Distributed energy storage device security access and identity authentication method and system

By constructing a trust chain graph structure and device behavior vectors, the credibility of distributed energy storage devices is dynamically evaluated, which solves the security risks of traditional authentication methods in complex network environments and realizes flexible and reliable identity authentication and resource allocation.

CN121887541BActive Publication Date: 2026-06-19BEIJING TRUTH WISDOM POWER TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TRUTH WISDOM POWER TECH CO LTD
Filing Date
2026-03-19
Publication Date
2026-06-19

AI Technical Summary

Technical Problem

Traditional distributed energy storage device access management relies on static keys or certificates for identity authentication, which cannot effectively cope with complex and ever-changing network environments and poses security risks, especially in terms of device access and identity authentication.

Method used

By acquiring device identification information and network environment information, collecting communication behavior characteristics, generating device behavior vectors, constructing a trust chain graph structure for multi-hop trust propagation, calculating device credibility, and training an authentication strategy optimization model based on historical authentication data, dynamic authentication control is achieved.

Benefits of technology

It improves the flexibility and reliability of identity authentication, enhances system security, prevents identity impersonation and spoofing attacks, and optimizes resource allocation and authentication efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887541B_ABST
    Figure CN121887541B_ABST
Patent Text Reader

Abstract

This invention provides a method and system for secure access and authentication of distributed energy storage devices, relating to the field of secure access and authentication technology for distributed energy storage devices. The method includes acquiring device identification information, access request information, and network environment information of the energy storage device to be accessed; collecting communication behavior characteristics and generating device behavior vectors; constructing a trust chain graph structure for multi-hop trust propagation; performing matching verification and authentication strategy optimization; and obtaining the authentication result by aggregating the results through partial authentication factor verification performed by multiple authenticated device nodes. This invention achieves secure and efficient access to energy storage devices, improving the security and reliability of distributed energy storage systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of secure access and authentication technology for distributed energy storage devices, and particularly to a method and system for secure access and identity authentication of distributed energy storage devices. Background Technology

[0002] With the rapid development of renewable energy and the advancement of power grid modernization, distributed energy storage devices, as an important component of smart grids, are playing an increasingly vital role in balancing electricity supply and demand and improving energy efficiency. By connecting to the grid, distributed energy storage devices can achieve bidirectional energy flow and dynamic regulation, providing flexibility support for the grid. However, the widespread deployment of these devices also brings new security challenges, particularly in terms of device access and authentication.

[0003] Traditional distributed energy storage device access management mainly relies on static keys or certificates for authentication, which faces security risks in complex and ever-changing network environments. With the application of IoT technology and the increasing intelligence of energy storage devices, the scenarios for device access to the power grid are becoming more diversified, requiring more flexible and secure authentication mechanisms to ensure the safe operation of the power grid. Summary of the Invention

[0004] This invention provides a method and system for secure access and authentication of distributed energy storage devices, which can solve the problems in the prior art.

[0005] A first aspect of the present invention provides a method for secure access and authentication of distributed energy storage devices, comprising:

[0006] Obtain the device identification information, access request information, and network environment information of the energy storage device to be connected;

[0007] Collect communication behavior characteristics of the energy storage device to be connected before the connection request is initiated, extract invariant features by jointly transforming the communication behavior characteristics in the time domain and frequency domain, and generate device behavior vector;

[0008] Based on the device identification information and the network environment information, historical interaction trust relationships are retrieved and the behavior consistency coefficient is calculated. The device behavior vector is used as a node attribute to construct a trust chain graph structure, perform multi-hop trust propagation, and calculate the device trustworthiness.

[0009] The device credibility is matched and verified with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area. Based on the historical authentication data, an authentication strategy optimization model is trained to obtain the regional authentication strategy.

[0010] Based on the regional authentication strategy, the authentication request is propagated along the trust path of the trust chain graph structure. Multiple authenticated device nodes perform partial authentication factor verification respectively. The authentication result is obtained by aggregating the cross-node consistency verification requirements and performing access control in combination with the channel allocation result.

[0011] The communication behavior characteristics of the energy storage device to be connected are collected before the connection request is initiated. These communication behavior characteristics are then jointly transformed in the time and frequency domains to extract invariant features, generating a device behavior vector, including:

[0012] Within a preset time window before the access request is initiated, the communication interaction between the energy storage device to be accessed and the existing devices in the network is monitored. The communication initiation time, duration and data transmission volume are recorded to form a communication interaction time sequence. The data packet arrival rate and length changes are collected to form communication load characteristics.

[0013] Based on the communication interaction time sequence, calculate the time interval sequence to obtain the time interval distribution pattern, identify the time intervals in which the rate of change of the number of communication interactions per unit time exceeds the burst judgment threshold, extract the burst transmission pattern, and combine the time interval distribution pattern to form a time domain feature matrix.

[0014] The communication load characteristics are converted to the frequency domain, and the spectral energy distribution characteristics are obtained through spectrum analysis. The periodic fluctuation characteristics are obtained by identifying the energy peak positions and combining them to form a frequency domain feature matrix.

[0015] By using the time-frequency domain transformation kernel function, cross-correlation operation is performed on the time-domain feature matrix and the frequency-domain feature matrix, and a mapping relationship is established in the two-dimensional space of time-frequency coordinates to obtain the time-frequency joint characterization matrix.

[0016] A rotation and scaling transformation is applied to the time-frequency joint representation matrix, the change is calculated, and the corresponding values ​​of the element positions below the invariance determination threshold are selected as invariant features. The invariant features are arranged in order of position in the time-frequency joint representation matrix and normalized to generate a device behavior vector.

[0017] Based on the device identification information and the network environment information, historical interaction trust relationships are retrieved and a behavior consistency coefficient is calculated. The device behavior vector is used as a node attribute to construct a trust chain graph structure, multi-hop trust propagation is performed, and device trustworthiness is calculated, including:

[0018] Based on the device identification information and the network environment information, historical interaction trust relationships related to the energy storage device to be connected are retrieved in the historical interaction database. The historical interaction trust relationships include direct interaction records and indirect association propagation records. The energy storage device to be connected and the certified device are used as nodes, and the historical interaction trust relationships are used as directed edges to construct an initial trust chain graph structure.

[0019] The device behavior vector is embedded as a node attribute into the initial trust chain graph structure to obtain the historical behavior vectors of the authenticated device nodes that have trusted path connections. The distance metric between the device behavior vector and the historical behavior vector is calculated to obtain the behavior consistency coefficient. When the behavior consistency coefficient exceeds the behavior stability threshold, temporary trust edges are established between the corresponding nodes and the edge weights are dynamically adjusted according to the behavior consistency coefficient to form the evolved trust chain graph structure.

[0020] In the evolved trust chain graph structure, multi-hop trust propagation is performed from the certified device node along the directed edges. The path trust propagation coefficient is calculated based on the path edge weight and the number of hops. The path propagation coefficients of all paths leading to the energy storage device to be connected are aggregated and weighted to obtain the device trustworthiness.

[0021] In the evolved trust chain graph structure, multi-hop trust propagation is performed from the authenticated device node along directed edges. The path trust propagation coefficient is calculated based on the path edge weight and hop count. The path propagation coefficients of all paths leading to the energy storage device to be connected are then aggregated and weighted to obtain the device trustworthiness, including:

[0022] In the evolved trust chain graph structure, the certified device node is selected as the source node. Traverse along the directed edges from each source node to record all reachable paths to the energy storage device to be connected. Extract the total number of hops and edge weights of the paths. Calculate the information entropy based on the frequency of edge weight values ​​to obtain the path weight entropy value. Convert the path weight entropy value into a path balance adjustment factor.

[0023] Identify node overlap between reachable paths, calculate the positional distribution of overlapping nodes in each path, determine path structure similarity based on positional distribution, count the number of redundant paths exceeding the similarity threshold, and generate path independence weights that decrease with redundancy.

[0024] The cumulative path weight is obtained by multiplying the edge weights of each reachable path together. This cumulative weight is then fused with the path balance adjustment factor and the path independence weight to obtain the path trust propagation coefficient. Based on the number of paths between each source node and the energy storage device to be connected, a weighted aggregation is performed to obtain the device trustworthiness.

[0025] The device trustworthiness is matched and verified with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area. Based on the historical authentication data, an authentication strategy optimization model is trained to obtain the regional authentication strategy, including:

[0026] Extract the requested bandwidth parameter from the access request information. For the energy storage device to be accessed whose device trustworthiness is greater than the trustworthiness threshold, select the candidate channel with the shortest response latency from the candidate channels that meet the requested bandwidth parameter as the allocation channel, and generate an allocation result containing the channel identifier and network area identifier.

[0027] Based on the network area identifier, historical authentication data of the corresponding network area is extracted, the device credibility distribution of successful and failed authentication is statistically analyzed, the boundary value of the overlapping distribution interval is calculated to determine the fuzzy judgment interval, and authentication records whose device credibility falls into the fuzzy judgment interval are selected as target training samples.

[0028] The device access time, request channel type, and network load status of the target training sample are extracted to form a feature vector, which is then paired with the authentication result identifier to form a training data pair.

[0029] Obtain authentication policy parameters for adjacent network regions, input the training data pairs and authentication policy parameters into the authentication policy optimization model for training, and update the model by incorporating parameter deviation values ​​according to the migration ratio during iteration to generate regional authentication policies.

[0030] Obtain authentication policy parameters for adjacent network regions, input the training data pairs and authentication policy parameters into the authentication policy optimization model for training, and update the model by incorporating parameter bias values ​​according to the migration ratio during iterations to generate regional authentication policies, including:

[0031] Identify the geographic boundary coordinates and network topology connections of the current network region, and determine the set of adjacent network regions that have physical boundary adjoining or direct network route connections;

[0032] Obtain the currently effective authentication policy parameters of each adjacent network region, calculate the regional correlation coefficient according to the frequency of device interaction between the adjacent network region and the current network region, and perform weighted fusion of the authentication policy parameters of each adjacent network region based on the regional correlation coefficient to generate a cross-regional reference policy benchmark.

[0033] The feature vectors from the training data pairs are input into the input layer of the authentication policy optimization model. The feature vectors are converted into initial policy parameters by the policy mapping unit inside the model. The difference between the feature vectors and the cross-regional reference policy benchmark is calculated to obtain the parameter deviation vector.

[0034] During the model iterative training process, the transfer ratio coefficient is dynamically adjusted according to the ratio of the current iteration round to the total iteration rounds. The parameter deviation vector is scaled according to the transfer ratio coefficient and then superimposed on the weight update gradient of the policy mapping unit to form a gradient correction amount that integrates cross-regional knowledge.

[0035] The gradient correction amount is used to update the parameters of the policy mapping unit of the authentication policy optimization model, extract the steady-state policy parameters, and perform local corrections based on the network load status and device density distribution of the current network area to generate a regional authentication policy.

[0036] Based on the aforementioned regional authentication strategy, the authentication request is propagated along the trust path of the trust chain graph structure. Multiple authenticated device nodes perform partial authentication factor verification respectively. The authentication result is obtained by aggregating the cross-node consistency verification requirements. Access control is then performed in conjunction with the channel allocation result, including:

[0037] The system receives access authentication requests from energy storage devices to be connected, extracts device identifiers and authentication factor sets, determines authentication process types and verification strength requirements from regional authentication policies, searches for authenticated device nodes with trust relationships with the device to be authenticated from the trust chain graph structure, calculates verification weight values ​​based on device trustworthiness and trust path length, and selects authenticated device nodes to form a distributed verification node set.

[0038] The authentication factor set is grouped into multiple authentication factor subsets according to verification complexity and security sensitivity. The authentication factor subsets are allocated according to the verification capability identifier of the authenticated device nodes to ensure that the verification complexity matches the node computing resources. Verification task requests are then sent to the distributed verification node set.

[0039] Each distributed verification node performs independent verification and generates a verification result containing the verification pass status and verification timestamp. It calculates the verification time difference value, removes abnormal verification results that exceed the synchronization deviation standard, and performs consistency verification on the remaining verification results.

[0040] When the number of nodes that pass the consistency check reaches the authentication threshold, an access permission instruction is sent to the energy storage device to be connected, and secure access is executed according to the channel allocation result; otherwise, an access rejection instruction is sent, and an abnormal access record is recorded.

[0041] A second aspect of the present invention provides a secure access and authentication system for distributed energy storage devices, comprising:

[0042] The first unit is used to obtain the device identification information, access request information, and network environment information of the energy storage device to be connected;

[0043] The second unit is used to collect the communication behavior characteristics of the energy storage device to be connected before the access request is initiated, extract invariant features by jointly transforming the communication behavior characteristics in the time domain and frequency domain, and generate a device behavior vector.

[0044] The third unit is used to retrieve historical interaction trust relationships and calculate behavior consistency coefficients based on the device identification information and the network environment information, construct a trust chain graph structure using the device behavior vector as node attributes, perform multi-hop trust propagation, and calculate device trustworthiness.

[0045] The fourth unit is used to match and verify the device trustworthiness with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area, and to train the authentication strategy optimization model based on the historical authentication data to obtain the regional authentication strategy.

[0046] The fifth unit is used to propagate the authentication request along the trust path of the trust chain graph structure based on the regional authentication policy. Multiple authenticated device nodes perform partial authentication factor verification respectively, and the authentication result is obtained by aggregating the cross-node consistency verification requirements. Access control is then performed in combination with the channel allocation result.

[0047] A third aspect of the embodiments of the present invention,

[0048] An electronic device is provided, comprising:

[0049] processor;

[0050] Memory used to store processor-executable instructions;

[0051] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0052] Fourth aspect of the present invention,

[0053] A computer-readable storage medium is provided, having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0054] The beneficial effects of this application are as follows:

[0055] By extracting invariant features through joint transformation of device communication behavior characteristics in the time and frequency domains, a device behavior vector is formed, effectively preventing identity impersonation and spoofing attacks, thus making identity authentication more reliable. A trust chain graph structure is constructed based on device identification information and network environment information. Device trustworthiness is calculated through multi-hop trust propagation, enabling the system to dynamically adapt to security requirements under different network environments and enhancing the flexibility of the authentication mechanism.

[0056] Based on the results of matching and verifying device trustworthiness with access request information, channels are allocated to achieve differentiated access control for devices with different trust levels, thus optimizing system resource allocation. An authentication policy optimization model is trained based on historical authentication data to obtain authentication policies for specific network areas, enabling the authentication mechanism to self-optimize according to regional characteristics and improving authentication efficiency.

[0057] By propagating authentication requests through a trust chain graph structure, multiple authenticated device nodes perform partial authentication factor verification, thereby achieving distributed authentication load and cross-node consistency verification of authentication results. This effectively prevents single-point authentication risks and enhances the overall security of the energy storage network. Attached Figure Description

[0058] Figure 1 This is a flowchart illustrating the secure access and authentication method for distributed energy storage devices according to an embodiment of the present invention.

[0059] Figure 2 This is a schematic diagram of the method for constructing a trust chain graph structure and calculating device trustworthiness according to an embodiment of the present invention. Detailed Implementation

[0060] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0061] The technical solution of the present invention will be described in detail below with reference to specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0062] Figure 1 This is a flowchart illustrating the secure access and authentication method for distributed energy storage devices according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0063] Obtain the device identification information, access request information, and network environment information of the energy storage device to be connected;

[0064] Collect communication behavior characteristics of the energy storage device to be connected before the connection request is initiated, extract invariant features by jointly transforming the communication behavior characteristics in the time domain and frequency domain, and generate device behavior vector;

[0065] Based on the device identification information and the network environment information, historical interaction trust relationships are retrieved and the behavior consistency coefficient is calculated. The device behavior vector is used as a node attribute to construct a trust chain graph structure, perform multi-hop trust propagation, and calculate the device trustworthiness.

[0066] The device credibility is matched and verified with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area. Based on the historical authentication data, an authentication strategy optimization model is trained to obtain the regional authentication strategy.

[0067] Based on the regional authentication strategy, the authentication request is propagated along the trust path of the trust chain graph structure. Multiple authenticated device nodes perform partial authentication factor verification respectively. The authentication result is obtained by aggregating the cross-node consistency verification requirements and performing access control in combination with the channel allocation result.

[0068] In one optional implementation, communication behavior characteristics of the energy storage device to be connected are collected before the connection request is initiated. Invariant features are extracted by jointly transforming the communication behavior characteristics in the time and frequency domains to generate a device behavior vector, including:

[0069] Within a preset time window before the access request is initiated, the communication interaction between the energy storage device to be accessed and the existing devices in the network is monitored. The communication initiation time, duration and data transmission volume are recorded to form a communication interaction time sequence. The data packet arrival rate and length changes are collected to form communication load characteristics.

[0070] Based on the communication interaction time sequence, calculate the time interval sequence to obtain the time interval distribution pattern, identify the time intervals in which the rate of change of the number of communication interactions per unit time exceeds the burst judgment threshold, extract the burst transmission pattern, and combine the time interval distribution pattern to form a time domain feature matrix.

[0071] The communication load characteristics are converted to the frequency domain, and the spectral energy distribution characteristics are obtained through spectrum analysis. The periodic fluctuation characteristics are obtained by identifying the energy peak positions and combining them to form a frequency domain feature matrix.

[0072] By using the time-frequency domain transformation kernel function, cross-correlation operation is performed on the time-domain feature matrix and the frequency-domain feature matrix, and a mapping relationship is established in the two-dimensional space of time-frequency coordinates to obtain the time-frequency joint characterization matrix.

[0073] A rotation and scaling transformation is applied to the time-frequency joint representation matrix, the change is calculated, and the corresponding values ​​of the element positions below the invariance determination threshold are selected as invariant features. The invariant features are arranged in order of position in the time-frequency joint representation matrix and normalized to generate a device behavior vector.

[0074] In this specific embodiment, a preset time window is set before the energy storage device to be connected initiates a formal access request, typically ranging from 30 minutes to 4 hours, which can be adjusted according to the actual grid scale and access process. Within this window, network monitoring probes are deployed to collect communication behavior data of the energy storage device. Specific data collected includes: communication initiation time (accurate to milliseconds), communication duration (in seconds), and data transmission volume (in bytes), forming a communication interaction time sequence. Simultaneously, the data packet arrival rate (the number of data packets received per unit time) and data packet length changes (byte size sequence) are collected to constitute communication load characteristics. For example, for a 500kW commercial or industrial energy storage device, approximately 300 communication interactions with the energy management system, local controller, and other devices are observed within 2 hours before the access request.

[0075] Based on the aforementioned communication interaction time sequence, a time interval sequence is calculated. The difference between the initiation times of every two adjacent communications is calculated to obtain {Δt1, Δt2, ..., Δt}. n The time interval sequence is analyzed, and the distribution of these interval values ​​is statistically analyzed to obtain the time interval distribution pattern, including statistical characteristics such as the mean, variance, kurtosis, and skewness of the interval duration. At the same time, a burst judgment threshold is set (such as the rate of change of communication frequency exceeding 200%), and the time period in which the rate of change of communication interaction frequency within a unit time (such as 10 seconds) exceeds this threshold is identified. Its start time, duration, and maximum rate of change are extracted to form a burst transmission pattern. The time interval distribution pattern and the burst transmission pattern are combined to construct an m×n-dimensional time domain feature matrix, such as a 5×8 matrix, where each row represents different types of time domain features (such as the mean of interval, burst frequency, etc.), and each column represents different time periods within the time window.

[0076] The communication load characteristics are transformed into the frequency domain for analysis. Fast Fourier Transform (FFT) is used to process the data packet arrival rate and length variation sequences to obtain spectral energy distribution characteristics. The energy distribution in different frequency bands is calculated, such as the energy proportions in the low-frequency band (0-0.1Hz), mid-frequency band (0.1-1Hz), and high-frequency band (>1Hz). Energy peak locations are identified, major periodic components are determined, and periodic fluctuation characteristics are extracted. For example, it is found that the energy storage device reports its status every 5 minutes, corresponding to a significant energy peak at 0.0033Hz in the spectrum. These frequency domain features are combined into a p×q dimensional frequency domain feature matrix.

[0077] After obtaining the time-domain feature matrix and the frequency-domain feature matrix, the two matrices are cross-correlated using a designed time-frequency domain transformation kernel function. The kernel function can employ methods such as Gabor transform or wavelet transform to achieve the organic fusion of time-domain and frequency-domain features. Specifically, for each time-domain feature element and frequency-domain feature element, the correlation between them at different time-frequency positions is calculated to form a time-frequency joint representation matrix. This matrix establishes a mapping relationship in the two-dimensional time-frequency coordinate space, which can simultaneously reflect the time characteristics and frequency characteristics of the device's communication behavior.

[0078] To extract invariant features, a series of transformation tests are applied to the time-frequency joint representation matrix, including rotation transformations. The matrix is ​​rotated in the time-frequency plane at different angles (e.g., 15°, 30°, 45°), and the changes in matrix elements before and after the transformation are calculated. A scaling transformation is also performed, scaling the matrix by different ratios (e.g., 0.8x, 1.2x, 1.5x), and the changes are calculated again. An invariance threshold is set (e.g., a change rate below 5%), and the values ​​corresponding to the positions of elements whose changes under these transformations are below the threshold are selected. These values ​​are considered invariant features of device communication behavior. These invariant features are arranged in order of their position in the time-frequency joint representation matrix and normalized (mapped to the [0,1] interval) to finally generate a device behavior vector.

[0079] In practical applications, such as a photovoltaic energy storage grid-connected system, this method can effectively identify the communication behavior characteristics of energy storage devices. A certain type of energy storage device exhibits a clear periodic status reporting pattern (every 5 minutes) and a sudden charge and discharge control command response pattern (response delay <200ms). By generating device behavior vectors, it is possible to compare them with the behavior patterns of known legitimate devices, effectively identify abnormal behavior, prevent the risk of malicious device access or legitimate device hijacking, and improve the security and stability of the power grid.

[0080] Figure 2 This is a schematic flowchart illustrating a method for constructing a trust chain graph structure and calculating device trustworthiness according to an embodiment of the present invention. In one optional implementation, based on the device identification information and the network environment information, historical interaction trust relationships are retrieved and a behavior consistency coefficient is calculated. The device behavior vector is used as a node attribute to construct a trust chain graph structure, multi-hop trust propagation is performed, and device trustworthiness is calculated, including:

[0081] Based on the device identification information and the network environment information, historical interaction trust relationships related to the energy storage device to be connected are retrieved in the historical interaction database. The historical interaction trust relationships include direct interaction records and indirect association propagation records. The energy storage device to be connected and the certified device are used as nodes, and the historical interaction trust relationships are used as directed edges to construct an initial trust chain graph structure.

[0082] The device behavior vector is embedded as a node attribute into the initial trust chain graph structure to obtain the historical behavior vectors of the authenticated device nodes that have trusted path connections. The distance metric between the device behavior vector and the historical behavior vector is calculated to obtain the behavior consistency coefficient. When the behavior consistency coefficient exceeds the behavior stability threshold, temporary trust edges are established between the corresponding nodes and the edge weights are dynamically adjusted according to the behavior consistency coefficient to form the evolved trust chain graph structure.

[0083] In the evolved trust chain graph structure, multi-hop trust propagation is performed from the certified device node along the directed edges. The path trust propagation coefficient is calculated based on the path edge weight and the number of hops. The path propagation coefficients of all paths leading to the energy storage device to be connected are aggregated and weighted to obtain the device trustworthiness.

[0084] In this specific embodiment, when the energy storage device requests to access the network, it obtains the device's identification information and network environment information. The identification information may include the device's unique identifier, model, manufacturer information, firmware version, etc.; the network environment information includes the network topology, gateway information, geographical location, etc. at the time of access.

[0085] Based on the acquired device identification information and network environment information, relevant historical interaction trust relationships are retrieved in the historical interaction database. The historical interaction trust relationships mainly include two categories: one is the direct interaction records between the energy storage device to be connected and other devices in the system, such as communication history and data exchange records; the other is the indirect association propagation records, that is, the trust relationship chain established through intermediate devices. For example, the energy storage battery pack to be connected has previously interacted with a specific energy storage management system, and the management system has been certified as a trusted device by the system.

[0086] After the retrieval is completed, the energy storage device to be connected and the certified device are used as nodes, and the historical interaction trust relationship is used as directed edges to construct an initial trust chain graph structure. In this graph structure, each directed edge represents a trust relationship from the source node to the target node. The initial weight of the edge is determined based on the frequency, timeliness and quality of the historical interaction. For example, relationships with frequent interactions and no anomalies in the past week can be assigned a higher initial weight, such as 0.8; while relationships with earlier interactions or those that have had anomalies can be assigned a lower weight, such as 0.4.

[0087] Device behavior vectors are embedded as node attributes into the initial trust chain graph structure. The device behavior vector is a combination of multi-dimensional features, including behavioral features such as device communication mode, resource usage, and function call sequence. At the same time, the historical behavior vectors of certified device nodes with trusted path connections are obtained. For example, for an energy storage inverter, its behavior vector includes feature dimensions such as charging and discharging mode, power regulation frequency, and response time.

[0088] The distance metric between the behavior vector of the device to be connected and its historical behavior vectors is calculated to obtain the behavior consistency coefficient. The distance metric can be cosine similarity or Euclidean distance. Taking cosine similarity as an example, the closer the cosine of the angle between two behavior vectors is to 1, the more similar the behavior patterns are, and the higher the behavior consistency coefficient. When the calculated behavior consistency coefficient exceeds a preset behavior stability threshold (e.g., 0.75), a temporary trust edge is established between the corresponding nodes, and the edge weight is dynamically adjusted according to the behavior consistency coefficient. For example, when the behavior consistency coefficient is 0.9, the weight of the temporary trust edge can be set to 0.85; while when the behavior consistency coefficient is 0.8, the edge weight can be set to 0.7.

[0089] After completing the above steps, an evolved trust chain graph structure is formed, which includes the original historical interaction trust relationship edges and newly added temporary trust edges based on behavioral consistency. In this evolved graph structure, multi-hop trust propagation starts from the certified device node and proceeds along the directed edges. Multi-hop propagation adopts a path decay model, that is, as the number of propagation hops increases, the trust level gradually decreases. For a specific path, its trust propagation coefficient can be calculated by multiplying the weights of each edge on the path by the hop decay factor.

[0090] Assuming there is a path A→B→C→E from the certified device A to the energy storage device E to be connected, with weights of 0.9, 0.8, and 0.7 respectively, a hop count of 3, and an attenuation factor of 0.9, then the trust propagation coefficient of this path is 0.9×0.8×0.7×(0.9^3)≈0.37.

[0091] The propagation coefficients of all paths leading to the energy storage device to be connected are aggregated and weighted to obtain the device confidence level. The aggregation method is a weighted average. For example, if there are three paths with propagation coefficients of 0.37, 0.25 and 0.41 respectively, the device confidence level after weighted average is about 0.34.

[0092] In practical applications, the system can dynamically adjust the behavior stability threshold and attenuation factor according to the specific scenario. In large-scale energy storage stations with high safety requirements, a higher threshold such as 0.85 and a larger attenuation factor such as 0.85 can be used to ensure strict access control. In ordinary home energy storage systems, the parameter settings can be appropriately relaxed, such as setting the threshold to 0.7 and the attenuation factor to 0.95.

[0093] Through the aforementioned trust chain graph-based credibility assessment mechanism, the energy storage device access system can effectively identify legitimate devices while resisting spoofing attacks, thus improving the overall system security. When the calculated device credibility exceeds the system's preset access threshold, the device is allowed to access the network; otherwise, the device is required to provide more authentication information or the access request is rejected.

[0094] In one optional implementation, in the evolved trust chain graph structure, multi-hop trust propagation is performed from the authenticated device node along directed edges. Path trust propagation coefficients are calculated based on path edge weights and hop counts. The propagation coefficients of all paths leading to the energy storage device to be connected are then aggregated and weighted to obtain the device trustworthiness, including:

[0095] In the evolved trust chain graph structure, the certified device node is selected as the source node. Traverse along the directed edges from each source node to record all reachable paths to the energy storage device to be connected. Extract the total number of hops and edge weights of the paths. Calculate the information entropy based on the frequency of edge weight values ​​to obtain the path weight entropy value. Convert the path weight entropy value into a path balance adjustment factor.

[0096] Identify node overlap between reachable paths, calculate the positional distribution of overlapping nodes in each path, determine path structure similarity based on positional distribution, count the number of redundant paths exceeding the similarity threshold, and generate path independence weights that decrease with redundancy.

[0097] The cumulative path weight is obtained by multiplying the edge weights of each reachable path together. This cumulative weight is then fused with the path balance adjustment factor and the path independence weight to obtain the path trust propagation coefficient. Based on the number of paths between each source node and the energy storage device to be connected, a weighted aggregation is performed to obtain the device trustworthiness.

[0098] In this specific embodiment, in the evolved trust chain graph structure, device nodes that have completed identity authentication and have high credibility are selected as source nodes. These source nodes typically include master control servers, core routers, or edge control devices that have undergone strict authentication. For each source node, a breadth-first traversal is performed along the directed edges until the energy storage device node to be connected is covered. During the traversal, the complete path information from each source node to the target node is recorded, including all intermediate nodes on the path and the weight values ​​of each edge.

[0099] For example, in a certain power microgrid system, there are three paths from the authentication node A to the energy storage device S to be connected: path 1 (A→B→D→S, with edge weights of 0.9, 0.8, and 0.7 respectively), path 2 (A→C→E→S, with edge weights of 0.85, 0.75, and 0.8 respectively), and path 3 (A→B→E→S, with edge weights of 0.9, 0.85, and 0.8 respectively). For each path, extract its total number of hops (3 hops) and the sequence of edge weights.

[0100] For each reachable path, its weight entropy value is calculated, the frequency distribution of the weight values ​​of each edge in the path is statistically analyzed, and the weight entropy value is calculated according to the information entropy formula. The weight entropy value reflects the balance of the weight distribution of the path. When the weight values ​​of each edge in the path are similar, the weight entropy value is higher, indicating that the trust transmission is more balanced; conversely, when there is an obvious "trust bottleneck" in the path (i.e., the weight value of one edge is significantly lower than that of other edges), the weight entropy value is lower.

[0101] For path 1 in the aforementioned example, its edge weight distribution is [0.9, 0.8, 0.7], and the calculated weight entropy value is relatively low because 0.7 is significantly lower than other edge weights, forming a weak link in trust transmission. The edge weight distribution of path 2 is [0.85, 0.75, 0.8], and its weight entropy value is moderate. The edge weight distribution of path 3 is [0.9, 0.85, 0.8], which has the most balanced weight distribution and the highest entropy value.

[0102] Based on the calculated weight entropy values, they are converted into path balance adjustment factors through a mapping function. When the weight entropy value is high, the adjustment factor is close to 1; when the weight entropy value is low, the adjustment factor is smaller. For example, the balance adjustment factor for path 1 is 0.82, for path 2 it is 0.88, and for path 3 it is 0.95.

[0103] After determining the path balance adjustment factor, it is necessary to identify the overlap between each reachable path, evaluate the independence between paths, compare all paths pairwise, calculate the proportion of shared nodes and their position distribution in each path, and consider the two paths to be highly similar in structure when two paths share a large number of nodes and these nodes are in close positions in the path.

[0104] In the example, path 1 and path 3 share nodes A and B, and their positions are exactly the same (both are the first two nodes of the path), while path 1 and path 2 only share the starting node A. Through position-weighted calculation, the structural similarity between path 1 and path 3 is determined to be 0.67, which exceeds the preset threshold of 0.5, and therefore they are considered to be mutually redundant paths.

[0105] For each path, the number of other paths with a structural similarity exceeding a threshold is counted as its redundancy. The higher the path redundancy, the lower the independence. The path independence weight is calculated based on the redundancy, using a function that decreases with redundancy. In the example, the redundancy of paths 1 and 3 is both 1 (redundant to each other), and their independence weight can be set to 0.85; while the redundancy of path 2 is 0, and its independence weight is 1.0.

[0106] Calculate the trust propagation coefficient for each reachable path by multiplying the weights of each edge along the path to obtain the cumulative weight. For example, the cumulative weight of path 1 is 0.9 × 0.8 × 0.7 = 0.504, path 2 is 0.85 × 0.75 × 0.8 = 0.51, and path 3 is 0.9 × 0.85 × 0.8 = 0.612. Multiply the cumulative weight by the path balance adjustment factor and the path independence weight to obtain the trust propagation coefficient. For path 1, the trust propagation coefficient is 0.504 × 0.82 × 0.85 ≈ 0.351; for path 2, it is 0.51 × 0.88 × 1.0 ≈ 0.449; and for path 3, it is 0.612 × 0.95 × 0.85 ≈ 0.494.

[0107] Based on the number of paths from each source node to the energy storage device to be connected, a weighted aggregation is performed to obtain the final trustworthiness of the device. If there is only one source node A, the trust propagation coefficients of all paths originating from A are summed and normalized. In the example, the propagation coefficients of the three paths from node A to energy storage device S are 0.351, 0.449 and 0.494, respectively. The sum is 1.294, and the normalization coefficient can be taken as 1 / 1.5 = 0.667. Therefore, the trustworthiness of the device is 1.294 × 0.667 ≈ 0.863.

[0108] If there are multiple source nodes, the weighted sum of the path propagation coefficients from each source node is calculated first, and then the weighted aggregation is performed based on the credibility of each source node. For example, if there is another source node G, and there are two paths from G to S, the calculated weighted sum of the propagation coefficients is 0.76, and the credibility of G is 0.9, while the credibility of A is 0.95, then the final device credibility is (0.863×0.95+0.76×0.9) / (0.95+0.9)≈0.813.

[0109] Through the above steps, the credibility assessment of energy storage devices based on multi-hop trust propagation was completed, providing a quantitative basis for energy storage device access decisions.

[0110] In one optional implementation, the device trustworthiness is matched and verified with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area. Based on the historical authentication data, an authentication policy optimization model is trained to obtain a regional authentication policy, including:

[0111] Extract the requested bandwidth parameter from the access request information. For the energy storage device to be accessed whose device trustworthiness is greater than the trustworthiness threshold, select the candidate channel with the shortest response latency from the candidate channels that meet the requested bandwidth parameter as the allocation channel, and generate an allocation result containing the channel identifier and network area identifier.

[0112] Based on the network area identifier, historical authentication data of the corresponding network area is extracted, the device credibility distribution of successful and failed authentication is statistically analyzed, the boundary value of the overlapping distribution interval is calculated to determine the fuzzy judgment interval, and authentication records whose device credibility falls into the fuzzy judgment interval are selected as target training samples.

[0113] The device access time, request channel type, and network load status of the target training sample are extracted to form a feature vector, which is then paired with the authentication result identifier to form a training data pair.

[0114] Obtain authentication policy parameters for adjacent network regions, input the training data pairs and authentication policy parameters into the authentication policy optimization model for training, and update the model by incorporating parameter deviation values ​​according to the migration ratio during iteration to generate regional authentication policies.

[0115] During the energy storage device access authentication process, it is necessary to obtain the access request information of the energy storage device to be accessed, as well as the trust information of the device. The access request information usually includes information such as device identifier, request bandwidth parameters, access time and request channel type. The device trust can be obtained by the device identity authentication system based on multi-dimensional indicators such as device certificate, historical behavior and security assessment score.

[0116] When matching and verifying device trustworthiness with access request information, the requested bandwidth parameter is extracted from the access request information. For energy storage devices with a trustworthiness higher than the preset trustworthiness threshold, the channel with the shortest response latency is selected as the allocation channel from the candidate channels that meet the requested bandwidth requirements. In specific implementation, the channel status monitoring module can be used to obtain the latency parameters of each candidate channel in real time, and the optimal channel is selected by comparing the latency values. For example, when an energy storage device requests a bandwidth of 10Mbps and has a trustworthiness of 0.85 (higher than the trustworthiness threshold of 0.8), the channel with the shortest current response latency (such as channel C with a latency of 15ms) is selected as the allocation result from all candidate channels with a bandwidth greater than or equal to 10Mbps.

[0117] After channel allocation is completed, an allocation result containing channel identifiers (such as "Channel C") and network area identifiers (such as "Area A") is generated. This allocation result is used to guide the access of energy storage devices and also serves as the data basis for subsequent authentication strategy optimization.

[0118] Based on the network area identifier, historical authentication data of the corresponding network area is extracted. This data contains the historical authentication records of all energy storage devices in the area. By statistically analyzing the credibility distribution characteristics of successfully and unsuccessfully authenticated devices, the boundary value of the overlapping interval of the two distributions is calculated to determine the fuzzy decision interval. In specific implementation, the kernel density estimation method can be used to fit the credibility distribution curves of successfully and unsuccessfully authenticated samples respectively, and the intersection point of the two curves is determined as the boundary value of the fuzzy interval. For example, by analyzing the historical authentication data of region A, it is found that there is a large overlap between the credibility of successfully and unsuccessfully authenticated samples and 0.75 to 0.85. Therefore, [0.75, 0.85] is determined as the fuzzy decision interval.

[0119] The authentication records in which the device credibility falls within the fuzzy judgment range are selected from historical authentication data as target training samples. These samples represent the boundary cases where there is uncertainty in the authentication decision, which is of great value for improving the authentication accuracy.

[0120] The device access time (converted into time features, such as morning peak, off-peak, evening peak, etc.), requested channel type (such as high-speed channel, standard channel, etc.), and network load status (such as low load, medium load, high load, etc.) are extracted from the target training samples to form feature vectors. These feature vectors are paired with the corresponding authentication result identifiers (1 for success, 0 for failure) to form training data pairs. For example, if a device accesses during the morning peak, requests a standard channel, and has a medium network load, and ultimately succeeds in authentication, the training data pair would be: ([morning peak, standard channel, medium load], 1).

[0121] The authentication policy parameters of adjacent network regions are obtained. These parameters include authentication threshold adjustment coefficients and time weight factors under different conditions. The training data and the authentication policy parameters of adjacent regions are input into the authentication policy optimization model for training. An iterative training method is adopted, and the parameter deviation value is incorporated into each iteration according to the set migration ratio for updating.

[0122] Specifically, the authentication strategy optimization model can employ a gradient descent-based parameter update mechanism to optimize the authentication decision boundary by minimizing the prediction error. During training, transfer learning is introduced, fusing parameter experience from neighboring regions according to a transfer ratio α (e.g., 0.3). For example, if the updated value of a parameter in the current region is Δθ, and the corresponding parameter deviation in neighboring regions is δ, then the final updated value is Δθ + α·δ. This approach preserves the features of the current region while also drawing on the experience of neighboring regions.

[0123] After training, a regional authentication policy is generated, which includes the optimal combination of authentication parameters for that network region. These parameters will guide subsequent energy storage device access authentication decisions, improving authentication accuracy and system security. For example, for the morning peak hours of region A, the generated authentication policy will dynamically adjust the confidence threshold to 0.82, while it will be reduced to 0.78 during off-peak hours.

[0124] In practical applications, as energy storage device access authentication data accumulates, the authentication strategy optimization model can be retrained periodically to keep the authentication strategy synchronized with changes in the network environment, ensuring the security of energy storage device access and the efficient utilization of network resources. This dynamic authentication strategy optimization method based on historical authentication data effectively solves the problem of accuracy in energy storage device access authentication in different network areas and at different times.

[0125] In one optional implementation, authentication policy parameters of adjacent network regions are obtained. The training data pairs and authentication policy parameters are input into an authentication policy optimization model for training. During iterations, parameter bias values ​​are incorporated according to the migration ratio for updating, generating a regional authentication policy, including:

[0126] Identify the geographic boundary coordinates and network topology connections of the current network region, and determine the set of adjacent network regions that have physical boundary adjoining or direct network route connections;

[0127] Obtain the currently effective authentication policy parameters of each adjacent network region, calculate the regional correlation coefficient according to the frequency of device interaction between the adjacent network region and the current network region, and perform weighted fusion of the authentication policy parameters of each adjacent network region based on the regional correlation coefficient to generate a cross-regional reference policy benchmark.

[0128] The feature vectors from the training data pairs are input into the input layer of the authentication policy optimization model. The feature vectors are converted into initial policy parameters by the policy mapping unit inside the model. The difference between the feature vectors and the cross-regional reference policy benchmark is calculated to obtain the parameter deviation vector.

[0129] During the model iterative training process, the transfer ratio coefficient is dynamically adjusted according to the ratio of the current iteration round to the total iteration rounds. The parameter deviation vector is scaled according to the transfer ratio coefficient and then superimposed on the weight update gradient of the policy mapping unit to form a gradient correction amount that integrates cross-regional knowledge.

[0130] The gradient correction amount is used to update the parameters of the policy mapping unit of the authentication policy optimization model, extract the steady-state policy parameters, and perform local corrections based on the network load status and device density distribution of the current network area to generate a regional authentication policy.

[0131] In this specific embodiment, it is necessary to identify the geographical boundary coordinates and network topology connections of the current network area. The geographical boundary information of the current network area, including latitude and longitude coordinate sequences, is obtained through the network management system. Simultaneously, a network topology map is collected, containing router connections, gateway configurations, and traffic exchange node information. Based on this information, graph theory algorithms are used to analyze network connectivity and determine the set of adjacent network areas that physically border or are directly connected to the current network area via network routes. For example, for an enterprise campus network, adjacent areas such as connected industrial park networks and urban public networks are identified, forming a list of adjacent areas.

[0132] The system retrieves the currently effective authentication policy parameters for each adjacent network region. This is done via the security management platform interface or authentication server configuration query to extract key parameters such as authentication methods (e.g., two-factor authentication, biometric recognition), session timeout duration, password complexity requirements, and authentication strength levels. Simultaneously, based on historical network traffic logs, the system analyzes the frequency of device interactions between the current network region and its adjacent regions, including metrics such as the number of cross-regional access requests and data transmission volume. A regional correlation coefficient is calculated based on the interaction frequency; a higher correlation coefficient indicates a closer business connection between the two regions. A weighted average method is then used, with the regional correlation coefficient as the weight, to fuse the authentication policy parameters of each adjacent region, generating a cross-regional reference policy benchmark.

[0133] The feature vectors from the training data pairs are input into the authentication policy optimization model. The training data pairs contain device feature vectors (device type, computing power, operating system version, etc.) and corresponding optimal authentication policy labels. The authentication policy optimization model adopts a multi-layer neural network structure, in which the policy mapping unit is responsible for converting the input feature vectors into initial policy parameters. In the specific implementation, after the feature vectors are processed by the embedding layer, they are mapped to a vector space with the same dimension as the policy parameters through a fully connected layer. The difference between the mapping result and the cross-regional reference policy benchmark generated in the previous step is calculated to obtain the parameter deviation vector, which represents the degree of difference between the current generated policy and the policies of adjacent regions.

[0134] During model iterative training, the transfer ratio coefficient is dynamically adjusted. The total number of iterations is set to T, and the current iteration is set to t. The transfer ratio coefficient λ is calculated, and the value of λ gradually decreases as training progresses. This allows the model to learn more from knowledge in neighboring regions in the early stages and pay more attention to the characteristics of the current region in the later stages. The parameter deviation vector is scaled according to the transfer ratio coefficient λ to obtain the cross-regional knowledge transfer amount. This amount is then superimposed on the weight update gradient of the policy mapping unit to form a gradient correction amount that integrates cross-regional knowledge. This approach maintains the optimization direction of gradient descent while introducing policy knowledge from neighboring regions, which helps to avoid the policy deviating excessively from common practices between regions.

[0135] The authentication policy optimization model is updated using gradient correction. After each training batch, the calculated gradient correction is applied to the model weight update formula to update the parameters of the policy mapping unit. After training, the distribution of policy parameters output by the model is collected by inputting typical device feature vectors of the current region multiple times. The steady-state policy parameters are extracted as the basic policy. Furthermore, the basic policy is locally corrected by combining the real-time network load status and device density distribution information of the current network region. For example, the authentication complexity is appropriately reduced in high-load areas to alleviate server pressure, and the spatial access control is strengthened in densely populated areas. An authentication policy suitable for the characteristics of the current network region is generated, including a complete set of parameters such as authentication method selection, authentication strength, and timeout settings.

[0136] In an application example, a corporate campus network and an adjacent industrial zone network have frequent business interactions. This method identifies the correlation coefficient between the two areas as 0.8. The two-factor authentication strategy adopted by the industrial zone is incorporated into the reference benchmark with high weight. During the corporate campus strategy optimization process, adaptive adjustments are made based on the characteristics of the corporate terminal devices and network load. The final generated authentication strategy maintains compatibility with the industrial zone's authentication system while also adapting to the company's own security needs and operating environment.

[0137] The above methods have enabled the optimization of network authentication strategies based on cross-regional knowledge transfer. While ensuring the consistency of authentication systems across regions, they have adapted to the specific needs of each region, thereby improving network security protection capabilities and user experience.

[0138] In one optional implementation, based on the regional authentication policy, the authentication request is propagated along the trust path of the trust chain graph structure, with multiple authenticated device nodes performing partial authentication factor verification respectively. The authentication result is obtained by aggregating the cross-node consistency verification requirements, and access control is performed in conjunction with the channel allocation result, including:

[0139] The system receives access authentication requests from energy storage devices to be connected, extracts device identifiers and authentication factor sets, determines authentication process types and verification strength requirements from regional authentication policies, searches for authenticated device nodes with trust relationships with the device to be authenticated from the trust chain graph structure, calculates verification weight values ​​based on device trustworthiness and trust path length, and selects authenticated device nodes to form a distributed verification node set.

[0140] The authentication factor set is grouped into multiple authentication factor subsets according to verification complexity and security sensitivity. The authentication factor subsets are allocated according to the verification capability identifier of the authenticated device nodes to ensure that the verification complexity matches the node computing resources. Verification task requests are then sent to the distributed verification node set.

[0141] Each distributed verification node performs independent verification and generates a verification result containing the verification pass status and verification timestamp. It calculates the verification time difference value, removes abnormal verification results that exceed the synchronization deviation standard, and performs consistency verification on the remaining verification results.

[0142] When the number of nodes that pass the consistency check reaches the authentication threshold, an access permission instruction is sent to the energy storage device to be connected, and secure access is executed according to the channel allocation result; otherwise, an access rejection instruction is sent, and an abnormal access record is recorded.

[0143] In this specific embodiment, when an energy storage device requests to access the network, it receives authentication request information sent by the energy storage device to be accessed. This request information includes a device identifier and a set of authentication factors. The device identifier can be a unique serial number, MAC address, or public key fingerprint, etc. The set of authentication factors includes various authentication elements, such as identity credentials, behavioral characteristics, and historical access records. For example, a photovoltaic energy storage device provides authentication factors including the device serial number "PV20231205-A789", a digital certificate issued by the manufacturer, and the characteristic data of the three most recent charging and discharging behaviors.

[0144] The type of certification process and the verification strength requirements applicable to the device are determined from the pre-configured regional certification strategy. The certification process types can be divided into three types: standard certification, fast certification, and strict certification. The verification strength requirements define the required combination of certification factors and the threshold for the number of verification nodes. For example, for energy storage devices in high-security areas, a strict certification process is adopted, which requires verification of at least five different types of certification factors and at least seven verification nodes.

[0145] The system searches the trust chain graph structure to find certified device nodes that have direct or indirect trust relationships with the device to be certified. The trust chain graph structure is a dynamically updated network topology that records the strength of trust relationships and trust paths between devices. Through graph traversal algorithms, a set of nodes with potential trust relationships with the device to be certified is identified. For each certified device node, a verification weight value is calculated based on its device trust score and trust path length.

[0146] The verification weight value is directly proportional to the device's trustworthiness and inversely proportional to the trust path length. The device's trustworthiness is determined by factors such as historical authentication accuracy, operational stability, and resource availability. For example, a high-trust node with a direct trust relationship (trustworthiness 0.95, path length 1) receives a weight value of 0.95, while a medium-trust node with an indirect trust relationship (trustworthiness 0.8, path length 2) receives a weight value of 0.4.

[0147] Based on the calculated verification weight values, nodes with weight values ​​higher than the system's set threshold are selected to form a distributed verification node set. This ensures that the nodes participating in the authentication have sufficient credibility and appropriate location relationships.

[0148] The set of authentication factors to be verified is grouped according to verification complexity and security sensitivity to obtain multiple subsets of authentication factors. Verification complexity takes into account the consumption of computing resources and time requirements, while security sensitivity takes into account the importance of factors and the risk of leakage. For example, authentication factors can be divided into three groups: basic identity verification subset, behavioral feature verification subset, and historical record verification subset.

[0149] Based on the verification capability identifier of the certified device nodes, a suitable subset of authentication factors is assigned to each node. The verification capability identifier includes information such as computing power level, available storage space, and supported verification algorithm types. This allocation ensures that the complexity of the verification task matches the computing resources of the node, avoiding resource overload or waste. For example, edge gateway nodes with strong computing power are assigned to handle complex behavioral feature verification, while resource-constrained terminal devices are only responsible for simple identity verification.

[0150] After allocation, a verification task request is sent to the distributed verification node set, which includes the subset of authentication factors to be verified, verification rules and expected response time. After receiving the task, each distributed verification node executes an independent verification process according to the locally stored verification rules and the received subset of authentication factors. The verification process includes technical means such as digital signature verification, behavior pattern matching and threshold detection.

[0151] After verification is completed, each node generates a verification result, including the verification pass status (pass, partial pass, or rejection) and the verification timestamp. To ensure time synchronization, the difference value of the verification timestamps of each node is calculated and compared with the synchronization deviation standard set by the system. For example, if the system sets the synchronization deviation standard to 200 milliseconds, verification results that differ from the median timestamp by more than 200 milliseconds are discarded and regarded as abnormal verification results.

[0152] The remaining verification results are subjected to consistency checks. The final authentication status is determined by majority voting or weighted voting. The number of nodes that pass the consistency check is counted and compared with the authentication threshold specified in the authentication strategy. When the number of nodes that pass the check reaches or exceeds the authentication threshold, and the authentication factors that pass the verification cover the necessary factor types required by the strategy, the authentication is considered successful.

[0153] After successful authentication, an access permission instruction is sent to the energy storage device to be connected. This instruction includes channel allocation results, resource restrictions, and security parameter configuration information. The channel allocation results are dynamically generated based on the device type, purpose, and network topology status. The instruction specifies the communication path and permission scope after the device is connected, executes the secure access process, establishes an encrypted communication tunnel, and completes device registration and initial configuration.

[0154] If authentication fails (the number of nodes that pass the consistency check does not reach the threshold or the necessary factor verification fails), an access rejection command is sent to the energy storage device to be connected, explaining the reason for rejection and suggested measures. At the same time, the abnormal access record is recorded in the system security log, including the device identifier, timestamp, location information and reason for failure, for subsequent security analysis and policy optimization.

[0155] Through the aforementioned distributed authentication method, the system can effectively resist single-point attacks and forged device access, improve the overall security of the energy storage network, and is particularly suitable for the security management of large-scale distributed energy storage systems.

[0156] The distributed energy storage device secure access and identity authentication system of this invention includes:

[0157] The first unit is used to obtain the device identification information, access request information, and network environment information of the energy storage device to be connected;

[0158] The second unit is used to collect the communication behavior characteristics of the energy storage device to be connected before the access request is initiated, extract invariant features by jointly transforming the communication behavior characteristics in the time domain and frequency domain, and generate a device behavior vector.

[0159] The third unit is used to retrieve historical interaction trust relationships and calculate behavior consistency coefficients based on the device identification information and the network environment information, construct a trust chain graph structure using the device behavior vector as node attributes, perform multi-hop trust propagation, and calculate device trustworthiness.

[0160] The fourth unit is used to match and verify the device trustworthiness with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area, and to train the authentication strategy optimization model based on the historical authentication data to obtain the regional authentication strategy.

[0161] The fifth unit is used to propagate the authentication request along the trust path of the trust chain graph structure based on the regional authentication policy. Multiple authenticated device nodes perform partial authentication factor verification respectively, and the authentication result is obtained by aggregating the cross-node consistency verification requirements. Access control is then performed in combination with the channel allocation result.

[0162] A third aspect of the present invention provides an electronic device, comprising:

[0163] processor;

[0164] Memory used to store processor-executable instructions;

[0165] The processor is configured to invoke instructions stored in the memory to execute the aforementioned method.

[0166] A fourth aspect of the present invention provides a computer-readable storage medium having stored thereon computer program instructions that, when executed by a processor, implement the aforementioned method.

[0167] This invention can be a method, apparatus, system, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for performing various aspects of the invention.

[0168] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for secure access and authentication of distributed energy storage devices, characterized in that, include: Obtain the device identification information, access request information, and network environment information of the energy storage device to be connected; Collect communication behavior characteristics of the energy storage device to be connected before the connection request is initiated, extract invariant features by jointly transforming the communication behavior characteristics in the time domain and frequency domain, and generate device behavior vector; Based on the device identification information and the network environment information, historical interaction trust relationships are retrieved and the behavior consistency coefficient is calculated. The device behavior vector is used as a node attribute to construct a trust chain graph structure, perform multi-hop trust propagation, and calculate the device trustworthiness. The device credibility is matched and verified with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area. Based on the historical authentication data, an authentication strategy optimization model is trained to obtain the regional authentication strategy. Based on the regional authentication strategy, the authentication request is propagated along the trust path of the trust chain graph structure. Multiple authenticated device nodes perform partial authentication factor verification respectively. The authentication result is obtained by aggregating the cross-node consistency verification requirements and performing access control in combination with the channel allocation result.

2. The method according to claim 1, characterized in that, The communication behavior characteristics of the energy storage device to be connected are collected before the connection request is initiated. These communication behavior characteristics are then jointly transformed in the time and frequency domains to extract invariant features, generating a device behavior vector, including: Within a preset time window before the access request is initiated, the communication interaction between the energy storage device to be accessed and the existing devices in the network is monitored. The communication initiation time, duration and data transmission volume are recorded to form a communication interaction time sequence. The data packet arrival rate and length changes are collected to form communication load characteristics. Based on the communication interaction time sequence, calculate the time interval sequence to obtain the time interval distribution pattern, identify the time intervals in which the rate of change of the number of communication interactions per unit time exceeds the burst judgment threshold, extract the burst transmission pattern, and combine the time interval distribution pattern to form a time domain feature matrix. The communication load characteristics are converted to the frequency domain, and the spectral energy distribution characteristics are obtained through spectrum analysis. The periodic fluctuation characteristics are obtained by identifying the energy peak positions and combining them to form a frequency domain feature matrix. By using the time-frequency domain transformation kernel function, cross-correlation operation is performed on the time-domain feature matrix and the frequency-domain feature matrix, and a mapping relationship is established in the two-dimensional space of time-frequency coordinates to obtain the time-frequency joint characterization matrix. A rotation and scaling transformation is applied to the time-frequency joint representation matrix, the change is calculated, and the corresponding values ​​of the element positions below the invariance determination threshold are selected as invariant features. The invariant features are arranged in order of position in the time-frequency joint representation matrix and normalized to generate a device behavior vector.

3. The method according to claim 1, characterized in that, Based on the device identification information and the network environment information, historical interaction trust relationships are retrieved and a behavior consistency coefficient is calculated. The device behavior vector is used as a node attribute to construct a trust chain graph structure, multi-hop trust propagation is performed, and device trustworthiness is calculated, including: Based on the device identification information and the network environment information, historical interaction trust relationships related to the energy storage device to be connected are retrieved in the historical interaction database. The historical interaction trust relationships include direct interaction records and indirect association propagation records. The energy storage device to be connected and the certified device are used as nodes, and the historical interaction trust relationships are used as directed edges to construct an initial trust chain graph structure. The device behavior vector is embedded as a node attribute into the initial trust chain graph structure to obtain the historical behavior vectors of the authenticated device nodes that have trusted path connections. The distance metric between the device behavior vector and the historical behavior vector is calculated to obtain the behavior consistency coefficient. When the behavior consistency coefficient exceeds the behavior stability threshold, temporary trust edges are established between the corresponding nodes and the edge weights are dynamically adjusted according to the behavior consistency coefficient to form the evolved trust chain graph structure. In the evolved trust chain graph structure, multi-hop trust propagation is performed from the certified device node along the directed edges. The path trust propagation coefficient is calculated based on the path edge weight and the number of hops. The path propagation coefficients of all paths leading to the energy storage device to be connected are aggregated and weighted to obtain the device trustworthiness.

4. The method according to claim 3, characterized in that, In the evolved trust chain graph structure, multi-hop trust propagation is performed from the authenticated device node along directed edges. The path trust propagation coefficient is calculated based on the path edge weight and hop count. The path propagation coefficients of all paths leading to the energy storage device to be connected are then aggregated and weighted to obtain the device trustworthiness, including: In the evolved trust chain graph structure, the certified device node is selected as the source node. Traverse along the directed edges from each source node to record all reachable paths to the energy storage device to be connected. Extract the total number of hops and edge weights of the paths. Calculate the information entropy based on the frequency of edge weight values ​​to obtain the path weight entropy value. Convert the path weight entropy value into a path balance adjustment factor. Identify node overlap between reachable paths, calculate the positional distribution of overlapping nodes in each path, determine path structure similarity based on positional distribution, count the number of redundant paths exceeding the similarity threshold, and generate path independence weights that decrease with redundancy. The cumulative path weight is obtained by multiplying the edge weights of each reachable path together. This cumulative weight is then fused with the path balance adjustment factor and the path independence weight to obtain the path trust propagation coefficient. Based on the number of paths between each source node and the energy storage device to be connected, a weighted aggregation is performed to obtain the device trustworthiness.

5. The method according to claim 1, characterized in that, The device trustworthiness is matched and verified with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area. Based on the historical authentication data, an authentication strategy optimization model is trained to obtain the regional authentication strategy, including: Extract the requested bandwidth parameter from the access request information. For the energy storage device to be accessed whose device trustworthiness is greater than the trustworthiness threshold, select the candidate channel with the shortest response latency from the candidate channels that meet the requested bandwidth parameter as the allocation channel, and generate an allocation result containing the channel identifier and network area identifier. Based on the network area identifier, historical authentication data of the corresponding network area is extracted, the device credibility distribution of successful and failed authentication is statistically analyzed, the boundary value of the overlapping distribution interval is calculated to determine the fuzzy judgment interval, and authentication records whose device credibility falls into the fuzzy judgment interval are selected as target training samples. The device access time, request channel type, and network load status of the target training sample are extracted to form a feature vector, which is then paired with the authentication result identifier to form a training data pair. Obtain authentication policy parameters for adjacent network regions, input the training data pairs and authentication policy parameters into the authentication policy optimization model for training, and update the model by incorporating parameter deviation values ​​according to the migration ratio during iteration to generate regional authentication policies.

6. The method according to claim 5, characterized in that, Obtain authentication policy parameters for adjacent network regions, input the training data pairs and authentication policy parameters into the authentication policy optimization model for training, and update the model by incorporating parameter bias values ​​according to the migration ratio during iterations to generate regional authentication policies, including: Identify the geographic boundary coordinates and network topology connections of the current network region, and determine the set of adjacent network regions that have physical boundary adjoining or direct network route connections; Obtain the currently effective authentication policy parameters of each adjacent network region, calculate the regional correlation coefficient according to the frequency of device interaction between the adjacent network region and the current network region, and perform weighted fusion of the authentication policy parameters of each adjacent network region based on the regional correlation coefficient to generate a cross-regional reference policy benchmark. The feature vectors from the training data pairs are input into the input layer of the authentication policy optimization model. The feature vectors are converted into initial policy parameters by the policy mapping unit inside the model. The difference between the feature vectors and the cross-regional reference policy benchmark is calculated to obtain the parameter deviation vector. During the model iterative training process, the transfer ratio coefficient is dynamically adjusted according to the ratio of the current iteration round to the total iteration rounds. The parameter deviation vector is scaled according to the transfer ratio coefficient and then superimposed on the weight update gradient of the policy mapping unit to form a gradient correction amount that integrates cross-regional knowledge. The gradient correction amount is used to update the parameters of the policy mapping unit of the authentication policy optimization model, extract the steady-state policy parameters, and perform local corrections based on the network load status and device density distribution of the current network area to generate a regional authentication policy.

7. The method according to claim 1, characterized in that, Based on the aforementioned regional authentication strategy, the authentication request is propagated along the trust path of the trust chain graph structure. Multiple authenticated device nodes perform partial authentication factor verification respectively. The authentication result is obtained by aggregating the cross-node consistency verification requirements. Access control is then performed in conjunction with the channel allocation result, including: The system receives access authentication requests from energy storage devices to be connected, extracts device identifiers and authentication factor sets, determines authentication process types and verification strength requirements from regional authentication policies, searches for authenticated device nodes with trust relationships with the device to be authenticated from the trust chain graph structure, calculates verification weight values ​​based on device trustworthiness and trust path length, and selects authenticated device nodes to form a distributed verification node set. The authentication factor set is grouped into multiple authentication factor subsets according to verification complexity and security sensitivity. The authentication factor subsets are allocated according to the verification capability identifier of the authenticated device nodes to ensure that the verification complexity matches the node computing resources. Verification task requests are then sent to the distributed verification node set. Each distributed verification node performs independent verification and generates a verification result containing the verification pass status and verification timestamp. It calculates the verification time difference value, removes abnormal verification results that exceed the synchronization deviation standard, and performs consistency verification on the remaining verification results. When the number of nodes that pass the consistency check reaches the authentication threshold, an access permission instruction is sent to the energy storage device to be connected, and secure access is executed according to the channel allocation result; otherwise, an access rejection instruction is sent, and an abnormal access record is recorded.

8. A distributed energy storage device secure access and authentication system, used to implement the method as described in any one of claims 1-7, characterized in that, include: The first unit is used to obtain the device identification information, access request information, and network environment information of the energy storage device to be connected; The second unit is used to collect the communication behavior characteristics of the energy storage device to be connected before the access request is initiated, extract invariant features by jointly transforming the communication behavior characteristics in the time domain and frequency domain, and generate a device behavior vector. The third unit is used to retrieve historical interaction trust relationships and calculate behavior consistency coefficients based on the device identification information and the network environment information, construct a trust chain graph structure using the device behavior vector as node attributes, perform multi-hop trust propagation, and calculate device trustworthiness. The fourth unit is used to match and verify the device trustworthiness with the access request information to obtain the channel allocation result and the historical authentication data of the corresponding network area, and to train the authentication strategy optimization model based on the historical authentication data to obtain the regional authentication strategy. The fifth unit is used to propagate the authentication request along the trust path of the trust chain graph structure based on the regional authentication policy. Multiple authenticated device nodes perform partial authentication factor verification respectively, and the authentication result is obtained by aggregating the cross-node consistency verification requirements. Access control is then performed in combination with the channel allocation result.

9. An electronic device, characterized in that, include: processor; Memory used to store processor-executable instructions; The processor is configured to invoke instructions stored in the memory to execute the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, they implement the method described in any one of claims 1 to 7.