Power protection measurement and control terminal information security protection method, system, equipment and medium

By constructing a power grid environment fingerprint database and quantum key distribution nodes, and combining power knowledge graphs and graph neural networks, the real-time perception and response delay problems of traditional power Internet of Things security solutions are solved, achieving efficient security protection for the power system and adapting to quantum computing threats.

CN120956444APending Publication Date: 2025-11-14GUIZHOU POWER GRID CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510880268.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

Traditional power Internet of Things (IoT) security solutions rely on static cryptography and preset rules, which are difficult to cope with complex and ever-changing electromagnetic environments and network attacks. They lack real-time environmental awareness capabilities, and there are delays in threat detection and response. Power monitoring and control terminals have difficulty recognizing the executed instructions, which poses a risk of power grid failure.

Method used

By collecting physical quantities of the power grid to construct an environmental fingerprint database, threat level assessments are conducted and security strategies are adjusted. Based on quantum key distribution nodes, differentiated secure transmission is provided. Anomaly detection is performed by combining power knowledge graphs and graph neural networks, thus realizing hybrid encrypted transmission of quantum and power line carrier.

Benefits of technology

It achieves real-time perception and adaptive response to complex electromagnetic environments, improves the system's environmental adaptability and security protection capabilities, eliminates response delays, constructs a hybrid encryption system resistant to quantum computing attacks, and ensures the long-term security and reliability of the power Internet of Things.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956444A_ABST
    Figure CN120956444A_ABST
Patent Text Reader

Abstract

The invention discloses an electric power protection measurement and control terminal information security protection method, system and device and a medium, and the method comprises the steps: building an environment fingerprint database through collecting the physical quantity of a power grid, carrying out the threat level evaluation, and adjusting a security strategy; based on the environment fingerprint database and the threat level evaluation result, classifying the transmission data, deploying quantum key distribution nodes in the transformer substation, and providing differentiated secure transmission for different types of transmission data; and in combination with the environment fingerprint database and the differentiated secure transmission data, executing cognitive security analysis, establishing an anomaly detection model, and obtaining threat traceability visual positioning. According to the method, the dynamic environment fingerprint database is constructed by collecting multi-dimensional physical quantities and is bound with the digital certificate to form a dual authentication mechanism, so that the defect that a traditional scheme depends on static cryptography is overcome, real-time perception and adaptive response to a complex and changeable electromagnetic environment are realized, and the security of the system is improved. And the environmental adaptability and the safety protection capability of the system are obviously improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to methods, systems, equipment and media for information security protection of power protection and control terminals. Background Technology

[0002] Traditional power IoT security solutions mainly rely on static cryptography and preset rules, which are difficult to cope with complex and ever-changing electromagnetic environments and network attacks. They also lack real-time environmental awareness capabilities, resulting in delays in threat detection and response. Under the threat of quantum computing, traditional encryption algorithms face the risk of being cracked, making it difficult to meet the real-time and reliability requirements of the power IoT. Furthermore, power monitoring and control terminals lack effective analysis of executed instructions, making it difficult to identify erroneous executed instructions when the power system is attacked, thus posing a risk of power grid failure. Summary of the Invention

[0003] In view of the aforementioned existing problems, the present invention is proposed.

[0004] Therefore, this invention provides a method, system, device, and medium for information security protection of power protection and control terminals. This addresses the problem that traditional power Internet of Things security solutions mainly rely on static cryptography and preset rules, which are difficult to cope with complex and ever-changing electromagnetic environments and network attacks, and lack real-time environmental awareness capabilities, resulting in delays in threat detection and response.

[0005] To solve the above-mentioned technical problems, the present invention provides the following technical solution:

[0006] In a first aspect, the present invention provides a method for information security protection of a power protection and control terminal, comprising:

[0007] An environmental fingerprint database is constructed by collecting physical quantities of the power grid, and threat level assessments are conducted to adjust security strategies.

[0008] Based on the environmental fingerprint database and threat level assessment results, the transmitted data is classified, and quantum key distribution nodes are deployed in substations to provide differentiated secure transmission for different types of transmitted data;

[0009] By combining the environmental fingerprint database and differentiated secure transmission data, cognitive security analysis is performed to establish an anomaly detection model and obtain visualized location of threat sources.

[0010] As a preferred embodiment of the power protection and control terminal information security protection method of the present invention, the adjustment step of the security strategy includes:

[0011] Obtain the types of physical quantities in the power grid and timestamp each type of physical quantity in the power grid.

[0012] The identified physical quantities of the power grid are linked to digital certificates to form an environmental fingerprint database;

[0013] Establish a threat level assessment matrix and quantify the threat level based on the types of physical quantities in the power grid;

[0014] A comprehensive threat index is calculated, and security strategies are adjusted based on this index.

[0015] The beneficial effects of this preferred technical solution are as follows: by binding timestamp identifiers and digital certificates, a dynamic environment fingerprint authentication system is constructed, which significantly improves the security and environmental adaptability of identity verification compared with traditional single authentication methods.

[0016] As a preferred embodiment of the power protection and control terminal information security protection method of the present invention, the operation steps of the threat level assessment matrix include:

[0017] Electromagnetic interference intensity is assessed using preset frequency band energy.

[0018] Network traffic anomaly is assessed using the entropy mutation rate;

[0019] Equipment temperature deviation is assessed by comparing the current temperature value with the historical baseline.

[0020] As a preferred embodiment of the power protection and control terminal information security protection method of the present invention, the cognitive security analysis step includes:

[0021] Constructing a power knowledge graph;

[0022] The equipment information is mapped into the power knowledge graph to establish the association between physical equipment and the logical model;

[0023] Semantic-level data verification is performed based on the aforementioned power knowledge graph;

[0024] Build an anomaly detection model to identify abnormal events.

[0025] The beneficial effects of this preferred technical solution are as follows: by establishing a mapping relationship between physical devices and logical models through the power knowledge graph, semantic-level data verification is achieved. Compared with the traditional rule-based verification method, it has stronger semantic understanding and anomaly recognition capabilities.

[0026] As a preferred embodiment of the power protection and control terminal information security protection method of the present invention, the step of differentiated secure transmission includes:

[0027] The transmitted data is divided into two categories: critical control commands and routine data.

[0028] Key control commands are transmitted encrypted via a quantum channel, with the key obtained in real time from the quantum key distribution node.

[0029] Regular data is transmitted encrypted via power line carrier, and session keys are derived using the substation master key.

[0030] The beneficial effects of this preferred technical solution are: it enables differentiated encrypted transmission of critical control commands and routine data; the quantum channel ensures the absolute security of critical commands; and the power line carrier ensures the efficient transmission of routine data, achieving an optimal balance between security and efficiency.

[0031] As a preferred embodiment of the power protection and control terminal information security protection method of the present invention, the comprehensive threat index is calculated using a weighted Euclidean distance model, and the calculation formula is as follows:

[0032]

[0033] In the formula, G is the threat index, E is the electromagnetic interference intensity score, N is the network traffic anomaly score, and T is the equipment temperature deviation score.

[0034] As a preferred embodiment of the power protection and control terminal information security protection method of the present invention, the anomaly detection model adopts a graph neural network structure and identifies operation sequences that violate power grid operation procedures, communication connections that deviate from standard topology and atypical equipment state combinations through a multi-head attention mechanism.

[0035] The operation steps of the multi-head attention mechanism include:

[0036] Feature encoding is performed on the node information in the power knowledge graph to obtain node feature vectors;

[0037] Based on the node feature vectors, the attention weights between nodes are calculated to obtain the degree of association between nodes;

[0038] The attention weights are assigned to multiple attention heads to process different types of relation patterns in parallel.

[0039] The weighted feature outputs of all attention heads are aggregated to form a comprehensive node, and based on the comprehensive node, operational sequences that violate power grid operation procedures, communication connections that deviate from standard topology, and atypical equipment state combinations are identified.

[0040] The beneficial effects of this preferred technical solution are: by using the multi-head attention mechanism of graph neural networks, parallel identification of multiple types of anomalies in complex power systems can be achieved. Compared with traditional single detection models, it has stronger multimodal fusion analysis capabilities and anomaly detection accuracy.

[0041] Secondly, the present invention provides an information security protection system for power protection and control terminals, including an environmental fingerprint database construction module, a security strategy adjustment module, a node deployment module, and a threat tracing and visualization positioning module.

[0042] The environmental fingerprint database construction module is responsible for collecting physical quantities of the power grid and constructing the environmental fingerprint database;

[0043] The security policy adjustment module assesses the level of threats faced based on information from the environmental fingerprint database and adjusts the security policy in a timely manner according to the assessment results.

[0044] The node deployment module deploys quantum key distribution nodes in the substation, using quantum key distribution technology to provide high-security-level differentiated secure transmission guarantees for different types of transmitted data;

[0045] The threat tracing and visualization localization module utilizes the previously established anomaly detection model to achieve threat tracing and visualization localization.

[0046] Thirdly, the present invention provides an electronic device, comprising:

[0047] Memory and processor;

[0048] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the power protection and control terminal information security protection method are implemented.

[0049] Fourthly, the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the power protection and control terminal information security protection method.

[0050] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0051] By collecting multi-dimensional physical quantities to construct a dynamic environmental fingerprint database and binding it with digital certificates to form a dual authentication mechanism, the shortcomings of traditional schemes that rely on static cryptography are overcome. This enables real-time perception and adaptive response to complex and ever-changing electromagnetic environments, significantly improving the system's environmental adaptability and security protection capabilities.

[0052] A threat assessment matrix was established, and a weighted Euclidean distance model was used to calculate the comprehensive threat index. The data sampling frequency, encryption algorithm strength, and communication protocol were dynamically adjusted according to the threat level. This solved the problem that traditional preset rules could not cope with changes in network attacks, achieved real-time threat detection and response, and eliminated the security risks of system response delay.

[0053] By employing quantum key distribution technology to provide quantum-level encryption protection for critical control commands, and combining it with power line carrier channels to achieve efficient transmission of conventional data, a hybrid encryption system resistant to quantum computing attacks has been constructed. This effectively addresses the threat of quantum computing to traditional encryption algorithms and ensures the long-term security and reliability of the power Internet of Things in the quantum era. Attached Figure Description

[0054] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0055] Figure 1 This is a schematic diagram of the overall process of the power protection and control terminal information security protection method according to an embodiment of the present invention. Detailed Implementation

[0056] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0057] Example 1, referring to Figure 1 As an embodiment of the present invention, a method for information security protection of a power protection and control terminal is provided, comprising steps S1 to S3:

[0058] S1: Construct an environmental fingerprint database by collecting physical quantities of the power grid, conduct threat level assessments, and adjust security strategies accordingly;

[0059] S2: Based on the environmental fingerprint database and threat level assessment results, the transmitted data is classified, and quantum key distribution nodes are deployed in substations to provide differentiated secure transmission for different types of transmitted data;

[0060] S3: Combining environmental fingerprint database and differentiated secure transmission data, perform cognitive security analysis, establish anomaly detection models, and obtain visualized location of threat sources.

[0061] It should be noted that traditional power Internet of Things security solutions mainly rely on static cryptography and preset rules, which are significantly insufficient when facing complex and ever-changing electromagnetic environments and network attacks. The lack of real-time environmental awareness leads to delays in threat detection and response. Under the threat of quantum computing, traditional encryption algorithms are at risk of being cracked. Power measurement and control terminals lack effective analysis capabilities for executed instructions, making it difficult to identify erroneous executed instructions when the power system is attacked, thus posing a risk of power grid failure.

[0062] Therefore, to address the aforementioned security protection and threat identification issues, a dynamic environmental fingerprint authentication system based on multi-dimensional physical quantity perception is constructed through steps S1-S3 to achieve real-time perception and adaptive response to complex electromagnetic environments; a quantum-carrier hybrid encryption transmission architecture is established to provide quantum-level security protection for critical control commands and an efficient transmission channel for routine data; based on power knowledge graphs and graph neural network technologies, deep semantic analysis and anomaly identification of executed commands are achieved, providing visualized location for threat tracing, thereby comprehensively improving the information security protection capabilities of power measurement and control terminals.

[0063] Example 2, refer to Figure 1 As an embodiment of the present invention, based on the above embodiment, a method for information security protection of power protection and control terminals is provided.

[0064] In this embodiment of the application, step S1 involves collecting power grid physical quantities to construct an environmental fingerprint database, conducting threat level assessments and adjusting security strategies, and obtaining multi-dimensional power grid physical quantities and timestamping them to form a dual authentication mechanism bound to digital certificates.

[0065] In one alternative implementation, the physical quantities of the power grid collected in step S1 can also be improved by expanding the coverage of the sensor network, increasing the monitoring of power quality parameters such as power factor changes and voltage imbalance, and combining machine learning algorithms to automatically identify abnormal patterns, thereby improving the comprehensiveness and accuracy of environmental perception.

[0066] In another alternative implementation, the environmental fingerprint database constructed in step S1 can also employ blockchain technology to ensure the immutability of fingerprint data, improve data reliability through distributed storage, and achieve data sharing and verification under privacy protection by combining homomorphic encryption technology.

[0067] In this embodiment of the application, the security policy adjustment step in step S1 includes steps A1 to A4:

[0068] A1: Obtain the types of physical quantities in the power grid and timestamp each type of physical quantity in the power grid;

[0069] Specifically, in step A1, the physical quantities of the power grid include, but are not limited to: the power grid frequency collected by the high-precision frequency measuring instrument, the harmonic characteristics of the current waveform collected by the harmonic analyzer, the voltage fluctuation characteristics collected by the voltage transient recorder, the equipment vibration modes collected by the triaxial MEMS vibration sensor, and the spatial electromagnetic radiation collected by the broadband electromagnetic field probe. Each physical quantity is marked with a high-precision timestamp after being collected to ensure the temporal consistency and traceability of the data.

[0070] A2: Bind the identified physical quantities of the power grid with digital certificates to form an environmental fingerprint database;

[0071] A3: Establish a threat level assessment matrix and quantify the threat level based on the types of physical quantities in the power grid;

[0072] Specifically, in step A3, the specific quantitative scoring method for the threat level assessment matrix is ​​as follows:

[0073] Electromagnetic interference intensity is assessed using energy in the 30MHz-1GHz frequency band, with scores of 0-3 corresponding to less than 10V / m and scores of 7-10 corresponding to greater than 100V / m.

[0074] Network traffic anomaly is assessed using the entropy mutation rate based on Shannon entropy, with 0-3 points corresponding to less than 5% and 7-10 points corresponding to greater than 30%.

[0075] Equipment temperature deviation is assessed by comparing the current value with the historical baseline temperature. A score of 0-3 corresponds to less than ±2℃, and a score of 7-10 corresponds to greater than ±10℃.

[0076] A4: A comprehensive threat index is calculated, and security strategies are adjusted based on the threat index.

[0077] In step A4, the comprehensive threat index is calculated using a weighted Euclidean distance model, and the calculation formula is as follows:

[0078]

[0079] In the formula, G is the threat index, E is the electromagnetic interference intensity score, N is the network traffic anomaly score, and T is the equipment temperature deviation score.

[0080] Dynamic adjustments are made based on the threat index level: for the 0-3 minute period, a 1kHz data sampling frequency, SM4 encryption algorithm, and UDP communication protocol are used.

[0081] The data sampling frequency is 5kHz, the encryption algorithm is AES-256, and the TCP+UDP hybrid communication protocol is used from 4 to 6 minutes.

[0082] The system uses a 10kHz data sampling frequency, AES-256+ chaotic obfuscation encryption algorithm, and TCP+ redundancy check communication protocol for the 7-10 minute interval.

[0083] In an optional implementation, the threat level assessment in step S1 can also incorporate auxiliary parameters such as device load rate and communication latency, automatically optimize the assessment weights through machine learning algorithms, and combine them with a historical attack pattern database for threat prediction, thereby improving the accuracy and foresight of the assessment.

[0084] In another optional implementation, the security policy adjustment in step S1 can also adopt a reinforcement learning method, with security and operational efficiency as reward functions. The agent automatically learns the optimal adjustment policy through interaction with the environment, thereby achieving more intelligent adaptive security protection.

[0085] In this embodiment of the application, the steps for operating the threat level assessment matrix include B1 to B3:

[0086] B1: Electromagnetic interference intensity is assessed using preset frequency band energy;

[0087] Specifically, in step B1, the electromagnetic interference intensity assessment uses a broadband electromagnetic field probe to monitor the 30MHz-1GHz frequency band in real time. The electric field intensity value at each frequency point is obtained through a spectrum analyzer, the energy integral within the frequency band is calculated, and it is compared with a preset threat level threshold. A score of 0-3 corresponds to a normal environment with an electric field intensity of less than 10V / m, a score of 4-6 corresponds to a moderate interference environment of 10V / m to 100V / m, and a score of 7-10 corresponds to a strong interference environment of greater than 100V / m. The scoring results are used to quantify the potential threat level of the electromagnetic environment.

[0088] B2: Network traffic anomaly is assessed using the entropy mutation rate;

[0089] Specifically, in step B2, the network traffic anomaly assessment is based on Shannon's entropy theory. It calculates the information entropy value within a unit time window by collecting characteristic parameters such as the source address, destination address, port number, and protocol type of network data packets in real time, and monitors the mutation rate of the entropy value to identify abnormal traffic patterns. The entropy mutation rate is calculated as the percentage change between the entropy value of the current time window and the entropy value of the previous time window. When the mutation rate is less than 5%, the score is 0-3 points; when it is 5%-30%, the score is 4-6 points; and when it is greater than 30%, the score is 7-10 points. This method can effectively identify network threats such as DDoS attacks and data injection attacks.

[0090] B3: Equipment temperature deviation is assessed by the temperature difference between the current value and the historical baseline.

[0091] Specifically, in B3, the equipment temperature deviation assessment monitors the operating temperature in real time through temperature sensors deployed on critical equipment, establishes a temperature baseline model based on historical data, and calculates the deviation between the current temperature and the baseline temperature. The temperature baseline is established through statistical analysis of temperature data over a historical period, including statistical parameters such as mean and standard deviation. The current temperature deviation is the absolute difference between the measured temperature and the baseline temperature. When the deviation is less than ±2℃, the score is 0-3 points; when it is ±2℃ to ±10℃, the score is 4-6 points; and when it is greater than ±10℃, the score is 7-10 points. This assessment can promptly identify potential safety threats such as equipment overheating and abnormal environment.

[0092] It should be noted that the aforementioned three-dimensional threat assessment system, through the coordinated monitoring of three different dimensions—electromagnetism, network, and temperature—can comprehensively capture the diverse threats faced by the power system. The entropy mutation detection method identifies abnormal patterns by analyzing the random changes in network traffic, and the temperature baseline deviation analysis detects abnormal states by establishing the normal operating temperature range of equipment. The fusion of multi-dimensional assessment results provides a reliable quantitative basis for the dynamic adjustment of subsequent security strategies.

[0093] In an optional implementation, the electromagnetic interference intensity assessment in step B1 can also be combined with spectrum occupancy analysis. By monitoring the channel occupancy of key frequency bands, malicious electromagnetic interference sources can be identified, and adaptive filtering techniques can be used to reduce the impact of interference on communication quality.

[0094] In another alternative implementation, the network traffic anomaly assessment in step B2 can also incorporate deep packet inspection technology, combined with protocol behavior analysis and machine learning algorithms, to build a more accurate abnormal traffic identification model and improve the ability to detect unknown attack patterns.

[0095] In this embodiment of the application, step S2, the differentiated secure transmission step includes steps C1 to C3:

[0096] C1: The transmitted data is divided into two categories: critical control commands and routine data;

[0097] Specifically, in step C1, the transmitted data is classified based on the importance and real-time requirements of the data. Key control commands include control information that directly affects the safe operation of the power grid, such as circuit breaker opening and closing commands, protection setting modification commands, and emergency shutdown commands. Regular data includes monitoring and statistical information such as voltage and current measurements, equipment status information, and historical operating data. The classification criteria include the execution priority of the command, the degree of impact on safety, the sensitivity level of the data, and the transmission delay requirements. The data type is automatically identified through a preset data classification rule table and intelligent analysis algorithm to ensure that different types of data adopt corresponding safe transmission strategies.

[0098] C2: Key control commands are transmitted encrypted via a quantum channel, with the key obtained in real time from the quantum key distribution node;

[0099] Specifically, in step C2, the quantum channel transmission of critical control commands adopts a quantum key distribution network. A quantum key distribution terminal is deployed as the master node in the substation, and slave nodes are deployed near the critical primary equipment to form a star topology. The quantum channel uses single-mode fiber to connect the master and slave nodes, and the fiber length is limited to within 50km. The classical channel transmits negotiation information and HMAC signatures through an Ethernet channel. The quantum key generation process includes two stages: photon polarization encoding and key negotiation. The master node generates a random bit sequence and maps 0 / 1 bits to horizontal / vertical polarization states or left / right-hand polarization states through a polarization modulator. A decoy state protocol is used to prevent photon number splitting attacks. The slave node measures the polarization state of the received photons, calculates the bit error rate by comparing a portion of the bit sequence through the classical channel, and uses the Cascade protocol for error correction. Finally, a symmetric one-time key pool is generated. Critical control commands are encrypted using the AES-256-GCM algorithm. The key is obtained from the quantum key distribution node in real time, and a new key pool is generated every 5 minutes for dynamic key management.

[0100] C3: Regular data is transmitted encrypted via power line carrier, and session keys are derived using the substation master key.

[0101] In step C3, the power line carrier transmission of regular data adopts an identity-based encryption scheme. Power lines are used as the communication medium, and digital signals are modulated onto the power lines through a power line carrier modulation module. The substation master key is used as the key, and an independent session key is derived for each communication session. The key derivation algorithm is based on the HMAC-SHA256 hash function, combined with timestamps, device identifiers, and random numbers to generate session keys, ensuring that different encryption keys are used for each communication. Regular data transmission adopts the SM4 symmetric encryption algorithm, which has high encryption efficiency and is suitable for the real-time transmission needs of large amounts of monitoring data. At the same time, a forward security mechanism is adopted, so even if the session key is cracked, it will not affect the security of other sessions.

[0102] It should be noted that the aforementioned differentiated secure transmission mechanism achieves an optimal balance between security and efficiency by using different encryption channels and security strategies for critical control commands and regular data. Quantum key distribution provides theoretically unbreakable security for critical commands, while power line carrier transmission provides an efficient and convenient transmission method for regular data. The hybrid transmission architecture ensures the absolute security of core services while avoiding the impact of quantum communication bandwidth limitations on overall performance. The dynamic key management and session isolation mechanism further enhance the anti-attack capability.

[0103] In an optional implementation, the data classification in step C1 can also incorporate machine learning classification algorithms. By analyzing the transmission patterns, importance, and security requirements of historical data, the algorithm automatically learns and optimizes data classification rules. Combined with deep learning models, it identifies the semantic features of data packets, achieving more accurate data type identification. At the same time, a dynamic classification mechanism is established to adjust the data classification strategy in real time according to the operating status and threat level. For example, in a high-threat environment, some regular data can be temporarily upgraded to critical data for quantum encryption transmission, and in a normal environment, the regular transmission mode can be restored. Adaptive classification improves flexibility and security protection capabilities.

[0104] In another optional implementation, the hybrid transmission mechanism in steps C2 and C3 can also be combined with blockchain technology to establish a distributed key management system. The generation, distribution, and usage records of quantum keys and session keys are stored on the blockchain to ensure the transparency and immutability of key management. Key rotation and expiration are automatically executed through smart contracts, and a multi-signature mechanism is established to ensure the authorization and compliance of key operations. At the same time, a key custody and recovery mechanism is introduced to securely restore communication capabilities in the event of equipment failure or key loss. In addition, a cross-regional quantum key sharing network can be established to extend the quantum communication distance through quantum repeater technology, realize quantum secure communication coverage of a large-scale power system, and improve the security protection level of the entire power Internet of Things.

[0105] In this embodiment of the application, the cognitive security analysis step S3 includes steps D1 to D4:

[0106] D1: Constructing a power knowledge graph;

[0107] Specifically, in step D1, the power knowledge graph construction integrates multi-source data such as equipment ledgers, historical fault records, operation tickets, and IEC 61850 model files. It uses RDF triples to represent entities such as equipment, faults, and operations, as well as their relationships, forming a structured knowledge representation system. Entities include physical equipment such as transformers, circuit breakers, and disconnectors; relationships include connection relationships, control relationships, and state relationships; and attributes include equipment parameters, operating status, and historical records. The complex power system topology relationships and semantic information are stored and managed through a graph database.

[0108] D2: Map device information to the power knowledge graph to establish the relationship between physical devices and logical models;

[0109] Specifically, in step D2, the device information mapping process establishes an association between logical devices and logical nodes in the IEC 61850 standard and physical devices in the power knowledge graph. Automatic matching is achieved through key fields such as device identification codes and function codes to establish a two-way mapping relationship between physical devices and logical models, so that each physical device corresponds to a corresponding logical node. For example, circuit breaker devices correspond to XCBR logical nodes, and power metering devices correspond to MMXU logical nodes. This mapping relationship enables standardized description and management of device functions, status, and operation.

[0110] D3: Semantic-level data validation based on power knowledge graph;

[0111] Specifically, in step D3, semantic-level data verification is performed based on the power knowledge graph, including three levels: topology constraint verification, operation specification verification, and state association verification. Topology constraint verification ensures basic electrical connection rules such as the busbar must be connected to at least two circuit breakers. Operation specification verification verifies the compliance of operation sequences such as the busbar side disconnect switch must be closed before the line is energized. State association verification checks the logical consistency of equipment states such as the corresponding interval current should be less than 0.1A when the circuit breaker is in operation. The semantic reasoning engine automatically detects abnormal situations that violate the power system operation procedures.

[0112] D4: Build an anomaly detection model to identify abnormal events.

[0113] Specifically, in step D4, the anomaly detection model adopts a graph neural network structure. By encoding the node information in the power knowledge graph, it obtains node feature vectors. Based on the node feature vectors, it calculates the attention weights between nodes to obtain the degree of correlation between nodes. The attention weights are assigned to multiple attention heads to process different types of relationship patterns in parallel. The weighted feature outputs of all attention heads are aggregated to form a comprehensive node representation. Based on the comprehensive node representation, it identifies operation sequences that violate power grid operation procedures, communication connections that deviate from standard topology, and atypical equipment state combinations, thereby realizing intelligent identification of abnormal events and threat tracing and location.

[0114] It should be noted that the above-mentioned cognitive security analysis system, through the construction of a power knowledge graph, unifies the multi-dimensional information of the power system, such as physical topology, logical relationships, and operating rules, and realizes a deep semantic understanding of the power system. The graph neural network anomaly detection model can capture complex cross-modal feature relationships through a multi-head attention mechanism. Compared with traditional rule-based or statistical detection methods, it has stronger generalization ability and the ability to identify unknown attack patterns, providing intelligent security protection for power measurement and control terminals.

[0115] In an optional implementation, the power knowledge graph construction in step D1 can also incorporate natural language processing technology to automatically extract entities and relationships from documents such as equipment manuals, operation manuals, and technical specifications. Named entity recognition algorithms are used to identify key information such as equipment names, models, and parameters. Relationship extraction models are used to mine connection relationships, control relationships, and dependencies between equipment. Knowledge fusion algorithms are used to eliminate redundant and conflicting information from different data sources. Entity alignment and relationship matching technologies are employed to ensure the consistency of the knowledge graph. Simultaneously, a dynamic update mechanism is established to automatically update the knowledge graph content when the power system configuration changes, improving the completeness, accuracy, and real-time performance of the knowledge graph and providing a reliable knowledge foundation for subsequent semantic analysis and anomaly detection.

[0116] In another optional implementation, the anomaly detection model in step D4 can also adopt a federated learning framework. Under the premise of protecting the data privacy of each substation, the generalization performance of the model can be improved through multi-site collaborative training. Specifically, each substation trains a graph neural network model locally, sharing only the model parameters without transmitting the original data. The model parameters of each site are aggregated through a federated averaging algorithm to form a globally optimized anomaly detection model. At the same time, differential privacy technology is introduced to add noise during parameter sharing to protect data privacy. In addition, a continuous learning mechanism can be combined to enable the model to learn new attack patterns without forgetting historical knowledge. Through techniques such as experience replay and elastic weight consolidation, catastrophic forgetting problems are avoided, ensuring that the model maintains stable detection performance in dynamic environments and achieves rapid adaptation and identification of emerging threats.

[0117] In this embodiment, the anomaly detection model adopts a graph neural network structure and uses a multi-head attention mechanism to identify operation sequences that violate power grid operation procedures, communication connections that deviate from standard topology, and atypical equipment state combinations.

[0118] The multi-head attention mechanism operates through steps E1 to E4:

[0119] E1: Encode the node information in the power knowledge graph to obtain the node feature vector;

[0120] Specifically, in step E1, the node feature encoding process converts the heterogeneous node information in the power knowledge graph into a unified feature vector representation. The node types include physical nodes, logical nodes, operational nodes, and status nodes. Physical nodes contain attribute information such as equipment type, manufacturer code, commissioning year, and current load rate. Logical nodes map to IEC 61850 logical nodes such as XCBR and MMXU, and contain information such as logical node type, dataset members, functional constraints, and health status. Operational nodes represent control operation instructions and contain attributes such as operation type, execution time, operation object, and permission level. Status nodes reflect the operating status of equipment and contain information such as status type, occurrence time, severity level, and related equipment. The categorical features are converted into dense vectors through the embedding layer, and the numerical features are normalized to finally form a fixed-dimensional node feature vector.

[0121] E2: Calculate the attention weights between nodes based on node feature vectors to obtain the degree of association between nodes;

[0122] Specifically, in step E2, the attention weight calculation is based on the quantitative evaluation of the similarity and correlation between node feature vectors. By calculating the attention score of the dot product between the query vector, key vector, and value vector, the semantic correlation between nodes is evaluated. The calculation of attention weight considers multiple dimensions such as topological distance, functional relevance, and temporal correlation between nodes. Nodes with strong electrical connections are given higher attention weights, and nodes with interdependent functions are also given higher attention. The attention score is normalized by the softmax function to ensure that the sum of the attention weights of all neighboring nodes is 1, forming an attention weight matrix in the form of a probability distribution.

[0123] E3: Distribute attention weights to multiple attention heads to process different types of relation patterns in parallel;

[0124] Specifically, in step E3, the multi-head attention mechanism distributes attention weights to multiple parallel attention heads. Each attention head specializes in handling specific types of relationship patterns. For example, the topology connection head focuses on identifying physical connection relationships between devices, the operation association head analyzes the correlation between operation commands and target devices, the state propagation head focuses on the impact path of device state changes, and the communication connection head identifies communication link patterns between network devices. Different attention heads use different parameter matrices for linear transformation, enabling each head to learn the feature representation of specific types of relationships. Parallel computation improves processing efficiency and enhances the model's ability to model complex relationship patterns.

[0125] E4: Aggregates the weighted feature outputs of all attention heads to form a comprehensive node, and identifies operation sequences that violate power grid operation procedures, communication connections that deviate from standard topology, and atypical equipment state combinations based on the comprehensive node.

[0126] Specifically, in step E4, the multi-head attention output aggregation merges the outputs of each attention head through splicing or weighted averaging to form a comprehensive node representation containing multiple relational information. This comprehensive representation can capture the feature information of nodes in different relational dimensions. Anomaly detection is performed based on the comprehensive node representation. Three types of anomaly patterns are identified by setting thresholds or training classifiers: operation sequences that violate power grid operation procedures are identified by analyzing the association patterns between operation nodes and related equipment nodes; communication connections that deviate from the standard topology are detected by comparing the differences between the actual communication connections and the standard configuration; and atypical equipment state combinations are discovered by analyzing the abnormal association patterns between equipment state nodes. Finally, the anomaly detection results and threat tracing information are output to provide decision support for security protection.

[0127] It should be noted that the above-mentioned multi-head attention mechanism achieves a unified representation of heterogeneous nodes through feature encoding, captures the complex relationships between nodes through attention weight calculation, improves the ability to identify different types of relationship patterns through multi-head parallel processing, and achieves effective fusion of multi-dimensional information through output aggregation. Compared with traditional graph neural network methods, this mechanism can better handle complex topological relationships and multimodal information in power systems, and improves the accuracy and generalization ability of anomaly detection.

[0128] In an optional implementation, the node feature encoding in step E1 can also be combined with a pre-trained language model to perform semantic encoding on unstructured data such as device description text, operation instructions, and status information. Deep semantic features of the text are extracted through BERT or other Transformer models and fused with numerical features to form richer node representations. At the same time, graph embedding techniques such as Node2Vec or GraphSAGE are used to pre-train node representations to capture high-order neighbor information in the graph structure. Multimodal feature fusion improves the quality of node representations and the performance of anomaly detection.

[0129] In another optional implementation, the multi-head attention mechanism in steps E3 and E4 can also introduce temporal attention and hierarchical attention mechanisms. Temporal attention focuses on the change pattern of node states in the time dimension. By assigning different attention weights to the node states at historical moments, it identifies the evolution trend and abnormal change points of device states. Hierarchical attention constructs a multi-layer attention structure, first performing attention calculations in the local subgraph, and then performing attention aggregation at the global graph level, to achieve hierarchical anomaly detection from local to global. At the same time, it combines adversarial training techniques to improve the robustness of the model to attack samples. By generating hard-negative samples through generative adversarial networks to train the detection model, it enhances the ability to identify unknown attack patterns.

[0130] In summary, by collecting multi-dimensional physical quantities to construct a dynamic environmental fingerprint database and binding it with digital certificates to form a dual authentication mechanism, this approach overcomes the shortcomings of traditional schemes that rely on static cryptography. It achieves real-time perception and adaptive response to complex and ever-changing electromagnetic environments, significantly improving the environmental adaptability and security protection capabilities of this application. A threat assessment matrix was established, and a weighted Euclidean distance model was used to calculate the comprehensive threat index. Data sampling frequency, encryption algorithm strength, and communication protocol were dynamically adjusted according to the threat level, solving the problem that traditional preset rules are insufficient to cope with changes in network attacks. This achieves real-time threat detection and response, eliminating the security risks associated with overall response latency. Quantum key distribution technology is used to provide quantum-level encryption protection for critical control commands. Simultaneously, combined with power line carrier channels to achieve efficient transmission of conventional data, a hybrid encryption system resistant to quantum computing attacks is constructed. This effectively addresses the threat of quantum computing to traditional encryption algorithms, ensuring the long-term security and reliability of the power Internet of Things in the quantum era.

[0131] Example 3 illustrates a schematic scheme for a method of protecting the information security of a power protection and control terminal. It should be noted that the technical solution of this power protection and control terminal information security protection system belongs to the same concept as the technical solution of the power protection and control terminal information security protection method described above. Details not described in detail in the technical solution of the power protection and control terminal information security protection system in this embodiment can be found in the description of the technical solution of the power protection and control terminal information security protection method described above.

[0132] This embodiment also provides a power protection and control terminal information security protection system, including an environmental fingerprint database construction module, a security policy adjustment module, a node deployment module, and a threat tracing and visualization positioning module;

[0133] The environmental fingerprint database construction module is responsible for collecting physical quantities of the power grid and constructing the environmental fingerprint database;

[0134] The security policy adjustment module assesses the level of threats based on information from the environmental fingerprint database and adjusts the security policy in a timely manner according to the assessment results.

[0135] The node deployment module deploys quantum key distribution nodes in substations, using quantum key distribution technology to provide differentiated security transmission guarantees with a high level of security for different types of transmitted data;

[0136] The threat attribution visualization and localization module utilizes the previously established anomaly detection model to achieve threat attribution and visualization localization.

[0137] This embodiment also provides an electronic device suitable for information security protection of power protection and control terminals, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to realize the information security protection method for power protection and control terminals proposed in the above embodiment.

[0138] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements the method for protecting the information security of power protection and control terminals as proposed in the above embodiments.

[0139] The storage medium proposed in this embodiment and the method for realizing information security protection of power protection and control terminal proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0140] Based on the above description of the implementation methods, those skilled in the art will clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0141] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for information security protection of power protection and control terminals, characterized in that, include: An environmental fingerprint database is constructed by collecting physical quantities of the power grid, and threat level assessments are conducted to adjust security strategies. Based on the environmental fingerprint database and threat level assessment results, the transmitted data is classified, and quantum key distribution nodes are deployed in substations to provide differentiated secure transmission for different types of transmitted data; By combining the environmental fingerprint database and differentiated secure transmission data, cognitive security analysis is performed to establish an anomaly detection model and obtain visualized location of threat sources.

2. The method for information security protection of a power protection and control terminal as described in claim 1, characterized in that, The steps for adjusting the security policy include: Obtain the types of physical quantities in the power grid and timestamp each type of physical quantity in the power grid. The identified physical quantities of the power grid are linked to digital certificates to form an environmental fingerprint database; Establish a threat level assessment matrix and quantify the threat level based on the types of physical quantities in the power grid; A comprehensive threat index is calculated, and security strategies are adjusted based on this index.

3. The method for information security protection of a power protection and control terminal as described in claim 2, characterized in that, The steps for operating the threat level assessment matrix include: Electromagnetic interference intensity is assessed using preset frequency band energy. Network traffic anomaly is assessed using the entropy mutation rate; Equipment temperature deviation is assessed by comparing the current temperature value with the historical baseline.

4. The method for information security protection of a power protection and control terminal as described in claim 3, characterized in that, The steps of the cognitive security analysis include: Constructing a power knowledge graph; The equipment information is mapped into the power knowledge graph to establish the association between physical equipment and the logical model; Semantic-level data verification is performed based on the aforementioned power knowledge graph; Build an anomaly detection model to identify abnormal events.

5. The method for information security protection of a power protection and control terminal as described in claim 4, characterized in that, The steps of the differentiated secure transmission include: The transmitted data is divided into two categories: critical control commands and routine data. Key control commands are transmitted encrypted via a quantum channel, with the key obtained in real time from the quantum key distribution node. Regular data is transmitted encrypted via power line carrier, and session keys are derived using the substation master key.

6. The method for information security protection of a power protection and control terminal as described in claim 5, characterized in that, The comprehensive threat index is calculated using a weighted Euclidean distance model, and the calculation formula is as follows: In the formula, G is the threat index, E is the electromagnetic interference intensity score, N is the network traffic anomaly score, and T is the equipment temperature deviation score.

7. The method for information security protection of a power protection and control terminal as described in claim 6, characterized in that, The anomaly detection model adopts a graph neural network structure and uses a multi-head attention mechanism to identify operation sequences that violate power grid operation procedures, communication connections that deviate from standard topology, and atypical equipment state combinations. The operation steps of the multi-head attention mechanism include: Feature encoding is performed on the node information in the power knowledge graph to obtain node feature vectors; Based on the node feature vectors, the attention weights between nodes are calculated to obtain the degree of association between nodes; The attention weights are assigned to multiple attention heads to process different types of relation patterns in parallel. The weighted feature outputs of all attention heads are aggregated to form a comprehensive node, and based on the comprehensive node, operational sequences that violate power grid operation procedures, communication connections that deviate from standard topology, and atypical equipment state combinations are identified.

8. A power protection and control terminal information security protection system, using the method described in any one of claims 1-7, characterized in that, It includes an environmental fingerprint database construction module, a security policy adjustment module, a node deployment module, and a threat tracing and visualization module; The environmental fingerprint database construction module is responsible for collecting physical quantities of the power grid and constructing the environmental fingerprint database; The security policy adjustment module assesses the level of threats faced based on information from the environmental fingerprint database and adjusts the security policy in a timely manner according to the assessment results. The node deployment module deploys quantum key distribution nodes in the substation, using quantum key distribution technology to provide high-security-level differentiated secure transmission guarantees for different types of transmitted data; The threat tracing and visualization localization module utilizes the previously established anomaly detection model to achieve threat tracing and visualization localization.

9. An electronic device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, they implement the steps of the power protection and control terminal information security protection method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the power protection and control terminal information security protection method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Wireless communication test method and system based on portable frequency spectrograph, and medium

    CN121194188A

  • A wireless communication test method, system and medium based on a portable spectrum analyzer

    CN121194188B