A method and system for detecting secondary equipment of a substation

By standardizing the detection kernel and the security interaction sandbox specification, a dedicated adaptive proxy unit is generated, which solves the firmware version compatibility problem in the detection method of substation secondary equipment, realizes efficient and secure automated detection, reduces costs and improves detection accuracy.

CN122068669BActive Publication Date: 2026-07-21POWERCHINA JIANGXI ELECTRIC POWER ENGINEERING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
POWERCHINA JIANGXI ELECTRIC POWER ENGINEERING CO LTD
Filing Date
2026-04-22
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing substation secondary equipment testing methods are incompatible with different firmware versions, leading to communication failures, interruptions in automated testing processes, misjudgments and missed detections. Furthermore, customized development is costly, lacks versatility, and cannot cover a large number of fragmented versions.

Method used

It adopts a pre-built, fully decoupled, standardized detection kernel, standardized generation rules, and power safety-grade security interaction sandbox specifications. It obtains device characteristics through the least privilege detection instruction set, generates a dedicated adaptation agent unit, builds a two-way communication link, and realizes full-scale automated detection.

Benefits of technology

It achieves efficient adaptation to a large number of fragmented device firmware versions, reduces R&D and maintenance costs, improves testing efficiency and accuracy, and ensures the safety, compliance and universality of power secondary equipment testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122068669B_ABST
    Figure CN122068669B_ABST
Patent Text Reader

Abstract

The application provides a secondary equipment detection method and system for a transformer substation, which comprises the following steps: before detection is started, a minimum permission detection instruction set is sent to the secondary equipment to be detected through standard power constraints based on a safe interaction sandbox specification, so that the characteristics of the secondary equipment to be detected are detected; a special adaptive agent unit uniquely matched with the secondary equipment to be detected is generated according to a standardized generation rule, and a bidirectional communication link between a standardized detection kernel and the secondary equipment to be detected is synchronously constructed; a general detection task set is output through the standardized detection kernel, and an execution timing and a result analysis rule adapted to the general detection task set are synchronously generated through the special adaptive agent unit; full-amount automatic detection of the secondary equipment to be detected is completed, and after the detection is completed, the special adaptive agent unit is standardized and archived according to the detection result through the standardized detection kernel based on the bidirectional communication link. The application can significantly improve the detection efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of substation operation and maintenance technology, and in particular to a method and system for testing secondary equipment in substations. Background Technology

[0002] Substation secondary equipment is key equipment responsible for core functions such as power grid fault protection, operational status monitoring and control, and data metering and transmission. Its operational performance and reliability directly determine the safety and stability level of the power system. With the continuous deepening of smart grid construction, automated and intelligent secondary equipment testing methods and systems have become the core technological foundation for supporting lean operation and maintenance of the power grid and improving maintenance efficiency.

[0003] In the long-term operation and maintenance practice of substations, secondary equipment has a design life of 15-20 years. Within the same substation, equipment of the same model, due to different commissioning batches and technical upgrade cycles, has resulted in a large number of fragmented firmware versions without unified standardized management. These different versions exhibit numerous implicit differences in setpoint calculation models, IEC 61850 protocol interaction logic, action boundary characteristics, and data interface definitions. Existing automated testing methods and systems for secondary equipment mostly employ standardized test cases and general adaptation logic, which cannot be compatible with the implicit differences between different firmware versions. This frequently leads to communication adaptation failures, automated test process interruptions, and misjudgments or missed detections, ultimately degenerating into manual single-point testing. The testing efficiency and accuracy cannot meet the core requirements of large-scale power grid operation and maintenance.

[0004] To address the shortcomings of the existing technologies, current solutions mainly fall into two categories: one is to forcibly upgrade the firmware of all station equipment to a unified version. This method requires long-term power outages and is highly susceptible to major power grid safety risks such as incompatibility in cross-device communication within the station and malfunctions or failures of protection systems, which does not meet the mandatory management requirements for the safety protection of power secondary systems; the other is to develop customized detection and adaptation modules for different firmware versions, which has inherent defects such as high development costs, poor versatility, and inability to cover a large number of fragmented versions. Summary of the Invention

[0005] Based on this, the purpose of the present invention is to provide a method and system for testing secondary equipment in substations, so as to solve the problem that the existing technology requires customized development of testing adaptation modules for different firmware versions, resulting in high development costs, poor universality, and inability to cover a large number of fragmented versions.

[0006] The first aspect of the present invention proposes:

[0007] A method for testing secondary equipment in a substation, wherein the method includes:

[0008] A pre-built, standardized detection kernel completely decoupled from the firmware version, adapted standardized generation rules, and power safety-grade security interaction sandbox specifications are used to send a minimum privilege probe instruction set to the secondary device under test through standard power constraints before the detection starts, based on the security interaction sandbox specifications, in order to detect the protocol interaction characteristics, instruction mapping characteristics, and data format characteristics of the secondary device under test.

[0009] Based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics, a uniquely matched dedicated adapter unit is generated according to the standardized generation rules and is simultaneously loaded into the security interaction sandbox to construct a bidirectional communication link between the standardized detection kernel and the tested secondary device.

[0010] The standardized detection kernel outputs a general detection task set, and the dedicated adaptation proxy unit simultaneously generates execution timing and result parsing rules adapted to the general detection task set.

[0011] Based on the execution timing and the result parsing rules, the full automated detection of the tested secondary device is completed. Simultaneously, after the detection is completed, based on the bidirectional communication link, the standardized detection kernel archives the dedicated adaptation agent unit according to the detection results for direct invocation in subsequent detection of devices of the same model and firmware version.

[0012] The beneficial effects of this invention are as follows: By pre-constructing a standardized detection kernel completely decoupled from firmware versions, standardized adaptation generation rules, and a power safety-grade security interaction sandbox specification, this invention fundamentally breaks the strong binding between the detection module and firmware versions, solving the core pain points of existing technologies such as high customized development costs, poor universality, and inability to cover massive fragmented firmware versions. Before detection starts, the protocol interaction, command mapping, and data format characteristics of the device under test are accurately obtained through the least privilege probe instruction set, automatically generating a dedicated adaptation agent unit. This eliminates the need for manual customization for different firmware versions, significantly reducing R&D and maintenance costs, and efficiently adapting to massive fragmented device firmware versions. Relying on the security interaction sandbox to ensure the safety and compliance of power secondary equipment detection, the timing and parsing rule adaptation of general detection tasks is completed through dedicated adaptation agents, achieving fully automated detection and significantly improving detection efficiency and accuracy. At the same time, the standardized archiving and reuse of adaptation agent units further compresses the detection cycle of devices of the same model and version, constructing an automated detection system for power secondary equipment that balances universality, adaptability, security, and efficiency.

[0013] Furthermore, the step of generating a uniquely matched dedicated adapter unit that matches the tested secondary device according to the standardized generation rules based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics includes:

[0014] Based on the principle of least privilege for the security protection of power secondary systems, the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics are compared with the standard interaction baseline to eliminate unauthorized features, and authorized features are simultaneously selected according to the execution boundary of the detection task.

[0015] Based on the aforementioned authorization features, an adaptation logic framework is constructed that includes a standard interaction domain and a firmware-specific adaptation domain, wherein the standard interaction domain and the firmware-specific adaptation domain are completely isolated.

[0016] The adaptation logic framework is verified in a closed loop through the secure interaction sandbox. After the verification is passed, a unique and tamper-proof digital signature is added to the tested secondary device to generate the corresponding exclusive adaptation proxy unit.

[0017] Furthermore, the step of adding a uniquely bound, tamper-proof digital signature to the tested secondary device after successful verification, in order to generate the corresponding dedicated adaptation proxy unit, includes:

[0018] After verification, the unique hash value corresponding to the authorized feature, the bidirectional conversion rule of the adaptation logic framework, and the minimum permission boundary parameter of the detection task are extracted, and a unique root digest adapted to the tested secondary device is generated simultaneously by combining the national cryptographic algorithm.

[0019] Based on the unique root digest, a cross-validated tamper-proof digital signature is generated that corresponds one-to-one with the dual-domain structure of the adaptation logic framework. The tamper-proof data signature is divided into a main signature dedicated to the standard interaction domain and a secondary signature dedicated to the firmware-specific adaptation domain. The main signature and the secondary signature are cross-validated, and if any domain logic is tampered with, both signatures become invalid simultaneously.

[0020] The tamper-proof digital signature is verified throughout its entire lifecycle to generate a traceability identifier bound to the unique root digest. Simultaneously, the adaptation logic framework is encapsulated based on the traceability identifier to generate the corresponding dedicated adaptation proxy unit.

[0021] Furthermore, the step of loading the dedicated adaptation proxy unit into the secure interaction sandbox to construct a bidirectional communication link between the standardized detection kernel and the tested secondary device includes:

[0022] Before loading, a trusted execution domain is pre-built inside the security interaction sandbox based on the minimum permission boundary of the detection task, and an initial trusted token corresponding to the detection task is generated synchronously according to the trusted execution domain.

[0023] The dedicated adaptation agent unit is subjected to full trust measurement, and the measurement results are simultaneously merged with the initial trust token to generate the corresponding dedicated running token.

[0024] The dedicated adaptation proxy unit is loaded into the trusted execution domain, and independent sub-tokens that are cross-endorsed with the dedicated running token are generated for the standard interaction domain and the firmware dedicated adaptation domain, respectively. The bidirectional communication link is constructed synchronously based on the independent sub-tokens and the dedicated running token.

[0025] Furthermore, the step of constructing the bidirectional communication link based on the independent sub-token and the dedicated runtime token includes:

[0026] The general detection task set is decomposed into several atomic detection execution units, and the independent sub-token is simultaneously decomposed into several time-slotted token slices according to each atomic detection execution unit.

[0027] Based on several of the aforementioned time-slotted token slices, corresponding downlink command time-slot links and uplink data time-slot links are constructed, and link cross-verification is performed synchronously to form an immutable trust chain.

[0028] Configure a security and business-level linkage circuit breaker mechanism for the immutable trust chain. When any circuit breaker condition is triggered, immediately invalidate all tokens and close the link port to generate a full link operation rule. Simultaneously bind the full link operation rule with the dedicated operation token to generate the bidirectional communication link.

[0029] Furthermore, the step of standardizing and archiving the dedicated adaptation proxy unit based on the detection results through the standardized detection kernel, based on the bidirectional communication link, includes:

[0030] Extract the adaptation deviation data corresponding to the dedicated adaptation agent unit from the detection results, and generate corresponding optimization instructions by combining the working logs of the security interaction sandbox.

[0031] The bidirectional communication link is optimized by the optimization instructions to generate a corresponding target communication link. Simultaneously, the transferable general adaptation features in the dedicated adaptation proxy unit are extracted through the target communication link, and after standardized encapsulation, separation and archiving are performed to output the corresponding archiving results.

[0032] The archived results are linked with test cases of similar equipment to complete the corresponding standardized archiving.

[0033] Furthermore, the step of linking the archived results with test cases of similar devices to complete the corresponding standardized archiving includes:

[0034] Based on the security interaction sandbox specification, the corresponding scene parameters in the detection cases are extracted and compared with the corresponding parameters in the archived results to filter out detection cases of the same type.

[0035] Based on the standardized generation rules, corresponding association identifiers are generated for the archived results and the detection cases of the same type, and the association identifiers are bound in a synchronous manner to construct an association identifier mapping table.

[0036] The associated identifier mapping table is loaded into the standardized detection kernel for associated storage, and the associated storage information, the archived results, and the similar detection cases are bound simultaneously to complete the standardized archiving.

[0037] The second aspect of the present invention proposes:

[0038] A secondary equipment testing system for a substation, wherein the system comprises:

[0039] The detection module is used to pre-build a standardized detection kernel that is completely decoupled from the firmware version, adapt standardized generation rules, and power safety-level security interaction sandbox specifications. Simultaneously, before the detection starts, based on the security interaction sandbox specifications, it sends a minimum privilege probe instruction set to the secondary device under test through standard power constraints to detect the protocol interaction characteristics, instruction mapping characteristics, and data format characteristics of the secondary device under test.

[0040] The construction module is used to generate a uniquely matched dedicated adapter unit that matches the tested secondary device according to the standardized generation rules based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics, and to load the dedicated adapter unit into the security interaction sandbox to build a bidirectional communication link between the standardized detection kernel and the tested secondary device.

[0041] The output module is used to output a general detection task set through the standardized detection kernel, and simultaneously generate execution timing and result parsing rules adapted to the general detection task set through the dedicated adaptation proxy unit.

[0042] The processing module is used to complete the full automated detection of the tested secondary device based on the execution timing and the result parsing rules. Simultaneously, after the detection is completed, based on the bidirectional communication link, the standardized detection kernel archives the dedicated adaptation agent unit according to the detection results for direct invocation in subsequent detection of devices of the same model and firmware version.

[0043] Furthermore, the building module is specifically used for:

[0044] Based on the principle of least privilege for the security protection of power secondary systems, the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics are compared with the standard interaction baseline to eliminate unauthorized features, and authorized features are simultaneously selected according to the execution boundary of the detection task.

[0045] Based on the aforementioned authorization features, an adaptation logic framework is constructed that includes a standard interaction domain and a firmware-specific adaptation domain, wherein the standard interaction domain and the firmware-specific adaptation domain are completely isolated.

[0046] The adaptation logic framework is verified in a closed loop through the secure interaction sandbox. After the verification is passed, a unique and tamper-proof digital signature is added to the tested secondary device to generate the corresponding exclusive adaptation proxy unit.

[0047] Furthermore, the building module is specifically used for:

[0048] After verification, the unique hash value corresponding to the authorized feature, the bidirectional conversion rule of the adaptation logic framework, and the minimum permission boundary parameter of the detection task are extracted, and a unique root digest adapted to the tested secondary device is generated simultaneously by combining the national cryptographic algorithm.

[0049] Based on the unique root digest, a cross-validated tamper-proof digital signature is generated that corresponds one-to-one with the dual-domain structure of the adaptation logic framework. The tamper-proof data signature is divided into a main signature dedicated to the standard interaction domain and a secondary signature dedicated to the firmware-specific adaptation domain. The main signature and the secondary signature are cross-validated, and if any domain logic is tampered with, both signatures become invalid simultaneously.

[0050] The tamper-proof digital signature is verified throughout its entire lifecycle to generate a traceability identifier bound to the unique root digest. Simultaneously, the adaptation logic framework is encapsulated based on the traceability identifier to generate the corresponding dedicated adaptation proxy unit.

[0051] Furthermore, the building module is specifically used for:

[0052] Before loading, a trusted execution domain is pre-built inside the security interaction sandbox based on the minimum permission boundary of the detection task, and an initial trusted token corresponding to the detection task is generated synchronously according to the trusted execution domain.

[0053] The dedicated adaptation agent unit is subjected to full trust measurement, and the measurement results are simultaneously merged with the initial trust token to generate the corresponding dedicated running token.

[0054] The dedicated adaptation proxy unit is loaded into the trusted execution domain, and independent sub-tokens that are cross-endorsed with the dedicated running token are generated for the standard interaction domain and the firmware dedicated adaptation domain, respectively. The bidirectional communication link is constructed synchronously based on the independent sub-tokens and the dedicated running token.

[0055] Furthermore, the building module is specifically used for:

[0056] The general detection task set is decomposed into several atomic detection execution units, and the independent sub-token is simultaneously decomposed into several time-slotted token slices according to each atomic detection execution unit.

[0057] Based on several of the aforementioned time-slotted token slices, corresponding downlink command time-slot links and uplink data time-slot links are constructed, and link cross-verification is performed synchronously to form an immutable trust chain.

[0058] Configure a security and business-level linkage circuit breaker mechanism for the immutable trust chain. When any circuit breaker condition is triggered, immediately invalidate all tokens and close the link port to generate a full link operation rule. Simultaneously bind the full link operation rule with the dedicated operation token to generate the bidirectional communication link.

[0059] Furthermore, the processing module is specifically used for:

[0060] Extract the adaptation deviation data corresponding to the dedicated adaptation agent unit from the detection results, and generate corresponding optimization instructions by combining the working logs of the security interaction sandbox.

[0061] The bidirectional communication link is optimized by the optimization instructions to generate a corresponding target communication link. Simultaneously, the transferable general adaptation features in the dedicated adaptation proxy unit are extracted through the target communication link, and after standardized encapsulation, separation and archiving are performed to output the corresponding archiving results.

[0062] The archived results are linked with test cases of similar equipment to complete the corresponding standardized archiving.

[0063] Furthermore, the processing module is specifically used for:

[0064] Based on the security interaction sandbox specification, the corresponding scene parameters in the detection cases are extracted and compared with the corresponding parameters in the archived results to filter out detection cases of the same type.

[0065] Based on the standardized generation rules, corresponding association identifiers are generated for the archived results and the detection cases of the same type, and the association identifiers are bound in a synchronous manner to construct an association identifier mapping table.

[0066] The associated identifier mapping table is loaded into the standardized detection kernel for associated storage, and the associated storage information, the archived results, and the similar detection cases are bound simultaneously to complete the standardized archiving.

[0067] The third aspect of the present invention proposes:

[0068] A computer includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the secondary equipment detection method for a substation as described above.

[0069] The fourth aspect of the present invention proposes:

[0070] A readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the secondary equipment detection method for a substation as described above.

[0071] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0072] Figure 1 A flowchart of a secondary equipment testing method for a substation provided in the first embodiment of the present invention;

[0073] Figure 2 This is a structural block diagram of a secondary equipment testing system for a substation provided in the third embodiment of the present invention.

[0074] The following detailed description, in conjunction with the accompanying drawings, will further illustrate the present invention. Detailed Implementation

[0075] To facilitate understanding of the present invention, a more complete description will be given below with reference to the accompanying drawings. Several embodiments of the invention are illustrated in the drawings. However, the invention can be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete.

[0076] It should be noted that when a component is said to be "fixed to" another component, it can be directly on the other component or there may be an intervening component. When a component is said to be "connected to" another component, it can be directly connected to the other component or there may be an intervening component. The terms "vertical," "horizontal," "left," "right," and similar expressions used in this document are for illustrative purposes only.

[0077] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0078] Please see Figure 1 The image shows a method for testing secondary equipment in substations provided in the first embodiment of the present invention. This method can adapt the timing and parsing rules of general testing tasks through a dedicated adapter, achieving fully automated testing and significantly improving testing efficiency and accuracy. At the same time, the standardized archiving and reuse of the adapter unit further compresses the testing cycle of the same model and version of equipment, thus constructing an automated testing system for power secondary equipment that takes into account universality, adaptability, security and efficiency.

[0079] Specifically, this embodiment provides:

[0080] A method for testing secondary equipment in a substation, wherein the method includes:

[0081] Step S10: A standardized detection kernel, adapted standardized generation rules, and power safety-level security interaction sandbox specifications that are completely decoupled from the firmware version are pre-built. Simultaneously, before the detection starts, based on the security interaction sandbox specifications, a minimum privilege detection instruction set is sent to the secondary device under test through standard power constraints to detect the protocol interaction characteristics, instruction mapping characteristics, and data format characteristics of the secondary device under test.

[0082] It's important to note that the core flaw of traditional testing methods lies in the deep binding of testing logic to device firmware versions. Once the device firmware is upgraded or the model is changed, the original testing tools become completely ineffective. Furthermore, the lack of a unified security interaction boundary makes it extremely easy to send unauthorized commands to the device, affecting the normal operation of substation secondary equipment and even causing power grid safety accidents such as protection malfunctions or failures to operate. This step first completes the construction of the underlying foundation of the testing system: a standardized testing kernel completely decoupled from firmware versions, encapsulating only general testing logic, testing items, and evaluation rules that conform to power industry standards, without containing any adaptation logic bound to specific devices or firmware, thus achieving standardization and universality of the core testing logic; the accompanying standardized generation rules are used to convert general testing logic into execution logic adapted to different devices, serving as a bridge connecting the standardized kernel and personalized devices; the power safety-grade security interaction sandbox specification defines an inviolable security boundary for the entire testing process. All interactions with the tested device must be completed within the sandbox, strictly adhering to the principle of least privilege to prevent unauthorized operations. Before the test begins, no read / write or control commands are sent directly to the device under test. Instead, based on the security interaction sandbox specification, a minimum privilege probe command set conforming to standard power constraints is sent. These commands are only used to obtain the basic interactive characteristics of the device and will not affect the device's operating status, completely avoiding interference with the normal operation of the secondary equipment during the test process. Through the feedback of the probe commands, the protocol interaction characteristics of the secondary equipment under test (such as the supported 104 protocol, IEC61850 MMS protocol, and the version and interaction rules of the manufacturer's proprietary protocol), command mapping characteristics (the correspondence between general test commands and device proprietary commands), and data format characteristics (encoding format, byte order, and dimension mapping rules of the data sent by the device) are accurately identified. This provides accurate input for the subsequent generation of dedicated adaptation agents, achieving risk-free and interference-free perception of the device under test.

[0083] Step S20: Based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics, generate a uniquely matched exclusive adapter agent unit that matches the tested secondary device according to the standardized generation rules, and simultaneously load the exclusive adapter agent unit into the security interaction sandbox to construct a bidirectional communication link between the standardized detection kernel and the tested secondary device.

[0084] It's important to note that the standardized testing kernel is generic and cannot directly communicate with secondary devices using different protocols and formats. Traditional methods involve directly writing the adaptation logic into the testing kernel, resulting in strong coupling between the kernel and firmware. This step decouples the kernel from the device through a dedicated adaptation proxy unit. This proxy unit acts as a "translator" between the standardized kernel and the device under test, handling only two tasks: first, converting the generic testing commands issued by the standardized kernel into private commands recognizable by the device under test and conforming to the device's protocol requirements; second, converting the private format data returned by the device under test into standard format data recognizable by the standardized testing kernel. All personalized adaptation logic related to device firmware and protocols is encapsulated within the dedicated adaptation proxy unit, while the standardized testing kernel remains unchanged, completely resolving the coupling issue between the kernel and firmware versions. After generating a dedicated adapter agent unit, it is loaded into a pre-built secure interaction sandbox. All communication with the device under test must be completed through the adapter agent unit in the sandbox. The sandbox defines strict security boundaries for the operation of the adapter agent. At the same time, based on the conversion rules of the adapter agent, a bidirectional communication link between the standardized detection kernel and the secondary device under test is built. This link is under the management of the secure sandbox throughout the entire process. All instructions and data are verified for compliance by the adapter agent to ensure that no unauthorized instructions are issued.

[0085] Step S30: Output a general detection task set through the standardized detection kernel, and simultaneously generate execution timing and result parsing rules adapted to the general detection task set through the dedicated adaptation proxy unit;

[0086] It's important to note that the universal testing task set output by the standardized testing kernel consists of general testing items that conform to power industry testing standards. These include secondary equipment setting verification, input / output circuit testing, sampling accuracy verification, communication link testing, and device self-test function verification. These testing items are not specific to any particular device; they are universal testing requirements for all types of secondary equipment. After receiving the universal testing task set, the dedicated adaptation agent unit, based on the previously identified device protocols, instruction mappings, and data format characteristics, breaks down the universal testing tasks into instruction execution sequences that meet the requirements of the tested equipment. It clarifies the issuance order, time interval, and interaction logic of each instruction, and generates corresponding result parsing rules, specifying the parsing method, unit conversion, and pass / fail threshold judgment rules for the equipment's returned data. This ensures that the universal testing tasks can be accurately executed on the tested equipment without any modifications to the standardized testing kernel, truly achieving the goal of "build once, adapt to all devices."

[0087] Step S40: Based on the execution timing and the result parsing rules, complete the full automated detection of the tested secondary device. Simultaneously, after the detection is completed, based on the bidirectional communication link, the standardized detection kernel archives the dedicated adaptation agent unit according to the detection results for direct invocation in subsequent detection of devices of the same model and firmware version.

[0088] It should be noted that, following the execution sequence and result parsing rules generated by the adapter proxy, the detection system automatically completes the distribution of all detection items, data feedback, result judgment, and anomaly recording without manual intervention. This achieves fully automated detection of secondary equipment, significantly improving the efficiency of substation on-site detection and avoiding human error in manual detection. After detection, the standardized detection kernel optimizes and improves the dedicated adapter proxy unit based on the execution status, adaptation deviation, and result parsing accuracy of this detection, and completes standardized archiving. The archived adapter proxy unit is uniquely bound to the model, firmware version, and protocol version of the tested equipment. When detecting secondary equipment of the same model and firmware version, there is no need to repeat the equipment detection and adapter proxy generation process; the archived adapter proxy unit can be directly called, achieving plug-and-play detection and significantly shortening the preparation time for subsequent detections. At the same time, through the detection of a large number of similar equipment, the adapter proxy library is continuously improved, forming a reusable and shareable substation secondary equipment detection adaptation capability system.

[0089] Second Embodiment

[0090] Furthermore, the step of generating a uniquely matched dedicated adapter unit that matches the tested secondary device according to the standardized generation rules based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics includes:

[0091] Based on the principle of least privilege for the security protection of power secondary systems, the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics are compared with the standard interaction baseline to eliminate unauthorized features, and authorized features are simultaneously selected according to the execution boundary of the detection task.

[0092] Based on the aforementioned authorization features, an adaptation logic framework is constructed that includes a standard interaction domain and a firmware-specific adaptation domain, wherein the standard interaction domain and the firmware-specific adaptation domain are completely isolated.

[0093] The adaptation logic framework is verified in a closed loop through the secure interaction sandbox. After the verification is passed, a unique and tamper-proof digital signature is added to the tested secondary device to generate the corresponding exclusive adaptation proxy unit.

[0094] It should be noted that one of the core principles of power secondary system security protection is the principle of least privilege. This means that during the testing process, only the minimum privileges necessary to complete the testing task are granted. It is absolutely forbidden to obtain equipment data unrelated to the testing task or to issue control commands unrelated to the testing task. This is a safety red line that cannot be crossed in the testing of substation secondary equipment. Traditional testing tools often integrate the entire instruction set of the device, posing a significant risk of unauthorized operation. Before generating the adapter agent, this step uses the principle of least privilege as a benchmark, comparing the previously detected device protocol interaction characteristics, instruction mapping characteristics, and data format characteristics with a pre-defined standard interaction baseline. The standard interaction baseline clarifies the instruction range, data reading range, and interaction permissions necessary to complete the testing task. Through comparison, all unauthorized features irrelevant to the testing task are eliminated, such as control commands like device setting modification and protection plate activation / deactivation. Only authorized features of reading and testing commands necessary to complete the testing task are retained. At the same time, based on the execution boundary of this testing task, the authorized features are further filtered to ensure that the adapter agent only has the minimum permissions to complete this testing task, eliminating the risk of unauthorized operation at the source and ensuring that the generation and operation of the adapter agent fully comply with power safety protection requirements.

[0095] To further decouple the standardized kernel from firmware-specific logic, while ensuring the stability of the standard logic and the flexibility of the custom adaptation logic, this step constructs a completely isolated dual-domain adaptation logic framework: The standard interaction domain is responsible for interfacing with the standardized detection kernel, encapsulating industry-standard interaction logic, data formats, and instruction specifications, regardless of the device model or firmware version. All standard interaction domains of the adaptation proxies follow a unified specification to ensure complete compatibility with the standardized detection kernel. The firmware-specific adaptation domain encapsulates personalized adaptation logic related to the firmware, protocol, and data format of the device under test, namely the conversion rules and mapping rules corresponding to the previously selected authorized features. All device-related personalized content is enclosed within this domain and is completely isolated from the standard interaction domain. This dual-domain isolation architecture offers two core advantages: First, when the device firmware version is updated, only the content of the firmware-specific adaptation domain needs to be modified, while the standard interaction domain remains unchanged, significantly reducing the maintenance cost of the adaptation logic. Second, the standard interaction domain directly interfaces with the security sandbox, and all instructions and data must undergo compliance verification in the standard interaction domain before entering the firmware-specific adaptation domain. This completely prevents the personalized logic of the firmware-specific adaptation domain from breaching security boundaries, further enhancing the security of the detection process.

[0096] After the adaptation logic framework is built, it cannot be used directly. It must first undergo closed-loop trusted verification within a secure interactive sandbox. The verification includes: whether the adaptation logic only contains authorized features, whether there are unauthorized instructions and data reading rules, whether the dual-domain isolation is effective, whether it will interfere with the operation of the tested device, and whether the instruction conversion and data parsing are accurate. Only when all verification items pass, confirming that the adaptation logic fully complies with security and adaptation requirements, can it proceed to the next stage. After successful verification, a tamper-proof digital signature is added to the adaptation logic framework, uniquely bound to the tested secondary device. The digital signature is generated based on national cryptographic algorithms and uniquely bound to the device model, firmware version, authorized features, and adaptation logic. Once the adaptation logic is tampered with, the digital signature will immediately become invalid and unable to load and run normally. This technically ensures the integrity and immutability of the adaptation proxy unit, ultimately generating a compliant, secure, and accurate dedicated adaptation proxy unit.

[0097] Furthermore, the step of adding a uniquely bound, tamper-proof digital signature to the tested secondary device after successful verification, in order to generate the corresponding dedicated adaptation proxy unit, includes:

[0098] After verification, the unique hash value corresponding to the authorized feature, the bidirectional conversion rule of the adaptation logic framework, and the minimum permission boundary parameter of the detection task are extracted, and a unique root digest adapted to the tested secondary device is generated simultaneously by combining the national cryptographic algorithm.

[0099] Based on the unique root digest, a cross-validated tamper-proof digital signature is generated that corresponds one-to-one with the dual-domain structure of the adaptation logic framework. The tamper-proof data signature is divided into a main signature dedicated to the standard interaction domain and a secondary signature dedicated to the firmware-specific adaptation domain. The main signature and the secondary signature are cross-validated, and if any domain logic is tampered with, both signatures become invalid simultaneously.

[0100] The tamper-proof digital signature is verified throughout its entire lifecycle to generate a traceability identifier bound to the unique root digest. Simultaneously, the adaptation logic framework is encapsulated based on the traceability identifier to generate the corresponding dedicated adaptation proxy unit.

[0101] It's important to note that the core trust foundation of the adaptation agent unit lies in the integrity and immutability of all its core content. After the adaptation logic framework passes trust verification, this step first extracts its core immutable elements: First, a unique hash value corresponding to the authorized features, generated using the national cryptographic SM3 hash algorithm, ensuring that the authorized features have not been tampered with or that no unauthorized features have been added; second, the bidirectional conversion rules of the adaptation logic framework, namely the conversion rules between general instructions and device-specific instructions, and the parsing rules between device data and standard data—this is the core functional logic of the adaptation agent; third, the minimum permission boundary parameters for the detection task, which clearly define the scope of the adaptation agent's permissions and serve as the core benchmark for security protection. After combining these core elements, a unique root digest compatible with the tested secondary device is generated using the national cryptographic SM3 algorithm. This root digest is the "digital identity fingerprint" of the adaptation agent unit, uniquely bound to the tested device's model, firmware version, authorized features, and permission boundaries. Any tampering with any core element will cause a change in the root digest, providing a core benchmark for subsequent anti-tampering signatures and traceability.

[0102] To address the dual-domain isolation architecture of the standard interaction domain and the firmware-specific adaptation domain in the adaptation logic framework, this step designs a cross-validation dual-signature mechanism instead of a single overall signature. This solves the problem that a single signature cannot achieve accurate identification of single-domain tampering and the problem of dual-domain linkage protection. Based on a unique root digest, a dedicated master signature is generated for the standard interaction domain and a dedicated secondary signature is generated for the firmware-specific adaptation domain using the national cryptographic SM2 asymmetric encryption algorithm. The master signature is bound to the core logic and root digest of the standard interaction domain, and the secondary signature is bound to the core logic and root digest of the firmware-specific adaptation domain. At the same time, a cross-validation mechanism is set between the master and secondary signatures. Both signatures must pass the verification simultaneously for the adaptation proxy unit to load and run normally. Once the logic of either domain is tampered with, not only will the signature of the corresponding domain become invalid, but the signature of the other domain will also become invalid due to the failure of cross-validation, and the entire adaptation proxy unit will fail to run. This cross-verification dual-signature mechanism achieves coordinated protection across two domains. It can accurately pinpoint which domain has been tampered with, and through cross-verification, it achieves a strong protection effect of "one tampering, all invalidation," completely eliminating the risk of breaching security boundaries and modifying adaptation logic by tampering with a single domain. It fully meets the power industry's requirements for strong anti-tampering of applications.

[0103] The tamper-proof digital signature is verified not only during loading but also continuously throughout the entire runtime of the adapter agent to prevent malicious tampering during operation. This step establishes a full-lifecycle verification mechanism for the tamper-proof digital signature. Throughout the entire process of adapter agent startup, instruction conversion, data parsing, and runtime termination, the primary and secondary signatures are cross-verified. If verification fails, the adapter agent's operation is immediately terminated, and the communication link is closed, ensuring security throughout the entire runtime. Simultaneously, a corresponding traceability identifier is generated based on the unique root digest. This identifier contains full-link traceability information, including the adapter agent's generation time, corresponding device model and firmware version, authorization scope, signature information, and the generating entity, achieving full lifecycle traceability and auditability for the adapter agent. Finally, the tamper-proof digital signature, traceability identifier, and dual-domain isolated adapter logic framework are integrated and encapsulated to generate a complete, tamper-proof, fully traceable, and strictly compliant with power safety requirements dedicated adapter agent unit.

[0104] Furthermore, the step of loading the dedicated adaptation proxy unit into the secure interaction sandbox to construct a bidirectional communication link between the standardized detection kernel and the tested secondary device includes:

[0105] Before loading, a trusted execution domain is pre-built inside the security interaction sandbox based on the minimum permission boundary of the detection task, and an initial trusted token corresponding to the detection task is generated synchronously according to the trusted execution domain.

[0106] The dedicated adaptation agent unit is subjected to full trust measurement, and the measurement results are simultaneously merged with the initial trust token to generate the corresponding dedicated running token.

[0107] The dedicated adaptation proxy unit is loaded into the trusted execution domain, and independent sub-tokens that are cross-endorsed with the dedicated running token are generated for the standard interaction domain and the firmware dedicated adaptation domain, respectively. The bidirectional communication link is constructed synchronously based on the independent sub-tokens and the dedicated running token.

[0108] It is important to note that before loading the dedicated adapter agent unit, a secure and isolated operating environment must be defined for it, and a trusted identity benchmark must be established. This step, based on the minimum permission boundaries of this detection task, pre-builds a dedicated trusted execution domain within the secure interaction sandbox. This trusted execution domain is a completely isolated operating environment, completely isolated from the host system and other business systems of the substation. The dedicated adapter agent unit can only run within this domain and cannot access any resources outside the domain, thus eliminating the risk of unauthorized access and malicious code spread at the environmental level. Simultaneously, based on the environmental characteristics of the trusted execution domain, the permission boundaries of this detection task, and the information of the inspected device, an initial trusted token corresponding to this detection task is generated using national cryptographic algorithms. This initial trusted token is the initial trusted identity credential for this detection task, valid only within the trusted execution domain of this detection. It is the core benchmark for all subsequent communication and permission management. Without the corresponding trusted token, no instruction or data can pass the verification of the trusted execution domain, and communication with the inspected device cannot be established.

[0109] Before loading the dedicated adapter agent unit, a full-scale trust measurement must be completed to ensure its integrity and trustworthiness. This step uses the national cryptographic SM3 algorithm to perform a hash measurement on all content of the dedicated adapter agent unit, including dual-domain adaptation logic, tamper-proof digital signature, traceability identifier, etc., to obtain a complete measurement result. This result is then verified to be consistent with the initially generated unique root digest and tamper-proof signature, confirming that the adapter agent unit has not been tampered with and is completely trustworthy. After successful verification, the measurement result is merged with the initial trust token to generate a dedicated runtime token uniquely bound to this detection task, the tested device, and the dedicated adapter agent using the national cryptographic algorithm. This dedicated runtime token is the unique trusted identity credential for communication between the trusted execution domain, the adapter agent unit, and the tested device throughout the entire detection process. The token also embeds the minimum permission boundaries of this detection task, clearly defining the scope of instructions that can be issued, the scope of data that can be read, and the effective communication period, thus achieving the integration of identity trust and permission management.

[0110] After loading the dedicated adaptation agent unit into the trusted execution domain, independent sub-tokens are generated for the standard interaction domain and the firmware-dedicated adaptation domain, based on its dual-domain isolation architecture. Both sub-tokens are cross-endorsed with the dedicated execution token and must pass the verification of the dedicated execution token to be effective. At the same time, the two sub-tokens correspond to the permission scope of the two domains respectively: the sub-token of the standard interaction domain manages its communication permissions with the standardized detection kernel, and only allows receiving general detection tasks from the standardized detection kernel and returning standardized detection results; the sub-token of the firmware-dedicated adaptation domain manages its communication permissions with the tested secondary device, and only allows issuing detection commands and receiving data returned by the device within the minimum permission boundaries. Based on a dedicated runtime token and two independent sub-tokens, a bidirectional communication link is established between the standardized detection kernel and the tested secondary device: In the downlink direction, the general detection commands of the standardized detection kernel must pass the verification of the standard interaction domain sub-token before entering the standard interaction domain of the adapter proxy. The converted device-specific commands must pass the verification of the firmware-specific adapter domain sub-token before being sent to the tested device. In the uplink direction, the data returned by the tested device must pass the verification of the firmware-specific adapter domain sub-token before entering the adapter proxy for parsing. The parsed standardized data must pass the verification of the standard interaction domain sub-token before being returned to the standardized detection kernel. Every data interaction in the entire bidirectional communication link must pass the verification of the corresponding token, ensuring that all communication is completed within the minimum permission boundaries and under the management of the trusted execution domain throughout, completely eliminating the risk of unauthorized communication and data leakage.

[0111] Furthermore, the step of constructing the bidirectional communication link based on the independent sub-token and the dedicated runtime token includes:

[0112] The general detection task set is decomposed into several atomic detection execution units, and the independent sub-token is simultaneously decomposed into several time-slotted token slices according to each atomic detection execution unit.

[0113] Based on several of the aforementioned time-slotted token slices, corresponding downlink command time-slot links and uplink data time-slot links are constructed, and link cross-verification is performed synchronously to form an immutable trust chain.

[0114] Configure a security and business-level linkage circuit breaker mechanism for the immutable trust chain. When any circuit breaker condition is triggered, immediately invalidate all tokens and close the link port to generate a full link operation rule. Simultaneously bind the full link operation rule with the dedicated operation token to generate the bidirectional communication link.

[0115] It's important to note that the general detection task set consists of multiple independent detection items. Traditional communication link management sets a unified token and permissions for the entire detection task, failing to achieve fine-grained management of individual detection items. If permissions are leaked, the security of the entire detection task will be compromised. This step first decomposes the general detection task set into several indivisible atomic detection execution units. Each atomic detection execution unit corresponds to an independent, minimal detection item, such as "Sampling Channel 1 Precision Verification" or "Input Loop 1 Status Reading." Each atomic unit has a clearly defined execution sequence, instruction range, and permission requirements. Based on the decomposed atomic detection execution units, the independent sub-tokens of the standard interaction domain and the firmware-specific adaptation domain are further decomposed into several time-slotted token slices. Each time-slotted token slice corresponds one-to-one with an atomic detection execution unit, is valid only within the execution slot of that atomic unit, and possesses only the minimum permissions required to complete that atomic unit. If the time slot or permission range is exceeded, the token slice immediately becomes invalid. This time-slotted token slicing mechanism enables atomic and time-sequential permission management for detection tasks. Even if a token slice is maliciously stolen, it will only take effect within a very short time slot and a very small permission range, and will not affect the entire detection process or device security. This significantly reduces security risks and improves the fine-grained management capabilities of the communication link.

[0116] Based on time-slotted token slicing, the original single bidirectional communication link is decomposed into downlink command time-slot links and uplink data time-slot links corresponding to the atomic detection execution units. The downlink command time-slot link is responsible for issuing the execution command of the corresponding atomic detection unit within the corresponding time slot, after valid token slice verification. The uplink data time-slot link is responsible for transmitting the device data of the corresponding atomic detection unit back within the corresponding time slot, after valid token slice verification. Simultaneously, cross-validation is performed on the downlink and uplink links. The token slice of each downlink command time slot must form a one-to-one verification relationship with the token slice of the corresponding uplink data time slot. Only after the downlink command is executed and the uplink data transmission verification passes will the link of that time slot be closed, allowing the link of the next time slot to be opened. This avoids problems such as missed command issuance, missed data transmission, and timing errors. By constructing and cross-validating time-slotted links, the communication links of the entire detection process are broken down into a series of time-series continuous and mutually verified time-slotted links. The execution status of each time-slotted link is recorded and hashed onto the blockchain using the national cryptographic algorithm, ultimately forming an immutable trust chain for the entire detection process. This fully records the issuance of each instruction and the return of each set of data, achieving traceability and auditability of the entire detection communication process, while ensuring the accuracy of the detection execution timing and the reliability of the communication process.

[0117] Substation secondary equipment is directly related to the safe and stable operation of the power grid. If any abnormality occurs during the testing process, all operations must be immediately terminated, and communication links severed to prevent the abnormality from spreading and affecting the normal operation of the equipment. This step configures a circuit breaker mechanism that links security and business operations in a dual-dimensional manner for the tamper-proof trust chain. Security-level circuit breaker conditions include: token verification failure, unauthorized command attempts, data tampering detection, and abnormal operation of the adaptation agent, among other security violations. Business-level circuit breaker conditions include: abnormal operation of the tested equipment, test data exceeding the device's normal range, and command execution causing device alarms, among other business anomalies that may affect the normal operation of the equipment. If any circuit breaker condition is triggered, the system will immediately invalidate all tokens used in this test, including dedicated operation tokens, independent sub-tokens, and all time-slotted token slices. Simultaneously, all communication link ports will be immediately closed, terminating all interaction with the tested equipment. This ensures that abnormal situations are blocked immediately and will not cause any impact on the tested equipment. The circuit breaker mechanism, time-slotted link rules, and token verification rules are integrated into a full-scale link operation rule, which is uniquely bound to a dedicated operation token, ultimately forming a complete two-way communication link with fine-grained management, full-link trust, and rapid anomaly response capabilities.

[0118] Furthermore, the step of standardizing and archiving the dedicated adaptation proxy unit based on the detection results through the standardized detection kernel, based on the bidirectional communication link, includes:

[0119] Extract the adaptation deviation data corresponding to the dedicated adaptation agent unit from the detection results, and generate corresponding optimization instructions by combining the working logs of the security interaction sandbox.

[0120] The bidirectional communication link is optimized by the optimization instructions to generate a corresponding target communication link. Simultaneously, the transferable general adaptation features in the dedicated adaptation proxy unit are extracted through the target communication link, and after standardized encapsulation, separation and archiving are performed to output the corresponding archiving results.

[0121] The archived results are linked with test cases of similar equipment to complete the corresponding standardized archiving.

[0122] It's important to note that the actual execution of this test is the best basis for verifying the adaptation accuracy, operational efficiency, and security of the dedicated adaptation proxy unit. Traditional archiving simply stores the adaptation proxy without optimizing it based on the actual test results, leading to adaptation deviations during reuse. This step first extracts adaptation deviation data corresponding to the dedicated adaptation proxy unit from the test results, including core adaptation indicators such as instruction conversion accuracy, data parsing errors, execution timing deviations, and false positive rates of test results. Simultaneously, it combines the work logs from the security interaction sandbox to extract operational data such as resource consumption, security verification status, token execution anomalies, and circuit breaker trigger records during the adaptation proxy's operation. By analyzing this data, it identifies adaptation defects and optimization points in the adaptation proxy unit, such as errors in the parsing rules for certain types of data, unreasonable conversion timing of certain instructions, and room for optimization in permission boundaries. Based on these optimization points, corresponding optimization instructions are generated, providing precise targets for the optimization of the adaptation proxy.

[0123] Based on the generated optimization instructions, the bidirectional communication link tested in this instance is first optimized to correct issues such as timing deviations, verification rule vulnerabilities, and unreasonable permission boundaries that occur during link operation. This generates a more stable, secure, and efficient target communication link. Simultaneously, the optimized content is updated to the corresponding logic in the dedicated adaptation agent unit to correct adaptation deviations and improve the adaptation accuracy and operational stability of the agent. Subsequently, through the optimized target communication link, transferable general adaptation features are extracted from the dedicated adaptation agent unit. These features are common adaptation logic for devices from the same manufacturer, series, and protocol type, such as common data parsing rules for a manufacturer's MMS protocol or common instruction mapping rules for protection devices in the same series. These general features do not change with specific models or firmware versions, possessing extremely high reusability. These transferable general adaptation features are standardized and encapsulated, and then archived separately from the device-specific personalized adaptation logic: general adaptation features are incorporated into the general adaptation library of the standardized detection kernel for rapid generation of adaptation proxies for subsequent devices of the same type, significantly shortening the adaptation cycle for new devices; device-specific personalized adaptation logic is archived together with the optimized adaptation proxy unit for direct invocation by devices of the same model and firmware version, ultimately outputting a complete archived result, realizing the classification, accumulation, and layered reuse of general and specific capabilities.

[0124] To further enhance the reusability of archived results and form a complete adaptation capability system, this step links the archived results generated this time with historical testing cases of equipment from the same manufacturer, model, and type. It clarifies the applicable scenarios, adaptation scope, optimization history, and testing results of the archived adaptation agent units. Simultaneously, the adaptation experience and optimization methods accumulated during this testing process are linked to the adaptation knowledge base for similar equipment. This allows subsequent adaptation agent generation for similar equipment to directly reuse existing experience and common features, achieving the effect of "one-time adaptation, full-series reuse." This continuously improves the adaptation capability library of the entire testing system, reduces the adaptation development cost for new equipment, and enhances the overall efficiency of substation secondary equipment testing.

[0125] Furthermore, the step of linking the archived results with test cases of similar devices to complete the corresponding standardized archiving includes:

[0126] Based on the security interaction sandbox specification, the corresponding scene parameters in the detection cases are extracted and compared with the corresponding parameters in the archived results to filter out detection cases of the same type.

[0127] Based on the standardized generation rules, corresponding association identifiers are generated for the archived results and the detection cases of the same type, and the association identifiers are bound in a synchronous manner to construct an association identifier mapping table.

[0128] The associated identifier mapping table is loaded into the standardized detection kernel for associated storage, and the associated storage information, the archived results, and the similar detection cases are bound simultaneously to complete the standardized archiving.

[0129] It's important to note that to achieve precise linkage between archived results and test cases, the first step is to accurately screen similar cases. Traditional archiving methods, which simply categorize by equipment model, fail to achieve accurate scenario-based matching, leading to incompatibility issues during reuse. This step, based on the security interaction sandbox specification, clarifies the core parameter dimensions for adaptable scenarios, including equipment manufacturer, equipment model, firmware version, supported protocol types, substation voltage level, test task type, and security protection level. Adaptable scenario parameters for all cases are extracted from the historical test case library and compared with the corresponding parameters of the current archived results across multiple dimensions. Test cases of the same type are screened based on parameter matching, such as cases of different models from the same manufacturer and series, cases of different manufacturers with the same protocol type, and cases of similar equipment at the same voltage level. This not only filters out cases of completely identical models but also covers similar types of cases with reuse value, providing a comprehensive sample foundation for subsequent association and binding.

[0130] To achieve stable and searchable linkage between archived results and similar cases, this step generates unique and standardized association identifiers for both the current archived results and the selected similar testing cases, based on pre-defined standardized generation rules. These association identifiers contain standardized coded information such as equipment manufacturer, model, protocol type, scenario parameters, and archive time, ensuring that each association identifier is globally unique and searchable. Subsequently, the association identifiers of the current archived results are bound to the association identifiers of similar testing cases in multiple dimensions, including binding relationships at different levels such as exact match binding for the same model, similar match binding for the same series, and general match binding for the same protocol type. Based on these binding relationships, a complete association identifier mapping table is constructed. This mapping table clearly defines all associated cases, association levels, and reuse priorities for each archived result, achieving a structured and hierarchical association between archived results and similar cases, rather than simple tag matching. This provides a clear mapping basis for subsequent retrieval, reuse, and iteration.

[0131] The constructed association identifier mapping table is loaded into the standardized detection kernel for associated storage. When the standardized detection kernel receives a new detection task, it can quickly retrieve the corresponding archived adaptation agent and similar detection cases based on the scenario parameters of the device under inspection through the association identifier mapping table. This enables rapid invocation or generation of adaptation agents without the need for developing device detection and adaptation logic from scratch. Simultaneously, the associated storage information, the current archiving results, and the corresponding similar detection cases are integrated and bound together to complete the final standardized archiving. The archived content not only includes the adaptation agent unit itself but also its entire lifecycle traceability information, optimization history, adaptation scenarios, associated cases, and detection results—a complete, searchable, reusable, and iterative knowledge base for substation secondary equipment detection adaptation. As detection tasks are continuously executed, archived content accumulates, the knowledge base is continuously improved, and the adaptation capabilities of the standardized detection kernel are continuously enhanced. Ultimately, this achieves standardized, automated, and high-security detection of all types, manufacturers, and versions of secondary equipment in substations, completely solving the industry pain points of poor coupling, low reusability, and high security risks associated with traditional detection methods.

[0132] Please see Figure 2 The third embodiment of the present invention provides:

[0133] A secondary equipment testing system for a substation, wherein the system comprises:

[0134] The detection module is used to pre-build a standardized detection kernel that is completely decoupled from the firmware version, adapt standardized generation rules, and power safety-level security interaction sandbox specifications. Simultaneously, before the detection starts, based on the security interaction sandbox specifications, it sends a minimum privilege probe instruction set to the secondary device under test through standard power constraints to detect the protocol interaction characteristics, instruction mapping characteristics, and data format characteristics of the secondary device under test.

[0135] The construction module is used to generate a uniquely matched dedicated adapter unit that matches the tested secondary device according to the standardized generation rules based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics, and to load the dedicated adapter unit into the security interaction sandbox to build a bidirectional communication link between the standardized detection kernel and the tested secondary device.

[0136] The output module is used to output a general detection task set through the standardized detection kernel, and simultaneously generate execution timing and result parsing rules adapted to the general detection task set through the dedicated adaptation proxy unit.

[0137] The processing module is used to complete the full automated detection of the tested secondary device based on the execution timing and the result parsing rules. Simultaneously, after the detection is completed, based on the bidirectional communication link, the standardized detection kernel archives the dedicated adaptation agent unit according to the detection results for direct invocation in subsequent detection of devices of the same model and firmware version.

[0138] Furthermore, the building module is specifically used for:

[0139] Based on the principle of least privilege for the security protection of power secondary systems, the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics are compared with the standard interaction baseline to eliminate unauthorized features, and authorized features are simultaneously selected according to the execution boundary of the detection task.

[0140] Based on the aforementioned authorization features, an adaptation logic framework is constructed that includes a standard interaction domain and a firmware-specific adaptation domain, wherein the standard interaction domain and the firmware-specific adaptation domain are completely isolated.

[0141] The adaptation logic framework is verified in a closed loop through the secure interaction sandbox. After the verification is passed, a unique and tamper-proof digital signature is added to the tested secondary device to generate the corresponding exclusive adaptation proxy unit.

[0142] Furthermore, the building module is specifically used for:

[0143] After verification, the unique hash value corresponding to the authorized feature, the bidirectional conversion rule of the adaptation logic framework, and the minimum permission boundary parameter of the detection task are extracted, and a unique root digest adapted to the tested secondary device is generated simultaneously by combining the national cryptographic algorithm.

[0144] Based on the unique root digest, a cross-validated tamper-proof digital signature is generated that corresponds one-to-one with the dual-domain structure of the adaptation logic framework. The tamper-proof data signature is divided into a main signature dedicated to the standard interaction domain and a secondary signature dedicated to the firmware-specific adaptation domain. The main signature and the secondary signature are cross-validated, and if any domain logic is tampered with, both signatures become invalid simultaneously.

[0145] The tamper-proof digital signature is verified throughout its entire lifecycle to generate a traceability identifier bound to the unique root digest. Simultaneously, the adaptation logic framework is encapsulated based on the traceability identifier to generate the corresponding dedicated adaptation proxy unit.

[0146] Furthermore, the building module is specifically used for:

[0147] Before loading, a trusted execution domain is pre-built inside the security interaction sandbox based on the minimum permission boundary of the detection task, and an initial trusted token corresponding to the detection task is generated synchronously according to the trusted execution domain.

[0148] The dedicated adaptation agent unit is subjected to full trust measurement, and the measurement results are simultaneously merged with the initial trust token to generate the corresponding dedicated running token.

[0149] The dedicated adaptation proxy unit is loaded into the trusted execution domain, and independent sub-tokens that are cross-endorsed with the dedicated running token are generated for the standard interaction domain and the firmware dedicated adaptation domain, respectively. The bidirectional communication link is constructed synchronously based on the independent sub-tokens and the dedicated running token.

[0150] Furthermore, the building module is specifically used for:

[0151] The general detection task set is decomposed into several atomic detection execution units, and the independent sub-token is simultaneously decomposed into several time-slotted token slices according to each atomic detection execution unit.

[0152] Based on several of the aforementioned time-slotted token slices, corresponding downlink command time-slot links and uplink data time-slot links are constructed, and link cross-verification is performed synchronously to form an immutable trust chain.

[0153] Configure a security and business-level linkage circuit breaker mechanism for the immutable trust chain. When any circuit breaker condition is triggered, immediately invalidate all tokens and close the link port to generate a full link operation rule. Simultaneously bind the full link operation rule with the dedicated operation token to generate the bidirectional communication link.

[0154] Furthermore, the processing module is specifically used for:

[0155] Extract the adaptation deviation data corresponding to the dedicated adaptation agent unit from the detection results, and generate corresponding optimization instructions by combining the working logs of the security interaction sandbox.

[0156] The bidirectional communication link is optimized by the optimization instructions to generate a corresponding target communication link. Simultaneously, the transferable general adaptation features in the dedicated adaptation proxy unit are extracted through the target communication link, and after standardized encapsulation, separation and archiving are performed to output the corresponding archiving results.

[0157] The archived results are linked with test cases of similar equipment to complete the corresponding standardized archiving.

[0158] Furthermore, the processing module is specifically used for:

[0159] Based on the security interaction sandbox specification, the corresponding scene parameters in the detection cases are extracted and compared with the corresponding parameters in the archived results to filter out detection cases of the same type.

[0160] Based on the standardized generation rules, corresponding association identifiers are generated for the archived results and the detection cases of the same type, and the association identifiers are bound in a synchronous manner to construct an association identifier mapping table.

[0161] The associated identifier mapping table is loaded into the standardized detection kernel for associated storage, and the associated storage information, the archived results, and the similar detection cases are bound simultaneously to complete the standardized archiving.

[0162] The fourth embodiment of the present invention provides a computer, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the secondary equipment detection method for substations as described above.

[0163] The fifth embodiment of the present invention provides a readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the secondary equipment detection method for substations as described above.

[0164] In summary, the secondary equipment testing method and system for substations provided in the above embodiments of the present invention can complete the timing and parsing rule adaptation of general testing tasks through dedicated adaptation agents, realize fully automated testing, and significantly improve testing efficiency and accuracy. At the same time, the standardized archiving and reuse of adaptation agent units further compresses the testing cycle of equipment of the same model and version, and constructs an automated testing system for power secondary equipment that takes into account universality, adaptability, security and efficiency.

[0165] It should be noted that the above modules can be functional modules or program modules, and can be implemented through software or hardware. For modules implemented through hardware, the above modules can reside in the same processor; or the above modules can be located in different processors in any combination.

[0166] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0167] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0168] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0169] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0170] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the appended claims.

Claims

1. A method for testing secondary equipment in a substation, characterized in that, The method includes: A pre-built, standardized detection kernel completely decoupled from the firmware version, adapted standardized generation rules, and power safety-grade security interaction sandbox specifications are used to send a minimum privilege probe instruction set to the secondary device under test through standard power constraints before the detection starts, based on the security interaction sandbox specifications, in order to detect the protocol interaction characteristics, instruction mapping characteristics, and data format characteristics of the secondary device under test. Based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics, a uniquely matched dedicated adapter unit is generated according to the standardized generation rules and is simultaneously loaded into the security interaction sandbox to construct a bidirectional communication link between the standardized detection kernel and the tested secondary device. The standardized detection kernel outputs a general detection task set, and the dedicated adaptation proxy unit simultaneously generates execution timing and result parsing rules adapted to the general detection task set. Based on the execution timing and the result parsing rules, the full automated detection of the tested secondary device is completed. Simultaneously, after the detection is completed, based on the bidirectional communication link, the standardized detection kernel archives the dedicated adaptation agent unit according to the detection results for direct invocation in subsequent detection of devices of the same model and firmware version. The step of generating a uniquely matched dedicated adapter unit that matches the tested secondary device according to the standardized generation rules based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics includes: Based on the principle of least privilege for the security protection of power secondary systems, the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics are compared with the standard interaction baseline to eliminate unauthorized features, and authorized features are simultaneously selected according to the execution boundary of the detection task. Based on the aforementioned authorization features, an adaptation logic framework is constructed that includes a standard interaction domain and a firmware-specific adaptation domain, wherein the standard interaction domain and the firmware-specific adaptation domain are completely isolated. The adaptation logic framework is verified in a closed loop through the secure interaction sandbox. After the verification is passed, a unique and tamper-proof digital signature is added to the tested secondary device to generate the corresponding exclusive adaptation proxy unit.

2. The method for testing secondary equipment in a substation according to claim 1, characterized in that, The step of adding a unique, tamper-proof digital signature to the tested secondary device after successful verification, in order to generate the corresponding dedicated adaptation proxy unit, includes: After verification, the unique hash value corresponding to the authorized feature, the bidirectional conversion rule of the adaptation logic framework, and the minimum permission boundary parameter of the detection task are extracted, and a unique root digest adapted to the tested secondary device is generated simultaneously by combining the national cryptographic algorithm. Based on the unique root digest, a cross-validated tamper-proof digital signature is generated that corresponds one-to-one with the dual-domain structure of the adaptation logic framework. The tamper-proof digital signature is divided into a main signature dedicated to the standard interaction domain and a secondary signature dedicated to the firmware-specific adaptation domain. The main signature and the secondary signature are cross-validated, and if any domain logic is tampered with, both signatures become invalid simultaneously. The tamper-proof digital signature is verified throughout its entire lifecycle to generate a traceability identifier bound to the unique root digest. Simultaneously, the adaptation logic framework is encapsulated based on the traceability identifier to generate the corresponding dedicated adaptation proxy unit.

3. The method for testing secondary equipment in a substation according to claim 2, characterized in that, The step of loading the dedicated adaptation proxy unit into the secure interaction sandbox to construct a bidirectional communication link between the standardized detection kernel and the tested secondary device includes: Before loading, a trusted execution domain is pre-built inside the security interaction sandbox based on the minimum permission boundary of the detection task, and an initial trusted token corresponding to the detection task is generated synchronously according to the trusted execution domain. The dedicated adaptation agent unit is subjected to full trust measurement, and the measurement results are simultaneously merged with the initial trust token to generate the corresponding dedicated running token. The dedicated adaptation proxy unit is loaded into the trusted execution domain, and independent sub-tokens that are cross-endorsed with the dedicated running token are generated for the standard interaction domain and the firmware dedicated adaptation domain, respectively. The bidirectional communication link is constructed synchronously based on the independent sub-tokens and the dedicated running token.

4. The method for testing secondary equipment in a substation according to claim 3, characterized in that, The step of constructing the bidirectional communication link based on the independent sub-token and the dedicated running token includes: The general detection task set is decomposed into several atomic detection execution units, and the independent sub-token is simultaneously decomposed into several time-slotted token slices according to each atomic detection execution unit. Based on several of the aforementioned time-slotted token slices, corresponding downlink command time-slot links and uplink data time-slot links are constructed, and link cross-verification is performed synchronously to form an immutable trust chain. Configure a security and business-level linkage circuit breaker mechanism for the immutable trust chain. When any circuit breaker condition is triggered, immediately invalidate all tokens and close the link port to generate a full link operation rule. Simultaneously bind the full link operation rule with the dedicated operation token to generate the bidirectional communication link.

5. The method for testing secondary equipment in a substation according to claim 1, characterized in that, The step of standardizing and archiving the dedicated adaptation proxy unit based on the detection results through the standardized detection kernel, based on the bidirectional communication link, includes: Extract the adaptation deviation data corresponding to the dedicated adaptation agent unit from the detection results, and generate corresponding optimization instructions by combining the working logs of the security interaction sandbox. The bidirectional communication link is optimized by the optimization instructions to generate a corresponding target communication link. Simultaneously, the transferable general adaptation features in the dedicated adaptation proxy unit are extracted through the target communication link, and after standardized encapsulation, separation and archiving are performed to output the corresponding archiving results. The archived results are linked with test cases of similar equipment to complete the corresponding standardized archiving.

6. The method for testing secondary equipment in a substation according to claim 5, characterized in that, The step of linking the archived results with test cases of similar devices to complete the corresponding standardized archiving includes: Based on the security interaction sandbox specification, the corresponding scene parameters in the detection cases are extracted and compared with the corresponding parameters in the archived results to filter out detection cases of the same type. Based on the standardized generation rules, corresponding association identifiers are generated for the archived results and the detection cases of the same type, and the association identifiers are bound in a synchronous manner to construct an association identifier mapping table. The associated identifier mapping table is loaded into the standardized detection kernel for associated storage, and the associated storage information, the archived results, and the similar detection cases are bound simultaneously to complete the standardized archiving.

7. A secondary equipment testing system for substations, characterized in that, The system is used to implement the secondary equipment testing method for substations as described in any one of claims 1 to 6, the system comprising: The detection module is used to pre-build a standardized detection kernel that is completely decoupled from the firmware version, adapt standardized generation rules, and power safety-level security interaction sandbox specifications. Simultaneously, before the detection starts, based on the security interaction sandbox specifications, it sends a minimum privilege probe instruction set to the secondary device under test through standard power constraints to detect the protocol interaction characteristics, instruction mapping characteristics, and data format characteristics of the secondary device under test. The construction module is used to generate a uniquely matched dedicated adapter unit that matches the tested secondary device according to the standardized generation rules based on the protocol interaction characteristics, the instruction mapping characteristics, and the data format characteristics, and to load the dedicated adapter unit into the security interaction sandbox to build a bidirectional communication link between the standardized detection kernel and the tested secondary device. The output module is used to output a general detection task set through the standardized detection kernel, and simultaneously generate execution timing and result parsing rules adapted to the general detection task set through the dedicated adaptation proxy unit. The processing module is used to complete the full automated detection of the tested secondary device based on the execution timing and the result parsing rules. Simultaneously, after the detection is completed, based on the bidirectional communication link, the standardized detection kernel archives the dedicated adaptation agent unit according to the detection results for direct invocation in subsequent detection of devices of the same model and firmware version.

8. A computer comprising a memory, a processor, and a computer program stored in the memory and capable of running on the processor, characterized in that, When the processor executes the computer program, it implements the secondary equipment detection method for substations as described in any one of claims 1 to 6.

9. A readable storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the secondary equipment detection method for substations as described in any one of claims 1 to 6.