A smart grid communication security and fault detection method

Through the cooperation between cloud servers and third-party trusted institutions, encryption algorithms and fault recorders are used to perform user login and device fault detection, solving user data and communication security problems in the smart grid, achieving rapid and accurate fault identification and classification, and improving the security and stability of the grid.

CN115146669BActive Publication Date: 2025-08-15GUANGDONG POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210535391.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-17
Publication Date
2025-08-15
Estimated Expiration
2042-05-17

AI Technical Summary

Technical Problem

There are hidden dangers in the user data on the meter side of the smart grid, and there are security risks in the data center and communications. It is difficult for the existing technology to quickly and accurately identify illegal users and equipment failures, affecting the stability and security of the power grid.

Method used

The cloud server is used to cooperate with third-party trusted institutions to verify user login through encryption algorithms and biological information, combine the fault recorder to collect current data for fault detection, and use transient high-frequency components and multi-dimensional scale dimensional reduction methods to classify faults to achieve fast and safe detection.

Benefits of technology

It improves the security and privacy of user data, reduces the detection burden of cloud servers, can quickly identify trusted users and equipment failures, prevent malicious interference, and improves the stability of the power grid and the accuracy and speed of fault detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure SMS_1
    Figure SMS_1
  • Figure SMS_2
    Figure SMS_2
  • Figure FDA0005300943380000011
    Figure FDA0005300943380000011
Patent Text Reader

Abstract

The present invention provides a smart grid communication security and fault detection method. The smart grid includes a cloud server that collects data transmitted to the cloud server via transmission lines from large-scale grid equipment and user smart meters and performs security fault detection. The cloud server also performs secondary registration and security verification with a third-party trusted institution and transmits the encrypted information to the third-party trusted institution via a secure channel. By establishing a third-party trusted institution to register and perform security verification on user login information and detect device security fault information, the present invention not only identifies trusted users and records their usage history, thereby enhancing the security and privacy of user-side data, but also reduces the burden on the cloud server to detect device security faults and prevents interference from malicious third parties.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to network security, and in particular to a smart grid communication security and fault detection method. Background Art

[0002] As an essential and vital facility in today's society, the power system impacts every aspect of people's lives and work. However, the traditional power grid, which is large in scale but small in number, and based on centralized power generation and long-distance, one-way transmission, is increasingly unable to meet people's demands for high-quality power and diverse power services.

[0003] The safe and reliable operation of distribution networks is fundamental to ensuring power supply reliability. With the increasing development of intelligent distribution networks, higher requirements are being placed on the safety of distribution lines. In response to these societal demands, a new smart grid architecture has emerged, driving power system reform. Built on a highly integrated, two-way communication network, this new grid features a small scale, a large number of grids, and modular functionality. This improves the significant system instability inherent in traditional large-scale grids, which suffer from centralized power generation and long-distance power supply.

[0004] In response to these societal demands, a new smart grid architecture has emerged, driving power system reform. Built on a highly integrated, two-way communication network, this new grid features a smaller, more numerous, and modular network. This overcomes the significant system instability inherent in traditional large-scale power grids, which rely on centralized generation and long-distance power supply. The self-healing capabilities of smart grids significantly improve system reliability and security. When a grid encounters a fault, it can self-diagnose and restore itself to its maximum operational state, ensuring continuous power supply service. Furthermore, smart grids utilize both distributed and centralized power generation technologies, supporting regional power supply compensation and small-scale, short-distance power transmission. This effectively reduces power losses and improves the utilization of power resources. Distributed generation technology supports the scientific integration of clean energy sources such as wind, solar, biomass, geothermal, and tidal energy, fostering coordinated generation of large-scale renewable energy with hydropower, thermal, and nuclear power, and transforming the traditional large-scale power grid's reliance on coal and thermal power. This not only conserves resources but also meets humanity's long-term goals of building an environmentally friendly society and implementing a sustainable development strategy.

[0005] The real-time two-way information exchange between smart grid devices and users provides a data foundation for the integrated development of current, information flow, and business flow. Frequent information exchange between the power grid and users, such as message authentication, data collection, and data communication, will bring new security risks, leading to information security risks within the power grid. The main problems are: hidden dangers in user data on the meter side, hidden dangers in the data center, and security and efficiency risks in data communication.

[0006] Smart meters primarily monitor users' electricity usage in real time, regularly collect data, and transmit it to data centers. While smart meters are the smallest data storage units in a power grid system, the entire grid comprises a vast number of them. Therefore, further research is needed to protect meter-side electricity usage data and prevent attackers from inserting malware to steal, modify, or falsify users' daily electricity usage data.

[0007] The proper operation and effective maintenance of smart grids rely on real-time data collected from power plants, transmission networks, distribution stations, user groups, markets, and grid operators. Without robust data storage systems and strong data security mechanisms, the grid system can lead to massive data leaks. Data centers are the largest data repositories for smart grids, collecting and analyzing various data indicators on grid operations to maintain and manage the balance between electricity supply and demand. If a data center is compromised or infected with a virus, it can affect grid operators' analysis and decision-making, leading to erroneous operations and instructions, causing grid equipment failures, and even threatening the lives of grid operators.

[0008] Smart grids are built on an integrated, high-speed, two-way communication network. The rapid growth of power facilities within the grid has made the grid environment and structure increasingly complex in both time and space. This complex network environment significantly increases the uncertainty of an attacker's attack range and the uncontrollability of their destructive power. In addition to ensuring the security of communication data between meters and data centers, communication costs must also be considered to ensure efficient data exchange. Due to the limited computing power of smart meters, computational complexity at the meter side must be minimized to achieve high privacy and integrity for meter-side data at a low communication cost. In short, two-way communication within the grid must ensure not only spatial security but also timeliness during data collection, transmission, and reception. Summary of the Invention

[0009] In order to solve the problems existing in the above-mentioned prior art, the purpose of the present invention is to provide a smart grid communication security and fault detection method to quickly and accurately detect illegal users logging in to steal information, while being able to quickly and safely identify the faulty network segments of power grid equipment and realize fault classification.

[0010] In order to achieve the above-mentioned object of the invention, the technical solution of the present invention is implemented in the following manner:

[0011] A method for communication security and fault detection in a smart grid, wherein the smart grid includes a cloud server that collects data transmitted by large-scale grid equipment and user smart meters to a third-party trusted organization via transmission lines and performs security fault detection, comprising the following steps:

[0012] A. User Login Security Check: When a user logs in and uploads data using pre-registered registration information using a smart meter (including user ID, user-defined password, and biometric information), the smart meter uses an encryption algorithm to encrypt the registration information and combines it with the current timestamp to calculate the encrypted user information, which is then sent to the cloud server via a secure channel. Upon receiving the encrypted user information, the cloud server uses a corresponding decryption algorithm to verify it and stores it in its own database as a login log. Simultaneously, the cloud server performs secondary registration and security verification with a third-party trusted institution, sending the encrypted information to the third-party trusted institution via a secure channel. Upon receiving the encrypted information at the current time, the third-party trusted institution uses a decryption algorithm to verify and register it.

[0013] The third-party trusted institution compares the decrypted calculated value with the previously stored registration information. If they match, the cloud server is notified to receive the data and proceed with the next operation. Otherwise, the service is denied.

[0014] B. Equipment Operation Data Security Detection: The cloud server receives equipment operation data of large-scale power grid equipment via a secure channel. This equipment operation data includes operation data recorded by a fault recorder. The cloud server calculates equipment encryption information based on the current timestamp and sends it to the cloud server via a secure channel. Upon receiving the encrypted equipment information, the cloud server verifies the equipment operation record using a corresponding decryption algorithm and stores it in its own database as an equipment usage log. Simultaneously, the cloud server also sends the encrypted equipment information to the third-party trusted institution via a secure channel.

[0015] When the third-party trusted institution receives the encrypted information at the current time, it uses a decryption algorithm to verify and perform fault detection. The third-party trusted institution notifies the cloud server of the fault detection result for real-time reporting of the security fault.

[0016] The user's biometric information includes fingerprints, vein fingerprints, and faces.

[0017] The specific steps of the fault detection include: collecting standard typical fault data and non-fault period data of the grounding section of the distribution network within a period of time through the fault recorder as training samples, normalizing the training samples, extracting the characteristic values of the training samples, and using the characteristic values and fault categories of each sample as input to train an output classification model; wherein the fault types include single-phase grounding fault and two-phase grounding fault;

[0018] The current data recorded in the operation log of a training sample for a period of time is decomposed into waveforms according to a set time period scale. After decomposition, the waveforms containing high-frequency components are extracted, and the transient high-frequency components are calculated. The high-dimensional transient high-frequency components are then reduced to a two-dimensional space using a multidimensional scaling method, and the eigenvalues of the matrix after dimensionality reduction are calculated.

[0019] According to the trained classification model, the existing untrained fault data samples are input as test samples, and the predicted fault type is output. The parameters of the classification model are iteratively corrected based on the classification results, so that the accuracy of the classification model reaches the set accuracy threshold;

[0020] The modified classification model is used to detect the fault type of the log data in the current fault area.

[0021] The transient high-frequency component is obtained by performing phase mode transformation and wavelet transformation on the detected fault current signal data to obtain the transient high-frequency component of the measured fault current signal.

[0022] The transient high-frequency component can also be obtained by performing a Prony iterative algorithm on the zero-sequence current signal measured at each terminal, and using the iterative calculation result as the transient high-frequency component.

[0023] The Prony iterative calculation is to fit the equally spaced sampling data using a linear combination of a set of exponential functions with arbitrary amplitude, phase, frequency and attenuation factor. Its general expression is:

[0024]

[0025] In formula (1), the amplitude A i , phase θ i , attenuation factor α i , oscillation frequency f i , (i=1, 2,…, q), t is the sampling time.

[0026] The accuracy threshold is 98%.

[0027] The fault recorder uploads normal data at a low frequency when the distribution network operates normally, and uploads high-frequency data when a fault occurs, thereby obtaining local high-frequency data.

[0028] The beneficial effects of the present invention are:

[0029] By setting up a third-party trusted institution to register and perform security checks on user login information and detect device safety fault information, this not only identifies trusted users and records their usage history, enhancing the security and privacy of user-side data, but also reduces the burden on cloud servers to detect device safety faults, while also preventing malicious third-party interference. Furthermore, since the third-party trusted institution's fault detection method utilizes waveform decomposition based on a set time period, extracts waveforms containing high-frequency components, calculates a transient high-frequency component matrix, and uses multidimensional scaling to reduce the high-dimensional transient high-frequency component matrix to a two-dimensional space, calculating the eigenvalues of the reduced matrix, this facilitates model training and convergence, improving the accuracy and speed of fault classification. This protects user identity information security and interests, while maintaining the stability of the power grid. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 It is a schematic diagram of the application of the smart grid communication security and fault detection method of the present invention;

[0031] Figure 2 It is a flow chart of the user login security detection steps in the method of the present invention;

[0032] Figure 3 It is a flow chart of the steps of equipment operation data security detection in the method of the present invention; DETAILED DESCRIPTION

[0033] A smart grid communication security and fault detection method of the present invention is as follows: Figure 1 As shown, the smart grid includes a cloud server that collects data transmitted by large-scale grid equipment and user smart meters to a third-party trusted organization through transmission lines and performs security fault detection, including the following steps:

[0034] A. User login security detection: Figure 2 As shown, when a user uses a smart meter to log in and upload data using pre-registered registration information, the registration information includes: user identity ID, user-defined password and user biometric information. The smart meter uses an encryption algorithm to encrypt the registration information and combines it with the current timestamp to calculate the user encrypted information and sends it to the cloud server through a secure channel. After receiving the above user encrypted information, the cloud server uses the corresponding decryption algorithm to verify it and stores it in its own database to form a login log. At the same time, the cloud server also performs secondary registration and security verification at a third-party trusted institution and sends the encrypted information to the third-party trusted institution through a secure channel. When the third-party trusted institution receives the encrypted information at the current time, it uses the decryption algorithm to verify and register it.

[0035] The third-party trusted institution compares the decrypted value with the previously stored registration information. If they match, the cloud server is notified to receive the data and proceed with the next operation. Otherwise, the service is denied.

[0036] B. Equipment operation data security detection: Figure 3 As shown, the cloud server receives the equipment operation data of the large-scale equipment of the power grid through a secure channel. The equipment operation data includes the operation data recorded by the fault recorder. The equipment encryption information is calculated by combining the current timestamp and sent to the cloud server through a secure channel. After receiving the above-mentioned equipment encryption information, the cloud server verifies it using a corresponding decryption algorithm to obtain the equipment operation record, and stores it in its own database to form an equipment usage log. At the same time, the cloud server also sends the equipment encryption information to the third-party trusted organization through a secure channel;

[0037] When the third-party trusted institution receives the encrypted information at the current time, it uses the decryption algorithm to verify and perform fault detection. The third-party trusted institution notifies the cloud server of the fault detection results for real-time reporting of security faults.

[0038] User biometric information includes fingerprints, vein fingerprints, and faces.

[0039] The specific steps of fault detection include: using a fault recorder to collect standard typical fault data and non-fault period data from the grounding section of the distribution network for a period of time as training samples, normalizing the training samples, extracting the training sample feature values, and using the feature values and fault categories of each sample as input to train an output classification model. Fault types include single-phase grounding faults and two-phase grounding faults.

[0040] The current data recorded in the operation log of a training sample for a period of time is decomposed into waveforms according to a set time period scale. After decomposition, the waveforms containing high-frequency components are extracted, and the transient high-frequency components are calculated. The high-dimensional transient high-frequency components are then reduced to a two-dimensional space using a multidimensional scaling method, and the eigenvalues of the matrix after dimensionality reduction are calculated.

[0041] According to the trained classification model, the existing untrained fault data samples are input as test samples, and the predicted fault type is output. The parameters of the classification model are iteratively corrected based on the classification results, so that the accuracy of the classification model reaches the set accuracy threshold;

[0042] The modified classification model is used to detect the fault type of the log data in the current fault area.

[0043] The transient high-frequency component is obtained by performing phase mode transformation and wavelet transformation on the detected fault current signal data.

[0044] The transient high-frequency component can also be obtained by performing a Prony iterative algorithm on the zero-sequence current signal measured at each terminal, and using the iterative calculation result as the transient high-frequency component.

[0045] Prony iterative calculation is to fit the equally spaced sampling data with a linear combination of a set of exponential functions with arbitrary amplitude, phase, frequency and attenuation factor. Its general expression is:

[0046]

[0047] In formula (1), the amplitude A i , phase θ i , attenuation factor α i , oscillation frequency f i , (i=1, 2,…, q), t is the sampling time.

[0048] The accuracy threshold is 98%.

[0049] The fault recorder uploads normal data at a low frequency when the distribution network is operating normally, and uploads high-frequency data when a fault occurs, thereby obtaining local high-frequency data.

[0050] The present invention registers and securely detects user login information data and detects device safety fault information by setting up a third-party trusted institution. This not only identifies trusted users and records their usage records, thereby enhancing the security and privacy of user-side data, but also reduces the burden of cloud servers on detecting device safety faults, while preventing malicious third-party interference. Furthermore, the fault detection method of the third-party trusted institution employs waveform decomposition based on a set time period scale, extracts waveforms containing high-frequency components after decomposition, calculates the transient high-frequency component matrix, and employs a multidimensional scaling dimensionality reduction method to reduce the high-dimensional transient high-frequency component matrix to a two-dimensional space, and calculates the eigenvalues of the reduced matrix. This is beneficial to model training and convergence, and is beneficial to improving the accuracy and speed of fault classification. This protects the user's identity information security and interest security, and maintains the stability of the power grid.

[0051] The above technical solutions only reflect the preferred technical solutions of the technical solutions of the present invention. Any changes that may be made to certain parts thereof by those skilled in the art all reflect the principles of the present invention and fall within the scope of protection of the present invention.

Claims

1. A method for communication security and fault detection in a smart grid, wherein the smart grid includes a cloud server that collects data transmitted by large-scale grid equipment and user smart meters to a third-party trusted institution via transmission lines and performs security fault detection, characterized in that The steps include: A. User Login Security Check: When a user logs in and uploads data using pre-registered registration information using a smart meter (including user ID, user-defined password, and biometric information), the smart meter uses an encryption algorithm to encrypt the registration information and combines it with the current timestamp to calculate the encrypted user information, which is then sent to the cloud server via a secure channel. Upon receiving the encrypted user information, the cloud server uses a corresponding decryption algorithm to verify it and stores it in its own database as a login log. Simultaneously, the cloud server performs secondary registration and security verification with a third-party trusted institution, sending the encrypted information to the third-party trusted institution via a secure channel. Upon receiving the encrypted information at the current time, the third-party trusted institution uses a decryption algorithm to verify and register it. The third-party trusted institution compares the decrypted calculated value with the previously stored registration information. If they match, the cloud server is notified to receive the data and proceed with the next operation. Otherwise, the service is denied. B. Equipment Operation Data Security Detection: The cloud server receives equipment operation data of large-scale power grid equipment via a secure channel. This equipment operation data includes operation data recorded by a fault recorder. The cloud server calculates equipment encryption information based on the current timestamp and sends it to the cloud server via a secure channel. Upon receiving the encrypted equipment information, the cloud server verifies the equipment operation record using a corresponding decryption algorithm and stores it in its own database as an equipment usage log. Simultaneously, the cloud server also sends the encrypted equipment information to the third-party trusted institution via a secure channel. When the third-party trusted institution receives the encrypted information at the current time, it uses a decryption algorithm to verify and perform fault detection. The third-party trusted institution notifies the cloud server of the fault detection result for real-time reporting of the security fault.

2. A smart grid communication security and fault detection method according to claim 1, characterized in that: The user's biometric information includes fingerprints, vein fingerprints, and faces.

3. The smart grid communication security and fault detection method according to claim 2, characterized in that: The specific steps of the fault detection include: collecting standard typical fault data and non-fault period data of the grounding section of the distribution network within a period of time through the fault recorder as training samples, normalizing the training samples, extracting the characteristic values of the training samples, and using the characteristic values and fault categories of each sample as input to train an output classification model; wherein the fault types include single-phase grounding fault and two-phase grounding fault; The current data recorded in the operation log of a training sample for a period of time is decomposed into waveforms according to a set time period scale. After decomposition, the waveforms containing high-frequency components are extracted, and the transient high-frequency components are calculated. The high-dimensional transient high-frequency components are then reduced to a two-dimensional space using a multidimensional scaling method, and the eigenvalues of the matrix after dimensionality reduction are calculated. According to the trained classification model, the existing untrained fault data samples are input as test samples, and the predicted fault type is output. The parameters of the classification model are iteratively corrected based on the classification results, so that the accuracy of the classification model reaches the set accuracy threshold; The modified classification model is used to detect the fault type of the log data in the current fault area.

4. A smart grid communication security and fault detection method according to claim 3, characterized in that: The transient high-frequency component is obtained by performing phase mode transformation and wavelet transformation on the detected fault current signal data to obtain the transient high-frequency component of the measured fault current signal.

5. The smart grid communication security and fault detection method according to claim 3, characterized in that: The transient high-frequency component can also be obtained by performing a Prony iterative algorithm on the zero-sequence current signal measured at each terminal, and using the iterative calculation result as the transient high-frequency component.

6. A smart grid communication security and fault detection method according to claim 5, characterized in that: The Prony iterative calculation is to fit the equally spaced sampling data using a linear combination of a set of exponential functions with arbitrary amplitude, phase, frequency and attenuation factor, and its expression is: In formula (1), the amplitude A i , phase θ i , attenuation factor α i , oscillation frequency f i , (i=1, 2,…, q), t is the sampling time.

7. A smart grid communication security and fault detection method according to any one of claims 3 to 6, characterized in that: The accuracy threshold is 98%.

8. A smart grid communication security and fault detection method according to any one of claims 1 to 6, characterized in that: The fault recorder uploads normal data at a low frequency when the distribution network operates normally, and uploads high-frequency data when a fault occurs, thereby obtaining local high-frequency data.

Citation Information

Patent Citations

  • Cloud service behavior trustworthiness attestation method and system based on trusted third party

    CN103905461A

  • Anonymous multi-dimensional data aggregation privacy protection method for smart power grid

    CN112989416A