Communication management method based on wide-narrow fusion sink node equipment
By adopting a communication management method based on wide-narrow convergence node equipment in the substation, the problem of inconsistent wireless networking protocols in the prior art is solved, secure access and unified management of equipment are realized, and communication security and management efficiency are improved.
Patent Information
- Application Number
- CN202510712685.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-05-30
AI Technical Summary
The existing technology has the problem of inconsistent wireless network communication protocols in substation wireless networking, which leads to high management difficulties, high network cost, relatively complex technology, and security risks, and is not suitable for scenarios with strict communication requirements.
The communication management method based on wide-narrow convergence node equipment is adopted, and through the wide-narrow band access controller and the authentication server, the device registration, certificate application and distribution, communication verification and connection authorization are realized to ensure the secure access of the equipment to be accessed.
It realizes unified access to broadband and narrowband equipment, reduces networking costs and management difficulties, improves communication security, and is suitable for substation scenarios with high communication requirements.
Smart Images

Figure CN120224341A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication, and in particular, to a communication management method based on a wide and narrow fusion aggregation node device. Background Art
[0002] Under the situation of the accelerated development of the new power system, the contradiction between the shortage of grass-roots equipment management personnel and the continuous growth of the equipment scale has become increasingly prominent. To solve the contradiction between the shortage of operation and maintenance personnel and the increasing equipment maintenance volume, substations rely on equipment such as unmanned aerial vehicles, robots, and intelligent sensing terminals to replace some of the substation operation and maintenance work of operation and maintenance personnel, greatly improving the overall operation and maintenance efficiency of substations.
[0003] However, in the aspect of substation wireless networking, due to the large number of wireless device manufacturers and complex interfaces, there is a problem of non-uniform wireless network communication protocols, and each manufacturer independently networks according to its own network requirements. The management of this networking mode is difficult, the networking cost is high, and the technology is relatively complex. CN116436943A discloses a communication system and method applied to the Internet of Things for power transmission and transformation equipment, including a wide and narrowband fusion core network, a fusion gateway, an access controller, an access node, an aggregation node, and a sensor terminal that are sequentially communicatively connected; a broadband board, a broadband independent antenna, a narrowband board, and a narrowband independent antenna are integrated in the access node; the sensor terminals are divided into wired sensor terminals and wireless sensor terminals; the number of the aggregation nodes, wired sensor terminals, and wireless sensor terminals is set to be multiple; the access node and the aggregation node are electrically connected through a wireless communication link or a wired communication link, and a suitable network communication method is selected according to service requirements and network quality to ensure the reliable and secure transmission of the Internet of Things wide and narrow networks, improve the utilization rate of network resources, and optimize the transmission performance of power transmission and transformation equipment. Although this application gives a method for compatibly connecting broadband devices and narrowband devices, this communication method has certain security risks and is not suitable for scenarios with relatively strict communication requirements in substations. The management of various devices is also relatively chaotic, and it is difficult to ensure communication security. Summary of the Invention
[0004] The purpose of the present invention is to provide a communication management method based on a wide and narrow fusion aggregation node device to solve the above-mentioned defects existing in the prior art.
[0005] The purpose of the present invention can be achieved by the following technical solutions: According to a first aspect of the present invention, there is provided a communication management method based on a wide - narrowband integrated convergence node device, which is used to implement communication connections between a wide - narrowband access controller, an authentication server, and a wide - narrowband integrated convergence node device, including device registration, certificate application and distribution, communication verification, and connection authorization. Through the cooperation of the wide - narrowband access controller and the authentication server, it is ensured that the device to be accessed can safely access the wide - narrowband integrated convergence node device.
[0006] Optionally, the method includes the following steps: In response to the received second device registration request sent by the wide - narrowband integrated convergence node device, the wide - narrowband access controller parses the second device registration request to obtain a first device registration request and the convergence node certificate of the wide - narrowband integrated convergence node device. The first device registration request is a request sent by the device to be accessed to the wide - narrowband integrated convergence node device and includes the device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in a substation. The wide - narrowband access controller sends the convergence node certificate to the authentication server. In response to the received first authentication success message sent by the authentication server after authenticating the convergence node certificate, the wide - narrowband access controller registers the device to be accessed according to the device information and applies to the authentication server for the device certificate of the device to be accessed. In response to the received device certificate made by the authentication server according to the device information, the wide - narrowband access controller sends the device certificate to the device to be accessed through the wide - narrowband integrated convergence node device. In response to the received communication verification request sent by the wide - narrowband integrated convergence node device, the wide - narrowband access controller parses the communication verification request to obtain the device certificate and the convergence node certificate of the device to be accessed, and sends the device certificate and the convergence node certificate of the device to be accessed to the authentication server for certificate authentication. In response to the received second authentication success message sent by the authentication server after authenticating the device certificate and the convergence node certificate, the wide - narrowband access controller sends an allow - connection message to the wide - narrowband integrated convergence node device so that the device to be accessed can access the wide - narrowband integrated convergence node device and become an access device.
[0007] Optionally, if the device to be accessed is a broadband device, the wide - narrowband integrated convergence node device receives the first device registration request sent by the device to be accessed according to the broadband wireless communication module; if the device to be accessed is a narrowband device, the wide - narrowband integrated convergence node device receives the first device registration request sent by the device to be accessed according to the narrowband wireless communication module.
[0008] Optionally, in response to a communication connection request received from a device to be accessed, the wide-narrowband fusion aggregation node device generates a communication verification request based on the communication connection request and the aggregation node certificate, and sends the communication verification request to the wide-narrowband access controller. The communication connection request includes the device certificate of the device to be accessed.
[0009] Optionally, after receiving the permission connection message, the wide-narrowband fusion aggregation node device performs a key negotiation with the device to be accessed to determine a session key.
[0010] Optionally, the session key includes the private key and public key of the wide-narrowband fusion aggregation node device. The method further includes: In response to the encrypted uplink communication data received from the access device, the wide-narrowband fusion aggregation node device decrypts the encrypted uplink communication data according to the private key of the wide-narrowband fusion aggregation node device to obtain the data content of the uplink communication data. The encrypted uplink communication data is encrypted by the access device according to the public key of the wide-narrowband fusion aggregation node device.
[0011] Optionally, the session key includes the private key and public key of the access device. The method further includes: In response to the encrypted downlink communication data received from the wide-narrowband fusion aggregation node device, the access device decrypts the encrypted downlink communication data according to the private key of the access device to obtain the data content of the downlink communication data. The encrypted downlink communication data is encrypted by the wide-narrowband fusion aggregation node device according to the public key of the access device.
[0012] Optionally, the access device includes wideband devices and narrowband devices. The wideband devices include remote inspection devices and operation and maintenance management devices. The narrowband devices include on-line monitoring devices. The remote inspection devices have a third security level, the operation and maintenance management devices have a second security level, and the narrowband devices have a first security level. The key negotiation frequency of the access devices with the third security level is higher than that of the devices with the second security level, and the key negotiation frequency of the access devices with the second security level is higher than that of the devices with the first security level.
[0013] Optionally, the access device includes wideband devices and narrowband devices. The wideband devices include remote inspection devices and operation and maintenance management devices. The narrowband devices include on-line monitoring devices. The remote inspection data sent by the remote inspection devices has a third-level priority, the operation and maintenance management data sent by the operation and maintenance management devices has a second-level priority, and the on-line monitoring data sent by the on-line detection devices has a first-level priority. An uplink data transmission message queue is provided in the wide-narrowband fusion aggregation node device. The method further includes: In response to receiving uplink communication data of multiple priorities, the wide - narrowband fusion aggregation node device arranges the remote inspection data of the third priority at the forefront of the uplink data transmission message queue; arranges the operation and maintenance management data of the second priority behind the remote inspection data; arranges the online monitoring data of the third priority behind the operation and maintenance management data; Each time, one piece of uplink communication data is taken from the head of the uplink data transmission message queue for processing; If there are multiple uplink communication data for each priority, they are sorted in the order of reception time within each priority.
[0014] Optionally, in response to receiving the device status of the access device collected by the wide - narrowband access controller, the wide - narrowband access controller manages the access device according to the device status, where the device status includes device location, device power, and device fault information.
[0015] Optionally, the access device is adapted to move in a substation to inspect the main equipment of the substation. The method further includes: The wide - narrowband access controller obtains the movement route of the access device in the substation, determines the wide - narrowband fusion aggregation node devices to be connected at each point on the movement route, and obtains a set of wide - narrowband fusion aggregation node devices to be connected; The wide - narrowband access controller sends the device certificate and the aggregation node certificates of each wide - narrowband fusion aggregation node device in the set of wide - narrowband fusion aggregation node devices to the authentication server, so that the authentication server performs certificate authentication, and after the authentication passes, writes the aggregation node device ID of each wide - narrowband fusion aggregation node device in the set of wide - narrowband fusion aggregation node devices into the device information of the device certificate to generate a multi - node access device certificate; In response to receiving the multi - node access device certificate made by the authentication server according to the device certificate after the authentication passes, the wide - narrowband access controller writes the aggregation node device ID of each wide - narrowband fusion aggregation node device in the set of wide - narrowband fusion aggregation node devices into the device information of the access device in the registration information table.
[0016] Optionally, the determination of the wide - narrowband fusion aggregation node devices to be connected at each point on the movement route includes: Dividing the movement route of the access device in the substation according to a predetermined step size to obtain multiple route nodes on the predetermined route, and the distance between adjacent two route nodes is the predetermined step size; Determining the wide - narrowband fusion aggregation node device with the maximum actual signal strength at each route node as the wide - narrowband fusion aggregation node device to be connected on the movement route, and obtaining a set of wide - narrowband fusion aggregation node devices to be connected on the movement route.
[0017] According to another aspect of the present invention, there is also provided a communication management system based on a wide-narrowband fusion convergence node device. The system includes a wide-narrowband access controller, an authentication server and a wide-narrowband fusion convergence node device communicatively connected to the wide-narrowband access controller. The wide-narrowband fusion convergence node device is adapted to generate a device registration second request according to the device registration first request and the convergence node certificate after receiving the device registration first request, and send it to the wide-narrowband access controller. The device registration first request is a request sent by a device to be accessed to the wide-narrowband fusion convergence node device, and the device registration first request includes device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in a substation. The wide-narrowband access controller is adapted to parse the received device registration second request in response to receiving it, obtain the device registration first request and the convergence node certificate of the wide-narrowband fusion convergence node device, and send the convergence node certificate to the authentication server. The authentication server is adapted to perform certificate authentication on the convergence node certificate. If the authentication is successful, it sends a first authentication success message to the wide-narrowband access controller. The wide-narrowband access controller is also adapted to register the device to be accessed according to the device information and apply to the authentication server for a device certificate of the device to be accessed. The authentication server is also adapted to generate a device certificate according to the device information of the device to be accessed. The wide-narrowband fusion convergence node device is also adapted to generate a communication verification request according to the communication connection request and the convergence node certificate after receiving the communication connection request sent by the access device, and send it to the wide-narrowband access controller. The communication connection request includes the device certificate. The wide-narrowband access controller is also adapted to parse the received communication verification request sent by the wide-narrowband fusion convergence node device in response to receiving it, obtain the device certificate of the device to be accessed and the convergence node certificate, and send the device certificate of the device to be accessed and the convergence node certificate to the authentication server for certificate authentication. The authentication server is also adapted to perform certificate authentication on the device certificate and the convergence node certificate. If the authentication is successful, it sends a second authentication success message to the authentication server. The wide-narrowband access controller is also adapted to send an allow connection message to the wide-narrowband fusion convergence node device in response to receiving the second authentication success message sent by the authentication server, so that the device to be accessed can access the wide-narrowband fusion convergence node device and become an access device.
[0018] Compared with the prior art, the present invention has the following beneficial effects: The present invention proposes a communication management method based on a wide-narrowband integrated convergence node device. The wide-narrowband integrated convergence node device can simultaneously access broadband devices and narrowband devices. When performing communication access, there is no need to separately network each type of device. The wide-narrowband integrated convergence node device uniformly receives the first device registration request of the device to be accessed, and the wide-narrowband access controller processes the device registration request generated by the wide-narrowband integrated convergence node device, registers the device to be accessed, and applies to the authentication server for a device certificate to complete the access preparation for the device to be accessed. The wide-narrowband access controller also authenticates the convergence node certificate of the wide-narrowband integrated convergence node device to ensure the security during the registration of the device to be accessed. When the device to be accessed is accessing, both the device certificate and the convergence node certificate are authenticated simultaneously to achieve the access of the device to be accessed and the security during access. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 FIG. is a schematic structural diagram of wireless networking of multiple types of devices in the prior art; Figure 2 FIG. is a schematic diagram of substation broadband integrated wireless networking according to an exemplary embodiment of the present invention; Figure 3 FIG. is a schematic diagram of a wide-narrowband integrated convergence node device according to an exemplary embodiment of the present invention; Figure 4 FIG. is a schematic diagram of a wide-narrowband integrated convergence node device according to another exemplary embodiment of the present invention; Figure 5 FIG. is a schematic diagram of substation broadband integrated wireless networking according to another exemplary embodiment of the present invention; Figure 6 FIG. is a flowchart of the communication management method according to the present invention; Figure 7 FIG. is a structural block diagram of a computing device according to an exemplary embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. This embodiment is implemented on the premise of the technical solution of the present invention, and gives detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to the following embodiments.
[0021] Embodiment 1 Figure 1 FIG. shows a schematic structural diagram of wireless networking of multiple types of devices in the prior art. As Figure 1 shown, narrowband devices and broadband devices are deployed in a substation. The narrowband devices and broadband devices respectively use different methods for wireless networking.
[0022] Among them, narrowband devices are connected to the first network server through edge physical proxy devices, and then connected to the corresponding first backend server through the first network server. When narrowband devices are connected to edge physical proxy devices, narrowband communication is adopted. Narrowband communication mainly uses low-frequency signals to transmit data, with a lower transmission rate than broadband signals, but it can penetrate obstacles and has a better coverage range in long-distance situations. Narrowband communication can be specifically implemented as communication technologies such as NB-IoT, LoRa, Sigfox, etc. Narrowband devices can be specifically implemented as sensor devices, and the present invention does not limit the specific implementation manner of narrowband devices.
[0023] According to an embodiment of the present invention, the edge physical proxy device can be specifically implemented as an edge device in a narrowband communication network to implement functions such as network management and data forwarding. The first network server is used to forward the narrowband data received from narrowband devices to the first backend server.
[0024] When broadband devices are connected to a router, broadband communication is adopted. Broadband communication mainly uses high-frequency signals to transmit data, with a very high transmission rate, but a limited coverage range. Broadband communication can be specifically implemented as communication technologies such as 4G, 5G, WiFi, etc. Broadband devices send broadband data to the second backend server through a router, a switch, and a second network server. Broadband devices can be specifically implemented as devices that use broadband for communication. The present invention does not limit the specific implementation manner of broadband devices.
[0025] Figure 2 The schematic diagram of the broadband integrated wireless networking of a substation according to an exemplary embodiment of the present invention is shown. As Figure 2 shown, narrowband devices and broadband devices are communicatively connected to a narrowband and broadband convergence node device, and the narrowband and broadband convergence node device is connected to an authentication server through an access switch. The authentication server and the access switch are also connected to a narrowband and broadband access controller.
[0026] According to an embodiment of the present invention, the communication mode of narrowband devices includes narrowband communication, the communication mode of broadband devices includes broadband communication, or the communication mode of narrowband devices is narrowband communication, and the communication mode of broadband devices is broadband communication.
[0027] Narrowband devices specifically include on-line monitoring devices, such as various sensors. In a substation, on-line monitoring devices are mainly narrowband wireless communication devices mainly used for environmental monitoring, and can be specifically implemented as sensors for monitoring device temperature, ambient temperature and humidity, partial discharge, leakage current, SF6 gas leakage, etc. The amount of data transmitted each time is about several hundred bytes, and the data is mostly reported periodically. Table 1 shows the information of some narrowband devices: Table 1 Information of Narrowband Devices
[0028] Broadband devices specifically include remote inspection devices and operation and maintenance management devices. In a substation, remote inspection devices mainly include those applied to in-station security monitoring, anti-theft, and personnel monitoring, including devices such as robots, cameras, and drones. The data transmitted includes inspection data of real-time video streams, and a high-bandwidth and real-time network is adopted. Operation and maintenance management devices mainly include those applied to supporting various operation behaviors of on-site personnel, including devices such as handheld terminals (including live detection instruments) and intelligent safety helmets. By means of trajectory tracking and personnel positioning, on-site personnel's inspection operations, switching operations, live maintenance, etc. are standardized, and data such as faces, personnel behaviors, and voices need to be collected. The network requirements are the same as those of remote inspection devices, and a high-bandwidth and real-time network needs to be adopted. Table 2 shows the information of some broadband devices: Table 2 Information of Broadband Devices
[0029] According to an embodiment of the present invention, the narrow-wideband convergence node device receives narrowband data sent by narrowband devices and broadband data sent by broadband devices.
[0030] According to an embodiment of the present invention, the narrow-wideband convergence node device includes a processing module, one or more narrowband wireless communication modules, and one or more broadband wireless communication modules.
[0031] The narrowband wireless communication module is adapted to, when the communication mode of the device to be accessed is determined to be narrowband communication, in response to a communication connection request sent by a narrowband device, obtain the wireless networking protocol of the power transmission and transformation equipment Internet of Things node device from the adaptive protocol library, and establish a communication connection with the narrowband device according to the wireless networking protocol of the power transmission and transformation equipment Internet of Things node device.
[0032] The broadband wireless communication module is adapted to, when the communication mode of the device to be accessed is determined to be broadband communication, in response to a communication connection request sent by a broadband device, obtain the WAPI protocol from the adaptive protocol library, and establish a communication connection with the broadband device according to the WAPI protocol.
[0033] The processing module is adapted to parse the narrowband data sent by the narrowband device according to the wireless networking protocol of the power transmission and transformation equipment Internet of Things node device, determine the monitored object, monitoring data, and monitoring time, encapsulate the monitored object, monitoring data, and monitoring time according to a preset format into a preset encapsulation format to obtain narrowband encapsulated data, parse the received broadband data according to the WAPI protocol, determine the monitored object, monitoring data, and monitoring time, and encapsulate the monitored object, monitoring data, and monitoring time according to a preset format into a preset encapsulation format to obtain broadband encapsulated data.
[0034] Figure 3 Shows a schematic diagram of a narrow-wideband convergence node device according to an exemplary embodiment of the present invention. As Figure 3 shown, the narrow-wideband convergence node device includes a central processor for processing received broadband data and narrowband data; and also includes a memory for storing received broadband data and narrowband data, etc.
[0035] According to an embodiment of the present invention, the narrow-wideband convergence node device further includes one or more narrowband wireless communication modules and one or more broadband wireless communication modules. The present invention does not limit the specific number of narrowband wireless communication modules or broadband wireless communication modules included in the narrow-wideband convergence node device, nor does it limit the specific frequency bands covered by the narrowband wireless communication modules or broadband wireless communication modules.
[0036] According to an embodiment of the present invention, the narrow-wideband convergence node device may include three narrowband wireless communication modules and one broadband wireless communication module.
[0037] According to an embodiment of the present invention, the frequency bands covered by the narrowband wireless communication modules in the narrow-wideband convergence node device may include 470M and 2.4G frequency bands, etc., and the frequency bands covered by the broadband wireless communication modules may include 2.4G and 5G frequency bands, etc.
[0038] According to an embodiment of the present invention, the communication protocol adopted by the narrowband wireless communication modules in the narrow-wideband convergence node device for narrowband communication with narrowband devices includes the wireless networking protocol for power transmission and transformation equipment Internet of Things node devices. The wireless networking protocol for power transmission and transformation equipment Internet of Things node devices is a communication protocol that standardizes the networking communication of node devices in the perception layer of the power transmission and transformation equipment Internet of Things, and is a protocol specified for realizing the standardized networking and data transmission of node devices.
[0039] The communication protocol adopted by the broadband wireless communication modules for broadband communication with broadband devices includes the WAPI protocol, that is, Wireless LAN Authentication and Privacy Infrastructure, which is Chinese for Wireless Local Area Network Authentication and Confidentiality Infrastructure, is a security protocol, and is also a mandatory standard for wireless local area network security in China.
[0040] Figure 4 Shows a schematic diagram of a narrow-wideband convergence node device according to another exemplary embodiment of the present invention. As Figure 4As shown in the figure, the wide - narrow integration aggregation node device includes a central processor and a memory, a node networking protocol communication module, a first micro - power wireless communication module, and a second micro - power wireless communication module, which are used as narrow - band wireless communication modules. The communication frequency band adopted by the node networking protocol communication module includes 470M, which can be used for narrow - band communication with other wide - narrow integration aggregation node devices, sensor devices that communicate in low - power mode, etc. Sensor devices that communicate in low - power mode specifically include devices with a small amount of data transmitted each time, such as less than 100Kb or less than 200b, etc. The communication frequency bands adopted by the first micro - power wireless communication module and the second micro - power wireless communication module include 2.4G. Devices for narrow - band communication by the node networking protocol communication module, the first micro - power wireless communication module, and the second micro - power wireless communication module include narrow - band devices, such as on - line monitoring devices.
[0041] According to an embodiment of the present invention, the wide - narrow integration aggregation node device further includes a WAPI wireless communication module as a broadband wireless communication module. The communication frequency bands adopted by the WAPI wireless communication module include 2.4G and 5G. Devices for broadband communication by the WAPI wireless communication module include broadband devices, such as remote inspection devices and operation and maintenance management devices.
[0042] According to an embodiment of the present invention, the wide - narrow integration aggregation node device is also provided with an optical fiber or network cable interface for connecting to devices such as an access switch for data exchange.
[0043] Back to Figure 2 , the access switch is used to realize data exchange among the authentication server, the wide - narrow band access controller, and the wide - narrow integration aggregation node device.
[0044] The authentication server can be specifically implemented as a broadband and narrow - band authentication server (AS). The authentication server is generally deployed centrally in the substation main station and communicates with the substation sub - stations. The authentication server can be deployed in a primary - standby mode. The authentication server is suitable for managing digital certificates of broadband devices, narrow - band devices, and wide - narrow band access controllers, including certificate issuance, certificate authentication, certificate revocation, etc.
[0045] The wide and narrowband access controller, namely the wide and narrowband AC, is an edge computing device that supports wide and narrowband integrated communication. It is generally deployed in the secondary room cabinet and is the management device for the wide and narrowband wireless network in the substation. It simultaneously realizes wide and narrowband network coverage, supports wide and narrowband network management functions, has the AC function of the broadband network WAPI built-in, and has all the functions of the access node in the wireless networking protocol of the original narrowband power transmission and transformation equipment Internet of Things node equipment. According to different voltage levels, the wide and narrowband AC can be selectively deployed in the station, regional centralized control, city or province to converge all the service data of the wide and narrowband integrated convergence node devices, namely the wide and narrowband integrated AP, and forward it externally in a unified manner. It supports the management of all wide and narrowband integrated AP devices, including the registration, networking, and configuration distribution of the wide and narrowband integrated AP.
[0046] Figure 5 FIG. shows a schematic diagram of a substation broadband integrated wireless networking according to another exemplary embodiment of the present invention. As Figure 5 shown, the dotted line represents the wireless network connection, and the wireless network includes a broadband network and a narrowband network, and the solid line represents the wired network.
[0047] The narrowband devices include wireless temperature and humidity sensors, voiceprint monitoring sensors, and environmental noise sensors for online monitoring; the broadband devices include drones, robots, ball cameras, intelligent monitoring mobile terminals for remote patrol, and safety helmets and handheld terminals for operation and maintenance management.
[0048] According to an embodiment of the present invention, the narrowband devices communicate with the wide and narrowband integrated AP in narrowband, and the broadband devices communicate with the wide and narrowband integrated AP in broadband. Multiple wide and narrowband integrated convergence node devices, namely the wide and narrowband integrated AP, can be distributedly deployed in the substation. The present invention does not limit the number and deployment method of the specifically deployed broadband integrated convergence node devices.
[0049] According to an embodiment of the present invention, when deploying one or more wide and narrowband integrated convergence node devices, one or more wireless access points AP for broadband communication can also be supplementarily set for the broadband network, such as the WAPI wireless access point AP that uses the WAPI protocol for broadband communication, abbreviated as WAPI AP.
[0050] According to an embodiment of the present invention, the narrowband integrated convergence node device, namely the wide and narrowband integrated AP, can be connected to the wide and narrowband access controller (AC) or the core switch through one of the access switches. Among them, the core switch can be set in the main and standby machine modes. The narrowband integrated convergence node device, namely the wide and narrowband integrated AP, can also be connected to the core switch through the optical network unit, optical splitter, and optical line terminal.
[0051] The narrowband fusion convergence node device, i.e., the narrow- and wide-band fusion AP, can also be connected to other switches of the master station through the core switch of the sub-station, and then connected to the authentication server deployed in the master station through other switches of the master station. The authentication server is also connected to the integrated network device, and the core switch is also connected to the master station system and is equipped with a firewall.
[0052] A forward isolation device and a reverse isolation device are also set between the sub-station and the master station and are connected to the integrated application host in the production control area.
[0053] According to an embodiment of the present invention, when deploying the narrow- and wide-band fusion convergence node devices in the substation, it is necessary to reasonably arrange multiple narrow- and wide-band fusion convergence node devices according to the data acquisition requirements in the substation and the locations where the narrow- and wide-band fusion convergence node devices can be set. If there is a demand for a broadband network but it is not covered, one or more wireless access points AP for broadband communication, such as WAPI wireless access points AP, need to be set up to meet the corresponding network requirements.
[0054] Embodiment 2 When broadband devices and narrowband devices want to access the narrow- and wide-band fusion convergence node, the authentication server and the narrow- and wide-band access controller manage the access and data transmission of broadband devices and narrowband devices.
[0055] According to an embodiment of the present invention, the authentication server first issues a convergence node certificate to multiple narrow- and wide-band fusion convergence node devices connected to the authentication server. The convergence node certificate is a certificate that identifies the legal identity of the narrow- and wide-band fusion convergence node device.
[0056] According to an embodiment of the present invention, an adaptive protocol library is also set in the narrow- and wide-band fusion convergence node device to meet the connection requirements of various devices, including broadband devices and narrowband devices. According to an embodiment of the present invention, after multiple narrow- and wide-band fusion convergence node devices are set up in the substation, the narrow- and wide-band fusion convergence node devices start to work and will send out AP signals. Broadband devices and narrowband devices can select one narrow- and wide-band fusion convergence node device with the strongest signal that can be searched to connect.
[0057] According to an embodiment of the present invention, among broadband devices and narrowband devices, different devices may have multiple communication methods, so one of the communication methods can be selected for communication according to the data to be transmitted and received.
[0058] According to an embodiment of the present invention, the devices to be accessed include broadband devices and narrowband devices. When the devices to be accessed establish a communication connection with the narrow- and wide-band fusion convergence node device for the first time, they send a first device registration request to the narrow- and wide-band fusion convergence node device.
[0059] If the device to be connected is a broadband device, the broadband device sends a first device registration request to the broadband wireless communication module through broadband communication; if the device to be connected is a narrowband device, the narrowband device sends a first device registration request to the narrowband wireless communication module through the narrowband communication module.
[0060] The first device registration request includes the device information of the device to be connected. The device information of the device to be connected includes: a unique identification code for identifying the device to be connected: device ID, communication method, aggregation node device ID, and data usage. The aggregation node device ID is the unique ID of the wide and narrow integration aggregation node device to which the device to be connected is to be connected.
[0061] Figure 6 A flowchart of a communication management method 600 based on a wide and narrow integration aggregation node device according to the present invention is shown. As Figure 6 shown, first, step 610 is executed. In response to the received second device registration request sent by the wide and narrow integration aggregation node device, the wide and narrowband access controller parses the second device registration request to obtain the first device registration request and the aggregation node certificate of the wide and narrow integration aggregation node device. The first device registration request is the request sent by the device to be connected to the wide and narrow integration aggregation node device. The first device registration request includes the device information of the device to be connected. The device to be connected includes broadband devices and narrowband devices deployed in a substation.
[0062] According to an embodiment of the present invention, after receiving the first device registration request, the broadband integration aggregation node device packages the first device registration request and the aggregation node certificate to generate a second device registration request and sends it to the wide and narrowband access controller. The wide and narrowband access controller parses the second device registration request to obtain the first device registration request and the aggregation node certificate.
[0063] Subsequently, step 620 is executed. The wide and narrowband access controller sends the aggregation node certificate to the authentication server. The authentication server performs certificate authentication on the aggregation node certificate. After successful authentication, the authentication server sends a first authentication success message to the wide and narrowband access controller.
[0064] Subsequently, step 630 is executed. In response to the first authentication success message sent by the authentication server after performing certificate authentication on the aggregation node certificate, the wide and narrowband access controller registers the device to be connected according to the device information and applies to the authentication server for a device certificate of the device to be connected.
[0065] In response to the received first authentication success message, the wide and narrowband access controller registers the device to be connected according to the device information of the device to be connected and writes each item of information in the device information of the device to be connected into the registration information table.
[0066] After the narrow and wideband access controller successfully registers the device to be accessed, it applies to the authentication server for the device certificate of the device to be accessed. The authentication server makes the device certificate according to the device information of the device to be accessed and sends it to the narrow and wideband access controller.
[0067] Subsequently, step 640 is executed. In response to the device certificate made by the authentication server received by the narrow and wideband access controller, the narrow and wideband access controller sends the device certificate to the device to be accessed through the narrow and wide fusion convergence node device.
[0068] According to an embodiment of the present invention, in response to the received made device certificate, the narrow and wideband access controller sends a registration success message and the device certificate to the narrow and wide fusion convergence node device. The narrow and wide fusion convergence node device sends the device certificate to the device to be accessed.
[0069] After the device to be accessed receives the device certificate, each time it establishes a communication connection with the narrow and wide fusion convergence node device, it sends a communication connection request to the narrow and wide fusion convergence node device, and the communication connection request includes the device certificate.
[0070] After the narrow and wide fusion convergence node device receives the communication connection request, it generates a communication verification request according to the communication connection request and the convergence node certificate and sends it to the narrow and wideband access controller.
[0071] Subsequently, step 650 is executed. In response to the communication verification request sent by the narrow and wide fusion convergence node device received by the narrow and wideband access controller, the narrow and wideband access controller parses the communication verification request to obtain the device certificate of the device to be accessed and the convergence node certificate, and sends the device certificate of the device to be accessed and the convergence node certificate to the authentication server for certificate authentication.
[0072] When the authentication server performs certificate authentication, if the authentication passes, it sends a second authentication success message to the narrow and wideband access controller.
[0073] Finally, step 660 is executed. In response to the second authentication success message sent by the authentication server received by the narrow and wideband access controller, the narrow and wideband access controller sends an allow connection message to the narrow and wide fusion convergence node device so that the device to be accessed can access the narrow and wide fusion convergence node device and become an access device.
[0074] Based on the second authentication success message, the narrow and wideband access controller allows the device to be accessed to access the narrow and wide fusion convergence node device and sends an allow connection message to the narrow and wide fusion convergence node device that received the communication connection request. After the narrow and wide fusion convergence node device receives the allow connection message, it negotiates a secret key with the device to be accessed to determine the session secret key. After the device to be accessed completes the secret key negotiation, it becomes an access device connected to the narrow and wide fusion convergence node device.
[0075] The session key includes the private key and public key of the access device, and the private key and public key of the wide - narrow convergence node device.
[0076] When the access device communicates with the wide - narrow convergence node device, the uplink communication data is encrypted according to the public key of the wide - narrow convergence node device and sent to the wide - narrow convergence node device. After receiving the encrypted uplink communication data, the wide - narrow convergence node device decrypts the uplink communication data according to its private key to obtain the data content of the uplink communication data.
[0077] When the wide - narrow convergence node device needs to communicate with the access device, the downlink communication data is encrypted according to the public key of the access device and sent to the access device. After receiving the downlink communication data sent by the wide - narrow convergence node device, the access device decrypts the downlink communication data according to its private key to obtain the data content of the downlink communication data.
[0078] According to an embodiment of the present invention, the access device includes broadband devices and narrowband devices. When a broadband device communicates with the wide - narrow convergence node device, it establishes a communication connection with the broadband wireless communication module for communication. When a narrowband device communicates with the wide - narrow convergence node device, it establishes a communication connection with the narrowband wireless communication module for communication.
[0079] According to an embodiment of the present invention, the uplink communication data includes narrowband data and broadband data. The downlink communication data includes data sent to narrowband devices and broadband devices.
[0080] According to an embodiment of the present invention, after the broadband devices and narrowband devices are connected to the wide - narrow convergence node device, the wide - narrow access controller manages the access devices according to the device type, that is, the access devices include broadband devices and narrowband devices; the broadband devices include remote inspection devices and operation and maintenance management devices; the narrowband devices include online monitoring devices, such as various sensors.
[0081] According to an embodiment of the present invention, the wide - narrow access controller can manage the access devices according to the registration information table. The registration information table also includes the device type of the access device, specifically whether it belongs to a broadband device or a narrowband device, and which type of device it is among broadband devices or narrowband devices.
[0082] According to an embodiment of the present invention, the wide - narrow access controller can also create device lists of different categories, such as device lists of broadband devices, device lists of narrowband devices, and can be further subdivided, such as device lists of remote inspection devices, device lists of operation and maintenance management devices, and device lists of online monitoring devices.
[0083] According to an embodiment of the present invention, the narrow and wideband access controller may also provide a management interface facing the backend. The management personnel at the backend can obtain the management status of various devices by the narrow and wideband access controller through the management interface, including various device lists.
[0084] The management interface also provides management controls in the device list. Users can disconnect the access devices in the device list according to the management controls, set the disconnection time, etc., and set to add to the blacklist to prohibit the device from accessing the narrow and wide integration convergence node device in the future. The present invention does not limit the specific implementation manner of the management control and the management manner of the access device.
[0085] According to an embodiment of the present invention, different types of devices can also be set to have different security levels. For example, it is set that the remote inspection devices have the third-level security level, the operation and maintenance management devices have the second-level security level, and the on-line monitoring devices have the first-level security level. The security level from the first level to the third level increases in turn.
[0086] Different security levels have different configuration items. For example, devices with different security levels have different key negotiation frequencies. For example, it is set that for devices with the first-level security level, when accessing the narrow and wide integration convergence node device, the key negotiation and key replacement are carried out with the narrow and wide integration convergence node device every month. For devices with the second-level security level, when accessing the narrow and wide integration convergence node device, the key negotiation and key replacement are carried out with the narrow and wide integration convergence node device every week. For devices with the third-level security level, when accessing the narrow and wide integration convergence node device, the key negotiation and key replacement are carried out with the narrow and wide integration convergence node device every day.
[0087] According to an embodiment of the present invention, different categories of devices are also set to have different data transmission priorities. For example, it is set that the remote inspection data sent by the remote inspection devices has the third-level priority, the operation and maintenance management data sent by the operation and maintenance management devices has the second-level priority, and the on-line monitoring data sent by the on-line monitoring devices has the first-level priority. The priority level from the first level to the third level increases in turn.
[0088] According to an embodiment of the present invention, an uplink data transmission message queue is set in the narrow and wide integration convergence node device. After the narrow and wide integration convergence node device receives the remote inspection data, operation and maintenance management data, and on-line monitoring data, the above data is sequentially added to the uplink data transmission message queue.
[0089] Subsequently, the data in the uplink data transmission message queue is sorted. The remote inspection data has the third-level priority and is ranked at the forefront of the message queue for acquisition and processing first. The operation and maintenance management data has the second priority and is ranked after the remote inspection data. The online monitoring data has the third priority and is ranked after the operation and maintenance management data. Subsequently, if there are multiple uplink communication data for each priority level, they are sorted within each priority level in the order of reception time; if there are multiple remote inspection data in the uplink data transmission message queue, they are sorted according to the reception time of each remote inspection data, and the remote inspection data with an earlier reception time is ranked before the remote inspection data with a later reception time. Similarly, if there are multiple operation and maintenance management data in the uplink data transmission message queue, the operation and maintenance management data with an earlier reception time is ranked before the operation and maintenance management data with a later reception time. If there are multiple online monitoring data in the uplink data transmission message queue, the online monitoring data with an earlier reception time is ranked before the online monitoring data with a later reception time.
[0090] By setting an uplink data transmission message queue in the wide and narrowband convergence node device and sorting various data according to priority levels in the uplink data transmission message queue, it can effectively ensure that important data is decrypted and sent with high priority, ensuring a smooth communication link. Remote inspection devices include inspection robots, drones, mobile ball cameras, etc., which often need to transmit real-time data to the backend for staff to view and control the remote inspection devices. Therefore, the remote inspection data of such devices should be processed with the highest priority. Operation and maintenance management devices include handheld terminals, intelligent safety helmets, etc., which need to transmit data back for real-time monitoring of the positions of personnel using the operation and maintenance management devices. Therefore, the processing priority of operation and maintenance management data is higher than that of online monitoring data.
[0091] According to an embodiment of the present invention, when the wide and narrowband convergence node device processes the data in the uplink data transmission message queue, one data is taken out from the head of the message queue for processing each time. The data processing process includes steps such as decryption and transmission. The present invention does not limit the specific steps included in the message processing process.
[0092] According to an embodiment of the present invention, the wide and narrowband convergence node device also collects the device status of the access devices and transmits the device status of the access devices to the wide and narrowband access controller so that the wide and narrowband access controller can manage the devices according to the device status of the access devices.
[0093] According to an embodiment of the present invention, the device status includes the device location, device power, device fault information, etc. The device location is the location of the currently connected device in the substation. The device power is the current power of the connected device, such as the remaining power of devices like inspection robots, drones, mobile surveillance cameras, etc. The device fault information includes the faults currently encountered by the device, such as the inspection robot having a problem with not being able to move forward, the drone having a problem with the images captured by the installed camera being unclear, etc.
[0094] According to an embodiment of the present invention, the connected device sends the device status to the broadband and narrowband access controller through the broadband and narrowband convergence node device. The broadband and narrowband access controller can at any time determine whether it is necessary to restart the connected device or suspend the use of the connected device based on the device status of the connected device.
[0095] According to an embodiment of the present invention, when the remaining power of a connected device, such as an inspection robot, a drone, a mobile surveillance camera, etc., is less than the preset power threshold, a command to suspend use can be sent to the connected device through the broadband and narrowband convergence node device, so that the connected device returns to the starting point using the remaining power.
[0096] According to an embodiment of the present invention, when a connected device, such as an inspection robot, a drone, a mobile surveillance camera, etc., encounters a fault, the connected device can be controlled to return to the starting point or suspended for use, waiting for maintenance personnel to repair the connected device according to the device fault information.
[0097] According to an embodiment of the present invention, the connected device can also perform the switching between broadband communication and narrowband communication. According to an embodiment of the present invention, if the connected device has the capabilities of both broadband communication and narrowband communication, when it is necessary to change the communication method according to the form of data to be sent and received and internal changes, a communication method change request can be sent to the broadband and narrowband convergence node device.
[0098] According to an embodiment of the present invention, the communication method change request includes the device certificate and the target communication method to be changed. For example, when changing from narrowband communication to broadband communication, the target communication method is broadband communication; when changing from broadband communication to narrowband communication, the target communication method is broadband communication.
[0099] When the broadband and narrowband convergence node device receives the communication method change request, it sends the communication method change request and the convergence node certificate to the broadband and narrowband access controller. The broadband and narrowband access controller parses the communication method change request to obtain the device certificate, and then sends the device certificate and the convergence node certificate to the authentication server. After receiving the device certificate and the convergence node certificate, the authentication server performs certificate authentication. If the authentication passes, a new device certificate is made according to the received device certificate. Specifically: in the new device certificate, the communication method in the device information is modified to the target communication method to obtain the new device certificate.
[0100] Subsequently, the authentication server sends the new device certificate to the narrow and broadband access controller. After receiving the new device certificate, the narrow and broadband access controller modifies the communication method in the device information of the access device to the target communication method in the registration information table, and then sends the new device certificate to the narrow and broadband convergence node device. After receiving the new device certificate, the narrow and broadband convergence node device forwards the new device certificate to the access device, and then uses the corresponding communication module to establish a communication connection with the access device according to the target communication method, and performs key negotiation to replace the key for communication.
[0101] According to an embodiment of the present invention, the access device uses narrowband communication before changing the communication method. When the access device needs to use broadband communication to communicate with the narrow and broadband convergence node device, it sends a communication method change request to the narrow and broadband convergence node device. The communication method change request includes the device certificate and the target communication method to be changed, that is, broadband communication.
[0102] After receiving the communication method change request, the narrow and broadband convergence node device sends the communication method change request and the convergence node certificate to the narrow and broadband access controller. The narrow and broadband access controller parses the communication method change request to obtain the device certificate, and then sends the device certificate and the convergence node certificate to the authentication server. After receiving the device certificate and the convergence node certificate, the authentication server performs certificate authentication. If the authentication passes, a new device certificate is made according to the received device certificate. Specifically: in the new device certificate, the communication method in the device information is modified to the target communication method to obtain the new device certificate. Specifically: in the new device certificate, the communication method in the device information is modified to broadband communication to obtain the new device certificate.
[0103] Subsequently, the authentication server sends the new device certificate to the narrow and broadband access controller. After receiving the new device certificate, the narrow and broadband access controller modifies the communication method in the device information of the access device to broadband communication in the registration information table, and then sends the new device certificate to the narrow and broadband convergence node device. After receiving the new device certificate, the narrow and broadband convergence node device forwards the new device certificate to the access device, and then uses the corresponding broadband wireless communication module to establish broadband communication with the access device according to broadband communication, and performs key negotiation to replace the key for broadband communication.
[0104] Embodiment 3 Since some access devices, such as inspection machines, drones, mobile surveillance cameras, etc. in remote inspection devices, need to move in a substation, these access devices need to replace the access wide and narrowband convergence node devices during the movement. In order to enable such access devices to seamlessly replace the access wide and narrowband convergence node devices during operation and keep their networks always unobstructed, the present invention has made the following related designs: According to an embodiment of the present invention, the wide and narrowband access controller obtains the movement route of the access device in the substation, determines the wide and narrowband convergence node devices to be connected at each point on the movement route, and obtains the set of wide and narrowband convergence node devices to be connected. The movement route can be determined by pre-setting the movement route of the access device, and the present invention does not limit the specific determination method of the movement route.
[0105] According to an embodiment of the present invention, to determine the wide and narrowband convergence node devices to be connected at each point on the movement route, the wide and narrowband convergence node device closest to each point on the movement route can be determined, and the wide and narrowband convergence node device closest to each point is used as the wide and narrowband convergence node device to be connected.
[0106] According to an embodiment of the present invention, the wide and narrowband convergence node devices to be connected at each point can also be determined by calculating the signal strength. First, obtain the floor plan of the substation. The floor plan of the substation includes the building walls of the substation, the main substation equipment, broadband devices, narrowband devices, and the movement route of the access device. The specific positions of the building walls of the substation, the main substation equipment, the wide and narrowband convergence node devices, the broadband devices, and the narrowband devices, as well as the movement route of the access device, are marked on the floor plan of the substation.
[0107] The building walls of the substation include the outer walls and inner walls of the substation's enclosure, buildings, etc. The main substation equipment is the equipment that maintains the normal operation of the substation, such as transformers, etc. The broadband devices and narrowband devices are suitable for monitoring the status of the substation environment, the main substation equipment, etc.
[0108] Since the building walls of the substation and the main substation equipment will both have a certain impact on the signal transmission of the broadband devices and narrowband devices, the signals of the wide and narrowband convergence node devices will attenuate to a certain extent when passing through the building walls or bypassing the substation.
[0109] According to an embodiment of the present invention, a signal attenuation coefficient of a substation wall is set for the signal attenuation caused by the substation wall to the present invention. The signal attenuation coefficient of the substation wall can be determined according to the thickness and material of different substation walls, and specifically can also be obtained through actual tests, and can also be preset, such as set to 0.7. When the signal of the wide and narrow fusion convergence node device passes through the substation wall once, the signal strength will be multiplied by the signal attenuation coefficient of the substation wall each time.
[0110] The present invention also sets a signal attenuation coefficient of the main substation equipment for the signal attenuation caused by the main substation equipment. The signal attenuation coefficient of the main substation equipment can be determined according to the size of different main substation equipment and the electromagnetic effect generated when the main substation equipment is working, and specifically can also be obtained through actual tests, and can also be preset, such as set to 0.8. When the signal of the wide and narrow fusion convergence node device bypasses the substation equipment once, the signal strength will be multiplied by the signal attenuation coefficient of the main substation equipment each time.
[0111] The position coordinates of each wide and narrow fusion convergence node device include the abscissa x and the ordinate y , the position coordinates of the wide and narrow fusion convergence node device can be represented by longitude and latitude respectively, and can also be determined by establishing a coordinate system with the floor plan of the substation. The present invention does not limit the specific representation method of the position coordinates of the wide and narrow fusion convergence node device. It is preset that a total of k wide and narrow fusion convergence node devices are set in the substation, then the position coordinates of the t th wide and narrow fusion convergence node device include ( ), t represents the t th wide and narrow fusion convergence node device, t The value range of is 1 - k .
[0112] The substation includes m access devices. Similar to the representation method of the position coordinates of the wide and narrow fusion convergence node device, i represents the i rd access device, i The value range of is 1 - m . The position coordinates of the i th access device include ( ). Since the access device moves in the substation, the position coordinates of the access device will change. According to an embodiment of the present invention, the movement route of the access device in the substation can be divided according to a predetermined step length to obtain a plurality of route nodes on the predetermined route, and the distance between adjacent two route nodes is the predetermined step length. Set the number of route nodes on the predetermined route of the access device to be n, the position coordinates of each route node can be expressed as ( ). l represents the l th route node on the predetermined route, l ranges from 1 to n .
[0113] According to the position coordinates ( i ) of the l th route node on the moving route of the th access device and the position coordinates ( t ) of the th narrow-wideband convergence node device, determine the straight-line distance , including: , is the straight-line distance between the l th route node on the moving route of the t th access device and the
[0114] th narrow-wideband convergence node device in the floor plan of the substation. t The signal transmitted from the i th narrow-wideband convergence node device to the l th route node on the moving route of the th access device has a theoretical signal strength of . is the theoretical signal strength function of the narrow-wideband convergence node device, which is related to the distance from the receiving device and
[0115] can be obtained through steps such as surveying and fitting. t Subsequently, set the number of substation walls and the number of main substation devices separated between the narrow-wideband convergence node device and the route node according to the connection lines between each narrow-wideband convergence node device and each route node on the floor plan of the substation. The number of substation walls separated between the i th narrow-wideband convergence node device and the l th route node on the moving route of the th access device is .
[0116] If the signal attenuation coefficient of the substation wall is α and the signal attenuation coefficient of the main substation device is β, then the actual signal strength of the signal transmitted from the t th narrow-wideband convergence node device to the i th route node on the moving route of the l th access device is: .
[0117] In the present invention, each access device is set to select the wide - narrow integration convergence node device with the maximum actual signal strength on its moving route for connection. Then, for the i th access device, the connection signal strength of the l th route node on its moving route is k the maximum value among the actual signal strengths of the narrow - band devices - in .
[0118] The wide - narrow integration convergence node device with the maximum actual signal strength at each route node is the wide - narrow integration convergence node device to be connected on the moving route, thereby obtaining the set of wide - narrow integration convergence node devices to be connected on the moving route.
[0119] According to an embodiment of the present invention, the wide - narrow band access controller sends the device certificate and the convergence node certificate of each wide - narrow integration convergence node device in the wide - narrow integration convergence node device set to the authentication server. After receiving the device certificate and the convergence node certificate, the authentication server conducts certificate authentication. If the authentication passes, a multi - node access device certificate is made according to the received device certificate. Specifically: in the multi - node access device certificate, the convergence node device ID of each wide - narrow integration convergence node device in the wide - narrow integration convergence node device set is written in the device information to generate the multi - node access device certificate.
[0120] Subsequently, the authentication server sends the multi - node access device certificate to the wide - narrow band access controller. After receiving the multi - node access device certificate, the wide - narrow band access controller writes the convergence node device ID of each wide - narrow integration convergence node device in the wide - narrow integration convergence node device set in the device information of the access device in the registration information table, completing the record - filing of the access device for accessing multiple wide - narrow integration convergence node devices.
[0121] Subsequently, the new multi - node access device certificate is sent to the wide - narrow integration convergence node device. After receiving the multi - node access device certificate, the wide - narrow integration convergence node device forwards the multi - node access device certificate to the access device.
[0122] When the access device moves on the preset moving route, it conducts authentication connection with the wide - narrow integration convergence node devices to be accessed on the moving route according to the multi - node access device certificate, thereby realizing seamless replacement of the accessed wide - narrow integration convergence node devices when moving on the moving route, keeping the network always unobstructed, without the need to re - register relevant information on the moving route, and avoiding network interruption and disconnection of the control of the access device during movement.
[0123] According to an embodiment of the present invention, the present invention further provides a communication management system based on a wide and narrowband integrated convergence node device. The system includes a wide and narrowband access controller, an authentication server and a wide and narrowband integrated convergence node device that are communicatively connected to the wide and narrowband access controller. The wide and narrowband integrated convergence node device is adapted to generate a device registration second request based on the device registration first request and the convergence node certificate after receiving the device registration first request, and send it to the wide and narrowband access controller. The device registration first request is a request sent by a device to be accessed to the wide and narrowband integrated convergence node device, and the device registration first request includes the device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in a substation; The wide and narrowband access controller is adapted to, in response to receiving the device registration second request, parse the device registration second request to obtain the device registration first request and the convergence node certificate of the wide and narrowband integrated convergence node device, and send the convergence node certificate to the authentication server; The authentication server is adapted to perform certificate authentication on the convergence node certificate. If the authentication is successful, it sends an authentication success message to the wide and narrowband access controller; The wide and narrowband access controller is further adapted to register the device to be accessed according to the device information and apply to the authentication server for a device certificate of the device to be accessed; The authentication server is further adapted to generate a device certificate according to the device information of the device to be accessed; The wide and narrowband integrated convergence node device is further adapted to generate a communication verification request based on the communication connection request and the convergence node certificate after receiving the communication connection request sent by the access device, and send it to the wide and narrowband access controller. The communication connection request includes a device certificate; The wide and narrowband access controller is further adapted to, in response to receiving the communication verification request sent by the wide and narrowband integrated convergence node device, parse the communication verification request to obtain the device certificate of the device to be accessed and the convergence node certificate, and send the device certificate of the device to be accessed and the convergence node certificate to the authentication server for certificate authentication; The authentication server is further adapted to perform certificate authentication on the device certificate and the convergence node certificate. If the authentication is successful, it sends an authentication success message to the authentication server; The wide and narrowband access controller is further adapted to, in response to receiving the authentication success message sent by the authentication server, send an allow connection message to the wide and narrowband integrated convergence node device, so that the device to be accessed can access the wide and narrowband integrated convergence node device and become an access device.
[0124] Embodiment 4 The wide and narrowband integrated convergence node device, the wide and narrowband access controller, and the authentication server of the present invention can be specifically implemented as a computing device. Figure 7 The schematic diagram of a computing device 700 according to an exemplary embodiment of the present invention is shown.
[0125] As shown Figure 7 in the figure, the computing device 700 may include: a central processing unit 710, a memory 720, an input / output interface 730, a communication interface 740, and a bus 750. Among them, the central processing unit 710, the memory 720, the input / output interface 730, and the communication interface 740 are communicatively connected to each other inside the computing device through the bus 750.
[0126] The central processing unit 710 may be implemented in the form of a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0127] The memory 720 may be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 720 may store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 720 and are called and executed by the central processing unit 710.
[0128] The input / output interface 730 is used to connect to an input / output module to implement information input and output. The communication interface 740 is used to implement communication and interaction between this computing device and other devices. The bus 750 includes a path for transmitting information between various components of the computing device (such as the central processing unit 710, the memory 720, the input / output interface 730, and the communication interface 740).
[0129] It should be noted that although the above computing device only shows the central processing unit 710, the memory 720, the input / output interface 730, the communication interface 740, and the bus 750, in the specific implementation process, this computing device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above computing device may also only include the components necessary to implement the solutions of the embodiments of this specification, and do not have to include all the components shown in the figure.
[0130] As used herein, unless otherwise specified, using ordinal numbers such as "first", "second", "third", etc. to describe ordinary objects only indicates different instances of similar objects, and does not intend to imply that the objects so described must have a given order in terms of time, space, sorting, or any other way.
[0131] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative efforts. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field based on the concept of the present invention through logical analysis, reasoning, or limited experiments on the basis of the prior art should fall within the protection scope determined by the claims.
Claims
1. A communication management method based on a wide and narrow fusion convergence node device, characterized in that It is used to realize the communication connection between the narrow and wideband access controller, the authentication server, and the narrow and wide integration convergence node device, including device registration, certificate application and distribution, communication verification, and connection authorization. Through the cooperation between the narrow and wideband access controller and the authentication server, it ensures the secure access of the device to be accessed to the narrow and wide integration convergence node device.
2. The communication management method based on the wide and narrow fusion convergence node device according to claim 1, wherein The method includes the following steps: In response to the received second device registration request sent by the narrow and wide integration convergence node device, the narrow and wideband access controller parses the second device registration request to obtain the first device registration request and the convergence node certificate of the narrow and wide integration convergence node device. The first device registration request is a request sent by the device to be accessed to the narrow and wide integration convergence node device, including the device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in the substation. The narrow and wideband access controller sends the convergence node certificate to the authentication server. In response to the received first authentication success message sent by the authentication server after authenticating the convergence node certificate, the narrow and wideband access controller registers the device to be accessed according to the device information and applies to the authentication server for the device certificate of the device to be accessed. In response to the received device certificate made by the authentication server according to the device information, the narrow and wideband access controller sends the device certificate to the device to be accessed through the narrow and wide integration convergence node device. In response to the received communication verification request sent by the narrow and wide integration convergence node device, the narrow and wideband access controller parses the communication verification request to obtain the device certificate and the convergence node certificate of the device to be accessed, and sends the device certificate and the convergence node certificate of the device to be accessed to the authentication server for certificate authentication. In response to the received second authentication success message sent by the authentication server after authenticating the device certificate and the convergence node certificate, the narrow and wideband access controller sends an allow connection message to the narrow and wide integration convergence node device, so that the device to be accessed can access the narrow and wide integration convergence node device and become an access device.
3. The communication management method based on the wide and narrow fusion convergence node device according to claim 2, characterized in that, In response to the received communication connection request sent by the device to be accessed, the narrow and wide integration convergence node device generates a communication verification request according to the communication connection request and the convergence node certificate, and sends the communication verification request to the narrow and wideband access controller. The communication connection request includes the device certificate of the device to be accessed.
4. The communication management method based on the wide and narrow fusion convergence node device according to claim 2, characterized in that, After receiving the allow connection message, the narrow and wide integration convergence node device negotiates a secret key with the device to be accessed to determine the session secret key. The session secret key includes the private key and public key of the narrow and wide integration convergence node device. The method further includes: In response to the received encrypted uplink communication data sent by the access device, the narrow and wide integration convergence node device decrypts the encrypted uplink communication data according to the private key of the narrow and wide integration convergence node device to obtain the data content of the uplink communication data. The encrypted uplink communication data is encrypted by the access device according to the public key of the narrow and wide integration convergence node device.
5. The communication management method of a wide-narrow fusion aggregation node device according to claim 4, characterized in that, The session key includes the private key and public key of the access device, and the method further includes: In response to receiving the encrypted downlink communication data sent by the wide - narrowband convergence node device, the access device decrypts the encrypted downlink communication data according to the private key of the access device to obtain the data content of the downlink communication data. The encrypted downlink communication data is encrypted by the wide - narrowband convergence node device according to the public key of the access device.
6. The communication management method of a wide and narrow fusion convergence node device according to claim 2, characterized in that, The access device includes broadband devices and narrowband devices. The broadband devices include remote inspection devices and operation and maintenance management devices. The narrowband devices include online monitoring devices. The remote inspection devices have a third security level, the operation and maintenance management devices have a second security level, the narrowband devices have a first security level. The key negotiation frequency of the access devices with the third security level is higher than that of the devices with the second security level, and the key negotiation frequency of the access devices with the second security level is higher than that of the devices with the first security level.
7. A communication management method based on a wide and narrow fusion convergence node device according to claim 2, characterized in that, The access device includes broadband devices and narrowband devices. The broadband devices include remote inspection devices and operation and maintenance management devices. The narrowband devices include online monitoring devices. The remote inspection data sent by the remote inspection devices has a third - level priority, the operation and maintenance management data sent by the operation and maintenance management devices has a second - level priority, and the online monitoring data sent by the online detection devices has a first - level priority; An uplink data sending message queue is set in the wide - narrowband convergence node device, and the method further includes: In response to receiving uplink communication data of multiple priorities, the wide - narrowband convergence node device arranges the remote inspection data with the third priority at the front of the uplink data sending message queue; Arranges the operation and maintenance management data with the second priority behind the remote inspection data; Arranges the online monitoring data with the third priority behind the operation and maintenance management data; Each time, one uplink communication data is taken out from the head of the uplink data sending message queue for processing; If there are multiple uplink communication data for each priority, they are sorted in the order of reception time within each priority.
8. A communication management method based on a wide and narrow fusion convergence node device according to claim 2, characterized in that, In response to receiving the device status of the access device collected by the wide - narrowband access controller, the wide - narrowband access controller manages the access device according to the device status. The device status includes device location, device power, and device fault information.
9. The communication management method based on a wide and narrow fusion convergence node device according to claim 2, wherein, The access device is suitable for moving in the substation to inspect the main equipment of the substation, and the method further includes: The wide - narrowband access controller obtains the moving route of the access device in the substation, determines the wide - narrowband convergence node devices to be connected at each point on the moving route, and obtains the set of wide - narrowband convergence node devices to be connected; The broadband and narrowband access controller sends the device certificate and the convergence node certificate of each broadband and narrowband convergence node device in the broadband and narrowband convergence node device set to the authentication server, so that the authentication server can perform certificate authentication, and after the authentication passes, write the convergence node device ID of each broadband and narrowband convergence node device in the broadband and narrowband convergence node device set into the device information of the device certificate to generate a multi-node access device certificate; In response to the multi-node access device certificate made by the authentication server according to the device certificate after the authentication passes, the broadband and narrowband access controller writes the convergence node device ID of each broadband and narrowband convergence node device in the broadband and narrowband convergence node device set into the device information of the access device in the registration information table.
10. The communication management method of a wide-narrow fusion aggregation node device according to claim 9, characterized in that, The determination of the broadband and narrowband convergence node devices that need to be connected at each point on the movement route includes: Dividing the movement route of the access device in the substation according to a predetermined step length to obtain a plurality of route nodes on the predetermined route, and the distance between two adjacent route nodes is the predetermined step length; Determine the broadband and narrowband convergence node device with the largest actual signal strength at each route node as the broadband and narrowband convergence node device that needs to be connected on the movement route, and obtain the set of broadband and narrowband convergence node devices to be connected on the movement route.
Citation Information
Patent Citations
Method, system, network server and terminal for obtaining WAPI certificate
CN101616373A
Transfer equipment, server, system and login method for narrowband and broadband communication
CN112118545A
Communication system and method applied to power transmission and transformation equipment internet of things
CN116436943A
Wideband and narrowband fused wireless data security access gateway and implementation method
CN119603678A
Terminal security access model based on WAPI technology, establishment method and management equipment
CN119967414A