A multi-device protocol monitoring management method and system applied to a power plant

By constructing a protocol call library and dynamically configuring network interfaces, combined with encryption rules and vulnerability assessments, the problem of insufficient communication security between power plant equipment was solved, enabling real-time monitoring and security adjustment of equipment protocols, and improving the security and stability of information interaction.

CN116866016BActive Publication Date: 2026-05-01NINGXIA ZHONGWEI GCL PHOTOVOLTAIC POWER CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NINGXIA ZHONGWEI GCL PHOTOVOLTAIC POWER CO LTD
Filing Date
2023-06-27
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies offer limited improvement in communication security during power plant equipment protocol monitoring and management, especially lacking effective security protection measures when equipment protocol calls are abnormal.

Method used

A protocol call library is built to dynamically configure the interface configuration strategies of network interfaces and device protocols. The interface configuration strategies are adjusted through encryption rules and vulnerability assessments. The call frequency and vulnerabilities of device protocols are monitored in real time to achieve comprehensive vulnerability assessment and security adjustment.

Benefits of technology

It enhances the security of communication between power plant equipment, enabling timely detection and response to protocol call anomalies, and improving the security and stability of information exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116866016B_ABST
    Figure CN116866016B_ABST
Patent Text Reader

Abstract

The application discloses a kind of multi-device protocol monitoring management method and system applied to power plant, it is related to protocol management technical field, including constructing protocol calling library and interface configuration strategy, under the premise of applying interface configuration strategy, according to the first hidden hazard evaluation of equipment protocol application situation determined according to the interpretation of equipment protocol, according to the difference characteristics of the interval of actual call frequency and standard call frequency of different equipment protocol, the second hidden hazard evaluation of equipment protocol application situation is determined, according to the first hidden hazard evaluation and the second hidden hazard evaluation of equipment protocol application situation, the comprehensive hidden hazard evaluation of equipment protocol application situation is carried out, according to the comprehensive hidden hazard evaluation of equipment protocol application situation, adjustment interface configuration strategy, not only can realize the application situation of equipment protocol whether there is exception, still can improve the security of information interaction by adjusting interface configuration strategy.
Need to check novelty before this filing date? Find Prior Art

Description

A method and system for multi-device protocol monitoring and management in power plants Technical Field

[0001] This invention relates to the field of equipment protocol management technology, and in particular to a multi-equipment protocol monitoring and management method and system applied to power plants. Background Technology

[0002] Power plants are vital energy suppliers, with various devices and systems working together to ensure efficient power generation and stable grid operation. To achieve coordinated operation and monitoring management among these devices, multi-device protocol monitoring and management methods are widely used in power plant automation systems.

[0003] In order to improve the efficiency of building a power plant information transmission network, the Internet was initially chosen to realize information exchange between the plant equipment and the management center. However, this method has the potential for network attacks and other risks. In order to improve the secure communication between the plant equipment and the management center, most existing technologies monitor and manage the equipment by calling the equipment protocol. In the event of abnormal equipment protocol calls, the security protection function is only an alarm, which has limited improvement on the security of communication. Summary of the Invention

[0004] The purpose of this invention is to provide a method and system for monitoring and managing multi-device protocols in power plants that effectively improves communication security.

[0005] Therefore, this invention discloses a multi-device protocol monitoring and management method applied to power plants, including:

[0006] Build a protocol call library for the application's device protocol;

[0007] Dynamically configure the network interface for each device protocol in the protocol call library, and generate interface configuration strategies that combine network interfaces and device protocols in real time;

[0008] A first encryption rule is constructed for the interface configuration policy, and the interface configuration policy is sent to the corresponding device side according to the first encryption rule;

[0009] The correspondence between the current network interface and the device protocol is determined according to the interface configuration policy. The device interaction information received by the network interface is matched with the corresponding device protocol for interpretation. Based on the interpretation, the first potential risk assessment of the device protocol application is determined.

[0010] Based on past protocol application records, several protocol call condition elements are identified, and several protocol call condition elements in the same time period are used to construct a protocol call demand group. Based on past protocol application records, the standard frequency range of different device protocol calls under the condition requirements of the protocol call demand group is determined, and the correspondence between the protocol call demand group and the standard frequency range of different device protocol calls is constructed into a protocol call frequency reference table.

[0011] Substitute the current protocol call condition elements into the protocol call frequency reference table for retrieval and analysis to determine the standard call frequency range of different device protocols at present.

[0012] Based on the differences between the actual call frequency and the standard call frequency range of different device protocols, a second potential risk assessment of the application of device protocols is determined;

[0013] Based on the first and second hazard assessments of the equipment protocol application, a comprehensive hazard assessment of the equipment protocol application is conducted.

[0014] Based on a comprehensive assessment of potential risks related to the application of equipment protocols, the interface configuration strategy is adjusted.

[0015] In some embodiments of this application, the method for adjusting the interface configuration strategy based on a comprehensive risk assessment of the device protocol application includes:

[0016] Obtain all callable network interfaces and device protocols, and establish network interface arrays and device protocol arrays for each of the callable network interfaces and device protocols, with the network interface arrays and device protocol arrays corresponding one-to-one according to the order.

[0017] Several order adjustment tables are set for the order of each network interface in the network interface array, and each order adjustment table includes the shuffled order.

[0018] The frequency of changing the sequence adjustment table is determined based on a comprehensive risk assessment of the application of the equipment protocol, and the sequence of different network interfaces in the network interface array is changed according to the changed sequence adjustment table.

[0019] In some embodiments of this application, the method for determining the frequency of replacing the sequence adjustment table based on a comprehensive hazard assessment of the device protocol application includes:

[0020] Several first comparison security evaluation corresponding value ranges are set, and each first comparison security evaluation corresponding value range is associated with a specific order adjustment table replacement frequency.

[0021] The frequency of changing the sequence adjustment table is determined based on the range of the first comparative safety evaluation value corresponding to the comprehensive hazard assessment value.

[0022] In some embodiments of this application, the method for determining the frequency of replacing the sequence adjustment table based on a comprehensive hazard assessment of the device protocol application includes:

[0023] A frequency conversion operator is constructed for comprehensive hazard assessment, and the replacement frequency of the sequence adjustment table is calculated based on the frequency conversion operator.

[0024] The expression for calculating the replacement frequency of the sequence adjustment table is:

[0025]

[0026] Where p is the frequency of changing the sequence adjustment table, and k i Let y3 be the frequency conversion coefficient for the i-th frequency, y3 be the corresponding value of the comprehensive hazard assessment, and b be the frequency conversion adjustment constant.

[0027] Where, k i The methods for determining this include:

[0028] Several second comparison security evaluation corresponding value intervals are set, and each second comparison security evaluation corresponding value interval is associated with a specific frequency conversion coefficient;

[0029] Based on the corresponding interval of the second comparative safety evaluation to which the corresponding value of the comprehensive hazard evaluation belongs, determine the frequency conversion coefficient that is substituted into the expression for the replacement frequency.

[0030] In some embodiments of this application, the first encryption rule includes:

[0031] Establish a key application timeline, mark several time nodes for the key application timeline, and associate specific keys with the time segments between each adjacent time node;

[0032] Obtain the current time from the power plant management side and the equipment side, and determine the specific key used by the power plant management side and the equipment side based on the time interval on the key application timeline to which the current time belongs.

[0033] In some embodiments of this application, the method for determining the first potential hazard assessment of the device protocol application based on the interpretation includes:

[0034] Statistical analysis is performed on all device interaction information that failed to be interpreted within a preset time period to obtain the first number of interpretation failures;

[0035] For all device interaction information that failed to be interpreted within a preset time period, device protocol matching is performed, and the first hidden danger weight corresponding to the device interaction information is determined according to the matched device protocol, and the second hidden danger weight corresponding to the device interaction information is determined according to the time node of the device protocol matching.

[0036] The first risk assessment of the device protocol application status is determined based on the number of first interpretation failures, the first risk weight, and the second risk weight of the device interaction information.

[0037] In some embodiments of this application, the first potential hazard assessment expression for determining the application status of the device protocol is:

[0038]

[0039] Among them, the first potential hazard assessment value corresponding to the application of the y1 device protocol is l. n1 Let l be the weight of the first potential hazard corresponding to the nth device interaction information. n2 Let x be the weight of the second potential hazard corresponding to the nth device interaction information. n c represents the number of first interpretation failures for the nth device's interactive information. n Adjust the constant for the number of failed interpretations of the nth device interaction information.

[0040] In some embodiments of this application, the method for determining the second potential hazard assessment of device protocol application includes:

[0041] Obtain the actual call frequency of the current device protocol, and calculate and analyze the frequency difference value between the actual call frequency and the upper limit of the standard call frequency range;

[0042] Based on the frequency difference value to which the difference value belongs, a hazard conversion adjustment coefficient is configured for the frequency difference value. By comprehensively analyzing the frequency difference value and the hazard conversion adjustment coefficient, the corresponding value of the second hazard assessment of the equipment protocol application is determined.

[0043] The expression for calculating the corresponding value of the second hazard assessment is:

[0044]

[0045] Where y2 is the value corresponding to the second hidden danger assessment of the equipment protocol application status, j ∝ Let be the adjustment coefficient for the hidden danger transformation corresponding to the ∝th difference value interval, Δδ be the frequency difference value, and m be the frequency difference adjustment constant.

[0046] In some embodiments of this application, the methods for comprehensively evaluating the potential risks of device protocol application include summation calculation and comprehensive analysis.

[0047] The summation method includes:

[0048] Add the corresponding values ​​of the first and second hazard assessments together to obtain the corresponding value of the comprehensive hazard assessment.

[0049] Comprehensive analysis methods include:

[0050] The first and second hazard assessments are combined to form a comprehensive hazard assessment group;

[0051] Based on the current requirements for calling different device protocols, several levels of hazard warning thresholds are dynamically configured for the first and second hazard assessments. The overall hazard assessment status of the device protocol application is determined based on the hazard assessment being just above a certain level of hazard warning threshold.

[0052] In some embodiments of this application, a multi-device protocol monitoring and management system for power plants is also disclosed, comprising:

[0053] The interface configuration strategy generation module is used to dynamically configure the network interface for each device protocol in the protocol call library, and generate an interface configuration strategy that combines the network interface and the device protocol in real time.

[0054] The encryption rule management module is used to construct a first encryption rule for the interface configuration policy, and send the interface configuration policy to the corresponding device side according to the first encryption rule;

[0055] The vulnerability assessment module is used to determine the correspondence between the current network interface and the device protocol based on the interface configuration policy, and to interpret the device interaction information received by the network interface by matching it with the corresponding device protocol. Based on the interpretation, it determines the first vulnerability assessment of the device protocol application. It is also used to identify several protocol call condition elements based on past protocol application records, and to construct a protocol call request group from several protocol call condition elements in the same time period. Based on past protocol application records, it determines the standard frequency range of different device protocol calls under the conditions of the protocol call request group, and constructs a protocol call frequency reference table by constructing the correspondence between the protocol call request group and the standard frequency range of different device protocol calls. The current protocol call condition elements are substituted into the protocol call frequency reference table for retrieval and analysis to determine the standard call frequency range of different device protocols. Based on the difference between the actual call frequency of different device protocols and the standard call frequency range, a second vulnerability assessment of the device protocol application is determined. Based on the first and second vulnerability assessments of the device protocol application, a comprehensive vulnerability assessment of the device protocol application is performed.

[0056] The interface configuration strategy adjustment module is used to adjust the interface configuration strategy based on a comprehensive risk assessment of the device protocol application.

[0057] This application discloses a multi-device protocol monitoring and management method and system for power plants, relating to the field of protocol management technology. The method includes constructing a protocol call library and interface configuration strategies. Under the premise of the application interface configuration strategies, a first potential risk assessment of the device protocol application status is determined based on the interpretation of the device protocols. A second potential risk assessment of the device protocol application status is determined based on the differences between the actual call frequency and the standard call frequency range of different device protocols. A comprehensive potential risk assessment of the device protocol application status is performed based on the first and second potential risk assessments. Based on the comprehensive potential risk assessment of the device protocol application status, the interface configuration strategies are adjusted. This not only enables the determination of whether there are any anomalies in the application status of the device protocols, but also improves the security of information interaction by adjusting the interface configuration strategies.

[0058] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0059] Figure 1 illustrates a multi-device protocol monitoring and management method and system applied to a power plant in an embodiment of this application. Detailed Implementation

[0060] The technical solution of the present invention will be further described below with reference to the accompanying drawings and embodiments.

[0061] The technical solution of the present invention will be clearly and completely described below with reference to the accompanying drawings and specific embodiments. It should be understood that the preferred embodiments described herein are only for illustration and explanation of the present invention and should not be construed as limiting the scope of protection of the present invention. Those skilled in the art can make some non-essential improvements and adjustments based on the following content of the present invention.

[0062] Example:

[0063] The purpose of this invention is to provide a method and system for monitoring and managing multi-device protocols in power plants that effectively improves communication security.

[0064] Therefore, this invention discloses a multi-device protocol monitoring and management method applied to power plants, as shown in Figure 1, including:

[0065] Step S100: Build a protocol call library for the application's device protocol.

[0066] It is important to understand that the protocol call library can include the device protocols of all devices within the power plant that need to access the information network.

[0067] Step S200: Dynamically configure the network interface for each device protocol in the protocol call library, and generate an interface configuration strategy that combines the network interface and the device protocol in real time.

[0068] It is important to understand that dynamically configuring network interfaces for each device protocol involves continuously changing the correspondence between device protocols and network interfaces. For example, for device protocols A01, A02, and A03, and network interfaces W01, W02, and W03, the correspondence at the first time point is A01-W01, A02-W02, and A03-W03. As the correspondence changes, the correspondence at the second time point becomes A01-W02, A02-W03, and A03-W01.

[0069] It is important to understand that the interface configuration strategy is the correspondence between different device protocols and different network interfaces at the current point in time.

[0070] Step S300: Construct a first encryption rule for the interface configuration policy, and send the interface configuration policy to the corresponding device side according to the first encryption rule.

[0071] Step S400: Determine the correspondence between the current network interface and the device protocol according to the interface configuration policy, and match the device interaction information received by the network interface with the corresponding device protocol for interpretation, and determine the first potential risk assessment of the device protocol application based on the interpretation.

[0072] It is important to understand that if the device protocol cannot interpret the device interaction information received by the network interface, it means that the end sending the device interaction information did not send the device interaction information to the correct network interface according to the interface configuration policy. Of course, there may be situations where the interface configuration policy is not completely synchronized on the device side and the management center side. Therefore, we can analyze the number of interpretation failures to determine the first potential risk assessment of the device protocol application.

[0073] Step S500: Based on past protocol application records, determine several protocol call condition elements, and construct a protocol call demand group from several protocol call condition elements in the same time period. Based on past protocol application records, determine the standard frequency range of different device protocol calls under the condition requirements of the protocol call demand group, and construct a protocol call frequency reference table by establishing the correspondence between the protocol call demand group and the standard frequency range of different device protocol calls.

[0074] Step S600: Substitute the current protocol call condition elements into the protocol call frequency reference table for retrieval and analysis to determine the standard call frequency range of different device protocols.

[0075] Step S700: Based on the differences between the actual call frequency and the standard call frequency range of different device protocols, determine the second potential risk assessment of the application of the device protocol.

[0076] Step S800: Based on the first and second hazard assessments of the equipment protocol application, a comprehensive hazard assessment of the equipment protocol application is conducted.

[0077] Step S900: Adjust the interface configuration strategy based on a comprehensive risk assessment of the device protocol application.

[0078] In some embodiments of this application, the method for adjusting the interface configuration strategy based on a comprehensive risk assessment of the device protocol application includes:

[0079] The first step is to obtain all callable network interfaces and device protocols, and then establish network interface arrays and device protocol arrays for each of the callable network interfaces and device protocols.

[0080] The second step involves setting several order adjustment tables for each network interface in the network interface array, with each order adjustment table including the shuffled order.

[0081] The third step is to determine the frequency of replacing the sequence adjustment table based on a comprehensive risk assessment of the application of the equipment protocol, and the sequence of different network interfaces in the network interface array is changed according to the replaced sequence adjustment table.

[0082] In some embodiments of this application, the method for determining the frequency of replacing the sequence adjustment table based on a comprehensive hazard assessment of the device protocol application includes:

[0083] The first step involves setting several first comparison security evaluation corresponding value ranges, and each first comparison security evaluation corresponding value range is associated with a specific frequency of change of the order adjustment table.

[0084] The second step is to determine the frequency of changing the sequence adjustment table based on the range of the first comparative safety evaluation value corresponding to the comprehensive hazard assessment value.

[0085] In some embodiments of this application, the method for determining the frequency of replacing the sequence adjustment table based on a comprehensive hazard assessment of the device protocol application includes:

[0086] A frequency conversion operator is constructed for comprehensive hazard assessment, and the replacement frequency of the sequence adjustment table is calculated based on the frequency conversion operator.

[0087] The expression for calculating the replacement frequency of the sequence adjustment table is:

[0088]

[0089] Where p is the frequency of changing the sequence adjustment table, and k iLet y3 be the frequency conversion coefficient of the i-th frequency, y3 be the corresponding value of the comprehensive hazard evaluation, and b be the frequency conversion adjustment constant.

[0090] Where, k i The methods for determining this include:

[0091] Several second comparison security evaluation corresponding value intervals are set, and each second comparison security evaluation corresponding value interval is associated with a specific frequency conversion coefficient.

[0092] Based on the corresponding interval of the second comparative safety evaluation to which the corresponding value of the comprehensive hazard evaluation belongs, determine the frequency conversion coefficient that is substituted into the expression for the replacement frequency.

[0093] In some embodiments of this application, the first encryption rule includes:

[0094] Establish a key application timeline, mark several time nodes on the key application timeline, and associate specific keys with the time segments between each adjacent time node.

[0095] Obtain the current time from the power plant management side and the equipment side, and determine the specific key used by the power plant management side and the equipment side based on the time interval on the key application timeline to which the current time belongs.

[0096] In some embodiments of this application, the method for determining the first potential hazard assessment of the device protocol application based on the interpretation includes:

[0097] The first step is to perform statistical analysis on all device interaction information that failed to be interpreted within a preset time period to obtain the first number of interpretation failures.

[0098] The second step is to perform device protocol matching on all device interaction information that failed to be interpreted within a preset time period, determine the first hidden danger weight corresponding to the device interaction information based on the matched device protocol, and determine the second hidden danger weight corresponding to the device interaction information based on the time node of the device protocol matching.

[0099] The third step is to determine the first potential risk assessment of the device protocol application based on the number of first interpretation failures, the first potential risk weight, and the second potential risk weight of the device interaction information.

[0100] In some embodiments of this application, the first potential hazard assessment expression for determining the application status of the device protocol is:

[0101]

[0102] Among them, the first potential hazard assessment value corresponding to the application of the y1 device protocol is l. n1 Let l be the weight of the first potential hazard corresponding to the nth device interaction information. n2Let x be the weight of the second potential hazard corresponding to the nth device interaction information. n c represents the number of first interpretation failures for the nth device's interactive information. n Adjust the constant for the number of failed interpretations of the nth device interaction information.

[0103] In some embodiments of this application, the method for determining the second potential hazard assessment of device protocol application includes:

[0104] The first step is to obtain the actual call frequency of the current device protocol and calculate and analyze the frequency difference value between it and the upper limit of the standard call frequency range.

[0105] The second step is to configure a hazard conversion adjustment coefficient for the frequency difference value according to the difference value range to which the frequency difference value belongs, and to comprehensively analyze the frequency difference value and the hazard conversion adjustment coefficient to determine the corresponding value of the second hazard assessment of the equipment protocol application.

[0106] The expression for calculating the corresponding value of the second hazard assessment is:

[0107]

[0108] Where y2 is the value corresponding to the second hidden danger assessment of the equipment protocol application status, j n∝ Let Δδ be the hidden danger conversion adjustment coefficient corresponding to the ∝th difference value interval of the nth device protocol application situation. n Let m be the frequency difference value for the application of the protocol on the nth device. n This is a constant used to adjust the frequency difference of the protocol application for the nth device.

[0109] In some embodiments of this application, the methods for comprehensively evaluating the potential risks of device protocol application include summation calculation and comprehensive analysis.

[0110] The summation method includes:

[0111] The corresponding values ​​of the first and second hazard assessments are added together to obtain the corresponding value of the comprehensive hazard assessment.

[0112] Comprehensive analysis methods include:

[0113] The first and second hazard assessments are combined to form a comprehensive hazard assessment group.

[0114] Based on the current requirements for calling different device protocols, several levels of hazard warning thresholds are dynamically configured for the first and second hazard assessments. The overall hazard assessment status of the device protocol application is determined based on the hazard assessment being just above a certain level of hazard warning threshold.

[0115] In some embodiments of this application, a multi-device protocol monitoring and management system for power plants is also disclosed, including: an interface configuration policy generation module, an encryption rule management module, a hidden danger evaluation module, and an interface configuration policy adjustment module.

[0116] The interface configuration strategy generation module is used to dynamically configure the network interface for each device protocol in the protocol call library, and generate an interface configuration strategy that combines the network interface and the device protocol in real time.

[0117] The encryption rule management module is used to construct a first encryption rule for the interface configuration policy, and send the interface configuration policy to the corresponding device side according to the first encryption rule.

[0118] The hazard assessment module is used to determine the correspondence between the current network interface and the device protocol according to the interface configuration strategy, and to interpret the device interaction information received by the network interface by matching it with the corresponding device protocol. Based on the interpretation, it determines the first hazard assessment of the device protocol application. It is also used to determine several protocol call condition elements based on past protocol application records, and to construct a protocol call demand group from several protocol call condition elements in the same time period. Based on past protocol application records, it determines the standard frequency range of different device protocol calls under the condition requirements of the protocol call demand group, and constructs a protocol call frequency reference table by constructing the correspondence between the protocol call demand group and the standard frequency range of different device protocol calls. It substitutes the current protocol call condition elements into the protocol call frequency reference table for retrieval and analysis to determine the standard call frequency range of different device protocols. Based on the difference between the actual call frequency of different device protocols and the standard call frequency range, it determines the second hazard assessment of the device protocol application. Based on the first and second hazard assessments of the device protocol application, it performs a comprehensive hazard assessment of the device protocol application.

[0119] The interface configuration strategy adjustment module is used to adjust the interface configuration strategy based on a comprehensive risk assessment of the device protocol application.

[0120] Through the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented in hardware or by means of software plus necessary general-purpose hardware platforms. Based on this understanding, the technical solution of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) and includes several instructions to cause a computer device (such as a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0121] This application discloses a multi-device protocol monitoring and management method and system for power plants, relating to the field of protocol management technology. The method includes constructing a protocol call library and interface configuration strategies. Under the premise of the application interface configuration strategies, a first potential risk assessment of the device protocol application status is determined based on the interpretation of the device protocols. A second potential risk assessment of the device protocol application status is determined based on the differences between the actual call frequency and the standard call frequency range of different device protocols. A comprehensive potential risk assessment of the device protocol application status is performed based on the first and second potential risk assessments. Based on the comprehensive potential risk assessment of the device protocol application status, the interface configuration strategies are adjusted. This not only enables the determination of whether there are any anomalies in the application status of the device protocols, but also improves the security of information interaction by adjusting the interface configuration strategies.

[0122] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A multi-device protocol monitoring and management method applied to power plants, characterized in that, include: Build a protocol call library for the application's device protocol; For each device protocol in the protocol call library, the network interface is dynamically configured, and an interface configuration policy combining the network interface and the device protocol is generated in real time. A first encryption rule is constructed for the interface configuration policy, and the interface configuration policy is sent to the corresponding device side according to the first encryption rule. The correspondence between the current network interface and the device protocol is determined based on the interface configuration policy, and the device interaction information received by the network interface is matched with the corresponding device protocol for interpretation. Based on the interpretation, a first potential risk assessment of the device protocol application is determined. For past protocol application records, several protocol call condition elements are determined, and several protocol call condition elements from the same time period are used to construct a protocol call request group. Based on past protocol application records, the standard frequency ranges of different device protocol calls under the conditions of the protocol call request group are determined, and a protocol call frequency reference table is constructed to establish the correspondence between the protocol call request group and the standard frequency ranges of different device protocol calls. The current protocol call condition elements are substituted into the protocol call frequency reference table for retrieval and analysis to determine the current standard call frequency ranges of different device protocols. Based on the differences between the actual call frequencies of different device protocols and the standard call frequency ranges, a second potential risk assessment of the device protocol application situation is determined. Based on the first and second potential risk assessments of the device protocol application situation, a comprehensive potential risk assessment of the device protocol application situation is conducted. Based on a comprehensive assessment of potential risks related to the application of equipment protocols, the interface configuration strategy is adjusted.

2. The multi-device protocol monitoring and management method for power plants according to claim 1, characterized in that, Based on a comprehensive risk assessment of device protocol application, the method for adjusting interface configuration strategies includes: obtaining all callable network interfaces and device protocols, and establishing network interface arrays and device protocol arrays for each of the callable network interfaces and device protocols, wherein the network interface arrays and device protocol arrays correspond one-to-one according to their order; setting several order adjustment tables for the order of each network interface in the network interface array, each order adjustment table including a shuffled order; determining the frequency of changing the order adjustment tables based on the comprehensive risk assessment of device protocol application, and changing the order of different network interfaces in the network interface array according to the changed order adjustment tables.

3. The multi-device protocol monitoring and management method for power plants according to claim 2, characterized in that, The method for determining the frequency of replacing the sequence adjustment table based on the comprehensive hazard assessment of the equipment protocol application includes: setting several first comparison safety assessment corresponding value intervals, and each first comparison safety assessment corresponding value interval is associated with a specific replacement frequency of the sequence adjustment table; determining the replacement frequency of the sequence adjustment table based on the first comparison safety assessment corresponding value interval to which the comprehensive hazard assessment corresponding value belongs.

4. The multi-device protocol monitoring and management method for power plants according to claim 2, characterized in that, The method for determining the frequency of replacing the sequence adjustment table based on a comprehensive hazard assessment of equipment protocol application includes: constructing a frequency transformation operator for the comprehensive hazard assessment, and calculating the replacement frequency of the sequence adjustment table based on the frequency transformation operator; the expression for calculating the replacement frequency of the sequence adjustment table is: Where p is the frequency of changing the sequence adjustment table, and k i Let y3 be the frequency conversion coefficient for the i-th frequency, y3 be the corresponding value of the comprehensive hazard assessment, and b be the frequency conversion adjustment constant; where k i The determination method includes: setting several second comparison safety evaluation corresponding value intervals, and each second comparison safety evaluation corresponding value interval is associated with a specific frequency conversion coefficient; determining the frequency conversion coefficient substituted into the expression of replacement frequency based on the second comparison safety evaluation corresponding interval to which the comprehensive hidden danger evaluation corresponding value belongs.

5. The multi-device protocol monitoring and management method for power plants according to claim 1, characterized in that, The first encryption rule includes: establishing a key application timeline, marking several time nodes on the key application timeline, and associating a specific key with the time segment between each adjacent time node; obtaining the current time on the power plant management side and the equipment side, and determining the specific key applied on the power plant management side and the equipment side based on the time segment on the key application timeline to which the current time belongs.

6. The multi-device protocol monitoring and management method for power plants according to claim 1, characterized in that, The method for determining the first potential hazard assessment of device protocol application based on the interpretation results includes: statistically analyzing all device interaction information that failed to be interpreted within a preset time period to obtain the first number of interpretation failures; matching the device protocols of all device interaction information that failed to be interpreted within the preset time period, determining the first potential hazard weight corresponding to the device interaction information based on the matched device protocols, and determining the second potential hazard weight corresponding to the device interaction information based on the time node of the device protocol matching; and determining the first potential hazard assessment of device protocol application based on the first number of interpretation failures, the first potential hazard weight, and the second potential hazard weight of the device interaction information.

7. A multi-device protocol monitoring and management method for power plants according to claim 6, characterized in that, The first potential hazard assessment expression for determining the application status of the equipment protocol is: Among them, the first potential hazard assessment value corresponding to the application of the y1 device protocol is l. n1 Let l be the weight of the first potential hazard corresponding to the nth device interaction information. n2 Let x be the weight of the second potential hazard corresponding to the nth device interaction information. n c represents the number of first interpretation failures for the nth device's interactive information. n Adjust the constant for the number of failed interpretations of the nth device interaction information.

8. The multi-device protocol monitoring and management method for power plants according to claim 1, characterized in that, The method for determining the second potential hazard assessment of equipment protocol application includes: obtaining the actual call frequency of the current equipment protocol and calculating and analyzing the frequency difference value compared with the upper limit of the standard call frequency range; configuring a hazard conversion adjustment coefficient for the frequency difference value according to the difference value range to which the frequency difference value belongs, and comprehensively analyzing the frequency difference value and the hazard conversion adjustment coefficient to determine the corresponding value of the second potential hazard assessment of equipment protocol application; the expression for calculating the corresponding value of the second potential hazard assessment is: Where y2 is the value corresponding to the second hidden danger assessment of the equipment protocol application status, j n∝ Let Δδ be the hidden danger conversion adjustment coefficient corresponding to the ∝th difference value interval of the nth device protocol application situation. n Let m be the frequency difference value for the application of the protocol on the nth device. n This is a constant used to adjust the frequency difference of the protocol application for the nth device.

9. A multi-device protocol monitoring and management method for power plants according to claim 1, characterized in that, The methods for conducting a comprehensive hazard assessment of equipment protocol application include a summation calculation method and a comprehensive analysis method. The summation calculation method involves adding the corresponding values ​​of the first and second hazard assessments to obtain the corresponding value of the comprehensive hazard assessment. The comprehensive analysis method involves constructing a comprehensive hazard assessment group from the first and second hazard assessments; dynamically configuring several levels of hazard warning thresholds for the first and second hazard assessments based on the current requirements for calling different equipment protocols; and determining the status of the comprehensive hazard assessment of the equipment protocol application based on the hazard assessment value being just greater than a certain level of hazard warning threshold.

10. A multi-device protocol monitoring and management system for power plants, characterized in that, include: The interface configuration strategy generation module is used to dynamically configure the network interface for each device protocol in the protocol call library, and generate an interface configuration strategy that combines the network interface and the device protocol in real time. The encryption rule management module is used to construct a first encryption rule for the interface configuration policy and send the interface configuration policy to the corresponding device side according to the first encryption rule; the risk assessment module is used to determine the correspondence between the current network interface and the device protocol according to the interface configuration policy, match the device interaction information received by the network interface with the corresponding device protocol for interpretation, and determine the first risk assessment of the application of the device protocol based on the interpretation. It is also used to identify several protocol call condition elements based on past protocol application records, and to construct a protocol call request group from several protocol call condition elements in the same time period. Based on past protocol application records, it determines the standard frequency range of different device protocol calls under the condition requirements of the protocol call request group, and constructs a protocol call frequency reference table by establishing the correspondence between the protocol call request group and the standard frequency range of different device protocol calls. The current protocol call condition elements are substituted into the protocol call frequency reference table for retrieval and analysis to determine the standard call frequency range of different device protocols. Based on the difference between the actual call frequency of different device protocols and the standard call frequency range, a second potential risk assessment of the device protocol application situation is determined. Based on the first and second potential risk assessments of the device protocol application situation, a comprehensive potential risk assessment of the device protocol application situation is performed. The interface configuration strategy adjustment module is used to adjust the interface configuration strategy based on the comprehensive potential risk assessment of the device protocol application situation.

Citation Information

Patent Citations

  • Omni-protocol engine for reconfigurable bit-stream processing in high-speed networks

    CN101578590A

  • Energy efficiency direct monitoring device based on demand response

    CN102880129A