Software and hardware integrated intelligent terminal power transaction system and method

The integrated hardware and software intelligent terminal power trading system, utilizing processors and security encryption chips, combined with a local decision engine and risk control module, solves the problems of insufficient data security and real-time performance in the existing power trading process, and achieves secure, controllable, real-time, efficient, continuous, stable and convenient operation and maintenance of power trading.

CN121120245APending Publication Date: 2025-12-12HEFEI YUANLI ZHONGHE ENERGY TECH CO LTD

Patent Information

Application Number
CN202511649024.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-12
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

The existing power trading process suffers from data security risks and insufficient real-time performance due to reliance on external platforms. Traditional network gateways are expensive and have limited functionality, failing to meet the needs of complex real-time trading strategy deployment and risk management.

Method used

The intelligent terminal power trading system adopts integrated hardware and software. The processor undertakes high-intensity computing tasks, and combined with redundant power supplies, security encryption chips and multi-port isolation, it builds localized trading decision-making capabilities. Through dual communication security modules and a full-process risk control system, it achieves localized data processing and security barriers.

Benefits of technology

It enables secure, controllable, real-time, efficient, continuous, stable, and convenient operation and maintenance of electricity transactions, meets the local independent decision-making and compliant operation needs of electricity sales companies, reduces the risk of leakage of core transaction data, and improves the real-time performance and security of transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121120245A_ABST
    Figure CN121120245A_ABST
Patent Text Reader

Abstract

The invention provides a software and hardware integrated intelligent terminal power transaction system and method, relates to the technical field of power market transaction, and solves the technical problems of data potential safety hazards and insufficient real-time performance caused by dependence on an external platform in a power transaction process in the prior art. The system specifically comprises a hardware architecture and a software function module, the hardware architecture comprises a processor, a redundant power supply, a storage device, a network interface, a security encryption chip and a display interface; the software function module comprises a core function layer, an interface layer and a security layer; wherein the core function layer is used for being responsible for processing and controlling the whole flow of power transaction; the interface layer is used for carrying out standardized and ordered external data interaction; and the security layer is used for guaranteeing the security of the terminal from multiple dimensions of communication, transaction, data and operation and maintenance. The method is used for electricity market transaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of electricity market trading technology, and in particular to an integrated hardware and software intelligent terminal electricity trading system and method. Background Technology

[0002] With the gradual opening of the electricity market and the advancement of spot trading, electricity sales companies need to handle a large amount of real-time data analysis and trading decisions while ensuring data security. In the current technology, electricity sales companies obtain trading-related data through VPN dedicated lines or cloud platform interfaces, and even conduct decision analysis directly in the cloud. Under this model, electricity sales companies lack independent decision-making capabilities locally, and core data stored in the cloud is prone to leakage or network attack risks. To improve security, network security isolation devices are usually used to achieve physical isolation between internal and external networks, allowing only one-way data flow, thereby preventing direct external access to the internal network. However, traditional network gateways are expensive and have limited functions, and cannot meet the needs of complex real-time trading strategy deployment and risk management. Therefore, existing technologies for electricity trading suffer from data security risks and insufficient real-time performance due to reliance on external platforms. Summary of the Invention

[0003] This application provides an integrated hardware and software intelligent terminal power trading system and method, which solves the technical problems of data security risks and insufficient real-time performance caused by reliance on external platforms in the power trading process in the prior art.

[0004] To achieve the above objectives, this application adopts the following technical solution: Firstly, a hardware-software integrated intelligent terminal power trading system is provided, comprising: a hardware architecture and software functional modules; the hardware architecture includes: a processor, redundant power supply, storage device, network interface, security encryption chip, and display interface; wherein, the processor is used to undertake local high-intensity computing tasks; computing tasks include receiving and processing power trading-related data, calculating electricity price and load forecasting models, calculating trading decision schemes, and assessing risk indicators; the redundant power supply is used to ensure uninterrupted system operation and provide power supply in the event of main power failure or abnormality; the storage device is used to store local databases and model repositories; the network interface includes internal network interfaces and external network interfaces; the internal network interface is used to connect to the company's internal business network; the external network interface is used to connect to external data or remote operation and maintenance channels; the security encryption chip is used to store system keys and perform encryption and decryption operations; the display interface is used to connect display devices and input devices; the software functional modules include: a core functional layer, an interface layer, and a security layer; wherein, the core functional layer is responsible for the processing and control of the entire power trading process; the interface layer is used for standardized and orderly external data interaction; the security layer is used to ensure terminal security from multiple dimensions such as communication, trading, data, and operation and maintenance.

[0005] In conjunction with the first aspect mentioned above, in one possible implementation, the core functional layer includes: a local decision engine, a risk control module, a model repository, and a data caching module; the local decision engine is used to generate trading decision schemes by utilizing embedded trading strategies and optimization algorithms, combined with real-time market data and local load / generation information, and supports customized strategy configuration; the risk control module is used to monitor risk indicators in the trading decision process in real time, execute preset risk control rule sets, and intercept or alarm abnormal situations; the model repository is used to store power trading-related algorithm models and parameter configurations; the data caching module is used to store and cache business data; business data includes historical trading data, market data, customer load and generation data.

[0006] In conjunction with the first aspect mentioned above, in one possible implementation, the interface layer includes: an external data interface and a screen interaction system; the external data interface is used to acquire external electricity market data and convert the external electricity market data into a standard format usable internally; the communication process for acquiring external electricity market data is compatible with HTTP / HTTPS, WebSocket, and MQTT protocol types; the screen interaction system is used to provide a visual human-computer interface and support multi-user hierarchical operation.

[0007] In conjunction with the first aspect mentioned above, in one possible implementation, the security layer includes: a communication encryption module, a transaction status monitoring module, and a log auditing system; the communication encryption module includes a one-way security gateway submodule and a software encryption submodule; the one-way security gateway submodule is used to ensure that data flows from the outside to the internal terminal and to refuse any internal information from being returned to the outside; the software encryption submodule is used to perform two-way authentication between the terminal and the external data source based on the PKI / CA digital certificate system, and to exchange session keys through an asymmetric encryption algorithm to build a high-strength encryption channel; the transaction status monitoring module is used to continuously monitor the status of each stage of the transaction process, and if an anomaly occurs, to record detailed logs and trigger warnings; the log auditing system is used to encrypt the detailed log data of the entire process through chained hash storage technology.

[0008] In conjunction with the first aspect mentioned above, in one possible implementation, the data caching module can also provide historical cached data to the local decision engine and model repository when the external network is interrupted.

[0009] In conjunction with the first aspect mentioned above, in one possible implementation, the one-way security gateway submodule and the software encryption submodule are not mutually exclusive. The one-way security gateway submodule can be deployed at the network boundary to construct a one-way data transmission channel, while the encrypted data stream processed by the software encryption submodule is carried within the one-way data transmission channel.

[0010] In conjunction with the first aspect mentioned above, in one possible implementation, the high-strength encrypted channel adopts the TLS 1.3 protocol, and requires external data sources to attach timestamps and sequence numbers to critical business data.

[0011] Secondly, a hardware-software integrated intelligent terminal power trading method is provided, including: acquiring external power market data through an external data interface; parsing the external power market data into a standard format recognizable by the core functional layer, removing abnormal data, and caching it together with local data in a data cache module; running a local decision engine through a processor, combining preprocessed data and embedded trading strategies to generate a trading decision scheme adapted to the trading scenario; calling a risk control rule set through a risk control module to calculate the risk indicators of the decision scheme, and if the limits are not exceeded, the scheme passes verification; if the limits are exceeded, automatic downgrading, manual approval, or direct interception is executed; when manual approval is executed, an external display device is connected through the terminal's display interface to display the details of the decision scheme and corresponding risk analysis data for on-site personnel to view and complete the approval operation; the execution status of verified declaration instructions is tracked through a transaction status monitoring module, and the execution progress and transaction results of the declaration instructions are displayed in real time through an external display device; if an anomaly occurs, information is recorded, an alarm is triggered, and a pop-up notification is displayed on the external display device; the entire process data is recorded through a log audit system and encrypted to prevent tampering, automatically generating transaction settlement reports and risk analysis reports, and displaying the reports and report content through an external display device, supporting on-site personnel to view or export them.

[0012] In conjunction with the second aspect mentioned above, one possible implementation involves providing a dual communication security scheme to ensure communication security when acquiring external power market data. This dual communication security scheme includes a one-way network gateway hardware solution and a software-encrypted communication solution. The one-way network gateway hardware solution constructs a physical isolation barrier by connecting to a one-way security gateway, allowing only external data sources to transmit data into the system and preventing any sensitive internal information from leaking out. The software-encrypted communication solution completes two-way authentication between the terminal and the external data source based on the PKI / CA digital certificate system, allowing only trusted entities to establish communication sessions. Simultaneously, it exchanges session keys using an asymmetric encryption algorithm to construct a high-strength encrypted channel.

[0013] In conjunction with the second aspect mentioned above, in one possible implementation, the method further includes device management and remote operation and maintenance. Device management and remote operation and maintenance includes: real-time monitoring of terminal hardware resource status and software module operation; triggering alarms on the local interactive interface and executing protective measures when device malfunctions are detected; device malfunctions include hardware malfunctions and software malfunctions; hardware malfunctions include persistent processor utilization exceeding limits, redundant power supply switching failure, network interface interruption, and storage device read / write errors; software malfunctions include module crashes and policy rule loading failures; protective measures include forced switching of redundant power supplies, restarting of faulty network interfaces, automatic restart of faulty processes, policy rollback to available versions, and cache count... Persistent storage is used for data storage; remote connections are established via encrypted VPN or dedicated maintenance lines, and after authentication, terminal diagnostics, log collection, parameter configuration, and software update operations are performed remotely, with all remote operations generating audit logs; parameters of new strategies or models to be deployed are imported into the terminal sandbox environment, and historical transaction data or simulation data are used to simulate operation and evaluate strategy performance and risk indicators; once the new strategy or model passes the sandbox test, deployment instructions are displayed on the display device; the deployment instructions are used to deploy the new strategy or model to the terminal production environment after confirmation by on-site personnel; all remote maintenance operations are recorded, and logs are stored in encrypted form; when unauthorized access occurs, alarm information is pushed to the security management platform.

[0014] Thirdly, this application provides an integrated hardware and software intelligent terminal power trading device, including: a communication unit and a processing unit; the communication unit is used to acquire external power market data; the processing unit is used to parse the external power market data into a standard format recognizable by the core functional layer, remove abnormal data, and cache it together with local data in a data cache module; the processor runs a local decision engine, combines preprocessed data and embedded trading strategies to generate a trading decision scheme adapted to the trading scenario; the risk control module calls the risk control rule set to calculate the risk indicators of the decision scheme, and if the risk indicators do not exceed the limits, the scheme passes the verification; if the risk indicators exceed the limits, the scheme executes automatic downgrading, manual approval, or... Direct interception; during manual approval, an external display device is connected via the terminal's display interface to show details of the decision-making plan and corresponding risk analysis data, allowing on-site personnel to view and complete the approval process; the transaction status monitoring module tracks the execution status of verified declaration instructions, while the execution progress and transaction results of the declaration instructions are displayed in real time on the external display device. If any abnormality occurs, information is recorded, alarms are triggered, and pop-up notifications are displayed on the external display device; the log audit system records all process data and encrypts it to prevent tampering, automatically generating transaction settlement reports and risk analysis reports, and displaying the reports and their contents on the external display device, supporting on-site personnel to view or export them.

[0015] Fourthly, this application provides a hardware-software integrated smart terminal power trading device, comprising: a processor and a storage medium; the storage medium includes instructions, and the processor is used to execute the instructions to implement the methods described in the second aspect and any possible implementation of the second aspect. This hardware-software integrated smart terminal power trading device can be an electronic device or a chip within an electronic device.

[0016] Fifthly, this application provides a computer-readable storage medium storing instructions that, when executed on a hardware-software integrated smart terminal power trading device, cause the hardware-software integrated smart terminal power trading device to perform the method described in the second aspect and any possible implementation thereof.

[0017] Sixthly, this application provides a computer program product containing instructions that, when run on a hardware-software integrated smart terminal power trading device, causes the hardware-software integrated smart terminal power trading device to perform the method described in the second aspect and any possible implementation of the second aspect.

[0018] This application provides an integrated hardware and software intelligent terminal power trading system and method. It achieves localized processing of the entire power trading process by deeply integrating customized hardware such as processors, redundant power supplies, multi-port isolation, and security encryption chips with a local decision engine, dual communication security modules, a full-process risk control system, data caching, and remote operation and maintenance modules. The system leverages the processor to handle high-intensity computational tasks such as electricity price and load forecasting and trading decisions, reducing reliance on external cloud platforms and avoiding the risk of core trading data leakage. It also constructs a security barrier through dual protection of physical isolation and software encryption via multiple network ports. Simultaneously, the redundant power supply ensures uninterrupted system operation, and the data caching module provides historical data support for local decision-making when external networks are interrupted, ensuring trading continuity. Furthermore, the full-process risk control rule verification, visual human-computer interaction, and encrypted VPN remote operation and maintenance solve the data security risks and real-time performance deficiencies caused by reliance on external platforms in existing technologies. It also overcomes the shortcomings of traditional network gateways, which have limited functionality and are difficult to adapt to complex trading scenarios. Ultimately, it achieves secure, controllable, real-time, efficient, continuous, stable, and convenient operation and maintenance of power trading, meeting the local autonomous decision-making and compliant operation needs of power sales companies.

[0019] It should be understood that the descriptions of technical features, technical solutions, beneficial effects, or similar language in this application do not imply that all features and advantages can be achieved in any single embodiment. Rather, it is understood that the description of a feature or beneficial effect means that a specific technical feature, technical solution, or beneficial effect is included in at least one embodiment. Therefore, the descriptions of technical features, technical solutions, or beneficial effects in this specification do not necessarily refer to the same embodiment. Furthermore, the technical features, technical solutions, and beneficial effects described in this embodiment can be combined in any suitable manner. Those skilled in the art will understand that embodiments can be implemented without one or more specific technical features, technical solutions, or beneficial effects of a particular embodiment. In other embodiments, additional technical features and beneficial effects may be identified in specific embodiments that do not embody all embodiments. Attached Figure Description

[0020] Figure 1 A system architecture diagram of an integrated hardware and software intelligent terminal power trading system provided for embodiments of this application; Figure 2 A system architecture diagram of another integrated hardware and software intelligent terminal power trading system provided for embodiments of this application; Figure 3 A flowchart illustrating a hardware and software integrated smart terminal power trading method provided in this application embodiment; Figure 4 This is a schematic diagram of a dual communication security scheme provided in an embodiment of this application; Figure 5 This is a schematic diagram of the risk control response process provided in the embodiments of this application; Figure 6 This is a schematic diagram of the risk control process provided in the embodiments of this application; Figure 7 A flowchart illustrating another integrated hardware and software smart terminal power trading method provided in this application embodiment; Figure 8 This is a schematic diagram of the device management and remote operation and maintenance structure provided in the embodiments of this application; Figure 9 A schematic diagram of the structure of an integrated hardware and software smart terminal power trading device provided in this application embodiment; Figure 10 This is a schematic diagram of the hardware structure of an integrated hardware and software smart terminal power trading device provided in an embodiment of this application. Detailed Implementation

[0021] In the description of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. The "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" means one or more, and "multiple" means two or more. The terms "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply differences.

[0022] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0023] The integrated hardware and software intelligent terminal power trading system provided in this application embodiment, such as... Figure 1 As shown, the system includes: hardware architecture 10A and software functional modules 10B; The hardware architecture 10A includes: a processor 101, a redundant power supply 102, a security encryption chip 103, a network interface 104, a storage device 105, and a display interface 106. The processor 101 is used to handle local high-intensity computing tasks, including receiving and processing data related to power trading, calculating electricity price and load forecasting models, calculating trading decision schemes, and assessing risk indicators. The redundant power supply 102 ensures uninterrupted system operation and provides power in case of main power failure or abnormality. The security encryption chip 103 stores system keys and performs encryption and decryption operations. The network interface 104 includes an internal network interface and an external network interface. The internal network interface connects to the company's internal business network, while the external network interface connects to external data or remote maintenance channels. The storage device 105 stores the local database and model repository. The display interface 106 connects to display devices and input devices.

[0024] The software functional module 10B includes: a core functional layer 107, an interface layer 108, and a security layer 109. The core functional layer 107 is responsible for the processing and control of the entire power trading process; the interface layer 108 is used for standardized and orderly external data interaction; and the security layer 109 is used to ensure terminal security from multiple dimensions, including communication, trading, data, and operation and maintenance.

[0025] Based on the aforementioned system, significant technological advantages are achieved through the deep integration of customized hardware and collaborative software. On the hardware side, the processor locally handles high-intensity calculations such as transaction data processing and electricity price and load forecasting, preventing the external transmission of core data; redundant power supplies ensure uninterrupted terminal operation, resolving service interruption issues during power outages; multiple network ports isolate internal and external networks, and a secure encryption chip protects keys and encryption / decryption, building a robust hardware security barrier. On the software side, the core functional layer enables full-process transaction management, supporting customized strategies for multiple scenarios and real-time risk control interception; the interface layer is compatible with multiple protocols, improving the efficiency of external data access; the security layer provides multi-dimensional protection from communication, transaction, data, and operation and maintenance dimensions, ensuring compliance and traceability. This solves the technical problems of data security risks and insufficient real-time performance in existing power trading technologies due to reliance on external platforms.

[0026] In one possible approach, combining the above... Figure 1 ,like Figure 2 As shown, the core functional layer 107 includes: a local decision engine, a risk control module, a model repository, and a data caching module; the interface layer 108 includes: an external data interface and a screen interaction system; and the security layer 109 includes: a communication encryption module, a transaction status monitoring module, and a log auditing system.

[0027] The system includes a local decision engine, which uses embedded trading strategies and optimization algorithms to generate trading decision schemes by combining real-time market data and local load / generation information, and supports customized strategy configuration; a risk control module, which monitors risk indicators in the trading decision-making process in real time, executes preset risk control rule sets, and intercepts or alerts for abnormal situations; a model repository, which stores power trading-related algorithm models and parameter configurations; and a data caching module, which stores and caches business data, including historical trading data, market data, customer load, and generation data.

[0028] An external data interface is used to acquire external electricity market data and convert it into a standard format usable internally; the communication process for acquiring external electricity market data is compatible with HTTP / HTTPS, WebSocket, and MQTT protocols; a screen interaction system is used to provide a visual human-machine interface and supports multi-user hierarchical operation.

[0029] The communication encryption module includes a one-way security gateway submodule and a software encryption submodule. The one-way security gateway submodule ensures that data flows from the outside to the internal terminal and prevents any internal information from being returned to the outside. The software encryption submodule performs two-way authentication between the terminal and the external data source based on the PKI / CA digital certificate system, and exchanges session keys through an asymmetric encryption algorithm to build a high-strength encryption channel. The transaction status monitoring module continuously monitors the status of each stage of the transaction process. If an anomaly occurs, it records detailed logs and triggers warnings. The log auditing system encrypts the detailed log data of the entire process using chained hash storage technology.

[0030] Based on the above system, the core functional layer is supported by a local decision engine, risk control module, model warehouse, and data caching module. It can generate trading solutions by combining real-time data and customized strategies, dynamically intercept risks, and ensure continuous trading when the external network is interrupted by local caching. The interface layer relies on external data interfaces compatible with multiple protocols and a multi-user hierarchical screen interaction system to efficiently complete external data format conversion. At the same time, it improves the convenience and security of operation through a visual interface and permission control. The security layer builds a tight protection from the dimensions of communication, transaction, and data through dual communication protection of one-way security gateway and software encryption, full-process transaction monitoring, and chain hash encrypted logs, ensuring the security and traceability of the entire transaction process and meeting the compliance requirements of the power industry.

[0031] Figure 3 A flowchart illustrating the integrated hardware and software smart terminal power trading method provided in this application embodiment is shown below. Figure 3 As shown, the method includes: S301. Obtain external electricity market data through an external data interface.

[0032] The external power market data includes market quotations / clearing results from the higher-level power trading platform and electricity price forecasts / weather data from third-party service providers; the external data interface is the core module of the interface layer; the dual communication security scheme adopted in the acquisition process includes a one-way network gateway hardware scheme and a software encrypted communication scheme.

[0033] In this embodiment, data is obtained through a dual communication security scheme, combining the external data interface of the interface layer with the communication encryption module of the security layer. For example... Figure 4 The diagram illustrates a dual-communication security scheme. When using a one-way network gateway hardware solution, a physical isolation barrier is constructed by connecting to a one-way security gateway, allowing only external data sources to transmit data to the system. When using a software-encrypted communication scheme, two-way identity authentication between the smart terminal and the external system is completed based on the PKI / CA digital certificate system. Session keys are exchanged through an asymmetric encryption algorithm to construct a TLS1.3 high-strength encryption channel. At the same time, timestamps and serial numbers are required to be added to critical business data.

[0034] It should be noted that the one-way gateway hardware solution and the software encrypted communication solution are not mutually exclusive. Depending on the security level, a one-way gateway can be deployed at the network boundary while carrying encrypted data streams within the one-way channel to further enhance security.

[0035] Based on the above steps, while acquiring external power market data, communication security can be guaranteed from both hardware and software levels, preventing sensitive internal information from leaking out, ensuring the reliability of data sources and the confidentiality and integrity of the transmission process, and reducing the hardware cost of the network gateway by adopting a software-encrypted communication scheme.

[0036] S302. Parse external power market data into a standard format recognizable by the core functional layer, remove abnormal data, and cache it together with local data in the data cache module.

[0037] The standard format is a data format that is compatible with all modules of the core functional layer (such as the local decision engine and model warehouse); abnormal data includes electricity price values ​​that exceed the reasonable range and load data that is missing key fields; local data includes historical transaction data, customer load and power generation data; the data caching module is a component of the core functional layer and is used for high-speed data storage.

[0038] In this embodiment, the external data interface of the interface layer first parses the external electricity market data into standard formats such as JSON or XML, and removes abnormal data such as negative electricity consumption and electricity prices exceeding the upper limit. Then, the data caching module of the core function layer caches the preprocessed external data together with the historical transaction data and customer load data in the local database.

[0039] It should be noted that the data preprocessing process can reduce the data processing pressure on the core functional layer modules, and all local data is persistently stored within the terminal and not uploaded to the external cloud, thus protecting the security of sensitive information.

[0040] As an example, the external data interface parses the XML-formatted clearing data from the upper-level trading platform into JSON format, removes abnormal electricity data of -50 kWh, and caches it together with the local storage of nearly 3 months of historical trading data into the data cache module.

[0041] Based on the above steps, a standard and clean dataset can be output, while local caching improves data reading efficiency and avoids frequent access to external interfaces.

[0042] S303: The processor runs a local decision engine, which combines preprocessed data and embedded trading strategies to generate a trading decision scheme adapted to the trading scenario.

[0043] Among them, the processor is the core computing component of the hardware architecture; the local decision engine is the core module of the core functional layer, which embeds trading strategies and optimization algorithms; the preprocessed data is the standardized data cached in S302; the trading scenarios include monthly auctions, day-ahead trading, and intraday adjustments.

[0044] In this embodiment, the processor of the hardware architecture provides computing power support, driving the local decision engine of the core functional layer to call the electricity price forecast and load forecast models in the model repository, and combine the preprocessed data cached by S302 with the embedded customized trading strategy to generate a trading decision scheme that includes the declared electricity volume and the bidding strategy, which is adapted to the needs of the current trading scenario.

[0045] Based on the above steps, localized computation of transaction decisions can be achieved, reducing reliance on cloud platforms, lowering network latency, and generating accurate decision-making solutions adapted to specific scenarios, thereby improving transaction response speed.

[0046] S304. The risk control module calls the risk control rule set to calculate the risk indicators of the decision plan. If the risk indicators do not exceed the limits, the plan passes the verification. If the risk indicators exceed the limits, the plan will automatically downgrade, require manual approval, or be directly blocked.

[0047] Among them, the risk control module is a component of the core functional layer; the risk control rule set includes regulatory policy restrictions and internal company risk limits; risk indicators include the maximum possible loss and margin requirements; automatic downgrading means reducing the transaction size, and direct interception means prohibiting the execution of the plan.

[0048] In the embodiments of this application, such as Figure 5 The diagram illustrates the risk control response process. The risk control module calls the risk control rule base to perform risk control rule checks on the transaction plan generated by the decision engine to calculate risk indicators. If the risk indicators do not exceed the limits, the plan passes the verification and is submitted to the trading platform. The transaction status monitoring module monitors and provides feedback on its execution status in real time. If the trading platform reports an abnormal transaction, a risk control reassessment is triggered. If the assessment result indicates increased risk, a three-level response mechanism is triggered: automatic downgrading, manual review, and direct interception. If the risk indicators exceed the limits during the risk control rule check, a three-level response is directly triggered. During automatic downgrading, transaction parameters (such as declared electricity volume and price) are adjusted and sent back to the decision engine, which regenerates the transaction plan and performs another risk control rule check. During manual review, authorized personnel approve the plan through a display device and output the execution or rejection result. During direct interception, the risk control event is recorded and a log is retained.

[0049] As an example, such as Figure 6The risk control process diagram shown illustrates that after external data sources are transmitted via a one-way gateway, the decision engine (A) generates a trading plan. This plan is then passed to the risk control rule check module (D), which uses the risk control rule set to calculate risk indicators. If the trading plan triggers manual review (Q) due to excessive electricity exposure, the adjusted parameters are sent back to the decision engine (A) to assist in optimizing subsequent trading plans. If the risk indicators are within limits, the plan is submitted to the trading platform, and the platform's transaction feedback is transmitted to the risk reassessment module (K). If further adjustments are needed after the reassessment, an automatic downgrade (G) operation can be triggered to optimize the trading plan.

[0050] Based on the above steps, risks can be identified and controlled in advance before the execution of transaction decisions, avoiding illegal or excessive transactions and ensuring the compliance and security of corporate transaction behavior.

[0051] S305. When performing manual approval, an external display device is connected through the terminal's display interface to display the details of the decision-making plan and the corresponding risk analysis data, so that on-site personnel can view and complete the approval operation.

[0052] The display interface is a component of the hardware architecture used to connect external display devices such as monitors and consoles; the decision-making details include the declared electricity volume, price quote, and transaction scenario; and the risk analysis data includes the reasons for exceeding risk indicators and adjustment suggestions.

[0053] In this embodiment, when the risk control module triggers manual approval, the display interface of the hardware architecture connects to external display devices such as industrial monitoring screens or operating consoles. The software layer's screen interaction system displays details such as the declared electricity volume and price of the transaction decision plan, as well as risk analysis data, for authorized management personnel to view and complete the approval or rejection operation through input devices.

[0054] Based on the above steps, manual intervention in high-risk transaction decisions can be achieved, approval efficiency can be improved through visualization, and unauthorized personnel intervention can be avoided, further ensuring transaction security.

[0055] S306. The transaction status monitoring module tracks the execution status of the verification declaration instructions and displays the execution progress and transaction results of the declaration instructions in real time through an external display device. If any abnormality occurs, the information is recorded, an alarm is triggered, and a pop-up window is displayed on the external display device.

[0056] The transaction status monitoring module is a component of the security layer; the declaration instruction is the execution instruction corresponding to the verified transaction decision scheme; the execution status includes successful submission, pending transaction, partial transaction, and failure; anomalies include declaration timeout and failure feedback from the transaction platform.

[0057] In this embodiment, the transaction status monitoring module of the security layer tracks the execution status of the declaration instruction on the power trading platform, obtains information such as submission feedback and transaction results in real time, and displays the execution progress and transaction results through an external display device connected to the hardware display interface. If any abnormality occurs, such as data timeout or declaration failure, the abnormality details are immediately recorded to the log audit system, triggering an audible and visual alarm and displaying the cause of the abnormality in a pop-up window on the display device.

[0058] It should be noted that abnormal information will be stored in the local logs simultaneously, which will facilitate subsequent investigation by operation and maintenance personnel. The alarm method can be configured as a pop-up window, SMS or email as needed.

[0059] Based on the above steps, the entire transaction execution process can be monitored in real time, abnormal situations can be detected and warned in a timely manner, transaction losses caused by unhandled abnormalities can be avoided, and a basis for anomaly investigation can be provided.

[0060] S307. The log audit system records all process data and encrypts it to prevent tampering. It automatically generates transaction settlement reports and risk analysis reports, and displays the reports and content through external display devices, supporting on-site personnel to view or export them.

[0061] The log auditing system is a component of the security layer and uses chained hash storage technology; the transaction settlement report includes transaction volume and revenue statistics; the risk analysis report includes changes in risk indicators and deviation analysis; and the chained hash storage can prevent log tampering.

[0062] In this embodiment, the log auditing system of the security layer records the entire process data of S301-S306, encrypts and prevents tampering through chain hash storage technology, automatically generates transaction settlement reports and risk analysis reports, and finally displays the report content through an external display device connected to the display interface, supporting on-site personnel to export to Excel or PDF format through the screen interaction system.

[0063] Based on the above steps, the entire transaction process can be traced, ensuring data integrity and immutability, while generating intuitive business reports to support enterprise review, optimization, and compliance audits.

[0064] Based on the above technical solutions, the design of the entire process of data acquisition, preprocessing, decision-making, risk control, approval, monitoring, and traceability enables the localization, security, and automation of power trading, solving the technical problems of data security risks and insufficient real-time performance caused by reliance on external platforms in the existing power trading process.

[0065] In one possible way, such as Figure 7 As shown, the method provided in this application also includes equipment management and remote operation and maintenance, and the specific process of equipment management and remote operation and maintenance can be implemented through the following S701-S704: S701 monitors the hardware resource status and software module operation of the terminal in real time. When an abnormal device operation is detected, an alarm is triggered on the local interactive interface and protective measures are implemented.

[0066] Among them, equipment malfunctions include hardware malfunctions and software malfunctions; protection measures include forced switching of redundant power supplies, restarting of faulty network interfaces, automatic restart of faulty processes, policy rollback to available versions, and persistent storage of cached data.

[0067] In this embodiment, the device management module collects hardware data such as terminal CPU usage, memory usage, and power status in real time, as well as the operation logs of software modules such as the decision engine and risk control module. If a hardware anomaly is detected, including continuous processor usage exceeding limits, redundant power supply switching failure, network interface interruption, storage device read / write errors, and software anomalies such as module crashes and policy rule loading failures, an alarm is triggered on the local interactive interface. Protective measures are triggered for different anomalies, including forced switching of redundant power supply, restart of faulty network interface, automatic restart of faulty process, policy rollback to an available version, and persistent storage of cached data.

[0068] Based on the above steps, the terminal's operating status can be monitored in real time, anomalies can be handled promptly to ensure system stability, and operations can be standardized through permission and version management.

[0069] S702: Establish a remote connection via encrypted VPN or dedicated maintenance line. After authentication, remotely perform terminal diagnostics, log collection, parameter configuration, and software update operations. All remote operations generate audit logs.

[0070] The encrypted VPN uses the IPSec / SSL protocol; authentication is a two-factor authentication method using both password and dynamic token; and the audit log includes the operator, time, and content.

[0071] In this embodiment, the remote operation and maintenance module initiates a connection request through an encrypted VPN or dedicated line. After two-factor authentication with a password and a dynamic token, it remotely performs operations such as terminal hardware diagnosis, log collection, parameter adjustment, and software update. Each operation generates an audit log and records it.

[0072] It should be noted that the remote connection is encrypted throughout and can be configured to block connections during non-working hours.

[0073] As an example, operations and maintenance personnel remotely connect to the terminal via SSL VPN (AES-256 encryption), collect risk control module logs and adjust decision engine parameters after two-factor authentication, and the operation logs are automatically archived.

[0074] Based on the above steps, secure and controllable remote operation and maintenance can be achieved, meeting cross-regional needs and ensuring traceability of operations.

[0075] S703: Import the parameters of the new strategy or model to be deployed into the terminal sandbox environment, simulate its operation using historical transaction data or simulation data, and evaluate the strategy's performance and risk indicators; once the new strategy or model passes the sandbox test, display the deployment instructions on the display device.

[0076] The sandbox environment is isolated from the production environment; historical transaction data is a record stored locally on the terminal; simulation data is simulated electricity market scenario data; deployment instructions are used to deploy the new strategy or model to the terminal production environment after confirmation by on-site personnel.

[0077] In this embodiment, the new strategy / model parameters are imported into the sandbox environment, historical transaction data or simulation data are called to simulate the operation, and performance and risk indicators are evaluated; if the simulation results of the new strategy or model meet the preset conditions, a deployment instruction is generated and displayed on the display device.

[0078] It should be noted that the sandbox is strictly isolated from the production environment, the testing standards can be customized, and this application does not specify the specific testing process.

[0079] Based on the above steps, new strategies are validated in advance through sandbox testing, reducing trading risks and ensuring smooth strategy iteration.

[0080] S704 records all remote operation and maintenance operations and stores the logs in encrypted form; when unauthorized access occurs, it pushes alarm information to the security management platform.

[0081] Among them, the security management platform is an enterprise-level security monitoring center.

[0082] In this embodiment, the log auditing and security alarm module records all remote operation and maintenance logs and stores them using the AES-256 algorithm for encryption; when an unauthorized access security event is detected, an alarm message is immediately pushed to the security management platform.

[0083] It should be noted that emails and text messages can also be sent to administrators for timely responses.

[0084] Based on the above steps, full-chain auditing of operation and maintenance and real-time alerts for security incidents are achieved, providing support for tracing and responding to security threats.

[0085] As an example, such as Figure 8The diagram illustrates the device management and remote operation and maintenance structure. The operation and maintenance operator initiates device management or policy update requests through the operation and maintenance console. These requests are first passed to the policy management system for policy rule verification and preliminary processing. After successful verification, the system enters a sandbox testing environment to simulate and verify the policy / operation and maintenance operations using simulation data or historical transaction data. If the sandbox test passes, the policy distribution process is executed, pushing compliant policies or operation and maintenance instructions to the business terminals. On the business terminal side, on one hand, the system monitors the CPU, memory, and storage of the devices to collect real-time data on hardware resource status and software process operation. If device anomalies are detected, alarms are reported to the security operation and maintenance center, and emergency response is initiated. Patches are pushed back to the device status monitoring process via remote diagnostics. On the other hand, the log management system synchronously records the entire process of policy distribution, device monitoring, and remote operations, generating operation audit logs.

[0086] Based on the above technical solutions, the security, standardization, and intelligence of equipment management and remote operation and maintenance are realized; it not only ensures the stable operation of the terminal and meets the needs of cross-regional operation and maintenance, but also reduces the risk of strategy iteration, responds to security threats in a timely manner, improves the efficiency and security of system operation and maintenance, and supports the long-term reliable operation of power trading terminals.

[0087] The above primarily describes the solutions of the embodiments of this application from the perspective of device implementation. It is understood that each device, such as a hardware-software integrated intelligent terminal power trading device, includes at least one of the hardware structure and software module corresponding to each function in order to achieve the above functions. Those skilled in the art should readily recognize that, based on the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0088] This application embodiment can divide the integrated hardware and software intelligent terminal power trading device into functional units based on the above method example. For example, each function can be divided into separate functional units, or two or more functions can be integrated into one processing unit. The integrated unit can be implemented in hardware or as a software functional unit. It should be noted that the unit division in this application embodiment is illustrative and only represents one logical functional division; other division methods may be used in actual implementation.

[0089] When using integrated units, Figure 9A possible structural schematic diagram of the integrated hardware and software smart terminal power trading device (referred to as integrated hardware and software smart terminal power trading device 90) involved in the above embodiments is shown. The integrated hardware and software smart terminal power trading device 90 includes a processing unit 901 and a communication unit 902, and may also include a storage unit 903. Figure 9 The structural diagram shown can be used to illustrate the structure of the integrated hardware and software smart terminal power trading device involved in the above embodiments.

[0090] when Figure 9 The schematic diagram shown illustrates the structure of the integrated hardware and software smart terminal power trading device involved in the above embodiments. The processing unit 901 is used to control and manage the operation of the integrated hardware and software smart terminal power trading device, the communication unit 902 is used for the integrated hardware and software smart terminal power trading device to communicate with other devices, and the storage unit 903 is used to store the program code and data of the integrated hardware and software smart terminal power trading device.

[0091] For example, communication unit 902 is used to acquire external electricity market data; Processing unit 901 is used to parse external power market data into a standard format recognizable by the core functional layer, remove abnormal data, and cache it along with local data in the data cache module; the processor runs the local decision engine, combining preprocessed data and embedded trading strategies to generate a trading decision scheme adapted to the trading scenario; the risk control module calls the risk control rule set to calculate the risk indicators of the decision scheme; if the limits are not exceeded, the scheme passes verification; if the limits are exceeded, automatic downgrading, manual approval, or direct interception is executed; when manual approval is executed, the terminal's display interface connects to an external display device to display the details of the decision scheme and the corresponding risk analysis data for on-site personnel to view and complete the approval operation; the transaction status monitoring module tracks the execution status of verified declaration instructions, and simultaneously displays the execution progress and transaction results of the declaration instructions in real time on the external display device; if an anomaly occurs, information is recorded, alarms are triggered, and pop-up prompts are displayed on the external display device; the log audit system records the entire process data and encrypts it to prevent tampering, automatically generates transaction settlement reports and risk analysis reports, and displays the reports and report content on the external display device, supporting on-site personnel to view or export them.

[0092] In one possible implementation, the processing unit 901 is also used to provide a dual communication security scheme to ensure communication security when acquiring external power market data. The dual communication security scheme includes a one-way network gateway hardware scheme and a software encrypted communication scheme. The one-way network gateway hardware scheme constructs a physical isolation barrier by connecting to a one-way security gateway, allowing only external data sources to transmit data to the system and preventing any sensitive information from flowing out. The software encrypted communication scheme completes two-way authentication between the terminal and the external data source based on the PKI / CA digital certificate system, allowing only trusted entities to establish a communication session, and exchanging session keys through an asymmetric encryption algorithm to build a high-strength encrypted channel.

[0093] In one possible implementation, the method further includes device management and remote operation and maintenance, which includes: real-time monitoring of terminal hardware resource status and software module operation; triggering alarms on the local interactive interface and implementing protection measures when device malfunctions are detected; establishing a remote connection via an encrypted VPN or dedicated operation and maintenance line; remotely performing terminal diagnostics, log collection, parameter configuration, and software update operations after authentication, with all remote operations generating audit logs; importing the parameters of the new strategy or model to be deployed into the terminal sandbox environment, simulating operation using historical transaction data or simulation data, and evaluating strategy performance and risk indicators; displaying deployment instructions on the display device after the new strategy or model passes the sandbox test; recording all remote operation and maintenance operations and encrypting and storing the logs; and pushing alarm information to the security management platform when unauthorized access occurs.

[0094] The processing unit 901 can be a processor or a controller, and the communication unit 902 can be a communication interface, transceiver, transceiver circuit, transceiver device, etc. The term "communication interface" is a general term and may include one or more interfaces. The storage unit 903 can be a memory. When the integrated hardware and software intelligent terminal power trading device 90 is a chip, the processing unit 901 can be a processor or a controller, and the communication unit 902 can be an input interface and / or an output interface, pins, or circuits, etc. The storage unit 903 can be a storage unit within the chip (e.g., a register, cache, etc.) or a storage unit located outside the chip (e.g., read-only memory (ROM), random access memory (RAM, etc.).

[0095] The communication unit can also be called a transceiver unit. The antenna and control circuit with transceiver functions in the integrated hardware and software intelligent terminal power trading device 90 can be considered as the communication unit 902 of the integrated hardware and software intelligent terminal power trading device 90, and the processor with processing functions can be considered as the processing unit 901 of the integrated hardware and software intelligent terminal power trading device 90. Optionally, the device in the communication unit 902 that implements the receiving function can be considered as the communication unit. The communication unit is used to execute the receiving steps in the embodiments of this application, and the communication unit can be a receiver, a receiver circuit, etc. The device in the communication unit 902 that implements the transmitting function can be considered as the transmitting unit. The transmitting unit is used to execute the transmitting steps in the embodiments of this application, and the transmitting unit can be a transmitter, a transmitter, a transmitting circuit, etc.

[0096] Figure 9 If the integrated units in the process are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, in essence, or the parts that contribute to the prior art, or all or part of the technical solutions, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. Storage media for storing computer software products include various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0097] Figure 9 The units in the process can also be called modules; for example, a processing unit can be called a processing module.

[0098] This application also provides a hardware structure diagram of an integrated hardware and software smart terminal power trading device (referred to as integrated hardware and software smart terminal power trading device 100), see [link to diagram]. Figure 10 The integrated hardware and software smart terminal power trading device 100 includes a processor 1001, and optionally, a memory 1002 connected to the processor 1001.

[0099] In the first possible implementation, see Figure 10The integrated hardware and software intelligent terminal power trading device 100 also includes a transceiver 1003. The processor 1001, memory 1002, and transceiver 1003 are connected via a bus. The transceiver 1003 is used to communicate with other devices or communication networks. Optionally, the transceiver 1003 may include a transmitter and a receiver. The device in the transceiver 1003 that implements the receiving function can be considered as a receiver, which is used to perform the receiving steps in the embodiments of this application. The device in the transceiver 1003 that implements the transmitting function can be considered as a transmitter, which is used to perform the transmitting steps in the embodiments of this application.

[0100] Based on the first possible implementation method Figure 10 The structural diagram shown can be used to illustrate the structure of the integrated hardware and software smart terminal power trading device involved in the above embodiments.

[0101] in, Figure 10 This can also be illustrated by the system chip in an integrated hardware and software smart terminal power trading device. In this case, the actions performed by the aforementioned integrated hardware and software smart terminal power trading device can be implemented by this system chip. The specific actions performed can be found above and will not be repeated here.

[0102] In implementation, each step of the method provided in this embodiment can be completed by integrated logic circuits in the processor or by instructions in software form. The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules in the processor.

[0103] The processor in this application may include, but is not limited to, at least one of the following: a central processing unit (CPU), a microprocessor, a digital signal processor (DSP), a microcontroller unit (MCU), or an artificial intelligence processor, etc., which are various computing devices that run software. Each computing device may include one or more cores for executing software instructions to perform calculations or processing. The processor may be a standalone semiconductor chip or integrated with other circuits into a single semiconductor chip. For example, it may form a System-on-a-Chip (SoC) with other circuits (such as encoding / decoding circuits, hardware acceleration circuits, or various bus and interface circuits), or it may be integrated as a built-in processor within an ASIC. The ASIC with the integrated processor may be packaged separately or together with other circuits. In addition to the cores for executing software instructions to perform calculations or processing, the processor may further include necessary hardware accelerators, such as field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), or logic circuits that implement dedicated logic operations.

[0104] The memory in the embodiments of this application may include at least one of the following types: read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions; random access memory (RAM) or other types of dynamic storage devices capable of storing information and instructions; or electrically erasable programmable-only memory (EEPROM). In some scenarios, the memory may also be a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto.

[0105] This application also provides a computer-readable storage medium including instructions that, when run on a computer, cause the computer to perform any of the methods described above.

[0106] This application also provides a computer program product containing instructions that, when run on a computer, cause the computer to perform any of the methods described above.

[0107] This application also provides a chip including a processor and an interface circuit. The interface circuit is coupled to the processor. The processor is used to run computer programs or instructions to implement the above-described method. The interface circuit is used to communicate with other modules outside the chip.

[0108] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks (SSDs)).

[0109] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, the disclosure, and the appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple components. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.

[0110] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the spirit and scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.

Claims

1. A hardware and software integrated intelligent terminal power trading system, characterized in that, The system includes: hardware architecture and software functional modules; The hardware architecture includes: a processor, redundant power supply, storage device, network interface, security encryption chip, and display interface; The processor is used to undertake local high-intensity computing tasks; the computing tasks include receiving and processing data related to power trading, calculating electricity price and load forecasting models, calculating trading decision schemes, and assessing risk indicators. The redundant power supply is used to ensure uninterrupted system operation and to provide power in the event of a main power failure or abnormality. The storage device is used to store the local database and model repository; The network interface includes an internal network interface and an external network interface; the internal network interface is used to connect to the company's internal business network; the external network interface is used to connect to external data or remote operation and maintenance channels. The security encryption chip is used to store the system key and perform encryption and decryption operations; The display interface is used to connect the display device and the input device; The software functional modules include: a core functional layer, an interface layer, and a security layer; The core functional layer is responsible for the processing and control of the entire power trading process. The interface layer is used for standardized and orderly external data interaction; The security layer is used to protect terminal security from multiple dimensions, including communication, transactions, data, and operation and maintenance.

2. The system according to claim 1, characterized in that, The core functional layer includes: a local decision engine, a risk control module, a model repository, and a data caching module; The local decision engine is used to generate trading decision schemes by utilizing embedded trading strategies and optimization algorithms, combined with real-time market data and local load / generation information, and supports customized strategy configuration. The risk control module is used to monitor risk indicators in the transaction decision-making process in real time, execute a preset set of risk control rules, and intercept or alert on abnormal situations. The model repository is used to store algorithm models and parameter configurations related to power trading; The data caching module is used to store and cache business data, including historical transaction data, market data, customer load and power generation data.

3. The system according to claim 1, characterized in that, The interface layer includes: an external data interface and a screen interaction system; The external data interface is used to acquire external electricity market data and convert the external electricity market data into a standard format usable internally; the communication process for acquiring external electricity market data is compatible with HTTP / HTTPS, WebSocket, and MQTT protocol types. The screen interaction system is used to provide a visual human-computer interface and support multi-user hierarchical operation.

4. The system according to claim 1, characterized in that, The security layer includes: a communication encryption module, a transaction status monitoring module, and a log auditing system; The communication encryption module includes a one-way security gateway submodule and a software encryption submodule. The one-way security gateway submodule is used to ensure that data flows from the outside to the internal terminal and to refuse any internal information from returning to the outside. The software encryption submodule is used to perform two-way identity authentication between the terminal and the external data source based on the PKI / CA digital certificate system, and at the same time exchange session keys through asymmetric encryption algorithms to build a high-strength encryption channel. The transaction status monitoring module is used to continuously monitor the status of each stage of the transaction process. If an abnormality occurs, it records a detailed log and triggers a warning. The log auditing system is used to encrypt detailed log data throughout the entire process using chained hash storage technology.

5. The system according to claim 2, characterized in that, The data caching module can also provide historical cached data for the local decision engine and the model repository when the external network is interrupted.

6. The system according to claim 4, characterized in that, The one-way security gateway submodule and the software encryption submodule are not mutually exclusive. The one-way security gateway submodule can be deployed at the network boundary to build a one-way data transmission channel, and the encrypted data stream processed by the software encryption submodule can be carried in the one-way data transmission channel.

7. The system according to claim 4, characterized in that, The high-strength encrypted channel adopts the TLS 1.3 protocol, and requires external data sources to attach timestamps and sequence numbers to critical business data.

8. A hardware and software integrated intelligent terminal power trading method, characterized in that, The method includes: Obtain external electricity market data through external data interfaces; The external power market data is parsed into a standard format recognizable by the core functional layer. After removing abnormal data, it is cached together with the local data in the data cache module. The processor runs a local decision engine, which combines preprocessed data and embedded trading strategies to generate trading decision solutions adapted to the trading scenario. The risk control module calls the risk control rule set to calculate the risk indicators of the decision-making plan. If the risk indicators do not exceed the limits, the plan passes the verification. If the limits are exceeded, the plan will be automatically downgraded, manually approved, or directly blocked. When performing the manual approval, an external display device is connected through the terminal's display interface to display the details of the decision-making scheme and the corresponding risk analysis data, so that on-site personnel can view and complete the approval operation; The transaction status monitoring module tracks the execution status of verified declaration instructions, and displays the execution progress and transaction results of the declaration instructions in real time through an external display device. If any abnormality occurs, the information is recorded, an alarm is triggered, and a pop-up notification is displayed on the external display device. The log auditing system records all process data and encrypts it to prevent tampering. It automatically generates transaction settlement reports and risk analysis reports, and displays the reports and content through external display devices, allowing on-site personnel to view or export them.

9. The method according to claim 8, characterized in that, The system provides a dual communication security solution to ensure communication security when acquiring external power market data. This dual security solution includes a one-way network gateway hardware solution and a software encrypted communication solution. The one-way network gateway hardware solution constructs a physical isolation barrier by connecting to a one-way security gateway, allowing only external data sources to transmit data into the system and preventing any sensitive internal information from leaking out. The software encrypted communication solution completes two-way authentication between the terminal and the external data source based on the PKI / CA digital certificate system, allowing only trusted entities to establish communication sessions. It also exchanges session keys through an asymmetric encryption algorithm to build a high-strength encrypted channel.

10. The method according to claim 8, characterized in that, The method also includes equipment management and remote operation and maintenance, which includes: The system monitors the terminal hardware resource status and software module operation in real time. When an abnormal device operation is detected, an alarm is triggered on the local interactive interface, and protective measures are executed. The abnormal device operation includes hardware abnormalities and software abnormalities. Hardware abnormalities include processor utilization exceeding limits, redundant power supply switching failure, network interface interruption, and storage device read / write errors. Software abnormalities include module crashes and policy rule loading failures. Protective measures include forced switching of redundant power supplies, restarting of faulty network interfaces, automatic restart of faulty processes, policy rollback to a usable version, and persistent storage of cached data. A remote connection is established via an encrypted VPN or dedicated maintenance line. After identity authentication, terminal diagnostics, log collection, parameter configuration, and software update operations are performed remotely, and all remote operations generate audit logs. The parameters of the new strategy or model to be deployed are imported into the terminal sandbox environment, and the strategy is simulated and run using historical transaction data or simulation data to evaluate the strategy performance and risk indicators. After the new strategy or model passes the sandbox test, the deployment instruction is displayed on the display device. The deployment instruction is used to deploy the new strategy or model to the terminal production environment after confirmation by on-site personnel. Record all remote operation and maintenance operations and store the logs in encrypted form; when unauthorized access occurs, push alarm information to the security management platform.

Citation Information

Patent Citations

  • Power supply station service architecture optimization method based on digital power grid construction achievement

    CN120654868A

  • Electric power spot market electric power transaction intelligent electricity price prediction and electric power dispatching system and method

    CN120851931A

  • Power transaction agent system based on AI auxiliary decision-making

    CN120894133A

  • Urban virtual power plant operation method and device based on agent architecture

    CN120930998A

Cited By

  • Network model configuration method, equipment and communication system

    CN121357026A

  • Relay protection tester safety system based on power gap system

    CN121479848A