WAPI network communication management and control method and system for transformer substation

By using WAPI technology in substations to identify terminal access requests, allocate wireless access points, process data streams and segment secure data streams, the security and stability issues of Wi-Fi wireless communications in substations are resolved, and the safe and stable operation and maintenance of substations and the digital business needs are achieved.

CN120640290APending Publication Date: 2025-09-12SICHUAN ENERGY INVESTMENT YIBIN XUZHOU ELECTRIC POWER CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510802156.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing technologies for Wi-Fi wireless communication in substations have deficiencies in security, anti-signal interference, equipment compatibility, and energy consumption. They are unable to provide a stable and reliable wireless communication environment, impacting substation operation and maintenance.

Method used

WAPI technology is used to establish a wireless communication network in the substation. By identifying terminal access requests, allocating wireless access points, performing data flow feature recognition and firewall processing, segmenting secure data streams, and transmitting them to the service platform, a secure and reliable WAPI communication network is built.

Benefits of technology

It achieves safe and stable operation and maintenance within the substation, provides a reliable wireless communication solution, and meets the needs of substation digital services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120640290A_ABST
    Figure CN120640290A_ABST
Patent Text Reader

Abstract

The invention relates to the field of intelligent power grids, in particular to a WAPI network communication management and control method and system for a transformer substation, and the method comprises the steps: identifying that a WAPI wireless network of the transformer substation receives an access request from a terminal side, determining the service characteristics of the terminal side, and distributing a wireless access point to the terminal; forming an upload data stream in the in-station switching network, performing firewall processing on the upload data stream in the transformer substation, and sending the processed upload data stream to the data communication network; the method comprises the following steps of: performing firewall security processing in a master station on an uploaded data stream received by a master station side, and identifying data fragment characteristics of a security data stream so as to divide the security data stream into a plurality of data sub-streams; obtaining the business operation condition of a service platform in the master station side, and transmitting the data substreams to the service platform; a wireless access point is arranged on a terminal side by utilizing a WAPI technology, a safe and reliable WAPI communication network is established on the terminal side, a site exchange network, a data communication network and a master station side, a reliable wireless communication scheme is provided for a digital service scene of a transformer substation, and safe and stable operation and maintenance of the transformer substation are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart grids, and in particular to a WAPI network communication management and control method and system for substations. Background Art

[0002] With the development of smart grids, substation service requirements are becoming increasingly complex. The continuous integration of numerous advanced sensors and intelligent terminals is driving a rapid increase in online monitoring data from various types of equipment. Furthermore, the emergence of new services based on artificial intelligence and multi-information sensing technologies, such as intelligent robot inspections and visual operations, has led to a proliferation of equipment, complex technologies, and massive amounts of data in substation operations and maintenance. This places higher demands on substation operation, maintenance, and data transmission. Currently, most substation operations and maintenance services rely on Wi-Fi wireless communication. However, Wi-Fi technology suffers from limitations in security, signal interference resistance, device compatibility, and energy efficiency, making it difficult to provide a stable and reliable wireless communication environment for substation operations and maintenance. Considering that WAPI technology, a wireless transmission security protocol developed independently by my country, offers the advantages of flexible wireless networking, strong scalability, and excellent compatibility, it can meet the wireless data transmission requirements of various substation equipment and provide a reliable data communication solution for the development of digital substation services. Currently, the use of WAPI technology to establish wireless communication networks for substations is still in the initial stages of research and development. The implementation and control of WAPI communication networks in substation scenarios is crucial for achieving digital substation management. Summary of the Invention

[0003] In response to the defects of the existing technology, the present invention provides a WAPI network communication management and control method and system for substations, which identifies the access request received by the WAPI wireless network of the substation from the terminal side, determines the business characteristics of the terminal side, and allocates a wireless access point to the terminal; forms an uploaded data stream in the station switching network, performs substation firewall processing on the uploaded data stream and sends it to the data communication network; performs main station firewall security processing on the uploaded data stream received by the master station side, and identifies the data segment characteristics of the security data stream, thereby dividing the security data stream into several data sub-streams; obtains the business operation status of the service platform on the master station side, and transmits the data sub-streams to the service platform; uses WAPI technology to set up a wireless access point on the terminal side, and establishes a safe and reliable WAPI communication network on the terminal side, the site switching network, the data communication network and the master station side, providing a reliable wireless communication solution for the digital business scenario of the substation, and realizing safe and stable operation and maintenance of the substation.

[0004] The present invention provides a WAPI network communication management and control method for a substation, comprising the following steps:

[0005] Step S1: The WAPI wireless network of the identification substation receives an access request from a terminal side, determines the service characteristics of the terminal side, and allocates a wireless access point to the terminal accordingly;

[0006] Step S2: acquiring data flow characteristics of all wireless access points, forming an upload data flow in the in-station switching network; performing in-station firewall processing on the upload data flow, and then sending the upload data flow to the data communication network;

[0007] Step S3, performing security processing on the upload data stream received by the master station side using the firewall in the master station to obtain a secure data stream, and identifying data segment features of the secure data stream;

[0008] Step S4: dividing the secure data stream into several data sub-streams according to the characteristics of the data segments; obtaining the business operation status of the service platform on the master station side, and transmitting the data sub-streams to the service platform.

[0009] In one embodiment disclosed in the present application, in step S1, identifying that a WAPI wireless network of a substation receives an access request from a terminal side, determining service characteristics of the terminal side, and allocating a wireless access point to the terminal accordingly, includes:

[0010] Collect and analyze all access requests received from the terminal side of the substation's WAPI wireless network, and obtain the terminal identity information and execution task information that initiated the access request;

[0011] Determining at least one wireless access point matching the terminal based on the terminal identity information; determining a service interaction bandwidth requirement characteristic of the terminal based on the execution task information;

[0012] According to the service interaction bandwidth requirement characteristics and the bandwidth information allowed to be provided by each of the at least one wireless access point, the terminal is allocated to connect to one of the wireless access points.

[0013] In one embodiment disclosed in the present application, in step S2, data flow characteristics of all wireless access points are obtained, and an upload data flow is formed in the intra-station switching network; after the upload data flow is processed by the intra-substation firewall, the upload data flow is sent to the data communication network, including:

[0014] Obtain the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, and classify and integrate the data streams from all wireless access points in the in-station switching network to form several upload data streams;

[0015] Identify the abnormal sample distribution characteristics of the uploaded data stream, perform virus isolation and filtering on the uploaded data stream using the firewall in the substation, and then send all uploaded data streams to the data communication network in sequence according to their respective timing characteristics.

[0016] In one embodiment disclosed in the present application, in step S3, the uploaded data stream received by the master station is subjected to firewall security processing within the master station to obtain a secure data stream, and data segment features of the secure data stream are identified, including:

[0017] Monitoring the master station's reception process of an upload data stream from a data communication network, and identifying an abnormal time node of the master station's reception of the upload data stream; wherein the abnormal time node refers to a time node when the data flow rate exceeds a preset flow threshold during the master station's reception of the upload data stream;

[0018] According to the data flow corresponding to the abnormal time node, the uploaded data stream received by the main station side is virus isolated and filtered by the firewall in the main station to obtain a safe data stream, and the data segment content type distribution characteristics of the safe data stream are identified.

[0019] In one embodiment disclosed in the present application, in step S4, the secure data stream is divided into a plurality of data sub-streams according to the characteristics of the data segments; the business operation status of the service platform on the master station side is obtained, and the data sub-streams are transmitted to the service platform, including:

[0020] Determining the data segment position boundary of the secure data stream according to the content type distribution characteristics of the data segments of the secure data stream; wherein the data segment position boundary refers to the character boundary between two adjacent data segments with different content types in the secure data stream;

[0021] dividing the secure data stream into a plurality of data segments according to the position boundaries of the data segments, and then integrating all data segments with the same content type into data sub-streams according to their original time sequence, thereby dividing the secure data stream into a plurality of data sub-streams;

[0022] Obtain the business operation status of all service platforms on the master station side, determine the schedulable computing power resources of all service platforms for different business tasks; and transmit each data substream to the matching service platform based on the schedulable computing power resources.

[0023] The present invention also provides a WAPI network communication management and control system for a substation, comprising:

[0024] The terminal side identification module is used to identify the access request received from the terminal side by the WAPI wireless network of the substation and determine the service characteristics of the terminal side;

[0025] A wireless access point allocation module, configured to allocate a wireless access point to a terminal according to service characteristics of the terminal side;

[0026] The data flow integration module is used to obtain the data flow characteristics of all wireless access points and form an upload data flow in the intra-site switching network;

[0027] A data stream sending module, configured to process the uploaded data stream through a firewall within the substation and then send the uploaded data stream to a data communication network;

[0028] The secure data stream generation module is used to perform firewall security processing on the uploaded data stream received by the master station to obtain a secure data stream;

[0029] A data segment feature recognition module, configured to recognize features of data segments of the secure data stream;

[0030] A data stream segmentation module, configured to segment the secure data stream into a plurality of data sub-streams according to characteristics of the data segments;

[0031] The data transmission module is used to obtain the business operation status of the service platform on the master station side and transmit the data sub-stream to the service platform.

[0032] In one embodiment disclosed in the present application, the terminal-side identification module is used to identify the access request received from the terminal side by the WAPI wireless network of the substation and determine the service characteristics of the terminal side, including:

[0033] Collect and analyze all access requests received from the terminal side of the substation's WAPI wireless network, and obtain the terminal identity information and execution task information that initiated the access request;

[0034] Determining at least one wireless access point matching the terminal based on the terminal identity information; determining a service interaction bandwidth requirement characteristic of the terminal based on the execution task information;

[0035] The wireless access point allocation module is configured to allocate a wireless access point to the terminal according to service characteristics of the terminal side, including:

[0036] According to the service interaction bandwidth requirement characteristics and the bandwidth information allowed to be provided by each of the at least one wireless access point, the terminal is allocated to connect to one of the wireless access points.

[0037] In one embodiment disclosed in the present application, the data stream integration module is used to obtain data stream characteristics of all wireless access points and form an upload data stream in the intra-site switching network, including:

[0038] Obtain the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, and classify and integrate the data streams from all wireless access points in the in-station switching network to form several upload data streams;

[0039] The data stream sending module is used to perform firewall processing on the uploaded data stream within the substation and then send the uploaded data stream to the data communication network, including:

[0040] Identify the abnormal sample distribution characteristics of the uploaded data stream, perform virus isolation and filtering on the uploaded data stream using the firewall in the substation, and then send all uploaded data streams to the data communication network in sequence according to their respective timing characteristics.

[0041] In one embodiment disclosed in the present application, the secure data stream generation module is used to perform firewall security processing within the master station on the uploaded data stream received by the master station side to obtain a secure data stream, including:

[0042] Monitoring the master station's reception process of an upload data stream from a data communication network, and identifying an abnormal time node of the master station's reception of the upload data stream; wherein the abnormal time node refers to a time node when the data flow rate exceeds a preset flow threshold during the master station's reception of the upload data stream;

[0043] According to the data flow corresponding to the abnormal time node, the uploaded data stream received by the master station side is subjected to virus isolation and filtering by the firewall in the master station to obtain a safe data stream;

[0044] The data segment feature identification module is used to identify the data segment features of the secure data stream, including:

[0045] Identify content type distribution characteristics of data segments of the secure data stream.

[0046] In one embodiment disclosed in the present application, the data stream segmentation module is configured to segment the secure data stream into a plurality of data sub-streams based on the data segment characteristics, including:

[0047] Determining the data segment position boundary of the secure data stream according to the content type distribution characteristics of the data segments of the secure data stream; wherein the data segment position boundary refers to the character boundary between two adjacent data segments with different content types in the secure data stream;

[0048] dividing the secure data stream into a plurality of data segments according to the position boundaries of the data segments, and then integrating all data segments with the same content type into data sub-streams according to their original time sequence, thereby dividing the secure data stream into a plurality of data sub-streams;

[0049] The data transmission module is used to obtain the business operation status of the service platform on the master station side and transmit the data sub-stream to the service platform, including:

[0050] Obtain the business operation status of all service platforms on the master station side, determine the schedulable computing power resources of all service platforms for different business tasks; and transmit each data substream to the matching service platform based on the schedulable computing power resources.

[0051] Compared with the existing technology, the WAPI network communication management and control method and system for substations identify the WAPI wireless network of the substation receiving access requests from the terminal side, determine the business characteristics of the terminal side, and allocate a wireless access point to the terminal; form an upload data stream in the station switching network, perform substation firewall processing on the upload data stream and send it to the data communication network; perform main station firewall security processing on the upload data stream received by the master station side, and identify the data segment characteristics of the security data stream, thereby dividing the security data stream into several data sub-streams; obtain the business operation status of the service platform on the master station side, and transmit the data sub-streams to the service platform; use WAPI technology to set up a wireless access point on the terminal side, and establish a safe and reliable WAPI communication network on the terminal side, site switching network, data communication network and master station side, providing a reliable wireless communication solution for the digital business scenario of the substation and realizing safe and stable operation and maintenance of the substation.

[0052] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.

[0053] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0055] Figure 1 A flow chart of the WAPI network communication control method for substations provided by the present invention.

[0056] Figure 2 This is the WAPI network communication networking architecture of the present invention.

[0057] Figure 3This is a schematic diagram of the framework of the WAPI network communication management and control system for substations provided by the present invention. DETAILED DESCRIPTION

[0058] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.

[0059] See Figure 1 , is a flow chart of a WAPI network communication control method for a substation provided by an embodiment of the present invention. The WAPI network communication control method for a substation includes:

[0060] Step S1: The WAPI wireless network of the identification substation receives an access request from the terminal side, determines the service characteristics of the terminal side, and allocates a wireless access point to the terminal;

[0061] Step S2: acquiring data flow characteristics of all wireless access points and forming an upload data flow in the in-station switching network; performing in-station firewall processing on the upload data flow and then sending the upload data flow to the data communication network;

[0062] Step S3, performing security processing on the upload data stream received by the master station side using the firewall in the master station to obtain a secure data stream, and identifying data segment features of the secure data stream;

[0063] Step S4: divide the secure data stream into several data sub-streams according to the data segment characteristics; obtain the business operation status of the service platform on the master station side, and transmit the data sub-streams to the service platform.

[0064] See Figure 2The WAPI network communication networking architecture of the present invention mainly includes a terminal side and a master station side, and the terminal side and the master station side are connected via a data communication network. The terminal side includes a variety of different types of terminals, which may include but are not limited to control balls, handheld terminals, smart meters, drones, voiceprint monitoring, security videos, smart helmets, inspection robots, PCs, etc. Different terminals can perform different functional operations on the substation to meet the daily operation and maintenance of the substation. At the same time, the terminal side also includes multiple WAPI wireless access points. Each terminal can access the corresponding WAPI wireless access point according to its own operating status to achieve communication connection between the terminal and the WAPI network. All WAPI wireless access points are also connected to the intra-station switching network, wherein the intra-station switching network may include multiple switches. These switches together constitute the intra-station switching network, which is used to process data received from all WAPI wireless access points by the terminals. The terminal side also includes a firewall in the substation, which serves as a security module on the terminal side and can effectively intercept virus data, etc., to ensure the security of data transmitted to the data communication network.

[0065] Furthermore, the data communication network, acting as an intermediary between the terminals and the master station, enables long-distance data transmission between the two. The master station includes an internal firewall. This prevents viruses from being embedded in the data communication network during data transmission, effectively intercepting the virus-infected data. The master station also includes multiple service platforms and an integrated network management system. Each service platform performs matching service processing operations on data distributed by the switch, while the integrated network management system oversees the network's operational status within the master station.

[0066] The beneficial effects of the above technical solution are as follows: the WAPI network communication control method for substations identifies the WAPI wireless network of the substation receiving an access request from the terminal side, determines the business characteristics of the terminal side, and allocates a wireless access point to the terminal; forms an uploaded data stream in the station switching network, performs substation firewall processing on the uploaded data stream and sends it to the data communication network; performs main station firewall security processing on the uploaded data stream received by the master station side, and identifies the data segment characteristics of the security data stream, thereby dividing the security data stream into several data sub-streams; obtains the business operation status of the service platform on the master station side, and transmits the data sub-stream to the service platform; uses WAPI technology to set up a wireless access point on the terminal side, and establishes a safe and reliable WAPI communication network on the terminal side, the site switching network, the data communication network and the master station side, providing a reliable wireless communication solution for the digital business scenario of the substation, and realizing safe and stable operation and maintenance of the substation.

[0067] Preferably, in step S1, the WAPI wireless network of the identification substation receives an access request from the terminal side, determines the service characteristics of the terminal side, and allocates a wireless access point to the terminal accordingly, including:

[0068] Collect and analyze all access requests received from the terminal side of the substation's WAPI wireless network, and obtain the terminal identity information and execution task information that initiates the access request;

[0069] Determine at least one wireless access point that matches the terminal based on the terminal identity information; determine the service interaction bandwidth requirement characteristics of the terminal based on the execution task information;

[0070] According to the service interaction bandwidth requirement characteristics and the bandwidth information allowed to be provided by at least one wireless access point, the terminal is allocated to connect to one of the wireless access points.

[0071] Terminals with different functions, such as surveillance cameras, handheld terminals, smart meters, drones, voiceprint monitoring, security cameras, smart helmets, inspection robots, and PCs, perform tasks to monitor the substation. During these tasks, they need to access the WAPI network to upload monitoring data to the host for processing. Given the differences in hardware and task types between different terminals, the bandwidth required to upload monitoring data during tasks varies. Generally speaking, when a terminal performs video monitoring tasks and uses a high-definition camera, a higher bandwidth is required to upload monitoring data. When a terminal performs text data reading monitoring tasks, a lower bandwidth is required to upload monitoring data. Furthermore, the access bandwidth provided by all WAPI wireless access points on the terminal side varies. The available access bandwidth depends on the maximum access bandwidth and the used access bandwidth of each WAPI wireless access point. To ensure that each terminal receives sufficient bandwidth and fully utilizes the bandwidth of each WAPI wireless access point, the substation's WAPI access requests from all terminals on the terminal side are first collected and analyzed. The identity and task information of each terminal initiating the access request are obtained. This information is then used to determine each terminal's device hardware (e.g., network communication hardware) and task type (e.g., the format of the monitoring data obtained during the task). Based on each terminal's device hardware, at least one wireless access point compatible with the terminal's network communication is identified. Based on each terminal's task type, the service interaction bandwidth requirements for the terminal during the task are determined, namely, the communication bandwidth required by the terminal during the task. The available access bandwidth of each of the at least one wireless access point compatible with the terminal's network communication is then compared with the communication bandwidth required by the terminal during the task. A wireless access point that meets the terminal's bandwidth requirements is identified, and the terminal is then assigned to the corresponding wireless access point, ensuring that monitoring data from the terminal during the task is quickly and stably uploaded to the WAPI network.

[0072] Preferably, in step S2, data flow characteristics of all wireless access points are obtained, and an upload data flow is formed in the intra-station switching network; after the upload data flow is processed by the intra-substation firewall, the upload data flow is sent to the data communication network, including:

[0073] Obtain the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, and classify and integrate the data streams from all wireless access points in the in-station switching network to form several upload data streams;

[0074] Identify the abnormal sample distribution characteristics of the uploaded data stream, isolate and filter the uploaded data stream by firewall virus in the substation, and then send all uploaded data streams to the data communication network in sequence according to their respective timing characteristics.

[0075] Wireless access points on the terminal side can connect to multiple terminals simultaneously. These terminals can be of the same or different types. Each terminal generates a corresponding monitoring data stream during task execution, with specific monitoring data flow and code format. Given the large number of terminals connected to a wireless access point, directly transmitting terminal monitoring data received by the access point to the master station via the data communications network would not only place a significant data transmission load on the data communications network but also cause crosstalk between different monitoring data within the network. In order to reduce the data transmission load and data transmission anti-interference performance of the data communication network, based on the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, the data streams from all wireless access points are classified and integrated in the intra-station switching network to form several upload data streams. For example, monitoring data streams with the same data stream code format characteristics are determined as monitoring data streams that can be integrated. Then, based on the data flow characteristics of the monitoring data streams that can be integrated, a portion of the monitoring data streams is selected and ultimately integrated to obtain an upload data stream, and the total data flow of the selected portion of data streams does not exceed a preset flow threshold. Through the above method, the integrated upload data stream has a unified data stream code format and the total data flow of the upload data stream is not too large to affect the smoothness of transmission through the data communication network to the master station side. Considering that some terminals may be in a state of being hijacked by the network and virus data is generated synchronously during the generation of monitoring data streams, these virus data will be integrated into the uploaded data stream during the data stream integration process of the station exchange network. If the uploaded data stream is directly transmitted to the main station side through the data communication network, the virus data will spread on the main station side, affecting the data security of the main station side. It is necessary to identify the abnormal sample distribution characteristics of all uploaded data streams formed by the integration of the station exchange network. The abnormal sample distribution characteristics may include but are not limited to the distribution characteristics of Trojan virus samples in the uploaded data stream. Then, the firewall in the substation is used to isolate and filter the uploaded data stream according to the abnormal sample distribution characteristics to achieve virus detection and killing of the uploaded data stream. Then, according to the time sequence characteristics of all uploaded data streams that have completed the virus detection and killing process and are expected to be transmitted to the main station side, all uploaded data streams are sent to the data communication network in sequence, so that the data communication network can transmit the uploaded data streams to the main station side in an orderly manner.

[0076] Preferably, in step S3, the uploaded data stream received by the master station is subjected to firewall security processing within the master station to obtain a secure data stream, and data segment features of the secure data stream are identified, including:

[0077] Monitoring the master station's reception process of the uploaded data stream from the data communication network, and identifying abnormal time nodes of the master station's reception of the uploaded data stream; wherein the abnormal time node refers to the time node when the data flow rate exceeds a preset flow threshold during the master station's reception of the uploaded data stream;

[0078] According to the data flow corresponding to the abnormal time node, the uploaded data stream received by the main station side is isolated and filtered by the firewall in the main station to obtain a safe data stream, and the content type distribution characteristics of the data fragments of the safe data stream are identified.

[0079] Considering that the data communication network is in an open state, the data communication network is susceptible to external interference when transmitting the uploaded data stream from the terminal side to the main station side. During the transmission process, the uploaded data stream may be affected by other terminals connected to the data communication network and embedded with virus data, forming a traffic attack using the uploaded data stream as a carrier, resulting in excessive traffic when the data communication network transmits the uploaded data to the main station side. To protect the main station side from traffic attacks, the main station side monitors the process of receiving the uploaded data stream from the data communication network, identifies abnormal time nodes when the uploaded data stream is received on the main station side, and uses the firewall within the main station to isolate and filter viruses on the uploaded data stream received on the main station side based on the data traffic corresponding to the abnormal time nodes, thereby obtaining a safe data stream and reducing the security risk of the uploaded data received by the main station side. In addition, the content type distribution characteristics of the data fragments of the safe data stream are identified, and the content types of all data fragments contained in the safe data stream received by the main station side are comprehensively calibrated, providing an accurate basis for subsequent data stream restoration.

[0080] Preferably, in step S4, the secure data stream is divided into several data sub-streams according to the characteristics of the data segments; the business operation status of the service platform on the master station side is obtained, and the data sub-streams are transmitted to the service platform, including:

[0081] Determine the position boundary of data segments of the secure data stream based on the content type distribution characteristics of the data segments of the secure data stream; wherein the data segment position boundary refers to the character boundary between two adjacent data segments with different content types in the secure data stream;

[0082] The secure data stream is divided into several data segments according to the data segment position boundaries, and then all data segments with the same content type are integrated into data sub-streams according to the original time sequence, thereby dividing the secure data stream into several data sub-streams;

[0083] Obtain the business operation status of all service platforms on the master station side, determine the schedulable computing resources of all service platforms for different business tasks; based on the schedulable computing resources, transmit each data sub-stream to the matching service platform.

[0084] Considering that the security data stream contains monitoring data from different terminals, it cannot be directly transmitted to the service platform for business processing. Instead, the monitoring data segments from different terminals within the security data stream must be extracted separately and all monitoring data segments from the same terminal must be integrated into complete data substreams before they can be transmitted to the service platform for business processing. To this end, the data segment location boundaries of the security data stream are calibrated based on the content type distribution characteristics of the data segments in the security data stream. The security data stream is then segmented into several data segments based on the data segment location boundaries. All data segments with the same content type are then integrated into data substreams according to their original time sequence, thus segmenting the security data stream into several data substreams. Finally, the business operation status of all service platforms on the master side is obtained, and the schedulable computing resources of each service platform for different business tasks are determined. Each data substream is then transmitted to the corresponding service platform, ensuring that each data substream is assigned to a service platform with appropriate computing resources to execute business processing, thereby ensuring the normal and rapid execution of substation operation and maintenance services.

[0085] See Figure 3 , which is a schematic diagram of the framework of a WAPI network communication management and control system for a substation provided by an embodiment of the present invention. The WAPI network communication management and control system for a substation includes:

[0086] The terminal side identification module is used to identify the access request received from the terminal side by the WAPI wireless network of the substation and determine the service characteristics of the terminal side;

[0087] A wireless access point allocation module is used to allocate wireless access points to terminals based on service characteristics of the terminal side;

[0088] The data flow integration module is used to obtain the data flow characteristics of all wireless access points and form an upload data flow in the intra-site switching network;

[0089] The data stream sending module is used to process the uploaded data stream through the firewall in the substation and then send the uploaded data stream to the data communication network;

[0090] The secure data stream generation module is used to perform firewall security processing on the uploaded data stream received by the master station to obtain a secure data stream;

[0091] A data segment feature recognition module, used to recognize data segment features of a secure data stream;

[0092] A data stream segmentation module is used to segment the secure data stream into several data sub-streams according to the characteristics of the data segments;

[0093] The data transmission module is used to obtain the business operation status of the service platform on the main station side and transmit the data sub-stream to the service platform.

[0094] The beneficial effects of the above technical solution are as follows: the WAPI network communication management and control system for substations identifies the access request received by the WAPI wireless network of the substation from the terminal side, determines the business characteristics of the terminal side, and allocates a wireless access point to the terminal; forms an uploaded data stream in the station switching network, performs firewall processing on the uploaded data stream in the substation and sends it to the data communication network; performs firewall security processing on the uploaded data stream received by the master station side, and identifies the data segment characteristics of the security data stream, thereby dividing the security data stream into several data sub-streams; obtains the business operation status of the service platform in the master station side, and transmits the data sub-stream to the service platform; uses WAPI technology to set up a wireless access point on the terminal side, and establishes a safe and reliable WAPI communication network on the terminal side, the site switching network, the data communication network and the master station side, providing a reliable wireless communication solution for the digital business scenario of the substation, and realizing safe and stable operation and maintenance of the substation.

[0095] Preferably, the terminal side identification module is used to identify the access request received from the terminal side by the WAPI wireless network of the substation and determine the service characteristics of the terminal side, including:

[0096] Collect and analyze all access requests received from the terminal side of the substation's WAPI wireless network, and obtain the terminal identity information and execution task information that initiates the access request;

[0097] Determine at least one wireless access point that matches the terminal based on the terminal identity information; determine the service interaction bandwidth requirement characteristics of the terminal based on the execution task information;

[0098] The wireless access point allocation module is used to allocate wireless access points to terminals based on the service characteristics of the terminal side, including:

[0099] According to the service interaction bandwidth requirement characteristics and the bandwidth information allowed to be provided by at least one wireless access point, the terminal is allocated to connect to one of the wireless access points.

[0100] Terminals with different functions, such as surveillance cameras, handheld terminals, smart meters, drones, voiceprint monitoring, security cameras, smart helmets, inspection robots, and PCs, perform tasks to monitor the substation. During these tasks, they need to access the WAPI network to upload monitoring data to the host for processing. Given the differences in hardware and task types between different terminals, the bandwidth required to upload monitoring data during tasks varies. Generally speaking, when a terminal performs video monitoring tasks and uses a high-definition camera, a higher bandwidth is required to upload monitoring data. When a terminal performs text data reading monitoring tasks, a lower bandwidth is required to upload monitoring data. Furthermore, the access bandwidth provided by all WAPI wireless access points on the terminal side varies. The available access bandwidth depends on the maximum access bandwidth and the used access bandwidth of each WAPI wireless access point. To ensure that each terminal receives sufficient bandwidth and fully utilizes the bandwidth of each WAPI wireless access point, the substation's WAPI access requests from all terminals on the terminal side are first collected and analyzed. The identity and task information of each terminal initiating the access request are obtained. This information is then used to determine each terminal's device hardware (e.g., network communication hardware) and task type (e.g., the format of the monitoring data obtained during the task). Based on each terminal's device hardware, at least one wireless access point compatible with the terminal's network communication is identified. Based on each terminal's task type, the service interaction bandwidth requirements for the terminal during the task are determined, namely, the communication bandwidth required by the terminal during the task. The available access bandwidth of each of the at least one wireless access point compatible with the terminal's network communication is then compared with the communication bandwidth required by the terminal during the task. A wireless access point that meets the terminal's bandwidth requirements is identified, and the terminal is then assigned to the corresponding wireless access point, ensuring that monitoring data from the terminal during the task is quickly and stably uploaded to the WAPI network.

[0101] Preferably, the data flow integration module is used to obtain data flow characteristics of all wireless access points and form an upload data flow in the intra-site switching network, including:

[0102] Obtain the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, and classify and integrate the data streams from all wireless access points in the in-station switching network to form several upload data streams;

[0103] The data stream transmission module is used to process the uploaded data stream through the substation firewall and then send the uploaded data stream to the data communication network, including:

[0104] Identify the abnormal sample distribution characteristics of the uploaded data stream, isolate and filter the uploaded data stream by firewall virus in the substation, and then send all uploaded data streams to the data communication network in sequence according to their respective timing characteristics.

[0105] Wireless access points on the terminal side can connect to multiple terminals simultaneously. These terminals can be of the same or different types. Each terminal generates a corresponding monitoring data stream during task execution, with specific monitoring data flow and code format. Given the large number of terminals connected to a wireless access point, directly transmitting terminal monitoring data received by the access point to the master station via the data communications network would not only place a significant data transmission load on the data communications network but also cause crosstalk between different monitoring data within the network. In order to reduce the data transmission load and data transmission anti-interference performance of the data communication network, based on the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, the data streams from all wireless access points are classified and integrated in the intra-station switching network to form several upload data streams. For example, monitoring data streams with the same data stream code format characteristics are determined as monitoring data streams that can be integrated. Then, based on the data flow characteristics of the monitoring data streams that can be integrated, a portion of the monitoring data streams is selected and ultimately integrated to obtain an upload data stream, and the total data flow of the selected portion of data streams does not exceed a preset flow threshold. Through the above method, the integrated upload data stream has a unified data stream code format and the total data flow of the upload data stream is not too large to affect the smoothness of transmission through the data communication network to the master station side. Considering that some terminals may be in a state of being hijacked by the network and virus data is generated synchronously during the generation of monitoring data streams, these virus data will be integrated into the uploaded data stream during the data stream integration process of the station exchange network. If the uploaded data stream is directly transmitted to the main station side through the data communication network, the virus data will spread on the main station side, affecting the data security of the main station side. It is necessary to identify the abnormal sample distribution characteristics of all uploaded data streams formed by the integration of the station exchange network. The abnormal sample distribution characteristics may include but are not limited to the distribution characteristics of Trojan virus samples in the uploaded data stream. Then, the firewall in the substation is used to isolate and filter the uploaded data stream according to the abnormal sample distribution characteristics to achieve virus detection and killing of the uploaded data stream. Then, according to the time sequence characteristics of all uploaded data streams that have completed the virus detection and killing process and are expected to be transmitted to the main station side, all uploaded data streams are sent to the data communication network in sequence, so that the data communication network can transmit the uploaded data streams to the main station side in an orderly manner.

[0106] Preferably, the secure data stream generating module is used to perform firewall security processing on the upload data stream received by the master station side to obtain a secure data stream, including:

[0107] Monitoring the master station's reception process of the uploaded data stream from the data communication network, and identifying abnormal time nodes of the master station's reception of the uploaded data stream; wherein the abnormal time node refers to the time node when the data flow rate exceeds a preset flow threshold during the master station's reception of the uploaded data stream;

[0108] According to the data flow corresponding to the abnormal time node, the uploaded data stream received by the main station is isolated and filtered by the firewall in the main station to obtain a safe data stream;

[0109] The data fragment feature recognition module is used to identify the data fragment features of the secure data stream, including:

[0110] Identify the content type distribution characteristics of data segments in secure data streams.

[0111] Considering that the data communication network is in an open state, the data communication network is susceptible to external interference when transmitting the uploaded data stream from the terminal side to the main station side. During the transmission process, the uploaded data stream may be affected by other terminals connected to the data communication network and embedded with virus data, forming a traffic attack using the uploaded data stream as a carrier, resulting in excessive traffic when the data communication network transmits the uploaded data to the main station side. To protect the main station side from traffic attacks, the main station side monitors the process of receiving the uploaded data stream from the data communication network, identifies abnormal time nodes when the uploaded data stream is received on the main station side, and uses the firewall within the main station to isolate and filter viruses on the uploaded data stream received on the main station side based on the data traffic corresponding to the abnormal time nodes, thereby obtaining a safe data stream and reducing the security risk of the uploaded data received by the main station side. In addition, the content type distribution characteristics of the data fragments of the safe data stream are identified, and the content types of all data fragments contained in the safe data stream received by the main station side are comprehensively calibrated, providing an accurate basis for subsequent data stream restoration.

[0112] Preferably, the data stream segmentation module is used to segment the secure data stream into several data sub-streams according to the characteristics of the data segments, including:

[0113] Determine the position boundary of data segments of the secure data stream based on the content type distribution characteristics of the data segments of the secure data stream; wherein the data segment position boundary refers to the character boundary between two adjacent data segments with different content types in the secure data stream;

[0114] The secure data stream is divided into several data segments according to the data segment position boundaries, and then all data segments with the same content type are integrated into data sub-streams according to the original time sequence, thereby dividing the secure data stream into several data sub-streams;

[0115] The data transmission module is used to obtain the business operation status of the service platform on the master station side and transmit the data sub-stream to the service platform, including:

[0116] Obtain the business operation status of all service platforms on the master station side, determine the schedulable computing resources of all service platforms for different business tasks; based on the schedulable computing resources, transmit each data sub-stream to the matching service platform.

[0117] Considering that the security data stream contains monitoring data from different terminals, it cannot be directly transmitted to the service platform for business processing. Instead, the monitoring data segments from different terminals within the security data stream must be extracted separately and all monitoring data segments from the same terminal must be integrated into complete data substreams before they can be transmitted to the service platform for business processing. To this end, the data segment location boundaries of the security data stream are calibrated based on the content type distribution characteristics of the data segments in the security data stream. The security data stream is then segmented into several data segments based on the data segment location boundaries. All data segments with the same content type are then integrated into data substreams according to their original time sequence, thus segmenting the security data stream into several data substreams. Finally, the business operation status of all service platforms on the master side is obtained, and the schedulable computing resources of each service platform for different business tasks are determined. Each data substream is then transmitted to the corresponding service platform, ensuring that each data substream is assigned to a service platform with appropriate computing resources to execute business processing, thereby ensuring the normal and rapid execution of substation operation and maintenance services.

[0118] As can be seen from the contents of the above embodiments, the WAPI network communication control method and system for substations identifies the access request received by the WAPI wireless network of the substation from the terminal side, determines the service characteristics of the terminal side, and allocates a wireless access point to the terminal; forms an upload data stream in the station switching network, performs substation firewall processing on the upload data stream and sends it to the data communication network; performs main station firewall security processing on the upload data stream received on the master station side, and identifies the data segment characteristics of the security data stream, thereby dividing the security data stream into several data sub-streams; obtains the business operation status of the service platform on the master station side, and transmits the data sub-streams to the service platform; uses WAPI technology to set up a wireless access point on the terminal side, and establishes a safe and reliable WAPI communication network on the terminal side, the site switching network, the data communication network and the master station side, providing a reliable wireless communication solution for the digital business scenario of the substation and realizing safe and stable operation and maintenance of the substation.

[0119] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A WAPI network communication control method for a substation, characterized in that: It includes the following steps: Step S1: The WAPI wireless network of the identification substation receives an access request from a terminal side, determines the service characteristics of the terminal side, and allocates a wireless access point to the terminal accordingly; Step S2, obtaining data flow characteristics of all wireless access points and forming an upload data flow in the intra-site switching network; After the uploaded data stream is processed by the firewall in the substation, the uploaded data stream is sent to the data communication network; Step S3, performing security processing on the upload data stream received by the master station side using the firewall in the master station to obtain a secure data stream, and identifying data segment features of the secure data stream; Step S4: dividing the secure data stream into several data sub-streams according to the characteristics of the data segments; obtaining the business operation status of the service platform on the master station side, and transmitting the data sub-streams to the service platform.

2. The WAPI network communication control method for a substation according to claim 1, wherein: In step S1, the WAPI wireless network of the authentication substation receives an access request from a terminal side, determines the service characteristics of the terminal side, and allocates a wireless access point to the terminal, including: Collect and analyze all access requests received from the terminal side of the substation's WAPI wireless network, and obtain the terminal identity information and execution task information that initiated the access request; Determining at least one wireless access point matching the terminal based on the terminal identity information; determining a service interaction bandwidth requirement characteristic of the terminal based on the execution task information; According to the service interaction bandwidth requirement characteristics and the bandwidth information allowed to be provided by each of the at least one wireless access point, the terminal is allocated to connect to one of the wireless access points.

3. The WAPI network communication control method for a substation according to claim 1, wherein: In step S2, data flow characteristics of all wireless access points are obtained, and an upload data flow is formed in the intra-site switching network; After performing firewall processing on the uploaded data stream within the substation, the uploaded data stream is sent to the data communication network, including: Obtain the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, and classify and integrate the data streams from all wireless access points in the in-station switching network to form several upload data streams; Identify the abnormal sample distribution characteristics of the uploaded data stream, perform virus isolation and filtering on the uploaded data stream using the firewall in the substation, and then send all uploaded data streams to the data communication network in sequence according to their respective timing characteristics.

4. The WAPI network communication control method for a substation according to claim 1, wherein: In step S3, the uploaded data stream received by the master station is subjected to firewall security processing within the master station to obtain a secure data stream, and data segment features of the secure data stream are identified, including: Monitoring the master station's reception process of an upload data stream from a data communication network, and identifying an abnormal time node of the master station's reception of the upload data stream; wherein the abnormal time node refers to a time node when the data flow rate exceeds a preset flow threshold during the master station's reception of the upload data stream; According to the data flow corresponding to the abnormal time node, the uploaded data stream received by the main station side is virus isolated and filtered by the firewall in the main station to obtain a safe data stream, and the data segment content type distribution characteristics of the safe data stream are identified.

5. The WAPI network communication control method for a substation according to claim 1, wherein: In step S4, the secure data stream is divided into a plurality of data sub-streams according to the characteristics of the data segments; the business operation status of the service platform on the master station side is obtained, and the data sub-streams are transmitted to the service platform, including: Determining the data segment position boundary of the secure data stream based on the content type distribution characteristics of the data segments of the secure data stream; wherein the data segment position boundary refers to the character boundary between two adjacent data segments with different content types in the secure data stream; dividing the secure data stream into a plurality of data segments according to the position boundaries of the data segments, and then integrating all data segments with the same content type into data sub-streams according to their original time sequence, thereby dividing the secure data stream into a plurality of data sub-streams; Obtain the business operation status of all service platforms on the master station side, determine the schedulable computing power resources of all service platforms for different business tasks; based on the schedulable computing power resources, transmit each data sub-stream to the matching service platform.

6. The WAPI network communication control system for substations is characterized by: include: The terminal side identification module is used to identify the access request received from the terminal side by the WAPI wireless network of the substation and determine the service characteristics of the terminal side; A wireless access point allocation module, configured to allocate a wireless access point to a terminal according to service characteristics of the terminal side; The data flow integration module is used to obtain the data flow characteristics of all wireless access points and form an upload data flow in the intra-site switching network; A data stream sending module, configured to process the uploaded data stream through a firewall within the substation and then send the uploaded data stream to a data communication network; The secure data stream generation module is used to perform firewall security processing on the uploaded data stream received by the master station to obtain a secure data stream; A data segment feature recognition module, configured to recognize features of data segments of the secure data stream; A data stream segmentation module, configured to segment the secure data stream into a plurality of data sub-streams according to characteristics of the data segments; The data transmission module is used to obtain the business operation status of the service platform on the master station side and transmit the data sub-stream to the service platform.

7. The WAPI network communication management and control system for a substation according to claim 6, characterized in that: The terminal side identification module is used to identify the access request received from the terminal side by the WAPI wireless network of the substation and determine the service characteristics of the terminal side, including: Collect and analyze all access requests received from the terminal side of the substation's WAPI wireless network, and obtain the terminal identity information and execution task information that initiated the access request; Determining at least one wireless access point matching the terminal based on the terminal identity information; determining a service interaction bandwidth requirement characteristic of the terminal based on the execution task information; The wireless access point allocation module is configured to allocate a wireless access point to the terminal according to service characteristics of the terminal side, including: According to the service interaction bandwidth requirement characteristics and the bandwidth information allowed to be provided by each of the at least one wireless access point, the terminal is allocated to connect to one of the wireless access points.

8. The WAPI network communication management and control system for a substation according to claim 6, characterized in that: The data flow integration module is used to obtain data flow characteristics of all wireless access points and form an upload data flow in the intra-site switching network, including: Obtain the data flow characteristics and data stream code format characteristics received by all wireless access points from the terminal, and classify and integrate the data streams from all wireless access points in the in-station switching network to form several upload data streams; The data stream sending module is used to perform firewall processing on the uploaded data stream within the substation and then send the uploaded data stream to the data communication network, including: Identify the abnormal sample distribution characteristics of the uploaded data stream, perform virus isolation and filtering on the uploaded data stream using the firewall in the substation, and then send all uploaded data streams to the data communication network in sequence according to their respective timing characteristics.

9. The WAPI network communication management and control system for a substation according to claim 6, characterized in that: The secure data stream generation module is used to perform firewall security processing on the upload data stream received by the master station to obtain a secure data stream, including: Monitoring the master station's reception process of an upload data stream from a data communication network, and identifying an abnormal time node of the master station's reception of the upload data stream; wherein the abnormal time node refers to a time node when the data flow rate exceeds a preset flow threshold during the master station's reception of the upload data stream; According to the data flow corresponding to the abnormal time node, the uploaded data stream received by the master station side is subjected to virus isolation and filtering by the firewall in the master station to obtain a safe data stream; The data segment feature identification module is used to identify the data segment features of the secure data stream, including: Identify content type distribution characteristics of data segments of the secure data stream.

10. The WAPI network communication management and control system for a substation according to claim 6, characterized in that: The data stream segmentation module is configured to segment the secure data stream into a plurality of data sub-streams according to the data segment characteristics, including: Determining the data segment position boundary of the secure data stream based on the content type distribution characteristics of the data segments of the secure data stream; wherein the data segment position boundary refers to the character boundary between two adjacent data segments with different content types in the secure data stream; dividing the secure data stream into a plurality of data segments according to the position boundaries of the data segments, and then integrating all data segments with the same content type into data sub-streams according to their original time sequence, thereby dividing the secure data stream into a plurality of data sub-streams; The data transmission module is used to obtain the business operation status of the service platform on the master station side and transmit the data sub-stream to the service platform, including: Obtain the business operation status of all service platforms on the master station side, determine the schedulable computing power resources of all service platforms for different business tasks; based on the schedulable computing power resources, transmit each data sub-stream to the matching service platform.