New approaches to the automated design of current thermal power plants
Thread Content
New Approaches to the Automated Design of Current Thermal Power Plants by Hou Ziliang (Thermal Power Plant Automation Technology Seminar)Table of Contents
1. Review of the Development of Power Plant Automation Technology
1.1 A Decade of Rapid Development in Power Plant Automation Technology
1.2 Experiences and Lessons from the Development of Automation Technology in Thermal Power Plants
2. Several Issues Related to the Automated Design of Unit Generators
2.2 Trends in Control Rooms and Control Methods
2.3 Issues Related to DCS Integration
2.4 Several Issues in the Protection Design of Unit Generators
2.5 Optimization of Monitoring Systems
3. Development of Technologies for Decentralized Functioning and Physical Distribution of Monitoring Systems
3.1 Issues Related to Decentralized Functioning of Monitoring Systems
3.2 Issues Related to Physical Distribution of Monitoring Systems
4. Automation of Auxiliary Systems (Workshops) Throughout the Plant
5. Plant-Level Monitoring and Information Systems
1. Review of the Development of Power Plant Automation Technology
1.1 A Decade of Rapid Development in Power Plant Automation Technology
Over the past decade or so, it has been the period of fastest development in automation technology for thermal power plants in China. Since the power market mechanism has not yet been fully established, the development of this technology has also relied on administrative and technical directives. When looking back at the technological developments over these ten years, it is necessary to consider the debates surrounding the formulation of such administrative directives as well. In the first phase, in the early 1990s, distributed control systems (DCS) evolved from pilot projects to widespread adoption. At the end of the 1980s, as an advanced and mature technology, DCS was widely used in the thermal power units introduced by Huaneng International Power Development Company; efforts were also made to select several power plants in China as pilot sites for its use. At that time, some problems that arose in certain projects involving the introduction of such units sparked a fierce debate regarding whether DCS should be adopted in power plants in our country. In response to this, the newly established Thermal Automation Leadership Group of the Ministry of Energy, headed by Chief Engineer Lu Yanchang, reached a conclusion regarding the debate. It was clearly stated that DCS is a new technology that has replaced traditional control systems on an international scale; it is now mature and suitable for China’s national conditions. The problems that arise in some projects are not due to issues with DCS itself, but rather as a result of adhering to outdated practices in China’s project management, which leads to the improper use of automation systems. Therefore, the leadership group made a prompt decision to actively and prudently promote the use of DCS in large-scale thermal power plant projects. From then on, a new chapter was opened in the history of automation development in thermal power plants in our country, and the automation of such plants began to be given its proper place. In the second phase, in the mid-1990s, automation technology for thermal power plants gradually matured. In the first five or six years of the 1990s, thanks to the efforts of leaders at all levels and a large number of engineering and technical personnel working in the field of automation, automation technology in thermal power plants developed rapidly in China. The application of such technology became increasingly mature, and the degree of automation kept rising. The main indicators of this development were as follows: 1) Data Acquisition Systems (DAS), Analog Control Systems (MCS), Sequential Control Systems (SCS), and Furnace Safety Supervision Systems (FSSS) were all integrated into DCS systems, with high availability rates for their various functions. Monitoring of individual power units was carried out through the human-machine interface of the DCS, while traditional backup monitoring methods were largely phased out. The availability rate of the automation system is at a high level when the new unit comes online. 2) A batch of engineering turbine control systems (DEH) utilize DCS equipment to achieve integration. 3) It resolved the issue of inconsistent control design between the boiler, turbine, and generator within the unit, and proposed and accelerated the integration of the generator-transformer set and plant service control (SCS G/A) into the unit’s DCS. 4) DCS is fully applied in thermal power units to upgrade the previously outdated automation technologies. It can be said now that the level of thermal automation equipment in China’s thermal power plants has reached international advanced standards, and the overall level of application is also gradually approaching these international standards. In the third phase, in the late 1990s, new approaches to the automated design of thermal power plants were proposed and applied in 2000. China’s automation technology for thermal power plants went through a period of development and consolidation, achieving certain results while also facing some issues. In light of international trends, the question of where China’s thermal power plant automation should head moved back onto the agenda in 2000. In the attachment to the document titled \"On the Construction of a New Generation of Demonstration (Pilot) Power Plants by the Year 2000\" submitted by the Electric Power Planning and Design Institute to **Electric Power Company in October 1997, the \"Design Principles for Instrumentation and Control (I&C) Systems in Power Plants by the Year 2000\" were outlined. The main principles included the following four aspects: 1) Further improvement in the intelligence and automation of unit control, along with the reduction in the size of control centers; 2) Application of principles for physically segmented design of monitoring systems; 3) More centralized monitoring of all auxiliary systems in the plant; 4) Development of plant-level Supervisory Information Systems (SIS) and Management Information Systems (MIS) to create a computer-based monitoring and information network across the entire plant. These new ideas have quickly found resonance across the country; some have been incorporated into regulations and standards, some are being promoted for wider use, and others are being tested in pilot power plants. The pace of development is faster than expected, and soon a number of power plants designed based on these new ideas will come online. We hope that the level of automation in thermal power plants can reach a new height, and that by the first decade of the 21st century, the level of automation in such plants can also attain international advanced standards. 1.2 Experiences and Lessons from a Decade of Development in Automation Technology: Over the past decade, the field of automation technology in power plants has experienced many ups and downs, bringing both experiences and lessons. What is most worth summarizing are the guiding principles behind our work in automation; the following points are presented for discussion ; 1) Be proactive. Those who are in leadership and technical roles in power plant automation must particularly possess the quality of foresight. Predictability includes the ability to anticipate social needs as well as the development of automation technologies. Social demands have been the fundamental driving force behind the development of automation technology in thermal power plants over the past decade. Currently, the reform of China’s electricity market mechanism has been put on the agenda, which imposes a range of requirements on the automation technology used in thermal power plants; for example, there is a need to reduce the number of personnel required for duty and maintenance within such systems. At present, many power plants have a large workforce, making it very difficult to reduce staff through layoffs. However, it should be recognized that the reform of the electricity market mechanism is an inevitable trend, and there will surely be a need to cut down the number of employees in the near future. Therefore, when carrying out technical upgrades, we should strive to reduce the number of control points; where one machine was controlled by one operator, this can be changed to two machines controlled by one operator (or even three machines controlled by one operator). In auxiliary workshops, highly centralized monitoring or unmanned operation can be adopted to further reduce the number of control points. Currently, some leaders are increasingly recognizing that adopting automation offers the best cost-benefit ratio (for example, by advocating for the use of information technology to drive industrial development), and they are paying more attention to the application of automation technologies. As a result, societal needs will be translated into demands for such automation technologies more rapidly. The rapid development and frequent updates in automation technology are a prominent feature of our field. Therefore, when engaging in automation planning and design, it is essential to be forward-thinking; the plans and designs should have a long lifespan, and care must also be taken regarding the lifecycle of the products chosen. There are valuable lessons to be learned from this – for example, in the early 1990s, only DAS systems were allowed to be used, failing to keep up with the widespread adoption of DCS systems ; For example, in the mid-1990s, the lack of foresight in the automation upgrades of some older factories led to the need for further upgrades shortly thereafter; in addition, some factories used unstable products from unreliable manufacturers. 2) Always maintain an \"open\" mindset and adhere to the principle of seeking truth from facts. The tendency to pursue large-scale solutions, rely on foreign methods, and copy what exists abroad has always been considered by some as the main error in the automation of thermal power plants. A very negative impression people have of us is that we are always trying to introduce new things. Yes, some of us have indeed made such blind mistakes on certain issues, but I believe this is not the main error. Open your eyes and take a look: the reason why automation technology in thermal power plants has developed so rapidly over these past decade or so, and has brought about qualitative changes to the safe and efficient operation of these plants, is due to \"openness\". We have adopted almost all of the advanced automation technologies that are commonly used in such plants. Practice has shown that nothing is unsuitable for China’s national conditions – whatever is applicable can be used. Therefore, it’s not the case that we are being too open; rather, it’s time to make efforts to learn from foreign advanced experiences. We should try to avoid the mistakes that other countries have made, and carefully analyze different solutions in order to select the best ones for our own use. When adopting foreign experiences, we must not copy them verbatim; instead, we should adhere to the principle of seeking truth from facts and proceed based on actual conditions. This is especially important when renovating old factories, in order to achieve practical results. Nor should we be constrained by the development of automation technologies abroad; we now have all the capability to innovate, and many aspects of automation technology in Chinese thermal power plants were pioneered by our own country. 3) Flexible thinking, with regulations not hindering development. In the era of a planned economy, including over the past decade, regulatory standards—whether they are construction standards or technical standards—have for the most part had a certain degree of mandatory character ; The formulation and enforcement of regulations are often handled by the same entity, that is, what is known as the integration of \"legislation\" and \"enforcement\" ; One purpose of formulating regulations, especially the construction standards section, is often **a means of managing enterprises. Currently, the reform of electricity market mechanisms is accelerating. Regulation will be carried out at three levels: **, industry associations (such as the China Electricity Council and its affiliated standardization technical committees), and enterprises. ** will no longer directly manage the economic activities of enterprises, but will only handle macro-level issues such as resource planning, environmental protection, and safety. ** will be responsible for formulating and enforcing laws in these areas. The association will be commissioned by enterprises to develop national or industry-specific regulations and standards; in principle, it only issues recommended standards and has no authority to issue mandatory standards, unless authorized or through administrative orders. Additionally, it does not have the role of enforcing these standards. Guild standards are accepted by businesses and users, and serve as a basis for large companies to establish their own standards, relying primarily on their authority or on activities such as joint voting by enterprises. To strengthen and standardize corporate management, enterprises (such as power generation investment companies) are likely to establish their own standards by combining industry norms with specific circumstances, and use these standards to review the designs of power generation projects they intend to build. However, regardless of how regulations and standards are formulated and implemented in the future, when specifying a particular clause in such regulations, it is important to explain the reasons and underlying assumptions for that specification, so as to prevent them from becoming rigid rules. This approach prevents rigid thinking and ensures that regulations do not hinder technological development. For example, regarding whether DEH should be integrated with DCS hardware, no absolute rules were established stating what was allowed or not; instead, the conditions under which each option could be used were outlined. This approach avoids forcing integration at the expense of technical maturity, while still paving the way for the development of integrated technologies ; For example, when electrical control was integrated into DCS in the 1990s, due to the lack of domestic experience at that time, AVR and ASS were not allowed to be included in DCS as a precaution. If we had known that such considerations were behind that decision, then could the previous rules be changed now that some companies have gained successful experience in using DCS equipment for ASS applications? Another example is the issue of large-screen displays: from a human-machine interface perspective, they have certain advantages, but their cost and availability rates were still high at that time, and there was no practical experience with them in China. Regarding such issues, I think one approach is to carry out pilot projects to gain experience; it’s not necessary to implement them across the entire organization right away or to abandon them altogether ; Furthermore, it is necessary to keep up with new developments in large-screen display technology, such as changes in availability and prices, and adjust one’s mindset accordingly. In short, the provisions of regulations should aim to prevent the situation where \"everything collapses as soon as a rule is imposed, and chaos ensues as soon as those rules are lifted.\" 4) It is necessary to adhere to a proactive yet cautious approach when gradually introducing and applying new technologies. Automation technology in power plants is developing rapidly; however, new technologies are often not fully mature at first or lack practical experience in application. Therefore, the process of introducing and applying such technologies must be both proactive and cautious. We have followed this approach in areas such as the deployment of DCS systems, the elimination of backup monitoring equipment, the use of large-screen displays, and the integration of electrical systems into DCS – advancing step by step. Once experience is gained, the pace of adoption can be accelerated, so that even a lack of initial experience does not result in significant losses. Practice has shown that this approach should be maintained. When promoting plant-level monitoring and information systems at present, I suggest adopting this approach as well: the network framework and database servers can be set up first, while application software can be developed and improved one by one depending on its level of maturity. 5) Strengthen the management of the entire automation process in thermal power plants, and improve the level of management regarding the application of automation technologies. Around the early 1990s, starting with Pingxu and Shiheng, the level of automation improved significantly, and DCS systems began to be used in thermal power plants in China; some problems arose at that time. As a result, some leaders criticized those working on automation without any analysis, accusing them of \"blindly copying foreign practices\" and claiming that the level of automation was insufficient and not suitable for China’s national conditions. It turned out, however, that the problem did not lie in the DCS itself, and that an improved level of automation was necessary to meet the requirements of operating large-scale units. The real issue was that some leaders still considered automation systems to be unnecessary; their management mindset lagged behind the progress of automation technology. As a result, automation systems were not given an appropriate place in the project milestones, and there was no proper planning of the overall process to allow for the necessary time for debugging these systems. Naturally, this led to many problems when the systems were put into operation. Later on, various regions appointed a number of technicians familiar with automation to leadership positions at all levels. The establishment of control rooms was set as a milestone indicating that the automation systems could now begin full-scale debugging, and this was included in the project milestones. As a result, the situation changed rapidly. Similar problems arose whenever electrical systems were integrated into DCS systems, or when plant-level monitoring and management information systems were introduced. Given the particularly rapid development of automation technology, which represents a highly dynamic form of advanced productive force, the phenomenon of management practices falling behind technological advancements will continue to occur. Therefore, in addition to selecting individuals familiar with automation technology at all levels of leadership, top leaders must also thoroughly study the management reforms necessitated by the progress of automation. 2. Some Issues in the Automated Design of Unit Systems. The technology for the automated design of unit systems has seen significant improvements since the introduction of the EBASCO technology from the United States; here, some views on several new issues arising in this design process are presented. 2.1 Trends in control rooms and control methods 1) Control points are becoming increasingly centralized, while the locations of control rooms are becoming more diverse. With the development of automation technology and the improvement of automation levels, the concepts regarding the responsibilities of operators are also changing, and the operation of machinery units relies increasingly on automated systems. To facilitate management and reduce the number of personnel on duty, the number of control points can be appropriately reduced. In the past, some power plants adopted a system of one controller per unit; therefore, during technical upgrades, this should be changed to a system of one controller per two units, or one controller per three units (in cases where there are three units in the plant), or even one controller per four units, in order to achieve highly centralized control across the entire plant. The Laibin B plant designed by the French uses a system of one controller per two units, with the control room located at a fixed location, and the distance between the control room and the units is similar to that in the system of one controller per four units. The location of control rooms is also becoming increasingly diverse; some are located at fixed sites like Plant B for guests, while abroad they may be found in production office buildings or separate small structures. It is believed that having a certain distance between them poses no problem, as there are few personnel working in the control rooms who must remain on duty, whereas inspections and auxiliary operations should be carried out by those on site. This provides new ideas for the comprehensive optimization of the entire plant layout. 1) Issues regarding the control methods of auxiliary and utility systems in unit plants: The automation design of the plant’s auxiliary systems (workshops) will be discussed in detail later; here, focus is placed on the control methods of the auxiliary and utility systems that are closely related to the unit plants. a) Circulating water pump room: It is closely related to the safe and economic operation of the unit systems. In the case of a pure unit system, it should be integrated into the DCS of that unit, to be monitored by the unit operator; in the case of an extended unit system, it should be incorporated into the common DCS of the two unit systems, with monitoring carried out by the operator of one of the units. b) The utility power system is generally incorporated into the unit’s utility DCS system for easier management, and is monitored by the operator of one of the units. c) The air compressor room is generally incorporated into the utility DCS of the unit train; if it is located near the water treatment plant, it can also be integrated into its automation system. d) Flue gas desulfurization system (FGD), which consists of both unit-specific components and common components. There are two control methods: one involves the crew responsible for the unit managing the desulfurization system as well, with the FGD system integrated into the unit’s and its common DCS systems. The advantage of this approach is that the desulfurization process is closely linked to the operation of the boiler, and unified monitoring facilitates safety and environmental protection; in the long term, it may not be necessary to have dedicated personnel for managing the FGD system. However, when the common areas are large, it places an additional burden on the unit supervisors, and the distances are also greater. Another approach is to establish a single control point for the entire plant’s desulfurization system, equipped with one or several DCS systems. This method is more convenient for management, and its advantages are particularly evident when upgrading older plants, or when a desulfurization system is added later, or when the construction of the desulfurization system is not synchronized with that of the main system. However, in the long term, in order to further reduce the number of personnel on duty, it is necessary to leave room for further consolidation of control points, such as those related to electrostatic dust removal and ash removal systems. e) Final treatment, chemical dosing, and steam/water analysis sampling; currently, some suggest integrating these functions into the unit train’s DCS, on the grounds that it is convenient to have them managed by the unit train within the main plant. Others advocate for unified management by the monitoring points of the plant’s water treatment auxiliary system, on the grounds that the professional setup is appropriate and distance is not a major issue; in either case, it relies primarily on inspection personnel. Personally, I believe the latter configuration method has many advantages and is worth recommending. 2) Control room design a) From an ergonomic perspective, the height of the CRT should be reduced; therefore, the desk on which the CRT is placed should be lowered, especially when very large-screen monitors are used. b) Miniaturization of the control room: This is an inevitable consequence of eliminating a large number of backup monitoring consoles. c) Regarding the issue of cable trays, since full CRT monitoring is used and there is little backup monitoring equipment, it is not necessary to have high cable trays beneath the main circuit in the control room; this space below can be utilized. d) As for the dual-CRT arrangement, such arrangements are common in the renovation projects of old factories in the United States. This is mainly because the control rooms are relatively small and there is only one operator on duty; this design approach was developed to reduce the area required for monitoring, and under certain specific circumstances, it can also serve as a viable solution to consider. 2.2 DCS Integration Issues The integration of DCS functions enables a variety of advantages, such as easier maintenance, reduced need for spare parts, fast and reliable information sharing, and a unified human-machine interface. The initial functions of DCS included DAS, MCS, SCS, and FSSS; today, the scope of DCS integration can be further expanded. 1) The issue of using a DCS system for DEH is addressed by the regulations, which lay out two prerequisites: first, the turbine manufacturer assumes overall responsibility, that is, it is responsible for developing and approving the functional diagrams and performance requirements as well as ensuring the interfaces with the turbine; second, the DCS company must have experience in using DCS systems to implement DEH functions. At present, most DCS manufacturers are able to meet the aforementioned requirements. Of course, we are not opposed to the option of having turbine manufacturers or specialized DEH manufacturers supply dedicated DEH systems; generally speaking, they have more experience. It is now possible to easily establish bidirectional redundant communication between the DCS and the DEH, allowing the DCS operator station to serve as a single human-machine interface (in some cases, hardwiring can be used for control signals). 2) The issue of including ETS in DCS. Through this practical experience, the reliability of DCS has **improved**. There have been several successful engineering projects that have integrated ETS into DCS, but it is important to note that the processing time of the ETS controllers should not exceed 50 ms; ideally, it should be between 20-30 ms. Additionally, independent redundant controllers should be used to maximize reliability. Recently, when the **electricity company organized a review of the ‘Guidelines for the Automation Upgrade of Old Plants’, it was decided that independent controllers should be used instead. 3) Incorporation of the automatic synchronization device (ASS) into the DCS issue. When electrical control systems were first integrated into DCS, due to a lack of experience, only the sequence control systems for generating sets and plant power supply (SCS G/A) were included in the DCS; automatic synchronization devices (ASS), automatic voltage regulation devices (AVR), and generator protection systems were not incorporated into the DCS. After four or five years of practice, integrating SCS G/A into the DCS became feasible both from a management perspective and technically, and successful application experiences were gained. Regarding ASS devices, DCS companies have already integrated them into their DCS systems. Therefore, when reviewing the guidelines for technical upgrades in existing plants, the relevant provisions were revised to allow ASS devices to be incorporated into DCS systems as well, whenever DCS companies have successful experience in doing so. This reflects the principle that regulations should evolve alongside technological advancements, thereby preventing regulations from becoming barriers to such progress. 2.3 Some Issues in the Protection Design of Unit Systems 1. Fast Load Shedding (FCB) Protection FCB refers to the mechanism by which, when the generator is disconnected or the main steam valve is closed, the protection system takes immediate action to quickly open the bypass valves to relieve pressure. At the same time, the boiler reduces the load to a level close to the maximum allowable load for the bypass, allowing the plant to continue operating for a short period of time – this is what is commonly referred to as shutting down the plant without stopping the boiler. The purpose of FCB is to enable a faster restoration of the load on the unit once faults in the turbine or generator are resolved; in some cases, it can also allow the machine itself to supply the plant’s electrical power. From a system perspective, under what circumstances must a unit be equipped with the FCB function? It depends on the system’s requirements for the unit; it may be responsible for maintaining operation of the plant’s own power supply in the event of a grid failure, in order to restore power system operation as quickly as possible. From this perspective, a power grid should have several power plants with such capabilities; unfortunately, the power grid management authorities have not yet paid attention to this or made appropriate plans. From the perspective of the power plant, to install an FCB, at least the following three conditions must be met: a) The unit must be able to activate its bypass at the time of load shedding. For Westinghouse-style units, the medium-pressure control valve is a non-regulating valve; it is not allowed to open to enable bypass operation when the turbine loses load. Therefore, Westinghouse’s original design called for the MET to shut down immediately when the generator was disconnected or the main steam valve was closed, and it was not possible to implement an FCB function unless extensive fundamental modifications were made. b) Based on past experience, for coal-fired boilers, to achieve successful FCB at full load shedding, the bypass capacity should be 50-60%; otherwise, it can only succeed during load shedding at lower loads. c) There must be a sound bypass system that can open quickly; in the past, some power plants experienced system failures when the bypass opened rapidly due to issues with the piping design and the steam drainage system, and this is something that must be taken into account. Based on the above analysis, in current new plant design projects, the typical configuration for the units is 50–60% rapid bypass, and there is extensive experience in designing the piping systems; therefore, it is recommended to include an FCB function during the project review phase. In general engineering projects, although shutting down the machine without shutting down the furnace has certain advantages (faster load restoration), it can easily lead to serious accidents during the FCB process. Moreover, in order to save on investment, only a bypass system accounting for about 30% of the capacity is installed for startup purposes, with the FCB function being ignored. However, technology is evolving. In particular, many power plants that were built in the past and are equipped with turbines of 125–300 MW already have 30% rapid bypass and FCB functions. I believe that before implementing these FCB functions, each power plant should determine, based on its own conditions, whether it is permissible to activate the bypass during turbine load shedding, and should conduct thorough tests and make design adjustments, including determining the amount of load shedding that triggers the FCB, conducting safety tests for the rapid activation of the bypass, and optimizing the logic design of the FCB. But one thing needs special attention: under unsuitable conditions, never rush to take action and cause a serious accident. 2 Inverse power-based generator disconnection issue **Requirement 9.1.6 of the ‘Twenty-Five Key Requirements for Preventing Major Accidents in Power Generation’ issued by power companies stipulates that during normal shutdown, after shutting off the switch, it is necessary to first check whether the active power has reached zero; only after the kilowatt-hour meter stops rotating or starts rotating in the reverse direction should the generator be disconnected from the system, or disconnection can be achieved by activating the inverse power protection mechanism. Disconnection under load is strictly prohibited. "However, Article 25 does not provide any specifications regarding the interlock protection for unit plants in the event of turbine failures. Current design technical specifications also do not provide clear guidelines on how to comply with the requirements of clause 3.1.6; in most cases, the generator is still disconnected immediately upon shutdown of the turbine (when the main steam valve closes and the terminal switch closes). The interlock conditions designed in this way are in conflict with the requirements of section 3.1.6, because during a normal shutdown, after the main steam valve is closed, as long as the terminal switch is closed, the generator is disconnected regardless of whether the main steam valve or the throttle valve is fully closed, and regardless of whether reverse power occurs. Of course, without changing the original interlock conditions, minor modifications can also meet the requirements of clause 3.1.6; for example, adding a \"normal shutdown\" button such that when this button is pressed to shut down the system, the generator is not immediately disconnected through interlocking. However, this can lead to accidental operations; therefore, I believe it is best to modify the protection interlock conditions for the individual units in line with the spirit of Article 3.1.6. 1) The conditions for disconnecting the generator have been modified to be the closing of the main steam valve terminal switch and the occurrence of an inverse power signal. During normal or emergency shutdowns, the main steam valve is closed and its end switch closes. Under the previous protection interlock conditions, regardless of whether the main steam valve and the throttle valve were properly closed, the generator would be disconnected via interlock, which could lead to serious runaway accidents. Several such severe incidents have occurred in recent years; the revised interlock conditions include an inverse power signal that enables accurate detection of situations where valves are not properly closed. Of course, if the reverse power signal is not issued after doing this, then in certain turbine failures (such as shutdown due to severe blade vibration), the inability to disconnect the system or reduce its speed in a timely manner can also cause serious damage to the turbine. Nevertheless, a runaway accident is even more severe. 2) Traditionally, an inverse power protection circuit is designed in electrical protection systems. When an inverse power signal is detected, an alarm is issued first; if this signal persists for a certain period of time (about 3 minutes), the generator is disconnected via interlock. This protection circuit is essential, as inverse power can occur easily during the process of connecting to the grid or shutting down the machine under reduced load, which may lead to the turbine operating without steam. Typically, steam turbine manufacturers stipulate that under normal condenser vacuum conditions, the turbine is allowed to operate without steam for more than 3 minutes. Prolonged operation can lead to accidents such as overheating and vibration in the turbine, and this protection circuit is designed based on such situations. According to the new design concept, the delay time of the generator reverse power tripping protection should be changed from the previous \"graded\" approach to a \"second-level\" approach. Of course, the allowable time for a turbine to operate without steam under normal conditions is a concept that involves different levels; therefore, it is always desirable to have some time available for operators to determine whether the reverse power signal is a false alarm. If it is indeed a false alarm, measures can be taken promptly to disable the reverse power protection, or actions can be taken to eliminate the reverse power condition when it actually occurs. However, our design does not allow for measures that would enable operators to disable the protection ; Secondly, while it is advantageous to give operators as much time as possible to carry out operations in order to avoid reverse power operation, this can also lead to negative consequences. When the turbine stops due to certain faults (such as excessive vibration), it is desirable to stop it as quickly as possible, sometimes even by breaking the vacuum in order to minimize damage to the turbine. If the main valve of the turbine closes and the terminal switch fails to send a signal, then it is necessary to rely on the reverse power signal, which arrives after a long delay, in order to disconnect the generator – clearly, this is not favorable. Therefore, at present, under the protection design philosophy that gives priority to protecting equipment over generating power, it makes sense to reduce latency. 3) The reliability of the reverse power signal should be improved, and a two-out-of-three mechanism should be adopted. As can be seen from the above analysis, the importance of the reverse power signal is evident. A failure to detect this signal will prevent the generator from being disconnected immediately after shutdown, while a false detection of it may lead to incorrect disconnection of the generator, or even cause a runaway condition (when the main steam valves and throttle valves do not close properly). Therefore, for such an important protection signal, a two-out-of-three voting mechanism should be employed. 3) Regarding the issue of shutting down the boiler without stopping the unit, during discussions on unit protection, some suggested that when the boiler protection triggers a shutdown, the main steam valve should not be closed immediately. If it is determined that the protection has triggered erroneously or if the fault can be resolved quickly, the boiler can be started again so that the unit can resume operating under load. We believe this approach not only contradicts current regulations but is also undesirable. Because: a) Operating using the waste heat from the boiler requires the turbine to operate at very low loads, which leads to significant thermal stress and reduced lifespan for the turbine, and it can also cause issues such as vibration and uneven expansion, all of which are unsafe factors. From the boiler’s perspective, a too rapid drop in the drum pressure can also lead to hazards such as water carryover or excessive thermal stress. Therefore, continuing to operate the equipment poses a greater potential risk than shutting it down. b) In the event of a fault in the boiler feedwater system (large drum water level difference), it is also not allowed to rely on waste heat for steam generation. c) Since a thorough inspection is required before restarting a boiler after it has been shut down, and the furnace must be purged in accordance with regulations, it is not possible to start it quickly. Attempting to start it in a hurry often leads to an expansion of the accident; such lessons are all too common and extremely painful. 2.4 Optimization of monitoring systems I pointed out at a conference that, entering the 21st century, DCS systems should undergo substantial changes. Apart from structural changes in DCS systems, this refers mainly to the application software aspects of the entire automation system, particularly the issue of optimizing monitoring systems. After more than a decade, DCS technology has become largely mature. Although there are still some shortcomings in the design and application of monitoring systems that need to be addressed, the focus should shift toward further optimization in order to achieve safety and efficiency. Abroad, progress in this area is also accelerating rapidly. I hope that this time there won’t be a large gap, and that we can even surpass them in some areas. Optimization of monitoring systems can focus on the following aspects: 1) Enhancing the operation guidance functions. This refers to open-loop monitoring systems that take into account both safety and economic factors; they are based on status calculation, analysis, and diagnosis. Sometimes, such systems require specialized and complex application software, or even entirely dedicated systems. Examples of such applications include deviation analysis in organic systems, optimization of combustion processes, and diagnosis of turbine vibration faults. However, some operation guidance functions can be implemented by simply summarizing practical operational experience from power plants using DCS configuration methods. For example: – Intelligent alarms (e.g., displaying the actual cause when multiple related alarm signals appear); – Generation of intelligent displays that provide guidance in case of deviations or faults in the main units (e.g., analyzing and showing possible reasons for low turbine vacuum); – Alerts regarding changes in the status of auxiliary units (compared with historical data) along with analysis (e.g., tracking and analyzing fluctuations in fan flow, pressure, and power levels). Therefore, we should not treat operation guidance as something mysterious. Of course, we need to bring in or recruit domestic experts who are familiar with the mechanics of the generating units, possess some operational knowledge, and have expertise in optimization theory, in order to develop advanced optimization monitoring systems. However, we should not neglect the need to develop basic yet practical operation guidelines based on insights gained from the actual operations of power plants, so as to move away from a situation where only theoretical discussions take place. 2) Improve the level of automation. At present, there is still a certain gap between the automation level of thermal power plants in China and that in foreign countries. During the period from the 1980s to the 1990s, the controllability of units in China was poor, the selection of control equipment was inadequate, management levels were low, there were many operators, and due to power shortages, most units operated at basic load levels. Therefore, the level of automation established in the 1990s was such that sequential control was primarily at the sub-group level, with only a very small portion achieving function-group level control; analog control was designed to operate automatically under high load conditions (with a few exceptions), which represents a significant gap compared to the level of automation abroad. Currently, the situation has changed significantly: electricity market reforms and the relative abundance of electricity have imposed many new requirements on the operation of power units (such as meeting peak-shaving and primary frequency regulation needs, reducing startup times, etc.), forcing power plant management to pursue continuous deeper reforms ; The controllability of newly built power plant units has seen significant improvement ; The selection of control equipment is not very different from that used abroad, and older power plants are also gradually bringing themselves up to par through renovations and new constructions. Therefore, in our new design concepts for the year 2000, we proposed that sequential control should gradually evolve toward functional group level and unit level control, while analog control should have an expanded range of values that can be automated. 3 Further implementation of optimal control: Optimal control includes the optimization of analog control and sequential control. Examples include: – Optimization control of the ball mill coal grinding system; – Optimization of steam temperature control; – New types of coordinated control systems; – Optimization of boiler soot blowing; – Optimization of unit startup. Many software solutions have been developed both domestically and internationally, some of which are already available commercially. It is necessary to thoroughly examine their effectiveness in order to decide whether to purchase them. There are also solutions that are practically ready for use, but still require some further development work. The transition of thermal power plants from manual (remote) control to automatic (sequential) control represents a major leap forward. Entering the 21st century, the monitoring systems in thermal power plants will evolve from traditional methods to optimized (intelligent) systems, which will constitute another qualitative leap. In October 1997, we proposed several aspects regarding \"new approaches to I&C design for thermal power plants by the year 2000.\" However, making progress toward optimizing these monitoring systems is the most challenging aspect; to achieve this goal, certain ideas and concepts need to be discussed. a) It is necessary to recognize that electricity market reforms will impose higher requirements on the safe and efficient operation of power plants, making the optimization of monitoring systems an objective necessity and an inevitable trend. Advanced countries abroad have made rapid progress in this area, which serves as a lesson for us; we should take the initiative to ensure our competitiveness in future competitions. b) Place emphasis on technology and talent. The optimization of monitoring systems places higher demands on talent, requiring significant amounts of skilled effort. Therefore, it is necessary to value such talent mentally, respect their work in practice, and provide them with appropriate compensation materially. As for suppliers, if they carry out effective work in this area, they should also receive fair rewards; otherwise, who would be willing to take on difficulties and incur losses? Only in this way can technological progress be promoted, and substantial benefits can be achieved. c) It is necessary to adhere to a proactive and cautious approach, launching each project once it is ready; there should be no reckless rush. For projects that have been decided upon, full focus must be exerted to ensure tangible results. 3. Application of functions dispersion and physical dispersion techniques in monitoring systems. The development of computers and network technologies has driven the advancement of DCS technology; at the same time, it has also created conditions for the diverse application of functions dispersion and physical dispersion techniques in monitoring systems. However, the optimal degree of dispersion in such systems ultimately depends on the characteristics of the process system. 3.1 Problem of fragmented functions in monitoring systems: When distributed control systems were first introduced, there were two main groups of developers. One group consisted of companies from Europe; based on the shortcomings of previous centralized computer control systems where failures occurred in one centralized location, they proposed that DCS should be developed following the principle of complete decentralization of control functions. Therefore, the control capacity in the DCS they have introduced is very limited; it is usually sufficient to control 1–2 loops, similar to traditional single-loop controllers ; The other group, composed mainly of companies from the United States and Japan, takes a middle path by adopting a principle of moderate diversification. At first, the European faction was welcomed to a certain extent because it conformed to the original *customs. However, over time, this approach was eventually phased out. Now even DCS companies, which were the originators of this concept back then, have abandoned the idea of completely decentralized control functions of that original type, and are instead introducing DCS products with a degree of decentralization. Looking at this period of DCS development, and taking into account the characteristics of control systems for unit plants in thermal power plants, I believe that the functional configuration of DCS will move in the exact opposite direction to its physical configuration, trending toward a more moderately centralized approach. The reason for this is that, first of all, there are intricate signal connections between the various control systems of a unit. A failure in one pair of controllers often results in another pair being unable to function properly due to the lack of proper signal connections, and may even cause incorrect operations ; Secondly, since there are currently few conventional backup monitoring devices, for most critical controllers, the failure of just one pair of controllers may force a shutdown. And too many controllers actually increase the probability of failure-induced shutdowns. Once again, both the capacity and speed of controllers have been **improved**; multiple closely interconnected control systems are consolidated into a single pair of controllers, which in turn enhances reliability due to easier internal information exchange. The DCSs offered by some branches currently feature a 2×2 CPU redundancy configuration (due to advances in computer technology, the increase in cost is minimal), thereby further enhancing reliability. In summary, depending on the characteristics of the power plant, efforts should be made to improve the reliability of each group of controllers; for example, controllers designed in accordance with the functional safety principles of IEC61508 can be used ; The CPU features 2×2 redundancy or triple redundancy ; If necessary, even redundancy can be applied to some I/O. And, when the controller capacity and speed permit it, the controllers can be configured appropriately (based on the process function areas) ; Integrate closely related control systems into the same controller, etc., to appropriately increase the degree of concentration in functional configuration. 3.2 The issue of physical dispersion in monitoring systems: With the development of computer and network technologies, debugging and maintenance have become increasingly easier, and the environmental requirements for modules have also decreased. The physical configuration of monitoring systems is shifting away from the traditional approach of concentrating everything in one control building, toward more diverse configurations that take practical considerations into account – that is, a pattern of moderate physical dispersion – in order to achieve the best return on investment. There are several ways to summarize domestic and international experiences: 1) Physically dispersing the electronic equipment rooms (controller cabinets) among different devices. In the UK, two large gas-steam combined cycle units have corresponding electronic equipment rooms located next to devices such as gas turbines, steam turbines, and waste heat boilers; these rooms also include electrical distribution systems. In Alstom’s BOT project in Guangxi, namely Plant B in Laibin, there are two electrical equipment rooms located next to the boiler and the turbine; these rooms also contain electrical distribution systems. In recent years, some power plants in our country, including demonstration plants, have also begun to explore the decentralization of electronic equipment. In most cases, the electronic equipment for boilers is still placed in the control building, while the electronic equipment for turbines is positioned as close as possible to the turbines in order to save on cables. In the renovation of old factories, cases have also emerged where electronic equipment is distributed across different locations; for example, when the system that previously relied on one controller per machine is modified to use two controllers per two machines or one controller per three machines, the electronic equipment remains in its original control rooms rather than being concentrated in one control room. Practice has shown that, when electronic devices (controller cabinets) are placed in suitable locations and dispersed physically to an appropriate extent, as long as the required environmental conditions are not too stringent, this not only helps to save cables but also avoids difficulties in operation and maintenance. 2) Physical dispersion of process channels: At present, most of the process I/O channel modules in DCS systems use fieldbuses for communication with controllers. With the advancement of electronic technology, not only remote I/O units equipped with specially designed enclosures, but also ordinary I/O units can function properly under certain environmental conditions when placed in enclosures that meet specific protection requirements – a fact that has been proven through numerous applications in China. The widespread use of a distributed configuration for remote I/O helps to save on cables and related costs. The biggest issue at present lies in the application of drive control I/O, and there are still concerns regarding this. In fact, it is now time to dispel such worries and pursue its widespread adoption. The reasons are as follows: Firstly, there is no fundamental difference between ordinary I/O modules and control I/O modules; their controllability and adaptability to different environments are the same. Secondly, the remotely placed control I/O modules are mainly used for digital control, and communication bus failures do not have a significant impact. In this regard, there are many successful application experiences abroad, as well as significant achievements in China. It is particularly noteworthy that the electrical engineering field has developed more rapidly than the thermal automation field in this area, and this technology is widely used in intelligent switchgear. 3) Applications of fieldbus control systems: The emergence of fieldbus control systems has made it possible to achieve complete physical decentralization of monitoring systems, and their applications extend beyond simply saving cables and the benefits that come with this. Field bus control systems rely on field buses and intelligent field devices; for such intelligent devices to be able to fully utilize their functions, it is necessary to have a control system built through field buses. However, the development of intelligent field devices is not solely aimed at creating field bus control systems – they have many other areas of development, such as functions for remote maintenance, adjustment, and management, and these functions existed even before the emergence of control functions. Therefore, I believe that approaching the issue from the perspective of the application prospects of intelligent field devices in thermal power plants could offer a broader outlook. a) Fieldbus analog control system. The fieldbus analog control system is undoubtedly the first application area for intelligent field devices; it enables complete physical and functional decentralization of the control system. It holds practical value and broad application prospects in some simple analog control systems in thermal power plants (including remote control). It integrates data acquisition, autonomous control, as well as the maintenance, adjustment, and management of on-site equipment, and it also offers advantages such as cable savings and reduced engineering workload. Therefore, it can be gradually promoted and applied in practical engineering in a proactive and cautious manner. However, for complex control systems, \"complete decentralization\" actually reduces the reliability of the system due to the increased number of failure points (even if redundant FF--HI or PROFIBUS--PA process automation buses are developed in the future), and it requires that the functions of a control system exchange information frequently within the layer 2 communication network at high processing rates; therefore, it is technically unfeasible for at least a considerable period of time. For the control functions of this part of the system, there is instead a trend toward moderate centralization. b) Field bus digital control systems utilize intelligent drivers and switchgear to connect to the DCS system via field buses. This represents another application of intelligent field devices; it addresses tasks such as the maintenance, adjustment, and management of field drive systems. Currently, this technology is mature, with a variety of products available. The question is whether it is cost-effective, and this is an issue that needs to be analyzed in terms of future development. The reform of the current electricity market system is accelerating; the separation of power plants from the grid and competitive bidding for electricity supply are about to be implemented. Improving operational safety and efficiency, as well as reducing the need for more staff while increasing productivity, is directly related to the interests of investors and employees, and thus receives increasing attention. The use of such systems not only enhances operational safety through intelligent diagnostics and remote maintenance, but also facilitates the electronic and modernization of on-site equipment management, thereby reducing the need for maintenance personnel. Internationally, this is also considered an emerging trend. c) Field bus data acquisition system: Intelligent transmitters are used to connect to the DCS system via field buses, which represents another application of intelligent field devices. It is very similar to the application of the fieldbus digital control system mentioned earlier. Imagine that in large thermal power plants, intelligent field devices are widely used to be connected to the DCS system via field buses, with only a small portion of them achieving closed-loop autonomous control. In this way, the thermal automation system not only contributes to the automation of thermal power plants but also lays the foundation for the modernization of the operation, maintenance, commissioning, and management of the automation systems themselves. Therefore, from a more forward-looking perspective, appropriate explorations can be carried out step by step in specific projects. 4. Automation of the plant’s auxiliary systems (workshops): In large thermal power plants, there are more than a dozen such auxiliary systems, including coal conveying systems, ash removal systems, slag removal systems, make-up water systems, reverse osmosis systems, condensate water systems, wastewater treatment systems, purification stations, chemical dosing and sampling systems, hydrogen production systems, fuel pump rooms, circulating water pump rooms, air compressor rooms, comprehensive pump rooms, electrostatic dust removal systems, and flue gas desulfurization systems. According to a survey of 168 thermal power plants in 28 provinces, municipalities, and autonomous regions that are equipped with units with a capacity of 125 MW or more, 74% of these plants have automated coal conveying systems, while 61% have automated systems for treating boiler make-up water. For the other auxiliary systems, the degree of automation varies between 10% and 40%. Moreover, due to the need for distributed duty shifts, the number of operating staff can range from 100 to 200 people. As the reforms of large and medium-sized state-owned enterprises are being gradually implemented, some of these enterprises have realized that highly centralized control of auxiliary workshops, with fewer monitoring points, can **improve labor productivity and result in cost savings of tens of millions per year. As a result, some advanced enterprises have begun to carry out technical upgrades to their auxiliary systems. In light of this situation, the report \"Design Principles for Power Plant Instrumentation and Control (I&C) Systems in the Year 2000\" issued in October 1997 specified that auxiliary systems (workshops) should have unified design, standardized equipment selection, and consistent design criteria, in order to improve the level of automation, reduce the number of monitoring points, and achieve higher efficiency with fewer personnel. The \"Design Code for Thermal Power Plants\" issued in 2000 also incorporated this design concept formally into the code, stipulating that \"the auxiliary production workshops adjacent to thermal power plants or auxiliary process systems with similar functions should share control systems and control points; the number of control points in auxiliary workshops should not exceed three (for coal transportation and ash removal, as well as water treatment), while the remaining workshops should be designed for unattended operation.\" " The number and arrangement of monitoring points should be appropriate to the process system design as well as the current level of operation and management, while also allowing for the possibility of further reducing the number of monitoring points. After thorough discussion, it was generally agreed that using coal, ash, and water as the three control points is appropriate at present. However, the systems and operation management methods in actual power plants vary widely; therefore, the aforementioned principles must not be turned into dogmas to be applied mechanically everywhere. For example, during the technical renovation of a power plant in Shanghai, the ash and slag removal systems did not have dedicated control points; instead, their controls were located in the unit control room, which created the conditions for further reducing the number of staff on duty in the future. For example, a power plant in Sichuan has a circulating fluidized bed boiler, and its coal transport system uses a single belt; as a result, this coal transport system is directly under the control of the unit control room. Another example is a power plant in Hainan, where gas turbine generators were converted into combined cycle units. Since the additional auxiliary systems were relatively simple, during the project review, it was unanimously agreed that all systems of the plant should be centralized in the unit control room, resulting in only one control point for the entire plant. 5. Plant-level monitoring and information systems: In the 1990s, significant progress was made in the automation of individual units, but the level of plant-level monitoring and management was quite backward. Therefore, in October 1997, the \"Design Principles for Power Plant Instrumentation and Control (I&C) Systems for the Year 2000\" called for an improvement in the overall level of automation and modern management across the plant, as well as the establishment of a networked system for plant monitoring and management. Plant-level monitoring and information systems include the Supervisory Information System (SIS), the Management Information System (MIS), and the Plant Bidding System (PBS); the overall structure is shown in the figure. Let’s now discuss several issues that need to be addressed in the development of plant-level monitoring and information systems: 1) The concept of plant-level monitoring information systems. In October 1997, the idea of developing SIS for thermal power plants was put forward; in January 1998, theoretical discussions on the concept and scope of SIS were conducted in light of the needs at that time. After four years of practical experience, I believe it is now possible and necessary to provide an accurate definition of SIS. What is a plant-level monitoring and control system (SIS)? I believe it can be defined as: \"A plant-level monitoring and control information system for thermal power plants is an information system for the real-time management and monitoring of production processes, designed primarily to serve the comprehensive optimization of the entire production process in such plants.\" The plant-level monitoring and control system (SIS) differs from the unit (plant) level monitoring systems (such as the DCS of a unit): a) the target audiences are different. SIS is primarily used for comprehensive optimization of the entire plant, while DCS and similar systems are used for automation at the unit (plant) level. Please note that the addition of the words \"mainly\" in the SIS definition implies that the development of SIS may involve moving certain management functions at the unit (workshop) level – such as performance calculation and analysis – to the SIS layer. b. The main functions are different. The SIS function is primarily used for managing real-time production processes, with only a small portion being used for monitoring purposes (such as real-time load scheduling). In contrast, DCS systems are mainly designed for monitoring functions, but they also include some management features (such as historical data storage). When naming, people often base it on the main function; therefore, it is called a monitoring information system at the plant level, while at the unit (workshop) level it is referred to as a monitoring system. The plant-level supervision information system (SIS) is also different from the management information system (MIS): a. Their scope of service is different. SIS falls under the category of real-time production process management and monitoring, whereas MIS belongs to the category of enterprise management modernization. b. The requirements for real-time performance are different. SIS features strong real-time capabilities. Not to mention the need for continuous monitoring of the entire production process in a plant (such as real-time load scheduling), even the management of the production process itself requires real-time handling; many issues must also be addressed on a 24/7 basis (for example, equipment status monitoring and analysis) ; Relatively speaking, MIS has lower real-time requirements; it is used for \"offline\" analysis and management, and generally does not require round-the-clock staffing. According to the concept of SIS, it can include many functions, such as monitoring of production process information, as well as statistical and analytical capabilities ; Plant-wide scheduling and optimal allocation of unit loads, as well as performance calculation and analysis at both plant and unit levels ; Device status monitoring as well as fault diagnosis and maintenance guidance functions ; Unit life management function ; Remote monitoring and technical service functions, etc. However, regarding the functions of SIS, the following points deserve attention: a) The functions of SIS are not limited to these aspects; they will continue to be expanded and improved in line with the needs of comprehensive monitoring and management of the plant’s real-time production processes, as well as through practical applications. In fact, some SIS systems developed by power plants have already introduced new functions. b. The SIS functions need to be determined based on the specific conditions of each power plant. For example, whether to implement a function for optimizing the load distribution among the generators is something that requires consideration in cases where there are only two generators of the same type in the plant, or when several generators are connected to different voltage levels, or when it is appropriate to use a \"direct control\" approach for the generators in that plant from a system perspective. c. The SIS function should be implemented in phases. Since SIS was introduced not long ago, there is a lack of experience in the development and application of its functional software modules; the technology is not yet mature, and its effectiveness remains to be evaluated. Therefore, it is not appropriate to implement all functions in every project at this stage, as this could lead to the discovery that these functions are ineffective after they are put into use, resulting in wasted project costs. As a result, major power investment companies should select a small number of power plants under their jurisdiction to serve as SIS pilot projects, equipping them with a range of advanced functions. After gaining experience from these pilots, such systems can then be rolled out on a broader scale. For ordinary power plants, it is sufficient to establish an SIS framework, a database, and a few relatively mature functional software modules for now, leaving room for future expansion and improvement. 2) Plant-level monitoring and information system networks: The development of computer network technology has provided universal and mature tools that can be utilized across various industries for \"integrated control and management\" as well as \"system integration\", enabling network interconnection throughout the plant, information sharing, and various levels of network security measures. However, for those working on the application of information technology in thermal power plants, it is necessary to study and address the core issues related to such applications. These issues vary greatly across different industries; in the case of thermal power plants, it is required to determine the network configuration for application systems, the levels of importance regarding network security, the scope of information sharing, and the information processing models, all based on the specific characteristics of management information systems, quotation decision-support systems, plant-level monitoring systems, and numerous monitoring systems at the unit (workshop) level. These are entirely new challenges that require research and development, as there are basically no existing, mature technologies that can be applied in this context. Since the proposal in October 1997 to equip large thermal power plants with plant-level monitoring information systems and management information systems, their network configuration has always been a subject of debate. There are two common approaches: Approach 1: The SIS and MIS share a single network, with security measures such as firewalls used to isolate them from each other. The advantage of this approach is that it facilitates the need for various SIS applications to access real-time data from the MIS network, while also allowing users on the MIS network to access real-time data as well. Option 2: SIS and MIS use separate networks, with information being exchanged between them through the data servers of each system. The advantage is that applications on the SIS network only need to communicate with the real-time/historical data server, while MIS applications only need to interact with the MIS relationship data server; this reduces the complexity of communication and enhances the independence and reliability of both networks. On November 9, 2001, the **Economic and Trade Commission issued the \"Interim Provisions on Network Security Protection for Computer Monitoring Systems and Dispatching Data in Power Grids and Power Plants,\" which states: \"The basic principle of security protection in power systems is that systems with a higher security level should not be affected by systems with a lower security level.\" The security level of the power monitoring system is higher than that of the power management information system and office automation systems. Each power monitoring system must be equipped with highly reliable built-in security protection mechanisms, and can only be directly connected to systems of the same security level. " "When power monitoring systems are interconnected via a network with office automation systems or other information systems, reliable, dedicated, and effective security isolation mechanisms that have been certified by **the relevant authorities** must be employed. " "To establish and improve the power dispatching data network, it is necessary to use specialized network equipment on dedicated channels to build the network, thereby ensuring secure isolation from public information networks at the physical level (such as through dedicated lines, synchronous digital sequences, and quasi-synchronous digital sequences). The power dispatching data network only allows the transmission of data services that are directly related to power dispatching operations. "Neither the power monitoring system nor the power dispatch data network shall be connected to the public Internet. " The term \"monitoring system\" as referred to in the regulations means \"grid dispatching automation systems at all levels, substation automation systems, computer monitoring systems for converter stations, computer monitoring systems for power plants, distribution network automation systems, microcomputer-based protection and safety automatic devices, water regulation automation systems and cascade dispatching automation systems for hydropower stations, electric energy metering and billing systems, auxiliary control systems for real-time electricity markets, etc.\" "A \"scheduling data network\" refers to \"special wide-area data networks for power scheduling at various levels, special dial-up networks used for remote maintenance and electricity billing, as well as local area networks within various computer monitoring systems.\" In line with the spirit of the Interim Provisions and the analysis of the concepts of SIS and MIS presented in this text, the following points should be noted: a MIS falls under the category of management information systems, and it is inevitably connected to the public Internet; its security standards are lower than those of power monitoring systems. b SIS falls within or is close to the category of “power monitoring systems”. When power plants use a “non-direct control” approach, SIS must also be connected to the “power dispatching data network”. Therefore, it cannot be “directly connected” to MIS systems with a lower security level; instead, “reliable, dedicated, and certified security isolation mechanisms provided by relevant authorities must be used”. "Given that the SIS is connected to the “power dispatch data network,” option one for interconnecting the SIS and MIS is not advisable. The nature of the c Plant Bidding System, which is an auxiliary system for bidding decisions on the power generation side, is not clearly specified in the Interim Provisions. The author believes that PBS does not fall under the category of \"power monitoring systems\"; rather, it belongs to the category of management information systems. However, due to its high importance and sensitivity, its security requirements are comparable to those of \"power monitoring systems\", and are higher than those required for ordinary MIS systems. Currently, when discussing the \"Design Guidelines for Power Plant Quotation Decision Support Systems,\" some people have proposed merging real-time scheduling and quotation decision-making into a single system that sends to the SIS: the scheduled plan, the real-time scheduling plan, the plans for auxiliary services (increasing or decreasing output or absorbing reactive power), as well as the immediate generator output commands (AGC). I hold different views on this. Although auxiliary quotation decision systems require a high level of importance and confidentiality, their security level is still clearly lower than that of security scheduling systems; the inclusion of PBS will reduce the security of the scheduling system ; Furthermore, according to the Interim Provisions, \"the power dispatching data network is only permitted to transmit data services that are directly related to power dispatching operations.\" When these two rules are combined, it inevitably results in a large amount of data that is not directly related to power dispatching operations being transmitted over the dispatching data network between the PBS and the power market trading system, thereby improperly linking the power market trading system and the secure dispatching system of the entire power grid into a single network. 3) Rational configuration of functional modules in plant-level monitoring and information systems. The subsystems included in plant-level monitoring and information systems (SIS, MIS, and BPS) often not only require the sharing of certain data but also have similar functional modules. However, in actual engineering projects, due to institutional and corporate interests, different subsystems are managed by separate departments or developed by different manufacturers, which tends to lead to isolated operations and poor communication, resulting in oversized subsystems with redundant functionality. Furthermore, even when developed by a single manufacturer, there is the issue of unified planning for the functions of the entire system. To this end, the author attempts to put forward some ideas for discussion with colleagues. a. Principles of functional configuration – Rational hierarchical allocation of functions: Function modules that are required only by a certain level of subsystem should be installed within that subsystem ; Functional modules required at both the upper and lower levels should be placed in the lower-level system. However, during development, it is necessary to fully consider the needs of the upper level in order to minimize the amount of work that needs to be done there. At the same time, functional modules that have already been implemented in the lower level should not be repeated in the upper level; otherwise, a large amount of raw data would have to be transmitted upward for processing again within those modules, leading to congestion in the data channels and waste of computer and network resources. This is especially true when different manufacturers are responsible for various subsystems; someone must carry out overall design work for unified planning and ensure coordination among them. --Simplifying and improving the reliability of the unit-level monitoring system: Before the advent of plant-level SIS, the DCS, which is the unit-level monitoring system, not only carried out tasks related to the direct monitoring of the units but also showed a trend toward expanding its management functions (including those with real-time monitoring capabilities), such as calculating unit performance, managing turbine life, storing long-term historical data, and providing operational guidance. The addition of these management functions in DCS makes it increasingly complex, and this is often a major cause of data congestion and software crashes ; Furthermore, reinstalling the same software on each unit also leads to increased costs. With the emergence of plant-level SIS, the structure of power plant automation systems must also change. In my opinion, in the future it is necessary to simplify the functions of the unit-level DCS as much as possible, focusing it on the direct monitoring of the units; management functions that do not require high real-time performance should be moved to the plant-level SIS. The DCS itself can then adopt a single-layer structure, which will inevitably simplify the direct monitoring level, improve reliability, and reduce overall investment costs. I think this should be a development direction for DCS. From this perspective, we need to properly understand the concept of integrated control. When adopting or introducing various advanced software from foreign companies, careful analysis is required, and such software should be appropriately allocated across different levels of automation systems based on its nature. b. Allocation of functional modules between MIS and BPS: The power plant bidding decision-support system needs to collect information from the power market trading center as well as data from the plant’s internal management and monitoring systems; through the calculations and analyses carried out by the bidding decision-support software, it provides recommendations for bidding decisions. Certain functional modules should be allocated appropriately between PBS and MIS. For example, tasks such as the calculation and analysis of power generation costs, fuel management, as well as maintenance planning and management require such data not only to assist in making pricing decisions externally, but also to improve internal plant management in order to meet external pricing requirements as well as internal management standards. Functional modules must be established for these calculations and analyses, and their complexity is much greater than that of the calculations used to assist in pricing decisions. Therefore, these functions should not be placed within the PBS subsystem, but rather within the MIS; the PBS can then retrieve the results of these calculations. Of course, their development, including specific functions, mathematical models, and even data formats, should all take into account the needs of internal management and external quotation decisions. This allows PBS to reduce the workload associated with secondary processing and minimize the use of databases, thereby preventing the situation where each subsystem becomes large and complex, leading to wasted resources. c. Allocation of SIS functional modules: SIS serves as an intermediate layer between the unit-level DCS and the plant-level MIS, acting as a link between the two. It is primarily focused on information management, but it also has functions for real-time monitoring. Therefore, it is generally agreed that a well-developed real-time database of appropriate scale must be established within SIS for use by the MIS. The following will present some views on how to configure certain functional modules: --Performance calculation, analysis, and operational guidance. Comprehensive performance calculation and analysis for the entire plant are essential for optimizing scheduling, and should undoubtedly be carried out within the plant-level SIS. The question is at which level it is better to carry out performance calculations and analyses at the unit level. In the past, people were accustomed to using this in DCS; I believe that once a well-structured SIS is in place in the plant, it is more reasonable to move this functionality to the SIS, as this helps at the unit level and enhances the reliability of the DCS ; Setting it at the plant level is also economically reasonable, and the real-time performance meets the requirements. --Optimal scheduling of the plant’s overall load (active and reactive power): With the implementation of the electricity market and competitive bidding for power supply, there is still disagreement regarding whether power plants should operate in a direct or indirect manner. Based on inquiries sent by the East China Institute to various power plants, most of them prefer an indirect operation mode, which makes sense given China’s circumstances. For non-directly controlled power plants, an important function of the SIS is to optimize the allocation of the unit loads across the entire plant based on safety and economic considerations. Optimizing allocation takes three factors into consideration: ① Economics – not only the economics of the generators themselves, but also the line loss associated with different power flows when the generators have different output connections. ②System stability and line congestion. ③Unit safety domain, such as defects in primary and auxiliary equipment, loss of functionality, etc. The unit safety domain calculation and analysis module can be implemented at the unit level or at the SIS level; in my opinion, it is better to implement it at the unit level. Firstly, the calculations are simpler in this case, and secondly, both the unit level, the SIS, and the PBS require data from this module, making the data flow more straightforward. Therefore, the thermal automation field should promptly study the requirements of various subsystems for the computational analysis of safety zones, in order to enable a more rational configuration of such software modules within the DCS. --Unit optimization control: Foreign companies have developed many software solutions for unit optimization control, and the offerings vary among different manufacturers. For example, optimizing combustion control or guidance, optimizing boiler purging control, new types of coordinated control, condensate throttling control, etc. Most of such modules require rapid, reliable, and direct intervention in the production process of the unit. Therefore, it is suitable for inclusion in the unit-level control system. However, for modules such as purge optimization control and combustion optimization operation guidance, where real-time requirements are not very high, they can be placed at the SIS level depending on the complexity of the software provided, in order to save resources and simplify the plant’s DCS. --Unit life management involves calculating thermal stress based on the metal temperature of unit components and its rate of change, in order to assess life degradation. During the start-up, shutdown, and load changes of the turbine, the thermal stress on its metal components changes rapidly; this is also the main control parameter for enabling ATC control of the turbine. Therefore, in foreign countries, this parameter is included in the turbine’s DEH system, rather than being moved to the SIS level. However, the life wear of various components of the unit, as well as the stress calculation and analysis of certain components that do not require real-time monitoring, should be incorporated into the SIS to save resources. --Status monitoring, fault diagnosis, and operational guidance – such functional modules often require large amounts of real-time data and/or historical data, with some demanding special fast sampling (for example, in the vibration fault analysis of turbines and rotating machinery). To achieve this function, it is often necessary to develop various advanced analysis software as well. This set of functions should be implemented at the SIS level, with dedicated workstations used for specific status monitoring and fault diagnosis tasks. The data required can be obtained from the SIS’ real-time database, or through rapid data sampling provided by the dedicated workstations themselves (for example, in turbine vibration fault diagnosis systems). 4) Issues related to PBS development: The development of PBS must be based on the establishment of SIS and MIS, but the creation of SIS and MIS is not intended solely for PBS. Therefore, before developing a PBS with complete functions, SIS and MIS should be established first. Some suggest that in cases where certain plants lack SIS and MIS, the functions and databases required for decision-making in PBS should be created within PBS itself. I believe this approach is inappropriate, as it will lead to repetition and waste when developing SIS and MIS in the future. Moreover, overall, the conditions for developing PBS are far less mature than those for SIS and MIS. Given the current uncertainty in electricity market regulations, it is impossible for PBS to be fully practical. Therefore, power plants should first establish SIS and MIS, and then develop PBS. If a region is eager to carry out pilot projects for electricity market operations, it should start with a simple PBS and improve it based on SIS and MIS once the actual rules of the electricity market are in place. Copyright © Production Technology Department of Jianbi Power Plant. Contact number: 0511-5352361