Power distribution network operation safety control method, device and equipment

By introducing Dynamic Operational Safety Space (DOSS) and hybrid intelligent optimization algorithms, the problem of the disconnect between distribution network safety verification and correction strategies has been solved, enabling precise perception and closed-loop control of distribution network operation, and improving safety and adaptability.

CN122456494APending Publication Date: 2026-07-24GUANGDONG POWER GRID CO LTD DONGGUAN POWER SUPPLY BUREAU
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610427630.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-01
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

In existing power distribution network operation safety control methods, safety verification and correction strategies are fragmented, lacking real-time linkage and closed-loop decision-making, resulting in the inability to accurately perceive and promptly handle power grid operation risks, and the potential for distributed resource regulation is not fully utilized.

Method used

By adopting the concept of Dynamic Operating Safety Space (DOSS), the complex physical safety constraints within the distribution network are transformed online into linearized, real-time updated fine boundaries. Combined with a hybrid intelligent optimization algorithm of sequential genetic algorithm and integer programming, the automation and closed-loop of safety verification and control are realized. The operation of the distribution network is optimized through multi-level verification and safety correction strategies.

Benefits of technology

It enables accurate perception of distribution network operation risks and economic, coordinated, and closed-loop safety correction, improving the safety and adaptability of distribution network operation and ensuring stable and reliable power supply to the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122456494A_ABST
    Figure CN122456494A_ABST
Patent Text Reader

Abstract

The application provides a power distribution network operation safety control method, device and equipment, and relates to the technical field of electric power. The method comprises the following steps: acquiring real-time operation data of a power distribution network, checking the real-time operation data through a pre-acquired safety check model to obtain a safety check result of the power distribution network. The safety check result comprises an operation state of the power distribution network and a decision instruction corresponding to the operation state. Finally, the decision instruction is executed. When the operation state of the power distribution network is an unsafe state, the decision instruction comprises executing a pre-acquired safety correction strategy. Through the above method, the technical problem that the power grid operation risk cannot be accurately perceived and timely disposed due to the split state of "checking and checking, correction and correction" in the existing power distribution network operation safety control technology is effectively solved, the accuracy of the power distribution network operation safety control is effectively improved, and the self-adaptability and operation resilience of the power distribution network are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power technology, and in particular to a method, device and equipment for safe control of power distribution network operation. Background Technology

[0002] With the large-scale integration of distributed resources into the distribution network, while improving the grid's absorption capacity, operating efficiency, and power supply reliability, the operation of the distribution network also exhibits strong randomness, volatility, and coupling, which can easily lead to safety issues such as voltage exceeding limits, power flow overload, and insufficient transformer capacity.

[0003] Existing power distribution network operation safety control methods often exhibit a disconnect between verification and correction. Safety verification primarily focuses on status assessment, lacking real-time linkage and closed-loop decision-making with multi-level correction strategies. This results in the inability to accurately perceive and promptly address power grid operation risks.

[0004] In conclusion, how to effectively improve the accuracy of power distribution network operation safety control is a technical problem that urgently needs to be solved. Summary of the Invention

[0005] This application provides a method, device, and equipment for controlling the safety of power distribution network operation, which can effectively improve the accuracy of power distribution network operation safety control and ensure the stable and reliable operation of the power distribution network.

[0006] In a first aspect, embodiments of this application provide a method for controlling the safety of power distribution network operation, including:

[0007] Obtain real-time operating data of the power distribution network;

[0008] Based on the real-time operating data, the safety verification result of the distribution network is obtained by verifying it through a pre-acquired safety verification model; wherein, the safety verification result includes the operating status of the distribution network and the decision instructions corresponding to the operating status;

[0009] Execute the decision instruction; wherein, when the operating state is an unsafe state, the decision instruction includes executing a pre-acquired security correction strategy.

[0010] In one possible implementation, the operational boundary of the security verification model includes a pre-acquired DOSS constraint set and a traditional boundary constraint set, and the method further includes:

[0011] If the DOSS constraint set is in a valid state, then the DOSS constraint set is determined as the running boundary of the security verification model;

[0012] If the DOSS constraint set is in an invalid state, then the traditional boundary constraint set is determined as the operating boundary of the security verification model.

[0013] In one possible implementation, the step of verifying the distribution network based on the real-time operational data using a pre-acquired security verification model to obtain the security verification result includes:

[0014] Based on the real-time operational data, multi-level verification is performed through the security verification model to obtain multiple preliminary verification results; wherein, the multi-level verification includes power range feasibility verification, scheduling plan safe execution verification, real-time operational status verification, and auxiliary service capability verification.

[0015] If any preliminary verification result is unsuccessful, the operating state is determined to be an unsafe state.

[0016] If all preliminary verification results are passed, the operating state is determined to be a safe state;

[0017] Based on the operating status, the decision instruction is determined.

[0018] In one possible implementation, determining the decision instruction based on the operating state includes:

[0019] If the operating state is a safe state, then the decision instruction is determined to be to execute the current scheduling plan;

[0020] If the operating state is unsafe, then the decision instruction is determined to be to execute the pre-acquired safety correction strategy.

[0021] In one possible implementation, the security correction strategy includes internal resource rescheduling, requesting negotiation of operating boundaries, or load / machine shedding control. When the operating state is an unsafe state, the method further includes:

[0022] Internal resource rescheduling was identified as the primary security correction strategy.

[0023] When the first security correction strategy has a feasible solution, the first security correction strategy is executed, and the scheduling plan obtained based on the first security correction strategy is determined as the new scheduling plan.

[0024] The real-time operating data of the distribution network after the first security correction strategy is executed is verified using the security verification model to obtain the first operating state of the distribution network.

[0025] When the first operating state is a safe state, the new scheduling plan is executed.

[0026] In one possible implementation, when the first operating state is an unsafe state or the first security correction strategy has no feasible solution, the method further includes:

[0027] The request to negotiate the operational boundary is defined as the second security correction strategy;

[0028] The second security correction strategy is executed, and the operating data of the distribution network after the second security correction strategy is executed is verified through the security verification model to obtain the second operating state of the distribution network.

[0029] In one possible implementation, when the second operating state is an unsafe state, the method further includes:

[0030] The load shedding / machine shedding control was determined as the third safety correction strategy;

[0031] Execute the third security correction strategy.

[0032] In one possible implementation, the population includes multiple chromosomes, each chromosome corresponding to a feasible solution of the first security correction strategy, and each feasible solution corresponding to a scheduling plan of the distribution network. The method further includes:

[0033] Initialize the population size, maximum number of iterations, and upper limit of computation time;

[0034] Multiple chromosomes are randomly generated using preset heuristic construction rules to obtain the initial population;

[0035] For each chromosome in the initial population, a new generation of population is generated iteratively based on sequential genetic algorithm and integer programming algorithm until the new generation of population meets the preset convergence condition;

[0036] The optimal chromosome in the new generation population is determined as the optimal solution for the first security correction strategy;

[0037] If the overall cost of the optimal scheduling plan corresponding to the optimal solution is less than a preset threshold, then the first security correction strategy is determined to have a feasible solution, and the optimal scheduling plan is determined as the new scheduling plan.

[0038] If the overall cost of the optimal scheduling plan is greater than or equal to the preset threshold, then the first security correction strategy is determined to have no feasible solution.

[0039] Secondly, embodiments of this application provide a power distribution network operation safety control device, comprising:

[0040] The first processing module is used to acquire real-time operating data of the power distribution network;

[0041] The second processing module is used to perform verification based on the real-time operating data using a pre-acquired security verification model to obtain the security verification result of the distribution network; wherein, the security verification result includes the operating status of the distribution network and the decision instructions corresponding to the operating status;

[0042] The third processing module is used to execute the decision instruction; wherein, when the operating state is an unsafe state, the decision instruction includes executing a pre-acquired security correction strategy.

[0043] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0044] The memory stores computer-executed instructions;

[0045] The processor executes computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0046] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0047] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0048] This application provides a method, apparatus, and equipment for safe operation control of a distribution network. The method involves inputting real-time operational data of the distribution network into a pre-constructed safety verification model for verification. This results in a safety verification result, including whether the distribution network's operating state is safe, and generates a corresponding decision instruction. Finally, the decision instruction is executed. When the distribution network's operating state is unsafe, the decision instruction includes executing a pre-acquired safety correction strategy. This method achieves closed-loop control of real-time data acquisition, model verification, and instruction execution, effectively solving the disconnect between verification and correction in existing distribution network operation safety control technologies. This significantly improves the safety and automation level of distribution network operation, and enhances the distribution network's adaptability and operational resilience. Attached Figure Description

[0049] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0050] Figure 1A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 1 ;

[0051] Figure 2 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 2 ;

[0052] Figure 3 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 3 ;

[0053] Figure 4 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 4 ;

[0054] Figure 5 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 5 ;

[0055] Figure 6 A schematic diagram of the structure of a power distribution network operation safety control device provided in this application;

[0056] Figure 7 This is a schematic diagram of the structure of an electronic device provided in this application.

[0057] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0058] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0059] The application background of this application is explained as follows:

[0060] With the large-scale integration of distributed resources such as distributed photovoltaics, distributed energy storage, and flexible loads into the distribution network, while significantly improving the distribution network's renewable energy absorption capacity, optimizing resource allocation efficiency, and enhancing system operation flexibility and power supply reliability, the distribution network also exhibits significant strong randomness, strong volatility, and multi-source coupling characteristics. This makes it extremely easy to trigger a series of safety operation problems such as node voltage exceeding limits, line power flow overload, insufficient transformer capacity, and heavy load overload, greatly increasing the difficulty of real-time safety management and stable operation of the distribution network.

[0061] Existing methods for power distribution network operation safety control often present a fragmented approach, separating verification from correction. Safety verification typically remains at the stage of assessing the distribution network's operational status, lacking real-time linkage and closed-loop decision-making with multi-level correction strategies. Correction strategies usually rely on sequential trial and error or simple protection tripping, resulting in inaccurate perception and timely handling of power grid operation risks. Furthermore, they fail to form a collaborative optimization system oriented towards minimum-cost intervention, integrating grid-side and resource-side regulation methods, leading to poor economic efficiency and adaptability.

[0062] Furthermore, regarding the safety operation boundary, existing distribution network operation safety control methods typically employ simplified boundaries that set fixed power limits at the point of common coupling. Such methods excessively aggregate the complex nonlinear safety constraints within the power grid, resulting in conservative and rigid boundaries that fail to accurately reflect the true carrying capacity of the distribution network, leading to a significant underutilization of the distributed resource regulation potential.

[0063] Therefore, how to accurately perceive the operational risks of the distribution network and trigger economic, coordinated, and closed-loop safety corrections, thereby improving the real-time performance and effectiveness of distribution network operation safety control, is an urgent technical problem to be solved.

[0064] Based on the aforementioned technical problems, the inventors, in the process of researching distribution network operation safety control methods, proposed the concept of Dynamic Operating Safety Space (DOSS). This concept transforms the complex physical safety constraints within the distribution network into linearized, real-time updated, fine-grained boundaries oriented towards distributed resource control commands, thus solving the problem of coarse-grained safety boundary modeling. Subsequently, through a hierarchical collaborative correction mechanism of online verification-real-time decision-making-closed-loop execution, when the distribution network safety verification fails, a pre-acquired progressive safety correction strategy is used. Furthermore, a hybrid intelligent optimization algorithm combining sequential genetic algorithms and integer programming is introduced to continuously optimize strategy parameters in a data-driven manner, ensuring the speed, economy, and global optimality of correction decisions, thereby achieving economic efficiency and adaptability in safety correction. Based on this, this application provides a distribution network operation safety control method, device, and equipment.

[0065] The technical solution of this application and how it solves the above-mentioned technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.

[0066] Figure 1 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 1 ,like Figure 1 As shown, the method includes:

[0067] S101: Obtain real-time operation data of the power distribution network.

[0068] In this step, real-time operating data refers to various power measurement information and equipment status information that reflect the current actual operating status of the distribution network, including but not limited to the real-time output and operating parameters of distributed resources such as node voltage, line current, active power, reactive power, load power, active power flow, and reactive power flow. This data can provide basic data support for the subsequent safe control of the distribution network operation.

[0069] Specifically, data can be collected in real time by data acquisition devices such as voltage and current transformers, phasor measurement units, and smart terminals deployed on power distribution lines, transformers, switching equipment, and distributed resource grid connection points. The data is then uploaded to the control system via the power communication network to form a usable real-time operation dataset, providing a data foundation for subsequent multi-level safety verification and hierarchical closed-loop safety correction of the power distribution network.

[0070] S102: Based on real-time operating data, the safety verification results of the distribution network are obtained by verifying the data through a pre-acquired safety verification model. The safety verification results include the operating status of the distribution network and the decision instructions corresponding to the operating status.

[0071] In this step, the operating state refers to the current safe or unsafe operating condition of the distribution network as determined by the safety verification model; the decision command refers to the dispatch control command or safety correction command that matches the operating state of the distribution network. The safety verification model uses a pre-defined resource aggregation model as its computational core and the constraint set determined by the control system as its operating boundary. It is used to perform safety verification on the acquired real-time operating data, determine whether the operating state of the distribution network is safe, and trigger corresponding control commands, thus achieving automation and closed-loop processing of the distribution network safety verification process. Optionally, in the safety verification model using the constraint set determined by the control system as its operating boundary, the constraint set includes both traditional boundary constraint sets and DOSS constraint sets.

[0072] Traditional boundary constraint sets can also be expressed as grid-side boundary constraint sets. These define the set of mandatory technical constraints imposed by the grid dispatching system to ensure the safe operation of the main grid (N-0, where N represents the total number of operating components in the distribution network, 0 represents no component failure or outage, and N-0 represents a fault-free normal operating state) while simultaneously regulating power interaction behavior at the point of common coupling. This grid-side boundary constraint set can serve as the external input and fundamental basis for this security verification model, transforming the complex internal physical security conditions of the power grid into simplified, executable operational boundaries.

[0073] Traditional boundary constraint sets are a conventional and conservative security assurance method used to simplify complex distribution network security conditions into a centralized constraint on the total power of the Point of Common Coupling (PCC), which may lead to a waste of distributed resource aggregation capabilities. In contrast, DOSS constraint sets maximize the aggregation and regulation capabilities and operational economy of distributed resources while ensuring the physical security of the distribution network. They can receive and process refined security constraint sets generated based on DOSS theory from higher-level grid dispatching agencies. This constraint set is a high-dimensional safe operating region defined by a set of linear inequality constraints on the active and reactive power of each controllable unit within the distributed resources. It can provide a more flexible scheduling optimization space for the distributed resource aggregation system while ensuring the overall security of the distribution network. It should be noted that in practical applications, the operating boundary of the security verification model can be either the grid-side boundary constraint set or the DOSS constraint set.

[0074] Optionally, the resource aggregation model is the core of the pre-defined distributed energy management system for unified digital representation and capacity calculation of its internal heterogeneous distributed resources. The constraints of this resource aggregation model define the mandatory constraints that must be met during operation, ensuring that the total output and total load within the distributed resource aggregation system remain in real-time balance. These constraints include both power balance constraints and resource operation constraints, specifically:

[0075] (1) Power balance constraint:

[0076]

[0077] in, N represents the net aggregation power of the distributed resource aggregation system at time t; PV N ESS N CL and N EV These represent the number of photovoltaic units, energy storage systems, controllable loads, and electric vehicle charging piles within the distributed resources, respectively. This represents the actual active power output of the i-th photovoltaic unit at time t; Let represent the discharge power of the j-th energy storage system at time t; Let represent the charging power of the j-th energy storage system at time t; This represents the active power consumption of the k-th controllable load at time t; This represents the charging power of the l-th electric vehicle charging station at time t; This represents the total power of all uncontrollable loads within the scope of distributed resource aggregation at time t.

[0078] (2) Resource operation constraints:

[0079] ① Photovoltaic unit constraints:

[0080]

[0081] in, This represents the predicted maximum available output of the i-th photovoltaic unit at time t.

[0082] ② Energy storage constraints:

[0083]

[0084]

[0085]

[0086]

[0087] in, This represents the state of charge of the j-th energy storage system at time t; This represents the state of charge of the j-th energy storage system at the next time step t+1; and Let represent the charging efficiency and discharging efficiency of the j-th energy storage system, respectively. Indicates the time step; This represents the rated capacity of the j-th energy storage system. and Let represent the minimum and maximum values ​​of the state of charge of the j-th energy storage system, respectively; and These represent the maximum allowable charging power and discharging power of the j-th energy storage system, respectively. This indicates the operating state of the j-th energy storage system (1 for charging, 0 for discharging). This constraint prevents simultaneous charging and discharging.

[0088] ③ Controllable load constraints:

[0089]

[0090] in, and Let represent the lower and upper limits of the power regulation of the k-th controllable load at time t, respectively.

[0091] ④ Electric vehicle constraints:

[0092]

[0093]

[0094]

[0095] in, This represents the state of charge of the battery of the l-th electric vehicle at time t; and These represent the minimum and maximum values ​​of the state of charge of the battery of the l-th electric vehicle, respectively. Indicates the time spent offline; This represents the target state of charge that the l-th electric vehicle is expected to achieve during the off-grid time. This represents the maximum charging power of the l-th electric vehicle.

[0096] Therefore, this safety verification model takes the resource aggregation model as the core of the calculation, the constraint set (traditional boundary constraint set / DOSS constraint set) determined by the control system as the operating boundary, and the real-time operating data obtained as the input. Its output is a binary decision signal S and the corresponding decision instruction. The binary decision signal is used to indicate whether the operating status of the distribution network is safe.

[0097] S103: Execute decision instructions.

[0098] When the operating state is unsafe, the decision instructions include executing a pre-acquired safety correction strategy.

[0099] Understandably, the execution of decision instructions is based on the binary decision signal and corresponding decision instructions output by the safety verification model in S102. The control system then issues and executes the corresponding control actions to each controllable unit.

[0100] Specifically, when the safety verification result indicates that the operating status of the distribution network is safe, the dispatching command to maintain the current operating condition is executed or the preset dispatching plan is authorized to be executed; when the safety verification result indicates that the operating status of the distribution network is unsafe, the corresponding safety correction strategy is triggered and executed. By adjusting the output of distributed photovoltaic power, the charging and discharging power of energy storage, and the power of controllable loads, the operating status of the distribution network is pulled back to the safe operating range to ensure stable and reliable power supply of the system.

[0101] The power distribution network operation safety control method provided in this application collects real-time operation data of the power distribution network and inputs it into a pre-constructed safety verification model. This model uses a preset resource aggregation model as its computational core and verifies the real-time operation data based on preset operating boundaries (including traditional boundary constraint sets or DOSS constraint sets generated based on DOSS theory) to obtain whether the operation state of the power distribution network is safe, and generates corresponding safety verification results for decision instructions. Finally, the control system executes these decision instructions; wherein, when the operation state of the power distribution network is unsafe, the decision instructions include executing a pre-acquired safety correction strategy.

[0102] The above methods have enabled the automation and closed-loop control of distribution network safety verification and control. By introducing a DOSS constraint set based on DOSS theory, it is possible to replace the traditional conservative constraint based solely on the total power of the point of common coupling, while ensuring the overall physical safety of the distribution network. This allows for a more thorough exploration and utilization of the aggregation and regulation potential of distributed resources, improving the economy and flexibility of distribution network operation and ensuring the stable and reliable power supply of the system.

[0103] Figure 2 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 2 ,like Figure 2 As shown, in this embodiment... Figure 1 Based on the embodiments, the method further includes:

[0104] S201: Obtain the DOSS constraint set and the power grid side boundary constraint set.

[0105] First, the complete network structure, line parameters, equipment characteristics, and other physical information of the distribution network are the fundamental basis. The electrical state of the distribution network during normal operation is accurately described by the power flow equation, which serves as the physical basis for the entire distribution network operation safety control method.

[0106] The mathematical representation of electrical state through power flow equations specifically includes:

[0107] For any node i in the distribution network, the active and reactive power balance at time t needs to satisfy the following equation, that is, the node power balance constraint can be expressed as:

[0108]

[0109]

[0110] in, and These represent the active power and reactive power injected by the distributed power source at node i, respectively. and These represent the active load power and reactive load power of node i, respectively. and These represent the active power and reactive power injected by the distributed power source at node i at time t, respectively. and These represent the active power flow and reactive power flow of the branch from node i to the adjacent node j, respectively. This represents the set of nodes directly connected to node i.

[0111] Power flow constraints can be expressed as:

[0112]

[0113]

[0114] in, and Let i and j represent the voltage amplitudes at time t, respectively. The voltage phase angle difference between node i and node j at time t is represented by... Calculations show that and Let represent the voltage phase angles of node i and node j at time t, respectively; and Let represent the conductance component and susceptance component of the admittance of branch ij, respectively; This represents the charge susceptance to ground of branch ij.

[0115] The node voltage safety constraint can be expressed as:

[0116]

[0117] in, and These represent the lower and upper limits of voltage allowed by the technical specifications, respectively.

[0118] The branch capacity safety constraint can be expressed as:

[0119]

[0120]

[0121] in, and Let represent the current and apparent power of branch ij, respectively. and These represent the thermal stability limits of current and apparent power, respectively.

[0122] Secondly, as mentioned in the aforementioned embodiments, the DOSS constraint set is an operational basis based on the optimization boundary constraints of DOSS theory, designed to overcome the shortcomings of traditional boundary constraint sets that may lead to wasted distributed resource aggregation capabilities. It is a high-dimensional safe operating region defined by a set of existing inequality constraints concerning the active and reactive power of each controllable unit within a distributed resource. The DOSS constraint set, based on the aforementioned nonlinear power flow equations and safety constraint terms, transforms them into a linearized and operable set of control commands for distributed resources through techniques such as online sensitivity analysis, thereby achieving efficient mapping and online verification of safety constraints. Mathematically, this can be represented as:

[0123]

[0124] Where N represents the total number of controllable distributed resources within the distributed resource; and These represent the active and reactive power setpoints (decision variables) of the j-th resource at time t, respectively. This represents the 2N-dimensional real space composed of the active and reactive power of all controllable distributed resources, which is the solution space where the decision variables reside. and This represents the real-time security coupling coefficient corresponding to the j-th resource in the m-th constraint; This represents the dynamic security limit corresponding to the m-th constraint, which is updated according to the operating status of the distribution network; M represents the total number of constraint items in the DOSS constraint set, which is positively correlated with the number of security critical points (such as sensitive nodes and heavy-load lines) that the distribution network needs to protect.

[0125] Optionally, the real-time security coupling coefficient matrix and It is generated by the distribution network operator through online sensitivity analysis based on real-time network topology, line parameters, basic power flow and safety margin. Specifically, it can use the adjoint matrix method or the Jacobian matrix inversion method based on power flow to calculate the sensitivity of distributed resource power changes to key safety indicators (such as node voltage and line load) in real time, and superimpose the predicted future time period safety margin changes. It can dynamically reflect the coupled impact of network topology changes and load fluctuations on the safety boundary and realize the forward-looking safety DOSS constraint set modeling.

[0126] For example, based on the current or predicted operating state of the distribution network, the sensitivity coefficients of active or reactive power changes in each controllable distributed resource unit to preset key safety indicators (such as sensitive node voltage, heavily loaded branch current, or apparent power) are calculated online using the adjoint matrix method or Jacobian matrix inversion / decomposition techniques based on power flow equations. Subsequently, based on the sensitivity coefficients and real-time safety margins... The above DOSS constraint set is obtained. ,in, and This refers to the sensitivity value, or the limit value. This is the dynamic security threshold.

[0127] In one possible implementation, to further improve the accuracy of the operational boundary, a data-driven adaptive optimization layer can be introduced. By continuously collecting historical operational data (including topology features, load levels, resource output, DOSS constraint sets, and actual verification results), a neural network machine learning model is trained. Using operational scenario features as input, it outputs optimized sensitivity coefficients or constraint parameters. This neural network machine learning model is used to compensate for model errors, generate predictive constraints, and supports online learning, dynamically adjusting parameters based on actual verification deviations, thereby continuously improving the adaptability and accuracy of the DOSS constraint set.

[0128] Understandably, by using online sensitivity analysis to linearize network flow and security constraints, a DOSS constraint set that can be directly mapped to resource-level control instructions is formed. It also supports adaptive optimization based on historical data from machine learning, enabling a leap from "static conservative" to "dynamic precise" operational boundaries.

[0129] Furthermore, as mentioned in the foregoing embodiments, the grid-side boundary constraint set is used to transform the complex internal physical security conditions of the power grid into simplified, executable operational boundaries. Mathematically, this grid-side boundary constraint set can be characterized as follows:

[0130]

[0131]

[0132]

[0133] in, It represents the total active power exchanged with the grid through the point of common coupling at time t. A positive value indicates that power is sent to the grid, and a negative value indicates that power is received from the grid. and These represent the lower and upper limits of the total active power that the power grid dispatching agency is allowed to exchange at the point of common coupling at time t, respectively. This represents the total reactive power exchanged with the grid through the point of common coupling at time t; and These represent the lower and upper limits of the total reactive power that the power grid dispatching agency is allowed to exchange at the point of common coupling at time t, respectively. Indicates the time interval between two consecutive scheduling or control cycles; This indicates the maximum permissible ramp rate of the total active power at the connection point, in MW / min.

[0134] S202: Determine whether the DOSS constraint set is in a valid state.

[0135] If yes, then execute S203; otherwise, execute S204.

[0136] The DOSS constraint set is automatically updated at fixed short intervals (e.g., every 5-15 minutes) to adapt to normal fluctuations in the operating status of the distribution network. Furthermore, a recalculation is immediately triggered when network topology changes, critical safety indicator exceedance warnings, or significant changes in superior dispatch instructions are detected.

[0137] For example, if any of the following occurs: the communication link between the upper-level power grid dispatch and the distributed resource aggregation system is interrupted, the data transmission delay times out, the DOSS constraint set calculation module malfunctions, or the distribution network topology undergoes a drastic change that causes the original sensitivity coefficient and safety limit to fail, then the DOSS constraint set is determined to be in an unavailable state, i.e., a failed state; otherwise, the DOSS constraint set is determined to be in an available state, i.e., a valid state.

[0138] S203: Determine the DOSS constraint set as the operating boundary of the security verification model.

[0139] In other words, if the DOSS constraint set is in a valid state, then the DOSS constraint set is determined as the operating boundary of the security verification model, that is, the DOSS constraint set is used as the highest priority boundary for security verification and optimization.

[0140] S204: Determine the traditional boundary constraint set as the operating boundary of the security verification model.

[0141] In other words, if the DOSS constraint set is in an invalid state, the traditional boundary constraint set will be determined as the operating boundary of the security verification model.

[0142] Understandably, if the DOSS constraint set is in a failed state, it will automatically revert to the preset traditional boundary constraint set (grid-side boundary constraint set) to ensure the basic safety of the distribution network.

[0143] The distribution network operation safety control method provided in this application further refines the mechanism for determining the operating boundary of the safety verification model. Specifically, it includes: firstly, obtaining two types of operating boundaries derived from the physical characteristics of the distribution network (such as power flow equations, node voltages, branch capacity constraints, etc.): one is the DOSS constraint set, which transforms nonlinear safety constraints into a linear inequality set through techniques such as online sensitivity analysis; the other is the traditional grid-side boundary constraint set based on the total power exchange limit at the point of common coupling. Subsequently, the operating boundary of the safety verification model is determined by judging whether the DOSS constraint set is in a valid state (e.g., normal communication, no faulty computing modules, no drastic topological changes, etc.). If the DOSS constraint set is in a valid state, it is determined as the operating boundary of the safety verification model; otherwise, the traditional boundary constraint set is determined as the operating boundary of the safety verification model. Through this method, the potential for distributed resource regulation and the improvement of operational economy and flexibility are fully utilized by leveraging the DOSS constraint set, while also retaining the traditional boundary as a safety baseline. This allows for seamless switching to the conservative but reliable traditional boundary constraint set in the event of communication interruption, thereby consistently ensuring the safe and stable operation of the distribution network and achieving a dynamic balance between safety and economy.

[0144] Figure 3 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 3 ,like Figure 3 As shown, in Figure 1 Based on the previous embodiment, in S102: based on real-time operating data, a safety verification model is used to perform verification to obtain the safety verification result of the distribution network, specifically including:

[0145] S301: Based on real-time operational data, multi-level verification is performed through a security verification model to obtain multiple preliminary verification results; among them, multi-level verification includes power range feasibility verification, scheduling plan safe execution verification, real-time operational status verification, and auxiliary service capability verification.

[0146] Specifically, the power range feasibility verification mainly checks the interaction power of the PCC and the output range of each distributed resource unit to verify whether the current power setting value meets the upper and lower limit requirements of the traditional boundary constraint set or DOSS constraint set, and ensures that the power interaction behavior does not exceed the physical limits of the power grid and equipment.

[0147] For example, the expression for power range feasibility verification can be represented as:

[0148]

[0149] in, and These represent the lower and upper limits of the total active power exchanged with the grid through the point of common coupling at time t, respectively. If this condition is met, the preliminary verification result of the power range feasibility check is considered passed; otherwise, the preliminary verification result of the power range feasibility check is considered failed.

[0150] The safe execution verification of the scheduling plan involves comparing real-time operating data with the preset scheduling plan, evaluating the execution deviation of scheduling instructions, and determining whether there are any problems such as deviation from the plan range or violation of scheduling timing requirements, so as to ensure the reliable implementation of the scheduling plan.

[0151] For example, the expression for verifying the safe execution of the scheduling plan can be represented as:

[0152]

[0153] in, This represents the active power of the dispatch plan issued by the upper-level power grid to the aggregation system at time t. If this condition is met, the preliminary verification result of the safe execution of the dispatch plan is determined to be passed; otherwise, the preliminary verification result of the safe execution of the dispatch plan is determined to be failed.

[0154] Real-time operation status verification takes the power flow equations of the distribution network and the power balance constraints of the nodes as the core, and combines key safety indicators such as voltage and line load to comprehensively verify whether the current real-time operation data meets the N-0 safety criterion, and promptly identify safety hazards such as voltage overruns and power flow overloads.

[0155] For example, the expression for real-time runtime status verification can be represented as:

[0156]

[0157] in, This represents the measured voltage value at the point of common coupling obtained by the measuring device at time t. This represents the measured value of the system frequency of the distribution network obtained by the measuring device at time t; and These represent the lower and upper limits of the system frequency's safety tolerance, typically ±0.2Hz from the rated frequency, such as 50±0.2Hz as specified in the national standard. If this condition is met, the preliminary verification result of the real-time operating status check is considered passed; otherwise, the preliminary verification result of the real-time operating status check is considered failed.

[0158] Understandably, when the operational boundary of the security verification model is determined to be the DOSS constraint set, its verification of the distribution network's operational status is no longer limited to the point of common coupling. Since the DOSS constraint set itself implicitly includes security checks on the voltages of multiple preset key security nodes and branch power flows within the distribution network, the expression for real-time operational status verification... and The verification process forms the final guarantee for power quality at the point of common coupling, based on the DOSS constraint set.

[0159] Ancillary service capability verification assesses whether the distribution network, under its current condition, possesses the potential to provide ancillary services such as peak shaving, frequency regulation, or reactive power support to meet the needs of the upper-level power grid. By calculating indicators such as adjustable capacity and response speed, it provides a basis for subsequent ancillary service invocation.

[0160] For example, the expression for verifying auxiliary service capabilities can be represented as:

[0161]

[0162] in, and These represent the actual increased and decreased reserve capacity of the distributed resource at time t, calculated in real time based on the internal resource status. and These represent the required increase and decrease in reserve capacity that the distributed resources need to provide to the power grid at time t, respectively, typically derived from contractual agreements with the power grid. If this condition is met, the preliminary verification result of the ancillary service capability check is determined to be passed; otherwise, the preliminary verification result of the ancillary service capability check is determined to be failed.

[0163] Understandably, four preliminary verification results can be obtained through S301, providing a basis for subsequent safety decisions and coordinated correction control.

[0164] S302: Determine whether all preliminary verification results are passed.

[0165] If yes, then execute S303; otherwise, execute S304.

[0166] S303: Determine that the operating status of the distribution network is safe, and determine the decision instruction to execute the current dispatch plan.

[0167] In other words, if all preliminary verification results pass, the operating state is determined to be safe. Further, based on the operating state, a decision instruction is determined. Specifically, if the operating state is safe, the decision instruction is to execute the current scheduling plan.

[0168] Understandably, the binary decision signal S = safe is output by the safety verification result if and only if all preliminary verification results pass. At this time, the distribution network meets the preset safety requirements in terms of power interaction, dispatch execution, steady-state operation, and ancillary service capabilities, and is authorized to execute the current dispatch plan. No additional safety correction control actions are required.

[0169] S304: Determine that the operating state of the distribution network is unsafe, and determine that the decision instruction is to execute the pre-acquired safety correction strategy.

[0170] In other words, if any preliminary verification result is unsuccessful, the operating state is determined to be unsafe. Further, based on the operating state, a decision instruction is determined. Specifically, if the operating state is unsafe, the decision instruction is to execute a pre-acquired safety correction strategy.

[0171] Understandably, if any preliminary verification result fails, the binary decision signal S = unsafe will be output by the safety verification result. At this time, the distribution network has at least one type of safety hazard, such as power exceeding the limit, plan deviation, operation index exceeding the standard, or insufficient ancillary service capability. In this case, the execution of the original dispatch plan will be terminated immediately, and the operation status of the distribution network will be pulled back to the safe range through the pre-acquired safety correction strategy.

[0172] The distribution network operation safety control method provided in this application, after acquiring real-time operation data of the distribution network, performs multi-level and multi-dimensional comprehensive verification through a pre-constructed safety verification model to obtain multiple preliminary verification results. Specifically, it includes four levels: power range feasibility verification, dispatch plan safety execution verification, real-time operation status verification, and ancillary service capability verification. These comprehensively evaluate the current operation status from the perspectives of power interaction boundaries, dispatch command execution deviations, grid steady-state safety criteria, and ancillary service support potential. Only when all preliminary verification results pass is the distribution network determined to be in a safe state and the original dispatch plan continues to be executed; if any preliminary verification result fails, the distribution network is determined to be in an unsafe state, and a preset safety correction strategy is immediately triggered to pull the system back to a safe operating range. Through this method, various safety hazards existing in the operation of the distribution network can be comprehensively and accurately identified, achieving an improvement from single-dimensional monitoring to multi-dimensional collaborative safety control, and enhancing the effectiveness of distribution network operation safety control.

[0173] Figure 4 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 4 ,like Figure 4 As shown, based on the above embodiments, the pre-acquired safety correction strategies include internal resource rescheduling, requesting negotiation of operating boundaries, or load / machine shedding control. When the operating state of the distribution network is unsafe, the distribution network operation safety control method further includes:

[0174] S401: Internal resource rescheduling is determined as the first security correction strategy.

[0175] In this step, internal resource rescheduling is the highest priority and most economical correction measure among the preset safety correction strategies. It aims to find a new and feasible internal scheduling scheme by initiating a rapid internal optimization process. In other words, the primary safety correction strategy is the most basic and highest priority safety correction method. By rapidly optimizing and adjusting within the distributed resource aggregation system, with the goal of minimizing power adjustment costs and aggregation capacity losses, the distribution network can be brought back to a safe operating range. This avoids disturbing the upper-level scheduling plan and quickly eliminates safety hazards at the lowest economic cost.

[0176] For example, internal resource rescheduling can be mathematically represented as:

[0177]

[0178] in, It represents the set of all controllable distributed resources within a distributed resource aggregation system; This represents the active power adjustment weighting coefficient for the i-th controllable resource, used to quantify the economic cost or technical price of adjusting a unit of active power. This represents the reactive power adjustment weighting coefficient for the i-th controllable resource, used to quantify the economic cost or technical price of a unit reactive power adjustment. This represents the active power adjustment of the i-th controllable resource, used to indicate the magnitude of change in the active power output or power consumption of that resource. This represents the reactive power adjustment amount of the i-th controllable resource, used to indicate the magnitude of change in the reactive power output or power consumption of that resource. This represents the capacity reduction factor due to security constraints, used to quantify the loss rate of aggregation and adjustment capabilities caused by cybersecurity constraints. This represents the congestion cost discount factor, used to... It is converted into an economic cost item that can be directly added to the power adjustment cost, balancing the adjustment cost and the loss of polymerization capacity. The value ranges from 0 to 1, and the larger the value, the more severe the loss of polymerization capacity.

[0179] The calculation formula is:

[0180]

[0181] in, This indicates the aggregate regulation capacity that the distributed resource cluster can actually call under the current operating boundary (DOSS constraint set or traditional boundary constraint set). It is calculated by security constraints and is the available regulation capacity limited by the physical security of the power grid. This means that, without considering the safety constraints of the distribution network, the inherent maximum physical aggregate capacity of the distributed resource cluster is determined solely by the physical output limit of each resource unit. The ratio of actual available capacity to maximum physical capacity is used to quantify the degree of reduction in aggregation regulation capacity due to security constraints, so as to provide an economical measure of security constraint loss and ultimately obtain an internal dispatch correction scheme that meets the security requirements of the distribution network and is economical and efficient.

[0182] In summary, internal resource rescheduling achieves optimal resource reallocation under security constraints by minimizing power adjustment costs and aggregation capacity loss costs. This ensures that while eliminating security risks, it not only pursues the minimum deviation from the original plan but also strives to reduce long-term capacity losses caused by network constraints, thereby optimizing the system's operational efficiency more globally.

[0183] S402: Determine whether the first safety correction strategy has a feasible solution.

[0184] If yes, then execute S403; otherwise, execute S407.

[0185] S403: Execute the first security correction strategy and determine the scheduling plan obtained based on the first security correction strategy as the new scheduling plan.

[0186] In other words, when the first security correction strategy has a feasible solution, the first security correction strategy is executed, and the scheduling plan obtained based on the first security correction strategy is determined as the new scheduling plan.

[0187] That is, if the first safety correction strategy can find the optimal solution within seconds and the optimal solution satisfies the preset conditions, the new scheduling plan obtained by the first safety correction strategy will be adopted. Replace the current scheduling plan .

[0188] S404: By using a security verification model, the real-time operating data of the distribution network after the first security correction strategy is executed is verified to obtain the first operating state of the distribution network.

[0189] Understandably, this step is a closed-loop verification of the internal resource rescheduling correction effect. By reusing the aforementioned multi-level verification logic, the safety compliance of dimensions such as power range, scheduling plan execution, real-time operating status, and ancillary service capabilities is checked again. This is to determine whether the internal resource adjustment has successfully brought the distribution network back to a safe operating range, and to provide a decision-making basis for whether a higher-level safety correction strategy needs to be initiated in the future.

[0190] S405: Determine whether the first operating state is a safe state.

[0191] If yes, then execute S406; otherwise, execute S407.

[0192] S406: Execute the new scheduling plan.

[0193] In other words, when the first operating state is a safe state, the new scheduling plan is executed.

[0194] The first operating state of the distribution network is a safe state, indicating that internal resource reschedules can eliminate potential safety hazards. Understandably, eliminating safety hazards is achieved by implementing a new scheduling plan.

[0195] S407: Request negotiation of the operating boundary as the second security correction strategy.

[0196] In other words, when the first operating state is an unsafe state or the first safety correction strategy does not have a feasible solution, the request to negotiate the operating boundary will be determined as the second safety correction strategy.

[0197] Understandably, if the first operating state of the distribution network is an unsafe state or the first security correction strategy does not have a feasible solution, it indicates that relying solely on internal resource rescheduling cannot eliminate the security risks of the distribution network. In this case, requesting negotiation to determine the operating boundary will be the second security correction strategy.

[0198] For example, in the distribution network operation safety control method provided in this application, the requested negotiation of the operation boundary follows an intelligent operation mode selection method. Specifically, if the distribution network operator pre-provides multiple DOSS constraint sets corresponding to different operation modes (such as different topologies, different safety margin strategies), the requested negotiation of the operation boundary specifically includes:

[0199] (1) Input the real-time running data into the security verification model and substitute it into each of the optional DOSS constraint sets for verification.

[0200] (2) For each security verification result, calculate the expected return C of the distributed resource cluster corresponding to the DOSS constraint set where the operating state of the distribution network is the safe state. VPP And congestion cost C VCC .

[0201] (3) The comprehensive cost (C) VPP +C VCC The lowest DOSS constraint set is determined as the new operating boundary for the security verification model to complete the request negotiation of the operating boundary. During the negotiation request process, not only are alarms about the inadequacy of the existing DOSS constraint set reported, but new operating boundaries are also proactively recommended, along with a quantitative benefit analysis.

[0202] Based on S402, if the first safety correction strategy cannot find a feasible solution within seconds, that is, there is a fundamental conflict between the internal capacity of the distribution network and the requirements of the power grid, the control system will negotiate with the superior power grid dispatching agency as a whole, specifically including the following two situations:

[0203] (1) If the preliminary verification result corresponding to the power range feasibility verification is unsuccessful, resulting in the distribution network operating state being unsafe, that is, the internal aggregation capacity range of the distribution network does not overlap with the allowable range of the power grid, the control system will send an alarm signal of insufficient capacity to the power grid and simultaneously report its own feasible domain data, requesting the power grid to modify or relax the power command at the point of common coupling.

[0204] (2) If the operating boundary of the security verification model is a traditional boundary constraint set (grid-side boundary constraint set), and the operating state of the distribution network is unsafe due to real-time abnormalities on the grid side (such as voltage exceeding the limit at the point of common coupling), then the network state is improved by requesting the grid to adjust the network operation mode, thereby creating feasible boundary conditions for the operation of the distribution network. After receiving the new boundary conditions issued by the grid, the distributed resource aggregation system will re-verify the security verification model based on these conditions.

[0205] S408: Execute the second security correction strategy and verify the operation data of the distribution network after the execution of the second security correction strategy through the security verification model to obtain the second operation state of the distribution network.

[0206] For details, please refer to the aforementioned embodiments, which will not be repeated here.

[0207] S409: Determine whether the second operating state is a safe state.

[0208] If yes, then execute S410; otherwise, execute S411.

[0209] S410: Agree to the request to negotiate the operational boundaries and determine the new operational boundaries.

[0210] In other words, if the second operating state is a safe state, then the request to negotiate the operating boundary is agreed upon, and a new operating boundary is determined.

[0211] The second operating state of the distribution network is a safe state, indicating that security risks in the distribution network can be eliminated by requesting negotiation of the operating boundary. Understandably, requesting negotiation of the operating boundary is achieved by agreeing to the request for negotiation of the operating boundary, thus determining a new operating boundary.

[0212] S411: Determine the load shedding / machine shedding control as the third safety correction strategy and execute the third safety correction strategy.

[0213] As the final line of defense for ensuring the physical safety of the distribution network, the load shedding / generator shedding control strategy is automatically executed when the aforementioned first safety correction strategy and second safety strategy are ineffective or when there is an emergency safety risk. Its core is to force the operating point of distributed resources back to the safe zone by actively and controllably reducing some non-core power loads or power generation unit outputs in an emergency.

[0214] For example, the execution process of load shedding / generator shedding control can be carried out according to a preset priority order, prioritizing the shedding or reduction of controllable loads with the least impact on user comfort and relatively low economic value (such as slow charging of electric vehicles, hot water energy storage, etc.), or reducing the output of non-critical distributed generation. The entire execution process adopts a closed-loop feedback mechanism, that is, while executing load shedding / generator shedding control, real-time operating data of the point of common coupling (such as voltage, current, system frequency, total active power, etc.) are monitored. Once all real-time operating data recover to a safe range, load shedding / generator shedding control is immediately stopped, thereby ensuring the safety and stability of the main grid and distributed resources with minimal necessary intervention.

[0215] Optionally, when performing protective load shedding / machine shedding control, to achieve the fastest possible recovery of safety while minimizing impact, the shedding priority can be dynamically calculated based on two dimensions: the certainty of adjustment potential and the ambiguity of user impact. The certainty of adjustment potential and the ambiguity of user impact can be quantified as follows:

[0216] (1) Determinism of adjustment potential: For resources with high output uncertainty (such as photovoltaics, which are greatly affected by weather), the current actual power that can be reduced may be lower than the rated value. Therefore, the reliable power that can be reduced is calculated by combining the latest forecast and measured data as the determination of adjustment potential.

[0217] (2) User impact fuzziness: Fuzzy comprehensive evaluation of the interruption impact of different types of loads is carried out, and a fuzzy impact score is formed based on the cost of breach of contract, loss of user comfort, social importance, etc.

[0218] The final resection order is determined by the following rules:

[0219] Prioritize reducing resources with high certainty of adjustment potential and low ambiguity of user impact (such as fully charged electric vehicle charging stations with no immediate travel plans); then consider resources with low certainty of adjustment potential or high ambiguity of user impact (such as energy storage systems currently supplying power to critical facilities).

[0220] In summary, the three safety correction strategies form a dynamic, hierarchical decision-making loop. It begins when the distribution network's operating state, as output by the safety verification model, is deemed unsafe. If so, the pre-acquired safety correction strategy must be executed. Specifically, this includes: first, automatically attempting internal resource rescheduling. If, after re-verifying the real-time operating data through the safety verification model, the distribution network's operating state changes to a safe state, then the distribution network resumes safe operation and is authorized to execute the predetermined scheduling plan. Conversely, if the rescheduling fails, the safety correction strategy automatically escalates, triggering a boundary condition negotiation request with the power grid dispatching agency. During the negotiation waiting period or in emergency situations where negotiation fails but safety risks escalate, protective load shedding / machine shedding control will be unconditionally activated to ensure safety through stringent measures.

[0221] In one possible implementation, every step of determining and executing the safety correction strategy, as well as the operating status and data of the distribution network, are fully recorded for subsequent event tracing, responsibility analysis, strategy evaluation, and model iterative learning. This continuously improves the self-healing ability and operational resilience of distributed resources without topology information, ultimately forming a complete safety management and control closed loop integrating perception, decision-making, and execution.

[0222] It can be seen that the power distribution network operation safety control method realizes the automatic triggering and closed-loop execution logic of the three-layer progressive correction strategy from verification to "internal optimization → grid-source negotiation → protection control" through the hierarchical closed-loop collaborative verification and correction mechanism of "verification-decision-execution-learning". It also integrates a data-driven learning mechanism to achieve collaborative autonomous correction of power distribution network safety risks with the lowest cost.

[0223] The distribution network operation safety control method provided in this application embodiment achieves multi-level defense from the most economical fine-tuning to emergency control by constructing a hierarchical and progressive safety correction strategy closed loop. Specifically, it includes: when the safety verification model determines that the distribution network is in an unsafe state, the first safety correction strategy, namely internal resource rescheduling, is first initiated. With the goal of minimizing power adjustment costs and aggregation capacity losses, a new scheduling plan is quickly optimized and generated within the distributed resource aggregation system. If the strategy has a feasible solution and the distribution network returns to a safe state after being verified again by the safety verification model, the scheduling plan is executed to complete the correction. Conversely, if the internal resource rescheduling strategy does not have a feasible solution or the verification result is still unsafe, the system is automatically upgraded to the second safety correction strategy, namely requesting negotiation of the operating boundary. This involves negotiating with the upper-level power grid to adjust the operating boundary or network operation mode to seek a new feasible scheduling scheme. If the negotiation is successful and the verification is safe, the corresponding scheduling plan is executed. Otherwise, the third safety correction strategy, namely load shedding / generator shedding control, is finally initiated. Non-core loads or outputs are dynamically shedding according to priority, and the operating point is forcibly pulled back to a safe range with hard measures to ensure the physical safety of the power grid.

[0224] The above methods achieve a progressive approach to safety correction measures while prioritizing economic efficiency. Under the premise of ensuring safety, the adjustment costs and user impact are minimized as much as possible. At the same time, closed-loop verification and full-process recording at each step provide data support for strategy evaluation and model iteration, effectively improving the self-healing capability, operational resilience, and adaptability to complex operating conditions of the distribution network.

[0225] Figure 5 A flowchart illustrating a power distribution network operation safety control method provided in this application. Figure 5 ,like Figure 5As shown, based on the above embodiments, the population includes multiple chromosomes, one chromosome corresponds to a feasible solution of the first security correction strategy, and each feasible solution corresponds to a scheduling plan of the distribution network. The distribution network operation security control method also includes a scheduling plan (new scheduling plan) obtained based on the first security correction strategy and a method for determining whether the first security correction strategy has a feasible solution, as detailed below:

[0226] S501: Initialize the population size, maximum number of iterations, and upper limit of computation time.

[0227] The purpose of the initialization phase is to build a diverse population, providing a starting point for subsequent evolutionary iterations. For example, assume the population contains N... p Number of chromosomes, i.e., population size N p The maximum number of iterations is G. max The computation time limit refers to the maximum allowed time threshold for iteration, typically measured in seconds or milliseconds. This is to prevent the algorithm from running indefinitely and to ensure real-time performance and feasibility. Let's assume the computation time limit is T. lim .

[0228] Among them, the population size N p The maximum number of iterations G can be flexibly set between tens and hundreds depending on the problem size, balancing computational efficiency and solution diversity; max The number of calculations is generally kept within several hundred, and can be adjusted appropriately according to real-time requirements; the upper limit of the calculation time T. lim The latency can be flexibly set according to hardware performance, problem complexity, and latency requirements, typically ranging from several milliseconds to tens of seconds. When the algorithm runtime reaches T... lim At that time, regardless of whether the maximum number of iterations G has been reached. max All iterations terminated to generate a new generation of population.

[0229] S502: Using preset heuristic construction rules, multiple chromosomes are randomly generated to obtain the initial population.

[0230] In this step, heuristic construction rules refer to the strategies and methods pre-defined based on experience or problem characteristics followed when generating chromosomes. This ensures that the chromosomes are not generated randomly and without any real order, thus making the generated chromosomes more closely match the solution requirements and closer to the distribution range of high-quality solutions, thereby improving the efficiency and effectiveness of subsequent optimization processes. For example, heuristic construction rules may include setting charging and discharging tendencies based on the current state of charge (SOC) of the energy storage device.

[0231] Furthermore, when randomly generating multiple chromosomes, a certain degree of randomness is maintained to ensure the diversity of the initial population, while heuristic construction rules are used to constrain the generation of invalid or inferior chromosomes, thus achieving a balance between diversity and quality in the initial population. In other words, the generation of the initial population combines both random generation and heuristic construction rules to improve the quality of the initial solution.

[0232] Understandably, the initial population is the first generation of the algorithm's iterations, used as the starting point for iterative optimization, providing a basic initial state for subsequent iterations to generate a new generation of populations.

[0233] S503: For each chromosome in the initial population, a new generation of population is generated iteratively based on sequential genetic algorithm and integer programming algorithm until the new generation of population meets the preset convergence condition.

[0234] In this step, the Sequential Genetic Algorithm (SGA) is an improved genetic algorithm for optimization problems with sequential order, permutation constraints, or temporal logic. Its core principle is to strictly maintain the legal order and permutation integrity of decision variables during evolutionary operations such as selection, crossover, and mutation, avoiding duplicates, conflicts, or invalid solutions that violate physical temporal order. This algorithm globally searches for the optimal sequence through population iteration, enabling rapid optimization in complex discrete spaces and effectively improving the stability and feasibility of the optimization process.

[0235] Integer programming (IP) is a class of mathematical programming methods that require all or some decision variables to take integer values. It is used to handle optimization problems with discrete choices, equipment start-up and shutdown, sequence number assignment, and other non-continuously separable variables. By finding solutions that satisfy integer constraints and the optimal objective function within the feasible region, it can effectively avoid invalid solutions in non-integer form and improve the executability and physical rationality of control commands.

[0236] Optionally, this power distribution network operation safety control method adopts a two-layer collaborative architecture of "outer-layer discrete decision optimization and inner-layer continuous variable solution," giving full play to the global search capability of the SGA algorithm in combinatorial optimization problems and the precise computational advantage of the IP algorithm in continuous variable optimization. Specifically:

[0237] Sequential genetic algorithm (SGA) is used to determine discrete decision variables, while integer programming (IP) algorithm is used to solve for continuous power variables based on these discrete decision variables. In other words, the outer SGA algorithm searches a high-dimensional discrete decision space, including the operating states (charging / discharging) of each energy storage unit, the switching states of controllable loads, and the charging mode priorities of electric vehicles. Through a population evolution mechanism, the SGA algorithm can effectively explore promising discrete decision combinations under complex constraints. The inner IP algorithm, based on the discrete states determined by the outer SGA algorithm, solves for continuous variables such as active and reactive power of each distributed resource, ensuring that the operating boundaries of the safety verification model are met and minimizing adjustment costs and congestion costs.

[0238] For example, for each chromosome in the initial population, during the iterative process of generating the next generation population, a hybrid intelligent optimization algorithm combining the SGA algorithm and the IP algorithm is used. This algorithm is employed to determine whether the internal resource rescheduling strategy has a feasible solution when the operating state of the distribution network output by the safety verification model is unsafe, and to generate a new scheduling plan that satisfies all safety and operational constraints if a feasible solution is found. Specifically, this hybrid intelligent optimization algorithm includes a chromosome hybrid encoding strategy, a fitness function, and genetic operators.

[0239] Specifically, this chromosome hybrid coding strategy represents heterogeneous decision variables through a hybrid coding method of binary coding, integer coding, and real number coding, achieving unified representation processing for different chromosomes. Among these, binary coding is used to represent the two-state operating mode of a device with only two working states, such as the charging and discharging state of an energy storage unit. (0 represents discharging, 1 represents charging), switch-type variables such as the switching status of controllable loads that only take 0 or 1; integer codes are used to represent multi-priority devices, such as electric vehicle charging priorities (integers 1~5, 1 represents the highest priority); real number codes represent continuous power variables and are used to provide an initial search point.

[0240] The fitness function F is used to comprehensively evaluate the merits of the scheme represented by the chromosome, and can be defined as:

[0241]

[0242] in, This represents the total cost obtained by the inner IP algorithm, calculated in the same way as the mathematical representation of internal resource rescheduling in S401; This indicates a penalty for constraint violation; if the inner IP issue is not feasible, then set... (M represents a maximum positive number); This indicates a response speed evaluation item, used to encourage solutions with smooth adjustment movements; , This represents the weighting coefficient, which can be optimized by learning from historical data.

[0243] The genetic operator design involves customizing the core operational rules of the hybrid intelligent optimization algorithm's evolutionary process to adapt to the aforementioned hybrid coding chromosome and ensure the stability and effectiveness of the optimization process. This includes selection, crossover, and mutation operators. The selection operator employs a combination of tournament selection and elite retention, which can select superior individuals to participate in the next generation of evolution while preserving historical optimal solutions, improving the algorithm's convergence efficiency and solution accuracy. The crossover operator can use uniform crossover, sequential crossover, and arithmetic crossover for different coding segments in the chromosome, ensuring that binary, integer, and real-number coding variables remain effective during gene recombination, avoiding the generation of physically infeasible solutions. The mutation operator uses an adaptive mutation rate strategy, dynamically adjusting the gene mutation amplitude according to the iteration process. This enhances global search capabilities in the early stages of the algorithm and strengthens local fine-tuning in the later stages, achieving a good balance between exploring the optimal solution space and ensuring solution feasibility.

[0244] In one possible implementation, for each chromosome in the initial population, the encoded chromosome is decoded to obtain the corresponding discrete control decision. Then, a simplified IP problem containing only continuous variables is constructed and solved based on this discrete decision. Finally, the fitness of the chromosome is calculated using the fitness function F. It should be noted that this process can be executed synchronously in parallel, thereby effectively improving the overall algorithm's computational speed.

[0245] After evaluating the fitness of multiple chromosomes, selection, crossover, and mutation operations are performed sequentially to generate a new generation of population with better performance. The entire iterative process continues until any of the following preset convergence conditions are met, at which point it stops: the maximum number of iterations G is reached. max Exceeding the allowed computation time limit T lim Or, the optimal fitness value has not significantly improved over multiple generations.

[0246] By combining the SGA algorithm with the IP algorithm, the hybrid intelligent optimization algorithm is used as the core computing engine for rapid internal resource rescheduling. It can achieve fast, economical and reliable correction decision generation under complex constraints, providing a foundation for the efficient operation of the entire hierarchical closed-loop correction system.

[0247] S504: Determine the optimal chromosome in the new generation population as the optimal solution for the first safety correction strategy.

[0248] Specifically, the chromosome with the best fitness and that satisfies all constraints in the new generation population obtained after iterative processing of the hybrid intelligent optimization algorithm is determined as the optimal solution of the first safety correction strategy. This optimal solution corresponds to the active and reactive power output adjustment scheme of each controllable unit within the distributed resource aggregation system. Under the premise of meeting the safety constraints of the distribution network, it can minimize the power adjustment cost and aggregation capacity loss cost. It is the best control instruction that can be directly executed in the internal resource rescheduling link.

[0249] S505: Determine whether the overall cost of the scheduling plan corresponding to the optimal solution is less than a preset threshold.

[0250] If yes, then execute S506; otherwise, execute S507.

[0251] Among them, the comprehensive cost refers to the total economic cost of executing the scheduling plan, and is the core indicator for measuring whether the scheduling plan is economically feasible.

[0252] As can be understood, as mentioned in the foregoing embodiments, the expression for the overall cost can be represented as:

[0253]

[0254] S506: Determine that the first safety correction strategy has a feasible solution, and determine the optimal scheduling plan as the new scheduling plan.

[0255] In other words, if the overall cost of the scheduling plan corresponding to the optimal solution is less than the preset threshold, then the first security correction strategy is determined to have a feasible solution, and the optimal scheduling plan is determined as the new scheduling plan.

[0256] Understandably, if the overall cost of the scheduling plan corresponding to the optimal solution is less than the preset threshold, it indicates that the scheduling scheme meets the requirements for safety correction of the distribution network while its economic cost is within the preset acceptable range. It achieves both safety correction of the distribution network operation status and meets the economic constraints. Therefore, it is determined that the first safety correction strategy adopted this time can effectively achieve the dual goals of safety and economy, and it has a feasible solution. A new scheduling plan that meets all safety and operation constraints is generated, namely the new scheduling plan.

[0257] S507: Determine that the first security correction strategy does not have a feasible solution, and redetermine the security correction strategy.

[0258] In other words, if the overall cost of the scheduling plan corresponding to the optimal solution is greater than or equal to the preset threshold, then the first security correction strategy is determined to have no feasible solution.

[0259] If the overall cost of the scheduling plan corresponding to the optimal solution is greater than or equal to the preset threshold, then the first security correction strategy is determined to be unfeasible. This indicates that the economic cost of the optimal scheduling scheme obtained under the current optimization conditions has exceeded the preset acceptable range and cannot simultaneously meet the dual requirements of distribution network security correction and economic constraints. In other words, it indicates that relying solely on the first security correction strategy (internal resource rescheduling) cannot eliminate the security risks of the distribution network. Therefore, the second security correction strategy (requesting negotiation of operating boundaries) is determined as the further security correction strategy.

[0260] In one possible implementation, to ensure the reliability and real-time performance of the hybrid intelligent optimization algorithm in a real power distribution network system, a parallel computing framework, degradation strategy, memory and hot-start mechanism, and parameter self-learning capability are integrated. Specifically:

[0261] (1) The overall computation time is shortened by solving multiple inner-layer IP problems simultaneously through a parallel computing framework.

[0262] (2) When the algorithm runtime reaches T lim If no feasible solution is returned, the system automatically switches to priority-based fast rule scheduling as a degradation strategy.

[0263] (3) Use solutions from similar historical scenarios to initialize the population to achieve a hot start, accelerate the convergence process, and continuously collect running data to optimize algorithm parameters, thereby continuously improving the adaptive capability of the hybrid intelligent optimization algorithm.

[0264] The power distribution network operation safety control method provided in this application adopts a hybrid intelligent optimization framework combining sequential genetic algorithm and integer programming algorithm when generating the first safety correction strategy. First, the population size, maximum number of iterations, and computation time limit are set through an initialization step. An initial population containing multiple chromosomes is randomly generated according to heuristic construction rules, with each chromosome representing a possible scheduling plan. Then, for each chromosome in the initial population, the algorithm enters a cyclic iterative process: the outer layer uses a sequential genetic algorithm to search for discrete decision variables (such as energy storage status and load switching), while the inner layer uses an integer programming algorithm to solve for continuous variables (such as power allocation) based on the determined discrete decisions. The fitness function is used to comprehensively evaluate the economy and feasibility of the scheme until the convergence condition is met, at which point the iteration ends, generating a new generation of population. Then, the optimal chromosome is selected from the new generation of population as the optimal solution for the first safety correction strategy. If the comprehensive cost of the scheduling plan corresponding to the optimal solution is less than a preset threshold, the first safety correction strategy is determined to have a feasible solution, and a new scheduling plan is output; otherwise, the first safety correction strategy is determined to have no feasible solution, and a request to negotiate the operating boundary is triggered as a subsequent correction measure.

[0265] The above methods have achieved a synergistic improvement and effective unification of the safety, economy and real-time operation of the distribution network. In other words, while ensuring the bottom line of safe operation of the power grid, it has effectively reduced regulation costs and resource losses, providing technical support for the safe, economical and efficient operation of the distribution network.

[0266] Figure 6 A schematic diagram of the structure of a power distribution network operation safety control device provided in this application is shown below. Figure 6 As shown, the power distribution network operation safety control device 60 provided in this embodiment includes:

[0267] The first processing module 601 is used to acquire real-time operating data of the power distribution network;

[0268] The second processing module 602 is used to perform verification based on real-time operating data and a pre-acquired security verification model to obtain the security verification result of the distribution network; wherein, the security verification result includes the operating status of the distribution network and the decision instructions corresponding to the operating status.

[0269] The third processing module 603 is used to execute decision instructions; wherein, when the operating state is unsafe, the decision instructions include executing a pre-acquired safety correction strategy.

[0270] In one possible implementation, the operational boundaries of the safety verification model include a pre-acquired DOSS constraint set and a traditional boundary constraint set. The distribution network operation safety control device 60 also includes a fourth processing module 604, used for:

[0271] If the DOSS constraint set is in a valid state, then the DOSS constraint set is determined as the running boundary of the security verification model;

[0272] If the DOSS constraint set is in an invalid state, then the traditional boundary constraint set will be determined as the operating boundary of the security verification model.

[0273] In one possible implementation, the second processing module 602 is specifically used for:

[0274] Based on real-time operational data, a multi-level verification was performed using a security verification model, resulting in several preliminary verification results. These multi-level verifications included power range feasibility verification, scheduling plan secure execution verification, real-time operational status verification, and auxiliary service capability verification.

[0275] If any preliminary verification result is unsuccessful, the operating status is determined to be unsafe.

[0276] If all preliminary verification results are passed, the operating status is determined to be a safe state;

[0277] Decision instructions are determined based on the operational status.

[0278] In one possible implementation, the second processing module 602 is further configured to:

[0279] If the running status is a safe state, then the decision instruction is to execute the current scheduling plan;

[0280] If the operating state is unsafe, the decision instruction is to execute the pre-acquired safety correction strategy.

[0281] In one possible implementation, the safety correction strategy includes internal resource rescheduling, requesting negotiation of operating boundaries, or load / machine shedding control. When the operating state is unsafe, the distribution network operation safety control device 60 further includes a fifth processing module 605, used for:

[0282] Internal resource rescheduling was identified as the primary security correction strategy.

[0283] When the first security correction strategy has a feasible solution, the first security correction strategy is executed, and the scheduling plan obtained based on the first security correction strategy is determined as the new scheduling plan;

[0284] The real-time operating data of the distribution network after the first security correction strategy is executed is verified by the security verification model to obtain the first operating state of the distribution network.

[0285] When the first operating state is a safe state, execute the new scheduling plan.

[0286] In one possible implementation, when the first operating state is an unsafe state or the first safety correction strategy has no feasible solution, the power distribution network operation safety control device 60 further includes a sixth processing module 606, used for:

[0287] The request to negotiate the operational boundary is defined as the second security correction strategy;

[0288] The second security correction strategy is executed, and the operation data of the distribution network after the second security correction strategy is executed is verified through the security verification model to obtain the second operation state of the distribution network.

[0289] In one possible implementation, when the second operating state is an unsafe state, the power distribution network operation safety control device 60 further includes a seventh processing module 607, used for:

[0290] The load shedding / machine shedding control was determined as the third safety correction strategy;

[0291] Implement the third security correction strategy.

[0292] In one possible implementation, the population includes multiple chromosomes, each chromosome corresponding to a feasible solution of the safety correction strategy, and each feasible solution corresponding to a scheduling plan for the distribution network. The distribution network operation safety control device 60 further includes an eighth processing module 608, used for:

[0293] Initialize the population size, maximum number of iterations, and upper limit of computation time;

[0294] Multiple chromosomes are randomly generated using preset heuristic construction rules to obtain the initial population;

[0295] For each chromosome in the initial population, a new generation of population is generated iteratively based on sequential genetic algorithm and integer programming algorithm until the new generation of population meets the preset convergence condition;

[0296] The optimal chromosome in the new generation population is determined as the optimal solution for the first safety correction strategy;

[0297] If the overall cost of the optimal scheduling plan corresponding to the optimal solution is less than the preset threshold, then the first security correction strategy is determined to have a feasible solution, and the optimal scheduling plan is determined as the new scheduling plan.

[0298] If the overall cost of the optimal scheduling plan is greater than or equal to the preset threshold, then the first safety correction strategy is determined to have no feasible solution.

[0299] The power distribution network operation safety control device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described again in this embodiment.

[0300] Figure 7 A schematic diagram of the structure of an electronic device provided in this application, such as... Figure 7 As shown, the electronic device 70 provided in this embodiment includes at least one processor 701 and a memory 702. Optionally, the electronic device 70 further includes a communication component 703. The processor 701, memory 702, and communication component 703 are connected via a bus 704.

[0301] In a specific implementation, at least one processor 701 executes computer execution instructions stored in memory 702, causing at least one processor 701 to perform the above-described method.

[0302] The specific implementation process of processor 701 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0303] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0304] The memory may include random access memory (RAM) in high-speed memory, and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0305] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0306] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0307] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0308] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0309] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside within an ASIC. Alternatively, the processor and the readable storage medium can exist as discrete components in a device.

[0310] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0311] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0312] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0313] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

[0314] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0315] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A method for safe operation control of a power distribution network, characterized in that, include: Obtain real-time operating data of the power distribution network; Based on the real-time operating data, the safety verification result of the distribution network is obtained by verifying it through a pre-acquired safety verification model; wherein, the safety verification result includes the operating status of the distribution network and the decision instructions corresponding to the operating status; Execute the decision instruction; wherein, when the operating state is an unsafe state, the decision instruction includes executing a pre-acquired security correction strategy.

2. The method according to claim 1, characterized in that, The operational boundary of the security verification model includes a pre-acquired DOSS constraint set and a traditional boundary constraint set. The method further includes: If the DOSS constraint set is in a valid state, then the DOSS constraint set is determined as the operating boundary of the security verification model; If the DOSS constraint set is in an invalid state, then the traditional boundary constraint set is determined as the operating boundary of the security verification model.

3. The method according to claim 1 or 2, characterized in that, The process of verifying the power distribution network based on the real-time operational data using a pre-acquired security verification model to obtain the security verification result includes: Based on the real-time operational data, multi-level verification is performed through the security verification model to obtain multiple preliminary verification results; wherein, the multi-level verification includes power range feasibility verification, scheduling plan safe execution verification, real-time operational status verification, and auxiliary service capability verification. If any preliminary verification result is unsuccessful, the operating state is determined to be an unsafe state. If all preliminary verification results are passed, the operating state is determined to be a safe state; Based on the operating status, the decision instruction is determined.

4. The method according to claim 3, characterized in that, Determining the decision instruction based on the operating state includes: If the operating state is a safe state, then the decision instruction is determined to be to execute the current scheduling plan; If the operating state is unsafe, then the decision instruction is determined to be to execute the pre-acquired safety correction strategy.

5. The method according to claim 4, characterized in that, The security correction strategy includes internal resource rescheduling, requesting negotiation of operating boundaries, or load / machine shedding control. When the operating state is an unsafe state, the method further includes: Internal resource rescheduling was identified as the primary security correction strategy. When the first security correction strategy has a feasible solution, the first security correction strategy is executed, and the scheduling plan obtained based on the first security correction strategy is determined as the new scheduling plan. The real-time operating data of the distribution network after the first security correction strategy is executed is verified using the security verification model to obtain the first operating state of the distribution network. When the first operating state is a safe state, the new scheduling plan is executed.

6. The method according to claim 5, characterized in that, When the first operating state is an unsafe state or the first security correction strategy has no feasible solution, the method further includes: The request to negotiate the operational boundary is defined as the second security correction strategy; The second security correction strategy is executed, and the operating data of the distribution network after the second security correction strategy is executed is verified through the security verification model to obtain the second operating state of the distribution network.

7. The method according to claim 6, characterized in that, When the second operating state is an unsafe state, the method further includes: The load shedding / machine shedding control was determined as the third safety correction strategy; Execute the third security correction strategy.

8. The method according to any one of claims 5 to 7, characterized in that, The population includes multiple chromosomes, one chromosome corresponds to a feasible solution of the first security correction strategy, and each feasible solution corresponds to a scheduling plan of the distribution network. The method further includes: Initialize the population size, maximum number of iterations, and upper limit of computation time; Multiple chromosomes are randomly generated using preset heuristic construction rules to obtain the initial population; For each chromosome in the initial population, a new generation of population is generated iteratively based on sequential genetic algorithm and integer programming algorithm until the new generation of population meets the preset convergence condition; The optimal chromosome in the new generation population is determined as the optimal solution for the first security correction strategy; If the overall cost of the optimal scheduling plan corresponding to the optimal solution is less than a preset threshold, then the first security correction strategy is determined to have a feasible solution, and the optimal scheduling plan is determined as the new scheduling plan. If the overall cost of the optimal scheduling plan is greater than or equal to the preset threshold, then the first security correction strategy is determined to have no feasible solution.

9. A power distribution network operation safety control device, characterized in that, include: The first processing module is used to acquire real-time operating data of the power distribution network; The second processing module is used to perform verification based on the real-time operating data using a pre-acquired security verification model to obtain the security verification result of the distribution network; wherein, the security verification result includes the operating status of the distribution network and the decision instructions corresponding to the operating status; The third processing module is used to execute the decision instruction; wherein, when the operating state is an unsafe state, the decision instruction includes executing a pre-acquired security correction strategy.

10. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1 to 8.