032] It should be noted that the real-time replication refers to using the parallel logic inside the FPGA to copy the complete frame content to an independent storage buffer via bus listening as the data frame flows through the data bus. This process is independent of the forwarding logic and does not introduce additional forwarding latency to the original link. Simultaneously, a unified high-precision clock source (such as a temperature-controlled crystal oscillator or a locked IEEE 1588 PTP clock) is configured inside the injection device to provide nanosecond-level timing synchronization for the acquisition actions of the first and second acquisition points, ensuring that the data from both sides have a strictly consistent time domain reference.
[0033] During the injection of sampled value SV messages by the injection device, whenever the injection control logic sends a test message to the forwarding path, a recording action is triggered synchronously to write the complete binary content of the message to the log storage area.
[0034] Specifically, this step achieves "what is sent is what is recorded," unlike traditional testing methods that only record test case scripts. This step directly records the actual bit stream sent by the physical layer. Because industrial environments may experience microsecond-level scheduling jitter or bus contention, leading to subtle differences between the actual sent messages and the preset model (such as sequence number jumps or random padding values), synchronously recording the injected messages eliminates this uncertainty, ensuring that the injected sequence, serving as evidence, is completely consistent with the actual waveform on the line, thereby guaranteeing the uniqueness and non-repudiation of the evidence chain.
[0035] It should be noted that the recording trigger signal for the injected message is directly taken from the transmit enable signal of the injection sending module, ensuring the consistency of the recording action and the sending action in the clock cycle; the recorded content includes the Ethernet frame header, VLAN tag, APPID, and complete ASDU. The log storage area includes, but is not limited to, the device's built-in DDR memory, non-volatile NVMe solid-state drive, or external high-capacity storage media connected through a high-speed interface, to adapt to debugging recording needs of different durations.
[0036] Based on the same preset time window, the data collected and recorded in the above steps are serialized, idle characters and preambles are removed, only the Ethernet frame payload is retained, and three raw datasets are output: MU side raw message sequence A, switch side mixed frame sequence B, and injected message record sequence L.
[0037] Specifically, this step transforms the signal into a mathematical set, clarifying the boundaries of subsequent algorithm processing. The original message sequence A on the MU side represents the undisturbed operational background, the injected message record sequence L represents the definite interference source, and the mixed frame sequence B on the switch side represents the observed facts to be decoupled. These three satisfy an inherent logical causal relationship; that is, elements in B either originate from the pass-through of A or from the injection of L. This complete set relationship is the foundation for this scheme to solve the SV stream aliasing problem.
[0038] Define the original message sequence A on the MU side as:
[0039]
[0040] The above formula means that set A consists of elements Composition, where i is an index variable, with a value ranging from 1 to... ; This indicates the total number of raw packets collected from the MU side within this time window; This represents the binary byte string of the i-th Ethernet frame acquired in chronological order from the MU side.
[0041] Define the switch-side hybrid frame sequence B as:
[0042]
[0043] The above formula means that set B consists of elements Composition, where j is an index variable, with a value range from 1 to... ; This indicates the total number of mixed frames collected from the switch side within this time window; This represents the binary byte string of the j-th Ethernet frame collected in chronological order from the switch side.
[0044] Define the injection message record sequence L as:
[0045]
[0046] The above formula means that set L consists of elements Composition, where k is an index variable, with a value ranging from 1 to... ; This indicates the total number of frames that were actually injected within the specified time window. This represents the binary byte string of the kth injected frame recorded in the injection order.
[0047] It should be noted that the byte strings in the above sequence , , Each sequence contains all bytes from the destination MAC address to the end of the Frame Check Sequence (FCS). Although this step fully preserves the FCS field to maintain the originality of the data, in the subsequent fingerprint calculation implementation, depending on the processing mechanism of the process layer switch for the FCS or VLAN priority fields, the above fields can be selectively masked in the algorithm (e.g., setting the corresponding bits to zero) to avoid affecting the accuracy of source determination due to legitimate modifications to non-critical fields of the packet by the process layer switching device. In addition, each sequence is associated with a nanosecond-level timestamp generated by the unified clock source to assist in data alignment or abnormal timing analysis.
[0048] Step Two: This step constructs a decentralized mathematical evidence system based on the original physical layer data. By constructing a dual deterministic fingerprint function, each frame in the original message sequence A and the injected message record sequence L on the MU side is mapped to a fixed-length integer feature value, thereby generating a corresponding fingerprint set. This provides a basis for subsequent source identification in the mixed stream. The specific process is as follows:
[0049] Define computational functions that can map Ethernet frame byte strings of arbitrary length to fixed-length integers, including first-level fingerprint functions. With secondary fingerprint function .
[0050] Specifically, this step does not rely on traditional CRC checks or simple accumulation algorithms, but instead uses a multinomial hash algorithm to construct a mapping relationship, ensuring that the fingerprint exhibits an avalanche effect when any bit within the packet is flipped. First, for any Ethernet frame f, its byte string content is parsed into vector form. .in, The value represents the decimal value of the t-th byte in the frame's byte string, ranging from 0 to 255; m represents the total length of the frame's bytes.
[0051] Define the first-level fingerprint function as follows:
[0052]
[0053] In the formula, f represents any input Ethernet frame data. Let t be the value of the t-th byte in frame f, used as the coefficient of the polynomial. `p` is a first-level radix constant used to weight bytes at different positions, and `p` is a first-level prime modulus used to limit the numerical range of the result. To calculate the first-level fingerprint value, specifically, a discrete byte sequence is mapped to a point in the integer field using polynomial expansion, where... By assigning weights to positional information, changes in byte order can lead to significant changes in the calculation results, thereby achieving a unique representation of the frame content.
[0054] Define a secondary fingerprint function as follows:
[0055]
[0056] In the formula, As a second-order cardinal constant, choose the one with... The distinct values are modulo second-order prime numbers; choose values that are distinct from p. For the calculated secondary fingerprint Specifically, a second verification dimension orthogonal to the first-level fingerprint function was constructed. By using different cardinality and modulus, the second-level fingerprint is used to distinguish between different fingerprints even in the case of a very low probability of a first-level fingerprint collision, thereby eliminating the risk of hash collisions in engineering.
[0057] It should be noted that, in order to ensure the uniformity of the hash distribution, the parameter selection follows these rules: cardinality. and All prime numbers greater than 255 are selected (e.g. =257, =263), to ensure that the value space of a single byte can be completely covered by the radix; modulus p and All are selected from large prime numbers (e.g.) , Furthermore, in specific program implementations, to prevent intermediate results from overflowing the computer register width, Horner's rule should be adopted, that is, performing a modulo operation immediately after each multiplication and addition operation.
[0058] Traverse the original message sequence A on the MU side, and for each original frame in the sequence... Using the defined fingerprint function, calculate the corresponding feature values and aggregate them into a first-level fingerprint set on the MU side. MU-side secondary fingerprint set .
[0059] Specifically, this step transforms the background data stream into a mathematical whitelist. The system reads elements from sequence A one by one. Substitute and The formula calculates two integer values, which are then stored in a set data structure. Because the set data structure ensures the distinctness of its elements, this process automatically removes potentially duplicate or retransmitted frames from the link while generating the fingerprint, retaining only unique content features.
[0060] Define the first-level fingerprint set on the MU side. for:
[0061]
[0062] In the formula For the i-th original frame in sequence A, For frames The calculated first-level fingerprint, For the set consisting of all unique first-level fingerprints, specifically, through Establish a primary feature library of background traffic as the primary basis for subsequent determination of whether a frame originates from a merging unit;
[0063] Define the MU-side secondary fingerprint set for:
[0064]
[0065] In the formula, For frames The calculated secondary fingerprint, For a set consisting of all unique secondary fingerprints, through Establish a secondary feature library for background traffic to assist in verification when ambiguity exists.
[0066] Iterate through the injection message record sequence L, and perform an injection operation on each injection frame in the sequence. Using the defined fingerprint function, calculate the corresponding primary and secondary fingerprints, and aggregate them into a set of primary fingerprints for the injection source. With the injection source secondary fingerprint set.
[0067] Specifically, this step converts the injected action records into data. The system learns a feature library. It reads elements from sequence L one by one. The same hash algorithm is used to extract its content features. This process establishes a deterministic lookup table, and any frame that matches it can be deterministically traced back to the test injection behavior.
[0068] Define the first-level fingerprint set of injection sources. for:
[0069]
[0070] In the formula, For the k-th injection frame in sequence L, For frames The calculated first-level fingerprint, This is a set consisting of the first-level fingerprints of all injected frames. Specifically, through... Establish a primary feature library for injected traffic to quickly identify injected packets in mixed streams.
[0071] Define the set of secondary fingerprints for injection sources. for:
[0072]
[0073] In the formula, For frames The calculated secondary fingerprint, For the set consisting of the secondary fingerprints of all injected frames, through Establish a secondary feature library for injected traffic to ensure the accuracy of source determination.
[0074] Specifically, this step outputs four sets. , , , This will be passed to subsequent steps as a read-only criterion. Compared to directly storing and comparing GB-level raw messages, converting them into fingerprint sets results in a very high data compression ratio, and subsequent comparison operations are performed using string matching (with a complexity of O(n log n)). (where m is the frame length) is transformed into an integer lookup (complexity O(m)). This is the key technology that enables this method to support real-time online analysis of massive SV flows in substations.
[0075] Step 3: Obtain the mixed frame sequence B from the switch side and the fingerprint set evidence generated in Step 2. Without relying on the packet header flow key (such as VLAN, AppID) to distinguish the source, the test injection packets in the mixed flow are deterministically separated through the set's attribution proof, thereby solving the same-key aliasing problem. That is, when the test flow and the background flow have the exact same network identifier, blind source separation is performed using the uniqueness of the content fingerprint. The specific process is as follows:
[0076] Create an empty set of inject pure streams. And initiate a frame-by-frame traversal procedure for the hybrid frame sequence B on the switch side. For each frame in the hybrid frame sequence B... Call the defined first-level fingerprint function With secondary fingerprint function Calculate the first-level fingerprint value for each frame. With secondary fingerprint value .
[0077] Specifically, this step maps the mixed streaming data to be classified into the same feature space as the evidence set, preparing for subsequent set operations.
[0078] The calculated first-level fingerprint value With injection source primary fingerprint set Perform a matching operation.
[0079] The first-level decision logic is defined as follows:
[0080] like Then determine the frame It definitely does not belong to the injection stream, so it is directly marked as a non-injection frame and the subsequent steps are skipped.
[0081] like Then determine the frame A candidate injection frame is defined as a frame whose primary fingerprint exists in the primary fingerprint set of the injection source. At this point, to eliminate extremely low-probability hash collisions (i.e., a frame in the background stream has the same primary fingerprint as a frame in the injection stream) or double-attribution ambiguity in the mixed stream (i.e., the same fingerprint appears in both the background and injection sets), further steps are taken. With Injection Set (In the case of [the previous step]), further steps are required to confirm the ownership.
[0082] For frames marked as candidate injection frames We introduce a two-level fingerprint for orthogonal verification and construct a source determination function. Using the injection source secondary fingerprint set The results of the Level 1 judgment are reviewed.
[0083] Define source determination function as follows:
[0084]
[0085] In the formula, For the currently being processed mixed stream frame, from sequence B, This is a Boolean state constant, indicating that the frame has been deterministically authenticated as the injection source. This is a Boolean state constant, indicating that the frame is a non-injection source (i.e., from the background of the merging unit or unknown interference). This means that to determine if an injection source is a source, both primary fingerprint matching and secondary fingerprint matching must be met simultaneously.
[0086] Specifically, the formula achieves zero-false-detection proof of origin through a dual-locking mechanism. First-level matching filters out all possible injected frames, while second-level matching uses orthogonal hash parameters to eliminate any possible coincidental collisions. Only when a frame can be associated with the injected message in two independent mathematical dimensions is it legally recognized as originating from the test generation module of the injected device, thus completely solving the identity recognition problem in aliasing scenarios.
[0087] It should be noted that in cases of extreme ambiguity, namely... This indicates that the primary fingerprint cannot distinguish whether the frame originated from the background or was injected. At this point, the logical AND operation in the above formula automatically takes effect, forcing a check of the secondary fingerprint. Does it exist in In this way, deterministic disambiguation can be achieved by utilizing the spatial distribution differences of fingerprint functions.
[0088] Based on the above judgment results, all those that meet the criteria will be... frames Extracted from hybrid stream B, preserved in its original timing sequence, and stored in the injected pure stream set. .
[0089] Define output set as follows:
[0090]
[0091] in, The final generated set of injected pure streams serves as the sole input source for subsequent debugging and evaluation. This indicates that the filtering targets are limited to the range of mixed flows actually collected on the switch side. Specifically, this formula defines the data cleaning rules. Through this step, the system accurately reconstructs the clean test data flow from the dirty data flow mixed with background traffic. Unlike traditional VLAN and MAC-based filtering, each element in this set has evidence to support its source, ensuring the auditability of subsequent debugging conclusions based on this data.
[0092] It should be noted that the output of this step... Although the content should be highly consistent with the injected message record sequence L, it retains the actual timing characteristics after being forwarded by the switch (such as forwarding jitter, queuing delay) and possible packet loss characteristics. Therefore, It reflects both the injection intent of the tester and the actual transmission quality of the network, making it the most authentic basis for evaluating the performance of secondary equipment.
[0093] Step Four: After completing the initial source classification of the mixed streams, establish a logical audit layer based on set theory. This layer aims to automatically verify the integrity and consistency of the evidence chain generated in the previous steps. By calculating coverage closure and mutual exclusion closure metrics, it prevents irreversible loss of the evidence chain due to unknown interference or hash collisions, thereby determining whether to allow entry into the final debugging and evaluation stage. The specific process is as follows:
[0094] Perform fingerprint coverage checks on all elements in the mixed frame sequence B on the switch side and calculate the Boolean value of the coverage closure. This metric is used to verify whether each frame in the hybrid stream can find a corresponding fingerprint in the known source set, that is, to verify whether the hybrid stream fingerprint set is completely covered by the fingerprint sets of the MU side and the injection source.
[0095] The formula for calculating the covering closure is defined as follows:
[0096]
[0097] in, To cover the closure metric, use a boolean type (True / False). This indicates that for each frame in sequence B The observed fingerprint set is formed after calculating the primary and secondary fingerprints. and Let represent the Cartesian product set of the MU side and the injection source in the two-dimensional fingerprint space, respectively. Specifically, this formula expresses the constraint that observations in the two-dimensional space must have a source. If the formula holds true, it means that all packets output by the switch can be traced back to the merging unit or the injection device. If the formula does not hold true, it means that abnormal packets that are neither sent by the MU nor the injection device have appeared in the mixed flow (such as error frames generated by the switch itself, interference frames introduced from outside the link, or frames with fingerprint calculation errors). In this case, the system must issue an alarm to prevent unknown interference data from contaminating the debugging conclusions.
[0098] Perform a positive reciprocity check on the MU evidence and the injected evidence, and calculate the Boolean value of the mutual exclusion closure. This metric is used to verify whether there is feature overlap between the background stream and the injected stream in the two-dimensional fingerprint space, that is, to ensure that there is no logical contradiction that the same frame is proven to be from both the MU and the injection device.
[0099] The formula for calculating a mutual exclusion closure is defined as follows:
[0100]
[0101] in, This is a mutual exclusion closure indicator, of boolean type (True / False). This represents the Cartesian product set of the primary and secondary fingerprints on the MU side, i.e., the two-dimensional feature pairs of all MU frames. . This represents the Cartesian product set of the primary and secondary fingerprints of the injection source, i.e., the two-dimensional feature pairs of all injected frames. . For an empty set, specifically, the formula expresses the constraint of mutual exclusion of identities: if the intersection is empty (the formula is true), it means that under the constraint of dual fingerprints, no frame belongs to both the background set and the injection set at the same time, and the source division is absolutely clear; if the intersection is not empty (the formula is false), it means that there is a very high probability of fingerprint collision or original data acquisition error, which makes it impossible to mathematically distinguish the source of a frame. At this time, the evaluation must be terminated to avoid outputting an ambiguous debugging report.
[0102] According to the covering closure metric and mutual exclusion closure index Generate the final evidence status determination signal.
[0103] Specifically, the system performs logical AND operations. If the calculation result is true, then the evidence chain within the current test window is determined to be complete and unique, the aliased mixed stream has been evidence-based controlled, and the system allows the injection of the pure stream extracted in step three. The result is passed to step five for consistency evaluation. If the result is false, the chain of evidence is determined to have a gap or conflict. The system locks the output, does not perform further performance evaluation, and outputs a status code indicating incomplete evidence.
[0104] Specifically, through the closure verification in this step, this method transforms auditability from a qualitative description into quantitative mathematical calculations. In the complex electromagnetic environment of industrial sites, this verification mechanism can effectively identify hidden link faults or external network attacks, ensuring that the final delivered debugging report is built on a rigorous logical loop and eliminating the risk of false conclusions due to false data.
[0105] Step 5: This step, as the final stage of the debugging method, aims to establish a data-driven closed-loop evaluation system. Assuming the completeness of the evidence chain is confirmed in Step 4, only the injected pure stream extracted in Step 3 is used. As valid input, the response behavior or signal quality of secondary equipment is quantitatively evaluated, and all key process data are packaged to generate an immutable digital digest, thereby enabling the verification and auditability of debugging results. The specific process is as follows:
[0106] Reading Coverage Closure Metrics With mutual exclusion closure index Perform logic gating checks.
[0107] Specifically, only when the logical expression The system only initiates subsequent evaluation logic when the result is true. This mechanism enforces the execution logic of first confirming rights and then evaluating. If the closure indicator is false, it indicates that the input data contains interference frames of unknown origin or contains logical contradictions. The system will directly terminate the process and issue an alarm, thereby preventing erroneous evaluation conclusions caused by dirty data from being generated or accepted.
[0108] For the injection of pure stream set Each frame in The protocol is parsed to extract the sampled values (SV) and application service data units (ASDU) to construct the measured sample sequence. .
[0109] Specifically, this step is the data extraction process from the network transport layer to the application service layer. The system decodes the current and voltage sample values within the frame according to IEC61850-9-2 or relevant power industry standards, and arranges them in the order of the sampling counters in the message to form discrete time-series data for comparison with preset test cases.
[0110] Read the preset test case reference sequence from the debug test case library Compare it with the measured sample sequence Compare the results and calculate the content consistency assessment value J.
[0111] Specifically, the use case reference sequence This refers to the theoretical sampled value sequence generated before commissioning, based on relay protection testing standards or preset fault models (such as sinusoidal steady-state, transient decay, etc.). This sequence represents the standard waveform data that the secondary equipment should receive in an ideal lossless network environment. In this embodiment, the commissioning system directly retrieves the corresponding standard waveform file from the database based on the user-selected use case ID. This eliminates the need for repeated calculations in real-time testing, serving as a measure of the measured data. A benchmark for signal integrity. The measured sample sequence. With reference sequence Timing alignment is performed using the sampling counter in the message.
[0112] The formula for calculating the consistency assessment value is defined as follows:
[0113]
[0114] In the formula, J is the content consistency assessment value, a dimensionless numerical value. This is a sample index set, which is automatically generated by the logic state machine of the debug test cases. This corresponds to the index of all sampling points within the time window from the fault initiation time to the fault clearing time. For example, in a 50Hz system, if the test fault duration is 40ms, then... This contains the indices n of all discrete sampling points within the 40ms interval, where n is a set. The sampling point index variable in the data. The value of the nth sampling point in the measured sample sequence is used to analyze the self-injected pure flow. , The value of the nth sampling point in the test case reference sequence represents the desired ideal injected data. Specifically, this formula is based on the principle of normalized error energy. The numerator calculates the deviation energy between the measured waveform and the desired waveform, and the denominator is the total energy of the desired waveform. The closer this index J is to 0, the higher the consistency between the waveform of the actual injected line and the waveform designed in the test case. Compared with a simple binary judgment of pass / fail, index J provides a continuous and quantifiable quality evaluation dimension, which can objectively reflect the signal fidelity during live commissioning.
[0115] The key data objects generated in the previous steps are structured and packaged, and a globally unique delivery digest is generated using a one-way encryption algorithm. .
[0116] The formula for calculating the delivery summary is defined as follows:
[0117]
[0118] in, A fixed-length hash string is used as the digital fingerprint for this debugging task. Deterministic hash functions (such as SHA-256) possess collision resistance and irreversibility properties. This is a unique identifier for the debug test case executed this time. Equipment identification for secondary equipment (such as protection devices) being debugged.
[0119] Specifically, this step enables cryptographic binding of data throughout the debugging process. (Abstract) Covering background noise ( Injection behavior () ), cleaning results ( This method outputs all key information from the evaluation value J to the final conclusion (J). Any tampering with the original data (such as modifying logs or replacing data streams) will result in a mismatch between the recalculated hash value and the delivery digest, thus giving the debug report non-repudiable validity. Therefore, the final output of this method contains the evaluation value J and the digest. The commissioning evidence package. In the commissioning methods used for secondary equipment in smart substations, this marks a shift in commissioning work from experience-driven to data-driven, completely eliminating the audit blind spots caused by SV stream aliases, and ensuring that the conclusions of each live-line commissioning are verifiable, traceable, and reusable.
[0120] Furthermore, refer to Figure 2 As shown, a commissioning system for secondary equipment in intelligent substations is proposed to implement the commissioning method for secondary equipment in intelligent substations as described above, including:
[0121] The data acquisition module is used to synchronously acquire the original message sequence on the MU side, the mixed frame sequence on the switch side, and the injected message record sequence within the same time window through a bypass injection device connected in series between the merging unit (MU) and the switch.
[0122] The fingerprint generation module is used to map the frames in the original message sequence on the MU side and the injected message record sequence using primary fingerprint functions and secondary fingerprint functions with different parameters, so as to generate the corresponding primary fingerprint set and secondary fingerprint set on the MU side, as well as the primary fingerprint set and secondary fingerprint set of the injection source.
[0123] The source identification module is used to calculate the primary fingerprint value and the secondary fingerprint value in the hybrid frame sequence on the switch side frame by frame using the primary fingerprint function and the secondary fingerprint function, and to filter out frames in the hybrid frame sequence on the switch side where both the primary fingerprint value and the secondary fingerprint value exist in the primary fingerprint set and the secondary fingerprint set of the injection source, and to construct a pure injection stream set.
[0124] The closure verification module is used to verify whether the set of primary and secondary fingerprint values of the hybrid frame sequence on the switch side is completely covered by the fingerprint set on the MU side and the fingerprint set of the injection source, and whether the intersection of the fingerprint set on the MU side and the fingerprint set of the injection source is empty. It generates a coverage closure index and a mutual exclusion closure index. The fingerprint set on the MU side includes the primary and secondary fingerprint sets on the MU side, and the fingerprint set of the injection source includes the primary and secondary fingerprint sets of the injection source.
[0125] The evaluation delivery module is used to calculate a consistency evaluation value and generate a delivery summary based on the comparison results between the injected pure stream set and the preset reference sequence when the coverage closure index and the mutual exclusion closure index indicate that the data are complete.
[0126] The above embodiments are only used to illustrate the technical methods of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical methods of the present invention without departing from the spirit and scope of the technical methods of the present invention.
Claims
1. A method for commissioning secondary equipment in a smart substation, characterized in that, include: By using a bypass injection device connected in series between the merging unit (MU) and the switch, the original message sequence on the MU side, the mixed frame sequence on the switch side, and the injected message record sequence can be obtained synchronously within the same time window. Using primary and secondary fingerprint functions with different parameters, the frames in the original message sequence on the MU side and the injected message record sequence are mapped to generate primary and secondary fingerprint sets on the MU side, as well as primary and secondary fingerprint sets of the injection source. Using the first-level fingerprint function and the second-level fingerprint function, the first-level fingerprint value and the second-level fingerprint value of the hybrid frame sequence on the switch side are calculated frame by frame. Frames in the hybrid frame sequence on the switch side whose first-level fingerprint value and second-level fingerprint value both exist in the first-level fingerprint set and the second-level fingerprint set of the injection source are selected to construct the injection clean stream set. Verify whether the set of primary and secondary fingerprint values of the hybrid frame sequence on the switch side is completely covered by the fingerprint set on the MU side and the fingerprint set of the injection source, and whether the intersection of the fingerprint set on the MU side and the fingerprint set of the injection source is empty. Generate coverage closure index and mutual exclusion closure index. The fingerprint set on the MU side includes the primary and secondary fingerprint sets on the MU side, and the fingerprint set of the injection source includes the primary and secondary fingerprint sets of the injection source. When the coverage closure metric and the mutual exclusion closure metric indicate complete data, a consistency evaluation value is calculated based on the comparison results between the injected pure stream set and the preset reference sequence, and a delivery summary is generated.
2. The commissioning method for secondary equipment in intelligent substations according to claim 1, characterized in that, The simultaneous acquisition of the original message sequence from the MU side, the mixed frame sequence from the switch side, and the injected message record sequence within the same time window includes: Configure the bypass injection device in physical layer pass-through mode to establish a connection between the output port of the merging unit and the input port of the switch; A first collection point and a second collection point are set on the internal forwarding path of the bypass injection device. The first collection point is located before the injection data merging logic and is used to capture the original packet sequence on the MU side. The second collection point is located after the injection data merging logic and is used to capture the mixed frame sequence on the switch side. In response to the message transmission action of the bypass injection device, the generated injection frames are synchronously recorded to obtain the injection message recording sequence.
3. The commissioning method for secondary equipment in intelligent substations according to claim 1, characterized in that, Both the primary fingerprint function and the secondary fingerprint function are constructed using a multinomial hash algorithm and are applicable to any frame in the original message sequence on the MU side, the mixed frame sequence on the switch side, and the injected message record sequence. The process of mapping frames in the original message sequence and the injected message record sequence on the MU side to generate corresponding primary and secondary fingerprint sets on the MU side, as well as primary and secondary fingerprint sets of the injection source, includes: The variable-length byte string of any frame is parsed into a numerical vector. The value of each byte in the vector is weighted by its position using a radix constant. The weighted result is then accumulated and moduloed to obtain the fixed-length integer feature value of the frame. The integer feature values calculated for each frame in the original message sequence on the MU side are aggregated and deduplicated to form the primary fingerprint set and secondary fingerprint set on the MU side. The integer feature values calculated for each frame in the injected message record sequence are aggregated and deduplicated to form the primary fingerprint set and secondary fingerprint set of the injection source.
4. The commissioning method for secondary equipment in an intelligent substation according to claim 3, characterized in that, The first-level fingerprint function and the second-level fingerprint function each use different prime numbers as base constants, and the value of the base constant is greater than the maximum value that a byte can represent; The first-level fingerprint function and the second-level fingerprint function each select different large prime numbers as the modulus for the modulo operation to construct orthogonal fingerprint verification dimensions.
5. The commissioning method for secondary equipment in an intelligent substation according to claim 1, characterized in that, The process of filtering out frames in the switch-side hybrid frame sequence where both the primary and secondary fingerprint values exist in the primary and secondary fingerprint sets of the injection source, and constructing an injection clean stream set, includes: For any frame in the hybrid frame sequence on the switch side, if the first-level fingerprint value of the frame belongs to the first-level fingerprint set of the injection source, and the second-level fingerprint value of the frame belongs to the second-level fingerprint set of the injection source, the frame is determined to be an injection packet and is included in the injection clean flow set.
6. The commissioning method for secondary equipment in an intelligent substation according to claim 1, characterized in that, The generation of covering closure metrics and mutual exclusion closure metrics includes: Verify whether the set of primary and secondary fingerprint values of the hybrid frame sequence on the switch side constitutes a subset of the union of the fingerprint set on the MU side and the fingerprint set of the injection source, so as to generate the coverage closure index. Verify whether the intersection of the fingerprint set on the MU side and the fingerprint set of the injection source in the two-dimensional feature space composed of primary fingerprints and secondary fingerprints is empty, so as to generate the mutual exclusion closure index.
7. The commissioning method for secondary equipment in an intelligent substation according to claim 5, characterized in that, The process of filtering out frames whose two-level fingerprint values both exist in the injection source's first-level fingerprint set and second-level fingerprint set, and constructing an injection clean stream set, includes: According to the original reception timing of the hybrid frame sequence on the switch side, the injected packets are stored in the injected pure stream set, and the timing jitter characteristics and queuing delay characteristics of the injected packets after being forwarded by the switch are retained.
8. The commissioning method for secondary equipment in a smart substation according to claim 1, characterized in that, The method further includes: Perform a logical AND operation on the covering closure metric and the mutual exclusion closure metric. When the operation result is true, it indicates that the data indicated by the two metrics is complete. The calculation of the consistency evaluation value includes: Based on the principle of normalized error energy, the deviation energy between the measured sampled values in the injected pure flow set and the ideal sampled values in the preset reference sequence is calculated, and the ratio of the deviation energy to the total energy of the ideal sampled values is calculated as a quantitative indicator to measure waveform consistency. The preset reference sequence refers to a sequence of theoretical sampled values generated based on relay protection test standards or preset fault models.
9. The commissioning method for secondary equipment in a smart substation according to claim 1, characterized in that, Generate a delivery summary, including: A one-way cryptographic hash algorithm is used to process key debugging data and generate corresponding digital digest strings; The key debugging data includes at least: the fingerprint set on the MU side, the fingerprint set of the injection source, the coverage closure metric, the mutual exclusion closure metric, the injection clean stream set, the consistency evaluation value, the test case identifier for this debugging, and the device identifier of the device being debugged.
10. A commissioning system for secondary equipment in a smart substation, used to implement the commissioning method for secondary equipment in a smart substation as described in any one of claims 1-9, characterized in that, include: The data acquisition module is used to synchronously acquire the original message sequence on the MU side, the mixed frame sequence on the switch side, and the injected message record sequence within the same time window through a bypass injection device connected in series between the merging unit (MU) and the switch. The fingerprint generation module is used to map the frames in the original message sequence on the MU side and the injected message record sequence using primary fingerprint functions and secondary fingerprint functions with different parameters, so as to generate a primary fingerprint set and a secondary fingerprint set on the MU side, as well as a primary fingerprint set and a secondary fingerprint set of the injection source. The source identification module is used to calculate the primary fingerprint value and the secondary fingerprint value in the hybrid frame sequence on the switch side frame by frame using the primary fingerprint function and the secondary fingerprint function, and to filter out frames in the hybrid frame sequence on the switch side where both the primary fingerprint value and the secondary fingerprint value exist in the primary fingerprint set and the secondary fingerprint set of the injection source, and to construct a pure injection stream set. The closure verification module is used to verify whether the set of primary and secondary fingerprint values of the hybrid frame sequence on the switch side is completely covered by the fingerprint set on the MU side and the fingerprint set of the injection source, and whether the intersection of the fingerprint set on the MU side and the fingerprint set of the injection source is empty. It generates a coverage closure index and a mutual exclusion closure index. The fingerprint set on the MU side includes the primary and secondary fingerprint sets on the MU side, and the fingerprint set of the injection source includes the primary and secondary fingerprint sets of the injection source. The evaluation delivery module is used to calculate a consistency evaluation value and generate a delivery summary based on the comparison results between the injected pure stream set and the preset reference sequence when the coverage closure index and the mutual exclusion closure index indicate that the data are complete.