Power plant secondary security protection and dispatching data network equipment transformation cutover method and power plant secondary security protection and dispatching data network equipment transformation cutover system
By switching business channels, cutting the centralized control side channels in the secondary security and scheduling data network of the power plant, verifying equipment policies and configurations, and backing up data, the interruption risk and compatibility problems during the equipment transformation process are solved, network stability and data security are achieved, and the operating efficiency of the power plant is improved.
Patent Information
- Application Number
- CN202510263196.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-07-18
AI Technical Summary
The existing secondary security and scheduling data network equipment transformation methods in power plants have problems such as high risk of business interruption, insufficient equipment compatibility, weak emergency response capabilities, and how to ensure data security and network stability optimization during the separating process.
By switching various services between different channels according to channel redundancy, separating the channel on the centralized control side, and verifying the equipment policy, configuring and connecting the equipment based on the topology structure, backing up the service data, and restoring the backup data in abnormal situations.
It improves the reliability and stability of network transmission, reduces equipment downtime, enhances equipment compatibility and emergency response capabilities, ensures data security and integrity, and improves the operating efficiency of the power plant.
Smart Images

Figure CN120342958A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the transformation and cutover of secondary security protection and dispatching data network equipment in power plants, and specifically relates to a method for the transformation and cutover of secondary security protection and dispatching data network equipment in power plants. Background Art
[0002] With the continuous improvement of the informatization and automation levels in the power industry, the secondary security protection and dispatching data network in power plants has become the core support system for power dispatching and production operation. The traditional dispatching data network adopts a fixed topology structure and relies on a single security policy for data transmission and equipment management. However, with the expansion of the power grid scale, the complexity of the dispatching system, and the improvement of security requirements, the traditional system gradually exposes limitations in aspects such as data transmission stability, equipment compatibility, and network security. In recent years, in order to improve the reliability and security of the secondary security protection and dispatching data network in power plants, various advanced network architectures, intelligent management technologies, and efficient cutover methods have emerged one after another. For example, the introduction of redundant design, intelligent service load balancing technology, network fault prediction models, etc. The introduction of these technologies has improved the security and stability of the system to a certain extent, but the existing technologies still face many problems such as a high risk of service interruption during the cutover process, insufficient equipment compatibility, and weak emergency response capabilities.
[0003] Traditional transformation and cutover methods often lack precise planning and redundant scheduling mechanisms, so that when switching equipment, key services such as monitoring systems and electric energy systems may experience short-term interruptions or even long-term failures, affecting the stability of power plant production operation. Especially when the service traffic is high or the cutover operation fails to accurately match the dispatching data flow direction, network congestion and data loss problems are likely to occur. Due to the fact that new and old equipment may use different communication protocols, hardware interfaces, and data transmission standards, there are equipment compatibility problems during the transformation process. The lack of an effective protocol conversion mechanism may cause some equipment to be unable to access the network normally, and even lead to data loss or system failures. This not only increases the technical complexity of the transformation, but also prolongs the construction period and increases the transformation cost. Currently, the transformation and cutover often lack unified planning and strict operation procedures, resulting in problems such as task confusion, step omission, and unclear responsibilities during the cutover process. For example, in the absence of effective topology structure optimization, the network reachability of some equipment connections may be lost due to incorrect cutover, affecting the stability of the overall dispatching network.
[0004] The existing cutover plan is relatively weak in dealing with sudden network failures or equipment failures, lacking real-time intelligent monitoring and automated recovery mechanisms. Once an abnormal situation occurs, it usually relies on manual troubleshooting and repair, resulting in a long service restoration time. In severe cases, it may affect the normal scheduling of power plant production. During the cutover process, if there is a lack of a perfect data backup and migration strategy, it may lead to data loss, tampering, or leakage. In addition, the traditional data storage and transmission mechanisms lack effective encryption and access control, making them vulnerable to network attacks and affecting the integrity and security of power plant scheduling data. Summary of the Invention
[0005] In view of the above existing problems, the present invention is proposed.
[0006] Therefore, the technical problems solved by the present invention are: the existing methods for transforming the secondary security protection and dispatching data network equipment in power plants have a high risk of service interruption, insufficient equipment compatibility, weak emergency handling capabilities, and the optimization problem of how to ensure data security and network stability during the cutover process.
[0007] To solve the above technical problems, the present invention provides the following technical solution: A method for transforming and cutover of secondary security protection and dispatching data network equipment in a power plant, including switching various services between different channels according to channel redundancy and performing cutover on the channels on the centralized control side; performing policy verification on the equipment, configuring and connecting the equipment based on the topological structure; backing up the service data and restoring the backup data in case of abnormal situations.
[0008] As a preferred solution of the method for transforming and cutover of secondary security protection and dispatching data network equipment in the power plant according to the present invention, wherein: the switching of various services between different channels according to channel redundancy includes, through the channel redundancy in the secondary security protection and dispatching data network on the centralized control side, switching various services between different channels according to service requirements, and performing real-time monitoring on the service data traffic through an adaptive algorithm. When the channel service traffic approaches the preset upper limit, automatically switch the service to a channel with a load lower than the preset load. Combine the dynamic adjustment of the channel switching priority mechanism with network fault prediction and real-time traffic monitoring. When it is predicted that a channel will have a fault or traffic overload, automatically switch the service to a normal channel according to the preset priority strategy, and the priority is dynamically adjusted according to the real-time traffic. When the channel traffic suddenly increases during the cutover, temporarily increase the channel switching priority of channels other than the current channel.
[0009] As a preferred solution of the power plant secondary security protection and dispatching data network equipment transformation and cutover method described in the present invention, wherein: the cutover of the channel on the centralized control side includes the cutover of channels A and B in areas 1 and 2 on the centralized control side. When cutting over channel A, switch the monitoring system service to run on channel B, disconnect the network cable between the switch A in area 1 on the centralized control side and the centralized control communication machine, observe the monitoring system service, if abnormal, resume troubleshooting. After confirming that channel B is transmitting normally, power off the longitudinal encryption device A in area 1, remove it and move it to a preset position, connect the power supply and network cable, turn on the machine and check whether the policy is normal. Lay a new network cable according to the topology diagram to connect the switch B in area 1 on the centralized control side and the centralized control communication machine, replace the original network cable and check the connection, switch the electric energy service and the network order issuing system service to run on channel B, perform the same operation on the longitudinal encryption device B in area 2, lay network cables from the switch C in area 2 on the centralized control side to the electric energy acquisition device and the centralized control order receiving system terminal respectively to replace the original network cable, and then lay a network cable from the dispatching switch C on the centralized control side to the ZTE SDH385 to replace the original network cable, and check whether the service transmission is normal;
[0010] When cutting over channel B, switch the monitoring system service to run on channel A, disconnect the network cable between the switch D in area 1 on the centralized control side and the centralized control communication machine, observe the monitoring system service, if abnormal, resume troubleshooting. After confirming that channel A is transmitting normally, power off the longitudinal encryption device C in area 1, remove it and move it to a preset position, connect the power supply and network cable, turn on the machine and check whether the policy is normal. Lay a new network cable according to the topology diagram to connect the switch E in area 1 on the centralized control side and the centralized control communication machine, replace the original network cable and check the connection, switch the electric energy service and the network order issuing system service to run on channel A, perform the same operation on the longitudinal encryption device D in area 2, lay network cables from the switch F in area 2 on the centralized control side to the electric energy acquisition device and the centralized control order receiving system terminal respectively to replace the original network cable, and then lay a network cable from the dispatching switch F on the centralized control side to the ZTE SDH385 to replace the original network cable, and check whether the service transmission is normal.
[0011] As a preferred solution of the method for the transformation and cutover of the secondary security protection and dispatching data network equipment in the power plant described in the present invention, wherein: the policy verification of the equipment includes logging in to the longitudinal encryption device A in Zone 1 through the equipment management interface, comparing the consistency of the current configured policy with the backup policy before power outage, switching the monitoring system service to run on Channel B, then observing the service data sent by the monitoring system to the centralized control center, checking the data transmission rate and packet loss rate indicators, and at the same time comparing the integrity and accuracy of the service data to confirm that it is consistent with the data in the normal operation state. Through the ping command or network connectivity test tool, perform a connectivity test on the longitudinal encryption device A in Zone 1 and the equipment. If all the detection and verification pass, the equipment migration and configuration operation is successful this time. If the verification fails, the system will immediately automatically restore to the original state, and at the same time generate an error report, recording the links and data where the verification fails. According to the error report, locate the problem and perform targeted repairs. After the repairs are completed, perform the detection and verification again until all the detection and verification pass.
[0012] As a preferred solution of the method for the transformation and cutover of the secondary security protection and dispatching data network equipment in the power plant described in the present invention, wherein: the device configuration and connection based on the topological structure includes performing device configuration and connection operations according to the transformed topological diagram of the centralized control secondary security protection network of the power plant, arranging the cutover sequence of the devices to avoid network failures and service interruptions caused by incorrect device connections or improper configurations. When deploying new devices, laying network cables, and connecting devices, the network topological status is monitored in real time through an intelligent topological monitoring system. The system uses the network discovery protocol and the link layer discovery protocol to automatically identify the devices and connection relationships in the network, and compare them with the preset topological diagram. If it is found that there are differences between the actual topology and the preset topological diagram, the system immediately issues an alarm and displays the difference points through a visual interface to locate the problem.
[0013] As a preferred solution of the method for the transformation and cutover of the secondary security protection and dispatching data network equipment in the power plant described in the present invention, wherein: the device configuration and connection based on the topological structure further includes regularly evaluating and optimizing the network topology based on the data collected by the intelligent topological monitoring. By analyzing the network traffic distribution, device load conditions, and link utilization rate indicators, potential network bottlenecks and performance shortboards are found. If it is monitored that the link continuously shows a high load situation during the peak power consumption period, resulting in an increase in data transmission delay, adjustments are made through topological optimization, the data flow direction is re-planned, the service traffic is distributed to idle links, or the high-load devices are upgraded to improve the device processing capacity. And along with the development and change of the network service, the network topology is actively adjusted adaptively. According to the requirements of the new service, the device connections are added or adjusted to enable the new service to access the network.
[0014] As a preferred solution of the method for reforming and switching the secondary security protection and dispatching data network equipment in a power plant according to the present invention, wherein: the backup of service data includes comprehensively backing up the service data during the reforming and switching process, storing the backup data in different external hard drives respectively to prevent data loss caused by a single storage medium failure. After the equipment switching is completed, if the data is abnormal or lost, the backup data is used for recovery to carry out the power plant business normally.
[0015] Another object of the present invention is to provide a reforming and switching system for secondary security protection and dispatching data network equipment in a power plant, which can orderly switch various services between different channels through a channel switching module and accurately switch the channel on the centralized control side, solving the problem that the current service switching easily causes system interruption.
[0016] As a preferred solution of the reforming and switching system for secondary security protection and dispatching data network equipment in a power plant according to the present invention, wherein: it includes a channel switching module, a verification and configuration module, and a data backup module; the channel switching module is used to switch various services between different channels according to channel redundancy and switch the channel on the centralized control side; the verification and configuration module is used to verify the strategy of the equipment and configure and connect the equipment based on the topological structure; the data backup module is used to back up the service data and recover the backup data in case of an abnormal situation.
[0017] A computer device includes a memory and a processor, the memory stores a computer program, and is characterized in that when the processor executes the computer program, the steps of the method for reforming and switching the secondary security protection and dispatching data network equipment in a power plant are realized.
[0018] A computer-readable storage medium stores a computer program thereon, and is characterized in that when the computer program is executed by a processor, the steps of the method for reforming and switching the secondary security protection and dispatching data network equipment in a power plant are realized.
[0019] Advantages of the present invention: The method for reforming and cutting over the secondary security protection and dispatching data network equipment of a power plant provided by the present invention effectively blocks external illegal network access through the optimization of the network topology structure, enhances the network boundary protection, ensures the accurate and stable transmission of dispatching data through the new data transmission mechanism and protocol optimization, improves the transmission reliability, optimizes the transmitted data, reduces the data transmission volume and transmission delay, enhances the transmission efficiency, divides the reform process into multiple stages, avoids the risks of system collapse or long-term downtime caused by large-scale reform at one time, improves the ability to respond to emergencies, considers the compatibility of equipment from different manufacturers and different models, improves the feasibility and success rate of reforming and cutting over, improves the secondary security protection performance and optimizes the dispatching data transmission, ensures the stable operation of power plant equipment, reduces the equipment downtime caused by network security problems or data transmission failures, and improves the overall operation efficiency of the power plant. The present invention achieves better effects in terms of reliability, compatibility and operation efficiency. Brief Description of the Drawings
[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. Among them:
[0021] Figure 1 It is the overall flowchart of a method for reforming and cutting over the secondary security protection and dispatching data network equipment of a power plant provided by the first embodiment of the present invention.
[0022] Figure 2 It is the overall module diagram of a system for reforming and cutting over the secondary security protection and dispatching data network equipment of a power plant provided by the third embodiment of the present invention. Detailed Embodiments
[0023] In order to make the above objects, features and advantages of the present invention more obvious and understandable, the detailed embodiments of the present invention will be described in detail below with reference to the drawings of the specification. Obviously, the described embodiments are some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0024] Embodiment 1
[0025] Refer to Figure 1 , which is an embodiment of the present invention, and provides a method for reforming and cutting over the secondary security protection and dispatching data network equipment of a power plant, including:
[0026] S1: Switch various services between different channels according to channel redundancy, and cut over the channels on the centralized control side.
[0027] Furthermore, switching various services between different channels according to channel redundancy includes channel redundancy in the secondary security protection on the centralized control side and the dispatching data network.
[0028] It should be noted that various services are switched between different channels according to service requirements, and the service data traffic is monitored in real time through an adaptive algorithm. When the channel service traffic approaches the preset upper limit, the service is automatically switched to a channel with a load lower than the preset load. The dynamic adjustment of the channel switching priority mechanism is combined with network fault prediction and real-time traffic monitoring. When it is predicted that a channel will have a fault or traffic overload, according to the preset priority strategy, the service is automatically switched to a normal channel, and the priority is dynamically adjusted according to the real-time traffic. When the channel traffic surges during the cutover, temporarily increase the channel switching priority of channels other than the current channel.
[0029] It should also be noted that during the peak electricity consumption period, the data traffic of the electric energy acquisition system and the monitoring system increases greatly. The intelligent load balancing system can timely adjust the service distribution, avoid channel congestion, and ensure smooth data transmission;
[0030] For a monitoring system with extremely high requirements for real-time performance, once an abnormal sign appears in the channel, it will be preferentially switched to ensure the timely transmission of monitoring data and avoid affecting the safe operation of the power plant.
[0031] Furthermore, cutting over the channels on the centralized control side includes cutting over channels A and B in Zone 1 and Zone 2 on the centralized control side.
[0032] It should be noted that when cutting over channel A, switch the monitoring system service to run on channel B, disconnect the network cable between the switch A in Zone 1 on the centralized control side and the centralized control communication machine, observe the monitoring system service. If it is abnormal, restore and check. After confirming that channel B is transmitting normally, power off the longitudinal encryption device A in Zone 1, remove it and move it to the preset position, connect the power supply and network cable, turn on the machine and check whether the strategy is normal. Lay a new network cable according to the topology diagram to connect the switch B in Zone 1 on the centralized control side and the centralized control communication machine, replace the original network cable and check the connection. Switch the electric energy service and the network order sending system service to run on channel B, perform the same operation on the longitudinal encryption device B in Zone 2. Lay network cables from the switch C in Zone 2 on the centralized control side to access the electric energy acquisition device and the centralized control receiving order system terminal respectively to replace the original network cable, and then lay a network cable from the dispatching switch C on the centralized control side to access the ZTE SDH385 to replace the original network cable, and check whether the service transmission is normal;
[0033] When making patch cuts to Channel B, switch the monitoring system services to run on Channel A. Disconnect the network cable between the centralized control communication machine and the first - zone switch D on the centralized control side, and observe the monitoring system services. If there are abnormalities, resume troubleshooting. After confirming that Channel A is transmitting normally, power off the first - zone longitudinal encryption device C, remove it and move it to the preset location, connect the power supply and network cable, and power on to check whether the policies are normal. Lay a new network cable according to the topology diagram to connect the first - zone switch E on the centralized control side and the centralized control communication machine, replace the original network cable and check the connection. Switch the power energy service and the network command - issuing system service to run on Channel A. Perform the same operations on the second - zone longitudinal encryption device D. Lay network cables from the second - zone switch F on the centralized control side to the power energy acquisition device and the centralized control order - receiving system terminal respectively to replace the original network cables. Then lay a network cable from the dispatching switch F on the centralized control side to connect to the ZTE SDH385 to replace the original network cable, and check whether the service transmission is normal.
[0034] S2: Conduct policy verification on the devices, and perform device configuration and connection based on the topology.
[0035] Furthermore, conducting policy verification on the devices includes logging in to the first - zone longitudinal encryption device A through the device management interface.
[0036] It should be noted that compare the consistency between the current configuration policy and the backup policy before power - off. Switch the monitoring system services to run on Channel B, and then observe the service data sent from the monitoring system to the centralized control center. Check the data transmission rate and packet loss rate indicators, and at the same time compare the integrity and accuracy of the service data to confirm that it is consistent with the data in the normal operation state. Use the ping command or network connectivity test tool to conduct a connectivity test between the first - zone longitudinal encryption device A and the devices. If all the detection and verification pass, the device migration and configuration operations are successful. If the verification fails, the system will immediately automatically restore to the original state, and at the same time generate an error report, record the links and data where the verification fails. According to the error report, locate the problem and perform targeted repairs. After the repairs are completed, conduct the detection and verification again until all the detection and verification pass.
[0037] Furthermore, performing device configuration and connection based on the topology includes performing device configuration and connection operations according to the transformed secondary security network topology diagram of the power plant centralized control.
[0038] It should be noted that arrange the patch - cut order of the devices to avoid network failures and service interruptions caused by incorrect device connections or improper configurations. When deploying new devices, laying network cables, and connecting devices, use the intelligent topology monitoring system to monitor the network topology status in real - time. The system uses the network discovery protocol and the link - layer discovery protocol to automatically identify the devices and connection relationships in the network, compare them with the preset topology diagram. If it is found that there are differences between the actual topology and the preset topology diagram, the system immediately issues an alarm and displays the difference points through the visualization interface to locate the problem.
[0039] It should also be noted that during the deployment of new equipment, laying of network cables, and connection between devices, ensure that the interface connection, IP address configuration, encryption policy setting, etc. of each device are exactly matched with the requirements of the topology diagram. For example, when laying the network cables between the centralized control side switch and the communication machine, electric energy acquisition device, centralized control order receiving system terminal, and ZTE SDH385, make accurate connections according to the topology diagram plan to ensure the correct data flow and efficient transmission in the network;
[0040] When an abnormality occurs in the network cable between the centralized control side switch and the electric energy acquisition device, the intelligent topology monitoring system can quickly detect it and notify the operation and maintenance personnel in the first time. The operation and maintenance personnel can, based on the information provided by the system, promptly troubleshoot the fault, restore the device connection, and ensure that data transmission is not affected.
[0041] Furthermore, device configuration and connection based on the topology structure also include data collected based on intelligent topology monitoring.
[0042] It should be noted that regularly evaluate and optimize the network topology. By analyzing network traffic distribution, device load conditions, and link utilization rate indicators, identify potential network bottlenecks and performance short - boards. If it is monitored that the link continuously shows a high - load situation during the peak power consumption period, resulting in an increase in data transmission delay, make adjustments through topology optimization, re - plan the data flow direction, allocate service traffic to idle links or upgrade high - load devices to improve device processing capabilities, and actively make adaptive adjustments to the network topology as the network business develops and changes. According to the requirements of new services, add or adjust device connections to enable new services to access the network.
[0043] It should also be noted that during the topology optimization process, fully consider the scalability and compatibility of the network, reserve space for future network upgrades and transformations, and ensure that the entire network system can operate stably and efficiently in the long term after the transformation.
[0044] S3: Back up business data and restore the backup data in case of abnormalities.
[0045] Furthermore, backing up business data includes during the transformation and cut - over process.
[0046] It should be noted that comprehensively back up business data, store the backup data in different external hard drives respectively to prevent data loss caused by a single storage medium failure. After the device cut - over is completed, if the data is abnormal or lost, use the backup data for restoration to carry out power plant business normally.
[0047] Embodiment 2
[0048] An embodiment of the present invention provides a method for the transformation and cutover of secondary security protection and dispatching data network equipment in a power plant. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0049] The experiment was carried out in the centralized control center of a large hydropower plant. A batch of typical dispatching data network equipment was selected as the research object, including switches, longitudinal encryption devices, dispatching data servers, etc. At the same time, the traditional cutover method was set as the control group. The experimental environment included the dispatching data network in the centralized control center, which adopted a dual-redundant channel, A-channel and B-channel structure, and also included old equipment models A1, B1, C1 and new equipment models A2, B2, C2.
[0050] In the preprocessing stage, data backup of existing equipment was carried out to ensure data recoverability during the cutover process. The current network structure was drawn through an intelligent topology monitoring system, and the key service traffic conditions were recorded. The compatibility between new and old equipment was evaluated, and a protocol conversion plan was formulated for incompatible parts. In the cutover implementation stage, the method of the present invention was used for gradual cutover. Part of the non-critical service traffic was switched to the B-channel for operation, and data consistency detection was carried out. Equipment was gradually migrated. After each piece of equipment was cut over, the data transmission quality, service continuity and security policy consistency were verified in real time. After the cutover was completed, the redundant channel switching technology was used to ensure that there was no obvious service interruption when finally switching to the new A-channel and B-channel structure. During the cutover process, the connection of a certain key equipment was deliberately disconnected to test the emergency response system and observe whether the intelligent load balancing system could automatically adjust the service flow direction to ensure that the service was not interrupted. The data integrity was verified through the data recovery strategy, and the system logs were checked to analyze the recovery time and recovery accuracy rate. Key indicators such as equipment response time, data packet loss rate, and service recovery time during the cutover process were recorded to compare the performance differences of different methods.
[0051] As shown in Table 1, the method of the present invention optimizes the dispatching order of service traffic and introduces intelligent load balancing technology, reducing the service interruption time to 7-12 seconds and improving the continuity of the power plant dispatching system. The method of the present invention carries out data migration and traffic optimization in advance, reducing the data packet loss rate to 0.3%-0.8% and ensuring the integrity and accuracy of dispatching data. The method of the present invention uses protocol conversion and intelligent topology monitoring technology, and no compatibility problems were found during the experiment, ensuring seamless docking of equipment. The method of the present invention adopts an intelligent recovery mechanism and can complete service recovery within 40-55 seconds, while the fault recovery time is shortened to 45 seconds, reducing production losses caused by sudden failures. Under the method of the present invention, the data integrity recovery rate is 99.5%-99.8%, ensuring the reliability of dispatching data and improving the security of the system. The method of the present invention uses intelligent monitoring and automatic recovery mechanisms to shorten the emergency response time to 12-15 seconds, ensuring that the service resumes normal operation in the shortest time.
[0052] Table 1 Experimental Data Sheet
[0053]
[0054] Example 3
[0055] Reference Figure 2 As an embodiment of the present invention, a system for the transformation and cutover of secondary security protection and dispatching data network equipment in a power plant is provided, including: a channel cutover module, a verification and configuration module, and a data backup module.
[0056] Among them, the channel cutover module is used to switch various services between different channels according to channel redundancy and perform cutover on the centralized control side channels; the verification and configuration module is used to verify the policies of the equipment, configure and connect the equipment based on the topological structure; the data backup module is used to back up the service data and restore the backup data in case of abnormal situations.
[0057] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that makes contributions to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0058] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or in combination with these instruction execution systems, apparatus, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.
[0059] More specific examples (a non-exhaustive list) of computer-readable media include the following: electrical connections (electronic devices) having one or more wirings, portable computer diskettes (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber devices, and portable compact disc read-only memory (CDROM). Additionally, the computer-readable media can even be paper or other suitable media on which a program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, then editing, interpreting, or otherwise processing it as appropriate, and then storing it in a computer memory.
[0060] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc. It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
[0061] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.
Claims
1. A method for the transformation and cutover of secondary security protection and dispatching data network equipment in a power plant, characterized in that, Including: Switch various services between different channels according to channel redundancy, and cut over the channels on the centralized control side; Conduct policy verification on devices, and configure and connect devices based on the topological structure; Back up service data and restore the backup data in case of anomalies.
2. The method for reforming and cut-over of the secondary security protection and dispatching data network equipment of a power plant according to claim 1, characterized in that: The switching of various services between different channels according to channel redundancy includes switching various services between different channels according to the channel redundancy in the secondary security protection on the centralized control side and the dispatching data network, and real-time monitoring of service data traffic through an adaptive algorithm. When the channel service traffic approaches the preset upper limit, automatically switch the service to a channel with a load lower than the preset load. Combine the dynamic adjustment of the channel switching priority mechanism with network fault prediction and real-time traffic monitoring. When it is predicted that a channel will have a fault or traffic overload, automatically switch the service to a normal channel according to the preset priority policy, and the priority is dynamically adjusted according to the real-time traffic. When the channel traffic surges during the cutover, temporarily increase the channel switching priority of channels other than the current channel.
3. The method for reforming and cut-over of the secondary security protection and dispatching data network equipment of a power plant according to claim 2, characterized in that: The cutover of the channels on the centralized control side includes cutting over channels A and B in Zone 1 and Zone 2 on the centralized control side. When cutting over channel A, switch the monitoring system service to run on channel B, disconnect the network cable between the switch A in Zone 1 on the centralized control side and the centralized control communication machine, observe the monitoring system service, and if it is abnormal, restore and troubleshoot. After confirming that channel B is transmitting normally, power off the longitudinal encryption device A in Zone 1, remove it and move it to the preset position, connect the power supply and network cable, power on and check whether the policy is normal, lay a new network cable according to the topological diagram to connect the switch B in Zone 1 on the centralized control side and the centralized control communication machine, replace the original network cable and check the connection, switch the electric energy service and the network order issuing system service to run on channel B, perform the same operation on the longitudinal encryption device B in Zone 2, lay network cables from the switch C in Zone 2 on the centralized control side to access the electric energy acquisition device and the centralized control order receiving system terminal respectively to replace the original network cable, and then lay a network cable from the dispatching switch C in Zone 1 on the centralized control side to access the ZTE SDH385 to replace the original network cable, and check whether the service transmission is normal; When cutting over channel B, switch the monitoring system service to run on channel A, disconnect the network cable between the switch D in Zone 1 on the centralized control side and the centralized control communication machine, observe the monitoring system service, and if it is abnormal, restore and troubleshoot. After confirming that channel A is transmitting normally, power off the longitudinal encryption device C in Zone 1, remove it and move it to the preset position, connect the power supply and network cable, power on and check whether the policy is normal, lay a new network cable according to the topological diagram to connect the switch E in Zone 1 on the centralized control side and the centralized control communication machine, replace the original network cable and check the connection, switch the electric energy service and the network order issuing system service to run on channel A, perform the same operation on the longitudinal encryption device D in Zone 2, lay network cables from the switch F in Zone 2 on the centralized control side to access the electric energy acquisition device and the centralized control order receiving system terminal respectively to replace the original network cable, and then lay a network cable from the dispatching switch F in Zone 1 on the centralized control side to access the ZTE SDH385 to replace the original network cable, and check whether the service transmission is normal.
4. The method for reforming and cut-over of the secondary security protection and dispatching data network equipment of a power plant according to claim 3, characterized in that: The policy verification of the device includes logging in to the vertical encryption device A in Area 1 through the device management interface, comparing the consistency of the current configured policy with the backup policy before power outage, switching the monitoring system service to run on Channel B, then observing the service data sent by the monitoring system to the centralized control center, checking the data transmission rate and packet loss rate indicators, and at the same time comparing the integrity and accuracy of the service data to confirm that it is consistent with the data under normal operation. Use the ping command or network connectivity test tool to perform a connectivity test between the vertical encryption device A in Area 1 and the device. If all the detection and verification pass, the device migration and configuration operation is successful. If the verification fails, the system will immediately automatically restore to the original state, and at the same time generate an error report, record the links and data where the verification fails, locate the problem according to the error report and perform targeted repairs. After the repairs are completed, perform the detection and verification again until all the detection and verification pass.
5. The method for reforming and cut-over of secondary security protection and dispatching data network equipment in a power plant according to claim 4, wherein: The device configuration and connection based on the topological structure includes performing device configuration and connection operations according to the transformed topological diagram of the secondary security protection network of the power plant centralized control, arranging the cutover sequence of the devices to avoid network failures and service interruptions caused by incorrect device connections or improper configurations. When deploying new devices, laying network cables, and connecting devices, use the intelligent topological monitoring system to monitor the network topological status in real time. The system uses the network discovery protocol and the link layer discovery protocol to automatically identify the devices and connection relationships in the network, and compare them with the preset topological diagram. If it is found that there are differences between the actual topology and the preset topological diagram, the system immediately issues an alarm and displays the difference points through a visual interface to locate the problem.
6. The method for reforming and cut-over of the secondary security protection and dispatching data network equipment of a power plant as described in claim 5, characterized in that: The device configuration and connection based on the topological structure also includes regularly evaluating and optimizing the network topology based on the data collected by the intelligent topology monitoring. By analyzing the network traffic distribution, device load conditions, and link utilization rate indicators, potential network bottlenecks and performance shortboards are found. If it is monitored that the link continuously shows a high load situation during the peak power consumption period, resulting in an increase in data transmission delay, adjust it through topology optimization, re-plan the data flow direction, allocate the service traffic to the idle link or upgrade the high-load device to improve the device processing capacity, and actively make adaptive adjustments to the network topology as the network service develops and changes. According to the requirements of the new service, add or adjust device connections to enable the new service to access the network.
7. The method for reforming and cut-over of the secondary security protection and dispatching data network equipment of a power plant according to claim 6, characterized in that: The backup of the service data includes comprehensively backing up the service data during the transformation cutover process, storing the backup data in different external hard drives respectively to prevent data loss caused by a single storage medium failure. After the device cutover is completed, if the data is abnormal or lost, use the backup data for recovery to carry out the power plant business normally.
8. A system adopting the power plant secondary security protection and dispatching data network equipment transformation and cutover method as described in any one of claims 1 to 7, characterized in that: It includes a channel cutover module, a verification and configuration module, and a data backup module; The channel cutover module is used to switch various services between different channels according to channel redundancy and perform cutover on the centralized control side channels; The verification and configuration module is used to perform policy verification on the device and perform device configuration and connection based on the topological structure; The data backup module is used to back up the service data and restore the backup data in case of abnormalities.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method for transforming and cut-over of the secondary security protection and dispatching data network equipment of the power plant described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method for transforming and cut-over of the secondary security protection and dispatching data network equipment of the power plant described in any one of claims 1 to 7 are implemented.