A communication management method based on a wide-narrow fusion convergence node device
Through the communication management method of wide-narrow convergence node equipment, the problem of inconsistent wireless equipment protocols in the substation is solved, and secure access and unified management of broadband and narrowband equipment is realized, networking costs are reduced and communication security is improved.
Patent Information
- Application Number
- CN202510712685.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-05-30
AI Technical Summary
In substations, due to the large number of wireless equipment manufacturers and complex interfaces, the wireless network communication protocol is inconsistent, network management is difficult and costly, and the existing communication methods have security risks, making it difficult to ensure communication security.
The communication management method based on wide-narrow convergence node equipment is adopted, and through the wide-narrow band access controller and the authentication server, the device registration, certificate application and distribution, communication verification and connection authorization are realized to ensure the secure access of the equipment to be accessed.
It realizes unified access to broadband and narrowband equipment without the need for separate networking, which improves communication security and management efficiency and reduces networking costs.
Smart Images

Figure CN120224341B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communication, and particularly to a communication management method based on a wide and narrowband fusion aggregation node device. Background Art
[0002] Under the situation of the accelerating development of the new power system, the contradiction between the shortage of grass-roots equipment management personnel and the continuous growth of the equipment scale has become increasingly prominent. To solve the contradiction between the shortage of operation and maintenance personnel and the increasing equipment maintenance volume, substations rely on equipment such as unmanned aerial vehicles, robots, and intelligent sensing terminals to replace some of the substation operation and maintenance work of operation and maintenance personnel, greatly improving the overall operation and maintenance efficiency of substations.
[0003] However, in terms of substation wireless networking, due to the large number of wireless device manufacturers and complex interfaces, there is a problem of inconsistent wireless network communication protocols. Moreover, each manufacturer conducts networking independently according to its own network requirements, making the management of this networking mode difficult, with high networking costs and complex technologies. CN116436943A discloses a communication system and method applied to the Internet of Things for power transmission and transformation equipment, including a wide and narrowband fusion core network, a fusion gateway, an access controller, an access node, an aggregation node, and a sensor terminal that are communicatively connected in sequence; a broadband board card, a broadband independent antenna, a narrowband board card, and a narrowband independent antenna are integrated in the access node; the sensor terminal is divided into a wired sensor terminal and a wireless sensor terminal; the number of the aggregation node, the wired sensor terminal, and the wireless sensor terminal is set to be multiple; the access node and the aggregation node are electrically connected through a wireless communication link or a wired communication link, and a suitable network communication method is selected according to service requirements and network quality to ensure the reliable and secure transmission of the Internet of Things wide and narrow networks, improve the utilization rate of network resources, and optimize the transmission performance of power transmission and transformation equipment. Although this application provides a method for compatibly connecting broadband devices and narrowband devices, this communication method has certain security risks and is not suitable for scenarios with relatively strict communication requirements in substations. The management of various devices is also relatively chaotic, making it difficult to ensure communication security. Summary of the Invention
[0004] The purpose of the present invention is to provide a communication management method based on a wide and narrowband fusion aggregation node device to solve the above-mentioned defects existing in the prior art.
[0005] The purpose of the present invention can be achieved through the following technical solutions:
[0006] According to the first aspect of the present invention, there is provided a communication management method based on a narrow-wideband integrated convergence node device, which is used to implement communication connections between a narrow-wideband access controller, an authentication server, and a narrow-wideband integrated convergence node device, including device registration, certificate application and distribution, communication verification, and connection authorization. Through the cooperation of the narrow-wideband access controller and the authentication server, it is ensured that the device to be accessed can safely access the narrow-wideband integrated convergence node device.
[0007] Optionally, the method includes the following steps:
[0008] In response to the received second device registration request sent by the narrow-wideband integrated convergence node device, the narrow-wideband access controller analyzes the second device registration request to obtain a first device registration request and the convergence node certificate of the narrow-wideband integrated convergence node device. The first device registration request is a request sent by the device to be accessed to the narrow-wideband integrated convergence node device and includes the device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in a substation;
[0009] The narrow-wideband access controller sends the convergence node certificate to the authentication server;
[0010] In response to the received first authentication success message sent by the authentication server after authenticating the convergence node certificate, the narrow-wideband access controller registers the device to be accessed according to the device information and applies to the authentication server for the device certificate of the device to be accessed;
[0011] In response to the received device certificate made by the authentication server according to the device information, the narrow-wideband access controller sends the device certificate to the device to be accessed through the narrow-wideband integrated convergence node device;
[0012] In response to the received communication verification request sent by the narrow-wideband integrated convergence node device, the narrow-wideband access controller analyzes the communication verification request to obtain the device certificate and the convergence node certificate of the device to be accessed, and sends the device certificate and the convergence node certificate of the device to be accessed to the authentication server for certificate authentication;
[0013] In response to the received second authentication success message sent by the authentication server after authenticating the device certificate and the convergence node certificate, the narrow-wideband access controller sends an allow connection message to the narrow-wideband integrated convergence node device so that the device to be accessed can access the narrow-wideband integrated convergence node device and become an access device.
[0014] Optionally, if the device to be accessed is a broadband device, the wide-and-narrow convergence node device receives a first device registration request sent by the device to be accessed according to the broadband wireless communication module; if the device to be accessed is a narrowband device, the wide-and-narrow convergence node device receives a first device registration request sent by the device to be accessed according to the narrowband wireless communication module.
[0015] Optionally, in response to the received communication connection request sent by the device to be accessed, the wide-and-narrow convergence node device generates a communication verification request according to the communication connection request and the convergence node certificate, and sends the communication verification request to the wide-and-narrow access controller. The communication connection request includes the device certificate of the device to be accessed.
[0016] Optionally, after receiving the permission connection message, the wide-and-narrow convergence node device negotiates a secret key with the device to be accessed to determine the session secret key.
[0017] Optionally, the session secret key includes the private key and public key of the wide-and-narrow convergence node device. The method further includes:
[0018] In response to the received encrypted uplink communication data sent by the access device, the wide-and-narrow convergence node device decrypts the encrypted uplink communication data according to the private key of the wide-and-narrow convergence node device to obtain the data content of the uplink communication data. The encrypted uplink communication data is encrypted by the access device according to the public key of the wide-and-narrow convergence node device.
[0019] Optionally, the session secret key includes the private key and public key of the access device. The method further includes:
[0020] In response to the received encrypted downlink communication data sent by the wide-and-narrow convergence node device, the access device decrypts the encrypted downlink communication data according to the private key of the access device to obtain the data content of the downlink communication data. The encrypted downlink communication data is encrypted by the wide-and-narrow convergence node device according to the public key of the access device.
[0021] Optionally, the access device includes broadband devices and narrowband devices. The broadband devices include remote inspection devices and operation and maintenance management devices. The narrowband devices include online monitoring devices. The remote inspection devices have a third security level, the operation and maintenance management devices have a second security level, the narrowband devices have a first security level. The secret key negotiation frequency of the access devices with the third security level is higher than that of the devices with the second security level, and the secret key negotiation frequency of the access devices with the second security level is higher than that of the devices with the first security level.
[0022] Optionally, the access device includes broadband devices and narrowband devices. The broadband devices include remote inspection devices and operation and maintenance management devices. The narrowband devices include online monitoring devices. The remote inspection data sent by the remote inspection devices has the third-level priority, the operation and maintenance management data sent by the operation and maintenance management devices has the second-level priority, and the online monitoring data sent by the online detection devices has the first-level priority;
[0023] An uplink data transmission message queue is set in the wide-band and narrow-band convergence node device, and the method further includes:
[0024] In response to receiving uplink communication data of multiple priorities, the wide-band and narrow-band convergence node device arranges the remote inspection data with the third priority at the forefront of the uplink data transmission message queue;
[0025] Arranges the operation and maintenance management data with the second priority after the remote inspection data;
[0026] Arranges the online monitoring data with the third priority after the operation and maintenance management data;
[0027] Each time, one piece of uplink communication data is taken from the head of the uplink data transmission message queue for processing;
[0028] If there are multiple uplink communication data for each priority, they are sorted in the order of reception time within each priority.
[0029] Optionally, in response to receiving the device status of the access device collected by the wide-band and narrow-band access controller, the wide-band and narrow-band access controller manages the access device according to the device status, and the device status includes device location, device power, and device fault information.
[0030] Optionally, the access device is adapted to move in the substation to inspect the main equipment of the substation, and the method further includes:
[0031] The wide-band and narrow-band access controller obtains the movement route of the access device in the substation, determines the wide-band and narrow-band convergence node devices to be connected at each point on the movement route, and obtains the set of wide-band and narrow-band convergence node devices to be connected;
[0032] The wide-band and narrow-band access controller sends the device certificate and the convergence node certificate of each wide-band and narrow-band convergence node device in the set of wide-band and narrow-band convergence node devices to the authentication server, so that the authentication server can perform certificate authentication, and after the authentication passes, write the convergence node device ID of each wide-band and narrow-band convergence node device in the set of wide-band and narrow-band convergence node devices into the device information of the device certificate, and generate a multi-node access device certificate;
[0033] The wide and narrow band access controller writes the aggregation node device ID of each wide and narrow band aggregation node device in the wide and narrow band aggregation node device set into the device information of the access device in the registration information table in response to the multi-node access device certificate made by the authentication server according to the device certificate after successful authentication.
[0034] Optionally, the determination of the wide and narrow band aggregation node devices to be connected at each point on the movement route includes:
[0035] Dividing the movement route of the access device in the substation according to a predetermined step length to obtain multiple route nodes on the predetermined route, and the distance between two adjacent route nodes is the predetermined step length;
[0036] Determining the wide and narrow band aggregation node device with the maximum actual signal strength at each route node as the wide and narrow band aggregation node device to be connected on the movement route, and obtaining the set of wide and narrow band aggregation node devices to be connected on the movement route.
[0037] According to another aspect of the present invention, there is also provided a communication management system based on a wide-and-narrowband fusion aggregation node device. The system includes a wide-and-narrowband access controller, an authentication server and a wide-and-narrowband fusion aggregation node device that are communicatively connected to the wide-and-narrowband access controller. The wide-and-narrowband fusion aggregation node device is adapted to generate a device registration second request based on the device registration first request and the aggregation node certificate after receiving the device registration first request, and send it to the wide-and-narrowband access controller. The device registration first request is a request sent by a device to be accessed to the wide-and-narrowband fusion aggregation node device, and the device registration first request includes the device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in a substation. The wide-and-narrowband access controller is adapted to parse the received device registration second request in response to receiving it, obtain the device registration first request and the aggregation node certificate of the wide-and-narrowband fusion aggregation node device, and send the aggregation node certificate to the authentication server. The authentication server is adapted to perform certificate authentication on the aggregation node certificate. If the authentication is successful, it sends a first authentication success message to the wide-and-narrowband access controller. The wide-and-narrowband access controller is also adapted to register the device to be accessed according to the device information and apply for the device certificate of the device to be accessed to the authentication server. The authentication server is also adapted to generate a device certificate according to the device information of the device to be accessed. The wide-and-narrowband fusion aggregation node device is also adapted to generate a communication verification request based on the communication connection request and the aggregation node certificate after receiving the communication connection request sent by the access device, and send it to the wide-and-narrowband access controller. The communication connection request includes the device certificate. The wide-and-narrowband access controller is also adapted to parse the received communication verification request sent by the wide-and-narrowband fusion aggregation node device in response to receiving it, obtain the device certificate and the aggregation node certificate of the device to be accessed, and send the device certificate and the aggregation node certificate of the device to be accessed to the authentication server for certificate authentication. The authentication server is also adapted to perform certificate authentication on the device certificate and the aggregation node certificate. If the authentication is successful, it sends a second authentication success message to the authentication server. The wide-and-narrowband access controller is also adapted to send an allow connection message to the wide-and-narrowband fusion aggregation node device in response to receiving the second authentication success message sent by the authentication server, so that the device to be accessed can access the wide-and-narrowband fusion aggregation node device and become an access device.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] The present invention provides a communication management method based on a wide - narrowband integrated convergence node device. The wide - narrowband integrated convergence node device can simultaneously access broadband devices and narrowband devices. When performing communication access, there is no need to separately network each type of device. The wide - narrowband integrated convergence node device uniformly receives the first device registration request of the devices to be accessed. The wide - narrowband access controller processes the device registration request generated by the wide - narrowband integrated convergence node device, registers the devices to be accessed, and applies to the authentication server for device certificates to complete the access preparation for the devices to be accessed. The wide - narrowband access controller also authenticates the convergence node certificates of the wide - narrowband integrated convergence node device to ensure the security when the devices to be accessed are registered. When the devices to be accessed are accessing, both the device certificates and the convergence node certificates are authenticated simultaneously to achieve the access of the devices to be accessed and the security during access. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a schematic structural diagram of wireless networking of multiple types of devices in the prior art;
[0041] Figure 2 is a schematic diagram of a substation broadband integrated wireless network according to an exemplary embodiment of the present invention;
[0042] Figure 3 is a schematic diagram of a wide - narrowband integrated convergence node device according to an exemplary embodiment of the present invention;
[0043] Figure 4 is a schematic diagram of a wide - narrowband integrated convergence node device according to another exemplary embodiment of the present invention;
[0044] Figure 5 is a schematic diagram of a substation broadband integrated wireless network according to another exemplary embodiment of the present invention;
[0045] Figure 6 is a flowchart of the communication management method according to the present invention;
[0046] Figure 7 is a structural block diagram of a computing device according to an exemplary embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] The present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. This embodiment is implemented on the premise of the technical solution of the present invention, and gives the detailed implementation manners and specific operation processes. However, the protection scope of the present invention is not limited to the following embodiments.
[0048] Embodiment 1
[0049] Figure 1 shows a schematic structural diagram of wireless networking of multiple types of devices in the prior art. As Figure 1As shown, narrowband devices and broadband devices are deployed in the substation. The narrowband devices and broadband devices use different methods for wireless networking respectively.
[0050] Among them, the narrowband devices are connected to the first network server through the edge physical proxy device, and then connected to the corresponding first backend server through the first network server. When the narrowband devices are connected to the edge physical proxy device, narrowband communication is used. Narrowband communication mainly uses low-frequency signals to transmit data. The transmission rate is lower than that of broadband signals, but it can penetrate obstacles and has a better coverage range in the case of long distances. Narrowband communication can be specifically implemented as communication technologies such as NB-IoT, LoRa, Sigfox, etc. The narrowband devices can be specifically implemented as sensor devices, and the present invention does not limit the specific implementation manner of the narrowband devices.
[0051] According to an embodiment of the present invention, the edge physical proxy device can be specifically implemented as an edge device in the narrowband communication network to implement functions such as network management and data forwarding. The first network server is used to forward the narrowband data received from the narrowband devices to the first backend server.
[0052] When the broadband devices are connected to the router, broadband communication is used. Broadband communication mainly uses high-frequency signals to transmit data. The transmission rate is very high, but the coverage range is limited. Broadband communication can be specifically implemented as communication technologies such as 4G, 5G, WiFi, etc. The broadband devices send the broadband data to the second backend server through the router, switch, and second network server. The broadband devices can be specifically implemented as devices that use broadband for communication. The present invention does not limit the specific implementation manner of the broadband devices.
[0053] Figure 2 Shows a schematic diagram of the broadband integrated wireless networking of the substation according to an exemplary embodiment of the present invention. As Figure 2 shown, the narrowband devices and broadband devices are communicatively connected to the narrowband and broadband convergence node device, and the narrowband and broadband convergence node device is connected to the authentication server through the access switch. The authentication server and the access switch are also connected to the narrowband and broadband access controller.
[0054] According to an embodiment of the present invention, the communication method of the narrowband devices includes narrowband communication, the communication method of the broadband devices includes broadband communication, or the communication method of the narrowband devices is narrowband communication, and the communication method of the broadband devices is broadband communication.
[0055] Narrowband devices specifically include online monitoring devices, such as various sensors. In a substation, online monitoring devices are mainly narrowband wireless communication devices mainly used for environmental monitoring. Specifically, they can be realized as sensors for monitoring equipment temperature, ambient temperature and humidity, partial discharge, leakage current, SF6 gas leakage, etc. The amount of data transmitted each time is about several hundred bytes, and the data is mostly reported periodically. Table 1 shows the information of some narrowband devices:
[0056] Table 1 Information of Narrowband Devices
[0057]
[0058] Broadband devices specifically include remote inspection devices and operation and maintenance management devices. In a substation, remote inspection devices mainly include devices for security monitoring, anti-theft, and personnel monitoring within the station, including robots, cameras, and drones, etc. The data transmitted includes inspection data of real-time video streams, and a high-bandwidth and real-time network is used. Operation and maintenance management devices mainly include devices for supporting various operation behaviors of on-site personnel, including handheld terminals (including live detection instruments), smart safety helmets, etc. By means of trajectory tracking and personnel positioning, the on-site personnel's inspection operations, switching operations, live maintenance, etc. are standardized, and data such as faces, personnel behaviors, and voices need to be collected. The network requirements are the same as those of remote inspection devices, and a high-bandwidth and real-time network is required. Table 2 shows the information of some broadband devices:
[0059] Table 2 Information of Broadband Devices
[0060]
[0061] According to an embodiment of the present invention, the narrow-wideband fusion aggregation node device receives narrowband data sent by narrowband devices and broadband data sent by broadband devices.
[0062] According to an embodiment of the present invention, the narrow-wideband fusion aggregation node device includes a processing module, one or more narrowband wireless communication modules, and one or more broadband wireless communication modules.
[0063] The narrowband wireless communication module is adapted to, when the communication mode of the device to be accessed is determined to be narrowband communication, in response to a communication connection request sent by a narrowband device, obtain the wireless networking protocol of the power transmission and transformation equipment Internet of Things node device from the adaptive protocol library, and establish a communication connection with the narrowband device according to the wireless networking protocol of the power transmission and transformation equipment Internet of Things node device.
[0064] The broadband wireless communication module is adapted to, when the communication mode of the device to be accessed is determined to be broadband communication, in response to a communication connection request sent by a broadband device, obtain the WAPI protocol from the adaptive protocol library, and establish a communication connection with the broadband device according to the WAPI protocol.
[0065] The processing module is adapted to parse the narrowband data sent by narrowband devices according to the wireless networking protocol of the power transmission and transformation equipment Internet of Things node devices, determine the monitored object, monitoring data and monitoring time, encapsulate the monitored object, monitoring data and monitoring time according to a preset format in a preset encapsulation format to obtain narrowband encapsulated data, parse the received broadband data according to the WAPI protocol, determine the monitored object, monitoring data and monitoring time, and encapsulate the monitored object, monitoring data and monitoring time according to a preset format in a preset encapsulation format to obtain broadband encapsulated data.
[0066] Figure 3 FIG. shows a schematic diagram of a narrowband and broadband fusion aggregation node device according to an exemplary embodiment of the present invention. As Figure 3 shown, the narrowband and broadband fusion aggregation node device includes a central processing unit for processing the received broadband data and narrowband data; and also includes a memory for storing the received broadband data and narrowband data, etc.
[0067] According to an embodiment of the present invention, the narrowband and broadband fusion aggregation node device further includes one or more narrowband wireless communication modules and one or more broadband wireless communication modules. The present invention does not limit the specific number of narrowband wireless communication modules or broadband wireless communication modules included in the narrowband and broadband fusion aggregation node device, nor does it limit the specific frequency bands covered by the narrowband wireless communication modules or broadband wireless communication modules.
[0068] According to an embodiment of the present invention, the narrowband and broadband fusion aggregation node device may include three narrowband wireless communication modules and one broadband wireless communication module.
[0069] According to an embodiment of the present invention, the frequency bands covered by the narrowband wireless communication modules in the narrowband and broadband fusion aggregation node device may include 470M and 2.4G frequency bands, etc., and the frequency bands covered by the broadband wireless communication modules may include 2.4G and 5G frequency bands, etc.
[0070] According to an embodiment of the present invention, the communication protocol adopted by the narrowband wireless communication module in the narrowband and broadband fusion aggregation node device for narrowband communication with narrowband devices includes the wireless networking protocol of the power transmission and transformation equipment Internet of Things node devices. The wireless networking protocol of the power transmission and transformation equipment Internet of Things node devices is a communication protocol that standardizes the networking communication of the sensing layer node devices of the power transmission and transformation equipment Internet of Things, and is a protocol specified for realizing the standardized networking and data transmission of node devices.
[0071] The communication protocols adopted by the broadband wireless communication module for broadband communication with broadband devices include the WAPI protocol, namely Wireless LAN Authentication and Privacy Infrastructure, which is named Wireless LAN Authentication and Privacy Infrastructure in Chinese. It is a security protocol and also a mandatory national standard for wireless LAN security in China.
[0072] Figure 4 FIG. shows a schematic diagram of a narrow-wideband convergence node device according to another exemplary embodiment of the present invention. As Figure 4 shown, the narrow-wideband convergence node device includes a central processor and a memory, a node networking protocol communication module, a first micro-power wireless communication module, and a second micro-power wireless communication module as narrowband wireless communication modules. The communication frequency band adopted by the node networking protocol communication module includes 470M, which can be used for narrowband communication with other narrow-wideband convergence node devices, sensor devices that communicate in a low-power mode, etc. Sensor devices that communicate in a low-power mode specifically include devices with a small amount of data transmitted each time, such as less than 100Kb or less than 200b, etc. The communication frequency bands adopted by the first micro-power wireless communication module and the second micro-power wireless communication module include 2.4G. The devices for narrowband communication by the node networking protocol communication module, the first micro-power wireless communication module, and the second micro-power wireless communication module include narrowband devices, such as on-line monitoring devices.
[0073] According to an embodiment of the present invention, the narrow-wideband convergence node device further includes a WAPI wireless communication module as a broadband wireless communication module. The communication frequency bands adopted by the WAPI wireless communication module include 2.4G and 5G. The devices for broadband communication by the WAPI wireless communication module include broadband devices, such as remote inspection devices and operation and maintenance management devices.
[0074] According to an embodiment of the present invention, the narrow-wideband convergence node device is further provided with an optical fiber or network cable interface for connecting to devices such as an access switch for data exchange.
[0075] Back to Figure 2 , the access switch is used to implement data exchange between the authentication server, the narrow-wideband access controller, and the narrow-wideband convergence node device.
[0076] The authentication server can be specifically implemented as a broadband and narrowband authentication server (AS). The authentication server is generally deployed centrally in the substation main station and communicates with the substation substation. The authentication server can be deployed in a primary and standby mode. The authentication server is suitable for managing the digital certificates of broadband devices, narrowband devices, and narrow-wideband access controllers, including certificate issuance, certificate authentication, certificate recovery, etc.
[0077] The wide and narrow band access controller, namely the wide and narrow band AC, is an edge computing device that supports wide and narrow band integrated communication. It is generally deployed in the secondary room cabinet and is the management device for the wide and narrow wireless networks in the substation. It simultaneously realizes wide and narrow network coverage, supports wide and narrow band network management functions, has the AC function of the broadband network WAPI built-in, and has all the functions of the access node in the wireless networking protocol of the original narrow band power transmission and transformation equipment Internet of Things node devices. According to different voltage levels, the wide and narrow band AC can be selectively deployed in the substation, regional centralized control, city or province, aggregating all the service data of the wide and narrow band integrated aggregation node devices, namely the wide and narrow band integrated AP, and forwarding it externally in a unified manner. It supports the management of all wide and narrow band integrated AP devices, including the registration, networking, and configuration distribution of the wide and narrow band integrated AP.
[0078] Figure 5 Figure 5 shows a schematic diagram of a substation broadband integrated wireless networking according to another exemplary embodiment of the present invention. As Figure 5 shown, the dotted line represents the wireless network connection, and the wireless network includes a broadband network and a narrow band network, while the solid line represents the wired network.
[0079] The narrow band devices include wireless temperature and humidity sensors, voiceprint monitoring sensors, and environmental noise sensors for online monitoring; the broadband devices include drones, robots, bullet cameras, and intelligent monitoring mobile terminals for remote patrol, as well as safety helmets and handheld terminals for operation and maintenance management.
[0080] According to an embodiment of the present invention, the narrow band devices communicate with the wide and narrow band integrated AP through narrow band communication, and the broadband devices communicate with the wide and narrow band integrated AP through broadband communication. Multiple wide and narrow band integrated aggregation node devices, namely the wide and narrow band integrated AP, can be distributedly deployed in the substation. The present invention does not limit the number and deployment method of the specifically deployed broadband integrated aggregation node devices.
[0081] According to an embodiment of the present invention, when deploying one or more wide and narrow band integrated aggregation node devices, one or more wireless access points AP for broadband communication can also be supplementarily set for the broadband network, such as the WAPI wireless access point AP that uses the WAPI protocol for broadband communication, simply referred to as the WAPI AP.
[0082] According to an embodiment of the present invention, the narrow band integrated aggregation node device, namely the wide and narrow band integrated AP, can be connected to the wide and narrow band access controller (AC) or the core switch through one of the access switches. Among them, the core switch can be set in the main and standby machine modes. The narrow band integrated aggregation node device, namely the wide and narrow band integrated AP, can also be connected to the core switch through the optical network unit, optical splitter, and optical line terminal.
[0083] The narrowband converged aggregation node, or broadband and narrowband converged AP, can also connect to other switches at the master station through the slave station's core switch, and further to the master station's authentication server through other switches. The authentication server is also connected to the integrated network equipment, and the core switch is also connected to the master station system and equipped with a firewall.
[0084] Forward isolation devices and reverse isolation devices are also set between the substation and the main station, and are connected to the comprehensive application host in the production control area.
[0085] According to one embodiment of the present invention, when installing a broadband and narrowband fusion aggregation node device in a substation, it is necessary to reasonably deploy multiple broadband and narrowband fusion aggregation node devices based on the data collection requirements in the substation and the location where the broadband and narrowband fusion aggregation node device can be set. If there is still a demand for a broadband network but it is not covered, it is necessary to set up one or more wireless access points AP for broadband communication, such as WAPI wireless access points AP, to meet the corresponding network requirements.
[0086] Example 2
[0087] When broadband devices and narrowband devices want to access the broadband-narrowband convergence node, the authentication server and the broadband-narrowband access controller manage the access and data transmission of the broadband devices and narrowband devices.
[0088] According to an embodiment of the present invention, the authentication server first issues a convergence node certificate to multiple broadband and narrowband convergence node devices connected to the authentication server. The convergence node certificate is a certificate that identifies the legal identity of the broadband and narrowband convergence node device.
[0089] According to one embodiment of the present invention, the broadband-narrowband convergence node device is also equipped with an adaptive protocol library to meet the connection requirements of multiple devices, including broadband and narrowband devices. According to one embodiment of the present invention, after multiple broadband-narrowband convergence node devices are set up within the substation, the broadband-narrowband convergence node device begins operation and transmits an AP signal. Broadband and narrowband devices can then select the broadband-narrowband convergence node device with the strongest signal that can be found for connection.
[0090] According to an embodiment of the present invention, different broadband devices and narrowband devices may have multiple communication modes, and thus one of the communication modes may be selected for communication according to the data to be sent or received.
[0091] According to an embodiment of the present invention, the access device includes a broadband device and a narrowband device. When the access device establishes a communication connection with the broadband-narrowband convergence node device for the first time, it sends a first device registration request to the broadband-narrowband convergence node device.
[0092] If the device to be accessed is a broadband device, the broadband device sends a first device registration request to the broadband wireless communication module through broadband communication; if the device to be accessed is a narrowband device, the narrowband device sends a first device registration request to the narrowband wireless communication module through the narrowband communication module.
[0093] The first device registration request includes the device information of the device to be connected. This information includes: a unique identifier for the device to be connected, including its device ID, communication method, aggregation node device ID, and data usage. The aggregation node device ID is the unique ID of the broadband and narrowband convergence aggregation node device that the device to be connected will connect to.
[0094] Figure 6 FIG. 6 is a flow chart showing a communication management method 600 based on a broadband-narrowband convergence node device according to the present invention. Figure 6 As shown, step 610 is first executed. The broadband and narrowband access controller responds to the second device registration request sent by the broadband and narrowband fusion aggregation node device, parses the second device registration request, and obtains the first device registration request and the aggregation node certificate of the broadband and narrowband fusion aggregation node device. The first device registration request is a request sent by the device to be accessed to the broadband and narrowband fusion aggregation node device. The first device registration request includes device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in the substation.
[0095] According to one embodiment of the present invention, after receiving a first device registration request, the broadband converged aggregation node device packages the first device registration request and the aggregation node certificate to generate a second device registration request, which is then sent to the broadband and narrowband access controller. The broadband and narrowband access controller parses the second device registration request and obtains the first device registration request and the aggregation node certificate.
[0096] Then, step 620 is executed, the broadband and narrowband access controller sends the aggregation node certificate to the authentication server, and the authentication server performs certificate authentication on the aggregation node certificate. After the authentication is successful, a first authentication success message is sent to the broadband and narrowband access controller.
[0097] Subsequently, step 630 is executed. The broadband and narrowband access controller responds to the first authentication success message sent by the authentication server after performing certificate authentication on the aggregation node certificate, registers the device to be accessed according to the device information, and applies for the device certificate of the device to be accessed from the authentication server.
[0098] In response to the received first authentication success message, the broadband and narrowband access controller registers the device to be accessed according to the device information of the device to be accessed, and writes various items of information in the device information of the device to be accessed into the registration information table.
[0099] After the broadband and narrowband access controller successfully registers the device to be accessed, it applies to the authentication server for the device certificate of the device to be accessed. The authentication server generates a device certificate based on the device information of the device to be accessed and sends it to the broadband and narrowband access controller.
[0100] Subsequently, step 640 is executed. In response to the device certificate generated by the authentication server based on the device information received, the broadband and narrowband access controller sends the device certificate to the device to be accessed through the broadband and narrowband convergence node device.
[0101] According to an embodiment of the present invention, in response to the received generated device certificate, the broadband and narrowband access controller sends a registration success message and the device certificate to the broadband and narrowband convergence node device. The broadband and narrowband convergence node device sends the device certificate to the device to be accessed.
[0102] After the device to be accessed receives the device certificate, each time it establishes a communication connection with the broadband and narrowband convergence node device, it sends a communication connection request to the broadband and narrowband convergence node device, and the communication connection request includes the device certificate.
[0103] After the broadband and narrowband convergence node device receives the communication connection request, it generates a communication verification request based on the communication connection request and the convergence node certificate and sends it to the broadband and narrowband access controller.
[0104] Subsequently, step 650 is executed. In response to the communication verification request sent by the broadband and narrowband convergence node device received, the broadband and narrowband access controller analyzes the communication verification request to obtain the device certificate of the device to be accessed and the convergence node certificate, and sends the device certificate of the device to be accessed and the convergence node certificate to the authentication server for certificate authentication.
[0105] When the authentication server performs certificate authentication, if the authentication passes, it sends a second authentication success message to the broadband and narrowband access controller.
[0106] Finally, step 660 is executed. In response to the second authentication success message sent by the authentication server received, the broadband and narrowband access controller sends an allow connection message to the broadband and narrowband convergence node device so that the device to be accessed can access the broadband and narrowband convergence node device and become an access device.
[0107] Based on the second authentication success message, the broadband and narrowband access controller allows the device to be accessed to access the broadband and narrowband convergence node device and sends an allow connection message to the broadband and narrowband convergence node device that received the communication connection request. After the broadband and narrowband convergence node device receives the allow connection message, it negotiates a secret key with the device to be accessed to determine the session secret key. After the device to be accessed completes the secret key negotiation, it becomes an access device connected to the broadband and narrowband convergence node device.
[0108] The session key includes the private key and public key of the access device, and the private key and public key of the wide and narrow integration convergence node device.
[0109] When the access device communicates with the wide and narrow integration convergence node device, the uplink communication data is encrypted according to the public key of the wide and narrow integration convergence node device and sent to the wide and narrow integration convergence node device. After receiving the encrypted uplink communication data, the wide and narrow integration convergence node device decrypts the uplink communication data according to the private key of the wide and narrow integration convergence node device to obtain the data content of the uplink communication data.
[0110] When the wide and narrow integration convergence node device needs to communicate with the access device, the downlink communication data is encrypted according to the public key of the access device and sent to the access device. After receiving the downlink communication data sent by the wide and narrow integration convergence node device, the access device decrypts the downlink communication data according to the private key of the access device to obtain the data content of the downlink communication data.
[0111] According to an embodiment of the present invention, the access device includes broadband devices and narrowband devices. When the broadband device communicates with the wide and narrow integration convergence node device, a communication connection is established with the broadband wireless communication module for communication. When the narrowband device communicates with the wide and narrow integration convergence node device, a communication connection is established with the narrowband wireless communication module for communication.
[0112] According to an embodiment of the present invention, the uplink communication data includes narrowband data and broadband data. The downlink communication data includes data sent to narrowband devices and broadband devices.
[0113] According to an embodiment of the present invention, after the broadband device and the narrowband device are connected to the wide and narrow integration convergence node device, the wide and narrow access controller manages the access devices according to the device type, that is, the access devices include broadband devices and narrowband devices; the broadband devices include remote inspection devices and operation and maintenance management devices; the narrowband devices include on-line monitoring devices, such as various sensors.
[0114] According to an embodiment of the present invention, the wide and narrow access controller can manage the access devices according to the registration information table. The registration information table also includes the device type of the access device, specifically whether it belongs to a broadband device or a narrowband device, and which device it is among the broadband devices or narrowband devices.
[0115] According to an embodiment of the present invention, the wide and narrow access controller can also create device lists of different categories, such as device lists of broadband devices, device lists of narrowband devices, and can be further subdivided, such as device lists of remote inspection devices, device lists of operation and maintenance management devices, and device lists of on-line monitoring devices.
[0116] According to an embodiment of the present invention, the broadband and narrowband access controller may also provide a management interface facing the backend. The management personnel at the backend can obtain the management status of various devices by the broadband and narrowband access controller through the management interface, including various device lists.
[0117] The management interface also provides management controls in the device list. The user can disconnect the access device in the device list according to the management controls, set the disconnection time, etc., and set to add it to the blacklist to prohibit the device from accessing the broadband and narrowband convergence node device in the future. The present invention does not limit the specific implementation manner of the management controls and the management manner of the access device.
[0118] According to an embodiment of the present invention, different types of devices can also be set to have different security levels. For example, it is set that the remote inspection devices have the third-level security level, the operation and maintenance management devices have the second-level security level, and the online monitoring devices have the first-level security level. The security level from the first level to the third level increases in turn.
[0119] Different security levels have different configuration items. For example, devices with different security levels have different key negotiation frequencies. For example, it is set that for the devices with the first-level security level, when accessing the broadband and narrowband convergence node device, the key negotiation is carried out with the broadband and narrowband convergence node device every month to replace the key. For the devices with the second-level security level, when accessing the broadband and narrowband convergence node device, the key negotiation is carried out with the broadband and narrowband convergence node device every week to replace the key. For the devices with the third-level security level, when accessing the broadband and narrowband convergence node device, the key negotiation is carried out with the broadband and narrowband convergence node device every day to replace the key.
[0120] According to an embodiment of the present invention, different categories of devices are also set to have different data transmission priorities. For example, it is set that the remote inspection data sent by the remote inspection devices has the third-level priority, the operation and maintenance management data sent by the operation and maintenance management devices has the second-level priority, and the online monitoring data sent by the online monitoring devices has the first-level priority. The priority level from the first level to the third level increases in turn.
[0121] According to an embodiment of the present invention, an uplink data transmission message queue is provided in the broadband and narrowband convergence node device. After the broadband and narrowband convergence node device receives the remote inspection data, operation and maintenance management data, and online monitoring data, the above data is sequentially added to the uplink data transmission message queue.
[0122] Subsequently, the data in the uplink data transmission message queue is sorted. The remote inspection data has the third-level priority and is placed at the forefront of the message queue for acquisition and processing first. The operation and maintenance management data has the second priority and is placed after the remote inspection data. The online monitoring data has the third priority and is placed after the operation and maintenance management data. Subsequently, if there are multiple uplink communication data for each priority level, they are sorted within each priority level in the order of reception time; if there are multiple remote inspection data in the uplink data transmission message queue, they are sorted according to the reception time of each remote inspection data, and the remote inspection data with an earlier reception time is placed before the remote inspection data with a later reception time. Similarly, if there are multiple operation and maintenance management data in the uplink data transmission message queue, the operation and maintenance management data with an earlier reception time is placed before the operation and maintenance management data with a later reception time. If there are multiple online monitoring data in the uplink data transmission message queue, the online monitoring data with an earlier reception time is placed before the online monitoring data with a later reception time.
[0123] By setting an uplink data transmission message queue in the wide-narrowband convergence node device and sorting various data according to priority levels in the uplink data transmission message queue, it can effectively ensure that important data is decrypted and transmitted with high priority, ensuring a smooth communication link. Remote inspection devices include inspection robots, drones, mobile surveillance balls, etc., which often need to transmit real-time data to the backend for staff to view and to control the remote inspection devices. Therefore, the remote inspection data of such devices should be processed with the highest priority. Operation and maintenance management devices include handheld terminals, smart safety helmets, etc., which need to transmit data back for real-time monitoring of the positions of personnel using the operation and maintenance management devices. Therefore, the processing priority of operation and maintenance management data is higher than that of online monitoring data.
[0124] According to an embodiment of the present invention, when the wide-narrowband convergence node device processes the data in the uplink data transmission message queue, it takes out one data from the head of the message queue for processing each time. The data processing process includes steps such as decryption and transmission. The present invention does not limit the specific steps included in the message processing process.
[0125] According to an embodiment of the present invention, the wide-narrowband convergence node device also collects the device status of the access device and transmits the device status of the access device to the wide-narrowband access controller so that the wide-narrowband access controller can manage the device according to the device status of the access device.
[0126] According to an embodiment of the present invention, the device status includes device location, device power, device fault information, etc. The device location is the location of the currently connected device in the substation. The device power is the current power of the connected device, such as the remaining power of inspection robots, drones, mobile surveillance cameras, etc. The device fault information includes the faults currently encountered by the device, such as the problem that the inspection robot cannot move forward, the problem that the images captured by the camera installed on the drone are unclear, etc.
[0127] According to an embodiment of the present invention, the connected device sends the device status to the broadband and narrowband access controller through the broadband and narrowband convergence node device. The broadband and narrowband access controller can determine at any time whether it is necessary to restart the connected device or suspend the use of the connected device according to the device status of the connected device.
[0128] According to an embodiment of the present invention, when the remaining power of the connected device, such as inspection robots, drones, mobile surveillance cameras, etc. is less than the preset power threshold, a suspension use command can be sent to the connected device through the broadband and narrowband convergence node device, so that the connected device returns to the starting point using the remaining power.
[0129] According to an embodiment of the present invention, when the connected device, such as inspection robots, drones, mobile surveillance cameras, etc. encounters a fault, the connected device can be controlled to return to the starting point or suspended for use, waiting for maintenance personnel to repair the connected device according to the device fault information.
[0130] According to an embodiment of the present invention, the connected device can also switch between broadband communication and narrowband communication. According to an embodiment of the present invention, if the connected device has the capabilities of both broadband communication and narrowband communication, when it is necessary to change the communication method according to the form of the data to be transmitted and received and internal changes, a communication method change request can be sent to the broadband and narrowband convergence node device.
[0131] According to an embodiment of the present invention, the communication method change request includes the device certificate and the target communication method to be changed. For example, when changing from narrowband communication to broadband communication, the target communication method is broadband communication; when changing from broadband communication to narrowband communication, the target communication method is narrowband communication.
[0132] When the broadband and narrowband convergence node device receives the communication method change request, it sends the communication method change request and the convergence node certificate to the broadband and narrowband access controller. The broadband and narrowband access controller analyzes the communication method change request to obtain the device certificate, and then sends the device certificate and the convergence node certificate to the authentication server. After receiving the device certificate and the convergence node certificate, the authentication server performs certificate authentication. If the authentication passes, a new device certificate is made according to the received device certificate. Specifically: in the new device certificate, the communication method in the device information is modified to the target communication method to obtain the new device certificate.
[0133] Subsequently, the authentication server sends the new device certificate to the narrow and broadband access controller. After receiving the new device certificate, the narrow and broadband access controller modifies the communication method in the device information of the access device to the target communication method in the registration information table, and then sends the new device certificate to the narrow and broadband convergence node device. After receiving the new device certificate, the narrow and broadband convergence node device forwards the new device certificate to the access device, and then uses the corresponding communication module to establish a communication connection with the access device according to the target communication method, and performs key negotiation to replace the key for communication.
[0134] According to an embodiment of the present invention, the access device uses narrowband communication before changing the communication method. When the access device needs to use broadband communication to communicate with the narrow and broadband convergence node device, it sends a communication method change request to the narrow and broadband convergence node device. The communication method change request includes the device certificate and the target communication method to be changed, that is, broadband communication.
[0135] After receiving the communication method change request, the narrow and broadband convergence node device sends the communication method change request and the convergence node certificate to the narrow and broadband access controller. The narrow and broadband access controller analyzes the communication method change request to obtain the device certificate, and then sends the device certificate and the convergence node certificate to the authentication server. After receiving the device certificate and the convergence node certificate, the authentication server performs certificate authentication. If the authentication passes, a new device certificate is made according to the received device certificate. Specifically: in the new device certificate, the communication method in the device information is modified to the target communication method to obtain the new device certificate. Specifically: in the new device certificate, the communication method in the device information is modified to broadband communication to obtain the new device certificate.
[0136] Subsequently, the authentication server sends the new device certificate to the narrow and broadband access controller. After receiving the new device certificate, the narrow and broadband access controller modifies the communication method in the device information of the access device to broadband communication in the registration information table, and then sends the new device certificate to the narrow and broadband convergence node device. After receiving the new device certificate, the narrow and broadband convergence node device forwards the new device certificate to the access device, and then uses the corresponding broadband wireless communication module to establish broadband communication with the access device according to broadband communication, and performs key negotiation to replace the key for broadband communication.
[0137] Embodiment 3
[0138] Since some access devices, such as inspection robots, drones, mobile surveillance cameras, etc. in remote inspection devices, need to move in a substation, these access devices need to replace the access wide and narrow fusion aggregation node devices during the movement. In order to enable such access devices to seamlessly replace the access wide and narrow fusion aggregation node devices during operation and keep their networks always unobstructed, the present invention has made the following related designs:
[0139] According to an embodiment of the present invention, the wide and narrow band access controller obtains the movement route of the access device in the substation, determines the wide and narrow fusion aggregation node devices to be connected at each point on the movement route, and obtains the set of wide and narrow fusion aggregation node devices to be connected. The determination method of the movement route can be obtained by pre-setting the movement route of the access device, and the present invention does not limit the specific determination method of the movement route.
[0140] According to an embodiment of the present invention, to determine the wide and narrow fusion aggregation node devices to be connected at each point on the movement route, the wide and narrow fusion aggregation node device closest to each point on the movement route can be determined, and the wide and narrow fusion aggregation node device closest to each point is used as the wide and narrow fusion aggregation node device to be connected.
[0141] According to an embodiment of the present invention, the wide and narrow fusion aggregation node devices to be connected at each point can also be determined by calculating the signal strength. First, obtain the floor plan of the substation. The floor plan of the substation includes the building walls of the substation, the main equipment of the substation, broadband devices, narrowband devices, and the movement route of the access device. The specific positions of the building walls of the substation, the main equipment of the substation, the wide and narrow fusion aggregation node devices, broadband devices, and narrowband devices, as well as the movement route of the access device, are marked on the floor plan of the substation.
[0142] The building walls of the substation include the outer walls and inner walls of buildings such as the perimeter wall and houses of the substation. The main equipment of the substation is the equipment for maintaining the normal operation of the substation, such as transformers, etc. The broadband devices and narrowband devices are suitable for monitoring the status of the substation environment, the main equipment of the substation, etc.
[0143] Since the building walls of the substation and the main equipment of the substation will both have a certain impact on the signal transmission of the broadband devices and narrowband devices, the signal of the wide and narrow fusion aggregation node device will generate a certain attenuation when passing through the building wall or bypassing the substation.
[0144] According to an embodiment of the present invention, a substation wall signal attenuation coefficient is set for the signal attenuation caused by the substation wall. The substation wall signal attenuation coefficient can be determined according to the thickness and material of different substation walls, and can specifically be obtained through actual testing, or can also be preset, such as set to 0.7. When the signal of the wide and narrow fusion convergence node device passes through the substation wall once, the signal strength is multiplied by the substation wall signal attenuation coefficient each time.
[0145] The present invention also sets a substation main equipment signal attenuation coefficient for the signal attenuation caused by the substation main equipment. The substation main equipment signal attenuation coefficient can be determined according to the size of different substation main equipment and the electromagnetic effect generated when the substation main equipment is working, and can specifically be obtained through actual testing, or can also be preset, such as set to 0.8. When the signal of the wide and narrow fusion convergence node device bypasses the substation equipment once, the signal strength is multiplied by the substation main equipment signal attenuation coefficient each time.
[0146] The position coordinates of each wide and narrow fusion convergence node device include the abscissa x and the ordinate y , the position coordinates of the wide and narrow fusion convergence node device can be represented by longitude and latitude respectively, and can also be determined by establishing a coordinate system with the floor plan of the substation as the reference. The present invention does not limit the specific representation method of the position coordinates of the wide and narrow fusion convergence node device. It is preset that a total of k wide and narrow fusion convergence node devices are set in the substation, then the position coordinates of the t th wide and narrow fusion convergence node device include ( ), t represents the t th wide and narrow fusion convergence node device, t has a value range of 1 - k .
[0147] The substation includes m access devices. Similar to the representation method of the position coordinates of the wide and narrow fusion convergence node device, i represents the i th access device, i has a value range of 1 - m . The position coordinates of the i th access device include ( ). Since the access device moves in the substation, the position coordinates of the access device will change. According to an embodiment of the present invention, the movement route of the access device in the substation can be divided according to a predetermined step size to obtain multiple route nodes on the predetermined route, and the distance between adjacent two route nodes is the predetermined step size. Set the number of route nodes on the predetermined route of the access device to be n, the position coordinates of each route node can be expressed as ( ). l Indicates the l th route node on the predetermined route, l The value range of is 1 - n .
[0148] According to the i th access device's mobile route, the position coordinates of the l th route node ( ) and the position coordinates of the t th narrow-wideband convergence node device position ( ), determine the straight-line distance , including:
[0149] ,
[0150] Is the straight-line distance between the l th route node on the mobile route of the i-th access device and the t th narrow-wideband convergence node device in the substation floor plan.
[0151] The t th narrow-wideband convergence node device transmits its signal to the i th access device's mobile route at the l th route node, and the theoretical signal strength is . Is the theoretical signal strength function of the narrow-wideband convergence node device, which is related to the distance from the receiving device, Can be obtained through steps such as surveying and fitting.
[0152] Subsequently, set the number of substation walls and the number of main substation equipment separated between the narrow-wideband convergence node device and the route node according to the connection lines between each narrow-wideband convergence node device and each route node on the substation floor plan. The number of substation walls separated between the t th narrow-wideband convergence node device and the i th access device's mobile route at the l th route node is , and the number of main substation equipment separated is .
[0153] The signal attenuation coefficient of the substation wall is α, and the signal attenuation coefficient of the main substation equipment is β. Then, the actual signal strength of the t th narrow-wideband convergence node device transmitting its signal to the i th access device's mobile route at the l th route node is: 。
[0154] In the present invention, each access device is set to select the widest and narrowest fusion convergence node device with the maximum actual signal strength on its moving route for connection. Then, for the i th access device, the connection signal strength of the l th route node on its moving route is k the maximum value of the actual signal strengths of the narrowband devices - in 。
[0155] The widest and narrowest fusion convergence node device with the maximum actual signal strength at each route node is the widest and narrowest fusion convergence node device to be connected on the moving route, thereby obtaining the set of widest and narrowest fusion convergence node devices to be connected on the moving route.
[0156] According to an embodiment of the present invention, the wide and narrowband access controller sends the device certificate and the convergence node certificate of each widest and narrowest fusion convergence node device in the widest and narrowest fusion convergence node device set to the authentication server. After receiving the device certificate and the convergence node certificate, the authentication server performs certificate authentication. If the authentication passes, a multi-node access device certificate is made according to the received device certificate. Specifically: in the multi-node access device certificate, the convergence node device ID of each widest and narrowest fusion convergence node device in the widest and narrowest fusion convergence node device set is written in the device information to generate the multi-node access device certificate.
[0157] Subsequently, the authentication server sends the multi-node access device certificate to the wide and narrowband access controller. After receiving the multi-node access device certificate, the wide and narrowband access controller writes the convergence node device ID of each widest and narrowest fusion convergence node device in the widest and narrowest fusion convergence node device set in the device information of the access device in the registration information table, completing the filing of the access device accessing multiple widest and narrowest fusion convergence node devices.
[0158] Subsequently, the new multi-node access device certificate is sent to the widest and narrowest fusion convergence node device. After receiving the multi-node access device certificate, the widest and narrowest fusion convergence node device forwards the multi-node access device certificate to the access device.
[0159] When the access device moves on the preset moving route, it performs authentication connection with the widest and narrowest fusion convergence node devices to be accessed on the moving route according to the multi-node access device certificate, so as to realize seamless replacement of the accessed widest and narrowest fusion convergence node devices when moving on the moving route, keep its network always unobstructed, and avoid registering relevant information again on the moving route, preventing network interruption and disconnection of the control of the access device when moving.
[0160] According to an embodiment of the present invention, the present invention further provides a communication management system based on a wide and narrowband fusion convergence node device. The system includes a wide and narrowband access controller, an authentication server, and a wide and narrowband fusion convergence node device that are communicatively connected to the wide and narrowband access controller. The wide and narrowband fusion convergence node device is adapted to generate a device registration second request based on the device registration first request and the convergence node certificate after receiving the device registration first request, and send it to the wide and narrowband access controller. The device registration first request is a request sent by a device to be accessed to the wide and narrowband fusion convergence node device, and the device registration first request includes the device information of the device to be accessed. The device to be accessed includes broadband devices and narrowband devices deployed in a substation;
[0161] The wide and narrowband access controller is adapted to parse the device registration second request in response to receiving it, obtain the device registration first request and the convergence node certificate of the wide and narrowband fusion convergence node device, and send the convergence node certificate to the authentication server;
[0162] The authentication server is adapted to authenticate the convergence node certificate. If the authentication is successful, it sends an authentication success message to the wide and narrowband access controller;
[0163] The wide and narrowband access controller is also adapted to register the device to be accessed according to the device information and apply to the authentication server for the device certificate of the device to be accessed;
[0164] The authentication server is also adapted to generate a device certificate according to the device information of the device to be accessed;
[0165] The wide and narrowband fusion convergence node device is also adapted to generate a communication verification request based on the communication connection request and the convergence node certificate after receiving the communication connection request sent by the access device, and send it to the wide and narrowband access controller. The communication connection request includes the device certificate;
[0166] The wide and narrowband access controller is also adapted to parse the communication verification request in response to receiving the communication verification request sent by the wide and narrowband fusion convergence node device, obtain the device certificate of the device to be accessed and the convergence node certificate, and send the device certificate of the device to be accessed and the convergence node certificate to the authentication server for certificate authentication;
[0167] The authentication server is also adapted to authenticate the device certificate and the convergence node certificate. If the authentication is successful, it sends an authentication success message to the authentication server;
[0168] The wide and narrowband access controller is also adapted to send an allow connection message to the wide and narrowband fusion convergence node device in response to receiving the authentication success message sent by the authentication server, so that the device to be accessed can access the wide and narrowband fusion convergence node device and become an access device.
[0169] Embodiment 4
[0170] The wide - narrowband fusion convergence node device, wide - narrowband access controller, and authentication server of the present invention can be specifically implemented as a computing device. Figure 7 FIG. shows a schematic diagram of a computing device 700 according to an exemplary embodiment of the present invention.
[0171] As Figure 7 shown, the computing device 700 may include: a central processing unit 710, a memory 720, an input / output interface 730, a communication interface 740, and a bus 750. Among them, the central processing unit 710, the memory 720, the input / output interface 730, and the communication interface 740 are communicatively connected to each other inside the computing device through the bus 750.
[0172] The central processing unit 710 can be implemented in ways such as a general - purpose CPU (Central Processing Unit), a microprocessor, an application - specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0173] The memory 720 can be implemented in forms such as ROM (Read Only Memory), RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 720 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 720 and are called and executed by the central processing unit 710.
[0174] The input / output interface 730 is used to connect to an input / output module to implement information input and output. The communication interface 740 is used to implement communication interaction between this computing device and other devices. The bus 750 includes a path for transmitting information between various components of the computing device (such as the central processing unit 710, the memory 720, the input / output interface 730, and the communication interface 740).
[0175] It should be noted that although the above - mentioned computing device only shows the central processing unit 710, the memory 720, the input / output interface 730, the communication interface 740, and the bus 750, in the specific implementation process, this computing device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above - mentioned computing device may also only include the components necessary to implement the solutions of the embodiments of this specification, and do not necessarily include all the components shown in the figure.
[0176] As used herein, unless otherwise specified, the use of ordinal numbers such as "first", "second", "third", etc. to describe ordinary objects merely indicates different instances of similar objects and is not intended to imply that the objects so described must have a given order in terms of time, space, ranking, or any other manner.
[0177] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative efforts. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field based on the concept of the present invention through logical analysis, reasoning, or limited experiments on the basis of the prior art shall fall within the protection scope determined by the claims.
Claims
1. A communication management method based on a broadband-narrowband convergence node device, characterized in that: Used to achieve communication connections between broadband and narrowband access controllers, authentication servers, and broadband and narrowband convergence node devices, including device registration, certificate application and distribution, communication verification, and connection authorization. Through the collaboration between broadband and narrowband access controllers and authentication servers, it ensures that the devices to be connected can securely access the broadband and narrowband convergence node devices. The method comprises the following steps: The broadband and narrowband access controller responds to the second device registration request received from the broadband and narrowband convergence node device, parses the second device registration request, and obtains the first device registration request and the convergence node certificate of the broadband and narrowband convergence node device, wherein the first device registration request is a request sent by the device to be accessed to the broadband and narrowband convergence node device, including device information of the device to be accessed, and the device to be accessed includes broadband devices and narrowband devices deployed in the substation; The broadband and narrowband access controller sends the aggregation node certificate to the authentication server; The broadband and narrowband access controller registers the device to be accessed according to the device information in response to the first authentication success message sent by the authentication server after performing certificate authentication on the aggregation node certificate, and applies for the device certificate of the device to be accessed from the authentication server; The broadband and narrowband access controller responds to the received device certificate generated by the authentication server according to the device information and sends the device certificate to the access device through the broadband and narrowband convergence node device; The broadband and narrowband access controller responds to the communication verification request received from the broadband and narrowband convergence node device, parses the communication verification request, obtains the device certificate and convergence node certificate of the device to be accessed, and sends the device certificate and convergence node certificate of the device to be accessed to the authentication server for certificate authentication; The broadband and narrowband access controller responds to the second authentication success message sent by the authentication server after authenticating the device certificate and the aggregation node certificate, and sends a connection permission message to the broadband and narrowband convergence node device, so that the device to be accessed can access the broadband and narrowband convergence node device and become an access device; The access devices include broadband devices and narrowband devices. The broadband devices include remote patrol devices and operation and maintenance management devices. The narrowband devices include online monitoring devices. The remote patrol devices have a third security level, the operation and maintenance management devices have a second security level, and the narrowband devices have a first security level. The key negotiation frequency of the access devices of the third security level is higher than that of the devices of the second security level, and the key negotiation frequency of the access devices of the second security level is higher than that of the devices of the first security level.
2. A communication management method based on a broadband-narrowband convergence node device according to claim 1, characterized in that: The broadband and narrowband convergence node device responds to the communication connection request received from the device to be accessed, generates a communication verification request based on the communication connection request and the convergence node certificate, and sends the communication verification request to the broadband and narrowband access controller, wherein the communication connection request includes the device certificate of the device to be accessed.
3. The communication management method based on broadband and narrowband convergence node equipment according to claim 1, characterized in that: After receiving the connection permission message, the broadband-narrowband convergence node device performs key negotiation with the device to be connected to determine a session key, where the session key includes a private key and a public key of the broadband-narrowband convergence node device. The method further includes: The broadband and narrowband fusion aggregation node device responds to the encrypted uplink communication data sent by the access device, decrypts the encrypted uplink communication data according to the private key of the broadband and narrowband fusion aggregation node device to obtain the data content of the uplink communication data. The encrypted uplink communication data is obtained by the access device encrypting the uplink communication data according to the public key of the broadband and narrowband fusion aggregation node device.
4. The communication management method based on broadband and narrowband convergence node equipment according to claim 3, characterized in that: The session key includes a private key and a public key of the access device, and the method further includes: In response to receiving the encrypted downlink communication data sent by the broadband and narrowband convergence node device, the access device decrypts the encrypted downlink communication data according to the access device private key to obtain the data content of the downlink communication data. The encrypted downlink communication data is obtained by the broadband and narrowband convergence node device encrypting the downlink communication data according to the access device public key.
5. The communication management method based on broadband and narrowband convergence node equipment according to claim 1, characterized in that: The access devices include broadband devices and narrowband devices. The broadband devices include remote inspection devices and operation and maintenance management devices. The narrowband devices include online monitoring devices. The remote inspection data sent by the remote inspection devices have a third-level priority, the operation and maintenance management data sent by the operation and maintenance management devices have a second-level priority, and the online monitoring data sent by the online detection devices have a first-level priority. The broadband-narrowband convergence node device is provided with an uplink data sending message queue, and the method further includes: In response to receiving uplink communication data of multiple priorities, the broadband-narrowband convergence node device puts the remote patrol data of the third priority at the front of the uplink data sending message queue; Arrange the second priority operation and maintenance management data after the remote inspection data; Arrange the third priority online monitoring data after the operation and maintenance management data; Each time, a piece of uplink communication data is taken from the head of the uplink data sending message queue for processing; If there are multiple uplink communication data of each priority level, they are sorted within each priority level in the order of reception time.
6. The communication management method based on broadband and narrowband convergence node equipment according to claim 1, characterized in that: The broadband and narrowband access controller manages the access device according to the device status received from the broadband and narrowband convergence node device, wherein the device status includes device location, device power and device fault information.
7. The communication management method based on broadband and narrowband convergence node equipment according to claim 1, characterized in that: The access device is suitable for moving in the substation to inspect the main equipment of the substation. The method further includes: The broadband and narrowband access controller obtains the mobile route of the access device in the substation, determines the broadband and narrowband convergence node device that needs to be connected at each point on the mobile route, and obtains the broadband and narrowband convergence node device set to be connected; The broadband and narrowband access controller sends the device certificate and the aggregation node certificate of each broadband and narrowband converged aggregation node device in the broadband and narrowband converged aggregation node device set to the authentication server so that the authentication server can perform certificate authentication. After the authentication is successful, the authentication server writes the aggregation node device ID of each broadband and narrowband converged aggregation node device in the device information of the device certificate to generate a multi-node access device certificate. The broadband and narrowband access controller responds to the multi-node access device certificate received, which is produced by the authentication server based on the device certificate after authentication, and writes the aggregation node device ID of each broadband and narrowband convergence node device in the device information of the access device in the registration information table.
8. The communication management method based on broadband and narrowband convergence node equipment according to claim 7, characterized in that: The step of determining the broadband-narrowband convergence node device to be connected at each point on the mobile route includes: The moving route of the access device in the substation is divided according to a predetermined step length to obtain multiple route nodes on the predetermined route, and the distance between two adjacent route nodes is the predetermined step length; The broadband and narrowband convergence node device with the largest actual signal strength at each route node is determined as the broadband and narrowband convergence node device to be connected on the mobile route, thereby obtaining a set of broadband and narrowband convergence node devices to be connected on the mobile route.
Citation Information
Patent Citations
Communication system and method applied to power transmission and transformation equipment internet of things
CN116436943A
Access device based on WAPI
CN221768283U