Information physical security defense method, system and equipment based on distribution network digital twin simulation platform, and medium

By constructing a digital twin simulation platform for distribution networks, the three-dimensional interaction and dynamic transformation between the physical power grid and the information model are realized. Combined with multi-level risk modeling and defense strategy generation, the problem of cyber-physical fusion simulation under large-scale multi-source load access conditions of traditional simulation platforms is solved, thereby improving the security defense capability and simulation accuracy of the distribution system.

CN120915560APending Publication Date: 2025-11-07GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202511183572.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing methods are insufficient to achieve cyber-physical fusion simulation under conditions of large-scale, multi-source load access. Traditional simulation platforms are also unable to achieve unified modeling, time-series coordination, and joint control when facing complex disturbances and information attacks, making it difficult for system simulation to meet the needs of rapid response and security defense.

Method used

A digital twin simulation platform based on the distribution network is constructed to realize data interaction between the physical power grid and the information model through a three-dimensional channel. A topology mapping structure and interaction mechanism are established, and a three-state dynamic transformation model between steady state, transient state and recovery state is constructed. A multi-level risk modeling system is adopted to identify complex attack scenarios. Defense strategies are generated by combining the risk identification results, and intelligent collaboration and continuous learning of cross-domain defense strategies are realized.

Benefits of technology

It enhances the robustness and responsiveness of power distribution systems in the face of cyber-physical attacks, improves the scalability, compatibility, and overall effectiveness of the simulation platform and defense strategies, supports minute-level scenario reconstruction and parameter tuning, and realizes quantitative analysis and high-precision synchronous simulation of cross-domain risks caused by network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915560A_ABST
    Figure CN120915560A_ABST
Patent Text Reader

Abstract

The invention discloses an information physical security defense method, system and device based on a distribution network digital twin simulation platform and a medium, and belongs to the technical field of information security and control defense of the power distribution Internet of Things, and the method comprises the steps: constructing a three-dimensional channel for interaction of a physical power grid, an information model and simulation data; on the basis of a three-dimensional channel, a three-state dynamic conversion model among a steady state, a transient state and a recovery state is constructed, and multi-state automatic switching simulation is achieved through sub-region division and parallel computing; a multi-level risk modeling system oriented to various risks is constructed based on simulation results, complex attack scenes are identified, and mapping of risk types and response paths is achieved; security risk assessment and defense strategy generation verification are completed, and intelligent collaboration and continuous learning of cross-domain defense strategies are achieved through collaborative optimization. According to the method, the construction efficiency of a complex risk scene is improved, quantitative analysis of cross-domain risks such as circuit breaker mis-tripping caused by network attacks is realized, and the limitation of traditional single-domain risk analysis is broken through.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of power distribution Internet of Things information security and control defense, and particularly relates to an information physical security defense method, system, equipment and medium based on a power distribution network digital twin simulation platform. BACKGROUND

[0002] With the continuous expansion of the scale of the new power distribution Internet of Things system and the increasing complexity of its structure, the power distribution system is gradually evolving into a typical information-physical fusion system. In this system, the running state of the electrical side is highly coupled with the communication interaction of the information side, and the traditional simulation technology that only focuses on the running rules of the physical side has been difficult to meet the actual needs of the full-domain perception, rapid response and security defense of the power distribution system. Especially in the background of a large number of distributed power sources, large-capacity energy storage, flexible loads and intelligent terminals, the uncertainty of system operation increases significantly, and higher requirements are put forward for the cross-domain modeling capability and information interaction simulation accuracy of the simulation platform.

[0003] At present, although the traditional physical simulation tool has strong power system modeling and analysis capability, it has limitations in dealing with dynamic behaviors such as communication interference and information attacks. While the communication network simulation tool has flexibility in information simulation, it is difficult to accurately respond to the dynamic state of the electrical side. There are fundamental differences between the two types of platforms in modeling language, data format and time scheduling mechanism, which leads to difficulties in unified modeling, time sequence coordination and joint control of system simulation. In addition, under complex disturbance scenarios such as denial of service, fake data, command tampering and other attack behaviors, serious physical abnormalities or even system paralysis can be caused, and existing simulation platforms are difficult to effectively deduce and verify strategies.

[0004] Although some researches have attempted to combine power simulation and network simulation platforms, or build a joint simulation environment based on middleware, due to the dispersion of models, complexity of interfaces and imperfect synchronization mechanism, it is still difficult to meet the information-physical fusion simulation needs under the condition of large-scale, multi-source load access.

[0005] Based on the above problems, the present application proposes an information physical security defense method based on a power distribution network digital twin simulation platform, which realizes functions such as virtual-real fusion, attack injection, linkage control and strategy verification, and improves the robustness and response ability of the power distribution system to information physical attacks. SUMMARY

[0006] In view of the above problems, the present application is proposed.

[0007] Therefore, the technical problem solved by the present application is: how to solve the existing method has part of research attempts to combine power simulation and network simulation platform, or based on middleware way to build joint simulation environment, but limited by model dispersion, interface complex and synchronization mechanism is not perfect, still difficult to meet the information physical fusion simulation demand under the condition of large-scale, multi-source load access.

[0008] To solve the above technical problems, the present application provides the following technical solutions: an information physical security defense method based on a distribution network digital twin simulation platform, comprising: constructing a three-dimensional channel for interaction of physical power grid, information model and simulation data, forming a topology mapping structure and interaction mechanism supporting virtual-real fusion;On the basis of the three-dimensional channel, a three-state dynamic conversion model between steady state, transient state and recovery state is constructed, automatic switching simulation of operating state is realized through sub-region division and parallel computing;Based on the simulation results, a multi-level risk modeling system for various risks is constructed, complex attack scenarios including false data injection are identified, and the mapping of risk types and response paths is realized;Combined with the risk identification results, security risk assessment and defense strategy generation verification are completed, and intelligent collaboration and continuous learning of cross-domain defense strategies are realized through collaborative optimization.

[0009] As a preferred scheme of the information physical security defense method based on the distribution network digital twin simulation platform, wherein: the three-dimensional channel for interaction of physical power grid, information model and simulation data comprises: establishing a topological correspondence relationship between physical entities and digital images through data mapping;Based on the interaction control mechanism, the energy flow and information flow are realized bidirectional collaboration;Simulation verification realizes real-time synchronization check of virtual-real interaction process.

[0010] As a preferred scheme of the information physical security defense method based on the distribution network digital twin simulation platform, wherein: on the basis of the three-dimensional channel, the three-state dynamic conversion model between steady state, transient state and recovery state is constructed, and the automatic switching simulation of operating state is realized through sub-region division and parallel computing, comprising: adopting parallel computing architecture, the distribution network is divided into multiple electrically coupled sub-regions;The simulation task of each sub-region is assigned to an independent computing node for execution;The interaction behavior of each sub-region is coordinated through a global clock synchronization mechanism.

[0011] As a preferred scheme of the information physical security defense method based on the network distribution digital twin simulation platform, the simulation result based multi-level risk modeling system is constructed, complex attack scenarios including false data injection are identified, the mapping of risk types and response paths is realized, including providing full life cycle risk pre-play ability, constructing physical risk, information risk and information physical coupling risk classification model; the risk coupling model is constructed, the correlation between different types of risks is established; the strategy linkage verification structure is constructed, the trigger relationship of risk events and control strategies is organized; the recovery path deduction process is constructed, and the set of backtracking paths from the abnormal state to the target state is defined.

[0012] As a preferred scheme of the information physical security defense method based on the network distribution digital twin simulation platform, the data mapping includes a dynamic data lake architecture with flow batch integration; the data mapping establishes the topological association matrix of information space and power grid physical system, realizes the unique digital mirror image of each physical entity through device coding mapping; the energy flow and information flow two-way feedback channel constructed by the interactive control mechanism realizes the space-time alignment of physical side power transmission and information side state monitoring; the simulation verification realizes real-time correction of parameter deviation of simulation model through information and physical coupling closed loop feedback.

[0013] The preferred scheme can realize accurate mapping of power grid physical structure and information space in the background of multi-source heterogeneous data fusion by constructing a topological association matrix through a dynamic data lake architecture with flow batch integration; the interaction between information and physical systems has uniqueness and traceability through digital mirror positioning combined with device coding; the state alignment path can be effectively supported through the two-way feedback channel of energy flow and information flow, which can effectively support the space-time synchronization between virtual and real; the simulation environment can be dynamically updated by combining closed loop feedback to correct model parameters, ensuring the accuracy and real-time of the simulation process.

[0014] As a preferred scheme of the information physical security defense method based on the network distribution digital twin simulation platform, the three-state dynamic conversion model between steady state, transient state and recovery state is constructed, including the segmented simulation mechanism based on event triggering, the three-state automatic switching of steady state operation mode, transient simulation mode and recovery reconstruction mode; the random process modeling and scene generation function are integrated, and the joint probability distribution scene of uncertain factors is generated through Monte Carlo simulation and Latin hypercube sampling technology.

[0015] The preferred scheme can realize automatic switching among the three operating states through an event-triggered segmented simulation mechanism, thereby covering the whole process dynamic evolution of the system from normal to abnormal and then to recovery;And the combined probability distribution scenarios generated by the Monte Carlo simulation and the Latin hypercube sampling technology can enhance the performance of the model in the uncertain environment and improve the coverage in the complex fault conditions.

[0016] As a preferred scheme of the information physical security defense method based on the digital twin simulation platform for distribution network, the combination of the risk identification result is used to complete the security risk assessment and defense strategy generation verification, and the intelligent cooperation and continuous learning of the cross-domain defense strategy are realized through collaborative optimization, including that the security risk assessment realizes the security situation quantitative analysis of multi-source data fusion, and the defense strategy generation constructs a three-level defense strategy library of preventive control, emergency control and recovery control;The security risk assessment constructs a three-dimensional evaluation space, and the influence of external events, internal events and security index quantization risks is quantified;The preventive control includes device inspection optimization, protection setting adjustment and network firewall rule update;The collaborative optimization realizes the cross-domain cooperation of network security isolation strategy and electrical protection action strategy through the establishment of a strategy correlation matrix.

[0017] The preferred scheme can construct a three-dimensional evaluation space, and can quantize the current risk situation of the system based on external events, internal events and security index multi-dimensional;The three-level defense strategy library constructed based on this can cover the control requirements of the whole cycle of prevention, emergency and recovery;The collaborative optimization establishes the linkage relationship between the network and electrical strategies through the strategy correlation matrix, and can realize the cooperative consistency and response closed loop among the cross-domain security strategies.

[0018] The application provides an information physical security defense system based on a digital twin simulation platform for distribution network.

[0019] To solve the above technical problems, the application provides the following technical scheme: an information physical security defense system based on a digital twin simulation platform for distribution network, comprising: an interactive channel construction module, a model construction module, a risk identification module and a strategy generation module;The interactive channel construction module is used to construct a three-dimensional channel for the interaction of physical power grid, information model and simulation data, forming a topology mapping structure and an interaction mechanism supporting virtual-real fusion;The model construction module is used to construct a three-state dynamic conversion model among steady state, transient state and recovery state on the basis of the three-dimensional channel, and realize automatic switching simulation of operating state through sub-region division and parallel computing;The risk identification module is used to construct a multi-level risk modeling system for various risks based on the simulation results, identify complex attack scenarios including false data injection, and realize the mapping of risk type and response path;The strategy generation module is used to complete the security risk assessment and defense strategy generation verification in combination with the risk identification result, and realize the intelligent cooperation and continuous learning of the cross-domain defense strategy through collaborative optimization.

[0020] The application provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and wherein the processor implements the steps of the information physical security defense method based on the network configuration digital twin simulation platform when executing the computer program.

[0021] The application provides a computer readable storage medium, which stores a computer program, and wherein the computer program implements the steps of the information physical security defense method based on the network configuration digital twin simulation platform when executed by a processor.

[0022] The application has the beneficial effects that: the application builds the whole-chain simulation capability of scene construction, risk injection and strategy verification, realizes the flexible configuration of topology structure, device parameters and load distribution by using an open scene self-defined platform, significantly improves the construction efficiency of complex risk scenes compared with the traditional fixed scene simulation method, and supports minute-level scene reconstruction and parameter optimization.

[0023] The application adopts a risk coupling modeling technology, establishes a correlation matrix of device physical failure probability and information attack success rate, realizes the quantitative analysis of cross-domain risks such as circuit breaker mis-trip caused by network attacks, and breaks through the limitations of traditional single-domain risk analysis.

[0024] The application builds a dynamic data lake and adopts a heterogeneous protocol adaptation technology, uses a flow-batch integrated data storage architecture and a general data conversion middleware, simultaneously supports historical data backtracking simulation and real-time data online simulation, and improves the expansibility and compatibility of the simulation platform.

[0025] The application adopts a differential-algebraic hybrid equation set to build a power grid dynamic model in the dynamic deduction of the distribution network form, uses a dynamic topology analysis technology and a time-varying delay compensation algorithm, and realizes high-precision synchronous simulation of device-level fast transient and system-level dynamic process.

[0026] The application uses a Monte Carlo simulation and a Latin hypercube sampling technology, generates a joint probability distribution scene covering various uncertainty factors by using random process modeling, and improves the simulation accuracy in the high-proportion distributed energy access scene.

[0027] The application adopts a three-dimensional evaluation space model in the security defense analysis, quantifies the overall security level of the system by using an analytic hierarchy process and a fuzzy comprehensive evaluation method, and improves the risk identification accuracy compared with a single index evaluation model.

[0028] The application builds a strategy correlation matrix, uses a collaborative optimization algorithm to coordinate the execution time sequence of preventive control, emergency control and recovery control, effectively avoids the conflict problem of traditional independent strategies, and improves the overall efficiency of the defense strategy. Attached Figure Description

[0029] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0030] Figure 1 This is a flowchart illustrating an overall cyber-physical security defense method based on a digital twin simulation platform for power distribution networks, as provided in one embodiment of the present invention.

[0031] Figure 2 This diagram illustrates the changes in security indicators of a cyber-physical security defense method based on a distribution network digital twin simulation platform, as provided in one embodiment of the present invention.

[0032] Figure 3 This invention provides a power grid security state evolution diagram for a cyber-physical security defense method based on a distribution network digital twin simulation platform, as an embodiment of the present invention. Detailed Implementation

[0033] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0034] Example 1, referring to Figure 1 This is one embodiment of the present invention, which provides a cyber-physical security defense method based on a distribution network digital twin simulation platform, comprising:

[0035] Step 1: Construct a three-dimensional channel for interaction between the physical power grid, information model, and simulation data, forming a topology mapping structure and interaction mechanism that supports the integration of virtual and real worlds.

[0036] Step 2: Based on the three-dimensional channel, construct a three-state dynamic transition model between steady state, transient state and recovery state, and realize the automatic switching simulation of the running state through sub-region partitioning and parallel computing.

[0037] Step 3: Based on the simulation results, construct a multi-level risk modeling system for various risks, identify complex attack scenarios including fake data injection, and realize the mapping between risk types and response paths.

[0038] Step four, complete the security risk assessment and defense strategy generation verification based on the risk identification results, and realize the intelligent cooperation and continuous learning of cross-domain defense strategies through cooperation optimization.

[0039] It should be noted that as the operation environment of the power distribution network becomes increasingly complex, network attacks and device abnormalities may occur simultaneously, causing cross-interference between physical and information systems, and traditional monitoring methods cannot support cross-domain response, which may lead to risk propagation and defense lag. At the same time, the existing simulation method has insufficient response accuracy for dynamic scenarios, and cannot fully predict the real operation situation of the power distribution network under disturbance.

[0040] Therefore, in view of the above problems, the technical process of steps one to four is used to build a data channel structure covering information and physical cooperation, support full-process dynamic simulation under complex conditions, provide modeling and response mechanisms for composite risks, and realize the cooperative optimization of cross-domain security strategies, thereby improving the overall security defense capability and adaptability of the power distribution network.

[0041] Embodiment 2, with reference to Figure 2 For an embodiment of the present application, based on the above embodiment, an information-physical security defense method based on a power distribution network digital twin simulation platform is provided, comprising:

[0042] In step one, a three-dimensional channel for interaction of physical power grid, information model and simulation data is constructed to form a topology mapping structure and interaction mechanism supporting virtual-real fusion, including steps A1-A3:

[0043] A1, a topology correspondence relationship between physical entities and digital images is established through data mapping.

[0044] A2, realize the bidirectional cooperation of energy flow and information flow based on the interaction control mechanism.

[0045] A3, simulation verification realizes real-time synchronization verification of virtual-real interaction process.

[0046] In the present application, the data mapping in step A1 can be to establish a topology correspondence relationship between the information model and the physical power grid, and a mapping matrix is constructed by device identification and node information to realize one-to-one correspondence between the physical structure of the power distribution network and the digital image. The data mapping adopts a dynamic data lake architecture integrating flow and batch.

[0047] In an optional embodiment, the data mapping can also be based on device coding rules to define the identification structure of physical devices in the information space, ensuring traceability between the data structure and the physical topology.

[0048] In another optional embodiment, the data mapping can also adopt a dynamic data lake architecture of stream batch integration, support multi-type data fusion and update, and enable continuous dynamic synchronization of data on the physical side and the information side.

[0049] The application constructs a physical and information bidirectional mapping structure with structural consistency and timeliness, supports precise alignment and continuous update of digital twins in the distribution network system, and improves the integrity and synchronization of virtual and real interactions.

[0050] In the embodiment of the application, the interaction control mechanism in step A2 can be a constructed energy flow and information flow bidirectional feedback channel, realizing spatiotemporal alignment of physical side electric energy transmission and information side state monitoring

[0051] In an optional embodiment, the interaction control mechanism can also be a bidirectional synchronization path set between state monitoring and control commands, realizing real-time closed-loop transmission of operation data on the information side and the physical side.

[0052] In another optional embodiment, the interaction control mechanism can also be a cross-level state linkage structure formed by coordinating data update rhythms of multiple system submodules through a unified scheduling module.

[0053] The application can realize accurate coupling of energy flow and information flow in time sequence and logic, and ensure consistency and real-time response of the simulation platform in the multi-source state perception, feedback verification and strategy scheduling process.

[0054] Specifically, in step A3, the simulation verification is performed through the closed-loop feedback of information and physical coupling, and the parameter deviation of the simulation model is corrected in real time.

[0055] The data mapping relationship and the interaction control channel are constructed, and the simulation verification is performed. This step can perform real-time synchronous verification on the virtual and real interaction process based on the physical entity, digital mirror image and simulation data ternary model conversion rule, and complete multi-modal data fusion and instruction conversion according to the operation requirement of the simulation platform.

[0056] The virtual and real interaction is realized through the triple coupling mechanism, the spatial fusion mechanism establishes a topological association matrix of the information space and the power grid physical system, and the one-to-one correspondence between the physical entity and the digital mirror image is realized through device coding mapping; the interaction control mechanism constructs a bidirectional feedback channel of energy flow and information flow, ensuring spatiotemporal alignment of physical side electric energy transmission and information side state monitoring; the simulation verification is performed based on closed-loop feedback to correct the parameter deviation of the simulation model in real time, and the system is driven to evolve to an optimal state. The full life cycle risk of the power distribution Internet of Things can be dynamically simulated based on the trinity simulation rules of risk factors, defense strategies and deduction evaluation, and multi-dimensional defense strategies are verified and optimized according to the security protection requirement.

[0057] In the embodiment of the application, the three-state dynamic conversion model between the steady state, the transient state and the recovery state in step two can be constructed by constructing a differential-algebraic hybrid equation set to uniformly describe the dynamic evolution characteristics of the power distribution network in different operating states, so that each state has continuous switching capability. The differential-algebraic hybrid equation is used to construct the three-state conversion model of the steady state, the transient state and the recovery state to realize high-precision simulation of the full dynamic process of the power distribution network. The dynamic topology analysis technology is integrated to support dynamic switching simulation of complex scenarios such as island operation and microgrid splitting.

[0058] In an alternative embodiment, the three-state dynamic conversion model between the steady state, the transient state and the recovery state can also be: dividing the power distribution network into multiple electrically coupled regions, and configuring an independent simulation task for each sub-region based on a parallel computing architecture, and switching the three states through an event-driven mechanism.

[0059] In another alternative embodiment, the three-state dynamic conversion model between the steady state, the transient state and the recovery state can also be: establishing a global clock synchronization mechanism to coordinate the simulation timing of each region, and realizing state collaborative switching and boundary consistency control between multiple regions.

[0060] The application can accurately simulate the complete state evolution process of the power distribution network under typical operating disturbances, and improve the comprehensive performance of the dynamic simulation system in terms of state switching accuracy and real-time response capability.

[0061] Further, in step two, a three-state dynamic conversion model between the steady state, the transient state and the recovery state is constructed based on the three-dimensional channel, and automatic switching simulation of the operating state is realized through sub-region division and parallel computing, including the following steps B1-B3:

[0062] B1, using a parallel computing architecture, the power distribution network is divided into multiple electrically coupled sub-regions.

[0063] B2, the simulation task of each sub-region is assigned to an independent computing node for execution.

[0064] B3, the interaction behavior of each sub-region is coordinated through a global clock synchronization mechanism.

[0065] Specifically, in step B3, a segmented simulation mechanism based on event triggering is supported, which includes three-state automatic switching of the steady state operation mode, the transient simulation mode and the recovery reconstruction mode; random process modeling and scenario generation functions are integrated to generate joint probability distribution scenarios of uncertain factors through Monte Carlo simulation and Latin hypercube sampling technology.

[0066] The differential-algebraic hybrid equation is used to construct the three-state conversion model of the steady state, the transient state and the recovery state to realize high-precision simulation of the full dynamic process of the power distribution network. The dynamic topology analysis technology is integrated to support dynamic switching simulation of complex scenarios such as island operation and microgrid splitting.

[0067] The power distribution network form dynamic process deduction step realizes multi-scale dynamic simulation of the power distribution network from steady-state operation to fault evolution, and solves the problem that the traditional method is difficult to depict a nonlinear process. Dynamic topology analysis, time-varying delay compensation and segmented simulation mechanism are used to accurately simulate the fault transient characteristics and recovery process. Support for distributed energy random scenario generation (such as light / wind speed fluctuation) and island operation mode switching, and integration of information, physical cross-domain joint simulation, reveal the cascading effect of network attacks and device failures. Through parallel computing and multi-source data fusion, both simulation efficiency and accuracy are taken into account.

[0068] In the embodiments of the present application, the step three of constructing a multi-level risk modeling system for various risks can be to set up three risk model structures of physical risk, information risk and information-physical coupling risk in the power distribution network digital twin simulation platform, and respectively establish risk classification nodes mapped with system states. Provide full life cycle risk pre-play capability, support three-level simulation of physical risk, information risk and information-physical coupling risk, and have risk coupling modeling, strategy linkage verification and recovery path deduction functions.

[0069] In an alternative embodiment, the multi-level risk modeling system for various risks can also be to construct a risk coupling relationship network to express the interaction paths between different risk types, and configure corresponding response levels and trigger rules.

[0070] In another alternative embodiment, the multi-level risk modeling system for various risks can also be to organize residual error detection, space-time correlation verification and structure verification mechanisms based on false data injection scenarios to constitute a response process with multi-level verification capability.

[0071] The present application can cover multiple types of composite risk events that may occur under complex operating environments, and realize cross-domain risk identification and linkage, effectively improving the protection capability and response accuracy of the system under uncertain scenarios.

[0072] Further, in step three, a multi-level risk modeling system for various risks is constructed based on simulation results to identify complex attack scenarios including false data injection, and to realize mapping of risk types and response paths, including the following steps C1-C4:

[0073] C1. Provide full life cycle risk pre-play capability, and construct classification models of physical risk, information risk and information-physical coupling risk.

[0074] C2. Construct a risk coupling model to establish the association between different types of risks.

[0075] C3. Construct a strategy linkage verification structure to organize the trigger relationship between risk events and control strategies.

[0076] C4, construct recovery path deduction process, define the rollback path set from the abnormal state to the target state.

[0077] Specifically, in step C1, the physical risk includes 12 types of device failures such as short circuit, lightning strike, and device aging; the information risk includes 8 types of network threats such as data tampering and protocol attack; and the information-physical coupling risk includes cross-domain risks such as false data injection causing protection misoperation.

[0078] The typical simulation deduces the risk scenario simulation through an open scenario construction platform (including five core components of algorithm example customization, event arrangement, data simulation, etc.), supports the full life cycle pre-performance of physical risk, information risk and information-physical coupling risk, and integrates risk coupling modeling, strategy linkage verification and recovery path deduction functions. The risk scenario simulation step can realize the response within 800ms of network security attack.

[0079] Based on the steady state, transient state and recovery state conversion mechanism, the full dynamic process of the distribution network can be simulated with high precision in multiple time scales, and the strategy verification and optimization under complex scenarios can be completed according to the operation demand.

[0080] Further, in step four, the risk identification result is combined to complete the security risk assessment and defense strategy generation verification, and the intelligent collaboration and continuous learning of cross-domain defense strategy are realized through collaborative optimization, including the following steps D1-D4:

[0081] D1, security risk assessment realizes the security situation quantitative analysis of multi-source data fusion, and the defense strategy generation constructs the three-level defense strategy library of preventive control, emergency control and recovery control.

[0082] D2, security risk assessment constructs a three-dimensional evaluation space, and quantifies the risk influence through external events, internal events and security indicators.

[0083] D3, preventive control includes device inspection optimization, protection setting adjustment, and network firewall rule update.

[0084] D4, collaborative optimization realizes the cross-domain collaboration of network security isolation strategy and electrical protection action strategy by establishing a strategy correlation matrix.

[0085] The distribution network security defense analysis constructs a three-dimensional security evaluation space (external event / internal state / security indicator) based on multi-source data, quantifies the risk and generates a three-level defense strategy library of prevention, emergency and recovery. Through strategy collaborative optimization and virtual verification, defense conflicts are avoided and response efficiency is improved. The built-in state machine model (7 kinds of running states) and machine learning mechanism realize the dynamic perception of situation and self-optimization of strategy. Combined with the visualization tool, risk positioning, strategy comparison and backtracking support are provided for decision makers, forming a closed-loop management of security defense. For example Figure 2The security situation of the power distribution network can be multi-dimensionally quantitatively analyzed based on a monitoring, evaluation and defense closed-loop management mechanism, and a targeted defense strategy scheme is generated according to the risk level. The security defense analysis step is provided with a strategy correlation matrix analysis tool.

[0086] The security risk evaluation constructs a three-dimensional evaluation space, quantifies the risk influence through an x-axis (external event), a y-axis (internal event) and a z-axis (security index); the defense strategy generation includes preventive control strategies such as device inspection optimization, protection setting adjustment and network firewall rule update; and the coordination optimization realizes cross-field coordination of network security isolation strategies and electrical protection action strategies by establishing a strategy correlation matrix.

[0087] Embodiment 3, refer to Figure 3 As an embodiment of the present application, a power distribution network digital twin simulation platform-based information physical security defense method is provided. In order to verify the beneficial effects of the present application, scientific demonstration is carried out through experiments.

[0088] As Figure 3 shown, the present application presents a security state evolution mechanism of a power distribution network information physical system (CPPS), which clearly divides two stages of safe operation and unsafe operation by adopting a double-level structure. In the safe operation stage, only a single state S1 (normal operation) is included; when the system enters the unsafe operation stage, five progressive sub-states S2 (vulnerability operation) to S6 (system collapse) are subdivided according to the risk severity, which completely covers the whole process from initial risk warning to final system collapse. The conversion between states is driven by a monitoring, warning, defense and evaluation closed-loop mechanism, wherein S4 (alert state) and S5 (emergency state) correspond to the strategy triggering nodes of preventive control and emergency control, respectively.

[0089] The implementation process of the power distribution network digital twin simulation platform-based information physical security defense method is as follows:

[0090] Model preparation and loading stage:

[0091] First, a three-dimensional interactive channel of the physical power grid, information model and simulation data is constructed through the information, physical and data conversion interface steps, spatial fusion is realized, a device coding mapping table is established, the topological association of physical entities and digital images is completed, flow state coordination is realized, the bidirectional feedback channels of energy flow and information flow are configured, and state driving is realized, and the closed-loop feedback parameter correction model is initialized.

[0092] Secondly, the data of each step is prepared, the open scenario construction platform is loaded in the risk scenario simulation step, the dynamic configuration of the topological structure, device parameters and load distribution is supported; the differential-algebraic equation set is configured in the form dynamic deduction step, including the steady state / transient state / recovery three-state model; and the three-dimensional evaluation space model and the strategy correlation matrix are loaded in the security defense analysis step.

[0093] Scene configuration and parameter setting stage:

[0094] Users can select risk types through a visual human-computer interaction interface: physical risks: short circuit, lightning strike, equipment aging, etc.; information risks: FDIA, DDoS, etc.

[0095] Simulation task startup and step invocation:

[0096] After the simulation begins, the system coordinates the operation of each step through a distributed scheduling engine: the risk scenario simulation step injects preset fault or attack events; the morphological dynamic inference step adopts parallel computing, divides the distribution network into sub-regions and assigns them to independent computing nodes, and automatically switches between steady-state / transient / recovery simulation modes according to the event type; the security defense analysis step monitors changes in the three-dimensional evaluation space indicators in real time and triggers the collaborative optimization of the strategy correlation matrix.

[0097] Event-driven and closed-loop verification phase:

[0098] During the simulation, when the system detects a preset event trigger: Timing synchronization: a time-varying delay compensation algorithm is used to correct timing deviations in measurement sampling and communication transmission; For attack response, against FDIA attacks: residual detection (primary), spatiotemporal correlation verification (intermediate), and blockchain verification (advanced) are executed sequentially; against DDoS attacks: backup communication paths are activated first; Closed-loop verification: the virtual environment executes strategies, compares the actual response of the physical system, and corrects the parameters of the evaluation model through a digital twin.

[0099] Results recording and multi-dimensional display stage:

[0100] The simulation platform continuously records the following data during operation: Risk evolution process: the entire lifecycle of state changes from risk injection to system recovery, including data based on... Figure 1 The system's seven operating states (S1-S7) transition sequence and dynamic changes of security indicators in the three-dimensional evaluation space; the effectiveness of defense strategy execution: the verification results of hierarchical defense strategies, including the response effectiveness of FDIA defense strategies (residual detection, spatiotemporal correlation verification, blockchain verification) and the communication recovery time of DDoS defense strategies (dynamic bandwidth allocation, edge caching, multi-mode communication redundancy); system state changes: evaluation indicator system data, including electrical safety indicators (voltage deviation, frequency fluctuation, equipment status indicators (temperature)) and network security indicators (communication latency, data integrity).

[0101] After the simulation is completed, the results are displayed through a 3D visualization interface, and an analysis report containing strategy optimization suggestions is generated.

[0102] The application realizes accurate simulation of multi-dimensional security threats of new power distribution networks by constructing a complete closed loop of risk simulation, dynamic deduction, and defense verification, and has the advantages of high scene construction efficiency (increased by 76%), comprehensive defense strategy verification (covering all stages of prevention, emergency, and recovery), and fast response speed (attack detection time is less than or equal to 800 ms) compared with traditional methods.

[0103] Embodiment 4 is an embodiment of the application, which provides an information-physical security defense system based on a power network digital twin simulation platform, comprising an interaction channel construction module, a model construction module, a risk identification module, and a strategy generation module.

[0104] The interaction channel construction module is used to construct a three-dimensional channel for interaction of physical power grids, information models, and simulation data, forming a topology mapping structure and an interaction mechanism supporting virtual-real fusion.

[0105] The model construction module is used to construct a three-state dynamic conversion model between steady state, transient state, and recovery state on the basis of the three-dimensional channel, and realize automatic switching simulation of operating states through sub-region division and parallel computing.

[0106] The risk identification module is used to construct a multi-level risk modeling system for various risks based on simulation results, identify complex attack scenarios including false data injection, and realize mapping of risk types and response paths.

[0107] The strategy generation module is used to complete security risk assessment and defense strategy generation verification in combination with risk identification results, and realize intelligent collaboration and continuous learning of cross-domain defense strategies through collaborative optimization.

[0108] The embodiment also provides an electronic device suitable for an information-physical security defense method based on a power network digital twin simulation platform, comprising a memory and a processor; the memory is used to store computer executable instructions, and the processor is used to execute the computer executable instructions to realize an information-physical security defense method based on a power network digital twin simulation platform as proposed in the above embodiment.

[0109] The embodiment also provides a storage medium having a computer program stored thereon, which is executed by a processor to realize an information-physical security defense method based on a power network digital twin simulation platform as proposed in the above embodiment.

[0110] The storage medium proposed in the embodiment and the information-physical security defense method based on a power network digital twin simulation platform proposed in the above embodiment belong to the same inventive concept, and technical details not described in detail in the embodiment can be referred to the above embodiment, and the embodiment and the above embodiment have the same beneficial effects.

[0111] From the above description of the embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software and necessary universal hardware, and of course can also be implemented by hardware, but in many cases the former is a better implementation. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a floppy disk, a ROM, a RAM, a FLASH, a hard disk, or an optical disc, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of various embodiments of the present application.

[0112] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application but not limit the present application, and although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application, and all of them should be covered in the scope of the claims of the present application.

Claims

1. A method for information-physical security defense based on a network configuration digital twin simulation platform, characterized in that: The method comprises the following steps: A three-dimensional channel for physical power grid, information model and simulation data interaction is constructed to form a topology mapping structure and an interaction mechanism supporting virtual-real integration; On the basis of the three-dimensional channel, a three-state dynamic conversion model between steady state, transient state and recovery state is constructed to realize automatic switching simulation of the running state through sub-region division and parallel computing; Based on the simulation results, a multi-level risk modeling system for various risks is constructed to identify complex attack scenarios including false data injection and realize the mapping of risk types and response paths; Combined with the risk identification results, security risk assessment and defense strategy generation verification are completed to realize intelligent collaboration and continuous learning of cross-domain defense strategies through collaborative optimization.

2. The information-physical security defense method based on the network configuration digital twin simulation platform of claim 1, wherein: The three-dimensional channel for physical power grid, information model and simulation data interaction comprises the following steps: A topology correspondence relationship between physical entities and digital images is established through data mapping; Based on the interaction control mechanism, bidirectional collaboration of energy flow and information flow is realized; Simulation verification realizes real-time synchronous verification of virtual-real interaction process.

3. The information-physical security defense method based on the network configuration digital twin simulation platform according to claim 2, wherein: On the basis of the three-dimensional channel, a three-state dynamic conversion model between steady state, transient state and recovery state is constructed to realize automatic switching simulation of the running state through sub-region division and parallel computing, The method comprises the following steps: A parallel computing architecture is adopted to divide the power distribution network into multiple electrically coupled sub-regions; The simulation tasks of each sub-region are allocated to independent computing nodes for execution; The interaction behavior of each sub-region is coordinated through a global clock synchronization mechanism.

4. The information-physical security defense method based on the network configuration digital twin simulation platform of claim 3, wherein: Based on the simulation results, a multi-level risk modeling system for various risks is constructed to identify complex attack scenarios including false data injection and realize the mapping of risk types and response paths, which comprises the following steps: A full life cycle risk pre-play capability is provided to construct a classification model of physical risks, information risks and information-physical coupling risks; A risk coupling model is constructed to establish the correlation between different types of risks; A strategy linkage verification structure is constructed to organize the triggering relationship between risk events and control strategies; A recovery path deduction process is constructed to define a set of rollback paths from abnormal state to target state.

5. The information-physical security defense method based on the network configuration digital twin simulation platform of claim 2, wherein: The data mapping comprises a dynamic data lake architecture with flow and batch integration; The data mapping establishes a topology correlation matrix between information space and power grid physical system to realize that each physical entity corresponds to a unique digital image through device code mapping; The interaction control mechanism constructs a bidirectional feedback channel of energy flow and information flow to realize the spatio-temporal alignment of physical side power transmission and information side state monitoring; The simulation verification realizes real-time correction of parameter deviation of the simulation model through information-physical coupling closed-loop feedback.

6. The information-physical security defense method based on the network configuration digital twin simulation platform of claim 5, wherein: The three-state dynamic conversion model between steady state, transient state and recovery state comprises the following steps: An event-triggered segmented simulation mechanism is adopted to realize automatic switching of three states including steady state operation mode, transient simulation mode and recovery reconstruction mode; Random process modeling and scenario generation functions are integrated to generate joint probability distribution scenarios of uncertain factors through Monte Carlo simulation and Latin hypercube sampling technology.

7. The information-physical security defense method based on the network configuration digital twin simulation platform of claim 6, wherein: Combined with the risk identification results, security risk assessment and defense strategy generation verification are completed to realize intelligent collaboration and continuous learning of cross-domain defense strategies through collaborative optimization. The security risk assessment realizes the security situation quantitative analysis of multi-source data fusion, and the defense strategy generation constructs a three-level defense strategy library of preventive control, emergency control and recovery control; The security risk assessment constructs a three-dimensional evaluation space, and quantifies the risk influence through external events, internal events and security indicators; The preventive control includes device inspection optimization, protection setting adjustment and network firewall rule update; The collaborative optimization realizes the cross-domain collaboration of network security isolation strategy and electrical protection action strategy by establishing a strategy correlation matrix.

8. An information-physical security defense system based on a network configuration digital twin simulation platform, applying an information-physical security defense method based on a network configuration digital twin simulation platform according to any one of claims 1-7, characterized in that, It comprises: An interactive channel construction module, a model construction module, a risk identification module and a strategy generation module; The interactive channel construction module is used to construct a three-dimensional channel for the interaction of physical power grids, information models and simulation data, and form a topology mapping structure and an interaction mechanism supporting virtual-real fusion; The model construction module is used to construct a three-state dynamic conversion model between steady state, transient state and recovery state on the basis of the three-dimensional channel, and realize the automatic switching simulation of operating state through sub-region division and parallel computing; The risk identification module is used to construct a multi-level risk modeling system for various risks based on simulation results, identify complex attack scenarios including false data injection, and realize the mapping of risk types and response paths; The strategy generation module is used to complete the security risk assessment and defense strategy generation verification in combination with the risk identification results, and realize the intelligent collaboration and continuous learning of cross-domain defense strategies through collaborative optimization. 9.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-8 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the information and physical security defense method based on the distribution network digital twin simulation platform in any one of claims 1 to 7.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the information and physical security defense method based on the distribution network digital twin simulation platform in any one of claims 1 to 7.

Citation Information

Cited By

  • Photovoltaic grid-connected flexible direct current power transmission and energy storage cooperative control system and method

    CN121150334A

  • Multi-domain fusion network target modeling method and system

    CN121486209A

  • Electric power system intelligent simulation control system based on digital twinning

    CN121634888A

  • Information interaction method for joint simulation of main network and active distribution network

    CN121723661A

  • Information interaction method for main network and active distribution network joint simulation

    CN121723661B