Power distribution type adjustable resource security access terminal, method, equipment and medium
By configuring a secure and reliable chip in the secure access terminal for distributed adjustable power resources, and controlling the delayed power-on of the communication chip and performing trusted authentication, the security risks caused by neglecting the operating system and communication protocol stack in the existing technology are solved, and secure access and continuous monitoring of distributed adjustable resources are realized, meeting the security and reliability requirements of the power grid.
Patent Information
- Application Number
- CN202511412862.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-29
- Publication Date
- 2026-02-27
AI Technical Summary
When distributed adjustable resources are connected to the power station system, existing technologies neglect the security of the communication protocol stack and operating system, resulting in serious security vulnerabilities in the access link and failing to meet the power grid's security and reliability requirements for the access equipment.
A secure and trusted chip is configured in the power distributed adjustable resource security access terminal, the power-on delay of the communication chip is controlled, and the image files of the operating system and communication protocol stack are used for trusted authentication. The operating status is monitored by probes, and the identity verification is performed before accessing the power master station system when there are no abnormalities.
It enables secure access to distributed adjustable resources, meets the power grid's security and reliability requirements for access equipment, avoids security risks caused by direct communication access, and ensures the safe operation of equipment through continuous monitoring.
Smart Images

Figure CN121585380A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security and reliability technology, specifically to secure access terminals, methods, devices, and media for distributed adjustable power resources. Background Technology
[0002] With the continuous advancement of the construction of new power systems, a large number of distributed adjustable resources (such as distributed photovoltaic power) are being connected to medium and low voltage distribution networks. Their scale has reached a point where all standby generating units must be shut down to meet the connection demand. However, the power generation capacity of distributed adjustable resources is highly susceptible to weather changes. In the event of a sudden power drop, the shut-down standby generating units cannot quickly restart, directly causing grid voltage fluctuations, frequency drops, and even regional power outages, posing a significant risk to the stable operation of the power grid.
[0003] To effectively prevent such security risks and fully leverage the role of distributed adjustable resources in power grid ancillary services, they need to be directly connected to the power substation system. However, as the core of power grid operation, the power substation system has extremely high requirements for the information security of the connected equipment.
[0004] Currently, the mainstream method for distributed adjustable resources to access the power station system is wireless virtual private network. This method only encrypts and protects the communication channel or transmitted data, but ignores the communication protocol stack and operating system. These two are precisely the main targets of network attacks, resulting in serious security risks in the access link between distributed adjustable resources and the power station system, which cannot meet the power grid's requirements for the security and reliability of access devices. Summary of the Invention
[0005] This invention provides a secure access terminal, method, device, and medium for distributed adjustable power resources, in order to solve the problem that existing distributed adjustable resource access methods have security risks and cannot meet the power grid's security and reliability requirements for access devices.
[0006] In a first aspect, the present invention provides a secure access terminal for distributed adjustable power resources, the terminal comprising a secure and trusted chip, a storage chip, a communication chip, an operating system, and a communication protocol stack, wherein the operating system includes a probe; A secure and reliable chip is used to control the delayed power-on of communication chips; The secure and trusted chip is also used to read the software image file of the storage chip and perform trusted authentication. When the trusted authentication result is passed, it controls the power-on of the communication chip. The software image file includes the image files of the operating system and the communication protocol stack. Probes are used to monitor the running status of the operating system and communication protocol stack. The communication chip is used to initiate identity verification to the power master station system when the probe does not detect any abnormal operating status, and to access the power master station system after passing the identity verification.
[0007] This invention configures a secure and trusted chip in a secure access terminal for distributed adjustable power resources. This chip controls the delayed power-on of the communication chip, avoiding the security risks associated with direct power-on for communication access. The secure and trusted chip then reads a software image file containing the operating system and communication protocol stack from a storage chip and performs trusted authentication. Upon successful authentication, it controls the communication chip to power on. Simultaneously, probes within the operating system are used to monitor for anomalies in the operating system and communication protocol stack, addressing the security vulnerabilities in existing technologies that ignore these components during access. When no anomalies are detected by the probes, the communication chip initiates identity verification with the power station system. Upon successful verification, it accesses the power station system, achieving secure access to distributed adjustable resources and meeting the power grid's security and trust requirements for access devices.
[0008] In one alternative implementation, the secure and trusted chip is specifically used for: Calculate the software image file to obtain the corresponding hash value; The hash value of the software image file is compared with the pre-stored trusted root corresponding to the software image file. If the hash value matches the pre-stored trusted root, the trusted authentication result is determined to be passed. If the hash value and the pre-stored root of trust are inconsistent, the trusted authentication result is determined to be unsuccessful, and the software image file is reread and the hash value is recalculated.
[0009] This embodiment calculates the hash value of the software image file and compares it with the corresponding pre-stored root of trust for trusted authentication. This helps to determine whether the software image file has been tampered with, thereby facilitating secure access.
[0010] In one alternative implementation, the communication chip is specifically used for: Report resource identifiers, trusted authentication results, and pre-stored digital certificates to the power master station system; Receive the master station credentials from the power master station system, and verify the identity when the master station credentials are verified.
[0011] This embodiment lays the foundation for establishing a secure communication connection with the power station system by establishing two-way identity verification between the communication chip and the power station system.
[0012] In one optional implementation, the probe is also used to report to the security management platform when it detects abnormal operating status of the operating system and / or communication protocol stack, and to receive and execute abnormal handling instructions issued by the security management platform.
[0013] This embodiment uses probes to monitor the abnormal operating status of the operating system and communication protocol stack, which solves the problem that the existing technology ignores the operating system and communication protocol stack during access, resulting in security risks in the access link. When an anomaly occurs, it reports it in a timely manner and accepts instructions for processing, ensuring the safe operation of distributed adjustable resources.
[0014] In one alternative implementation, the terminal further includes a control circuit; Control circuitry is used to connect secure and reliable chips and communication chips, as well as secure and reliable chips and memory chips.
[0015] This embodiment uses a control circuit to achieve the connection between chips, providing a prerequisite for secure access.
[0016] In one alternative implementation, the communication chip is also used to read the software image file in the storage chip whose trusted authentication result is passed, and to start running based on the software image file.
[0017] This embodiment reads software image files that have passed trusted certification from the storage chip and starts running based on these files, ensuring that it starts running in a safe and compliant software environment and avoiding operational abnormalities or security risks caused by loading uncertified software.
[0018] In one alternative implementation, the probe is also used to continuously monitor the operating system and communication protocol stack after accessing the power station system.
[0019] This embodiment uses probes to continuously monitor before and after access, ensuring secure access and operation of distributed adjustable resources.
[0020] In a second aspect, the present invention provides a method for secure access to distributed adjustable power resources, applied to a secure access terminal for distributed adjustable power resources according to the first aspect above or any corresponding embodiment thereof, the method comprising: A secure and reliable chip is used to control the delayed power-on of the communication chip; A secure and trusted chip is used to read the software image file of the storage chip and perform trusted authentication. When the trusted authentication result is passed, the communication chip is powered on. The software image file includes the image files of the operating system and the communication protocol stack. The operating system and communication protocol stack are monitored using probes; Using a communication chip, when the probe does not detect any abnormal operating status, it initiates identity verification to the power master station system, and connects to the power master station system after passing the identity verification.
[0021] Thirdly, the present invention provides an electronic device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform the power distributed adjustable resource security access method described in the second aspect or any corresponding embodiment thereof.
[0022] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute the power distributed adjustable resource security access method described in the first aspect or any corresponding embodiment thereof. Attached Figure Description
[0023] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0024] Figure 1 This is a schematic diagram of a power distributed adjustable resource security access terminal according to an embodiment of the present invention; Figure 2 This is a flowchart of trusted authentication according to an embodiment of the present invention; Figure 3 This is a flowchart of a method for secure access to distributed adjustable power resources according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0025] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0026] It is understood that before using the technical solutions disclosed in the various embodiments of the present invention, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in the present invention and their authorization should be obtained in accordance with relevant laws and regulations through appropriate means.
[0027] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.
[0028] The mainstream method for accessing distributed adjustable resources to a power substation system is a wireless virtual private network (VPN). This method only encrypts the communication channel or transmitted data, neglecting the communication protocol stack and operating system, which are precisely the main targets of network attacks. This results in serious security vulnerabilities in the access link between distributed adjustable resources and the power substation system, failing to meet the power grid's security and trust requirements for access devices. This invention provides a secure access terminal for distributed adjustable resources in the power grid. By configuring a secure and trusted chip in the terminal, it controls the delayed power-on of the communication chip, avoiding the security risks associated with direct power-on for communication access. Then, the secure and trusted chip reads a software image file containing the operating system and communication protocol stack from a storage chip and performs trusted authentication. Upon successful authentication, it controls the power-on of the communication chip. Simultaneously, probes within the operating system are used to monitor the operating system and communication protocol stack for anomalies, solving the problem of existing technologies neglecting these components during access, leading to security vulnerabilities in the access link. When the probe monitoring shows no anomalies, the communication chip initiates identity verification with the power substation system. Upon successful verification, it accesses the power substation system, achieving secure access to distributed adjustable resources and meeting the power grid's security and trust requirements for access devices.
[0029] This embodiment provides a secure access terminal for distributed adjustable power resources. Figure 1 This is a schematic diagram of a power distributed adjustable resource security access terminal according to an embodiment of the present invention, as shown below. Figure 1 As shown, the terminal includes a security and trust chip, a storage chip, a communication chip, a probe, an operating system, and a communication protocol stack. The operating system includes the probe. The security and trust chip is used to control the delayed power-on of the communication chip. The security and trust chip is also used to read the software image file of the storage chip and perform trusted authentication. When the trusted authentication result is successful, it controls the power-on of the communication chip. The software image file includes image files of the operating system and the communication protocol stack. The probe is used to monitor the operating status of the operating system and the communication protocol stack. The communication chip is used to initiate identity verification to the power master station system when the probe does not detect any abnormal operating status, and connects to the power master station system after successful identity verification.
[0030] Specifically, a secure and trusted chip, also commonly referred to as a security chip, trusted platform module, or TCM (Trusted Cryptography Module), is a dedicated microprocessor designed to provide hardware-level security functions. It features secure storage, key generation and management, encryption and decryption, digital signature and verification, platform integrity verification (trusted boot), and identity authentication. It provides an independent, isolated, and tamper-proof execution environment for core security functions and is a core component for secure access in distributed adjustable resources. A storage chip, or flash memory chip, serves as the storage medium for distributed adjustable resources. A communication chip, or 4G / 5G SoC (System on Chip) chip, includes baseband circuitry, a CPU (Central Processing Unit), RAM, and other peripheral interfaces, serving as the communication medium between distributed adjustable resources and the power station system.
[0031] The secure and trusted chip first delays the power-on of the communication chip, preventing security risks arising from direct communication access with the power station system. Then, the secure and trusted chip reads the software image file containing the operating system and communication protocol stack from the storage chip, performs trusted authentication on it, and only powers on the communication chip after successful authentication. The software image file refers to the complete software data package that enables the basic operation and communication functions of the distributed adjustable resources. Besides the operating system and communication protocol stack, it also includes image files of other configuration files required for the operation of the distributed adjustable resources. The probe runs within the operating system, monitoring the operating system's task scheduling, memory management, and the data traffic and port status of the communication protocol stack in real time, preventing abnormal risks during operation. If the probe does not detect any abnormalities, the communication chip initiates identity verification with the power station system through its internal security application. After successful verification, a communication connection is established with the power station system, enabling secure access to the distributed adjustable resources. This terminal design solves the problem of related technologies ignoring the communication protocol stack and operating system during access, leading to security vulnerabilities in the access link, and ensures secure access to distributed adjustable resources through trusted authentication and identity verification, meeting the high security requirements of the power station system for direct acquisition and control of distributed adjustable resources.
[0032] In one optional implementation, the secure and trusted chip is specifically used to: calculate the corresponding hash value of the software image file; compare the hash value of the software image file with the pre-stored trusted root corresponding to the software image file; determine that the trusted authentication result is passed when the hash value matches the pre-stored trusted root; determine that the trusted authentication result is failed when the hash value does not match the pre-stored trusted root, and reread the software image file and calculate the hash value.
[0033] Specifically, during trusted authentication, the secure and trusted chip first reads software image files containing the operating system, communication protocol stack, and configuration files from the storage chip. It then calculates a corresponding hash value for each type of software image file. Next, it compares the hash values of the operating system, communication protocol stack, and configuration files with the corresponding pre-stored trusted roots built into the secure and trusted chip. If the hash values of all types of software image files match their corresponding pre-stored trusted roots, meaning the software image files have not been tampered with, the trusted authentication passes. If the hash value of any type of software image file does not match its corresponding pre-stored trusted root, meaning the software image file may have been tampered with, the trusted authentication fails. In this case, the secure and trusted chip rereads the software image files and recalculates the hash values to eliminate misjudgments caused by potential deviations during data reading, further ensuring the accuracy of the trusted authentication.
[0034] Figure 2 This is a flowchart of trusted authentication according to an embodiment of the present invention, such as... Figure 2 As shown, the secure and trusted chip first controls the communication chip to power on with a delay, then reads the software image file containing the operating system and communication protocol stack from the storage chip. It calculates the hash value of each software image file and compares it with its corresponding pre-stored root of trust. If they match, the trust authentication passes, the secure and trusted chip controls the communication chip to power on, and the communication chip reads the software image file that has passed the trust authentication to start running. If they do not match, the trust authentication fails, and the process returns to the step of reading the software image file from the storage chip.
[0035] In one alternative implementation, the communication chip is specifically used for: reporting resource identifiers, trusted authentication results, and pre-stored digital certificates to the power master station system; receiving master station credentials fed back by the power master station system; and verifying identity when the master station credentials are verified.
[0036] Specifically, during identity verification, the communication chip first proactively reports information to the power master station system through its internal security application. The reported information includes a resource identifier uniquely identifying the distributed adjustable resource, the result of the trusted authentication of the software image file previously performed by the secure and trusted chip, and a pre-stored digital certificate. The pre-stored digital certificate is a legal credential pre-installed at the factory by the distributed adjustable resource, used to prove its trusted identity. Simultaneously, the communication chip's security application receives the master station credential from the power master station system and initiates a security verification of that credential. If the verification confirms that the master station credential is authentic, unaltered, and of legitimate origin, it is deemed secure and valid, and the identity verification passes. The master station credential also serves as proof of the trusted identity of the power master station system. This two-way identity verification lays the foundation for establishing a secure communication connection with the power master station system.
[0037] In one optional implementation, the probe is also used to report to the security management platform when it detects abnormal operating status of the operating system and / or communication protocol stack, and to receive and execute abnormal handling instructions issued by the security management platform.
[0038] Specifically, in addition to monitoring the operating system and communication protocol stack, the probe is also used to promptly report any abnormal operating conditions detected in either to the security management platform and receive exception handling instructions from the platform, performing corresponding operations accordingly. On one hand, the probe monitors the operation of the operating system and business applications in real time. Once it detects risky behaviors such as forced port occupation or abnormal network traffic, it immediately reports the anomaly to the power grid network security management platform and simultaneously receives exception handling instructions from the platform, implementing anomaly control management for the operating system and business applications. The business applications are software developed to meet the needs of power business and rely on the operating system to run. On the other hand, the probe also synchronously monitors the operating status of the communication protocol stack. Once it detects abnormalities in network traffic status, port operating status, or other abnormalities, it reports the anomalies to the security management platform and executes corresponding processing operations according to the instructions issued by the platform, ensuring the operational security of distributed adjustable resources.
[0039] In one alternative implementation, the terminal further includes a control circuit; the control circuit is used to connect the security and trusted chip and the communication chip, and to connect the security and trusted chip and the storage chip.
[0040] Specifically, the secure and reliable chip can precisely control the power-on state of the communication chip through electrical signals output by the control circuit. Simultaneously, the secure and reliable chip can achieve data interaction with the memory chip through control commands transmitted by the control circuit.
[0041] In one alternative implementation, the communication chip is also used to read the software image file in the storage chip whose trusted authentication result is passed, and to start running based on the software image file.
[0042] Specifically, after the secure and trusted chip completes the trusted authentication of the software image file and controls the communication chip to power on, the communication chip will read the trusted and authenticated software image file in the storage chip and load these files according to the preset startup process to ensure that it starts and runs based on a secure and compliant software environment, avoiding operational abnormalities or security risks caused by loading uncertified software.
[0043] In one alternative implementation, the probe is also used to continuously monitor the operating system and communication protocol stack after accessing the power station system.
[0044] Specifically, the probe monitoring runs through the entire process of distributed adjustable resources accessing the power station system. Before access, the real-time monitoring of the probe provides a basis for security verification in the access process; after access, the probe continues to monitor to ensure the continuous and safe operation of distributed adjustable resources after access.
[0045] This invention configures a secure and trusted chip in a secure access terminal for distributed adjustable power resources. This chip controls the delayed power-on of the communication chip, avoiding the security risks associated with direct power-on for communication access. The secure and trusted chip then reads a software image file containing the operating system and communication protocol stack from a storage chip and performs trusted authentication. Upon successful authentication, it controls the communication chip to power on. Simultaneously, probes within the operating system are used to monitor for anomalies in the operating system and communication protocol stack, addressing the security vulnerabilities in existing technologies that ignore these components during access. When no anomalies are detected by the probes, the communication chip initiates identity verification with the power station system. Upon successful verification, it accesses the power station system, achieving secure access to distributed adjustable resources and meeting the power grid's security and trust requirements for access devices.
[0046] This embodiment provides a method for secure access to distributed adjustable power resources, which can be used in the aforementioned secure access terminal for distributed adjustable power resources. Figure 3 This is a flowchart of a method for secure access to distributed adjustable power resources according to an embodiment of the present invention, such as... Figure 3 As shown, the process includes the following steps: Step S301: Use a secure and reliable chip to control the delayed power-on of the communication chip.
[0047] Step S302: Using a secure and trusted chip, read the software image file of the storage chip and perform trusted authentication. When the trusted authentication result is passed, control the communication chip to power on. The software image file includes the image files of the operating system and the communication protocol stack.
[0048] Step S303: Use probes to monitor the running status of the operating system and communication protocol stack.
[0049] Step S304: Using a communication chip, when the probe does not detect any abnormal operating status, an identity verification is initiated to the power master station system, and the user is connected to the power master station system after passing the identity verification.
[0050] This invention employs a secure and trusted chip to control the delayed power-on of the communication chip, avoiding the security risks associated with direct power-on for communication access. Then, the secure and trusted chip reads a software image file containing the operating system and communication protocol stack from a storage chip and performs trusted authentication. Powering on the communication chip is controlled only when the authentication is successful. Simultaneously, probes within the operating system are used to monitor the operating system and communication protocol stack for anomalies, addressing the security vulnerabilities in existing technologies that ignore these components during access. When no anomalies are detected by the probes, the communication chip initiates identity verification with the power station system. Upon successful verification, access to the power station system is established, enabling secure access to distributed adjustable resources and meeting the power grid's security and trust requirements for access devices.
[0051] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention.
[0052] The following is a detailed reference. Figure 4 This diagram illustrates a structural schematic suitable for implementing an electronic device according to embodiments of the present invention. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 401, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 402 or a program loaded from memory 408 into random access memory (RAM) 403. The RAM 403 also stores various programs and data required for the operation of the electronic device. The processor 401, ROM 402, and RAM 403 are interconnected via a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.
[0053] Typically, the following devices can be connected to I / O interface 405: input devices 406 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 407 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 408 including, for example, magnetic tapes, hard disks, etc.; and communication devices 409. Communication device 409 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 4 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.
[0054] In particular, according to embodiments of the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present invention include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 409, or installed from a memory 408, or installed from a ROM 402. When the computer program is executed by the processor 401, it performs the functions defined in the power distributed adjustable resource secure access method of the embodiments of the present invention.
[0055] Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of use of the embodiments of the present invention.
[0056] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the secure access method for distributed adjustable power resources shown in the above embodiments is implemented.
[0057] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0058] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A power distributed adjustable resource security access terminal, characterized in that, The terminal includes a security and trust chip, a storage chip, a communication chip, an operating system, and a communication protocol stack. The operating system includes a probe. The secure and reliable chip is used to control the delayed power-on of the communication chip; The secure and trusted chip is also used to read the software image file of the storage chip and perform trusted authentication. When the trusted authentication result is successful, it controls the communication chip to power on. The software image file includes the image files of the operating system and the communication protocol stack. The probe is used to monitor the running status of the operating system and the communication protocol stack; The communication chip is used to initiate identity verification to the power station system when the probe does not detect any abnormal operating status, and to access the power station system after passing the identity verification.
2. The terminal according to claim 1, characterized in that, The secure and reliable chip is specifically used for: Calculate the corresponding hash value of the software image file; The hash value of the software image file is compared with the pre-stored trusted root corresponding to the software image file. When the hash value matches the pre-stored trusted root, the trusted authentication result is determined to be passed. If the hash value and the pre-stored trusted root are inconsistent, the trusted authentication result is determined to be unsuccessful, and the software image file is reread and the hash value is calculated.
3. The terminal according to claim 1, characterized in that, The communication chip is specifically used for: Report resource identifiers, trusted authentication results, and pre-stored digital certificates to the power master station system; The system receives the master station credentials from the power master station system and performs identity verification when the master station credentials are verified.
4. The terminal according to claim 1, characterized in that, The probe is also used to report to the security management platform when it detects abnormal operating status of the operating system and / or the communication protocol stack, and to receive and execute abnormal handling instructions issued by the security management platform.
5. The terminal according to claim 1, characterized in that, The terminal also includes a control circuit; The control circuit is used to connect the secure and trusted chip and the communication chip, as well as to connect the secure and trusted chip and the storage chip.
6. The terminal according to claim 1, characterized in that, The communication chip is also used to read the software image file in the storage chip whose trusted authentication result is passed, and to start running based on the software image file.
7. The terminal according to claim 1, characterized in that, The probe is also used to continuously monitor the operating system and the communication protocol stack after accessing the power station system.
8. A method for secure access to distributed adjustable power resources, characterized in that, The method, applied to the power distributed adjustable resource security access terminal according to any one of claims 1-7, comprises: A secure and reliable chip is used to control the delayed power-on of the communication chip; Using the aforementioned secure and trusted chip, the software image file of the storage chip is read and trusted authentication is performed. When the trusted authentication result is passed, the communication chip is powered on. The software image file includes image files of the operating system and the communication protocol stack. The operating status of the operating system and the communication protocol stack is monitored using probes; Using the aforementioned communication chip, when the probe does not detect any abnormal operating conditions, an identity verification is initiated to the power master station system, and the user connects to the power master station system after passing the identity verification.
9. An electronic device, characterized in that, include: The system includes a memory and a processor, which are interconnected. The memory stores computer instructions, and the processor executes these computer instructions to perform the power distributed adjustable resource security access method as described in claim 8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause the computer to execute the secure access method for distributed adjustable power resources as described in claim 8.