Power system information secure transmission method, device, equipment and medium

The hashing algorithm and asymmetric encryption generate digital signatures, combined with transmission behavior model and physical fingerprint verification, multi-level secure transmission of power system information is realized, solving the problem that power system information is prone to tampering and intercepting, and improving the security of the system.

CN120358025AActive Publication Date: 2025-07-22STATE GRID ZHEJIANG ELECTRIC POWER CO LTD NINGBO POWER SUPPLY CO
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510831289.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-07-22
Estimated Expiration
2045-06-20

AI Technical Summary

Technical Problem

Information transmission in power systems is relatively low in security and is susceptible to tampering and interception.

Method used

The hashing algorithm is used to generate digest identifiers without symmetric encryption, and a digital encryption signature is generated, combining transmission behavior model and physical fingerprint verification to perform multi-level security verification.

Benefits of technology

Effectively prevent information from being tampered with forged identity, reduce the risk of interception and tampering, and improve the security of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358025A_ABST
    Figure CN120358025A_ABST
Patent Text Reader

Abstract

The invention provides a power system information security transmission method, device, equipment and medium, and relates to the technical field of information security transmission, the method comprises the following steps: generating a digital encryption signature by using a Hash algorithm and asymmetric encryption; obtaining and locking a receiving file of a receiving end, decrypting the digital encryption signature, generating a receiving abstract identifier, and comparing the original abstract identifier with the receiving abstract identifier to generate an identifier security verification result; when the identification security verification result is secure, acquiring communication data between a sending end and a receiving end corresponding to the to-be-transmitted information, inputting the communication data into a trained transmission behavior model, and generating an information security probability; and when the information security probability is greater than or equal to a preset probability threshold, respectively collecting an actual physical fingerprint and an auxiliary physical fingerprint, determining a physical similarity, and when the physical similarity is greater than or equal to a preset similarity threshold, generating an information transmission normal report, and unlocking the received file. According to the invention, the safety can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information security transmission, and in particular, to a method, device, equipment and medium for information security transmission in a power system. Background Art

[0002] There is a wide variety of information to be transmitted in the power system, covering all links from power generation to power consumption. This information is crucial for ensuring the stable operation of the power system, optimizing resource allocation, and rapid response.

[0003] In the related art, data in the power system is usually directly transmitted through public or semi-public networks, and these network environments are relatively open, so the risk of intercepted and tampered information transmitted directly is relatively high, resulting in low security of power system information. Summary of the Invention

[0004] The problem solved by the present invention is how to improve the security of power system information.

[0005] To solve the above problems, the present invention provides a method, device, equipment and medium for information security transmission in a power system.

[0006] In a first aspect, the present invention provides a method for information security transmission in a power system, including: Obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted by using a hash algorithm, and encrypt the original digest identifier with the private key of asymmetric encryption to generate a digital encryption signature; Package and encapsulate the information to be transmitted and the digital encryption signature, and send them to the receiving end of the power system; Obtain and lock the received file at the receiving end, decrypt the digital encryption signature with the public key of asymmetric encryption to generate a received digest identifier, compare the original digest identifier and the received digest identifier, verify the security of information transmission, and generate an identifier security verification result; When the identifier security verification result is secure, obtain the communication data between the sending end corresponding to the information to be transmitted and the receiving end, input the communication data into the trained transmission behavior model to generate an information security probability; When the information security probability is greater than or equal to a preset probability threshold, respectively collect the actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint, and when the physical similarity is greater than or equal to a preset similarity threshold, generate an information transmission normal report and unlock the received file; When the identification security verification result is abnormal, or the information security probability is less than a preset probability threshold, or the physical similarity is less than a preset similarity threshold, an information transmission abnormality report is generated.

[0007] Optionally, the communication data includes data frequency data, traffic pattern data, communication path data, protocol type data, and delay fluctuation data; The trained transmission behavior model includes an input processing layer, a multi-layer GCN network, a time series network, a fusion layer, and an output layer; The input processing layer is used to classify the data frequency data, the traffic pattern data, the communication path data, the protocol type data, and the delay fluctuation data into graph data and non-graph data; The multi-layer GCN network extracts node representations corresponding to the graph data based on an attention mechanism; The time series network is used to extract time series features corresponding to the non-graph data; The fusion layer is used to fuse all the node representations and the time series features to generate fusion features; The output layer is used to generate the information security probability according to the fusion features by using an activation function.

[0008] Optionally, the time series network includes a dynamic time step embedding unit, a multi-scale convolutional attention unit, an adaptive sparse memory enhanced Transformer, and a state-aware gated recurrent unit; The dynamic time step embedding unit is used to embed the time series features into time intervals by using a position encoding function to generate a time interval embedding vector sequence; The multi-scale convolutional attention unit is used to perform local correlation extraction and attention weighting on the time interval embedding vector sequence at multiple time granularities to generate enhanced local attention features; The adaptive sparse memory enhanced Transformer is used to fuse an external memory matrix into the enhanced local attention features to generate memory-enhanced attention features; The state-aware gated recurrent unit is used to capture the long-term dependence relationship of the memory-enhanced attention features based on a state-aware mechanism to generate the time series features.

[0009] Optionally, the fusion layer includes a heterogeneous information network unit, a projection transformation unit, and a deep neural decision forest unit; The heterogeneous information network unit is used to capture the semantic relationship between all the node representations and the time series features to generate a semantic relationship embedding vector; The projection transformation unit is used to project the semantic relation embedding vector, all the node representations, and the time series features into the same latent space, and perform a linear transformation to generate a preliminary fusion feature; The deep neural decision forest unit is used to further refine the preliminary fusion feature based on the hierarchical characteristics of the decision tree to generate the fusion feature.

[0010] Optionally, determining the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint includes: Constructing an actual spatial intensity map of the actual physical fingerprint and an auxiliary spatial intensity map of the auxiliary physical fingerprint respectively; Mapping the actual spatial intensity map and the auxiliary spatial intensity map into a low-dimensional space respectively, and using the kernel density estimation method to construct the actual probability distribution feature of the actual spatial intensity map in the low-dimensional space and the auxiliary probability distribution feature of the auxiliary spatial intensity map in the low-dimensional space respectively; Generating the physical similarity according to the actual probability distribution feature and the auxiliary probability distribution feature.

[0011] Optionally, generating the physical similarity according to the actual probability distribution feature and the auxiliary probability distribution feature includes: Generating the physical similarity according to the actual probability distribution feature and the auxiliary probability distribution feature by using a physical similarity formula and an interference function, where the physical similarity formula includes: ; where S is the physical similarity, F real is the actual probability distribution feature, F aux is the auxiliary probability distribution feature, is a scaling factor, D is the interference function, is an enhancement non-linear discrimination ability factor.

[0012] Optionally, after generating the information transmission anomaly report, it further includes: Disconnecting the communication connection between the sending end and the receiving end, and deleting the received file.

[0013] In a second aspect, the present invention provides a power system information security transmission device, including: An encryption module, configured to obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted by using a hash algorithm, and encrypt the original digest identifier by using the private key of the asymmetric encryption to generate a digital encryption signature; A packaging module, configured to package and encapsulate the information to be transmitted and the digital encryption signature, and send the packaged result to the receiving end of the power system; A decryption module, configured to obtain and lock the received file at the receiving end, decrypt the digital encryption signature using the public key of asymmetric encryption to generate a received digest identifier, compare the original digest identifier and the received digest identifier, verify the security of information transmission, and generate an identifier security verification result; A probability module, configured to, when the identifier security verification result is secure, obtain the communication data between the sending end and the receiving end corresponding to the information to be transmitted, input the communication data into the trained transmission behavior model, and generate an information security probability; A similarity module, configured to, when the information security probability is greater than or equal to a preset probability threshold, respectively collect the actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint, and when the physical similarity is greater than or equal to a preset similarity threshold, generate a normal information transmission report and unlock the received file; A result module, configured to, when the identifier security verification result is abnormal, or the information security probability is less than the preset probability threshold, or the physical similarity is less than the preset similarity threshold, generate an abnormal information transmission report.

[0014] In a third aspect, the present invention provides an electronic device, including a memory and a processor; The memory is configured to store a computer program; The processor is configured to, when executing the computer program, implement the power system information security transmission method as described in the first aspect.

[0015] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the power system information security transmission method as described in the first aspect is implemented.

[0016] The beneficial effects of the power system information security transmission method, device, equipment and medium of the present invention are: Since the digest identifier generated by the hashing algorithm is unique, any tampering with the original information will cause the digest to change. Therefore, by using the hashing algorithm to extract the original digest identifier of the information to be transmitted and encrypting the original digest identifier with the private key of asymmetric encryption to generate a digital encryption signature, the identities of both the sender and the receiver can be verified, effectively preventing a third party from forging identities to tamper with information, reducing the risk of information being intercepted and tampered with, and improving the security of the power system. Then, the information to be transmitted and the digital encryption signature are packaged and sent to the receiving end of the power system. The received file at the receiving end is obtained and locked, and only unlocked after subsequent security verification, further improving the security of the power system. Next, the digital encryption signature is decrypted with the public key of asymmetric encryption to generate a received digest identifier, and the original digest identifier and the received digest identifier are compared to verify the security of information transmission and generate an identifier security verification result, which can make a preliminary judgment on the received data to confirm whether it has been tampered with. When the preliminary judgment result is secure, the communication data is input into the trained transmission behavior model to make a secondary judgment on the communication process between the sender and the receiver to confirm whether there is a possibility of interception and tampering, generate an information security probability, and when the information security probability is greater than or equal to the preset probability threshold, that is, when the second judgment is also normal, a third judgment is made. The actual physical fingerprint of the sender and the auxiliary physical fingerprint of the device homologous to the sender are collected respectively, and the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint is determined to confirm whether the device of the sender is real, avoiding the possibility of a simulated device intercepting and tampering with information. Finally, an accurate information transmission normal report is generated, and the received file confirmed to be secure is unlocked for system use. Through encryption and three progressive layers of verification with different angles in each layer, the present invention can greatly reduce the risk of information being intercepted and tampered with, accurately confirm whether the received information has been tampered with, and finally unlock and use the secure file after three precise verifications, greatly improving the security of the power system. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a schematic flowchart of the power system information security transmission method provided by an embodiment of the present invention; Figure 2 It is a schematic structural diagram of the power system information security transmission device provided by an embodiment of the present invention; Figure 3 It is a schematic structural diagram of the electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following will describe in detail the specific embodiments of the present invention with reference to the accompanying drawings. Although some embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be construed as limited to the embodiments described herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present invention. It should be understood that the drawings and embodiments of the present invention are only for exemplary purposes and are not used to limit the protection scope of the present invention.

[0019] It should be understood that the various steps recorded in the method embodiments of the present invention can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present invention is not limited in this regard.

[0020] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to"; the term "based on" is "at least partially based on"; the term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments"; the term "optionally" means "optional embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present invention are only used to distinguish different devices, modules, or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules, or units.

[0021] It should be noted that the modifications of "one" and "multiple" mentioned in the present invention are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly stated in the context, it should be understood as "one or more".

[0022] The names of the messages or information exchanged between multiple devices in the embodiments of the present invention are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0023] In view of the problems existing in the above related technologies, this embodiment provides a method, device, equipment, and medium for secure transmission of power system information.

[0024] As Figure 1 shown, a method for secure transmission of power system information provided by an embodiment of the present invention includes: Obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted using a hash algorithm, and encrypt the original digest identifier using the private key of asymmetric encryption to generate a digital encrypted signature.

[0025] Specifically, the information to be transmitted in the power system refers to various data and information that need to be exchanged and processed during the operation and management of the power system. For example, telemetry data, remote control instructions, transaction information, maintenance information, etc. These information are crucial for ensuring the safe, stable and efficient operation of the power grid. The original summary identifier is a unique identifier with a fixed length generated by the hash algorithm for input data of any length. For example, SHA-256 will generate a 256-bit hash value. Then, the private key encryption is performed using the RSA tool of the asymmetric encryption algorithm to generate a binary or Base64-encoded digital encryption signature to achieve double encryption for subsequent verification.

[0026] Package and encapsulate the information to be transmitted and the digital encryption signature, and send them to the receiving end of the power system.

[0027] Specifically, package and encapsulate the information to be transmitted and the digital encryption signature. At the same time, a lightweight MAC (Message Authentication Code) can be combined with a timestamp to form an "integrity label" and attach it to the packaged data packet, and then send it to the receiving end of the power system for subsequent integrity and security verification.

[0028] Obtain and lock the received file at the receiving end, decrypt the digital encryption signature using the public key of asymmetric encryption to generate a received summary identifier, and compare the original summary identifier and the received summary identifier to verify the security of information transmission and generate an identifier security verification result.

[0029] Specifically, obtain the received file at the receiving end and lock the received file at the receiving end, and unlock and use the file after successful verification. Decrypt the digital encryption signature using the public key of the RSA tool of the asymmetric encryption algorithm to generate the received summary identifier at the receiving end, and compare the original summary identifier and the received summary identifier, that is, compare all the contents of the original summary identifier and the received summary identifier, such as encoding, format, timestamp, etc., to verify the integrity and security of information transmission, and generate an identifier security verification result for all the contents of the original summary identifier and the received summary identifier. For example, when the encoding of the original summary identifier and the received summary identifier is consistent, the format of the original summary identifier and the received summary identifier is consistent, and the timestamp of the original summary identifier and the received summary identifier is consistent and other contents are exactly the same, the identifier security verification result is secure. When any one of the contents is inconsistent, the identifier security verification result is abnormal.

[0030] When the identifier security verification result is secure, obtain the communication data between the sending end and the receiving end corresponding to the information to be transmitted, and input the communication data into the trained transmission behavior model to generate an information security probability.

[0031] Specifically, when the identified security verification result is secure, obtain the communication data between the sender and the receiver corresponding to the information to be transmitted, input the communication data into the trained transmission behavior model to generate an information security probability, and conduct a second verification. Because, in an ideal situation, if the hash algorithm is secure enough, the key is not leaked, and the system is implemented correctly, the digest decrypted by the public key being exactly the same as the original digest means that the data has not been tampered with. However, in actual work, there are some potential risks that may cause the data to be tampered with even if it seems not to be. For example, the hash algorithm has a collision vulnerability, that is, if an attacker finds two different input data such that their hash values are the same (referred to as a hash collision), then the data can be tampered with and a forged signature can be created; the private key is leaked or misused, that is, if an attacker steals the private key of the sender signer, then the signature of any data can be forged. Therefore, use the trained transmission behavior model to verify the communication data between the sender and the receiver again to determine whether there are abnormal behaviors during the communication process, such as intercepting and tampering with data, etc. The transmission behavior model can adopt the combination of a neural network and a time series model to deeply analyze the characteristics and time series relationships between data. The transmission behavior model can be trained with historical secure communication data to obtain the trained transmission behavior model to analyze the current data and generate an information security probability.

[0032] When the information security probability is greater than or equal to the preset probability threshold, respectively collect the actual physical fingerprint of the sender and the auxiliary physical fingerprint of the device homologous to the sender, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint. When the physical similarity is greater than or equal to the preset similarity threshold, generate an information transmission normal report and unlock the received file.

[0033] Specifically, the preset probability threshold can be set according to the actual situation. For example, 95%. The preset similarity threshold can be set according to the actual situation. For example, 96%. The homologous device refers to a device of the same model, the same size, and a similar running time as the transmitting device. The physical fingerprint refers to the unique real-time operating parameters of the power system device. For example, the on-off coil current waveform, the power frequency harmonic component, and the shaft system torsional vibration frequency waveform, etc. When the information security probability is greater than or equal to the preset probability threshold, it means that the transmission behavior model has not detected any abnormal behaviors during the communication process. However, at this time, there may still be vulnerabilities. For example, an attacker uses a fake transmitting device, a simulated transmitting device, or invades the transmitting device to send information to spread tampered information. Therefore, respectively collect the actual physical fingerprint of the sender and the auxiliary physical fingerprint of the device homologous to the sender, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint. When the physical similarity is greater than or equal to the preset similarity threshold, determine that the device of the sender is real and not invaded, thereby proving the security of the received information, generate an information transmission normal report, and unlock the received file for use.

[0034] When the identification security verification result is abnormal, or the information security probability is less than a preset probability threshold, or the physical similarity is less than a preset similarity threshold, an information transmission abnormality report is generated.

[0035] Specifically, when the identification security verification result is abnormal, or the information security probability is less than a preset probability threshold, or the physical similarity is less than a preset similarity threshold, it indicates that there is an abnormality in data transmission, and an information transmission abnormality report is generated.

[0036] In this embodiment, since the digest identification generated by the hash algorithm is unique, any tampering with the original information will cause the digest to change. Therefore, by using the hash algorithm to extract the original digest identification of the information to be transmitted, and using the private key of asymmetric encryption to encrypt the original digest identification to generate a digital encryption signature, the identities of both the sending end and the receiving end can be verified, effectively preventing a third party from forging identities to tamper with information, reducing the risk of information being intercepted and tampered with, and improving the security of the power system. Then, the information to be transmitted and the digital encryption signature are packaged and sent to the receiving end of the power system. Then, the received file of the receiving end is obtained and locked, and it is only unlocked after subsequent security verification, further improving the security of the power system. Next, the digital encryption signature is decrypted using the public key of asymmetric encryption to generate a received digest identification, and the original digest identification and the received digest identification are compared to verify the security of information transmission and generate an identification security verification result, which can make a preliminary judgment on the received data to confirm whether it has been tampered with. When the preliminary judgment result is secure, the communication data is input into the trained transmission behavior model to make a secondary judgment on the communication process between the sending end and the receiving end to confirm whether there is a possibility of interception and tampering, generate an information security probability, and when the information security probability is greater than or equal to the preset probability threshold, that is, when the second judgment is also normal, a third judgment is made. The actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end are respectively collected to determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint to confirm whether the device at the sending end is real, avoiding the possibility of a simulated device intercepting and tampering with information, and finally generating an accurate information transmission normal report and unlocking the received file confirmed to be secure for system use. Through encryption and three-layer progressive verification with different angles for each layer, the present invention can greatly reduce the risk of information being intercepted and tampered with, accurately confirm whether the received information has been tampered with, and finally unlock and use the secure file after three-layer precise verification, greatly improving the security of the power system.

[0037] Optionally, the communication data includes data frequency data, traffic pattern data, communication path data, protocol type data, and delay fluctuation data; The trained transmission behavior model includes an input processing layer, a multi-layer GCN network, a time series network, a fusion layer, and an output layer; The input processing layer is used to classify the data frequency data, the traffic pattern data, the communication path data, the protocol type data, and the delay fluctuation data into graph data and non-graph data; Multiple layers of the GCN network extract node representations corresponding to the graph data based on the attention mechanism; The time series network is used to extract time series features corresponding to the non-graph data; The fusion layer is used to fuse all the node representations and the time series features to generate fusion features; The output layer is used to generate the information security probability by using an activation function according to the fusion features.

[0038] Specifically, the communication data includes data frequency data, traffic pattern data, communication path data, protocol type data, and delay fluctuation data. Among them, the communication path data is graph data, and the data frequency data, traffic pattern data, protocol type data, and delay fluctuation data are non-graph data. The trained transmission behavior model includes an input processing layer, multiple layers of GCN network, time series network, fusion layer, and output layer connected in sequence. The input processing layer is used to classify the data frequency data, traffic pattern data, communication path data, protocol type data, and delay fluctuation data into graph data and non-graph data, and perform standardization and normalization processing to obtain standardized and unified graph data and non-graph data. Multiple layers of GCN network use multiple layers of GCN to capture the relationships between nodes at different depths, and through the attention mechanism, allow the model to dynamically focus on different nodes or edges, improve the sensitivity to key information, and thus extract node representations corresponding to the graph data. The time series network is used to extract time series features corresponding to the non-graph data. The fusion layer is used to fuse all the node representations and time series features to generate fusion features. The output layer generates the information security probability according to the fusion features by outputting the security probability of the current communication data through a series of fully connected layers plus the Softmax activation function.

[0039] Optionally, the time series network includes a dynamic time step embedding unit, a multi-scale convolutional attention unit, an adaptive sparse memory enhanced Transformer, and a state-aware gated recurrent unit; The dynamic time step embedding unit is used to embed the time series features into time intervals by using a position encoding function to generate a sequence of time interval embedding vectors; The multi-scale convolutional attention unit is used to perform local correlation extraction and attention weighting on the sequence of time interval embedding vectors at multiple time granularities to generate enhanced local attention features; The adaptive sparse memory enhanced Transformer is used to fuse an external memory matrix into the enhanced local attention features to generate memory enhanced attention features; The state-aware gated recurrent unit is used to capture the long-term dependencies of the memory-enhanced attention features based on the state-aware mechanism and generate the time series features.

[0040] Specifically, the time series network includes a dynamically-sized time step embedding unit, a multi-scale convolutional attention unit, an adaptive sparse memory-enhanced Transformer, and a state-aware gated recurrent unit connected in sequence. The dynamically-sized time step embedding unit is used to encode the irregular time intervals into vector representations using a positional encoding function and embed the time series features into the time intervals to help the model understand the relative time distances between events, generating a sequence of time interval embedding vectors. The multi-scale convolutional attention unit is used to perform local correlation extraction and attention weighting on the sequence of time interval embedding vectors at multiple time granularities, that is, to extract local correlations and perform attention weighting at multiple time granularities. Among them, the multi-scale convolutional attention unit parallelly uses multiple one-dimensional convolutional kernels (such as kernel_size = [3, 5, 7]) to extract local features. After each convolutional layer, LayerNorm and ReLU are connected, and then the outputs of each convolution are concatenated and compressed to a unified dimension through a linear transformation, and then the multi-head attention mechanism is applied to capture cross-scale context dependencies, generating enhanced local attention features. The adaptive sparse memory-enhanced Transformer adds a long-term memory mechanism on the basis of the traditional Transformer to improve the model's ability to model long-term dependencies, and introduces an external memory matrix. In each Transformer block, the current enhanced local attention features are calculated for similarity with the memory bank, the most relevant memory segments are selected, and the most relevant memory segments are fused with the enhanced local attention features to generate memory-enhanced attention features with long-term memory enhancement. The state-aware gated recurrent unit further captures the long-term dependencies in the sequence and introduces a state-aware mechanism to enhance the model's sensitivity to abnormal behaviors, generating time series features. Among them, the state-aware gated recurrent unit first obtains the preliminary sequence hidden state through a bidirectional gated recurrent unit, and then inputs the result into the state-aware LSTM model (State-Aware LSTM). The state-aware LSTM model adjusts the activation thresholds of the forget gate and the input gate according to the state change in the previous step, and defines a state change detection function, such as Euclidean distance or cosine similarity, to dynamically adjust the gating mechanism, and finally generates time series features.

[0041] Optionally, the fusion layer includes a heterogeneous information network unit, a projection transformation unit, and a deep neural decision forest unit; The heterogeneous information network unit is used to capture the semantic relationships between all the node representations and the time series features and generate semantic relationship embedding vectors; The projection transformation unit is used to project the semantic relationship embedding vector, all the node representations, and the time series features into the same latent space, and perform a linear transformation to generate a preliminary fusion feature; The deep neural decision forest unit is used to further refine the preliminary fusion feature based on the hierarchical characteristics of the decision tree to generate the fusion feature.

[0042] Specifically, the fusion layer includes a heterogeneous information network unit, a projection transformation unit, and a deep neural decision forest unit connected in sequence. The heterogeneous information network (HIN) unit can model different types of nodes (such as users, items, locations, etc.) and edges (such as friendship relationships, access records, etc.). For communication data, this may mean being able to better understand the relevance between different communication patterns. For example, how data of a certain protocol type affects the traffic pattern on a specific path. The heterogeneous information network unit can capture the complex semantic relationships between these different types of entities, that is, between all the node representations and the time series features, through the learned embedding vector, enhance the model's understanding ability of different data sources, improve the robustness and accuracy of the overall system, and generate a semantic relationship embedding vector. The projection transformation unit is used to project the semantic relationship embedding vector, all the node representations, and the time series features into the same latent space, and perform a linear transformation to generate a preliminary fusion feature. The deep neural decision forest unit is used to further refine the preliminary fusion feature based on the hierarchical characteristics of the decision tree. The preliminary fusion feature is used as input to train a series of decision trees, and each tree is split based on different subset features. For each sample data of the decision tree, record its path in all the trees and convert it into a binary coding form to form a new feature representation, that is, generate the fusion feature.

[0043] Optionally, determining the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint includes: Construct the actual spatial intensity map of the actual physical fingerprint and the auxiliary spatial intensity map of the auxiliary physical fingerprint respectively; Map the actual spatial intensity map and the auxiliary spatial intensity map to a low-dimensional space respectively, and use the kernel density estimation method to construct the actual probability distribution feature of the actual spatial intensity map in the low-dimensional space and the auxiliary probability distribution feature of the auxiliary spatial intensity map in the low-dimensional space respectively; Generate the physical similarity according to the actual probability distribution feature and the auxiliary probability distribution feature.

[0044] Specifically, each sampling point in the physical fingerprint is used as a node of the actual spatial intensity map. The sampling point is a specific data point extracted from the physical fingerprint, which can reflect the working characteristics of the device at that moment. When the physical fingerprint includes the closing and opening coil current waveforms, power frequency harmonic components, and shaft torsional vibration frequency waveforms, the closing and opening coil current waveforms, power frequency harmonic components, and shaft torsional vibration frequency waveforms are first time-aligned and then sampled to obtain sampling points in a unified time series. First, determine the connection distance between the nodes. The connection distance refers to the distance in time between two nodes. Then, determine the signal difference between the nodes. The signal difference refers to the difference between the signal characteristics represented by two nodes. The Euclidean distance can be used to measure this difference. The combined result of the connection distance and the signal difference between the sampling points is set as the edge weight. Among them, the weighted method can be used to calculate the combined result of the connection distance and the signal difference. Then, based on the nodes and the edge weights, construct the spatial intensity map, that is, if the edge weight between two nodes is less than the preset edge threshold, an edge is constructed between these two nodes. In this way, judgments and edge constructions are performed between each pair of nodes until all nodes have been judged, and the spatial intensity map is obtained. Therefore, based on this step, the actual spatial intensity map can be constructed according to the nodes and edge weights of the actual physical fingerprint, and the auxiliary spatial intensity map can be constructed according to the nodes and edge weights of the auxiliary physical fingerprint. Then, using Laplacian eigenmaps, the actual spatial intensity map and the auxiliary spatial intensity map are respectively mapped to a low-dimensional space, and the kernel density estimation method is used to respectively construct the actual probability distribution characteristics of the actual spatial intensity map in the low-dimensional space and the auxiliary probability distribution characteristics of the auxiliary spatial intensity map in the low-dimensional space. The actual probability distribution characteristics and the auxiliary probability distribution characteristics express the distribution characteristics of the actual physical fingerprint and the auxiliary physical fingerprint in the low-dimensional space. Therefore, according to the actual probability distribution characteristics and the auxiliary probability distribution characteristics, the physical similarity can be determined.

[0045] Optionally, generating the physical similarity according to the actual probability distribution characteristics and the auxiliary probability distribution characteristics includes: According to the actual probability distribution characteristics and the auxiliary probability distribution characteristics, using the physical similarity formula and the interference function to generate the physical similarity, where the physical similarity formula includes: ; where S is the physical similarity, F real is the actual probability distribution characteristic, F aux is the auxiliary probability distribution characteristic, is the scaling factor, D is the interference function, is the factor to enhance the non-linear discrimination ability.

[0046] Specifically, a interference function is set in the physical similarity formula to simulate the interference of environmental changes on signals, so as to increase the accuracy of the technology. The enhanced non-linear discrimination ability factor can enhance the non-linear discrimination ability, making small differences amplified when calculating the similarity score, thereby improving the sensitivity to subtle differences and generating an accurate physical similarity.

[0047] Optionally, after generating the information transmission anomaly report, it further includes: Disconnect the communication connection between the sending end and the receiving end, and delete the received file.

[0048] Specifically, in case of an anomaly, in order to prevent the intercepted and tampered file from causing further harm, the communication connection between the sending end and the receiving end is disconnected, and the received file is deleted to ensure the safety of the power system.

[0049] As Figure 2 shown, a power system information security transmission device provided by an embodiment of the present invention includes: An encryption module, configured to obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted by using a hash algorithm, and encrypt the original digest identifier by using the private key of asymmetric encryption to generate a digital encryption signature; A packaging module, configured to package and encapsulate the information to be transmitted and the digital encryption signature, and send them to the receiving end of the power system; A decryption module, configured to obtain and lock the received file at the receiving end, decrypt the digital encryption signature by using the public key of asymmetric encryption to generate a received digest identifier, and compare the original digest identifier and the received digest identifier to verify the security of information transmission and generate an identifier security verification result; A probability module, configured to, when the identifier security verification result is secure, obtain the communication data between the sending end corresponding to the information to be transmitted and the receiving end, input the communication data into the trained transmission behavior model to generate an information security probability; A similarity module, configured to, when the information security probability is greater than or equal to a preset probability threshold, respectively collect the actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint, and when the physical similarity is greater than or equal to a preset similarity threshold, generate an information transmission normal report and unlock the received file; A result module, configured to generate an information transmission anomaly report when the identifier security verification result is abnormal, or the information security probability is less than the preset probability threshold, or the physical similarity is less than the preset similarity threshold.

[0050] As Figure 3As shown in the figure, an electronic device 300 provided by an embodiment of the present invention includes a memory 310 and a processor 320; the memory 310 is used to store a computer program; the processor 320 is used to implement the power system information security transmission method as described above when executing the computer program.

[0051] Or, an electronic device 300 includes a memory 310 and a processor 320 coupled to the memory 310; the memory 310 is configured to store a computer program; the processor 320 is configured to perform the following operations when executing the computer program: Obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted by using a hash algorithm, and encrypt the original digest identifier with the private key of asymmetric encryption to generate a digital encryption signature; Package and encapsulate the information to be transmitted and the digital encryption signature, and send them to the receiving end of the power system; Obtain and lock the received file at the receiving end, decrypt the digital encryption signature with the public key of asymmetric encryption to generate a received digest identifier, compare the original digest identifier and the received digest identifier, verify the security of information transmission, and generate an identifier security verification result; When the identifier security verification result is secure, obtain the communication data between the sending end and the receiving end corresponding to the information to be transmitted, input the communication data into the trained transmission behavior model, and generate an information security probability; When the information security probability is greater than or equal to a preset probability threshold, respectively collect the actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint, and when the physical similarity is greater than or equal to a preset similarity threshold, generate a normal information transmission report and unlock the received file; When the identifier security verification result is abnormal, or the information security probability is less than the preset probability threshold, or the physical similarity is less than the preset similarity threshold, generate an information transmission abnormal report.

[0052] A computer-readable storage medium provided by an embodiment of the present invention has a computer program stored thereon. When the computer program is executed by a processor, the power system information security transmission method as described above is implemented.

[0053] Or, a non-volatile computer-readable storage medium has a computer program stored thereon. When the computer program is executed by a processor, the processor is made to perform the following operations: Obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted using a hash algorithm, and encrypt the original digest identifier with the private key of asymmetric encryption to generate a digital encryption signature; Package and encapsulate the information to be transmitted and the digital encryption signature, and send them to the receiving end of the power system; Obtain and lock the received file at the receiving end, decrypt the digital encryption signature with the public key of asymmetric encryption to generate a received digest identifier, compare the original digest identifier and the received digest identifier, verify the security of information transmission, and generate an identifier security verification result; When the identifier security verification result is secure, obtain the communication data between the sending end and the receiving end corresponding to the information to be transmitted, input the communication data into the trained transmission behavior model, and generate an information security probability; When the information security probability is greater than or equal to a preset probability threshold, respectively collect the actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint, and when the physical similarity is greater than or equal to a preset similarity threshold, generate a normal information transmission report and unlock the received file; When the identifier security verification result is abnormal, or the information security probability is less than the preset probability threshold, or the physical similarity is less than the preset similarity threshold, generate an information transmission abnormal report.

[0054] Now, an electronic device 300 that can be a server or a client of the present invention will be described. It is an example of a hardware device that can be applied to various aspects of the present invention. The electronic device 300 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device 300 can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described herein and / or claimed.

[0055] The electronic device 300 includes a computing unit that can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) or a computer program loaded from a storage unit into a random access memory (RAM). In the RAM, various programs and data required for device operation can also be stored. The computing unit, ROM, and RAM are connected to each other through a bus. An input / output (I / O) interface is also connected to the bus.

[0056] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc. In this application, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. One can select some or all of the units according to actual needs to achieve the purpose of the solution of the embodiments of the present invention. In addition, the functional units in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0057] Although the present invention is disclosed as above, the scope of protection of the present invention is not limited thereto. Those skilled in the art can make various changes and modifications without departing from the spirit and scope of the present invention, and these changes and modifications will all fall within the scope of protection of the present invention.

Claims

1. A method for secure transmission of power system information, characterized in that, Including: Obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted using a hash algorithm, and encrypt the original digest identifier using the private key of asymmetric encryption to generate a digital encryption signature; Package and encapsulate the information to be transmitted and the digital encryption signature, and send them to the receiving end of the power system; Obtain and lock the received file at the receiving end, decrypt the digital encryption signature using the public key of asymmetric encryption to generate a received digest identifier, and compare the original digest identifier and the received digest identifier to verify the security of information transmission and generate an identifier security verification result; When the identifier security verification result is secure, obtain the communication data between the sending end and the receiving end corresponding to the information to be transmitted, and input the communication data into the trained transmission behavior model to generate an information security probability; When the information security probability is greater than or equal to a preset probability threshold, respectively collect the actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint, and when the physical similarity is greater than or equal to a preset similarity threshold, generate an information transmission normal report and unlock the received file; When the identifier security verification result is abnormal, or the information security probability is less than the preset probability threshold, or the physical similarity is less than the preset similarity threshold, generate an information transmission abnormal report.

2. The information security transmission method for the power system according to claim 1, characterized in that The communication data includes data frequency data, traffic pattern data, communication path data, protocol type data, and delay fluctuation data; The trained transmission behavior model includes an input processing layer, a multi-layer GCN network, a time series network, a fusion layer, and an output layer; The input processing layer is used to classify the data frequency data, the traffic pattern data, the communication path data, the protocol type data, and the delay fluctuation data into graph data and non-graph data; The multi-layer GCN network extracts the node representation corresponding to the graph data based on the attention mechanism; The time series network is used to extract the time series features corresponding to the non-graph data; The fusion layer is used to fuse all the node representations and the time series features to generate a fusion feature; The output layer is used to generate the information security probability according to the fusion feature using an activation function.

3. The information security transmission method for a power system according to claim 2, wherein The time series network includes a dynamic time step embedding unit, a multi-scale convolutional attention unit, an adaptive sparse memory enhanced Transformer, and a state-aware gated recurrent unit; The dynamic time step embedding unit is used to embed the time series features into the time interval using a position encoding function to generate a time interval embedding vector sequence; The multi-scale convolutional attention unit is used to perform local correlation extraction and attention weighting on the time interval embedding vector sequence at multiple time granularities to generate enhanced local attention features; The adaptive sparse memory enhanced Transformer is used to fuse an external memory matrix into the enhanced local attention features to generate memory-enhanced attention features; The state-aware gated recurrent unit is used to capture the long-term dependencies of the memory-enhanced attention features based on the state-aware mechanism and generate the time series features.

4. The information security transmission method of the power system according to claim 2, characterized in that, The fusion layer includes a heterogeneous information network unit, a projection transformation unit, and a deep neural decision forest unit; The heterogeneous information network unit is used to capture the semantic relationships between all the node representations and the time series features and generate semantic relationship embedding vectors; The projection transformation unit is used to project the semantic relationship embedding vectors, all the node representations, and the time series features into the same latent space, perform a linear transformation, and generate preliminary fusion features; The deep neural decision forest unit is used to further refine the preliminary fusion features based on the hierarchical characteristics of decision trees and generate the fusion features.

5. The information security transmission method of the power system according to claim 1, characterized in that Determining the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint includes: Constructing an actual spatial intensity map of the actual physical fingerprint and an auxiliary spatial intensity map of the auxiliary physical fingerprint respectively; Mapping the actual spatial intensity map and the auxiliary spatial intensity map to a low-dimensional space respectively, and using the kernel density estimation method to construct the actual probability distribution feature of the actual spatial intensity map in the low-dimensional space and the auxiliary probability distribution feature of the auxiliary spatial intensity map in the low-dimensional space respectively; Generating the physical similarity according to the actual probability distribution feature and the auxiliary probability distribution feature.

6. The information security transmission method of the power system according to claim 5, characterized in that The generating the physical similarity according to the actual probability distribution feature and the auxiliary probability distribution feature includes: Generating the physical similarity according to the actual probability distribution feature and the auxiliary probability distribution feature by using a physical similarity formula and an interference function, where the physical similarity formula includes: ; where S is the physical similarity degree, F real is the actual probability distribution feature, F aux is the auxiliary probability distribution feature, is the scaling factor, D is the interference function, is the factor for enhancing the non-linear discrimination ability.

7. The information security transmission method of the power system according to any one of claims 1-6, characterized in that, After generating the information transmission anomaly report, it further includes: Disconnecting the communication connection between the sending end and the receiving end and deleting the received file.

8. An information security transmission device for a power system, characterized in that, It includes: An encryption module, which is used to obtain the information to be transmitted in the power system, extract the original digest identifier of the information to be transmitted by using a hash algorithm, and encrypt the original digest identifier by using the private key of asymmetric encryption to generate a digital encryption signature; A packaging module, which is used to package and encapsulate the information to be transmitted and the digital encryption signature and send them to the receiving end of the power system; A decryption module, which is used to obtain and lock the received file at the receiving end, decrypt the digital encryption signature by using the public key of asymmetric encryption to generate a received digest identifier, compare the original digest identifier and the received digest identifier, verify the security of information transmission, and generate an identifier security verification result; A probability module, which is used to, when the identifier security verification result is secure, obtain the communication data between the sending end corresponding to the information to be transmitted and the receiving end, input the communication data into the trained transmission behavior model, and generate an information security probability; A similarity module, configured to respectively collect the actual physical fingerprint of the sending end and the auxiliary physical fingerprint of the device homologous to the sending end when the information security probability is greater than or equal to a preset probability threshold, determine the physical similarity between the actual physical fingerprint and the auxiliary physical fingerprint, and generate an information transmission normal report and unlock the received file when the physical similarity is greater than or equal to a preset similarity threshold; A result module, configured to generate an information transmission abnormal report when the identity security verification result is abnormal, or the information security probability is less than the preset probability threshold, or the physical similarity is less than the preset similarity threshold.

9. An electronic device, characterized in that, Comprising a memory and a processor; The memory is used for storing a computer program; The processor is configured to implement the power system information security transmission method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the storage medium, and when the computer program is executed by the processor, the power system information security transmission method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Automatic extraction method for electric power internet of things terminal features

    CN117354251A

  • Method and system for synchronizing data between trusted DCS (Distributed Control System) terminals

    CN119155305A

  • Communication method for power asset management master station system and mobile terminal

    CN119966720A

  • Internet of Things information platform and implementation method thereof

    CN120017670A

  • Online platform using voice analysis results

    KR102318642B1