A distributed energy storage system based on the Internet of Things

Through the Internet of Things, the security defense network and unit defense network of distributed energy storage systems are built, and the identification point positioning attack equipment is used to solve the problem of rapid positioning and response to network attacks, and the security and stability of energy storage power stations are improved.

CN119051888BActive Publication Date: 2025-07-22GUANGZHOU ENERGY STORAGE GROUP CO LTD +1

Patent Information

Application Number
CN202410995440.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-24
Publication Date
2025-07-22
Estimated Expiration
2044-07-24

AI Technical Summary

Technical Problem

The existing technology is difficult to quickly and accurately locate the network attack location of distributed energy storage power stations, resulting in the inability to respond quickly. The network attacks cause software and hardware damage to the equipment, affecting the stability of the energy storage power stations.

Method used

By obtaining device information based on the Internet of Things, a system security defense network and unit defense network are built, and the attacked equipment is located by identifying points, related channels and real-time status monitoring are established, response means are obtained, and connections are cut off from attacking equipment.

Benefits of technology

It realizes rapid monitoring and protection of distributed energy storage power plants, reduces equipment damage, improves safety management, and ensures the stability of energy storage power plants and promptly avoids hazards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119051888B_ABST
    Figure CN119051888B_ABST
Patent Text Reader

Abstract

The present invention discloses a distributed energy storage system based on the Internet of Things, which relates to the technical field of distributed energy storage. A first acquisition module is used to acquire device information of a distributed energy storage power station based on the Internet of Things. A first establishment module is connected to the acquisition module and is used to obtain protected object devices based on the device information. A second establishment module is connected to the first establishment module and is used to establish a system security defense network for the distributed energy storage power station. A second acquisition module is connected to the second establishment module and is used to acquire real-time status information of the security defense network and the unit defense network based on an associated channel. A processing module is connected to the second acquisition module and is used to acquire attacked devices based on defense information. The present invention reduces the possibility of devices being attacked and damaged, ensures the safety of the energy storage power station, can achieve timely risk avoidance, and greatly improves the safety management of the devices of the energy storage power station.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of distributed energy storage, and particularly to a distributed energy storage system based on the Internet of Things. Background Art

[0002] With the development of society and the innovation of technology, new energy has also developed rapidly and entered people's lives to a greater extent;

[0003] In the power conversion of new energy photovoltaic, energy storage power stations are an indispensable part. At present, the safety management of distributed energy storage power stations is particularly important. During network attacks in the operation of energy storage power stations, since the influence of a single device in the energy storage power station is also relatively large, there will be network attacks on the device. When a network attack is carried out on the device, it is difficult to quickly and accurately locate the attack position, and thus it is impossible to quickly respond. The network will cause damage to the software and hardware of the device, and it is difficult to ensure the stability of the energy storage system of the energy storage power station. Summary of the Invention

[0004] The purpose of the present invention is to provide a distributed energy storage system based on the Internet of Things to solve the deficiencies in the background art.

[0005] To achieve the above purpose, the present invention provides the following technical solution: A distributed energy storage system based on the Internet of Things, comprising:

[0006] A first acquisition module, configured to acquire device information of a distributed energy storage power station based on the Internet of Things, wherein the device information is a topological structure marked with device network security information and operation parameter information;

[0007] A first establishment module, connected to the acquisition module, configured to obtain protected object devices based on the device information and establish unit defense networks according to the protected object devices within the system security defense network;

[0008] A second establishment module, connected to the first establishment module, configured to establish a system security defense network for the distributed energy storage power station and build an association channel between the system security defense network and the unit defense network;

[0009] A second acquisition module, connected to the second establishment module, configured to acquire real-time status information of the security defense network and the unit defense network based on the association channel, and judge whether the real-time status information is normal based on preset conditions to obtain defense information;

[0010] A processing module, connected to the second acquisition module, configured to acquire the attacked device based on the defense information and obtain countermeasures according to the attacked device.

[0011] In a preferred embodiment, the first acquisition module includes:

[0012] An acquisition unit for acquiring multiple energy storage power station information of a distributed energy storage power station, where the energy storage power station information includes energy storage capacity and the location of the energy storage power station, constructing an electronic map based on the energy storage power station information, with multiple energy storage power stations existing in the electronic map, and using the energy storage power stations as identification points;

[0013] A storage unit, connected to the acquisition unit, for using the identification points of multiple energy storage power stations in the electronic map as storage nodes;

[0014] A construction unit, connected to the storage unit, for acquiring the internal devices based on the energy storage power station, constructing a topology structure with the devices as network nodes and storing it in the storage nodes;

[0015] An identification unit, connected to the construction unit, for identifying the network security information and operating parameter information of the devices in the topology structure as device information and storing it in the storage nodes.

[0016] In a preferred embodiment, the storage unit includes:

[0017] A setting unit for respectively connecting a server to the identification points of multiple energy storage power stations in the electronic map, setting an entry recognition code for the identification points, and entering the server based on the recognition code;

[0018] An establishment unit, connected to the setting unit, for using the server as a blockchain node, and obtaining a blockchain through a consortium of multiple blockchain nodes.

[0019] In a preferred embodiment, the first establishment module includes:

[0020] An erection unit for erecting an outer system security defense network based on the distributed energy storage power station;

[0021] An information acquisition unit for determining the protected object devices of the energy storage power station based on security preset conditions;

[0022] A collection unit, connected to the information acquisition unit, for acquiring the protection scope of the protected object devices, where the protection scope is the network protection scope of the protected object devices and the devices connected to the protected object devices;

[0023] A corresponding unit, connected to the collection unit and the erection unit, for erecting an inner layer unit defense network in the system security defense network based on the protected object devices and the protection scope information, and the unit defense network has a one-to-one correspondence with the protection scope.

[0024] In a preferred embodiment, the information acquisition unit includes:

[0025] A data acquisition unit for acquiring the safety information of equipment in an energy storage power station, where the safety information includes the historical failure times, the number of directly affected equipment, and the social value of the equipment;

[0026] A calculation unit, connected to the data acquisition unit, for calculating a safety preset condition based on the safety information, where the calculation formula for the safety preset condition is:

[0027] where θ τ is the safety preset condition, n1 is the historical failure times, α is the equipment impact weight, n2 is the number of directly affected equipment, and s j is the social value of the equipment;

[0028] A judgment unit, connected to the calculation unit, for determining the equipment corresponding to the safety preset condition higher than the preset value as the protected object equipment.

[0029] In a preferred embodiment, the second establishment module includes:

[0030] A safety defense unit for establishing a system safety defense network based on a distributed energy storage power station, where the system safety defense network is a firewall;

[0031] A corresponding unit, connected to the safety defense unit, for obtaining the defense corresponding information between the system safety defense network and the equipment based on the equipment location, where the defense corresponding information includes the range information of the system safety defense network corresponding to the equipment defense;

[0032] A setting unit, connected to the corresponding unit, for corresponding the unit defense network with the system safety defense network based on the range information, and establishing an association channel between the unit defense network and the system safety defense network, where the association channel includes multiple identification points set between the unit defense network and the system safety defense network, and the identification points include the operation data of the unit defense network and the system safety defense network and the security password of the association channel.

[0033] In a preferred embodiment, the second acquisition module includes:

[0034] A real-time acquisition unit for acquiring the real-time status information of the safety defense network and the unit defense network based on the identification points in the association channel, where the real-time status information includes connection status information, log information, rule configuration information, and the security password status information of the identification points;

[0035] An information judgment unit, connected to the fact acquisition unit, for setting preset conditions for the real-time status information respectively, and judging the real-time status information exceeding the preset conditions as abnormal information and using it as defense information.

[0036] In a preferred embodiment, the processing module includes:

[0037] The first processing unit is used to obtain the corresponding unit defense network based on the defense information of the abnormal state, and obtain the attacked device based on the unit defense network;

[0038] The second processing unit is connected to the first processing unit and is used to obtain the connection information of the attacked device participating in the operation of the energy storage power station. The connection information includes the connection method and the connection location. Based on the connection information, the connection between the attacked device and the energy storage power station is cut off as a countermeasure, and at the same time, it is displayed in the corresponding topological structure.

[0039] In the above technical solution, the technical effects and advantages provided by the present invention are:

[0040] The present invention has a good monitoring and protection effect, locates the specific attacked device according to the recognition point, and then can perform operation responses according to the specific attacked device subsequently. At the same time, it can also give a certain judgment buffer time for the operation response, can quickly respond, reduce the possibility of the device being damaged by the attack, ensure the safety of the energy storage power station, can achieve timely risk avoidance, and greatly improve the safety management of the energy storage power station equipment. Description of the Drawings

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0042] Figure 1 It is the system block diagram of the present invention. Detailed Embodiments

[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0044] Embodiment 1. Please refer to Figure 1 As shown, the distributed energy storage system based on the Internet of Things described in this embodiment includes:

[0045] The first acquisition module is used to acquire the device information of the distributed energy storage power station based on the Internet of Things. The device information is a topological structure marked with device network security information and operation parameter information;

[0046] The first establishment module, connected to the acquisition module, is used to obtain the protected object device based on the device information, and establish a unit defense network within the system security defense network according to the protected object device;

[0047] The second establishment module, connected to the first establishment module, is used to establish the system security defense network of the distributed energy storage power station and build an association channel between the system security defense network and the unit defense network;

[0048] The second acquisition module, connected to the second establishment module, is used to obtain the real-time status information of the security defense network and the unit defense network based on the association channel, and judge whether the real-time status information is normal based on preset conditions to obtain defense information;

[0049] The processing module, connected to the second acquisition module, is used to obtain the attacked device based on the defense information and obtain countermeasures according to the attacked device;

[0050] Furthermore, with the development of society and the innovation of technology, new energy has also developed rapidly and entered people's lives to a greater extent;

[0051] In the power conversion of new energy photovoltaic, the energy storage power station is an indispensable department. At present, the safety management of distributed energy storage power stations is particularly important. During network attacks when the energy storage power station is operating, since the influence of a single device in the energy storage power station is also relatively large, there will be network attacks on the device. When conducting a network attack on the device, it is difficult to quickly and accurately locate the attack position, and thus it is impossible to quickly respond. The network will cause damage to the software and hardware of the device, and it is difficult to ensure the stability of the energy storage system of the energy storage power station. However, in this application, it has a good monitoring and protection effect, and the specific attacked device is located according to the identification point. Subsequently, operations and reactions can be carried out according to the specific attacked device, and at the same time, a certain judgment buffer time can be given to the operation reaction, enabling a quick response, reducing the possibility of the device being damaged by the attack, ensuring the safety of the energy storage power station, being able to avoid risks in a timely manner, and greatly improving the safety management of the energy storage power station equipment;

[0052] In one embodiment, the first acquisition module includes:

[0053] An acquisition unit, used to acquire multiple energy storage power station information of the distributed energy storage power station. Among them, the energy storage power station information includes the energy storage capacity and the location of the energy storage power station. An electronic map is constructed based on the energy storage power station information. There are multiple energy storage power stations in the electronic map, and the energy storage power stations are used as identification points;

[0054] A storage unit, connected to the acquisition unit, is used to use the identification points of multiple energy storage power stations in the electronic map as storage nodes;

[0055] The construction unit is connected to the storage unit and is used to obtain the internal devices of the energy storage power station based on the energy storage power station, construct a topological structure with the devices as network nodes, and store it in the storage node;

[0056] The identification unit is connected to the construction unit and is used to identify the network security information and operation parameter information of the devices in the topological structure as device information and store it in the storage node;

[0057] In one embodiment, since the distributed energy storage power stations are located in many places and are relatively distributed, it is necessary to obtain the information of a single energy storage power station in the distributed energy storage power station. Among them, the information of a single energy storage power station includes the energy storage capacity and the location of a single energy storage power station. Based on this information, the information of a single energy storage power station can be understood, and then the location relationship between single energy storage power stations can be obtained, and an electronic map can be constructed. The electronic map consists of multiple energy storage power stations, and the energy storage power stations are reflected in the electronic map through identification points. Each identification point is used as a storage node to store the information of a single energy storage power station. Based on the energy storage power station, its internal devices are obtained, and a topological structure is constructed with the devices as network nodes and stored in the storage node. In the topological structure, the network security information and operation parameter information of the devices are identified as device information. Among them, the network security information is information related to network security stability such as the network stability data and network access data of the devices, and the operation parameter information is the operation parameters of the devices during the working process, such as temperature, current, voltage and other operation parameter information. Then, the network security information and operation parameter information in the devices are identified as device information in the topological structure, and the management of the devices in the distributed energy storage power station can be reflected through the topological structure;

[0058] In one embodiment, the storage unit includes:

[0059] The setting unit is used to connect a server to each identification point of multiple energy storage power stations in the electronic map respectively, set an entry identification code for the identification point, and enter the server based on the identification code;

[0060] The establishment unit is connected to the setting unit and is used to use the server as a blockchain node, and multiple blockchain nodes obtain a blockchain through a protocol alliance;

[0061] Further explanation, there are multiple identification points of energy storage power stations in the electronic map. One identification point corresponds to one server, and thus the subsequent relevant information of the energy storage power station can be stored corresponding to the server. Enter the server based on the identification point, and set an entry identification code in the identification point, which is equivalent to a password for entering the server from the identification point. Subsequent personnel can enter the server according to the output of this password. Multiple servers are used as blockchain nodes, and each blockchain node obtains a blockchain through a protocol alliance, which can greatly improve the security management of information and also better assist in the storage of information;

[0062] In one embodiment, the first establishment module includes:

[0063] A construction unit, configured to build an outer - layer system security defense network based on a distributed energy storage power station;

[0064] An information acquisition unit, configured to determine protected target devices of the energy storage power station based on security preset conditions;

[0065] An acquisition unit, connected to the information acquisition unit, configured to acquire the protection scope of the protected target devices, where the protection scope is the network protection scope of the protected target devices and the devices connected to the protected target devices;

[0066] A corresponding unit, connected to the acquisition unit and the construction unit, configured to build an inner - layer unit defense network within the system security defense network based on the protected target devices and protection scope information, and the unit defense network has a one - to - one correspondence with the protection scope;

[0067] Further explanation, for a monitoring system of a distributed energy storage, in terms of its security protection, first, a system - wide system security defense network is formulated for the devices in the system, and this system security defense network is set on the outer layer. Then, based on the acquisition conditions, the protected target devices of the device information are determined, where the acquisition conditions are the security preset conditions of network security information, which can acquire the devices that need to be key - protected and provide corresponding protection. Then, according to the protection scope of the protected target devices, an inner - layer unit defense network is built within the system security defense network, and the unit defense network is a unit defense network centered on the protected target devices, and there is a situation where the unit defense networks overlap. It is possible that one device is protected by multiple unit defense networks. The multiple unit protection networks are independent of each other, and all have security protection functions in the overlapping part. If a device is under a network attack, since it is covered by multiple overlapping unit defense networks, therefore, multiple unit defense networks will all respond and give early warnings. Furthermore, the importance of the invaded device can be understood, where the importance is the number of unit defense networks covering the device, representing that the device has information inter - communication with more other devices. If this device is attacked, it will have a greater impact, and it has a good early - warning protection function, improving the safe operation of distributed energy storage devices;

[0068] In one embodiment, the information acquisition unit includes:

[0069] A data acquisition unit, configured to acquire the security information of the devices in the energy storage power station, where the security information includes the number of historical faults, the number of directly affected devices, and the social value of the devices;

[0070] A calculation unit, connected to the data acquisition unit, configured to calculate the security preset conditions based on the security information, where the calculation formula of the security preset conditions is:

[0071] Among them, θ τ is the safety preset condition, n1 is the number of historical failures, α is the equipment impact weight, n2 is the number of directly affected devices, and s j is the social value of the device. It should be noted that the larger the values of n1, and s j , the larger the value of θ τ , which represents a greater impact degree of the device and a higher safety preset condition;

[0072] The judgment unit is connected to the calculation unit and is used to determine the device corresponding to the safety preset condition higher than the preset value as the protected object device;

[0073] Furthermore, obtain the safety information of the devices in the energy storage power station. Among them, the safety information includes the number of historical failures, the number of directly affected devices, and the social value of the devices. In addition, the data of directly affected devices represents the number of other devices directly affected by a device failure. The profile, the social value of the device is the purchase price, which can reflect the value of the device and thus the impact of damage. According to the safety information, the safety preset condition can be calculated, and then the safety preset condition is screened according to the preset value, and the device corresponding to the safety preset condition higher than the preset value is determined as the protected object device, which has a good safety control effect on the protected object device, greatly improves the accuracy of the safety evaluation of the device, and facilitates the safety protection management of the device;

[0074] In one embodiment, the second establishment module includes:

[0075] The security defense unit is used to establish a system security defense network based on the distributed energy storage power station. Among them, the system security defense network is a firewall;

[0076] The corresponding unit is connected to the security defense unit and is used to obtain the defense corresponding information between the system security defense network and the device based on the device location. Among them, the defense corresponding information includes the range information of the system security defense network corresponding to the device defense;

[0077] The setting unit is connected to the corresponding unit and is used to correspond the unit defense network with the system security defense network based on the range information, and establish an association channel between the unit defense network and the system security defense network. Among them, the association channel includes multiple identification points set between the unit defense network and the system security defense network. The identification points include the recorded operation data of the unit defense network and the system security defense network and the association channel security password;

[0078] Further explanation: A system security defense network is constructed for the energy storage power station. Among them, the system security defense network is a firewall, and the unit defense network is also an anti-firewall. The system security defense network firewall is for the energy storage power station, and the unit defense network firewall is for a single device in the energy storage power station. At the same time, the unit defense network corresponds to multiple associated devices involved in a single device. After the system security defense network is established, there is also a certain corresponding relationship between the system security defense network and the device. Therefore, the corresponding information between the device and the system security defense network is obtained and used as the defense corresponding information. Then, the defense corresponding information includes the range information of the system security defense network corresponding to the device defense. After that, the unit defense network and the system security defense network are corresponded according to the range information. Then, an association channel is established between the unit defense network and the system security defense network according to the corresponding relationship. This association channel is not a real channel. It is to set several identification points between the unit defense network and the system security defense network. These several identification points serve as the association channel. Among them, the identification point includes the operation data of the unit defense network and the system security defense network and the security password of the association channel recorded. Each identification point has a security password for the association channel. When attacking the device through the network, it can be resisted through the security password of the identification point when invading the system security defense network. There are several layers of resistance behaviors for several identification points, which has a good effect of protecting the device, can greatly improve the security management of the device, avoid the harm degree of network attack intrusion, and ensure the safety of the operation of the energy storage power station;

[0079] In one embodiment, the second acquisition module includes:

[0080] A real-time acquisition unit, which is used to acquire the real-time status information of the security defense network and the unit defense network based on the identification points in the association channel. Among them, the real-time status information includes connection status information, log information, rule configuration information, and the security password status information of the identification points;

[0081] An information judgment unit, which is connected to the real-time acquisition unit, and is used to set preset conditions for the real-time status information respectively. The real-time status information that exceeds the preset conditions is judged as abnormal information and used as defense information;

[0082] Further explanation: Obtain the real-time status information of the security defense network and the unit defense network through the identification points. Among them, the real-time status information includes connection status information, log information, rule configuration information, and the security password status information of the identification points. Among them, the connection status information is the connection status of the monitoring firewall with other devices, including the connection status with internal network devices and the connection status with external network devices. The log information is the log information of the monitoring firewall, including the log generation volume, log type, and log content, etc., so as to discover and solve security incidents in a timely manner; the log information of the monitoring firewall, including the log generation volume, log type, and log content, etc., so as to discover and solve security incidents in a timely manner. The security password status information of the identification points is the number of times the security password is attacked. Preset conditions are respectively set for the real-time status information. The real-time status information that exceeds the preset conditions is judged as abnormal information and used as defense information, which has a good monitoring and protection effect. And the specific device under attack is located according to the identification point. Then, subsequent operations can be carried out according to the specific device under attack, and at the same time, a certain judgment buffer time can be given to the operation reaction, which has an effective protection effect;

[0083] In one embodiment, the processing module includes:

[0084] The first processing unit is used to obtain the corresponding unit defense network based on the defense information in the abnormal state, and obtain the attacked device based on the unit defense network;

[0085] The second processing unit is connected to the first processing unit and is used to obtain the connection information of the attacked device participating in the operation of the energy storage power station. Among them, the connection information includes the connection method and the connection location. Based on the connection information, the connection between the attacked device and the energy storage power station is cut off as a countermeasure, and at the same time, it is displayed in the corresponding topological structure;

[0086] Further explanation: When the defense information in the abnormal state is collected through the identification points, the corresponding unit defense network is obtained according to the identification points. Through the unit defense network, the corresponding attacked device can be obtained. The connection information of the attacked device participating in the operation of the energy storage power station is obtained. Among them, the connection information includes the connection method and the connection location. Based on the connection information, the connection between the attacked device and the energy storage power station is cut off and at the same time it is displayed in the corresponding topological structure. It can accurately understand the location where the energy storage power station is abnormally attacked currently, take corresponding countermeasures for the corresponding equipment, be able to react quickly, avoid the attacked device from being damaged, ensure the safety of the energy storage power station, be able to take timely evasive actions, and greatly improve the safety management of the energy storage power station equipment.

[0087] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the said claims.

Claims

1. A distributed energy storage system based on the Internet of Things, characterized in that, Including: A first acquisition module, configured to acquire device information of a distributed energy storage power station based on the Internet of Things, where the device information is a topological structure marked with device network security information and operating parameter information; A first establishment module, connected to the acquisition module, configured to obtain protected object devices based on the device information, and establish a unit defense network according to the protected object devices within the system security defense network; A second establishment module, connected to the first establishment module, configured to establish a system security defense network for the distributed energy storage power station, and build an association channel between the system security defense network and the unit defense network; A second acquisition module, connected to the second establishment module, configured to acquire real-time status information of the security defense network and the unit defense network based on the association channel, and judge whether the real-time status information is normal based on preset conditions to obtain defense information; A processing module, connected to the second acquisition module, configured to acquire the attacked devices based on the defense information, and obtain countermeasures according to the attacked devices; The first establishment module includes: A building unit, configured to build an outer system security defense network based on the distributed energy storage power station; An information acquisition unit, configured to determine the protected object devices of the energy storage power station based on security preset conditions; A collection unit, connected to the information acquisition unit, configured to acquire the protection scope of the protected object devices, where the protection scope is the network protection scope of the protected object devices and the devices connected to the protected object devices; A corresponding unit, connected to the collection unit and the building unit, configured to build an inner unit defense network within the system security defense network based on the protected object devices and the protection scope information, and there is a one-to-one correspondence between the unit defense network and the protection scope; The information acquisition unit includes: A data acquisition unit, configured to acquire the security information of the devices in the energy storage power station, where the security information includes the historical failure times, the number of directly affected devices, and the social value of the devices; A calculation unit, connected to the data acquisition unit, configured to calculate the security preset conditions based on the security information, where the calculation formula of the security preset conditions is: ϑ_τ = ln[n_1 * α^(n_2) √(s_j)], where ϑ_τ is the security preset condition, n_1 is the historical failure times, α is the device influence weight, n_2 is the number of directly affected devices, and s_j is the social value of the device; A judgment unit, connected to the calculation unit, configured to determine the devices corresponding to the security preset conditions higher than the preset value as the protected object devices.

2. The distributed energy storage system based on the Internet of Things according to claim 1, characterized in that: The first acquisition module includes: An acquisition unit, configured to acquire multiple energy storage power station information of the distributed energy storage power station, where the energy storage power station information includes the energy storage capacity and the location of the energy storage power station, build an electronic map based on the energy storage power station information, there are multiple energy storage power stations in the electronic map, and use the energy storage power stations as identification points; A storage unit, connected to the acquisition unit, configured to use the identification points of multiple energy storage power stations in the electronic map as storage nodes; A construction unit, connected to the storage unit, configured to acquire the internal devices based on the energy storage power station, build a topological structure with the devices as network nodes and store it in the storage nodes; An identification unit, connected to the construction unit, is used to identify the network security information and operating parameter information of the device in the topological structure as device information and store it in the storage node.

3. The distributed energy storage system based on the Internet of Things according to claim 2, characterized in that: The storage unit includes: A setting unit, which is used to connect a server to each identification point of multiple energy storage power stations in the electronic map respectively, set an entry identification code for the identification point, and enter the server based on the identification code; A building unit, connected to the setting unit, is used to use the server as a blockchain node, and multiple blockchain nodes obtain a blockchain through a protocol alliance.

4. A distributed energy storage system based on the Internet of Things according to claim 1, characterized in that: The second building module includes: A security defense unit, which is used to establish a system security defense network based on the distributed energy storage power station. Among them, the system security defense network is a firewall; A corresponding unit, connected to the security defense unit, is used to obtain the defense corresponding information between the system security defense network and the device based on the device location. Among them, the defense corresponding information includes the range information of the system security defense network corresponding to the device defense; A setting unit, connected to the corresponding unit, is used to correspond the unit defense network with the system security defense network based on the range information, and establish an association channel between the unit defense network and the system security defense network. Among them, the association channel includes multiple identification points set between the unit defense network and the system security defense network. The identification point includes the operating data of the unit defense network and the system security defense network and the security password of the association channel.

5. A distributed energy storage system based on the Internet of Things according to claim 1, characterized in that: The second acquisition module includes: A real-time acquisition unit, which is used to obtain the real-time status information of the security defense network and the unit defense network based on the identification points in the association channel. Among them, the real-time status information includes connection status information, log information, rule configuration information, and the security password status information of the identification point; An information judgment unit, connected to the fact acquisition unit, is used to set preset conditions for the real-time status information respectively, and judge the real-time status information exceeding the preset conditions as abnormal information and use it as defense information.

6. The distributed energy storage system based on the Internet of Things according to claim 1, wherein: The processing module includes: A first processing unit, which is used to obtain the corresponding unit defense network based on the defense information in the abnormal state, and obtain the attacked device based on the unit defense network; A second processing unit, connected to the first processing unit, is used to obtain the connection information of the attacked device participating in the operation of the energy storage power station. Among them, the connection information includes the connection method and the connection location, cut off the connection between the attacked device and the energy storage power station based on the connection information as a countermeasure, and at the same time display it in the corresponding topological structure.

Citation Information

Patent Citations

  • Power Internet of Things security defense method and system, storage medium and server

    CN114143348A

  • Joint defence method and apparatus for network security, and server and storage medium

    US20190098027A1

Cited By

  • Energy storage power station remote authorization locking system based on Internet of Things

    CN122394231A