Power network equipment automation intelligent operation and maintenance system and method
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- JIANGXI SHUANGYUAN ELECTRIC POWER HIGH-TECH CO LTD
- Filing Date
- 2026-07-09
- Publication Date
- 2026-08-07
AI Technical Summary
[0003]现有技术在处理电力网络设备配置变更准入问题时存在以下缺陷:一是现有运维系统在评估配置变更影响时,普遍缺乏对网络拓扑路径的自动扩散推理能力,难以准确识别变更操作沿转发路径波及的全部电力业务及其安全敏感级别,导致影响范围评估不完整;二是现有系统在执行准入决策时普遍未能充分结合电网实时运行状态,多依赖静态配置信息进行判断,难以充分反映电网运行方式等级与关键线路负载状况对变更风险的实质影响;三是现有系统普遍缺乏对继电保护装置主保护通道投退状态的动态感知能力,当主保护通道处于退出状态时,后备保护通道承载业务的实际安全敏感程度显著提升,而现有系统难以识别这一动态变化并对准入决策作出相应修正,存在因信息不对称导致误操作的风险;四是当配置变更操作当前不满足准入条件时,现有系统普遍无法自动预测并推荐满足安全要求的未来执行窗口,操作时机的选择仍主要依赖运维人员的个人经验,缺乏量化依据
与现有技术相比,本发明通过基于电力业务承载映射库的路径扩散推理自动识别配置变更沿网络拓扑波及的全部受影响端口及其业务安全敏感级别,并结合电网运行方式等级与关键线路潮流负载率构建二维安全域矩阵实现多维联动的准入决策;在此基础上,通过优先级动态修正机制实时感知继电保护装置主保护通道投退状态,在主保护通道退出时自动将对应后备保护通道承载业务的安全敏感级别提升至最高等级并触发决策反转检测,解决了现有技术因忽略保护装置动态运行状态而导致准入决策失准的问题;当准入决策为禁止或条件允许时,系统自动预测未来各时段状态并按裕度加权排序输出安全执行窗口推荐列表,将操作时机选择由经验判断转化为量化决策,有效降低了配置变更操作对电力业务造成意外中断的风险。
Smart Images

Figure CN122533242A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power communication network operation and maintenance technology, specifically to an automated intelligent operation and maintenance system and method for power network equipment. Background Technology
[0002] Power communication networks carry core power services such as relay protection and dispatch data. Changes to network equipment configurations directly affect the continuity of these services and the safety of power grid operation, thus placing high demands on access decisions for such changes.
[0003] Existing technologies have the following shortcomings in handling the access issues of power network equipment configuration changes: First, existing operation and maintenance systems generally lack the ability to automatically propagate and reason about network topology paths when assessing the impact of configuration changes, making it difficult to accurately identify all power services affected by the change operation along the forwarding path and their security sensitivity levels, resulting in incomplete impact assessments. Second, existing systems generally fail to fully consider the real-time operating status of the power grid when making access decisions, relying more on static configuration information for judgment, which makes it difficult to fully reflect the substantial impact of the power grid operating mode level and the load status of critical lines on the risk of changes. Third, existing systems generally lack the ability to dynamically perceive the activation and deactivation status of the main protection channel of relay protection devices. When the main protection channel is in an deactivated state, the actual security sensitivity of the services carried by the backup protection channel increases significantly, and existing systems are unable to identify this dynamic change and make corresponding corrections to the access decisions, posing a risk of misoperation due to information asymmetry. Fourth, when the current configuration change operation does not meet the access conditions, existing systems generally cannot automatically predict and recommend future execution windows that meet security requirements, and the selection of the operation timing still mainly relies on the personal experience of operation and maintenance personnel, lacking quantitative basis. Summary of the Invention
[0004] This invention provides an automated intelligent operation and maintenance system and method for power network equipment, which enables configuration change access decision-making that links power service impact identification with real-time grid operation status, and automatically recommends a safe execution window when access conditions are not met, thereby reducing the risk of unexpected power service interruption caused by configuration changes.
[0005] To achieve the above objectives, the present invention provides the following technical solution: The present invention provides an automated intelligent operation and maintenance system for power network equipment, comprising: Power grid status sensing module: acquires real-time power grid operation data and outputs the power grid operation mode level, power flow load rate of key lines, and the main protection channel activation / deactivation status of power grid relay protection devices; Service impact identification module: Receives network device configuration change requests, performs path diffusion reasoning along the network topology based on the pre-built power service bearer mapping library, and outputs the power service type carried by the port within the diffusion path, the corresponding relay protection device identifier and static security sensitivity level, forming a service security sensitivity level vector; Priority dynamic correction module: Based on the matching result between the main protection channel's activation / deactivation status and the relay protection device identifier in the business security sensitivity level vector, the static security sensitivity level of the backup protection channel corresponding to the relay protection device whose main protection channel is in the deactivated state is upgraded and corrected, and the corrected business security sensitivity level vector is output. Access Decision Module: Using the highest security sensitivity level in the modified business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate, query the pre-calibrated two-dimensional security domain matrix and output the access decision; The execution window recommendation module predicts the power grid operation mode level, critical line power flow load rate, and main protection channel activation / deactivation status of relay protection devices for future time periods when the access decision is prohibited or conditionally permitted. This information is then substituted into the priority dynamic correction module and the access decision module. The business security sensitivity level vector remains unchanged as a fixed input. The modules are sorted from high to low according to the margin between the time period where the access decision is permitted or conditionally permitted and the boundary of the two-dimensional security domain matrix, and the safe execution window recommendation list is output.
[0006] As a preferred embodiment of the present invention, in the power grid status sensing module, the outputs of the power grid operation mode level, the critical line power flow load rate, and the main protection channel activation / deactivation status of the power grid relay protection device specifically include: The critical lines are transmission lines that are pre-designated and recorded by the dispatching agency in accordance with the power grid dispatching regulations; Collect active power data for each critical path and calculate the power flow load rate for each critical path. The power flow load rate is the ratio of the current active power of the corresponding critical path to its thermal stability limit. Collect the channel status signals of each relay protection device, determine and extract the current activation / deactivation status of the main protection channel of each relay protection device based on the channel status signals, and the activation / deactivation status is set to either activation or deactivation; According to the dispatching procedures, the current power grid operation status is divided into corresponding operation mode levels. The operation mode levels are pre-set ordered discrete levels. The higher the level value, the lower the safety margin of the power grid operation. The operating mode level, the power flow load rate of each critical line, and the main protection channel activation / deactivation status of each relay protection device are combined and output.
[0007] As a preferred embodiment of the present invention, the construction of the power service bearer mapping library in the service impact identification module specifically includes: By identifying the protocol characteristics of power communication protocols in network traffic, the type of power service carried by each port is automatically inferred, and an initial mapping record is generated. The initial mapping records are formally entered into the database after being reviewed and confirmed by the operations and maintenance personnel. Record the device identifier, port identifier, power service type, associated relay protection device identifier, static security sensitivity level, and redundancy path availability status at the port level. The static security sensitivity level is manually marked and entered by operation and maintenance personnel during the review and confirmation process based on the power service type and the importance level of the associated relay protection device.
[0008] As a preferred embodiment of the present invention, the specific steps of the path diffusion reasoning in the business impact identification module include: Starting with the port identifier of the object being changed, traverse each port on the downstream forwarding path hop by hop along the network topology; At each node, query the power service bearer mapping library to obtain the power service type, the identifier of the relay protection device to which it belongs, the static security sensitivity level, and the availability status of the redundant path for the corresponding port; When the redundant path of a node is available, the diffusion stops with that node as the termination boundary. When the redundant path of a node is in an unavailable state, it continues to spread downstream; The power service type, the corresponding relay protection device identifier, and the static security sensitivity level of each port on all unterminated paths are summarized to form the service security sensitivity level vector.
[0009] As a preferred embodiment of the present invention, the priority dynamic correction module further includes the step of constructing a primary and backup protection channel correspondence table: Import static configuration data, extract the mapping relationship between the main protection channel identifier and the corresponding backup protection channel identifier of each relay protection device, and form a static correspondence record; The system analyzes the channel status dataset reported by relay protection devices in the IEC 61850 MMS messages in the network, extracts the current actual main protection channel identifier and backup protection channel identifier of each relay protection device, and forms a dynamic correspondence record. The dynamic correspondence record is compared and fused with the static correspondence record with priority. When the two are consistent, the correspondence is confirmed. When the two are inconsistent, an alarm is output and the dynamic correspondence record is used as the standard to generate the main and backup protection channel correspondence table. The main and backup protection channel correspondence table is indexed by the relay protection device identifier and records the main protection channel identifier and the corresponding backup protection channel identifier of each relay protection device. The priority dynamic correction module performs the matching based on the primary and backup protection channel correspondence table.
[0010] As a preferred embodiment of the present invention, in the priority dynamic correction module, the specific steps of the improvement correction include: Extract the relay protection device identifiers that are in the deactivated state of the main protection channel from the main protection channel activation / deactivation status, and form a set of deactivated relay protection device identifiers; Based on the main and backup protection channel correspondence table, the relay protection device identifiers that have corresponding backup protection channels in the set of exited relay protection device identifiers are selected to form a valid set of exited relay protection device identifiers; The port whose relay protection device identifier belongs to the set of valid exited relay protection device identifiers is retrieved from the business security sensitivity level vector and is used as the port with a successful match. For ports that are successfully matched and whose static security sensitivity level is lower than the highest level, their security sensitivity level is adjusted to the highest level. For ports that are not found, their security sensitivity level remains unchanged from the static security sensitivity level. Summarize the corrected security sensitivity levels of all ports and output the corrected service security sensitivity level vector.
[0011] As a preferred embodiment of the present invention, the priority dynamic correction module further includes a decision reversal detection step: The two-dimensional security domain matrix is queried using the highest level of static security sensitivity level in the business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate to obtain the pre-correction access decision. The modified access decision is obtained by querying the two-dimensional security domain matrix with the highest level in the modified business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate. When the access decision was allowed before the correction but is prohibited or conditionally allowed after the correction, a decision reversal is determined to have occurred, and a decision reversal prompt is output to the operator. The decision reversal prompt includes the port identifier that triggered the reversal, the corresponding relay protection device identifier, and the current enabled / disabled status of the main protection channel of the relay protection device.
[0012] As a preferred embodiment of the present invention, the calibration of the two-dimensional security domain matrix in the access decision module specifically includes: A matrix is constructed using the power business security sensitivity level as the row index and the combined range of the power grid operation mode level and the power flow load rate of the critical line as the column index. Power system professionals and network operation and maintenance professionals jointly perform initial calibration of the access decision for each cell, with the access decision value being allowed, conditionally allowed, or prohibited; When the cell admission decision is set to allow conditions, the corresponding execution time window requirements and rollback trigger conditions are recorded synchronously. When the actual execution result is inconsistent with the access decision marked in the corresponding cell, the inconsistency record will be submitted to power system professionals and network operation and maintenance professionals for review. After review and confirmation, the access decision of the corresponding cell will be corrected and updated.
[0013] As a preferred embodiment of the present invention, the specific steps of sorting according to the margin from high to low in the execution window recommendation module include: The minimum step difference between the corresponding cell in the two-dimensional security domain matrix and the nearest prohibited boundary cell is calculated for the period when the admission decision is allowed or conditionally allowed, and this step is used as the margin value for that period. The margin values for each time period are weighted by confidence level according to the time interval from the current time, with the time period further away from the current time being assigned a lower confidence level weight; Sort the weighted margin values from highest to lowest and output the recommended list of safe execution windows.
[0014] This invention also proposes an automated and intelligent operation and maintenance method for power network equipment, including: Acquire real-time power grid operation data and output the power grid operation mode level, power flow load rate of key lines, and the main protection channel activation / deactivation status of power grid relay protection devices; Upon receiving a network device configuration change request, the system performs path diffusion reasoning along the network topology based on a pre-built power service bearer mapping library, and outputs the power service type carried by the port within the diffusion path, the identifier of the corresponding relay protection device, and the static security sensitivity level, thus forming a service security sensitivity level vector. Based on the matching results between the main protection channel's activation / deactivation status and the relay protection device identifier in the business security sensitivity level vector, the static security sensitivity level of the backup protection channel corresponding to the relay protection device whose main protection channel is in deactivation status is improved and corrected, and the corrected business security sensitivity level vector is output. Using the highest security sensitivity level in the corrected business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate, query the pre-calibrated two-dimensional security domain matrix and output the admission decision; When the access decision is prohibited or conditionally permitted, predict the power grid operation mode level, critical line power flow load rate, and main protection channel activation / deactivation status of relay protection devices for each future time period, and substitute them into the priority dynamic correction step and access decision step. The business security sensitivity level vector is used as a fixed input and remains unchanged. Sort the time periods with access decisions of permitted or conditionally permitted and the margin of the two-dimensional security domain matrix boundary from high to low, and output a list of recommended security execution windows.
[0015] The beneficial effects of this invention are: Compared with existing technologies, this invention automatically identifies all affected ports and their service security sensitivity levels along the network topology affected by configuration changes through path diffusion inference based on the power service bearer mapping library. It also constructs a two-dimensional security domain matrix by combining the power grid operation mode level and the power flow load rate of critical lines to achieve multi-dimensional linkage access decision-making. On this basis, it uses a priority dynamic correction mechanism to perceive the main protection channel of the relay protection device in real time. When the main protection channel is deactivated, it automatically raises the security sensitivity level of the corresponding backup protection channel to the highest level and triggers decision reversal detection, solving the problem of inaccurate access decision-making caused by ignoring the dynamic operation status of protection devices in existing technologies. When the access decision is prohibited or conditionally permissible, the system automatically predicts the status of future time periods and outputs a recommended list of safe execution windows by weighted sorting according to margin, transforming the selection of operation timing from experience judgment to quantitative decision-making, effectively reducing the risk of unexpected interruption of power services caused by configuration change operations. Attached Figure Description
[0016] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a schematic diagram of the structure of the automated intelligent operation and maintenance system for power network equipment of the present invention; Figure 2 This is a flowchart illustrating the automated intelligent operation and maintenance method for power network equipment according to the present invention. Detailed Implementation
[0017] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0018] Example 1: As Figure 1 As shown, the automated intelligent operation and maintenance system for power network equipment of the present invention includes: Power grid status sensing module: acquires real-time power grid operation data and outputs the power grid operation mode level, power flow load rate of key lines, and the main protection channel activation / deactivation status of power grid relay protection devices; Specifically, the power grid status perception module is connected to the communication interface of the dispatch automation system and relay protection devices, collects power grid operation data in real time, and continuously outputs the power grid operation mode level, power flow load rate of each key line and the main protection channel activation / deactivation status of each relay protection device to the priority dynamic correction module and the access decision module.
[0019] Furthermore, the output of the power grid operation mode level, critical line power flow load rate, and the main protection channel activation / deactivation status of the power grid relay protection device specifically includes the following steps.
[0020] Critical lines are transmission lines that are pre-designated and recorded by the dispatching agency in accordance with the power grid dispatching regulations. The list of critical lines is imported as static configuration data before the system is put into operation. If adjustments are needed, the dispatching agency will update and re-import the data.
[0021] The power grid status sensing module collects active power data for each critical line and calculates the power flow load rate of each critical line based on its corresponding thermal stability limit. The thermal stability limit is the upper limit of active power allowed to pass through the corresponding critical line under thermal stability constraints over a long period; it is provided by power grid planning data and pre-entered into the system as a static parameter. The power flow load rate of the critical path is denoted as Its value is the measured value of the current active power of the line. With the thermal stability limit of this line The ratio, i.e. , Output is in percentage form, ranging from 0% to over 100%. The power flow load rate of each critical path is refreshed in real time according to the active power acquisition cycle.
[0022] The power grid status sensing module collects channel status signals from each relay protection device, determines and extracts the current active / deactivated status of the main protection channel for each relay protection device based on these signals, with the status set to either active or deactivated. The active / deactivated status of the main protection channel for each relay protection device is updated in real time using the relay protection device identifier as an index, and is transmitted downstream as one of the outputs of this module.
[0023] The power grid status sensing module classifies the current power grid operating status into corresponding operating mode levels according to the dispatching procedures. These operating mode levels are pre-defined ordered discrete levels; a higher level value indicates a lower safety margin for power grid operation. The operating mode level is automatically output by the dispatch automation system based on the current power grid topology and operating status, and this module directly collects this output value. In one implementation, the operating mode levels are divided into three categories: normal mode, maintenance mode, and emergency mode, corresponding to level values of 1, 2, and 3, respectively. Normal mode indicates that the power grid is operating under complete wiring conditions; maintenance mode indicates that the power grid has component outages but still meets the N-1 safety criterion; and emergency mode indicates that the power grid no longer meets the N-1 safety criterion or that important components are simultaneously out of service.
[0024] The power grid status sensing module will include the above-mentioned power grid operation mode level and the power flow load rate of each key line. The real-time output includes the combined on / off status of the main protection channels of each relay protection device, including the power grid operation mode level and the power flow load rate of the critical lines. As input to query the two-dimensional security domain matrix, the main protection channel's activation / deactivation status serves as input for the priority dynamic correction module to perform matching.
[0025] Service impact identification module: Receives network device configuration change requests, performs path diffusion reasoning along the network topology based on the pre-built power service bearer mapping library, and outputs the power service type carried by the port within the diffusion path, the corresponding relay protection device identifier and static security sensitivity level, forming a service security sensitivity level vector; Specifically, after receiving a network device configuration change request, the service impact identification module extracts the port identifier of the object to be changed, and initiates path diffusion reasoning in the power service bearer mapping library starting from the port identifier. Finally, it summarizes the power service type, the corresponding relay protection device identifier, and the static security sensitivity level of all ports included in the impact scope within the diffusion path (including termination boundary nodes and ports on non-termination paths) to form a service security sensitivity level vector, which is then output to the priority dynamic correction module.
[0026] Furthermore, the construction of the power service bearer mapping library specifically includes the following steps.
[0027] The system automatically infers the type of power service carried by each port by identifying the protocol characteristics of power communication protocols in network traffic, and generates an initial mapping record. It should be noted that the identification of protocol characteristics of power communication protocols is a conventional technical means in this field, and the identification results, as the source of the initial mapping record, do not constitute a limitation on the specific protocol types used in this invention.
[0028] Maintenance personnel review and confirm each initial mapping record, and formally enter it into the database after approval. Simultaneously, based on the power service type and the importance level of the associated relay protection device, maintenance personnel manually label and enter the static security sensitivity level for each record. In one implementation, the static security sensitivity level is divided into three levels: Level 1 corresponds to ports carrying primary relay protection services without redundant paths; Level 2 corresponds to ports carrying auxiliary relay protection services or with redundant paths; and Level 3 corresponds to ports carrying non-relay protection power services. A higher level value indicates a lower level of security sensitivity. This three-level division is merely illustrative and does not constitute a limitation of the invention.
[0029] The power service bearer mapping database records data at the port level. Each record contains six fields: device identifier, port identifier, power service type, associated relay protection device identifier, static security sensitivity level, and redundancy path availability status. The redundancy path availability status is set to available or unavailable, and is entered by operations and maintenance personnel based on the current network topology and service deployment during review and confirmation. It is updated in real time as the network status changes.
[0030] Furthermore, the specific steps of the path diffusion reasoning are as follows.
[0031] The service impact identification module starts with the port identifier of the changed object and traverses each port on the downstream forwarding path hop-by-hop along the network topology. The downstream forwarding path is determined based on the forwarding path with the changed object port as the entry point in the network device forwarding table or routing table, and extends downstream hop-by-hop along the data forwarding direction with the changed object port as the root node. At each node, the module queries the power service bearer mapping library to obtain the power service type, the identifier of the relay protection device to which it belongs, the static security sensitivity level, and the availability status of the redundant path for the corresponding port of that node.
[0032] When the query results show that the redundant path of a node is available, the node is included in the scope of influence, and the influence continues to spread downstream from that node, using that node as the termination boundary. This is because when the redundant path is available, the impact of configuration changes on downstream services of that node can be absorbed by the redundant path, and downstream ports of that node do not need to be included in the scope of influence. When the query results show that the redundant path of a node is unavailable, the node is included in the scope of influence and the influence continues to spread downstream until the end of the path or a node with an available redundant path is encountered.
[0033] After the diffusion process concludes, the business impact identification module summarizes the power service type, associated relay protection device identifier, and static security sensitivity level of all ports included in the impact scope along the diffusion path (including each termination boundary node and each port on the non-termination path), forming a business security sensitivity level vector, which is then output to the priority dynamic correction module. Each element in the business security sensitivity level vector corresponds to the above three attributes of an affected port within the diffusion path, serving as the basic input for subsequent priority dynamic correction and access decisions.
[0034] Priority dynamic correction module: Based on the matching result between the main protection channel's activation / deactivation status and the relay protection device identifier in the business security sensitivity level vector, the static security sensitivity level of the backup protection channel corresponding to the relay protection device whose main protection channel is in the deactivated state is upgraded and corrected, and the corrected business security sensitivity level vector is output. Specifically, the priority dynamic correction module receives the main protection channel activation / deactivation status from the power grid status perception module and the service security sensitivity level vector from the service impact identification module. Based on the pre-built main and backup protection channel correspondence table, it performs matching and improvement correction, and performs decision reversal detection after correction. Finally, it outputs the corrected service security sensitivity level vector to the admission decision module.
[0035] Furthermore, the priority dynamic correction module also includes the step of constructing a primary and backup protection channel correspondence table, as detailed below.
[0036] The system imports static configuration data and extracts the mapping relationship between the main protection channel identifier and the corresponding backup protection channel identifier of each relay protection device, forming a static mapping record. Simultaneously, the system parses the channel status dataset reported by the relay protection devices within the IEC 61850 MMS messages in the network, extracting the currently active main protection channel identifier and backup protection channel identifier of each relay protection device, forming a dynamic mapping record. It should be noted that parsing IEC 61850 MMS messages is a standard technique in this field and will not be elaborated upon here.
[0037] The system prioritizes dynamic correspondence records and compares and merges them line by line with static correspondence records. When the two match, the correspondence between the main and backup protection channels of the relay protection device is confirmed; when they do not match, the system outputs an alarm and uses the dynamic correspondence record as the standard. After the comparison and fusion are completed, a main and backup protection channel correspondence table is generated. This table uses the relay protection device identifier as an index and records the main protection channel identifier and the corresponding backup protection channel identifier for each relay protection device. The priority dynamic correction module performs subsequent matching based on the main and backup protection channel correspondence table.
[0038] Furthermore, the specific steps for the improvement and correction are as follows.
[0039] The priority dynamic correction module extracts the relay protection device identifiers that are in the off state from the main protection channel activation / deactivation status output by the power grid status sensing module, and forms a set of off relay protection device identifiers.
[0040] Based on the main and backup protection channel correspondence table, relay protection device identifiers with corresponding backup protection channel records are selected from the set of deactivated relay protection device identifiers to form a valid set of deactivated relay protection device identifiers. Relay protection device identifiers without corresponding backup protection channel records in the set of deactivated relay protection device identifiers are not included in the valid set of deactivated relay protection device identifiers.
[0041] In the service security sensitivity level vector, ports whose relay protection device identifiers belong to the set of validly exited relay protection device identifiers are retrieved, and these retrieved ports are considered successfully matched ports. For ports that are successfully matched and whose static security sensitivity level is lower than the highest level, their security sensitivity level is corrected to the highest level; for ports that are not found, their security sensitivity level remains unchanged from the static security sensitivity level. The corrected security sensitivity levels of all ports are summarized, and the corrected service security sensitivity level vector is output.
[0042] In one implementation, the above correction process is illustrated using an example where the service security sensitivity level vector output by the service impact identification module contains three port records. The relay protection device identifiers for the three ports are RPD-01, RPD-02, and RPD-03, with static security sensitivity levels of Level 1, Level 2, and Level 3, respectively. The main protection channel activation / deactivation status output by the power grid status perception module shows that the main protection channel of RPD-02 is deactivated, while the main protection channels of RPD-01 and RPD-03 are activated. The resulting set of deactivated relay protection device identifiers is {RPD-02}. A query of the main / backup protection channel correspondence table shows that RPD-02 has a corresponding backup protection channel record; therefore, the effective set of deactivated relay protection device identifiers is {RPD-02}. The port with the relay protection device identifier RPD-02 is retrieved from the service security sensitivity level vector. This port is a successfully matched port, and its static security sensitivity level is Level 2, lower than the highest level, Level 1. After correction, the security sensitivity level is raised to Level 1. Ports corresponding to RPD-01 and RPD-03 were not found, and their security sensitivity levels remain unchanged from the original static levels, namely Level 1 and Level 3, respectively. In the revised service security sensitivity level vector, the security sensitivity levels of the three ports are Level 1, Level 1, and Level 3, respectively.
[0043] Furthermore, the priority dynamic correction module also includes a decision reversal detection step, as detailed below.
[0044] The priority dynamic correction module uses the highest static security sensitivity level in the business security sensitivity level vector, combined with the power grid operation mode level and critical line power flow load rate, to query the two-dimensional security domain matrix to obtain the access decision before correction. Then, using the highest level in the corrected business security sensitivity level vector, combined with the same power grid operation mode level and critical line power flow load rate, it queries the two-dimensional security domain matrix to obtain the access decision after correction.
[0045] When the access decision was allowed before the correction but is prohibited or conditionally allowed after the correction, a decision reversal is determined to have occurred, and the system outputs a decision reversal prompt to the operator. The decision reversal prompt includes the port identifier that triggered the reversal, the corresponding relay protection device identifier, and the current enabled / disabled status of the main protection channel of the relay protection device, so that the operator can understand the specific reason for the decision reversal and the corresponding power grid protection status.
[0046] Continuing with the example in the above implementation, the highest level in the business security sensitivity level vector before correction is level one, and the highest level in the business security sensitivity level vector after correction is also level one. Therefore, no decision reversal occurs in this example. If the static security sensitivity level of the port corresponding to RPD-02 in the above example is adjusted to level two, and the highest level before correction is level two, while the highest level after correction is raised to level one, then under the current power grid operation mode level and critical line power flow load rate conditions, if the access decision corresponding to level two is allowed while the access decision corresponding to level one is prohibited or conditionally allowed, then a decision reversal is determined to have occurred, and the system outputs a decision reversal prompt. The prompt content includes the port identifier corresponding to RPD-02, the relay protection device identifier RPD-02, and the current exit status of its main protection channel.
[0047] Access Decision Module: Using the highest security sensitivity level in the modified business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate, query the pre-calibrated two-dimensional security domain matrix and output the access decision; Specifically, the admission decision module receives the corrected business security sensitivity level vector from the priority dynamic correction module and the power grid operation mode level and critical line power flow load rate from the power grid status perception module. It extracts the highest security sensitivity level from the corrected business security sensitivity level vector, queries the two-dimensional security domain matrix using the combination of the security sensitivity level, the power grid operation mode level, and the critical line power flow load rate as an index, and outputs the admission decision. The admission decision can be set to allow, conditionally allowed, or prohibited.
[0048] Furthermore, the calibration of the two-dimensional security domain matrix specifically includes the following steps.
[0049] Before constructing the two-dimensional security domain matrix, the power flow load rate of the critical path is divided into several discrete intervals according to a preset threshold. In one embodiment, based on the percentage of the critical path's thermal stability limit, the power flow load rate is divided into a low-load interval, a medium-load interval, and a high-load interval. The low-load interval corresponds to a power flow load rate of 0% to 60%, the medium-load interval corresponds to a power flow load rate of 60% to 80%, and the high-load interval corresponds to a power flow load rate of over 80%. The above interval division is merely illustrative and does not constitute a limitation of the present invention.
[0050] The two-dimensional security domain matrix is constructed using the power business security sensitivity level as the row index and the combination of the power grid operation mode level and the critical line power flow load rate range as the column index. In one implementation, the power business security sensitivity level is divided into three levels: Level 1, Level 2, and Level 3; the power grid operation mode level is divided into three levels: normal mode, maintenance mode, and emergency mode; and the power flow load rate range is divided into three levels: low load, medium load, and high load. The combination of the operation mode level and the power flow load rate range forms nine column indexes, which, combined with the three rows of security sensitivity levels, constitute a 3-row, 9-column two-dimensional security domain matrix. The initial calibration values of each cell in the matrix are shown in Table 1.
[0051] Table 1 Example of a two-dimensional security domain matrix
[0052] It should be noted that the matrix values described above are merely illustrative and do not constitute a limitation of the present invention. In practical applications, they should be jointly determined by power system professionals and network operation and maintenance professionals based on specific power grid operation requirements. The matrix values follow the following logical self-consistency principle: the higher the security sensitivity level, the higher the operating mode level, and the higher the power flow load rate range, the stricter the access decision. There is no situation where a low security sensitivity level corresponds to prohibition while a high security sensitivity level corresponds to permission.
[0053] After power system professionals and network operation and maintenance professionals jointly perform initial calibration of the access decisions for each cell, when the cell's access decision is calibrated as condition-allowed, the corresponding execution time window requirements and rollback trigger conditions are recorded simultaneously. In one implementation, for cells with a safety sensitivity level of Level 1, a grid operation mode of normal mode, and a power flow load rate range of low load, the execution time window requirement is that the operation must be completed between 00:00 and 04:00 on the same day, and the rollback trigger condition is that if the power flow load rate of any critical line exceeds 80% within 30 minutes after the operation, automatic rollback is triggered. The above specific parameters are for illustrative purposes only and do not constitute a limitation of the present invention.
[0054] When the actual execution result is inconsistent with the access decision marked in the corresponding cell, the system submits the inconsistency record to power system professionals and network operation and maintenance professionals for review. After review and confirmation, the access decision of the corresponding cell is corrected and updated so that the two-dimensional security domain matrix continues to conform to the actual power grid operation rules.
[0055] The execution window recommendation module predicts the power grid operation mode level, critical line power flow load rate, and main protection channel activation / deactivation status of relay protection devices for future time periods when the access decision is prohibited or conditionally permitted. This information is then substituted into the priority dynamic correction module and the access decision module. The business security sensitivity level vector remains unchanged as a fixed input. The modules are sorted from high to low according to the margin between the time period where the access decision is permitted or conditionally permitted and the boundary of the two-dimensional security domain matrix, and the safe execution window recommendation list is output.
[0056] Specifically, the execution window recommendation module receives admission decisions from the admission decision module. When the admission decision is prohibitive or conditionally permissible, the module initiates a future time period prediction process, sequentially performing corrections and decision deductions for each prediction time period, filtering time periods where the admission decision is permissible or conditionally permissible, calculating the margin value for each time period and performing confidence-weighted sorting, and finally outputting a safe execution window recommendation list. It should be noted that the prediction methods for the power grid operation mode level, critical line power flow load rate, and the main protection channel activation / deactivation status of relay protection devices in future time periods are conventional techniques in this field. This invention does not limit the specific prediction method; the prediction results are used as input for this module. In one embodiment, the activation / deactivation status of the main protection channel of the relay protection device can be obtained by reading the maintenance plan issued by the dispatching agency or the planned maintenance schedule pre-entered by maintenance personnel.
[0057] The execution window recommendation module, for each predicted time period, substitutes the predicted power grid operation mode level, critical line power flow load rate, and relay protection device main protection channel activation / deactivation status into the priority dynamic correction module. The business security sensitivity level vector remains unchanged as the fixed input corresponding to the current change request. After the priority dynamic correction module outputs the corrected business security sensitivity level vector for that time period, it is then substituted into the admission decision module to query the two-dimensional security domain matrix to obtain the admission decision for that predicted time period. Predicted time periods selected based on the admission decision as allowed or conditionally permissible are excluded from subsequent sorting.
[0058] Furthermore, the specific steps for sorting by the margin from high to low are as follows.
[0059] For each period where the admission decision is allowed or conditionally allowed, the prediction period is used. The minimum step difference between the corresponding cell in the two-dimensional security domain matrix and the nearest prohibited boundary cell is calculated and used as the margin value for that prediction period, denoted as . ,in The prediction period is numbered. The minimum step size is calculated by moving stepwise along the row and column indices in the two-dimensional security domain matrix, starting from the cell where the current admission decision is allowed or conditionally allowed. Each step is counted as 1 step for each security sensitivity level in the row direction and 1 step for each combination of operating mode level and power load rate in the column direction. Row steps and column steps are equivalent and each counts as 1 step. The number of steps taken to reach the first cell where the admission decision is prohibited in both the row and column directions is calculated, and the minimum of the two is taken as the margin value for the prediction period. . A larger value indicates that the time period is further away from the prohibition boundary, and the higher the execution safety margin.
[0060] Margin values for each forecast period The confidence level is weighted according to the time interval from the current time to obtain the weighted margin value. The calculation method is as follows: ; in, For the first Confidence weights for each prediction period The confidence weight decreases monotonically as the time interval from the current time increases, with lower weights assigned to time intervals further away from the current time. In one implementation, It can take the form of exponential decay, that is ,in The attenuation coefficient and The specific value is determined by the maintenance personnel based on their experience with prediction accuracy. The above attenuation forms are merely illustrative and do not constitute a limitation of the present invention.
[0061] By weighted margin The prediction periods for each admission decision (either allowed or conditionally permitted) are sorted from highest to lowest, and a recommended list of safe execution windows is output. Each entry in the recommended list of safe execution windows includes the time identifier of the corresponding prediction period, the predicted grid operation mode level, the predicted critical line power flow load factor, and the weighted margin value. And the corresponding admission decision type; when the admission decision for the prediction period is conditionally permissible, the execution time window requirements and rollback trigger conditions marked in the corresponding cell of the two-dimensional security domain matrix are read synchronously and output together with the entry, so that the operator can know and follow the execution when selecting the execution time.
[0062] Example 2: To address the operational challenges brought about by the continuous expansion of its communication network, the surge in the number of devices, and the increasing complexity of the network topology, and to address prominent issues such as the uncontrollable risks of configuration changes, reliance on manual experience for relay protection service impact assessments, and the lack of quantitative basis for selecting operation timing under the traditional manual operation and maintenance model, a power supply company adopted the following approach: Figure 2The automated intelligent operation and maintenance method for power network equipment shown in this invention has systematically transformed the configuration change management process of its information communication network.
[0063] The company's communication network manages 171 network devices, and the power services it carries cover relay protection main channel services, relay protection auxiliary services, and non-relay protection power services such as dispatch data network. The network involves multiple relay protection devices, and some relay protection devices experience temporary outages of the main protection channel during routine operation and maintenance.
[0064] In a typical configuration change scenario, the operations and maintenance personnel submitted a VLAN configuration change request for a specific port of a core aggregation switch. Upon receiving the request, a path propagation inference was performed along the network topology, starting from the port identifier. Three affected ports were identified along the propagation path. After querying the power service bearer mapping library, the following service security sensitivity level vectors were obtained: Port A belongs to relay protection device identifier RPD-01, carries primary relay protection services and has no redundant paths, with a static security sensitivity level of Level 1; Port B belongs to relay protection device identifier RPD-02, carries auxiliary relay protection services, with a static security sensitivity level of Level 2; Port C belongs to relay protection device identifier RPD-03, carries dispatch data network services, with a static security sensitivity level of Level 3.
[0065] At the same time, the current real-time operation data of the power grid is obtained, and the power grid operation mode level is output as maintenance mode. The power flow load rate of each key line is in the medium load range. The main protection channel of RPD-02 is in the off state, while the main protection channels of RPD-01 and RPD-03 are in the on state.
[0066] Based on the matching results between the main protection channel's activation / deactivation status and the corresponding relay protection device identifiers in the service security sensitivity level vector, the set of deactivated relay protection device identifiers, {RPD-02}, is extracted from the main protection channel's activation / deactivation status. A query of the main / backup protection channel correspondence table confirms that RPD-02 has a corresponding backup protection channel record, thus the valid deactivated relay protection device identifier set is {RPD-02}. In the service security sensitivity level vector, port B, whose corresponding relay protection device identifier is RPD-02, is retrieved, and its static security sensitivity level is upgraded from Level 2 to Level 1. The security sensitivity levels of the remaining ports remain unchanged. In the corrected service security sensitivity level vector, the security sensitivity levels of the three ports are Level 1, Level 1, and Level 3, with Level 1 being the highest.
[0067] In this scenario, since the static security sensitivity level of port A is already level one, the highest level in the business security sensitivity level vector before the correction was already level one. After port B is upgraded from level two to level one, the highest level remains unchanged. By querying the two-dimensional security domain matrix using level one security sensitivity level, maintenance method, and medium load range as indexes, the access decision of the corresponding cell is prohibition. Therefore, the access decision before and after the correction is prohibition, and no decision reversal occurs. To illustrate the triggering logic of decision reversal detection separately, a simplified scenario is assumed as follows: If the current diffusion path only involves ports B and C and does not include port A, then the highest level in the business security sensitivity level vector before correction is level two, and after correction it is upgraded to level one. Under the combined conditions of maintenance method and medium load range, the two-dimensional security domain matrix is queried. Level two corresponds to the access decision being conditionally allowed, while level one corresponds to the access decision being prohibited. A decision reversal is determined to have occurred, and a decision reversal prompt is output to the operator. The prompt includes the port identifier of port B, the relay protection device identifier RPD-02, and the current exit status of its main protection channel. This allows the operator to be aware of the real risk in a timely manner even without being informed that the main protection channel of RPD-02 is out of service, thus avoiding misoperation due to information asymmetry.
[0068] Returning to the current scenario, the two-dimensional security domain matrix is queried using the highest level (Level 1) in the corrected business security sensitivity level vector, the power grid operation mode level maintenance mode, and the load range in the critical line power flow load rate as indexes. The output admission decision is "prohibit".
[0069] After the access decision is set to prohibit, the current business security sensitivity level vector is used as a fixed input to predict the power grid operation mode level, critical line power flow load rate, and RPD-02 main protection channel activation / deactivation status for future time periods. These predictions are then substituted into the priority dynamic correction step and the access decision step for simulation. The prediction results show that the power grid operation mode level will return to normal between 00:00 and 04:00 on the same day, the critical line power flow load rate will drop to the low load range, and the RPD-02 main protection channel is predicted to remain in the deactivated state. After priority dynamic correction, the highest level remains Level 1. The access decision output from the two-dimensional security domain matrix is conditionally allowed. The corresponding execution time window requirement is that the operation must be completed between 00:00 and 04:00. The rollback trigger condition is that if the power flow load rate of any critical line exceeds 80% within 30 minutes after the operation, automatic rollback will be triggered. After calculating the margin between this time period and the boundary of the two-dimensional security domain matrix and weighting it with confidence, this time period is ranked first in the recommended list of security execution windows for maintenance personnel to refer to when selecting execution timing.
[0070] Compared with the traditional manual operation and maintenance mode, the present invention achieves the following effects in the above scenario: First, it automatically identifies the dynamic risk factor of the RPD-02 main protection channel exiting and automatically upgrades the security sensitivity level of the corresponding backup protection channel carrying services, without relying on operation and maintenance personnel to actively check the operating status of the protection device; Second, through decision reversal detection, it accurately pushes alarms to operators when dynamic risk factors cause substantial changes in access decisions, avoiding missed judgments caused by information asymmetry; Third, by recommending and quantifying the specific executable time periods and margin rankings through execution windows, it transforms the timing selection that originally relied on the experience judgment of operation and maintenance personnel into automatic system recommendations, significantly reducing the risk of unexpected interruption of relay protection services caused by configuration change operations.
[0071] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. An automated intelligent operation and maintenance system for power network equipment, characterized in that, include: Power grid status sensing module: acquires real-time power grid operation data and outputs the power grid operation mode level, power flow load rate of key lines, and the main protection channel activation / deactivation status of power grid relay protection devices; Service impact identification module: Receives network device configuration change requests, performs path diffusion reasoning along the network topology based on the pre-built power service bearer mapping library, and outputs the power service type carried by the port within the diffusion path, the corresponding relay protection device identifier and static security sensitivity level, forming a service security sensitivity level vector; Priority dynamic correction module: Based on the matching result between the main protection channel's activation / deactivation status and the relay protection device identifier in the business security sensitivity level vector, the static security sensitivity level of the backup protection channel corresponding to the relay protection device whose main protection channel is in the deactivated state is upgraded and corrected, and the corrected business security sensitivity level vector is output. Access Decision Module: Using the highest security sensitivity level in the modified business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate, query the pre-calibrated two-dimensional security domain matrix and output the access decision; The execution window recommendation module predicts the power grid operation mode level, critical line power flow load rate, and main protection channel activation / deactivation status of relay protection devices for future time periods when the access decision is prohibited or conditionally permitted. This information is then substituted into the priority dynamic correction module and the access decision module. The business security sensitivity level vector remains unchanged as a fixed input. The modules are sorted from high to low according to the margin between the time period where the access decision is permitted or conditionally permitted and the boundary of the two-dimensional security domain matrix, and the safe execution window recommendation list is output.
2. The automated intelligent operation and maintenance system for power network equipment according to claim 1, characterized in that, In the power grid status sensing module, the outputs of the power grid operation mode level, critical line power flow load rate, and the main protection channel activation / deactivation status of the power grid relay protection device specifically include: The critical lines are transmission lines that are pre-designated and recorded by the dispatching agency in accordance with the power grid dispatching regulations; Collect active power data for each critical path and calculate the power flow load rate for each critical path. The power flow load rate is the ratio of the current active power of the corresponding critical path to its thermal stability limit. Collect the channel status signals of each relay protection device, determine and extract the current activation / deactivation status of the main protection channel of each relay protection device based on the channel status signals, and the activation / deactivation status is set to either activation or deactivation; According to the dispatching procedures, the current power grid operation status is divided into corresponding operation mode levels. The operation mode levels are pre-set ordered discrete levels. The higher the level value, the lower the safety margin of the power grid operation. The operating mode level, the power flow load rate of each critical line, and the main protection channel activation / deactivation status of each relay protection device are combined and output.
3. The automated intelligent operation and maintenance system for power network equipment according to claim 1, characterized in that, In the business impact identification module, the construction of the power service bearer mapping library specifically includes: By identifying the protocol characteristics of power communication protocols in network traffic, the type of power service carried by each port is automatically inferred, and an initial mapping record is generated. The initial mapping records are formally entered into the database after being reviewed and confirmed by the operations and maintenance personnel. Record the device identifier, port identifier, power service type, associated relay protection device identifier, static security sensitivity level, and redundancy path availability status at the port level. The static security sensitivity level is manually marked and entered by operation and maintenance personnel during the review and confirmation process based on the power service type and the importance level of the associated relay protection device.
4. The automated intelligent operation and maintenance system for power network equipment according to claim 3, characterized in that, In the business impact identification module, the specific steps of the path diffusion reasoning include: Starting with the port identifier of the object being changed, traverse each port on the downstream forwarding path hop by hop along the network topology; At each node, query the power service bearer mapping library to obtain the power service type, the identifier of the relay protection device to which it belongs, the static security sensitivity level, and the availability status of the redundant path for the corresponding port; When the redundant path of a node is available, the diffusion stops with that node as the termination boundary. When the redundant path of a node is in an unavailable state, it continues to spread downstream; The power service type, the corresponding relay protection device identifier, and the static security sensitivity level of each port on all unterminated paths are summarized to form the service security sensitivity level vector.
5. The automated intelligent operation and maintenance system for power network equipment according to claim 1, characterized in that, The priority dynamic correction module also includes the step of constructing a primary and backup protection channel correspondence table: Import static configuration data, extract the mapping relationship between the main protection channel identifier and the corresponding backup protection channel identifier of each relay protection device, and form a static correspondence record; The system analyzes the channel status dataset reported by relay protection devices in the IEC 61850 MMS messages in the network, extracts the current actual main protection channel identifier and backup protection channel identifier of each relay protection device, and forms a dynamic correspondence record. The dynamic correspondence record is compared and fused with the static correspondence record with priority. When the two are consistent, the correspondence is confirmed. When the two are inconsistent, an alarm is output and the dynamic correspondence record is used as the standard to generate the main and backup protection channel correspondence table. The main and backup protection channel correspondence table is indexed by the relay protection device identifier and records the main protection channel identifier and the corresponding backup protection channel identifier of each relay protection device. The priority dynamic correction module performs the matching based on the primary and backup protection channel correspondence table.
6. The automated intelligent operation and maintenance system for power network equipment according to claim 5, characterized in that, In the priority dynamic correction module, the specific steps of the improvement correction include: Extract the relay protection device identifiers that are in the deactivated state of the main protection channel from the main protection channel activation / deactivation status, and form a set of deactivated relay protection device identifiers; Based on the main and backup protection channel correspondence table, the relay protection device identifiers that have corresponding backup protection channels in the set of exited relay protection device identifiers are selected to form a valid set of exited relay protection device identifiers; The port whose relay protection device identifier belongs to the set of valid exited relay protection device identifiers is retrieved from the business security sensitivity level vector and is used as the port with a successful match. For ports that are successfully matched and whose static security sensitivity level is lower than the highest level, their security sensitivity level is adjusted to the highest level. For ports that are not found, their security sensitivity level remains unchanged from the static security sensitivity level. Summarize the corrected security sensitivity levels of all ports and output the corrected service security sensitivity level vector.
7. The automated intelligent operation and maintenance system for power network equipment according to claim 6, characterized in that, The priority dynamic correction module also includes a decision reversal detection step: The two-dimensional security domain matrix is queried using the highest level of static security sensitivity level in the business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate to obtain the pre-correction access decision. The modified access decision is obtained by querying the two-dimensional security domain matrix with the highest level in the modified business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate. When the access decision was allowed before the correction but is prohibited or conditionally allowed after the correction, a decision reversal is determined to have occurred, and a decision reversal prompt is output to the operator. The decision reversal prompt includes the port identifier that triggered the reversal, the corresponding relay protection device identifier, and the current enabled / disabled status of the main protection channel of the relay protection device.
8. The automated intelligent operation and maintenance system for power network equipment according to claim 1, characterized in that, In the admission decision module, the calibration of the two-dimensional security domain matrix specifically includes: A matrix is constructed using the power business security sensitivity level as the row index and the combined range of the power grid operation mode level and the power flow load rate of the critical line as the column index. Power system professionals and network operation and maintenance professionals jointly perform initial calibration of the access decision for each cell, with the access decision value being allowed, conditionally allowed, or prohibited; When the cell admission decision is set to allow conditions, the corresponding execution time window requirements and rollback trigger conditions are recorded synchronously. When the actual execution result is inconsistent with the access decision marked in the corresponding cell, the inconsistency record will be submitted to power system professionals and network operation and maintenance professionals for review. After review and confirmation, the access decision of the corresponding cell will be corrected and updated.
9. The automated intelligent operation and maintenance system for power network equipment according to claim 1, characterized in that, In the execution window recommendation module, the specific steps for sorting by margin from high to low include: The minimum step difference between the corresponding cell in the two-dimensional security domain matrix and the nearest prohibited boundary cell is calculated for the period when the admission decision is allowed or conditionally allowed, and this step is used as the margin value for that period. The margin values for each time period are weighted by confidence level according to the time interval from the current time, with the time period further away from the current time being assigned a lower confidence level weight; Sort the weighted margin values from highest to lowest and output the recommended list of safe execution windows.
10. A method for automated and intelligent operation and maintenance of power network equipment, characterized in that, include: Acquire real-time power grid operation data and output the power grid operation mode level, power flow load rate of key lines, and the main protection channel activation / deactivation status of power grid relay protection devices; Upon receiving a network device configuration change request, the system performs path diffusion reasoning along the network topology based on a pre-built power service bearer mapping library, and outputs the power service type carried by the port within the diffusion path, the identifier of the corresponding relay protection device, and the static security sensitivity level, thus forming a service security sensitivity level vector. Based on the matching results between the main protection channel's activation / deactivation status and the relay protection device identifier in the business security sensitivity level vector, the static security sensitivity level of the backup protection channel corresponding to the relay protection device whose main protection channel is in deactivation status is improved and corrected, and the corrected business security sensitivity level vector is output. Using the highest security sensitivity level in the corrected business security sensitivity level vector, the power grid operation mode level, and the critical line power flow load rate, query the pre-calibrated two-dimensional security domain matrix and output the admission decision; When the access decision is prohibited or conditionally permitted, predict the power grid operation mode level, critical line power flow load rate, and main protection channel activation / deactivation status of relay protection devices for each future time period, and substitute them into the priority dynamic correction step and access decision step. The business security sensitivity level vector is used as a fixed input and remains unchanged. Sort the time periods with access decisions of permitted or conditionally permitted and the margin of the two-dimensional security domain matrix boundary from high to low, and output a list of recommended security execution windows.