Power control service interaction trusted data flow twin modeling and security detection method

By constructing a trusted data flow model of digital twin for power control business interaction, the problem of trustworthiness verification at the temporal logic level in power control business security detection was solved, enabling end-to-end trusted determination of power control operations and identification of advanced threats, thereby improving the reliability and security of the system.

CN122120040AInactive Publication Date: 2026-05-29ZHEJIANG TENGLONG WANGAN TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG TENGLONG WANGAN TECH CO LTD
Filing Date
2026-04-29
Publication Date
2026-05-29
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing power control security detection technologies lack credibility verification at the time-series logic level, making it impossible to achieve end-to-end credibility determination from instruction transmission to equipment execution. Furthermore, they lack a unified modeling method for multi-dimensional constraints, making it difficult to identify advanced persistent threats and balancing real-time performance with accuracy.

Method used

A trusted digital twin data flow model for power control business interaction is constructed. By combining the operation control sequence logic model, communication data flow model, and finite state machine model with power safety rules and wiring logic, communication messages are collected and compared in real time to generate a time-series-logic compliant operation rule sequence set, thereby achieving full-chain deep security detection of power control operations.

Benefits of technology

It achieves dual verification of power control operations, improves the reliability and security of control operations, is applicable to a variety of complex operating scenarios, and enhances the reliability and intelligence level of industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120040A_ABST
    Figure CN122120040A_ABST
Patent Text Reader

Abstract

The application discloses a kind of electric power control service interaction trusted data stream twin modeling and safety detection method, comprising: according to electric power safety rule and electric power wiring logic, build operation control sequential logic model;Extract the communication behavior characteristics and message interaction relationship corresponding to each operation control step, form communication data flow model;Based on communication data flow model and operation control sequential logic model, build communication finite state machine model and measure operation control finite state machine model;Configure instruction interaction timing constraint, build timing logic compliance operation rule sequence set, form trusted data flow model;Real-time acquisition of communication message in electric power monitoring system, real-time instruction, communication characteristics, point data and sending timing information are obtained by parsing, compared with trusted data flow model to carry out safety detection.The application can effectively detect the timing violation and logic violation behavior in electric power control service, improve the safety of electric power system operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power system security detection technology, and in particular to a reliable data flow twin modeling and security detection method for power control business interactions. Background Technology

[0002] With the deepening of the digital transformation of the power system, the network security protection of power monitoring systems faces unprecedented challenges. Traditional power control system security protection mainly relies on dedicated networks, security partitions, and boundary isolation strategies. However, with the construction of smart grids and the increasing demand for remote control, the interconnection between power monitoring systems and external networks is constantly expanding, and the attack surface is continuously increasing. Existing security protection technologies, mainly through firewalls, intrusion detection systems, and vertical encryption devices, can effectively ensure the integrity, confidentiality, and identity trustworthiness of communication channels, but they still have significant shortcomings in terms of deep security detection capabilities at the control business logic level.

[0003] In recent years, digital twin technology has received widespread attention and application in the field of industrial control system security protection. However, existing technologies still have significant shortcomings in the security detection of power control operations. First, existing security detection mechanisms mainly focus on the integrity and authentication of the communication layer, preventing unauthorized access and data tampering through firewalls, vertical encryption, or message signing, but generally neglect the credibility verification of control operations at the temporal logic level. Second, existing technologies lack a unified modeling method that can integrate communication behavior, equipment status, power security rules, and temporal constraints, making it impossible to establish a complete mapping relationship from communication commands to equipment execution. Third, traditional security detection methods mainly focus on the question of "whether the command has been transmitted," while lacking the end-to-end credibility judgment capability of "whether the equipment has actually moved and whether it has moved correctly," making it difficult to identify advanced persistent threats targeting control logic. In addition, existing digital twin modeling methods lack comprehensive consideration of multi-dimensional constraints such as the five-prevention logic, operation timing, and equipment state changes in power control business scenarios, and cannot construct a truly reliable data flow model that reflects the characteristics of power control operations. Finally, existing technologies struggle to balance real-time performance and accuracy, lacking efficient real-time detection algorithms to handle the large volume of communication messages in power monitoring systems while ensuring both accuracy and timeliness of detection.

[0004] Therefore, there is an urgent need for a reliable data flow modeling and security detection method that can deeply integrate the characteristics of power control business, support multi-dimensional constraint joint verification, and have efficient real-time processing capabilities. Summary of the Invention

[0005] In view of this, this invention proposes a digital twin trusted data flow modeling and security detection method for power control business interaction. This method addresses the technical problem that existing power grid control business security detection mechanisms generally neglect the credibility verification of control operations at the temporal logic level, lack a unified modeling method that integrates communication behavior, equipment status, five-prevention logic, and temporal constraints, and are unable to achieve end-to-end trusted determination from "whether the instruction has been transmitted" to "whether the equipment has actually moved and whether it has moved correctly". This invention enables in-depth security detection of the entire power control operation chain.

[0006] In a first aspect, this application provides a method for modeling and security detection of trusted data flow of digital twins for power control business interaction, including: constructing an operation control sequence logic model of power control business according to power safety rules and power wiring logic, wherein the model defines multiple operation control steps connected in a preset order and their preconditions;

[0007] For each operation control step in the operation control sequence logic model, extract its corresponding communication behavior features and message interaction relationships to form an operation control digital twin communication data flow model.

[0008] Based on the communication data flow model, the transmission timing and communication control fields of the instruction message are extracted, and a communication finite state machine model is constructed.

[0009] Based on the communication data flow model and the operation control sequence logic model, the point data features, operation preconditions and post-execution states in the instruction message are extracted to construct a measurement operation control finite state machine model.

[0010] Based on the operation control sequence logic model, communication data flow model, communication finite state machine model and measurement operation control finite state machine model, the timing constraints of instruction interaction are configured, a timing-logic compliant operation rule sequence set is constructed, and a digital twin trusted data flow model for control business interaction is formed.

[0011] The system collects communication messages from the power monitoring system in real time, parses them to obtain real-time commands, communication characteristics, location data and transmission timing information, and compares them with a trusted data flow model for security detection, and issues alarms for non-compliance.

[0012] Secondly, the present invention provides a trusted data flow modeling and security detection device for digital twin of power control business interaction, comprising: an operation logic modeling module; extracting the operation sequence and its preconditions of power control business according to power safety rules and power wiring logic, and forming a digital twin operation control sequence logic model for power control business interaction;

[0013] Communication data stream extraction module: For each operation control step in the operation control sequence logic model, extract the communication behavior characteristics and message interaction relationships of the corresponding operation instructions to form a digital twin communication data stream model for power control business interaction operation control.

[0014] A communication finite state machine construction module is used to extract the transmission timing and communication control fields of instruction messages based on the communication data flow model, and to construct a digital twin communication finite state machine model for power control business interaction.

[0015] The module constructs a finite state machine for operation; based on the communication data flow model and the operation control sequence logic model, it extracts the point data features, operation preconditions and post-execution states from the instruction message, and constructs a finite state machine model for power control business interaction digital twin measurement operation control.

[0016] Trusted rule generation module: Based on the operation control sequence logic model, communication data flow model, communication finite state machine model and measurement operation control finite state machine model, configure the timing constraints of instruction interaction, construct a timing-logic compliant operation rule sequence set, and form a digital twin trusted data flow model for control business interaction;

[0017] Real-time detection and alarm module: Collects communication messages in the power monitoring system in real time, parses them to obtain real-time commands, communication characteristics, point data and transmission timing information, compares them with the trusted data flow model and performs security detection, and alarms are triggered for non-compliance.

[0018] Thirdly, this application provides a trusted data flow twin modeling and security detection system for power control business interaction, characterized in that it includes: a dispatch master station, an intelligent remote control device, a measurement and control protection device, a safety and stability control device, an automatic switching device for backup power supply, a reactive power compensation device, a step-out disconnection device, an intelligent terminal, and a trusted data flow modeling and security detection device for digital twin of power control business interaction.

[0019] The device possesses multi-channel acquisition capabilities, with multiple communication connections to the intelligent remote control and dispatch master station interconnection switch, the station control layer network, and the process layer network. It is used to collect in real-time communication messages between the dispatch master station and the intelligent remote control device, between the intelligent remote control device and the measurement and control protection device, between the safety and stability control device / backup power automatic switching device / reactive power compensation device / out-of-step disconnection device and the measurement and control protection device, and between the measurement and control protection device and the intelligent terminal. It also executes a power control business interaction digital twin trusted data flow modeling and security detection method. The device connects to the mirror ports of the station control layer and bay layer core switches via multiple channels to collect network messages in a bypass mode, and performs in-depth analysis and detection of the collected IEC104, MMS, GOOSE, and SV protocol messages.

[0020] The beneficial effects of the technical solution of the present invention, which provides a trusted data flow modeling and security detection method for digital twins in power control business interactions, include at least the following:

[0021] By constructing a communication finite state machine and a measurement operation control finite state machine, trusted data flow modeling is performed from two dimensions: compliance of communication behavior and correctness of physical operation logic. This breaks through the limitations of traditional security detection, which only focuses on message legality or isolated monitoring of equipment status. It achieves dual verification of "whether the command is correctly issued" and "whether the equipment is performing genuine and compliant actions," significantly improving the credibility of control operations. The five-prevention logic of electrical equipment is formalized into the preconditions of operation steps. Combined with typical equipment action delays, a structured time-series-logic compliance operation rule sequence set is constructed, upgrading security detection from "static rule matching" to "dynamic process trusted verification." Based on substation wiring logic and typical control scenarios, a configurable and scalable digital twin operation control model is constructed, deeply coupling security detection rules with actual business operations. It is applicable to various complex operation scenarios, has good engineering adaptability and scalability, and significantly improves the reliability, security, and intelligence level of industrial control systems. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of this specification, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a schematic diagram of the process for modeling and security detection of trusted data streams in digital twins for power control business interactions, as provided in the embodiments of this specification.

[0024] Figure 2 This is a schematic diagram of the group summoning process provided in the embodiments of this specification.

[0025] Figure 3 This is a schematic diagram of the instruction issuance process provided in the embodiments of this specification.

[0026] Figure 4 This is a schematic diagram of the operation execution process provided in the embodiments of this specification.

[0027] Figure 5 This is a schematic diagram of the execution feedback process provided in the embodiments of this specification.

[0028] Figure 6 This is a schematic diagram of a power control business interaction digital twin trusted data flow modeling and security detection device provided in the embodiments of this specification.

[0029] Figure 7 This is a schematic diagram of a trusted data flow modeling and security detection system for power control business interaction digital twins provided in the embodiments of this specification. Detailed Implementation

[0030] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. The terms "first," "second," "third," etc., in the specification, claims, and accompanying drawings are used to distinguish different objects, not to describe a specific order. In addition, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products, or devices.

[0031] In the following description, terms such as “inner,” “outer,” “upper,” “lower,” “left,” and “right” are used only to facilitate the description of the embodiments and to simplify the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this specification.

[0032] This embodiment provides a method for trusted data flow twin modeling and security detection of power control business interactions. This method is applied to various typical power grid control business scenarios in smart substations, including but not limited to: power line closing and opening scenarios; measurement and control protection scenarios such as bus / transformer differential protection scenarios; automatic backup power supply switching scenarios; and safety and stability control scenarios, etc., to perform trusted data flow modeling and security detection of business interaction processes. Please refer to the appendix. Figure 1 The method includes at least the following steps:

[0033] Step S1: Construct a digital twin operation control sequence logic model for power control business interaction. In this embodiment, the sequence of detection, operation, and control in the target power control business scenario, as well as the preconditions that must be met for each operation, are extracted based on power safety rules and substation power wiring logic to construct a digital twin operation control sequence logic model.

[0034] The five-prevention rules for power safety include preventing accidental opening / closing of circuit breakers, preventing opening / closing of disconnectors under load, preventing closing of grounding switches while energized, preventing closing of circuit breakers with grounding wires connected, and preventing accidental entry into energized compartments. Power control operations include, but are not limited to, line closure for power supply, busbar switching, line or transformer maintenance, busbar differential protection, transformer differential protection, automatic switching of standby lines, safety and stability control, and automatic voltage regulation of transformers. It should be noted that the operation process in this embodiment must meet the topological constraints defined in the substation primary wiring logic diagram and follow the operational logic of power control operations. The execution of each operation step is premised on the satisfaction of its preconditions. For example, the disconnector can only be closed when the load current is zero, or the grounding disconnector can only be closed when the busbar is de-energized. Based on the above constraints and logic, the operation control sequence logic model is constructed. This model, in the form of step sequences, lists, sequence diagrams, or state flowcharts, fully describes the execution sequence and preconditions of the operation of circuit breakers, switches, or disconnectors involved in specific control operations, such as state detection, electrical quantity measurement, and opening / closing control. In this model, the closing or opening operation control of a complete circuit breaker / switch / disconnector is defined as an atomic operation control unit. The execution logic of this unit includes three stages: instruction issuance, operation execution, and execution feedback, which are performed sequentially.

[0035] Command issuance phase: The dispatch master station initiates operation control commands (such as closing commands) and sends them to station control layer equipment, such as intelligent remote control devices, through the IEC104 protocol. The intelligent remote control devices convert the commands and forward them to bay layer equipment, such as measurement and control devices, through the MMS protocol. The measurement and control devices finally send the commands to process layer equipment, such as intelligent terminals, through the GOOSE protocol to drive the actuators of circuit breakers, switches, or disconnectors.

[0036] Operation execution phase: The corresponding circuit breaker, switch or disconnector is driven by the intelligent terminal of the process layer equipment to complete the mechanical action.

[0037] Execution feedback phase: The process layer equipment intelligent terminal collects the real-time physical position status (such as open or closed) of circuit breakers, switches or disconnectors, and publishes it through the GOOSE protocol; the bay layer equipment measurement and control device receives this status information, determines whether the execution meets the timing requirements by combining the time window of the operation execution, and feeds back the position status and execution result to the station control layer equipment intelligent remote control device through the MMS protocol. The intelligent remote control device processes and aggregates the received information, classifies and packages it into IEC104 protocol messages (such as remote signaling and telemetry messages) and sends them back to the dispatch master station to form a closed loop.

[0038] In the above execution process, each communication interaction between the control master station, station control layer equipment, bay layer equipment, and process layer equipment is abstracted and modeled as an operation control step in the operation control sequence logic model. Multiple such steps are chained together according to the business logic sequence to form a complete control business interaction flow. For example, the following description uses the master station control power supply business of a smart substation as an example. This business involves the opening and closing operations of four disconnect switches, two circuit breakers, and three grounding disconnect switches according to a specific timing and logic. Related equipment includes the dispatch master station 1001, intelligent remote control device 1002, first measurement and control device 1003 and second measurement and control device 1004, first intelligent terminal 1005 and second intelligent terminal 1006, and first merging unit 1007 and second merging unit 1008. Please refer to the appendix. Figure 2 The key steps of its normal process are described below:

[0039] S101: Initial Status Acquisition. The dispatch master station 1001 first sends a command to the intelligent remote control device 1002 through the group call function of the IEC104 protocol to obtain the current status information of the relevant disconnectors, circuit breakers and grounding disconnectors.

[0040] S102: After parsing the instruction, the intelligent remote control device 1002 sends an acknowledgment response to the dispatch master station 1001, and at the same time converts the instruction into an MMS protocol message, which is forwarded to the first measurement and control device 1003 and the second measurement and control device 1004 respectively.

[0041] S103: The first telemetry and control device 1003 and the second telemetry and control device 1004 extract all the status information configured as the target of this group summoning from the local cache, encapsulate it into an MMS response message and return it to the intelligent remote control device 1002;

[0042] S104: The intelligent remote control device 1002 receives and parses the response from the measurement and control device, packages all the acquired status information (remote signaling information in this embodiment) into an IEC104 protocol message, and sends it to the dispatch master station 1001. After receiving the complete group call response, the dispatch master station 1001 obtains the initial status of all target devices.

[0043] S105: After obtaining the initial state and completing the safety logic verification, the dispatch master station 1001 will issue control commands to close or open the specified disconnector, circuit breaker or switch in sequence according to the process defined by the operation control sequence logic model. The subsequent command issuance, operation execution and execution feedback process follow the general interaction mode of the aforementioned three stages.

[0044] The following section uses the control cutter closure operation of the scheduling master station as an example to illustrate the implementation process of this invention. This operation includes three stages: instruction issuance, operation execution, and execution feedback. The specific steps are as follows:

[0045] Appendix Figure 3 The diagram illustrates the instruction issuance process. The dispatch master station 1001 sends an operation control instruction to the intelligent remote control device 1002 to close the disconnect switch 2001 via the IEC104 protocol. The intelligent remote control device 1002 receives the IEC104 protocol message, converts it into an MMS protocol message, and forwards it to the first monitoring and control device 1003. Upon receiving the MMS protocol message, the first monitoring and control device 1003 verifies the status of relevant circuit breakers, disconnect switches, and grounding disconnect switches in its local cache according to the five-prevention logic rules. If the verification is successful, it converts the message into a GOOSE protocol message and forwards it to the first intelligent terminal 1005, simultaneously recording the timestamp t0 of the instruction issuance.

[0046] Appendix Figure 4 The diagram illustrates the operation execution process. The first intelligent terminal 1005 parses and obtains the closing operation control command of the knife switch 2001, and drives its actuator to perform the closing action.

[0047] Appendix Figure 5 The diagram illustrates the execution feedback process. The first intelligent terminal 1005 collects the position status information of the disconnector 2001 in real time. After the closing operation is completed, the position status of the disconnector 2001 changes, and the first intelligent terminal 1005 immediately generates a GOOSE message containing the new status and publishes it. The first measurement and control device 1003 subscribes to and receives the GOOSE message, records the reception timestamp t1, and parses out the position status information of the disconnector 2001. Subsequently, the first measurement and control device 1003 performs a double check: first, it determines whether the parsed position status matches the expected target status (i.e., the position); second, it calculates the action time and determines whether the timing constraint is met (e.g., t1-t0≤10 seconds). If the above states match and the time constraints are met, the first monitoring and control device 1003 packages this position status information into an MMS protocol message and reports it to the intelligent remote control device 1002. Upon receiving the message, the intelligent remote control device 1002 converts it into an IEC104 protocol message and sends it to the dispatch master station 1001, thus completing a full command-execution-feedback closed loop. If the verification fails, the corresponding exception handling and alarm procedures are triggered.

[0048] The subsequent steps, such as disconnecting the grounding switch, controlling the dispatching master station, and disconnecting the grounding switch controlled by the dispatching master station, are similar in operation and control process to the aforementioned switch closure operation, all including the three stages mentioned above, and will not be elaborated further here. All steps are connected in series according to the operation sequence, thus forming the digital twin operation control sequence logic model of the master station control power supply service.

[0049] Step S2: Construct a digital twin communication data flow model for power control business interaction operation control. Based on the constructed operation control sequence logic model, this step further extracts the corresponding communication behavior characteristics for each operation control step, combined with the actual operation control scheme and business logic of the substation power monitoring system, in order to construct a digital twin communication data flow model.

[0050] Specifically, for each operation control step, communication behavior characteristic information of the messages used to send equipment status detection, electrical quantity measurement, and equipment control commands is extracted. This characteristic information includes:

[0051] Communication subject identifiers: source / destination IP addresses and MAC addresses of the message sender and receiver;

[0052] Protocol types include: IEC04 protocol for information exchange between the scheduling master station and the intelligent remote control device; MMS protocol for data service between the intelligent remote control device and the measurement and control device; GOOSE protocol for fast status / command transmission between the measurement and control device and the intelligent terminal; and SV protocol for the merging unit to transmit sampled values ​​to the measurement and control device.

[0053] Command semantic information: command code, message request / response / acknowledgment type;

[0054] Business data characteristics: Measurement, operation or control point numbers and data values ​​obtained from the message. The point numbers are, for example, the common address and information object address in the IEC104 protocol, or the object reference path in the MMS protocol; the data values ​​are, for example, the device location status, voltage value or current value.

[0055] It should be noted that the electrical analog quantity measurements such as equipment status detection values, voltage, current, and power, as well as equipment control commands, under different business scenarios, are exchanged between different power equipment through power-specific protocol messages, including IEC104, MMS, GOOSE, and SV. Specifically, the open / closed status detection values ​​of circuit breakers / switches / disconnectors are published by the intelligent terminal via the GOOSE protocol. When the intelligent terminal detects a change in the status value, it triggers a GOOSE sending event, uploading the status to the monitoring and control device in real time. The monitoring and control device subscribes to the corresponding GOOSE control block. When it receives the GOOSE protocol message, it immediately updates the status model of the content and actively uploads it to the intelligent remote control device in real time through the MMS reporting service. The intelligent remote control device receives the MMS report message, parses out the status value and timestamp information, maps it to the IEC104 remote signaling point table, and immediately actively uploads it to the dispatch master station via the IEC104 protocol message. Analog measurements such as voltage, current, and power are transmitted to the measurement and control device via the SV protocol at a sampling rate of 4kHz or 12.8kHz by the merging unit or an intelligent terminal integrating this function. The measurement and control device receives the high-frequency analog measurements and updates them in real time. Under normal conditions, data is actively uploaded to the intelligent remote control device via the MMS reporting mechanism at a cycle of 2s to 5s. Additionally, when the analog quantity change exceeds the preset dead zone or the data quality changes, the measurement and control device also triggers active data upload. Upon receiving an MMS report message or when the internal timer expires, the intelligent remote control device packages the analog measurements into an IEC104 protocol message and actively uploads it to the dispatch master station. Circuit breaker / switch / disconnector closing / opening control commands are issued from the dispatch master station to the intelligent remote control device via the IEC104 protocol, then forwarded to the measurement and control device via the station's MMS, and finally forwarded to the intelligent terminal for execution via GOOSE.

[0056] For example, taking the operation of closing a disconnector controlled by the dispatch master station in a smart substation as an example, this illustrates the specific method for extracting communication behavior feature information for each operation control step. The operation process mainly includes two communication phases: instruction issuance and execution feedback. The following details each step:

[0057] First, in the instruction issuance phase, the issuance of closure control instructions involves the following steps:

[0058] Step S201: The dispatch master station issues a remote control selection command. The dispatch master station 1001 sends a remote control selection command for closing the disconnect switch 2001 to the intelligent remote control device 1002. This step uses the IEC104 protocol. The communication behavior feature information to be extracted is shown in Table 1.

[0059] Table 1. Communication behavior characteristics to be extracted when the dispatch master station sends a closed disconnector operation control command to the intelligent remote control device.

[0060] .

[0061] Step S202: The intelligent remote control device returns a selection confirmation. The intelligent remote control device 1002 returns a remote control selection confirmation to the dispatch master station 1001, and the message also uses the IEC104 protocol. The categories of communication behavior feature information to be extracted are the same as in step S201, but the specific feature values ​​change accordingly.

[0062] Step S203: The dispatch master station issues a remote control execution command. The dispatch master station 1001 sends a remote control execution command to the intelligent remote control device 1002 to close the disconnect switch 2001. The categories of communication behavior feature information to be extracted are the same as in step S201, but the specific feature values ​​change accordingly.

[0063] Step S204: The intelligent remote control device forwards the execution command to the monitoring and control device. The intelligent remote control device 1002 forwards the remote control execution command to the first monitoring and control device 1003. The message in this step uses the MMS protocol. According to the protocol specification, the communication behavior feature information to be extracted is shown in Table 2.

[0064] Table 2. Communication behavior characteristics to be extracted when the intelligent remote control device forwards the remote control execution command for closing the disconnect switch to the monitoring and control device.

[0065] .

[0066] Step S205: The monitoring and control device forwards the execution command to the intelligent terminal. The first monitoring and control device 1003 forwards the remote control execution command for closing the disconnect switch 2001 to the first intelligent terminal 1005. This step uses the GOOSE protocol for rapid message delivery. The communication behavior feature information to be extracted is shown in Table 3.

[0067] Table 3. Communication behavior feature information to be extracted when the monitoring and control device forwards the remote control execution command for closing the disconnect switch to the intelligent terminal.

[0068] .

[0069] Secondly, during the feedback phase, the upload of the switch position status detection values ​​is involved, and the sequence of steps is as follows:

[0070] Step S206: The intelligent terminal publishes the position status of the disconnector. After the operation is completed, the first intelligent terminal 1005 publishes the closed position status information of disconnector 2001 via the GOOSE protocol. Based on the protocol specifications, the communication behavior feature information to be extracted is shown in Table 4.

[0071] Table 4. Communication behavior features to be extracted when intelligent terminals release switch closing position status information.

[0072] .

[0073] Step S207: The monitoring and control device forwards the position status to the intelligent remote control device. After receiving the GOOSE status message, the first monitoring and control device 1003 immediately reports the closed position status value of the disconnector 2001 to the intelligent remote control device 1002 via the MMS reporting service. Based on the protocol specifications, the communication behavior feature information to be extracted is shown in Table 5.

[0074] Table 5. Communication behavior characteristics to be extracted when the monitoring and control device forwards the disconnector closing position status information to the intelligent remote control device.

[0075] .

[0076] Step S208: The intelligent remote control device forwards the disconnector closing position status information to the dispatch master station. The intelligent remote control device 1002 parses and reconstructs the received MMS report, converts it into an IEC104 protocol message, and finally reports it to the dispatch master station 1001, completing the closed-loop feedback. The categories of communication behavior feature information to be extracted in this step are the same as in step S201, but the specific feature values ​​change accordingly.

[0077] Based on the above process, following the sequence of control service steps, the communication behavior feature information extracted from each step is sequentially associated and combined to construct the interactive operation control digital twin communication data flow model corresponding to the control service instance. It should be noted that for analog quantity measurements such as voltage, current, and power, these are typically sampled at high frequency by the merging unit and periodically published via the SV protocol. The measurement and control device calculates the engineering quantities based on the SV stream and then periodically and proactively reports them to the intelligent remote control device via the MMS service, and further reports them to the dispatch master station. Since analog quantity uploading is an independent process driven by periodicity or change, and has no dependency on operation control events, it can occur at any stage of the operation control process. Because this part of the operation mainly involves changes in analog quantity measurements that may affect the judgment of preconditions, but has no impact on the normal operation control process of circuit breakers, switches, and disconnectors, it is only necessary to ensure that the system normally acquires analog quantity measurements; there is no need to embed the communication behavior feature information into the power control service interactive operation control digital twin communication data flow model.

[0078] Step S3: Construct a digital twin communication finite state machine model for power control business interaction. Based on the communication data flow model constructed in Step S2, this step extracts the message transmission sequence and the communication control fields and state information contained in request, response, or acknowledgment messages for each data record, and constructs a communication finite state machine model accordingly. Specifically, the construction process of the communication finite state machine includes the following steps:

[0079] Define a communication state set. Based on the extracted message transmission timing information and communication state information, the business process is divided into multiple different communication stages, thereby defining a communication state set. Each state in the state set represents a stable logical stage of the control service in the communication interaction, rather than an instantaneous action. For example, the "Waiting for Selection Confirmation" state indicates that a remote selection command has been issued and is waiting to receive a response confirming the transmission reason as activation. This state will continue until a state transition is triggered.

[0080] Define the communication input event set. External signals that may trigger state transitions are used as the communication input event set, which mainly includes two categories: first, received communication messages, such as IEC104 protocol remote control commands, MMS protocol operation responses, or GOOSE protocol status feedback; second, timeout signals triggered by internal timers, used to detect communication delays or missing signals.

[0081] Define state transition conditions. The logical criteria for state transitions are determined by combining the input events and the extracted communication control fields. In addition to the source / destination MAC address and IP address of the communication device, the transition conditions are pre-configured with different application layer control fields as matching criteria based on different current states and related protocol types. For example, for the IEC104 protocol, type identifier, transmission reason, common address, and information object address can be used as additional state transition judgment information; where the type identifier is used to distinguish remote control, remote signaling, group call, etc.; the transmission reason is used to identify semantics such as request, confirmation, and termination; the common address is used by the master station to distinguish different substations; and the information object address is used to locate specific control or status points. For the MMS protocol, service type, call identifier, operation result, and object reference path can be used as additional state transition judgment information; where the service type is used to identify the operation request; the call identifier is used to uniquely associate the request and response; the operation result includes success, failure, and an additional reason code; and the object reference path is used to accurately locate the device model node. The state transition conditions also require corresponding timing constraints, which must simultaneously satisfy both protocol semantic matching and timing compliance conditions. Specifically, the protocol semantic matching condition requires that when the input event is a communication message, the values ​​of one or more predetermined communication control fields parsed from the message must match the expected field values ​​preset for the transition rule. The timing compliance condition requires that the occurrence time of the input event must fall within a preset time window determined based on the occurrence time of a previous related event. For example, to transition to the next normal state from a state waiting to execute a command, it is not only required to receive an IEC104 message with communication behavior characteristic information matching preset values ​​(e.g., type identifier C_DC_NA_1, information object address 1001, Select=false), but also that the message arrives within a specified time, such as 10 seconds, after the selection command is issued; otherwise, it is considered an illegal operation, triggering the transition to an abnormal state.

[0082] Define the initial state and the final state. The initial state of the communication finite state machine is set to the idle state, representing that the system has not participated in any control command interaction and is in a standby state; the final state includes a successful communication state and several abnormal final states, used to identify the final communication result of the operation. Among them, abnormal final states include timeout errors, protocol loss, and five-prevention interlocking.

[0083] For example, taking the remote control closing of disconnect switches by the dispatch master station in a smart substation as an example, the construction and operation process of the communication finite state machine is explained. First, based on the communication data flow model, and according to the extracted message transmission timing information and communication state information, the communication state set of this service is divided and defined. For example, this includes S0 (idle state), S1 (waiting for selection confirmation), S2 (waiting for command execution), ...Sn (communication successful), and abnormal states such as E1 (timeout error), E2 (protocol loss), and E3 (five-prevention interlocking). Second, the state transition conditions are designed. Taking the transition from state S1 (waiting for selection confirmation) to state S2 (waiting for command execution) as an example, the transition conditions must be met simultaneously: within a preset time window, an IEC104 protocol message is received with the MAC and IP addresses of the source device (intelligent remote control device 1002) and the destination device (dispatch master station), and its type identifier is dual-point remote signaling M_DP_NA_1, 1; the transmission reason is 7, where 7 indicates activation confirmation; the common address is 1, indicating the current substation; and the information object address is 1001, representing the control point of disconnector 2001. Communication input events are the system receiving a message or receiving a timeout signal. The state transition process can be implemented through a state transition table, decision tree, or rule engine. According to the business logic, when the normal transition conditions are met, the state transitions sequentially from S0 to Sn; if abnormal transition conditions are met (such as timeout or field mismatch), the current state jumps to the corresponding abnormal state E1, E2, or E3. For example, the system is currently in state S1 (waiting for selection confirmation). Within the specified time, the system receives an IEC104 protocol message, triggering a transition condition check. The system parses the message, obtaining field values ​​such as source / destination address, type identifier, transmission reason, and information object address, and compares them with the transition conditions preset for state S1. If all fields match and the timeout period has not expired, the state transition condition is met, and the system enters state S2 (waiting for command execution). In this way, a digital twin communication finite state machine model is constructed for the target control service.

[0084] Step S4: Construct a digital twin finite state machine model for power control business interaction measurement operation control. Based on the communication data flow model constructed in Step S2, this step further extracts business semantic features related to operation intent, equipment status, and electrical environment to construct the measurement operation control finite state machine model, focusing on the reliability of control operation execution at the physical device level.

[0085] Specifically, the modeling process includes the following steps: First, extracting the service feature information of the instruction message from the data records associated with the communication data flow model constructed in step S2. The service feature information includes:

[0086] Measurement, operation, or control point numbering, such as the common address and information object address in the IEC104 protocol or the logical device / logical node / data object path in the MMS protocol;

[0087] Command values, such as circuit breaker closing command values, grounding switch opening commands, etc.;

[0088] Feedback values: such as the device's returned position status, effective voltage value, current amplitude, active power, etc.

[0089] Secondly, combining the substation primary wiring diagram and the five-prevention rules for electrical equipment, the preconditions for each measurement operation control step are formally defined. These preconditions are expressed in Boolean logic expressions; for example, the precondition allowing the circuit breaker to close can be defined as:

[0090] "Circuit breaker 2101 status == open (0)" && "Knife switch 2002 status == closed (1)" && "Grounding knife switch 2201 status == open (0)" && "Bus voltage connected to circuit breaker 2101 > 200kV".

[0091] Next, based on the operation control logic, the open / closed state of the circuit breaker, switch, or disconnector after the command is executed is determined. For electrical quantity measurements such as voltage, current, and power, as well as operation completion time and state stability, real physical feedback from the process layer after command execution is collected as the parameter basis for the operation control command execution.

[0092] Based on the above information, the elements of the finite state machine model for the measurement operation control are constructed, and the model elements include:

[0093] Measurement and Operation Control State Set: Each state in this state set represents the stable physical or logical operating condition of the power equipment during the operation process, rather than an instantaneous action. Typical states include: Pre-operation safety conditions: such as circuit breaker open, disconnector closed, no grounding, busbar energized; Permissible operation conditions: meeting the five protection requirements, waiting to be executed; Equipment operation status: such as circuit breaker closing; Successful operation final state: such as successful closing and energization, successful opening and de-energization; Abnormal states: such as refusal to operate, five protection lockout, contradictory states.

[0094] Measurement operation control input event set: The input event set includes external sensing signals that can trigger state transitions, mainly from GOOSE, SV or MMS protocol messages, specifically including: equipment position status change events: such as a circuit breaker changing from open to intermediate state or closed; electrical quantity over-limit events: such as voltage dropping to 0, current suddenly increasing to the rated value; operation timeout events: triggered by an internal timer to detect equipment non-response.

[0095] Measurement operation control transition conditions: The transition conditions are logical judgments of state transitions, which must be met simultaneously: a valid input event is detected; the current state of the equipment meets the preconditions of the operation step, such as the five-prevention rule being met; the electrical quantity response meets physical expectations, such as the bus voltage should recover and the current should increase after closing.

[0096] Measurement operation control initial and final states: The initial state of the finite state machine is the safe operating condition state before operation, that is, the system currently meets all the safety and logical prerequisites for starting the control operation; the normal final state indicates that the operation is completed as expected and the equipment enters a stable operating state; the abnormal final state includes failure to move, such as the command is issued but the equipment does not move, five-prevention interlocking, such as the preconditions are not met, state contradiction, such as position == closed but voltage == 0, etc., that is, there is a fault or violation at the physical operation level.

[0097] Measurement operation control state transition function: The state transition function formally defines the mapping relationship between the current state, input events and transition conditions to the new state, and is implemented through a state transition table, decision tree or rule engine.

[0098] Step S5: Integrate the above models and configure time windows and logical constraints to generate a structured set of time-series-logical compliance operation rules, forming a trusted data flow model.

[0099] Based on the separate construction of the operation control sequence logic model, communication data flow model, communication finite state machine model, and measurement operation control finite state machine model, this step further integrates the above models, configures refined time constraints and logical rules, constructs a structured time-logic compliant operation rule sequence set, and finally forms a digital twin trusted data flow model for control business interaction.

[0100] Specifically, the construction process includes the following steps:

[0101] First, define multi-level time window constraints, which include:

[0102] Command-Response Time Window: Sets the maximum allowed time difference for messages with request / response / acknowledgment. For example, the time between an IEC104 remote control selection command and its acknowledgment should not exceed 100 milliseconds; the time between an MMS operation request and its response should not exceed 50 milliseconds; and the time between the control execution command being issued and the device status remote signaling feedback should not exceed 2000 milliseconds.

[0103] Inter-command interval window: Sets the relative time allowable range for multiple consecutively sent related commands. For example, the interval between remote control selection and execution commands must be between 100 milliseconds and 10 seconds. It should be noted that too short an interval is considered a replay, and too long an interval is considered a timeout failure. The interval between two closing operations of the same device should not be less than 30 seconds. This setting is to prevent accidental operation.

[0104] Secondly, the time window constraints and logical rules are structured and encoded to form a set of time-series-logic compliant operation rule sequences that can be read by a computer. The rule set is stored in the form of structured data, and each rule includes: operation step identifier (such as 2001 closing - selection), associated message characteristics (such as protocol type, public address, information object address, transmission reason, call identifier, etc.), pre-state requirements, time window constraints, and expected final state information (such as measurement operation control finite state machine model).

[0105] Furthermore, a nested finite state machine structure is adopted for model fusion. Specifically, the measurement operation control finite state machine is used as a sub-state machine and embedded in the state node representing the waiting state feedback within the communication finite state machine. Under this nested structure: the communication finite state machine acts as the master state machine, responsible for monitoring whether communication messages arrive on time; the measurement operation control finite state machine acts as a sub-state machine, responsible for monitoring whether the physical device state changes according to the expected logic; the master state machine is only allowed to transition out of the waiting state feedback state when the sub-state machine reaches the expected final state and the master state machine receives a matching remote signaling message; if the sub-state machine enters an abnormal final state, such as refusing to operate, then even if a remote signaling message is received, the data stream is determined to be unreliable.

[0106] Finally, according to the operational control sequence of the business, the structured compliance rule sequence of all operational steps and the aforementioned nested relationships are integrated to form a unified digital twin trusted data flow model for control business interaction. During operation, the trusted data flow model drives the state transitions of its internal state machine through input messages until a final state is reached. If an abnormal final state is reached, the corresponding message data flow is determined to be untrustworthy. After reaching the final state, the model's internal state machine is reset to its initial state through a manual reset or automatic timeout reset mechanism, preparing for the execution of the next operational control business.

[0107] Step S6: Real-time acquisition and parsing of communication messages, comparison with the trusted data flow model, to achieve accurate security detection and alarm for abnormal operations. Based on the completed construction of the digital twin trusted data flow model for control business interaction, a real-time security detection engine is further deployed to dynamically compare and identify anomalies in the actual communication behavior of the power monitoring system, thereby achieving credibility verification and risk alarm for the entire control operation process.

[0108] Specifically, the security testing process includes the following steps:

[0109] First, the system collects full-flow industrial control communication messages in the substation control layer, bay layer and process layer network in real time, covering mainstream power protocols such as IEC104, MMS, GOOSE, and SV.

[0110] Secondly, each collected message is analyzed in depth to extract the following key real-time information: Communication characteristics: including source / destination IP address, source / destination MAC address, port number, and transport layer protocol; Protocol semantic information: IEC104 type identifier, transmission reason, common address, and information object address; MMS service type, call identifier, and object reference path; Service data: including instruction code (e.g., closing == 1), communication status word (e.g., remote signaling value == 10 indicates closing), measurement / operation / control point number and value; Timing information: message arrival timestamp, time interval with previous messages, and instruction sending sequence number.

[0111] The parsed real-time information is used as input and compared in multiple dimensions with the preset time-logic compliance operation rule sequence set in the trusted data flow model. The following core anomaly determinations are performed: Time-sequence violation determination: Determines whether the sending order, time interval, and response delay of real-time commands exceed the allowable range set in the rule sequence set. For example: the interval between remote control selection and execution commands is less than 100 milliseconds or greater than 10 seconds, exceeding the running time range; the status feedback delay is greater than 2000 milliseconds, exceeding the maximum status feedback delay; the same device is repeatedly operated within 30 seconds, etc. Logic precondition violation determination: Verifies whether the device status meets the preconditions or device status conditions defined in the rule sequence set when the current command is executed. For example: executing a tripping command when a disconnector is under load; closing a circuit breaker when a grounding switch is closed, etc., all violate the five-prevention rules. Skipping the selection step and directly sending the execution command during operation control violates the IEC104 operation specification.

[0112] Finally, for operations deemed abnormal, the system automatically generates structured alarm information, including: anomaly type (e.g., timing, status, logic), violation step number, actual message characteristics (IP, Addr, IOA, COT, timestamp), expected model characteristics, and suggested handling measures (e.g., blocking subsequent operations, notifying maintenance personnel). This alarm information can be pushed through a human-machine interface, SCADA system interface, or network security management platform to achieve closed-loop handling of security risks.

[0113] This manual provides a digital twin trusted data flow modeling and security detection device for power control business interaction. Please refer to the appendix. Figure 6 The device includes:

[0114] Operation logic modeling module 1101: Based on the substation primary wiring diagram and electrical safety rule library, it decomposes the power control business (such as power supply of power lines, circuit breaker closing, automatic transfer switch, safety and stability control, etc.) into a process, extracts the sequence of operation steps and preconditions, and generates a structured operation control sequence logic model.

[0115] The communication data stream extraction module 1102 is used to extract the communication features corresponding to each step of the operation based on the specifications and control logic of power operation control services and by parsing historical or real-time communication messages. For IEC104 messages, the module extracts the type identifier, transmission reason, common address, and information object address; for MMS protocol messages, it extracts the service type, call identifier, operation result, and object reference path; and for GOOSE or SV protocols, it extracts the APPID, MAC address, and dataset content. These features are stored in the form of data records to form a communication data stream model.

[0116] Communication Finite State Machine Construction Module 1103: Used to construct a finite state machine with communication interaction stages as states based on a communication data flow model. The finite state machine includes a predefined set of states and state transition rules configured with corresponding conditions; for example, a state set is defined for the disconnector closing operation: {IDLE,WAIT_SELECT_ACK,WAIT_EXECUTE_CMD,...,SUCCESS,TIMEOUT}, and transition conditions are configured (for example, transitioning from WAIT_SELECT_ACK requires receiving COT=7 and Δt≤100ms).

[0117] Measurement and Operation Control Finite State Machine Construction Module 1104: Used to construct a finite state machine with physical operation stages as states based on equipment state and electrical quantity characteristics. The finite state machine includes a predefined set of states and state transition rules configured with corresponding conditions; for example, the state set is defined as: {INIT,READY,CLOSING,CLOSED_SUCCESS,REJECTED}, and the transition conditions include "GOOSE stVal=ON" and "Uab>200kV".

[0118] Trusted rule generation module 1105: is used to integrate the finite state machine including a predefined set of states and state transition rules configured with corresponding conditions; and to configure time windows (such as selection-execution interval ∈ [100ms, 10s]) and logical constraints (such as prohibiting the circuit breaker from being closed when the grounding switch is closed) to generate a structured time-logic compliance operation rule sequence set, forming a trusted data flow model.

[0119] Real-time message parsing and comparison module 1106: Used to monitor network mirror traffic in real time, perform deep parsing of IEC104, MMS, GOOSE, and SV protocol messages to extract real-time features, and compare the real-time features with the trusted data flow model. If a timing violation (such as executing a command without a corresponding selection) or logical conflict (such as closing a circuit breaker with grounding) is detected, an alarm is immediately triggered and the anomaly details are recorded.

[0120] This device can be deployed on a substation monitoring host or a standalone network security monitoring device, supporting automated modeling and real-time detection of all station control operations.

[0121] This manual also provides a digital twin trusted data flow modeling and security detection system for power control business interaction, covering the complete control link from the dispatch master station to primary equipment. Please refer to the appendix. Figure 7 The system includes:

[0122] Includes: a dispatch master station, intelligent remote control device, measurement and control protection device, safety and stability control device, automatic backup power supply switching device, reactive power compensation device, out-of-step disconnection device, intelligent terminal, and a digital twin trusted data flow modeling and security detection device for power control business interaction;

[0123] The device possesses multi-channel acquisition capabilities, with multiple communication connections to the intelligent remote control and dispatch master station interconnection switch, the station control layer network, and the process layer network. It is used to collect in real-time communication messages between the dispatch master station and the intelligent remote control device, between the intelligent remote control device and the measurement and control protection device, between the safety and stability control device / backup power automatic switching device / reactive power compensation device / out-of-step disconnection device and the measurement and control protection device, and between the measurement and control protection device and the intelligent terminal. It also executes a power control business interaction digital twin trusted data flow modeling and security detection method. The device connects to the mirror ports of the station control layer and bay layer core switches via multiple channels to collect network messages in a bypass mode, and performs in-depth analysis and detection of the collected IEC104, MMS, GOOSE, and SV protocol messages.

[0124] The above description is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined in the claims, they should all fall within the protection scope of the present invention.

Claims

1. A method for trusted data flow twin modeling and security detection in power control business interactions, characterized in that, include: Based on power safety rules and power wiring logic, an operation control sequence logic model for power control services is constructed. The model defines multiple operation control steps connected in a preset order and their prerequisites. For each operation control step in the operation control sequence logic model, extract its corresponding communication behavior features and message interaction relationships to form an operation control digital twin communication data flow model. Based on the communication data flow model, the transmission timing and communication control fields of the instruction message are extracted, and a communication finite state machine model is constructed. Based on the communication data flow model and the operation control sequence logic model, the point data features, operation preconditions and post-execution states in the instruction message are extracted to construct a measurement operation control finite state machine model. Based on the operation control sequence logic model, communication data flow model, communication finite state machine model and measurement operation control finite state machine model, the timing constraints of instruction interaction are configured, a timing-logic compliant operation rule sequence set is constructed, and a digital twin trusted data flow model for control business interaction is formed. The system collects communication messages from the power monitoring system in real time, parses them to obtain real-time commands, communication characteristics, location data and transmission timing information, and compares them with a trusted data flow model for security detection, and issues alarms for non-compliance.

2. The method for trusted data flow twin modeling and security detection of power control business interaction according to claim 1, characterized in that, In the operation control sequence logic model, multiple operation control steps are connected in series according to a preset order to jointly complete a closing or opening operation control of a circuit breaker / switch / disconnector. The operation control is defined as an atomic operation control unit, whose execution logic includes three stages: instruction issuance, operation execution, and execution feedback, performed sequentially. During the instruction issuance phase, the communication flow is from the dispatch master station through the station control layer equipment, the interval layer equipment, and finally to the process layer equipment. During the operation execution phase, the process layer equipment drives the actuator to complete the action; During the execution feedback phase, the communication flow is as follows: status information is collected from process layer devices, and then fed back to the dispatch master station via interval layer devices and station control layer devices.

3. The method for trusted data flow twin modeling and security detection of power control business interaction according to claim 1, characterized in that, Methods for forming communication data flow models include: For each operation control step in the operation control sequence logic model, determine its corresponding communication interaction session in the power monitoring system network; Extract communication behavior features involved in the communication interaction session, wherein the communication behavior features include at least one of the following: communication topic identifier, protocol type, instruction semantic information, and service data features; Establish associations between different message types within the same communication session; The extracted communication behavior features and relationships are used as data records bound to the operation control step, and the collection of all data records constitutes the communication data flow model.

4. The method for trusted data flow twin modeling and security detection of power control business interaction according to claim 1, characterized in that, Constructing a communication finite state machine model includes: Based on the communication data flow model, multiple stable states are defined to represent different communication stages of the control service, forming a communication state set; Define the input event set as either the receipt of a communication message or the occurrence of a timeout. Configure at least one state transition rule for each state in the communication state set; wherein each state transition rule is associated with an expected input event and includes the following two conditions as the basis for transition judgment: Protocol semantic matching condition: When the input event is a communication message, the value of one or more predefined communication control fields parsed from the message matches the expected field value preset for this migration rule; Timing compliance condition: The occurrence time of this input event is within a preset time window determined based on the occurrence time of the previous related event; The initial state of the communication finite state machine is set to the idle state, and at least one communication success state is set as the normal termination state, and multiple abnormal states representing different types of communication failures are set as abnormal termination states.

5. The method for trusted data flow twin modeling and security detection of power control business interaction according to claim 1, characterized in that, Constructing a finite state machine model for measurement operation control includes: Based on the communication data flow model and the operation control sequence logic model, the equipment location identifiers, instruction values, and feedback status and electrical quantity data related to the operation instructions are extracted. Based on power safety rules, the equipment state and electrical quantity conditions that must be met for the execution of each operation control step are formally defined as the preconditions for Boolean logic expression. Define a measurement operation control state set, which includes business semantic states that characterize the stable operating conditions of the equipment; Define the set of input events as equipment status change events, electrical quantity change events, and operation timeout events; Configure state transition rules for each state in the state set; wherein, to transition from the current state to the next state, the following conditions must be met simultaneously: a valid input event is detected, the current device and electrical environment states meet the preconditions for operation corresponding to the input event, and the feedback electrical quantity data meets the expected physical conditions after the operation is executed. Define the initial state as the safe operating condition before operation, and define the successful operation state and multiple abnormal states as the final state.

6. The method for trusted data flow twin modeling and security detection of power control business interaction according to claim 1, characterized in that, The timing constraints for configuration command interaction include: For each pair of command message exchanges with a request-response relationship, a first absolute time allowable range is set as the command-response time window; For multiple consecutively sent command messages with logical dependencies, a second relative time allowable range is set as the interval window between commands.

7. The method for trusted data flow twin modeling and security detection of power control business interaction according to claim 1, characterized in that, Constructing the time-series-logic compliance operation rule sequence set includes: The logical sequence defined by the operation control sequence logic model, the communication state transition path defined by the communication finite state machine model, the device state transition path defined by the measurement operation control finite state machine model, and the timing constraints are integrated and encoded into a structured sequence of compliance rules. Integrate all operational steps into a structured sequence of compliance rules to form a time-series-logic compliance operational rule sequence set.

8. The method for trusted data flow twin modeling and security detection of power control business interaction according to claim 1, characterized in that, The security detection includes at least one of the following anomaly determinations: If the order in which real-time instructions are sent does not conform to the logical order defined by the rule sequence set, or if the timing indicators of instruction interaction exceed the time allowable range set by the rule sequence set, it is judged as a timing violation. If, during the execution of a real-time instruction, the parsed device status information indicates that the instruction does not meet the preconditions defined in the rule sequence set, then the instruction is deemed to have violated the logical preconditions.

9. A device for reliable data flow modeling and security detection of digital twins for power control business interaction, characterized in that, include: Operational logic modeling module; Based on power safety rules and power wiring logic, the operation sequence and its prerequisites of power control business are extracted to form a digital twin operation control sequence logic model for power control business interaction. Communication data stream extraction module; For each operation control step in the operation control sequence logic model, the communication behavior characteristics and message interaction relationships of the corresponding operation instructions are extracted to form a digital twin communication data flow model for power control business interaction operation control. A communication finite state machine construction module is used to extract the transmission timing and communication control fields of instruction messages based on the communication data flow model, and to construct a digital twin communication finite state machine model for power control business interaction. The module constructs a finite state machine for operation; based on the communication data flow model and the operation control sequence logic model, it extracts the point data features, operation preconditions and post-execution states from the instruction message, and constructs a finite state machine model for power control business interaction digital twin measurement operation control. Trusted rule generation module; Based on the operation control sequence logic model, communication data flow model, communication finite state machine model and measurement operation control finite state machine model, the timing constraints of instruction interaction are configured, a timing-logic compliant operation rule sequence set is constructed, and a digital twin trusted data flow model for control business interaction is formed. Real-time detection and alarm module: Collects communication messages in the power monitoring system in real time, parses them to obtain real-time commands, communication characteristics, point data and transmission timing information, compares them with the trusted data flow model and performs security detection, and alarms are triggered for non-compliance.

10. A reliable data flow twin modeling and security detection system for power control business interaction, characterized in that, include: The system includes a dispatching master station, an intelligent remote control device, a measurement and control protection device, a safety and stability control device, an automatic backup power supply switching device, a reactive power compensation device, a step-out disconnection device, an intelligent terminal, and the device as described in claim 9. The device has multi-channel acquisition capability and multiple communication connections to the intelligent remote control and dispatch master station interconnection switch, station control layer network and process layer network. It is used to collect communication messages exchanged between the dispatch master station and the intelligent remote control device, between the intelligent remote control device and the measurement and control protection device, between the safety and stability control device / backup power automatic switching device / reactive power compensation device / out-of-step disconnection device and the measurement and control protection device, and between the measurement and control protection device and the intelligent terminal in real time, and execute the method as described in any one of claims 1-8. The device connects to the mirror ports of the core switches at the station control layer and the bay layer via multiple channels to collect network packets in a bypass manner, and performs in-depth analysis and detection on the collected IEC104, MMS, GOOSE, and SV protocol packets.