Data transmission method and device based on longitudinal encryption authentication device and readable medium

By employing a data transmission method based on a vertical encryption authentication device, dynamic identity verification, and dual-channel encrypted transmission tunnels, the security and latency issues in power system data transmission are resolved, achieving efficient and secure data transmission.

CN121967071APending Publication Date: 2026-05-01BEIJING GUOQI NEW ENERGY TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING GUOQI NEW ENERGY TECHNOLOGY CO LTD
Filing Date
2026-03-10
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In the process of power system data transmission, existing technologies have problems such as high encryption overhead, high latency and insufficient data security. In particular, the theft, tampering or forgery of data may cause equipment damage and large-scale power outages.

Method used

A data transmission method based on a vertical encryption authentication device is adopted. The main and secondary data transmission tunnels are generated through dynamic identity verification. The data packet sequence is grouped and identity verification tags are generated. Combined with the vertical encryption authentication device, dual-path independent encrypted transmission is carried out to ensure data security and transmission speed.

Benefits of technology

It improves the security and speed of power system data transmission, reduces latency, prevents data tampering, and ensures the stable operation of power equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121967071A_ABST
    Figure CN121967071A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a data transmission method and device based on a longitudinal encryption authentication device and a readable medium. A specific embodiment of the method comprises the following steps: carrying out dynamic identity confirmation on a target substation; generating a data transmission tunnel and transmission configuration information; carrying out data packet grouping on to-be-transmitted data packets in the to-be-transmitted data packet sequence; generating an identity verification label corresponding to the to-be-transmitted data packet group; according to the data security configuration information and the longitudinal encryption authentication device, performing data encryption on a data load in a to-be-transmitted data packet in the to-be-transmitted data packet sequence and the obtained identity verification tag sequence; and transmitting the encrypted data packet sequence to the target substation through the data master transmission tunnel, and transmitting the encrypted identity verification tag sequence to the target substation through the data slave transmission tunnel. According to the implementation, the data transmission logic is optimized, the data delay is reduced, and the data security of the data related to the power system in the data transmission process is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Data transmission method, apparatus, and readable medium based on vertical encryption authentication device. Technical Field

[0001] The embodiments disclosed herein relate to the fields of power, computer technology, and data security transmission, and specifically to a data transmission method, apparatus, and readable medium based on a longitudinal encryption authentication device. Background Technology

[0002] In the context of data-driven transformation, power system-related data (such as equipment operation data and equipment control data) is vulnerable to theft, tampering, or even forgery during data transmission. This can lead not only to data leaks but also damage to power equipment and even widespread power outages, seriously threatening national energy security and public safety. Furthermore, because power system-related data is often uninterrupted, conventional data transmission methods suffer from high encryption overhead, potentially causing transmission delays. Summary of the Invention

[0003] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0004] Some embodiments of this disclosure propose a data transmission method, apparatus, and readable medium based on a longitudinal encryption authentication device to address the technical problems mentioned in the background section above.

[0005] In a first aspect, some embodiments of this disclosure provide a data transmission method based on a vertical encryption authentication device. The method includes: in response to recognizing a control request for a target substation, dynamically verifying the identity of the target substation; in response to the dynamic identity verification, generating a data transmission tunnel and transmission configuration information, wherein the data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel, and the transmission configuration information includes data security configuration information and tunnel configuration information; grouping data packets in a sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted, wherein the sequence of data packets to be transmitted corresponds to substation control information for the target substation; generating an authentication tag corresponding to each data packet group in the sequence of data packet groups to be transmitted; encrypting the data payload within the data packets to be transmitted in the sequence of data packets to be transmitted, and the obtained authentication tag sequence, according to the data security configuration information and the vertical encryption authentication device, respectively, to obtain an encrypted data packet sequence and an encrypted authentication tag sequence; and transmitting the encrypted data packet sequence to the target substation through the primary data transmission tunnel and the encrypted authentication tag sequence through the secondary data transmission tunnel, according to the tunnel configuration information.

[0006] Secondly, some embodiments of this disclosure provide a data transmission apparatus based on a vertical encryption authentication device. The apparatus includes: a dynamic identity verification unit configured to perform dynamic identity verification on the target substation in response to recognizing a control request for the target substation; a first generation unit configured to generate a data transmission tunnel and transmission configuration information in response to the dynamic identity verification, wherein the data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel, and the transmission configuration information includes data security configuration information and tunnel configuration information; and a data packet grouping unit configured to group the data packets to be transmitted in a sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted, wherein the sequence of data packets to be transmitted corresponds to the target substation. The system includes: a substation control information unit; a second generation unit configured to generate an authentication tag corresponding to each data packet group in the data packet group sequence; a data encryption unit configured to encrypt the data payload within the data packets in the data packet sequence and the obtained authentication tag sequence according to the data security configuration information and the vertical encryption authentication device, respectively, to obtain an encrypted data packet sequence and an encrypted authentication tag sequence; and a transmission unit configured to transmit the encrypted data packet sequence to the target substation through the main data transmission tunnel according to the tunnel configuration information, and to transmit the encrypted authentication tag sequence to the target substation through the data transfer tunnel.

[0007] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.

[0008] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the implementations of the first aspect above.

[0009] The various embodiments of this disclosure have the following beneficial effects: the data transmission method based on a vertical encryption authentication device in some embodiments of this disclosure ensures the data security of power system-related data during data transmission and reduces data latency. Specifically, firstly, in response to the identification of a control request for a target substation, dynamic identity verification is performed on the target substation. This dynamic identity verification verifies the identity of the initiator of the control request, avoiding data security issues caused by identity forgery. Secondly, in response to the dynamic identity verification, a data transmission tunnel and transmission configuration information are generated. The data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel, and the transmission configuration information includes data security configuration information and tunnel configuration information. In practice, to ensure data transmission security, this disclosure uses a dual transmission tunnel approach for data transmission. This improves data transmission security and, more importantly, the parallel dual transmission tunnels further increase data transmission speed. Next, the data packets to be transmitted in the data packet sequence are grouped to obtain a data packet group sequence, where the data packet sequence corresponds to substation control information for the target substation. Furthermore, for each data packet group in the aforementioned sequence of data packets to be transmitted, an authentication tag corresponding to that data packet group is generated. In practice, conventional methods mainly ensure data transmission consistency through CRC (Cyclic Redundancy Check), but there are still cases where verification can be bypassed through collision attacks, brute-force enumeration, etc. Therefore, this disclosure combines the data characteristics corresponding to the power system-related data and dynamically generates authentication tags through the generation of data packets to be transmitted and authentication tags to improve authentication capabilities. In addition, based on the aforementioned data security configuration information and the vertical encryption authentication device, the data payload within the data packets to be transmitted in the aforementioned sequence of data packets to be transmitted, as well as the obtained authentication tag sequence, are encrypted to obtain an encrypted data packet sequence and an encrypted authentication tag sequence. By combining the vertical encryption authentication device and the data security configuration information, dual-path independent encrypted transmission of the data payload and authentication tag is achieved, thereby further improving the information's anti-tampering capability. Finally, based on the aforementioned tunnel configuration information, the encrypted data packet sequence is transmitted to the aforementioned target substation through the aforementioned main data transmission tunnel, and the encrypted authentication tag sequence is transmitted to the aforementioned target substation through the aforementioned data transfer tunnel. Independent parallel data transmission is achieved through dual transmission tunnels, thereby improving data transmission speed and information security during transmission. This approach optimizes data transmission logic, reducing data latency. Simultaneously, it ensures the security of power system-related data during transmission. Attached Figure Description

[0010] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.

[0011] Figure 1 is a flowchart of some embodiments of the data transmission method based on the vertical encryption authentication device according to the present disclosure; Figure 2 is a schematic diagram of the connection relationship between the substation and the dispatch master station; Figure 3 is a schematic diagram of the communication process scenario between the dispatch master station and the target substation; Figure 4 is a schematic diagram of another communication process scenario between the dispatch master station and the target substation; Figure 5 is a structural schematic diagram of some embodiments of the data transmission device based on the vertical encryption authentication device according to the present disclosure; Figure 6 is a structural schematic diagram of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation

[0012] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0013] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0014] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0015] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0016] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0017] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.

[0018] Referring to Figure 1, a flow 100 of some embodiments of the data transmission method based on a vertical encryption authentication device according to the present disclosure is shown. The data transmission method based on a vertical encryption authentication device includes the following steps: Step 101, in response to recognizing a control request for a target substation, performing dynamic identity verification on the target substation.

[0019] In some embodiments, the execution entity (e.g., a computing device) of the data transmission method based on the longitudinal encryption authentication device may perform dynamic identity verification of the target substation in response to the recognition of a control request for the target substation.

[0020] The target substation can be a substation that needs to exchange data with the dispatch master station. The dispatch master station is a control center used for real-time equipment monitoring, data acquisition and analysis, and equipment control of power equipment within a fixed area. A control request is a request directed to the target substation for controlling the power equipment within that substation. For example, a control request may include: control type, control equipment parameters, and target address. The control equipment parameters represent the equipment parameters of the power equipment within the target substation that requires control. The target address is the communication address corresponding to the target substation.

[0021] As an example, a control request could be automatically initiated when the target substation needs to connect to the dispatch master station for the first time. Alternatively, a control request could be automatically initiated after transmission fluctuations occur between the target substation and the dispatch master station, thereby achieving automatic restoration of the transmission tunnel. Yet another example is that a control request could be automatically initiated at preset intervals to regenerate the transmission tunnel, thus improving the security of information transmission.

[0022] As another example, refer to Figure 2, which illustrates the connection between substations and the dispatch master station. Figure 2 shows three substations: A1, A2, and A3. For example, the target substation could be A3. The dispatch master station can communicate with substations A1, A2, and A3. Specifically, the dispatch master station can access systems within the substations such as SCADA (Supervisory Control and Data Acquisition), PAS (Power Application Software), and AVC (Automatic Voltage Control) systems to indirectly monitor the real-time health of the power equipment, collect and analyze data, and control the equipment. Furthermore, in addition to the substations shown in Figure 2, the dispatch master station can also monitor, collect and analyze data, and control the power equipment in power plants and secondary dispatch centers within a fixed area.

[0023] In practice, firstly, the aforementioned executing entity can parse the control request to obtain the target address. Then, it establishes a communication connection with the target address and sends an identity tag retrieval request to the target address. Next, in response to receiving the identity tag response for the identity tag retrieval request, it verifies the identity tag on the response. For example, dynamic identity verification can be achieved by matching the identity tag response with a pre-built identity tag library.

[0024] It should be noted that the aforementioned computing devices can be either hardware or software. When the computing device is hardware, it can be implemented as a distributed cluster consisting of multiple servers or terminal devices, or as a single server or terminal device. When the computing device is software, it can be installed within the hardware devices listed above. It can be implemented as, for example, multiple software programs or software modules used to provide distributed services, or as a single software program or software module. No specific limitations are made here. Specifically, the aforementioned execution entity can be a scheduling master station.

[0025] In some optional implementations of some embodiments, the execution entity performs dynamic identity verification of the target substation, including: step S1: parsing the control request to obtain the target address.

[0026] The target address mentioned above is the communication address corresponding to the target substation.

[0027] In practice, the control request can be parsed according to the request encapsulation format to obtain the target address.

[0028] Step S2: Create a temporary communication tunnel based on the target address mentioned above.

[0029] In practice, since the communication address of the scheduling master station is known, a P2P (Peer-to-Peer) encrypted communication tunnel can be created using the WireGuard protocol, based on the communication address of the scheduling master station and the target address, as a temporary communication tunnel. Specifically, since the temporary communication tunnel is mainly used for obtaining communication tickets and identity information, and is destroyed after acquisition, and the encrypted communication tunnel created based on the WireGuard protocol has extremely fast handshake speed, transmission performance, and kernel-level encryption performance, this disclosure adopts the WireGuard protocol to create temporary communication tunnels.

[0030] Step S2: In response to the successful creation of the temporary communication tunnel, a communication ticket acquisition request is sent to the target address through the temporary communication tunnel.

[0031] Among them, the communication ticket retrieval request is a retrieval request used to obtain a communication ticket from the target substation corresponding to the target address.

[0032] In practice, after the temporary communication tunnel is generated, a key (asymmetric key) is generated for the data transmitted through the temporary communication tunnel. This key is pre-sent to the target substation via the temporary communication tunnel. Therefore, the communication ticket retrieval request is encrypted with the key and transmitted through the temporary communication tunnel to the target substation corresponding to the target address. Upon receiving the encrypted communication ticket retrieval request, the target substation decrypts the request using the key to obtain the communication ticket retrieval request.

[0033] Step S3: In response to receiving the target communication ticket sent by the target substation through the aforementioned temporary communication tunnel, verify the validity of the target communication ticket.

[0034] The target communication ticket represents the creation ticket for a data transmission tunnel already created to connect the target substation and the dispatch master station. Specifically, the target communication ticket may include: a ticket identifier, a tunnel identifier, and a ticket verification identifier. The ticket identifier is a unique identifier for the target communication ticket. The tunnel identifier represents the tunnel identifier of the data transmission tunnel associated with the target communication ticket. The ticket verification identifier represents the verification value corresponding to the target communication ticket.

[0035] In practice, when network fluctuations occur, the data transmission tunnel between the target substation and the dispatch master station may be interrupted due to latency or other issues. Conventional methods for reconnection in such situations involve re-verification and regeneration of the data transmission tunnel. This leads to frequent identity verification and tunnel regeneration during network fluctuations, increasing verification overhead and reducing data transmission efficiency. Therefore, this disclosure addresses this issue by allocating communication tickets. When dynamic identity verification is required, the communication ticket is first acquired and its validity verified. When the (target) communication ticket passes verification, a confirmation result indicating that the target substation has passed dynamic identity verification is directly generated. Subsequently, the connection between the target substation and the dispatch master station is quickly restored through transmission tunnel recovery, thereby reducing verification overhead and improving data transmission efficiency. Specifically, during the communication ticket allocation process, in addition to sending a target communication ticket to the (target) substation, the dispatch master station also retains a copy of the target communication ticket for validity verification.

[0036] As an example, refer to Figure 3, which illustrates a communication process between the dispatch master station and the target substation. The dispatch master station sends a communication ticket retrieval request to the target address via the aforementioned temporary communication tunnel. The target substation sends a target communication ticket to the dispatch master station via the temporary communication tunnel.

[0037] Step S4: In response to the above target communication ticket passing the ticket validity verification, generate a confirmation result indicating that the above target substation has passed dynamic identity verification.

[0038] In some optional implementations of some embodiments, the above-mentioned response to recognizing a control request for a target substation and performing dynamic identity verification of the target substation further includes: step S5: in response to the target communication ticket failing the ticket validity verification, or the target communication ticket not being received after a preset response tolerance period, sending a first identity certificate and identity information acquisition request to the target address through the temporary communication tunnel.

[0039] The aforementioned identity information acquisition request is used to obtain the identity certificate corresponding to the target substation. The preset response tolerance time characterizes the response tolerance time after the communication ticket acquisition request is issued. The first identity certificate is the CA (Certificate Authority) certificate corresponding to the dispatch master station. Specifically, the power equipment within the fixed area corresponding to the dispatch master station, as well as the dispatch master station itself, all have their identity certificates pre-issued through the same CA center.

[0040] In practice, since communication tickets are mainly used for rapid identity verification and rapid regeneration of data transmission tunnels, in order to avoid the potential problem of the target substation not responding to the communication ticket acquisition request for a long time, this disclosure sets a preset response tolerance time to determine whether to wait for the target substation's response to the communication ticket acquisition request.

[0041] In practice, since the first identity certificate and the identity information retrieval request are transmitted through a temporary communication tunnel, they also need to be encrypted using the key corresponding to the temporary communication tunnel before transmission. Upon receiving the encrypted first identity certificate and the encrypted identity retrieval request, the target substation decrypts them using the key to obtain the original first identity certificate and identity retrieval request.

[0042] Specifically, the target substation will verify the first identity certificate (e.g., through a CA center). Once the first identity certificate is verified, it will send a certificate confirmation message and a second identity certificate to the dispatch master station via a temporary communication tunnel. The second identity certificate is the CA certificate corresponding to the target substation.

[0043] Step S6: In response to receiving the second identity certificate sent by the target substation through the temporary communication tunnel, perform certificate verification on the second identity certificate.

[0044] The verification process for the first and second identity certificates is the same, except that the verification of the first identity certificate is initiated by the target substation to the CA center, while the verification of the second identity certificate is initiated by the dispatch master station to the CA center.

[0045] Step S7: In response to the second identity certificate passing the certificate verification and receiving the certificate confirmation information sent by the substation for the first identity certificate through the temporary communication tunnel, generate a confirmation result indicating that the target substation has passed the dynamic identity verification.

[0046] In practice, when the target substation successfully verifies the first identity certificate, it sends the second identity certificate and a certificate confirmation message for the first identity certificate to the dispatch master station through a temporary communication tunnel. When the dispatch master station successfully verifies the second identity certificate and receives the certificate confirmation message for the first identity certificate sent to the target substation, it generates a confirmation result indicating that the target substation has passed the dynamic identity verification. This achieves the purpose of double verification and ensures the robustness of the verification.

[0047] Step S8: In response to the failure of the second identity certificate to pass certificate verification, or the failure to receive the certificate confirmation information sent by the substation for the first identity certificate through the temporary communication tunnel, a confirmation result is generated indicating that the target substation has failed dynamic identity verification.

[0048] As an example, refer to Figure 4, which illustrates another communication scenario between the dispatch master station and the target substation. In this scenario, the dispatch master station sends a first identity certificate and an identity information retrieval request to the target address via the aforementioned temporary communication tunnel. The target substation then sends a second identity certificate and certificate confirmation information for the first identity certificate to the dispatch master station via the temporary communication tunnel.

[0049] Optionally, in response to not receiving the second identity certificate sent by the target substation through the aforementioned temporary communication tunnel, a confirmation result indicating that the target substation has failed dynamic identity verification is generated.

[0050] Step 102: In response to dynamic identity verification, generate data transmission tunnel and transmission configuration information.

[0051] In some embodiments, the aforementioned executing entity may generate a data transmission tunnel and transmission configuration information in response to dynamic identity verification.

[0052] The data transmission tunnel is a stable transmission tunnel used for long-term continuous data transmission between the dispatch master station and the target substation. Transmission configuration information represents the configuration information related to the data transmission tunnel and data transmission encryption during the data transmission process.

[0053] The data transmission tunnels include a primary data transmission tunnel and a secondary data transmission tunnel. The primary data transmission tunnel is used for transmitting encrypted data packet sequences. The secondary data transmission tunnel is used for transmitting encryption-related configuration information and encrypted authentication tag sequences. The transmission configuration information includes data security configuration information and tunnel configuration information. The data security configuration information represents the encryption parameters used by the primary and secondary data transmission tunnels, respectively. Specifically, the data security configuration information may include: the encryption algorithm type of the primary transmission tunnel, the encryption algorithm type of the secondary transmission tunnel, the primary transmission tunnel key, the secondary transmission tunnel key, the validity period of the primary transmission tunnel key, and the validity period of the secondary transmission tunnel key. The encryption algorithm type of the primary transmission tunnel represents the encryption algorithm type used by the primary data transmission tunnel. The primary transmission tunnel key represents the key used by the primary data transmission tunnel. The validity period of the primary transmission tunnel key represents the validity period of the primary transmission tunnel key. The encryption algorithm type of the secondary transmission tunnel represents the encryption algorithm type used by the secondary data transmission tunnel. The secondary transmission tunnel key represents the key used by the secondary data transmission tunnel. The validity period of the secondary transmission tunnel key represents the validity period of the secondary transmission tunnel key.

[0054] In practice, two data transmission tunnels can be created between the target substation and the dispatch master station using the WireGuard protocol, serving as the primary data transmission tunnel and the secondary data transmission tunnel, respectively, to obtain the corresponding tunnel configuration information. Based on the IKE (Internet Key Exchange) key exchange mechanism, the key (primary transmission tunnel key) and encryption algorithm type (primary transmission tunnel encryption algorithm type) corresponding to the primary data transmission tunnel, and the key (secondary transmission tunnel key) and encryption algorithm type (secondary transmission tunnel encryption algorithm type) corresponding to the secondary data transmission tunnel are determined. Furthermore, according to a preset data transmission tunnel key update cycle, the validity period of the primary transmission tunnel key and the secondary transmission tunnel key are set, thus obtaining the data security configuration information.

[0055] In some optional implementations of some embodiments, the execution entity generates a data transmission tunnel and transmission configuration information in response to dynamic identity verification, including: Step S1: In response to the target communication ticket passing the ticket validity verification, the transmission tunnel is restored according to the target communication ticket to obtain the data transmission tunnel and the tunnel configuration information included in the transmission configuration information.

[0056] In practice, when a target communication ticket passes the ticket validity verification, it indicates a disconnected data transmission tunnel exists between the target substation and the dispatch master station. Both the target substation and the dispatch master station store the tunnel configuration information corresponding to the disconnected data transmission tunnel. Therefore, the connection can be directly restored through the transmission tunnel. Specifically, the dispatch master station can send a probe restoration request to the target substation and restore the data transmission tunnel based on the response to the probe restoration request, thereby obtaining the data transmission tunnel and the tunnel configuration information included in the transmission configuration information. This method can quickly restore the connection between the target substation and the dispatch master station, thereby reducing verification overhead and improving data transmission efficiency.

[0057] Step S2: In response to the above target communication ticket failing the ticket validity verification, or if the above target communication ticket is not received after a preset response tolerance period, candidate tunnel configuration information is generated.

[0058] The candidate tunnel configuration information represents the configuration information related to the data transmission tunnel recommended by the scheduling master station. For example, the candidate tunnel configuration information may include: the recommended transmission protocol type and the recommended port number.

[0059] Step S3: Send the candidate tunnel configuration information to the target substation through the temporary communication tunnel.

[0060] In practice, when a target communication ticket fails the validity verification, it indicates that there is no disconnected data transmission tunnel between the dispatch master station and the target substation. Therefore, the dispatch master station sends candidate tunnel configuration information to the target substation through a temporary communication tunnel. The candidate tunnel configuration information still needs to be encrypted and decrypted using the key corresponding to the temporary communication tunnel during transmission.

[0061] Step S4: In response to receiving the first response information sent by the target substation through the temporary communication tunnel regarding the candidate tunnel configuration information, generate a data transmission tunnel and tunnel configuration information including the transmission configuration information, and generate candidate data security configuration information based on the first response information.

[0062] The first response information represents the transmission protocol type and port number selected by the target substation based on the candidate tunnel configuration information (since a primary data transmission tunnel and a secondary data transmission tunnel need to be created, the first response information should include the two sets of transmission protocol types and port numbers selected by the target substation). The candidate data security configuration information represents the configuration information related to data transmission encryption recommended by the dispatch master station. For example, the candidate data security configuration information may include: the recommended encryption algorithm type.

[0063] In practice, firstly, after receiving the initial response information, two communication tunnels are created between the dispatch master station and the target substation based on the selected transmission protocol type and port number. These tunnels serve as the data transmission tunnels, including the primary data transmission tunnel and the secondary data transmission tunnel, thereby obtaining the transmission configuration information. Secondly, the dispatch master station can generate candidate data security configuration information based on the available encryption algorithms.

[0064] Step S5: Send candidate data security configuration information from the transmission tunnel to the target substation via the data included in the above data transmission tunnel.

[0065] In practice, since data is generated from the transmission tunnel, candidate data security configuration information can be sent to the target substation via the transmission tunnel. Simultaneously, the use of the temporary communication tunnel is complete, and therefore the temporary communication tunnel can be deactivated.

[0066] Step S6: In response to receiving the second response information sent by the target substation from the transmission tunnel via the above data, which pertains to the security configuration information of the candidate data, generate the data security configuration information included in the transmission configuration information based on the second response information.

[0067] The second response information is the encryption algorithm type selected by the target substation based on the candidate data security configuration information (since both the main data transmission tunnel and the slave data transmission tunnel have corresponding keys, the second response information should include the two encryption algorithm types selected by the target substation).

[0068] In practice, after the dispatch master station receives the second response information, it negotiates a key with the target substation through the data transmission tunnel based on the encryption algorithm type corresponding to the second response information. This yields the data security configuration information, including the encryption algorithm type of the main transmission tunnel, the encryption algorithm type of the secondary transmission tunnel, the main transmission tunnel key, the secondary transmission tunnel key, the validity period of the main transmission tunnel key, and the validity period of the secondary transmission tunnel key. By transmitting the encryption information and key-related information separately, the data's anti-cracking capability can be improved, thereby further enhancing the security of data transmission.

[0069] Step 103: Group the data packets to be transmitted in the sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted.

[0070] In some embodiments, the aforementioned execution entity may group the data packets to be transmitted in the sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted.

[0071] In this sequence of data packets to be transmitted, each data packet corresponds to an authentication tag. The authentication tag is used by the target substation to verify whether the data packet sequence has been tampered with after receiving it. The sequence of data packets to be transmitted represents the instruction information to be sent from the dispatch master station to the target substation. Specifically, the instruction information can be constructed into data packets according to the transmission protocol to obtain the sequence of data packets to be transmitted.

[0072] In practice, the aforementioned executing entity can use a fixed-length grouping method to segment the sequence of data packets to be transmitted, thereby obtaining a sequence of data packet groups to be transmitted.

[0073] As an example, assuming the segment length is N and the number of data packets to be transmitted in the sequence is M, then the sequence of data packet groups to be transmitted can include K groups of data packets to be transmitted. Here, M, N, and K are all greater than 0. Specifically, when M / N is an integer, K = M / N. When M / N is a decimal, K = the integer part of M / N + 1.

[0074] In some implementations of some embodiments, the execution subject groups the data packets to be transmitted in the sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted, including: Step S1: According to the sequence of data packets to be transmitted, perform the following processing steps: Step S11: Take out the data packet to be transmitted located at the beginning of the sequence from the sequence of data packets to be transmitted as the target data packet to be transmitted.

[0075] In practice, the sequence of data packets to be transmitted is an ordered sequence. Therefore, the first data packet to be transmitted in the sequence from beginning to end can be taken as the target data packet to be transmitted.

[0076] Step S12: Determine the payload type of the data payload in the target data packet to be transmitted.

[0077] Among them, the load type represents the instruction type of the instruction information to which the data load belongs.

[0078] In practice, firstly, the data payload within the target data packet can be parsed according to the transmission protocol corresponding to the target data packet. Then, based on the payload content, the instruction type of the instruction information to which the data payload belongs can be determined, and this is used as the payload type. Specifically, the number and types of instruction information sent from the dispatch master station to the substation can be enumerated, therefore, the corresponding instruction type can be pre-set for each different type of instruction information.

[0079] Step S13: In response to the existence of a target data packet group corresponding to the payload type, and the available position value corresponding to the target data packet group is equal to 1, add the target data packet to be transmitted to the target data packet group to obtain the data packet group to be transmitted.

[0080] The target data packet group is a queue used to temporarily store data packets that have not yet been determined to be part of a data packet group to be transmitted. When a target data packet group is initially generated, corresponding available position values ​​are initialized. These available position values ​​represent the upper limit of the number of data packets to be transmitted within the target data packet group. Target data packet groups correspond to payload types. Therefore, when multiple payload types exist, multiple target data packet groups will exist.

[0081] In practice, when the available position value corresponding to the target data packet group is equal to 1, it means that after the target data packet to be transmitted is added to the target data packet group, the available position value of the target data packet group is 0, so as to reach the upper limit of the data packets to be transmitted in the group. Therefore, the target data packet group after adding the target data packet to be transmitted can be used as the data packet group to be transmitted.

[0082] Step S14: In response to the existence of a target data packet group corresponding to the payload type, and the available position value corresponding to the target data packet group is greater than 1, add the target data packet to be transmitted to the target data packet group to obtain the updated data packet group as the target data packet group, and decrement the available position value corresponding to the updated target data packet group.

[0083] In practice, the available location value can be updated by decrementing the available location value by 1 for the target data packet group.

[0084] Step S15: In response to the absence of a target data packet group corresponding to the payload type, generate a target data packet group and initialize the available location values ​​corresponding to the target data packet group.

[0085] In practice, when the target data packet group is initially generated, the available location values ​​can be randomly selected from a preset list of available location values. For example, the list of available location values ​​could be [5, 10, 15, 20, 25, 30].

[0086] Step S16: In response to the available position value corresponding to the target data packet group being greater than 1, add the target data packet to be transmitted to the target data packet group to obtain the updated data packet group, which serves as the target data packet group, and decrement the available position value corresponding to the updated target data packet group.

[0087] In practice, the available location value can be updated by decrementing the available location value by 1 for the target data packet group.

[0088] Step S17: In response to the fact that the sequence of data packets to be transmitted after removing the target data packet is empty, the above processing steps are terminated; Step S2: In response to the fact that the sequence of data packets to be transmitted after removing the target data packet is not empty, the sequence of data packets to be transmitted after removing the target data packet is used as the sequence of data packets to be transmitted, and the above processing steps are executed again.

[0089] Step 104: For each data packet group in the sequence of data packets to be transmitted, generate an authentication tag corresponding to the data packet group to be transmitted.

[0090] In some embodiments, the execution entity may generate an authentication tag corresponding to each data packet group in the sequence of data packets to be transmitted.

[0091] Among them, the authentication label represents the identity label of the data packet to be transmitted in the group of data packets to be transmitted.

[0092] As an example, the authentication tag may include: the sequence position of the data packet to be transmitted in the data packet sequence within the group of data packets to be transmitted, the payload type, and the tag verification identifier. For example, the tag verification identifier can be obtained by hashing the sequence position (list) and the payload type.

[0093] In some optional implementations of some embodiments, the execution entity generates an authentication tag corresponding to each data packet group in the data packet group sequence to be transmitted, including: Step S1: Determine the packet position of the data packet to be transmitted in the data packet group sequence to be transmitted, and obtain packet position information.

[0094] The packet location information represents the position of each packet in the packet group within the sequence of packets to be transmitted. Since the number of packets in each packet group is greater than one, the packet location information is represented in the form of a location list.

[0095] Step S2: Hash the above packet location information to obtain a hash identifier.

[0096] In practice, the above packet location information can be hashed to obtain a hash identifier.

[0097] Step S3: Generate a payload identifier based on the payload type corresponding to the above-mentioned data packet group to be transmitted.

[0098] In practice, since the payload type corresponds to the instruction information, and the control instructions corresponding to the instruction information can be enumerated, a mapping table containing the payload type and the corresponding payload identifier can be constructed in a predefined manner. Based on this mapping table, the payload type corresponding to the above-mentioned data packet group to be transmitted can be determined, and the payload identifier can be generated.

[0099] Step S4: Generate an authentication tag corresponding to the above-mentioned packet location information, hash identifier, and payload identifier.

[0100] In practice, the aforementioned executing entity can encapsulate the packet location information, hash identifier, and payload identifier to obtain the authentication label corresponding to the data packet group to be transmitted.

[0101] In practice, when the target substation receives the sequence of data packets to be transmitted and the sequence of authentication tags, taking an authentication tag as an example, firstly, the packet location information is hashed using the same hashing method to obtain a new hash identifier. This new hash identifier is then compared with the hash identifier included in the authentication tag. If they do not match, it indicates that there is a tampered data packet in the data packet group corresponding to that authentication tag. If they match, the corresponding data packet in the data packet sequence can be extracted based on the packet location information included in the authentication tag. It is then determined whether the payload type and payload identifier of the extracted data packet match. If they match, the next data packet to be transmitted is extracted; if they do not match, it indicates that there is a tampered data packet in the data packet group corresponding to that authentication tag.

[0102] In practice, firstly, existing technologies typically employ methods such as CRC redundancy check to ensure data transmission consistency, but these methods can still be bypassed through collision attacks and brute-force enumeration. Furthermore, it is difficult to quickly locate the instruction information corresponding to the tampered location. Additionally, the method of independently verifying each data packet requires each packet to carry a verification code, but power system data is often uninterrupted, leading to significant data transmission and verification overhead. Therefore, this disclosure reduces the time complexity of independent verification from O(M) to O(N) by grouping data packets according to load type, where N << M. Simultaneously, by controlling the group length variation of the data packet groups to be transmitted through the randomness of available location values ​​(for example, two groups of data packets with the same load type may contain different numbers of data packets due to different available location values), attackers are prevented from determining grouping patterns through statistical methods, thereby further increasing the resistance to attacks during data transmission. Furthermore, authentication tags can quickly locate the position of the tampered data packet and its corresponding quality information type, thus rapidly assessing the risk of data tampering.

[0103] Step 105: Based on the data security configuration information and the vertical encryption authentication device, encrypt the data payload in the data packet to be transmitted in the data packet sequence to be transmitted, as well as the obtained authentication tag sequence, to obtain the encrypted data packet sequence and the encrypted authentication tag sequence.

[0104] In some embodiments, the aforementioned execution entity may encrypt the data payload within the data packet to be transmitted in the data packet sequence and the obtained authentication tag sequence according to the data security configuration information and the vertical encryption authentication device, respectively, to obtain the encrypted data packet sequence and the encrypted authentication tag sequence.

[0105] The vertical encryption authentication device can be a dedicated network security device installed between the dispatch master station and the target substation. All data sent from the dispatch master station to the target substation must be encrypted using the vertical encryption authentication device corresponding to the dispatch master station. Similarly, all data sent from the target substation to the dispatch master station must also be encrypted using the vertical encryption authentication device corresponding to the target substation.

[0106] In practice, firstly, the data security configuration information includes the encryption algorithm type and key for the primary data transmission tunnel. Since the primary data transmission tunnel is used to transmit data packets within a sequence of data packets to be transmitted, a vertical encryption authentication device can encrypt the data packets within the sequence of data packets to be transmitted based on the primary transmission tunnel encryption algorithm type and key, resulting in an encrypted data packet sequence. Next, the data security configuration information includes the encryption algorithm type and key for the secondary data transmission tunnel. Since the secondary data transmission tunnel is used to transmit authentication tag sequences, a vertical encryption authentication device can encrypt the authentication tag sequences based on the secondary transmission tunnel encryption algorithm type and key, resulting in an encrypted authentication tag sequence.

[0107] In some optional implementations of some embodiments, the execution entity encrypts the data payload in the data packet to be transmitted in the data packet sequence to be transmitted and the obtained authentication tag sequence according to the data security configuration information and the vertical encryption authentication device, respectively, to obtain the encrypted data packet sequence and the encrypted authentication tag sequence, including: Step S1: Parse the data security configuration information to obtain the data packet key and the tag key.

[0108] Specifically, the data packet key corresponds to the primary data transmission tunnel, and the tag key corresponds to the secondary data transmission tunnel. The data packet key is the primary transmission tunnel key, and the tag key is the secondary transmission tunnel key.

[0109] Step S2: Based on the above-mentioned vertical encryption authentication device and tag key, encrypt the authentication tag sequence to obtain the encrypted authentication tag sequence.

[0110] In practice, since the data volume of the authentication tag sequence is smaller than that of the data packet sequence to be transmitted, and the function of the authentication tag sequence is to verify the data packet sequence to be transmitted, the encryption priority of the authentication tag sequence can be lower than that of the data packet sequence to be transmitted. Therefore, the authentication tag sequence can be encrypted by the main control CPU of the vertical encryption authentication device to obtain the encrypted authentication tag sequence.

[0111] Step S3: Decompose the above sequence of data packets to be transmitted into a set of data packet encryption tasks.

[0112] Among them, the data packet encryption task is assigned a task priority.

[0113] In practice, the aforementioned executing entity divides data packets of the same payload type into the same encryption task based on the payload type within the data packets to be transmitted, thereby generating multiple data packet encryption tasks and obtaining a set of data packet encryption tasks. In particular, different task priorities can be mapped according to the payload type. For example, the task priority of the data packet encryption task corresponding to control commands is higher than that of the data packet encryption task corresponding to remote signaling commands. The task priority of the data packet encryption task corresponding to remote signaling commands is higher than that of the data packet encryption task corresponding to telemetry commands.

[0114] Step S4: Generate an encrypted data packet sequence through the following encryption steps: Step S41: Perform hardware data encryption on the data packet encryption task with the first task priority in the data packet encryption task set using the data encryption accelerator included in the above-mentioned vertical encryption authentication device and the above-mentioned data packet key.

[0115] The data encryption accelerator is a vertical encryption authentication device that includes a dedicated encryption chip.

[0116] Step S42: Using the above-mentioned vertical encryption authentication device and the above-mentioned data packet key, perform local zero-copy data encryption on the data packet encryption task in the above-mentioned data packet encryption task set that has the corresponding task priority of the second task priority.

[0117] In practice, local zero-copy data encryption can be performed on the data packet encryption task with the second priority in the data packet encryption task set by means of the above-mentioned vertical encryption authentication device and the above-mentioned data packet key through shared memory mapping.

[0118] Step S43: Using the above-mentioned vertical encryption authentication device and the above-mentioned data packet key, perform batch data encryption on the data packet encryption task in the above-mentioned data packet encryption task set that has the corresponding task priority of the third task priority.

[0119] In practice, the aforementioned executing entity can use the scheduler in the vertical encryption authentication device to divide the data packets in the aforementioned data packet encryption task set, which have a corresponding task priority of third task priority, into multiple encryption batches, and encrypt the data batch by batch.

[0120] In practice, this optimization method has improved the data encryption logic, enabling priority data encryption processing for core data packets and ensuring the overall data encryption efficiency for the sequence of data packets to be transmitted.

[0121] Step 106: Based on the tunnel configuration information, transmit the encrypted data packet sequence to the target substation through the main data transmission tunnel, and transmit the encrypted authentication tag sequence to the target substation through the data transfer tunnel.

[0122] In some embodiments, the aforementioned execution entity may, based on tunnel configuration information, transmit an encrypted data packet sequence to the target substation via the main data transmission tunnel, and transmit an encrypted authentication tag sequence to the target substation via the data transfer tunnel.

[0123] In practice, the tunnel configuration information specifies the transmission protocol type and port number. Therefore, according to the transmission protocol type and port number corresponding to the main data transmission tunnel and the data slave transmission tunnel, the encrypted data packet sequence is transmitted to the target substation through the main data transmission tunnel, and the encrypted authentication tag sequence is transmitted to the target substation through the data slave transmission tunnel.

[0124] The various embodiments of this disclosure have the following beneficial effects: the data transmission method based on a vertical encryption authentication device in some embodiments of this disclosure ensures the data security of power system-related data during data transmission and reduces data latency. Specifically, firstly, in response to the identification of a control request for a target substation, dynamic identity verification is performed on the target substation. This dynamic identity verification verifies the identity of the initiator of the control request, avoiding data security issues caused by identity forgery. Secondly, in response to the dynamic identity verification, a data transmission tunnel and transmission configuration information are generated. The data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel, and the transmission configuration information includes data security configuration information and tunnel configuration information. In practice, to ensure data transmission security, this disclosure uses a dual transmission tunnel approach for data transmission. This improves data transmission security and, more importantly, the parallel dual transmission tunnels further increase data transmission speed. Next, the data packets to be transmitted in the data packet sequence are grouped to obtain a data packet group sequence, where the data packet sequence corresponds to substation control information for the target substation. Furthermore, for each data packet group in the aforementioned sequence of data packets to be transmitted, an authentication tag corresponding to that data packet group is generated. In practice, conventional methods mainly ensure data transmission consistency through CRC (Cyclic Redundancy Check), but there are still cases where verification can be bypassed through collision attacks, brute-force enumeration, etc. Therefore, this disclosure combines the data characteristics corresponding to the power system-related data and dynamically generates authentication tags through the generation of data packets to be transmitted and authentication tags to improve authentication capabilities. In addition, based on the aforementioned data security configuration information and the vertical encryption authentication device, the data payload within the data packets to be transmitted in the aforementioned sequence of data packets to be transmitted, as well as the obtained authentication tag sequence, are encrypted to obtain an encrypted data packet sequence and an encrypted authentication tag sequence. By combining the vertical encryption authentication device and the data security configuration information, dual-path independent encrypted transmission of the data payload and authentication tag is achieved, thereby further improving the information's anti-tampering capability. Finally, based on the aforementioned tunnel configuration information, the encrypted data packet sequence is transmitted to the aforementioned target substation through the aforementioned main data transmission tunnel, and the encrypted authentication tag sequence is transmitted to the aforementioned target substation through the aforementioned data transfer tunnel. Independent parallel data transmission is achieved through dual transmission tunnels, thereby improving data transmission speed and information security during transmission. This approach optimizes data transmission logic, reducing data latency. Simultaneously, it ensures the security of power system-related data during transmission.

[0125] Referring further to Figure 5, as an implementation of the methods shown in the above figures, this disclosure provides some embodiments of a data transmission device based on a vertical encryption authentication device. These device embodiments correspond to the method embodiments shown in Figure 1. The data transmission device based on a vertical encryption authentication device can be specifically applied to various electronic devices.

[0126] As shown in Figure 5, a data transmission device 500 based on a vertical encryption authentication device in some embodiments includes: a dynamic identity verification unit 501, a first generation unit 502, a data packet grouping unit 503, a second generation unit 504, a data encryption unit 505, and a transmission unit 506. The dynamic identity verification unit 501 is configured to perform dynamic identity verification on the target substation in response to recognizing a control request for the target substation. The first generation unit 502 is configured to generate a data transmission tunnel and transmission configuration information in response to dynamic identity verification. The data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel, and the transmission configuration information includes data security configuration information and tunnel configuration information. The data packet grouping unit 503 is configured to group the data packets to be transmitted in the sequence of data packets to be transmitted to obtain the data packets to be transmitted. The sequence of data packets to be transmitted corresponds to substation control information for the target substation. A second generation unit 504 is configured to generate an authentication tag corresponding to each data packet group in the data packet group sequence. A data encryption unit 505 is configured to encrypt the data payload within the data packets to be transmitted in the data packet sequence and the obtained authentication tag sequence according to the data security configuration information and the vertical encryption authentication device, respectively, to obtain an encrypted data packet sequence and an encrypted authentication tag sequence. A transmission unit 506 is configured to transmit the encrypted data packet sequence to the target substation through the main data transmission tunnel according to the tunnel configuration information, and to transmit the encrypted authentication tag sequence to the target substation through the data transfer tunnel.

[0127] It is understood that the units described in the data transmission apparatus 500 based on the vertical encryption authentication device correspond to the various steps in the method described with reference to FIG1. ​​Therefore, the operations, features, and beneficial effects described above for the method also apply to the data transmission apparatus 500 based on the vertical encryption authentication device and the units contained therein, and will not be repeated here.

[0128] Referring now to FIG6, a schematic diagram of the structure of an electronic device (e.g., a computing device) 600 suitable for implementing some embodiments of the present disclosure is shown. The electronic device shown in FIG6 is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of the present disclosure.

[0129] As shown in Figure 6, the electronic device 600 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory 602 or a program loaded from a storage device 608 into a random access memory 603. The random access memory 603 also stores various programs and data required for the operation of the electronic device 600. The processing unit 601, the read-only memory 602, and the random access memory 603 are interconnected via a bus 604. An input / output interface 605 is also connected to the bus 604.

[0130] Typically, the following devices can be connected to the input / output interface 605: input devices 606 including, for example, a touchscreen, touchpad, keyboard, mouse, camera, microphone, accelerometer, gyroscope, etc.; output devices 607 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 608 including, for example, magnetic tape, hard disk, etc.; and communication devices 609. Communication devices 609 allow the electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although FIG. 6 shows an electronic device 600 with various devices, it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed alternatively. Each box shown in FIG. 6 may represent one device, or multiple devices may be represented as needed.

[0131] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a read-only memory 602. When the computer program is executed by the processing device 601, it performs the functions defined above in the methods of some embodiments of this disclosure.

[0132] It should be noted that, in some embodiments of this disclosure, the computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0133] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0134] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: in response to recognizing a control request for a target substation, perform dynamic identity verification of the target substation; in response to dynamic identity verification, generate a data transmission tunnel and transmission configuration information, wherein the data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel, and the transmission configuration information includes data security configuration information and tunnel configuration information; and group the data packets to be transmitted in the sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted, wherein the sequence of data packets to be transmitted corresponds to the target substation. The system generates an authentication tag for each data packet in the sequence of data packets to be transmitted. Based on the data security configuration information and the vertical encryption authentication device, it encrypts the data payload within the data packets to be transmitted and the obtained authentication tag sequence, resulting in an encrypted data packet sequence and an encrypted authentication tag sequence. Based on the tunnel configuration information, it transmits the encrypted data packet sequence to the target substation via the main data transmission tunnel and transmits the encrypted authentication tag sequence to the target substation via the data transfer tunnel.

[0135] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0136] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0137] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0138] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.

Claims

1. A data transmission method based on a vertical encryption authentication device, characterized in that, include: In response to the detection of a control request for the target substation, the target substation is dynamically identified; In response to dynamic identity verification, a data transmission tunnel and transmission configuration information are generated. The data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel. The transmission configuration information includes data security configuration information and tunnel configuration information. Data packets to be transmitted in the sequence of data packets to be transmitted are grouped to obtain a sequence of data packet groups to be transmitted. Each sequence of data packets to be transmitted corresponds to substation control information for the target substation. For each data packet group in the sequence of data packets to be transmitted, an authentication tag is generated. Based on the data security configuration information and the vertical encryption authentication device, the data payload within the data packets to be transmitted in the sequence of data packets to be transmitted, as well as the obtained authentication tag sequence, are encrypted to obtain an encrypted data packet sequence and an encrypted authentication tag sequence. Based on the tunnel configuration information, the encrypted data packet sequence is transmitted to the target substation through the primary data transmission tunnel, and the encrypted authentication tag sequence is transmitted to the target substation through the secondary data transmission tunnel.

2. The data transmission method based on a vertical encryption authentication device according to claim 1, characterized in that, The step of dynamically verifying the identity of the target substation in response to the detection of a control request for the target substation includes: parsing the control request to obtain a target address, wherein the target address is the communication address corresponding to the target substation; creating a temporary communication tunnel based on the target address; sending a communication ticket acquisition request to the target address through the temporary communication tunnel in response to the successful creation of the temporary communication tunnel; verifying the validity of the target communication ticket upon receiving the target communication ticket sent by the target substation through the temporary communication tunnel; and generating a confirmation result indicating that the target substation has passed the dynamic identity verification in response to the target communication ticket passing the validity verification.

3. The data transmission method based on a vertical encryption authentication device according to claim 2, characterized in that, The step of dynamically verifying the identity of the target substation in response to the detection of a control request for the target substation further includes: in response to the target communication ticket failing the ticket validity verification, or the target communication ticket not being received after a preset response tolerance period, sending a first identity certificate and an identity information acquisition request to the target address through the temporary communication tunnel, wherein the identity information acquisition request is used to acquire the identity certificate corresponding to the target substation; in response to receiving a second identity certificate sent by the target substation through the temporary communication tunnel, performing certificate verification on the second identity certificate; in response to the second identity certificate passing the certificate verification, and receiving certificate confirmation information for the first identity certificate sent by the substation through the temporary communication tunnel, generating a confirmation result indicating that the target substation has passed the dynamic identity verification; in response to the second identity certificate failing the certificate verification, or not receiving certificate confirmation information for the first identity certificate sent by the substation through the temporary communication tunnel, generating a confirmation result indicating that the target substation has failed the dynamic identity verification.

4. The data transmission method based on a vertical encryption authentication device according to claim 3, characterized in that, The step of generating a data transmission tunnel and transmission configuration information in response to dynamic identity verification includes: responding to the target communication ticket passing ticket validity verification, restoring the transmission tunnel based on the target communication ticket to obtain the data transmission tunnel and tunnel configuration information included in the transmission configuration information; responding to the target communication ticket failing ticket validity verification, or not receiving the target communication ticket after a preset response tolerance period, generating candidate tunnel configuration information; sending the candidate tunnel configuration information to the target substation through the temporary communication tunnel; responding to receiving a first response message from the target substation regarding the candidate tunnel configuration information through the temporary communication tunnel, generating the data transmission tunnel and tunnel configuration information included in the transmission configuration information, and generating candidate data security configuration information based on the first response message; sending the candidate data security configuration information to the target substation through the data transmission tunnel via the data from the transmission tunnel; responding to receiving a second response message from the target substation regarding the candidate data security configuration information through the data from the transmission tunnel, generating the data security configuration information included in the transmission configuration information based on the second response message.

5. The data transmission method based on a vertical encryption authentication device according to claim 4, characterized in that, The process of grouping the data packets to be transmitted in the sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted includes: performing the following processing steps based on the sequence of data packets to be transmitted: extracting the data packet at the beginning of the sequence as the target data packet to be transmitted; determining the payload type of the data payload within the target data packet to be transmitted; in response to the existence of a target data packet group corresponding to the payload type, and the available position value corresponding to the target data packet group being equal to 1, adding the target data packet to the target data packet group to obtain a data packet group to be transmitted; in response to the existence of a target data packet group corresponding to the payload type, and the available position value corresponding to the target data packet group being greater than 1, adding the target data packet to the target data packet group to obtain an updated data packet group, as... The process involves: generating a target data packet group and decrementing the available position value corresponding to the target data packet group; generating a target data packet group and initializing the available position value corresponding to the target data packet group in response to the absence of a target data packet group corresponding to the payload type; adding the target data packet to be transmitted to the target data packet group in response to the available position value corresponding to the target data packet group being greater than 1, obtaining an updated data packet group as the target data packet group, and decrementing the available position value corresponding to the target data packet group; ending the processing step in response to the sequence of data packets to be transmitted after removing the target data packet being empty; and re-executing the processing step in response to the sequence of data packets to be transmitted after removing the target data packet being non-empty, using the sequence of data packets to be transmitted after removing the target data packet as the sequence of data packets to be transmitted.

6. The data transmission method based on a vertical encryption authentication device according to claim 5, characterized in that, The step of generating an authentication tag corresponding to each data packet group in the sequence of data packets to be transmitted includes: determining the packet position of the data packet to be transmitted in the sequence of data packets to be transmitted to obtain packet position information; performing hash processing on the packet position information to obtain a hash identifier; generating a payload identifier according to the payload type corresponding to the data packet group to be transmitted; and generating an authentication tag corresponding to the data packet group to be transmitted according to the packet position information, the hash identifier, and the payload identifier.

7. The data transmission method based on a vertical encryption authentication device according to claim 6, characterized in that, The step of encrypting the data payload within the data packets to be transmitted in the sequence of data packets to be transmitted, and the obtained authentication tag sequence, according to the data security configuration information and the vertical encryption authentication device, to obtain an encrypted data packet sequence and an encrypted authentication tag sequence, includes: parsing the data security configuration information to obtain a data packet key and a tag key, wherein the data packet key corresponds to the main data transmission tunnel, and the tag key corresponds to the secondary data transmission tunnel; encrypting the authentication tag sequence according to the vertical encryption authentication device and the tag key to obtain an encrypted authentication tag sequence; and decomposing the sequence of data packets to be transmitted into a set of data packet encryption tasks, wherein the data packets... Encryption tasks are assigned task priorities; an encrypted data packet sequence is generated through the following encryption steps: hardware data encryption is performed on the data packet encryption task with the first task priority in the data packet encryption task set using the data encryption accelerator included in the vertical encryption authentication device and the data packet key; local zero-copy data encryption is performed on the data packet encryption task with the second task priority in the data packet encryption task set using the vertical encryption authentication device and the data packet key; batch data encryption is performed on the data packet encryption task with the third task priority in the data packet encryption task set using the vertical encryption authentication device and the data packet key.

8. A data transmission device based on a vertical encryption authentication device, characterized in that, include: The dynamic identity verification unit is configured to perform dynamic identity verification on the target substation in response to the recognition of a control request for the target substation. A first generation unit is configured to generate a data transmission tunnel and transmission configuration information in response to dynamic identity verification, wherein the data transmission tunnel includes a primary data transmission tunnel and a secondary data transmission tunnel, and the transmission configuration information includes data security configuration information and tunnel configuration information; a data packet grouping unit is configured to group the data packets to be transmitted in the sequence of data packets to be transmitted to obtain a sequence of data packet groups to be transmitted, wherein the sequence of data packets to be transmitted corresponds to substation control information for the target substation; a second generation unit is configured to generate an authentication tag corresponding to each data packet group to be transmitted in the sequence of data packet groups to be transmitted; a data encryption unit is configured to encrypt the data payload in the data packets to be transmitted in the sequence of data packets to be transmitted and the obtained authentication tag sequence according to the data security configuration information and the vertical encryption authentication device, respectively, to obtain an encrypted data packet sequence and an encrypted authentication tag sequence; a transmission unit is configured to transmit the encrypted data packet sequence to the target substation through the primary data transmission tunnel and the encrypted authentication tag sequence to the target substation according to the tunnel configuration information.

9. An electronic device, characterized in that, include: One or more processors; A storage device having one or more programs stored thereon; when the one or more programs are executed by the one or more processors, the one or more processors perform the method as described in any one of claims 1 to 7.

10. A computer-readable medium, characterized in that, It stores a computer program thereon, wherein the computer program, when executed by a processor, implements the method as described in any one of claims 1 to 7.