A terminal security access and data protection method based on a virtual power plant

CN122204401BActive Publication Date: 2026-09-18SHENZHEN YUENENG ENERGY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610235286.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-02-27
Publication Date
2026-09-18
Estimated Expiration
2046-02-27

AI Technical Summary

Technical Problem

[0003]现有技术中,虚拟电厂终端多依赖软件协议或固定密钥方式实现身份认证与数据加密,容易受到终端仿冒、密钥泄露、重放攻击及数据篡改等安全风险影响;同时,数据传输过程通常侧重内容加密,缺乏对会话时序、数据顺序及终端运行状态的综合保护,难以有效防范复杂攻击场景

Benefits of technology

本发明通过将终端安全接入、会话级硬件认证与数据传输保护深度融合于虚拟电厂运行架构中,形成了一种以硬件时序和会话行为为核心的端到端的安全防护机制。相较于仅依赖软件协议或固定密钥的现有技术,本方法通过双层硬件认证模块动态生成会话临时标识和动态会话密钥,使每一次终端接入均与终端实时状态、会话触发行为及时序特征唯一绑定,有效避免终端伪装、会话冒用及密钥重放风险;同时,通过将虚拟电厂数据在硬件层面进行分段处理,并在加密过程中引入会话授权令牌、非线性顺序加密及扰动时序发送,使数据的内容安全性、顺序安全性和时序安全性同时得到保障,即便数据被截获也难以重组还原;控制中心基于对应的硬件解密模块和会话授权令牌进行逐段校验与顺序恢复,进一步增强了数据完整性校验和重放防护能力。整体方案充分利用硬件寄存器、时钟周期和触发时序等底层特性,在不显著增加系统通信负载的前提下,大幅提升虚拟电厂终端接入的可信性和数据传输的抗攻击能力,适用于对安全性和可靠性要求较高的虚拟电厂集中管控场景。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122204401B_ABST
    Figure CN122204401B_ABST
Patent Text Reader

Abstract

This invention relates to the field of data transmission technology, and in particular to a method for secure terminal access and data protection based on a virtual power plant. The method includes the following steps: setting up a two-layer hardware authentication module in the terminal device to complete secure access based on terminal status and session characteristics; sending a temporary session identifier and a dynamic session key to the control center via a secure bus, whereby the control center generates a one-time session authorization token and returns it to the terminal; hardware segmenting the collected virtual power plant data, binding each data unit to the session authorization token, performing non-linear sequential encryption, and sending it according to a perturbation timing sequence; the control center decrypts and verifies the data units segment by segment based on the session authorization token, and reconstructs the complete data by combining the sending order and the perturbation timing sequence. This invention, by introducing a two-layer authentication, non-linear encryption, and perturbation transmission mechanism based on hardware timing and session behavior, achieves trusted virtual power plant terminal access and end-to-end security and replay protection throughout the data transmission process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data transmission technology, and in particular to a method for secure terminal access and data protection based on a virtual power plant. Background Technology

[0002] As the application of virtual power plants in distributed energy aggregation, load dispatching, and collaborative control continues to expand, a large number of terminal devices need to interact with the control center through communication networks. Terminal access security and data transmission reliability have become important factors affecting the stable operation of virtual power plants.

[0003] In existing technologies, virtual power plant terminals mostly rely on software protocols or fixed keys for authentication and data encryption, making them vulnerable to security risks such as terminal impersonation, key leakage, replay attacks, and data tampering. Furthermore, data transmission typically focuses on content encryption, lacking comprehensive protection for session timing, data order, and terminal operating status, making it difficult to effectively defend against complex attack scenarios. In virtual power plant applications with a large number of terminals, frequent access, and complex communication environments, existing security mechanisms struggle to balance access trustworthiness, real-time performance, and overall system security.

[0004] Therefore, there is an urgent need for a terminal security access and data protection method that can combine hardware characteristics, session behavior and data transmission process to improve the security and reliability of virtual power plant operation. Summary of the Invention

[0005] Therefore, it is necessary to provide a terminal security access and data protection method based on a virtual power plant to solve at least one of the above-mentioned technical problems.

[0006] To achieve the above objectives, a terminal security access and data protection method based on a virtual power plant is provided. This method is applied to the terminal, terminal equipment, and control center of the virtual power plant. The terminal is electrically connected to the control center via a secure communication interface hosted by its terminal equipment. The terminal equipment has a built-in hardware encryption module, and the control center has a built-in hardware decryption module. The method includes the following steps: Step S1: Configure a two-layer hardware authentication module in the terminal device; Step S2: The terminal sends a temporary session identifier and a dynamic session key to the control center via the security bus. The control center generates a one-time session authorization token based on the received information and returns the session authorization token to the terminal according to the hardware handshake sequence. Step S3: The terminal divides the collected virtual power plant data into multiple data units according to hardware logic. Each data unit is encrypted in a non-linear order by binding the current session authorization token in the hardware encryption module and sent sequentially according to the perturbation timing. Step S4: The control center sequentially verifies each data unit through the hardware decryption module and the corresponding session authorization token, and restores the complete virtual power plant data according to the sending order and disturbance timing, thereby achieving end-to-end security protection and replay protection.

[0007] The present invention has the following beneficial effects: This invention deeply integrates secure terminal access, session-level hardware authentication, and data transmission protection into the virtual power plant's operational architecture, forming an end-to-end security protection mechanism centered on hardware timing and session behavior. Compared to existing technologies that rely solely on software protocols or fixed keys, this method dynamically generates temporary session identifiers and dynamic session keys through a two-layer hardware authentication module. This ensures that each terminal access is uniquely bound to the terminal's real-time state, session triggering behavior, and timing characteristics, effectively avoiding risks such as terminal spoofing, session impersonation, and key replay. Simultaneously, by segmenting virtual power plant data at the hardware level and introducing session authorization tokens, non-linear sequential encryption, and perturbation-based timing transmission during encryption, the content security, sequence security, and timing security of the data are simultaneously guaranteed. Even if the data is intercepted, it is difficult to reconstruct and restore. The control center performs segment-by-segment verification and sequence recovery based on the corresponding hardware decryption module and session authorization token, further enhancing data integrity verification and replay protection capabilities. The overall solution fully utilizes the underlying characteristics of hardware registers, clock cycles, and trigger timing to significantly improve the reliability of virtual power plant terminal access and the anti-attack capability of data transmission without significantly increasing the system communication load. It is suitable for centralized management and control scenarios of virtual power plants with high security and reliability requirements. Attached Figure Description

[0008] Figure 1 This is a flowchart illustrating the steps of a method for secure terminal access and data protection based on a virtual power plant. Figure 2 for Figure 1 A detailed flowchart illustrating the implementation steps of step S2. Figure 3 This is a schematic diagram illustrating the relationship between a terminal security access and data protection method based on a virtual power plant, as described in this application. The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0009] The technical method of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0010] Furthermore, the accompanying drawings are merely illustrative of the invention and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor methods and / or microcontroller methods.

[0011] It should be understood that although the terms "first," "second," etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are used merely to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0012] To achieve the above objectives, please refer to Figures 1 to 3 A method for secure terminal access and data protection based on a virtual power plant is disclosed. This method is applied to terminals, terminal equipment, and a control center within a virtual power plant. The terminal is electrically connected to the control center via a secure communication interface hosted by its terminal equipment. The terminal equipment has a built-in hardware encryption module, and the control center has a built-in hardware decryption module. The method includes the following steps: Step S1: Configure a two-layer hardware authentication module in the terminal device; In one embodiment, to improve the security of the terminal device, a dual-layer hardware authentication module is pre-configured in the terminal device. The dual-layer hardware authentication module includes a first hardware authentication module and a second hardware authentication module, which are used for different levels of authentication and encryption processing, respectively.

[0013] During the setup process, the first hardware authentication module is first integrated into the main control chip or security processing unit of the terminal device to handle security tasks such as device identification, fingerprint or key storage; then the second hardware authentication module is placed in a separate security chip or security coprocessor to handle dynamic token generation, session key management and encrypted communication with the control center.

[0014] In some embodiments, the dual-layer hardware authentication modules are interconnected through an internal security bus, enabling the first hardware authentication module and the second hardware authentication module to work together, while preventing security failures caused by single-point hardware attacks or single-module malfunctions.

[0015] It is important to note that during the power-on initialization of the terminal device, the dual-layer hardware authentication module needs to complete self-test and initialization, including verifying the integrity of the module, loading the preset key, and initializing the random number generator, to ensure that subsequent authentication operations can be executed reliably.

[0016] In some embodiments, the dual-layer hardware authentication module can be interface-bound with the terminal device's operating system or application software to automatically trigger hardware-level security authentication when the device starts up, a session is established, or data is transmitted, thereby improving the security of the terminal device accessing the virtual power plant system.

[0017] Step S2: The terminal sends a temporary session identifier and a dynamic session key to the control center via the security bus. The control center generates a one-time session authorization token based on the received information and returns the session authorization token to the terminal according to the hardware handshake sequence. In one embodiment, after the terminal device completes the initialization of the two-layer hardware authentication module, the terminal device sends a temporary session identifier and a dynamic session key to the control center via the security bus. The temporary session identifier is used to mark the uniqueness of the current session, while the dynamic session key is used for encrypted communication and authentication.

[0018] During transmission, the terminal device first generates a temporary session identifier through the first hardware authentication module and encrypts the dynamic session key through the second hardware authentication module; then, the combined information is sent to the control center through the security bus to ensure the confidentiality and integrity of the information during transmission.

[0019] After receiving the information sent by the terminal, the control center first verifies the temporary session identifier to confirm that the identifier has not been used or forged. Then, it uses the dynamic session key to authenticate the terminal's identity and generates a one-time session authorization token. This token contains the terminal's session permissions and validity period information, which is used to limit the scope and duration of session operations.

[0020] The generated session authorization token is returned to the terminal device according to a preset hardware handshake sequence. In some embodiments, the hardware handshake sequence includes multi-level handshake steps, such as: firstly, a first hardware authentication module completes the initial token reception confirmation, and then a second hardware authentication module performs token integrity verification to ensure that the token has not been tampered with or intercepted.

[0021] It is important to note that multiple verification mechanisms can be set up during the process of returning the session authorization token to the terminal, including timestamp verification, session identifier matching, and cross-verification of the dynamic session key, thereby improving communication security and preventing security risks such as man-in-the-middle attacks or reuse of session tokens.

[0022] In some embodiments, once the terminal successfully receives and verifies the session authorization token, it can initiate a secure session to exchange encrypted data with the control center for secure access and data protection operations of the virtual power plant system.

[0023] Step S3: The terminal divides the collected virtual power plant data into multiple data units according to hardware logic. Each data unit is encrypted in a non-linear order by binding the current session authorization token in the hardware encryption module and sent sequentially according to the perturbation timing. In one embodiment, after completing the session authorization token verification in step S2, the terminal device first performs hardware logic partitioning on the collected virtual power plant data. The terminal divides the overall data stream into several continuous data units, the size of which can be preset according to the data type and acquisition frequency. For example, each unit contains 10 to 50 measurement data points or each unit corresponds to a real-time data segment of 1 to 5 seconds.

[0024] Subsequently, each data unit is processed within the terminal's hardware encryption module. Specifically, this includes binding the session authorization token generated in step S2 to the current data unit, ensuring that each encrypted data unit can only be verified using that session token. Within the hardware encryption module, a non-linear encryption algorithm is executed on each data unit, employing hardware-level obfuscation and scrambling techniques. This ensures that the same data unit generates different ciphertexts in different sessions, while maintaining that the encryption order depends on perturbation parameters or a randomized sequence to prevent prediction or reverse parsing. Based on the perturbation counter and time offset value set internally in the terminal, the encrypted data units are sent sequentially in a non-linear, controllable perturbation order. The transmission interval can be dynamically adjusted, for example, varying between 200 and 500 milliseconds, to further enhance transmission security.

[0025] In some embodiments, the hardware encryption module also records the transmission status of each data unit and automatically adjusts the perturbation timing and retransmission order when transmission fails or is abnormally interrupted, to ensure data integrity and session security.

[0026] It is important to note that by combining session authorization token binding with non-linear sequential encryption, each data unit has independent security protection during transmission, while ensuring that the order between data units is controllable, so that the subsequent control center verification and data parsing processes can accurately correspond to the original data collection order.

[0027] Finally, the terminal sends all data units to the control center in sequence in the manner described above.

[0028] Step S4: The control center sequentially verifies each data unit through the hardware decryption module and the corresponding session authorization token, and restores the complete virtual power plant data according to the sending order and disturbance timing, thereby achieving end-to-end security protection and replay protection.

[0029] In one embodiment, after receiving each data unit sent by the terminal, the control center first inputs each data unit into the hardware decryption module for processing. The hardware decryption module uses the corresponding session authorization token generated in step S2 to perform the following operations: verifying the session authorization token attached to each data unit to confirm that the data unit belongs to a valid session, preventing the acceptance of data with unauthorized or expired tokens. Using the session authorization token, a non-linear decryption operation is performed on the data unit to restore the encrypted data to the original virtual power plant data fragments. In some embodiments, integrity verification is performed during decryption to ensure that the data has not been tampered with during transmission. Based on the perturbation timing and sequence identifier at the time of terminal transmission, the decrypted data units are reordered, restoring out-of-order or non-linearly perturbed data fragments to continuous time-series data, thereby reconstructing the complete virtual power plant data stream.

[0030] In some embodiments, the control center also performs replay protection checks on each decrypted data unit: it checks whether the timestamp, session identifier, and sequence index of the data unit are duplicated or abnormal. If a data unit is found to be sent repeatedly or has an abnormal timing, the unit is rejected and an anomaly log is recorded to prevent data replay attacks from affecting the integrity of the virtual power plant data.

[0031] It is important to note that the hardware decryption module can be combined with a high-precision time synchronization mechanism to ensure that the data sequence is restored according to the actual acquisition time, thereby guaranteeing the continuity and accuracy of the virtual power plant data. Finally, after the above decryption, session verification, disturbance timing recovery, and replay protection processes, the control center obtains complete, continuous, and secure virtual power plant data.

[0032] In another embodiment, the diagram showing the secure access and data protection relationship of the virtual power plant terminal can be referenced. Figure 3 In this process, sequence ① indicates that after the terminal collects the raw data from the virtual power plant, it divides it into multiple independent data units according to hardware logic, preparing for subsequent encryption and transmission. Sequence ② indicates that each data unit is bound to the current session authorization token in the terminal device's hardware encryption module and undergoes non-linear sequential encryption, ensuring that each data block has a unique identity and encryption protection. Sequence ③ indicates that the encrypted data units are shuffled in their original order and sent to the control center sequentially according to the perturbation sequence. This dynamically shuffled transmission method can effectively prevent data replay attacks. Sequence ④ indicates that the control center uses the hardware decryption module to verify the legitimacy of each data unit one by one using the corresponding session authorization token, and then restores the complete original data according to the sending order and perturbation sequence, completing end-to-end security protection.

[0033] Preferably, step S1 includes: A dual-layer hardware authentication module is set in the terminal device. The dual-layer hardware authentication module includes a first module and a second module. The first module generates a temporary session identifier based on the terminal status register, and the second module generates a dynamic session key based on the characteristics of the previous communication and a random perturbation sequence before each access.

[0034] In one embodiment, and in some embodiments, a dual-layer hardware authentication module is pre-installed in the terminal device to ensure secure communication with the control center. The dual-layer hardware authentication module includes a first module and a second module: this module connects to the terminal device's status register and reads the terminal device's operating status information in real time, including power status, operating mode, and communication interface status. Based on the read terminal status register information, a temporary session identifier is generated. This identifier uniquely corresponds to the current session and is used for subsequent session authorization and data encryption binding. The temporary session identifier is generated during each session initialization and expires after the session ends or times out, ensuring the independence and non-replayability of each communication.

[0035] Before each access or data transmission, the second module generates a dynamic session key based on characteristics of the previous communication (such as the response token, encrypted data digest, or transmission status information from the previous session) and a random perturbation sequence. The dynamic session key has a short validity period, is valid only within the current transmission session, and can be bound to a temporary session identifier generated by the first module. This key is used for hardware encryption of data units sent by the terminal, ensuring the security and unpredictability of each data unit.

[0036] In some embodiments, the dual-layer hardware authentication module is connected to the CPU and storage unit on the terminal device via a dedicated security bus. The first module is responsible for quickly generating session identifiers, and the second module is responsible for dynamic key generation and hardware encryption before each data access, ensuring end-to-end security throughout the entire communication process.

[0037] It is important to note that through the dual-layer hardware authentication mechanism, the terminal device can achieve the following functions: generate a unique temporary identifier for each session to prevent session replay; perform non-linear hardware encryption on data units based on dynamic session keys to improve data transmission security; and combine session identifiers and dynamic keys to achieve end-to-end encryption protection and anti-tampering capabilities.

[0038] Preferably, the first module generates a session temporary identifier based on the terminal status register, including: Obtain the current access session and read at least one terminal status register corresponding to the current access session on the terminal device, wherein the terminal status register is used to reflect the terminal power-on status, running stage or communication interface status; The contents of the terminal status register are combined and their values ​​are obtained to form the original status identifier data corresponding to the current session; The original state identifier data is input into the hardware identifier generation logic of the first module, and associated with the session trigger signal to generate a temporary session identifier that uniquely corresponds to the current session. When a session ends or the terminal state changes, the current session temporary identifier is cleared and its reuse in subsequent access processes is prohibited.

[0039] In one embodiment, when a terminal device accesses the control center, it first identifies the currently active session and determines at least one terminal status register corresponding to that session. The terminal status register is used to reflect key operational information of the terminal device, such as: terminal power-on status (power on, standby, or restart); current operating stage (initialization, data acquisition, hibernation, etc.); and communication interface status (wired, wireless, or secure channel status).

[0040] In some embodiments, multiple status registers can be read simultaneously to ensure the uniqueness and complexity of the generated session identifier.

[0041] The read status register contents are combined and processed using bitwise concatenation, XOR, or cryptographic hashing to obtain the original status identifier data. This data reflects the current terminal status characteristics and is used in subsequent session identifier generation logic.

[0042] The raw status identifier data is input into the hardware identifier generation logic built into the first module. Simultaneously, the current session trigger signal is acquired; this signal can originate from a session request from the control center or a session initialization event on the terminal. The hardware identifier generation logic jointly processes the raw status identifier data and the session trigger signal to generate a temporary session identifier uniquely corresponding to the current session.

[0043] In some embodiments, dedicated hardware logic circuits can be used to implement nonlinear mixing and perturbation, thereby improving the unpredictability of the identifier.

[0044] When the current session ends, or the contents of the terminal status register change significantly (such as restarting or entering standby mode), the first module will immediately clear the session temporary identifier. The cleared session temporary identifier is prohibited from being reused in subsequent sessions to prevent session replay attacks.

[0045] It is important to note that the temporary session identifier generated through the above steps has the following characteristics: it is uniquely bound to the current session, ensuring the independence of each session; it is dynamically generated based on changes in the terminal state register, and can be updated as the terminal's operating state is adjusted; it is directly generated in the hardware logic, reducing software intervention and improving security and real-time performance.

[0046] Preferably, the original status identifier data is input into the hardware identifier generation logic of the first module and associated with the session trigger signal, specifically as follows: When an access request is detected by a terminal, the first module receives a session trigger signal generated by the terminal's communication interface, whereby the session trigger signal is used to characterize the occurrence of this access behavior; Within the preset hardware timing window when the session trigger signal arrives, the original state identifier data is latched into the identifier generation register unit of the first module; Based on the triggering order of the session triggering signals and their corresponding hardware timing positions, the original state identifier data is rearranged bit-wise to form session-related state data; Output the session-associated state data as a temporary session identifier for the current session, and allow it to be invoked only within the corresponding session period.

[0047] In one embodiment, when the terminal device detects an access request, the terminal communication interface generates a session trigger signal. This signal is used to identify the occurrence of this session access behavior. The first module receives the session trigger signal and internally identifies the arrival time and triggering sequence of the signal. The session trigger signal may include digital pulses, level changes, or bus communication events for hardware timing triggering.

[0048] Within the preset hardware timing window when the session trigger signal arrives, the first module latches the original state identifier data into the identifier generation register unit. The identifier generation register unit is a hardware register or a dedicated storage circuit used to temporarily store the original state data, ensuring that the data is stably stored under hardware timing control.

[0049] The first module performs bit-level rearrangement of the latched original status identifier data based on the arrival order of the session trigger signals and the corresponding hardware timing position. Bit-level rearrangement may include: inverting or swapping specified bits; XORing specified bits; and adjusting the data arrangement order according to the trigger order. The session-associated status data generated after bit-level rearrangement is logically tightly bound to the session trigger signals, achieving uniqueness.

[0050] The generated session-associated state data is output as a temporary session identifier for the current session. The temporary session identifier is only valid within the corresponding session period and automatically expires after the session period ends. It cannot be called repeatedly in other sessions.

[0051] In some embodiments, the session temporary identifier can be directly used by the hardware encryption module or communication authentication logic to protect the security of subsequent data transmission.

[0052] It is important to note that the temporary session identifier generated through this method of associating hardware timing with data bits is uniquely bound to the current session, ensuring the independence of each session; based on hardware trigger timing, it is difficult to be predicted or replayed by external software; and it supports rapid generation and invocation in high-frequency access environments, improving the real-time authentication capabilities of terminal devices.

[0053] Preferably, the bit-level rearrangement of the original state identifier data based on the triggering order of the session trigger signals and their corresponding hardware timing positions includes: The number of times and the order of triggering of session trigger signals during terminal access are counted, and the counting results are written into the timing count register of the first module; Within a preset hardware clock cycle, the timing position corresponding to the arrival of the session trigger signal is recorded, and the timing position is combined with the counting result in the timing counter register to form a session timing index; Based on the session time sequence index, the corresponding data bits are selected from the original state identifier data and their arrangement is adjusted to generate session-related state data after bit-level rearrangement. The session-associated state data is output to the identifier generation register, and data bits that do not match the session time sequence index are prohibited from participating in subsequent reordering operations.

[0054] In one embodiment, during terminal access, whenever a session trigger signal is generated, the first module increments the trigger count and records the order of the trigger signals. The count result is written to a hardware timing counter register, which is dedicated to storing the trigger count information of the current session and is cleared after the session ends.

[0055] Within a preset hardware clock cycle, the first module captures the specific timing position (e.g., clock count value or pulse position) when the session trigger signal arrives. The recorded timing position is combined with the number of triggers in the timing count register to form a session timing index, which is used to uniquely identify each trigger event.

[0056] Based on the session timing index, specific data bits are selected from the original state identifier data. These selected data bits are then rearranged according to the session timing index order. For example, the order of data bits in the output data can be adjusted; the selected bits can be XORed, inverted, or cyclically shifted; and data bits corresponding to different indices can be cross-combined. This rearrangement operation ensures that the generated session-related state data is tightly bound to the triggering order and hardware timing, achieving data uniqueness and unpredictability.

[0057] The bit-level rearranged session-related state data is output to the identifier generation register unit and used as the temporary session identifier for the current session. Data bits that do not match the session timing index are prohibited from participating in subsequent rearrangement operations, ensuring that only signals triggered by the current session affect the generation of the temporary session identifier. When the session ends or the state changes, the bit-level rearrangement results and related registers are cleared to prevent information from being reused or leaked.

[0058] It should be noted that the session-related state data generated through the above embodiments has the following characteristics: it is closely related to the order and timing of the session trigger signal, ensuring that the temporary identifier generated for each session is unique; the bit-level reordering process is completed internally in the hardware and cannot be directly predicted or simulated by the software; it supports rapid calculation and invocation in high-frequency session triggering environments, providing end-to-end security for terminal devices.

[0059] Preferably, selecting the corresponding data bits from the original status identifier data and adjusting their arrangement includes: Based on the session timing index, the original state identifier data is divided into at least one data bit segment of fixed length, and each data bit segment corresponds to a continuous hardware timing interval. The number of times the session trigger signal appears in each hardware timing interval is used as the bit segment offset parameter to determine the basic offset position of each data bit segment in the target arrangement. Within each data segment, based on the relative arrival position of the session trigger signal within the corresponding time interval, at least one of the following operations is performed on the data bits within the data segment: sequential reversal, interleaved insertion, or cyclic movement. The data segments, after being adjusted for offset and internal arrangement, are recombined according to their basic offset positions to form session-related state data with adjusted arrangement.

[0060] In one embodiment, the terminal device is a virtual power plant field acquisition terminal, whose main control chip has several terminal status registers, including but not limited to a power-on status register, an operation phase register, and a communication interface status register. During the session establishment phase, the first module reads status information from the aforementioned registers and forms raw status identification data of 32 bits in length.

[0061] In this embodiment, the 32-bit original status identifier data is divided into four fixed-length data segments according to the hardware timing interval. Each segment is 8 bits long, and the specific correspondence is as follows: Segment 1 (bit0~bit7): corresponds to the terminal power-on status and reset flag; Segment 2 (bit8~bit15): corresponds to the terminal's current operating stage status; Segment 3 (bit16~bit23): corresponds to the communication interface enable and link status; Segment 4 (bit24~bit31): corresponds to the terminal security configuration and anomaly flag. Each data segment corresponds to a continuous hardware timing interval, which is divided by the terminal's internal unified hardware clock, for example, using 10 clock cycles as a timing interval.

[0062] During the process of a terminal initiating an access request, the communication interface generates a session trigger signal. The first module counts the number of times the session trigger signal occurs in each hardware timing interval. For example, 1 session trigger signal is detected in the first timing interval; 3 session trigger signals are detected in the second timing interval; 2 session trigger signals are detected in the third timing interval; and 0 session trigger signals are detected in the fourth timing interval. The above occurrence counts are then used as the bit offset parameters for the corresponding data bits, and the basic offset position of each data bit segment in the target arrangement is determined accordingly. For example, the second bit segment is shifted backward by 3 bits, the third bit segment is shifted backward by 2 bits, while the fourth bit segment remains unchanged.

[0063] Within each data segment, the data bits within the data segment are arranged and adjusted according to the relative arrival position of the session trigger signal within the corresponding hardware timing interval.

[0064] In one example, one or a combination of the following rules are used: when the session trigger signal first appears within the timing interval, the corresponding bit segment is reversed; when the session trigger signal arrives in the middle of the timing interval, the corresponding bit segment is interleaved, that is, the high 4 bits and low 4 bits are alternately arranged; when the session trigger signal arrives at the end of the timing interval, the corresponding bit segment is cyclically shifted, for example, cyclically shifted left by 2 bits. For example, for the second bit segment (bit 8 to bit 15), if the session trigger signal arrives in the middle of the timing interval, interleaving is performed on the 8 bits of data; for the third bit segment, if the trigger signal arrives near the end of the timing interval, a cyclic left shift is performed.

[0065] The first module reassembles the data segments, after adjustment of bit offset and internal arrangement, according to the previously determined base offset positions to form the final session association state data. This session association state data is written to the identifier generation register and serves as the temporary session identifier for the current session, and can only be accessed within the corresponding session period; data segments that do not match the current session timing index will be blocked by hardware logic and prohibited from participating in subsequent rearrangement or identifier generation processes.

[0066] Preferably, based on the relative arrival position of the session trigger signal within the corresponding time interval, performing at least one of the following operations on the data bits within the data segment: sequential reversal, interleaving insertion, or cyclic shifting: Obtain the arrival time offset of the session trigger signal within the corresponding timing interval, wherein the arrival time offset is in clock cycles and is within the range of 0 to 32 clock cycles; When the arrival time offset is within the range of 0 to 10 clock cycles, the data bits in the corresponding data segment are reversed, that is, rearranged from the most significant bit to the least significant bit according to the bit number. When the arrival time offset is within the range of 11 to 20 clock cycles, the data bits in the corresponding data bit segment are interleaved, that is, the data bits are alternately inserted and recombined according to the parity bit sequence number. When the arrival time offset is within the range of 21 to 32 clock cycles, the data bits in the corresponding data bit segment are cyclically shifted, with a shift amount of 1 to 8 bits. After completing the sequence reversal, interleaving insertion, or cyclic shift operation, output the adjusted data bit field.

[0067] In one embodiment, the first module configures a set of timing detection logic for each data bit segment to obtain the arrival time offset of the session trigger signal within the corresponding hardware timing interval. The arrival time offset is measured in system hardware clock cycles and is obtained by reading the count value of the local timing counter when the session trigger signal arrives; its value ranges from 0 to 32 clock cycles. The following explanation uses a single 8-bit data bit segment as an example, with the initial content set as: Original data bit segment: b7b6b5b4b3b2b1b0.

[0068] When the arrival time offset of the session trigger signal within the corresponding timing interval is detected to be within the range of 0 to 10 clock cycles, the first module controls the bit segment processing unit to perform a sequence reversal operation on the data bit segment. Specifically, the data bits are rearranged from the most significant bit to the least significant bit according to the bit sequence number, and the original sequence b7b6b5b4b3b2b1b0 is adjusted to: the reversed data bit segment: b0b1b2b3b4b5b6b7. This reversal operation is completed in one step by a hardware multiplexer without introducing additional computational delay.

[0069] When the arrival time offset is within the range of 11 to 20 clock cycles, the first module performs an interleaving insertion operation on the data bit segment. In this embodiment, the interleaving insertion operation specifically involves grouping the data bits according to their parity bit numbers, extracting the even-numbered bits (b0, b2, b4, b6) and the odd-numbered bits (b1, b3, b5, b7) and arranging them alternately to form a new bit sequence. For example, the data bit segment after interleaving insertion is: b0b1b2b3b4b5b6b7; or in another optional implementation, it is formed as: b0b2b1b3b4b6b5b7. The specific arrangement rules can be preset as fixed logic in the hardware to ensure consistency within the same session cycle.

[0070] When the arrival time offset is within the range of 21 to 32 clock cycles, the first module performs a cyclic shift operation on the data segment. In this embodiment, the displacement of the cyclic shift is determined by taking the modulo of the arrival time offset and the length of the data segment. For example, when the arrival time offset is 23 clock cycles, a cyclic left shift of 3 bits is determined; when the arrival time offset is 29 clock cycles, a cyclic left shift of 5 bits is determined. Taking a cyclic left shift of 3 bits as an example, the original data segment b7b6b5b4b3b2b1b0 becomes the cyclically shifted data segment: b4b3b2b1b0b7b6b5. This cyclic shift operation is implemented through a shift register in conjunction with wraparound logic.

[0071] After completing the order reversal, interleaving insertion, or cyclic shift operation, the first module outputs the adjusted data bit segment to the bit segment buffer register unit and marks the data bit segment as having completed the timing association processing; data bit segments that do not trigger the above conditions remain in their original arrangement state and do not participate in this bit-level rearrangement.

[0072] As an example of the present invention, reference is made to... Figure 2 As shown, step S3 in this example includes: Step S31: Input the collected virtual power plant data into the data segmentation control unit, and perform hardware logic segmentation of the virtual power plant data according to the preset data bus width to generate at least two data units, wherein each data unit has a fixed data bit length; Step S32: Assign a session authorization token identifier corresponding to the current session to each data unit, and write the session authorization token identifier into the corresponding data unit control field to form a session-bound data unit; Step S33: Send the session-bound data units sequentially into the hardware encryption module. In the hardware encryption module, determine the encryption processing order according to the session authorization token identifier, and perform non-linear sequential encryption on each data unit so that the encrypted output order of the data units is inconsistent with their original generation order. Step S34: After completing the nonlinear sequential encryption, according to the data transmission disturbance parameters generated by the session trigger signal, different transmission waiting periods are set for each encrypted data unit, and the data is sent to the control center in sequence according to the corresponding disturbance timing.

[0073] In one embodiment, after the terminal device collects a frame of virtual power plant operation data, it inputs the virtual power plant data to the data segmentation control unit.

[0074] In this embodiment, the data bus width of the terminal device is preset to 64 bits. The data segmentation control unit performs hardware logic segmentation on the input virtual power plant data according to the data bus width and a fixed length. For example, when the acquired virtual power plant data length is 256 bits, the data segmentation control unit divides the virtual power plant data into four data units through a parallel register array. Each data unit has a data bit length of 64 bits, denoted as data units D1, D2, D3, and D4, respectively. After segmentation, each data unit is written to its corresponding data unit buffer register, carrying its original generation sequence number, for subsequent comparison and recovery.

[0075] After data unit segmentation is completed, the terminal device invokes the valid session authorization token identifier within the current session period. In this embodiment, the session authorization token identifier is a fixed-length token field, such as a 32-bit binary identifier, issued by the control center during the session establishment phase and cached on the terminal side. The data segmentation control unit writes the session authorization token identifier into the control field of each data unit, establishing a one-to-one binding relationship between each data unit and the current session authorization token, thereby forming session-bound data units. For example, the data structure of data units D1 to D4 can be represented as: Control field: Session authorization token identifier; Data field: 64-bit virtual power plant data content. Through the above method, it is ensured that each data unit carries a clear session identity attribute in subsequent processing.

[0076] In this embodiment, session-bound data units are sequentially sent to the hardware encryption module in the order of their generation. The hardware encryption module has internal sequence control logic, which dynamically determines the encryption processing order of the data units based on the session authorization token identifier carried in the data unit and a preset non-linear sequence mapping rule.

[0077] For example, in the current session, the hardware encryption module calculates the following sequence mapping result based on the session authorization token identifier: Original sequence: D1→D2→D3→D4, Encryption processing sequence: D3→D1→D4→D2. The hardware encryption module performs encryption operations on each data unit according to the above non-linear sequence. Each data unit is immediately output to the encryption buffer after encryption is completed, and its output order is inconsistent with the original generation order. This non-linear sequential encryption process is completed at the hardware level, and external software cannot directly perceive or predict the actual encryption order.

[0078] After completing the nonlinear sequential encryption, the timing transmission control unit of the terminal device generates corresponding data transmission perturbation parameters based on the session trigger signal. In this embodiment, the data transmission perturbation parameters include at least one transmission waiting period parameter, used to indicate the number of clock cycles each encrypted data unit needs to wait before transmission. For example, for the encrypted data units, the timing transmission control unit can generate the following perturbation configuration: encrypted data unit D3: transmit after waiting for 2 clock cycles; encrypted data unit D1: transmit after waiting for 5 clock cycles; encrypted data unit D4: transmit after waiting for 1 clock cycle; encrypted data unit D2: transmit after waiting for 4 clock cycles. The timing transmission control unit times each encrypted data unit according to the above transmission waiting period parameters, and after the corresponding waiting period ends, transmits the data units to the control center sequentially according to the perturbation timing.

[0079] Preferably, the perturbation parameters sent based on the data generated by the session trigger signal include: The session trigger signals are counted, and the count results are written to the disturbance count register; Within a preset hardware clock cycle, the arrival time of the session trigger signal is collected, and a corresponding timing offset value is generated in clock cycles. The counting result and timing offset value in the disturbance count register are input into the disturbance parameter generation logic. At least one data transmission disturbance parameter is generated according to the preset combination rules, and the data transmission disturbance parameter is stored in the data transmission control unit.

[0080] In one embodiment, when a terminal device establishes a new communication session or enters the data transmission phase, the session trigger detection unit monitors the session trigger signal generated by the terminal communication interface in real time. In this embodiment, whenever a valid session trigger signal is detected, the disturbance count register performs an auto-increment count operation within the current session period and stores the count result in the register. For example, during a data transmission preparation process, if the session trigger signal is detected three times in succession, the count results recorded in the disturbance count register will be 1 for the first trigger, 2 for the second trigger, and 3 for the third trigger, respectively, which is used to characterize the number of times and the sequence of trigger signals occurring in the current session. The disturbance count register is cleared after the session ends to prevent historical count results from affecting subsequent sessions.

[0081] In this embodiment, the terminal device is equipped with a hardware clock unit synchronized with the system master clock. When a session trigger signal arrives, the timing acquisition unit samples the arrival time of the trigger signal within a preset hardware clock cycle and records its time offset relative to the current hardware clock start point.

[0082] The time offset is represented in clock cycles as the basic unit and written into the corresponding timing offset buffer unit. For example, within a fixed-length hardware timing window, the session trigger signal may arrive at the 3rd, 7th, or 12th clock cycle. The timing acquisition unit records the corresponding timing offset value to reflect the specific arrival position of the trigger signal within the timing window.

[0083] In this embodiment, the disturbance parameter generation logic simultaneously receives the counting result from the disturbance count register and the timing offset value from the timing acquisition unit. The disturbance parameter generation logic performs joint processing on the counting result and the timing offset value according to a preset combination rule to generate at least one data transmission disturbance parameter.

[0084] For example, the disturbance parameter generation logic can determine the basic disturbance level to be used for this data transmission based on the current count result in the disturbance count register; then, based on the corresponding timing offset value, it can refine and adjust the basic disturbance level to obtain the data transmission disturbance parameters used to control the data unit's transmission waiting period or transmission sequence. The generated data transmission disturbance parameters are written into the disturbance parameter storage area inside the data transmission control unit and can be directly called during subsequent data transmission processes.

[0085] After generating the data transmission perturbation parameters, the data transmission control unit associates and stores these parameters with the current session identifier. During subsequent data unit transmission, the data transmission control unit sets different transmission waiting times or transmission orders for each encrypted data unit according to the stored data transmission perturbation parameters, thereby achieving dynamic perturbation of the data transmission timing. When the current session ends, the data transmission control unit clears the stored data transmission perturbation parameters to prevent them from being reused in the next session.

[0086] The preferred, preset combination rules are as follows: Set the count result in the disturbance count register as the first disturbance factor, where the first disturbance factor is a dimensionless integer with a value range of 1 to 16; The timing offset value is set as the second perturbation factor, where the second perturbation factor is in clock cycles and the value ranges from 0 to 32 clock cycles. Data transmission perturbation parameters are generated according to the following hardware combination rules: The first perturbation factor and the second perturbation factor are weighted and combined to obtain the result after modulo processing; The result after modulo processing is mapped to data transmission perturbation parameters, where the data transmission perturbation parameters are in units of clock cycles and range from 1 to 8 clock cycles. Write the data transmission disturbance parameters into the data transmission control unit.

[0087] In one embodiment, the counting result recorded in the disturbance count register is directly used as the first disturbance factor. The first disturbance factor is a dimensionless integer value used to reflect the cumulative triggering characteristics of the session trigger signal in the current session, and its value is limited to the range of 1 to 16. For example, during a session, if the session trigger signal is the 5th trigger in the current session, the counting result in the disturbance count register is 5, and the corresponding first disturbance factor is set to 5; when the counting result exceeds 16, the disturbance parameter generation logic limits it to a preset range to ensure the stability of subsequent processing.

[0088] The arrival time of the session trigger signal recorded by the timing acquisition unit is set as the second perturbation factor. The second perturbation factor, using a hardware clock cycle as the basic unit, characterizes the specific arrival position of the session trigger signal within a preset hardware timing window, and its value range is limited to 0 to 32 clock cycles. For example, when the session trigger signal arrives at the 12th clock cycle within a certain hardware timing window, the timing offset value recorded by the timing acquisition unit is 12, and the corresponding second perturbation factor is 12.

[0089] The perturbation parameter generation logic simultaneously reads the first perturbation factor and the second perturbation factor within the same hardware processing cycle, and performs a weighted combination process on them. This weighted combination process comprehensively reflects the trigger frequency and timing arrival characteristics of the session trigger signal, ensuring that the generated data transmission perturbation parameter is affected by both the trigger frequency and timing position. After the combination process is completed, the perturbation parameter generation logic performs a modulo-based constraint process on the combination result, ensuring that the final result falls within a preset finite value range, thereby preventing the perturbation parameter from becoming too large or out of control.

[0090] The combined result after modulo processing is further mapped to data transmission perturbation parameters. These parameters, measured in hardware clock cycles, are limited to a range of 1 to 8 clock cycles and are used to directly control the waiting period or transmission rhythm of data units before transmission. For example, in a single combination process, if the mapped value of the combined result after limitation is 3, the generated data transmission perturbation parameter will be 3 clock cycles; the data transmission control unit will delay the transmission action by 3 clock cycles before sending the corresponding data unit.

[0091] After generating data transmission perturbation parameters, the perturbation parameter generation logic writes these parameters into the perturbation parameter register area of ​​the data transmission control unit and stores them in association with the current session identifier. During subsequent data transmission, the data transmission control unit directly invokes these perturbation parameters to set different transmission wait periods for different data units, thereby achieving dynamic perturbation of the transmission timing without changing the data content. When the current session ends, the data transmission control unit clears the written perturbation parameters to prevent them from being reused in subsequent sessions.

[0092] Most importantly, the control center sequentially verifies each data unit using the hardware decryption module and the corresponding session authorization token, including: The control center receives each encrypted data unit sent by the terminal device according to the disturbance timing, and stores each received data unit into the hardware buffer register in the order of receipt; For each data unit, the data unit and its bound session authorization token identifier are read sequentially from the hardware buffer register, and the token identifier is input into the token verification unit of the hardware decryption module. In the hardware decryption module, the read data unit is matched and verified with the corresponding session authorization token. Data decryption is initiated only when the verification is successful. Units that fail the verification are marked as abnormal and subsequent decryption is blocked. The hardware decryption module performs non-linear sequential decryption processing on the verified data units according to the decryption order parameters embedded in the session authorization token, so that the decryption output order corresponds to the original terminal generation order.

[0093] In one embodiment, the control center receives encrypted data units sent by the terminal device according to the perturbation timing sequence, and stores each received data unit in a hardware buffer register in the order of arrival. The hardware buffer register may be a FIFO type register, used to ensure the consistency of the recorded receiving order with subsequent decryption processing.

[0094] For each data unit stored in the hardware buffer register, the control center sequentially reads the data unit and its associated session authorization token identifier. After reading, the session authorization token identifier is input into the token verification unit in the hardware decryption module.

[0095] In the hardware decryption module, the token verification unit matches and verifies the data unit against the corresponding session authorization token. Specific operations include: checking if the unique identifier in the session authorization token matches the data unit's binding information; checking if the session authorization token's validity period matches the current session state; only units that pass verification are allowed to enter the decryption processing channel, while units that fail verification are immediately marked as abnormal, and the hardware decryption module blocks subsequent decryption actions to prevent illegal data from interfering with normal data processing.

[0096] For verified data units, the hardware decryption module performs non-linear sequential decryption processing based on the decryption order parameters embedded in the session authorization token. This non-linear sequential decryption can be achieved by adjusting the read order of the internal buffer of the decryption module or through an internal asynchronous decryption pipeline, restoring the decryption output order to the original generation order of the terminal device.

[0097] In practice, the decrypted data unit can be directly written into the data recovery buffer of the control center, and the receiving timestamp and verification status of the data unit are recorded for subsequent integrity checks and end-to-end security audits.

[0098] Of particular importance is the process of matching and verifying the read data unit against the corresponding session authorization token, which includes: In the token verification unit of the hardware decryption module, the session binding identifier in the header of the read data unit is extracted and compared with the corresponding session authorization token read from the buffer register; Based on preset hardware verification rules, the comparison results determine whether the data unit and the session authorization token are consistent. The hardware verification rules include: Perform a bit-by-bit comparison between the session token identifier and the data unit identifier; Calculate the XOR value of the two and count the number of different bits in the XOR result, the number of different bits shall not exceed 1 bit; When the XOR result is less than or equal to the preset threshold, the match is confirmed to be successful, and the data unit is marked as valid to enter the decryption process; When the XOR result is greater than a preset threshold, the data unit is marked as abnormal, and a blocking signal is generated in the hardware decryption module to prevent the unit from participating in subsequent decryption.

[0099] In one embodiment, the token verification unit of the hardware decryption module first extracts the session binding identifier contained in the header of the read data unit. This identifier is used to characterize the unique binding relationship between the data unit and the session authorization token. Subsequently, the extracted session binding identifier is compared with the corresponding session authorization token read from the buffer register.

[0100] The hardware decryption module performs verification operations according to preset hardware verification rules. These hardware verification rules include the following steps: comparing the session authorization token identifier with the session binding identifier in the data unit header bit by bit to determine if each bit is consistent; performing difference statistics on the comparison results; if the number of differing bits is less than or equal to a preset threshold, the data unit is confirmed to have successfully matched the session authorization token; if the number of differing bits exceeds the preset threshold, the match is deemed to have failed, the data unit is marked as abnormal, and a blocking signal is generated in the hardware decryption module to prevent the data unit from participating in subsequent decryption processing.

[0101] If a match is successful, the data unit is marked as valid and enters the decryption processing channel of the hardware decryption module. The hardware decryption module performs non-linear sequential decryption on the valid data unit according to the order parameters embedded in the session authorization token to restore the original data generation order.

[0102] In practice, the hardware decryption module can simultaneously record the verification status, reception time, and matching result of each data unit, enabling subsequent integrity auditing and security tracing of the complete data stream. This method ensures that only bound, legitimate data units can participate in decryption, preventing unauthorized data injection or replay attacks.

[0103] Therefore, the embodiments should be considered as exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of the equivalents of the application are intended to be included within the invention.

[0104] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.

Claims

1. A method for secure terminal access and data protection based on a virtual power plant, characterized in that, The method, which utilizes terminals, terminal equipment, and a control center in a virtual power plant, involves the following steps: The terminal is electrically connected to the control center via a secure communication interface hosted by the terminal equipment it carries. The terminal equipment has a built-in hardware encryption module, and the control center has a built-in hardware decryption module. Step S1: Configure a two-layer hardware authentication module in the terminal device; wherein, step S1 includes: A dual-layer hardware authentication module is set in the terminal device. The dual-layer hardware authentication module includes a first module and a second module. The first module generates a temporary session identifier based on the terminal status register, and the second module generates a dynamic session key based on the characteristics of the previous communication and a random perturbation sequence before each access. Step S2: The terminal sends a temporary session identifier and a dynamic session key to the control center via the security bus. The control center generates a one-time session authorization token based on the received information and returns the session authorization token to the terminal according to the hardware handshake sequence. Step S3: The terminal divides the collected virtual power plant data into multiple data units according to hardware logic. Each data unit is encrypted non-linearly by binding the current session authorization token in the hardware encryption module, and then sent sequentially according to the perturbation timing. Step S3 includes the following steps: Step S31: Input the collected virtual power plant data into the data segmentation control unit, and perform hardware logic segmentation of the virtual power plant data according to the preset data bus width to generate at least two data units, wherein each data unit has a fixed data bit length; Step S32: Assign a session authorization token identifier corresponding to the current session to each data unit, and write the session authorization token identifier into the corresponding data unit control field to form a session-bound data unit; Step S33: Send the session-bound data units sequentially into the hardware encryption module. In the hardware encryption module, determine the encryption processing order according to the session authorization token identifier, and perform non-linear sequential encryption on each data unit so that the encrypted output order of the data units is inconsistent with their original generation order. Step S34: After completing the nonlinear sequential encryption, based on the data transmission perturbation parameters generated by the session trigger signal, different transmission waiting periods are set for each encrypted data unit, and the data is sequentially transmitted to the control center according to the corresponding perturbation timing; wherein, the data transmission perturbation parameters generated by the session trigger signal include: The session trigger signals are counted, and the count results are written to the disturbance count register; Within a preset hardware clock cycle, the arrival time of the session trigger signal is collected, and a corresponding timing offset value is generated in clock cycles. The counting result and timing offset value in the disturbance count register are input into the disturbance parameter generation logic to generate at least one data transmission disturbance parameter according to a preset combination rule, and the data transmission disturbance parameter is stored in the data transmission control unit; wherein, the preset combination rule is as follows: Set the count result in the disturbance count register as the first disturbance factor, where the first disturbance factor is a dimensionless integer with a value range of 1 to 16; The timing offset value is set as the second perturbation factor, where the second perturbation factor is in clock cycles and the value ranges from 0 to 32 clock cycles. Data transmission perturbation parameters are generated according to the following hardware combination rules: The first perturbation factor and the second perturbation factor are weighted and combined to obtain the result after modulo processing; The result after modulo processing is mapped to data transmission perturbation parameters, where the data transmission perturbation parameters are in units of clock cycles and range from 1 to 8 clock cycles. Write the data transmission disturbance parameters into the data transmission control unit; Step S4: The control center sequentially verifies each data unit through the hardware decryption module and the corresponding session authorization token, and restores the complete virtual power plant data according to the sending order and disturbance timing, thereby achieving end-to-end security protection and replay protection.

2. The terminal security access and data protection method based on a virtual power plant according to claim 1, characterized in that, The first module generates a temporary session identifier based on the terminal status register, including: Obtain the current access session and read at least one terminal status register corresponding to the current access session on the terminal device, wherein the terminal status register is used to reflect the terminal power-on status, running stage or communication interface status; The contents of the terminal status register are combined and their values ​​are obtained to form the original status identifier data corresponding to the current session; The original state identifier data is input into the hardware identifier generation logic of the first module, and associated with the session trigger signal to generate a temporary session identifier that uniquely corresponds to the current session. When a session ends or the terminal state changes, the current session temporary identifier is cleared and its reuse in subsequent access processes is prohibited.

3. The terminal security access and data protection method based on a virtual power plant according to claim 2, characterized in that, The raw status identifier data is input into the hardware identifier generation logic of the first module, and then associated with the session trigger signal for processing. When an access request is detected by a terminal, the first module receives a session trigger signal generated by the terminal's communication interface, whereby the session trigger signal is used to characterize the occurrence of this access behavior; Within the preset hardware timing window when the session trigger signal arrives, the original state identifier data is latched into the identifier generation register unit of the first module; Based on the triggering order of the session triggering signals and their corresponding hardware timing positions, the original state identifier data is rearranged bit-wise to form session-related state data; Output the session-associated state data as a temporary session identifier for the current session, and allow it to be invoked only within the corresponding session period.

4. The terminal security access and data protection method based on a virtual power plant according to claim 3, characterized in that, Based on the triggering order of session trigger signals and their corresponding hardware timing positions, bit-level rearrangement of the original status identifier data includes: The number of times and the order of triggering of session trigger signals during terminal access are counted, and the counting results are written into the timing count register of the first module; Within a preset hardware clock cycle, the timing position corresponding to the arrival of the session trigger signal is recorded, and the timing position is combined with the counting result in the timing counter register to form a session timing index; Based on the session time sequence index, the corresponding data bits are selected from the original state identifier data and their arrangement is adjusted to generate session-related state data after bit-level rearrangement. The session-associated state data is output to the identifier generation register, and data bits that do not match the session time sequence index are prohibited from participating in subsequent reordering operations.

5. The terminal security access and data protection method based on a virtual power plant according to claim 4, characterized in that, Selecting the corresponding data bits from the original status identifier data and adjusting their arrangement includes: Based on the session timing index, the original state identifier data is divided into at least one data bit segment of fixed length, and each data bit segment corresponds to a continuous hardware timing interval. The number of times the session trigger signal appears in each hardware timing interval is used as the bit segment offset parameter to determine the basic offset position of each data bit segment in the target arrangement. Within each data segment, based on the relative arrival position of the session trigger signal within the corresponding time interval, at least one of the following operations is performed on the data bits within the data segment: sequential reversal, interleaved insertion, or cyclic movement. The data segments, after being adjusted for offset and internal arrangement, are recombined according to their basic offset positions to form session-related state data with adjusted arrangement.

6. The terminal security access and data protection method based on a virtual power plant according to claim 5, characterized in that, Based on the relative arrival position of the session trigger signal within the corresponding time interval, at least one of the following operations is performed on the data bits within the data segment: sequential reversal, interleaved insertion, or cyclic shifting. Obtain the arrival time offset of the session trigger signal within the corresponding timing interval, wherein the arrival time offset is in clock cycles and is within the range of 0 to 32 clock cycles; When the arrival time offset is within the range of 0 to 10 clock cycles, the data bits in the corresponding data segment are reversed, that is, rearranged from the most significant bit to the least significant bit according to the bit number. When the arrival time offset is within the range of 11 to 20 clock cycles, the data bits in the corresponding data bit segment are interleaved, that is, the data bits are alternately inserted and recombined according to the parity bit sequence number. When the arrival time offset is within the range of 21 to 32 clock cycles, the data bits in the corresponding data bit segment are cyclically shifted, with a shift amount of 1 to 8 bits. After completing the sequence reversal, interleaving insertion, or cyclic shift operation, output the adjusted data bit field.

Citation Information

Patent Citations

  • Industrial control automation system

    CN115113563A

  • Medical knowledge distribution method and system based on dynamic token technology

    CN118473838A