Electric power metering network security protection system and electric quantity acquisition data encryption transmission protocol
By introducing technologies such as the SM7 security chip, data perturbation encryption, and the improved SM2-4P algorithm into the power metering network, a full-link security architecture is constructed, which solves the security and communication stability problems of the power metering network and achieves efficient and reliable data transmission.
Patent Information
- Application Number
- CN202511271212.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-12-12
AI Technical Summary
Existing power metering networks suffer from insufficient security levels in encryption algorithms, low key negotiation efficiency, lack of physical security protection, and poor communication stability, making it difficult to meet the comprehensive requirements of new power systems for high security, high real-time performance, and high reliability.
Employing technologies such as the SM7 security chip, multi-level boot chain, data perturbation encryption, power consumption perturbation injection, and physical disassembly detection, combined with the improved SM2-4P key negotiation algorithm and SM4-CBC data encryption, and combined with LSTM deep learning behavior modeling and Turbo error correction coding, a full-link security architecture is constructed.
It achieves trusted communication throughout the entire process, improves system security, encrypted communication efficiency and environmental adaptability, defends against various attacks, and ensures the reliability and real-time performance of data transmission.
Smart Images

Figure CN121125079A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power information security and communication encryption technology, and in particular to a power metering network security protection system suitable for smart grid environments, as well as an encrypted transmission protocol for power data acquisition used in conjunction with the system. Background Technology
[0002] With the rapid development of new power systems and smart grids, electricity metering, as a fundamental sensing link, is gradually evolving from traditional manual meter reading to an automated system integrating remote data acquisition, real-time communication, and centralized settlement. Modern electricity metering systems typically consist of terminal smart meters, data concentrators, edge communication devices, and a main station metering management platform, relying on wired or wireless communication links to achieve integrated "end-edge-cloud" electricity data interaction.
[0003] Currently, mainstream communication protocols in the industry include standards such as DL / T 645, DLMS / COSEM, and IEC 62351. These protocols typically employ symmetric encryption (such as AES and 3DES) or basic public-key mechanisms (such as RSA) for data protection and device authentication. However, with the increasing complexity of network attack methods and the penetration of attack scenarios into embedded devices, traditional power metering security architectures face numerous challenges, mainly in the following aspects:
[0004] First, the security level of the encryption algorithms is insufficient. Some protocols still use algorithms that are considered weak in the industry (such as MD5 and SHA1), or use static key encryption in resource-constrained devices, lacking a dynamic key update mechanism, making them extremely vulnerable to threats such as man-in-the-middle attacks, replay attacks, and offline brute-force attacks.
[0005] Secondly, the key exchange process is inefficient and has a high communication load. Typical RSA or ECC key negotiation protocols require multiple rounds of interaction when executed on embedded terminals, resulting in significant processing delays. This is especially true in remote areas, public wireless networks, or low-power wide-area networks (such as NB-IoT), often causing connection timeouts and authentication failures.
[0006] Secondly, terminal devices lack effective physical security protection mechanisms. Smart meters and concentrators are deployed on the user side for extended periods and are often unmonitored, making them vulnerable to becoming physical entry points for attackers. Traditional designs do not harden against side-channel attacks (such as power consumption analysis and electromagnetic leakage) or include disassembly detection or secure erasure mechanisms, posing a risk of key leakage.
[0007] Furthermore, existing systems lack anomaly detection capabilities based on behavioral modeling. Most security protocols employ static configuration, making it impossible to detect and respond to abnormal network behavior. In particular, when encountering abnormal behaviors such as DDoS attacks, connection overload, and traffic replay, the system cannot dynamically limit traffic or block abnormal activity.
[0008] Finally, communication stability is insufficient in complex electromagnetic environments. Smart metering devices are widely deployed, often in mountainous areas, industrial and mining enterprises, microgrids, and other scenarios. In environments with low temperatures, strong interference, or low signal-to-noise ratios, traditional communication protocols lack adaptability, have fixed modulation methods, and limited error correction capabilities, which can easily lead to data frame loss and increased bit error rate, seriously affecting the accuracy and real-time performance of metering data.
[0009] In summary, existing power metering networks, under the "end-edge-master" architecture, generally suffer from weak encryption systems, outdated key management, lack of physical security, and poor communication stability, making it difficult to support the comprehensive requirements of new power systems for "high security, high real-time performance, and high reliability" on the metering side. Therefore, there is an urgent need for a new metering security protection system that integrates domestically developed cryptographic algorithms, physical protection mechanisms, dynamic behavior modeling, and environmental adaptability, along with a high-efficiency, low-latency, and authenticable power data encryption communication protocol to achieve end-to-end trusted assurance from equipment to platform. Summary of the Invention
[0010] To address the shortcomings of existing power metering systems in terms of encryption algorithm strength, key negotiation efficiency, physical security protection, and environmental adaptability, this invention proposes a technical solution with a complete security-in-depth architecture. This solution aims to achieve a trusted communication mechanism throughout the entire process, from data acquisition at the metering terminal and encrypted transmission to centralized verification on the main station platform. This solution not only fully integrates the compliance requirements of the National Commercial Cryptography System (SM series) in the power information field but also introduces several embeddable security enhancement measures, adapting to the new demands of the power industry for integrated secure operation of the "terminal-network-cloud" system. The following will elaborate on the system architecture, key module functions, and communication protocol mechanism proposed in this invention to clarify its technical implementation path and innovative points.
[0011] In one possible implementation, a power metering network security protection system is provided, including a metering terminal module, an edge gateway module, a master station platform module, and a supporting data encryption communication protocol stack, for realizing full-process security protection from data acquisition, encryption processing, remote transmission to centralized management.
[0012] In one possible implementation, the metering terminal module is deployed on the user's electricity consumption side, mainly used for collecting basic electrical parameters such as voltage, current, active power, and reactive power, and includes the following functional components:
[0013] Security Chip Unit: This chip is an SM7 security chip with support for national cryptographic algorithms. It is used to perform SM2 key exchange, SM4 encryption and decryption, SM3 digest and other algorithm operations. It also has anti-spyware encapsulation and physical tampering response mechanisms. The chip has an independent key storage area to store the master key and dynamic session key.
[0014] The secure boot chain mechanism employs a tiered verification process: first, BL0 is loaded from the hardware ROM; then, BL1 performs firmware signature verification; and finally, BL2 completes integrity verification and logical image verification. The entire boot process is completed within 300ms, ensuring that the terminal firmware is protected from unauthorized replacement threats.
[0015] Data perturbation encryption unit: This unit introduces linear perturbations into the measurement data.
[0016] V′=(a·V+b)mod(2 16 -1)
[0017] Where a is a floating-point coefficient with a value range of [1.2, 1.8], and b is a constant offset with a range of [0.3, 0.7]. This processing method is used to improve the robustness of the sampled data to the reconstruction algorithm and suppress replay attacks based on correlation.
[0018] Power consumption disturbance injection mechanism: When performing key decomposition or SM4 encryption operations, the built-in control module controls the power supply ripple to achieve ±15% voltage / current disturbance, which is used to disrupt the stability of the side channel power consumption curve and improve the resistance to SPA / DPA attacks.
[0019] Physical disassembly detection module: Integrates a 3-axis MEMS accelerometer and an ambient light sensor. When the device casing is opened or the displacement exceeds a threshold (e.g., ≥1.5g / 50ms), it triggers the safe zone erase logic within 50ms and interrupts all IO communication to prevent the chip from being subjected to "cold start extraction" attacks.
[0020] In one possible implementation, the system further includes an edge gateway module deployed on the transformer substation side, which has data relay and local encryption capabilities that are bound to metering terminals in a one-to-many manner, including:
[0021] The encryption processing module, built on Xilinx UltraScale FPGA, has a four-stage pipeline structure: key expansion, byte substitution, row shifting and column obfuscation, which conforms to the SM4 algorithm standard.
[0022] The system supports a minimum of 4 parallel data channels and a maximum of 8 parallel data channels, which can be used to encrypt data blocks of 64 bits or 128 bits in length at the same time, with a maximum throughput of 256KB per second.
[0023] The processing module combines the pipeline timing optimization configuration file to ensure that the critical path constraints are met, and the single-frame data processing latency does not exceed 50μs at a 64MHz main frequency;
[0024] The edge gateway has local caching capabilities, supporting caching of 1024 frames of encrypted power data, effectively alleviating short-term congestion pressure on the main station.
[0025] In one possible implementation, the main platform is deployed within a data center, providing secure data access services for the entire network, and possesses the following capabilities:
[0026] It can stably handle more than 100,000 concurrent encrypted connections per day and supports dual-stack authentication with TLS+SM encrypted channels;
[0027] Automated load balancing, horizontal scaling, and fault isolation are achieved through Kubernetes container cluster scheduling.
[0028] It has a Key Management System (KMS) for issuing master keys, public key certificates, and managing the key lifecycle, including mandatory key revocation, rotation, and renewal.
[0029] In one possible implementation, the communication protocol stack is a state machine-driven model, and the overall process is divided into six stages: time synchronization, key negotiation, data transmission, integrity verification, session maintenance, and anomaly detection.
[0030] Time synchronization phase: The metering terminal receives the BeiDou-3 B2a band time signal every 15 minutes and completes local time correction by combining it with the crystal oscillator drift model. The drift compensation model is as follows:
[0031]
[0032] Where α∈[10⁻⁹,10⁻⁸], β∈[10⁻¹³,10⁻¹²], and γ∈[1,5]μs, time synchronization accuracy at the ±50ns level can be achieved;
[0033] Key negotiation phase: The improved SM2-4P algorithm is used, which reduces the number of interaction rounds by about 40% compared with the traditional SM2 protocol. The SessionKey generated by combining the terminal number and timestamp has better anti-replay capability.
[0034] Data encryption stage: The power acquisition data frame (64 bytes) is encrypted and encapsulated using the SM4-CBC algorithm. The frame structure is as follows: Header (8B) + Payload (64B) + MAC check (16B);
[0035] Integrity verification phase: The main platform performs SM3 hash verification on the MAC field to ensure that the data has not been tampered with during transmission;
[0036] Anomaly detection phase: The main station platform uses an LSTM deep learning model, combined with a 120s sliding window, to construct a communication behavior graph, and introduces the following rate limiting function to dynamically adjust bandwidth:
[0037] B(t) = B0·e -λt +∑w i ·f(t-τ i )
[0038] Where λ = 0.05, w i ∈[0.8,1.2], f is the basis function within the sliding window.
[0039] In one possible implementation, the system has strong environmental adaptability, with the bit error rate controlled within 10⁻⁹ in a wide temperature range of -40℃ to 85℃ and a 6dB SNR communication channel; with the help of Turbo error correction coding and dynamic switching of QPSK / 16QAM / 64QAM modulation, it can maintain a communication success rate of over 99.3% even in high-noise electromagnetic environments such as mountainous areas and industrial mines.
[0040] Based on the above technical solutions, the power metering network security protection system and power acquisition data encryption transmission protocol proposed in this invention address the current smart grid development's demand for high security, low latency, and high reliability data communication. It constructs an overall security architecture covering a three-tier structure of terminals, edge, and master stations, and achieves innovative technological breakthroughs in several key areas. Its specific advantages are reflected in the following five dimensions:
[0041] I. Enhanced System Security Across the Entire Chain
[0042] This invention embeds the SM7 commercial cryptographic security chip on the metering terminal side, combined with a multi-level boot chain (BL0–BL2), side-channel power consumption disturbance, and abnormal disassembly detection mechanism, to achieve a trusted execution chain throughout the entire process from device startup, data acquisition, encryption encapsulation to physical protection, effectively defending against the following attack paths:
[0043] Risks of firmware tampering and malicious loading;
[0044] Side-channel attacks such as electromagnetic analysis (EM) and power analysis (DPA);
[0045] Physical intrusion behavior involving disassembling the device to extract the key.
[0046] The system's built-in emergency key erasure logic and secure I / O interrupt response mechanism ensure that information leakage paths can be quickly blocked in the event of a physical intrusion, significantly enhancing the device-level proactive security capabilities.
[0047] II. The encrypted communication protocol provides both high efficiency and high strength.
[0048] The encrypted transmission protocol used in this invention is based on the improved SM2-4P key negotiation algorithm and the SM4-CBC data encryption method, and has the following advantages compared with the existing IEC 62351 protocol:
[0049] Key negotiation latency is reduced by more than 40%, making it suitable for resource-constrained embedded devices;
[0050] The simplified encrypted frame structure (Header+Payload+MAC) effectively controls bandwidth overhead, with an average single-frame encapsulation latency of less than 28μs.
[0051] By combining BeiDou time synchronization with a time drift compensation model, the Session Key and data timestamp are strictly matched, with a synchronization accuracy of ±50ns, which greatly reduces the risk of key failure or replay due to time inconsistency.
[0052] The protocol adopts a state machine-driven architecture, which has strong logic partitioning and process rollback capabilities, and is suitable for deployment environments of power metering systems with multiple terminals and complex topologies.
[0053] III. Systematized Enhancement of Anti-Attack Capabilities
[0054] This invention introduces an LSTM deep learning behavior modeling mechanism on the main station platform side, which can analyze communication behavior characteristics within 120 seconds in real time. Combined with a dynamic sliding window rate limiting function, it achieves intelligent defense against security events such as DDoS attacks, connection flooding, and replay anomalies. Specifically, it is manifested as follows:
[0055] Anomaly detection accuracy is ≥92%, and it has a good identification effect on atypical attacks;
[0056] Even when faced with a 1Gbps traffic flood attack, the system's service throughput can still maintain more than 85%.
[0057] The protocol supports an automatic key renegotiation mechanism every 30 minutes, enabling closed-loop control of the key lifecycle and effectively preventing data eavesdropping risks caused by long-term key expiration.
[0058] By using a master-edge-end collaborative security modeling and response, a layered defense capability is formed, breaking through the passive response strategy of traditional power metering systems.
[0059] IV. Environmental adaptability is superior to existing technologies.
[0060] This invention combines a Turbo code error correction mechanism with a QPSK / 16QAM / 64QAM adaptive modulation strategy to ensure that the system still has reliable communication capabilities under the following extreme scenarios:
[0061] In industrial wide-temperature environments (-40℃~85℃), the link bit error rate is ≤10⁻⁹;
[0062] Under high noise interference (SNR=6dB) conditions, the bit error rate is ≤10-6, and the communication success rate reaches 99.3%;
[0063] For deployment environments such as mountain power grids, residential photovoltaic microgrids, and remote isolated distribution areas, the system can automatically adjust the encryption rate and frequency response to improve network robustness.
[0064] In addition, the edge gateway design features cache latency recovery and local encryption capabilities, which can continue to ensure local secure communication and improve system resilience even when the main station is disconnected.
[0065] V. Balancing Architectural Generality and Engineering Implementability
[0066] The system of this invention fully considers the existing equipment systems of the State Grid and Southern Power Grid, and supports the following typical terminal and system scenarios:
[0067] Single-phase electricity meters, three-phase electricity meters, concentrator terminals;
[0068] ARM or FPGA platform for edge nodes in the distribution area;
[0069] The main site is deployed with both Kubernetes cloud clusters and traditional servers.
[0070] The system design is compatible with the national cryptographic algorithm standard system (SM2 / 3 / 4 / 9) and meets the State Grid's data security compliance requirements. At the same time, the protocol design is lightweight, the modules are detachable, and the interface is highly standardized, which is conducive to seamless embedding into existing AMI systems and realizes a smooth transition from traditional communication links to high-security links.
[0071] In summary, this invention, through the construction of a multi-level security system consisting of "system-level structural protection + protocol-level transmission encryption + chip-level active security + platform-level behavioral modeling," fundamentally improves the operational security, response efficiency, and practical adaptability of power metering systems in intelligent, electrified, and highly reliable network environments, and possesses promising industrial application prospects and promotional value. Attached Figure Description
[0072] Figure 1 Architecture diagram of the power metering network security protection system
[0073] The attached diagram illustrates the three-tier architecture of a power metering network security protection system: metering terminal, edge gateway, and main station platform. The function of each module is as follows:
[0074] Metering terminal module: Responsible for collecting electricity data and performing data encryption and key protection through an embedded SM7 security chip. This module also includes security mechanisms to prevent side-channel attacks and physical tampering.
[0075] Edge gateway module: Deployed on the station side, it is responsible for relaying and caching encrypted data to ensure the secure transmission of encrypted data.
[0076] Main platform module: Responsible for receiving and verifying encrypted data, and performing anomaly detection and dynamic key updates.
[0077] Figure 2 Security mechanisms and data encryption processes for metering terminals
[0078] This attached diagram illustrates in detail how the metering terminal protects electrical energy data through multiple security mechanisms:
[0079] Data perturbation encryption unit: The collected power data is first perturbed by a linear perturbation encryption algorithm (using a∈[1.2,1.8], b∈[0.3,0.7]) to enhance the ability to resist reconstruction attacks.
[0080] Power consumption perturbation injection mechanism: During the encryption process, the system enhances its resistance to side-channel attacks by perturbing the power supply current with noise.
[0081] Physical disassembly detection module: It monitors whether the device has been disassembled in real time through acceleration sensors and ambient light sensors. Once an abnormality is detected, it immediately triggers an emergency erasure mechanism.
[0082] Figure 3 Data Encryption Communication Protocol Flowchart
[0083] The attached diagram illustrates the complete process of the encrypted transmission protocol for power acquisition data:
[0084] 1. Time synchronization: The terminal synchronizes its time with the BeiDou-3 B2a signal to ensure time accuracy during data transmission.
[0085] 2. Key exchange: By using the improved SM2-4P algorithm, the number of key negotiation rounds is reduced, thus improving efficiency.
[0086] 3. Encrypted data transmission: Data is encrypted using the SM4-CBC algorithm, and a data frame containing an 8-byte header, a 64-byte payload, and a 16-byte MAC checksum field is generated.
[0087] 4. Integrity verification: The main platform verifies the MAC value of the data frame to ensure that the data has not been tampered with.
[0088] 5. Anomaly detection and flow control: Analyze communication behavior using an LSTM model and dynamically adjust bandwidth and flow based on the detection results. Detailed Implementation
[0089] To ensure a clearer and more complete understanding of the technical solution of this invention, the following detailed description, in conjunction with the structural composition and functional flow of this invention and referencing typical application scenarios, will describe its possible specific implementation methods. This embodiment is not intended to limit the invention, but rather, under the premise of conforming to the core concept of this invention, describes the collaborative relationships between modules, data interaction logic, and key algorithm processing flow from an engineering feasibility perspective, thereby enabling those skilled in the art to deploy, debug, and optimize accordingly. Furthermore, it should be understood that the specific embodiments of this invention can be flexibly modified according to different application requirements, and any solution that uses the same or similar technical means to achieve the same functional effect should be considered to fall within the protection scope of this invention.
[0090] like Figure 1 As shown, this invention proposes a network security protection system for power metering and the encrypted transmission protocol for power collection data used therein. The system adopts a three-layer logical architecture of "metering terminal - edge gateway - main station platform" to achieve full-process security control from bottom-level data collection, local encrypted relay to the central platform, and adapts to the current development trend of multi-point deployment, multi-source communication and coexistence of heterogeneous terminals in smart grids.
[0091] like Figure 2 As shown, in the embodiment of this invention, a metering terminal with security functions is first deployed on the user side. This terminal can be a single-phase smart meter, a three-phase smart meter, or a data concentrator, depending on the on-site power consumption and data access method. The metering terminal integrates a domestically produced commercial cryptographic chip (such as SM7) supporting SM2, SM3, and SM4 algorithms for local data encryption and key protection. The terminal system startup process employs a three-level secure startup chain, including ROM booting at the BL0 stage, firmware signature verification at the BL1 stage, and an integrity verification mechanism at the BL2 stage, effectively preventing the loading and execution of unauthorized firmware. The total response time of this startup chain is controlled within 300 milliseconds, ensuring rapid startup while maintaining a trusted foundation.
[0092] Regarding power data acquisition, the terminal obtains analog signals such as voltage and current through an A / D converter, and generates power parameters after sampling and filtering. To prevent passive sampling reconstruction attacks, the acquired data undergoes a linear transformation process by a perturbation module before entering the encryption channel. The mathematical model is as follows:
[0093] V′=(a·V+b)mod(2 16 -1)
[0094] Where 'a' is the floating-point multiplication factor, limited to the range [1.2, 1.8]; and 'b' is the additive offset, ranging from [0.3, 0.7]. This perturbation model not only introduces data variability but also improves the nonlinear distribution characteristics of the encrypted data, helping to enhance its resistance to sampling and reverse engineering. Subsequently, the perturbed data is encrypted using the SM4-CBC mode, with the key negotiated with the master platform via the SM2-4P protocol and stored within the controlled area of the security chip.
[0095] To prevent side-channel attacks, this invention further incorporates a power consumption perturbation injection module. During the execution of critical encryption instructions, this module actively applies ±15% power noise perturbation to the power supply system, thereby interfering with the power consumption characteristic identification process of traditional DPA (Differential Power Analysis) attacks. These perturbation parameters are dynamically generated by an internal true random number module, ensuring that the power consumption curve for each encryption operation is unpredictable. Furthermore, to prevent physical disassembly and cold / hot start attacks, the terminal is equipped with a triaxial accelerometer and an ambient light sensor to monitor device displacement and sudden changes in illumination in real time. Once an unauthorized power-on is detected, an emergency key erasure procedure will be triggered within 50 milliseconds, interrupting all external interface communication. This emergency handling function is implemented through an internal FLASH erasure instruction, with the specific implementation logic as follows:
[0096]
[0097] The acquired data is transmitted to the edge gateway on the distribution station side via communication methods such as UART, RS485, PLC, or NB-IoT. The edge gateway is used for data relay, local encryption buffering, and communication scheduling. Its core is an encryption pipeline structure implemented based on Xilinx UltraScale series FPGAs. This structure includes a key expansion module, a byte replacement module, a row shifting module, and a column obfuscation module, adhering to the national standard SM4 algorithm and meeting high-speed processing requirements through multi-clock domain isolation and timing constraints. In actual deployment, the edge encryption channel can handle 4 to 8 concurrent channels, each supporting concurrent encryption of 64-bit or 128-bit data blocks, with a single-frame encryption latency of no more than 50 microseconds. Through the FPGA's cache management module, the gateway can cache no less than 1024 frames of data, ensuring secure local data storage and subsequent retransmission even in scenarios of brief disconnection from the main station.
[0098] The main platform is typically deployed in the data centers of provincial or municipal power companies, running on a Kubernetes cloud-native platform. The platform possesses large-scale encrypted connection scheduling capabilities, supporting concurrent communication requests from over 100,000 terminals. Internally, the main platform includes a session management module and a key rotation module, which update the SessionKey for all active terminals every 30 minutes, and employ a time synchronization mechanism to ensure key consistency. The synchronization signal originates from the BeiDou-3 B2a band navigation signal, periodically captured by the terminal demodulator and drift corrected using an internal temperature-compensated crystal oscillator. The platform also embeds an integrity verification module; received data frames must pass MAC value verification calculated by SM3 before being connected to the business system.
[0099] To address network security threats such as Distributed Denial-of-Service (DDoS) attacks, local abnormal packet flushing, and long-lived connection exhaustion, this invention integrates an abnormal behavior detection module based on LSTM (Long Short-Time Memory) architecture. This module uses communication behavior over the past 120 seconds as a sliding window, extracting multiple time-series features such as packet interval, connection failure rate, and data length changes to perform model judgment and output an anomaly score. Combined with this model, the platform can invoke dynamic rate limiting strategies in real time, adjusting bandwidth resources for each link according to the following formula:
[0100] B(t) = B0·e -λt +∑w i ·f(t-τ i )
[0101] Where B0 is the initial bandwidth threshold, λ is the attenuation coefficient (recommended value 0.05), and w i The historical window weights are defined, and the function f is a weighted activation function constructed based on anomaly scoring. The platform's response mechanism includes rate limiting, disconnection, blacklisting, and policy distribution.
[0102] The adaptability of the system to extreme environmental conditions has also been fully verified. Under a wide temperature range of -40℃ to +85℃, the communication module maintains a bit error rate of less than 10⁻⁹. At a signal-to-noise ratio of 6dB, combined with Turbo error correction coding and a QPSK / 16QAM / 64QAM three-mode modulation switching mechanism, the data bit error rate can be kept below 10⁻⁶, and the overall communication success rate reaches over 99.3%, making it suitable for diverse deployment environments such as mountainous areas, distributed photovoltaic systems, and microgrids.
[0103] In summary, this embodiment provides an integrated security system encompassing terminal data acquisition, physical security protection, encrypted link transmission, and master station key management and anomaly detection. This system not only boasts high engineering feasibility but also supports rapid deployment and standardized expansion, demonstrating significant potential for industrial adoption.
[0104] Application Example 1: Application of Smart Meters in Urban Distribution Networks under Large-Scale Concurrent Meter Reading Environment
[0105] In this embodiment, the system of the present invention is deployed in a residential community of a large urban power distribution network. The goal is to replace the communication link with security vulnerabilities in the original concentrator-meter architecture and realize unified encrypted access and remote meter reading management for 5,000 smart meter terminals.
[0106] like Figure 3 As shown, in actual deployment, each household installs a three-phase smart meter integrating the technical solution of this invention as a metering terminal. This meter embeds an SM7 security chip and completes system security boot through the three-level boot chain mechanism (BL0→BL1→BL2) provided by this invention, ensuring firmware legitimacy. During the electrical parameter acquisition cycle of once per second, the terminal collects information such as voltage, current, and active power, first performs linear perturbation preprocessing through the perturbation encryption module, and then calls the SM4-CBC algorithm to complete data encryption.
[0107] The community uses fiber optic communication to aggregate all terminal data to an edge gateway node equipped with an FPGA module. This gateway is built on Xilinx UltraScale series chips and can process ≥2000 frames of 64-byte data per second in parallel. It also provides buffer redundancy and encrypted relay functions in the local network, effectively reducing the risk of communication congestion during peak meter reading periods.
[0108] The main platform runs in the municipal power bureau's cloud data center, deployed in a Kubernetes container cluster, and employs an LSTM anomaly detection model and a dynamic key update mechanism. The platform automatically rotates all session keys every 30 minutes and coordinates terminal clocks based on the BeiDou time synchronization mechanism to maintain data timestamp consistency.
[0109] In this scenario, the statistical results of the system's actual operation for 30 days show that:
[0110] The average encryption response time is 27.8 μs;
[0111] The overall meter reading success rate has increased to 99.97%;
[0112] The main site's average concurrent processing capacity is stable at 106,000 sessions / hour;
[0113] No data replay or illegal instruction injection incidents occurred.
[0114] This embodiment verifies the high concurrency carrying capacity and information security assurance capability of the system of the present invention under the condition of dense urban network deployment.
[0115] Application Example 2: Encrypted Access Application of Smart Metering in Microgrids in Remote Mountainous Areas
[0116] In this embodiment, the present invention is applied to an off-grid microgrid environment in a mountainous township. Due to the long distances, high altitudes, and cold climate, conventional communication equipment in this region is susceptible to interference and physical damage. The objective is to deploy a smart metering and communication system with high environmental adaptability, low power consumption, and resistance to physical intrusion for 40 residential photovoltaic users in the region.
[0117] To adapt to extreme environments, each household is equipped with a low-power single-phase smart meter supported by this invention. This meter features a rugged industrial casing, is capable of operating at temperatures ranging from -40℃ to +85℃, and incorporates a temperature-compensated crystal oscillator and an SM7 security chip. On the terminal side, it uses the BeiDou B2a satellite frequency band to receive timing signals, achieving ±50ns time synchronization through a time drift compensation model. Simultaneously, a power disturbance module and a self-destruct mechanism protect the security of critical key areas.
[0118] Due to weak public network signals, this system uses NB-IoT communication for data upload. Considering the instability of wireless links, the system allows terminals to cache 8 hours of data and is configured to initiate redundant encrypted backup when a relay failure lasts for more than 20 minutes.
[0119] The main platform is located in the provincial company's data center and configured with specific scheduling strategies and model parameters to adapt to the high latency and uncertain link conditions in rural communications. During this deployment, the platform used a dynamic rate limiting algorithm to cope with the short-term "packet-rushing storm" caused by the abnormal and concentrated recovery of communications after the snow disaster, ensuring that the main station was not overwhelmed by malicious requests.
[0120] The results of the operation show that:
[0121] Even at a minimum temperature of -28℃, the average communication success rate of the terminal remained at 98.4%.
[0122] In harsh electromagnetic environments with a signal-to-noise ratio of 6dB, the system bit error rate remains below 10⁻⁶.
[0123] When encountering a sudden base station backhaul anomaly, the platform's DDoS flow control module triggers a bandwidth suppression mechanism within 3 seconds, restoring CPU utilization to below normal load.
[0124] All terminals can complete key erasure and communication disconnection within 50ms when their casing is removed or exposed to strong light.
[0125] This embodiment fully demonstrates the robustness, security, and remote maintainability of the present invention under high interference, extreme climate, and low bandwidth environments, and verifies the high adaptability of the present invention to the fields of new rural power systems and distributed energy metering.
[0126] In summary, the power metering network security protection system and power data encryption transmission protocol proposed in this invention are based on a three-tier architecture of "terminal-edge-master station," integrating domestically produced commercial cryptographic algorithms, security chips, physical protection mechanisms, and intelligent traffic control models. This constructs a complete, autonomous, and controllable power metering security protection system from the underlying hardware and communication protocols to platform services. This system not only effectively solves the technical bottlenecks of existing power metering systems, such as insufficient encryption algorithm strength, lack of physical security protection, low key negotiation efficiency, and poor adaptability to communication environments, but also possesses good scalability and engineering implementation capabilities, enabling it to be widely adapted to typical application scenarios such as smart grids, distributed energy management, and new microgrids. Through the promotion and implementation of this invention, the security level and operational reliability of my country's power information infrastructure can be significantly improved, providing solid security support for the country's digital energy transformation.
[0127] It should be understood that the above description of the embodiments of the present invention is intended to help those skilled in the art better understand the technical solutions of the present invention and to enable them to implement the present invention, and is not intended to limit the scope of protection of the present invention. For those skilled in the art, various equivalent substitutions or improvements can be made to the technical solutions without departing from the spirit and essence of the present invention, and all such substitutions or improvements should be covered within the scope of protection claimed by the present invention. In particular, any other communication protocol variants, security chip packaging schemes, edge processing structures, or anomaly detection algorithm combinations developed based on the concept of the present invention, as long as their technical effects are equivalent or similar, should be considered to fall within the scope of protection of the present invention.
Claims
1. A power metering network security protection system, characterized by, Comprise: Meter terminal module for collecting electric energy data, and integrated with: Security chip (SM7) for implementing encryption and decryption operations and key storage; Boot chain module including BL0, BL1 and BL2 three-level boot logic, the startup delay is not more than 300 ms, and BL2 has integrity verification function; Data perturbation encryption unit adopts linear transformation perturbation encryption algorithm V' = (a-V + b) mod (2 16 -1) Wherein, a∈[1.2, 1.8], b∈[0.3, 0.7], for enhancing the ability of anti-sampling reconstruction attack; Power consumption perturbation unit injects ±15% power supply current noise during each encryption operation, for defending side channel attack; Edge gateway module is deployed at the transformer area side, and has: FPGA encryption processor based on Xilinx UltraScale architecture, which contains four-level pipeline modules of key expansion, byte substitution, row shift and column confusion in the interior; Parallel encryption channel ≥4 ways, supporting 64bit-128bit data block concurrent processing, single frame processing delay ≤50μs; Master station platform module for centralized receiving and verifying encrypted data, and issuing security policy, having concurrent encryption processing capacity supporting ≥100,000 sessions; Communication protocol stack contains state machine driven process, and the communication process includes: a. Time synchronization: terminal performs clock correction based on Beidou No.3 B2a signal every 15 minutes, and the drift error is not more than ±50 ns; b. Key exchange: SM2-4P improved algorithm is adopted, negotiation process round ≤2 rounds, and Session Key is generated for symmetric encryption; c. Data encryption transmission: SM4-CBC algorithm is used, and the data frame structure includes 8-byte header, 64-byte payload and 16-byte MAC check field; d. Integrity verification: consistency check is performed on received data based on MAC code; Abnormal detection module analyzes communication behavior in the past 120 s based on LSTM neural network model at the master station platform, the abnormal identification accuracy is ≥92%, and the downlink bandwidth flow is controlled in combination with dynamic flow limiting algorithm.
2. The system of claim 1, wherein, The security chip supports SM2, SM3, SM4 and SM9 series national secret algorithms, and the key length is 256 bits.
3. The system of claim 1, wherein, The abnormal detection module adopts the following flow dynamic flow limiting model: B(t) = B0·e -λt +∑w i ·f(t-τ i ) where λ = 0.05, w i ∈ [0.8, 1.2], f is the basis function within the sliding window.
4. The system of claim 1, wherein, The meter terminal has an abnormal disassembly detection module, which includes a three-axis acceleration sensor and an ambient light sensor, and triggers the safety area self-destruction logic within 50 ms when detecting that the terminal shell is opened.
5. The system of claim 4, wherein, The self-destruction logic is realized by calling the following erase program: voidemergency_wipe(){ flash_erase(CRYPTO_ZONE); gpio_set(RESET_PIN,HIGH); }。 6. The system of claim 1, wherein, The communication link has bit error rate ≤10-9 under industrial temperature environment (-40℃-85℃), and the error rate is ≤10-6 under 6dB signal-to-noise ratio.
7. The system of claim 1, wherein, The data sampling interval is 1s, the key update period is not more than 30 minutes, and the TLS superimposed encryption channel is used for double authentication.
8. The system of claim 1, wherein, The FPGA encryption module uses 23,000-24,000 LUT logic resources and 48 BRAM blocks, and the proportion of the two does not exceed 50% of the overall logic resources.
9. The system of claim 1, wherein, Support three deployment forms: single-phase smart meter, three-phase meter and distribution automation terminal.
10. The system of claim 1, wherein, The main station platform is deployed based on the Kubernetes architecture and has a container-level isolation mechanism and load balancing scheduling capability to ensure the stable operation of the encryption business.
Citation Information
Cited By
Electric energy data secure transmission method and system for intelligent electric meter
CN122268676A