A cpps distributed security state estimation method based on cross-domain authentication and asynchronous admm

By combining cross-domain authentication and asynchronous ADMM, the problems of data transmission security and cross-domain authentication efficiency of smart terminals are solved, the security and real-time performance of distributed state estimation are optimized, and effective prevention and rapid recovery from network attacks are achieved.

CN119210829BActive Publication Date: 2025-10-24SHANGHAI UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411308167.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-19
Publication Date
2025-10-24
Estimated Expiration
2044-09-19

AI Technical Summary

Technical Problem

In existing technologies, smart terminal data transmission security is insufficient, cross-domain authentication efficiency and security are inadequate, distributed state estimation is vulnerable to network attacks, and problems such as asynchronous computing, data packet loss and latency have not been effectively solved.

Method used

A distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is adopted for CPPS. The power grid area is divided by K-means to establish a distributed security state estimation framework. Combining active defense mechanism and passive detection technology, the asynchronous ADMM algorithm is used for state update, and KL divergence detection is introduced to prevent network attacks.

Benefits of technology

It significantly improves the security level of distributed systems, optimizes system operating efficiency, enhances the real-time performance and reliability of data processing, enables rapid recovery to normal operation, and resists denial-of-service attacks and fake data injection attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119210829B_ABST
    Figure CN119210829B_ABST
Patent Text Reader

Abstract

The application provides a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM, and relates to the technical field of network security and state estimation. The method comprises the following steps: dividing the power grid region into several sub-regions by using a K-means algorithm to reduce global communication and calculation load; establishing a distributed security state estimation framework covering a physical layer, a network layer and a service layer; performing authentication and state iteration of the sub-region state estimator, including registration, cross-domain authentication, K-L divergence calculation and state update; and applying an asynchronous alternating direction multiplier method (ADMM) algorithm, so that the sub-region state estimator can be iterated without waiting for state update of all adjacent sub-regions. The application effectively deals with data packet loss, denial of service (DoS) attacks and false data injection (FDI) attacks by combining active defense and passive detection, and reduces the delay influence of network transmission and cross-domain security authentication calculation. The faster convergence speed and stronger attack resistance of the method are proved by an example.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security and state estimation, and particularly relates to a CPPS distributed secure state estimation method based on cross-domain authentication and asynchronous ADMM. BACKGROUND

[0002] With the continuous development of the cyber-physical power system (CPPS), the intelligent terminal faces many security problems in the process of data transmission. In the prior art, for the data transmission of the intelligent terminal of the CPPS, the commonly used technical solution includes the certificateless aggregated signcryption (CLASC) scheme, which attempts to ensure the security of data in the transmission process. However, since the intelligent terminal operates in a resource-limited environment, the security of its data transmission is still threatened. Although the certificateless aggregated signcryption scheme provides a certain protection, there are still potential security risks.

[0003] In terms of cross-domain communication, the intelligent terminal in the CPPS needs to share and interact data between different domains. The existing security authentication mechanism often cannot meet the efficient and secure needs in the cross-domain environment. Although some schemes attempt to use blockchain technology for cross-domain security authentication, the existing technology still has room for improvement in authentication efficiency and security in the environment of data heterogeneity and resource limitation.

[0004] In addition, in the distributed state estimation, the state estimators of each sub-area cooperate through the information network. However, this mode of information exchange makes the system vulnerable to various network attacks, such as denial of service attacks (DoS attacks) and fake data injection attacks (FDI attacks). The existing technical solutions have not fully solved these security problems, especially when dealing with asynchronous computation, data packet loss and delay in distributed state estimation, more effective defense measures are still needed. Therefore, improving the security and effectiveness of the distributed state estimation system has become the focus of current research. SUMMARY

[0005] In order to solve the technical problems of insufficient security of intelligent terminal data transmission, insufficient efficiency and security of cross-domain authentication, and vulnerability to network attacks in distributed state estimation in the prior art, the present application provides a CPPS distributed secure state estimation method based on cross-domain authentication and asynchronous ADMM.

[0006] In the prior art, although the certificateless aggregate signcryption (CLASC) scheme provides certain protection for data transmission, the security still has hidden dangers due to the limited resources of intelligent terminals. For cross-domain communication, the existing security authentication mechanism cannot meet the efficient and secure needs, although some schemes adopt blockchain technology, but still need to be improved in the environment of data heterogeneity and resource limitation. In addition, the information exchange mode in distributed state estimation is vulnerable to denial of service (DoS) attacks and false data injection (FDI) attacks, and the existing scheme is still insufficient in handling asynchronous computation, data packet loss and delay.

[0007] The technical scheme provided by the application is as follows:

[0008] The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the application comprises:

[0009] S1, dividing the entire power grid region into several sub-regions based on K-means, so as to reduce the global communication cost and computing load;

[0010] S2, establishing a distributed security state estimation framework in each state estimator in the sub-region, the framework comprising a physical layer, a network layer and a business layer, each sub-region comprising a state estimator;

[0011] S3, authentication and state iteration of the sub-region state estimator:

[0012] S3a, the state estimator of the sub-region registers with the KGC;

[0013] S3b, the state estimator of the sub-region performs cross-domain authentication and exchanges boundary node state information;

[0014] S3c, the state estimator of the sub-region performs K-L divergence calculation on the received boundary node state information, and judges whether it is within the threshold interval;

[0015] S3d, according to the received part of the adjacent sub-region boundary node information, the state is updated, and it is judged whether it converges, if not, the next iteration is entered;

[0016] S4, introducing an asynchronous alternating direction multiplier method (ADMM) algorithm, so that each state estimator of the sub-region can perform the next iteration without waiting for the state update of all adjacent sub-regions.

[0017] The technical scheme provided by the application has at least the following beneficial effects:

[0018] (1) In the present application, the active defense mechanism and passive detection technology are combined, and a distributed security state estimation scheme based on cross-domain authentication and asynchronous alternating direction multiplier method (ADMM) is proposed for the security problem in distributed state estimation. The scheme not only effectively resists the data packet loss problem, but also effectively prevents denial of service attacks (DoS attacks) and false data injection attacks (FDI attacks), two common network attacks. By combining the active defense mechanism with the passive detection technology, the overall security protection level of the distributed system is significantly improved, thereby ensuring the stable operation of the system in various complex attack environments.

[0019] (2) In the present application, by introducing the asynchronous ADMM algorithm and cross-domain authentication technology, the delay influence caused by network transmission and cross-domain security authentication calculation cost is effectively reduced. The application of asynchronous ADMM allows local state estimation to be calculated asynchronously without the need for all adjacent sub-regional state estimators to complete the calculation, thereby significantly reducing the delay caused by data transmission and authentication process. This mechanism optimizes the operation efficiency of the system, improves the real-time performance of data processing, and ensures the efficient operation of the system in high-load and high-complexity environments.

[0020] (3) In the present application, the distributed state estimation shows fast convergence speed and excellent anti-attack ability. The design of this scheme takes into account various complex situations in practical applications, and can quickly recover to normal state and maintain the stability of the system when facing network attacks and data transmission challenges. The innovative algorithm design and efficient authentication mechanism not only enhance the defense ability of the system against attacks, but also optimize the data processing process, improve the reliability and response speed of the system in practical applications. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0022] Figure 1 A flowchart of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiments of the present application is shown in the figure.

[0023] Figure 2 A distributed security state estimation framework structure diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiments of the present application is shown in the figure.

[0024] Figure 3A distributed security state estimation framework process schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0025] Figure 4 A power transmission line equivalent model schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0026] Figure 5 A synchronous ADMM iteration schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0027] Figure 6 An asynchronous ADMM iteration schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0028] Figure 7 A sub-region division result schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0029] Figure 8 A synchronous ADMM sub-region 1 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0030] Figure 9 A synchronous ADMM sub-region 2 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0031] Figure 10 A synchronous ADMM sub-region 3 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0032] Figure 11 A synchronous ADMM sub-region 4 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0033] Figure 12 A synchronous ADMM sub-region 5 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the application.

[0034] Figure 13A synchronization ADMM sub-region state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0035] Figure 14 An asynchronous ADMM sub-region 1 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0036] Figure 15 An asynchronous ADMM sub-region 2 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0037] Figure 16 An asynchronous ADMM sub-region 3 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0038] Figure 17 An asynchronous ADMM sub-region 4 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0039] Figure 18 An asynchronous ADMM sub-region 5 state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0040] Figure 19 An asynchronous ADMM sub-region state estimation error schematic diagram of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0041] Figure 20 A sub-region 1 state estimation error schematic diagram under FDI attack of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0042] Figure 21 A sub-region 2 state estimation error schematic diagram under FDI attack of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0043] Figure 22 A sub-region 3 state estimation error schematic diagram under FDI attack of a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM provided by the embodiment of the present application;

[0044] Figure 23 A sub-region 4 state estimation error schematic diagram under FDI attack of a CPPS distributed secure state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the present application.

[0045] Figure 24 A sub-region 5 state estimation error schematic diagram under FDI attack of a CPPS distributed secure state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the present application.

[0046] Figure 25 A sub-region 5 state estimation error schematic diagram under FDI attack of a CPPS distributed secure state estimation method based on cross-domain authentication and asynchronous ADMM is provided for the embodiment of the present application. DETAILED DESCRIPTION

[0047] The technical solutions in the present application will be described below with reference to the drawings.

[0048] In the embodiments of the present application, the words such as "example", "for example" and the like are used to represent as an example, illustration or description. Any embodiment or design scheme described as "example" in the present application should not be interpreted as more preferred or more advantageous than other embodiments or design schemes. Rather, the word "example" is intended to present the concept in a specific manner. In addition, in the embodiments of the present application, the meaning expressed by "and / or" can be both, or can be one of the two.

[0049] In the embodiments of the present application, "image" and "picture" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized. "Of", "corresponding" and "corresponding" can be used interchangeably at times, and it should be pointed out that the meanings expressed are consistent when the distinction is not emphasized.

[0050] In the embodiments of the present application, sometimes the subscript such as W1 can be mistakenly used in the form of non-subscript such as W1, and the meanings expressed are consistent when the distinction is not emphasized.

[0051] In order to make the technical problems, technical solutions and advantages to be solved by the present application more clear, the following will be described in detail with reference to the drawings and specific embodiments.

[0052] Reference is made to the accompanying drawings and specific embodiments described in the specification Figure 1 , a flowchart of a CPPS distributed secure state estimation method based on cross-domain authentication and asynchronous ADMM is shown.

[0053] The embodiment of the application provides a CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM, and a processing flow can include the following steps:

[0054] In the distributed state estimation, the whole system can be divided into a plurality of sub-regions, and nodes in each sub-region exchange and calculate state information, so that the global communication cost and the calculation load are reduced, and the robustness of the system is improved. For large-scale power grid partition, in order to balance the calculation cost of each sub-region state estimator and reduce the communication cost between each sub-region state estimator. Each subsystem should have as similar size (i.e. node number) as possible, and each subsystem and the subsystem should have less connection lines. Therefore, the embodiment of the application adopts K-means-based region division for large-scale power grid, and the steps are as follows:

[0055] Firstly, the system structure is abstracted into a weighted undirected graph according to graph theory. The power nodes and the generators are regarded as points, and the branches (i.e. the connection relationship of power equipment such as transmission lines and transformers in the power system) are regarded as edges. It is assumed that there are N nodes and L edges in the undirected graph, and the connection matrix C L is used to represent the connection relationship between nodes, that is:

[0056]

[0057] If the connection weight w ij is used to represent the cost paid for destroying the connection between node i and node j, the weight matrix W L of the connection matrix C L is defined, that is:

[0058]

[0059] According to the principle of the K-means clustering algorithm, the distortion function is defined as:

[0060]

[0061] Wherein, k represents that there are k clustering centers in total, C j represents the jth center, index is a vector, which represents the index (the range is 1 to k) of each node to the corresponding clustering center, w i· represents the ith row of the weight matrix.

[0062] In order to obtain the optimal solution of the distortion function, the partition cost function is defined as:

[0063]

[0064] Wherein, Pi represents the matrix obtained by mapping the index vector index.

[0065] Based on the above, the partitioning process based on the K-means method is as follows:

[0066] 1) Numerical preparation: collect the node data of the power grid (including the position information of the nodes, load data, power generation information, etc.) and determine the relevant weights according to the distance between the nodes, the size of the current, the importance of the load and other parameters;

[0067] 2) Selection of cluster centers: select k cluster centers;

[0068] 3) Cluster assignment: for each node, calculate its distance from each cluster center and assign it to the cluster where the nearest cluster center is located, to obtain the index index of the corresponding cluster center of each node;

[0069] 4) Cost calculation: calculate the disconnection cost C according to the index index obtained in step 3 cost ;

[0070] 5) Repeat iteration: repeat the cluster assignment and cost calculation until the termination condition (k clusters do not change or the cost function C cost is less than the threshold value) is met.

[0071] To protect the sharing of boundary node state information between sub-area state estimators, embodiments of the present application design a distributed secure state estimation framework based on cross-domain security authentication, and the specific content is as follows:

[0072] The distributed secure state estimation framework can be modeled as three layers, namely the physical layer, the network layer and the business layer, as shown in Figure 2 .

[0073] 1) Physical layer: the physical layer represents the actual large-scale power grid, which is divided into different sub-areas according to the power grid partitioning result. Each sub-area includes internal nodes and boundary nodes. Each sub-area includes a state estimator, and exchanges state information of boundary nodes with state estimators of adjacent sub-areas to realize cooperation.

[0074] 2) Network layer: according to the content of Chapter 3, each sub-area state estimator (regarded as the intelligent terminal of the area) should be registered to the KGC of the area by the gateway, mutually authenticated with the state estimators of adjacent sub-areas, and data exchanged and negotiated with the state estimators of adjacent sub-areas.

[0075] 3) Business layer: including the registration information of the sub-area state estimator published by the KGC, and the registration information of other STs in the CPPS.

[0076] The specific process is as Figure 3As shown, first, the sub-region state estimator registers with the KGC to which it belongs; then, it performs cross-domain authentication with adjacent sub-region state estimators and exchanges boundary node state information, performs K-L divergence calculation on the received boundary node state information, and judges whether it is within the threshold interval; finally, it performs state update according to the received part of the adjacent sub-region boundary node information, judges whether it converges, and if not, enters the next iteration.

[0077] The DC model obtained by simplifying the AC model has faster calculation speed and can be used for fast preliminary analysis of large-scale power grids, and embodiments of the present application mainly consider distributed security state estimation under the DC model. The following conditions are introduced to convert the nonlinear relationship of the AC model into the linear relationship of the DC model:

[0078] 1) Assuming that the voltage phase difference between two nodes is very small, i.e. ij ≈θ ij ,cosθ ij ≈1;

[0079] 2) The voltage amplitude of the node is close to the unit quantity 1 p.u.;

[0080] 3) For a transmission branch, the branch conductance is much smaller than the branch susceptance, i.e. ij <<b ij .

[0081] The charging power is attributed to the load power, and the equivalent model of the transmission line is obtained as Figure 4 The current, complex power and active power of the branch from node i to node j in the AC model are respectively:

[0082]

[0083] Substituting the simplified conditions, the active power and reactive power of the DC model branch are obtained:

[0084]

[0085] Q ij =0

[0086] Therefore, the active power injected into node i is:

[0087]

[0088] wherein, is an N-dimensional vector, and the DC model of the power grid can be obtained according to the above formula:

[0089]

[0090] where z includes the measurements of node injection power and branch power, H is the measurement matrix, and v is the measurement error (with mean 0 and Gaussian distribution with variance R v The relationship between the measurement value and the state value of each sub-area is as follows:

[0091] z i = H i θ i +v i

[0092]

[0093] where z i is the measurement value of the sub-area i, H i is the measurement matrix of the sub-area i, θ i is the state variable of the extended area, including the state variable θ i,int of the internal node of the sub-area i and the state variable θ i [j] (j ∈ N i , N i is a set of sub-areas adjacent to the sub-area i) of the boundary node of the adjacent area of the sub-area i, v i is the measurement noise of the sub-area i, and v i ~ N(0, R i ) is a Gaussian distribution.

[0094] According to the principle of minimum error square, a target function with boundary constraints is constructed:

[0095]

[0096] where J(θ i ) is the target function of the state estimation of the sub-area i, W i is the corresponding weight matrix, and the intermediate variable θ ij and the boundary connection matrix D ij are introduced, so that θ i [j] = θ j [i] = θ ij = D ij θ i , and it is derived that:

[0097]

[0098] According to the alternating vector multiplier method for solving the minimum problem with equality constraints, first, the target function is brought into the augmented Lagrange matrix, and the Lagrange multiplier is scaled to obtain:

[0099]

[0100] Among them, ρ is the penalty parameter, u i,j is the telescopic Lagrange multiplier. The corresponding iterative steps are:

[0101]

[0102] Will Substitute into It can be introduced in:

[0103]

[0104] Substituting formula (2) into formula (1) yields:

[0105]

[0106] The above equation shows that the state variables of each subregion are solved completely independently, allowing for distributed parallel computing. Only boundary state information needs to be exchanged with adjacent subregions, reducing communication costs. However, during iterative computing, information from all adjacent subregion nodes must be received before the next iteration can proceed.

[0107] In actual scenarios, the computational load and speed of each sub-area state estimator in a large-scale power grid vary due to issues such as the number of nodes, synchronization period, and computing resources of the equipment. Consequently, the computational time required to complete local state estimation also varies. Furthermore, as the scale of the CPPS information network continues to expand and the network environment becomes increasingly complex, the likelihood of data packet loss and transmission delays occurring in the collaboration of each sub-area state estimator due to insufficient network resources, attacks, or the adoption of data protection schemes has greatly increased. Using the classic ADMM algorithm will not be able to effectively address the issues of data packet loss and transmission delays, and the iterative computation time will be long. To address these issues, the ADMM algorithm is modified to achieve asynchronous computation:

[0108] Assume that there are N adjacent subregions i | sub-regions, received p i The boundary node information of adjacent sub-areas is required to receive at least p[|N i |](1≤p[|N i |]≤N i ) adjacent sub-regions’ boundary node information can be updated next time, i.e. i ≥p[|N i |]. Let N k represents the set of sub-regions that meet the update conditions at the kth iteration, then formula (2) can be rewritten as:

[0109]

[0110] The following five sub-regions are taken as examples to illustrate the difference between asynchronous ADMM and traditional (synchronous) ADMM, assuming that each sub-region is adjacent to each other, when p[|N i Figures 5-6 Figures 5-6 As can be seen from

[0111] The active defense mechanism of cross-domain security authentication can protect the sub-region state estimator from FDI attacks initiated by tampering, disguising, replaying and man-in-the-middle, etc. However, the attacker can still achieve FDI attack through backdoor attack, so it is necessary to introduce a passive defense detection method to improve the defense mechanism.

[0112] K-L divergence is a method for measuring the difference between two probability distributions, which has been widely used in many fields. The mathematical definition of K-L divergence is as follows:

[0113]

[0114] Where D KL (p(y)||q(y0))≥0, if and only if y=y0, D KL (p(y)||q(y0))=0.

[0115] When the sub-region state estimator is cooperating, the state variables of the boundary nodes sent to the neighboring sub-regions should be slowly changing. The change of the state variables of the boundary nodes is defined as Most of the state variables change very little, close to 0.

[0116] Therefore, K-L divergence can be used to determine whether the boundary node state variables received by the sub-region state estimator are attacked:

[0117]

[0118] Where τ max , τ min ​​an alarm threshold for bad data attack detection, D KL (p(y)||q(y0)) should be within a threshold interval, if D KL (p(y)||q(y0)) exceeds the range, it is considered to be attacked. The range of K-L divergence at 99% confidence level without attack is 4.9334 to 5.9915, so τ max = 5.9915, τ min = 4.9334. Wherein, y is the increment of the adjacent sub-region boundary node state variable that may include bad data; p(y) is the probability distribution of the increment of the boundary node state variable; y0 is the increment of the historical normal boundary node state variable; and q(y0) is the probability distribution of the increment of the historical normal boundary node state variable.

[0119] Since the K-L divergence detection threshold uses a 99% confidence range, and the threshold will be exceeded when an attack occurs, the credibility of the sub-region state estimator needs to be evaluated. Therefore, the scheme in this chapter needs to add an intelligent contract based on the cross-domain authentication scheme in the third chapter:

[0120] Credibility contract: the adjacent sub-region state estimator judges the boundary node state variable from the sub-region i, if it exceeds the threshold specified by the K-L divergence, the credibility contract is called to record this failure. When the credibility contract records the failure from the sub-region i exceeds the specified upper limit k err , the deregistration contract is called, considering that the state estimator of the sub-region i is not credible, and the boundary node information from the sub-region i is no longer used, and the boundary node state information before the attack is used instead.

[0121] In the embodiment of the application, the distributed secure state estimation scheme based on cross-domain authentication and asynchronous ADMM proposed in the embodiment of the application is evaluated from the aspects of convergence speed and attack resistance of the sub-region state estimator. A notebook computer (Ubuntu 22.0464-bit system or Windows 1064-bit system, 2.11GHz Intel I5 CPU, 16GB RAM) is used to simulate the cooperation process of the sub-region state estimator. The notebook computer with Ubuntu system simulates the KGC, and the notebook computer with Windows system simulates the edge gateway EG and the sub-region state estimator, and the scheme proposed in the embodiment of the application is verified by experiments. The IEEE-118 node system

[88] is used for simulation, and the results of the example analysis are as follows:

[0122] ​First, the IEEE-118 node system is partitioned according to the large-scale power grid region partitioning method based on K-means given above. Setting, the power grid is divided into 5 sub-regions; and the non-diagonal elements of the weight matrix are all set to 0.01, indicating that the cost of destroying the connection between nodes is the same. Select nodes 1, 103, 76, 18, 35 as reference nodes, and the partitioning result obtained is as shown in Figure 7 .

[0123] It is assumed that the active power measurement error of the sub-region node obeys the Gaussian distribution N(0, 0.03 2 ), and the branch active power measurement error obeys the Gaussian distribution N(0, 0.03 2 ). The penalty parameter ρ is 10. The results of synchronous ADMM and asynchronous ADMM are compared, as shown in Figures 8-19 .

[0124] According to the experimental results, the synchronous ADMM needs a total of 25 iterations to reach convergence, and the time consumption is 14.4331 seconds. The iteration steps of each sub-region in the asynchronous ADMM are 54, 29, 29, 29, and 28 respectively, and the time consumption is 11.2140 seconds. It can be seen that although the asynchronous ADMM has more iteration times, the time consumption is greatly reduced compared with the synchronous ADMM, which can better adapt to the delay problem caused by insufficient network resources or the use of cross-domain security authentication when each sub-region state estimator cooperates, and is more suitable for the increasingly complex network environment of CPPS.

[0125] To verify the response ability of the scheme to packet loss and the passive defense detection performance, it is assumed that the state estimator of sub-region 4 is attacked and captured as a backdoor attack node, and 10% attack strength is applied to the boundary node state information sent by the state estimator to sub-region 1 after the 2nd, 10th, 12th, 15th, and 20th iterations, and 10% attack strength is also applied to the state information sent by the state estimator to sub-region 3 after the 2nd, 3rd, 4th, 5th, 6th, 12th, 17th, 18th, 19th, 21st, and 27th iterations. The experimental results are as shown in Figures 20-25 .

[0126] According to the experimental results, each FDI attack can be detected by the K-L divergence detector, and this data is regarded as packet loss. Each sub-region state estimator needs 51, 29, 29, 29, and 29 iterations to reach convergence, and the total time consumption is 11.2149 seconds. Compared with the case without attack, the iteration steps and iteration time consumption have only a slight change. It can be seen that the distributed secure state estimation scheme provided by the embodiment of the present application can well resist data packet loss, DoS attack and FDI attack.

[0127] The technical scheme provided by the embodiment of the present application has at least the following beneficial effects:

[0128] (1) In the present application, the active defense mechanism and passive detection technology are combined, and a distributed security state estimation scheme based on cross-domain authentication and asynchronous alternating direction multiplier method (ADMM) is proposed for the security problem in distributed state estimation. The scheme not only effectively resists the data packet loss problem, but also effectively prevents denial of service attack (DoS attack) and false data injection attack (FDI attack), two common network attacks. By combining the active defense mechanism with the passive detection technology, the overall security protection level of the distributed system is significantly improved, thereby ensuring the stable operation of the system in various complex attack environments.

[0129] (2) In the present application, by introducing the asynchronous ADMM algorithm and cross-domain authentication technology, the delay influence caused by network transmission and cross-domain security authentication calculation cost is effectively reduced. The application of asynchronous ADMM allows asynchronous calculation of local state estimation without the need for all adjacent sub-regional state estimators to complete the calculation, thereby significantly reducing the delay caused by data transmission and authentication process. This mechanism optimizes the operation efficiency of the system, improves the real-time performance of data processing, and ensures the efficient operation of the system in high-load and high-complexity environments.

[0130] (3) In the present application, the distributed state estimation shows faster convergence speed and excellent anti-attack ability. The design of this scheme considers various complex situations in practical applications, and can quickly recover to normal state and maintain the stability of the system when facing network attacks and data transmission challenges. The innovative algorithm design and efficient authentication mechanism not only enhance the defense ability of the system against attacks, but also optimize the data processing process, improve the reliability and response speed of the system in practical applications.

[0131] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any skilled person in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0132] The following points need to be explained:

[0133] (1) The drawings of the embodiments of the present application only involve the structures related to the embodiments of the present application, and other structures can be referred to the usual design.

[0134] (2) For clarity, in the drawings used to describe the embodiments of the present application, the thickness of layers or regions are exaggerated or reduced, that is, the drawings are not drawn on scale. It will be understood that when an element such as a layer, film, region or substrate is referred to as being "on" or "under" another element, it can be "directly" on or under the other element or an intervening element can also be present.

[0135] (3) The embodiments of the present application and the features in the embodiments can be combined with each other to obtain new embodiments, without conflict.

[0136] The above merely describes the specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM, characterized in that, The application relates to a power grid regionalization method based on K-means, and a distributed security state estimation framework based on the method. The method comprises the following steps: S1, power grid regionalization based on K-means, the whole power grid region is divided into several sub-regions, so as to reduce the global communication cost and the calculation load; S2, a distributed security state estimation framework is established through a state estimator in each sub-region, the framework comprises a physical layer, a network layer and a service layer, each sub-region comprises a state estimator; S3, authentication and state iteration of the sub-region state estimator: S3a, the state estimator of the sub-region is registered to a KGC; S3b, the state estimator of the sub-region is cross-domain authenticated and exchanges boundary node state information; S3c, the state estimator of the sub-region performs K-L divergence calculation on the received boundary node state information, and judges whether the K-L divergence is within a threshold interval; S3d, the state is updated according to the received part of the adjacent sub-region boundary node information, whether the state is converged is judged, and if not, the next iteration is entered; 2. The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM according to claim 1, characterized in that, S4, an asynchronous alternating direction multiplier method (ADMM) algorithm is introduced, so that the state estimator of each sub-region can perform the next iteration without waiting for the state update of all adjacent sub-regions. The S1 specifically comprises the following steps: S1a, collecting node data of the power grid region, the node data comprising the position, load data and power generation information of nodes, and determining the relevant weight according to the distance between the nodes, the current size and the importance parameter of the load; S1b, selecting k cluster centers; S1d, calculating the disconnection cost C according to the index index cost ; S1e, repeating the cluster assignment and cost calculation until a termination condition is met, the termination condition being that the k clusters do not change or the cost C cost the function is less than the threshold value.

3. The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM of claim 1, wherein, S1c, for each node, the distance from each cluster center is calculated, and the node is distributed to the cluster where the nearest cluster center is located, so as to obtain the index of the corresponding cluster center of each node. The S2 specifically comprises the following steps: The physical layer: representing the power grid region, the power grid region is divided into the sub-regions, each sub-region comprises internal nodes and boundary nodes, and each sub-region comprises a state estimator, and the state estimator exchanges the state information of the boundary nodes with the state estimators of adjacent sub-regions; The network layer: each state estimator is regarded as an intelligent terminal of the sub-region, and is registered to the KGC of the sub-region by the gateway, is mutually authenticated with the state estimators of adjacent sub-regions, and exchanges data and negotiates with the state estimators of adjacent sub-regions; 4. The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM of claim 1, wherein, The service layer: comprising the registration information of the sub-region state estimators published by the KGC, and the registration information of other STs in the CPPS. The S3c specifically comprises the following steps: wherein, and D is an alarm threshold for bad data attack detection, D KL (p(y) || q(y0)) should be within a threshold interval, if D KL (p(y) || q(y0)) is out of range, it is considered to be attacked, y is the increment of the state variable of the boundary node of the adjacent sub-region including the bad data p(y) is the probability distribution of the increment of the state variable of the boundary node, y0 is the increment of the state variable of the historical normal boundary node, and q(y0) is the probability distribution of the increment of the state variable of the historical normal boundary node.

5. The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM of claim 1, wherein, The K-L divergence is used to judge whether the boundary point state variable received by the sub-region state estimator is attacked: The S4 specifically comprises the following steps: where z includes the measurements of node injection power and branch power, H is the measurement matrix, v is the measurement error, P ij is the active power of the branch from node i to node j in the alternating current model, P i is the active power injected at node i, and the relationship between the measurements and the state values of each of the sub-areas is obtained as follows: z i = H i θ i + v i where z i is the measurement value of sub-area i, H i is the measurement matrix of sub-area i, θ i is the state variable of the extended area, including the state variable θ i,int of the internal nodes of the sub-area and the state variable θ i of the boundary nodes of the adjacent area of the sub-area i, j ∈ N i , N i is the set of sub-areas adjacent to the sub-area i, v i is the measurement noise of the sub-area i, which is subject to a Gaussian distribution v i ~ N(0, R i ). S4a, converting the nonlinear relationship of an alternating current model into the linear relationship of a direct current model: where J(θ i ) is the objective function of the state estimation of sub-area i, W i is the corresponding weight matrix, S4c, introduce intermediate variables θ ij and the boundary connection matrix D ij , so that θ i [j] = θ j [i] = θ ij = D ij θ i , it is inferred that: S4b, constructing a target function with boundary constraints according to the minimum error square principle: where p is a penalty parameter, u i,j is the elastic Lagrange multiplier; S4d, according to the alternating vector multiplier method, the target function is substituted into an augmented Lagrange matrix, and the Lagrange multiplier is stretched to obtain: S4e, through corresponding iteration, According to the above formula, each of the sub-region state variables is solved completely independently, distributed computing can be performed, and only the state information of the boundary needs to be exchanged with the adjacent sub-region.

6. The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM according to claim 5, characterized in that, The S4 further comprises: S4f, to solve the problems that the classic ADMM algorithm cannot well cope with data packet loss and transmission delay and the iteration time is long, the classic ADMM algorithm is modified to realize asynchronous computing: Assume that there are N adjacent to the sub-region i. i | sub-regions, received p i The boundary node information of adjacent sub-areas is required to receive at least p[|N i |],1≤p[|N i |]≤N i The next update can only be performed after the boundary node information of adjacent sub-regions is p i ≥p[|N i |], let N k Represents the set of sub-regions that meet the update conditions at the kth iteration, and we get: The asynchronous ADMM algorithm does not need to wait for all the adjacent sub-regions in the region to complete K-L divergence detection, cross-domain authentication, sub-region calculation and mutual communication, compared with synchronous ADMM iteration update, the asynchronous ADMM algorithm uses the boundary node state variable in the previous iteration step of the adjacent sub-region state estimator.

7. The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM of claim 5, wherein, The S4a comprises: Assume that the voltage phase difference between two nodes is very small, i.e. sinθ ij ≈θ ij , cosθ ij ≈1; The voltage amplitude of the node is close to the unit quantity 1p.u.; For a transmission branch, the branch conductance is much smaller than the branch susceptance, i.e. g ij <<b ij ; The charging power is calculated to the load power to obtain an equivalent model of a transmission line, and the current, complex power and active power of the branch from the node i to the node j in the AC model are respectively: After substituting the simplified condition, the active power and the reactive power of the DC model branch are obtained: Q ij =0 Therefore, the active power injected into the node i is: where is an N-dimensional vector, then the dc model of the grid is obtained from the above equation.

8. The CPPS distributed security state estimation method based on cross-domain authentication and asynchronous ADMM of claim 4, wherein, Specifically, it comprises: In order to prevent the situation that the threshold value of K-L divergence detection is in the range of 99% confidence from causing the threshold value to be exceeded when the attack occurs, the smart contract is increased to evaluate the credibility of the sub-region state estimator: The adjacent sub-area state estimator judges the boundary node state variables from the sub-area i, and if it exceeds the threshold value specified by the K-L divergence, it calls the credibility contract to record this failure, and when the credibility contract records the failure from the sub-area i exceeds the specified upper limit k err , the deregistration contract is called, it is considered that the state estimator of the sub-area i is not credible, the boundary node information from the sub-area i is no longer used, and the boundary node state information before the attack is used instead.

Citation Information

Patent Citations

  • Active distribution network robust estimation method based on PMU quasi-real-time data

    CN110299762A

  • Distributed state estimation method and system based on operation topology of power distribution network

    CN114915030A