Power transmission line data security transmission device and method based on VPN encryption channel

By using a VPN-based encrypted channel for secure data transmission, the problems of high data redundancy and insufficient security in traditional power transmission line data transmission are solved, achieving efficient and secure data transmission and ensuring the stability and integrity of the data transmission process.

CN122160169APending Publication Date: 2026-06-05FUJIAN SHENGYAO TECHNOLOGY GROUP CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FUJIAN SHENGYAO TECHNOLOGY GROUP CO LTD
Filing Date
2026-04-16
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

Traditional power transmission lines do not implement graded processing based on data sensitivity, resulting in high data redundancy, difficulty in accurately matching transmission load and channel resources, easy transmission congestion and high latency, lack of dynamic path planning and multi-channel concurrent mapping capabilities, and difficulty in ensuring stable data transmission security and integrity.

Method used

A data security transmission device based on a VPN encrypted channel is adopted, including a module for obtaining the characteristics to be transmitted, a gateway negotiation and configuration module, a path dynamic planning module, a multi-channel concurrent mapping module, and an integrity verification module. Through sensitivity classification, dynamic path planning, and multi-channel concurrent mapping, combined with VPN encrypted channel and gateway negotiation and configuration, secure encrypted transmission and integrity verification of data are achieved.

Benefits of technology

It significantly improves data transmission efficiency and channel utilization, achieves lightweight, high-throughput transmission, ensures the continuity and stability of data transmission, and provides full-process security protection and reliable restoration of data transmission through VPN encrypted channels and packet encapsulation encryption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122160169A_ABST
    Figure CN122160169A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of electric power communication, and discloses a power transmission line data security transmission device and method based on a VPN encryption channel. The device comprises a to-be-transmitted feature acquisition module, a gateway negotiation configuration module, a path dynamic planning module, a multi-channel concurrent mapping module, a grouping and packaging distribution module and an integrity checking module. The power transmission line data is subjected to risk research and sensitivity grading to obtain to-be-transmitted features. Transmission load features are obtained through flow feature analysis, and are negotiated and configured with preset VPN gateway strategy parameters to construct a safe encryption transmission channel. The encryption channel is dynamically planned to obtain an optimal transmission channel. The to-be-transmitted features are mapped in multiple channels to generate route mapping data streams. The data streams are grouped and packaged into VPN transmission messages and are distributed for transmission. The received messages are subjected to integrity checking and credible restoration in the cloud to obtain safe transmission data of the power transmission line data. The application can improve the efficiency of power transmission line data security transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power communication technology, and in particular to a device and method for secure transmission of power line data based on a VPN encrypted channel. Background Technology

[0002] Traditional power transmission lines do not implement graded processing based on data sensitivity, resulting in high data redundancy. The transmission load and channel resources are difficult to match precisely, which can easily lead to transmission congestion, high latency, and low channel transmission efficiency and data processing efficiency.

[0003] Existing technologies lack dynamic path planning and multi-channel concurrent mapping capabilities, have insufficient adaptability to data transmission security protocols, and lack end-to-end integrity verification and trusted restoration mechanisms, making it difficult to reliably guarantee the security and integrity of data transmission. Therefore, improving the efficiency, security, and integrity of data transmission in power transmission lines has become an urgent problem to be solved. Summary of the Invention

[0004] This invention provides a device and method for secure data transmission of power transmission lines based on VPN encrypted channels, in order to solve the problems mentioned in the background art.

[0005] To achieve the above objectives, the present invention provides a secure data transmission device for power transmission lines based on a VPN encrypted channel, characterized in that the device includes a module for acquiring characteristics to be transmitted, a gateway negotiation and configuration module, a path dynamic planning module, a multi-channel concurrent mapping module, a packet encapsulation and distribution module, and an integrity verification module, wherein: The module for obtaining the features to be transmitted is used to perform risk assessment on the transmission line data, obtain the sensitivity classification of the transmission line data, and perform differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data. The gateway negotiation and configuration module is used to perform traffic characteristic analysis on the characteristics to be transmitted, obtain the transmission load characteristics of the transmission line data, and negotiate and configure the data transmission load characteristics with the preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data. The path dynamic planning module is used to dynamically plan the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data. The multi-channel concurrent mapping module is used to perform multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data; The packet encapsulation and distribution module is used to encapsulate the routing mapping data stream into packets to obtain VPN transmission data packets of the transmission line data, and to distribute and transmit the VPN transmission data packets to obtain cloud reception packets of the transmission line data. The integrity verification module is used to perform integrity verification on the cloud-received message to obtain verification information of the transmission line data, and based on the verification information, to perform reliable restoration of the cloud-received message to obtain secure transmission data of the transmission line data.

[0006] In a preferred embodiment, when the feature acquisition module performs risk assessment on transmission line data to obtain a sensitivity classification of the transmission line data, and performs differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data, it is specifically used for: Semantic parsing is performed on the transmission line data to obtain its structured features; Risk quantification is performed on the structured features to obtain the risk characterization of the transmission line data; Based on the risk characterization, the sensitivity attributes of the transmission line data are classified and mapped to obtain the sensitivity classification of the transmission line data. Based on the sensitivity classification, redundant fields of the transmission line data are non-intrusively stripped to obtain simplified data of the transmission line data. The simplified data is normalized and reconstructed to obtain the transmission characteristics of the transmission line data.

[0007] In a preferred embodiment, when the gateway negotiation and configuration module performs traffic characteristic analysis on the features to be transmitted to obtain the transmission load characteristics of the transmission line data, and negotiates and configures the data transmission load characteristics with preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data, it is specifically used for: The transmission line data is subjected to flow profile extraction to obtain multidimensional flow features of the transmission line data. By performing load situation analysis on the multidimensional flow characteristics, the transmission load characteristics of the transmission line data are obtained. Based on preset VPN gateway connection policy parameters, differential policy matching is performed on the transmission load characteristics to obtain candidate gateway configuration parameters for the transmission line data. Based on the candidate gateway configuration parameters, the feasibility of the transmission path for the feature to be transmitted is verified to obtain the link negotiation characterization of the transmission line data. By adapting the link negotiation representation to a security protocol, a secure encrypted transmission channel for the transmission line data is obtained.

[0008] In a preferred embodiment, when the gateway negotiation configuration module performs load situation analysis on the multi-dimensional traffic characteristics to obtain the transmission load characteristics of the transmission line data, it is specifically used for: The multidimensional flow characteristics are analyzed by time-series correlation to obtain the flow fluctuation sequence of the transmission line data. Pattern recognition is performed on the flow fluctuation sequence to obtain the behavioral pattern label of the transmission line data; Based on the behavioral pattern labels, the peak flow of the transmission line data is compared with a threshold to obtain the congestion risk level of the transmission line data. Based on the congestion risk level, the weights of the multidimensional flow characteristics are adjusted to obtain the transmission load characteristics of the transmission line data.

[0009] In a preferred embodiment, when the path dynamic planning module performs dynamic planning on the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data, it is specifically used for: Path enumeration is performed on the secure encrypted transmission channel to obtain the initial candidate paths for the transmission line data; The transmission delay characteristics of the initial candidate path are analyzed for trend prediction to obtain the delay prediction characterization of the transmission line data. Based on the time delay prediction characterization, the transmission congestion nodes in the candidate paths are avoided and screened to obtain the available paths for the transmission line data. Based on the historical transmission records of the transmission line data, the stability of the available paths is backtested to obtain the path score of the transmission line data; The overall transmission efficiency value of the available path is calculated based on the latency prediction characterization, the congestion risk level, and the path score. A global optimization search is performed on the comprehensive transmission efficiency value to obtain the optimal transmission channel for the transmission line data.

[0010] In a preferred embodiment, the formula for calculating the overall transmission performance value is as follows: ; in, The overall transmission performance value is... Rate the path. This is the time delay prediction characterization. The congestion risk level is... The preset weighting coefficients, The preset weighting coefficients, These are the preset weighting coefficients.

[0011] In a preferred embodiment, when the multi-channel concurrent mapping module performs multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data, it is specifically used for: The optimal transmission channel is decomposed into multiple paths to obtain the concurrent transmission branches of the transmission line data; Extract the branch identifier and branch carrying capacity from the concurrent transmission branches; Based on the carrying capacity of the branch, the feature to be transmitted is partitioned into feature loads to obtain feature load fragments of the concurrent transmission branch; Based on the branch identifier and the characteristic load fragment, the matching degree of the concurrent transmission branch is checked to obtain the load distribution weight of the concurrent transmission branch; Based on the load distribution weight, the characteristic load fragments are branch-bound to obtain the load mapping relationship of the concurrent transmission branches; The load mapping relationship is mapped to the optimal transmission channel to obtain the routing mapping data stream of the transmission line data.

[0012] In a preferred embodiment, when the packet encapsulation and distribution module performs packet encapsulation on the routing mapping data stream to obtain VPN transmission data packets of the transmission line data, and distributes and transmits the VPN transmission data packets to obtain cloud reception packets of the transmission line data, it is specifically used for: The routing mapping data stream is segmented and parsed to obtain data slices of the transmission line data, and the slice features and slice timestamps of the data slices are extracted. Based on the slice characteristics, the data slice is subjected to encryption strategy matching to obtain the differentiated encryption parameters of the data slice; Based on the differentiated encryption parameter set and the slice timestamp, the data slice is encapsulated with encrypted payload and a preset integrity verification anchor is embedded to obtain the VPN transmission data packet of the transmission line data. The VPN transmission data packets are injected with a distribution path identifier to obtain the path tracing identifier of the VPN transmission data packets; Based on the path tracing identifier, the VPN transmission data packets are delivered in an orderly manner, and the status feedback of the VPN transmission data packets is aggregated to obtain the cloud reception packets of the transmission line data.

[0013] In a preferred embodiment, when the integrity verification module performs integrity verification on the cloud-received message to obtain verification information of the transmission line data, and performs reliable reconstruction of the cloud-received message based on the verification information to obtain secure transmission data of the transmission line data, it is specifically used for: The field consistency of the cloud-received message is compared to obtain the field matching characterization of the cloud-received message; Based on the field matching characteristics, the cloud-received message is identified and traced for verification to obtain a trusted identifier for the cloud-received message; Based on the trusted identifier, the authenticity of the content of the cloud-received message is verified to obtain the verification information of the transmission line data; Based on the verification information, the missing content of the cloud-received message is filled in to obtain the filled message of the cloud-received message; The completed message is reliably integrated to obtain the secure transmission data of the power transmission line.

[0014] To address the aforementioned problems, this invention also provides a method for secure data transmission of power transmission lines based on a VPN encrypted channel, the method comprising: Step a: The feature acquisition module to be transmitted performs risk assessment on the transmission line data, obtains the sensitivity classification of the transmission line data, and performs differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data. Step b: The gateway negotiation and configuration module performs traffic characteristic analysis on the features to be transmitted to obtain the transmission load characteristics of the transmission line data, and negotiates and configures the data transmission load characteristics with the preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data. Step c: The path dynamic planning module performs dynamic planning on the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data; Step d: The multi-channel concurrent mapping module performs multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data; Step e: The grouping, encapsulation, and distribution module encapsulates the routing mapping data stream into groups to obtain VPN transmission data packets of the transmission line data, and distributes and transmits the VPN transmission data packets to obtain cloud receiving packets of the transmission line data. Step f: The integrity verification module performs integrity verification on the cloud-received message to obtain verification information of the transmission line data, and based on the verification information, performs reliable restoration of the cloud-received message to obtain secure transmission data of the transmission line data.

[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention significantly improves data transmission efficiency and channel utilization by performing sensitivity classification and differentiated cleaning on transmission line data, combined with dynamic path planning and multi-channel concurrent mapping mechanism, thereby achieving lightweight, high-throughput transmission of transmission line data while ensuring the continuity and stability of the data transmission process.

[0016] 2. This invention achieves security protocol adaptation through VPN encrypted channel and gateway negotiation configuration, combined with packet encapsulation encryption and integrity verification anchor point verification, to realize security protection and reliable restoration of the entire data transmission process, effectively improving the security and integrity of power transmission line data transmission, and ensuring that cloud-received data can be accurately restored and used stably. Attached Figure Description

[0017] Figure 1 This is a device architecture diagram of a power transmission line data security transmission device based on a VPN encrypted channel provided in an embodiment of the present invention; Figure 2 This is a flowchart illustrating a method for secure data transmission of power transmission lines based on a VPN encrypted channel, as provided in an embodiment of the present invention.

[0018] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments belong to some, but not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “said” and “the” as used in the embodiments of this invention and the appended claims are also intended to include the plural forms, and “multiple” generally includes at least two unless the context clearly indicates otherwise.

[0021] Depending on the context, the word "if" or "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."

[0022] Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0023] In practice, the server-side equipment deployed by the VPN-based encrypted transmission channel data security transmission device may consist of one or more devices. This VPN-based encrypted transmission channel data security transmission device can be implemented as a service instance, a virtual machine, or a hardware device. For example, it can be implemented as a service instance deployed on one or more devices in a cloud node. Simply put, it can be understood as software deployed on a cloud node to provide VPN-based encrypted transmission channel data security transmission to various user terminals. Alternatively, it can be implemented as a virtual machine deployed on one or more devices in a cloud node, with application software installed to manage various user terminals. Or, it can also be implemented as a server composed of numerous identical or different types of hardware devices, with one or more hardware devices configured to provide VPN-based encrypted transmission channel data security transmission to various user terminals.

[0024] In terms of implementation, the VPN-based encrypted transmission line data security transmission device and the user terminal are mutually compatible. That is, if the VPN-based encrypted transmission line data security transmission device is implemented as an application installed on a cloud service platform, then the user terminal is a client that establishes a communication connection with the application; or if the VPN-based encrypted transmission line data security transmission device is implemented as a website, then the user terminal is implemented as a webpage; or if the VPN-based encrypted transmission line data security transmission device is implemented as a cloud service platform, then the user terminal is implemented as a mini-program in an instant messaging application.

[0025] like Figure 1 The diagram shown is a device architecture diagram of a power transmission line data security transmission device based on a VPN encrypted channel provided in an embodiment of the present invention.

[0026] The VPN-encrypted channel-based power transmission line data security transmission device 100 of this invention can be installed in a cloud server. In terms of implementation, it can be used as one or more service devices, or as an application installed in the cloud (e.g., a mobile service operator's server, server cluster, etc.), or it can be developed into a website. Depending on the implemented functions, the VPN-encrypted channel-based power transmission line data security transmission device 100 may include a transmittance feature acquisition module 101, a gateway negotiation and configuration module 102, a path dynamic planning module 103, a multi-channel concurrent mapping module 104, a packet encapsulation and distribution module 105, and an integrity verification module 106. The module described in this invention can also be called a unit, which refers to a series of computer program segments that can be executed by the processor of an electronic device and can perform a fixed function, stored in the memory of the electronic device.

[0027] In this embodiment of the invention, in the VPN-encrypted channel-based power transmission line data security transmission device, each of the above-mentioned modules can be implemented independently and can call other modules. This calling can be understood as a module connecting to multiple modules of another type and providing corresponding services to those connected modules. In the VPN-encrypted channel-based power transmission line data security transmission device provided by this embodiment of the invention, without modifying the program code, the applicability of the VPN-encrypted channel-based power transmission line data security transmission device architecture can be adjusted by adding modules and directly calling them, achieving cluster-based horizontal expansion to quickly and flexibly expand the VPN-encrypted channel-based power transmission line data security transmission device. In practical applications, the above-mentioned modules can be set in the same device or different devices, or they can be set in a virtual device, such as a service instance in a cloud server.

[0028] The following describes, with reference to specific embodiments, each component and its specific workflow of the power transmission line data security transmission device based on a VPN encrypted channel: The feature acquisition module 101 is used to perform risk assessment on the transmission line data, obtain the sensitivity classification of the transmission line data, and perform differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data. In this embodiment of the invention, when the module for obtaining the features to be transmitted performs risk assessment on the transmission line data, obtains the sensitivity classification of the transmission line data, and performs differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data, it is specifically used for: Semantic parsing is performed on the transmission line data to obtain its structured features; Risk quantification is performed on the structured features to obtain the risk characterization of the transmission line data; Based on the risk characterization, the sensitivity attributes of the transmission line data are classified and mapped to obtain the sensitivity classification of the transmission line data. Based on the sensitivity classification, redundant fields of the transmission line data are non-intrusively stripped to obtain simplified data of the transmission line data. The simplified data is normalized and reconstructed to obtain the transmission characteristics of the transmission line data.

[0029] When performing semantic parsing on transmission line data, the original data is disassembled field by field according to the preset power data field specifications. The numerical type, text type and identifier type content in the data are identified, and the discrete and disordered original data is organized into a standardized format containing fixed field names, field types and field values, thus obtaining the structured features of the transmission line data.

[0030] When quantifying the risks of structured features, the matching relationship between each field in the structured features and the preset list of sensitive data is checked one by one. Fields involving equipment number, operating parameters and location information are marked. Based on the degree of impact of the fields on the safe operation of transmission lines, clear risk level labels are assigned to form a description that can intuitively reflect the degree of data security risk, thus obtaining the risk characterization of transmission line data.

[0031] When mapping the sensitivity attributes of transmission line data based on risk characterization, the data is divided into three distinct levels: high sensitivity, medium sensitivity, and low sensitivity, according to the risk level marked by the risk characterization. Each level corresponds to a fixed sensitivity attribute judgment standard. The risk characterization results are directly matched one-to-one with the three levels to complete the classification of sensitivity attributes and obtain the sensitivity classification of transmission line data.

[0032] When performing non-intrusive stripping of redundant fields in transmission line data based on sensitivity grading, all valid fields of the high-sensitivity level are retained according to the sensitivity grading results. Duplicate, invalid, and blank fields that do not affect the core meaning of the data in the low-sensitivity level are directly removed. The stripping process does not modify the original content and data format of the retained fields, resulting in simplified transmission line data.

[0033] When reconstructing simplified data through normalization, the simplified data is organized according to a unified data length, data format, and arrangement order. Simplified data of different formats and lengths are adjusted to a unified form that conforms to transmission standards, eliminating transmission obstacles caused by differences in data formats, forming a standardized data form that adapts to subsequent transmission processes, and obtaining the transmission characteristics of transmission line data.

[0034] The beneficial effects are that semantic parsing enables the structured organization of transmission line data, risk quantification and hierarchical mapping enables the accurate classification of data sensitivity, non-intrusive stripping of redundant fields reduces the data transmission volume, and normalization reconstruction ensures the standardization and compatibility of the features to be transmitted. The original core data content is not changed throughout the process, which not only improves the efficiency of data preprocessing, but also lays a stable and reliable data foundation for subsequent safe transmission.

[0035] The gateway negotiation configuration module 102 is used to perform traffic feature analysis on the features to be transmitted to obtain the transmission load features of the transmission line data, and to negotiate and configure the data transmission load features with preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data. In this embodiment of the invention, when the gateway negotiation configuration module performs traffic feature analysis on the features to be transmitted to obtain the transmission load features of the transmission line data, and negotiates and configures the data transmission load features with preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data, it is specifically used for: The transmission line data is subjected to flow profile extraction to obtain multidimensional flow features of the transmission line data. By performing load situation analysis on the multidimensional flow characteristics, the transmission load characteristics of the transmission line data are obtained. Based on preset VPN gateway connection policy parameters, differential policy matching is performed on the transmission load characteristics to obtain candidate gateway configuration parameters for the transmission line data. Based on the candidate gateway configuration parameters, the feasibility of the transmission path for the feature to be transmitted is verified to obtain the link negotiation characterization of the transmission line data. By adapting the link negotiation representation to a security protocol, a secure encrypted transmission channel for the transmission line data is obtained.

[0036] When the gateway negotiation and configuration module performs load situation analysis on the multi-dimensional traffic characteristics to obtain the transmission load characteristics of the transmission line data, it is specifically used for: The multidimensional flow characteristics are analyzed by time-series correlation to obtain the flow fluctuation sequence of the transmission line data. Pattern recognition is performed on the flow fluctuation sequence to obtain the behavioral pattern label of the transmission line data; Based on the behavioral pattern labels, the peak flow of the transmission line data is compared with a threshold to obtain the congestion risk level of the transmission line data. Based on the congestion risk level, the weights of the multidimensional flow characteristics are adjusted to obtain the transmission load characteristics of the transmission line data.

[0037] Extract all attribute information related to data transmission from the features to be transmitted, and collect the transmission speed, total amount of data transmitted in a single transmission, duration of transmission process, number of simultaneous transmission connections, and start and end directions of data transmission for each feature to be transmitted per unit time. Collect and organize these different dimensions of flow-related information to form a multi-dimensional information set that can comprehensively reflect the flow status, and obtain the multi-dimensional flow characteristics of transmission line data.

[0038] Following the chronological order of the timeline, the flow information at each moment in the multidimensional flow characteristics is arranged in an orderly manner, establishing the corresponding relationship between the flow data at adjacent time points. The discrete multidimensional flow characteristics are spliced ​​into a continuous flow data chain that changes over time, fully presenting the increase or decrease of flow in different time periods, and obtaining the flow fluctuation sequence of transmission line data.

[0039] By traversing all data segments of the flow fluctuation sequence, analyzing the rising, falling, and stable change patterns of flow values, different change patterns such as continuous and stable flow, slow flow growth, rapid flow decline, and periodic flow fluctuation are distinguished. Each specific change pattern is assigned a unique and fixed label name, so that the flow change pattern can be intuitively identified and distinguished, and behavioral pattern labels of transmission line data are obtained.

[0040] Extract the node data where the traffic value reaches the maximum from the traffic fluctuation sequence, directly compare the traffic peak data with a pre-set fixed traffic threshold, determine the congestion risk level of the current transmission link based on the specific extent to which the traffic peak exceeds the threshold, classify the risk level into clear grades, and obtain the congestion risk level of the transmission line data.

[0041] Based on the specific results of the congestion risk level, corresponding influence weights are assigned to various information such as transmission speed, transmission duration, total data volume, and number of concurrent connections in the multidimensional flow characteristics. The higher the congestion risk level, the higher the weight is assigned to the feature items that have a greater impact on transmission efficiency. The various flow characteristics after adjusting the weights are reintegrated into a unified overall information to obtain the transmission load characteristics of the transmission line data.

[0042] Each indicator in the transmission load characteristics is precisely compared with the preset VPN gateway connection policy parameters, which include the gateway bandwidth limit, encryption strength level, maximum connection duration, number of supported concurrent connections, and transmission packet loss rate requirements. Based on the actual situation of the transmission load characteristics, the most suitable gateway connection execution rules are matched, and the gateway configuration content that meets the conditions is selected to obtain the candidate gateway configuration parameters for the transmission line data.

[0043] Based on all the requirements of the candidate gateway configuration parameters, a comprehensive path detection is performed on the transmission path to check whether the physical connectivity, signal transmission strength, data transmission stability, and link response speed of the transmission path meet the standards of the candidate gateway configuration parameters. The detection results are compared with the parameter requirements to form a clear verification conclusion and obtain the link negotiation characterization of the transmission line data.

[0044] Based on the link transmission status and data transmission security requirements reflected by the link negotiation characterization, an encryption protocol and an authentication protocol that are fully compatible with the link status are selected. The selected security protocol is bound to the transmission link to complete the adaptation configuration of the protocol and the link, so that the transmission link has the ability to perform encrypted transmission and identity verification, forming a dedicated secure transmission path, and obtaining a secure encrypted transmission channel for transmission line data.

[0045] The beneficial effects are: to accurately grasp the real-time status and potential risks of transmission line data transmission through complete traffic profile extraction and detailed load status analysis; to achieve precise adaptation of transmission load and gateway parameters by relying on differentiated strategy matching; to ensure that the transmission path meets the transmission requirements through path feasibility verification; and to build a stable and reliable VPN encrypted channel through security protocol adaptation, thereby effectively improving the utilization rate of gateway resources, reducing transmission congestion and interruption, and comprehensively ensuring the security, stability and efficiency of transmission line data transmission.

[0046] The path dynamic planning module 103 is used to dynamically plan the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data. In this embodiment of the invention, when the path dynamic planning module performs dynamic planning on the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data, it is specifically used for: Path enumeration is performed on the secure encrypted transmission channel to obtain the initial candidate paths for the transmission line data; The transmission delay characteristics of the initial candidate path are analyzed for trend prediction to obtain the delay prediction characterization of the transmission line data. Based on the time delay prediction characterization, the transmission congestion nodes in the candidate paths are avoided and screened to obtain the available paths for the transmission line data. Based on the historical transmission records of the transmission line data, the stability of the available paths is backtested to obtain the path score of the transmission line data; The overall transmission efficiency value of the available path is calculated based on the latency prediction characterization, the congestion risk level, and the path score. A global optimization search is performed on the comprehensive transmission efficiency value to obtain the optimal transmission channel for the transmission line data.

[0047] The formula for calculating the overall transmission performance value is as follows: ; in, The overall transmission performance value is... Rate the path. This is the time delay prediction characterization. The congestion risk level is... The preset weighting coefficients, The preset weighting coefficients, These are the preset weighting coefficients.

[0048] By traversing all network links and node combinations covered by the secure encrypted transmission channel, all path combinations that can transmit data from the origin to the destination are listed. Each path retains the complete node sequence and link connection relationship, forming a set of paths covering all feasible transmission directions, thus obtaining the initial candidate paths for transmission line data.

[0049] Historical transmission delay data of each link on the initial candidate path is collected, the delay change process is sorted out in chronological order, the change trend of delay with transmission period and link load is analyzed, the direction and range of path delay change in the future specified transmission period are determined, and a descriptive result that can intuitively reflect the future delay status is formed, thus obtaining the delay prediction characterization of transmission line data.

[0050] Based on the future latency changes and congestion trends reflected in the latency prediction, the locations of nodes in the initial candidate paths that will experience high latency and data congestion are identified. Path segments containing these high-risk congestion nodes are removed from the initial candidate paths, and only the path portions with unobstructed nodes and latency within a reasonable range are retained, forming a set of pathways that can stably carry data transmission, thus obtaining the usable paths for transmission line data.

[0051] The system retrieves all historical records of the available paths used in the past transmission of transmission line data, checks the number of successful transmissions, interruptions, packet loss, and frequency of anomalies for each available path, and quantifies the reliability of each available path based on its actual operational performance to form a specific evaluation value representing the stability of the path, thus obtaining a path score for the transmission line data.

[0052] By comprehensively integrating the latency status reflected by latency prediction, the degree of congestion reflected by congestion risk level, and the stability represented by path score, and using path score as the basic reference, the overall performance of high-latency paths is reduced by combining latency prediction and the overall performance of low-risk paths is improved by combining congestion risk level. By superimposing each feature, a result that can comprehensively reflect the path transmission capacity is formed, and the overall transmission efficiency value of available paths is obtained.

[0053] In the formula for calculating the comprehensive transmission performance value, the path score is derived from real-time collection and quantification of the link connectivity, packet loss rate, and bandwidth fluctuation of the current transmission path. The specific path score is obtained by weighted summation of the collected multi-dimensional path status data. The latency prediction is derived from time-series analysis and trend fitting of historical transmission latency data. Based on the transmission latency variation patterns under similar past scenarios, the future transmission latency under the current path is predicted and quantified into a specific value. The congestion risk level is derived from monitoring and statistically analyzing the bandwidth utilization, queue buffer length, and packet retransmission count of the current path, mapping the statistical results to a preset risk level value. The preset weighting coefficients are derived from the preliminary demand analysis and experimental calibration of the transmission scenario. Fixed values ​​for each coefficient are determined by testing and evaluating the importance of various influencing factors under different transmission scenarios.

[0054] The significance of the comprehensive transmission performance value calculation formula lies in the fact that by quantifying and integrating the three core influencing factors of path stability, delay prediction and congestion risk, a unified numerical evaluation of the comprehensive transmission capability of the transmission path is achieved. This provides a quantifiable reference for the selection and scheduling decisions of transmission paths, ensuring that the comprehensive transmission performance value can accurately reflect the overall performance of the path in terms of stable transmission, delay control and congestion avoidance.

[0055] The trend in the calculation formula for the overall transmission efficiency value is as follows: the higher the path score, the higher the overall transmission efficiency value. The larger the delay prediction value, the lower the overall transmission efficiency value. The higher the congestion risk level, the lower the overall transmission efficiency value. The larger the preset weight coefficient, the more significant the moderating effect of the corresponding influencing factors on the overall transmission efficiency value. The larger the weight coefficient corresponding to the path score, the greater the change in the overall transmission efficiency value with the path score. The larger the weight coefficients corresponding to the delay prediction value and the congestion risk level, the greater the change in the overall transmission efficiency value with the delay prediction value and the congestion risk level.

[0056] The overall transmission efficiency values ​​of all available paths are compared horizontally. The overall transmission efficiency values ​​of each path are compared one by one, and the path with the highest overall transmission efficiency value is selected. This path achieves the best matching state in the three dimensions of time delay, congestion risk and stability, and is determined as the transmission path to be adopted in the end, thus obtaining the optimal transmission channel for transmission line data.

[0057] The beneficial effects are that by comprehensively enumerating all feasible transmission paths, predicting transmission risks in advance through latency trends, improving path reliability by avoiding congestion nodes, evaluating path stability by combining historical data backtracking, and calculating the comprehensive transmission efficiency value through the integration of multi-dimensional indicators, the optimal transmission channel is finally accurately selected, effectively reducing data transmission latency and congestion probability, and improving the overall efficiency and stability of power transmission line data transmission.

[0058] The multi-channel concurrent mapping module 104 is used to perform multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data; In this embodiment of the invention, when the multi-channel concurrent mapping module performs multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data, it is specifically used for: The optimal transmission channel is decomposed into multiple paths to obtain the concurrent transmission branches of the transmission line data; Extract the branch identifier and branch carrying capacity from the concurrent transmission branches; Based on the carrying capacity of the branch, the feature to be transmitted is partitioned into feature loads to obtain feature load fragments of the concurrent transmission branch; Based on the branch identifier and the characteristic load fragment, the matching degree of the concurrent transmission branch is checked to obtain the load distribution weight of the concurrent transmission branch; Based on the load distribution weight, the characteristic load fragments are branch-bound to obtain the load mapping relationship of the concurrent transmission branches; The load mapping relationship is mapped to the optimal transmission channel to obtain the routing mapping data stream of the transmission line data.

[0059] Based on the link structure and node distribution of the optimal transmission channel, the overall channel is divided into multiple independent sub-paths that can work simultaneously according to physical links and logical transmission units. Each sub-path has the ability to transmit data independently. The splitting process ensures that the branches do not interfere with each other and work together, thus obtaining the concurrent transmission branches of the transmission line data.

[0060] The unique identification number and physical location information are read from each concurrent transmission branch. At the same time, the maximum amount of data that each branch can carry per unit time, the supported transmission rate, and the load limit for stable operation are detected. The branch identification information and carrying capacity information are completely extracted and matched one by one to obtain the branch identifier and branch carrying capacity of the concurrent transmission branch.

[0061] Based on the upper limit of the carrying capacity of each concurrent transmission branch, the overall data volume and composition of the feature to be transmitted are split. The feature to be transmitted is divided into several data segments according to the size that the branch can carry. The size of each data segment strictly matches the transmission upper limit of the corresponding branch, ensuring that each data segment can be transmitted smoothly in the branch without overload or resource idleness, thus obtaining the feature payload fragments of the concurrent transmission branch.

[0062] The data size and transmission requirements of each feature payload fragment are checked against the branch identifier and branch carrying capacity of the corresponding concurrent transmission branch. The degree of compatibility between the fragmented data and the branch is determined. Based on the degree of compatibility, the data weight and transmission priority to be allocated to each branch are determined, forming a clear allocation basis and obtaining the payload distribution weight of the concurrent transmission branch.

[0063] According to the allocation rules determined by the load distribution weight, each feature load fragment is fixedly bound to the corresponding concurrent transmission branch, so that each feature load fragment can only be transmitted on the designated branch. After binding, the correspondence between the data fragment and the branch remains unchanged, ensuring that the transmission process is orderly and controllable, and the load mapping relationship of the concurrent transmission branch is obtained.

[0064] The established load mapping relationship is fully loaded into the overall link of the optimal transmission channel. According to the mapping relationship, each concurrent transmission branch is directed to start data transmission synchronously. All branches transmit the corresponding characteristic load fragments at the same time, forming an ordered data stream of multi-path simultaneous transmission, and thus obtaining the routing mapping data stream of the transmission line data.

[0065] The beneficial effects are that by splitting the optimal transmission channel into multiple parallel transmission branches, combining the branch carrying capacity to complete the reasonable subdivision of characteristic loads, determining the accurate distribution weights through matching degree verification and completing branch binding, a stable multi-channel concurrent transmission structure is finally constructed, which greatly improves the data transmission throughput capacity, makes full use of channel resources, and ensures efficient and orderly data transmission of transmission lines.

[0066] The packet encapsulation and distribution module 105 is used to encapsulate the routing mapping data stream into packets to obtain VPN transmission data packets of the transmission line data, and to distribute and transmit the VPN transmission data packets to obtain cloud receiving packets of the transmission line data. In this embodiment of the invention, when the packet encapsulation and distribution module performs packet encapsulation on the routing mapping data stream to obtain VPN transmission data packets of the transmission line data, and distributes and transmits the VPN transmission data packets to obtain cloud reception packets of the transmission line data, it is specifically used for: The routing mapping data stream is segmented and parsed to obtain data slices of the transmission line data, and the slice features and slice timestamps of the data slices are extracted. Based on the slice characteristics, the data slice is subjected to encryption strategy matching to obtain the differentiated encryption parameters of the data slice; Based on the differentiated encryption parameter set and the slice timestamp, the data slice is encapsulated with encrypted payload and a preset integrity verification anchor is embedded to obtain the VPN transmission data packet of the transmission line data. The VPN transmission data packets are injected with a distribution path identifier to obtain the path tracing identifier of the VPN transmission data packets; Based on the path tracing identifier, the VPN transmission data packets are delivered in an orderly manner, and the status feedback of the VPN transmission data packets is aggregated to obtain the cloud reception packets of the transmission line data.

[0067] The routing mapping data stream is segmented according to a fixed data length and transmission unit. The continuous data stream is divided into several data segments of the same length and transmitted independently. Each data segment maintains a complete content structure and transmission attributes. At the same time, the time of generation of each data segment and the data's own type, length and format information are recorded to obtain data slices of transmission line data. The slice features and slice timestamps of the data slices are then extracted.

[0068] Based on the data sensitivity, data type, and transmission priority contained in the slice characteristics, a one-to-one match is performed against a preset encryption strategy library. High-sensitivity data is matched with a high-strength encryption method, ordinary data with a standard encryption method, and low-sensitivity data with a lightweight encryption method. A unique encryption method and encryption rules are determined for each data slice, resulting in differentiated encryption parameters for the data slice.

[0069] The data slices are encrypted according to the encryption method specified by the differentiated encryption parameters. The encrypted data is combined with the slice timestamp to form a complete payload structure. A dedicated identifier point for subsequent verification is embedded at a fixed position in the payload structure. This identifier point is used to verify whether the data has been tampered with or lost during transmission. After encapsulation, an independent message conforming to the VPN transmission specification is formed, resulting in the VPN transmission data packet of the transmission line data.

[0070] The corresponding transmission tributary number, transmission direction, and transmission order information are written into the header of each VPN transmission data packet. This information serves as a unique identifier for the packet during transmission, enabling each packet to be accurately identified and located. At the same time, the transmission path to which the packet belongs is recorded, thus obtaining the path tracking identifier of the VPN transmission data packet.

[0071] According to the transmission order and transmission branch specified by the path tracing identifier, the VPN transmission data packets are sent to the corresponding channels for transmission in sequence. During the transmission process, the arrival status, packet loss, and transmission delay information of the packets are collected in real time. The cloud receiving device receives all packets completely and summarizes all transmission status information. All received packets are temporarily stored and their status is integrated to obtain the cloud receiving packets of the transmission line data.

[0072] The beneficial effects are as follows: by accurately segmenting and parsing the routing mapping data stream and extracting features and timestamps, and combining the segment features with differentiated encryption parameters to achieve hierarchical security protection, the integrity verification anchors are embedded in the encapsulation to ensure the trustworthiness of data transmission, and path tracing identifiers are injected to make the messages traceable and controllable. Finally, orderly delivery and status aggregation are completed to ensure that VPN transmission data packets are delivered to the cloud securely, completely and accurately, thereby improving the security, controllability and integrity of power transmission line data transmission.

[0073] The integrity verification module 106 is used to perform integrity verification on the cloud-received message to obtain verification information of the transmission line data, and based on the verification information, to perform reliable restoration of the cloud-received message to obtain secure transmission data of the transmission line data.

[0074] In this embodiment of the invention, when the integrity verification module performs integrity verification on the cloud-received message to obtain verification information of the transmission line data, and performs reliable reconstruction of the cloud-received message based on the verification information to obtain secure transmission data of the transmission line data, it is specifically used for: The field consistency of the cloud-received message is compared to obtain the field matching characterization of the cloud-received message; Based on the field matching characteristics, the cloud-received message is identified and traced for verification to obtain a trusted identifier for the cloud-received message; Based on the trusted identifier, the authenticity of the content of the cloud-received message is verified to obtain the verification information of the transmission line data; Based on the verification information, the missing content of the cloud-received message is filled in to obtain the filled message of the cloud-received message; The completed message is reliably integrated to obtain the secure transmission data of the power transmission line.

[0075] The header fields, data fields, and validation fields of the received messages from the cloud are compared bit by bit with the standard field format preset by the sender. The position, length, and value of each field are checked to ensure that they are completely consistent with the standard format. This confirms that there are no misalignments, missing parts, or tampering in the field structure of the received messages. The comparison results are then integrated into an intuitive representation that reflects the degree of field matching, thus obtaining the field matching characterization of the received messages from the cloud.

[0076] Based on the completeness and compliance of the fields presented by the field matching representation, the source of the path tracing identifier integrity verification anchor branch identifier carried by the cloud received message is traced. It is verified whether these identifiers are completely the same as the original identifier sent by the sender, confirming that the message has not been replaced, forged or illegally tampered with, forming an identifier result that can prove the legitimate source of the message, and obtaining a trusted identifier for the cloud received message.

[0077] Based on the legitimate source of the message confirmed by the trusted identifier, the actual data content of the message received in the cloud is checked segment by segment. The received content is compared with the characteristics of the original data from the sending end to determine whether the data has been tampered with, lost, or disordered. All the verification results and abnormalities are summarized into a complete inspection result to obtain the verification information of the transmission line data.

[0078] Based on the missing message location, missing data segment length, and abnormal data entries recorded in the verification information, the corresponding missing content is retrieved from the sender's cache or retransmission queue. The missing part is then accurately filled into the corresponding position of the cloud-received message to repair the incompleteness of the message, restore the message structure and content to a complete state, and obtain the completed message received by the cloud.

[0079] According to the transmission order, slice number, and data combination rules set by the sending end, the completed message is sorted, spliced, and format restored. The scattered message segments are merged into a complete and continuous data structure. The encapsulation information and verification marks added during transmission are removed, and the original data form that can be directly used by the business is restored, ensuring that the data is true, complete, reliable, and usable, thus obtaining the secure transmission data of the power transmission line.

[0080] The beneficial effects are that by constructing a full-process integrity verification system through field consistency comparison, identifier traceability verification, and content authenticity identification, it can accurately identify missing, tampered, or disordered issues that occur in messages during transmission. Based on the verification information, it can complete the missing content and reliable integration, ensuring that the transmission line data received by the cloud is authentic, complete, and has not been tampered with, effectively improving the credibility and availability of data transmission, and providing reliable data support for subsequent power business processing.

[0081] Reference Figure 2 The diagram shown is a flowchart illustrating a method for secure data transmission of power transmission lines based on a VPN encrypted channel, according to an embodiment of the present invention. In this embodiment, the method for secure data transmission of power transmission lines based on a VPN encrypted channel includes: Step a: The feature acquisition module to be transmitted performs risk assessment on the transmission line data, obtains the sensitivity classification of the transmission line data, and performs differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data. Step b: The gateway negotiation and configuration module performs traffic characteristic analysis on the features to be transmitted to obtain the transmission load characteristics of the transmission line data, and negotiates and configures the data transmission load characteristics with the preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data. Step c: The path dynamic planning module performs dynamic planning on the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data; Step d: The multi-channel concurrent mapping module performs multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data; Step e: The grouping, encapsulation, and distribution module encapsulates the routing mapping data stream into groups to obtain VPN transmission data packets of the transmission line data, and distributes and transmits the VPN transmission data packets to obtain cloud receiving packets of the transmission line data. Step f: The integrity verification module performs integrity verification on the cloud-received message to obtain verification information of the transmission line data, and based on the verification information, performs reliable restoration of the cloud-received message to obtain secure transmission data of the transmission line data.

[0082] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0083] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application device that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A data security transmission device for power transmission lines based on a VPN encrypted channel, characterized in that, The device includes a module for acquiring features to be transmitted, a gateway negotiation and configuration module, a path dynamic planning module, a multi-channel concurrent mapping module, a packet encapsulation and distribution module, and an integrity verification module, wherein: The module for obtaining the features to be transmitted is used to perform risk assessment on the transmission line data, obtain the sensitivity classification of the transmission line data, and perform differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data. The gateway negotiation and configuration module is used to perform traffic characteristic analysis on the characteristics to be transmitted, obtain the transmission load characteristics of the transmission line data, and negotiate and configure the data transmission load characteristics with the preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data. The path dynamic planning module is used to dynamically plan the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data. The multi-channel concurrent mapping module is used to perform multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data; The packet encapsulation and distribution module is used to encapsulate the routing mapping data stream into packets to obtain VPN transmission data packets of the transmission line data, and to distribute and transmit the VPN transmission data packets to obtain cloud reception packets of the transmission line data. The integrity verification module is used to perform integrity verification on the cloud-received message to obtain verification information of the transmission line data, and based on the verification information, to perform reliable restoration of the cloud-received message to obtain secure transmission data of the transmission line data.

2. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 1, characterized in that, When the module for acquiring features to be transmitted performs risk assessment on transmission line data, obtains the sensitivity classification of the transmission line data, and performs differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data, it is specifically used for: Semantic parsing is performed on the transmission line data to obtain its structured features; Risk quantification is performed on the structured features to obtain the risk characterization of the transmission line data; Based on the risk characterization, the sensitivity attributes of the transmission line data are classified and mapped to obtain the sensitivity classification of the transmission line data. Based on the sensitivity classification, redundant fields of the transmission line data are non-intrusively stripped to obtain simplified data of the transmission line data. The simplified data is normalized and reconstructed to obtain the transmission characteristics of the transmission line data.

3. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 1, characterized in that, When the gateway negotiation and configuration module performs traffic characteristic analysis on the features to be transmitted to obtain the transmission load characteristics of the transmission line data, and negotiates and configures the data transmission load characteristics with preset VPN gateway connection policy parameters to obtain a secure and encrypted transmission channel for the transmission line data, it is specifically used for: The transmission line data is subjected to flow profile extraction to obtain multidimensional flow features of the transmission line data. By performing load situation analysis on the multidimensional flow characteristics, the transmission load characteristics of the transmission line data are obtained. Based on preset VPN gateway connection policy parameters, differential policy matching is performed on the transmission load characteristics to obtain candidate gateway configuration parameters for the transmission line data. Based on the candidate gateway configuration parameters, the feasibility of the transmission path for the feature to be transmitted is verified to obtain the link negotiation characterization of the transmission line data. By adapting the link negotiation representation to a security protocol, a secure encrypted transmission channel for the transmission line data is obtained.

4. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 3, characterized in that, When the gateway negotiation and configuration module performs load situation analysis on the multi-dimensional traffic characteristics to obtain the transmission load characteristics of the transmission line data, it is specifically used for: The multidimensional flow characteristics are analyzed by time-series correlation to obtain the flow fluctuation sequence of the transmission line data. Pattern recognition is performed on the flow fluctuation sequence to obtain the behavioral pattern label of the transmission line data; Based on the behavioral pattern labels, the peak flow of the transmission line data is compared with a threshold to obtain the congestion risk level of the transmission line data. Based on the congestion risk level, the weights of the multidimensional flow characteristics are adjusted to obtain the transmission load characteristics of the transmission line data.

5. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 1, characterized in that, When the path dynamic planning module performs dynamic planning on the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data, it is specifically used for: Path enumeration is performed on the secure encrypted transmission channel to obtain the initial candidate paths for the transmission line data; The transmission delay characteristics of the initial candidate path are analyzed for trend prediction to obtain the delay prediction characterization of the transmission line data. Based on the time delay prediction characterization, the transmission congestion nodes in the candidate paths are avoided and screened to obtain the available paths for the transmission line data. Based on the historical transmission records of the transmission line data, the stability of the available paths is backtested to obtain the path score of the transmission line data; The overall transmission efficiency value of the available path is calculated based on the latency prediction characterization, the congestion risk level, and the path score. A global optimization search is performed on the comprehensive transmission efficiency value to obtain the optimal transmission channel for the transmission line data.

6. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 5, characterized in that, The formula for calculating the overall transmission performance value is as follows: ; in, The overall transmission performance value is... Rate the path. This is the time delay prediction characterization. The congestion risk level is... The preset weighting coefficients, The preset weighting coefficients, These are the preset weighting coefficients.

7. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 1, characterized in that, When the multi-channel concurrent mapping module performs multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data, it is specifically used for: The optimal transmission channel is decomposed into multiple paths to obtain the concurrent transmission branches of the transmission line data; Extract the branch identifier and branch carrying capacity from the concurrent transmission branches; Based on the carrying capacity of the branch, the feature to be transmitted is partitioned into feature loads to obtain feature load fragments of the concurrent transmission branch; Based on the branch identifier and the characteristic load fragment, the matching degree of the concurrent transmission branch is checked to obtain the load distribution weight of the concurrent transmission branch; Based on the load distribution weight, the characteristic load fragments are branch-bound to obtain the load mapping relationship of the concurrent transmission branches; The load mapping relationship is mapped to the optimal transmission channel to obtain the routing mapping data stream of the transmission line data.

8. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 1, characterized in that, When the packet encapsulation and distribution module performs packet encapsulation on the routing mapping data stream to obtain VPN transmission data packets of the transmission line data, and distributes and transmits the VPN transmission data packets to obtain cloud reception packets of the transmission line data, it is specifically used for: The routing mapping data stream is segmented and parsed to obtain data slices of the transmission line data, and the slice features and slice timestamps of the data slices are extracted. Based on the slice characteristics, the data slice is subjected to encryption strategy matching to obtain the differentiated encryption parameters of the data slice; Based on the differentiated encryption parameter set and the slice timestamp, the data slice is encapsulated with encrypted payload and a preset integrity verification anchor is embedded to obtain the VPN transmission data packet of the transmission line data. The VPN transmission data packets are injected with a distribution path identifier to obtain the path tracing identifier of the VPN transmission data packets; Based on the path tracing identifier, the VPN transmission data packets are delivered in an orderly manner, and the status feedback of the VPN transmission data packets is aggregated to obtain the cloud reception packets of the transmission line data.

9. The data security transmission device for power transmission lines based on a VPN encrypted channel as described in claim 1, characterized in that, When the integrity verification module performs integrity verification on the cloud-received message to obtain verification information of the transmission line data, and performs reliable reconstruction of the cloud-received message based on the verification information to obtain secure transmission data of the transmission line data, it is specifically used for: The field consistency of the cloud-received message is compared to obtain the field matching characterization of the cloud-received message; Based on the field matching characteristics, the cloud-received message is identified and traced for verification to obtain a trusted identifier for the cloud-received message; Based on the trusted identifier, the authenticity of the content of the cloud-received message is verified to obtain the verification information of the transmission line data; Based on the verification information, the missing content of the cloud-received message is filled in to obtain the filled message of the cloud-received message; The completed message is reliably integrated to obtain the secure transmission data of the power transmission line.

10. A method for secure data transmission in power transmission lines based on a VPN encrypted channel, characterized in that, The method for using the VPN-based encrypted channel-based power transmission line data security transmission device according to claim 1: Step a: The feature acquisition module to be transmitted performs risk assessment on the transmission line data, obtains the sensitivity classification of the transmission line data, and performs differential cleaning on the sensitivity classification to obtain the features to be transmitted of the transmission line data. Step b: The gateway negotiation and configuration module performs traffic characteristic analysis on the features to be transmitted to obtain the transmission load characteristics of the transmission line data, and negotiates and configures the data transmission load characteristics with the preset VPN gateway connection policy parameters to obtain a secure encrypted transmission channel for the transmission line data. Step c: The path dynamic planning module performs dynamic planning on the secure encrypted transmission channel to obtain the optimal transmission channel for the transmission line data; Step d: The multi-channel concurrent mapping module performs multi-channel concurrent mapping on the features to be transmitted based on the optimal transmission channel to obtain the routing mapping data stream of the transmission line data; Step e: The grouping, encapsulation, and distribution module encapsulates the routing mapping data stream into groups to obtain VPN transmission data packets of the transmission line data, and distributes and transmits the VPN transmission data packets to obtain cloud receiving packets of the transmission line data. Step f: The integrity verification module performs integrity verification on the cloud-received message to obtain verification information of the transmission line data, and based on the verification information, performs reliable restoration of the cloud-received message to obtain secure transmission data of the transmission line data.