A large-scale micro-grid secure communication traffic obfuscation processing method and system
By constructing a logical causal graph and generating logically consistent obfuscated communication data packets through a fusion-based obfuscation generation network, the problem of easily identifiable communication traffic in large-scale microgrids is solved, thereby improving the security and reliability of power dispatch.
Patent Information
- Application Number
- CN202510825214.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2045-06-19
AI Technical Summary
Existing communication traffic obfuscation techniques struggle to generate logically consistent and time-sequential pseudo-traffic in large-scale microgrids, making them easily recognizable by machine learning models. This results in insufficient communication security and impacts the accuracy and reliability of power dispatching.
Based on the semantic similarity, temporal transition probability, and causal relationship of power business units, a logical causal graph is constructed. A fusion-type obfuscation generation network generates obfuscated communication data packets with consistent logical causality, which are then inserted into the PLC communication link to ensure that obfuscation does not interfere with actual scheduling tasks.
It improves the security of microgrid communication, prevents data-driven attacks, enhances the accuracy of power dispatch and the robustness of system operation, and reduces the identification risk of traffic feature analysis.
Smart Images

Figure CN120602174B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to intelligent dispatching systems for large-scale power grids, and more particularly to the field of communication traffic obfuscation processing, specifically a method and system for secure communication traffic obfuscation processing in large-scale microgrids. Background Technology
[0002] Against the backdrop of the accelerated construction of new power systems, microgrids, with their advantages of being distributed, autonomous, and flexible, have become an important component supporting the integration of clean energy and local load regulation. Microgrids typically consist of distributed power sources (such as photovoltaic and wind power), energy storage devices, load equipment, and energy management systems, relying on high-frequency, low-latency communication for real-time scheduling and control. Among these, PLC (Power Line Communication) is widely used for control signal transmission and operational status information feedback between microgrid devices because it requires no additional wiring and is interconnected with the power grid's physical infrastructure.
[0003] In large-scale microgrid systems, PLC communication undertakes tasks such as distributing dispatch instructions for critical power services, transmitting status monitoring data, and issuing load forecasting instructions. Different functional types of communication data packets correspond to different business logic and control objectives. These communication data packets often contain structured information such as functional fields, node addresses, timestamps, and payloads, which can clearly reflect the behavioral characteristics and scheduling modes of the system during operation.
[0004] Currently, communication traffic obfuscation technology is widely used to improve network communication security. Traditional obfuscation methods mainly include random delayed insertion, communication command perturbation, and encryption identifier masking. However, most of these methods do not consider the logical consistency between obfuscated data packets and the real business semantics, making them easily detected and identified by machine learning models based on traffic characteristics.
[0005] For example, patent CN118573477B discloses a communication data transmission method that determines the risk of data leakage on the server side, generates a communication data mask sequence and a perturbation data sequence, and constructs a fused communication truth sequence through an obfuscation circuit, thereby outputting the disguised communication result. This scheme improves the concealment of communication information to some extent, but its obfuscation generation does not consider the characteristics of the business layer logic, making it difficult to forge obfuscated traffic with reasonable context and consistent timing in complex PLC scenarios, and thus still carries the risk of being detected.
[0006] Against this backdrop, how to effectively prevent and respond to the leakage and attack of communication traffic has become an important problem that urgently needs to be solved. In response to this problem, this application proposes a method and system for obfuscating communication traffic in large-scale microgrids. By generating pseudo-traffic that conforms to the semantics of power business, PLC communication traffic is effectively obfuscated, which can avoid erroneous scheduling caused by malicious attacks and improve the accuracy and reliability of power dispatching in microgrids. Summary of the Invention
[0007] This invention provides a method and system for obfuscating secure communication traffic in large-scale microgrids. Based on the semantic similarity, temporal transition probability, and causal relationships between power business units, a fusion-based obfuscation generation network is used to construct semantically consistent, structurally sound, and statistically spoofable obfuscated communication data packets. These obfuscated communication data packets maintain a high degree of logical causal consistency with the communication data packets to be obfuscated in terms of functional fields and payloads. However, their execution is essentially a harmless simulation task or a redundant retransmission of completed instructions, effectively interfering with attackers' reverse analysis and behavioral reasoning of communication traffic. By inserting obfuscated communication data packets conforming to the semantics of power business into critical periods or sensitive communication paths as accompanying cover packets for the communication data packets to be obfuscated, the system can construct nonlinear and nondeterministic business behavior representations, greatly increasing the cost for attackers to reconstruct the real scheduling path. Simultaneously, this obfuscation process strictly adheres to the principles of causal graph and business logic consistency, ensuring that obfuscated communication does not interfere with actual scheduling tasks, thereby enhancing communication security without affecting the accuracy and real-time performance of scheduling control.
[0008] Therefore, the method proposed in this application can not only effectively prevent scheduling misdirection and control deception caused by data-driven attacks, but also improve the operational robustness and overall scheduling reliability of microgrid systems in complex environments.
[0009] To achieve the above objectives, the present invention provides a method for obfuscating secure communication traffic in large-scale microgrids, comprising the following steps:
[0010] S1: Collect communication data packets from the historical communication data packet sequence of the PLC communication link, divide the communication data packets into functional categories according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, form multiple power business units, and construct a mapping relationship table between functional fields and power business units;
[0011] S2: Based on the communication data packets in the power business unit, identify the logical and causal relationships between different power business units, take the power business unit as a node, and the logical and causal relationships between the power business units as the edge weights between the nodes, and construct a logical causal graph between the power business units.
[0012] S3: Collect real-time communication data packets from the PLC communication link in real time, select communication data packets to be confused from the real-time communication data packets according to the confusion selection rules, identify the power business unit corresponding to the communication data packets to be confused based on the mapping relationship table, and select the mimicry power business unit for mimicry analysis of the communication data packets to be confused based on the logical cause-effect graph.
[0013] S4: Utilize the converged obfuscation generation network to receive the mimicry power service unit, perform logical causal consistency forgery on the communication data packet to be obfuscated, generate an obfuscated communication data packet with logical causal consistency with the communication data packet to be obfuscated, and use it as an accompanying cover data packet of the communication data packet to be obfuscated. This data packet is then inserted into the communication flow of the PLC communication link along with the communication data packet to be obfuscated, thus obtaining the obfuscated PLC communication traffic.
[0014] As a further improvement of the present invention:
[0015] Optionally, distributed power devices in a microgrid system interact with each other via a PLC communication link, wherein the communication data packets are physical frame data in the PLC communication link, including:
[0016] The communication data packet includes data frame header information, function fields, timestamp, and payload. The data frame header information includes a start flag, a length field, and a CRC checksum. The function fields indicate the service function of the communication data packet. The timestamp is the time when the communication data packet was generated. The payload is the service layer data stream in the communication data packet.
[0017] Collect the historical communication data packet sequence sent by the distributed power equipment in the PLC communication link, extract the communication data packets from the historical communication data packet sequence, divide the communication data packets into functional categories according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, form multiple power business units, each power business unit contains multiple communication data packets, and record the generation order of each communication data packet and the functional description of the functional fields in the communication data packet;
[0018] Establish a mapping relationship between functional fields and power service units that contain communication data packets containing those functional fields, and obtain a mapping relationship table between functional fields and power service units.
[0019] Optionally, based on the communication data packets in the power service unit, the logical and causal relationships between different power service units are identified, including:
[0020] The logical relationships between different power business units include time-series transition probabilities and semantic similarity;
[0021] The timing transition probability is the frequency at which communication data packets associated with two power service units appear adjacent to each other in the communication data packet sequence;
[0022] The communication data packets associated with the power business unit are the communication data packets contained within the power business unit.
[0023] The functional descriptions are converted into word vector sequences using a word vector model. The cosine similarity between two word vector sequences is calculated as the similarity between the two functional descriptions. The mean similarity of functional descriptions between different power business units is used as the semantic similarity.
[0024] A minute-level time window is added to the communication data packet sequence sent by the distributed power equipment, dividing the communication data packet sequence into a minute-level time window sequence. The minute-level time window sequence consists of multiple consecutive minute-level time windows, and each minute-level time window contains multiple communication data packets.
[0025] The frequency of communication data packets associated with each power business unit is counted in each minute-level time window to form a frequency sequence of the power business unit.
[0026] The frequency sequences of two power business units are obtained, and an autoregressive model and an extended model based on the autoregressive model are constructed. The autoregressive model uses the frequency sequence of one power business unit for prediction, and the extended model introduces the frequency sequence of the other power business unit as a predictor on the basis of the autoregressive model.
[0027] The sum of squared residuals for the autoregressive model and the extended model were calculated separately, and the F-test was performed to obtain the P-value corresponding to the F-test. The P-value was converted to a value between 0 and 1, which was used as the causal relationship between the additional power business unit introduced in the extended model and the power business unit in the autoregressive model.
[0028] Optionally, based on the logical and causal relationships between different power business units, a logical causal graph between power business units is constructed, including:
[0029] The nodes in the logical causal graph are power business units, and the edge weights between nodes represent the logical and causal relationships between power business units. The logical relationships include the temporal transition probability and semantic similarity between two power business units, and the causal relationships are the causal relationships between two power business units.
[0030] Optionally, real-time communication data packets are acquired from the PLC communication link, and communication data packets to be obfuscated are selected from the real-time communication data packets, including:
[0031] Real-time communication data packets are collected from the PLC communication link, and the distributed power equipment from which the real-time communication data packets originate and the power business unit to which the communication data packets are classified are extracted.
[0032] The obfuscation selection rule is as follows: real-time communication data packets originating from distributed power acquisition equipment, located at the edge of the PLC communication link topology, and whose classified power business units are not causal relay nodes in the logical causal graph are selected as communication data packets to be obfuscated.
[0033] The causal relay node in the logical causal graph is the node with the smallest sum of causal pointing relationships. For causal relationship g... i→n This indicates a pointer to the power business unit. i The causal relationship, g i→n Unit represents the power business unit. i For power business units n causal relationship, Unit n Unit represents the nth power business unit. i Let i represent the i-th power business unit, where i, n ∈ [1, N], and N represents the number of power business units.
[0034] Optionally, the power service unit corresponding to the communication data packet to be obfuscated is identified, and the mimicry power service unit for performing mimicry analysis on the communication data packet to be obfuscated is selected based on the logical cause-effect graph, including:
[0035] Extract the functional fields from the communication data packets to be obfuscated. Based on the mapping table between functional fields and power service units, select the power service unit mapped to the functional fields in the communication data packets to be obfuscated as the power service unit Unit corresponding to the communication data packets to be obfuscated, where Unit ∈ {Unit} n |n∈[[1,N]};
[0036] Based on the logical causal graph, the edge weights between the power business unit (Unit) and other power business units are extracted. The edge weights represent the logical and causal relationships between the power business units, where other power business units are those different from the power business unit (Unit).
[0037] Based on the extracted edge weights, a multi-dimensional mimicry scoring model is constructed to obtain the multi-dimensional mimicry scores between the power business unit and other power business units. The power business unit with the highest multi-dimensional mimicry score is selected as the mimicry power business unit used for mimicry analysis of the communication data packets to be obfuscated.
[0038] Optionally, a converged obfuscation generation network is used to receive a simulated power service unit, and logical causality consistency forgery is performed on the communication data packets to be obfuscated to generate obfuscated communication data packets with logical causality consistent with the communication data packets to be obfuscated, including:
[0039] Extract the functional field x1 and payload x2 from the communication data packet to be obfuscated;
[0040] Calculate the similarity between the functional description of functional field x1 and the functional description of any functional field in the simulated power business unit, and the frequency of the communication data packets associated with the functional fields in the simulated power business unit in the PLC communication link. Obtain the similarity and frequency of occurrence of the functional fields in the simulated power business unit. Calculate the product between the similarity and the frequency of occurrence, and select the functional field with the highest product result as the functional field y1 in the obfuscated communication data packet.
[0041] The functional description of the functional field x1 of the communication data packet to be obfuscated, the payload x2, and the functional description of the functional field y1 in the simulated power business unit are used as inputs to the converged obfuscation generation network.
[0042] A fusion-based obfuscation generator network is used to extract the word vector sequence of functional descriptions. The effective payload x2 is compressed into a context feature vector using Transformer encoding. The word vector sequence of functional descriptions is then concatenated with the context feature vector to obtain the concatenated vector.
[0043] The generator in the fusion-type obfuscation generation network uses a multi-layer residual structure MLP module to perform semantic and numerical modal feature fusion and reconstruction on the splicing vector to obtain a functional description that conforms to the functional field y1 and a payload y2 that has a contextual association with the payload x2. The payload y2 is used as the payload in the obfuscated communication data packet.
[0044] Construct a valid data frame header as the data frame header Q of the obfuscated communication data packet, and generate the timestamp Time of the obfuscated communication data packet;
[0045] Construct a scrambled communication data packet: package = [Q, y1, Time, y2], and send the scrambled communication data packet package at timestamp Time.
[0046] To address the aforementioned problems, the present invention also provides a large-scale microgrid secure communication traffic obfuscation processing system, which includes a data acquisition device, a logical causality identification module, and a communication data packet obfuscation module.
[0047] The data acquisition device is used to acquire communication data packets, classify the communication data packets according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, construct a mapping relationship table between functional fields and power business units, and form multiple power business units.
[0048] The logical causal identification module is used to identify the logical and causal relationships between different power business units and to construct a logical causal graph between power business units.
[0049] The communication data packet obfuscation module is used to collect real-time communication data packets from the PLC communication link in real time, select the communication data packets to be obfuscated, identify the power business unit corresponding to the communication data packets to be obfuscated based on the mapping relationship table, select the mimicry power business unit for mimicry analysis of the communication data packets to be obfuscated based on the logical causal graph, receive the mimicry power business unit using the fusion obfuscation generation network, perform logical causal consistency forgery on the communication data packets to be obfuscated, generate obfuscated communication data packets, and insert the generated obfuscated communication data packets into the communication flow of the PLC communication link as the obfuscated PLC communication traffic;
[0050] This achieves the aforementioned method for obfuscating secure communication traffic in large-scale microgrids.
[0051] To address the above problems, the present invention also provides an electronic device, the electronic device comprising:
[0052] Memory, storing at least one instruction;
[0053] Communication interfaces enable communication between electronic devices; and
[0054] The processor executes the instructions stored in the memory to implement the above-described method for obfuscating secure communication traffic in a large-scale microgrid.
[0055] To address the aforementioned problems, the present invention also provides a computer-readable storage medium storing at least one instruction, which is executed by a processor in an electronic device to implement the aforementioned method for obfuscating secure communication traffic in a large-scale microgrid.
[0056] Compared with existing technologies, this invention proposes a method and system for handling secure communication traffic obfuscation in large-scale microgrids. This technology has the following beneficial effects:
[0057] First, to ensure that obfuscation is effective without affecting actual business functions, this invention designs selection criteria for communication data packets from multiple dimensions, including basic attributes such as device type and network topology location. Specifically, the selection of communication data packets is first based on the distributed power equipment and functional attributes of the communication source. Priority is given to non-control communication data packets generated from data acquisition equipment (such as electricity meters), especially those with periodic business behaviors such as "telemetry reporting" and "periodic data transmission" as their functional fields. Compared with control or alarm communication, data acquisition communication data packets have higher redundancy and time tolerance, and semantic masquerading will not interfere with the real-time control security of the power system. In addition, this invention also prioritizes high-frequency communication data packets with stable data structures as obfuscation targets to improve the naturalness and coverage of the traffic after obfuscation. Furthermore, data packets generated at the edge nodes of the PLC communication link topology are more suitable as obfuscation entry points due to their strong business independence and low upstream and downstream dependencies, which helps to achieve local controllability and overall generalization of obfuscation behavior.
[0058] Meanwhile, compared to traditional random insertion or simple scrambling obfuscation methods, this method introduces the functional semantics, temporal transition probabilities, and causal correlation information of power service units. It utilizes a fusion-based obfuscation generation network to achieve consistent forgery of the service context, making obfuscated communication packets statistically difficult to distinguish from real communication data packets. Furthermore, through pseudo-power service unit selection based on logical causal graphs, it effectively avoids scheduling errors caused by communication anomalies, significantly improving the microgrid dispatch system's resistance to traffic feature analysis attacks and ensuring the accuracy of dispatch instructions and the stability of grid operation. Attached Figure Description
[0059] Figure 1 This is a flowchart illustrating a method for handling secure communication traffic obfuscation in a large-scale microgrid, as provided in an embodiment of the present invention.
[0060] Figure 2 This is a schematic diagram illustrating an obfuscation processing method for communication data packets to be obfuscated, according to an embodiment of the present invention.
[0061] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0062] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0063] This application provides a method for obfuscating secure communication traffic in large-scale microgrids. The executing entity of this method includes, but is not limited to, at least one electronic device configured to execute the method provided in this application, such as a server or a terminal. In other words, the method can be executed by software or hardware installed on a terminal device or a server device, and the software may be a blockchain platform. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster.
[0064] Reference Figure 1 Embodiment 1 of the present invention is as follows:
[0065] S1: Collect communication data packets from the historical communication data packet sequence of the PLC communication link, divide the communication data packets into functional categories according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, form multiple power business units, and construct a mapping relationship table between functional fields and power business units.
[0066] In a microgrid system, distributed power devices interact with each other via a PLC communication link. The communication data packets are physical frame data within the PLC communication link, including:
[0067] The communication data packet includes data frame header information, function fields, timestamp, and payload. The data frame header information includes a start flag, a length field, and a CRC checksum. The function fields indicate the service function of the communication data packet. The timestamp is the time when the communication data packet was generated. The payload is the service layer data stream in the communication data packet.
[0068] Collect the historical communication data packet sequence sent by the distributed power equipment in the PLC communication link, extract the communication data packets from the historical communication data packet sequence, divide the communication data packets into functional categories according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, form multiple power business units, each power business unit contains multiple communication data packets, and record the generation order of each communication data packet and the functional description of the functional fields in the communication data packet;
[0069] Establish a mapping relationship between functional fields and power service units that contain communication data packets containing those functional fields, and obtain a mapping relationship table between functional fields and power service units.
[0070] Specifically, the power service unit includes reading service units, control or configuration service units, switch control service units, and alarm service units;
[0071] The read-type service units include, but are not limited to, function fields 0x03 and 0x04, with corresponding function descriptions of reading holding registers and reading input registers, respectively; the control or configuration-type service units include, but are not limited to, function fields 0x06 and 0x10, with corresponding function descriptions of writing a single register and writing multiple registers, respectively.
[0072] The switch control business units include, but are not limited to, 0x05 and 0x08, with corresponding function descriptions of controlling coil and controlling multiple coils, respectively; the alarm business units include, but are not limited to, function fields 0x31 and 0x32, with corresponding function descriptions of uploading alarm events and alarm confirmation responses, respectively.
[0073] It should be noted that functional fields involving register reading are classified as read-type business units, functional fields with write properties are classified as control or configuration-type business units, functional fields involving switch control are classified as switch control-type business units, and special or custom functional fields used for event reporting, alarm transmission, etc., are classified as alarm-type business units. The mapping relationship between functional fields and business units can be dynamically updated.
[0074] S2: Based on the communication data packets in the power business unit, identify the logical and causal relationships between different power business units, take the power business unit as a node, and the logical and causal relationships between the power business units as the edge weights between the nodes, and construct a logical causal graph between the power business units.
[0075] Based on the communication data packets in the power service units, identify the logical and causal relationships between different power service units, including:
[0076] The logical relationships between different power business units include time-series transition probabilities and semantic similarity;
[0077] The timing transition probability is the frequency of adjacent occurrence of communication data packets associated with two power business units in a communication data packet sequence. The higher the timing transition probability, the higher the frequency of adjacent occurrence of communication data packets associated with two power business units in the communication data packet sequence, and the stronger the logical correlation. Specifically, a higher timing transition probability also indicates that the communication data packet of one power business unit is the input or triggering condition of another power business unit.
[0078] The communication data packets associated with the power business unit are the communication data packets contained within the power business unit.
[0079] The functional descriptions are converted into word vector sequences using a word vector model. The cosine similarity between two word vector sequences is calculated as the similarity between the two functional descriptions. The mean similarity between functional descriptions of different power business units is used as the semantic similarity. The higher the semantic similarity, the more frequent the interaction and communication between the two power business units.
[0080] As an embodiment of the present invention, the word vector model is the Word2Vec model;
[0081] In one specific embodiment of this application, semantic similarity is used to smooth the temporal transition probability, wherein the calculation formula is as follows:
[0082]
[0083] Where, α i,j Unit represents the power business unit. i To the Power Business Unit j The temporal transition probability of making a transition. Represents the time transition probability α i,j Smoothness correction results; Count((Unit i →Unit j ) represents the power service unit in the communication data packet sequence. i With Power Business Unit j The number of consecutive occurrences of the associated communication data packets, Unit i Unit j Unit n These are the i, j, and n-th power business units, respectively, where i, j, n ∈ [[1, N], and N represents the number of power business units. Count(Unit) i →Unit n ) represents the power service unit in the communication data packet sequence. i With Power Business Unit n The number of times adjacent communication data packets appear together;
[0084] S n,j Unit represents the power business unit. n With Power Business Unit j The semantic similarity between them, γ represents the smoothing coefficient (preset value is 0.4 or 0.6), which is used to adjust the contribution of semantic similarity to the temporal transition probability correction;
[0085] In the traditional time-series transition probability calculation process, the transition relationship between power business units depends entirely on the actual frequency of occurrence in the communication data packet sequence, which can easily lead to a severely low or zero transition probability in sparse data areas. Especially when the communication data packet sequence is short or there are many types of power business units, the relationship between some reasonable but rare power business units will be completely ignored, which limits the diversity and robustness of the generation of obfuscated communication data packets.
[0086] Based on the above formula, according to the power business unit (Unit) j With Power Business Unit n Semantic similarity S between n,j Combining semantic similarity S n,j The associated time transition probability α i,n This yields a temporal transition probability compensation value weighted by semantic similarity for the power business unit. j With Power Business Unit n The higher the semantic similarity between them, the more frequent the interaction and communication between them, and the higher the time transition probability α. i,n The higher the value, the higher the power business unit. i With Power Business Unit n The stronger the logical relationship between them, the better for α. i,j The higher the compensation value, the less likely it is that the power business unit will be to be affected. i With Power Business Unit j There is a problem of insufficient observation leading to a low probability of time series transitions;
[0087] The smoothness correction method provided in this embodiment not only preserves the credibility of the original time-series transition probability, but also significantly improves the completeness of the expression of the time-series transition probability in low-frequency paths, enhances the semantic rationality of the obfuscated communication data packets, and improves the concealment and generalization ability of the obfuscated communication data packets generated under mimicry analysis.
[0088] A minute-level time window is added to the communication data packet sequence sent by the distributed power equipment, dividing the communication data packet sequence into a minute-level time window sequence. The minute-level time window sequence consists of multiple consecutive minute-level time windows, and each minute-level time window contains multiple communication data packets.
[0089] The frequency of communication data packets associated with each power business unit is counted in each minute-level time window to form a frequency sequence of the power business unit.
[0090] For example, if the power business unit n The frequency of occurrence of the associated communication data packets in the first to fifth minute time windows are 1, 2, 0, 5, and 4 respectively. Therefore, the power service unit (Unit) nThe frequency sequence is (1,2,0,5,4);
[0091] The frequency sequences of two power business units are obtained, and an autoregressive model and an extended model based on the autoregressive model are constructed. The autoregressive model uses the frequency sequence of one power business unit for prediction, and the extended model introduces the frequency sequence of the other power business unit as a predictor on the basis of the autoregressive model.
[0092] The sum of squared residuals for the autoregressive model and the extended model were calculated separately, and the F-test was performed to obtain the P-value corresponding to the F-test. The P-value was converted into a value between 0 and 1, which is used as the causal relationship between the additional power business unit introduced in the extended model and the power business unit in the autoregressive model. The closer the causal relationship is to 1, the more significant the causal impact of the additional power business unit introduced in the extended model on the power business unit in the autoregressive model.
[0093] Specifically, utilizing the power business unit n The autoregressive model constructed from the frequency sequence is model n Additional power business unit (Unit) introduced i The frequency sequence, the constructed extended model is as follows: Calculate the autoregressive model respectively n and extended models The residual sum of squares is calculated, and an F-test is performed to obtain the corresponding P-value. The P-value is then converted to a value between 0 and 1, which is used as the power business unit. i For power business units n The causal relationship, and also indicates a reference to the power business unit. i The causal relationship;
[0094] In one specific embodiment of this application, the conversion formula between causality and P-value is as follows:
[0095] g = 1 - min(1, p_value);
[0096] Where g represents the causal relationship obtained by converting p_value, p_value represents the P value, and min(1,p_value) means selecting the minimum value among 1 and p_value. This conversion method can extend the statistical binary judgment to a continuous numerical expression, realizing the quantitative representation of causal relationship.
[0097] Based on the logical and causal relationships between different power business units, a logical causal graph between power business units is constructed, including:
[0098] The nodes in the logical causal graph are power business units, and the edge weights between nodes represent the logical and causal relationships between power business units. The logical relationships include the temporal transition probability and semantic similarity between two power business units, and the causal relationships are the causal relationships between two power business units.
[0099] It should be noted that the logical causal graph consists of nodes and the edge weights between nodes, and is divided into a set of nodes and a set of edge weights.
[0100] The node set is {Unit n |n∈[1,N]}, the set of edge weights is {w(Unit n Unit i )|n,i∈
[0101] [1,N],n≠i},Unit n w represents the nth power business unit, N represents the number of power business units, and w(Unit) n Unit i ) represents the power business unit. n Unit i The edge weights between them, where the edge weight w(Unit) n Unit i This includes the power business unit. n With Unit i semantic similarity between sim n,i Power Business Unit n To Unit i Temporal transition probability of the transition and the power business unit i To Unit n Temporal transition probability of the transition Power Business Unit n For Unit i causal relationship g n→i and the power business unit i For Unit n causal relationship g i→n .
[0102] S3: Collect real-time communication data packets from the PLC communication link in real time, select communication data packets to be obfuscated from the real-time communication data packets according to the obfuscation selection rules, identify the power business unit corresponding to the communication data packets to be obfuscated based on the mapping relationship table, and select the mimicry power business unit for the mimicry analysis of the communication data packets to be obfuscated based on the logical cause-effect graph.
[0103] Real-time communication data packets are acquired from the PLC communication link, and communication data packets to be obfuscated are selected from the real-time communication data packets, including:
[0104] Real-time communication data packets are collected from the PLC communication link, and the distributed power equipment from which the real-time communication data packets originate and the power business unit to which the communication data packets are classified are extracted.
[0105] The obfuscation selection rule is as follows: real-time communication data packets originating from distributed power acquisition equipment, located at the edge of the PLC communication link topology, and whose classified power business units are not causal relay nodes in the logical causal graph are selected as communication data packets to be obfuscated.
[0106] The data acquisition type distributed power equipment will periodically and frequently upload real-time communication data packets. The data structure of the uploaded real-time communication data packets is fixed, the service latency tolerance is high, and the obfuscation has little impact on the service execution path.
[0107] The causal relay node in the logical causal graph is the node with the smallest sum of causal pointing relationships. The real-time communication data packets sent by this node are generally control command or task confirmation communication behaviors. For causal relationship g... i→n This indicates a pointer to the power business unit. i The causal relationship, g i→n Unit represents the power business unit. i For power business units n causal relationship, Unit n Unit represents the nth power business unit. i Let i represent the i-th power business unit, where i, n ∈ [1, N], and N represents the number of power business units;
[0108] To avoid affecting the synchronous business processes between multiple distributed power devices, real-time communication data packets sent by distributed power devices at the edge of the PLC communication link topology are obfuscated.
[0109] Identify the power service unit corresponding to the communication data packet to be obfuscated, and select the mimicry power service unit for mimicry analysis of the communication data packet to be obfuscated based on the logical cause-effect graph, including:
[0110] Extract the functional fields from the communication data packets to be obfuscated. Based on the mapping table between functional fields and power service units, select the power service unit mapped to the functional fields in the communication data packets to be obfuscated as the power service unit Unit corresponding to the communication data packets to be obfuscated, where Unit ∈ {Unit} n |n∈[[1,N]};
[0111] Based on the logical causal graph, the edge weights between the power business unit (Unit) and other power business units are extracted. The edge weights represent the logical and causal relationships between the power business units, where other power business units are those different from the power business unit (Unit).
[0112] Based on the extracted edge weights, a multi-dimensional mimicry scoring model is constructed to obtain the multi-dimensional mimicry scores between the power business unit and other power business units. The power business unit with the highest multi-dimensional mimicry score is selected as the mimicry power business unit used for mimicry analysis of the communication data packets to be obfuscated.
[0113] It should be noted that the scoring dimensions of the multi-dimensional mimicry score include structural similarity score, semantic similarity score, temporal transition probability score, and causal relationship strength score. Among them, structural similarity is calculated from the intersection and union of the neighbor nodes between two power business units. The higher the structural similarity, the more similar the neighbor nodes of the two power business units are, and the closer their structural positions in the logical causal graph. The higher the semantic similarity score, the higher the contextual mimicry consistency between the two power business units. The higher the temporal transition probability score, the more frequently the data packets associated with the two power business units appear together, which helps to enhance the realism and continuity of the context during mimicry analysis. The higher the causal relationship strength score, the higher the causal explanatory power between the two power business units.
[0114] For example, if the power business unit n With Power Business Unit i Time-frequency transition probability between The probability is greater than the preset transition probability threshold (preset 0.4), and the causal relationship g n→i If the value exceeds the preset causality threshold (preset 0.6), it indicates that the power business unit (Unit) is at risk. i For power business units n The neighboring nodes;
[0115] In one specific embodiment of this application, the scoring formula for the multi-dimensional mimicry score is:
[0116]
[0117] Where Score(Unit,Unit) n ) represents the power business unit and the power business unit. n The multi-dimensional mimicry score between them, Score k (Unit,Unit n ) represents the power business unit and the power business unit. nThe scoring results for the k-th scoring dimension, k∈[1,4], where the 1st to 4th scoring dimensions are structural similarity score, semantic similarity score, temporal transition probability score, and causal relationship strength score, respectively, λ. k This represents the rating weight of the k-th rating dimension. And presuppose λ1 = 0.2, λ2 = 0.2, λ3 = 0.3, λ4 = 0.4;
[0118] L(Unit) represents the set of neighbor nodes of a power service unit (Unit). n ) represents the power business unit. n The set of neighboring nodes, Sum(·) represents the count of nodes in the set;
[0119] Score2(Unit,Unit n (Corresponding to Power Business Unit and Power Business Unit) n The semantic similarity between them, Score3(Unit,Unit) n (Corresponding to the power business unit) n The temporal transition probability of the transition, Score4(Unit,Unit) n (Corresponding to the power business unit Unit to Unit) n causal relationship;
[0120] Compared to traditional communication obfuscation methods based on random perturbations or static rules, this application introduces four types of scoring indicators: structural similarity, semantic similarity, temporal transition probability, and causal relationship strength. This enables multi-dimensional contextual semantic mimicry analysis of the communication data packets to be obfuscated. It not only ensures the semantic consistency between the obfuscated communication packets and the functions of the real business at the semantic level, but also maintains the continuity of their structural roles, temporal order, and behavioral driving chains in the logical causal graph. This effectively avoids communication behavior anomalies or control flow interruptions caused by improper obfuscation.
[0121] Specifically, structural similarity scoring helps improve the global consistency and anti-detection capability of mimicry obfuscation, semantic similarity scoring helps generate semantically coherent and highly reasonable obfuscated communication packets, and temporal transition probability scoring helps maintain the realism of obfuscated communication flow in time series, reducing the identification risk of traffic behavior model detection. Furthermore, selecting power business unit units and power business units with causal relationships for obfuscation replacement helps maintain the continuity of the entire communication flow's functional chain and prevents abnormal behavior caused by causal breaks.
[0122] S4: Utilize the converged obfuscation generation network to receive the mimicry power service unit, perform logical causal consistency forgery on the communication data packet to be obfuscated, generate an obfuscated communication data packet with logical causal consistency with the communication data packet to be obfuscated, and use it as an accompanying cover data packet of the communication data packet to be obfuscated. This data packet is then inserted into the communication flow of the PLC communication link along with the communication data packet to be obfuscated, thus obtaining the obfuscated PLC communication traffic.
[0123] Using a converged obfuscation generation network to receive mimicry power service units, logical causality consistency forgery is performed on the communication data packets to be obfuscated, generating obfuscated communication data packets with logical causality consistent with the communication data packets to be obfuscated, including:
[0124] Extract the functional field x1 and payload x2 of the communication data packet to be obfuscated, where the functional field represents the service function of the communication data packet and the payload is the service layer data stream in the communication data packet.
[0125] Calculate the similarity between the functional description of functional field x1 and the functional description of any functional field in the simulated power business unit, and the frequency of the communication data packets associated with the functional fields in the simulated power business unit in the PLC communication link. Obtain the similarity and frequency of occurrence of the functional fields in the simulated power business unit. Calculate the product between the similarity and the frequency of occurrence, and select the functional field with the highest product result as the functional field y1 in the obfuscated communication data packet.
[0126] Specifically, a word vector model is used to convert functional descriptions into word vector sequences, and the cosine similarity between two word vector sequences is calculated as the similarity between the two functional descriptions.
[0127] The functional description of the functional field x1 of the communication data packet to be obfuscated, the payload x2, and the functional description of the functional field y1 in the simulated power business unit are used as inputs to the fusion obfuscation generation network, which is in the form of a generative adversarial neural network.
[0128] A fusion-based obfuscation generator network is used to extract the word vector sequence of functional descriptions. The effective payload x2 is compressed into a context feature vector using Transformer encoding. The word vector sequence of functional descriptions is then concatenated with the context feature vector to obtain the concatenated vector.
[0129] The generator in the fusion-type obfuscation generation network uses a multi-layer residual structure MLP module to perform semantic and numerical modal feature fusion and reconstruction on the concatenated vector to obtain a functional description that conforms to the functional field y1 and a payload y2 that has a contextual relationship with the payload x2. The payload y2 is used as the payload in the obfuscated communication data packet. Specifically, Jensen-Shannon divergence is used as the loss function for adversarial training to effectively measure the similarity between the generated obfuscated communication data packet and the distribution of real communication data, so that the obfuscated communication data packet generated by the generator approximates the real communication data packet in statistical characteristics.
[0130] Construct a valid data frame header as the data frame header Q of the obfuscated communication data packet, and generate the timestamp Time of the obfuscated communication data packet;
[0131] Construct a scrambled communication data packet: package = [Q, y1, Time, y2], and send the scrambled communication data packet package at timestamp Time.
[0132] Specifically, the timestamp Time is generated as follows:
[0133]
[0134] Where Time0 represents the timestamp of the communication data packet to be obfuscated, f represents the transmission frequency of the communication data packet associated with the mimic power business unit, and δ represents the disturbance parameter that conforms to a Gaussian distribution.
[0135] like Figure 2 The diagram illustrates an obfuscation process for communication data packets to be obfuscated. Multiple obfuscation techniques are employed to generate obfuscated communication data packets that are logically consistent in their functional fields, have payloads that conform to the descriptions of their functional fields, and possess data consistency.
[0136] This embodiment calculates the expected packet interval based on the historical packet transmission frequency of the mimic power service unit, and performs timing disturbance control by combining the timestamp of the communication data packet to be obfuscated. This effectively avoids being identified by traffic analysis due to frequency spoofing distortion. By introducing a light disturbance and time fusion mechanism, the dynamic balance and context consistency of the microgrid PLC communication traffic in the time domain after obfuscation are achieved, which significantly enhances the robustness and anti-interference capability of the microgrid dispatching system.
[0137] Example 2:
[0138] A large-scale microgrid secure communication traffic obfuscation processing system includes a data acquisition device, a logical causality identification module, and a communication data packet obfuscation module.
[0139] The data acquisition device is used to acquire communication data packets, classify the communication data packets according to the functional fields in the communication data packets, classify communication data packets with similar functions into the same power business unit, construct a mapping relationship table between functional fields and power business units, and form multiple power business units.
[0140] The logical causal identification module is used to identify the logical and causal relationships between different power business units and to construct a logical causal graph between power business units.
[0141] The communication data packet obfuscation module is used to collect real-time communication data packets from the PLC communication link, select the communication data packets to be obfuscated, identify the power service unit corresponding to the communication data packets to be obfuscated based on the mapping table, select the mimic power service unit for mimicry analysis of the communication data packets to be obfuscated based on the logical causal graph, receive the mimic power service unit using the fused obfuscation generation network, perform logical causal consistency forgery on the communication data packets to be obfuscated, generate obfuscated communication data packets, and insert the generated obfuscated communication data packets into the communication flow of the PLC communication link as the obfuscated PLC communication traffic.
[0142] It should be understood that the embodiments described are for illustrative purposes only and are not limited to this structure in the scope of the patent application.
[0143] It should be noted that the sequence numbers of the above embodiments of the present invention are merely for descriptive purposes and do not represent the superiority or inferiority of the embodiments. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, apparatus, article, or method. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0144] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0145] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.
Claims
1. A large-scale microgrid secure communication traffic obfuscation processing method, characterized in that, The method comprises: S1: collecting communication data packets from a historical communication data packet sequence of a PLC communication link, functionally classifying the communication data packets according to a function field in the communication data packets, classifying communication data packets with similar functions into the same power service unit to form a plurality of power service units, and constructing a mapping relationship table between the function field and the power service units; S2: identifying the logical relationship and the causal relationship between different power service units based on the communication data packets in the power service units, taking the power service units as nodes, and taking the logical relationship and the causal relationship between the power service units as the edge weight between the nodes to construct a logical causal graph between the power service units; The logical relationship between the different power service units comprises a time sequence transfer probability and a semantic similarity; the time sequence transfer probability is the frequency of adjacent occurrence of communication data packets associated with two power service units in the communication data packet sequence; The communication data packets associated with the power service units are the communication data packets contained in the power service units; a word vector model is used to convert the function description language into a word vector sequence, the cosine similarity between two word vector sequences is calculated as the similarity between two function description languages, and the average similarity of the function description languages between different power service units is taken as the semantic similarity; a minute-level time window is added to the communication data packet sequence sent by the distributed power equipment, the communication data packet sequence is divided into a minute-level time window sequence, the minute-level time window sequence is composed of a plurality of continuous minute-level time windows, each minute-level time window contains a plurality of communication data packets; the frequency of occurrence of the communication data packets associated with the power service units in each minute-level time window is counted to form a frequency sequence of the power service units; The frequency sequences of two power service units are obtained, an autoregressive model and an extended model based on the autoregressive model are constructed, wherein the autoregressive model uses the frequency sequence of one power service unit for prediction, and the extended model additionally introduces the frequency sequence of another power service unit as a prediction factor on the basis of the autoregressive model; The residual sum of squares of the autoregressive model and the extended model is calculated respectively, and F test is performed to obtain the P value corresponding to the F test, which is converted to a value between 0 and 1 as the causal relationship of the power service unit additionally introduced in the extended model to the power service unit in the autoregressive model; The nodes in the logical causal graph are power service units, the edge weight between the nodes is the logical relationship and the causal relationship between the power service units, the logical relationship comprises the time sequence transfer probability and the semantic similarity between two power service units, and the causal relationship is the causal relationship between the two power service units; S3: collecting real-time communication data packets from the PLC communication link in real time, selecting to-be-confused communication data packets from the real-time communication data packets according to a confusion selection rule, identifying the power service units corresponding to the to-be-confused communication data packets based on the mapping relationship table, and selecting a pseudo-state power service unit for pseudo-state analysis of the to-be-confused communication data packets based on the logical causal graph. S4: receiving a quasi-state power service unit by using the fusion confusion generation network, performing logical causal consistency forgery on the communication data packet to be confused, generating a confused communication data packet that is logically and causally consistent with the communication data packet to be confused, as a companion cover data packet of the communication data packet to be confused, inserting the confused communication data packet into the communication flow of the PLC communication link together with the communication data packet to be confused, and obtaining PLC communication traffic after confusion processing; The confused communication data packet that is logically and causally consistent with the communication data packet to be confused is generated by: Extracting functional fields of communication data packets to be obfuscated and payloads ; The function description words of the function fields of the plurality of power service units are compared with each other to obtain a similarity between the function description words of the function fields of the plurality of power service units. The similarity between the function description words of the function fields of the plurality of power service units is obtained by comparing the function description words of the function fields of the plurality of power service units with each other. The similarity between the function description words of the function fields of the plurality of power service units is obtained by comparing the function description words of the function fields of the plurality of power service units with each other. functionality field of a communication data packet to be obfuscated functionality description, payload and functionality field in a metamorphic power service unit as input to a fusion obfuscation generation network; The functional description words are extracted into word vector sequences by using a fusion confusion generation network, and the payloads are encoded into context feature vectors by using a Transformer encoding mode The word vector sequences of the functional description words are spliced with the context feature vectors to obtain spliced vectors The generator in the fusion confusion generation network uses an MLP module with a multi-layer residual structure to perform feature fusion and reconstruction of the splicing vector in the semantic and numerical modalities, to obtain a functional description statement conforming to the functional field and a payload associated with the context , the payload as a payload in the confusion communication data packet; Constructing format valid data frame header information as data frame header information of obfuscated communication data packets and generating a timestamp of the obfuscated communication data packets ; Constructing obfuscated communication data packets: at a timestamp obfuscated communication data packets are issued.
2. The method of claim 1, wherein the method further comprises: The distributed power equipment in the micro-grid system exchanges information through the PLC communication link, and the communication data packet is a physical frame data in the PLC communication link, including: The communication data packet includes data frame header information, a function field, a timestamp, and a payload, wherein the data frame header information includes a start flag, a length field, and a CRC check code, the function field indicates the service function of the communication data packet, the timestamp is the generation time of the communication data packet, and the payload is the service layer data stream in the communication data packet; Collecting a sequence of historical communication data packets sent by the distributed power equipment in the PLC communication link, extracting the communication data packet from the sequence of historical communication data packets, functionally dividing the communication data packet according to the function field in the communication data packet, classifying the communication data packets with similar functions into the same power service unit, forming a plurality of power service units, wherein each power service unit contains a plurality of communication data packets, and recording the generation order of each communication data packet and the function description of the function field in the communication data packet; A mapping relationship between the function field and the power service unit containing the function field is established, and a mapping relationship table between the function field and the power service unit is obtained.
3. The method of claim 1, wherein the method further comprises: Real-time communication data packets are collected from the PLC communication link in real time, and the communication data packet to be confused is selected from the real-time communication data packets, including: Real-time communication data packets are collected from the PLC communication link in real time, and the distributed power equipment from which the real-time communication data packet originates and the power service unit to which the communication data packet is classified are extracted; The confusion selection rule is to select a real-time communication data packet as the communication data packet to be confused, which originates from a collection-type distributed power equipment, is located at the edge of the PLC communication link topology, and the classified power service unit is not a causal relay node in the logical causal graph; The causal relay node in the logic causal graph is the node with the minimum sum of causal direction relations, for the causal relation , represents a causal direction relation to the power service unit , represents a causal relation of the power service unit to the power service unit , represents the nth power service unit, represents the nth power service unit, , N represents the number of power service units.
4. The secure communication traffic obfuscation method for a large-scale microgrid of claim 3, wherein, Identifying the power service unit corresponding to the communication data packet to be confused, selecting a quasi-state power service unit for quasi-state analysis of the communication data packet to be confused based on the logical causal graph, including: extracting a function field in the communication data packet to be confused, selecting a power service unit to which the function field in the communication data packet to be confused is mapped as the power service unit corresponding to the communication data packet to be confused based on a mapping relationship table between the function field and the power service unit wherein ; Extracting power business units based on a logical causal graph edge weights between other power business units, the edge weights being logical and causal relationships between the power business units and the other power business units, wherein the other power business units are different power business units from the power business unit According to the extracted edge weight, a multi-dimensional quasiparticle scoring model is constructed to obtain the power business unit The multi-dimensional quasiparticle score between the power business unit and other power business units is selected, and the power business unit with the highest multi-dimensional quasiparticle score is selected as the quasiparticle power business unit for quasiparticle analysis of the communication data packet to be confused.
5. A large-scale microgrid secure communication traffic obfuscation processing system, characterized in that, The large-scale micro-grid secure communication traffic confusion processing system includes a data collection device, a logical causal identification module, and a communication data packet confusion module: The data collection device is used to collect communication data packets, functionally divide the communication data packets according to the function field in the communication data packets, classify the communication data packets with similar functions into the same power service unit, construct a mapping relationship table between the function field and the power service unit, and form a plurality of power service units; The logic-causality identification module is configured to identify the logic relationship and the causality relationship between different power service units, and to construct a logic-causality graph between the power service units; The communication data packet confusion module is configured to collect real-time communication data packets from a PLC communication link in real time, select a communication data packet to be confused, identify the power service unit corresponding to the communication data packet to be confused based on a mapping relationship table, select a quasi-energy power service unit for quasi-energy analysis of the communication data packet to be confused based on the logic-causality graph, receive the quasi-energy power service unit by using a fusion-type confusion generation network, perform logic-causality consistency forgery on the communication data packet to be confused, generate a confused communication data packet, insert the generated confused communication data packet into a communication stream of the PLC communication link as PLC communication traffic after confusion processing, and achieve the method for large-scale micro-grid secure communication traffic confusion processing according to any one of claims 1-4. The method for large-scale micro-grid secure communication traffic confusion processing according to any one of claims 1-4.
Citation Information
Patent Citations
Generative adversarial network-based power grid flow data privacy protection method and system
CN119210801A
Power production data private network security situation awareness system and method
CN120110735A