A transformer area microgrid black start sequence self-generation method and device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-08
- Publication Date
- 2026-08-11
AI Technical Summary
[0004]为解决配电台区或园区微电网等供电或配电系统在外部电网失电后依赖人工经验或固定顺序进行黑启动,难以适应负荷结构、储能状态、构网逆变器容量和新能源可用出力变化的问题,本发明提供一种台区微网黑启动序列自生成方法及装置
[0020]综上,本发明提供的技术方案在外部电网失电后,先依据历史用电曲线、负荷类型、冷负荷启动电流和关键负荷等级形成负荷恢复指纹,再依据拓扑开关状态、故障隔离边界、储能接入点和负荷分布形成可恢复岛段,并对每一可恢复岛段计算启动冲击、无功需求、频率跌落风险和储能支撑裕度。在此基础上,系统生成储能建压、关键负荷恢复、新能源并入、普通负荷分批投入和并网校核的黑启动序列,并在各步骤执行后依据实时电压、频率、逆变器电流、储能荷电状态、新能源出力和保护告警状态进行校核或重排。该方案使黑启动序列能够随台区负荷状态、储能状态和拓扑状态变化而调整。
Smart Images

Figure CN122553347A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of black-start control technology for power supply or distribution systems and energy storage systems, specifically to a method and apparatus for self-generating black-start sequences for distribution substations or park microgrids. Background Technology
[0002] Distribution substations or industrial park microgrids are power supply or distribution systems with energy storage, distributed power sources, and various types of loads. They typically connect to energy storage, photovoltaic systems, charging facilities, production equipment, fire protection and security systems, communication equipment, and residential and office loads. When the external power grid experiences a power outage, the microgrid needs to rely on energy storage and grid-connected inverters to establish voltage, maintain frequency, and gradually restore critical loads, distributed power sources, and ordinary loads. Due to the complex types of loads in the distribution substation, the restoration after a power outage may result in cold load starting current, motor inrush current, and a sudden increase in reactive power demand. If the restoration sequence is not set properly, it can easily cause bus voltage drops, frequency deviations, inverter overcurrent, or insufficient energy storage support.
[0003] Existing black-start control methods typically rely on preset sequences, manual experience, or simple prioritization based on load power and importance levels. These methods struggle to simultaneously reflect the coupling relationships between historical electricity consumption characteristics, cold-start impacts, load recovery priorities, grid inverter capacity, and energy storage state of charge. While partial source-load coordinated recovery methods can perform optimization calculations, they lack unified quantitative processing of the start-up impacts, reactive power demand, frequency drop risks, and energy storage support margins for recoverable island segments within the transformer substation area. They also lack mechanisms for automatically backtracking and rearranging subsequent recovery steps based on execution feedback. Therefore, a technical solution is needed that can automatically generate black-start sequences by combining load fingerprints, island segment risks, and energy storage support capabilities. Summary of the Invention
[0004] To address the problem that power supply or distribution systems such as distribution substations or industrial park microgrids rely on manual experience or fixed sequences for black starts after external grid failures, which are difficult to adapt to changes in load structure, energy storage status, grid-connected inverter capacity, and available renewable energy output, this invention provides a method and apparatus for self-generating black start sequences for substation microgrids. After the microgrid enters an islanded self-recovery state, this scheme does not directly add loads according to a preset load list. Instead, it first generates a calculable load recovery fingerprint based on load operation data and the equipment status of energy storage, grid-connected inverters, controllable switches, and distributed power sources. Then, it forms recoverable island segments based on the current distribution topology and fault isolation boundaries, and calculates the start-up risk and support capacity of each recoverable island segment, thereby generating a black start sequence that matches the current power supply recovery conditions.
[0005] One aspect of this invention provides a method for self-generating a black start sequence for a microgrid in a distribution area. This method is applied to a power supply or distribution microgrid system including an energy storage system, a grid-connected inverter, a controllable switch, renewable energy units, critical loads, and general loads. The energy storage system provides voltage build-up energy and load restoration support after an external power grid failure. The grid-connected inverter establishes or maintains the voltage and frequency of the microgrid in islanded operation. The controllable switch switches feeders, branches, loads, and renewable energy units. The renewable energy units can be photovoltaic power generation units, wind power generation units, or other distributed power sources. The critical loads can include communication, security, fire protection, medical, production control, or other loads requiring priority power restoration.
[0006] After detecting and isolating an external power grid failure, the microgrid's historical power consumption curves, load types, cold load start-up currents, energy storage state of charge, grid inverter capacity, critical load levels, topology switch status, and available renewable energy output are acquired. The external power grid failure can be determined comprehensively based on grid connection point voltage, frequency, circuit breaker location, protection action signals, and grid-side communication status. Fault isolation can be achieved by disconnecting faulty branches, locking faulty switches, and marking unrecoverable areas to prevent black-start sequences from including the faulty area in the recovery process.
[0007] When acquiring operational data, data can be read from smart meters, smart distribution terminals, energy storage management systems, grid-connected inverter controllers, distributed power controllers, and distribution automation terminals. Data from different sources has different sampling periods and communication delays, allowing for time alignment, outlier removal, and validity marking of the operational data. Historical electricity consumption curves are associated with corresponding branches, user-side metering points, or equipment objects according to load identifiers. Load types are categorized into motor loads, constant power electronic loads, lighting loads, air conditioning / cooling loads, charging loads, and backup loads. Cold load starting current is determined based on load type, outage duration, historical starting records, and rated power. The energy storage state of charge and available discharge power are used together to characterize the energy storage's voltage build-up capability and subsequent support capacity. The grid-connected inverter capacity can be adjusted based on rated capacity, short-time overload capacity, temperature status, and current alarm status.
[0008] After obtaining the above operational data, load recovery fingerprints are generated for the loads to be restored based on historical power consumption curves, load types, cold load starting currents, and critical load levels. Load recovery fingerprints characterize the priority and risk level of a load suitable for restoration during a black start process. For the k-th load to be restored, Lk, a load recovery fingerprint LFk can be formed. LFk includes historical power characteristics Pk_hist, load type Typek, cold load starting current Icold_k, cold load surge multiple Kcold_k, starting reactive power demand Qstart_k, critical load level Gradek, interruptibility attribute Interruptk, outage duration Toff_k, and allowable ramp recovery capability Rampk. The above fingerprint fields can be configured fully or simplified based on available field data, but loads within the same microgrid should be calculated according to a unified fingerprint rule.
[0009] Furthermore, the load recovery priority value PRk can be calculated based on the load recovery fingerprint. PRk can be determined using the following expression: PRk=a1×GradeScorek+a2×ContinuityScorek+a3×CriticalTimeScorek-a4×ColdImpactScorek-a5×ReactiveScorek-a6×RampRiskScorek Where a1 to a6 are preset weights, GradeScorek is determined by the critical load level, ContinuityScorek by the continuous power supply demand, CriticalTimeScorek by the allowable interruption duration or recovery time, ColdImpactScorek by the cold load starting current and cold load impact multiple, ReactiveScorek by the starting reactive power demand, and RampRiskScorek by the allowable ramp recovery capability and outage duration. This expression describes an implementable scoring relationship. In practical applications, an equivalent scoring method can be used while maintaining the positive impact of the critical load level, the cold start impact, and the negative impact of reactive power demand.
[0010] After generating load recovery fingerprints, the microgrid is divided into multiple recoverable island segments based on topology switch status, fault isolation boundaries, energy storage access points, and load distribution. When dividing recoverable island segments, the current electrical topology's buses, feeders, sectionalizing switches, tie switches, energy storage access points, grid-connected inverter access points, critical load access points, and fault isolation boundaries can be used as criteria to determine candidate areas that are electrically isolated from the fault area and can be independently switched by controllable switches. For these candidate areas, recoverable island segments are then formed based on line capacity, transformer capacity, energy storage support paths, the number of critical loads, and the capacity of ordinary loads.
[0011] When high-initiation-impact loads and critical loads are mixed within the same candidate area, the candidate area can be further divided into critical load sub-island segments and ordinary load sub-island segments, allowing critical loads to recover preferentially under smaller initiation-impact conditions. When a candidate area lacks network support paths, has uncontrollable switch boundaries, or has unclear isolation status from the fault area, the candidate area can be marked as a temporarily deferred recovery island segment. Through this processing, the black-start object is no longer just a single load or the entire feeder, but a recoverable island segment that matches the field topology, switch controllability, and support paths.
[0012] For each recoverable island segment, calculate the startup impact, reactive power demand, frequency sag risk, and energy storage support margin. For the j-th recoverable island segment Ij, calculate the startup impact SIj, reactive power demand RQj, frequency sag risk FRj, and energy storage support margin SMj. The startup impact SIj represents the degree of short-term capacity occupancy of the grid inverter when the island segment is put into operation, and can be expressed as: SIj=(Σxk×Pstart_k+Σxm×Pinrush_m) / Sgfm_j Where xk indicates whether the corresponding load belongs to the candidate set for connection, xm indicates whether the corresponding impulsive load belongs to the candidate set for connection, Pstart_k indicates the equivalent active power impact at load startup, Pinrush_m indicates the transient impact power of the impulsive load, and Sgfm_j indicates the correction capacity of the grid inverter supporting the recoverable island segment. The reactive power demand RQj represents the voltage support capability requirement after the island segment is connected, and can be expressed as: RQj=Σxk×Qstart_k+Qline_j+Qmag_j-Qlocal_j Where Qstart_k represents the reactive power demand for load startup, Qline_j represents the reactive power consumption of the line, Qmag_j represents the reactive power of transformer excitation, and Qlocal_j represents the local available reactive power support. Frequency sag risk FRj represents the risk of frequency drop caused by active power imbalance resulting from island segment commissioning, and can be expressed as: FRj=ΔPj / Preserve_j Where ΔPj represents the active power imbalance caused by the island segment's commissioning, and Preserve_j represents the active power regulation margin of the energy storage and grid-connected inverters within the allowable frequency deviation. The energy storage support margin SMj represents the support capability of energy storage for the island segment in both power and energy dimensions, and can be expressed as: SMj=min(Pess_avail / Pstep_j,Eess_avail / Esupport_j) Where Pess_avail represents the available discharge power of the energy storage, Pstep_j represents the expected additional power in this step, Eess_avail represents the available energy after deducting the minimum state of charge and reserve, and Esupport_j represents the energy required for the island segment within the preset support duration.
[0013] After obtaining the load recovery fingerprint and island segment calculation results, a black start sequence is generated based on the load recovery fingerprint and the calculation results of each recoverable island segment. When generating the black start sequence, it can be first determined whether the energy storage state of charge, available energy storage discharge power, and grid-connected inverter correction capacity meet the voltage build-up conditions. If the voltage build-up conditions are met, an energy storage voltage build-up step is generated, controlling the corresponding grid-connected inverter of the energy storage system to enter voltage source control or equivalent grid-connected control mode to establish the microgrid bus voltage and frequency. After voltage build-up is completed, the no-load bus voltage, no-load frequency, inverter current, and protection alarm status are verified.
[0014] After the energy storage pressure build-up step passes verification, the subsequent execution sequence is determined based on the recovery level of the recoverable island segments. When the SIj of a recoverable island segment is less than the start-up impact threshold, RQj is less than the reactive power threshold, FRj is less than the frequency risk threshold, and SMj is greater than the support margin threshold, that recoverable island segment is included in the current recoverable set. When the SIj or RQj of a recoverable island segment containing a critical load exceeds the corresponding threshold, but SMj meets the support margin threshold, load splitting, delayed deployment, segmented deployment, or power limiting deployment are performed on that recoverable island segment. When SMj does not meet the support margin threshold, the recoverable island segment is scheduled for recovery after the integration of new energy sources or the removal of low-priority loads.
[0015] When generating critical load restoration steps, the critical load restoration targets are selected based on load restoration priority, critical load level, startup impact, and the energy storage support margin of the island segment. For critical loads where the cold load startup current Icold_k is greater than the preset cold start current threshold Ith or the cold load impact multiple Kcold_k is greater than the preset impact multiple threshold Kth, delayed activation, segmented activation, or ramp activation conditions can be set. Ith and Kth are determined based on the short-term withstand capability of the grid inverter, branch protection settings, and historical startup records. After the critical load is activated, bus voltage, frequency, grid inverter current, and energy storage output power are collected, and it is determined whether the activation result meets the conditions for continued restoration. If voltage exceedance, frequency drop, or inverter overcurrent occurs after the critical load is activated, subsequent load restoration can be suspended, and the most recently activated load can be deloaded, disconnected, or rearranged.
[0016] During the renewable energy integration process, once the bus voltage, frequency, and phase are within permissible ranges, the renewable energy units can be controlled to integrate into the microgrid in a power-limited and slope-limited manner. After renewable energy integration, the available active power regulation margin, local available reactive power support, and energy storage support margin are updated based on the actual output of the renewable energy. For renewable energy units such as photovoltaics, which have large output fluctuations, the integration capacity can be limited based on irradiance, inverter status, power forecasts, and the current power change rate to avoid frequency and voltage fluctuations caused by the renewable energy integration process.
[0017] When generating the phased deployment of ordinary loads, the ordinary loads are divided into multiple deployment batches based on load recovery priority, the startup impact of the recoverable island segment, reactive power demand, frequency drop risk, and energy storage support margin. The total startup impact of each deployment batch does not exceed the short-term withstand capacity of the grid inverter, the expected reactive power demand of each deployment batch does not exceed the local reactive power support capacity, and the energy required by each deployment batch within the preset support duration does not exceed the available energy of the energy storage. After each deployment batch is executed, bus voltage, frequency, grid inverter current, energy storage output power, energy storage state of charge, renewable energy output, and protection alarm status are collected. If the collected results meet the verification conditions, the next deployment batch is executed. If the collected results do not meet the verification conditions, the loads in the most recent deployment batch are sorted in ascending order according to the load recovery priority value PRk, and the load at the top of the sorted list is removed. Then, the deployment batches for the remaining ordinary loads are recalculated.
[0018] During the grid connection verification process, after the external grid is restored, the voltage amplitude, frequency, phase angle, synchronous voltage difference, power exchange direction, and grid connection switch status are collected from both the microgrid side and the external grid side. When the voltage amplitude difference, frequency difference, phase angle difference, and predicted power exchange value meet the grid connection conditions, a grid connection execution command is generated. If the grid connection conditions are not met, islanded operation is maintained, and the operation status of the restored loads and renewable energy units continues according to the black start sequence. After grid connection is completed, the execution steps, input objects, verification indicators, reordering times, and anomaly causes throughout the entire black start process can be recorded to correct subsequent load restoration fingerprints.
[0019] Another aspect of the present invention provides a device for automatically generating black start sequences for microgrids in power distribution areas. This device is used for power outage self-recovery control in power supply or distribution microgrid systems, and includes a power outage identification and status acquisition module, a load recovery fingerprint generation module, a recoverable island segment division module, an island segment risk assessment module, a start sequence generation module, an execution verification and rearrangement module, and a human-machine interaction recording module. The power outage identification and status acquisition module is used to acquire historical electricity consumption curves, load types, cold load start currents, energy storage state of charge, grid inverter capacity, critical load levels, topology switch status, and available renewable energy output after detecting an external grid outage and completing fault isolation. The load recovery fingerprint generation module is used to generate load recovery fingerprints for loads to be restored and calculate load recovery priority values. The recoverable island segment division module is used to divide recoverable island segments according to topology switch status, fault isolation boundaries, energy storage access points, and load distribution. The island segment risk assessment module is used to calculate the start-up impact, reactive power demand, frequency drop risk, and energy storage support margin for each recoverable island segment. The startup sequence generation module generates a black start sequence that includes energy storage voltage building, critical load restoration, renewable energy integration, phased commissioning of ordinary loads, and grid connection verification. The execution verification and rearrangement module verifies or rearranges subsequent black start sequences based on the voltage, frequency, inverter current, energy storage state of charge, renewable energy output, and protection alarm status after the black start steps are executed. The human-machine interaction recording module displays the black start sequence, island segment risk indicators, execution status, and rearrangement results, and records black start execution data to correct subsequent load restoration fingerprints.
[0020] In summary, the technical solution provided by this invention, after an external power grid failure, first generates a load recovery fingerprint based on historical power consumption curves, load types, cold load start-up currents, and critical load levels. Then, it forms recoverable island segments based on topology switch status, fault isolation boundaries, energy storage access points, and load distribution. For each recoverable island segment, it calculates the start-up impact, reactive power demand, frequency drop risk, and energy storage support margin. Based on this, the system generates a black-start sequence for energy storage voltage building up, critical load recovery, renewable energy integration, phased commissioning of ordinary loads, and grid connection verification. After each step is executed, verification or rearrangement is performed based on real-time voltage, frequency, inverter current, energy storage state of charge, renewable energy output, and protection alarm status. This solution allows the black-start sequence to adjust according to changes in the load status, energy storage status, and topology status of the distribution area.
[0021] Compared to existing methods that rely on fixed sequences or manual experience to restore loads, this invention uses load restoration fingerprints as the basis for restoration sequencing. This ensures that the restoration order reflects not only the importance of the load but also factors such as cold start impact, reactive power demand, interruptibility attributes, and outage duration. This reduces the probability of high-impact loads being directly put into operation during the initial voltage build-up phase and increases the likelihood of critical loads being prioritized for restoration when support capacity is sufficient. Furthermore, this invention calculates start-up impact, reactive power demand, frequency drop risk, and energy storage support margin at the recoverable island segment level, expanding the load restoration target from individual loads to island segments with electrical boundaries and support paths. This processing more accurately reflects the impact of a branch or area being put into operation on bus voltage, frequency, and energy storage power, thereby reducing restoration failures caused by unreasonable local branch load combinations.
[0022] Finally, this invention integrates energy storage voltage establishment, critical load restoration, renewable energy integration, phased deployment of ordinary loads, and grid connection verification into a single sequence generation process. Energy storage and grid-connected inverters are first used to establish stable voltage and frequency. Critical loads are restored first after support conditions are met. Renewable energy is integrated as a subsequent support resource after voltage and frequency stability. Ordinary loads are deployed in batches according to the updated support margin. Grid connection verification is then performed after the external grid is restored. Through this process, the black start process has a relatively complete self-recovery chain. After each black start step, this invention collects voltage, frequency, inverter current, energy storage state of charge, renewable energy output, and protection alarm status. Based on the verification results, it continues execution, pauses execution, disconnects low-priority loads, or regenerates the remaining sequence. Therefore, even if there is a deviation between the actual load start-up impact and the estimated value, or changes in renewable energy output or energy storage status, the system can still correct subsequent recovery steps based on the latest operating status.
[0023] This invention can be deployed in smart converged terminals in distribution substations, microgrid energy management systems, energy storage controllers, grid-connected inverter controllers, or edge computing gateways. These devices can acquire data from smart meters, energy storage management systems, distributed power controllers, and distribution automation terminals via communication interfaces, and issue execution commands to controllable switches, energy storage systems, grid-connected inverters, and new energy units. Through this deployment method, the microgrid can generate a black-start sequence matching its current operating state with minimal human intervention after an external power grid failure, providing dispatchers with traceable recovery steps and risk indicators. Attached Figure Description
[0024] To more clearly illustrate the technical solution of this application, the accompanying drawings are briefly described below. The following drawings are used to illustrate the method flow, system architecture, load fingerprint construction, island segmentation, risk assessment, execution timing, device modules, and application effects of this application, and do not constitute a limitation on the physical location of each module, the number of interfaces, device size, communication protocol, or the scale of the illustrations.
[0025] Figure 1 This is a schematic diagram of the overall process of the method for automatically generating the black startup sequence of a microgrid in a transformer area, as provided in an embodiment of the present invention.
[0026] Figure 2 This is a schematic diagram of the system architecture for the self-generated black startup sequence of the microgrid in the substation provided in an embodiment of the present invention.
[0027] Figure 3 This is a schematic diagram of load recovery fingerprint generation provided in an embodiment of the present invention.
[0028] Figure 4 This is a schematic diagram of recoverable island segment division provided in an embodiment of the present invention.
[0029] Figure 5 This is a schematic diagram illustrating the island segment risk calculation and recovery level determination provided in an embodiment of the present invention.
[0030] Figure 6 This is a schematic diagram of the execution timing of the black start sequence provided in an embodiment of the present invention.
[0031] Figure 7 A schematic diagram of the module structure of the self-generating device for the black startup sequence of the microgrid in the substation provided in an embodiment of the present invention.
[0032] Figure 8 The diagram illustrates the application scenarios and technical effects provided in the embodiments of the present invention. Detailed Implementation
[0033] The technical solution of the present invention will be further described below with reference to the accompanying drawings. The described embodiments are used to illustrate the implementation process of the present invention and are not intended to limit the model, communication method, parameter values or application scenarios of each device. For microgrids with energy storage, grid-connected inverters, controllable switches, new energy units and multiple types of loads, such as distribution substations, industrial parks, commercial parks, campuses, hospitals, data centers or rural substations, a black start sequence can be generated according to the processing logic of the present invention.
[0034] Example 1 This embodiment provides a method for self-generating a black startup sequence for a microgrid in a transformer area. (Refer to...) Figure 1 This method can be executed by a smart converged terminal in the distribution area, a microgrid energy management system, an edge computing gateway, an energy storage controller, or a control device that communicates with the above-mentioned equipment. The microgrid includes an energy storage system, a grid-connected inverter, controllable switches, renewable energy units, critical loads, and general loads. The energy storage system provides voltage build-up energy and load recovery support after an external power grid failure; the grid-connected inverter establishes voltage and frequency references in islanded mode; the controllable switches are used to switch feeders, branches, and loads; and the renewable energy units supplement the microgrid with active or reactive power support after voltage and frequency stabilization.
[0035] Reference Figure 2 The black-start sequence self-generation process of this application can be implemented collaboratively as a data acquisition layer, a sequence generation layer, and an execution verification layer. The data acquisition layer provides the sequence generation layer with the basic operating data and equipment status data required for black-start sequence generation. It may include smart meters, an energy storage management system, a grid-connected inverter controller, and a topology and switch status acquisition unit. Smart meters provide historical power consumption curves, current power, and load change characteristics for each load branch or user-side metering point. The energy storage management system provides the energy storage state of charge, available discharge power, available energy, energy storage alarm status, and energy storage operating constraints. The grid-connected inverter controller provides the grid-connected inverter's rated capacity, short-time overload capacity, current control mode, output current, voltage and frequency support capability, and alarm status. The topology and switch status acquisition unit provides the status of grid-connected switches, sectionalizing switches, tie switches, load branch switches, and fault isolation boundaries.
[0036] The sequence generation layer is used to generate the calculation results of the black start sequence based on the data provided by the data acquisition layer. This layer includes a load recovery fingerprint generation module, a recoverable island segment division module, an island segment risk assessment module, and a start sequence generation module. The load recovery fingerprint generation module receives data corresponding to smart meters and load files, generates load recovery fingerprints for each load to be restored, and outputs load recovery priority values. The recoverable island segment division module receives information on energy storage access points, topology switch status, fault isolation boundaries, and load distribution to form recoverable island segments that can be independently switched on and off by controllable switches or restored in stages. The island segment risk assessment module receives the recoverable island segment division results and, combined with the support capability data provided by the energy storage management system and the grid-connected inverter controller, calculates the start-up impact, reactive power demand, frequency drop risk, and energy storage support margin for each recoverable island segment. The start sequence generation module generates the execution sequence of energy storage pressure building, critical load restoration, new energy integration, phased commissioning of ordinary loads, and grid connection verification based on the load recovery fingerprints and island segment risk assessment results.
[0037] Figure 2 The connection between the load recovery fingerprint generation module and the start-up sequence generation module indicates that the load recovery fingerprint is used not only to determine the recovery priority of critical loads and ordinary loads, but also to determine the order of load commissioning and rollback in ordinary load batching, abnormal load shedding, and subsequent rearrangement. The connection between the recoverable island segment division module and the island segment risk assessment module indicates that risk calculation is based on recoverable island segments, not just individual loads. The connection between the island segment risk assessment module and the start-up sequence generation module indicates that the start-up sequence generation module will only include the corresponding island segment or load batch in the current executable sequence after the island segment meets the constraints of start-up impact, reactive power demand, frequency drop risk, and energy storage support margin.
[0038] The execution verification layer is used to implement the execution results generated by the startup sequence generation module to the field equipment and return the execution feedback to the sequence generation layer. This layer may include controllable switches, load branches, renewable energy units, and an execution verification and rearrangement module. The controllable switches, based on the switching commands output by the startup sequence generation module, perform closing, opening, or blocking control on energy storage support paths, critical load branches, ordinary load branches, and renewable energy access branches. After being connected, load branches feed back branch current, active power, reactive power, switch position, and protection alarm status to the execution verification and rearrangement module. During the connection process, renewable energy units output according to power limiting and slope limiting commands and feed back actual output, voltage support status, and operating alarm status.
[0039] Figure 2 The dashed feedback relationship in the diagram indicates that when the execution verification and rearrangement module detects voltage exceeding limits, frequency drops exceeding thresholds, grid inverter overcurrent, energy storage state of charge below the guaranteed threshold, renewable energy output fluctuations exceeding thresholds, or protection alarms, the execution verification and rearrangement module returns the abnormal object, abnormal time, most recently commissioned batch, feedback indicators, and rollback results to the sequence generation layer. Based on this, the sequence generation layer updates the corresponding load's cold load impact score, slope risk score, frequency drop risk of the island segment, and energy storage support margin, and regenerates the remaining black start sequence. Figure 2 The architecture shown forms a closed loop between data acquisition, sequence generation, and execution verification, enabling the black start sequence to adjust according to changes in energy storage status, topology status, load start-up impact, and field feedback.
[0040] Specifically, in step S101, the control device detects whether the external power grid has lost power and completes fault isolation when the power loss criterion is met. External power grid loss can be determined comprehensively based on the voltage amplitude at the grid connection point, the grid connection point frequency, the status of the grid connection switch, protection action signals, and the communication status with the upstream power grid. For example, when the three-phase voltage at the grid connection point is lower than a preset power loss threshold and remains below it for more than a preset confirmation time, or when the grid connection switch is in the open state and there is no effective voltage on the upstream power grid side, the control device determines that the external power grid has lost power. Fault isolation can be accomplished by disconnecting the faulty branch switch, locking the fault area tie switch, or marking unrecoverable feeders. This process ensures that subsequent black-start sequences are generated only for microgrid areas that can be safely restored, avoiding including the faulty area within the recovery scope.
[0041] In step S102, the control device acquires historical electricity consumption curves, load types, cold load starting currents, energy storage state of charge (SOC), grid inverter capacity, critical load levels, topology switch status, and available renewable energy output. Historical electricity consumption curves can be obtained from smart meters, branch metering units, or regional historical load databases, and their time scale can be minute-level, hour-level, or day-level. Load types can be determined from load ledgers, user files, or equipment identification results. Cold load starting currents can be estimated based on historical starting records, rated power, load type, and outage duration. The SOC is provided by the energy storage management system, the grid inverter capacity is provided by the inverter controller, the topology switch status is provided by the distribution automation terminal or switch control unit, and the available renewable energy output is provided by the renewable energy inverter or prediction module.
[0042] After acquiring the above data, the control device performs time alignment and validity processing on data from different sources. For data with slow changes, such as energy storage state of charge, critical load levels, and load types, the most recent valid value can be used in the calculation; for data with rapid changes, such as bus voltage, frequency, inverter current, and renewable energy output, the value can be taken according to the current control cycle or the most recent sampling window. If a data item is missing but its corresponding equipment is not in an alarm state, the previous valid value can be used with a reduced reliability; if the data loss continues for more than a set time, the control device will mark the corresponding load, equipment, or island segment as a temporarily delayed recovery object.
[0043] In step S103, the control device generates a load recovery fingerprint for the load to be restored. For the k-th load to be restored, Lk, the load recovery fingerprint LFk can be represented as LFk={Pk_hist, Typek, Icold_k, Kcold_k, Qstart_k, Gradek, Interruptk, Toff_k, Rampk}. Wherein, Pk_hist represents historical power characteristics, Typek represents load type, Icold_k represents cold load starting current, Kcold_k represents cold load surge multiple, Qstart_k represents starting reactive power demand, Gradek represents critical load level, Interruptk represents interruptibility attribute, Toff_k represents outage duration, and Rampk represents allowed ramp recovery capability. Through this fingerprint, the control device can simultaneously describe the load's importance, starting surge, reactive power demand, and recovery flexibility.
[0044] The control device can further calculate the load recovery priority value PRk based on the load recovery fingerprint. PRk can be expressed as PRk = a1 × GradeScorek + a2 × ContinuityScorek + a3 × CriticalTimeScorek - a4 × ColdImpactScorek - a5 × ReactiveScorek - a6 × RampRiskScorek. Here, a1 to a6 are weighted parameters: GradeScorek is determined by the critical load level; ContinuityScorek is determined by continuous power supply demand; CriticalTimeScorek is determined by the allowable interruption duration or recovery time limit; ColdImpactScorek is determined by the cold load starting current and cold load impact multiple; ReactiveScorek is determined by the starting reactive power demand; and RampRiskScorek is determined by the allowable ramp recovery capability and outage duration. In power supply assurance scenarios, a1 and a2 can be increased; when energy storage capacity is low or grid inverter capacity is small, a4 and a5 can be increased, allowing high-impact, high-reactive-demand loads to have their recovery delayed during the initial voltage build-up phase.
[0045] In this embodiment, the preset cold start current threshold Ith and the preset impact multiple threshold Kth are used to determine whether critical loads need to be delayed, segmented, or ramped up. Ith can be determined by converting the grid inverter's allowable short-time current, branch protection settings, and the corresponding load's rated current. Kth can be determined by historical start-up peak values, load type, and outage duration. For loads that are disconnected after a batch of ordinary loads malfunctions, the control device sorts the loads in the most recently connected batches according to PRk from smallest to largest, and selects the first load in the sort that meets the interruptibility condition as the rollback target. When the first load in the sort does not meet the interruptibility condition, the next load that meets the interruptibility condition is selected sequentially according to the sorting result.
[0046] In step S104, the control device divides the recoverable island segment according to the topology switch status, fault isolation boundary, energy storage access point, and load distribution. (Refer to...) Figure 4 The microgrid busbar can connect multiple branches via sectionalizing switches or tie switches. These branches house communication, security, production control, general office, and other loads. The control device uses the busbar, feeders, sectionalizing switches, tie switches, transformers, energy storage access points, grid inverter access points, critical load access points, and fault isolation boundaries as criteria to determine candidate areas that can be independently switched by controllable switches and are isolated from fault zones.
[0047] When both critical loads and ordinary loads with high start-up impact exist within a candidate area, the control device can divide the candidate area into critical load sub-island segments and ordinary load sub-island segments. For example, if a communication equipment room and a large air conditioner are located on the same branch, and the switch or contactor can achieve branch switching, the communication equipment room will be preferentially formed into an independent sub-island segment; if it cannot be switched independently, the branch needs to be evaluated as a whole, taking into account the start-up impact and energy storage support margin. When a candidate area lacks a network support path, the switch status is uncontrollable, or the fault isolation status is unclear, the control device marks it as a temporarily deferred recovery island segment.
[0048] In step S105, the control device calculates the startup impact, reactive power demand, frequency drop risk, and energy storage support margin for each recoverable island segment. (Refer to...) Figure 5 The starting impact SIj characterizes the short-term capacity occupancy of the grid inverter when the j-th recoverable island segment Ij is put into operation. SIj can be expressed as SIj=(Σxk×Pstart_k+Σxm×Pinrush_m) / Sgfm_j. Here, xk indicates whether the corresponding load belongs to the candidate input set, xm indicates whether the corresponding impulsive load belongs to the candidate input set, Pstart_k represents the equivalent active power impact of the load startup, Pinrush_m represents the transient impact power of the impulsive load, and Sgfm_j represents the corrected capacity of the grid inverter supporting that island segment. The corrected capacity of the grid inverter can be determined by the rated capacity, short-term overload capacity, temperature status, and alarm status.
[0049] Reactive power demand RQj is used to characterize the voltage support capability required after an island segment is put into operation. RQj can be expressed as RQj=Σxk×Qstart_k+Qline_j+Qmag_j-Qlocal_j. Here, Qstart_k represents the reactive power demand for load startup, Qline_j represents the reactive power consumption of the line, Qmag_j represents the reactive power of transformer excitation, and Qlocal_j represents the locally available reactive power support. For island segments containing motors, water pumps, cold storage compressors, or large air conditioners, Qstart_k is usually higher. The control device can set delayed or segmented operation conditions for such island segments based on the reactive power support capability.
[0050] Frequency drop risk (FRj) characterizes the impact of active power imbalance caused by island segment commissioning on the microgrid frequency. FRj can be expressed as FRj = ΔPj / Preserve_j. Here, ΔPj represents the active power imbalance caused by island segment commissioning, and Preserve_j represents the active power regulation margin of energy storage and grid-connected inverters within the allowable frequency deviation range. Energy storage support margin (SMj) characterizes the support capability of energy storage in both power and energy dimensions. SMj can be expressed as SMj = min(Pess_avail / Pstep_j, Eess_avail / Esupport_j). Here, Pess_avail represents the available discharge power of energy storage, Pstep_j represents the expected additional power in this step, Eess_avail represents the available energy after deducting minimum state of charge and reserve, and Esupport_j represents the energy required by the island segment within the preset support duration.
[0051] In step S106, the control device generates a black start sequence based on the load recovery fingerprint and island segment risk calculation results. This black start sequence includes energy storage voltage building up, critical load recovery, renewable energy integration, phased commissioning of ordinary loads, and grid connection verification. The energy storage voltage building up step is located at the beginning of the sequence. The control device selects an energy storage system whose state of charge, available discharge power, inverter alarm status, and switching status all meet the requirements as the voltage building up resource, and controls the corresponding grid-type inverter to enter voltage source control or equivalent grid control mode. After voltage building up is completed, the control device collects bus voltage, bus frequency, inverter current, and protection alarm status to confirm that the microgrid is ready for load commissioning.
[0052] The critical load restoration procedure is executed after the energy storage pressure build-up verification is passed. The control unit selects the critical load restoration targets based on the load restoration priority value PRk, critical load level Gradek, and the island segment SIj, RQj, FRj, and SMj. For communication, fire protection, security, medical, or production control loads, priority is given to activation if their startup impact is low and the support margin of their island segment meets the requirements. For loads whose critical load level meets the priority restoration conditions and whose cold load startup current Icold_k is greater than Ith or whose cold load impact multiple Kcold_k is greater than Kth, the control unit can set delayed activation, segmented activation, power-limited activation, or ramp-up activation conditions to restore them without exceeding the short-term withstand capacity of the grid inverter.
[0053] The integration of new energy sources is executed after critical loads are put into operation and the bus voltage and frequency are stable. The control device issues power and slope limiting commands to the new energy units, enabling them to gradually provide active power or reactive power support to the microgrid. After the new energy sources are integrated, the control device updates Preserve_j, Qlocal_j, and SMj based on the actual output. If the output of the new energy sources is lower than the predicted value or the fluctuation exceeds the preset threshold, the control device reduces the capacity of subsequent batches of normal loads; if the stable output of the new energy sources increases, the capacity limit of the normal load recovery batch can be appropriately increased.
[0054] The phased activation of ordinary loads is executed after the integration of new energy sources or the stabilization of critical loads. The control device divides ordinary loads into multiple activation batches based on load recovery priority, the startup impact of the island segment, reactive power demand, frequency drop risk, and energy storage support margin. The total startup impact of each activation batch does not exceed the short-term withstand capacity of the grid inverter, the expected reactive power demand of each activation batch does not exceed the local reactive power support capacity, and the energy required by each activation batch within the preset support period does not exceed the available energy of the energy storage. Through these batch constraints, the ordinary load recovery process can be matched with the energy storage support capacity and the grid inverter capacity.
[0055] The grid connection verification step is performed after the external power grid is restored. The control device collects the voltage amplitude, frequency, phase angle, synchronous voltage difference, power exchange direction, and grid connection switch status from both the microgrid side and the external power grid side. When the voltage amplitude difference, frequency difference, phase angle difference, and predicted power exchange value meet the grid connection conditions, a grid connection execution command is generated; when the grid connection conditions are not met, the control device maintains islanded operation and continues to maintain the stable operation of the restored loads and new energy units according to the current black start sequence.
[0056] Reference Figure 6 The sequence generation device first sends voltage-building commands to the energy storage and grid-connected inverters in terms of timing. After the no-load voltage, no-load frequency, and inverter current verifications are passed, it enters the load recovery phase. Subsequently, the grid-connected inverter side performs key load connection and verification to the load switch side. The sequence generation device then issues slope-limiting connection commands to the renewable energy units, enabling the renewable energy output to be connected to the microgrid in a controlled manner. The batch connection and feedback of ordinary loads are returned to the sequence generation device from the load switch side to determine whether to continue execution or trigger reordering. After the external grid is restored, the sequence generation device performs synchronization grid connection verification and generates grid connection execution commands based on the voltage, frequency, and phase angle difference between the microgrid side and the external grid side.
[0057] In step S107, the control device collects feedback data after executing each black-start step in the black-start sequence generated in step S106. The feedback data includes bus voltage, bus frequency, grid inverter current, energy storage output power, energy storage state of charge, renewable energy output, and protection alarm status. For critical load restoration and ordinary load connection steps, the corresponding branch current, branch active power, branch reactive power, and switch position can also be collected. After collecting the feedback data, the control device determines whether the current step meets the conditions for continuing execution.
[0058] In step S108, the control device verifies or rearranges the subsequent sequence based on the feedback data. When the feedback data meets the constraints of voltage, frequency, inverter current, energy storage state of charge, and protection alarm, the control device executes the next step. If, after any step is executed, voltage exceeds the limit, frequency drops beyond the threshold, grid inverter experiences overcurrent, energy storage state of charge falls below the minimum threshold, renewable energy output fluctuations exceed the threshold, or a protection alarm occurs, the control device suspends the unexecuted steps, updates the cold load impact weight of the corresponding load, the frequency drop risk of the island segment, and the energy storage support margin, and regenerates the remaining black start sequence. If the anomaly is caused by a batch of ordinary loads, the control device sorts the loads in the most recently added batch according to PRk from smallest to largest, and prioritizes cutting off the first load in the sort that meets the interruptibility conditions; if the anomaly involves a critical load, the control device prioritizes reducing the recovery amount of ordinary loads in the same island segment or waits for the renewable energy support capacity to be updated before restoring them.
[0059] In this embodiment, steps S101 to S108 form a closed-loop recovery process. This closed-loop process ensures that the black-start sequence is not a fixed list, but is continuously adjusted based on load recovery fingerprints, recoverable island risks, and real-time execution feedback. In this way, the microgrid can generate a recovery sequence adapted to current operating conditions, taking into account changes in energy storage state of charge, grid inverter capacity, renewable energy output, and load impact characteristics.
[0060] Example 2 This embodiment, based on Embodiment 1, further explains the specific implementation methods of load recovery fingerprints and load recovery priority values. (Refer to...) Figure 3 Load recovery fingerprinting is used to convert the importance, start-up impact, reactive power demand, recovery time limit, and controllability of the load to be restored during the black start process into a computable data structure. Through this data structure, the control device can prioritize critical and ordinary loads after energy storage pressure build-up and correct the subsequent recovery sequence when abnormal feedback occurs.
[0061] Specific reference Figure 3The historical power characteristics, load type, cold load starting current, critical load level, and starting reactive power demand in the fingerprint input on the left are obtained from load profiles, metering curves, historical starting records, and operation sampling data, respectively. Figure 3 The arrows pointing from input quantities to scoring quantities indicate the mapping relationship between fields and scoring items. Among them, historical power characteristics, load type and critical load level mainly participate in the level scoring, continuous power supply scoring and recovery time limit scoring, while cold load starting current and starting reactive power demand mainly participate in cold start risk scoring, reactive power risk scoring and ramp risk scoring. Figure 3 The load recovery priority value PRk on the right is not a separate output sorting result, but is output together with the load recovery fingerprint LFk; LFk stores the input field and the scoring field, and PRk is used for subsequent critical load recovery sorting, ordinary load batch division and reordering after execution anomalies.
[0062] In this embodiment, the control device can establish a load profile based on load identifiers. Load identifiers can correspond to individual electrical equipment, user-side metering points, feeder branches, building branches, or independently switchable load groups. The load profile includes rated power, rated voltage, load type, historical electricity consumption curves, critical load level, cold load starting current, starting reactive power demand, allowable interruption duration, interruptibility attributes, switch control method, and the most recent start-up record. For loads where the cold load starting current cannot be directly obtained, it can be estimated based on the load type, rated power, and peak current during historical start-ups.
[0063] Historical power characteristics Pk_hist can be extracted from historical power consumption curves at multiple time scales. The control device can read the average power, maximum power, minimum power, power fluctuation amplitude, power at the same time on similar days, and average power of similar loads within the operating window before the power outage, and normalize them into historical power characteristics. For production control loads, communication loads, or fire and security loads, historical power characteristics are mainly used to estimate the continuous power demand after restoration; for air conditioning cooling loads, motor loads, and charging loads, historical power characteristics are also used to determine whether the load was high before the power outage, thereby correcting for cold start impact.
[0064] Load type (Typek) is used to determine the basic values for cold start impact, reactive power demand, and ramp recovery capability. Motor loads typically have high starting current and reactive power demand upon activation, and the control unit assigns higher ColdImpactScorek and ReactiveScorek to these loads. Constant-power electronic loads may rapidly absorb power after voltage recovery, and the control unit can determine RampRiskScorek based on their power supply type and historical power change rate. Lighting loads generally have low start-up impact and can recover earlier when energy storage support margins are sufficient. Air conditioning / refrigeration loads are strongly correlated with the duration of the outage; the longer the outage, the higher the impact caused by compressor startup and temperature control recovery. Charging loads can be assigned lower or higher priority based on interruptibility attributes and recovery requirements. Assurance loads are assigned a higher score based on their power supply continuity requirements.
[0065] The cold load starting current Icold_k can be determined from actual measurements, historical starting records, or estimated values. If the load has branch current sampling capability, the control device can read the current peak value during historical starting periods and use the ratio of this peak value to the rated current as the cold load impact factor Kcold_k. If historical starting records are unavailable, the control device can determine a default impact factor based on the load type and rated power. For example, a higher default impact factor can be used for motor loads, a lower default impact factor can be used for lighting loads, and the default impact factor for air conditioning loads can be adjusted based on the duration of the power outage. The above default values are not fixed and can be updated in practice based on the operating records of the transformer substation.
[0066] The starting reactive power demand, Qstart_k, can be determined based on load type, power factor, starting method, and historical voltage drop records. For motor loads, the starting reactive power demand can be estimated based on rated capacity, starting current multiple, and starting power factor. For loads equipped with frequency converters or soft starters, the control device can reduce their starting reactive power demand score. For loads that historically caused significant voltage drops upon startup, the control device can increase their ReactiveScorek, ensuring they are scheduled for recovery during a phase with sufficient reactive power support in subsequent black start sequences.
[0067] The critical load level (Gradek) reflects the importance of power supply for load restoration. Control devices can classify critical load levels into four categories: Level 1 (ensuring basic needs), Level 2 (ensuring basic needs), Level 3 (critical production), and Level 4 (general needs), or use continuous scoring. Communication, fire protection, security, medical, emergency lighting, and production control loads can be set to higher critical load levels. General office lighting, general air conditioning, landscape lighting, and loads with deferred charging can be set to lower levels. The higher the critical load level, the higher the GradeScore, but this score does not directly equate to immediate power-on conditions. If the cold start impact or reactive power demand exceeds the current support capacity, the control device can still restore power through phased power-on, delayed power-on, or waiting for renewable energy to be integrated.
[0068] The interruptibility attribute `Interruptk` indicates whether a load is allowed to be disconnected again or have its power reduced after recovery. `Interruptk` can take a normalized value from 0 to 1, and a preset interruptibility threshold `Int_th` is used to determine whether a load meets the interruptibility criteria. For communication equipment rooms, fire control, critical production control, and medical support loads, `Interruptk` is typically less than `Int_th`, meaning it should not be arbitrarily disconnected after recovery. For general lighting, general air conditioning, landscape lighting, and charging loads, `Interruptk` is typically greater than or equal to `Int_th`, allowing them to participate in disconnection or load reduction when feedback anomalies occur. The control device can use the interruptibility attribute to calculate `ContinuityScorek` and anomaly rollback strategies, ensuring that the recovery sequence considers both the order of activation and the order of rollback.
[0069] The outage duration Toff_k is used to correct for cold load surges and recovery time. For air conditioning, cold storage, water pumps, and some production equipment, the longer the outage duration, the higher the startup surge, recovery power ramp-up, and reactive power demand upon restarting. The control unit can map Toff_k to an outage time correction factor and apply it to ColdImpactScorek and RampRiskScorek. For communication, security, and production control loads, the outage duration can also be used to determine CriticalTimeScorek; the closer the outage is to the upper limit of the allowable interruption duration, the higher the CriticalTimeScorek.
[0070] The ramp recovery capability (Rampk) indicates whether a load can recover by gradually increasing power. For loads with inverters, soft starters, charging power regulation interfaces, or building control interfaces, Rampk can be higher, indicating that the load can be engaged with a small initial power and gradually increase power. For direct-start motors or non-adjustable electronic loads, Rampk is lower, indicating that the engagement process is difficult to mitigate the impact. The lower the Rampk, the higher the RampRiskScorek. The control device can prioritize loads with ramp recovery capability when generating the recovery sequence to reduce single-step power surges.
[0071] When calculating the load restoration priority value PRk, the control device first normalizes each score to the same numerical range. GradeScorek is determined by the critical load level; ContinuityScorek by interruptibility attributes and continuous power supply demand; CriticalTimeScorek by the allowable interruption duration and outage duration; ColdImpactScorek by the cold load initiation current, cold load surge multiple, and outage duration; ReactiveScorek by the initiation reactive power demand and historical voltage drop records; and RampRiskScorek by the allowable ramp recovery capability and power ramp-up characteristics. After normalization, the control device calculates the load restoration priority value according to PRk = a1 × GradeScorek + a2 × ContinuityScorek + a3 × CriticalTimeScorek - a4 × ColdImpactScorek - a5 × ReactiveScorek - a6 × RampRiskScorek.
[0072] In one implementation, a1 to a6 can be set according to the transformer substation type and recovery strategy. For transformer substations requiring guaranteed power supply, a1, a2, and a3 can be increased to prioritize the recovery of critical loads and continuously supplied loads when support capacity constraints are met. For transformer substations with small energy storage capacity, a4, a5, and a6 can be increased to postpone the recovery of loads with large cold start impacts, high reactive power demand, or poor slope recovery capabilities. For microgrids in industrial parks with a high proportion of renewable energy, the impact of a4 and a5 can be dynamically reduced after renewable energy is integrated, allowing the batch of ordinary loads to expand as support capacity increases. The weighting parameters can be preset or modified based on historical black start execution records.
[0073] Load recovery fingerprints can also be used for abnormal rollback and reordering. When a batch of loads causes a frequency drop exceeding a threshold after being put into operation, the control device can identify loads with higher ColdImpactScorek or RampRiskScorek within that batch and increase their risk weight in subsequent calculations. When a load is put into operation without causing significant voltage or frequency disturbances, the control device can retain its current fingerprint parameters or appropriately reduce its risk score. When a load triggers protection alarms during multiple recovery processes, the control device can mark it as a high-risk load and schedule its recovery in subsequent black-start sequences after the integration of new energy sources or after manual confirmation.
[0074] In a specific example, a microgrid in a certain industrial park includes a communication equipment room, a fire pump control cabinet, general office lighting, air conditioning chiller units, and charging piles. The communication equipment room has a high critical load level, low cold start impact, and low interruptibility attribute; therefore, its GradeScorek and ContinuityScorek are high, while its ColdImpactScorek is low, resulting in a high load recovery priority. The fire pump control cabinet has a high critical load level, but its motor starting impact and starting reactive power demand are high; therefore, its recovery priority is suppressed by ColdImpactScorek and ReactiveScorek. The control device can schedule it after the communication equipment room and set delayed commissioning or soft-start conditions. The cold impacts of the air conditioning chiller units increase when the power outage duration is long, and they are usually not restored during the initial voltage build-up phase. If the charging piles have power regulation capabilities, their Rampk is high, and they can be commissioned in a power-limited manner during normal load phases; if they do not have power regulation capabilities, their commissioning can be delayed.
[0075] Through the load recovery fingerprinting process in this embodiment, the control device can simultaneously incorporate load importance and startup risk into the prioritization process. This process avoids premature activation of high-impact loads due to recovery based solely on critical levels, and also avoids delaying important loads due to recovery based solely on load power. The load recovery fingerprint also provides a unified data foundation for subsequent risk calculation of recoverable island segments, phased activation of ordinary loads, and anomaly reordering.
[0076] Example 3 This embodiment, based on Embodiments 1 and 2, further explains the specific implementation methods for the division of recoverable island segments, island segment risk calculation, and recovery level determination. (Refer to...) Figure 4 and Figure 5 A recoverable island segment is used to represent a local power supply area that can be demarcated by a controllable switch, isolated from the fault area, and supported by energy storage and grid-connected inverters after an external power grid failure. Island segment risk calculation is used to determine whether this local power supply area is suitable for recovery at the current stage.
[0077] Before dividing the recoverable island segments, the control device first establishes a microgrid topology model. This topology model can include buses, transformers, feeders, sectionalizing switches, tie switches, branch switches, energy storage access points, grid-connected inverter access points, renewable energy access points, critical load access points, general load access points, and fault isolation zones. Nodes in the topology model represent electrical connection points, switches, or equipment, and edges represent lines, feeders, or branches. Each edge can record line capacity, line impedance, length, protection status, and whether it is in a recoverable path. Each node can record switch status, voltage status, communication status, and whether it is controllable.
[0078] After detecting a power outage in the external power grid, the control device updates the topology model based on the fault location results. If a branch is marked as a faulty branch by protection operation or manual confirmation, the control device marks that branch and its downstream area as an unrecoverable area. If the status of a switch cannot be confirmed, the control device can mark the area related to that switch as a delayed recovery area to avoid performing recovery when the topology status is uncertain. If an energy storage access point or a grid-connected inverter access point is in an alarm state, the control device reduces its support capacity for downstream island segments or marks the relevant support path as unavailable.
[0079] After the topology model is updated, the control device searches for candidate areas electrically isolated from the fault area, using the busbar, sectionalizing switch, tie switch, and branch switch as boundaries. Candidate areas should be able to form an activation boundary with a controllable switch, and after activation, they should be connectable to the energy storage system or grid-connected inverter via at least one support path. Candidate areas should also have line and transformer capacities no less than the expected recovery capacity. If there are no critical loads within a candidate area and the ordinary load capacity is large, the control device can use this candidate area as an ordinary load recovery area and restore it in batches. If there are critical loads within a candidate area, the control device prioritizes determining whether the critical load can be isolated into a sub-island segment.
[0080] In one partitioning method, the control device can first search for controllable switch boundaries upstream from the critical load access point and search for switchable branches downstream to form a critical load sub-island segment. If the critical load sub-island segment only contains critical loads and necessary auxiliary loads, then the sub-island segment can be prioritized for restoration. If the sub-island segment also contains large motors, air conditioning chiller units, or charging loads, the control device determines whether these high starting impact loads have independent switches or control interfaces; if they do, they are removed from the critical load sub-island segment and assigned to subsequent ordinary load batches; if they do not, the critical load sub-island segment needs to undergo starting impact and reactive power demand verification before restoration.
[0081] In another partitioning method, the control unit can form recoverable island segments according to feeder sections. For each feeder segment, the control unit determines whether its upstream switch is controllable, whether its downstream contains a fault area, whether it has an energy storage support path, whether it contains renewable energy access points, and whether it contains critical loads. If the upstream of the feeder segment is controllable and the downstream is fault-free, and the energy storage support path meets the capacity requirements, then a recoverable island segment is formed. If there are many renewable energy access points within the feeder segment, the control unit can designate the area where the renewable energy access points are located as a sub-area to be connected, and execute the renewable energy connection after energy storage voltage buildup and critical load recovery.
[0082] Specific reference Figure 4 The energy storage and grid inverter are located on the support side of the microgrid bus, and the sectionalizing switch S1, sectionalizing switch S2 and tie switch S3 form the connection boundaries of different branches. Figure 4 Island segment I1 corresponds to communication and security loads, island segment I2 corresponds to production control loads, and island segment I3 corresponds to general office loads. The new energy unit is connected to the busbar by a dashed line, indicating that it will be incorporated into the current recovery cycle after energy storage pressure building and critical load recovery. The fault isolation zone is associated with island segment I3 by a dashed line, indicating that although this area is located downstream of the same branch, it will not enter the current recovery cycle after fault isolation is completed. The control device... Figure 4 The support paths, switch boundaries, and fault isolation boundaries shown indicate that areas that can be directly switched and have network support paths are identified as candidate island segments, while areas lacking controllable boundaries or located downstream of a fault are marked as temporarily unrecoverable or unrecoverable.
[0083] After forming a recoverable island segment, the control device calculates the startup impact SIj for each segment. The startup impact calculation includes not only the stable operating power of the load within the island segment but also the cold load startup current and motor transient impact that may occur at the moment of connection. For the j-th island segment Ij, the startup impact SIj can be expressed as SIj=(Σxk×Pstart_k+Σxm×Pinrush_m) / Sgfm_j. Pstart_k can be obtained by correcting for the load's rated power, the cold load impact multiple, and the outage duration. Pinrush_m can be calculated from the historical peak current of motor-type loads, compressor loads, or other impact-type loads. Sgfm_j represents the corrected capacity of the grid-connected inverter capable of supporting this island segment. If the grid-connected inverter is in a high-temperature, current-limiting, or alarm state, Sgfm_j should be lower than its rated capacity.
[0084] The control unit also calculates the reactive power demand RQj for each island segment. The reactive power demand for an island segment includes load start-up reactive power, line reactive power consumption, and transformer excitation reactive power, minus the available local reactive power support. RQj can be expressed as RQj = Σxk × Qstart_k + Qline_j + Qmag_j - Qlocal_j. For island segments with a large number of motor loads, Qstart_k is larger; for island segments with longer lines or transformers connected under no-load conditions, Qline_j and Qmag_j are larger; for island segments with renewable energy inverters or reactive power compensation devices, Qlocal_j can be increased. If RQj exceeds the reactive power threshold, the control unit can choose to postpone the restoration of that island segment, reduce the capacity of ordinary loads connected within that island segment, or restore it only after renewable energy is integrated.
[0085] Frequency drop risk (FRj) is used to determine whether energy storage and grid-connected inverters can compensate for active power imbalances within allowable frequency deviations after the island segment is put into operation. FRj can be expressed as FRj = ΔPj / Preserve_j. ΔPj is jointly determined by the increased active power demand caused by the island segment's operation, the power ramp-up during cold load recovery, and changes in renewable energy output. Preserve_j is jointly determined by the available discharge power of energy storage, the active power regulation capability of the grid-connected inverter, and the reserved reserve. If FRj is high, it indicates that the island segment's operation may cause a frequency drop. In this case, the control device can reduce the single-operation capacity, increase the operation interval, or wait for the renewable energy support capability to improve.
[0086] The energy storage support margin SMj is used to determine whether the energy storage system can support the island segment in terms of both power and energy. SMj can be expressed as SMj = min(Pess_avail / Pstep_j, Eess_avail / Esupport_j). Pess_avail represents the current available discharge power of the energy storage, Pstep_j represents the expected additional power in this step, Eess_avail represents the available energy after deducting the minimum state of charge and reserve, and Esupport_j represents the energy required for the island segment within the preset support duration. If SMj is greater than the support margin threshold, it means that the energy storage has the support conditions in both power and energy dimensions; if SMj is less than or equal to the support margin threshold, the control device can postpone the restoration of the island segment or reduce the capacity of ordinary loads in the island segment.
[0087] After calculating SIj, RQj, FRj, and SMj, the control unit determines the recovery level for each recoverable island segment. If SIj is less than the start-up impact threshold, RQj is less than the reactive power threshold, FRj is less than the frequency risk threshold, and SMj is greater than the support margin threshold, then the island segment is determined to be currently recoverable. Currently recoverable island segments can be restored according to load recovery priority after energy storage pressure building and necessary verification. If an island segment contains critical loads and SMj meets support requirements, but SIj or RQj is slightly higher than the threshold, then the island segment is determined to be a split or power-limited recovery island segment. For such island segments, the control unit prioritizes restoring critical load branches and postpones the introduction of ordinary loads or high-impact loads. If SMj is insufficient or FRj exceeds the threshold, then the island segment is determined to be a temporarily deferred recovery island segment and will be reassessed after the integration of new energy sources or other load reductions.
[0088] Specific reference Figure 5 The startup impact threshold SIj, reactive power demand RQj, frequency drop risk FRj, and energy storage support margin SMj are input from the top of the graph to the threshold and constraint determination unit. This determination unit compares the startup impact threshold, reactive power threshold, frequency risk threshold, and support margin threshold simultaneously, rather than making a recovery decision based solely on a single load power. Figure 5 If all paths meet the current recoverable result, it means that the island segment can enter the current black start sequence; if a critical load but partially overloaded path corresponds to a split or power-limited recovery result, it means that the critical load branch is restored first and the high-impact ordinary load is postponed; if the support margin is insufficient, the recovery result is postponed until the new energy is incorporated, it means that the risk indicators of the island segment will be recalculated after the new energy slope is incorporated or the low-priority load is reduced.
[0089] Recovery level determination is not a one-time result. Whenever the state of charge of energy storage, renewable energy output, load connection status, or grid inverter capacity changes, the control device can recalculate SIj, RQj, FRj, and SMj. For example, after the incorporation of renewable energy units with limited slope, Qlocal_j and Preserve_j may increase, and some island segments that were originally temporarily deferred for recovery can be converted to recoverable island segments. Furthermore, after a batch of ordinary loads fails to connect and is disconnected, the control device can lower the recovery level of the island segment containing similar loads, or split these loads into smaller batches.
[0090] In a specific example, a microgrid in a certain industrial park includes an energy storage access bus, a communication equipment room branch, a production control branch, an office air conditioning branch, and a photovoltaic access branch. After an external power grid failure, the control device forms three recoverable island segments based on the topology switch status. Island segment I1 includes the communication equipment room and security system, with low startup impact, low reactive power demand, and high energy storage support margin, and is determined to be the currently recoverable island segment. Island segment I2 includes the production control system and a water pump, with a high critical load level, but high startup impact and reactive power demand, and is determined to be a split or power-limited recovery island segment. The control device first restores the production control system and then postpones the restoration of the water pump. Island segment I3 includes office air conditioning and charging loads, with a large general load capacity and insufficient energy storage support margin, and is determined to be a temporarily deferred recovery island segment, to be reassessed after the photovoltaic system is connected and its output stabilizes.
[0091] Through the recoverable island segment division and risk calculation in this embodiment, the black start sequence generation object is expanded from a single load to island segments with electrical boundaries and support paths. The control device can determine the impact of each area's activation on voltage, frequency, inverter capacity, and energy storage capacity before restoration, and generate subsequent sequences based on current recoverability, splitting or limited power restoration, or delayed restoration levels. This process helps avoid activating high-impact branches solely based on load importance and also facilitates timely expansion of the recoverable range after the integration of new energy sources.
[0092] Example 4 This embodiment provides a device for automatically generating a black startup sequence for a microgrid in a transformer area. (Refer to...) Figure 7 The device includes an operation data interface 100, a power failure identification and status acquisition module 110, a load recovery fingerprint generation module 120, a recoverable island segment division module 130, an island segment risk assessment module 140, a start-up sequence generation module 150, an execution verification and rearrangement module 160, a human-machine interaction recording module 170, and an execution command interface 180. This device can be deployed in a smart converged terminal in a distribution area, a microgrid energy management system, an edge computing gateway, or an energy storage controller, or it can be implemented by a processor, memory, communication interface, and program instructions stored in the memory. The operation data interface 100 is used to connect to smart meters, energy storage management systems, grid-type inverter controllers, distributed power controllers, distribution automation terminals, controllable switch controllers, and human-machine interaction terminals, enabling the device to obtain the operation data required for black-start sequence generation and to issue control commands to field execution equipment.
[0093] In its specific implementation, the operational data interface 100 may include a metering data access unit, an energy storage status access unit, an inverter status access unit, a topology status access unit, and an execution feedback access unit. The metering data access unit receives voltage, current, active power, reactive power, and historical power consumption curves for each load branch. The energy storage status access unit receives the energy storage state of charge, available discharge power, available energy, minimum reserved state of charge, fault alarms, and permissible charge / discharge status. The inverter status access unit receives the rated capacity, short-time overload capacity, operating mode, output current, bus voltage, frequency, and alarm status of the grid-connected inverter. The topology status access unit receives the status of the bus, feeders, sectionalizing switches, tie switches, branch switches, fault isolation boundaries, and renewable energy access points. The execution feedback access unit recovers voltage, frequency, inverter current, energy storage state of charge, renewable energy output, and protection alarm information after the black start procedure is executed. The runtime data interface 100 can write the above data into the real-time data area, historical curve area, topology status area, and device constraint area according to the device identifier and timestamp, for subsequent modules to call.
[0094] The power failure identification and status acquisition module 110 is used to determine whether the external power grid has lost power and to generate the initial state required for black start calculation after the power failure. In its specific implementation, this module may include a power grid status discrimination unit, a fault isolation confirmation unit, a data synchronization unit, and an initial state generation unit. The power grid status discrimination unit reads the grid connection point voltage, grid connection point frequency, grid connection switch position, protection action signals, and upstream power grid communication status. When the grid connection point voltage is continuously lower than the preset power failure threshold, or when the grid connection switch is in the open state and there is no effective voltage on the external power grid side, it generates an external power grid power failure flag. The fault isolation confirmation unit determines the unrecoverable area based on the protection action record, fault location results, and switch status, and writes the faulty branch, the branch with unknown status, and the locked switch into the topology status area. The data synchronization unit uses the black start trigger time as a reference to time-align the metering data, energy storage status, inverter status, topology status, and new energy status. The initial state generation unit generates a black start initial state table based on the synchronized data. This initial state table includes available energy storage resources, available grid resources, controllable switch set, recoverable load set, temporarily deferred recovery load set, and fault isolation area.
[0095] The load restoration fingerprint generation module 120 is used to generate load restoration fingerprints for the loads to be restored based on the initial state table and load profile. In its specific implementation, this module may include a load profile reading unit, a historical curve processing unit, a cold start impact estimation unit, a critical level processing unit, a reactive power demand estimation unit, and a priority value calculation unit. The load profile reading unit reads the rated power, load type, branch, switch control method, critical load level, interruptibility attribute, and allowable interruption duration according to the load identifier. The historical curve processing unit extracts the pre-outage window power, similar daily power, average power during the same period, and power fluctuation amplitude from historical power consumption curves, forming a historical power characteristic Pk_hist. The cold start impact estimation unit determines the cold load starting current Icold_k and the cold load impact multiple Kcold_k based on the load type, rated power, outage duration, and historical starting peak value. The reactive power demand estimation unit determines the starting reactive power demand Qstart_k based on the load type, power factor, starting method, and historical voltage drop records. The critical level processing unit converts the critical load level, continuous power supply demand, interruptibility attribute, and allowable interruption duration into corresponding scores. The priority calculation unit generates a load recovery fingerprint LFk based on the above data, and calculates the load recovery priority value PRk according to PRk=a1×GradeScorek+a2×ContinuityScorek+a3×CriticalTimeScorek-a4×ColdImpactScorek-a5×ReactiveScorek-a6×RampRiskScorek. This module can also correct the cold start impact score, reactive power risk score, and ramp risk score of the load based on the historical execution results saved by the human-machine interaction recording module 170.
[0096] The recoverable island segmentation module 130 is used to form recoverable island segments based on topology status and supporting resources. In its implementation, this module may include a topology model construction unit, a support path search unit, a candidate region generation unit, a sub-island segment splitting unit, and an island segment status marking unit. The topology model construction unit converts buses, transformers, feeders, sectionalizing switches, tie switches, branch switches, energy storage access points, grid-type inverter access points, new energy access points, critical load access points, and fault isolation zones into an electrical topology diagram. The support path search unit starts from the energy storage access point or grid-type inverter access point and searches for power supply paths capable of supporting load recovery along controllable switches and available lines. The candidate region generation unit forms candidate recovery regions that can be independently switched based on controllable switch boundaries, fault isolation boundaries, and load distribution. When critical loads and high-start-impact ordinary loads exist simultaneously within the same candidate region, the sub-island segment splitting unit splits the candidate region into critical load sub-island segments and ordinary load sub-island segments according to branch switches, contactors, building control interfaces, or equipment control interfaces. The island segment status marking unit marks areas lacking support paths, with uncontrollable switch boundaries, or with unclear fault isolation status as temporarily delayed recovery areas, and areas with support paths and controllable boundaries as recoverable island segments.
[0097] The island segment risk assessment module 140 is used to calculate the startup risk and support capacity of each recoverable island segment output by the recoverable island segment division module 130. In its specific implementation, this module may include a startup impact calculation unit, a reactive power demand calculation unit, a frequency risk calculation unit, an energy storage support margin calculation unit, and a recovery level determination unit. The startup impact calculation unit reads the cold load startup current, startup equivalent active power impact, and transient power of the impact load for each load within the island segment, and calculates the startup impact SIj in conjunction with the corrected capacity of the grid-connected inverter. The reactive power demand calculation unit calculates the reactive power demand RQj based on the load startup reactive power demand, line reactive power consumption, transformer excitation reactive power, and local reactive power support. The frequency risk calculation unit calculates the frequency drop risk FRj based on the active power imbalance caused by the island segment's commissioning and the active power regulation margin of the energy storage and grid-connected inverter within the allowable frequency deviation range. The energy storage support margin calculation unit calculates the energy storage support margin SMj based on the available discharge power of the energy storage, the available energy of the energy storage, the step-by-step additional power, and the preset support duration. The recovery level determination unit compares SIj, RQj, FRj and SMj with the corresponding thresholds, determines the island segment as currently recoverable, split or power-limited recovery, temporarily suspended recovery or unrecoverable, and sends the determination result to the startup sequence generation module 150.
[0098] The startup sequence generation module 150 is used to convert load recovery fingerprints, recoverable island segments, and island segment risk assessment results into executable black start sequences. In its specific implementation, this module may include a voltage build-up step generation unit, a critical load step generation unit, a renewable energy integration step generation unit, a general load batch generation unit, a grid connection verification step generation unit, and a sequence constraint check unit. The voltage build-up step generation unit generates energy storage voltage build-up steps based on the energy storage state of charge, available energy storage discharge power, grid-connected inverter correction capacity, and switching status. The critical load step generation unit generates the critical load activation sequence based on the critical load level, load recovery priority value, and island segment recovery level, and sets delayed activation, segmented activation, or ramp activation conditions for critical loads with a cold load start-up current Icold_k greater than Ith or a cold load impact multiple Kcold_k greater than Kth. The renewable energy integration step generation unit generates renewable energy power-limited and slope-limited integration steps after the bus voltage, frequency, and phase have stabilized. The ordinary load batch generation unit generates ordinary load input batches based on load recovery priority, island segment startup impact, reactive power demand, frequency drop risk, and energy storage support margin, ensuring that each batch meets the short-time capacity, reactive power support capability, and energy storage energy constraints of the grid-connected inverter. After the external grid recovers, the grid connection verification step generation unit generates synchronous grid connection verification steps based on the voltage amplitude difference, frequency difference, phase angle difference, and power exchange prediction results between the microgrid side and the external grid side. The sequence constraint checking unit checks whether the preconditions, verification conditions, and failure rollback actions between adjacent steps are complete, avoiding the generation of recovery steps lacking verification conditions or unable to roll back.
[0099] The execution verification and reordering module 160 is used to determine whether to continue execution, roll back execution, or regenerate the remaining sequence based on the feedback data after the black start step. In its specific implementation, this module may include a feedback acquisition unit, an over-limit judgment unit, a cause location unit, a rollback processing unit, and a reordering trigger unit. The feedback acquisition unit reads the bus voltage, bus frequency, grid inverter current, energy storage output power, energy storage state of charge, renewable energy output, branch current, and protection alarms after each execution step through the running data interface 100. The over-limit judgment unit compares the feedback data with preset verification conditions. The cause location unit determines, based on the time of the over-limit occurrence, the most recently added load, the load recovery fingerprint, and the island segment risk indicators, that the anomaly is more likely to originate from cold start impact, insufficient reactive power, insufficient frequency support, insufficient energy storage support, or renewable energy fluctuations. When an anomaly is caused by a batch of ordinary loads, the rollback processing unit sorts the loads in the most recently added batch that meet the interruptible conditions according to PRk from smallest to largest, and cuts off the load at the top of the sort. When an anomaly is caused by a critical load, it prioritizes reducing the amount of ordinary load recovery in the same island segment or suspending the addition of subsequent ordinary loads. The rearrangement triggering unit updates the risk weight of the corresponding load, the FRj and SMj of the corresponding island segment according to the cause of the anomaly, and triggers the startup sequence generation module 150 to regenerate the remaining black startup sequence.
[0100] The human-machine interaction recording module 170 is used to display the black start sequence, risk indicators, execution status, and reordering results, and to save the black start execution data. In its specific implementation, this module may include a status display unit, a manual confirmation unit, a log storage unit, and a fingerprint correction unit. The status display unit displays the current microgrid operating status, executed steps, pending steps, recoverable island segment level, SIj, RQj, FRj, SMj, energy storage state of charge, grid inverter current, and renewable energy output. The manual confirmation unit is used to receive confirmation instructions from dispatchers for steps requiring manual confirmation, such as the connection of high-risk critical loads, recovery of areas with uncertain fault isolation status, or simultaneous grid connection. The log storage unit records the execution object, execution time, preconditions, feedback indicators, failure reasons, rollback actions, and reordering results for each black start step. The fingerprint correction unit corrects the load recovery fingerprint based on historical logs. For example, if a load causes frequency drops after multiple connections, the ColdImpactScorek or RampRiskScorek of that load is increased; if the feedback of a load stabilizes after connection, the risk score of that load is maintained or decreased.
[0101] The execution command interface 180 is used to convert the steps generated by the startup sequence generation module 150 into control commands executable by field devices, and returns the execution results to the execution verification and rearrangement module 160. In specific implementations, the execution command interface 180 may include an energy storage voltage building command unit, a switch-on command unit, a renewable energy integration command unit, a load batch switching command unit, and a grid connection execution command unit. The energy storage voltage building command unit sends voltage building control commands to the energy storage system and the grid-connected inverter. The switch-on command unit sends closing, opening, or blocking commands to the controllable switch. The renewable energy integration command unit sends power limiting, slope limiting, or reactive power support commands to the renewable energy units. The load batch switching command unit controls the connection of load branches according to the order determined by the ordinary load batch generation unit. After the grid connection verification is passed, the grid connection execution command unit sends a grid connection execution command to the grid connection switch or synchronizing device.
[0102] In this embodiment, the operation data interface 100 provides operation data to the power failure identification and status acquisition module 110. The power failure identification and status acquisition module 110 outputs the initial state of the black start. The load recovery fingerprint generation module 120 generates a load recovery fingerprint based on the initial state. The recoverable island segment division module 130 generates recoverable island segments. The island segment risk assessment module 140 calculates the island segment risk index and determines the recovery level. The start sequence generation module 150 forms a black start sequence. The execution command interface 180 sends the black start sequence to the field equipment. The execution verification and rearrangement module 160 decides whether to continue execution, roll back, or rearrange based on the feedback results. The human-machine interaction recording module 170 records the above process and provides a basis for subsequent fingerprint correction. Through the above specific structure, the device can not only describe the functions of each module, but also complete the self-generation of the microgrid black start sequence after the external power grid fails with a clear data flow, control flow, and feedback flow.
[0103] Example 5 This embodiment, using a power outage self-recovery scenario of a campus-type microgrid, further illustrates the implementation process, data conditions, parameter settings, execution details, and comparison with existing recovery methods of the technical solution proposed in this application. The specific capacity, threshold, and load quantity in this embodiment are used to illustrate the feasible implementation methods of this application and do not constitute a limitation on the scope of protection. In actual engineering, adjustments can be made based on the transformer capacity, protection settings, energy storage configuration, and load structure.
[0104] This industrial park microgrid consists of a 10kV / 0.4kV distribution transformer, a 0.4kV microgrid bus, a grid-connected switch, an energy storage system, a grid-type energy storage converter, a photovoltaic inverter, multiple controllable branch switches, and various types of loads. The energy storage system has a rated power of 500kW and a rated energy of 1000kWh. Before the external grid failure, the energy storage system's state of charge (SOC) is 78%, with a minimum reserved SOC of 25% and a black-start standby SOC of 10%. The grid-type energy storage converter has a rated capacity of 500kVA, a short-time overload factor of 1.2, and an allowable duration of 5 seconds. The park's photovoltaic installed capacity is 350kW, with an estimated available output of 220kW at the time of power failure. The allowable grid connection ramp rate is set at 10% of the rated power per second. The allowable deviation of bus voltage is set at ±7% of the rated voltage, and the allowable deviation of frequency is set at ±0.3Hz. The instantaneous current verification threshold for grid-type energy storage converters is set at 1.15 times the rated current, and the short-time verification upper limit is set at 1.25 times the rated current with a duration not exceeding 3 seconds. The energy storage support margin threshold SMth is set at 1.2, the start-up impact threshold is set at 0.65, the reactive power demand threshold is set at 0.60, and the frequency drop risk threshold is set at 0.55.
[0105] The loads within the park include communication and security loads, fire control loads, fire pumps, production control loads, office lighting loads, air conditioning and cooling loads, and charging loads. The communication and security load has a rated power of approximately 35kW, with low starting impact and short permissible interruption time, and is designated as a primary load. The fire control load has a rated power of approximately 18kW and is designated as a primary load; the associated fire pump has a rated power of approximately 75kW, is a motor load, and has an initial cold load impact factor of 4.5, resulting in high starting reactive power requirements. The production control load has a rated power of approximately 60kW and is designated as a secondary load. The office lighting load has a rated power of approximately 80kW and low starting impact. The air conditioning and cooling load has a rated power of approximately 180kW; the risk of cold start impact and power creep increases after a power outage lasting more than 15 minutes. The charging load has a rated power of approximately 120kW, with some charging equipment supporting power-limited recovery, where the initial recovery power can be limited to 20% to 40% of the rated power.
[0106] After an external power grid failure occurs, the operation data interface 100 acquires data from the grid connection point voltage sampling device, energy storage management system, grid-connected energy storage converter controller, photovoltaic inverter, controllable branch switch, and smart meter. The grid connection point voltage sampling period is 100ms, the grid-connected energy storage converter status sampling period is 100ms, the energy storage charge status and available power update period is 1s, the branch smart meter power data update period is 1s, and the controllable switch status update period is 200ms. The power failure identification and status acquisition module 110 generates an external power grid failure flag after detecting that the three-phase voltage at the grid connection point is lower than 0.2 times the rated voltage for 2 seconds, and the grid connection switch is in the open state. Subsequently, the module reads the protection action record, confirms that a branch circuit on the third floor of the office building has tripped due to a fault, marks this branch circuit as a fault isolation zone, and removes it from the initial recovery target.
[0107] The load recovery fingerprint generation module 120 generates load recovery fingerprints based on the historical power consumption curves and load files of each branch. The historical power characteristics of the communication and security load are stable, with an operating power of approximately 30kW before the power outage. The cold load starting current is approximately 1.2 times the rated current, resulting in low starting reactive power demand. Therefore, its GradeScorek, ContinuityScorek, and CriticalTimeScorek are relatively high, while ColdImpactScorek and ReactiveScorek are relatively low. The fire control load itself has a low starting impact, but the fire pump branch is a motor-type load, with an estimated cold load starting current of 4.5 times the rated current, resulting in higher starting reactive power demand. Therefore, module 120 distinguishes between fire control cabinets and fire pumps as different recovery targets. The allowable interruption time for the production control load is set to 10 minutes. When the power outage duration reaches 6 minutes, its CriticalTimeScorek is higher than that of ordinary office loads. For the air conditioning cooling load, when the power outage duration reaches 20 minutes, module 120 corrects its Kcold_k from the initial value of 2.5 to 3.2 and increases RampRiskScorek. The RampRiskScorek of the power-limited charging load is lower than that of the non-adjustable charging load due to the presence of a power adjustment interface.
[0108] The recoverable island segment division module 130 forms four main island segments based on the park topology. Island segment I1 includes communication and security loads and some emergency lighting, with a rated recovery power of approximately 45kW. Island segment I2 includes production control loads and fire control loads; if fire pumps are not activated, the estimated recovery power is approximately 78kW. Island segment I3 includes fire pumps and their related motor branches, with a rated power of approximately 75kW but a high starting impact. Island segment I4 includes office lighting, air conditioning, and charging loads, with a large capacity and a high proportion of general loads. Photovoltaic access branches are separately marked as new energy integration areas and will not participate in active integration before energy storage is built up and critical loads are restored. The faulty branch on the third floor of the office building corresponding to the fault isolation area is marked as an unrecoverable area and will not enter this round of black start sequence.
[0109] The island segment risk assessment module 140 calculates the startup impact, reactive power demand, frequency drop risk, and energy storage support margin for the aforementioned island segment. Based on the conditions of a storage SOC of 78%, a minimum reserved SOC of 25%, and a standby SOC of 10%, the available energy for energy storage is calculated after deducting the reserved and standby energy, which is approximately 430 kWh. The available discharge power for energy storage is based on a rated power of 500 kW, adjusted for converter alarm status. In this embodiment, there are no alarms, so 500 kW is used. Island segment I1 has SIj approximately 0.12, RQj approximately 0.10, FRj approximately 0.09, and SMj approximately 6.8, and is determined to be currently recoverable. Island segment I2 has SIj approximately 0.24, RQj approximately 0.22, FRj approximately 0.18, and SMj approximately 4.1, and is also determined to be currently recoverable. Due to the significant impact of the fire pump startup on Island Segment I3, with SIj approximately 0.72, RQj approximately 0.70, FRj approximately 0.48, and SMj approximately 2.5, it was determined to be split or subject to power limitation restoration. For Island Segment I4, with all normal loads being connected at once, SIj approximately 0.88, RQj approximately 0.64, FRj approximately 0.66, and SMj approximately 1.05, it was determined to be temporarily deferred for restoration and will need to be connected in batches after the photovoltaic system is integrated.
[0110] The startup sequence generation module 150 generates an initial black startup sequence based on the above results. The first step is to generate an energy storage voltage build-up step, controlling the energy storage converter to enter grid-connected operation mode and closing the support switch from energy storage to the microgrid bus. The verification and rearrangement module 160 collects the bus voltage and frequency after voltage build-up. It detects that the bus voltage is stable within 0.98 to 1.02 times the rated value, the frequency is stable within 49.92 Hz to 50.06 Hz, and the grid-connected energy storage converter current is less than 0.15 times the rated current; therefore, the voltage build-up step is considered successful. The second step is to generate an island segment I1 recovery step, activating communication and security loads and emergency lighting. After execution, the bus voltage drops to a minimum of 0.97 times the rated value, the frequency drops to a minimum of 49.93 Hz, and the energy storage output power increases to approximately 48 kW, meeting the verification conditions. The third step is to generate an island segment I2 recovery step, activating production control loads and the fire control cabinet. After execution, the energy storage output power increases to approximately 126 kW, the minimum frequency is 49.90 Hz, and no over-limit trigger is observed.
[0111] For island segment I3 where the fire pump is located, the start-up sequence generation module 150 does not schedule it to be put into operation immediately after initial pressurization. Instead, it generates a conditional recovery step based on the judgment result of the island segment risk assessment module 140. This step requires that the fire pump can only be put into operation when the fire control cabinet has been restored, the bus frequency deviation is less than 0.15Hz, the energy storage output power is less than 250kW, and the current of the grid-type energy storage converter is less than 0.8 times the rated current. If the fire pump is equipped with a soft starter, the execution command interface 180 sends a soft start or delayed start command to it; if it is not equipped with a soft starter, the load is scheduled to be put into operation after the photovoltaic system is connected and the support margin is updated. In this embodiment, the fire pump has a soft start control interface. The start sequence generation module 150 sets it to start soft start after a 30s delay. During the start-up period, the verification and rearrangement module 160 monitors the current of the grid-type energy storage converter at a 100ms cycle. If the current exceeds 1.15 times the rated current and lasts for more than 1s, the step is immediately stopped and the fire control cabinet is kept powered.
[0112] After the critical load is restored, the sequence generation module 150 generates the photovoltaic ramp rate integration steps. The execution command interface 180 issues an initial integration power of 80kW and a ramp rate of no more than 35kW / s to the photovoltaic inverter. During the integration process, the execution verification and rearrangement module 160 continuously monitors changes in bus voltage, frequency, and photovoltaic output power. After the photovoltaic integration stabilizes, the actual available output is approximately 210kW, and the island segment risk assessment module 140 updates Preserve_j and Qlocal_j. After the update, if all ordinary loads are put into island segment I4 at once, the SIj and FRj thresholds are still not met. However, after splitting the ordinary loads into three batches, each batch meets the single batch constraints.
[0113] When ordinary loads are put into operation in batches, the sequence generation module 150 generates three batches. The first batch includes office lighting and necessary socket loads, with an estimated additional power of approximately 65kW, SIj of approximately 0.18, and SMj of approximately 3.8. The second batch includes some air conditioning cooling loads, which are put into operation with a delay and in groups, with an estimated additional power of approximately 90kW, SIj of approximately 0.42, and SMj of approximately 2.6. The third batch includes charging loads that support power limiting and the remaining ordinary office loads. The initial power of the charging loads is limited to 30% of the rated power, with an estimated additional power of approximately 85kW, SIj of approximately 0.35, and SMj of approximately 2.3. After each batch is put into operation, the verification and rearrangement module 160 collects the bus voltage, frequency, energy storage output power, energy storage SOC, grid-type energy storage converter current, and protection alarms. If the voltage is lower than 0.93 times the rated value or the frequency is lower than 49.70Hz after a batch is put into operation, module 160 triggers a rollback.
[0114] In one execution of this embodiment, after the second batch of air conditioning cooling loads was put into operation, the bus frequency dropped to 49.69Hz within a short period of time, below the set frequency verification threshold. The verification and rearrangement module 160, based on the most recently put into operation, load recovery fingerprint, and branch current changes, determined that the anomaly was mainly caused by the cold start impact of the two groups of air conditioning cooling loads in the second batch. Instead of cutting off communication security, fire control, or production control loads, module 160 cut off the first group of air conditioning loads in the second batch that met the interruptible condition (PRk ranking), and increased the ColdImpactScorek and RampRiskScorek of that group of air conditioning loads. Subsequently, the start-up sequence generation module 150 regenerated the remaining ordinary load batches, splitting the remaining air conditioning loads into two smaller batches and extending the batch interval to 60s. When the loads were put into operation again after rearrangement, the lowest bus frequency value remained at 49.78Hz, meeting the conditions for continued execution.
[0115] After the external power grid is restored, the startup sequence generation module 150 generates grid connection verification steps. The verification and rearrangement module 160 collects the voltage amplitude, frequency, and phase angle of the microgrid side and the external power grid side. The synchronization conditions are set as follows: the voltage amplitude difference does not exceed 5% of the rated value, the frequency difference does not exceed 0.1Hz, the phase angle difference does not exceed 10°, and the predicted power exchange value before grid connection does not exceed the preset impact threshold. When the microgrid side voltage is detected to be 0.99 times the rated value, the external power grid side voltage is 1.01 times the rated value, the frequency difference is 0.04Hz, and the phase angle difference is 6°, the device determines that the synchronization conditions are met and sends a grid connection execution command to the grid connection switch through the execution command interface 180. After grid connection, the human-machine interaction recording module 170 records the entire black start process, including the energy storage voltage build-up time, the key load restoration sequence, the photovoltaic power connected, the batch of ordinary loads, the abnormal rollback objects, the rearrangement reasons, and the final recovery result.
[0116] To demonstrate the processing effect of the technical solution of this application compared with the existing fixed-sequence recovery method, this embodiment compares the two under the same park load conditions. The fixed-sequence recovery method executes energy storage voltage building, communication load, production control, fire pumps, office lighting, air conditioning, charging load, and photovoltaic integration sequentially according to a preset list, without dynamically adjusting based on energy storage SOC, grid inverter short-term capacity, cold load start-up impact, and island segment support margin. This method is prone to frequency drops or grid-type energy storage converter current approaching limits when fire pumps or air conditioning loads are put into operation early, requiring manual disconnection of some ordinary loads and restart. The self-generating recovery method of this application first identifies high-impact loads through load recovery fingerprinting, then judges the current recovery conditions through island segment risk indicators, and updates the support capacity after photovoltaic integration. Therefore, it can postpone or split high-impact ordinary loads and automatically roll back and rearrange in the event of anomalies.
[0117] Reference Figure 8Sub-figure A shows the steps sequentially: energy storage pressure build-up, island segment I1 recovery, island segment I2 recovery, photovoltaic slope limiting incorporation, first batch of ordinary load input, and recovery status after abnormal rearrangement. The frequency and voltage thresholds shown in Sub-figure A reflect the judgment boundaries of the verification and rearrangement module 160. When the frequency deviation of the ordinary load batch approaches or exceeds the threshold, module 160 pauses subsequent steps and triggers rearrangement. Sub-figure B lists SIj, RQj, FRj, and SMj for island segments I1 to I4 in a matrix. The recovery conclusions on the right side of the matrix correspond to the current recoverable, split, or limited power recovery, as well as the processing results of temporarily suspending batching. Sub-figure C compares the load recovery rates of the self-generated recovery method and the fixed-sequence recovery method, and simultaneously shows the trend of energy storage SOC decreasing with each recovery step, illustrating that this application improves the recoverable load ratio while maintaining energy storage support capacity constraints. Subgraph D compares the frequency deviation response of the fixed sequence recovery method and the self-generated recovery method of this application within the abnormal window after the second batch of normal load is put into operation. Using -0.30Hz as the frequency verification threshold, it shows the process of frequency disturbance gradually converging after the back-off rearrangement is performed.
[0118] Table 1 shows a set of comparative records under the same load conditions. The data in the table are engineering examples under the scenario of this embodiment, used to illustrate the processing results of different control methods, and do not limit this application to obtaining fixed values in all scenarios.
[0119] Table 1 Comparison of Black Startup Handling Effects of Microgrids in Typical Industrial Parks
[0120] As shown in Table 1, under the microgrid conditions of this industrial park, the fixed-sequence recovery method, due to its failure to distinguish between critical loads and high-impact ordinary loads within the same branch and its failure to recalculate support capacity after photovoltaic integration, is prone to causing frequency and voltage disturbances when fire pumps or air conditioning cooling loads are put into operation at an early stage. The self-generating recovery method of this application prioritizes the recovery of low-impact critical loads such as communication security and production control, restores fire pumps according to soft-start conditions, splits air conditioning cooling and charging loads into multiple batches of ordinary loads, and updates the energy storage support margin after photovoltaic integration. Therefore, under the given parameters in this embodiment, the maximum frequency drop, maximum voltage drop, and maximum grid inverter current during the recovery process are all lower than the corresponding indicators of the fixed-sequence recovery method.
[0121] Furthermore, this application features a clearer data loop in handling anomaly feedback. Fixed-sequence recovery methods typically require manual judgment of the removal target after a batch of loads fails, and the cause of failure is not necessarily translated into subsequent recovery rules. This application, when detecting frequency exceeding limits after the second batch of air conditioning cooling loads is put into operation, can locate possible causes based on the most recent batch, load recovery fingerprint, and island segment risk indicators, and increase the ColdImpactScorek and RampRiskScorek of the corresponding air conditioning load, ensuring that subsequent reordering does not restore the load according to the original batch. This processing allows for smaller batches and longer intervals for the second operation in the same scenario, thereby reducing the possibility of exceeding limits again.
[0122] Figure 8 Subplot D further illustrates the rearrangement effect using an abnormal window frequency response curve. The horizontal axis represents the abnormal window time after the second batch of normal loads is put into operation, and the vertical axis represents the bus frequency deviation. The -0.30Hz horizontal line in the figure represents the frequency verification threshold, and the vertical line at the 30s position indicates the moment when the verification and rearrangement module 160 triggers the rollback rearrangement. Under the fixed sequence recovery method, the frequency deviation exceeds the frequency verification threshold after 20s and reaches approximately -0.42Hz around 30s. Although it recovers afterward, it remains close to the threshold for a relatively long period. In this application, when the frequency deviation approaches the threshold, the air conditioning load that is at the top of the PRk sorting and meets the interruptible condition is removed, and the remaining air conditioning load is split into smaller batches and put back into operation. After rearrangement, the frequency deviation gradually recovers from approximately -0.31Hz to approximately -0.12Hz. This subplot shows that the verification and rearrangement module 160 does not only record the over-limit event, but also changes the subsequent load input batches according to the load recovery fingerprint and island segment risk index, so that the frequency disturbance during the normal load recovery process is lower than that of the fixed sequence recovery method.
[0123] In terms of human-computer interaction and operation and maintenance, this application can also generate traceable records. The human-computer interaction recording module 170 saves the execution object, execution time, verification indicators, abnormal reasons, rollback actions, and reordering results for each step. For the air conditioning load frequency exceeding the limit event in this embodiment, the log records the corresponding branch, frequency changes before and after commissioning, branch current peak, batch capacity after reordering, and final recovery status. When external power grid failure occurs again, the load recovery fingerprint generation module 120 can read this historical record, directly improve the cold start impact score of the air conditioning branch, and arrange it in the small batch recovery stage after photovoltaic integration. Thus, the black start sequence generation process can use historical execution data to correct the load risk estimate.
[0124] As can be seen from this embodiment, the technical solution of this application can be implemented in a specific industrial park microgrid according to the following process: external power grid failure identification, operation data access, load recovery fingerprint generation, recoverable island segment division, island segment risk calculation, energy storage voltage establishment, critical load recovery, new energy integration, phased commissioning of ordinary loads, anomaly rollback rearrangement, and grid connection verification. This process uses operation data, topology boundaries, load characteristics, energy storage support capabilities, and execution feedback together to generate a black start sequence, ensuring that the recovery steps match the on-site support capabilities, and automatically correcting subsequent recovery plans when the execution results deviate from expectations.
[0125] It should be noted that the energy storage capacity, grid-connected inverter capacity, threshold range, sampling period, load power, and recovery time listed in the foregoing embodiments are only used to illustrate the feasible implementation of the technical solution of this application in a substation or park microgrid, and do not constitute a limitation on the scope of protection of this application. In practical applications, the energy storage system capacity, the short-time overload capacity of the grid-connected inverter, the load classification rules, the cold load start-up current estimation method, the island segment division granularity, the batch capacity of ordinary loads, and the grid connection verification threshold can all be adjusted according to the microgrid capacity level, protection settings, load structure, communication conditions, and operating strategies.
[0126] The modules described in this application can be implemented by hardware circuits, processor-executed software programs, programmable logic devices, edge computing gateways, intelligent converged terminals for distribution areas, microgrid energy management systems, energy storage controllers, or combinations thereof. Data transmission between modules can employ wired communication, wireless communication, fieldbus, Ethernet, serial communication, or internal data bus. Modules can be centrally deployed within the same device or distributed across different control devices. Any implementation method that can complete power failure identification, load recovery fingerprint generation, recoverable island segment division, island segment risk assessment, startup sequence generation, and execution verification and rearrangement processes falls under the scope of this application's technical solution.
[0127] The load restoration fingerprint referred to in this application is not limited to the field combinations listed in the embodiments. Without altering its function of characterizing load restoration priority and startup risk, fields can be added or removed based on field data conditions. For example, branch voltage sensitivity, load geographical location, user-side backup power status, equipment maintenance status, or historical fault records can be added. Some fields can also be merged into an equivalent score. Correspondingly, the calculation expression for the load restoration priority value can also be implemented using equivalent weighting, segmented scoring, rule-based determination, or model scoring methods.
[0128] The recoverable island segment referred to in this application is not limited to a single feeder, a single branch, or a single building area. Any area that can be identified as a power supply area capable of independent or phased recovery based on topology boundaries, fault isolation boundaries, support paths, and switch controllability can be considered a recoverable island segment in this application. For areas where switch boundaries are not fully controllable but have load grouping control capabilities, equivalent recoverable island segments can also be formed through load control interfaces.
[0129] The verification and rescheduling described in this application are not limited to being performed once after each black start step. In specific implementations, verification can be performed continuously during voltage build-up, critical load commissioning, renewable energy integration, batch commissioning of ordinary loads, and grid connection verification. Verification can also be performed according to a preset time window or event-triggered method. When it is detected that the voltage, frequency, grid inverter current, energy storage state of charge, renewable energy output, or protection alarm does not meet the conditions, rollback, suspension, load reduction, delay, batch rescheduling, or manual confirmation can be triggered.
[0130] The above embodiments are only used to illustrate the technical solutions of this application. Those skilled in the art can adjust, combine, or make equivalent substitutions to the specific implementations without departing from the technical concept of this application. All equivalent changes made based on the disclosure of this application should fall within the protection scope of this application.
Claims
1. A method for generating a microgrid black start sequence of a substation, applied to a microgrid system for power supply or distribution, the microgrid system comprising an energy storage system, a grid-forming inverter, a controllable switch, a new energy unit, a key load and a general load, characterized in that, This includes: after detecting an external power grid failure and completing fault isolation, acquiring the microgrid's historical power consumption curves, load types, cold load start-up currents, energy storage state of charge, grid inverter capacity, critical load levels, topology switch status, available output of new energy sources, and controllable switch boundaries, and forming a set of recoverable loads and a set of temporarily deferred recovery loads; Based on the historical electricity consumption curves, load types, cold load starting currents, and critical load levels, a load recovery fingerprint is generated for the loads to be restored. The microgrid is divided into multiple recoverable island segments based on the topology switch status, fault isolation boundary, energy storage access point, and load distribution. Calculate the startup impact, reactive power demand, frequency drop risk, and energy storage support margin for each recoverable island segment; Based on the load recovery fingerprint and the calculation results of each recoverable island segment, a black start sequence is generated, including energy storage voltage building, critical load recovery, new energy integration, batch commissioning of ordinary loads, and grid connection verification. After each step is executed, the subsequent black start sequence is verified or rearranged based on voltage, frequency, inverter current, and energy storage state of charge.
2. The method of claim 1, wherein the method further comprises: When acquiring historical electricity consumption curves, load types, cold load starting currents, energy storage status of charge, grid-connected inverter capacity, critical load levels, topology switch status, and available renewable energy output for the microgrid, operational data is read from smart meters, smart distribution terminals, energy storage management systems, grid-connected inverter controllers, distributed power controllers, and distribution automation terminals. The read operational data is then time-aligned, outlier removed, and validity-marked. Historical electricity consumption curves are associated with corresponding branches or user-side metering points according to load identifiers. Load types are categorized into motor loads, constant power electronic loads, lighting loads, air conditioning / cooling loads, charging loads, and backup loads. Cold load starting currents are determined based on load type, outage duration, historical starting records, and rated power. Energy storage status of charge and available energy storage discharge power are used together to characterize voltage build-up and subsequent support capabilities. Grid-connected inverter capacity is corrected for rated capacity, short-time overload capacity, and current alarm status before being included in subsequent calculations.
3. The method of claim 1, wherein the method further comprises: When generating load recovery fingerprints for loads to be restored, a load recovery fingerprint LFk is formed for the k-th load Lk to be restored. LFk includes historical power characteristics Pk_hist, load type Typek, cold load starting current Icold_k, cold load surge multiple Kcold_k, starting reactive power demand Qstart_k, critical load level Gradek, interruptibility attribute Interruptk, outage duration Toff_k, and allowable ramp recovery capability Rampk. Based on the load recovery fingerprint, a load recovery priority value PRk is calculated, where PRk = a1 × GradeScorek + a2 × ContinuityScorek + a3 × CriticalTimeScorek - a4 × ColdImpactScorek - a5 × ReactiveScorek - a6 × RampRiskScorek, where a1 to a6 are preset weights, GradeScorek is determined by the critical load level, ColdImpactScorek is determined by the cold load starting current and cold load impact multiple, ReactiveScorek is determined by the starting reactive power demand, and RampRiskScorek is determined by the allowable ramp recovery capability and the power outage duration.
4. The method of claim 1, wherein the method further comprises: When dividing a microgrid into multiple recoverable island segments, the busbars, feeders, sectionalizing switches, tie switches, energy storage access points, grid-connected inverter access points, critical load access points, and fault isolation boundaries in the current electrical topology are used as the basis for division. Candidate areas that are electrically isolated from the fault area and can be independently switched by controllable switches are determined. Recoverable island segments are formed based on the line capacity, transformer capacity, energy storage support path, number of critical loads, and capacity of ordinary loads in the candidate areas. When high-start-up impact loads and critical loads are mixed in the same candidate area, the candidate area is further divided into critical load sub-island segments and ordinary load sub-island segments. When a candidate area lacks a grid-connected support path or the switch boundary is uncontrollable, the candidate area is marked as a temporarily deferred recovery island segment.
5. The method of claim 1, wherein the method further comprises: When calculating the startup impact, reactive power demand, frequency sag risk, and energy storage support margin for each recoverable island segment, the startup impact SIj, reactive power demand RQj, frequency sag risk FRj, and energy storage support margin SMj are calculated for the j-th recoverable island segment Ij. Here, SIj = (Σxk×Pstart_k + Σxm×Pinrush_m) / Sgfm_j, where xk indicates whether the corresponding load belongs to the candidate input set, xm indicates whether the corresponding impact load belongs to the candidate input set, Pstart_k represents the equivalent active power impact of the load startup, Pinrush_m represents the transient impact power of the impact load, and Sgfm_j represents the grid inverter correction capacity supporting this recoverable island segment; RQj = Σxk×Qstart_k + Qline_j + Qmag_j - Qloc al_j, Qline_j represents line reactive power consumption, Qmag_j represents transformer excitation reactive power, Qlocal_j represents local available reactive power support; FRj=ΔPj / Preserve_j, ΔPj represents the active power imbalance caused by the island segment input, Preserve_j represents the active power regulation margin of energy storage and grid-connected inverters within the allowable frequency deviation; SMj=min(Pess_avail / Pstep_j, Eess_avail / Esupport_j), Pess_avail represents the available discharge power of energy storage, Pstep_j represents the expected new power in this step, Eess_avail represents the available energy after deducting the minimum state of charge and reserve, and Esupport_j represents the energy required within the preset support duration.
6. The method of claim 5, wherein the method further comprises: When generating the black start sequence based on the load recovery fingerprint and the calculation results of each recoverable island segment, the system first determines whether the energy storage state of charge, available energy storage discharge power, and grid-connected inverter correction capacity meet the voltage build-up conditions. If the voltage build-up conditions are met, the energy storage voltage build-up step is generated. After voltage build-up is completed, the subsequent execution order is determined according to the recovery level of the recoverable island segment. Specifically, when SIj is less than the start-up impact threshold, RQj is less than the reactive power threshold, FRj is less than the frequency risk threshold, and SMj is greater than the support margin threshold, the corresponding recoverable island segment is included in the current recoverable set. When the SIj or RQj of the recoverable island segment where the critical load is located exceeds the corresponding threshold but SMj meets the support margin threshold, load splitting or power limiting is performed on the recoverable island segment. When SMj does not meet the support margin threshold, the recoverable island segment is scheduled to be restored after the integration of new energy sources or the removal of low-priority loads.
7. The method of claim 1, wherein the method further comprises: When generating critical load restoration and renewable energy integration steps, after verifying the no-load voltage, no-load frequency, and grid-connected inverter current in the energy storage voltage building step, the critical load restoration targets are selected based on the load restoration priority value, critical load level, start-up impact, and the energy storage support margin of the island segment. For critical loads where the cold load start-up current Icold_k is greater than the preset cold start-up current threshold Ith or the cold load impact multiple Kcold_k is greater than the preset impact multiple threshold Kth, delayed connection, segmented connection, or ramp connection conditions are set. After the critical load is connected, if the bus voltage, frequency, and inverter current are within the allowable range, the renewable energy integration step is generated, and the renewable energy units are controlled to connect to the microgrid in a power-limited and slope-limited manner. At the same time, the available active power regulation margin, local available reactive power support, and energy storage support margin are updated according to the actual output of renewable energy, so that subsequent batches of ordinary loads are reordered according to the updated support capacity.
8. The method of claim 1, wherein, When generating the batching of ordinary loads, the ordinary loads are divided into multiple batches according to the load recovery priority value, the start-up impact of the recoverable island segment, reactive power demand, frequency drop risk and energy storage support margin. This ensures that the total start-up impact of the same batch does not exceed the short-term withstand capacity of the grid inverter, the expected reactive power demand of the same batch does not exceed the local reactive power support capacity, and the energy required by the same batch within the preset support time does not exceed the available energy storage energy. After each batch of loads is executed, bus voltage, frequency, grid inverter current, energy storage output power, energy storage state of charge, renewable energy output, and protection alarm status are collected. If the collected results meet the verification conditions, the next batch of loads is executed. If the collected results do not meet the verification conditions, the loads in the most recent batch of loads are sorted from smallest to largest according to the load recovery priority value PRk, and the load at the top of the sort is removed. Then the batch of loads for the remaining ordinary loads is recalculated.
9. The method for self-generating the black startup sequence of a microgrid in a transformer substation according to claim 1, characterized in that, When generating grid connection verification steps and verifying or rearranging subsequent black start sequences, after the external grid is restored, the voltage amplitude, frequency, phase angle, synchronous voltage difference, power exchange direction, and grid connection switch status of the microgrid side and the external grid side are collected. When the voltage amplitude difference, frequency difference, phase angle difference, and power exchange prediction value meet the grid connection conditions, a grid connection execution command is generated. When any black start step is executed and voltage exceeds the limit, frequency drops exceed the threshold, grid inverter experiences overcurrent, energy storage state of charge is lower than the minimum threshold, new energy output fluctuations exceed the threshold, or a protection alarm occurs, the unexecuted steps are suspended, the cold load impact weight of the corresponding load, the frequency drop risk of the island segment, and the energy storage support margin are updated, and the remaining black start sequence is regenerated based on the updated calculation results.
10. A device for self-generating a black start sequence for a microgrid in a transformer substation, characterized in that, The system includes a power outage identification and status acquisition module, a load recovery fingerprint generation module, a recoverable island segment division module, an island segment risk assessment module, a start-up sequence generation module, an execution verification and rearrangement module, and a human-machine interaction recording module. The power outage identification and status acquisition module is used to acquire historical electricity consumption curves, load types, cold load start-up currents, energy storage state of charge, grid inverter capacity, critical load levels, topology switch status, and available renewable energy output after detecting an external grid outage and completing fault isolation. The load recovery fingerprint generation module is used to generate load recovery fingerprints for loads to be restored and calculate load recovery priority values. The recoverable island segment division module is used to determine the recovery priority based on topology switch status, fault isolation boundaries, energy storage access points, and other relevant factors. The load distribution is divided into recoverable island segments; the island segment risk assessment module is used to calculate the start-up impact, reactive power demand, frequency drop risk, and energy storage support margin of each recoverable island segment; the start-up sequence generation module is used to generate a black start sequence including energy storage voltage building, critical load recovery, renewable energy integration, phased commissioning of ordinary loads, and grid connection verification; the execution verification and rearrangement module is used to verify or rearrange the subsequent black start sequence based on the voltage, frequency, inverter current, energy storage state of charge, renewable energy output, and protection alarm status after the black start steps are executed; the human-machine interaction recording module is used to display the black start sequence, island segment risk indicators, execution status, and rearrangement results, and record black start execution data to correct the fingerprint of subsequent load recovery.