Power terminal data authentication method and system based on network identification dynamic binding
By generating dynamic network identifiers and time-series authentication tags, the security threat to power terminal data is solved, dynamic authentication and binding of data are realized, and the data security and authentication efficiency of the power system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- STATE GRID SHANDONG ELECTRIC POWER CO
- Filing Date
- 2025-05-27
- Publication Date
- 2026-05-05
AI Technical Summary
Power terminals face complex security threats such as data tampering, malicious attacks, and unauthorized access, which affect the reliable operation of the power system. Furthermore, existing technologies are insufficient to effectively guarantee the integrity and legitimacy of data sources.
By acquiring terminal operation data and network topology data from power terminals, dynamic network identifier generation parameters are generated, dynamic network identifiers are allocated, and combined with time-series authentication tags and real-time authentication rules, dynamic authentication and binding of power terminal data are achieved, forming a data set with time-series authentication tags, and the authentication strategy is dynamically adjusted to adapt to environmental changes.
It enhances the security and reliability of power terminal data, achieves data immutability and traceability, improves the accuracy and adaptability of authentication, and ensures the integrity and legality of data during transmission and storage.
Smart Images

Figure CN120567470B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and more specifically, to a method and system for power terminal data authentication based on dynamic binding of network identifiers. Background Technology
[0002] In modern power systems, power terminals, as key devices for data acquisition, transmission, and control command execution, generate data that plays a crucial role in the safe and stable operation of the power system. This data not only reflects the real-time operating status of power equipment but also provides important information for power system dispatching decisions, fault diagnosis, and maintenance management. However, with the continuous expansion of power system scale and the increasing level of intelligence, power terminals face increasingly complex security threats, such as data tampering, malicious attacks, and unauthorized access. These security issues seriously threaten the reliable operation of the power system. Therefore, ensuring the integrity, legality of the source, and security of power terminal data has become a critical issue that urgently needs to be addressed in the field of power system security. Summary of the Invention
[0003] In view of the aforementioned problems, and in conjunction with the first aspect of the present invention, embodiments of the present invention provide a power terminal data authentication method based on dynamic binding of network identifiers, the method comprising:
[0004] Acquire the terminal operation data set and associated network topology data set of the target power terminal within a preset time window, and generate dynamic network identifier generation parameters based on the terminal operation data set. The dynamic network identifier generation parameters include terminal status fluctuation characteristics, network communication quality characteristics and environmental interference characteristics.
[0005] Based on the dynamic network identifier generation parameters and the associated network topology data set, a dynamic network identifier allocation operation is performed to generate a dynamic network identifier sequence corresponding to the target power terminal. The dynamic network identifier sequence contains multiple dynamic network identifiers, and each dynamic network identifier is associated with a sub-time period within the time window.
[0006] Dynamic binding processing is performed on the dynamic network identifier sequence and the terminal operation data set to generate a power terminal data set with a time-series authentication tag, wherein the time-series authentication tag is used to verify the integrity and source legitimacy of the power terminal data set;
[0007] Based on a preset set of real-time authentication rules, the power terminal data set with time-series authentication tags is dynamically authenticated and matched to generate an authentication result set and authentication strategy adjustment parameters. The authentication strategy adjustment parameters are used to dynamically adjust the generation logic of the dynamic network identifier generation parameters.
[0008] The dynamic network identifier generation parameters are updated based on the authentication result set and the authentication strategy adjustment parameters, and the updated dynamic network identifier generation parameters are synchronized to the target power terminal to trigger the data authentication iteration of the next time window.
[0009] In another aspect, embodiments of the present invention also provide a power terminal data authentication system based on dynamic binding of network identifiers, including a processor and a machine-readable storage medium connected to the processor. The machine-readable storage medium is used to store programs, instructions or code, and the processor is used to execute the programs, instructions or code in the machine-readable storage medium to implement the above-described method.
[0010] Based on the above, this embodiment of the invention first integrates the terminal operation data set and associated network topology data set of the target power terminal within a preset time window, extracting key information such as terminal status fluctuation characteristics, network communication quality characteristics, and environmental interference characteristics to generate dynamic network identifier generation parameters. Based on these parameters and the associated network topology data set, a dynamic network identifier allocation operation is performed to generate a dynamic network identifier sequence corresponding to the target power terminal. Each dynamic network identifier is associated with a sub-time period within the time window, enhancing not only the uniqueness and timeliness of the identifier but also effectively addressing potential operational changes and network fluctuations that may occur in the power terminal at different times. By dynamically binding the dynamic network identifier sequence with the terminal operation data set, a power terminal data set with a time-series authentication tag is generated. This tag serves as a verification basis for data integrity and source legitimacy, achieving deep integration of data and identifiers. This ensures that the data possesses tamper-proof and traceable characteristics during transmission and storage, significantly improving data security and reliability. Furthermore, based on a preset set of real-time authentication rules, dynamic authentication matching is performed on the power terminal data set with time-series authentication tags to generate an authentication result set and authentication strategy adjustment parameters. These parameters dynamically adjust the generation logic of the dynamic network identifier generation parameters, forming a feedback adjustment mechanism. This allows the authentication process to continuously optimize the dynamic network identifier generation parameters based on real-time authentication results, adapting to the constantly changing operating environment and data characteristics of the power terminals, thus improving the accuracy and adaptability of authentication. Finally, the dynamic network identifier generation parameters are updated according to the authentication result set and the authentication strategy adjustment parameters, and the updated parameters are synchronized to the target power terminal to trigger the next time window's data authentication iteration. This achieves continuous evolution and dynamic optimization of data authentication, automatically adapting to dynamic changes in the power terminal's operating environment and data characteristics. While ensuring data security and integrity, it improves the efficiency and accuracy of authentication. Attached Figure Description
[0011] Figure 1This is a schematic diagram of the execution flow of the power terminal data authentication method based on dynamic binding of network identifiers provided in an embodiment of the present invention.
[0012] Figure 2 This is a schematic diagram of exemplary hardware and software components of the power terminal data authentication system based on dynamic binding of network identifiers provided in an embodiment of the present invention. Detailed Implementation
[0013] The present invention will now be described in detail with reference to the accompanying drawings. Figure 1 This is a flowchart illustrating a power terminal data authentication method based on dynamic binding of network identifiers according to an embodiment of the present invention. The following is a detailed description of the power terminal data authentication method based on dynamic binding of network identifiers.
[0014] Step S110: Obtain the terminal operation data set and associated network topology data set of the target power terminal within a preset time window, and generate dynamic network identifier generation parameters based on the terminal operation data set. The dynamic network identifier generation parameters include terminal status fluctuation characteristics, network communication quality characteristics, and environmental interference characteristics.
[0015] In this embodiment, the preset time window can be set to one day to fully capture changes in the operating characteristics of the target power terminal. The target power terminal is equipped with various sensors to collect various operating data in real time. The terminal operating data set covers various operating indicators of the power terminal within that day, such as voltage, current, power, and temperature. The associated network topology data set is obtained from the network management system, which records in detail the topology of the network where the target power terminal is located, including the location of each node, connection relationships, and link bandwidth.
[0016] For example, voltage data in the terminal operation dataset is recorded at a sampling point every 10 minutes, totaling 144 data points per day; current data is also sampled every 10 minutes, while power data is sampled every 15 minutes. Environmental interference fluctuation data is collected by electromagnetic interference sensors and meteorological sensors installed near the power terminal, recording changes in electromagnetic interference intensity and meteorological conditions, respectively.
[0017] Step S111: Extract edge node communication delay data, power terminal status change data, and environmental interference fluctuation data from the terminal operation data set.
[0018] In this embodiment, data filtering and classification algorithms can be used to extract the required data from the terminal's operational data set. For edge node communication delay data, the delay time for each communication is obtained by recording the timestamps of data sent from the target power terminal to the edge node and the timestamps of data received by the edge node, and calculating the difference between the two. For example, within a day, a total of 720 communication delay data points are recorded, forming a delay data sequence containing 720 elements.
[0019] The extraction of power terminal status transition data is achieved by monitoring the status flag bits of the power terminal. When a status flag bit changes, the time of the change and the status information before and after it are recorded. For example, a power terminal may have three operating states: normal operation, standby, and fault. If 20 status transitions occur in a day, these transition information are compiled into a status transition dataset containing 20 records.
[0020] The extraction of environmental interference fluctuation data is based on data from different types of sensors. The electromagnetic interference sensor records the interference intensity every 5 minutes, recording a total of 288 data points per day; the meteorological sensor records meteorological conditions, such as temperature, humidity, and wind speed, every 15 minutes, recording a total of 96 sets of meteorological data per day. The above data are combined into an environmental interference fluctuation dataset.
[0021] Step S112: Extract delay fluctuation features from the edge node communication delay data to generate network communication quality features, wherein the network communication quality features include the mean communication delay, the delay variance, and the delay peak interval.
[0022] In this embodiment, the average communication delay is first calculated by summing the 720 communication delay data points to obtain the total delay time, and then dividing by 720 to obtain the average communication delay. Assuming the 720 delay data points are t1, t2, ..., t720, and the total delay time is t1 + t2 + ... + t720, the average communication delay is (t1 + t2 + ... + t720) ÷ 720.
[0023] Next, the delay variance is calculated. For each delay data point ti, the difference between it and the mean communication delay is calculated. The squares of these differences are then summed, and the result is divided by 720 to obtain the delay variance. The specific calculation process is as follows: First, calculate each difference (ti - mean communication delay). Then, square these differences to obtain (ti - mean communication delay)². Sum all the (ti - mean communication delay)² values and finally divide by 720.
[0024] The peak delay interval is calculated by identifying peak points in the delayed data sequence. A threshold is set; when delayed data exceeds this threshold, it is considered a peak point. The time intervals between two adjacent peak points are recorded to obtain the peak delay interval sequence. For example, in 720 delayed data points, 10 peak points are identified, and the 9 interval times between these 10 peak points are calculated, forming a peak delay interval sequence containing 9 elements.
[0025] The calculated mean delay, variance delay, and peak delay interval sequence are combined to form a network communication quality feature. This network communication quality feature is a multi-dimensional dataset containing a mean value, a variance value, and an interval sequence.
[0026] Step S113: Perform state trend analysis on the power terminal state transition data to generate terminal state fluctuation characteristics, which include state transition frequency, state duration and state anomaly deviation.
[0027] In this embodiment, the state transition frequency is calculated by dividing the number of state transitions in a day (20) by the total duration of a day (24 hours), resulting in a state transition frequency of approximately 0.83 times per hour (20 ÷ 24 ≈ 0.83 times / hour).
[0028] The duration of a state is calculated based on the time information in the state transition data. For each state transition, the duration from the start of that state to the next transition is calculated. For example, the first state transition is from normal operation to standby. The start time of the normal operation state and the start time of the standby state are recorded, and the difference between the two is the duration of the normal operation state. The durations of all states are recorded to form a sequence of 20 state durations.
[0029] Calculating the deviation from normal operating conditions requires first defining the range of normal state changes. For various operating parameters of a power terminal, such as voltage, current, and power, there is a normal fluctuation range. When a state transition occurs, it is checked whether the relevant operating parameters exceed the normal range. If they do, the degree of excess is calculated as the deviation from normal operating conditions. For example, if the normal voltage range is 210V-230V, and the voltage changes to 240V during a state transition, exceeding the normal range by 10V, this 10V deviation is taken as the deviation from normal operating conditions for that transition. All deviations from normal operating conditions are recorded, forming a sequence of 20 elements representing the deviation from normal operating conditions.
[0030] By combining the sequence of state transition frequency, state duration, and state anomaly deviation, the terminal state fluctuation characteristics are formed, constituting a multi-dimensional dataset.
[0031] Step S114: Quantify the interference intensity of the environmental interference fluctuation data to generate environmental interference features, which include interference signal amplitude, interference duration and interference frequency band distribution.
[0032] In this embodiment, the amplitude of the interference signal is determined by finding the maximum value among the 288 interference intensity data recorded by the electromagnetic interference sensor, which is then used as the amplitude of the interference signal.
[0033] The duration of interference is calculated based on interference intensity data. Specifically, an interference intensity threshold is set; when the interference intensity exceeds this threshold, interference is considered to have occurred. The start and end times of the interference are recorded, and the difference between the two times is calculated to obtain the interference duration. For example, if five interference events occur in a day, the durations of these five events are calculated, forming a sequence of interference durations containing five elements.
[0034] The analysis of interference frequency band distribution involves performing spectral analysis on the electromagnetic interference signal. The interference signal is decomposed into components of different frequencies, and the energy distribution of each frequency band is statistically analyzed. For example, the frequency range can be divided into 10 frequency bands, and the proportion of energy in the interference signal for each band can be statistically analyzed, forming an interference frequency band distribution sequence containing 10 elements.
[0035] Therefore, by combining the amplitude of the interference signal, the duration of the interference, and the frequency band distribution sequence of the interference, environmental interference characteristics are formed.
[0036] Step S115: The network communication quality characteristics, terminal status fluctuation characteristics and environmental interference characteristics are fused in multiple dimensions to generate dynamic network identifier generation parameters.
[0037] When performing multi-dimensional fusion, a weighted splicing method can be used. For example, a weight of 0.3 can be assigned to network communication quality characteristics, a weight of 0.4 to terminal state fluctuation characteristics, and a weight of 0.3 to environmental interference characteristics.
[0038] First, the network communication quality characteristics, terminal state fluctuation characteristics, and environmental interference characteristics are normalized. The average communication delay, delay variance, state transition frequency, and interference signal amplitude are normalized to the [0, 1] interval to facilitate subsequent splicing operations.
[0039] Then, the network communication quality characteristics, terminal status fluctuation characteristics, and environmental interference characteristics are concatenated according to their weights. For example, the data of each dimension of the network communication quality characteristics are scaled with a weight of 0.3, the data of each dimension of the terminal status fluctuation characteristics are scaled with a weight of 0.4, and the data of each dimension of the environmental interference characteristics are scaled with a weight of 0.3. Finally, the three scaled feature data are concatenated together to form a dynamic network identifier generation parameter. This dynamic network identifier generation parameter is a long sequence of data containing multiple dimensions, comprehensively reflecting the operating status of the power terminal, network communication quality, and environmental interference.
[0040] Step S120: Based on the dynamic network identifier generation parameters and the associated network topology data set, perform a dynamic network identifier allocation operation to generate a dynamic network identifier sequence corresponding to the target power terminal. The dynamic network identifier sequence contains multiple dynamic network identifiers, and each dynamic network identifier is associated with a sub-time period within the time window.
[0041] In this embodiment, a day's time window can be divided into 24 sub-time periods, each lasting one hour. When performing the dynamic network identifier allocation operation, it is necessary to combine the dynamic network identifier generation parameters and information from the associated network topology data set.
[0042] Step S121: Parse the associated network topology data set to determine the node distribution characteristics and link load characteristics of the network partition where the target power terminal is located.
[0043] In this embodiment, the associated network topology data set is parsed. By analyzing the network topology map and node information, the node distribution characteristics of the network partition where the target power terminal is located are determined. Node distribution characteristics include the number, location, and connection relationships of nodes. For example, if the network partition has 10 nodes, the specific coordinates of each node can be determined using a Geographic Information System (GIS). These coordinates are then organized into a node location sequence containing 10 coordinate pairs. Simultaneously, the connection relationships between nodes are recorded, forming a connection matrix. The elements in the connection matrix indicate whether a connection exists between nodes.
[0044] Link load characteristics are determined by monitoring the bandwidth usage of each link in the network. The bandwidth utilization rate of each link is recorded every 15 minutes throughout the day. For the five links in this network partition, a total of 96 data points are recorded per day, forming a 5-row, 96-column link bandwidth utilization matrix. By analyzing this matrix, the average bandwidth utilization rate, maximum bandwidth utilization rate, and bandwidth utilization fluctuation range of each link are calculated as the link load characteristics.
[0045] Step S122: Determine the set of neighbor node identifiers of the target power terminal based on the node distribution characteristics, and calculate the communication priority weight of the target power terminal based on the link load characteristics.
[0046] In this embodiment, based on the connection matrix in the node distribution characteristics, the nodes directly connected to the target power terminal are identified. These nodes are the neighbor nodes of the target power terminal. Assuming the target power terminal is directly connected to three nodes, and the identifiers of these three nodes are ID1, ID2, and ID3 respectively, then the set of neighbor node identifiers = {ID1, ID2, ID3}.
[0047] The communication priority weight of the target power terminal is calculated based on link load characteristics. For each link between the target power terminal and its neighboring nodes, a comprehensive score is calculated based on its average bandwidth utilization, maximum bandwidth utilization, and bandwidth utilization fluctuation range. Links with lower average bandwidth utilization, lower maximum bandwidth utilization, and smaller bandwidth utilization fluctuation ranges receive higher comprehensive scores. For example, if the link between the target power terminal and neighboring node ID1 has an average bandwidth utilization of 20%, a maximum bandwidth utilization of 30%, and a bandwidth utilization fluctuation range of 10%, a comprehensive score for this link is obtained using a pre-defined calculation method. Comprehensive scores are calculated for all links between the target power terminal and its neighboring nodes, and these scores are then normalized to obtain the communication priority weight corresponding to each neighboring node. Assume the communication priority weights for ID1, ID2, and ID3 are 0.4, 0.3, and 0.3, respectively.
[0048] Step S123: Generate the basic encoding of the dynamic network identifier based on the terminal state fluctuation characteristics and environmental interference characteristics in the dynamic network identifier generation parameters.
[0049] In this embodiment, terminal state fluctuation features and environmental interference features can be extracted from the dynamic network identifier generation parameters. The state transition frequency, state duration sequence, and state anomaly deviation sequence in the terminal state fluctuation features, and the interference signal amplitude, interference duration sequence, and interference frequency band distribution sequence in the environmental interference features are encoded.
[0050] First, these feature data are quantized and converted into binary codes. For example, a state transition frequency of 0.83 times / hour is converted into an 8-bit binary code. For sequence data, each element is sequentially converted into a binary code and then concatenated. The encoding results of terminal state fluctuation characteristics and environmental interference characteristics are concatenated in a specific order to form the basic dynamic network identifier code. This basic dynamic network identifier code is a relatively long binary sequence containing information on the state fluctuations and environmental interference of the power terminal.
[0051] Step S124: Adjust the weighted basic encoding of the dynamic network identifier according to the communication priority weight to generate a weighted dynamic encoding.
[0052] In this embodiment, communication priority weights can be applied to the dynamic network identifier base code. For each bit in the dynamic network identifier base code, the weights are adjusted according to the communication priority weights of its corresponding neighboring nodes. Assuming the dynamic network identifier base code is a binary sequence of length 100, for the i-th bit, if it is related to neighboring node ID1 and ID1's communication priority weight is 0.4, then the importance of that bit is increased by a factor of 0.4. This can be achieved using a weighting matrix, where each element corresponds to the weight of each bit. Multiplying the dynamic network identifier base code bit by bit with the weighting matrix yields the weighted encoding sequence, i.e., the weighted dynamic code.
[0053] Step S125: Concatenate the weighted dynamic code with the neighbor node identifier set to generate an initial dynamic network identifier sequence.
[0054] The weighted dynamic code is concatenated with the set of neighbor node identifiers. First, the neighbor node identifiers ID1, ID2, and ID3 are converted into binary codes. Then, these codes are concatenated sequentially to the weighted dynamic code to form the initial dynamic network identifier sequence. For example, if the weighted dynamic code is 100 bits long, and the binary codes for ID1, ID2, and ID3 are 8 bits, 8 bits, and 8 bits long respectively, then the length of the concatenated initial dynamic network identifier sequence is 100 + 8 + 8 + 8 = 124 bits.
[0055] Step S126: Divide the initial dynamic network identifier sequence into time windows to obtain the dynamic network identifier sequence, wherein each dynamic network identifier corresponds to a sub-time period and includes a timestamp check code.
[0056] For example, the 24 sub-segments of a day are numbered 0-23. For each sub-segment, a segment of the same length is extracted from the initial dynamic network identifier sequence as the base part of the dynamic network identifier for that sub-segment. Then, a timestamp checksum is added to each dynamic network identifier. The timestamp checksum is generated based on the sub-segment number; for example, the timestamp checksum for sub-segment 0 could be an 8-bit binary code associated with 0. The timestamp checksum is concatenated to the base part of the dynamic network identifier to obtain the complete dynamic network identifier. This results in a dynamic network identifier sequence containing 24 dynamic network identifiers, each corresponding to a sub-segment of one hour.
[0057] Step S130: Perform dynamic binding processing on the dynamic network identifier sequence and the terminal operation data set to generate a power terminal data set with a time-series authentication tag, wherein the time-series authentication tag is used to verify the integrity and source legitimacy of the power terminal data set.
[0058] After obtaining the dynamic network identifier sequence and the terminal operation data set, dynamic binding processing can be performed to ensure the security and traceability of power terminal data.
[0059] Step S131: Align the dynamic network identifier sequence with the terminal running data set according to sub-time periods to generate an aligned data set.
[0060] For example, the first dynamic network identifier in the dynamic network identifier sequence corresponds to the data in the 0:00-1:00 sub-time period of the terminal operation data set. For the terminal operation data in this sub-time period, including data such as voltage, current, and power, it is combined with the first dynamic network identifier to form a data pair. This operation is performed on all 24 sub-time periods to obtain 24 data pairs, which are then combined to form an aligned data set.
[0061] Step S132: Perform hash binding processing on each sub-period data in the aligned data set to generate a primary bound data set, wherein the hash binding processing adopts a dynamic hash algorithm and the hash seed is dynamically adjusted based on the environmental interference characteristics in the dynamic network identifier generation parameters.
[0062] Hash binding is performed on the data for each sub-time period in the aligned dataset. A dynamic hashing algorithm is used, and the hash seed is dynamically adjusted based on the environmental interference features in the dynamic network identifier generation parameters. First, environmental interference features are extracted from the dynamic network identifier generation parameters, including the interference signal amplitude, interference duration sequence, and interference frequency band distribution sequence. These feature data are combined and processed to generate a hash seed.
[0063] For each data pair in each sub-time period, the terminal running data and the corresponding dynamic network identifier are concatenated to form a string to be hashed. This string is then hashed using a dynamic hash algorithm and a generated hash seed to obtain a hash value. This hash value is combined with the original data pair to form a new data item. This process is repeated for all 24 data pairs in the sub-time periods, resulting in 24 new data items. These data items are then combined to form the initial bound data set.
[0064] Step S133: Perform timestamp synchronization encryption processing on the primary binding data set to generate a power terminal data set with a time-series authentication tag, wherein the timestamp synchronization encryption processing includes performing a bidirectional XOR operation between the timestamp verification code in the dynamic network identifier and the primary binding data set.
[0065] Perform timestamp synchronization encryption on the primary binding data set. For each data item in the primary binding data set, extract the timestamp checksum from the corresponding dynamic network identifier. Perform a bidirectional XOR operation on the timestamp checksum, the terminal runtime data in the data item, and the hash value.
[0066] Specifically, a bitwise XOR operation is performed between the timestamp checksum and the binary encoding of the terminal operation data to obtain the encrypted terminal operation data. Similarly, a bitwise XOR operation is performed between the timestamp checksum and the binary encoding of the hash value to obtain the encrypted hash value. The encrypted terminal operation data, the encrypted hash value, and the timestamp checksum are combined to form a data item with a time-series authentication tag. This process is repeated for all 24 data items to obtain 24 data items with time-series authentication tags. These data items are then combined to form a power terminal data set with time-series authentication tags.
[0067] Step S134: Verify the integrity and consistency of the time-series authentication tag. If there are inconsistent tags, regenerate the dynamic network identifier sequence based on the associated network topology data set and re-execute the dynamic binding process.
[0068] The integrity and consistency of time-series authentication tags in the power terminal data set with time-series authentication tags are verified. Integrity verification mainly checks whether the timestamp checksum, encrypted terminal operation data, and encrypted hash value are complete and without missing or corrupted information. Consistency verification checks whether the correspondence between the timestamp checksum and the sub-time period is correct, and whether the encrypted hash value is consistent with the recalculated hash value.
[0069] The specific verification process is as follows: For each data item with a time-series authentication tag, firstly, the timestamp checksum is extracted, and the correctness of its corresponding sub-time period is determined based on the timestamp checksum. Then, the encrypted terminal operation data and the timestamp checksum are XORed in reverse to obtain the original terminal operation data. The same dynamic hash algorithm and hash seed are used to hash the original terminal operation data and the corresponding dynamic network identifier to obtain a new hash value. This new hash value is XORed in reverse with the encrypted hash value to obtain the decrypted hash value. The decrypted hash value is compared with the newly calculated hash value. If they match, the time-series authentication tag is complete and consistent; if they do not match, the time-series authentication tag has a problem.
[0070] When inconsistent labels are detected, it is necessary to regenerate the dynamic network identifier sequence based on the associated network topology data set and re-execute the dynamic binding process. First, the associated network topology data set is parsed again to redetermine the node distribution characteristics and link load characteristics of the network partition where the target power terminal is located. This step is similar to the previous step S121, but this parsing may yield different results due to real-time changes in network status. For example, the bandwidth usage of some links may have changed, or new nodes may have joined or left the network.
[0071] When redetermining node distribution characteristics, the number of nodes within the network partition is counted again, the location coordinates of each node are obtained, and the connection relationships between nodes are clarified. If a new node joins the network partition later in the day, the number of nodes will increase, and the node location sequence and connection matrix need to be updated accordingly. Regarding link load characteristics, the bandwidth usage of each link is monitored again. Based on the latest 96 bandwidth utilization data points (recorded every 15 minutes throughout the day), the average bandwidth utilization, maximum bandwidth utilization, and bandwidth utilization fluctuation range for each link are recalculated.
[0072] Next, based on the newly determined node distribution characteristics, the set of neighbor node identifiers for the target power terminal is determined, and the communication priority weight of the target power terminal is calculated based on the new link load characteristics. This is the same operation as in step S122. Due to changes in network status, the set of neighbor node identifiers may differ, and the communication priority weights will be adjusted accordingly. For example, newly added nodes may become neighbor nodes of the target power terminal, or changes in the load of a certain link may cause its corresponding communication priority weight to change.
[0073] Next, the basic code for the dynamic network identifier is regenerated based on the terminal state fluctuation characteristics and environmental interference characteristics in the dynamic network identifier generation parameters. This step is consistent with step S123. However, because the operating state of the power terminal and the environmental interference situation may change over time, the generated basic code for the dynamic network identifier may also be different. For example, if the frequency of state transitions of the power terminal increases or the amplitude of interference signals in the environment increases during a certain sub-period, the basic code for the dynamic network identifier will change.
[0074] The newly generated dynamic network identifier base code is then weighted according to the newly calculated communication priority weights to generate a weighted dynamic code, as in step S124. The new communication priority weights will weight each bit of the dynamic network identifier base code to different degrees, thus obtaining different weighted dynamic codes.
[0075] The weighted dynamic code is concatenated with the new set of neighbor node identifiers to generate a new initial dynamic network identifier sequence, similar to the operation in step S125. Since both the set of neighbor node identifiers and the weighted dynamic code may change, the new initial dynamic network identifier sequence will also differ from the previous one.
[0076] The new initial dynamic network identifier sequence is divided into time windows to obtain a new dynamic network identifier sequence. Each dynamic network identifier corresponds to a sub-time period and contains a timestamp check code, which is consistent with step S126.
[0077] After obtaining the new dynamic network identifier sequence, the dynamic binding process is re-executed. First, the new dynamic network identifier sequence is aligned with the terminal operation data set by sub-time period to generate a new aligned data set, as in step S131. Then, hash binding is performed on the data of each sub-time period in the new aligned data set to generate a new primary binding data set. During this process, the hash seed is still dynamically adjusted based on the environmental interference characteristics in the dynamic network identifier generation parameters, consistent with step S132. Next, timestamp synchronization encryption is performed on the new primary binding data set to generate a new power terminal data set with time-series authentication tags, including performing a bidirectional XOR operation between the timestamp checksum in the dynamic network identifier and the primary binding data set, the same as step S133. Finally, the integrity and consistency of the new time-series authentication tags are verified again. If inconsistent tags still exist, the above regeneration and rebinding process is repeated until all time-series authentication tags are complete and consistent.
[0078] Step S140: Based on a preset set of real-time authentication rules, perform dynamic authentication matching processing on the power terminal data set with time-series authentication tags to generate an authentication result set and authentication strategy adjustment parameters. The authentication strategy adjustment parameters are used to dynamically adjust the generation logic of the dynamic network identifier generation parameters.
[0079] After obtaining the power terminal data set with time-series authentication tags, dynamic authentication matching processing begins according to a preset set of real-time authentication rules. This preset set of real-time authentication rules was developed based on extensive historical data and security requirement analysis, and includes a series of rules for determining the legality and integrity of the data.
[0080] Step S141: Parse the dynamic network identifier code and timestamp verification code in the time-series authentication tag to generate an authentication input feature set.
[0081] Each time-series authentication tag in the power terminal data set with time-series authentication tags is parsed. First, the dynamic network identifier code is extracted, which contains information such as terminal state fluctuation characteristics, environmental interference characteristics, and neighbor node identifiers. Then, this information is broken down and organized. For example, the state transition frequency, state duration sequence, and state anomaly deviation sequence in the terminal state fluctuation characteristics are extracted separately. The interference signal amplitude, interference duration sequence, and interference frequency band distribution sequence in the environmental interference characteristics are also extracted separately. At the same time, the neighbor node identifier is extracted.
[0082] For the timestamp checksum, its corresponding sub-period information is recorded. The information extracted from the dynamic network identifier encoding and the sub-period information corresponding to the timestamp checksum are combined to form a multi-dimensional authentication input feature set. For example, the authentication input feature set may contain a value representing the state transition frequency, a sequence containing the state duration, a sequence containing the state anomaly deviation, an interference signal amplitude value, a sequence containing the interference duration, a sequence containing the interference frequency band distribution, a set containing neighbor node identifiers, and a sub-period number.
[0083] Step S142: Call the preset authentication matching model to process the authentication input feature set and generate a preliminary authentication result, wherein the authentication matching model is trained based on historical authentication data and the input and output dimensions are consistent with the dimensions of the authentication input feature set.
[0084] The pre-defined authentication matching model is trained on a large amount of historical authentication data. This historical authentication data includes the authentication input feature set under different conditions and the corresponding authentication results (success or failure). During training, machine learning algorithms, such as neural network algorithms, are used to adjust the parameters of the authentication matching model so that the model can accurately predict the authentication result based on the input authentication feature set.
[0085] The generated set of authentication input features is input into a preset authentication matching model. The authentication matching model can analyze and calculate the input features. After a series of calculations and judgments, the authentication matching model outputs a preliminary authentication result. The preliminary authentication result can be a numerical value representing the credibility of the authentication. The higher the value, the greater the probability of successful authentication. It can also be a classification label, such as "authentication successful" or "authentication failed".
[0086] Step S143: Based on the network communication quality characteristics in the dynamic network identifier generation parameters, perform communication delay compensation on the primary authentication result to generate a compensated authentication result.
[0087] In this embodiment, network communication quality features are extracted from the dynamic network identifier generation parameters, including the mean communication delay, the variance of the delay, and the peak delay interval. Communication delay may affect the accuracy of the authentication result because data may be delayed during transmission, leading to a deviation in the correspondence between the timestamp checksum and the data.
[0088] The initial authentication results are adjusted based on the mean and variance of communication delays. A large mean communication delay indicates generally slow data transmission, which may negatively impact the authentication results, necessitating appropriate corrections. For example, a compensation value related to the mean and variance of communication delays can be subtracted from the initial authentication results using a pre-defined compensation formula.
[0089] For peak delay intervals, a short interval indicates potential sudden and significant fluctuations in communication latency, which can affect authentication results. The compensation value can be adjusted based on the magnitude of the peak delay interval. For example, when the peak delay interval is below a certain threshold, the compensation value can be increased. These adjustments generate compensated authentication results, making the authentication results more accurately reflect the true state of the data.
[0090] Step S144: Compare the compensated authentication result with the preset authentication threshold. If the compensated authentication result exceeds the authentication threshold, the authentication is determined to be successful and an authentication success flag is generated; otherwise, the authentication is determined to be unsuccessful and an authentication retry mechanism is triggered.
[0091] The preset authentication threshold is a fixed value set based on historical authentication data and security requirements. The compensated authentication result is compared with this threshold. If the compensated authentication result exceeds the threshold, the data has passed authentication, the authentication is successful, and an authentication success identifier is generated. The authentication success identifier can be a specific code or flag used for subsequent statistics and analysis.
[0092] If the compensated authentication result does not exceed the authentication threshold, authentication is deemed to have failed. At this point, an authentication retry mechanism is triggered to re-authenticate the data for that sub-period. The authentication retry mechanism may include re-executing steps S141-S143, i.e., re-parseing the time-series authentication labels to generate the authentication input feature set, calling the authentication matching model again to generate the initial authentication result, and then performing communication latency compensation. If authentication still fails after multiple retries, it may be necessary to further check the source and integrity of the data, or adjust the authentication rules and model.
[0093] Step S145: Count the authentication success and failure flags for all sub-time periods, generate an authentication result set, and extract the authentication strategy adjustment parameters based on the sub-time period data corresponding to the authentication failure flags.
[0094] The authentication success and failure flags are counted for all 24 sub-time periods in the power terminal data set with time-series authentication tags. The authentication result for each sub-time period is recorded to form an authentication result set containing 24 elements, where each element is either an authentication success flag or an authentication failure flag.
[0095] For the sub-time period data corresponding to the authentication failure identifier, a detailed analysis is performed to extract authentication policy adjustment parameters. These parameters include the dynamic network identifier update weight, hash seed adjustment coefficient, and time stamp synchronization offset.
[0096] For dynamic network identifier update weights, the terminal state fluctuation characteristics and environmental interference characteristics of the authentication failure sub-periods are analyzed to determine the degree of influence of these characteristics on authentication failure. For example, if the state transition frequency is too high in a certain sub-period, leading to authentication failure, the weight of the state transition frequency in dynamic network identifier generation can be increased, that is, its importance in the basic coding of dynamic network identifiers can be enhanced. By comprehensively analyzing the data from multiple authentication failure sub-periods, the update weight of each feature component is determined, forming a dynamic network identifier update weight set containing multiple weight values.
[0097] The hash seed adjustment factor is determined based on the environmental interference characteristics of the authentication failure sub-periods. If, during certain sub-periods, the amplitude of environmental interference signals is large or the distribution of interference frequency bands is abnormal, leading to inaccurate hash binding results and thus authentication failure, then the hash seed generation rules can be adjusted. By analyzing the relationship between the environmental interference characteristics of the authentication failure sub-periods and the hash binding results, an adjustment factor is determined to modify the seed generation rules of the dynamic hash algorithm, making the newly generated hash seed more adaptable to changes in environmental interference.
[0098] The extraction of the timestamp synchronization offset takes into account that communication delays may cause deviations in the correspondence between the timestamp checksum and the data. The network communication quality characteristics of the authentication failure sub-period are analyzed, particularly the average and peak latency intervals. Based on these characteristics, a timestamp synchronization offset is calculated to compensate for the offset of the timestamp checksum, ensuring the synchronization between the timestamp checksum and the data.
[0099] Step S150: Update the dynamic network identifier generation parameters according to the authentication result set and the authentication strategy adjustment parameters, and synchronize the updated dynamic network identifier generation parameters to the target power terminal to trigger the data authentication iteration of the next time window.
[0100] After obtaining the authentication result set and authentication policy adjustment parameters, the dynamic network identifier generation parameters are updated to improve the accuracy and reliability of subsequent data authentication.
[0101] Step S151: Adjust the weight allocation ratio of the terminal state fluctuation feature in the dynamic network identifier generation parameters according to the dynamic network identifier update weight.
[0102] For example, we first analyze the sub-period weight distribution matrix in the dynamic network identifier update weights. The sub-period weight distribution matrix records the weight information of each feature component corresponding to each sub-period. For example, for the three feature components of state transition frequency, state duration, and state deviation, there is a corresponding weight value in each sub-period.
[0103] The adjustment magnitude of each component of the terminal state fluctuation characteristic is determined based on the sub-period weight distribution matrix. For the state transition frequency, its original weight in each sub-period is multiplied by the corresponding updated weight to obtain the adjusted weight. For example, in a certain sub-period, the original weight of the state transition frequency is 0.3, and the updated weight is 1.2, then the adjusted weight is 0.3 × 1.2 = 0.36. The same method is used to adjust the state maintenance duration and the degree of state anomalous deviation.
[0104] The state transition frequency, state duration, and state deviation from normal operation characteristics of the terminal are proportionally scaled based on the adjustment range. The original values of these three parameters are multiplied by their adjusted weights. For example, if the original state transition frequency is 0.83 times / hour and the adjusted weight is 0.36, then the scaled state transition frequency is 0.83 × 0.36 = 0.2988 times / hour.
[0105] The scaled state transition frequency, state duration, and state anomaly deviation are then re-integrated into an updated terminal state fluctuation feature. A simple concatenation method can be used to combine the three scaled feature components together to form a new terminal state fluctuation feature sequence.
[0106] Verify the compatibility between the updated terminal state fluctuation characteristics and network communication quality characteristics. This can be done by analyzing the correlation between the two. For example, check whether changes in state transition frequency affect communication latency. If a compatibility conflict is found, such as a significant increase in state transition frequency leading to a significant increase in communication latency, then a secondary adjustment is made based on the node distribution characteristics in the associated network topology dataset. According to the node distribution characteristics, adjust the weight allocation of state transition frequency, state duration, and state anomaly deviation to ensure that the updated terminal state fluctuation characteristics and network communication quality characteristics are coordinated.
[0107] The terminal state fluctuation characteristics after secondary adjustment are fused with network communication quality characteristics and environmental interference characteristics in a multidimensional manner to generate adjusted terminal state fluctuation characteristics. A weighted concatenation method is used to assign weights, such as 0.4, 0.3, and 0.3, to the terminal state fluctuation characteristics, network communication quality characteristics, and environmental interference characteristics, respectively. Then, they are concatenated according to their weights to form the final adjusted terminal state fluctuation characteristics.
[0108] Step S152: Modify the seed generation rule of the dynamic hash algorithm based on the hash seed adjustment coefficient, so that the correlation between the newly generated hash seed and the current environmental interference characteristics is improved.
[0109] The seed generation rule of the dynamic hash algorithm is modified based on the hash seed adjustment factor. The original hash seed generation rule might have simply been based on a single factor in environmental interference characteristics, such as the amplitude of the interference signal. Now, based on the hash seed adjustment factor, more environmental interference characteristics are taken into account, such as the interference duration sequence and the interference frequency band distribution sequence.
[0110] For example, the original hash seed generation formula was: Hash seed = Interference signal amplitude × Fixed coefficient. Now, the modified formula is: Hash seed = Interference signal amplitude × Coefficient 1 + Mean of interference duration sequence × Coefficient 2 + Energy proportion of a specific frequency band in the interference frequency band distribution sequence × Coefficient 3. Here, Coefficient 1, Coefficient 2, and Coefficient 3 are determined based on the hash seed adjustment coefficients.
[0111] This modification allows the newly generated hash seed to more comprehensively reflect the characteristics of current environmental interference, thereby improving the accuracy and security of hash binding. In subsequent hash binding processes, the new hash seed is used for calculations, making the hash value more resistant to the effects of environmental interference.
[0112] Step S153: Perform offset compensation on the timestamp check code according to the timestamp synchronization offset to generate a synchronized and updated timestamp check code.
[0113] Extract the timestamp synchronization offset from the authentication policy adjustment parameters. The timestamp synchronization offset is a numerical value representing the offset that needs to be made to the timestamp checksum.
[0114] For each timestamp checksum in the dynamic network identifier sequence, add the timestamp synchronization offset to obtain the synchronized and updated timestamp checksum. For example, if a timestamp checksum is 1234 and the timestamp synchronization offset is 5, then the synchronized and updated timestamp checksum is 1234 + 5 = 1239.
[0115] In the subsequent timestamp synchronization encryption process, the synchronized and updated timestamp checksum is used for bidirectional XOR operation to ensure the synchronization between the timestamp checksum and the data, and reduce the impact of communication delay on the authentication result.
[0116] Step S154: Combine the adjusted terminal status fluctuation characteristics, the modified hash seed generation rules, and the synchronized updated timestamp verification code to generate updated dynamic network identifier generation parameters.
[0117] The adjusted terminal state fluctuation characteristics, the modified hash seed generation rules, and the synchronized and updated timestamp checksums are integrated. A structured approach can be used to combine them into a new data structure.
[0118] For example, create a structure containing three parts: the first part stores the adjusted terminal state fluctuation characteristics; the second part stores the modified hash seed generation rules (the new generation formula and correlation coefficient can be recorded in text form); and the third part stores the synchronized and updated timestamp checksum sequence. Combining these three parts forms the updated dynamic network identifier generation parameters.
[0119] Step S155: Encrypt the updated dynamic network identifier generation parameters and send them to the target power terminal to overwrite the original dynamic network identifier generation parameters to trigger the data authentication iteration of the next time window.
[0120] The updated dynamic network identifier generation parameters are encrypted to ensure data security during transmission. A symmetric encryption algorithm, such as AES, can be used, and a suitable key can be selected to encrypt the updated dynamic network identifier generation parameters.
[0121] The encrypted and updated dynamic network identifier generation parameters are sent to the target power terminal through a secure communication channel. After receiving the encrypted data, the target power terminal decrypts it using the same key to obtain the updated dynamic network identifier generation parameters.
[0122] The target power terminal overwrites the original dynamic network identifier generation parameters with the updated dynamic network identifier generation parameters. When the next time window (e.g., a new day) begins, the target power terminal re-executes steps S110-S150 based on the updated dynamic network identifier generation parameters to perform a new round of data authentication iteration, continuously improving the accuracy and security of data authentication.
[0123] Step S156: When the next time window starts, regenerate the dynamic network identifier sequence based on the updated dynamic network identifier generation parameters.
[0124] When the new time window begins, the target power terminal begins to regenerate the dynamic network identifier sequence using the updated dynamic network identifier generation parameters. This process is similar to the previous steps S120-S126, but uses the updated parameters.
[0125] First, the target power terminal re-acquires the terminal operation data set and associated network topology data set within the current time window. Then, based on the terminal state fluctuation characteristics and environmental interference characteristics in the updated dynamic network identifier generation parameters, a new dynamic network identifier base code is generated. Since the terminal state fluctuation characteristics and environmental interference characteristics may have been adjusted, the newly generated dynamic network identifier base code will also be different from the previous one.
[0126] Next, the set of neighbor node identifiers and communication priority weights for the target power terminal are determined based on the updated associated network topology data set. The communication priority weights may be adjusted due to changes in network status and updated parameters. The dynamic network identifier base code is then weighted according to the new communication priority weights to generate a weighted dynamic code.
[0127] The weighted dynamic code is concatenated with the neighbor node identifier set to generate an initial dynamic network identifier sequence. Finally, the initial dynamic network identifier sequence is divided into time windows to obtain a new dynamic network identifier sequence. Each dynamic network identifier corresponds to a sub-time period, and each dynamic network identifier contains a timestamp checksum. This timestamp checksum is generated based on the start time of the sub-time period to ensure that each dynamic network identifier is unique and traceable in the time dimension. For example, if the new time window is also divided into 24 sub-time periods, each lasting one hour, and the first sub-time period starts at 0:00, its timestamp checksum will be generated as a unique code value based on this start time (0:00) using a specific encoding algorithm.
[0128] Step S157: Perform a pre-authentication test on the regenerated dynamic network identifier sequence to generate a pre-authentication result set.
[0129] Before the regenerated dynamic network identifier sequence is officially put into use, pre-certification testing is required to ensure its effectiveness and reliability.
[0130] Step S1571: Extract a set of test data that matches the current environmental interference characteristics from historical certification data.
[0131] Data matching the current environmental interference characteristics is selected from a large amount of historical authentication data. Environmental interference characteristics include multiple dimensions such as interference signal amplitude, interference duration, and interference frequency band distribution. In practice, the numerical ranges of each of the current environmental interference characteristics are first determined. For example, the current interference signal amplitude is between 10-15 units, the interference duration is concentrated between 5-10 minutes, and the interference frequency band is distributed within a few specific frequency bands. Then, data records that meet these range conditions are searched in the historical authentication data. Assuming the historical authentication data includes the environmental interference characteristics and corresponding terminal operation data for each sub-time period of each day over the past month, data matching the current environmental interference characteristics are selected through a comparison, forming a test dataset. The number of data in this test dataset may vary depending on the stringency of the matching criteria. If the matching criteria are set more leniently, dozens or even hundreds of data points may be selected; if the criteria are strict, only a dozen or so data points may be selected.
[0132] Step S1572: Perform simulated dynamic binding processing on the test data set and the regenerated dynamic network identifier sequence to generate a simulated authentication tag set.
[0133] The selected test dataset is then dynamically bound to the newly generated dynamic network identifier sequence. This process is similar to the actual data binding process. First, each data item in the test dataset is time-aligned with its corresponding dynamic network identifier in the newly generated dynamic network identifier sequence according to its sub-time period. For example, if a data item in the test dataset corresponds to the sub-time period of 2:00-3:00, it is combined with the corresponding dynamic network identifier for 2:00-3:00 in the dynamic network identifier sequence.
[0134] Next, hash binding is performed on the aligned data pairs. A dynamic hashing algorithm is used, with the hash seed dynamically adjusted based on environmental interference features in the updated dynamic network identifier generation parameters. For each data pair, the test data and the corresponding dynamic network identifier are concatenated to form a string to be hashed. This string is then hashed using the dynamic hashing algorithm and the hash seed generated by the current environmental interference features to obtain a hash value. This hash value is combined with the original data pair to form a simulated authentication label. This process is performed on all data items in the test data set, ultimately generating a set of simulated authentication labels.
[0135] Step S1573: Call the authentication matching model to process the simulated authentication tag set and generate a simulated authentication result set.
[0136] The pre-trained authentication matching model is invoked to process the simulated authentication tag set. Each simulated authentication tag in the set is taken as input and fed into the authentication matching model. The model analyzes and calculates the input simulated authentication tags according to the trained rules.
[0137] The model parses the dynamic network identifier (NRI) and timestamp checksum from the simulated authentication tags to generate a set of authentication input features. For example, it extracts terminal state fluctuation features, environmental interference features, and neighbor node identifiers from the NRI, while simultaneously recording the sub-time period information corresponding to the timestamp checksum. The model then uses these authentication input features to assess the legality and completeness of the data. For each simulated authentication tag, the model outputs a simulated authentication result, which can be a numerical value representing authentication credibility or a classification label, such as "authentication successful" or "authentication failed." The simulated authentication results for all simulated authentication tags are combined to form a set of simulated authentication results.
[0138] Step S1574: Calculate the pass rate of the simulated authentication result set. If the pass rate exceeds the pre-authentication threshold, the pre-authentication is determined to be successful; otherwise, the pre-authentication is determined to be unsuccessful, and the pre-authentication result set is obtained.
[0139] Count the number of successful authentications and the total number of successful authentications in the simulated authentication result set. Assume there are 50 simulated authentication results in the set, of which 40 are successful. Calculate the pass rate: Pass rate = Number of successful authentications ÷ Total number, i.e., 40 ÷ 50 = 0.8.
[0140] The pre-authentication threshold is a fixed value set based on the system's security requirements and historical experience; for example, it might be set to 0.7. The calculated pass rate is compared to the pre-authentication threshold. Since 0.8 is greater than 0.7, pre-authentication is considered successful; if the pass rate is less than or equal to the pre-authentication threshold, pre-authentication is considered a failure. Regardless of success or failure, these results are recorded to form a pre-authentication result set.
[0141] Step S158: If the pre-authentication results of all sub-time periods in the pre-authentication result set exceed the preset pre-authentication threshold, the regenerated dynamic network identifier sequence is marked as valid and enabled; otherwise, the dynamic network identifier generation parameters of the previous version are rolled back and an alarm mechanism is triggered.
[0142] Examine the pre-authentication results for each sub-time period in the pre-authentication result set. If the pass rate for the pre-authentication results of all sub-time periods exceeds the preset pre-authentication threshold, it indicates that the regenerated dynamic network identifier sequence can pass authentication well under various simulation conditions, and has high reliability and effectiveness. In this case, mark the regenerated dynamic network identifier sequence as valid and enable the sequence in subsequent actual data authentication processes.
[0143] If the pre-authentication results in one or more sub-periods of the pre-authentication result set do not exceed the pre-authentication threshold, it indicates that the regenerated dynamic network identifier sequence may have a problem and cannot guarantee the authentication accuracy in practical applications. In this case, it is necessary to roll back to the previous version of the dynamic network identifier generation parameters.
[0144] Step S1581: Record the environmental interference characteristics, terminal status fluctuation characteristics, and network communication quality characteristics corresponding to the current pre-authentication failure.
[0145] When pre-authentication fails, detailed records are made of the environmental interference characteristics, terminal state fluctuation characteristics, and network communication quality characteristics corresponding to the current pre-authentication failure. Environmental interference characteristics record specific values such as interference signal amplitude, interference duration, and interference frequency band distribution; terminal state fluctuation characteristics record information such as state transition frequency, state duration, and state anomaly deviation; network communication quality characteristics record data such as mean communication delay, delay variance, and delay peak interval. For example, the current interference signal amplitude is recorded as 12 units, the interference duration as 8 minutes, and the interference frequency band distributed in three specific frequency band intervals; the state transition frequency is 0.9 times / hour, the average state duration is 2.5 hours, and the state anomaly deviation is 15%; the mean communication delay is 50 milliseconds, the delay variance is 20 milliseconds², and the delay peak interval is 30 minutes.
[0146] Step S1582: Generate an interference feature matching template based on the recorded environmental interference features, and add the interference feature matching template to the exclusion list of the dynamic network identifier generation parameters.
[0147] An interference feature matching template is generated based on the recorded environmental interference characteristics. This template contains the numerical ranges of various environmental interference characteristics and is used for subsequent screening and exclusion of environmental interference situations that may lead to pre-certification failure. For example, based on the recorded interference signal amplitude of 12 units, interference duration of 8 minutes, and interference frequency band distribution, a template is generated that specifies that interference signal amplitudes between 11 and 13 units, interference durations between 7 and 9 minutes, and interference frequency band distributions within three specific frequency band intervals are excluded.
[0148] The generated interference feature matching template is added to the exclusion list of the dynamic network identifier generation parameters. The exclusion list is a list that stores environmental interference feature templates that may cause authentication failure. When generating dynamic network identifier generation parameters, this exclusion list will be referred to to avoid generating parameters that may have problems.
[0149] Step S1583: Filter the terminal running data set for the next time window based on the exclusion list to generate a filtered subset of terminal running data.
[0150] After acquiring the terminal running data set in the next time window, it is filtered according to an exclusion list. For each data item in the terminal running data set, its corresponding environmental interference characteristics are checked to see if they match the interference characteristic matching template in the exclusion list. If they match, the data item is excluded from the terminal running data set; otherwise, it is retained. This filtering operation generates a filtered subset of terminal running data. For example, if the terminal running data set in the next time window has 100 data items, after filtering with the exclusion list, it is found that 10 data items have environmental interference characteristics that match the template in the exclusion list. These 10 data items are excluded, resulting in a filtered subset of terminal running data containing 90 data items.
[0151] Step S1584: Process the filtered terminal running data subset using the dynamic network identifier generation parameters of the previous version to generate the rolled-back dynamic network identifier sequence.
[0152] The filtered subset of terminal operation data is processed using the dynamic network identifier generation parameters from the previous version. The processing procedure is similar to the steps for generating the dynamic network identifier sequence. First, a basic dynamic network identifier code is generated based on the terminal state fluctuation characteristics and environmental interference characteristics from the previous version's dynamic network identifier generation parameters. Then, the set of neighbor node identifiers and communication priority weights of the target power terminal are determined according to the associated network topology data set, and the basic dynamic network identifier code is weighted and adjusted to generate a weighted dynamic code. The weighted dynamic code is concatenated with the set of neighbor node identifiers to generate the initial dynamic network identifier sequence. Finally, the initial dynamic network identifier sequence is divided into time windows to obtain the rolled-back dynamic network identifier sequence.
[0153] Step S1585: Send the rolled-back dynamic network identifier sequence and pre-authentication failure information to the network management terminal, so that the network management terminal can parse the environmental interference characteristics, terminal status fluctuation characteristics and network communication quality characteristics in the pre-authentication failure information and generate a fault diagnosis report.
[0154] The rolled-back dynamic network identifier sequence and pre-authentication failure information are sent to the network management terminal. The pre-authentication failure information contains detailed data such as environmental interference characteristics, terminal status fluctuation characteristics, and network communication quality characteristics corresponding to the pre-authentication failure. After receiving this information, the network management terminal parses the pre-authentication failure information.
[0155] The network management terminal extracts specific values of environmental interference characteristics, terminal state fluctuation characteristics, and network communication quality characteristics from the pre-authentication failure information, and analyzes the interrelationships between these characteristics and their impact on the authentication results. For example, it analyzes whether the inaccurate hash binding result is due to excessively large interference signal amplitude, or whether excessively high state transition frequency affects the generation of dynamic network identifiers. Based on the analysis results, a fault diagnosis report is generated, which details the cause of the pre-authentication failure, possible problems, and suggested solutions.
[0156] Step S1586: Adjust the quantization threshold of the environmental interference feature in the dynamic network identifier generation parameters based on the fault diagnosis report.
[0157] Based on the analysis results of the fault diagnosis report, the quantization threshold of environmental interference features in the dynamic network identifier generation parameters is adjusted. For example, if the fault diagnosis report indicates that an interference signal amplitude exceeding 10 units is likely to cause authentication failure, then the quantization threshold for interference signal amplitude in the environmental interference features is adjusted from the original 12 units to 10 units. The quantization thresholds for other environmental interference features, such as interference duration and interference frequency band distribution, are also adjusted accordingly to ensure better adaptation to environmental interference conditions and improved authentication accuracy during subsequent dynamic network identifier generation.
[0158] Step S1587: In response to the input calibration command, calibrate the seed generation rule of the dynamic hash algorithm so that the hash seed matches the updated environmental interference feature quantization threshold.
[0159] Upon receiving a calibration command, the seed generation rule of the dynamic hash algorithm is calibrated. The purpose of calibration is to match the hash seed with the updated environmental interference feature quantization threshold. For example, if the updated environmental interference feature quantization threshold adjusts the range of interference signal amplitude, interference duration, and interference frequency band distribution, then the weights and coefficients of each environmental interference feature factor are adjusted accordingly in the hash seed generation rule.
[0160] Assuming the original hash seed generation rule was: Hash Seed = Interference Signal Amplitude × 0.5 + Interference Duration × 0.3 + A Certain Index of Interference Frequency Band Distribution × 0.2. Based on the updated environmental interference characteristic quantization threshold, it was found that the interference signal amplitude has a greater impact, so its weight was adjusted to 0.6, the interference duration weight to 0.2, and the interference frequency band distribution index weight to 0.2. Simultaneously, according to the new quantization threshold range, the specific values of the coefficients were adjusted so that the generated hash seed more accurately reflects changes in environmental interference characteristics, improving the accuracy of hash binding.
[0161] Step S1588: Re-execute the pre-certification test and parameter update operation until the pass rate of the pre-certification result set meets the requirements. Mark the manually adjusted dynamic network identifier generation parameters as stable version and lock them to prevent subsequent automatic update operations from overwriting the version parameters of this stable version.
[0162] After adjusting the quantization threshold of environmental interference features in the dynamic network identifier generation parameters and calibrating the seed generation rules of the dynamic hash algorithm, the pre-authentication test is re-executed. Following the process in step S157, a test data set matching the current environmental interference features is extracted from the historical authentication data. The test data set is then subjected to simulated dynamic binding processing with the regenerated dynamic network identifier sequence to generate a simulated authentication tag set. The authentication matching model is then called to process the simulated authentication tag set to generate a simulated authentication result set, and the pass rate of the simulated authentication result set is calculated.
[0163] If the pass rate does not meet the requirements, analyze the reasons for the pre-authentication failure again, repeat steps S1581-S1587, and further adjust the dynamic network identifier generation parameters and the seed generation rules of the hash algorithm. Repeat this process until the pass rate of the pre-authentication result set meets the preset pre-authentication threshold requirements.
[0164] When the pass rate of the pre-certification result set meets the requirements, the manually adjusted dynamic network identifier generation parameters are marked as the stable version. To ensure that this stable version of the parameters is not overwritten by subsequent automatic update operations, it is locked. During subsequent system operation, unless a manual calibration command is received again, this stable version of the dynamic network identifier generation parameters will be used for data authentication to ensure system stability and authentication accuracy.
[0165] Step S159: Perform dynamic binding processing on the valid dynamic network identifier sequence and the new terminal operation data set to generate a new power terminal data set with time-series authentication tags.
[0166] If the regenerated dynamic network identifier sequence passes the pre-authentication test and is marked as valid, then it is dynamically bound to the new terminal runtime data set. This process is similar to the previous steps S130-S134.
[0167] First, the valid dynamic network identifier sequence is time-aligned with the new terminal operation data set by sub-time period to generate an aligned data set. For example, the new terminal operation data set contains operation data such as voltage, current, and power for each sub-time period of the new day, and the data for each sub-time period is combined with the corresponding dynamic network identifier.
[0168] Next, hash binding is performed on the data for each sub-period in the aligned dataset to generate a primary bound dataset. A dynamic hashing algorithm is used, with the hash seed dynamically adjusted based on environmental interference characteristics in the updated dynamic network identifier generation parameters. A hash operation is performed on the data for each sub-period and its corresponding dynamic network identifier to obtain a hash value, which is then combined with the data and identifier.
[0169] Then, timestamp synchronization encryption is performed on the primary binding data set to generate a power terminal data set with time-series authentication tags. A bidirectional XOR operation is performed between the timestamp checksum in the dynamic network identifier and the primary binding data set to ensure data security and timeliness.
[0170] Finally, the integrity and consistency of the time-series authentication labels are verified. If inconsistent labels exist, the dynamic network identifier sequence is regenerated based on the associated network topology data set, and the dynamic binding process is re-executed until all time-series authentication labels are complete and consistent, resulting in a new power terminal data set with time-series authentication labels.
[0171] Step S160: Repeat the dynamic authentication matching process and parameter update operation until the preset iteration termination condition is reached.
[0172] After generating a new set of power terminal data with time-series authentication tags, the dynamic authentication matching process and parameter update operation are repeated. The dynamic authentication matching process is performed according to steps S140-S145, which involves performing dynamic authentication matching on the set of power terminal data with time-series authentication tags based on a preset set of real-time authentication rules, generating a set of authentication results and authentication strategy adjustment parameters.
[0173] The parameter update operation is performed according to steps S150-S159. The parameters for generating the dynamic network identifier are adjusted according to the authentication result set and authentication strategy. The updated dynamic network identifier generation parameters are synchronized to the target power terminal, the dynamic network identifier sequence is regenerated, and a pre-authentication test is performed. If the pre-authentication is successful, the dynamic network identifier is dynamically bound to the new terminal operation data set.
[0174] The preset iteration termination conditions can be set according to actual needs. For example, stopping after reaching a certain number of iterations, such as 100 iterations; or stopping iteration when the pass rate of the authentication result set reaches a very high level for multiple consecutive times, such as 10 consecutive pass rates exceeding 0.95. When the preset iteration termination conditions are met, the entire data authentication iteration process stops, the system enters a stable operation phase, and continues to use the currently valid dynamic network identifier generation parameters and dynamic network identifier sequences for data authentication to ensure the security and integrity of power terminal data.
[0175] Figure 2 The diagram illustrates exemplary hardware and software components of a power terminal data authentication system 100 based on dynamic binding of network identifiers, which can implement the inventive concept according to some embodiments of the present invention. For example, a processor 120 can be used in the power terminal data authentication system 100 based on dynamic binding of network identifiers and to perform the functions in the present invention.
[0176] The power terminal data authentication system 100 based on dynamic binding of network identifiers can be a general-purpose server or a special-purpose server; both can be used to implement the power terminal data authentication method based on dynamic binding of network identifiers of this invention. Although only one server is shown in this invention, for convenience, the functions described in this invention can be implemented in a distributed manner on multiple similar platforms to balance the load.
[0177] For example, a power terminal data authentication system 100 based on dynamic binding of network identifiers may include a network port 110 connected to a network, one or more processors 120 for executing program instructions, a communication bus 130, and various forms of storage media 140, such as a disk, ROM, or RAM, or any combination thereof. Exemplarily, the power terminal data authentication system 100 based on dynamic binding of network identifiers may also include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The method of the present invention can be implemented according to these program instructions. The power terminal data authentication system 100 based on dynamic binding of network identifiers also includes an input / output (I / O) interface 150 between the computer and other input / output devices.
[0178] For ease of explanation, only one processor is described in the power terminal data authentication system 100 based on dynamic binding of network identifiers. However, it should be noted that the power terminal data authentication system 100 based on dynamic binding of network identifiers in this invention may also include multiple processors. Therefore, the steps executed by one processor described in this invention may also be executed jointly by multiple processors or individually. For example, if the processor of the power terminal data authentication system 100 based on dynamic binding of network identifiers executes steps A and B, it should be understood that steps A and B may also be executed jointly by two different processors or individually by one processor. For example, the first processor executes step A, the second processor executes step B, or the first processor and the second processor jointly execute steps A and B.
[0179] Furthermore, this embodiment of the invention also provides a readable storage medium, wherein computer-executable instructions are preset in the readable storage medium, and when the processor executes the computer-executable instructions, the above-mentioned power terminal data authentication method based on network identifier dynamic binding is implemented.
[0180] It should be noted that, in order to simplify the description of the present invention and thus help to understand one or more embodiments of the invention, multiple features may sometimes be grouped into one embodiment, drawing or description thereof in the foregoing description of the embodiments of the present invention.
Claims
1. A power terminal data authentication method based on dynamic binding of network identifiers, characterized in that, The method includes: Acquire the terminal operation data set and associated network topology data set of the target power terminal within a preset time window, and generate dynamic network identifier generation parameters based on the terminal operation data set. The dynamic network identifier generation parameters include terminal status fluctuation characteristics, network communication quality characteristics and environmental interference characteristics. Based on the dynamic network identifier generation parameters and the associated network topology data set, a dynamic network identifier allocation operation is performed to generate a dynamic network identifier sequence corresponding to the target power terminal. The dynamic network identifier sequence contains multiple dynamic network identifiers, and each dynamic network identifier is associated with a sub-time period within the time window. Dynamic binding processing is performed on the dynamic network identifier sequence and the terminal operation data set to generate a power terminal data set with a time-series authentication tag, wherein the time-series authentication tag is used to verify the integrity and source legitimacy of the power terminal data set; Based on a preset set of real-time authentication rules, the power terminal data set with time-series authentication tags is dynamically authenticated and matched to generate an authentication result set and authentication strategy adjustment parameters. The authentication strategy adjustment parameters are used to dynamically adjust the generation logic of the dynamic network identifier generation parameters. The dynamic network identifier generation parameters are updated based on the authentication result set and the authentication strategy adjustment parameters, and the updated dynamic network identifier generation parameters are synchronized to the target power terminal to trigger the data authentication iteration of the next time window.
2. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 1, characterized in that, The generation of dynamic network identifier generation parameters based on the terminal operation data set includes: Extract edge node communication delay data, power terminal status change data, and environmental interference fluctuation data from the terminal operation data set; Delay fluctuation features are extracted from the communication delay data of the edge nodes to generate network communication quality features, wherein the network communication quality features include the mean communication delay, the delay variance, and the delay peak interval. The power terminal state transition data is analyzed for state trend to generate terminal state fluctuation characteristics, which include state transition frequency, state duration and state anomaly deviation. The environmental interference fluctuation data is quantified to generate environmental interference characteristics, which include interference signal amplitude, interference duration, and interference frequency band distribution. The network communication quality characteristics, terminal status fluctuation characteristics, and environmental interference characteristics are fused in multiple dimensions to generate dynamic network identifier generation parameters.
3. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 1, characterized in that, The step of performing a dynamic network identifier allocation operation based on the dynamic network identifier generation parameters and the associated network topology data set to generate a dynamic network identifier sequence corresponding to the target power terminal includes: The associated network topology data set is analyzed to determine the node distribution characteristics and link load characteristics of the network partition where the target power terminal is located; The set of neighbor node identifiers of the target power terminal is determined based on the node distribution characteristics, and the communication priority weight of the target power terminal is calculated based on the link load characteristics. The basic encoding of the dynamic network identifier is generated based on the terminal state fluctuation characteristics and environmental interference characteristics in the dynamic network identifier generation parameters. The dynamic network identifier base code is weighted and adjusted according to the communication priority weight to generate a weighted dynamic code; The weighted dynamic code is concatenated with the neighbor node identifier set to generate an initial dynamic network identifier sequence; The initial dynamic network identifier sequence is divided into time windows to obtain the dynamic network identifier sequence, wherein each dynamic network identifier corresponds to a sub-time period and includes a timestamp check code.
4. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 1, characterized in that, The step of performing dynamic binding processing on the dynamic network identifier sequence and the terminal operation data set to generate a power terminal data set with time-series authentication tags includes: The dynamic network identifier sequence is aligned with the terminal operation data set by sub-time period to generate an aligned data set. A hash binding process is performed on each sub-time period data in the aligned data set to generate a primary bound data set. The hash binding process uses a dynamic hash algorithm and the hash seed is dynamically adjusted based on the environmental interference characteristics in the dynamic network identifier generation parameters. The primary binding data set is subjected to timestamp synchronization encryption processing to generate a power terminal data set with time sequence authentication tags. The timestamp synchronization encryption processing includes performing a bidirectional XOR operation between the timestamp verification code in the dynamic network identifier and the primary binding data set. Verify the integrity and consistency of the time-series authentication tags. If inconsistent tags exist, regenerate the dynamic network identifier sequence based on the associated network topology data set and re-execute the dynamic binding process.
5. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 4, characterized in that, The system performs dynamic authentication matching processing on the power terminal data set with time-series authentication tags based on a preset set of real-time authentication rules, generating an authentication result set and authentication strategy adjustment parameters, including: The dynamic network identifier code and timestamp check code in the time-series authentication tag are parsed to generate an authentication input feature set; A preset authentication matching model is invoked to process the authentication input feature set and generate a preliminary authentication result. The authentication matching model is trained based on historical authentication data and its input and output dimensions are consistent with the dimensions of the authentication input feature set. Based on the network communication quality characteristics in the dynamic network identifier generation parameters, the primary authentication result is compensated for communication delay to generate a compensated authentication result. The compensated authentication result is compared with a preset authentication threshold. If the compensated authentication result exceeds the authentication threshold, the authentication is determined to be successful and an authentication success flag is generated; otherwise, the authentication is determined to be unsuccessful and an authentication retry mechanism is triggered. The system collects authentication success and failure flags for all sub-time periods, generates an authentication result set, and extracts and adjusts authentication strategy parameters based on the sub-time period data corresponding to the authentication failure flags.
6. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 5, characterized in that, The authentication policy adjustment parameters include dynamic network identifier update weight, hash seed adjustment coefficient, and time stamp synchronization offset. Updating the dynamic network identifier generation parameters based on the authentication result set and the authentication policy adjustment parameters includes: The weight allocation ratio of the terminal state fluctuation feature in the dynamic network identifier generation parameters is adjusted according to the dynamic network identifier update weight. Based on the hash seed adjustment coefficient, the seed generation rule of the dynamic hash algorithm is modified so that the correlation between the newly generated hash seed and the current environmental interference characteristics is improved. The timestamp check code is offset-compensated according to the timestamp synchronization offset to generate a synchronized and updated timestamp check code. The adjusted terminal status fluctuation characteristics, the modified hash seed generation rules, and the synchronized updated timestamp verification code are combined to generate updated dynamic network identifier generation parameters. The updated dynamic network identifier generation parameters are encrypted and sent to the target power terminal, overwriting the original dynamic network identifier generation parameters to trigger the data authentication iteration of the next time window.
7. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 6, characterized in that, The data authentication iteration that triggers the next time window includes: When the next time window starts, the dynamic network identifier sequence is regenerated based on the updated dynamic network identifier generation parameters; Perform pre-authentication testing on the regenerated dynamic network identifier sequence to generate a set of pre-authentication results; If the pre-authentication results of all sub-time periods in the pre-authentication result set exceed the preset pre-authentication threshold, the regenerated dynamic network identifier sequence will be marked as valid and enabled; otherwise, the dynamic network identifier generation parameters of the previous version will be rolled back and an alarm mechanism will be triggered. The effective dynamic network identifier sequence is dynamically bound to the new terminal operation data set to generate a new power terminal data set with time-series authentication tags. Repeatedly execute dynamic authentication matching and parameter update operations until the preset iteration termination condition is met.
8. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 7, characterized in that, The pre-authentication test on the regenerated dynamic network identifier sequence, generating a pre-authentication result set, includes: Extract a set of test data that matches the current environmental interference characteristics from historical certification data; The test data set is subjected to simulated dynamic binding processing with the regenerated dynamic network identifier sequence to generate a simulated authentication tag set; The authentication matching model is invoked to process the simulated authentication tag set, generating a simulated authentication result set; Calculate the pass rate of the simulated authentication result set. If the pass rate exceeds the pre-authentication threshold, the pre-authentication is determined to be successful; otherwise, the pre-authentication is determined to be unsuccessful, and the pre-authentication result set is obtained.
9. The power terminal data authentication method based on dynamic binding of network identifiers according to claim 8, characterized in that, The rollback to the previous version of the dynamic network identifier generation parameters and triggering of the alarm mechanism includes: Record the environmental interference characteristics, terminal status fluctuation characteristics, and network communication quality characteristics corresponding to the current pre-authentication failure; An interference feature matching template is generated based on the recorded environmental interference features, and the interference feature matching template is added to the exclusion list of the dynamic network identifier generation parameters. Based on the exclusion list, filter the terminal running data set of the next time window to generate a filtered subset of terminal running data; The filtered subset of terminal running data is processed using the dynamic network identifier generation parameters from the previous version to generate a rolled-back dynamic network identifier sequence. The rolled-back dynamic network identifier sequence and pre-authentication failure information are sent to the network management terminal, so that the network management terminal can parse the environmental interference characteristics, terminal status fluctuation characteristics and network communication quality characteristics in the pre-authentication failure information and generate a fault diagnosis report. The quantization threshold of the environmental interference feature in the dynamic network identifier generation parameters is adjusted based on the fault diagnosis report. In response to the input calibration command, the seed generation rule of the dynamic hash algorithm is calibrated so that the hash seed matches the updated environmental interference feature quantization threshold. Re-execute the pre-certification test and parameter update operation until the pass rate of the pre-certification result set meets the requirements. Mark the manually adjusted dynamic network identifier generation parameters as a stable version and lock them to prevent subsequent automatic update operations from overwriting the version parameters of this stable version.
10. A power terminal data authentication system based on dynamic binding of network identifiers, characterized in that, The device includes a processor and a memory, the memory being connected to the processor. The memory is used to store programs, instructions, or code, and the processor is used to execute the programs, instructions, or code in the memory to implement the power terminal data authentication method based on dynamic binding of network identifiers as described in any one of claims 1-9.
Citation Information
Patent Citations
Method for dynamically adjusting time sequence between adjacent networks of synchronous network and electronic price tag system
CN115802477A
Security protection method and system for power terminal
WO2023216641A1