A power information dynamic encryption cooperative protection method and system

By employing protocol-adaptive dynamic encryption, distributed threat awareness, and redundant storage technologies, the system addresses the issues of rigid encryption, delayed response, and weak data resilience in power information security protection systems. This enables flexible encryption and rapid response in power systems, ensuring the security and reliability of data transmission.

CN121309221BActive Publication Date: 2026-05-15BEIJING QIANRUNHE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING QIANRUNHE TECH CO LTD
Filing Date
2025-12-10
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing power information security protection systems suffer from rigid encryption mechanisms, delayed security responses, lack of coordination in protection strategies, and weak data resilience, making it difficult to meet the security and reliability requirements of modern power systems.

Method used

By employing protocol-adaptive dynamic encryption, distributed collaborative threat awareness, adaptive traffic filtering, and redundant verification storage, and by deploying a protocol stack deep parsing engine, hardware probe nodes, and redundant memory arrays, dynamic encryption algorithm matching, rapid threat response, and data consistency assurance are achieved.

Benefits of technology

It improves the flexibility and security of encryption, enables rapid response to high-frequency data interaction needs, ensures the stability and reliability of data transmission, reduces false alarms of abnormal traffic, achieves zero-trust protection, and improves the security and operational efficiency of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121309221B_ABST
    Figure CN121309221B_ABST
Patent Text Reader

Abstract

The application relates to a power information dynamic encryption cooperative protection method and system, and relates to the technical field of power communication security protection, and comprises the following steps: protocol adaptive dynamic encryption: through a protocol stack depth analysis engine arranged in a power terminal gateway, a protocol header field of a communication message is analyzed in real time, a protocol type identifier, a data packet length and a priority sign are extracted; a preset encryption algorithm mapping table is matched according to the protocol type identifier, an encryption algorithm is dynamically selected, and an elliptic curve dynamic segmentation mechanism ECDSA-Segment is adopted based on device performance grading; through the dynamic encryption engine, the encryption algorithm is automatically matched and the key fragments are updated according to actual communication requirements, the flexibility and security of encryption are improved, the demand of high-frequency data interaction can be quickly responded, and the consistency and reliability of data are ensured through a redundant check memory array, so that data loss and damage are prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power communication security protection technology, and in particular to a dynamic encryption collaborative protection method and system for power information. Background Technology

[0002] With the rapid development of smart grid construction and the energy internet, the network architecture of power systems is showing a trend towards high complexity and ubiquitous interconnection. The number of intelligent terminal devices in all aspects of power generation, transmission, substation, distribution, and consumption has surged, and high-frequency, real-time, and multi-source data interaction has become the foundation for supporting stable grid operation and intelligent decision-making. However, while the dynamic flow of massive amounts of data improves system efficiency, it also significantly expands the attack surface, making power information systems face increasingly severe security threats, including data theft, protocol hijacking, and denial-of-service attacks. Traditional security protection systems have exposed a series of structural defects in dealing with new dynamic threats, becoming a bottleneck restricting the high-reliability operation of power systems.

[0003] Existing technologies have the following shortcomings: Current mainstream power information security protection systems generally adopt a static, centralized, and rule-based technical approach, which still suffers from the following defects:

[0004] 1. Rigid encryption mechanisms: They rely heavily on fixed algorithms such as RSA and AES and pre-allocated key strategies, with key update cycles lasting for hours or even days. However, the operating conditions of power systems change rapidly, such as sudden load changes and transient faults. Static encryption cannot dynamically adapt to different risk levels, resulting in insufficient security redundancy for highly sensitive data transmission or over-encryption of low-risk data.

[0005] 2. Delayed Security Response: Security analysis heavily relies on a central server to centrally process network traffic, resulting in significant delays in data transmission and decision-making. When facing rapidly spreading threats such as APT attacks and zero-day vulnerabilities, the time from attack identification to policy implementation often exceeds minutes, making it difficult to meet the mandatory "second-level response" requirement in the "Regulations on Security Protection of Power Monitoring Systems."

[0006] 3. Lack of coordination in protection strategies: Traffic filtering rules are preset based on historical threat characteristics and adjustments require manual intervention. In complex power grid environments such as new energy fluctuation access and dynamic topology reconfiguration, fixed rules are prone to causing false interception of normal control commands and even malfunction of protection devices. At the same time, due to the heterogeneity of protocols, it is difficult to achieve unified adaptation of key strategies for cross-vendor terminal devices.

[0007] 4. Weak Data Resilience: Employing single storage redundancy mechanisms such as primary / standby replicas or RAID lacks dynamic redundancy scheduling capabilities based on business continuity. In the event of ransomware attacks or regional failures, it is difficult to guarantee the real-time consistency and rapid recoverability of critical data.

[0008] Existing protection systems are inadequate in addressing the security challenges of modern power systems. For example, application number CN202510442499.X discloses a method and device for dynamic adjustment of data keys for power information security protection, which can, to some extent, cope with the challenges brought about by the complex and ever-changing operating environment of power systems and improve data security and system reliability. However, it still fails to fully solve the problems of high response latency, rigid encryption protocols, and poor cross-device compatibility in traditional security protection systems. Therefore, there is an urgent need for a new dynamic encryption collaborative protection method and system for power information to meet the security and reliability requirements of modern power systems.

[0009] The information disclosed in the background section is only intended to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0010] To address the shortcomings of existing technologies, this invention provides a dynamic encryption collaborative protection method and system for power information, which solves the problems mentioned in the background section.

[0011] To achieve the above objectives, the present invention provides a method for dynamic encryption and collaborative protection of power information, comprising the following steps:

[0012] S1. Protocol Adaptive Dynamic Encryption: Through the protocol stack deep parsing engine deployed on the power terminal gateway, the protocol header field of the communication message is parsed in real time to extract the protocol type identifier, data packet length and priority flag; the encryption algorithm is dynamically selected according to the protocol type identifier by matching the preset encryption algorithm mapping table, and the elliptic curve dynamic segmentation mechanism ECDSA-Segment is adopted based on the device performance classification.

[0013] S2, Distributed Collaborative Threat Awareness: Hardware probe nodes are deployed at the edge layer of the substation. The probe nodes build a P2P network through the blockchain-style state synchronization protocol BSP. When any probe detects that the threat index exceeds the threshold, a collaborative response chain of all probes in the network is triggered.

[0014] S3, Adaptive Traffic Filtering: A lightweight filtering module is implanted in the L4 transport layer of the TCP / IP protocol stack to dynamically adjust the allow threshold based on the threat index and perform fast channel rerouting on mistakenly blocked data packets;

[0015] S4. Data Resilient Storage and Recovery: A redundant parity memory array is constructed using 3DXPoint non-volatile storage media. The redundant parity memory array includes a main channel and a secondary channel, which are used to write the original encrypted data and an LZ4 compressed copy verified by CRC32C, respectively. Data consistency is then ensured by constructing a Merkle hash tree.

[0016] Optionally, the dynamic selection of encryption algorithm in step S1 includes enabling the AES-256 algorithm when the protocol identifier is IEC 61850 GOOSE message, and enabling the national cryptographic SM4 algorithm when the protocol identifier is DL / T 645-2007 electricity meter protocol.

[0017] In step S1, an elliptic curve dynamic segmentation mechanism ECDSA-Segment is adopted based on the equipment performance classification. This includes updating the complete key for high-performance PLC equipment every 15 minutes, distributing key fragments to low-performance RTU equipment, with each fragment being ≤512 bits, and generating a valid key by combining the fragments through the key control center.

[0018] Optionally, the implementation steps of the elliptic curve dynamic segmentation mechanism in step S1 are as follows:

[0019] Central preset parameters: The key control center generates the reference elliptic curve parameters, including the prime field. Base point Private key segmentation number ;

[0020] Device-specific segment: For the first Each terminal device calculates an asymmetric key segment based on its device ID and time slot. The formula for calculating the key segment is as follows: In the formula, Represented as an elliptic curve for calculating the first... Scalar of key fragments for each terminal device Represented as the system's base private key, and a 256-bit integer, the master key. This is represented as the dot product operation on elliptic curves. Represented as the SHA-256 hash function, Represented as the first The ID of each terminal device, This is represented as a byte concatenation operation. This represents the time slot number corresponding to the current time period;

[0021] Terminal synthesis verification: The i-th terminal device generates a valid key by weighting the fragments according to security level, where the formula for calculating the valid key is as follows: ,and In the formula, This represents the final valid private key generated by the i-th terminal. This is represented as the security level weight of the terminal device. Represented as the first The scalar of the j-th key fragment generated by the terminal device. Represented as modular arithmetic in a finite field. It is represented as an elliptic curve prime field.

[0022] Optionally, the operation steps of the blockchain-based state synchronization protocol BSP in step S2 are as follows:

[0023] Periodic initialization: Set a fixed synchronization period Each probe maintains a local threat fingerprint database. ;

[0024] Differential hash calculation: The differential hash is calculated at the beginning of the period, and the formula for calculating the differential hash is as follows: In the formula, Represented as a difference hash, This is represented as a bitwise XOR operation, used for efficiently identifying differing bits. This represents the fingerprint database from the previous synchronization cycle. Represented as the SHA-256 hash function;

[0025] Neighbor broadcast: Broadcast to neighboring probe nodes ;

[0026] Inverse difference solution: receiving neighbor's The newly added feature set is then obtained by inverse analysis using a Bloom filter, where the expression for the newly added feature set is: In the formula, This represents a set of newly added threat features. This is represented as the inverse mechanism of a Bloom filter;

[0027] Fingerprint database update: The expression for updating the fingerprint database is In the formula, This indicates an update to the fingerprint database. This is represented as a set union operation.

[0028] Optionally, the steps for generating the dynamic whitelist rules in step S3 are as follows:

[0029] Constructing rule vectors: In the formula, This is represented by the historical credibility of the source IP. This is represented as the attenuation coefficient for false interception. Represented as real-time threat confidence. Represented as a dynamic whitelist rule vector;

[0030] Calculate the release threshold: In the formula, This is represented as the dynamic release threshold;

[0031] Traffic credibility assessment: Real-time calculation based on traffic characteristics In the formula, This is represented as a traffic credibility score;

[0032] Judgment execution: .

[0033] Optionally, the data consistency verification step in step S4 is as follows:

[0034] Damaged block location: Damaged block index is detected using a Merkle tree;

[0035] Copy verification: Read the compressed copy from the secondary channel, decompress it, and calculate the checksum. In the formula, This is represented as decompressed data. This is represented as the secondary channel replica check value. This represents the CRC checksum of the main channel.

[0036] Consistency verification: ;

[0037] Merkle tree update: In the formula, This indicates updating the Merkle tree. Represented as the hash of the repaired data block. Represented as the sibling node hash. This is represented as a byte concatenation operation.

[0038] A dynamic encryption collaborative protection system for power information includes a dynamic encryption engine, a distributed probe network, an adaptive filtering pipeline, and a redundant verification memory array. The dynamic encryption engine is deployed on a power terminal gateway and includes a protocol parsing unit, an algorithm matching unit, and a key segmentation and distribution unit.

[0039] The distributed probe network deploys hardware probe nodes at the substation edge layer, and a P2P topology is formed by several hardware probe nodes. Each probe integrates a traffic modeling chip and a BSP communication module.

[0040] The adaptive filtering pipeline is embedded in the L4 layer filtering module of the operating system kernel, and has a built-in dynamic rule engine and rerouting controller.

[0041] The redundant check memory array uses a dual-channel storage device with 3DXPoint media and integrates a hash tree manager and a CRC checker.

[0042] Optionally, the algorithm matching unit in the dynamic encryption engine includes a protocol feature register, an algorithm lookup table (LUT), and a key fragment buffer, wherein the protocol feature register is used to store the power protocol header feature codes of IEC 61850 and DL / T 645.

[0043] The algorithm lookup table (LUT) uses the protocol signature as an index and outputs the encryption algorithm ID and the initialization vector (IV).

[0044] The key fragment buffer is used to temporarily store elliptic curve key fragments to be distributed;

[0045] The dual-channel architecture of the redundancy check memory array includes a main channel controller, a secondary channel compression engine, and a hash tree coprocessor, wherein the main channel controller directly writes encrypted data and triggers CRC calculation;

[0046] The secondary channel compression engine performs LZ4 compression and CRC32C verification in real time.

[0047] The hash tree coprocessor generates data block hashes in parallel and constructs a Merkle tree.

[0048] A computer device includes: a memory and a processor; the memory stores a computer program, and the processor executes the computer program to implement the steps of the above-described dynamic encryption collaborative protection method for power information.

[0049] A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the above-described dynamic encryption collaborative protection method for power information.

[0050] In summary, this application includes at least one of the following beneficial technical effects:

[0051] 1. This invention employs a dynamic encryption engine to automatically match encryption algorithms and update key fragments according to actual communication needs, thereby improving the flexibility and security of encryption and enabling rapid response to the demands of high-frequency data interaction. Furthermore, the redundant verification memory array ensures data consistency and reliability, preventing data loss and damage. Simultaneously, the system's collaborative protection and dynamic adjustment mechanisms can promptly address various security threats, ensuring the stable operation of the power system and improving the efficiency and security of data processing.

[0052] 2. Through a distributed probe node network, rapid extraction of packet behavior features and synchronization of the attack feature fingerprint database are achieved, enabling timely detection and prevention of various attacks; the adaptive traffic filtering pipeline reduces false alarms of abnormal traffic and improves the accuracy of traffic filtering by using dynamic whitelist rules and real-time adjustment of allowance thresholds.

[0053] 3. By employing a variety of technical means such as dynamic encryption, collaborative analysis, adaptive traffic filtering, and redundancy verification, comprehensive protection is provided for the transmission of power information, ensuring that only authorized users and devices can access and transmit data, thus realizing the concept of zero-trust protection. Attached Figure Description

[0054] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0055] Figure 1 This is a flowchart illustrating the dynamic encryption and collaborative protection method for power information according to the present invention.

[0056] Figure 2 This is a schematic diagram of the modules of the dynamic encryption and collaborative protection system for power information of the present invention. Detailed Implementation

[0057] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, they are provided so that the description of this disclosure will be more complete and fully convey the concept of the exemplary embodiments to those skilled in the art.

[0058] Example 1

[0059] This invention provides, for example Figure 1 The power information dynamic encryption collaborative protection method shown includes the following steps:

[0060] S1. Protocol Adaptive Dynamic Encryption: Through the protocol stack deep parsing engine deployed on the power terminal gateway, the protocol header field of the communication message is parsed in real time to extract the protocol type identifier, data packet length and priority flag; the encryption algorithm is dynamically selected according to the protocol type identifier by matching the preset encryption algorithm mapping table, and the elliptic curve dynamic segmentation mechanism ECDSA-Segment is adopted based on the device performance classification.

[0061] S2, Distributed Collaborative Threat Awareness: Hardware probe nodes are deployed at the edge layer of the substation. The probe nodes build a P2P network through the blockchain-style state synchronization protocol BSP. When any probe detects that the threat index exceeds the threshold, a collaborative response chain of all probes in the network is triggered.

[0062] S3, Adaptive Traffic Filtering: A lightweight filtering module is implanted in the L4 transport layer of the TCP / IP protocol stack to dynamically adjust the allow threshold based on the threat index and perform fast channel rerouting on mistakenly blocked data packets;

[0063] S4. Data Resilient Storage and Recovery: A redundant parity memory array is constructed using 3DXPoint non-volatile storage media. The redundant parity memory array includes a main channel and a secondary channel, which are used to write the original encrypted data and an LZ4 compressed copy verified by CRC32C, respectively. Data consistency is then ensured by constructing a Merkle hash tree.

[0064] Furthermore, the dynamic selection of encryption algorithms in step S1 includes enabling the AES-256 algorithm when the protocol identifier is IEC61850 GOOSE message, and enabling the national cryptographic SM4 algorithm when the protocol identifier is DL / T 645-2007 electricity meter protocol.

[0065] In step S1, an elliptic curve dynamic segmentation mechanism ECDSA-Segment is adopted based on the equipment performance classification. This includes updating the complete key for high-performance PLC equipment every 15 minutes, distributing key fragments to low-performance RTU equipment, with each fragment being ≤512 bits, and generating a valid key by combining the fragments through the key control center.

[0066] To further explain, the implementation steps of the elliptic curve dynamic segmentation mechanism in step S1 are as follows:

[0067] Central preset parameters: The key control center generates the reference elliptic curve parameters, including the prime field. Base point Private key segmentation number ;

[0068] Device-specific segment: For the first Each terminal device calculates an asymmetric key segment based on its device ID and time slot. The formula for calculating the key segment is as follows: In the formula, Represented as elliptic curve calculation of the first Scalar of key fragments for each terminal device Represented as the system's base private key, and a 256-bit integer, the master key. This is represented as the dot product operation on elliptic curves. Represented as the SHA-256 hash function, Represented as the first The ID of each terminal device, This is represented as a byte concatenation operation. This represents the time slot number corresponding to the current time period;

[0069] Terminal synthesis verification: The i-th terminal device generates a valid key by weighting the fragments according to security level, where the formula for calculating the valid key is as follows: ,and In the formula, This represents the final valid private key generated by the i-th terminal. This is represented as the security level weight of the terminal device. Represented as the first The scalar of the j-th key fragment generated by the terminal device. Represented as modular arithmetic in a finite field. It is represented as an elliptic curve prime field.

[0070] To further explain, the operation steps of the blockchain-based state synchronization protocol BSP in step S2 are as follows:

[0071] Periodic initialization: Set a fixed synchronization period Each probe maintains a local threat fingerprint database. ;

[0072] Differential hash calculation: The differential hash is calculated at the beginning of the period, and the formula for calculating the differential hash is as follows: In the formula, Represented as a difference hash, This is represented as a bitwise XOR operation, used for efficiently identifying differing bits. This represents the fingerprint database from the previous synchronization cycle. Represented as the SHA-256 hash function;

[0073] Neighbor broadcast: Broadcast to neighboring probe nodes ;

[0074] Inverse difference solution: receiving neighbor's The newly added feature set is then obtained by inverse analysis using a Bloom filter, where the expression for the newly added feature set is: In the formula, This represents a set of newly added threat features. This is represented as the inverse mechanism of a Bloom filter;

[0075] Fingerprint database update: The expression for updating the fingerprint database is In the formula, This indicates an update to the fingerprint database. This is represented as a set union operation.

[0076] To further clarify, the steps for generating the dynamic whitelist rules in step S3 are as follows:

[0077] Constructing rule vectors: In the formula, This is represented by the historical credibility of the source IP. This is represented as the attenuation coefficient for false interception. Represented as real-time threat confidence. Represented as a dynamic whitelist rule vector;

[0078] Calculate the release threshold: In the formula, This is represented as the dynamic release threshold;

[0079] Traffic credibility assessment: Real-time calculation based on traffic characteristics In the formula, This is represented as a traffic credibility score;

[0080] Judgment execution: .

[0081] To further clarify, the data consistency verification steps in step S4 are as follows:

[0082] Damaged block location: Damaged block index is detected using a Merkle tree;

[0083] Copy verification: Read the compressed copy from the secondary channel, decompress it, and calculate the checksum. In the formula, This is represented as decompressed data. This is represented as the secondary channel replica check value. This represents the CRC checksum of the main channel;

[0084] Consistency verification: ;

[0085] Merkle tree update: In the formula, This indicates updating the Merkle tree. Represented as the hash of the repaired data block. Represented as the sibling node hash. This is represented as a byte concatenation operation.

[0086] Example 2

[0087] This invention provides, for example Figure 2 The power information dynamic encryption collaborative protection system shown includes a dynamic encryption engine, a distributed probe network, an adaptive filtering pipeline and a redundant verification memory array. The dynamic encryption engine is deployed on the power terminal gateway and includes a protocol parsing unit, an algorithm matching unit and a key segmentation and distribution unit.

[0088] The distributed probe network deploys hardware probe nodes at the substation edge layer, and a P2P topology is formed by several hardware probe nodes. Each probe integrates a traffic modeling chip and a BSP communication module.

[0089] The adaptive filtering pipeline is embedded in the L4 layer filtering module of the operating system kernel, and has a built-in dynamic rule engine and rerouting controller.

[0090] The redundant check memory array uses a dual-channel storage device with 3DXPoint media and integrates a hash tree manager and a CRC checker.

[0091] Furthermore, the algorithm matching unit in the dynamic encryption engine includes a protocol feature register, an algorithm lookup table (LUT), and a key fragment buffer. The protocol feature register is used to store the power protocol header feature codes of IEC 61850 and DL / T645.

[0092] The algorithm lookup table (LUT) uses the protocol signature as an index and outputs the encryption algorithm ID and the initialization vector (IV).

[0093] The key fragment buffer is used to temporarily store elliptic curve key fragments to be distributed.

[0094] Furthermore, the dual-channel architecture of the redundant check memory array includes a main channel controller, a secondary channel compression engine, and a hash tree coprocessor, wherein the main channel controller directly writes encrypted data and triggers CRC calculation;

[0095] The secondary channel compression engine performs LZ4 compression and CRC32C verification in real time.

[0096] The hash tree coprocessor generates data block hashes in parallel and constructs a Merkle tree.

[0097] The above formulas are all dimensionless calculations. The formulas are derived from software simulations based on a large amount of collected data to obtain the most recent real-world results. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0098] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0099] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0100] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0101] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A dynamic encryption and collaborative protection method for power information, characterized in that, Includes the following steps: S1. Protocol Adaptive Dynamic Encryption: Through the protocol stack deep parsing engine deployed on the power terminal gateway, the protocol header fields of the communication message are parsed in real time to extract the protocol type identifier, data packet length and priority flag; The encryption algorithm is dynamically selected by matching the protocol type identifier with the preset encryption algorithm mapping table, and the elliptic curve dynamic segmentation mechanism ECDSA-Segment is adopted based on the device performance classification. S2. Distributed Collaborative Threat Awareness: Hardware probe nodes are deployed at the substation edge layer. A P2P network is built between the probe nodes using a blockchain-based state synchronization protocol (BSP). The operation steps of the BSP are as follows: Periodic initialization: Set a fixed synchronization period Each probe maintains a local threat fingerprint database. ; Differential hash calculation: The differential hash is calculated at the beginning of the period, and the formula for calculating the differential hash is as follows: In the formula, Represented as a difference hash, This is represented as a bitwise XOR operation, used for efficiently identifying differing bits. This represents the fingerprint database from the previous synchronization cycle. Represented as the SHA-256 hash function; Neighbor broadcast: Broadcast to neighboring probe nodes ; Inverse difference solution: receiving neighbor's The newly added feature set is then obtained by inverse analysis using a Bloom filter, where the expression for the newly added feature set is: In the formula, This represents a set of newly added threat features. This is represented as the inverse mechanism of a Bloom filter; Fingerprint database update: The expression for updating the fingerprint database is In the formula, This indicates an update to the fingerprint database. It is represented as a set union operation, and when any probe detects a threat index exceeding the threshold, it triggers a collaborative response chain of all probes in the network; S3. Adaptive Traffic Filtering: A lightweight filtering module is implanted at the L4 transport layer of the TCP / IP protocol stack. Based on the threat index, the allow threshold is dynamically adjusted. The steps for generating dynamic whitelist rules are as follows: Constructing rule vectors: In the formula, This is represented by the historical credibility of the source IP. This is represented as the attenuation coefficient for false interception. Represented as real-time threat confidence. Represented as a dynamic whitelist rule vector; Calculate the release threshold: In the formula, This is represented as the dynamic release threshold; Traffic credibility assessment: Real-time calculation based on traffic characteristics In the formula, This is represented as a traffic credibility score; Judgment execution: And perform fast-channel rerouting on mistakenly intercepted data packets; S4. Data Resilient Storage and Recovery: A redundant parity memory array is constructed using 3DXPoint non-volatile storage media. The redundant parity memory array includes a main channel and a secondary channel, which are used to write the original encrypted data and an LZ4 compressed copy verified by CRC32C, respectively. Data consistency is then ensured by constructing a Merkle hash tree.

2. The method for dynamic encryption and collaborative protection of power information according to claim 1, characterized in that, The dynamic selection of encryption algorithms in step S1 includes enabling the AES-256 algorithm when the protocol identifier is IEC 61850 GOOSE message, and enabling the national cryptographic SM4 algorithm when the protocol identifier is DL / T 645-2007 electricity meter protocol. In step S1, an elliptic curve dynamic segmentation mechanism ECDSA-Segment is adopted based on the equipment performance classification. This includes updating the complete key for high-performance PLC equipment every 15 minutes, distributing key fragments to low-performance RTU equipment, with each fragment being ≤512 bits, and generating a valid key by combining the fragments through the key control center.

3. The method for dynamic encryption and collaborative protection of power information according to claim 2, characterized in that, The implementation steps of the elliptic curve dynamic segmentation mechanism in step S1 are as follows: Central preset parameters: The key control center generates the reference elliptic curve parameters, including the prime field. Base point Private key segmentation number ; Device-specific segment: For the first Each terminal device calculates an asymmetric key segment based on its device ID and time slot. The formula for calculating the key segment is as follows: , Represented as an elliptic curve for calculating the first... Scalar of key fragments for each terminal device Represented as the system's base private key, and a 256-bit integer, the master key. This is represented as the dot product operation on elliptic curves. Represented as the SHA-256 hash function, Represented as the first The ID of each terminal device, This is represented as a byte concatenation operation. This represents the time slot number corresponding to the current time period; Terminal synthesis verification: The i-th terminal device generates a valid key by weighting the fragments according to security level, where the formula for calculating the valid key is as follows: ,and In the formula, This represents the final valid private key generated by the i-th terminal. This is represented as the security level weight of the terminal device. Represented as the first The scalar of the j-th key fragment generated by the terminal device. Represented as modular arithmetic in a finite field. It is represented as an elliptic curve prime field.

4. The method for dynamic encryption and collaborative protection of power information according to claim 3, characterized in that, The data consistency verification steps in step S4 are as follows: Damaged block location: Damaged block index is detected using a Merkle tree; Copy verification: Read the compressed copy from the secondary channel, decompress it, and calculate the checksum. In the formula, This is represented as decompressed data. This is represented as the secondary channel replica check value. This represents the CRC checksum of the main channel. Consistency verification: ; Merkle tree update: In the formula, This indicates updating the Merkle tree. Represented as the hash of the repaired data block. Represented as the sibling node hash. This is represented as a byte concatenation operation.

5. A dynamic encryption collaborative protection system for power information, implemented according to any one of claims 1-4, characterized in that, It includes a dynamic encryption engine, a distributed probe network, an adaptive filtering pipeline, and a redundant verification memory array. The dynamic encryption engine is deployed on the power terminal gateway and includes a protocol parsing unit, an algorithm matching unit, and a key segmentation and distribution unit. The distributed probe network deploys hardware probe nodes at the substation edge layer, and a P2P topology is formed by several hardware probe nodes. Each probe integrates a traffic modeling chip and a BSP communication module. The adaptive filtering pipeline is embedded in the L4 layer filtering module of the operating system kernel, and has a built-in dynamic rule engine and rerouting controller. The redundant check memory array uses a dual-channel storage device with 3DXPoint media and integrates a hash tree manager and a CRC checker.

6. The power information dynamic encryption collaborative protection system according to claim 5, characterized in that, The algorithm matching unit in the dynamic encryption engine includes a protocol feature register, an algorithm lookup table (LUT), and a key fragment buffer. The protocol feature register is used to store the power protocol header feature codes of IEC 61850 and DL / T 645. The algorithm lookup table (LUT) uses the protocol signature as an index and outputs the encryption algorithm ID and the initialization vector (IV). The key fragment buffer is used to temporarily store elliptic curve key fragments to be distributed; The dual-channel architecture of the redundancy check memory array includes a main channel controller, a secondary channel compression engine, and a hash tree coprocessor, wherein the main channel controller directly writes encrypted data and triggers CRC calculation; The secondary channel compression engine performs LZ4 compression and CRC32C verification in real time. The hash tree coprocessor generates data block hashes in parallel and constructs a Merkle tree.

7. A computer device, comprising: A memory and a processor; the memory stores a computer program, characterized in that: when the processor executes the computer program, it implements the steps of the dynamic encryption collaborative protection method for power information as described in any one of claims 1 to 4.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the dynamic encryption and collaborative protection method for power information as described in any one of claims 1 to 4.