A selective encryption method for remote control switch of power distribution area

By selectively encrypting remote control messages in power distribution substations, and only encrypting and decrypting messages in important areas, the problems of high computational load and insufficient security in existing technologies are solved, achieving efficient data transmission and simplified equipment operation.

CN119382932BActive Publication Date: 2025-10-21ZHEJIANG HUAYUN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411323849.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2025-10-21
Estimated Expiration
2044-09-23

AI Technical Summary

Technical Problem

In existing power distribution network automation systems, the encryption and decryption of remote control switches involves large computational loads, low data transmission efficiency, and a lack of effective security measures, resulting in a high risk of information leakage and theft.

Method used

A selective encryption method for remote control switches in distribution radio areas is adopted. By adding encryption chips at important positions at the head and tail ends, an encryption channel is established. Only remote control-related messages with high security are encrypted and decrypted, while other data is not encrypted or decrypted, thereby reducing the amount of computation and interactive data.

Benefits of technology

This approach achieves security in critical areas while reducing the number of encryption switches and computational load, simplifying equipment workflows, improving data transmission efficiency, and reducing the workload of engineering debugging and troubleshooting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382932B_ABST
    Figure CN119382932B_ABST
Patent Text Reader

Abstract

The application discloses a power distribution area remote control switch selective encryption method, which overcomes the problem of large encryption and decryption calculation amount of power distribution terminals and power distribution remote control switches in the prior art, and comprises the following steps: adding encryption chips at the power distribution terminals of the head end and the switches at the important positions of the tail end, inquiring about the encryption chip conditions of the tail end at the head end and establishing an information table, exchanging encryption security certificates with the tail end supporting encryption to establish an encryption channel, and performing first-layer encryption selection of the switch devices under different security levels; the head end generates a management message and issues the management message, if the management message is a predetermined remote control related message and the target node supports the encryption chip, the management message is encrypted according to the data encryption strategy of the node and is issued to the tail end, the tail end encrypts the corresponding feedback information and sends the feedback information to the head end, and the second-layer encryption selection work is completed. The encryption and decryption calculation amount in a single encryption switch in the important area is reduced, and the data transmission efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of encrypted transmission of distribution network information, and in particular to a selective encryption method for remote control switches in distribution station areas. Background Art

[0002] Typically, the management of remote switches within a distribution substation involves telemetry, telesignaling, and remote control, involving a wide range of data. Remote switches are operated remotely, which differs from telemetry and telesignaling. Because some areas involve the supply and disconnection of power to critical areas, the impact is significant and requires high security.

[0003] However, existing power distribution network automation systems lack adequate security measures, leading to numerous information security risks within the network. This can lead to information leakage, loss, and theft during the communication process, from the master station sending remote control commands to terminals, or from the master station obtaining field data from terminals. Encrypting all switches in all zones and all data items at different security levels would require significant computational effort, increase workflow complexity, and hinder engineering debugging and troubleshooting. Summary of the Invention

[0004] The purpose of the present invention is to solve the problems in the prior art of large encryption and decryption calculation amount and low data transmission efficiency of distribution terminals and distribution remote control switches, and provide a selective encryption method for remote control switches in distribution stations, which reduces the number of switches involved in encryption in the system while ensuring the safety of important areas, reduces the encryption and decryption calculation amount in a single encryption switch, simplifies the equipment workflow, simplifies engineering debugging, reduces the workload of problem investigation, and improves data transmission efficiency.

[0005] In order to achieve the above object, the present invention adopts the following technical solutions:

[0006] A method for selective encryption of a remote control switch in a distribution station area, characterized by comprising the following steps:

[0007] Encryption chips are added to the power distribution terminals at the headend and switches at key locations at the tailend. The headend queries the status of the encryption chips at the tailend and creates an information table. It then exchanges encryption security certificates with the encryption-supported tailend to establish an encrypted channel, performing the first-layer encryption selection for switchgear at different security levels.

[0008] The head end generates a management message and sends it down. If the management message is an established remote control-related message and the target node supports the encryption chip, the message will be encrypted according to the data encryption policy of the node and sent down to the tail end. The tail end will encrypt the corresponding feedback information and send it uplink to the head end, completing the second-layer encryption selection work.

[0009] The method of the present invention applies security chips to remote-controlled switches in distribution stations based on their importance, selectively encrypting some switches and not others within a single distribution station. This reduces the computational complexity of encryption and decryption at distribution terminals and the amount of system-encrypted exchange data. Only highly secure remote-controlled messages are encrypted and decrypted, while less important data, such as telemetry, is not encrypted. This selective mechanism, encrypting some content and not others within a single remote-controlled switch, reduces the computational complexity of encryption and decryption for distribution remote-controlled switches equipped with encryption chips.

[0010] Preferably, in the second-layer encryption selection, the tail end that supports encryption, after receiving the encrypted message, decrypts it according to the predetermined strategy to obtain the plain text and performs control operations. The tail end also encrypts the corresponding feedback information and sends it up to the head end. The head end performs the predetermined decryption and then sends it up to the upper layer of business for further processing.

[0011] As a preference, in the first layer encryption selection, after the tail end is powered on and registered with the head end, the head end actively initiates a query in turn. After the tail end receives the query message, it synchronizes the management information of whether encryption is supported or not to the head end.

[0012] Preferably, in the second-layer encryption selection, if the target node does not support the encryption chip, the remote control related message is directly released.

[0013] Preferably, after encrypting the message according to the data encryption policy of the node, the encrypted message is filled into the payload area of ​​the encrypted message DI of the communication protocol extended for this encryption application and sent downstream.

[0014] Preferably, the tail end encrypts the corresponding feedback information and then sends it uplink to the head end, including: judging whether the DI of the received message is the encrypted message DI of the extended communication protocol, and if so, decrypting the encrypted message of the load according to the encryption protocol; after the execution result is encrypted, it is filled into the load area of ​​the encrypted message DI of the communication protocol extended for this encryption application and then sent uplink.

[0015] Preferably, the security layer identifies the management message sent by the head end and performs predetermined decryption on the encrypted information fed back by the tail end. The security layer is added to the software level of the head end which originally has no encryption component.

[0016] Preferably, if the DI of the received message is not the encrypted message DI of the extended communication protocol, it indicates that it is ordinary plaintext data, and the message is directly parsed, and the execution result is sent back in plaintext.

[0017] Preferably, in the first encryption selection, for the tail end that fails to query, the head end always keeps querying at a fixed frequency.

[0018] Preferably, the tail-end device includes a photovoltaic tail-end and a line monitoring unit. The tail-end device cooperates with the head-end to complete the first-layer encryption selection, and at the same time completes the second-layer single-node internal selection encryption mechanism to distinguish between encrypted / unencrypted business operations.

[0019] Therefore, the present invention has the following beneficial effects:

[0020] 1. For the remote control switches in the distribution area, encryption chips are only installed on important switches according to the importance of the application. That is, within a single distribution area, some switches are configured with encryption while others are not, thereby reducing the calculation amount of encryption and decryption of the distribution terminal and the amount of system encryption-related interactive data.

[0021] 2. The remote control switch equipped with an encryption chip only encrypts and decrypts the remote control-related messages with high security, while other unimportant data such as telemetry are not encrypted and decrypted. That is, a selective mechanism is adopted in a single remote control switch, in which part of the content is encrypted and part of the content is not encrypted, thereby reducing the computational complexity of encryption and decryption of the distribution remote control switch. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] Figure 1 This is a flow chart of the overall steps of the selective encryption method for remote control switches in distribution stations of the present invention.

[0023] Figure 2 This is a schematic diagram of the encryption preparation of the tail-end device in Example 2.

[0024] Figure 3 This is a flow chart of the tail end cooperating with the head end to complete the first layer encryption selection in the second embodiment.

[0025] Figure 4 This is a schematic diagram of the process of selecting the first layer of encryption performed by the head end to the tail end in Example 2.

[0026] Figure 5 This is a schematic diagram of the process of selecting the second layer encryption of a single node by the head end in Example 2.

[0027] Figure 6 This is a flow chart of the process of completing the second-layer encryption selection at the tail end in Example 2. DETAILED DESCRIPTION

[0028] The present invention is further described in detail below with reference to the accompanying drawings and specific embodiments:

[0029] Example 1:

[0030] This embodiment provides a method for selective encryption of remote control switches in a distribution area, such as Figure 1As shown, the operation process is as follows: Step 1, encryption chips are added to the power distribution terminal at the head end and the switches at important positions at the tail end. The head end queries the encryption chip status of the tail end and establishes an information table, exchanges encryption security certificates with the tail end that supports encryption once to establish an encryption channel, and performs the first layer of encryption selection for switch devices under different security levels; Step 2, the head end generates a management message and sends it down. If the management message is an established remote control related message and the target node supports the encryption chip, the message is encrypted according to the data encryption policy of the node and sent to the tail end. The tail end encrypts the corresponding feedback information and sends it up to the head end, completing the second layer of encryption selection.

[0031] This embodiment provides a selective encryption method for remote-controlled switches in a distribution area. For remote-controlled switches in a distribution area, security chips are only installed on critical switches, based on their importance. This selective mechanism allows some switches within a single distribution area to be encrypted while others are not. This reduces the computational complexity of encryption and decryption at the distribution terminal and the amount of encryption-related interactive data in the system. Remote-controlled switches equipped with encryption chips only encrypt and decrypt highly secure remote-controlled messages, while unencrypting less important data such as telemetry. This selective mechanism allows some content within a single remote-controlled switch to be encrypted while others are not, reducing the computational complexity of encryption and decryption for the distribution remote-controlled switches.

[0032] The following further illustrates the technical solutions and technical effects of the present invention through specific examples and specific application scenarios. The following examples are intended to explain the present invention, but the present invention is not limited to the following examples.

[0033] Typically, a remote control switch in a distribution area, acting as the tail-end device within the area, is managed by the distribution terminal at the head-end of the distribution area via a local communication network (e.g., 485, power line carrier). This embodiment provides a method for selectively encrypting remote control switches in a distribution area, primarily using two mechanisms to achieve selective encryption of remote control switches.

[0034] In this embodiment, some specific terms are represented as follows:

[0035] Remote control switch: In the field of power distribution, some switches with remote control, such as circuit breakers, etc.

[0036] Local communication network: refers to a communication network in which the communication distance between nodes in the network is within a few hundred meters, such as 485 bus and broadband power line carrier.

[0037] Distribution terminal: A digital metering and monitoring device located next to a distribution transformer in a distribution area in a distribution network, used to monitor the operation of the transformer and the entire distribution area.

[0038] Specifically:

[0039] 1. First-tier mechanism: encryption selection for switchgear at different security levels.

[0040] Based on the original system without encryption components, encryption chips are added to the distribution terminal at the head end, while at the tail end, encryption chips are only added to switches in important positions to perform the first layer of encryption selection for switch devices at different security levels.

[0041] The specific working process is as follows: After each tail end is powered on and registered with the head end, the head end proactively initiates queries, sending query messages to determine whether each tail end supports encryption chips. After receiving the query message, each tail end responds with a yes or no response based on the actual situation, synchronizing encryption support management information to the head end. For tail ends that fail the query, the head end continues to query at a certain frequency. After collecting information on the encryption chips of each tail end, the head end creates an information table to reflect the encryption support status of the tail ends in the area. At the same time, the head end and the tail ends that support encryption establish an encrypted channel by exchanging encryption security certificates, completing the first layer of encryption mechanism.

[0042] The information table includes the tail end location and whether the tail end device has an additional encryption chip.

[0043] The head end is the distribution terminal; the tail end includes distributed equipment in the substation, such as photovoltaic micro-breakers and line monitoring units, which complete the encryption selection mechanism within the second-layer single-node device and distinguish between encrypted / unencrypted business operations.

[0044] Among them, the important position is determined according to the safety of the switch at the position in actual use.

[0045] 2. Second-layer mechanism: encryption selection for message data.

[0046] In this embodiment, among all types of data of the remote control switch, only the relevant messages of the actual remote control operation are selectively encrypted, while the data items such as telemetry and telesignaling are not encrypted, thereby realizing the second layer of message level encryption selection.

[0047] The specific working process is as follows: a security layer is added to the existing software layer at the headend, which does not have encryption components. When the headend generates a management message for transmission, the security layer identifies it as a message related to actual remote control operations and the target node supports encryption chips. If the security layer detects that the management message is a pre-defined message related to actual remote control operations and that the target node supports encryption chips, it encrypts the management message according to the node's data encryption policy and sends the encrypted management message down. If the target node does not support encryption chips, the management message is directly released.

[0048] After receiving the encrypted message, the tail end, which supports encryption chips, decrypts it according to the predefined policy to obtain the plaintext and perform control operations. The tail end also encrypts the corresponding feedback information and sends it upstream to the head end. The head end's security layer performs the predefined decryption and then passes it to the upper layer for further processing. This completes the second layer of encryption.

[0049] The selective encryption method for remote control switches in distribution stations provided in this embodiment reduces the number of switches involved in encryption in the system while ensuring the safety of important areas, reduces the encryption and decryption calculations in a single encryption switch, simplifies the equipment workflow, simplifies engineering debugging, and reduces the workload of problem troubleshooting.

[0050] Example 2:

[0051] This embodiment provides a method for selectively encrypting remote control switches in a distribution station area, which is used to further apply the method for selectively encrypting remote control switches in a distribution station area provided in the first embodiment.

[0052] This working mechanism is mainly divided into two mechanisms to achieve selective encryption of remote control switches.

[0053] Specifically:

[0054] Mechanism 1: Encryption selection work for switchgear at different security levels.

[0055] Software and hardware preparation at the headend (distribution terminal): Based on the original system without encryption components, encryption chips are added to the hardware of the headend distribution terminal and encrypted communication functions are added to the software. At the tailend, encryption chips are added to the hardware of the switches in important locations and encrypted communication functions are added to the software. This provides the first layer of encryption selection for switchgear at different security levels.

[0056] The encryption process is:

[0057] (1) Software and hardware preparation at the head end (distribution terminal).

[0058] The distribution terminal hardware adds an encryption chip, and the distribution terminal software adds encrypted communication capabilities, as well as software functions for encryption and decryption interactions between the headend and tailend. This allows the headend distribution terminal to establish a secure communication channel with the tailend's decryption-supported switch via the encryption chip, thus preparing the software and hardware for subsequent encryption and decryption communications.

[0059] (2) Preparation of tail-end equipment.

[0060] Preparation of tail-end equipment includes preparation of distributed equipment in the substation area, such as photovoltaic micro-breakers, line monitoring units and other equipment.

[0061] Tail-end switch importance assessment: Users are required to evaluate the importance of all switches in the area. Switches identified as having high security requirements (those located in key locations within the substation) are then equipped with the encryption chips that are compatible with the head-end distribution terminals. Switches with lower security requirements do not require encryption chips. This ensures that switches with high security requirements have confidentiality features while also reducing the number of devices requiring encryption by not installing encryption chips on switches with lower security requirements. This reduces the amount of encryption and decryption computations and the amount of encryption and decryption-related communication traffic at the head-end distribution terminals. It also reduces the number of encryption switches required for debugging and troubleshooting in subsequent engineering projects.

[0062] At the same time, the tail-end switch software has been enhanced with encryption and decryption software functions related to the encryption chip, as well as software functions for encryption and decryption interactions between the headend and tail-end. This enables the tail-end switch to establish a secure communication channel with the headend power distribution terminal through the encryption chip, preparing the software and hardware for subsequent encryption and decryption communications.

[0063] The record adds the tail switch of the encryption chip and encryption / decryption software to generate the tail node record table.

[0064] like Figure 2 As shown, taking the PV micro-break as an example, first evaluate whether the PV micro-break to be tested is a PV micro-break at an important location in the substation. If so, add an encryption chip to the hardware of the PV micro-break and add an encrypted communication function to the software of the PV micro-break. If the PV micro-break to be tested is a PV micro-break at a non-important location, then other devices such as line monitoring units do not need to add an encryption chip.

[0065] (3) The tail end cooperates with the head end to complete the first layer of encryption selection.

[0066] Tail-end equipment: including photovoltaic micro-circuits, line monitoring units and other distributed equipment in the substation area, cooperating with the head-end to complete the first layer of encryption selection.

[0067] The specific process is:

[0068] When the system is powered on, the software on each switch and line monitoring terminal at the tail end checks whether the hardware circuitry contains an encryption chip. If so, it records the chip and responds "yes" to subsequent queries from the head end regarding "whether encryption is supported." If not, it records the chip and responds "no" to subsequent queries regarding "whether encryption is supported." This is the software workflow diagram for the tail end (PV switches and other equipment).

[0069] like Figure 3As shown, when the tail end is powered on, it detects whether it has an encryption chip. If so, when the tail end receives a query message from the head end asking whether encryption is supported, the tail end replies yes. The tail end then cooperates with the head end to establish an encrypted communication channel before secure communication begins. If the tail end does not have an encryption chip, when the tail end receives a query message from the head end asking whether encryption is supported, the tail end replies no.

[0070] (4) The headend selects the first layer of encryption.

[0071] Head end (distribution terminal): The first layer of encryption selection mechanism for the tail-end equipment in the substation (photovoltaic micro-circuit breakers, line monitoring terminals).

[0072] After the system environment is initialized at power-up, each tail-end switch, line monitoring terminal, and other devices initiate network registration with the head-end distribution terminal. The distribution head-end then queries each switch in turn to see if encryption is supported. If so, the encryption chip-related processes are followed to establish an encrypted channel between the head-end and tail-end. If not, encryption-related transactions are not processed. The head-end stores the encryption support status of each tail-end so that it can subsequently adopt different encryption or non-encryption confidentiality policies for different nodes. For switches that have not yet received a response to whether encryption is supported, the head-end continues to query them at a regular interval. This is the software workflow diagram for the head-end (distribution terminal) during this phase.

[0073] Specifically, such as Figure 4 As shown, the headend detects whether the tail-end node has connected to the distribution substation. If it has, it continues detecting until it detects a tail-end node. After detecting that the tail-end node has connected to the distribution substation, the headend directly sends a query message to the tail-end node, asking "Does encryption support exist?" If the tail-end node replies "yes," the headend establishes an encrypted channel with the tail-end node according to the encryption protocol, records the tail-end node as an encryption-supported device in the software, and subsequently encrypts messages from the tail-end node. If the headend receives a "no" reply from the tail-end node, the software records the node as a non-encrypted device, and subsequently does not encrypt messages from the node.

[0074] After the above steps, the encryption selection of mechanism one is completed.

[0075] Mechanism 2: Encryption selection for message data.

[0076] Among all types of data of the remote control switch, only the relevant messages of the actual remote control work are selectively encrypted, while the telemetry, telesignaling and other data items are not encrypted, realizing the second layer of message level encryption selection.

[0077] The encryption process is:

[0078] (1) Second layer encryption selection at the head end.

[0079] The headend (distribution terminal) selects the second layer of encryption for messages within a single node device.

[0080] When the headend generates a message to be sent, it identifies it. If it is a message related to the intended remote control operation and the target node supports encryption chips, it encrypts the message according to the node's data encryption policy and sends the encrypted message down. If the target node does not support encryption chips, it is directly released.

[0081] The software workflow diagram for this stage is as follows Figure 5 As shown, it determines whether any message involves remote control and requires encryption. If so, it checks the tail node record table to see if the tail node supports encryption. If so, it encrypts the message according to the encryption protocol recorded in the encryption and decryption software. If no message involves remote control, the message is sent downstream as plaintext. If the node record table indicates that the node does not support encryption, the message is sent downstream as plaintext.

[0082] The encrypted message is filled into the payload area of ​​the encrypted message DI of the communication protocol extended for this encryption application and sent downstream. Similarly, the encrypted message in the upstream direction will also be filled into the payload area of ​​the DI.

[0083] In this embodiment, the communication protocol adopts the 645 protocol. The 645 protocol is a question-and-answer (master-slave) communication protocol in accordance with my country's power industry standard DL / T 645-2007, including DLT645-1997 and DLT645-2007, and is a multifunctional electric energy meter communication protocol.

[0084] In this communication mode, there is usually a master station (head end) and one or more slave stations (tail end). The master station is responsible for initiating communication requests, and the slave stations provide corresponding responses based on the master station's requests.

[0085] In this embodiment, the communication process of the question-answer protocol generally includes the following steps:

[0086] 1) The head-end initiates a request: The head-end sends a request message to a specific tail-end. The request message contains the operations that the tail-end needs to perform, such as reading electric energy and reading real-time parameters.

[0087] 2) The tail end receives the request: After the tail end receives the request from the head end, it processes it according to the content of the request.

[0088] 3) Tail end prepares response: The tail end prepares the corresponding data according to the content of the request and constructs a response message.

[0089] 4) The tail end sends a response: The tail end sends the constructed response message back to the head end.

[0090] 5) The head end receives the response: After the head end receives the response from the tail end, it performs corresponding processing based on the response content.

[0091] DI: Data identifier in the 645 protocol. Data identifiers are encoded using four bytes, represented by DI3, DI2, DI1, and DI0, to distinguish different data items. Each byte is encoded in hexadecimal. The DI is an identifier established to ensure mutual recognition and differentiation between devices in a communication system. Communication DIs primarily include hardware DIs and software DIs. Hardware DIs are unique identifiers pre-set for hardware devices at the factory, while software DIs are dynamically generated according to specific rules during the use of the hardware device. Communication DIs play a crucial role in modern communications technology, improving overall system security and stability.

[0092] (2) The tail end completes the encryption selection mechanism within the single-node device of the second layer.

[0093] Tail end: including photovoltaic micro-breaks, line monitoring units and other distributed equipment in the substation area, completing the encryption selection mechanism within the second-layer single-node equipment, and distinguishing between encrypted / unencrypted business operations.

[0094] The tail end that supports encryption chips, after receiving the encrypted message, decrypts it according to the predetermined strategy to obtain the plain text and perform control operations. At the same time, the tail end encrypts the corresponding feedback information and sends it up to the head end, which decrypts it according to the predetermined strategy to convert it into plain text and then hands it over to the upper layer of business for further processing.

[0095] The software workflow at this stage is as follows Figure 6 As shown, the tail end determines whether it has received a message sent downlink from the head end to the tail end node. If so, it determines whether the message's DI is encrypted using the extended communication protocol (645 protocol in this embodiment). If so, it decrypts the encrypted message in the DI payload area according to the encryption protocol. If the tail end does not receive the message sent downlink from the head end to the tail end node, it indicates that the message is plaintext data. The message is directly parsed according to normal procedures, and the result is sent back as plaintext. If the message's DI is not DI using the extended communication protocol, it indicates that the message is plaintext data. The message is directly parsed according to normal procedures, and the result is sent back as plaintext.

[0096] The decrypted message is parsed and processed for normal business purposes. The execution result is encrypted and filled into the payload area of ​​the encrypted message DI of the 645 protocol extended for this encryption application before being transmitted upstream.

[0097] The selective encryption method for remote control switches in distribution stations provided in this embodiment can reduce the number of switches involved in encryption in the system while ensuring the safety of important areas, reduce the amount of encryption and decryption calculations in a single encryption switch, simplify the equipment workflow, simplify engineering debugging, and reduce the workload of problem troubleshooting.

[0098] The embodiment described above is only a preferred solution of the present invention and does not limit the present invention in any form. Other variations and modifications are possible without exceeding the technical solution described in the claims.

Claims

1. A selective encryption method for remote control switches in a distribution area, characterized in that: include: Encryption chips are added to the power distribution terminals at the headend and switches at key locations at the tailend. The headend queries the status of the encryption chips at the tailend and creates an information table. It then exchanges encryption security certificates with the encryption-supported tailend to establish an encrypted channel, performing the first-layer encryption selection for switchgear at different security levels. The head end generates a management message and sends it down. If the management message is an established remote control-related message and the target node supports the encryption chip, the message will be encrypted according to the data encryption policy of the node and sent down to the tail end. The tail end will encrypt the corresponding feedback information and send it uplink to the head end, completing the second-layer encryption selection work.

2. A method for selective encryption of remote control switches in a distribution station area according to claim 1, characterized in that: In the second-layer encryption selection, the tail end that supports encryption, after receiving the encrypted message, decrypts it according to the predetermined strategy to obtain the plain text and performs control operations. The tail end also encrypts the corresponding feedback information and sends it up to the head end. The head end performs the predetermined decryption and then sends it up to the upper layer of business for further processing.

3. A method for selective encryption of remote control switches in a distribution station area according to claim 1 or 2, characterized in that: In the first layer of encryption selection, after the tail end is powered on and registered with the head end, the head end actively initiates a query in turn. After receiving the query message, the tail end synchronizes the management information of whether encryption is supported or not to the head end.

4. A method for selective encryption of remote control switches in a distribution station area according to claim 1 or 2, characterized in that: In the second-layer encryption selection, if the target node does not support the encryption chip, the remote control related message is directly released.

5. The selective encryption method for remote control switches in a distribution area according to claim 1, characterized in that: After encrypting the message according to the data encryption policy of the node, the encrypted message is filled into the payload area of ​​the encrypted message DI of the communication protocol extended for this encryption application and sent downstream.

6. A method for selective encryption of remote control switches in a distribution station area according to claim 1 or 5, characterized in that: The tail end encrypts the corresponding feedback information and then sends it uplink to the head end, including: judging whether the DI of the received message is the encrypted message DI of the extended communication protocol, and if so, decrypting the encrypted message of the load according to the encryption protocol; after the execution result is encrypted, it is filled into the load area of ​​the encrypted message DI of the communication protocol extended for this encryption application and then sent uplink.

7. A method for selective encryption of remote control switches in a distribution station area according to claim 1, 2 or 5, characterized in that: The security layer identifies the management message sent by the head end and performs predetermined decryption on the encrypted information fed back by the tail end. The security layer is added to the software level of the head end which originally has no encryption component.

8. A method for selective encryption of remote control switches in a distribution station area according to claim 6, characterized in that: If the DI of the received message is not the encrypted message DI of the extended communication protocol, it indicates that it is ordinary plaintext data. The message is directly parsed and the execution result is sent back as plaintext.

9. A method for selective encryption of remote control switches in a distribution station area according to claim 1, 2 or 5, characterized in that: In the first encryption selection, for the tail end whose query fails, the head end keeps querying at a fixed frequency.

10. A method for selective encryption of remote control switches in a distribution station area according to claim 1, 2 or 5, characterized in that: The tail-end equipment includes the photovoltaic tail-end and the line monitoring unit. The tail-end equipment cooperates with the head-end to complete the first-layer encryption selection, and at the same time completes the second-layer single-node internal selection encryption mechanism to distinguish between encrypted / unencrypted business operations.

Citation Information

Patent Citations

  • Encryption remote control system of power distribution network

    CN104320419A

  • Power consumer demarcation load switch with encrypted communication function

    CN105098983A