Method and system for testing over-limit protection of fault module of flexible direct current valve control system
By configuring a graded protection strategy with minor, severe, and redundant depletion thresholds for each bridge arm of the flexible DC valve control system, and combining the detection main control board and real-time simulation model, graded alarm and trip protection are achieved. This solves the problems of lack of graded early warning and insufficient test coverage in the protection strategy in the existing technology, and improves the stability and reliability of the system.
Patent Information
- Application Number
- CN202610963766.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-30
- Publication Date
- 2026-08-25
AI Technical Summary
The protection strategy of the existing flexible DC valve control system lacks a graded early warning mechanism, which makes the system susceptible to tripping and blocking impacts. In addition, the protection test scheme has limited coverage and cannot detect crosstalk between bridge arms, which can easily lead to protection malfunctions.
A preset hierarchical protection strategy is adopted, configuring minor threshold, severe threshold and redundancy depletion threshold for each bridge arm. By detecting the number of faulty modules on the main control board, hierarchical alarm and trip protection are realized. A real-time simulation model and closed-loop test environment are constructed, and a fault simulation device and monitoring background are configured for hierarchical verification.
Ensure that differentiated early warnings are output in a tiered manner during the accumulation of fault modules, avoid false protection activation, improve system stability, cover the core rules of the fault statistics algorithm, and avoid unplanned outages.
Smart Images

Figure CN122631985A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of flexible DC transmission, and in particular to a test method and system for over-limit protection of the number of fault modules in a flexible DC valve control system. Background Technology
[0002] Flexible DC transmission is a core power transmission technology in the current power grid field. Modular multilevel converter valves, as core equipment in flexible DC projects, adopt a multi-power module cascaded topology, with each bridge arm configured with a certain number of redundant power modules to improve operational reliability. The flexible DC valve control system is responsible for the control, status monitoring, and fault protection of all bridge arm power modules. Among them, the alarm for exceeding the fault module limit and trip protection are the core protection functions of the valve control system, which directly determine the safe operation of the converter valve. Its functional correctness is a key verification indicator before the project is put into operation.
[0003] Currently, flexible DC valve control systems generally possess the capability to protect against excessive fault module counts. Conventional protection logic uses the number of redundant modules per bridge arm as a threshold; when the number of faulty modules exceeds the redundancy limit, it directly triggers the converter valve to lock out and trip, preventing serious damage to the converter valve due to insufficient voltage output capacity. The corresponding functional testing method typically involves setting up test paths for module faults sequentially on a single bridge arm to verify the triggering actions of alarms and tripping thresholds, thus completing the basic verification of the protection function. As the capacity and voltage level of flexible DC projects continue to increase, the power grid's requirements for system operational stability and protection reliability are constantly rising.
[0004] However, existing solutions either lack a tiered early warning mechanism in their protection strategies, only setting up single-level over-limit tripping actions, making it impossible for operators to identify risks and apply for shutdowns in advance during the accumulation of faults. Sudden valve group blocking can easily cause system power surges, threatening grid stability. Or, the test methods have limited coverage dimensions. The test path with single-arm faults cannot detect logical defects in the statistical crosstalk of fault numbers between arms in the code writing, which can easily lead to protection malfunctions and unplanned shutdowns. These problems make it difficult for existing protection strategies to fully guarantee the safety of engineering operation. Summary of the Invention
[0005] This application provides a test method and system for over-limit protection of fault modules in a flexible DC valve control system. It is used to solve the technical problems of existing protection strategies lacking a graded early warning mechanism, which makes the system highly susceptible to tripping and blocking impacts. Moreover, the protection test scheme has limited coverage dimensions and cannot detect statistical crosstalk between bridge arms, which can easily lead to protection maloperation.
[0006] In view of this, the first aspect of this application provides a test method for over-limit protection of the number of fault modules in a flexible direct current valve control system, including: Each bridge arm is configured with multiple fault modules according to a preset hierarchical protection strategy, which includes a minor threshold, a severe threshold, and a redundancy exhaustion threshold. The number of faults in a single bridge arm is obtained by counting the number of fault modules on the corresponding bridge arm through the detection main control board configured in each bridge arm. When the number of faults in a single bridge arm is not less than the minor threshold, it is determined whether a minor alarm is triggered and the system is operating normally. If the alarm is triggered and cleared after deducting the number of faults cleared by maintenance, then the minor fault protection mechanism of the current bridge arm is normal. When the number of faults in a single bridge arm is not less than the critical threshold, it is determined whether a critical alarm is triggered and the system is operating normally. If so, the critical fault protection mechanism of the current bridge arm is normal. When the number of single bridge arm failures is equal to the redundancy exhaustion threshold, determine whether a redundancy exhaustion alarm is triggered and the system is operating normally. If so, the redundancy exhaustion alarm protection mechanism of the current bridge arm is normal. When the number of faults in a single bridge arm exceeds the redundancy depletion threshold, it is determined whether a redundancy depletion trip is triggered and the system is locked. If so, the redundancy depletion trip protection mechanism of the current bridge arm is normal.
[0007] Preferably, the step of configuring multiple fault modules for each bridge arm according to a preset hierarchical protection strategy further includes: Construct a closed-loop test environment for the real-time simulation model and the flexible direct current valve control system, and configure a fault simulation device, a valve control monitoring backend, and a maintenance mode operation entry. In the flexible direct current valve control system, basic parameter information is configured, including the total number of modules in a single bridge arm, the number of redundant modules in a single bridge arm, and a preset hierarchical protection strategy. The parameters and states of the real-time simulation model and the relevant equipment of the flexible direct current valve control system are initialized.
[0008] Preferably, the step of configuring multiple fault modules for each bridge arm according to a preset hierarchical protection strategy includes: Before the real-time simulation model is closed for charging, the fault simulation device configures multiple fault modules for each bridge arm according to a preset hierarchical protection strategy.
[0009] Preferably, when the number of faults in a single bridge arm is not less than the minor threshold, determining whether a minor alarm is triggered, and the system is operating normally, and the alarm is cleared after deducting the number of faults cleared through maintenance, if so, then the minor fault protection mechanism for the current bridge arm is normal, including: S1: Start the real-time simulation model to close and charge. If the number of single bridge arm faults is not less than the minor threshold, and a minor alarm is triggered while the system is running normally, proceed to S2. S2: Lock down the real-time simulation model, trigger the flexible direct current valve control system to switch to maintenance mode to clear fault modules, and mark the fault clearing symbol; S3: Restart the real-time simulation model to charge, determine whether the number of faults in a single bridge arm is less than the minor threshold, and whether the alarm is cleared and the system is running normally. If so, the minor fault protection mechanism of the current bridge arm is normal.
[0010] Preferably, when the number of faults in a single bridge arm is not less than the minor threshold, the step of determining whether a minor alarm is triggered, and the system is operating normally, and the alarm is cleared after deducting the number of faults cleared through maintenance, if so, then the minor fault protection mechanism for the current bridge arm is normal, and the step further includes: Determine whether the number of single-arm faults in the current bridge arm is equal to the difference between the number of configured fault modules and the number of faults cleared during maintenance. If so, determine that no cross-arm faults have entered the system.
[0011] Preferably, when the number of faults in a single bridge arm exceeds the redundancy depletion threshold, the step of determining whether a redundancy depletion trip and system lockout are triggered, and if so, the redundancy depletion trip protection mechanism of the current bridge arm is normal, further includes: The test operation ends by issuing a lockout command to the flexible direct current valve control system to keep the converter valve in a stable lockout state.
[0012] The second aspect of this application provides a test system for over-limit protection against faulty modules in a flexible direct current valve control system, including: The fault deployment unit is used to configure multiple fault modules for each bridge arm according to a preset hierarchical protection strategy, which includes a minor threshold, a severe threshold, and a redundancy exhaustion threshold. The quantity counting unit is used to count the number of fault modules on the corresponding bridge arm through the detection main control board configured in each bridge arm, so as to obtain the number of faults in a single bridge arm; The first test unit is used to determine whether a minor alarm is triggered when the number of faults in a single bridge arm is not less than the minor threshold, and the system is operating normally. If the alarm is triggered after deducting the number of faults cleared by maintenance, then the minor fault protection mechanism of the current bridge arm is normal. The second test unit is used to determine whether a serious alarm is triggered and the system is operating normally when the number of faults in a single bridge arm is not less than the serious threshold. If so, the serious fault protection mechanism of the current bridge arm is normal. The third test unit is used to determine whether a redundancy exhaustion alarm is triggered and the system is operating normally when the number of single bridge arm failures is equal to the redundancy exhaustion threshold. If so, the redundancy exhaustion alarm protection mechanism of the current bridge arm is normal. The fourth test unit is used to determine whether to trigger a redundancy depletion trip and system lockout when the number of faults in a single bridge arm exceeds the redundancy depletion threshold. If so, the redundancy depletion trip protection mechanism of the current bridge arm is normal.
[0013] Preferably, it also includes a test platform construction unit, used for: Construct a closed-loop test environment for the real-time simulation model and the flexible direct current valve control system, and configure a fault simulation device, a valve control monitoring backend, and a maintenance mode operation entry. In the flexible direct current valve control system, basic parameter information is configured, including the total number of modules in a single bridge arm, the number of redundant modules in a single bridge arm, and a preset hierarchical protection strategy. The parameters and states of the real-time simulation model and the relevant equipment of the flexible direct current valve control system are initialized.
[0014] Preferably, the first test unit is specifically used for: S1: Start the real-time simulation model to close and charge. If the number of single bridge arm faults is not less than the minor threshold, and a minor alarm is triggered while the system is running normally, proceed to S2. S2: Lock down the real-time simulation model, trigger the flexible direct current valve control system to switch to maintenance mode to clear fault modules, and mark the fault clearing symbol; S3: Restart the real-time simulation model to charge, determine whether the number of faults in a single bridge arm is less than the minor threshold, and whether the alarm is cleared and the system is running normally. If so, the minor fault protection mechanism of the current bridge arm is normal.
[0015] Preferably, it further includes a fault statistics test unit, used for: Determine whether the number of single-arm faults in the current bridge arm is equal to the difference between the number of configured fault modules and the number of faults cleared during maintenance. If so, determine that no cross-arm faults have entered the system.
[0016] As can be seen from the above technical solutions, the embodiments of this application have the following advantages: This application provides a test method for over-limit protection of fault modules in a flexible DC valve control system, including: configuring multiple fault modules for each bridge arm according to a preset hierarchical protection strategy, which includes a minor threshold, a severe threshold, and a redundancy depletion threshold; counting the number of fault modules on the corresponding bridge arm using the detection main control board configured for each bridge arm to obtain the number of faults in a single bridge arm; when the number of faults in a single bridge arm is not less than the minor threshold, determining whether a minor alarm is triggered and the system is operating normally, and whether the alarm is cleared after deducting the number of faults cleared for maintenance, if so, the minor fault protection mechanism of the current bridge arm is normal; when the number of faults in a single bridge arm is not less than the severe threshold, determining whether a severe alarm is triggered and the system is operating normally, if so, the severe fault protection mechanism of the current bridge arm is normal; when the number of faults in a single bridge arm is equal to the redundancy depletion threshold, determining whether a redundancy depletion alarm is triggered and the system is operating normally, if so, the redundancy depletion alarm protection mechanism of the current bridge arm is normal; when the number of faults in a single bridge arm exceeds the redundancy depletion threshold, determining whether a redundancy depletion trip is triggered and the system is locked, if so, the redundancy depletion trip protection mechanism of the current bridge arm is normal.
[0017] The test method for over-limit protection of fault modules in a flexible DC valve control system provided in this application sets up a preset hierarchical protection strategy including minor threshold, severe threshold, and redundancy exhaustion threshold. Different threshold judgment nodes correspond to verifying the hierarchical alarm and trip protection action logic under different fault numbers. By verifying the alarm status and system operation status layer by layer, the effectiveness of the hierarchical protection mechanism can be fully verified, ensuring that the fault module accumulation process can output differentiated early warning signals in a layered manner. In addition, the test scheme uses the number of faults in a single bridge arm as the basis for analysis, and configures an independent statistical unit such as a detection main control board for each bridge arm. Then, the protection mechanisms at each level of different bridge arms are verified separately, ensuring the independence of fault statistics for each bridge arm and avoiding unplanned outages caused by protection maloperation. Moreover, this process also verifies the protection status under the condition of deducting the number of faults after bridge arm maintenance, which can largely cover the core rules of the fault statistics algorithm and make up for the verification blind spots of traditional single bridge arm tests. Therefore, this application can solve the technical problems of existing protection strategies lacking a graded early warning mechanism, which makes the system extremely vulnerable to tripping and blocking impacts, and the protection test scheme having limited coverage dimensions, failing to detect crosstalk between bridge arms, and easily causing protection malfunctions. Attached Figure Description
[0018] Figure 1 A flowchart illustrating the test method for over-limit protection of the number of fault modules in a flexible direct current valve control system provided in this application embodiment; Figure 2 This is a schematic diagram of the structure of the over-limit protection test system for the number of fault modules in the flexible direct current valve control system provided in the embodiments of this application. Detailed Implementation
[0019] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.
[0020] For easier understanding, please refer to Figure 1 The embodiments of the test method for over-limit protection of fault modules in a flexible direct current valve control system provided in this application include: Step 101: Configure multiple fault modules for each bridge arm according to the preset hierarchical protection strategy. The preset hierarchical protection strategy includes minor threshold, severe threshold and redundancy exhaustion threshold.
[0021] It should be noted that the preset protection strategy is a rule for triggering fault over-limit protection warnings based on thresholds such as minor threshold, severe threshold, and redundancy exhaustion threshold. Triggering the corresponding level threshold will trigger the corresponding level alarm. Based on the known preset protection strategy, multiple different fault modules are configured for each bridge arm in multiple different bridge arms. The number of fault modules configured for each bridge arm can be recorded. This mechanism can simulate different bridge arms reaching different levels of triggering warnings, thereby verifying the effectiveness of the protection mechanisms of these bridge arms in the current system at different levels.
[0022] It is understandable that as the values of the minor threshold, severe threshold, and redundancy exhaustion threshold increase sequentially, the warning level rises accordingly. Therefore, it is foreseeable that the warning priority also increases progressively, with redundancy exhaustion having the highest alarm level. Furthermore, the number of bridge arms in the system can be set according to actual conditions, for example, six. The preset hierarchical protection strategy includes, but is not limited to, the four thresholds mentioned above. More detailed hierarchical thresholds that better suit actual scenarios can also be designed; this is merely an example and not a limitation.
[0023] Furthermore, step 101, preceding the following, also includes: Construct a closed-loop test environment for the real-time simulation model and the flexible direct current valve control system, and configure a fault simulation device, a valve control monitoring backend, and a maintenance mode operation entry. Configure basic parameter information in the flexible DC valve control system. The basic parameter information includes the total number of modules in a single bridge arm, the number of redundant modules in a single bridge arm, and the preset hierarchical protection strategy. The parameters and states of the relevant equipment in the real-time simulation model and the flexible direct current valve control system are initialized.
[0024] It should be noted that a complete test environment or test platform needs to be set up before deploying the fault module on the bridge arm. Specifically, this involves building a closed-loop test environment for the real-time simulation model and the flexible DC valve control system, and then configuring the backend modules, namely the fault simulation device, the valve control system monitoring backend, and the maintenance mode operation entry. Next, the basic parameter information needs to be configured in the flexible DC valve control system, including but not limited to the total number of modules in a single bridge arm, the number of redundant modules in a single bridge arm, and the preset hierarchical protection strategy.
[0025] In addition, the parameters and states of the relevant equipment in the real-time simulation model and the flexible DC valve control system need to be initialized. For example, in the real-time simulation model, the AC incoming circuit breaker is in the open state, the converter valve is in the locked state, the flexible DC valve control system is out of maintenance mode, the fault statistics of all bridge arms are cleared to zero, and no activity alarms or trip signals are generated. After completing the scenario setup and parameter configuration before testing, specific fault deployment and protection strategy testing can be carried out.
[0026] Step 102: Count the number of faulty modules on each bridge arm by using the detection main control board configured for each bridge arm, and obtain the number of faults in a single bridge arm.
[0027] Further, step 102 includes: Before the real-time simulation model is closed for charging, multiple fault modules are configured for each bridge arm according to a preset hierarchical protection strategy using a fault simulation device.
[0028] It should be noted that each bridge arm is equipped with an independent detection control board, capable of independently detecting the number of faulty modules on a single bridge arm, i.e., the number of faults in a single bridge arm. This detection can be performed in real time, so regardless of whether faulty modules have been repaired or cleared, the control board can still count the number of faulty modules in a single bridge arm. If the detected number of faulty modules is compared with the previously configured number, and they match, it indicates that no other bridge arm faults have interfered with the statistical results. If they do not match, it is analyzed whether the number of faulty modules repaired should be deducted, and then compared with the real-time detected number of faulty modules. If they match, it also indicates no interference. Subsequently, all bridge arms can use their independent detection control boards to verify the number of faulty modules that have been introduced across bridge arms. This is the significant meaning of independently counting the number of faults in a single bridge arm.
[0029] The deployment of fault modules on a single bridge arm is an operation completed before the real-time simulation model is closed for charging. In order to efficiently test the effectiveness of the protection strategy, different numbers of fault modules can be configured for different bridge arms based on different level thresholds in the preset hierarchical protection strategy. For example, configure the first bridge arm with a number of fault modules with a minor threshold, and configure the second bridge arm with a number of fault modules with a severe threshold, etc. Then test whether the corresponding level protection mechanism of the current bridge arm can be triggered normally, and whether the system operation is within the corresponding protection strategy. If so, it means that the protection mechanism is normal.
[0030] Step 103: When the number of faults in a single bridge arm is not less than the minor threshold, determine whether a minor alarm is triggered and the system is running normally. If the alarm is triggered after deducting the number of faults cleared by maintenance, then the minor fault protection mechanism of the current bridge arm is normal.
[0031] Further, step 103 includes: S1: Start the real-time simulation model to close the circuit and charge. If the number of faults in a single bridge arm is not less than the minor threshold, and a minor alarm is triggered while the system is running normally, then enter the maintenance mode. S2: Lock down the real-time simulation model, trigger the flexible DC valve control system to switch to maintenance mode to clear faulty modules, and mark the fault clearing symbol; S3: Restart the real-time simulation model to charge the circuit breaker, determine whether the number of faults in a single bridge arm is less than the minor fault threshold, and whether the alarm is cleared and the system is running normally. If so, the minor fault protection mechanism of the current bridge arm is normal.
[0032] It should be noted that if the number of single-arm faults in the current bridge arm is not less than the minor threshold, it indicates that the protection conditions for the minor warning level have been triggered. In this case, if the bridge arm protection mechanism is normal, a minor alarm will be triggered, and the system will continue to operate normally. To improve the reliability of the test results and expand the test coverage of this embodiment, the fault repair and clearing situation is also considered. That is, the real-time simulation model is locked down, triggering the flexible DC valve control system to switch to maintenance mode to clear fault modules. It can directly clear faults until the number of single-arm faults is less than the minor threshold, and these cleared faults are marked as "fault modules cleared and replaced during shutdown maintenance". When charging is restarted and the number of faults is counted, the number of single-arm faults will no longer meet the minor warning conditions. If the alarm is cleared and the system operates normally at this time, it indicates that the bridge arm protection mechanism is responding normally and there is no problem. Since the number of faults cleared during maintenance must reach a level that ensures the number of single-arm faults is lower than the minor threshold to be meaningful for verification, the situation where the number of maintenance is not up to standard is not discussed. This can be adjusted according to actual testing and will not be elaborated further.
[0033] Understandably, when the real-time simulation model is charging and performing fault statistics and judgment, the converter valve needs to be unlocked to generate full rated power; after clearing the fault module in the maintenance mode, the maintenance mode needs to be exited through valve control.
[0034] Furthermore, step 103, followed by: Determine whether the number of single-arm faults in the current bridge arm is equal to the difference between the number of configured fault modules and the number of faults cleared. If so, determine that no faults have entered the bridge arm.
[0035] Since fault repair was performed after the minor alarm test, the number of single-arm faults in the current bridge arm is below the minor alarm threshold. If the number of faults in the current bridge arm is counted again at this time, it can be verified whether it is equal to the difference between the initially configured number of fault modules and the number of faults cleared after repair. If so, it means that no other bridge arm faults have entered the system. If no repair was performed, the counted number of faults is directly compared with the configured number of faults. If they match, it means that no faults have entered the system.
[0036] To further verify the accuracy of this test method, this embodiment can also set up a control group. Based on the minor alarm test described above, another bridge arm AD is added, also configured with a number of fault modules not less than the minor threshold, for example, directly the number of minor alarm modules, denoted as X. The number of single bridge arm faults x of this added bridge arm is detected and counted, and the protection action verification is performed based on the threshold comparison. If the protection action of the minor fault mechanism is triggered normally, and the number of faults x detected is consistent with the number of faults X configured, that is, the number of minor alarm modules, it indicates that there are no other bridge arm faults interfering with the added bridge arm.
[0037] Step 104: When the number of faults in a single bridge arm is not less than the critical threshold, determine whether a critical alarm is triggered and the system is operating normally. If so, the critical fault protection mechanism of the current bridge arm is normal.
[0038] Similarly, for other bridge arms, it can be determined whether the number of faulty modules deployed therein is not less than the critical threshold. If so, the critical fault protection strategy is triggered, i.e., a critical alarm is triggered, and the system continues to operate normally. If so, it means that the critical fault protection mechanism of the current bridge arm is normal.
[0039] If the number of faults in a single bridge arm is less than the severe threshold, insufficient to trigger a severe alarm mechanism, it can be determined whether the number of faults in a single bridge arm is not less than the minor threshold, i.e., between the minor and severe thresholds. In this case, a minor warning mechanism can be triggered, i.e., a minor alarm is triggered, and the system continues to operate normally without alarm escalation. In other words, alarm escalation, from a minor alarm to a severe alarm, can only be triggered when the number of faults in a single bridge arm is not less than the severe threshold. If the test results do not achieve the expected response, it indicates a problem with the protection mechanism, which cannot protect the normal operation of the system.
[0040] Step 105: When the number of faults in a single bridge arm is equal to the redundancy exhaustion threshold, determine whether a redundancy exhaustion alarm is triggered and the system is operating normally. If so, the redundancy exhaustion alarm protection mechanism of the current bridge arm is normal.
[0041] Because the redundancy depletion threshold is greater than the critical threshold, when other bridge arms determine the effectiveness of the redundancy protection mechanism, if the number of faults in a single bridge arm is less than the redundancy depletion threshold, the warning escalation cannot be triggered, that is, the redundancy depletion alarm mechanism cannot be triggered, and only the critical alarm is triggered; when the number of faults in a single bridge arm is equal to the redundancy depletion threshold, it indicates that the redundancy depletion alarm mechanism has been triggered. If the test executes a normal alarm and the system operates normally, it indicates that the redundancy depletion alarm protection mechanism of the current bridge arm is normal, and the flexible DC valve control system has achieved alarm escalation; this process will not trigger blocking or tripping.
[0042] Step 106: When the number of faults in a single bridge arm exceeds the redundancy depletion threshold, determine whether redundancy depletion tripping is triggered and the system is locked. If so, the redundancy depletion tripping protection mechanism of the current bridge arm is normal.
[0043] Furthermore, step 106, followed by: The test operation was completed by issuing a lockout command to the flexible direct current valve control system to keep the converter valve in a stable lockout state.
[0044] Similarly, if the number of faults in a single bridge arm exceeds the redundancy depletion threshold, observe whether the test process triggers redundancy depletion tripping and system lockout actions. If so, the protection strategy is executed normally, indicating that the redundancy depletion tripping protection mechanism of the current bridge arm is normal. Moreover, the redundancy depletion tripping alarm message in this embodiment is the highest level alarm signal. The valve control system will trigger the outlet lockout tripping, and the converter valve will automatically enter the lockout state. The polar control system will issue a formal lockout command to keep the converter valve in a stable lockout state without any abnormal signals. At this point, the test ends.
[0045] It should be noted that the hierarchical protection alarm mechanisms for minor alarms, serious alarms, redundancy exhaustion alarms, and redundancy exhaustion trips can only be triggered when their respective alarm thresholds are reached. For example, if the number of faults reaches the minor alarm range but not the serious alarm range, only a minor alarm will be triggered. The test will only pass if the actions are triggered according to this mechanism; otherwise, the test will fail.
[0046] Furthermore, regardless of the execution order of the above minor alarm tests, severe alarm tests, redundancy exhaustion alarm tests, or tripping tests—for example, whether the tests are performed sequentially according to severity or simultaneously—one point must be ensured: during the testing phase, the number of single-arm faults detected and counted in the current arm should be consistent with the number of faults configured earlier, or consistent with the number of faults after deducting the fault clearing modules for maintenance. This ensures that the number of faults in a single arm is kept constant, thereby ensuring that the statistics of the number of faults in a single arm are not affected by the intrusion of faults in other arms.
[0047] If the above testing process is a progressive sequential operation, with the initial fault statistics of all bridge arms reset to zero, test bridge arms can be added progressively according to the alarm level. Each time a new bridge arm is added to the test, the statistical results and alarm level are checked and verified. This can verify the trigger boundary of each threshold level, as well as the dynamic escalation process of the main control board alarm priority as the number of faults increases. It also makes it easier to locate the specific bridge arm where the error occurred, reducing the difficulty of troubleshooting.
[0048] If the above testing process is a parallel deployment test, and the number of fault modules deployed in each bridge arm is known, the number of faults in each single bridge arm counted by the flexible DC valve control system can be compared one by one with the number of faults configured and deployed. If there is maintenance, the number of faults cleared by maintenance can be deducted. If the numbers are consistent, it can be proven that there is no code defect that crosses the number of faults.
[0049] In other words, whether the test method in this embodiment is executed simultaneously or sequentially will not affect the test results. It can still achieve fault over-limit protection strategy testing with a wide coverage range and realize hierarchical protection of faults, ensuring more stable operation of the system and avoiding high-frequency blocking impacts.
[0050] As a test case, taking six bridge arms as an example, specifically AU, AD, BU, BD, CU, and CD, the test uses sequential execution timing logic, that is, gradually increasing the test bridge arms on the test platform. First, before the real-time simulation model is closed for charging, a slight threshold can be configured for the AU bridge arm. The faulty module, namely the AU bridge arm. Each module was marked as faulty; then, charging was initiated, the converter valve was unlocked, and after the load was increased to full rated power and stable operation was achieved, the number of single-arm faults in the AU arm was counted. ,judge In fact This can trigger a minor alarm. If a minor alarm is triggered directly during the test and the system is running normally without any blocked trip output, it means that the protection strategy is being executed normally. At this time, the number of faults in other bridge arms is 0, and they are not included in the test.
[0051] Then, the real-time simulation model can be shut down, and the flexible DC valve control system can be switched to maintenance mode. In maintenance mode, the AU bridge arm front... Each module is marked as a faulty module that has been cleared and replaced during the shutdown and maintenance period. After marking, the maintenance mode is exited. Then, the AC incoming circuit breaker is closed again for charging, the converter valve is unlocked, and the rated power is restored. After stable operation, the number of faults in a single AU bridge arm is detected and counted. And perform alarm judgment based on a slight threshold, obviously That is to say, At this point, a minor alarm should not be triggered, and the system should operate normally. If it is, then the test is passed.
[0052] A new AD bridge arm was added for testing, and the AD bridge arm was configured under the same conditions. Each faulty module is identified and marked; then the number of faults per AD bridge arm is counted at this time. If the quantity and If the alarms are consistent and trigger the normal minor alarm mechanism, it means that the AD bridge arm was not affected by the AU bridge arm when counting the number of faults, and its alarm mechanism is also normal; that is, there is no situation where the number of faults across bridge arms is entered.
[0053] Next, the BU bridge arm can be added for testing, and a severe threshold can be configured for the BU bridge arm under the same conditions. The number of faulty modules is determined, and then the number of single-arm faults in the BU bridge arm is counted at this time. According to theory, as long as This can trigger the critical alarm mechanism, at which point... Therefore, the expected test result is that a severe alarm mechanism is triggered, and the system operates normally, achieving fault alarm escalation. If the number of counted faults does not reach the severe threshold, only a minor alarm mechanism is triggered. This test can be verified on the BD bridge arm, which will not be elaborated here. Moreover, at this time, the number of faults in a single BU bridge arm... Should with The results must be consistent; otherwise, there is a possibility of the number of faults in the bridge arm being entered into the code. Based on this, it can be verified whether there is a code defect.
[0054] Similarly, a CU bridge arm is added, and under the same conditions, a redundancy depletion threshold is configured for the CU bridge arm. The system counts the number of faulty modules and monitors protection actions based on thresholds. If the redundancy exhaustion alarm is triggered normally and the system is operating normally, then the current protection strategy is normal. The CD bridge arm can be used to verify whether the redundancy exhaustion alarm mechanism is not triggered when the number of faults does not reach the redundancy exhaustion threshold, and only the critical alarm mechanism is triggered.
[0055] If the number of faults in the CU bridge arm configuration exceeds the redundancy exhaustion threshold Number of faulty modules, for example The number of single bridge arm failures will be counted. With redundancy exhaustion threshold In comparison, it is clear that the redundancy exhaustion alarm mechanism has been triggered. Then observe whether the expected redundancy exhaustion trip protection strategy is triggered. At this time, the system is directly blocked, and the flexible DC valve control system outputs a redundancy exhaustion trip message, which is regarded as the highest level alarm signal. If the observed operation is triggered normally, the test is passed.
[0056] This application also provides an application example of fault detection based on a preset hierarchical protection strategy. Taking a six-arm system as an example, that is, the six arm control boards of the flexible DC valve control system, each arm control board is responsible for controlling and monitoring one arm of the flexible DC converter valve. Each arm control board will automatically detect the number of modules with accumulated faults in the arm corresponding to the converter valve in real time. The fault module count detection logic for the six boom control boards is independent of each other. The fault module count detection process for a single boom control board is as follows: 1) The control board of a single bridge arm detects the total number of faulty modules in the corresponding bridge arm in real time, and then subtracts the total number of faulty modules that were cleared or replaced during the last system shutdown and maintenance, thus obtaining the total number of faulty modules in the corresponding bridge arm at the current moment. And will continue to update; 2) The control board of a single bridge arm detects the cumulative number of faulty modules in the corresponding bridge arm in real time. ,if The bridge arm control board will send a "minor alarm" signal to the upper-level flexible direct current valve control system main control board; 3) The control board of a single bridge arm detects the cumulative number of faulty modules in the corresponding bridge arm in real time. ,if The bridge arm control board will send a "critical alarm" signal to the upper-level flexible direct current valve control system main control board; 4) The control board of a single bridge arm detects the cumulative number of faulty modules in the corresponding bridge arm in real time. ,if , Typically, the number of redundant modules N in a single bridge arm is taken. 冗余 The bridge arm control board will send a "redundancy exhaustion alarm" signal to the upper-level flexible direct current valve control system main control board; 5) The control board for each bridge arm monitors the cumulative number of faulty modules in the corresponding bridge arm in real time. ,if The bridge arm control board will send a "redundancy exhaustion trip" signal to the upper-level flexible DC valve control system main control board.
[0057] In addition, the number of faulty modules in the six bridge arms in this case. Upon detection, the upper-level flexible direct current valve control system main control board will monitor the alarm / fault signals sent from each bridge arm control board in real time and process them according to the following logic: 1) The severity levels of alarm signals are ranked as follows: "Redundancy exhaustion trip" > "Redundancy exhaustion alarm" > "Severe alarm" > "Minor alarm"; 2) The main control board of the flexible DC valve control system selects the signal with the highest severity level among the 6 bridge arm signals as the final output signal of the entire flexible DC valve control system; 3) When "redundancy exhaustion trip" is the highest severity signal, the flexible DC valve control system will report a "redundancy exhaustion trip" message, and the system output will be blocked from tripping; 4) When the "redundancy exhaustion alarm" is the highest severity level signal, the flexible DC valve control system will report a "redundancy exhaustion alarm" message. The system will operate normally without output blocking or tripping, reminding the operators to immediately apply for temporary shutdown. 5) When the "Critical Alarm" is the highest level of severity signal, the flexible DC valve control system will report a "Critical Alarm" message. The system will operate normally without output blocking or tripping, and will remind operators to apply for temporary shutdown as appropriate. 6) When the "minor alarm" is the highest severity level signal, the flexible DC valve control system will report a "minor alarm" message. The system will operate normally without output blocking or tripping, reminding operators to pay attention to changes in the number of faulty modules.
[0058] The over-limit protection test method for the number of fault modules in a flexible DC valve control system provided in this application embodiment sets up a preset hierarchical protection strategy including minor threshold, severe threshold, and redundancy exhaustion threshold. Different threshold judgment nodes correspond to verifying the hierarchical alarm and trip protection action logic under different numbers of faults. By verifying the alarm status and system operation status layer by layer, the effectiveness of the hierarchical protection mechanism can be fully verified, ensuring that the fault module accumulation process can output differentiated early warning signals in a layered manner. In addition, the test scheme uses the number of faults in a single bridge arm as the basis for analysis, and configures an independent statistical unit such as a detection main control board for each bridge arm. Then, the protection mechanisms at each level of different bridge arms are verified separately, ensuring the independence of fault statistics for each bridge arm and avoiding unplanned outages caused by protection maloperation. Moreover, this process also verifies the protection status under the condition of deducting the number of faults after bridge arm maintenance and clearing, which can cover the core rules of the fault statistics algorithm to a large extent and make up for the verification blind spots of traditional single bridge arm tests. Therefore, the embodiments of this application can solve the technical problems of existing protection strategies lacking a graded early warning mechanism, which makes the system extremely vulnerable to tripping and blocking impacts, and the protection test scheme having limited coverage dimensions, failing to detect fault statistical crosstalk between bridge arms, and easily causing protection maloperation.
[0059] For easier understanding, please refer to Figure 2This application provides an embodiment of a test system for over-limit protection against faulty modules in a flexible direct current valve control system, including: The fault deployment unit 201 is used to configure multiple fault modules for each bridge arm according to a preset hierarchical protection strategy. The preset hierarchical protection strategy includes a minor threshold, a severe threshold, and a redundancy exhaustion threshold. The quantity counting unit 202 is used to count the number of fault modules on the corresponding bridge arm through the detection main control board configured for each bridge arm, so as to obtain the number of faults in a single bridge arm. The first test unit 203 is used to determine whether a minor alarm is triggered when the number of faults in a single bridge arm is not less than the minor threshold, and the system is running normally. If the alarm is triggered after deducting the number of faults cleared by maintenance, then the minor fault protection mechanism of the current bridge arm is normal. The second test unit 204 is used to determine whether a serious alarm is triggered and the system is running normally when the number of faults in a single bridge arm is not less than the serious threshold. If so, the serious fault protection mechanism of the current bridge arm is normal. The third test unit 205 is used to determine whether a redundancy exhaustion alarm is triggered and the system is running normally when the number of single bridge arm failures is equal to the redundancy exhaustion threshold. If so, the redundancy exhaustion alarm protection mechanism of the current bridge arm is normal. The fourth test unit 206 is used to determine whether to trigger a redundancy depletion trip and system lockout when the number of faults in a single bridge arm exceeds the redundancy depletion threshold. If so, the redundancy depletion trip protection mechanism of the current bridge arm is normal.
[0060] Furthermore, it also includes a test platform setup unit 207, used for: Construct a closed-loop test environment for the real-time simulation model and the flexible direct current valve control system, and configure a fault simulation device, a valve control monitoring backend, and a maintenance mode operation entry. Configure basic parameter information in the flexible DC valve control system. The basic parameter information includes the total number of modules in a single bridge arm, the number of redundant modules in a single bridge arm, and the preset hierarchical protection strategy. The parameters and states of the relevant equipment in the real-time simulation model and the flexible direct current valve control system are initialized.
[0061] Furthermore, the first test unit 203 is specifically used for: S1: Start the real-time simulation model to close and charge. If the number of faults in a single bridge arm is not less than the minor threshold, and a minor alarm is triggered while the system is running normally, then proceed to S2. S2: Lock down the real-time simulation model, trigger the flexible DC valve control system to switch to maintenance mode to clear faulty modules, and mark the fault clearing symbol; S3: Restart the real-time simulation model to charge the circuit breaker, determine whether the number of faults in a single bridge arm is less than the minor fault threshold, and whether the alarm is cleared and the system is running normally. If so, the minor fault protection mechanism of the current bridge arm is normal.
[0062] Furthermore, it also includes a fault statistics test unit 208, used for: Determine whether the number of single-arm faults in the current bridge arm is equal to the difference between the number of configured fault modules and the number of faults cleared. If so, determine that no faults have entered the bridge arm.
[0063] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0064] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0065] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0066] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for executing all or part of the steps of the methods described in the various embodiments of this application through a computer device (which may be a personal computer, server, or network device, etc.). The aforementioned storage medium includes: USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media capable of storing program code.
[0067] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A test method for over-limit protection of fault modules in a flexible direct current valve control system, characterized in that, include: Each bridge arm is configured with multiple fault modules according to a preset hierarchical protection strategy, which includes a minor threshold, a severe threshold, and a redundancy exhaustion threshold. The number of faults in a single bridge arm is obtained by counting the number of fault modules on the corresponding bridge arm through the detection main control board configured in each bridge arm. When the number of faults in a single bridge arm is not less than the minor threshold, it is determined whether a minor alarm is triggered and the system is operating normally. If the alarm is triggered and cleared after deducting the number of faults cleared by maintenance, then the minor fault protection mechanism of the current bridge arm is normal. When the number of faults in a single bridge arm is not less than the critical threshold, it is determined whether a critical alarm is triggered and the system is operating normally. If so, the critical fault protection mechanism of the current bridge arm is normal. When the number of single bridge arm failures is equal to the redundancy exhaustion threshold, determine whether a redundancy exhaustion alarm is triggered and the system is operating normally. If so, the redundancy exhaustion alarm protection mechanism of the current bridge arm is normal. When the number of faults in a single bridge arm exceeds the redundancy depletion threshold, it is determined whether a redundancy depletion trip is triggered and the system is locked. If so, the redundancy depletion trip protection mechanism of the current bridge arm is normal.
2. The test method for over-limit protection of the number of fault modules in a flexible direct current valve control system according to claim 1, characterized in that, The configuration of multiple fault modules for each bridge arm according to a preset hierarchical protection strategy, prior to which also includes: Construct a closed-loop test environment for the real-time simulation model and the flexible direct current valve control system, and configure a fault simulation device, a valve control monitoring backend, and a maintenance mode operation entry. In the flexible direct current valve control system, basic parameter information is configured, including the total number of modules in a single bridge arm, the number of redundant modules in a single bridge arm, and a preset hierarchical protection strategy. The parameters and states of the real-time simulation model and the relevant equipment of the flexible direct current valve control system are initialized.
3. The test method for over-limit protection of fault module number in a flexible direct current valve control system according to claim 2, characterized in that, The configuration of multiple fault modules for each bridge arm according to a preset hierarchical protection strategy includes: Before the real-time simulation model is closed for charging, the fault simulation device configures multiple fault modules for each bridge arm according to a preset hierarchical protection strategy.
4. The test method for over-limit protection of fault module number in a flexible direct current valve control system according to claim 2, characterized in that, When the number of faults in a single bridge arm is not less than the minor threshold, it is determined whether a minor alarm is triggered, and the system is operating normally. Furthermore, if the alarm is cleared after deducting the number of faults cleared through maintenance, then the minor fault protection mechanism for the current bridge arm is normal, including: S1: Start the real-time simulation model to close and charge. If the number of single bridge arm faults is not less than the minor threshold, and a minor alarm is triggered while the system is running normally, proceed to S2. S2: Lock down the real-time simulation model, trigger the flexible direct current valve control system to switch to maintenance mode to clear fault modules, and mark the fault clearing symbol; S3: Restart the real-time simulation model to charge, determine whether the number of faults in a single bridge arm is less than the minor threshold, and whether the alarm is cleared and the system is running normally. If so, the minor fault protection mechanism of the current bridge arm is normal.
5. The test method for over-limit protection of fault module number in a flexible direct current valve control system according to claim 1, characterized in that, When the number of faults in a single bridge arm is not less than the minor threshold, it is determined whether a minor alarm is triggered, and the system is operating normally. Furthermore, if the alarm is cleared after deducting the number of faults cleared through maintenance, then the minor fault protection mechanism for the current bridge arm is normal. The process then further includes: Determine whether the number of single-arm faults in the current bridge arm is equal to the difference between the number of configured fault modules and the number of faults cleared during maintenance. If so, determine that no cross-arm faults have entered the system.
6. The test method for over-limit protection of the number of fault modules in a flexible direct current valve control system according to claim 2, characterized in that, When the number of faults in a single bridge arm exceeds the redundancy depletion threshold, it is determined whether a redundancy depletion trip is triggered and the system is locked. If so, the redundancy depletion trip protection mechanism of the current bridge arm is normal. The process then further includes: The test operation ends by issuing a lockout command to the flexible direct current valve control system to keep the converter valve in a stable lockout state.
7. A test system for over-limit protection of the number of fault modules in a flexible direct current valve control system, characterized in that, include: The fault deployment unit is used to configure multiple fault modules for each bridge arm according to a preset hierarchical protection strategy, which includes a minor threshold, a severe threshold, and a redundancy exhaustion threshold. The quantity counting unit is used to count the number of fault modules on the corresponding bridge arm through the detection main control board configured in each bridge arm, so as to obtain the number of faults in a single bridge arm; The first test unit is used to determine whether a minor alarm is triggered when the number of faults in a single bridge arm is not less than the minor threshold, and the system is operating normally. If the alarm is triggered after deducting the number of faults cleared by maintenance, then the minor fault protection mechanism of the current bridge arm is normal. The second test unit is used to determine whether a serious alarm is triggered and the system is operating normally when the number of faults in a single bridge arm is not less than the serious threshold. If so, the serious fault protection mechanism of the current bridge arm is normal. The third test unit is used to determine whether a redundancy exhaustion alarm is triggered and the system is operating normally when the number of single bridge arm failures is equal to the redundancy exhaustion threshold. If so, the redundancy exhaustion alarm protection mechanism of the current bridge arm is normal. The fourth test unit is used to determine whether to trigger a redundancy depletion trip and system lockout when the number of faults in a single bridge arm exceeds the redundancy depletion threshold. If so, the redundancy depletion trip protection mechanism of the current bridge arm is normal.
8. The test system for over-limit protection of fault module number in a flexible direct current valve control system according to claim 7, characterized in that, It also includes a test platform setup unit, used for: Construct a closed-loop test environment for the real-time simulation model and the flexible direct current valve control system, and configure a fault simulation device, a valve control monitoring backend, and a maintenance mode operation entry. In the flexible direct current valve control system, basic parameter information is configured, including the total number of modules in a single bridge arm, the number of redundant modules in a single bridge arm, and a preset hierarchical protection strategy. The parameters and states of the real-time simulation model and the relevant equipment of the flexible direct current valve control system are initialized.
9. The test system for over-limit protection of fault module number in a flexible direct current valve control system according to claim 8, characterized in that, The first test unit is specifically used for: S1: Start the real-time simulation model to close and charge. If the number of single bridge arm faults is not less than the minor threshold, and a minor alarm is triggered while the system is running normally, proceed to S2. S2: Lock down the real-time simulation model, trigger the flexible direct current valve control system to switch to maintenance mode to clear fault modules, and mark the fault clearing symbol; S3: Restart the real-time simulation model to charge, determine whether the number of faults in a single bridge arm is less than the minor threshold, and whether the alarm is cleared and the system is running normally. If so, the minor fault protection mechanism of the current bridge arm is normal.
10. The test system for over-limit protection of the number of fault modules in a flexible direct current valve control system according to claim 7, characterized in that, It also includes a fault statistics test unit, used for: Determine whether the number of single-arm faults in the current bridge arm is equal to the difference between the number of configured fault modules and the number of faults cleared during maintenance. If so, determine that no cross-arm faults have entered the system.