Electric power internet of things connection system
By constructing a multi-protocol automatic identification and digital certificate dynamic authentication mechanism, quantum entropy-driven data fusion technology, real-time data transmission rate adjustment, and multi-dimensional trust assessment, the problems of protocol fragmentation, inefficient data processing, and poor security of power equipment have been solved, achieving efficient, secure, and flexible equipment management of the power system.
Patent Information
- Application Number
- CN202511345256.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-19
- Publication Date
- 2025-12-12
AI Technical Summary
Traditional power equipment suffers from problems such as fragmented protocols, inefficient data processing, poor communication stability, passive security protection, and crude load scheduling. This results in complex equipment commissioning and access, high operation and maintenance costs, and difficulty in real-time data monitoring and analysis, making it impossible to support the optimized operation and fault early warning of the power system.
The system employs a device access module to construct a multi-protocol automatic identification and digital certificate dynamic authentication mechanism, a data processing module to use quantum entropy-driven multi-source heterogeneous data fusion technology, a communication management module to adjust the data transmission rate in real time, a security protection module to perform encryption processing and multi-dimensional trust assessment, and a load balancing module to perform dynamic scheduling. A multi-dimensional dynamic scheduling algorithm is constructed to solve the above problems.
It enables efficient access and authentication of devices with different communication protocols, improves data processing and communication stability, enhances security and load scheduling flexibility, reduces operation and maintenance costs, and supports real-time monitoring and optimized operation of power systems.
Smart Images

Figure CN121125776A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of power internet of things, and particularly relates to a power internet of things connection system. BACKGROUND
[0002] At present, traditional power equipment faces the fragmentation problem of "seven countries and eight systems", and the communication protocols and data formats of equipment of different brands and types are different.
[0003] In a substation, devices such as relay protection devices, intelligent cameras and environmental sensors are very complex to debug and access due to non-uniform protocols, often requiring a lot of time and labor costs. Under the traditional scheme, the device debugging and access time may be as long as 72 hours. With the acceleration of new power system construction, "source, network, load and storage" four-dimensional interaction has become the key to maintaining the real-time dynamic balance of the power system. Distributed new energy, electric vehicle charging piles, distributed energy storage and other new power elements are emerging, and their dispersion, volatility and randomness have exacerbated the complexity of power system supply and demand interaction. At the same time, the scale of power internet of things terminals is growing rapidly, and the complexity of equipment is increasing, which makes the internet of things have great difficulties in connection and device management.
[0004] In the process of digital transformation of the power industry, the traditional power equipment management mode has exposed many drawbacks. In terms of operation and maintenance, the efficiency is low and the cost is high, which is difficult to adapt to the development rhythm of modern power systems. For example, in the operation and maintenance of transmission lines, relying on manual inspection not only consumes a lot of manpower and material resources, but also is difficult to achieve real-time and accurate monitoring. In terms of data processing and application, the previous scattered and isolated data state cannot provide strong support for the optimized operation, load prediction, fault warning and other aspects of the power system. SUMMARY
[0005] The present application provides a power internet of things connection system to solve the problems of traditional power internet of things equipment protocol fragmentation, inefficient data processing, poor communication stability, passive security protection and extensive load scheduling.
[0006] According to an aspect of the present application, a power internet of things connection system is provided, the system comprising: a device access module, a data processing module, a communication management module, a security protection module and a load balancing module; wherein,
[0007] The device access module is configured to build a multi-protocol automatic identification and digital certificate dynamic authentication mechanism to connect and authenticate power equipment of different types of communication protocols;
[0008] The data processing module is configured to fuse the multi-source heterogeneous data obtained from different power equipment by introducing a quantum entropy driven multi-source heterogeneous data fusion technology;
[0009] the communication management module is configured to determine the network bandwidth between the power equipment and the power system, and to adjust the data transmission rate in real time according to the network bandwidth;
[0010] the security protection module is configured to perform encryption processing on the transmission data, and to evaluate the security risk of the power system through multi-dimensional dynamic trust evaluation;
[0011] the load balancing module is configured to construct a multi-dimensional dynamic scheduling algorithm, and to dynamically allocate network load according to the multi-dimensional dynamic scheduling algorithm.
[0012] The technical scheme of the embodiment of the application comprises a device access module, a data processing module, a communication management module, a security protection module and a load balancing module; wherein the device access module is configured to construct a multi-protocol automatic identification and digital certificate dynamic authentication mechanism to connect and authenticate power equipment of different types of communication protocols; the data processing module is configured to fuse multi-source heterogeneous data obtained from different power equipment by introducing quantum entropy driven multi-source heterogeneous data fusion technology; the communication management module is configured to determine the network bandwidth between the power equipment and the power system, and to adjust the data transmission rate in real time according to the network bandwidth; the security protection module is configured to perform encryption processing on the transmission data, and to evaluate the security risk of the power system through multi-dimensional dynamic trust evaluation; and the load balancing module is configured to construct a multi-dimensional dynamic scheduling algorithm, and to dynamically allocate network load according to the multi-dimensional dynamic scheduling algorithm. Through the power Internet of Things connection system, the problems of fragmentation of traditional power equipment protocols, low efficiency of data processing, poor communication stability, passive security protection and extensive load scheduling are solved.
[0013] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the application, nor is it intended to limit the scope of the application. Other features of the application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0014] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0015] Figure 1 is a structural schematic diagram of a power Internet of Things connection system provided by the embodiment of the application. DETAILED DESCRIPTION
[0016] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0017] The acquisition, storage, use, and processing of data in the technical solution of this application all comply with relevant laws and regulations. It should be noted that the terms "first," "second," "target," and "original," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising," "etc.," and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0018] Figure 1 This is a schematic diagram of a power Internet of Things (IoT) connection system provided in an embodiment of the present invention. This embodiment is applicable to situations where systemic breakthroughs are achieved through multi-module collaborative innovation to address problems such as fragmented protocols, inefficient data processing, poor communication stability, passive security protection, and crude load scheduling in traditional power IoT devices. Figure 1 As shown, the system includes: a device access module 110, a data processing module 120, a communication management module 130, a security protection module 140, and a load balancing module 150; wherein,
[0019] The device access module 110 is used to construct a multi-protocol automatic identification and digital certificate dynamic authentication mechanism to connect and authenticate power devices with different types of communication protocols.
[0020] The data processing module 120 is used to fuse multi-source heterogeneous data acquired from different power devices by introducing quantum entropy-driven multi-source heterogeneous data fusion technology.
[0021] The communication management module 130 is used to determine the network bandwidth between the power equipment and the power system, and adjust the data transmission rate in real time according to the network bandwidth;
[0022] The security protection module 140 is used to encrypt the transmitted data and assess the security risks of the power system through multi-dimensional dynamic trust assessment.
[0023] The load balancing module 150 is used to construct a multi-dimensional dynamic scheduling algorithm and dynamically allocate network load according to the multi-dimensional dynamic scheduling algorithm.
[0024] Optionally, the device access module is used to identify the communication protocols of different types of power devices. When a power device is connected, it detects the communication protocol type of the power device and establishes a connection between different types of power devices according to the common protocol type. When the power device is connected, it uses digital certificate authentication to authenticate the identity of the power device.
[0025] In one optional embodiment of the present invention, the device access module is specifically used for:
[0026] When power equipment is connected to the power system, the communication protocol type of the power equipment is detected, and the corresponding power equipment connection is established according to the communication protocol type.
[0027] After the power equipment connection is established, a digital certificate dynamic authentication mechanism is used to authenticate the authenticity and legality of the power equipment's identity.
[0028] When various power devices are connected to the Dianhongyilian Power Internet of Things (IoT) system, the device access module can detect the communication protocol type used by the connected power devices and identify power devices with different communication protocols. Based on the detection results, connections are established for different types of power devices according to the corresponding common protocol type, ensuring smooth basic data transmission channels. After the connection is established, the system uses digital certificate authentication to ensure the authenticity and legitimacy of the device's identity. The device sends an authentication request containing its own digital certificate; this "digital ID card" carries the device's key identity information. After receiving the request, the system verifies the certificate with the help of a certificate verification server.
[0029] Specifically, the verification process relies on a specific certificate verification algorithm to determine the validity of the certificate; the certificate verification algorithm can be expressed as:
[0030] V=g(C, S, δ, ρ, χ, ψ)
[0031] Where C represents the device digital certificate, which is the digital representation of the device's identity; S represents the system trust root certificate, which is the cornerstone of the system's trust system; δ represents the certificate update frequency coefficient, reflecting the frequency of certificate updates and affecting the certificate's timeliness; ρ represents the certificate credibility decay factor, used to characterize the potential decrease in credibility over time; χ represents the certificate chain integrity factor, used to ensure that the certificate chain has not been tampered with or missing during transmission, guaranteeing the reliability of the certificate's source; and ψ represents the certificate timestamp fuzziness factor. (The formula is used to...) A certificate timestamp fuzziness factor ψ is calculated, where t is the current time, t0 is the certificate timestamp, and τ is the time fuzziness threshold. This factor is introduced to prevent malicious and precise tampering of the timestamp, increasing security in the time dimension. Through exponential calculation, a parameter is generated to assist in verifying the legitimacy of the certificate based on the difference between the current time and the certificate timestamp, as well as the set time fuzziness threshold. Combining these parameters, the certificate verification algorithm determines whether the certificate is legitimate, thereby determining whether power equipment is allowed to access the system and preventing the infiltration of unauthorized power equipment.
[0032] The device access module in this embodiment of the invention can identify the communication protocols of different types of power equipment and establish connections, which greatly improves the system's compatibility. Whether it's traditional power equipment or new intelligent power equipment, as long as its communication protocol is within the system's recognizable range, it can successfully access the system. This allows the system to be widely applied in various power scenarios without the need to develop separate adaptation systems for devices with different protocols, reducing system construction and maintenance costs and improving resource utilization efficiency. The use of digital certificate authentication, combined with a complex and multi-dimensional parameter certificate verification algorithm, provides high security for power equipment identity authentication. Digital certificates act as "electronic ID cards" for devices, making them difficult to forge. The multi-parameter verification algorithm comprehensively verifies the certificate itself, the root of trust, update frequency, credibility decay, integrity, and timestamps, effectively resisting various certificate-related attacks, such as certificate forgery, tampering, and replay attacks. Only devices that pass strict verification can access the system, preventing unauthorized devices from accessing the power Internet of Things and posing security risks. This ensures the security and stability of the entire power system, avoiding data leaks, equipment failures, and power supply anomalies caused by unauthorized device access, and ensuring the safe and reliable operation of the power system.
[0033] Optionally, data transmitted by different power devices may follow different communication protocols. The data processing module parses and processes the data according to these different protocols to understand the meaning expressed by the data. Then, it converts the parsed data of various formats into a unified standard data format to facilitate the subsequent unified processing and analysis of the data by the system.
[0034] In one optional embodiment of the present invention, the data processing module is specifically used for:
[0035] The system parses and processes the transmission data of power equipment with different communication protocols, and then converts the parsed transmission data into a unified data format.
[0036] For power equipment transmitting data using different communication protocol types, the following formula is used for data conversion, which can be expressed as:
[0037]
[0038] Where P is the power value after data conversion; U is the voltage; and I is the current. Voltage and current reflect the basic electrical parameters in power transmission. θ is the power factor, which reflects the efficiency of equipment power consumption; θ is the load fluctuation correction factor, used to account for the impact of load changes on power calculation; w is the harmonic distortion rate, which measures the degree to which the current or voltage waveform deviates from a sine wave; k h f is the amplitude of the h-th voltage fluctuation component. h For the h-th fluctuation frequency, φ h Γ is the phase angle, which comprehensively reflects the effect of voltage fluctuations on power; Γ is the equipment temperature influence coefficient; Λ is the humidity correction factor; and γ is the air pressure influence factor. By substituting these parameters into the formula for calculation, the power value that accurately reflects the actual power of the electrical equipment is finally obtained.
[0039] The data format conversion for transmission takes into account various factors affecting power, including but not limited to electrical parameters (voltage, current, power factor, etc.), equipment operating characteristic parameters (load fluctuations, harmonic distortion, etc.), and environmental parameters (temperature, humidity, air pressure, etc.). By calculating power values using complex and comprehensive formulas, this method more accurately reflects the power situation of electrical equipment during actual operation. Compared to simple power calculation methods that only consider basic electrical parameters, it provides more reliable data support for power system power management, energy consumption analysis, and load forecasting. This helps power companies allocate power resources more rationally, optimize power system operation, reduce energy losses, improve energy utilization efficiency, and achieve refined management and energy conservation in the power system.
[0040] This invention addresses the challenge of integrating and processing multi-source heterogeneous data in the power Internet of Things by parsing and converting transmission data from power devices with different communication protocols into a unified format. This enables data from different manufacturers and types of power devices to be smoothly analyzed, stored, and shared within the same system, improving data processing efficiency and accuracy. It lays a solid foundation for data management and application throughout the power system, facilitating comprehensive monitoring and analysis of the operating status of power equipment.
[0041] In one optional embodiment of the present invention, the data processing module is specifically used for:
[0042] Multi-source heterogeneous data is obtained from at least two power devices, and the multi-source heterogeneous data is fused by introducing a fusion formula of quantum entropy.
[0043] The data fusion unit in the data processing module first collects heterogeneous data from multiple different power devices. These devices include, but are not limited to, generators, transformers, and meters. The data generated by these power devices differ in format, type, and meaning; for example, some devices provide real-time voltage data, while others provide cumulative electricity consumption data, resulting in a heterogeneous data source. In this embodiment of the invention, the heterogeneous data is fused using a fusion formula to reflect the real-time operating status of the power devices. The fusion formula is expressed as:
[0044]
[0045] Among them, D f D represents the merged data; i υ1 represents the data from the i-th data source; υ1 represents the weight of the i-th data source, as different data sources contribute differently to the final fusion result; υ1 is used to reflect the importance of the i-th data source, for example, a data source that directly reflects key power parameters may be assigned a higher weight; σ i σ is the data confidence coefficient, which measures the reliability of the data from the i-th data source. If the historical data from a certain data source is highly accurate and stable, its σ is higher. i A relatively high value indicates that the data source's influence will be enhanced in fusion computing; ij The correlation between the i-th data source and the j-th reference standard; s j To determine the importance of the j-th reference standard, the fusion result is adjusted by comprehensively considering the relationship between each data source and the reference standard, as well as the importance of the reference standard itself. For example, data sources closely related to important reference standards have a greater impact on the fusion result; χ 1i χ represents the quantum entropy of the i-th data source, reflecting the degree of uncertainty or disorder in the data from that data source. 2jγ represents the entanglement degree of the j-th data source, reflecting the correlation characteristics between the data; k The decoherence factor for the i-th data source measures the degree to which data loses quantum coherence during transmission or processing. By comprehensively considering these quantum-related factors, the fusion results are further optimized, enabling the fused data to more accurately reflect the actual operating status of power equipment.
[0046] This invention, through the fusion of heterogeneous data from multiple sources, overcomes the limitations and incompleteness that may exist in a single data source. For example, data from a certain device may experience temporary anomalies due to a fault. By fusing data from other relevant devices, this anomaly can be corrected and supplemented, resulting in more comprehensive, accurate, and reliable fused data. This improves data quality and provides a more solid data foundation for subsequent power system analysis and decision-making. The fusion process considers various complex factors, such as data correlation and quantum properties, enabling the uncovering of hidden relationships and information between different data sources. This helps power companies gain a deeper understanding of the operating patterns of power equipment and the overall operating status of the power system, identifying potential power loss points and equipment failure hazards. It provides strong support for power system optimization scheduling, equipment maintenance, and fault early warning, enhancing the intelligent management level of the power system and ensuring its safe and efficient operation.
[0047] Optionally, the communication management module is used to manage data transmission between power equipment and the power system, and adjust the data transmission rate in real time according to network conditions.
[0048] Specifically, the network bandwidth between power equipment and the power system is determined using a network bandwidth formula, and the data transmission rate is adjusted in real time based on this network bandwidth. The network bandwidth formula can be expressed as:
[0049]
[0050] Where B is the network bandwidth; I is the amount of data transmitted per unit time; T is the transmission time, which directly affects the data transmission rate; α is the device collaborative transmission gain coefficient, reflecting the gain effect brought about by multiple devices cooperating in transmission; β is the environmental interference factor, reflecting the degree of interference of the external environment on data transmission; γ is the signal attenuation compensation coefficient, used to compensate for signal attenuation during transmission; ε is the multipath fading factor, used to consider the fading of the signal caused by multipath propagation; λ i d is the gain factor for the i-th relay node; i The distance to the i-th relay node affects signal transmission and amplification. Closer proximity to the relay node and a larger gain factor are more beneficial for bandwidth improvement; d0 is the reference distance; μ j f is the intensity of the j-th interference source; jΩ represents the j-th interference frequency, reflecting the interference from external sources on the network. The stronger the interference, the greater the negative impact on bandwidth. Ω represents the orthogonal frequency division multiplexing gain factor. Ξ represents the carrier aggregation efficiency. Π represents the spectrum hole utilization rate, reflecting the gain related to spectrum resource utilization. Reasonable utilization of spectrum resources can effectively improve network bandwidth.
[0051] When network bandwidth B falls below a set threshold, it indicates poor network conditions, potentially leading to congestion or weak signal. In this situation, the communication management module reduces the data transmission rate, decreasing the amount of data transmitted per unit time. This prevents excessive data transmission from exacerbating network congestion or causing data loss, thus ensuring data transmission stability and reliable data transfer between devices and the system. By calculating network bandwidth in real time and adjusting the data transmission rate accordingly, the communication management module effectively copes with complex and changing network environments. Timely reduction of the transmission rate when network conditions are poor avoids packet loss and retransmission issues, ensuring the stability and reliability of data transmission between devices and the system. This enables the power system to operate continuously and stably, providing reliable communication support for real-time monitoring and control of the power system.
[0052] This invention considers numerous factors affecting network bandwidth and performs precise calculations to utilize network resources more rationally. When network bandwidth is sufficient, it fully utilizes the bandwidth for high-speed data transmission, improving data transmission efficiency. When network bandwidth is insufficient, it reduces the transmission rate to avoid network congestion, achieving dynamic optimization of network resource allocation, improving the resource utilization efficiency of the entire power IoT communication network, reducing operating costs, and enhancing the overall system performance. The communication management module calculates network bandwidth in real time and adjusts the transmission rate accordingly, dynamically adapting to actual network conditions. During network congestion, it reduces the rate to ensure stable transmission, avoiding data loss and retransmission; when the network is good, it fully utilizes the bandwidth to improve transmission efficiency.
[0053] In an optional embodiment of the present invention, the communication management module further includes a data caching submodule, which is specifically used for:
[0054] When determining network congestion based on the network bandwidth between power equipment and the power system, the data to be transmitted is temporarily buffered, and the priority value of the data to be transmitted is calculated using the priority value determination formula.
[0055] Based on the priority of the data to be transmitted, when network congestion is relieved, the data to be transmitted that is at the beginning of the buffer queue is taken out in sequence for transmission; the higher the priority of the data to be transmitted, the earlier it is in the buffer queue.
[0056] Specifically, when the communication management module detects network congestion, the data caching submodule is activated. At this time, data that was originally scheduled to be transmitted over the network is no longer sent immediately but is temporarily stored in the cache space to prevent a large influx of data during network congestion from causing further congestion or even network paralysis. The priority value of the data to be transmitted is determined, and the calculated priority value P is used... rank The system determines the position of the data to be transmitted in the buffer queue. Data with higher priority is placed at the front of the queue. When network congestion eases, the system will prioritize retrieving data from the front of the queue for transmission, ensuring that important and time-sensitive data can be transmitted as quickly as possible, thus guaranteeing the orderly and efficient transmission of power system data.
[0057] Specifically, the priority value calculation formula can be expressed as:
[0058]
[0059] Among them, P rank α is the calculated priority value; μ is the time decay coefficient; f1 is the data importance weight coefficient; β is the frequency influence factor; δ is the data timeliness factor; σ is the data integrity verification value; τ is the cache space utilization rate; Φ is the data freshness index; θ is the data redundancy; Ψ is the cache read / write energy consumption ratio.
[0060] Among them, according to the priority value P rank The location of the data to be transmitted in the cache queue can be determined. The time decay coefficient α, combined with time t, reflects the change in the importance of data over time. If α is large, the priority of data that has not been processed for a long time will decrease rapidly, prompting the system to prioritize newly generated or time-sensitive data. The data importance weight coefficient μ highlights the status of important data; a larger μ value indicates higher importance and a correspondingly higher priority. The data access frequency f1 and the frequency influence factor β work together, with frequently accessed data having a higher priority. The data timeliness factor δ and the data integrity check value σ measure the timeliness and integrity of data; data with strong timeliness and high integrity will have a higher priority due to the influence of this part of the calculation. The cache space occupancy rate τ reflects the utilization of cache space; when space is tight, it will affect the calculation of data priority. The data freshness index Φ and the data redundancy θ consider the freshness and redundancy of data; data with high freshness and low redundancy has a more favorable priority. The cache read / write energy consumption ratio Ψ affects the priority calculation from an energy consumption perspective; if read / write energy consumption is high, it will have a certain regulatory effect on the priority.
[0061] In this embodiment of the invention, the data caching submodule caches data during network congestion and determines the data transmission order through priority value calculation. This effectively alleviates network pressure, ensures priority transmission of critical data, and guarantees the orderliness and efficiency of power IoT system communication in complex network environments. Through reasonable caching and orderly transmission, the network maintains basic data transmission functions even under congestion, preventing network collapse due to excessive congestion and maintaining the stability of power IoT communication. A complex and multi-factor-integrated priority value calculation formula accurately distinguishes the importance and transmission priority of data to be transmitted. This ensures that critical data, such as important and time-sensitive data, is prioritized in the cache queue and transmitted first after network access is restored. This ensures that critical information in the power system (such as equipment fault warning data and real-time power parameter data) can be transmitted to the power system in a timely and accurate manner, supporting the reliable operation and timely decision-making of the power system, improving the power system's ability to cope with network anomalies, and enhancing the quality of data transmission.
[0062] Optionally, the security module uses the generated encryption key to encrypt the data transmitted between devices and systems in the power Internet of Things (IoT). The original data is converted into ciphertext using a specific encryption algorithm and the generated key, ensuring that even if the data is intercepted during transmission, its content cannot be deciphered without the corresponding key.
[0063] In one optional embodiment of the present invention, the security protection module is specifically used for:
[0064] An encryption key is generated using a key generation function, and the transmitted data is encrypted using the encryption key.
[0065] Specifically, the key generation function is expressed as:
[0066]
[0067] Where K is the transmitted data obtained after encryption; f() is the key generation function; S is the randomly generated seed value, which serves as the starting point for key generation and introduces initial randomness into the key, so that each generated key has a certain difference; γ is the device aging coefficient, which takes into account the performance changes that may occur as the device is used over time, and is used to reflect the device aging factor in key generation, so that the key is associated with the actual state of the device. ψ is the entropy enhancement factor, used to enhance the entropy of the key, increase the uncertainty and complexity of the key, and improve the security of encryption. The higher the entropy, the stronger the randomness and unpredictability of the key; ψ is the chaotic mapping parameter. With the help of the characteristics of chaotic mapping, chaotic mapping has the characteristics of being sensitive to initial conditions and having unpredictable long-term behavior; ψ is the random parameter. The participation of the ψ parameter makes the key generation process more complex and random; ω is the output parameter of the quantum random number generator. Where, φ i For quantum phase, θ i By using a random phase angle and real-time monitoring of network traffic, potential attack behaviors are identified through abnormal traffic detection. Quantum property parameters generated by a quantum random number generator introduce true randomness, further enhancing the security and randomness of the key. By combining these parameters, a key is generated to encrypt transmitted data.
[0068] This invention utilizes a complex key generation function to generate encryption keys for encrypting transmitted data, significantly improving data security during transmission. Multiple factors participate in key generation, particularly the introduction of quantum randomness, making the keys difficult to crack, preventing data theft and tampering, and ensuring the confidentiality and integrity of sensitive power data (such as user electricity consumption information and power system operating parameters) in the power Internet of Things, thus maintaining the safe and stable operation of the power system.
[0069] In one optional embodiment of the present invention, the security protection module can also monitor network traffic in real time. This is achieved by analyzing various network traffic indicators, such as traffic volume, traffic rate changes, and the distribution of traffic sources and destinations. When abnormal traffic is detected, such as a sudden and significant increase in traffic, or abnormal traffic sources or destinations, it is determined that potential attack behaviors, such as denial-of-service (DoS) attacks or distributed denial-of-service (DDoS) attacks, may exist, and corresponding measures (such as alarms and blocking suspicious connections) are taken promptly to ensure system security.
[0070] This invention provides a security protection module that monitors network traffic in real time and identifies potential attacks, enabling the system to proactively defend against attacks. It can promptly detect signs of network attacks and take countermeasures before they cause serious damage, reducing the impact of attacks on the power system, ensuring the continuity and reliability of power supply, and minimizing power system failures and economic losses caused by network attacks.
[0071] In an optional embodiment of the present invention, the security protection module further includes a risk assessment submodule, which is specifically used for:
[0072] The risk assessment value of the power Internet of Things is evaluated in real time from at least two dimensions, and corresponding preventive measures are taken based on the risk assessment value; wherein, the at least two dimensions include vulnerability severity, probability of exploitation, threat source activity, attack type, and attack source characteristics.
[0073] This approach comprehensively considers multiple factors, including vulnerability severity, probability of exploitation, threat source activity, attack type, and attack source characteristics, to conduct real-time risk assessments of the power Internet of Things (IoT). Compared to assessment methods that consider only one or a few factors, this approach more accurately reflects the actual security risk level faced by the system, providing a reliable basis for subsequent security decisions. The risk assessment value can be expressed as:
[0074]
[0075] Where R is the risk assessment value; L i Let L represent the severity of the i-th vulnerability, reflecting the potential harm each vulnerability poses to system security. For example, a high-risk vulnerability could lead to data leakage or paralysis of critical functions. i The value is relatively high; N i Let be the probability of the i-th vulnerability being exploited. We will assess the likelihood of the vulnerability being exploited by an attacker by considering factors such as the vulnerability's own characteristics and the system environment. The threat source activity coefficient reflects the activity level of threat sources (such as hacker groups, malware, etc.). The higher the activity level, the greater the likelihood of harm to the system; t i The longer the vulnerability has been known since its discovery, the greater the potential change in risk as attackers become aware of it; T risk λ is the risk decay time constant; j The weight for the j-th attack type is used to distinguish the importance of different attack types (such as network sniffing, brute-force attacks, etc.) to the system security threat; a j Ω represents the detection confidence level for the j-th attack type, reflecting the reliability of the detection results for that attack type; j Γ represents the geographic distribution entropy of attack sources, used to measure the degree of dispersion or uncertainty of attack sources in geographical distribution. The more dispersed the distribution and the higher the uncertainty, the more difficult it may be to defend against the attack sources; k Πl is the attack time distribution entropy, which reflects the distribution characteristics of attacks in the time dimension, such as whether attacks are concentrated in certain specific time periods; Πl is the attack method diversity index, which reflects the richness of the attack methods used by attackers. The higher the diversity, the greater the risk that the system may face.
[0076] In this embodiment of the invention, the risk assessment submodule comprehensively evaluates system security risks in real time based on multiple factors, obtaining a quantified risk assessment value. This helps power system managers to grasp the system security situation in advance, formulate targeted security strategies, and rationally allocate security resources. By assessing risks in real time, it is possible to promptly identify potential upward trends in security risks or newly emerging high-risk situations within the system. Power system managers can take corresponding preventative measures in advance based on the risk assessment results, such as patching vulnerabilities, strengthening network monitoring, and adjusting security strategies, effectively reducing the likelihood of security incidents, ensuring the safe and stable operation of the power system, and minimizing adverse consequences such as power supply interruptions and economic losses caused by security accidents.
[0077] In an optional embodiment of the present invention, the security protection module further includes a trust assessment submodule, which is specifically used for:
[0078] The power equipment is assessed for trust level based on its historical information, and corresponding permissions or resources are allocated to the power equipment based on the trust level; wherein, the historical information includes historical behavior, current behavior, and certificate status.
[0079] This assessment comprehensively and meticulously evaluates equipment trustworthiness by considering its historical and current behavior, certification status, and various other influencing factors. Compared to assessments using a single dimension or simplistic methods, this approach more accurately determines the trustworthiness of equipment within the power Internet of Things (IoT) system, providing a reliable basis for system decision-making. Specifically, the equipment trustworthiness assessment formula is expressed as follows:
[0080]
[0081] Among them, T r Total trust level; T rh Historical trust level is determined based on data such as the device's past behavior and interaction records within the system. For example, if a device has operated stably for a long period without any record of violations or security issues, its historical trust level is relatively high. rb Behavioral trust is assessed based on the device's current real-time behavior, including the frequency of data transmission, data accuracy and consistency, and whether operations conform to established rules. For example, a sudden, abnormally high frequency of data transmission or a significant increase in the data error rate will lower the behavioral trust level. rc The trust level of a certificate is assessed by evaluating the digital certificate possessed by the device. Factors such as the legality, validity period, and credibility of the issuing authority determine the certificate's trust level. If the certificate is expired or tampered with, the trust level will decrease. xr β xr γ xr w represents the weighting coefficient. xriζ represents the weight of the i-th trust-influencing factor, reflecting the importance of this factor in the assessment of device trustworthiness; xri Γ is the assessment value of the i-th trust influencing factor; gzi For device anonymity; Λ gzj For interactive historical continuity; γ gzk The decay rate of trust transmission.
[0082] In this embodiment of the invention, the trust assessment submodule evaluates device trust levels from multiple dimensions, providing a quantitative basis for the system's management of devices. This helps the system to manage devices with different trust levels in a differentiated manner, enhancing the overall security and stability of the system. By accurately assessing device trust levels, the system can grant more permissions or resources to high-trust devices and take restrictive measures against low-trust devices, such as strengthening monitoring and restricting data access. This helps prevent untrusted devices from posing security threats to the system, such as unauthorized access by malicious devices or data tampering, effectively enhancing the security and stability of the power Internet of Things system and ensuring the reliable operation of the power system.
[0083] Optionally, the load balancing module calculates the load balance of power equipment by comprehensively considering factors such as equipment and services, and dynamically allocates network load. This avoids excessive concentration of equipment load, maintains a balanced load within the system, improves equipment resource utilization, and extends equipment lifespan. By ensuring balanced equipment load, it effectively prevents system performance degradation caused by overload of some equipment. This ensures the power system's response speed and processing capacity when handling various power services, maintaining stable and efficient system operation.
[0084] In one optional embodiment of the present invention, the load balancing module is specifically used for:
[0085] The load balance degree of each power device is determined by the load balancing formula, and the network load is dynamically allocated to the power devices based on the load balance degree.
[0086] The load balancing module determines the load balance degree of each power device using a load balancing formula, and dynamically distributes the network load to each device based on the load balance degree, so that the load on the devices in the system is as even as possible, avoiding situations where some devices are overloaded while others are underloaded. Specifically, the load balance degree is expressed as:
[0087]
[0088] Where L is the load balancing degree, w fzi The weight of the i-th device reflects its importance or performance advantage in the entire system; for example, a high-performance server might have a higher weight. fzi U represents the remaining computing power of the i-th device, indicating the amount of computing resources the device currently possesses;fzi α represents the current load of the i-th device, reflecting the workload the device is currently undertaking; fzj Priority for the j-th business type; β fzj For the real-time requirements of the j-th type of service; Γ fzj The equipment heterogeneity index measures the degree of difference between equipment in terms of performance, functionality, etc.; Λ fzk Business coupling degree represents the degree of correlation between different business functions; γ fzl Load migration cost represents the expense required to migrate a load from one device to another, including resource consumption and time costs.
[0089] The load balancing module in this invention dynamically allocates network load by comprehensively considering multiple factors, enabling more efficient and rational utilization of device resources within the system. This avoids the waste of idle resources caused by uneven device loads, while also preventing performance degradation or even malfunctions of some devices due to overload, thus improving the resource utilization efficiency of the entire power IoT system and reducing operating costs. It also helps maintain the overall stability of the power IoT system's performance. Furthermore, it avoids network latency and data transmission problems caused by excessive load on individual devices, ensuring the system can process various power services promptly and accurately, such as real-time power data acquisition, analysis, and device control, guaranteeing reliable power system operation and improving user experience and service quality. Load balancing provides a clear understanding of the load status of each device in the system. Based on this, network load can be rationally allocated to different devices to avoid resource waste. For example, computationally intensive tasks can be assigned to devices with strong remaining computing power and appropriate load balancing, allowing for full utilization of device resources and improving the resource utilization efficiency of the entire power IoT system.
[0090] Optionally, the power IoT connection system provided in this embodiment of the invention also includes a data traceability module. This module calculates the data traceability reliability by comprehensively considering factors from multiple stages. It can comprehensively assess the quality of data at each stage, promptly identify problems in data processing, storage, and transmission, and ensure the high quality of power IoT data. Based on accurate traceability reliability calculations, when data problems occur, the source and flow path of the data can be quickly and accurately traced. This facilitates power companies in finding the root cause of data problems and provides a powerful means to resolve data disputes and investigate data tampering.
[0091] In an optional embodiment of the present invention, the system further includes a data traceability module, which is specifically used for:
[0092] The reliability of data traceability of transmitted data is considered and calculated from at least two dimensions. Based on the reliability of data traceability, the quality of transmitted data at each stage is determined, and when the reliability of data traceability is low, problem stages are specifically identified. The at least two dimensions include the error rate of data processing, the reliability of storage nodes, and the security of transmission paths.
[0093] The data traceability module comprehensively assesses data quality at each stage by considering and calculating factors such as error rate in data processing, reliability of storage nodes, and security of transmission paths. When low data traceability reliability is detected, problematic stages can be identified, such as replacing unreliable storage devices, thereby ensuring the accuracy and integrity of data in the power Internet of Things (IoT) and providing a reliable data foundation for subsequent data analysis and applications. Specifically, the data traceability reliability is expressed as:
[0094]
[0095] Among them, S sy To calculate the data source traceability credibility; ε syi φ represents the error rate of the i-th processing stage, reflecting the degree to which errors or deviations may occur in the transmitted data at that processing stage; syj ψ represents the reliability of the j-th storage node; syj For the security of the j-th transmission path; Ω syj Data encryption strength reflects the degree of data encryption protection; the higher the encryption strength, the more difficult it is for the data to be illegally obtained and tampered with. syk Timestamp accuracy is used to accurately record the time of data generation and flow. Higher accuracy is more conducive to accurately tracing the timeline of data; Π syl Metadata integrity refers to the completeness of data-related metadata (such as data format, source identifier, etc.). The higher the integrity, the more sufficient the basis for data traceability.
[0096] This invention accurately calculates data traceability credibility, which helps to precisely trace the source and flow path of data in the power Internet of Things. When data anomalies occur (such as data errors, data tampering, etc.) or when it is necessary to verify the authenticity of data, the system can quickly locate the link in the data problem based on data traceability credibility and related calculation factors, such as determining which processing stage the error occurred in, which storage node caused the data to be unreliable, etc., thereby improving the efficiency and accuracy of data traceability, meeting the stringent requirements of the power system for data traceability, and ensuring the safe and reliable operation of the power system.
[0097] This invention addresses the problems of fragmented protocols, inefficient data processing, poor communication stability, passive security protection, and crude load scheduling in traditional power equipment by achieving a systemic breakthrough through multi-module collaborative innovation. In the device access module, a multi-protocol automatic identification and dynamic digital certificate authentication mechanism is constructed to solve the problems of cross-brand device interconnection and identity trustworthiness. The data processing module introduces quantum entropy-driven multi-source heterogeneous data fusion technology to improve data integrity and metering accuracy. The communication management module designs adaptive network bandwidth adjustment and priority caching queues to ensure stable data transmission in complex environments. The security protection module integrates quantum random key generation and multi-dimensional dynamic trust assessment to achieve proactive defense and second-level attack response. The load balancing module develops a multi-dimensional dynamic scheduling algorithm to improve equipment resource utilization and critical business response efficiency. Furthermore, a full-link tracking system is constructed through data traceability and trusted metric technology, forming a complete technical closed loop from device access to data application, significantly improving the intelligence, security, and efficiency of the power Internet of Things.
[0098] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0099] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A power Internet of Things (IoT) connection system, characterized in that, The system includes: a device access module, a data processing module, a communication management module, a security protection module, and a load balancing module; wherein, The device access module is used to build a multi-protocol automatic identification and digital certificate dynamic authentication mechanism to connect and authenticate power devices with different types of communication protocols. The data processing module is used to fuse multi-source heterogeneous data acquired from different power devices by introducing quantum entropy-driven multi-source heterogeneous data fusion technology. The communication management module is used to determine the network bandwidth between the power equipment and the power system, and adjust the data transmission rate in real time based on the network bandwidth. The security protection module is used to encrypt the transmitted data and assess the security risks of the power system through multi-dimensional dynamic trust assessment. The load balancing module is used to construct a multi-dimensional dynamic scheduling algorithm and dynamically allocate network load according to the multi-dimensional dynamic scheduling algorithm.
2. The system according to claim 1, characterized in that, The device access module is specifically used for: When power equipment is connected to the power system, the communication protocol type of the power equipment is detected, and the corresponding power equipment connection is established according to the communication protocol type. After the power equipment connection is established, a digital certificate dynamic authentication mechanism is used to authenticate the authenticity and legality of the power equipment's identity.
3. The system according to claim 1, characterized in that, The data processing module is specifically used for: Multi-source heterogeneous data is obtained from at least two power devices, and the multi-source heterogeneous data is fused by introducing a fusion formula of quantum entropy; The fusion formula is expressed as follows: Among them, D f D represents the merged data; i Let υ1 be the weight of the i-th data source, and σ be the weight of the i-th data source. i r is the confidence coefficient of the data. ij Let s be the correlation between the i-th data source and the j-th reference standard. j χ represents the importance of the j-th reference standard. 1i Let χ be the quantum entropy of the i-th data source. 2j Let γ be the entanglement degree of the j-th data source. k Let be the decoherence factor of the i-th data source.
4. The system according to claim 1, characterized in that, The data processing module is also specifically used for: The system parses and processes the transmission data of power equipment with different communication protocols, and converts the parsed transmission data into a unified data format. Specifically, the conversion of transmitted data is represented as follows: Where P is the power value after data conversion; U is the voltage; and I is the current. θ is the power factor, θ is the load fluctuation correction factor, w is the harmonic distortion rate, and k is the power factor. h f is the amplitude of the h-th voltage fluctuation component. h For the h-th fluctuation frequency, φ h Γ is the phase angle, Γ is the equipment temperature influence coefficient, Λ is the humidity correction factor, and γ is the air pressure influence factor.
5. The system according to claim 1, characterized in that, The communication management module further includes a data caching submodule, which is specifically used for: When determining network congestion based on the network bandwidth between power equipment and the power system, the data to be transmitted is temporarily buffered, and the priority value of the data to be transmitted is calculated using the priority value determination formula. Based on the priority of the data to be transmitted, when network congestion is relieved, the data to be transmitted that is at the beginning of the buffer queue is taken out in sequence for transmission; the higher the priority of the data to be transmitted, the earlier it is in the buffer queue.
6. The system according to claim 1, characterized in that, The security protection module is specifically used for: An encryption key is generated using a key generation function, and the transmitted data is encrypted using the encryption key. Specifically, the key generation function is expressed as: Where K is the transmitted data obtained after encryption; f() is the key generation function; S is a randomly generated seed value, which serves as the starting point for key generation; and γ is the device aging coefficient. ψ is the entropy enhancement factor, used to enhance the entropy of the key, increasing the uncertainty and complexity of the key; ψ is the chaos mapping parameter; ψ is the random parameter; ω is the output parameter of the quantum random number generator.
7. The system according to claim 1, characterized in that, The security protection module also includes a risk assessment submodule, which is specifically used for: The risk assessment value of the power Internet of Things is evaluated in real time from at least two dimensions, and corresponding preventive measures are taken based on the risk assessment value; wherein, the at least two dimensions include vulnerability severity, probability of exploitation, threat source activity, attack type, and attack source characteristics; Specifically, the risk assessment value can be expressed as: Where R is the risk assessment value; L i N represents the severity of the i-th vulnerability. i Let be the probability that the i-th vulnerability is exploited. t represents the threat source activity coefficient. i For the time the vulnerability was discovered, T risk Let λ be the risk decay time constant. j Let a be the weight of the j-th attack type. j Let Ω be the detection confidence level for the j-th attack type. j Γ represents the geographic distribution entropy of the attack source. k Πl represents the attack time distribution entropy, and Πl represents the attack method diversity index.
8. The system according to claim 1, characterized in that, The security protection module also includes a trust assessment submodule, which is specifically used for: The trust level of power equipment is assessed based on its historical information, and corresponding permissions or resources are allocated to the power equipment based on the trust level; wherein, the historical information includes historical behavior, current behavior, and certificate status; Specifically, the formula for assessing equipment trustworthiness is as follows: Among them, T r For the total trust level, T rh For historical trust level, T rb For behavioral trust level, T rc For certificate trust level, α xr β xr γ xr w is the weighting coefficient. xri Let ζ be the weight of the i-th trust influencing factor. xri Let Γ be the evaluation value of the i-th trust influencing factor. gzi For device anonymity, Λ gzj For interactive historical continuity, γ gzk The decay rate of trust transmission.
9. The system according to claim 1, characterized in that, The load balancing module is specifically used for: The load balance degree of each power device is determined by the load balancing formula, and the network load is dynamically allocated to the power devices based on the load balance degree. Specifically, the load balancing degree is expressed as: Where L is the load balancing degree, w fzi Let C be the weight of the i-th device. fzi U represents the remaining computing power of the i-th device. fzi For the current load of the i-th device, α fzj For the priority of the j-th business type, β fzj For the real-time requirements of the j-th type of service, Γ fzj Λ is the equipment heterogeneity index. fzk For business coupling, γ fzl Cost of load migration.
10. The system according to claim 1, characterized in that, The system also includes a data traceability module, which is specifically used for: The reliability of data traceability of transmitted data is considered and calculated from at least two dimensions. Based on the reliability of data traceability, the quality of transmitted data at each stage is determined, and problematic stages are specifically identified when the reliability of data traceability is low. The at least two dimensions include the error rate of data processing, the reliability of storage nodes, and the security of transmission paths. Specifically, the credibility of the data traceability is expressed as follows: Among them, S sy To calculate the data source traceability reliability, ε syi Let φ be the error rate of the i-th processing stage. syj For the reliability of the j-th storage node, ψ syj For the security of the j-th transmission path, Ω syj For data encryption strength, Ξ syk For timestamp accuracy, Πsyl represents metadata integrity.