Data security protection method for photovoltaic power station under smart grid environment
By using attack tree models and blockchain technology to identify data risks in photovoltaic power stations, generate unique digital identities and implement access control, and build multi-level cryptographic security protection, the data security issues of photovoltaic power stations are resolved, the security and integrity of the data are achieved, and the stable operation of the power system is ensured.
Patent Information
- Application Number
- CN202411869089.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-12-18
AI Technical Summary
In the smart grid environment, the data security of photovoltaic power stations faces the risk of information leakage and malicious attacks. Existing technologies are difficult to effectively protect the data security of photovoltaic power stations, especially during data transmission, storage and processing.
Use attack tree models and threat models to identify risks, use blockchain technology to generate unique digital identities and implement access control, build multi-level cryptographic security protection, use white box encryption algorithms and domestic cryptographic technology to encrypt storage and transmission data, design a power system architecture compatible with multiple new energy access, and implement backup energy scheduling and smart meter measurement cryptographic security protection.
It ensures the security and integrity of photovoltaic power station data, prevents data leakage and tampering, ensures the stable operation of the power system, and improves data processing efficiency and security.
Smart Images

Figure CN119696899B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent water supply equipment inspection, and in particular to a data security protection method for a photovoltaic power station in a smart grid environment. Background Art
[0002] With the widespread adoption and in-depth application of renewable energy, the power system is becoming more complex than ever before. This change is accompanied by a sharp increase in the demand for information security and data protection in various business scenarios. In particular, photovoltaic power stations, as a key link in the access of renewable energy, generate huge amounts of data, placing higher demands on the data processing capabilities of the power system. At this stage: the implementation of time-of-use electricity pricing strategies, dedicated transformer intelligent cost control and other refined management business scenarios require not only the efficient processing of large amounts of data, but also the security and integrity of this data during transmission, storage and processing to prevent any form of information leakage or malicious attacks. Therefore, data security protection of photovoltaic power stations has become a key link in the safe and stable operation of the power system. Summary of the Invention
[0003] In order to solve the above technical problems, the present invention is implemented through the following technical solutions: a data security protection method for a photovoltaic power station in a smart grid environment, comprising the following steps;
[0004] Step 1: Use attack tree models and threat models to identify and assess data security risks in PV power plants and evaluate the risk level. Simultaneously, based on blockchain technology, generate unique digital identities for PV power plant equipment and their business scenarios, and implement access control. Digital identities are managed and authenticated using encrypted public-private key pairs.
[0005] Step 2: Build multi-level cryptographic security protection, load and execute white-box encryption algorithms in the Trusted Execution Environment (TEE) to process key data and core algorithms; use domestic cryptographic technology and security monitoring technology to encrypt the storage and transmission of key data to enhance data security;
[0006] Step 3: Design a power system architecture compatible with multiple renewable energy sources: Leverage real-time data collection and analysis, using long-short-term memory (LSTM) and boosting tree models, to predict renewable energy generation and system load demand. Based on these predictions, implement backup energy scheduling, including using advanced scheduling algorithms to automatically optimize energy distribution. Renewable energy sources include photovoltaics, wind power, and energy storage. Backup energy scheduling is used to adapt to power demand and maintain system stability.
[0007] Step 4: Build a smart meter password security protection subsystem: Use high-strength password security strategies to generate and manage secure passwords to protect meter data; perform encryption authentication and security monitoring on new energy access, time-of-use electricity price parameters, and dedicated transformer smart fee control to ensure the security of key business data throughout its life cycle; the password security strategy includes the use of secure hash algorithms and symmetric encryption technology to generate, store, and transmit passwords, and implement customized encryption authentication and access control strategies for key business scenarios to ensure data integrity and confidentiality.
[0008] Preferably, the process of assessing the risk level is as follows: clarifying the equipment operation data, power generation data, business process-related data, and user and operation and maintenance personnel-related authority data involved in the photovoltaic power station, and at the same time sorting out the basic information of the corresponding business scenarios and equipment connection status to obtain the scope of data asset assessment; collecting historical data from the monitoring system, energy management system, and billing system of the photovoltaic power station, and collecting data on data security case studies that have occurred in photovoltaic power stations in the industry to obtain photovoltaic power station-related data; among which, historical data includes records of abnormal events that have occurred in the past, equipment failure data, and network access logs; taking the ultimate goal of threatening the data security of the photovoltaic power station as the root node, and then gradually decomposing the various means and conditions for achieving the ultimate goal as child nodes, constructing a complete attack tree structure, and clearly showing possible attack paths; among which, the ultimate goal includes data leakage and data tampering;
[0009] For the leaf nodes of the attack tree, which represent the most basic attack methods at the bottom layer, we assign an initial attack success probability value to each leaf node by combining existing security research data, historical statistics, and the experience and judgment of professionals. We then calculate the probability from the bottom up: using probability calculation rules, we start from the leaf nodes and gradually calculate the attack success probability for each intermediate node and the final root node.
[0010] Based on the internal and external environmental conditions of the PV power station, potential threat sources are analyzed and the potential threatening behaviors they may carry out are determined. Threat sources include external hacker groups, internal malicious employees, and natural environmental factors. Natural environmental factors include lightning strikes that may affect equipment and thus threaten data security. Threat behaviors include cyberattacks by hackers and illegal data access by employees. Based on threat behaviors, combined with statistical data from past power station incidents and the current protective measures taken by the power station, the likelihood of threatening behaviors occurring is assessed to determine the threat probability. The impact of threatening behaviors on the data security of the PV power station, if any, is analyzed. The threat probability is categorized into three levels: high, medium, and low.
[0011] Using the risk matrix method, a matrix is constructed with the threat possibility as the horizontal axis and the impact degree as the vertical axis. Different intervals correspond to different risk levels. According to the threat possibility and impact degree of the threatening behavior, the risk level corresponding to each threat is determined, including high threat possibility and high impact degree corresponding to high risk level. The root node attack success probability and the risk level corresponding to each threat in the threat model are summarized and integrated. According to the pre-set weight distribution principle, the integrated risk-related indicators are weighted and calculated to finally determine the overall risk level of photovoltaic power station data security. The risk level is divided into high, medium and low risk levels, which can intuitively reflect the severity of the current data security and provide a basis for the subsequent formulation of targeted protection strategies. Among them, the weight distribution principle is: if the technical level risk reflected by the attack tree model is considered to be more critical, it can be given a higher weight; the actual threat situation reflected by the threat model has a slightly lower weight.
[0012] Preferably, the process of generating a unique digital identity is as follows: establishing a blockchain network infrastructure applicable to the photovoltaic power station, determining the node types in the network, which include device nodes, business server nodes, and management nodes, wherein the device nodes include photovoltaic panel controller nodes, inverter nodes, and electricity meter nodes; the business server nodes are responsible for energy scheduling and billing business processing; the management nodes are used to configure and monitor the entire blockchain network; configuring the basic parameters of the blockchain network, and generating a unique digital identity DID for each photovoltaic power station device and business scenario using a hash algorithm; the hash algorithm has anti-collision and unidirectional properties, ensuring that each identity is unique and difficult to forge;
[0013] The generated digital identity and the corresponding photovoltaic power station equipment or business scenario detailed information are registered on the blockchain to form an unalterable digital identity record; at the same time, an encrypted public-private key pair is generated for each digital identity. The public key is published on the blockchain as the basis for identity verification, and the private key is securely stored by the corresponding device or business system for subsequent digital signature encryption operations to prove its own identity.
[0014] Optimally, the process of implementing access control is as follows: analyzing the operational requirements of different devices and business scenarios in the photovoltaic power station, and determining different role types, including operation and maintenance administrator role, general operation and maintenance personnel role, and energy dispatching system role. Operation and maintenance administrator role: can configure and monitor the equipment, view and modify business data; general operation and maintenance personnel role: can only view the equipment status and some business data; energy dispatching system role: can perform energy allocation operations according to power generation and power consumption; for each role, define its access rights in different devices and business scenarios, including that the operation and maintenance administrator role can start and stop all devices and access all business data, while Ordinary operation and maintenance personnel can only read the power generation data of photovoltaic panels. These access control policies are written in the form of smart contracts and deployed to the blockchain network. Smart contracts are automatically executed on the blockchain to ensure the transparency and tamper-proof nature of the access control policies. Devices or users initiate access requests: When device A or a user needs to access device B or business system resources, they first generate an access request message containing their own digital identity (DID), information about the target resource to be accessed, and detailed information about the access request. The target resource information includes the DID of the target device or the interface address of the business system. The access request details include the type of operation requested, whether to read or modify data.
[0015] Use its own private key to digitally sign the access request message to prove the authenticity and integrity of the request, and then send the signed access request to the blockchain network; the blockchain network verifies the access request: after receiving the access request, the node in the blockchain network first verifies the validity of the digital signature and uses the public key of the requester to decrypt and verify the signature. If the verification fails, the access request is directly rejected because this may mean that the request has been tampered with or comes from an illegal requester; after the signature is successfully verified, check whether the role corresponding to the digital identity of the requester has access rights to the target resource according to the access control smart contract; authorize access and resource interaction: if the access request passes the digital signature verification and permission check, the blockchain network sends an authorization notification to the target device or business system, allowing the requester to perform the access operation.
[0016] Preferably, the implementation of access control also includes: during the entire access process, the blockchain network continuously monitors access behavior, records the time of access and the content of the operation in the log on the blockchain for subsequent auditing and tracking; if abnormal behavior is found during the access process, the blockchain network will automatically trigger the corresponding security mechanism, including temporarily freezing access rights and issuing alarm notifications; when the business needs of the photovoltaic power station change, the authorized administrator initiates a permission change request through the management interface; the permission change request is submitted to the blockchain network after verification by the administrator's digital identity signature; the smart contract in the blockchain network updates the access permission settings of the corresponding role in different devices and business scenarios according to the content of the permission change request, and broadcasts the updated permission information to the entire blockchain network.
[0017] Preferably, the attack tree model evaluation includes calculating the attack success probability of the leaf nodes to identify key security vulnerabilities and optimizing the security configuration of the system accordingly. The process of identifying key security vulnerabilities is as follows:
[0018] Construct an attack tree model: First, define the target and clarify the goal of data security protection for the photovoltaic power station, using the target as the root node of the attack tree; then decompose the attack path, starting from the root node, and analyze all possible ways that the security target may be compromised; continue to decompose each intermediate node until the most basic attack method is decomposed, that is, the leaf node; sort out the asset list and sort out the assets of the photovoltaic power station; clarify the importance and sensitivity of each asset, and record each asset's location, access method, and the business processes involved; evaluate existing security measures and collect information on existing security measures in the photovoltaic power station, including network firewall rule settings, intrusion detection / prevention system (IDS / IPS) configuration, access control policies, and the use of encryption algorithms; analyze the protection level of existing security measures for different assets; and identify weaknesses in existing security measures.
[0019] Collect historical security incidents and vulnerability information, including records of past security incidents at the PV power plant itself, including the type of incident, the resulting losses, the incident handling process, and the results. Obtain information on security incidents and vulnerabilities occurring in PV power plants or energy systems within the industry through security information websites, industry reports, and vulnerability notices issued by security vendors. Analyze the correlation between these historical incidents and vulnerability information and the assets and security measures of the power plant to identify areas within the power plant that may have similar risks. Calculate the probability of successful attacks on leaf nodes, first assigning a basic probability: For each leaf node in the attack tree, assign an initial probability of successful attack based on existing information, historical data, and expert experience.
[0020] According to the logical relationship between the leaf nodes and the intermediate nodes and the root nodes in the attack tree, the calculation method of the attack success probability is determined; under the logical and relationship, the success probability of the upper node is the product of the success probabilities of each lower node; under the logical or relationship, the success probability of the upper node is equal to 1 minus the product of the unsuccessful probabilities of each lower node; identify the key security vulnerabilities: first, set a threshold value according to the risk tolerance of the photovoltaic power station to data security, and set a threshold value of the attack success probability; then identify and screen the vulnerabilities: starting from the root node of the attack tree, according to the calculated attack success probability, screen out the paths with a probability exceeding the threshold value; finally, verify and confirm the vulnerabilities: for the key security vulnerabilities identified initially, verify them through vulnerability scanning tools and penetration testing to obtain clear key security vulnerabilities.
[0021] Preferably, the process of optimizing the security configuration of the system is as follows: according to the key security vulnerabilities identified in the attack tree model, classify them according to the type of vulnerabilities; divide them into four categories: network protocol vulnerabilities, operating system vulnerabilities, application program vulnerabilities and physical security vulnerabilities; network protocol vulnerabilities include TCP / IP protocol stack related vulnerabilities, operating system vulnerabilities include unpatched vulnerabilities in the operating system of photovoltaic power station servers or devices, application program vulnerabilities include vulnerabilities in energy management software and monitoring software, and physical security vulnerabilities include insufficient protection of device physical access points; for each category, record in detail the devices, business scenarios and possible security risk consequences involved by the vulnerabilities, which include data leakage, system paralysis and reduced power generation efficiency; according to the calculated leaf node attack success probability and the possible impact of the vulnerabilities, determine the priority of the security vulnerabilities; use a quantitative risk assessment matrix method to divide the attack success probability into high, medium and low levels, and divide the impact degree into serious, relatively serious and general levels; for high-priority security vulnerabilities related to network protocol vulnerabilities, adjust the firewall rules; implement intrusion detection / prevention system IDS / IPS optimization; configure the rules of IDS / IPS according to the characteristics of the vulnerabilities; use virtual private network VPN technology to enhance network communication security; use VPN for encrypted communication between different areas (such as power generation area and control area) in the photovoltaic power station or when remotely accessing, to prevent network sniffing and man-in-the-middle attacks;
[0022] For operating system vulnerabilities, security patches are updated in a timely manner, and an automated patch management system is established to ensure that the operating systems of all devices in the photovoltaic power station obtain and install the latest security patches in a timely manner to reduce the risk of attacks; for application vulnerabilities, code reviews and software updates are conducted; the development team conducts code reviews on energy management and data monitoring applications, fixes discovered security vulnerabilities, and upgrades the software version; at the same time, during the software deployment process, minimize software permissions to avoid security risks caused by software running with excessive permissions; implement access control policy optimization; adjust user and device access rights based on vulnerability conditions; for physical security vulnerabilities, strengthen equipment physical protection; set up guardrails and access control systems around key equipment in the photovoltaic power station to limit physical contact by unauthorized personnel; install surveillance cameras and alarm systems; install video surveillance equipment in equipment areas and key channels to monitor personnel activities in real time and link with the alarm system; once abnormal physical intrusion behavior is detected, issue an alarm in a timely manner and notify relevant personnel.
[0023] Preferably, the process of building multi-level cryptographic security protection in step 2 is as follows: evaluate the existing hardware infrastructure of the photovoltaic power station, select devices with hardware features that support TEE functions, including key servers and security chips in smart meters, and install and configure TEE-related hardware drivers and firmware to ensure the normal operation of TEE and achieve secure isolation and interaction with other components of the device, install TEE drivers on the server so that it can identify and manage the TEE environment; deploy the TEE operating system or runtime environment, set minimized attack surface and high security parameters, initialize and configure security parameters and key management policies, build a key storage area inside the TEE and limit access to the key to specific authorized processes, and establish a secure communication channel between the TEE and the external system, using encrypted tunnel technology or secure messaging protocols to achieve secure data transmission and interaction;
[0024] Select white-box encryption algorithms based on the security requirements and data characteristics of the photovoltaic power station, and identify the key data of the photovoltaic power station: user electricity billing information, equipment control parameters, and energy scheduling data. When the data enters the TEE environment, use the white-box encryption algorithm to encrypt the key data. Select encryption algorithms that meet domestic cryptographic standards: SM2, SM3, and SM4. Determine the algorithm combination for different key data based on data importance and usage scenarios. Deploy the domestic cryptographic algorithm library and related encryption tools in the photovoltaic power station storage system. Configure the storage system to automatically call the corresponding algorithm for encryption before writing data to the storage medium. Set up an encryption plug-in in the database management system to automatically encrypt and store data when inserting it into the table.
[0025] Build a key management system based on domestic cryptographic technology to generate, store, distribute and update encryption keys. Adopt a hierarchical key management architecture, apply domestic cryptographic technology in the network communication link of the photovoltaic power station, adopt an encryption communication protocol based on domestic cryptographic algorithms for inter-device communication and remote operation and maintenance access communication, configure network equipment and communication software to support the encryption transmission function of domestic cryptographic algorithms, set up encrypted tunnels or virtual private networks (VPNs) on network equipment and configure them with domestic cryptographic algorithms, customize and adapt the security transmission protocol according to the business needs and network architecture of the photovoltaic power station, and embed the application logic of domestic cryptographic algorithms in the protocol to ensure the confidentiality, integrity and authentication of data transmission.
[0026] Preferably, during the design of a power system architecture compatible with the integration of multiple renewable energy sources, the process of obtaining the final prediction model is as follows:
[0027] For photovoltaic power stations, real-time photovoltaic power generation data, including power generation power, irradiance, and temperature, is collected from photovoltaic panel power monitoring equipment and inverter data output ports. For wind farms, wind speed, wind direction, and power output data are obtained from the wind turbine monitoring system. Battery power, charge and discharge power, and state of charge (SOC) data are collected from energy storage systems. System load demand data, including power consumption information for different regions and time periods, is collected from power system load monitoring points.
[0028] Remove outliers and erroneous data from the collected data, and identify, correct, or delete data that exceeds the normal range; synchronize data to the same time resolution of 5-minute intervals; and fill missing data using mean filling, historical data trend filling, or interpolation algorithms to ensure data continuity and integrity.
[0029] For photovoltaic power generation forecasting, the irradiance, temperature, historical power generation time series characteristics, and derived characteristics of the irradiance change rate are extracted from the pre-processed raw data. For wind power generation forecasting, the wind speed mean, variance, maximum value, wind direction distribution characteristics, and correlation characteristics with historical wind power are extracted. For energy storage systems, battery aging characteristics such as cycle number, current SOC, and historical charge and discharge pattern characteristics are considered. For system load demand forecasting, the impact of special factors such as the periodicity of historical load data and holidays is analyzed and quantified.
[0030] The extracted feature data is divided into training set, validation set and test set, and the long short-term memory (LSTM) model and the Boosting tree model are trained using the training set data. For the LSTM model, the network structure parameters are adjusted: the number of hidden layers, the number of neurons and the time step. For the Boosting tree model, a decision tree is selected and the hyperparameters are adjusted: tree depth, learning rate and number of iterations. The hyperparameters are evaluated and adjusted using the validation set data, and cross-validation is used to prevent overfitting. The optimal hyperparameters are determined based on the validation set loss function value, and the test set is used to evaluate the performance of the trained model. The two models are then integrated or a better single model is selected as the final prediction model based on the scenario.
[0031] Preferably, the process of designing a power system architecture compatible with the access of multiple renewable energy sources also includes: inputting the photovoltaic, wind power, energy storage related data and system load demand data collected and pre-processed in real time into the trained prediction model in the format required by the model; the model calculates based on the input real-time data, predicts the new energy power generation and system load demand for a specific time period in the future: 1 hour, 6 hours or 24 hours, and outputs the prediction results in numerical form, where the new energy power generation includes photovoltaic power generation and wind power generation; formulates a backup energy scheduling strategy based on the predicted new energy power generation and system load demand results; if the new energy power generation is greater than the system load demand, stores the excess electricity in the energy storage system, adjusts the power generation of some new energy power generation equipment, or transmits electricity to the external power grid; if the new energy power generation is less than the system load demand, determines the energy storage system discharge Strategy, calculate the amount of electricity it needs to provide to fill the gap. If the energy storage capacity is insufficient, start the backup traditional energy generation equipment or coordinate scheduling with the energy supplier. When formulating the strategy, consider the economic factors of energy transmission loss, equipment start-up and shutdown costs, and energy price differences; use dynamic programming to convert the scheduling strategy into specific energy allocation instructions, with the prediction results, energy system equipment parameters, energy transmission network topology and transmission capacity as input, and determine the power generation or charge and discharge power of each energy device at each time step through optimization calculation, and send the scheduling instructions to the corresponding energy device controller for automatic optimization of energy allocation; continuously monitor energy production and consumption during scheduling execution, compare the prediction results, and adjust the scheduling strategy and algorithm parameters in time to adapt to uncertainty and changes. Among them, energy equipment includes photovoltaic, wind power, energy storage, and backup traditional energy generation equipment;
[0032] Implementing access control includes: using blockchain-based smart contracts to automatically execute access control policies to ensure the correct allocation and verification of permissions during data transmission and processing, thereby preventing unauthorized access and data leakage; implementing access control further includes: using blockchain-based authentication and permission allocation, and controlling access rights through smart contracts to enhance the security protection of data during storage and transmission, especially in multi-user and multi-business scenarios;
[0033] The white box encryption algorithm module performs security zone access authentication through TEE, ensuring that encryption operations are performed in an isolated secure environment, thereby improving the overall system's ability to resist attacks.
[0034] The present invention provides a data security protection method for photovoltaic power stations in a smart grid environment, which has the following beneficial effects:
[0035] 1. The data security protection method of the photovoltaic power station in the smart grid environment realizes the efficient processing of large amounts of data by designing a power system architecture compatible with the access of multiple new energy sources, utilizing real-time data collection and analysis as well as advanced prediction models. It accurately predicts the power generation of new energy sources and the system load demand, provides a basis for energy distribution, and avoids energy waste or insufficient supply caused by improper data processing. At the same time, in terms of data security, multi-level cryptographic security protection measures play a key role. White box encryption algorithms are loaded in a trusted execution environment to process key data and core algorithms, and domestic cryptographic technology is used to encrypt storage and transmission of data, effectively preventing data from being stolen or tampered with at all links, ensuring the security and integrity of the data.
[0036] 2. The data security protection method for photovoltaic power stations in the smart grid environment can not only efficiently process large amounts of data, but also ensure the security and integrity of these data during transmission, storage and processing, avoid information leakage or malicious attacks, improve the data security of photovoltaic power stations, and ensure the safe and stable operation of the power system. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 This is a flowchart of the data security protection method for photovoltaic power stations in a smart grid environment of the present invention. DETAILED DESCRIPTION
[0038] The present invention will be described in further detail below with reference to the accompanying drawings and specific embodiments. The embodiments of the present invention are provided for purposes of illustration and description and are not intended to be exhaustive or to limit the invention to the disclosed forms. Many modifications and variations will be apparent to those skilled in the art. The embodiments are chosen and described to better illustrate the principles of the invention and its practical application, and to enable those skilled in the art to understand the invention and design various embodiments with various modifications suitable for specific applications.
[0039] like Figure 1 As shown, the present invention provides a technical solution: a data security protection method for a photovoltaic power station in a smart grid environment, comprising the following steps:
[0040] Step 1: Use attack tree models and threat models to identify and assess data security risks in PV power plants and evaluate the risk level. Simultaneously, based on blockchain technology, generate unique digital identities for PV power plant equipment and their business scenarios, and implement access control. Digital identities are managed and authenticated using encrypted public-private key pairs.
[0041] Step 2: Build multi-level cryptographic security protection, load and execute white-box encryption algorithms in the Trusted Execution Environment (TEE) to process key data and core algorithms; use domestic cryptographic technology and security monitoring technology to encrypt the storage and transmission of key data to enhance data security;
[0042] Step 3: Design a power system architecture compatible with diverse renewable energy access. Leveraging real-time data collection and analysis, using long-short-term memory (LSTM) and boosting tree models, we predict renewable energy generation and system load demand. Based on these predictions, we implement backup energy scheduling, including using advanced scheduling algorithms to automatically optimize energy distribution. Renewable energy sources include photovoltaics, wind power, and energy storage. Backup energy scheduling is used to adapt to power demand and maintain system stability.
[0043] Step 4: Build a smart meter password security protection subsystem: Use high-strength password security strategies to generate and manage secure passwords to protect meter data; perform encryption authentication and security monitoring on new energy access, time-of-use electricity price parameters, and dedicated transformer smart fee control to ensure the security of key business data throughout its life cycle; password security strategies include using secure hash algorithms and symmetric encryption technologies to generate, store, and transmit passwords, and implement customized encryption authentication and access control strategies for key business scenarios to ensure data integrity and confidentiality.
[0044] The process for assessing risk levels is:
[0045] Clarify the equipment operation data, power generation data, business process-related data, and user and operation and maintenance personnel-related permission data involved in the photovoltaic power station, and at the same time sort out the basic information of the corresponding business scenarios and equipment connection status to obtain the scope of data asset assessment; collect historical data from the photovoltaic power station's monitoring system, energy management system, and billing system, and at the same time collect data on data security cases that have occurred in photovoltaic power stations within the industry to obtain photovoltaic power station-related data; among these, historical data includes records of past abnormal events, equipment failure data, and network access logs; take the ultimate goal of threatening the data security of the photovoltaic power station as the root node, and then gradually decompose the various means and conditions for achieving the ultimate goal as child nodes. For example, the means of obtaining permissions through network intrusion can be used as an intermediate node, and further subdivided into network port scanning and exploiting software vulnerabilities as leaf nodes) to construct a complete attack tree structure to clearly display possible attack paths; among these, the ultimate goal includes data leakage and data tampering;
[0046] For the leaf nodes of the attack tree, which represent the most basic attack methods at the bottom layer, an initial attack success probability value is assigned to each leaf node, combining existing security research data, historical statistics, and the experience of professionals. This probability value reflects the likelihood of the attack method succeeding under the current general environment. For example, for a known but partially patched software vulnerability, the probability of its exploitation being successful is estimated based on the prevalence of its patch. Probability is calculated from the bottom up: using probability calculation rules (such as the corresponding calculation formulas for logical AND and logical OR, where the success probability of the parent node under the logical AND relationship is equal to the product of the success probabilities of each child node; and where the success probability of the parent node under the logical OR relationship is equal to 1 minus the product of the failure probabilities of each child node), starting from the leaf nodes and working upwards, the attack success probability corresponding to each intermediate node and ultimately the root node is calculated. For example, if there are two attack path branches under the root node, with the nodes on one branch connected by a logical AND relationship and the other by a logical OR relationship, the probability of the final node of each branch is calculated according to the corresponding rules, and then the root node probability is calculated together.
[0047] Based on the internal and external environmental conditions of the PV power station, potential threat sources are analyzed and the potential threatening behaviors they may carry out are determined. Threat sources include external hacker groups, internal malicious employees, and natural environmental factors. Natural environmental factors include lightning strikes that may affect equipment and thus threaten data security. Threat behaviors include cyberattacks by hackers and illegal data access by employees. Based on threat behaviors, combined with statistical data from past power station incidents and the current protective measures taken by the power station, the likelihood of threatening behaviors occurring is assessed to determine the threat probability. The impact of threatening behaviors on the data security of the PV power station, if any, is analyzed. The threat probability is categorized into three levels: high, medium, and low.
[0048] Using the risk matrix method, a matrix is constructed with threat possibility as the horizontal axis and impact degree as the vertical axis. Different intervals correspond to different risk levels. The risk level corresponding to each threat is determined based on the threat possibility and impact degree of the threatening behavior, with high threat possibility and high impact corresponding to high risk level. The root node attack success probability and the risk level corresponding to each threat in the threat model are summarized and integrated. According to the pre-set weight distribution principle, the integrated risk-related indicators are weighted and calculated to finally determine the overall risk level of photovoltaic power station data security. The risk level is divided into high, medium and low risk levels, which can intuitively reflect the severity of the current data security and provide a basis for the subsequent formulation of targeted protection strategies. Among them, the weight distribution principle is: if the technical level risk reflected by the attack tree model is considered more critical, it can be given a higher weight; the actual threat situation reflected by the threat model has a slightly lower weight.
[0049] It should be further explained that, in the specific implementation process, the process of identifying threat behaviors includes: the complete tampering of key data, which cannot be restored through backup or simple data repair methods, resulting in serious errors in the operational decisions of the entire photovoltaic power station, such as incorrect energy scheduling plans that undermine the stability of the power grid; the loss and inability to recover important business data, which directly affects the economic benefits and reputation of the power station, may cause major disputes with users and partners, and cannot be operated normally for a long time; among them, important business data includes power generation data and user billing data; large-scale leakage of commercial secrets and user privacy information puts the power station at an extremely disadvantageous position in the market competition and faces legal proceedings and severe sanctions from regulatory authorities; the malicious use of leaked data directly causes major security incidents, such as hackers remotely controlling power station equipment based on leaked power station control system permissions, causing equipment damage or even casualties, all of which are classified as serious impacts. Among them, commercial secrets include the core technical details of the power station and the undisclosed energy reserve strategic plan, and user privacy information includes detailed user electricity usage information and identity information; key data includes the operating parameters of core equipment, financial settlement data, and long-term energy forecast models.
[0050] The leakage of some sensitive information, such as the configuration parameters of some equipment and the general electricity usage habits of some users, poses a certain threat to the security of the power plant and may be exploited by competitors to gain a certain advantage or cause some users to worry about data security, but it does not yet constitute a major legal or reputational crisis. The leaked data may be used to carry out some harassment activities, such as users receiving too many marketing messages, which has a negative impact on the user experience and indirectly affects the image of the power plant. These situations are classified as relatively serious.
[0051] Errors or loss of a small amount of non-critical data will have no substantial impact on the overall operation of the power plant. Brief small fluctuations or inaccuracies in the data can be quickly restored to normal through the system's automatic correction mechanism, and will not affect subsequent energy management and operational decisions. These situations are classified as general impact.
[0052] The process of generating a unique digital identity:
[0053] Establish a blockchain network infrastructure applicable to photovoltaic power plants and determine the node types in the network. Node types include device nodes, business server nodes, and management nodes. Device nodes include photovoltaic panel controller nodes, inverter nodes, and electricity meter nodes. Business server nodes are responsible for energy scheduling and billing processing. Management nodes are used to configure and monitor the entire blockchain network.
[0054] Configure basic parameters of the blockchain network, such as using the Practical Byzantine Fault Tolerance (PBFT) algorithm, to ensure fast and reliable consensus in the relatively closed environment of the photovoltaic power plant, which has high consistency requirements, thereby ensuring stable operation and data consistency of the blockchain network.
[0055] A unique digital ID (DID) is generated using a hash algorithm for each PV plant device (based on the device's unique ID or MAC address) and business scenario (using the name or ID of a specific business process combined with an associated timestamp). This hash algorithm is collision-resistant and one-way, ensuring that each ID is unique and difficult to forge. For example, a DID for a PV panel might be a fixed-length string generated by hashing the device's model, production date, and installation location.
[0056] The generated digital identity and the corresponding detailed information of the photovoltaic power station equipment or business scenario (such as equipment model and business function description) are registered on the blockchain to form an unalterable digital identity record. At the same time, an encrypted public-private key pair is generated for each digital identity. The public key is published on the blockchain as one of the bases for identity authentication, and the private key is securely stored by the corresponding device or business system for subsequent digital signature encryption operations to prove its own identity.
[0057] The process of implementing access control:
[0058] Analyze the operational requirements of different devices and business scenarios in the photovoltaic power station, and determine different role types, including operation and maintenance administrator role, general operation and maintenance personnel role, and energy dispatch system role. The operation and maintenance administrator role can configure and monitor the equipment, view and modify business data; the general operation and maintenance personnel role can only view the equipment status and some business data; the energy dispatch system role can perform energy allocation operations based on power generation and power consumption; for each role, define its access rights in different devices and business scenarios, including the operation and maintenance administrator role can start and stop all devices and access all business data, while the general operation and maintenance personnel role can only view the equipment status and some business data. Only the power generation data of the photovoltaic panels can be read; these access control policies are written in the form of smart contracts and deployed to the blockchain network. Smart contracts are automatically executed on the blockchain to ensure the transparency and non-tamperability of the access control policies; devices or users initiate access requests: When device A or a user needs to access device B or business system resources, they first generate an access request message containing their own digital identity DID, access target resource information, and access request details; the access target resource information includes the DID of the target device or the interface address of the business system; the access request details include the type of operation requested, whether to read data or modify data;
[0059] The access request message is digitally signed using its own private key to prove the authenticity and integrity of the request, and then the signed access request is sent to the blockchain network; the blockchain network verifies the access request: after receiving the access request, the node in the blockchain network first verifies the validity of the digital signature and uses the public key of the requester to decrypt and verify the signature. If the verification fails, the access request is directly rejected because this may mean that the request has been tampered with or comes from an illegal requester; after the signature is successfully verified, the access control smart contract is checked to see whether the role corresponding to the digital identity of the requester has access rights to the target resource; for example, if an ordinary operation and maintenance personnel role requests to modify the key parameters of the energy dispatching system, and its permissions clearly stipulate that it does not have such modification permissions, the access request is rejected; authorized access and resource interaction: if the access request passes the digital signature verification and permission check, the blockchain network sends an authorization notification to the target device or business system, allowing the requester to perform the access operation; at this time, the requester and the target resource interact with data or perform corresponding operations, such as data transmission between devices and users reading or modifying business system data.
[0060] The implementation of access control also includes: throughout the access process, the blockchain network continuously monitors access behavior, records the time of access and the content of the operation in the log on the blockchain for subsequent auditing and tracking; if abnormal behavior is found during the access process, such as reading or modifying data beyond the normal amount, or frequent incorrect access attempts, the blockchain network will automatically trigger the corresponding security mechanism, including temporarily freezing access rights and issuing alarm notifications; when the business needs of the photovoltaic power station change, such as the addition of a new equipment maintenance operation that requires new permissions for operation and maintenance personnel, or the need to revoke certain permissions due to security vulnerability repairs, the authorized administrator will initiate a permission change request through the management interface; the permission change request is submitted to the blockchain network after verification by the administrator's digital identity signature; the smart contract in the blockchain network updates the access permission settings of the corresponding role in different devices and business scenarios based on the content of the permission change request, and broadcasts the updated permission information to the entire blockchain network to ensure that all nodes can obtain the latest access control policy, so that the new access permission rules can take effect in real time;
[0061] Through the above steps, access control of photovoltaic power station equipment and its business scenarios is realized based on blockchain technology. Digital identity and public-private key pairs are used to ensure the security, traceability and non-tamperability of access, effectively protecting the data and system resource security of the photovoltaic power station.
[0062] Attack tree model assessment involves calculating the attack success probability of leaf nodes to identify critical security vulnerabilities and optimizing the system's security configuration accordingly. The process of identifying critical security vulnerabilities is as follows:
[0063] Construct an attack tree model: First, define the target and clarify the target of data security protection of photovoltaic power stations, such as preventing data leakage, ensuring the stable operation of energy dispatching systems, and protecting the control parameters of key equipment from being tampered with; use the target as the root node of the attack tree; for example, "preventing the leakage of photovoltaic power generation data" is the root node, which represents one of the core goals of the entire security protection; then decompose the attack path, starting from the root node, analyze all ways that may lead to the destruction of security goals; this includes physical attacks on photovoltaic power stations (such as illegal intrusion into equipment rooms), network attacks (such as intrusion into energy management systems through the network) and multiple internal threats, such as malicious data leakage by internal personnel; taking network attacks as an example, further decompose possible attack paths, including through Scan network ports for vulnerabilities, exploit software vulnerabilities for remote code execution, and conduct man-in-the-middle attacks to steal information in data transmission channels. These subpaths serve as intermediate nodes in the attack tree. Each intermediate node is further decomposed until the most basic attack method, namely the leaf node, is reached. For example, for the intermediate node "exploit software vulnerabilities for remote code execution," leaf nodes may include "exploit known operating system vulnerabilities" and "exploit specific version vulnerabilities of energy management software." The asset inventory is sorted out, including hardware equipment (such as photovoltaic panels, inverters, smart meters, and servers), software systems (such as energy management software, monitoring software, and billing software), and data assets (such as power generation data, equipment operating parameters, and user information).
[0064] Clarify the importance and sensitivity of each asset. For example, power generation data and user billing information are generally highly sensitive data, while non-critical operating parameters of some equipment may be less sensitive data. Record each asset's location (physical or network location), access method (such as network protocol and port), and the business processes involved.
[0065] Evaluate existing security measures and collect information on existing security measures at the PV power plant, including network firewall rule settings, intrusion detection / prevention system (IDS / IPS) configuration, access control policies, and encryption algorithm usage; analyze the degree to which existing security measures protect different assets, for example, checking whether the firewall restricts unauthorized access to key server ports and whether the IDS can detect common network attack patterns targeting the plant's assets; identify weaknesses in existing security measures, such as insufficient access control for certain devices or untimely rule updates for certain security devices;
[0066] Collect historical security events and vulnerability information, collect records of security events that occurred in the photovoltaic power station itself in the past, including the type of event (such as data leakage, equipment failure, network attack), the losses caused, the handling process and results of the event; obtain security events and vulnerability information of photovoltaic power stations or energy systems in the industry through security information websites, industry reports, and vulnerability notices issued by security vendors; analyze the relationship between these historical events and vulnerability information and the assets and security measures of this power station, and determine the areas where similar risks may exist in this power station; calculate the probability of successful attack on leaf nodes, and first assign a basic probability value: for the leaf nodes of the attack tree, assign an initial probability value to each leaf node based on existing information, historical data and expert experience. The probability of success of the initial attack is given. It should be further explained that, during the specific implementation process, for the leaf node "Exploiting a known operating system vulnerability", if the vulnerability already has a public patch and most of the equipment in the power plant has been updated with the patch, a lower probability of success (such as 10%) can be assigned. If the vulnerability is newly discovered and no effective patch is available, and the equipment in the power plant may be at risk of attack, a higher probability (such as 60%) can be assigned. The probability is adjusted based on the complexity of the attack, the resources required, and the skill level of the attacker. For example, for a leaf node that requires highly specialized skills and complex attack tools, the probability of success can be appropriately reduced even if the vulnerability exists.
[0067] According to the logical relationship (such as logical and, logical or) between the leaf nodes and the intermediate nodes, root nodes in the attack tree, the calculation method of attack success probability is determined; under the logical and relationship, the success probability of the upper node is the product of the success probability of each lower node; under the logical or relationship, the success probability of the upper node is equal to 1 minus the product of the unsuccessful probability of each lower node; for example, for an intermediate node "get data access permission by network port scanning and exploit software vulnerabilities", if the success probability of the "network port scanning" leaf node is 30%, the success probability of the "exploit software vulnerabilities" leaf node is 40%, and the two nodes are in logical and relationship, then the attack success probability of this intermediate node is 0.3x0.4=12%; identify key security vulnerabilities: first set a threshold, according to the risk tolerance of photovoltaic power station to data security, set a threshold of attack success probability; it needs to be further explained that in the specific implementation process, for the attack path related to high sensitive data assets, set the threshold to 30%; for the attack path related to low sensitive data assets, set the threshold to 50%; this threshold will be an important basis for judging key security vulnerabilities, the nodes involved in the path with attack success probability exceeding the threshold may contain key security vulnerabilities; then identify and screen the vulnerabilities: starting from the root node of the attack tree, according to the calculated attack success probability, screen out the paths with probability exceeding the threshold; it needs to be further explained that in the specific implementation process, for the nodes on these paths, especially the leaf nodes and the intermediate nodes directly related to them, detailed analysis is carried out; the attack means or security weak links represented by these nodes are likely to be key security vulnerabilities; for example, if the overall attack success probability of an attack path "unauthorized physical access-access server-steal power generation data" exceeds the set threshold of high sensitive data, then the security problems corresponding to the "unauthorized physical access" and "server access control weak" nodes can be identified as key security vulnerabilities; finally verify and confirm the vulnerabilities: for the key security vulnerabilities identified initially, verify them through vulnerability scanning tools and penetration testing to get clear key security vulnerabilities; use professional network vulnerability scanning tools to scan the network equipment and system of the power station, check whether there are actual security problems related to the identified vulnerabilities; carry out targeted penetration testing, simulate the attacker using the identified vulnerabilities to attack, and observe whether the security defense line can be successfully broken through, so as to further confirm the authenticity and severity of these vulnerabilities.
[0068] The process of optimizing the security configuration of the system is as follows: according to the key security vulnerabilities identified in the attack tree model, classify them according to the type of vulnerability; divided into network protocol vulnerability, operating system vulnerability, application program vulnerability and physical security vulnerability these four categories; network protocol vulnerability contains TCP / IP protocol stack related vulnerabilities, operating system vulnerability contains unpatched vulnerabilities existing in photovoltaic power station server or device operating system, application program vulnerability contains vulnerabilities of energy management software and monitoring software, physical security vulnerability contains insufficient protection of device physical access points; for each category, record the devices involved, business scenarios and possible security risk consequences in detail, security risk consequences include data leakage, system paralysis and power generation efficiency reduction; according to the calculated leaf node attack success probability and the impact degree of the vulnerability, determine the priority of the security vulnerability; using the quantitative risk assessment matrix method, the attack success probability is divided into high, medium and low three levels, and the impact degree is divided into serious, relatively serious and general three levels; for example, the priority of the vulnerability with high attack success probability and serious impact degree is the highest, which should be handled first; while the priority of the vulnerability with low attack success probability and general impact degree is low; at the same time, considering the exploitability and diffusion speed after being exploited, the priority is adjusted comprehensively;
[0069] For high-priority security vulnerabilities related to network protocol vulnerabilities, adjust the firewall rules; for example, limit access to specific high-risk ports, and only allow authorized IP address ranges to access critical network services (such as the communication port of the energy dispatching server); implement intrusion detection / prevention system IDS / IPS optimization; according to the characteristics of the vulnerability, configure the rules of IDS / IPS, such as increasing the detection and blocking ability of specific network attack patterns (such as malicious traffic characteristics related to identified vulnerabilities); use virtual private network VPN technology to enhance network communication security; use VPN for encrypted communication between different areas (such as power generation area and control area) in photovoltaic power station, or when remotely accessing, to prevent network sniffing and man-in-the-middle attacks;
[0070] For operating system vulnerabilities, timely update security patches, establish an automated patch management system, ensure that the operating systems of all devices in the photovoltaic power station (such as servers, smart meters) obtain and install the latest security patches in a timely manner to reduce the risk of attacks; for application vulnerabilities, conduct code review and software updates; the development team conducts code review of energy management and data monitoring applications, fixes discovered security vulnerabilities, and upgrades the software version; at the same time, during the software deployment process, minimize software permissions to avoid security risks caused by running software with excessive permissions; implement access control policy optimization; adjust user and device access rights according to vulnerability conditions; for example For example, if a loophole is found in the access control of a certain device, resulting in the possibility of unauthorized access, access rights should be tightened and multi-factor authentication (such as a combination of passwords, digital certificates, and biometrics) should be used to enhance the security of access control. For physical security loopholes, the physical protection of the equipment should be strengthened. Fences and access control systems should be set up around key equipment in the photovoltaic power station (such as server rooms and distribution cabinets) to restrict physical access by unauthorized personnel. Surveillance cameras and alarm systems should be installed. Video surveillance equipment should be installed in equipment areas and key passages to monitor personnel activities in real time and linked to the alarm system. Once abnormal physical intrusion behavior is discovered, an alarm should be issued in a timely manner and relevant personnel should be notified.
[0071] It should be further explained that, during the specific implementation process, according to the formulated security configuration optimization strategy, the security configuration is gradually updated in the photovoltaic power station system; it involves the configuration update of network equipment (such as routers and switches), parameter adjustment of servers and software systems, and installation and activation of physical security facilities; during the update process, the accuracy and consistency of the configuration are ensured; configuration management tools are used to back up and compare the configuration files before and after the update to prevent new security problems or system failures caused by configuration errors; after the security configuration update is completed, a comprehensive security test is carried out; including network security testing, including vulnerability scanning: using professional network vulnerability scanning tools, rescanning the system to check the previously identified Whether other vulnerabilities have been fixed, penetration testing: simulate the behavior of attackers, attempt to attack the system from the outside and inside, and verify the effectiveness of security configurations; perform functional testing and security verification on systems and software; check whether the updated systems and software can operate normally, and whether there are any functional anomalies caused by security configuration updates; for example, verify whether legitimate users can still access required resources normally after tightening access rights, and whether the updated software correctly handles security-related operations such as data encryption and identity authentication; test physical security facilities; check whether the access control system is working properly, whether the surveillance camera can clearly record personnel activities, and whether the alarm system can respond in a timely manner;
[0072] Establish a security monitoring system to monitor key indicators of the photovoltaic power station in real time, including network traffic, equipment status, and software operation status. Collect data including network connection requests, equipment resource usage, and software error logs. By analyzing this data, potential security threats and abnormal behavior can be promptly identified. Use a security information and event management system (SIEM) to centrally manage and analyze collected security-related data. The SIEM system can correlate data from different sources, identify possible security event patterns, such as frequent failed login attempts and abnormal data access requests, and issue timely alerts.
[0073] Re-evaluate the system's security configuration monthly or quarterly; check whether the existing security configuration is still valid based on new security threat intelligence, business changes, and security monitoring data feedback; business changes include the addition of new equipment or business functions; if new security vulnerabilities are discovered or the existing security configuration cannot meet security requirements, repeat the above security vulnerability classification, optimization strategy formulation, configuration update and testing to continuously optimize the system security configuration to ensure that the PV power station always maintains a relatively safe operating state.
[0074] The process of building multi-level cryptographic security protection in step 2 is as follows: evaluate the existing hardware infrastructure of the photovoltaic power station, select devices with hardware features that support TEE functions (such as specific processor instruction set extensions or secure isolation circuits), including key servers and security chips in smart meters, and install and configure TEE-related hardware drivers and firmware to ensure the normal operation of TEE and achieve secure isolation and interaction with other components of the device. Install TEE drivers on the server so that it can identify and manage the TEE environment; deploy the TEE operating system or runtime environment, set minimized attack surface and high security parameters, initialize and configure security parameters and key management policies, build a key storage area within the TEE and limit key access to specific authorized processes, and establish a secure communication channel between the TEE and external systems, using encrypted tunneling technology or secure messaging protocols to achieve secure data transmission and interaction;
[0075] Select a white-box encryption algorithm based on the security requirements and data characteristics of the photovoltaic power station, taking into account algorithm strength, performance overhead, and adaptability to various types of data (such as power generation data and equipment configuration information). Once selected, integrate it into the TEE environment, compile, link, and load the algorithm code into the TEE's specific memory area. This ensures that the algorithm runs in a secure environment and is compatible with the existing software architecture and data processing flow. The algorithm is then adapted for different data types and business scenarios.
[0076] Identify the key data of the photovoltaic power station: user electricity billing information, equipment control parameters, and energy scheduling data. When the data enters the TEE environment, use the white box encryption algorithm to encrypt the key data. For example, after the smart meter power data is transmitted to the server, it is encrypted and stored in the server TEE environment. For core algorithms (such as energy scheduling algorithms, data aggregation and analysis algorithms), white box encryption algorithms are also used in TEE for protection to ensure that the algorithm execution process and related data encryption operations are carried out, and the algorithm logic and data are not stolen or tampered with. The energy scheduling algorithm is based on encrypted data operations and encrypted transmission scheduling instructions to the execution device, and the device decrypts and executes in the TEE environment. Select encryption algorithms that meet domestic cryptographic standards: SM2, SM3, and SM4. Determine the algorithm combination for different key data based on data importance and usage scenarios. Deploy domestic cryptographic algorithm libraries and related encryption tools in the photovoltaic power station storage system (database server, distributed storage node), configure the storage system to automatically call the corresponding algorithm for encryption before writing data to the storage medium, and set encryption plug-ins in the database management system to automatically encrypt and store data when inserting it into the table.
[0077] Build a key management system for domestic cryptographic technology to generate, store, distribute, and update encryption keys. Use a hierarchical key management architecture. The root key is generated by a secure hardware device (such as the hardware security module HSM in the key management server) to store and encrypt other hierarchical keys (such as the data encryption key DEK). Independent key pairs or key groups are allocated to different data storage areas or business systems to ensure key independence and security. For example, different key pairs are used for the power generation data storage area and the user management data storage area. Keys are updated regularly, and update operations are triggered based on time periods (monthly or quarterly) or specific security events (suspected key leaks).
[0078] Domestic cryptographic technology is applied to the network communication links of photovoltaic power plants. For inter-device communication (PV panels and inverters, inverters and servers) and remote operation and maintenance access communications, encrypted communication protocols based on domestic cryptographic algorithms are adopted. For example, the SM4 algorithm is used to encrypt network data packets and the SM3 algorithm is used to calculate hash values for integrity verification. Network equipment (routers, switches) and communication software (network communication libraries, message middleware) are configured to support the encrypted transmission function of domestic cryptographic algorithms. Encrypted tunnels or virtual private networks (VPNs) are set up on network equipment and configured with domestic cryptographic algorithms. For example, a VPN tunnel based on the SM4 algorithm is established on a router to achieve data encryption transmission. Customized and adapted secure transmission protocols are implemented based on the business needs and network architecture of the photovoltaic power plant. The application logic of domestic cryptographic algorithms is embedded in the protocol to ensure the confidentiality, integrity, and authentication of data transmission. For example, the energy scheduling data transmission protocol adds the SM2 algorithm for device identity authentication to prevent unauthorized access and data theft. The secure transmission protocol is optimized to improve the performance and efficiency of encrypted transmission. To meet the needs of large-scale real-time data transmission (reporting of power generation data and issuing of energy scheduling instructions), the encryption algorithm working mode is optimized and the computational overhead is reduced. For example, the stream encryption mode is used to process continuous real-time data to reduce initialization and switching overhead.
[0079] During the design of a power system architecture compatible with the integration of multiple renewable energy sources, the final prediction model was obtained as follows: For photovoltaic power plants, real-time photovoltaic power generation, irradiance, and temperature data were collected from the photovoltaic panel power monitoring equipment and inverter data output ports. For wind farms, wind speed, wind direction, and power output data were obtained from the wind turbine monitoring system. Battery power, charge and discharge power, and state of charge (SOC) data were collected from the energy storage system. At the same time, system load demand data, including power consumption information in different regions and time periods, was collected from the power system load monitoring points.
[0080] Remove outliers and erroneous data from the collected data, and identify, correct, or delete data that exceeds the normal range; synchronize data to the same time resolution of 5-minute intervals; and fill missing data using mean filling, historical data trend filling, or interpolation algorithms to ensure data continuity and integrity.
[0081] For photovoltaic power generation forecasting, the irradiance, temperature, historical power generation time series characteristics, and derived characteristics of the irradiance change rate are extracted from the pre-processed raw data. For wind power generation forecasting, the wind speed mean, variance, maximum value, wind direction distribution characteristics, and correlation characteristics with historical wind power are extracted. For energy storage systems, battery aging characteristics such as cycle number, current SOC, and historical charge and discharge pattern characteristics are considered. For system load demand forecasting, the impact of special factors such as the periodicity of historical load data and holidays is analyzed and quantified.
[0082] The extracted feature data is divided into training set, validation set and test set, and the long short-term memory (LSTM) model and the Boosting tree model are trained using the training set data. For the LSTM model, the network structure parameters are adjusted: the number of hidden layers, the number of neurons and the time step. For the Boosting tree model, a decision tree is selected and the hyperparameters are adjusted: tree depth, learning rate and number of iterations. The hyperparameters are evaluated and adjusted using the validation set data, and cross-validation is used to prevent overfitting. The optimal hyperparameters are determined based on the validation set loss function value, and the test set is used to evaluate the performance of the trained model. The two models are then integrated or a better single model is selected as the final prediction model based on the scenario.
[0083] The process of designing a power system architecture compatible with multiple renewable energy sources also includes: inputting real-time collected and pre-processed photovoltaic, wind power, and energy storage data, as well as system load demand data, into the trained prediction model in the required format (e.g., after standardization or normalization);
[0084] The model calculates based on real-time input data and predicts renewable energy power generation and system load demand for a specific time period in the future: 1 hour, 6 hours, or 24 hours. The forecast results are output in numerical form. Renewable energy power generation includes photovoltaic power generation and wind power generation. For example, if the photovoltaic power generation in the next hour is X megawatts, the wind power generation is Y megawatts, and the system load demand is Z megawatts, this forecast result will serve as the basis for backup energy scheduling.
[0085] Formulate a backup energy dispatch strategy based on the predicted renewable energy generation and system load demand. If renewable energy generation exceeds system load demand, store the excess power in the energy storage system, adjust the power generation of some renewable energy generation equipment, or transmit power to the external power grid (if grid connection is permitted and economically beneficial). If renewable energy generation is less than system load demand, determine the energy storage system discharge strategy and calculate the amount of power it needs to provide to fill the gap. If the energy storage capacity is insufficient, activate backup traditional energy generation equipment or coordinate dispatch with energy suppliers. When formulating the strategy, consider energy transmission losses, equipment startup and shutdown costs, and energy price differences.
[0086] Dynamic programming is used to convert scheduling strategies into specific energy allocation instructions. The prediction results, energy system equipment parameters, energy transmission network topology and transmission capacity are used as inputs. The power generation or charge and discharge power of each energy device at each time step is determined through optimization calculation, and the scheduling instructions are sent to the corresponding energy device controller for automatic optimization of energy allocation. During the scheduling execution, energy production and consumption are continuously monitored, and the prediction results are compared. The scheduling strategy and algorithm parameters are adjusted in time to adapt to uncertainties and changes. Among them, energy equipment includes photovoltaic, wind power, energy storage, and backup traditional energy power generation equipment.
[0087] It should be further explained that, during the specific implementation process, blockchain technology is used to generate unique digital identities for photovoltaic power station equipment and its business scenarios, and strict access control is implemented. This measure ensures that only authorized devices and users can access the corresponding resources, effectively preventing unauthorized access and data leakage. When accessing through a device or user, a message containing a digital identity and detailed access request information must be generated, and the identity must be verified through a private key digital signature, and permissions are then checked based on the smart contract. The entire process achieves transparency and tamper-proof access control, enhancing the security of data during transmission and processing, especially in multi-user and multi-business scenarios, ensuring data security protection.
[0088] Based on blockchain technology, a unique digital identity is generated for photovoltaic power station equipment and its business scenarios, and strict access control is implemented. This measure ensures that only authorized devices and users can access the corresponding resources, effectively preventing unauthorized access and data leakage. For example, when a device or user accesses, a message containing a digital identity and detailed access request information must be generated, and the identity must be verified through a private key digital signature, and then the permissions must be checked based on the smart contract. The entire process achieves transparency and non-tamperability of access control, enhances the security of data during transmission and processing, and ensures data security protection, especially in multi-user and multi-business scenarios.
[0089] Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field and related fields without making creative efforts should fall within the scope of protection of the present invention. Structures, devices, and operating methods not specifically described and explained in the present invention shall be implemented in accordance with conventional means in the field unless otherwise specified or limited.
Claims
1. A data security protection method for photovoltaic power stations in a smart grid environment, characterized in that: The following steps are included: Step 1: Use attack tree models and threat models to identify and assess data security risks in PV power plants and evaluate the risk level. Simultaneously, based on blockchain technology, generate unique digital identities for PV power plant equipment and their business scenarios, and implement access control. Digital identities are managed and authenticated using encrypted public-private key pairs. Step 2: Build multi-level cryptographic security protection, load and execute white-box encryption algorithms in the Trusted Execution Environment (TEE) to process key data and core algorithms; use domestic cryptographic technology and security monitoring technology to encrypt, store, and transmit key data; Step 3: Design a power system architecture compatible with multiple renewable energy sources: Leverage real-time data collection and analysis, using long-short-term memory (LSTM) and boosting tree models, to predict renewable energy generation and system load demand. Based on these predictions, implement backup energy scheduling, including using advanced scheduling algorithms to automatically optimize energy distribution. Renewable energy sources include photovoltaics, wind power, and energy storage. Backup energy scheduling is used to adapt to power demand and maintain system stability. Step 4: Build a smart meter password security protection subsystem: use high-strength password security strategies to generate and manage secure passwords; perform encryption authentication and security monitoring on new energy access, time-of-use electricity price parameters, and dedicated transformer smart fee control; the password security strategy includes the use of secure hash algorithms and symmetric encryption technology to generate, store, and transmit passwords, and implement customized encryption authentication and access control strategies for key business scenarios.
2. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 1 is characterized by: The process for assessing risk levels is: Identify the equipment operation data, power generation data, business process-related data, and user and operation and maintenance personnel authority data involved in the photovoltaic power station. At the same time, organize the corresponding business scenarios and basic information on equipment connection status to determine the scope of the data asset assessment. Collect historical data from the photovoltaic power station's monitoring system, energy management system, and billing system. At the same time, collect data on data security cases that have occurred in photovoltaic power stations within the industry to obtain relevant data about the photovoltaic power station. This historical data includes records of past abnormal events, equipment failure data, and network access logs. Take the ultimate goal of threatening the data security of the photovoltaic power station as the root node, and then gradually decompose the various means and conditions for achieving the ultimate goal as child nodes to construct an attack tree. The ultimate goal includes data leakage and data tampering. For the leaf nodes of the attack tree, we combine existing security research data, historical statistics, and professional judgment to assign an initial attack success probability value to each leaf node. We then calculate the probability from the bottom up: using probability calculation rules, we start from the leaf nodes and gradually calculate the attack success probability for each intermediate node and the final root node. Based on the internal and external environment of the PV power station, we analyze potential threat sources and determine the threatening behaviors they may carry out. These include external hacker groups, internal malicious employees, and natural environmental factors. Based on the threatening behaviors, combined with statistical data from past plant incidents and the current protective measures implemented by the plant, we assess the likelihood of the threatening behaviors occurring and determine the threat probability. We also analyze the impact of the threatening behaviors on the PV power station's data security if they occur. The risk matrix method is adopted to construct a matrix with the threat possibility as the horizontal axis and the impact degree as the vertical axis. Different intervals correspond to different risk levels. The risk level corresponding to each threat is determined according to the threat possibility and impact degree of the threatening behavior. The success probability of the root node attack and the risk level corresponding to each threat in the threat model are summarized and integrated. According to the pre-set weight distribution principle, the integrated risk-related indicators are weighted and calculated to finally determine the overall risk level of the photovoltaic power station data security.
3. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 2 is characterized by: The process of generating a unique digital identity: Establish a blockchain network infrastructure suitable for photovoltaic power plants, determine the node types in the network, including device nodes, business server nodes, and management nodes; configure the basic parameters of the blockchain network; use a hash algorithm to generate a unique digital identity DID for each photovoltaic power plant device and business scenario; register the generated digital identity and the corresponding photovoltaic power plant equipment or business scenario detailed information on the blockchain to form an unalterable digital identity record; at the same time, generate an encrypted public-private key pair for each digital identity, and make the public key public on the blockchain as the basis for identity verification.
4. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 3 is characterized by: The process of implementing access control: Analyze the operational requirements of different devices and business scenarios within the PV power station, identify different role types, and define access rights for each role in different devices and business scenarios. Devices or users initiate access requests: When device A or a user needs to access device B or business system resources, they first generate an access request message containing their own digital identity (DID), information about the target resource to be accessed, and detailed information about the access request. Use its own private key to digitally sign the access request message to prove the authenticity and integrity of the request, and then send the signed access request to the blockchain network; the blockchain network verifies the access request: after receiving the access request, the node in the blockchain network first verifies the validity of the digital signature and uses the public key of the requester to decrypt and verify the signature. If the verification fails, the access request is directly rejected; after the signature is successfully verified, check whether the role corresponding to the digital identity of the requester has access rights to the target resource according to the access control smart contract; authorize access and resource interaction: if the access request passes the digital signature verification and permission check, the blockchain network sends an authorization notification to the target device or business system, allowing the requester to perform the access operation.
5. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 4 is characterized in that: The implementation of access control also includes: during the entire access process, the blockchain network continuously monitors access behavior, records the access time and operation content in the log on the blockchain for subsequent audit and tracking; if abnormal behavior is found during the access process, the blockchain network will automatically trigger the corresponding security mechanism, including temporarily freezing access rights and issuing alarm notifications; when the business needs of the photovoltaic power station change, the authorized administrator initiates a permission change request through the management interface; the permission change request is submitted to the blockchain network after verification by the administrator's digital identity signature; the smart contract in the blockchain network updates the access permission settings of the corresponding role in different devices and business scenarios according to the content of the permission change request, and broadcasts the updated permission information to the entire blockchain network.
6. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 5 is characterized by: Attack tree model assessment involves calculating the attack success probability of leaf nodes to identify critical security vulnerabilities and optimizing the system's security configuration accordingly. The process of identifying critical security vulnerabilities is as follows: Construct an attack tree model: First, define the target and clarify the goal of PV power plant data security protection, using the target as the root node of the attack tree. Then, decompose the attack path. Starting from the root node, analyze all possible ways to compromise the security target. Continue to decompose each intermediate node until you reach the most basic attack method, namely the leaf node. Organize the asset list and sort out the assets of the PV power plant. Clarify the importance and sensitivity of each asset, and record each asset's location, access method, and the business processes involved. Evaluate existing security measures and collect information on existing security measures in the PV power plant, including network firewall rule settings, intrusion detection / prevention system (IDS / IPS) configuration, access control policies, and the use of encryption algorithms. Analyze the degree of protection of different assets by existing security measures and identify weaknesses in existing security measures. Collect historical security incidents and vulnerability information, including records of past security incidents at the PV power plant itself, including the type of incident, the resulting losses, the incident handling process, and the results. Obtain information on security incidents and vulnerabilities occurring in PV power plants or energy systems within the industry through security information websites, industry reports, and vulnerability notices issued by security vendors. Analyze the correlation between these historical incidents and vulnerability information and the assets and security measures of the power plant to identify areas within the power plant that may have similar risks. Calculate the probability of successful attacks on leaf nodes, first assigning a basic probability: For each leaf node in the attack tree, assign an initial probability of successful attack based on existing information, historical data, and expert experience. Based on the logical relationship between the leaf nodes, intermediate nodes, and root nodes in the attack tree, the calculation method of the attack success probability is determined; under the logical and relationship, the success probability of the upper node is the product of the success probabilities of each lower node; under the logical or relationship, the success probability of the upper node is equal to 1 minus the product of the failure probabilities of each lower node; Identify key security vulnerabilities: First, set a threshold. According to the risk tolerance of the photovoltaic power station for data security, set a threshold for the attack success probability; then identify and screen the vulnerabilities: starting from the root node of the attack tree, according to the calculated attack success probability, screen out the paths with probabilities exceeding the threshold; finally, verify and confirm the vulnerabilities: For the key security vulnerabilities initially identified, verify them through vulnerability scanning tools and penetration testing to obtain clear key security vulnerabilities.
7. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 6 is characterized by: The process of optimizing the security configuration of the system is as follows: Based on the critical security vulnerabilities identified in the attack tree model, they are classified according to vulnerability type; they are divided into four categories: network protocol vulnerabilities, operating system vulnerabilities, application vulnerabilities, and physical security vulnerabilities; For each category, record in detail the devices involved in the vulnerability, business scenarios, and possible security risk consequences; Determine the priority of security vulnerabilities based on the calculated probability of successful attacks on leaf nodes and the potential impact of the vulnerabilities. Using a quantitative risk assessment matrix, the probability of attack success is categorized into high, medium, and low levels, and the degree of impact is categorized into severe, relatively severe, and general. For high-priority security vulnerabilities related to network protocol vulnerabilities, firewall rules are adjusted. Intrusion detection / prevention systems (IDS / IPS) are optimized. Based on vulnerability characteristics, IDS / IPS rules are configured, and virtual private network (VPN) technology is used to enhance network communication security. VPNs are used for encrypted communication between different areas within the PV power plant (such as the power generation area and the control area), or for remote operation and maintenance access, to prevent network sniffing and man-in-the-middle attacks. For operating system vulnerabilities, timely update security patches and establish an automated patch management system; for application vulnerabilities, conduct code reviews and software updates; implement access control policy optimization; adjust user and device access rights based on vulnerability conditions; for physical security vulnerabilities, set up protective fences and access control systems around key equipment in the photovoltaic power station to restrict physical access by unauthorized personnel; install surveillance cameras and alarm systems; install video surveillance equipment in equipment areas and key channels to monitor personnel activities in real time and link them with the alarm system; Once abnormal physical intrusion behavior is detected, an alarm will be issued in time and relevant personnel will be notified.
8. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 7 is characterized by: The process of building multi-level password security protection in step 2 is as follows: Evaluate the existing hardware infrastructure of the PV power plant, select devices with hardware features that support TEE functionality, deploy the TEE's operating system or runtime environment, set parameters to minimize the attack surface and ensure high security, initialize and configure security parameters and key management policies, build a key storage area within the TEE, restrict key access to only authorized processes, and establish secure communication channels between the TEE and external systems. Select white-box encryption algorithms based on the security requirements and data characteristics of photovoltaic power stations to identify key data of photovoltaic power stations: user electricity billing information, equipment control parameters, and energy scheduling data. When the data enters the TEE environment, use white-box encryption algorithms to encrypt the key data and select encryption algorithms that meet domestic cryptographic standards: SM2, SM3, and SM4. Determine the algorithm combination for different key data based on data importance and usage scenarios, build a key management system with domestic cryptographic technology, generate, store, distribute, and update encryption keys, adopt a hierarchical key management architecture, apply domestic cryptographic technology to photovoltaic power station network communication links, and adopt encryption communication protocols based on domestic cryptographic algorithms for inter-device communication and remote operation and maintenance access communication. Configure network equipment and communication software to support domestic cryptographic algorithm encryption transmission functions, set up encrypted tunnels or virtual private networks (VPNs) on network equipment and configure them with domestic cryptographic algorithms. Customize and adapt secure transmission protocols based on the business needs and network architecture of photovoltaic power stations, and embed domestic cryptographic algorithm application logic in the protocol to ensure the confidentiality, integrity, and authentication of data transmission.
9. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 8, characterized in that: When designing a power system architecture that is compatible with the integration of multiple renewable energy sources, the process of obtaining the final prediction model is as follows: For photovoltaic power stations, real-time photovoltaic power generation data, including power generation power, irradiance, and temperature, is collected from photovoltaic panel power monitoring equipment and inverter data output ports. For wind farms, wind speed, wind direction, and power output data are obtained from the wind turbine monitoring system. Battery power, charge and discharge power, and state of charge (SOC) data are collected from energy storage systems. System load demand data, including power consumption information for different regions and time periods, is collected from power system load monitoring points. Remove outliers and erroneous data from the collected data, and identify, correct, or delete data that falls outside the normal range; synchronize data to the same time resolution of 5-minute intervals; and fill missing data using mean filling, historical data trend filling, or interpolation algorithms. For photovoltaic power generation forecasting, the irradiance, temperature, historical power generation time series characteristics and the derived characteristics of irradiance change rate are extracted from the pre-processed raw data. For wind power generation forecasting, the wind speed mean, variance, maximum value, wind direction distribution characteristics and the correlation characteristics with historical wind power are extracted. For energy storage systems, the battery aging characteristics are considered: number of cycles, current SOC and historical charge and discharge pattern characteristics; and the system load demand is predicted. The extracted feature data is divided into training set, validation set and test set, and the long short-term memory (LSTM) model and the Boosting tree model are trained using the training set data. For the LSTM model, the network structure parameters are adjusted: the number of hidden layers, the number of neurons and the time step. For the Boosting tree model, a decision tree is selected and the hyperparameters are adjusted: tree depth, learning rate and number of iterations. The hyperparameters are evaluated and adjusted using the validation set data, and cross-validation is used to prevent overfitting. The optimal hyperparameters are determined based on the validation set loss function value, and the test set is used to evaluate the performance of the trained model. The two models are then integrated or a better single model is selected as the final prediction model based on the scenario.
10. The data security protection method for photovoltaic power stations in a smart grid environment according to claim 9, characterized in that: The process of designing a power system architecture that is compatible with the integration of multiple renewable energy sources also includes: Input the real-time collected and pre-processed photovoltaic, wind power, energy storage related data and system load demand data into the trained prediction model in the format required by the model; The model calculates and predicts renewable energy power generation and system load demand based on real-time input data for a specific time period in the future: 1 hour, 6 hours, or 24 hours, and outputs the prediction results in numerical form. Renewable energy power generation includes photovoltaic power generation and wind power generation. Formulate a backup energy dispatch strategy based on the predicted renewable energy generation and system load demand. If renewable energy generation exceeds system load demand, store the excess power in the energy storage system, adjust the power generation of some renewable energy generation equipment, or transmit power to the external power grid. If renewable energy generation is less than system load demand, determine the energy storage system discharge strategy and calculate the amount of power it needs to provide to fill the gap. If the energy storage capacity is insufficient, activate the backup traditional energy generation equipment or coordinate dispatch with the energy supplier. Dynamic programming is used to convert scheduling strategies into specific energy allocation instructions. The prediction results, energy system equipment parameters, energy transmission network topology and transmission capacity are used as input. The power generation or charge and discharge power of each energy device at each time step is determined through optimization calculation, and the scheduling instructions are sent to the corresponding energy device controller for automatic optimization of energy allocation.
Citation Information
Patent Citations
Intelligent power grid information security protection method
CN117640207A
Cloud master station security protection system, method and device and storage medium
CN117834195A