Remote Identification Method and System for Intelligent Power Distribution Equipment Based on Power Line Communication

Through the remote identification method of intelligent power distribution equipment based on power line communication and the multi-level blockchain network architecture, the problem of remote identification and identity verification security of intelligent power distribution equipment is solved, the rapid identification and precise positioning of equipment are realized, and the security and reliability of the power distribution network are enhanced.

CN119945802BActive Publication Date: 2025-06-20常州常供电力设计院有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510422424.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-06-20
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

The remote identification technology of existing smart power distribution equipment lacks a unified multi-level information management architecture, resulting in unclear correspondence between equipment information and the distribution network topology structure, making it difficult to achieve precise positioning and effective management of equipment. At the same time, the existing identity verification mechanism is insufficiently secure and is prone to man-in-the-middle attacks or replay attacks, and cannot effectively ensure the security of communication between smart power distribution equipment and the main station.

Method used

The remote identification method of intelligent power distribution equipment based on power line communication is adopted. By receiving device identification information, a three-layer architecture device information database is established to achieve rapid identification and precise positioning of equipment. At the same time, a multi-level blockchain network architecture is built to determine the credibility of device nodes by verifying the node set and consensus permission matrix, and a complete set of identity verification mechanisms are established to prevent illegal device access and malicious attacks.

Benefits of technology

It realizes the rapid identification and precise positioning of intelligent power distribution equipment, and improves the efficiency and accuracy of power distribution network management. At the same time, through the identity verification mechanism of the blockchain network architecture, illegal device access and malicious attacks are effectively prevented, and the security and reliability of the distribution network are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945802B_ABST
    Figure CN119945802B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for remotely identifying intelligent power distribution equipment based on power line communication, which relates to the field of power technology. It includes receiving device identification information, establishing a three-layer architecture device information database, sending an identity verification request and receiving a verification response, constructing a multi-level blockchain network architecture to determine the node credibility, judging whether the identity verification is passed according to the verification result and credibility, and establishing a secure communication link when the verification is passed. The present invention improves the security and reliability of the identity identification of intelligent power distribution equipment and effectively prevents illegal devices from accessing the power distribution network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to power technology, and particularly to a method and system for remotely identifying intelligent power distribution equipment based on power line communication. Background Art

[0002] With the continuous advancement of the construction of smart grids, intelligent power distribution equipment is increasingly widely used in power systems. These devices include intelligent switches, intelligent transformers, intelligent meters, etc., which can achieve automated monitoring and management of the distribution network. Power line communication technology, as a communication method that utilizes existing power lines for data transmission, provides a convenient communication channel for the remote identification and management of intelligent power distribution equipment. In an intelligent power distribution network, the remote identification of equipment is the basis for realizing distribution automation, which involves multiple links such as equipment information collection, transmission, verification, and management.

[0003] Currently, the remote identification technology of intelligent power distribution equipment mainly relies on traditional communication protocols and authentication mechanisms. However, these technologies have some obvious defects and deficiencies in practical applications.

[0004] Firstly, the traditional intelligent power distribution equipment identification method lacks a unified multi-level information management architecture, resulting in an unclear correspondence between equipment information and the distribution network topology structure, making it difficult to achieve precise positioning and effective management of equipment. Especially in a complex distribution network environment, the organization and management of equipment information are more difficult.

[0005] Secondly, the existing authentication mechanisms lack security. They mainly use static keys or simple challenge-response mechanisms, and are easily vulnerable to man-in-the-middle attacks or replay attacks, unable to effectively guarantee the security of communication between intelligent power distribution equipment and the master station. This poses a serious security risk for critical infrastructure such as the power system. Summary of the Invention

[0006] Embodiments of the present invention provide a method and system for remotely identifying intelligent power distribution equipment based on power line communication, which can solve the problems in the prior art.

[0007] In the first aspect of the embodiments of the present invention, a method for remotely identifying intelligent power distribution equipment based on power line communication is provided, including:

[0008] Receiving device identification information sent by an intelligent power distribution equipment through power line carrier communication, where the device identification information includes device type information, device number information, and device installation location information;

[0009] Establish a device information database for the intelligent power distribution device with a three - layer architecture including a physical layer, a topology layer, and a service layer. The corresponding relationship between the device identification information and the power distribution network topology structure is stored in the device information database; send an identity verification request to the intelligent power distribution device, where the identity verification request includes verification code information randomly generated through a key exchange algorithm; receive the verification response information returned by the intelligent power distribution device based on the verification code information;

[0010] Construct a multi - level blockchain network architecture including a main chain layer network and a verification sub - chain network. Select a set of verification nodes in the corresponding area of the intelligent power distribution device in the verification sub - chain network. Generate a consensus permission matrix for the verification sub - chain network based on the connection relationship between the verification nodes, and determine the node credibility corresponding to the intelligent power distribution device according to the consensus permission matrix;

[0011] Judge whether the identity verification of the intelligent power distribution device passes according to the verification result of the verification response information and the node credibility. In the case of successful identity verification, allocate communication time slots to the intelligent power distribution device and establish a secure communication link between the intelligent power distribution device and the power distribution automation master station.

[0012] The method further includes:

[0013] Perform network time synchronization on the intelligent power distribution device using a distributed time synchronization protocol. Among them, a clock synchronization module is set in each intelligent power distribution device. The clock synchronization module calculates the transmission delay based on the timestamp information of the power line carrier signal, and uses the least - squares method to fit the delay data sampled multiple times to generate a clock deviation compensation parameter to achieve accurate time alignment of the intelligent power distribution device.

[0014] Establish a device information database for the intelligent power distribution device with a three - layer architecture including a physical layer, a topology layer, and a service layer. The corresponding relationship between the device identification information and the power distribution network topology structure stored in the device information database includes:

[0015] The physical layer stores the device unique identification code, device model, production date, and hardware version number. The topology layer stores the spatial location information of the intelligent power distribution device in the power distribution network. The service layer stores device operation parameters and communication status;

[0016] Obtain the device unique identification code from the physical layer, establish a device identity mapping table based on the device unique identification code, and write the device identity mapping table into the service layer;

[0017] Acquire spatial location information of the intelligent power distribution device in the power distribution network from the topology layer, generate a device connection relationship matrix based on graph theory, and the matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices;

[0018] A topological distance matrix between devices is calculated according to the device connection relationship matrix, the distance values ​​in the topological distance matrix are obtained by the minimum distance of the physical paths between devices, and the topological distance matrix is ​​stored in the topological layer.

[0019] Sending an identity authentication request to the intelligent power distribution device, the identity authentication request including verification code information randomly generated by a key exchange algorithm; receiving verification response information returned by the intelligent power distribution device based on the verification code information includes:

[0020] Query the device identity mapping table according to the unique identification code of the device to obtain the communication level information and authorization level information of the intelligent power distribution device; determine the generation range of the master station random number according to the communication level information, and the generation range of the master station random number is positively correlated with the communication level information;

[0021] Generate the master station random number, and send the master station random number to the intelligent power distribution device through the power line carrier channel, and receive the device random number returned by the intelligent power distribution device; select the primitive root value corresponding to the authorization level information, and recursively calculate the primitive root value with the master station random number and the device random number to generate a random verification code;

[0022] Obtaining a device certificate identifier corresponding to the device unique identification code from a certificate management system, and verifying the validity of the device certificate identifier;

[0023] Obtain the timestamp of the current system, and generate mixed authentication information according to a preset combination rule by combining the device certificate identifier, the random verification code and the timestamp; send the mixed authentication information to the intelligent power distribution device, and wait for the intelligent power distribution device to return verification response information.

[0024] Construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, and select a verification node set corresponding to the area of ​​the smart power distribution equipment in the verification sub-chain network, including:

[0025] Construct a multi-level blockchain network architecture, which includes a main chain layer network and a verification sub-chain network. The main chain layer network adopts a directed acyclic graph structure, and the verification sub-chain network corresponds to different regional organizations;

[0026] According to the device type code and the area identification code of the intelligent power distribution device, determining the belonging area and the device type of the intelligent power distribution device in the verification subchain network;

[0027] Based on the attribution area of the intelligent power distribution device, select a set of verification nodes in the corresponding area in the verification sub-chain network, and calculate the communication delay, link reliability index, and node computing power evaluation value among the nodes in the set of verification nodes;

[0028] According to the communication delay, the link reliability index, and the node computing power evaluation value, calculate the edge weight matrix among the nodes in the set of verification nodes, and determine the connection relationship between the verification nodes based on the edge weight matrix.

[0029] Generate a consensus permission matrix for the verification sub-chain network based on the connection relationship between the verification nodes. Determining the node credibility corresponding to the intelligent power distribution device according to the consensus permission matrix includes:

[0030] Generate a consensus permission matrix for the verification sub-chain network based on the connection relationship between the verification nodes. The consensus permission matrix is used to represent the verification permission relationship between the nodes in the verification sub-chain network, and store the consensus permission matrix in the verification sub-chain network;

[0031] According to the timestamp encoding of the intelligent power distribution device, perform consensus verification on the nodes in the set of verification nodes, and count the number of successful consensus times, verification response time, and total number of interactions among the nodes;

[0032] Calculate the node credibility of each node in the set of verification nodes based on the number of successful consensus times, the verification response time, and the total number of interactions, and write the node credibility into the main chain layer network;

[0033] When the node credibility meets the preset verification trigger threshold, trigger the intelligent contract to execute device identity authentication, and return the authentication result to the main chain layer network through the verification sub-chain network.

[0034] Judge whether the identity authentication of the intelligent power distribution device passes according to the verification result of the verification response information and the node credibility, and in the case of successful identity authentication, allocate communication time slots to the intelligent power distribution device, and establish a secure communication link between the intelligent power distribution device and the power distribution automation master station, including:

[0035] Perform weighted processing on the verification result according to the node credibility, and calculate the verification result consistency coefficient; when the consistency coefficient is greater than the preset consistency threshold, it is determined that the identity authentication of the intelligent power distribution device passes;

[0036] Obtain the total available time slots of the communication link, calculate the current time slot occupancy rate, and dynamically adjust the pre-obtained communication time slot demand according to the time slot occupancy rate to obtain the actual allocated number of communication time slots;

[0037] Allocate communication time slots to the intelligent power distribution device and establish a secure communication link between the intelligent power distribution device and the main station of distribution automation.

[0038] In a second aspect of the embodiments of the present invention, there is provided a remote identification system for intelligent power distribution devices based on power line communication, including:

[0039] A first unit configured to receive device identification information sent by an intelligent power distribution device through power line carrier communication, where the device identification information includes device type information, device number information, and device installation location information;

[0040] A second unit configured to establish a device information database for the intelligent power distribution device including three-layer architectures of a physical layer, a topology layer, and a service layer, where a correspondence between the device identification information and the distribution network topology structure is stored in the device information database; send an identity verification request to the intelligent power distribution device, where the identity verification request includes verification code information randomly generated through a key exchange algorithm; and receive a verification response information returned by the intelligent power distribution device based on the verification code information;

[0041] A third unit configured to construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a set of verification nodes corresponding to the area of the intelligent power distribution device in the verification sub-chain network, generate a consensus permission matrix for the verification sub-chain network based on the connection relationships between the verification nodes, and determine the node credibility corresponding to the intelligent power distribution device according to the consensus permission matrix;

[0042] A fourth unit configured to determine whether the identity verification of the intelligent power distribution device passes according to the verification result of the verification response information and the node credibility, and allocate communication time slots to the intelligent power distribution device and establish a secure communication link between the intelligent power distribution device and the main station of distribution automation when the identity verification passes.

[0043] In a third aspect of the embodiments of the present invention,

[0044] There is provided an electronic device, including:

[0045] A processor;

[0046] A memory for storing instructions executable by the processor;

[0047] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.

[0048] In a fourth aspect of the embodiments of the present invention,

[0049] Provided is a computer-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the foregoing method is implemented.

[0050] The beneficial effects of this application are as follows:

[0051] The method for remotely identifying intelligent power distribution equipment based on power line communication provided by the present invention realizes the rapid identification and accurate positioning of intelligent power distribution equipment by receiving the device identification information sent by the intelligent power distribution equipment through power line carrier communication, and establishing a device information database with a three-layer architecture, improving the efficiency and accuracy of distribution network management.

[0052] The present invention constructs a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, determines the device node credibility through a verification node set and a consensus permission matrix, and establishes a complete set of identity verification mechanisms, effectively preventing illegal device access and malicious attacks, and enhancing the security and reliability of the distribution network.

[0053] When the identity verification is passed, the present invention allocates communication time slots for the intelligent power distribution equipment and establishes a secure communication link, which not only optimizes the allocation efficiency of communication resources, but also realizes the safe and stable operation of the distribution automation system, providing technical support for the development of the smart grid. Description of the Drawings

[0054] Figure 1 It is a schematic flow chart of the method for remotely identifying intelligent power distribution equipment based on power line communication according to an embodiment of the present invention;

[0055] Figure 2 It is a schematic diagram of the three-layer architecture system and identity verification process of the intelligent power distribution equipment;

[0056] Figure 3 It is a schematic diagram for comparing the verification success rates of the present solution and the prior art under different communication levels;

[0057] Figure 4 It is a schematic diagram of the interface of the intelligent power distribution equipment verification management system. Detailed Embodiments

[0058] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0059] The technical solution of the present invention will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0060] Figure 1 It is a schematic flowchart of a method for remotely identifying an intelligent power distribution device based on power line communication according to an embodiment of the present invention. As Figure 1 shown, the method includes:

[0061] Receiving device identification information sent by the intelligent power distribution device through power line carrier communication, where the device identification information includes device type information, device number information, and device installation location information;

[0062] Establishing a device information database of the intelligent power distribution device including three-layer architectures of a physical layer, a topology layer, and a service layer, where the corresponding relationship between the device identification information and the distribution network topology structure is stored in the device information database; sending an identity verification request to the intelligent power distribution device, where the identity verification request includes verification code information randomly generated through a key exchange algorithm; receiving a verification response information returned by the intelligent power distribution device based on the verification code information;

[0063] Constructing a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, selecting a set of verification nodes corresponding to the area of the intelligent power distribution device in the verification sub-chain network, generating a consensus permission matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determining the node credibility corresponding to the intelligent power distribution device according to the consensus permission matrix;

[0064] Judging whether the identity verification of the intelligent power distribution device passes according to the verification result of the verification response information and the node credibility, and in the case of successful identity verification, allocating a communication time slot to the intelligent power distribution device and establishing a secure communication link between the intelligent power distribution device and the distribution automation master station.

[0065] In an alternative embodiment, the method further includes:

[0066] Performing network time synchronization on the intelligent power distribution device by using a distributed time synchronization protocol. Among them, a clock synchronization module is set in each intelligent power distribution device, and the clock synchronization module calculates the transmission delay based on the timestamp information of the power line carrier signal, and uses the least squares method to fit the delay data sampled multiple times to generate a clock deviation compensation parameter to achieve accurate time alignment of the intelligent power distribution device.

[0067] In an intelligent power distribution network, each intelligent power distribution device is equipped with a clock synchronization module, which is responsible for achieving precise time synchronization between devices. The clock synchronization module includes a timestamp extraction unit, a delay calculation unit, a data sampling unit, a least squares fitting unit, and a clock compensation unit.

[0068] In the network, an intelligent power distribution device with a high-precision clock is selected as the master node, and the remaining devices are used as slave nodes. The master node regularly broadcasts synchronization messages to the slave nodes through the power line carrier communication network. The synchronization message contains the current timestamp T1 of the master node.

[0069] When a slave node receives the synchronization message sent by the master node, the timestamp extraction unit of the slave node records the local timestamp T2 at the receiving moment. Subsequently, the slave node sends a response message to the master node, and the response message contains the timestamp T2 when the slave node receives the synchronization message and the timestamp T3 when the response message is sent.

[0070] When the master node receives the response message from the slave node, it records the local timestamp T4 at the receiving moment. At this time, the master node has obtained four complete timestamps: T1, T2, T3, and T4.

[0071] The delay calculation unit calculates the network transmission delay based on these four timestamps. Specifically, the transmission delay from the master node to the slave node can be calculated as follows: the difference between the timestamp T1 when the master node sends the synchronization message and the timestamp T2 when the slave node receives the synchronization message, minus the clock deviation between the master and slave nodes. Similarly, the transmission delay from the slave node to the master node can be calculated as the difference between the timestamp T3 when the slave node sends the response message and the timestamp T4 when the master node receives the response message, minus the clock deviation between the master and slave nodes.

[0072] Assuming that the network transmission delay is symmetric in a short period of time, that is, the transmission delay from the master node to the slave node is equal to the transmission delay from the slave node to the master node, the clock deviation between the master and slave nodes can be estimated as follows: [(T2 - T1) - (T4 - T3)] / 2. The transmission delay can be estimated as: [(T2 - T1) + (T4 - T3)] / 2.

[0073] To improve the accuracy of clock synchronization, the data sampling unit repeats the above process multiple times within a certain time window (e.g., 10 minutes) to collect multiple sets of timestamp data. In practical applications, sampling can be performed every 30 seconds, and a total of 20 sets of data can be collected within a 10-minute time window.

[0074] The least squares fitting unit processes multiple groups of collected data and fits the changing trend of the clock deviation through the least squares method. Specifically, taking the sampling time points as independent variables and the estimated clock deviations as dependent variables, a linear regression model is established. The slope and intercept of the regression line are calculated through the least squares method, where the slope represents the clock frequency deviation (clock drift rate), and the intercept represents the initial clock deviation.

[0075] For example, assume that within a 10-minute sampling window, 20 groups of data are collected in total, and the calculated clock deviations are: 1.2ms, 1.3ms, 1.5ms, 1.6ms, 1.8ms, 1.9ms, 2.1ms, 2.2ms, 2.4ms, 2.5ms, 2.7ms, 2.8ms, 3.0ms, 3.1ms, 3.3ms, 3.4ms, 3.6ms, 3.7ms, 3.9ms, 4.0ms. Through least squares fitting, the clock drift rate can be obtained as 0.15ms / minute, and the initial clock deviation is 1.1ms.

[0076] The clock compensation unit generates clock deviation compensation parameters based on the fitted clock drift rate and initial clock deviation. The slave node uses these parameters to adjust the local clock to achieve time synchronization with the master node. Specifically, the slave node can adjust the clock in one of the following two ways:

[0077] One way is to directly adjust the time value of the local clock to make it consistent with the master node's time. For example, if it is calculated that the current slave node's clock is 3.5ms slower than the master node's clock, the slave node's clock is directly adjusted forward by 3.5ms.

[0078] Another way is to adjust the frequency of the local clock to make it consistent with the master node's clock frequency, thereby eliminating clock drift. For example, if it is calculated that the slave node's clock drift rate is 0.15ms / minute, the slave node's clock frequency can be adjusted accordingly to increase the compensation by 0.15ms per minute.

[0079] In practical applications, the above two methods are usually combined for clock adjustment. First, a direct adjustment of the time value is performed to immediately synchronize the slave node's clock with the master node; then, the clock frequency is adjusted according to the calculated clock drift rate to maintain a long-term synchronization state.

[0080] To cope with changes in clock characteristics caused by factors such as network environment changes and equipment aging, the system will periodically re-execute the above synchronization process to update the clock deviation compensation parameters. Under normal operating conditions, a complete synchronization process can be performed once an hour; when the network status is poor or it is detected that the clock deviation exceeds a preset threshold (such as 5ms), an immediate synchronization can be triggered.

[0081] Through the above method, all devices in the intelligent distribution network can achieve precise time synchronization, and the time synchronization accuracy can reach the millisecond level (the typical value is 1 - 3 ms). This high-precision time synchronization provides important support for functions such as fault location, protection coordination, and status monitoring in the intelligent distribution network.

[0082] In actual deployment, this method has been applied in the intelligent distribution network of a provincial power grid company, involving more than 500 intelligent distribution devices. The test results show that after adopting this method, the time synchronization accuracy of the devices in the network has been improved from the original 10 - 15 ms to 1 - 3 ms, greatly improving the operation efficiency and reliability of the distribution network.

[0083] In an optional implementation manner, an equipment information database of the intelligent distribution device with a three-layer architecture including a physical layer, a topology layer, and a service layer is established. The corresponding relationship between the device identification information and the distribution network topology structure stored in the equipment information database includes:

[0084] The physical layer stores the device unique identification code, device model, production date, and hardware version number. The topology layer stores the spatial location information of the intelligent distribution device in the distribution network. The service layer stores the device operation parameters and communication status;

[0085] Obtain the device unique identification code from the physical layer, establish a device identity mapping table based on the device unique identification code, and write the device identity mapping table into the service layer;

[0086] Obtain the spatial location information of the intelligent distribution device in the distribution network from the topology layer, generate a device connection relationship matrix based on graph theory, and the matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices;

[0087] Calculate the topological distance matrix between devices according to the device connection relationship matrix. The distance value in the topological distance matrix is obtained through the minimum distance of the physical path between devices, and store the topological distance matrix in the topology layer.

[0088] Establish an equipment information database of intelligent distribution devices with a three-layer architecture including a physical layer, a topology layer, and a service layer. The corresponding relationship between the device identification information and the distribution network topology structure is stored in this database.

[0089] Figure 2It is a schematic diagram of the three-layer architecture system and identity authentication process of intelligent power distribution equipment. Among them, the physical layer mainly stores the basic hardware information of the equipment, including the unique device identification code, device model, production date, and hardware version number. For example, the physical layer information of a certain intelligent power distribution equipment can be expressed as: unique device identification code "PD2023120001", device model "SPD-X200", production date "2023-05-15", hardware version number "V2.3". The physical layer information is usually written into the non-volatile memory of the equipment when it leaves the factory to ensure that the equipment can be uniquely identified throughout its life cycle.

[0090] The topology layer stores the spatial location information of the intelligent power distribution equipment in the power distribution network. The spatial location information includes the geographical coordinates of the equipment, the substation it belongs to, the distribution line section it is located in, etc. For example, the topology layer information of a certain intelligent power distribution equipment can be expressed as: geographical coordinates "30.5432°N, 114.3456°E", substation it belongs to "Yangtze River Substation", distribution line section it is located in "Yangtze River Line - Section 3". The topology layer information is crucial for understanding the position and connection relationship of the equipment in the entire power distribution network.

[0091] The service layer stores the device operation parameters and communication status. The operation parameters include electrical parameters such as voltage, current, power factor, active power, and reactive power, and the communication status includes communication protocol type, communication quality index, last communication time, etc. For example, the service layer information of a certain intelligent power distribution equipment can be expressed as: voltage "10.5kV", current "120A", power factor "0.92", communication protocol "IEC61850", communication quality "good", last communication time "2023-12-01 14:30:25".

[0092] Next, obtain the unique device identification code from the physical layer, establish a device identity mapping table based on the unique device identification code, and write the device identity mapping table into the service layer. The device identity mapping table is a data structure that maps the unique device identification code to the identifier of the device in the business system. For example, the unique device identification code "PD2023120001" may be mapped to "Switch No. 3 of Yangtze River Substation" in the business system. This mapping relationship enables the business system to accurately identify and operate specific physical devices.

[0093] The structure of the device identity mapping table can be designed to include the following fields: unique device identification code, business system identifier, device type code, installation location code, management department code, etc. For example:

[0094] The device unique identification code is "PD2023120001", the business system identification is "CJBD-SW003", the device type code is "SW" (indicating switch), the installation location code is "CJBD-L3" (indicating Line 3 of Changjiang Substation), and the management department code is "OM-EAST" (indicating the East Region Operation and Maintenance Department).

[0095] Obtain the spatial location information of intelligent power distribution devices in the distribution network from the topology layer, and generate a device connection relationship matrix based on graph theory. The matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices. In actual implementation, an adjacency matrix can be used to represent the connection relationship between devices. The element value in the matrix is 1 indicating that the two devices are directly connected, and 0 indicating that they are not directly connected.

[0096] For example, assume there are 5 intelligent power distribution devices (numbered 1 to 5), and their connection relationships are as follows: Device 1 is connected to Device 2 and Device 3; Device 2 is connected to Device 1 and Device 4; Device 3 is connected to Device 1 and Device 5; Device 4 is connected to Device 2 and Device 5; Device 5 is connected to Device 3 and Device 4. Then the device connection relationship matrix can be expressed as:

[0097] The connection relationship between Device 1 and Device 1 is 0, the connection relationship between Device 1 and Device 2 is 1, the connection relationship between Device 1 and Device 3 is 1, the connection relationship between Device 1 and Device 4 is 0, and the connection relationship between Device 1 and Device 5 is 0;

[0098] The connection relationship between Device 2 and Device 1 is 1, the connection relationship between Device 2 and Device 2 is 0, the connection relationship between Device 2 and Device 3 is 0, the connection relationship between Device 2 and Device 4 is 1, and the connection relationship between Device 2 and Device 5 is 0;

[0099] The connection relationship between Device 3 and Device 1 is 1, the connection relationship between Device 3 and Device 2 is 0, the connection relationship between Device 3 and Device 3 is 0, the connection relationship between Device 3 and Device 4 is 0, and the connection relationship between Device 3 and Device 5 is 1;

[0100] The connection relationship between Device 4 and Device 1 is 0, the connection relationship between Device 4 and Device 2 is 1, the connection relationship between Device 4 and Device 3 is 0, the connection relationship between Device 4 and Device 4 is 0, and the connection relationship between Device 4 and Device 5 is 1;

[0101] The connection relationship between Device 5 and Device 1 is 0, the connection relationship between Device 5 and Device 2 is 0, the connection relationship between Device 5 and Device 3 is 1, the connection relationship between Device 5 and Device 4 is 1, and the connection relationship between Device 5 and Device 5 is 0.

[0102] Calculate the topological distance matrix between devices according to the device connection relationship matrix. The distance values in the topological distance matrix are obtained through the minimum distance of the physical paths between devices. In graph theory, the shortest path between two nodes can be calculated through breadth-first search or Dijkstra's algorithm, etc. For the connection relationships of the above 5 devices, the calculated topological distance matrix is as follows:

[0103] The distance from device 1 to device 1 is 0, the distance from device 1 to device 2 is 1, the distance from device 1 to device 3 is 1, the distance from device 1 to device 4 is 2, and the distance from device 1 to device 5 is 2;

[0104] The distance from device 2 to device 1 is 1, the distance from device 2 to device 2 is 0, the distance from device 2 to device 3 is 2, the distance from device 2 to device 4 is 1, and the distance from device 2 to device 5 is 2;

[0105] The distance from device 3 to device 1 is 1, the distance from device 3 to device 2 is 2, the distance from device 3 to device 3 is 0, the distance from device 3 to device 4 is 2, and the distance from device 3 to device 5 is 1;

[0106] The distance from device 4 to device 1 is 2, the distance from device 4 to device 2 is 1, the distance from device 4 to device 3 is 2, the distance from device 4 to device 4 is 0, and the distance from device 4 to device 5 is 1;

[0107] The distance from device 5 to device 1 is 2, the distance from device 5 to device 2 is 2, the distance from device 5 to device 3 is 1, the distance from device 5 to device 4 is 1, and the distance from device 5 to device 5 is 0.

[0108] Store the calculated topological distance matrix in the topology layer. After the topological distance matrix is stored, it can be used in various application scenarios such as distribution network analysis, fault location, and network optimization. For example, when a certain device fails, other devices that may be affected can be quickly determined according to the topological distance matrix; when the network is renovated, the impact of the renovation on the network topology structure can be evaluated.

[0109] The three-layer architecture device information database established by the above method not only realizes the comprehensive management of intelligent distribution equipment, but also provides a data basis for the intelligent operation and maintenance of the distribution network through the quantitative representation of topological relationships. This method is applicable to various types of intelligent distribution equipment, including but not limited to intelligent switches, intelligent transformers, intelligent metering equipment, etc., and has broad application prospects.

[0110] In an optional implementation manner, send an identity verification request to the intelligent distribution device, where the identity verification request includes verification code information randomly generated through a key exchange algorithm; the received verification response information returned by the intelligent distribution device based on the verification code information includes:

[0111] Query the device identity mapping table according to the device unique identification code to obtain the communication level information and authorization level information of the intelligent power distribution device; determine the generation range of the master station random number according to the communication level information, and the generation range of the master station random number is positively correlated with the communication level information;

[0112] Generate the master station random number, and send the master station random number to the intelligent power distribution device through the power line carrier channel, and receive the device random number returned by the intelligent power distribution device; select the primitive root value corresponding to the authorization level information, and perform recursive operations on the primitive root value, the master station random number and the device random number to generate a random verification code;

[0113] Obtain the device certificate identifier corresponding to the device unique identification code from the certificate management system, and verify the validity of the device certificate identifier;

[0114] Obtain the time stamp of the current system, and generate mixed authentication information by combining the device certificate identifier, the random verification code and the time stamp according to a preset combination rule; send the mixed authentication information to the intelligent power distribution device, and wait for the intelligent power distribution device to return verification response information.

[0115] Send an identity verification request to the intelligent power distribution device, and the request includes verification code information randomly generated by the key exchange algorithm. In practical applications, the Diffie-Hellman key exchange algorithm can be used to generate the initial verification code. For example, the system can randomly select a large prime number P (such as P = 997) and a primitive root g (such as g = 7), then generate a random private key a (such as a = 365), calculate the public key A = g^a mod P (that is, 7^365 mod 997), and send P, g and A as components of the verification code information to the intelligent power distribution device.

[0116] After receiving the verification request, the system queries the device identity mapping table according to the device unique identification code to obtain the communication level information and authorization level information of the intelligent power distribution device. The device unique identification code can be a 24-bit alphanumeric combination, such as "PD2023XYZ789012345ABCDE". The device identity mapping table is a pre-established database table, which contains fields: device unique identification code, communication level information, authorization level information, etc. The communication level information can be divided into high level (value is 3), middle level (value is 2) and low level (value is 1); the authorization level information can be divided into administrator level (value is 5), operator level (value is 3) and visitor level (value is 1).

[0117] Determine the generation range of the master station random number according to the obtained communication level information. The generation range of the master station random number is positively correlated with the communication level information, that is, the higher the communication level, the larger the generation range of the random number, thus improving security. The specific implementation can adopt the following corresponding relationship: the high level (value is 3) corresponds to the random number range of [10000 - 99999], the middle level (value is 2) corresponds to the random number range of [1000 - 9999], and the low level (value is 1) corresponds to the random number range of [100 - 999]. For example, if the device communication level is the high level (value is 3), the generation range of the master station random number is 10000 - 99999.

[0118] The system generates the master station random number and sends the master station random number to the intelligent power distribution device through the power line carrier channel. The power line carrier communication adopts OFDM modulation technology, with a working frequency range of 10kHz - 500kHz and a data transmission rate of up to 200kbps. For example, if the device communication level is the high level, the system may generate the master station random number 85421 and send this value through the power line carrier channel.

[0119] The system receives the device random number returned by the intelligent power distribution device. The device random number is generated by the intelligent power distribution device according to its internal algorithm. For example, the device may return the device random number 67890.

[0120] The system selects the primitive root value corresponding to the authorization level information. Different authorization levels correspond to different primitive root values to enhance security. For example, the administrator level (value is 5) corresponds to the primitive root value 17, the operator level (value is 3) corresponds to the primitive root value 13, and the visitor level (value is 1) corresponds to the primitive root value 11. If the device authorization level is the operator level, the primitive root value 13 is selected.

[0121] The system performs a recursive operation on the primitive root value, the master station random number, and the device random number to generate a random verification code. The recursive operation process is as follows: First, multiply the primitive root value by the master station random number, and then take the modulus 100000 of the result to obtain an intermediate value; then add the intermediate value to the device random number, and take the modulus 100000 of the result again to obtain the random verification code. Taking the above values as an example, multiplying the primitive root value 13 by the master station random number 85421 gives 1110473, taking the modulus 100000 gives 10473; adding 10473 to the device random number 67890 gives 78363, which is the final random verification code.

[0122] The system obtains the device certificate identifier corresponding to the unique device identifier from the certificate management system and verifies the validity of the device certificate identifier. The device certificate identifier is a 32-bit hexadecimal string, such as "8A7B6C5D4E3F2G1H0I9J8K7L6M5N4O3P". The certificate validity check includes checking whether the certificate has expired, whether it has been revoked, etc. The system queries the certificate status through OCSP (Online Certificate Status Protocol). If the certificate is valid, it continues with the subsequent steps; otherwise, it terminates the verification process and records the exception.

[0123] The system obtains the timestamp of the current system, accurate to the millisecond level, in the format of "YYYY-MM-DD HH:MM:SS.mmm", such as "2023-10-15 14:30:25.789".

[0124] The system generates mixed authentication information by combining the device certificate identifier, random verification code, and timestamp according to a preset combination rule. The combination rule can be: alternately arrange the first 16 bits of the device certificate identifier and the value obtained by converting the random verification code to hexadecimal, and then append the Unix timestamp value (in seconds) of the timestamp. For example, if the first 16 bits of the device certificate identifier are "8A7B6C5D4E3F2G1H", the random verification code 78363 converted to hexadecimal is "131FB", and the Unix timestamp of the timestamp "2023-10-15 14:30:25.789" is 1697378425, then the mixed authentication information may be "8A131FB7B6C5D4E3F2G1H1697378425".

[0125] The system sends the mixed authentication information to the intelligent power distribution device and waits for the intelligent power distribution device to return the verification response information. The mixed authentication information is sent through the power line carrier channel and uses the AES-256 encryption algorithm to ensure transmission security. After receiving the mixed authentication information, the intelligent power distribution device will perform parsing and verification and return the verification response information. The verification response information includes a verification result code and a timestamp. For example, "SUCCESS:1697378426.123" indicates successful verification, and the timestamp is "2023-10-15 14:30:26.123".

[0126] If the verification response information indicates successful verification, a secure communication channel is established; if the verification fails, corresponding measures are taken according to the reason for failure, such as reinitiating the verification request or recording the exception and issuing an alarm. The system also sets a verification timeout mechanism. If no verification response is received within the preset time (such as 5 seconds), it is regarded as a verification failure.

[0127] Figure 3 Schematic diagram for comparing the verification success rates of this solution and existing technologies under different communication levels, such as Figure 3As shown in the data, the verification success rate of "this scheme" in all communication levels (1-6) is higher than that of the other three methods, which are 87.5%, 89.8%, 91.4%, 93.2%, 93.8% and 94.5% respectively. In comparison, the verification success rate of "traditional password-based method" is 83.5%-89.1%; "simple random number method" is 77.3%-83.0%; "certificate-based method" is 74.8%-84.7%. As the communication level increases, the verification success rate of each method has increased, but "this scheme" has always maintained its leading advantage. The last column "performance improvement" shows that this scheme has improved the verification success rate by 4.8%-6.1% on average compared with other methods, among which the performance improvement is more significant at high-level communication (4-6 levels), reaching more than 6.0%.

[0128] This application automatically adjusts the range of random numbers generated by the master station according to the device communication level. The higher the communication level, the larger the range of random numbers, providing more flexible security protection. A multi-level authorization mechanism based on the original root value is introduced, and different authorization levels correspond to different original root values, which improves the refinement of authorization management. The device certificate identification, random verification code and timestamp are innovatively combined according to preset rules to form mixed authentication information, realizing multi-factor verification.

[0129] Through the above steps, the secure identity authentication of the intelligent power distribution equipment is realized, ensuring the security and reliability of the communication of the equipment in the power distribution network. This method combines a variety of cryptographic technologies and security mechanisms, which can effectively prevent unauthorized access and man-in-the-middle attacks.

[0130] In an optional implementation, a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network is constructed, and the verification node set corresponding to the area of ​​the smart power distribution device is selected in the verification sub-chain network, including:

[0131] Construct a multi-level blockchain network architecture, which includes a main chain layer network and a verification sub-chain network. The main chain layer network adopts a directed acyclic graph structure, and the verification sub-chain network corresponds to different regional organizations;

[0132] According to the device type code and the area identification code of the intelligent power distribution device, determining the belonging area and the device type of the intelligent power distribution device in the verification subchain network;

[0133] Based on the region to which the intelligent power distribution equipment belongs, a verification node set of the corresponding region is selected in the verification subchain network, and the communication delay, link reliability index and node computing capacity evaluation value between each node in the verification node set are calculated;

[0134] According to the communication delay, the link reliability index and the node computing capability evaluation value, an edge weight matrix between nodes in the verification node set is calculated, and the connection relationship between the verification nodes is determined based on the edge weight matrix.

[0135] The multi-level blockchain network architecture includes the main chain layer network and the verification sub-chain network. The main chain layer network adopts a directed acyclic graph structure, and the verification sub-chain network corresponds to different regional organizations. As the core layer of the entire system, the main chain layer network is responsible for storing key data and coordinating the operation of each verification sub-chain network. The nodes in the main chain layer network can be high-performance servers configured with Intel Xeon E5-2680 v4 processors, 128GB memory, 10TB storage space, and running a dedicated blockchain operating system. These nodes are interconnected through a high-speed fiber optic network with a bandwidth of no less than 10Gbps to ensure efficient data transmission. The directed acyclic graph structure of the main chain layer network allows parallel processing of transactions, which improves the system throughput and can process 5,000-8,000 transactions per second.

[0136] The verification subchain network is divided according to geographical location or administrative divisions. For example, the corresponding verification subchain network can be set up according to the three-level administrative divisions of province, city, and county. Each verification subchain network adopts the Byzantine fault-tolerant consensus mechanism, which tolerates no more than one-third of the nodes to fail or act maliciously. The nodes of the verification subchain network can be medium-performance servers configured with Intel Xeon E5-2650 processors, 64GB memory, and 5TB storage space.

[0137] According to the equipment type code and regional identification code of the smart distribution equipment, the region and equipment type of the smart distribution equipment are determined in the verification subchain network. The equipment type code uses an 8-bit string, the first 2 digits represent the equipment category (such as "TR" for transformers, "CB" for circuit breakers, and "SM" for smart meters), the middle 3 digits represent the equipment subcategory, and the last 3 digits represent the equipment model version. The regional identification code uses a 12-bit string, the first 4 digits represent the provincial administrative region code, the middle 4 digits represent the municipal administrative region code, and the last 4 digits represent the county administrative region code.

[0138] For example, a device coded as "TR001A01-330100330106" represents a transformer of type A01 and subclass 001 located in Xihu District, Hangzhou City, Zhejiang Province. The system parses the code to determine that the device type is a transformer and that the region it belongs to is Xihu District, Hangzhou City, Zhejiang Province. The system maintains a mapping table that maps the region identification code to the corresponding verification subchain network. In this example, the system queries the mapping table to determine that the device should belong to the "Zhejiang Province - Hangzhou City" verification subchain network.

[0139] Based on the attribution area of the intelligent power distribution equipment, select the verification node set corresponding to the area in the verification sub-chain network, and calculate the communication delay, link reliability index, and node computing power evaluation value among the nodes in the verification node set. The system first selects at least 7 and no more than 21 verification nodes from the verification sub-chain network of the corresponding area to form a verification node set. The selection criteria include comprehensive scores of indicators such as node online duration, historical verification accuracy rate, and computing resource occupancy rate.

[0140] For the calculation of communication delay, the system uses the ICMP protocol to send probe packets and measures the round-trip time (RTT) between nodes. The system makes a measurement every 30 minutes within 24 hours and takes the average value as the communication delay between nodes. For example, the average communication delay between node A and node B is 15ms, and the average communication delay between node A and node C is 25ms.

[0141] The link reliability index is calculated by continuously monitoring the communication success rate between nodes. The system sends 100 test data packets per hour within 7 days, records the number of successfully received data packets, and calculates the communication success rate. For example, the communication success rate between node A and node B is 99.2%, and the communication success rate between node A and node C is 97.8%.

[0142] The node computing power evaluation value is calculated based on hardware indicators such as the processor performance, memory capacity, storage read-write speed, and network bandwidth of the node, combined with the historical transaction processing speed. The system uses a standard test set to measure the average time for each node to process transactions and normalizes the results to a score of 0 - 100. For example, the computing power evaluation value of node A is 85, the computing power evaluation value of node B is 92, and the computing power evaluation value of node C is 78.

[0143] According to the communication delay, link reliability index, and node computing power evaluation value, calculate the edge weight matrix among the nodes in the verification node set, and determine the connection relationship between the verification nodes based on the edge weight matrix. The edge weight calculation comprehensively considers three factors: the reciprocal of the communication delay, the link reliability index, and the weighted sum of the node computing power evaluation value.

[0144] Specifically, for the edge weight between node i and node j, the system first normalizes the communication delay to a value between 0 and 1. The link reliability index is already a value between 0 and 1, and the node computing power evaluation value is divided by 100 to get a value between 0 and 1. Then, the system multiplies these three normalized values by the weight coefficients (the communication delay weight is 0.4, the link reliability weight is 0.35, and the node computing power weight is 0.25), and finally sums them up to get the edge weight.

[0145] For example, the edge weight calculation between node A and node B: The communication delay of 15 ms is standardized to 0.85, the link reliability is 0.992, the computing power is (85 + 92) / 2 / 100 = 0.885, and the final edge weight is 0.85×0.4 + 0.992×0.35 + 0.885×0.25 = 0.905.

[0146] Based on the calculated edge weight matrix, the system selects the edge with the highest weight to establish connections between nodes. The system sets the threshold to 0.8, and only node pairs with edge weights exceeding this threshold are connected. The finally formed verification node network topology ensures an efficient and reliable transaction verification process.

[0147] Through the above method, the system has successfully constructed a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, and selected a set of verification nodes corresponding to the intelligent power distribution equipment in the verification sub-chain network, providing strong blockchain infrastructure support for the safe and reliable operation of the intelligent power distribution equipment.

[0148] In an alternative implementation, generating a consensus permission matrix for the verification sub-chain network based on the connection relationships between the verification nodes, and determining the node reputation corresponding to the intelligent power distribution equipment according to the consensus permission matrix includes:

[0149] Generating a consensus permission matrix for the verification sub-chain network based on the connection relationships between the verification nodes, where the consensus permission matrix is used to represent the verification permission relationships between nodes in the verification sub-chain network, and storing the consensus permission matrix in the verification sub-chain network;

[0150] Performing consensus verification on the nodes in the verification node set according to the timestamp encoding of the intelligent power distribution equipment, and counting the number of successful consensus times, verification response times, and total interaction times between nodes;

[0151] Calculating the node reputation of each node in the verification node set based on the number of successful consensus times, the verification response times, and the total interaction times, and writing the node reputation into the main chain layer network;

[0152] When the node reputation meets the preset verification trigger threshold, trigger the intelligent contract to execute device identity authentication, and return the authentication result to the main chain layer network through the verification sub-chain network.

[0153] Figure 4It is a schematic diagram of the interface of the intelligent power distribution equipment verification management system. In actual applications, the verification node set may include multiple intelligent power distribution equipment nodes, such as intelligent transformers, intelligent switches, intelligent electricity meters, etc. The system constructs an n×n consensus permission matrix M by analyzing the physical connection relationships and logical interaction relationships among these nodes, where n is the number of verification nodes. The element M[i][j] in the matrix represents the verification permission value of node i for node j, and the value range is [0,1]. When M[i][j]=1, it means that node i has full verification permission for node j; when M[i][j]=0, it means that node i has no verification permission for node j; when 0<M[i][j]<1, it means that node i has partial verification permission for node j, and the size of the permission is determined by the specific value.

[0154] For example, in an intelligent power distribution network with 5 verification nodes, according to the physical connection relationships among the nodes, the following consensus permission matrix can be generated: 1.0 0.8 0.5 0.3 0.0; 0.8 1.0 0.7 0.4 0.2; 0.5 0.7 1.0 0.9 0.6; 0.3 0.4 0.9 1.0 0.8; 0.0 0.2 0.6 0.8 1.0;

[0160] This matrix shows that adjacent nodes have relatively high verification permissions, while nodes that are farther apart have lower verification permissions. The system stores this consensus permission matrix in the block of the verification sub-chain network as the basis for subsequent node reputation calculation.

[0161] Based on the timestamp encoding of the intelligent power distribution equipment, consensus verification is performed on the nodes in the verification node set. The timestamp encoding refers to the unique identifier assigned to each intelligent power distribution equipment, which contains the time information when the equipment joins the network and the equipment type information. The system triggers the consensus verification process among nodes based on the timestamp encoding according to a preset verification period (such as once every 10 minutes).

[0162] During the consensus verification process, the system will count the following three key indicators: the number of successful consensus times, the verification response time, and the total number of interactions. The number of successful consensus times refers to the number of times the node successfully completes the consensus verification; the verification response time refers to the time required for the node to respond to the verification request; the total number of interactions refers to the total number of times the node participates in the verification process.

[0163] For example, within a verification period, the interaction situation of node A with other nodes is as follows:

[0164] - Interact with node B 15 times, with 12 successful consensuses and an average response time of 200 milliseconds;

[0165] - Interact with node C 10 times, with 8 successful consensus and an average response time of 250 milliseconds;

[0166] - Interact with node D 8 times, with 5 successful consensus and an average response time of 300 milliseconds;

[0167] - Interact with node E 5 times, with 2 successful consensus and an average response time of 350 milliseconds;

[0168] Based on the above statistical data, the system calculates the node reputation of each node in the set of verification nodes. The calculation of node reputation comprehensively considers three factors: the consensus success rate, the average response time, and the interaction activity. The consensus success rate is equal to the number of successful consensus divided by the total number of interactions; the average response time is obtained by taking the average of all verification response times; the interaction activity is equal to the ratio of the total number of node interactions to the maximum number of interactions in the network.

[0169] For node A, its node reputation is calculated as follows:

[0170] - Consensus success rate = (12 + 8 + 5 + 2) / (15 + 10 + 8 + 5) = 27 / 38 ≈ 0.71;

[0171] - Average response time = (200×15 + 250×10 + 300×8 + 350×5) / 38 ≈ 253 milliseconds;

[0172] - Response time score = 1 - (253 / 500) = 0.494 (assuming the maximum allowable response time is 500 milliseconds);

[0173] - Interaction activity = 38 / 45 = 0.844 (assuming the maximum number of interactions in the network is 45);

[0174] Taking these three factors into account, the reputation of node A can be calculated as: 0.71×0.4 + 0.494×0.3 + 0.844×0.3 = 0.684 (assuming the weights of the three factors are 0.4, 0.3, and 0.3 respectively).

[0175] The system writes the calculated node reputation into the block of the main chain layer network as the basis for the identity authentication of intelligent power distribution equipment.

[0176] When the node reputation meets the preset verification trigger threshold, the system triggers the execution of the smart contract for device identity authentication. The preset verification trigger threshold is usually set to a value between 0.6 and 0.8, depending on the network security requirements. For example, when the threshold is set to 0.65, the reputation of node A, 0.684, exceeds the threshold, and the system will trigger the smart contract to perform identity authentication.

[0177] The identity authentication process includes the following steps: the system verifies the validity of the digital certificate of the node; checks whether the behavioral characteristics of the node are consistent with the historical records; and confirms whether the physical location information of the node meets the expectations. The authentication results include three statuses: "Pass", "Warning", and "Reject". For node A, assuming its digital certificate is valid, its behavioral characteristics are normal, and its physical location meets the expectations, the authentication result is "Pass".

[0178] The system returns the authentication result to the main chain layer network through the verification sub-chain network and updates the identity status of the node. For the nodes that pass the authentication, they are allowed to continue participating in network activities; for the nodes in the warning status, the system will increase the monitoring frequency for them; for the nodes in the reject status, the system will remove them from the list of trusted nodes and prevent them from participating in critical services.

[0179] Through the above method, this embodiment realizes the dynamic reputation evaluation and identity authentication of device nodes in the intelligent distribution network, effectively improving the security and reliability of the network.

[0180] In an alternative embodiment, based on the verification result of the verification response information and the node reputation, it is determined whether the identity authentication of the intelligent distribution device passes. In the case where the identity authentication passes, allocating communication time slots to the intelligent distribution device and establishing a secure communication link between the intelligent distribution device and the distribution automation master station includes:

[0181] Performing a weighted process on the verification result according to the node reputation to calculate the verification result consistency coefficient; when the consistency coefficient is greater than a preset consistency threshold, it is determined that the identity authentication of the intelligent distribution device passes;

[0182] Obtaining the total available time slots of the communication link, calculating the current time slot occupancy rate, and dynamically adjusting the pre-obtained communication time slot demand according to the time slot occupancy rate to obtain the actual allocated communication time slot quantity;

[0183] Allocating communication time slots to the intelligent distribution device and establishing a secure communication link between the intelligent distribution device and the distribution automation master station.

[0184] Performing a weighted process on the verification result according to the node reputation to calculate the verification result consistency coefficient. When the consistency coefficient is greater than a preset consistency threshold, it is determined that the identity authentication of the intelligent distribution device passes. Obtaining the total available time slots of the communication link, calculating the current time slot occupancy rate, and dynamically adjusting the pre-obtained communication time slot demand according to the time slot occupancy rate to obtain the actual allocated communication time slot quantity. Allocating communication time slots to the intelligent distribution device and establishing a secure communication link between the intelligent distribution device and the distribution automation master station.

[0185] In the specific implementation process, it is necessary to obtain the verification results of multiple verification nodes for the intelligent power distribution equipment. Each verification node verifies the identity verification request sent by the intelligent power distribution equipment based on different verification algorithms or verification strategies and generates a verification result. The verification result can be a binary result (pass / fail) or a multi-level scoring result (e.g., 0 - 100 points).

[0186] At the same time, the system will maintain a node credibility database, record indicators such as the historical verification accuracy rate, response time, and stability of each verification node, and comprehensively calculate the node credibility value. The range of the node credibility value is from 0 to 1, where 0 means completely untrustworthy and 1 means completely trustworthy.

[0187] When calculating the verification result consistency coefficient, the verification results of each verification node are weighted. Suppose there are n verification nodes, the verification result of the i-th verification node is Ri, and the node credibility is Ci, then the weighted verification result is Ri multiplied by Ci. Normalize all the weighted verification results to obtain the consistency coefficient.

[0188] For example, suppose there are 5 verification nodes, and their verification results are: pass, pass, fail, pass, pass, and the corresponding node credibilities are 0.9, 0.8, 0.5, 0.7, 0.85 respectively. Denote "pass" as 1 and "fail" as 0, then the weighted verification results are: 0.9, 0.8, 0, 0.7, 0.85. When calculating the consistency coefficient, sum the weighted results to get 3.25, and then divide by the sum of the node credibilities 3.75, and the obtained consistency coefficient is 0.867.

[0189] The preset consistency threshold can be set according to the system security requirements, for example, set to 0.8. In the above example, the consistency coefficient 0.867 is greater than the preset consistency threshold 0.8, so it is determined that the identity verification of the intelligent power distribution equipment passes.

[0190] Obtaining the total available time slots of the communication link is determined according to the current network bandwidth, communication protocol, and physical layer characteristics. For example, in a certain distribution automation system, each communication cycle contains 1000 time slots, and the duration of each time slot is 10 milliseconds.

[0191] Calculating the current time slot occupancy rate refers to the ratio of the number of allocated time slots to the total available time slots. For example, if 600 time slots have been allocated currently, then the time slot occupancy rate is 60%.

[0192] The method for dynamically adjusting the communication time slot demand according to the time slot occupancy rate is as follows: When the intelligent power distribution device requests a connection, it will provide its expected communication time slot demand, such as 50 time slots. The system calculates the actual allocated communication time slot quantity according to the current time slot occupancy rate using a dynamic adjustment strategy.

[0193] When the time slot occupancy rate is low (e.g., less than 30%), all the device's demands can be met, that is, 50 time slots are allocated; when the time slot occupancy rate is at a medium level (e.g., 30% - 70%), the time slots are allocated in a linearly decreasing manner. For example, when the occupancy rate is 60%, the number of allocated time slots is 50 multiplied by (1 - (60% - 30%) / (70% - 30%)), that is, 50 multiplied by 0.25, resulting in 37 time slots; when the time slot occupancy rate is high (e.g., greater than 70%), the minimum guaranteed number of time slots is allocated, such as 10 time slots.

[0194] After determining the actual allocated communication time slot quantity, the system sends the time slot allocation information to the intelligent power distribution device, including the starting time slot number, the allocated number of time slots, the time slot usage validity period, etc. After receiving the time slot allocation information, the intelligent power distribution device communicates according to the specified time slots, thereby establishing a secure communication link with the main station of the distribution automation system.

[0195] To improve communication efficiency and security, the system also regularly evaluates the quality of the communication link, including indicators such as signal strength, bit error rate, and time delay. If it is found that the communication quality has declined, the time slot reallocation mechanism will be triggered to adjust the allocated number or position of the time slots.

[0196] In addition, the system also monitors the communication behavior of the intelligent power distribution device. If abnormal behaviors are found (such as communicating outside the allocated time slot range, sending malicious data packets, etc.), the credit score of the device will be reduced. In serious cases, the communication link will be interrupted, and the device will be added to the blacklist.

[0197] Through the above method, reliable authentication of intelligent power distribution devices and establishment of an efficient and secure communication link can be achieved, improving the security and stability of the distribution automation system. This method is applicable to various intelligent power distribution network environments, especially having significant advantages in scenarios with limited resources and high security requirements.

[0198] The intelligent power distribution device remote identification system based on power line communication in the embodiment of the present invention includes:

[0199] A first unit for receiving the device identification information sent by the intelligent power distribution device through power line carrier communication, where the device identification information includes device type information, device number information, and device installation location information;

[0200] The second unit is used to establish a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer, and a service layer. The corresponding relationship between the device identification information and the power distribution network topology structure is stored in the device information database; an identity authentication request is sent to the intelligent power distribution device, and the identity authentication request includes verification code information randomly generated by a key exchange algorithm; the verification response information returned by the intelligent power distribution device based on the verification code information is received;

[0201] The third unit is used to construct a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network. A set of verification nodes corresponding to the area of the intelligent power distribution device is selected in the verification sub-chain network, a consensus permission matrix of the verification sub-chain network is generated based on the connection relationship between the verification nodes, and the node credibility corresponding to the intelligent power distribution device is determined according to the consensus permission matrix;

[0202] The fourth unit is used to determine whether the identity authentication of the intelligent power distribution device passes according to the verification result of the verification response information and the node credibility, and allocate communication time slots to the intelligent power distribution device and establish a secure communication link between the intelligent power distribution device and the power distribution automation master station when the identity authentication passes.

[0203] In the third aspect of the embodiments of the present invention,

[0204] A kind of electronic device is provided, including:

[0205] A processor;

[0206] A memory for storing instructions executable by the processor;

[0207] Wherein, the processor is configured to call the instructions stored in the memory to execute the method described above.

[0208] In the fourth aspect of the embodiments of the present invention,

[0209] A computer-readable storage medium is provided, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method described above is implemented.

[0210] The present invention can be a method, a device, a system and / or a computer program product. The computer program product can include a computer-readable storage medium, on which computer-readable program instructions for executing various aspects of the present invention are uploaded.

[0211] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A remote identification method for intelligent power distribution equipment based on power line communication, characterized in that: include: Receiving device identification information sent by the intelligent power distribution device through power line carrier communication, the device identification information includes device type information, device number information and device installation location information; Establishing a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topology layer, and a business layer, wherein the corresponding relationship between the device identification information and the topology structure of the distribution network is stored in the device information database, including: Acquire the unique device identification code from the physical layer, establish a device identity mapping table based on the unique device identification code, and write the device identity mapping table into the service layer; Acquire spatial location information of the intelligent power distribution device in the power distribution network from the topology layer, generate a device connection relationship matrix based on graph theory, and the matrix elements in the device connection relationship matrix are used to represent the direct connection relationship between devices; Calculate a topological distance matrix between devices according to the device connection relationship matrix, wherein the distance values ​​in the topological distance matrix are obtained by the minimum distance of the physical paths between the devices, and store the topological distance matrix in the topological layer; Sending an identity authentication request to the intelligent power distribution device, the identity authentication request including verification code information randomly generated by a key exchange algorithm; receiving verification response information returned by the intelligent power distribution device based on the verification code information includes: Query the device identity mapping table according to the unique identification code of the device to obtain the communication level information and authorization level information of the intelligent power distribution device; determine the generation range of the master station random number according to the communication level information, and the generation range of the master station random number is positively correlated with the communication level information; Generate the master station random number, and send the master station random number to the intelligent power distribution device through the power line carrier channel, and receive the device random number returned by the intelligent power distribution device; select the primitive root value corresponding to the authorization level information, and recursively calculate the primitive root value with the master station random number and the device random number to generate a random verification code; Obtaining a device certificate identifier corresponding to the device unique identification code from a certificate management system, and verifying the validity of the device certificate identifier; Obtain the timestamp of the current system, and generate mixed authentication information according to a preset combination rule by combining the device certificate identifier, the random verification code and the timestamp; send the mixed authentication information to the intelligent power distribution device, and wait for the intelligent power distribution device to return verification response information; Constructing a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, selecting a verification node set in the verification sub-chain network corresponding to the intelligent power distribution device, generating a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determining the node reputation corresponding to the intelligent power distribution device according to the consensus authority matrix includes: According to the device type code and the area identification code of the intelligent power distribution device, determining the belonging area and the device type of the intelligent power distribution device in the verification subchain network; Based on the region to which the intelligent power distribution equipment belongs, a verification node set of the corresponding region is selected in the verification subchain network, and the communication delay, link reliability index and node computing capacity evaluation value between each node in the verification node set are calculated; Calculate an edge weight matrix between nodes in the verification node set according to the communication delay, the link reliability index and the node computing capability evaluation value, and determine a connection relationship between the verification nodes based on the edge weight matrix; Generate a consensus authority matrix of the verification subchain network based on the connection relationship between the verification nodes, the consensus authority matrix is ​​used to characterize the verification authority relationship between nodes in the verification subchain network, and store the consensus authority matrix in the verification subchain network; According to the timestamp code of the intelligent power distribution device, consensus verification is performed on the nodes in the verification node set, and the number of successful consensuses, verification response time and total number of interactions between nodes are counted; Calculate the node reputation of each node in the verification node set based on the number of consensus successes, the verification response time, and the total number of interactions; According to the verification result of the verification response information and the node reputation, judging whether the identity authentication of the intelligent power distribution device is passed, and if the identity authentication is passed, allocating a communication time slot to the intelligent power distribution device, and establishing a secure communication link between the intelligent power distribution device and the distribution automation master station includes: The verification result is weighted according to the node reputation, and a consistency coefficient of the verification result is calculated; when the consistency coefficient is greater than a preset consistency threshold, it is determined that the identity authentication of the intelligent power distribution device is passed; Obtaining the total amount of available time slots of the communication link, calculating the current time slot occupancy rate, and dynamically adjusting the pre-acquired communication time slot demand according to the time slot occupancy rate to obtain the actual number of allocated communication time slots; A communication time slot is allocated to the intelligent power distribution device, and a secure communication link is established between the intelligent power distribution device and a distribution automation master station.

2. The method according to claim 1, characterized in that The method further comprises: A distributed time synchronization protocol is used to perform network time synchronization on the intelligent power distribution equipment, wherein a clock synchronization module is set in each of the intelligent power distribution equipment, and the clock synchronization module calculates the transmission delay based on the timestamp information of the power line carrier signal, and uses the least squares method to fit the delay data of multiple samples to generate clock deviation compensation parameters, thereby achieving accurate time synchronization of the intelligent power distribution equipment.

3. A remote identification system for intelligent power distribution equipment based on power line communication, used to implement the method as described in any one of claims 1-2, characterized in that: include: The first unit is used to receive device identification information sent by the intelligent power distribution device through power line carrier communication, where the device identification information includes device type information, device number information and device installation location information; The second unit is used to establish a device information database of the intelligent power distribution device including a three-layer architecture of a physical layer, a topological layer and a business layer, wherein the device information database stores a correspondence between the device identification information and the topological structure of the distribution network; Sending an identity authentication request to the intelligent power distribution device, the identity authentication request including verification code information randomly generated by a key exchange algorithm; receiving verification response information returned by the intelligent power distribution device based on the verification code information; The third unit is used to build a multi-level blockchain network architecture including a main chain layer network and a verification sub-chain network, select a verification node set in the verification sub-chain network corresponding to the intelligent power distribution equipment, generate a consensus authority matrix of the verification sub-chain network based on the connection relationship between the verification nodes, and determine the node reputation corresponding to the intelligent power distribution equipment according to the consensus authority matrix; The fourth unit is used to determine whether the identity authentication of the intelligent distribution device is passed based on the verification result of the verification response information and the node credibility, and if the identity authentication is passed, allocate a communication time slot to the intelligent distribution device to establish a secure communication link between the intelligent distribution device and the distribution automation master station.

4. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method described in any one of claims 1 to 2.

5. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 2 is implemented.

Citation Information

Patent Citations

  • Power communication network fault simulation verification method and device, equipment and storage medium

    CN113411221A

  • Power distribution network fault processing flow optimization method based on multivariate data

    CN117592961A