Encryption measurement terminal arrangement optimization method and device, computer equipment and storage medium

By simulating attack scenarios and identifying key assets, and optimizing the layout of encrypted measurement terminals, the problem of low security in power systems when facing network attacks is solved, and more efficient defense and economicality is achieved.

CN120030533APending Publication Date: 2025-05-23ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510319867.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

When power systems face cyber attacks and fake data injection attacks, they have low security problems, and traditional defense methods are difficult to deal with complex security threats.

Method used

By obtaining attack scenario simulation data of the power system, multiple attack simulation scenarios are constructed, attack simulations are carried out to analyze the impact, identify key power assets, and optimize the layout plan of the encrypted measurement terminal based on this information to minimize costs and prioritize the protection of key buses with high failure risk.

Benefits of technology

It improves the identification accuracy of key power assets in the power system, enhances the positioning ability of vulnerable areas, realizes the balance between defense effects and economics of encrypted measurement terminal layout, and improves the security and resilience of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030533A_ABST
    Figure CN120030533A_ABST
Patent Text Reader

Abstract

The invention relates to an encryption measurement terminal arrangement optimization method and device, computer equipment and a storage medium. The method comprises the following steps: acquiring attack scene simulation data of a power system; constructing a plurality of attack simulation scenes based on the attack scene simulation data; performing attack simulation on the constructed power system model based on each attack simulation scene to obtain an attack influence analysis result of each attack simulation scene; according to the attack influence analysis result of each attack simulation scene, key power assets in the power system are identified, asset information of the key power assets is acquired, and the key power assets comprise key buses; solving a pre-constructed optimization objective function based on the asset information of the key power assets and a preset constraint condition by taking the minimum cost and preferential protection of a high-fault-risk key bus as targets to obtain an optimal solution; and determining an arrangement scheme of the encrypted measurement terminal of the power system based on the optimal solution. The method is beneficial to improving the safety of the power system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of power system security, and in particular to a method, device, computer equipment, computer-readable storage medium and computer program product for optimizing the layout of encrypted measurement terminals. Background Art

[0002] Power system security technology refers to a series of technical means and measures to ensure that the power system can maintain its normal operation and recover quickly when encountering various potential threats and abnormal situations. This includes real-time monitoring of the system's operating status, fault detection and isolation, and defense against external attacks and natural disasters. Specifically, power system security not only involves the protection of physical infrastructure, but also covers the security of information systems in the power network, such as preventing network attacks, data tampering, false data injection and other behaviors that threaten system operation.

[0003] With the development of digitalization and intelligence of power systems, the security risks and challenges faced by power systems are increasing. The automation and informatization of power systems make their operation more efficient, but also expose the system to more network attacks and information security issues, especially network attacks and false data injection attacks (FDIA). For example, load redistribution attacks (LRA) may cause cascading failures and affect the normal operation of the system by manipulating the load distribution in the power system. As the power system's dependence on external information deepens, traditional defense measures can no longer cope with emerging complex security threats, resulting in low security in the power system. Summary of the invention

[0004] Based on this, it is necessary to provide a method, device, computer equipment, computer-readable storage medium and computer program product for optimizing the layout of encrypted measurement terminals that can improve the security of the power system in response to the above-mentioned technical problems.

[0005] In a first aspect, the present application provides a method for optimizing the layout of encrypted measurement terminals, comprising:

[0006] Obtain attack scenario simulation data for power systems;

[0007] Based on attack scenario simulation data, build multiple attack simulation scenarios;

[0008] Perform attack simulations on the constructed power system model based on each attack simulation scenario, and obtain attack impact analysis results of each attack simulation scenario;

[0009] According to the attack impact analysis results of each attack simulation scenario, identify the key power assets in the power system and obtain asset information of the key power assets, including key busbars;

[0010] With the goal of minimizing costs and giving priority to protecting critical buses with high fault risks, the pre-built optimization objective function is solved based on the asset information of key power assets and preset constraints to obtain the optimal solution. The optimization objective function is constructed based on the installation cost of the encrypted measurement terminal, the impact frequency of the critical bus, and the power flow change of the critical bus.

[0011] Based on the optimal solution, determine the layout plan of the encrypted measurement terminals of the power system.

[0012] In one embodiment, the attack scenario simulation data includes an operating point set, a target attack line set, a load deviation amplitude set, and a bus number set;

[0013] Based on the attack scenario simulation data, multiple attack simulation scenarios are constructed, including:

[0014] Perform data verification on attack scenario simulation data;

[0015] The following processing is performed on the attack scenario simulation data that has passed the verification:

[0016] A parameter is extracted from the operating point set, the target attack line set, the load deviation amplitude set and the bus number set respectively, and then combined to obtain multiple groups of parameter combinations;

[0017] For each parameter combination, the pre-constructed two-layer optimization model is solved according to the parameter combination to generate an attack simulation scenario. The upper optimization function of the two-layer optimization model is constructed based on the power flow change of the target attack line, and the lower optimization function is constructed based on the power generation cost.

[0018] In one embodiment, attack simulation is performed on the constructed power system model based on each attack simulation scenario to obtain attack impact analysis results, including:

[0019] For each attack simulation scenario, according to the operating point in the attack simulation scenario, the system state of the power system model is loaded, according to the load deviation amplitude in the attack simulation scenario, the injection power of the target attack line in the power system model is adjusted, according to the number of buses in the attack simulation scenario, the injection power of the corresponding number of buses in the power system model is adjusted to simulate a load redistribution attack on the power system;

[0020] Determine the power flow load of the line in the power system model, evaluate the failure of the line in the power system model according to the power flow load of the line and the preset line tripping protection evaluation condition, and obtain the line failure evaluation result;

[0021] According to the line failure assessment result, determine whether a cascading failure will occur in the attack simulation scenario, and obtain the cascading failure judgment result of the attack simulation scenario;

[0022] The line failure assessment results and cascade fault judgment results are integrated to obtain the attack impact analysis results of the attack simulation scenario.

[0023] In one embodiment, according to the attack impact analysis results of each attack simulation scenario, key power assets are identified from the power assets of the power system, and asset information of the key power assets is obtained, including:

[0024] According to the attack impact analysis results of each attack simulation scenario, the busbars affected by the attack are screened out from the power system model;

[0025] For each bus, determine the impact frequency and dynamic power flow change of the bus between each attack simulation scenario, and determine the fault risk level of the bus based on the impact frequency and dynamic power flow change of the bus;

[0026] According to the influence frequency and dynamic power flow change of each bus, the key bus is selected from the buses;

[0027] The impact frequency, dynamic power flow change and fault risk level of the key bus are integrated to obtain the asset information of the key bus.

[0028] In one embodiment, the preset constraints include global observation constraints, key line coverage constraints and high-risk bus protection constraints. The global observation constraints enable each bus to meet the preset observation requirements. The key line coverage constraints are used to enable the bus on the key line to be observed. The high-risk bus protection constraints are used to constrain the layout of encrypted measurement terminals on the high-risk bus. Based on the asset information of the key power assets and the preset constraints, the pre-constructed optimization objective function is solved to obtain the optimal solution of the function, including:

[0029] Based on the asset information of key power assets, global observation constraints, key line coverage constraints and high-risk bus protection constraints, the pre-constructed optimization objective function is solved through mixed integer linear programming to obtain the optimal solution.

[0030] In one embodiment, after performing attack simulation on the constructed power system model based on each attack simulation scenario and obtaining the attack impact analysis result of each attack simulation scenario, the method further includes:

[0031] For each attack simulation scenario, when the target attack line triggers tripping protection and the number of lines that trigger tripping protection is greater than or equal to a preset line number threshold, the attack simulation scenario is marked as a high threat scenario.

[0032] In a second aspect, the present application also provides an encryption measurement terminal layout optimization device, including:

[0033] A data acquisition module, used to acquire attack scenario simulation data of the power system;

[0034] A scenario construction module is used to construct multiple attack simulation scenarios based on attack scenario simulation data;

[0035] The attack simulation module is used to perform attack simulation on the constructed power system model based on each attack simulation scenario, and obtain the attack impact analysis results of each attack simulation scenario;

[0036] An asset identification module is used to identify key power assets in the power system and obtain asset information of key power assets based on the attack impact analysis results of each attack simulation scenario. Key power assets include key buses.

[0037] The layout scheme determination module is used to solve the pre-constructed optimization objective function based on the asset information of key power assets and preset constraints to obtain the optimal solution with the goal of minimizing costs and giving priority to protecting key buses with high fault risks. The optimization objective function is constructed based on the installation cost of the encrypted measurement terminal, the impact frequency of the key bus and the power flow change of the key bus; based on the optimal solution, the layout scheme of the encrypted measurement terminals of the power system is determined.

[0038] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps in any one of the above-mentioned encryption measurement terminal layout optimization method embodiments are implemented.

[0039] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in any one of the above-mentioned encryption measurement terminal layout optimization method embodiments are implemented.

[0040] In a fifth aspect, the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements the steps in any one of the above-mentioned encryption measurement terminal layout optimization method embodiments.

[0041] The above-mentioned encrypted measurement terminal layout optimization method, device, computer equipment, computer-readable storage medium and computer program product generate a set of attack simulation scenarios for load redistribution attacks, simulate attacks on the power system, analyze the impact of the attack simulation on the power system, obtain attack impact analysis results, and identify key power assets from the power assets of the power system based on the attack impact results, thereby improving the accuracy of key power asset identification. By accurately identifying key power assets in the power system, it is helpful to locate vulnerable areas of the power system. In order to achieve a balance between the defense effect and economy of the encrypted measurement terminal layout, based on the installation cost of the encrypted measurement terminal, the impact frequency of the key bus and the power flow change, an optimization objective function is constructed with the goal of minimizing costs and protecting key buses with high failure risks. Through the key power asset information and preset constraints, the optimal solution is obtained, and the optimized layout plan of the encrypted measurement terminal is determined according to the optimal solution, which provides optimization support for the defense capability and operation stability of the power system, thereby facilitating the optimal layout of the encrypted measurement terminal according to the layout plan, so as to enhance the monitoring capability, adaptability and defense effect of the power system in the face of attacks, and is conducive to enhancing the security and resilience of the system, reducing the risk of continuous failures caused by attacks, and improving the reliability and economy of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0043] Figure 1 An application environment diagram of an encryption measurement terminal layout optimization method in one embodiment;

[0044] Figure 2 A schematic diagram of a flow chart of a method for optimizing the arrangement of encryption measurement terminals in one embodiment;

[0045] Figure 3 A schematic diagram of a flow chart of a method for optimizing the arrangement of encryption measurement terminals in another embodiment;

[0046] Figure 4 It is a flowchart of a method for optimizing the arrangement of encryption measurement terminals in another embodiment;

[0047] Figure 5 A schematic diagram of a flow chart of a method for optimizing the arrangement of encryption measurement terminals in yet another embodiment;

[0048] Figure 6A multi-dimensional visualization diagram of the frequency distribution of load redistribution attacks on key lines in one embodiment;

[0049] Figure 7 A diagram showing a comparison and analysis of system load estimation strategies in one embodiment;

[0050] Figure 8 A comparative analysis diagram of power flow load rate of power system lines based on optimized arrangement of encrypted measurement terminals in one embodiment;

[0051] Fig. 9 It is a structural block diagram of an encryption measurement terminal arrangement optimization device in one embodiment;

[0052] Fig.10 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0053] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0054] The encryption measurement terminal layout optimization method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, the terminal 102 communicates with the server 104 through a network. The data storage system can store data that the server 104 needs to process. The data storage system can be integrated on the server 104, or placed on the cloud or other network servers.

[0055] Specifically, the operator may upload the attack scenario simulation data of the power system to the server 104 through the terminal 102, and then send the encrypted measurement terminal layout optimization message to the server 104 through the terminal 102. The server 104 obtains the attack scenario simulation data of the power system, and constructs multiple attack simulation scenarios based on the attack scenario simulation data. Secondly, the constructed power system model is subjected to attack simulation based on each attack simulation scenario to obtain the attack impact analysis results of each attack simulation scenario. Then, according to the attack impact analysis results of each attack simulation scenario, the key power assets in the power system are identified, and the asset information of the key power assets is obtained. The key power assets include key buses. Finally, with the goal of minimizing costs and giving priority to protecting key buses with high fault risks, the pre-constructed optimization objective function is solved based on the asset information of the key power assets and preset constraints to obtain the optimal solution. The optimization objective function is constructed based on the installation cost of the encrypted measurement terminal, the impact frequency of the key bus, and the power flow change of the key bus. Based on the optimal solution, the layout plan data of the encrypted measurement terminal of the power system is determined.

[0056] The terminal 102 may be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, IoT devices, and portable wearable devices. The IoT devices may be smart TVs, smart car devices, projection devices, etc. The portable wearable devices may be smart watches, smart bracelets, etc. The server 104 may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.

[0057] In an exemplary embodiment, Figure 2 As shown, a method for optimizing the layout of encrypted measurement terminals is provided. Figure 1 The server 104 in the example is used for explanation, and includes the following S100 to S400. Among them:

[0058] S100, acquiring attack scenario simulation data of the power system.

[0059] Among them, the attack simulation data may include target attack node data, target attack line data and attack parameters, etc. Among them, the target attack node data includes multiple target attack nodes, and the target attack node represents the target node of the simulated attack; the target attack line data includes multiple target attack lines, and the target attack line represents the target line of the simulated attack, and the attack parameters may include the adjustment amount of the power flow of the target attack node. The attack scenario simulation data is used to generate an attack simulation scenario for simulating an attack on the power system. In this embodiment, the simulated attack can be a simulated attack on a load redistribution attack (LRA).

[0060] In practical applications, attack simulation data can be obtained based on actual power grid data and a random number generator. For example, target attack node data and target attack line data can be determined based on actual power grid data, and attack parameters can be randomly generated based on a random number generator.

[0061] S200, construct multiple attack simulation scenarios based on attack scenario simulation data.

[0062] Among them, the attack simulation scenario is used to characterize the strategy of the simulated attack.

[0063] In practical applications, the data structure of the attack simulation scenario can be predefined, such as each attack simulation scenario contains a scenario identifier, a target attack node, a target attack line, and attack parameters. Initialize an empty list, and then add different attack simulation data to the list in a loop to obtain multiple attack simulation scenarios. The constructed attack simulation scenario data can be serialized into a JSON file for subsequent loading and analysis.

[0064] S300, performing attack simulation on the constructed power system model based on each attack simulation scenario, and obtaining attack impact analysis results of each attack simulation scenario.

[0065] The attack impact analysis results characterize the impact of the simulated attack on the power system model and are used to locate the area affected by the attack. The attack impact analysis results may include the affected lines and buses. The affected lines may be lines with a larger power flow change compared to the initial power flow after the simulated attack.

[0066] In practical applications, the power flow of the corresponding nodes and lines in the power system model can be adjusted according to the target attack nodes, target attack lines and attack parameters in each attack simulation scenario. The power flow change of each line and bus in the power system model is obtained, and the lines and buses with large power flow changes are respectively determined as the affected lines and buses, and the relevant parameters of the affected lines and buses are obtained, such as line identifiers, bus identifiers and power flow changes. The attack impact analysis results corresponding to each attack simulation scenario are recorded.

[0067] S400, based on the attack impact analysis results of each attack simulation scenario, identify the key power assets in the power system and obtain asset information of the key power assets, where the key power assets include key buses.

[0068] The asset information of the critical power asset may include an identifier of the critical power asset and an amount of change that affects frequency and power flow.

[0069] In practical applications, after obtaining the attack impact analysis results of each attack simulation scenario, the busbars that are affected multiple times can be determined as critical busbars. For example, an impact frequency threshold is set, and the number of times each affected busbar is affected in all attack simulation scenarios is counted as the impact frequency of the busbar, and the busbars with an impact frequency greater than or equal to the impact frequency threshold are determined as critical busbars. Obtaining the asset information of the critical busbars may be obtaining the identifier, impact frequency, and power flow change of the critical busbars.

[0070] S500, with the goal of minimizing costs and giving priority to protecting critical buses with high fault risks, solves the pre-built optimization objective function based on the asset information of key power assets and preset constraints to obtain the optimal solution. The optimization objective function is constructed based on the installation cost of the encrypted measurement terminal, the impact frequency of the critical bus, and the power flow change of the critical bus.

[0071] Among them, the preset constraints may include global observation constraints and N-1 security constraints. The encrypted measurement terminal is a phasor measurement unit (PMU) with security encryption function. The encrypted measurement terminal can be used for real-time monitoring of power data in the power system to identify the fault location and fault type and trigger the protection mechanism. The optimal solution may include the layout status of the encrypted measurement terminal on the bus. The layout status includes whether the encrypted measurement terminal is deployed.

[0072] In practical applications, the optimization objective function is constructed in advance based on the installation cost of the encrypted measurement terminal, the impact frequency of the key bus, and the power flow change of the key bus. The global observation constraint can be set according to the bus connection relationship matrix to ensure that the bus meets the global observation requirements of the power system. The N-1 safety constraint can be set according to the line connection relationship matrix to ensure that even if one PMU fails in the power system, the system can still maintain basic functions and observability. According to the asset information of the key bus, the optimal solution is obtained by linear programming.

[0073] S600: Determine a layout plan of encrypted measurement terminals of the power system based on the optimal solution.

[0074] In practical applications, the optimal layout scheme of the encrypted measurement terminals of the power system is determined according to the layout status of the encrypted measurement terminals of each key bus in the optimal solution.

[0075] In the above-mentioned encrypted measurement terminal layout optimization method, by generating a set of attack simulation scenarios for load redistribution attacks, simulating attacks on the power system, analyzing the impact of the attack simulation on the power system, and obtaining the attack impact analysis results, the key power assets are identified from the power assets of the power system based on the attack impact attack results, which improves the accuracy of key power asset identification. By accurately identifying the key power assets in the power system, it is helpful to locate the vulnerable areas of the power system. In order to achieve a balance between the defense effect and economy of the encrypted measurement terminal layout, based on the installation cost of the encrypted measurement terminal, the impact frequency of the key bus and the power flow change, an optimization objective function with the goal of minimizing costs and protecting the key bus with high fault risk is constructed. Through the key power asset information and the preset constraints, the optimal solution is obtained, and the layout plan of the encrypted measurement terminal is determined according to the optimal solution, which provides optimization support for the defense capability and operation stability of the power system, so as to facilitate the optimization layout of the encrypted measurement terminal according to the layout plan, so as to improve the monitoring capability, adaptability and defense effect of the power system in the face of attacks, and to enhance the security and resilience of the system, reduce the risk of continuous failures caused by attacks, and improve the reliability and economy of the system.

[0076] In an exemplary embodiment, the attack scenario simulation data includes an operating point set, a target attack line set, a load deviation amplitude set, and a bus number set, such as Figure 3 As shown, S200 includes S220 to S260. Among them:

[0077] In this embodiment, the attack simulation scenario is used to simulate a load redistribution attack.

[0078] In the obtained attack scenario simulation data, the running point set Including multiple operating points in the power system model, operating point set , used to characterize different operating states of the system; target attack line set including lines in the power system that may be subjected to simulated attacks, ; Load deviation amplitude set Including multiple simulated attack load deviation amplitudes, ; Bus quantity collection Contains the number of buses that may be manipulated in the attack simulation. .

[0079] S220, performing data verification on the attack scenario simulation data.

[0080] In practical applications, an attack simulation scenario list may be predefined to store attack simulation scenarios, and the attack simulation scenario list includes attack simulation scenario number, operating point, target attack line, load deviation amplitude and bus number. Specifically, create an empty attack simulation scenario list , define the attack simulation scenario list structure as ,in, Number the simulated attack scenarios; is the operating point; Attack lines for targets; is the load deviation amplitude; is the number of buses to be manipulated; Mark whether the simulated attack scenario is a high-threat scenario.

[0081] Verify the data integrity and data range of the attack scenario simulation data to ensure the accuracy of subsequent attack simulation analysis. Specifically, the verification conditions are as follows:

[0082] For the set of running points : Verify the initial power distribution at each operating point Non-empty to ensure that the collection Contains at least one valid operating point.

[0083] For target attack line set : Verify that the electrical parameters (such as impedance and capacity) of the target attack line are defined to ensure the collection is not null,

[0084] For the load deviation amplitude set :Verify that the deviation value does not exceed the steady-state limit of the system operation to ensure the collection Contains a reasonable range of load deviation values.

[0085] For busbar quantity set : Check set Maximum value The total number of buses in the system shall not exceed ; Minimum It should be able to cover at least one critical line to ensure that the bus quantity range matches the system scale.

[0086] Verify that the attack simulation data meets the dynamic power flow constraints: by formula , verify whether the attack simulation data can support the dynamic balance calculation of power flow. is the power flow distribution factor matrix, and are the node voltage amplitude vector and the demand voltage vector respectively, and are the changes in power generation and load power respectively. If any of the above conditions is not met, an error log is recorded and the verification of the attack simulation data is terminated.

[0087] The following processing is performed on the attack scenario simulation data that has passed the verification:

[0088] S240, extracting a parameter from the operating point set, the target attack line set, the load deviation amplitude set, and the bus number set respectively, and combining them to obtain multiple groups of parameter combinations.

[0089] In practical applications, an attack simulation scenario generator can be pre-built, and the attack simulation data can be used as input data to call the attack simulation scenario generator and initialize the attack simulation scenario number. , extract a parameter from the operating point set, target attack line set, load deviation amplitude set and bus number set respectively, and obtain multiple sets of parameter combinations. Specifically, traverse each set in the attack simulation data and extract the parameters in the set: traverse the operating point set , select the operating point ; Traverse the target attack line set , select the current target attack line As the target of attack; traverse the load deviation range set , select the load deviation value , to try different deviation amplitudes one by one; traverse the bus number set , select the number of busbars , in order to simulate different busbar manipulation strategies, the selected parameters are combined to obtain multiple groups of parameter combinations.

[0090] S260, for each parameter combination, according to the parameter combination, the pre-constructed two-layer optimization model is solved to generate an attack simulation scenario, the upper optimization function of the two-layer optimization model is constructed based on the power flow change of the target attack line, and the lower optimization function is constructed based on the power generation cost.

[0091] In practical applications, a two-layer optimization model is pre-built, which includes a two-layer optimization objective function and multiple constraints. The two-layer optimization objective function includes an upper-layer optimization objective function and a lower-layer optimization objective function:

[0092] Upper-level optimization objective: maximize the power flow change of the target attack line.

[0093]

[0094] in, Indicates line The power flow distribution factor, Representation Node The load offset (i.e., the load change caused by the attack) of the target function is:

[0095] Lower-level optimization objective: minimize the total power generation cost.

[0096]

[0097] in, is the total power generation cost, For generator The unit cost of electricity generation is is the actual power generated.

[0098] The constraints include total load balance constraints, node load offset range constraints, generator output range constraints, line power flow capacity constraints, and system power balance constraints:

[0099] 1. Total load balancing constraints:

[0100]

[0101] 2. Node load offset range constraints:

[0102]

[0103] in, Representation Node The initial load, is the allowed load offset ratio. This constraint is used to limit the attack's control range on a single node and ensure the concealment of the attack.

[0104] 3. Generator output range constraints:

[0105]

[0106] in, and Generator The minimum and maximum output.

[0107] 4. Line power flow capacity constraints:

[0108]

[0109] in, and For line The minimum and maximum power flows ensure that the line is not overloaded by the attack.

[0110] 5. System-wide power balance constraints to ensure that the generated power meets the load demand:

[0111]

[0112] For each parameter combination, run the two-layer optimization model to generate and record attack scenarios. Add the parameter combination to the attack scenario list Incremental :

[0113]

[0114] Through the two-layer optimization model, multiple attack simulation scenarios are constructed.

[0115] In this embodiment, on the one hand, by performing data verification on the attack scenario simulation data, the accuracy and effectiveness of the attack simulation are improved, which is beneficial to improve the accuracy of identifying key power and encrypted measurement terminal layout based on accurate attack impact analysis results; on the other hand, based on the characteristics of load redistribution attacks, a two-layer optimization model is established, and attack simulation scenarios are generated through the two-layer optimization model, which improves the accuracy and cost of attack simulation, and is beneficial to accurately identify the key assets of the system and effectively locate the affected area according to the simulated attack results, which is beneficial to guiding the layout of encrypted measurement terminals and improving the protection coverage effect of key asset areas.

[0116] To improve the accuracy of the analysis of the impact of load redistribution attacks, in an exemplary embodiment, Figure 4 As shown, S300 includes S320 to S380. Among them:

[0117] S320, for each attack simulation scenario, according to the operating point in the attack simulation scenario, the system state of the power system model is loaded, according to the load deviation amplitude in the attack simulation scenario, the injection power of the target attack line in the power system model is adjusted, according to the number of buses in the attack simulation scenario, the injection power of the corresponding number of buses in the power system model is adjusted to simulate a load redistribution attack on the power system.

[0118] Among them, the power system model includes the bus connection matrix (adjacency matrix) ; Line impedance matrix ; Initial voltage and power distribution ; Power flow distribution factor matrix PTDF.

[0119] In actual applications, each attack simulation scenario , according to the operating point in the simulation scenario , load the corresponding initial system state ; Set the target attack line Set to attack line, according to the load deviation amplitude Modify the injection power of the target attack line; according to the number of buses , select the corresponding number of buses and adjust the injected power of these buses.

[0120] S340, determining the power flow load of the line in the power system, and evaluating the failure of the line in the power system according to the power flow load of the line and the preset line tripping protection evaluation condition, to obtain a line failure evaluation result.

[0121] The preset line tripping protection condition is used to evaluate whether the line triggers the tripping protection. The line failure evaluation result may include the line that triggers the tripping protection, the failed busbar, the number of lines that trigger the tripping protection, the fault status of each line, and the power flow change.

[0122] In practical applications, for each attack simulation scenario, it is evaluated whether the target attack line triggers the tripping protection. If the target attack line triggers the tripping protection, it indicates that the target attack line is invalid, and at the same time, the topology update of the power system model is triggered. After the system topology update is triggered, it is evaluated whether other lines in the power system model trigger the tripping protection. Among them:

[0123] Evaluate whether the line triggers trip protection:

[0124]

[0125] in, For Line The power flow (power flow), For line Rated power capacity, is the trip protection threshold, (usually in the range ).

[0126] If the target attack line meets this condition, it represents the target attack line Failure triggers a system topology update.

[0127] In the case where the target attack line triggers the trip protection, the power flow load of other lines except the target attack line is re-determined based on the dynamic power flow calculation formula to evaluate whether other lines trigger the trip protection. If other lines have triggered the trip protection, repeat the steps of re-determining the power flow load of other lines except the line that triggered the trip protection based on the dynamic power flow formula and evaluating whether other lines trigger the trip protection until the power system is restored to stability. The dynamic power flow of the line is calculated by the following formula:

[0128]

[0129] in, is the power flow distribution factor matrix; and is the power allocation factor matrix; For power generation scheduling in attack simulation scenarios; is the actual load distribution.

[0130] The number of lines that failed (triggered tripping protection) in the attack simulation scenario was counted, and the line number that triggered the tripping protection, the failed bus number, the failed bus, the fault status of each line (whether the tripping protection was triggered) and the power flow change were recorded to obtain the line failure assessment result of the attack simulation scenario.

[0131] S360: According to the line failure assessment result, it is determined whether a cascading failure will occur in the attack simulation scenario, and a cascading failure determination result of the attack simulation scenario is obtained.

[0132] Among them, the cascading failure judgment result may include whether a cascading failure will occur. Cascading failure refers to the phenomenon that an initial fault or disturbance triggers a series of subsequent faults in the power system. The characteristic of cascading failure is its chain reaction nature, that is, the failure of one component may affect multiple other components, which in turn causes more components to fail, forming a vicious cycle.

[0133] In actual applications, a threshold value of the number of failed lines is pre-set to determine whether a cascading failure will occur in an attack simulation scenario. For each attack simulation scenario, the number of failed lines in the line failure assessment results is compared. , and the preset failure line number threshold (such as the failure line number threshold is 2), if the number of failed lines is greater than or equal to the preset failure line number threshold ( ,), it is determined that the attack simulation scenario will cause cascading failure. On the contrary, it is determined that the attack simulation scenario does not have the potential to cause cascading failure, and no cascading failure will occur, and the cascading failure judgment result of the attack simulation scenario is obtained.

[0134] S380, integrating the line failure assessment result and the cascade fault judgment result to obtain the attack impact analysis result of the attack simulation scenario.

[0135] In practical applications, for each attack simulation scenario, the line failure assessment results and cascade failure judgment results can be integrated into a list to obtain the attack impact analysis results of the attack simulation scenario. The list is formatted as:

[0136]

[0137] in, Number the attack simulation scenarios; is the number of failed lines; Number the line affected by the attack; Number the busbars affected by the attack; Whether a cascading failure will occur. The line affected by the attack may be a failed line (the line that triggers the cascading failure), and the bus affected by the attack may be a failed bus.

[0138] If anomalies such as parameter mismatch or calculation divergence occur during the simulated attack, the error log will be recorded and the current attack simulation scenario will be skipped.

[0139] In this embodiment, an attack simulation is performed on the power system model according to the attack simulation scenario, and analysis is performed from two aspects: line failure status and cascading failure potential, to obtain attack impact analysis results for each attack simulation scenario. This is beneficial for identifying key power assets that pose a greater threat to the stability of the power system based on multiple attack impact analysis results, and is beneficial for improving the accuracy of identifying key power assets.

[0140] In an exemplary embodiment, Figure 5 As shown, S400 also includes S420 to S480. Among them:

[0141] S420, selecting a busbar affected by the attack from the power system according to the attack impact analysis results of each attack simulation scenario.

[0142] In practical applications, the bus affected by the attack can be extracted from the attack impact analysis results of each attack simulation scenario. Extract the buses affected by the attack and construct the bus set affected by the attack , characterizing that these buses are marked as directly or indirectly affected buses in the cascading fault simulation.

[0143] S440, for each bus, determining the impact frequency and dynamic power flow change of the bus between various attack simulation scenarios, and determining the fault risk level of the bus according to the impact frequency and dynamic power flow change of the bus.

[0144] The impact frequency is used to characterize the frequency at which the bus is affected by the attack.

[0145] In actual applications, according to the attack impact analysis results of each attack simulation scenario, statistics are collected for each bus. Frequency of impact in all attack scenarios .

[0146] For each bus , determine the dynamic power flow of the bus to measure its impact on the system power flow:

[0147]

[0148] in, For bus The power flow distribution factor, For power generation scheduling in attack simulation scenarios; For load distribution.

[0149] Pre-set the impact frequency scoring standard, such as the higher the impact frequency, the higher the impact frequency score; pre-set the dynamic power flow change scoring standard, such as the larger the dynamic power flow change, the higher the dynamic power flow change score. Assign weights to the impact frequency score and the dynamic power flow change score respectively. For each bus, the impact frequency score and the dynamic power flow change score of the bus are obtained by the preset impact frequency scoring standard and the dynamic power flow change scoring standard, and the fault risk score of the bus is obtained by weighted summation according to the corresponding weights. Set multiple fault risk levels, set a corresponding fault risk score range for each fault risk level, and determine the fault risk score level of the bus according to its fault risk score. The higher the fault risk level of the bus, the greater the threat of the bus to the stability of the system.

[0150] S460, selecting a key bus from the buses according to the influencing frequency and the dynamic power flow variation of each bus.

[0151] Among them, the key bus is used to guide the layout plan of encrypted measurement terminals.

[0152] In practical applications, the candidate critical buses can be screened out according to the influencing frequency of the bus, and the candidate critical buses are characterized as having a greater threat to the stability of the system. Specifically, the influencing frequency threshold can be pre-set. , used to screen out candidate key buses, and the impact frequency threshold can be set based on experience. And the preset impact frequency threshold, filter out candidate critical buses: .

[0153] For the candidate critical busbars, the critical busbars are screened out according to the impact frequency and dynamic power flow change of the candidate critical busbars. Specifically, the critical lines in the power system can be marked in advance according to the actual power grid data. If the dynamic power flow change of the candidate critical busbar affects multiple critical lines, its screening priority is increased. If the candidate critical busbar frequently participates in cascade fault propagation in multiple attack simulation scenarios, its screening priority is increased, and the critical busbar is screened out. The critical busbar is the key location for the subsequent layout of encrypted measurement terminals.

[0154] S480 integrates the impact frequency, dynamic power flow change and fault risk level of the key bus to obtain the asset information of the key bus.

[0155] In practical applications, a list is pre-established to store the asset information of key buses. ,in, is the bus number, is the influence frequency of the bus, is the dynamic power flow variation, Indicates the fault risk level of the busbar

[0156] For each critical bus, determine whether the bus has a high fault risk based on the fault risk level of the bus. Specifically, a high fault risk level threshold may be set in advance based on the fault risk level range. When the fault risk level of the bus is higher than the high fault risk level threshold, determine that the critical bus has a high fault risk, and obtain a high fault risk judgment result for the critical bus. Record the impact frequency, dynamic power flow change, and fault risk level of the critical bus.

[0157] Import the impact frequency, power flow change and high fault risk judgment results of the key bus into The asset information of the key busbars can be obtained from the list. The asset information of the key busbars can be used as the candidate layout location of the encrypted measurement terminal. Specifically, the asset information of the key busbars includes the busbar number of each key busbar. , Impact frequency , power flow change and high failure risk judgment results (whether there is a high failure risk) are used to provide core input data for subsequent steps.

[0158] In this embodiment, the critical bus is screened out through the influence frequency and dynamic power flow change of the bus, which improves the accuracy and pertinence of the screening. The influence frequency, dynamic power flow change and fault risk level of the critical bus are integrated to obtain the asset information of the critical bus, which is conducive to optimizing the layout of encrypted measurement terminals according to the asset information of the critical bus.

[0159] In an exemplary embodiment, the preset constraints include global observation constraints, key line coverage constraints, and high-risk bus protection constraints. The global observation constraints enable each bus to meet the preset observation requirements. The key line coverage constraints are used to enable the bus on the key line to be observed. The high-risk bus protection constraints are used to constrain the layout of encrypted measurement terminals on the high-risk bus. Based on the asset information of the key power assets and the preset constraints, the pre-constructed optimization objective function is solved to obtain the optimal solution of the function, including:

[0160] Based on the asset information of key power assets, global observation constraints, key line coverage constraints and high-risk bus protection constraints, the pre-constructed optimization objective function is solved through mixed integer linear programming to obtain the optimal solution.

[0161] In practical applications, the optimization objective function is constructed with the goal of minimizing the total installation cost of the encrypted measurement terminal while giving priority to protecting the critical busbars with high failure risks:

[0162]

[0163] in, For bus PMU installation cost; For bus Frequency of impact in attack simulation scenarios; For bus Dynamic power flow variation; Indicates busbar Whether to install the encrypted measurement terminal (1 means installed, 0 means not installed) It is a parameter adjustment used to balance the importance of frequency and dynamic power flow changes. It can be adjusted dynamically according to the actual scenario. , giving priority to the protection of busbars with high frequency and high dynamic power flow changes.

[0164] In order to meet the global observation requirements of the power system, the global observation constraints are set:

[0165]

[0166] in, is the busbar connection relationship matrix; It represents the observation requirement of each bus, which is set to 2 for buses marked as high failure risk and 1 for ordinary buses. Through the global observation constraint, it is beneficial to make each bus achieve global observability through its directly connected encrypted measurement terminal to meet the overall monitoring needs.

[0167] To ensure that the buses on the critical lines are fully observed, set the critical line coverage constraints:

[0168]

[0169] in, is the key line identification matrix, is the total number of critical line buses. The critical line coverage constraint condition is conducive to ensuring that the buses on the critical lines are equipped with sufficient encrypted measurement terminals, so that these lines that are critical to the stability of the power grid can be fully and accurately monitored, which is conducive to maintaining the safety and reliability of the system.

[0170] Encrypted measurement terminals must be arranged on high-risk busbars, and high-risk busbar protection constraints must be set:

[0171]

[0172] The high-risk busbar may be a busbar with a high risk of failure. The high-risk busbar protection constraint condition is helpful to monitor potential vulnerable points such as the high-risk busbar, thereby enhancing the rapid response capability to emergencies and the effectiveness of preventive measures.

[0173] According to the high-risk bus protection constraint conditions, initialize the layout status of the bus encrypted measurement terminal:

[0174]

[0175] The optimization objective function and all constraints (global observation constraints, critical line coverage constraints, and high-risk bus protection constraints) are input into the mixed integer linear programming solver. During the solution process, the layout status of non-high-risk buses is Dynamically adjust according to the objective function to ensure that the goals are met: global observability of the system; key line coverage requirements; and minimization of installation costs.

[0176] The optimal solution is output, which includes the layout status of the encrypted measurement terminals of each bus (whether to arrange the encrypted measurement terminals) and the installation cost.

[0177] In other embodiments, after obtaining the optimal solution, an optimization report is generated based on the optimal solution. The optimization report includes the following information:

[0178] Total installation cost: ;

[0179] System global observability achieved: Satisfied coverage;

[0180] Key line coverage: Satisfied coverage;

[0181] Protection rate of high-risk busbar: Satisfy .

[0182] Arrange the result record format: .

[0183] In this embodiment, on the one hand, global observation, high-risk bus protection and key line coverage constraints are set to solve the optimization plan for the layout of encrypted measurement terminals, which is beneficial to improving the power system's defense capability against load redistribution attacks and enhancing the safety and stability of power system operation; on the other hand, in order to take into account both the safety and defense costs of the power system, consideration is given to optimizing the layout of encrypted measurement terminals on key buses to meet the global observability requirements of the power system at the lowest cost, and to give priority to protecting buses and lines marked as high fault risks in load redistribution attack simulation scenarios, so as to solve the optimal layout plan, achieve a balance between defense effect and economy, and effectively reduce the investment cost of protection resources while ensuring system safety.

[0184] In an exemplary embodiment, after performing attack simulation on the constructed power system model based on each attack simulation scenario and obtaining the attack impact analysis result of each attack simulation scenario, the method further includes:

[0185] For each attack simulation scenario, when the target attack line triggers tripping protection and the number of lines that trigger tripping protection is greater than or equal to a preset line number threshold, the attack simulation scenario is marked as a high threat scenario.

[0186] In practical applications, for each attack simulation scenario, determine the power flow change caused by the attack simulation:

[0187]

[0188] in, is the power flow distribution factor matrix, and are the node voltage amplitude vector and the demand voltage vector respectively, and are the changes in power generation and load power respectively. In most attack scenarios, the communication architecture is limited so that , so the formula simplifies to:

[0189]

[0190] Determine whether the line triggers trip protection:

[0191]

[0192] in, For line The power flow (power flow), For line Rated power capacity, is the trip protection threshold, (usually in the range ).

[0193] The tripping protection is triggered on the target attack line, and the line number threshold that triggers the tripping protection (for example, the line number threshold is 2), that is, the attack simulation scenario meets and triggering tripping of two or more lines ( ), marking the attack simulation scenario as a high-threat scenario ( ). Otherwise, it is marked as a non-high threat scenario.

[0194] In other embodiments, after adding a high-threat scenario mark to each scenario, all high-threat scenarios are screened out, and based on the attack impact analysis results of the high-threat scenarios, critical power assets in the power system are identified. Specifically, referring to the above-mentioned steps in the embodiment of identifying critical power assets from power assets in the power system according to the attack impact analysis results of each attack simulation scenario, no further description is given here.

[0195] In this embodiment, according to the number of triggered tripping protections of the line in the attack impact analysis results of each attack simulation scenario, high threat scenarios are screened out, which is conducive to identifying critical buses according to high threat scenarios, thereby reducing the amount of calculation and improving the efficiency of identifying critical buses.

[0196] Considering the low security of the power system, encrypted measurement terminals and optimized layout methods are used to ensure that the power system maintains safe and stable operation in the event of attacks, failures or other abnormal situations. Especially in the face of network attacks with the potential for continuous failures, such as false data injection and load redistribution attacks, optimizing the layout of encrypted measurement terminals and improving the system's ability to identify, monitor and respond to potential threats can greatly enhance the resilience of the power system. By improving defense capabilities, not only can the shutdown and catastrophic accidents of the power system be avoided, but the economy and reliability of the system can also be improved, thereby providing protection for national power security and social stability.

[0197] In the prior art, there are deficiencies in the identification and precise positioning of key assets, the lack of dynamic adjustment capabilities of defense strategies, the difficulty in coping with complex scenarios, the lack of complexity of network modeling and optimization methods, and the failure to effectively balance economic efficiency and safety in the detection and defense of load redistribution attacks in the field of power system security. This application proposes an optimization method for the layout of encrypted measurement terminals for load redistribution attacks. Through attack simulation, the key assets most susceptible to load redistribution attacks are accurately identified, and they are used as the core basis for the optimization of the layout of encrypted measurement terminals, thereby improving the coverage capability of high-risk areas and solving the deficiencies of the prior art in asset identification and positioning. Based on the real-time changes in the operating status of the power system and the attack scenario, the layout of the encrypted measurement terminals can be dynamically adjusted to ensure that the system is always in the optimal defense state, and the adaptability in complex scenarios is significantly improved. In addition, by constructing a two-layer optimization model, this application combines system security constraints with economic dispatch requirements, realizes the optimization of the overall defense plan at the high level, and adjusts the configuration of the encrypted measurement terminals according to real-time data at the low level to ensure the feasibility and efficiency of the optimized layout plan. This application provides a more accurate, dynamic, economical and efficient technical means for defending against load redistribution attacks. In order to make a clearer description of the encryption measurement terminal layout optimization method provided by the present application, a specific embodiment is described below, and the specific embodiment includes the following steps:

[0198] S1, acquiring attack scenario simulation data of the power system, the attack scenario simulation data including an operating point set, a target attack line set, a load deviation amplitude set, and a bus number set.

[0199] S2, perform data verification on the attack scenario simulation data, and for the attack scenario simulation data that passes the verification, execute: extract a parameter from the operating point set, the target attack line set, the load deviation amplitude set and the bus number set respectively, and combine them to obtain multiple groups of parameter combinations. For each parameter combination, solve the pre-constructed two-layer optimization model according to the parameter combination to generate an attack simulation scenario. The upper optimization function of the two-layer optimization model is constructed based on the power flow change of the target attack line, and the lower optimization function is constructed based on the power generation cost.

[0200] For each attack simulation scenario, execute S3 to S5:

[0201] S3, according to the operating point in the attack simulation scenario, loads the system state of the power system model, adjusts the injection power of the target attack line in the power system model according to the load deviation amplitude in the attack simulation scenario, and adjusts the injection power of the corresponding number of buses in the power system model according to the number of buses in the attack simulation scenario to simulate a load redistribution attack on the power system.

[0202] S4, determine the power flow load of the line in the power system, evaluate the failure of the line in the power system according to the power flow load of the line and the preset line tripping protection evaluation conditions, and obtain the line failure evaluation result, and judge whether a cascading failure will occur in the attack simulation scenario according to the line failure evaluation result, and obtain the cascading failure judgment result of the attack simulation scenario, and integrate the line failure evaluation result and the cascading failure judgment result to obtain the attack impact analysis result of the attack simulation scenario.

[0203] S5, when the target attack line triggers tripping protection and the number of lines that trigger tripping protection is greater than or equal to a preset line number threshold, marking the attack simulation scenario as a high threat scenario.

[0204] S6. According to the attack impact analysis results of each attack simulation scenario, the busbars affected by the attack are screened out from the power system. For each busbar, the impact frequency and dynamic power flow change of the busbar between each attack simulation scenario are determined. According to the impact frequency and dynamic power flow change of the busbar, the fault risk level of the busbar is determined.

[0205] S7, based on the impact frequency and dynamic power flow change of each bus, select the key bus from the bus; integrate the impact frequency, dynamic power flow change and fault risk level of the key bus to obtain the asset information of the key bus.

[0206] S8, with the goal of minimizing costs and giving priority to protecting critical busbars with high fault risks, is based on the asset information of key power assets, global observation constraints, key line coverage constraints and high-risk busbar protection constraints. The pre-constructed optimization objective function is solved through mixed integer linear programming to obtain the optimal solution. The optimization objective function is constructed based on the installation cost of encrypted measurement terminals, the impact frequency of critical buses and the power flow change of critical buses. Among them, the global observation constraint enables each bus to meet the preset observation requirements, the critical route coverage constraint is used to make the bus on the critical line observed, and the high-risk busbar protection constraint is used to constrain the layout of encrypted measurement terminals on high-risk buses.

[0207] S9, based on the optimal solution, determine the layout plan of the encrypted measurement terminals of the power system.

[0208] For example, a load redistribution attack (LRA) simulation platform can be built in advance based on the IEEE 30-node standard system to study the impact of load redistribution attacks and the identification of key power assets, as well as to optimize the layout strategy of encrypted measurement terminals. The IEEE 30-node system contains 30 nodes, 41 transmission lines, and 6 generators. The simulation is completed using MATLAB and Matpower7.1 on a high-performance computing device equipped with 8GB of memory and a 5-core processor to ensure the accuracy of the analysis results and the complexity of the simulation scenario.

[0209] In the attack simulation scenario generation phase, a total of 4,000 attack simulation scenarios were generated, of which 1,162 scenarios had the potential for continuous failures (cascading failures). The simulation parameters in the attack simulation data were set as follows: the load deviation range was 5%-50%, the system load level was 100%-150%, and the number of manipulated buses was between 3-20. Through comprehensive analysis, two typical attack simulation scenarios were selected as the research focus. Under the conditions of a load level of 100% and a load deviation of 50%:

[0210] 1. The LR-1 attack affected three lines, 21-22, 15-23 and 25-27, causing a total of three lines to trip, with a total power flow change of 70.6MW (megawatts);

[0211] 2. The LR-2 attack affected two lines, 21-22 and 15-23, causing two lines to trip and a total power flow change of 51.8MW.

[0212] Further analysis of line failures showed that LR-2 triggered a more severe cascade fault despite having fewer tripped lines. Lines 10-22, 22-24, and 23-24 tripped in succession in the subsequent stages, with a cumulative power flow change of 92.3MW. During the fault propagation process, lines 21-22 and 15-23 first reached the tripping protection threshold, with power flows exceeding 140.36% and 150.98% of the rated capacity, respectively. Next, the power flow of line 10-22 rose sharply to 222.81% of the rated capacity, and the power flows of lines 22-24 and 23-24 reached 145.51% and 233.57%, respectively, eventually leading to the gradual failure of these lines.

[0213] Based on the analysis of power transfer distribution factor (PTDF), high-impact busbar groups with significant impact on key lines are identified as follows:

[0214] 1. Line 6-8: affected by busbars 8, 28, 27, 29 and 30;

[0215] 2. Line 15-18: affected by busbars 18, 19, 20, 15 and 14;

[0216] 3. Line 21-22: affected by busbars 21, 22, 24, 25 and 26;

[0217] 4. Line 15-23: affected by busbars 23, 24, 15, 25 and 26;

[0218] 5. Line 25-27: affected by busbars 25, 26, 27, 29 and 30;

[0219] 6. Line 27-30: Mainly affected by bus No. 30 and No. 29.

[0220] In order to evaluate the effect of the layout of encrypted measurement terminals, three different layout strategies were designed, and the installation cost of encrypted measurement terminals was quantitatively analyzed. Assuming that the installation cost of a single-channel encrypted measurement terminal is 4,000 yuan, as the number of channels increases, the cost of a five-channel encrypted measurement terminal increases to 8,000 yuan:

[0221] Strategy 1: Deploy PMUs at all 17 key bus locations, including buses 3, 5, 6, 8, 10, 11, 12, 15, 18, 19, 21, 22, 23, 25, 26, 27, and 30, to achieve maximum coverage;

[0222] Strategy 2: Deploy PMUs only on 11 high-fault-risk buses, including buses 3, 5, 11, 13, 15, 16, 19, 22, 26, 28, and 29, to ensure monitoring capabilities in key areas while controlling costs;

[0223] Strategy 3: Combining economy and defense effectiveness, dynamically adjust the layout of encrypted measurement terminals through a two-layer optimization model to achieve optimal cost-effectiveness.

[0224] The simulation results are as follows Figures 6 to 8 As shown:

[0225] Figure 6This is a multi-dimensional visualization diagram of the frequency distribution of the load redistribution attack on critical lines. The figure shows the frequency distribution of 6 groups of critical lines (6-8, 15-18, 21-22, 15-23, 25-27, 27-30) in the attack simulation scenario, which is presented in two visualization methods: a star radar chart and a 3D pie chart. It can be seen from the figure that: 1) The attack frequencies of lines 15-23 and 21-22 are the highest, 303 times and 296 times respectively, and they are the most vulnerable critical lines; 2) The power frequency of line 6-8 is 250 times; 3) Line 25-27 is at a medium level, with an attack frequency of 150 times; 4) Lines 15-18 and 27-30 have the lowest attack frequencies, both 82 times.

[0226] Figure 7 This is a comparative analysis chart of system load estimation strategies. The figure shows the system load estimation data under three different situations: the estimated load of the unencrypted PMU, the benchmark load, and the estimated load of the encrypted PMU. Through data comparison, it can be found that: 1) There is a significant deviation between the load estimation value of the unencrypted PMU and the benchmark load, and the maximum deviation can reach about 8kW (such as at data point 8); 2) After the encrypted PMU is deployed, the fluctuation of the system load estimation is significantly reduced, and the estimated value is closer to the benchmark load, indicating that the deployment of the encrypted PMU can effectively improve the accuracy of the system load estimation; 3) Among the 30 test data points, the estimation error of the encrypted measurement terminal PMU solution is always maintained at a low level, with high stability and reliability. It can be seen that the encrypted measurement terminal has a significant advantage in improving the accuracy of system load estimation.

[0227] Figure 8 This is a comparative analysis chart of the power flow load rate of power system lines based on the optimized PMU layout. The figure shows the comparison data of the power flow load rate (power flow / rated capacity) of 41 transmission lines under three conditions: normal working conditions, non-optimized encrypted PMU layout, and optimized encrypted PMU layout. It can be seen from the figure that when the encrypted measurement terminal layout is not optimized, the load rate of many lines exceeds the protection threshold Γ=1.1, and there is a high overload risk; after the optimized layout of the encrypted measurement terminal, the load rate of all lines is controlled between 0.92-0.99, which is significantly lower than the protection threshold Γ. This verifies that the optimized layout of the encrypted measurement terminal can effectively monitor and control the changes in line power flow, so that it always remains within the safe operating range, thereby greatly reducing the risk of cascading failures in the system. In addition, the figure also clearly identifies the load rate distribution and protection threshold limits under three working conditions through bar charts of different colors and red dotted lines, intuitively demonstrating the effectiveness of the optimized layout of the encrypted measurement terminal.

[0228] The above results show that the encrypted PMU optimization layout method proposed in the present invention can comprehensively cover key power assets, significantly improve the system's ability to resist load redistribution attacks, and at the same time achieve the optimization of defense costs.

[0229] It can be seen from the above technical solutions that the present invention has the following advantages:

[0230] First, based on the characteristics of load redistribution attack (LRA), the present invention analyzes the vulnerability of key buses and lines in the power system and establishes a two-layer optimization model to achieve accurate identification of key assets in the system and effective positioning of the affected area. Compared with the traditional solution that simply relies on detection methods such as load change and state estimation residual, this method can better guide the layout of PMUs and improve the protection coverage effect of high-risk areas.

[0231] Second, based on the real-time operating status of the power system, the present invention realizes the dynamic adjustment of the encrypted PMU layout scheme by constructing an optimization objective function that takes into account the observability of the system and the protection requirements of key lines. This method introduces busbar influence frequency and dynamic power flow changes as key indicators, enabling the PMU layout to respond to system state changes in a timely manner, significantly improving the system's adaptability and defense effect in complex attack scenarios.

[0232] Third, based on the idea of ​​two-layer optimization modeling, the present invention achieves a balance between defense effect and economy by optimizing the overall defense solution at a high level and adjusting the PMU configuration according to real-time data at a low level. This method comprehensively considers multiple dimensions such as PMU installation cost, system global observability requirements, and key asset protection, effectively reducing the investment cost of protection resources while ensuring system security.

[0233] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0234] In an exemplary embodiment, Fig. 9As shown, an encryption measurement terminal layout optimization device 600 is provided, including: a data acquisition module 610, a scenario construction module 620, a simulated attack module 630, an asset identification module 640 and a layout scheme determination module 650, wherein:

[0235] A data acquisition module 610 is used to acquire attack scenario simulation data of the power system;

[0236] A scenario construction module 620, configured to construct multiple attack simulation scenarios based on attack scenario simulation data;

[0237] The attack simulation module 630 is used to perform attack simulation on the constructed power system model based on each attack simulation scenario to obtain the attack impact analysis result of each attack simulation scenario;

[0238] The asset identification module 640 is used to identify the key power assets in the power system according to the attack impact analysis results of each attack simulation scenario, and obtain asset information of the key power assets, wherein the key power assets include key buses;

[0239] The layout scheme determination module 650 is used to solve the pre-constructed optimization objective function based on the asset information of key power assets and preset constraints to obtain the optimal solution with the goal of minimizing costs and giving priority to protecting key buses with high fault risks. The optimization objective function is constructed based on the installation cost of the encrypted measurement terminal, the impact frequency of the key bus and the power flow change of the key bus; based on the optimal solution, the layout scheme of the encrypted measurement terminals of the power system is determined.

[0240] In an exemplary embodiment, the scenario construction module 620 is also used to perform data verification on the attack scenario simulation data; for the attack scenario simulation data that has passed the verification, the following steps are performed: a parameter is extracted from the operating point set, the target attack line set, the load deviation amplitude set and the bus number set, and they are combined to obtain multiple groups of parameter combinations; for each parameter combination, a pre-constructed two-layer optimization model is solved according to the parameter combination to generate an attack simulation scenario, wherein the upper optimization function of the two-layer optimization model is constructed based on the power flow change of the target attack line, and the lower optimization function is constructed based on the power generation cost.

[0241] In an exemplary embodiment, the simulated attack module 630 is also used to load the system state of the power system model according to the operating point in the attack simulation scenario for each attack simulation scenario, adjust the injection power of the target attack line in the power system model according to the load deviation amplitude in the attack simulation scenario, and adjust the injection power of the corresponding number of buses in the power system model according to the number of buses in the attack simulation scenario to simulate a load redistribution attack on the power system; determine the power flow load of the line in the power system model, and evaluate the failure of the line in the power system model according to the power flow load of the line and the preset line tripping protection evaluation conditions to obtain a line failure evaluation result; determine whether a cascading failure will occur in the attack simulation scenario according to the line failure evaluation result, and obtain a cascading failure judgment result of the attack simulation scenario; integrate the line failure evaluation result and the cascading failure judgment result to obtain an attack impact analysis result of the attack simulation scenario.

[0242] In an exemplary embodiment, the asset identification module 640 is also used to screen out buses affected by the attack from the power system model based on the attack impact analysis results of each attack simulation scenario; for each bus, determine the impact frequency and dynamic power flow change of the bus between each attack simulation scenario, and determine the fault risk level of the bus based on the impact frequency and dynamic power flow change of the bus; screen out key buses from the buses based on the impact frequency and dynamic power flow change of each bus; integrate the impact frequency, dynamic power flow change and fault risk level of the key bus to obtain the asset information of the key bus.

[0243] In an exemplary embodiment, the layout scheme determination module 650 is also used to solve the pre-constructed optimization objective function through mixed integer linear programming to obtain the optimal solution based on the asset information of key power assets, global observation constraints, key line coverage constraints and high-risk bus protection constraints.

[0244] In an exemplary embodiment, the encrypted measurement terminal layout optimization device 600 also includes a high-threat scenario marking module 660, which is used to mark the attack simulation scenario as a high-threat scenario for each attack simulation scenario when the target attack line triggers tripping protection and the number of lines triggering tripping protection is greater than or equal to a preset line number threshold.

[0245] Each module in the above-mentioned encrypted measurement terminal layout optimization device 600 can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0246] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Fig.10 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a method for optimizing the layout of encrypted measurement terminals is implemented.

[0247] Those skilled in the art will understand that Fig.10 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0248] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the steps in any one of the above encryption measurement terminal layout optimization method embodiments are implemented.

[0249] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in any one of the above encryption measurement terminal layout optimization method embodiments are implemented.

[0250] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in any one of the above encryption measurement terminal layout optimization method embodiments are implemented.

[0251] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.

[0252] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to a memory, a database or other medium used in the embodiments provided in this application may include at least one of a non-volatile memory and a volatile memory. Non-volatile memory may include a read-only memory (ROM), a tape, a floppy disk, a flash memory, an optical memory, a graphene memory, etc. Volatile memory may include a random access memory (RAM) or an external cache memory, etc. As an illustration and not limitation, RAM may be in various forms, such as a static random access memory (SRAM) or a dynamic random access memory (DRAM). The database involved in the embodiments provided in this application may include at least one of a relational database and a non-relational database. A non-relational database may include a distributed database based on a blockchain, etc., but is not limited thereto. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but is not limited thereto.

[0253] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0254] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.

Claims

1. A method for optimizing the layout of encrypted measurement terminals, characterized in that: The method comprises: Obtain attack scenario simulation data for power systems; Based on the attack scenario simulation data, construct multiple attack simulation scenarios; Perform attack simulation on the constructed power system model based on each of the attack simulation scenarios to obtain attack impact analysis results of each of the attack simulation scenarios; According to the attack impact analysis results of each of the attack simulation scenarios, critical power assets in the power system are identified, and asset information of the critical power assets is obtained, wherein the critical power assets include critical buses; With the goal of minimizing costs and giving priority to protecting critical buses with high failure risks, a pre-constructed optimization objective function is solved based on the asset information of the critical power assets and preset constraints to obtain an optimal solution. The optimization objective function is constructed based on the installation cost of the encrypted measurement terminal, the impact frequency of the critical bus, and the power flow change of the critical bus; Based on the optimal solution, a layout plan of encrypted measurement terminals of the power system is determined.

2. The method according to claim 1, characterized in that The attack scenario simulation data includes an operating point set, a target attack line set, a load deviation amplitude set, and a bus number set; The constructing a plurality of attack simulation scenarios based on the attack scenario simulation data comprises: Performing data verification on the attack scenario simulation data; The following processing is performed on the attack scenario simulation data that has passed the verification: Extracting a parameter from the operating point set, the target attack line set, the load deviation amplitude set, and the bus number set respectively, and combining them to obtain multiple groups of parameter combinations; For each of the parameter combinations, a pre-constructed two-layer optimization model is solved according to the parameter combination to generate an attack simulation scenario, wherein the upper optimization function of the two-layer optimization model is constructed based on the power flow change of the target attack line, and the lower optimization function is constructed based on the power generation cost.

3. The method according to claim 2, characterized in that The attack simulation is performed on the constructed power system model based on each of the attack simulation scenarios to obtain the attack impact analysis results, including: For each of the attack simulation scenarios, according to the operating point in the attack simulation scenario, the system state of the power system model is loaded, according to the load deviation amplitude in the attack simulation scenario, the injection power of the target attack line in the power system model is adjusted, according to the number of buses in the attack simulation scenario, the injection power of the corresponding number of buses in the power system model is adjusted to simulate a load redistribution attack on the power system; Determine the power flow load of the line in the power system model, and evaluate the failure of the line in the power system model according to the power flow load of the line and a preset line trip protection evaluation condition to obtain a line failure evaluation result; According to the line failure assessment result, determine whether a cascading failure will occur in the attack simulation scenario, and obtain a cascading failure determination result of the attack simulation scenario; The line failure assessment result and the cascade fault judgment result are integrated to obtain the attack impact analysis result of the attack simulation scenario.

4. The method according to claim 3, characterized in that The step of identifying key power assets from the power assets of the power system according to the attack impact analysis results of each of the attack simulation scenarios and acquiring asset information of the key power assets includes: According to the attack impact analysis results of each of the attack simulation scenarios, the busbars affected by the attack are screened out from the power system model; For each of the buses, determining the impact frequency and dynamic power flow change of the bus between the attack simulation scenarios, and determining the fault risk level of the bus according to the impact frequency and dynamic power flow change of the bus; Selecting key buses from the buses according to the influence frequency and dynamic power flow change of each bus; The impact frequency, dynamic power flow change and fault risk level of the key bus are integrated to obtain the asset information of the key bus.

5. The method according to any one of claims 1 to 4, characterized in that: The preset constraints include global observation constraints, key line coverage constraints and high-risk bus protection constraints. The global observation constraints enable each bus to meet the preset observation requirements. The key line coverage constraints are used to enable the bus on the key line to be observed. The high-risk bus protection constraints are used to constrain the arrangement of encrypted measurement terminals on the high-risk bus. The method of solving the pre-built optimization objective function based on the asset information of the key power assets and the preset constraints to obtain the optimal solution of the function includes: Based on the asset information of the key power assets, the global observation constraints, the key line coverage constraints and the high-risk bus protection constraints, the pre-constructed optimization objective function is solved by mixed integer linear programming to obtain the optimal solution.

6. The method according to any one of claims 2 to 4, characterized in that: After performing attack simulation on the constructed power system model based on each of the attack simulation scenarios and obtaining the attack impact analysis results of each of the attack simulation scenarios, the method further includes: For each of the attack simulation scenarios, when the target attack line triggers tripping protection and the number of lines that trigger tripping protection is greater than or equal to a preset line number threshold, the attack simulation scenario is marked as a high threat scenario.

7. An encryption measurement terminal layout optimization device, characterized in that: The device comprises: A data acquisition module, used to acquire attack scenario simulation data of the power system; A scenario construction module, used to construct multiple attack simulation scenarios based on the attack scenario simulation data; A simulation attack module, used to perform attack simulation on the constructed power system model based on each of the attack simulation scenarios, and obtain attack impact analysis results of each of the attack simulation scenarios; An asset identification module, used to identify key power assets in the power system according to the attack impact analysis results of each attack simulation scenario, and obtain asset information of the key power assets, wherein the key power assets include key buses; A layout scheme determination module is used to solve a pre-constructed optimization objective function based on the asset information of the key power assets and preset constraints to obtain an optimal solution with the goal of minimizing costs and giving priority to protecting key buses with high fault risks. The optimization objective function is constructed based on the installation cost of the encrypted measurement terminal, the impact frequency of the key bus, and the power flow change of the key bus; based on the optimal solution, determine the layout scheme of the encrypted measurement terminals of the power system.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.