Power transmission line monitoring data security protection method and device based on encrypted transmission

By verifying digital certificates and generating dynamic session keys for the security proxy gateway, combined with transport layer security protocols, the security and efficiency issues in data transmission for power transmission line monitoring are resolved, achieving full-process security hardening and efficient transmission.

CN122372214APending Publication Date: 2026-07-10FUJIAN SHENGYAO TECHNOLOGY GROUP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FUJIAN SHENGYAO TECHNOLOGY GROUP CO LTD
Filing Date
2026-04-16
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing technologies lack a full-process digital certificate verification and key generation mechanism in transmission line monitoring data transmission, resulting in insufficient data encryption security, low transmission efficiency, and a lack of comprehensive security audit log generation.

Method used

By performing certificate chain verification on the digital certificate of the security proxy gateway, a dynamic session key is generated. Combined with the transport layer security protocol handshake, a two-way encrypted communication tunnel is established to perform data encryption and signature verification, and a dedicated transmission policy is configured to ensure the security and integrity of the data.

Benefits of technology

It has achieved full-process security reinforcement of transmission line monitoring data, improved data confidentiality and integrity, ensured the efficiency and traceability of data transmission, and generated a complete security audit log.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372214A_ABST
    Figure CN122372214A_ABST
Patent Text Reader

Abstract

This invention relates to the field of data encryption technology and proposes a method and device for secure protection of transmission line monitoring data based on encrypted transmission. The method includes: performing certificate chain verification on the digital certificate of the security proxy gateway and performing a transport layer security protocol handshake to obtain a bidirectional encrypted communication tunnel; performing key derivation on the session key factor and device key of the security proxy gateway to obtain a dynamic session key; performing symmetric encryption on the data payload and digitally signing the obtained encrypted data block to obtain a secure data message; delivering the secure data message to the security proxy gateway through the bidirectional encrypted communication tunnel to obtain the message reception status; performing symmetric decryption on the encrypted data block and performing digital signature verification to obtain the data payload to be verified and the signature validity verification result; and performing protocol adaptation encapsulation on the data payload to be verified to obtain a security audit log. This invention can improve the efficiency of security protection for transmission line monitoring data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption technology, and in particular to a method and device for protecting the security of transmission line monitoring data based on encrypted transmission. Background Technology

[0002] In the security protection of transmission line monitoring data transmission, existing technologies lack a full-process compliance verification mechanism for digital certificates when establishing a communication connection between the monitoring terminal and the security proxy gateway. They fail to perform complete certificate chain tracing and certificate revocation list queries, making it impossible to accurately confirm the integrity and compliance of the certificates. Relying solely on simple certificate validity verification to complete the communication handshake is insufficient to mitigate the security risks of unauthorized gateway access at the source. Furthermore, during the transport layer security protocol handshake process, strict consistency verification between the client key exchange parameters and the preset master key is not performed. The collaborative confirmation process for encryption suite selection and session ticket generation is missing, making it impossible to stably construct a communication tunnel with bidirectional encryption capabilities. This results in significant vulnerabilities in the underlying link security protection of data transmission.

[0003] Existing technologies for encryption protection and transmission management of transmission line monitoring data have many shortcomings. Key generation does not combine the session key factor of the security proxy gateway with the device key of the monitoring terminal for targeted key derivation. It only uses a fixed key to encrypt the data, which cannot generate dynamic session keys that are compatible with different monitoring terminals. This makes the data encryption security insufficient and vulnerable to data cracking. At the same time, the data transmission stage does not match the corresponding transmission strategy according to the link status and message characteristics. The sliding window capacity and congestion control of fragmented transmission lack dynamic adjustment mechanisms. The selective retransmission strategy for fragmented transmission is missing, which can easily lead to message loss or low transmission efficiency. Furthermore, the decryption, signature verification and protocol adaptation encapsulation stages after data reception are poorly connected. The verification process lacks standardized design and cannot effectively generate complete security audit logs. As a result, the overall efficiency of monitoring data security protection is low, making it difficult to achieve comprehensive security protection for monitoring data. Summary of the Invention

[0004] This invention provides a method and apparatus for secure protection of transmission line monitoring data based on encrypted transmission, in order to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides a method for secure protection of transmission line monitoring data based on encrypted transmission, comprising: Pt.1. Based on the connection request sent by the monitoring terminal to the security proxy gateway, the digital certificate of the security proxy gateway is verified by certificate chain verification, and a transport layer security protocol handshake is performed with the monitoring terminal based on the certificate validity confirmation result to obtain the bidirectional encrypted communication tunnel of the monitoring terminal. Pt.2. Perform key derivation on the session key factor of the security proxy gateway and the device key of the monitoring terminal to obtain the dynamic session key of the monitoring terminal; Pt.3. Based on the dynamic session key, the data payload of the monitoring terminal is symmetrically encrypted, and based on the device private key of the monitoring terminal, the obtained encrypted data block is digitally signed to obtain the secure data message of the monitoring terminal. Pt.4. Based on the monitoring terminal, the security data message is delivered to the security proxy gateway through the bidirectional encrypted communication tunnel to obtain the message reception status of the monitoring terminal; Pt.5. Based on the dynamic session key, the encrypted data block is symmetrically decrypted, and the signature data of the secure data message is digitally verified to obtain the data payload to be verified and the signature validity verification result of the monitoring terminal. Pt.6. Using the signature validity verification result as the pass condition, the payload of the data to be verified is protocol adapted and encapsulated to obtain the security audit log of the monitoring terminal.

[0006] In a preferred embodiment, the step of performing certificate chain verification on the digital certificate of the security proxy gateway based on the connection request sent by the monitoring terminal to the security proxy gateway, and performing a transport layer security protocol handshake with the monitoring terminal based on the certificate validity confirmation result to obtain a bidirectional encrypted communication tunnel for the monitoring terminal includes: Based on the connection request sent by the monitoring terminal to the security proxy gateway, the digital certificate of the security proxy gateway is traced back to obtain the certificate chain integrity authentication identifier of the monitoring terminal. Using the certificate chain integrity authentication identifier as the compliance pass status, the digital certificate is queried from the certificate revocation list to obtain the certificate compliance authentication credential of the monitoring terminal; With the certificate compliance authentication credential as the compliance status, a transport layer security protocol handshake negotiation request is initiated to the monitoring terminal, and the client key exchange parameters returned by the monitoring terminal are received. The consistency of the client key exchange parameters with the preset master key is verified to obtain the matching confirmation credential of the monitoring terminal. Based on the matching confirmation credential, the selection of encryption suites and the generation of session tickets between the monitoring terminal and the security proxy gateway are collaboratively confirmed to obtain a two-way encrypted communication tunnel for the monitoring terminal.

[0007] In a preferred embodiment, the step of derivation of the session key factor of the security proxy gateway and the device key of the monitoring terminal to obtain the dynamic session key of the monitoring terminal includes: The random entropy source of the security proxy gateway is encapsulated with a session key factor to obtain the initial parameters for key derivation of the monitoring terminal. The initial parameters for key derivation are concatenated with the device private key of the monitoring terminal to obtain the dynamic session key on the monitoring terminal side of the monitoring terminal; Based on the key derivation initial parameters, the device public key of the monitoring terminal is entropy-mixed to obtain the gateway-side dynamic session key of the monitoring terminal; The dynamic session key of the monitoring terminal is obtained by comparing the dynamic session key on the monitoring terminal side with the dynamic session key on the gateway side using a key fingerprint.

[0008] In a preferred embodiment, the step of symmetrically encrypting the data payload of the monitoring terminal based on the dynamic session key, and digitally signing the obtained encrypted data block based on the device private key of the monitoring terminal to obtain the secure data message of the monitoring terminal includes: Protocol data is constructed from the original transmission line monitoring data of the monitoring terminal, and field information is embedded into the generated data payload to obtain the encrypted message carrier of the monitoring terminal. Based on the dynamic session key, the message carrier to be encrypted is symmetrically encrypted to obtain the data carrier to be signed by the monitoring terminal. Based on the device private key of the monitoring terminal, a digital signature is bound to the data carrier to be signed, a digital signature value is generated, and the integrity verification credential of the monitoring terminal is obtained. The encrypted data block and the integrity verification credential are aggregated to obtain the security data message of the monitoring terminal.

[0009] In a preferred embodiment, the step of delivering the security data packet to the security proxy gateway through the bidirectional encrypted communication tunnel based on the monitoring terminal, and obtaining the packet reception status of the monitoring terminal, includes: The security data packets are marked with transmission priority to obtain the packet queuing ready status of the monitoring terminal; Based on the message queuing ready state, the transmission strategy of the security data message is matched through the bidirectional encrypted communication tunnel to obtain the transmission strategy configuration parameters of the monitoring terminal. Based on the transmission strategy configuration parameters, the security data packet is segmented to obtain the segmentation transmission progress record of the monitoring terminal; For the fragment delivery feedback set of the fragment transmission progress record, selective retransmission is performed on the missing transmission fragments of the security data message to obtain the full message delivery certificate of the monitoring terminal. Based on the full message delivery credential, the security data message is marked with a transmission status, a message reception status record is generated, and the message reception status record is used as the message reception status of the monitoring terminal.

[0010] In a preferred embodiment, the step of performing transmission policy matching on the secure data packets through the bidirectional encrypted communication tunnel based on the packet queuing ready state to obtain the transmission policy configuration parameters of the monitoring terminal includes: Based on the message queuing ready state, probe frame interaction is performed on the link status of the bidirectional encrypted communication tunnel to obtain the link quality characteristic parameter set of the monitoring terminal; Based on the link quality feature parameter set, the transmission strategy features of the preset transmission strategy feature library are compared to obtain the baseline transmission strategy parameter set of the monitoring terminal. The security data message payload length is measured, and based on the obtained total payload bytes and the initial sliding window capacity in the reference transmission strategy parameter set, the security data message is segmented and assembled to obtain the fragmentation scheme of the monitoring terminal. The total number of fragment sequences in the fragmentation scheme is compared with the slow start threshold in the baseline transmission strategy parameter set to obtain the transmission strategy configuration parameters of the monitoring terminal.

[0011] In a preferred embodiment, the calculation formulas for the transmission policy adjustment factor and the corrected sliding window capacity in the transmission policy configuration parameters are as follows: , ; In the formula, This is the adjustment factor for the transmission strategy. The initial sliding window capacity, The bit error rate is the value in the set of link quality characteristic parameters. The transmission round-trip delay is the value in the set of link quality characteristic parameters. The total number of the fragmented sequences, The corrected sliding window capacity is... The total number of bytes in the payload. This is the preset maximum segment length in bytes.

[0012] In a preferred embodiment, the step of symmetrically decrypting the encrypted data block based on the dynamic session key and digitally verifying the signature data of the secure data packet to obtain the verification results of the data payload and signature validity of the monitoring terminal includes: The security data message is parsed to obtain the message parsing information set of the monitoring terminal; Based on the dynamic session key version number of the message parsing information set, the dynamic session key in the preset local repository is matched and located to obtain the decryption key material of the monitoring terminal. Based on the decryption key material, the encrypted data blocks in the security data message are processed to obtain the data payload to be verified of the monitoring terminal. Based on the message parsing information set, the local repository is traversed and searched to obtain the signature verification key material of the monitoring terminal; Based on the signature verification key material, the binding relationship of the signature data of the secure data message is verified to obtain the signature validity verification result of the monitoring terminal.

[0013] In a preferred embodiment, the step of using the signature validity verification result as a pass condition to perform protocol adaptation encapsulation on the payload of the data to be verified to obtain the security audit log of the monitoring terminal includes: When the signature validity verification result is passed, the adaptation encapsulation start signal of the monitoring terminal is obtained; Based on the adaptive encapsulation start signal, the type of the payload to be verified is identified to obtain the payload attribute parsing result of the monitoring terminal; Based on the monitoring data type identifier in the net load attribute parsing result, a protocol matching search is performed on the preset master station system communication protocol library to obtain the protocol adaptation template of the monitoring terminal. The data structure of the payload to be verified is mapped to a data frame of the target protocol format in the protocol adaptation template to obtain the adapted data message of the monitoring terminal. The adapted data packets are encapsulated with audit records to obtain the security audit log of the monitoring terminal.

[0014] To address the above problems, the present invention also provides a data security protection device for transmission line monitoring based on encrypted transmission, the device comprising: The verification tunneling module is used to verify the digital certificate chain of the security proxy gateway based on the connection request sent by the monitoring terminal to the security proxy gateway, and to perform a transport layer security protocol handshake with the monitoring terminal based on the certificate validity confirmation result, so as to obtain a two-way encrypted communication tunnel for the monitoring terminal. The key derivation module is used to derive the dynamic session key of the monitoring terminal from the session key factor of the security proxy gateway and the device key of the monitoring terminal. The encryption and signing module is used to perform symmetric encryption on the data payload of the monitoring terminal based on the dynamic session key, and to digitally sign the obtained encrypted data block based on the device private key of the monitoring terminal to obtain the secure data message of the monitoring terminal. The tunneling message module is used to deliver the security data message to the security proxy gateway through the two-way encrypted communication tunnel based on the monitoring terminal, and to obtain the message reception status of the monitoring terminal. The signature verification module is used to perform symmetric decryption of the encrypted data block based on the dynamic session key, and to perform digital signature verification on the signature data of the secure data message, so as to obtain the data payload to be verified and the signature validity verification result of the monitoring terminal. The audit encapsulation module is used to perform protocol adaptation encapsulation on the payload of the data to be verified, based on the signature validity verification result as the pass condition, to obtain the security audit log of the monitoring terminal.

[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention performs complete certificate chain verification and compliance checks on the digital certificate of the security proxy gateway, constructs a stable bidirectional encrypted communication tunnel by combining a standardized transport layer security protocol handshake process, and generates dynamic session keys by using the session key factor of the security proxy gateway and the key of the monitoring terminal device for targeted key derivation. Secure data packets are generated by using dynamic session key symmetric encryption combined with device private key digital signature. A full-process security protection system is formed from communication link establishment, key generation to data packet encryption and sealing, which strengthens the security reinforcement effect of transmission line monitoring data before transmission, greatly improves the confidentiality and integrity of monitoring data, and makes the security protection of data transmission targeted and adaptable.

[0016] 2. This invention configures a dedicated transmission strategy for secure data packets, matches appropriate transmission parameters through link state detection and completes reasonable fragmentation processing, and ensures full and efficient delivery of packets with a selective retransmission mechanism. Simultaneously, it relies on standardized processes to decrypt encrypted data blocks and verify the validity of digital signatures. Based on the monitoring data type, it achieves precise protocol adaptation and encapsulation and generates complete security audit logs. This enables standardized and refined management of the entire process of transmission line monitoring data from transmission delivery to parsing and processing, effectively improving the efficiency of data transmission and the accuracy of data parsing and verification. It ensures that the entire process of monitoring data security protection is auditable and traceable, thereby improving the overall execution efficiency and effectiveness of transmission line monitoring data security protection. Attached Figure Description

[0017] Figure 1 This is a flowchart illustrating a method for protecting the security of transmission line monitoring data based on encrypted transmission, according to an embodiment of the present invention. Figure 2 A functional block diagram of a power transmission line monitoring data security protection device based on encrypted transmission provided in an embodiment of the present invention; The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0018] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0019] This application provides a method for secure protection of transmission line monitoring data based on encrypted transmission. The executing entity of this method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. In other words, the method for secure protection of transmission line monitoring data based on encrypted transmission can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.

[0020] Reference Figure 1 The diagram shown is a flowchart illustrating a method for protecting transmission line monitoring data security based on encrypted transmission, according to an embodiment of the present invention. In this embodiment, the method for protecting transmission line monitoring data security based on encrypted transmission includes: Pt.1. Based on the connection request sent by the monitoring terminal to the security proxy gateway, the digital certificate of the security proxy gateway is verified by certificate chain verification, and a transport layer security protocol handshake is performed with the monitoring terminal based on the certificate validity confirmation result to obtain the bidirectional encrypted communication tunnel of the monitoring terminal. In this embodiment of the invention, the step of performing certificate chain verification on the digital certificate of the security proxy gateway based on the connection request sent by the monitoring terminal to the security proxy gateway, and performing a transport layer security protocol handshake with the monitoring terminal based on the certificate validity confirmation result to obtain a bidirectional encrypted communication tunnel for the monitoring terminal includes: Based on the connection request sent by the monitoring terminal to the security proxy gateway, the digital certificate of the security proxy gateway is traced back to obtain the certificate chain integrity authentication identifier of the monitoring terminal. Using the certificate chain integrity authentication identifier as the compliance pass status, the digital certificate is queried from the certificate revocation list to obtain the certificate compliance authentication credential of the monitoring terminal; With the certificate compliance authentication credential as the compliance status, a transport layer security protocol handshake negotiation request is initiated to the monitoring terminal, and the client key exchange parameters returned by the monitoring terminal are received. The consistency of the client key exchange parameters with the preset master key is verified to obtain the matching confirmation credential of the monitoring terminal. Based on the matching confirmation credential, the selection of encryption suites and the generation of session tickets between the monitoring terminal and the security proxy gateway are collaboratively confirmed to obtain a two-way encrypted communication tunnel for the monitoring terminal.

[0021] After the monitoring terminal sends a connection request to the security proxy gateway, the security proxy gateway extracts the hierarchical association information of its own digital certificate. Starting from the digital certificate, it traces upwards level by level to the root certificate, and checks the consistency and continuity of the signature association, certificate validity period, certificate authority identifier, and other fields of each level of certificate. It confirms that there are no broken nodes, information tampering, or missing content in the certificate chain. When all the checked fields of all nodes in the certificate chain meet the preset certificate chain verification standard, a certificate chain integrity authentication mark indicating compliance is generated. When any checked field of any node in the certificate chain does not meet the preset certificate chain verification standard, a certificate chain integrity authentication mark indicating non-compliance is generated.

[0022] When the certificate chain integrity authentication status is "compliant," the security proxy gateway retrieves the certificate revocation list database maintained by a pre-defined authoritative certificate authority. It extracts the unique identification information of the security proxy gateway's digital certificate, such as the serial number and public key hash value. This unique identification information is then precisely matched and verified field by field against the information in the certificate revocation list of the currently valid version in the certificate revocation list database. If the unique identification information of the digital certificate does not appear in the certificate revocation list, a certificate compliance authentication credential indicating compliance is generated. If the unique identification information of the digital certificate appears in the certificate revocation list, a certificate compliance authentication credential indicating non-compliance is generated.

[0023] When the certificate compliance authentication credential is in a compliant state, the security proxy gateway sends a transport layer security protocol handshake negotiation request to the monitoring terminal, which includes the transport layer security protocol version number and the basic identifier of the encryption algorithm. After receiving the request and completing local protocol adaptation, the monitoring terminal returns client key exchange parameters to the security proxy gateway, which include key exchange algorithm parameters and random number information. The security proxy gateway retrieves the locally pre-stored master key and performs a full field-by-field comparison and verification between the key-related information in the client key exchange parameters and the corresponding information in the master key. When all fields of information completely match, a matching confirmation credential indicating a match is generated. When any field of information does not match, a matching confirmation credential indicating a mismatch is generated.

[0024] Based on the matching confirmation credentials, the security proxy gateway and the monitoring terminal each retrieve their own pre-stored encryption suite support lists, filter out encryption suites that are common to both lists and meet the preset transmission security level requirements, and complete the encryption suite selection operation. Subsequently, based on the selected encryption suite, both parties generate a unique and valid session ticket containing the identity identifiers of both communicating parties, encryption suite information, and a valid session timestamp according to the established specifications of the transport layer security protocol. After the security proxy gateway and the monitoring terminal complete the interactive transmission and local verification of the session ticket, they establish a bidirectional encrypted communication tunnel that is only compatible with the monitoring terminal and the security proxy gateway, relying on the selected encryption suite and the valid session ticket. This tunnel enables bidirectional encrypted data transmission and reception between the monitoring terminal and the security proxy gateway.

[0025] Pt.2. Perform key derivation on the session key factor of the security proxy gateway and the device key of the monitoring terminal to obtain the dynamic session key of the monitoring terminal; In this embodiment of the invention, the step of derivation of the session key factor of the security proxy gateway and the device key of the monitoring terminal to obtain the dynamic session key of the monitoring terminal includes: The random entropy source of the security proxy gateway is encapsulated with a session key factor to obtain the initial parameters for key derivation of the monitoring terminal. The initial parameters for key derivation are concatenated with the device private key of the monitoring terminal to obtain the dynamic session key on the monitoring terminal side of the monitoring terminal; Based on the key derivation initial parameters, the device public key of the monitoring terminal is entropy-mixed to obtain the gateway-side dynamic session key of the monitoring terminal; The dynamic session key of the monitoring terminal is obtained by comparing the dynamic session key on the monitoring terminal side with the dynamic session key on the gateway side using a key fingerprint.

[0026] The security proxy gateway extracts the raw entropy data generated by its built-in random entropy source, extracts the generation timestamp of the entropy data and the gateway's unique hardware identifier, and sequentially integrates and encapsulates the raw entropy data, generation timestamp, and gateway's unique hardware identifier in a structured manner according to the preset key factor encapsulation format. After encapsulation, the integrated data is checked for field integrity. When all preset fields of the encapsulated data are complete and the format meets the preset encapsulation verification standard, the encapsulated structured data is determined as the initial parameters for key derivation of the monitoring terminal.

[0027] Extract the complete byte stream of the key derivation initial parameters of the monitoring terminal and the complete byte stream of the device private key of the monitoring terminal. According to the preset key material concatenation rules, the byte stream of the key derivation initial parameters is used as the first part and the byte stream of the device private key is used as the last part for continuous concatenation to obtain the concatenated complete byte data. The concatenated byte data is then processed to a fixed length, which is uniformly adjusted to the preset 256-bit key standard length. Zero padding is used to supplement any part that is less than 256 bits, and truncation is used to remove any part that exceeds 256 bits. The resulting 256-bit fixed-length data is the monitoring terminal-side dynamic session key of the monitoring terminal.

[0028] The core entropy data is extracted from the initial parameters of the key derivation of the monitoring terminal. The complete byte stream of the device public key of the monitoring terminal is extracted. The core entropy data and the device public key byte stream are XORed bit by bit in the same bit order to obtain intermediate data after XOR processing. The intermediate data is then subjected to a preset one-way hash processing. The processing result is uniformly converted into a preset 256-bit key standard length. The 256-bit fixed-length data obtained after processing is the dynamic session key on the gateway side of the monitoring terminal.

[0029] Pre-defined key fingerprint extraction processes are performed on the dynamic session keys on the monitoring terminal side and the gateway side respectively. The extracted key fingerprint is a fixed 128-bit hexadecimal character sequence. The fingerprints of the dynamic session keys on the monitoring terminal side and the gateway side are compared character by character in order. When all 128 characters of the two fingerprints completely overlap, the dynamic session key corresponding to the fingerprint is determined as the dynamic session key of the monitoring terminal. When any character of the two fingerprints does not overlap, the entire key derivation process is repeated until the fingerprints of the dynamic session keys on both sides completely overlap.

[0030] Pt.3. Based on the dynamic session key, the data payload of the monitoring terminal is symmetrically encrypted, and based on the device private key of the monitoring terminal, the obtained encrypted data block is digitally signed to obtain the secure data message of the monitoring terminal. In this embodiment of the invention, the step of symmetrically encrypting the data payload of the monitoring terminal based on the dynamic session key, and digitally signing the obtained encrypted data block based on the device private key of the monitoring terminal to obtain the secure data message of the monitoring terminal includes: Protocol data is constructed from the original transmission line monitoring data of the monitoring terminal, and field information is embedded into the generated data payload to obtain the encrypted message carrier of the monitoring terminal. Based on the dynamic session key, the message carrier to be encrypted is symmetrically encrypted to obtain the data carrier to be signed by the monitoring terminal. Based on the device private key of the monitoring terminal, a digital signature is bound to the data carrier to be signed, a digital signature value is generated, and the integrity verification credential of the monitoring terminal is obtained. The encrypted data block and the integrity verification credential are aggregated to obtain the security data message of the monitoring terminal.

[0031] The raw transmission line monitoring data collected by the monitoring terminal is extracted. This data includes core information such as transmission line operating status parameters, data acquisition time, and terminal acquisition identifier. The raw data is structured and framed according to the preset transmission line monitoring data protocol format to form a standardized data payload. Then, fixed field information such as the monitoring terminal's unique device identifier, the data frame's unique sequence number, and the data integrity check code are embedded into the preset extended fields of the data payload. After embedding, the format and length of all fields in the data payload are checked. When the format of all fields conforms to the preset protocol standard and the field length matches the preset threshold, the processed data payload is determined as the carrier of the encrypted message of the monitoring terminal.

[0032] The dynamic session key of the generated monitoring terminal is extracted as the core key for symmetric encryption. The data carrier of the monitoring terminal to be encrypted is divided into blocks according to a preset fixed length of 128 bits. For the last block of data to be encrypted that is less than 128 bits, it is padded according to the preset PKCS7 padding rule so that all data blocks reach the standard length of 128 bits. Then, the dynamic session key is used to perform symmetric encryption on each standard length data block in turn. After encryption, all encrypted data blocks are continuously spliced ​​together according to the original block order. The complete encrypted data is the data carrier to be signed of the monitoring terminal. This data carrier to be signed is also the encrypted data block formed by encrypting the corresponding data payload.

[0033] The data carrier to be signed undergoes a pre-defined one-way hashing process, converting it into a unique hash value of fixed length 256 bits. This hash value forms a unique correspondence with the content of the data carrier to be signed. Then, the device private key of the monitoring terminal is extracted, and the 256-bit hash value is asymmetrically encrypted using this device private key. The resulting encryption result is the digital signature value. This digital signature value is then bound one-to-one with the frame sequence number and device identifier of the data carrier to be signed, forming structured verification data containing the digital signature value and associated identifiers. This structured verification data serves as the integrity verification credential of the monitoring terminal.

[0034] According to the preset secure data message frame structure specification, the encrypted data block is deployed in the main payload field area of ​​the message, and the integrity verification credential is deployed in the additional verification field area of ​​the message. At the same time, preset basic information such as message version number, message generation timestamp, main payload data length, and verification field length are embedded in the header field of the message. After the deployment and embedding of each field are completed, the frame structure, field position, and data length of the entire message are fully verified. When all structural features of the message conform to the preset secure data message format standard, the message that has completed structured encapsulation is identified as the secure data message of the monitoring terminal.

[0035] Pt.4. Based on the monitoring terminal, the security data message is delivered to the security proxy gateway through the bidirectional encrypted communication tunnel to obtain the message reception status of the monitoring terminal; In this embodiment of the invention, the step of delivering the security data packet to the security proxy gateway through the bidirectional encrypted communication tunnel based on the monitoring terminal, and obtaining the packet reception status of the monitoring terminal, includes: The security data packets are marked with transmission priority to obtain the packet queuing ready status of the monitoring terminal; Based on the message queuing ready state, the transmission strategy of the security data message is matched through the bidirectional encrypted communication tunnel to obtain the transmission strategy configuration parameters of the monitoring terminal. Based on the transmission strategy configuration parameters, the security data packet is segmented to obtain the segmentation transmission progress record of the monitoring terminal; For the fragment delivery feedback set of the fragment transmission progress record, selective retransmission is performed on the missing transmission fragments of the security data message to obtain the full message delivery certificate of the monitoring terminal. Based on the full message delivery credential, the security data message is marked with a transmission status, a message reception status record is generated, and the message reception status record is used as the message reception status of the monitoring terminal.

[0036] Based on the message queuing readiness state, the transmission strategy matching of the secure data message through the bidirectional encrypted communication tunnel is performed to obtain the transmission strategy configuration parameters of the monitoring terminal, including: Based on the message queuing ready state, probe frame interaction is performed on the link status of the bidirectional encrypted communication tunnel to obtain the link quality characteristic parameter set of the monitoring terminal; Based on the link quality feature parameter set, the transmission strategy features of the preset transmission strategy feature library are compared to obtain the baseline transmission strategy parameter set of the monitoring terminal. The security data message payload length is measured, and based on the obtained total payload bytes and the initial sliding window capacity in the reference transmission strategy parameter set, the security data message is segmented and assembled to obtain the fragmentation scheme of the monitoring terminal. The total number of fragment sequences in the fragmentation scheme is compared with the slow start threshold in the baseline transmission strategy parameter set to obtain the transmission strategy configuration parameters of the monitoring terminal.

[0037] The calculation formulas for the transmission strategy adjustment factor and the corrected sliding window capacity in the transmission strategy configuration parameters are as follows: , ; In the formula, This is the adjustment factor for the transmission strategy. The initial sliding window capacity, The bit error rate is the value in the set of link quality characteristic parameters. The transmission round-trip delay is the value in the set of link quality characteristic parameters. The total number of the fragmented sequences, The corrected sliding window capacity is... The total number of bytes in the payload. This is the preset maximum segment length in bytes.

[0038] The data type of transmission line monitoring carried in the safety data messages generated by the monitoring terminal is extracted. The transmission line monitoring data transmission priority is divided into two levels: the first level is transmission line fault monitoring data, and the second level is transmission line routine operation monitoring data. The corresponding transmission priority level identifier is matched according to the monitoring data type identifier in the message. The level identifier is embedded into the preset priority field in the header of the safety data message. After the embedding is completed, the format, bit length and content of the priority field are verified. When all the characteristics of the field meet the preset message marking standard, the safety data message is marked as being able to enter the transmission queuing sequence. This state is the message queuing ready state of the monitoring terminal.

[0039] When a security data packet is in the packet queuing ready state, the monitoring terminal continuously sends a preset fixed-length link probe frame to the security proxy gateway through a two-way encrypted communication tunnel, with a preset interval of 500 milliseconds. It receives the probe frame response data returned by the security proxy gateway, extracts link quality characteristic information such as link error rate, transmission round-trip time, and link bandwidth utilization from the response data, and retrieves the locally pre-stored transmission policy feature library. This feature library stores a one-to-one correspondence between link quality characteristic information and transmission policy parameters. The extracted link quality characteristic information is precisely matched with the information in the feature library to determine the corresponding transmission policy parameters. The parameters are then verified for compatibility with the actual link state of the current two-way encrypted communication tunnel. When the parameters fully match the actual link state, this set of transmission policy parameters is determined as the transmission policy configuration parameters for the monitoring terminal.

[0040] The core configuration information, such as the maximum fragment byte length and fragment sequence number encoding rules, is extracted from the transmission strategy configuration parameters of the monitoring terminal. The security data packets are continuously fragmented according to the maximum fragment byte length. For the last fragment that is shorter than the maximum fragment byte length, fixed-length padding is applied according to a preset packet padding rule to ensure all fragments conform to the preset byte length standard. A unique decimal sequence number is assigned to each fragment, and the sequence number increments sequentially from 1 according to the fragmentation order. Simultaneously, information such as the sequence number, data byte length, data starting offset address, and preset transmission time of each fragment is recorded. All fragment-related information is structured and organized according to the sequence number order to form a structured document containing all fragment transmission-related information. This document serves as the fragment transmission progress record for the monitoring terminal.

[0041] The monitoring terminal receives the fragment delivery feedback set returned by the security proxy gateway in real time. This feedback set is a list of successfully received packet fragment sequence numbers compiled by the security proxy gateway according to a preset format. The fragment sequence numbers in the feedback set are compared one by one with all fragment sequence numbers in the fragment transmission progress record. The packet fragments corresponding to the fragment sequence numbers that do not appear in the feedback set are filtered out and identified as missing transmission fragments. The missing transmission fragments are retransmitted sequentially according to the sequence number order in the fragment transmission progress record, with a preset retransmission interval of 300 milliseconds. After each missing fragment retransmission is completed, the fragment delivery feedback set of the security proxy gateway is received again and the sequence number is compared again until the feedback set contains all the fragment sequence numbers in the fragment transmission progress record. At this time, structured confirmation data containing the unique identifier of the security data packet, the delivery confirmation identifier of all fragments, the number of retransmissions of missing fragments, and the final delivery time of all fragments is generated. This data is the full packet delivery certificate of the monitoring terminal.

[0042] The core information, such as the delivery confirmation identifiers and unique identifiers of all fragments, is extracted from the full message delivery certificate of the monitoring terminal. According to the preset message transmission status division standard, when all fragments in the certificate have a delivery confirmation identifier, the transmission status of the security data message is marked as full delivery. Based on this marking result, combined with the retransmission count, final delivery time in the full message delivery certificate, and the gateway reception confirmation information returned by the security proxy gateway, the preset fields such as unique identifier of message, transmission status marking result, total number of fragments, retransmission count, final delivery time of all fragments, and gateway reception confirmation code are filled in sequentially according to the preset message reception status record format. After all fields are filled in, the completeness of the fields and the consistency of the information in the record are verified. When all preset fields of the record are filled in completely and the information is completely consistent with the full message delivery certificate, the structured record is determined as the message reception status record, and the message reception status record is used as the message reception status of the monitoring terminal.

[0043] When a security data packet is in the packet queuing ready state, the monitoring terminal continuously sends 10 fixed-length (64-byte) link probe frames to the security proxy gateway. The transmission interval of the probe frames is set to 500 milliseconds, and the probe frames only contain the basic identifiers and verification information required for link status detection. The monitoring terminal receives the probe frame response data returned by the security proxy gateway in real time. Probe frames that are not returned within the preset 1000-millisecond response time limit are marked as no response, and probe frames with incorrect response data verification are marked as error responses. The link bit error rate is calculated by the ratio of the number of probe frames with no response and error responses to the total number of probe frames sent. For each normal response probe frame, the error rate is calculated from the time it was sent to... The round-trip time is obtained by averaging the received time difference. The link bandwidth utilization is calculated by the ratio of the amount of data transmitted in the link during the probe frame interaction process to the theoretical maximum transmission capacity of the link. At the same time, the link packet loss rate is calculated. The calculated link bit error rate, round-trip time, link bandwidth utilization, and link packet loss rate are integrated into a structured parameter set. The value range of each parameter in the set is verified to ensure that the bit error rate is in the range of 0-1, the round-trip time is in the range of 0-1000 milliseconds, the link bandwidth utilization is in the range of 0-1, and the link packet loss rate is in the range of 0-1. When all parameters meet the value range requirements, the structured parameter set is determined as the link quality characteristic parameter set of the monitoring terminal.

[0044] The system retrieves a locally stored transmission strategy feature library. This library contains a one-to-one correspondence between link quality feature parameter ranges and baseline transmission strategy parameters. Each link quality feature parameter is divided into continuous and non-overlapping numerical ranges. The baseline transmission strategy parameters in the feature library include core transmission parameters such as initial sliding window capacity, slow start threshold, and maximum fragment byte length. The link error rate, round-trip time, link bandwidth utilization, and link packet loss rate in the link quality feature parameter set are precisely matched with the corresponding parameter ranges in the feature library. A unique parameter range combination that completely matches all parameters is found. A complete set of baseline transmission strategy parameters corresponding to this parameter range combination is extracted. The extracted baseline transmission strategy parameters are validated to ensure that the initial sliding window capacity and slow start threshold are positive integers, and the maximum fragment byte length is a fixed value that conforms to the communication standard. When all parameters pass the validity validation, this complete set of baseline transmission strategy parameters is determined as the baseline transmission strategy parameter set of the monitoring terminal.

[0045] Extract the main payload field carrying monitoring data from the security data message, and count the number of bytes in this field byte by byte. The result is the total number of bytes in the security data message payload. Record this value and perform a second verification to ensure that the statistics are error-free. Extract the initial sliding window capacity and maximum fragment byte length from the baseline transmission strategy parameter set. The initial sliding window capacity represents the maximum number of fragments that can be continuously transmitted in a single transmission, and the maximum fragment byte length represents the maximum byte limit of a single transmission fragment. Perform continuous segmentation of the main payload data corresponding to the total number of bytes in the payload according to the maximum fragment byte length. If the total number of bytes in the payload is divisible by the maximum fragment byte length, then the number of segments is determined. The quantity is the quotient of the total number of bytes in the payload and the maximum segment length. If it is not divisible, the number of segments is the integer part of the quotient plus 1. Each segment is assigned a unique decimal segment sequence number starting from 1 and incrementing sequentially. The sequence number, start byte position, end byte position, actual byte length, and whether it is the last segment are recorded for each segment. All the relevant information of the segments are organized in a structured manner according to the sequence number to form a complete segmentation planning document. The actual byte lengths of all segments in the document are summed and compared with the total number of bytes in the payload. When the two values ​​are completely consistent, the structured planning document is determined as the segmentation scheme of the monitoring terminal.

[0046] The total number of structured record fragment sequences is extracted from the fragmentation scheme of the monitoring terminal. This value represents the total number of fragments after the secure data packet is segmented. A preset slow-start threshold is extracted from the baseline transmission strategy parameter set. This threshold is the core judgment value for congestion window adjustment. The total number of fragment sequences is directly compared with the slow-start threshold. If the total number of fragment sequences is less than or equal to the slow-start threshold, the initial congestion window capacity in the baseline transmission strategy parameter set remains unchanged. If the total number of fragment sequences is greater than the slow-start threshold, the congestion window capacity is adjusted to a value equal to the total number of fragment sequences. After the congestion window capacity adjustment is completed, it is combined with the baseline... The initial sliding window capacity, maximum fragment byte length, slow start threshold, adjusted congestion window capacity, and total number of fragment sequences in the fragmentation scheme of the quasi-transmission strategy parameter set are used to perform an overall adaptability verification of the transmission parameters. This ensures that the numerical combination of each parameter can match the current link state of the bidirectional encrypted communication tunnel and the actual transmission requirements of secure data packets. When all parameters pass the overall adaptability verification, the structured parameter set including the adjusted congestion window capacity, initial sliding window capacity, maximum fragment byte length, slow start threshold, and total number of fragment sequences is determined as the transmission strategy configuration parameters of the monitoring terminal.

[0047] The initial sliding window capacity is directly extracted from the baseline transmission strategy parameter set. This parameter set is the effective transmission parameter set of the monitoring terminal obtained by comparing the transmission strategy features of the link quality feature parameter set and the preset transmission strategy feature library.

[0048] The bit error rate is directly extracted from the link quality feature parameter set, which is a set of link quality indicators of the monitoring terminal obtained after the detection frame interaction is completed on the link status of the bidirectional encrypted communication tunnel based on the message queuing ready state.

[0049] The transmission round-trip delay is directly extracted from the link quality feature parameter set, and the method of obtaining this parameter set is completely consistent with the method of obtaining the link quality feature parameter set from which the bit error rate comes.

[0050] The total number of fragmented sequences is directly extracted from the fragmentation scheme. This scheme is a fragmentation planning scheme for monitoring terminals obtained by combining the total number of bytes of the payload with the initial sliding window capacity in the baseline transmission strategy parameter set after determining the length of the security data message payload.

[0051] The result of this calculation is the transmission strategy adjustment factor. The calculation of this factor combines the actual transmission quality of the link and the actual fragmentation characteristics of the message. Based on the initial sliding window capacity, it combines the link transmission accuracy reflected by the bit error rate, the link transmission speed reflected by the round-trip delay, and the message transmission fragmentation scale reflected by the total number of fragment sequences. Through fixed operation logic, the initial sliding window capacity is adaptively adjusted so that the obtained adjustment factor can accurately match the current link state of the bidirectional encrypted communication tunnel and the actual transmission requirements of secure data messages. It becomes the core adaptation coefficient for subsequent correction of the sliding window capacity, ensuring that the corrected sliding window capacity matches the actual transmission capacity of the link and the actual transmission characteristics of the message.

[0052] The initial sliding window capacity is directly extracted from the baseline transmission strategy parameter set. This parameter set is the effective transmission parameter set of the monitoring terminal obtained by comparing the transmission strategy features of the link quality feature parameter set and the preset transmission strategy feature library.

[0053] The transmission strategy adjustment factor is calculated by using fixed operational logic based on the initial sliding window capacity, bit error rate, transmission round-trip time, and total number of fragmented sequences. This factor is the core adaptation coefficient that adapts the link state of the bidirectional encrypted communication tunnel to the fragmentation characteristics of secure data packets.

[0054] The total number of payload bytes is a value obtained by counting the number of bytes in the main payload field of the security data message. This value is the core result after determining the length of the security data message's byte payload.

[0055] The maximum fragment length is a preset fixed value, which is the core judgment standard followed when performing segmentation and fragmentation operations on secure data packets.

[0056] The result of this calculation is the corrected sliding window capacity. The calculation first uses the initial sliding window capacity and the transmission strategy adjustment factor to obtain a first reference value. Then, it uses the total number of payload bytes and the maximum fragment length to obtain a second reference value. Finally, the smaller of the two reference values ​​is selected as the final corrected sliding window capacity. This calculation logic, by taking the smaller of the two reference values, ensures that the corrected sliding window capacity matches both the current link transmission capacity of the bidirectional encrypted communication tunnel and the actual payload and fragmentation characteristics of the secure data packets. This avoids link congestion caused by setting the sliding window capacity too large, and also avoids reduced fragmentation transmission efficiency due to setting the capacity too small. As a core indicator in the transmission strategy configuration parameters, the corrected sliding window capacity provides a precisely adapted window capacity standard for the fragmented transmission of secure data packets through the bidirectional encrypted communication tunnel. This ensures the efficiency and stability of the secure data packet fragmentation transmission process, achieving comprehensive matching and adaptation between the transmission strategy, the actual link state, and the actual characteristics of the packets.

[0057] Pt.5. Based on the dynamic session key, the encrypted data block is symmetrically decrypted, and the signature data of the secure data message is digitally verified to obtain the data payload to be verified and the signature validity verification result of the monitoring terminal. In this embodiment of the invention, the step of symmetrically decrypting the encrypted data block based on the dynamic session key and digitally verifying the signature data of the secure data packet to obtain the verification results of the data payload and signature validity of the monitoring terminal includes: The security data message is parsed to obtain the message parsing information set of the monitoring terminal; Based on the dynamic session key version number of the message parsing information set, the dynamic session key in the preset local repository is matched and located to obtain the decryption key material of the monitoring terminal. Based on the decryption key material, the encrypted data blocks in the security data message are processed to obtain the data payload to be verified of the monitoring terminal. Based on the message parsing information set, the local repository is traversed and searched to obtain the signature verification key material of the monitoring terminal; Based on the signature verification key material, the binding relationship of the signature data of the secure data message is verified to obtain the signature validity verification result of the monitoring terminal.

[0058] The security proxy gateway receives security data packets transmitted by the monitoring terminal. According to the preset security data packet header field division rules, it performs structured parsing of the packet header field by field, extracting all preset core field information contained in the header, such as the dynamic session key version number, the unique device identifier of the monitoring terminal, the packet frame sequence number, the byte length of the encrypted data block, and the signature data storage location identifier. The character format and bit length of each extracted field are verified one by one to ensure that the format of each field fully conforms to the preset packet header field standard and that the field bit length does not deviate from the preset fixed bit length threshold. All verified field information is systematically integrated to form a structured set containing all valid header information. When there are no preset missing fields or field information errors in this set, the structured set is determined as the packet parsing information set of the monitoring terminal.

[0059] The dynamic session key version number is extracted from the message parsing information set. The preset local repository constructs a two-level index storage structure based on the unique device identifier of the monitoring terminal and the dynamic session key version number. All dynamic session keys in the valid usage period are classified and stored. First, the unique device identifier of the monitoring terminal in the message parsing information set is used to match the corresponding monitoring terminal-specific storage directory in the local repository. Then, the dynamic session key version number is used to perform precise key retrieval in the specific directory. The retrieved dynamic session key is verified for integrity. If the key's byte length is confirmed to be the preset 256 bits and there are no missing characters or information tampering, the verified dynamic session key is determined as the decryption key material of the monitoring terminal.

[0060] Extract the complete encrypted data block from the security data message. Divide the encrypted data block into equal blocks of a preset 128-bit fixed byte length. If the last block is less than 128 bits, keep the original data state without padding. Extract the decryption key material as the core key for symmetric decryption. Use this key to perform symmetric decryption on all 128-bit standard blocks and the remaining original blocks one by one. After decryption, concatenate all decrypted block data in the original block order to obtain the concatenated complete original data. Perform preset PKCS7 padding bit identification on the original data to remove the padding data added by the monitoring terminal during the encryption stage. Perform format verification on the final data after padding to ensure that the data structure conforms to the protocol data construction standard of transmission line monitoring data. The data that passes the verification is determined as the data payload to be verified by the monitoring terminal.

[0061] The unique device identifier of the monitoring terminal and the message frame sequence number, and other identification information related to signature verification, are extracted from the message parsing information set. The device public key submitted by each monitoring terminal when completing device registration is permanently stored in the preset local repository according to the unique device identifier of the monitoring terminal. This device public key is a unique signature verification key paired with the monitoring terminal's private key. Using the unique device identifier of the monitoring terminal as the core search keyword, the device public key storage area of ​​the local repository is fully traversed and searched to match the corresponding monitoring terminal device public key. The validity of the device public key is verified to confirm that the public key encoding format conforms to the preset asymmetric encryption key standard, the binding relationship between the public key and the device identifier has not been tampered with, and the public key is within the preset valid use period. The device public key that passes all verification items is determined as the signature verification key material of the monitoring terminal.

[0062] The complete signature data is extracted from the secure data message. This signature data is the digital signature value in the integrity verification credential generated by the monitoring terminal. The payload to be verified is subjected to a preset one-way hashing process, converting the payload into a unique hash value of fixed length 256 bits. The signature verification key material, namely the public key of the monitoring terminal, is extracted. The signature data is then decrypted using the public key to obtain a 256-bit original hash value. This original hash value is compared character by character with the hash value generated from the payload to be verified. At the same time, the binding relationship between the signature data and the message frame sequence number and the unique device identifier of the monitoring terminal in the message parsing information set is checked to see if it conforms to the preset signature binding rules. When the 256 characters of the two hash values ​​completely overlap and the binding relationship of the signature data is completely consistent with the preset rules, a signature validity verification result indicating that the verification has passed is generated. When any character of the two hash values ​​does not overlap or the binding relationship of the signature data does not conform to the preset rules, a signature validity verification result indicating that the verification has failed is generated.

[0063] Pt.6. Using the signature validity verification result as the pass condition, the payload of the data to be verified is protocol adapted and encapsulated to obtain the security audit log of the monitoring terminal.

[0064] In this embodiment of the invention, the step of performing protocol adaptation encapsulation on the payload of the data to be verified, using the signature validity verification result as a pass condition, to obtain the security audit log of the monitoring terminal includes: When the signature validity verification result is passed, the adaptation encapsulation start signal of the monitoring terminal is obtained; Based on the adaptive encapsulation start signal, the type of the payload to be verified is identified to obtain the payload attribute parsing result of the monitoring terminal; Based on the monitoring data type identifier in the net load attribute parsing result, a protocol matching search is performed on the preset master station system communication protocol library to obtain the protocol adaptation template of the monitoring terminal. The data structure of the payload to be verified is mapped to a data frame of the target protocol format in the protocol adaptation template to obtain the adapted data message of the monitoring terminal. The adapted data packets are encapsulated with audit records to obtain the security audit log of the monitoring terminal.

[0065] When the signature validity verification result presents a preset pass status fixed identifier, which is a hexadecimal 00 encoding without any other additional characters, the security proxy gateway automatically generates a standardized adaptation encapsulation start signal. This signal contains preset core information such as the unique device identifier of the monitoring terminal, the security data packet frame sequence number, and the start signal generation timestamp. The character encoding format of the signal conforms to the preset communication instruction standard, and the bit length is fixed at 64 bytes. The generated instruction signal with a correct format is determined as the adaptation encapsulation start signal of the monitoring terminal.

[0066] After the adaptation and encapsulation start signal is triggered, the data payload to be verified from the monitoring terminal is extracted. The 16-bit data type identifier field in the header of the data payload is parsed. At the same time, all preset attribute information such as the acquisition timestamp, data acquisition port identifier, data effective byte length, and transmission line monitoring point code in the data payload are extracted. The format and validity of each extracted attribute information are checked to ensure that the data type identifier field is a preset legal code, the acquisition timestamp is a standard time format, and the monitoring point code is consistent with the preset transmission line point database information. All data type identifiers and attribute information that pass the verification are structured and integrated to form an attribute set without missing fields and without information errors. This set is the payload attribute parsing result of the monitoring terminal.

[0067] The monitoring data type identifier is extracted from the net load attribute analysis results. This identifier is a fixed code that corresponds one-to-one with the monitoring data type of the transmission line. The preset master station system communication protocol library establishes a first-level index according to the monitoring data type identifier. The library stores master station system communication protocol templates corresponding to each type of monitoring data. Each template contains complete protocol specification information such as the frame structure definition of the target protocol, field length requirements, field arrangement order, and fixed protocol identifier. Using the extracted monitoring data type identifier as the search keyword, a precise one-to-one protocol matching search is performed in the master station system communication protocol library to extract the unique matching protocol template. The integrity of the template is verified to ensure that the template contains all preset protocol specification fields and that there is no content tampering. The protocol template that passes the verification is determined as the protocol adaptation template of the monitoring terminal.

[0068] The process involves analyzing all the specifications of the target protocol format data frame as defined in the protocol adaptation template, including the field composition of the frame header, body, and trailer, the bit length thresholds of each field, the order of fields, and fixed padding characters. Each data item in the payload to be verified is precisely mapped to the preset fields of the protocol adaptation template. The bit length of each data item is adjusted according to the template requirements. Fields shorter than the preset length are padded according to the template standard, and fields longer than the preset length are truncated according to the template rules. Fixed protocol identifiers and verification characters are then added to the specified positions as required by the template. All mapped and adjusted fields are assembled into a frame structure according to the order specified in the template to form a complete data frame. The frame structure, field bit lengths, and order of this data frame are then fully verified to ensure complete consistency with the target protocol format of the protocol adaptation template. Data frames that pass the verification are identified as the adapted data packets for the monitoring terminal.

[0069] Complete information of the adapted data packets from the monitoring terminal is extracted, including packet frame sequence number, protocol type identifier, valid data content, and packet generation time. Simultaneously, the entire process information of the monitoring data from transmission to parsing is integrated, specifically including the monitoring terminal's unique device identifier, secure data packet transmission time, dynamic session key version number, digital signature verification result, protocol adaptation template matching identifier, adaptation encapsulation completion time, and all preset audit information. Following a preset security audit log format, the adapted data packet information and the entire process information are sequentially filled into the corresponding preset fields of the log. The log field lengths and character formats all adhere to fixed standards and include a unique sequence number for the audit record. After all fields are filled, a comprehensive verification of the log's field completeness, information consistency, and format standardization is performed to ensure no missing fields, no information contradictions, and no format errors. The structured audit record that passes the verification is identified as the monitoring terminal's security audit log.

[0070] like Figure 2 The diagram shown is a functional block diagram of a power transmission line monitoring data security protection device based on encrypted transmission, provided in an embodiment of the present invention.

[0071] The encrypted transmission line monitoring data security protection device described in this invention can be installed in electronic devices. Depending on the functions implemented, the encrypted transmission line monitoring data security protection device may include a verification tunneling module, a key derivation module, an encrypted signature module, a tunneling message module, a signature decryption and verification module, and an audit encapsulation module. The module described in this invention can also be called a unit, which refers to a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.

[0072] In this embodiment, the functions of each module / unit are as follows: The verification and tunneling module is used to verify the digital certificate chain of the security proxy gateway based on the connection request sent by the monitoring terminal to the security proxy gateway, and to perform a transport layer security protocol handshake with the monitoring terminal based on the certificate validity confirmation result, so as to obtain a two-way encrypted communication tunnel for the monitoring terminal. The key derivation module is used to derive the dynamic session key of the monitoring terminal from the session key factor of the security proxy gateway and the device key of the monitoring terminal. The encryption and signing module is used to perform symmetric encryption on the data payload of the monitoring terminal based on the dynamic session key, and to digitally sign the obtained encrypted data block based on the device private key of the monitoring terminal to obtain the secure data message of the monitoring terminal. The tunneling message module is used to deliver the security data message to the security proxy gateway through the bidirectional encrypted communication tunnel based on the monitoring terminal, and obtain the message reception status of the monitoring terminal. The signature decryption and verification module is used to perform symmetric decryption of the encrypted data block based on the dynamic session key, and to perform digital signature verification on the signature data of the secure data message, so as to obtain the data payload to be verified and the signature validity verification result of the monitoring terminal. The audit encapsulation module is used to perform protocol adaptation encapsulation on the payload of the data to be verified, based on the signature validity verification result as the pass condition, to obtain the security audit log of the monitoring terminal.

[0073] In the several embodiments provided by this invention, it should be understood that the disclosed methods and apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0074] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0075] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0076] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0077] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application device that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0078] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for protecting the security of transmission line monitoring data based on encrypted transmission, characterized in that, The method includes: Pt.

1. Based on the connection request sent by the monitoring terminal to the security proxy gateway, the digital certificate of the security proxy gateway is verified by certificate chain verification, and a transport layer security protocol handshake is performed with the monitoring terminal based on the certificate validity confirmation result to obtain the bidirectional encrypted communication tunnel of the monitoring terminal. Pt.

2. Perform key derivation on the session key factor of the security proxy gateway and the device key of the monitoring terminal to obtain the dynamic session key of the monitoring terminal; Pt.

3. Based on the dynamic session key, the data payload of the monitoring terminal is symmetrically encrypted, and based on the device private key of the monitoring terminal, the obtained encrypted data block is digitally signed to obtain the secure data message of the monitoring terminal. Pt.

4. Based on the monitoring terminal, the security data message is delivered to the security proxy gateway through the bidirectional encrypted communication tunnel to obtain the message reception status of the monitoring terminal; Pt.

5. Based on the dynamic session key, the encrypted data block is symmetrically decrypted, and the signature data of the secure data message is digitally verified to obtain the data payload to be verified and the signature validity verification result of the monitoring terminal. Pt.

6. Using the signature validity verification result as the pass condition, the payload of the data to be verified is protocol adapted and encapsulated to obtain the security audit log of the monitoring terminal.

2. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 1, characterized in that, The process of verifying the digital certificate of the security proxy gateway based on the connection request sent by the monitoring terminal to the security proxy gateway, and performing a transport layer security protocol handshake with the monitoring terminal based on the certificate validity confirmation result to obtain a bidirectional encrypted communication tunnel for the monitoring terminal includes: Based on the connection request sent by the monitoring terminal to the security proxy gateway, the digital certificate of the security proxy gateway is traced back to obtain the certificate chain integrity authentication identifier of the monitoring terminal. Using the certificate chain integrity authentication identifier as the compliance pass status, the digital certificate is queried from the certificate revocation list to obtain the certificate compliance authentication credential of the monitoring terminal; With the certificate compliance authentication credential as the compliance status, a transport layer security protocol handshake negotiation request is initiated to the monitoring terminal, and the client key exchange parameters returned by the monitoring terminal are received. The consistency of the client key exchange parameters with the preset master key is verified to obtain the matching confirmation credential of the monitoring terminal. Based on the matching confirmation credential, the selection of encryption suites and the generation of session tickets between the monitoring terminal and the security proxy gateway are collaboratively confirmed to obtain a two-way encrypted communication tunnel for the monitoring terminal.

3. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 1, characterized in that, The step of deriving the dynamic session key of the monitoring terminal from the session key factor of the security proxy gateway and the device key of the monitoring terminal includes: The random entropy source of the security proxy gateway is encapsulated with a session key factor to obtain the initial parameters for key derivation of the monitoring terminal. The initial parameters for key derivation are concatenated with the device private key of the monitoring terminal to obtain the dynamic session key on the monitoring terminal side of the monitoring terminal; Based on the key derivation initial parameters, the device public key of the monitoring terminal is entropy-mixed to obtain the gateway-side dynamic session key of the monitoring terminal; The dynamic session key of the monitoring terminal is obtained by comparing the dynamic session key on the monitoring terminal side with the dynamic session key on the gateway side using a key fingerprint.

4. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 1, characterized in that, The process of symmetrically encrypting the data payload of the monitoring terminal based on the dynamic session key, and digitally signing the resulting encrypted data block based on the device private key of the monitoring terminal to obtain the secure data message of the monitoring terminal includes: Protocol data is constructed from the original transmission line monitoring data of the monitoring terminal, and field information is embedded into the generated data payload to obtain the encrypted message carrier of the monitoring terminal. Based on the dynamic session key, the message carrier to be encrypted is symmetrically encrypted to obtain the data carrier to be signed by the monitoring terminal. Based on the device private key of the monitoring terminal, a digital signature is bound to the data carrier to be signed, a digital signature value is generated, and the integrity verification credential of the monitoring terminal is obtained. The encrypted data block and the integrity verification credential are aggregated to obtain the security data message of the monitoring terminal.

5. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 1, characterized in that, The step of delivering the security data packet to the security proxy gateway through the bidirectional encrypted communication tunnel based on the monitoring terminal, and obtaining the packet reception status of the monitoring terminal, includes: The security data packets are marked with transmission priority to obtain the packet queuing ready status of the monitoring terminal; Based on the message queuing ready state, the transmission strategy of the security data message is matched through the bidirectional encrypted communication tunnel to obtain the transmission strategy configuration parameters of the monitoring terminal. Based on the transmission strategy configuration parameters, the security data packet is segmented to obtain the segmentation transmission progress record of the monitoring terminal; For the fragment delivery feedback set of the fragment transmission progress record, selective retransmission is performed on the missing transmission fragments of the security data message to obtain the full message delivery certificate of the monitoring terminal. Based on the full message delivery credential, the security data message is marked with a transmission status, a message reception status record is generated, and the message reception status record is used as the message reception status of the monitoring terminal.

6. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 5, characterized in that, Based on the message queuing readiness state, the transmission strategy matching of the secure data message through the bidirectional encrypted communication tunnel is performed to obtain the transmission strategy configuration parameters of the monitoring terminal, including: Based on the message queuing ready state, probe frame interaction is performed on the link status of the bidirectional encrypted communication tunnel to obtain the link quality characteristic parameter set of the monitoring terminal; Based on the link quality feature parameter set, the transmission strategy features of the preset transmission strategy feature library are compared to obtain the baseline transmission strategy parameter set of the monitoring terminal. The security data message payload length is measured, and based on the obtained total payload bytes and the initial sliding window capacity in the reference transmission strategy parameter set, the security data message is segmented and assembled to obtain the fragmentation scheme of the monitoring terminal. The total number of fragment sequences in the fragmentation scheme is compared with the slow start threshold in the baseline transmission strategy parameter set to obtain the transmission strategy configuration parameters of the monitoring terminal.

7. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 6, characterized in that, The calculation formulas for the transmission strategy adjustment factor and the corrected sliding window capacity in the transmission strategy configuration parameters are as follows: , ; In the formula, This is the adjustment factor for the transmission strategy. The initial sliding window capacity, The bit error rate is the value in the set of link quality characteristic parameters. The transmission round-trip delay is the value in the set of link quality characteristic parameters. The total number of the fragmented sequences, The corrected sliding window capacity is... The total number of bytes in the payload. This is the preset maximum segment length in bytes.

8. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 1, characterized in that, The process of symmetrically decrypting the encrypted data block based on the dynamic session key and digitally verifying the signature data of the secure data message to obtain the verification results of the data payload and signature validity of the monitoring terminal includes: The security data message is parsed to obtain the message parsing information set of the monitoring terminal; Based on the dynamic session key version number of the message parsing information set, the dynamic session key in the preset local repository is matched and located to obtain the decryption key material of the monitoring terminal. Based on the decryption key material, the encrypted data blocks in the security data message are processed to obtain the data payload to be verified of the monitoring terminal. Based on the message parsing information set, the local repository is traversed and searched to obtain the signature verification key material of the monitoring terminal; Based on the signature verification key material, the binding relationship of the signature data of the secure data message is verified to obtain the signature validity verification result of the monitoring terminal.

9. The method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 1, characterized in that, The process involves using the signature validity verification result as a pass condition to perform protocol adaptation and encapsulation on the payload of the data to be verified, resulting in the security audit log of the monitoring terminal, including: When the signature validity verification result is passed, the adaptation encapsulation start signal of the monitoring terminal is obtained; Based on the adaptive encapsulation start signal, the type of the payload to be verified is identified to obtain the payload attribute parsing result of the monitoring terminal; Based on the monitoring data type identifier in the net load attribute parsing result, a protocol matching search is performed on the preset master station system communication protocol library to obtain the protocol adaptation template of the monitoring terminal. The data structure of the payload to be verified is mapped to a data frame of the target protocol format in the protocol adaptation template to obtain the adapted data message of the monitoring terminal. The adapted data packets are encapsulated with audit records to obtain the security audit log of the monitoring terminal.

10. A data security protection device for transmission line monitoring based on encrypted transmission, characterized in that, The device for implementing the method for secure protection of transmission line monitoring data based on encrypted transmission as described in claim 1 includes: The verification and tunneling module is used to verify the digital certificate chain of the security proxy gateway based on the connection request sent by the monitoring terminal to the security proxy gateway, and to perform a transport layer security protocol handshake with the monitoring terminal based on the certificate validity confirmation result, so as to obtain a two-way encrypted communication tunnel for the monitoring terminal. The key derivation module is used to derive the dynamic session key of the monitoring terminal from the session key factor of the security proxy gateway and the device key of the monitoring terminal. The encryption and signing module is used to perform symmetric encryption on the data payload of the monitoring terminal based on the dynamic session key, and to digitally sign the obtained encrypted data block based on the device private key of the monitoring terminal to obtain the secure data message of the monitoring terminal. The tunneling message module is used to deliver the security data message to the security proxy gateway through the two-way encrypted communication tunnel based on the monitoring terminal, and to obtain the message reception status of the monitoring terminal. The signature verification module is used to perform symmetric decryption of the encrypted data block based on the dynamic session key, and to perform digital signature verification on the signature data of the secure data message, so as to obtain the data payload to be verified and the signature validity verification result of the monitoring terminal. The audit encapsulation module is used to perform protocol adaptation encapsulation on the payload of the data to be verified, based on the signature validity verification result as the pass condition, to obtain the security audit log of the monitoring terminal.