Intelligent operation and maintenance management and control method for large-scale 5G power distribution communication network

By preprocessing and analyzing real-time operation and maintenance data of the power distribution communication network, scheduling strategies are generated. Combined with fault prediction models and decision trees, the problem of low efficiency in traditional operation and maintenance methods is solved, dynamic optimization and security protection of network resources are realized, and fault detection and threat handling capabilities are improved.

CN120935600APending Publication Date: 2025-11-11AKSU POWER SUPPLY COMPANY STATE GRID XINJIANG ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511149534.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-18
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Traditional operation and maintenance management methods for power distribution communication networks are inefficient, make it difficult to detect potential faults in real time, lack the ability to deeply analyze and process operation and maintenance data, and cannot accurately predict faults, leading to an expansion of the fault range and affecting network stability and security.

Method used

By collecting real-time operation and maintenance data streams, performing data preprocessing and noise filtering, determining monitoring windows and operation and maintenance status labels, generating negative or positive scheduling strategies, and combining fault prediction models and abnormal operation and maintenance decision trees, dynamic optimization and security protection of network resources can be achieved.

Benefits of technology

It improves the real-time performance and accuracy of fault detection, optimizes network resource allocation, mitigates the risks of sudden traffic surges and equipment overload, quickly identifies and handles network security threats, and ensures the stability and security of the power distribution communication network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120935600A_ABST
    Figure CN120935600A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent operation and maintenance management and control method for a large-scale 5G power distribution communication network, and the method comprises the steps: collecting a real-time operation and maintenance data flow, carrying out the preprocessing, and determining an operation and maintenance state label representing a fault risk level based on the target operation and maintenance data in a monitoring window. When the label is in a high-risk state, a negative scheduling strategy is generated in combination with the current scheduling strategy; and when the state is a safe state, a forward scheduling strategy is generated. According to the method, accurate monitoring is realized by dynamically adjusting the length of a monitoring window, and state judgment is performed by adopting a network health index. Meanwhile, an emergency instruction is triggered according to scheduling strategy abnormity, service flow speed limiting or safety protection activation is implemented, and self-adaptive scheduling and risk prevention and control of power distribution communication network resources are achieved. According to the invention, the fault early warning accuracy and resource scheduling efficiency of the 5G power distribution communication network can be improved, and real-time blocking of a high-risk state and accurate triggering of safety protection are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of 5G communication and smart grid technology, and more specifically, to a method for intelligent operation and maintenance management of large-scale 5G power distribution communication networks. Background Technology

[0002] With the rapid development of 5G technology and its widespread application in power distribution communication networks, the operation and maintenance (O&M) management of large-scale 5G power distribution communication networks faces numerous challenges. Traditional O&M management methods for power distribution communication networks mainly rely on manual inspections and simple fault alarm mechanisms. O&M personnel need to periodically inspect equipment, checking indicator lights and recording operating parameters to determine if the equipment is operating normally. When equipment malfunctions, the fault is often only located through simple alarm signals emitted by the equipment. This method is inefficient and makes it difficult to detect potential faults in a timely manner, easily leading to the expansion of the fault range and affecting the stable operation of the entire power distribution communication network.

[0003] In terms of technical principles, traditional operation and maintenance (O&M) management methods lack the ability to deeply analyze and process real-time O&M data. Although some equipment operation data can be collected, this data is often unprocessed and unmined, failing to accurately reflect the real-time operating status and fault risk level of the power distribution communication network. Fault prediction is also relatively crude, unable to accurately predict fault occurrence in advance, and can only be handled passively after a fault has occurred, making it difficult to meet the needs of modern large-scale 5G power distribution communication networks for efficient and intelligent O&M management.

[0004] In implementing the embodiments of the present invention, the prior art has at least the following problems or defects: it is impossible to effectively preprocess and analyze the real-time operation and maintenance data of the power distribution communication network; it is difficult to accurately determine the monitoring window and operation and maintenance status label; it is impossible to generate reasonable scheduling strategy information based on the operation and maintenance status label; the processing of abnormal operation and maintenance information is not timely and accurate enough; there is a lack of effective fault prediction models and emergency command generation mechanisms; it is impossible to achieve reasonable isolation and allocation of network slice resources and refined management of security protection, etc. These problems seriously affect the operation and maintenance management efficiency and reliability of the 5G power distribution communication network. Summary of the Invention

[0005] This invention provides a method for intelligent operation and maintenance management of large-scale 5G power distribution communication networks, applicable to power distribution gateway equipment or security protection systems, comprising: Collect real-time operation and maintenance data streams for the power distribution communication network; The real-time operation and maintenance data stream is preprocessed to obtain a preprocessed operation and maintenance data stream; The monitoring window is determined based on the preprocessed operation and maintenance data stream; Based on the target maintenance data stream, determine the maintenance status label, wherein the target maintenance data stream is the preprocessed maintenance data located within the monitoring window in the preprocessed maintenance data stream, and the maintenance status label represents the fault risk level for the power distribution communication network; In response to determining that the operation and maintenance status label is a high-risk status label, negative scheduling policy information for network resources is generated based on the current scheduling policy information corresponding to the power distribution communication network and the operation and maintenance status label, and used as the updated scheduling policy information. In response to determining that the operation and maintenance status label is a security status label, positive scheduling policy information for network resources is generated based on the current scheduling policy information and the operation and maintenance status label, and used as the updated scheduling policy information.

[0006] Further, the step of scheduling resources in the power distribution communication network according to the current scheduling strategy information or the updated scheduling strategy information includes: Based on the current scheduling policy information or the updated scheduling policy information, as well as the operation and maintenance status label and fault prediction model, abnormal operation and maintenance information is determined; When it is determined that the abnormal operation and maintenance information indicates that there is a control abnormality in the current scheduling strategy information or the updated scheduling strategy information, an emergency instruction corresponding to the abnormal operation and maintenance information is determined in the abnormal operation and maintenance decision tree. According to the emergency instructions, the service flow rate of relevant communication nodes in the power distribution communication network is limited, or the security protection system is activated to block abnormal access.

[0007] Further, the step of preprocessing the real-time operation and maintenance data stream to obtain a preprocessed operation and maintenance data stream includes: For each piece of real-time operation and maintenance data in the real-time operation and maintenance data stream, perform the following processing steps: Perform data validity verification on the real-time operation and maintenance data; In response to determining that the real-time operation and maintenance data has passed the validity verification, the real-time operation and maintenance data is subjected to message noise filtering to obtain filtered operation and maintenance data. The filtered operation and maintenance data is then subjected to data standardization processing to obtain standardized operation and maintenance data; Determine the collection granularity corresponding to the real-time operation and maintenance data stream, wherein the collection granularity characterizes the data collection frequency of the real-time operation and maintenance data stream; In response to determining that the acquisition granularity is not the benchmark acquisition granularity and that the acquisition granularity is smaller than the benchmark acquisition granularity, the standardized operation and maintenance dataset is downsampled using the benchmark acquisition granularity to obtain the preprocessed operation and maintenance data stream.

[0008] Further, determining the monitoring window based on the preprocessed operation and maintenance data stream includes: Initialize the window length corresponding to the monitoring window to obtain the initial monitoring window, wherein the window length of the initial monitoring window is the initial window length; Based on the initial window length and the preprocessed maintenance data stream, the following window determination steps are performed: Determine the target operation and maintenance data stream, where the target operation and maintenance data in the target operation and maintenance data stream is the preprocessed operation and maintenance data located within the initial monitoring window; Calculate the average value of operation and maintenance data based on the target operation and maintenance data flow; Based on the target operation and maintenance data stream, the average operation and maintenance data, the first target operation and maintenance data, and the second target operation and maintenance data, calculate the window feature value of the initial monitoring window, where the first target operation and maintenance data is the maximum value of the target operation and maintenance data stream, and the second target operation and maintenance data is the minimum value of the target operation and maintenance data stream; In response to determining that the average value of operation and maintenance data is greater than or equal to the dynamic risk threshold, the initial monitoring window is determined as the monitoring window, wherein the dynamic risk threshold is dynamically configured according to the distribution network topology. In response to the determination that the average value of the operation and maintenance data is less than the dynamic risk threshold, the window length of the initial monitoring window is incremented to obtain a monitoring window with an increased length, which is then used as the initial monitoring window, and the window determination step is executed again.

[0009] Furthermore, determining the operation and maintenance status label based on the target operation and maintenance data stream includes: For each target operation and maintenance data point in the target operation and maintenance data stream, the network health index is calculated according to the following formula:

[0010] in: Let i be the bandwidth utilization at time i. Let i be the network latency (ms). For node idle computing resources, Total computing resources for the node The weighting coefficients and ; In response to the network health index continuously falling below the high-risk threshold Upon reaching the first time window, the operation and maintenance status label is determined to be a high-risk status label; In response to the network health index continuously exceeding the security threshold Upon reaching the second time window, the operation and maintenance status label is determined to be a safe status label.

[0011] Furthermore, the fault prediction model is constructed through the following steps: Extracting features of sudden changes in business flow:

[0012] in Let be the traffic mutation rate at time t. Let t be the business traffic at time t. For the service traffic at time t-1, To prevent extremely small positive numbers with a denominator of zero; Extracting channel contention coefficients:

[0013] in Let be the channel contention coefficient at time t. This represents the current number of channel requests. The maximum number of requests that the channel can support. Let j be the length of the channel queue. This is the total channel queue length; The mutation characteristics and competition coefficients are input into the LSTM time series model, which outputs the future... Failure probability during a time period ,in For the predicted time interval.

[0014] Furthermore, the abnormal operation and maintenance decision tree includes: First-level node: Determine the business flow mutation rate Has the safety limit been exceeded? ,in This serves as a safe threshold for the business flow mutation rate. Second-level node: Responding to Detect whether it exists Attack characteristics; Third-level node: Responds to existence The attack characteristics were identified, and the first emergency command was output to activate the traffic scrubbing service. Fourth-level node: responds to non-existence Attack characteristics, output second emergency command to execute network element isolation.

[0015] Furthermore, it also includes a network slicing resource isolation mechanism: allocating dedicated network slices for distribution automation services.

[0016] in: For the frequency band range of slice k, This is the minimum value in the frequency band. The maximum value of the frequency band. Given the maximum time delay requirement for slice k, Let k be the maximum bit error rate of slice k.

[0017] Furthermore, the forward scheduling strategy includes: employing Q-learning-based radio resource block allocation.

[0018] in: For state Next action Q value, For learning rate, To perform the action The subsequent reward value (business) Satisfaction rate improvement value). As a discount factor, To perform the action The next state after that, This is an optional action for the next state; state Defined as the resource utilization rate of each slice, action For spectrum allocation schemes, rewards For business Satisfaction rate improvement value.

[0019] Furthermore, it also includes security protection mechanisms: establishing a fingerprint database for power distribution terminal equipment.

[0020] in The device's fingerprint identifier is represented by the MAC address, the IMEI (International Mobile Equipment Identity), and the CETF (Digital Certificate). XOR operation; Hash is a hash function. In response to the detection of an unregistered device accessing the network, a deep packet inspection of the signaling system is triggered:

[0021] in The threat level is represented by N, and the number of detected features is N. Let i be the weight of the i-th feature. Let be the anomaly value of the i-th feature; where, For the set of work order instructions, For the first Individual device fingerprint identifier, For the first Scheduling actions for individual devices; Commands are sent to the network management system via the northbound interface; command execution status is monitored in real time. ,in For the first The execution status of the instruction (success / failure); when there is At that time, the manual intervention protocol is activated.

[0022] The embodiments of the present invention have at least the following beneficial effects: 1. By collecting power distribution communication network operation and maintenance data streams in real time and performing multi-level preprocessing, including validity verification, noise filtering and standardization, combined with a dynamic monitoring window mechanism, and based on adaptive adjustment of mean and risk threshold, the real-time performance and accuracy of anomaly detection are improved, solving the problems of low efficiency and difficulty in detecting hidden faults in traditional manual inspections. 2. Based on the network health index, intelligent status determination is achieved by integrating bandwidth utilization, latency, and computing resource indicators. Combined with positive / negative scheduling strategies triggered by high-risk / safe status labels, dynamic optimization of network resources can be realized to mitigate the risk of service interruption caused by sudden traffic surges or equipment overload. 3. By constructing a fault prediction model, combining the characteristics of sudden changes in service flow and the channel contention coefficient with the abnormal operation and maintenance decision tree, attack characteristics are judged in layers and cleaning or isolation is triggered. Combined with the equipment fingerprint database and deep packet inspection technology, an end-to-end security protection system is formed, which solves the problem of rapid identification and handling of network security threats such as illegal access to power distribution terminals and DDoS attacks. Attached Figure Description

[0023] The above and other objects, features, and advantages of exemplary embodiments of the present invention will become readily apparent from the following detailed description taken in conjunction with the accompanying drawings. Several embodiments of the invention are illustrated in the drawings by way of example and not limitation, wherein: Figure 1 This is a flowchart illustrating a method for intelligent operation and maintenance management of a large-scale 5G power distribution communication network according to an embodiment of the present invention. Detailed Implementation

[0024] The principles and spirit of the invention will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and implement the invention, and are not intended to limit the scope of the invention in any way. Rather, these embodiments are provided to make the invention more thorough and complete, and to fully convey the scope of the invention to those skilled in the art.

[0025] Those skilled in the art will recognize that embodiments of the present invention can be implemented as a system, apparatus, device, method, or computer program product. Therefore, the present invention can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.

[0026] It should be noted that the number of any elements in the accompanying drawings is for illustrative purposes only and not as a limitation, and any naming is for distinction only and has no limiting meaning.

[0027] The following is for reference. Figure 1 , Figure 1This is a flowchart illustrating a method for intelligent operation and maintenance management of a large-scale 5G power distribution communication network according to an embodiment of the present invention. Figure 1 As shown, a method for intelligent operation and maintenance management of large-scale 5G power distribution communication networks includes: S1. Collect real-time operation and maintenance data streams for the power distribution communication network; S2. Perform data preprocessing on the real-time operation and maintenance data stream to obtain a preprocessed operation and maintenance data stream; S3. Determine the monitoring window based on the preprocessed operation and maintenance data stream; S4. Determine the operation and maintenance status label based on the target operation and maintenance data stream, wherein the target operation and maintenance data stream is the preprocessed operation and maintenance data located within the monitoring window in the preprocessed operation and maintenance data stream, and the operation and maintenance status label represents the fault risk level for the power distribution communication network. S5. In response to determining that the operation and maintenance status label is a high-risk status label, generate negative scheduling policy information for network resources based on the current scheduling policy information corresponding to the power distribution communication network and the operation and maintenance status label, as the updated scheduling policy information. S6. In response to determining that the operation and maintenance status label is a security status label, generate positive scheduling policy information for network resources based on the current scheduling policy information and the operation and maintenance status label, as the updated scheduling policy information.

[0028] It should be noted that this invention proposes a method for intelligent operation and maintenance management of large-scale 5G power distribution communication networks. This method is mainly applied to power distribution gateway equipment or security protection systems. Power distribution gateway equipment is a key node connecting the power distribution network and the communication network, responsible for data forwarding and issuing control commands; the security protection system is used to ensure the secure operation of the communication network and prevent external attacks and data leaks. This method first requires collecting real-time operation and maintenance data streams for the power distribution communication network. Real-time operation and maintenance data streams refer to the data sets generated in real time during the operation of the power distribution communication network, related to equipment operating status, network performance, etc., which reflect the current operating status of the communication network. Next, the collected real-time operation and maintenance data streams are preprocessed. Data preprocessing is the initial stage of data processing, aiming to remove noise, fill in missing values, and standardize data formats to improve data quality and usability. After preprocessing, a preprocessed operation and maintenance data stream is obtained. Then, a monitoring window is determined based on the preprocessed operation and maintenance data stream. The monitoring window refers to a specific time range of data selected from the preprocessed operation and maintenance data stream for subsequent analysis and processing. Next, the operation and maintenance status label is determined based on the target operation and maintenance data stream. The target operation and maintenance data stream is the preprocessed operation and maintenance data located within the monitoring window. The operation and maintenance status label is an identifier of the fault risk level of the distribution communication network, used to indicate the current health status of the network. When the operation and maintenance status label is determined to be a high-risk status label, negative scheduling policy information for network resources is generated based on the current scheduling policy information and the operation and maintenance status label of the corresponding distribution communication network. This is used as the updated scheduling policy information. The negative scheduling policy information refers to the strategy of restricting or adjusting network resources when a high-risk situation is detected, in order to reduce the risk. When the operation and maintenance status label is determined to be a safe status label, positive scheduling policy information for network resources is generated based on the current scheduling policy information and the operation and maintenance status label. This is used as the updated scheduling policy information. The positive scheduling policy information refers to the strategy of optimizing the configuration of network resources when the network operation is confirmed to be safe, in order to improve resource utilization.

[0029] Specifically, real-time operation and maintenance data streams for the power distribution communication network are collected, including but not limited to equipment performance indicators, network traffic, and error logs. Equipment performance indicators can include CPU utilization and memory usage, which reflect the equipment's load status; network traffic refers to the amount of data transmitted on the communication link, and analyzing traffic can reveal the network's busy level; error logs record various error messages that occur during equipment operation, helping to locate problems. Data preprocessing is performed on the real-time operation and maintenance data streams, specifically including data validity verification, i.e., checking whether the data conforms to the expected format and range, and removing invalid or erroneous data; message noise filtering, which removes irrelevant noise information from the data to improve data purity; and data standardization, which converts the data into a unified format and unit to facilitate subsequent analysis and processing. A monitoring window is determined, and the initial monitoring window length can be set according to actual needs, for example, 10 minutes. Then, the average operation and maintenance data is calculated based on the data in the preprocessed operation and maintenance data stream. The average operation and maintenance data is the average value of all operation and maintenance data within the monitoring window, reflecting the average operating status of the network during that time period. The initial monitoring window's window characteristic value is calculated. This value is derived by comprehensively considering data characteristics such as the maximum, minimum, and average values ​​within the monitoring window, and is used to assess data changes within the window. The dynamic risk threshold is dynamically configured based on the distribution network topology. Different topologies may correspond to different risk thresholds; for example, in complex topologies, the risk threshold may be set lower to more sensitively detect potential risks. The determination of the operation and maintenance status label is based on the network health index, which is an indicator calculated by comprehensively considering multiple factors such as bandwidth utilization, network latency, and node idle computing resources, used to assess the network's health status. The fault prediction model is constructed by analyzing data such as service flow mutation characteristics and channel contention coefficients. Service flow mutation characteristics reflect sudden changes in service traffic, while the channel contention coefficient represents the degree of competition for channel resources. These characteristics help predict potential future faults. The abnormal operation and maintenance decision tree is a rule-based decision model that outputs corresponding emergency instructions, such as activating traffic scrubbing services or executing network element isolation, by judging whether the service flow mutation rate exceeds the safety limit. Network slicing resource isolation mechanism refers to allocating independent network slice resources to different services. Each slice resource has specific parameters such as frequency band range, maximum latency requirement, and maximum bit error rate to ensure the independence and quality of service of different services. The forward scheduling strategy adopts Q-learning-based radio resource block allocation. Q-learning is a reinforcement learning algorithm that optimizes resource allocation strategies by learning the Q-value between states and actions. The state can be defined as the resource occupancy rate of each slice, the action is the spectrum allocation scheme, and the reward is the improvement in service satisfaction.Security protection mechanisms include establishing a fingerprint database for power distribution terminal equipment. The equipment fingerprint is obtained through specific calculations using information such as the equipment's physical address, International Mobile Equipment Identity (IMEI), and digital certificate, and is used to identify the equipment's identity. Signaling deep packet inspection involves detailed analysis of the signaling when the equipment connects, and the security of the connected equipment is determined by calculating the threat level.

[0030] Preferably, for collecting real-time operation and maintenance data streams for the power distribution communication network, this can be achieved by deploying data acquisition modules on the power distribution gateway equipment and communication nodes. These modules can collect data such as equipment performance indicators and network traffic at set time intervals, such as once per second. During data preprocessing of the real-time operation and maintenance data stream, data validity verification can use methods such as regular expressions to check whether the data conforms to preset format rules; message noise filtering can remove noisy data below a set threshold; data standardization can use the Z-score standardization method to convert the data into a standard distribution with a mean of 0 and a standard deviation of 1. When determining the monitoring window, the initial window length can be set according to the network size and complexity; for small networks, it can be set to 5 minutes, and for large networks, it can be set to 15 minutes. When calculating the mean of the operation and maintenance data, a weighted average can be applied to all data within the monitoring window, assigning different weights according to the importance of the data; when calculating the window feature value, statistical methods such as variance can be used to measure the dispersion of the data. Dynamic risk thresholds can be dynamically calculated based on the distribution network topology parameters, such as the number of nodes and connection methods, through a pre-defined functional relationship. When determining the operation and maintenance status label, the network health index calculation formula includes bandwidth utilization (obtained by monitoring network bandwidth usage), network latency (calculated by sending test signals and measuring return time), node idle computing resources and total node computing resources (obtained by querying the device's resource management module), and weighting coefficients (adjusted based on the impact of each factor on network health). In the construction of the fault prediction model, the extraction of service flow mutation characteristics can be achieved by calculating the difference in service traffic between adjacent time points, and the extraction of channel contention coefficients can be accomplished by statistically analyzing information such as the number of channel requests and channel queue length. These characteristics are then input into the LSTM time series model, and the model is trained to predict the probability of faults in future periods. The construction of the abnormal operation and maintenance decision tree can be designed based on actual operation and maintenance experience and rules. For example, the safety upper limit for the service flow mutation rate can be set to 50% based on historical data and experience. When the service flow mutation rate exceeds this value, further detection is performed to check for DDoS attack characteristics. If present, an emergency command to activate traffic scrubbing services is output; otherwise, an emergency command to execute network element isolation is output. In the network slicing resource isolation mechanism, when allocating dedicated network slices for distribution automation services, parameters such as the frequency band range, maximum latency requirement, and maximum bit error rate of the slices can be set according to the needs of the services. For example, for services with high real-time requirements, slices with lower latency requirements can be allocated.In the forward scheduling strategy, the specific implementation of Q-learning-based wireless resource block allocation can include setting parameters such as learning rate and discount factor. The learning rate determines the speed of Q-value updates, the discount factor measures the present value of future rewards, the state can be the specific value of resource occupancy rate of each slice, the action can be a specific spectrum allocation scheme, and the reward can be the specific value of improved service satisfaction. In the security protection mechanism, when establishing a fingerprint database for power distribution terminal equipment, device fingerprint identifiers can be generated using information such as the device's MAC address, IMEI, and digital certificate, employing XOR operations and hash functions. When an unregistered device is detected accessing the network, deep packet inspection is triggered, and the device's security is judged by calculating the threat level. If the threat level exceeds a set threshold, a manual intervention protocol is activated.

[0031] In some embodiments, the step of scheduling resources in the power distribution communication network according to the current scheduling policy information or the updated scheduling policy information includes: Based on the current scheduling policy information or the updated scheduling policy information, as well as the operation and maintenance status label and fault prediction model, abnormal operation and maintenance information is determined; When it is determined that the abnormal operation and maintenance information indicates that there is a control abnormality in the current scheduling strategy information or the updated scheduling strategy information, an emergency instruction corresponding to the abnormal operation and maintenance information is determined in the abnormal operation and maintenance decision tree. According to the emergency instructions, the service flow rate of relevant communication nodes in the power distribution communication network is limited, or the security protection system is activated to block abnormal access.

[0032] It should be noted that when scheduling resources in the power distribution communication network, this invention determines abnormal operation and maintenance (O&M) information based on the current or updated scheduling strategy information, as well as O&M status tags and fault prediction models. Abnormal O&M information refers to unexpected O&M situations that may occur under the current scheduling strategy, such as abnormal network traffic or degraded equipment performance. If the abnormal O&M information indicates a control anomaly in the current or updated scheduling strategy information—meaning the current scheduling strategy cannot effectively address network anomalies—then it is necessary to determine the corresponding emergency instructions in the abnormal O&M decision tree. The abnormal O&M decision tree is a rule-based decision model used to generate corresponding emergency instructions based on different anomalies. Based on the emergency instructions, service flow rate limiting can be applied to relevant communication nodes in the power distribution communication network, i.e., limiting the traffic of certain services to prevent network congestion; or the security protection system can be activated to block abnormal access, i.e., preventing insecure devices or data from accessing the network to ensure the safe operation of the network.

[0033] Specifically, the current scheduling strategy information refers to the pre-set resource allocation and management strategies during the operation of the power distribution communication network. These strategies allocate network resources based on the normal operating status of the network. Updated scheduling strategy information is a new strategy generated based on operation and maintenance status labels and fault prediction models after a network anomaly is detected. It is used to adjust the allocation of network resources to cope with abnormal situations. Operation and maintenance status labels are determined based on indicators such as network health indices and are used to identify the current fault risk level of the network, such as high risk or safe. The fault prediction model predicts possible future fault situations through the analysis of historical and real-time data. Determining abnormal operation and maintenance information requires comprehensive consideration of the current or updated scheduling strategy and the output results of the fault prediction model. The abnormal operation and maintenance decision tree is a hierarchical decision structure. The first-level node judges whether the service flow mutation rate exceeds the safety limit. The service flow mutation rate refers to the rate of change of service traffic in a short period of time. The safety limit is a preset threshold used to judge whether the service flow change is abnormal. If the service flow mutation rate exceeds the safety limit, it enters the second-level node to detect whether there are DDoS attack characteristics. DDoS attacks are a common network attack method that causes an abnormal increase in network traffic. If DDoS attack characteristics are present, the first emergency command is issued to activate the traffic scrubbing service, which can remove malicious traffic from the network. If no DDoS attack characteristics are present, the second emergency command is issued to perform network element isolation, that is, to isolate the network unit with the problem to prevent the problem from spreading. Service flow rate limiting restricts the traffic of specific services; for example, the traffic of a certain service can be limited to a certain range to ensure the normal operation of other services. Activating the security protection system can take various measures, such as adjusting firewall rules and starting the intrusion detection system, to enhance the network's security protection capabilities.

[0034] Preferably, when determining abnormal operation and maintenance information, a threshold can be set. When the failure probability output by the fault prediction model exceeds this threshold, a control anomaly is considered to exist. For example, if the fault prediction model predicts that the probability of a failure occurring within the next 10 minutes exceeds 30%, the current scheduling strategy is considered to have a control anomaly. In the abnormal operation and maintenance decision tree, the service flow mutation rate safety threshold of the first-level node can be set according to historical data and the actual network situation, for example, set to 20%, meaning that when the service flow mutation rate exceeds 20%, an anomaly is considered to be possible. When detecting DDoS attack characteristics, specific algorithms can be used, such as traffic feature-based detection algorithms, to analyze the packet size, frequency, and other characteristics of network traffic to determine whether a DDoS attack exists. If a DDoS attack is detected, the first emergency command can include specific traffic cleaning parameters, such as the range of traffic to be cleaned and the duration of cleaning. If no DDoS attack exists, the second emergency command can specify the range of network elements to be isolated and the specific isolation measures. When executing service flow rate limiting, rate limiting parameters can be set according to the importance and priority of the service, for example, a larger rate limit can be applied to non-critical services, while a smaller rate limit can be applied to critical services. When activating the security protection system, you can adjust its parameters, such as the strictness of firewall rules and the sensitivity of the intrusion detection system, based on the characteristics of abnormal access, in order to more effectively block abnormal access.

[0035] In some embodiments, the step of preprocessing the real-time operation and maintenance data stream to obtain a preprocessed operation and maintenance data stream includes: For each piece of real-time operation and maintenance data in the real-time operation and maintenance data stream, perform the following processing steps: Perform data validity verification on the real-time operation and maintenance data; In response to determining that the real-time operation and maintenance data has passed the validity verification, the real-time operation and maintenance data is subjected to message noise filtering to obtain filtered operation and maintenance data. The filtered operation and maintenance data is then subjected to data standardization processing to obtain standardized operation and maintenance data; Determine the collection granularity corresponding to the real-time operation and maintenance data stream, wherein the collection granularity characterizes the data collection frequency of the real-time operation and maintenance data stream; In response to determining that the acquisition granularity is not the benchmark acquisition granularity and that the acquisition granularity is smaller than the benchmark acquisition granularity, the standardized operation and maintenance dataset is downsampled using the benchmark acquisition granularity to obtain the preprocessed operation and maintenance data stream.

[0036] It should be noted that, in the preprocessing of real-time operation and maintenance data streams, this invention first performs data validity verification on each piece of real-time operation and maintenance data to ensure the accuracy and reliability of the data. Data validity verification uses a series of rules or algorithms to check whether the data conforms to the expected format and range. If the data passes the validity verification, it is then subjected to message noise filtering to remove noise components from the data. This noise may be caused by equipment failure, transmission interference, or data acquisition errors. The filtered data is then subjected to data standardization processing to convert the data into a unified format and unit to facilitate subsequent analysis and processing. Acquisition granularity refers to the data acquisition frequency of the real-time operation and maintenance data stream, i.e., the time interval between data acquisitions. If the acquisition granularity is smaller than the baseline acquisition granularity, it indicates that the actual data acquisition is more frequent than expected. In this case, it is necessary to downsample the standardized operation and maintenance dataset using the baseline acquisition granularity to reduce the data volume and maintain data consistency, ultimately obtaining the preprocessed operation and maintenance data stream.

[0037] Specifically, data validity verification can be achieved by setting rules for data format, range, and type. For example, for equipment performance index data, it can be stipulated that it must be positive and within a certain performance threshold range; for network traffic data, it can be stipulated that its unit must be bytes or bits, and the value cannot exceed the upper limit of network bandwidth. Packet noise filtering can be achieved by setting noise thresholds. For example, for network traffic data, a traffic threshold can be set, and data below this threshold is considered noise and filtered out. Data standardization can use the Z-score standardization method to convert the data into a standard distribution with a mean of 0 and a standard deviation of 1, thus eliminating dimensional differences between different data. Collection granularity refers to the time interval between data collections; for example, collecting data once per second has a collection granularity of 1 second. The baseline collection granularity is a pre-set standard collection frequency; for example, for some critical equipment, the baseline collection granularity can be set to collect data once every 5 seconds. If the actual collection granularity is once per second, i.e., the collection granularity is less than the baseline collection granularity, then the standardized maintenance data needs to be downsampled. For example, one data point can be selected every 5 data points to meet the requirements of the baseline collection granularity.

[0038] Preferably, during data validity verification, regular expressions can be used to check whether the data format conforms to preset rules. For example, for a device's MAC address, regular expressions can be used to verify whether it conforms to the standard MAC address format. In packet noise filtering, a moving average algorithm can be used to smooth the data and remove short-term fluctuation noise. For example, for network traffic data, the average traffic over the past 5 time points can be calculated, and this average can be used to replace the traffic value at the current time point, thereby reducing the impact of noise. In data standardization, the Min-Max standardization method can be used to scale the data to the [0,1] interval, which can better handle data boundary values. When determining the collection granularity and baseline collection granularity, they can be set according to the device performance and network bandwidth. For example, for high-performance devices, a lower collection granularity can be set to obtain more detailed data; for networks with limited bandwidth, the collection granularity can be appropriately increased to reduce data transmission volume. During downsampling, random sampling or fixed-interval sampling methods can be used. For example, for every 10 data points, 2 data points can be randomly selected, or one data point can be selected every 5 data points to achieve the purpose of downsampling.

[0039] In some embodiments, determining the monitoring window based on the preprocessed maintenance data stream includes: Initialize the window length corresponding to the monitoring window to obtain the initial monitoring window, wherein the window length of the initial monitoring window is the initial window length; Based on the initial window length and the preprocessed maintenance data stream, the following window determination steps are performed: Determine the target operation and maintenance data stream, where the target operation and maintenance data in the target operation and maintenance data stream is the preprocessed operation and maintenance data located within the initial monitoring window; Calculate the average value of operation and maintenance data based on the target operation and maintenance data flow; Based on the target operation and maintenance data stream, the average operation and maintenance data, the first target operation and maintenance data, and the second target operation and maintenance data, calculate the window feature value of the initial monitoring window, where the first target operation and maintenance data is the maximum value of the target operation and maintenance data stream, and the second target operation and maintenance data is the minimum value of the target operation and maintenance data stream; In response to determining that the average value of operation and maintenance data is greater than or equal to the dynamic risk threshold, the initial monitoring window is determined as the monitoring window, wherein the dynamic risk threshold is dynamically configured according to the distribution network topology. In response to the determination that the average value of the operation and maintenance data is less than the dynamic risk threshold, the window length of the initial monitoring window is incremented to obtain a monitoring window with an increased length, which is then used as the initial monitoring window, and the window determination step is executed again.

[0040] It should be noted that, in determining the monitoring window, this invention first initializes the window length corresponding to the monitoring window to obtain an initial monitoring window. The initial window length is the initial window length, which can be set according to actual needs and network characteristics. Next, based on the initial window length and the preprocessed operation and maintenance data stream, a series of window determination steps are executed. These steps include determining the target operation and maintenance data stream, i.e., the preprocessed operation and maintenance data located within the initial monitoring window; calculating the mean of the operation and maintenance data to assess the average level of the data within the window; and calculating the window feature value of the initial monitoring window, which comprehensively considers data characteristics such as the maximum, minimum, and mean values ​​within the window to assess data changes. If the mean of the operation and maintenance data is greater than or equal to the dynamic risk threshold, it indicates that the data within the current window has a high risk, and the initial monitoring window is determined as the monitoring window. If the mean of the operation and maintenance data is less than the dynamic risk threshold, the window length of the initial monitoring window is incremented to expand the monitoring range, and the window determination steps are executed again until a suitable monitoring window is found.

[0041] Specifically, the initial window length can be set according to the network size and data volatility. For example, for a small distribution communication network, the initial window length can be set to 5 minutes; for a large network, the initial window length can be set to 15 minutes. The target maintenance data stream refers to the pre-processed maintenance data within the initial monitoring window, which is used for subsequent analysis and calculation. The maintenance data mean is obtained by calculating the average value of all data in the target maintenance data stream; it reflects the average level of the data within the window. Window characteristic values ​​are calculated by comprehensively considering characteristics such as the maximum, minimum, and mean values ​​of the target maintenance data stream. For example, variance or standard deviation in statistics can be used to measure the dispersion of the data. The dynamic risk threshold is dynamically configured according to the distribution network topology; different topologies may correspond to different risk thresholds. For example, in complex topologies, the risk threshold may be set lower to more sensitively detect potential risks.

[0042] Preferably, when initializing the monitoring window, the initial window length can be set based on historical data and experience. For example, if historical data shows that network data changes relatively steadily within 10 minutes, the initial window length can be set to 10 minutes. When calculating the average of maintenance data, a weighted average method can be used, assigning different weights according to the importance of the data. For example, data from critical equipment can be given a higher weight. When calculating window characteristic values, more complex statistical methods can be used, such as calculating the skewness and kurtosis of the data, to more comprehensively assess the distribution of the data. The configuration of the dynamic risk threshold can be adjusted according to the real-time topology parameters of the network. For example, if multiple nodes are added to the network, the risk threshold can be appropriately reduced to improve the sensitivity of monitoring. During the window length increment process, an increment step can be set, such as incrementing by 5 minutes each time, until a monitoring window that meets the conditions is found.

[0043] In some embodiments, determining the operation and maintenance status label based on the target operation and maintenance data stream includes: For each target operation and maintenance data point in the target operation and maintenance data stream, the network health index is calculated according to the following formula:

[0044] in: Let i be the bandwidth utilization at time i. Let i be the network latency (ms). For node idle computing resources, Total computing resources for the node The weighting coefficients and ; In response to the network health index continuously falling below the high-risk threshold Upon reaching the first time window, the operation and maintenance status label is determined to be a high-risk status label; In response to the network health index continuously exceeding the security threshold Upon reaching the second time window, the operation and maintenance status label is determined to be a safe status label.

[0045] It should be noted that this invention assesses the operational status of the power distribution communication network by calculating a network health index when determining the operation and maintenance status label. The network health index is a comprehensive indicator that combines multiple key parameters such as bandwidth utilization, network latency, and idle node computing resources, weighted by specific coefficients. These parameters reflect different aspects of network performance; for example, bandwidth utilization indicates the usage of network bandwidth, network latency reflects data transmission delays, and idle node computing resources represent the remaining processing capacity of the equipment. By calculating the network health index, it is possible to determine whether the network is in a high-risk or safe state. If the network health index is continuously below a set high-risk threshold for a period of time (first time window), the network is considered to be in a high-risk state; if the network health index is continuously above a set safe threshold for a period of time (second time window), the network is considered to be in a safe state. This assessment method based on the network health index can more comprehensively reflect the network's operational status, thus providing a basis for subsequent scheduling strategy adjustments.

[0046] Specifically, the calculation of the network health index involves multiple parameters and weighting coefficients. Bandwidth utilization refers to the ratio of actual network bandwidth usage to total bandwidth, usually expressed as a percentage. Network latency refers to the delay time for data transmission in the network, usually measured in milliseconds (ms). Node idle computing resources refer to the currently unused computing power of a device, usually expressed as the percentage of processor idle time. Total node computing resources refer to the total processing power of the device. Weighting coefficients are pre-set based on the degree of impact of each parameter on network health; for example, if bandwidth utilization has a greater impact on network health, it can be assigned a higher weight. High-risk thresholds and security thresholds are set based on network operating experience and historical data, used to distinguish between high-risk and secure network states. The first and second time windows are time parameters used to determine the shortest time for the network health index to continuously meet high-risk or secure conditions; for example, the first time window can be set to 5 minutes, and the second time window can be set to 10 minutes.

[0047] Preferably, the following steps can be used to calculate the network health index: First, collect parameters such as bandwidth utilization, network latency, and node idle computing resources from the operational data of each target. Then, sum these parameters according to pre-set weighting coefficients. For example, if the weight of bandwidth utilization is 0.4, the weight of network latency is 0.3, and the weight of node idle computing resources is 0.3, then the network health index can be calculated as follows: Network Health Index = 0.4 × Bandwidth Utilization + 0.3 × Network Latency + 0.3 × (Node Idle Computing Resources / Total Node Computing Resources). When setting high-risk and safety thresholds, historical network operation data can be analyzed. For example, by analyzing network operation data from the past year, the range of the network health index under normal operation can be determined, and then the high-risk threshold can be set as the lower limit of the normal range, and the safety threshold as the upper limit of the normal range. When determining the first and second time windows, they can be set according to the network's business needs and fault tolerance capabilities. For example, for services with high real-time requirements, the first time window can be set to a shorter duration, such as 3 minutes; for services with high stability requirements, the second time window can be set to a longer duration, such as 15 minutes. In this way, the network's operating status can be assessed more accurately, and scheduling strategies can be adjusted in a timely manner.

[0048] In some embodiments, the fault prediction model is constructed through the following steps: Extracting features of sudden changes in business flow:

[0049] in Let be the traffic mutation rate at time t. Let t be the business traffic at time t. For the service traffic at time t-1, To prevent extremely small positive numbers with a denominator of zero; Extracting channel contention coefficients:

[0050] in Let be the channel contention coefficient at time t. This represents the current number of channel requests. The maximum number of requests that the channel can support. Let j be the length of the channel queue. This is the total channel queue length; The mutation characteristics and competition coefficients are input into the LSTM time series model, which outputs the future... Failure probability during a time period ,in For the predicted time interval.

[0051] It should be noted that this invention, in constructing the fault prediction model, primarily extracts two key features: traffic flow abrupt change characteristics and channel contention coefficients. These features are then input into the LSTM time series model to predict the probability of a fault occurring within a future time period. Traffic flow abrupt change characteristics reflect the changes in traffic volume between adjacent time points, helping to identify abnormal traffic fluctuations; the channel contention coefficient represents the degree of competition for channel resources, reflecting the channel load. Through these two features, the model can more accurately predict faults, thereby enabling proactive measures to avoid or mitigate their impact.

[0052] Specifically, the traffic flow mutation feature is obtained by calculating and normalizing the difference between the traffic flow at the current moment and the previous moment to prevent the value from being too large or too small and affecting the calculation results. The channel contention coefficient is obtained by calculating the ratio of the current number of channel requests to the maximum number of channel requests supported, and the ratio of the channel queue length to the total channel queue length. It reflects the utilization of channel resources. These two features reflect the network's operating status from the perspectives of traffic change and resource contention, respectively. The LSTM time series model is a deep learning model specifically designed for processing time series data and can capture long-term dependencies in the data. The model's inputs are the traffic flow mutation feature and the channel contention coefficient, and the output is the probability of failure within a future time period. The prediction time interval can be set according to actual needs, such as predicting the probability of failure within the next 10 minutes.

[0053] Preferably, the fault prediction model can be constructed using the following steps: First, historical traffic data and channel resource usage data are collected and used to train the model. Then, traffic flow mutation characteristics and channel contention coefficients are calculated using the methods described above, serving as input features for the model. Next, a suitable LSTM model architecture is selected; for example, multiple LSTM layers can be included to improve the model's expressive power. During model training, fault records from historical data are used as labels, and model parameters are optimized by minimizing the difference between the predicted fault probability and the actual fault occurrence. For example, mean squared error can be used as the loss function, and the Adam optimizer can be employed for training. After model training is complete, the model's performance can be evaluated using methods such as cross-validation to ensure its accuracy and reliability in practical applications. In actual use, the model receives new traffic flow mutation characteristics and channel contention coefficients in real time, outputting the fault probability for a future period, thus providing early warnings to operations and maintenance personnel so that appropriate preventative measures can be taken.

[0054] In some embodiments, the abnormal operation and maintenance decision tree includes: First-level node: Determine the business flow mutation rate Has the safety limit been exceeded? ,in This serves as a safe threshold for the business flow mutation rate. Second-level node: Responding to Detect whether it exists Attack characteristics; Third-level node: Responds to existence The attack characteristics were identified, and the first emergency command was output to activate the traffic scrubbing service. Fourth-level node: responds to non-existence Attack characteristics, output second emergency command to execute network element isolation.

[0055] It should be noted that the anomaly operation and maintenance decision tree of this invention is a rule-based decision model used to generate corresponding emergency instructions based on different anomaly operation and maintenance information. This decision tree, through a hierarchical logical structure, progressively determines whether the service flow mutation rate exceeds the security limit and whether specific attack characteristics exist, thereby outputting corresponding emergency instructions. This structured approach can quickly respond to different anomalies, ensuring the stable operation of the network.

[0056] Specifically, the first-level node of the anomaly operation and maintenance decision tree determines whether the service flow mutation rate exceeds the security limit. The service flow mutation rate refers to the rate of change of service traffic within a short period of time, and the security limit is a preset threshold used to determine whether the service flow change is abnormal. If the service flow mutation rate exceeds the security limit, the process moves to the second-level node to detect the presence of specific attack characteristics, such as DDoS attack characteristics. DDoS attacks are a common type of network attack that causes an abnormal increase in network traffic. If DDoS attack characteristics are present, the first emergency command is output to activate the traffic scrubbing service, which can remove malicious traffic from the network. If DDoS attack characteristics are not present, the second emergency command is output to perform network element isolation, that is, to isolate the network unit with the problem to prevent the problem from spreading.

[0057] Preferably, the following steps can be followed when constructing the anomaly operation and maintenance decision tree: First, set a safety upper limit for the service flow mutation rate based on historical data and experience, for example, 20%. That is, when the service flow mutation rate exceeds 20%, an anomaly is considered to be possible. When detecting DDoS attack characteristics, specific algorithms can be used, such as traffic feature-based detection algorithms, to analyze the packet size, frequency, and other characteristics of network traffic to determine whether a DDoS attack exists. If a DDoS attack is detected, the first emergency command can include specific traffic cleaning parameters, such as the range of traffic to be cleaned and the duration of the cleaning. If no DDoS attack exists, the second emergency command can specify the range of network elements to be isolated and the specific isolation measures. In practical applications, the parameters and logical structure of the decision tree can be adjusted according to the specific network conditions and business needs to improve the accuracy and efficiency of decision-making.

[0058] In some embodiments, a network slicing resource isolation mechanism is also included: allocating dedicated network slices for distribution automation services.

[0059] in: For the frequency band range of slice k, This is the minimum value in the frequency band. The maximum value of the frequency band. Given the maximum time delay requirement for slice k, Let k be the maximum bit error rate of slice k.

[0060] It should be noted that the network slicing resource isolation mechanism in this invention is primarily designed to meet the dedicated network resource requirements of distribution automation services. This is achieved by allocating independent network slices to different services, ensuring resource isolation and independent operation between them. Network slicing is a technology that divides a physical network into multiple logical networks. Each logical network, or network slice, can be independently configured and managed to meet the needs of different services. Distribution automation services typically have strict requirements for network latency, bandwidth, and reliability; therefore, dedicated network slices are necessary to ensure stable operation.

[0061] Specifically, the network slicing resource isolation mechanism involves allocating dedicated network slices for distribution automation services. This includes defining parameters such as the slice's frequency band range, maximum latency requirement, and maximum bit error rate. The frequency band range refers to the wireless spectrum resources allocated to the slice for data transmission; the maximum latency requirement refers to the maximum allowable delay time for data transmission, which is particularly important for services with high real-time requirements; the maximum bit error rate refers to the maximum allowable error rate during data transmission, reflecting the network's reliability. The settings of these parameters need to be determined based on the specific needs of the distribution automation services. For example, for services requiring rapid response, the maximum latency requirement may need to be set lower, such as within 10 milliseconds; for services with high data integrity requirements, the maximum bit error rate may need to be set lower, such as... .

[0062] Preferably, the implementation of a network slicing resource isolation mechanism can be carried out according to the following steps: First, based on the needs of distribution automation services, determine the network slice parameters required for each service, such as frequency band range, maximum latency requirements, and maximum bit error rate. Then, configure these parameters through the network management system to allocate a dedicated network slice for each service. During the configuration process, Software-Defined Networking (SDN) technology can be used to dynamically adjust slice resources to adapt to changes in service requirements. For example, if the traffic of a certain service suddenly increases, the SDN controller can automatically adjust the frequency band range of the slice to provide more bandwidth. In practical applications, the operating status of the slice can also be evaluated by monitoring network slice performance indicators, such as actual latency and bit error rate, and optimized as needed. For example, if the actual bit error rate of a slice exceeds the maximum bit error rate, measures such as adding redundant paths or adjusting the modulation and demodulation methods can be taken to reduce the bit error rate and ensure stable service operation.

[0063] In some embodiments, the forward scheduling strategy includes: employing Q-learning-based radio resource block allocation.

[0064] in: For state Next action Q value, For learning rate, To perform the action The subsequent reward value (business) Satisfaction rate improvement value). As a discount factor, To perform the action The next state after that, This is an optional action for the next state; state Defined as the resource utilization rate of each slice, action For spectrum allocation schemes, rewards For business Satisfaction rate improvement value.

[0065] It should be noted that the forward scheduling strategy in this invention employs a Q-learning-based radio resource block allocation method, a reinforcement learning algorithm used to optimize radio resource allocation. Q-learning optimizes resource allocation strategies by learning the Q-value between states and actions, thereby improving network resource utilization efficiency and service satisfaction. A state can be defined as the resource occupancy rate of each slice, an action as a spectrum allocation scheme, and a reward as the improvement in service satisfaction. In this way, the allocation of radio resources can be dynamically adjusted to adapt to network changes and service demands.

[0066] Specifically, in the Q-learning algorithm, the state refers to the current utilization of network slice resources, such as bandwidth utilization and latency utilization of each slice. The action refers to the spectrum allocation scheme that can be taken in the current state, such as allocating a certain amount of spectrum resources to a specific slice. The reward refers to the improvement in service satisfaction after performing an action, such as an increase in throughput or a decrease in latency. The learning rate determines the speed at which the Q-value is updated, and the discount factor measures the present value of future rewards. The settings of these parameters need to be determined based on the actual network environment and service requirements. For example, the learning rate can be set to 0.1, and the discount factor can be set to 0.9; these values ​​can be adjusted based on experimental results.

[0067] Preferably, when implementing Q-learning-based wireless resource block allocation, the following steps can be followed: First, initialize the Q-table, a two-dimensional table where rows represent states and columns represent actions. The value of the Q-table represents the expected reward for taking an action in a given state. Then, at each time step, select an action based on the current state. This action selection can be achieved through an ε-greedy strategy, i.e., selecting the action with the largest value in the current Q-table with a certain probability, and randomly selecting an action with a certain probability, to ensure a balance between exploration and utilization. After executing the selected action, observe the new state and the obtained reward, and then update the Q-table according to the Q-learning update rule. The update rule is: the new Q-value equals the old Q-value plus the learning rate multiplied by , and the immediate reward plus a discount factor multiplied by the maximum Q-value of the next state minus the old Q-value. Repeat this process until the Q-table converges, i.e., the Q-value no longer changes significantly. In practical applications, the Q-learning model can be trained by simulating the network environment, and then the trained model can be applied to actual wireless resource allocation. For example, the allocation of spectrum resources can be dynamically adjusted according to the real-time state of the network to improve the overall network performance and service satisfaction.

[0068] In some embodiments, a security protection mechanism is also included: Establish a fingerprint database for power distribution terminal equipment:

[0069] in The device's fingerprint identifier is represented by the MAC address, the IMEI (International Mobile Equipment Identity), and the CETF (Digital Certificate). XOR operation; Hash is a hash function. In response to the detection of an unregistered device accessing the network, a deep packet inspection of the signaling system is triggered:

[0070] in The threat level is represented by N, and the number of detected features is N. Let i be the weight of the i-th feature. Let be the anomaly value of the i-th feature; where, For the set of work order instructions, For the first Individual device fingerprint identifier, For the first Scheduling actions for individual devices; Commands are sent to the network management system via the northbound interface; command execution status is monitored in real time. ,in For the first The execution status of the instruction (success / failure); when there is At that time, the manual intervention protocol is activated.

[0071] It should be noted that the security protection mechanism in this invention primarily achieves device identification and verification by establishing a fingerprint database of power distribution terminal equipment. The device fingerprint database is a unique identifier generated based on device characteristic information, used to distinguish between legitimate and illegitimate devices. When an unregistered device is detected accessing the network, deep packet inspection is triggered, and the security of the accessing device is determined by calculating the threat level. If the threat level exceeds a set threshold, a manual intervention protocol will be activated to ensure the secure operation of the network.

[0072] Specifically, device fingerprint identification is generated by processing information such as the device's physical address (MAC address), International Mobile Equipment Identity (IMEI), and device digital certificate (Certificate) through XOR operations and hash functions. The MAC address is the device's unique physical identifier, the IMEI is the mobile device's unique identifier, and the digital certificate is used to verify the device's identity. XOR operation is a bitwise operation used to combine multiple feature information, while the hash function converts the combined information into a fixed-length unique identifier. Deep packet inspection (DPI) is a technique that performs detailed analysis of network signaling, detecting abnormal features in the signaling to determine the presence of security threats. The threat level is calculated based on the number and severity of detected abnormal features and is used to assess the security of device access.

[0073] Preferably, the security protection mechanism can be implemented according to the following steps: First, collect the MAC address, IMEI, and digital certificate information of all legitimate power distribution terminal devices. Generate device fingerprints using XOR operations and hash functions, and store these fingerprints in a device fingerprint database. When a new device is detected, extract its MAC address, IMEI, and digital certificate information, generate a device fingerprint, and compare it with the fingerprints in the database. If the device fingerprint is not in the database, trigger deep packet inspection (DPI) to analyze the device's access signaling in detail. Calculate the threat level based on preset feature weights and anomaly values. For example, weights can be assigned to each detection feature, such as 0.3 for IP address anomalies and 0.5 for port scan anomalies. The anomaly value is determined based on the actual detection results. If the threat level exceeds a set threshold, such as 0.8, activate the manual intervention protocol for further inspection and handling by maintenance personnel. This method effectively prevents unauthorized device access and ensures the safe operation of the power distribution communication network.

[0074] The above embodiments of the present invention have the following beneficial effects: 1. By collecting power distribution communication network operation and maintenance data streams in real time and performing multi-level preprocessing, including validity verification, noise filtering and standardization, combined with a dynamic monitoring window mechanism, and based on adaptive adjustment of mean and risk threshold, the real-time performance and accuracy of anomaly detection are improved, solving the problems of low efficiency and difficulty in detecting hidden faults in traditional manual inspections. 2. Based on the network health index, intelligent status determination is achieved by integrating bandwidth utilization, latency, and computing resource indicators. Combined with positive / negative scheduling strategies triggered by high-risk / safe status labels, dynamic optimization of network resources can be realized to mitigate the risk of service interruption caused by sudden traffic surges or equipment overload. 3. By constructing a fault prediction model, combining the characteristics of sudden changes in service flow and the channel contention coefficient with the abnormal operation and maintenance decision tree, attack characteristics are judged in layers and cleaning or isolation is triggered. Combined with the equipment fingerprint database and deep packet inspection technology, an end-to-end security protection system is formed, which solves the problem of rapid identification and handling of network security threats such as illegal access to power distribution terminals and DDoS attacks.

[0075] Furthermore, the storage medium in the embodiments of this application stores program instructions capable of implementing all the above methods. These program instructions can be stored in the storage medium in the form of a software product, including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, or terminal devices such as computers, servers, mobile phones, and tablets.

[0076] The above description is merely an explanation of some preferred embodiments of the present invention and the technical principles employed. Those skilled in the art should understand that the scope of the invention as described in the embodiments of the present invention is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of the present invention.

Claims

1. A method for intelligent operation and maintenance management of large-scale 5G power distribution communication networks, applied to power distribution gateway equipment or security protection systems, characterized in that, include: Collect real-time operation and maintenance data streams for the power distribution communication network; The real-time operation and maintenance data stream is preprocessed to obtain a preprocessed operation and maintenance data stream; The monitoring window is determined based on the preprocessed operation and maintenance data stream; Based on the target maintenance data stream, determine the maintenance status label, wherein the target maintenance data stream is the preprocessed maintenance data located within the monitoring window in the preprocessed maintenance data stream, and the maintenance status label represents the fault risk level for the power distribution communication network; In response to determining that the operation and maintenance status label is a high-risk status label, negative scheduling policy information for network resources is generated based on the current scheduling policy information corresponding to the power distribution communication network and the operation and maintenance status label, and used as the updated scheduling policy information. In response to determining that the operation and maintenance status label is a security status label, positive scheduling policy information for network resources is generated based on the current scheduling policy information and the operation and maintenance status label, and used as the updated scheduling policy information.

2. The method according to claim 1, characterized in that, The step of scheduling resources in the power distribution communication network according to the current scheduling policy information or the updated scheduling policy information includes: Based on the current scheduling policy information or the updated scheduling policy information, as well as the operation and maintenance status label and fault prediction model, abnormal operation and maintenance information is determined; When it is determined that the abnormal operation and maintenance information indicates that there is a control abnormality in the current scheduling strategy information or the updated scheduling strategy information, an emergency instruction corresponding to the abnormal operation and maintenance information is determined in the abnormal operation and maintenance decision tree. According to the emergency instructions, the service flow rate of relevant communication nodes in the power distribution communication network is limited, or the security protection system is activated to block abnormal access.

3. The method according to claim 1, characterized in that, The step of preprocessing the real-time operation and maintenance data stream to obtain a preprocessed operation and maintenance data stream includes: For each piece of real-time operation and maintenance data in the real-time operation and maintenance data stream, perform the following processing steps: Perform data validity verification on the real-time operation and maintenance data; In response to determining that the real-time operation and maintenance data has passed the validity verification, the real-time operation and maintenance data is subjected to message noise filtering to obtain filtered operation and maintenance data. The filtered operation and maintenance data is then subjected to data standardization processing to obtain standardized operation and maintenance data; Determine the collection granularity corresponding to the real-time operation and maintenance data stream, wherein the collection granularity characterizes the data collection frequency of the real-time operation and maintenance data stream; In response to determining that the acquisition granularity is not the benchmark acquisition granularity and that the acquisition granularity is smaller than the benchmark acquisition granularity, the standardized operation and maintenance dataset is downsampled using the benchmark acquisition granularity to obtain the preprocessed operation and maintenance data stream.

4. The method according to claim 2, characterized in that, The step of determining the monitoring window based on the preprocessed maintenance data stream includes: Initialize the window length corresponding to the monitoring window to obtain the initial monitoring window, wherein the window length of the initial monitoring window is the initial window length; Based on the initial window length and the preprocessed maintenance data stream, the following window determination steps are performed: Determine the target operation and maintenance data stream, where the target operation and maintenance data in the target operation and maintenance data stream is the preprocessed operation and maintenance data located within the initial monitoring window; Calculate the average value of operation and maintenance data based on the target operation and maintenance data flow; Based on the target operation and maintenance data stream, the average operation and maintenance data, the first target operation and maintenance data, and the second target operation and maintenance data, calculate the window feature value of the initial monitoring window, where the first target operation and maintenance data is the maximum value of the target operation and maintenance data stream, and the second target operation and maintenance data is the minimum value of the target operation and maintenance data stream; In response to determining that the average value of operation and maintenance data is greater than or equal to the dynamic risk threshold, the initial monitoring window is determined as the monitoring window, wherein the dynamic risk threshold is dynamically configured according to the distribution network topology. In response to the determination that the average value of the operation and maintenance data is less than the dynamic risk threshold, the window length of the initial monitoring window is incremented to obtain a monitoring window with an increased length, which is then used as the initial monitoring window, and the window determination step is executed again.

5. The method according to claim 3, characterized in that, The step of determining the operation and maintenance status label based on the target operation and maintenance data stream includes: For each target operation and maintenance data point in the target operation and maintenance data stream, the network health index is calculated according to the following formula: ; in, Let i be the bandwidth utilization at time i. Let i be the network latency at time i. For node idle computing resources, Total computing resources for the node The weighting coefficients and ; In response to the network health index continuously falling below the high-risk threshold Upon reaching the first time window, the operation and maintenance status label is determined to be a high-risk status label; In response to the network health index continuously exceeding the security threshold Upon reaching the second time window, the operation and maintenance status label is determined to be a safe status label.

6. The method according to claim 4, characterized in that, The fault prediction model is constructed through the following steps: Extracting features of sudden changes in business flow: ; in, Let be the traffic mutation rate at time t. Let t be the business traffic at time t. For the service traffic at time t-1, To prevent extremely small positive numbers with a denominator of zero; Extracting channel contention coefficients: ; in, Let be the channel contention coefficient at time t. This represents the current number of channel requests. The maximum number of requests that the channel can support. Let j be the length of the channel queue. This is the total channel queue length; The mutation characteristics and competition coefficients are input into the LSTM time series model, which outputs the future... Failure probability during a time period ,in For the predicted time interval.

7. The method according to claim 1, characterized in that, The abnormal operation and maintenance decision tree includes: First-level node: Determine the business flow mutation rate Has the safety limit been exceeded? ,in This serves as a safe threshold for the business flow mutation rate. Second-level node: Responding to Detect whether it exists Attack characteristics; Third-level node: Responds to existence The attack characteristics were identified, and the first emergency command was output to activate the traffic scrubbing service. Fourth-level node: responds to non-existence Attack characteristics, output second emergency command to execute network element isolation.

8. The method according to claim 6, characterized in that, It also includes a network slicing resource isolation mechanism: allocating dedicated network slices for distribution automation services. ; in: For the frequency band range of slice k, This is the minimum value in the frequency band. This is the maximum value of the frequency band. Given the maximum time delay requirement for slice k, Let k be the maximum bit error rate of slice k.

9. The method according to claim 7, characterized in that, Forward scheduling strategies include: using Q-learning-based radio resource block allocation. ; in, For state Next action Q value, For learning rate, To perform the action The subsequent reward value, As a discount factor, To perform the action The next state after that, This is an optional action for the next state; state Defined as the resource utilization rate of each slice, action For spectrum allocation schemes, rewards For business Satisfaction rate improvement value.

10. The method according to claim 1, characterized in that, It also includes security protection mechanisms: establishing a fingerprint database for power distribution terminal equipment. ; in, The device's fingerprint identifier is represented by the MAC address, the IMEI (International Mobile Equipment Identity), and the CETF (Digital Certificate). XOR operation; Hash is a hash function. In response to the detection of an unregistered device accessing the network, a deep packet inspection of the signaling system is triggered: ; in, The threat level is represented by N, and the number of detected features is N. Let i be the weight of the i-th feature. Let be the anomaly value of the i-th feature; where, For the set of work order instructions, For the first Individual device fingerprint identifier, For the first Scheduling actions for individual devices; Commands are sent to the network management system via the northbound interface; command execution status is monitored in real time. ,in For the first The execution status of the instruction; When it exists At that time, the manual intervention protocol is activated.