Distributed energy regulation and control method and system based on wired and short multiplexing communication modes
By combining wired and short-pass multiplexing communication methods, a cold standby dual-channel distributed energy regulation system was constructed, which solved the security and reliability issues of low-voltage distributed photovoltaic power participating in grid regulation and achieved the stability and security of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-04-07
AI Technical Summary
Currently, the regulation of distributed energy sources cannot fully meet the power business needs of low-voltage distributed photovoltaic power grid participation in grid regulation in terms of security, bandwidth, and channel reliability, which threatens the stability and security of grid operation.
The method combines wired and short-multiplexed communication, and constructs a cold standby dual channel through wired access and short-multiplexed access, which has seamless switching function. Data transmission is realized by using industrial Ethernet switches, optical network units, 4G/5G base stations and other equipment, and data isolation and transmission are achieved through the power's own optical fiber transmission network and power-dedicated VPN channel.
It achieves stable and reliable transmission of distributed energy regulation and control business data, and has a dual-channel cold backup and automatic switching mechanism, which improves channel reliability and security, and ensures the continuity and security of power regulation and control business data transmission.
Smart Images

Figure CN121814792A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of power communication technology and relates to a method and system for distributed energy regulation. Background Technology
[0002] With the large-scale integration of distributed photovoltaic (PV) systems, problems such as grid peak shaving, distribution network equipment overload, and voltage exceeding limits are becoming increasingly prominent. Most low-voltage distributed PV projects lack sufficient "observable, measurable, adjustable, and controllable" capabilities, hindering their ability to fully participate in grid regulation and posing a serious threat to the stability and security of the power grid. The sheer number of low-voltage distributed PV systems and their large-scale grid connection inevitably bring challenges related to peak shaving, frequency regulation, power balance, power quality, and spot trading. However, current distributed energy regulation services primarily rely on single-mode wireless or wired connections, which cannot fully meet the power service requirements of low-voltage distributed PV systems participating in grid regulation in terms of security, bandwidth, and channel reliability. Summary of the Invention
[0003] To address the issue described in the background art that current distributed energy regulation cannot fully meet the power business requirements of low-voltage distributed photovoltaic power grid participation in grid regulation in terms of security, bandwidth, and channel reliability, this invention provides a distributed energy regulation method and system based on wired and short-pass multiplexing communication. This method combines the two secure and reliable communication methods of wired and short-pass multiplexing, leveraging the advantages of both methods simultaneously. This allows the distributed energy regulation business terminal to have a backup channel during data transmission, enabling automatic switching and ensuring channel reliability.
[0004] The method of the present invention includes: The distributed energy control service terminal transmits power distributed energy control service data to the control master station system server through two access methods: wired and short-term multiplexing. The two access methods are cold standby methods and have seamless switching capabilities. The wired access method includes: deploying an access layer industrial Ethernet switch in the distributed energy control service terminal, collecting power distributed energy control service data through the access layer industrial Ethernet switch and uploading it through an optical fiber ring network, utilizing the power company's own optical fiber transmission network, and transmitting it to the control master station system server through a wired secure access area; and deploying an optical network unit (ONU) in the distributed energy control service terminal, collecting power distributed energy control service data through the ONU and uploading it through a daisy-chain network, utilizing the power company's own optical fiber transmission network, and transmitting it to the control master station system server through a wired secure access area. The short-multiplexed access method includes: the distributed energy control service terminal opens a dedicated VPN channel for power services in the operator's distribution and aggregation network through a 4G base station or a 5G base station, and isolates the distributed energy control service from the operator's services through the dedicated VPN channel; the distributed energy control service isolated by the dedicated VPN channel is transmitted to a dedicated UPF using the power's own optical fiber transmission network and a short-multiplexed communication method, and the dedicated UPF forwards it to the control master station system server through the wireless security access zone.
[0005] Furthermore, the distributed energy control service terminal is connected to the access layer industrial Ethernet switch via an RJ45 interface. The access layer industrial Ethernet switch uses the power company's own optical fiber transmission network through an optical fiber ring network to aggregate the power distributed energy control service data from the aggregation layer industrial Ethernet switch to the core layer industrial Ethernet switch. After passing through the wired secure access area, the power distributed energy control service data is finally transmitted to the control master station system server.
[0006] Furthermore, the distributed energy control service terminal is connected to the optical network unit (ONU) via an RJ45 interface. The ONU is connected to multiple parallel optical splitters in a daisy-chain network. Utilizing the power company's own optical fiber transmission network, the distributed energy control service data is aggregated and transmitted to the OLT optical line unit. After passing through the wired secure access area, the distributed energy control service data is finally transmitted to the control master station system server.
[0007] Furthermore, the distributed energy control service terminal uses 4G or 5G base stations for access, sharing access between the operator's 4G or 5G base stations and the power 5GC. It shares RB resources on the air interface side of the operator's 4G or 5G base stations, adds interfaces to the operator's distribution aggregation network equipment, and opens a dedicated VPN channel for power through the added interfaces to isolate the distributed energy control service from the operator's service. The distributed energy control service uses short-multiplexed communication to aggregate to a dedicated UPF, and the dedicated UPF forwards the data to the control master station system server via the wireless security access zone.
[0008] Furthermore, the short-multiplexed communication method includes: through a converged architecture of 4G or 5G short-multiplexed communication with shared time and frequency resources, and through a dedicated power core network and dedicated network number, card number and IP, a dedicated channel with end-to-end deterministic isolation and stable latency and a completely closed and independent wide-area dedicated power network are reconstructed and customized on the public network wireless air interface, so as to autonomously manage the power SIM card number, the configuration of power distributed energy regulation services and system operation and maintenance.
[0009] Furthermore, the interconnection between the operator's data center and the power data center includes: The power transmission network equipment and the operator's distribution aggregation network equipment are connected by a dual optical cable laid between the power equipment room and the operator's aggregation equipment. Firewalls or isolation devices are deployed between the power transmission network equipment and the government and enterprise dedicated access equipment of the operator's distribution aggregation network. The firewalls or isolation devices are interconnected with the power transmission network equipment through Ethernet interfaces and with the government and enterprise dedicated access equipment of the operator's distribution aggregation network through Ethernet interfaces, and Layer 2 port aggregation is enabled. Power business data is aggregated to the operator's core computer room through the operator's access network and aggregation network. Interconnection access routers and isolation devices for controlled and non-controlled services are deployed between the operator's core router and the power's own transmission network equipment, and interconnected with the power's own transmission network equipment through Ethernet interfaces.
[0010] Furthermore, the dedicated VPN tunnel for power systems ensures information security in the following ways: By adopting a unified IP address coding scheme, a network organizational structure is established to manage access permissions for business systems, abnormal IP addresses are detected and blocked in a timely manner, thereby improving network security quality. Employing multi-level data exchange, leveraging multiple data structures to achieve information protection, performing analysis according to data type, strengthening management access control, and enhancing information and data security; It employs multi-type information data encryption algorithms to complete the plaintext data conversion and decryption using a specific key to ensure data security; Information security transmission encapsulation is adopted, and information protection is achieved through packaging and encapsulation to intercept network information access behavior; Implement secondary verification and binding authentication to further ensure information security isolation; IPSec encryption is enabled on the interfaces of base station-power 5GC, base station-UPF, and UPF-secure access zone.
[0011] Furthermore, the power system's proprietary transmission network includes a time-division multiplexing-based SDH optical fiber transmission network, a wavelength-division-based OTN optical transmission network, an OTN-based OSU optical service unit, a packet-slicing packet network based on a packet transmission network, and an Ethernet-based data communication network. Based on the existing power system's proprietary transmission network, the power system selects and organizes network channels shared by operators: base station-power 5GC, power UPF-power 5GC, and power UPF-power service system.
[0012] Furthermore, both the wired and wireless secure access zones include industrial Ethernet switches and / or xPON; power distributed energy control service data is transmitted to the control master station system server via the wired secure access zone through address mapping; power distributed energy control service data is forwarded to the control master station system server via the wireless secure access zone through address mapping using short multiplexing; the wired and wireless secure access zones are constructed independently and networked separately.
[0013] Based on the above method, the present invention provides a distributed energy control system based on wired and short-multiplexed communication, including a distributed energy control service terminal, an access layer industrial Ethernet switch, an optical network unit (ONU), a wired secure access area, a 4G base station or a 5G base station, a dedicated UPF, a wireless secure access area, a power-owned optical fiber transmission network, and a control master station system server. The distributed energy control service terminal is equipped with an access layer industrial Ethernet switch. The power distributed energy control service data is collected through the access layer industrial Ethernet switch and uploaded through the optical fiber ring network. The data is then transmitted to the control master station system server via the power company's own optical fiber transmission network and the wired secure access area. The distributed energy control service terminal is equipped with an optical network unit (ONU). The ONU collects power distributed energy control service data and uploads it through a daisy-chain network. It utilizes the power company's own optical fiber transmission network and transmits the data to the control master station system server via a wired secure access area. The distributed energy control service terminal opens a dedicated VPN channel for power services in the operator's distribution and aggregation network via a 4G or 5G base station. The dedicated VPN channel isolates the distributed energy control service from the operator's services. The distributed energy control service isolated by the dedicated VPN channel is transmitted to a dedicated UPF using the power company's own optical fiber transmission network and short multiplexing communication. The dedicated UPF then forwards the data to the control master station system server via a wireless security access zone.
[0014] Compared with the prior art, the present invention has the following advantages: (1) Dual-channel cold standby and automatic switching mechanism: This invention constructs a cold standby dual channel through wired and short-term multiplexing communication methods and has a seamless switching function; when the primary channel fails or its performance degrades, the system can automatically switch to the backup channel to ensure that the power control business data transmission is uninterrupted; this mechanism is based on the redundancy backup principle of the communication system, which effectively improves the reliability of the channel and avoids the business stagnation caused by the interruption or congestion of a single communication method. (2) Stable transmission architecture of wired access: The wired access uses industrial Ethernet switches to form a fiber optic ring network, or uses optical network units (ONUs) to form a daisy-chain network. Both rely on the power's own fiber optic transmission network for data transmission. This method utilizes the characteristics of strong anti-interference, high bandwidth and low latency of fiber optic communication to ensure the security and stability of the control business transmission within the power private network, which meets the basic requirements of the power system for a highly reliable communication channel. (3) Security isolation design of short multiplex private network channel: The short multiplex access accesses the operator network through 4G / 5G base stations and opens a dedicated VPN channel for power to realize the logical isolation between power services and public services; after the service data enters the power's own transmission network through the VPN channel, it is forwarded to the control master station through a dedicated UPF and wireless security access area; this design is based on network virtualization and secure tunnel technology, which, while taking advantage of the operator's wide wireless coverage and flexible deployment, ensures the private network nature and transmission security of the service data. (4) Optimization of transmission path and maximization of use of proprietary network resources: Both access methods emphasize the use of the power company’s proprietary fiber optic transmission network for carrying after aggregation, which reduces the exposure of data in the public network and shortens the transmission path in the public network. This design is based on the principle of network transmission path optimization. By making the maximum use of the power company’s proprietary isolation pipeline, it reduces the risk of data being stolen or tampered with, while improving transmission efficiency and controllability. (5) Enhanced overall service access reliability through converged communication mode: By combining the high stability of wired communication with the flexible coverage of wireless short-term multiplexing, a heterogeneous communication converged bearer mode is constructed. Based on the principle of complementary enhancement of communication networks, this mode enables the distributed energy control system to obtain reliable access in different geographical and network environments, thereby enhancing the overall adaptability and access resilience of control services to complex communication conditions.
[0015] In summary, this invention utilizes a combination of wired and short-multiplexed methods to achieve the transmission of distributed energy regulation services. It features stable and reliable fiber optic channels, short-multiplexed channels with the shortest public network segmentation, minimal leasing of links, and maximum utilization of the isolation pipelines provided by the power grid's own transmission network. Both channels employ a cold standby method, further enhancing the stability of distributed energy regulation service access. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of a distributed energy regulation system. Detailed Implementation
[0017] To make the technical problems, technical solutions, and beneficial effects to be solved by this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and are not intended to limit the scope of this application.
[0018] A schematic diagram of a distributed energy regulation system is shown below. Figure 1 As shown, based on Figure 1 This application provides a detailed description of the access methods and systems for distributed energy regulation and control service terminals, mainly including industrial Ethernet switch method, xPON method, short multiplexing method, power proprietary transmission network, and secure access zone.
[0019] Example 1 This application provides a distributed energy control method based on wired and short-pass multiplexing communication. The distributed energy control service terminal transmits power distributed energy control service data to the control master station system server through both wired and short-pass multiplexing access methods. These two access methods are cold standby methods, providing seamless switching functionality.
[0020] Specifically, there are two wired access methods: 1. Deploy access layer industrial Ethernet switches in the distributed energy control business terminal. Collect distributed energy control business data through the access layer industrial Ethernet switches and upload it through the fiber optic ring network. Utilize the power company's own fiber optic transmission network and transmit it to the control master station system server through the wired secure access area.
[0021] 2. Deploy optical network units (ONUs) in the distributed energy regulation and control service terminals. Collect distributed energy regulation and control service data through the ONUs and upload it through a daisy-chain network. Utilize the power company's own optical fiber transmission network and transmit it to the regulation and control master station system server via a wired secure access area.
[0022] In one embodiment, the distributed energy control service terminal is connected to the access layer industrial Ethernet switch via an RJ45 interface. The access layer industrial Ethernet switch uses the power company's own optical fiber transmission network through an optical fiber ring network to aggregate the power distributed energy control service data from the aggregation layer industrial Ethernet switch to the core layer industrial Ethernet switch. After passing through the wired security access zone, the power distributed energy control service data is finally transmitted to the control master station system server.
[0023] In this embodiment, distributed energy control business data is transmitted to the inverter communication interface, which can use communication interfaces such as RS232, RS485, and RJ45. However, since the transmission rate and protocol compatibility of interfaces such as RS232 and RS485 are limited, the mainstream approach is to convert the Modbus protocol to the TCP / IP protocol to expand the communication protocol and support remote control, and to use the RJ45 interface as the communication interface.
[0024] The industrial Ethernet switch network architecture comprises an access layer, an aggregation layer, and a core layer. The access layer is used for data acquisition and uploading from the service terminals, the aggregation layer for data aggregation from the access layer, and the core layer for data aggregation from the aggregation layer and transmission of the data to the service master station server via a wired secure access zone. The access layer industrial Ethernet switches are deployed on the service terminal side, interconnecting with the distributed energy control terminal communication module via RJ45 interfaces and with the upper-layer industrial Ethernet switches via two different optical ports to form a ring network. The RPS ring network protocol is enabled, providing rapid channel convergence capability. The aggregation layer industrial Ethernet switches, via RJ45 interfaces, utilize the power grid's own transmission network (including various existing networks such as SDH, OTN, fgOTN, SPN, and data communication networks), allocating dedicated production time slot channels to transmit data to the control master station system server via a wired secure access zone.
[0025] In one embodiment, the distributed energy control service terminal is connected to the optical network unit (ONU) via an RJ45 interface. The ONU is connected to multiple parallel optical splitters in a daisy-chain network. Using the power company's own optical fiber transmission network, the distributed energy control service data is aggregated and transmitted to the OLT optical line unit. After passing through the wired security access area, the distributed energy control service data is finally transmitted to the control master station system server.
[0026] In this embodiment, distributed energy control business data is transmitted to the inverter communication interface, which can use communication interfaces such as RS232, RS485, and RJ45. However, since the transmission rate and protocol compatibility of interfaces such as RS232 and RS485 are limited, the mainstream approach is to convert the Modbus protocol to the TCP / IP protocol to expand the communication protocol and support remote control, and to use the RJ45 interface as the communication interface.
[0027] The xPON network architecture includes an OLT (Optical Line Unit), an ODN (Optical Distribution Unit), and an ONU (Optical Network Unit). The ONU is used for data acquisition and uploading at the service terminal side, while the ODN is used for fiber optic core distribution. The OLT is deployed at core or aggregation sites such as provincial / regional / substations, used for ONU data aggregation and transmission of data to the service master station server via a wired secure access area. The ONU is deployed at the service terminal side, interconnected with the distributed energy control terminal communication module via an RJ45 interface, and connected to two different ODNs via two PON ports. It connects to two different OLTs or different PON ports of the same OLT via optical cables, using a daisy-chain networking approach, providing rapid channel switching capability and improving the channel reliability of wired transmission. The OLT, through an RJ45 interface, utilizes the power grid's own transmission network (including various existing networks such as SDH, OTN, fgOTN, SPN, and data communication networks) to allocate dedicated production time slot channels, transmitting data to the control master station system server via a wired secure access area.
[0028] Specifically, the short-multiplexed access method is as follows: the distributed energy control service terminal opens a dedicated VPN channel for power services in the operator's distribution and aggregation network through a 4G base station or a 5G base station, and isolates the distributed energy control service from the operator's services through the dedicated VPN channel; the distributed energy control service isolated by the dedicated VPN channel is transmitted to the dedicated UPF using the power's own optical fiber transmission network and the short-multiplexed communication method, and the dedicated UPF forwards it to the control master station system server through the wireless security access zone.
[0029] In one embodiment, the distributed energy control service terminal uses a 4G base station or a 5G base station for access, shares the access of the operator's 4G base station or 5G base station to the power 5GC, shares RB resources on the air interface side of the operator's 4G base station or 5G base station, adds an interface on the operator's distribution aggregation network equipment, and opens a dedicated VPN channel for power through the added interface to isolate the power distributed energy control service from the operator's service. The power distributed energy control service uses short multiplexing communication to aggregate to a dedicated UPF, and the dedicated UPF forwards to the control master station system server through the wireless security access zone.
[0030] In this embodiment, distributed energy control business data is transmitted to the inverter communication interface, which can use communication interfaces such as RS232, RS485, and RJ45. However, since the transmission rate and protocol compatibility of interfaces such as RS232 and RS485 are limited, the mainstream approach is to convert the Modbus protocol to the TCP / IP protocol to expand the communication protocol and support remote control, and to use the RJ45 interface as the communication interface.
[0031] The short-multiplexed network architecture includes base stations, a radio access network, an operator bearer network, a power grid-owned transmission network, a power grid 5GC, and a power grid UPF (configured as a production control area UPF, management information area UPF, etc., depending on the service). Base stations include 4G and 5G base stations, sharing access to the power grid 5GC via an S1 link. Service terminals share RB resources on the radio interface side to access the base stations. The radio access network includes radio frequency units (RRU, for transmitting and receiving 4G radio signals; AAU, for transmitting and receiving 5G radio signals) and a baseband processing unit (BBU, for separate 4G and 5G access). The baseband processing unit converts radio signals into data packets that can be transmitted by the bearer network. The interconnection between the operator's bearer network and the power grid's proprietary transmission network is based on the relative length of the power business data transmission path, and includes two interconnection methods. One method involves aggregating power data using aggregation routers in the operator's aggregation room and short-multiplexed dedicated access routers, then interconnecting with the power grid's proprietary transmission network through firewalls / isolation devices. The other method involves transmitting power data via the operator's bearer network to the core router in the regional hub room, then aggregating the power data through short-multiplexed dedicated access routers, and finally interconnecting with the power grid's proprietary transmission network through firewalls / isolation devices. Utilizing the power grid's proprietary transmission network (including various existing networks such as SDH, OTN, fgOTN, SPN, and data communication networks), dedicated production time slot channels are allocated to transmit data to the power UPF and base station signaling to the power 5GC. The UPF then transmits the data through a wired secure access area to the control master station system server.
[0032] In practical applications, short-multiplexed communication methods include: using a converged architecture of 4G or 5G short-multiplexed communication through time-frequency resource sharing, and reconstructing a dedicated, end-to-end deterministically isolated, latency-stable dedicated channel and a completely closed and independent wide-area dedicated power network on the public wireless air interface through a dedicated power core network and dedicated network numbers, card numbers and IPs, so as to autonomously manage power SIM card numbers, power distributed energy regulation service configuration and system operation and maintenance.
[0033] In one embodiment, the operator's data center is interconnected with the power supply data center, including: A dual optical fiber cable is laid between the power equipment room and the operator's aggregation equipment room to connect the optical paths of the power company's own transmission network equipment and the operator's distribution aggregation network equipment. Firewalls or isolation devices are deployed between the power company's own transmission network equipment and the dedicated government and enterprise access equipment of the operator's distribution aggregation network. The firewalls or isolation devices are interconnected with the power company's own transmission network equipment through Ethernet interfaces, and interconnected with the dedicated government and enterprise access equipment of the operator's distribution aggregation network through Ethernet interfaces, with Layer 2 port aggregation enabled. Power business data is aggregated to the operator's core equipment room through the operator's access network and aggregation network. Interconnection access routers and isolation devices for controlled and non-controlled services are deployed between the operator's core router and the power company's own transmission network equipment, respectively, and interconnected with the power company's own transmission network equipment through Ethernet interfaces.
[0034] In practical applications, for interconnections between carrier aggregation rooms and power supply rooms, the carrier's city or county-level aggregation rooms are selected, and dual optical cables are laid between the power supply and the carrier aggregation rooms. An interconnection firewall (isolation device) is added to the power supply room, and a link channel is configured between the power supply's proprietary transmission network, the interconnection firewall (isolation device), and the carrier's dedicated enterprise access router in the aggregation room. For interconnections between carrier city-level hub rooms and power supply rooms, the carrier's city-level hub room is selected, and interconnection access routers and isolation devices are deployed at the city power supply company. A link channel is configured between the power supply's proprietary transmission network, the isolation device, the interconnection access router, and the carrier's core bearer network equipment.
[0035] In one embodiment, to prevent conventional VPN technologies from failing to prevent data tracking, viruses, or malware, and from being unable to prevent phishing scams, and from posing security risks such as information tampering, data eavesdropping, and node impersonation when dealing with network attacks, malicious intrusions, and virus implantations, thus causing data leakage and other security vulnerabilities, the power-dedicated VPN channel uses the following methods to ensure information security: By adopting a unified IP address coding scheme, a network organizational structure is established to manage access permissions for business systems, abnormal IP addresses are detected and blocked in a timely manner, thereby improving network security quality. Employing multi-level data exchange, leveraging multiple data structures to achieve information protection, performing analysis according to data type, strengthening management access control, and enhancing information and data security; It employs multi-type information data encryption algorithms to complete the plaintext data conversion and decryption using a specific key to ensure data security; Information security transmission encapsulation is adopted, and information protection is achieved through packaging and encapsulation to intercept network information access behavior; Implement secondary verification and binding authentication to further ensure information security isolation; IPSec encryption is enabled on the interfaces of base station-power 5GC, base station-UPF, and UPF-secure access zone.
[0036] In practical applications, enabling IPSec national standard encryption functions includes: enabling IPSec national standard encryption functions on the N2 port of the base station-power 5GC; enabling IPSec national standard encryption functions on the N3 port of the base station-power UPF; enabling IPSec national standard encryption functions on the N4 port of the power UPF-power 5GC; and enabling IPSec national standard encryption functions on the N6 port of the power UPF-secure access zone (wireless).
[0037] In one embodiment, the power system's proprietary transmission network includes a time-division multiplexing-based SDH optical fiber transmission network, a wavelength division multiplexing-based OTN optical transmission network, an OTN-based OSU optical service unit, a packet-slicing packet network based on a packet transmission network, and an Ethernet-based data communication network. The power system selects and organizes network channels shared by operators for the base station-power 5GC, power UPF-power 5GC, and power UPF-power service system, based on the existing power system proprietary transmission network.
[0038] In practical applications, based on the current status of the power grid's own transmission network, various proprietary transmission networks such as SDH, OTN, OSU, SPN, and data communication networks can be flexibly selected, and base station-power 5GC, power UPF-power 5GC, and power UPF-security access zone-control master station system channels can be configured as needed to maximize the utilization of the power grid's own transmission network.
[0039] In one embodiment, both the wired security access zone and the wireless security access zone include industrial Ethernet switches and / or xPON; power distributed energy control service data is transmitted to the control master station system server through the wired security access zone via address mapping; power distributed energy control service data is forwarded to the control master station system server via the wireless security access zone using short multiplexing; the wired security access zone and the wireless security access zone are constructed independently and networked separately.
[0040] In practical applications, before aggregating distributed energy regulation and control business data to the main control station system server via industrial Ethernet switches, xPON, and short multiplexing, the data is first accessed through a secure access zone. Wired and wireless secure access zones are deployed separately, using industrial Ethernet switches and xPON for wired access and short multiplexing for wireless access. These zones are not directly interconnected with the main control station system server to ensure data isolation and protect the server. Data is ultimately transmitted to the main control station system server via address mapping through the secure access zone.
[0041] Example 2 This application provides a distributed energy control system based on wired and short-multiplexed communication, including a distributed energy control service terminal, an access layer industrial Ethernet switch, an optical network unit (ONU), a wired secure access area, a 4G or 5G base station, a dedicated UPF, a wireless secure access area, a power-owned optical fiber transmission network, and a control master station system server.
[0042] The distributed energy control service terminal is deployed with an access layer industrial Ethernet switch. The power distributed energy control service data is collected through the access layer industrial Ethernet switch and uploaded through the fiber optic ring network. It utilizes the power company's own fiber optic transmission network and transmits the data to the control master station system server through the wired security access area.
[0043] The distributed energy control service terminal is equipped with an optical network unit (ONU). The ONU collects power distributed energy control service data and uploads it through a daisy-chain network. It utilizes the power company's own optical fiber transmission network and transmits the data to the control master station system server via a wired secure access area.
[0044] The distributed energy control service terminal opens a dedicated VPN channel for power services in the operator's distribution and aggregation network through 4G or 5G base stations. The dedicated VPN channel isolates the distributed energy control service from the operator's services. The distributed energy control service isolated by the dedicated VPN channel is transmitted to a dedicated UPF using the power company's own optical fiber transmission network and short multiplexing communication. The dedicated UPF then forwards the data to the control master station system server via a wireless security access zone.
[0045] In one embodiment, the distributed energy control service terminal is connected to the access layer industrial Ethernet switch via an RJ45 interface. The access layer industrial Ethernet switch uses the power company's own optical fiber transmission network through an optical fiber ring network to aggregate the power distributed energy control service data from the aggregation layer industrial Ethernet switch to the core layer industrial Ethernet switch. After passing through the wired security access zone, the power distributed energy control service data is finally transmitted to the control master station system server.
[0046] In this embodiment, distributed energy control business data is transmitted to the inverter communication interface, which can use communication interfaces such as RS232, RS485, and RJ45. However, since the transmission rate and protocol compatibility of interfaces such as RS232 and RS485 are limited, the mainstream approach is to convert the Modbus protocol to the TCP / IP protocol to expand the communication protocol and support remote control, and to use the RJ45 interface as the communication interface.
[0047] The industrial Ethernet switch network architecture comprises an access layer, an aggregation layer, and a core layer. The access layer is used for data acquisition and uploading from the service terminals, the aggregation layer for data aggregation from the access layer, and the core layer for data aggregation from the aggregation layer and transmission of the data to the service master station server via a wired secure access zone. The access layer industrial Ethernet switches are deployed on the service terminal side, interconnecting with the distributed energy control terminal communication module via RJ45 interfaces and with the upper-layer industrial Ethernet switches via two different optical ports to form a ring network. The RPS ring network protocol is enabled, providing rapid channel convergence capability. The aggregation layer industrial Ethernet switches, via RJ45 interfaces, utilize the power grid's own transmission network (including various existing networks such as SDH, OTN, fgOTN, SPN, and data communication networks), allocating dedicated production time slot channels to transmit data to the control master station system server via a wired secure access zone.
[0048] In one embodiment, the distributed energy control service terminal is connected to the optical network unit (ONU) via an RJ45 interface. The ONU is connected to multiple parallel optical splitters in a daisy-chain network. Using the power company's own optical fiber transmission network, the distributed energy control service data is aggregated and transmitted to the OLT optical line unit. After passing through the wired security access area, the distributed energy control service data is finally transmitted to the control master station system server.
[0049] In this embodiment, distributed energy control business data is transmitted to the inverter communication interface, which can use communication interfaces such as RS232, RS485, and RJ45. However, since the transmission rate and protocol compatibility of interfaces such as RS232 and RS485 are limited, the mainstream approach is to convert the Modbus protocol to the TCP / IP protocol to expand the communication protocol and support remote control, and to use the RJ45 interface as the communication interface.
[0050] The xPON network architecture includes an OLT (Optical Line Unit), an ODN (Optical Distribution Unit), and an ONU (Optical Network Unit). The ONU is used for data acquisition and uploading at the service terminal side, while the ODN is used for fiber optic core distribution. The OLT is deployed at core or aggregation sites such as provincial / regional / substations, used for ONU data aggregation and transmission of data to the service master station server via a wired secure access area. The ONU is deployed at the service terminal side, interconnected with the distributed energy control terminal communication module via an RJ45 interface, and connected to two different ODNs via two PON ports. It connects to two different OLTs or different PON ports of the same OLT via optical cables, using a daisy-chain networking approach, providing rapid channel switching capability and improving the channel reliability of wired transmission. The OLT, through an RJ45 interface, utilizes the power grid's own transmission network (including various existing networks such as SDH, OTN, fgOTN, SPN, and data communication networks) to allocate dedicated production time slot channels, transmitting data to the control master station system server via a wired secure access area.
[0051] In one embodiment, the distributed energy control service terminal uses a 4G base station or a 5G base station for access, shares the access of the operator's 4G base station or 5G base station to the power 5GC, shares RB resources on the air interface side of the operator's 4G base station or 5G base station, adds an interface on the operator's distribution aggregation network equipment, and opens a dedicated VPN channel for power through the added interface to isolate the power distributed energy control service from the operator's service. The power distributed energy control service uses short multiplexing communication to aggregate to a dedicated UPF, and the dedicated UPF forwards to the control master station system server through the wireless security access zone.
[0052] In this embodiment, distributed energy control business data is transmitted to the inverter communication interface, which can use communication interfaces such as RS232, RS485, and RJ45. However, since the transmission rate and protocol compatibility of interfaces such as RS232 and RS485 are limited, the mainstream approach is to convert the Modbus protocol to the TCP / IP protocol to expand the communication protocol and support remote control, and to use the RJ45 interface as the communication interface.
[0053] The short-multiplexed network architecture includes base stations, a radio access network, an operator bearer network, a power grid-owned transmission network, a power grid 5GC, and a power grid UPF (configured as a production control area UPF, management information area UPF, etc., depending on the service). Base stations include 4G and 5G base stations, sharing access to the power grid 5GC via an S1 link. Service terminals share RB resources on the radio interface side to access the base stations. The radio access network includes radio frequency units (RRU, for transmitting and receiving 4G radio signals; AAU, for transmitting and receiving 5G radio signals) and a baseband processing unit (BBU, for separate 4G and 5G access). The baseband processing unit converts radio signals into data packets that can be transmitted by the bearer network. The interconnection between the operator's bearer network and the power grid's proprietary transmission network is based on the relative length of the power business data transmission path, and includes two interconnection methods. One method involves aggregating power data using aggregation routers in the operator's aggregation room and short-multiplexed dedicated access routers, then interconnecting with the power grid's proprietary transmission network through firewalls / isolation devices. The other method involves transmitting power data via the operator's bearer network to the core router in the regional hub room, then aggregating the power data through short-multiplexed dedicated access routers, and finally interconnecting with the power grid's proprietary transmission network through firewalls / isolation devices. Utilizing the power grid's proprietary transmission network (including various existing networks such as SDH, OTN, fgOTN, SPN, and data communication networks), dedicated production time slot channels are allocated to transmit data to the power UPF and base station signaling to the power 5GC. The UPF then transmits the data through a wired secure access area to the control master station system server.
[0054] In practical applications, short-multiplexed communication methods include: using a converged architecture of 4G or 5G short-multiplexed communication through time-frequency resource sharing, and reconstructing a dedicated, end-to-end deterministically isolated, latency-stable dedicated channel and a completely closed and independent wide-area dedicated power network on the public wireless air interface through a dedicated power core network and dedicated network numbers, card numbers and IPs, so as to autonomously manage power SIM card numbers, power distributed energy regulation service configuration and system operation and maintenance.
[0055] In one embodiment, the operator's data center is interconnected with the power supply data center, including: A dual optical fiber cable is laid between the power equipment room and the operator's aggregation equipment room to connect the optical paths of the power company's own transmission network equipment and the operator's distribution aggregation network equipment. Firewalls or isolation devices are deployed between the power company's own transmission network equipment and the dedicated government and enterprise access equipment of the operator's distribution aggregation network. The firewalls or isolation devices are interconnected with the power company's own transmission network equipment through Ethernet interfaces, and interconnected with the dedicated government and enterprise access equipment of the operator's distribution aggregation network through Ethernet interfaces, with Layer 2 port aggregation enabled. Power business data is aggregated to the operator's core equipment room through the operator's access network and aggregation network. Interconnection access routers and isolation devices for controlled and non-controlled services are deployed between the operator's core router and the power company's own transmission network equipment, respectively, and interconnected with the power company's own transmission network equipment through Ethernet interfaces.
[0056] In practical applications, for interconnections between carrier aggregation rooms and power supply rooms, the carrier's city or county-level aggregation rooms are selected, and dual optical cables are laid between the power supply and the carrier aggregation rooms. An interconnection firewall (isolation device) is added to the power supply room, and a link channel is configured between the power supply's proprietary transmission network, the interconnection firewall (isolation device), and the carrier's dedicated enterprise access router in the aggregation room. For interconnections between carrier city-level hub rooms and power supply rooms, the carrier's city-level hub room is selected, and interconnection access routers and isolation devices are deployed at the city power supply company. A link channel is configured between the power supply's proprietary transmission network, the isolation device, the interconnection access router, and the carrier's core bearer network equipment.
[0057] In one embodiment, to prevent conventional VPN technologies from failing to prevent data tracking, viruses, or malware, and from being unable to prevent phishing scams, and from posing security risks such as information tampering, data eavesdropping, and node impersonation when dealing with network attacks, malicious intrusions, and virus implantations, thus causing data leakage and other security vulnerabilities, the power-dedicated VPN channel uses the following methods to ensure information security: By adopting a unified IP address coding scheme, a network organizational structure is established to manage access permissions for business systems, abnormal IP addresses are detected and blocked in a timely manner, thereby improving network security quality. Employing multi-level data exchange, leveraging multiple data structures to achieve information protection, performing analysis according to data type, strengthening management access control, and enhancing information and data security; It employs multi-type information data encryption algorithms to complete the plaintext data conversion and decryption using a specific key to ensure data security; Information security transmission encapsulation is adopted, and information protection is achieved through packaging and encapsulation to intercept network information access behavior; Implement secondary verification and binding authentication to further ensure information security isolation; IPSec encryption is enabled on the interfaces of base station-power 5GC, base station-UPF, and UPF-secure access zone.
[0058] In practical applications, enabling IPSec national standard encryption functions includes: enabling IPSec national standard encryption functions on the N2 port of the base station-power 5GC; enabling IPSec national standard encryption functions on the N3 port of the base station-power UPF; enabling IPSec national standard encryption functions on the N4 port of the power UPF-power 5GC; and enabling IPSec national standard encryption functions on the N6 port of the power UPF-secure access zone (wireless).
[0059] In one embodiment, the power system's proprietary transmission network includes a time-division multiplexing-based SDH optical fiber transmission network, a wavelength division multiplexing-based OTN optical transmission network, an OTN-based OSU optical service unit, a packet-slicing packet network based on a packet transmission network, and an Ethernet-based data communication network. The power system selects and organizes network channels shared by operators for the base station-power 5GC, power UPF-power 5GC, and power UPF-power service system, based on the existing power system proprietary transmission network.
[0060] In practical applications, based on the current status of the power grid's own transmission network, various proprietary transmission networks such as SDH, OTN, OSU, SPN, and data communication networks can be flexibly selected, and base station-power 5GC, power UPF-power 5GC, and power UPF-security access zone-control master station system channels can be configured as needed to maximize the utilization of the power grid's own transmission network.
[0061] In one embodiment, both the wired security access zone and the wireless security access zone include industrial Ethernet switches and / or xPON; power distributed energy control service data is transmitted to the control master station system server through the wired security access zone via address mapping; power distributed energy control service data is forwarded to the control master station system server via the wireless security access zone using short multiplexing; the wired security access zone and the wireless security access zone are constructed independently and networked separately.
[0062] In practical applications, before aggregating distributed energy regulation and control business data to the main control station system server via industrial Ethernet switches, xPON, and short multiplexing, the data is first accessed through a secure access zone. Wired and wireless secure access zones are deployed separately, using industrial Ethernet switches and xPON for wired access and short multiplexing for wireless access. These zones are not directly interconnected with the main control station system server to ensure data isolation and protect the server. Data is ultimately transmitted to the main control station system server via address mapping through the secure access zone.
[0063] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of this application can be implemented in various computer languages, such as object-oriented programming languages like Java, C++, Python, and interpreted scripting languages like JavaScript.
[0064] This application is described with reference to flowchart illustrations and / or block diagrams of methods, electronic devices (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing electronic device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing electronic device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0065] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing electronic device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0066] These computer program instructions can also be loaded onto a computer or other programmable data processing electronic device to cause a series of operational steps to be performed on the computer or other programmable electronic device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable electronic device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0067] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0068] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A distributed energy regulation method based on wired and short-pass multiplexing communication, characterized in that, include: The distributed energy control service terminal transmits the power distributed energy control service data to the control master station system server through two access methods: wired and short-term multiplexing. Both access methods are cold standby methods, which have seamless switching capabilities; The wired access method includes: deploying an access layer industrial Ethernet switch in the distributed energy control service terminal, collecting power distributed energy control service data through the access layer industrial Ethernet switch and uploading it through an optical fiber ring network, utilizing the power company's own optical fiber transmission network, and transmitting it to the control master station system server through a wired secure access area; and deploying an optical network unit (ONU) in the distributed energy control service terminal, collecting power distributed energy control service data through the ONU and uploading it through a daisy-chain network, utilizing the power company's own optical fiber transmission network, and transmitting it to the control master station system server through a wired secure access area. The short-multiplexed access method includes: the distributed energy control service terminal opens a dedicated VPN channel for power services in the operator's distribution and aggregation network through a 4G base station or a 5G base station, and isolates the distributed energy control service from the operator's services through the dedicated VPN channel; the distributed energy control service isolated by the dedicated VPN channel is transmitted to a dedicated UPF using the power's own optical fiber transmission network and a short-multiplexed communication method, and the dedicated UPF forwards it to the control master station system server through the wireless security access zone.
2. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 1, characterized in that: The distributed energy control service terminal is connected to the access layer industrial Ethernet switch via an RJ45 interface. The access layer industrial Ethernet switch uses the power company's own optical fiber transmission network through an optical fiber ring network to aggregate the power distributed energy control service data from the aggregation layer industrial Ethernet switch to the core layer industrial Ethernet switch. After passing through the wired security access area, the power distributed energy control service data is finally transmitted to the control master station system server.
3. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 1, characterized in that: The distributed energy control service terminal is connected to the optical network unit (ONU) via an RJ45 interface. The ONU is connected to multiple parallel optical splitters in a daisy-chain network. Using the power company's own optical fiber transmission network, the distributed energy control service data is aggregated and transmitted to the OLT optical line unit. After passing through the wired security access area, the distributed energy control service data is finally transmitted to the control master station system server.
4. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 1, characterized in that: The distributed energy control service terminal uses 4G or 5G base stations for access, sharing access to the power 5GC with the operator's 4G or 5G base stations. It shares RB resources on the air interface side of the operator's 4G or 5G base stations, adds interfaces to the operator's distribution aggregation network equipment, and opens a dedicated VPN channel for power through the added interfaces to isolate the power distributed energy control service from the operator's service. The power distributed energy control service uses short multiplexing communication to aggregate to a dedicated UPF, and the dedicated UPF forwards to the control master station system server through the wireless security access zone.
5. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 4, characterized in that: The short-multiplexed communication method includes: through a converged architecture of 4G or 5G short-multiplexed communication using time-frequency resource sharing, and through a dedicated power core network and dedicated network number, card number and IP, a dedicated, end-to-end deterministically isolated, latency-stable dedicated channel and a completely closed and independent wide-area dedicated power network are reconstructed and customized on the public network wireless air interface, so as to autonomously manage the power SIM card number, the configuration of power distributed energy regulation services and system operation and maintenance.
6. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 5, characterized in that: The interconnection between the operator's data center and the power supply data center includes: The power transmission network equipment and the operator's distribution aggregation network equipment are connected by a dual optical cable laid between the power equipment room and the operator's aggregation equipment. Firewalls or isolation devices are deployed between the power transmission network equipment and the government and enterprise dedicated access equipment of the operator's distribution aggregation network. The firewalls or isolation devices are interconnected with the power transmission network equipment through Ethernet interfaces and with the government and enterprise dedicated access equipment of the operator's distribution aggregation network through Ethernet interfaces, and Layer 2 port aggregation is enabled. Power business data is aggregated to the operator's core computer room through the operator's access network and aggregation network. Interconnection access routers and isolation devices for controlled and non-controlled services are deployed between the operator's core router and the power's own transmission network equipment, respectively, and interconnected with the power's own transmission network equipment through Ethernet interfaces.
7. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 4, characterized in that: The dedicated VPN tunnel for power systems uses the following methods to ensure information security: By adopting a unified IP address coding scheme, a network organizational structure is established to manage access permissions for business systems, abnormal IP addresses are detected and blocked in a timely manner, thereby improving network security quality. Employing multi-level data exchange, leveraging multiple data structures to achieve information protection, performing analysis according to data type, strengthening management access control, and enhancing information and data security; It employs multi-type information data encryption algorithms to complete the plaintext data conversion and decryption using a specific key to ensure data security; Information security transmission encapsulation is adopted, and information protection is achieved through packaging and encapsulation to intercept network information access behavior; Implement secondary verification and binding authentication to further ensure information security isolation; IPSec encryption is enabled on the interfaces of base station-power 5GC, base station-UPF, and UPF-secure access zone.
8. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 1, characterized in that: The power system's proprietary transmission network includes a time-division multiplexing-based SDH optical fiber transmission network, a wavelength division multiplexing-based OTN optical transmission network, an OTN-based OSU optical service unit, a packet slicing network based on a packet transmission network, and an Ethernet-based data communication network. Based on the existing power system's proprietary transmission network, the power system selects and organizes network channels shared by operators: base station-power 5GC, power UPF-power 5GC, and power UPF-power service system.
9. The distributed energy regulation method based on wired and short-pass multiplexing communication as described in claim 1, characterized in that: Both the wired and wireless security access zones include industrial Ethernet switches and / or xPON; power distributed energy control service data is transmitted to the control master station system server through the wired security access zone via address mapping; power distributed energy control service data is forwarded to the control master station system server via the wireless security access zone using short multiplexing; the wired and wireless security access zones are constructed independently and networked separately.
10. A distributed energy control system based on wired and short-pass multiplexing communication, applicable to the distributed energy control method based on wired and short-pass multiplexing communication as described in any one of claims 1-9, characterized in that: This includes distributed energy control service terminals, access layer industrial Ethernet switches, optical network units (ONUs), wired secure access areas, 4G or 5G base stations, dedicated UPFs, wireless secure access areas, power-owned fiber optic transmission networks, and control master station system servers. The distributed energy control service terminal is equipped with an access layer industrial Ethernet switch. The power distributed energy control service data is collected through the access layer industrial Ethernet switch and uploaded through the optical fiber ring network. The data is then transmitted to the control master station system server via the power company's own optical fiber transmission network and the wired secure access area. The distributed energy control service terminal is equipped with an optical network unit (ONU). The ONU collects power distributed energy control service data and uploads it through a daisy-chain network. It utilizes the power company's own optical fiber transmission network and transmits the data to the control master station system server via a wired secure access area. The distributed energy regulation service terminal opens a dedicated VPN channel for power services in the operator's distribution and aggregation network through a 4G base station or a 5G base station, and isolates the distributed energy regulation service for power services from the operator's services through the dedicated VPN channel. The power distributed energy control services isolated by the dedicated VPN channel are transmitted to the dedicated UPF via the power company's own fiber optic transmission network using short-multiplexed communication. The dedicated UPF then forwards the data to the control master station system server via the wireless security access zone.