Security event tracing and response management platform suitable for wind and light storage station

By constructing a collaborative architecture between the edge layer of the power station and the middleware layer in the cloud, unified collection, cross-domain tracing and response management of safety incidents at wind, solar and energy storage power stations have been achieved. This solves the problem of insufficient cross-domain information integration in existing technologies and improves the safety resilience and intelligent operation and maintenance level of new energy power stations.

CN121965992APending Publication Date: 2026-05-01XIAN THERMAL POWER RES INST CO LTD +1
View PDF 0 Cites 2 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XIAN THERMAL POWER RES INST CO LTD
Filing Date
2026-01-07
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

The existing safety management system for new energy power plants lacks cross-domain information fusion capabilities, resulting in fragmented collection and processing of safety incidents, inconsistent data formats, and large time synchronization errors. This makes it difficult to achieve real-time traceability and accountability, and to effectively identify the source and propagation path of incidents in a multi-source collaborative environment, leading to delays in safety incident handling and lagging response strategies.

Method used

It adopts a two-layer collaborative architecture of site edge layer and cloud middleware layer, and realizes unified collection of multi-source data, cross-domain tracing and security response management through modules such as data acquisition and isolation unit, time synchronization and evidence shaping unit, trusted evidence storage and equipment snapshot unit, cross-domain causal graph and root cause analysis engine, and control physical consistency verification model.

Benefits of technology

It enables reliable tracing of safety incidents, root cause analysis, and controllable response, significantly improving the safety resilience and intelligent operation and maintenance level of integrated wind, solar, and energy storage stations in complex environments, and possessing millisecond-level proactive response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121965992A_ABST
    Figure CN121965992A_ABST
Patent Text Reader

Abstract

The invention discloses a security event traceability and response management platform suitable for a wind and light storage station. The platform comprises a station edge layer and a cloud middle platform layer. The station edge layer comprises an acquisition and isolation unit, a time synchronization and evidence shaping unit and a credible evidence storage and equipment snapshot unit; the evidence storage module is used for underlying data acquisition, time synchronization, evidence shaping and credible evidence storage to form original event data and an encrypted evidence chain; the cloud middle platform layer comprises a cross-domain causal atlas and root cause analysis engine, a control physical consistency verification model, a hierarchical response and energy storage security state control unit, a drill and strategy verification unit and a redisk and adaptive optimization unit; the method is used for cross-domain causal analysis, control consistency verification, hierarchical response decision and strategy redisk optimization. Unified acquisition, credible recording and cross-domain traceability of security events are realized, event sources and propagation paths can be accurately identified in a complex operation environment, and closed-loop control of security response is supported.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of new energy safety monitoring and relates to a safety incident tracing and response management platform applicable to wind, solar and energy storage stations. Background Technology

[0002] With the rapid development of new energy sources, the installed capacity of wind power, photovoltaic power, and energy storage devices in the power system is continuously increasing. Integrated wind-solar-storage power plants achieve high-proportion grid connection and stable output of renewable energy by coordinating and controlling different energy forms and implementing complementary dispatch. However, the operation of equipment such as wind turbines, photovoltaic inverters, and energy storage converters relies on complex communication networks and control systems. Their safe operation not only affects power generation efficiency but also directly impacts grid stability and power supply security. In an environment of multi-source energy collaborative operation, how to conduct safety monitoring and unified event management of distributed equipment has become a key fundamental issue in the field of new energy operation and maintenance.

[0003] Existing safety management of renewable energy power plants largely relies on traditional monitoring and data acquisition systems for operational status monitoring. However, these systems typically focus on a single energy plant and lack cross-domain information fusion capabilities. The collection and processing of safety incidents are often scattered across different control subsystems, resulting in inconsistent data formats, significant time synchronization errors, and reliance on manual verification and log comparison for event recording, making real-time traceability and accountability difficult. For hybrid wind-solar-storage power plants, events such as network layer attacks, electrical disturbances, and control logic anomalies often exhibit multi-factor interplay. Traditional systems cannot establish causal relationships between network, control, and physical behavior, leading to delays in safety incident handling and lagging response strategies, failing to meet the safety management needs of renewable energy power plants under multi-source collaboration and high grid connection conditions. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of the prior art and provide a safety incident tracing and response management platform suitable for wind, solar and energy storage stations. This platform enables unified collection, reliable recording and cross-domain tracing of safety incidents, accurately identifies the source and propagation path of incidents in complex operating environments, and supports closed-loop control of safety responses.

[0005] To achieve the above objectives, the present invention employs the following technical solution: A safety incident tracing and response management platform suitable for wind, solar and energy storage facilities includes a facility edge layer and a cloud-based middleware layer; The station's edge layer communication connects to the cloud middleware layer; The site edge layer includes a data acquisition and isolation unit, a time synchronization and evidence shaping unit, and a trusted evidence storage and equipment snapshot unit; it is used for underlying data acquisition, time synchronization, evidence shaping and trusted evidence storage, forming original event data and encrypted evidence chains; The cloud-based middleware layer includes a cross-domain causal graph and root cause analysis engine, a control physical consistency verification model, a hierarchical response and energy storage safety state control unit, a drill and strategy verification unit, and a review and adaptive optimization unit; used for cross-domain causal analysis, control consistency verification, hierarchical response decision-making, and strategy review and optimization.

[0006] Optionally, the acquisition and isolation unit includes a read-only communication interface, which connects to the data channels of the wind turbine controller, photovoltaic inverter, and energy storage converter; the communication link of the acquisition and isolation unit is equipped with a one-way optical shutter and an isolation relay.

[0007] Optionally, the time synchronization and evidence shaping unit connects to the PTP master clock as a primary time source and connects to the IRIG-B signal as a redundant time source; the time synchronization and evidence shaping unit marks the collected data with device timestamps and platform timestamps.

[0008] Optionally, the trusted evidence storage and device snapshot unit is connected to a consortium blockchain node and a WORM read-only array storage; the trusted evidence storage and device snapshot unit uses the Merkle tree algorithm to generate the root hash value of the event digest and writes it to the consortium blockchain node; the trusted evidence storage and device snapshot unit encrypts the device snapshot file and writes it to the WORM read-only array storage.

[0009] Optionally, the cross-domain causal graph and root cause analysis engine includes a network layer causal model, a control layer causal model, and a physical layer causal model; the cross-domain causal graph and root cause analysis engine establishes a source index table, which records the event identifier, source device code, time window, and on-chain evidence number.

[0010] Optionally, the control physical consistency verification model includes a real-time power flow calculation model; the control physical consistency verification model receives control commands and generates a predicted response vector, which corresponds to the actual measurement vector; the control physical consistency verification model compares the deviation between the predicted response vector and the actual measurement vector.

[0011] Optionally, the graded response and energy storage safety state control unit stores joint risk indicators and priority matrices; the graded response and energy storage safety state control unit is connected to the energy storage unit and sends safety state control curves to the energy storage unit; the safety state control curves include power change rate limit values, state of charge range values ​​and bus voltage deviation values.

[0012] Optionally, the exercise and strategy verification unit includes a digital twin model; the debriefing and adaptive optimization unit includes an optimization engine that connects a cross-domain causal graph and a root cause analysis engine to update the graph edge weights.

[0013] A method for tracing and responding to safety incidents at wind and solar storage facilities includes the following steps: The edge layer of the station collects the operating data of the equipment through a read-only interface and isolates the control signals through a one-way optical shutter. The station edge layer uses the PTP master clock to perform drift correction on the operating data and marks it with dual timestamps to form an event set; The digest hash value of the event set generated at the edge layer of the site is written to the consortium blockchain, and the device snapshots of key events are written to read-only storage; The cloud-based middleware layer constructs a causal graph comprising the network layer, control layer, and physical layer, and searches for the set of causes of anomalies. The cloud-based middle platform generates a predicted response through real-time power flow calculation and compares the predicted response with the actual measurement for deviation. The cloud-based middleware layer determines the response level based on the comparison results and risk indicators, and sends the safety state control curve to the energy storage system. The cloud-based middleware layer uses a digital twin model to replay historical events and update the edge weights of the causal graph.

[0014] Optionally, after updating the edge weights of the causal graph, a new strategy version is generated and pushed to the field edge layer; in the event of an abnormal data collection task, a backup communication link is enabled and the data that has not been uploaded to the chain is retransmitted from the cache.

[0015] Compared with the prior art, the present invention has the following beneficial effects: This invention utilizes edge-side multi-source data shaping and blockchain-based evidence storage technology to ensure the temporal consistency and immutability of multi-source wind, solar, and energy storage data at the source, solving the problems of data isolation and low evidence credibility in traditional monitoring. Building upon this, the cloud-based platform constructs a cross-domain causal graph covering the network-control physical layer and combines it with a control physical consistency verification model. This enables multi-dimensional correlation analysis of network logs, control commands, and electrical responses, overcoming the limitations of traditional systems in establishing cross-domain causal relationships. This allows for precise location of the root causes of complex attacks or failures. Finally, combined with a hierarchical response and adaptive strategy optimization mechanism, it achieves millisecond-level proactive response to security events and continuous iteration of defense strategies, significantly improving the security resilience and intelligent operation and maintenance level of integrated wind, solar, and energy storage facilities in a multi-source collaborative environment. Attached Figure Description

[0016] Figure 1 This is a schematic diagram of a module of a safety incident tracing and response management platform applicable to wind and solar storage stations according to an embodiment of the present invention; Figure 2 This is a schematic diagram of a module of the edge layer of a safety incident tracing and response management platform for wind and solar storage stations according to an embodiment of the present invention; Figure 3 This is a schematic diagram of the cloud-based middleware layer in a safety incident tracing and response management platform applicable to wind and solar power storage stations according to an embodiment of the present invention; Figure 4 This is a schematic diagram of the workflow of a safety incident tracing and response management platform applicable to wind and solar storage stations, according to an embodiment of the present invention. Detailed Implementation

[0017] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.

[0018] The following disclosure provides many different embodiments or examples for implementing various structures of the invention. To simplify the disclosure, specific examples of components and arrangements are described below. These are merely examples and are not intended to limit the invention. Furthermore, reference numerals and / or letters may be repeated in different examples; such repetition is for simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or arrangements discussed. In addition, examples of various specific processes and materials are provided in this invention, but those skilled in the art will recognize the application of other processes and / or the use of other materials.

[0019] This invention provides a safety incident tracing and response management platform applicable to wind-solar-storage hybrid power plants, belonging to the field of new energy safety monitoring and intelligent operation and maintenance technology. Addressing the problems of isolated multi-source safety incident information, insufficient evidence traceability, difficulty in linking causal relationships across multiple network-control physical domains, and delayed response of energy storage devices under abnormal conditions in existing wind-solar-storage hybrid power plants, this platform proposes a full-process safety management system based on a trusted evidence chain and cross-domain causal reasoning. This system achieves closed-loop management of safety incidents from collection, shaping, on-chaining, analysis to response and review.

[0020] like Figures 1 to 4 As shown, the platform of this invention adopts a two-layer collaborative architecture of site edge layer and cloud middleware layer for deployment and operation.

[0021] The site edge layer is used to perform underlying data acquisition, time synchronization, evidence shaping and trusted storage, forming raw event data and encrypted evidence chains; The cloud-based middleware layer undertakes tasks such as cross-domain causal analysis, control consistency verification, hierarchical response decision-making, and strategy review and optimization, thereby achieving functional synergy between security situation awareness and proactive response.

[0022] The platform mainly includes the following eight functional modules: 1. Acquisition and isolation unit.

[0023] 2. Time synchronization and evidence shaping unit.

[0024] 3. Trusted Evidence Storage and Device Snapshot Unit.

[0025] 4. Cross-domain causal mapping and root cause analysis engine.

[0026] 5. Control the physical consistency verification model.

[0027] 6. Graded response and energy storage safety state control unit.

[0028] 7. Exercise and strategy verification unit.

[0029] 8. Retrospective analysis and adaptive optimization unit.

[0030] During operation, the platform utilizes an edge-cloud collaborative mechanism to achieve real-time monitoring, tracing, and policy adjustment of multi-source security events. The edge layer is responsible for collecting on-site signals and generating evidence, while the cloud-based middleware platform is responsible for causal reasoning, verification and judgment, and closed-loop policy optimization. This architecture enables reliable tracing of security events, root cause identification, controllable response, and self-evolving policies, significantly improving the security resilience and intelligence level of integrated wind, solar, and energy storage facilities under complex operating conditions such as network attacks, electrical disturbances, and control anomalies.

[0031] To ensure the long-term stability of the platform, this invention incorporates redundancy in both software and hardware architecture. The edge layer host employs a dual-machine hot standby and network outage autonomy mode, ensuring that in the event of a host failure or communication interruption, the backup host can seamlessly take over data acquisition and local response tasks. The cloud-based middleware layer adopts a containerized microservice deployment structure, achieving multi-node collaborative computing through load balancing and task distribution, and possessing horizontal scalability and modular maintenance capabilities. Asynchronous interaction between functional modules is achieved through a message queue mechanism; the message body includes digital signatures, task identifiers, and version number information to ensure data consistency and interface traceability.

[0032] The platform employs an independent thread monitoring mechanism for critical tasks, detecting message blocking, memory usage, and communication latency in real time. Upon detecting anomalies, it automatically switches to redundant links or backup task channels to prevent data loss or response delays. The platform supports independent module-level maintenance and online upgrades. When any module is updated, the main task thread enters protection mode to ensure that security event monitoring, data acquisition, and response control functions are unaffected.

[0033] To make the technical solution and operating mechanism of this invention clearer, the platform structure and working principle of this invention will be described in detail below with reference to the accompanying drawings. It should be understood that the following description is only for illustrating the implementation of this invention and is not intended to limit the scope of protection of this invention. Through a layered explanation of the platform structure and functional logic, the deployment mode and functional collaboration of this invention in actual new energy power plants can be intuitively understood. Specifically, the technical implementation process of this invention can be divided into two parts: the power plant edge layer and the cloud-based middleware layer. These two layers form a complete closed loop for security event tracing and response through encrypted communication and task collaboration mechanisms, as detailed below.

[0034] (a) Station edge layer: like Figure 2 As shown, the edge layer of the wind, solar, and energy storage facility is the front-end foundational layer of the platform of this invention, mainly responsible for data acquisition, time synchronization, evidence shaping, and reliable storage. The edge layer is deployed in the station control system network of the wind, solar, and energy storage facility, and achieves local autonomy and secure isolation through an independent industrial host.

[0035] The edge layer includes an acquisition and isolation unit, a time synchronization and evidence shaping unit, and a trusted evidence storage and device snapshot unit. The acquisition and isolation unit connects to the operational data channels of wind turbine controllers, photovoltaic inverters, energy storage converters, protection and control devices, and network security equipment via a read-only communication interface. To prevent back-end control signal intrusion, the edge layer communication link is equipped with a unidirectional optical shutter and isolation relay structure, ensuring data only flows out and not in, achieving physical isolation between the field control domain and the monitoring domain.

[0036] The time synchronization and evidence shaping unit uses the PTP master clock as the primary time source and the IRIG-B signal as a redundant time source to estimate and correct the drift of data timestamps from different devices. During the acquisition phase, the system adds a dual timestamp to each event: device time and platform time, and uses a deviation correction algorithm to achieve unified time-series ordering. The shaped event stream forms a unified timeline event set for subsequent causal analysis and attribution.

[0037] The trusted evidence storage and device snapshot unit performs periodic evidence storage on the shaped event set. Within each storage period, the system uses the Merkle tree algorithm to generate the root hash value of the event digest and writes it to the consortium blockchain node to form a tamper-proof anchor record. Simultaneously, the edge host performs device snapshot collection when a critical event is triggered, including information such as control register status, buffer data, and counter values. The snapshot file is then encrypted and written to the WORM read-only array storage to achieve long-term reliable preservation and authenticity verification of evidence.

[0038] Under long-term operation and complex field conditions, the edge layer is equipped with an event caching and link self-checking mechanism to temporarily save event records and maintain data integrity in the event of communication interruption, transmission delay, or temporary unavailability of the on-chain channel. The caching module adopts a time-stamped sorting strategy to ensure that the data not yet on-chain can be retransmitted in the order of event occurrence after communication is restored, preventing time sequence errors or duplicate submissions.

[0039] The edge host incorporates drift detection and clock self-calibration logic. When the deviation between the local clock of the acquisition terminal and the system reference clock exceeds a set threshold, the host automatically sends a calibration command to the terminal and records the deviation correction log. The system also features a heartbeat monitoring mechanism for acquisition tasks, which detects data stream interruptions, acquisition delays, and abnormal input formats in real time. When an acquisition anomaly is detected, a restart sequence is triggered or a backup communication link is activated to ensure the continuity and stability of the data chain.

[0040] In addition, to ensure the compatibility and security of field device access, the acquisition unit supports parallel adaptation of Modbus, IEC104 and custom TCP communication protocols, and uses security certificates for device authentication, so that the data access and upload process meets the requirements of encrypted communication and access authorization.

[0041] (II) Cloud-based middleware layer: like Figure 3 As shown, the cloud-based middleware layer is the core of intelligent analysis and decision-making of the platform of this invention, mainly including a cross-domain causal graph and root cause analysis engine, a control physical consistency verification model, a hierarchical response and energy storage safety state control unit, an exercise and strategy verification unit, and a review and adaptive optimization unit.

[0042] The cross-domain causal graph and root cause analysis engine receives event summaries and evidence indexes from the edge layer. By establishing a three-layer causal model (network layer, control layer, and physical layer), it maps network logs, control commands, protection actions, and electrical measurements into a multi-layer graph structure. The weight of each graph edge is determined by temporal proximity, logical consistency, and physical consistency. The system uses a restricted minimum cut algorithm to search for the minimum set of causes covering the target anomaly, outputting the root cause confidence and the corresponding device set, thus achieving automatic source tracing and partitioned correlation analysis of complex events.

[0043] To ensure the interpretability and verifiability of the causal analysis process, this invention establishes a source index table for each causal relationship while performing inference calculations. This index table records the unique identifier of the involved event, the source device code, the time window, and the associated on-chain evidence storage number. After generating the causal path, the system automatically generates a corresponding list of evidence citations and creates an audit copy in the cloud database. Operations personnel can directly locate the corresponding hash record in the consortium blockchain using the evidence number, achieving full-chain verification from the analysis results to the original data.

[0044] In addition, the system provides a visual causal chain display interface, presenting event nodes from different domains in a hierarchical structure. The connections between nodes are labeled with weights and directions to illustrate the formation logic of causal relationships. Through this mechanism, security managers can trace the triggering conditions, propagation paths, and termination points of each security incident, ensuring that analysis conclusions are transparent, processes are verifiable, and results are traceable.

[0045] The control physical consistency verification model compares the command output of the control chain with the primary electrical response. Using a real-time power flow calculation model as a reference, the system generates a predicted response vector for the control command and compares it with the actual measured vector within the corresponding time window to determine the deviation. When the deviation exceeds a threshold, the model generates a consistency anomaly event and feeds it back to the causal graph for updating edge weights and triggering response strategy determination.

[0046] The graded response and energy storage safety state control unit executes a dynamic response strategy based on a joint risk index and priority matrix. This matrix comprehensively considers three dimensions: power generation loss, system risk, and energy storage health, and automatically determines the response level. For energy storage units, the system issues safety state control curves in real time, limiting the rate of change of power, state of charge range, and bus voltage deviation to ensure that the energy storage system can maintain a safe operating state under grid disturbances or communication anomalies.

[0047] The exercise and strategy verification unit constructs a digital twin model and verifies the effectiveness and response latency of the current strategy through historical event replay and virtual disturbance injection. Based on the exercise results, the system comprehensively scores the recovery time, steady-state deviation, and energy storage loss of different response paths, generating a strategy verification report.

[0048] During the strategy verification phase, the system can automatically generate typical perturbation combinations and random anomaly samples based on historical event types to test the broad adaptability of the strategy. During the exercise, the cloud model records the strategy trigger time, response duration, and state change sequence, and presents the verification process as curves on the visualization interface, including indicators such as event energy change trajectory, recovery trend, and system steady-state recovery rate.

[0049] Verification results are archived in report form, including the strategy version number, operating conditions, and a results summary, for strategy review and continuous optimization. All exercise data is synchronously written to the log database and indexed with tags for subsequent comparison of the response effects of different strategy versions. Through this mechanism, the platform achieves a closed-loop verification system from strategy design to execution verification and performance evaluation, significantly improving the systematization and maintainability of strategy management.

[0050] The retrospective and adaptive optimization unit takes the event root cause, response behavior, and recovery metric as triplet input samples, and updates the edge weights of the causal graph and the policy threshold through the optimization engine. After training, a new policy version is generated and pushed to the edge nodes asynchronously, realizing the self-learning and adaptive evolution of the security policy.

[0051] (III) System Workflow: like Figure 4 As shown, the workflow of the platform of this invention includes seven main stages: 1. Evidence collection and fingerprinting stage.

[0052] Data from devices such as wind turbines, photovoltaic inverters, and energy storage converters can be widely accessed through read-only interfaces. One-way optical shutters and isolation relays are used to achieve physical-level outgoing but not incoming control signals, preventing reverse penetration of control signals. Device identity authentication is completed in conjunction with security certificates.

[0053] 2. Time alignment and shaping stage.

[0054] The platform uses the PTP master clock to perform drift correction on multi-source data and adds a dual timestamp of device time and platform time to each event, thereby transforming the messy data stream into an ordered set of events with a unified timeline.

[0055] 3. Trusted on-chain and snapshot storage stage.

[0056] The system uses the Merkle tree algorithm to generate event summaries and writes them to the consortium blockchain to prevent tampering. At the same time, it captures the status of device registers and buffers at critical moments and writes them to read-only storage. Even in the event of a network outage, the system can ensure the complete retransmission of data through a caching mechanism.

[0057] 4. Causal mapping construction and root cause analysis stage.

[0058] The platform establishes a three-layer causal model covering the network layer, control layer, and physical layer. It uses the restricted minimum cut algorithm to automatically search for the minimum causal set of anomalies and establishes an evidence index for the analysis results that can be traced back to the original hash record.

[0059] 5. Consistency verification and risk assessment stage.

[0060] The system uses a real-time power flow calculation model to predict the response that the control command should produce, compares it with the actual electrical measurements, and once the deviation exceeds the threshold, it is determined that the logic and physical state are inconsistent. This anomaly is then fed back to the causal graph to update the risk weights.

[0061] 6. Stage of graded response and energy storage control.

[0062] The system automatically determines the response level based on indicators such as power generation loss, system risk, and energy storage health. In particular, it issues safety-state control curves for energy storage units to limit their power change rate and voltage deviation in order to maintain system stability.

[0063] 7. Review and strategy optimization phase.

[0064] The platform uses digital twin technology to replay historical events and inject virtual perturbations to verify the effectiveness of the strategy. Based on the exercise results, it adaptively updates the edge weights and policy thresholds of the causal graph. The generated new strategy is then pushed back to the edge nodes, realizing continuous self-learning and iteration of security protection capabilities.

[0065] During actual system operation, tasks at each stage are coordinated and executed by a unified scheduling and management module. This module uses a state machine mechanism to maintain the lifecycle of event processing, and the execution status of each task is marked with an identifier and a result flag. When a task anomaly, delay, or missing data is detected, the system automatically enters the anomaly compensation process, reschedules incomplete tasks, and records error logs.

[0066] The system performs a status check before each task switch to ensure that the results of the previous step have been stored and synchronized, preventing process misalignment or data rewriting.

[0067] In high-concurrency scenarios, the system can dynamically adjust task priorities and allocate higher computing resources and bandwidth channels to critical security events, thereby ensuring timely event response.

[0068] The cloud-based platform also provides a task tracking interface, allowing users to view the entire status and results of each stage of an event from data collection to review by task number. Through this unified scheduling and status management mechanism, this invention achieves task continuity, process controllability, and data consistency in complex operating environments.

[0069] The safety incident tracing and response management platform proposed in this invention, applicable to wind, solar and energy storage stations, achieves full-process control of safety incidents in wind, solar and energy storage systems from occurrence and tracking to handling by constructing an integrated architecture of edge trusted data collection, cloud causal analysis and strategy review.

[0070] The platform incorporates three core mechanisms in its design: trusted evidence chain, cross-domain causal reasoning, and hierarchical response control. These mechanisms enable unified management of multi-domain data and traceable handling of abnormal events, as well as rapid identification of root causes and generation of optimized response strategies when security threats occur.

[0071] Among them, the edge layer is responsible for the collection and storage of raw data to ensure the authenticity and integrity of basic information; the cloud platform realizes the unified mapping of logical chain and physical chain through cause-effect graph and consistency verification, forming a complete path of security event evolution, and achieving the goal of intelligent security management that is verifiable, traceable and controllable.

[0072] Furthermore, the system employs a multi-layered access and operation auditing mechanism in its overall security design. Based on user identity and permission levels, the platform sets strict access control policies for security events, policy management, and data access. The system is divided into three permission levels: operations and maintenance personnel, management and supervision, and auditing bodies. Different levels can only access data and operation interfaces within their respective authorized scope.

[0073] The cloud-based middleware platform has built-in access control lists (ACLs) and identity authentication modules. All critical operations automatically generate log entries, which record the operation time, operator identifier, and operation content summary. These logs are also linked to the timestamps stored on the consortium blockchain, forming a dual chain of evidence: security events and operation records.

[0074] If unauthorized access or high-risk commands are detected during system operation, the system will immediately trigger a security alarm and freeze the session channel to prevent unauthorized operations from interfering with the running system.

[0075] Through this multi-level permission and auditing system, this invention not only ensures the authenticity and traceability of security incidents, but also achieves compliance and regulatory oversight of system operations, providing solid evidence for subsequent security accountability.

[0076] The platform architecture of this invention has high scalability and versatility, and can be flexibly deployed according to different scenarios. For a single wind farm, photovoltaic power station, or independent energy storage station, only edge-side modules and lightweight cloud interfaces can be deployed to form a localized security event monitoring and tracing system.

[0077] For wind, solar, and energy storage integrated or cross-regional collaborative operation of multiple power stations, a complete edge-cloud architecture can be enabled, with multi-station joint security situation analysis, collaborative response, and strategy co-construction achieved at the cloud-based middleware layer. The system uses a unified data format and interface standard to achieve aggregated analysis and hierarchical processing of security data from multiple power stations, supporting integrated deployment at the regional or provincial level for new energy dispatch centers.

[0078] The platform is compatible with existing power plant monitoring and control systems (SCADA), energy storage management systems (BMS), and power dispatching systems (EMS), enabling modular access without altering the original hardware architecture. The system provides API interfaces, data adapters, and message queue gateways, supporting mainstream industrial communication protocols and distributed message transmission protocols, thus ensuring rapid implementation and promotion of this invention in various operation and maintenance environments.

[0079] Through the above technical architecture, this invention not only realizes the secure and reliable management of multi-source data from wind, solar and energy storage stations, but also forms a closed-loop operation system covering perception, tracing, response, review and optimization, providing systematic and sustainable technical support for the safe operation and maintenance of new energy power stations.

[0080] The platform described in this invention has taken into account the communication structure, operation and maintenance process, and security protection requirements of actual new energy power plants, and its software and hardware design scheme can be fully implemented under existing technical conditions. At the hardware level: edge nodes can consist of industrial-grade host, PLC or embedded controller, equipped with network isolation module, clock synchronization module and read-only array storage unit.

[0081] On the software side: The system supports Linux or domestic operating system environments, and its modular design facilitates deployment via containerized services.

[0082] Communication and security: Nodes interact through TLS encrypted communication channels and employ key signing, hash digest, and anti-replay mechanisms to ensure data security.

[0083] The system's core algorithm modules (causal graph, control consistency verification, and strategy optimization) are all built based on standard data structures and logical reasoning rules. They do not depend on specific hardware devices and can be directly integrated through existing data acquisition and monitoring systems of new energy power plants.

[0084] Therefore, the present invention has high feasibility for engineering implementation and universal adaptability.

[0085] The security incident tracing and response management platform proposed in this invention is applicable to hybrid power plants consisting of wind power generation, photovoltaic power generation and energy storage systems, as well as microgrids, integrated energy systems and regional energy internet environments.

[0086] By establishing a unified evidence chain structure and event causal model, the platform can effectively improve the network security protection capabilities, event handling efficiency, and intelligence level of new energy systems, providing security for the high-proportion grid-connected operation of new energy power plants.

[0087] This invention provides a safety incident tracing and response management platform suitable for wind, solar, and energy storage facilities. By constructing an integrated hardware and software architecture that coordinates the edge layer of the facility and the cloud-based middleware layer, it achieves reliable management of the entire safety incident process. Through the coordinated operation of modules such as data acquisition isolation, time synchronization, evidence shaping, and on-chain evidence storage, the platform ensures the authenticity and temporal consistency of multi-source data, avoiding the problems of fragmented event information and difficulties in evidence collection in traditional facility monitoring systems.

[0088] The platform of this invention introduces cross-domain causal graphs and consistency verification models in the cloud middleware layer to establish multi-domain correlations of network, control and physical domains, and realize root cause identification and hierarchical response of security events; at the same time, combined with strategy exercise and debriefing optimization mechanism, the security strategy has self-learning and dynamic evolution capabilities, thereby improving the security defense and response efficiency of wind, solar and energy storage integrated stations.

[0089] By comprehensively applying the above-mentioned technical features, this invention not only achieves traceability, verifiability, and closed-loop response to security incidents, but also constructs a scalable security management and control system, significantly improving the resilience and intelligence level of new energy power stations under complex operating conditions such as network attacks, electrical disturbances, and control anomalies, and has good engineering applicability and promotion value.

[0090] This invention achieves safety and controllability while possessing promising prospects for widespread application. 1. Standardized interface design: It can be quickly connected to various SCADA and energy storage control systems to achieve safe management of cross-vendor equipment.

[0091] 2. Algorithm scalability: Supports continuous learning and self-optimization of causal analysis models and strategy libraries.

[0092] 3. Diverse application scenarios: It can be used for independent deployment at a single site, or it can be extended to a regional security management and data sharing platform.

[0093] In summary, this invention provides a systematic solution in the field of new energy safety management that integrates trusted evidence storage, cross-domain causal analysis, and strategy self-evolution. It not only solves the problems of poor event traceability and low response timeliness in existing technologies, but also realizes intelligent safety closed-loop management of wind, solar and energy storage stations through systematic design, and has significant practical value and creativity.

[0094] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0095] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0096] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0097] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0098] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

[0099] It should be understood that the above description is for illustrative purposes and not for limitation. Many embodiments and applications beyond the provided examples will be apparent to those skilled in the art upon reading the above description. Therefore, the scope of this patent should not be determined by reference to the above description, but rather by reference to the foregoing claims and the full scope of their equivalents. For purposes of completeness, all articles and references, including patent applications and publications, are incorporated herein by reference. The omission of any aspect of the subject matter disclosed herein in the foregoing claims is not intended as a waiver of that subject matter, nor should it be construed as an indication that the applicant has not considered that subject matter as part of the disclosed inventive subject matter.

Claims

1. A safety incident tracing and response management platform suitable for wind and solar power storage facilities, characterized in that, Including the station edge layer and the cloud middleware layer; The station's edge layer communication connects to the cloud middleware layer; The site edge layer includes a data acquisition and isolation unit, a time synchronization and evidence shaping unit, and a trusted evidence storage and equipment snapshot unit; it is used for underlying data acquisition, time synchronization, evidence shaping and trusted evidence storage, forming original event data and encrypted evidence chains; The cloud-based middleware layer includes a cross-domain causal graph and root cause analysis engine, a control physical consistency verification model, a hierarchical response and energy storage safety state control unit, a drill and strategy verification unit, and a review and adaptive optimization unit; used for cross-domain causal analysis, control consistency verification, hierarchical response decision-making, and strategy review and optimization.

2. The safety incident tracing and response management platform for wind, solar and energy storage facilities as described in claim 1, characterized in that, The acquisition and isolation unit includes a read-only communication interface, which connects to the data channels of the wind turbine controller, photovoltaic inverter, and energy storage converter; the communication link of the acquisition and isolation unit is equipped with a one-way optical shutter and an isolation relay.

3. The safety incident tracing and response management platform for wind, solar and energy storage facilities as described in claim 1, characterized in that, The time synchronization and evidence shaping unit connects to the PTP master clock as the primary time source and to the IRIG-B signal as a redundant time source; the time synchronization and evidence shaping unit marks the collected data with device timestamps and platform timestamps.

4. The safety incident tracing and response management platform for wind, solar and energy storage facilities as described in claim 1, characterized in that, The trusted evidence storage and device snapshot unit is connected to a consortium blockchain node and a WORM read-only array storage; the trusted evidence storage and device snapshot unit uses the Merkle tree algorithm to generate the root hash value of the event digest and writes it to the consortium blockchain node; the trusted evidence storage and device snapshot unit encrypts the device snapshot file and writes it to the WORM read-only array storage.

5. The safety incident tracing and response management platform for wind, solar and energy storage facilities as described in claim 1, characterized in that, The cross-domain causal graph and root cause analysis engine includes a network layer causal model, a control layer causal model, and a physical layer causal model. The cross-domain causal graph and root cause analysis engine establishes a source index table, which records the event identifier, source device code, time window, and on-chain evidence number.

6. The safety incident tracing and response management platform for wind and solar power storage facilities according to claim 1, characterized in that, The control physical consistency verification model includes a real-time power flow calculation model; the control physical consistency verification model receives control commands and generates a predicted response vector, which corresponds to the actual measurement vector; the control physical consistency verification model compares the deviation between the predicted response vector and the actual measurement vector.

7. The safety incident tracing and response management platform for wind, solar and energy storage facilities as described in claim 1, characterized in that, The graded response and energy storage safety state control unit stores joint risk indicators and priority matrices; the graded response and energy storage safety state control unit connects to the energy storage unit and sends safety state control curves to the energy storage unit; the safety state control curves include power change rate limit values, state of charge range values ​​and bus voltage deviation values.

8. The safety incident tracing and response management platform for wind, solar and energy storage stations according to claim 1, characterized in that, The exercise and strategy verification unit includes a digital twin model; the debriefing and adaptive optimization unit includes an optimization engine that connects a cross-domain causal graph and a root cause analysis engine to update the graph edge weights.

9. A method for tracing and responding to safety incidents at wind and solar power storage facilities, based on the platform described in any one of claims 1-8, characterized in that, Includes the following steps: The edge layer of the station collects the operating data of the equipment through a read-only interface and isolates the control signals through a one-way optical shutter. The station edge layer uses the PTP master clock to perform drift correction on the operating data and marks it with dual timestamps to form an event set; The digest hash value of the event set generated at the edge layer of the site is written to the consortium blockchain, and the device snapshots of key events are written to read-only storage; The cloud-based middleware layer constructs a causal graph comprising the network layer, control layer, and physical layer, and searches for the set of causes of anomalies. The cloud-based middle platform generates a predicted response through real-time power flow calculation and compares the predicted response with the actual measurement for deviation. The cloud-based middleware layer determines the response level based on the comparison results and risk indicators, and sends the safety state control curve to the energy storage system. The cloud-based middleware layer uses a digital twin model to replay historical events and update the edge weights of the causal graph.

10. The method for tracing and responding to safety incidents at wind, solar, and energy storage facilities as described in claim 9, characterized in that, After updating the edge weights of the causal graph, a new strategy version is generated and pushed to the field edge layer; when the data collection task is abnormal, a backup communication link is enabled and the data that has not been uploaded to the chain is retransmitted from the cache.

Citation Information

Cited By

  • A cloud-edge synchronization method and system of a distributed internet of things rule engine

    CN122179461A

  • A cloud-edge synchronization method and system for a distributed IoT rules engine

    CN122179461B