Integrated renewable energy system based on distributed intelligent network security and control architecture thereof
By employing a distributed intelligent network security architecture, combined with machine learning and data mining technologies, the network security threats and control adaptability issues of integrated renewable energy systems have been addressed, achieving efficient and stable energy management and security control.
Patent Information
- Application Number
- CN202411633338.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-15
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-11-15
AI Technical Summary
Existing integrated renewable energy systems face serious cybersecurity threats, lack security and adaptability, and rely on centralized control, resulting in poor system stability and difficulty in coping with the needs of complex scenarios and technological advancements.
The system adopts a distributed intelligent network security architecture, including a distributed adaptive access control module, a distributed intrusion detection and response module, and a control policy conflict monitoring module. It utilizes machine learning and data mining technologies to dynamically adjust network security policies, reduce dependence on central nodes, and achieve adaptive control and rapid response.
It improves system security and control adaptability, reduces the risk of single point of failure, optimizes resource utilization, enhances system flexibility and scalability, and ensures system stability and efficient operation.
Smart Images

Figure CN119652563B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of control systems, and specifically relates to an integrated renewable energy system based on distributed intelligent network security and a control architecture thereof. BACKGROUND
[0002] With the growing global demand for sustainable energy, integrated renewable energy systems (IRES) have been rapidly developing in recent years due to their ability to effectively integrate multiple renewable energy sources (such as solar, wind, and water power), achieve "cold, heat, and electricity" tri-generation, and combine "source, grid, and load" (i.e., energy supply, grid scheduling, and load management) into an efficient operation mode. This system not only helps improve energy utilization efficiency and reduce environmental pollution, but also provides a new approach to solving energy security problems.
[0003] However, as IRES systems are widely used, they face increasingly serious network security threats. Traditional network security measures are inadequate in dealing with modern cyber attacks, mainly in the following aspects:
[0004] Password cracking: attackers obtain system login credentials through brute force cracking or social engineering, thereby illegally entering the system to perform operations or steal data.
[0005] Hack attacks: using system vulnerabilities to implement denial-of-service attacks (DoS / DDoS), SQL injection, cross-site scripting (XSS), and other attacks, resulting in system crashes or data breaches.
[0006] Malware: spreading viruses, Trojans, ransomware, and other malicious software through email, download links, and other channels, damaging system files and affecting normal operation.
[0007] In addition, existing IRES systems also have the following shortcomings:
[0008] Lack of security: traditional protection mechanisms are difficult to resist advanced persistent threat (APT) attacks, and the system is vulnerable to attacks.
[0009] Poor adaptability and scalability: as technology advances and application scenarios change, the system needs to be upgraded to meet new demands, but existing architectures often lack good flexibility and scalability.
[0010] Dependence on centralized control: highly dependent on central nodes for management and scheduling, once the central node fails, the entire system may be in a chaotic state, affecting control efficiency and accuracy.
[0011] Based on this, the application provides a comprehensive renewable energy system based on distributed intelligent network security and a control architecture thereof. SUMMARY
[0012] In order to solve the above problems in the prior art, that is, the deficiencies and control limitations of the existing comprehensive renewable energy system, the poor system security and poor control adaptability, and the like, and to meet the requirements of safe and reliable adaptive control, the application provides a comprehensive renewable energy system based on distributed intelligent network security and a control architecture thereof.
[0013] In a first aspect, the application provides a comprehensive renewable energy system based on distributed intelligent network security, which comprises a distributed adaptive access control module, a distributed intrusion detection and response module, and a control strategy conflict monitoring module.
[0014] The distributed adaptive access control module distributes control tasks on each node in the network, and acquires data on each node, wherein the data at least comprises access requests, network security situations, and user behavior data, continuously learns, adapts to, and feeds back changes in user behavior patterns and network environments, and dynamically adjusts access strategies.
[0015] The distributed intrusion detection and response module distributes intrusion monitoring sensors on each network node, acquires network traffic data, mines abnormal behaviors and security threats in the network traffic data based on a data mining algorithm, and intelligently generates corresponding response strategies according to the nature of the network environment and the security threats.
[0016] The control strategy conflict monitoring module automatically discovers and solves conflicts based on the priority, applicable range, and effective time of the control strategies, and based on an online learning and feedback mechanism.
[0017] In some preferred embodiments, the distributed adaptive access control module acquires data on each node, wherein the data at least comprises:
[0018] Each sub-node acquires sensor data, request data of a user in a network access process, behavior pattern characteristics, and a network security situation according to itself.
[0019] In some preferred embodiments, the method of continuously learning, adapting to, and feeding back changes in user behavior patterns and network environments comprises a machine learning algorithm and a data analysis algorithm. In some preferred embodiments, the control access strategy at least comprises power station total parameters, primary frequency modulation, voltage control, active control, reactive control, full-power support control, fluctuation suppression control, multi-energy collaborative control, anti-overload control, power distribution, and PID control.
[0020] In some preferred embodiments, the distributed intrusion detection and response module distributes intrusion monitoring sensors on each node in the network, and the specific method is as follows:
[0021] An intrusion detection sensor is arranged on each node in the network, and network traffic data is monitored and acquired in a distributed manner through the intrusion detection sensor.
[0022] In another aspect of the present application, a control architecture of a comprehensive renewable energy system based on distributed intelligent network security is provided, which is based on a comprehensive renewable energy system based on distributed intelligent network security, comprising a perception layer, a network layer, a control layer, an application layer and a management layer.
[0023] The perception layer is used to arrange various types of signal perception devices.
[0024] The network layer is used to transmit the perception data acquired by the signal perception devices to the application layer.
[0025] The application layer is arranged with a comprehensive renewable energy system, and the control tasks of the comprehensive renewable energy system are arranged on each node of the network layer, each node monitors and controls energy data based on perception data, and the energy data at least includes energy assets, energy efficiency, energy consumption and energy planning.
[0026] The control layer is used to acquire control access strategies and issue them to field devices.
[0027] The management layer is used to provide management of resources, tasks, users and security.
[0028] In some preferred embodiments, the perception devices at least include sensors, cameras, intelligent gateways and data acquisition instruments.
[0029] In some preferred embodiments, the perception devices are connected with a first security assurance module, and the first security assurance module at least includes a hardware security assurance module, an access security assurance module and a terminal data security assurance module.
[0030] In some preferred embodiments, the network layer transmits the perception data through a transmission device, and the transmission device at least includes one or more of optical fiber, mobile communication and GPRS.
[0031] In some preferred embodiments, the transmission device is connected with a second security assurance module, and the second security assurance module at least includes a network security assurance module and a data transmission security assurance module.
[0032] The present application has the following beneficial effects:
[0033] The present application distributes network security control functions in a distributed manner on multiple nodes, each node responsible for specific network security control functions, and uses artificial intelligence, machine learning and other technologies to analyze and predict network security situation, and automatically adjust network security control strategy according to the analysis results, while supporting the access of multiple network security technologies and devices, ultimately improving the efficiency, accuracy and scalability of network security control, reducing the risk of single point failure, and reducing the workload of network security management personnel. Specifically:
[0034] Enhance system security and control adaptability: By applying distributed adaptive access control module, distributed intrusion detection and response module and control strategy conflict monitoring module, the system can effectively resist password cracking, hacker attacks and malicious software, and dynamically adjust the control strategy to adapt to various complex scenarios. Especially for advanced persistent threat (APT) attacks, the system can quickly identify abnormal behavior and take appropriate defensive measures, significantly improving the overall security of the system.
[0035] Improve adaptability and scalability: The invention adopts a distributed architecture design, making the system more flexible to adapt to different scenarios and technological progress needs. For example, when new energy types need to be added or existing energy configurations need to be adjusted, only local modifications need to be made on the corresponding nodes without the need for large-scale changes to the entire system architecture, greatly reducing system maintenance costs and complexity.
[0036] Reduce the risk of single point failure: Compared with traditional centralized control systems, the distributed intelligent network security solution proposed by the invention reduces the dependence on the central node. Even if a node fails, other nodes can continue to work, ensuring the stability and reliability of the system.
[0037] Optimize resource utilization: By combining the data obtained by the perception layer with the intelligent decision-making of the control layer, precise assessment of energy assets, optimization of energy efficiency and effective monitoring of energy consumption can be achieved, thereby promoting the rational allocation and efficient use of resources. BRIEF DESCRIPTION OF DRAWINGS
[0038] Other features, objects and advantages of the present application will become more apparent from the following detailed description of non-limiting embodiments made with reference to the accompanying drawings:
[0039] Figure 1 is a structural schematic diagram of a comprehensive renewable energy system based on distributed intelligent network security of the present application;
[0040] Figure 2 is a functional module diagram of a comprehensive renewable energy system based on distributed intelligent network security of the present application;
[0041] Figure 3 is a structural schematic diagram of a control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to the present application;
[0042] Figure 4 is a flow chart of an automatic control strategy of energy storage charging and discharging and an inverter photovoltaic power according to the present application. DETAILED DESCRIPTION
[0043] The present application will be further described below in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related application, and not to limit the application. In addition, it should be noted that only the parts related to the application are shown in the drawings for ease of description.
[0044] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and embodiments.
[0045] As shown in Figure 1 and Figure 2 , the first embodiment of the present application provides a comprehensive renewable energy system based on distributed intelligent network security, which comprises: a distributed adaptive access control module, a distributed intrusion detection and response module, and a control strategy conflict monitoring module.
[0046] The distributed adaptive access control module distributes control tasks on each node in the network and obtains data on each node, wherein the data at least includes access requests, network security situation and user behavior data, continuously learns, adapts and feeds back the changes of user behavior patterns and network environment, and dynamically adjusts the control access strategy.
[0047] The distributed intrusion detection and response module distributes intrusion monitoring sensors on each network node to obtain network traffic data, mines abnormal behaviors and security threats in the network traffic data based on data mining algorithms, and intelligently generates corresponding response strategies according to the nature of network environment and security threats.
[0048] The control strategy conflict monitoring module automatically discovers and solves conflicts based on the priority, applicable scope and effective time of the control strategy, and based on online learning and feedback mechanism.
[0049] In order to more clearly describe the comprehensive renewable energy system based on distributed intelligent network security according to the present application, the following describes each module in the embodiments of the present application in conjunction with Figure 1 and Figure 2 , and the modules are described in detail as follows:
[0050] The control task of the distributed adaptive access control module is not completed on a central controller, but is deployed in a distributed manner on each node in the network to realize localized access control decision-making, reduce decision-making delay and reduce sensitivity to single-point failures, and obtain data on each node to continuously learn, adapt, and feedback user behavior patterns and changes in the network environment to dynamically adjust the control access strategy.
[0051] In this embodiment, the distributed adaptive access control module obtains data on each network node, including at least: each sub-node according to its own sensor data, user request data during network access, behavior pattern characteristics, and network security situation.
[0052] The method of continuously learning, adapting, and feeding back user behavior patterns and changes in the network environment includes machine learning algorithms and data analysis algorithms. Specifically, machine learning algorithms can use supervised learning, unsupervised learning, or reinforcement learning techniques to train models to identify differences between legitimate access and malicious behavior. For example, random forests or support vector machines (SVM) can be used to classify user behavior.
[0053] Data analysis algorithms can use statistical analysis, clustering analysis, and other methods to process large amounts of raw data, extract valuable information, and help optimize access control decisions.
[0054] The control access strategy includes at least power station total parameters, primary frequency modulation, voltage control, active power control, reactive power control, full power support control, fluctuation suppression control, multi-energy collaborative control, anti-overload control, power distribution, and PID control.
[0055] In this embodiment, the sensors can be physical or environmental sensors (such as temperature, humidity, light intensity, etc.) installed on each node to collect data for evaluating the working state of the equipment and environmental conditions.
[0056] User request data in this embodiment can be all requests generated when users interact with the system, including but not limited to login attempts, operation instructions, etc., to analyze user behavior patterns.
[0057] Behavior pattern characteristics are identified through learning of historical data to identify normal user behavior and potential attacker activity patterns.
[0058] The network security situation can be continuous monitoring of the overall health of the network, including but not limited to network connection status, abnormal traffic detection, etc.
[0059] In this embodiment, the specific implementation steps of the distributed adaptive access control module are as follows:
[0060] Step S1, initialization phase: define initial security policy and control parameters, establish basic access rules.
[0061] Step S2, data collection: start data collection tasks on each node, ensure data integrity and accuracy.
[0062] Step S3, model training: use collected data to train machine learning model, continuously optimize model accuracy.
[0063] Step S4, policy generation: dynamically generate or adjust access control policy based on model prediction results and real-time data analysis.
[0064] Step S5, execution and feedback: apply updated control policy to the system, and collect execution effect as the basis for subsequent optimization.
[0065] Through the above process, the distributed adaptive access control module can effectively protect the integrated renewable energy system from illegal access, while ensuring the efficient operation of the system.
[0066] The distributed intrusion detection and response module, on each network node, distributes intrusion monitoring sensors for obtaining network traffic data, based on data mining algorithms, mines abnormal behaviors and security threats in the network traffic data, and intelligently generates corresponding response strategies according to the nature of the network environment and security threats.
[0067] The distributed intrusion detection and response module in this embodiment takes into account that traditional intrusion detection systems are usually analyzed by security experts to analyze attack behavior, summarize attack characteristics, and then establish intrusion detection rules through complex manual coding for identifying intrusions. In addition, intruders can also train the intrusion detection system, so that behaviors initially considered abnormal are considered normal after a period of training. Therefore, this paper deploys intrusion detection sensors on each node in the network and monitors network traffic data in a distributed manner, introduces data mining technology into intrusion detection, mines normal and intrusion behavior patterns from a large number of audit records, and automatically generates rules to identify abnormal behaviors and security threats. In addition, according to the nature of the network environment and security threats, intelligent selection of appropriate response measures can effectively deal with security threats.
[0068] Among them, the intrusion detection sensor is mainly used to capture all network traffic data passing through the node, including but not limited to packet header information, packet payload content, etc. The captured raw traffic data is converted into a format suitable for analysis, facilitating subsequent data mining processing.
[0069] The data mining algorithm, which can adopt, in this embodiment, association rule learning, cluster analysis, classification algorithm, etc., extracts useful features such as access frequency, packet size distribution, etc. from a large amount of network traffic data, identifies new potential threats by comparing known normal behavior and intrusion behavior patterns, automatically generates intrusion detection rules according to the mined behavior patterns, and continuously updates and optimizes the rule base.
[0070] The corresponding response strategy in this embodiment is generated, specifically:
[0071] The network environment is continuously monitored for changes, including network topology, traffic patterns, etc.; the security threat level is evaluated according to the severity and impact of the detected intrusion behavior; the most appropriate response strategy is intelligently selected based on the threat evaluation results, such as disconnecting, limiting access permissions, triggering alarms, etc.; and the selected response strategy is applied to the affected nodes or the entire network to mitigate or eliminate the threat.
[0072] This embodiment can automatically generate and adjust intrusion detection rules according to changes in the network environment, improving the flexibility and adaptability of the system. Using data mining technology to automatically identify intrusion behavior reduces the need for human intervention and improves detection efficiency. Each node works independently and collaborates with each other, enhancing the robustness and scalability of the system. It can intelligently select response strategies based on real-time threat conditions to ensure the security and stability of the system.
[0073] The control strategy conflict monitoring module automatically discovers and resolves conflicts based on the priority, scope of application and effective time of the control strategy, and based on online learning and feedback mechanisms.
[0074] The control strategy conflict monitoring module in the application can store all defined control strategies, including but not limited to power plant total parameter control, primary frequency modulation, voltage control, active power control, reactive power control, full power support control, fluctuation suppression control, multi-energy collaborative control, anti-overload control, power distribution and PID control, etc. The priority, scope of application and effective time of each strategy are recorded, and an efficient indexing mechanism is established to facilitate quick searching and matching of related strategies.
[0075] The control strategy conflict monitoring module in this embodiment is used to continuously monitor the execution of control strategies by each node in the system and collect real-time data. By comparing the priority, scope of application and effective time of different strategies, potential conflict points are detected. Different types of conflicts are identified, such as priority conflicts, time window overlaps, resource competition, etc.
[0076] The strategy of the control strategy conflict monitoring module is specifically:
[0077] The conflicting policies are sorted according to their priorities, and the policies with high priorities are executed first. For the policies with overlapping time windows, their effective times are adjusted to ensure that they do not interfere with each other. In the case of limited resources, the resources are allocated reasonably to avoid conflicts caused by resource competition. For the policies that can be combined, new comprehensive policies are generated to simplify the control logic.
[0078] The control policy conflict monitoring module in this embodiment also includes a self-learning and adaptation function. Specifically:
[0079] Various data generated during system operation are collected, including control policy execution results and system performance indicators.
[0080] Machine learning algorithms such as decision trees and neural networks are used to train conflict detection and resolution models to improve their accuracy and robustness.
[0081] Based on the model prediction results and actual execution effects, the conflict detection and resolution strategies are dynamically adjusted to form a closed-loop feedback mechanism.
[0082] The control policy conflict monitoring module in this embodiment automatically discovers potential control policy conflicts through real-time monitoring and intelligent analysis, reducing human intervention. Combined with online learning and feedback mechanisms, the conflict resolution strategies are dynamically adjusted to improve the system's adaptive ability. This ensures that all control policies work in harmony and avoids system instability or failure caused by policy conflicts. Through a closed-loop feedback mechanism, the conflict detection and resolution models are continuously optimized to improve the overall performance and reliability of the system.
[0083] It should be noted that the comprehensive renewable energy system based on distributed intelligent network security provided in the above embodiments is only used as an example for the division of the above functional modules. In actual applications, the above functions can be completed by different functional modules as needed, i.e., the modules or steps in the embodiments of the present application can be further decomposed or combined to complete all or part of the functions described above. The names of the modules and steps involved in the embodiments of the present application are only used to distinguish the modules and steps, and should not be considered as an improper limitation of the present application.
[0084] In order to overcome the control limitations of the comprehensive renewable energy system, improve the adaptability, safety and accuracy of system control, and make up for the low control efficiency of existing comprehensive renewable energy systems, accurately and quickly guide the control process of the comprehensive renewable energy system, a control architecture for a comprehensive renewable energy system based on distributed intelligent network security is proposed. This framework is scalable and highly secure.
[0085] As Figure 3As shown, the second embodiment of the present application proposes a control architecture of an integrated renewable energy system based on distributed intelligent network security, based on an integrated renewable energy system based on distributed intelligent network security, comprising a perception layer, a network layer, a control layer, an application layer and a management layer;
[0086] The perception layer is used to arrange a plurality of types of signal perception devices;
[0087] The network layer is used to transmit the perception data obtained by the signal perception device to the application layer;
[0088] The application layer is arranged with an integrated renewable energy system, and the control task of the integrated renewable energy system is arranged on each node of the network layer, and each node monitors and controls energy data based on perception data, wherein the energy data at least includes energy assets, energy efficiency, energy consumption and energy planning;
[0089] The control layer is used to obtain control access strategies and issue them to field devices;
[0090] The management layer is used to provide management of resources, tasks, users and security.
[0091] Among them, the perception device at least includes a sensor, a camera, an intelligent gateway and a data acquisition instrument. The perception device is connected with a first security assurance module, and the first security assurance module at least includes a hardware security assurance module, an access security assurance module and a terminal data security assurance module.
[0092] In this embodiment, the sensor can be used to measure temperature, humidity, light intensity and various physical quantities. The camera can be used for video monitoring and image acquisition.
[0093] The intelligent gateway serves as a communication hub to realize interconnection and intercommunication between different types of devices.
[0094] The data acquisition instrument is used to collect and preliminarily process data from a plurality of sensors.
[0095] These perception devices interact with other hierarchical devices through different communication protocols (such as MQTT, HTTP, etc.).
[0096] In order to ensure the security and integrity of the perception data in this embodiment, the perception device needs to be connected with the first security assurance module. The first security assurance module includes the following sub-modules:
[0097] Hardware security assurance module: ensure the physical security of the perception device itself, prevent unauthorized access and damage.
[0098] In this embodiment, the hardware security module can select device anti-theft device, waterproof device, anti-interference device and encryption device. Specifically,
[0099] For the device anti-theft device, a miniature GPS receiver is embedded in the device, allowing the device to report its current location. If the device leaves the preset safe area, it will automatically send an alarm to the monitoring center.
[0100] Each device can also be equipped with a unique RFID tag, which can detect the presence and status of the device when it passes through a specific reading point.
[0101] Integrated sound or light alarm activated when abnormal movement is detected to attract attention.
[0102] For the waterproof device, a shell material that meets the IP67 and above standards can be selected to ensure that the device can still work normally when briefly immersed in water. Waterproof rubber rings or silicone sealing strips are used at all interfaces to ensure good sealing effect. Drainage holes are appropriately set without affecting waterproofness to prevent internal water accumulation.
[0103] For the anti-interference device, a metal shield can be used to cover electronic components to reduce the impact of external electromagnetic waves. EMI / RFI filters are installed on power lines and signal lines to filter out unnecessary noise. Techniques such as opto-isolation or transformer isolation are used to further enhance anti-interference capability.
[0104] For the encryption device, strong encryption algorithms such as AES-256 can be used to encrypt transmitted data to ensure that even if the data is intercepted, it cannot be read. Strict key management procedures are implemented, including key generation, distribution, storage and update, to ensure the security of the key. A two-way authentication mechanism is used to ensure that both the sender and receiver of the data are legitimate entities that have been verified.
[0105] Access security module: through the identity authentication and authorization of the device, it is ensured that only legal devices can access the network.
[0106] The access security module in this embodiment includes a mandatory authentication module, an intrusion prevention module, an encrypted communication module and an abnormal alarm module. Specifically:
[0107] The mandatory authentication module can use digital certificates or pre-shared keys (PSK) to authenticate the identity of the device. Each device needs to provide valid identification when first connected. It can also combine device hardware feature codes, MAC addresses and other factors for authentication to increase the reliability of authentication. One-time passwords (OTP) or time-synchronized dynamic passwords (such as TOTP) can also be used to generate new passwords each time the device connects, ensuring the security of the password.
[0108] Intrusion prevention module can deploy firewalls at network boundaries, configure rules to limit unauthorized access requests, and only allow necessary communication traffic to pass through. It can also deploy intrusion detection systems based on signature and behavior analysis to monitor network traffic in real time, detect abnormal behavior, and issue alerts.
[0109] Encrypted communication module can use TLS / SSL protocol to encrypt transmitted data, ensuring data security during transmission. It can also establish an end-to-end encrypted channel between devices and servers, using symmetric encryption algorithms such as AES-256 to encrypt data.
[0110] Abnormal alarm module can use network monitoring tools to monitor network traffic and device status in real time, detect abnormal behavior. It can also set thresholds for key indicators such as bandwidth usage, login attempts, etc., and trigger alarms when thresholds are exceeded. It can also configure automated scripts or tools to automatically perform predefined operations such as disconnecting, logging, etc. when detecting abnormalities.
[0111] Terminal data security protection module: protect the security of perception data during transmission, such as using encryption technology to prevent data from being stolen or tampered with.
[0112] In this embodiment, the terminal data security protection module includes a data encryption module, a data leakage prevention module, a data copy prevention module, and a white list and black list setting module.
[0113] For the data encryption module, encryption can be performed using keys.
[0114] For the data leakage prevention module, data can be classified and labeled to distinguish between sensitive data and non-sensitive data, ensuring that sensitive data is strictly protected. Fine-grained access control policies can also be implemented to ensure that only authorized users and applications can access sensitive data.
[0115] For the data copy prevention module, file and directory permissions can be set to prohibit unauthorized users from copying or modifying data. Invisible watermarks can also be embedded in sensitive data to trace the source after data leakage.
[0116] White list and black list setting module:
[0117] White list management: maintain a list of trusted applications and users, only applications and users listed in the white list can access sensitive data.
[0118] Black list management: maintain a list of untrusted applications and users, prohibit applications and users listed in the black list from accessing data.
[0119] Dynamic updates: Regularly update the whitelist and blacklist to ensure the latest security policies are effectively implemented.
[0120] The perception layer captures various changes in the surrounding environment in real-time through built-in sensors or other sensing elements, and converts these data into electrical or digital signals. These signals are then transmitted to the smart gateway or other intermediate devices through wireless or wired communication, and finally aggregated to the data acquisition instrument. The data acquisition instrument performs preliminary processing on the collected data, such as denoising and filtering, and then transmits it to the application layer through the network layer.
[0121] Throughout the process, the first security module monitors the flow of data to ensure safe transmission. The hardware security module regularly checks the status of the perception device, detects and fixes potential security risks in a timely manner. The access security module performs identity verification when the device accesses the network to prevent illegal devices from accessing the network. The terminal data security module uses encryption technology during data transmission to ensure that data cannot be intercepted or tampered with by third parties.
[0122] The application scenarios of the perception layer are very wide, especially in integrated renewable energy systems, it can be used to monitor the working status of key facilities such as wind power plants, solar photovoltaic panels, energy storage devices, and changes in the surrounding environmental conditions. By collecting and analyzing these data in real-time, the system can more accurately predict and regulate energy production and consumption, thereby improving energy utilization efficiency and reducing energy costs.
[0123] The perception layer is the foundation of the integrated renewable energy system, which realizes comprehensive perception and data collection of the physical world by deploying various types of signal perception devices, laying a solid foundation for subsequent data processing and analysis. At the same time, with the protection of the first security module, the security and integrity of the perception data are ensured, providing important protection for the stable operation of the system.
[0124] The network layer in this embodiment transmits perception data through a transmission device, which includes at least one or more of optical fiber, mobile communication, and GPRS.
[0125] The transmission device is connected with the second security module, which includes at least a network security module and a data transmission security module.
[0126] Among them, the optical fiber can provide high-speed and high-bandwidth data transmission, suitable for long-distance and large-capacity data transmission requirements.
[0127] The mobile communication includes 4G, 5G, WIFI and other mobile communication technologies, suitable for data transmission of mobile devices and remote nodes.
[0128] The GPRS general packet radio service technology is suitable for low-speed and low-cost data transmission requirements.
[0129] These transmission devices can be flexibly selected and combined according to actual application scenarios and requirements.
[0130] Among them, the network security guarantee module in the embodiment includes a network security isolation module, a device access authentication module, and a network attack early warning module. Specifically:
[0131] The network security isolation module can be set up in the form of a firewall.
[0132] The device access authentication module can use digital certificate authentication or MAC address binding.
[0133] The network attack early warning module can deploy an IDS based on signature and behavior analysis to monitor network traffic in real time, detect abnormal behavior, and issue an alarm. It can also automatically take measures to block the attack source when intrusion behavior is detected, protecting the network from intrusion.
[0134] In the embodiment, the data transmission security guarantee module includes a data transmission encryption module, a data backup and recovery module, a data breakpoint resume transmission module, and a data integrity protection module. Specifically:
[0135] The data transmission encryption module can also be encrypted by key.
[0136] The data backup and recovery module can back up important data to a secure storage device or cloud regularly. It can also perform incremental backup based on full backup to reduce backup time and storage space.
[0137] The data breakpoint resume transmission module is used to ensure that data transmission can continue in the event of network interruption or failure, preventing data loss. This can be achieved in the following ways:
[0138] Breakpoint recording: During data transmission, record the location and status of the transmitted data.
[0139] Re-transmission mechanism: After network interruption, automatically start transmission from the breakpoint position to avoid repeated transmission of successfully transmitted data.
[0140] Timeout retry: Set a reasonable timeout, and if no confirmation information is received within the specified time, automatically retry the transmission.
[0141] The data integrity protection module can be checked by hash, digital signature, etc.
[0142] The application layer in this invention also includes an application security module, which is used for business permission management, access authentication, and application detection. Specifically:
[0143] Business access control ensures that users can only access the business functions they are authorized to, preventing unauthorized operations. It defines different roles based on business needs, such as administrators, operators, and auditors. Each role is assigned corresponding permissions, such as viewing data, modifying settings, and performing operations. Permission inheritance between roles is supported, simplifying access control management. User permissions are dynamically adjusted according to business changes, ensuring timeliness and accuracy.
[0144] Access authentication is used to ensure that only authorized users can access the system, preventing unauthorized access.
[0145] Application detection is used to monitor the running status of applications in real time, detect and handle potential security threats.
[0146] like Figure 4 As shown, based on the content of the first and second embodiments, the third embodiment of the present invention proposes an automatic control strategy for energy storage charging and discharging and inverter photovoltaic power, such as... Figure 4 As shown, the magnitude of renewable energy generation power (Pv) and load power (PI) is determined every minute: When Pv > PI, ① the percentage of remaining energy storage battery capacity (SOC) is ≥ 97% or = 0. If the reverse power is > 55kW, photovoltaic power control is initiated; if the reverse power is < 50kW, the power limiting is lifted and the system is connected to the grid normally. ② If SOC < 97%, the energy storage system is charged. When Pv ≤ PI, ① if SOC ≤ 10% or = 0, and if the forward power is ≤ 55kW, normal grid connection is sufficient; if the normal power is greater than 55kW, controllable loads are disconnected. ② If SOC > 10%, the energy storage system is discharged.
[0147] The terms “first”, “second”, etc., are used to distinguish similar objects, not to describe or indicate a specific order or sequence.
[0148] The term "comprising" or any other similar term is intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus / device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent in such process, method, article, or apparatus / device.
[0149] The technical scheme of the present application has been described in combination with the preferred embodiments shown in the drawings, but it is easy for those skilled in the art to understand that the protection scope of the present application is obviously not limited to these specific embodiments. Those skilled in the art can make equivalent changes or replacements to the related technical features without departing from the principles of the present application, and the technical schemes after the changes or replacements will all fall within the protection scope of the present application.
Claims
1. A control architecture for a comprehensive renewable energy system based on distributed intelligent network security, characterized in that, The control architecture includes: The layers are: perception layer, network layer, control layer, application layer, and management layer. The sensing layer is used to deploy various types of signal sensing devices; The network layer is used to transmit the sensed data acquired by the signal sensing device to the application layer; An integrated renewable energy system is deployed within the application layer. The control tasks of the integrated renewable energy system are deployed on each node of the network layer. Each node monitors and controls energy data based on sensing data. The energy data includes at least energy assets, energy efficiency, energy consumption, and energy planning. The control layer is used to acquire control access policies and distribute them to field devices; The management layer is used to provide management of resources, tasks, users, and security; The integrated renewable energy system includes: a distributed adaptive access control module, a distributed intrusion detection and response module, and a control policy conflict monitoring module; The distributed adaptive access control module distributes control tasks across each node in the network and acquires data from each node. The data includes at least access requests, network security status, and user behavior data. It continuously learns, adapts to, and provides feedback on changes in user behavior patterns and the network environment, and dynamically adjusts the access control strategy. The distributed intrusion detection and response module deploys intrusion monitoring sensors on various network nodes to acquire network traffic data. Based on data mining algorithms, it identifies abnormal behaviors and security threats in the network traffic data and intelligently generates corresponding response strategies according to the network environment and the nature of the security threats. The control strategy conflict monitoring module automatically detects and resolves conflicts based on the priority, scope of application, and effective time of the control strategy, and based on an online learning and feedback mechanism.
2. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 1, characterized in that, The distributed adaptive access control module acquires data from each node, and the data includes at least: Each child node is based on its own sensor data, user request data during network access, behavioral patterns, and network security status.
3. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 1, characterized in that, The methods for continuously learning, adapting to, and responding to changes in user behavior patterns and the network environment include machine learning algorithms and data analysis algorithms.
4. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 1, characterized in that, The control access strategy includes at least the power plant's total parameters, primary frequency regulation, voltage control, active power control, reactive power control, full power support control, fluctuation smoothing control, multi-energy coordinated control, over-generation prevention control, power distribution, and PID control.
5. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 1, characterized in that, The distributed intrusion detection and response module distributes intrusion detection sensors across each node in the network, specifically as follows: An intrusion detection sensor is deployed at each node in the network to monitor and acquire network traffic data in a distributed manner.
6. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 1, characterized in that, The sensing device includes at least sensors, cameras, smart gateways, and data acquisition devices.
7. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 6, characterized in that, The sensing device is connected to the first security module, which includes at least a hardware security module, an access security module, and a terminal data security module.
8. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 1, characterized in that, The network layer transmits sensing data through a transmission device, which includes at least one or more of optical fiber, mobile communication, and GPRS.
9. The control architecture of a comprehensive renewable energy system based on distributed intelligent network security according to claim 8, characterized in that, The transmission device is connected to a second security module, which includes at least a network security module and a data transmission security module.
Citation Information
Patent Citations
Cloud master station security protection system, method and device and storage medium
CN117834195A
Information network virus intrusion detection system and method based on ad hoc network
CN118118224A