AGC safety control design method and system based on FEMA theory

CN122595564APending Publication Date: 2026-08-18STATE GRID ANHUI ELECTRIC POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610720751.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-25
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

[0004]然而,现有技术仍存在明显缺陷:缺乏从功能设计源头出发的系统性防误理论指导,未能覆盖功能策划、失效模式识别、风险量化评估等全流程安全设计环节

Benefits of technology

[0074]Beneficial Effects: Compared with existing technologies, this invention has the following significant advantages: 1. This invention introduces FMEA theory from the functional design source, constructing a systematic AGC safety control design method covering the entire process through seven steps: functional planning, architecture analysis, functional analysis, failure analysis, risk analysis, safety optimization, and structural documentation. This effectively alleviates the problem of frequency fluctuations caused by abnormal instructions under new rapid resource adjustment, and significantly improves AGC safety control capabilities; 2. By identifying multiple potential failure modes such as hardware device failures, software vulnerabilities, operational anomalies, and external data anomalies, and evaluating their impact on local, secondary, and system levels respectively, the precise location of failure impacts is achieved. 3. Based on severity, frequency of occurrence, and detectability, calculate the risk priority number of each failure mode, classify the risk level accordingly, and configure differentiated anti-misoperation parameter thresholds, software testing, redundant design, and automatic blocking measures for low, medium, and high risks and for failures that have already occurred, so as to achieve graded and precise risk control; 4. In the entire life cycle of AGC function development, testing, operation and upgrade, update the anomaly monitoring algorithm based on operation data, update the early warning model with new failure events, and continuously optimize the failure risk level and safety anti-misoperation measures, while outputting structured record documents to support continuous improvement and full-process traceability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122595564A_ABST
    Figure CN122595564A_ABST
Patent Text Reader

Abstract

The application discloses an AGC safety control design method and system based on FEMA theory, and the method comprises the following steps: obtaining AGC control and safety error prevention requirements, establishing a research and development scheme; performing overall architecture design, and determining the relationship between data interaction and safety checking; dividing function modules, establishing function logic, data interaction and safety error prevention logic; performing failure mode analysis, and constructing an AGC software failure model; performing failure influence analysis, and determining the influence range and level; performing risk assessment, calculating risk priority number and dividing risk grades; configuring prevention, correction and safety error prevention measures according to different risk grades, and rolling optimization in the AGC whole life cycle, and outputting a structured record document; the application introduces the FMEA theory from the source of function design, constructs a systematic AGC safety control method through seven steps, effectively alleviates the frequency fluctuation caused by abnormal instructions, and improves the AGC safety control capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of active power control technology in power systems, and particularly relates to an AGC safety control design method and system based on FEMA theory. Background Technology

[0002] Currently, with the accelerated construction of new power systems, new regulatory resources such as new energy sources and energy storage are being connected to the grid on a large scale and gradually incorporated into the unified regulation and control of automatic generation control (AGC). Compared with traditional large-scale synchronous units, new resources are characterized by their large quantity, fast regulation rate, and complex response characteristics. The objects controlled by AGC are shifting from "few and stable" to "many and variable," and the system operating environment is becoming increasingly complex, placing higher demands on the safety control capabilities of AGC.

[0003] In existing technologies, AGC safety control design mainly adopts multi-level safety verification and anomaly prevention mechanisms. During the control command generation phase, limit-crossing verification is performed using parameters such as power constraints and ramp rate limits. During the command issuance phase, rationality is judged based on the unit's status. During the execution phase, feedback information is used to form a closed-loop verification. Simultaneously, some solutions construct abnormal operation identification models and anomaly prevention strategy libraries to achieve tiered alarms or automatic interception of abnormal commands, and employ a layered and partitioned control architecture at the master station level to reduce the risk of single-point failures.

[0004] However, existing technologies still have significant shortcomings: they lack systematic anti-misoperation theoretical guidance starting from the functional design source, and fail to cover the entire safety design process, including functional planning, failure mode identification, and risk quantification assessment. When AGC issues abnormal commands, combined with the rapid adjustment rate of new resources, it may cause rapid fluctuations in grid power or even frequency over-limit accidents in a short period of time, making it difficult to fundamentally improve the safety anti-misoperation capability of AGC functions. Summary of the Invention

[0005] Purpose of the invention: The purpose of this invention is to provide an AGC safety control design method and system based on FEMA theory. It aims to start from the source of functional design and build a systematic AGC safety control design method covering the entire process based on FMEA theory, so as to alleviate the problem that existing technologies are unable to cope with frequency fluctuations caused by abnormal instructions under new and rapidly adjusting resources due to the lack of anti-misoperation theory guidance.

[0006] Technical solution: The AGC safety control design method based on FEMA theory described in this invention includes the following steps:

[0007] S1. Obtain the control requirements and safety and error prevention requirements of the automatic power generation control (AGC) function, and establish an R&D plan for the automatic power generation control function.

[0008] S2. Based on the aforementioned research and development plan, design the overall architecture of the automatic power generation control function, and establish data interaction and security verification relationships between the automatic power generation control function and external functions, as well as between internal functional modules.

[0009] S3. Based on the results of the overall architecture design, the automatic power generation control function is divided into functional modules, and the functional logic, data interaction logic and safety anti-misoperation logic of each functional module are established.

[0010] S4. Based on the aforementioned functional modules and safety anti-misoperation logic, perform failure mode analysis on the automatic power generation control function, identify the potential failure modes and failure causes corresponding to each functional module, and establish an AGC software failure model.

[0011] S5. Based on the failure model of the AGC software, conduct failure impact analysis on each failure mode to determine the impact range and impact level of each failure mode.

[0012] S6. Based on the results of the failure impact analysis, conduct a risk assessment for each failure mode, calculate the risk priority number corresponding to each failure mode, and determine the risk level of the failure mode according to the risk priority number.

[0013] S7. Based on the risk level, configure preventive measures, corrective measures and safety precautions for the corresponding failure mode;

[0014] S8. During the development, testing, operation and upgrading of automatic power generation control functions, the failure model, risk level and safety prevention measures are continuously optimized, and corresponding structured record documents are output.

[0015] This technical solution starts from the functional design source and constructs a systematic AGC safety control design method covering the entire process based on FMEA theory: Steps S1 to S3 strengthen the integrity of functional logic and safety verification from the root by clarifying control and error prevention requirements, establishing the overall architecture and modular design; Steps S4 to S6 systematically identify potential failure modes and their propagation paths and risk levels by establishing failure models, analyzing failure impacts and calculating risk priority numbers, which helps to alleviate the problem of difficulty in predicting the impact range of abnormal commands under new rapid resource adjustment due to the lack of error prevention theory guidance; Steps S7 to S8 improve the proactive prevention and control capabilities against frequency fluctuations caused by abnormal commands throughout the development, testing, operation and upgrade process by configuring targeted prevention, correction and error prevention measures and continuously optimizing failure models and structured records, thereby reducing later maintenance costs and enhancing the traceability of design and records.

[0016] Preferably, step S1 includes:

[0017] S11. Determine the project establishment information for the software development project with automatic power generation control function;

[0018] S12. Clearly define the control object, control objective, operation method, and safety and error prevention requirements of the automatic power generation control function;

[0019] S13. Establish a research and development organization that includes a requirements analysis team, a coding team, a testing and verification team, a failure mode analysis team, a risk analysis team, and an optimization measures team;

[0020] S14. Develop a project milestone plan that includes milestones for requirements analysis completion, functional design completion, failure mode analysis completion, coding completion, testing completion, and exception verification.

[0021] S15. Output team allocation information and time Gantt chart.

[0022] The aforementioned preferred step S1, by clarifying project initiation information, control objects, and safety and error prevention requirements, combined with multi-disciplinary team collaboration and milestone planning, enhances the systematicness and controllability of the R&D process from organizational and time perspectives. Specifically, steps S11 to S12 help to pre-define the core requirements and error prevention requirements of the automatic power generation control function, reducing deviations at the requirement level; step S13, by establishing a team structure covering analysis, coding, testing, and risk management, provides clear responsibility support for subsequent failure mode identification and risk response; and steps S14 to S15, through the visualization of milestone plans and Gantt charts, enhance the traceability of development progress and the efficiency of the connection between deliverables at each stage, thereby mitigating problems such as omissions or delays in safety design due to unclear requirements or insufficient team cooperation.

[0023] Preferably, step S2 includes:

[0024] S21. Determine the interaction method, interaction content, and interaction safety requirements between the automatic power generation control function and external functions;

[0025] S22. Determine the data interaction methods, content, and security requirements between the modules within the automatic power generation control function;

[0026] S23. Establish the data structure for external interaction interfaces and internal module interfaces;

[0027] S24. Establish safety prevention models and anomaly risk rating models for each functional module;

[0028] S25, Overall architecture diagram of automatic power generation control function.

[0029] The aforementioned optimization step S2, by clarifying the external and internal data interaction methods, content, and security requirements, combined with interface data structure design and the establishment of security error prevention and risk rating models, enhances the systematic nature of the automatic power generation control function in terms of information flow and security verification at the architectural level. Specifically, steps S21 to S22 help to identify potential risk points in multi-level interaction relationships, providing clear security constraints for instruction and data transmission in abnormal scenarios; step S23, by standardizing the interface data structure, enhances the consistency and resolvability of information between different modules and external systems; and step S24, by introducing error prevention and risk rating models, lays a structured evaluation foundation for subsequent failure mode analysis and risk priority number calculation, thereby mitigating the risk of abnormal instructions spreading across modules and causing frequency fluctuations due to unclear interaction relationships or non-standard interfaces.

[0030] Preferably, the functional modules described in step S3 include at least a pattern maintenance module, a data reading module, a data processing module, an adjustment demand calculation module, a control command calculation module, a control command verification and issuance module, and a safety error prevention control module.

[0031] Step S3 also includes:

[0032] S31. Determine the input data, output data, and module processing logic for each functional module;

[0033] S32. Determine the data dependencies and mutual support relationships between each functional module;

[0034] S33. Establish control command generation, verification, and blocking logic;

[0035] S34. Output function requirements description, function interaction requirements description, and safety and error prevention module function description.

[0036] The aforementioned preferred step S3, by clearly defining core functional modules such as model maintenance, data reading, data processing, adjustment demand calculation, control command calculation, command verification and issuance, and safety error prevention control, and combining the input-output logic, data dependencies, and command generation, verification, and blocking mechanisms of each module, enhances the modularity and verifiability of automatic power generation control design from the perspective of functional decomposition and logical closed-loop. Specifically, steps S31 to S32 help clarify the data flow and support relationships between modules, providing an analytical basis for identifying abnormal propagation paths; step S33, by embedding command verification and blocking logic, enhances the ability to intervene in abnormal control commands in new, rapidly adjusting resource scenarios; and the functional specification document output in step S34 provides a clear basis for subsequent failure mode identification, risk analysis, and error prevention measure configuration, thereby mitigating the potential risk of frequency fluctuations caused by abnormal command issuance due to ambiguous functional boundaries or missing verification mechanisms.

[0037] Preferably, step S4 includes:

[0038] S41. Identify potential failure modes in automatic generation control functions based on FMEA theory;

[0039] S42. The potential failure modes are classified into one or more of the following: hardware equipment failure, basic platform failure, database failure, software vulnerability, abnormal operation by operators, and abnormal external data.

[0040] S43. Analyze the failure consequences corresponding to each failure mode.

[0041] S44. Analyze the failure causes corresponding to each failure mode;

[0042] S45. Output the AGC software failure model, which includes failure modes, failure causes, and failure consequences.

[0043] The aforementioned optimization step S4, based on FMEA theory, identifies potential failure modes in the automatic generation control function and categorizes them into various types, including hardware equipment failure, basic platform failure, database failure, software vulnerability, abnormal operator operation, and external data anomaly. Combining a step-by-step analysis of the consequences and causes of each failure mode, a structured AGC software failure model is constructed. Steps S41 to S42 help to comprehensively identify failure sources from multiple dimensions, avoiding the omission of key failure modes due to unclear classification. Steps S43 to S44 establish the correlation between failure consequences and causes, providing a clear causal link for subsequent failure impact analysis and risk rating. The failure model output in step S45 strengthens the predictability of abnormal command generation and propagation paths under new rapid adjustment resources from the functional design source, thereby alleviating the problem of difficulty in dealing with frequency fluctuation risks due to the lack of a systematic failure identification framework.

[0044] Preferably, the impact hierarchy described in step S5 includes local impact, secondary impact, and system impact; wherein: local impact is used to characterize that the failure mode only affects the operation of the current functional module; secondary impact is used to characterize that the failure mode affects the operation of the current functional module and related functional modules; system impact is used to characterize that the failure mode affects the overall operation of the automatic generation control function.

[0045] The aforementioned preferred step S5 provides a hierarchical analytical framework for risk assessment of automatic generation control functions by classifying the impact levels of failure modes into local impact, secondary impact, and system impact. Local impact identifies failure scenarios limited to the current module, helping to pinpoint the source of the problem and narrow down the investigation scope. Secondary impact reveals the propagation path of failures to related modules, facilitating the assessment of the cascading effects of abnormal commands or data between functions. System impact focuses on key risks that may affect the overall operation of automatic generation control, thus supporting the development of targeted prevention and control strategies from a global perspective. Through this hierarchical mechanism, this solution helps alleviate the problem of insufficient estimation of frequency fluctuations or mismatched countermeasures caused by abnormal commands under new rapid adjustment resources due to unclear impact scope.

[0046] Preferably, step S6 includes:

[0047] S61. Obtain the severity, occurrence, and detectability of each failure mode.

[0048] S62. Calculate the corresponding risk priority number according to the formula RPN=Severity×Occurrence×Detection;

[0049] S63. Classify the failure modes by risk level according to the risk priority number;

[0050] S64. Output failure risk level information.

[0051] The aforementioned optimization step S6 obtains the severity, frequency, and detectability of each failure mode, and performs quantitative calculations based on the product relationship of risk priority numbers. Based on this, risk levels are classified for each failure mode, providing a relatively orderly assessment basis for risk management of automatic generation control functions. Specifically, steps S61 to S62 help to comprehensively express multi-dimensional risk characteristics into a comparable value, facilitating the ranking of relative priorities among different failure modes. Steps S63 to S64, through level classification and information output, ensure that high-concern failure modes receive appropriate resource allocation in subsequent measure configurations. This mechanism, from a risk quantification perspective, alleviates the problem of insufficiently focused control measures for frequency fluctuations caused by abnormal commands under new rapid adjustment resources due to the lack of a consistent risk assessment scale.

[0052] Preferably, step S7 includes:

[0053] For low-risk failure modes, configure error prevention parameter thresholds and manual double confirmation measures;

[0054] For medium-risk failure modes, configure software testing, regular updates, and security patch management measures;

[0055] For high-risk failure modes, implement redundant design, regular maintenance, automatic monitoring, and functional upgrade measures;

[0056] Configure data verification, data correction, automatic blocking, and anomaly warning measures for the failure modes that have occurred.

[0057] The aforementioned optimization step S7 constructs a layered and progressive safety and error prevention strategy for the automatic generation control function by configuring differentiated prevention and control measures for failure modes with different risk levels. Specifically, configuring error prevention parameter thresholds and manual double confirmation for low-risk failure modes helps add necessary verification barriers in the operation process; configuring software testing, regular updates, and security patch management for medium-risk failure modes helps improve the continuous robustness of the function throughout its operating cycle; employing redundant design, regular maintenance, automatic monitoring, and function upgrades for high-risk failure modes enhances the ability to withstand and respond to key risks at the architectural level; and configuring data verification, correction, automatic blocking, and anomaly warning for failed modes that have already occurred can, to some extent, suppress the continued spread of abnormal commands. This layered system of measures helps alleviate the problem that a single risk response strategy under new rapid adjustment resources may be insufficient to cover different types of failure modes, potentially exacerbating frequency fluctuation risks.

[0058] Preferably, step S8 includes:

[0059] S81, Algorithm for monitoring anomalies in automatic power generation control function operation data updates;

[0060] S82. Update the failure early warning model and failure prevention strategy based on the newly added failure events;

[0061] S83. Reclassify risk levels based on the updated failure model;

[0062] S84. Adjust the corresponding safety precautions based on the updated risk level;

[0063] S85. The execution results of steps S1 to S7 are stored in a structured manner to generate corresponding structured record documents.

[0064] The aforementioned optimization step S8 updates the anomaly monitoring algorithm based on operational data from the automatic power generation control function, and continuously optimizes the failure early warning model and blocking strategy based on newly added failure events. On this basis, risk levels are reclassified and safety prevention measures are adjusted accordingly, forming a rolling optimization mechanism from data-driven to closed-loop measures. Simultaneously, step S85 structures and documents the execution results of each previous stage, helping to ensure the traceability of the design, analysis, and optimization process. This dynamic iterative mechanism alleviates the problem that the evolving failure modes in new, rapidly adjusting resource environments may lead to a decline in the adaptability of existing control measures and a resurgence of frequency fluctuation risks caused by abnormal commands, and provides structured record support for subsequent system upgrades and maintenance.

[0065] The AGC safety control design system based on FEMA theory described in this invention includes:

[0066] The project planning module is used to obtain the control requirements and safety and error prevention requirements of the automatic power generation control function, and to establish a research and development plan for the automatic power generation control function.

[0067] The architecture analysis module is used to design the overall architecture of the automatic power generation control function, and to establish the data interaction and security verification relationships between the automatic power generation control function and external functions, as well as between internal functional modules.

[0068] The functional analysis module is used to divide the automatic power generation control function into functional modules and establish the functional logic, data interaction logic and safety error prevention logic of each functional module.

[0069] The failure mode analysis module is used to identify the potential failure modes and causes of failure for each functional module, and to establish a failure model for the AGC software.

[0070] The failure impact analysis module is used to determine the impact range and impact level of each failure mode.

[0071] The risk assessment module is used to calculate the risk priority number corresponding to each failure mode and determine the corresponding risk level;

[0072] The error prevention measures module is used to configure preventive measures, corrective measures, and safety error prevention measures based on risk levels.

[0073] The rolling optimization module is used to continuously optimize the failure model, risk level, and safety precautions, and output structured record documents.

[0074] Beneficial Effects: Compared with existing technologies, this invention has the following significant advantages: 1. This invention introduces FMEA theory from the functional design source, constructing a systematic AGC safety control design method covering the entire process through seven steps: functional planning, architecture analysis, functional analysis, failure analysis, risk analysis, safety optimization, and structural documentation. This effectively alleviates the problem of frequency fluctuations caused by abnormal instructions under new rapid resource adjustment, and significantly improves AGC safety control capabilities; 2. By identifying multiple potential failure modes such as hardware device failures, software vulnerabilities, operational anomalies, and external data anomalies, and evaluating their impact on local, secondary, and system levels respectively, the precise location of failure impacts is achieved. 3. Based on severity, frequency of occurrence, and detectability, calculate the risk priority number of each failure mode, classify the risk level accordingly, and configure differentiated anti-misoperation parameter thresholds, software testing, redundant design, and automatic blocking measures for low, medium, and high risks and for failures that have already occurred, so as to achieve graded and precise risk control; 4. In the entire life cycle of AGC function development, testing, operation and upgrade, update the anomaly monitoring algorithm based on operation data, update the early warning model with new failure events, and continuously optimize the failure risk level and safety anti-misoperation measures, while outputting structured record documents to support continuous improvement and full-process traceability. Attached Figure Description

[0075] Figure 1 This is a flowchart illustrating the AGC safety control design of the present invention. Detailed Implementation

[0076] The technical solution of the present invention will be further described below with reference to the accompanying drawings.

[0077] This invention provides an AGC safety control design method based on FEMA theory. Starting from the mature Failure Mode and Effects Analysis (FMEA) theory, it employs seven steps—functional planning, architecture analysis, functional analysis, failure analysis, risk analysis, safety optimization, and structural documentation—to design automatic generation control safety control functions for the safety control requirements of new power systems. This significantly improves AGC safety control capabilities and ensures stable and safe grid frequency operation. Figure 1 As shown, it includes the following steps:

[0078] (1) To address the frequency and tie-line control requirements of high-proportion renewable energy power grids, a new type of automatic generation control function for power grid dispatch is typically deployed in the power grid dispatch control center (hereinafter referred to as the dispatch center). This function automatically adjusts various types of regulation resources within the dispatch range, such as conventional thermal power units, centralized and distributed renewable energy power plants, and various types of energy storage, to meet the needs of safe and stable operation of the power grid frequency. At the same time, in response to the basic requirements for the safety control of various types of resources, a comprehensive safety anti-misoperation mechanism and anomaly anti-misoperation function need to be configured simultaneously. When developing the automatic generation control function for power grid dispatch, it is determined at the beginning of the development and design that the software functions to be developed need to take into account functional correctness, operational stability, anomaly robustness, and ease of operation and maintenance.

[0079] (2) When developing the automatic generation control function for power grid dispatch, the first step is to carry out relevant planning for the automatic generation control function, including the following steps:

[0080] (21) Determine the project establishment information for software R&D projects and clarify the basic requirements for automatic power generation control functions, including information such as control objects, control objectives, operation methods and safety and error prevention requirements;

[0081] (22) The project R&D team must include a requirements analysis team, a coding team, a testing and verification team, a failure model analysis team, a risk analysis team, and an optimization measures team.

[0082] (23) Determine the project development milestone plan, which should include at least the completion nodes of requirements analysis, functional design, failure model analysis, coding, testing, and anomaly verification.

[0083] (24) Output team allocation and time Gantt chart after completing the functional planning.

[0084] (3) After completing the project planning for the automatic power generation control function, the next step is to conduct an overall functional architecture analysis, determine the design of the function and external functions, internal interaction interfaces, internal and external interaction data, and safety verification methods, including:

[0085] (31) Determine the interaction mode, interaction content, interaction safety requirements and possible failure modes between the automatic power generation control function and external functions;

[0086] (32) Determine the internal large-scale module division of automatic generator, the data interaction method between modules, the interaction content and interaction safety requirements, and the possible failure modes;

[0087] (33) Determine the safety protection design, failure model of the protection function, and abnormal risk rating for each module;

[0088] (34) Determine the data structure, security error prevention model, and anomaly risk rating of external interaction interfaces and internal module interfaces;

[0089] (35) After completing the overall functional architecture analysis, the overall functional architecture diagram needs to be output.

[0090] (4) Complete the overall functional architecture analysis. Based on the overall functional architecture diagram, the next step is to conduct functional analysis, performing a detailed analysis of the relevant functions of the automatic power generation control software, and clarifying the role and interrelationships of each functional module. Specifically, this includes:

[0091] (41) Functional module division: The automatic power generation control function is divided into multiple modules, such as basic functions like model maintenance, data reading, data processing, adjustment demand calculation, control command calculation, control command verification and issuance. Detailed analysis and design of each functional module will be carried out subsequently.

[0092] (42) Safety anti-misoperation control module design: In view of the high reliability requirements of the automatic power generation control function, the functional design is specifically carried out for the anti-misoperation requirements related to the control.

[0093] (43) Design of data interaction function between modules: sort out the various functional modules of automatic power generation control, and clarify the role and mutual support relationship of each functional module;

[0094] (44) After completing the functional analysis, output the functional requirements description, functional interaction requirements description and safety and error prevention module functional description.

[0095] (5) After completing the automatic power generation control function analysis, based on the functional module design specifications and safety anti-misoperation function specifications, further functional failure mode analysis is conducted to identify each potential failure mode in the AGC software module product and analyze its possible failure causes. The specific steps are as follows:

[0096] (51) Based on FMEA theory, identify each potential failure mode in the system and decompose the failure modes of AGC software products into multiple failure modes such as hardware equipment failure, basic platform failure, database failure, software vulnerabilities, abnormal operation by operators, and abnormal external data.

[0097] (52) Based on the failure mode, list the possible consequences of each type of failure, such as: hardware failure may cause the AGC software to exit without warning, platform failure may cause the AGC software to exit normally, external data abnormality may cause data acquisition errors or control command execution failure; internal software vulnerabilities of AGC may cause the control program to exit abnormally or generate incorrect control commands, and human error may include the dispatcher incorrectly inputting control commands or not performing operations according to the prescribed procedures.

[0098] (53) Based on failure mode analysis, further analyze the causes of failure, that is, conduct in-depth analysis of each identified failure mode to determine its possible causes of failure. For example, equipment failure may be caused by hardware aging, insufficient maintenance or environmental factors; software vulnerabilities may be caused by negligence in the development process or technical limitations; human error may be caused by operator negligence, insufficient training or non-standard operating procedures.

[0099] (54) Based on the failure mode analysis results, this step outputs the failure model of the AGC software, including information such as failure mode and failure cause.

[0100] (6) Based on failure mode analysis, further failure impact analysis is carried out to determine the potential impact of each failure mode on the AGC software, which is divided into three levels: local impact, secondary impact and system impact.

[0101] (61) Local impact is defined as the failure of this part only affects this module, which may cause the module to operate abnormally. For example, the failure of the data reading function only affects the data reading module.

[0102] (62) Secondary impact is defined as the failure of this part affecting this module and related secondary modules. For example, the failure of the AGC real-time measurement processing module may cause the AGC adjustment demand calculation module to malfunction, thus forming a secondary impact.

[0103] (63) The system impact is defined as the failure of this part that may affect the abnormal operation of the entire AGC function. For example, a defect in the software code may lead to a memory leak, which may affect the overall operation of the AGC function.

[0104] (64) This step outputs the impact range information of the failure mode.

[0105] (7) After completing the failure impact analysis, the next step is to assess the severity of the impact. The method is as follows:

[0106] (71) Calculate the risk priority number (RPN = S × O × D) based on the severity (S), occurrence (O), and detectability (D) of the failure mode.

[0107] (72) Then assess the risk level. Based on the calculated risk priority number, conduct a risk assessment for each failure mode. The higher the RPN value, the greater the risk of the failure mode. The failure mode risk can be divided into three risk levels: low, medium, and high. For example, failure modes with an RPN value greater than a certain threshold (such as 200) are considered to be of high risk. Different anti-misoperation measures are taken for different risk levels.

[0108] (73) This step outputs the failure risk level information.

[0109] (8) Optimize error prevention measures. For failure modes with different risk levels, formulate prevention and error prevention measures, reduce risk priority, and improve system reliability.

[0110] (81) For low-risk failure modes, error prevention measures are adopted and error prevention parameter thresholds are set. For example, for the failure mode of abnormal operation of scheduling interface, manual double confirmation is designed to reduce the failure risk.

[0111] (82) For medium-risk failure modes, improve the stability and security of the software through rigorous software testing, regular updates and security patch management;

[0112] (83) For high-risk failure modes, adopt measures such as increasing redundancy design, regular maintenance, and software to add automatic monitoring and function upgrades to reduce failure risk.

[0113] (84) At the same time, corrective measures should be developed to address the failure modes that have already occurred and reduce the impact of the failures. For example, for data acquisition errors, data accuracy can be ensured through data verification and correction mechanisms; for erroneous control commands, automatic blocking and early warning mechanisms can be used to prevent the execution of erroneous commands.

[0114] (85) This step outputs the countermeasures for different risk failure modes.

[0115] (9) Rolling optimization: continuously optimize based on FMEA theory during the upgrade and improvement of automatic power generation control function. By continuously improving the anomaly monitoring algorithm, failure early warning model and failure blocking strategy, different correction software failure models and risk classifications, and improve the correction measures according to different risk classifications.

[0116] (10) Output structured documents. In the process of functional planning, architecture analysis, functional analysis, failure mode analysis, failure impact analysis, risk analysis, optimization and error prevention measures and rolling optimization, structured record documents are output and used as the starting point for rolling optimization.

[0117] To address the frequency and tie-line control requirements of high-proportion renewable energy power grids, automatic generation control functions are typically deployed in the power grid dispatch and control center. This function automatically adjusts various types of regulation resources within the dispatch and control scope, such as conventional thermal power units, centralized and distributed renewable energy power plants, and various types of energy storage, to meet the needs of safe and stable operation of the power grid frequency. At the same time, in response to the basic requirements for the safety control of various types of resources, a comprehensive safety anti-misoperation mechanism and anomaly anti-misoperation function need to be configured.

[0118] When developing automatic generation control functions for power grid dispatch, in addition to ensuring functional correctness and operational stability, it is also necessary to improve the safety and error prevention capabilities of the automatic generation control functions. First, preliminary functional planning must be conducted to clarify the software development project's initiation information and define the basic requirements for the automatic generation control functions, including the control object, control objectives, operation methods, and safety and error prevention requirements. A project development team must be established, which must include a requirements analysis team, a coding team, a testing and verification team, a failure mode analysis team, a risk analysis team, and an optimization measures team. A project development milestone plan must be set, including at least the completion milestones for requirements analysis, functional design, failure mode analysis, coding, testing, and anomaly verification. After completing the preliminary functional planning, a team allocation and time Gantt chart should be created.

[0119] After completing the project planning for the automatic power generation control function, the overall functional architecture analysis is then conducted. This involves determining the design of the function's interaction interfaces with external functions, internal functions, internal and external interaction data, and safety verification methods. Specifically, this includes determining the interaction methods, content, and safety requirements between the automatic power generation control function and external functions, as well as potential failure modes. It also involves determining the division of the automatic power generation control function into large internal modules, the data interaction methods between modules, the content and safety requirements, and potential failure modes. Furthermore, it involves determining the safety protection design for each module, the failure modes of the protection function, and the anomaly risk rating. Finally, it involves determining the data structure of external interaction interfaces and internal module interfaces, the safety protection model, and the anomaly risk rating. After completing the overall functional architecture analysis, a functional architecture diagram is generated.

[0120] Then, based on the functional architecture diagram, functional analysis is carried out to clarify the role and interrelationship of each functional module, including the division of functional modules, the design of the safety and error prevention control module, and the design of data interaction functions between modules. Then, functional requirements specifications, functional interaction requirements specifications, and safety and error prevention module functional specifications are formed to guide functional coding.

[0121] After completing the basic functional design and error prevention module, a functional failure mode analysis (FMEA) was conducted to identify each potential failure mode in the AGC software module and analyze its possible causes. The method was based on FMEA theory, identifying each potential failure mode in the system and decomposing the AGC software product's failure modes into multiple categories, including hardware equipment failure, basic platform failure, database failure, software vulnerabilities, operator error, and external data anomalies. The potential consequences of each type of failure were listed, and further analysis of the causes was performed. This involved in-depth analysis of each identified failure mode to determine its possible causes. After completing the failure mode analysis, an AGC software failure model was formed, including information such as failure modes and causes.

[0122] Based on failure mode analysis, the next step is to conduct failure impact analysis to determine the potential impact of each failure mode on the AGC software, categorized into three levels: local impact, secondary impact, and systemic impact. Local impact is defined as the failure affecting only this module, potentially causing malfunctions in that module; secondary impact is defined as the failure affecting this module and related secondary modules; systemic impact is defined as the failure potentially causing malfunctions in the entire AGC function. The failure impact analysis outputs information on the scope of the failure modes' impact.

[0123] After completing the failure impact analysis, the next step is to assess the severity of the impact. This is done by calculating a risk priority number based on the severity, frequency, and detectability of the failure mode. Then, based on the calculated risk priority number, a risk assessment is performed on each failure mode. Failure mode risks can be divided into three risk levels: low, medium, and high. For example, failure modes with an RPN value greater than a certain threshold (such as 200) are considered to be at a high risk level. Different preventative measures are taken for different risk levels. The failure risk level information is output through the failure risk assessment.

[0124] The next step is to develop prevention and mitigation measures for failure modes with different risk levels, reducing the risk priority and improving system reliability. This includes: for low-risk failure modes, implementing mitigation measures and setting mitigation parameter thresholds; for example, for failure modes involving abnormal operation of the scheduling interface, designing a manual double-confirmation method to reduce the risk of failure; for medium-risk failure modes, improving software stability and security through rigorous software testing, regular updates, and security patch management; and for high-risk failure modes, reducing the risk of failure by increasing redundancy design, regular maintenance, and adding automatic monitoring and function upgrades to the software.

[0125] Simultaneously, corrective measures should be developed to address existing failure modes and mitigate their impact. For example, data acquisition errors can be addressed through data verification and correction mechanisms to ensure data accuracy; erroneous control commands can be prevented from being executed through automatic blocking and early warning mechanisms.

[0126] After completing the above steps, continue to carry out rolling optimization. By continuously improving the anomaly monitoring algorithm, failure early warning model and failure prevention strategy, continuously revise the software failure model and risk classification, and improve the corrective measures according to different risk classifications.

[0127] Structured documents are output simultaneously in each safety design process. Structured record documents are output during the functional planning, architecture analysis, functional analysis, failure mode analysis, failure impact analysis, risk analysis, optimization of error prevention measures and rolling optimization processes, and serve as the starting point for rolling optimization.

[0128] Based on a similar inventive concept, embodiments of the present invention also provide an AGC safety control design system based on FEMA theory, corresponding to the AGC safety control design method based on FEMA theory, comprising:

[0129] The project planning module is used to obtain the control requirements and safety and error prevention requirements of the automatic power generation control function, and to establish a research and development plan for the automatic power generation control function.

[0130] The architecture analysis module is used to design the overall architecture of the automatic power generation control function, and to establish the data interaction and security verification relationships between the automatic power generation control function and external functions, as well as between internal functional modules.

[0131] The functional analysis module is used to divide the automatic power generation control function into functional modules and establish the functional logic, data interaction logic and safety error prevention logic of each functional module.

[0132] The failure mode analysis module is used to identify the potential failure modes and causes of failure for each functional module, and to establish a failure model for the AGC software.

[0133] The failure impact analysis module is used to determine the impact range and impact level of each failure mode.

[0134] The risk assessment module is used to calculate the risk priority number corresponding to each failure mode and determine the corresponding risk level;

[0135] The error prevention measures module is used to configure preventive measures, corrective measures, and safety error prevention measures based on risk levels.

[0136] The rolling optimization module is used to continuously optimize the failure model, risk level, and safety precautions, and output structured record documents.

Claims

1. An AGC safety control design method based on FEMA theory, characterized in that, Includes the following steps: S1. Obtain the control requirements and safety and error prevention requirements of the automatic power generation control (AGC) function, and establish an R&D plan for the automatic power generation control function. S2. Based on the aforementioned research and development plan, design the overall architecture of the automatic power generation control function, and establish data interaction and security verification relationships between the automatic power generation control function and external functions, as well as between internal functional modules. S3. Based on the results of the overall architecture design, the automatic power generation control function is divided into functional modules, and the functional logic, data interaction logic and safety anti-misoperation logic of each functional module are established. S4. Based on the aforementioned functional modules and safety anti-misoperation logic, perform failure mode analysis on the automatic power generation control function, identify the potential failure modes and failure causes corresponding to each functional module, and establish an AGC software failure model. S5. Based on the failure model of the AGC software, conduct failure impact analysis on each failure mode to determine the impact range and impact level of each failure mode. S6. Based on the results of the failure impact analysis, conduct a risk assessment for each failure mode, calculate the risk priority number corresponding to each failure mode, and determine the risk level of the failure mode according to the risk priority number. S7. Based on the risk level, configure preventive measures, corrective measures and safety precautions for the corresponding failure mode; S8. During the development, testing, operation and upgrading of automatic power generation control functions, the failure model, risk level and safety prevention measures are continuously optimized, and corresponding structured record documents are output.

2. The method according to claim 1, characterized in that, Step S1 includes: S11. Determine the project establishment information for the software development project with automatic power generation control function; S12. Clearly define the control object, control objective, operation method, and safety and error prevention requirements of the automatic power generation control function; S13. Establish a research and development organization that includes a requirements analysis team, a coding team, a testing and verification team, a failure mode analysis team, a risk analysis team, and an optimization measures team; S14. Develop a project milestone plan that includes milestones for requirements analysis completion, functional design completion, failure mode analysis completion, coding completion, testing completion, and exception verification. S15. Output team allocation information and time Gantt chart.

3. The method according to claim 1, characterized in that, Step S2 includes: S21. Determine the interaction method, interaction content, and interaction safety requirements between the automatic power generation control function and external functions; S22. Determine the data interaction methods, content, and security requirements between the modules within the automatic power generation control function; S23. Establish the data structure for external interaction interfaces and internal module interfaces; S24. Establish safety prevention models and anomaly risk rating models for each functional module; S25, Overall architecture diagram of automatic power generation control function.

4. The method according to claim 1, characterized in that, The functional modules described in step S3 include at least a pattern maintenance module, a data reading module, a data processing module, an adjustment demand calculation module, a control command calculation module, a control command verification and issuance module, and a safety error prevention control module. Step S3 also includes: S31. Determine the input data, output data, and module processing logic for each functional module; S32. Determine the data dependencies and mutual support relationships between each functional module; S33. Establish control command generation, verification, and blocking logic; S34. Output function requirements description, function interaction requirements description, and safety and error prevention module function description.

5. The method according to claim 1, characterized in that, Step S4 includes: S41. Identify potential failure modes in automatic generation control functions based on FMEA theory; S42. The potential failure modes are classified into one or more of the following: hardware equipment failure, basic platform failure, database failure, software vulnerability, abnormal operation by operators, and abnormal external data. S43. Analyze the failure consequences corresponding to each failure mode. S44. Analyze the failure causes corresponding to each failure mode; S45. Output the AGC software failure model, which includes failure modes, failure causes, and failure consequences.

6. The method according to claim 1, characterized in that, The impact hierarchy described in step S5 includes local impact, secondary impact, and system impact; wherein: local impact is used to characterize that the failure mode only affects the operation of the current functional module; secondary impact is used to characterize that the failure mode affects the operation of the current functional module and related functional modules; system impact is used to characterize that the failure mode affects the overall operation of the automatic generation control function.

7. The method according to claim 1, characterized in that, Step S6 includes: S61. Obtain the severity, occurrence, and detectability of each failure mode. S62. Calculate the corresponding risk priority number according to the formula RPN=Severity×Occurrence×Detection; S63. Classify the failure modes by risk level according to the risk priority number; S64. Output failure risk level information.

8. The method according to claim 1, characterized in that, Step S7 includes: For low-risk failure modes, configure error prevention parameter thresholds and manual double confirmation measures; For medium-risk failure modes, configure software testing, regular updates, and security patch management measures; For high-risk failure modes, implement redundant design, regular maintenance, automatic monitoring, and functional upgrade measures; Configure data verification, data correction, automatic blocking, and anomaly warning measures for the failure modes that have occurred.

9. The method according to claim 1, characterized in that, Step S8 includes: S81, Algorithm for monitoring anomalies in automatic power generation control function operation data updates; S82. Update the failure early warning model and failure prevention strategy based on the newly added failure events; S83. Reclassify risk levels based on the updated failure model; S84. Adjust the corresponding safety precautions based on the updated risk level; S85. The execution results of steps S1 to S7 are stored in a structured manner to generate corresponding structured record documents.

10. An AGC safety control design system based on FEMA theory, characterized in that, include: The project planning module is used to obtain the control requirements and safety and error prevention requirements of the automatic power generation control function, and to establish a research and development plan for the automatic power generation control function. The architecture analysis module is used to design the overall architecture of the automatic power generation control function, and to establish the data interaction and security verification relationships between the automatic power generation control function and external functions, as well as between internal functional modules. The functional analysis module is used to divide the automatic power generation control function into functional modules and establish the functional logic, data interaction logic and safety error prevention logic of each functional module. The failure mode analysis module is used to identify the potential failure modes and causes of failure for each functional module, and to establish a failure model for the AGC software. The failure impact analysis module is used to determine the impact range and impact level of each failure mode. The risk assessment module is used to calculate the risk priority number corresponding to each failure mode and determine the corresponding risk level; The error prevention measures module is used to configure preventive measures, corrective measures, and safety error prevention measures based on risk levels. The rolling optimization module is used to continuously optimize the failure model, risk level, and safety precautions, and output structured record documents.