Power distribution network iot terminal self-description and access control method
Patent Information
- Application Number
- CN202511737970.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-25
- Publication Date
- 2026-08-18
- Estimated Expiration
- 2045-11-25
AI Technical Summary
[0004]配电网物联终端远距离指示时,因需控制各电路开合,会产生众多数据,然而多种接入控制数据需多重核对,终端难以主动开展多维度自描述核对,同时异常问题数据剥离处理困难,会大量占用数据控制处理线路资源,而正常数据因多重核验,指示响应速度降低,难以加速处理,这造成正常数据处理迟缓,异常数据处理堆积,使得配电网物联终端在远距离控制指示过程中,远距离电路指示数据的处理效率低下
本发明通过构建自描述专用电路模块与多维核对机制,实现了异常终端的精准识别与快速隔离,系统在硬件层面集成多类型传感器与边缘计算单元,对采集的数据进行实时预处理与结构化封装,主站侧通过格式、逻辑、状态三重校验,能够有效识别设备故障或数据异常,并立即触发告警与隔离,结合核对失败后的降速剥离处理流程,系统可将异常终端通信频率大幅降低,并通过路由修改将其数据流导向隔离区,从而显著减少异常数据对主站资源的占用,使CPU占用率降低,保障了主站处理能力的有效利用,大幅度提高远距离电路指示数据的处理效率。
Smart Images

Figure CN121618740B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power grid IoT control technology, and more specifically, to a method for self-describing and access control of distribution network IoT terminals. Background Technology
[0002] In AC power transmission above 750 kV, large-scale power grid security and defense systems, and intelligent dispatching systems, the self-description and access control method of distribution network IoT terminals provides remote indication of network conditions. Its core purpose is to improve the control operation of the power grid's open and closed states.
[0003] Among existing publicly available documents, patent publication number CN115603462A discloses an information interaction method, device, and storage medium for medium-voltage distribution networks. This technology involves configuring communication parameters for distribution terminals in batches according to construction phases; requesting self-describing file information from the distribution terminals and receiving self-describing files uploaded by the distribution terminals; parsing the self-describing files to obtain self-describing information; determining whether the self-describing information has changed; and if it has changed, notifying the distribution master station. This expands the information interaction model between the distribution terminals and the distribution master station, supporting automatic sensing and automatic modeling of medium-voltage distribution networks. However, this technology still has the following problems.
[0004] When distribution network IoT terminals provide remote indications, they need to control the opening and closing of various circuits, which generates a large amount of data. However, multiple access control data require multiple verifications, and the terminal cannot actively carry out multi-dimensional self-description verification. At the same time, it is difficult to process abnormal data, which will consume a lot of data control processing line resources. Meanwhile, normal data has a reduced indication response speed due to multiple verifications, making it difficult to speed up processing. This results in slow processing of normal data and accumulation of abnormal data, making the processing efficiency of remote circuit indication data of distribution network IoT terminals low during remote control indication. Summary of the Invention
[0005] To overcome the aforementioned shortcomings of the prior art, this invention provides a self-describing and access control method for IoT terminals in power distribution networks, comprising the following specific steps: S1. IoT self-describing circuit access acquisition, integrating multiple types of sensors at the terminal hardware level, with dedicated circuit modules divided into 5-15 groups to generate raw data streams, and using edge computing units to preprocess the raw data streams. S2. Self-description multi-dimensional verification: After receiving the description file, the main station first performs format verification, then logic verification, and finally status verification. S3. Access control circuit verification: On the terminal side, the access control circuit integrates an encryption chip sE security unit and a communication protocol stack, supporting encryption by the encryption chip to prevent command forgery. On the main station side, an access gateway device is deployed to intercept abnormal traffic such as frequent reconnection 5-10 times / s and data packet flooding, with the interception time controlled within 30-60ms. S4. Speed reduction and stripping process for verification failure: When a terminal fails in self-description verification or access control verification, such as when the description file format is incorrect or the communication encryption verification fails, the main station first issues a speed reduction instruction to the terminal. At the same time, the maintenance personnel locate the communication module fault according to the work order and repair it in 1-2 hours to restore the terminal to normal access. S5. Accelerated access upon successful verification: After the terminal verifies itself against the access control, the main station, based on the critical or non-critical equipment in the terminal type and the real-time monitoring or periodic reporting in the business requirements, allows the terminal to skip the historical data supplementation in some non-critical verification steps and directly enter the normal operating status data. S6. Acceleration control circuit: On the terminal side, the acceleration control circuit uses a high-speed MCU with a main frequency of 200-500MHz and a large-capacity memory of 20-50MB. It processes and decrypts 500-1000 channels of terminal data at the same time and quickly forwards the processing results to the backend computer. S7. Control execution verification is accelerated. After the main station issues a remote control command, execution timing and status monitoring are started simultaneously. When the terminal receives the command, the encryption chip performs secondary verification of the digital signature of the command. At the same time, the edge node starts local video recording and playback. The video stream of the switch action is uploaded to the main station through the 5G module in 10-15 seconds, which helps maintenance personnel to quickly locate mechanical jamming or contact sticking faults and complete the verification acceleration. S8. The switch control circuit performs accelerated feedback. On the terminal side, the switch control circuit integrates a high-speed relay with an action time controlled within 5-10ms and a position sensor resolution of 0.1-0.3°. It executes the closing or opening command issued by the master station and compares it with the actual feedback data for confirmation. If they match, the command is quickly confirmed to have been executed successfully.
[0006] In a preferred embodiment, the multiple types of sensors in S1 include voltage sensors, current transformers, temperature sensors, communication signal strength detection modules, and microprocessors, constructing a self-describing dedicated circuit module. The dedicated circuit module collects input voltage, load current, and power factor from the electrical parameters of the terminal in real time, equipment temperature and humidity from environmental parameters, and signal strength and packet loss rate from communication parameters. The raw data stream storage group is 20-30 groups.
[0007] In a preferred embodiment, the edge computing unit in S1 consists of 5-10 sets of computing chips and 20-40 cloud service computers. It performs data cleaning to remove outliers, feature extraction to identify harmonic components from the current waveform, and format conversion to convert analog signals into digital signals. Based on a preset self-describing template XML format, it encapsulates the processed data into a structured description file. The file content includes the MAC address and serial number in the device identification, the telemetry, remote signaling, and protection functions in the function list, the switch open / close position and battery power in the real-time status, and the IP address and port number in the communication configuration.
[0008] In a preferred embodiment, step S2 checks whether the file structure conforms to the standard template 5-15 times, whether the XML format fields are complete, and whether the data types match. If the format is incorrect, the file is discarded and an alarm is triggered every 5 seconds. The logic verification compares the device model in the description file with the pre-recorded ledger information, verifies whether the function list matches the device type, such as the fault indicator should not include remote control function. If there is a logical conflict, the device is marked as suspicious. During the status verification, if the status is contradictory, it is determined to be data abnormal. If the deviation between the current sampling value in the description file and the value collected by the adjacent terminal exceeds 15%-30% during the verification process, it is confirmed by manual review within 5-10 seconds as a sensor fault. During the status verification, the status information switch opening and closing positions in the description file are verified by combining real-time operating data with the line current collected by other terminals. If they are not the same, the suspicious device is isolated in time, without the risk of erroneous operation.
[0009] In a preferred embodiment, in step S3, the uploaded data description file and telemetry data are encrypted 80-100 times, and the remote control closing command issued by the master station is digitally signed and verified 50-70 sets of data to prevent command forgery.
[0010] In a preferred embodiment, the gateway device in S3 has 15-35 built-in firewalls and intrusion detection systems to manage terminal IP addresses, port numbers, and communication protocols in a whitelist, allowing only pre-registered devices to access the network, with the access dwell time controlled to 15-30 seconds. At the same time, it analyzes the communication content through deep packet inspection (DPI) technology.
[0011] In a preferred embodiment, the speed reduction instruction in S4 reduces the terminal's communication frequency from the default 1 time / s to 1 time / 500s, reducing the impact of abnormal data uploads on the main station's processing resources. Simultaneously, the main station marks the terminal as a suspicious device and initiates a stripping process on the edge node side. The edge node modifies 20-30 groups of routing tables to divert the terminal's data into 50-100 groups, directing it to the isolation zone to avoid mixing with data from other normal terminals. Finally, the main station generates an alarm work order of 30-60 pages, notifying maintenance personnel to conduct on-site verification to confirm that no access is required. The verification time is controlled within 10-15 seconds, and the main station's CPU utilization rate decreases from 85%-86% to 40%-52%.
[0012] In a preferred embodiment, in step S5, the resource bandwidth priority, QoS level, and edge node CPU utilization in the computing resources are dynamically allocated. Simultaneously, the main station preloads the sampling frequency, alarm threshold, and fault handling scripts in the configuration file required by the terminal to avoid repeated downloads after the terminal goes online, controlling the repeated download rate to 5%-8%. Furthermore, the main station opens a green channel. In step S6, data acquisition, encryption, packaging, and uploading need to be completed simultaneously. The circuit integrates a gigabit Ethernet or 5G communication module to achieve high-speed data transmission of 500-800Mbps, reducing communication latency. On the main station side, an acceleration gateway device is deployed to support multi-task parallel processing. This device uses a chip to implement hardware acceleration, performing parallel parsing and processing of the terminal data stream.
[0013] In a preferred embodiment, in step S7, 10-15 sets of key data are verified. After confirming that they are correct, the high-speed relay is driven to operate. The terminal uploads the action timestamp and status data through dual channels. The main station acceleration gateway completes data decryption and parsing within 30-50ms. The deviation value between the actual action time of the switch and the theoretical model is compared with the allowable error of 2-5ms. If no feedback is received within the time limit or the status is abnormal, the backup channel retransmission mechanism is immediately triggered with a retransmission interval of 10-20ms.
[0014] In a preferred embodiment, the switch status in S8 is fed back every 10-50ms. At the same time, the circuit adopts a dual-channel redundancy design. The main channel uses power line carrier and 5G in the backup channel to transmit status information simultaneously, with the simultaneous time controlled within 50-80ms. The switch status is fed back in real time through a position sensor. On the main station side, a feedback acceleration module is deployed. This module predicts the switch action result 30-50ms in advance by using a predictive LSTM neural network.
[0015] The technical effects and advantages of this invention are as follows: This invention achieves accurate identification and rapid isolation of abnormal terminals by constructing a self-describing dedicated circuit module and a multi-dimensional verification mechanism. At the hardware level, the system integrates multiple types of sensors and edge computing units to perform real-time preprocessing and structured encapsulation of the collected data. The main station effectively identifies equipment failures or data anomalies through triple verification of format, logic, and status, and immediately triggers alarms and isolation. Combined with the speed reduction and stripping process after verification failure, the system can significantly reduce the communication frequency of abnormal terminals and redirect their data flow to the isolation area through routing modification. This significantly reduces the occupation of main station resources by abnormal data, lowers CPU utilization, ensures the effective utilization of the main station's processing capacity, and greatly improves the processing efficiency of long-distance circuit indication data.
[0016] This invention employs a dynamic resource allocation and preloading strategy, significantly improving the access efficiency and data processing speed of legitimate terminals. For terminals that pass verification, the system dynamically allocates communication bandwidth priority, QoS level, and edge computing resources based on their device type and business needs, and preloads the required configuration files and business logic scripts. This keeps the duplicate download rate after the terminal goes online at a low level, opens a green channel allowing compliant terminals to skip non-critical verification steps and directly enter the running state. Combined with the acceleration control circuit and hardware acceleration gateway on the terminal and main station side, it achieves high-speed data transmission and parallel parsing, enabling the simultaneous decryption of a large number of data streams, fundamentally solving the problem of slow processing of legitimate data caused by multiple verifications.
[0017] 3. This invention employs a control execution verification acceleration and dual-channel feedback mechanism, which greatly optimizes the response speed and reliability of long-distance circuit indication. After the master station issues control commands, the terminal encryption chip performs secondary verification and drives the high-speed relay to execute. Status data is uploaded redundantly through power line carrier and 5G dual channels. The master station acceleration gateway can complete decryption, parsing, and result comparison within a specified time. By introducing an LSTM neural network prediction model, the switching action result can be predicted in advance. If an anomaly occurs, the system immediately starts a retransmission mechanism to assist in diagnosis by backtracking according to the interval time and video stream, ensuring the accuracy and timeliness of command execution. This effectively solves the problems of abnormal data processing accumulation and normal control command response delay, and improves the overall efficiency of remote control of the power distribution network. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the self-description and access control method for IoT terminals in the power distribution network according to the present invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] As attached Figure 1 The self-describing and access control method for IoT terminals in the distribution network shown below yields the following three sets of implementation examples: Example
[0021] The self-description and access control method for IoT terminals in power distribution networks includes the following specific steps: S1. IoT self-describing circuit access and acquisition: At the terminal hardware level, multiple types of sensors are integrated, including voltage sensors, current transformers, temperature sensors, communication signal strength detection modules, and microprocessors. A dedicated self-describing circuit module is constructed, which is divided into 5 groups. The dedicated circuit module collects the terminal's electrical parameters such as input voltage, load current, and power factor, environmental parameters such as equipment temperature and humidity, and communication parameters such as signal strength and packet loss rate in real time to generate raw data streams. The raw data streams are stored in 20 groups. At the same time, the raw data streams are preprocessed using edge computing units, which consist of 5 groups of computing chips and 20 cloud service computers. The edge computing units perform data cleaning to remove outliers, feature extraction to identify harmonic components from the current waveform, and format conversion to convert analog signals into digital signals. Based on the preset self-describing template XML format, the processed data is encapsulated into a structured description file. The file content includes the MAC address and serial number in the device identification, the telemetry, remote signaling, and protection functions in the function list, the switch open / closed position and battery power in the real-time status, and the IP address and port number in the communication configuration. S2. Self-description multi-dimensional verification: After receiving the description file, the main station first performs format verification, checking whether the file structure conforms to the standard template 5 times, whether the XML format fields are complete, and whether the data types match. If the format is incorrect, it is directly discarded and an alarm is triggered every 5 seconds. Next, logical verification is performed, comparing the device model in the description file with the pre-recorded ledger information, and verifying whether the function list matches the device type. For example, the fault indicator should not include remote control function. If there is a logical conflict, it is marked as a suspicious device. Finally, status verification is performed, combining real-time operating data with the line current collected by other terminals to verify whether the status information switch opening and closing positions in the description file are the same. If the status is contradictory, it is determined to be a data anomaly. During the verification process, it was found that the current sampling value in the description file deviated from the value collected by the adjacent terminal by more than 15%. After manual review within 5 seconds, it was confirmed as a sensor fault, and the device was isolated in time to avoid the risk of erroneous operation. S3. Access control circuit verification: On the terminal side, the access control circuit integrates an encryption chip sE security unit and a communication protocol stack, supporting encryption by the encryption chip. It encrypts the uploaded data description file and telemetry data 80 times, and performs digital signature verification on 50 sets of remote control closing instructions issued by the master station to prevent instruction forgery. On the master station side, an access gateway device is deployed. This device has a built-in firewall and intrusion detection system with 15 sets of functions. It manages the terminal IP address, port number, and communication protocol in a whitelist, allowing only pre-registered devices to access. The access dwell time is controlled within 15 seconds. At the same time, it analyzes the communication content through deep packet inspection (DPI) technology to intercept abnormal traffic such as frequent reconnection 5 times / second and data packet flooding. The interception time is controlled within 30ms. S4. Verification Failure Speed Reduction and Stripping Process: When a terminal fails in self-description verification or access control verification, such as due to incorrect description file format or communication encryption verification failure, the master station first issues a speed reduction command to the terminal, reducing the terminal's communication frequency from the default 1 time / s to 1 time / 500s to reduce the occupation of master station processing resources by abnormal data upload. At the same time, the master station marks the terminal as a suspicious device and initiates the stripping process on the edge node side. The edge node modifies 20 groups of routing tables to divert the terminal's data into 50 groups and direct them to the isolation zone to avoid mixing with data from other normal terminals. Finally, the master station generates a 30-page alarm work order to notify the operation and maintenance personnel to conduct on-site verification to determine that no access is required. The verification time is controlled within 10 seconds, and the master station's CPU utilization rate drops from 85% to 40%. At the same time, the operation and maintenance personnel locate the communication module fault according to the work order, repair it within 2 hours, and restore the terminal's normal access. S5. Accelerated access upon successful verification: After the terminal verifies itself against the access control, the master station dynamically allocates communication resource bandwidth priority, QoS level, and edge node CPU utilization in computing resources based on the critical or non-critical equipment in the terminal type and the real-time monitoring or periodic reporting in the business requirements. At the same time, the master station preloads the sampling frequency, alarm threshold, and fault handling script in the configuration file required by the terminal to avoid repeated downloads after the terminal goes online, keeping the repeated download rate below 5%. In addition, the master station opens a green channel, allowing the terminal to skip the historical data supplementation in some non-critical verification steps and directly enter the normal operating status data. S6. Acceleration Control Circuit: On the terminal side, the acceleration control circuit uses a high-speed MCU with a main frequency of 200MHz and a large-capacity memory of 20MB. It supports multi-task parallel processing and can simultaneously complete data acquisition, encryption, packaging, and uploading. At the same time, the circuit integrates a gigabit Ethernet or 5G communication module to achieve high-speed data transmission of 500Mbps and reduce communication latency. On the main station side, an acceleration gateway device is deployed. This device uses a chip to achieve hardware acceleration and performs parallel parsing and processing of terminal data streams. During processing, it simultaneously decrypts 500 channels of terminal data and quickly forwards the processing results to the backend computer. S7. Control execution verification acceleration: After the main station issues a remote control command, execution timing and status monitoring are started simultaneously. When the terminal receives the command, the encryption chip performs secondary verification of the command digital signature and verifies 10 sets of key data. After confirming that there are no errors, the high-speed relay is driven to act. The terminal uploads the action timestamp and status data through dual channels. The main station acceleration gateway completes data decryption and parsing within 30ms. The deviation value between the actual action time of the switch and the theoretical model is compared with the allowable error of 2ms. If no feedback is received within the time limit or the status is abnormal, the backup channel retransmission mechanism is immediately triggered with a retransmission interval of 10ms. At the same time, the edge node starts local video recording and playback. The switch action video stream is uploaded to the main station through the 5G module in 10s to assist maintenance personnel in quickly locating mechanical jamming or contact sticking faults and completing the verification acceleration. S8. The switch control circuit performs accelerated feedback. On the terminal side, the switch control circuit integrates a high-speed relay with an action time controlled within 5ms and a position sensor with a resolution of 0.1°. It executes the closing or opening commands issued by the master station and provides real-time feedback on the switch status through the position sensor. The switch status is fed back every 10ms. At the same time, the circuit adopts a dual-channel redundancy design. The main channel uses power line carrier and the backup channel 5G to transmit status information simultaneously, with the simultaneous transmission time controlled within 50ms. On the master station side, a feedback acceleration module is deployed. This module predicts the switch action result 30ms in advance through a predictive LSTM neural network and compares it with the actual feedback data for confirmation. If they match, the command is quickly confirmed to have been executed successfully. Example
[0022] The self-description and access control method for IoT terminals in power distribution networks includes the following specific steps: S1. IoT self-describing circuit access and acquisition: At the terminal hardware level, multiple types of sensors are integrated, including voltage sensors, current transformers, temperature sensors, communication signal strength detection modules, and microprocessors. A dedicated self-describing circuit module is constructed, which is divided into 10 groups. The dedicated circuit module collects the terminal's electrical parameters such as input voltage, load current, and power factor, environmental parameters such as equipment temperature and humidity, and communication parameters such as signal strength and packet loss rate in real time to generate raw data streams. The raw data streams are stored in 15 groups. At the same time, the raw data streams are preprocessed using edge computing units, which consist of 8 computing chips and 30 cloud service computers. The edge computing units perform data cleaning to remove outliers, feature extraction to identify harmonic components from current waveforms, and format conversion to convert analog signals into digital signals. Based on the preset self-describing template XML format, the processed data is encapsulated into a structured description file. The file content includes the MAC address and serial number in the device identification, the telemetry, remote signaling, and protection functions in the function list, the switch open / closed position and battery power in the real-time status, and the IP address and port number in the communication configuration. S2. Self-description multi-dimensional verification: After receiving the description file, the main station first performs format verification, checking whether the file structure conforms to the standard template 12 times, whether the XML format fields are complete, and whether the data types match. If the format is incorrect, it is directly discarded and an alarm is triggered every 5 seconds. Next, logical verification is performed, comparing the device model in the description file with the pre-recorded ledger information, and verifying whether the function list matches the device type. For example, the fault indicator should not include remote control function. If there is a logical conflict, it is marked as a suspicious device. Finally, status verification is performed, combining real-time operating data with the line current collected by other terminals to verify whether the status information switch opening and closing positions in the description file are the same. If the status is contradictory, it is determined to be a data anomaly. During the verification process, it was found that the current sampling value in the description file deviated from the value collected by the adjacent terminal by more than 20%. After manual review within 8 seconds, it was confirmed to be a sensor fault, and the device was isolated in time to avoid the risk of malfunction. S3. Access control circuit verification: On the terminal side, the access control circuit integrates an encryption chip sE security unit and a communication protocol stack, supporting encryption by the encryption chip. It encrypts the uploaded data description file and telemetry data 90 times, and digitally verifies 60 sets of data for remote control closing commands issued by the master station to prevent command forgery. On the master station side, an access gateway device is deployed. This device has a built-in firewall and intrusion detection system with 20 sets of data. It manages the terminal IP address, port number, and communication protocol in a whitelist, allowing only pre-registered devices to access. The access dwell time is controlled within 25 seconds. At the same time, it analyzes the communication content through deep packet inspection (DPI) technology to intercept abnormal traffic such as frequent reconnection 8 times / second and data packet flooding. The interception time is controlled within 50ms. S4. Verification Failure Speed Reduction and Stripping Process: When a terminal fails in self-description verification or access control verification, such as due to incorrect description file format or communication encryption verification failure, the master station first issues a speed reduction instruction to the terminal, reducing the terminal's communication frequency from the default 1 time / s to 1 time / 500s to reduce the occupation of master station processing resources by abnormal data upload. At the same time, the master station marks the terminal as a suspicious device and initiates the stripping process on the edge node side. The edge node modifies 25 groups of routing tables to divert the terminal's data into 80 groups and direct them to the isolation zone to avoid mixing with data from other normal terminals. Finally, the master station generates a 50-page alarm work order to notify the operation and maintenance personnel to verify on-site and confirm that no access is required. The verification time is controlled within 12 seconds, and the master station's CPU utilization rate drops from 86% to 45%. At the same time, the operation and maintenance personnel locate the communication module fault according to the work order, repair it in 1.5 hours, and restore the terminal's normal access. S5. Accelerated access upon successful verification: After the terminal verifies itself against the access control, the master station dynamically allocates communication resources such as bandwidth priority, QoS level, and edge node CPU utilization based on the critical or non-critical equipment in the terminal type and the real-time monitoring or periodic reporting in the business requirements. At the same time, the master station preloads the sampling frequency, alarm threshold, and fault handling script in the configuration file required by the terminal to avoid repeated downloads after the terminal goes online, keeping the repeated download rate below 7%. In addition, the master station opens a green channel, allowing the terminal to skip the historical data supplementation in some non-critical verification steps and directly enter the normal operating status data. S6. Acceleration Control Circuit: On the terminal side, the acceleration control circuit uses a high-speed MCU with a main frequency of 400MHz and a large-capacity memory of 30MB. It supports multi-task parallel processing and can simultaneously complete data acquisition, encryption, packaging, and uploading. At the same time, the circuit integrates a gigabit Ethernet or 5G communication module to achieve high-speed data transmission of 600Mbps and reduce communication latency. On the main station side, an acceleration gateway device is deployed. This device uses a chip to achieve hardware acceleration and performs parallel parsing and processing of terminal data streams. During processing, it simultaneously decrypts 800 channels of terminal data and quickly forwards the processing results to the backend computer. S7. Control execution verification acceleration: After the main station issues a remote control command, execution timing and status monitoring are started simultaneously. When the terminal receives the command, the encryption chip performs secondary verification of the command digital signature and verifies 12 sets of key data. After confirming that there are no errors, the high-speed relay is driven to act. The terminal uploads the action timestamp and status data through dual channels. The main station acceleration gateway completes data decryption and parsing within 40ms. The deviation value between the actual action time of the switch and the theoretical model is compared with the allowable error of 3ms. If no feedback is received within the time limit or the status is abnormal, the backup channel retransmission mechanism is immediately triggered with a retransmission interval of 15ms. At the same time, the edge node starts local video recording and playback. The switch action video stream is uploaded to the main station through the 5G module in 12s to assist maintenance personnel in quickly locating mechanical jamming or contact sticking faults and completing the verification acceleration. S8. The switch control circuit performs accelerated feedback. On the terminal side, the switch control circuit integrates a high-speed relay with an action time controlled within 8ms and a position sensor with a resolution of 0.2°. It executes the closing or opening commands issued by the master station and provides real-time feedback on the switch status through the position sensor. The switch status is fed back every 30ms. At the same time, the circuit adopts a dual-channel redundancy design. The main channel uses power line carrier and the backup channel 5G to transmit status information simultaneously, with the simultaneous transmission time controlled within 70ms. On the master station side, a feedback acceleration module is deployed. This module predicts the switch action result 40ms in advance through a predictive LSTM neural network and compares it with the actual feedback data for confirmation. If they match, the command is quickly confirmed to have been executed successfully. Example
[0023] The self-description and access control method for IoT terminals in power distribution networks includes the following specific steps: S1. IoT self-describing circuit access and acquisition: At the terminal hardware level, multiple types of sensors are integrated, including voltage sensors, current transformers, temperature sensors, communication signal strength detection modules, and microprocessors. A dedicated self-describing circuit module is constructed, which is divided into 15 groups. The dedicated circuit module collects the terminal's electrical parameters such as input voltage, load current, and power factor, environmental parameters such as equipment temperature and humidity, and communication parameters such as signal strength and packet loss rate in real time to generate raw data streams. The raw data streams are stored in 30 groups. At the same time, the raw data streams are preprocessed using edge computing units, which consist of 10 computing chips and 40 cloud service computers. The edge computing units perform data cleaning to remove outliers, feature extraction to identify harmonic components from the current waveform, and format conversion to convert analog signals into digital signals. Based on the preset self-describing template XML format, the processed data is encapsulated into a structured description file. The file content includes the MAC address and serial number in the device identification, the telemetry, remote signaling, and protection functions in the function list, the switch open / closed position and battery power in the real-time status, and the IP address and port number in the communication configuration. S2. Self-description multi-dimensional verification: After receiving the description file, the main station first performs format verification, checking whether the file structure conforms to the standard template 15 times, whether the XML format fields are complete, and whether the data types match. If the format is incorrect, it is directly discarded and an alarm is triggered every 5 seconds. Next, logical verification is performed, comparing the device model in the description file with the pre-recorded ledger information, and verifying whether the function list matches the device type. For example, the fault indicator should not include remote control function. If there is a logical conflict, it is marked as a suspicious device. Finally, status verification is performed, combining real-time operating data with the line current collected by other terminals to verify whether the status information switch opening and closing positions in the description file are the same. If the status is contradictory, it is determined to be a data anomaly. During the verification process, it was found that the current sampling value in the description file deviated from the value collected by the adjacent terminal by more than 30%. After manual review within 10 seconds, it was confirmed to be a sensor fault, and the device was isolated in time to avoid the risk of malfunction. S3. Access control circuit verification: On the terminal side, the access control circuit integrates an encryption chip sE security unit and a communication protocol stack, supporting encryption by the encryption chip. It encrypts the uploaded data description file and telemetry data 100 times, and performs digital signature verification on 70 sets of remote control closing instructions issued by the master station to prevent instruction forgery. On the master station side, an access gateway device is deployed. This device has a built-in firewall and intrusion detection system with 35 sets of functions. It manages the terminal IP address, port number, and communication protocol in a whitelist, allowing only pre-registered devices to access. The access dwell time is controlled within 30 seconds. At the same time, it analyzes the communication content through deep packet inspection (DPI) technology to intercept abnormal traffic such as frequent reconnection 10 times / second and data packet flooding, with the interception time controlled within 60ms. S4. Verification Failure Speed Reduction and Stripping Process: When a terminal fails in self-description verification or access control verification, such as due to an incorrect description file format or communication encryption verification failure, the master station first issues a speed reduction command to the terminal, reducing the terminal's communication frequency from the default 1 time / s to 1 time / 500s to reduce the occupation of master station processing resources by abnormal data uploads. At the same time, the master station marks the terminal as a suspicious device and initiates the stripping process on the edge node side. The edge node modifies 30 groups of routing tables to divert the terminal's data into 100 groups and direct them to the isolation zone to avoid mixing with data from other normal terminals. Finally, the master station generates a 60-page alarm work order to notify the operation and maintenance personnel to conduct on-site verification to determine that no access is required. The verification time is controlled within 10 seconds, and the master station's CPU utilization rate drops from 86% to 40%. At the same time, the operation and maintenance personnel locate the communication module fault according to the work order, repair it within 1 hour, and restore the terminal's normal access. S5. Accelerated access upon successful verification: After the terminal verifies itself against the access control, the master station dynamically allocates communication resources such as bandwidth priority, QoS level, and edge node CPU utilization based on the critical or non-critical equipment in the terminal type and the real-time monitoring or periodic reporting in the business requirements. At the same time, the master station preloads the sampling frequency, alarm threshold, and fault handling script in the configuration file required by the terminal to avoid repeated downloads after the terminal goes online, keeping the repeated download rate below 8%. In addition, the master station opens a green channel, allowing the terminal to skip the historical data supplementation in some non-critical verification steps and directly enter the normal operating status data. S6. Acceleration Control Circuit: On the terminal side, the acceleration control circuit uses a high-speed MCU with a main frequency of 500MHz and a large-capacity memory of 50MB. It supports multi-task parallel processing and can simultaneously complete data acquisition, encryption, packaging, and uploading. At the same time, the circuit integrates a gigabit Ethernet or 5G communication module to achieve high-speed data transmission of 800Mbps and reduce communication latency. On the main station side, an acceleration gateway device is deployed. This device uses a chip to achieve hardware acceleration, performs parallel parsing and processing of terminal data streams, and simultaneously decrypts 1000 channels of terminal data and quickly forwards the processing results to the backend computer. S7. Control execution verification acceleration: After the main station issues a remote control command, execution timing and status monitoring are started simultaneously. When the terminal receives the command, the encryption chip performs a second verification of 15 sets of key data for the digital signature of the command. After confirming that there are no errors, the high-speed relay is driven to act. The terminal uploads the action timestamp and status data through dual channels. The main station acceleration gateway completes data decryption and parsing within 50ms. The deviation value between the actual action time of the switch and the theoretical model is compared with the allowable error of 5ms. If no feedback is received within the time limit or the status is abnormal, the backup channel retransmission mechanism is immediately triggered with a retransmission interval of 20ms. At the same time, the edge node starts local video recording and playback. The switch action video stream is uploaded to the main station through the 5G module in 15s to assist maintenance personnel in quickly locating mechanical jamming or contact sticking faults and completing the verification acceleration. S8. The switch control circuit performs accelerated feedback. On the terminal side, the switch control circuit integrates a high-speed relay with an action time controlled within 10ms and a position sensor with a resolution of 0.3°. It executes the closing or opening commands issued by the master station and provides real-time feedback on the switch status through the position sensor. The switch status is fed back every 50ms. At the same time, the circuit adopts a dual-channel redundancy design. The main channel uses power line carrier and the backup channel 5G to transmit status information simultaneously, with the simultaneous transmission time controlled within 80ms. On the master station side, a feedback acceleration module is deployed. This module predicts the switch action result 50ms in advance through a predictive LSTM neural network and compares it with the actual feedback data for confirmation. If they match, the command is quickly confirmed to have been executed successfully.
[0024] The following description is based on the above embodiments 1-3: The above embodiments 1-3 were compared and tested based on the following data: self-descriptive multi-dimensional verification time (s), abnormal data stripping and processing (ms), main station CPU usage reduction rate (when abnormal data is being processed) (%), switch action command execution acceleration time (ms), number of repeated downloads reduced (times), and decryption terminal data path rate (%). The following table shows the resulting data: In summary, Example 3 exhibits the shortest self-describing multi-dimensional verification time, the shortest abnormal data stripping processing time, the highest main station CPU utilization reduction rate (during abnormal data processing), the fastest execution speed of switch action instructions, the least amount of repeated downloading of abnormal data, and the highest data path rate of decryption terminals. Therefore, it effectively identifies equipment faults or data anomalies and immediately triggers alarms and isolation. Combined with the speed-down stripping process after verification failure, the system can significantly reduce the communication frequency of abnormal terminals and redirect their data flow to the isolation area through routing modification. This significantly reduces the occupation of main station resources by abnormal data, lowers CPU utilization, ensures the effective utilization of main station processing capabilities, and greatly improves the processing efficiency of long-distance circuit indication data.
[0025] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for self-describing and access control of IoT terminals in power distribution networks, characterized in that: The specific steps are as follows: S1. IoT self-describing circuit access acquisition, integrating multiple types of sensors at the terminal hardware level, with dedicated circuit modules divided into 5-15 groups, generating raw data streams, and using edge computing units to preprocess the raw data streams; S2. Self-description multi-dimensional verification: After receiving the description file, the main station first performs format verification, then logic verification, and finally status verification. S3. Access control circuit verification: On the terminal side, the access control circuit integrates an encryption chip sE security unit and a communication protocol stack, supporting encryption by the encryption chip to prevent command forgery. On the main station side, an access gateway device is deployed to intercept abnormal traffic. The interception time is controlled within 30-60ms. Abnormal traffic includes frequent reconnection 5-10 times / s and data packet flooding. S4. Speed Reduction and Stripping Handling for Verification Failures: When a terminal fails in self-description verification or access control verification, the master station first issues a speed reduction command to the terminal. Failures in self-description verification or access control verification include incorrect description file format and communication encryption verification failure. At the same time, maintenance personnel locate the communication module fault according to the work order, repair it within 1-2 hours, and restore the terminal's normal access. S5. Accelerated access upon successful verification: After the terminal verifies itself against the access control, the main station, based on the critical or non-critical equipment in the terminal type and the real-time monitoring or periodic reporting in the business requirements, allows the terminal to skip the historical data supplementation in some non-critical verification steps and directly enter the normal operating status data. S6. Acceleration control circuit: On the terminal side, the acceleration control circuit uses a high-speed MCU with a main frequency of 200-500MHz and a large-capacity memory of 20-50MB. It processes and decrypts 500-1000 channels of terminal data at the same time and quickly forwards the processing results to the backend computer. S7. Control execution verification is accelerated. After the main station issues a remote control command, execution timing and status monitoring are started simultaneously. When the terminal receives the command, the encryption chip performs secondary verification of the command's digital signature. At the same time, the edge node starts local video recording and playback. The switching action video stream is uploaded to the main station through the 5G module in 10-15 seconds, which helps maintenance personnel quickly locate mechanical jamming or contact sticking faults and complete the verification acceleration. S8. The switch control circuit performs accelerated feedback. On the terminal side, the switch control circuit integrates a high-speed relay with an action time controlled within 5-10ms and a position sensor resolution of 0.1-0.3°. It executes the closing or opening command issued by the master station and compares it with the actual feedback data for confirmation. If they match, the command is quickly confirmed to have been executed successfully.
2. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: The S1 contains multiple types of sensors, including voltage sensors, current transformers, temperature sensors, communication signal strength detection modules, and microprocessors. A self-describing dedicated circuit module is constructed. The dedicated circuit module collects the input voltage, load current, and power factor from the electrical parameters of the terminal in real time, the equipment temperature and humidity from the environmental parameters, and the signal strength and packet loss rate from the communication parameters. The raw data stream is stored in 20-30 groups.
3. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: The edge computing unit in S1 consists of 5-10 sets of computing chips and 20-40 cloud service computers. It performs data cleaning to remove outliers, feature extraction to identify harmonic components from current waveforms, and format conversion to convert analog signals into digital signals. Based on a preset self-describing template XML format, it encapsulates the processed data into a structured description file. The file content includes the MAC address and serial number in the device identification, the telemetry, remote signaling, and protection functions in the function list, the switch open / close position and battery power in the real-time status, and the IP address and port number in the communication configuration.
4. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: In step S2, the file structure is checked 5-15 times to ensure it conforms to the standard template. XML format fields are checked for completeness and data type matching. If a format error is found, the file is discarded and an alarm is triggered every 5 seconds. Logical verification compares the device model in the description file with the pre-recorded ledger information. The function list is verified to match the device type. If a logical conflict is found, the device is marked as suspicious. Verification of the function list to match the device type includes ensuring that fault indicators do not contain remote control functions. Device marking information is also verified. If a status contradiction is found during status verification, it is determined to be data abnormality. During the verification process, if the current sampling value in the description file deviates from the value collected by adjacent terminals by more than 15%-30%, it is manually verified within 5-10 seconds to confirm a sensor fault. In status verification, real-time operating data is combined with line current collected by other terminals to verify whether the switch opening / closing positions in the description file are the same. If they are not the same, the suspicious device is isolated promptly, eliminating the risk of erroneous operation.
5. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: In step S3, the uploaded data description file and telemetry data are encrypted 80-100 times. At the same time, the remote control closing command issued by the master station is digitally signed and verified 50-70 sets of data to prevent command forgery.
6. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: The gateway device in S3 has a built-in firewall and intrusion detection system of 15-35 groups. It manages the terminal IP address, port number and communication protocol through a whitelist, allowing only pre-registered devices to access the network. The access dwell time is controlled within 15-30 seconds. At the same time, it analyzes the communication content through deep packet inspection (DPI) technology.
7. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: The speed-down command in S4 reduces the terminal's communication frequency from the default 1 time / s to 1 time / 500s, reducing the impact of abnormal data uploads on the main station's processing resources. Simultaneously, the main station marks the terminal as a suspicious device and initiates a stripping process on the edge node side. The edge node modifies 20-30 groups of routing tables to divert the terminal's data into 50-100 groups, directing it to the isolation zone to avoid mixing with data from other normal terminals. Finally, the main station generates an alarm work order of 30-60 pages, notifying maintenance personnel to conduct on-site verification to confirm that no access is required. The verification time is controlled within 10-15 seconds, and the main station's CPU utilization rate decreases from 85%-86% to 40%-52%.
8. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: In S5, the priority of communication resources, QoS level, and edge node CPU utilization in computing resources are dynamically allocated. At the same time, the main station preloads the sampling frequency, alarm threshold, and fault handling script in the configuration file required by the terminal to avoid repeated downloads after the terminal goes online, keeping the repeated download rate at 5%-8%. In addition, the main station opens a green channel. In S6, the processing needs to complete data acquisition, encryption, packaging, and uploading simultaneously. At the same time, the circuit integrates gigabit Ethernet or 5G communication modules to achieve high-speed data transmission of 500-800Mbps and reduce communication latency. On the main station side, an acceleration gateway device is deployed to support multi-task parallel processing. This device uses a chip to implement hardware acceleration and performs parallel parsing and processing of terminal data streams.
9. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: In step S7, 10-15 sets of key data are verified. After confirming that they are correct, the high-speed relay is driven to operate. The terminal uploads the action timestamp and status data through dual channels. The main station acceleration gateway completes data decryption and parsing within 30-50ms. The deviation between the actual action time of the switch and the theoretical model is allowed to be 2-5ms. If no feedback is received within the time limit or the status is abnormal, the backup channel retransmission mechanism is immediately triggered with a retransmission interval of 10-20ms.
10. The self-describing and access control method for IoT terminals in a power distribution network according to claim 1, characterized in that: In the S8, the switch status is fed back every 10-50ms. At the same time, the circuit adopts a dual-channel redundancy design. The main channel uses power line carrier and 5G in the backup channel to transmit status information simultaneously, with the simultaneous time controlled within 50-80ms. The switch status is fed back in real time through the position sensor. On the main station side, a feedback acceleration module is deployed. This module predicts the switch action result 30-50ms in advance by using a predictive LSTM neural network.
Citation Information
Patent Citations
Information interaction method and device of medium-voltage power distribution network and storage medium
CN115603462A
Plug-and-play method for power distribution terminal suitable for APP dynamic loading
CN108649691A
Universal internet access type power distribution data communication device and control method
CN110365505A