Safe data transmission system and method for unmanned aerial vehicle nest and electric power intranet

By coordinating the design of the power safety IoT card and the secure access platform, the security vulnerabilities and stability issues in data transmission between the drone nest and the power intranet were resolved, realizing secure data transmission between the drone nest and the power intranet and improving the efficiency and security of power inspection.

CN121967053AInactive Publication Date: 2026-05-01刘伟
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
刘伟
Filing Date
2026-02-10
Publication Date
2026-05-01
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing data transmission between drone nests and the power grid's internal network suffers from public network security vulnerabilities, high risks of internal network access, and unstable data transmission, failing to meet the power industry's security and flexibility requirements.

Method used

By employing a power safety IoT card and a secure access platform working together, and accessing the dedicated power communication network through a dedicated APN, an end-to-end encrypted transmission channel is constructed. Combined with identity authentication and anomaly monitoring, full-process security protection is achieved, and millisecond-level card switching is supported to ensure transmission stability.

Benefits of technology

Completely blocks public network attack paths, achieves full-process security protection, ensures the stability and security of data transmission, complies with power intranet access standards, and improves inspection efficiency and data timeliness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967053A_ABST
    Figure CN121967053A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric power communication security, and discloses a security data transmission system and method for an unmanned aerial vehicle nest and an electric power intranet, and the system comprises an unmanned aerial vehicle terminal, an unmanned aerial vehicle nest with a built-in electric power security Internet of Things card, a security access platform constructed based on a national secret algorithm, and an electric power intranet unmanned aerial vehicle management and control platform. The method comprises the steps that the unmanned aerial vehicle terminal collects data and uploads the data to the unmanned aerial vehicle nest, the unmanned aerial vehicle nest triggers the electric power security Internet of Things card to encrypt the data and transmits the data to the security access platform through the special APN, and after identity authentication, decryption, abnormity monitoring and permission verification, the data are securely accessed to the intranet management and control platform. According to the invention, the special APN isolation public network is adopted, and the national cryptographic algorithm full-process encryption and the main and standby dual-card redundancy design are combined, so that the security risk of the public network is blocked, the transmission stability is ensured, the power intranet access specification is adapted, and the inspection efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Secure data transmission system and method between UAV nests and power grid Technical Field

[0001] This invention relates to the field of power communication security technology, specifically to a secure data transmission system and method between a drone's nest and the power grid intranet, applicable to remote data acquisition, encrypted transmission, and secure access in power grid inspection scenarios. Background Technology

[0002] With the widespread application of drone inspection technology in the power industry, drone nests, serving as terminals for drone parking, charging, and data storage, need to remotely transmit collected inspection data to the drone management platform within the power intranet for centralized data analysis and management. However, existing technologies have several shortcomings: if drone nests are directly connected to the power intranet via the public internet, the public network transmission channel lacks dedicated encryption protection, making it highly vulnerable to attacks such as illegal eavesdropping, data tampering, and identity forgery. Illegal terminals may also infiltrate the power intranet through the public network link, causing major security incidents such as power grid dispatch data leakage and control system paralysis. If data transmission is completely separated from the public network, it cannot meet the flexible data upload needs of drone nests in remote deployment scenarios such as mountainous areas and remote transmission line areas, resulting in the inability to transmit inspection data in real time, affecting inspection efficiency and the timeliness of fault handling.

[0003] Furthermore, existing ordinary IoT cards can only achieve basic data transmission, lacking dedicated security protection mechanisms for the power industry, and cannot coordinate with the access control of the power intranet, making it difficult to solve the dual challenges of "public network transmission security" and "intranet access isolation." Therefore, there is an urgent need for a technical solution that combines transmission stability, security, and intranet access isolation to achieve secure data interaction between the drone's nest and the power intranet management platform. Summary of the Invention

[0004] The purpose of this invention is to address the problems of public network security vulnerabilities, high risks of intranet access, and unstable data transmission in existing data transmission between drone nests and power intranets. It provides a secure data transmission system and method for drone nests and power intranets. Through the collaboration of power security IoT cards and secure access platforms, it ensures real-time data transmission while preventing public network attacks from penetrating the power intranet, thus protecting the security of power communication networks and data.

[0005] To achieve the above objectives, this invention provides a secure data transmission system between a drone's nest and a power grid intranet, comprising a drone terminal, a drone nest, a secure access platform, and a power grid intranet drone management platform. These modules work together to form a secure transmission link throughout the entire process: the drone terminal establishes a local communication connection (such as WiFi or Bluetooth) with the drone nest to collect power inspection data, and uploads the collected data to the drone nest via the local communication link; the drone nest has a built-in data storage unit, control unit, and power safety IoT card for temporarily storing the data collected by the drone, and triggers data encryption transmission commands through the control unit; the power safety IoT card adopts an industrial-grade design, integrating a dedicated APN module, a VPN tunnel construction module, and a data encryption module, accessing the dedicated power communication network via the dedicated APN instead of the public internet, and constructing end-to-end encryption through a VPN tunnel protocol. The transmission channel uses data encryption algorithms to encrypt transmitted data. The secure access platform is deployed at the boundary of the power intranet and is built based on identity authentication and decryption algorithms. It includes an identity authentication unit, a data decryption unit, an anomaly monitoring unit, and an access control unit. The identity authentication unit performs hardware identification (e.g., IMSI, ICCID) and key dual authentication on the power security IoT card of the drone nest to verify the terminal's legitimacy. The data decryption unit receives encrypted data and decrypts it by matching the key. The anomaly monitoring unit builds a profile of the terminal device, monitors data parameters in real time, and identifies abnormal behavior. The access control unit assigns exclusive data transmission permissions to different drone nests and restricts the access range. The power intranet drone management platform is deployed on the power intranet and receives the inspection data decrypted by the secure access platform for data storage, analysis, and display.

[0006] As a further description of the above technical solution: the power inspection data collected by the UAV terminal includes images, videos and power equipment operating parameters, wherein the power equipment operating parameters include conductor temperature and equipment defect correlation parameters.

[0007] As a further description of the above technical solution: the power safety IoT card is equipped with a primary and backup dual-card redundancy unit, which can achieve millisecond-level automatic switching, and is used to maintain the connection of the encrypted transmission channel when the current communication link is abnormal, so as to ensure that the transmission link is not interrupted.

[0008] As a further description of the above technical solution: the preferred data encryption algorithm for the power safety IoT card is the national standard SM4 algorithm.

[0009] As a further description of the above technical solution: the identity authentication algorithm of the secure access platform is preferably the national cryptographic SM2 algorithm, and the decryption algorithm is preferably the national cryptographic SM4 algorithm.

[0010] As a further description of the above technical solution: the data parameters monitored by the anomaly monitoring unit of the secure access platform include transmission rate, data packet format, data packet integrity, access location, access IP, access frequency, and data traffic.

[0011] As a further description of the above technical solution: the abnormal behaviors identified by the anomaly monitoring unit of the secure access platform include unauthorized access, data tampering, and access IP not matching the preset area.

[0012] To achieve the above objectives, the present invention also provides a secure data transmission method between a UAV nest and a power grid intranet. Utilizing the aforementioned secure data transmission system, the method includes the following steps: (1) After the UAV terminal completes power inspection data collection, it uploads the data to the storage unit of the UAV nest via a local communication link; (2) Upon detecting the completion of data storage, the control unit of the UAV nest sends a data transmission trigger command to the power security IoT card; (3) After receiving the command, the power security IoT card accesses the dedicated power communication network via a dedicated APN, initiates a VPN tunnel protocol to construct an encrypted transmission channel, and simultaneously uses a data encryption algorithm to encrypt the inspection data; (4) The encrypted inspection data is transmitted via… (5) The identity authentication unit of the power security IoT card extracts the hardware identifier and key of the power security IoT card and performs dual identity authentication through the identity authentication algorithm. If the authentication is successful, the next step is entered. If the authentication fails, the data is rejected and an abnormal log is recorded. (6) After the identity authentication is successful, the data decryption unit uses a decryption algorithm that matches the data encryption algorithm to decrypt the encrypted data. (7) The abnormal monitoring unit monitors the parameters in the data transmission process in real time. If abnormal behavior is detected, the transmission is immediately interrupted and a warning message is sent to the management and control platform. (8) After the decrypted compliant data is verified by the permission management and control unit, it is securely accessed to the power intranet drone management and control platform.

[0013] As a further description of the above technical solution: if the current communication link is abnormal in step (3), the primary and backup dual-card redundancy unit configured in the power safety IoT card will automatically switch to the backup card, and the switching response time is in milliseconds, maintaining the connection of the encrypted transmission channel.

[0014] As a further description of the above technical solution: In step (8), the access control unit only allows the decrypted compliant data to access the designated database of the UAV management platform. The designated database is a dedicated database of inspection data corresponding to the UAV nest, thus restricting the scope of data access.

[0015] Compared with existing technologies, this invention has the following advantages: 1. Completely blocks public network security risks: By accessing the dedicated power communication network through the dedicated APN of the power safety IoT card, direct connection between the drone's nest and the public network is avoided, isolating illegal attack paths from the transmission layer; 2. Full-process security protection: Achieves full-link security control of "terminal encryption - channel encryption - identity authentication - data decryption - anomaly monitoring". The application of national cryptographic algorithms (SM2, SM4) meets the cryptographic compliance requirements of the power industry, effectively preventing data leakage, tampering and illegal access; 3. High transmission stability: The industrial-grade power safety IoT card is suitable for harsh environments such as high-altitude cold and strong electromagnetic fields in power inspections. The primary and backup dual-card redundancy design achieves millisecond-level switching, ensuring uninterrupted data transmission; 4. Adapts to power intranet access standards: The secure access platform is deployed at the intranet boundary. Through strict identity authentication and access control, it complies with the power intranet security access standards, avoiding intranet security risks caused by terminal access; 5. Improves inspection efficiency: Data is encrypted and transmitted to the intranet management platform in real time, eliminating the need for manual on-site data export, solving the problem of data backhaul for remotely deployed drone nests, and ensuring the timeliness of inspection data. Attached Figure Description

[0016] Figure 1 is a system architecture diagram of the present invention.

[0017] Figure 2 is a structural diagram of the power safety IoT card.

[0018] Figure 3 is a structural diagram of the secure access platform.

[0019] Figure 4 is a data transmission flowchart of the method of the present invention. Detailed Implementation

[0020] The claims of the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments, but this does not constitute any limitation on the present invention. Any limited modifications made by any person within the scope of protection of the claims of the present invention shall still be within the scope of protection of the claims of the present invention.

[0021] This embodiment provides a secure data transmission system between a drone's nest and a power intranet. Its system architecture, as shown in Figure 1, includes a drone terminal, a drone nest, a secure access platform, and a power intranet drone management platform. These modules work together to form a secure transmission link throughout the entire process: The drone terminal collects power inspection data (images, videos, parameter data, etc.), establishes a local communication connection with the drone nest (e.g., WiFi, Bluetooth), and uploads the collected data to the nest; the drone nest has a built-in data storage unit, control unit, and power security IoT card, used to temporarily store the data collected by the drone and trigger data encryption transmission commands through the control unit; the structure of the power security IoT card, as shown in Figure 2, adopts an industrial-grade design, integrating a dedicated APN module, a VPN tunnel construction module, and a data encryption module, and is configured with a primary / backup dual-card redundancy unit; it accesses the dedicated power communication network through a dedicated APN, rather than the public internet, and constructs an end-to-end encrypted transmission channel through a VPN tunnel protocol, using the national cryptographic SM4 algorithm to encrypt the transmitted data. The primary / backup dual-card redundancy unit can achieve... Millisecond-level automatic switching is used to maintain the encrypted transmission channel connection when the current communication link is abnormal, ensuring that the transmission link is not interrupted. The full access platform is deployed at the boundary of the power intranet and is built based on the identity authentication algorithm (national cryptographic SM2 algorithm) and decryption algorithm (national cryptographic SM4 algorithm). The structure is shown in Figure 3, including an identity authentication unit, a data decryption unit, an anomaly monitoring unit, and an access control unit. The identity authentication unit is used to perform dual authentication of the power security IoT card of the UAV nest with hardware identification (IMSI, ICCID) and key to verify the legitimacy of the terminal. The data decryption unit is used to receive encrypted data and decrypt it by matching the key. The anomaly monitoring unit is used to build a terminal device profile, monitor parameters such as data transmission rate, data packet format, and access location in real time, and identify abnormal behaviors such as unauthorized access and data tampering. The access control unit is used to assign exclusive data transmission permissions to different UAV nests and restrict the access range. The power intranet UAV management platform is deployed in the power intranet and is used to receive the inspection data decrypted by the secure access platform for data storage, analysis, and display.

[0022] Example 2 This example provides a secure data transmission method between a drone nest and the power intranet. The data transmission process is shown in Figure 4. The specific operations are as follows: 1. System deployment: Drone nest deployment: Deploy drone nests or mobile drone nests in inspection areas such as along transmission lines and around substations. The nests have built-in power safety IoT cards and complete communication pairing with drone terminals; Secure access platform deployment: Deploy a secure access platform at the boundary of the power company's intranet, configure two servers (master and backup mode), run a domestic operating system, integrate SM2 and SM4 cryptographic modules, and preset the hardware identifier whitelist and authentication key of the power safety IoT card; Link configuration: The power safety IoT card accesses a dedicated APN network through a dedicated power base station, establishes a VPN tunnel with the secure access platform, and the secure access platform connects to the drone management platform through an intranet switch, constructing a dedicated secure transmission link from the drone nest to the power intranet management platform.

[0023] 2. Operation Process: After takeoff, the drone collects images of power transmission line defects and data such as conductor temperature along a preset inspection route. Upon completion, it automatically returns to its nest and uploads the data to the data storage unit via WiFi, completing data collection and initial storage. The drone's control unit detects the data upload completion and sends a transmission command to the power safety IoT card. The power safety IoT card then uses the national cryptographic SM4 algorithm to encrypt the data and establishes a VPN tunnel with the secure access platform via a dedicated APN, sending the encrypted data to the secure access platform. During this process, if the current communication link malfunctions, the power safety IoT card's built-in primary / backup dual-card redundancy unit will automatically switch to the backup card to maintain the encrypted transmission channel connection and ensure data transmission integrity. Interruption; The secure access platform extracts the IMSI and ICCID numbers of the power safety IoT card and compares them with a preset whitelist. Simultaneously, it verifies the authentication key using the national cryptographic SM2 algorithm. Upon successful authentication, the data is decrypted using the national cryptographic SM4 algorithm. If authentication fails, access is denied and an anomaly log is recorded, ensuring strict verification of terminal legitimacy. The anomaly monitoring unit monitors the data transmission rate in real time. If a sudden drop in rate or data packet verification failure occurs, an early warning is immediately triggered to promptly identify security risks during data transmission. The decrypted data is verified by the access control unit, allowing access only to the designated database of the drone management platform. Finally, defect images and temperature data are displayed on the management platform for staff analysis, ensuring secure, stable, and efficient data transmission.

[0024] This invention utilizes a collaborative authentication mechanism between a power safety IoT card and a secure access platform: through dual authentication of hardware identifiers and keys, combined with dedicated APN isolation of the public network, it achieves dual protection of terminal legitimacy and transmission channel security; the entire process of data encryption / decryption and identity authentication adopts national cryptographic algorithms: data transmission uses the national cryptographic SM4 algorithm, and identity authentication uses the national cryptographic SM2 algorithm, which complies with power industry security standards and prevents data eavesdropping and tampering; dual fault tolerance of primary and backup dual-card redundancy and anomaly monitoring: it not only ensures the stability of the transmission link, but also identifies abnormal risks in real time, improving the system's anti-interference and anti-attack capabilities.

[0025] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions will not cause the essence of the corresponding technical solutions to deviate from the protection scope of the present invention.

Claims

1. A secure data transmission system between a drone's nest and the power grid, characterized in that: The system includes a drone terminal, a drone nest, a secure access platform, and a power intranet drone management platform. The drone terminal establishes a local communication connection with the drone nest to collect power inspection data and upload it to the drone nest. The drone nest has a built-in data storage unit, control unit, and power safety IoT card for temporarily storing the power inspection data collected by the drone terminal and triggering data encryption transmission commands through the control unit. The power safety IoT card integrates a dedicated APN module, a VPN tunnel construction module, and a data encryption module. It accesses the dedicated power communication network through the dedicated APN, constructs an end-to-end encrypted transmission channel through the VPN tunnel protocol, and encrypts the transmitted data using data encryption algorithms. The secure access platform is deployed at the boundary of the power intranet and is built based on identity authentication and decryption algorithms. It includes an identity authentication unit, a data decryption unit, an anomaly monitoring unit, and an access control unit. The identity authentication unit is used to perform dual authentication of the power safety IoT card of the drone nest using both hardware identification and key, verifying the legitimacy of the terminal; The data decryption unit is used to receive encrypted data and decrypt it using a matching key; the anomaly monitoring unit is used to build a profile of the terminal device, monitor data parameters in real time, and identify abnormal behavior. The access control unit is used to assign exclusive data transmission permissions to different drone nests and restrict the access range; the power intranet drone management platform is deployed on the power intranet and is used to receive inspection data decrypted by the secure access platform for data storage, analysis and display.

2. The secure data transmission system according to claim 1, characterized in that: The power inspection data collected by the drone terminal includes images, videos, and operating parameters of power equipment.

3. The secure data transmission system according to claim 1, characterized in that: The power safety IoT card is also equipped with a primary and backup dual-card redundancy unit, which can achieve automatic switching at the millisecond level to maintain the connection of the encrypted transmission channel when the current communication link is abnormal.

4. The secure data transmission system according to claim 1, characterized in that: The data encryption algorithm of the power safety IoT card is the national cryptographic algorithm SM4.

5. The secure data transmission system according to claim 1, characterized in that: The authentication algorithm of the secure access platform is the national cryptographic SM2 algorithm, and the decryption algorithm is the national cryptographic SM4 algorithm.

6. The secure data transmission system according to claim 1, characterized in that: The anomaly monitoring unit of the secure access platform monitors data parameters including transmission rate, data packet format, data packet integrity, access location, access IP, access frequency, and data traffic.

7. The secure data transmission system according to claim 1, characterized in that: The abnormal behaviors identified by the anomaly monitoring unit of the secure access platform include unauthorized access, data tampering, and access IP not matching the preset area.

8. A method for secure data transmission between a drone's nest and a power grid, characterized in that, The secure data transmission system according to any one of claims 1-7 comprises the following steps: (1) After the UAV terminal completes the power inspection data collection, it uploads the data to the storage unit of the UAV nest through the local communication link; (2) After the control unit of the UAV nest detects that the data storage is completed, it sends a data transmission trigger command to the power safety IoT card; (3) After receiving the command, the power safety IoT card accesses the power dedicated communication network through a dedicated APN, starts the VPN tunnel protocol to build an encrypted transmission channel, and uses a data encryption algorithm to encrypt the inspection data; (4) The encrypted inspection data is transmitted to the security IoT card through the power dedicated communication network. Access platform; (5) The identity authentication unit of the secure access platform extracts the hardware identifier and key of the power safety IoT card, performs dual identity authentication through the identity authentication algorithm, and proceeds to the next step if the authentication is successful, and refuses to receive data and records the abnormal log if the authentication fails; (6) After the identity authentication is successful, the data decryption unit uses the decryption algorithm that matches the data encryption algorithm to decrypt the encrypted data; (7) The abnormal monitoring unit monitors the parameters in the data transmission process in real time. If abnormal behavior is detected, the transmission is immediately interrupted and a warning message is sent to the management and control platform; (8) After the decrypted compliant data is verified by the permission management and control unit, it is securely accessed to the power intranet drone management and control platform.

9. The secure data transmission method according to claim 8, characterized in that: If the current communication link is abnormal in step (3), the primary and backup dual-card redundancy unit configured in the power safety IoT card will automatically switch to the backup card to maintain the connection of the encrypted transmission channel.

10. The secure data transmission method according to claim 8, characterized in that: In step (8), the access control unit only allows decrypted compliant data to access the designated database of the drone management platform, thus restricting the scope of data access.