A data transmission method and device, a power distribution master station and a power distribution terminal
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE SHANGHAI ICT CO LTD
- Filing Date
- 2022-03-24
- Publication Date
- 2026-08-07
AI Technical Summary
[0005]本发明的目的是提供一种数据传输方法、装置、配电主站及配电终端,解决了现有技术中电力终端数据如何通过无线网络穿越安全接入区目前没有解决方案的问题
[0054] The method of this invention establishes a Virtual Private Network (VPN) tunnel between the power distribution master station and the power distribution terminal by configuring a firewall within the secure access zone. The VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the substation side is configured with the second IP address range. This enables the sending of encrypted first interactive data to the power distribution terminal and/or the receiving of encrypted second interactive data from the power distribution terminal via the VPN tunnel. Thus, the VPN tunnel allows power terminal data to traverse the secure access zone via a wireless network, improving the data transmission efficiency within the secure access zone.
Smart Images

Figure CN116846569B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a data transmission method, apparatus, power distribution master station and power distribution terminal. Background Technology
[0002] In order to prevent attacks on power secondary systems by hackers and malicious code and the resulting power system accidents, it is necessary to establish a security protection system for power secondary systems and ensure the safe and stable operation of power systems. This requires strengthening the construction, deployment and testing of power system secondary security protection equipment.
[0003] The general principle of power monitoring system security protection is "security zoning, dedicated network, horizontal isolation, and vertical authentication". By using measures such as network zoning, vertical encryption, and horizontal isolation, information security is ensured. Therefore, it is particularly important to know how power terminal data can achieve two-way interaction with the monitoring system master station through the secure access zone.
[0004] Currently, in the construction of secondary security protection systems for power systems, power terminals generally use wired networks for transmission. There is currently no solution for how power terminal data can traverse secure access zones via wireless networks. Summary of the Invention
[0005] The purpose of this invention is to provide a data transmission method, device, power distribution master station, and power distribution terminal, which solves the problem that there is currently no solution for how power terminal data can cross the secure access zone through a wireless network in the prior art.
[0006] In a first aspect, embodiments of the present invention provide a data transmission method applied to a distribution master station on the master station side, comprising:
[0007] A virtual private network (VPN) tunnel is established between the power distribution master station and the power distribution terminal by configuring a firewall in the secure access zone; wherein, the VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range; the firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range, and the LAN port of the wireless router on the plant side is configured to the second IP address range; through the VPN tunnel, encrypted first interactive data is sent to the power distribution terminal, and / or encrypted second interactive data is received from the power distribution terminal.
[0008] Optionally, the VPN tunnel is established between the first vertical encryption device and the second vertical encryption device;
[0009] The first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the LAN port of the wireless router.
[0010] Optionally, after establishing a Virtual Private Network (VPN) tunnel between the power distribution master station and the power distribution terminal through a firewall configured in the secure access zone, the above method further includes:
[0011] The firewall receives a login request carrying security parameters sent by the second vertical encryption device through a wireless router.
[0012] The firewall verifies the security parameters, and upon successful verification, establishes a VPN tunnel between the first vertical encryption device and the second vertical encryption device.
[0013] Optionally, after receiving the encrypted second interactive data sent by the power distribution terminal through the VPN tunnel, the method further includes:
[0014] The encrypted second interactive data is decrypted using the first vertical encryption device to obtain the second interactive data.
[0015] The second interactive data is converted into text format by the first communication server and stored in the upstream file directory of the first communication server;
[0016] The second interactive data in text format is obtained from the upstream file directory through the reverse isolation device, and the second interactive data in text format is transmitted to the upstream file directory of the second communication server.
[0017] The second communication server retrieves the second interactive data in text format, unpacks it into a message in 104 protocol format, puts it into the uplink file buffer, and sends the message to the power distribution master station in the production control area via a TCP connection.
[0018] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0019] Optionally, before sending the encrypted first interactive data to the power distribution terminal through the VPN tunnel, the method further includes:
[0020] The second communication server receives the first interactive data sent by the power distribution master station.
[0021] The first interactive data is converted into text format by the second communication server and stored in the downstream file directory of the second communication server;
[0022] The first interactive data in text format is obtained from the downlink file directory through the forward isolation device, and the first interactive data in text format is transmitted to the downlink file directory of the first communication server.
[0023] The first communication server retrieves the first interactive data in text format, unpacks it into a message in 104 protocol format, places it in the uplink file buffer, and sends the message to the first vertical encryption device via TCP connection for encryption processing to obtain the encrypted first interactive data.
[0024] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0025] Secondly, embodiments of the present invention provide a data transmission method applied to a power distribution terminal on the substation side, comprising:
[0026] By establishing a VPN tunnel between the power distribution master station and the power distribution terminal, the system receives encrypted first interactive data sent by the power distribution master station and / or sends encrypted second interactive data to the power distribution master station.
[0027] The VPN tunnel is established through a firewall configured in the secure access zone and is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured to the second IP address range.
[0028] Optionally, the VPN tunnel is established between the first vertical encryption device and the second vertical encryption device;
[0029] The first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the wireless router.
[0030] Optionally, before receiving encrypted first interactive data sent by the distribution master station through a VPN tunnel established between the distribution master station and the distribution terminal, and / or sending encrypted second interactive data to the distribution master station, the method further includes:
[0031] The second vertical encryption device sends a login request carrying security parameters to the firewall on the main site side via a wireless router; wherein, after the security parameters are verified, a VPN tunnel is established between the first vertical encryption device and the second vertical encryption device through the firewall.
[0032] Optionally, after receiving the encrypted first interactive data sent by the power distribution master station through the VPN tunnel, the method further includes:
[0033] The encrypted first interactive data file is decrypted using the second vertical encryption device.
[0034] The decrypted first interactive data is packaged according to the protocol used by the power distribution terminal using the terminal data acquisition device, and then the first interactive data is sent to the power distribution terminal.
[0035] Optionally, before sending the encrypted second interactive data to the distribution master station via a VPN tunnel established between the distribution master station and the distribution terminal, the method further includes:
[0036] The terminal data acquisition device packages the second interactive data to be sent according to the standard 104 protocol and then sends it to the second vertical encryption device.
[0037] The second interactive data is encrypted by the second vertical encryption device to obtain the encrypted second interactive data.
[0038] Thirdly, embodiments of the present invention provide a data transmission device applied to a power distribution master station on the master station side, comprising:
[0039] A virtual private network (VPN) tunnel is established between the power distribution master station and the power distribution terminal by configuring a firewall in the secure access zone; wherein, the VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range; the firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range;
[0040] Through the VPN tunnel, encrypted first interactive data is sent to the power distribution terminal, and / or encrypted second interactive data is received from the power distribution terminal.
[0041] Fourthly, embodiments of the present invention provide a data transmission device applied to a power distribution terminal on the substation side, comprising:
[0042] By establishing a VPN tunnel between the power distribution master station and the power distribution terminal, the system receives encrypted first interactive data sent by the power distribution master station and / or sends encrypted second interactive data to the power distribution master station.
[0043] The VPN tunnel is established through a firewall configured in the secure access zone and is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured to the second IP address range.
[0044] Fifthly, embodiments of the present invention provide a power distribution master station, comprising: a transceiver and a processor; wherein the processor is configured to perform the following processes:
[0045] A virtual private network (VPN) tunnel is established between the power distribution master station on the master station side and the power distribution terminal on the plant side by configuring a firewall in the secure access zone; wherein, the VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range; the firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range; the LAN port of the wireless router on the plant side is configured to the second IP address range;
[0046] Through the VPN tunnel, encrypted first interactive data is sent to the power distribution terminal, and / or encrypted second interactive data is received from the power distribution terminal.
[0047] Sixthly, embodiments of the present invention provide a power distribution terminal, including: a transceiver and a processor; wherein the processor is configured to perform the following processes:
[0048] By establishing a VPN tunnel between the power distribution master station on the master station side and the power distribution terminal on the substation side, the system receives encrypted first interactive data sent by the power distribution master station and / or sends encrypted second interactive data to the power distribution master station.
[0049] The VPN tunnel is established through a firewall configured in the secure access zone and is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured to the second IP address range.
[0050] In a seventh aspect, embodiments of the present invention provide a power distribution master station, comprising: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor, when executing the program or instructions, implements the data transmission method as described in the first aspect.
[0051] Eighthly, embodiments of the present invention provide a power distribution terminal, comprising: a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor executes the program or instructions to implement the data transmission method as described in the second aspect.
[0052] In a ninth aspect, embodiments of the present invention provide a readable storage medium having a program or instructions stored thereon, which, when executed by a processor, implement the steps of the data transmission method as described in the first or second aspect.
[0053] The beneficial effects of the above-described technical solution of the present invention are as follows:
[0054] The method of this invention establishes a Virtual Private Network (VPN) tunnel between the power distribution master station and the power distribution terminal by configuring a firewall within the secure access zone. The VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the substation side is configured with the second IP address range. This enables the sending of encrypted first interactive data to the power distribution terminal and / or the receiving of encrypted second interactive data from the power distribution terminal via the VPN tunnel. Thus, the VPN tunnel allows power terminal data to traverse the secure access zone via a wireless network, improving the data transmission efficiency within the secure access zone. Attached Figure Description
[0055] Figure 1 This is one of the flowcharts of the data transmission method according to an embodiment of the present invention;
[0056] Figure 2 This is one of the communication architecture diagrams of an embodiment of the present invention;
[0057] Figure 3 This is a second schematic diagram of the communication architecture according to an embodiment of the present invention;
[0058] Figure 4 This is a second flowchart of the data transmission method according to an embodiment of the present invention;
[0059] Figure 5 This is the third flowchart of the data transmission method according to an embodiment of the present invention;
[0060] Figure 6This is the fourth flowchart of the data transmission method according to an embodiment of the present invention;
[0061] Figure 7 This is one of the structural diagrams of the data transmission device according to an embodiment of the present invention;
[0062] Figure 8 This is a structural diagram of a data transmission device according to another embodiment of the present invention;
[0063] Figure 9 This is a structural diagram of the power distribution master station according to an embodiment of the present invention;
[0064] Figure 10 This is a structural diagram of the power distribution terminal according to an embodiment of the present invention;
[0065] Figure 11 This is a structural diagram of a power distribution master station according to another embodiment of the present invention;
[0066] Figure 12 This is a structural diagram of a power distribution terminal according to another embodiment of the present invention. Detailed Implementation
[0067] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0068] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0069] In various embodiments of the present invention, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0070] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0071] like Figure 1 As shown, an embodiment of the present invention provides a data transmission method applied to a distribution master station on the master station side, comprising:
[0072] Step 101: Establish a Virtual Private Network (VPN) tunnel between the power distribution master station and the power distribution terminal on the substation side by configuring a firewall in the secure access zone; wherein, the VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range; the firewall port is mapped to a fixed IP address on the public network, and the fixed IP address belongs to the first IP address range, and the LAN port of the wireless router on the substation side is configured to the second IP address range;
[0073] It should be noted that the main station side refers to the side where the main distribution station is located, while the substation side refers to the side where the distribution terminals are located. Figure 3 In the process, the main station side includes the production control area and the security access area, while the power distribution main station side includes: power distribution terminal, wireless router, second vertical encryption device and terminal data acquisition terminal.
[0074] In this step, the VPN tunnel is used for bidirectional communication between the first IP address range and the second IP address range, so that as long as they are within these two address ranges, they can access each other through the VPN server.
[0075] Step 102: Send encrypted first interactive data to the power distribution terminal through the VPN tunnel, and / or receive encrypted second interactive data sent by the power distribution terminal.
[0076] It should be noted that since the location of power distribution terminals is often exposed in the outdoor public environment, in order to ensure the security of interactive data, it is necessary to encrypt the interactive data before transmitting it wirelessly. However, if the encrypted data is directly connected to the wireless router, the router will assign it a secondary IP address, and the plant side (the side where the power distribution terminal is located) and the master station side (the side where the power distribution master station is located) cannot directly communicate with each other. Therefore, the encrypted interactive data cannot be directly transmitted through the wireless network, and the network structure needs to be improved.
[0077] In the above embodiments, the public network access router at the power distribution master station maps the firewall port to a fixed IP address on the public network. In addition to normal policies, the firewall enables VPN service and acts as a VPN server. The wireless router on the plant side is configured as a VPN client and performs VPN tunneling to the devices below, so that the power distribution master station and the power distribution terminal can communicate using the IP address in the VPN tunnel, realize mutual access at the same layer, and solve the problem that encrypted interactive data cannot directly enter the secure access zone through the wireless network.
[0078] See Figure 2In one embodiment, the VPN tunnel is established between a first vertical encryption device and a second vertical encryption device; wherein, the first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the wireless router.
[0079] In this embodiment, Figure 2 The first vertical encryption device is configured in the secure access zone, and its gateway is set to the first IP address range of the VPN service. The wireless router on the plant side (the gateway of the second vertical encryption device) is configured to dial up and randomly obtain a secondary IP address provided by the operator. The LAN port of the wireless router is configured to be one of the secure network segments (the second IP address range) set by the VPN service, and this second IP address range is used as the gateway for all devices under the plant (on the side where the power distribution terminal is located). In this way, the second vertical encryption device on the plant side can access the network segment configured with the first vertical encryption device on the main site side through the VPN tunnel of the wireless router.
[0080] Furthermore, in one embodiment, after step 101, the method further includes:
[0081] The firewall receives a login request carrying security parameters sent by the second vertical encryption device through a wireless router.
[0082] The firewall verifies the security parameters, and upon successful verification, establishes a VPN tunnel between the first vertical encryption device and the second vertical encryption device.
[0083] Security parameters include, but are not limited to: username, password, protocol type, and security proposal.
[0084] In the above embodiments, after configuring the VPN tunnel, login to the VPN service is only possible after passing security authentication, and data transmission can then be performed through the VPN tunnel. Specifically, the wireless router accesses the public IP address of the VPN service via public network dial-up, and then performs VPN dial-up using the security parameters provided by the VPN service. This allows the wireless router to send a login request to the VPN server based on the security parameters configured in the firewall, perform security authentication, and complete the exchange of encryption certificates.
[0085] See Figure 3 It shows a schematic diagram of the communication architecture between the power distribution master station and the power distribution terminal.
[0086] based on Figure 3The communication architecture shown divides the data transmission process in the secure access zone into two parts: data uplink and data downlink. Data uplink refers to the process of data uploaded by the distribution terminal being transmitted through the secure access zone to the master station system within the production control zone. Data downlink refers to the process of the distribution master station within the production control zone sending control commands to the distribution terminal through the secure access zone. Specifically, the substation side is equipped with a second vertical encryption device to decrypt uplink data and encrypt downlink data; the distribution master station side is equipped with a first vertical encryption device to establish a VPN tunnel between the substation side and the master station side, as well as to decrypt downlink data and encrypt uplink data.
[0087] Furthermore, the distribution terminal includes: a three-remote data acquisition terminal and a two-remote data acquisition terminal. The three-remote data acquisition terminal and the two-remote data acquisition terminal are connected to a terminal data acquisition device. The terminal data acquisition device is used to collect data information from the terminal, establish a communication tunnel with the secure access zone communication server, configure encryption strategies, and encrypt data. Messages from the substation side are converted from plaintext to ciphertext by the second vertical encryption device and transmitted over the wireless data network. The distribution master station is simultaneously configured with a first vertical encryption authentication device to establish a tunnel between the substation (the side where the distribution terminal is located) and the distribution master station, and to decrypt received data. Specifically, based on... Figure 3 The communication architecture shown below will be followed by an introduction to the uplink data processing procedure.
[0088] In one embodiment, after receiving the encrypted second interactive data sent by the power distribution terminal in step 102, the method further includes:
[0089] The encrypted second interactive data is decrypted using the first vertical encryption device to obtain the second interactive data.
[0090] The second interactive data is converted into text format by the first communication server and stored in the upstream file directory of the first communication server;
[0091] The second interactive data in text format is obtained from the upstream file directory through the reverse isolation device, and the second interactive data in text format is transmitted to the upstream file directory of the second communication server.
[0092] The second interactive data in text format is sent to the power distribution master station in the production control area via a TCP connection through the second communication server.
[0093] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0094] In the above embodiments, for uplink data, the encrypted second interactive data uploaded by the plant side through the VPN tunnel is converted from ciphertext to plaintext after being encrypted by the first vertical encryption device; further, it is transmitted to the second communication server through the first communication device and the reverse isolation device. The second communication server retrieves the text-formatted second interactive data from the uplink file directory and puts it into the uplink file buffer, which is then sent to the power distribution master station in the production control area via a TCP connection, thus completing the uplink data transmission process in the secure access area.
[0095] Specifically, based on Figure 3 The communication architecture shown below will be followed by an introduction to the downlink data processing procedure.
[0096] In one embodiment, before sending the encrypted first interactive data to the power distribution terminal through the VPN tunnel in step 102, the method further includes:
[0097] The second communication server receives the first interactive data sent by the power distribution master station.
[0098] The first interactive data is converted into text format by the second communication server and stored in the downstream file directory of the second communication server;
[0099] The first interactive data in text format is obtained from the downlink file directory through the forward isolation device, and the first interactive data in text format is transmitted to the downlink file directory of the first communication server.
[0100] The first interactive data in text format is sent to the first vertical encryption device via a TCP connection through the first communication server for encryption processing, thereby obtaining the encrypted first interactive data.
[0101] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0102] In the above embodiments, for downlink data, the first interactive data sent by the distribution master station reaches the downlink file directory of the first communication server through the second communication server and the forward isolation device. The first communication server puts the text-formatted first interactive data into the file cache area and sends it to the first vertical encryption device through a TCP connection. Further, the first vertical encryption device encrypts the text-formatted first interactive data to obtain encrypted first interactive data. Finally, the encrypted first interactive data is transmitted to the second vertical encryption device on the substation side through a VPN tunnel, completing the downlink data transmission process within the secure access area.
[0103] like Figure 4As shown, this application embodiment provides a data transmission method applied to a power distribution terminal on the substation side, including:
[0104] Step 201: Receive encrypted first interactive data sent by the power distribution master station through a VPN tunnel established between the power distribution master station and the power distribution terminal on the master station side, and / or send encrypted second interactive data to the power distribution master station.
[0105] The VPN tunnel is established through a firewall configured in the secure access zone and is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured to the second IP address range.
[0106] See Figure 2 In one embodiment, the VPN tunnel is established between a first longitudinal encryption device and a second longitudinal encryption device;
[0107] The first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the wireless router.
[0108] In this embodiment, Figure 2 The first vertical encryption device is configured in the secure access zone, and its gateway is set to the first IP address range of the VPN service. The wireless router on the plant side (the gateway of the second vertical encryption device) is configured to dial up and randomly obtain a secondary IP address provided by the operator. The LAN port of the wireless router is configured to be one of the secure network segments (the second IP address range) set up in the VPN service, and this second IP address range is used as the gateway for all devices under the plant (on the side where the power distribution terminal is located). In this way, the second vertical encryption device on the plant side can access the network segment configured with the first vertical encryption device on the main site side through the VPN tunnel of the wireless router.
[0109] In one embodiment, prior to step 201, the method further includes:
[0110] The second vertical encryption device sends a login request carrying security parameters to the firewall on the main site side via a wireless router; wherein, after the security parameters are verified, a VPN tunnel is established between the first vertical encryption device and the second vertical encryption device through the firewall.
[0111] Security parameters include, but are not limited to: username, password, protocol type, and security proposal.
[0112] In the above embodiments, based on the security parameters configured in the firewall, a login request is sent to the VPN server through the wireless router for security authentication, and the encryption certificate is exchanged. After passing the security authentication, the user logs into the VPN service, thereby enabling data transmission through the VPN tunnel.
[0113] It should be noted that the distribution master station of a power monitoring system typically interacts with the distribution terminal via the standard 104 protocol. However, distribution terminal manufacturers support various protocol types, and their encapsulation methods for the 104 protocol differ. To ensure proper data exchange between the distribution master station and the distribution terminal, protocol conversion is required before communication between them. Simultaneously, protocol conversion is also necessary for the received interactive data from the distribution master station.
[0114] The following section introduces the protocol conversion process between downlink and uplink data.
[0115] In one embodiment, for downlink data, after receiving the encrypted first interactive data sent by the distribution master station through the VPN tunnel in step 201, the method further includes:
[0116] The encrypted first interactive data file is decrypted using the second vertical encryption device.
[0117] The decrypted first interactive data is packaged according to the protocol used by the power distribution terminal using the terminal data acquisition device, and then the first interactive data is sent to the power distribution terminal.
[0118] In this embodiment, the second vertical encryption device processes the first interactive data file from ciphertext to plaintext. Furthermore, since the distribution master station sends messages packaged in the standard 104 protocol, it is necessary to obtain the actual protocol and its field descriptions used by the distribution terminal. The first interactive data is then converted into the actual protocol used by the terminal through the terminal data acquisition device before being sent to the distribution terminal, thus enabling the distribution master station to control the distribution terminal.
[0119] In one embodiment, for uplink data, before sending encrypted second interactive data to the distribution master station via a VPN tunnel established between the distribution master station and the distribution terminal, the method further includes:
[0120] The terminal data acquisition device packages the second interactive data to be sent according to the standard 104 protocol and then sends it to the second vertical encryption device.
[0121] The second interactive data is encrypted by the second vertical encryption device to obtain the encrypted second interactive data.
[0122] In this embodiment, in the terminal data acquisition device, the second interactive data is packaged into a standard 104 message according to the standard 104 protocol to complete the protocol conversion of the terminal message; further, the packaged standard message is sent upward to the second vertical encryption device.
[0123] As can be seen from the above embodiments, the main functions of the first communication server include: receiving messages in the standard 104 protocol; converting standard 104 protocol messages to text format files; maintaining the upstream and downstream file directories; maintaining the downstream file buffer; and sending messages from the downstream file buffer to the terminal. The main functions of the second communication server include: receiving messages in the standard 104 protocol; converting 104 protocol messages to text format files; maintaining the upstream and downstream file directories; maintaining the upstream file buffer; and sending messages from the upstream file buffer to the power distribution master station.
[0124] The following is in conjunction with the appendix Figure 5 and 6 The uplink processing procedure and the downlink processing procedure are described separately.
[0125] like Figure 5 As shown, the uplink processing mainly includes the following steps:
[0126] Step 51: The terminal data acquisition device acquires the power data of the power distribution terminal (belonging to the second interactive data);
[0127] Step 52: Encapsulate the power data into a standard 104 protocol message using the terminal data acquisition device;
[0128] Step 53: Encrypt the message using the second encryption device;
[0129] Step 54: The encrypted message is transmitted over the public wireless network through the VPN tunnel;
[0130] Step 55: The encrypted message is accessed through the secure access zone;
[0131] Step 56: Decrypt the message using the first vertical encryption device;
[0132] Step 57: Package the message into text format using the first communication device;
[0133] Step 58: The text-formatted message is transmitted to the power distribution master station through the reverse isolation device and the second communication device.
[0134] like Figure 6As shown, the downlink processing mainly includes the following steps:
[0135] Step 61: The power distribution master station packages the control commands (belonging to the first interactive data) into a message;
[0136] Step 62: The message enters the first communication server through the forward isolation device;
[0137] Step 63: Convert the message into text format through the first communication server;
[0138] Step 64: Encrypt the message using the first vertical encryption device;
[0139] Step 65: The message leaves the secure access zone;
[0140] Step 66: The message is transmitted over the public network via the VPN tunnel to the second vertical encryption device;
[0141] Step 67: Decrypt the message using the second vertical encryption device;
[0142] Step 68: Convert the standard 104 protocol message into a private protocol message using the terminal data acquisition device;
[0143] Step 69: The terminal data acquisition device sends the private protocol message to the power distribution terminal.
[0144] like Figure 7 As shown, this embodiment of the invention provides a data transmission device 700, applied to a power distribution master station on the master station side, comprising:
[0145] The first processing module 701 establishes a virtual private network (VPN) tunnel between the power distribution master station and the power distribution terminal through a firewall configured in the secure access zone; wherein, the VPN tunnel is used for bidirectional communication between a first IP address segment and a second IP address segment; the firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address segment, and the LAN port of the wireless router on the plant side is configured to the second IP address segment;
[0146] The first transceiver module 702 is used to send encrypted first interactive data to the power distribution terminal through the VPN tunnel, and / or receive encrypted second interactive data sent by the power distribution terminal.
[0147] Optionally, the VPN tunnel is established between the first vertical encryption device and the second vertical encryption device;
[0148] The first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the LAN port of the wireless router.
[0149] Optionally, the first processing module 701 includes:
[0150] The first processing submodule is used to receive, through the firewall, a login request carrying security parameters sent by the second vertical encryption device via a wireless router;
[0151] The second processing submodule is used to verify the security parameters through the firewall, and after successful verification, to establish a VPN tunnel between the first vertical encryption device and the second vertical encryption device.
[0152] Optionally, the device 700 also includes:
[0153] The first decryption module is used to decrypt the encrypted second interactive data through the first vertical encryption device to obtain the second interactive data;
[0154] The second processing module is used to convert the second interactive data into text format through the first communication server and store it in the upstream file directory of the first communication server.
[0155] The third processing module is used to obtain the second interactive data in text format from the upstream file directory through the reverse isolation device, and transmit the second interactive data in text format to the upstream file directory of the second communication server.
[0156] The fourth processing module is used to send the second interactive data in text format to the power distribution master station in the production control area via the second communication server using a TCP connection.
[0157] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0158] Optionally, the device 700 also includes:
[0159] The fourth processing module is used to receive the first interactive data sent by the power distribution master station through the second communication server;
[0160] The fifth processing module is used to convert the first interactive data into text format through the second communication server and store it in the downstream file directory of the second communication server;
[0161] The sixth processing module is used to obtain the first interactive data in text format from the downlink file directory through the forward isolation device, and transmit the first interactive data in text format to the downlink file directory of the first communication server.
[0162] The seventh processing module is used to send the first interactive data in text format to the first vertical encryption device via the first communication server through a TCP connection for encryption processing, so as to obtain the encrypted first interactive data.
[0163] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0164] The data processing apparatus 700 provided in this application embodiment can implement the various processes implemented in the method embodiment applied to the main station side. To avoid repetition, it will not be described again here.
[0165] like Figure 8 As shown, this embodiment of the invention provides a data transmission device 800, applied to a power distribution terminal on the substation side, comprising:
[0166] The second transceiver module 801 is used to receive encrypted first interactive data sent by the power distribution master station through a VPN tunnel established between the power distribution master station on the master station side and the power distribution terminal, and / or send encrypted second interactive data to the power distribution master station.
[0167] The VPN tunnel is established through a firewall configured in the secure access zone and is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured to the second IP address range.
[0168] Optionally, the VPN tunnel is established between the first vertical encryption device and the second vertical encryption device;
[0169] The first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the wireless router.
[0170] Optionally, the device 800 further includes:
[0171] The eighth processing module is used to send a login request carrying security parameters to the firewall on the main station side via a wireless router; wherein, after the security parameters are verified, a VPN tunnel is established between the first vertical encryption device and the second vertical encryption device through the firewall.
[0172] Optionally, the device 800 further includes:
[0173] The ninth processing module is used to decrypt the encrypted first interactive data file through the second vertical encryption device;
[0174] The tenth processing module is used to package the decrypted first interactive data according to the protocol used by the power distribution terminal through the terminal data acquisition device, and then send the first interactive data to the power distribution terminal.
[0175] Optionally, the device 800 further includes:
[0176] The eleventh processing module is used to package the second interactive data to be sent according to the standard 104 protocol through the terminal data acquisition device and then send it to the second vertical encryption device.
[0177] The twelfth processing module is used to encrypt the second interactive data using the second vertical encryption device to obtain encrypted second interactive data.
[0178] The data processing apparatus 800 provided in this application embodiment can implement the various processes implemented in the method embodiment applied to the plant side. To avoid repetition, it will not be described again here.
[0179] like Figure 9 As shown, an embodiment of the present invention provides a configuration master station 900, in which an optional power distribution master station is located on the master station side, including a processor 910 and a transceiver 920, wherein the transceiver 920 is used to receive and transmit data under the control of the processor 910; the processor is used to execute the following processes:
[0180] A virtual private network (VPN) tunnel is established between the power distribution master station and the power distribution terminal on the substation side by configuring a firewall in the secure access zone; wherein, the VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range; the firewall port is mapped to a fixed IP address on the public network, and the fixed IP address belongs to the first IP address range, and the LAN port of the wireless router on the substation side is configured to the second IP address range;
[0181] Through the VPN tunnel, encrypted first interactive data is sent to the power distribution terminal, and / or encrypted second interactive data is received from the power distribution terminal.
[0182] Optionally, the VPN tunnel is established between the first vertical encryption device and the second vertical encryption device;
[0183] The first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the wireless router.
[0184] Optionally, the processor 910 is specifically configured to receive, through the firewall, a login request carrying security parameters sent by the second longitudinal encryption device via a wireless router;
[0185] The firewall verifies the security parameters, and upon successful verification, establishes a VPN tunnel between the first vertical encryption device and the second vertical encryption device.
[0186] Optionally, the processor 910 is further configured to perform the following processes:
[0187] The encrypted second interactive data is decrypted using the first vertical encryption device to obtain the second interactive data.
[0188] The second interactive data is converted into text format by the first communication server and stored in the upstream file directory of the first communication server;
[0189] The second interactive data in text format is obtained from the upstream file directory through the reverse isolation device, and the second interactive data in text format is transmitted to the upstream file directory of the second communication server.
[0190] The second interactive data in text format is sent to the power distribution master station in the production control area via a TCP connection through the second communication server.
[0191] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0192] Optionally, the processor 910 is further configured to perform the following processes:
[0193] The second communication server receives the first interactive data sent by the power distribution master station.
[0194] The first interactive data is converted into text format by the second communication server and stored in the downstream file directory of the second communication server;
[0195] The first interactive data in text format is obtained from the downlink file directory through the forward isolation device, and the first interactive data in text format is transmitted to the downlink file directory of the first communication server.
[0196] The first interactive data in text format is sent to the first vertical encryption device via a TCP connection through the first communication server for encryption processing, thereby obtaining the encrypted first interactive data.
[0197] The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
[0198] In the above embodiment, the master station 900 is configured to access the router via the public network and map the firewall port to a fixed IP address on the public network. In addition to normal policies, the firewall enables VPN service as a VPN server. The wireless router on the plant side is configured as a VPN client and performs VPN tunneling to the devices below, so that the power distribution master station and the power distribution terminal can communicate using the IP address in the VPN tunnel, realize mutual access at the same layer, and solve the problem that encrypted interactive data cannot directly enter the secure access area through the wireless network.
[0199] like Figure 10 As shown, this embodiment of the invention provides a power distribution terminal 1000, optionally installed on the substation side, including a processor 1010 and a transceiver 1020. The transceiver 1020 is used to receive and transmit data under the control of the processor 1010; the processor is used to execute the following processes:
[0200] The system receives encrypted first interactive data sent by the power distribution master station and / or sends encrypted second interactive data to the power distribution master station via a VPN tunnel established between the power distribution master station and the power distribution terminal. The VPN tunnel is established through a firewall configured in the secure access zone and is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address. The LAN port of the wireless router on the plant side is configured with the second IP address range.
[0201] Optionally, the VPN tunnel is established between the first vertical encryption device and the second vertical encryption device;
[0202] The first vertical encryption device is configured on the main station side, and the gateway of the first vertical encryption device is the first IP address range of the VPN service; the second vertical encryption device is configured on the plant side, and the gateway of the second vertical encryption device is the second IP address range of the wireless router.
[0203] Optionally, the processor 1010 is further configured to perform the following processes:
[0204] The second vertical encryption device sends a login request carrying security parameters to the firewall on the main site side via a wireless router; wherein, after the security parameters are verified, a VPN tunnel is established between the first vertical encryption device and the second vertical encryption device through the firewall.
[0205] Optionally, the processor 1010 is further configured to perform the following processes:
[0206] The encrypted first interactive data file is decrypted using the second vertical encryption device.
[0207] The decrypted first interactive data is packaged according to the protocol used by the power distribution terminal using the terminal data acquisition device, and then the first interactive data is sent to the power distribution terminal.
[0208] Optionally, the processor 1010 is further configured to perform the following processes:
[0209] The terminal data acquisition device packages the second interactive data to be sent according to the standard 104 protocol and then sends it to the second vertical encryption device.
[0210] The second interactive data is encrypted by the second vertical encryption device to obtain the encrypted second interactive data.
[0211] The configuration terminal 1000 in the above embodiment establishes a communication connection with the power distribution master station through the IP address in the VPN tunnel, enabling same-layer mutual access and solving the problem that encrypted interactive data cannot directly enter the secure access area through the wireless network.
[0212] like Figure 11 As shown, another embodiment of the present invention provides a configuration master station including a transceiver 1110, a processor 1100, a memory 1120, and a program or instructions stored in the memory 1120 and executable on the processor 1100; when the processor 1100 executes the program or instructions, it implements the above-described data transmission method.
[0213] The transceiver 1110 is used to receive and send data under the control of the processor 1100.
[0214] Among them, Figure 11In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1100 and memory represented by memory 1120 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1110 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, user interface 1130 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0215] The processor 1100 is responsible for managing the bus architecture and general processing, and the memory 1120 can store the data used by the processor 1100 when performing operations.
[0216] Another embodiment of the power distribution terminal of the present invention, such as Figure 12 As shown, it includes a transceiver 1210, a processor 1200, a memory 1220, and a program or instructions stored in the memory 1220 and executable on the processor 1200; when the processor 1200 executes the program or instructions, it implements the above-described data transmission method.
[0217] The transceiver 1210 is used to receive and send data under the control of the processor 1200.
[0218] Among them, Figure 12 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1200 and memory represented by memory 1220 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1210 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, user interface 1230 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0219] The processor 1200 is responsible for managing the bus architecture and general processing, while the memory 1220 can store the data used by the processor 1200 when performing operations.
[0220] This invention provides a readable storage medium storing a program or instructions. When executed by a processor, the program or instructions implement the steps of the data transmission method described above and achieve the same technical effect. To avoid repetition, further details are omitted here. The computer-readable storage medium may include read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0221] It should be further noted that the terminals described in this specification include, but are not limited to, smartphones, tablets, etc., and many of the functional components described are referred to as modules in order to emphasize the independence of their implementation.
[0222] In this embodiment of the invention, the module can be implemented in software so that it can be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions, which may be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but may include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the module's intended purpose.
[0223] In practice, an executable code module can be a single instruction or many instructions, and can even be distributed across multiple different code segments, different programs, and across multiple memory devices. Similarly, operational data can be identified within the module and can be implemented in any suitable form and organized within any suitable type of data structure. This operational data can be collected as a single dataset or distributed across different locations (including different storage devices), and can exist, at least in part, solely as electronic signals within the system or network.
[0224] When a module can be implemented using software, considering the current level of hardware technology, modules that can be implemented in software can be implemented using hardware circuits by those skilled in the art to achieve the corresponding functions, without considering cost. These hardware circuits include conventional very-large-scale integrated circuits (VLSI) or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules can also be implemented using programmable hardware devices, such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0225] The exemplary embodiments described above are with reference to the accompanying drawings. Many different forms and embodiments are feasible without departing from the spirit and teachings of the invention. Therefore, the invention should not be construed as limiting the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided to make the invention complete and convey the scope of the invention to those skilled in the art. In these drawings, component dimensions and relative dimensions may be exaggerated for clarity. The terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. As used herein, unless clearly indicated otherwise, the singular forms “a,” “an,” and “the” are intended to include all such forms. It will be further understood that the terms “comprising” and / or “including”, when used in this specification, indicate the presence of the stated features, integers, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, integers, steps, operations, components, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of the range and any subranges in between.
[0226] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A data transmission method, characterized in that, The distribution master station applied to the master station side includes: A Virtual Private Network (VPN) tunnel is established between the power distribution master station and the power distribution terminals on the substation side by configuring a firewall within the secure access zone. The VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the substation side is configured with the second IP address range. The VPN tunnel is established between a first vertical encryption device and a second vertical encryption device. The first vertical encryption device is configured on the master station side, and its gateway is the first IP address range of the VPN service. The second vertical encryption device is configured on the substation side, and its gateway is the second IP address range of the LAN port of the wireless router. Through the VPN tunnel, encrypted first interactive data is sent to the power distribution terminal, and / or encrypted second interactive data is received from the power distribution terminal.
2. The data transmission method according to claim 1, characterized in that, After establishing a Virtual Private Network (VPN) tunnel between the power distribution master station and the power distribution terminal through a firewall configured in the secure access zone, the method further includes: The firewall receives a login request carrying security parameters sent by the second vertical encryption device through a wireless router. The firewall verifies the security parameters, and upon successful verification, establishes a VPN tunnel between the first vertical encryption device and the second vertical encryption device.
3. The data transmission method according to claim 1, characterized in that, After receiving encrypted second interactive data sent by the power distribution terminal through the VPN tunnel, the method further includes: The encrypted second interactive data is decrypted using the first vertical encryption device to obtain the second interactive data. The second interactive data is converted into text format by the first communication server and stored in the upstream file directory of the first communication server; The second interactive data in text format is obtained from the upstream file directory through the reverse isolation device, and the second interactive data in text format is transmitted to the upstream file directory of the second communication server. The second interactive data in text format is sent to the power distribution master station in the production control area via a TCP connection through the second communication server. The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
4. The data transmission method according to claim 1, characterized in that, Before sending the encrypted first interactive data to the power distribution terminal through the VPN tunnel, the method further includes: The second communication server receives the first interactive data sent by the power distribution master station. The first interactive data is converted into text format by the second communication server and stored in the downstream file directory of the second communication server; The first interactive data in text format is obtained from the downlink file directory through the forward isolation device, and the first interactive data in text format is transmitted to the downlink file directory of the first communication server. The first interactive data in text format is sent to the first vertical encryption device via a TCP connection through the first communication server for encryption processing, thereby obtaining the encrypted first interactive data; The first communication server is configured within the secure access zone, and the second communication server is configured within the production control zone.
5. A data transmission method, characterized in that, Distribution terminals used on the substation side include: By establishing a VPN tunnel between the power distribution master station on the master station side and the power distribution terminal, the system receives encrypted first interactive data sent by the power distribution master station and / or sends encrypted second interactive data to the power distribution master station. The VPN tunnel is established through a firewall configured in the secure access zone. The VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on the public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured with the second IP address range. The VPN tunnel is established between a first vertical encryption device and a second vertical encryption device. The first vertical encryption device is configured on the main station side, and its gateway is the first IP address range of the VPN service. The second vertical encryption device is configured on the plant side, and its gateway is the second IP address range of the wireless router.
6. The data transmission method according to claim 5, characterized in that, Before receiving encrypted first interactive data sent by the distribution master station through a VPN tunnel established between the distribution master station and the distribution terminal, and / or sending encrypted second interactive data to the distribution master station, the method further includes: The second vertical encryption device sends a login request carrying security parameters to the firewall on the main site side via a wireless router; wherein, after the security parameters are verified, a VPN tunnel is established between the first vertical encryption device and the second vertical encryption device through the firewall.
7. The data transmission method according to claim 5, characterized in that, After receiving the encrypted first interactive data sent by the power distribution master station through the VPN tunnel, the method further includes: The encrypted first interactive data file is decrypted using the second vertical encryption device. The decrypted first interactive data is packaged according to the protocol used by the power distribution terminal using the terminal data acquisition device, and then the first interactive data is sent to the power distribution terminal.
8. The data transmission method according to claim 5, characterized in that, Before sending encrypted second interactive data to the distribution master station via a VPN tunnel established between the distribution master station and the distribution terminal, the method further includes: The terminal data acquisition device packages the second interactive data to be sent according to the standard 104 protocol and then sends it to the second vertical encryption device. The second interactive data is encrypted by the second vertical encryption device to obtain the encrypted second interactive data.
9. A data transmission device, characterized in that, Applied to power distribution master stations, including: A Virtual Private Network (VPN) tunnel is established between the power distribution master station and the power distribution terminal by configuring a firewall within the secure access zone. The VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The VPN tunnel is established between a first vertical encryption device and a second vertical encryption device. The first vertical encryption device is configured on the master station side, and its gateway is the first IP address range of the VPN service. The second vertical encryption device is configured on the substation side, and its gateway is the second IP address range of the wireless router's LAN port. Through the VPN tunnel, encrypted first interactive data is sent to the power distribution terminal, and / or encrypted second interactive data is received from the power distribution terminal.
10. A data transmission device, characterized in that, Distribution terminals used on the substation side include: By establishing a VPN tunnel between the power distribution master station on the master station side and the power distribution terminal, the system receives encrypted first interactive data sent by the power distribution master station and / or sends encrypted second interactive data to the power distribution master station. The VPN tunnel is established through a firewall configured in the secure access zone and is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured with the second IP address range. The VPN tunnel is established between a first vertical encryption device and a second vertical encryption device. The first vertical encryption device is configured on the main station side, and its gateway is the first IP address range of the VPN service. The second vertical encryption device is configured on the plant side, and its gateway is the second IP address range of the LAN port of the wireless router.
11. A power distribution master station, comprising: The transceiver and processor are characterized in that the processor is configured to perform the following process: A Virtual Private Network (VPN) tunnel is established between the power distribution master station on the master station side and the power distribution terminal on the substation side by configuring a firewall in the secure access zone. The VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The VPN tunnel is established between a first vertical encryption device and a second vertical encryption device. The first vertical encryption device is configured on the master station side, and its gateway is the first IP address range of the VPN service. The second vertical encryption device is configured on the substation side, and its gateway is the second IP address range of the LAN port of a wireless router. Through the VPN tunnel, encrypted first interactive data is sent to the power distribution terminal, and / or encrypted second interactive data is received from the power distribution terminal.
12. A power distribution terminal, comprising: The transceiver and processor are characterized in that the processor is configured to perform the following process: By establishing a VPN tunnel between the power distribution master station on the master station side and the power distribution terminal on the substation side, the system receives encrypted first interactive data sent by the power distribution master station and / or sends encrypted second interactive data to the power distribution master station. The VPN tunnel is established through a firewall configured in the secure access zone. The VPN tunnel is used for bidirectional communication between a first IP address range and a second IP address range. The firewall port is mapped to a fixed IP address on a public network, and the fixed IP address belongs to the first IP address range. The LAN port of the wireless router on the plant side is configured with the second IP address range. The VPN tunnel is established between a first vertical encryption device and a second vertical encryption device. The first vertical encryption device is configured on the main station side, and its gateway is the first IP address range of the VPN service. The second vertical encryption device is configured on the plant side, and its gateway is the second IP address range of the LAN port of the wireless router.
13. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps in the data transmission method as described in any one of claims 1-8.
Citation Information
Patent Citations
System and method for data communication between power distribution master station system and power distribution terminal
CN102185382A
Internet of Things wireless terminal equipment and communication module
CN212463256U