Thermal power plant digital safety protection method and digital twin safety body thereof

By constructing a hybrid twin model and virtual network for thermal power plants, identifying and verifying simulated attacks, and making intelligent decisions, the high-risk and fragmented defense issues of thermal power plant security are resolved, achieving proactive and intelligent security protection.

CN122027338APending Publication Date: 2026-05-12HUANENG POWER INT INC +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-03-24
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing security measures for thermal power plants are insufficient to cope with complex cyber threats, experimental security testing is high-risk and high-cost, and traditional defense methods are inadequate to meet the requirements.

Method used

By constructing a hybrid twin model of key equipment in thermal power plants, real-time operating conditions and key variable prediction results are generated. A virtual industrial control network consistent with the real network is established, simulated attack behaviors are injected for identification and verification, multi-source data is integrated for risk assessment and intelligent decision-making, and the optimal protection and scheduling scheme is generated.

Benefits of technology

It has enabled a shift from post-event response to pre-event early warning, built a risk-free network testbed, improved the initiative and intelligence of defense, broken the isolation and lag limitations of traditional security measures, and formed an integrated intelligent protection closed loop.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122027338A_ABST
    Figure CN122027338A_ABST
Patent Text Reader

Abstract

The invention discloses a thermal power plant digital safety protection method and a digital twinborn safety body thereof, and belongs to the technical field of information safety, the method comprises the following steps: generating a mixed twinborn model of equipment according to real-time operation data and carrying out calibration to obtain a real-time operation condition and a key variable prediction result; acquiring communication data of a real industrial control network of the thermal power plant, analyzing an industrial protocol behavior, establishing a virtual industrial control network according to the communication data and the industrial protocol behavior, and performing simulation to obtain network operation state data; injecting a simulated attack behavior into the virtual industrial control network, and identifying and verifying the simulated attack behavior to obtain security confrontation scene data; and after fusing the real-time operation condition, the key variable prediction result, the network operation state data and the security confrontation scene data, carrying out risk assessment and intelligent decision to obtain an optimal protection scheduling scheme. The safety defects of an existing thermal power plant can be overcome, and the safety protection capacity is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, specifically relating to a digital security protection method for thermal power plants and its digital twin security system. Background Technology

[0002] As a crucial component of the energy system, thermal power plants heavily rely on automated control systems and industrial networks for their production processes. With the advancement of "smart power plants" and "digital power plants," thermal power plants not only need to ensure the stable operation of their units but also face complex cybersecurity threats, such as malicious intrusions, data tampering, and ransomware attacks. In this context, relying solely on traditional cybersecurity defense methods (firewalls, IDS, antivirus software, etc.) is insufficient. Furthermore, the complex operating environment of thermal power plant equipment often makes experimental security testing high-risk and high-cost. Digital twin security systems, through digital twin technology, can virtualize and simulate physical operations, network communications, and security attacks and defenses, enabling prediction, defense, and decision-making within a safe and controllable environment. Summary of the Invention

[0003] The purpose of this invention is to provide a digital safety protection method for thermal power plants and its digital twin safety body, so as to solve the existing safety defects of thermal power plants and improve safety protection capabilities.

[0004] To achieve the above objectives, the present invention adopts the following technical solution: Firstly, a digital safety protection method for thermal power plants includes the following steps: Real-time operating data of key equipment in thermal power plants are collected, and a hybrid twin model of the equipment is generated and calibrated based on the real-time operating data to obtain real-time operating conditions and prediction results of key variables. The communication data of the real industrial control network of a thermal power plant is acquired and the industrial protocol behavior is analyzed. A virtual industrial control network is established based on the communication data and industrial protocol behavior, and the network operation status data is obtained through simulation. Simulated attack behaviors are injected into the virtual industrial control network, and the simulated attack behaviors are identified and verified to obtain security confrontation scenario data. By integrating the real-time operating conditions, key variable prediction results, network operating status data, and security confrontation scenario data, risk assessment and intelligent decision-making are performed to obtain the optimal protection and scheduling scheme.

[0005] In some implementations, generating a hybrid twin model of the device based on the real-time operational data specifically includes: Based on the real-time operating data, a hybrid twin model of the device is constructed by combining the mechanism model and the data-driven model. The mechanism model is built using Simulink, and the data-driven model uses an LSTM network.

[0006] In some implementations, the parsing of industrial protocol behavior includes parsing at least one industrial protocol among IEC 60870-5-104, Modbus, PROFINET, and EtherNet / IP; The virtual industrial control network is divided into online mirror mode and offline sandbox mode.

[0007] In some implementations, injecting simulated attack behaviors into the virtual industrial control network includes: Attack scenarios are constructed based on threat modeling methods, and simulated attack behaviors are injected into the virtual industrial control network through traffic replay or attack scripts. The threat modeling method employs at least one of the following: ATT&CK framework, attack tree, or Petri net.

[0008] In some implementations, the identification and verification of the simulated attack behavior specifically includes: The simulated attack behavior is subjected to feature rule detection, abnormal behavior detection, and intrusion detection.

[0009] In some implementations, the risk assessment employs a Bayesian network or reinforcement learning model, and the intelligent decision-making employs a deep reinforcement learning model or a graph neural network model.

[0010] Secondly, a digital twin security entity includes: The physical twin layer is used to collect real-time operating data of key equipment in thermal power plants, generate hybrid twin models of the equipment based on the real-time operating data, and perform calibration to obtain real-time operating conditions and prediction results of key variables. The network twin layer is used to acquire communication data from the real industrial control network of a thermal power plant and parse industrial protocol behavior. Based on the communication data and industrial protocol behavior, a virtual industrial control network is established, and network operation status data is simulated. A security twin layer is used to inject simulated attack behaviors into the virtual industrial control network, identify and verify the simulated attack behaviors, and obtain security confrontation scenario data. The intelligent decision-making layer is used to perform risk assessment and intelligent decision-making after integrating the real-time operating conditions, key variable prediction results, network operating status data and security confrontation scenario data, so as to obtain the optimal protection scheduling scheme.

[0011] Thirdly, an electronic device includes a memory, a processor, and a computer program stored in the memory and executable in the processor, wherein the processor executes the computer program to implement the steps of the digital security protection method for thermal power plants.

[0012] Fourthly, a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the digital security protection method for a thermal power plant.

[0013] Fifthly, a computer program product comprising a computer program, characterized in that, when executed by a processor, the computer program implements the steps of the digital security protection method for thermal power plants.

[0014] Compared with the prior art, the present invention has the following beneficial effects: This invention provides a digital security protection method for thermal power plants. By collecting real-time operational data to construct and calibrate a hybrid twin model, it achieves real-time reproduction and advanced prediction of the operating conditions of key equipment, shifting security protection from post-event response to pre-event early warning. By establishing a virtual industrial control network consistent with the real network and performing high-fidelity simulation, a risk-free network test field is constructed, overcoming the shortcomings of traditional testing that cannot penetrate the real production environment. By actively injecting simulated attack behaviors into the virtual network and identifying and verifying them, closed-loop testing and continuous strengthening of protection capabilities are achieved, improving the level of proactive defense against unknown threats. Finally, by integrating physical, network, and security multi-source data and performing cross-domain risk assessment and intelligent decision-making, a collaboratively optimized protection scheduling scheme is generated, breaking the limitations of isolated and lagging traditional security measures and forming an integrated intelligent protection closed loop. This systematically solves the problems of high testing risk, fragmented defense, and reliance on manual decision-making in existing thermal power plant security systems, significantly improving the overall, proactive, and intelligent level of security protection. Attached Figure Description

[0015] Figure 1 A detailed flowchart of a digital security protection method for thermal power plants provided in an embodiment of the present invention; Figure 2 A data processing flowchart of a digital security protection method for thermal power plants provided in an embodiment of the present invention; Figure 3 This is a structural diagram of a digital twin provided in an embodiment of the present invention. Detailed Implementation

[0016] To enable those skilled in the art to better understand the present invention, the technical solution of the present invention will be further described in detail below with reference to the accompanying drawings. The content described herein is for explanation rather than limitation of the present invention.

[0017] It should be noted that the terms "comprising" and "having" and any variations thereof in the specification and claims of this invention are intended to cover a non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such processes, methods, systems, products, or devices.

[0018] like Figure 1 and Figure 2 As shown, this embodiment provides a digital security protection method for thermal power plants, including the following steps: S1. Construct a physical twin layer, collect real-time operating data of key equipment in the thermal power plant, generate a hybrid twin model of the equipment based on the real-time operating data and perform calibration, and obtain real-time operating conditions and key variable prediction results. Specifically, by deploying sensors on key equipment in thermal power plants, including boilers, steam turbines, and generator sets, real-time operating data such as temperature, pressure, flow rate, and vibration are collected. Combined with historical operating curves and thermodynamic models, digital models of the physical equipment are constructed. The models are then continuously calibrated through real-time data to achieve virtual reproduction and prediction of unit operating conditions. In the physical twin layer of a thermal power plant, data from field measurement points such as pressure, temperature, flow rate, vibration, and rotational speed are first collected in real time using industrial protocols such as OPC, Modbus, and PROFINET, as well as a plant-level time-series database. Millisecond-level clock synchronization and data buffering are achieved through an edge gateway. Subsequently, a hybrid twin system is constructed, with a mechanistic model (such as Simulink) as the core and combined with a data-driven model (LSTM, etc.), and 3D visualization is achieved through a Unity biomimetic interface. In terms of operation modes, there are online mirror mode (tracking real-time operating conditions) and offline sandbox mode (scenario simulation). Parameter identification and model calibration are performed using historical operating condition data, and an automatic recalibration mechanism is set to control latency and accuracy. Finally, key variables such as steam drum water level, main steam pressure, and generator terminal voltage can be predicted within a 5-second time window, and the accuracy and high fidelity of the twin model are verified by comparing it with DCS trend and abnormal operating condition playback.

[0019] A hybrid twin model is constructed based on collected real-time operational data and historical operating condition data. This model is built by combining a mechanistic model and a data-driven model. The mechanistic model is built in the Simulink environment based on thermodynamics and fluid mechanics principles; the data-driven model can employ time-series prediction models such as Long Short-Term Memory (LSTM) networks. Historical data is used to identify and continuously calibrate model parameters, and an automatic recalibration mechanism is set up to control model latency and prediction accuracy.

[0020] This layer ultimately outputs a virtual reproduction of the real-time operating conditions and can predict key variables such as drum water level, main steam pressure, and generator terminal voltage within a set time window, such as 5 seconds. By comparing the results with historical trends and abnormal operating condition playback of the distributed control system (DCS), the accuracy and high fidelity of the twin model can be verified.

[0021] S2, construct a network twin layer, acquire communication data of the real industrial control network of the thermal power plant and parse industrial protocol behavior, establish a virtual industrial control network based on the communication data and industrial protocol behavior, and simulate network operation status data. Specifically, a virtual network consistent with the actual network topology is established in the industrial control network, covering nodes such as DCS, PLC, and monitoring host. Simulation tools are used to model protocols such as IEC 60870-5-104 and Modbus to simulate data flow, link load and latency characteristics. By comparing with real network traffic, a high-fidelity network operation twin environment is formed.

[0022] In the implementation of the network twin layer in thermal power plants, the first step is to collect communication data based on the actual topology of on-site DCS, PLC, monitoring host, engineering workstation, and other equipment using packet capture, traffic mirroring, or port mirroring of industrial switches. Network behavior is then parsed and reconstructed using protocols such as IEC60870-5-104, Modbus, PROFINET, and EtherNet / IP. Next, a virtual network topology consistent with the on-site network is constructed in a virtual environment (such as OPNET or NS-3), and network parameters such as latency, packet loss, and bandwidth usage are introduced for simulation. Simultaneously, combining historical traffic with real-time collected data, high-fidelity traffic reproduction in the virtual network is achieved using traffic replay, feature replay, and traffic modeling (such as traffic generation models based on GAN and LSTM). In terms of deployment, the network twin layer supports both online mirroring mode (synchronizing with the real network operation status for real-time monitoring and alarms) and offline sandbox mode (for new strategy testing and attack simulation). The consistency between the virtual and real networks is verified through traffic consistency checks, latency comparisons, and anomaly detection result comparisons, thus providing a reliable network foundation for the upper-layer security twin.

[0023] Based on the actual network topology of equipment such as DCS (Distributed Control System), PLC (Programmable Logic Controller), monitoring host, and engineering workstations in a thermal power plant, network communication data is collected using methods such as port mirroring and packet capture. The collected communication data undergoes industrial protocol behavior analysis, including deep packet analysis of at least one of the following industrial protocols: IEC 60870-5-104, Modbus, PROFINET, and EtherNet / IP, to reconstruct the communication behavior and interaction logic of network nodes.

[0024] In network simulation environments such as OPNET and NS-3, a virtual industrial control network with the same topology as the real network is constructed. Network parameters such as latency, packet loss, and bandwidth occupancy are introduced into the simulation, and high-fidelity traffic reproduction in the virtual network is achieved by using traffic replay, feature replay, or traffic generation models based on generative adversarial networks (GANs) and LSTM, thereby simulating network operating status data.

[0025] The virtual industrial control network supports online mirroring mode and offline sandbox mode. Online mirroring mode is used to synchronize the real-time operating status of the actual network, supporting real-time monitoring and anomaly alarms; offline sandbox mode provides a test space isolated from the production environment for testing new network policies or subsequent security attack simulations, thereby verifying network configurations and policies in a risk-free environment.

[0026] S3. Construct a security twin layer, inject simulated attack behaviors into the virtual industrial control network, identify and verify the simulated attack behaviors, and obtain security confrontation scenario data. Specifically, attack modeling and threat simulation are introduced into the network twin environment, such as replay attacks, denial-of-service attacks, and malicious command injection. Multi-source attack scenario data is generated through traffic replay, attack scripts, and red team / blue team adversarial tests. This data is then verified by combining intrusion detection, anomaly detection, and behavioral analysis models, thereby constructing a virtual mapping of security countermeasures and protection effects.

[0027] In the security twin layer of a thermal power plant, data such as protocol traffic, host logs, and control commands from the real network twin environment are first integrated into the security simulation platform. Typical attack scenarios, including replay attacks, denial-of-service attacks, malicious command injection, and Trojan implantation, are then constructed using threat modeling methods (such as ATT&CK, attack trees, and Petri nets). Subsequently, attack injection is implemented in the twin environment using traffic replay tools, attack scripts, and red team / blue team exercises, generating multi-source attack samples. For detection mechanisms, a multi-layered detection and defense system is formed by combining feature-based rules (Snort / Suricata), abnormal behavior detection (One-Class SVM, temporal prediction residual method), and deep learning IDS models. Simultaneously, an online simulation mode (real-time threat monitoring and comparison with the real system) and an offline simulation mode (testing new attacks and defense strategies) are set up. The effectiveness of the security twin is verified through detection rate, false alarm rate, and attack scenario reproducibility, thereby achieving virtual rehearsal and verification of potential attacks.

[0028] First, attack scenarios are constructed based on threat modeling methods. These methods can employ at least one of the following: the ATT&CK framework, attack tree, or Petri net, to define typical attack chains such as replay attacks, denial-of-service (DoS) attacks, malicious command injection, and Trojan implantation. Then, in the virtual industrial control network, attack behaviors are simulated through traffic replay or attack script injection to generate multi-source attack sample data.

[0029] A multi-layered detection system is used to identify and verify injected simulated attack behaviors. This system integrates the following detection methods: First, feature rule detection, such as using tools like Snort or Suricata to match known attack features; second, abnormal behavior detection, such as using One-Class SVM or methods based on temporal prediction residuals to identify behaviors deviating from the normal baseline; third, intrusion detection, employing a deep learning-based Intrusion Detection System (IDS) model to learn from traffic and identify complex or variant attack patterns. The effectiveness of the security protection mechanism is verified by calculating metrics such as detection rate and false positive rate. Finally, security adversarial scenario data is output, including attack characteristics, injection process, and detection results.

[0030] S4. Construct an intelligent decision-making layer, which integrates the real-time operating conditions, key variable prediction results, network operating status data, and security confrontation scenario data to conduct risk assessment and intelligent decision-making, and obtain the optimal protection scheduling scheme.

[0031] Specifically, based on the data fusion of physical, network and security twin layers, a risk assessment engine and AI-assisted decision-making model are established to predict and trace abnormal operating conditions and network attacks, and provide scheduling strategies, forming a closed loop of "detection, assessment, response and verification" to achieve safe and intelligent operation of thermal power plants.

[0032] In the intelligent decision-making layer, data from physical twins, network twins, and security twins are first integrated to construct a unified data lake and knowledge graph, linking equipment operating conditions, network status, and security events in a model. Based on this, a risk assessment engine (based on Bayesian networks or reinforcement learning) is introduced to perform probabilistic risk assessment and impact analysis of equipment failures and network attacks. Then, artificial intelligence decision-making models (such as DRL reinforcement learning and graph neural networks) are used to generate optimal protection and scheduling strategies, including unit load reduction, network isolation, switching to backup control channels, automatic alarms, and emergency responses. Simultaneously, the decision results are pushed to operators through a visual interface and a SCADA mimicry platform, and virtual verification is performed in the twin environment, forming a closed loop of detection, assessment, response, and verification. Ultimately, this achieves intelligent, proactive, and adaptive safe operation of the thermal power plant.

[0033] Construct a unified data lake or knowledge graph, integrating real-time operational status and key variable prediction results from the physical twin layer, network operational status data from the network twin layer, and security confrontation scenario data from the security twin layer. Based on this, conduct cross-domain risk assessments. These risk assessments can employ Bayesian networks for probabilistic reasoning or use reinforcement learning models to learn a risk value function through interaction with the environment.

[0034] Based on the risk assessment results, an optimal protection and scheduling scheme is generated using an artificial intelligence decision-making model. This intelligent decision-making can employ a deep reinforcement learning (DRL) model to continuously optimize the decision strategy through trial and error in a virtual environment; or a graph neural network model to reason about the correlation graph formed by devices, network nodes, and security events. The generated strategies include, but are not limited to, specific coordinated scheduling measures such as unit load reduction commands, network isolation commands, and commands to switch to backup control channels.

[0035] The generated protection and scheduling scheme is not directly applied to the real system, but is first simulated and verified in a sandbox environment composed of the virtual industrial control network. By simulating the execution of the strategy and observing the feedback from devices, networks, and security status in the virtual environment, the effectiveness and security of the strategy are verified. Based on the verification results, directly executable control commands or parameters for optimizing the strategy are output, thus forming a complete closed loop for security protection. This significantly reduces the risk of implementing unverified strategies in the real system, achieving proactive and intelligent security protection.

[0036] like Figure 3 As shown, this embodiment provides a digital twin, including: The physical twin layer is used to collect real-time operating data of key equipment in thermal power plants, generate hybrid twin models of the equipment based on the real-time operating data, and perform calibration to obtain real-time operating conditions and prediction results of key variables. The network twin layer is used to acquire communication data from the real industrial control network of a thermal power plant and parse industrial protocol behavior. Based on the communication data and industrial protocol behavior, a virtual industrial control network is established, and network operation status data is simulated. A security twin layer is used to inject simulated attack behaviors into the virtual industrial control network, identify and verify the simulated attack behaviors, and obtain security confrontation scenario data. The intelligent decision-making layer is used to perform risk assessment and intelligent decision-making after integrating the real-time operating conditions, key variable prediction results, network operating status data and security confrontation scenario data, so as to obtain the optimal protection scheduling scheme.

[0037] The module division in this embodiment of the invention is illustrative and represents only one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional modules in the various embodiments of the invention can be integrated into a single processor, exist as separate physical entities, or be integrated into a single module. The integrated modules described above can be implemented in hardware or as software functional modules.

[0038] This embodiment also provides a computer device, which includes a processor and a memory. The memory is used to store a computer program (in this embodiment, the computer program includes a computing component and an iterative component, capable of model calculation and model updating). The computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in the computer storage medium to realize the corresponding method flow or corresponding function. The processor described in this embodiment can be used in the operation of a digital security protection method for thermal power plants.

[0039] This embodiment also provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device used to store programs and data. It is understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and extended storage media supported by the computer device. The computer-readable storage medium provides storage space that stores the terminal's operating system. Furthermore, this storage space also stores one or more instructions suitable for loading and execution by a processor. These instructions can be one or more computer programs (including program code). It should be noted that the computer-readable storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the digital security protection method for thermal power plants in the above embodiment.

[0040] This embodiment also provides a computer program product, which includes a computer program that, when executed by a processor, implements the corresponding steps of a digital security protection method for thermal power plants described in the above embodiment.

[0041] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0042] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0043] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0044] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0045] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A digital safety protection method for thermal power plants, characterized in that, Includes the following steps: Real-time operating data of key equipment in thermal power plants are collected, and a hybrid twin model of the equipment is generated and calibrated based on the real-time operating data to obtain real-time operating conditions and prediction results of key variables. The communication data of the real industrial control network of a thermal power plant is acquired and the industrial protocol behavior is analyzed. A virtual industrial control network is established based on the communication data and industrial protocol behavior, and the network operation status data is obtained through simulation. Simulated attack behaviors are injected into the virtual industrial control network, and the simulated attack behaviors are identified and verified to obtain security confrontation scenario data. By integrating the real-time operating conditions, key variable prediction results, network operating status data, and security confrontation scenario data, risk assessment and intelligent decision-making are performed to obtain the optimal protection and scheduling scheme.

2. The digital safety protection method for thermal power plants according to claim 1, characterized in that, The hybrid twin model of the device generated based on the real-time operating data specifically includes: Based on the real-time operating data, a hybrid twin model of the device is constructed by combining the mechanism model and the data-driven model. The mechanism model is built using Simulink, and the data-driven model uses an LSTM network.

3. The digital safety protection method for thermal power plants according to claim 1, characterized in that, The parsing of industrial protocol behavior includes parsing at least one of the industrial protocols IEC 60870-5-104, Modbus, PROFINET, and EtherNet / IP; The virtual industrial control network is divided into online mirror mode and offline sandbox mode.

4. The digital safety protection method for thermal power plants according to claim 1, characterized in that, Injecting simulated attack behaviors into the virtual industrial control network, including: Attack scenarios are constructed based on threat modeling methods, and simulated attack behaviors are injected into the virtual industrial control network through traffic replay or attack scripts. The threat modeling method employs at least one of the following: ATT&CK framework, attack tree, or Petri net.

5. A digital safety protection method for thermal power plants according to claim 1, characterized in that, The identification and verification of the simulated attack behavior specifically includes: The simulated attack behavior is subjected to feature rule detection, abnormal behavior detection, and intrusion detection.

6. The digital safety protection method for thermal power plants according to claim 1, characterized in that, The risk assessment employs a Bayesian network or reinforcement learning model, while the intelligent decision-making employs a deep reinforcement learning model or a graph neural network model.

7. A digital twin security entity, characterized in that, include: The physical twin layer is used to collect real-time operating data of key equipment in thermal power plants, generate hybrid twin models of the equipment based on the real-time operating data, and perform calibration to obtain real-time operating conditions and prediction results of key variables. The network twin layer is used to acquire communication data from the real industrial control network of a thermal power plant and parse industrial protocol behavior. Based on the communication data and industrial protocol behavior, a virtual industrial control network is established, and network operation status data is simulated. A security twin layer is used to inject simulated attack behaviors into the virtual industrial control network, identify and verify the simulated attack behaviors, and obtain security confrontation scenario data. The intelligent decision-making layer is used to perform risk assessment and intelligent decision-making after integrating the real-time operating conditions, key variable prediction results, network operating status data and security confrontation scenario data, so as to obtain the optimal protection scheduling scheme.

8. An electronic device, characterized in that, The method includes a memory, a processor, and a computer program stored in the memory and executable in the processor, wherein the processor executes the computer program to implement the steps of the digital security protection method for a thermal power plant as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the digital security protection method for thermal power plants according to any one of claims 1 to 6.

10. A computer program product, the computer program product comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the digital security protection method for thermal power plants as described in any one of claims 1 to 6.