A multi-channel substation integrated automation system
Through multi-channel design and camouflage information technology, combined with dual-ring interconnect topology and dynamic load balancing, the data transmission reliability and network security problems of traditional substation integrated automation systems are solved, and efficient and reliable data transmission and security protection are achieved.
Patent Information
- Application Number
- CN202510905800.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2045-07-02
AI Technical Summary
Traditional substation integrated automation systems have low data transmission reliability and network security risks, making it difficult to meet the real-time and security needs of smart grids.
Using multi-path design and camouflage information technology, redundant data copies are transmitted in parallel through four physical links, combined with the dual-ring interconnect topology and dynamic load balancing, Markov processes and Bayesian networks are used to predict link states and fusion and enhance network security protection.
It improves the reliability and security of data transmission, ensures the continuity and stability of data transmission, reduces the risk of network attacks, and improves data processing efficiency and accuracy.
Smart Images

Figure CN120414914B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power system automation, and in particular to a multi-channel substation integrated automation system. Background Art
[0002] As smart grid construction continues to advance, substation automation systems, as a key hub in the power system, shoulder the core responsibility of real-time data collection, transmission, and processing. Through the coordinated operation of the device, communication, and management layers, these systems enable functions such as power parameter monitoring, equipment status control, and fault warning. However, in practice, traditional substation automation systems still suffer from low data transmission reliability and high network security risks, making them unable to meet the smart grid's requirements for power system stability and intelligence.
[0003] Data transmission reliability issues. Traditional substation integrated automation systems mostly use a single-path data transmission architecture. When the primary channel fails, manual intervention is required to switch to the backup channel, which takes a long time and cannot meet the real-time requirements of smart grids. Some systems also use a dual-link redundancy design, but lack a dynamic assessment mechanism. When one link is damaged, the system cannot perceive the link status change in real time and still distributes data according to the original ratio. This leads to excessive load on the intact link and increased data transmission delay.
[0004] Network security risks. Traditional data frames use a fixed format and lack effective security protection. For example, the Modbus protocol data frame header contains clear function codes and address information, allowing attackers to easily identify control commands by analyzing traffic characteristics. Traditional telecontrol communication management machines, as single receiving nodes, can easily become the focus of attacks and cause paralysis, preventing the upload of monitoring data from the entire station. Passive defense mechanisms lag behind, and existing firewalls and intrusion detection systems rely on signature library matching, making them difficult to respond to new attacks.
[0005] Therefore, there is an urgent need for a multi-channel substation integrated automation system that can effectively improve the reliability and security of data transmission. Summary of the Invention
[0006] The purpose of the present invention is to provide a multi-channel substation integrated automation system to improve data transmission reliability and enhance network security protection capabilities.
[0007] In order to solve the above technical problems, the technical solution of the present invention is:
[0008] A multi-channel substation integrated automation system includes an equipment layer, a communication layer and a management layer; the equipment layer includes a microcomputer line protection and measurement and control device, the microcomputer line protection and measurement and control device is configured with four independent network ports, each network port is connected to a physical link; the microcomputer line protection and measurement and control device is used to collect original data and encode it into multiple redundant data copies, generate a data frame header including camouflage information for each data copy, and then transmit the redundant data copies in parallel to four physical links through four independent network ports according to the optimal data distribution ratio issued by the server; the communication layer includes four Ethernet switches and a telecontrol communication management machine, the four Ethernet switches form a dual-ring interconnection topology through four interconnection links, and the telecontrol communication management machine is connected to two different switches in the dual-ring network through dual network ports respectively; the telecontrol The communication management machine is configured with: multiple camouflage receiving modules, which simulate service interfaces of different protocol types and are used to receive and record data frames including camouflage information; a load balancer, which is used to distribute the received data frames to the core processing module according to a preset strategy; the core processing module is used to check and convert the data frames and transmit the processed data frames to the server; the management layer includes a server, which is configured to: construct a link state prediction model based on the Markov process, output the failure rate prediction of each physical link, and calculate the optimal data distribution ratio through a linear programming model based on the failure rate prediction, combined with the load and attack situation of the physical link, and send it to the microcomputer line protection and measurement and control device; through the Bayesian network data fusion engine, combined with the consistency matrix and Bayesian weight factor, weighted fusion of each data copy is performed.
[0009] Furthermore, the disguised information in the data frame header is used to confuse potential network attacks, including: at least two virtual receiving target identifiers, a randomly generated protocol type identifier, and a forged priority identifier; the disguised information and the payload part and check part of the data frame together constitute a complete data frame structure.
[0010] Furthermore, the virtual receiving target identifier is randomly selected from a list of masquerading receiving modules of the telecontrol communication management machine, and the virtual receiving target identifier corresponds to a service interface type of the masquerading receiving module.
[0011] Furthermore, the camouflaged receiving module supports simulating service interfaces of at least three protocol types, including IEC60870-5-104, Modbus, and DNP3, and each camouflaged receiving module independently records the source device ID and receiving time of the received data frame.
[0012] Furthermore, the load balancer distributes the data frame to the core processing module based on the priority of the data frame, the load status of the disguised receiving module, and the link failure rate prediction result; after the disguised receiving module receives the data frame, it first determines whether the source device ID of the data frame is in the preset trusted device list. If not, it is marked as a suspected attack data frame and stored in isolation.
[0013] Furthermore, the core processing module verifies the data frame by verifying the CRC check code and digital signature of the data frame, and judging the authenticity of the data frame by comparing the virtual receiving target identifier in the disguised information with the preset target library.
[0014] Furthermore, the telecontrol communication management machine is also configured with a security monitoring module, which identifies attack patterns based on the attack data recorded by the disguised receiving module and the machine learning algorithm, and dynamically adjusts the type and number of simulated service interfaces of the disguised receiving module.
[0015] Furthermore, the calculation process of the optimal data allocation ratio is as follows: the physical link status is divided into three categories: normal, warning and fault, and the state transition matrix is obtained based on historical data training to predict the probability of the physical link being in different states at future moments, and then the failure rate weight of the physical link is weighted and calculated; the risk value of the physical link is calculated by comprehensively considering the failure rate weight, real-time load rate and attack count of the physical link; with the goal of minimizing the comprehensive risk, an objective function including the failure rate weight, load rate and attack count is established, and the data allocation ratio of each physical link is solved through linear programming.
[0016] Furthermore, the fusion steps of the Bayesian network data fusion engine include: receiving multiple redundant data copies from the core processing module; obtaining the failure rate prediction results of each transmission path based on the Markov link prediction model; calculating the Bayesian weight factor of each data copy in combination with the attack count recorded by the camouflage receiving module; determining the credibility of each data copy based on the Bayesian weight factor, and selecting the data copy with the highest credibility as the main data source.
[0017] Furthermore, the server is also configured to: verify the main data source in combination with the consistency matrix, and use the data if the verification passes, otherwise trigger the retransmission mechanism; when the retransmission mechanism is triggered, the server recalculates the optimal data distribution ratio based on the current load and failure rate prediction results of each physical link, and sends it to the microcomputer line protection measurement and control device at the equipment layer for retransmission.
[0018] The beneficial effects of the present invention are:
[0019] (1) High reliability of data transmission: This invention uses four physical links with different transmission media and redundant geographic routing to avoid data transmission interruptions caused by single link failures or regional disasters. Furthermore, the dual-ring interconnected Ethernet switch topology can dynamically adjust the data allocation ratio in conjunction with the link status prediction model, ensuring the continuity and stability of data transmission and significantly improving the reliability of the substation integrated automation system.
[0020] (2) Enhanced network security protection: Data frames are designed with disguised information. The telecontrol communication management machine deploys multiple disguised receiving modules to simulate different protocol service interfaces, which can effectively confuse potential network attacks and shift the attack targets from core devices to the disguised modules. At the same time, through multiple verifications such as digital signatures and CRC checks on data frames, combined with the machine learning recognition of attack patterns by the security monitoring module, active defense is achieved, significantly improving the network security performance of the system.
[0021] (3) Efficient data processing and fusion: The data fusion engine based on the Markov process link state prediction model and Bayesian network can dynamically adjust the data transmission strategy according to the link failure rate and perform weighted fusion of multiple redundant data copies to remove erroneous or unreliable data, thereby improving data accuracy. In addition, the collaborative work of the load balancer and core processing module enables rapid data distribution and processing, reduces data processing delays, and improves the overall efficiency of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 It is a system architecture diagram of the present invention;
[0023] Figure 2 It is a data processing flow chart of the present invention. DETAILED DESCRIPTION
[0024] For the convenience of understanding the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood by those skilled in the art that the embodiments are only provided to help understand the present invention and should not be regarded as specific limitations of the present invention.
[0025] In the following description of the embodiments, specific details such as specific system structures and techniques are provided for illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0026] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their collections. It should also be understood that the term "and / or" used in the present specification and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0027] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0028] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the description and are not to be understood as indicating or implying relative importance. References to "one embodiment" or "some embodiments" etc. described in the present application specification mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized.
[0029] like Figure 1 、 2As shown, the present invention provides a multi-channel substation integrated automation system, including an equipment layer, a communication layer and a management layer; the equipment layer includes a microcomputer line protection and measurement and control device, which is configured with four independent network ports, each of which is connected to a physical link; the transmission medium used by the physical link includes at least two of optical fiber, shielded twisted pair, and wireless microwave; the microcomputer line protection and measurement and control device is used to collect original data and encode it into multiple redundant data copies, generate a data frame header including camouflage information for each data copy, and then transmit the redundant data copies in parallel to four physical links through four independent network ports according to the optimal data distribution ratio issued by the server; the communication layer includes four Ethernet switches and a telecontrol communication management machine, the four Ethernet switches form a dual-ring interconnection topology through four interconnection links, and the telecontrol communication management machine distributes the redundant data through the dual network ports. They are connected to two different switches in the dual-ring network; the telecontrol communication management machine is configured with: multiple camouflage receiving modules, which simulate service interfaces of different protocol types and are used to receive and record data frames including camouflage information; a load balancer, which is used to distribute the received data frames to the core processing module according to a preset strategy; the core processing module is used to check and convert the data frames, and transmit the processed data frames to the server; the management layer includes servers, and the server is configured to: build a link state prediction model based on the Markov process, output the failure rate prediction of each physical link, and calculate the optimal data distribution ratio through a linear programming model based on the failure rate prediction, combined with the load and attack situation of the physical link, and send it to the microcomputer line protection and measurement and control device; through the Bayesian network data fusion engine, combined with the consistency matrix and Bayesian weight factor, the data copies are weightedly fused.
[0030] This invention enables reliable multi-channel transmission of substation data. Its four physical links and dual-ring topology significantly reduce the risk of data interruption due to single-link failures. Data redundancy coding at the device layer and load balancing at the communication layer ensure efficient data transmission; link status prediction and dynamic data allocation at the management layer further optimize transmission efficiency. Furthermore, the data frame camouflage design and communication layer security mechanisms enhance the system's network security and effectively defend against network attacks. The server's data fusion processing ensures data accuracy and integrity, providing strong support for the stable operation and intelligent control of substations.
[0031] The camouflage information in the data frame header refers to the false target identifier, protocol type and other information contained in the data frame header, which is used to confuse potential network attacks and prevent attackers from accurately identifying the transmission path and target of the real data. The camouflage information includes: at least two virtual receiving target identifiers, a randomly generated protocol type identifier and a forged priority identifier; the camouflage information and the payload part and checksum part of the data frame together constitute a complete data frame structure. By setting complex camouflage information in the data frame header, potential network attackers can be effectively confused, making it difficult for them to distinguish the real data transmission target and protocol type. Therefore, the attack target can be transferred from the core device to the virtual target, reducing the risk of the core device being attacked. At the same time, the complete data frame structure design ensures the integrity and verifiability of the data during transmission, further improving the security and reliability of the system.
[0032] The virtual receiving target identifier is part of the disguised information and is used to mimic the ID of a real receiving device, tricking attackers into shifting their attack targets to the virtual target. The virtual receiving target identifier is randomly selected from the list of disguised receiving modules on the telecontrol communication management unit and corresponds to the service interface type of the disguised receiving module. This alignment of the virtual receiving target identifier with the service interface type of the disguised receiving module enhances the authenticity and deceptiveness of the disguise, making it more difficult for attackers to determine the true direction of data flow based on information such as the protocol type. This further improves the system's ability to resist cyberattacks and ensures the security of substation data transmission.
[0033] The masquerade receiver module supports emulating service interfaces for at least three protocol types, including IEC 60870-5-104, Modbus, and DNP3. Each masquerade receiver module independently records the source device ID and reception time of received data frames. This multi-protocol emulation enables the system to respond to detection and attacks from diverse attackers, expanding the system's protection capabilities. Each masquerade receiver module independently records the source device ID and reception time, facilitating attack tracing and analysis. By statistically analyzing these records, attack patterns can be identified, enabling timely adjustments to security strategies and enhancing the system's security capabilities.
[0034] The load balancer distributes data frames to the core processing module based on the data frame's priority, the load status of the disguised receiving module, and the predicted link failure rate. The load balancer distributes data frames based on multiple factors, achieving efficient and rational data processing at the communication layer and preventing system performance from being affected by excessive load on certain links or modules. After receiving a data frame, the disguised receiving module first determines whether the source device ID of the data frame is in the preset trusted device list. If not, it is marked as a suspected attack data frame and stored in isolation. The disguised receiving module's verification of the source device ID and isolated storage of suspected attack data frames can promptly detect and block potential network attacks, prevent malicious data from entering the core processing flow, and ensure the security and stable operation of the system.
[0035] The core processing module verifies the data frame's CRC checksum and digital signature, and verifies the authenticity of the data frame by comparing the virtual receiving target identifier in the disguised information with a preset target library. This multi-verification mechanism rigorously verifies data frames from multiple perspectives, including data integrity, source legitimacy, and the plausibility of the disguise. It effectively prevents data mishandling caused by data transmission errors, malicious tampering, or illegal forgery. Only data frames that pass all verifications are allowed to proceed to the subsequent processing flow, ensuring the authenticity and reliability of the data entering the server and providing an accurate data foundation for subsequent data integration and correct substation control.
[0036] The telecontrol communication management unit is also equipped with a security monitoring module. Based on the attack data recorded by the masquerade receiver module and using machine learning algorithms, the module identifies attack patterns and dynamically adjusts the type and number of simulated service interfaces in the masquerade receiver module. This module, combined with machine learning algorithms, automatically identifies new and unknown attack patterns, overcoming the limitations of traditional rule-based security systems. Dynamically adjusting the masquerade receiver module's settings provides the system with proactive defense capabilities, enabling flexible adaptation of protection strategies based on attack dynamics. This effectively protects against evolving cyberattacks and continuously enhances the system's network security.
[0037] The optimal data allocation ratio is calculated as follows: the physical link status is divided into three categories: normal, warning, and fault. The state transition matrix is trained based on historical data to predict the probability of the physical link being in different states at future moments, and then the failure rate weight of the physical link is weighted and calculated. The risk value of the physical link is calculated by comprehensively considering the failure rate weight of the physical link, the real-time load rate, and the attack count. With the goal of minimizing the comprehensive risk, an objective function that includes the failure rate weight, load rate, and attack count is established, and the data allocation ratio of each physical link is solved through linear programming.
[0038] The server's Bayesian network data fusion engine uses the data frame's transmission path, the attack count of the masquerading receiver module, and the predicted link failure rate as input variables when calculating the posterior probability of each data copy. By comprehensively considering multiple factors, including the data frame's transmission path, attack scenario, and link status, the posterior probability calculation enables the Bayesian network data fusion engine to more accurately assess the credibility and reliability of each data copy. This more precise probabilistic data fusion improves the accuracy and reliability of the fused data, providing stronger data support for substation operation monitoring and decision-making.
[0039] The fusion steps of the Bayesian network data fusion engine include: receiving multiple redundant data copies from the core processing module; obtaining failure rate predictions for each transmission path based on a Markov link prediction model; calculating the Bayesian weight factor for each data copy based on the attack counts recorded by the camouflaged receiving module; determining the credibility of each data copy based on the Bayesian weight factor, and selecting the most credible data copy as the primary data source. The Bayesian weight factor is a weight coefficient used in the Bayesian network data fusion engine to measure the reliability of each data source and is dynamically adjusted based on historical data and real-time link status. The primary data source is determined through a scientific calculation process, fully considering the impact of link status and attack conditions on data credibility, and avoiding incorrect selections due to single-factor judgments. Selecting the most credible data copy as the primary data source improves the quality and accuracy of data fusion, ensures the reliability of the data ultimately used for substation monitoring, and reduces the risk of decision-making errors due to inaccurate data.
[0040] The server is also configured to verify the primary data source using a consistency matrix. If the verification passes, the data is used; otherwise, a retransmission mechanism is triggered. When the retransmission mechanism is triggered, the server recalculates the optimal data allocation ratio based on the current load and failure rate predictions of each physical link, and sends it to the microcomputer line protection and measurement and control device at the equipment layer for retransmission. The consistency matrix verification and retransmission mechanism ensures the accuracy and reliability of the final data used, enabling timely detection and correction of potential data errors or inconsistencies. The allocation ratio of retransmitted data is dynamically adjusted based on link load and failure rate, avoiding link load imbalance and transmission efficiency degradation caused by retransmission. This ensures data accuracy while maintaining the efficiency and stability of system data transmission.
[0041] In a 35kV smart substation, the equipment layer uses a BHE-316 microcomputer-based line protection and measurement and control device. This device has four independent network ports, each connected to four physical links: Physical Link 1 uses single-mode fiber and is laid along the cable trench on the east side of the substation; Physical Link 2 uses multimode fiber and is run along the cable trench on the south side; Physical Link 3 uses shielded twisted-pair cable and is transmitted via the west overhead line; and Physical Link 4 uses wireless microwave and is relayed via the north tower. Redundant geographic routing is employed, with multiple physical links deployed along different geographic paths to reduce the risk of simultaneous failure of multiple physical links due to regional events such as natural disasters and man-made sabotage. The microcomputer-based line protection and measurement and control device collects raw data such as busbar voltage and current in real time, encodes it into three redundant data copies, and generates a disguised information data frame header for each copy, containing a virtual receiving target identifier, a random protocol type identifier, and a forged priority identifier. The server calculates the optimal data allocation ratio for each link based on a Markov link prediction model and then distributes it. The microcomputer-based line protection and measurement and control device transmits the redundant data copies in parallel to the four physical links via the four network ports.
[0042] The communication layer deploys four Huawei S5720-52P Ethernet switches and a BHE-352 telecontrol communication management unit. The four Ethernet switches form a dual-ring interconnected topology via four interconnected links. The primary ring consists of Switch 1, Switch 2, Switch 3, and Switch 1, using the STP protocol. The backup ring consists of Switch 2, Switch 4, Switch 3, and Switch 2, using the ERPS protocol. The telecontrol communication management unit connects to Switch 2 and Switch 3 in the dual-ring network through dual network ports. The telecontrol communication management machine is equipped with 10 disguised receiving modules, of which 5 simulate the IEC 60870-5-104 protocol service interface, 3 simulate the Modbus TCP service interface, and 2 simulate the DNP3 service interface. The load balancer distributes the data frames to the core processing module based on the data frame priority, the load status of the disguised receiving module, and the link failure rate prediction results. The core processing module verifies the CRC checksum and digital signature of the data frames, and compares the virtual receiving target identifier in the disguised information. After the verification is completed, the data frame is converted from Modbus, DNP3 and other protocols to the IEC61850 standard protocol and transmitted to the server.
[0043] The BHE-316 microcomputer line protection device is suitable for line protection of voltage levels of 66kV and below. It can be installed in a centralized panel or dispersedly in a switch cabinet and has its own AC / DC operating circuit.
[0044] Electrical parameters: Rated power supply supports DC / AC 220V / 110V, rated AC current 5A / 1A, voltage 100V, low power consumption (power circuit ≤10W, AC circuit ≤0.5VA / phase), adaptable to the conventional electrical environment of substations.
[0045] Accuracy and reliability: current / voltage protection error ≤±2%, action time error ≤±20ms, remote signaling event resolution ≤2ms, remote control accuracy ≥99.99%, meeting the "data accuracy and real-time" requirements.
[0046] Its core functions are:
[0047] (1) Multi-channel data acquisition and transmission:
[0048] It has 4 independent network ports, which can collect raw data such as bus voltage and current in real time, and communicate with the BHE-352 communication management unit through the CAN bus and the network to upload telemetry and telesignaling data and receive remote control commands.
[0049] (2) Data processing and protection logic:
[0050] The device supports three-stage directional overcurrent protection, zero-sequence current protection, three-phase primary reclosing (with no-voltage and synchronization detection), and low-frequency load shedding, meeting the requirements of data reliability verification and fault protection. Its sudden change-triggered fault recording function (first 8 cycles + last 56 cycles, 32 sampling points per cycle) assists in data integrity verification.
[0051] (3) Safety and anti-interference design:
[0052] It has functions such as PT disconnection detection and locking protection, CT disconnection monitoring, and its anti-interference performance meets the test requirements of Level III high-frequency pulse and Level IV electrostatic discharge.
[0053] (IV) Functional scalability:
[0054] Through secondary development, the "data frame camouflage information generation" function (such as adding virtual target identification and forging priority) can be integrated. Its existing protection logic and communication protocol (supporting IEC60870-5-104, etc.) can cooperate with the BHE-352 camouflage receiving module to achieve attack obfuscation and security protection.
[0055] As the core equipment of the substation communication layer, the BHE-352 microcomputer communication management unit can cooperate with protection devices such as BHE-316 to achieve multi-protocol data interaction, load balancing and safety protection. It is suitable for the integrated automation system of 110kV and below substations.
[0056] Hardware interface configuration: Equipped with multiple network ports and CAN communication terminals, it can be connected to a dual-ring network topology and support the formation of a redundant network with four switches.
[0057] Data processing capability: Remote signaling event resolution ≤ 2ms, remote control accuracy ≥ 99.99%, supports CRC check and digital signature verification of data frames to ensure transmission reliability.
[0058] Its core functions are:
[0059] (1) Multi-protocol communication and data interaction:
[0060] It supports CAN bus and network communication, and can upload and download telemetry, telesignaling, and energy data with devices such as BHE-316. It is compatible with IEC60870-5-104, Modbus, DNP3 and other protocols.
[0061] (2) Pretend reception and attack confusion:
[0062] It has 10 built-in camouflage receiver modules (5 simulating IEC60870-5-104, 3 simulating Modbus, and 2 simulating DNP3), which can generate virtual receiving target identifiers (such as "decoy_01") to confuse attackers and record the attack source IP and time.
[0063] (3) Load balancing and data scheduling:
[0064] Real-time monitoring of data frame priority (such as the highest level 255), module load status (receiving frequency / processing time) and link failure rate prediction results, and dynamic allocation of data to the core processing module.
[0065] The management layer uses a Lenovo ThinkServer T100C server. The server builds a link status prediction model based on a Markov process, outputting a failure rate forecast for each physical link every five minutes. Based on the prediction results, combined with the load and attack conditions of the physical links, a linear programming model is used to calculate the optimal data allocation ratio, which is then sent to the microcomputer line protection and control device. The server's Bayesian network data fusion engine receives multiple data copies from the communication layer and performs weighted fusion processing based on the consistency matrix and Bayesian weighting factors.
[0066] During a data transmission, the microcomputer-based line protection and measurement and control device generated a data frame header with fictitious receiver identifiers set to "decoy_01" and "decoy_03," corresponding to the camouflaged receiver modules in the telecontrol communication management unit that simulated the IEC 60870-5-104 and Modbus protocols, respectively. The randomly generated protocol type identifier was "05" (simulating a non-existent protocol type), and the forged priority identifier was set to the highest level, "255," to confuse attackers. This camouflaged information, along with the data frame's payload (containing collected current and voltage data) and checksum (CRC checksum and digital signature), formed a complete data frame structure, which was transmitted along with redundant data copies across four physical links.
[0067] The telecontrol communication management machine's masquerading receiving module list contains information about 10 modules, including module IDs and simulated protocol types. When the microcomputer-based line protection and measurement and control device generates masquerading information for the data frame header, it randomly selects a virtual receiving target identifier from this list. If "GRASS-05" is selected as the virtual receiving target identifier, the corresponding masquerading receiving module simulates a DNP3 protocol service interface. During data frame transmission, the masquerading receiving module emulates data destined for this DNP3 protocol interface, thereby attracting the attacker's attention while concealing the actual data's intended recipient.
[0068] Of the ten masquerading receiver modules in the telecontrol communication management machine, five simulate IEC 60870-5-104 protocol service interfaces, listening on port 2404; three simulate Modbus TCP service interfaces, listening on port 502; and two simulate DNP3 service interfaces, listening on port 20000. Upon receiving a data frame, each masquerading receiver module immediately records the source device ID and receipt time. For example, when a masquerading receiver module simulating the Modbus TCP protocol receives a data frame from a source device with the ID "192.168.1.100," it records the ID and the receipt time, "2025-02-20 10:30:05," providing data support for subsequent attack analysis and security policy adjustments.
[0069] The load balancer monitors the priority field of each data frame (such as remote control command frames, which are set to the highest priority), the load status of the masquerade receiver module (determined by the frequency and processing time of data frames received by the module), and the link failure rate prediction results issued by the server in real time. If the predicted failure rate of physical link 1 increases and the load of a masquerade receiver module emulating the IEC60870-5-104 protocol is low, the load balancer redirects some data frames originally destined for other physical links to the core processing module path corresponding to that module. Upon receiving a data frame, the masquerade receiver module first compares the source device ID of the frame with a preset list of trusted devices. If the source device ID is not in the list, such as a frame from an unfamiliar IP address "10.10.10.10," the frame is immediately marked as a suspected attack frame and isolated in a dedicated secure storage area to prevent the attack from spreading.
[0070] After receiving a data frame, the core processing module first verifies the frame's CRC checksum. By recalculating the CRC value of the frame's payload and comparing it with the checksum in the header, it determines whether any errors occurred during data transmission. It then verifies the digital signature and decrypts it using the sender's public key to ensure the data has not been tampered with and is indeed from a legitimate sender. Finally, it compares the virtual recipient identifier in the disguised information with a pre-set target library to verify the legitimacy of the data frame. If the virtual recipient identifier is "decoy_02," but the pre-set target library does not contain a valid configuration corresponding to that identifier, the data frame is deemed to be authentic and rejected.
[0071] The security monitoring module of the telecontrol communication management machine continuously collects attack data recorded by the masquerade receiving module, including attack source IP addresses, attack times, and attack types (such as port scans and data tampering attempts). Machine learning algorithms, such as support vector machines (SVMs), analyze and train this attack data to identify attack patterns. When a new attack pattern is detected, such as an exploitation attack involving a previously unseen protocol vulnerability, the security monitoring module dynamically adjusts the type and number of simulated service interfaces in the masquerade receiving module based on the analysis results. This can increase the number of masquerade interfaces simulating protocols with similar vulnerabilities, tricking attackers into revealing more information while strengthening protection for the real service interfaces.
[0072] Calculation of optimal data distribution ratio:
[0073] First, calculate the failure rate weight of the physical link. Physical link states are categorized as normal, warning, and faulty. Based on historical data and state transition patterns, the Markov model predicts the probability of the physical link being in each state within the next 10 minutes (e.g., 10 minutes). For example, the predicted probability of physical link 1 being in the warning state is 20%, the probability of being in the faulty state is 5%, and the probability of being in the normal state is 75%. Weight coefficients are assigned to each state to determine its impact on the failure rate: the warning state has a smaller impact on the failure rate, so the coefficient is 0.3; the faulty state has a larger impact on the failure rate, so the coefficient is 0.7; the impact of the normal state on the failure rate is considered zero (because the failure rate is already very low). The failure rate weight is calculated as follows: failure rate weight = 0.3 × warning state probability + 0.7 × fault state probability. For example, if the warning probability of physical link 1 is 20% and the faulty probability is 5%, the failure rate weight = 0.3 × 20% + 0.7 × 5% = 0.095. The failure rate weight measures the reliability risk of the physical link; a higher weight indicates a higher probability of failure.
[0074] Next, the risk value of the physical link is calculated by comprehensively considering the failure rate weight, real-time load rate, and attack count. For example, if the current load rate of physical link 1 is 60% and the attack count is 2 (normalized to 0.4), its risk value is 0.095 + 0.6 + 0.4 = 1.095. Similarly, the risk values for physical links 2, 3, and 4 are 0.73, 1.3, and 0.3, respectively.
[0075] Finally, with the goal of minimizing overall risk, an objective function is established that includes failure rate weights, load ratios, and attack counts. Linear programming is used to determine the data allocation ratio for each physical link. Physical link 4, which carries the lowest risk, can be allocated a higher ratio (e.g., 40%), while physical link 2 can be allocated 30%. Physical links 1 and 3, which carry higher risks, can be allocated 20% and 10%, respectively. This ensures that data is preferentially transmitted over more reliable physical links, achieving dynamic load balancing and risk optimization.
[0076] The server's Bayesian network data fusion engine calculates the posterior probability of each data copy using the data frame's transmission path (e.g., physical link 1 is optical fiber, physical link 2 is microwave), the attack count of the masquerading receiver module (e.g., a module suffered five attacks in the past hour), and the predicted link failure rate (e.g., the failure rate of physical link 3 is predicted to be 10% in the next 10 minutes) as input variables. Using the Bayesian formula, the posterior probability of each data copy is calculated. For example, for the data copy from physical link 1, the posterior probability is calculated to be 0.8, combining the stability of its transmission path, the attack count of the corresponding masquerading receiver module, and the link failure rate. This probability is used for subsequent data fusion decisions.
[0077] The server's Bayesian network data fusion engine receives multiple redundant data copies from the core processing module and uses a Markov link prediction model to predict the failure rate of each transmission path. The Markov link prediction model is a link state prediction model based on Markov processes, which predicts future link states by analyzing historical failure rate data. For example, if three copies of voltage data are received from different physical links, assuming the failure rate of physical link 1 is 5%, the failure rate of physical link 2 is 8%, and the failure rate of physical link 3 is 3%, and combined with the attack counts recorded by the masquerading receiver module, for example, the attack count for physical link 1 is 2, for physical link 2 is 0, and for physical link 3 is 1, then the Bayesian weight factor for each data copy is calculated. The credibility of each data copy is then determined based on the weight factors for physical links 1, 2, and 3, which are derived through the algorithm. The data copy corresponding to the most credible physical link is selected as the primary data source for subsequent data processing and analysis.
[0078] The server verifies the selected primary data source using a consistency matrix, which records the associations and consistency relationships between different data copies. If the difference in key data fields between the primary data source and other data copies exceeds a preset threshold, such as if the primary data source for voltage data is 10.5kV, while the other copies are all between 10.2-10.3kV, with a difference exceeding 0.2kV, the verification is deemed to have failed, triggering a retransmission mechanism. When the retransmission mechanism is triggered, the server recalculates the optimal data allocation ratio based on the current load of each physical link (e.g., the load of physical link 1 is 70%, the load of physical link 2 is 30%) and the failure rate prediction results (e.g., the failure rate of physical link 3 is higher), and adjusts the data originally allocated to physical link 3 to physical link 2. The new allocation ratio is then sent to the microcomputer line protection and measurement and control device at the equipment layer, which retransmits the data according to the new ratio.
[0079] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0080] In various embodiments, the hardware implementation of the technology can directly utilize existing intelligent devices, including but not limited to industrial computers, personal computers, smart phones, handheld computers, floor-standing computers, etc. The input device preferably utilizes an on-screen keyboard, the data storage and calculation modules utilize existing memories, calculators, and controllers, the internal communication modules utilize existing communication ports and protocols, and remote communication utilizes existing GPRS networks, the World Wide Web, etc.
[0081] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0082] In the embodiments provided by the present invention, it should be understood that the disclosed apparatus / terminal equipment and methods can be implemented in other ways. For example, the apparatus / terminal equipment embodiments described above are merely schematic. For example, the division of modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of the apparatus or unit, which can be electrical, mechanical or other forms. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the scheme of this embodiment.
[0083] The functional units in the various embodiments of the present invention may be integrated into a single processing unit, each unit may exist physically separately, or two or more units may be integrated into a single unit. These integrated units may be implemented in either hardware or software functional units. If the integrated modules / units are implemented as software functional units and sold or used as standalone products, they may be stored on a computer-readable storage medium. Based on this understanding, the present invention may also implement all or part of the process steps in the above-described method embodiments by instructing the relevant hardware through a computer program. The computer program may be stored on a computer-readable storage medium, and when executed by a processor, the computer program may implement the steps of the above-described method embodiments. The computer program includes computer program code, which may be in source code, object code, executable files, or some intermediate form. Computer-readable media may include any entity or device capable of carrying computer program code, recording media, USB flash drives, removable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunications signals, and software distribution media.
[0084] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A multi-channel substation integrated automation system, comprising a device layer, a communication layer and a management layer; characterized in that: The equipment layer includes a microcomputer line protection, measurement, and control device configured with four independent network ports, each of which is connected to a physical link. The microcomputer line protection, measurement, and control device is configured to collect original data and encode it into multiple redundant data copies, generate a data frame header including camouflage information for each data copy, and then transmit the redundant data copies in parallel to the four physical links through the four independent network ports according to the optimal data distribution ratio issued by the server. The communication layer includes four Ethernet switches and a telecontrol communication management machine. The four Ethernet switches form a dual-ring interconnection topology through four interconnection links. The telecontrol communication management machine is connected to two different switches in the dual-ring network through dual network ports. The telecontrol communication management machine is equipped with: multiple camouflage receiving modules that simulate service interfaces of different protocol types and are used to receive and record data frames including camouflage information; Load balancer, used to distribute received data frames to core processing modules according to preset strategies; The core processing module is used to check and convert the data frames and transmit the processed data frames to the server; The management layer includes a server configured to: construct a link status prediction model based on a Markov process, output a failure rate prediction for each physical link, calculate an optimal data allocation ratio using a linear programming model based on the failure rate prediction and in combination with the load and attack status of the physical link, and transmit the optimal data allocation ratio to the microcomputer line protection measurement and control device; Through the Bayesian network data fusion engine, combined with the consistency matrix and Bayesian weight factor, each data copy is weightedly fused.
2. The multi-channel substation integrated automation system according to claim 1, characterized in that: The disguised information in the data frame header is used to confuse potential network attacks, including: at least two virtual receiving target identifiers, a randomly generated protocol type identifier and a forged priority identifier; the disguised information and the payload part and check part of the data frame together constitute a complete data frame structure.
3. The multi-channel substation integrated automation system according to claim 2, characterized in that: The virtual receiving target identifier is randomly selected from the masquerading receiving module list of the telecontrol communication management machine, and the virtual receiving target identifier corresponds to the service interface type of the masquerading receiving module.
4. The multi-channel substation integrated automation system according to claim 2, characterized in that: The camouflaged receiving module supports simulating service interfaces of at least three protocol types, including IEC 60870-5-104, Modbus, and DNP3. Each camouflaged receiving module independently records the source device ID and receiving time of the received data frame.
5. The multi-channel substation integrated automation system according to claim 4, characterized in that: The load balancer distributes the data frames to the core processing module according to the priority of the data frames, the load status of the camouflage receiving module and the link failure rate prediction result; After receiving the data frame, the disguised receiving module first determines whether the source device ID of the data frame is in the preset trusted device list. If not, it is marked as a suspected attack data frame and isolated and stored.
6. The multi-channel substation integrated automation system according to claim 5, characterized in that: The core processing module verifies the data frame by verifying the CRC check code and digital signature of the data frame, and judging the authenticity of the data frame by comparing the virtual receiving target identifier in the disguised information with the preset target library.
7. The multi-channel substation integrated automation system according to claim 6, characterized in that: The telecontrol communication management machine is also equipped with a security monitoring module, which identifies attack patterns based on the attack data recorded by the disguised receiving module and the machine learning algorithm, and dynamically adjusts the type and number of simulated service interfaces of the disguised receiving module.
8. The multi-channel substation integrated automation system according to claim 1, characterized in that: The optimal data allocation ratio is calculated by classifying the physical link status into three categories: normal, warning, and fault. A state transition matrix is obtained based on historical data training to predict the probability of the physical link being in different states in the future. The failure rate weight of the physical link is then calculated based on the weighted matrix. The risk value of a physical link is calculated by comprehensively considering the failure rate weight, real-time load rate, and attack count of the physical link. With the goal of minimizing the comprehensive risk, an objective function including failure rate weight, load rate and attack count is established, and the data allocation ratio of each physical link is solved through linear programming.
9. The multi-channel substation integrated automation system according to claim 1, characterized in that: The fusion steps of the Bayesian network data fusion engine include: receiving multiple redundant data copies from the core processing module; obtaining the failure rate prediction results of each transmission path based on the Markov link prediction model; calculating the Bayesian weight factor of each data copy in combination with the attack count recorded by the camouflage receiving module; determining the credibility of each data copy based on the Bayesian weight factor, and selecting the data copy with the highest credibility as the main data source.
10. The multi-channel substation integrated automation system according to claim 9, characterized in that: The server is also configured to: verify the main data source in combination with the consistency matrix, and use the data if the verification passes, otherwise trigger the retransmission mechanism; when the retransmission mechanism is triggered, the server recalculates the optimal data distribution ratio based on the current load and failure rate prediction results of each physical link, and sends it to the microcomputer line protection measurement and control device at the equipment layer for retransmission.
Citation Information
Patent Citations
Blade server system with rack-switch
WO2006093929A2
Data link service processing system and method for networked encrypted transmission
WO2023216424A1