Substation terminal wireless access communication management system and method based on wireless authentication and privacy infrastructure (WAPI)
Through the combination of WAPI two-way authentication and deep learning analysis, the shortcomings of identity authentication and continuous monitoring in substation wireless access communication are solved, and high security and reliability wireless access communication management is achieved.
Patent Information
- Application Number
- CN202510537233.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing wireless LAN security protocols have defects in one-way authentication mechanisms in substations, are vulnerable to man-in-the-middle attacks, lack continuous monitoring and management, making it difficult to deal with advanced sustainable threats, and lack of communication security and reliability.
The WAPI two-way authentication process is adopted to manage unique digital certificates through the CAS system, generate dynamic session keys, and introduce deep learning algorithms to analyze traffic mode characteristics to realize end-to-end encrypted transmission and continuous monitoring.
It improves the security and reliability of wireless access communications at the substation terminals, prevents advanced threats, and ensures trusted authentication of equipment identity and abnormal perception of transmission processes.
Smart Images

Figure CN120264280A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of communication management, and more specifically, to a wireless access communication management system and method for substation terminals based on WAPI. Background Art
[0002] With the continuous deepening of the construction of the smart grid, as a key link of it, smart substations have put forward higher requirements for the levels of automation, informatization and interaction. A large number of intelligent electronic devices (IEDs), sensors and control terminals are deployed inside substations. Efficient and reliable data communication is required between devices and with the superior system to achieve functions such as status monitoring, protection control, information collection and optimized operation. Although the traditional wired communication method is stable, in the complex electromagnetic environment of substations, with the wide distribution of devices and the possible need for flexible movement or transformation, there are problems such as difficult wiring, high cost and poor flexibility. Therefore, introducing wireless communication technology and constructing a wireless access communication solution for substation terminals has become an important development direction to improve the intelligent level of substations, reduce operation and maintenance costs and enhance deployment flexibility. However, as a national key infrastructure, the security and reliability of the communication system in substations are of crucial importance. The openness of the wireless channel makes the communication face security threats such as being easily eavesdropped, tampered with, and impersonated for access, posing potential risks to the safe and stable operation of the power grid. Therefore, there is an urgent need for a comprehensive solution that can not only meet the wireless access requirements, but also provide high-intensity security protection and effective communication management.
[0003] Currently, in the field of wireless local area network security, some smart substations attempt to use general wireless security protocols (such as WPA2-PSK) to achieve terminal access authentication. However, existing solutions mostly adopt a one-way authentication mechanism, which has the risk of man-in-the-middle attacks and inherent defects such as the lack of a certificate system and static key configuration. More critically, traditional wireless access management often focuses on identity authentication and link establishment before access, and lacks a continuous and effective monitoring and management mechanism for the terminal communication behavior after successful access. When an attacker passes the initial authentication, data theft or instruction tampering can be carried out covertly for a long time, and the existing traffic monitoring technology based on fixed traffic thresholds is difficult to cope with advanced persistent threats with latency and persistence.
[0004] Therefore, an optimized wireless access communication management system and method for substation terminals based on WAPI are expected. Summary of the Invention
[0005] To solve the above technical problems, the present application is proposed. Embodiments of the present application provide a WAPI-based wireless access communication management system and method for substation terminals. It obtains the unique digital certificates of the substation terminals to be accessed and the target micro-stations respectively from the CAS system, starts the WAPI two-way authentication process during wireless access, completes the two-way legality verification by exchanging digital certificates and through the CAS system, and ensures the identity credibility of the terminal and the micro-station. After the authentication is passed, both parties generate a dynamic session key based on the WAPI key negotiation mechanism to achieve end-to-end encrypted transmission of service data. Furthermore, during the data transmission process, the data stream metadata of the encrypted transmission layer is collected in real time, and a deep learning algorithm is introduced to perform time series slicing analysis on it to extract the time series context features of the traffic pattern of the communication network. By comparing and analyzing with the normal behavior baseline, the traffic pattern deviation caused by key leakage or malicious attack is identified. This method not only ensures the device identity credible authentication in the wireless access stage, but also realizes the abnormal perception during the transmission process through network traffic behavior feature modeling, forming a double-depth defense of access authentication and continuous monitoring, and can effectively improve the security and reliability of the wireless access communication of substation terminals.
[0006] Correspondingly, according to one aspect of the present application, there is provided a WAPI-based wireless access communication management method for substation terminals, which includes:
[0007] The substation terminal to be accessed and the micro-station respectively obtain their unique digital certificates from the control and authentication system;
[0008] After the substation terminal to be accessed enters the coverage range of the micro-station, it selects the micro-station and sends an access request;
[0009] After receiving the access request from the substation terminal to be accessed, the micro-station starts the WAPI authentication process. Among them, the WAPI authentication process includes the substation terminal to be accessed and the micro-station exchanging the unique digital certificates with each other, and only when the unique digital certificates of both the substation terminal to be accessed and the micro-station pass the CAS verification, the mutual authentication is determined to be successful;
[0010] After the mutual authentication is determined to be successful, the substation terminal to be accessed and the micro-station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent data encrypted transmission;
[0011] After the session key is established, the substation terminal to be accessed and the micro-station use the session key to perform encrypted transmission of service data.
[0012] According to another aspect of the present application, there is provided a WAPI-based wireless access communication management system for substation terminals, which includes:
[0013] A digital certificate acquisition module, configured to obtain their respective unique digital certificates for the substation terminal to be connected and the micro-station from the control and authentication system;
[0014] An access request sending module, configured to select a micro-station and send an access request after the substation terminal to be connected enters the coverage area of the micro-station;
[0015] An authentication module, configured to start the WAPI authentication process after the micro-station receives an access request from the substation terminal to be connected. Among them, the WAPI authentication process includes the substation terminal to be connected and the micro-station exchanging the unique digital certificates with each other, and mutual authentication is determined to be successful only when the unique digital certificates of the substation terminal to be connected and the micro-station both pass the CAS verification;
[0016] A key negotiation and generation module, configured to generate a session key for subsequent encrypted data transmission using the key negotiation mechanism defined in the WAPI protocol after mutual authentication is determined to be successful by the substation terminal to be connected and the micro-station;
[0017] An encrypted transmission module, configured to perform encrypted transmission of service data by the substation terminal to be connected and the micro-station using the session key after the session key is established.
[0018] Compared with the prior art, the wireless access communication management system and method for substation terminals provided by this application obtain the respective unique digital certificates of the substation terminal to be connected and the target micro-station from the CAS system, start the WAPI two-way authentication process during wireless access, complete two-way legality verification by exchanging digital certificates and the CAS system, and ensure the identity credibility of the terminal and the micro-station. After the authentication is passed, both parties generate a dynamic session key based on the WAPI key negotiation mechanism to achieve end-to-end encrypted transmission of service data. Furthermore, during the data transmission process, the data stream metadata of the encrypted transmission layer is collected in real time, and a deep learning algorithm is introduced to perform time series slicing analysis on it to extract the time series context features of the traffic pattern of the communication network. By comparing and analyzing with the normal behavior baseline, the traffic pattern deviation caused by key leakage or malicious attack is identified. This method not only ensures the trusted authentication of device identities in the wireless access stage, but also realizes abnormal perception during the transmission process through network traffic behavior feature modeling, forming a double-depth defense of access authentication and continuous monitoring, and can effectively improve the security and reliability of substation terminal wireless access communication. Description of the Drawings
[0019] The above and other objects, features, and advantages of the present application will become more apparent by describing the embodiments of the present application in more detail with reference to the accompanying drawings. The drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation to the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0020] Figure 1 It is a flowchart of a method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application.
[0021] Figure 2 It is a flowchart of step S5 in the method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application.
[0022] Figure 3 It is a schematic diagram of data flow of step S5 in the method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application.
[0023] Figure 4 It is a flowchart of step S52 in the method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application.
[0024] Figure 5 It is a flowchart of step S523 in the method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application.
[0025] Figure 6 It is a block diagram of a system for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application. Detailed Embodiments
[0026] Next, exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments of the present application. It should be understood that the present application is not limited by the exemplary embodiments described herein.
[0027] Figure 1 It is a flowchart of a method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application. As Figure 1As shown in the figure, the method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application includes the following steps: S1, the substation terminal to be accessed and the micro-station respectively obtain their unique digital certificates from the control and authentication system; S2, after the substation terminal to be accessed enters the coverage area of the micro-station, it selects the micro-station and sends an access request; S3, after the micro-station receives the access request from the substation terminal to be accessed, it starts the WAPI authentication process. Among them, the WAPI authentication process includes the substation terminal to be accessed and the micro-station mutually exchanging the unique digital certificates, and only when the unique digital certificates of the substation terminal to be accessed and the micro-station both pass the CAS verification, the mutual authentication is determined to be successful; S4, after the mutual authentication is determined to be successful, the substation terminal to be accessed and the micro-station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent encrypted data transmission; S5, after the session key is established, the substation terminal to be accessed and the micro-station use the session key to perform encrypted transmission of service data.
[0028] In the above method for wireless access communication management of a substation terminal based on WAPI, in step S1, the substation terminal to be accessed and the micro-station respectively obtain their unique digital certificates from the control and authentication system. It should be understood that in the face of scenarios with a large number of devices and scattered locations such as substations, the traditional static key scheme has problems such as complex key management and easy to be cracked. Once the key is leaked, the entire network needs to be updated, and the operation and maintenance cost is extremely high. The digital certificate system can centrally manage the device identities through the control and authentication system (Control and Authentication System, CAS system). In an intelligent substation, various terminal devices (such as distributed measurement and control units, environmental monitoring sensors, and unmanned aerial vehicle inspection terminals) and wireless micro-stations (access points deployed near switch cabinets and transformers) need to first access the control and authentication system (CAS) to complete identity registration. The CAS system assigns an X.509v3 certificate containing hardware fingerprints (such as CPU serial number, MAC address hash value) to each device. For example, when the inspection robot is shipped from the factory, it submits the hardware information to the CAS through a secure USB interface. The CAS uses the elliptic curve algorithm (ECDSA) to generate the certificate, and the private key is stored in the device security element (SE), and the public key and certificate chain are stored in the trust list of the micro-station. At the same time, as the root certificate authority (CA), the CAS also regularly updates the invalid certificates through the certificate revocation list (CRL) to ensure the timeliness of the certificate chain. In this way, it helps to achieve "one device, one certificate". Even for devices of the same model, they have unique identity identifiers, and the certificate contains device permission information (such as "the 110kV bus measurement and control terminal can only access the SCADA system"), providing a basis for subsequent access control. Moreover, the certificate validity period is bound to the device life cycle, and the certificates of retired devices automatically become invalid, preventing the reuse of old devices.
[0029] In the above-mentioned wireless access communication management method for substation terminals based on WAPI, in step S2, after the substation terminal to be accessed enters the coverage area of the micro-station, it selects the micro-station and sends an access request. It should be understood that the substation terminal to be accessed needs to dynamically access the nearest micro-station according to its physical location to ensure the quality of the communication link. Taking the high-voltage field area of the substation as an example, when the smart meter with a wireless module enters the signal coverage area (about 50 meters) of a certain micro-station (deployed beside the switch in this field area), it discovers the legal micro-station through the scanning mechanism of the 802.11 protocol, avoiding accessing the micro-station in the unauthorized area due to signal attenuation (such as accidentally accessing the micro-station in the adjacent field area, resulting in cross-regional data leakage). Specifically, the substation terminal to be accessed first performs passive scanning (listening to the Beacon frames periodically broadcast by the micro-station). If no signal is received, it starts active scanning and sends a Probe Request frame with a "substation-specific SSID" (such as "Substation-WAPI-110kV"). The micro-station includes an IE (information element) of "supporting WAPI authentication" in the Beacon frame. After parsing, the substation terminal communicates only with the micro-stations identified as WAPI-compatible. In addition, to cope with the signal instability problem caused by the multipath effect in the substation, the substation terminal to be accessed uses the RSSI (Received Signal Strength Indication) threshold filtering (for example, only connecting to the micro-stations with RSSI greater than -70 dBm), and realizes the dynamic switching of the micro-station through the signal quality monitoring algorithm.
[0030] In the above-mentioned wireless access communication management method for substation terminals based on WAPI, in step S3, after the micro-station receives an access request from a substation terminal to be accessed, it starts the WAPI authentication process. Among them, the WAPI authentication process includes the mutual exchange of the unique digital certificates between the substation terminal to be accessed and the micro-station, and only when the unique digital certificates of both the substation terminal to be accessed and the micro-station pass the CAS verification, the mutual authentication is determined to be successful. It should be understood that the WPA2-PSK of traditional Wi-Fi cannot verify the identity of the AP, and attackers can set up a disguised micro-station near the substation (such as faking the SSID as "Substation-WAPI") to deceive the terminal to access. However, in this application, by starting the WAPI authentication process and based on the WAI (Wireless Authentication Infrastructure) protocol of WAPI, through certificate exchange, it can be ensured that "the terminal knows that it is communicating with a real micro-station, and the micro-station also knows that the terminal is a legitimate device". Specifically, after the micro-station receives an access request from a substation terminal to be accessed, it sends an authentication request (AuthReq) containing its own certificate digest to the terminal; the terminal returns its own certificate and the signature of the micro-station digest (using the terminal private key); the micro-station forwards the terminal certificate and signature to the CAS through a secure tunnel (such as IPSec), and the CAS uses the terminal public key to verify the signature and checks whether the certificate is in the CRL; then, the CAS returns the verification result. If it passes, the micro-station sends its own complete certificate to the terminal; the terminal uses the root certificate of the CAS to verify the signature of the micro-station certificate (such as the root certificate of the CAS has been pre-installed in the terminal firmware), and at the same time checks whether the device type in the certificate matches (such as the "device type" field in the micro-station certificate should be "AccessPoint"). In this way, by constructing a three-party mutual trust chain of "terminal - micro-station - CAS", for example, when an attacker forges a micro-station to send a false certificate, the terminal will refuse to access because it cannot pass the CAS verification. At the same time, the micro-station will record the abnormal authentication request and report it to the security management platform.
[0031] In the above wireless access communication management method for substation terminals based on WAPI, in step S4, after mutual authentication is determined to be successful, the substation terminal to be accessed and the micro-station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent encrypted data transmission. It should be understood that traditional static keys are difficult to manage when there are a large number of devices (for example, 1000 devices require maintaining 1000 groups of PSKs), and the keys remain unchanged for a long time and are easily cracked by brute force. However, in this application, by using the key negotiation mechanism defined in the WAPI protocol, a temporary encryption key is created for the current communication session, which conforms to the "principle of least privilege" and the "principle of minimum key lifetime", ensures the uniqueness of each session, and enhances the security of communication. Specifically, this application adopts the KDF (Key Derivation Function) of WAPI and implements key negotiation based on the ECDH algorithm. First, the terminal generates an ephemeral elliptic curve key pair (Ephemeral Key) and sends the public key E_T to the micro-station; the micro-station generates a temporary key pair (E_A) and sends the public key E_A to the terminal; then, both parties use the public key of the other party and their own private key to calculate the shared secret S = d_T * E_A = d_A * E_T (d is the private key), and combine the random numbers (Nonce_T, Nonce_A) and device certificate serial numbers (SN_T, SN_A) in the authentication phase, and generate the session key SK = HMAC(S, Nonce_T || Nonce_A || SN_T || SN_A || session ID) through the HMAC-SHA3-256 algorithm. In addition, in the specific implementation, to prevent replay attacks, the Nonce value is forced to be updated after each key negotiation, and a timestamp factor is added to the session key to ensure the uniqueness and timeliness of each session key. In this way, the "one-time one-key" of the communication session is effectively realized. For example, the communication session between a certain sensor and the micro-station renegotiates the key every 30 minutes. Even if an attacker steals the key through the previous session, they cannot decrypt the subsequent data, and at the same time, it avoids the risk of "the whole network being paralyzed due to the key leakage of one device" in the traditional PSK scheme, not only improving the security of communication, but also effectively preventing the security risks caused by key leakage or being cracked.
[0032] In the above-mentioned wireless access communication management method for substation terminals based on WAPI, in step S5, after the session key is established, the substation terminal to be accessed and the micro-station use the session key to encrypt and transmit service data. That is, the plaintext data is converted into ciphertext using the session key, and an authentication tag is attached to prevent tampering. In the embodiments of the present application, the AES-256-GCM algorithm is adopted to implement data encryption and integrity verification, ensuring the confidentiality and integrity of data transmission. The AES-256-GCM algorithm combines the 256-bit encryption strength of the Advanced Encryption Standard (AES) and the authentication function of the Galois / Counter Mode (GCM), providing strong security protection for data communication. During the encryption process, the substation terminal to be accessed and the micro-station use the established session key to perform AES encryption on the transmitted service data to generate ciphertext. At the same time, the GCM mode also generates an authentication tag, which is transmitted together with the ciphertext for the receiving party to verify the integrity and authenticity of the data. If the data is tampered with or forged during transmission, the authentication tag will not match, thus triggering a security alarm to ensure the reliability of communication. In addition, the efficiency of the AES-256-GCM algorithm also ensures the real-time nature of data transmission, meeting the communication performance requirements of substations.
[0033] To further guard against potential advanced threats after authentication, after the encryption channel is established, the present application also continuously monitors the communication traffic between the substation terminal to be accessed and the micro-station through traffic monitoring technology to detect abnormal behaviors.
[0034] Figure 2 It is a flowchart of step S5 in the wireless access communication management method for substation terminals based on WAPI according to the embodiments of the present application. Figure 3 It is a schematic diagram of data flow in step S5 in the wireless access communication management method for substation terminals based on WAPI according to the embodiments of the present application. As Figure 2 and Figure 3 shown, step S5 further includes: S51, obtaining the data flow metadata transmitted by the substation terminal to be accessed and the micro-station through the WAPI network; S52, extracting traffic pattern features from the data flow metadata to obtain a network traffic pattern feature coding vector; S53, comparing the network traffic pattern feature coding vector with the normal behavior baseline coding vector to determine whether there is a traffic pattern anomaly.
[0035] Specifically, in step S51, data stream metadata transmitted by the substation terminal to be accessed and the micro-station through the WAPI network is obtained. Specifically, in this application, the 802.11n / ac traffic between the micro-station and the terminal is copied to the acquisition server through the mirror port, and high-performance frameworks such as PF_RING are used to parse the IP layer header to extract data stream metadata such as five-tuples, traffic statistics, packet length, timestamp, and session duration, so as to achieve in-depth analysis of communication behaviors.
[0036] Specifically, in step S52, traffic pattern features are extracted from the data stream metadata to obtain a network traffic pattern feature coding vector. Among them, Figure 4 is a flowchart of step S52 in the method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of this application. As Figure 4 shown, step S52 includes: S521, performing data segmentation on the data stream metadata based on a predetermined time window to obtain a sequence distribution of local time-domain data stream metadata; S522, extracting traffic pattern features of each local time-domain data stream metadata in the sequence distribution of the local time-domain data stream metadata to obtain a sequence distribution of local time-series traffic pattern feature coding vectors; S523, performing traffic pattern time-series context aggregation coding on the sequence distribution of the local time-series traffic pattern feature coding vectors to obtain the network traffic pattern feature coding vector.
[0037] More specifically, in step S521, data segmentation is performed on the data stream metadata based on a predetermined time window to obtain a sequence distribution of local time-domain data stream metadata. It should be understood that considering that attack behaviors may be manifested as short-term traffic fluctuations (such as stealing data through staged transmissions). Therefore, in order to capture abnormal communication behaviors in a more fine-grained manner, this application performs data segmentation on the data stream metadata based on a predetermined time window, and divides the continuous data stream into multiple time segments, so as to capture the pattern changes of the data stream metadata within each local time-domain segment (such as the change trends of indicators such as the number of data packets, transmission rate, and frequency of session establishment and closure within a time period), thereby timely discovering abnormal communication behaviors and providing a basis for subsequent security analysis.
[0038] More specifically, in step S522, the traffic pattern feature of each local time-domain data stream metadata in the sequence distribution of the local time-domain data stream metadata is extracted to obtain the sequence distribution of the local time-series traffic pattern feature coding vectors. In a specific example of the present application, the traffic pattern feature extraction based on the LSTM model is respectively performed on each local time-domain data stream metadata in the sequence distribution of the local time-domain data stream metadata to obtain the sequence distribution of the local time-series traffic pattern feature coding vectors. It should be understood that the LSTM (Long Short-Term Memory) model is a special recurrent neural network (RNN), which is suitable for processing and predicting long-term dependencies in time series data. In the present application, by using the LSTM model to perform feature learning on each local time-domain data stream metadata, the time dependence and hidden features in the data can be effectively captured, so as to more accurately extract the traffic pattern features in each local time domain. Specifically, first, the data stream metadata of each time step is subjected to normalization processing and embedding combination to convert different types of data into feature vectors of a fixed length, and the data stream metadata is converted into an input format that can be processed by the LSTM model. Then, the embedded features of the data stream metadata of each time step are input into the LSTM network for sequence learning. Through the mechanisms such as memory units, forget gates, input gates, and output gates inside the LSTM network, the embedded features of the data stream metadata of each time step are iteratively processed, and the state information is gradually accumulated and updated to capture the long-term dependencies and hidden features in the data stream, and the traffic pattern feature coding vectors of each local time-domain data stream metadata are output.
[0039] More specifically, in step S523, traffic pattern time-series context aggregation coding is performed on the sequence distribution of the local time-series traffic pattern feature coding vectors to obtain the network traffic pattern feature coding vectors. That is, considering that in the complex communication scenario of intelligent substations, the dynamic traffic pattern formed by the interweaving of periodic service traffic and bursty control instructions has strong time-series correlation characteristics, the traffic feature analysis method based on a fixed time window may lead to pattern misjudgment due to time-series context fragmentation. For example, an attacker may disguise low-frequency and scattered data stealing behaviors as normal service traffic. The local features within a single time window have insignificant differences from the baseline, but the time-series combination pattern across windows shows abnormal evolution rules. Therefore, the present application further performs traffic pattern time-series context aggregation coding on the sequence distribution of the local time-series traffic pattern feature coding vectors to deeply explore the correlation and evolution rules of traffic features in the time dimension.
[0040] Figure 5 It is a flowchart of step S523 in the wireless access communication management method for substation terminals based on WAPI according to an embodiment of the present application. As Figure 5As shown, step S523 includes: S5231, performing linear clustering analysis on the sequence distribution of the local temporal traffic pattern feature encoding vectors to obtain an initial linear clustering center encoding vector of the network traffic pattern features; S5232, compensating and correcting the initial linear clustering center encoding vector of the network traffic pattern features based on the feature clustering compensation increment of the sequence distribution of the local temporal traffic pattern feature encoding vectors relative to the initial linear clustering center encoding vector of the network traffic pattern features to obtain the encoding vector of the network traffic pattern features.
[0041] More specifically, step S5231 can be expressed by the formula:
[0042] X = {x1, x2,..., x i ,..., x n}
[0043]
[0044] where X represents the sequence distribution of the local temporal traffic pattern feature encoding vectors, x1, x2, x i and x n respectively represent the 1st, 2nd, ith, and nth local temporal traffic pattern feature encoding vectors in the sequence distribution of the local temporal traffic pattern feature encoding vectors, n represents the number of local temporal traffic pattern feature encoding vectors in the sequence distribution of the local temporal traffic pattern feature encoding vectors, and x c represents the initial linear clustering center encoding vector of the network traffic pattern features.
[0045] That is, for the quasi-linear temporal features formed by the periodic service traffic of the substation (such as second-level telemetry and minute-level device status reporting), the present application first performs linear clustering analysis on the sequence distribution of the local temporal traffic pattern feature encoding vectors to capture the principal component distribution of the typical service traffic of the substation in the time dimension, reduce the high-dimensional feature space to a linearly interpretable linear subspace, and establish a reference anchor point for subsequent non-linear compensation, while avoiding the dimensionality disaster caused by directly dealing with complex non-linear relationships.
[0046] More specifically, step S5232 includes: calculating a feature clustering compensation increment operator of each local temporal traffic pattern feature coding vector in the sequence distribution of the local temporal traffic pattern feature coding vectors relative to the initial linear clustering center coding vector of the network traffic pattern feature to obtain a sequence distribution of the network traffic pattern feature clustering compensation increment operator. In a specific example of the present application, calculating a feature clustering compensation increment operator of each local temporal traffic pattern feature coding vector in the sequence distribution of the local temporal traffic pattern feature coding vectors relative to the initial linear clustering center coding vector of the network traffic pattern feature to obtain a sequence distribution of the network traffic pattern feature clustering compensation increment operator includes: First, constructing a deep collaborative implicit coding vector between each local temporal traffic pattern feature coding vector in the sequence distribution of the local temporal traffic pattern feature coding vectors and the initial linear clustering center coding vector of the network traffic pattern feature to obtain a sequence distribution of the network traffic pattern feature deep collaborative implicit coding vector, which is expressed by the formula:
[0047] v c =sigmoid(x c )
[0048] r i =Sigmoid{W i [contact(x i ;v c )]+b i}
[0049] where sigmoid(·) represents the Sigmoid activation function, v c represents the initial linear clustering center activation coding vector of the network traffic pattern feature, b i represents the bias term, W i represents the weight matrix, contact(·;·) represents the concatenation function, and r i represents the i-th network traffic pattern feature deep collaborative implicit coding vector in the sequence distribution of the network traffic pattern feature deep collaborative implicit coding vector.
[0050] That is, considering that attack traffic often penetrates into the legitimate traffic pattern through minute temporal offsets (such as abnormal elongation of instruction intervals and gradual change in packet size distribution). Therefore, the present application further captures the feature association between each local temporal traffic pattern feature coding vector and the initial clustering center by constructing a deep collaborative coding network, and mines the deviation information between the traffic pattern features of each local window and the typical service pattern. For example, when the GOOSE message retransmission rate in a certain period continues to be higher than the clustering center representation, the dimensional difference is amplified by deep collaborative coding to provide a quantitative basis for subsequent compensation.
[0051] Next, each network traffic pattern feature depth collaborative implicit coding vector in the sequence distribution of the network traffic pattern feature depth collaborative implicit coding vectors is respectively subjected to feature clustering difference compensation calculation with the initial linear clustering center coding vector of the network traffic pattern feature to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator, which is expressed by the formula:
[0052]
[0053] where, log2 represents the logarithmic function with base 2, r ik represents the eigenvalue at the k-th position in r i and v ck represents the eigenvalue at the k-th position in v c L represents the feature scale value of the network traffic pattern feature depth collaborative implicit coding vector, and λ i represents the network traffic pattern feature clustering compensation increment operator corresponding to x i .
[0054] Here, considering that the deviation information between the traffic pattern features of each local window and the typical service pattern usually has different significance and importance. Therefore, in order to accurately evaluate the actual impact of these deviation information, the present application further conducts a quantitative analysis of the feature differences between each network traffic pattern feature depth collaborative implicit coding vector and the initial clustering center through feature clustering difference compensation calculation, and obtains the sequence distribution of the corresponding network traffic pattern feature clustering compensation increment operator, as a quantitative characterization of the influence degree of the traffic pattern deviation features of each local window on the overall traffic pattern.
[0055] More specifically, the step S5232 further includes: calculating a linear clustering compensation component of the sequence distribution of the local temporal traffic pattern feature coding vector based on the sequence distribution of the network traffic pattern feature clustering compensation increment operator to obtain a network traffic pattern feature linear clustering compensation component coding vector. In particular, considering that when calculating the network traffic pattern feature clustering compensation increment operator, due to the addition of incremental non-linear information based on the linear clustering result of the network traffic pattern feature deep collaborative implicit coding vector outside the original local temporal traffic pattern feature coding vector, it leads to the addition of clustering elements in the clustering space, thus causing a systematic non-equilibrium state in the clustering space distribution. Based on this, in a preferred example of the present application, resonance coupling enhancement based on clustering balance correction is performed on each network traffic pattern feature clustering compensation increment operator in the sequence distribution of the network traffic pattern feature clustering compensation increment operator to obtain an optimized sequence distribution of the network traffic pattern feature clustering compensation increment operator. That is, the spatial distribution of the network traffic pattern feature clustering compensation increment operator is dynamically corrected through the resonance coupling enhancement mechanism to solve the systematic deviation problem caused by non-linear information injection.
[0056] Based on this, first, use the inner product <x i ,r i > of the local temporal traffic pattern feature coding vector and the network traffic pattern feature deep collaborative implicit coding vector to construct a clustering eigenenergy term ∑ i , and calculate the clustering adjustment coefficient Γ i , which is expressed by the formula:
[0057] ∑ i =<x i ,r i >
[0058]
[0059] where <·,·> represents calculating the inner product, ∑ i represents the clustering eigenenergy term between x i and r i , σ(·) 2 represents the variance of the sequence distribution composed of all eigenvalues in the vector, ∈ i represents the eigen-scattering factor related to the clustering eigenenergy term ∑ i , Γ i is the clustering adjustment coefficient of r i , representing the dissipation adjustment effect of r i under the clustering space on the linear clustering center.
[0060] Finally, combine the clustering adjustment coefficient Γ i corresponding to the clustering eigenenergy term ∑ i , and through ×L -1 / 2 (where e (·) represents the exponential function with the natural constant as the base, represents the modified network traffic pattern feature clustering compensation increment operator), perform resonance collaboration based on energy state balance on the network traffic pattern feature clustering compensation increment operator in the clustering space, so as to realize the dynamic coupling optimization of the network traffic pattern feature clustering compensation increment operator under the fractal space representation, and achieve the clustering steady-state correction effect of non-linear increment collaboration.
[0061] Next, perform normalization processing based on the Softmax function on the sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator to obtain the sequence distribution of the normalized network traffic pattern feature clustering compensation increment operator, and based on the sequence distribution of the normalized network traffic pattern feature clustering compensation increment operator, perform weighted aggregation on the sequence distribution of the local temporal traffic pattern feature encoding vector to obtain the network traffic pattern feature linear clustering compensation component encoding vector, which is expressed by the formula:
[0062]
[0063] where softmax(·) represents the normalized exponential function, and ε i represents the ′i corresponding normalized network traffic pattern feature clustering compensation increment operator, and x b represents the network traffic pattern feature linear clustering compensation component encoding vector.
[0064] That is, in order to realize the effective fusion of the traffic pattern feature compensation information in each local time domain, this application uses Softmax to perform normalization processing on the sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator, maps each compensation increment operator to the interval [0,1], to ensure the rationality of its physical meaning and the numerical stability of subsequent weighted aggregation. Subsequently, based on the normalized network traffic pattern feature clustering compensation increment operator, perform weighted processing on each local temporal traffic pattern feature encoding vector, which is essentially a weighted emphasis on the traffic pattern features in each local window based on their degree of deviation from the typical service pattern, so as to realize the effective fusion of global compensation information.
[0065] More specifically, step S5232 further includes: fusing the network traffic pattern feature linear clustering compensation component encoding vector and the network traffic pattern feature initial linear clustering center encoding vector to obtain the network traffic pattern feature encoding vector, which is expressed by the formula:
[0066] v f =α·x b +β·xc
[0067] Among them, α and β represent different weight parameters, and v f represents the encoding vector of the network traffic pattern feature.
[0068] That is, by weighted aggregation of the linear clustering compensation component encoding vector of the network traffic pattern feature and the initial linear clustering center encoding vector of the network traffic pattern feature, the deviation information in the local time-series traffic pattern is effectively integrated back into the overall traffic pattern feature representation, and a comprehensive network traffic pattern feature encoding vector that includes both typical service pattern features and reflects local deviation information is constructed. Through this process, the network traffic pattern feature encoding vector not only retains the main features of the substation service traffic, but also can sensitively capture the small deviations in each local time-series traffic pattern, providing a more comprehensive and detailed data basis for subsequent intelligent analysis and anomaly detection.
[0069] Specifically, in step S53, the network traffic pattern feature encoding vector is compared with the normal behavior baseline encoding vector to determine whether there is a traffic pattern anomaly. In a specific example of the present application, the cosine similarity between the network traffic pattern feature encoding vector and the normal behavior baseline encoding vector is calculated, and it is determined whether there is a traffic pattern anomaly based on a preset similarity threshold. It should be understood that the normal behavior baseline encoding vector is the normal behavior baseline representation obtained by performing the above encoding process on historical normal traffic pattern data, which represents the normal behavior pattern of the substation service traffic. By calculating the similarity between the real-time network traffic pattern feature encoding vector and the normal behavior baseline encoding vector, the deviation degree between the current traffic pattern and the normal behavior pattern can be quantitatively evaluated. When the cosine similarity is lower than the preset similarity threshold, it is considered that there is a traffic pattern anomaly, which may indicate a potential network security threat or equipment failure, thereby triggering a corresponding warning mechanism or fault troubleshooting process. This process not only improves the accuracy of anomaly detection, but also provides timely and effective fault location information for operation and maintenance personnel, helping to improve the operation safety and reliability of the substation.
[0070] In summary, the method for wireless access communication management of a substation terminal based on WAPI according to an embodiment of the present application is elucidated. It obtains the respective unique digital certificates of the substation terminal to be accessed and the target micro-station from the CAS system, starts the WAPI two-way authentication process during wireless access, completes the two-way legality verification by exchanging digital certificates and through the CAS system, and ensures the identity credibility of the terminal and the micro-station. After successful authentication, both parties generate a dynamic session key based on the WAPI key negotiation mechanism to achieve end-to-end encrypted transmission of service data. Furthermore, during the data transmission process, the data stream metadata of the encrypted transmission layer is collected in real time, and a deep learning algorithm is introduced to perform time-series slicing analysis on it to extract the time-series context features of the traffic pattern of the communication network. By comparing and analyzing with the normal behavior baseline, the traffic pattern deviation caused by key leakage or malicious attack is identified. This method not only ensures the device identity credible authentication in the wireless access stage but also realizes the abnormal perception during the transmission process through network traffic behavior feature modeling, forming a double-depth defense of access authentication and continuous monitoring, and can effectively improve the security and reliability of the wireless access communication of the substation terminal.
[0071] Furthermore, the present application also provides a wireless access communication management system for a substation terminal based on WAPI.
[0072] Figure 6 FIG. is a block diagram of a wireless access communication management system for a substation terminal based on WAPI according to an embodiment of the present application. As Figure 6 shown, the wireless access communication management system 100 for a substation terminal based on WAPI according to an embodiment of the present application includes: a digital certificate acquisition module 110, configured to obtain the respective unique digital certificates of the substation terminal to be accessed and the micro-station from the control and authentication system; an access request sending module 120, configured to select a micro-station and send an access request after the substation terminal to be accessed enters the coverage range of the micro-station; an authentication module 130, configured to start the WAPI authentication process after receiving the access request from the substation terminal to be accessed, where the WAPI authentication process includes the substation terminal to be accessed and the micro-station mutually exchanging the unique digital certificates, and only when the unique digital certificates of both the substation terminal to be accessed and the micro-station pass the CAS verification, the mutual authentication is determined to be successful; a key negotiation generation module 140, configured to, after the mutual authentication is determined to be successful, the substation terminal to be accessed and the micro-station generate a session key for subsequent encrypted data transmission using the key negotiation mechanism defined in the WAPI protocol; an encrypted transmission module 150, configured to, after the session key is established, the substation terminal to be accessed and the micro-station perform encrypted transmission of service data using the session key.
[0073] Here, those skilled in the art can understand that the specific operations of the various modules in the above-mentioned wireless access communication management system for a substation terminal based on WAPI have been described above according to Figures 1 to 5The description of the wireless access communication management method for substation terminals based on WAPI has been introduced in detail, and therefore, its repeated description will be omitted.
[0074] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A wireless access communication management method for substation terminals based on WAPI, characterized in that Including: The substation terminal to be connected and the micro-station respectively obtain their unique digital certificates from the control and authentication system; After the substation terminal to be connected enters the coverage area of the micro-station, it selects the micro-station and sends an access request; After receiving the access request from the substation terminal to be connected, the micro-station starts the WAPI authentication process. Among them, the WAPI authentication process includes the substation terminal to be connected and the micro-station exchanging the unique digital certificates with each other, and only when the unique digital certificates of the substation terminal to be connected and the micro-station both pass the CAS verification, the mutual authentication is determined to be successful; After the mutual authentication is determined to be successful, the substation terminal to be connected and the micro-station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent data encryption transmission; After the session key is established, the substation terminal to be connected and the micro-station use the session key to perform encrypted transmission of service data.
2. The method for wireless access communication management of a substation terminal based on WAPI according to claim 1, wherein After the session key is established, the substation terminal to be connected and the micro-station use the session key to perform encrypted transmission of service data, including: Obtaining the data stream metadata transmitted by the substation terminal to be connected and the micro-station through the WAPI network; Extracting the traffic pattern features from the data stream metadata to obtain a network traffic pattern feature coding vector; Based on the comparison between the network traffic pattern feature coding vector and the normal behavior baseline coding vector, to determine whether there is an abnormal traffic pattern.
3. The method for wireless access communication management of a substation terminal based on WAPI according to claim 2, wherein Extracting the traffic pattern features from the data stream metadata to obtain a network traffic pattern feature coding vector, including: Performing data segmentation on the data stream metadata based on a predetermined time window to obtain the sequence distribution of local time-domain data stream metadata; Extracting the traffic pattern features of each local time-domain data stream metadata in the sequence distribution of the local time-domain data stream metadata to obtain the sequence distribution of local time-series traffic pattern feature coding vectors; Performing traffic pattern time-series context aggregation coding on the sequence distribution of the local time-series traffic pattern feature coding vectors to obtain the network traffic pattern feature coding vector.
4. The method for wireless access communication management of a substation terminal based on WAP I according to claim 3, characterized in that, Extracting the traffic pattern features of each local time-domain data stream metadata in the sequence distribution of the local time-domain data stream metadata to obtain the sequence distribution of local time-series traffic pattern feature coding vectors, including: Performing traffic pattern feature extraction based on the LSTM model on each local time-domain data stream metadata in the sequence distribution of the local time-domain data stream metadata to obtain the sequence distribution of the local time-series traffic pattern feature coding vectors.
5. The method for wireless access communication management of a substation terminal based on WAPI according to claim 4, characterized in that, Performing traffic pattern time-series context aggregation coding on the sequence distribution of the local time-series traffic pattern feature coding vectors to obtain the network traffic pattern feature coding vector, including: Performing linear clustering analysis on the sequence distribution of the local time-series traffic pattern feature coding vectors to obtain an initial linear clustering center coding vector of network traffic pattern features; Based on the feature clustering compensation increment of the sequence distribution of the local time-series traffic pattern feature coding vectors relative to the initial linear clustering center coding vector of network traffic pattern features, compensating and correcting the initial linear clustering center coding vector of network traffic pattern features to obtain the network traffic pattern feature coding vector.
6. The method for wireless access communication management of a substation terminal based on WAP I according to claim 5, characterized in that, Compensating and correcting the initial linear clustering center encoding vector of the network traffic pattern features based on the feature clustering compensation increment of the sequence distribution of the local temporal traffic pattern feature encoding vectors relative to the initial linear clustering center encoding vector of the network traffic pattern features to obtain the network traffic pattern feature encoding vector, including: Calculating the feature clustering compensation increment operator of each local temporal traffic pattern feature encoding vector in the sequence distribution of the local temporal traffic pattern feature encoding vectors relative to the initial linear clustering center encoding vector of the network traffic pattern features to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator; Calculating the linear clustering compensation component of the sequence distribution of the local temporal traffic pattern feature encoding vectors based on the sequence distribution of the network traffic pattern feature clustering compensation increment operator to obtain the network traffic pattern feature linear clustering compensation component encoding vector; Fusing the network traffic pattern feature linear clustering compensation component encoding vector and the initial linear clustering center encoding vector of the network traffic pattern features to obtain the network traffic pattern feature encoding vector.
7. The method for wireless access communication management of a substation terminal based on WAP I according to claim 6, characterized in that Calculating the feature clustering compensation increment operator of each local temporal traffic pattern feature encoding vector in the sequence distribution of the local temporal traffic pattern feature encoding vectors relative to the initial linear clustering center encoding vector of the network traffic pattern features to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator, including: Constructing the deep collaborative implicit encoding vector between each local temporal traffic pattern feature encoding vector in the sequence distribution of the local temporal traffic pattern feature encoding vectors and the initial linear clustering center encoding vector of the network traffic pattern features to obtain the sequence distribution of the network traffic pattern feature deep collaborative implicit encoding vector; Performing feature clustering difference compensation calculation on each network traffic pattern feature deep collaborative implicit encoding vector in the sequence distribution of the network traffic pattern feature deep collaborative implicit encoding vectors and the initial linear clustering center encoding vector of the network traffic pattern features respectively to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator.
8. The method for wireless access communication management of a substation terminal based on WAP I according to claim 7, characterized in that Calculating the linear clustering compensation component of the sequence distribution of the local temporal traffic pattern feature encoding vectors based on the sequence distribution of the network traffic pattern feature clustering compensation increment operator to obtain the network traffic pattern feature linear clustering compensation component encoding vector, including: Performing resonance coupling enhancement based on clustering balance correction on each network traffic pattern feature clustering compensation increment operator in the sequence distribution of the network traffic pattern feature clustering compensation increment operator to obtain the sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator; Performing normalization processing based on the Softmax function on the sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator to obtain the sequence distribution of the normalized network traffic pattern feature clustering compensation increment operator; Based on the sequence distribution of the clustering compensation increment operator for the normalized network traffic pattern features, the sequence distribution of the local temporal traffic pattern feature encoding vectors is weighted and aggregated to obtain the network traffic pattern feature linear clustering compensation component encoding vector.
9. The method for wireless access communication management of a substation terminal based on WAP I according to claim 8, wherein Based on the comparison between the network traffic pattern feature encoding vector and the normal behavior baseline encoding vector to determine whether there is a traffic pattern anomaly, including: Calculating the cosine similarity between the network traffic pattern feature encoding vector and the normal behavior baseline encoding vector, and determining whether there is a traffic pattern anomaly based on a preset similarity threshold.
10. A substation terminal wireless access communication management system based on WAPI, characterized in that, Including: A digital certificate acquisition module, configured to enable the substation terminal to be connected and the microstation to respectively obtain their unique digital certificates from the control and authentication system; An access request sending module, configured to, after the substation terminal to be connected enters the coverage area of the microstation, select the microstation and send an access request; An authentication module, configured to, after receiving an access request from the substation terminal to be connected, initiate a WAPI authentication process, wherein the WAPI authentication process includes the substation terminal to be connected and the microstation mutually exchanging the unique digital certificates, and only when the unique digital certificates of the substation terminal to be connected and the microstation both pass the CAS verification, the mutual authentication is determined to be successful; A key negotiation and generation module, configured to, after the mutual authentication is determined to be successful, the substation terminal to be connected and the microstation use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent encrypted data transmission; An encrypted transmission module, configured to, after the session key is established, the substation terminal to be connected and the microstation use the session key to perform encrypted transmission of service data.
Citation Information
Patent Citations
Access method and access system for cellular mobile communication network
CN101616410A
Cloud data security protection method and system based on 5G network
CN117156442A
Nonlinear network adaptive fuzzy control system under multiple network attacks
CN118011814A
Monitoring terminal wireless access communication management system based on wireless authentication and privacy infrastructure (WAPI)
CN119277471A
Substation WAPI network security management method based on quantum authentication
CN119449304A