Digital twin-driven power network security situation awareness method

Through the combination of the digital twin model and the power network security event library, data conflict and redundant situation analysis are carried out, and the shortcomings of traditional power network security monitoring methods are solved, real-time security situation awareness and risk identification of the power network are realized, and the security management efficiency of the power network is improved.

CN120358094BActive Publication Date: 2025-08-26STATE GRID JIANGSU ELECTRIC POWER CO LTD NANTONG POWER SUPPLY BRANCH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510846654.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-08-26
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

Traditional power network security monitoring methods cannot adapt to the complex and changeable power system environment, and it is difficult to identify and warn of potential safety risks in a timely manner, affecting the stable operation of the power network.

Method used

By establishing a digital twin model, accessing the power network security event library, obtaining network traffic and user behavior sample data, conducting data conflict situation analysis and redundant situation analysis, identifying potential security risks and issuing early warning signals.

Benefits of technology

Real-time security situation awareness of the power network is realized, and it can timely identify and respond to potential risks, which improves the security management capabilities of the power network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358094B_ABST
    Figure CN120358094B_ABST
Patent Text Reader

Abstract

The present application relates to the field of electric power safety technology, and provides a method for electric power network security situation awareness driven by digital twins. The method includes: setting a digital twin model; accessing an event library and writing multiple security maintenance tasks; mining equipment groups based on maintenance tasks to obtain sample data sets; introducing sample data based on the digital twin model, performing data conflict situation analysis with user behavior samples, and setting a conflict network layer; performing data redundancy situation analysis with network traffic samples, and setting a redundant network layer; based on the maintenance tasks of the event library, coupling the conflict and redundant network layers, identifying security risks and issuing early warning signals. The present application solves the technical problems of untimely and difficult to accurately identify security risks in electric power network security situation awareness, and realizes real-time monitoring of the electric power network security status through a digital twin model, identifying potential risks and issuing early warning signals, thereby improving the accuracy of electric power network security situation awareness and response efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of power engineering technology, specifically to the field of power safety technology, and in particular to a method for power network security situation awareness driven by digital twins. Background Art

[0002] With the increasing scale and complexity of modern power systems, the security and stability of power networks face enormous challenges. Power networks contain a large number of device nodes and communication links, and the operating status of each node is complex and interconnected, making it significantly more difficult to identify and warn of potential security risks in the power network. Traditional power network security monitoring methods typically rely on a single data source or static security rules, are unable to adapt to the complex and changing power system environment, and lack a global understanding of the overall status of the power network. Therefore, traditional security monitoring methods have difficulty in timely detecting and warning of potential security risks, making it difficult for the power system to respond promptly when attacked or malfunctions occur, affecting the stable operation of the power network. Summary of the Invention

[0003] This application provides a digital twin-driven power network security situation awareness method, aiming to solve the technical problems of untimely power network security situation awareness and difficulty in accurately identifying security risks.

[0004] In view of the above problems, this application provides a digital twin-driven power network security situation awareness method.

[0005] The present application provides a digital twin-driven power network security situation awareness method, which includes: setting a digital twin model based on the power grid topology and each power equipment; accessing the power network security event library, where multiple power network security maintenance tasks are written into the power network security event library; performing power equipment group mining based on the first power network security maintenance task among the multiple power network security maintenance tasks to obtain a first sample data set, where the first sample data set includes network traffic sample data and user behavior sample data, and the first power network security maintenance task is any one of the multiple power network security maintenance tasks; based on the digital twin model, introducing the first sample data set, performing data conflict situation analysis with the user behavior sample data, and setting a data conflict network layer; performing data redundancy situation analysis with the network traffic sample data, and setting a data redundancy network layer; based on the multiple power network security maintenance tasks in the power network security event library, coupling the data conflict network layer and the data redundancy network layer to identify potential security risks and issue a security warning signal.

[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0007] The digital twin-driven power network security situational awareness method builds a digital twin model based on the power grid topology and individual power equipment to fully reflect the actual power network operation. Subsequently, the method integrates a power network security event database, which records multiple power network security maintenance tasks, to ensure real-time transmission of security maintenance task information to the digital twin model. Next, based on any specific maintenance task in the event database, data mining is performed on the relevant power equipment to extract sample datasets including network traffic and user behavior. This process ensures accurate status information from multiple dimensions, helping to identify specific security situations related to the task. After the sample data is imported into the digital twin model, data conflict analysis is performed using user behavior sample data to establish a data conflict network layer, thereby identifying potential risks caused by abnormal or inconsistent behavior. Simultaneously, network traffic sample data is used for data redundancy analysis to establish a data redundancy network layer, which helps identify redundancy risks caused by duplicate or abnormal traffic. Based on these two network layers, the data conflict layer and the data redundancy layer are coupled and connected, enabling a comprehensive assessment of potential security risks through correlation analysis. When any abnormal trends or risk signals are detected, an alert will be issued to ensure that security issues can be quickly identified and responded to.

[0008] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0010] Figure 1 1. A schematic flow chart of a method for power network security situation awareness driven by digital twins in one embodiment;

[0011] Figure 2 A schematic diagram of the process of obtaining a first sample data set in a digital twin-driven power network security situation awareness method in one embodiment. DETAILED DESCRIPTION

[0012] The embodiments of the present application solve the technical problems of untimely awareness of power network security situation and difficulty in accurately identifying security risks by providing a digital twin-driven power network security situation awareness method.

[0013] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0014] It should be noted that the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products or devices.

[0015] Examples, such as Figure 1 As shown, the present application provides a digital twin-driven power network security situation awareness method, the method comprising:

[0016] Set up a digital twin model based on the grid topology and various power equipment.

[0017] In this embodiment of the present application, the system terminal collects detailed topological data of the power grid, including the location of each line and node, and the connections between nodes. This topological data typically comes from power network management systems such as GIS (Geographic Information Systems) and SCADA (Supervisory Control and Data Acquisition Systems). Furthermore, the specific location and connection information of power equipment (such as transformers, circuit breakers, and distribution cabinets) in the topology are collected. Subsequently, operational data and physical and electrical characteristics of each power device in the power network are obtained. For example, real-time monitoring data such as voltage, current, power, and temperature, as well as basic information such as the device model, capacity, rated power, and health status, are collected. Sensors and monitoring devices collect this data using IoT technology and aggregate it into the system terminal to ensure real-time and accurate data. Based on the collected topological data and device data, a digital twin model is then constructed using 3D modeling software or a digital twin platform. The model maps the actual power grid structure to the locations of power equipment, ensuring that the digital twin model accurately reflects the physical structure and connections of the actual power grid. This model not only includes the physical location and connection relationships of each device, but also records the status parameters and operating status of each device. Through this digital twin model, the system terminal can monitor the overall operating status of the power network and the status changes of each device in real time, providing basic data for subsequent risk detection.

[0018] Accessing a power network security event library, wherein a plurality of power network security maintenance tasks are written into the power network security event library.

[0019] In one embodiment, the system terminal accesses a power network security event library. This library is an information repository dedicated to storing and managing power network security events, risk records, and maintenance tasks. Multiple power network security maintenance tasks are written into it to support security situation awareness and risk management of the power network. By accessing the event library, detailed information about historical events and current maintenance tasks on the power network can be obtained. These tasks include possible network security events, risk handling requirements, and equipment status checks. Each task contains information such as the target device for the task and the task processing method. The security maintenance task information stored in the power network security event library provides a basis for subsequent situation analysis, enabling the system terminal to call on this task data, timely understand the potential risks and security maintenance needs of the power network, and thus more efficiently carry out security monitoring and early warning management of the power network.

[0020] Based on the first power network security maintenance task among the multiple power network security maintenance tasks, power equipment group mining is performed to obtain a first sample data set, wherein the first sample data set includes network traffic sample data and user behavior sample data, and the first power network security maintenance task is any one of the multiple power network security maintenance tasks.

[0021] In one embodiment, the system terminal randomly selects a power network security maintenance task from multiple power network security maintenance tasks stored in the power network security event library as the first power network security maintenance task, and based on this task, combines the constructed digital twin model to perform correlation analysis and mining on the power equipment group, identifies the power equipment related to the task, so as to better focus on the key equipment and data required for the task, and obtains the network traffic sample data and user behavior sample data of these power equipment to form a first sample data set, providing a basis for further security situation analysis. Among them, the network traffic sample data can reflect the communication mode and data transmission situation between power equipment, and the user behavior sample data is helpful in analyzing the user's access and operation situation in the power equipment. By extracting this data, the system terminal can conduct a deeper situational awareness and risk analysis of the power equipment involved in the first power network security maintenance task, laying a data foundation for subsequent conflict detection and redundancy analysis.

[0022] Further, if Figure 2 As shown, performing power equipment group mining based on a first power network security maintenance task among the multiple power network security maintenance tasks to obtain a first sample data set includes:

[0023] Collect power equipment operation data associated with the first power network security maintenance task and set a network security scenario; based on the digital twin model, mark abnormal conflict nodes and abnormal flow nodes in the network security scenario; use the abnormal conflict nodes and abnormal flow nodes as starting points to mine the power equipment group and obtain a first sample data set.

[0024] Preferably, the system terminal identifies power equipment related to the first power network security maintenance task, typically including transformers, circuit breakers, and distribution cabinets. Sensors and monitoring systems installed on the power equipment collect real-time operational data from the power equipment. This data includes key parameters such as voltage, current, power, frequency, temperature, and device status. Subsequently, a network security scenario is constructed based on the collected device operational data and the topology of the power network. This scenario includes the connectivity between devices, network traffic patterns under normal operating conditions, and load conditions. When constructing the scenario, key parameters are defined, such as network topology, device location, traffic flow direction, and load distribution. These parameters help simulate the behavior and state of the power network under normal conditions. Then, based on the digital twin model, real-time analysis of the power equipment operational data is performed within the configured network security scenario. Threshold detection is used to identify and mark abnormal conflict nodes and abnormal traffic nodes in the network. Abnormal conflict nodes are identified by comparing parameters such as device load and device temperature with corresponding thresholds, and abnormal traffic nodes are identified by comparing parameters such as network traffic volume and traffic fluctuation amplitude with corresponding thresholds. Any abnormality is marked. After marking the abnormal conflict nodes and abnormal traffic flow nodes, the system terminal uses these marked nodes as a starting point for power device group mining. By analyzing the connections between these nodes and other power devices, the system identifies the associated device groups. From these mined power device groups, the system then extracts a first sample dataset. This dataset contains various data related to the first power network security maintenance task, including network traffic sample data and user behavior sample data. This sample data will provide important information for subsequent security situation analysis and risk assessment.

[0025] Furthermore, the present application provides a method of using the abnormal conflict node and the abnormal flow node as a starting point to mine a power equipment group and obtain a first sample data set, including:

[0026] Obtain the Internet of Things communication protocol of each power device and set up a communication link; take the abnormal conflict node as the starting point, and determine a first connection relationship along the propagation path corresponding to the communication link; take the abnormal traffic node as the starting point, and determine a second connection relationship along the propagation path corresponding to the communication link; based on the first connection relationship and the second connection relationship, obtain a first sample data set.

[0027] Optionally, the system terminal identifies all power equipment in the power network, including transformers, circuit breakers, and distribution cabinets, ensuring they are registered with the network. It then queries and collects the IoT communication protocols used by these devices, such as MQTT, CoAP, Modbus, and DNP3. Each protocol may have different data formats and communication methods, and obtaining these protocols is crucial for subsequent data exchange and communication link setup. Subsequently, communication links are established between the power equipment based on the collected communication protocols. This process includes defining the data transmission paths, network topology, and communication latency between devices to ensure that each power equipment can effectively communicate data using the specified communication protocol. Next, the marked abnormal conflict node is used as a starting point to analyze its position in the communication link. The system terminal traces the data propagation path from the abnormal conflict node along the established communication link, identifies other devices directly or indirectly connected to the node, and their connection relationships. It then records the device connection relationships associated with the abnormal conflict node, forming a mapping of the first connection relationships. Similarly, using the marked abnormal traffic node as the starting point, the system analyzes its position in the communication link. The data propagation path from the abnormal traffic node is traced along the established communication link. Other devices directly connected to the node and their connection relationships are identified. The device connection relationships associated with the abnormal traffic node are recorded to form a second connection relationship mapping. Then, based on the first and second connection relationships, data is extracted from the relevant devices to form a first sample dataset, providing important data support for subsequent security situation analysis.

[0028] Based on the digital twin model, the first sample data set is introduced, data conflict situation analysis is performed using the user behavior sample data, and a data conflict network layer is set.

[0029] In one embodiment, user behavior sample data from a first sample dataset is introduced into a digital twin model. This data includes user operation records on power equipment, access frequency, and other information. Within the digital twin model, a new data conflict network layer is constructed. This data conflict network layer is used to analyze data conflict situations and generate conflict risk values ​​for nodes. Methods for constructing this data conflict network layer include graph neural networks (GNNs) and long-short-term memory networks (LSTMs). Taking the LSTM network as an example, the system terminal cleans and standardizes the user behavior sample data from the first sample dataset, ensuring that no missing data is present and converting it into a format suitable for network layer input to form a training set. For example, categorical variables (such as user roles or operation types) are encoded into numerical form to facilitate network layer processing. Subsequently, the model structure of the data conflict network layer is designed, including an input layer, an LSTM layer (multiple LSTM layers can be used to enhance model capabilities), and an output layer. The training set is input into the data conflict network layer for forward propagation, calculating the network layer's conflict risk value. The loss is then calculated using the mean squared error (MSE) between the conflict risk value output by the network layer and the true conflict risk value labeled in the training set. The backpropagation algorithm then calculates the gradient of the loss with respect to the network layer parameters, and an optimization algorithm (such as Adam or SGD) is used to update the network layer weights and biases to minimize the loss. This training cycle (epochs) is repeated, with multiple forward and backward propagations performed in each cycle, until the preset number of training rounds is reached or the loss converges. By implementing a data conflict network layer, the system terminal can dynamically calculate and optimize conflict risk values ​​while processing user behavior data, thereby improving the safety management capabilities of the power network.

[0030] The network traffic sample data is used to perform data redundancy situation analysis and set a data redundancy network layer.

[0031] In one embodiment, the system terminal uses the network traffic sample data from the first sample data set in the same manner as described above to set up a data redundancy network layer in the digital twin model. This data redundancy network layer is used to perform data redundancy situation analysis and generate redundancy risk values ​​for nodes. The specific construction process is the same as described above. By setting up a data redundancy network layer, the redundancy risk value can be dynamically calculated and optimized during the processing of network traffic data, thereby improving the safety management capabilities of the power network.

[0032] Based on the multiple power network security maintenance tasks in the power network event library, the data conflict network layer and the data redundancy network layer are coupled and connected to identify potential security risks and issue security warning signals.

[0033] In one embodiment, after completing the configuration of the data conflict network layer and the data redundancy network layer, the system terminal couples the two network layers based on multiple power network security maintenance tasks in the power network event library. This coupling process enables the two network layers to share information. After the coupling is completed, the system terminal comprehensively analyzes the outputs of the two network layers using a security risk value calculation formula and configures a propagation situation diagram based on the analysis results. Subsequently, a safety warning signal is generated based on the nodes in the configured propagation situation diagram, notifying maintenance personnel to take necessary precautions to maintain the safety and stability of the power network. This process ensures that security maintenance can respond promptly in a dynamic power network environment, improving overall security management capabilities.

[0034] Furthermore, the present application provides obtaining a first sample data set based on the first connection relationship and the second connection relationship, including:

[0035] Based on sudden disasters, an emergency safety maintenance mark is generated, and the emergency safety maintenance mark includes a fault impact area; based on the emergency safety maintenance mark, the data conflict network layer is used to evaluate the conflict risk level under the fault impact area mapping, and combined with the first connection relationship, a first priority sequence is added; based on the emergency safety maintenance mark, the data redundancy network layer is used to evaluate the redundancy risk level under the fault impact area mapping, and combined with the second connection relationship, a second priority sequence is added.

[0036] Optionally, the system terminal identifies the affected fault areas based on the type of sudden disaster and historical experience, with abnormal nodes as the center. These areas may include power equipment, lines or network nodes. The system terminal generates an emergency safety maintenance mark for the determined fault-affected area. Subsequently, based on the emergency safety maintenance mark, the data conflict network layer is used to analyze the status of each node in the fault-affected area, and the conflict risk value is calculated based on the user behavior data of each node, and compared with the preset conflict risk level table to determine the conflict risk level of each node. The data redundancy network layer is used to analyze the status of each node in the fault-affected area, and the redundancy risk value is calculated based on the network traffic data of each node, and compared with the preset redundancy risk level table to determine the redundancy risk level of each node. Thereafter, the security risk value of each node is calculated based on the security risk value calculation formula in combination with the conflict risk value and the redundancy risk value, and the calculation result is combined with the first connection relationship and added to the first priority sequence, and the calculation result is combined with the second connection relationship and added to the second priority sequence. Through the above steps, it can be ensured that after an emergency disaster occurs, the power network can quickly identify and respond to potential safety risks, providing data support and decision-making basis for the implementation of effective maintenance and protection measures.

[0037] Furthermore, the present application provides a method for evaluating the conflict risk level under the fault impact area mapping based on the emergency safety maintenance mark using the data conflict network layer, combining the first connection relationship, and adding a first priority sequence, including:

[0038] Utilize the data conflict network layer to perform conflict risk analysis on the N nodes under the fault impact area mapping, and calculate the security risk values ​​corresponding to the N nodes, where N is the total number of nodes; sort the N nodes according to the security risk values ​​corresponding to them to obtain the first priority sequence; based on the first connection relationship, access the propagation situation of the first priority sequence along the propagation path corresponding to the communication link to set a first propagation situation diagram.

[0039] Optionally, the system terminal identifies and selects N nodes related to the fault based on the fault impact area in the emergency safety maintenance mark. Subsequently, the data conflict network layer analyzes the status and behavior of each node, performs a conflict risk analysis on each node, and calculates a corresponding conflict risk value for each node. The data redundancy network layer analyzes the status and behavior of each node, performs a redundancy risk analysis on each node, and calculates a corresponding redundancy risk value for each node. The conflict risk value and redundancy risk value for each node are then combined using a security risk value calculation formula to calculate the security risk values ​​for the N nodes. After calculating the security risk values ​​for the N nodes, the system terminal sorts the calculated security risk values ​​for the N nodes according to their priority scores to identify the nodes that require the most priority attention. Based on the sorting results, a first priority sequence is formed to determine the nodes that should be prioritized in the event of a fault. Then, based on the first connection relationship, a propagation status survey is conducted on the communication links between the nodes in the priority sequence to determine the information transmission paths between the nodes. These paths demonstrate how effective monitoring and information sharing can be achieved through the network. A first propagation status map is constructed based on the propagation paths identified by the propagation status strength. The diagram shows the connection relationship and data flow between each node, allowing maintenance personnel to intuitively understand the propagation dynamics of the fault-affected area and its potential risks.

[0040] Furthermore, this application provides a formula for calculating the security risk value, including:

[0041] Safety risk value calculation formula: ,in, Used to characterize the security risk value of the i-th node, is the conflict risk value of the i-th node, is the redundancy risk value of the i-th node, is a weight coefficient used to balance conflict risk and redundancy risk; based on the security risk values ​​corresponding to N nodes, the priority score is calculated , determine the first priority sequence.

[0042] Optionally, the security risk value calculation formula is used to evaluate the security risk level of each node in the power network. For each node i, the security risk value calculation formula is as follows: ,in, It is used to characterize the security risk value of the i-th node, indicating the comprehensive security risk level of the node under the current circumstances. is a weight coefficient between 0 and 1, used to balance the importance of conflict risk and redundancy risk. A larger value indicates a greater emphasis on conflict risk. is the conflict risk value of the i-th node, which indicates the risk level caused by equipment failure, operation conflict, etc. Is the redundancy risk value of the i-th node, indicating the risk level caused by data redundancy, network traffic anomaly, etc. The system terminal converts the conflict risk value of the i-th node into According to weight Weighted, plus the redundant risk value of the i-th node and 1− This calculation method ensures that when assessing security risks, potential risks caused by device conflicts and redundancy can be taken into account. After calculating the security risk values ​​of all nodes, the system terminal calculates the priority score of each node based on these security risk values. The specific calculation method is as follows: ;in, is the priority score of the i-th node, indicating its relative importance among all nodes. A higher score indicates a higher priority. N is the total number of nodes. The system terminal calculates the priority score of each node, ranks them according to these scores, and adds the ranking results to the first priority sequence. This helps the system terminal identify and address high-risk nodes in the event of a fault, thereby enhancing the safety and stability of the power network.

[0043] Furthermore, the present application provides setting a first propagation situation map, including:

[0044] The communication link distance from node i to node j is recorded as , calculate the transmission situation strength from node i to node j ; Set the first propagation situation map , where V is the set corresponding to N nodes under the fault impact area mapping.

[0045] Optionally, when performing propagation situation analysis, the system terminal first determines the communication link distance from node i to node j, which is recorded as , and then calculate the transmission situation strength from node i to node j based on the determined communication link distance. The calculation formula of transmission situation strength is as follows: ;in, is the priority score of node i. The intensity of the propagation situation is proportional to the priority score between nodes and inversely proportional to the distance of the communication link, that is, the shorter the distance, the greater the intensity of the propagation. Subsequently, the first propagation situation diagram is set according to the risk propagation path iteration formula , the graph shows the propagation relationship between nodes, specifically including the edge set , where V is the set of N nodes corresponding to the fault impact area mapping. This first propagation situation map will provide maintenance personnel with intuitive information to facilitate understanding of the information flow between nodes and potential risk propagation paths under specific fault conditions, providing decision support for subsequent emergency response and safety management.

[0046] Furthermore, the present application provides for adjusting the initialization output impedance, including

[0047] Risk propagation path iteration formula: ;in, and are the security risk values ​​of node i and node j respectively, It is the optimal path to isolate the spread of risk, and Path is the path of risk transmission.

[0048] Optionally, when selecting a risk propagation path, the system terminal uses the following objective function to determine the best path: ; In this formula, the goal is to find a path that minimizes the risk spread along the entire path. Specifically, represents the transmission intensity from node i to node j, which is derived from the previous analysis. The transmission risk of each segment in the path is affected by the security risk value of the connected node, that is, and are the security risk values ​​of node i and node j respectively. When selecting a path, the system terminal considers the propagation strength of each link in the path and the security risk value of the node. By taking the product of the maximum risk value in the path, the system terminal can ensure that the selected path can withstand the potential risk even in the most unfavorable situation. The "Path" represents the optimal path for isolating risk propagation, effectively reducing overall network security risks. The "Path" represents the actual path of risk propagation, providing a crucial basis for subsequent decision-making and emergency response. This process not only optimizes the selection of risk propagation paths but also enhances the ability to manage potential risks, enabling the power grid to respond more effectively to security threats.

[0049] In summary, the embodiments of the present application have at least the following technical effects:

[0050] This embodiment of the present application establishes a digital twin model based on the power grid topology and power equipment, and accesses a power network event library to write multiple maintenance tasks. Subsequently, by analyzing the power network security maintenance tasks, a first sample dataset containing network traffic and user behavior sample data is obtained. Data conflict and data redundancy situation analyses are performed based on this dataset, and a data conflict network layer and a data redundancy network layer are established, respectively. By coupling these two network layers, potential security risks are identified and security warning signals are issued. Furthermore, an emergency security maintenance marker is generated in the context of an emergency, and conflict and redundancy risks are assessed for the fault-affected areas. A priority sequence is generated based on the connection relationships. Finally, by calculating the security risk value between nodes, the propagation situation strength, and an iterative formula, the risk propagation path is optimized, ensuring timely and effective response and decision support in power network security management. These technical effects collectively address the technical issues of delayed power network security situational awareness and difficulty in accurately identifying security risks. This enables real-time monitoring of the power network security status through a digital twin model, identifying potential risks and issuing warning signals, thereby improving the accuracy of power network security situational awareness and response efficiency.

[0051] It should be noted that the order in which the embodiments of the present application are presented is for illustrative purposes only and does not necessarily represent the superiority or inferiority of the embodiments. Furthermore, the foregoing descriptions of specific embodiments of this specification are provided. The processes depicted in the accompanying drawings do not necessarily require the specific order or sequential sequence shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0052] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

[0053] This specification and drawings are merely illustrative of the present application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Obviously, those skilled in the art may make various modifications and variations to this application without departing from the scope of this application. Thus, this application is intended to include such modifications and variations as fall within the scope of this application and its equivalents.

Claims

1. A digital twin-driven power network security situation awareness method, characterized by: The method comprises: Set up a digital twin model based on the grid topology and various power equipment; Accessing a power network security event library, wherein the power network security event library stores a plurality of power network security maintenance tasks; Performing power equipment group mining based on a first power network security maintenance task among the multiple power network security maintenance tasks to obtain a first sample data set, the first sample data set including network traffic sample data and user behavior sample data, the first power network security maintenance task being any one of the multiple power network security maintenance tasks; Based on the digital twin model, the first sample data set is introduced, data conflict situation analysis is performed using the user behavior sample data, and a data conflict network layer is set; Performing data redundancy situation analysis based on the network traffic sample data and setting a data redundancy network layer; Based on the multiple power network security maintenance tasks in the power network security event library, the data conflict network layer and the data redundancy network layer are coupled and connected to identify potential security risks and issue security warning signals; The method of performing power equipment group mining based on a first power network security maintenance task among the plurality of power network security maintenance tasks to obtain a first sample data set includes: Collecting power equipment operation data associated with the first power network security maintenance task and setting a network security scenario; Based on the digital twin model, marking abnormal conflict nodes and abnormal traffic nodes in the network security scenario; Taking the abnormal conflict nodes and abnormal flow nodes as starting points, mining the power equipment group to obtain a first sample data set; The abnormal conflict node and the abnormal flow node are used as starting points to mine the power equipment group and obtain a first sample data set, including: Obtain the IoT communication protocol for each power device and set up the communication link; Taking the abnormal conflict node as a starting point, determining a first connection relationship along a propagation path corresponding to the communication link; Taking the abnormal traffic node as a starting point, determining a second connection relationship along the propagation path corresponding to the communication link; Based on the first connection relationship and the second connection relationship, obtaining a first sample data set; The method of obtaining a first sample data set based on the first connection relationship and the second connection relationship further includes: Generate an emergency safety maintenance mark based on a sudden disaster, wherein the emergency safety maintenance mark includes a fault-affected area; Based on the emergency safety maintenance mark, using the data conflict network layer to evaluate the conflict risk level under the fault impact area mapping, combined with the first connection relationship, adding a first priority sequence; Based on the emergency safety maintenance mark, the redundancy risk level under the fault impact area mapping is evaluated using the data redundancy network layer, and a second priority sequence is added in combination with the second connection relationship.

2. The digital twin-driven power network security situation awareness method according to claim 1, characterized in that: Based on the emergency safety maintenance mark, using the data conflict network layer to evaluate the conflict risk level under the fault impact area mapping, and combining the first connection relationship to add a first priority sequence, the method further includes: Using the data conflict network layer, conflict risk analysis is performed on N nodes mapped under the fault impact area, and security risk values ​​corresponding to the N nodes are calculated, where N is the total number of nodes; Sort the N nodes by their corresponding security risk values ​​to obtain the first priority sequence; Based on the first connection relationship, the first priority sequence is accessed for a propagation situation along the propagation path corresponding to the communication link to set a first propagation situation map.

3. The digital twin-driven power network security situation awareness method according to claim 2, characterized in that: Safety risk value calculation formula: ,in, Used to characterize the security risk value of the i-th node, is the conflict risk value of the i-th node, is the redundancy risk value of the i-th node, and β is the weight coefficient used to balance the conflict risk and redundancy risk; Calculate the priority score based on the security risk values ​​corresponding to N nodes , determine the first priority sequence.

4. The digital twin-driven power network security situation awareness method according to claim 3, characterized in that: The communication link distance from node i to node j is recorded as , calculate the transmission situation strength from node i to node j ; Set up the first propagation situation map , where V is the set corresponding to N nodes under the fault impact area mapping.

5. The digital twin-driven power network security situation awareness method according to claim 4 is characterized in that: The method further comprises: Risk propagation path iteration formula: ; in, and are the security risk values ​​of node i and node j respectively, It is the optimal path to isolate the spread of risk, and Path is the path of risk transmission.

Citation Information

Patent Citations

  • Network security analysis method and system based on digital twinning

    CN119276611A

  • Unified multi-agent system for abnormality detection and isolation

    US20220327204A1