Substation terminal wireless access communication management system and method based on WAPI
By combining WAPI two-way authentication and deep learning analysis, the identity authentication and continuous monitoring issues of the substation wireless LAN are solved, the security and reliability of wireless access communications of substation terminals are improved, and a double-depth defense is formed.
Patent Information
- Application Number
- CN202510537233.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-04-27
AI Technical Summary
Existing wireless LAN security protocols have defects in one-way authentication mechanisms in substations, are vulnerable to man-in-the-middle attacks, and lack continuous monitoring and management mechanisms, making it difficult to cope with advanced persistent threats, affecting communication security and reliability.
The WAPI two-way authentication process is adopted to obtain the unique digital certificates of the terminal and micro-station through the CAS system, generate dynamic session keys, and introduce deep learning algorithms to analyze network traffic patterns to achieve end-to-end encrypted transmission and anomaly detection.
Ensure trusted authentication of terminal identities, improve the security and reliability of wireless access communications, prevent advanced threats, form a double-depth defense mechanism, and enhance the security and flexibility of substation communication systems.
Smart Images

Figure CN120264280B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication management technology, and more specifically, to a WAPI-based substation terminal wireless access communication management system and method. Background Art
[0002] As smart grid construction continues to deepen, smart substations, as a key component, are placing higher demands on automation, informationization, and interactivity. Substations are equipped with a large number of intelligent electronic devices (IEDs), sensors, and control terminals. Efficient and reliable data communication is required between these devices and with higher-level systems to implement functions such as status monitoring, protection and control, information collection, and optimized operation. Traditional wired communication methods, while stable, present challenges such as wiring difficulties, high costs, and limited flexibility in substations, given the complex electromagnetic environment, widespread distribution of equipment, and the potential need for flexible relocation or modification. Therefore, introducing wireless communication technology and developing wireless access solutions for substation terminals has become a key development direction for improving substation intelligence, reducing operation and maintenance costs, and enhancing deployment flexibility. However, as critical national infrastructure, the security and reliability of substation communication systems are paramount. The open nature of wireless channels makes communications vulnerable to security threats such as eavesdropping, tampering, and counterfeit access, posing a potential risk to the safe and stable operation of the power grid. Therefore, a comprehensive solution is urgently needed that not only meets wireless access requirements but also provides strong security and effective communication management.
[0003] Currently, in the field of wireless LAN security, some smart substations are attempting to implement terminal access authentication using common wireless security protocols (such as WPA2-PSK). However, existing solutions often rely on one-way authentication mechanisms, which pose the risk of man-in-the-middle attacks and suffer from inherent flaws such as a lack of a certificate system and static key configuration. More critically, traditional wireless access management often focuses on identity authentication and link establishment prior to access, lacking a continuous and effective monitoring and management mechanism for terminal communication behavior after successful access. Once an attacker passes initial authentication, they can conduct long-term, covert data theft or command tampering. However, existing traffic monitoring technologies based on fixed traffic thresholds are unable to address the latent and persistent nature of advanced persistent threats.
[0004] Therefore, an optimized WAPI-based substation terminal wireless access communication management system and method is expected. Summary of the Invention
[0005] In order to solve the above technical problems, the present application is proposed. The embodiment of the present application provides a WAPI-based substation terminal wireless access communication management system and method, which obtains the unique digital certificates of the substation terminal to be accessed and the target micro station from the CAS system, starts the WAPI two-way authentication process during wireless access, and ensures the identity credibility of the terminal and the micro station by exchanging digital certificates and completing the two-way legitimacy verification by the CAS system. After the authentication is passed, the two parties generate a dynamic session key based on the WAPI key negotiation mechanism to achieve end-to-end encrypted transmission of business data. Furthermore, during the data transmission process, the data stream metadata of the encrypted transport layer is collected in real time, and a deep learning algorithm is introduced to perform time-series slicing analysis on it to extract the time-series context features of the traffic pattern of the communication network. By comparing and analyzing with the normal behavior baseline, the traffic pattern deviation caused by key leakage or malicious attack is identified. This method not only ensures the trusted authentication of the device identity in the wireless access stage, but also realizes the perception of abnormalities in the transmission process through network traffic behavior feature modeling, forming a dual depth defense of access authentication and continuous monitoring, which can effectively improve the security and reliability of the wireless access communication of the substation terminal.
[0006] Accordingly, according to one aspect of the present application, a WAPI-based substation terminal wireless access communication management method is provided, which includes:
[0007] The substation terminal and microstation to be connected obtain their unique digital certificates from the control and authentication systems respectively;
[0008] After the access substation terminal enters the coverage area of the micro station, it selects the micro station and sends an access request;
[0009] After receiving the access request from the substation terminal to be connected, the micro station starts the WAPI authentication process, wherein the WAPI authentication process includes the substation terminal to be connected and the micro station exchanging the unique digital certificates. Only when the unique digital certificates of the substation terminal to be connected and the micro station pass the CAS verification, the mutual authentication is determined to be successful;
[0010] After mutual authentication is determined to be successful, the substation terminal to be connected and the micro station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent data encryption transmission;
[0011] After the session key is established, the substation terminal to be connected and the micro station use the session key to encrypt and transmit business data.
[0012] According to another aspect of the present application, a WAPI-based substation terminal wireless access communication management system is provided, which includes:
[0013] A digital certificate acquisition module is used for the substation terminal and micro station to be connected to obtain their unique digital certificates from the control and authentication systems respectively;
[0014] An access request sending module is used to select a micro station and send an access request after the substation terminal to be accessed enters the coverage area of the micro station;
[0015] An authentication module is configured to initiate a WAPI authentication process after the micro station receives an access request from the substation terminal to be accessed. The WAPI authentication process includes the substation terminal to be accessed and the micro station exchanging the unique digital certificates with each other. Mutual authentication is considered successful only if the unique digital certificates of both the substation terminal to be accessed and the micro station pass CAS verification.
[0016] The key negotiation generation module is used to generate a session key for subsequent data encryption transmission by the substation terminal to be connected and the micro station using the key negotiation mechanism defined in the WAPI protocol after mutual authentication is determined to be successful;
[0017] The encryption transmission module is used to encrypt and transmit business data using the session key between the terminal to be connected to the substation and the micro station after the session key is established.
[0018] Compared with the existing technology, the WAPI-based substation terminal wireless access communication management system and method provided by this application obtains the unique digital certificates of the substation terminal to be accessed and the target micro-station from the CAS system, starts the WAPI two-way authentication process during wireless access, and ensures the identity credibility of the terminal and the micro-station by exchanging digital certificates and completing the two-way legitimacy verification by the CAS system. After the authentication is passed, the two parties generate a dynamic session key based on the WAPI key negotiation mechanism to achieve end-to-end encrypted transmission of business data. Furthermore, during the data transmission process, the data stream metadata of the encrypted transmission layer is collected in real time, and a deep learning algorithm is introduced to perform time-series slicing analysis on it to extract the traffic pattern time-series context features of the communication network, and compare and analyze them with the normal behavior baseline to identify traffic pattern deviations caused by key leakage or malicious attacks. This method not only ensures the trusted authentication of the device identity in the wireless access stage, but also realizes the perception of transmission process anomalies through network traffic behavior feature modeling, forming a dual depth defense of access authentication and continuous monitoring, which can effectively improve the security and reliability of wireless access communication of substation terminals. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The above and other purposes, features, and advantages of the present application will become more apparent through a more detailed description of the embodiments of the present application in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0020] Figure 1 This is a flowchart of a WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application.
[0021] Figure 2 This is a flowchart of step S5 in the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application.
[0022] Figure 3 Schematic diagram of data flow in step S5 of the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application.
[0023] Figure 4 This is a flowchart of step S52 in the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application.
[0024] Figure 5 This is a flowchart of step S523 in the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application.
[0025] Figure 6 This is a block diagram of a WAPI-based substation terminal wireless access communication management system according to an embodiment of the present application. DETAILED DESCRIPTION
[0026] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described herein.
[0027] Figure 1 FIG. 1 is a flow chart of a WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application. Figure 1As shown, the WAPI-based wireless access communication management method for substation terminals according to an embodiment of the present application includes the following steps: S1, the substation terminal to be accessed and the micro station respectively obtain their unique digital certificates from the control and authentication systems; S2, after the substation terminal to be accessed enters the coverage range of the micro station, it selects the micro station and sends an access request; S3, after the micro station receives the access request from the substation terminal to be accessed, it starts the WAPI authentication process, wherein the WAPI authentication process includes the substation terminal to be accessed and the micro station exchanging the unique digital certificates with each other, and only when the unique digital certificates of the substation terminal to be accessed and the micro station pass the CAS verification, the mutual authentication is judged to be successful; S4, after the mutual authentication is judged to be successful, the substation terminal to be accessed and the micro station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent data encryption transmission; S5, after the session key is established, the substation terminal to be accessed and the micro station use the session key to encrypt and transmit business data.
[0028] In the above-mentioned WAPI-based substation terminal wireless access communication management method, in step S1, the substation terminal and micro station to be connected obtain their unique digital certificates from the control and authentication system respectively. It should be understood that the traditional static key scheme has the problem of complex key management and easy cracking when facing scenarios such as substations with a large number of devices and scattered locations. Once the key is leaked, the entire network needs to be updated, and the operation and maintenance cost is extremely high. The digital certificate system can centrally manage the device identity through the control and authentication system (CAS system). In the smart substation, various terminal devices (such as distributed measurement and control units, environmental monitoring sensors, drone inspection terminals) and wireless micro stations (access points deployed near switch cabinets and transformers) must first access the control and authentication system (CAS) to complete identity registration. The CAS system assigns each device an X.509v3 certificate containing a hardware fingerprint (such as the CPU serial number and MAC address hash value). For example, when an inspection robot leaves the factory, it submits hardware information to the CAS via a secure USB interface. CAS generates the certificate using the elliptic curve algorithm (ECDSA). The private key is stored in the device's secure element (SE), and the public key and certificate chain are stored in the microstation's trust list. Furthermore, as a root certificate authority (CA), CAS regularly updates invalid certificates through a certificate revocation list (CRL) to ensure the timeliness of the certificate chain. This approach helps achieve a "one device, one certificate" policy, ensuring that even devices of the same model have a unique identity. The certificate also includes device permission information (such as "110kV busbar measurement and control terminals can only access the SCADA system"), providing a basis for subsequent access control. Furthermore, the certificate validity period is tied to the device lifecycle, and certificates for retired devices automatically expire to prevent reuse of old equipment.
[0029] In the aforementioned WAPI-based wireless access communication management method for substation terminals, in step S2, after the substation terminal to be connected enters the coverage area of a micro-station, it selects a micro-station and sends an access request. It should be understood that the substation terminal to be connected needs to dynamically access the nearest micro-station based on its physical location to ensure the quality of the communication link. Taking the high-voltage area of a substation as an example, when a smart meter equipped with a wireless module enters the signal coverage range (approximately 50 meters) of a micro-station (deployed next to the switch in that area), it uses the 802.11 protocol scanning mechanism to discover legitimate micro-stations, avoiding access to micro-stations in unauthorized areas due to signal attenuation (such as mistakenly accessing a micro-station in an adjacent area, resulting in cross-regional data leakage). Specifically, the substation terminal to be connected first performs passive scanning (listening to the Beacon frames periodically broadcast by the micro-station). If no signal is received, it initiates active scanning, sending a Probe Request frame with the "substation-specific SSID" (e.g., "Substation-WAPI-110kV"). Micro stations include an IE (Information Element) indicating "Supports WAPI Authentication" in their Beacon frames. Substation terminals parse these IEs and only communicate with those identified as WAPI-compatible. Furthermore, to address signal instability caused by substation multipath, the terminals in the substation to be connected use RSSI (Received Signal Strength Indicator) threshold filtering (for example, only connecting to micro stations with an RSSI greater than -70dBm) and dynamically switch between micro stations using a signal quality monitoring algorithm.
[0030] In the above-mentioned WAPI-based substation terminal wireless access communication management method, in step S3, after receiving the access request from the substation terminal to be accessed, the micro station starts the WAPI authentication process, wherein the WAPI authentication process includes the substation terminal to be accessed and the micro station exchanging the unique digital certificates with each other, and only when the unique digital certificates of the substation terminal to be accessed and the micro station are both verified by CAS, the mutual authentication is determined to be successful. It should be understood that the WPA2-PSK of traditional Wi-Fi cannot verify the identity of the AP. An attacker can set up a disguised micro station (such as impersonating the SSID as "Substation-WAPI") near the substation to trick the terminal into accessing. However, this application starts the WAPI authentication process and, based on the WAPI's WAI (Wireless Authentication Infrastructure) protocol, can ensure through certificate exchange that "the terminal knows that it is communicating with the real micro station, and the micro station also knows that the terminal is a legitimate device." Specifically, after receiving an access request from a terminal in the substation to be connected, the microstation sends an authentication request (AuthReq) containing its own certificate digest to the terminal. The terminal returns its own certificate and a signature of the microstation digest (using the terminal's private key). The microstation forwards the terminal certificate and signature to the CAS via a secure tunnel (such as IPSec). The CAS verifies the signature using the terminal's public key and checks whether the certificate is in the CRL. CAS then returns the verification result. If successful, the microstation sends its full certificate to the terminal. The terminal verifies the signature of the microstation certificate using the CAS root certificate (e.g., the CAS root certificate is pre-installed in the terminal firmware) and checks whether the device type in the certificate matches (e.g., the "Device Type" field in the microstation certificate should be "AccessPoint"). In this way, by building a three-party trust chain of "terminal-microstation-CAS," for example, if an attacker forges a microstation and sends a false certificate, the terminal will be denied access because it cannot pass CAS verification. At the same time, the microstation will record the abnormal authentication request and report it to the security management platform.
[0031] In the above-mentioned WAPI-based substation terminal wireless access communication management method, in step S4, after the mutual authentication is judged to be successful, the substation terminal to be accessed and the micro station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent data encryption transmission. It should be understood that traditional static keys are difficult to manage when the number of devices is large (such as 1000 sets of PSK need to be maintained for 1000 devices), and the keys are easily cracked by brute force if they remain unchanged for a long time. However, this application creates a temporary encryption key for the current communication session by using the key negotiation mechanism defined in the WAPI protocol, which complies with the "least privilege principle" and "minimum key lifetime" principles, ensures that each session is unique, and enhances the security of communication. Specifically, this application adopts WAPI's KDF (key derivation function) and implements key negotiation based on the ECDH algorithm. First, the terminal generates a temporary elliptic curve key pair (Ephemeral Key) and sends the public key E_T to the micro station. The micro station generates a temporary key pair (E_A) and sends the public key E_A to the terminal. Then, both parties use the other party's public key and their own private key to calculate the shared secret S = d_T*E_A = d_A*E_T (d is the private key). Combined with the random numbers (Nonce_T, Nonce_A) from the authentication phase and the device certificate serial number (SN_T, SN_A), the session key SK = HMAC(S, Nonce_T||Nonce_A||SN_T||SN_A||Session ID) is generated using the HMAC-SHA3-256 algorithm. In addition, in a specific embodiment, to prevent replay attacks, the Nonce value is forcibly updated after each key negotiation, and a timestamp factor is added to the session key to ensure the uniqueness and timeliness of each session key. In this way, the "one-time, one-password" communication session is effectively achieved. For example, the communication session between a sensor and a microstation renegotiates the key every 30 minutes. Even if an attacker steals the key through the previous session, he or she will not be able to decrypt subsequent data. At the same time, it avoids the risk of "one device key leakage causing the entire network to be paralyzed" in the traditional PSK scheme. This not only improves the security of communication, but also effectively prevents security risks caused by key leakage or cracking.
[0032] In the above-mentioned WAPI-based substation terminal wireless access communication management method, in step S5, after the session key is established, the substation terminal to be connected and the micro station use the session key to encrypt and transmit business data. That is, the plaintext data is converted into ciphertext using the session key, and an authentication tag is attached to prevent tampering. In an embodiment of the present application, the AES-256-GCM algorithm is used to implement data encryption and integrity verification to ensure the confidentiality and integrity of data transmission. The AES-256-GCM algorithm combines the 256-bit encryption strength of the Advanced Encryption Standard (AES) and the authentication function of the Galois / Counter Mode (GCM), providing strong security protection for data communication. During the encryption process, the substation terminal to be connected and the micro station use the established session key to AES encrypt the transmitted business data to generate ciphertext. At the same time, the GCM mode also generates an authentication tag, which is transmitted together with the ciphertext for the recipient to verify the integrity and authenticity of the data. If the data is tampered with or forged during transmission, the authentication tag will not match, thereby triggering a security alarm to ensure the reliability of communication. In addition, the high efficiency of the AES-256-GCM algorithm also ensures the real-time data transmission and meets the substation's requirements for communication performance.
[0033] In order to further prevent potential advanced threats after authentication, after the encrypted channel is established, this application also continuously monitors the communication traffic between the substation terminal to be connected and the micro station through traffic monitoring technology to achieve abnormal behavior detection.
[0034] Figure 2 This is a flowchart of step S5 in the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application. Figure 3 FIG. 1 is a data flow diagram of step S5 in the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application. Figure 2 and Figure 3 As shown, the step S5 also includes: S51, obtaining the data stream metadata transmitted by the substation terminal and micro station to be connected through the WAPI network; S52, extracting the traffic pattern characteristics from the data stream metadata to obtain a network traffic pattern characteristic coding vector; S53, comparing the network traffic pattern characteristic coding vector with the normal behavior baseline coding vector to determine whether there is a traffic pattern abnormality.
[0035] Specifically, step S51 obtains metadata about data flows transmitted by the connected substation terminal and micro-station via the WAPI network. Specifically, this application copies the 802.11n / ac traffic between the micro-station and the terminal to the collection server via a mirrored port, parses the IP layer header using a high-performance framework such as PF_RING, and extracts data flow metadata such as the quintuple, traffic statistics, packet length, timestamp, and session duration to enable in-depth analysis of communication behavior.
[0036] Specifically, the step S52 extracts traffic pattern features from the data stream metadata to obtain a network traffic pattern feature encoding vector. Figure 4 FIG. 5 is a flowchart of step S52 in the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application. Figure 4 As shown, the step S52 includes: S521, performing data segmentation on the data stream metadata based on a predetermined time window to obtain a sequence distribution of the local time domain data stream metadata; S522, extracting the traffic pattern characteristics of each local time domain data stream metadata in the sequence distribution of the local time domain data stream metadata to obtain a sequence distribution of the local time series traffic pattern feature coding vector; S523, performing traffic pattern time series context aggregation coding on the sequence distribution of the local time series traffic pattern feature coding vector to obtain the network traffic pattern feature coding vector.
[0037] More specifically, the step S521 performs data segmentation on the data stream metadata based on a predetermined time window to obtain a sequence distribution of the local time domain data stream metadata. It should be understood that, considering that the attack behavior may manifest as a short-term traffic fluctuation (such as transmitting stolen data in stages). Therefore, in order to capture abnormal communication behavior in a more fine-grained manner, the present application performs data segmentation on the data stream metadata based on a predetermined time window, and divides the continuous data stream into multiple time segments, so as to capture the pattern changes of the data stream metadata in each local time domain segment (such as the number of data packets in the time period, the transmission rate, the frequency of session establishment and closure, and other indicators). Trends in changing trends can thereby promptly detect abnormal communication behavior and provide a basis for subsequent security analysis.
[0038] More specifically, step S522 extracts the traffic pattern features of each local time domain data stream metadata in the sequence distribution of the local time domain data stream metadata to obtain the sequence distribution of the local time series traffic pattern feature encoding vector. In a specific example of the present application, the traffic pattern feature extraction based on the LSTM model is performed on each local time domain data stream metadata in the sequence distribution of the local time domain data stream metadata to obtain the sequence distribution of the local time series traffic pattern feature encoding vector. It should be understood that the LSTM (Long Short-Term Memory) model is a special recurrent neural network (RNN) that is suitable for processing and predicting long-term dependencies in time series data. In the present application, the LSTM model is used to perform feature learning on each local time domain data stream metadata, which can effectively capture the time dependencies and hidden features in the data, thereby more accurately extracting the traffic pattern features in each local time domain. Specifically, first, the data stream metadata of each time step is standardized and embedded to convert different types of data into feature vectors of fixed length and convert the data stream metadata into an input format that can be processed by the LSTM model. Next, the metadata embedding features of the data stream at each time step are input into the LSTM network for sequence learning. Through the memory unit and forget gate, input gate, output gate and other mechanisms within the LSTM network, the metadata embedding features of the data stream at each time step are iteratively processed, and the state information is gradually accumulated and updated to capture the long-term dependencies and hidden features in the data stream, and output the traffic pattern feature encoding vector of each local time domain data stream metadata.
[0039] More specifically, in step S523, the sequence distribution of the local time series traffic pattern feature coding vector is subjected to traffic pattern time series context aggregation coding to obtain the network traffic pattern feature coding vector. That is, considering that in the complex communication scenario of the smart substation, the dynamic traffic pattern formed by the interweaving of periodic business traffic and bursty control instructions has a strong time series correlation characteristic, the traffic feature analysis method based on a fixed time window may cause pattern misjudgment due to the fragmentation of the time series context. For example, an attacker may disguise himself as normal business traffic through low-frequency and scattered data theft behavior. The local features within a single time window are not significantly different from the baseline, but the time series combination pattern across windows shows an abnormal evolution law. To this end, the present application further performs traffic pattern time series context aggregation coding on the sequence distribution of the local time series traffic pattern feature coding vector to deeply explore the correlation and evolution law of traffic features in the time dimension.
[0040] Figure 5 FIG. 5 is a flowchart of step S523 in the WAPI-based substation terminal wireless access communication management method according to an embodiment of the present application. Figure 5As shown, the step S523 includes: S5231, performing linear clustering analysis on the sequence distribution of the local time series traffic pattern feature coding vector to obtain the network traffic pattern feature initial linear clustering center coding vector; S5232, based on the feature clustering compensation increment of the sequence distribution of the local time series traffic pattern feature coding vector relative to the network traffic pattern feature initial linear clustering center coding vector, compensating and correcting the network traffic pattern feature initial linear clustering center coding vector to obtain the network traffic pattern feature coding vector.
[0041] More specifically, the step S5231 can be expressed as follows:
[0042] X={x1,x2,...,x i ,...,x n}
[0043]
[0044] Among them, X represents the sequence distribution of the local time series traffic pattern feature encoding vector, x1, x2, x i and x n They represent the first, second, i-th and n-th local time series traffic pattern feature coding vectors in the sequence distribution of local time series traffic pattern feature coding vectors, n represents the number of local time series traffic pattern feature coding vectors in the sequence distribution of local time series traffic pattern feature coding vectors, x c Represents the initial linear cluster center encoding vector of network traffic pattern characteristics.
[0045] That is, in response to the quasi-linear time series characteristics formed by the periodic business traffic of the substation (such as second-level telemetry and minute-level equipment status reporting), this application first performs a linear clustering analysis on the sequence distribution of the local time series traffic pattern feature encoding vector to capture the principal component distribution of the typical business traffic of the substation in the time dimension, and reduces the high-dimensional feature space to a linear subspace with physical interpretability. Subsequent nonlinear compensation establishes a benchmark anchor point, while avoiding the dimensional disaster brought about by directly processing complex nonlinear relationships.
[0046] More specifically, the step S5232 includes: calculating the feature clustering compensation increment operator of each local time series traffic pattern feature coding vector in the sequence distribution of the local time series traffic pattern feature coding vector relative to the network traffic pattern feature initial linear clustering center coding vector to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator. In a specific example of the present application, calculating the feature clustering compensation increment operator of each local time series traffic pattern feature coding vector in the sequence distribution of the local time series traffic pattern feature coding vector relative to the network traffic pattern feature initial linear clustering center coding vector to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator, including: first, constructing a deep collaborative implicit coding vector between each local time series traffic pattern feature coding vector in the sequence distribution of the local time series traffic pattern feature coding vector and the network traffic pattern feature initial linear clustering center coding vector to obtain the sequence distribution of the network traffic pattern feature deep collaborative implicit coding vector, which is expressed by the formula:
[0047] v c =sigmoid(x c )
[0048] r i =Sigmoid{W i [contact(x i ;v c )]+b i}
[0049] Among them, sigmoid(·) represents the Sigmoid activation function, v c Represents the initial linear cluster center activation encoding vector of network traffic pattern characteristics, b i represents the bias term, W i represents the weight matrix, contact(·;·) represents the cascade function, r i Represents the i-th network traffic pattern feature deep collaborative implicit coding vector in the sequence distribution of network traffic pattern feature deep collaborative implicit coding vectors.
[0050] That is, considering that attack traffic often penetrates into legitimate traffic patterns through tiny timing offsets (such as abnormally lengthened instruction intervals and gradual changes in packet size distribution). Therefore, this application further captures the characteristic associations between the characteristic coding vectors of each local timing traffic pattern and the initial cluster center by constructing a deep collaborative coding network, and mines the deviation information between the traffic pattern characteristics of each local window and the typical business pattern. For example, when the GOOSE message retransmission rate in a certain period of time continues to be higher than the cluster center representation, the dimensional difference is amplified through deep collaborative coding to provide a quantitative basis for subsequent compensation.
[0051] Next, each network traffic pattern feature deep collaborative implicit coding vector in the sequence distribution of the network traffic pattern feature deep collaborative implicit coding vector is respectively subjected to feature clustering difference compensation calculation with the network traffic pattern feature initial linear cluster center coding vector to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator, which is expressed as follows:
[0052]
[0053] Among them, log2 represents the logarithmic function with base 2, r ik Represents r i The eigenvalue at the kth position in ck Indicates v c The k-th position eigenvalue in , L represents the characteristic scale value of the network traffic pattern feature depth collaborative implicit coding vector, λ i Represents x i The corresponding network traffic pattern feature clustering compensation increment operator.
[0054] Here, it is considered that the deviation information between the traffic pattern characteristics of each local window and the typical business pattern usually has different significance and importance. Therefore, in order to accurately evaluate the actual impact of these deviation information, this application further performs a quantitative analysis of the feature differences between the deep collaborative implicit coding vectors of each network traffic pattern feature and the initial cluster center through feature clustering difference compensation calculation, and obtains the corresponding sequence distribution of the network traffic pattern feature clustering compensation increment operator as a quantitative representation of the degree of influence of the traffic pattern deviation characteristics of each local window on the overall traffic pattern.
[0055] More specifically, the step S5232 further includes: based on the sequence distribution of the network traffic pattern feature clustering compensation increment operator, calculating the linear clustering compensation component of the sequence distribution of the local time series traffic pattern feature coding vector to obtain the network traffic pattern feature linear clustering compensation component coding vector. In particular, considering that when calculating the network traffic pattern feature clustering compensation increment operator, the incremental nonlinear information of the linear clustering result based on the network traffic pattern feature deep collaborative implicit coding vector is added in addition to the original local time series traffic pattern feature coding vector, resulting in the addition of cluster elements in the cluster space, thereby causing a system non-equilibrium state of the cluster space distribution. Based on this, in a preferred example of the present application, each network traffic pattern feature clustering compensation increment operator in the sequence distribution of the network traffic pattern feature clustering compensation increment operator is subjected to resonance coupling enhancement based on cluster balance correction to obtain a sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator. That is, the spatial distribution of the network traffic pattern feature clustering compensation increment operator is dynamically corrected through the resonance coupling enhancement mechanism to solve the systematic offset problem caused by nonlinear information injection.
[0056] Based on this, we first use the inner product of the local time series traffic pattern feature encoding vector and the network traffic pattern feature deep collaborative implicit encoding vector <x i ,r i >Construct clustering intrinsic energy term ∑ i , and calculate the clustering adjustment coefficient Γ i , which can be expressed as:
[0057] ∑ i = <x i ,r i >
[0058]
[0059] Among them, <·,·> means calculating the inner product, ∑ i Represents x i and r i The clustering eigenenergy term between 2 Represents the variance of the sequence distribution composed of all eigenvalues in the calculation vector, ∈ i Represents the clustering eigenenergy term ∑ i The associated intrinsic scattering factor, Γ i For r i The clustering adjustment coefficient represents the r in the clustering space i Dissipative regulation effect on linear cluster centers.
[0060] Finally, combined with the clustering intrinsic energy term ∑ i The corresponding clustering adjustment coefficient Γ i ,pass ×L -1 / 2 (where e (·) represents an exponential function with a natural constant as the base, Represents the corrected network traffic pattern feature clustering compensation incremental operator), and implements resonance coordination based on energy state balance on the network traffic pattern feature clustering compensation incremental operator in the clustering space, thereby realizing dynamic coupling optimization of the network traffic pattern feature clustering compensation incremental operator under the fractal space representation, and achieving the clustering steady-state correction effect of nonlinear incremental coordination.
[0061] Next, the sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator is normalized based on the Softmax function to obtain the sequence distribution of the normalized network traffic pattern feature clustering compensation increment operator, and based on the sequence distribution of the normalized network traffic pattern feature clustering compensation increment operator, the sequence distribution of the local time series traffic pattern feature encoding vector is weightedly aggregated to obtain the network traffic pattern feature linear clustering compensation component encoding vector, which is expressed as follows:
[0062]
[0063] Among them, softmax(·) represents the normalized exponential function, ε i Represents λ ′i The corresponding normalized network traffic pattern feature clustering compensation increment operator, x b Represents the linear clustering compensation component encoding vector of network traffic pattern characteristics.
[0064] That is, in order to achieve effective fusion of traffic pattern feature compensation information in each local time domain, this application uses Softmax to normalize the sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator, and maps each compensation increment operator to the interval [0,1] to ensure the rationality of its physical meaning and the numerical stability of subsequent weighted aggregation. Subsequently, based on the normalized network traffic pattern feature clustering compensation increment operator, each local time series traffic pattern feature encoding vector is weighted. In essence, it is to weight the traffic pattern features in each local window based on the degree of its deviation from the typical business pattern, thereby achieving effective fusion of global compensation information.
[0065] More specifically, the step S5232 further includes: fusing the network traffic pattern feature linear cluster compensation component encoding vector and the network traffic pattern feature initial linear cluster center encoding vector to obtain the network traffic pattern feature encoding vector, which is expressed as:
[0066] v f =α·x b +β·xc
[0067] Among them, α and β represent different weight parameters, v f Represents the network traffic pattern feature encoding vector.
[0068] That is, by weightedly aggregating the network traffic pattern feature linear cluster compensation component encoding vector and the network traffic pattern feature initial linear cluster center encoding vector, the deviation information in the local time-series traffic pattern is effectively integrated back into the overall traffic pattern feature representation, thereby constructing a comprehensive network traffic pattern feature encoding vector that not only contains typical business pattern characteristics but also reflects local deviation information. Through this process, the network traffic pattern feature encoding vector not only retains the main characteristics of the substation business traffic, but also can sensitively capture subtle deviations in each local time-series traffic pattern, providing a more comprehensive and detailed data foundation for subsequent intelligent analysis and anomaly detection.
[0069] Specifically, step S53 compares the network traffic pattern feature encoding vector with the normal behavior baseline encoding vector to determine whether a traffic pattern anomaly exists. In a specific example of the present application, the cosine similarity between the network traffic pattern feature encoding vector and the normal behavior baseline encoding vector is calculated, and the presence of a traffic pattern anomaly is determined based on a preset similarity threshold. It should be understood that the normal behavior baseline encoding vector is a normal behavior baseline representation obtained by performing the above-mentioned encoding process on historical normal traffic pattern data, which represents the normal behavior pattern of substation business traffic. By calculating the similarity between the real-time network traffic pattern feature encoding vector and the normal behavior baseline encoding vector, the degree of deviation between the current traffic pattern and the normal behavior pattern can be quantitatively assessed. When the cosine similarity is lower than the preset similarity threshold, the traffic pattern anomaly is considered to exist, which may indicate a potential network security threat or equipment failure, thereby triggering a corresponding early warning mechanism or troubleshooting process. This process not only improves the accuracy of anomaly detection but also provides operation and maintenance personnel with timely and effective fault location information, helping to improve the operational safety and reliability of the substation.
[0070] In summary, according to the embodiment of the present application, the WAPI-based substation terminal wireless access communication management method is explained, which obtains the unique digital certificates of the substation terminal to be accessed and the target micro-station from the CAS system, starts the WAPI two-way authentication process during wireless access, and ensures the identity credibility of the terminal and the micro-station by exchanging digital certificates and completing the two-way legitimacy verification by the CAS system. After the authentication is passed, the two parties generate a dynamic session key based on the WAPI key negotiation mechanism to achieve end-to-end encrypted transmission of business data. Furthermore, during the data transmission process, the data stream metadata of the encrypted transmission layer is collected in real time, and a deep learning algorithm is introduced to perform time-series slicing analysis on it to extract the traffic pattern time-series context features of the communication network, and compare and analyze it with the normal behavior baseline to identify traffic pattern deviations caused by key leakage or malicious attacks. This method not only ensures the trusted authentication of the device identity in the wireless access stage, but also realizes the perception of transmission process anomalies through network traffic behavior feature modeling, forming a dual depth defense of access authentication and continuous monitoring, which can effectively improve the security and reliability of wireless access communication of substation terminals.
[0071] Furthermore, the present application also provides a WAPI-based substation terminal wireless access communication management system.
[0072] Figure 6 FIG is a block diagram of a WAPI-based substation terminal wireless access communication management system according to an embodiment of the present application. Figure 6 As shown, according to the WAPI-based substation terminal wireless access communication management system 100 of the embodiment of the present application, it includes: a digital certificate acquisition module 110, which is used for the substation terminal to be accessed and the micro station to obtain their unique digital certificates from the control and authentication systems respectively; an access request sending module 120, which is used for the substation terminal to be accessed to select the micro station and send an access request after entering the coverage range of the micro station; an authentication module 130, which is used for the micro station to start the WAPI authentication process after receiving the access request from the substation terminal to be accessed, wherein the WAPI authentication process includes the substation terminal to be accessed and the micro station exchanging the unique digital certificates with each other, and only when the unique digital certificates of the substation terminal to be accessed and the micro station pass CAS verification, the mutual authentication is judged to be successful; a key negotiation generation module 140, which is used for the substation terminal to be accessed and the micro station to use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent data encryption transmission after the mutual authentication is judged to be successful; an encryption transmission module 150, which is used for the substation terminal to be accessed and the micro station to use the session key to encrypt and transmit business data after the session key is established.
[0073] Here, those skilled in the art will appreciate that the specific operations of each module in the above-mentioned WAPI-based substation terminal wireless access communication management system have been described in the above-mentioned Figures 1 to 5The description of the WAPI-based substation terminal wireless access communication management method has been introduced in detail, and therefore, its repeated description will be omitted.
[0074] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A WAPI-based substation terminal wireless access communication management method, characterized in that: include: The substation terminal and microstation to be connected obtain their unique digital certificates from the control and authentication systems respectively; After the access substation terminal enters the coverage area of the micro station, it selects the micro station and sends an access request; After receiving the access request from the substation terminal to be connected, the micro station starts the WAPI authentication process, wherein the WAPI authentication process includes the substation terminal to be connected and the micro station exchanging the unique digital certificates. Only when the unique digital certificates of the substation terminal to be connected and the micro station pass the CAS verification, the mutual authentication is determined to be successful; After mutual authentication is determined to be successful, the substation terminal to be connected and the micro station use the key negotiation mechanism defined in the WAPI protocol to generate a session key for subsequent data encryption transmission; After the session key is established, the substation terminal to be connected and the micro station use the session key to encrypt and transmit business data; After the session key is established, the substation terminal to be connected and the micro station use the session key to encrypt and transmit business data, including: Obtain metadata of data streams transmitted via the WAPI network by the substation terminals and micro-stations to be connected; Extracting traffic pattern features from the data stream metadata to obtain a network traffic pattern feature encoding vector; Comparing the network traffic pattern feature encoding vector with the normal behavior baseline encoding vector to determine whether there is a traffic pattern anomaly; Extracting traffic pattern features from the data stream metadata to obtain a network traffic pattern feature encoding vector includes: Segmenting the data stream metadata based on a predetermined time window to obtain a sequence distribution of the local time domain data stream metadata; Extracting the traffic pattern features of each local time domain data stream metadata in the sequence distribution of the local time domain data stream metadata to obtain a sequence distribution of local time series traffic pattern feature encoding vectors; Performing linear cluster analysis on the sequence distribution of the local time series traffic pattern feature coding vector to obtain an initial linear cluster center coding vector of the network traffic pattern feature; Based on the feature clustering compensation increment of the sequence distribution of the local temporal traffic pattern feature coding vector relative to the network traffic pattern feature initial linear clustering center coding vector, the network traffic pattern feature initial linear clustering center coding vector is compensated and corrected to obtain the network traffic pattern feature coding vector.
2. The WAPI-based substation terminal wireless access communication management method according to claim 1, characterized in that: Extracting the traffic pattern features of each local time-domain data stream metadata in the sequence distribution of the local time-domain data stream metadata to obtain a sequence distribution of local time series traffic pattern feature encoding vectors, including: Traffic pattern feature extraction based on the LSTM model is performed on each local time domain data stream metadata in the sequence distribution of the local time domain data stream metadata to obtain the sequence distribution of the local time series traffic pattern feature encoding vector.
3. The WAPI-based substation terminal wireless access communication management method according to claim 2, characterized in that: Based on the feature clustering compensation increment of the sequence distribution of the local time series traffic pattern feature coding vector relative to the network traffic pattern feature initial linear clustering center coding vector, compensating and correcting the network traffic pattern feature initial linear clustering center coding vector to obtain the network traffic pattern feature coding vector, including: Calculating a feature clustering compensation increment operator of each local time series traffic pattern feature coding vector in the sequence distribution of the local time series traffic pattern feature coding vector relative to the network traffic pattern feature initial linear clustering center coding vector to obtain a sequence distribution of the network traffic pattern feature clustering compensation increment operator; Based on the sequence distribution of the network traffic pattern feature clustering compensation increment operator, calculating the linear clustering compensation component of the sequence distribution of the local time series traffic pattern feature coding vector to obtain the network traffic pattern feature linear clustering compensation component coding vector; The network traffic pattern feature linear clustering compensation component encoding vector and the network traffic pattern feature initial linear clustering center encoding vector are fused to obtain the network traffic pattern feature encoding vector.
4. The WAPI-based substation terminal wireless access communication management method according to claim 3, characterized in that: Calculating a feature clustering compensation increment operator of each local time series traffic pattern feature encoding vector in the sequence distribution of the local time series traffic pattern feature encoding vector relative to the network traffic pattern feature initial linear clustering center encoding vector to obtain a sequence distribution of the network traffic pattern feature clustering compensation increment operator, including: Constructing a deep collaborative implicit coding vector between each local time series traffic pattern feature coding vector in the sequence distribution of the local time series traffic pattern feature coding vector and the network traffic pattern feature initial linear clustering center coding vector to obtain a sequence distribution of the network traffic pattern feature deep collaborative implicit coding vector; Each network traffic pattern feature deep collaborative implicit coding vector in the sequence distribution of the network traffic pattern feature deep collaborative implicit coding vector is respectively subjected to feature clustering difference compensation calculation with the network traffic pattern feature initial linear clustering center coding vector to obtain the sequence distribution of the network traffic pattern feature clustering compensation increment operator.
5. The WAPI-based substation terminal wireless access communication management method according to claim 4, characterized in that: Based on the sequence distribution of the network traffic pattern feature clustering compensation increment operator, calculating the linear clustering compensation component of the sequence distribution of the local time series traffic pattern feature encoding vector to obtain the network traffic pattern feature linear clustering compensation component encoding vector, including: Performing a resonance coupling enhancement based on clustering balance correction on each network traffic pattern feature clustering compensation incremental operator in the sequence distribution of the network traffic pattern feature clustering compensation incremental operator to obtain an optimized sequence distribution of the network traffic pattern feature clustering compensation incremental operator; Normalizing the sequence distribution of the optimized network traffic pattern feature clustering compensation increment operator based on a Softmax function to obtain a sequence distribution of a normalized network traffic pattern feature clustering compensation increment operator; Based on the sequence distribution of the normalized network traffic pattern feature clustering compensation increment operator, the sequence distribution of the local time series traffic pattern feature encoding vector is weightedly aggregated to obtain the network traffic pattern feature linear clustering compensation component encoding vector.
6. The WAPI-based substation terminal wireless access communication management method according to claim 5, characterized in that: Comparing the network traffic pattern feature encoding vector with the normal behavior baseline encoding vector to determine whether there is a traffic pattern anomaly includes: The cosine similarity between the network traffic pattern feature encoding vector and the normal behavior baseline encoding vector is calculated, and whether there is a traffic pattern anomaly is determined based on a preset similarity threshold.
7. A WAPI-based substation terminal wireless access communication management system, used to execute the method according to any one of claims 1 to 6, characterized in that: include: A digital certificate acquisition module is used for the substation terminal and micro station to be connected to obtain their unique digital certificates from the control and authentication systems respectively; An access request sending module is used to select a micro station and send an access request after the substation terminal to be accessed enters the coverage area of the micro station; An authentication module is configured to initiate a WAPI authentication process after the micro station receives an access request from the substation terminal to be accessed. The WAPI authentication process includes the substation terminal to be accessed and the micro station exchanging the unique digital certificates with each other. Mutual authentication is considered successful only if the unique digital certificates of both the substation terminal to be accessed and the micro station pass CAS verification. The key negotiation generation module is used to generate a session key for subsequent data encryption transmission by the substation terminal to be connected and the micro station using the key negotiation mechanism defined in the WAPI protocol after mutual authentication is determined to be successful; The encryption transmission module is used to encrypt and transmit business data using the session key between the terminal to be connected to the substation and the micro station after the session key is established.
Citation Information
Patent Citations
Cloud data security protection method and system based on 5G network
CN117156442A
Power grid abnormal flow detection and identification method based on multi-mode machine learning algorithm
CN119892401A
WAPI-based wireless encryption transformer substation integrated monitoring system
CN221598147U