A network access method, system, and readable medium for a secure access gateway.

By optimizing the data transmission process of the secure access gateway, and combining the source and access mode of the transmitted data, parallel scheduling optimization is adopted to solve the problem of insufficient reliability of the communication system under high-concurrency access in traditional methods, and realize efficient network communication for substation inspection services.

CN116319593BActive Publication Date: 2026-05-26SHENZHEN POWER SUPPLY BUREAU

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN POWER SUPPLY BUREAU
Filing Date
2023-02-27
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Traditional network access methods cannot guarantee the reliability of communication systems under high-concurrency access conditions, and cannot meet the security requirements of substation inspection services.

Method used

By optimizing the data transmission process of the secure access gateway, and considering the source and access mode of the transmitted data, parallel scheduling optimization is adopted to optimize the uplink subprocess, downlink subprocess, and data security authentication subprocess respectively. This includes filtering preprocessing and multi-path parallel scheduling optimization. The reported data queue is prioritized according to the warning level of the acquisition device.

Benefits of technology

It achieves the security requirements of substation inspection services under high-concurrency access conditions, improves the reliability and efficiency of network communication, and saves network resources and economic costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116319593B_ABST
    Figure CN116319593B_ABST
Patent Text Reader

Abstract

This invention discloses a network access method, system, and readable medium for a secure access gateway, relating to the field of network communication technology. It involves acquiring the source and access mode of transmitted data, the scheduling process and its sub-processes during data transmission in the secure access gateway; optimizing each sub-process; associating the access mode of transmitted data with the optimized sub-processes to start the scheduling process, thereby achieving network access to the secure access gateway; optimizing the scheduling process during data transmission by considering the source and access mode (single access or high-concurrency access) of transmitted data in actual operation; and optimizing the data security authentication sub-process through parallel scheduling optimization, thus meeting the security requirements of substation inspection services and providing efficient network communication technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network communication technology, and more specifically to a network access method, system, and readable medium for a secure access gateway. Background Technology

[0002] During the process of terminal devices accessing the network through the access gateway, the security authentication technology of the terminal devices is closely integrated with the business requirements of network services. Different security level authentication technologies are selected according to the security level requirements of different services. At the same time, due to the wide distribution, large number, and high concurrency of various terminal devices, network services place strict requirements on the reliability, scalability, and real-time performance of the communication system. Summary of the Invention

[0003] The technical problem this invention aims to solve is that, due to the wide distribution, large number, and high concurrency of various terminal devices, traditional network access methods struggle to guarantee the reliability of communication systems when dealing with high-concurrency access scenarios. This invention aims to provide a network access method, system, and readable medium for a secure access gateway. By combining the source and access mode of transmitted data in actual operation, it selectively optimizes the scheduling process during data transmission in the secure access gateway. Through parallel scheduling optimization, it achieves optimization of the data security authentication subprocess, meeting the security requirements of substation inspection services and providing an efficient network communication technology.

[0004] This invention is achieved through the following technical solution:

[0005] This solution provides a network access method for a secure access gateway, the method comprising the following steps:

[0006] Step 1: Obtain the source and access mode of the transmitted data, the scheduling process and its sub-processes during the data transmission process of the secure access gateway; the sub-processes include: uplink sub-process, downlink sub-process and data security authentication sub-process; the access mode of the transmitted data includes single access mode and high-concurrency access mode;

[0007] Step two, optimize each child process individually:

[0008] In the downlink subprocess, the transmitted data is filtered and preprocessed; in the data security authentication subprocess, the authentication algorithm is optimized through multi-path parallel scheduling; in the uplink subprocess, the reporting data queue is prioritized and reorganized based on the source of the transmitted data.

[0009] Step 3: Associate the access mode for data transmission, start the scheduling process with the optimized subprocess, and realize secure network access to the gateway.

[0010] The working principle of this solution is as follows: The purpose of this invention is to provide a network access method, system and readable medium for a secure access gateway. By combining the source and access mode of the data transmitted in actual operation, the scheduling process of the secure access gateway in the data transmission process is selectively optimized. Through parallel scheduling optimization, the data security authentication subprocess is optimized, which meets the security requirements of substation inspection business and is an efficient network communication technology.

[0011] This solution is applied to the inspection work of terminal equipment such as substation inspection robots in the field. Since the inspection robot runs one or more inspection services internally, it transmits the data detected in the field to the server during its work. Because there are multiple services internally, it is necessary to ensure the security of data transmission for each service. This solution optimizes the scheduling process of data transmission in the secure access gateway by considering the source of the transmitted data (the data acquisition devices on the inspection robot corresponding to the transmitted data, such as temperature acquisition devices, readings of various meters, gas detection devices, etc.) and the access mode of the transmitted data (single access or high-concurrency access) in actual operation. Through parallel scheduling optimization, the data security authentication subprocess is optimized, which meets the security requirements of substation inspection business and is an efficient network communication technology.

[0012] The further optimized solution is that step three includes the following sub-steps:

[0013] Obtain the access mode for transmitted data;

[0014] In the single access mode for data transmission, the scheduling process is initiated by optimizing the downlink subprocess, the original data security authentication subprocess, and the original uplink subprocess to achieve secure access to the gateway's network access.

[0015] In the high-concurrency access mode for data transmission, a optimized subprocess is used to enable secure access to the gateway's network.

[0016] When data transmission is normally accessed, only the downlink subprocess can be optimized, and the optimized downlink subprocess, the original data security authentication subprocess, and the original uplink subprocess can be used to start the scheduling process.

[0017] In scenarios involving high-concurrency data transmission, it is necessary to optimize the downlink subprocess, the data security authentication subprocess, and the uplink subprocess. The optimized subprocesses will then start the scheduling process to enable secure network access to the gateway.

[0018] Substation inspection focuses on primary equipment within the station, including transformers, disconnectors, circuit breakers, instrument transformers, surge arresters, busbars, capacitors, and reactors. The primary objective is to promptly identify equipment defects to prevent further deterioration. Inspection tasks include meter reading, status indicator signal identification, equipment discharge and temperature detection, transformer oil level reading, equipment operating noise identification, equipment appearance inspection, disconnector and disconnector position detection, and ambient temperature and humidity monitoring. Robots replacing manual inspections should possess the basic functions of human inspectors, enabling precise "observation, listening, questioning, and diagnosis" of equipment. This means that inspection robots are equipped with monitoring terminals for various project types and modes. The robot summarizes and organizes the collected information, displays corresponding alarms based on set alarm levels, and conveniently uploads the information to the upper-level platform via a gateway.

[0019] Inspection robots operate in two pre-defined modes during daily work: training mode and return-to-home mode. Besides these two modes, other inspection methods can be configured as needed, such as single-item inspection mode or multi-item inspection mode; however, these hidden functions are used less frequently and are usually overlooked. In this solution, the data access mode can be determined based on these two operating modes of the inspection robot, and the optimized sub-processes are rationally invoked to start the scheduling process according to the robot's operating mode.

[0020] After starting the inspection robot, set the working mode of the inspection robot (single-item detection mode or multi-item detection mode). The working mode of the inspection robot will trigger the access mode of the security access gateway, which is either single access mode or high-concurrency access mode.

[0021] For example, when a substation needs to conduct a separate inspection of a certain project A, it is set to a single project inspection mode. The data that the security access gateway needs to transmit is mainly the inspection data of project A. The security access gateway transmits data in a single access mode. At this time, it will not affect the hardware and software resources and computing efficiency of the communication system in the authentication, encryption and other processes. The network access of the security access gateway can be realized by simply using the optimized downlink subprocess to filter and preprocess the inspection data. This avoids a lot of optimization calculations in the scheduling process and saves network resources and economic costs.

[0022] When inspection robots perform full-item or multi-item inspections, the monitoring terminals for various items are widely distributed, with multiple data modes and high concurrency opportunities. Under high concurrency, the hardware and software resources and computing efficiency of the communication system in authentication, encryption, and other processes will be affected. In the authentication process under high concurrency, there will be queuing for encryption or decryption. The main station service for network access places strict requirements on the reliability, scalability, and real-time performance of the communication system. At this time, it is necessary to optimize the downlink subprocess, data security authentication subprocess, and uplink subprocess. The optimized subprocess starts the scheduling process to achieve secure access to the gateway network access, and meets the network communication technology that matches the security requirements of substation inspection services and is efficient.

[0023] This solution offers a novel technical concept: selectively optimizing the scheduling of subprocesses within the data transmission source access mode to address both single-access data mode and high-concurrency access data mode.

[0024] Further optimization measures include the following methods for optimizing the uplink subprocess:

[0025] Obtain information about the data acquisition device for transmitting data;

[0026] The reported data queue is prioritized according to the warning level of the data acquisition device: the higher the warning level of the data acquisition device, the lower the priority of the transmitted data of the corresponding data acquisition device in the reported data queue.

[0027] A further optimized solution is to classify the early warning levels of the data acquisition equipment using the following methods:

[0028] Acquire the alarm sensitivity of the acquisition device corresponding to the transmitted data, and the real-time alarm subprocess of the scheduling process;

[0029] The warning levels of the data acquisition equipment are determined based on the following conditions:

[0030] a. Determine whether there is alarm information in the real-time alarm subprocess: the alarm level of the acquisition device with alarm information is higher than that of the acquisition device without alarm information; the real-time alarm subprocess stores a variety of alarm information. When the acquisition device with its own alarm system alarms, the alarm of the acquisition device itself is compared with the alarm information stored in the real-time alarm subprocess and then transmitted to the network, so that the maintenance personnel at the control end can grasp the situation on site in a timely manner.

[0031] b. The higher the alarm sensitivity of the data acquisition device, the higher its warning level.

[0032] Data with higher priority is reported first; for some important and emergency equipment in the substation, there is an independent real-time alarm subprocess configured in the dispatch process. Therefore, when the corresponding transmitted data is reported through the uplink subprocess, its priority can be lower, and other data without real-time alarm subprocesses can be reported first to save network resources; for data acquisition equipment without its own alarm system, its alarm sensitivity is zero.

[0033] The aforementioned data acquisition equipment refers to the inspection data acquisition equipment mounted on the inspection robot. Direct data acquisition equipment within substations can also be used to determine the warning level of the data acquisition equipment; the higher the alarm sensitivity of the direct data acquisition equipment, the higher its corresponding warning level. For example:

[0034] Item 1: The direct reading device for transformer oil level will immediately activate the alarm when the transformer oil level exceeds the preset oil level A. At the same time, the inspection and data acquisition device will also immediately activate the alarm when it detects that the transformer oil level exceeds the preset oil level B.

[0035] Item 2 of the inspection: There is no direct reading device for ambient gas detection in the substation, but the inspection and data acquisition device will immediately activate the alarm after detecting abnormal gas.

[0036] For test item 3, the open position status of the device's disconnector or circuit breaker is reflected in the real-time alarm subprocess. When its status is abnormal, the security access gateway will directly trigger the alarm mechanism.

[0037] Thus, the warning level of transformer oil level detection item 1 is higher than that of ambient gas detection item 2, and the transmission data corresponding to transformer oil level detection is ranked with lower priority in the reporting data queue.

[0038] The warning level of item 3 for the open position status detection of the disconnector or circuit breaker of the equipment is higher than that of item 1 and item 2. The lower the priority of the transmitted data corresponding to the open position status detection of the disconnector or circuit breaker of the equipment in the reporting data queue.

[0039] Further optimization measures include the following methods for optimizing the downlink subprocess:

[0040] Acquire transmitted data;

[0041] The analysis determines whether the physical changes in the transmitted data are linear or random.

[0042] Filtering is performed on the transmitted data that exhibits linear and random variations respectively:

[0043] For transmitted data that changes randomly, the current sampled data is compared with the previous sampled data. If it is within the allowable deviation range, the current sampled data is considered valid; such as slowly changing data like temperature and humidity.

[0044] For linearly varying transmitted data, samples are taken N times consecutively (N being an odd number). The N sampled values ​​are then arranged in ascending order, and the median value is taken as the valid value for this test. This method can effectively overcome single-pulse interference caused by accidental factors, especially for data with abrupt changes in current or voltage.

[0045] A further optimized solution is to use the following filtering method for continuously increasing transmitted data: Set up a queue with a total data volume of N. Place the collected transmitted data at the end of the queue, delete the data at the head of the queue, and then take the arithmetic mean of the N data points in the queue as the valid value for that data period. For continuously increasing data such as electrical energy data, this method can effectively mitigate periodic interference.

[0046] With the increasing performance of embedded devices, simple data can be processed entirely in the downlink subprocess, enabling real-time data processing and analysis. This brings data processing closer to the source, rather than an external data center or cloud, reducing latency. It also reduces network traffic and alleviates the pressure on the central server. In the downlink subprocess, data processing primarily involves filtering the collected data, removing invalid or obviously erroneous data. This significantly reduces the burden on the platform when processing data aggregation, classification, and report generation.

[0047] A further optimization scheme is that the multi-path parallel scheduling optimization process includes:

[0048] T1, invokes n parallel modules of the SM2 algorithm in the data security authentication subprocess;

[0049] T2: Poll the parallel modules from 0 to n to see if they are idle. If an idle parallel module i exists, proceed to T3; otherwise, continue executing T2; i=0,1,2,…,n;

[0050] T3 loads the task and control commands into the corresponding RAM according to the address of the idle parallel module i;

[0051] At T4, the idle parallel module i reads its own task and control command from RAM. If the control command is "start", it means that the task has been configured and the calculation begins; otherwise, it jumps to T3 to continue waiting.

[0052] T5, when the idle parallel module i completes the calculation, write the address, completion flag and calculation result into the i-th FIFO;

[0053] T6 polls all FIFOs from 0 to n. If the completion flag is 1, the polling results are aggregated into the final FIFO and reported.

[0054] A further optimization scheme is to execute steps T2-T6 in parallel and transmit data through asynchronous RAM or FIFO.

[0055] This solution also provides a network access system for a secure access gateway, used to implement the network access method for the secure access gateway described above, wherein the secure access gateway operates under conditions of high-concurrency data transmission; the system includes:

[0056] The acquisition module is used to acquire the source and access mode of the transmitted data, the scheduling process and its sub-processes during the data transmission process of the secure access gateway; the sub-processes include: uplink sub-process, downlink sub-process and data security authentication sub-process;

[0057] The optimization module is used to optimize each subprocess individually.

[0058] In the downlink subprocess, the transmitted data is filtered and preprocessed; in the data security authentication subprocess, the authentication algorithm is optimized through multi-path parallel scheduling; in the uplink subprocess, the reporting data queue is prioritized according to the source of the transmitted data.

[0059] The startup module is used to associate the access mode of data transmission, start the scheduling process with the optimized subprocess, and realize secure access to the network gateway.

[0060] This solution also provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, can implement a network access method for a secure access gateway as described above.

[0061] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0062] This invention provides a network access method, system, and readable medium for a secure access gateway. By considering the source of the transmitted data (the data acquisition devices on the inspection robot corresponding to the transmitted data, such as temperature acquisition devices, readings of various meters, gas detection devices, etc.) and the access mode of the transmitted data (single access or high-concurrency access) in actual operation, the scheduling process of the secure access gateway during data transmission is optimized. Through parallel scheduling optimization, the data security authentication subprocess is optimized, which meets the security requirements of substation inspection business and is an efficient network communication technology. Attached Figure Description

[0063] To more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be considered as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort. In the drawings:

[0064] Figure 1 A schematic diagram of the network access method for secure access gateways;

[0065] Figure 2 A schematic diagram of the network access process for secure access to the gateway during substation inspection;

[0066] Figure 3 Security topology deployment diagram for secure access gateway;

[0067] Figure 4 A diagram showing the scheduling process during data transmission at the secure access gateway. Detailed Implementation

[0068] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of this invention are only for explaining this invention and are not intended to limit this invention.

[0069] Inspection robots and other terminal equipment operate within substation sites. Each inspection robot runs multiple services, transmitting data detected during its inspections to a server. Due to the multiple internal services, ensuring the security of data transmission for each service is crucial. The secure access gateway employs SSAL, Chinese national cryptographic standard SS1, or IPsec security technologies, providing strong authentication for terminals based on digital certificates and other methods. It also enables terminals to authenticate their identity with the secure access gateway, achieving bidirectional peer-to-peer authentication and providing secure transmission services for business operations.

[0070] Terminal security authentication technology is closely integrated with the business application requirements and robot centralized control within the intranet. Different security level authentication technologies are selected based on the security level requirements of different business applications. Meanwhile, due to the wide distribution, large number, and high concurrency of various terminals, the main station's services place stringent requirements on the communication system in terms of reliability, scalability, and real-time performance.

[0071] In view of this, the present solution provides the following embodiments to address the above problems:

[0072] In this embodiment, the gateway edge agent is deployed separately as a security module to meet the multi-service (multi-type data monitoring) application scenarios of the inspection robot, and its deployment topology is as follows: Figure 3 As shown: a security access gateway is deployed at the substation aggregation switch; a security module is deployed at the aggregation point of all service exits in the inspection robot, and the inspection robot communicates wirelessly with the security access gateway; the security module contains information on the data collection equipment (services) and the working mode of the inspection robot.

[0073] like Figure 4 As shown, the network access process of the secure access gateway is as follows: Transmitted data enters the data storage subprocess through the downlink process, is encrypted and authenticated by the data security authentication subprocess, and then is transmitted to the network through the uplink subprocess. The scheduling process is the main process. The uplink subprocess, downlink subprocess, data storage subprocess, encryption subprocess (data security authentication subprocess), and operation and maintenance subprocess are all created by the scheduling process according to the configuration. There are 1 to N uplink and downlink subprocesses. Uplink subprocesses are created according to the port of the reporting server used, one port, one uplink subprocess; downlink subprocesses are created according to the port of the gateway used and the port of the downlink SOCKET used, one port, one downlink subprocess; there are 0 to 1 operation and maintenance processes, which are only created when configured for use.

[0074] Example 1: This example provides a network access method for a secure access gateway, such as... Figure 1 As shown, the method includes the following steps:

[0075] Step 1: Obtain the source and access mode of the transmitted data, the scheduling process and its sub-processes during the data transmission process of the secure access gateway; the sub-processes include: uplink sub-process, downlink sub-process, and data security authentication sub-process; the access mode of the transmitted data includes single access mode and high-concurrency access mode.

[0076] Step two, optimize each child process individually:

[0077] In the downlink subprocess, the transmitted data is filtered and preprocessed; in the data security authentication subprocess, the authentication algorithm is optimized through multi-path parallel scheduling; in the uplink subprocess, the reporting data queue is prioritized and reorganized based on the source of the transmitted data.

[0078] Methods for optimizing uplink child processes include:

[0079] Obtain information about the data acquisition device for transmitting data;

[0080] The reported data queue is prioritized according to the warning level of the data acquisition device: the higher the warning level of the data acquisition device, the lower the priority of the transmitted data of the corresponding data acquisition device in the reported data queue.

[0081] The methods for classifying the early warning levels of data acquisition equipment include:

[0082] Acquire the alarm sensitivity of the acquisition device corresponding to the transmitted data, and the real-time alarm subprocess of the scheduling process;

[0083] The warning levels of the data acquisition equipment are determined based on the following conditions:

[0084] a. Determine whether there is alarm information in the real-time alarm subprocess when transmitting data: the alarm level of the data acquisition device with alarm information is higher than that of the data acquisition device without alarm information;

[0085] b. The higher the alarm sensitivity of the data acquisition device, the higher its warning level.

[0086] The aforementioned data acquisition equipment refers to the inspection data acquisition equipment mounted on the inspection robot. Direct data acquisition equipment within substations can also be used to determine the warning level of the data acquisition equipment; the higher the alarm sensitivity of the direct data acquisition equipment, the higher its corresponding warning level. For example:

[0087] Item 1: The direct reading device for transformer oil level will immediately activate the alarm when the transformer oil level exceeds the preset oil level A. At the same time, the inspection and data acquisition device will also immediately activate the alarm when it detects that the transformer oil level exceeds the preset oil level B.

[0088] Item 2 of the inspection: There is no direct reading device for ambient gas detection in the substation, but the inspection and data acquisition device will immediately activate the alarm after detecting abnormal gas.

[0089] For test item 3, the open position status of the device's disconnector or circuit breaker is reflected in the real-time alarm subprocess. When its status is abnormal, the security access gateway will directly trigger the alarm mechanism.

[0090] Thus, the warning level of transformer oil level detection item 1 is higher than that of ambient gas detection item 2, and the transmission data corresponding to transformer oil level detection is ranked with lower priority in the reporting data queue.

[0091] The warning level of item 3 for the open position status detection of the disconnector or circuit breaker of the equipment is higher than that of item 1 and item 2. The lower the priority of the transmitted data corresponding to the open position status detection of the disconnector or circuit breaker of the equipment in the reporting data queue.

[0092] Different detection items are prioritized according to their warning level and alarm information in the real-time alarm subprocess, and the data queue is arranged accordingly. This facilitates timely reporting of abnormal data for items with imperfect alarm systems, and ensures the safe operation of substations from multiple perspectives.

[0093] Methods for optimizing downlink subprocesses include:

[0094] Acquire transmitted data;

[0095] The analysis determines whether the physical changes in the transmitted data are linear or random.

[0096] Filtering is performed on the transmitted data that exhibits linear and random variations respectively:

[0097] For transmitted data that changes randomly, the current sampled data is compared with the previous sampled data. If it is within the allowable deviation range, the current sampled data is considered valid; such as slowly changing data like temperature and humidity.

[0098] For linearly varying transmitted data, samples are taken N times consecutively (N being an odd number). The N sampled values ​​are then arranged in ascending order, and the median value is taken as the valid value for this test. This method can effectively overcome single-pulse interference caused by accidental factors, especially for data with abrupt changes in current or voltage.

[0099] The filtering method for continuously increasing transmitted data is as follows: Set up a queue with a total data volume of N. Place the collected transmitted data at the end of the queue and delete the data at the head of the queue. Then, take the arithmetic mean of the N data points in the queue as the valid value for that data period. For continuously increasing data such as electrical energy data, this method can be effective against periodic interference.

[0100] With the increasing performance of embedded devices, simple data can be processed entirely in the downlink subprocess, enabling real-time data processing and analysis. This brings data processing closer to the source, rather than an external data center or cloud, reducing latency. It also reduces network traffic and alleviates the pressure on the central server. In the downlink subprocess, data processing primarily involves filtering the collected data, removing invalid or obviously erroneous data. This significantly reduces the burden on the platform when processing data aggregation, classification, and report generation.

[0101] The multi-path parallel scheduling optimization process includes:

[0102] T1, invokes n parallel modules of the SM2 algorithm in the data security authentication subprocess;

[0103] T2: Poll the parallel modules from 0 to n to see if they are idle. If an idle parallel module i exists, proceed to T3; otherwise, continue executing T2; i=0,1,2,…,n;

[0104] T3 loads the task and control commands into the corresponding RAM according to the address of the idle parallel module i;

[0105] At T4, the idle parallel module i reads its own task and control command from RAM. If the control command is "start", it means that the task has been configured and the calculation begins; otherwise, it jumps to T3 to continue waiting.

[0106] T5, when the idle parallel module i completes the calculation, write the address, completion flag and calculation result into the i-th FIFO;

[0107] T6 polls all FIFOs from 0 to n. If the completion flag is 1, the polling results are aggregated into the final FIFO and reported.

[0108] Steps T2-T6 are executed in parallel, and data is transmitted via asynchronous RAM or FIFO.

[0109] The secure access gateway implements national commercial cryptographic algorithms such as SM1, SM2, SM3, and SM4. All encryption and decryption operations on transmitted data are performed within the data security authentication subprocess, ensuring the security of the algorithms and keys. To further accelerate SM2 computation, this embodiment instantiates multiple parallel modules on the FPGA. Each parallel module is independent and managed by an upper-layer state machine, thereby achieving parallel processing of multiple tasks and improving scalability. This embodiment distributes tasks based on a greedy strategy. When computation is complete, arbitration is performed, and the corresponding result is reported using the address as an identifier.

[0110] Step 3 involves associating the access mode for data transmission and starting the scheduling process with the optimized sub-process to achieve secure network access to the gateway. Step 3 includes the following sub-steps:

[0111] Determine the access mode for transmitted data;

[0112] In the single access mode for data transmission, the scheduling process is initiated by the optimized downlink subprocess, the original data security authentication subprocess, and the original uplink subprocess to achieve secure access to the gateway's network access.

[0113] In the high-concurrency access mode for data transmission, a optimized subprocess is used to enable secure access to the gateway's network.

[0114] The access mode for data transmission can be determined based on the working mode of the inspection robot. The optimized subprocess is called to start the scheduling process according to the working mode of the inspection robot. For example, when a certain parameter needs to be inspected separately in a substation, the inspection robot will work in a single monitoring mode. The data that the security access gateway needs to transmit is a non-high-concurrency access situation. In this case, it will not affect the hardware and software resources and computing efficiency of the communication system in authentication, encryption, etc. It is only necessary to use the optimized downlink subprocess to realize the network access of the security access gateway. This avoids a lot of optimization calculations in the scheduling process, saving network resources and economic costs.

[0115] Substation inspection focuses on primary equipment within the station, including transformers, disconnectors, circuit breakers, instrument transformers, surge arresters, busbars, capacitors, and reactors. The primary objective is to promptly identify equipment defects to prevent further deterioration. Inspection tasks include meter reading, status indicator signal identification, equipment discharge and temperature detection, transformer oil level reading, equipment operating noise identification, equipment appearance inspection, disconnector and disconnector position detection, and ambient temperature and humidity monitoring. Robots replacing manual inspections should possess the basic functions of human inspectors, enabling precise "observation, listening, questioning, and diagnosis" of equipment. This means that inspection robots are equipped with monitoring terminals for various project types and modes. The robot summarizes and organizes the collected information, displays corresponding alarms based on set alarm levels, and conveniently uploads the information to the upper-level platform via a gateway.

[0116] The inspection robot operates in two pre-defined modes during daily work: training mode and return-to-home mode. Besides these two modes, the robot can also be configured with other inspection methods as needed, such as single-item inspection mode or multi-item inspection mode; however, these hidden functions are used less frequently and are usually overlooked. In this embodiment, the data access mode can be determined based on the robot's two operating modes, and the optimized sub-process is rationally invoked to start the scheduling process according to the robot's operating mode.

[0117] After starting the inspection robot, set the working mode of the inspection robot (single-item detection mode or multi-item detection mode). The working mode of the inspection robot will trigger the access mode of the security access gateway, which is either single access mode or high-concurrency access mode.

[0118] For example, such as Figure 2As shown, when a substation needs to conduct a separate inspection of a certain project A, it is set to a single project detection mode. The data that the security access gateway needs to transmit is mainly the detection data of project A. The security access gateway transmits data in a single access mode. At this time, it will not affect the hardware and software resources and computing efficiency of the communication system in the authentication, encryption and other processes. The network access of the security access gateway can be realized by simply using the optimized downlink subprocess to filter and preprocess the detection data. This avoids a lot of optimization calculations in the scheduling process and saves network resources and economic costs.

[0119] When inspection robots perform full-item or multi-item inspections, the monitoring terminals for various items are widely distributed, with multiple data modes and high concurrency opportunities. Under high concurrency, the hardware and software resources and computing efficiency of the communication system in authentication, encryption, and other processes will be affected. In the authentication process under high concurrency, there will be queuing for encryption or decryption. The main station service for network access places strict requirements on the reliability, scalability, and real-time performance of the communication system. At this time, it is necessary to optimize the downlink subprocess, data security authentication subprocess, and uplink subprocess. The optimized subprocess starts the scheduling process to achieve secure access to the gateway network access, and meets the network communication technology that matches the security requirements of substation inspection services and is efficient.

[0120] In the comprehensive inspection mode of the inspection robot, various monitoring terminals are widely distributed, numerous, and have a high chance of concurrency. The main station business of network access places strict requirements on the reliability, scalability, and real-time performance of the communication system. At this time, the scheduling process is started with an optimized subprocess to realize secure access to the gateway network. By optimizing the uplink process, downlink process, and authentication operation scheduling during data transmission, the network communication technology that matches the security requirements of substation inspection business is met and is highly efficient.

[0121] Example 2: This example provides a network access system for a secure access gateway, used to implement the network access method for the secure access gateway described in the previous example. The secure access gateway operates in a high-concurrency data transmission access scenario. The system includes:

[0122] The acquisition module is used to acquire the source and access mode of the transmitted data, the scheduling process and its sub-processes during the data transmission process of the secure access gateway; the sub-processes include: uplink sub-process, downlink sub-process and data security authentication sub-process;

[0123] The optimization module is used to optimize each subprocess individually.

[0124] In the downlink subprocess, the transmitted data is filtered and preprocessed; in the data security authentication subprocess, the authentication algorithm is optimized through multi-path parallel scheduling; in the uplink subprocess, the reporting data queue is prioritized according to the source of the transmitted data.

[0125] The startup module is used to associate the access mode of data transmission, start the scheduling process with the optimized subprocess, and realize secure access to the network gateway.

[0126] Example 3: This example provides a computer-readable medium having a computer program stored thereon. The computer program, when executed by a processor, can implement a network access method for a secure access gateway as described in Example 1.

[0127] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A network access method for a secure access gateway, characterized in that, The method includes the following steps: Step 1: Obtain the source and access mode of the transmitted data, the scheduling process and its sub-processes during the data transmission process of the secure access gateway; the sub-processes include: uplink sub-process, downlink sub-process and data security authentication sub-process; the access mode of the transmitted data includes single access mode and high-concurrency access mode; Step two, optimize each child process individually: In the downlink subprocess, the transmitted data is filtered and preprocessed; in the data security authentication subprocess, the authentication algorithm is optimized through multi-path parallel scheduling; in the uplink subprocess, the reporting data queue is prioritized and reorganized based on the source of the transmitted data. Step 3: Associate the access mode for data transmission, start the scheduling process with the optimized subprocess, and realize secure network access to the gateway.

2. The network access method of a secure access gateway according to claim 1, characterized in that, Step 3 includes the following sub-steps: Determine the access mode for transmitting data: In the single access mode for data transmission, the scheduling process is initiated by the optimized downlink subprocess, the original data security authentication subprocess, and the original uplink subprocess to achieve secure access to the gateway's network access. In the high-concurrency access mode for data transmission, a optimized subprocess is used to enable secure access to the gateway's network.

3. The network access method of a secure access gateway according to claim 1, characterized in that, Methods for optimizing uplink child processes include: Obtain information about the data acquisition device for transmitting data; The reported data queue is prioritized according to the warning level of the data acquisition device: the higher the warning level of the data acquisition device, the lower the priority of the transmitted data of the corresponding data acquisition device in the reported data queue.

4. The network access method of a secure access gateway according to claim 3, characterized in that, The methods for classifying the early warning levels of data acquisition equipment include: Acquire the alarm sensitivity of the acquisition device corresponding to the transmitted data, and the real-time alarm subprocess of the scheduling process; The warning levels of the data acquisition equipment are determined based on the following conditions: a. Determine whether there is alarm information in the real-time alarm subprocess when transmitting data: the alarm level of the data acquisition device with alarm information is higher than that of the data acquisition device without alarm information; b. The higher the alarm sensitivity of the data acquisition device, the higher its warning level.

5. A network access method for a secure access gateway according to claim 1, characterized in that, Methods for optimizing downlink subprocesses include: Acquire transmitted data; The analysis determines whether the physical changes in the transmitted data are linear or random. Filtering is performed on the transmitted data that exhibits linear and random variations respectively: For transmitted data that varies randomly, the current sampled data is compared with the previous sampled data. If it is within the allowable deviation range, the current sampled data is a valid value. For linearly varying transmitted data, samples are taken N times consecutively, where N is an odd number. The N sampled values ​​are then arranged in order of magnitude, and the median value is taken as the valid value for this test.

6. A network access method for a secure access gateway according to claim 5, characterized in that, The filtering method for continuously increasing transmitted data is as follows: Set up a queue with a total of N data points, put the collected transmitted data at the end of the queue, delete the data at the head of the queue, and then take the arithmetic mean of the N data points in the queue as the valid value for this time.

7. A network access method for a secure access gateway according to claim 1, characterized in that, The multi-path parallel scheduling optimization process includes: T1, invokes n parallel modules of the SM2 algorithm in the data security authentication subprocess; T2: Poll the parallel modules from 0 to n to see if they are idle. If an idle parallel module i exists, proceed to T3; otherwise, continue executing T2; i=0,1,2,…,n; T3 loads the task and control commands into the corresponding RAM according to the address of the idle parallel module i; At T4, the idle parallel module i reads its own task and control command from RAM. If the control command is "start", it means that the task has been configured and the calculation begins; otherwise, it jumps to T3 to continue waiting. T5, when the idle parallel module i completes the calculation, write the address, completion flag and calculation result into the i-th FIFO; T6 polls all FIFOs from 0 to n. If the completion flag is 1, the polling results are aggregated into the final FIFO and reported.

8. A network access method for a secure access gateway according to claim 7, characterized in that, Steps T2-T6 are executed in parallel, and data is transmitted via asynchronous RAM or FIFO.

9. A network access system with a secure access gateway, characterized in that, The network access method for implementing the secure access gateway according to any one of claims 1-8, wherein the secure access gateway operates in a situation of high-concurrency access for data transmission; The system includes: The acquisition module is used to acquire the source and access mode of the transmitted data, the scheduling process and its sub-processes during the data transmission process of the secure access gateway; the sub-processes include: uplink sub-process, downlink sub-process and data security authentication sub-process; The optimization module is used to optimize each subprocess individually. In the downlink subprocess, the transmitted data is filtered and preprocessed; in the data security authentication subprocess, the authentication algorithm is optimized through multi-path parallel scheduling; in the uplink subprocess, the reporting data queue is prioritized according to the source of the transmitted data. The startup module is used to associate the access mode of data transmission, start the scheduling process with the optimized subprocess, and realize secure access to the network gateway.

10. A computer-readable medium having a computer program stored thereon, characterized in that, The computer program, when executed by a processor, can implement a network access method for a secure access gateway as described in any one of claims 1-7.