Intelligent power distribution equipment remote identification method and system based on power line communication

By adopting a three-layer architecture device information database and a multi-level blockchain network architecture identity authentication mechanism in the remote identification method of smart power distribution equipment, the problem of remote identification and identity authentication security of smart power distribution equipment is solved, the rapid identification and precise management of equipment are realized, and the security and reliability of the power distribution network are enhanced.

CN119945802AActive Publication Date: 2025-05-06常州常供电力设计院有限公司

Patent Information

Application Number
CN202510422424.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-05-06
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

The remote identification method of existing smart power distribution equipment lacks a unified multi-level information management architecture, resulting in unclear correspondence between equipment information and the distribution network topology structure, making it difficult to achieve precise positioning and effective management of equipment. At the same time, the existing identity verification mechanism is insufficiently secure and is vulnerable to attacks, and cannot effectively ensure the security of communication between smart distribution equipment and the main station.

Method used

The remote identification method of intelligent power distribution equipment based on power line communication is adopted. By receiving device identification information, a three-layer architecture device information database is established to achieve rapid identification and precise positioning of equipment. At the same time, a multi-level blockchain network architecture is built to determine the credibility of device nodes by verifying the node set and consensus permission matrix, and a complete identity verification mechanism is established to prevent illegal device access and malicious attacks.

Benefits of technology

It realizes the rapid identification and precise positioning of intelligent power distribution equipment, and improves the efficiency and accuracy of power distribution network management. At the same time, through the identity verification mechanism of the blockchain network architecture, the security and reliability of the distribution network are enhanced, and illegal device access and malicious attacks are prevented.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945802A_ABST
    Figure CN119945802A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent power distribution equipment remote identification method and system based on power line communication, and relates to the technical field of electric power, and the method comprises the steps: receiving equipment identification information, building a three-layer architecture equipment information database, sending an identity verification request, receiving a verification response, constructing a multi-level block chain network architecture, and determining the node credibility; and judging whether the identity verification is passed or not according to the verification result and the credibility, and establishing a secure communication link when the verification is passed. The safety and reliability of identity recognition of the intelligent power distribution equipment are improved, and illegal equipment is effectively prevented from accessing the power distribution network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to electric power technology, and in particular to a remote identification method and system for intelligent power distribution equipment based on power line communication. Background Art

[0002] With the continuous advancement of smart grid construction, the application of smart distribution equipment in power systems is becoming more and more extensive. These devices include smart switches, smart transformers, smart meters, etc., which can realize the automatic monitoring and management of distribution networks. Power line communication technology, as a communication method that uses existing power lines for data transmission, provides a convenient communication channel for remote identification and management of smart distribution equipment. In the smart distribution network, remote identification of equipment is the basis for realizing distribution automation, which involves multiple links such as the collection, transmission, verification and management of equipment information.

[0003] At present, the remote identification technology of intelligent power distribution equipment mainly relies on traditional communication protocols and identity authentication mechanisms. However, these technologies have some obvious defects and deficiencies in practical applications.

[0004] First, the traditional intelligent distribution equipment identification method lacks a unified multi-level information management architecture, resulting in unclear correspondence between equipment information and distribution network topology, making it difficult to accurately locate and effectively manage equipment, especially in a complex distribution network environment, where the organization and management of equipment information is even more difficult.

[0005] Secondly, the existing authentication mechanism lacks security, mainly using static keys or simple challenge-response mechanisms, which are vulnerable to man-in-the-middle attacks or replay attacks and cannot effectively guarantee the security of communication between smart distribution equipment and the master station. This poses a serious security risk to critical infrastructure such as the power system. Summary of the invention

[0006] The embodiments of the present invention provide a remote identification method and system for intelligent power distribution equipment based on power line communication, which can solve the problems in the prior art.

[0007] A first aspect of an embodiment of the present invention provides a remote identification method for intelligent power distribution equipment based on power line communication, comprising:

[0008] Receiving device identification information sent by the intelligent power distribution device through power line carrier communication, the device identification information includes device type information, device number information and device installation location information;

[0009] Establishing a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer, and a business layer, wherein the device information database stores the correspondence between the device identification information and the topology structure of the distribution network; sending an identity authentication request to the intelligent power distribution device, wherein the identity authentication request includes verification code information randomly generated by a key exchange algorithm; and receiving verification response information returned by the intelligent power distribution device based on the verification code information;

[0010] Construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a verification node set in the verification sub-chain network corresponding to the intelligent power distribution device, generate a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determine the node reputation corresponding to the intelligent power distribution device according to the consensus authority matrix;

[0011] Based on the verification result of the verification response information and the node reputation, determine whether the identity authentication of the intelligent distribution device is passed. If the identity authentication is passed, allocate a communication time slot to the intelligent distribution device to establish a secure communication link between the intelligent distribution device and the distribution automation master station.

[0012] The method further comprises:

[0013] A distributed time synchronization protocol is used to perform network time synchronization on the intelligent power distribution equipment, wherein a clock synchronization module is set in each of the intelligent power distribution equipment, and the clock synchronization module calculates the transmission delay based on the timestamp information of the power line carrier signal, and uses the least squares method to fit the delay data of multiple samples to generate clock deviation compensation parameters, thereby achieving accurate time synchronization of the intelligent power distribution equipment.

[0014] Establishing a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer, and a business layer, wherein the corresponding relationship between the device identification information and the topology structure of the distribution network is stored in the device information database, including:

[0015] The physical layer stores the unique identification code, device model, production date and hardware version number of the device, the topological layer stores the spatial location information of the intelligent power distribution device in the power distribution network, and the business layer stores the operating parameters and communication status of the device;

[0016] Acquire the unique device identification code from the physical layer, establish a device identity mapping table based on the unique device identification code, and write the device identity mapping table into the service layer;

[0017] Acquire spatial location information of the intelligent power distribution device in the power distribution network from the topology layer, generate a device connection relationship matrix based on graph theory, and the matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices;

[0018] A topological distance matrix between devices is calculated according to the device connection relationship matrix, the distance values ​​in the topological distance matrix are obtained by the minimum distance of the physical paths between devices, and the topological distance matrix is ​​stored in the topological layer.

[0019] Sending an identity authentication request to the intelligent power distribution device, the identity authentication request including verification code information randomly generated by a key exchange algorithm; receiving verification response information returned by the intelligent power distribution device based on the verification code information includes:

[0020] Query the device identity mapping table according to the unique identification code of the device to obtain the communication level information and authorization level information of the intelligent power distribution device; determine the generation range of the master station random number according to the communication level information, and the generation range of the master station random number is positively correlated with the communication level information;

[0021] Generate the master station random number, and send the master station random number to the intelligent power distribution device through the power line carrier channel, and receive the device random number returned by the intelligent power distribution device; select the primitive root value corresponding to the authorization level information, and recursively calculate the primitive root value with the master station random number and the device random number to generate a random verification code;

[0022] Obtaining a device certificate identifier corresponding to the device unique identification code from a certificate management system, and verifying the validity of the device certificate identifier;

[0023] Obtain the timestamp of the current system, and generate mixed authentication information according to a preset combination rule by combining the device certificate identifier, the random verification code and the timestamp; send the mixed authentication information to the intelligent power distribution device, and wait for the intelligent power distribution device to return verification response information.

[0024] Construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, and select a verification node set corresponding to the area of ​​the smart power distribution equipment in the verification sub-chain network, including:

[0025] Construct a multi-level blockchain network architecture, which includes a main chain layer network and a verification sub-chain network. The main chain layer network adopts a directed acyclic graph structure, and the verification sub-chain network corresponds to different regional organizations;

[0026] According to the device type code and the area identification code of the intelligent power distribution device, determining the belonging area and the device type of the intelligent power distribution device in the verification subchain network;

[0027] Based on the region to which the intelligent power distribution equipment belongs, a verification node set of the corresponding region is selected in the verification subchain network, and the communication delay, link reliability index and node computing capacity evaluation value between each node in the verification node set are calculated;

[0028] According to the communication delay, the link reliability index and the node computing capability evaluation value, an edge weight matrix between nodes in the verification node set is calculated, and the connection relationship between the verification nodes is determined based on the edge weight matrix.

[0029] Generating a consensus authority matrix for the verification subchain network based on the connection relationship between the verification nodes, and determining the node reputation corresponding to the intelligent power distribution device according to the consensus authority matrix includes:

[0030] Generate a consensus authority matrix of the verification subchain network based on the connection relationship between the verification nodes, the consensus authority matrix is ​​used to characterize the verification authority relationship between nodes in the verification subchain network, and store the consensus authority matrix in the verification subchain network;

[0031] According to the timestamp code of the intelligent power distribution device, consensus verification is performed on the nodes in the verification node set, and the number of successful consensuses, verification response time and total number of interactions between nodes are counted;

[0032] Calculate the node reputation of each node in the verification node set based on the number of consensus successes, the verification response time, and the total number of interactions, and write the node reputation into the main chain layer network;

[0033] When the node reputation meets the preset verification trigger threshold, the smart contract is triggered to execute device identity authentication, and the authentication result is returned to the main chain layer network through the verification sub-chain network.

[0034] According to the verification result of the verification response information and the node reputation, judging whether the identity authentication of the intelligent power distribution device is passed, and if the identity authentication is passed, allocating a communication time slot to the intelligent power distribution device, and establishing a secure communication link between the intelligent power distribution device and the distribution automation master station includes:

[0035] The verification result is weighted according to the node reputation, and a consistency coefficient of the verification result is calculated; when the consistency coefficient is greater than a preset consistency threshold, it is determined that the identity authentication of the intelligent power distribution device is passed;

[0036] Obtaining the total amount of available time slots of the communication link, calculating the current time slot occupancy rate, and dynamically adjusting the pre-acquired communication time slot demand according to the time slot occupancy rate to obtain the actual number of allocated communication time slots;

[0037] A communication time slot is allocated to the intelligent power distribution device, and a secure communication link is established between the intelligent power distribution device and a distribution automation master station.

[0038] A second aspect of an embodiment of the present invention provides a remote identification system for intelligent power distribution equipment based on power line communication, comprising:

[0039] The first unit is used to receive device identification information sent by the intelligent power distribution device through power line carrier communication, where the device identification information includes device type information, device number information and device installation location information;

[0040] The second unit is used to establish a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer and a business layer, wherein the device information database stores a correspondence between the device identification information and the topology structure of the distribution network; send an identity authentication request to the intelligent power distribution device, wherein the identity authentication request includes verification code information randomly generated by a key exchange algorithm; and receive verification response information returned by the intelligent power distribution device based on the verification code information;

[0041] The third unit is used to build a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a verification node set in the verification sub-chain network corresponding to the intelligent power distribution equipment, generate a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determine the node reputation corresponding to the intelligent power distribution equipment according to the consensus authority matrix;

[0042] The fourth unit is used to determine whether the identity authentication of the intelligent distribution device is passed based on the verification result of the verification response information and the node credibility, and if the identity authentication is passed, allocate a communication time slot to the intelligent distribution device to establish a secure communication link between the intelligent distribution device and the distribution automation master station.

[0043] According to a third aspect of the embodiments of the present invention,

[0044] An electronic device is provided, comprising:

[0045] processor;

[0046] a memory for storing processor-executable instructions;

[0047] The processor is configured to call the instructions stored in the memory to execute the aforementioned method.

[0048] A fourth aspect of the embodiments of the present invention is:

[0049] A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.

[0050] The beneficial effects of this application are as follows:

[0051] The remote identification method of intelligent power distribution equipment based on power line communication provided by the present invention establishes a three-layer equipment information database by receiving equipment identification information sent by the intelligent power distribution equipment through power line carrier communication, thereby realizing rapid identification and precise positioning of the intelligent power distribution equipment and improving the efficiency and accuracy of distribution network management.

[0052] The present invention constructs a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, determines the credibility of device nodes by verifying the node set and the consensus authority matrix, and establishes a complete identity authentication mechanism, which effectively prevents illegal device access and malicious attacks, and enhances the security and reliability of the distribution network.

[0053] When identity authentication is passed, the present invention allocates communication time slots for intelligent distribution equipment and establishes a secure communication link, which not only optimizes the allocation efficiency of communication resources, but also realizes the safe and stable operation of the distribution automation system, providing technical support for the development of smart grids. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 A schematic diagram of a flow chart of a remote identification method for intelligent power distribution equipment based on power line communication according to an embodiment of the present invention;

[0055] Figure 2 It is a schematic diagram of the three-layer architecture system and identity authentication process of intelligent power distribution equipment;

[0056] Figure 3 A schematic diagram showing the comparison of verification success rates of this solution and the prior art at different communication levels;

[0057] Figure 4 This is a schematic diagram of the interface of the intelligent power distribution equipment verification management system. DETAILED DESCRIPTION

[0058] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0059] The technical solution of the present invention is described in detail with specific embodiments below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.

[0060] Figure 1 FIG. 1 is a flow chart of a remote identification method for intelligent power distribution equipment based on power line communication according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0061] Receiving device identification information sent by the intelligent power distribution device through power line carrier communication, the device identification information includes device type information, device number information and device installation location information;

[0062] Establishing a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer, and a business layer, wherein the device information database stores the correspondence between the device identification information and the topology structure of the distribution network; sending an identity authentication request to the intelligent power distribution device, wherein the identity authentication request includes verification code information randomly generated by a key exchange algorithm; and receiving verification response information returned by the intelligent power distribution device based on the verification code information;

[0063] Construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a verification node set in the verification sub-chain network corresponding to the intelligent power distribution device, generate a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determine the node reputation corresponding to the intelligent power distribution device according to the consensus authority matrix;

[0064] Based on the verification result of the verification response information and the node reputation, determine whether the identity authentication of the intelligent distribution device is passed. If the identity authentication is passed, allocate a communication time slot to the intelligent distribution device to establish a secure communication link between the intelligent distribution device and the distribution automation master station.

[0065] In an optional implementation, the method further includes:

[0066] A distributed time synchronization protocol is used to perform network time synchronization on the intelligent power distribution equipment, wherein a clock synchronization module is set in each of the intelligent power distribution equipment, and the clock synchronization module calculates the transmission delay based on the timestamp information of the power line carrier signal, and uses the least squares method to fit the delay data of multiple samples to generate clock deviation compensation parameters, thereby achieving accurate time synchronization of the intelligent power distribution equipment.

[0067] In the intelligent power distribution network, each intelligent power distribution device is equipped with a clock synchronization module, which is responsible for achieving accurate time synchronization between devices. The clock synchronization module includes a timestamp extraction unit, a delay calculation unit, a data sampling unit, a least squares fitting unit and a clock compensation unit.

[0068] In the network, an intelligent power distribution device with a high-precision clock is selected as the master node, and the rest of the devices are slave nodes. The master node regularly broadcasts synchronization messages to the slave nodes through the power line carrier communication network. The synchronization message contains the current timestamp T1 of the master node.

[0069] When the slave node receives the synchronization message sent by the master node, the timestamp extraction unit of the slave node records the local timestamp T2 of the receiving moment. The slave node then sends a response message to the master node, which includes the timestamp T2 of the slave node receiving the synchronization message and the timestamp T3 of sending the response message.

[0070] When the master node receives the response message from the slave node, it records the local timestamp T4 of the receiving time. At this point, the master node has obtained the complete four timestamps: T1, T2, T3 and T4.

[0071] The delay calculation unit calculates the network transmission delay based on the four timestamps. Specifically, the transmission delay from the master node to the slave node can be calculated by the difference between the timestamp T1 when the master node sends the synchronization message and the timestamp T2 when the slave node receives the synchronization message, minus the clock deviation between the master and slave nodes. Similarly, the transmission delay from the slave node to the master node can be calculated by the difference between the timestamp T3 when the slave node sends the response message and the timestamp T4 when the master node receives the response message, minus the clock deviation between the master and slave nodes.

[0072] Assuming that the network transmission delay is symmetrical in a short period of time, that is, the transmission delay from the master node to the slave node is equal to the transmission delay from the slave node to the master node, the clock deviation between the master and slave nodes can be estimated as follows: [(T2-T1)-(T4-T3)] / 2. The transmission delay can be estimated as: [(T2-T1)+(T4-T3)] / 2.

[0073] In order to improve the accuracy of clock synchronization, the data sampling unit repeats the above process multiple times within a certain time window (for example, 10 minutes) to collect multiple sets of timestamp data. In practical applications, sampling can be performed every 30 seconds, and a total of 20 sets of data can be collected within a 10-minute time window.

[0074] The least squares fitting unit processes the collected data and fits the changing trend of the clock deviation through the least squares method. Specifically, the sampling time point is used as the independent variable and the estimated clock deviation is used as the dependent variable to establish a linear regression model. The slope and intercept of the regression line are calculated through the least squares method, where the slope represents the clock frequency deviation (clock drift rate) and the intercept represents the initial clock deviation.

[0075] For example, assuming that 20 sets of data are collected within a 10-minute sampling window, the calculated clock deviations are: 1.2ms, 1.3ms, 1.5ms, 1.6ms, 1.8ms, 1.9ms, 2.1ms, 2.2ms, 2.4ms, 2.5ms, 2.7ms, 2.8ms, 3.0ms, 3.1ms, 3.3ms, 3.4ms, 3.6ms, 3.7ms, 3.9ms, 4.0ms. Through the least squares fitting method, it can be obtained that the clock drift rate is 0.15ms / minute and the initial clock deviation is 1.1ms.

[0076] The clock compensation unit generates clock deviation compensation parameters based on the fitted clock drift rate and initial clock deviation. The slave node uses these parameters to adjust the local clock to achieve time synchronization with the master node. Specifically, the slave node can adjust the clock in one of the following two ways:

[0077] One way is to directly adjust the time value of the local clock to make it consistent with the time of the master node. For example, if the calculation shows that the current slave node clock is 3.5ms slower than the master node, the slave node clock is directly adjusted forward by 3.5ms.

[0078] Another way is to adjust the frequency of the local clock to keep it consistent with the clock frequency of the master node, thereby eliminating clock drift. For example, if the calculated clock drift rate of the slave node is 0.15ms / minute, the clock frequency of the slave node can be adjusted accordingly to increase the compensation by 0.15ms per minute.

[0079] In practical applications, the above two methods are usually combined for clock adjustment. First, a direct adjustment of the time value is performed to synchronize the slave node's clock with the master node immediately; then the clock frequency is adjusted according to the calculated clock drift rate to maintain a long-term synchronization state.

[0080] In order to cope with the changes in clock characteristics caused by factors such as changes in the network environment and equipment aging, the system will periodically re-execute the above synchronization process to update the clock deviation compensation parameters. Under normal operating conditions, a complete synchronization process can be performed once an hour; when the network status is poor or the clock deviation is detected to exceed the preset threshold (for example, 5ms), immediate synchronization can be triggered.

[0081] Through the above method, all devices in the smart distribution network can achieve accurate time synchronization, and the time synchronization accuracy can reach millisecond level (typical value is 1-3ms). This high-precision time synchronization provides important support for fault location, protection coordination, status monitoring and other functions in the smart distribution network.

[0082] In actual deployment, this method has been applied in the intelligent distribution network of a provincial power grid company, involving more than 500 intelligent distribution devices. Test results show that after adopting this method, the time synchronization accuracy of devices in the network has been improved from the original 10-15ms to 1-3ms, greatly improving the operating efficiency and reliability of the distribution network.

[0083] In an optional implementation, a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer, and a business layer is established, and the corresponding relationship between the device identification information and the topology structure of the distribution network stored in the device information database includes:

[0084] The physical layer stores the unique identification code, device model, production date and hardware version number of the device, the topological layer stores the spatial location information of the intelligent power distribution device in the power distribution network, and the business layer stores the operating parameters and communication status of the device;

[0085] Acquire the unique device identification code from the physical layer, establish a device identity mapping table based on the unique device identification code, and write the device identity mapping table into the service layer;

[0086] Acquire spatial location information of the intelligent power distribution device in the power distribution network from the topology layer, generate a device connection relationship matrix based on graph theory, and the matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices;

[0087] A topological distance matrix between devices is calculated according to the device connection relationship matrix, the distance values ​​in the topological distance matrix are obtained by the minimum distance of the physical paths between devices, and the topological distance matrix is ​​stored in the topological layer.

[0088] An equipment information database of intelligent power distribution equipment including a three-layer architecture of physical layer, topology layer and business layer is established, and the corresponding relationship between equipment identification information and the topology structure of the distribution network is stored in the database.

[0089] Figure 2The following is a schematic diagram of the three-layer architecture and identity authentication process of smart power distribution equipment. The physical layer mainly stores the basic hardware information of the equipment, including the unique device identification code, device model, production date, and hardware version number. For example, the physical layer information of a smart power distribution equipment can be expressed as: unique device identification code "PD2023120001", device model "SPD-X200", production date "2023-05-15", and hardware version number "V2.3". The physical layer information is usually written into the non-volatile memory of the device when it leaves the factory to ensure that the device can be uniquely identified throughout its life cycle.

[0090] The topology layer stores the spatial location information of the intelligent power distribution equipment in the distribution network. The spatial location information includes the geographical coordinates of the equipment, the substation to which it belongs, the distribution line section to which it is located, etc. For example, the topology layer information of a certain intelligent power distribution equipment can be expressed as: geographical coordinates "30.5432°N, 114.3456°E", the substation to which it belongs "Yangtze River Substation", and the distribution line section to which it is located "Yangtze River Line-3 Section". The topology layer information is crucial for understanding the location and connection relationship of the equipment in the entire distribution network.

[0091] The business layer stores the device operating parameters and communication status. The operating parameters include electrical parameters such as voltage, current, power factor, active power, and reactive power. The communication status includes the communication protocol type, communication quality index, and last communication time. For example, the business layer information of a smart power distribution device can be expressed as: voltage "10.5kV", current "120A", power factor "0.92", communication protocol "IEC61850", communication quality "good", and last communication time "2023-12-01 14:30:25".

[0092] Next, the device unique identification code is obtained from the physical layer, and a device identity mapping table is established based on the device unique identification code, and the device identity mapping table is written to the business layer. The device identity mapping table is a data structure that maps the device unique identification code to the device's identity in the business system. For example, the device unique identification code "PD2023120001" may be mapped to "Yangtze River Substation-Switch No. 3" in the business system. This mapping relationship enables the business system to accurately identify and operate specific physical devices.

[0093] The structure of the device identity mapping table can be designed to include the following fields: device unique identification code, business system identification, device type code, installation location code, management department code, etc. For example:

[0094] The equipment's unique identification code is "PD2023120001", the business system identifier is "CJBD-SW003", the equipment type code is "SW" (indicating switch), the installation location code is "CJBD-L3" (indicating Line 3 of the Yangtze River Substation), and the management department code is "OM-EAST" (indicating the East District Operation and Maintenance Department).

[0095] The spatial location information of the intelligent power distribution equipment in the distribution network is obtained from the topology layer, and the device connection relationship matrix is ​​generated based on graph theory. The matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices. In actual implementation, the adjacency matrix can be used to represent the connection relationship between devices. The element value in the matrix is ​​1, indicating that the two devices are directly connected, and 0, indicating that they are not directly connected.

[0096] For example, suppose there are 5 intelligent power distribution devices (numbered 1 to 5), and their connection relationships are as follows: Device 1 is connected to Device 2 and Device 3; Device 2 is connected to Device 1 and Device 4; Device 3 is connected to Device 1 and Device 5; Device 4 is connected to Device 2 and Device 5; Device 5 is connected to Device 3 and Device 4. Then the device connection relationship matrix can be expressed as:

[0097] The connection relationship between device 1 and device 1 is 0, the connection relationship between device 1 and device 2 is 1, the connection relationship between device 1 and device 3 is 1, the connection relationship between device 1 and device 4 is 0, and the connection relationship between device 1 and device 5 is 0;

[0098] The connection relationship between device 2 and device 1 is 1, the connection relationship between device 2 and device 2 is 0, the connection relationship between device 2 and device 3 is 0, the connection relationship between device 2 and device 4 is 1, and the connection relationship between device 2 and device 5 is 0;

[0099] The connection relationship between device 3 and device 1 is 1, the connection relationship between device 3 and device 2 is 0, the connection relationship between device 3 and device 3 is 0, the connection relationship between device 3 and device 4 is 0, and the connection relationship between device 3 and device 5 is 1;

[0100] The connection relationship between device 4 and device 1 is 0, the connection relationship between device 4 and device 2 is 1, the connection relationship between device 4 and device 3 is 0, the connection relationship between device 4 and device 4 is 0, and the connection relationship between device 4 and device 5 is 1;

[0101] The connection relationship between device 5 and device 1 is 0, the connection relationship between device 5 and device 2 is 0, the connection relationship between device 5 and device 3 is 1, the connection relationship between device 5 and device 4 is 1, and the connection relationship between device 5 and device 5 is 0.

[0102] The topological distance matrix between devices is calculated based on the device connection relationship matrix. The distance value in the topological distance matrix is ​​obtained by the minimum distance of the physical path between devices. In graph theory, the shortest path between two nodes can be calculated by breadth-first search or Dijkstra algorithm. For the connection relationship of the above five devices, the calculated topological distance matrix is:

[0103] The distance between device 1 and device 1 is 0, the distance between device 1 and device 2 is 1, the distance between device 1 and device 3 is 1, the distance between device 1 and device 4 is 2, and the distance between device 1 and device 5 is 2;

[0104] The distance from device 2 to device 1 is 1, the distance from device 2 to device 2 is 0, the distance from device 2 to device 3 is 2, the distance from device 2 to device 4 is 1, and the distance from device 2 to device 5 is 2;

[0105] The distance from device 3 to device 1 is 1, the distance from device 3 to device 2 is 2, the distance from device 3 to device 3 is 0, the distance from device 3 to device 4 is 2, and the distance from device 3 to device 5 is 1;

[0106] The distance from device 4 to device 1 is 2, the distance from device 4 to device 2 is 1, the distance from device 4 to device 3 is 2, the distance from device 4 to device 4 is 0, and the distance from device 4 to device 5 is 1;

[0107] The distance from device 5 to device 1 is 2, the distance from device 5 to device 2 is 2, the distance from device 5 to device 3 is 1, the distance from device 5 to device 4 is 1, and the distance from device 5 to device 5 is 0.

[0108] The calculated topological distance matrix is ​​stored in the topological layer. After being stored, the topological distance matrix can be used in various application scenarios such as power distribution network analysis, fault location, and network optimization. For example, when a device fails, other devices that may be affected can be quickly determined based on the topological distance matrix; when performing network transformation, the impact of the transformation on the network topology can be evaluated.

[0109] The three-layer architecture equipment information database established by the above method not only realizes the comprehensive management of intelligent power distribution equipment, but also provides a data basis for the intelligent operation and maintenance of the power distribution network through the quantitative representation of topological relationships. This method is applicable to various types of intelligent power distribution equipment, including but not limited to intelligent switches, intelligent transformers, intelligent metering equipment, etc., and has broad application prospects.

[0110] In an optional implementation, sending an identity authentication request to the smart power distribution device, the identity authentication request including verification code information randomly generated by a key exchange algorithm; and receiving verification response information returned by the smart power distribution device based on the verification code information includes:

[0111] Query the device identity mapping table according to the unique identification code of the device to obtain the communication level information and authorization level information of the intelligent power distribution device; determine the generation range of the master station random number according to the communication level information, and the generation range of the master station random number is positively correlated with the communication level information;

[0112] Generate the master station random number, and send the master station random number to the intelligent power distribution device through the power line carrier channel, and receive the device random number returned by the intelligent power distribution device; select the primitive root value corresponding to the authorization level information, and recursively calculate the primitive root value with the master station random number and the device random number to generate a random verification code;

[0113] Obtaining a device certificate identifier corresponding to the device unique identification code from a certificate management system, and verifying the validity of the device certificate identifier;

[0114] Obtain the timestamp of the current system, and generate mixed authentication information according to a preset combination rule by combining the device certificate identifier, the random verification code and the timestamp; send the mixed authentication information to the intelligent power distribution device, and wait for the intelligent power distribution device to return verification response information.

[0115] An authentication request is sent to the smart power distribution device, which contains verification code information randomly generated by a key exchange algorithm. In practical applications, the Diffie-Hellman key exchange algorithm can be used to generate the initial verification code. For example, the system can randomly select a large prime number P (such as P=997) and a primitive root g (such as g=7), then generate a random private key a (such as a=365), calculate the public key A = g^a mod P (i.e. 7^365 mod 997), and send P, g, and A as components of the verification code information to the smart power distribution device.

[0116] After receiving the verification request, the system queries the device identity mapping table according to the device unique identification code to obtain the communication level information and authorization level information of the intelligent power distribution device. The device unique identification code can be a 24-digit alphanumeric combination, such as "PD2023XYZ789012345ABCDE". The device identity mapping table is a pre-established database table containing fields: device unique identification code, communication level information, authorization level information, etc. Communication level information can be divided into high level (value is 3), middle level (value is 2) and low level (value is 1); authorization level information can be divided into administrator level (value is 5), operator level (value is 3) and visitor level (value is 1).

[0117] Determine the range of random numbers generated by the master station based on the acquired communication level information. The range of random numbers generated by the master station is positively correlated with the communication level information, that is, the higher the communication level, the larger the range of random numbers generated, thereby improving security. The specific implementation can adopt the following corresponding relationship: the high level (value is 3) corresponds to a random number range of [10000-99999], the middle level (value is 2) corresponds to a random number range of [1000-9999], and the low level (value is 1) corresponds to a random number range of [100-999]. For example, if the device communication level is high level (value is 3), the range of random numbers generated by the master station is 10000-99999.

[0118] The system generates a master random number and sends it to the intelligent power distribution device through the power line carrier channel. Power line carrier communication uses OFDM modulation technology, with an operating frequency range of 10kHz-500kHz and a data transmission rate of up to 200kbps. For example, if the device communication level is high, the system may generate a master random number of 85421 and send it through the power line carrier channel.

[0119] The system receives the device random number returned by the intelligent power distribution device. The device random number is generated by the intelligent power distribution device according to its internal algorithm. For example, the device may return the device random number 67890.

[0120] The system selects the original root value that corresponds to the authorization level information. Different authorization levels correspond to different original root values ​​to enhance security. For example, the administrator level (value 5) corresponds to the original root value 17, the operator level (value 3) corresponds to the original root value 13, and the guest level (value 1) corresponds to the original root value 11. If the device authorization level is the operator level, the original root value 13 is selected.

[0121] The system recursively calculates the original root value with the master random number and the device random number to generate a random verification code. The recursive calculation process is as follows: first, multiply the original root value with the master random number, then take the result modulo 100000 to get the intermediate value; then add the intermediate value to the device random number, and take the result modulo 100000 again to get the random verification code. Taking the above values ​​as an example, the original root value 13 is multiplied by the master random number 85421 to get 1110473, and the modulo 100000 is 10473; 10473 is added to the device random number 67890 to get 78363, which is the final random verification code.

[0122] The system obtains the device certificate identifier corresponding to the device's unique identification code from the certificate management system and verifies the validity of the device certificate identifier. The device certificate identifier is a 32-bit hexadecimal string, such as "8A7B6C5D4E3F2G1H0I9J8K7L6M5N4O3P". Certificate validity verification includes checking whether the certificate is expired or revoked. The system queries the certificate status through OCSP (Online Certificate Status Protocol). If the certificate is valid, the subsequent steps will be continued. Otherwise, the verification process will be terminated and the exception will be recorded.

[0123] The system obtains the current system timestamp, accurate to milliseconds, in the format of "YYYY-MM-DD HH:MM:SS.mmm", for example "2023-10-15 14:30:25.789".

[0124] The system generates mixed authentication information by combining the device certificate identifier, random verification code, and timestamp according to the preset combination rules. The combination rule can be: the first 16 digits of the device certificate identifier and the hexadecimal value of the random verification code are arranged alternately, and then the Unix timestamp value (second level) of the timestamp is appended. For example, the first 16 digits of the device certificate identifier are "8A7B6C5D4E3F2G1H", the random verification code 78363 is converted to hexadecimal "131FB", and the Unix timestamp of the timestamp "2023-10-15 14:30:25.789" is 1697378425, then the mixed authentication information may be "8A131FB7B6C5D4E3F2G1H1697378425".

[0125] The system sends the hybrid authentication information to the smart power distribution device and waits for the smart power distribution device to return the verification response information. The hybrid authentication information is sent through the power line carrier channel and uses the AES-256 encryption algorithm to ensure transmission security. After receiving the hybrid authentication information, the smart power distribution device will parse and verify it and return the verification response information. The verification response information contains the verification result code and timestamp. For example, "SUCCESS:1697378426.123" means that the verification is successful, and the timestamp is "2023-10-15 14:30:26.123".

[0126] If the verification response information indicates that the verification is successful, a secure communication channel is established; if the verification fails, appropriate measures are taken according to the cause of the failure, such as re-initiating the verification request or recording the abnormality and alarming. The system also sets a verification timeout mechanism. If no verification response is received within a preset time (such as 5 seconds), the verification is considered to have failed.

[0127] Figure 3 The following is a schematic diagram showing the comparison of the verification success rate of this solution and the existing technology at different communication levels. Figure 3As shown in the data, the verification success rate of "this scheme" in all communication levels (1-6) is higher than that of the other three methods, which are 87.5%, 89.8%, 91.4%, 93.2%, 93.8% and 94.5% respectively. In comparison, the verification success rate of "traditional password-based method" is 83.5%-89.1%; "simple random number method" is 77.3%-83.0%; "certificate-based method" is 74.8%-84.7%. As the communication level increases, the verification success rate of each method has increased, but "this scheme" has always maintained its leading advantage. The last column "performance improvement" shows that this scheme has improved the verification success rate by 4.8%-6.1% on average compared with other methods, among which the performance improvement is more significant at high-level communication (4-6 levels), reaching more than 6.0%.

[0128] This application automatically adjusts the range of random numbers generated by the master station according to the device communication level. The higher the communication level, the larger the range of random numbers, providing more flexible security protection. A multi-level authorization mechanism based on the original root value is introduced, and different authorization levels correspond to different original root values, which improves the refinement of authorization management. The device certificate identification, random verification code and timestamp are innovatively combined according to preset rules to form mixed authentication information, realizing multi-factor verification.

[0129] Through the above steps, the secure identity authentication of the intelligent power distribution equipment is realized, ensuring the security and reliability of the communication of the equipment in the power distribution network. This method combines a variety of cryptographic technologies and security mechanisms, which can effectively prevent unauthorized access and man-in-the-middle attacks.

[0130] In an optional implementation, a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network is constructed, and the verification node set corresponding to the area of ​​the smart power distribution device is selected in the verification sub-chain network, including:

[0131] Construct a multi-level blockchain network architecture, which includes a main chain layer network and a verification sub-chain network. The main chain layer network adopts a directed acyclic graph structure, and the verification sub-chain network corresponds to different regional organizations;

[0132] According to the device type code and the area identification code of the intelligent power distribution device, determining the belonging area and the device type of the intelligent power distribution device in the verification subchain network;

[0133] Based on the region to which the intelligent power distribution equipment belongs, a verification node set of the corresponding region is selected in the verification subchain network, and the communication delay, link reliability index and node computing capacity evaluation value between each node in the verification node set are calculated;

[0134] According to the communication delay, the link reliability index and the node computing capability evaluation value, an edge weight matrix between nodes in the verification node set is calculated, and the connection relationship between the verification nodes is determined based on the edge weight matrix.

[0135] The multi-level blockchain network architecture includes the main chain layer network and the verification sub-chain network. The main chain layer network adopts a directed acyclic graph structure, and the verification sub-chain network corresponds to different regional organizations. As the core layer of the entire system, the main chain layer network is responsible for storing key data and coordinating the operation of each verification sub-chain network. The nodes in the main chain layer network can be high-performance servers configured with Intel Xeon E5-2680 v4 processors, 128GB memory, 10TB storage space, and running a dedicated blockchain operating system. These nodes are interconnected through a high-speed fiber optic network with a bandwidth of no less than 10Gbps to ensure efficient data transmission. The directed acyclic graph structure of the main chain layer network allows parallel processing of transactions, which improves the system throughput and can process 5,000-8,000 transactions per second.

[0136] The verification subchain network is divided according to geographical location or administrative divisions. For example, the corresponding verification subchain network can be set up according to the three-level administrative divisions of province, city, and county. Each verification subchain network adopts the Byzantine fault-tolerant consensus mechanism, which tolerates no more than one-third of the nodes to fail or act maliciously. The nodes of the verification subchain network can be medium-performance servers configured with Intel Xeon E5-2650 processors, 64GB memory, and 5TB storage space.

[0137] According to the equipment type code and regional identification code of the smart distribution equipment, the region and equipment type of the smart distribution equipment are determined in the verification subchain network. The equipment type code uses an 8-bit string, the first 2 digits represent the equipment category (such as "TR" for transformers, "CB" for circuit breakers, and "SM" for smart meters), the middle 3 digits represent the equipment subcategory, and the last 3 digits represent the equipment model version. The regional identification code uses a 12-bit string, the first 4 digits represent the provincial administrative region code, the middle 4 digits represent the municipal administrative region code, and the last 4 digits represent the county administrative region code.

[0138] For example, a device coded as "TR001A01-330100330106" represents a transformer of type A01 and subclass 001 located in Xihu District, Hangzhou City, Zhejiang Province. The system parses the code to determine that the device type is a transformer and that the region it belongs to is Xihu District, Hangzhou City, Zhejiang Province. The system maintains a mapping table that maps the region identification code to the corresponding verification subchain network. In this example, the system queries the mapping table to determine that the device should belong to the "Zhejiang Province - Hangzhou City" verification subchain network.

[0139] Based on the region of the intelligent power distribution equipment, the verification node set of the corresponding region is selected in the verification subchain network, and the communication delay, link reliability index and node computing capacity evaluation value between the nodes in the verification node set are calculated. The system first selects at least 7 and no more than 21 verification nodes from the verification subchain network of the corresponding region to form a verification node set. The selection criteria include a comprehensive score of indicators such as node online time, historical verification accuracy, and computing resource occupancy rate.

[0140] For the calculation of communication delay, the system uses ICMP protocol to send detection packets and measure the round-trip time (RTT) between nodes. The system measures every 30 minutes within 24 hours and takes the average value as the communication delay between nodes. For example, the average communication delay between node A and node B is 15ms, and the average communication delay between node A and node C is 25ms.

[0141] The link reliability index is calculated by continuously monitoring the communication success rate between nodes. The system sends 100 test data packets every hour for 7 days, records the number of successfully received data packets, and calculates the communication success rate. For example, the communication success rate between node A and node B is 99.2%, and the communication success rate between node A and node C is 97.8%.

[0142] The node computing power evaluation value is calculated based on the node's hardware indicators such as processor performance, memory capacity, storage read and write speed, and network bandwidth, combined with historical transaction processing speed. The system uses a standard test set to measure the average time for each node to process transactions and standardizes the results into a score of 0-100. For example, the computing power evaluation value of node A is 85, the computing power evaluation value of node B is 92, and the computing power evaluation value of node C is 78.

[0143] According to the communication delay, link reliability index and node computing power evaluation value, the edge weight matrix between nodes in the verification node set is calculated, and the connection relationship between the verification nodes is determined based on the edge weight matrix. The edge weight calculation comprehensively considers three factors: the inverse of the communication delay, the link reliability index and the weighted sum of the node computing power evaluation value.

[0144] Specifically, for the edge weight between node i and node j, the system first normalizes the communication delay to a value between 0 and 1, the link reliability index is already a value between 0 and 1, and the node computing power evaluation value is divided by 100 to get a value between 0 and 1. Then, the system multiplies these three standardized values ​​by the weight coefficients (communication delay weight is 0.4, link reliability weight is 0.35, node computing power weight is 0.25), and finally sums them up to get the edge weight.

[0145] For example, the edge weight calculation between node A and node B: the communication delay is standardized to 15ms to be 0.85, the link reliability is 0.992, the computing power is (85+92) / 2 / 100=0.885, and the final edge weight is 0.85×0.4+0.992×0.35+0.885×0.25=0.905.

[0146] The system selects the edge with the highest weight to establish connections between nodes based on the calculated edge weight matrix. The system sets a threshold of 0.8, and only node pairs with edge weights exceeding this threshold are connected. The final verification node network topology ensures an efficient and reliable transaction verification process.

[0147] Through the above method, the system successfully built a multi-level blockchain network architecture including the main chain layer network and the verification sub-chain network, and selected the verification node set corresponding to the area of ​​the smart distribution equipment in the verification sub-chain network, providing a solid blockchain infrastructure support for the safe and reliable operation of the smart distribution equipment.

[0148] In an optional implementation, a consensus authority matrix of the verification subchain network is generated based on the connection relationship between the verification nodes, and determining the node reputation corresponding to the intelligent power distribution device according to the consensus authority matrix includes:

[0149] Generate a consensus authority matrix of the verification subchain network based on the connection relationship between the verification nodes, the consensus authority matrix is ​​used to characterize the verification authority relationship between nodes in the verification subchain network, and store the consensus authority matrix in the verification subchain network;

[0150] According to the timestamp code of the intelligent power distribution device, consensus verification is performed on the nodes in the verification node set, and the number of successful consensuses, verification response time and total number of interactions between nodes are counted;

[0151] Calculate the node reputation of each node in the verification node set based on the number of consensus successes, the verification response time, and the total number of interactions, and write the node reputation into the main chain layer network;

[0152] When the node reputation meets the preset verification trigger threshold, the smart contract is triggered to execute device identity authentication, and the authentication result is returned to the main chain layer network through the verification sub-chain network.

[0153] Figure 4It is a schematic diagram of the interface of the intelligent power distribution equipment verification management system. In actual applications, the verification node set may include multiple intelligent power distribution equipment nodes, such as intelligent transformers, intelligent switches, intelligent electricity meters, etc. The system constructs an n×n consensus permission matrix M by analyzing the physical connection relationships and logical interaction relationships among these nodes, where n is the number of verification nodes. The element M[i][j] in the matrix represents the verification permission value of node i for node j, and the value range is [0,1]. When M[i][j]=1, it means that node i has full verification permission for node j; when M[i][j]=0, it means that node i has no verification permission for node j; when 0<M[i][j]<1, it means that node i has partial verification permission for node j, and the size of the permission is determined by the specific value.

[0154] For example, in an intelligent power distribution network with 5 verification nodes, according to the physical connection relationships among the nodes, the following consensus permission matrix can be generated: 1.0 0.8 0.5 0.3 0.0; 0.8 1.0 0.7 0.4 0.2; 0.5 0.7 1.0 0.9 0.6; 0.3 0.4 0.9 1.0 0.8; 0.0 0.2 0.6 0.8 1.0;

[0160] This matrix indicates that adjacent nodes have relatively high verification permissions, while nodes that are farther apart have lower verification permissions. The system stores this consensus permission matrix in the block of the verification sub-chain network as the basis for subsequent node reputation calculation.

[0161] Based on the timestamp encoding of the intelligent power distribution equipment, consensus verification is performed on the nodes in the verification node set. The timestamp encoding refers to the unique identifier assigned to each intelligent power distribution equipment, which contains the time information when the equipment joins the network and the equipment type information. The system triggers the consensus verification process among nodes based on the timestamp encoding according to a preset verification period (such as once every 10 minutes).

[0162] During the consensus verification process, the system will count the following three key metrics: the number of successful consensus times, the verification response time, and the total number of interactions. The number of successful consensus times refers to the number of times the node successfully completes the consensus verification; the verification response time refers to the time required for the node to respond to the verification request; the total number of interactions refers to the total number of times the node participates in the verification process.

[0163] For example, within a verification period, the interaction situation of node A with other nodes is as follows:

[0164] - Interacts with node B 15 times, with 12 successful consensuses and an average response time of 200 milliseconds;

[0165] - Interacted with node C 10 times, consensus was successful 8 times, and the average response time was 250 milliseconds;

[0166] - Interacted with node D 8 times, consensus was successful 5 times, and the average response time was 300 milliseconds;

[0167] - Interacted with node E 5 times, consensus was successful 2 times, and the average response time was 350 milliseconds;

[0168] Based on the above statistical data, the system calculates the node reputation of each node in the verification node set. The node reputation calculation takes into account three factors: consensus success rate, average response time and interaction activity. The consensus success rate is equal to the number of consensus successes divided by the total number of interactions; the average response time is obtained by taking the average of all verification response times; the interaction activity is equal to the ratio of the total number of node interactions to the maximum number of interactions in the network.

[0169] For node A, its node reputation is calculated as follows:

[0170] - Consensus success rate = (12+8+5+2) / (15+10+8+5) = 27 / 38 ≈ 0.71;

[0171] - Average response time = (200×15 + 250×10 + 300×8 + 350×5) / 38 ≈ 253 milliseconds;

[0172] - Response time score = 1 - (253 / 500) = 0.494 (assuming the maximum tolerable response time is 500 milliseconds);

[0173] - Interaction activity = 38 / 45 = 0.844 (assuming the maximum number of interactions in the network is 45);

[0174] Combining these three factors, the reputation of node A can be calculated as: 0.71×0.4 + 0.494×0.3 + 0.844×0.3 = 0.684 (assuming that the weights of the three factors are 0.4, 0.3, and 0.3, respectively).

[0175] The system writes the calculated node reputation into the block of the main chain layer network as the basis for identity authentication of the smart distribution equipment.

[0176] When the node reputation meets the preset verification trigger threshold, the system triggers the smart contract to perform device identity authentication. The preset verification trigger threshold is usually set to a value between 0.6 and 0.8, depending on network security requirements. For example, when the threshold is set to 0.65, the reputation of node A, 0.684, exceeds the threshold, and the system will trigger the smart contract to perform identity authentication.

[0177] The authentication process includes the following steps: the system verifies the validity of the node's digital certificate; checks whether the node's behavior characteristics are consistent with historical records; and confirms whether the node's physical location information is as expected. The authentication results include "pass", "warning" and "reject". For node A, assuming that its digital certificate is valid, its behavior characteristics are normal, and its physical location is as expected, the authentication result is "pass".

[0178] The system returns the authentication result to the main chain network through the verification sub-chain network and updates the node's identity status. For nodes that pass the authentication, they are allowed to continue to participate in network activities; for nodes in the warning state, the system will increase the frequency of monitoring; for nodes in the rejected state, the system will remove them from the trusted node list and prevent them from participating in key business.

[0179] Through the above method, this embodiment realizes dynamic reputation evaluation and identity authentication of device nodes in the smart power distribution network, effectively improving the security and reliability of the network.

[0180] In an optional implementation, judging whether the identity authentication of the intelligent power distribution device is passed according to the verification result of the verification response information and the node reputation, and allocating a communication time slot to the intelligent power distribution device if the identity authentication is passed, and establishing a secure communication link between the intelligent power distribution device and the distribution automation master station includes:

[0181] The verification result is weighted according to the node reputation, and a consistency coefficient of the verification result is calculated; when the consistency coefficient is greater than a preset consistency threshold, it is determined that the identity authentication of the intelligent power distribution device is passed;

[0182] Obtaining the total amount of available time slots of the communication link, calculating the current time slot occupancy rate, and dynamically adjusting the pre-acquired communication time slot demand according to the time slot occupancy rate to obtain the actual number of allocated communication time slots;

[0183] A communication time slot is allocated to the intelligent power distribution device, and a secure communication link is established between the intelligent power distribution device and a distribution automation master station.

[0184] The verification results are weighted according to the node reputation, and the consistency coefficient of the verification results is calculated. When the consistency coefficient is greater than the preset consistency threshold, the identity authentication of the intelligent distribution device is determined to be passed. The total available time slots of the communication link are obtained, the current time slot occupancy rate is calculated, and the pre-acquired communication time slot demand is dynamically adjusted according to the time slot occupancy rate to obtain the actual number of allocated communication time slots. Communication time slots are allocated to the intelligent distribution equipment, and a secure communication link is established between the intelligent distribution equipment and the distribution automation master station.

[0185] In the specific implementation process, it is necessary to obtain the verification results of multiple verification nodes on the smart distribution equipment. Each verification node verifies the identity authentication request sent by the smart distribution equipment based on different verification algorithms or verification strategies, and generates a verification result. The verification result can be a binary result (pass / fail) or a multi-level scoring result (for example, 0-100 points).

[0186] At the same time, the system will maintain a node reputation database, record the historical verification accuracy, response time, stability and other indicators of each verification node, and calculate the node reputation value comprehensively. The node reputation value ranges from 0 to 1, where 0 means completely untrustworthy and 1 means completely trustworthy.

[0187] When calculating the consistency coefficient of the verification result, the verification result of each verification node is weighted. Assuming there are n verification nodes, the verification result of the i-th verification node is Ri, and the node reputation is Ci, then the weighted verification result is Ri multiplied by Ci. All weighted verification results are normalized to obtain the consistency coefficient.

[0188] For example, suppose there are 5 verification nodes, and their verification results are: passed, passed, failed, passed, passed, and the corresponding node reputations are 0.9, 0.8, 0.5, 0.7, and 0.85. Let "pass" be 1 and "fail" be 0, then the weighted verification results are: 0.9, 0.8, 0, 0.7, and 0.85. When calculating the consistency coefficient, sum the weighted results to get 3.25, and then divide it by the sum of the node reputations 3.75, and get a consistency coefficient of 0.867.

[0189] The preset consistency threshold can be set according to the system security requirements, for example, set to 0.8. In the above example, the consistency coefficient 0.867 is greater than the preset consistency threshold 0.8, so it is determined that the identity authentication of the smart power distribution device has passed.

[0190] The total amount of available time slots for obtaining the communication link is determined according to the current network bandwidth, communication protocol and physical layer characteristics. For example, in a certain distribution automation system, each communication cycle contains 1000 time slots, and each time slot lasts for 10 milliseconds.

[0191] The current timeslot occupancy rate is calculated as the ratio of the number of allocated timeslots to the total number of available timeslots. For example, if 600 timeslots are currently allocated, the timeslot occupancy rate is 60%.

[0192] The method for dynamically adjusting the communication time slot demand according to the time slot occupancy rate is as follows: the intelligent power distribution device provides its expected communication time slot demand when requesting a connection, for example, 50 time slots. The system calculates the actual number of allocated communication time slots using a dynamic adjustment strategy based on the current time slot occupancy rate.

[0193] When the slot occupancy rate is low (for example, less than 30%), all the needs of the equipment can be met, that is, 50 time slots are allocated; when the slot occupancy rate is at a medium level (for example, 30%-70%), the time slots are allocated in a linear decreasing manner. For example, when the occupancy rate is 60%, the number of allocated time slots is 50 multiplied by (1-(60%-30%) / (70%-30%)), that is, 50 multiplied by 0.25, which is 37 time slots; when the slot occupancy rate is high (for example, greater than 70%), the minimum guaranteed number of time slots is allocated, for example, 10 time slots.

[0194] After determining the actual number of allocated communication time slots, the system will send time slot allocation information to the intelligent distribution equipment, including the starting time slot number, the number of allocated time slots, the validity period of the time slot, etc. After receiving the time slot allocation information, the intelligent distribution equipment communicates according to the specified time slot, thereby establishing a secure communication link with the distribution automation master station.

[0195] In order to improve communication efficiency and security, the system will also regularly evaluate the quality of the communication link, including indicators such as signal strength, bit error rate, and latency. If the communication quality is found to have deteriorated, the time slot reallocation mechanism will be triggered to adjust the number or location of the allocated time slots.

[0196] In addition, the system will also monitor the communication behavior of smart distribution equipment. If abnormal behavior is found (such as communicating beyond the allocated time slot range, sending malicious data packets, etc.), the credit score of the device will be reduced. In severe cases, the communication link will be interrupted and the device will be added to the blacklist.

[0197] Through the above method, reliable identity authentication and efficient and secure communication link establishment of intelligent distribution equipment can be achieved, improving the security and stability of the distribution automation system. This method is applicable to various intelligent distribution network environments, especially in scenarios with limited resources and high security requirements.

[0198] The intelligent power distribution equipment remote identification system based on power line communication in the embodiment of the present invention includes:

[0199] The first unit is used to receive device identification information sent by the intelligent power distribution device through power line carrier communication, where the device identification information includes device type information, device number information and device installation location information;

[0200] The second unit is used to establish a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer and a business layer, wherein the device information database stores a correspondence between the device identification information and the topology structure of the distribution network; send an identity authentication request to the intelligent power distribution device, wherein the identity authentication request includes verification code information randomly generated by a key exchange algorithm; and receive verification response information returned by the intelligent power distribution device based on the verification code information;

[0201] The third unit is used to build a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a verification node set in the verification sub-chain network corresponding to the intelligent power distribution equipment, generate a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determine the node reputation corresponding to the intelligent power distribution equipment according to the consensus authority matrix;

[0202] The fourth unit is used to determine whether the identity authentication of the intelligent distribution device is passed based on the verification result of the verification response information and the node credibility, and if the identity authentication is passed, allocate a communication time slot to the intelligent distribution device to establish a secure communication link between the intelligent distribution device and the distribution automation master station.

[0203] According to a third aspect of the embodiments of the present invention,

[0204] An electronic device is provided, comprising:

[0205] processor;

[0206] a memory for storing processor-executable instructions;

[0207] The processor is configured to call the instructions stored in the memory to execute the aforementioned method.

[0208] A fourth aspect of the embodiments of the present invention is:

[0209] A computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the aforementioned method is implemented.

[0210] The present invention may be a method, an apparatus, a system and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for executing various aspects of the present invention.

[0211] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A remote identification method for intelligent power distribution equipment based on power line communication, characterized in that: include: Receiving device identification information sent by the intelligent power distribution device through power line carrier communication, the device identification information includes device type information, device number information and device installation location information; Establishing a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer and a business layer, wherein the device information database stores a correspondence between the device identification information and the topology structure of the distribution network; Sending an identity authentication request to the intelligent power distribution device, the identity authentication request including verification code information randomly generated by a key exchange algorithm; receiving verification response information returned by the intelligent power distribution device based on the verification code information; Construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a verification node set in the verification sub-chain network corresponding to the intelligent power distribution device, generate a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determine the node reputation corresponding to the intelligent power distribution device according to the consensus authority matrix; Based on the verification result of the verification response information and the node reputation, determine whether the identity authentication of the intelligent distribution device is passed. If the identity authentication is passed, allocate a communication time slot to the intelligent distribution device to establish a secure communication link between the intelligent distribution device and the distribution automation master station.

2. The method according to claim 1, characterized in that The method further comprises: A distributed time synchronization protocol is used to perform network time synchronization on the intelligent power distribution equipment, wherein a clock synchronization module is set in each of the intelligent power distribution equipment, and the clock synchronization module calculates the transmission delay based on the timestamp information of the power line carrier signal, and uses the least squares method to fit the delay data of multiple samples to generate clock deviation compensation parameters, thereby achieving accurate time synchronization of the intelligent power distribution equipment.

3. The method according to claim 1, characterized in that Establishing a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer, and a business layer, wherein the corresponding relationship between the device identification information and the topology structure of the distribution network is stored in the device information database, including: The physical layer stores the unique identification code, device model, production date and hardware version number of the device, the topological layer stores the spatial location information of the intelligent power distribution device in the power distribution network, and the business layer stores the operating parameters and communication status of the device; Acquire the unique device identification code from the physical layer, establish a device identity mapping table based on the unique device identification code, and write the device identity mapping table into the service layer; Acquire spatial location information of the intelligent power distribution device in the power distribution network from the topology layer, generate a device connection relationship matrix based on graph theory, and the matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices; A topological distance matrix between devices is calculated according to the device connection relationship matrix, the distance values ​​in the topological distance matrix are obtained by the minimum distance of the physical paths between devices, and the topological distance matrix is ​​stored in the topological layer.

4. The method according to claim 3, characterized in that Sending an identity authentication request to the intelligent power distribution device, wherein the identity authentication request includes verification code information randomly generated by a key exchange algorithm; Receiving verification response information returned by the intelligent power distribution device based on the verification code information includes: Query the device identity mapping table according to the unique identification code of the device to obtain the communication level information and authorization level information of the intelligent power distribution device; determine the generation range of the master station random number according to the communication level information, and the generation range of the master station random number is positively correlated with the communication level information; Generate the master station random number, and send the master station random number to the intelligent power distribution device through the power line carrier channel, and receive the device random number returned by the intelligent power distribution device; select the primitive root value corresponding to the authorization level information, and recursively calculate the primitive root value with the master station random number and the device random number to generate a random verification code; Obtaining a device certificate identifier corresponding to the device unique identification code from a certificate management system, and verifying the validity of the device certificate identifier; Obtain the timestamp of the current system, and generate mixed authentication information according to a preset combination rule by combining the device certificate identifier, the random verification code and the timestamp; send the mixed authentication information to the intelligent power distribution device, and wait for the intelligent power distribution device to return verification response information.

5. The method according to claim 1, characterized in that Construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, and select a verification node set corresponding to the area of ​​the smart power distribution equipment in the verification sub-chain network, including: Construct a multi-level blockchain network architecture, which includes a main chain layer network and a verification sub-chain network. The main chain layer network adopts a directed acyclic graph structure, and the verification sub-chain network corresponds to different regional organizations; According to the device type code and the area identification code of the intelligent power distribution device, determining the belonging area and the device type of the intelligent power distribution device in the verification subchain network; Based on the region to which the intelligent power distribution equipment belongs, a verification node set of the corresponding region is selected in the verification subchain network, and the communication delay, link reliability index and node computing capacity evaluation value between each node in the verification node set are calculated; According to the communication delay, the link reliability index and the node computing capability evaluation value, an edge weight matrix between nodes in the verification node set is calculated, and the connection relationship between the verification nodes is determined based on the edge weight matrix.

6. The method according to claim 5, characterized in that Generating a consensus authority matrix for the verification subchain network based on the connection relationship between the verification nodes, and determining the node reputation corresponding to the intelligent power distribution device according to the consensus authority matrix includes: Generate a consensus authority matrix of the verification subchain network based on the connection relationship between the verification nodes, the consensus authority matrix is ​​used to characterize the verification authority relationship between nodes in the verification subchain network, and store the consensus authority matrix in the verification subchain network; According to the timestamp code of the intelligent power distribution device, consensus verification is performed on the nodes in the verification node set, and the number of successful consensuses, verification response time and total number of interactions between nodes are counted; Calculate the node reputation of each node in the verification node set based on the number of consensus successes, the verification response time, and the total number of interactions, and write the node reputation into the main chain layer network; When the node reputation meets the preset verification trigger threshold, the smart contract is triggered to execute device identity authentication, and the authentication result is returned to the main chain layer network through the verification sub-chain network.

7. The method according to claim 1, characterized in that According to the verification result of the verification response information and the node reputation, judging whether the identity authentication of the intelligent power distribution device is passed, and if the identity authentication is passed, allocating a communication time slot to the intelligent power distribution device, and establishing a secure communication link between the intelligent power distribution device and the distribution automation master station includes: The verification result is weighted according to the node reputation, and a consistency coefficient of the verification result is calculated; when the consistency coefficient is greater than a preset consistency threshold, it is determined that the identity authentication of the intelligent power distribution device is passed; Obtaining the total amount of available time slots of the communication link, calculating the current time slot occupancy rate, and dynamically adjusting the pre-acquired communication time slot demand according to the time slot occupancy rate to obtain the actual number of allocated communication time slots; A communication time slot is allocated to the intelligent power distribution device, and a secure communication link is established between the intelligent power distribution device and a distribution automation master station.

8. An intelligent power distribution equipment remote identification system based on power line communication, used to implement the method according to any one of claims 1 to 7, characterized in that: include: The first unit is used to receive device identification information sent by the intelligent power distribution device through power line carrier communication, where the device identification information includes device type information, device number information and device installation location information; The second unit is used to establish a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topological layer and a business layer, wherein the device information database stores a correspondence between the device identification information and the topological structure of the distribution network; Sending an identity authentication request to the intelligent power distribution device, the identity authentication request including verification code information randomly generated by a key exchange algorithm; receiving verification response information returned by the intelligent power distribution device based on the verification code information; The third unit is used to build a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a verification node set in the verification sub-chain network corresponding to the intelligent power distribution equipment, generate a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determine the node reputation corresponding to the intelligent power distribution equipment according to the consensus authority matrix; The fourth unit is used to determine whether the identity authentication of the intelligent distribution device is passed based on the verification result of the verification response information and the node credibility, and if the identity authentication is passed, allocate a communication time slot to the intelligent distribution device to establish a secure communication link between the intelligent distribution device and the distribution automation master station.

9. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method described in any one of claims 1 to 7.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Intelligent terminal safety communication method based on block chain

    CN110581854A

  • Power communication network fault simulation verification method and device, equipment and storage medium

    CN113411221A

  • Power distribution network fault processing flow optimization method based on multivariate data

    CN117592961A

  • Method and system for verifying topology identification function of power distribution area

    CN117669361A

  • New energy power equipment health early warning model management method and device and terminal equipment

    CN118193191A

Cited By

  • Blind state execution method for power protection unit of power distribution micro-grid in disaster weather

    CN122052334A