Intelligent fusion terminal system of power distribution Internet of Things station area
By constructing a logical dual-system architecture on a single physical processor and utilizing hardware virtualization technology and an input/output memory management unit to isolate resources, the system reliability and security issues of existing distribution IoT transformer area convergence terminals are solved, achieving efficient resource isolation and fault recovery, and improving the system's reliability and flexibility.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG NIKON ELECTRIC TECH CO LTD
- Filing Date
- 2025-11-21
- Publication Date
- 2026-04-28
AI Technical Summary
Existing distribution IoT integrated terminals suffer from low system reliability, insufficient control strategies, and unclear security boundaries. In particular, under a single master control architecture, single point of failure can easily lead to the paralysis of both production and marketing operations, and there is a lack of effective resource isolation and scheduling mechanisms.
A dual-system logical architecture is built on a single physical processor. Two independent virtual machines are created through hardware virtualization technology, which are used for power distribution monitoring and power consumption data acquisition, respectively. The input/output memory management unit is combined to achieve hardware isolation between memory and devices. Real-time performance and security are ensured through virtual machine monitors and interrupt isolation mechanisms. A trusted execution environment and fault detection algorithm module are introduced to achieve system redundancy and differentiated recovery.
A logical dual-system architecture was implemented on a single hardware device, which improved the system's fault tolerance, ensured data security isolation and flexible resource expansion for different business domains, met the requirements of real-time performance and high reliability, and reduced the number of devices and on-site installation workload.
Smart Images

Figure CN121939620A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of distribution IoT, and specifically to a distribution IoT smart converged terminal system for distribution transformer areas. Background Technology
[0002] In the construction of the distribution Internet of Things (IoT), the intelligent transformation of distribution substations is a core link in achieving digital operation and maintenance and refined management. Traditional solutions often deploy distribution terminals and electricity information collection concentrators separately under the transformers in the substations. Distribution terminals are mainly for production and dispatching, undertaking tasks such as equipment status monitoring, fault diagnosis, and remote control; while collection concentrators are used for marketing and metering, responsible for aggregating electricity consumption information of users in the substation. The two types of equipment belong to different business domains, resulting in a separation of functions and responsibilities from the initial design stage. Although this separate deployment model can meet the basic needs of each business, its limitations have gradually been exposed in engineering practice. The terminal hardware has overlapping functions, leading to redundant deployment within the substation and high costs; insufficient data interaction between different systems creates information silos; at the same time, on-site installation, commissioning, and subsequent operation and maintenance all require dealing with two sets of equipment, resulting in a large workload and complexity. As the scale of substations expands and application needs grow, this fragmented system architecture is increasingly unable to support the efficient development of the distribution IoT.
[0003] To address the aforementioned issues, the industry has begun exploring the integration of distribution terminals and concentrators. Taking the intelligent integrated distribution terminal disclosed in announcement CN112117832B as an example, this terminal integrates a data acquisition module and a main control module within a single casing. The main control module is positioned as the core of the entire terminal, responsible for uniformly processing the data streams of both distribution monitoring and electricity consumption data collection, and undertaking edge computing tasks. The data acquisition module focuses on two basic functions: first, achieving high-precision AC sampling of the three-phase voltage, three-phase current, and zero-sequence current of the distribution area through voltage and current transformers; second, powering the entire terminal through a built-in power system, and using a large-capacity supercapacitor as a backup power source to ensure that the terminal still has sufficient time for data storage and transmission after external power failure. This solution, through the electrical connection and collaborative work of the two modules, enables the terminal to simultaneously possess the functions of distribution monitoring and electricity consumption information collection, achieving initial hardware-level integration of distribution and operation services. Compared to traditional separate solutions, this terminal has achieved significant improvements in equipment integration, on-site construction convenience, and operation and maintenance efficiency, and is therefore considered an important direction for the development of distribution terminal technology.
[0004] Announcement No. CN111028499A discloses an IoT smart converged terminal for a low-voltage distribution area, including a metering chip that is coupled to the power grid of the low-voltage distribution area via a precision current transformer to measure the three-phase voltage, the corresponding current of the three-phase voltage, and the total residual current of the distribution area; a processor coupled to the metering chip for processing the data collected by the metering chip and sending the data to a remote master station; and a wireless communication module coupled to the processor for enabling communication between the processor and the remote master station, thereby realizing data acquisition and processing by the IoT smart converged terminal for the distribution area.
[0005] However, this converged architecture, with its single main controller and software-defined functionalities, has revealed deep-seated system-level problems in practice:
[0006] While traditional separate deployments are cumbersome, they inherently offer the reliability of business isolation—a power distribution terminal failure does not affect meter reading, and a concentrator crash does not affect fault diagnosis of the power distribution terminal. However, in a single-controller converged architecture, control of both major business operations is centralized on a single central processing unit (CPU). Whether it's an operating system kernel malfunction, a memory leak due to software defects, or a non-critical business process abnormally consuming CPU resources, the entire control system could crash. This single point of failure in the control core will directly paralyze both production and marketing operations, with systemic risks far exceeding those of traditional solutions. For example, in smart distribution terminals based on IPv6 IoT technology, emphasis is placed on establishing secure data access channels to prevent malicious attacks and data eavesdropping, and implementing redundant backups of communication channels; however, existing converged architectures still struggle to avoid the risk of single-point failures. During the gradual deployment of these integrated terminals, there have been instances where the terminal power module overheated and damaged, causing the entire device to lose both power distribution monitoring and power consumption data collection functions. The distribution area was unable to report operating status such as voltage and current, nor could it collect user power consumption data, resulting in a double paralysis of production and marketing operations. Such single-point failures actually made the overall system reliability lower than that of traditional discrete deployments.
[0007] A single master controller must simultaneously handle two distinct tasks: one is high real-time, high-priority tasks on the distribution side, such as millisecond-level fault recording and remote tripping; the other is high-throughput, low-priority tasks on the marketing side, such as concurrent meter reading of massive amounts of user data and edge computing of large data volumes. When the system is running at full load, high-throughput data streams, such as high-speed power line carrier communication meter reading, can easily preempt the central processing unit and bus bandwidth, causing high-priority control tasks, such as fault diagnosis, to fail to respond in a timely manner, or even triggering timeouts, which is unacceptable on the dispatching side.
[0008] Existing converged architectures lack effective system resource isolation and scheduling mechanisms. For example, in the demand for intelligent transformation of distribution networks brought about by the integration of new energy sources, it is necessary to complete intelligent scheduling of distributed power sources and precise control on the power consumption side. However, existing converged terminals face the problems of increased risks to grid safety and insufficient energy regulation capabilities when matching and adjusting on the load side and the power supply side.
[0009] In a converged architecture, although power distribution monitoring data and user electricity consumption data logically belong to different business domains, they are ultimately processed by the same processor at the physical level. In practice, some technicians have worried that if the communication link of the marketing system is attacked, it could indirectly affect the data security of the production scheduling domain through the shared processing module, thus triggering cross-domain risks. This hidden danger of blurred security boundaries is a problem rarely encountered in traditional separate deployments.
[0010] The core challenge for existing converged terminals has shifted from hardware integration to system and control. How to further optimize the architecture design based on convergence, improve the system's fault tolerance, enhance the flexibility and scalability of interfaces and functions, and ensure data security isolation between different business domains have become urgent technical challenges to overcome in the construction of the power distribution Internet of Things (IoT). Summary of the Invention
[0011] Therefore, the purpose of this invention is to provide a distribution IoT transformer area converged terminal system that can build a logical dual-system architecture on a single physical hardware, realize the redundancy of the control core, the isolation of system resources and the hard division of security boundaries, so as to solve the system reliability, control strategy and security problems of existing converged terminals.
[0012] To achieve the above objectives, the present invention provides the following technical solution:
[0013] A distribution IoT smart converged terminal system for distribution transformer areas includes:
[0014] A single physical processor, which supports hardware virtualization extensions and an input / output memory management unit;
[0015] The first virtual machine is dedicated to power distribution monitoring business, runs a real-time operating system, and handles fault recording and remote tripping tasks.
[0016] The second virtual machine is dedicated to electricity consumption collection services, running a non-real-time operating system to handle data collection and edge computing tasks.
[0017] Virtual Machine Monitor (VM Monitor) runs directly on a single physical processor and is used to create and manage the first and second virtual machines.
[0018] The Virtual Machine Monitor implements memory and device hardware isolation between the first and second virtual machines through the Input / Output Memory Management Unit.
[0019] The present invention is further configured such that: the virtual machine monitor includes a hot backup module for periodically synchronizing memory snapshots of the second virtual machine to generate a backup image for hot backup switching.
[0020] The present invention is further configured such that: the single physical processor is a multi-core processor, and the virtual machine monitor assigns at least one core to the first virtual machine through core affinity allocation.
[0021] Core affinity allocation includes setting an affinity mask during system initialization, binding a specified processor core to the first virtual machine, and reserving processor time for the first virtual machine through a real-time scheduling strategy to ensure real-time task response.
[0022] The present invention is further configured such that: each virtual machine has an independent network protocol stack and memory space; the second virtual machine exposes an external communication interface, which includes a high-speed power line carrier communication interface or a fourth-generation mobile communication interface; the first virtual machine only supports internal communication; and the virtual machine monitor enforces access control policies.
[0023] The present invention is further configured to include a trusted execution environment, which is integrated into a single physical processor for storing sensitive keys and production domain data.
[0024] The invention is further configured to include a metering chip, which is coupled to the low-voltage distribution area power grid through a precision transformer, for measuring three-phase voltage, three-phase current and residual current, and routing the data to the first virtual machine and the second virtual machine for processing.
[0025] The present invention is further configured such that: the virtual machine monitor supports containerized loading of business applications, can be extended to a second virtual machine on demand, and maintains the end-to-cloud collaboration function.
[0026] The present invention is further configured such that: the virtual machine monitor includes a service quality scheduling module, which is used to monitor the load inside the second virtual machine and dynamically adjust the resource allocation ratio inside the second virtual machine through feedback control loop to ensure the service quality of different non-real-time services.
[0027] The present invention is further configured such that: the virtual machine monitor includes an interrupt isolation mechanism for directly mapping real-time interrupt vectors to the first virtual machine and shielding the second virtual machine from accessing the real-time interrupt vectors, so as to prevent interrupt contention.
[0028] The present invention is further configured such that: the virtual machine monitor includes a fault detection algorithm module, which periodically checks the running status of the first virtual machine and the second virtual machine through heartbeat signals, and triggers a differentiated recovery strategy when an anomaly is detected:
[0029] When an anomaly is detected in the first virtual machine, a fast restart of the first virtual machine is triggered;
[0030] When an anomaly is detected in the second virtual machine, a hot backup switch to the backup image is triggered.
[0031] Compared with the shortcomings of the prior art, the beneficial effects of the present invention are as follows:
[0032] It implements a logical dual-system architecture within a single physical processor and a unified chassis, eliminating the need for additional hardware modules. Compared to traditional separate deployments, it significantly reduces the number of devices, cabling complexity, and on-site installation workload. It also supports containerized loading of business applications and edge-cloud collaboration, possessing excellent functional scalability and compatibility, making it easy to scale up and deploy applications.
[0033] Hardware-level isolation between memory and devices is achieved through an input / output memory management unit. Combined with core affinity allocation, time slice reservation by a real-time deferred server scheduler, and priority-based scheduling algorithm module, it effectively prevents high-throughput power consumption acquisition tasks from preempting high real-time task resources for power distribution monitoring when the system is running at full load. This ensures timely response to millisecond-level control commands such as fault recording and remote tripping, meeting the stringent real-time requirements of the dispatching side. Attached Figure Description
[0034] Figure 1 This is a schematic diagram of the system architecture of the present invention;
[0035] Figure 2 This is a comparison chart of real-time task jitter and non-real-time domain load in this invention;
[0036] Figure 3 This is a comparison chart showing the system function recovery after a non-real-time domain crash according to the present invention. Detailed Implementation
[0037] Reference Figure 1 The system operates on a single physical processor, which is preferably a multi-core embedded processor that supports hardware virtualization extensions, such as an ARM-v8VE and an input / output memory management unit (IOMMU).
[0038] A hypervisor is a lightweight, first-level Type-1 virtual machine monitor that runs directly on a single bare-metal physical processor and provides the highest level of management over all hardware resources.
[0039] This virtual machine monitor creates and manages two completely isolated virtual machines with different criticalities when the system starts up:
[0040] The first virtual machine, VM1, serves as a virtual production control terminal (v-TTU). It is dedicated to power distribution monitoring and must guarantee high real-time performance and high security. Therefore, it runs a real-time operating system (RTOS). VM1 specifically handles high-priority production scheduling tasks, such as millisecond-level fault recording and execution of remote tripping commands.
[0041] The second virtual machine, VM2, serves as a virtual marketing management terminal. It is dedicated to electricity consumption data collection and analysis, prioritizing high throughput and flexibility. Therefore, it runs a non-real-time operating system, GPOS. VM2 handles high-bandwidth data collection, such as through HPLC, edge computing analysis, and non-real-time data interaction with the main station.
[0042] The core isolation mechanism is implemented by the Input / Output Memory Management Unit (IOMMU). During virtual machine monitor initialization, the IOMMU's address translation table is configured. The IOMMU intercepts all DMA and direct memory access requests from peripherals such as network cards, UARTs, and HPLC modules. The virtual machine monitor allocates completely independent and physically isolated memory spaces for VM1 and VM2. The IOMMU ensures that devices allocated to VM1, such as GPIO for remote circuit breaker tripping, can only access VM1's memory domain, while devices allocated to VM2, such as 4G modules, can only access VM2's memory domain. Any illegal cross-domain DMA access is blocked by the IOMMU at the hardware level, thus achieving hard isolation between memory and devices and completely resolving the ambiguity of security boundaries caused by shared processors in the background technology.
[0043] To ensure absolute real-time performance of VM1 (v-TTU), a static resource binding strategy based on core affinity (CoreAffinity) is adopted. A single physical processor is a quad-core processor (Core0-3). During system initialization, the virtual machine monitor allocates Core0 and Core1 exclusively to VM1 by setting an affinity mask (AffinityMask). Simultaneously, Core2 and Core3 are allocated to VM2.
[0044] The Virtual Machine Monitor (VM) employs a real-time scheduling strategy to manage VCPUs (Virtual CPUs), utilizing a real-time deferred server scheduler. The scheduling algorithm works as follows: the VM assigns a fixed computational "budget" Q and a fixed period P to VM1 (v-TTU). For example, Q = 4ms, P = 10ms. This means that VM1 is guaranteed a maximum of 4ms of CPU time within each 10ms period, with the highest priority. If VM1 completes its task early within a period (e.g., using only 1ms), its remaining budget Q is deferred until the end of that period, allowing it to respond immediately to sudden interruptions, unlike other schedulers that immediately hand over the CPU to VM2. This mechanism ensures that VM1 will never be preempted by any task from VM2 on its bound physical Core 0 and Core 1, thus guaranteeing its deterministic, microsecond-level responsiveness.
[0045] To further ensure real-time performance, an interrupt isolation mechanism is employed. Critical, high-priority hardware interrupt signals, such as overcurrent / overvoltage interrupt vectors from the metering chip or trip command interrupt vectors from the remote control module, are directly mapped to the virtual interrupt controller of VM1 by the virtual machine monitor through the IOMMU's remapping function. Simultaneously, the virtual machine monitor shields VM2 from any access to or awareness of these critical interrupt vectors. This design allows VM1 to bypass the scheduling latency of the virtual machine monitor and directly respond to critical interrupts with near-physical machine performance, preventing interrupt contention and response delays caused by high-throughput tasks on VM2, such as interrupt storms triggered by data meter reading, from affecting VM1.
[0046] In terms of security model, strict network isolation is implemented. VM1 and VM2 each have independent network protocol stacks and memory spaces. The terminal's physical 4G / 5G module and high-speed power line carrier communication module are directly allocated to VM2 via IOMMU. VM2 is responsible for handling all external, high-exposure network communications for data uploading and remote management.
[0047] Conversely, VM1 (v-TTU) does not allocate any external physical network interface card (NIC). It only supports internal communication. The virtual machine monitor enforces access control policies, which are implemented through a one-way secure ring buffer mechanism. This is achieved by the virtual machine monitor creating a shared memory region (e.g., 4KB) in physical memory and using the IOMMU to configure asymmetric access permissions for both virtual machines.
[0048] VM1 (v-TTU) is granted "write-only" permissions for this memory region.
[0049] VM2 (v-Collector) is granted "read-only" access to this memory region. The VM1 driver writes telemetry data (such as voltage and current) as producers into this circular buffer;
[0050] The VM2 driver reads from it as a consumer. This mechanism ensures at the hardware level that VM2 can never write any data or make any requests to VM1, thus achieving unidirectional data flow in the most efficient and secure way, and eliminating the possibility of the marketing domain penetrating the production domain.
[0051] To achieve the highest level of security, a Trusted Execution Environment (TEE) integrated into a single physical processor, private keys used for performing the highest-security operations such as remote tripping, and critical production domain control algorithms are all stored within the secure world of the TEE. When VM1 needs to perform a tripping signature, it requests the TEE to execute it via a Security Monitor Call (SMC). The TEE performs the signing operation within its secure world and only returns the signature result to VM1. This design ensures that even if VM1's real-time operating system itself is compromised, attackers cannot steal or misuse sensitive keys used for grid control.
[0052] At the data input end, the system includes a metering chip coupled to the low-voltage distribution grid via a precision current transformer, which measures three-phase voltage, three-phase current, and residual current with high accuracy. This metering chip is connected to the processor via an SPI or I2C bus. The virtual machine monitor processes the chip's data using I / O virtualization technology: it reads the data from the physical chip and then routes (copies and distributes) the data to the memory space of VM1 for real-time fault diagnosis and to the memory space of VM2 for power accumulation and data analysis.
[0053] To address the issues of flexibility and resource conflicts in non-real-time services, a Quality of Service (QoS) scheduling module and containerized loading functionality were deployed within VM2.
[0054] VM2 supports containerized loading of business applications. This allows power grid companies to update or deploy new edge computing applications (such as load forecasting and distribution area profiling) on demand and independently, just like deploying cloud applications, without restarting the entire terminal or affecting the stable operation of VM1.
[0055] To manage resource conflicts between these containerized applications and other tasks within the VM2 instance (such as data collection), a Quality of Service (QoS) scheduling module was introduced. This module monitors the CPU, memory, and bus load within the VM2 instance and dynamically adjusts the resource allocation ratio for internal tasks through a feedback control loop.
[0056] The QoS module adopts a token bucket-based feedback control model:
[0057] Suppose that VM2 has n non-real-time tasks. Each task This corresponds to a token bucket, whose parameter is the bucket capacity. and token generation rate .Task CPU time slices or bus bandwidth can only be consumed when a token is acquired.
[0058] At the core of this module is a PID controller, used to dynamically adjust low-priority tasks (such as edge computing containers). ) token generation rate :
[0059]
[0060]
[0061] in: This is the current total CPU load of VM2; The preset target load threshold for VM2 is 80%; E(t) is the load error. It is the container's baseline token rate. and These are the proportional and integral gain coefficients.
[0062] Among them, when the internal load of VM2 (For example, due to high-concurrency data collection) rises and approaches When the error E(t) becomes negative, the PID controller will automatically reduce the application of low-priority containers. The token rate is used to proactively suppress edge computing tasks and ensure that high-priority data collection tasks (also within VM2) receive sufficient quality of service.
[0063] To achieve high system reliability, a hot backup module and a fault detection algorithm module are integrated.
[0064] Passive detection: The hypervisor provides a paravirtualized watchdog device for both VM1 and VM2. Inside VM1, the critical control process of its RTOS must periodically (e.g., every 100ms) "feed the watchdog" to this virtual device.
[0065] Inside VM2, its critical application processes must also periodically (e.g., every 5000ms) "feed the dog". The virtual machine monitor monitors these two virtual devices, and if either VM fails to complete the "feed the dog" operation within its specified timeout period, the virtual machine monitor determines that the VM has "suspended" or crashed.
[0066] Active detection: To prevent VMs from being "alive" but "dead" (e.g., the kernel scheduler is locked, preventing application processes from being scheduled), the virtual machine monitor periodically (e.g., every 500ms) injects a paravirtualization interrupt into VM1 and VM2. The VM's kernel driver must respond to this interrupt within a very short time (e.g., 5ms). If a VM fails to respond to this "echo request" multiple times consecutively, the virtual machine monitor also determines that the VM has either "deadlocked" or crashed.
[0067] When the fault detection algorithm module determines that the VM is abnormal through any of the above mechanisms, the system will immediately trigger a differentiated recovery strategy:
[0068] For VM1 (v-TTU): When an anomaly is detected in VM1, since VM1 is a stateless or lightly stateful real-time system, restoring it from a snapshot is both slow and degrades real-time performance. Therefore, the strategy is a rapid restart. The virtual machine monitor immediately terminates the VM1 instance and reloads and starts VM1 from the original image in memory. Given the lightweight nature of RTOS, the entire restart process is preferably completed within 1 second, minimizing the offline time of production control functions.
[0069] For VM2 (v-Collector): When a VM2 anomaly is detected, a simple restart would result in data loss because VM2 hosts a large amount of stateful marketing data. At this point, the hot backup module is activated. This module periodically (e.g., every 10 minutes) synchronizes its memory snapshots to non-volatile storage, generating backup images, while VM2 is running normally. After a VM2 crash, the virtual machine monitor immediately performs a hot backup switch, discarding the corrupted VM2 instance and restoring VM2 from the most recent backup image. While this process takes a few seconds (e.g., 5-10 seconds), it ensures maximum retention of marketing data (maximum loss of 10 minutes of data).
[0070] This differentiated recovery strategy balances the fastest recovery in the production domain with the data integrity in the marketing domain.
[0071] like Figure 2 As shown: In Comparison 1 (single master control fusion), the real-time task jitter (Y-axis) increases exponentially (or at least sharply non-linearly) with the increase of non-real-time domain load (X-axis). When the load reaches 80Mbps, the jitter has soared to 2300μs (milliseconds). This fatally demonstrates the flaws of the shared architecture: high-throughput tasks on the marketing side (such as meter reading) directly preempt the CPU and bus resources of the production side (TTU), causing a complete collapse of the real-time performance (QoS) of the production domain, which is absolutely unacceptable in power grid dispatching.
[0072] The curves of this technology (virtualization) and control 2 (traditional separation) are almost a perfect horizontal straight line, always stable at an extremely low jitter level of 20-25μs, completely unaffected by any increase in non-real-time domain load.
[0073] This strongly demonstrates that the hardware isolation mechanism (core affinity binding, IOMMU interrupt isolation) of this invention is completely effective. It successfully creates a protection for the real-time system (VM1) on a single physical processor, with resource determinism completely consistent with the physically separated control 2. This invention fundamentally solves the persistent problem of resource conflicts in single-master schemes.
[0074] like Figure 3 As shown in Figure 1 (single master controller), at time t=0, the non-real-time domain crashed, and the system status of Figure 1 instantly dropped from "2" (completely normal) to "0" (system offline). This clearly exposes its fatal flaw of "single point of failure"—a software bug on the marketing side caused a double paralysis of "production + marketing" operations. Furthermore, it requires a "cold reboot" of up to 90 seconds to restore all functions.
[0075] At time t=0, the system state of both this technology (virtualization) and Control 2 (traditional separation) only decreased from "2" to "1" (degraded operation). This proves that both schemes achieve "fault isolation"—the collapse on the marketing side does not affect the stable operation of the production side (VM1 or physical TTU), and the power grid's safety monitoring and control functions are preserved.
[0076] The most critical difference lies in the recovery speed. Compared to traditional separation, it takes 90 seconds to restart and restore the marketing function; while this technology (virtualization), with its "differentiated recovery strategy" (VM2 snapshot hot recovery), restores the marketing domain (VM2) to normal in just 7.5 seconds, and the system function returns to "2" (fully normal).
[0077] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any ordinary changes and substitutions made by those skilled in the art within the scope of the technical solutions of the present invention should be included within the protection scope of the present invention.
Claims
1. A smart converged terminal system for distribution network IoT areas, characterized in that, include: A single physical processor, which supports hardware virtualization extensions and an input / output memory management unit; The first virtual machine is dedicated to power distribution monitoring business, runs a real-time operating system, and handles fault recording and remote tripping tasks. The second virtual machine is dedicated to electricity consumption collection services, runs a non-real-time operating system, and handles data collection and edge computing tasks. The Virtual Machine Monitor runs directly on a single physical processor and is used to create and manage the first and second virtual machines. The Virtual Machine Monitor implements memory and device hardware isolation between the first and second virtual machines through the Input / Output Memory Management Unit.
2. The distribution IoT smart converged terminal system for distribution transformer areas according to claim 1, characterized in that, The virtual machine monitor includes a hot backup module for periodically synchronizing memory snapshots of a second virtual machine to generate a backup image for hot backup switching.
3. The distribution IoT smart converged terminal system for distribution transformer areas according to claim 2, characterized in that, The single physical processor is a multi-core processor, and the virtual machine monitor assigns at least one core to the first virtual machine using core affinity allocation. Core affinity allocation includes setting an affinity mask during system initialization, binding a specified processor core to the first virtual machine, and reserving processor time for the first virtual machine through a real-time scheduling strategy to ensure real-time task response.
4. The distribution IoT smart converged terminal system for distribution transformer areas according to claim 3, characterized in that, Each virtual machine has an independent network protocol stack and memory space. The second virtual machine exposes an external communication interface, which may include a high-speed power line carrier communication interface or a fourth-generation mobile communication interface. The first virtual machine only supports internal communication. The virtual machine monitor enforces access control policies.
5. The distribution IoT smart converged terminal system for distribution transformer areas according to claim 1, characterized in that, It also includes a Trusted Execution Environment (TEE), which is integrated into a single physical processor and is used to store sensitive keys and production domain data.
6. The distribution IoT smart converged terminal system for distribution transformer areas according to claim 1, characterized in that, It also includes a metering chip, which is coupled to the low-voltage distribution area power grid through a precision transformer to measure three-phase voltage, three-phase current and residual current, and routes the data to the first virtual machine and the second virtual machine for processing.
7. The distribution IoT smart converged terminal system for distribution areas according to claim 2, characterized in that, The virtual machine monitor supports containerized loading of business applications, can be scaled up to a second virtual machine on demand, and maintains end-to-end cloud collaboration capabilities.
8. The distribution IoT smart converged terminal system for distribution transformer areas according to claim 7, characterized in that, The virtual machine monitor includes a service quality scheduling module, which monitors the load inside the second virtual machine and dynamically adjusts the resource allocation ratio inside the second virtual machine through feedback control loop to ensure the service quality of different non-real-time services.
9. A distribution IoT smart converged terminal system for distribution transformer areas according to claim 8, characterized in that, The virtual machine monitor includes an interrupt isolation mechanism to directly map real-time interrupt vectors to the first virtual machine and shield the second virtual machine from accessing the real-time interrupt vectors, thus preventing interrupt contention.
10. A distribution IoT smart converged terminal system for distribution transformer areas according to claim 9, characterized in that, The virtual machine monitor includes a fault detection algorithm module. This module periodically checks the running status of the first and second virtual machines using heartbeat signals and triggers a differentiated recovery strategy when an anomaly is detected. When an anomaly is detected in the first virtual machine, a fast restart of the first virtual machine is triggered; When an anomaly is detected in the second virtual machine, a hot backup switch to the backup image is triggered.
Citation Information
Patent Citations
Internet-of-Things transformer area intelligent fusion terminal and data acquisition and processing method thereof
CN111028499A
Intelligent fusion terminal in the substation
CN112117832B