Intelligent lightning protection online monitoring method and system based on multi-terminal data fusion

CN122815031APending Publication Date: 2026-09-25广州都信电子科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610959869.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-30
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

现有系统在处理这些数据时,通常仍以单终端阈值判断、服务器接收时间排序或简单时间窗口聚合为主,容易将同一次雷击中的雷电流突变、SPD动作、漏电流变化、温度变化和接地阻值响应排列成错误顺序,也容易把无关时段的数据纳入同一次报警过程

Benefits of technology

[0016]上述处理过程中,监控服务器保存候选事件窗口编号、参与终端编号、原始数据帧索引、链路补偿来源、统一事件时间轴、雷击事件链编号和事件化处置结果,使从终端采集到在线处置的技术链条能够追溯;当某一终端数据缺失、通信补偿不可用或现场拓扑配置失效时,服务器不强行生成完整事件链,而是记录不可判定原因并限制对应结果的报警等级。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122815031A_ABST
    Figure CN122815031A_ABST
Patent Text Reader

Abstract

The application provides an intelligent lightning protection online monitoring method and system based on multi-terminal data fusion, which comprises the following steps: taking lightning current waveform mutation or SPD action state change as a trigger source, constructing a lightning candidate event window in a monitoring server; using gateway polling records, wireless retransmission records, waveform cache upload records and terminal configuration upload periods to form a candidate compensation set corresponding to the terminal of the current event point, and generating a unified event time axis; based on the unified event time axis, generating a lightning event chain with a propagation direction; according to the lightning event chain, performing eventized treatment analysis on the chain nodes, identifying main abnormal nodes, affected nodes, propagation paths, alarm levels and treatment priorities, and executing eventized online monitoring treatment. The application improves the accuracy of lightning event sequence judgment, propagation process restoration and operation and maintenance treatment direction on the basis of keeping the basic deployment mode of the field terminal stable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of intelligent online lightning protection monitoring, and particularly relates to an intelligent online lightning protection monitoring method and system based on multi-terminal data fusion. Background Technology

[0002] With the increasing density of electronic equipment in scenarios such as communication base stations, rail transit, power distribution rooms, petrochemical stations, smart parks, and important computer rooms, the impact of lightning surges on the safe operation of equipment is becoming increasingly prominent. Relying on manual inspections, periodic testing, and single-point alarms for lightning protection management is no longer sufficient to reflect the true operating status of on-site lightning protection systems in a timely manner. Existing online lightning protection monitoring solutions typically involve deploying SPD intelligent monitoring terminals, grounding resistance monitors, lightning current waveform recorders, and environmental sensors associated with the installation points on-site. Data such as SPD operation status, leakage current, temperature, grounding resistance, and lightning current waveforms are uploaded to a data acquisition gateway via RS485, wireless, or Ethernet. The gateway then aggregates the data and sends it to a monitoring server for storage, display, alarm functions, and sharing with third-party platforms. Compared to manual detection, this type of solution has achieved remote and online capabilities. However, in engineering sites, a single lightning strike or surge disturbance is often short in duration and exhibits rapid waveform changes. Furthermore, different terminals have inconsistent data sampling methods, upload cycles, communication links, and local time stamps. Lightning current waveform recorders typically latch waveforms in a burst mode, SPD intelligent monitoring terminals usually upload action, leakage current, and temperature data in a state change or periodic manner, grounding resistance monitors typically upload grounding resistance data at a lower frequency, and environmental sensors are used to provide slowly changing state quantities such as installation point temperature. Existing systems, when processing this data, typically still rely on single-terminal threshold judgment, server-received time sorting, or simple time window aggregation. This can easily lead to incorrect sequencing of lightning current surges, SPD actions, leakage current changes, temperature changes, and grounding resistance responses from the same lightning strike, and can also easily include data from irrelevant time periods in the same alarm process. Especially in scenarios with multiple SPDs, multiple grounding busbars, or multiple feeders, multiple terminals may experience consecutive anomalies within a short period. Without event windows, link compensation, and propagation mechanisms for the lightning strike process, the monitoring server can only display multiple isolated anomalies, making it difficult to determine which node is closer to the lightning trigger source, which nodes belong to subsequently affected equipment, and which changes are merely accompanying responses within the same discharge process. For example, in a distribution cabinet, a lightning current waveform recorder first records a sudden change in lightning current, followed by the activation of a primary SPD, then leakage current and temperature rise changes in a secondary SPD, and finally, a grounding resistance monitor records the grounding resistance response. However, due to bus polling, wireless retransmission, or periodic upload delays, the server's receiving order may differ from the actual order of occurrence on-site, leading to deviations in the root cause assessment of the alarm. Furthermore, leakage current, temperature, and grounding resistance are different types of engineering quantities. Comparing only the original amplitude changes makes it difficult to reasonably determine the main anomaly nodes and their handling priorities within the same lightning strike event chain.Therefore, although existing online lightning protection monitoring technologies have the capabilities of multi-terminal data collection, gateway uploading, alarm display, and platform sharing, they still have shortcomings in determining the data boundaries of the same lightning strike event, asynchronous time correction, reconstruction of event propagation relationships, and generation of event-based handling results. This makes it easy for online monitoring results to remain at the level of detecting anomalies and issuing separate alarms, making it difficult for maintenance personnel to make accurate judgments on lightning propagation paths, major abnormal nodes, affected equipment, and handling priorities.

[0003] The technical essence of the above problem lies in the inconsistency of the acquisition clock, communication link, sampling period, and equipment topology of various types of lightning protection monitoring terminals, making it difficult to reconstruct the physical response during the same lightning strike into a reliable event chain in the monitoring server. Therefore, an online monitoring and processing method is needed that can define event boundaries, correct time offsets of multiple terminals, reconstruct the propagation path by combining the lightning protection structure topology, and output event-level monitoring results, rather than just providing manual management suggestions. Summary of the Invention

[0004] The purpose of this invention is to propose an intelligent online lightning protection monitoring method and system based on multi-terminal data fusion to solve the above-mentioned problems.

[0005] To achieve the above objectives, a first aspect of the present invention provides an intelligent online lightning protection monitoring method and system based on multi-terminal data fusion, comprising: Using sudden changes in lightning current waveform or changes in SPD operating status as trigger sources, a lightning strike candidate event window is constructed in the monitoring server, and the SPD operating status, leakage current, temperature, grounding resistance and lightning current waveform data in the lightning strike candidate event window are obtained. Based on the lightning strike candidate event window, a candidate compensation set corresponding to the terminal to which the current event point belongs is formed by using gateway polling records, wireless retransmission records, waveform buffer upload records and terminal configuration upload cycle, so as to generate the selected link compensation time of the current event point and the corrected event time of the current event point. Compensation value selection and time conversion are performed on lightning current sudden change event points, SPD action event points, leakage current change event points, temperature change event points and grounding resistance change event points to generate a unified event time axis. Based on the unified event timeline, the pre-entered SPD hierarchical relationship, grounding connection relationship, and equipment installation location relationship are invoked. Event points serve as chain nodes, and the link association value between event points is determined by time proximity, equipment topology, and state propagation direction to generate a lightning strike event chain with propagation direction. The lightning strike event chain retains the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp, and corrected event time for each chain node, and records the connection relationship between chain nodes according to the propagation direction. Based on the lightning strike event chain, the chain nodes are analyzed for event-based handling to identify major abnormal nodes, affected nodes, propagation paths, alarm levels, and handling priorities, and event-based online monitoring and handling are executed.

[0006] Preferably, the step of constructing a lightning strike candidate event window in the monitoring server specifically involves: Centered on the triggering time of the triggering source, a first preset range is extracted forward and a second preset range is extracted backward. The lightning current waveform, SPD operation status, leakage current, temperature and grounding resistance data falling within the time interval are grouped into the same event window. When multiple triggering sources appear within the overlapping range of the window, they are merged into the same window and multiple triggering sources are retained.

[0007] Preferably, the first preset range is used to retain the equipment state before the lightning strike; the second preset range is used to retain the changes in leakage current, temperature and grounding resistance after the SPD is activated.

[0008] Preferably, the candidate compensation set includes: For SPD intelligent monitoring terminals accessed via RS485, the candidate compensation set comes from the polling wait records saved by the gateway during that time period; for terminals accessed via wireless means, the candidate compensation set comes from the retransmission wait records saved by the gateway; for lightning current waveform recorders, the candidate compensation set comes from the device logs between waveform buffer write records and upload records; for grounding resistance monitors, the candidate compensation set comes from the period offset formed between their configured upload period and the gateway's received records.

[0009] Preferably, the link compensation time is generated based on the terminal's original timestamp at the current event point, a candidate value in the candidate compensation set, the terminal's original timestamp corresponding to the triggering event, the collection cycle or upload cycle recorded by the current terminal in the gateway configuration table, and the scenario sequence deviation corresponding to the current candidate compensation value, and is used to determine the compensation value that should be adopted for the current event point from the candidate compensation set; The corrected event time for the current event point is generated based on the terminal's original time stamp for the current event point and the link compensation time.

[0010] Preferably, the unified event timeline is generated by arranging each event point from early to late based on the corrected event time to form a unified event timeline.

[0011] Preferably, the link association value is calculated as follows: it is generated by summing the time proximity item, device association item, and state propagation direction item after multiplying them by their corresponding weights; wherein, the time proximity item is determined by the acquisition cycle or upload cycle of the terminal to which the candidate subsequent event belongs and the event time interval; the device association item comes from the SPD hierarchy relationship, grounding connection relationship, and device installation location relationship; and the state propagation direction item comes from the server's judgment on the order of event types and the direction of change of monitoring quantity. The corresponding weight is the proportional weight preset by the server in the lightning protection monitoring configuration.

[0012] Preferably, the generation of the lightning strike event chain with a propagation direction specifically includes: Using a lightning current mutation event or an SPD activation event as the starting point of the chain, subsequent events whose link association values ​​reach the threshold are sequentially connected to the end of the chain according to the corrected event time sequence, forming a directed propagation path from lightning strike triggering or SPD discharge to grounding response. If multiple candidate events meet the connection conditions, the server will prioritize the event with the closer device association. The lightning strike event chain is continuously expanded until the link correlation value between the subsequent event and the current chain tail event is lower than the connection threshold set by the system, or there are no candidate events in the unified event timeline that are after the current chain tail event and belong to the same lightning protection structure.

[0013] Preferably, the event-based handling analysis of chain nodes involves calculating the intra-chain impact value of each chain node, specifically including: It is generated by combining the proportional change amplitude, hierarchical enhancement term, and propagation time attenuation term corresponding to the node; wherein, the hierarchical enhancement term is determined according to the hierarchical position of the equipment to which the chain node belongs in the on-site lightning protection structure, and the propagation time attenuation term is determined according to the ratio of the time distance of the current chain node relative to the chain start point to the terminal acquisition cycle or upload cycle; The event-based online monitoring and handling includes: saving the lightning strike event chain number, chain node information, major abnormal nodes, affected nodes, propagation path, alarm level, and handling priority; displaying the event propagation path on the monitoring interface; triggering audible and visual alarms; generating historical event query records; and pushing event summaries to third-party platforms via API.

[0014] A second aspect of the present invention provides an intelligent online lightning protection monitoring system based on multi-terminal data fusion, the system comprising: The event window generation module is used to construct a lightning strike candidate event window in the monitoring server based on lightning current waveform abrupt change or SPD action status change as the trigger source, and to obtain SPD action status, leakage current, temperature, grounding resistance and lightning current waveform data in the lightning strike candidate event window. The timing correction module is used to form a candidate compensation set corresponding to the terminal to which the current event point belongs based on the lightning strike candidate event window, using gateway polling records, wireless retransmission records, waveform buffer upload records and terminal configuration upload cycle, so as to generate the selected link compensation time of the current event point and the corrected event time of the current event point. It performs compensation value selection and time conversion for lightning current change event points, SPD action event points, leakage current change event points, temperature change event points and grounding resistance change event points to generate a unified event time axis. The event chain generation module is used to generate a lightning strike event chain with a propagation direction by calling the pre-entered SPD hierarchical relationship, grounding connection relationship and equipment installation location relationship based on the unified event timeline, with event points as chain nodes, and determining the link association value between event points through time proximity, equipment topology and state propagation direction; wherein, the lightning strike event chain retains the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp and corrected event time of each chain node, and records the connection relationship between chain nodes according to the propagation direction; The online handling module is used to perform event-based handling analysis on the chain nodes according to the lightning strike event chain, identify the main abnormal nodes, affected nodes, propagation paths, alarm levels and handling priorities, and perform event-based online monitoring and handling.

[0015] The beneficial technical effects of the present invention are at least as follows: This invention addresses the engineering problems in multi-terminal online lightning protection monitoring, such as the difficulty in attributing continuous data to the same lightning strike process, time discrepancies between different terminal events, lack of propagation relationships among multiple anomalies, and the inability of handling results to directly guide operation and maintenance. It proposes an event-based fusion processing scheme based on an existing architecture of SPD intelligent monitoring terminals, grounding resistance monitors, lightning current waveform recorders, environmental sensors, data acquisition gateways, and monitoring servers. The scheme first uses lightning current waveform mutations or SPD action status changes as trigger sources. A lightning strike candidate event window is constructed in the monitoring server, incorporating lightning current waveforms, SPD action status, leakage current, temperature, and grounding resistance data before and after the same suspected lightning strike or surge disturbance into the same event data object, providing clear data boundaries for subsequent processing. Subsequently, the server uses gateway polling records, wireless retransmission records, waveform cache upload records, and terminal configuration upload cycles to form candidate compensation sets for different terminals. Combining the proximity of trigger times and the engineering sequence relationships between lightning current mutations, SPD actions, leakage current changes, temperature changes, and grounding resistance responses, a link compensation value is selected for each event point, resulting in a unified event timeline. This allows multiple terminal events during the same lightning strike process to be arranged in a reliable chronological order. Based on a unified event timeline, this invention further utilizes the SPD hierarchy, grounding connection relationships, and equipment installation location relationships saved during the system deployment phase. Each event point is treated as a propagation node in the lightning protection structure for connection and judgment. The lightning strike event chain is determined by time proximity, equipment topology, and state propagation direction, organizing lightning strike triggering, SPD discharge, equipment state changes, and grounding response into an event path with a propagation direction. Finally, the monitoring server performs event-based handling analysis on the chain nodes based on this lightning strike event chain. It proportionalizes the change amplitudes of different types of monitored quantities and determines the impact value within the chain by combining the equipment hierarchy location and the propagation position of the node relative to the chain start point. This identifies major abnormal nodes, affected nodes, propagation paths, alarm levels, and handling priorities, and executes event storage, historical query record generation, audible and visual alarm triggering, and third-party platform API sharing. Through the above processing, the present invention upgrades the existing online lightning protection monitoring system from a single-point threshold alarm to a system that integrates multi-terminal data fusion, time correction, event chain reconstruction, and online handling around a single lightning strike process. It can improve the accuracy of lightning strike event sequence judgment, propagation process reconstruction, and operation and maintenance handling direction while maintaining the stability of the basic deployment mode of on-site terminals.

[0016] During the above process, the monitoring server saves the candidate event window number, participating terminal number, original data frame index, link compensation source, unified event timeline, lightning strike event chain number, and event-based handling result, so that the technical chain from terminal data collection to online handling can be traced. When a terminal data is missing, communication compensation is unavailable, or the on-site topology configuration fails, the server does not forcibly generate a complete event chain, but records the undetermined cause and limits the alarm level of the corresponding result. Attached Figure Description

[0017] The present invention will be further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present invention. For those skilled in the art, other drawings can be obtained based on the following drawings without creative effort.

[0018] Figure 1 This is a flowchart of the intelligent online lightning protection monitoring method based on multi-terminal data fusion according to the present invention. Detailed Implementation

[0019] Embodiments of the present invention are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.

[0020] like Figure 1 As shown in the figure, the intelligent online lightning protection monitoring method based on multi-terminal data fusion provided by the embodiments of the present invention includes: S1. Using sudden changes in lightning current waveform or changes in SPD operating status as trigger sources, construct a lightning strike candidate event window in the monitoring server, and obtain the SPD operating status, leakage current, temperature, grounding resistance and lightning current waveform data in the lightning strike candidate event window.

[0021] Specifically, this step is used to extract the data range related to the same suspected lightning strike or surge disturbance from continuously uploaded multi-terminal lightning protection monitoring data, forming a lightning strike candidate event window for subsequent time series correction. The data processed comes from SPD intelligent monitoring terminals, grounding resistance monitors, lightning current waveform recorders, and environmental sensors in the existing field system, and is uploaded to the monitoring server by the data acquisition gateway. The SPD intelligent monitoring terminal provides SPD operation status and leakage current data, and provides SPD module temperature or receives installation point temperature data uploaded by its associated environmental sensors; the grounding resistance monitor provides grounding resistance data; and the lightning current waveform recorder provides lightning current waveform data. Each data frame contains at least the device desensitization number, terminal type, original timestamp, monitoring quantity type, and monitoring quantity value. The device desensitization number is used to distinguish different field devices, the original timestamp is obtained by mapping the terminal's local recording time or the gateway's access record, and is stored in the corresponding field time series of the gateway, and the monitoring quantity type is used to distinguish between lightning current, SPD operation status, leakage current, temperature, and grounding resistance. During on-site operation, the lightning current waveform recorder continuously buffers short-time waveforms, latching waveform segments before and after the abrupt change when a rapid rise in waveform is detected; the SPD intelligent monitoring terminal uploads data when the SPD status changes or during periodic data acquisition; the grounding resistance monitor uploads grounding resistance values ​​according to a set period; and the environmental sensor uploads temperature data at the corresponding location after being bound to the SPD installation point. The monitoring server uses the original timestamp as the basis for event interception, and combines it with the device desensitization number and monitoring quantity type to group data from different terminals into the same candidate event range.

[0022] Before intercepting the data frame, the server first verifies the integrity of the data frame, the consistency between the device anonymization number and the terminal configuration table, whether the original timestamp is empty or reversed, whether the monitored value exceeds the sensor range, and whether the gateway has a disconnection and reconnection record. If the data frame is missing necessary fields, the terminal is not registered in the configuration table, or the monitored value is in a sensor fault state, the data frame will only be written to the original abnormal record and will not be used as a normal trigger window or normal event point input.

[0023] Understandably, this step sets up two trigger sources. The first trigger source is the waveform abrupt change recorded by the lightning current waveform recorder. When the recorder detects that the waveform changes from a stable state to a rapidly rising state, the original timestamp corresponding to the waveform abrupt change point is used as the trigger time. The second trigger source is the change in the action status of the SPD intelligent monitoring terminal. When the SPD action status changes from inactive to active, the original timestamp corresponding to the status change is used as the trigger time. If both trigger sources occur within a short interval, the earlier trigger time is used as the starting point reference for the candidate event window of this lightning strike, so that the lightning current waveform, SPD action, leakage current change, temperature change, and grounding resistance change of the same lightning strike can be included in the same processing range. If multiple waveform abrupt changes or multiple SPD action changes occur consecutively in the same location within the window overlap range, the server first determines whether they belong to the same continuous lightning strike process based on the trigger time interval and the topology range of the involved equipment. If they belong to the same process, they are merged into the same candidate event window and multiple trigger sources are retained. If they do not belong to the same process, separate window numbers are generated to avoid adjacent lightning strike events from being mixed up. The lightning strike candidate event window adopts the basic idea of ​​event-triggered interception in engineering signal processing, retaining relevant data before and after the event triggering time as the center. This application extends single-signal interception to multi-terminal synchronous interception, that is, extracting SPD operating status, leakage current, temperature, grounding resistance, and lightning current waveform data around the same triggering time, enabling subsequent steps to perform multi-terminal timing correction within the same candidate event range. The window is expressed as: ; in, This window displays candidate lightning strike events. The original time stamp of the terminal corresponding to the triggering event is derived from the waveform change record of the lightning current waveform recorder or the action status change record of the SPD intelligent monitoring terminal. This indicates the range to be captured before the lightning strike, which is the first preset range used to preserve the device state before the lightning strike. This represents the intercepted range after triggering, which is the second preset range used to retain the changes in leakage current, temperature, and grounding resistance after the SPD operates. Both ends of the formula are time interval boundaries. , and All are processed using the same time base, and the endpoints of the intervals are obtained by adding or subtracting time values. If Missing or If the value is not configured, is zero, or is less than the minimum truncation range set by the server, the server will not generate a normal lightning strike candidate event window, but will output a record of invalid trigger data or invalid window configuration; if the window length exceeds the maximum event duration range set by the server, it will be truncated to the maximum range and the truncation mark will be saved.

[0024] in, and The system configuration is pre-configured based on the upload cycle of the field terminals or determined according to the terminal configuration table. In actual implementation, in scenarios where the upload cycle of the grounding resistance monitor is relatively long, the system configuration is larger. This allows changes in grounding resistance to be captured within the same window. In scenarios with high recording density of lightning current waveform recorders and the risk of continuous disturbances at the site, a more compact window range in the system configuration ensures clear boundaries between adjacent events. Taking a power distribution room as an example, if the lightning current waveform recorder records a waveform abrupt change at the original time marker 1000, and the system is configured with a 50-second truncation range before triggering and a 200-second truncation range after triggering, then the resulting candidate lightning strike event window is: The monitoring server then retrieves the SPD operation status, leakage current, temperature, grounding resistance, and lightning current waveform data that fall within the specified time interval from the cache database, and categorizes them according to the device anonymization number and monitoring quantity type. For lightning current waveform data, waveform segments before and after the abrupt change, as well as the original time stamp of the waveform abrupt change point, are retained; for SPD operation status, the status value before and after the status change, as well as the operation time stamp, are retained; for leakage current and temperature, continuous records corresponding to the SPD device within the window are retained; for grounding resistance, resistance records uploaded by the grounding resistance monitor within the window are retained. If a certain monitoring quantity has no valid record within the window, the server does not delete the candidate event window, but instead writes a missing monitoring quantity marker and a missing terminal number into the window data object, enabling subsequent steps to determine whether the terminal did not upload, the gateway link was interrupted, or this type of response did not occur.

[0025] Finally, this step outputs the lightning strike candidate event window. The data within this window is limited to a single set of data related to a suspected lightning strike or surge disturbance, and includes the original timestamps, terminal types, and monitoring values ​​required for generating a unified event timeline in subsequent step two. Through this window, continuous full-volume monitoring data is organized into event data objects with clearly defined boundaries, data types, and device sources, providing input for subsequent multi-terminal asynchronous timing correction. The server also outputs the window number, trigger source, valid trigger data markers, a list of participating terminals, and a list of missing monitoring values.

[0026] S2. Based on the lightning strike candidate event window, a candidate compensation set corresponding to the terminal to which the current event point belongs is formed by using gateway polling records, wireless retransmission records, waveform buffer upload records and terminal configuration upload cycles, so as to generate the selected link compensation time of the current event point and the corrected event time of the current event point. Compensation value selection and time conversion are performed on lightning current sudden change event points, SPD action event points, leakage current change event points, temperature change event points and grounding resistance change event points to generate a unified event time axis.

[0027] Specifically, the lightning strike candidate event window As input, The collected lightning current waveform data, SPD operation status data, leakage current data, temperature data, grounding resistance data, and the corresponding original timestamps of each data point are converted into a unified event timeline. Step one has already limited the continuous operating data to the event range corresponding to a single suspected lightning strike or surge disturbance. This step uses this range, reading each data record within the window and extracting records that can characterize a sudden change in state as event points. For lightning current waveform data, the monitoring server reads the waveform segments before and after the sudden change latched by the waveform recorder, and uses the original timestamp corresponding to the position where the waveform rises the fastest as the lightning current sudden change event point. For SPD operation status data, records where the state changes from inactive to active are read, and the original timestamp corresponding to that record is used as the SPD operation event point. For leakage current, temperature, and grounding resistance data, the position with the most significant change among adjacent records within the window is read, and the original timestamp corresponding to that position is used as the corresponding state change event point. All of the above event points are from... And retain the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, and original timestamp to ensure that the processing object in this step remains continuous with the output of step one. If a certain monitoring quantity is in If there is only a single sampling point or the number of sampling points is less than the minimum number of event points to be extracted set by the server, the server will not extract the state change event point of the monitored quantity, but will retain the insufficient sampling mark of the monitored quantity; if neither the lightning current sudden change event point nor the SPD action event point exists, the window will not enter the normal unified event timeline generation process.

[0028] Understandably, the formula for this step is based on the timestamp offset correction relationship in engineering measurement, where the observation time is formed by the actual event time and the link offset, and the link offset needs to be subtracted when calculating the event time in reverse. This type of offset correction is a routine mathematical process in industrial data acquisition, bus polling, and remote measurement systems. This application makes scenario-based improvements on this basis: the link offset is not directly taken as a single fixed value, but is selected from the candidate compensation set of the corresponding terminal; when selecting, the proximity of the compensation value to the triggering event time and whether the compensation value makes the lightning strike event conform to the engineering sequence of the on-site lightning protection process are considered simultaneously. For SPD intelligent monitoring terminals accessed via RS485, the candidate compensation set comes from the polling wait records stored by the gateway during that time period; for terminals accessed via wireless, the candidate compensation set comes from the retransmission wait records stored by the gateway; for lightning current waveform recorders, the candidate compensation set comes from the device log between waveform buffer write records and upload records; for grounding resistance monitors, the candidate compensation set comes from the period offset formed between its configured upload period and the gateway's received records. The server is designed for... For each event point, a compensation value is selected from the candidate compensation set of the corresponding terminal, and the selection relationship is as follows: ; in, Indicates the link compensation time selected for the current event point; This represents a candidate value in the candidate compensation set; This represents the candidate compensation set corresponding to the terminal to which the current event point belongs, which is derived from gateway polling records, wireless retransmission records, waveform cache upload records, or terminal configuration upload cycles. This indicates that the current event point is in the lightning strike candidate event window. The original timestamp of the terminal is stored in the database; This represents the original time stamp of the terminal corresponding to the triggering event determined in step one; This indicates the current terminal's collection or upload cycle recorded in the gateway configuration table, used to convert the time proximity into a proportional value. The weights representing the constraints of the sequence of scenes are preset by the monitoring server in the lightning protection monitoring configuration; This indicates the deviation in the scene sequence corresponding to the current candidate compensation value. This deviation is determined by the server based on the candidate correction time. With Lightning Strike Candidate Event Window The relative order of other event points is determined. In specific handling, when lightning current surge events, SPD activation events, and grounding resistance change events occur simultaneously... In the process, the server prioritizes candidate compensation values ​​that ensure the lightning current surge occurs before or within the adjacent permissible range of the SPD operation and that the grounding resistance change occurs after the discharge process; when the lightning strike candidate event window... When a window is formed by an SPD action, the server prioritizes candidate compensation values ​​that ensure the leakage current and temperature changes fall within the subsequent state change range of the SPD action. The first term in the formula is the time proximity term, calculated by dividing the time difference by the terminal's acquisition or upload cycle; the second term is the scene sequence term. Set according to the proportional value. Since the weights are proportional, the two items within the parentheses can be added together and used jointly for candidate compensation value selection. If Empty If the event point is not configured or is less than the minimum valid period, the server will not perform the normal selection of the formula, but will mark the current event point as compensation unavailable; this event point can be retained in the original record of the unified event timeline, but will not be used as a strong connection node in step three. If multiple candidate compensation values ​​reach the same minimum value, the server will prioritize the candidate value from the most recent log record from the same gateway and save the candidate compensation source number.

[0029] In some embodiments, the above selection relationship can be understood as being derived from ordinary timestamp compensation. If only link offset correction is considered, then each candidate compensation value will yield a candidate correction time. In order to select the data arrangement that best matches this lightning strike event from among multiple candidate compensation values, this application compares the candidate correction time with the triggering time determined in step one. Proximity comparisons were performed, and the chronological order of lightning protection events was introduced to account for any discrepancies. In this way, the server selects... It originates from on-site communication records and matches the engineering process of the lightning strike incident. (Completed) After selection, the original timestamp of the current event point is converted into the corrected event time according to the timestamp offset correction relationship: ; in, Indicates the corrected event time for the current event point; Indicates the current event point at The original timestamp of the terminal is stored in the database; This represents the link compensation time selected from the corresponding terminal candidate compensation set by the previous equation. The logical relationship between this equation and the previous one is as follows: the previous equation determines the compensation value to be used for the current event point from the candidate compensation set, and the second equation substitutes this compensation value into the timestamp offset correction relationship to obtain the position of the event point under a unified time reference. If the calculated... Beyond the Lightning Strike Candidate Event Window If the allowed expansion range is exceeded, or if the corrected event time contradicts the order of adjacent event points on the same terminal, the server will mark the event point as a correction anomaly and will not consider it as a priority connection object in the lightning strike event chain in step three.

[0030] Understandably, taking a lightning strike candidate event window at a certain power distribution room as an example, the lightning strike candidate event window... This includes lightning current surge events, SPD activation events, and grounding resistance change events. The original timestamp for the lightning current surge event is 1000, the original timestamp for the SPD activation event is 1012, and the original timestamp for the grounding resistance change event is 1040. The gateway operation log shows that the candidate compensation set formed by the RS485 link where the SPD terminal is located during this period is... The candidate compensation set corresponding to the grounding resistance monitor is When calculating SPD action events, the candidate correction time corresponding to candidate value 6 is 1006, the candidate correction time corresponding to candidate value 8 is 1004, and the candidate correction time corresponding to candidate value 10 is 1002; the server combines... Based on the locations of leakage current changes and lightning current abrupt changes, the event sequence corresponding to candidate value 8 better matches the field process of SPD activation after the lightning current abrupt change; therefore, it was selected. And obtain the SPD action event. When calculating the ground resistance change event, the candidate correction time corresponding to candidate value 20 is 1020, the candidate correction time corresponding to candidate value 25 is 1015, and the candidate correction time corresponding to candidate value 30 is 1010. The server, considering that the SPD action event has already been corrected to 1004 and the position where the ground resistance change should occur during the discharge response process, selects... And obtain the grounding resistance change event. After the above processing, the original timestamps 1000, 1012, and 1040 are converted to 1000, 1004, and 1015. The events within the window are arranged as lightning current surge, SPD activation, and grounding resistance change, forming a unified sequence that conforms to the on-site lightning strike entry, SPD discharge, and grounding response process.

[0031] The server sequentially processes the lightning strike candidate event windows. The server performs compensation value selection and time conversion for lightning current abrupt change events, SPD action events, leakage current change events, temperature change events, and grounding resistance change events. For lightning current abrupt change events, the server uses a candidate compensation set formed by the waveform recorder's own cached write records and uploaded records. For SPD action events, the server uses a candidate compensation set formed by the gateway polling records and SPD status change records. For leakage current and temperature change events, the server associates the event with an SPD action event under the same device's desensitized ID based on the SPD device it belongs to before selecting the compensation value. For grounding resistance change events, the server uses a candidate compensation set formed by the upload cycle of the grounding resistance monitor and the grounding change location within the window. After each event point is calibrated, the server uses the calibrated event time for that event point. Arranged from morning to night, each record retains the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp, corrected event time, compensation source, and correction validity mark.

[0032] This step ultimately outputs a unified event timeline. The unified event timeline is generated from the lightning strike candidate event window. The unified event timeline, formed after compensation value selection and time conversion, includes a unified sorting result of lightning current surge events, SPD activation events, leakage current change events, temperature change events, and grounding resistance change events. This unified event timeline serves as the input for generating the lightning event chain in step three, enabling subsequent organization of lightning triggering, SPD discharge, grounding response, and equipment status change processes based on the corrected event sequence. For event points where compensation is unavailable or correction is abnormal, the unified event timeline retains their original records and abnormal markers, but step three lowers their connection priority or excludes them when establishing propagation connections, thereby preventing abnormal timestamps from disrupting the lightning event chain sequence.

[0033] S3. Based on the unified event timeline, the pre-entered SPD hierarchical relationship, grounding connection relationship, and equipment installation location relationship are called. The event point is used as a chain node. The link association value between the event points is determined by time proximity, equipment topology, and state propagation direction to generate a lightning strike event chain with propagation direction. The lightning strike event chain retains the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp, and corrected event time of each chain node, and records the connection relationship between the chain nodes according to the propagation direction.

[0034] Specifically, using a unified event timeline as input, lightning current surge events, SPD activation events, leakage current change events, temperature change events, and grounding resistance change events that have undergone time correction are organized into lightning strike event chains. Each event record in the unified event timeline includes the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp, and corrected event time. All of this information is reused in this step: the device anonymization number is used to identify the device to which the event belongs; the terminal type and monitoring quantity type are used to identify the event category; the monitoring quantity value is used to determine the direction of the state change; the original timestamp is retained as event tracing information; and the corrected event time... This step is used to determine the chronological order of events. During this process, the server also retrieves the SPD hierarchy, grounding connection relationships, and equipment installation location relationships recorded during the system deployment phase. Examples include the hierarchical relationship between primary and secondary SPDs, the discharge relationship between SPDs and grounding busbars, and the line relationship between the lightning current waveform recorder and the down conductor. Thus, discrete event points in the unified event timeline are placed within specific lightning protection structures for connection determination, ensuring the event chain has both chronological order and equipment propagation path. If the chain start point in the unified event timeline is missing, or if the on-site SPD hierarchy, grounding connection relationships, and equipment installation location relationships are not configured, the server will not generate a normal lightning strike event chain but will instead output a record indicating a missing topology configuration or a missing chain start point.

[0035] In some embodiments, the calculation of event connectivity is derived from the concept of node edge weights in graph theory, treating each event point in the unified event timeline as a node and converting the establishment of a connection between two event points into a judgment of edge weight. Conventional edge weight calculation is usually determined by node distance or adjacency. This application improves upon this by combining it with the online lightning protection monitoring scenario, merging three factors—time proximity, device topology, and state propagation—into a link association value. The server selects the chain starting point from the unified event timeline, prioritizing lightning current mutation events; when a lightning strike candidate event window is formed by an SPD action, the chain starting point is the corresponding SPD action event. After the chain starting point is determined, the server calculates the chain based on the corrected event timeline. Scan backwards for subsequent events, focusing on the current tail event. Following events with candidates Calculate link association value: ; in, Representing the event point Event Point Link association values ​​between; Representing the event point The corrected event time obtained in step two; the corrected event time obtained in step two; Representing the event point The collection period or upload period recorded in the gateway configuration table of the terminal to which the current candidate subsequent event belongs in step two is used to convert the event time interval into a proportional relationship. The device association items are derived from the SPD hierarchy, grounding connection, and device installation location relationships saved during system deployment. The state propagation direction item is derived from the server's judgment on the order of event types and the direction of changes in monitored quantities; , and This represents the pre-set proportional weight of the server in the lightning protection monitoring configuration. The first term in the formula is the time proximity term. Derived from time proximity calculation, using The first term is a proportional value, meaning that the smaller the event time interval, the higher the contribution of temporal proximity; the second term comes from the adjacency relation expression in graph theory edge weights, which this application concretizes as the topological association between lightning protection devices; the third term comes from the directional consistency expression in directed edge relations, which this application concretizes as the engineering propagation order between lightning current abrupt changes, SPD operation, leakage current changes, temperature changes, and grounding resistance changes. and Also set according to the proportional value, , and Since the weights are proportional, the sum of the three items still forms a proportional correlation value used for sorting and threshold determination. If Invalid or candidate subsequent events are marked as invalid, and the server does not use the candidate event to calculate the normal link association value; if , or If not configured, the server uses the factory default weights and saves the weight version number in the event log.

[0036] In practice, The event point is obtained by the server querying the field device association table based on the device's anonymized ID. Belongs to Level 1 SPD, Event Point When two SPDs belong to the same distribution cabinet as a secondary SPD, there is a hierarchical SPD relationship between them. Take the higher value; take the higher value for the event point; event point Belongs to SPD action events and event points When the grounding resistance change events belong to the same grounding busbar, the two events are related in terms of grounding discharge. Equipment and event points When the equipment is located at an adjacent grounding node, Take the median value; when the two are located on different feeders and are not directly related in the field configuration table. Take the lower value. The server determines this based on the event type and the direction of change in the monitored quantity. When a lightning current surge event is followed by an SPD action event, and the SPD's action status changes from inactive to active, Take the higher value; when a leakage current change event occurs after an SPD activation event, and the leakage current corresponding to the same SPD shows an increase or abnormal fluctuation, Take the higher value; when a temperature change event is connected after an SPD action event, and the temperature record of the same SPD shows a subsequent upward trend, Take the higher value; when an SPD action event or leakage current change event is followed by a ground resistance change event, and the ground resistance change originates from the same ground busbar or adjacent grounding nodes, Take the higher value. Through this processing, the connectivity between events is determined by the corrected event time, the actual device connectivity, and the direction of change in lightning protection status. The server will... and The value range is limited to 0 to 1; when the device association table cannot find the relationship between two event points... Take the lowest correlation value and record the topology unknown marker.

[0037] Understandably, taking a substation as an example, the unified event timeline output in step two sequentially includes lightning current surge events, primary SPD action events, secondary SPD action events, leakage current change events, temperature change events, and grounding resistance change events. After reading the site configuration, the server confirms that the lightning current waveform recorder is installed near the incoming lead of the substation, the primary SPD is installed on the incoming side, the secondary SPD is installed on the branch circuit, the leakage current and temperature records are from the secondary SPD intelligent monitoring terminal, and the grounding resistance record is from the grounding resistance monitor corresponding to the grounding busbar of the substation. For the lightning current surge event and the primary SPD action event, the corrected event times are 1000 and 1003 respectively. The upload cycle of the terminal to which the candidate subsequent event belongs is configured to be 10. The server configuration... , , Equipment association items State propagation direction term, state propagation direction term The link association value is then calculated. For the same lightning current surge event and a temperature change event on another unrelated feeder, assuming the corrected event times are 1000 and 1005 respectively, and the upload cycle of the terminal to which the candidate subsequent event belongs is configured to be 10, the device association item... The server prioritizes events with higher link correlation values ​​that follow the current chain tail event as propagation connection objects, thus connecting events that follow the same lightning strike propagation path. In the example above, the two calculation results correspond to the same distribution cabinet lightning protection path and an unrelated feeder event, respectively, demonstrating that the link correlation value is affected by both time proximity and equipment topology.

[0038] Furthermore, the server executes event connections starting from the beginning of the chain according to a unified event timeline. When the current tail event is a lightning current mutation event, the server prioritizes searching for subsequent SPD action events and calculates the time interval between them. When the current chain tail event is an SPD action event, the server continues to search for leakage current change events, temperature change events, and ground resistance change events corresponding to the same SPD or its subordinate SPDs; when the current chain tail event is a leakage current change event or a temperature change event, the server continues to search for ground resistance change events within the same grounding association range. For each candidate subsequent event, the server calculates the corresponding... The server selects events with higher link correlation values ​​and whose corrected event times are after the current chain tail event as the next node. If multiple candidate events meet the connection conditions, the server prioritizes events with closer device relationships, such as the same SPD device over the same distribution cabinet device, the same grounding busbar over adjacent grounding busbars, and upper / lower level SPDs over non-same level feeder devices. The server continues to expand the chain according to the above rules until the link correlation value between the subsequent event and the current chain tail event is lower than the connection threshold set by the system, or there are no candidate events in the unified event timeline that are after the current chain tail event and belong to the same lightning protection structure. The connection threshold is preset by the server based on historical lightning strike event review records or on-site debugging records; if a candidate event is not connected to the main chain, the server retains it as a side event record to avoid accidentally deleting data that may be related to the same window but has insufficient connection strength.

[0039] After the propagation connection is established, the server generates a lightning strike event chain according to the connection direction: ; in, Indicates the current lightning strike event chain; This indicates the chain start event, which originates from lightning current mutation events or SPD action events in the unified event timeline. to This indicates subsequent events connected sequentially according to the propagation connection relationship, originating from SPD action events, leakage current change events, temperature change events, and grounding resistance change events in the unified event timeline; the arrows indicate the event propagation direction, which is determined by the corrected event time. Equipment association items and state propagation direction term The expression is jointly determined. This expression originates from the concept of directed graph path representation, and this application uses it to represent the propagation process of a lightning strike or surge disturbance in a lightning protection system. The first equation is used to calculate whether adjacent events should be connected, and the second equation is used to organize the events determined by connection into directed event paths according to the propagation direction. If only a chain starting point exists without subsequent events satisfying the connection threshold, the server generates a single-node event chain and marks it as insufficient propagation paths. If multiple paths satisfy the threshold and belong to different lightning protection structures, the server generates different event chain numbers for each and saves the multi-chain relationship in the window record.

[0040] This step outputs the lightning strike event chain. . The system retains the device de-identification number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp, and corrected event time for each chain node, and records the connection relationships between nodes according to the propagation direction. This output directly serves as the input for step four, which executes event-based online monitoring and handling. The monitoring server can subsequently determine the main abnormal nodes based on the chain starting point, the affected nodes based on subsequent nodes within the chain, the propagation path based on the device connection order in the chain, and the alarm level and handling priority based on the type and quantity of events within the chain. Through this step, the unified event timeline obtained in step two is converted into an event chain that can express the lightning strike process, allowing the multi-terminal data fusion results to enter an engineering form that can be used for online monitoring and handling. The server also saves the data for each connection edge. The connection threshold, weight version number, topology version number, and list of side events make the formation process of the lightning strike event chain traceable.

[0041] S4. Based on the lightning strike event chain, perform event-based handling analysis on the chain nodes, identify the main abnormal nodes, affected nodes, propagation paths, alarm levels and handling priorities, and execute event-based online monitoring and handling.

[0042] Specifically, taking step three, the lightning strike event chain, as an example. As input, online monitoring and handling of lightning strike events that have completed propagation connections are performed. Lightning strike event chain. The data retains the device de-identification number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp, and corrected event time for each chain node. All of this information will continue to be used in this step: the device anonymization number is used to identify the main abnormal nodes and affected nodes; the terminal type and monitoring quantity type are used to determine the event category; the monitoring quantity value is used to calculate the degree of impact on the node; the original timestamp is used for event tracing; and the corrected event time... Used to determine the propagation position of a chain node relative to the chain start point. The server reads... Then, analyze sequentially according to the direction of the arrows in the chain. to ,in The initial event in the chain typically corresponds to a sudden surge in lightning current or an SPD activation event. Subsequent nodes correspond to events such as SPD activation, leakage current changes, temperature changes, and grounding resistance changes. The server simultaneously invokes the SPD hierarchy, grounding connection relationships, and equipment installation location relationships used in step three to map the chain nodes to specific lightning protection structure locations, such as incoming-side SPDs, branch circuit SPDs, grounding busbars, or adjacent grounding nodes. If an event is marked as having an insufficient propagation path or missing topology configuration, the server will still retain the event log, but will reduce the automatic handling level and transfer the event to a manual review or on-site configuration review process.

[0043] Understandably, the decision-making process in this step employs the cumulative path risk approach. This approach originates from the cumulative path risk model in engineering systems, where the overall impact of a fault propagation path is formed by the combined effects of each node in the path. Conventional path risk calculations typically only consider the number of nodes or the sum of anomalous amplitudes at a single point. This application improves upon this by considering the online lightning protection monitoring scenario: events closer to the chain start point in lightning propagation are usually closer to the impact source, higher-level SPDs or critical grounding nodes have a greater impact on the system's protection capability, and the amplitude changes of different monitored quantities reflect the degree of anomaly at different nodes. Therefore, the server targets each node in the lightning strike event chain... Calculate the intra-chain impact value, taking into account the propagation time location, equipment level location, and the magnitude of changes in monitored quantities: ; in, Represents a chain node The in-chain impact value; Represents a chain node The hierarchical position of the equipment in the on-site lightning protection structure is derived from the SPD hierarchical relationship and grounding connection relationship saved during the system deployment phase. For example, the incoming line SPD, branch circuit SPD, and grounding busbar correspond to different hierarchical positions. Represents a chain node The proportional change amplitude of the corresponding monitored quantity comes from The difference between the monitored value of the chain node and the initial state value within the same lightning strike candidate event window is then proportionalized to the alarm threshold, rated variation range, or equipment configuration reference value corresponding to the monitored value. For example, changes in leakage current, temperature, and grounding resistance are proportionalized according to their respective configuration references. For SPD action status nodes, Determined by the status change markers and the status impact benchmark corresponding to the rated level of the SPD equipment; for nodes experiencing sudden lightning current changes, It is obtained by ratio of waveform peak value, rising edge amplitude, or lightning current alarm threshold. Represents a chain node The corrected event times obtained in step two and retained in step three; Indicates the chain start event The corrected event time; The collection period or upload period recorded in the gateway configuration table of the corresponding terminal in step two is used to convert the time distance between the chain node and the chain starting point into a proportional relationship. This represents the pre-set hierarchical enhancement weights in the server's lightning protection monitoring configuration. This formula is derived from the node weight relationships in the path accumulation model, and it proportionally changes the amplitude. As a basic item, add a hierarchical enhancement item at its beginning. This is used to highlight the importance of high-level SPDs and critical grounding nodes in lightning protection structures; a propagation time attenuation term is added after it. This is used to show that the farther a chain node is from the starting point of the chain, the lower its contribution to the determination of the root cause of the event. , , Both the ratio to time and the ratio to the time are proportional parameters, therefore It can be used for sorting and alarm level determination among different types of chain nodes within the same event chain. invalid, Earlier The chain node may lack a configuration baseline value, causing the server to fail to calculate correctly. Instead, the chain node is marked as having an incalculable impact value and the original monitoring data is retained.

[0044] In practice, the server follows the lightning strike event chain. The chain nodes are read sequentially. Taking a lightning strike event chain in a substation as an example... This includes lightning current surge events, primary SPD activation events, secondary SPD activation events, leakage current change events, temperature change events, and grounding resistance change events. After reading the field configuration, the server confirms that the primary SPD is located on the incoming line side, the secondary SPD is located on the branch circuit, leakage current and temperature records are from the secondary SPD intelligent monitoring terminal or the environmental sensor bound to its installation point, and grounding resistance records are from the grounding resistance monitor corresponding to the grounding busbar of the distribution cabinet. For a given chain node, if its hierarchical position... The value is 3. The amplitude of the monitored quantity change of this chain node is obtained after being processed by the corresponding configuration benchmark ratio. The corrected event time interval between the chain start point and the time interval is 4, corresponding to the terminal upload cycle. The server configuration is 10. Then the in-chain influence value of this chain node is calculated as follows: If another node with changing grounding resistance is located at a lower level, has a smaller proportional change amplitude, and is farther from the chain start point in time, then its influence within the chain is lower than that of the aforementioned node. The server... All chain nodes undergo the same calculations, and the main abnormal nodes and affected nodes are determined according to the intra-chain impact value and propagation order: devices near the chain start point with high intra-chain impact values ​​are identified as main abnormal nodes; devices located on subsequent propagation paths with low intra-chain impact values ​​but connected to the main abnormal nodes are identified as affected nodes; when a node with a change in grounding resistance has a high intra-chain impact value, its corresponding grounding busbar is marked as a key inspection target. In this example... The calculation uses the correction time formed in step two, the chain node sequence formed in step three, and the device hierarchy saved during the system deployment phase. The source of variables can be closed to the aforementioned steps.

[0045] The server then generates event-based online monitoring and handling results based on the propagation range and impact value of the entire lightning strike event chain. For cases where the chain originates from a sudden lightning current event and is followed by multiple SPDs operating continuously, the server identifies the event type as a main line lightning propagation event and raises the alarm level based on nodes with higher impact values ​​within the chain. For cases where the impact within the chain is concentrated on the operation, leakage current, and temperature nodes corresponding to a specific SPD device, the server marks the device's desensitized number as a major abnormal node. For cases where the impact within the chain is concentrated on nodes with changes in grounding resistance, the server marks the corresponding grounding busbar or grounding node as a key inspection target. The event propagation path is... The node connection order is directly generated, for example, "Lightning current waveform recorder corresponding down conductor—Level 1 SPD—Level 2 SPD—Grounding busbar". The handling priority is determined by the alarm level, the location of the main abnormal node, and the impact value within the chain. The handling priority corresponding to the incoming SPD or main grounding busbar is higher than that of the terminal branch equipment. The alarm level threshold and handling priority rules are preset in the monitoring server parameter area and are associated with the on-site lightning protection level, SPD rated parameters, and grounding system configuration version. When the impact value within the chain is lower than the minimum alarm threshold but a valid lightning current mutation event exists, the server generates a low-level event record without triggering a high-level linkage.

[0046] After completing the above judgment, the monitoring server executes online monitoring and handling actions. The server stores the lightning strike event chain number, chain node information, major abnormal nodes, affected nodes, propagation path, alarm level, and handling priority in the event database; and generates [data / information] in the monitoring interface. The corresponding event propagation path is displayed; audible and visual alarm devices are triggered according to the alarm level; historical event query records are generated, enabling maintenance personnel to query the current lightning strike propagation process by event number; and event summaries are pushed to third-party platforms via API. The event summary is limited to the event number, device anonymized number, alarm level, event time, and event type, ensuring that the third-party platform receives event-level monitoring results. For continuous lightning strike scenarios, the server performs the above actions according to different lightning strike event chain numbers; when multiple lightning strike event chains occur near the same grounding busbar, the server performs actions according to their respective... The server generates handling records for the chain start point, the corrected event time, and the propagation path. The server also stores uncomputable nodes, compensation unavailable event points, side events, and topology unknown markers, enabling operations and maintenance personnel to distinguish between "no response" and "insufficient data to make a determination".

[0047] This step ultimately outputs the event-based online monitoring and handling results. These results include the lightning strike event chain number, major abnormal nodes, affected nodes, propagation path, alarm level, impact value within the chain, and handling records. These records are stored, queried, used for audio-visual linkage, and API sharing as official event logs on the monitoring server. Through this step, the lightning strike event chain formed in step three... The data is transformed into actionable online monitoring and response results, enabling the entire solution to complete a continuous processing flow from multi-terminal data acquisition, unified time correction, lightning strike event chain generation to event-based online monitoring and response. This result directly corresponds to the operational status of on-site lightning protection monitoring equipment and communication links, indicating which SPDs, grounding busbars, lightning current waveform recorders, data acquisition gateways, or communication links require verification, thus forming a closed-loop technical response system for online lightning protection monitoring.

[0048] This invention also provides an intelligent online lightning protection monitoring system based on multi-terminal data fusion, the system comprising: The event window generation module is used to construct a lightning strike candidate event window in the monitoring server based on lightning current waveform abrupt change or SPD action status change as the trigger source, and to obtain SPD action status, leakage current, temperature, grounding resistance and lightning current waveform data in the lightning strike candidate event window. The timing correction module is used to form a candidate compensation set corresponding to the terminal to which the current event point belongs based on the lightning strike candidate event window, using gateway polling records, wireless retransmission records, waveform buffer upload records and terminal configuration upload cycle, so as to generate the selected link compensation time of the current event point and the corrected event time of the current event point. It performs compensation value selection and time conversion for lightning current change event points, SPD action event points, leakage current change event points, temperature change event points and grounding resistance change event points to generate a unified event time axis. The event chain generation module is used to generate a lightning strike event chain with a propagation direction by calling the pre-entered SPD hierarchical relationship, grounding connection relationship and equipment installation location relationship based on the unified event timeline, with event points as chain nodes, and determining the link association value between event points through time proximity, equipment topology and state propagation direction; wherein, the lightning strike event chain retains the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp and corrected event time of each chain node, and records the connection relationship between chain nodes according to the propagation direction; The online handling module is used to perform event-based handling analysis on the chain nodes according to the lightning strike event chain, identify the main abnormal nodes, affected nodes, propagation paths, alarm levels and handling priorities, and perform event-based online monitoring and handling.

[0049] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0050] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection of apparatuses or units may be electrical, mechanical, or other forms.

[0051] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0052] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.

Claims

1. A smart online lightning protection monitoring method based on multi-terminal data fusion, characterized in that, The method includes the following steps: Using sudden changes in lightning current waveform or changes in SPD operating status as trigger sources, a lightning strike candidate event window is constructed in the monitoring server, and the SPD operating status, leakage current, temperature, grounding resistance and lightning current waveform data in the lightning strike candidate event window are obtained. Based on the lightning strike candidate event window, a candidate compensation set corresponding to the terminal to which the current event point belongs is formed by using gateway polling records, wireless retransmission records, waveform buffer upload records and terminal configuration upload cycle, so as to generate the selected link compensation time of the current event point and the corrected event time of the current event point. Compensation value selection and time conversion are performed on lightning current sudden change event points, SPD action event points, leakage current change event points, temperature change event points and grounding resistance change event points to generate a unified event time axis. Based on the unified event timeline, the pre-entered SPD hierarchical relationship, grounding connection relationship, and equipment installation location relationship are invoked. Event points serve as chain nodes, and the link association value between event points is determined by time proximity, equipment topology, and state propagation direction to generate a lightning strike event chain with propagation direction. The lightning strike event chain retains the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp, and corrected event time for each chain node, and records the connection relationship between chain nodes according to the propagation direction. Based on the lightning strike event chain, the chain nodes are analyzed for event-based handling to identify major abnormal nodes, affected nodes, propagation paths, alarm levels, and handling priorities, and event-based online monitoring and handling are executed.

2. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 1, characterized in that, The process of constructing a lightning strike candidate event window in the monitoring server specifically involves: Centered on the triggering time of the triggering source, a first preset range is extracted forward and a second preset range is extracted backward. The lightning current waveform, SPD operation status, leakage current, temperature and grounding resistance data falling within the time interval are grouped into the same event window. When multiple triggering sources appear within the overlapping range of the window, they are merged into the same window and multiple triggering sources are retained.

3. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 2, characterized in that, The first preset range is used to retain the equipment state before the lightning strike; the second preset range is used to retain the changes in leakage current, temperature and grounding resistance after the SPD is activated.

4. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 1, characterized in that, The candidate compensation set includes: For SPD intelligent monitoring terminals accessed via RS485, the candidate compensation set comes from the polling wait records saved by the gateway during that time period; for terminals accessed via wireless means, the candidate compensation set comes from the retransmission wait records saved by the gateway; for lightning current waveform recorders, the candidate compensation set comes from the device logs between waveform buffer write records and upload records; for grounding resistance monitors, the candidate compensation set comes from the period offset formed between their configured upload period and the gateway's received records.

5. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 1, characterized in that, The link compensation time is generated based on the terminal's original timestamp at the current event point, a candidate value in the candidate compensation set, the terminal's original timestamp corresponding to the triggering event, the collection cycle or upload cycle recorded by the current terminal in the gateway configuration table, and the scenario sequence deviation corresponding to the current candidate compensation value. It is used to determine the compensation value that should be adopted for the current event point from the candidate compensation set. The corrected event time for the current event point is generated based on the terminal's original time stamp for the current event point and the link compensation time.

6. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 5, characterized in that, The unified event timeline is generated by arranging each event point from early to late based on the corrected event time to form a unified event timeline.

7. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 1, characterized in that, The link association value is calculated as follows: it is generated by multiplying the time proximity item, the device association item, and the state propagation direction item by their respective weights and then summing them. Among them, the time proximity item is determined by the acquisition cycle or upload cycle of the terminal to which the candidate subsequent event belongs and the event time interval. The device association item comes from the SPD hierarchy relationship, grounding connection relationship, and device installation location relationship. The state propagation direction item comes from the server's judgment on the order of event types and the direction of change of monitoring quantity. The corresponding weight is the proportional weight preset by the server in the lightning protection monitoring configuration.

8. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 1, characterized in that, The generation of the lightning strike event chain with a propagation direction specifically includes: Using a lightning current mutation event or an SPD activation event as the starting point of the chain, subsequent events whose link association values ​​reach the threshold are sequentially connected to the end of the chain according to the corrected event time sequence, forming a directed propagation path from lightning strike triggering or SPD discharge to grounding response. If multiple candidate events meet the connection conditions, the server will prioritize the event with the closer device association. The lightning strike event chain is continuously expanded until the link correlation value between the subsequent event and the current chain tail event is lower than the connection threshold set by the system, or there are no candidate events in the unified event timeline that are after the current chain tail event and belong to the same lightning protection structure.

9. The intelligent online lightning protection monitoring method based on multi-terminal data fusion according to claim 1, characterized in that, The event-based handling analysis of chain nodes involves calculating the intra-chain impact value of each chain node, specifically including: It is generated by combining the proportional change amplitude, hierarchical enhancement term, and propagation time attenuation term corresponding to the node; wherein, the hierarchical enhancement term is determined according to the hierarchical position of the equipment to which the chain node belongs in the on-site lightning protection structure, and the propagation time attenuation term is determined according to the ratio of the time distance of the current chain node relative to the chain start point to the terminal acquisition cycle or upload cycle; The event-based online monitoring and handling includes: saving the lightning strike event chain number, chain node information, major abnormal nodes, affected nodes, propagation path, alarm level, and handling priority; displaying the event propagation path on the monitoring interface; triggering audible and visual alarms; generating historical event query records; and pushing event summaries to third-party platforms via API.

10. An intelligent online lightning protection monitoring system based on multi-terminal data fusion, characterized in that, The system includes: The event window generation module is used to construct a lightning strike candidate event window in the monitoring server based on lightning current waveform abrupt change or SPD action status change as the trigger source, and to obtain SPD action status, leakage current, temperature, grounding resistance and lightning current waveform data in the lightning strike candidate event window. The timing correction module is used to form a candidate compensation set corresponding to the terminal to which the current event point belongs based on the lightning strike candidate event window, using gateway polling records, wireless retransmission records, waveform buffer upload records and terminal configuration upload cycle, so as to generate the selected link compensation time of the current event point and the corrected event time of the current event point. It performs compensation value selection and time conversion for lightning current change event points, SPD action event points, leakage current change event points, temperature change event points and grounding resistance change event points to generate a unified event time axis. The event chain generation module is used to generate a lightning strike event chain with a propagation direction by calling the pre-entered SPD hierarchical relationship, grounding connection relationship and equipment installation location relationship based on the unified event timeline, with event points as chain nodes, and determining the link association value between event points through time proximity, equipment topology and state propagation direction; wherein, the lightning strike event chain retains the device desensitization number, terminal type, monitoring quantity type, monitoring quantity value, original timestamp and corrected event time of each chain node, and records the connection relationship between chain nodes according to the propagation direction; The online handling module is used to perform event-based handling analysis on the chain nodes according to the lightning strike event chain, identify the main abnormal nodes, affected nodes, propagation paths, alarm levels and handling priorities, and perform event-based online monitoring and handling.