Power grid safety protection system, method, equipment and medium
By working in tandem with the multi-dimensional risk perception module and the protection decision module, the comprehensiveness and dynamism of the power grid security protection system are solved, realizing all-round security protection and real-time response for the power grid.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-17
- Publication Date
- 2026-03-13
AI Technical Summary
The existing power grid security protection system lacks comprehensiveness, insufficient data utilization, static protection decisions, lack of guarantee for command transmission, and weak visualization capabilities, making it difficult to form a collaborative protection effect and affecting the safe and stable operation of the power grid.
A multi-dimensional risk perception module is adopted to integrate security assessments at the physical, network, and behavioral levels. Combined with a protection decision module, the optimal response strategy is generated. Encrypted communication ensures command execution, and a visualization monitoring module is deployed for real-time display and historical tracing.
It has achieved comprehensive safety protection for the power grid, improved response speed and accuracy, enhanced the utilization and visualization capabilities of real-time data, and ensured the safe and stable operation of the power grid.
Smart Images

Figure CN121663792A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power grid security protection technology, and in particular to a power grid security protection system, method, device and medium. Background Technology
[0002] In the current field of power system security protection, existing technical solutions generally have significant limitations, primarily manifested in the incomplete construction of protection systems. Most power grid security protection systems remain at a single-dimensional protection level, either overly focusing on network-level security protection, such as firewalls and intrusion detection systems, or only emphasizing the security protection of physical equipment, such as substation access control systems and equipment monitoring. This fragmented protection model lacks a holistic consideration of the three key dimensions of physical security, network security, and personnel behavior security, making it difficult to form a synergistic protection effect. At the same time, existing systems are significantly insufficient in mining and utilizing the large amount of real-time data generated during power grid operation, failing to fully release the value of the data, thus limiting the comprehensiveness and accuracy of security risk assessments.
[0003] More critically, current security protection decision-making mechanisms exhibit a pronounced static nature. Protection strategies are often based on preset rules and fixed thresholds, failing to adapt to real-time grid operation status, load changes, and dynamically evolving security threats. In the command transmission and execution phases, reliable encrypted communication mechanisms and effective execution feedback loops are generally lacking. This not only increases the risk of malicious interception and tampering of commands but also makes it difficult to detect and correct erroneous operations in a timely manner. Furthermore, existing systems have significant shortcomings in visualization capabilities; risk profiles are not displayed intuitively, and historical security event tracing functions are weak, severely restricting the efficiency of maintenance personnel in rapidly responding to and handling security incidents. With the deepening of smart grid construction and the continuous expansion of the grid scale, these systemic deficiencies are increasingly becoming bottlenecks restricting the safe and stable operation of the grid, urgently requiring solutions through technological innovation. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a power grid security protection system, method, device and medium that can solve the problems of incomplete protection system, insufficient data utilization, static protection decision-making, lack of guarantee for command transmission and weak visualization capability in the prior art.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: In a first aspect, the present invention provides a power grid security protection system, comprising: The data acquisition module is used to continuously acquire real-time operating parameters and environmental monitoring information of key nodes in the power grid; The asset management module is used to register, track, and maintain the digital profiles and physical status of all connected devices in the power grid; The multi-dimensional risk perception module is used to integrate information from the operational data acquisition module and the asset management module to perform a comprehensive security risk assessment covering physical, network, and behavioral levels. The protection decision module receives the evaluation results from the multi-dimensional risk perception module, combines them with the preset protection rule base and the power grid operation context, and generates the optimal safety response strategy. The instruction execution module is deployed at the edge to receive security instructions issued by the protection decision module and call the local control interface to perform isolation, alarm or recovery operations. The visualization monitoring module is used to display the risk assessment process, decision-making basis, and execution results in real time and allow for historical tracing through a graphical interface; The protection decision-making module is deployed in the cloud core system; the terminal components of the operation data acquisition module, instruction execution module and visualization monitoring module are deployed at edge nodes in each region.
[0007] As a preferred embodiment of the power grid security protection system described in this invention, the multi-dimensional risk perception module includes a physical security assessment unit, a network intrusion detection unit, and an abnormal behavior analysis unit. The physical safety assessment unit is equipped with an insulation performance detection engine, an arc fault identification engine, and a load status monitoring engine, which are used to quantitatively assess the physical health of electrical equipment. The network intrusion detection unit integrates an anomaly detection model based on traffic characteristics and a threat matching engine based on signatures to identify potential network attack behaviors. The abnormal behavior analysis unit detects suspicious behaviors that deviate from the normal pattern by establishing a baseline model of personnel activities, equipment operation, and data access.
[0008] As a preferred embodiment of the power grid security protection system described in this invention, the physical security assessment unit further includes a comprehensive scoring engine; The comprehensive scoring engine receives output signals from the insulation performance detection engine, the arc fault identification engine, and the load condition monitoring engine. Based on a preset weighted algorithm, various physical indicators are converted into a unified quantitative score to generate a comprehensive safety index for the equipment. When the overall security index falls below the preset security threshold, a high-risk warning is triggered, and the warning information is pushed to the protection decision module and the visualization monitoring module.
[0009] As a preferred embodiment of the power grid security protection system of the present invention, the baseline model in the abnormal behavior analysis unit is dynamically constructed and updated through machine learning methods; The baseline model covers multi-dimensional features of operation sequences, access time windows, and data interaction patterns under normal operating conditions; When the similarity between the real-time monitored behavioral pattern and the baseline model is lower than the set confidence level, it is judged as an abnormal behavioral event.
[0010] As a preferred embodiment of the power grid security protection system of the present invention, the protection decision module includes a strategy matching engine and an instruction orchestration engine; The strategy matching engine retrieves and matches the most suitable response plan from the protection rule base based on the risk type, risk level, scope of affected assets, and current power grid operation mode. The instruction orchestration engine transforms the selected plan into a set of ordered, executable control instructions, and adds execution priority, target device identifier and digital signature to each instruction.
[0011] In a preferred embodiment of the power grid security protection system of the present invention, the instruction execution module and the protection decision module interact through an encrypted communication queue that supports message confirmation. After receiving the instruction sequence, the instruction execution module verifies the validity of the digital signature and the integrity of the instructions; According to the priority order of the instructions, the local preset control functions are called in sequence to perform physical or logical operations, and the execution status and results are fed back to the protection decision module.
[0012] As a preferred embodiment of the power grid security protection system of the present invention, the operation data acquisition module includes a data cleaning and standardization sub-module; The data cleaning and standardization submodule performs preprocessing operations such as noise filtering, missing value imputation, and unit standardization on the raw running data. The processed, standardized data stream is provided to the multidimensional risk perception module for real-time analysis to ensure the accuracy and reliability of risk assessment.
[0013] Secondly, the present invention provides a power grid security protection method, comprising: Obtain real-time operating parameters and environmental monitoring information of key nodes in the power grid; Register, track, and maintain digital profiles and physical status of all connected devices in the power grid; By integrating the acquired data, digital archives, and physical status, a comprehensive security risk assessment covering physical, network, and behavioral levels is performed. Receive the assessment results of the comprehensive security risk assessment, and generate the optimal security response strategy by combining the preset protection rule base with the power grid operation context; Receive security instructions from the optimal security response strategy and invoke the local control interface to perform isolation, alarm, or recovery operations.
[0014] Thirdly, the present invention provides an electronic device including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described above.
[0015] Fourthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described above.
[0016] Compared with existing technologies, the beneficial effects of this invention are as follows: This invention proposes a power grid security protection system that integrates modules for data acquisition, asset management, risk perception, protection decision-making, command execution, and visual monitoring to achieve security risk assessment at the physical, network, and behavioral levels. The protection decision-making module is deployed in the cloud, while the data acquisition, command execution, and monitoring modules are distributed at edge nodes, improving response speed. The multi-dimensional risk perception module monitors power grid security from different angles: the physical security assessment unit generates equipment security indices, and the network intrusion detection and abnormal behavior analysis units detect network attacks and personnel anomalies, respectively, providing comprehensive threat perception. The protection decision-making module generates optimal response strategies through policy matching and command orchestration engines, and interacts with the command execution module via an encrypted communication queue to ensure security. The data acquisition module cleans and standardizes data, providing a reliable foundation for assessment. Based on this system, this invention achieves comprehensive power grid security protection by acquiring real-time parameters, maintaining equipment files, assessing risks, generating strategies, and executing commands. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a schematic diagram of the system structure of a power grid security protection system provided in one embodiment of the present invention.
[0019] Figure 2 This is an internal structural diagram of an electronic device for a power grid security protection method provided in one embodiment of the present invention. Detailed Implementation
[0020] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0021] Example 1, referring to Figure 1 This is the first embodiment of the present invention, which provides a power grid security protection system, including: Existing technologies suffer from several problems. For example, the protection system is not comprehensive enough, focusing only on single-dimensional protection and lacking a holistic consideration of physical, network, and personnel security, making it difficult to achieve a synergistic protection effect. Furthermore, insufficient utilization of the large amount of real-time data generated by power grid operation limits the comprehensiveness and accuracy of security risk assessments. Simultaneously, the security protection decision-making mechanism is static, unable to adaptively adjust to real-time power grid status, load changes, and dynamic threats. In the command transmission and execution phase, the lack of reliable encrypted communication guarantees and effective execution feedback loops increases the risk of malicious interception and tampering of commands, and hinders the timely detection and correction of erroneous operations. Additionally, existing systems lack sufficient visualization capabilities, the risk situation is not intuitively displayed, and the historical security event tracing function is weak, affecting the efficiency of operation and maintenance personnel in responding to and handling security incidents.
[0022] This invention provides a method that can effectively solve the problems mentioned above. The following will describe in detail how to establish the power grid security protection system with reference to several embodiments. Figure 1 A schematic diagram of the system structure of a power grid security protection system is shown, including: The data acquisition module is used to continuously acquire real-time operating parameters and environmental monitoring information of key nodes in the power grid; The asset management module is used to register, track, and maintain the digital profiles and physical status of all connected devices in the power grid; The multi-dimensional risk perception module is used to integrate information from the operational data acquisition module and the asset management module to perform a comprehensive security risk assessment covering physical, network, and behavioral levels. The protection decision module receives the evaluation results from the multi-dimensional risk perception module, combines them with the preset protection rule base and the power grid operation context, and generates the optimal safety response strategy. The instruction execution module is deployed at the edge to receive security instructions issued by the protection decision module and call the local control interface to perform isolation, alarm or recovery operations. The visualization monitoring module is used to display the risk assessment process, decision-making basis, and execution results in real time and allow for historical tracing through a graphical interface; The protection decision-making module is deployed in the cloud core system; the terminal components of the data acquisition module, command execution module and visualization monitoring module are deployed at the edge nodes of each region.
[0023] In one optional implementation, each module can consist of different units or components that cooperate to achieve the module's function. Taking a data acquisition module as an example, it may include a sensor unit, a data transmission unit, and a data preprocessing unit. The sensor unit is responsible for collecting real-time operating parameters and environmental monitoring information from key nodes of the power grid, such as voltage sensors, current sensors, and temperature sensors. These sensors can accurately acquire various data related to power grid operation. The data transmission unit transmits the data collected by the sensors to subsequent processing stages in a timely and accurate manner. It can use wired or wireless communication methods to ensure stable data transmission. The data preprocessing unit performs preliminary processing on the transmitted data, such as data cleaning and filtering, to remove noise and outliers and improve data quality.
[0024] In one optional implementation, the asset management module may consist of an equipment registration unit, a status monitoring unit, and a file update unit. The equipment registration unit performs initial registration of all connected equipment in the power grid, recording basic equipment information such as model, specifications, and manufacturer. The status monitoring unit monitors the physical status of the equipment in real time, using various monitoring methods, such as parameters like vibration, temperature, and humidity, to determine whether the equipment is operating normally. The file update unit updates the digital files of the equipment promptly based on its actual operating conditions and maintenance records, ensuring the accuracy and timeliness of the file information.
[0025] In one optional implementation, the multi-dimensional risk perception module may include an information fusion unit, a risk assessment unit, and a result output unit. The information fusion unit integrates information provided by the operational data acquisition module and the asset management module, eliminating redundancy and conflicts between information to form a unified information source. Based on the fused information, the risk assessment unit conducts a comprehensive security risk assessment from physical, network, and behavioral levels, using various assessment models and algorithms to calculate the power grid's risk level. The result output unit outputs the assessment results in a clear and easy-to-understand manner, providing a basis for subsequent protection decisions.
[0026] In one optional implementation, the protection decision module may include a rule matching unit, a strategy generation unit, and a result verification unit. The rule matching unit searches for matching rules in a pre-defined protection rule base based on the evaluation results of the multi-dimensional risk perception module. The strategy generation unit optimizes and adjusts the matched rules in conjunction with the power grid operating context to generate the optimal safety response strategy. The result verification unit verifies the generated strategy to ensure its feasibility and effectiveness.
[0027] In one optional implementation, the instruction execution module may include an instruction receiving unit, an interface calling unit, and an operation execution unit. The instruction receiving unit is responsible for receiving security instructions issued by the protection decision module, ensuring accurate reception of the instructions. The interface calling unit calls local control interfaces, such as switch control interfaces and alarm interfaces, according to the requirements of the instructions. The operation execution unit performs corresponding isolation, alarm, or recovery operations to ensure the safe operation of the power grid.
[0028] In one optional implementation, the visualization monitoring module may consist of a data display unit, a historical data tracing unit, and an interactive operation unit. The data display unit presents the risk assessment process, decision-making basis, and execution results to the user in a graphical interface format, such as line charts, bar charts, and maps, enabling the user to intuitively understand the power grid's safety status. The historical data tracing unit allows users to query historical data and events, and analyze trends in the power grid's safety status. The interactive operation unit provides user-system interaction functions, such as allowing users to set parameters and query specific information through the interface.
[0029] In this embodiment of the invention, the multi-dimensional risk perception module includes a physical security assessment unit, a network intrusion detection unit, and an abnormal behavior analysis unit. The physical safety assessment unit is equipped with an insulation performance testing engine, an arc fault identification engine, and a load status monitoring engine, which are used to quantitatively assess the physical health of electrical equipment. The network intrusion detection unit integrates an anomaly detection model based on traffic characteristics and a threat matching engine based on signatures to identify potential network attack behaviors; The abnormal behavior analysis unit detects suspicious behaviors that deviate from normal patterns by establishing baseline models of personnel activities, equipment operations, and data access.
[0030] It should be noted that the physical safety assessment unit is used to detect and evaluate the physical condition of electrical equipment to ensure its operational safety. Multiple engines are used to monitor and analyze specific physical parameters.
[0031] For example, the insulation performance testing engine can measure the insulation resistance value of electrical circuits. If it finds that the insulation layer is aging and the resistance is decreasing, it will determine that there is a safety hazard. The arc fault identification engine can capture the location and intensity of abnormal arcs in the circuit and give timely warnings of the risk of fire.
[0032] It should be noted that the network intrusion detection unit focuses on the field of network security, using specific technical means to monitor network traffic and threat characteristics in order to discover potential attack behaviors.
[0033] For example, an anomaly detection model based on traffic characteristics can analyze whether the data packet transmission rate exceeds the normal range within a certain period of time, thereby inferring whether a DDoS attack exists; while a threat matching engine based on signatures can quickly identify file download requests containing viruses or Trojans by comparing them with known malicious code libraries.
[0034] It should be noted that the abnormal behavior analysis unit defines “normal” behavior patterns by building a baseline model and detects any behavior that deviates from the standard, which may indicate an inside threat or other problem.
[0035] For example, in a factory, the system records the time and frequency of employees' daily operation of mechanical equipment. If an employee frequently starts critical equipment outside of working hours on a certain day, it will be marked as suspicious behavior. Similarly, if a server suddenly receives a large number of unauthorized data access requests, it will also trigger an alarm to prompt the administrator to check the cause.
[0036] In an embodiment of the present invention, the physical security assessment unit further includes a comprehensive scoring engine; The comprehensive scoring engine receives output signals from the insulation performance testing engine, the arc fault identification engine, and the load condition monitoring engine. Based on a preset weighted algorithm, various physical indicators are converted into a unified quantitative score to generate a comprehensive safety index for the equipment. When the overall security index falls below the preset security threshold, a high-risk warning is triggered, and the warning information is pushed to the protection decision module and the visualization monitoring module.
[0037] It should be noted that a comprehensive scoring engine refers to a calculation tool or algorithm module used to weight multiple input signals according to specific rules to obtain a unified quantitative score.
[0038] For example, the comprehensive scoring engine in this invention converts the results of insulation performance, arc fault identification and load condition monitoring into a single comprehensive safety index. For instance, it generates a comprehensive score of 75 by weighting 80% insulation qualification rate, 90% arc stability and 70% load health.
[0039] It should be noted that the preset weighting algorithm refers to a pre-defined mathematical formula or logical rule used to assign weights according to the importance of different indicators and calculate the final result accordingly.
[0040] For example, in this invention, assuming that insulation performance accounts for 40% of the weight, arc fault identification accounts for 30%, and load condition monitoring accounts for 30%, the comprehensive scoring engine will calculate the final safety index based on these weight ratios.
[0041] It should be noted that the comprehensive safety index is a single value obtained by quantifying multiple physical indicators of the equipment, used to characterize the overall safety level of the equipment.
[0042] For example, if a device scores 80 points for insulation performance, 70 points for arc fault identification, and 60 points for load condition monitoring, the overall safety index obtained by the weighted algorithm may be 71 points.
[0043] It should be noted that a high-risk warning means that when the safety index of a device falls below a certain set standard, the system will automatically issue a warning message to alert the user of potential dangers.
[0044] For example, if the overall safety index is below 60 points (assuming the safety threshold is 60 points), the system will immediately trigger a high-risk warning, such as popping up a message saying "Insulation performance has dropped below the critical value, please check the equipment".
[0045] It should be noted that the protection decision module refers to the functional component responsible for receiving early warning information and formulating corresponding response strategies, which aims to reduce or eliminate security risks.
[0046] For example, when a high-risk warning is triggered, the protection decision module may suggest reducing the equipment load or cutting off the power to prevent the arc fault from worsening.
[0047] It should be noted that the visual monitoring module refers to a component that provides an intuitive interface to display the operating status and related information of the equipment, making it easy for operators to keep track of the situation in real time.
[0048] For example, in the scenario of this invention, the visualization monitoring module can display a trend chart of the changes in the comprehensive safety index, and highlight parameters that are currently in a high-risk state, such as "abnormal insulation performance," with red markings.
[0049] Specifically, the physical safety assessment unit establishes real-time data stream connections with the insulation performance testing engine, the arc fault identification engine, and the load status monitoring engine. By receiving physical status scoring signals from these three engines, it performs weighted fusion calculations to achieve a comprehensive assessment and risk classification of the overall health status of electrical equipment. This connection method employs a local frequency synchronous sampling mechanism to ensure strict alignment of the three engine outputs in the time dimension, avoiding assessment distortion due to timing misalignment. The physical safety assessment unit internally includes a comprehensive scoring engine, whose core function is to uniformly map multi-source heterogeneous physical indicators to a single dimensional space, thereby supporting subsequent global safety decisions. The specific mathematical expression is as follows: In this invention, the following settings are provided: The comprehensive safety index of the equipment has a value range of [0, 1], with lower values indicating higher physical risks; this invention sets... The insulation degradation score output by the insulation performance testing engine is compressed to the [0, 1] interval by a nonlinear normalization function from original parameters such as partial discharge intensity and dielectric loss tangent; in this invention, the following settings are provided. The arc risk score output by the arc fault identification engine is obtained by mapping high-frequency transient current waveform features through a convolutional neural network classifier; in this invention, a... The load health score output by the load status monitoring engine is a weighted composite of parameters such as RMS current, temperature rise rate, and harmonic distortion rate; this invention sets... For the preset weighting coefficients, satisfy Its value is set based on historical fault statistics and expert experience. For example, in a substation scenario, it can be set to... To highlight the dominant role of insulation performance. When At that time, the physical security assessment unit proactively triggers a high-risk warning. As a physical security threshold, the present invention selects .
[0050] In this embodiment of the invention, the baseline model in the abnormal behavior analysis unit is dynamically constructed and updated using machine learning methods; The baseline model covers multi-dimensional features of operation sequences, access time windows, and data interaction patterns under normal operating conditions; When the similarity between the real-time monitored behavioral pattern and the baseline model is lower than the set confidence level, it is judged as an abnormal behavioral event.
[0051] It should be noted that the baseline model is a reference standard generated by modeling the behavioral characteristics of the system under normal operating conditions, used to determine whether the current behavior deviates from the normal range.
[0052] Example: Suppose an internal document management system where employees typically access specific types of documents between 9:00 AM and 6:00 PM on weekdays, completing operations in a fixed sequence (e.g., opening, editing, saving). These behavioral patterns are recorded and used to build a baseline model. If, at 10:00 PM one evening, an account attempts to download a large number of files in bulk, this behavior deviates from the baseline model and may trigger an anomaly alert.
[0053] It should be noted that dynamically building and updating through machine learning methods refers to using machine learning algorithms to continuously adjust and improve the baseline model based on the system's real-time and historical data, so that it can adapt to environmental changes or new normal behavior patterns.
[0054] For example, in a web server environment, the initial baseline model sets up an average of 5 file uploads per day after a user logs in as normal behavior. However, as business expands, the upload frequency gradually increases to 10 times per day. The machine learning algorithm automatically detects this trend and incorporates the new behavioral pattern into the baseline model, avoiding false alarms.
[0055] It should be noted that the multi-dimensional characteristics of operation sequence, access time window and data interaction mode refer to the key characteristics that describe normal behavior from multiple perspectives, including the order of operation execution, the time period in which they occur, and comprehensive information such as the mode and scale of data transmission.
[0056] For example, in the monitoring system of an automated production line in a manufacturing plant, device A typically initiates a self-test program first, then connects to the database to read configuration parameters, and finally begins processing tasks. These operations generally occur within the first 30 minutes after the start of the morning shift, and the amount of data exchanged each time remains consistently around 1MB. These details collectively constitute the multi-dimensional characteristics of the baseline model.
[0057] It should be noted that when the similarity is lower than the set confidence level, the behavior event is judged as abnormal by comparing the degree of matching between the real-time monitored behavior and the baseline model. When the difference between the two exceeds the predefined threshold, the behavior is considered abnormal.
[0058] For example, a financial institution's core transaction system has a rule that any request exceeding twice the normal transaction amount will be considered suspicious. For instance, if a customer usually transfers less than 5,000 yuan per transaction, but suddenly submits a transfer request for 500,000 yuan, the system calculates its similarity and finds it to be significantly lower than the confidence level, thus marking it as an abnormal behavior event and issuing a warning.
[0059] Specifically, the abnormal behavior analysis unit establishes behavioral data subscription connections with personnel activity log collectors, equipment operation record buffers, and data access flow probes. By receiving multi-dimensional time-series behavioral feature vectors, it performs dynamic baseline model matching to automatically identify suspicious behaviors that deviate from normal patterns. This connection adopts an event-driven architecture; whenever a new behavioral event occurs, it triggers the feature extraction and similarity calculation process, ensuring a detection latency of less than 500 milliseconds. The baseline model is updated online by a machine learning engine, with incremental training performed during low-load periods every morning to adapt to the slow drift of operational patterns.
[0060] The abnormal behavior analysis unit contains a similarity calculation core, the mathematical expression of which is as follows: In this invention, the following settings are provided: This represents the similarity between the current behavior pattern and the baseline model, with a value range of [0, 1]. A value closer to 1 indicates more normal behavior. In this invention, it is set... The number of behavioral feature dimensions is selected in this invention. These correspond to the operation sequence matching degree, access time window offset, and data interaction frequency ratio, respectively; in this invention, the following settings are provided. For the first The current observation value, such as the operation sequence matching degree, can be obtained by normalizing the edit distance; in this invention, it is set... and For the baseline model, the first The mean and standard deviation of the dimensional features are dynamically calculated from data within a sliding window over the past 30 days; this invention sets... The confidence threshold is selected in this invention. ,when At that time, the abnormal behavior analysis unit generates an abnormal event report and pushes it to the protection decision module, while the personnel and equipment involved are highlighted in the visualization monitoring module.
[0061] In this embodiment of the invention, the protection decision module includes a strategy matching engine and an instruction orchestration engine; The strategy matching engine retrieves and matches the most suitable response plan from the protection rule base based on the risk type, risk level, scope of affected assets, and current power grid operation mode. The instruction orchestration engine transforms the selected plan into a set of ordered, executable control instructions, and adds execution priority, target device identifier and digital signature to each instruction.
[0062] In this embodiment of the invention, the instruction execution module and the protection decision module interact through an encrypted communication queue that supports message confirmation; After receiving the instruction sequence, the instruction execution module verifies the validity of the digital signature and the integrity of the instructions; According to the priority order of the instructions, the local preset control functions are called in sequence to perform physical or logical operations, and the execution status and results are fed back to the protection decision module.
[0063] It should be noted that the protection decision-making module consists of two core components: a policy matching engine and an instruction orchestration engine. The former is responsible for selecting the most suitable contingency plan from the rule base based on the current risk situation, while the latter transforms the selected contingency plan into an executable sequence of instructions.
[0064] For example, when the power grid is under cyberattack, the policy matching engine will match a contingency plan from the protection rule base based on the attack type (such as DDoS), attack level (high risk), scope of affected equipment (a substation) and current operating mode (peak load mode) to "start backup communication links and isolate attacked equipment". Subsequently, the instruction orchestration engine will convert the contingency plan into specific operation steps, such as "disconnect device A" or "activate backup link B".
[0065] It should be noted that the strategy matching engine uses a variety of key parameters to select the most suitable response plan for the current scenario from the protection rule base, ensuring that the response measures are targeted and efficient.
[0066] For example, suppose an event has a risk type of "data tampering," a risk level of "medium," and affects assets including "a regional distribution automation system," while the power grid is currently operating in "off-peak mode." The policy matching engine might match a contingency plan that involves "real-time data verification of the affected area and switching to manual control."
[0067] It should be noted that the instruction orchestration engine refines the abstract plan into specific, sequentially arranged operation instructions, and adds necessary attribute information to each instruction, such as priority, target device identifier, and digital signature.
[0068] For example, for the contingency plan of "activating backup communication links and isolating attacked devices", the instruction orchestration engine generates the following instruction sequence: Command 1: "Disconnect device A", Priority: High, Target device: A001, Digital signature: Generated; Command 2: "Activate backup link B", priority: medium, target device: B002, digital signature: generated.
[0069] It should be noted that the communication between the instruction execution module and the protection decision module is protected by security mechanisms, including encrypted transmission and message confirmation functions, to ensure the security and reliability of the data.
[0070] For example, when the protection decision module sends a "shut down device C" instruction to the instruction execution module, the instruction is encrypted and transmitted through a communication queue. The receiver needs to return an acknowledgment message to indicate that the instruction has been successfully received.
[0071] It should be noted that before executing any instruction, the instruction execution module verifies the digital signature of the instruction to confirm that its source is legitimate and has not been tampered with, thereby ensuring the authenticity and integrity of the instruction.
[0072] For example, when the instruction execution module receives the instruction "adjust the transformer output power to 50%", it first checks whether the digital signature of the instruction is valid. If the signature is invalid or the data has been modified, it refuses to execute.
[0073] It should be noted that the instruction execution module calls the internally predefined control logic one by one according to the priority of the instructions to complete the actual operation, and reports the status changes during the execution process and the final result to the protection decision module.
[0074] For example, for three instructions—"Disconnect device X" (priority: high), "Reduce load Y power" (priority: medium), and "Log Z" (priority: low)—the instruction execution module will first disconnect device X, then reduce load Y power, and finally log Z, and feed back the execution results of each step to the protection decision module.
[0075] Specifically, the strategy matching engine in the protection decision-making module establishes semantic-level data associations with the multi-dimensional risk perception module, the protection rule base, and the power grid operation context database, by receiving risk event types. Risk level Affected asset collection Compared with the current operating mode This system performs multi-objective optimization matching to achieve intelligent selection of response plans. It employs a knowledge graph-based semantic retrieval mechanism to map potential risks and plan conditions to a unified ontology space, improving matching accuracy.
[0076] The strategy matching engine has a built-in pre-plan scoring function, the mathematical expression of which is as follows: In this invention, the following settings are provided: For the selected optimal response plan, from the plan set Selected from; the present invention is set The total number of candidate contingency plans in the protection rule base is set to no more than 200 in this invention; this invention sets... Contingency Plan The matching score for the current risk type and level is calculated by the rule engine based on preset conditions. For example, "network attack + high risk" matching "disconnecting the regional firewall + enabling the backup channel" scores 0.92. This invention sets... Contingency Plan The execution cost score under the current asset scope and operating mode is obtained by normalizing the load transfer losses and power outage impact range estimated by the power grid power flow simulator; this invention sets... To adjust the weights, satisfy In this invention, the following are selected Prioritizing the effectiveness of security responses. Matching results It will be passed to the instruction orchestration engine for further decomposition.
[0077] The instruction orchestration engine establishes a pipelined functional connection with the policy matching engine, digital signature module, and priority allocator, receiving the optimal plan. The system performs atomic instruction decomposition, digital signature attachment, and execution priority labeling to achieve secure, ordered, and traceable instruction packet generation. This connection employs a Directed Acyclic Graph (DAG) scheduling algorithm to ensure correct dependencies between instructions, strictly maintaining timing constraints such as "isolate before restart." The internal structure of the instruction orchestration engine outputs a structured instruction sequence, mathematically expressed as follows: In this invention, the following settings are provided: For the first The control instructions constitute the final instruction sequence; in this invention, the following control instructions are set. As for operation types, this invention defines eight atomic operations, including ISO (isolation), ALM (alarm), RST (recovery), and BLK (lockout); this invention sets... This is a unique identifier for the target device, formatted as "region code-device type-serial number", for example, "BJ-ZB-0017"; This invention sets... The execution priority is determined by integers from 1 to 5, with 1 being the highest, and is jointly determined by the dependency graph topology sorting and the risk urgency. In this invention, the following settings are provided: For digital signatures, where The SHA-256 hash function is used. This indicates string concatenation. UTC millisecond timestamp To protect the private key of the decision-making module; this invention sets This represents the total number of instructions after the contingency plan is broken down, typically between 3 and 15. The generated instruction sequence is pushed to the instruction execution modules of each edge node via an encrypted queue. The instruction execution module and the protection decision module establish a two-way secure channel through an encrypted communication queue that supports message acknowledgment, and receive instruction sequences. The system performs digital signature verification, data integrity checks, and priority scheduling execution to ensure secure and reliable command delivery. This connection uses TLS 1.3 encrypted transmission and an ACK / NACK confirmation mechanism to ensure commands are protected against eavesdropping, tampering, and replay. The command execution module internally houses a verification and execution engine, the mathematical expression of which is as follows: In this invention, the following settings are provided: For the first The local verification result of the instruction is 1, indicating that the verification is successful and the instruction can be executed; 0 indicates that execution is rejected and an exception is reported. This invention sets... The SHA-256 hash function used by the receiving end must be strictly consistent with that used by the sending end; this invention sets... To protect the public key of the decision-making module, it is pre-stored in the secure storage area of the instruction execution module; this invention sets... The cyclic redundancy check code calculated by the sending end uses the CRC-32 algorithm; in this invention, it is set... This is a checksum recalculated by the receiving end in response to the received instruction; only when... When, the instruction is pressed Execution is prioritized and queued, and the execution results are fed back to the protection decision module through the same channel, forming a closed-loop control.
[0078] In this embodiment of the invention, the data acquisition module includes a data cleaning and standardization sub-module; The data cleaning and standardization submodule performs preprocessing operations such as noise filtering, missing value imputation, and unit standardization on the raw running data. The processed, standardized data stream is provided to the multidimensional risk perception module for real-time analysis to ensure the accuracy and reliability of risk assessment.
[0079] It should be noted that the runtime data acquisition module is a component responsible for collecting various raw data generated during runtime from the target system or device.
[0080] For example, in this embodiment, the data acquisition module is used to acquire real-time operating parameters of industrial equipment such as temperature, pressure, and vibration.
[0081] It should be noted that the data cleaning and standardization submodule is a functional unit that processes the collected raw data, removes noise, fills in missing values, and standardizes the data format and units.
[0082] For example, this submodule improves data quality by filtering out outliers (such as temperature readings that are outside the reasonable range), supplementing missing data caused by sensor malfunctions, and unifying pressure units from different sources to Pascals (Pa).
[0083] It should be noted that noise filtering is used to identify and remove invalid or interfering information in the data in order to retain the true and meaningful data.
[0084] For example, for the vibration signal of a machine, high-frequency noise caused by environmental electromagnetic interference is removed, and only the effective low-frequency components reflecting the health status of the equipment are retained.
[0085] It should be noted that missing value imputation refers to using specific algorithms or methods to infer and supplement the missing or non-existent parts of a dataset, thereby restoring data integrity.
[0086] For example, when the humidity sensor does not return any records for a certain period of time, the average value of the preceding and following time points is used as the estimate to fill in the gaps.
[0087] It should be noted that the multidimensional risk perception module refers to an advanced computing unit that comprehensively analyzes multiple types of input data to assess potential risk conditions.
[0088] For example, based on a preprocessed standardized data stream, the module simultaneously monitors equipment temperature change trends, load fluctuations, and external environmental conditions to predict potential overheating or overload risks.
[0089] It should be noted that the accuracy and reliability of risk assessment refers to the ability of risk judgments derived through scientific methods to accurately reflect the actual situation and maintain consistency and stability in repeated experiments.
[0090] For example, by learning from historical failure cases and combining them with the characteristics of current standardized data streams, the system can accurately identify more than 95% of high-risk scenarios, while keeping the false alarm rate below 1%, demonstrating the high efficiency of the evaluation system.
[0091] The above-mentioned unit modules can be embedded in the processor of the electronic device in hardware form or independent of it, or they can be stored in the memory of the electronic device in software form, so that the processor can call and execute the corresponding operations of the above modules.
[0092] Example 2, in a preferred embodiment, involves the data cleaning and standardization submodule within the data acquisition module establishing a raw data subscription connection with the sensor network and SCADA system deployed in substations, transmission towers, and distribution rooms, and receiving raw data streams. The system performs noise filtering, missing value imputation, and dimension normalization to provide high-quality, highly consistent data, supporting the accuracy of subsequent risk assessments. The connection uses the MQTT protocol to subscribe to topics, supports reconnection after disconnection and data caching to ensure no data loss.
[0093] The mathematical expression of the internal processing flow of the data cleaning and standardization submodule is as follows: In this invention, the following settings are provided: For the first After standardizing the data points, the output value range is forcibly normalized to [0, 1]; in this invention, the following is set... The cleaned data is derived from the original data. Impulse noise is removed by sliding window mid-range filtering, and missing values are filled in using linear interpolation. This invention sets... and The minimum and maximum values within the current processing batch (batch size is set to 1000 points in this invention) are used to perform Min-Max normalization; this standardized output The data is pushed to the multi-dimensional risk perception module in real time, serving as a common input source for the physical security assessment unit, network intrusion detection unit, and abnormal behavior analysis unit. This ensures that the three assessment engines perform calculations based on the same data benchmark, avoiding conflicts in assessment results due to differences in dimensions or noise.
[0094] Example 3, referring to Figure 2 This embodiment also provides a power grid security protection method, including: Obtain real-time operating parameters and environmental monitoring information of key nodes in the power grid; Register, track, and maintain digital profiles and physical status of all connected devices in the power grid; By integrating the acquired data, digital archives, and physical status, a comprehensive security risk assessment covering physical, network, and behavioral levels is performed. Receive the assessment results of the comprehensive security risk assessment, and generate the optimal security response strategy by combining the preset protection rule base with the power grid operation context; Receive security instructions from the optimal security response strategy and invoke the local control interface to perform isolation, alarm, or recovery operations.
[0095] This embodiment also provides an electronic device, which can be a terminal, and its internal structure diagram can be as follows: Figure 2As shown, the electronic device includes a processor, memory, communication interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a power grid safety protection method. The display screen can be an LCD screen or an e-ink screen. The input device can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the device's casing, or an external keyboard, touchpad, or mouse.
[0096] This embodiment also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, it performs the following steps: Obtain real-time operating parameters and environmental monitoring information of key nodes in the power grid; Register, track, and maintain digital profiles and physical status of all connected devices in the power grid; By integrating the acquired data, digital archives, and physical status, a comprehensive security risk assessment covering physical, network, and behavioral levels is performed. Receive the assessment results of the comprehensive security risk assessment, and generate the optimal security response strategy by combining the preset protection rule base with the power grid operation context; Receive security instructions from the optimal security response strategy and invoke the local control interface to perform isolation, alarm, or recovery operations.
[0097] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
[0098] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0099] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A power grid security protection system, characterized in that, include: The data acquisition module is used to continuously acquire real-time operating parameters and environmental monitoring information of key nodes in the power grid; The asset management module is used to register, track, and maintain the digital profiles and physical status of all connected devices in the power grid; The multi-dimensional risk perception module is used to integrate information from the operational data acquisition module and the asset management module to perform a comprehensive security risk assessment covering physical, network, and behavioral levels. The protection decision module receives the evaluation results from the multi-dimensional risk perception module and, in conjunction with the preset protection rule base and the power grid operation context, generates the optimal safety response strategy. The instruction execution module is deployed at the edge to receive security instructions issued by the protection decision module and call the local control interface to perform isolation, alarm or recovery operations. The visualization monitoring module is used to display the risk assessment process, decision-making basis, and execution results in real time and allow for historical tracing through a graphical interface; The protection decision-making module is deployed in the cloud core system; the terminal components of the operation data acquisition module, instruction execution module and visualization monitoring module are deployed at edge nodes in each region.
2. The power grid security protection system as described in claim 1, characterized in that, The multi-dimensional risk perception module includes a physical security assessment unit, a network intrusion detection unit, and an abnormal behavior analysis unit. The physical safety assessment unit is equipped with an insulation performance detection engine, an arc fault identification engine, and a load status monitoring engine, which are used to quantitatively assess the physical health of electrical equipment. The network intrusion detection unit integrates an anomaly detection model based on traffic characteristics and a threat matching engine based on signatures to identify potential network attack behaviors. The abnormal behavior analysis unit detects suspicious behaviors that deviate from the normal pattern by establishing a baseline model of personnel activities, equipment operation, and data access.
3. The power grid security protection system as described in claim 2, characterized in that, The physical security assessment unit further includes a comprehensive scoring engine; The comprehensive scoring engine receives output signals from the insulation performance detection engine, the arc fault identification engine, and the load condition monitoring engine. Based on a preset weighted algorithm, various physical indicators are converted into a unified quantitative score to generate a comprehensive safety index for the equipment. When the overall security index falls below the preset security threshold, a high-risk warning is triggered, and the warning information is pushed to the protection decision module and the visualization monitoring module.
4. The power grid security protection system as described in claim 3, characterized in that, The baseline model in the abnormal behavior analysis unit is dynamically constructed and updated using machine learning methods. The baseline model covers multi-dimensional features of operation sequences, access time windows, and data interaction patterns under normal operating conditions; When the similarity between the real-time monitored behavioral pattern and the baseline model is lower than the set confidence level, it is judged as an abnormal behavioral event.
5. A power grid security protection system as described in claim 4, characterized in that, The protection decision module includes a strategy matching engine and an instruction orchestration engine; The strategy matching engine retrieves and matches the most suitable response plan from the protection rule base based on the risk type, risk level, scope of affected assets, and current power grid operation mode. The instruction orchestration engine transforms the selected plan into a set of ordered, executable control instructions, and adds execution priority, target device identifier and digital signature to each instruction.
6. The power grid security protection system as described in claim 5, characterized in that, The instruction execution module and the protection decision module interact through an encrypted communication queue that supports message confirmation; After receiving the instruction sequence, the instruction execution module verifies the validity of the digital signature and the integrity of the instructions; According to the priority order of the instructions, the local preset control functions are called in sequence to perform physical or logical operations, and the execution status and results are fed back to the protection decision module.
7. A power grid security protection system as described in claim 6, characterized in that, The operational data acquisition module includes a data cleaning and standardization sub-module; The data cleaning and standardization submodule performs preprocessing operations such as noise filtering, missing value imputation, and unit standardization on the raw running data. The processed, standardized data stream is provided to the multidimensional risk perception module for real-time analysis to ensure the accuracy and reliability of risk assessment.
8. A power grid security protection method, using the system described in any one of claims 1 to 7, characterized in that, include: Obtain real-time operating parameters and environmental monitoring information of key nodes in the power grid; Register, track, and maintain digital profiles and physical status of all connected devices in the power grid; By integrating the acquired data, digital archives, and physical status, a comprehensive security risk assessment covering physical, network, and behavioral levels is performed. Receive the assessment results of the comprehensive security risk assessment, and generate the optimal security response strategy by combining the preset protection rule base with the power grid operation context; Receive security instructions from the optimal security response strategy and invoke the local control interface to perform isolation, alarm, or recovery operations.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the power grid security protection method according to claim 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the power grid security protection method according to claim 8.