Access control security protection method under vehicle network zero-trust architecture
By collecting power grid dispatch and charging pile power sequences, detecting the feature vectors of electric vehicles and performing aggregation analysis, and using impedance and directionality difference indicators to identify the authenticity of batteries, the problem of fraudulent charging attacks on linear simulation equipment is solved, and a balance between power grid security and normal equipment response is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ECONOMIC TECH RES INST OF STATE GRID HENAN ELECTRIC POWER
- Filing Date
- 2026-02-11
- Publication Date
- 2026-05-05
AI Technical Summary
In existing technologies, identity authentication mechanisms based on digital certificates cannot effectively identify security risks that use linear analog devices to impersonate real batteries for fraudulent claims, leading to risks to power grid operation safety.
By collecting the power sequence of power grid dispatch instructions and the power sequence of charging piles, step change events are detected, feature vectors are extracted, and feature aggregation analysis is performed within a sliding window. The authenticity of the access object is judged by the impedance rise index and the directional difference index, and a hierarchical power control strategy is executed.
It improves the accuracy of distinguishing between real physical systems and ideal linear simulators, effectively blocks simulation attacks, ensures the safety of power grid operation, and allows compliant equipment to respond normally.
Smart Images

Figure CN121984074A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power grid regulation technology, and more specifically to a security protection method for access control under a vehicle-to-grid zero-trust architecture. Background Technology
[0002] In vehicle-to-grid (V2G) systems, electric vehicles participate in the grid's automatic generation control frequency regulation business as distributed energy storage units. Grid operators pay economic compensation based on the vehicle's response capacity and mileage. However, this mechanism has led to the risk of fraudulently obtaining compensation by using low-cost equipment. Some malicious users use linear resistor arrays or algorithm simulators based on power electronic converters to replace real chemical batteries and connect to the grid.
[0003] Since analog devices have no battery cycle life loss and can perfectly forge protocol data at the communication layer, while existing identity authentication mechanisms based on digital certificates can only identify the legitimacy of the communication subject and have difficulty identifying the true attributes of physical entities, relying solely on communication layer identity authentication cannot identify the security risks of using linear analog devices to disguise themselves as real batteries for fraudulent claims. Summary of the Invention
[0004] To address the security vulnerability of existing technologies that rely solely on communication layer authentication, which cannot identify fraudulent attacks using linear analog devices masquerading as real batteries, the present invention aims to provide an access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks. The specific technical solution adopted is as follows: The first aspect of this application provides an access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks, including: The system collects the command power sequence issued by the power grid dispatch and the metered power sequence fed back by the charging pile, and detects step change events in the command power sequence; for each step change event, it extracts a feature vector containing load power, adjustment direction and response lag index. Based on the load power, all feature vectors within the preset sliding window are mapped to preset power segments. Within each power segment, the full feature aggregation features in the amplitude dimension are analyzed based on the load power and response hysteresis index of the feature vectors; the directional grouping aggregation features in the time series dimension are analyzed based on the adjustment direction and response hysteresis index of the feature vectors. Based on the changing trend of the full feature aggregation characteristics of all segments, an impedance rise index is obtained; based on the differences in the directional grouping aggregation characteristics of all segments, a directional difference index is obtained; based on the threshold judgment results of the impedance rise index and the directional difference index, the access characteristic status of the access object is determined. Based on the access characteristic status, a hierarchical power control strategy is executed on the access object.
[0005] Furthermore, the method for detecting the step change event includes: Perform a first-order difference on the command power sequence. When the absolute value of the difference is greater than the preset step trigger threshold, record the step change event.
[0006] Furthermore, the method for obtaining the feature vector includes: For any step change event, the absolute value of the command power at the last moment of the corresponding moment of the step change event is taken as the load power of the step change event. The adjustment direction is determined based on the sign of the difference value corresponding to the step change event; Within a preset analysis window following the initial moment of the step change event, the transmission delay time is calculated using a cross-correlation algorithm, and the metering power sequence is time-aligned based on the transmission delay time. The response energy deviation is obtained by accumulating the error between the aligned command power sequence and the metering power sequence. The ratio of the response energy deviation to the load power corresponding to the step change event is used as the response hysteresis index. The vector composed of the load power, adjustment direction, and response hysteresis index of the step change event is used as the feature vector.
[0007] Furthermore, the step of mapping all feature vectors within a preset sliding window to a preset power segment based on load power includes: The power analysis range is set with the maximum rated power as the upper limit, and the power analysis range is divided into continuous and non-overlapping power segments. Within the preset sliding window, the feature vector is mapped to the corresponding power segment based on the load power value of the feature vector.
[0008] Furthermore, the method for obtaining the aggregated features of the full set of features includes: Within each power segment, the vector composed of the average load power and average response hysteresis index of all feature vectors is used as the full aggregate feature.
[0009] Furthermore, the method for obtaining the directional grouping aggregation feature includes: The feature vectors within each power segment are divided into loading and unloading groups according to the adjustment direction; the average response hysteresis index of the loading group and the average response hysteresis index of the unloading group are calculated to form directional grouped aggregate features.
[0010] Furthermore, the method for obtaining the impedance rise index includes: When the number of power segments with eigenvectors is greater than the preset number of analyses, the variance of the average load power in the full aggregate features of all power segments with eigenvectors is calculated as an indicator of load instability. When the load instability index is less than the preset stability threshold, the impedance rise index is set as the preset minimum index; otherwise, the least squares method is used to perform linear fitting on each power segment with eigenvectors, based on the average load power and average unit response hysteresis index in the full aggregate feature, and the slope of the fitted line is used as the impedance rise index.
[0011] Furthermore, the method for obtaining the directional difference index includes: Power segments that contain both load group data and unload group data are selected as valid power segments. Calculate the difference between the average unit response hysteresis index of the loading group and the average unit response hysteresis index of the unloading group in the directional grouping aggregation feature corresponding to each effective power segment to obtain the directional deviation; use the mean of the directional deviations of all effective power segments as the directional difference index.
[0012] Furthermore, the method for determining the access characteristic state includes: If the impedance rise index is greater than the preset nonlinear threshold, or the directional difference index is greater than the preset asymmetry threshold, then the access characteristic state is recorded as a valid entity state. If, within the preset observation time, the impedance rise index is less than or equal to the preset nonlinear threshold, and the directional difference index is less than or equal to the preset asymmetry threshold, then the access characteristic state is recorded as a simulated attack state; otherwise, the access characteristic state is recorded as a pending state.
[0013] Furthermore, the step of implementing a tiered power control strategy for the access object based on the access characteristic state includes: During the initial access phase, the execution power is limited to the first limit, and the response lag indicator is monitored. When the response lag indicator is stable, the phase is marked as switching to the grayscale phase, and the execution power is relaxed to the second limit. During the grayscale phase, impedance rise indicators and directional difference indicators are accumulated and access characteristic status is determined. When the access characteristic status is a valid entity status, the system switches to the valid phase and removes the execution power limit. When the access characteristic status is determined to be a simulated attack status, an anomaly is marked and an alarm is triggered.
[0014] Secondly, this application provides an access control security protection system under a vehicle-to-everything (V2X) zero-trust architecture, the system comprising: The data extraction module is used to collect the command power sequence issued by the power grid dispatch and the metered power sequence fed back by the charging pile, and to detect step change events in the command power sequence; for each step change event, it extracts a feature vector containing load power, adjustment direction and response lag index. The aggregation feature analysis module is used to map all feature vectors within a preset sliding window to preset power segments based on load power. Within each power segment, it performs full feature aggregation based on the load power and response hysteresis index of the feature vectors in the amplitude dimension; and performs directional grouping aggregation based on the adjustment direction and response hysteresis index of the feature vectors in the time series dimension. The access status analysis module is used to obtain the impedance rise index based on the changing trend of the aggregated full features of all segments; to obtain the directional difference index based on the differences in the aggregated directional grouping features of all segments; and to determine the access characteristic status of the access object based on the threshold judgment results of the impedance rise index and the directional difference index. The analysis and control module is used to execute a hierarchical power control strategy on the access object based on the access characteristic status.
[0015] Thirdly, this application provides a computer device including a memory and a processor. The memory is used to store computer program code, and the processor is used to call and run the computer program code from the memory to perform the method as described in the first aspect of this application or any embodiment of the first aspect.
[0016] Fourthly, this application provides a computer program product comprising computer program code, which, when executed, performs the method as described in the first aspect of this application or any embodiment thereof.
[0017] Fifthly, this application provides a computer-readable storage medium that stores computer program code, which, when executed, performs the method as described in the first aspect of this application or any embodiment thereof.
[0018] The present invention has the following beneficial effects: This invention collects power sequences from power grid dispatch commands and charging pile metering power sequences, combines step event detection with time-series lag alignment analysis, and then utilizes power segmentation mapping to analyze the rise in impedance with power change in the amplitude dimension and the directional difference in loading / unloading paths in the time dimension. It leverages the inherent nonlinearity and asymmetry characteristics of real physical systems that cannot be eliminated by low-cost linear algorithms, improving the accuracy of distinguishing between real physical systems and ideal linear simulators. By implementing a hierarchical power control strategy based on the analyzed access characteristic states, it achieves smooth progression control from detection and grayscale to full power. This approach can accumulate physical characteristic evidence through limited power when data is insufficient and effectively block simulated attacks. By analyzing the inherent inertia and nonlinear response lag of physical systems, this invention distinguishes between real physical systems and ideal linear simulator states. Through a hierarchical power control strategy, it dynamically adjusts power access permissions while gradually accumulating verification data, ensuring the normal response of compliant equipment and the safety of power grid operation. Attached Figure Description
[0019] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a flowchart of an access control security protection method under a zero-trust architecture for vehicle networks, provided in one embodiment of the present invention. Figure 2 This is a structural diagram of an access control security protection system under a zero-trust architecture for vehicle networks, provided in one embodiment of the present invention. Figure 3 This is a schematic diagram of a computer device structure provided in one embodiment of the present invention. Detailed Implementation
[0021] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of an access control security protection method under a zero-trust architecture for vehicle networks proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0022] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0023] The following description, in conjunction with the accompanying drawings, details the specific scheme of the access control security protection method under the zero-trust architecture of the vehicle network provided by this invention.
[0024] This application provides an access control security protection method under a vehicle-to-everything (V2X) zero-trust architecture. Please refer to [link / reference]. Figure 1 The diagram illustrates a flowchart of an access control security protection method under a zero-trust architecture for vehicle networks, according to an embodiment of the present invention. The method includes the following steps: S1: Collect the command power sequence issued by the power grid dispatch and the metered power sequence fed back by the charging pile, and detect step change events in the command power sequence; for each step change event, extract a feature vector containing load power, adjustment direction and response lag index.
[0025] In this embodiment of the invention, the power sequence of instructions issued by the power grid dispatch center represents the power adjustment demand instructions from the power grid to the connected objects, reflecting the desired power target value of the dispatch center. The metering power sequence fed back by the charging pile represents the actual response result of the connected objects to this instruction, reflecting the actual power status. Therefore, two signals are simultaneously collected with a fixed sampling period. In this embodiment of the invention, the fixed sampling period can be 100ms. The specific data collected can be adjusted by the implementer according to the specific implementation scenario, and no limitation is imposed here.
[0026] A step change event is a significant power regulation action by the power grid on the connected object. The response behavior of the connected object under this event, such as the degree of lag and the trend of change, best highlights its inherent physical attributes, such as inertia and impedance characteristics. Compared with the response in the steady power range, it has more analytical and identification value. Therefore, it is necessary to detect such key events from the command power sequence.
[0027] In this embodiment of the invention, the command power sequence is first-order differentiated to quantify the change in command power between adjacent sampling times. By capturing abrupt power fluctuations, minor jitters in the communication link or smooth adjustments in the power grid command are filtered out. When the absolute value of the difference exceeds a preset step trigger threshold, it indicates that the power grid has issued a significant power adjustment command, rather than communication noise or smooth adjustments, and the step change event is recorded. A step change event is a significant adjustment action issued by the power grid to the access object, where the power change amplitude exceeds the stable fluctuation range. Its core characteristic is that it can trigger the dynamic response process of the access object, thereby highlighting its physical attribute differences. The preset step trigger threshold can be set to 0.5 kW; the specific value can be adjusted by the implementer and is not limited here.
[0028] To quantify the physical response characteristics of the access object, core parameters need to be extracted for each step change event. In this embodiment of the invention, for any step change event, the absolute value of the command power at the last moment of the corresponding moment of the step change event is taken as the load power of the step change event, reflecting the intensity of the power adjustment.
[0029] Furthermore, the adjustment direction is determined based on the sign of the difference value corresponding to the step change event. Specifically, when the difference value is positive, it indicates that the commanded power is changing from the current value to a larger value, and the adjustment direction is determined to be the loading direction, meaning the accessed object needs to increase its power output or input, such as increasing charging power or increasing discharging power. When the difference value is negative, it indicates that the commanded power is changing from the current value to a smaller value, and the adjustment direction is determined to be the unloading direction, meaning the accessed object needs to reduce its power output or input, such as decreasing charging power or decreasing discharging power. The adjustment direction is crucial for subsequent analysis of the asymmetry of the physical system in the charging and discharging paths.
[0030] Then, within a preset analysis window following the initial moment of the step change event, the transmission delay time is calculated using a cross-correlation algorithm. Based on this transmission delay time, the metering power sequence is time-aligned. Specifically, the command power subsequence and the metering power subsequence are obtained within the preset analysis window. The cross-correlation coefficient between the two subsequences at different time displacements is calculated using the cross-correlation algorithm. The displacement corresponding to the maximum cross-correlation coefficient is taken as the transmission delay time. The metering power subsequence is then shifted and compensated according to this displacement, ensuring that the response process of the metering power matches the delivery process of the command power on the time axis. By eliminating the interference of random transmission delays in the communication link on the response analysis, it is ensured that the error in subsequent calculations originates only from the physical response characteristics of the access object, rather than network transmission factors, providing a clean data foundation for extracting true physical characteristics. The preset analysis window is a 5-second window after the initial moment; the specific window size can be adjusted by the implementer.
[0031] The response energy deviation is obtained by accumulating the error between the aligned command power sequence and the metered power sequence. Specifically, the absolute value of the power difference between the two sequences is calculated at each sampling point, and all absolute values of the difference within the preset analysis window are accumulated and summed to obtain the response energy deviation. This reflects the total energy difference between the actual power and the command power of the access object during the step response process, and can comprehensively reflect the degree of lag and fluctuation of the response.
[0032] The ratio of the response energy deviation to the load power corresponding to the step change event is used as the response hysteresis index. It is normalized by the step amplitude so that the hysteresis analysis is not affected by the load power adjustment amplitude and can more objectively reflect the inherent physical inertia of the access object.
[0033] Therefore, the vector composed of the load power, adjustment direction and response hysteresis index of the step change event is used as the feature vector. The feature vector represents the key input and core physical inertia of an independent power adjustment event, providing data samples for subsequent statistical analysis.
[0034] S2: Based on the load power, map all feature vectors within the preset sliding window to the preset power segments. Within each power segment, analyze the full feature aggregation of the load power and response hysteresis index based on the feature vectors in the amplitude dimension; analyze the directional grouping aggregation of the time sequence dimension based on the adjustment direction and response hysteresis index based on the feature vectors.
[0035] Since a single feature vector can only reflect the instantaneous response of a device at a specific moment and under a single operating condition, its value is easily affected by random interference, such as power grid voltage fluctuations and sensor noise. Directly using it for access characteristic determination can easily lead to misjudgment. Therefore, further systematic organization and aggregation of feature vectors are needed to transform the scattered and random output feature vectors into ordered and stable statistical features, providing high-quality data for accurate determination of subsequent access characteristic status.
[0036] In this embodiment of the invention, a sliding window is first preset, specifically, the maximum capacity of the sliding window can be set, such as 500 feature vectors, and the sample validity period is set, such as 30 minutes. A first-in-first-out (FIFO) queue mechanism is used to manage the samples for constraints. The purpose of the preset sliding window is to accumulate a certain number of valid feature vectors, and to filter out samples that reflect the recent physical state of the accessed object through time and capacity constraints, avoiding interference from outdated data, such as the response when the battery is low, and ensuring the timeliness and stability of the statistical results.
[0037] Furthermore, the power analysis range is set with the maximum rated power as the upper limit. This range covers all load power ranges that the access object may be involved in when participating in grid frequency regulation services, extending from 0 to the maximum rated power of the equipment. Setting this range aims to define all possible operating conditions and ensure that data analysis covers the entire range from no-load to full power, thereby comprehensively revealing the behavior patterns of the equipment under different load pressures.
[0038] The power analysis range is then divided into continuous and non-overlapping power segments. For example, if the rated power is 50kW, it is divided into 10 segments, each covering a power range of 5kW, such as 0-5kW, 5-10kW, ..., 45-50kW. Within a preset sliding window, the feature vector is mapped to the corresponding power segment based on the load power value of the feature vector. Specifically, for any feature vector within the sliding window, the load power value is extracted. If the load power falls within the power range corresponding to the nth power segment, the feature vector is assigned to the nth preset power segment. If the load power equals the maximum rated power, it is directly assigned to the last power segment. This mapping of feature vectors to power segments is achieved by matching the load power value range. The scattered time-series feature vectors are reorganized into ordered sample clusters according to power levels, eliminating the problem of pattern masking caused by the mixing of data at different power levels. This provides a structured data foundation for subsequent feature aggregation analysis of power-specific scenarios.
[0039] After segmentation, the overall trend of device response lag with load power change is analyzed by the amplitude dimension. In this embodiment of the invention, within each power segment, the vector composed of the average load power and the average response lag index of all feature vectors is used as the full aggregate feature to reflect the average physical response status of the access object within the power segment. The average load power clarifies the core power level of the segment, while the average response lag index integrates the inherent inertial characteristics of all samples under the power.
[0040] On the other hand, by analyzing the response differences of devices in the energy flow direction through time-series analysis, in this embodiment of the invention, the feature vectors within each power segment are divided into loading and unloading groups according to the adjustment direction. Specifically, feature vectors with power increase in the adjustment direction are designated as the loading group, and feature vectors with power decrease in the adjustment direction are designated as the unloading group, ensuring that the two groups of samples correspond to different adjustment paths. The average response hysteresis index of the loading group and the average response hysteresis index of the unloading group are calculated to form a directional grouping aggregation feature, reflecting the inherent response differences of the access object within the power segment under the two adjustment paths of loading and unloading. In real physical devices, due to the influence of cell chemical characteristics, power converter hysteresis effect, etc., the two sets of indicators will have significant differences, while in simulated devices, the two sets of indicators are usually approximately consistent.
[0041] Thus, by combining the full aggregation features of the amplitude dimension with the directional grouping aggregation features of the temporal dimension, the structured statistics and pattern extraction of the feature vectors within the sliding window have been completed.
[0042] S3: Based on the changing trend of the full feature aggregation characteristics of all segments, obtain the impedance rise index; based on the differences in the directional grouping aggregation characteristics of all segments, obtain the directional difference index; based on the threshold judgment results of the impedance rise index and the directional difference index, determine the access characteristic status of the access object.
[0043] Real physical systems (consisting of battery cells, converters, and control circuits) typically exhibit a nonlinear increase in damping under high power, i.e., an increase in impedance. Furthermore, they exhibit path asymmetry during loading and unloading due to hysteresis or control dead zones. In contrast, linear simulators usually exhibit constant impedance and symmetrical response. Quantitative indicators based on these characteristics can be used to determine the physical property status of the connected object, facilitating subsequent control.
[0044] Considering that only by accumulating a sufficient number of samples with dispersed power distribution can the trend of response hysteresis changing with power be accurately captured, and to avoid fitting distortion caused by a small number of segmented or concentrated power data, in this embodiment of the invention, when the number of power segments with eigenvectors is greater than the preset number of analyses, it is considered that there is sufficient data distribution for meaningful trend analysis. The variance of the average load power in the full aggregate features of all power segments with eigenvectors is calculated as a load instability indicator. This indicator is used to determine whether the power distribution of each power segment is sufficiently dispersed. If the distribution is too concentrated, the fitted slope will not be able to truly reflect the nonlinear characteristics of impedance changing with power. The preset number of analyses can be set to 2, and the specific value can be adjusted by the implementer according to the system sensitivity, without limitation.
[0045] Furthermore, when the load instability index is less than the preset stability threshold, it indicates that the data is too concentrated in the power dimension. The impedance rise index is then set as the preset minimum index, signifying that no obvious impedance nonlinearity can be detected at this time. The preset stability threshold can be set to 0.01, and the preset minimum index can be set to 0 according to the system measurement noise floor setting. The specific values can be adjusted by the implementer and are not restricted here.
[0046] Otherwise, when the data has a sufficient distribution along the power dimension, the least squares method is used to segment each power segment with eigenvectors. A linear fit is then performed with the average load power in the aggregated full-data features as the x-axis and the average response hysteresis index as the y-axis. The slope of the fitted line is used as the impedance rise index, quantifying the rate of change of response hysteresis with increasing load power. Due to the nonlinear impedance characteristics of real physical devices, the impedance rise index is typically positive, while that of analog devices is close to zero due to linear impedance. It should be noted that the linear fitting method is a well-known technique in the art and will not be elaborated upon here.
[0047] Considering that only power segments that simultaneously contain data from both the loading and unloading groups can effectively compare the response differences of bidirectional adjustment paths, in order to avoid misjudgment due to asymmetry caused by a single adjustment direction, in this embodiment of the invention, power segments that simultaneously contain data from both the loading and unloading groups are selected as valid power segments. This ensures that subsequent difference calculations are based on complete bidirectional response data under the same power level, and compares the characteristics of different adjustment paths of the access object under the same power scenario.
[0048] The difference between the average unit response hysteresis index of the loading group and the average unit response hysteresis index of the unloading group in the directional grouping aggregation feature corresponding to each effective power segment is calculated to obtain the directional deviation. This deviation characterizes the difference in average response time between the charging and discharging processes at the same power level, reflecting the degree of asymmetry in the bidirectional adjustment of the access object at that power level. Due to inherent factors such as the chemical characteristics of the battery cell and the hysteresis effect of the power converter, the directional deviation of real physical devices is usually non-zero and stable. However, due to the lack of physical path dependence, the directional deviation of simulated devices tends to be close to zero.
[0049] The mean of the directional deviations of all effective power segments is used as the directional difference index, which comprehensively reflects the path asymmetry exhibited by the device at different power levels. The larger the directional difference index, the more significant the overall difference in charging and discharging response, and the more it conforms to the characteristics of a real physical system, such as the influence of hysteresis. If the device is an ideally symmetrical linear simulator, the directional difference index is closer to zero.
[0050] Furthermore, the access characteristic status of the access object is determined by judging the threshold results of the impedance rise index and the directivity difference index. The thresholds are calibrated using standard analog equipment testing, which can accurately distinguish the characteristic boundaries between real physical equipment and analog equipment, ensuring the reliability of the judgment results. In this embodiment of the invention, a standard linear resistive load box is connected to the system, a test process of a preset duration is run, the statistical distribution of the impedance rise index and the directivity difference index is recorded during the test, the mean and standard deviation of the two types of indices are calculated, and then based on 3... The principle is to determine the final threshold to ensure that the threshold can cover the system measurement noise floor in the current environment. This avoids misjudging the weak physical characteristics of real devices as simulated attacks and prevents the ideal characteristics of simulated devices from escaping identification. The specific value can be flexibly adjusted by the implementer according to the power grid environment, equipment type, etc. of the actual deployment scenario, and there are no restrictions here.
[0051] In this embodiment of the invention, if the impedance rise index is greater than the preset nonlinear threshold, or the directional difference index is greater than the preset asymmetry threshold, it indicates that the access object has the impedance nonlinearity or bidirectional adjustment path asymmetry characteristics unique to real physical devices, and does not have the ideal linear and symmetrical response characteristics of low-cost simulation devices. In this case, the access characteristic state is recorded as an effective entity state, representing that the access object is a reliable electrochemical energy storage device that can participate normally in grid frequency regulation services.
[0052] If, within the preset observation time, the impedance rise index is less than or equal to the preset nonlinearity threshold, and the directional difference index is less than or equal to the preset asymmetry threshold, it indicates that the response characteristics of the access object continuously conform to the ideal characteristics of the simulated equipment, lacking the inherent damping and path dependence of the real physical system. In this case, the access characteristic state is recorded as a simulated attack state, representing a fraudulent risk of the access object deceiving the power grid for compensation. The preset observation time can be set to 5 minutes to filter out misjudgments caused by instantaneous operating condition fluctuations, ensuring that the judgment result is based on stable characteristic performance. The specific value can be adjusted by the implementer according to the system response speed requirements and is not limited here.
[0053] Otherwise, if the conditions for determining a valid entity state or simulated attack state are not met, the access characteristic state will be recorded as pending, indicating that the physical attributes of the access object cannot be clearly determined at present, and feature data needs to be accumulated for further verification to avoid misjudgment due to insufficient information.
[0054] Thus, by combining the threshold comparison of the two indicators with the time stability verification, the identification of the physical attributes of the access object was completed, providing a more reliable decision-making basis for the subsequent implementation of differentiated hierarchical power control strategies.
[0055] S4: Based on the access characteristic status, execute a hierarchical power control strategy on the access object.
[0056] By using threshold judgments based on dual-dimensional indicators, three types of access characteristic states of access objects were identified. The core requirement of the vehicle-to-grid zero-trust architecture is to prevent fraudulent attacks by simulated devices to ensure grid security, while avoiding excessive restrictions that prevent compliant devices from accessing normally, all while addressing the cold start deadlock problem of "no data without authorization, and difficulty in verification without data" in zero-trust architectures. Therefore, a differentiated hierarchical power control strategy needs to be implemented based on the access characteristic state: For access objects that have been determined to be valid entities, their physical attributes have been verified as trustworthy, and sufficient power access permissions should be granted to ensure the normal operation of grid frequency regulation services. For access objects determined to be in a simulated attack state, there is a clear risk of fraud, and strict security control measures must be taken to prevent the risk from spreading. For access objects in an undetermined state, current data is insufficient to determine their physical attributes, and verification data needs to be continuously accumulated through limited power authorization to avoid misjudgment or omission.
[0057] In this embodiment of the invention, the initial access is designated as the probing phase. This phase is based on the "initial zero trust" principle, assuming that all new access objects are potential attackers. The execution power is limited to a first limit, and response hysteresis indicators are monitored. Specifically, the first limit is set to be no less than twice a preset step trigger threshold to ensure that the response of the access object within this power range can trigger a valid step event to extract response hysteresis indicators. Simultaneously, it avoids the power grid security risks caused by initial high-power access. For example, the first limit can be set to 10% of the maximum rated power; the specific value can be adjusted by the implementer.
[0058] When the response lag index is stable, it indicates that the access object can generate an observable physical response, which provides a basis for further verification. In a specific embodiment of the present invention, if the response lag index corresponding to three or more consecutive step events falls within a preset reasonable range, that is, there is no significant change or an abnormal zero, it is recorded as switching to the grayscale stage, and the execution power is relaxed to the second limit, wherein the second limit can be set to 50% of the maximum rated power, and the implementer can adjust the specific value himself.
[0059] During the grayscale phase, impedance rise and directional difference indicators are accumulated and used to determine the access characteristic status. Changes in these two indicators are continuously monitored to assess the possibility of abnormal equipment status. When the access characteristic status is a valid entity status, the system switches to the valid phase, removes the execution power limit, and allows the access device to fully respond to the grid's AGC frequency regulation commands within its rated power range, ensuring its full participation in grid frequency regulation services.
[0060] When the access characteristic status is determined to be a simulated attack status, an anomaly is marked and an alarm is issued. In one specific embodiment of the present invention, an anomaly log containing the access object ID, the dual indicator values of the determination time, and the event timestamp is immediately generated, and alarm information is sent to the power grid safety management platform simultaneously. At the same time, the charging pile control system can be linked to restrict the subsequent access permissions of the access object to prevent the spread of fraud risk.
[0061] By using hierarchical control logic that matches the access characteristics and status, it is possible to achieve differentiated management and control of access objects with different risk levels, and to achieve a balance between security protection and system availability, thus realizing closed-loop access control under a zero-trust architecture.
[0062] In summary, this method collects power sequences from power grid dispatch commands and charging pile metering power sequences, combines step event detection with time-series lag alignment analysis, and then utilizes power segmentation mapping to analyze the rise in impedance with power change in the amplitude dimension and the directional difference in loading / unloading paths in the time dimension. It leverages the inherent nonlinearity and asymmetry characteristics of real physical systems that cannot be eliminated by low-cost linear algorithms, improving the accuracy of distinguishing between real physical systems and ideal linear simulators. By implementing a hierarchical power control strategy based on the analyzed access characteristic states, it achieves smooth progression control from detection and grayscale to full power. This approach can accumulate physical characteristic evidence through limited power when data is insufficient and effectively block simulated attacks. This invention distinguishes between real physical systems and ideal linear simulator states by analyzing the inherent inertia and nonlinear response lag of physical systems. Through a hierarchical power control strategy, it dynamically adjusts power access permissions while gradually accumulating verification data, ensuring the normal response of compliant equipment and the safety of power grid operation.
[0063] This application also provides an access control security protection system under a vehicle-to-everything (V2X) zero-trust architecture. Please refer to [link / reference]. Figure 2 The diagram illustrates a structural diagram of an access control security protection system under a zero-trust architecture for vehicle-to-everything (V2X) network, provided by an embodiment of the present invention. The system includes: a data extraction module 201, an aggregation feature analysis module 202, an access status analysis module 203, and an analysis control module 204.
[0064] The data extraction module 201 is used to collect the command power sequence issued by the power grid dispatch and the metered power sequence fed back by the charging pile, and to detect step change events in the command power sequence; for each step change event, it extracts a feature vector containing load power, adjustment direction and response lag index. The aggregation feature analysis module 202 is used to map all feature vectors within a preset sliding window to preset power segments based on load power. Within each power segment, it performs full feature aggregation based on the load power and response hysteresis index of the feature vectors to analyze the amplitude dimension of the feature aggregation feature; and performs directional grouping aggregation based on the adjustment direction and response hysteresis index of the feature vectors to analyze the time-series dimension of the feature aggregation feature. The access status analysis module 203 is used to obtain the impedance rise index based on the changing trend of the full feature aggregation characteristics of all segments; to obtain the directional difference index based on the differences in the directional group aggregation characteristics of all segments; and to determine the access characteristic status of the access object based on the threshold judgment results of the impedance rise index and the directional difference index. The analysis and control module 204 is used to execute a hierarchical power control strategy on the access object based on the access characteristic status.
[0065] It should be noted that the system provided in the above embodiments is only an example of the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the computer device can be divided into different functional modules to complete all or part of the functions described above. In addition, the access control security protection system under the vehicle network zero-trust architecture and the access control security protection method under the vehicle network zero-trust architecture provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0066] This application also provides a computer device; please refer to [link / reference]. Figure 3 The illustration shows a schematic diagram of a computer device structure provided by an embodiment of the present invention. The computer device includes a memory 301, a processor 302, and a computer program 303 stored in the memory 301 and running on the processor 302. When the processor 302 executes the computer program 303, the computer device can execute any of the access control security protection methods under the aforementioned vehicle network zero-trust architecture.
[0067] This application also provides a computer program product that, when run on a computer device, enables the computer device to execute any of the aforementioned access control security protection methods under the vehicle-to-everything (V2X) zero-trust architecture.
[0068] This application also provides a computer-readable storage medium storing computer program code. When the computer program code is run on a computer device, the computer device can execute any of the aforementioned access control security protection methods under the vehicle-to-everything (V2X) zero-trust architecture.
[0069] In the embodiments provided in this application, it should be understood that the computer device, computer program product and computer-readable storage medium provided are all used to perform the corresponding methods provided above, and therefore the beneficial effects they can achieve can be referred to the beneficial effects of the methods provided above, which will not be repeated here.
[0070] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0071] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
Claims
1. A security protection method for access control under a zero-trust architecture for vehicle-to-everything (V2X) networks, characterized in that, The method includes: The system collects the command power sequence issued by the power grid dispatch and the metered power sequence fed back by the charging pile, and detects step change events in the command power sequence; for each step change event, it extracts a feature vector containing load power, adjustment direction and response lag index. Based on the load power, all feature vectors within the preset sliding window are mapped to preset power segments. Within each power segment, the full feature aggregation features in the amplitude dimension are analyzed based on the load power and response hysteresis index of the feature vectors; the directional grouping aggregation features in the time series dimension are analyzed based on the adjustment direction and response hysteresis index of the feature vectors. Based on the changing trend of the full feature aggregation characteristics of all segments, an impedance rise index is obtained; based on the differences in the directional grouping aggregation characteristics of all segments, a directional difference index is obtained; based on the threshold judgment results of the impedance rise index and the directional difference index, the access characteristic status of the access object is determined. Based on the access characteristic status, a hierarchical power control strategy is executed on the access object.
2. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 1, characterized in that, The method for detecting the step change event includes: Perform a first-order difference on the command power sequence. When the absolute value of the difference is greater than the preset step trigger threshold, record the step change event.
3. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 2, characterized in that, The method for obtaining the feature vector includes: For any step change event, the absolute value of the command power at the last moment of the corresponding moment of the step change event is taken as the load power of the step change event. The adjustment direction is determined based on the sign of the difference value corresponding to the step change event; Within a preset analysis window following the initial moment of the step change event, the transmission delay time is calculated using a cross-correlation algorithm, and the metering power sequence is time-aligned based on the transmission delay time. The response energy deviation is obtained by accumulating the error between the aligned command power sequence and the metering power sequence. The ratio of the response energy deviation to the load power corresponding to the step change event is used as the response hysteresis index. The vector composed of the load power, adjustment direction, and response hysteresis index of the step change event is used as the feature vector.
4. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 1, characterized in that, The step of mapping all feature vectors within a preset sliding window to a preset power segment based on load power includes: The power analysis range is set with the maximum rated power as the upper limit, and the power analysis range is divided into continuous and non-overlapping power segments. Within the preset sliding window, the feature vector is mapped to the corresponding power segment based on the load power value of the feature vector.
5. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 1, characterized in that, The method for obtaining the aggregated features of the full feature set includes: Within each power segment, the vector composed of the average load power and average response hysteresis index of all feature vectors is used as the full aggregate feature.
6. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 1, characterized in that, The method for obtaining the directional grouping aggregation feature includes: The feature vectors within each power segment are divided into loading and unloading groups according to the adjustment direction; the average response hysteresis index of the loading group and the average response hysteresis index of the unloading group are calculated to form directional grouped aggregate features.
7. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 1, characterized in that, The method for obtaining the impedance rise index includes: When the number of power segments with eigenvectors is greater than the preset number of analyses, the variance of the average load power in the full aggregate features of all power segments with eigenvectors is calculated as an indicator of load instability. When the load instability index is less than the preset stability threshold, the impedance rise index is set as the preset minimum index; otherwise, the least squares method is used to perform linear fitting on each power segment with eigenvectors, based on the average load power and average unit response hysteresis index in the full aggregate feature, and the slope of the fitted line is used as the impedance rise index.
8. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 1, characterized in that, The method for obtaining the directional difference index includes: Power segments that contain both load group data and unload group data are selected as valid power segments. Calculate the difference between the average unit response hysteresis index of the loading group and the average unit response hysteresis index of the unloading group in the directional grouping aggregation feature corresponding to each effective power segment to obtain the directional deviation; use the mean of the directional deviations of all effective power segments as the directional difference index.
9. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) networks according to claim 1, characterized in that, The method for determining the access characteristic status includes: If the impedance rise index is greater than the preset nonlinear threshold, or the directional difference index is greater than the preset asymmetry threshold, then the access characteristic state is recorded as a valid entity state. If, within the preset observation time, the impedance rise index is less than or equal to the preset nonlinear threshold, and the directional difference index is less than or equal to the preset asymmetry threshold, then the access characteristic state is recorded as a simulated attack state; otherwise, the access characteristic state is recorded as a pending state.
10. The access control security protection method under a zero-trust architecture for vehicle-to-everything (V2X) network according to claim 9, characterized in that, The step of implementing a tiered power control strategy for the access object based on the access characteristic state includes: During the initial access phase, the execution power is limited to the first limit, and the response lag indicator is monitored. When the response lag indicator is stable, the phase is marked as switching to the grayscale phase, and the execution power is relaxed to the second limit. During the grayscale phase, impedance rise indicators and directional difference indicators are accumulated and access characteristic status is determined. When the access characteristic status is a valid entity status, the system switches to the valid phase and removes the execution power limit. When the access characteristic status is determined to be a simulated attack status, an anomaly is marked and an alarm is triggered.