A power-specific encrypted wireless communication terminal device

By integrating hardware security chips and a multi-mode communication architecture, the dedicated encrypted wireless communication terminal equipment for power systems solves the problem of insufficient data transmission security in power systems, achieves end-to-end encryption and communication stability, and meets the high security requirements of the power industry.

CN121012684BActive Publication Date: 2026-03-13TIANJIN HAIHE ELECTRIC CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing terminal communication equipment lacks sufficient data transmission security in public network communication scenarios outside of the power private network, making it susceptible to theft or tampering and failing to meet the high security requirements of the power industry. This problem is particularly prominent in new energy power plants and unattended terminal application scenarios.

Method used

A dedicated encrypted wireless communication terminal device for power applications was designed, integrating a security encryption module, a multi-mode communication module, a protocol adaptation module, an edge intelligent processing module, and a remote operation and maintenance management module. It adopts a hardware security chip, two-way digital certificate authentication, and a multi-mode communication architecture to achieve end-to-end encryption and identity authentication. Through automatic switching between cellular network and power line carrier communication, it ensures the security and stability of data transmission.

Benefits of technology

It achieves end-to-end encryption from field equipment to the dispatch master station, preventing data theft, tampering or forgery, meeting the high security requirements of the power system for network communication, and maintaining communication continuity and stability in weak coverage and network interruption scenarios, significantly reducing the amount of invalid data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121012684B_ABST
    Figure CN121012684B_ABST
Patent Text Reader

Abstract

This invention discloses a dedicated encrypted wireless communication terminal device for power equipment, belonging to the field of power equipment communication technology. It includes a security encryption module for encrypting and decrypting communication data and remote management data; a multi-mode communication module for uploading encrypted data to the master station via a cellular wireless communication link or a power line carrier communication link; a protocol adaptation module for encapsulating raw device data into data frames conforming to the master station protocol; an edge intelligent processing module for performing variable compression and dead-zone filtering on collected field device data; a remote operation and maintenance management module for configuring device parameters, upgrading firmware, monitoring status, and managing warnings; and a core control processing module for executing task scheduling, resource allocation, and security policy control. This invention, using the above-mentioned device, effectively prevents data from being stolen, tampered with, or forged during transmission over public wireless networks or power line carrier links, meeting the high security requirements of the power industry for network communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power equipment communication technology, and in particular to a dedicated encrypted wireless communication terminal device for power equipment. Background Technology

[0002] The power system is a crucial infrastructure of the national economy, and its operation relies on distributed monitoring and centralized dispatching systems. To achieve real-time monitoring and control of the power grid's operational status, various terminal communication devices are widely deployed, such as switch terminals installed on distribution lines, remote control units (RTUs) in substations, inverter control terminals in renewable energy plants, and various smart meters. These terminal devices typically need to transmit collected operational data, such as voltage, current, frequency, power, and switch status, to the dispatching master station via public wireless networks or dedicated power networks; simultaneously, they receive remote control commands and operational strategies from the master station to achieve functions such as distribution automation and centralized control of renewable energy.

[0003] Most existing terminal communication devices are designed based on general industrial communication platforms, with their core function focusing on data transparent transmission and limited security protection capabilities. In public network communication scenarios outside of the power private network environment, data is easily stolen or tampered with during transmission, making it difficult to meet the high security requirements of the power industry for data transmission. This deficiency is particularly prominent in applications such as new energy power plants, remote distribution networks, and unattended terminals. Summary of the Invention

[0004] The purpose of this invention is to provide a dedicated encrypted wireless communication terminal device for power applications to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides a power-specific encrypted wireless communication terminal device, including a security encryption module, a multi-mode communication module, a protocol adaptation module, an edge intelligent processing module, a remote operation and maintenance management module, and a core control processing module;

[0006] Security encryption module: Used to encrypt and decrypt communication data and remote management data to ensure the security of data transmission and storage;

[0007] Multimode communication module: Connected to the security encryption module, it is used to upload encrypted data to the master station via cellular wireless communication link or power line carrier communication link, and to receive encrypted data from the master station;

[0008] Protocol adaptation module: Connected to the security encryption module, it encapsulates the raw device data from the edge intelligent processing module into data frames that conform to the master station protocol, and parses the decrypted downlink data into control commands adapted to the field equipment.

[0009] Edge intelligent processing module: Connected to the protocol adaptation module, it is used to compress changes and filter dead zones in the collected field equipment data, and execute local logic control. At the same time, it transmits status data, warning information and event records to the protocol adaptation module.

[0010] Remote operation and maintenance management module: It connects to the multi-mode communication module, the security encryption module and the edge intelligent processing module respectively, and is used to realize device parameter configuration, firmware upgrade, status monitoring and warning management through the web terminal or remote management platform;

[0011] The core control and processing module is the computing and control core of the terminal device, used to perform task scheduling, resource allocation and security policy control.

[0012] Preferably, the various modules are logically coordinated through the core control processing module, as follows:

[0013] The security encryption module encrypts the data from the protocol adaptation module and the remote operation and maintenance management module before sending it to the multi-mode communication module for uploading.

[0014] The data received by the multi-mode communication module is decrypted by the security encryption module and then sent to the protocol adaptation module or the remote operation and maintenance management module.

[0015] The protocol adaptation module transmits the processed data to the edge intelligent processing module for on-site logic execution, thereby achieving secure data transmission and remote control of the device.

[0016] Preferably, the security encryption module includes a hardware security unit, a data encryption / decryption unit, a two-way authentication unit, an encrypted transmission link unit, an access control unit, and a security policy management unit;

[0017] Hardware security unit: Built-in national cryptographic algorithm hardware security chip, supporting multiple algorithms; has an independent security environment for key generation, storage, updating and destruction; the chip supports a true random number generator, physical anti-tampering detection mechanism and automatic key clearing function when power is off;

[0018] Data encryption / decryption unit: used to encrypt uplink business data received from the protocol adaptation module, decrypt downlink encrypted data received from the main station, and perform integrity verification;

[0019] Two-way authentication unit: Based on the digital certificate system, it realizes two-way identity authentication between the terminal and the master station; it supports certificate renewal, revocation and validity period management; and it combines the private key inside the hardware chip for signature verification during the authentication process.

[0020] Encrypted transmission link unit: works in conjunction with the multi-mode communication module to establish an encrypted tunnel, supports key negotiation and encryption modes, and provides anti-replay attack mechanism and message integrity detection;

[0021] Access control unit: Supports whitelist policies, works with remote operation and maintenance management module to dynamically adjust access policies, and records and audits access behavior;

[0022] Security Policy Management Unit: Selects different encryption algorithms, authentication methods, and link protection levels according to different security zone requirements at the power site; interacts with the remote operation and maintenance management module to realize remote distribution and online upgrade of security policies; has a security warning triggering mechanism, which automatically triggers warnings and reports to the main station when key expiration, certificate abnormality, or suspicious attack behavior is detected.

[0023] The security policy management unit has a built-in security partition identification table, which determines the security zone the terminal belongs to based on the terminal's installation location. When the terminal detects a change in its security partition, it will automatically match the corresponding security policy template to achieve adaptive adjustment of algorithms, authentication, and link protection policies.

[0024] Preferably, when switching encryption algorithms, the security policy management unit performs the following operations: first, establish a temporary secure channel to ensure that configuration instructions during the switching process are not eavesdropped on; generate a new key and load the target algorithm in the hardware security unit; and after all established service connections have completed the current data frame exchange, smoothly switch to the new algorithm to avoid communication interruption.

[0025] Preferably, different authentication methods are used for different partitions, including high-level partitions and low-level partitions; high-level partitions use two-way certificate authentication between the terminal and the master station; low-level partitions use one-way certificate authentication or shared key authentication.

[0026] The security policy management unit selects the authentication method based on the partition policy and calls the private key and certificate in the hardware security chip to perform signing or verification operations.

[0027] Preferably, the link protection level includes full traffic encryption and partial service encryption; full traffic encryption means encrypting all service data during transmission; partial service encryption means encrypting only critical service data and transmitting non-sensitive data in plaintext to improve efficiency.

[0028] The selection of link protection level is controlled by a security policy table, and the table entries are updated online by the remote operation and maintenance management module.

[0029] Preferably, the multi-mode communication module includes a cellular communication unit, a power line carrier communication unit, a link management and handover unit, a dual SIM dual standby and signal enhancement unit, a power consumption and power supply adaptation unit, and a network security coordination unit;

[0030] Cellular communication unit: Supports multiple communication modes and is compatible with the networks of the three major operators; automatically selects the operator network with the best signal quality and has channel monitoring and reconstruction capabilities;

[0031] Power line carrier communication unit: integrates a high-speed power line carrier communication interface, using existing power lines as the communication medium; adopts orthogonal frequency division multiplexing modulation and adaptive channel equalization method to adapt to different cable types and complex electromagnetic environments; serves as a backup link for cellular communication and is automatically activated when the cellular network is unavailable;

[0032] Link Management and Switching Unit: Real-time monitoring of latency, packet loss rate, and signal-to-noise ratio for cellular and power line carrier links; supports automatic redundancy switching, seamlessly switching to a backup link when the primary link fails or its quality degrades to a set threshold; provides a link recovery mechanism, automatically switching back after the primary link recovers.

[0033] Dual SIM Dual Standby and Signal Enhancement Unit: Equipped with dual SIM card slots, enabling automatic switching between primary and secondary SIM cards; with an external high-gain antenna, it supports directional adjustment; and supports antenna diversity reception and multiple-input multiple-output modes.

[0034] Power consumption and power adapter unit: Supports a wide range of DC power input and features a dual power redundancy design; It has a low-power sleep and wake-up mechanism to extend equipment life and reduce maintenance costs in unattended scenarios;

[0035] Network security collaboration unit: works in conjunction with the security encryption module to perform encryption authentication during the link establishment process; provides integrity verification and anti-replay protection for data packets during transmission; and provides a network attack detection mechanism to trigger security warnings when malicious scanning or fake base station behavior is detected.

[0036] Preferably, the protocol adaptation module includes an uplink protocol processing unit, a downlink protocol processing unit, a protocol script extension unit, a protocol conversion and data mapping unit, and a security interface coordination unit;

[0037] Uplink Protocol Processing Unit: Supports multiple standard power uplink communication protocols; responsible for converting the equipment operating parameters, status variables and warning events collected by the terminal into data frames that conform to the format received by the master station; provides a time synchronization interface to align with the time base of the master station and ensure that the timestamps of event records are accurate and reliable.

[0038] Downlink protocol processing unit: Supports common field device protocol interfaces; parses and converts control commands issued by the master station into instruction sets that can be recognized by the corresponding field devices; realizes downlink adaptation for remote control on / off, parameter configuration, and equipment debugging;

[0039] Specification Script Extension Unit: Provides scripted development interfaces, supports quick access to user-defined parsing rules and private protocols; shortens device deployment cycle by dynamically loading scripts without firmware changes; supports remote upgrades and hot reloading.

[0040] Protocol Conversion and Data Mapping Unit: Implements data field mapping and unified format conversion between uplink and downlink protocols; supports unified data identification, units of measurement, and precision; collaborates with the edge intelligent processing module to generate optimized protocol messages by combining data compression and dead-zone filtering rules.

[0041] Security Interface Collaboration Unit: Connects to the security encryption module to ensure that all protocol data is encrypted before transmission and decrypted after reception; performs digital signature verification on master station control commands to prevent forged instructions; provides access authentication interface to ensure that only legitimate protocol callers can access the system.

[0042] Preferably, the edge intelligent processing module includes a data optimization unit, an event detection and sequential event recording unit, a local logic control unit, a breakpoint resume and local caching unit, and an interface collaboration unit;

[0043] Data optimization unit: performs real-time analysis of data collected on-site; adopts a change detection algorithm to upload only data that exceeds a set threshold or undergoes a sudden change in state; integrates dead-zone filtering function to ignore minor fluctuations within a set range and reduce the amount of invalid data transmission;

[0044] Event detection and sequential event recording unit: performs real-time detection of events on field devices; provides sequential event recording with a time resolution of 0.1ms, and supports power failure protection and cache storage; provides accurate timestamp data to the dispatch master station for fault analysis and closed-loop control;

[0045] Local logic control unit: Supports user-defined or master station preset logic rules; enables autonomous operation in the event of master station communication interruption or delay, ensuring that the basic control functions of field equipment are not interrupted; supports remote distribution and local editing of logic policies;

[0046] Resume interrupted downloads and local caching unit: When communication is interrupted, the collected data and event information are cached in local storage; after communication is restored, data is automatically synchronized to ensure data integrity; it supports resume interrupted downloads and data verification mechanisms to prevent data loss or duplication;

[0047] Interface Collaboration Unit: Connects to the protocol adaptation module, encapsulates optimized data into standardized messages; receives control commands parsed by the protocol adaptation module and executes on-site logic; collaborates with the remote operation and maintenance management module to provide edge processing status and performance parameters.

[0048] Preferably, the remote operation and maintenance management module includes a status monitoring unit, a remote configuration and upgrade unit, a log and audit unit, a warning management unit, and a user permission management unit;

[0049] Status monitoring unit: Monitors key operating parameters in real time, and triggers warnings and automatically reports when indicators are abnormal;

[0050] Remote configuration and upgrade unit: Provides web and cloud platform interfaces to enable remote parameter configuration, policy distribution and firmware or specification library upgrades; supports OTA remote upgrades without on-site disassembly; all remote operations are encrypted and authenticated through a security encryption module.

[0051] Log and Audit Unit: Records operation logs throughout the entire lifecycle; log files are encrypted and stored, and can be exported for security auditing purposes according to operation and maintenance needs; meets the compliance requirements for power system security auditing and event tracing;

[0052] Warning Management Unit: Supports multiple warning methods based on the severity level of the event, and can be linked with third-party warning platforms to achieve centralized operation and maintenance management;

[0053] User access control unit: Supports multi-level user role hierarchical management; provides certificate-based user authentication and access control; ensures that remote operation and maintenance access processes are secure, controllable, and traceable.

[0054] Therefore, the present invention employs the above-mentioned encrypted wireless communication terminal device for power applications, which has the following beneficial effects:

[0055] (1) By integrating hardware security chips, digital certificate two-way authentication mechanism and security tunnel based on IPSec VPN or SSLVPN, full-link encryption and identity trust can be achieved from field equipment to dispatch master station; it can effectively prevent data from being stolen, tampered or forged during transmission on wireless public network or power line carrier link, and meet the high security requirements of the power industry for network communication.

[0056] (2) A multi-mode communication architecture of cellular network and high-speed power line carrier is adopted, and a link real-time monitoring and automatic switching mechanism is used to ensure the continuity and stability of the communication link in weak coverage, network interruption or electromagnetic interference scenarios.

[0057] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0058] Figure 1 This is a schematic diagram of the structure of a power-specific encrypted wireless communication terminal device according to an embodiment of the present invention. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0060] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0061] Example

[0062] like Figure 1 As shown, the present invention provides a power-specific encrypted wireless communication terminal device, including a security encryption module, a multi-mode communication module, a protocol adaptation module, an edge intelligent processing module, a remote operation and maintenance management module, and a core control processing module.

[0063] Security encryption module: Used to encrypt and decrypt communication data and remote management data to ensure the security of data transmission and storage.

[0064] Multimode communication module: Connected to the security encryption module, it is used to upload encrypted data to the master station via cellular wireless communication link or power line carrier communication link, and to receive encrypted data from the master station.

[0065] Protocol adaptation module: Connected to the security encryption module, it encapsulates the raw device data from the edge intelligent processing module into data frames that conform to the master station protocol; at the same time, it parses the decrypted downlink data into control commands adapted to the field devices.

[0066] Edge intelligent processing module: Connected to the protocol adaptation module, it is used to compress changes and filter dead zones in the collected field device data, and execute local logic control; at the same time, it transmits status data, warning information and event log SOE to the protocol adaptation module.

[0067] Remote operation and maintenance management module: It connects to the multi-mode communication module, security encryption module and edge intelligent processing module respectively, and is used to realize device parameter configuration, firmware upgrade, status monitoring and warning management through the web terminal or remote management platform.

[0068] The core control and processing module is the computing and control core of the terminal device. It has a built-in high-performance multi-core processor and a real-time operating system, which is used to perform task scheduling, resource allocation and security policy control.

[0069] The modules are logically coordinated through the core control and processing module, as follows:

[0070] The security encryption module encrypts the data from the protocol adaptation module and the remote operation and maintenance management module before sending it to the multi-mode communication module for uploading.

[0071] The data received by the multi-mode communication module is decrypted by the security encryption module and then sent to the protocol adaptation module or the remote operation and maintenance management module.

[0072] The protocol adaptation module transmits the processed data to the edge intelligent processing module for on-site logic execution, thereby achieving secure data transmission and remote control of the device.

[0073] The security encryption module includes a hardware security unit, a data encryption / decryption unit, a two-way authentication unit, an encrypted transmission link unit, an access control unit, and a security policy management unit.

[0074] Hardware security unit: Built-in hardware security chip for national cryptographic algorithms, supporting SM1, SM2, SM3, SM4, and SM9 algorithms; has an independent secure environment for key generation, storage, updating, and destruction, preventing keys from being accessed or exported by the software layer and ensuring the physical security of the key lifecycle; the chip supports a true random number generator (TRNG), a physical anti-tampering detection mechanism, and an automatic key clearing function when power is off.

[0075] Data encryption / decryption unit: encrypts uplink business data received from the protocol adaptation module to ensure that the data is not eavesdropped or tampered with during transmission in the multi-mode communication module; decrypts downlink encrypted data received from the master station and performs integrity verification (such as MAC verification and digital signature verification) to ensure that the data source is trustworthy and the content has not been tampered with.

[0076] Two-way authentication unit: Based on the X.509 digital certificate system (following the DL / T860 standard), it realizes two-way identity authentication between the terminal and the master station; it supports certificate renewal, revocation and validity period management; during the authentication process, it combines the private key inside the hardware chip for signature verification to ensure that the authentication process cannot be forged.

[0077] Encrypted transmission link unit: works in conjunction with the multi-mode communication module to establish an encrypted tunnel (e.g., IPSec VPN or SSL VPN), supports IKEv2 key negotiation and AES-GCM / SM4-GCM encryption modes; provides anti-replay attack mechanism (Sequence Number + Timestamp) and message integrity detection (HMAC-SM3).

[0078] Access control unit: Supports whitelist policies, which allow only specific master station IP addresses and ports to access the terminal communication interface, automatically blocking illegal scanning and unauthorized access; in conjunction with the remote operation and maintenance management module, access policies can be dynamically adjusted, and access behavior can be recorded and audited.

[0079] Security policy management unit: can select different encryption algorithms, authentication methods and link protection levels according to different security zone requirements of the power site; interacts with the remote operation and maintenance management module to realize remote distribution and online upgrade of security policies; has a security warning triggering mechanism, which automatically triggers warnings and reports to the main station when key failure, certificate abnormality or suspicious attack behavior is detected.

[0080] The security policy management unit has a built-in security partition identification table, which determines the security zone to which the terminal belongs by combining the terminal's installation location (through configuration file or location parameters). When the terminal detects that the security partition it is in has changed (such as through GPS or scheduling system configuration updates), it will automatically match the corresponding security policy template to achieve adaptive adjustment of algorithms, authentication and link protection policies.

[0081] When switching encryption algorithms, the security policy management unit performs the following operations: first, establishes a temporary secure channel to ensure that configuration instructions during the switching process are not eavesdropped on; generates a new key and loads the target algorithm in the hardware security unit; and waits for all established service connections to complete the current data frame exchange before smoothly switching to the new algorithm to avoid communication interruption.

[0082] Different partitions employ different authentication methods, including high-level and low-level partitions. High-level partitions use two-way certificate authentication between the terminal and the master station (both parties verify each other's identity); low-level partitions use one-way certificate authentication or shared key authentication (only verifying the terminal or only verifying the master station). The security policy management unit selects the authentication method according to the partition policy and uses the private key and certificate in the hardware security chip to perform signature / verification operations.

[0083] Link protection levels include full-traffic encryption and partial service encryption. Full-traffic encryption encrypts all service data (monitoring data, control commands, management data) during transmission. Partial service encryption encrypts only critical service data (such as remote control and policy distribution), while non-sensitive data is transmitted in plaintext to improve efficiency. The selection of link protection levels is controlled by a security policy table, whose entries can be updated online by the remote operation and maintenance management module.

[0084] The multi-mode communication module includes a cellular communication unit, a power line carrier communication unit, a link management and switching unit, a dual SIM dual standby and signal enhancement unit, a power consumption and power supply adaptation unit, and a network security coordination unit.

[0085] Cellular communication unit: Supports 4G LTE and 5G NSA / SA communication modes, compatible with the networks of the three major operators; can automatically select the operator network with the best signal quality to achieve flexible adaptation to different field environments; has channel monitoring and reconstruction capabilities to ensure that the wireless link remains stable during network jitter or handover.

[0086] Power line carrier communication unit: integrates a high-speed power line carrier (PLC) communication interface, which can use existing power lines as a communication medium; adopts orthogonal frequency division multiplexing modulation (OFDM) and adaptive channel equalization method to adapt to different cable types and complex electromagnetic environments; as a backup link for cellular communication, it is automatically activated when the cellular network is unavailable to achieve network redundancy.

[0087] Link management and switching unit: Real-time monitoring of latency, packet loss rate and signal-to-noise ratio for cellular and power line carrier links; supports automatic redundancy switching, seamlessly switching to the backup link within 3 seconds when the primary link fails or its quality degrades to a set threshold; provides a link recovery mechanism, which can automatically switch back after the primary link recovers to normal, ensuring the continuity and stability of the communication link.

[0088] Dual SIM Dual Standby and Signal Enhancement Unit: Equipped with dual SIM card slots, enabling automatic switching between the primary and secondary SIM cards; with an external high-gain antenna (optional 5dBi), it supports directional adjustment to cope with remote or weak signal environments; it supports antenna diversity reception and multiple-input multiple-output (MIMO) mode (for 5G) to improve data throughput and link stability.

[0089] Power consumption and power adapter unit: Supports 24V / 48V wide range DC power input and has a dual power redundancy design; has a low power sleep and wake-up mechanism, which can extend the equipment life and reduce operation and maintenance costs in unattended scenarios.

[0090] Network security collaboration unit: works in conjunction with the security encryption module to perform encryption authentication during the link establishment process; provides integrity verification and anti-replay protection for data packets during transmission; and provides a network attack detection mechanism to trigger security warnings when malicious scanning or fake base station behavior is detected.

[0091] The protocol adaptation module includes an uplink protocol processing unit, a downlink protocol processing unit, a protocol script extension unit, a protocol conversion and data mapping unit, and a security interface coordination unit.

[0092] Uplink Protocol Processing Unit: Supports multiple standard power uplink communication protocols, including IEC 60870-5-101, IEC 60870-5-104, DNP3.0, Modbus TCP, IEC 61850 MMS, etc.; responsible for converting the equipment operating parameters, status variables, and warning events collected by the terminal into data frames that conform to the master station's receiving format; provides a time synchronization interface to align with the master station's time reference, ensuring that the timestamps of the Event Record (SOE) are accurate and reliable.

[0093] Downlink protocol processing unit: Supports common field device protocol interfaces, including RS-485 (DL / T 645 meter protocol), CAN (photovoltaic inverter protocol), IEC 61850-9-2 sampled values, etc.; parses and converts control commands issued by the master station into instruction sets that can be recognized by the corresponding field devices; and can realize downlink adaptation for operations such as remote control on / off, parameter configuration, and equipment debugging.

[0094] Specification Script Extension Unit: Provides a scripting development interface (SDK) to support user-defined parsing rules and rapid access to private protocols; by dynamically loading scripts, new device specifications can be adapted without changing firmware, shortening the device launch cycle; supports remote upgrades and hot reloading, improving operational flexibility.

[0095] Protocol Conversion and Data Mapping Unit: Enables data field mapping and unified format conversion between uplink and downlink protocols; supports unified data identification, units of measurement, and precision to ensure semantic consistency between the master station and field devices; can collaborate with the edge intelligent processing module to generate optimized protocol messages by combining data compression and dead zone filtering rules.

[0096] Security Interface Collaboration Unit: Connects to the security encryption module to ensure that all protocol data is encrypted before transmission and decrypted after reception; performs digital signature verification on master station control commands to prevent forged instructions; provides access authentication interface to ensure that only legitimate protocol callers can access the system.

[0097] The edge intelligent processing module includes a data optimization unit, an event detection and sequential event recording unit, a local logic control unit, a breakpoint resume and local caching unit, and an interface collaboration unit.

[0098] Data optimization unit: performs real-time analysis of voltage, current, frequency, power and other data collected on site; adopts change detection algorithm to upload only data that exceeds the set threshold or has a sudden change in state; integrates dead zone filtering function to ignore small fluctuations within the set range (such as voltage ±0.5V) and reduce invalid data transmission by ≥70%.

[0099] Event detection and sequential event recording unit: Real-time detection of events such as remote signaling changes, protection actions, and fault warnings of field equipment; provides sequential event recording (SOE) with a time resolution of 0.1ms, and supports power failure protection and cache storage; provides accurate timestamp data for the dispatch master station for fault analysis and closed-loop control.

[0100] Local logic control unit: Supports user-defined or master-station preset logic rules, such as battery charging and discharging strategies, reactive power compensation control, load shedding / switching, etc.; can achieve autonomous operation in the event of master-station communication interruption or delay, ensuring that the basic control functions of field equipment are not interrupted; supports remote distribution and local editing of logic strategies.

[0101] Resume interrupted transmission and local caching unit: When communication is interrupted, the collected data and event information are cached in local storage; after communication is restored, data is automatically synchronized to ensure data integrity; it supports resume interrupted transmission and data verification mechanisms to prevent data loss or duplication.

[0102] Interface Collaboration Unit: Connects to the protocol adaptation module, encapsulates optimized data into standardized messages; receives control commands parsed by the protocol adaptation module and executes on-site logic; collaborates with the remote operation and maintenance management module to provide edge processing status and performance parameters.

[0103] The remote operation and maintenance management module includes a status monitoring unit, a remote configuration and upgrade unit, a log and audit unit, a warning management unit, and a user permission management unit.

[0104] Status monitoring unit: Real-time monitoring of key operating parameters such as device temperature, power status, communication signal strength, link quality, SIM card status, CPU / memory usage, etc.; when indicators are abnormal (such as temperature exceeding limits, link loss, SIM card arrears, etc.), it triggers warnings and automatically reports them.

[0105] Remote configuration and upgrade unit: Provides web and cloud platform interfaces to enable remote parameter configuration, policy distribution and firmware / specification library upgrades; supports OTA remote upgrades, allowing system software and security policies to be updated without on-site disassembly; all remote operations are encrypted and authenticated through a security encryption module.

[0106] Log and Audit Unit: Records full lifecycle operation logs such as user access behavior, device configuration changes, key updates, and control command execution; log files are encrypted and stored, and can be exported for security auditing purposes according to operation and maintenance needs; meets the compliance requirements of power system security auditing and event tracing.

[0107] Warning Management Unit: Supports multiple warning methods such as SMS, email, and platform push based on the severity level of the event; can be linked with third-party warning platforms (such as dispatch duty systems) to achieve centralized operation and maintenance management.

[0108] User access control unit: Supports multi-level user role hierarchical management (administrator, operator, read-only user, etc.); provides certificate-based user authentication and access control; ensures that remote operation and maintenance access is secure, controllable, and traceable.

[0109] Therefore, the present invention employs the aforementioned power-specific encrypted wireless communication terminal equipment to achieve end-to-end encryption from field equipment to the dispatch master station, preventing data from being stolen, tampered with, or forged, and meeting the power system's high security requirements for data transmission; through algorithms such as variable compression and dead-zone filtering, the amount of invalid data transmission is significantly reduced, thereby reducing the processing pressure on the master station.

[0110] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical solutions of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical solutions to deviate from the spirit and scope of the technical solutions of the present invention.

Claims

1. A power dedicated encrypted wireless communication terminal device, characterized by: The security encryption module, the multi-mode communication module, the protocol adaptation module, the edge intelligent processing module, the remote operation and maintenance module and the core control processing module are included. The security encryption module is used for encrypting and decrypting communication data and remote management data, and ensuring the security of data transmission and storage. The multi-mode communication module is connected with the security encryption module, and is used for uploading the encrypted data to a master station through a cellular wireless communication link or a power carrier communication link, and receiving encrypted data from the master station. The protocol adaptation module is connected with the security encryption module, and is used for encapsulating device original data from the edge intelligent processing module into a data frame conforming to a master station specification, and parsing the decrypted downlink data into control commands suitable for field devices. The edge intelligent processing module is connected with the protocol adaptation module, and is used for compressing the collected field device data in a change amount and filtering a dead zone, and performing local logic control, and transmitting state data, warning information and event records to the protocol adaptation module. The remote operation and maintenance module is connected with the multi-mode communication module, the security encryption module and the edge intelligent processing module, and is used for realizing device parameter configuration, firmware upgrade, state monitoring and warning management through a Web terminal or a remote management platform. The core control processing module is the operation and control core of the terminal device, and is used for performing task scheduling, resource allocation and security policy control. The modules are logically coordinated through the core control processing module, and the process is as follows: The security encryption module encrypts the data from the protocol adaptation module and the remote operation and maintenance module, and transmits the encrypted data to the multi-mode communication module for uploading; The data received by the multi-mode communication module is decrypted by the security encryption module, and is transmitted to the protocol adaptation module or the remote operation and maintenance module; The protocol adaptation module transmits the processed data to the edge intelligent processing module for local logic execution, so as to realize safe transmission of device data and remote controllability.

2. The power dedicated encrypted wireless communication terminal device according to claim 1, wherein: The security encryption module includes a hardware security unit, a data encryption and decryption unit, a bidirectional authentication unit, an encrypted transmission link unit, an access control unit and a security policy management unit. The hardware security unit is built-in with a national secret algorithm hardware security chip, supports multiple algorithms, has an independent security environment for key generation, storage, update and destruction, and supports a true random number generator, a physical tamper-proof detection mechanism and a power-off automatic key clearing function. The data encryption and decryption unit is used for encrypting the uplink service data transmitted from the protocol adaptation module, decrypting the downlink encrypted data received from the master station, and performing integrity verification. The bidirectional authentication unit realizes bidirectional identity authentication between the terminal and the master station based on a digital certificate system, supports certificate update, revocation and validity period management, and performs signature verification in combination with the private key in the hardware chip during the authentication process. The encrypted transmission link unit cooperates with the multi-mode communication module to establish an encrypted tunnel, supports key negotiation and encryption mode, and provides a replay attack prevention mechanism and a message integrity detection mechanism. The access control unit supports a white list strategy, dynamically adjusts the access strategy in cooperation with the remote operation and maintenance module, and records and audits the access behavior. ​ Security policy management unit: according to the different security partition requirements of power field, select different encryption algorithm, authentication mode and link protection level; Interaction with remote operation and management module, realize the remote delivery and online upgrade of security policy; With security warning triggering mechanism, when detecting key invalidation, certificate anomaly or suspicious attack behavior, automatically trigger warning and report to master station; Security policy management unit built-in security partition identification table, combined with terminal installation location to determine the security area; When the terminal detects the change of the security partition, it will automatically match the corresponding security policy template, realize the adaptive adjustment of algorithm, authentication and link protection strategy.

3. A power dedicated encrypted wireless communication terminal device according to claim 2, characterized in that: When switching encryption algorithm, the security policy management unit performs the following operations: first, establish a temporary secure channel to ensure that the configuration instructions in the switching process are not eavesdropped; Generate new key in hardware security unit and load target algorithm; Wait for all established business connections to complete the current data frame exchange, and smoothly switch to new algorithm to avoid communication interruption.

4. A power dedicated encrypted wireless communication terminal device according to claim 3, characterized in that Different partitions use different authentication methods, including high-level and low-level partitions; High-level partition uses bidirectional certificate authentication between terminal and master station; Low-level partition uses one-way certificate authentication or shared key authentication; The security policy management unit selects the authentication method according to the partition strategy, and calls the private key and certificate in the hardware security chip for signature or verification operation.

5. A power dedicated encrypted wireless communication terminal device according to claim 4, characterized in that Link protection level includes full traffic encryption and partial traffic encryption; Full traffic encryption is to encrypt all traffic data for transmission; Partial traffic encryption is to encrypt only key traffic data, and non-sensitive data is transmitted in plaintext to improve efficiency; The selection of link protection level is controlled by security policy table, which is updated online by remote operation and management module.

6. The power dedicated encrypted wireless communication terminal device according to claim 1, wherein: Multi-mode communication module includes cellular communication unit, power carrier communication unit, link management and switching unit, dual card and signal enhancement unit, power consumption and power supply adaptation unit, and network security cooperation unit; Cellular communication unit: supports multiple communication modes, compatible with three major operator networks; Automatically select the operator network with the best signal quality, and has channel monitoring and reconstruction capability; Power carrier communication unit: integrates high-speed power carrier communication interface, uses existing power lines as communication medium; Adopt orthogonal frequency division multiplexing modulation and adaptive channel equalization method to adapt to different cable types and complex electromagnetic environment; As a backup link of cellular communication, it is automatically enabled when cellular network is unavailable; Link management and switching unit: real-time monitor delay, packet loss rate and signal-to-noise ratio of cellular link and power carrier link; Support automatic redundant switching, when the main link fails or the quality drops to the set threshold, seamlessly switch to standby link; Provide link recovery mechanism, automatically switch back when the main link recovers to normal; Dual card and signal enhancement unit: equipped with dual card slot, realize automatic switching between main card and auxiliary card; With external high-gain antenna, support directional adjustment; Support antenna diversity reception and multiple input multiple output mode; Power consumption and power adapter unit: support wide range of DC power input, and has dual power redundancy design; has low power consumption sleep and wake up mechanism, in unattended scene to prolong the life of the device and reduce the operation and maintenance cost; Network security cooperation unit: link with security encryption module, encrypted authentication for link establishment process; Provide integrity check and anti-replay protection for data packets in transmission process; provide network attack detection mechanism, trigger security warning when malicious scanning or pseudo base station behavior is detected.

7. The power dedicated encrypted wireless communication terminal device according to claim 1, wherein: Protocol adaptation module includes uplink protocol processing unit, downlink protocol processing unit, protocol script extension unit, protocol conversion and data mapping unit and security interface cooperation unit; Uplink protocol processing unit: support multiple standard power uplink communication protocols; responsible for converting the terminal collected device operating parameters, state variables and warning events into data frames that meet the receiving format of the master station; Provide time synchronization interface, align with the master station time reference to ensure the accuracy and reliability of event record timestamp; Downlink protocol processing unit: support common field device protocol interface; parse and convert the control commands issued by the master station into instruction sets that can be recognized by corresponding field devices; realize remote control, parameter configuration and downlink adaptation of device debugging; Protocol script extension unit: provides script development interface, supports user-defined parsing rules and private protocol fast access; Through dynamic script loading, no need to change firmware, shorten the device online period; support remote upgrade and hot loading; Protocol conversion and data mapping unit: realize data field mapping and unified format conversion between uplink and downlink protocols; support unified data identification, dimension unit and precision; Cooperate with edge intelligent processing module, combine data compression and dead zone filtering rules to generate optimized protocol messages; Security interface cooperation unit: connected with security encryption module, ensure that all protocol data is encrypted before transmission and decrypted after reception; perform digital signature verification on master station control commands to prevent counterfeit instructions; provide access authentication interface to ensure that only legitimate protocol callers can access the system.

8. The power dedicated encrypted wireless communication terminal device according to claim 1, wherein: Edge intelligent processing module includes data optimization unit, event detection and sequential event recording unit, local logic control unit, breakpoint resume and local cache unit and interface cooperation unit; Data optimization unit: real-time analysis of field collected data; use change detection algorithm to upload only data that exceeds the set threshold or state mutation; Integrate dead zone filtering function, ignore small fluctuations within the set range, reduce invalid data transmission volume; Event detection and sequential event recording unit: real-time detection of field device events; provide 0.1ms time resolution sequential event recording, and support power failure protection and cache storage; Provide accurate timestamp data for dispatching master station, used for fault analysis and closed-loop control; Local logic control unit: support user-defined or master station pre-installed logic rules; in case of master station communication interruption or delay, realize autonomous operation to ensure basic control function of field devices is not interrupted; support remote issuance and local editing of logic strategy; Breakpoint resume and local cache unit: When communication is interrupted, collect data and event information and cache in local storage; After communication is restored, automatically synchronize data to ensure data integrity; Support breakpoint resume and data verification mechanism to prevent data loss or duplication; Interface coordination unit: Connect with protocol adaptation module to encapsulate optimized data into standardized messages; Receive control commands from protocol adaptation module after analysis and execute field logic; Collaborate with remote operation and management module to provide edge processing status and performance parameters.

9. The power dedicated encrypted wireless communication terminal device according to claim 1, wherein: Remote operation and management module includes state monitoring unit, remote configuration and upgrade unit, log and audit unit, warning management unit and user permission management unit; State monitoring unit: Real-time monitoring of key operating parameters, triggering warnings and automatic reporting when indicators are abnormal; Remote configuration and upgrade unit: Provides Web and cloud platform interfaces to realize remote parameter configuration, policy distribution and firmware or protocol library upgrade; Support remote upgrade without disassembly; All remote operations are encrypted and authenticated through a secure encryption module; Log and audit unit: Records operation logs throughout the life cycle; Log files are encrypted and stored, and exported for security audit according to operation needs; Meet the compliance requirements of power system security audit and event traceability; Warning management unit: Supports multiple warning methods according to event severity levels, and cooperates with third-party warning platforms to realize centralized operation and management; User permission management unit: Supports multi-level user role management; Provides user identity authentication and access control based on certificates; Ensures the safety, controllability and traceability of remote operation and access process.

Citation Information

Patent Citations

  • Power telecommunication network field operation and maintenance data encryption transmission and verification method

    CN104301317A

  • Communication method for power asset management master station system and mobile terminal

    CN119966720A