Identity authentication method and device of power distribution network equipment, electronic equipment and medium

By employing a phased multimodal feature and layered blockchain authentication method, the security and efficiency issues in the identity authentication of power distribution network equipment are resolved. This method effectively identifies and defends against counterfeit devices and advanced attacks, thereby improving the accuracy of authentication and the robustness of the system.

CN120856342APending Publication Date: 2025-10-28INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510854289.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

The existing wireless device identity authentication technology for distribution networks has problems such as high trust risk, insufficient physical layer security protection, easy circumvention of single authentication methods, poor environmental adaptability, difficulty in balancing authentication efficiency and security, and lack of an efficient hierarchical collaborative management mechanism.

Method used

The authentication method adopts a phased multimodal feature and layered blockchain approach. It collects communication behavior information and radio frequency signals of devices through edge nodes to perform communication behavior authentication and hardware-level identity authentication. It combines self-attention mechanism and Bayesian optimized feature extraction to construct a legitimate radio frequency fingerprint template and uses blockchain for authentication log and identity credential management.

Benefits of technology

It significantly improves the ability to identify and defend against counterfeit devices and advanced attacks, enhances the security and authentication accuracy of power distribution network equipment access, improves authentication efficiency and system robustness, and adapts to dynamic changes in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856342A_ABST
    Figure CN120856342A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to the technical field of power system security and block chains, and provides an identity authentication method and device for power distribution network equipment, electronic equipment and a medium, and the method comprises the steps: in response to an access request of the power distribution network equipment to be accessed to a power system, collecting first stream data sent by the power distribution network equipment, the first stream data comprises communication behavior information of the power distribution network equipment; performing communication behavior authentication on the power distribution network equipment based on the communication behavior information; after the communication behavior authentication is passed, acquiring a first original radio frequency signal or first channel state information of the power distribution network equipment through an edge node; and performing hardware-level identity authentication on the power distribution network equipment based on the first original radio frequency signal or the first channel state information. Therefore, rapid, accurate and credible identity authentication of massive wireless equipment of the power distribution network is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of power system security and blockchain technology, and in particular to an identity authentication method, device, electronic device and medium for power distribution network equipment. Background Technology

[0002] As smart grids evolve towards distributed and intelligent architectures, wireless communication technologies, such as Long Term Evolution (LTE) private networks and Wireless Local Area Networks (WLANs), are widely used in distribution networks. These technologies support remote monitoring, coordinated control, and optimized management of massive numbers of devices, including smart meters and Data Transfer Units (DTUs), significantly improving the automation level and operational reliability of the distribution network. However, the large-scale access of wireless terminal devices and the openness of wireless channels in distribution networks also bring serious security challenges, mainly manifested in: 1. Inherent security threats in wireless communication environments: Wireless channels are susceptible to eavesdropping and interference. Attackers can use tools such as Software Defined Radio (SDR) to perform MAC address spoofing and replay attacks, resulting in man-in-the-middle attacks involving "legitimate identity + illegitimate device", which seriously threatens the security of data flow in the power distribution network.

[0003] 2. Management challenges arising from device heterogeneity and dynamic access: Distribution networks contain a wide variety of devices (such as smart meters, sensors, and controllers), and their status (online / offline) changes frequently, placing higher demands on the adaptability and efficiency of identity authentication systems. Traditional centralized authentication schemes struggle to cope with such complex and dynamic scenarios.

[0004] Currently, the main technical solutions for identity authentication of wireless terminal equipment in power distribution networks are as follows: Traffic-based authentication schemes: These schemes monitor and analyze the behavioral characteristics of device communication traffic (such as communication frequency, packet size distribution, protocol sequences, etc.), and use machine learning algorithms to build device behavior models for identity determination. While easy to deploy, this approach is susceptible to network fluctuations and has limited ability to detect sophisticated spoofing attacks.

[0005] Encryption-based identity authentication schemes employ symmetric or asymmetric encryption algorithms, using pre-set keys or digital certificates to encrypt and verify device identity information. While this approach offers high security, key management is complex, centralized key distribution presents a single point of failure risk, and end-to-end encryption may introduce significant latency, making it unsuitable for all edge devices.

[0006] Physical fingerprint-based authentication schemes extract inherent, difficult-to-copy physical features of device hardware (such as phase / amplitude characteristics of radio frequency signals, clock offset, and electromagnetic radiation characteristics of circuit boards) as device fingerprints for identification. This scheme effectively resists software-level spoofing attacks, but is susceptible to environmental interference; the robustness of feature extraction and matching remains a key challenge.

[0007] The aforementioned existing wireless device authentication schemes for power distribution networks still have many shortcomings in practical applications, making it difficult to fully meet the requirements of new power systems for secure, efficient, and reliable authentication. For example, schemes based on traffic characteristics lack robustness and security: the extracted traffic characteristics are easily affected by factors such as network environment fluctuations and equipment load changes, leading to feature drift and a high false positive rate. Attackers can bypass authentication by mimicking the communication patterns of legitimate devices or performing traffic replay attacks, and this scheme usually lacks the ability to monitor abnormal behavior during device operation in real time. Schemes based on encryption mechanisms suffer from centralization risks and cost / delay issues: traditional centralized key management models face the risk of single point of failure and key leakage. Relying on secure chips to store keys will significantly increase hardware modification costs and deployment difficulty. In addition, especially for resource-constrained edge devices, complex encryption / decryption and on-chain verification processes may introduce unacceptable authentication delays. Schemes based on physical fingerprints are greatly affected by the environment and lack collaborative mechanisms: physical features such as radio frequency fingerprints are easily affected by environmental factors such as signal propagation path attenuation, multipath effects, and noise interference during the collection process, leading to fingerprint feature distortion and affecting authentication accuracy. Meanwhile, existing solutions mostly employ a single-level authentication architecture, lacking a collaborative mechanism for rapid local verification and global cross-domain auditing. This leads to decreased system throughput when authenticating massive numbers of devices concurrently, and makes it difficult to adapt to the hierarchical and partitioned management characteristics and business needs of power distribution networks. Furthermore, directly performing high-precision physical fingerprint authentication on all devices incurs enormous computational overhead and is inefficient. The lack of multi-dimensional information fusion and dynamic adaptability is another issue: authentication schemes based on a single feature source cannot comprehensively characterize device identity and are vulnerable to targeted attacks. Most existing solutions lack effective multi-modal feature collaboration mechanisms and fail to fully utilize the dynamic changes in device behavior to improve the persistence and robustness of authentication.

[0008] Therefore, the existing wireless device authentication technologies for power distribution networks have problems such as high trust risks, insufficient physical layer security protection, easy circumvention of single authentication methods, poor environmental adaptability, difficulty in balancing authentication efficiency and security, and lack of efficient hierarchical collaborative management mechanisms, which urgently need to be solved. Summary of the Invention

[0009] This invention provides a method, device, electronic device, and medium for identity authentication of power distribution network equipment, which addresses the shortcomings of existing technologies such as high trust risk, insufficient physical layer security protection, easy circumvention of single authentication methods, poor environmental adaptability, difficulty in balancing authentication efficiency and security, and lack of efficient hierarchical collaborative management mechanisms, thereby achieving fast, accurate, and reliable identity authentication for a large number of wireless devices in the power distribution network.

[0010] This invention provides an authentication method for power distribution network equipment, comprising: In response to an access request from a distribution network device seeking to connect to the power system, first stream data sent by the distribution network device is collected, wherein the first stream data includes communication behavior information of the distribution network device; The communication behavior of the power distribution network equipment is authenticated based on the communication behavior information. Once the communication behavior authentication is successful, the first original radio frequency signal or the first channel status information of the power distribution network equipment is collected through the edge node. Hardware-level authentication is performed on the power distribution network equipment based on the first original radio frequency signal or the first channel state information.

[0011] In one possible implementation, the method further includes: Second-stream data of the secure power distribution network equipment is collected through edge nodes, wherein the second-stream data contains communication behavior information of the secure power distribution network equipment; The second stream data is denoised, and the denoised second stream data is divided according to a preset time window to obtain multiple second stream data subsequences; The plurality of second-stream data subsequences are converted into a fixed-length two-dimensional sequence matrix; A feature extraction model based on a self-attention mechanism is used to extract features from the two-dimensional sequence matrix to obtain a fixed-dimensional behavioral feature vector. The optimal hyperparameters of the Bayesian optimization automatic clustering algorithm are selected with the goal of maximizing the silhouette coefficient. Based on the behavioral feature vector, the behavioral feature clusters of the safety distribution network equipment are performed to obtain multiple behavioral feature categories. Among them, the equipment behavior patterns in each behavioral feature category are similar and legitimate.

[0012] In one possible implementation, the method further includes: Acquire the second raw radio frequency signal or second channel status information of the safe distribution network equipment, and acquire the second device identifier of the safe distribution network equipment; Extract the second radio frequency fingerprint feature vector from the second original radio frequency signal or the second channel state information; A valid radio frequency fingerprint template for the secure power distribution network device is constructed based on the second radio frequency fingerprint feature vector and the second device identifier.

[0013] In one possible implementation, the method further includes: Based on the communication behavior information, extract the first behavior feature vector of the power distribution network equipment corresponding to the communication behavior information; Calculate the vector similarity between the first behavioral feature vector and the behavioral feature vectors in the plurality of behavioral feature categories; When the vector similarity is less than a preset similarity threshold, it is determined that the communication behavior authentication of the power distribution network equipment has failed, and an abnormal audit is performed on the power distribution network equipment. When the vector similarity is greater than or equal to a preset similarity threshold, the communication behavior authentication of the power distribution network equipment is determined to be successful.

[0014] In one possible implementation, the method further includes: Extract the first radio frequency fingerprint feature vector from the first original radio frequency signal or the first channel state information; Obtain the first device identifier of the power distribution network equipment; Query the target valid radio frequency fingerprint template corresponding to the second device identifier that is the same as the first device identifier; Compare the cosine similarity between the first radio frequency fingerprint feature vector and the target legitimate radio frequency fingerprint template; When the cosine similarity is greater than or equal to a preset similarity threshold, the hardware-level identity of the power distribution network equipment is determined to be legitimate. When the cosine similarity is less than a preset similarity threshold, the hardware-level identity of the power distribution network equipment is determined to be illegal.

[0015] In one possible implementation, the method further includes: The multiple behavioral feature categories and legitimate radio frequency fingerprint templates are recorded in the blockchain; The authentication logs for communication behavior authentication and hardware-level identity authentication are recorded in the blockchain.

[0016] The present invention also provides an identity authentication device for power distribution network equipment, comprising the following modules: The acquisition module is used to acquire first stream data sent by the power distribution network equipment in response to the access request of the power distribution network equipment to be connected to the power system, wherein the first stream data includes communication behavior information of the power distribution network equipment; The authentication module is used to authenticate the communication behavior of the power distribution network equipment based on the communication behavior information. The acquisition module is also used to acquire the first original radio frequency signal or the first channel status information of the power distribution network equipment through the edge node after the communication behavior authentication is passed; The authentication module is also used to perform hardware-level identity authentication on the power distribution network equipment based on the first original radio frequency signal or the first channel state information.

[0017] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the authentication method for power distribution network equipment as described above.

[0018] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the authentication method for power distribution network equipment as described above.

[0019] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the authentication method for power distribution network equipment as described above.

[0020] The present invention provides a method, apparatus, electronic device, and medium for authenticating distribution network equipment. In response to an access request from a distribution network equipment seeking to connect to the power system, the method collects first-stream data sent by the distribution network equipment, wherein the first-stream data includes communication behavior information of the distribution network equipment. Based on the communication behavior information, the method performs communication behavior authentication on the distribution network equipment. After successful communication behavior authentication, the method collects a first original radio frequency signal or a first channel state information of the distribution network equipment through an edge node. Based on the first original radio frequency signal or the first channel state information, the method performs hardware-level authentication on the distribution network equipment. Compared to the shortcomings of existing technologies, such as high trust risk, insufficient physical layer security protection, susceptibility to circumvention of single authentication methods, poor environmental adaptability, difficulty in balancing authentication efficiency and security, and lack of an efficient hierarchical collaborative management mechanism, this solution significantly improves the identification and resistance capabilities against advanced attacks such as spoofed devices, unauthorized access, and SDR forgery through phased verification of collaborative behavior characteristics and physical fingerprints, thereby comprehensively enhancing the security and authentication accuracy of distribution network equipment access. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0022] Figure 1 This is a flowchart illustrating the identity authentication method for power distribution network equipment provided by the present invention.

[0023] Figure 2 This is a flowchart illustrating the behavioral feature clustering method provided by the present invention.

[0024] Figure 3 This is a schematic diagram of the process for constructing a legitimate radio frequency fingerprint template provided by the present invention.

[0025] Figure 4 This is one of the flowcharts illustrating the communication behavior authentication provided by the present invention.

[0026] Figure 5 This is the second schematic diagram of the communication behavior authentication process provided by the present invention.

[0027] Figure 6 This is a schematic diagram of the hardware-level identity authentication process provided by the present invention.

[0028] Figure 7 This is a schematic diagram of the radio frequency fingerprint feature extraction model based on CNN and contrastive learning provided by the present invention.

[0029] Figure 8 This is a schematic diagram of the device registration and authentication management process based on consortium blockchain at the regional layer provided by the present invention.

[0030] Figure 9 This is a schematic diagram of the identity authentication device for power distribution network equipment provided by the present invention.

[0031] Figure 10 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0032] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0033] To facilitate understanding of the embodiments of the present invention, further explanations and descriptions will be provided below with reference to the accompanying drawings and specific embodiments. These embodiments do not constitute a limitation on the embodiments of the present invention.

[0034] Figure 1 This is a flowchart illustrating the identity authentication method for power distribution network equipment provided by the present invention, as shown below. Figure 1 As shown, the method includes the following: S11. In response to the access request of the distribution network equipment to be connected to the power system, collect the first stream data sent by the distribution network equipment.

[0035] This invention provides a method for identity authentication of power distribution network equipment based on phased multimodal features and hierarchical blockchain. The method mainly comprises three core components: a first-stage coarse-grained behavioral authentication, a second-stage fine-grained radio frequency physical fingerprint authentication, and authentication management and information synchronization based on hierarchical blockchain.

[0036] First, in the initial stage, rapid and preliminary identity screening of access devices is performed, filtering out devices with obviously abnormal or unexpected behavioral patterns to reduce the pressure on the subsequent fine-grained authentication in the second stage. In response to access requests from distribution network devices seeking to connect to the power system, first-stream data sent by these devices is collected through edge nodes. This first-stream data includes communication behavior information of the distribution network devices (e.g., quintuples, timing, and statistical characteristics such as specific command frequencies). Rapid identity screening is achieved by analyzing the macroscopic characteristics of device communication behavior. Edge nodes refer to computing and communication devices deployed at the network edge.

[0037] S12. Authentication of the communication behavior of the power distribution network equipment based on the communication behavior information.

[0038] In this embodiment of the invention, a feature extraction model can be used to extract features from the first stream data, and the communication behavior feature vector of the power distribution network equipment can be extracted from the communication behavior information in the first stream data.

[0039] Furthermore, the communication behavior feature vectors of distribution network equipment can be compared with the legitimate equipment behavior patterns of pre-built secure distribution network equipment to authenticate the communication behavior of distribution network equipment.

[0040] If the communication behavior authentication of the power distribution network equipment passes, the next stage of fine-grained authentication will begin; otherwise, the system can use anomaly rules to determine whether to refuse access or mark the device as an unknown device and trigger an audit.

[0041] S13. After the communication behavior is authenticated, the first original radio frequency signal or the first channel status information of the power distribution network equipment is collected through the edge node.

[0042] To ensure the physical uniqueness of devices and prevent advanced spoofing attacks (such as SDR spoofing), this stage of hardware-level identity verification (fine-grained radio frequency physical fingerprint authentication) is performed on devices that pass communication behavior authentication or require deep verification.

[0043] Once the communication behavior is authenticated, the edge node collects the raw radio frequency signals (such as I / Q sampling data) or channel state information (CSI) of the power distribution network equipment and transmits them to the regional authentication server.

[0044] S14. Perform hardware-level identity authentication on the power distribution network equipment based on the first original radio frequency signal or the first channel status information.

[0045] Hardware-level authentication verifies the true identity of a device by analyzing its physical signal characteristics, preventing unauthorized access. It compares the acquired raw radio frequency signal or channel state information with pre-stored device hardware characteristics. It analyzes whether the signal's frequency, amplitude, phase, and other characteristics match the device's hardware features. It also checks whether the channel state information conforms to the device's transmission characteristics. Hardware-level authentication ensures that accessing devices are authorized and genuine, preventing unauthorized devices from accessing the system through fraudulent communication behavior.

[0046] If hardware-level authentication passes, the device successfully connects to the power system. If authentication fails, the system rejects the device's access and may log relevant events for later analysis.

[0047] The authentication method for distribution network equipment provided by this invention, in response to the access request of the distribution network equipment to be connected to the power system, collects the first stream data sent by the distribution network equipment, wherein the first stream data includes the communication behavior information of the distribution network equipment; performs communication behavior authentication on the distribution network equipment based on the communication behavior information; when the communication behavior authentication is successful, collects the first original radio frequency signal or the first channel state information of the distribution network equipment through an edge node; and performs hardware-level authentication on the distribution network equipment based on the first original radio frequency signal or the first channel state information. Compared with the shortcomings of existing technologies, such as high trust risk, insufficient physical layer security protection, easy circumvention of single authentication methods, poor environmental adaptability, difficulty in balancing authentication efficiency and security, and lack of efficient hierarchical collaborative management mechanism, this method significantly improves the ability to identify and resist advanced attacks such as counterfeit devices, unauthorized access, and SDR forgery through phased verification of collaborative behavior characteristics and physical fingerprints, thereby comprehensively enhancing the security and authentication accuracy of distribution network equipment access.

[0048] Figure 2 This is a flowchart illustrating the behavioral feature clustering method provided by the present invention, specifically including: S21. Acquire second-stream data from secure power distribution network equipment via edge nodes.

[0049] This invention mainly illustrates a behavior feature clustering method, which collects second-stream data from security distribution network equipment through edge nodes. The second-stream data contains communication behavior information of the security distribution network equipment.

[0050] Specifically, streaming data mainly includes the following aspects: Five-tuple information: refers to five key pieces of information used to uniquely identify a network connection in network communication, including: Source IP address: The IP address of the device that initiated the communication.

[0051] Destination IP address: The IP address of the device receiving the communication.

[0052] Source port number: The port number used by the device that initiates the communication.

[0053] Destination port number: The port number used by the receiving device.

[0054] Protocol type: The network protocol used (such as TCP, UDP, etc.).

[0055] This information helps identify and differentiate different network connections and is the basis for analyzing device communication behavior.

[0056] Timing characteristics: refer to the characteristics of device communication behavior in the time dimension, including: Communication timestamp: The specific time point at which a device sends or receives data.

[0057] Communication interval: The time interval between continuous communication between devices.

[0058] Communication duration: The duration of a single communication process between the devices.

[0059] By analyzing these timing characteristics, we can understand the communication frequency and patterns of the device, which helps to identify abnormal behavior.

[0060] Statistical characteristics: These refer to the characteristics obtained from statistical analysis of device communication data, including: Data packet size distribution: The distribution of data packet sizes sent or received by the device.

[0061] Specific command frequency: The frequency at which a device sends specific commands during communication.

[0062] Total communication traffic: The total amount of data sent and received by a device within a certain period of time.

[0063] These statistical characteristics can reflect the communication load and behavior patterns of a device, helping to identify normal and abnormal states of the device.

[0064] Other relevant information includes: Device type and status: The type of device (such as smart meter, sensor, controller, etc.) and the current status of the device (such as online or offline).

[0065] Communication protocol details: The specific communication protocol used by the device and its details, such as the TCP three-way handshake process and the connectionless nature of UDP.

[0066] Error and exception information: Error information and exceptions generated during device communication, such as packet loss and retransmission.

[0067] Streaming data plays a crucial role in the authentication of distribution network equipment, including: Behavioral modeling: By analyzing streaming data, a normal communication behavior model of the device can be constructed for subsequent identity authentication.

[0068] Anomaly detection: Anomalies in streaming data can help identify whether a device has been attacked or faces other security threats.

[0069] Rapid screening: In the first stage of coarse-grained authentication, the statistical and temporal characteristics of streaming data can quickly screen out devices with obviously abnormal behavior patterns, reducing the pressure on subsequent authentication.

[0070] S22. The second stream data is denoised, and the denoised second stream data is divided according to a preset time window to obtain multiple second stream data subsequences.

[0071] The second-stream data undergoes denoising to remove useless, interfering, or irrelevant portions, retaining only useful information. In the streaming data of distribution network equipment, the primary purpose of denoising is to remove abnormal or inaccurate data points caused by network fluctuations, equipment failures, environmental interference, and other factors. This noisy data may interfere with subsequent analysis and authentication processes, leading to misjudgments.

[0072] S23. Convert the plurality of second-stream data subsequences into a fixed-length two-dimensional sequence matrix.

[0073] Then, the denoised second-stream data is segmented and converted into a fixed-length two-dimensional sequence matrix according to the time window. Segmentation by time window refers to dividing continuous streaming data into multiple subsequences according to fixed time intervals. This segmentation method helps to break down long-term continuous data into smaller, more easily processed segments, facilitating subsequent feature extraction and analysis.

[0074] S24. Use a feature extraction model based on self-attention mechanism to extract features from the two-dimensional sequence matrix to obtain a fixed-dimensional behavioral feature vector.

[0075] Subsequently, a Transformer-based feature extraction model is used to process the sequence matrix and generate a fixed-dimensional (e.g., 128-dimensional) behavioral feature vector. The extracted behavioral feature vectors are used for subsequent behavioral modeling and clustering.

[0076] S25. The optimal hyperparameters of the clustering algorithm are automatically selected using Bayesian optimization, with the goal of maximizing the silhouette coefficient. Based on the behavioral feature vector, the behavioral feature clustering of the safety distribution network equipment is performed to obtain multiple behavioral feature categories.

[0077] This invention employs the optimal hyperparameters of the Density-Based Spatial Clustering of Applications with Noise (DBSCAN) algorithm to maximize the silhouette coefficient and achieve high-quality clustering of device behavior features. Each resulting cluster represents a class of legitimate device behavior patterns.

[0078] Device behavior feature clustering refers to grouping the communication behavior feature vectors of devices into groups such that devices within the same group exhibit similar behaviors, while devices in different groups show significant differences in behavior. The purpose of clustering is to identify different types of device behavior patterns, thereby enabling rapid determination of whether the behavior of the device to be authenticated belongs to a known legitimate behavior pattern during subsequent authentication processes.

[0079] DBSCAN is a density-based clustering algorithm. It forms clusters by finding high-density regions and can identify noise points (i.e., points that do not belong to any cluster). The main advantages of DBSCAN are that it does not require pre-specifying the number of clusters, can handle clusters of different shapes and sizes, and is highly robust to noise.

[0080] The DBSCAN algorithm has two key parameters: ε (epsilon): representing the radius of the neighborhood, used to define the neighborhood range of a point; and MinPts (minimum number of points): representing the minimum number of points required within the neighborhood, used to define whether a point is a core point. The choice of these two parameters has a significant impact on the quality of the clustering results.

[0081] Bayesian optimization is an optimization method based on Bayes' theorem, used to find the optimal value of an objective function within a given search space. It constructs a probabilistic model to predict the value of the objective function and uses this model to guide the search process, thereby efficiently finding the optimal solution. Bayesian optimization is particularly suitable for situations where the objective function has high computational cost or the search space is large. In this embodiment of the invention, Bayesian optimization is used to automatically select the hyperparameters (ε and MinPts) of the DBSCAN algorithm to maximize the quality of the clustering results.

[0082] The silhouette coefficient is a metric for evaluating the quality of clustering, used to measure the effectiveness of clustering results. The silhouette coefficient ranges from [-1, 1], where: Close to 1: This indicates that the clustering results are very good, with points within the same cluster being very close to each other and points between different clusters being very far apart.

[0083] Close to 0: This indicates that the clustering results are average, with points within the same cluster and points between different clusters being close in distance.

[0084] Close to -1: This indicates poor clustering results, where points within the same cluster are more distant than points between different clusters.

[0085] By maximizing the silhouette coefficient, the quality of clustering results can be ensured, meaning that devices within the same cluster exhibit highly similar behavior, while devices in different clusters show significant differences in behavior.

[0086] The specific steps are as follows: Define the objective function: Use the silhouette coefficient as the objective function, and evaluate the quality of the clustering results by maximizing the silhouette coefficient.

[0087] Constructing a probabilistic model: Use Bayesian optimization to construct a probabilistic model to predict the silhouette coefficient values ​​under different combinations of hyperparameters.

[0088] Optimized Search: Using Bayesian optimization methods, we can efficiently search within a given hyperparameter search space to find the hyperparameter combination that maximizes the silhouette coefficient.

[0089] Perform clustering: Use the optimized hyperparameters to execute the DBSCAN clustering algorithm to obtain high-quality clustering results of device behavior features.

[0090] This invention employs the Transformer model to deeply mine the temporal dependencies of device TCP stream data and extract highly discriminative behavioral feature vectors. It can automatically and efficiently select the optimal clustering parameters and combine Bayesian-optimized DBSCAN clustering and Dirichlet distribution to accurately model the probabilistic behavior patterns of legitimate devices, providing a foundation for subsequent robust similarity comparison based on Wasserstein distance.

[0091] Figure 3 This is a schematic diagram of the process for constructing a legitimate radio frequency fingerprint template provided by the present invention, specifically including: S31. Collect the second original radio frequency signal or second channel status information of the safe distribution network equipment, and collect the second device identifier of the safe distribution network equipment.

[0092] The construction of a legitimate radio frequency fingerprint template is based on the radio frequency signal characteristics of secure power distribution network equipment, used to verify the physical identity of the equipment in the fine-grained authentication stage. The main construction steps include: During the registration phase, secure distribution network equipment needs to send multiple radio frequency (RF) signal samples, which are received by edge nodes or dedicated acquisition devices. The acquired signals typically include raw RF signals (such as I / Q sampled data) or channel state information (CSI).

[0093] Optionally, the acquired radio frequency signals need to be preprocessed to remove noise and environmental interference. Preprocessing may include signal filtering, normalization, and other operations. For example, an additive white Gaussian noise (AWGN) model can be used to simulate and remove noise.

[0094] S32. Extract the second radio frequency fingerprint feature vector from the second original radio frequency signal or the second channel state information.

[0095] S33. Construct a legitimate radio frequency fingerprint template for the secure power distribution network device based on the second radio frequency fingerprint feature vector and the second device identifier.

[0096] like Figure 7 As shown, a deep learning model based on Convolutional Neural Networks (CNN) is used to extract refined radio frequency fingerprint feature vectors from the received radio frequency signals / CSI data. ,in This refers to the fingerprint feature dimension. To improve the discriminative power and robustness of the features, positive sample pairs (different signal samples from the same device) are constructed. ) and negative sample pairs (signal samples from different devices) And optimize using the contrastive loss function Triplet Loss: in It is a CNN model (feature extractor). They are the first The triplet consists of the anchor point, positive sample, and negative sample signals, with margin being a preset boundary value. This loss function aims to cluster fingerprints of similar devices more closely together in the feature space, while keeping fingerprints of dissimilar devices further apart.

[0097] The extracted radio frequency fingerprint feature vectors are used as radio frequency fingerprint templates for legitimate power distribution network equipment and stored in a regional layer blockchain or associated storage. These templates will be used in subsequent authentication processes, comparing them with the real-time radio frequency fingerprints of the equipment to be authenticated to determine the equipment's legitimacy.

[0098] This invention utilizes a convolutional neural network (CNN) to extract a fine physical fingerprint from the device's radio frequency signal / CSI. By introducing contrastive learning mechanisms such as Triplet Loss for model optimization, the intra-class compactness and inter-class separability of fingerprint features are enhanced. Furthermore, methods such as cosine similarity are employed for high-precision fingerprint comparison to ensure the uniqueness of the device's physical identity.

[0099] Figure 4 This is one of the flowcharts illustrating the communication behavior authentication provided by the present invention, specifically including: S41. Based on the communication behavior information, extract the first behavior feature vector of the power distribution network equipment corresponding to the communication behavior information.

[0100] The embodiments of the present invention are combined with Figure 5 The second flowchart illustrating the communication behavior authentication process is provided below. First, in the first stage, a rapid, preliminary identity screening of access devices is performed, filtering out devices with obviously abnormal or unexpected behavioral patterns to reduce the pressure on the subsequent fine-grained authentication in the second stage. In response to access requests from distribution network devices seeking to connect to the power system, the edge nodes collect the first-stream data sent by these devices. This first-stream data includes communication behavior information of the distribution network devices (e.g., quintuples, timing, and statistical characteristics such as specific command frequencies). Rapid identity screening is achieved by analyzing the macroscopic characteristics of the device communication behavior. Edge nodes refer to computing and communication devices deployed at the network edge.

[0101] S42. Calculate the vector similarity between the first behavioral feature vector and the behavioral feature vectors in the plurality of behavioral feature categories.

[0102] In this embodiment of the invention, similarity comparison and authentication decision-making based on Wasserstein distance can be performed. The behavioral feature vector of the distribution network equipment to be authenticated. (or the distribution it forms) and the modeled legitimate device behavior patterns (Dirichlet distributions of each cluster) or its center of mass Similarity is measured by calculating the Wasserstein distance (or its approximation). It can also be calculated using other vector similarity comparison methods.

[0103] S43. When the vector similarity is less than a preset similarity threshold, it is determined that the communication behavior authentication of the power distribution network equipment has failed, and an abnormal audit is performed on the power distribution network equipment.

[0104] S44. When the vector similarity is greater than or equal to a preset similarity threshold, the communication behavior authentication of the power distribution network equipment is determined to be successful.

[0105] If the Wasserstein distance is less than a preset threshold If the communication behavior authentication of the distribution network equipment is successful, it will proceed to the next stage of fine-grained authentication; otherwise, it will determine whether to refuse access or mark it as an unknown device and trigger auditing based on the abnormal rules.

[0106] The rapid behavior screening mechanism in the first stage provided by the embodiments of the present invention effectively optimizes the authentication process, greatly improves authentication efficiency and reduces system overhead, and is especially suitable for the needs of concurrent authentication of massive devices.

[0107] Figure 6 This is a schematic diagram of the hardware-level identity authentication process provided by the present invention, specifically including: S61. Extract the first radio frequency fingerprint feature vector from the first original radio frequency signal or the first channel state information.

[0108] To ensure the physical uniqueness of devices and prevent advanced spoofing attacks (such as SDR spoofing), this stage of hardware-level identity verification (fine-grained radio frequency physical fingerprint authentication) is performed on devices that pass communication behavior authentication or require deep verification.

[0109] Once the communication behavior is authenticated, the edge node collects the raw radio frequency signals (such as I / Q sampling data) or channel state information (CSI) of the power distribution network equipment and transmits them to the regional authentication server.

[0110] S62. Obtain the first device identifier of the power distribution network equipment.

[0111] S63. Query the target legitimate radio frequency fingerprint template corresponding to the second device identifier that is the same as the first device identifier.

[0112] By querying the device identifier of the distribution network equipment, the device identifier of the safe distribution network equipment that is the same as the device identifier in the pre-built legitimate radio frequency fingerprint template is obtained. The legitimate radio frequency fingerprint template corresponding to the device identifier of the safe distribution network equipment is used as the target template to perform fine-grained identity authentication on the distribution network equipment to be connected.

[0113] S64. Compare the cosine similarity between the first radio frequency fingerprint feature vector and the target legitimate radio frequency fingerprint template.

[0114] Hardware-level authentication verifies the true identity of a device by analyzing its physical signal characteristics, preventing counterfeit devices from accessing the network.

[0115] Extracted real-time radio frequency fingerprint feature vector of the device to be authenticated The legitimate RFID fingerprint template corresponding to the device ID pre-existing in the regional layer blockchain (or associated storage) will be used. Using cosine similarity Perform high-precision comparison.

[0116] S65. When the cosine similarity is greater than or equal to the preset similarity threshold, the hardware-level identity of the power distribution network equipment is determined to be legitimate.

[0117] S66. When the cosine similarity is less than the preset similarity threshold, the hardware-level identity of the power distribution network equipment is determined to be illegal.

[0118] If the real-time fingerprint highly matches the template (similarity greater than or equal to the preset similarity threshold) If the device's hardware-level identity is valid, then the device's hardware-level identity is deemed valid; otherwise, the device's hardware-level identity is deemed invalid.

[0119] This invention utilizes a convolutional neural network (CNN) to extract a fine physical fingerprint from the device's radio frequency signal / CSI. By introducing contrastive learning mechanisms such as Triplet Loss for model optimization, the intra-class compactness and inter-class separability of fingerprint features are enhanced. Furthermore, methods such as cosine similarity are employed for high-precision fingerprint comparison to ensure the uniqueness of the device's physical identity.

[0120] It should be noted that in the identity authentication method of this power distribution network equipment, the authentication logs of the above-mentioned communication behavior authentication and hardware-level identity authentication are recorded in the blockchain.

[0121] To achieve reliable and efficient management of the above two-stage authentication process (coarse-grained behavioral authentication and fine-grained radio frequency fingerprint authentication), and to ensure the secure sharing and storage of device identity credentials, authentication records and key operation logs, this invention constructs a three-level blockchain-enabled system of "edge layer - regional layer - global layer".

[0122] Edge Layer: As the front end of the authentication process, it is primarily responsible for performing rapid, coarse-grained behavioral authentication in the first stage and acquiring the radio frequency data required for the fine-grained authentication in the second stage. Its preliminary authentication results and requests for further processing are reported to the region layer.

[0123] Regional Layer: Corresponding to a specific geographical or administrative area, this layer is built on consortium blockchain technology. Its nodes can include authentication servers and key gateways within the region. The regional layer is the core hub of authentication management, primarily responsible for executing the more computationally intensive second-stage fine-grained RFID fingerprint authentication. More importantly, the regional layer automates key management processes through smart contracts, including: Device registration and identity credential management: Securely record the identity identifiers of new devices, such as behavioral model hashes and RF fingerprint template hashes, on the consortium blockchain.

[0124] Authentication results on the blockchain: The final results of the two-stage authentication and their key summary information are recorded and stored as evidence.

[0125] Authentication policy management: Supports dynamic adjustment and secure distribution of authentication policies to edge layer nodes. Specific processes at the regional layer, such as device registration, authentication log recording, and policy management, can be implemented through corresponding smart contract interfaces, such as... Figure 8 The diagram shows a schematic of the device registration and authentication management process based on a consortium blockchain at the regional layer provided by this invention.

[0126] Global Layer: Can be built on a public blockchain or a higher-level consortium blockchain. Its main function is to synchronize and store critical, long-term, and globally visible authentication log summaries, global abnormal behavior traces, and cross-regional authentication audit information from various regional layers. Leveraging the immutability of blockchain, the global layer provides the system with global security auditing, attack tracing, and dispute arbitration capabilities.

[0127] This three-tiered blockchain architecture clarifies the responsibilities of each layer (rapid response at the edge layer, in-depth authentication and trusted management at the regional layer, and audit supervision at the global layer), achieving a reasonable allocation of authentication tasks. Leveraging the core advantages of blockchain technology (decentralization, immutability, transparency, and traceability), it significantly improves the security, reliability, and management efficiency of the entire power distribution network equipment identity authentication system.

[0128] This invention constructs a three-tiered blockchain system: edge layer, regional layer, and global layer. The edge layer performs rapid behavioral authentication and data collection; the regional layer consortium blockchain automates core processes such as device registration (behavioral model hash and fingerprint template hash on-chain), authentication result recording, and authentication policy management through smart contracts; and the global layer provides cross-regional auditing and traceability capabilities. This system ensures transparency, trustworthiness, and efficient collaboration throughout the entire authentication process.

[0129] Ultimately, the identity authentication method for distribution network equipment provided by this invention significantly improves the ability to identify and resist advanced attacks such as counterfeit devices, unauthorized access, and SDR forgery through phased verification of collaborative behavioral features and physical fingerprints, thereby comprehensively enhancing the security and authentication accuracy of distribution network equipment access. Its first-stage rapid behavioral screening mechanism effectively optimizes the authentication process, significantly improving authentication efficiency and reducing system overhead, especially adapting to the needs of concurrent authentication of massive numbers of devices. Simultaneously, by combining the first-stage behavioral modeling, Wasserstein distance comparison, and the second-stage contrastive learning-optimized fingerprint extraction technology, this invention enhances the robustness and dynamic adaptability of the authentication system in complex environments such as network fluctuations, signal interference, and normal evolution of device behavior. More importantly, the application of layered blockchain and smart contracts ensures the immutability, transparency, traceability, and efficient collaborative management of key data such as device identity credentials, authentication policies, and authentication logs, achieving reliable assurance and automated operation of the entire authentication process, eliminating the risks of traditional centralized authentication, and providing a solid foundation for security auditing. By providing reliable device identity authentication, it effectively prevents unauthorized access by malicious devices, powerfully guaranteeing the security of distribution network communication and the stability and reliability of power services.

[0130] The authentication device for power distribution network equipment provided by the present invention is described below. The authentication device for power distribution network equipment described below can be referred to in correspondence with the authentication method for power distribution network equipment described above.

[0131] Figure 9 This is a schematic diagram of the structure of the identity authentication device for power distribution network equipment provided by the present invention, specifically including: The acquisition module 901 is used to acquire first-stream data sent by the distribution network equipment in response to an access request from the equipment to be connected to the power system. The first-stream data includes communication behavior information of the distribution network equipment. For detailed explanation, please refer to the relevant descriptions in the above method embodiments; they will not be repeated here.

[0132] The authentication module 902 is used to authenticate the communication behavior of the power distribution network equipment based on the communication behavior information. For detailed explanations, please refer to the relevant descriptions in the above method embodiments; they will not be repeated here.

[0133] The acquisition module 901 is further configured to acquire the first original radio frequency signal or the first channel status information of the power distribution network equipment through the edge node after the communication behavior authentication is successful. For detailed explanations, please refer to the relevant descriptions in the above method embodiments, which will not be repeated here.

[0134] The authentication module 902 is further configured to perform hardware-level identity authentication on the power distribution network equipment based on the first original radio frequency signal or the first channel state information. For detailed explanations, please refer to the relevant descriptions in the above method embodiments; they will not be repeated here.

[0135] Figure 10 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 10 As shown, the electronic device may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840, wherein the processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The processor 810 can call logical instructions in the memory 830 to execute an authentication method for the distribution network equipment. This method includes: responding to an access request from a distribution network equipment seeking to connect to the power system, collecting first stream data sent by the distribution network equipment, wherein the first stream data includes communication behavior information of the distribution network equipment; performing communication behavior authentication on the distribution network equipment based on the communication behavior information; after successful communication behavior authentication, collecting a first raw radio frequency signal or first channel state information of the distribution network equipment through an edge node; and performing hardware-level authentication on the distribution network equipment based on the first raw radio frequency signal or first channel state information.

[0136] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0137] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the authentication method for distribution network equipment provided by the above methods. The method includes: in response to an access request from a distribution network equipment to be connected to the power system, collecting first stream data sent by the distribution network equipment, wherein the first stream data includes communication behavior information of the distribution network equipment; performing communication behavior authentication on the distribution network equipment based on the communication behavior information; after the communication behavior authentication is successful, collecting a first original radio frequency signal or a first channel state information of the distribution network equipment through an edge node; and performing hardware-level authentication on the distribution network equipment based on the first original radio frequency signal or the first channel state information.

[0138] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements an authentication method for distribution network equipment provided by the methods described above. The method includes: in response to an access request from a distribution network equipment to be connected to the power system, collecting first stream data sent by the distribution network equipment, wherein the first stream data includes communication behavior information of the distribution network equipment; performing communication behavior authentication on the distribution network equipment based on the communication behavior information; after the communication behavior authentication is successful, collecting a first original radio frequency signal or a first channel state information of the distribution network equipment through an edge node; and performing hardware-level authentication on the distribution network equipment based on the first original radio frequency signal or the first channel state information.

[0139] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0140] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0141] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for authenticating the identity of power distribution network equipment, characterized in that, include: In response to an access request from a distribution network device seeking to connect to the power system, first stream data sent by the distribution network device is collected, wherein the first stream data includes communication behavior information of the distribution network device; The communication behavior of the power distribution network equipment is authenticated based on the communication behavior information. Once the communication behavior authentication is successful, the first original radio frequency signal or the first channel status information of the power distribution network equipment is collected through the edge node. Hardware-level authentication is performed on the power distribution network equipment based on the first original radio frequency signal or the first channel state information.

2. The method according to claim 1, characterized in that, The method further includes: Second-stream data of the secure power distribution network equipment is collected through edge nodes, wherein the second-stream data contains communication behavior information of the secure power distribution network equipment; The second stream data is denoised, and the denoised second stream data is divided according to a preset time window to obtain multiple second stream data subsequences; The plurality of second-stream data subsequences are converted into a fixed-length two-dimensional sequence matrix; A feature extraction model based on a self-attention mechanism is used to extract features from the two-dimensional sequence matrix to obtain a fixed-dimensional behavioral feature vector. The optimal hyperparameters of the Bayesian optimization automatic clustering algorithm are selected with the goal of maximizing the silhouette coefficient. Based on the behavioral feature vector, the behavioral feature clusters of the safety distribution network equipment are performed to obtain multiple behavioral feature categories. Among them, the equipment behavior patterns in each behavioral feature category are similar and legitimate.

3. The method according to claim 1, characterized in that, The method further includes: Acquire the second raw radio frequency signal or second channel status information of the safe distribution network equipment, and acquire the second device identifier of the safe distribution network equipment; Extract the second radio frequency fingerprint feature vector from the second original radio frequency signal or the second channel state information; A valid radio frequency fingerprint template for the secure power distribution network device is constructed based on the second radio frequency fingerprint feature vector and the second device identifier.

4. The method according to claim 2, characterized in that, The communication behavior authentication of the power distribution network equipment based on the communication behavior information includes: Based on the communication behavior information, extract the first behavior feature vector of the power distribution network equipment corresponding to the communication behavior information; Calculate the vector similarity between the first behavioral feature vector and the behavioral feature vectors in the plurality of behavioral feature categories; When the vector similarity is less than a preset similarity threshold, it is determined that the communication behavior authentication of the power distribution network equipment has failed, and an abnormal audit is performed on the power distribution network equipment. When the vector similarity is greater than or equal to a preset similarity threshold, the communication behavior authentication of the power distribution network equipment is determined to be successful.

5. The method according to claim 3, characterized in that, The hardware-level authentication of the power distribution network equipment based on the first original radio frequency signal or the first channel state information includes: Extract the first radio frequency fingerprint feature vector from the first original radio frequency signal or the first channel state information; Obtain the first device identifier of the power distribution network equipment; Query the target valid radio frequency fingerprint template corresponding to the second device identifier that is the same as the first device identifier; Compare the cosine similarity between the first radio frequency fingerprint feature vector and the target legitimate radio frequency fingerprint template; When the cosine similarity is greater than or equal to a preset similarity threshold, the hardware-level identity of the power distribution network equipment is determined to be legitimate. When the cosine similarity is less than a preset similarity threshold, the hardware-level identity of the power distribution network equipment is determined to be illegal.

6. The method according to any one of claims 2-5, characterized in that, The method further includes: The multiple behavioral feature categories and legitimate radio frequency fingerprint templates are recorded in the blockchain; The authentication logs for communication behavior authentication and hardware-level identity authentication are recorded in the blockchain.

7. An identity authentication device for power distribution network equipment, characterized in that, include: The acquisition module is used to acquire first stream data sent by the power distribution network equipment in response to the access request of the power distribution network equipment to be connected to the power system, wherein the first stream data includes communication behavior information of the power distribution network equipment; The authentication module is used to authenticate the communication behavior of the power distribution network equipment based on the communication behavior information. The acquisition module is also used to acquire the first original radio frequency signal or the first channel status information of the power distribution network equipment through the edge node after the communication behavior authentication is passed; The authentication module is also used to perform hardware-level identity authentication on the power distribution network equipment based on the first original radio frequency signal or the first channel state information.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the authentication method for power distribution network equipment as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the identity authentication method for power distribution network equipment as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the authentication method for power distribution network equipment as described in any one of claims 1 to 6.