Novel steam turbine emergency trip control device
By adopting a DCS system and a 3-out-of-2 logic judgment in the emergency trip control device of the steam turbine, the problems of signal redundancy and power supply independence are solved, reliable protection is achieved in emergency situations, false alarms and failure to operate are avoided, and the safety and reliability of the system are improved.
Patent Information
- Application Number
- CN202520218781.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-12
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2035-02-12
AI Technical Summary
The existing emergency trip control device for steam turbines has problems such as the lack of redundancy in protection signals, the sharing of signal output relays and power supplies, which leads to malfunctions or failures to operate the protection system, making it unable to effectively trip the turbine in emergency situations and posing a safety hazard.
The DCS system replaces the PLC-controlled ETS system. The NLP terminal board and the ETS 3-to-2 dedicated terminal board achieve three-way redundant configuration and distributed isolation of signals. Combined with independent power supply, independent signal transmission and logical judgment are ensured. The 3-to-2 logic judgment is adopted to improve reliability.
The reliability and safety of the turbine emergency trip control device have been improved, ensuring that the turbine can trip correctly in an emergency, avoiding malfunctions and failures to trip, and meeting safety requirements.
Smart Images

Figure CN223647885U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of steam turbine technology, specifically a novel emergency shutdown control device for steam turbines. Background Technology
[0002] The Emergency Trip Control System (ETS) for steam turbines is a crucial system for ensuring the safe operation of steam turbines. Its main function is to quickly shut off the steam inlet valves of the steam turbine automatically or manually in emergency situations to prevent equipment damage and the escalation of accidents. An ETS system typically includes multiple subsystems and components, such as AST solenoid valves, OPC solenoid valves, and overspeed protection devices, which work together to ensure the safe operation of the steam turbine.
[0003] Some power plants' 300MW units use PLC controllers for their ETS systems. Field protection signals are switch signals, hardwired into the cabinet, connected to the control unit's I / O module, and then into the PLC controller. The controller scans and analyzes the signals. When the trip signal is determined to be "true," a trip switch signal is output to the I / O module, driving the trip relay and cutting off the power to the field AST solenoid valve, thus achieving the shutdown protection function. Thermal control engineers can connect to the PLC controller via a dedicated computer to edit, modify, install, remove, and debug its logic program. However, this emergency trip control device has several issues: some protection signals lack redundancy, trip signals share output relays, and the AST solenoid valve shares a single power supply. These issues do not comply with the "Twenty-Five Key Requirements for Preventing Power Production Accidents," which stipulates that "protection signals should adhere to the principle of relative independence from the sampling point to the input module." This can easily lead to malfunctions and poses significant safety hazards.
[0004] The factory's emergency trip control device uses only two signals for some protection signals, each connected to an input relay before entering the PLC controller's I / O module. This fails to meet the required 2-out-of-3 design. While some protection signals use three signals for 2-out-of-3 logic, they are all connected to the same I / O module in the PLC controller. In the first scenario, if one signal fails (e.g., a short circuit, grounding, or malfunction of the signal cable, or a fault in the field detection device), preventing proper signal transmission, the system cannot correctly determine the signal's location when it is triggered, even if the other signal transmits normally. This can easily lead to protection failure, preventing the unit from tripping correctly in an emergency. In the second scenario, if two or three signals are connected to the same I / O module, even if all three signals transmit normally, a fault in the I / O module can cause the two or three signals connected to it to fail or erroneously operate, resulting in system failure or erroneous operation. The unit will fail to trip or trip incorrectly, meaning it will stop when it should or stop when it shouldn't. Utility Model Content
[0005] (a) Technical problems to be solved
[0006] To address the shortcomings of existing technologies, this utility model provides a novel emergency shutdown control device for steam turbines, which solves the aforementioned problems.
[0007] (II) Technical Solution
[0008] To achieve the above objectives, this utility model provides the following technical solution: a novel steam turbine emergency shutdown control device, comprising:
[0009] NLP terminal block A, NLP terminal block B, NLP terminal block C, ETS 3-in-2 dedicated terminal block;
[0010] When the main unit's oil tank level is low, a 3-to-2 tripping test point is set, and the signal enters the first 3 input channels of NLP terminal board A, NLP terminal board B, and NLP terminal board C.
[0011] Among them, the oil level of the main engine oil tank is low 1 and enters the first channel of NLP terminal board A (NLP1-1); the oil level of the main engine oil tank is low 2 and enters the second channel of NLP terminal board B (NLP1-2); the oil level of the main engine oil tank is low 3 and enters the third channel of NLP terminal board CNLP1-3.
[0012] The outputs of NLP terminal boards A, B, and C are connected to the ETS3-select-2 dedicated terminal board.
[0013] Preferably, the NLP terminal board A, NLP terminal board B, and NLP terminal board C are interconnected via cables.
[0014] Preferably, the cable is an ETS-specific parallel D-type 37-core cable.
[0015] Preferably, the outputs of NLP terminal boards A, B, and C are connected to relays, and the relays are connected to the ETS3-to-2 dedicated terminal board.
[0016] (III) Beneficial Effects
[0017] This utility model provides a novel emergency shutdown control device for steam turbines, which has at least the following advantages compared with the prior art:
[0018] This solution replaces the PLC-controlled ETS system with a DCS system, maximizing benefits with minimal time and investment. It aims to improve the overall control capabilities and production management level of the unit's ETS system. By optimizing input and output configurations, full redundancy is achieved for critical protection signals on the turbine side. Online monitoring of the ETS system's input / output status and logical operation is enabled on the DCS side. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the connection between the NLP terminal board A, NLP terminal board B, and NLP terminal board C of this utility model and the ETS3-select-2 dedicated terminal board;
[0020] Figure 2 This is a system logic block diagram of the present invention. Detailed Implementation
[0021] The technical solutions of the present utility model will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present utility model, and not all embodiments. Based on the embodiments of the present utility model, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of the present utility model.
[0022] Please see Figure 1-2 This utility model provides a technical solution: a novel steam turbine emergency trip control device, characterized in that it includes: NLP terminal board A, NLP terminal board B, NLP terminal board C, and ETS 3-to-2 dedicated terminal board; the main engine oil tank low oil level is a 3-to-2 trip measurement point, and the signal enters the first 3 input channels of NLP terminal board A, NLP terminal board B, and NLP terminal board C.
[0023] The main engine oil tank has three output channels: Low oil level 1 (connects to NLP terminal board A, NLP1-1, first channel); Low oil level 2 (connects to NLP terminal board B, NLP1-2, second channel); and Low oil level 3 (connects to NLP terminal board CNLP1-3, third channel). The outputs of NLP terminal boards A, B, and C are connected to the ETS 3-to-2 dedicated terminal board. NLP terminal boards A, B, and C are interconnected via a dedicated parallel D-type 37-core cable. The outputs of NLP terminal boards A, B, and C are connected to a relay, which is then connected to the ETS 3-to-2 dedicated terminal board.
[0024] The original PLC system was dismantled, and an emergency trip control device was adopted to implement the ETS system functions. This system consists of a human-machine interface station, a distributed processing unit, I / O modules, a power supply module, and a communication module. The system mainly performs the following functions: Trip condition signals from the field, such as the EH low oil pressure switch signal, are hardwired into the I / O module, i.e., the input signal acquisition card. The input card adopts a reasonable configuration mode to ensure that "protection signals should follow the principle of relative independence throughout the entire process from the sampling point to the input module." The input card converts various signals from the field into signals that can be processed by the distributed processing unit, and then sends them to the distributed processing unit for various signal processing steps. When the trip condition is met, a trip signal is output. This signal is sent to the output card, and then to the field to drive the corresponding equipment to trip, thus realizing the turbine protection function.
[0025] This power supply solution utilizes one factory-grade UPS (Uninterruptible Power Supply) and another backup power supply, meaning the system receives two 220VAC power supplies (UPS + APS) to power the system cabinet, I / O boards, etc. The 220VAC AC power from the UPS and backup power supply is converted into redundant 24VDC power through four independent 24V power modules within the cabinet. High-quality power conversion components are used to supply various cards, relays, and other components, while also powering on-site switching signals. A power failure alarm output function is also included.
[0026] The present invention provides a distributed input and output configuration scheme for the ETS system. The trip input signal of the ETS system adopts a 3-to-2 type. The new emergency trip control device adopts a distributed design for the 3-to-2 type in terms of hardware configuration, and configures dedicated ETS modules and matching terminal boards according to the number of trip I / Os.
[0027] Example of input method: For the main unit's low oil level signal (3-to-2 trip test point), this signal enters the first three input channels of the first group of terminal boards. The specific physical wiring is as follows: Low oil level 1 enters NLP terminal board A (NLP1-1, first channel); Low oil level 2 enters NLP terminal board B (NLP1-2, second channel); Low oil level 3 enters NLP terminal board C (NLP1-3, third channel). The other two signals from each module (NLP terminal board) are read from each other via an "ETS dedicated parallel D-type 37-core cable." This achieves distributed configuration in the IO input stage, allowing all three modules (NLP terminal boards) in this group to receive three low oil level signals from the main unit's oil tank for logical judgment. Example of output method: Each module (A, B, C) receives three low oil level signals from the main unit's oil tank. After logical judgment, a Trip signal is sent, activating the relays on their respective terminal boards. Each module then selects two relays to send to the "ETS dedicated 2 / 3 terminal boards" (a total of six nodes) for judgment before sending the signal to the trip solenoid valve circuit. The above configuration ensures both the distributed isolation of input signals and the distributed distribution of output drive circuits, thereby improving the reliability of the ETS system.
[0028] All protection signals use three-way signals, with three redundant independent configurations from field detection instruments, control cables, and I / O modules.
[0029] The power supply consists of one factory-grade UPS uninterruptible power supply and another emergency power supply. The two 220VAC AC power supplies from the UPS and emergency power supply are converted into redundant 24VDC power through four independent 24V power modules inside the cabinet. The power conversion components use high-quality products to provide a stable and reliable power supply for the device.
[0030] The emergency shutdown control device communicates with the unit's DCS system, enabling online monitoring of protection and output signals on the host computer, and also has an accident event recording function.
[0031] Name resolution:
[0032] ETS System: The Emergency Trip System (ETS) is the turbine emergency trip system, which is a protection system for the turbine in emergency situations.
[0033] Misoperation: This refers to the erroneous operation of a protective device or relay in a power system or other equipment when there is no external fault or when it is not required to operate. This phenomenon can be caused by a variety of reasons, including unreasonable equipment design, manufacturing defects, environmental factors, electromagnetic interference, equipment aging, etc.
[0034] "Failure to operate" refers to the phenomenon where a circuit breaker or related equipment fails to perform its intended action during the operation of relay protection and automatic safety devices. This phenomenon can be caused by a variety of reasons, including electrical faults, mechanical faults, and improper operation.
[0035] The "two-out-of-three" voting mechanism is a widely used logical voting mechanism in many fields. Its core idea is to use three redundant signals for voting; when two of the signals meet the conditions, the system considers the condition to be true. This mechanism is mainly used to improve the reliability and security of the system and prevent malfunctions and failures to operate.
[0036] Redundancy: In the engineering and technology field, redundancy refers to a spare, alternative system or component to ensure the availability and stability of the system.
[0037] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0038] Although embodiments of the present invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the present invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A novel emergency shutdown control device for steam turbines, characterized in that, include: NLP terminal block A, NLP terminal block B, NLP terminal block C, ETS 3-in-2 dedicated terminal block; When the main unit's oil tank level is low, a 3-to-2 tripping test point is established, and the signal enters the first 3 input channels of NLP terminal board A, NLP terminal board B, and NLP terminal board C. Among them, the oil level of the main engine oil tank is low 1 and enters the first channel of NLP terminal board A (NLP1-1); the oil level of the main engine oil tank is low 2 and enters the second channel of NLP terminal board B (NLP1-2); the oil level of the main engine oil tank is low 3 and enters the third channel of NLP terminal board CNLP1-3. The outputs of NLP terminal boards A, B, and C are connected to the ETS3-select-2 dedicated terminal board.
2. The novel steam turbine emergency shutdown control device according to claim 1, characterized in that: The NLP terminal board A, NLP terminal board B, and NLP terminal board C are interconnected via cables.
3. The novel steam turbine emergency shutdown control device according to claim 2, characterized in that: The cable is an ETS-specific parallel D-type 37-core cable.
4. The novel steam turbine emergency shutdown control device according to claim 1, characterized in that: The outputs of NLP terminal boards A, B, and C are connected to relays, and the relays are connected to the ETS3-select-2 dedicated terminal board.