A steganography security defense method and system for a transformer area intelligent fusion terminal

Through mimetic defense technology and container technology, a mimetic security defense system for substation integrated terminals is designed, which solves the data protection problems of micro-applications and MQTT agents, improves the security protection capabilities of intelligent integrated terminals in distribution substations, and realizes lightweight micro-application-level scheduling and automatic recovery of abnormal services.

CN119743282BActive Publication Date: 2025-10-17EAST CHINA INST OF COMPUTING TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411723673.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-10-17
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

In the existing technology of intelligent fusion terminals in distribution substations, the data protection capabilities of micro-applications and MQTT agents are insufficient, and traditional passive defense mechanisms are difficult to cope with new threats and advanced attacks.

Method used

Using mimetic defense technology, a mimetic security defense system is designed for the integrated terminal in the substation, including distribution components, judgment components, executors and negative feedback scheduling modules. It implements active defense against unknown threats through heterogeneous redundancy and dynamic scheduling. Combining container technology and MQTT protocol, it realizes lightweight scheduling at the micro-application level and automatic cleaning and recovery of abnormal services.

Benefits of technology

It improves the unknown threat defense capability of the integrated terminal, reduces resource consumption, ensures the reliability of data transmission and the self-healing capability of the system, adapts to the general subscription distribution model architecture, and realizes the mimetic transformation of business micro-applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119743282B_ABST
    Figure CN119743282B_ABST
Patent Text Reader

Abstract

The present application relates to a kind of quasi-state security defense method and system for intelligent fusion terminal of transformer area, system includes distribution component, decision component, executor, data interaction center and negative feedback scheduling module, decision component includes publisher decision component and subscriber decision component, executor includes publisher executor and subscriber executor, method is added with publisher decision maker and subscriber decision maker, while adopting MQTT proxy center itself to distribute subscriber data, increase the message retransmission mechanism of timing consistency, reduce the resource consumption when system runs and synchronizes.It solves how to improve the security protection capability of intelligent fusion terminal of distribution transformer area, solves the problem of micro application and MQTT proxy data protection, the present application combines quasi-state defense technology, designs quasi-state defense method and device of the MQTT micro application of transformer area fusion terminal, improves the unknown threat defense capability of fusion terminal micro application.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a quasi-state security defense method and system for a transformer area intelligent fusion terminal. BACKGROUND

[0002] With the rapid construction of new power systems, distributed resources such as distributed power supplies, energy storage and electric vehicles are rapidly developing, and distribution networks are facing new demands such as new energy consumption, resource aggregation, and coordinated control. The coordination and complementary and flexible interaction between the distributed wind, light, and microgrids, flexible loads, and energy storage in the transformer area, between transformer areas, and across regions have become important features of new distribution networks. Along with this, the security risks of distribution transformer terminal devices, communication networks, and business systems are constantly increasing, and the security protection capabilities of business applications in response to unknown vulnerabilities and unknown attacks are insufficient, and other problems are increasingly prominent.

[0003] The transformer area intelligent fusion terminal is used as an edge-side application, and adopts a software framework scheme of a unified operating system based on container technology, which is the core management unit and edge computing node of the intelligent distribution transformer area in the power distribution Internet of Things. The uplink communication is responsible for transmitting monitoring data from the transformer area intelligent fusion terminal to the upper master station, and the downlink communication is responsible for the information interaction of the control instructions and the like between the transformer area intelligent fusion terminal and the lower terminal device, so that the micro applications in the fusion terminal follow three basic principles: first, the micro applications interact through the message mechanism provided by the data center, avoid private communication, realize data interaction decoupling, reduce interaction management complexity, second, data is centrally managed to avoid each micro application establishing a private database, ensure data security performance, and improve data use efficiency, and third, the micro application naming, function, and reserved interface are clear to ensure effective management of the micro application. In view of the above principles, the micro applications of the transformer area generally interact with the data center and the device, the data interaction architecture adopts the MQTT protocol architecture of subscription distribution, and the device and the micro application register the virtual model and the virtual device to the data center through the MQTT protocol.

[0004] Quasi-state defense is an active security defense behavior, and a dynamic heterogeneous redundant architecture similar to biological quasi-state is constructed to make the real system immune to the detection and attack of attackers. The fusion quasi-state defense architecture of the transformer area fusion terminal can enhance the unknown threat defense capability of the system, but compared with traditional information systems, how to adapt the fusion terminal business application to the quasi-state defense technology is still a technical problem to be solved.

[0005] Traditional intelligent terminal security protection technology mostly relies on passive defense mechanism, such as firewall and security gateway technology. However, with the emergence of new threats and advanced attack means, passive defense effect is limited. As a new type of Internet of Things terminal, the intelligent fusion terminal of the power distribution area not only has the traditional data acquisition and transmission function, but also increases the data processing application, including acquisition application, analysis application and basic application (MQTT proxy middleware), as shown in Figure 1 The implementation mode of these applications in the intelligent fusion terminal is as follows:

[0006] 1. Acquisition application: as a micro application data publisher, responsible for collecting data from various sensor terminals, such as electric meter acquisition, temperature acquisition, switch acquisition, etc.

[0007] 2. Analysis application: as a micro application data subscriber, receiving and processing the data sent by the acquisition application, such as line loss analysis, power quality analysis, etc.

[0008] 3. Basic application: such as MQTT proxy middleware, providing data proxy service, realizing edge management and cloud-edge communication.

[0009] How to improve the security protection capability of the intelligent fusion terminal of the power distribution area, solve the data protection problem of the micro application and the MQTT proxy, which is the problem to be solved by the present application. SUMMARY

[0010] In order to improve the security protection capability of the intelligent fusion terminal of the power distribution area, solve the problem of micro application and MQTT proxy data protection, a quasi-state security defense method and system for the intelligent fusion terminal of the power distribution area are proposed. The quasi-state defense method and device of the MQTT micro application of the fusion terminal of the power distribution area are designed in combination with the quasi-state defense technology, and the unknown threat defense capability of the micro application of the fusion terminal is improved.

[0011] The technical scheme of the present application is:

[0012] A quasi-state security defense system for the intelligent fusion terminal of the power distribution area, comprising a distribution component, a decision component, an execution body, a data interaction center and a negative feedback scheduling module, the decision component comprising a publisher decision component and a subscriber decision component, the execution body comprising a publisher execution body and a subscriber execution body,

[0013] Distribution component:

[0014] The main function of the distribution component is to copy and forward the data generated by the device side and the instructions issued by the cloud to N (N >= 3) micro application publisher execution bodies, and to distribute the data in the form of delay cache queue according to the time sequence when distributing the data, so as to guarantee the time sequence consistency of the message sending and support the message retransmission; it is the only entrance to receive input data;

[0015] Micro application publisher executor:

[0016] The micro application publisher executor is one of the paratopic defense architecture defense objects, which is generated by the fusion terminal micro application through heterogeneous redundancy technology, follows the processing logic of the original application of the fusion terminal, and independently processes the distributed data between the micro application publisher executors and sends the results to the publisher decision component for consistency decision. The micro application publisher executor adopts the micro-isolation redundancy deployment mode and realizes the active defense of unknown threats and vulnerability backdoors through the dynamic scheduling of the negative feedback scheduling component.

[0017] Publisher decision component:

[0018] The main function of the publisher decision component is to merge the execution results of N executors, and to make a decision on the response results of the publisher executor by using the majority voting method. At the same time, the majority consistent result is published to the data interaction center through the decision, which is the reference basis for identifying whether the publisher executor is abnormal and for feedback control component cleaning and recovery.

[0019] Negative feedback scheduling:

[0020] Negative feedback scheduling is an execution program for cleaning and recovery of the system in the face of abnormal response. According to the decision result of the decision component, the scheduling algorithm is used to realize the cleaning and recovery of the abnormal executor container level, and the distributor is notified to resend the message for processing, so as to ensure the reliability of the system data transmission and realize the attack self-healing and state recovery of the system in the face of unknown threats.

[0021] Subscriber executor:

[0022] The subscriber executor subscribes to the specified topic of the data interaction center, receives the message published by the specified micro application publisher executor, follows the original message processing logic of the fusion terminal, and independently processes the message between the subscriber executors. The processed results are sent to the subscriber decision component for decision.

[0023] Subscriber decision component:

[0024] The main function of the subscriber decision component is to receive the message sent by the subscriber executor and decide the final response result according to the decision result. It is the only export of external output data and also the symbol of message processing completion.

[0025] A paratopic security defense method for a smart fusion terminal in a transformer area, which is implemented based on the paratopic security defense system for the smart fusion terminal in the transformer area, and the specific workflow is as follows:

[0026] In the initialization phase, the subscriber executor establishes a connection with the MQTT data interaction center as a client and registers to the specified message topic of the MQTT broker. After the decision of the mimic decider of the publisher decision component, the publisher executor establishes a connection with the MQTT data interaction center as a publisher, publishes the message of the specified topic to the MQTT data interaction center, and then realizes the initialization and construction of the message communication mechanism under the MQTT protocol architecture.

[0027] In the working phase, the data processing process is shown in the following steps:

[0028] Step 1: The distributor component receives the data collected by the sensor, stores the data in the cache queue, and when the distributor receives the processed message sent by the subscriber decision component, takes out the message packet from the cache queue and makes N copies (N >= 3), and sends them to the specified micro application publisher executor respectively.

[0029] Step 2: After the micro application publisher executor receives the data sent by the distributor, it analyzes and processes the data respectively, and sends the analysis result to the publisher decision component for consistency decision.

[0030] Step 3: The publisher decision component makes a decision on the analysis result of the micro application publisher executor. When the decision result is consistent, the message is published to the MQTT data center, and the process goes to step 4. When the decision result is inconsistent, the decision maker sends an exception feedback to the negative feedback scheduling, and the process goes to step 3.1.

[0031] Step 3.1: The negative feedback scheduling schedules the micro application publisher executor, and after cleaning and recovery, notifies the distributor to resend the packet to the micro application publisher executor for execution, and the process goes to step 1.

[0032] Step 4: The MQTT data center pushes the message subscribed to the distribution topic to the subscriber executor.

[0033] Step 5: The subscriber executor processes the data according to the original logic of the program and sends it to the subscriber decision component for consistency decision.

[0034] Step 6: The subscriber decision component makes a decision on the processing result of the subscriber executor. When the decision result is consistent, the data is transmitted to the subsequent service, and the message of this packet is sent to the distributor. When the decision data is inconsistent, the decision maker sends the packet to the negative feedback scheduling, and the process goes to step 6.1.

[0035] Step 6.1: The negative feedback scheduling cleans and recovers the subscriber, and notifies the distributor to resend the packet, and the process goes to step 1.

[0036] Further, the docker container is used as the deployment environment of the executor.

[0037] Further, the distribution component adopts the netty component of java as the message forwarding carrier, analyzes and forwards the mqtt protocol, and the data forwarding adopts the form of cache queue for processing, redis can be used as the cache queue for message sending, and each single message is distributed to guarantee the consistency of the message order.

[0038] Further, the decision component is realized by adopting a competitive hierarchical decision algorithm, the messages are merged based on the MQTT protocol, a time window is set during message receiving, the messages in the time window are compared, when the compared contents of the messages are consistent, one message is selected and published to the data interaction center, and when the compared contents of the messages are inconsistent, feedback is given to the scheduling component for cleaning and recovery.

[0039] Further, the negative feedback scheduling component is realized by adopting the native API of docker, the running container is stopped, deleted, created and restarted, the attacked container is replaced in time, so that the dynamic recovery of the system execution body is realized, and on the scheduling rule, the scheduling can be based on the credibility in the design, the scheduling rule is optimized through the historical performance of different execution bodies, and the scheduling rule can also be dynamically updated in combination with other rules.

[0040] Further, the data interaction center adopts Mosquitto as the MQTT message proxy, provides a lightweight publish / subscribe message transmission mechanism, and realizes the message communication of the message publisher and the subscriber.

[0041] The present application has the advantages that:

[0042] The present application is based on the existing scene of the intelligent fusion terminal, designs the mimic security defense architecture of the fusion terminal micro application, adapts the general subscription distribution model architecture, and can realize the mimic transformation of the fusion terminal business micro application with low invasion.

[0043] The present application realizes the lightweight micro application level scheduling through the container technology, reduces the resource consumption, realizes the automatic cleaning and recovery of the abnormal service, and improves the threat active immunity ability of the system.

[0044] The present application designs the message retransmission mechanism, designs the linkage processing mechanism of distribution, decision and negative feedback in the system operation mechanism, improves the scheduling efficiency of the system, and guarantees the reliable transmission of the system message. DETAILED DESCRIPTION

[0045] Figure 1 The figure is a main APP structure of the fusion terminal;

[0046] Figure 2 The figure is a mimic transformation architecture of the fusion terminal micro application of the present application;

[0047] Figure 3 The message processing flowchart under the subscription distribution model for the present application. DETAILED DESCRIPTION

[0048] The present application will be described in detail below with reference to the accompanying drawings and specific embodiments. The present embodiment is implemented on the basis of the technical solution of the present application, and detailed implementation and specific operation processes are given, but the protection scope of the present application is not limited to the following embodiments.

[0049] The present application proposes a kind of security protection method of district area fusion terminal based on mimetic defense architecture, traditional mimetic reconstruction scheme is mainly to the input and output of dynamic redundancy system service end program respectively monitored, to identify abnormal attack behavior, district area fusion terminal can utilize resource is less, and message passing mechanism is typical subscription distribution mode, although the decoupling between micro application is realized, but the processing of data needs to pass through publisher subscriber and multiple micro applications in this mode, traditional reconstruction scheme needs to carry out heterogeneous redundant processing to all applications in input and output, the amount of resource consumed is large, it is difficult to realize on fusion terminal, and since only the decision on input and output, it is difficult to identify the threat state of intermediate state execution body, increase the difficulty of system recovery, therefore, according to the characteristics of fusion terminal resource limitation, based on the software framework architecture of intelligent fusion terminal based on container technology unified operating system, low-invasion fusion terminal micro application reconstruction scheme is designed, and micro application level decision is carried out, micro application level threat identification is realized, the range of cleaning recovery is reduced while resource consumption is reduced.

[0050] The present application designs mimetic defense architecture under subscription distribution communication mode in the scene of district area fusion terminal, increases subscriber decision maker and publisher decision maker, simultaneously adopts that MQTT proxy center itself distributes subscriber data, increases message retransmission mechanism of time sequence consistency, reduces resource consumption when system runs and synchronizes.

[0051] The mimetic security defense system for district area intelligent fusion terminal provided by the present application mainly includes distribution component, decision component, execution body, data interaction center and negative feedback scheduling module, decision component includes publisher decision component and subscriber decision component, execution body includes publisher execution body and subscriber execution body, reference is made to the accompanying drawings Figure 2 :

[0052] 1) distribution component (i.e. distributor, distribution agent component)

[0053] The main function of the distribution component is to copy and forward the data generated by the device side and the instructions issued by the cloud to N (N >= 3) application executors (i.e. micro application publisher executors), and to distribute the data in the form of a delay cache queue according to the time sequence when distributing the data, thereby guaranteeing the time sequence consistency of the message transmission while supporting message retransmission. It is the only entrance for receiving input data.

[0054] 2) Micro application publisher executors (i.e. publisher executors)

[0055] The micro application publisher executors are one of the defense objects of the paratonic defense architecture, which are generated by the fusion terminal micro application through heterogeneous redundancy technology, and follow the processing logic of the original application of the fusion terminal. The micro application publisher executors independently process the distributed data and send the results to the publisher decision component for consistency decision. The micro application publisher executors are deployed in a micro-isolation redundancy manner and are dynamically scheduled by the negative feedback scheduling component, thereby achieving active defense against unknown threats and vulnerability backdoors.

[0056] 3) Publisher decision component (i.e. publisher decider)

[0057] The main function of the publisher decider is to merge the execution results of N executors and make a decision on the response results of the publisher executors using a large number voting method. The publisher decider publishes the majority consistent result to the data interaction center, which is the reference basis for identifying whether the publisher executors are abnormal and for the feedback control component to clean up and recover.

[0058] 4) Negative feedback scheduling (i.e. feedback control component, negative feedback scheduling module, negative feedback scheduling component)

[0059] The negative feedback scheduling is an execution program for cleaning up and recovering the abnormal executors when the system encounters abnormal responses. According to the decision result of the publisher decider, the negative feedback scheduling uses a scheduling algorithm to clean up and recover the abnormal executors at the container level, and notifies the distributor to retransmit the message for processing, thereby guaranteeing the reliability of the system data transmission and enabling the system to self-heal and recover when facing unknown threats.

[0060] 5) Subscriber executors

[0061] The subscriber executors subscribe to the specified topics of the data interaction center, receive the messages published by the specified micro application publisher executors, follow the original message processing logic of the fusion terminal, and independently process the messages between the subscriber executors. The processed results are sent to the subscriber decider for decision.

[0062] 6) Subscriber decision component (i.e. subscriber decider, micro application subscriber decider)

[0063] The main function of the micro application subscriber decider is to receive the messages sent by the subscriber executor, and determine the final returned response result according to the decision result, which is the only export of the output data and the symbol of the completion of the message processing.

[0064] The above is the function and working mode of each component of the mimicry defense architecture of the fusion terminal. The working process of the whole system is introduced below.

[0065] In the initialization stage, the subscriber executor acts as a client to establish a connection with the MQTT data interaction center and is registered to the specified MQTT message broker publishing topic. The publisher executor establishes a connection with the MQTT data interaction center after being judged by the mimicry decider of the publisher decision component, and publishes the message of the specified topic to the MQTT data interaction center, thereby realizing the initialization construction of the message communication mechanism under the MQTT protocol architecture.

[0066] In the working stage, the data processing process is shown in the following steps:

[0067] Step 1: The distributor component receives the data collected by the sensor, such as the power consumption data of the electric meter, stores the data in the cache queue, and when the distributor receives the processed message sent by the subscriber decider, takes out the message packet from the cache queue and makes N copies (N >= 3), and sends them to the specified micro application publisher executor.

[0068] Step 2: After the micro application publisher executor receives the data sent by the distributor, it analyzes and processes the data respectively, and sends the analysis result to the publisher decision component for consistency decision.

[0069] Step 3: The publisher decider judges the analysis result of the micro application publisher executor, and when the decision result is consistent, publishes the message to the MQTT data center, and goes to step 4. When the decision result is inconsistent, the decider sends an abnormal feedback to the negative feedback scheduling, and goes to step 3.1.

[0070] Step 3.1: The negative feedback scheduling schedules the micro application publisher executor, and after cleaning and recovery, notifies the distributor to resend the packet to the micro application publisher executor for execution, and goes to step 1.

[0071] Step 4: The MQTT data center pushes the message subscribed to the distribution topic to the subscriber executor.

[0072] Step 5: The subscriber executor processes the data according to the original logic of the program and sends it to the subscriber decider for consistency decision.

[0073] Step 6 The subscriber decision maker judges the processing result of the subscriber executor, judges the result to be consistent, transmits data to the subsequent service, and sends a message that the message is processed to the distributor, the message is processed, when the judgment data is inconsistent, the decision maker sends a message to the negative feedback scheduling, and goes to step 6.1.

[0074] Step 6.1 The negative feedback scheduling cleans and recovers the subscriber, informs the distributor to resend the message, and goes to step 1.

[0075] The implementation tool in the embodiment is as follows:

[0076] The system is constructed by taking the deployment environment of the docker container as the executor.

[0077] The distributor uses the netty component of java as the message forwarding carrier, analyzes and forwards the mqtt protocol, and processes the data forwarding in the form of a cache queue, which can use redis as the cache queue of the message sending, and distributes a single message each time to guarantee the consistency of the message order.

[0078] The decision component is realized by using a competitive hierarchical arbitration algorithm, merges the messages based on the MQTT protocol, sets a time window during the message receiving, compares the messages in the time window, selects one message to publish to the data interaction center when the message comparison content is consistent, and feeds back to the scheduling component for cleaning and recovery when the message comparison content is inconsistent.

[0079] The negative feedback scheduling component is realized by using the docker native API, stops, deletes, creates and restarts the running container, rotates the attacked container in time to realize the dynamic recovery of the system executors, and can be scheduled based on the credibility in the design, optimizes the scheduling rule through the historical performance of different executors, and can also be dynamically updated in combination with other rules.

[0080] The data interaction center uses Mosquitto as the MQTT message proxy to provide a lightweight publish / subscribe message transmission mechanism and realize the message communication between the message publisher and the subscriber.

[0081] The above-described embodiment only expresses one embodiment of the present application, and the description is more specific and detailed, but it cannot be understood as a limitation on the scope of the patent. It should be noted that, for ordinary skilled persons in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

Claims

1. A mimic security defense system for intelligent fusion terminals in substations, characterized in that: It includes distribution components, decision components, executive bodies, data interaction centers, and negative feedback scheduling modules. The decision components include publisher decision components and subscriber decision components. The executive bodies include micro-application publisher executive bodies and subscriber executive bodies. Distribution component: The function of the distribution component is to copy and forward the data generated on the device side and the instructions issued by the cloud to N and N>=3 micro-application publisher execution bodies. During data distribution, it uses a delayed cache queue to distribute data according to the time sequence, ensuring the timing consistency of message sending while supporting message retransmission. It is the only entry point for receiving input data. Micro-application publisher executors: These are one of the defense targets of the mimic defense architecture. They are generated by fusion terminal micro-applications using heterogeneous redundancy technology and follow the processing logic of the original fusion terminal applications. Micro-application publisher executors independently process distributed data and send the results to the publisher judgment component for consistency determination. They utilize micro-isolation redundant deployment and dynamic scheduling through the negative feedback scheduling module to achieve active defense against unknown threats and vulnerability backdoors. Publisher judgment component: The function of the publisher judgment component is to merge the execution results of N execution bodies and use the majority vote method to judge the response results of the micro-application publisher execution body. At the same time, the majority consensus result is published to the data interaction center through judgment. It is a reference for identifying whether the micro-application publisher execution body has anomalies and feeding back to the negative feedback scheduling module for cleaning and recovery; Negative Feedback Scheduling Module: This module is the execution program for cleaning and recovering the system's abnormal response. Based on the judgment results of the publisher judgment component, it uses a scheduling algorithm to implement container-level cleaning and recovery of abnormal execution bodies, and notifies the distribution component to resend messages for processing, ensuring the reliability of system data transmission and enabling the system to self-heal and recover from attacks in the face of unknown threats. Subscriber Executor: The subscriber executor subscribes to the designated topic of the data interaction center and receives messages published by the designated micro-application publisher executor. Following the original message processing logic of the fusion terminal, each subscriber executor performs redundant and independent processing on the message and sends the result of the processing and analysis for judgment. Subscriber decision component: The function of the subscriber decision component is to receive messages sent from the subscriber executor and determine the final response result based on the decision result. It is the only outlet for outputting data to the outside world and also serves as a sign that message processing is completed.

2. A mimic security defense method for intelligent fusion terminals in a substation area, characterized in that: Based on the implementation of the mimic security defense system for the intelligent fusion terminal in the substation area as claimed in claim 1, the specific workflow is as follows: In the initialization phase, the subscriber executor establishes a connection with the MQTT data interaction center as a client and registers with the MQTT agent to specify the message topic. After the publisher judgment component makes a decision, the micro-application publisher executor establishes a connection with the MQTT data interaction center as a micro-application publisher executor. The micro-application publisher executor publishes messages of the specified topic to the MQTT data interaction center, thereby realizing the initialization construction of the message communication mechanism under the MQTT protocol architecture. During the working phase, the data processing flow is as follows: Step 1: The distribution component receives the data collected by the sensor and stores the data in the cache queue. When the distribution component receives the processed message sent by the subscriber judgment component, it takes the message message from the cache queue and copies it N times (N>=3), and sends it to the specified micro-application publisher executable respectively. Step 2: After receiving the data sent by the distribution component, the micro-application publisher executive body analyzes and processes the data and sends the analysis results to the publisher judgment component for consistency judgment; Step 3: The publisher judgment component judges the analysis results of the micro-application publisher's executable body. If the judgment results are consistent, the message is published to the MQTT data center and the process goes to step 4. If the judgment results are inconsistent, the publisher judgment component sends an exception feedback to the negative feedback scheduling module and the process goes to step 3.

1. Step 3.1 The negative feedback scheduling module schedules the micro-application publisher executive body. After the cleaning and recovery are completed, it notifies the distribution component to resend the message to the micro-application publisher executive body for execution, and then goes to step 1; Step 4 The MQTT data center pushes the message subscribed to the topic to the subscriber execution body; Step 5: The subscriber executor processes the data according to the original logic of the program and sends it to the subscriber judgment component for consistency judgment; Step 6: The subscriber judgment component judges the processing results of the subscriber execution body. If the judgment results are consistent, the data is transmitted to the subsequent service and the message of the completion of the message processing is sent to the distribution component. If the judgment data is inconsistent, the subscriber judgment component sends a message to the negative feedback scheduling module and goes to step 6.

1. Step 6.1 The negative feedback scheduling module cleans and recovers the subscriber execution body, notifies the distribution component to resend this message, and then goes to step 1.

3. The mimic security defense method for intelligent fusion terminals in substations according to claim 2, characterized in that: A deployment environment using Docker containers as execution bodies.

4. The mimic security defense method for a smart fusion terminal in a substation according to claim 2, characterized in that: The distribution component uses Java's Netty component as the message forwarding carrier, analyzes and forwards the MQTT protocol, processes data forwarding in the form of a cache queue, and uses Redis as the cache queue for message sending. It distributes a single message each time to ensure the consistency of the message order.

5. The mimic security defense method for intelligent fusion terminals in substations according to claim 2, characterized in that: The judgment component is implemented using a competitive hierarchical decision algorithm, which merges and processes messages based on the MQTT protocol. A time window is set during message reception, and messages within the time window are compared. When the message comparison contents are consistent, one message is selected and published to the data interaction center. When the message comparison contents are inconsistent, feedback is given to the negative feedback scheduling module for cleaning and recovery.

6. The mimic security defense method for intelligent fusion terminals in substations according to claim 2, characterized in that: The negative feedback scheduling module is implemented using the Docker native API to stop, delete, create, and restart running containers, and to rotate attacked containers in a timely manner to achieve dynamic recovery of each executor in the system. The scheduling rules are based on credibility, and the scheduling rules are optimized through the historical performance of different executors, or dynamically updated in combination with other rules.

7. The mimic security defense method for intelligent fusion terminals in a substation according to claim 2, characterized in that: The data interaction center uses Mosquitto as the MQTT message broker, providing a lightweight publish / subscribe message transmission mechanism to realize message communication between message publishers and subscribers.

Citation Information

Patent Citations

  • Micro-service-based mimicry application architecture system and scheduling method thereof

    CN115794297A

  • Mimicry HSS network element signaling processing method and system

    CN116668097A