Power load management method and system based on Internet of Things

By adopting encryption and signature technology, distributed storage and redundant backup in the IoT power load management system, as well as real-time monitoring of network transmission flow rates, the difficulties of information encryption and attack prevention in IoT power load management are solved, and high data security and reliability are achieved.

CN119945740APending Publication Date: 2025-05-06MAOMING POWER SUPPLY BUREAU GUANGDONG POWER GRID CORP
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411954162.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The prior art is difficult to ensure the implementation of security mechanisms such as encryption of information and prevention of attacks in the management of power loads in the Internet of Things.

Method used

By using IoT sensors to acquire power load data and preprocess it, data is protected using encryption and signature technologies, data security is enhanced using distributed storage systems and redundant backup strategies, and network transmission flow rate is monitored in real time to trigger alarms.

Benefits of technology

Ensure the confidentiality and integrity of the data during transmission, enhance the security and reliability of the data, promptly detect and respond to abnormal traffic or attack behaviors, and improve the overall security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945740A_ABST
    Figure CN119945740A_ABST
Patent Text Reader

Abstract

The invention provides a power load management method and system based on the Internet of Things, and relates to the technical field of power load management, and the method comprises the steps: continuously obtaining power load data through employing an Internet of Things sensor, carrying out the preprocessing, carrying out the encryption and signature according to the preprocessed power load data, so as to obtain signed power load data, and transmitting the signed power load data to a server; transmitting the signed power load data to a control center through a network, storing the signed power load data by using a distributed storage system, and performing redundant backup on the signed power load data to obtain stored power load data; in the network transmission process, the data transmission flow rate is monitored in real time to obtain a monitoring result; according to a monitoring result and a preset threshold value, if abnormal traffic or attack behaviors are monitored, the system triggers an alarm; and according to the stored power load data, the control center carries out decryption and verification to obtain decrypted power load data. According to the invention, the realization of security mechanisms such as information encryption and attack prevention is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power load management, and in particular to a power load management method and system based on the Internet of Things. Background Art

[0002] With the acceleration of industrialization and urbanization, electricity demand continues to grow, and power load management has become increasingly important. The rise of Internet of Things technology has provided a new solution for power load management. The power load management system based on the Internet of Things can monitor, analyze and control power loads in real time, and improve the efficiency and stability of the power system. The Internet of Things technology uses various information sensing devices to collect various information that needs to be monitored, connected, and interacted in the power system in real time, such as voltage, current, power and other parameters. The information is transmitted to the cloud or data center for analysis and processing, thereby providing data support for power load management.

[0003] Although the Internet of Things technology has improved the intelligence level of power load management, it has also brought new security risks. How to ensure the implementation of security mechanisms such as information encryption and attack prevention during data transmission and storage is an issue that existing technologies need to focus on. Summary of the invention

[0004] The present invention provides an Internet of Things-based power load management method and system to ensure the implementation of security mechanisms such as information encryption and attack prevention.

[0005] In order to solve the above technical problems, the technical solution of the present invention is as follows:

[0006] In a first aspect, a method for managing power load based on the Internet of Things is provided, the method comprising:

[0007] Use IoT sensors to continuously acquire power load data and perform preprocessing to obtain preprocessed power load data;

[0008] Encrypting and signing the preprocessed power load data to obtain the signed power load data;

[0009] The signed power load data is transmitted to the control center through the network and stored using a distributed storage system, and the signed power load data is redundantly backed up to obtain the stored power load data;

[0010] During the network transmission process, the data transmission flow rate is monitored in real time to obtain the monitoring results;

[0011] Based on the monitoring results and preset thresholds, if abnormal traffic or attack behavior is detected, the system will trigger an alarm;

[0012] Based on the stored power load data, the control center performs decryption and verification to obtain the decrypted power load data.

[0013] Furthermore, the power load data is continuously acquired using IoT sensors and preprocessed to obtain preprocessed power load data, including:

[0014] Use IoT sensors to continuously monitor and record power load data;

[0015] Performing data cleaning on the power load data to obtain cleaned power load data;

[0016] According to the cleaned power load data, data standardization is performed to obtain standardized power load data, that is, pre-processed power load data.

[0017] Further, encryption and signing are performed according to the preprocessed power load data to obtain signed power load data, including:

[0018] According to the preprocessed power load data, use C=E K (P) performs symmetric encryption to obtain symmetric encrypted power load data, where C represents the ciphertext, i.e., the encrypted power load data, and E κ represents the AES encryption function using the key K, P represents the plain text, i.e. the pre-processed power load data, and K is the AES key K;

[0019] According to the AES key K, use C K =E PU (K) performs asymmetric encryption to obtain the AES key K after asymmetric encryption, where C K It is the ciphertext of AES key K encrypted by RSA public key PU, that is, the key K of AES after asymmetric encryption, E PU represents the RSA encryption function using the key PU, K is the key K of AES;

[0020] According to the symmetrically encrypted power load data, use D = H (C), S = D d mod n is used to sign the data packet to obtain the signed power load data, where D is the summary of the data packet, H is the SHA-256 hash function, C represents the ciphertext, i.e. the encrypted power load data, K is the AES key K, d is the exponent part of the private key (d, n), n is the modulus of the RSA key pair, and S is the signature.

[0021] Furthermore, the signed power load data is transmitted to the control center through the network and stored using a distributed storage system, and the signed power load data is redundantly backed up to obtain the stored power load data, including:

[0022] Transmit the signed power load data to the control center via the network;

[0023] After receiving the signed power load data, the control center uses a distributed storage system to disperse the data to multiple nodes for storage, so as to obtain the signed power load data stored in the distributed system;

[0024] According to the signed power load data stored in the distributed system, erasure coding technology is used for redundant backup to obtain the stored power load data.

[0025] Furthermore, during the network transmission process, the data transmission flow rate is monitored in real time to obtain monitoring results, including:

[0026] Use network monitoring tools to capture data packets in the network in real time;

[0027] Based on the captured data packets, calculate the number of data packets transmitted within time t;

[0028] Depending on the number of packets transmitted, use Calculate the data transmission flow rate, where NFR t is the data transmission flow rate at time point t, TB is the transmission size of the i-th data packet, WF is the network weight factor of the i-th data packet, LT is the transmission delay of the i-th data packet, n is the total number of data packets transmitted in the monitoring window, and PLR t is the packet loss rate at time point t, α and β are adjustment coefficients, DDR i is the data demand change rate at time point t, indicating the change in data demand in the network; J i is the network congestion index at time t;

[0029] Repeat the above steps to monitor the data transmission flow rate in real time to obtain the monitoring results.

[0030] Furthermore, based on the monitoring results and preset thresholds, if abnormal traffic or attack behavior is detected, the system triggers an alarm, including:

[0031] According to the monitoring result, the flow rate is compared with the preset flow rate threshold to obtain a comparison result;

[0032] According to the comparison result, if the data transmission flow rate does not exceed the normal threshold, the traffic is normal;

[0033] According to the comparison results, if the data transmission flow rate reaches or exceeds the normal threshold, it is determined that there is abnormal traffic or attack behavior;

[0034] If an anomaly is detected, the system triggers an alarm.

[0035] Furthermore, the control center performs decryption and verification based on the stored power load data to obtain the decrypted power load data, including:

[0036] According to the stored power load data, the asymmetrically encrypted AES key is decrypted using the RSA private key to obtain the decrypted key K. The decryption process is: K = RSA d′ (C K ), where K is the AES key obtained after decryption, RSA d′ represents the RSA decryption function using the private key d, C κ It is the AES key ciphertext after asymmetric encryption;

[0037] The same hash function D′=H(C) as used for signing is used to calculate the summary of the symmetrically encrypted power load data, where D′ is the calculated summary, H is the SHA-256 hash function, and C is the symmetrically encrypted power load data;

[0038] According to the abstract, use D″=S e mod n to perform signature verification to obtain the verification result, where D″ is the summary after signature verification, S is the signature, e is the exponent part of the public key (e, n), and n is the modulus of the RSA key pair;

[0039] Compare the calculated summary D′ with the summary D″ after signature verification to obtain a comparison result;

[0040] According to the comparison result, if the calculated summary D′ is consistent with the summary D″ after the signature is verified, it means that the data has not been tampered with during transmission or storage;

[0041] The key K obtained after decryption is used to decrypt the symmetrically encrypted power load data to obtain the decrypted power load data. The decryption process is: Where P is the pre-processed power load data obtained after decryption, represents the AES decryption function using the key K, and C represents the ciphertext, i.e. the encrypted power load data.

[0042] In the second aspect, an Internet of Things-based power load management system includes:

[0043] An acquisition module, used to continuously acquire power load data using an IoT sensor and perform preprocessing to obtain preprocessed power load data;

[0044] The processing module is used to encrypt and sign the pre-processed power load data to obtain the signed power load data; transmit the signed power load data to the control center through the network, store it using a distributed storage system, and perform redundant backup of the signed power load data to obtain the stored power load data; during the network transmission process, the data transmission flow rate is monitored in real time to obtain the monitoring results; according to the monitoring results and the preset threshold, if abnormal traffic or attack behavior is monitored, the system triggers an alarm; according to the stored power load data, the control center decrypts and verifies to obtain the decrypted power load data.

[0045] According to a third aspect, a computing device includes:

[0046] one or more processors;

[0047] The storage system is used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the above method.

[0048] In a fourth aspect, a computer-readable storage medium stores a program, and the program implements the above method when executed by a processor.

[0049] The above solution of the present invention includes at least the following beneficial effects:

[0050] The above-mentioned scheme of the present invention ensures the confidentiality and integrity of data during transmission by using encryption and signature technology, and can effectively prevent data from being stolen or tampered by unauthorized personnel, thereby maintaining the accuracy and reliability of power load data; the distributed storage system and redundant backup strategy further enhance the security of data, even if some storage nodes fail or are attacked, other nodes can still ensure the integrity and availability of data, reducing the risk of data loss; real-time monitoring of data transmission flow rate during network transmission can timely detect and respond to abnormal traffic or attack behavior, which helps to timely detect potential security threats and take corresponding defensive measures, thereby improving the overall security of the system; when abnormal traffic or attack behavior is detected, the system can trigger an alarm and promptly notify relevant personnel to handle it, which helps to quickly respond to security incidents and reduce potential losses; by decrypting and verifying the stored power load data by the control center, accurate and reliable power load data can be obtained; based on accurate power load data, the control center can formulate more scientific and reasonable power load management strategies to improve the operating efficiency and stability of the power system. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1It is a flow chart of the power load management method based on the Internet of Things provided by an embodiment of the present invention.

[0052] Figure 2 It is a schematic diagram of an Internet of Things-based power load management system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0053] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0054] like Figure 1 As shown, an embodiment of the present invention proposes a power load management method based on the Internet of Things, the method comprising:

[0055] 11. Use IoT sensors to continuously acquire power load data and perform preprocessing to obtain preprocessed power load data;

[0056] 12. Encrypt and sign the preprocessed power load data to obtain the signed power load data;

[0057] 13. According to the signed power load data, the signed power load data is transmitted to the control center through the network, and stored using a distributed storage system, and the signed power load data is redundantly backed up to obtain the stored power load data;

[0058] 14. During the network transmission process, the data transmission flow rate is monitored in real time to obtain the monitoring results;

[0059] 15. Based on the monitoring results and preset thresholds, if abnormal traffic or attack behavior is detected, the system will trigger an alarm;

[0060] 16. Based on the stored power load data, the control center performs decryption and verification to obtain the decrypted power load data.

[0061] In the embodiment of the present invention, the power load data is continuously acquired through the Internet of Things sensor, which ensures the real-time and accuracy of the data, helps to timely discover the changing trend of the power load, and provides strong support for subsequent decision-making and analysis; the collected power load data is preprocessed, such as denoising, smoothing, etc., which can effectively improve the quality of the data and reduce errors and uncertainties in subsequent processing; the preprocessed power load data is encrypted and signed to ensure the confidentiality and integrity of the data during transmission. The encryption technology can prevent the data from being stolen or tampered with by unauthorized personnel, while the signature technology can verify the source and integrity of the data, thereby enhancing the credibility of the data; the use of a distributed storage system to store the signed power load data and perform redundant backup of it can ensure the high availability and fault tolerance of the data. Even if a storage node fails or is attacked, other nodes can continue to provide The service ensures the integrity and continuity of data; during network transmission, real-time monitoring of data transmission flow rate can timely detect abnormal traffic or attack behavior. The real-time monitoring mechanism helps to quickly respond to potential security threats and reduce potential losses; when abnormal traffic or attack behavior is detected, the system can trigger an alarm and promptly notify relevant personnel to handle it. The alarm mechanism helps to quickly locate the problem and take corresponding measures to improve the security and stability of the system; the control center decrypts and verifies the stored power load data to ensure the authenticity and accuracy of the data. The decrypted data can be used for subsequent power load analysis, prediction and scheduling tasks; based on the decrypted power load data, the control center can formulate a more scientific and reasonable power load management strategy to improve the operating efficiency and stability of the power system. These data can also provide important references for transactions and pricing in the power market.

[0062] like Figure 1 As shown in 11, the power load data is continuously acquired using the IoT sensor and preprocessed to obtain the preprocessed power load data, including:

[0063] Use IoT sensors to continuously monitor and record power load data;

[0064] Performing data cleaning on the power load data to obtain cleaned power load data;

[0065] According to the cleaned power load data, data standardization is performed to obtain standardized power load data, that is, pre-processed power load data.

[0066] In the embodiment of the present invention, the IoT sensor can monitor the load condition of the power system in real time and quickly capture small changes in the load data. Real-time monitoring can promptly detect abnormal conditions in the power system and prevent overload or failure. The sensor can accurately record power load data, including key parameters such as current, voltage, and power factor. The accuracy and integrity of the data provide a solid foundation for subsequent data analysis and processing. In the power load data, there may be abnormal values ​​caused by sensor failure, data transmission errors, etc. The data cleaning process can identify and remove these abnormal values ​​to ensure the accuracy and reliability of subsequent analysis. For missing values ​​caused by equipment failure or data transmission interruption, the data cleaning process can use appropriate interpolation methods or prediction models to fill in to ensure the integrity and continuity of the data. The power load data may involve multiple different physical quantities, such as current (amperes), voltage (volts), power (watts), etc. The data standardization process can convert these data of different dimensions into a unified metric for easy Subsequent data analysis and comparison; through data standardization, the influence of different dimensions on data analysis results can be eliminated, making the analysis results more objective and accurate, and the standardized data is also easier to perform subsequent statistical analysis, machine learning and other processing; after continuous monitoring, data cleaning and data standardization, the power load data has higher accuracy, completeness and consistency, providing high-quality input for subsequent data analysis and processing; high-quality power load data can provide strong support for the dispatching, planning, optimization and other decisions of the power system. Through in-depth analysis of these data, the operating laws of the power system can be discovered, load change trends can be predicted, resource allocation can be optimized, etc., thereby improving the operating efficiency and stability of the power system; with the continuous development and application of Internet of Things technology, the power load data acquisition and preprocessing methods based on Internet of Things sensors will become an important cornerstone for the intelligent development of the power system. By continuously optimizing and improving these methods, the intelligence level of the power system can be further improved and the sustainable development of the power system can be promoted.

[0067] like Figure 1 As shown in 12, encryption and signing are performed according to the pre-processed power load data to obtain the signed power load data, including:

[0068] According to the preprocessed power load data, use C=E K (P) performs symmetric encryption to obtain symmetric encrypted power load data, where C represents the ciphertext, i.e., the encrypted power load data, and E κ represents the AES encryption function using the key K, P represents the plain text, i.e. the pre-processed power load data, and K is the AES key K;

[0069] According to the AES key K, use C K =EPU (K) performs asymmetric encryption to obtain the AES key K after asymmetric encryption, where C K It is the ciphertext of AES key K encrypted by RSA public key PU, that is, the key K of AES after asymmetric encryption, E PU represents the RSA encryption function using the key PU, K is the key K of AES;

[0070] According to the symmetrically encrypted power load data, use D = H (C), S = D d mod n is used to sign the data packet to obtain the signed power load data, where D is the summary of the data packet, H is the SHA-256 hash function, C represents the ciphertext, i.e. the encrypted power load data, K is the AES key K, d is the exponent part of the private key (d, n), n is the modulus of the RSA key pair, and S is the signature.

[0071] In an embodiment of the present invention, the pre-processed power load data ( is encrypted using an AES encryption function to obtain symmetrically encrypted power load data; AES (Advanced Encryption Standard) can ensure the confidentiality of data during transmission by performing AES encryption on the power load data to prevent unauthorized personnel from stealing or tampering with the data; the AES key is encrypted using an RSA encryption function to obtain an asymmetrically encrypted AES key (i.e., a ciphertext encrypted by an RSA public key); RSA (Rivest-Shamir-Adleman) security is based on the difficulty of large number decomposition. By performing RSA encryption on the AES key, the security of the AES key during transmission can be ensured. Even if the ciphertext is intercepted, it is difficult for an attacker to extract the AES key from it; the SHA-256 hash function (represented by H) is used to perform a hash operation on the symmetrically encrypted power load data (ciphertext) to generate a summary (D) of the data packet; SHA-256 has the characteristics of anti-collision and anti-tampering. By generating a summary of the data packet, the integrity of the data can be ensured, that is, the data has not been tampered with during transmission; the exponent part of the private key is used The RSA signature operation is performed on the summary of the data packet using the modulus of the RSA key pair to obtain the signature; the signature is a proof of data integrity and source authenticity. By verifying the signature, the receiver can confirm that the data has not been tampered with during transmission and that the data does come from the claimed sender; the dual protection of AES symmetric encryption and RSA asymmetric encryption can ensure the confidentiality and integrity of power load data during transmission. Even if the ciphertext is intercepted, it is difficult for attackers to extract useful information or tamper with the data; the summary of the data packet is generated by the SHA-256 hash function and signed with the RSA private key to ensure the integrity of the data. After receiving the data, the receiver can verify the signature to confirm that the data has not been tampered with during transmission; the application of encryption and signature technology can enhance the credibility of the entire power load management system. By ensuring the confidentiality, integrity and source authenticity of the data, it can enhance the user's trust in the system and promote the widespread application and sustainable development of the system.

[0072] like Figure 1 As shown in 13, the signed power load data is transmitted to the control center through the network, and stored using a distributed storage system, and the signed power load data is redundantly backed up to obtain the stored power load data, including:

[0073] Transmit the signed power load data to the control center via the network;

[0074] After receiving the signed power load data, the control center uses a distributed storage system to disperse the data to multiple nodes for storage, so as to obtain the signed power load data stored in the distributed system;

[0075] According to the signed power load data stored in the distributed system, erasure coding technology is used for redundant backup to obtain the stored power load data.

[0076] In an embodiment of the present invention, the signed power load data is securely transmitted to the control center through the network, ensuring the integrity of the data during transmission and the authenticity of the source, because the data has been encrypted and signed; after the control center receives the signed power load data, it uses a distributed storage system to disperse the data to multiple nodes for storage. The distributed storage system improves the availability and fault tolerance of the data by splitting the data into multiple parts or copies and storing them on different physical or logical nodes respectively; through distributed storage, even if a node fails or is attacked, the data copies on other nodes can still continue to provide services, ensuring the continuous availability of data and the stability of the system; in the distributed storage system, in order to further enhance the reliability and security of the data, erasure coding technology is used to perform redundant backup of the signed power load data. Erasure coding technology generates additional data blocks (called check blocks) so that the original data can still be restored when some data blocks are lost. The application of erasure coding technology enables the system to tolerate more node failures or data loss without affecting the integrity and availability of the data. Even if multiple nodes fail at the same time, as long as the remaining data blocks and check blocks are sufficient, the system can still restore the complete signed power load data. Through the combined application of network transmission, distributed storage and redundant backup, the reliability of the power load management system is significantly improved. Even in the face of challenges such as network failure, node failure or data loss, the system can still ensure the integrity and availability of the data. Since the data has been encrypted and signed during transmission, and distributed storage and redundant backup technology are used during storage, the security of the data is also enhanced. It is difficult for unauthorized personnel to steal or tamper with the data. Even if the data is intercepted or partially lost, the complete original data cannot be restored. The use of distributed storage systems enables the system to easily expand storage capacity and computing power to meet the growing demand for power load data. The application of erasure coding technology also reduces the dependence on the reliability of a single node, making the system more flexible and scalable.

[0077] like Figure 1 As shown in 14, during the network transmission process, the data transmission flow rate is monitored in real time to obtain monitoring results, including:

[0078] Use network monitoring tools to capture data packets in the network in real time;

[0079] Based on the captured data packets, calculate the number of data packets transmitted within time t;

[0080] Depending on the number of packets transmitted, use Calculate the data transmission flow rate, where NFR t is the data transmission flow rate at time point t, TB is the transmission size of the i-th data packet, WF is the network weight factor of the i-th data packet, LT is the transmission delay of the i-th data packet, n is the total number of data packets transmitted in the monitoring window, and PLR t is the packet loss rate at time point t, α and β are adjustment coefficients, DDR i is the data demand change rate at time point t, indicating the change in data demand in the network; J i is the network congestion index at time t;

[0081] Repeat the above steps to monitor the data transmission flow rate in real time to obtain the monitoring results.

[0082] In an embodiment of the present invention, the data transmission flow rate is monitored in real time during network transmission to obtain detailed data on network transmission performance and efficiency, which is helpful to identify network bottlenecks, optimize data transmission strategies, and ensure the stability and reliability of power load data during transmission. In a specific embodiment, the power load management system needs to transmit the encrypted and signed power load data to the control center through the network. First, a network monitoring tool such as Wireshark is used to capture data packets in the network in real time. These data packets contain the transmission information of the power load data. A time window is set (for example, every 5 minutes is a time window), and the number of data packets transmitted in the time window is calculated. For example, in the time window t 1 Within 1000 packets were transmitted; using Calculate the data transmission flow rate, where NFR t is the data transmission flow rate at time point t, TB is the transmission size of the i-th data packet, WF is the network weight factor of the i-th data packet, LT is the transmission delay of the i-th data packet, n is the total number of data packets transmitted in the monitoring window, and PLR t is the packet loss rate at time point t, α and β are adjustment coefficients, DDR i is the data demand change rate at time point t, indicating the change in data demand in the network, J iis the network congestion index at time t; repeat the above steps to monitor the data transmission flow rate in real time, for example, calculate the data transmission flow rate every 5 minutes, and record the results in the log file; by analyzing the real-time monitoring results, we can obtain the change of the data transmission flow rate over time during the network transmission process, the impact of factors such as network congestion and data packet loss on the data transmission flow rate, and the impact of changes in data demand on network transmission performance; it helps us identify network bottlenecks, optimize data transmission strategies, and ensure the stability and reliability of power load data during transmission. For example, when it is found that the data transmission flow rate is significantly reduced, the network configuration or transmission strategy can be adjusted in time to improve data transmission efficiency.

[0083] like Figure 1 As shown in 15, based on the monitoring results and the preset thresholds, if abnormal traffic or attack behavior is detected, the system triggers an alarm, including:

[0084] According to the monitoring result, the flow rate is compared with the preset flow rate threshold to obtain a comparison result;

[0085] According to the comparison result, if the data transmission flow rate does not exceed the normal threshold, the traffic is normal;

[0086] According to the comparison results, if the data transmission flow rate reaches or exceeds the normal threshold, it is determined that there is abnormal traffic or attack behavior;

[0087] If an anomaly is detected, the system triggers an alarm.

[0088] In an embodiment of the present invention, based on the monitoring results of network transmission and a preset threshold, the data transmission flow rate is detected for abnormalities, and an alarm is triggered when abnormal traffic or attack behavior is detected, ensuring the important link of the security of power load data in the network transmission process, and being able to timely discover and respond to potential network threats; first, the real-time monitored data transmission flow rate is compared with the preset normal traffic threshold, and the threshold is set based on factors such as historical network data, business requirements and security policies, and is used to distinguish between normal traffic and abnormal traffic; according to the comparison result, if the data transmission flow rate does not exceed the normal threshold, the traffic is determined to be in a normal state and monitoring can be continued; if the data transmission flow rate reaches or exceeds the normal threshold, the next step of the abnormal detection process is entered; in the case of abnormal data transmission flow rate In this case, the system needs to further analyze the traffic data to determine whether there is abnormal traffic or attack behavior. This can be achieved by analyzing the source, destination, size, frequency and other characteristics of the traffic. If the system detects the characteristics of abnormal traffic or attack behavior, such as DDoS attacks, SQL injections, etc., it will immediately trigger an alarm to notify the security administrator or relevant team to respond; once the alarm is triggered, the system should provide detailed alarm information, including the type, time, source, and scope of impact of the abnormal traffic, so that the security administrator can quickly locate the problem and take corresponding countermeasures. The system also records relevant information of the abnormal event for subsequent analysis and improvement; through real-time monitoring of network traffic, anomaly detection and alarm triggering mechanisms, it provides effective security protection for the network transmission of the power load management system.

[0089] like Figure 1 As shown in 16, the control center performs decryption and verification based on the stored power load data to obtain the decrypted power load data, including:

[0090] According to the stored power load data, the asymmetrically encrypted AES key is decrypted using the RSA private key to obtain the decrypted key K. The decryption process is: K = RSA d′ (C K ), where K is the AES key obtained after decryption, RSA d′ represents the RSA decryption function using the private key d, C κ It is the AES key ciphertext after asymmetric encryption;

[0091] The same hash function D′=H(C) as used for signing is used to calculate the summary of the symmetrically encrypted power load data, where D′ is the calculated summary, H is the SHA-256 hash function, and C is the symmetrically encrypted power load data;

[0092] According to the abstract, use D″=S emod n to perform signature verification to obtain the verification result, where D″ is the summary after signature verification, S is the signature, e is the exponent part of the public key (e, n), and n is the modulus of the RSA key pair;

[0093] Compare the calculated summary D′ with the summary D″ after signature verification to obtain a comparison result;

[0094] According to the comparison result, if the calculated summary D′ is consistent with the summary D″ after the signature is verified, it means that the data has not been tampered with during transmission or storage;

[0095] The key K obtained after decryption is used to decrypt the symmetrically encrypted power load data to obtain the decrypted power load data. The decryption process is: Where P is the pre-processed power load data obtained after decryption, represents the AES decryption function using the key K, and C represents the ciphertext, i.e. the encrypted power load data.

[0096] In an embodiment of the present invention, the RSA private key is used to decrypt the stored asymmetrically encrypted AES key. The decryption process is to apply the RSA decryption function, with the private key and ciphertext as input and the decrypted AES key as output. The same hash function (such as SHA-256) as that used for signing is used to calculate the summary of the symmetrically encrypted power load data. The summary calculation process is to apply the hash function, with the symmetrically encrypted data as input and the calculated summary as output. The public key is used to perform signature verification based on the calculated summary and the stored signature. The signature verification process is to apply the signature verification algorithm, with the summary, signature, exponent part of the public key and modulus as input and the output is The verified summary; the calculated summary is compared with the summary after the signature is verified; the comparison result is used to determine whether the data has been tampered with during transmission or storage; if the comparison results are consistent, it means that the data has not been tampered with, and the AES key obtained after decryption is used to decrypt the symmetrically encrypted power load data; the decryption process is to apply the AES decryption function, with the input being the key and ciphertext, and the output being the decrypted pre-processed power load data; the security and integrity of the power load data during transmission and storage are ensured, which not only verifies the source and integrity of the data, but also restores the original data through decryption, providing a basis for subsequent data analysis and processing.

[0097] like Figure 2 As shown, an embodiment of the present invention further provides an Internet of Things-based power load management system 20, comprising:

[0098] An acquisition module 21 is used to continuously acquire power load data using an IoT sensor and perform preprocessing to obtain preprocessed power load data;

[0099] The processing module 22 is used to encrypt and sign the pre-processed power load data to obtain the signed power load data; transmit the signed power load data to the control center through the network, store it using a distributed storage system, and perform redundant backup of the signed power load data to obtain the stored power load data; during the network transmission process, monitor the data transmission flow rate in real time to obtain the monitoring results; based on the monitoring results and the preset thresholds, if abnormal traffic or attack behavior is detected, the system triggers an alarm; based on the stored power load data, the control center decrypts and verifies to obtain the decrypted power load data.

[0100] It should be noted that the system is a system corresponding to the above method, and all implementation methods in the above method embodiment are applicable to this embodiment and can achieve the same technical effect.

[0101] The embodiment of the present invention further provides a computing device, comprising: a processor, a memory storing a computer program, wherein when the computer program is executed by the processor, the method described above is executed. All implementations in the above method embodiment are applicable to this embodiment and can achieve the same technical effect.

[0102] The embodiment of the present invention also provides a computer-readable storage medium storing instructions, which, when executed on a computer, enable the computer to execute the method described above. All implementations in the above method embodiment are applicable to this embodiment and can achieve the same technical effect.

[0103] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0104] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, systems and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0105] In the embodiments provided by the present invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of systems or units, which can be electrical, mechanical or other forms.

[0106] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0107] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0108] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical disks.

[0109] In addition, it should be noted that in the system and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. Moreover, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but it is not necessary to perform them in chronological order, and some steps can be performed in parallel or independently of each other. For those of ordinary skill in the art, it is understood that all or any steps or components of the method and system of the present invention can be implemented in any computing system (including processors, storage media, etc.) or a network of computing systems in hardware, firmware, software or a combination thereof, which can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.

[0110] Therefore, the purpose of the present invention can also be achieved by running a program or a group of programs on any computing system. The computing system can be a well-known general system. Therefore, the purpose of the present invention can also be achieved by simply providing a program product containing a program code that implements the method or system. That is to say, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be pointed out that in the system and method of the present invention, it is obvious that each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent schemes of the present invention. In addition, the steps of performing the above-mentioned series of processing can naturally be performed in chronological order according to the order of description, but it is not necessary to perform them in chronological order. Some steps can be performed in parallel or independently of each other.

[0111] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.

Claims

1. A power load management method based on the Internet of Things, characterized in that: The method comprises: Use IoT sensors to continuously acquire power load data and perform preprocessing to obtain preprocessed power load data; Encrypting and signing the preprocessed power load data to obtain the signed power load data; The signed power load data is transmitted to the control center through the network and stored using a distributed storage system, and the signed power load data is redundantly backed up to obtain the stored power load data; During the network transmission process, the data transmission flow rate is monitored in real time to obtain the monitoring results; Based on the monitoring results and preset thresholds, if abnormal traffic or attack behavior is detected, the system will trigger an alarm; Based on the stored power load data, the control center performs decryption and verification to obtain the decrypted power load data.

2. The power load management method based on the Internet of Things according to claim 1 is characterized in that: Use IoT sensors to continuously acquire power load data and perform preprocessing to obtain preprocessed power load data, including: Use IoT sensors to continuously monitor and record power load data; Performing data cleaning on the power load data to obtain cleaned power load data; According to the cleaned power load data, data standardization is performed to obtain standardized power load data, that is, pre-processed power load data.

3. The power load management method based on the Internet of Things according to claim 2 is characterized in that: According to the pre-processed power load data, encryption and signing are performed to obtain the signed power load data, including: According to the preprocessed power load data, use C=E K( P ) Symmetric encryption is performed to obtain symmetrically encrypted power load data, where C represents the ciphertext, i.e. the encrypted power load data, and E κ represents the AES encryption function using the key K, P represents the plain text, i.e. the pre-processed power load data, and K is the AES key K; According to the AES key K, use C K =E PU (K) performs asymmetric encryption to obtain the AES key K after asymmetric encryption, where C K It is the ciphertext of AES key K encrypted by RSA public key PU, that is, the key K of AES after asymmetric encryption, E PU represents the RSA encryption function using the key PU, K is the key K of AES; According to the symmetrically encrypted power load data, use D = H (C), S = D d mod n is used to sign the data packet to obtain the signed power load data, where D is the summary of the data packet, H is the SHA-256 hash function, C represents the ciphertext, i.e. the encrypted power load data, K is the AES key K, d is the exponent part of the private key (d, n), n is the modulus of the RSA key pair, and S is the signature.

4. The power load management method based on the Internet of Things according to claim 3 is characterized in that: The signed power load data is transmitted to the control center through the network and stored using a distributed storage system. The signed power load data is backed up redundantly to obtain the stored power load data, including: Transmit the signed power load data to the control center via the network; After receiving the signed power load data, the control center uses a distributed storage system to disperse the data to multiple nodes for storage, so as to obtain the signed power load data stored in the distributed system; According to the signed power load data stored in the distributed system, erasure coding technology is used for redundant backup to obtain the stored power load data.

5. The power load management method based on the Internet of Things according to claim 4 is characterized in that: During network transmission, the data transmission flow rate is monitored in real time to obtain monitoring results, including: Use network monitoring tools to capture data packets in the network in real time; Based on the captured data packets, calculate the number of data packets transmitted within time t; Depending on the number of packets transmitted, use Calculate the data transmission flow rate, where NFR t is the data transmission flow rate at time point t, TB is the transmission size of the i-th data packet, WF is the network weight factor of the i-th data packet, LT is the transmission delay of the i-th data packet, n is the total number of data packets transmitted in the monitoring window, and PLR t is the packet loss rate at time point t, α and β are adjustment coefficients, DDR i is the data demand change rate at time point t, indicating the change in data demand in the network; J i is the network congestion index at time t; Repeat the above steps to monitor the data transmission flow rate in real time to obtain the monitoring results.

6. The power load management method based on the Internet of Things according to claim 5 is characterized in that: Based on the monitoring results and preset thresholds, if abnormal traffic or attack behavior is detected, the system triggers an alarm, including: According to the monitoring result, the flow rate is compared with the preset flow rate threshold to obtain a comparison result; According to the comparison result, if the data transmission flow rate does not exceed the normal threshold, the traffic is normal; According to the comparison results, if the data transmission flow rate reaches or exceeds the normal threshold, it is determined that there is abnormal traffic or attack behavior; If an abnormality is detected, the system triggers an alarm.

7. The power load management method based on the Internet of Things according to claim 6 is characterized in that: According to the stored power load data, the control center performs decryption and verification to obtain the decrypted power load data, including: According to the stored power load data, the asymmetrically encrypted AES key is decrypted using the RSA private key to obtain the decrypted key K. The decryption process is: K = RSA d′ (C K ), where K is the AES key obtained after decryption, RSA d′ represents the RSA decryption function using the private key d, C κ It is the AES key ciphertext after asymmetric encryption; The same hash function D′=H(C) as used for signing is used to calculate the summary of the symmetrically encrypted power load data, where D′ is the calculated summary, H is the SHA-256 hash function, and C is the symmetrically encrypted power load data; According to the abstract, use D″=S e mod n to perform signature verification to obtain the verification result, where D″ is the summary after signature verification, S is the signature, e is the exponent part of the public key (e, n), and n is the modulus of the RSA key pair; Compare the calculated summary D′ with the summary D″ after signature verification to obtain a comparison result; According to the comparison result, if the calculated summary D′ is consistent with the summary D″ after the signature is verified, it means that the data has not been tampered with during transmission or storage; The key K obtained after decryption is used to decrypt the symmetrically encrypted power load data to obtain the decrypted power load data. The decryption process is: Where P is the pre-processed power load data obtained after decryption, represents the AES decryption function using the key K, and C represents the ciphertext, i.e. the encrypted power load data.

8. An Internet of Things-based power load management system, characterized in that: include: An acquisition module, used to continuously acquire power load data using an IoT sensor and perform preprocessing to obtain preprocessed power load data; A processing module, used for encrypting and signing the pre-processed power load data to obtain the signed power load data; The signed power load data is transmitted to the control center through the network and stored using a distributed storage system, and the signed power load data is redundantly backed up to obtain the stored power load data; During network transmission, the data transmission flow rate is monitored in real time to obtain monitoring results; based on the monitoring results and preset thresholds, if abnormal traffic or attack behavior is detected, the system triggers an alarm; Based on the stored power load data, the control center performs decryption and verification to obtain the decrypted power load data.

9. A computing device, characterized in that include: one or more processors; A storage system for storing one or more programs, when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a program, which, when executed by a processor, implements the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Electric power data transmission system based on one-way isolation gatekeeper

    CN120692072A