Implementation method and device of power information physical system real-time simulation platform

By using open-source software to build simulation models of power and communication systems, and combining them with policy routing mechanisms and attack protection models, the problem of poor scalability of real-time simulation platforms for power cyber-physical systems was solved, resulting in cost reduction and improved user experience.

CN119720528BActive Publication Date: 2025-11-18CHANGSHA KELIANG TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411786478.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-11-18
Estimated Expiration
2044-12-06

AI Technical Summary

Technical Problem

Existing real-time simulation platforms for power information physical systems have poor scalability, and commercial software cannot be further developed according to actual needs, and the cost is high.

Method used

We use open-source software such as Simulink, RT-LAB, OPAL-RT real-time simulator and OMNet++ to build simulation models of power and communication systems. We combine policy routing mechanisms to realize data transmission and integrate attack and protection models in the communication simulation environment.

Benefits of technology

It reduces the cost of building a simulation platform, improves scalability, enables users to perform secondary development according to actual needs, and enhances user experience and the flexibility of the simulation platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119720528B_ABST
    Figure CN119720528B_ABST
Patent Text Reader

Abstract

The application is suitable for the technical field of modeling simulation, and provides an implementation method and an implementation device of a power information physical system real-time simulation platform, which adopts Simulink, RT-LAB software and OPAL-RT real-time simulation to build a power system simulation model and realize real-time simulation of the power system; in an OMNet++ environment, an INET model library is adopted to build a communication system simulation model, and the network topology structure and the communication protocol of the communication system are configured; based on the power system simulation model, the communication system simulation model and a SCADA system, a power information physical system real-time simulation platform is built; in the power information physical system real-time simulation platform, based on a strategy routing mechanism, data transmission between the power system simulation model, the communication system simulation model and the SCADA system is realized; in the power information physical system real-time simulation platform, an attack model and a protection model are integrated under a communication simulation environment, and the security of the power system is verified based on the attack model and the protection model, so that the expansibility of the simulation platform is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of modeling and simulation technology, and in particular relates to a method and apparatus for implementing a real-time simulation platform for a power information physical system. Background Technology

[0002] With the development of smart grid technology and the physical information system of the power grid, the integration of power systems and communication networks is becoming increasingly close. Power communication has become an important infrastructure of modern power grids and an important means to ensure the safe, stable and economical operation of the power grid.

[0003] Currently, there are various ways to build a real-time simulation platform for power cyber-physical systems. The most common approach is to use Simulink for power system modeling, RT-LAB for real-time simulation management, OPAL-RT as the real-time simulator, and Exata or OPNET for network communication simulation. However, in this approach, all related software is expensive commercial software, and the commercial network communication simulation software already has pre-defined communication equipment and security models, which users cannot add or adjust according to actual needs, resulting in poor scalability.

[0004] Therefore, improving the scalability of real-time simulation platforms for power cyber-physical systems has become an urgent problem to be solved. Summary of the Invention

[0005] This application provides a method and apparatus for implementing a real-time simulation platform for a power cyber-physical system, aiming to improve the scalability of the real-time simulation platform for power cyber-physical systems.

[0006] In a first aspect, embodiments of this application provide a method for implementing a real-time simulation platform for a power cyber-physical system. The method includes: constructing a power system simulation model using Simulink, RT-LAB software, and the OPAL-RT real-time simulator, and implementing real-time simulation of the power system; constructing a communication system simulation model using the INET model library in the OMNet++ environment, and configuring the network topology and communication protocol of the communication system; building a real-time simulation platform for the power cyber-physical system based on the power system simulation model, the communication system simulation model, and the SCADA system; implementing data transmission between the power system simulation model, the communication system simulation model, and the SCADA system in the real-time simulation platform based on a policy routing mechanism; and integrating an attack model and a protection model in the communication simulation environment within the real-time simulation platform, and verifying the security of the power system based on the attack model and the protection model.

[0007] In one possible implementation, the data transmission between the power system simulation model, the communication system simulation model, and the SCADA system based on a policy routing mechanism within the real-time simulation platform for the power information physical system includes: connecting a first device, a second device, and a third device via Ethernet, and configuring their respective IP addresses as a first IP address, a second IP address, and a third IP address, wherein the first device, the second device, and the third device are devices for deploying the OPAL-RT real-time simulator, the SCADA system, and the OMNet++ software, respectively; in the third device, creating a first virtual network node and a second virtual network node in the communication system simulation model, configuring their respective IP addresses as a fourth IP address and a fifth IP address, and establishing mappings between the first IP address and the fourth IP address, and between the second IP address and the fifth IP address, in the communication system simulation model; and using the policy routing mechanism based on the first IP address, the second IP address, the third IP address, the fourth IP address, and the fifth IP address to implement data transmission between the power system simulation model, the communication system simulation model, and the SCADA system.

[0008] In one possible implementation, the data transmission between the power system simulation model, the communication system simulation model, and the SCADA system using the policy routing mechanism based on the first IP address, the second IP address, the third IP address, the fourth IP address, and the fifth IP address includes: using the third IP address as the next-hop address; configuring a first static routing rule on the first device and a second static routing rule on the second device; the first static routing rule is used to transmit data generated by the first device to the third device, and the second static routing rule is used to transmit data generated by the second device to the third device; creating a first TAP device and a second TAP device in the third device, and configuring the IP addresses of the first TAP device and the second TAP device as the sixth IP address and the seventh IP address, respectively; configuring a first policy route based on the source IP address on the third device and creating a first policy routing table, in which the sixth IP address is used as the next hop. The system configures a third static routing rule based on the address, and uses the first policy routing, the first policy routing table, and the third static routing rule together to route data from the first device to the first TAP device. On the third device, a second policy routing based on the source IP is configured based on the second IP address, and a new second policy routing table is created. In the second policy routing table, the seventh IP address is used as the next-hop address. A fourth static routing rule is configured, and uses the second policy routing, the second policy routing table, and the fourth static routing rule together to route data from the second device to the second TAP device. Based on the first IP address and the fourth IP address, a first network address translation (NAT) is configured for the first virtual network node, which translates between the first IP address and the fourth IP address. Based on the second IP address and the fifth IP address, a second network address translation (NAT) is configured for the second virtual network node, which translates between the second IP address and the fifth IP address.

[0009] In one possible implementation, the integration of an attack model and a protection model in a communication simulation environment within the real-time simulation platform for the power cyber-physical system, and the verification of the power system's security based on the attack model and the protection model, includes: setting simulation parameters, which include the timing, method, and intensity of the attack, as well as the deployment and configuration of protective measures; running the simulation to simulate the operation of the power system and to simulate security events in the network based on the attack model; collecting simulation data, which includes the behavior and response of the power system based on the protection model when attacked; and adjusting the parameters of the attack model and the protection model according to the simulation data.

[0010] In one possible implementation, the method further includes: constructing a simulation model of the communication system using NS-3 simulation software.

[0011] In one possible implementation, the method further includes: selecting a cloud service platform; and deploying a simulation environment based on the cloud service platform.

[0012] In one possible implementation, the attack model is one or more of the following: denial-of-service attack, distributed denial-of-service attack, malware propagation, phishing attack, insider attack, and advanced persistent threat; the protection model is one or more of the following: firewall, intrusion detection system, intrusion prevention system, security information and event management, encryption and authentication mechanisms, and network isolation and segmentation.

[0013] Secondly, embodiments of this application provide an implementation apparatus for a real-time simulation platform for a power cyber-physical system. The apparatus includes: a first model building module, used to build a power system simulation model using Simulink, RT-LAB software, and the OPAL-RT real-time simulator, and to implement real-time simulation of the power system; a second model building module, used to build a communication system simulation model in the OMNet++ environment using the INET model library, and to configure the network topology and communication protocol of the communication system; a simulation platform building module, used to build a real-time simulation platform for the power cyber-physical system based on the power system simulation model, the communication system simulation model, and the SCADA system; a data transmission setting module, used to implement data transmission between the power system simulation model, the communication system simulation model, and the SCADA system in the real-time simulation platform for the power cyber-physical system based on a policy routing mechanism; and a security verification module, used to integrate an attack model and a protection model in the communication simulation environment of the real-time simulation platform for the power cyber-physical system, and to verify the security of the power system based on the attack model and the protection model.

[0014] Thirdly, embodiments of this application provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method as described in the first aspect or any of the implementations thereof.

[0015] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in the first aspect or any of the implementations thereof.

[0016] Fifthly, embodiments of this application provide a computer program product, the computer program product including a computer program, which, when executed by a processor, implements the steps of the method as described in the first aspect or any of the implementations thereof.

[0017] The beneficial effects of this application's embodiments compared to existing technologies are as follows: Power system simulation models and communication system simulation models are constructed using open-source simulation software such as RT-LAB, OPAL-RT real-time simulators, and OMNet++, and real-time joint simulation is performed. A real-time simulation platform for power cyber-physical systems is built based on the power system simulation model, communication system simulation model, and SCADA system. Within this platform, data transmission between the power system simulation model, communication system simulation model, and SCADA system is achieved based on a policy routing mechanism. Attack and protection models are integrated within the communication simulation environment, and the security of the power system is verified based on these models. Compared to using commercial software such as Exata or OPNET to build the simulation platform, using open-source simulation software not only reduces construction costs but also improves the scalability of the simulation platform, enabling users to perform secondary development according to actual needs and enhancing the user experience.

[0018] It is understood that the implementation device, electronic device, computer-readable storage medium and computer program product of the real-time simulation platform for power cyber-physical systems provided in the embodiments of this application have the same beneficial effects as the implementation method of the real-time simulation platform for power cyber-physical systems described above, and will not be repeated here. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1A flowchart illustrating an implementation method for a real-time simulation platform for a power cyber-physical system, provided in an embodiment of this application;

[0021] Figure 2 A schematic diagram of a power system simulation model provided in an embodiment of this application;

[0022] Figure 3 A schematic diagram of a communication system simulation model provided in an embodiment of this application;

[0023] Figure 4 A schematic diagram of a simulation test bench for a real-time simulation platform of a power cyber-physical system provided in an embodiment of this application;

[0024] Figure 5 A structural block diagram of an implementation device for a real-time simulation platform for a power cyber-physical system provided in an embodiment of this application;

[0025] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0026] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0027] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0028] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0029] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0030] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0031] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0032] With the development of smart grid technology and the physical information system of the power grid, the integration of power systems and communication networks is becoming increasingly close. Power communication has become an important infrastructure of modern power grids and an important means to ensure the safe, stable and economical operation of the power grid.

[0033] Currently, there are various construction schemes for real-time simulation platforms of power cyber-physical systems. Two commonly used schemes are shown in Table 1:

[0034] Table 1

[0035]

[0036] The two solutions mentioned above have the following main drawbacks:

[0037] 1. All related software is expensive commercial software, and the equipment models of some network communication simulation software (such as EXata) are not available for authorization or purchase by domestic users, which greatly limits the application of real-time simulation of power information physical systems in terms of scenario coverage.

[0038] 2. Existing commercial network communication simulation software has limitations in terms of secondary development capabilities. When users verify the impact of new communication technologies or security measures on the power system, they are often limited by the software's own development and expansion capabilities.

[0039] To address the aforementioned technical issues, this application provides a method for implementing a real-time simulation platform for power cyber-physical systems. The method employs Simulink, RT-LAB software, and the OPAL-RT real-time simulator to construct a power system simulation model and achieve real-time simulation of the power system. In the OMNet++ environment, a communication system simulation model is constructed using the INET model library, and the network topology and communication protocols of the communication system are configured. Based on the power system simulation model, the communication system simulation model, and the SCADA system, a real-time simulation platform for power cyber-physical systems is built. Within this platform, a policy-based routing mechanism enables data transmission between the power system simulation model, the communication system simulation model, and the SCADA system. Furthermore, within the communication simulation environment, attack and protection models are integrated into the platform, and the security of the power system is verified based on these models. This approach reduces the construction cost of the simulation platform and improves its scalability, allowing users to perform secondary development according to actual needs and enhancing the user experience.

[0040] For ease of understanding, the technical solution of this application will be described in detail below with reference to the accompanying drawings.

[0041] Figure 1 This is a flowchart illustrating a method for implementing a real-time simulation platform for a power information physical system according to an embodiment of this application. For ease of explanation, only the parts relevant to this embodiment are shown. The method provided in this embodiment includes the following steps:

[0042] The S110 uses Simulink, RT-LAB software, and the OPAL-RT real-time simulator to build a power system simulation model and realize real-time simulation of the power system.

[0043] Specifically, Simulink is a modular graph environment for multi-domain simulation and model-based design. It supports system design, simulation, automatic code generation, and continuous testing and verification of embedded systems. Simulink provides a graphical editor, a customizable library of modules, and solvers, enabling dynamic system modeling and simulation.

[0044] Specifically, the OPAL-RT real-time simulator is widely used in the development and testing of power electronics, energy systems, and control systems. Through the combination of high-performance computing hardware and simulation software, the system can run large-scale physical models in real time, thereby achieving hardware-in-the-loop (HIL) and software-in-the-loop (SIL) simulations.

[0045] Specifically, RT-LAB real-time simulation management software serves as the host computer software for the OPAL-RT real-time simulator. RT-LAB integrates with MATLAB / Simulink to provide users with a seamless distributed computing execution platform for real-time synchronization, user interface, real-time hardware interface, and data interaction.

[0046] In specific implementation, such as Figure 2 As shown, a power system simulation model is built using Simulink. Model components include, but are not limited to, generators, transformers, and transmission lines. The completed power system simulation model is then executed on the OPAL-RT real-time simulator using RT-LAB software to achieve real-time simulation of the power system.

[0047] S120 uses the INET model library to build a simulation model of the communication system in the OMNet++ environment, and configures the network topology and communication protocol of the communication system.

[0048] Specifically, the Object Modular Network TestBed in C++ (OMNet++) is an open-source multi-protocol network simulation software. As an open network simulation platform based on modular components, it has a complete graphical interface and an embeddable simulation kernel, and can be used for the simulation of distributed systems and communication networks.

[0049] Specifically, INET is a commonly used network protocol and component model library on the OMNet++ platform, covering a variety of protocols and technologies from the network layer to the application layer. Its main functions and features include: Internet stack models such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), Internet Protocol Version 4 (IPv4), Internet Protocol Version 6 (IPv6), Open Shortest Path First (OSPF), and Border Gateway Protocol (BGP); wired and wireless link layer protocols such as Ethernet, Point-to-Point Protocol (PPP), and Institute of Electrical and Electronics Engineers (IEEE) 802.11; and high-level application protocol models that help simulate the traffic behavior of real-world network applications, such as Hypertext Transfer Protocol (HTTP) and File Transfer Protocol (FTP).

[0050] In specific implementation, such as Figure 3 As shown, in the OMNet++ environment, a communication system simulation model is built using the INET model library, including but not limited to network components such as routers, switches, and terminal devices. Then, the network topology and communication protocols are configured to simulate different network communication scenarios.

[0051] S130 is a real-time simulation platform for power cyber-physical systems built based on power system simulation models, communication system simulation models, and SCADA systems.

[0052] Specifically, Supervisory Control and Data Acquisition (SCADA) is a computer-based distributed control system (DCS) and power automation monitoring system.

[0053] In practice, the power system simulation model, the communication system simulation model, and the SCADA system are connected via Ethernet to build a real-time simulation platform for the power cyber-physical system.

[0054] S140, in the real-time simulation platform of power cyber-physical systems, realizes data transmission between power system simulation models, communication system simulation models and SCADA systems based on the policy routing mechanism.

[0055] In practice, the data stream generated by the power system simulation model in the OPAL-RT real-time simulator and the control command data generated by the SCADA system are directly routed as IP packets to the OMNet++ host through the Linux policy routing mechanism. They are then transparently mapped to the virtual network nodes in OMNet++ to achieve seamless connection between the power system and the communication system and ensure smooth data transmission.

[0056] S150 integrates attack and protection models in a communication simulation environment within a real-time simulation platform for power cyber-physical systems, and verifies the security of the power system based on the attack and protection models.

[0057] Specifically, OMNeT++ employs a modular design, where each component in the simulation (such as network devices and protocol stacks) is encapsulated as an independent module. It also provides a rich set of Application Programming Interfaces (APIs) and libraries, supporting the simulation of various network protocols and components. Based on this design framework, it is easy to build and add customized network security attack and protection models specific to power grid systems. By configuring the simulation environment to simulate specific network attack scenarios, the secure communication mechanisms between the power system and the communication system can be verified.

[0058] As an example, attack models include, but are not limited to, denial-of-service attacks, distributed denial-of-service attacks, malware propagation, phishing attacks, insider attacks, and advanced persistent threats.

[0059] For example, a Denial of Service (DoS) attack simulates attackers making the communication network or control center of a power system unusable through flood attacks, resource exhaustion, etc.; a Distributed Denial of Service (DDoS) attack simulates a large number of distributed attackers launching simultaneous attacks on the power system to overwhelm network devices and servers; malware propagation simulates the spread of malware such as worms and viruses within the power system's internal network, affecting the normal operation of the system; phishing attacks simulate attackers impersonating legitimate entities to trick users into disclosing login credentials or other sensitive information; insider attacks simulate insiders abusing their privileges to damage the power system or leak data; and Advanced Persistent Threats (APTs) simulate sophisticated, organized attackers lurking in the network for extended periods, conducting covert reconnaissance and attacks.

[0060] As an example, protection models include, but are not limited to, firewalls, intrusion detection systems, intrusion prevention systems, security information and event management, encryption and authentication mechanisms, and network isolation and segmentation.

[0061] For example, firewalls filter network traffic to block unauthorized access and malicious traffic; Intrusion Detection Systems (IDS) monitor network traffic to detect and alert on potential attacks; Intrusion Prevention Systems (IPS) automatically take measures to block attacks when they are detected; Security Information and Event Management (SIEM) provides visualization and management of security threats by collecting and analyzing security events; Encryption and Authentication Mechanisms simulate the use of encryption technology to protect the security of data transmission and the use of authentication mechanisms to ensure the origin and integrity of data; Network Isolation and Segmentation simulates the segmentation of critical networks through physical or logical means to limit the spread of attacks.

[0062] The technical solution provided in this application utilizes open-source simulation software such as RT-LAB, OPAL-RT real-time simulators, and OMNet++ to construct power system simulation models and communication system simulation models, and performs real-time co-simulation. Based on the power system simulation model, communication system simulation model, and SCADA system, a real-time simulation platform for power cyber-physical systems is built. Within this platform, a policy-based routing mechanism enables data transmission between the power system simulation model, communication system simulation model, and SCADA system. Attack and protection models are integrated within the communication simulation environment, and the security of the power system is verified based on these models. Compared to using commercial software such as Exata or OPNET to build the simulation platform, using open-source simulation software not only reduces construction costs but also improves the scalability of the simulation platform, allowing users to perform secondary development according to actual needs and enhancing the user experience.

[0063] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically, in this embodiment, in the real-time simulation platform for power information physical systems, data transmission between the power system simulation model, the communication system simulation model, and the SCADA system is realized based on a policy routing mechanism, including:

[0064] The first device, the second device, and the third device are connected via Ethernet, and their IP addresses are configured as the first IP address, the second IP address, and the third IP address, respectively. The first device, the second device, and the third device are respectively the devices for deploying the OPAL-RT real-time emulator, the SCADA system, and the OMNet++ software.

[0065] In the third device, a first virtual network node and a second virtual network node are created in the communication system simulation model, and their IP addresses are configured as the fourth IP address and the fifth IP address, respectively. A mapping between the first IP address and the fourth IP address and a mapping between the second IP address and the fifth IP address are established in the communication system simulation model.

[0066] Based on the first IP address, second IP address, third IP address, fourth IP address, and fifth IP address, a policy-based routing mechanism is used to realize data transmission between the power system simulation model, the communication system simulation model, and the SCADA system.

[0067] In specific implementation, such as Figure 4 As shown, to simulate the application scenario and communication process of Modbus TCP in the power industry, the first device Host_A is deployed as an OPAL-RT real-time simulator, the second device Host_B is a SCADA system, and the third device Host_C runs the network communication simulation software OMNet++. Host_A, Host_B, and Host_C are connected together via Ethernet. The first IP address of Host_A is 192.168.1.100, the second IP address of Host_B is 192.168.1.101, and the third IP address of Host_C is 192.168.1.254. In the Host_C device, a communication system simulation model is built using OMNet++ and INET. A first virtual network node and a second virtual network node are created in the communication system simulation model, configured with the fourth IP address 192.168.4.100 and the fifth IP address 192.168.4.101, respectively. A Modbus-based simulation software is configured in the power system simulation model of Host_A. The TCP slave device is used, while the SCADA system in Host_B acts as the master device. The first IP address of the slave running in Host_A is mapped to the fourth IP address 192.168.4.100 of the first virtual network node built in OMNet++, and the second IP address of the SCADA system running in Host_B is mapped to the fifth IP address 192.168.4.101 of the second virtual network node built in OMNet++.

[0068] As an example, when the Master of the SCADA system running on the second IP address 192.168.1.101 needs to obtain data from the Slave on the first IP address 192.168.1.100, the Slave's IP address is configured in the SCADA system to be the fourth IP address of the first virtual network node in OMNet++, 192.168.4.100.

[0069] The technical solution provided in this embodiment realizes data transmission in the real-time simulation platform of the power cyber-physical system based on the policy routing mechanism, achieving seamless connection between the power system and the communication system and ensuring smooth data transmission.

[0070] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically, in this embodiment, based on the first IP address, the second IP address, the third IP address, the fourth IP address, and the fifth IP address, a policy routing mechanism is used to realize data transmission between the power system simulation model, the communication system simulation model, and the SCADA system, including:

[0071] Using the third IP address as the next-hop address, configure a first static routing rule on the first device and a second static routing rule on the second device. The first static routing rule is used to transmit data generated by the first device to the third device, and the second static routing rule is used to transmit data generated by the second device to the third device.

[0072] In the third device, a first TAP device and a second TAP device are created, and the IP addresses of the first TAP device and the second TAP device are configured as the sixth IP address and the seventh IP address, respectively. These two TAP devices serve as the interface for communication between the real network and the communication system simulation model built by OMNet++, and complete the transparent access of communication data between the first device and the second device to the simulation network.

[0073] On the third device, a first policy route based on the source IP is configured based on the first IP address and a new first policy route table is created. In the first policy route table, the sixth IP address is used as the next hop address, and a third static route rule is configured. Based on the combined effect of the first policy route, the first policy route table, and the third static route rule, data from the first device is routed to the first TAP device.

[0074] On the third device, a second policy route based on the source IP is configured based on the second IP address and a new second policy route table is created. In the second policy route table, the seventh IP address is used as the next hop address, and a fourth static route rule is configured. Based on the combined effect of the second policy route, the second policy route table, and the fourth static route rule, data from the second device is routed to the second TAP device.

[0075] Based on the first IP address and the fourth IP address, configure the first network address translation of the first virtual network node. The first network address translation is used to realize the translation between the first IP address and the fourth IP address.

[0076] Based on the second IP address and the fifth IP address, configure the second network address translation of the second virtual network node. The second network address translation is used to realize the translation between the second IP address and the fifth IP address.

[0077] In practical implementation, the specific steps of the data transmission process in the real-time simulation platform of the power cyber-physical system are as follows:

[0078] Step 1: Configure the first static routing rule in Host_A: ip route add 192.168.4.0 / 24 via 192.168.1.254, so that the data generated by the power system simulation model in the OPAL-RT real-time simulator is routed to the host Host_C where OMNet++ is located;

[0079] Step 2: Configure a second static routing rule in Host_B: ip route add 192.168.4.0 / 24 via 192.168.1.254, so that the control command data generated by the SCADA system is routed to the host Host_C where OMNet++ is located;

[0080] Step 3: Open the OMNet++ network communication simulation software in Host_C, build the network topology using the INET library, and create the first virtual network node V_Host_A and the second virtual network node V_Host_B using the StandardHost model. Configure one network card for each of V_Host_A and V_Host_B. Set the IP address of eth0 of V_Host_A to the fourth IP address 192.168.4.100, and set the IP address of eth0 of V_Host_B to the fifth IP address 192.168.4.101. The specific configuration in omnetpp.ini is as follows: *.configurator.config = xml(" <config><interface hosts=’V_Host_A’names=’eth0’address=192.168.4.100’netmask=’255.255.255.0’ / ><interfacehosts=’V_Host_B’names=’eth0’address=192.168.4.101’netmask=’255.255.255.0’ / >< / config> “), where eth0 of V_Host_A represents the real Host_A, and eth0 of V_Host_B represents the real Host_B;

[0081] Step 4: Enable the system's IP forwarding function in Host_C;

[0082] Step 5: Create a new first policy routing table (policyroute1) and a first TAP device (tapa) in Host_C. Configure the IP address of tapa as the sixth IP address, 192.168.2.100. Add a third static routing rule to the first policy routing table (policyroute1): `sudo ip route add 192.168.4.0 / 24via 192.168.2.100policyroute1`. Configure the first policy route based on the source IP address using the following command: `sudo ip rule add from 192.168.1.100 / 32policyroute1`. This will route IP packets from the first IP address 192.168.1.100 (the real OPAL-RT host) to the fourth IP address 192.168.4.100 (the first virtual network node) to tapa.

[0083] Step 6: Create a second policy routing table (policyroute2) and a second TAP device (tapb) in Host_C. Configure the IP address of tapb as the seventh IP address, 192.168.2.101. Add a fourth static routing rule to the second policy routing table (policyroute2): `sudo ip route add 192.168.4.0 / 24via 192.168.2.101policyroute2`. Configure the second policy route based on the source IP address using the following command: `sudo ip rule add from 192.168.1.101 / 32policyroute2`. This will route IP packets from the second IP address 192.168.1.101 (the real SCADA host) to the fifth IP address 192.168.4.101 (the second virtual network node) to tapb.

[0084] Step 7: Return to the OMNet++ network communication simulation software opened in Host_C, and add another network card eth1 for V_Host_A and V_Host_B respectively, which is used to connect the data in tapa and tapb to the simulation network built by OMNet++. Specifically, the configuration in omnetpp.ini is as follows: *.V_Host_A.eth[1].typename=“ExtUpperEthernetInterface” *.V_Host_A.eth[1].device=“tapa” *.V_Host_A.eth[1].copyConfiguration=“copyFromExt” *.V_Host_B.eth[1].typename=“ExtUpperEthernetInterface” *.V_Host_B.eth[1].device=“tapb” *.V_Host_B.eth[1].copyConfiguration=“copyFromExt”;

[0085] Step 8: Configure the first Network Address Translation (NAT) for V_Host_A in omnetpp.ini. This will translate the source address of IP packets originating from the first IP address of the real network host (192.168.1.100) to the fourth IP address of the first virtual network node (192.168.4.100), and the source address of IP packets originating from the fourth IP address of the first virtual network node (192.168.4.100) to the external real first IP address (192.168.1.100). The specific configuration is as follows: *.V_Host_A.ipv4.natTable.config = xml(" <config><entry type=’postrouting’packetFilter=’has(Ipv4Header)&;&;Ipv4Header.srcAddress.str()==\"192.168.1.100\”srcAddress=’192.168.4.100’ / ><entry type=’prerouting’packetFilter=’has(Ipv4Header)&;&;Ipv4Header.destAddress.str()==\"192.168.4.100\”’destAddress=’192.168.1.100’ / >< / config> ”);

[0086] Step 9: Configure the second network address translation (NAT) of V_Host_B in omnetpp.ini. This will translate the source address of IP packets originating from the second IP address 192.168.1.101 of the real network host to the fifth IP address 192.168.4.101 of the second virtual network node, and translate the source address of IP packets originating from the fifth IP address 192.168.4.101 of the second virtual network node to the external real second IP address 192.168.1.101. The specific configuration is as follows: *.V_Host_B.ipv4.natTable.config = xml(" <config><entry type=’postrouting’packetFilter=’has(Ipv4Header)&;&;Ipv4Header.srcAddress.str()==\"192.168.1.101\”’srcAddress=’192.168.4.101’ / ><entry type=’prerouting’packetFilter=’has(Ipv4Header)&;&;Ipv4Header.destAddress.str()==\"192.168.4.101\”’destAddress=’192.168.1.101’ / >< / config> ”).

[0087] The technical solution provided in this embodiment achieves seamless integration between the power system and the communication system through policy routing configuration, without requiring modification of the power system model.

[0088] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically, in this embodiment, in the real-time simulation platform for power cyber-physical systems, an attack model and a protection model are integrated in a communication simulation environment, and the security of the power system is verified based on the attack model and the protection model, including:

[0089] Set simulation parameters, including the timing, method, and intensity of the attack, as well as the deployment and configuration of protective measures;

[0090] Run simulations to model the operation of power systems and simulate security events in networks based on attack models;

[0091] Collect simulation data, which includes the behavior and response of the power system based on the protection model when it is attacked;

[0092] Adjust the parameters of the attack model and the defense model based on the simulation data.

[0093] In practical implementation, attack and defense models are integrated into the communication simulation environment to ensure their interaction with the power system simulation model; simulation parameters are set, including the timing, method, and intensity of attacks, as well as the deployment and configuration of defense measures; the simulation is run, simultaneously simulating the operation of the power system and security events in the network, observing the behavior and response of the power system when attacked; simulation data is collected to assess the impact of attacks and the effectiveness of defense measures, analyzing the vulnerabilities and potential risks of the power system; the parameters of the attack and defense models are adjusted based on the simulation data to optimize the security configuration of the power system; multiple simulations are conducted to test different attack scenarios and defense strategies to ensure the security of the power system.

[0094] The technical solution provided in this embodiment, under the OMNet++ framework, is based on the open-source INET model and is customized to extend the attack model and protection model, so as to better simulate the network attack scenarios that may exist in the power system. These attack models and protection models can simulate the secure communication and potential attack behaviors between the power system and the information system during the simulation process, and flexibly adjust the security mechanisms in the communication link according to the needs, thus realizing the comprehensive verification of the communication security of the power system.

[0095] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically, in this embodiment, the method further includes:

[0096] A simulation model of the communication system was constructed using NS-3 simulation software.

[0097] Specifically, in addition to OMNet++, other open-source network simulation software such as NS-3 can also be considered for building communication system simulation models. NS-3 also supports a variety of network protocols and models and has active community support.

[0098] In practice, it is necessary to first assess whether the simulation software's model library supports the required power system and communication system models, and adjust the integration method of the simulation platform to ensure compatibility with the power system model and the OPAL-RT real-time simulator.

[0099] The technical solution provided in this embodiment uses open-source simulation software to build a simulation model of the communication system, which reduces the construction cost of a real-time simulation platform for power information physical systems, while improving the flexibility and scalability of the simulation platform.

[0100] Based on the above embodiments, this embodiment further explains and optimizes the technical solution. Specifically, in this embodiment, the method further includes:

[0101] Choose a cloud service platform;

[0102] The simulation environment is deployed based on a cloud service platform.

[0103] In practice, select a suitable cloud service platform, such as Amazon Web Services (AWS), Azure, or Google Cloud, to deploy the simulation environment, ensure the security of data transmission and processing, and ensure seamless integration between the cloud platform and the local simulation environment.

[0104] The technical solution provided in this embodiment utilizes cloud computing resources for the simulation of power systems and communication systems. It can provide flexible computing power and storage resources to adapt to simulation needs of different scales, thereby improving the flexibility of the real-time simulation platform for power cyber-physical systems.

[0105] Figure 5 This is a structural block diagram of an implementation device for a real-time simulation platform for a power cyber-physical system, provided as an embodiment of this application. For ease of explanation, only the parts relevant to the embodiment of this application are shown. (Refer to...) Figure 5 The device 500 for implementing the real-time simulation platform of the power information physical system may include a first model building module 501, a second model building module 502, a simulation platform building module 503, a data transmission setting module 504, and a security verification module 505.

[0106] The first model building module 501 is used to build a power system simulation model and realize the real-time simulation of the power system using Simulink, RT-LAB software and OPAL-RT real-time simulator.

[0107] The second model building module 502 is used to build a communication system simulation model in the OMNet++ environment using the INET model library, and to configure the network topology and communication protocol of the communication system.

[0108] The simulation platform building module 503 is used to build a real-time simulation platform for power cyber-physical systems based on power system simulation models, communication system simulation models, and SCADA systems.

[0109] The data transmission setting module 504 is used to realize data transmission between the power system simulation model, the communication system simulation model, and the SCADA system in the real-time simulation platform of the power information physical system based on the policy routing mechanism.

[0110] The security verification module 505 is used to integrate attack models and protection models in a communication simulation environment within a real-time simulation platform for power cyber-physical systems, and to verify the security of the power system based on the attack models and protection models.

[0111] The implementation apparatus for a real-time simulation platform for a power cyber-physical system provided in this application embodiment has the same beneficial effects as the aforementioned implementation method for a real-time simulation platform for a power cyber-physical system.

[0112] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0113] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0114] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 6 As shown, the electronic device 6 of this embodiment includes: at least one processor 60 ( Figure 6 Only one is shown in the diagram), memory 61, and a computer program 62 stored in memory 61 and executable on at least one processor 60, wherein the processor 60 executes the computer program 62 to implement the above. Figure 1 The steps in the method embodiments, or the implementation of the above Figure 5 The functions of each module / unit in the device embodiment.

[0115] Electronic device 6 can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. This electronic device 6 may include, but is not limited to, a processor 60 and a memory 61. Those skilled in the art will understand that... Figure 6 This is merely an example of electronic device 6 and does not constitute a limitation on electronic device 6. It may include more or fewer components than shown, or combine certain components, or different components, such as input / output devices, network access devices, etc.

[0116] The processor 60 can be a Central Processing Unit (CPU), but it can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0117] In some embodiments, memory 61 may be an internal storage unit of electronic device 6, such as a hard disk or memory of electronic device 6. In other embodiments, memory 61 may be an external storage device of electronic device 6, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on electronic device 6. Furthermore, memory 61 may include both internal and external storage units of electronic device 6. Memory 61 is used to store operating system, application programs, bootloader, data, and other programs, such as program code of computer programs. Memory 61 may also be used to temporarily store data that has been output or will be output.

[0118] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the steps in the above-described method embodiments.

[0119] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to an electronic device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks.

[0120] The computer-readable storage medium provided in this application embodiment has the same beneficial effects as the above-described implementation method of a real-time simulation platform for a power information physical system.

[0121] This application provides a computer program product, which includes a computer program that, when executed by a processor, can implement the steps described in the above method embodiments.

[0122] The computer program product provided in this application embodiment has the same beneficial effects as the above-described implementation method of a real-time simulation platform for a power information physical system.

[0123] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0124] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0125] In the embodiments provided in this application, it should be understood that the disclosed devices / electronic devices and methods can be implemented in other ways. For example, the device / electronic device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings or direct couplings or communication connections may be through some interfaces; indirect couplings or communication connections between devices or units may be electrical, mechanical, or other forms.

[0126] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0127] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A method for implementing a real-time simulation platform for a power cyber-physical system, characterized in that, The method includes: Simulink, RT-LAB software, and OPAL-RT real-time simulator were used to build a power system simulation model and realize the real-time simulation of the power system. In the OMNet++ environment, a simulation model of the communication system is built using the INET model library, and the network topology and communication protocol of the communication system are configured. A real-time simulation platform for power cyber-physical systems is built based on the power system simulation model, the communication system simulation model, and the SCADA system. In the real-time simulation platform of the power information physical system, data transmission between the power system simulation model, the communication system simulation model, and the SCADA system is realized based on a policy routing mechanism. This includes: connecting a first device, a second device, and a third device via Ethernet, and configuring their respective IP addresses as a first IP address, a second IP address, and a third IP address. The first device, the second device, and the third device are respectively devices for deploying the OPAL-RT real-time simulator, the SCADA system, and the OMNet++ software. In the third device, a first virtual network node and a second virtual network node are created in the communication system simulation model, configured with IP addresses as a fourth IP address and a fifth IP address, respectively. A mapping between the first IP address and the fourth IP address, and between the second IP address and the fifth IP address, are established in the communication system simulation model. Address mapping; based on the first IP address, the second IP address, the third IP address, the fourth IP address, and the fifth IP address, the policy routing mechanism is used to realize data transmission between the power system simulation model, the communication system simulation model, and the SCADA system; including: using the third IP address as the next-hop address, configuring a first static routing rule on the first device and a second static routing rule on the second device, the first static routing rule being used to transmit data generated by the first device to the third device, and the second static routing rule being used to transmit data generated by the second device to the third device; creating a first TAP device and a second TAP device in the third device, and configuring the first TAP device and the second TAP device with IP addresses as the sixth IP address and the seventh IP address, respectively; In the real-time simulation platform for the power cyber-physical system, an attack model and a protection model are integrated in a communication simulation environment, and the security of the power system is verified based on the attack model and the protection model.

2. The method according to claim 1, characterized in that, The method of implementing data transmission between the power system simulation model, the communication system simulation model, and the SCADA system using the policy routing mechanism based on the first IP address, the second IP address, the third IP address, the fourth IP address, and the fifth IP address further includes: On the third device, a first policy route based on the source IP is configured based on the first IP address and a first policy route table is created. In the first policy route table, the sixth IP address is used as the next hop address, and a third static route rule is configured. Based on the combined effect of the first policy route, the first policy route table, and the third static route rule, data from the first device is routed to the first TAP device. On the third device, a second policy route based on the source IP is configured based on the second IP address and a new second policy route table is created. In the second policy route table, the seventh IP address is used as the next hop address, and a fourth static route rule is configured. Based on the combined effect of the second policy route, the second policy route table, and the fourth static route rule, data from the second device is routed to the second TAP device. Based on the first IP address and the fourth IP address, configure the first network address translation of the first virtual network node. The first network address translation is used to realize the translation between the first IP address and the fourth IP address. Based on the second IP address and the fifth IP address, configure the second network address translation of the second virtual network node. The second network address translation is used to realize the translation between the second IP address and the fifth IP address.

3. The method according to claim 1, characterized in that, The process of integrating attack and protection models within a communication simulation environment in the real-time simulation platform of the power cyber-physical system, and verifying the security of the power system based on the attack and protection models, includes: Set simulation parameters, including the time, method, and intensity of the attack, as well as the deployment and configuration of protective measures; Run simulations to simulate the operation of the power system and to simulate security events in the network based on the attack model; Collect simulation data, which includes the behavior and response of the power system based on the protection model when it is attacked; The parameters of the attack model and the defense model are adjusted based on the simulation data.

4. The method according to claim 1, characterized in that, The method further includes: The communication system simulation model was constructed using NS-3 simulation software.

5. The method according to claim 1, characterized in that, The method further includes: Choose a cloud service platform; The simulation environment is deployed based on the cloud service platform.

6. The method according to any one of claims 1 to 5, characterized in that, The attack model is one or more of the following: denial-of-service attack, distributed denial-of-service attack, malware propagation, phishing attack, insider attack, and advanced persistent threat. The protection model is one or more of the following: firewall, intrusion detection system, intrusion prevention system, security information and event management, encryption and authentication mechanism, and network isolation and segmentation.

7. A device for implementing a real-time simulation platform for a power information physical system, characterized in that, The apparatus for implementing the method according to any one of claims 1 to 6, the apparatus comprising: The first model building module is used to build a power system simulation model using Simulink, RT-LAB software and OPAL-RT real-time simulator and realize the real-time simulation of the power system. The second model building module is used to build a communication system simulation model in the OMNet++ environment using the INET model library, and to configure the network topology and communication protocol of the communication system. The simulation platform building module is used to build a real-time simulation platform for the power cyber-physical system based on the power system simulation model, the communication system simulation model, and the SCADA system. The data transmission setting module is used to realize data transmission between the power system simulation model, the communication system simulation model, and the SCADA system in the real-time simulation platform of the power information physical system based on the policy routing mechanism. The security verification module is used to integrate attack models and protection models in the real-time simulation platform of the power cyber-physical system under the communication simulation environment, and to verify the security of the power system based on the attack models and the protection models.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Real-time dynamic simulation test system and method for fast frequency response controller of new energy station

    CN113741214A

  • Power distribution network simulation method, system and device, and computer-readable storage medium

    WO2024103232A1