Five-prevention interlocking safety protection method and system based on multi-source state perception
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHANGZHOU SMART METRO TECH CO LTD
- Filing Date
- 2026-04-28
- Publication Date
- 2026-08-04
AI Technical Summary
[0003]现有五防闭锁系统多以预设流程放行为主,通常默认现场操作对象与作业票计划对象一致,难以对同类型相邻设备之间的误操作、错股道操作、错端位操作及状态表面正确但对象实际错误的情形进行有效识别;同时,现有系统对后续步骤的放行多基于单点状态确认,缺少对实际变位对象与后继操作对象之间对应关系的精确约束,在上游对象状态失效时也难以及时撤销已释放的后续许可,易造成闭锁控制精度不足和作业风险传递,故而需要基于多源状态感知的五防闭锁安全防护方法及系统解决上述问题
该基于多源状态感知的五防闭锁安全防护方法及系统,通过建立作业区段设备映射表,并结合候选设备组的操作前基准状态数据、操作后状态数据、电子钥匙授权记录和现场读取结果,确定当前步骤中实际发生状态变位的实际变位对象,再基于所述实际变位对象与计划对象的一致性校验结果,唯一确定对应的后继设备,生成下一步骤操作许可信息并在校验通过后释放下一步骤操作许可,从而能够有效区分计划对象与相邻同类型设备,避免错股道、错端位、错设备条件下的误放行;同时,通过在下一步骤执行期间持续校验实际变位对象的保持状态,并在保持状态失效时撤销下一步骤操作许可并恢复闭锁状态,能够防止上游状态失效后的风险向后续步骤传递,进而提升五防闭锁控制的对象识别准确性、步骤放行针对性及全过程安全防护可靠性。
Smart Images

Figure CN122501429A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of rail transit safety control technology, specifically to a five-prevention interlocking safety protection method and system based on multi-source state perception. Background Technology
[0002] In daily operations at rail transit depots, parking and inspection depots, and maintenance depots, processes such as power outages, voltage testing, grounding, working at heights, and power restoration are all considered high-risk operations. To reduce risks such as accidental disconnection / reconnection, accidental entry into energized areas, and grounding into live areas, the industry has gradually introduced five-proof interlocking devices, electronic keys, work ticket management terminals, and back-end interlocking management systems. These systems are evolving from simple mechanical interlocking to a combination of electrical interlocking, information prompts, and work records. With increasing depot operation frequency, denser equipment layout, and ever-increasing on-site control requirements, the five-proof interlocking system has become a crucial technical means to ensure the safe and orderly conduct of rail transit maintenance operations.
[0003] Existing five-prevention interlocking systems mostly rely on preset procedures for release, typically assuming that the on-site operation object matches the planned object on the work order. This makes it difficult to effectively identify misoperations, wrong track operations, wrong end position operations, and situations where the status appears correct but the object is actually incorrect between adjacent equipment of the same type. At the same time, existing systems rely on single-point status confirmation for the release of subsequent steps, lacking precise constraints on the correspondence between the actual changed object and the subsequent operation object. It is also difficult to revoke the released subsequent permission in a timely manner when the upstream object's status fails, which can easily lead to insufficient interlocking control accuracy and the transmission of operational risks. Therefore, a five-prevention interlocking safety protection method and system based on multi-source status perception is needed to solve the above problems. Summary of the Invention
[0004] To address the above problems, this invention provides the following technical solution: a five-prevention interlocking security protection method based on multi-source state perception, comprising: S1. Based on the five-prevention operation tasks of the target track, establish an equipment mapping table for the operation section. The equipment mapping table for the operation section records the correspondence between the planned object, the subsequent equipment corresponding to the planned object, and the candidate equipment group of the same type and spatially adjacent to the planned object. S2. Collect the pre-operation baseline status data of the candidate equipment group, which includes equipment coding data, track position data and equipment status data; S3. After performing the current step operation, collect the post-operation status data of the candidate device group, and compare the post-operation status data with the pre-operation baseline status data to determine the actual change object that actually changed its status in the current step. S4. Perform a consistency check between the actual displacement object and the planned object. If the check passes, determine the successor device corresponding to the actual displacement object according to the work section equipment mapping table. If the check fails, maintain the locked state of the successor device corresponding to the planned object. S5. Generate the next step operation permission information corresponding to the successor device, and verify the field reading object at the start of the next step. When the verification is successful, release the next step operation permission to the successor device. During the execution of the next step, continuously verify the holding state of the actual displacement object. When the holding state fails, revoke the next step operation permission and restore the successor device to the locked state.
[0005] Furthermore, the work section equipment mapping table includes a planned object identifier, a successor equipment identifier, a step type identifier, and a candidate equipment group identifier. The planned object identifier corresponds one-to-one with the successor equipment identifier, and the planned object identifier corresponds one-to-one with the step type identifier. The candidate equipment group identifier is used to represent a set of equipment of the same type as the planned object and spatially adjacent to the planned object.
[0006] Furthermore, the equipment coding data includes the equipment code, the track position data includes the track code and the end code, and the equipment status data includes the lock status, switch position status, voltage detection status, and grounding status.
[0007] Furthermore, S3 includes: Each candidate device in the candidate device group is compared before and after the operation. Combining the electronic key authorization record and the on-site reading result, the candidate device that meets the requirements of having an authorized operation record, changing the device status, and having the device code data and track position data in the post-operation status data consistent with the on-site reading result is determined. When the candidate object for displacement is unique, the candidate object for displacement is determined as the actual object for displacement. When the candidate object for displacement is empty or the candidate object for displacement is not unique, the locking state of the successor device corresponding to the planned object is maintained.
[0008] Furthermore, the equipment coding data and track position data of the actual displacement object and the planned object are compared item by item, and the step type corresponding to the actual displacement object is compared with the step type corresponding to the planned object. When all comparison results are consistent, the verification is deemed to have passed.
[0009] Furthermore, S4 includes: after the consistency verification passes, retrieving the successor device that uniquely corresponds to the actual displacement object from the work segment device mapping table, determining the next step type corresponding to the successor device according to the step type identifier, and identifying the successor device as the only device object allowed to execute the next step type operation after the current step ends.
[0010] Furthermore, generating the next-step operation license information corresponding to the subsequent device and releasing the next-step operation license includes: Write the device code data, track position data, and next step type of the subsequent equipment into the current job session; At the start of the next step, the equipment code data and track position data of the object to be read on site are collected and compared item by item with the equipment code data and track position data of the subsequent equipment recorded in the current work session. When all comparison results are consistent and the current start step type is consistent with the next step type, the operation permission for the next step is released.
[0011] Furthermore, the continuous verification of the retention status of the actual displacement object includes: continuously collecting device status data corresponding to the actual displacement object during the execution of the next step, comparing the continuously collected device status data with the post-operation status data, and determining that the retention status is invalid when the comparison results are inconsistent.
[0012] Furthermore, when the holding state is determined to be invalid, the permission for the next step operation is revoked, the subsequent device is prohibited from responding to the electronic key authorization command and the handheld terminal operation permission, and the subsequent device is restored to the locked state.
[0013] This invention also provides a five-proof interlocking security protection system based on multi-source state perception, including: The mapping table creation module is used to create a work section equipment mapping table based on the five-prevention operation tasks of the target track. The work section equipment mapping table records the correspondence between the planned object, the subsequent equipment corresponding to the planned object, and the candidate equipment group of the same type and spatially adjacent to the planned object. The baseline status acquisition module is used to acquire the pre-operation baseline status data of the candidate equipment group. The pre-operation baseline status data includes equipment coding data, track position data, and equipment status data. The actual displacement object determination module is used to collect the post-operation status data of the candidate device group after the current step operation is performed, and compare the post-operation status data with the pre-operation baseline status data to determine the actual displacement object that actually undergoes a state displacement in the current step. The consistency verification module is used to perform consistency verification between the actual displacement object and the planned object. When the verification passes, the module determines the successor device corresponding to the actual displacement object according to the work section equipment mapping table. When the verification fails, the module maintains the locked state of the successor device corresponding to the planned object. The permission output and lockout recovery module is used to generate the next step operation permission information corresponding to the successor device, and to verify the field read object at the beginning of the next step. When the verification is successful, the next step operation permission is released to the successor device. During the execution of the next step, the holding state of the actual displacement object is continuously verified. When the holding state fails, the next step operation permission is revoked and the successor device is restored to the lockout state.
[0014] Compared with the prior art, the present invention has the following beneficial effects: This five-prevention interlocking safety protection method and system based on multi-source state perception establishes a work section equipment mapping table and combines pre-operation baseline state data, post-operation state data, electronic key authorization records, and on-site reading results of candidate equipment groups to determine the actual change object that has undergone a state change in the current step. Then, based on the consistency verification result between the actual change object and the planned object, the corresponding successor equipment is uniquely determined, and the operation permission information for the next step is generated and released after verification. This effectively distinguishes the planned object from adjacent equipment of the same type, avoiding mis-release under conditions of wrong track, wrong end position, or wrong equipment. At the same time, by continuously verifying the holding state of the actual change object during the execution of the next step, and revoking the operation permission for the next step and restoring the interlocking state when the holding state fails, it can prevent the risk of upstream state failure from being transmitted to subsequent steps, thereby improving the object identification accuracy, step release targeting, and overall safety protection reliability of the five-prevention interlocking control. Attached Figure Description
[0015] Figure 1 A schematic diagram illustrating the steps of the five-prevention interlocking security protection method based on multi-source state perception provided by the present invention; Figure 2 A flowchart illustrating the five-prevention interlocking security protection method based on multi-source state perception provided by the present invention; Figure 3 This is a schematic diagram of the structure of the five-prevention interlocking safety protection system based on multi-source state perception provided by the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] To enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0018] Please see Figure 1-2 , Figure 1 A schematic diagram illustrating the steps of the five-prevention interlocking security protection method based on multi-source state perception provided by the present invention; Figure 2 This is a flowchart illustrating the five-proof interlocking security protection method based on multi-source state perception provided by the present invention; the present invention provides a five-proof interlocking security protection method based on multi-source state perception, including: S1. Based on the five-prevention operation tasks of the target track, establish an equipment mapping table for the operation section. The equipment mapping table for the operation section records the correspondence between the planned object, the subsequent equipment corresponding to the planned object, and the candidate equipment group of the same type and spatially adjacent to the planned object. Specifically, upon receiving the five-prevention operation task for the target track, the back-end control terminal first reads the track information, operation end position, and current operation node from the task, and then retrieves the equipment layout data and process connection data within the corresponding operation section of that track. Based on the track information, operation end position, and current operation node, the planned object to be operated in the current step is determined; based on the equipment layout data, equipment with the same equipment type as the planned object and located in adjacent tracks or adjacent ends is selected within the same operation section to form a candidate equipment group; based on the process connection data, the subsequent equipment corresponding to the planned object after the current step is completed is determined.
[0019] To further facilitate understanding by those skilled in the art, for example, when the current task is to disconnect the south-end disconnector of track 4, the planned object is identified as the south-end disconnector of track 4; the candidate equipment group may include the north-end disconnector of track 4, the south-end disconnector of adjacent track, and the north-end disconnector of adjacent track; the subsequent equipment is identified as the voltage testing point corresponding to the south-end disconnector of track 4. After creating the table using the above method, subsequent status comparisons are limited to the same type and adjacent range, and the released object is limited to a single pre-associated subsequent device. Therefore, in scenarios where adjacent equipment is densely arranged, it is possible to distinguish the planned operation object from adjacent objects of the same type.
[0020] Furthermore, in one embodiment provided by the present invention, the work section equipment mapping table includes a planned object identifier, a successor equipment identifier, a step type identifier, and a candidate equipment group identifier. The planned object identifier corresponds one-to-one with the successor equipment identifier, and the planned object identifier corresponds one-to-one with the step type identifier. The candidate equipment group identifier is used to characterize a set of equipment of the same type as the planned object and spatially adjacent to the planned object.
[0021] Specifically, the planned object identifier uniquely identifies the device to be operated on in the current step; the successor device identifier uniquely identifies the device allowed to proceed to the next step after the current step is completed; the step type identifier indicates the job type corresponding to the current device; and the candidate device group identifier indicates the set of similar neighboring devices participating in subsequent displacement identification. When establishing the mapping table, each planned object is bound to a successor device identifier and a step type identifier, and a candidate device group identifier is configured for that planned object.
[0022] To facilitate further understanding by those skilled in the art, for example, the planned object identifier can use a combination of codes such as "4 tracks, south end, disconnect switch," the subsequent equipment identifier can use a combination of codes such as "4 tracks, south end, voltage testing point," the step type identifier can be recorded as "voltage testing after power outage," and the candidate equipment group identifier can be associated with "all adjacent disconnect switches within the same section." During subsequent execution, the system directly locates the currently operable equipment through the planned object identifier, directly locates the next equipment allowed for release through the subsequent equipment identifier, determines the category of subsequent procedures through the step type identifier, and limits the range of equipment participating in the comparison through the candidate equipment group identifier.
[0023] S2. Collect the pre-operation baseline status data of the candidate equipment group, which includes equipment coding data, track position data and equipment status data; Specifically, before the current step begins, the backend control terminal or handheld terminal performs a baseline data acquisition on each device in the candidate device group. During acquisition, the device identification information, installation location identifier, and current operating status of each candidate device are read, and the data obtained in the same acquisition is stored item by item in the baseline status record for each device. To avoid misjudgment caused by inconsistent acquisition times of different devices, it is preferable that each device in the candidate device group completes the baseline acquisition within the same acquisition cycle, and the acquisition time is written into the record.
[0024] In one implementation, device identification information can be obtained by reading the device's built-in serial number, electronic lock cylinder serial number, RFID tag serial number, or QR code serial number; installation location identification can be obtained by matching track tags, end tags, or the background device layout table; current operating status can be obtained by reading the lock status detection unit, switch position detection unit, voltage detection feedback unit, and grounding status detection unit. After completing the baseline acquisition, each device in the candidate device group corresponds to a pre-operation baseline status record. When performing the current step operation, if the post-operation status record of a candidate device changes relative to the baseline status record, it can be directly identified which candidate device the change occurred on, rather than simply assuming the change occurred on the planned object based on the job task.
[0025] Furthermore, in one embodiment provided by the present invention, the device coding data includes a device code, the track position data includes a track code and an end code, and the device status data includes a lock status, a switch position status, a voltage detection status, and a grounding status.
[0026] Specifically, the equipment code is used to distinguish specific equipment within the same work area, the track code is used to distinguish the track where the equipment is located, and the end code is used to distinguish whether the equipment is located at the south end, north end, platform side, or non-platform side. The lock status indicates whether the lock is currently locked, unlocked, or in a half-travel state; the switch position status indicates whether the isolating switch is currently in the open, closed, or intermediate position; the voltage testing status indicates whether the voltage testing result is not tested, energized, or de-energized; and the grounding status indicates whether the grounding device is not grounded, grounded, or disconnected from grounding.
[0027] In one implementation, the equipment code uses a fixed-length encoding; the track code uses a track sequence number encoding; the end position code uses a preset end position encoding; and the lock status, switch position status, voltage detection status, and grounding status are all recorded using discrete status values. Taking a 4-track south-end disconnect switch as an example, its pre-operation baseline status record may include: equipment code 4N-GK01, track code 4, end position code south, lock status locked, switch position status closed, voltage detection status not detected, and grounding status not grounded. Subsequent comparisons can identify whether a change in equipment status has occurred, and also identify which track, end position, and equipment the change occurred on, thereby distinguishing status changes between adjacent, similar equipment.
[0028] S3. After performing the current step operation, collect the post-operation status data of the candidate device group, and compare the post-operation status data with the pre-operation baseline status data to determine the actual change object that actually changed its status in the current step. Specifically, after the current step is completed, the status of the candidate equipment group is collected again to obtain the post-operation status record for each candidate equipment. The collected content is consistent with the baseline status record before the operation, still including equipment coding data, track position data, and equipment status data. It is preferred that this data be collected within the same collection cycle after the current step is completed to reduce status deviations caused by different collection times for different candidate equipment. Subsequently, the post-operation status record for each candidate equipment is compared with the corresponding baseline status record before the operation to identify whether the equipment status data has changed.
[0029] In one implementation, if at least one of the following states of a candidate device—lock status, switch position status, voltage detection status, or grounding status—changes relative to the baseline state record before operation, the candidate device is considered to have undergone a state change. If the device coding data and track position data remain unchanged, but only the device status data changes, it indicates that the change occurred on the same device rather than during device switching. After comparing each item, a set of devices that have undergone state changes can be selected from the candidate device group. Taking the disconnecting switch step as an example, if the disconnecting switch at the south end of track 4 was locked and closed before operation, and then became unlocked and open after operation, while the other disconnecting switches in the candidate device group remain in their original states, then the disconnecting switch at the south end of track 4 can be included in the set of devices with state changes.
[0030] Furthermore, in one embodiment provided by the present invention, S3 includes: Each candidate device in the candidate device group is compared before and after the operation. Combining the electronic key authorization record and the on-site reading result, the candidate device that meets the requirements of having an authorized operation record, changing the device status, and having the device code data and track position data in the post-operation status data consistent with the on-site reading result is determined. When the candidate object for displacement is unique, the candidate object for displacement is determined as the actual object for displacement. When the candidate object for displacement is empty or the candidate object for displacement is not unique, the locking state of the successor device corresponding to the planned object is maintained.
[0031] Specifically, after screening out the set of devices with changed status, electronic key authorization records and on-site reading results are used for cross-verification. Electronic key authorization records indicate whether an unlocking or execution permission has been issued for a specific device during this step; the record content may include the authorization time, key number, target device number, and task number. On-site reading results indicate the device actually accessed by the operator on-site; the reading content may include device coding data and track position data. For each device in the candidate device group, three conditions are checked sequentially: first, an electronic key authorization record corresponding to the current task exists; second, the status comparison before and after the operation indicates that the device status has changed; and third, the device coding data and track position data in the post-operation status record are consistent with the on-site reading results. Devices that simultaneously meet all three conditions are identified as candidates for status change.
[0032] When there is only one candidate device for displacement, that device is directly identified as the actual displacement device. For example, in the step of disconnecting the south end disconnector of track 4, if the electronic key authorization record corresponds to the south end disconnector of track 4, the on-site reading result also points to the south end of track 4, and only the lock status and switch position status of that device change, then that device is identified as the actual displacement device. When there are no candidate devices for displacement, it means that no identifiable actual displacement device has been formed in the current step; when there are more than one candidate device for displacement, it means that the device object corresponding to the current step cannot be uniquely identified, such as adjacent devices of the same type changing their status simultaneously, or the on-site reading result matching multiple candidate devices simultaneously. In these two cases, the subsequent release process is not initiated, but the locked state of the subsequent device corresponding to the planned object is maintained. After this processing, the actual displacement device of the current step is identified only when all three conditions of "authorized, displacement completed, and on-site object consistent" are met and the object is unique, thereby intercepting the situation of misoperation of adjacent devices of the same type and non-unique object identification before the release of subsequent steps.
[0033] S4. Perform a consistency check between the actual displacement object and the planned object. If the check passes, determine the successor device corresponding to the actual displacement object according to the work section equipment mapping table. If the check fails, maintain the locked state of the successor device corresponding to the planned object. Specifically, after identifying the actual displaced object, the backend control terminal or handheld terminal first reads the object information and current operation information corresponding to the actual displaced object, and then performs a consistency check with the pre-determined planned object in the current task. The purpose of the consistency check is not to determine again whether the device has changed position, but to determine whether the displaced device is the target device required for operation in the current task. If the check result is correct, the subsequent device identification process continues; if the check result is incorrect, the subsequent release process is not initiated, and the locked state of the subsequent device corresponding to the planned object is maintained.
[0034] For example, if the current task corresponds to the south-end disconnector of track 4, but the actual change target obtained after the previous step is the north-end disconnector of track 4, then although there is a real change device, this device is inconsistent with the target object in the current task. In this case, it is not allowed to continue releasing subsequent voltage testing or grounding related equipment based on this actual change target. A direct verification relationship is established between equipment status changes and the task objective, thus enabling the interception of erroneous releases caused by incorrect track, incorrect end position, or incorrect equipment.
[0035] Furthermore, in one embodiment of the present invention, the equipment coding data and track position data of the actual displacement object and the planned object are compared item by item, and the step type corresponding to the actual displacement object is compared with the step type corresponding to the planned object. When all comparison results are consistent, the verification is determined to be successful.
[0036] Specifically, equipment code data is used to identify specific equipment, track position data is used to identify the track and end position of the equipment, and step type is used to identify the work procedure corresponding to the current equipment in this task. During verification, the equipment code data of the actual displacement object and the planned object are first compared to see if they are consistent, then the track position data of the two are compared to see if they are consistent, and finally the corresponding step types of the two are compared to see if they are consistent; if all three results are consistent, the actual displacement object is considered to match the planned object in the current task.
[0037] In one implementation, inconsistent equipment coding data indicates that the device that has changed position is not the one corresponding to the current task; inconsistent equipment coding data but inconsistent track position data indicates that there is a misidentification of the same type of equipment across tracks or ends; inconsistent equipment coding data and track position data but inconsistent step types indicate that although the currently identified change occurred on the correct device, it does not belong to the work procedure that should correspond to this round of steps. For example, the same device may correspond to both a power outage operation and a power restoration operation at a certain moment. If the current task is in the post-power outage electronic verification process, but the step type comparison result points to power restoration, then the verification will still fail.
[0038] Furthermore, in one embodiment provided by the present invention, S4 includes: after the consistency verification is passed, retrieving the successor device that uniquely corresponds to the actual displacement object from the work segment device mapping table, determining the next step type corresponding to the successor device according to the step type identifier, and determining the successor device as the only device object allowed to execute the next step type operation after the current step is completed.
[0039] Specifically, after the consistency verification passes, the backend control terminal directly retrieves the identifier of the subsequent device bound to the actual displacement object based on the mapping relationship in the work section equipment mapping table; then, based on the step type identifier corresponding to the current task, it determines the next step type that the subsequent device is allowed to enter in this round of process. Once the subsequent device is determined, the subsequent release scope shrinks from a set of similar devices to a single device object, and once the next step type is determined, the subsequent release content shrinks from general operation permission to single process permission.
[0040] For example, if the actual changeover target is the disconnect switch at the south end of track 4 and the consistency verification passes, the corresponding subsequent equipment in the work section equipment mapping table can be read as the voltage testing point at the south end of track 4. If the step type identifier indicates that the current process is a voltage testing procedure after power outage, then the next step type corresponding to this subsequent equipment is determined to be voltage testing. At this time, the system only considers the voltage testing point at the south end of track 4 as the equipment object that is allowed to perform voltage testing operations, and will not allow voltage testing points on adjacent tracks, voltage testing points at the other end of the same track, or other types of equipment.
[0041] S5. Generate the next step operation permission information corresponding to the successor device, and verify the field reading object at the start of the next step. When the verification is successful, release the next step operation permission to the successor device. During the execution of the next step, continuously verify the holding state of the actual displacement object. When the holding state fails, revoke the next step operation permission and restore the successor device to the locked state.
[0042] Specifically, after the successor device is determined, the backend control terminal first generates the next-step operation permission information corresponding to that successor device. This next-step operation permission information is used to limit the equipment objects and process types allowed to enter the next step in the current process. After the permission information is generated, the successor device does not immediately enter the operable state. Instead, object verification is performed at the start of the next step. After the object verification passes, the backend control terminal issues a release command to the corresponding control unit and handheld terminal of the successor device, allowing the successor device to enter the operable state allowed in the current step. After entering the next step, the system continuously reads the current device state of the actual object and compares it with the post-operation state formed at the end of the current step. If they match, the released next-step operation permission is maintained; if they do not match, the upstream state is deemed invalid, and the next-step operation permission is immediately revoked, while the successor device is restored to the locked state.
[0043] For example, if the actual change object determined in the current step is the disconnect switch at the south end of track 4, and the subsequent equipment is the voltage testing point at the south end of track 4, then the system first generates voltage testing permission information for the voltage testing point; before the voltage testing begins, the object to be operated on site is checked, and voltage testing is only allowed after the check is correct; during the voltage testing process, the system continuously monitors whether the disconnect switch at the south end of track 4 remains in the open position. If the disconnect switch is detected to change from the open position to the non-open position, the voltage testing permission is immediately stopped and the voltage testing point is restored to an inoperable state.
[0044] Furthermore, in one embodiment of the present invention, generating the next-step operation permission information corresponding to the subsequent device and releasing the next-step operation permission includes: Write the device code data, track position data, and next step type of the subsequent equipment into the current job session; At the start of the next step, the equipment code data and track position data of the object to be read on site are collected and compared item by item with the equipment code data and track position data of the subsequent equipment recorded in the current work session. When all comparison results are consistent and the current start step type is consistent with the next step type, the operation permission for the next step is released.
[0045] Specifically, the current job session records the unique equipment object and unique operation type allowed to be operated in this round of the process. Data written to the current job session includes the equipment code data of the subsequent equipment, track position data, and the next step type. Upon reaching the next step, the operator approaches the field equipment via a handheld terminal and reads the equipment code data and track position data of the equipment to be operated. The system compares the read results item by item with the records in the current job session, while simultaneously verifying whether the operation type to be initiated matches the written next step type. Only when both the equipment object and the operation type match will the handheld terminal release operation permission to the subsequent equipment.
[0046] For example, if the recorded successor device in the current work session is the power testing point at the south end of track 4, and the recorded next step type is power testing, then the system will only allow the operation to continue if the object read on-site is also the power testing point at the south end of track 4, and the current start procedure is power testing; if the object read on-site is the power testing point at the north end of track 4, or the current start procedure is grounding, then the operation permission will not be released.
[0047] Furthermore, in one embodiment of the present invention, the continuous verification of the retention state of the actual displacement object includes: continuously collecting device status data corresponding to the actual displacement object during the execution of the next step, comparing the continuously collected device status data with the post-operation status data, and determining that the retention state is invalid when the comparison results are inconsistent.
[0048] Specifically, the status verification checks whether the upstream actual displacement object still maintains a valid state after the current step ends. During the execution of the next step, the system continuously reads the device status data of the actual displacement object according to a preset sampling period and compares it item by item with the post-operation status data saved at the end of the current step. The comparison is performed on a per-status-item basis, including the status items corresponding to the current object among the lock status, switch position status, voltage detection status, and grounding status; if any corresponding status item changes, the status retention is considered to have failed.
[0049] For example, when the actual object being changed is a disconnector switch, the focus of comparison is on the lock status and switch position status; when the actual object being changed is a grounding point, the focus of comparison is on the grounding status; when the actual object being changed is a voltage testing point, the focus of comparison is on the voltage testing status. By adopting a method of continuous data collection and item-by-item comparison, the system can promptly detect upstream object status rollback, cancellation, or abnormal changes during the execution of the next step.
[0050] Furthermore, in one embodiment of the present invention, when it is determined that the holding state has failed, the permission for the next step operation is revoked, the subsequent device is prohibited from responding to the electronic key authorization command and the handheld terminal operation permission, and the subsequent device is restored to the locked state.
[0051] Specifically, upon the failure of the hold status, the system immediately performs three actions. First, it clears the valid next-step operation permission, so that the handheld terminal no longer displays that the subsequent device is in an operable state. Second, it stops sending electronic key authorization signals and terminal execution signals to the subsequent device, so that even if the operator continues to perform unlocking, voltage testing, grounding, or climbing-related actions, the subsequent device will no longer respond. Third, it restores the subsequent device to the locked state, returning the device to the non-accessible state.
[0052] In one implementation, the system records the revocation time, the object of failure, and the reason for failure when revoking the permission for the next step, for work review. For example, if the corresponding isolating switch fails after the voltage testing step has been approved, the voltage testing point authorization is immediately stopped, and the voltage testing point is restored to an inoperable state; if the corresponding grounding status fails after the climbing step has been approved, the response of the platform door or the object with the climbing permission is immediately stopped. The next step will be cut off when the upstream status support is lost.
[0053] Please see Figure 3 , Figure 3 This invention provides a schematic diagram of a five-proof interlocking security protection system based on multi-source state perception. The invention also provides a five-proof interlocking security protection system based on multi-source state perception for implementing the above method, comprising: The mapping table creation module is used to create a work section equipment mapping table based on the five-prevention operation tasks of the target track. The work section equipment mapping table records the correspondence between the planned object, the subsequent equipment corresponding to the planned object, and the candidate equipment group of the same type and spatially adjacent to the planned object. The baseline status acquisition module is used to acquire the pre-operation baseline status data of the candidate equipment group. The pre-operation baseline status data includes equipment coding data, track position data, and equipment status data. The actual displacement object determination module is used to collect the post-operation status data of the candidate device group after the current step operation is performed, and compare the post-operation status data with the pre-operation baseline status data to determine the actual displacement object that actually undergoes a state displacement in the current step. The consistency verification module is used to perform consistency verification between the actual displacement object and the planned object. When the verification passes, the module determines the successor device corresponding to the actual displacement object according to the work section equipment mapping table. When the verification fails, the module maintains the locked state of the successor device corresponding to the planned object. The permission output and lockout recovery module is used to generate the next step operation permission information corresponding to the successor device, and to verify the field read object at the beginning of the next step. When the verification is successful, the next step operation permission is released to the successor device. During the execution of the next step, the holding state of the actual displacement object is continuously verified. When the holding state fails, the next step operation permission is revoked and the successor device is restored to the lockout state.
[0054] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0055] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A five-prevention interlocking security protection method based on multi-source state perception, characterized in that, include: S1. Based on the five-prevention operation tasks of the target track, establish an equipment mapping table for the operation section. The equipment mapping table for the operation section records the correspondence between the planned object, the subsequent equipment corresponding to the planned object, and the candidate equipment group of the same type and spatially adjacent to the planned object. S2. Collect the pre-operation baseline status data of the candidate equipment group, which includes equipment coding data, track position data and equipment status data; S3. After performing the current step operation, collect the post-operation status data of the candidate device group, and compare the post-operation status data with the pre-operation baseline status data to determine the actual change object that actually changed its status in the current step. S4. Perform a consistency check between the actual displacement object and the planned object. If the check passes, determine the successor device corresponding to the actual displacement object according to the work section equipment mapping table. If the check fails, maintain the locked state of the successor device corresponding to the planned object. S5. Generate the next step operation permission information corresponding to the successor device, and verify the field reading object at the start of the next step. When the verification is successful, release the next step operation permission to the successor device. During the execution of the next step, continuously verify the holding state of the actual displacement object. When the holding state fails, revoke the next step operation permission and restore the successor device to the locked state.
2. The five-prevention interlocking security protection method based on multi-source state perception according to claim 1, characterized in that: The work section equipment mapping table includes a planned object identifier, a successor equipment identifier, a step type identifier, and a candidate equipment group identifier. The planned object identifier corresponds one-to-one with the successor equipment identifier, and the planned object identifier corresponds one-to-one with the step type identifier. The candidate equipment group identifier is used to represent a set of equipment of the same type as the planned object and spatially adjacent to the planned object.
3. The five-prevention interlocking security protection method based on multi-source state perception according to claim 1, characterized in that: The equipment coding data includes the equipment code, the track position data includes the track code and the end code, and the equipment status data includes the lock status, switch position status, voltage detection status, and grounding status.
4. The five-prevention interlocking security protection method based on multi-source state perception according to claim 1, characterized in that, S3 includes: Each candidate device in the candidate device group is compared before and after the operation. Combining the electronic key authorization record and the on-site reading result, the candidate device that meets the requirements of having an authorized operation record, changing the device status, and having the device code data and track position data in the post-operation status data consistent with the on-site reading result is determined. When the candidate object for displacement is unique, the candidate object for displacement is determined as the actual object for displacement. When the candidate object for displacement is empty or the candidate object for displacement is not unique, the locking state of the successor device corresponding to the planned object is maintained.
5. The five-prevention interlocking security protection method based on multi-source state perception according to claim 1, characterized in that: The equipment coding data and track position data of the actual displacement object and the planned object are compared item by item, and the step type corresponding to the actual displacement object is compared with the step type corresponding to the planned object. The verification is deemed successful when all comparison results are consistent.
6. The five-prevention interlocking security protection method based on multi-source state perception according to claim 2, characterized in that, S4 includes: after the consistency verification is passed, retrieving the successor device that uniquely corresponds to the actual displacement object from the work segment device mapping table, determining the next step type corresponding to the successor device according to the step type identifier, and identifying the successor device as the only device object allowed to execute the next step type operation after the current step is completed.
7. The five-prevention interlocking security protection method based on multi-source state perception according to claim 6, characterized in that, The step of generating the next step operation license information corresponding to the successor device and releasing the next step operation license includes: Write the device code data, track position data, and next step type of the subsequent equipment into the current job session; At the start of the next step, the equipment code data and track position data of the object to be read on site are collected and compared item by item with the equipment code data and track position data of the subsequent equipment recorded in the current work session. When all comparison results are consistent and the current start step type is consistent with the next step type, the operation permission for the next step is released.
8. The five-prevention interlocking security protection method based on multi-source state perception according to claim 1, characterized in that, The continuous verification of the retention status of the actual displacement object includes: continuously collecting device status data corresponding to the actual displacement object during the execution of the next step, comparing the continuously collected device status data with the post-operation status data, and determining that the retention status is invalid when the comparison results are inconsistent.
9. The five-prevention interlocking security protection method based on multi-source state perception according to claim 1, characterized in that: When the holding state is determined to be invalid, the permission for the next step operation is revoked, the subsequent device is prohibited from responding to electronic key authorization commands and handheld terminal operation permissions, and the subsequent device is restored to the locked state.
10. A five-proof interlocking security protection system based on multi-source state perception, characterized in that, include: The mapping table creation module is used to create a work section equipment mapping table based on the five-prevention operation tasks of the target track. The work section equipment mapping table records the correspondence between the planned object, the subsequent equipment corresponding to the planned object, and the candidate equipment group of the same type and spatially adjacent to the planned object. The baseline status acquisition module is used to acquire the pre-operation baseline status data of the candidate equipment group. The pre-operation baseline status data includes equipment coding data, track position data, and equipment status data. The actual displacement object determination module is used to collect the post-operation status data of the candidate device group after the current step operation is performed, and compare the post-operation status data with the pre-operation baseline status data to determine the actual displacement object that actually undergoes a state displacement in the current step. The consistency verification module is used to perform consistency verification between the actual displacement object and the planned object. When the verification passes, the module determines the successor device corresponding to the actual displacement object according to the work section equipment mapping table. When the verification fails, the module maintains the locked state of the successor device corresponding to the planned object. The permission output and lockout recovery module is used to generate the next step operation permission information corresponding to the successor device, and to verify the field read object at the beginning of the next step. When the verification is successful, the next step operation permission is released to the successor device. During the execution of the next step, the holding state of the actual displacement object is continuously verified. When the holding state fails, the next step operation permission is revoked and the successor device is restored to the lockout state.