Protection setting value calibration device and method
By using multi-protocol communication and encrypted storage technology to protect the setpoint calibration device, the problems of insufficient protocol compatibility and low data security in the existing technology are solved, and efficient and reliable setpoint calibration and data security are achieved.
Patent Information
- Application Number
- CN202510849310.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-11-21
AI Technical Summary
Existing protection device setting management technologies suffer from insufficient protocol compatibility, cumbersome operation, and low data security, making it difficult to meet the needs of rapid on-site commissioning.
A protective setpoint calibration device is provided, including a main control module, a multi-protocol communication module and a security module. By dynamically adapting to the communication protocols of different manufacturers, it performs setpoint data interaction and comparison, and achieves efficient calibration and data security through encrypted storage to prevent tampering and evidence preservation.
It enables dynamic interaction, efficient comparison and repair of setting data from protection devices of different manufacturers, ensuring the compatibility, reliability and data security of setting calibration, and improving calibration efficiency.
Smart Images

Figure CN120999514A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of power system technology, and in particular to a protection setting calibration device and method. Background Technology
[0002] Against the backdrop of rapid development of smart grids, the setting management of substation protection devices, as a crucial link in the safe and stable operation of power systems, faces higher requirements in terms of accuracy, reliability, and efficiency. The accurate calibration and safe management of protection settings directly affect the rapid isolation of grid faults and system recovery. Errors in settings or management loopholes can lead to serious accidents such as large-scale power outages and equipment damage. Currently, substation protection device setting management technologies mainly employ solutions such as manual recording, vendor-specific software, general-purpose handheld debugging instruments, and mobile applications.
[0003] However, existing technologies suffer from several drawbacks: For example, traditional manual recording methods rely on paper ledgers, which are not only inefficient and prone to errors, but also suffer from the fatal flaws of easily lost and untraceable records. While PC-based, single-vendor software can read setpoints, it only supports a single vendor's protocol and cannot adapt to the proprietary extended fields of other vendors' devices. Furthermore, such solutions require an external laptop, which is severely lacking in portability for field operations, making it difficult to meet the needs of rapid on-site debugging. Mobile application solutions rely on mobile terminals, which suffer from poor reliability and are prone to crashes and disconnections in the strong electromagnetic environment of substations. Therefore, existing protection device setpoint management technologies suffer from insufficient protocol compatibility, cumbersome operation, and low data security.
[0004] The preceding description is intended to provide general background information and does not necessarily constitute prior art. Summary of the Invention
[0005] To address the shortcomings of existing protection device setting management technologies, such as insufficient protocol compatibility, cumbersome operation, and low data security, this application provides a protection setting calibration device and method. This method enables dynamic interaction, efficient comparison, and repair of setting data from protection devices from different manufacturers. Furthermore, it uses encrypted storage to prevent tampering of operation logs, thereby improving the efficiency of setting calibration while effectively ensuring its compatibility, reliability, and data security.
[0006] To achieve the above objectives, this application provides a protection setting calibration device, including a main control module, and a multi-protocol communication module and a security module respectively connected to the main control module;
[0007] The multi-protocol communication module is used to dynamically adapt to the communication protocols of protection devices from different manufacturers, and to establish communication with the protection device according to the communication protocol, and to exchange setpoint data with the protection device.
[0008] The main control module is used to perform group hash comparison and tolerance determination on the acquired fixed value data, and generate corresponding repair instructions;
[0009] The security module is used to encrypt and store the set value data in order to prevent tampering and preserve the operation log.
[0010] Furthermore, in some embodiments of this application, the multi-protocol communication module includes:
[0011] A serial communication interface for supporting at least one serial communication protocol;
[0012] Ethernet interface, used to support at least one Ethernet communication protocol;
[0013] The wireless communication module is used to support cloud download of protocol libraries and log upload.
[0014] Furthermore, in some embodiments of this application, the main control module includes:
[0015] The protocol parsing unit is used to dynamically load the protocol driver library according to the device identification information of protection devices from different manufacturers, match the corresponding communication protocol, and parse the standard protocol and private extension fields based on the communication protocol.
[0016] A two-level comparison unit is used to locate the difference group through a hash tree and perform tolerance comparison on the parameters within the difference group;
[0017] Repair the control unit, which is used to generate a setpoint write command and perform secondary verification.
[0018] Furthermore, in some embodiments of this application, the protocol parsing unit includes:
[0019] The identification reading subunit is used to read the device identification information of protection devices from different manufacturers, as well as to read the imported setting text and the real-time operating setting of the protection device;
[0020] The local loading subunit is used to load the corresponding protocol driver from the local protocol library according to the device identification information;
[0021] The cloud caching subunit is used to obtain and cache the corresponding protocol driver from the cloud server when the local protocol library has no matching driver.
[0022] Furthermore, in some embodiments of this application, the two-level comparison unit includes:
[0023] The hash tree comparison subunit is used to generate hash values by grouping the read real-time fixed values, construct the corresponding Merkle tree, and compare the Merkle tree with the benchmark file to locate the difference group;
[0024] The tolerance comparison subunit is used to compare the parameters in the difference group item by item and to determine the floating-point differences using a relative error method.
[0025] Furthermore, in some embodiments of this application, the leaf nodes of the Merkle tree are SHA-256 hash values of the same type of fixed parameter, and the parent node of the Merkle tree is a cascaded hash of the child node hash values.
[0026] Furthermore, in some embodiments of this application, the security module includes:
[0027] An encrypted storage unit is used to encrypt and store a baseline value using a preset encryption algorithm, and the key for the baseline is bound to a unique device identifier;
[0028] The blockchain evidence storage unit is used to generate the hash value corresponding to the operation log and upload it to the blockchain node for evidence storage.
[0029] Furthermore, in some embodiments of this application, the device further includes a repair authentication module, which is used to verify the fixed value data read a second time after executing the repair instruction. If the verification shows inconsistency, an alarm is triggered and an error report is generated.
[0030] Furthermore, in some embodiments of this application, the device further includes a human-computer interaction module for enabling interactive operation between the user and the protection setting calibration device; the human-computer interaction module includes a touch screen for displaying a two-column comparison view of the difference items and exporting a report.
[0031] Accordingly, this application also provides a protection setting calibration method, performed on the protection setting calibration device described above, comprising the following steps:
[0032] It dynamically adapts to the communication protocols of protection devices from different manufacturers, establishes communication with the protection device according to the communication protocol, and exchanges setpoint data with the protection device.
[0033] The obtained fixed-value data is subjected to grouped hash comparison and tolerance determination, and corresponding repair instructions are generated.
[0034] The fixed value data is encrypted and stored to prevent tampering and preserve evidence of the operation log.
[0035] Implementing the embodiments of this application has the following beneficial effects:
[0036] As described above, this application provides a protection setting calibration device and method. The protection setting calibration device includes a main control module, a multi-protocol communication module, and a security module, which are respectively connected to the main control module. The multi-protocol communication module is used to dynamically adapt to the communication protocols of protection devices from different manufacturers, establish communication with the protection device according to the communication protocol, and exchange setting data with the protection device. The main control module is used to perform group hash comparison and tolerance determination on the acquired setting data, and generate corresponding repair instructions. The security module is used to encrypt and store the setting data to prevent tampering and provide evidence for the operation log. In the protection setting calibration scheme provided in this application, a multi-protocol communication module dynamically adapts to the communication protocols of protection devices from different manufacturers, ensuring the compatibility of setting calibration. This allows the device to communicate and exchange setting data with protection devices from various manufacturers. The main control module performs group hash comparison and tolerance determination on the acquired setting data and generates repair instructions. This not only quickly locates differences in the setting data but also accurately determines whether the data is within the allowable range through tolerance determination, thus achieving precise calibration. A security module encrypts and stores the setting data, ensuring its security and integrity. Therefore, this application enables dynamic interaction, efficient comparison, and repair of setting data from protection devices from different manufacturers. Encrypted storage prevents tampering of operation logs, improving the efficiency of setting calibration while effectively ensuring its compatibility, reliability, and data security. Attached Figure Description
[0037] Figure 1 This is a schematic diagram of the structure of the protection setting calibration device in one embodiment of this application;
[0038] Figure 2 This is another structural schematic diagram of the protection setting calibration device in one embodiment of this application;
[0039] Figure 3 This is a schematic flowchart of a protection setting calibration method in one embodiment of this application.
[0040] The realization of the purpose, functional features and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0041] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application.
[0042] Figure 1 This is a schematic diagram of the structure of the protection setting calibration device in one embodiment of this application. (Reference) Figure 1 The protection setting calibration device may specifically include a main control module 10, a multi-protocol communication module 20 and a security module 30 respectively connected to the main control module;
[0043] The multi-protocol communication module 20 is used to dynamically adapt to the communication protocols of protection devices from different manufacturers, and to establish communication with the protection device according to the communication protocol, and to exchange setpoint data with the protection device.
[0044] Specifically, the multi-protocol communication module 20 is responsible for communicating with protection devices from different manufacturers, achieving dynamic adaptation of multiple communication protocols. It includes an RS485 interface (supporting Modbus-RTU and DNP3 protocols, with an adaptive baud rate of 9600–115200 bps), a fiber optic Ethernet interface (supporting IEC 61850 MMS / GOOSE protocols, with a transmission distance ≥10 km), and a Wi-Fi 6 / 5G module (for remote log upload and firmware upgrades). By automatically reading the SCL file or sending Modbus function code 0x43 to read the device identifier, it downloads the corresponding driver from the local protocol library or the cloud, achieving seamless communication with devices from different manufacturers. The multi-protocol communication module can be further expanded to support more emerging communication protocols and technologies, such as Industrial Internet of Things (IIoT) protocols and 5G private network communication, to adapt to the ever-evolving communication needs of smart grids. Simultaneously, it can optimize protocol switching and adaptation algorithms, improving communication efficiency and stability, and reducing communication latency and data loss.
[0045] The main control module 10 is used to perform group hash comparison and tolerance determination on the acquired fixed value data, and generate corresponding repair instructions;
[0046] Specifically, the main control module 10, as the core control unit of the protection setting calibration device, is built on the Rockchip RK3588S chip, possessing powerful processing capabilities and multi-task parallel processing capabilities. This chip uses a 6nm process, features an eight-core ARM Cortex-A76 / A55 architecture with a main frequency of up to 2.4GHz, and is equipped with 4GB LPDDR5 memory and 64GB eMMC storage, enabling it to quickly process large amounts of setting data and run multiple functional units simultaneously. The main control module can also integrate more advanced data processing algorithms and artificial intelligence technologies, such as machine learning algorithms, to predict potential setting deviations through analysis of historical setting data and calibration records, providing early warnings and calibration optimization. Simultaneously, the main control module can be deeply integrated with other smart grid systems to achieve broader grid monitoring and control functions.
[0047] Security module 30 is used to encrypt and store the fixed value data in order to prevent tampering and preserve the operation log;
[0048] Specifically, for security module 30, an independent security chip (such as the XST-SE200 from Chipstar Technology) is used to encrypt and store setpoint data, ensuring data confidentiality and integrity. Simultaneously, the security module is also responsible for generating hash values for operation logs and uploading them to blockchain nodes for evidence storage. Leveraging the immutability of the blockchain, the authenticity and traceability of the operation logs are guaranteed. The security module can further strengthen security mechanisms, such as adding multi-factor authentication to improve the security of user authentication; and employing more advanced encryption algorithms and key management mechanisms to enhance data encryption strength and key security. Furthermore, it can be linked with the power grid's network security system to monitor and prevent network security threats in real time, ensuring the safe operation of the calibration device.
[0049] In a specific embodiment, the main control module is based on the Rockchip RK3588S chip and connects to multi-protocol communication modules via general purpose input / output (GPIO) interfaces, serial peripheral interfaces (SPI), or mobile industrial processor interfaces (MIPI). For example, RS485 interfaces, fiber optic Ethernet interfaces, and wireless communication modules (Wi-Fi 6 / 5G) are all connected to the corresponding interfaces of the main control module to achieve data transmission. The main control module connects to the security module via a secure access bus (such as ARM's TrustZone technology). The security module is an independent chip (such as the Chipstar XST-SE200) that shares part of the data bus with the main control module, but its internal encrypted storage area interacts with the main control module through a secure authentication mechanism. When the main control module needs to encrypt and store fixed-value data or read encrypted data, it sends the data to the security module through the secure bus for encryption or decryption operations. At the same time, the security module will return the encrypted data or operation results to the main control module. The RS485 interface of the multi-protocol communication module is connected to the corresponding serial interface of the protection device via a twisted pair cable; the fiber optic Ethernet interface is connected to the Ethernet port of the protection device via a fiber optic patch cord; and the wireless communication module communicates with the protection device that has wireless communication capabilities via a wireless network (such as Wi-Fi or 5G network).
[0050] This embodiment achieves efficient calibration and secure management of setting values for protection devices from different manufacturers through the collaborative work of the main control module, multi-protocol communication module, and security module. The multi-protocol communication module ensures compatibility with various protection devices and quickly acquires setting data; the main control module uses advanced algorithms to process and calibrate the data, improving the accuracy and efficiency of calibration; and the security module ensures the confidentiality and integrity of the data, preventing data leakage and tampering, and providing reliable protection for the safe and stable operation of the power grid.
[0051] Furthermore, in some embodiments, the multi-protocol communication module 20 may specifically include:
[0052] A serial communication interface for supporting at least one serial communication protocol;
[0053] Specifically, the serial communication interface primarily uses the RS485 interface, supporting various serial communication protocols such as Modbus-RTU and DNP3. The baud rate can be adaptively adjusted within the range of 9600–115200 bps. Its electrical characteristics conform to the EIA-RS-485 standard, employing differential balanced transmission to effectively suppress common-mode interference. The transmission distance can reach 1200 meters, and it can connect more than 32 nodes. The communication line uses shielded twisted-pair cable, and surge protectors and transient voltage suppression diodes are installed at the interface to ensure stable operation in the strong electromagnetic interference environment of substations.
[0054] Ethernet interface, used to support at least one Ethernet communication protocol;
[0055] Specifically, the Ethernet interface primarily uses a fiber optic Ethernet interface, supporting the IEC 61850 MM / GOOSE protocol. This interface can achieve a transmission distance of over 10km and a communication rate of 100Mbps / 1000Mbps auto-sensing. The interface uses LC or SC type fiber optic connectors to connect to the fiber optic Ethernet port of the protection device, and data transmission is achieved through fiber optic patch cords. The interface is internally equipped with an optical module that can convert between electrical and optical signals and has an automatic optical power adjustment function to adapt to the transmission requirements of fiber optic cables of different lengths.
[0056] The wireless communication module is used to support cloud download of protocol libraries and log upload.
[0057] Specifically, the wireless communication module mainly consists of a Wi-Fi 6 module and a 5G module, supporting wireless communication protocols such as IEEE 802.11ax and 3GPP NR, enabling remote log uploading and firmware upgrades. The Wi-Fi 6 module operates in the 2.4GHz and 5GHz frequency bands, supporting new technologies such as OFDMA and TWT, providing high-speed and stable local area network communication; the 5G module supports frequency bands such as n41, n78, and n79, enabling wide area network coverage. The module is equipped with a high-gain antenna, which enhances signal reception and transmission capabilities, ensuring reliable wireless communication even in the complex environment of a substation.
[0058] This embodiment ensures a stable connection with traditional protection devices through a serial communication interface, meets the high-speed data transmission requirements of modern intelligent protection devices through an Ethernet interface, and provides flexibility and convenience for remote communication through a wireless communication module. This ensures that the calibration device can communicate and exchange data efficiently with protection devices of various types and from different manufacturers, providing strong support for achieving high efficiency and accuracy in setting value calibration.
[0059] Furthermore, in some embodiments, the main control module 10 may specifically include:
[0060] The protocol parsing unit is used to dynamically load the protocol driver library based on the device identification information of protection devices from different manufacturers, match the corresponding communication protocol, and parse the standard protocol and private extension fields based on the communication protocol.
[0061] Specifically, the protocol parsing unit is a crucial component of the main control module. It is responsible for dynamically loading protocol driver libraries based on the device identification information of protection devices from different manufacturers and matching the corresponding communication protocols. It can parse standard protocols (such as IEC 61850, Modbus, DNP3, etc.) and proprietary extended fields, converting non-standard protocol data into a unified format for subsequent processing.
[0062] Two-level comparison units are used to locate the difference group through the hash tree and perform tolerance comparison on the parameters within the difference group;
[0063] Specifically, the two-level comparison unit includes a hash tree comparison subunit and a tolerance comparison subunit. The hash tree comparison subunit generates hash values by grouping the read real-time fixed values, constructs a Merkle tree, and compares it with the benchmark file to quickly locate the difference group. The tolerance comparison subunit compares the parameters within the difference group item by item, using a relative error method to determine floating-point differences, ensuring the accuracy and consistency of the data.
[0064] Repair the control unit to generate a setpoint write command and perform secondary verification;
[0065] Specifically, the repair control unit is responsible for generating setting value write commands and performing secondary verification. After confirming the discrepancies, the repair control unit generates the corresponding write command according to the communication protocol and sends it to the protection device for setting value repair. After the repair is completed, the setting value data is read again for verification to ensure the accuracy and reliability of the repair.
[0066] This embodiment ensures compatibility and adaptability to communication protocols of protection devices from different manufacturers through a protocol parsing unit. A two-level comparison unit improves the efficiency and accuracy of setting data comparison, while the repair control unit enables automatic repair and verification, guaranteeing the accuracy and reliability of the setting data. This integrated and automated processing significantly enhances the performance and efficiency of the calibration device, providing strong technical support for the setting management of power grid protection devices.
[0067] Furthermore, in some embodiments, the protocol parsing unit may specifically include:
[0068] The identification reading subunit is used to read the device identification information of protection devices from different manufacturers, as well as to read the imported setting text and the real-time operating setting of the protection device;
[0069] Specifically, the identification reading subunit is responsible for reading the device identification information of protection devices from different manufacturers, typically by parsing the identification data packets returned by the protection device. Device identification information can include key data such as manufacturer code, device model, and serial number, forming the basis for subsequent dynamic protocol loading. For example, for protection devices supporting the IEC 61850 standard, the identification reading subunit can obtain detailed device information by parsing the field identification field in the MMS message; for devices using the Modbus protocol, it can read data from the device identification register by sending a specific function code (such as function code 0x43). Furthermore, artificial intelligence technology can be combined to intelligently classify and manage device identification data, improving the efficiency and intelligence level of device identification.
[0070] Furthermore, the identification reading subunit in this embodiment can not only read device identification information from protection devices of different manufacturers, but also has the ability to read imported setting text and read real-time operating setting values from the protection device. Imported setting text can be imported via USB, SD card, or network transmission, and the text format is typically CSV, XML, or JSON. Device operating setting values are read from the protection device via a multi-protocol communication module. In addition, automatic verification and conversion functions can be added to the imported setting text to ensure the correctness and consistency of the text format. Real-time monitoring and early warning functions can be added to the device operating setting values to promptly detect abnormal situations.
[0071] The local loading subunit is used to load the corresponding protocol driver from the local protocol library based on the device identification information;
[0072] Specifically, the local loading subunit retrieves the device identification information from the identification read subunit and searches for and loads the corresponding manufacturer and device model's protocol driver from the local protocol library (usually stored in the calibration device's internal memory, such as eMMC or SSD). The local protocol library contains protocol drivers for various common manufacturers and devices, which define the specific rules and data formats for communication with the corresponding protection devices. For example, for NARI Group's PCS-900 series protection devices, the local loading subunit loads its corresponding IEC 61850 proprietary extended protocol driver to correctly parse and process its setting data. Simultaneously, more efficient storage and retrieval algorithms can be employed to improve the loading speed and reliability of the protocol driver. Furthermore, some local optimization functions for the protocol driver can be added to better adapt it to the communication characteristics of specific devices.
[0073] The cloud caching subunit is used to retrieve and cache the corresponding protocol driver from the cloud server when there is no matching driver in the local protocol library;
[0074] Specifically, the cloud-based caching subunit activates when a matching driver is not found in the local protocol library. It connects to the cloud server via the calibration device's wireless communication module (such as 4G / 5G or Wi-Fi), sends device identification information to the server, and requests the download of the corresponding protocol driver. The cloud server stores a more comprehensive protocol driver library, covering various manufacturers and device models. After downloading, the cloud-based caching subunit caches the acquired protocol driver in the local protocol library for later use. For example, when encountering a new Siemens protection device whose driver is not found in the local protocol library, the cloud-based caching subunit downloads and caches the device's DNP3 proprietary protocol driver from the cloud. Simultaneously, a pre-loading function for cloud-based protocol drivers can be added, downloading potentially needed protocol drivers in advance based on device usage history and trend predictions, reducing on-site waiting time. Furthermore, the collaborative management between the cloud-based caching subunit and the local protocol library can be enhanced to achieve more intelligent caching strategies and space management.
[0075] This embodiment accurately obtains the device identifier through the identifier reading subunit, quickly loads the matching driver from the local protocol library through the local loading subunit, and promptly retrieves and caches the required driver from the cloud when no matching driver is available locally. This multi-layered protocol driver loading mechanism significantly improves the compatibility and adaptability of the calibration device to various protection devices, ensuring accurate reading of setpoint data and smooth calibration work, and providing solid technical support for achieving efficient and reliable protection setpoint calibration.
[0076] Furthermore, in some embodiments, the two-level comparison unit may specifically include:
[0077] The hash tree comparison subunit is used to generate hash values by grouping the read real-time fixed values, construct the corresponding Merkle tree, and compare the Merkle tree with the benchmark file to locate the difference group;
[0078] Specifically, the hash tree comparison subunit uses a Merkle tree for comparison. First, the read real-time setpoint data is grouped by parameter category (e.g., overcurrent protection, differential protection), and a SHA-256 hash value is generated for each group. Then, a Merkle tree is constructed. This unit compares the constructed Merkle tree with the hash tree in the benchmark file, quickly locating differing groups by comparing the root hash values. For example, in a comparison, if the hash value of the overcurrent protection parameter group differs from the hash value of that group in the benchmark file, it indicates a difference in that parameter group.
[0079] The tolerance comparison subunit is used to compare parameters within the difference group item by item and to determine floating-point differences using a relative error method.
[0080] Specifically, the tolerance comparison subunit performs a step-by-step comparison of parameters within the difference group identified by the hash tree comparison subunit. For floating-point parameters, a relative error method is used to determine the difference, with the formula |V1-V2| / max(V1,V2)≤0.5%, where V1 is the baseline setpoint and V2 is the real-time read setpoint. For example, if the baseline setpoint is 100.0 and the real-time read setpoint is 100.3, the relative error is 0.3%, which is within the allowable error range. For integer or other types of parameters, comparisons are also performed according to corresponding judgment rules. This unit can distinguish which parameter differences are caused by normal error ranges and which are deviations that truly need to be corrected. The tolerance judgment rules can be further refined, setting different allowable error ranges based on different protection device types and parameter importance.
[0081] This embodiment uses a hash tree comparison subunit to quickly locate the difference group, greatly narrowing down the range of data that needs to be checked in detail; the tolerance comparison subunit performs fine judgment within the difference group, accurately identifying out-of-tolerance parameters, ensuring both the efficiency of the comparison and the accuracy of the results, providing a reliable basis for subsequent repair work.
[0082] Furthermore, in some embodiments, the leaf nodes of the Merkle tree are SHA-256 hash values of the same type of fixed parameters, and the parent nodes of the Merkle tree are cascaded hashes of the child node hash values.
[0083] Specifically, the leaf nodes of a Merkle tree form the foundation of the tree, with each leaf node representing the hash value of a data block. In protection setting calibration devices, these data blocks are typically collections of setting parameters of the same type, such as overcurrent protection settings and differential protection settings. The hash value of a leaf node is obtained by performing a SHA-256 hash operation on the corresponding setting parameter data. For example, for a set of overcurrent protection setting parameters (including overcurrent stage I values, overcurrent stage II values, etc.), after serialization, a SHA-256 hash operation is performed, and the resulting hash value serves as the leaf node. As the foundation of the Merkle tree, the accuracy and reliability of the hash values of the leaf nodes directly determine the credibility of the entire Merkle tree. By using secure hash algorithms such as SHA-256, the uniqueness and immutability of the leaf node hash values are ensured, providing a solid foundation for subsequent hash tree comparisons and guaranteeing the integrity and consistency of the setting data.
[0084] A parent node is the node one level above a leaf node in a Merkle tree. The hash value of each parent node is obtained by a concatenation hash operation of the hash values of its child nodes. For example, if there are two child nodes A and B with hash values H(A) and H(B) respectively, then the hash value of the parent node is H(H(A)||H(B)), where "||" represents the concatenation operation. Parent nodes are built upwards layer by layer, eventually forming the root node of the Merkle tree. The parent node integrates the hash values of its child nodes through concatenation hash operations, forming a hierarchical data structure. This structure allows for quick determination of whether the data of its child nodes has changed during comparison by comparing the hash values of the parent nodes, greatly improving the efficiency and accuracy of data comparison. At the same time, the hash value of the parent node inherits the immutability of the child nodes, further enhancing the integrity and reliability of the data.
[0085] As can be seen, this embodiment constructs an efficient and reliable data comparison and verification system by defining the leaf nodes of the Merkle tree as SHA-256 hash values of the same type of fixed parameters and the parent node as a concatenated hash of the child node hash values. This makes the integrity verification of fixed data fast and accurate, and can promptly detect any tampering or damage that may occur during the transmission and storage of data.
[0086] Furthermore, in some embodiments, the security module 30 may specifically include:
[0087] An encrypted storage unit is used to encrypt and store the baseline value using a preset encryption algorithm, and the key for the baseline customization is bound to the unique identifier of the device.
[0088] Specifically, the encrypted storage unit is a crucial component of the security module. Its core function is to encrypt and store the baseline value using a preset encryption algorithm (such as the Chinese national standard SM4 algorithm) and ensure that the key is bound to a unique device identifier (such as a MAC address) to prevent the encrypted data from being illegally copied or used. The encrypted storage unit typically includes an encryption chip or module. These hardware components are responsible for performing encryption and decryption operations and providing a secure key management mechanism. For example, the encryption chip can generate and store encryption keys, ensuring key security, while simultaneously encrypting the baseline value data and storing it in the device's internal memory (such as eMMC or SSD).
[0089] The blockchain evidence storage unit is used to generate hash values corresponding to operation logs and upload them to blockchain nodes for evidence storage.
[0090] Specifically, the blockchain evidence storage unit is responsible for tamper-proof evidence storage of operation logs. Its workflow involves first generating a hash value corresponding to the operation log, and then uploading this hash value to a blockchain node for evidence storage. The operation log contains key information such as timestamps, operator IDs, device IDs, and operation content. This information is used to generate unique hash values through a hash algorithm (such as SHA-256). After receiving the hash value, the blockchain node records it on the blockchain, utilizing the blockchain's distributed ledger and consensus mechanism to ensure that the stored hash value is immutable and traceable. For example, after each calibration operation on a protection device, the blockchain evidence storage unit records the specific time of the operation, the operator's ID, the device ID of the calibration device, and the content of the calibration operation, generates a hash value, and uploads it to a pre-configured State Grid blockchain node for evidence storage.
[0091] The encrypted storage unit provided in this embodiment ensures the confidentiality and integrity of the setpoint data during the storage process, preventing data leakage and tampering; the blockchain evidence storage unit provides immutable and traceable evidence for the operation log, enhancing the transparency and credibility of operation and maintenance management. This not only meets the stringent requirements of the power industry for data security, but also provides solid technical support for protecting the reliable operation of the setpoint calibration device, reducing data security risks.
[0092] Furthermore, in some embodiments, such as Figure 2 As shown, the device protection setting calibration device provided in this embodiment may further include a repair authentication module 40. The repair authentication module 40 is used to verify the setting data read a second time after executing the repair instruction. If the verification is inconsistent, an alarm is triggered and an error report is generated.
[0093] Specifically, the protection setting calibration device provided in this embodiment may also include a repair authentication module, a key component for ensuring the accuracy and reliability of the repair process. After the main control module generates and executes the repair instruction, the repair authentication module reads the setting data of the protection device again to verify whether the repair operation was successful. Specifically, the repair authentication module re-establishes a communication connection with the protection device, reads the setting data according to the same communication protocol and data format as the repair instruction, and compares it with the expected repair result. If the read setting data matches the repair target, the repair is considered successful; if not, an alarm is triggered and a detailed error report is generated. This module typically works in conjunction with a security module to ensure data integrity and operational traceability during the repair process.
[0094] The repair authentication module in this embodiment employs a rigorous secondary verification mechanism to ensure the accuracy and reliability of repair operations, effectively preventing protection device setting errors due to repair failures and reducing power grid operation risks. Simultaneously, its alarm and error reporting functions can promptly notify maintenance personnel to address issues, improving maintenance efficiency and further enhancing the security and traceability of the repair process.
[0095] Furthermore, in some embodiments, such as Figure 2 As shown, the device protection setting calibration device provided in this embodiment may further include a human-machine interaction module 50. The human-machine interaction module 50 is used to realize the interactive operation between the user and the protection setting calibration device. The human-machine interaction module includes a touch screen, which is used to display a two-column comparison view of the difference items and export the report.
[0096] Specifically, the protection setting calibration device provided in this embodiment may also include a human-machine interface module, such as an industrial touch screen with high resolution, capable of clearly displaying complex setting data and operating interfaces. The screen uses capacitive multi-touch technology, supporting gesture operation, allowing users to easily perform zooming, swiping, and other operations. The touch screen surface is covered with special scratch-resistant glass, providing anti-glare functionality and maintaining good visibility even in strong light environments. Simultaneously, the screen supports operation while wearing gloves, adapting to the working conditions in substation sites. Its main functions are displaying a two-column comparison view of the differences, intuitively presenting the differences between the baseline setting and the real-time setting, and exporting a repair report.
[0097] In addition to the touchscreen, the human-machine interface module is equipped with a series of physical buttons and indicator lights. The buttons include a power button, an emergency stop button, and function keys for quickly executing critical operations. For example, the emergency stop button can immediately interrupt the calibration operation in an emergency to ensure the safety of the equipment and personnel. The indicator lights display the equipment's operating status, such as power status, communication status, and repair status. For instance, the communication indicator light flashes when communicating with the protection device, reminding the user that communication is in progress.
[0098] Furthermore, the voice interaction unit is a crucial component of the human-computer interaction module, comprising a speech recognition module and a speech synthesis module. The speech recognition module can recognize operator voice commands, such as "Start calibration" and "Display differences," enabling voice control operations. The speech synthesis module converts device status information and prompts into spoken messages, such as "Calibration complete" and "Differences detected, please confirm." Utilizing speech recognition and synthesis technologies, the voice interaction unit adapts to different accents and speaking speeds, ensuring accurate recognition and clear delivery of voice commands.
[0099] The protection setting calibration device provided in this embodiment may also include a power module. The power module uses a 12000mAh lithium battery, supports PD 45W fast charging and reverse power supply, and can provide temporary power to the protection device.
[0100] This embodiment provides operators with a comprehensive, efficient, and convenient operation and information feedback mechanism through the collaborative work of the touch screen, buttons, indicator lights, and voice interaction unit of the human-machine interaction module. For example, the touch screen enables intuitive data display and precise operation control, while the buttons and indicator lights ensure the rapid execution of key operations and real-time monitoring of equipment status. The voice interaction unit further enhances the convenience and safety of operation, effectively improving the usability and operational efficiency of the protection setting calibration device, reducing operational difficulty and error rate, and enabling staff to complete setting calibration tasks more efficiently and accurately, adapting to the complex and ever-changing working environment of substations.
[0101] In summary, this embodiment dynamically adapts to the communication protocols of protection devices from different manufacturers through a multi-protocol communication module, ensuring the compatibility of setpoint calibration. This allows the device to communicate and exchange setpoint data with protection devices from various manufacturers. The main control module performs group hash comparison and tolerance determination on the acquired setpoint data and generates repair instructions. This not only quickly locates differences in the setpoint data but also accurately determines whether the data is within the allowable range through tolerance determination, thereby achieving precise calibration. The security module encrypts and stores the setpoint data with tamper-proof evidence, ensuring the security and integrity of the setpoint data. Therefore, this embodiment enables dynamic interaction, efficient comparison, and repair of setpoint data from protection devices from different manufacturers. Furthermore, encrypted storage and tamper-proof storage of operation logs improve the efficiency of setpoint calibration while effectively ensuring its compatibility, reliability, and data security.
[0102] To facilitate better implementation of the protection setting calibration device of this application embodiment, this application embodiment also provides a protection setting calibration method based on the protection setting calibration device. The meanings of the terms used are the same as in the protection setting calibration device described above, and specific implementation details can be found in the description of the device embodiment.
[0103] like Figure 3 As shown, this application embodiment also provides a protection setting calibration method, executed in the protection setting calibration device described above, including the following steps:
[0104] S1. Dynamically adapts to the communication protocols of protection devices from different manufacturers, and establishes communication with the protection device according to the communication protocol, and exchanges setpoint data with the protection device;
[0105] Specifically, for step S1, the protection setting calibration device dynamically adapts to the communication protocols of protection devices from different manufacturers through a multi-protocol communication module. This module includes an RS485 interface, a fiber optic Ethernet interface, and a wireless communication module, supporting various communication protocols such as IEC 61850, Modbus, and DNP3. After startup, the device automatically matches and loads the corresponding protocol driver by reading the protection device's identification information (such as manufacturer code and device model). For example, when connected to a PCS-900 series protection device from NARI Group Corporation, the device automatically loads the IEC 61850 proprietary extended protocol driver to parse its setting data. By establishing a communication connection with the protection device, the calibration device can read the current setting parameters and write new setting parameters as needed.
[0106] S2. Perform grouped hash comparison and tolerance determination on the obtained fixed value data, and generate corresponding repair instructions;
[0107] Specifically, in step S2, the main control module of the calibration device performs grouped hash comparison and tolerance determination on the acquired setpoint data. First, the setpoint data is grouped according to parameter category (e.g., overcurrent protection, differential protection), and a SHA-256 hash value is generated for each group, constructing a Merkle tree. By comparing the hash tree of the real-time setpoint data with the hash tree in the reference file, the parameter groups with discrepancies are quickly located. Then, the parameters within the discrepancy groups are compared item by item, and floating-point differences are determined using a relative error method. If the parameter deviation exceeds the allowable range, the main control module generates a corresponding repair instruction.
[0108] S3. Encrypt and store the fixed value data to prevent tampering and preserve the operation log;
[0109] Specifically, for step S3, the calibration device's security module is responsible for encrypting and storing the setpoint data and operation logs, and for tamper-proof evidence preservation. The security module uses the national cryptographic algorithm SM4 to encrypt and store the benchmark setpoints, with the key bound to the device's unique identifier (such as a MAC address) to prevent unauthorized copying and use. Simultaneously, it generates a hash value for the operation log and uploads it to a blockchain node for evidence preservation. The operation log contains information such as timestamps, operator IDs, device IDs, and operation details. Through the blockchain's distributed ledger and consensus mechanism, the hash value of the evidence preservation is ensured to be immutable and traceable.
[0110] In a specific embodiment, when the calibration device is started and connected to the protection device, the multi-protocol communication module first establishes a communication link with the protection device according to pre-configured connection parameters (such as RS485 baud rate, Ethernet IP address, etc.). If the connected protection device is from an unknown manufacturer or of an unknown model, the multi-protocol communication module will automatically send a device identification request. For example, it reads the device identification information by sending Modbus function code 0x43. Once the device identification is obtained, the multi-protocol communication module searches for a matching protocol driver in its local protocol library. If no matching driver is found in the local protocol library, it downloads the corresponding protocol driver from the cloud server via the wireless communication module and caches it. After establishing communication and loading the appropriate protocol driver, the multi-protocol communication module begins to interact with the protection device to exchange setting data. Following the data format and transmission rules specified in the protocol, it reads the setting data from the protection device and sends this data to the main control module through an interface with the main control module (such as SPI or GPIO).
[0111] After receiving the setpoint data from the multi-protocol communication module, the main control module first performs protocol parsing. Based on the device identification information of the protection device, it dynamically loads the parsing rules from the protocol driver library. For example, for an MMS message using the IEC 61850 protocol, the main control module extracts information such as the category and value of the setpoint parameters according to the data format definition in the protocol standard. Next, the main control module performs grouped hash comparison on the setpoint data. It groups the setpoint data according to preset parameter categories (such as overcurrent protection, differential protection, etc.) and then generates an SHA-256 hash value for each group. Simultaneously, the main control module constructs a Merkle tree and compares the real-time read hash values with the hash tree in a pre-stored reference file. In this way, it quickly locates the groups of setpoint parameters that differ. For the groups of setpoints that differ, the main control module further performs tolerance determination. For floating-point type fixed parameters, a relative error method is used to determine the difference, that is, by calculating [|V1-V2| / max(V1,V2)≤0.5%] to determine whether the two values are within the allowable error range. For integer type or other type parameters, comparison is performed according to the corresponding judgment rules. If the fixed data is found to have a deviation exceeding the allowable range, the main control module will generate a corresponding repair instruction.
[0112] While the main control module processes the setpoint data, the security module participates in the secure processing of the data. When the main control module needs to encrypt and store the setpoint data, it sends the data to the security module. The security module encrypts the data using a preset encryption algorithm (such as the SM4 algorithm), and the encryption key is bound to the device's unique identifier (such as the MAC address). This prevents the encrypted data from being decrypted and used without authorization. For operation logs, the security module generates corresponding hash values and uploads them to blockchain nodes for evidence storage. Whenever a setpoint calibration operation (such as reading or repairing setpoints) occurs, the security module records the operation's timestamp, operator ID, device ID, and other information. After calculating the hash value, it broadcasts it to other nodes through the blockchain network for verification and storage, thereby achieving tamper-proof and traceable operation logs.
[0113] This embodiment dynamically adapts to the communication protocols of protection devices from different manufacturers through a multi-protocol communication module, ensuring the compatibility of setpoint calibration. This allows the device to communicate and exchange setpoint data with protection devices from various manufacturers. The main control module performs group hash comparison and tolerance determination on the acquired setpoint data and generates repair instructions. This not only quickly locates differences in the setpoint data but also accurately determines whether the data is within the allowable range through tolerance determination, thereby achieving precise calibration. A security module encrypts and stores the setpoint data with tamper-proof evidence, ensuring the security and integrity of the setpoint data. Therefore, this embodiment enables dynamic interaction, efficient comparison, and repair of setpoint data from protection devices from different manufacturers. Furthermore, encrypted storage and tamper-proof storage of operation logs improve the efficiency of setpoint calibration while effectively ensuring its compatibility, reliability, and data security.
[0114] The terms "first" and "second" in the above-mentioned modules / units are only used to distinguish different modules / units and are not intended to specify which module / unit has a higher priority or any other limiting meaning. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or modules is not necessarily limited to those steps or modules explicitly listed, but may include other steps or modules not explicitly listed or inherent to these processes, methods, products, or devices. The module divisions appearing in this application are merely logical divisions; in actual applications, different division methods may be used.
[0115] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0116] The sequence numbers of the embodiments in this application are merely for description and do not represent the superiority or inferiority of the embodiments. Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0117] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A protection setpoint calibration device, characterized in that, It includes a main control module, and a multi-protocol communication module and a security module respectively connected to the main control module; The multi-protocol communication module is used to dynamically adapt to the communication protocols of protection devices from different manufacturers, and to establish communication with the protection device according to the communication protocol, and to exchange setpoint data with the protection device. The main control module is used to perform group hash comparison and tolerance determination on the acquired fixed value data, and generate corresponding repair instructions; The security module is used to encrypt and store the set value data in order to prevent tampering and preserve the operation log.
2. The protection setpoint calibration device according to claim 1, characterized in that, The multi-protocol communication module includes: A serial communication interface for supporting at least one serial communication protocol; Ethernet interface, used to support at least one Ethernet communication protocol; The wireless communication module is used to support cloud download of protocol libraries and log upload.
3. The protection setpoint calibration device according to claim 1, characterized in that, The main control module includes: The protocol parsing unit is used to dynamically load the protocol driver library according to the device identification information of protection devices from different manufacturers, match the corresponding communication protocol, and parse the standard protocol and private extension fields based on the communication protocol. A two-level comparison unit is used to locate the difference group through a hash tree and perform tolerance comparison on the parameters within the difference group; Repair the control unit, which is used to generate a setpoint write command and perform secondary verification.
4. The protection setpoint calibration device according to claim 3, characterized in that, The protocol parsing unit includes: The identification reading subunit is used to read the device identification information of protection devices from different manufacturers, as well as to read the imported setting text and the real-time operating setting of the protection device; The local loading subunit is used to load the corresponding protocol driver from the local protocol library according to the device identification information; The cloud caching subunit is used to obtain and cache the corresponding protocol driver from the cloud server when the local protocol library has no matching driver.
5. The protection setpoint calibration device according to claim 3, characterized in that, The two-level comparison unit includes: The hash tree comparison subunit is used to generate hash values by grouping the read real-time fixed values, construct the corresponding Merkle tree, and compare the Merkle tree with the benchmark file to locate the difference group; The tolerance comparison subunit is used to compare the parameters in the difference group item by item and to determine the floating-point differences using a relative error method.
6. The protection setpoint calibration device according to claim 5, characterized in that, The leaf nodes of the Merkle tree are SHA-256 hash values of the same type of fixed parameter, and the parent node of the Merkle tree is a cascade hash of the hash values of the child nodes.
7. The protection setpoint calibration device according to claim 1, characterized in that, The security module includes: An encrypted storage unit is used to encrypt and store a baseline value using a preset encryption algorithm, and the key for the baseline is bound to a unique device identifier; The blockchain evidence storage unit is used to generate the hash value corresponding to the operation log and upload it to the blockchain node for evidence storage.
8. The protection setpoint calibration device according to claim 1, characterized in that, The device also includes a repair authentication module, which verifies the fixed value data read a second time after the repair command is executed. If the verification shows that the data is inconsistent, an alarm is triggered and an error report is generated.
9. The protection setpoint calibration device according to claim 1, characterized in that, The device also includes a human-computer interaction module for enabling users to interact with the protection setting calibration device; the human-computer interaction module includes a touch screen for displaying a two-column comparison view of the differences and exporting reports.
10. A method for calibrating protection setpoints, characterized in that, The protection setting calibration device as described in any one of claims 1-9 includes the following steps: It dynamically adapts to the communication protocols of protection devices from different manufacturers, establishes communication with the protection device according to the communication protocol, and exchanges setpoint data with the protection device. The obtained fixed-value data is subjected to grouped hash comparison and tolerance determination, and corresponding repair instructions are generated. The fixed value data is encrypted and stored to prevent tampering and preserve evidence of the operation log.