A method for district edge security linkage based on power utilization information collection terminal
By generating exclusive session windows and virtual segments in the transformer substation terminal, and combining shadow integrity tags and sequence commitments, the problem of identifying and handling near-source anomalies in transformer substation communication is solved, thereby achieving stability and reliability of transformer substation communication and meeting the requirements of secure access partitioning and compliance.
Patent Information
- Application Number
- CN202511851166.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-10
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2045-12-10
AI Technical Summary
Without altering existing electricity meters and their communication protocols, how can we establish a segment-oriented session exclusivity and order verification mechanism at the local communication port layer of the transformer terminal to identify and constrain anomalies such as near-source insertion, replay, impersonation, and timing conflicts, thereby ensuring the reliability and compliance of meter reading and control?
By generating exclusive session windows, implementing virtual segmentation and selective connectivity of switch arrays, rolling of carrier communication session keys, 485 exclusive sessions and whitelist rate limiting, combining shadow integrity tags and sequence commitments, performing physical fingerprint determination, hierarchical processing and recording of bypass mirroring and equivalent migration mapping, and completing key certificate rotation and upgrade.
It improves the reliability of data collection and control, reduces port layer contention, ensures the stability and auditability of area communication, and meets the requirements of secure access zoning, vertical authentication, and monitoring and auditing.
Smart Images

Figure CN121309212B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of power distribution terminal security, and particularly relates to a substation edge security linkage method based on a power utilization information collection terminal. BACKGROUND
[0002] At the substation level of a power distribution network, residents and small business users are concentrated, lines are branched, and the operation environment is complex. Electric energy meters are connected to marketing, power distribution and Internet of Things platforms via a substation intelligent fusion terminal or concentrator. The terminal generally adopts power carrier and four-eight-five bus as local communication media on the downward side, and is interconnected with the master station on the upward side through a private network or mobile communication; the terminal internally gradually bears edge computing and multi-service micro applications. The existing system has mature specifications in terms of interoperability and data objects, and can complete basic functions such as reading, event uploading and remote control; a complete transmission layer security and identity authentication method has also been formed on the station side and the wide area side.
[0003] At the same time, the engineering characteristics of local communication at the end of the substation are still prominent: the four-eight-five bus is a multi-point bus, and by default lacks identity authentication and encryption, and is easy to be inserted, replayed or contended near the source; the power carrier is affected by the coupling path, noise and network topology, and the link quality fluctuates with time and load. In combination with scenes such as residential buildings, old communities and commercial areas, common phenomena include: a large number of meters are hung under the same bus, and the wiring span is long, resulting in high error codes and time sequence conflicts; the box and metering position are easy to access, and abnormal access, address impersonation or interference with the order of messages occur; when events such as power failure, recovery and load mutation are superimposed at the same time, reading and control are concentrated in a short time, and the port layer resource contention is further intensified.
[0004] The current common practice is to strengthen encryption, authentication and dedicated channels on the master station and station side, or to introduce higher-level security components on the side of new meters; but for the existing massive meters and existing field arrangement, the above-mentioned methods still have room for improvement in the maintenance of the order in the segment and the on-site disposal at the local bus level of the substation, which is manifested in that: the reading success rate is affected by the near-source interference and fluctuates, the authorization chain of control actions is difficult to form auditable evidence at the port layer, and the range and length of abnormal isolation are difficult to quantitatively constrain, which makes it difficult to meet the closed-loop landing requirements of security access partitioning, vertical authentication, monitoring and auditing at the substation side.
[0005] In addition, the existing object-oriented data exchange standard focuses on the consistency of data model and interface between the master station and the terminal, and does not give uniform semantics for the segment control, session order and audit evidence of the local bus of the transformer area. Hybrid bearing and link selection can improve connectivity, but has limited constraints on near-source abnormalities such as segment insertion, message replay and address usurpation, and it is difficult to provide a quantifiable minimum impact range and recovery sequence at the port layer. If this problem persists, it will cause an increase in re-copying and on-site work orders, a lag in non-technical loss identification, an increase in user-side complaint risks caused by miscontrol, and an increase in compliance verification costs and operational risks. Among them, the power consumption information acquisition terminal can be a transformer area intelligent fusion terminal, concentrator and other transformer area terminals, hereinafter collectively referred to as transformer area terminal.
[0006] Therefore, the technical problem to be solved at present is: without changing the stock electric energy meter and its communication protocol, how to establish a session exclusion and order proof mechanism for the segment in the local communication port layer of the transformer area terminal, to timely identify and constrain abnormalities such as near-source insertion, replay, impersonation and timing conflict, implement hierarchical disposal according to the minimum impact range at the end side, and form an authorized and evidence chain that can be audited, while coordinating with the identity authentication and access zoning requirements of the upstream, to stably guarantee the reliability and compliance of copying and control in complex transformer area scenarios. SUMMARY
[0007] (I) Technical problems to be solved
[0008] In view of the deficiencies in the prior art, the present application provides a transformer area edge security linkage method based on a power consumption information acquisition terminal, which generates an exclusive session window, implements virtual segmentation and switch array selective connectivity, carrier communication session key rolling (re-keying), 485 exclusive session and white list throttling; calculates the shadow integrity label and sequence commitment in the end, and determines the abnormality in combination with the physical fingerprint, and disposes hierarchically according to the minimum impact range and records the bypass mirror and equivalent migration mapping; performs double authorization and time limit for control, range check, solidifies the evidence chain, completes key certificate rotation and upgrade; improves the reliability of copying and control without changing the meter, reduces the contention at the port layer and narrows the impact radius; solves the background technology.
[0009] (II) Technical solutions
[0010] In order to achieve the above purpose, the present application is implemented by the following technical solutions:
[0011] The transformer area edge security linkage method based on the power consumption information acquisition terminal comprises: only reading the objects, actions and time window generation intention fingerprints of the master station messages, establishing an edge security access zoning, verifying and completing access with a certificate and a one-time token, setting a northbound session state according to the access decision, and recording access audit logs;
[0012] According to the intention fingerprint and the time window, an exclusive session window is generated and whitelist and frequency throttling are performed; the window period maps the bus to a virtual segment, and a switch array is driven by segment number to generate an on-off vector, realizing selective connection, and generating a window number corresponding to the window;
[0013] Within the window, a shadow integrity label and sequential commitment are calculated and associated with the on-off vector, and a segment physical fingerprint is collected and compared with the baseline, thereby determining the treatment level and solving the minimum impact range, generating a bypass mirror record and equivalent migration mapping;
[0014] The control action is determined according to the double authorization, time limit and range conditions, and an authorization reply is output; a proof chain is archived by window number, sequential commitment and one-time token, and the integrity, trust domain and rollback verification of northbound key and certificate rotation and remote upgrade are performed.
[0015] Further, the edge security access partition distinguishes between collection entries and control entries, and performs certificate chain verification, revocation status check and one-time token verification on the messages entering the partition in turn, enables the built-in probe to record access events and partition boundary crossing requests, writes the records to the access audit log, and establishes a one-to-one correspondence between the session identifier and the intention fingerprint, which is called to maintain consistency when the subsequent window is released.
[0016] Further, the one-time token is bound to the intention fingerprint, window number and source identity, the token contains the invalidation time and replay count, and the access decision only opens the northbound session when the token is not expired and not reused, and blocks when the token is expired or reused, and the access audit log records the trace number and associates it with the certificate fingerprint; the idempotent control ensures that each session corresponds to only one token, and the rejection reason code is written when rejected.
[0017] Further, the exclusive session window is determined according to the intention fingerprint, granularity and session seed, and is generated in order according to the window number; when different object windows overlap, the first-come-first-served and order extension strategy is used to solve the conflict, and the adjusted window number and object number are uniformly registered in the exclusive window log; each window is associated with a function code whitelist and an access budget count, and when the budget is used up, it is delayed to the next shift for execution, and the whitelist and budget list are associated with the object number.
[0018] Further, when the virtual segment is mapped to a physical channel, the on-off vector is calculated and issued before the exclusive session window reaches a granularity step, and only the target branch is turned on during the window period, and the non-target branch remains high resistance;
[0019] If the switch array read-back and the on-off vector are inconsistent, the window is delayed and reissued, and the issuance result is registered in the on-off record together with the window number and segment number, and at the end of the window, each channel is restored to the default off state, and a record is appended to the exclusive window log.
[0020] Further, the carrier communication performs a session key roll at the beginning of each exclusive session window and generates a rekey number corresponding to the window number;
[0021] The four-eight-five bus only allows messages matching the object-action to go back and forth within the window, remains silent outside the window, and clears the temporary release table at the end. The session key roll record is classified into the rekey record and associated with the subsequent evidence chain as a foreign key. The four-eight-five side directly discards the request without carrying a one-time token.
[0022] Further, the shadow integrity label is generated by combining the intent fingerprint, window starting point, sequential sequence number, and on-off vector in a fixed order. The sequential commitment is generated by combining the previous commitment and the current integrity label and written into the evidence cache.
[0023] When the fingerprint similarity is insufficient or the commitment is not coherent, the record source is inconsistent. The splicing order of the combined field is fixed and consistent in the system. The initial value of the integrity label and the sequential commitment is a preset constant or a device unique initial value, which is fixed in the secure area.
[0024] Further, the minimum impact range is isolated according to the transformer area topology account and the on-off vector. The branch set that meets the isolation requirement and has the least number of branches is selected as the range.
[0025] The first, second, and third treatments are bound to the minimum impact range and executed in the order of branch first and trunk second. When the range only contains the end branch, it is executed within the branch. When it crosses the branch, it is executed in the smallest set that can cut off the propagation. The range, window number, and object number are registered together.
[0026] Further, the double authorization includes two signatures, which are experienced and consistent with the evidence anchor. The evidence anchor is composed of the window number, the tail of the sequential commitment chain, the shadow integrity label, and the one-time token.
[0027] The authorization judgment is only turned on when the signature is valid, not overdue, and the treatment range does not exceed the upper limit. After turning on, the authorization receipt is generated and associated with the evidence chain archive entry. If the conditions are not met, the record rejection reason code is recorded and the previous treatment level is maintained. The code can be retrieved in the authorization audit.
[0028] Further, the evidence chain archive is written in a fixed field order, which contains the intent fingerprint, segment number, window starting point, on-off vector, shadow integrity label, sequential commitment, treatment level, authorization receipt, and timestamp in turn. It establishes a cross index according to the object number and window number, uses a sequential addition only-increase structure, and establishes a foreign key association between the evidence item and the rekey record and bypass mirror record to support replay retrieval by session.
[0029] (Three) beneficial effects
[0030] The application provides a substation edge security linkage method based on a power utilization information collection terminal.
[0031] Through the access decision of the intent fingerprint, the edge security access partition, and the one-time token, the identity and time constraint consistent binding of the main station message is completed before entering the substation terminal, the general service crossing the partition is prevented, the subsequent exclusive session window and virtual segmentation are developed on the unified entrance, the entrance boundary is clear and can be reviewed.
[0032] Through the on-off vector formed by the exclusive session window, the virtual segmentation, and the switch array, the same bus is temporarily converged to one-to-one connection in the key period, and combined with the white list and frequency flow limiting, the carrier session secret exchange and the four-eight-five exclusive session, the frame insertion and contention are inhibited, and the in-segment timing and access order are stable.
[0033] Through the chain proof of the shadow integrity label and the sequential commitment, the replayable order evidence is established without modifying the message, and then the source consistency is verified by the segmentation physical fingerprint, which can give structured judgment basis when replay, impersonation and out-of-order occur, and provide clear trigger conditions for subsequent on-site disposal.
[0034] According to the on-off vector and the substation topology, the minimum influence range is obtained, and the first-level weight reduction, the second-level segmentation isolation, and the third-level bypass mirror are bound and executed according to the range, and at the same time, the encryption, authentication and alarm levels are kept consistent between the carrier and the private network by equivalent migration, and the bearing consistency and continuity in the disposal process are maintained. BRIEF DESCRIPTION OF DRAWINGS
[0035] Figure 1 The application provides a substation edge security linkage method based on a power utilization information collection terminal. DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the application will be clearly and completely described below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, not all the embodiments. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the application.
[0037] Please refer to Figure 1 The application provides a substation edge security linkage method based on a power utilization information collection terminal, which comprises,
[0038] Step one, without changing the prescribed field, complete the extraction and verification of the main station service to the intent fingerprint (object identification, action type and time window description), and generate the corresponding intent fingerprint, establish an encrypted entry, identity verification, token control and access audit in the terminal area terminal, provide a unique and reliable starting point for subsequent exclusive window and segmentation control.
[0039] Establish an encrypted entry, identity verification, token control and access audit in the terminal area terminal, divide the collection entry and control entry into a dual-channel edge security access partition (hereinafter referred to as access partition) in the terminal, and provide a unique and reliable starting point for subsequent exclusive window and segmentation control.
[0040] The busbar of the terminal area is a shared medium. If the entry is not constrained, the session concurrency and control request will be stacked at the port layer, causing problems such as unclear sequence and unclear source. Therefore, semantic extraction, time constraint binding and identity link binding need to be completed before the service enters the busbar, so as to limit the subsequent session arrangement and segmentation control within a determinable boundary.
[0041] After the main station message enters the terminal area terminal, the semantic parser reads only the object and interface meaning to generate an intent fingerprint. Then, certificate verification and encryption chain building are completed in the access partition. On this basis, a one-time token is generated, and the token is bound with the intent fingerprint, time constraint and source identity. Finally, an intent-token list and an access audit log are formed as the input of the second step of scheduling and white list.
[0042] Among them, only the object, action and time window of the main station message are extracted and standardized without adding or deleting original fields. Through clock tracing and constraint comparison, it is confirmed that the intent is not contradictory to the current terminal area topology, operation plan and reading cycle. The extracted results are uniquely characterized to provide a basic identification for subsequent token and partition mapping.
[0043] Further, a service message is received from the main station side, and the syntax rule table completes field positioning to obtain object identification, action type and time window description. To avoid ambiguity caused by format differences of the same service in the uplink path, an irreversible hash is used to form a fingerprint, which is specifically: ;
[0044] In the formula: intent fingerprint : The value is a fixed-length hash digest, which is used for subsequent binding and auditing; anti-collision hash function : The value is a function family that meets the requirements of one-way and anti-collision; object identification : The value is a unique identification set element of the electric energy meter or terminal device; action type : The value is one of reading, event acquisition, breaking and power limiting;
[0045] Time window description : Value is a closed interval consisting of start and end time; additional constraint set : Value is an ordered group of transformer area topology number, job number and priority.
[0046] Semantic parser generates according to rule table , , , , call to get intent fingerprint , write intent fingerprint to admission cache and mark trace number at the same time. The same business in different paths or formats is consistent , thus ensuring the reviewability of subsequent mapping and auditing; unknown or missing fields form empty placeholders to avoid entry ambiguity caused by extraction differences.
[0047] Further, the transformer area terminal determines whether the time window of the main station intent and the transformer area time sequence are consistent according to local time service and reading plan, and then generates a one-time token and binds it with the intent fingerprint. The token is generated by encryption transformation: ;
[0048] In the formula: one-time token : Value is a cipher byte string, which is valid only within the current intent time window; intent fingerprint : Value is a fixed-length hash digest, used for token binding; symmetric encryption transformation : Value is an authenticated block cipher mode of operation; token key : Value is a key material stored in a secure chip; time window normalized description : Value is quantized time slice sequence.
[0049] The terminal cross-compares the local clock with the time service source to form the time window normalized description , and the secure chip issues the token key , completes the generation and registration of the one-time token ; the registration item contains the trace number, certificate chain digest and invalid time. Technical effect: The business is accompanied by a verifiable time constraint and a unique identifier before entering the bus, avoiding misuse of the same action at different time slices; in the subsequent session, the can be directly used as an entry key for verification, reducing repeated analysis.
[0050] The dual-channel access partition is divided inside the terminal, which includes collection entrance and control entrance. All entering sessions must complete certificate verification, token verification and partition mapping. The binding of identity and link is established for registered intention, and general service is prohibited to cross the partition. The terminal establishes encrypted channels for copying and control according to partition rules. In the chain building process, the intention fingerprint and time sequence identifier are bound by using signature operator: ;
[0051] In the formula: binding sequence : the value is signature result, which is used to prove the consistency of the current link and intention; intention fingerprint : the value is a fixed-length hash digest, which is used to participate in signature binding; digital signature operator : the value is an authenticated signature algorithm;
[0052] Signature key : the value is saved in the key material of the security chip; time sequence identifier : the value is the timestamp of the handshake moment; random number : the value is generated by a true random source, which is used to resist replay.
[0053] The terminal first verifies the main station certificate and revocation status, and then establishes collection channel and control channel respectively. The first message of each channel is attached with which is used for identity link binding. After successful binding, the partition state is set to accessed. Identity, time and link are bound by the same signature at the entrance, and the consistency can be verified according to this when subsequent session switching or reconnection occurs. Collection and control partitions do not interfere with each other, avoiding control request through general service.
[0054] Further, all entering requests are judged by the decision function at the partition entrance: ;
[0055] In the formula: admission decision result : the value is or , which is released when ; indication function : the value is when the condition is true, otherwise ; signature verification Boolean quantity : the value is or ; certificate state Boolean quantity : the value is or ; time validity Boolean quantity : the value is obtained by comparing with the current clock; token idempotency Boolean quantity : the value is obtained by checking the token registration table.
[0056] entry decision is when, generate audit records, record items contain intent fingerprints , tokens , binding sequence , partition name and entry time; decision is when, record the reason for rejection and keep the downlink port closed. The release of the access partition has a verifiable evidence chain, and the rejection behavior can also be played back; the idempotent control avoids the same token being used multiple times to cause session replay.
[0057] Step two, build a pseudo-random exclusive session window with a unified object-action-time window as the index, complete the dual-layer decision of virtual segmentation-physical connectivity, form an order within the segment that is schedulable, separable and auditable; On this basis, implement the carrier session rekeying and the 485 exclusive session rules respectively, output the exclusive window log, white list audit record and rekeying record for the next step of abnormal proof and on-site disposal call.
[0058] If the same bus is connected to multiple power meters and the wiring span is large, and if who speaks at what time is not limited and only who is physically connected, frame insertion, collision and timing contention may occur. Therefore, the session needs to be stripped in time through a pseudo-random exclusive window, and the connectivity range needs to be narrowed down in physics through selective connectivity; then, the bearing differentiation protection is added, so that the messages within the same segment converge in time and physics first, and then enter the subsequent order proof and disposal.
[0059] There are two parallel main lines: one is the session arrangement and logical segmentation in the time dimension, with a unified granularity aligned time window as the skeleton, generating an exclusive window sequence according to the intent fingerprint, combining the white list and frequency throttling to form virtual segmentation and exclusive session; the second is the selective connectivity and bearing differentiation protection in the physical dimension, when the exclusive window hits, only the target branch is connected, the rest of the branches remain high resistance, and short-period rekeying and sequence number transition are performed on the carrier communication side, and exclusive session and integrity-timing rules are performed on the 485 side. The two main lines are connected through a unified session identifier, and time-physical convergence is realized within the same window.
[0060] With the intent fingerprint and time window alignment result output in step one as input, for each object-action-time window, an unpredictable but verifiable exclusive window sequence is generated, and only the function code and object access related to the object are allowed to pass within the window period; outside the window, the remaining objects are silenced according to the logical segmentation to avoid competition within the window. The core lies in two points: one is the pseudo-random generation and stable verification of the exclusive window, and the other is the bounded execution of the white list and frequency throttling.
[0061] Generate exclusive window sequence for each object-action-time window, which allows only one object to speak in the same window; the sequence is determined by intent fingerprint, granularity and session seed to ensure that the windows of different objects are distinguishable on the timeline and can be reviewed in subsequent audits. The formal representation is as follows: ;
[0062] Wherein: the start of the window represents the starting time of the th exclusive window, which is the local timeline, defining the window boundary; the intent fingerprint is the fingerprint generated in step one, which is a fixed-length digest, anchoring the time arrangement to a specific intent; the granularity is the local uniform window step, which is a positive real number, consistent with the alignment of step one; the session seed , the fixed random seed of the terminal in the on-duty period, which is the output of the device random source and is fixed in the on-duty period; the generation function is a deterministic pseudo-random sequence generation function, which is a function family that meets the uniformity and reproducibility to ensure that the sequence can be verified.
[0063]
[0064] In the formula: the initial time is the start of the timeline, which comes from time service; the granularity is the window step; the rotation modulus is a positive integer that determines the number of window buckets in the on-duty period; the pseudo-random function is a deterministic pseudo-random function with session seed as the key; is the modulo operator.
[0065] Generate window start sequence by object grouping, resolve overlapping windows according to first-come-first-served and extension strategy; assign each window a unique three-tuple identifier of window number-object number-action type, and write it into the exclusive window log. Exclusive windows divide the timeline into verifiable segments, so that the same bus no longer has multiple objects speaking at the same time; based on the generation method of intent fingerprint and on-duty seed, the window arrangement is unpredictable and reviewable, providing a time reference for subsequent dispute replay and evidence playback.
[0066] When the exclusive window is hit, only the function code and data object access matching the current object-action are released, and the number of times is configured for each object in the shift, and the subsequent window is suspended when the budget is exceeded. The budget is bound to the window granularity to avoid excessive stacking in a single window. A function code whitelist and access budget list are maintained for each object, and when the window arrives, the action to be sent down is matched one by one. If the budget is not exhausted, it is deducted and released; if the budget is exhausted, an audit item is recorded and delayed to the next shift. The whitelist and budget make the conversation in the window contain only the minimum set allowed by the object-action-time window, avoiding irrelevant access; the budget is bound to the granularity, so the frequency of each object conversation in the shift is controllable, thereby reserving a feasible window density for subsequent physical segmentation and bearer protection.
[0067] When the exclusive window is hit, the corresponding object branch is physically connected alone, and the remaining branches remain high resistance, forming a one-to-one transient connection relationship; and differential protection is applied according to the bearer category: the carrier communication performs session rekeying and sequence number transition at the beginning of the window, and the four-eight-five bus performs exclusive session and integrity-timing rules within the window, so that the convergence of time and physical dimensions works together with the bearer security policy.
[0068] The virtual segment-object number is mapped to the on-off vector of the physical channel-switch array when the window arrives, and only the target branch is on and the rest is off; this mapping is indexed by the segment number and remains constant within the same window. The formal representation is as follows:
[0069] ;
[0070] Where: the on-off vector is the physical on-off state of the current window, taking a binary vector, driving the switch array to turn on and off bit by bit; the mapping matrix is a fixed mapping from segment to channel, taking a zero-one matrix, defining the segment-channel relationship; the basis vector is the segment number corresponding to the unit basis, taking a standard unit vector, selecting the target segment; the segment number : taking a natural number, uniquely indicating the current virtual segment.
[0071] An exclusive window arrives one granularity step in advance, calculates the current and obtains the on-off vector , and issues a bit-by-bit on-off instruction to the switch controller; when the window ends, it is restored to the all-off or the instruction set of the next window.
[0072] The selective communication temporarily pulls the multi-point bus into one-to-one at the physical level, and the insertion frame and contention space are compressed to be inaccessible; the time dimension decision of the exclusive window is complementary to each other, so that only the unique object-unique branch connection relationship is reserved in the same window, and a clear boundary is provided for the subsequent order proof.
[0073] Further, at the window opening moment, the carrier communication performs short-period session key rolling (re-keying) and advances the sequence number; the 485 bus performs exclusive session and integrity-timing rule determination within the window, and only allows the round-trip message of the object-action to pass.
[0074] Among them, the session key rolling (carrier re-keying) can be represented as: ;
[0075] Among them, the session key is the key used in the last window, and the session key is the new key of the current window, which is an element of the key space, and is bound to the window and the session; the window start point is the starting time of the current round, which is the local time axis, and provides a time basis for re-keying; the intention fingerprint binds the re-keying to the specific intention as before;
[0076] The update function is a key update function, which takes a key evolution function family to ensure short-term irreconstructibility, ; among them is a key derivation function family (anti-prediction, anti-collision), and the input connection order is fixed.
[0077] The carrier side calls the update function at the window start point to complete the re-keying and record the re-keying number; the 485 side takes the window hit + token carrying as the release condition, and compares the function code and object access item of the round-trip message one by one within the window, and remains silent outside the window; at the end of the window, the carrier side increments the sequence number and closes the key usage right, and the 485 side clears the temporary release table.
[0078] In use, the carrier re-keying makes the sessions in the same window have independent key fingerprints, and the correspondence between the window and the message is clear at the evidence level; the 485 exclusive session only allows the minimum message set of the object-action to run within the window, so that the order in the segment converges from both the physical and time sides.
[0079] Step three, without changing the message, complete the provable determination of whether the order is destroyed in the terminal of the transformer station, and lock the disposal action to the minimum impact range under the same evidence system, while maintaining the security attribute equivalence during bearer switching, so that the subsequent authorization and archiving are established on the basis of consistent and replayable facts.
[0080] The exclusive window and the selective connectivity have converged the intra-session in both time and physical dimensions, but it is still necessary to answer whether the current message is a continuous link of the same session, and whether it comes from the same physical source. Therefore, the integrity label and the sequential commitment are calculated for each window in the end to prove the continuity of the window sequence in a chain manner; and the consistency of the source is checked by the low-dimensional physical fingerprint, so as to determine whether there is replay, insertion, impersonation and out-of-order in a double-evidence parallel manner.
[0081] The exclusive window log and the on-off vector are read by taking the window number-object number-action type as the index, and the current integrity label and the sequential commitment are calculated based on the chain summary of the previous window and the content, timing and on-off state of the current message at the beginning of the window. At the same time, the fingerprint vector of the window is extracted from the physical layer, and the similarity measure is made with the registered baseline. The two-way results are coupled with a threshold to form an abnormality judgment, and the abnormality items and evidence fragments are output for disposal call.
[0082] Among them, at the beginning of each window, the intention fingerprint, the window starting point, the serial number and the on-off vector are irreversibly combined to obtain the integrity label of the current window; then the previous window's sequential commitment and the current integrity label are taken as inputs to obtain a new sequential commitment, which is used to prove the connection relationship between the previous link and the next link: ;
[0083] ;
[0084] In the formula: the integrity label is a fixed-length digest, which is used to define the uniqueness and tamper resistance of the window ; the anti-collision hash function is a function family that meets the one-wayness and extended collision resistance; the intention fingerprint is a fixed-length digest, which runs through steps 1 to 4; the window starting point is the time on the time axis, which comes from step 2;
[0085] the serial number is a strictly increasing integer sequence, which is used for sequential judgment; the on-off vector is a binary vector, which describes the physical connectivity of the window ; the sequential commitment is a fixed-length digest, which represents the chain commitment up to the window .
[0086] The integrity label is calculated at the beginning of the window, and the sequential commitment and the integrity label are generated at the end of the window to generate the sequential commitment and write it into the evidence cache; if Then the sequence commitment is initialized with the agreed starting value .
[0087] The integrity label bundles the key information of each window together, and the sequence commitment chains the window sequence with a chain digest, any insertion, deletion or rearrangement will be immediately reflected on the chain, thus providing a replayable, structured evidence segment for subsequent handling.
[0088] The low-dimensional physical features are collected in the window, the subcarrier energy ratio vector is selected on the carrier side, the steady-state potential and slope statistical vector are selected on the 485 side, and they are normalized to the same feature space to obtain the current fingerprint vector and the registered baseline fingerprint. The similarity is calculated and compared with the threshold; if the similarity is insufficient, it is marked as inconsistent.
[0089] The sampling duration is fixed in the window, the current fingerprint vector is read according to the object number, and the similarity is calculated with the registered baseline fingerprint; if the medium changes, the step two record and the window number are used as an interpolation bridge to complete the fingerprint mapping across media first and then compare; the determination result is written into the abnormal item together with the window number. The physical fingerprint provides a second source of evidence independent of the message, and is independent of the sequence commitment; when both are true, the credibility of the source consistency is significantly improved; when there is a false claim or near-source insertion, even if the message content is reasonable on the surface, the fingerprint will expose the source difference.
[0090] Once the anomaly is established, it needs to be handled within the minimum range, both to avoid expanding the impact and to preserve the evidence continuity for subsequent authorization; when the bearer needs to be switched from the carrier to the private network or from the private network to the carrier, the security attribute must not be degraded, and the constraint strength must not be weakened during the handling process.
[0091] Based on the sequence commitment, integrity label and fingerprint determination, the first level (degraded) is entered first, and if necessary, it is upgraded to the second level (segmented isolation) or the third level (bypass mirror); the minimum impact range is solved by the topology and load image as the constraint; if the bearer is switched, the encryption, authentication and alarm levels are aligned item by item according to the equivalent criterion, so that the handling actions have consistent properties on different bearers.
[0092] To lock the handling in the necessary minimum range, construct the minimum coverage problem: select the smallest node set as the minimum impact range under the premise of meeting the isolation constraint, and bind the set with the handling level:
[0093] ;
[0094] Where: the minimum impact range : the value is a node set, used for bearer handling; candidate set : the value is any subset of : the whole set of controllable nodes : the set of branches that can be isolated in the area; constraint matrix : the zero-one matrix representing the branch-constraint relationship; eigenvector , the zero-one vector of the same dimension as , representing the set ; demand vector : the zero-one vector representing the isolation demand to be met; : the partial order relation not less than each component.
[0095] According to the on-off vector and the topological account, the constraint matrix is constructed and the demand vector , the above problem is solved by greedy or branch and bound to obtain ; when the anomaly only affects the terminal branch, the minimum impact range is the branch; when the impact spans branches, the minimum impact range is the smallest branch set that can cut off the propagation of the anomaly; then the first level (degraded weight), the second level (segment isolation), and the third level (bypass mirror) are bound to the minimum impact range .
[0096] When used, the solution formalizes the minimization of the treatment range, avoiding empirical circle expansion; the hierarchical action is bound, so that the same anomaly has a clear and consistent boundary under different topologies.
[0097] When the session migrates from the carrier to the private network or migrates back from the private network to the carrier, check whether the encryption, authentication, and alarm levels meet the non-degradation condition according to the equivalence criterion, and record the mapping relationship after the migration is completed, so as to interface with the evidence chain:
[0098] ;
[0099] In the formula: equivalence criterion : the value is or , which represents that the attribute is not degraded when ; weight matrix : the value is a diagonal or semi-positive definite matrix, used for item-by-item weighting; attribute vector before migration , the value is an ordered vector of encryption strength, identity authentication level, and alarm level; attribute vector after migration , the value is of the same type as ; : the partial order relation not greater than each component; : indicator function, condition true , otherwise .
[0100] Read the carrier change record and window number at the migration trigger point, generate the migration transaction number; calculate the attribute vector before migration and the attribute vector after migration and bring it into the criterion, if then register the migration mapping and release the subsequent window; if then back up to the previous bearer or upgrade the attribute configuration of the latter until it meets the requirements.
[0101] The equivalence criterion turns the non-downgrade of attributes from an oral constraint into a determinable condition, ensuring that the handling intensity and evidence semantics remain consistent during bearer switching. Among them, the weight matrix can be set to a unit matrix or a diagonal matrix that emphasizes a certain component according to the scene, and the attribute vector can be extended to include session delay or log retention level, all of which retain the semantics of non-downgrade.
[0102] Step four, based on the principles of evidence priority and constraint priority, complete the dual authorization and time limit control of the action involved in the control, solidify the chain evidence and correspond to the window, token, and sequential commitment; at the same time, establish a rotation mechanism for northbound keys and certificates and a triple guarantee of integrity-trust domain-rollback for remote upgrade, ultimately forming a long-term operation and maintenance order that is auditable, traceable, and accountable.
[0103] The action involved in the control directly affects the user side, and must be based on the evidence first and the minimum impact range as the boundary.
[0104] To avoid problems such as single signature, overtime execution, and out-of-bound execution, the effectiveness, time constraints, and range constraints of the two signatures need to be combined into a criterion; and the entire process of release or rejection is solidified into a chain of evidence, allowing subsequent audits to be played back according to the window and commitment chain.
[0105] The window number, sequential commitment chain tail, shadow integrity tag, and one-time token form the evidence anchor, which is the binding object for dual authorization verification and judgment. First, verify the two signatures one by one and check the validity period, then check if the disposal is limited to the minimum impact range; if all conditions are met, execute the release and generate an authorization receipt, otherwise reject and record the reason; regardless of release or rejection, the new event is appended to the end of the evidence chain, and the chain tail digest and receipt number are output.
[0106] Among them, the authorization judgment quantity is constructed, requiring both signatures to be valid, time not to exceed the limit, and disposal range not to exceed the intersection of the minimum impact range and the upper limit range:
[0107] ;
[0108] In the formula: the judgment quantity is valued at or , and acts as the only condition for release or not.
[0109] Verify function : Value is a digital signature verification process, function is to verify the consistency of the signature and the evidence anchor , using existing public digital signature algorithm and certificate chain verification process to achieve, here not limited to specific algorithm, only limited to its input is the evidence anchor and signature, output is the signature validity determination result, and the result is used for subsequent access decision and double authorization determination;
[0110] Signature : Value is the signature object on the two signed files, which proves the binding of the source and content; evidence anchor : Value is the ordered combination of window number, sequence commitment chain tail, shadow integrity label, and one-time token, function is to uniformly bind authorization and previous evidence; time delay : Value is the time interval from signature generation to execution determination, function is time limit check; threshold : Value is the maximum time delay allowed by authorization, function is to avoid expired execution; minimum impact range set : Value is the segmented set obtained in step three that needs to be isolated, function is to handle the boundary; upper limit range : Value is the maximum reachable range configured by the policy, function is to prevent out-of-bound.
[0111] When the determination quantity , the terminal executes control according to the recovery sequence of the main line first and the branch line second and generates an authorization reply; when the determination quantity , the terminal refuses to execute and writes the rejection reason as an event into the evidence chain.
[0112] Double verification and time-range synthesis make the release behavior meet the three constraints of correct source, time not expired, and range limited; the same evidence anchor is associated with the previous window and commitment chain, ensuring that authorization is consistent with on-site facts.
[0113] Further, to realize audit playback, events-policy-disposal-authorization-result are packaged as evidence blocks and chained: ;
[0114] In the formula: evidence block digest : Fixed-length digest, function is the current chain tail of the evidence chain; hash function : Anti-collision hash family, function is to ensure non-tamperability; previous block digest : Fixed-length digest, function is to form a chain connection; event digest : Event content digest of this release or rejection, function is to record behavior;
[0115] Window number : Window number for exclusive use, used to bind with time boundary; tail of commitment chain : Value is the tail digest of the sequence commitment of this window, used to bind with in-segment order; one-time token : Value is the token generated in step one, used to bind with intent-action-time window.
[0116] Generate evidence block digest immediately after each determination And write it into the evidence chain archive together with the authorization reply number. The archive adopts a sequential append-only structure and establishes a cross-index (search by object number, window number). The evidence block combines the evidence anchor and the authorized behavior into a single, replayable chain record. Any subsequent changes will be amplified and displayed on the chain;
[0117] The sequential append-only structure ensures that the archiving process is simple and can be implemented.
[0118] After the disposal closed loop is completed, the four dimensions of long-term running key-certificate-upgrade-accounting need to be included in the same evidence view: when the abnormal frequency is high or the time reaches the upper limit, the key and certificate are rotated; in the upgrade scenario, use signature verification and the smallest trust domain to ensure that no new uncertainty is introduced; finally, output the comparison items of clauses-technical mechanisms-evidence according to the regulatory provisions.
[0119] The rotation trigger degree is synthesized by the sliding aggregation of abnormal scores and time factors; when the trigger degree exceeds the threshold, the rotation is performed and the rotation transaction is written into the evidence chain; when upgrading, first verify the upgrade package and the list, then write it to a small range of mirrors, fail to roll back, and succeed to append the evidence block; the clause accounting is based on the field mapping and report generation of the evidence chain.
[0120] ;
[0121] : Abnormal score, non-negative real number; : Decay factor, ; : Synthesis length; positive integer, : Original abnormal quantity; the weighted sum of integrity failure weight, commitment chain breakage weight, and fingerprint inconsistency weight.
[0122] Among them, the rotation trigger degree is synthesized by the sliding aggregation of the time interval since the last rotation, the abnormal intensity, and the authorized use intensity, and according to this, it is determined whether to start the rotation: ;
[0123] In the formula: rotation trigger degree : Value is a non-negative real number, used as the only basis for rotation;
[0124] Synthesis function : value is a monotonic function with public reproducible value (piecewise linear or smooth convex function), function is to unify the three dimensionless quantities; time interval : value is a non-negative real number, function is to reflect the time interval since the last rotation; abnormal intensity : value is a non-negative real number, function is to slide aggregation of abnormal score; authorized use intensity : value is a non-negative integer, function is to represent the use intensity of the control action in this period.
[0125] When the rotation trigger degree exceeds the set threshold, the rotation transaction is triggered, and the terminal generates a rotation mapping with the new and old certificate fingerprints and key fingerprints, checks that the three items of encryption strength, identity authentication level, and log retention level are not lower than the current level (no downgrade check), and then completes the replacement within a short maintenance window; after the rotation is completed, write into the evidence chain.
[0126] The specific form of the synthesis function :
[0127] ;
[0128] : time interval since the last rotation; non-negative real number; : sliding aggregation of abnormal intensity (can take or its smooth value);
[0129] : authorized use intensity (control action count in this period); : non-negative weight, and can be normalized; : normalized scale; : trigger threshold. Online calculation , if , execute certificate and key rotation in the maintenance window and write chain.
[0130] Combine time and risk-load three factors into a single trigger degree, taking into account periodic rotation and abnormal trigger rotation; no downgrade check ensures consistent strength of rotation-disposal-evidence three lines. Equivalent embodiments: sliding aggregation can use exponential decay or bounded integral form, and the threshold can be configured according to the operation strategy.
[0131] In the upgrade scenario, use the sequence of signature verification-minimal trust domain writing-failure rollback, and write the upgrade event into the evidence chain; at the same time, based on the evidence chain field, output the clause account report: ;
[0132] In the formula: upgrade decision quantity : value is or , function is the condition of whether to execute the upgrade; hash function : same as above, function is to calculate the upgrade package and the digest of the list, without limiting the specific hash algorithm implementation form, only limiting the input of the hash function to be the data field of the explicit splicing order, and the output is a fixed length hash value, which is used as the basis data for identification, integrity check and chain connection.
[0133] Upgrade package : the value is a binary image, and the function is to write the content; list : the value is an upgrade list, and the function is to record the target version and the writing range; digest : the value is a fixed-length digest, and the function is to associate with the signature verification result; certificate chain verification : the value is a Boolean, and the function is to check the root of trust and verify the signature; minimum trust domain check : the value is a Boolean, and the function is to verify that only the image partition is written and no boundary is crossed.
[0134] When the upgrade decision quantity , first write in the image partition, and switch the startup flag after writing is completed; if the verification fails or an abnormality occurs, roll back to the previous image and write the failure event into the evidence chain; after successful upgrade, append the upgrade success evidence block, including the window number, the chain tail commitment, the upgrade digest, and the signature fingerprint. In the clause reconciliation phase, the encrypted channel, double authorization, built-in probe, log retention, rotation record, and upgrade record in the evidence chain are mapped to the regulatory clauses one by one, and the clause-technology mechanism-evidence reconciliation report is output. Further, the three safeguards control the upgrade risk in the image partition and the switching instant, without touching the running partition; the failure rollback and the evidence addition make the upgrade a recoverable and traceable process; and the clause reconciliation translates the technology mechanism into auditable items.
[0135] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0136] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0137] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. For example, the division of the above-described device embodiment is only a logical function division, and there can be another division manner for actual implementation, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections between different units, or the among different units, can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0138] The units described as separated components can or can not be physically separated, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.
[0139] The above describes only specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for safety linkage at the edge of a transformer substation based on an electricity consumption information collection terminal, characterized in that: include, Only read the objects, actions, and time windows of the main station messages to generate intent fingerprints, establish edge security access partitions, complete access control with certificate verification and one-time tokens, set the northbound session status according to the access control decision, and record access audit logs; Based on the intent fingerprint and time window, an exclusive session window is generated and whitelisting and frequency limiting are implemented; during the window period, the bus is mapped to a virtual segment, and the switch array is driven to generate on / off vectors according to the segment number to achieve selective connectivity and generate a window number corresponding to the window. Within the window, calculate the shadow integrity label and sequence commitment and associate them with the on / off vector. Collect segmented physical fingerprints to compare with the registration baseline. Based on this, determine the treatment level and solve the minimum impact range. Generate bypass mirror records and equivalent migration mappings. For actions involving control, determine the authorization based on dual authorization, time limits, and scope conditions, and output an authorization receipt; Generate an evidence chain archive using window number, sequential commitment, and one-time token, and perform integrity, trust domain, and rollback verification for northbound key and certificate rotation and remote upgrades; Exclusive session windows are determined based on intent fingerprints, granularity, and session seeds, and are generated in order of window numbering. When different object windows overlap, a first-come-first-served and deferred strategy is used to resolve the conflict, and the adjusted window number and object number are uniformly registered in the exclusive window log. Each window is associated with a function code whitelist and access budget count. When the budget is exhausted, execution is delayed until the next shift. The whitelist and budget list are associated with the object number. The shadow integrity label is generated by combining the intent fingerprint, window start point, sequence number and pass / fail vector in a fixed order. The sequential commitment is generated by combining the previous commitment with the current integrity label and written into the evidence cache. When fingerprint similarity is insufficient or commitments are inconsistent, record inconsistent sub-items from different sources. The concatenation order of combined fields is fixed in the system and kept consistent. The initial values of integrity labels and sequence commitments are preset constants or device-unique initial values, and are fixed in the secure area. The minimum impact range is determined by establishing isolation constraints based on the transformer area topology ledger and the connectivity vector, and selecting the set of branches that meets the isolation requirements and has the fewest number of branches as the range. Level 1, Level 2, and Level 3 actions are each bound to the minimum impact range for execution, and are restored in the order of branch lines first and then trunk lines. When the range only includes the terminal branch, it is executed within that branch. When it crosses branches, it is executed within the smallest set that can cut off the propagation. The range, window number, and object number are registered together.
2. The method for security linkage at the edge of a transformer substation according to claim 1, characterized in that: The edge security access partition distinguishes between the collection entry point and the control entry point. For packets entering the partition, certificate chain verification, revocation status check and one-time token verification are performed in sequence. Built-in probes are enabled to record access events and partition boundary crossing requests. The records are written to the access audit log, and a one-to-one correspondence between session identifier and intent fingerprint is established. The correspondence is called when the window is allowed in the future to maintain consistency.
3. The method for security linkage at the edge of a transformer substation according to claim 2, characterized in that: One-time tokens are bound one-to-one with intent fingerprints, window numbers and source identities. Tokens include expiration time and replay count. Admission decisions only enable northbound sessions when the token has not expired and has not been reused. They are blocked when timeout or replay is detected. The source number is registered in the access audit log and associated with the certificate fingerprint. Idempotent control ensures that each session corresponds to only one token. When a session is rejected, a rejection reason code is written.
4. The method for security linkage at the edge of a transformer substation according to claim 3, characterized in that: When virtual segments are mapped to physical channels, the on / off vector is calculated and sent out before the exclusive session window reaches the previous granularity step size. During the window period, only the target branch is turned on, and non-target branches are kept at high impedance. If the switch array readback is inconsistent with the on / off vector, the window is delayed and reissued. The reissue result, window number, and segment number are recorded in the on / off record. When the window ends, each channel is restored to the default off state, and a record is appended to the exclusive window log.
5. The method for security linkage at the edge of a transformer substation according to claim 4, characterized in that: Carrier communication performs session key rolling and generates a password change number at the beginning of each exclusive session window, and establishes a correspondence between the password change number and the window number. The 485 bus only allows messages that match the object-action pairing to travel back and forth within the window, remains silent outside the window, and clears the temporary release table when it ends. The session key rolling record is incorporated into the key exchange record and established with a foreign key association with the subsequent evidence chain. The 485 side directly discards requests that do not carry a one-time token.
6. The method for security linkage at the edge of a transformer substation according to claim 5, characterized in that: Dual authorization includes two separate signatures that are verified and consistent with the evidence anchor. The evidence anchor consists of a window number, the end of the sequential commitment chain, a shadow integrity tag, and a one-time token. The authorization decision is made only when the approval is valid, the time limit has not expired, and the scope of disposal does not exceed the upper limit. After being made authorized, an authorization receipt is generated and associated with the evidence chain archived item. If the conditions are not met, the rejection reason code is recorded and the previous disposal level is maintained. The code can be retrieved in the authorization audit.
7. The method for security linkage at the edge of a transformer substation according to claim 6, characterized in that: The evidence chain archive is written in a fixed field order, including intent fingerprint, segment number, window start point, access vector, shadow integrity label, sequence commitment, disposition level, authorization receipt and timestamp. A cross-index is established by object number and window number, and a sequential append-only structure is adopted. Foreign key associations are established between evidence items and password change records and bypass mirror records to support session replay retrieval.
Citation Information
Patent Citations
Civil aircraft field service operation scheduling control system
CN120915808A
Government administration department knowledge base access authority control method based on block chain
CN121098508A