Autonomous emergency control method and system for communication disconnection of oilfield offshore production platform
Patent Information
- Application Number
- CN202611072694.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-20
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2046-07-20
AI Technical Summary
[0004]本申请提供了一种油田海上生产平台通讯失联的自主应急控制方法及系统,进而至少在一定程度上可以解决油田海上生产平台在台风模式远程操控,通讯失联情况下的自主应急过程中,存在生产运行风险和可靠性较低的问题
[0019] This technical solution triggers autonomous emergency response through multi-link interruption detection, avoiding single-point misjudgment. After isolating the emergency generator and confirming the establishment of the replacement channel, the chaotic characteristics of the terminal pressure signal are used to identify the replacement front, enabling real-time monitoring of the replacement progress and replacing blind timed replacement. Based on the actual replacement volume, the redundancy duration is dynamically calculated and compared with the absolute safety upper limit to generate a termination time that balances completion and safety. Finally, through graded shutdown and orderly power cut-off, and transition to low-power silence, the system effectively extends the endurance of key monitoring modules while ensuring thorough replacement. This achieves closed-loop control of the replacement process and sequential shutdown of equipment, ensuring the safety of pipeline replacement and low-power standby of equipment under communication loss, and improving the reliability and stability of autonomous emergency control of oilfield offshore production platforms in the event of communication loss.
Smart Images

Figure CN122579103B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of control system technology, and more specifically, to an autonomous emergency control method and system for communication loss of an offshore oil production platform. Background Technology
[0002] Offshore oilfield clusters typically consist of multiple production platforms, floating production storage and offloading (FPSO) units, and subsea pipelines connecting these facilities. Before severe weather such as typhoons, all offshore personnel must evacuate to land, and production control is remotely monitored and operated from a land-based remote control center via sea-land communication. However, during typhoons, sea conditions are severe, and communication links are easily interfered with or even completely disrupted. When sea-land communication is lost, land-based control cannot send control commands to the platform, which must then rely on its local control system to autonomously complete emergency shutdowns and pipeline replacements to prevent safety accidents such as crude oil condensation in subsea pipelines, equipment damage, or environmental pollution.
[0003] In existing technologies, autonomous emergency control after communication loss typically employs a timed open-loop control method, which presets a fixed replacement duration and a fixed valve operation sequence. This method cannot detect the actual position of the replacement front within the subsea pipeline, easily leading to incomplete or excessive replacement. Furthermore, it lacks a closed-loop confirmation mechanism for valve positioning and pump operation status; if any actuator malfunctions, the entire replacement process will fail to detect and adapt accordingly. Therefore, autonomous emergency control of offshore oilfield production platforms in the event of communication loss suffers from low efficiency and reliability. Summary of the Invention
[0004] This application provides an autonomous emergency control method and system for offshore oilfield production platforms when communication is lost, which can at least partially solve the problems of low production operation risk and low reliability in the autonomous emergency process of offshore oilfield production platforms under remote control and communication loss in typhoon mode.
[0005] Other features and advantages of this application will become apparent from the following detailed description, or may be learned in part from practice of this application.
[0006] According to one aspect of this application, an autonomous emergency control method for communication loss of an offshore oilfield production platform is provided, comprising: monitoring the status of at least two independent communication links in the offshore oilfield production platform; when it is determined that all communication links are interrupted and the interruption duration reaches a first preset threshold, switching to an autonomous emergency mode; in the autonomous emergency mode, performing emergency generator isolation operations in a preset sequence, controlling multiple valves on the pipeline sweeping path to establish a replacement channel, and determining that the replacement channel has been successfully established based on the arrival feedback signals emitted by each valve; after the channel replacement is successful, acquiring sensor signals from the subsea pipeline, performing multi-scale transformation on the sensor signals, and calculating... A preset characteristic index is used to calculate the frontal discrimination index. When the frontal discrimination index exceeds a second preset threshold, it is determined that the frontal has passed the monitoring point. After determining that the frontal has passed the monitoring point, the redundant replacement time is dynamically calculated based on the replaced volume, the total volume of the subsea pipeline, and the average replacement flow. The first termination time generated based on the redundant replacement time is compared with the second termination time generated based on the preset absolute replacement time, and the earlier one is selected as the replacement termination time. When the replacement termination time is reached, the power equipment is shut down, the valves are closed, and the auxiliary systems are shut down in a preset hierarchical order, and the system enters a low-power silent mode.
[0007] In this application, based on the aforementioned scheme, the establishment of a replacement channel by multiple valves on the control sweep path, and the determination of successful establishment of the replacement channel based on the arrival feedback signal issued by each valve, includes: issuing a valve control command to control multiple valves on the sweep path to establish a replacement channel, and starting a timer to monitor the arrival feedback signal of the valve; if an arrival feedback signal is received before the timer expires, the replacement channel is determined to be established successfully; if no arrival feedback signal is received before the timer expires, the operation is determined to be a failure, the same valve control command is issued again and the timer is restarted; after the repeated operation reaches a preset maximum number of repetitions, if the valve still has not reached the target position, the entire replacement process is terminated, a safety shutdown is performed, and the failed valve tag number and the reason for failure are written to the local fault log.
[0008] In this application, based on the aforementioned scheme, the step of performing multi-scale transformation on the sensor signal and calculating preset feature indices includes: performing multi-scale coarse-grained transformation on the sensor signal to obtain coarse-grained sequences at multiple time scales; reconstructing the phase space of the coarse-grained sequences, statistically analyzing the probability distribution of permutation patterns, and calculating the normalized permutation entropy; constructing a recursion graph based on the sensor signal, statistically analyzing the diagonal length distribution in the recursion graph, and calculating a deterministic index; and using the normalized permutation entropy and the deterministic index as the feature indices.
[0009] In this application, based on the aforementioned scheme, the calculation of the frontal discriminant index based on the characteristic index includes: generating normalized deviations for each scale based on the normalized permutation entropy and the seawater baseline permutation entropy at each scale; fusing the normalized deviations at all scales to obtain the average deviation of the multi-scale permutation entropy; performing nonlinear mapping on the average deviation using a sigmoid function to obtain a first intermediate quantity; processing the deterministic index using a fractional function to obtain a second intermediate quantity; and multiplying the first intermediate quantity by the second intermediate quantity to obtain the frontal discriminant index.
[0010] In this application, based on the aforementioned scheme, the step of dynamically calculating the redundant replacement time according to the replaced volume, the total subsea pipeline volume, and the average replacement flow includes: subtracting the replaced volume from the start of replacement to the moment the frontal face passes from the total subsea pipeline volume to obtain the remaining unreplaced volume; dividing the cumulative instantaneous flow value of the entire replacement process by the replacement duration to obtain the average replacement flow; dividing the remaining unreplaced volume by the average replacement flow to obtain the theoretical venting time, and then multiplying it by a preset safety redundancy coefficient to obtain the redundant replacement time.
[0011] In this application, based on the aforementioned scheme, the step of comparing the first termination time generated based on the redundant permutation duration with the second termination time generated based on a preset absolute permutation duration and selecting the earlier one as the permutation termination time includes: adding the redundant permutation duration to the permutation start time to obtain the first termination time; adding the preset upper limit of the absolute permutation duration to the permutation start time to obtain the second termination time; comparing the first termination time with the second termination time and selecting the earlier one as the permutation termination time.
[0012] In this application, based on the aforementioned scheme, before reaching the replacement termination time, the process includes: during the redundant replacement execution, continuously updating the average flow rate and the cumulative volume replaced throughout the replacement process at a frequency lower than the baseline scan frequency; recalculating the redundant replacement duration based on the updated average flow rate and cumulative volume, and updating the first termination time according to the recalculated redundant replacement duration; comparing the updated first termination time with the second termination time again, and taking the earlier one as the updated replacement termination time; wherein, the adjustment range of the replacement termination time for each update does not exceed the preset maximum step size, and the termination time is only allowed to be adjusted in the direction of postponement, and is not allowed to be adjusted in the direction of advancement.
[0013] In this application, based on the aforementioned scheme, the preset hierarchical sequence includes: Level 1, power equipment shutdown, including first stopping the booster pump for replacement and confirming shutdown, delaying for a first preset time, stopping the fire pump, performing start-up suppression lock on it, and disconnecting its starter battery circuit; Level 2, valve closure, including delaying for a second preset time again, closing each valve on the sweeping path in order of proximity to the power source, and determining whether the position is reached after each valve is closed by a position feedback signal issued by a limit switch; Level 3, auxiliary system shutdown, including closing the outlet valve of the nitrogen cylinder group and performing a graded load shedding operation, retaining power supply only to the control, communication, and monitoring storage devices.
[0014] In this application, based on the aforementioned scheme, it further includes: receiving and processing fire and gas monitoring signals, waking up the output module to perform emergency response when a fire or gas leak is detected; sending heartbeat detection messages to the land side and listening for response signals to detect the recovery status of the communication link; and continuously running a real-time clock to record time information during the silent period.
[0015] According to one aspect of this application, an autonomous emergency control system for communication loss of an offshore oilfield production platform is provided, comprising: The monitoring module is used to monitor the status of at least two independent communication links in the offshore production platform of the oilfield. When it is determined that all communication links are interrupted and the interruption duration reaches the first preset threshold, it switches to the autonomous emergency mode. The isolation module is used to perform emergency generator isolation operations in a preset sequence in autonomous emergency mode, control multiple valves on the sweeping path to establish a replacement channel, and determine the success of the replacement channel establishment based on the arrival feedback signals sent by each valve. The discrimination module is used to collect sensor signals from the subsea pipeline after successful channel replacement, perform multi-scale transformation on the sensor signals and calculate preset feature indicators, calculate the front discrimination index based on the feature indicators, and determine that the front has passed the monitoring point when the front discrimination index exceeds a second preset threshold; the front discrimination index represents the degree of deviation of the pressure at the current end of the subsea pipeline from the seawater baseline state; the sensor signals are collected by pressure sensors, flow sensors and timing sensors; The timing module is used to dynamically calculate the redundant replacement time based on the replaced volume, the total volume of the subsea pipeline, and the average replacement flow rate after the frontal surface passes the monitoring point. It compares the first termination time generated based on the redundant replacement time with the second termination time generated based on the preset absolute replacement time and selects the earlier one as the replacement termination time. The shutdown module is used to execute the shutdown of power equipment, valve closure, and auxiliary system shutdown in a preset hierarchical sequence when the replacement termination time is reached, and enter a low-power silent mode.
[0016] According to one aspect of this application, a computer-readable medium is provided having a computer program stored thereon, which, when executed by a processor, implements the autonomous emergency control method for communication loss of an offshore oilfield production platform as described in the above embodiments.
[0017] According to one aspect of this application, an electronic device is provided, comprising: one or more processors; and a storage device for storing one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement the autonomous emergency control method for communication loss of an offshore oilfield production platform as described in the above embodiments.
[0018] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the autonomous emergency control method for communication loss of an offshore oilfield production platform provided in the various optional implementations described above.
[0019] This technical solution triggers autonomous emergency response through multi-link interruption detection, avoiding single-point misjudgment. After isolating the emergency generator and confirming the establishment of the replacement channel, the chaotic characteristics of the terminal pressure signal are used to identify the replacement front, enabling real-time monitoring of the replacement progress and replacing blind timed replacement. Based on the actual replacement volume, the redundancy duration is dynamically calculated and compared with the absolute safety upper limit to generate a termination time that balances completion and safety. Finally, through graded shutdown and orderly power cut-off, and transition to low-power silence, the system effectively extends the endurance of key monitoring modules while ensuring thorough replacement. This achieves closed-loop control of the replacement process and sequential shutdown of equipment, ensuring the safety of pipeline replacement and low-power standby of equipment under communication loss, and improving the reliability and stability of autonomous emergency control of oilfield offshore production platforms in the event of communication loss.
[0020] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0021] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0022] Figure 1The flowchart illustrating an autonomous emergency control method for communication loss of an offshore production platform in an oilfield, as shown in one embodiment of this application, is illustrated.
[0023] Figure 2 A flowchart illustrating the calculation of the redundancy permutation duration is shown in one embodiment of this application.
[0024] Figure 3 The diagram illustrates an autonomous emergency control system for communication loss of an offshore production platform in an oilfield, as shown in one embodiment of this application.
[0025] Figure 4 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown. Detailed Implementation
[0026] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this application more comprehensive and complete, and to fully convey the concept of the exemplary embodiments to those skilled in the art.
[0027] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this application. However, those skilled in the art will recognize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this application.
[0028] It should be noted that the data acquisition or information collection in this embodiment is performed after authorization by the user or the object of collection, and its process and purpose strictly follow the relevant regulations.
[0029] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, or in one or more hardware modules composed of smart chips, smart integrated circuits, or application-specific integrated circuits (ASICs), or in different network and / or processor devices and / or microcontroller devices.
[0030] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily need to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.
[0031] The implementation details of the technical solution of this application are described below: Figure 1 A flowchart illustrating an autonomous emergency control method for communication loss of an offshore oilfield production platform according to an embodiment of this application is shown. (Refer to...) Figure 1 As shown, the autonomous emergency control method for the communication loss of the offshore production platform in this oil field includes at least steps S110 to S150, which are detailed below: S110 monitors the status of at least two independent communication links in an offshore oilfield production platform. When it is determined that all communication links are interrupted and the interruption duration reaches the first preset threshold, it switches to autonomous emergency mode.
[0032] In this embodiment, this step can be executed by the dedicated control system (dedicated control system) of the offshore oilfield production platform, without relying on the land-based remote control center or external operators. Through communication status monitoring, it operates cyclically at fixed time intervals, acquiring real-time sea-to-land communication link status signals via hard-wired and network communication methods.
[0033] Specifically, in this embodiment, the dedicated control system (dedicated control system) is a local industrial control system or cloud platform control system that can autonomously perform emergency control tasks without relying on the land-based remote control center or external operators when the offshore production platform in the oilfield loses communication.
[0034] Specifically, during the monitoring of the status signals of the sea-land communication links, two physically independent communication links are monitored simultaneously: a satellite communication link and a microwave scattering communication link. Heartbeat detection messages are sent to the corresponding gateway at the land control center at a fixed frequency. If no correct response is received from the land side within several consecutive detection cycles, the link is considered to be interrupted. The status of the two links is determined independently.
[0035] First, a logical AND operation is performed on the states of the two communication links. The initial determination of communication loss is only true when both the satellite link and microwave link are interrupted simultaneously. Based on this, the module starts a timer to record the duration of the communication loss, incrementing by one scan cycle each time the communication loss determination is true, otherwise resetting to zero. When the timer's accumulated value reaches a preset threshold, for example, 5 minutes based on over-limit operating conditions, the final confirmation flag of the communication loss is set.
[0036] When it is determined that all communication links are interrupted and the interruption duration reaches a first preset threshold, a state transition is executed. First, the current timestamp is written to the internal memory and recorded as the moment of disconnection. Then, the autonomous emergency mode activation flag is switched from logical false to logical true. The predefined communication disconnection branch process in the timing logic diagram is then executed, which automatically takes over subsequent control tasks such as the connection of replacement paths and the sequential start-up of pumps and valves.
[0037] In addition, state transition events are recorded in a local log storage, including the time of mode switching, the state before switching, the state after switching, and the specific values of the condition signals that triggered the switching. This log information can be remotely retrieved by the land control center after sea-land communication is restored for post-event analysis of the cause of the communication interruption and response actions.
[0038] The above process monitors at least two independent communication links and only triggers switching after all links are interrupted for a duration reaching a preset threshold. First, the dual-link redundancy monitoring mechanism effectively eliminates false triggering caused by momentary interference or equipment jitter on a single link, preventing erroneous entry into emergency mode during brief communication instability. Second, the duration threshold setting acts as an anti-jitter filter, ensuring that only confirmed and continuous communication interruptions trigger mode switching, further improving the reliability of the judgment. Third, after switching to autonomous emergency mode, external control commands are blocked, fundamentally eliminating possible command conflicts or erroneous command interference during communication recovery, ensuring that subsequent emergency operations are executed independently under a purely local solution, guaranteeing the consistency and security of the control logic.
[0039] In autonomous emergency mode, S120 performs emergency generator isolation operations in a preset sequence, controls multiple valves on the sweeping path to establish a replacement channel, and determines that the replacement channel has been successfully established based on the arrival feedback signals sent by each valve.
[0040] In this embodiment, this step is automatically triggered after the autonomous emergency mode activation flag in S110 is set to true. The isolation operation of the emergency generator is executed sequentially according to the timing logic diagram, while simultaneously configuring and connecting key valves on the pipeline replacement path. This eliminates potential interference sources during the replacement process and establishes a stable seawater transport channel from the diesel fire pump outlet to the subsea pipeline.
[0041] In practical applications, subsea pipelines are submarine pipelines that connect offshore production platforms with land terminals or other platforms to transport media such as crude oil and natural gas. In emergency replacement scenarios for communication loss, they refer to safety-critical facilities that need to be replaced by seawater sweeping to prevent crude oil from solidifying in the pipeline.
[0042] Optionally, to ensure the rapid establishment of the replacement channel, priority is given to controlling and confirming the opening of key valves at the pipeline inlet, while the remaining valves complete their operation within a short period after the pump starts, and are confirmed to be in place before the replacement front arrives.
[0043] After confirming communication failure and switching to autonomous emergency mode, the emergency generator is isolated. Under normal operating conditions, the emergency generator serves as a backup power source after the main power supply fails, and its automatic start-up logic relies on busbar voltage detection. If the emergency generator abnormally starts during the replacement process due to detected voltage fluctuations, it will alter the platform's power distribution topology, potentially causing load contention or phase conflicts with the operating diesel fire pump and diesel booster pump, affecting the power supply stability of the replacement equipment. Therefore, following a preset sequence, the emergency generator's control mode is first switched to manual, removing it from the automatic start-up logic's control range; then, a continuous emergency shutdown signal is output to ensure it is in a stopped state; next, its starting function is suppressed through software locking, forming a multi-layered anti-starting barrier; finally, its starting battery circuit is disconnected, completely cutting off the starting energy source from a physical perspective.
[0044] Simultaneously or subsequently, the configuration control of multiple valves along the pipeline sweep path is executed. Establishing the replacement channel requires seawater to be transported from the diesel fire pump outlet to the subsea pipeline inlet via a booster pump, which necessitates that several key valves along the pipeline sweep path be in specific on / off combinations.
[0045] Specifically, an open command is issued to the valves that need to be opened, and a close command is issued to the valves that need to be closed. After each command is issued, a timer is started and the corresponding valve limit switch feedback signal is continuously monitored. The valve position feedback is direct evidence to determine whether the valve core has actually reached the target position. Compared to relying solely on command issuance, the introduction of position feedback upgrades control from open-loop to closed-loop. Only when all valves have provided the correct position signal before the timer expires is it confirmed that the replacement channel has been physically established successfully.
[0046] Optionally, a fault-tolerant retry mechanism is built-in for handling abnormal valve positioning feedback. If a valve fails to provide a positioning signal before the timer expires, the operation is deemed a failure, and the same valve control command is reissued while the timer is reset to wait again. After repeating the attempts up to the preset maximum number, if the valve still fails to reach the target position, the replacement channel is deemed unable to be established. At this point, the entire replacement process is terminated, and the system enters a safe shutdown state. The tag number of the failed valve and the reason for the failure are written to the local fault log for subsequent maintenance analysis.
[0047] In one embodiment of this application, multiple valves along the scanning path are controlled to establish a replacement channel, and the successful establishment of the replacement channel is determined based on the arrival feedback signals emitted by each valve, including: Issue valve control commands to control multiple valves on the sweeping path to establish a replacement channel, and start a timer to monitor the valve's arrival feedback signal; If a feedback signal is received before the timer expires, the replacement channel is considered to have been successfully established. If no feedback signal is received before the timer expires, the operation is deemed a failure, the same valve control command is issued again, and the timer is restarted. If the valve still fails to reach the target position after the preset maximum number of repetitions has been reached, the entire replacement process will be terminated, a safety shutdown will be performed, and the failed valve tag number and the reason for failure will be written to the local fault log.
[0048] In one specific embodiment of this application, the valve configuration control employs a mechanism combining closed-loop confirmation and fault-tolerant retry. First, an open or closed control command is issued to the target valve on the sweep path. Simultaneously, a timer is started, continuously monitoring the position signal fed back by the valve's limit switch. If a position feedback signal consistent with the command is received within the timer's preset timeout period, it indicates that the valve core has actually moved to the target position, and the node of the replacement channel is confirmed to have been successfully established. The same operation continues for the next valve.
[0049] If a correct position feedback signal is not received before the timer expires, the valve operation is deemed a failure. The same valve control command is then automatically reissued, and the timer is reset to restart. If, after the cumulative number of repeated attempts reaches the preset maximum, the valve still fails to provide a correct position signal, the replacement channel is deemed unable to be established. At this point, the entire replacement process is immediately terminated, and a safety shutdown is performed. Simultaneously, the tag number of the failed valve and the reason for the failure are written to the local fault log for remote retrieval and analysis after communication is restored. This mechanism effectively avoids the problem of prolonged suspension or misjudgment of success in the replacement process due to a single valve jamming or lost feedback signal, significantly improving the system's robustness and fault traceability.
[0050] Optionally, if the channel establishment fails during the replacement process, such as the valve not being in place within the maximum number of repeated attempts, the entire replacement process is terminated, a safe shutdown is performed, and the failed valve tag number and reason are written to the local fault log, which is then retrieved and analyzed by the land after communication is restored.
[0051] The above process, in autonomous emergency mode, executes the emergency generator isolation operation and controls the valves to establish a replacement channel according to a preset sequence. This step produces the following technical effects: First, the isolation operation of the emergency generator eliminates the power interference source of the diesel fire pump and booster pump during the replacement process. If the emergency generator starts abnormally during the replacement, it may change the power distribution logic or cause load competition. Preemptively switching it to manual mode, shutting it off, and locking it ensures the power supply priority and operational stability of the replacement power equipment. Second, the successful establishment of the channel is confirmed by the valve's arrival feedback signal, transforming the open-loop command transmission into a closed-loop confirmation mechanism to accurately perceive the actual physical state of the replacement channel and avoid the risk of seawater failing to reach its destination or crossflow due to valve jamming or failure to arrive. Third, the pre-conduction of the replacement channel shortens the time delay from decision to execution. Once the pump starts, seawater can enter the subsea pipeline, improving the timeliness of the emergency response.
[0052] S130: After the channel replacement is successful, sensor signals from the subsea pipeline are collected, multi-scale transformation is performed on the sensor signals and preset feature indicators are calculated, and a frontal discrimination index is calculated based on the feature indicators. When the frontal discrimination index exceeds a second preset threshold, it is determined that the frontal has passed the monitoring point.
[0053] In this embodiment, the displacement front refers to the fluid interface formed by the seawater injected into the subsea pipeline and the original crude oil inside the pipeline, which moves along the pipeline direction.
[0054] In this embodiment, after the replacement process is started, the diesel fire pump and booster pump are running stably, and seawater has begun to be injected into the subsea pipeline, the real-time pressure signal of the end pressure transmitter is continuously collected, and the characteristic index of the signal is calculated online. Based on this, it is automatically determined whether the replacement front has passed the monitoring point.
[0055] Once the seawater displacement channel is established and injection begins, sensor signals from the end of the subsea pipeline are continuously collected at a fixed sampling frequency. In this embodiment, the sensor signals are acquired through pressure sensors, flow sensors, and timing sensors. Due to the significant differences in density and viscosity between seawater and crude oil, the chaotic characteristics of the pressure signal change abruptly when the displacement front passes through the monitoring point. To capture this abrupt change, a multi-scale coarse-grained transformation is performed on the acquired raw pressure sequence, extracting the multi-scale permutation entropy of the signal from multiple time scales. Simultaneously, a recursive graph is constructed and a deterministic index is calculated. The deviation between the multi-scale permutation entropy and the baseline value is then mapped nonlinearly to obtain a first intermediate quantity, and the deterministic index is mapped fractionally to obtain a second intermediate quantity. Finally, the two are multiplied to obtain the front discrimination index. This index comprehensively reflects the degree of orderliness of the pressure signal and the determinism of the system behavior. When it continuously exceeds a preset threshold, it is determined that the displacement front has passed through the monitoring point, thereby achieving accurate perception based on the chaotic characteristics of the end-pressure and avoiding blind reliance on a fixed displacement duration.
[0056] In one embodiment of this application, performing multi-scale transformation on the sensor signal and calculating preset feature indices includes: The sensor signal is subjected to multi-scale coarse-grained transformation to obtain coarse-grained sequences at multiple time scales; The phase space of the coarse-grained sequence is reconstructed, the probability distribution of the permutation pattern is statistically analyzed, and the normalized permutation entropy is calculated. Based on the sensor signals, a recursive graph is constructed, the diagonal length distribution in the recursive graph is statistically analyzed, and deterministic indices are calculated. The normalized permutation entropy and the deterministic index are used as the feature index.
[0057] Specifically, the raw pressure sequence, composed of sensor signals within the current time window, is extracted from the circular buffer. To analyze the dynamic characteristics of the pressure signals in the sensor signals at multiple time scales, a multi-scale coarse-grained transformation is performed on the raw pressure sequence. The coarse-graining process is performed according to different scale factors. For each scale factor, the raw pressure sequence is divided into several non-overlapping and continuous sub-intervals, and the length of each sub-interval is equal to that scale factor.
[0058] First, the arithmetic mean of all pressure values within each sub-interval is calculated, resulting in a coarse-grained new sequence. The length of this new sequence is approximately the length of the original pressure sequence divided by the scale factor. This coarse-graining transformation is then performed sequentially on sequences with scale factors of 1, 2, 3, and 4, resulting in four coarse-grained pressure sequences at different time scales. This achieves downsampling and local averaging of the original signal, allowing simultaneous observation of rapid fluctuations in the pressure signal at a fine time scale and its trend changes at a coarse time scale.
[0059] Specifically, in this embodiment, during the multi-scale coarse-grained transformation, the scale factors are set to 1, 2, 3, and 4 respectively; the embedding dimension m of the phase space reconstruction is set to 3, and the time delay τ is set to 1; the coarse-grained sequence is generated as follows: for the scale factor s, the original pressure sequence {x} is... i The average of every s points in sequence is used to obtain a new sequence y. j = (x_{(j-1)s+1} + ... + x_{js}) / s, where the underscores represent subscripts.
[0060] Subsequently, for each coarse-grained pressure sequence, a series of consecutive numbers are extracted from the sequence to form a vector in a high-dimensional space. The number of elements in the vector is set to a fixed value, i.e., the embedding dimension, which can be 3. By combining each point in the sequence with its subsequent points into a vector, the one-dimensional pressure time series is mapped to a high-dimensional phase space, thereby revealing the evolutionary trajectory of the system in the phase space. Each reconstructed phase space vector is analyzed, all values within the vector are extracted, and then sorted in ascending order of magnitude.
[0061] After sorting, each value's original position in the vector is moved to a new ordered position. This mapping from the original position to the sorted position is called the permutation pattern. Since the embedding dimension is fixed, the total number of possible permutation patterns is definite. The process iterates through all phase space vectors generated from the entire coarse-grained sequence, counts the frequency of each permutation pattern, and calculates the probability of each pattern occurring.
[0062] Subsequently, based on the probability distribution obtained from the above statistics, the permutation entropy is calculated. In this embodiment, the permutation entropy is used to represent the degree of order and regularity of the signal sequence in the phase space, that is, to measure the randomness of the signal under the embedding dimension. The probability of each permutation pattern occurring is multiplied by the natural logarithm of that probability, and then the calculated results of all patterns are summed and the negative value is taken. When the pressure signal is completely random noise, all permutation patterns occur with equal probability, and the permutation entropy reaches its maximum value; when the pressure signal is a completely deterministic periodic signal, only a few permutation patterns occur, and the permutation entropy is small.
[0063] Next, the calculated permutation entropy is divided by its theoretical maximum value, which is the entropy value when all permutation patterns occur with equal probability. The normalized permutation entropy value is limited to between 0 and 1, facilitating comparisons under different conditions. The normalized permutation entropy is calculated separately for each of the four coarse-grained sequences, eliminating the influence of different embedding dimensions on the entropy dimension. In this embodiment, the normalized permutation entropy is used to represent a quantitative measure of the randomness and orderliness of the pressure signal at different time scales.
[0064] Simultaneously, a recursion graph is constructed based on the sensor signals. The original pressure sequence composed of pressure signals from the sensor signals is reconstructed into phase space vectors, and the Euclidean distance between each pair of phase space vectors is calculated. A preset distance threshold is used. When the Euclidean distance between two phase space vectors is less than this threshold, the state of these two phase space vectors is determined to be recursive, and a value of 1 is recorded at the corresponding position in the recursion graph; otherwise, a value of 0 is recorded. The recursion point patterns on the diagonal and parallel lines of the recursion graph reflect the degree of determinism of the system. By analyzing all continuous diagonal segments parallel to the main diagonal in the recursion graph and counting the frequency of occurrence of diagonal segments of each length, the probability distribution of diagonal lengths is obtained.
[0065] Next, the deterministic index of the probability distribution is calculated. This is the total length of all diagonal segments with a length greater than or equal to 2 (i.e., the sum of the number of times each segment of length appears), divided by the total length of all diagonal segments. The resulting deterministic index DET is: in, P(l) The length of the diagonal in the recursive graph is... l The probability distribution, The value is 2, and N represents the maximum value among the number of rows and columns in the recursion graph. The calculated deterministic index ranges from 0 to 1. When the system exhibits highly deterministic behavior, a long diagonal line appears in the recursion graph, and the deterministic index approaches 1; when the system exhibits random behavior, the diagonal line is very short or non-existent, and the deterministic index approaches 0.
[0066] In one embodiment of this application, calculating the frontal discriminant index based on the characteristic index includes: Based on the normalized permutation entropy at each scale and the seawater baseline permutation entropy, the normalized deviation at each scale is generated, and the normalized deviation at all scales is fused to obtain the average deviation of the multi-scale permutation entropy. The average deviation is nonlinearly mapped using a sigmoid function to obtain the first intermediate quantity; The deterministic index is processed using a fractional function to obtain a second intermediate quantity; Multiply the first intermediate value by the second intermediate value to obtain the frontal discrimination index.
[0067] Specifically, in this embodiment, two statistical parameters are pre-stored: the mean of the arrangement entropy at each scale during the seawater replacement stage, and the standard deviation of the arrangement entropy at each scale during the seawater replacement stage. These two parameters are baseline values calculated based on historical pressure signals collected during the offline commissioning phase when seawater flows stably within the pipeline.
[0068] First, subtract the mean of the corresponding scale from the normalized permutation entropy of the four scales calculated so far, and then divide by the standard deviation of the corresponding scale to obtain the normalized deviation at each scale, which is the multi-scale permutation entropy.
[0069] Subsequently, the normalized deviations at the four scales were arithmetically averaged to obtain the average deviation of the multi-scale permutation entropy. The calculated average deviation reflects the degree of deviation of the current pressure signal's permutation entropy from the seawater baseline state. When the pressure signal exhibits highly chaotic characteristics of a two-phase flow of crude oil and water, the permutation entropy deviates significantly from the seawater baseline, and the average deviation is positive. After the replacement is completed, the pressure signal returns to the seawater state, the permutation entropy approaches the baseline value, and the average deviation approaches 0.
[0070] Then, the average deviation of the calculated multi-scale permutation entropy is nonlinearly mapped through a sigmoid transformation function. In this embodiment, the sigmoid transformation function can be: f(x)=1 / (1+e^(-k*x)), where k is the adjustment slope parameter, and in this embodiment, k can be 2.
[0071] Simultaneously, the deterministic index of the recursive graph is substituted into a fractional function for processing. In this embodiment, the fractional function can be g(y) = y^2 / (1+y^2). This ensures that when the deterministic index is low, the output value of this term is small; when the deterministic index is high, the output value of this term approaches 1.
[0072] Finally, the product of the above two items is taken as the discrimination index of the permutation front at the current moment. The physical meaning of this product result is: the discrimination index will approach 1 only when the permutation entropy of the pressure signal is close to the seawater reference value (indicating that the signal is ordered) and the deterministic index is high (indicating that the system exhibits deterministic behavior); otherwise, the discrimination index will approach 0.
[0073] In this embodiment, the frontal discrimination index is continuously calculated at each moment, and a moving average filter is applied to the frontal discrimination index to eliminate instantaneous noise. When the filtered frontal discrimination index continuously exceeds a preset threshold and remains so for a sufficiently long time, it is determined that the permutation front has stably passed the monitoring point. At this time, the frontal passage flag is switched from logical false to logical true, and the current system clock is recorded as the precise time of frontal passage for use in subsequent steps.
[0074] The above process involves collecting end-point pressure signals after channel replacement, performing multi-scale transformations, calculating characteristic indices, and then calculating the frontal discriminant index to determine whether the front has passed the monitoring point. This step produces the following technical effects: First, by utilizing the chaotic characteristics of the pressure signal rather than the absolute pressure value for judgment, it fundamentally eliminates the influence of differences in geometric parameters such as pipeline length, diameter, and topographic relief, as well as batch differences in crude oil properties, on the judgment benchmark, making the method universal across subsea pipelines and oil fields. Second, multi-scale transformation enables the algorithm to simultaneously capture the rapid chaotic fluctuations of the pressure signal on a fine time scale and the trend changes on a coarse time scale, avoiding the problem of missing key features that may occur with single-scale analysis. Third, by fusing characteristic indices into a single frontal discriminant index, the complex nonlinear chaotic judgment problem is transformed into a threshold comparison problem, significantly reducing the computational complexity of online judgment and enabling it to run in real time on industrial-grade controllers. Fourth, compared with the traditional fixed-duration replacement method, this step achieves real-time perception of the replacement progress, allowing timely termination after replacement, avoiding excessive replacement that wastes power resources, and also preventing insufficient replacement that leads to crude oil residue.
[0075] S140: After determining that the front has passed the monitoring point, the redundant replacement time is dynamically calculated based on the replaced volume, the total volume of the subsea pipeline, and the average replacement flow rate. The first termination time generated based on the redundant replacement time is compared with the second termination time generated based on the preset absolute replacement time, and the earlier one is selected as the replacement termination time.
[0076] In this embodiment, after the replacement front is detected to have passed the monitoring point, a redundant replacement duration is dynamically calculated based on the replaced subsea pipeline volume, the length of the remaining unreplaced section, and the average flow rate throughout the replacement process. Combined with an absolute safety time limit, the command trigger time for termination of replacement is finally generated.
[0077] Specifically, the replaced volume refers to the total volume of seawater injected into the subsea pipeline and displacing crude oil from the start of the replacement process to the present moment. This volume is obtained by integrating the instantaneous flow rate over time using flow meters. The total subsea pipeline volume refers to the total volume of space within the entire subsea pipeline that is available for fluid passage. This volume is derived from the hydraulic calculation report during the engineering design phase and is pre-stored in the system's non-volatile memory, serving as the baseline total for determining the completion of the replacement process. The average replacement flow rate refers to the overall average level of the seawater injection rate throughout the entire replacement process from the start of the replacement process to the present moment. This is calculated by dividing the cumulative instantaneous flow rate of the entire replacement process by the duration of the replacement process, and is used to eliminate the impact of instantaneous flow rate fluctuations caused by pump start-up, shutdown, or speed adjustments on subsequent duration estimations.
[0078] like Figure 2 As shown, in one embodiment of this application, the redundant replacement time is dynamically calculated based on the replaced volume, the total subsea pipeline volume, and the average replacement flow rate, including: S210, subtract the replaced volume from the time of replacement start to the time of the frontal passage from the total subsea pipeline volume to obtain the remaining unreplaced volume; S220, divide the cumulative instantaneous flow rate of the entire replacement process by the duration of the replacement to obtain the average replacement flow rate; S230, the remaining unreplaced volume is divided by the average replacement flow rate to obtain the theoretical evacuation time, and then multiplied by the preset safety redundancy coefficient to obtain the redundant replacement time.
[0079] In this embodiment, the displacement flow rate is continuously integrated and accumulated from the moment the displacement begins. The displacement flow rate signal comes from a flow meter installed on the sweep path. This flow meter transmits the instantaneous flow rate value to a counter or analog input module in the form of a pulse signal or analog signal. The current instantaneous flow rate value is read in each scan cycle and multiplied by the length of the scan cycle to obtain the volume of seawater flowing through the pipe in that cycle. This volume is then accumulated into a dedicated accumulation register.
[0080] The accumulator register is initialized to 0 at the start of the displacement process and incremented by one value in each subsequent scan cycle. When the displacement front passes the monitoring point, the current value of the accumulator register is read; this value represents the total volume of seawater injected into the pipeline and displacing the crude oil from the start of the displacement until the front passes. This integral accumulation process employs an accumulation algorithm with error compensation to reduce integration errors caused by the discretization of the sampling period.
[0081] In this embodiment, the total volume parameters of the entire subsea pipeline are pre-stored in non-volatile memory. These parameters are derived from the hydraulic calculation report during the engineering design phase. The total pipeline volume is subtracted from the cumulative volume already replaced to obtain the volume occupied by the pipeline segment not yet replaced by seawater. This volume corresponds to the internal space of the pipeline from downstream of the monitoring point to the pipeline's final outlet, where some undisplaced crude oil still remains.
[0082] This embodiment uses an accumulator to sum all instantaneous flow rates since the start of the replacement process, while a timer records the total elapsed time from the start of the replacement to the current moment. Dividing the sum of the accumulated flow rates by the total time yields the average flow rate throughout the replacement process. This average flow rate reflects the overall seawater injection rate during the entire replacement process, eliminating the impact of instantaneous flow rate fluctuations caused by pump start-up / stop and speed adjustments.
[0083] The redundant replacement time is dynamically calculated based on three parameters: the safety redundancy factor, the remaining unreplaced volume, and the average flow rate throughout the pipeline. The safety redundancy factor is a preset constant greater than 1, which physically represents a margin reserved for incomplete replacement. Specifically, since the state of the crude oil in the downstream pipeline is unknown after the replacement front passes the monitoring point, and there may be local sedimentation or adhesion, seawater needs to be continuously injected for a longer period than the theoretical emptying time to ensure that the remaining crude oil is completely pushed out of the end of the subsea pipeline. The value of the safety redundancy factor can be calibrated engineeringly based on factors such as pipeline length and crude oil properties. Dividing the remaining unreplaced volume by the average flow rate throughout the pipeline yields the theoretical time required to empty the remaining section at the current average flow rate. Then, multiplying this theoretical time by the safety redundancy factor yields the actual redundant replacement time.
[0084] In one embodiment of this application, comparing a first termination time generated based on the redundancy permutation duration with a second termination time generated based on a preset absolute permutation duration, and selecting the earlier one as the permutation termination time, includes: The first termination time is obtained by adding the redundant replacement duration to the replacement start time. The second termination time is obtained by adding the preset absolute replacement duration limit to the replacement start time; Compare the first termination time with the second termination time, and take the earlier one as the termination time of the substitution.
[0085] In this embodiment, a preset upper limit for absolute replacement time is read from the memory. This upper limit is derived from the hydraulic verification results of the subsea pipeline replacement scheme and is the maximum safe time to complete the replacement of the entire subsea pipeline, as confirmed by calculation. If this time is exceeded, the replacement must be terminated even if it is not yet completed, to avoid prolonged overload operation of the pump unit or other safety hazards.
[0086] In this embodiment, the total elapsed time from the start of the replacement process to the current time is calculated, and the redundant replacement time is added to obtain an estimated offset of the termination time relative to the start time. This offset is then compared with the upper limit of the absolute replacement time, and the smaller of the two values is taken as the final effective total replacement time. This comparison operation ensures that no matter how large the calculated value of the redundant replacement time is, the total system runtime will not exceed the preset safety limit. The replacement start time is added to the calculated effective total replacement time to obtain a specific termination time. This termination time serves as the absolute time reference for subsequent shutdown operations.
[0087] Optionally, while calculating the termination time, a termination condition monitoring logic is generated. The system clock will be continuously monitored, and a replacement termination instruction will be triggered when the current time reaches or exceeds the calculated termination time.
[0088] Optionally, an auxiliary monitoring condition is set: if the flow meter detects that the instantaneous flow rate is continuously lower than a certain lower limit and the cumulative volume is close to the total volume of the subsea pipeline before the termination time is reached, a termination command is issued in advance as a protection against hydraulic anomalies.
[0089] Optionally, after the redundancy replacement duration is calculated, the average flow rate and the cumulative replaced volume continue to be updated at a lower frequency. If a significant change in the average flow rate is detected, the redundancy replacement duration is recalculated, and the termination time is updated accordingly. However, this dynamic update is subject to a rate-of-change limitation, meaning that the adjustment to the termination time in each update must not exceed a preset maximum step size to prevent drastic changes in the termination time due to instantaneous flow fluctuations.
[0090] Optionally, a one-way update rule can be set for the termination time, meaning the termination time can only be postponed (i.e., the replacement time can be increased), but cannot be brought forward (i.e., premature termination). The design principle of this rule is: it is better to ensure safety by extending the replacement time than to stop prematurely due to calculation errors, resulting in incomplete replacement.
[0091] Optionally, once the termination time has been calculated and verified for stability, the time is stored in a dedicated register. This register remains valid throughout the redundancy replacement process and can be read by the shutdown control module at any time.
[0092] Optionally, the valid flag for termination time can be set to logical true, indicating that the termination condition has been generated and can be used for subsequent shutdown judgment. If the calculation process fails for any reason, such as loss of flow meter signal, the valid flag will remain logical false, and the system will switch to fail-safe mode, using the upper limit of absolute replacement time as the termination criterion.
[0093] In one embodiment of this application, before reaching the replacement termination time, the process includes: During the redundant replacement process, the average flow rate and the cumulative volume replaced are continuously updated at a frequency lower than the baseline scan frequency. The redundancy replacement duration is recalculated based on the updated average flow and cumulative volume, and the first termination time is updated according to the recalculated redundancy replacement duration. Compare the updated first termination time with the second termination time again, and take the earlier one as the updated replacement termination time. In each update, the adjustment range of the termination time of the replacement shall not exceed the preset maximum step size, and the termination time is only allowed to be adjusted in the direction of postponement, and is not allowed to be adjusted in the direction of advancement.
[0094] In the above process, after determining that the front has passed, the redundant replacement time is dynamically calculated based on the replaced volume, the total subsea pipeline volume, and the average replacement flow rate. The first termination time based on the redundant replacement time is compared with the second termination time based on the upper limit of the absolute replacement time, and the earlier one is selected as the replacement termination time. The above process produces the following technical effects: First, the dynamic calculation of the redundancy replacement time enables the system to adaptively adjust the subsequent replacement time according to the actual replacement flow rate. When the replacement flow rate is large, the redundancy time is automatically shortened, and when the replacement flow rate is small, the redundancy time is automatically extended, realizing intelligent compensation for the uncertainty of the replacement process. Second, the introduction of the safety redundancy coefficient provides an engineering margin for the complete discharge of residual crude oil, effectively addressing actual factors that the ideal venting model cannot cover, such as adhesion to the inner wall of the pipeline and local deposition. Third, by comparing the termination time based on dynamic calculation with the termination time based on the absolute safety upper limit and selecting the earlier one, a dual protection mechanism is formed: it ensures that the replacement is completed as much as possible, and also ensures that it will not run indefinitely under any abnormal conditions, breaking through the limitations of a single control mode. Fourth, this step connects the front face with the subsequent time control through this physical event, forming a hybrid control architecture of event triggering plus time compensation, which takes into account both the accuracy of physical perception and the reliability of time control.
[0095] S150, when the replacement termination time is reached, the power equipment is stopped, the valve is closed, and the auxiliary system is shut down in a preset hierarchical order, and the system enters a low-power silent mode.
[0096] In this embodiment, when the termination time is reached, the pump stop operation, valve closing operation, and auxiliary system power-off operation are executed in sequence according to the pre-set hierarchical order. Finally, all key operating parameters are written to local storage, so that the platform enters a low-power safe silent state.
[0097] In this embodiment, a high-precision real-time clock is maintained and continuously compared with the termination time register generated in the above process. The current clock value is read in each scan cycle and the difference is calculated with the value stored in the termination time register. When the difference is 0 or changes from positive to negative, the termination time is determined to have been reached. Once the termination time condition is met, a state-locked mode is entered. In this mode, any external or internal factors are prohibited from restarting the already shut-down equipment, and any instructions are prohibited from modifying the generated termination decision. Simultaneously, the termination execution flag is set to logical true, and the system clock value at the termination time is recorded for subsequent state recording.
[0098] In one embodiment of this application, the preset hierarchical order includes: Level 1: Power equipment shutdown, including first stopping the replacement booster pump and confirming the shutdown, then after a first preset time delay, stopping the fire pump, performing start suppression lock and disconnecting its starter battery circuit; The second stage involves valve closure, including a second preset time delay followed by the sequential closure of valves along the sweeping path in order of distance from the power source. After each valve is closed, the position feedback signal from the limit switch is used to determine whether the position is in place. The third level involves shutting down the auxiliary systems, including closing the outlet valve of the nitrogen cylinder group and performing a graded load shedding operation, while only maintaining power supply to the control, communication, and monitoring storage equipment.
[0099] In this embodiment, the first-level shutdown operation is performed: power equipment shutdown. This includes the shutdown of the diesel booster pump. The control panel of the diesel booster pump is hardwired to the dedicated control system, and a shutdown command signal is sent to the control panel via the output module. This signal triggers the shutdown logic circuit inside the control panel, cutting off the fuel supply and disconnecting the starting circuit. After issuing the shutdown command, the booster pump's operating status feedback signal is continuously monitored. This feedback signal comes from the pump set's speed sensor or the auxiliary contact of the operating contactor. When this signal changes from high to low and remains low for more than three consecutive scan cycles, it is confirmed that the booster pump has stopped rotating.
[0100] Optionally, after confirming that the booster pump has completely stopped, a delay timer is started. This delay is designed to allow sufficient pressure release within the pipeline, preventing water hammer during subsequent operations. During the delay, the status of all pumps and valves is monitored, but no new operational commands are executed.
[0101] In this embodiment, a shutdown sequence for the diesel fire pumps is executed. This sequence comprises three sub-operations, executed sequentially. The first sub-operation is to stop the operation of both diesel fire pumps by sending shutdown commands to the control panels of diesel fire pump A and diesel fire pump B, and monitoring their respective operation feedback signals until the operation signals of both pumps return to zero. The second sub-operation is to suppress the automatic start of the diesel fire pumps by writing a start-suppression flag bit to the control panels of both fire pumps. Once this flag bit is written, the logic inside the control panel will refuse to respond to any automatic start requests from pressure switches or other sensors. This operation ensures that during the subsequent silent period, even if the fire pipeline pressure drops, the fire pumps will not automatically start and consume diesel fuel. The third sub-operation is to disconnect the starting batteries of the diesel fire pumps. The electromagnetic switches on the battery output lines of the two fire pumps are controlled via a relay output module. After outputting a disconnect signal to the electromagnetic switch, the circuit between the battery and the starter motor is physically severed. The successful execution of the disconnection operation is confirmed by reading the feedback signal from the auxiliary contacts of the electromagnetic switches. The electromagnetic switch is a DC contactor, whose coil is driven by the control system output module, and its contacts are connected in series between the positive terminal of the battery and the starter motor.
[0102] After the diesel fire pump shutdown sequence is completed, the second-stage shutdown is executed: the valves are closed. A one-minute delay timer is then restarted. This delay is also used for pipeline pressure stabilization.
[0103] After the delay period, all valves along the sweep path are closed. The valves are closed sequentially from closest to furthest from the diesel fire pump outlet to minimize the cumulative water hammer effect. First, the valves at the diesel fire pump outlet and the booster pump outlet are closed; these are the closest shut-off valves to the power source, and prioritizing their closure confines the high-pressure seawater to a short section of pipe near the pump outlet. Next, the valves at the subsea pipeline inlet and those along the replacement path are closed; these valve closures isolate the main part of the sweep path from the subsea pipeline. Finally, the two isolation valves, located on auxiliary pipelines, are closed to ensure that all possible seawater pathways are physically cut off.
[0104] Optionally, for each valve, after issuing a closing command, the closure is confirmed by reading the closed-position feedback signal from the limit switch. If a valve fails to provide a closed-position signal within a specified time, the closing command is issued a maximum of three times. If the valve still fails after three attempts, its status is marked as abnormal, and a fault code is recorded in the local log, but the subsequent shutdown process is not interrupted.
[0105] After all valve closure operations are completed, the third-level shutdown is executed: auxiliary system shutdown. In this embodiment, the auxiliary system includes various auxiliary equipment that provides indirect power output support for the normal production and emergency operations of the offshore production platform. Specifically, this includes: nitrogen cylinder groups (providing a power source for pneumatic valve actuators), and non-critical loads in the uninterruptible power supply system (such as air conditioning equipment, non-safety-related control circuits, some fans, and non-critical instruments). In the third-level operation of the graded shutdown, the power supply to these auxiliary devices will be cut off sequentially to reduce power consumption and extend the operating time of critical monitoring equipment, with only the control, communication, and monitoring storage equipment being powered.
[0106] First, close the outlet valve of the nitrogen cylinder bank. The nitrogen cylinder bank provides power to multiple pneumatic valve actuators, sending a closing command to the outlet solenoid valve to disconnect the nitrogen cylinder bank from the downstream gas supply network. This operation prevents nitrogen depletion due to pipeline leaks during subsequent quiescent periods. After closing, initiate a one-minute delay to allow residual pressure in the gas supply network to release.
[0107] After the delay ends, the uninterruptible power supply (UPS) system performs a load shedding operation. During the shedding period, the UPS system supplies power to multiple loads, including the dedicated control system, communication equipment, instruments, and some control circuits. Upon entering the silent phase, all loads except those essential for operation must be powered off to extend the UPS's battery life. The power management system sends tiered load shedding commands to the UPS system. The first-level load shedding command cuts off power to non-critical instruments, lighting, and some fans. The second-level load shedding command is issued after confirming the successful execution of the first-level load shedding, cutting off power to air conditioning equipment and non-safety-related control circuits. After these two levels of load shedding, the UPS system maintains continuous power supply only to three core loads: the dedicated control system itself, communication link monitoring equipment, and the hard disk recorder of the closed-circuit television monitoring system.
[0108] Optionally, after all shutdown operations are completed, the entire process parameters of this autonomous emergency replacement are written to the local non-volatile memory. The written data includes: replacement start time, replacement front passage time, replacement end time, total replacement duration, total replacement volume, average flow rate throughout the replacement process, front discrimination index value at the judgment time, success and failure status of each pump and valve operation, and fault codes for any abnormal events.
[0109] Optionally, the replacement end flag is set to logical true. Changes in this flag's state are synchronously recorded in the operation log, including the timestamp of the state change and the source of the termination condition that triggered it. A final snapshot of all internal process variables is saved, including the instantaneous readings of each pressure transmitter, temperature transmitter, and flow meter at the moment of termination. This data can be remotely retrieved by the land control center after communication is restored for analyzing the replacement effect and diagnosing potential problems.
[0110] Optionally, after the above operations are completed, the system switches to a safe silent mode. In this mode, any active control command output is stopped, and all output modules are placed in a safe zero state. Simultaneously, all non-essential communication ports and data processing tasks are shut down, and the CPU's operating frequency is reduced to the minimum sustaining frequency to minimize the power consumption of the uninterruptible power supply system.
[0111] In one embodiment of this application, after entering the low-power silent mode, the following is also included: Receive and process fire and gas monitoring signals, and wake up the output module to execute emergency response when a fire or gas leak is detected; Send heartbeat detection messages to the land side and listen for response signals to detect the status of the communication link recovery; A real-time clock is continuously running to record time information during periods of silence.
[0112] In one embodiment of this application, after entering a low-power silent mode, three core functions continue to operate. First, the reception and processing of fire and gas monitoring signals; if a fire or gas leak signal is detected during the silent period, some output modules can be woken up to execute an emergency response. Second, the status monitoring of the communication link continues, sending heartbeat detection messages to the land-side gateway and continuously listening for response signals to ensure immediate detection after sea-land communication is restored. Third, the continuous counting of the real-time clock ensures the system can accurately record the duration of the silent period. In the safe silent mode, it operates with an extremely low scan cycle, spending most of its time in sleep mode, only performing the above three core monitoring tasks at preset wake-up times. This low-power operating mode ensures that the uninterruptible power supply system's battery can support the system until personnel return to the platform, or until the platform is remotely woken up by land commands after communication is restored.
[0113] The above process, upon reaching the termination time of the replacement, executes the shutdown of power equipment, valve closure, and auxiliary system shutdown according to a preset hierarchical sequence, and enters a low-power silent mode. This step produces the following technical effects: First, the hierarchical execution makes the shutdown process orderly and controllable. The timing arrangement of stopping the pump before closing the valve avoids the risk of pressure buildup or pipeline overpressure caused by the pump continuing to run after the valve is closed. The order of closing the main passage valve before closing the isolation valve ensures that each section of pipeline is gradually isolated from the power source, reducing the cumulative effect of water hammer impact. Second, the delay settings between each operation stage play a role in pressure relief and system stability. This ensures that the residual energy from the previous operation is fully dissipated before the next operation begins, reducing the cumulative mechanical stress on the equipment. Third, the tiered shutdown of the auxiliary system and the switching of the low-power silent mode allow the uninterruptible power supply to switch from a high-load distribution mode during replacement to a low-power maintenance mode during silent periods, significantly extending the battery-powered runtime and ensuring that the system can maintain critical monitoring functions until communication is restored. Fourth, writing system status parameters into local memory preserves the original basis for post-fault analysis and process review, which can be transmitted back to land after communication is restored, forming a complete closed-loop data chain.
[0114] This technical solution triggers autonomous emergency response through multi-link interruption detection, avoiding single-point misjudgment. After isolating the emergency generator and confirming the establishment of the replacement channel, the chaotic characteristics of the terminal pressure signal are used to identify the replacement front, enabling real-time monitoring of the replacement progress and replacing blind timed replacement. Based on the actual replacement volume, the redundancy duration is dynamically calculated and compared with the absolute safety upper limit to generate a termination time that balances completion and safety. Finally, through graded shutdown and orderly power cut-off, and transition to low-power silence, the system effectively extends the endurance of key monitoring modules while ensuring thorough replacement. This achieves closed-loop control of the replacement process and sequential shutdown of equipment, ensuring the safety of pipeline replacement and low-power standby of equipment under communication loss, and improving the reliability and stability of autonomous emergency control of oilfield offshore production platforms in the event of communication loss.
[0115] The following describes an embodiment of the autonomous emergency control system for communication loss of an offshore oilfield production platform according to this application, which can be used to execute the autonomous emergency control method for communication loss of an offshore oilfield production platform in the above embodiments of this application. It is understood that the autonomous emergency control system for communication loss of an offshore oilfield production platform can be a computer program (including program code) running on a computer device. For example, the autonomous emergency control system for communication loss of an offshore oilfield production platform may be an industrial application software or industrial control management software installed to achieve industrial cloud computing of industrial big data generated during the production process through an industrial cloud platform. The autonomous emergency control system for communication loss of an offshore oilfield production platform can be used to execute the corresponding steps in the method provided in the embodiments of this application. For details not disclosed in the embodiments of the autonomous emergency control system for communication loss of an offshore oilfield production platform of this application, please refer to the embodiments of the autonomous emergency control method for communication loss of an offshore oilfield production platform described above in this application.
[0116] Figure 3 A block diagram of an autonomous emergency control system for communication loss of an offshore oilfield production platform according to an embodiment of this application is shown.
[0117] Reference Figure 3 As shown, an autonomous emergency control system for communication loss of an offshore oilfield production platform according to one embodiment of this application includes: Monitoring module 310 is used to monitor the status of at least two independent communication links in an offshore oilfield production platform. When it is determined that all communication links are interrupted and the interruption duration reaches a first preset threshold, it switches to autonomous emergency mode. The isolation module 320 is used to perform emergency generator isolation operations in a preset sequence in autonomous emergency mode, control multiple valves on the sweeping path to establish a replacement channel, and determine the success of the replacement channel establishment based on the arrival feedback signals sent by each valve. The discrimination module 330 is used to collect sensor signals from the subsea pipeline after successful channel replacement, perform multi-scale transformation on the sensor signals and calculate preset feature indicators, calculate the front discrimination index based on the feature indicators, and determine that the front has passed the monitoring point when the front discrimination index exceeds a second preset threshold; the front discrimination index represents the degree of deviation of the pressure at the end of the current subsea pipeline from the seawater reference state; the sensor signals are collected by pressure sensors, flow sensors and timing sensors; The timing module 340 is used to dynamically calculate the redundant replacement time based on the replaced volume, the total volume of the subsea pipeline, and the average replacement flow rate after determining that the front has passed the monitoring point. It compares the first termination time generated based on the redundant replacement time with the second termination time generated based on the preset absolute replacement time and selects the earlier one as the replacement termination time. The shutdown module 350 is used to execute the shutdown of power equipment, valve closure, and auxiliary system shutdown in a preset hierarchical sequence when the replacement termination time is reached, and enter a low-power silent mode.
[0118] In this application, based on the aforementioned scheme, the establishment of a replacement channel by multiple valves on the control sweep path, and the determination of successful establishment of the replacement channel based on the arrival feedback signal issued by each valve, includes: issuing a valve control command to control multiple valves on the sweep path to establish a replacement channel, and starting a timer to monitor the arrival feedback signal of the valve; if an arrival feedback signal is received before the timer expires, the replacement channel is determined to be established successfully; if no arrival feedback signal is received before the timer expires, the operation is determined to be a failure, the same valve control command is issued again and the timer is restarted; after the repeated operation reaches a preset maximum number of repetitions, if the valve still has not reached the target position, the entire replacement process is terminated, a safety shutdown is performed, and the failed valve tag number and the reason for failure are written to the local fault log.
[0119] In this application, based on the aforementioned scheme, the step of performing multi-scale transformation on the sensor signal and calculating preset feature indices includes: performing multi-scale coarse-grained transformation on the sensor signal to obtain coarse-grained sequences at multiple time scales; reconstructing the phase space of the coarse-grained sequences, statistically analyzing the probability distribution of permutation patterns, and calculating the normalized permutation entropy; constructing a recursion graph based on the sensor signal, statistically analyzing the diagonal length distribution in the recursion graph, and calculating a deterministic index; and using the normalized permutation entropy and the deterministic index as the feature indices.
[0120] In this application, based on the aforementioned scheme, the calculation of the frontal discriminant index based on the characteristic index includes: generating normalized deviations for each scale based on the normalized permutation entropy and the seawater baseline permutation entropy at each scale; fusing the normalized deviations at all scales to obtain the average deviation of the multi-scale permutation entropy; performing nonlinear mapping on the average deviation using a sigmoid function to obtain a first intermediate quantity; processing the deterministic index using a fractional function to obtain a second intermediate quantity; and multiplying the first intermediate quantity by the second intermediate quantity to obtain the frontal discriminant index.
[0121] In this application, based on the aforementioned scheme, the step of dynamically calculating the redundant replacement time according to the replaced volume, the total subsea pipeline volume, and the average replacement flow includes: subtracting the replaced volume from the start of replacement to the moment the frontal face passes from the total subsea pipeline volume to obtain the remaining unreplaced volume; dividing the cumulative instantaneous flow value of the entire replacement process by the replacement duration to obtain the average replacement flow; dividing the remaining unreplaced volume by the average replacement flow to obtain the theoretical venting time, and then multiplying it by a preset safety redundancy coefficient to obtain the redundant replacement time.
[0122] In this application, based on the aforementioned scheme, the step of comparing the first termination time generated based on the redundant permutation duration with the second termination time generated based on a preset absolute permutation duration and selecting the earlier one as the permutation termination time includes: adding the redundant permutation duration to the permutation start time to obtain the first termination time; adding the preset upper limit of the absolute permutation duration to the permutation start time to obtain the second termination time; comparing the first termination time with the second termination time and selecting the earlier one as the permutation termination time.
[0123] In this application, based on the aforementioned scheme, before reaching the replacement termination time, the process includes: during the redundant replacement execution, continuously updating the average flow rate and the cumulative volume replaced throughout the replacement process at a frequency lower than the baseline scan frequency; recalculating the redundant replacement duration based on the updated average flow rate and cumulative volume, and updating the first termination time according to the recalculated redundant replacement duration; comparing the updated first termination time with the second termination time again, and taking the earlier one as the updated replacement termination time; wherein, the adjustment range of the replacement termination time for each update does not exceed the preset maximum step size, and the termination time is only allowed to be adjusted in the direction of postponement, and is not allowed to be adjusted in the direction of advancement.
[0124] In this application, based on the aforementioned scheme, the preset hierarchical sequence includes: Level 1, power equipment shutdown, including first stopping the booster pump for replacement and confirming shutdown, delaying for a first preset time, stopping the fire pump, performing start-up suppression lock on it, and disconnecting its starter battery circuit; Level 2, valve closure, including delaying for a second preset time again, closing each valve on the sweeping path in order of proximity to the power source, and determining whether the position is reached after each valve is closed by a position feedback signal issued by a limit switch; Level 3, auxiliary system shutdown, including closing the outlet valve of the nitrogen cylinder group and performing a graded load shedding operation, retaining power supply only to the control, communication, and monitoring storage devices.
[0125] In this application, based on the aforementioned scheme, it further includes: receiving and processing fire and gas monitoring signals, waking up the output module to perform emergency response when a fire or gas leak is detected; sending heartbeat detection messages to the land side and listening for response signals to detect the recovery status of the communication link; and continuously running a real-time clock to record time information during the silent period.
[0126] This technical solution triggers autonomous emergency response through multi-link interruption detection, avoiding single-point misjudgment. After isolating the emergency generator and confirming the establishment of the replacement channel, the chaotic characteristics of the terminal pressure signal are used to identify the replacement front, enabling real-time monitoring of the replacement progress and replacing blind timed replacement. Based on the actual replacement volume, the redundancy duration is dynamically calculated and compared with the absolute safety upper limit to generate a termination time that balances completion and safety. Finally, through graded shutdown and orderly power cut-off, and transition to low-power silence, the system effectively extends the endurance of key monitoring modules while ensuring thorough replacement. This achieves closed-loop control of the replacement process and sequential shutdown of equipment, ensuring the safety of pipeline replacement and low-power standby of equipment under communication loss, and improving the reliability and stability of autonomous emergency control of oilfield offshore production platforms in the event of communication loss.
[0127] Figure 4 A schematic diagram of the structure of a computer system suitable for implementing the electronic device of the present application is shown.
[0128] It should be noted that the computer system of the electronic device in this embodiment is only an example and should not impose any limitations on the function and scope of use of the embodiments of this application.
[0129] In this embodiment, the computer system includes a central processing unit 401, which can perform various appropriate actions and processes based on programs stored in read-only memory 402 or programs loaded from storage section 408 into random access memory 403, such as executing the autonomous emergency control method for communication loss of an oilfield offshore production platform described in the above embodiment. The random access memory 403 also stores various programs and data required for system operation, thereby realizing big data storage and big data management. The central processing unit 401, read-only memory 402, and random access memory 403 are interconnected via bus 404. Input / output interface 405 is also connected to bus 404.
[0130] The following components are connected to the input / output interface 405: an input section 406 including a keyboard, mouse, etc.; an output section 407 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 408 including a hard disk, etc.; and a communication section 409 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 409 performs communication processing via a network such as the Internet. A drive 410 is also connected to the input / output interface 405 as needed. A removable medium 411, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 410 as needed so that computer programs read from it can be installed into the storage section 408 as needed.
[0131] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 409, and / or installed from removable medium 411. When the computer program is executed by central processing unit 401, it performs various functions defined in the system of this application.
[0132] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying a computer-readable computer program. Such transmitted data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.
[0133] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. Each block in a flowchart or block diagram may represent a module, segment, or portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0134] The units described in the embodiments of this application can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.
[0135] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various alternative implementations described above.
[0136] On the other hand, this application also provides a computer-readable medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable medium carries one or more programs, which, when executed by the electronic device, enable the electronic device to implement the autonomous emergency control method for communication loss of an offshore oilfield production platform as described in the above embodiments.
[0137] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0138] Through the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, touch terminal, or network device, etc.) to execute the methods according to the embodiments of this application.
[0139] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the embodiments disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.
[0140] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. An autonomous emergency control method for communication loss of an offshore oilfield production platform, characterized in that, include: Monitor the status of at least two independent communication links in the offshore production platform of the oilfield. When it is determined that all communication links are interrupted and the interruption duration reaches the first preset threshold, switch to autonomous emergency mode. In autonomous emergency mode, the emergency generator isolation operation is performed in a preset sequence, multiple valves on the sweeping path are controlled to establish a replacement channel, and the establishment of the replacement channel is determined by the arrival feedback signal sent by each valve. After the channel replacement is successful, sensor signals from the subsea pipeline are collected. The sensor signals are then subjected to multi-scale transformation and preset characteristic indices are calculated. Based on the characteristic indices, a frontal discrimination index is calculated. When the frontal discrimination index exceeds a second preset threshold, it is determined that the front has passed the monitoring point. The frontal discrimination index represents the degree of deviation of the pressure at the current end of the subsea pipeline from the seawater baseline state. The sensor signals are collected by pressure sensors, flow sensors, and timing sensors. After determining that the front has passed the monitoring point, the redundant replacement time is dynamically calculated based on the replaced volume, the total volume of the subsea pipeline, and the average replacement flow rate. The first termination time generated based on the redundant replacement time is compared with the second termination time generated based on the preset absolute replacement time, and the earlier one is selected as the replacement termination time. The redundant replacement time represents the estimated length of time that additional seawater needs to be continuously injected after the front has passed the monitoring point to ensure that the residual crude oil in the subsea pipeline is completely discharged. When the replacement termination time is reached, the power equipment is shut down, the valves are closed, and the auxiliary system is shut down in a preset hierarchical order, and the system enters a low-power silent mode.
2. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to claim 1, characterized in that, Multiple valves along the sweeping path are controlled to establish a replacement channel. The success of the replacement channel establishment is determined based on the arrival feedback signals from each valve, including: Issue valve control commands to control multiple valves on the sweeping path to establish a replacement channel, and start a timer to monitor the valve's arrival feedback signal; If a feedback signal is received before the timer expires, the replacement channel is considered to have been successfully established. If no feedback signal is received before the timer expires, the operation is deemed a failure, the same valve control command is issued again, and the timer is restarted. If the valve still fails to reach the target position after the preset maximum number of repetitions has been reached, the entire replacement process will be terminated, a safety shutdown will be performed, and the failed valve tag number and the reason for failure will be written to the local fault log.
3. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to claim 1, characterized in that, Perform multi-scale transformation on the sensor signal and calculate preset feature indices, including: The sensor signal is subjected to multi-scale coarse-grained transformation to obtain coarse-grained sequences at multiple time scales; The phase space of the coarse-grained sequence is reconstructed, the probability distribution of the permutation pattern is statistically analyzed, and the normalized permutation entropy is calculated. Based on the sensor signals, a recursive graph is constructed, the diagonal length distribution in the recursive graph is statistically analyzed, and deterministic indices are calculated. The normalized permutation entropy and the deterministic index are used as the feature index.
4. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to claim 3, characterized in that, The calculation of the frontal discrimination index based on the aforementioned feature indicators includes: Based on the normalized permutation entropy at each scale and the seawater baseline permutation entropy, the normalized deviation at each scale is generated, and the normalized deviation at all scales is fused to obtain the average deviation of the multi-scale permutation entropy. The average deviation is nonlinearly mapped using a sigmoid function to obtain the first intermediate quantity; The deterministic index is processed using a fractional function to obtain a second intermediate quantity; Multiply the first intermediate value by the second intermediate value to obtain the frontal discrimination index.
5. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to claim 1, characterized in that, The redundant replacement time is dynamically calculated based on the replaced volume, the total subsea pipeline volume, and the average replacement flow rate, including: Subtract the replaced volume from the time of replacement start to the time of frontal passage from the total subsea pipeline volume to obtain the remaining unreplaced volume; Divide the cumulative instantaneous flow rate of the entire displacement process by the duration of the displacement to obtain the average displacement flow rate. The theoretical emptying time is obtained by dividing the remaining unreplaced volume by the average replacement flow rate, and then multiplied by the preset safety redundancy coefficient to obtain the redundant replacement time.
6. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to claim 5, characterized in that, The first termination time generated based on the redundancy permutation duration is compared with the second termination time generated based on the preset absolute permutation duration, and the earlier one is selected as the permutation termination time, including: The first termination time is obtained by adding the redundant replacement duration to the replacement start time. The second termination time is obtained by adding the preset absolute replacement duration limit to the replacement start time; Compare the first termination time with the second termination time, and take the earlier one as the termination time of the substitution.
7. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to claim 6, characterized in that, Before reaching the termination time of the replacement, including: During the redundant replacement process, the average flow rate and the cumulative volume replaced are continuously updated at a frequency lower than the baseline scan frequency. The redundancy replacement duration is recalculated based on the updated average flow and cumulative volume, and the first termination time is updated according to the recalculated redundancy replacement duration. Compare the updated first termination time with the second termination time again, and take the earlier one as the updated replacement termination time. In each update, the adjustment range of the termination time of the replacement shall not exceed the preset maximum step size, and the termination time is only allowed to be adjusted in the direction of postponement, and is not allowed to be adjusted in the direction of advancement.
8. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to claim 1, characterized in that, The preset hierarchical order includes: Level 1: Power equipment shutdown, including first stopping the replacement booster pump and confirming the shutdown, then after a first preset time delay, stopping the fire pump, performing start suppression lock and disconnecting its starter battery circuit; The second stage involves valve closure, including a second preset time delay followed by the sequential closure of valves along the sweeping path in order of distance from the power source. After each valve is closed, the position feedback signal from the limit switch is used to determine whether the position is in place. The third level involves shutting down the auxiliary systems, including closing the outlet valve of the nitrogen cylinder group and performing a graded load shedding operation, while only maintaining power supply to the control, communication, and monitoring storage equipment.
9. The autonomous emergency control method for communication loss of an offshore oilfield production platform according to any one of claims 1-8, characterized in that, After entering low-power silent mode, it also includes: Receive and process fire and gas monitoring signals, and wake up the output module to execute emergency response when a fire or gas leak is detected; Send heartbeat detection messages to the land side and listen for response signals to detect the status of the communication link recovery; A real-time clock is continuously running to record time information during periods of silence.
10. An autonomous emergency control system for communication loss on an offshore oilfield production platform, characterized in that: include: The monitoring module is used to monitor the status of at least two independent communication links in the offshore production platform of the oilfield. When it is determined that all communication links are interrupted and the interruption duration reaches the first preset threshold, it switches to the autonomous emergency mode. The isolation module is used to perform emergency generator isolation operations in a preset sequence in autonomous emergency mode, control multiple valves on the sweeping path to establish a replacement channel, and determine the success of the replacement channel establishment based on the arrival feedback signals sent by each valve. The discrimination module is used to collect sensor signals from the subsea pipeline after successful channel replacement, perform multi-scale transformation on the sensor signals and calculate preset feature indicators, calculate the front discrimination index based on the feature indicators, and determine that the front has passed the monitoring point when the front discrimination index exceeds a second preset threshold; the front discrimination index represents the degree of deviation of the pressure at the current end of the subsea pipeline from the seawater baseline state; the sensor signals are collected by pressure sensors, flow sensors and timing sensors; The timing module is used to dynamically calculate the redundant replacement time based on the replaced volume, the total volume of the subsea pipeline, and the average replacement flow rate after the frontal surface passes the monitoring point. It compares the first termination time generated based on the redundant replacement time with the second termination time generated based on the preset absolute replacement time and selects the earlier one as the replacement termination time. The redundant replacement time represents the estimated length of time that additional seawater needs to be continuously injected after the frontal surface passes the monitoring point to ensure that the residual crude oil in the subsea pipeline is completely discharged. The shutdown module is used to execute the shutdown of power equipment, valve closure, and auxiliary system shutdown in a preset hierarchical sequence when the replacement termination time is reached, and enter a low-power silent mode.
Citation Information
Patent Citations
Communication self-inspection and emergency shutdown method for offshore wind turbine generator
CN120321154A
One-button type automatic replacement triggering method and system for offshore oilfield management and control platform
CN121300091A