Cross-power automation system data acquisition method and system based on secure access area
By establishing a data acquisition channel model and a reverse isolation device for the secure access zone in the target system, the problem of resource consumption in cross-power automation system data acquisition was solved, achieving efficient data transmission and parsing, and reducing the consumption of network communication resources and operation and maintenance costs.
Patent Information
- Application Number
- CN202511738177.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-03-06
AI Technical Summary
Existing technologies require long-term use of network and system resources for data acquisition across power automation systems, which cannot efficiently achieve network isolation and data transmission, resulting in resource waste and increased maintenance workload.
By establishing a data acquisition channel model in the target system and utilizing the reverse isolation device of the secure access zone to achieve cross-network isolated transmission of data files, combined with the main station front-end server, data processing unit and visualization software, the reading, parsing and visualization of data files are automatically completed, avoiding long-term network links and data forwarding procedures.
It enables economical and reliable data acquisition across power automation systems, saves network communication resources, reduces software and hardware costs and maintenance workload, and supports data acquisition needs of various heterogeneous source systems.
Smart Images

Figure CN121614439A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to data acquisition across power automation systems, and more particularly to a method and system for data acquisition across power automation systems based on a secure access zone. Background Technology
[0002] In conventional cross-power automation system data acquisition methods, the source and target systems typically establish dedicated network communication. The source system runs a dedicated data forwarding program that assembles the collected power terminal data according to standard specifications and sends it to the target system for processing via the network. To ensure system network security, different power automation systems are isolated from each other. Network communication between systems requires dedicated communication equipment, and network bandwidth is limited. This method requires both parties to maintain a communication link for extended periods, necessitating the running of dedicated programs in the source system and consuming significant network and system resources. To improve the security of power automation systems, secure access zones have been widely used in various power automation system constructions. However, the current use of secure access zones is primarily for network isolation between terminals and the master station, and cannot be directly applied to cross-power automation system data acquisition. Therefore, how to achieve economical and reliable data acquisition between cross-power automation systems with less network and system resources has become an urgent need for intelligent management in the field of power automation. Summary of the Invention
[0003] To address the problems existing in the prior art, the purpose of this invention is to provide a method and system for cross-power automation system data acquisition based on secure access zones, which requires less network and system resources.
[0004] To achieve the above-mentioned objectives, the present invention provides the following technical solution:
[0005] This invention provides a method for data acquisition across power automation systems based on a secure access zone, comprising the following steps:
[0006] (1) Create acquisition channels for the target system and the source system respectively, and associate the acquisition channels of the target system with the acquisition channels of the source system to form an acquisition channel association relationship;
[0007] (2) The target system allocates a corresponding data storage area for the acquisition channel;
[0008] (3) The main station communication server of the source system security access zone obtains the real-time generated power terminal collection data and forms a collection data file together with the source system collection channel identifier. The copy of the collection data file is sent to the main station front-end server of the target system security zone through the reverse isolation device deployed in the security access zone.
[0009] (4) The security access processing unit of the main station front-end server of the target system security zone reads the data collection file, extracts the source system acquisition channel identifier from the data collection file, extracts the target system acquisition channel identifier associated with the source system acquisition channel identifier according to the acquisition channel association relationship, and stores the power terminal acquisition data in the data collection file into the data storage area corresponding to the target system acquisition channel identifier.
[0010] (5) The data processing unit of the main station front-end server in the target system security zone parses the data in the data storage area and saves the parsed data to the data storage area;
[0011] (6) The visualization software of the main station front-end server in the target system security zone reads and parses data from the data storage area according to the acquisition channel selected by the user and then visualizes it.
[0012] Furthermore, in step (1), the information of the acquisition channel created includes: acquisition channel number, acquisition channel name, communication protocol type, and acquisition channel number of other associated systems, wherein the acquisition channel number is the acquisition channel identifier.
[0013] Furthermore, the acquisition channel number of the source system is unique within the source system, the acquisition channel number of the target system is unique within the target system, and the acquisition channel of the source system can only be associated with one acquisition channel in one target system.
[0014] Furthermore, in step (2), the data storage area is implemented using shared memory and includes a raw data storage sub-area and a parsed data storage sub-area for the collected data files.
[0015] Furthermore, in step (3), the name of the data acquisition file generated in the source system includes the system feature identifier of the source system, which is extracted from the source system configuration file.
[0016] Furthermore, the reverse isolation device includes a target path for the collected data file, which is specified by the target system.
[0017] Furthermore, step (4) includes the following:
[0018] Add configuration information to the configuration file of the secure access processing unit. The configuration information includes the system feature identifier of the source system, so that the secure access processing unit only reads the collected data file whose name contains the system feature identifier of the source system.
[0019] Furthermore, in step (5), the target system reads the collected data from the data storage area in ascending order according to the acquisition channel identifier in this system, and the parsed data types include remote signaling and telemetry.
[0020] Furthermore, in step (6), the visualization software can only view the parsed data of one acquisition channel at a time, and displays it in descending order according to the data acquisition time.
[0021] This invention also provides a cross-power automation system data acquisition system based on a secure access zone, comprising a source system end and a target system end, wherein:
[0022] The source system includes:
[0023] The data acquisition module is used to collect power terminal measurement data based on the secure access zone, and form power terminal acquisition data.
[0024] The main station communication server, deployed in the secure access zone, is used to acquire real-time generated power terminal data and form a data acquisition file together with the source system acquisition channel identifier.
[0025] The reverse isolation device, deployed in the secure access zone, is used to send a copy of the collected data file to the main station front-end server in the target system's secure zone;
[0026] The target system includes:
[0027] The secure access processing unit is used to read the collected data file, extract the source system acquisition channel identifier from the collected data file, extract the target system acquisition channel identifier associated with the source system acquisition channel identifier according to the acquisition channel association relationship, and store the power terminal collected data in the collected data file into the data storage area corresponding to the target system acquisition channel identifier.
[0028] The data processing unit is used to parse the data in the data storage area and save the parsed data back to the data storage area;
[0029] Visualization software is used to read and parse data from the data storage area and visualize it according to the acquisition channel selected by the user.
[0030] Compared with existing technologies, the advantages of this invention are as follows: This invention fully utilizes the data acquisition implementation schemes and technical conditions of power automation systems based on secure access zones. By establishing an acquisition channel model in the target system to associate it with the data acquisition channel in the source system, and deploying a reverse isolation device in the secure access zone of the source system, it achieves cross-network isolated transmission of acquired data files without long-term occupation of network resources, existing only briefly during data file transmission. The secure access processing unit, data processing unit, and visualization software of the master station front-end server in the target system's secure zone automatically complete the reading, parsing, and visualization functions of the acquired files. This invention's cross-power automation system data acquisition method based on secure access zones avoids establishing long-term network communication links and data forwarding programs between different systems, saving network communication resources and effectively reducing hardware and software costs and maintenance workload. A single target system can simultaneously meet the data acquisition needs of multiple heterogeneous source systems, demonstrating promising application prospects. Attached Figure Description
[0031] Figure 1 This is a flowchart illustrating the cross-power automation system data acquisition method based on a secure access zone provided in an embodiment of the present invention.
[0032] Figure 2 This is a schematic diagram of the structure of a cross-power automation system data acquisition system based on a secure access zone, provided in an embodiment of the present invention. Detailed Implementation
[0033] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0034] Example 1
[0035] This invention provides a method for data acquisition across power automation systems based on secure access zones, such as... Figure 1 As shown, it includes the following steps:
[0036] (1) Create acquisition channels for the target system and the source system respectively, and associate the acquisition channels of the target system with the acquisition channels of the source system to form an acquisition channel association relationship.
[0037] The created acquisition channel information includes: acquisition channel number, acquisition channel name, communication protocol type, and acquisition channel numbers of other associated systems. The acquisition channel number serves as the acquisition channel identifier. The acquisition channel number of the source system is unique within the source system, and the acquisition channel number of the target system is unique within the target system. An acquisition channel in the source system can only be associated with one acquisition channel in one target system. Optional communication protocol types include IEC 101 and IEC 104.
[0038] For example, taking the OPEN 5200 distribution network automation system and the new generation dispatching technology support system, which collect power terminal measurement data based on secure access, as an example, the OPEN 5200 distribution network automation system is the target system, and the new generation dispatching technology support system is the source system. The model creation tool dbi provided in the OPEN 5200 distribution network automation system is used to create a data acquisition channel. The channel name is "Jiananda Photovoltaic Distributed Power Generation - Unnamed Channel", the channel number is 16196, the protocol type is selected as IEC 104, and the associated acquisition channel number in the new generation dispatching technology support system is 1685.
[0039] (2) The target system allocates a corresponding data storage area for the acquisition channel.
[0040] The data storage area is implemented using shared memory and includes a raw data storage sub-area and a parsed data storage sub-area for the collected data files. The space size is an integer multiple of 4096 bytes, with a minimum of 4096 bytes.
[0041] For example, the OPEN 5200 distribution network automation system allocates 4096 bytes of raw data storage space and 16384 bytes of parsed data storage space for acquisition channel number 16196.
[0042] (3) The main station communication server of the source system security access zone obtains the real-time generated power terminal collection data and forms a collection data file together with the source system collection channel identifier. A copy of the collection data file is sent to the main station front-end server of the target system security zone through the reverse isolation device deployed in the security access zone.
[0043] The name of the collected data file generated in the source system includes the system characteristic identifier of the source system, which is extracted from the source system configuration file. The reverse isolation device has a target path for the collected data file, which is specified by the target system. The security zone includes Security Zone I, Security Zone II, etc. In this embodiment, the main station front-end server is specifically located in Security Zone I.
[0044] For example, in the new generation of dispatching technology support system, the configuration file fes_dmsaccess.sys contains the system feature flag "nuspfile". The name of the collected data file generated by the master communication server in the secure access area is "up_report_nuspfile_nb-sf1_nb1-fes_20240307164659_852.DT". The "nuspfile" in the file name is the system feature identifier marking the new generation of dispatching technology support system, and "20240307164659_852" is the time information of file generation, indicating that the file was generated at 16:46:59.852 milliseconds on March 7, 2024. The storage path of the file copy is / home / nusp / ningbo / var / saa_edata / fx_send_file_bak. The content of the collected data file is as follows:
[0045] <up_report>
[0046] @Channel number Channel message
[0047] #168568121E0002000D0103000100660000BC74BF4000
[0048] < / up_report>
[0049] <Upstream message>
[0050] @Number of channels Synchronization time
[0051] #120240307164659_852
[0052] < / upstream message>
[0053] Open the configuration software of the reverse isolation device. The source path of the configuration file transmission is the directory / home / nusp / ningbo / var / saa_edata / fx_send_file_bak of the communication server in the secure access area of the source system, and the destination path is the directory / home / d5000 / ningbo / var / saa_edata / inter_imp / isolate_recv in the front-end server of the main station in the secure I area of the OPEN5200 distribution automation system. The file transmission scan period is 1 second. After the configuration is completed, start the file transmission function.
[0054] In addition, before step (4), there is also a step of adding configuration information to the configuration file of the secure access processing unit. The configuration information includes the system feature identifier of the source system, so that the secure access processing unit only reads the collected data files whose names contain the system feature identifier of the source system.
[0055] For example, in the OPEN 5200 distribution network automation system, add configuration information to the fes_dmsaccess.sys configuration file in the master front-end server of Security Zone I:
[0056] [source_systems_number]
[0057] number = 1
[0058] [source_systems_tag]
[0059] source1 = nuspfile
[0060] When reading data acquisition files sent by the communication server in the secure access zone of this system, the secure access processing unit only reads data acquisition files with the "nuspfile" characteristic, ignoring data acquisition files with other system identifiers. The secure access processing unit supports configuring system feature identifiers of multiple systems simultaneously.
[0061] (4) The security access processing unit of the main station front-end server of the target system security zone reads the data collection file, extracts the source system acquisition channel identifier from the data collection file, extracts the target system acquisition channel identifier associated with the source system acquisition channel identifier according to the acquisition channel association relationship, and stores the power terminal acquisition data in the data collection file into the data storage area corresponding to the target system acquisition channel identifier.
[0062] For example, when the secure access processing unit of the OPEN 5200 distribution network automation system reads a data acquisition file with the "nuspfile" characteristic, the source system data acquisition channel number is 1685, and the power terminal acquisition data is "68121E0002000D0103000100660000BC74BF4000". According to the acquisition channel association relationship, the source system acquisition channel number 1685 is associated with acquisition channel number 16196 in the target system, and the power terminal acquisition data is written to the original data storage sub-area of the data storage area corresponding to channel 16196.
[0063] (5) The data processing unit of the main station front-end server in the target system security zone parses the data in the data storage area and saves the parsed data to the data storage area.
[0064] The target system reads the collected data from the data storage area in ascending order according to the acquisition channel identifiers in this system. The parsed data types include remote signaling and telemetry.
[0065] For example, in the OPEN 5200 distribution network automation system, the data processing unit of the master station front-end server in Safety Zone I reads data sequentially from the original data storage sub-area of the corresponding channel in ascending order of all channel numbers in the system. When processing the acquisition channel number 16196, it reads the acquisition data "68121E0002000D0103000100660000BC74BF4000" from the original data storage sub-area, parses the message according to the IEC 104 standard, the acquisition data type is telemetry, the point number is 2, and the measured value is 5.983. The acquisition data and the parsed response data are then written into the parsed data storage sub-area of the data storage area of channel 16196.
[0066] (6) The visualization software of the main station front-end server in the target system security zone reads and parses data from the data storage area according to the acquisition channel selected by the user and then visualizes it.
[0067] The visualization software can only view the parsed data from one acquisition channel at a time, with a query cycle of 300 milliseconds, and displays the data in descending order of acquisition time.
[0068] For example, when a user launches the visualization software fes_display and double-clicks the channel named "Jiananda Photovoltaic Distributed Power - Unnamed Channel" in the channel list, the visualization software reads data from the parsed data storage area of channel number 16196 and displays it in the display area. The displayed parsed data content is as follows:
[0069] Receive (Telemetry): 68121E000200 0D <Data type: short floating-point number> 01 <Number of data: 1> 03000100 <Transmission reason: Active upload> 660000BC74BF4000 <2:5.983>
[0070] When the OPEN 5200 distribution network automation system receives a new data acquisition file, the latest parsed data is displayed below the previous parsed data for the selected channel in the visualization software after processing.
[0071] Example 2
[0072] This invention also provides a cross-power automation system data acquisition system based on a secure access zone, such as... Figure 2 As shown, it includes the source system end and the target system end, wherein:
[0073] The source system includes:
[0074] The data acquisition module is used to collect power terminal measurement data based on the secure access zone, and form power terminal acquisition data.
[0075] The main station communication server, deployed in the secure access zone, is used to acquire real-time generated power terminal data and form a data acquisition file together with the source system acquisition channel identifier.
[0076] The reverse isolation device, deployed in the secure access zone, is used to send a copy of the collected data file to the main station front-end server in the target system's secure zone;
[0077] The target system includes:
[0078] The secure access processing unit is used to read the collected data file, extract the source system acquisition channel identifier from the collected data file, extract the target system acquisition channel identifier associated with the source system acquisition channel identifier according to the acquisition channel association relationship, and store the power terminal collected data in the collected data file into the data storage area corresponding to the target system acquisition channel identifier.
[0079] The data processing unit is used to parse the data in the data storage area and save the parsed data back to the data storage area;
[0080] Visualization software is used to read and parse data from the data storage area and visualize it according to the acquisition channel selected by the user.
[0081] The system provided in this embodiment of the invention can be used to execute the method provided in Embodiment 1 of the invention, and has the corresponding functions and beneficial effects of executing the method.
[0082] It is worth noting that in the embodiments of the above system, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy distinction between each other and are not used to limit the scope of protection of the present invention.
[0083] The embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art will clearly understand that each implementation can be achieved using software plus necessary general-purpose hardware platforms, or it can be implemented solely through hardware, as long as the function or purpose can be achieved.
[0084] It should be understood that the embodiments and descriptions above are only the principles, main features and advantages of the present invention. Various changes and modifications can be made to the present invention without departing from the spirit and scope of the invention, and all such changes and modifications fall within the protection scope of the present invention.
Claims
1. A secure access zone based cross power automation system data collection method, comprising: The method comprises the following steps: (1) The target system and the source system create collection channels respectively, and associate the collection channel of the target system with the collection channel of the source system to form a collection channel association relationship; (2) The target system allocates a corresponding data storage area for the collection channel; (3) The source system safely accesses the main station communication server of the area to obtain the real-time generated power terminal collection data, and forms a collection data file together with the source system collection channel identifier, and sends a copy of the collection data file to the main station front-end server of the target system safe area through the reverse isolation device deployed in the safe access area; (4) The safe access processing unit of the main station front-end server of the target system safe area reads the collection data file, extracts the source system collection channel identifier from the collection data file, and extracts the target system collection channel identifier associated with the source system collection channel identifier according to the collection channel association relationship, and stores the power terminal collection data in the collection data file to the data storage area corresponding to the target system collection channel identifier; (5) The data processing unit of the main station front-end server of the target system safe area parses the data in the data storage area, and saves the parsed data to the data storage area; (6) The visualization software of the main station front-end server of the target system safe area reads the parsed data from the data storage area according to the collection channel selected by the user for visualization.
2. The method of claim 1, wherein the method is based on a secure access zone. In step (1), the collection channel information created includes: collection channel number, collection channel name, communication protocol type, collection channel number of other systems associated, and the collection channel number is the collection channel identifier.
3. The method of claim 2, wherein the method is based on a secure access zone. The collection channel number of the source system is unique in the source system, the collection channel number of the target system is unique in the target system, and the collection channel of the source system can only be associated with one collection channel in the target system.
4. The secure access zone based cross power automation system data collection method of claim 1, wherein, In step (2), the data storage area is realized by shared memory, including a raw data storage sub-area of the collection data file and a parsed data storage sub-area.
5. The method of claim 1, wherein the method is based on a secure access zone. In step (3), the name of the collection data file generated in the source system contains the system feature identifier of the source system, and the system feature identifier is extracted from the source system configuration file.
6. The secure access zone based cross power automation system data collection method of claim 1, wherein, The reverse isolation device is provided with a target path of the collection data file, and the target path is specified by the target system.
7. The secure access zone based cross power automation system data collection method of claim 5, wherein, Before step (4), it further includes: Add configuration information to the configuration file of the safe access processing unit, which includes the system feature identifier of the source system, so that the safe access processing unit only reads the collection data file whose name contains the system feature identifier of the source system.
8. The secure access zone based cross power automation system data collection method of claim 1, wherein, In step (5), the target system reads the collection data from the data storage area in ascending order of the collection channel identifier in the system, and the parsed data type includes remote signaling and remote measurement.
9. The secure access zone based cross power automation system data collection method of claim 1, wherein, In step (6), the visualization software can only view the parsed data of one collection channel at the same time, and displays in descending order according to the data collection time.
10. A secure access zone based cross power automation system data acquisition system, comprising: The method comprises a source system end and a target system end, wherein: The source system end comprises: A collection module for collecting power terminal measurement data based on a safe access area to form power terminal collection data; The main station communication server is arranged in the secure access area, and is configured to acquire the real-time generated power terminal collection data, and form a collection data file together with the source system collection channel identifier; The reverse isolation device is arranged in the secure access area, and is configured to send a copy of the collection data file to the main station front-end server in the target system secure area; The target system comprises: The secure access processing unit is configured to read the collection data file, extract the source system collection channel identifier from the collection data file, extract the target system collection channel identifier associated with the source system collection channel identifier according to the collection channel association relationship, and store the power terminal collection data in the collection data file to the data storage area corresponding to the target system collection channel identifier; The data processing unit is configured to parse the data in the data storage area, and save the parsed data to the data storage area; The visualization software is configured to read the parsed data from the data storage area according to the collection channel selected by a user, and perform visualization.
Citation Information
Patent Citations
Intelligent telecontrol communication machine based remote data subscribing and releasing method
CN103546541A
Power distribution automation data acquisition device and method based on safe access area
CN107947357A
Cross-security-zone wireless data access system and method
CN108053630A
Resource data cross-isolation acquisition method and resource data cross-isolation acquisition system of power communication network
CN108337245A
Scheduling automation data acquisition method and system based on secure access area
CN115776175A