A charging pile group cooperative scheduling and privacy management method and device based on secure multi-party computation, an electronic device, a computer readable storage medium, a charging pile and a system
By extracting encrypted gradient vectors from charging pile clusters and generating global load gradient compensation vectors using secure multi-party computation, the contradiction between privacy protection and load governance in charging pile cluster scheduling is resolved, achieving synergy between privacy protection and load scheduling, and improving the stability and flexibility of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING CHAOYANG ELECTRIC POWER IND DEV CO LTD
- Filing Date
- 2026-05-28
- Publication Date
- 2026-07-10
AI Technical Summary
Existing charging pile group scheduling schemes present a contradiction between protecting the charging privacy of vehicle owners and managing the overall load of the power grid. They cannot achieve collaborative scheduling of multiple nodes while ensuring that the underlying data does not leave the local area, and the system has poor security in managing charging behavior data.
By extracting local electricity consumption preference parameters and converting them into encrypted gradient vectors that hide the original dimensions, encrypted state aggregation operations are performed in the cloud using a secure multi-party computation protocol to generate a global load gradient compensation vector, which is then sent to local charging piles for load scheduling and adjustment, forming a decentralized power distribution convergence closed loop.
This approach enhances the consistency of load balancing decisions across the region and the flexibility of system control while protecting user privacy, thereby improving the stability and compliance of coordinated scheduling of charging pile groups.
Smart Images

Figure CN122372328A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of data processing and power distribution network control technology, and more specifically, to a method, device, electronic device, computer-readable storage medium, charging pile and system based on secure multi-party computation for collaborative scheduling and privacy governance of charging pile groups. Background Technology
[0002] With the large-scale popularization of new energy electric vehicles, the concurrent charging behavior of charging pile groups in the power supply area has an increasingly significant impact on the load of the distribution network. The coordinated scheduling and load management of charging pile groups have become key links in maintaining the stable operation of the distribution network.
[0003] Existing charging pile cluster scheduling schemes typically employ a centralized plaintext data acquisition architecture to achieve regional load management. This scheme first requires each charging pile to directly upload its collected raw electricity consumption data, including user charging time, power demand, and instantaneous power, to a central control node. The central control node then aggregates and performs global analysis of this raw plaintext data to generate a load peak-shaving and valley-filling strategy for the entire region. Finally, the central control node issues specific power limiting commands to each charging pile based on this strategy for unified scheduling intervention.
[0004] However, this centralized plaintext data collection architecture has significant technical flaws. Because grid-side load management is highly dependent on data integrity, requiring the collection of detailed underlying electricity consumption data, the original electricity consumption data of a single charging station becomes "off-site" and extremely easy to correlate and reverse-engineer. This creates a severe conflict between protecting the charging privacy of car owners and the overall load management of the power grid. It is impossible to achieve coordinated scheduling of multiple nodes while ensuring that the underlying data does not leave the local area, resulting in poor security for the system's management of charging behavior data. Summary of the Invention
[0005] This application provides a method, apparatus, electronic device, computer-readable storage medium, charging pile, and system for collaborative scheduling and privacy governance of charging pile groups based on secure multi-party computation, so as to at least alleviate the above-mentioned technical problems.
[0006] The technical advantages of the technical solution provided in this application are: This application presents a method and system for collaborative scheduling and privacy governance of charging pile groups based on secure multi-party computation. Addressing the technical shortcomings of traditional plaintext data acquisition architectures—such as the ease with which raw electricity consumption data from a single charging pile can be reverse-engineered and the severe conflict between protecting vehicle owner privacy and global load management—this application solves the security risk of single-pile underlying data being directly separated from the local storage by extracting local electricity consumption preference parameters from initial electricity consumption feature data and converting them into encrypted gradient vectors that hide the original dimensions. Compared to the traditional method of uploading raw power and time-series data in plaintext, this application extracts gradient vectors and performs multinomial obfuscation encryption only within the local microprocessor, ensuring that features representing sensitive user behavior patterns remain local, thus providing higher privacy protection and security.
[0007] Furthermore, this application sends the encrypted gradient vector to the cloud and triggers a secure multi-party computation protocol to perform encrypted state aggregation operations, resolving the coordination contradiction between the dependence of power grid load management on data integrity and the need for underlying privacy to remain local. Traditional solutions require the aggregation of plaintext data for comprehensive analysis, while this application utilizes the symmetric cancellation rules between encrypted exchange channels and random noise arrays in sandboxes to generate a global load gradient compensation vector representing the overall trend without decrypting the gradients of individual charging piles. This eliminates the possibility of data back-calculation while ensuring the consistency of load stabilization decisions across the entire region, and demonstrates strong cross-node collaborative interaction capabilities.
[0008] Finally, this application distributes the global load gradient compensation vector to instruct each local charging pile to correct its local load scheduling instructions, forming a decentralized power distribution convergence closed loop. Traditional control methods rely on a central node to directly limit power, which is highly interventionist; this application, however, distributes compensation amounts through the cloud, and the underlying hardware of each charging pile independently uses the compensation amounts to adjust the baseline drive power output interface. This not only ensures that the concurrent charging load in the target power supply area converges within the preset safety node, but also enhances the system's control flexibility, resulting in a significant improvement in the stability and compliance of comprehensive governance. Attached Figure Description
[0009] Figure 1 This application presents an embodiment of a scenario for collaborative scheduling and privacy governance of charging pile groups based on secure multi-party computation. Detailed Implementation
[0010] like Figure 1The illustration shows a scenario for collaborative scheduling and privacy governance of charging pile groups based on secure multi-party computation according to an embodiment of this application. The embodiment of this application provides a method for collaborative scheduling and privacy governance of charging pile groups based on secure multi-party computation, comprising the following steps: acquiring initial electricity consumption characteristic data of multiple local charging piles located within a target power supply area; extracting local electricity consumption preference representation parameters from the initial electricity consumption characteristic data; determining the gradient update vector of the local electricity consumption preference representation parameters in the current control cycle, and performing a ciphertext conversion operation on the gradient update vector to generate an encrypted gradient vector that hides the dimension of the initial electricity consumption characteristic data; sending the encrypted gradient vector generated by each local charging pile to a cloud collaborative processing server; triggering a secure multi-party computation protocol within the cloud collaborative processing server to perform ciphertext-state aggregation operations on all received encrypted gradient vectors to generate a global load gradient compensation vector for the target power supply area; and distributing the global load gradient compensation vector to each local charging pile to instruct each local charging pile to parse the global load gradient compensation vector and correct its local load scheduling instructions, thereby controlling the power output interface of each local charging pile and converging the concurrent charging load within the target power supply area into a preset power distribution safety node.
[0011] Optionally, initial power consumption characteristic data of multiple local charging piles located within the target power supply area are obtained, and local power consumption preference representation parameters are extracted from the initial power consumption characteristic data. This includes: collecting the port voltage sampling sequence and corresponding access time stamp of each local charging pile within a historical control cycle, generating initial power consumption characteristic data based on the port voltage sampling sequence and access time stamp; constructing a time-domain smoothing track within the configured adaptive filtering node, pushing the initial power consumption characteristic data into the time-domain smoothing track for abrupt interference signal removal; waking up the feature parsing unit to scan the initial power consumption characteristic data after removing abrupt interference signals, locating the stationary point coordinates representing the user's charging behavior pattern, and formatting and reconstructing based on the acquired multiple stationary point coordinates to generate local power consumption preference representation parameters.
[0012] Preferably, the specific implementation process for obtaining initial power consumption characteristic data of multiple local charging piles located within the target power supply area and extracting local power consumption preference representation parameters from the initial power consumption characteristic data is as follows: Each local charging pile first determines the historical control period corresponding to the current control period based on the start time position of the current control period and the scheduling refresh frequency of the charging pile group within the target power supply area. The historical control period is not an arbitrarily selected time segment, but a data review range jointly defined by the sampling range before the access event, the charging access duration range, and the sampling range after the access exit. Among them, the sampling range before the access event is used to carry the no-load benchmark before the vehicle access, the charging access duration range is used to carry the load ramp-up state and stable output state formed after the vehicle access, and the sampling range after the access exit is used to carry the port recovery state after the vehicle exits. After determining the historical control period, each local charging pile writes the historical control period into the sampling period configuration record and establishes a source correspondence between the sampling period configuration record and the power output interface of the corresponding local charging pile, so that the subsequently collected port voltage sampling sequence can point back to its local charging pile, power output interface, and historical control period. Since the historical control period is jointly defined by the sampling range before the access event, the duration of charging access, and the sampling range after access exit, the historical control period can cover the vehicle access time position, vehicle access time position, and vehicle access time position required for the formation of user charging behavior patterns, thus avoiding the lack of a time source basis for subsequent local electricity consumption preference representation parameters due to only capturing a single instantaneous data.
[0013] Preferably, the acquisition process of the port voltage sampling sequence is completed locally at each local charging station. Each local charging station reads the discrete port voltage value from the port detection position of the power output interface according to the sampling cycle configuration record, and establishes a binding relationship between each read discrete port voltage value and the corresponding sampling sequence position. The port detection position is the local sampling position at the power output interface used to form the discrete port voltage value. The port detection position and the power output interface maintain a fixed source correspondence, so that the discrete port voltage value read from the port detection position can point back to the corresponding power output interface. The technical essence of the discrete port voltage value is the port voltage amplitude data corresponding to the power output interface at a sampling moment, and the technical essence of the sampling sequence position is the arrangement position of the discrete port voltage value within the historical control cycle. Each local charging station performs sequential encapsulation of the discrete port voltage values according to the sampling sequence position to form the port voltage sampling sequence. The technical essence of the port voltage sampling sequence is a local load response sequence formed by arranging multiple discrete port voltage values in the order of sampling. Each sequence element in the local load response sequence corresponds to a port voltage amplitude of the power output interface within a historical control period. Therefore, the port voltage sampling sequence can reflect the port voltage change pattern of the local charging pile during vehicle access, load ramp-up, stable output, and access / exit processes.
[0014] Preferably, the configuration process of the access timing stamp is synchronized with the port voltage sampling sequence. When reading the discrete port voltage value, each local charging pile simultaneously reads the sampling time position under the local clock reference and performs relative indexing processing on the sampling time position according to the access trigger position corresponding to the vehicle access event, thus forming an access timing stamp corresponding to the discrete port voltage value. The vehicle access event can be triggered by a change in access state when the power output interface transitions from an idle state to a charging access state. The access trigger position is used to define the time reference point for the start of vehicle access within the historical control cycle. The technical essence of the access timing stamp is time indexing data formed by the local clock reference, sampling time position, and access trigger position, which can express the relative time relationship between the discrete port voltage value and the vehicle access event, whether it is before, after, or during the vehicle access process. Each local charging pile writes the discrete port voltage value, sampling sequence position, and access timing stamp into the same sampling binding record and forms port voltage timing binding data based on multiple sampling binding records. The port voltage timing binding data stores the one-to-one correspondence between the port voltage discrete values, sampling sequence position, and access timing stamp. The port voltage timing binding data then participates in the initial power consumption characteristic data generation process, so that the port voltage sampling sequence is no longer a simple amplitude arrangement, but carries the time source relationship of the access timing stamp.
[0015] Preferably, when generating initial power consumption characteristic data based on the port voltage sampling sequence and access time stamp, each local charging pile first establishes a power consumption sampling bearer record. This record includes the local charging pile identifier, historical control cycle identifier, power output interface identifier, port voltage sampling sequence, access time stamp, and sampling sequence position. The power consumption sampling bearer record serves only as intermediate bearer data and is not directly used as initial power consumption characteristic data. Subsequently, each local charging pile performs time-position alignment processing on the port voltage sampling sequence in the power consumption sampling bearer record according to the access time stamp, forming a time-position aligned port voltage sampling sequence. The time-position alignment processing includes converting the sampling sequence position within the same historical control cycle into a relative time position with reference to the access trigger position, and attaching the discrete port voltage values to the corresponding relative time positions. The time-position aligned port voltage sampling sequence is further divided according to the access time stamp into a pre-access reference segment, an access climb segment, a stable output segment, and an access exit segment. The segment source identifier, segment start and end time positions, port voltage amplitude variation range, and port voltage variation direction of each segment are written into the power consumption characteristic encapsulation record. Each local charging station then performs field encapsulation processing based on the electricity consumption characteristic encapsulation record to form initial electricity consumption characteristic data. The technical essence of the initial electricity consumption characteristic data is that it is a low-level representation data of local charging behavior, which is composed of port voltage sampling sequence, access time stamp, segment source identifier, and port voltage amplitude change relationship. The low-level representation data of local charging behavior is entered into the subsequent adaptive filtering node in the form of initial electricity consumption characteristic data so as to remove abrupt interference signals while retaining the regularity of user charging behavior.
[0016] Preferably, before receiving the initial power consumption characteristic data, the adaptive filtering node first establishes a filtering configuration record based on the historical control cycle identifier, sampling sequence position, and segment source identifier in the initial power consumption characteristic data. The filtering configuration record includes a sampling clock field, a segment source field, a smoothing window width field, a mutation determination amplitude field, an adjacency position field, and an output retention field. The sampling clock field is used to read the sampling interval of the port voltage sampling sequence; the segment source field is used to identify the pre-access reference segment, the access ramp-up segment, the stable output segment, and the access exit segment; the smoothing window width field is used to limit the time span for adjacent port voltage discrete values to enter the same comparison range; the mutation determination amplitude field is used to limit the deviation of the current port voltage discrete value from the adjacent port voltage discrete values; the adjacency position field is used to store the forward and backward adjacency positions of the current port voltage discrete value; and the output retention field is used to write the initial power consumption characteristic data after removing mutation interference signals. The adaptive filtering node constructs a time-domain smoothing track based on the filtering configuration record. The technical essence of this time-domain smoothing track is a continuous buffer path arranged according to the access time stamp. This continuous buffer path assigns a time position, forward adjacent position, backward adjacent position, and segment source identifier to each port voltage discrete value. Because the time-domain smoothing track uses the access time stamp and segment source identifier, the adaptive filtering node can smoothly judge the port voltage discrete values within different segments under the same time indexing caliber, without misjudging the normal rise process in the access climb segment as a sudden interference signal.
[0017] Preferably, when the initial power consumption characteristic data is pushed into the time-domain smoothing track, the adaptive filtering node first reads the access time stamp and sampling sequence position from the initial power consumption characteristic data, and then writes the port voltage discrete values into the continuous buffer positions of the time-domain smoothing track according to the order of the access time stamps. After writing the port voltage discrete value into each continuous buffer position, the adaptive filtering node continues to write the segment source identifier, forward adjacent position, and backward adjacent position corresponding to the port voltage discrete value into the same continuous buffer position to form a port voltage smoothing unit in the time-domain smoothing track. The technical essence of the port voltage smoothing unit is that it is a comparable data unit of port voltage discrete value in the time-domain smoothing track, which simultaneously carries the port voltage amplitude, time position, and segment source. The adaptive filtering node reads the port voltage smoothing units sequentially along the time-domain smoothing track and compares the port voltage discrete value of the current port voltage smoothing unit with the port voltage discrete values in the forward adjacent position and the backward adjacent position to form a local time-domain reference segment. The local time domain reference segment is composed of the current port voltage smoothing unit, the port voltage smoothing unit corresponding to the forward adjacent position, and the port voltage smoothing unit corresponding to the backward adjacent position. The local time domain reference segment then participates in the abrupt interference signal elimination operation, so that the abrupt interference signal elimination operation can be performed based on the continuous change relationship between adjacent time positions, rather than based on the single point amplitude.
[0018] Preferably, the abrupt interference signal removal operation specifically includes short-time spike identification, short-time drop identification, single-point jump identification, and smooth replacement processing. The adaptive filtering node reads the forward port voltage continuous change trend and the backward port voltage continuous change trend of the current port voltage discrete value within the local time domain reference segment, and compares the current port voltage discrete value with the forward port voltage continuous change trend and the backward port voltage continuous change trend. When the current port voltage discrete value shows a short-term upward convexity relative to the continuous trend of the forward port voltage, and the continuous trend of the backward port voltage does not continue this short-term upward convexity, the adaptive filtering node marks the current port voltage discrete value as a short-term spike-type sudden change interference signal; when the current port voltage discrete value shows a short-term downward convexity relative to the continuous trend of the forward port voltage, and the continuous trend of the backward port voltage does not continue this short-term downward convexity, the adaptive filtering node marks the current port voltage discrete value as a short-term drop-type sudden change interference signal; when the current port voltage discrete value deviates from both the forward adjacent position and the backward adjacent position, and the deviation does not form a change in the same direction within a continuous time range, the adaptive filtering node marks the current port voltage discrete value as a single-point jump-type sudden change interference signal. For short-duration spike-type, short-duration drop-type, and single-point jump-type abrupt interference signals, the adaptive filtering node generates a smooth replacement value using the continuous change trends of the forward and backward port voltages in the local time-domain reference segment. This smooth replacement value replaces the marked discrete value of the current port voltage, forming a port voltage smoothing unit after removing the abrupt interference signal. Multiple port voltage smoothing units after removing the abrupt interference signal are re-encapsulated according to the access time stamp to form the initial power consumption characteristic data after removing the abrupt interference signal.
[0019] Preferably, the initial power consumption characteristic data after removing sudden interference signals does not delete the access timing stamp and segment source identifier. Instead, it retains the access timing stamp, sampling sequence position, segment source identifier, and power output interface identifier corresponding to each discrete port voltage value. After completing the sudden interference signal removal operation, the adaptive filtering node writes the initial power consumption characteristic data after removing the sudden interference signal into the output reserved field and generates a filtering completion identifier based on the output reserved field. The filtering completion identifier includes a historical control cycle identifier, a segment source identifier, a filtering completion time position, and a feature parsing unit entry identifier. The historical control cycle identifier is used to limit the historical control cycle corresponding to this filtering completion identifier. The segment source identifier is used to limit the segment range that is still retained in the initial power consumption characteristic data after removing the sudden interference signal. The filtering completion time position is used to indicate the time position when the adaptive filtering node completes the sudden interference signal removal operation. The feature parsing unit entry identifier is used to guide the filtering completion identifier to the corresponding feature parsing unit. The filtering completion identifier then wakes up the feature parsing unit, enabling the feature parsing unit to use the initial power consumption characteristic data after removing the sudden interference signal as the scanning source, instead of rereading the unfiltered port voltage sampling sequence.
[0020] Preferably, the wake-up process of the feature analysis unit is triggered by the filtering completion flag. After detecting the filtering completion flag, the feature analysis unit reads the historical control cycle flag, segment source flag, and feature analysis unit entry flag from the filtering completion flag, and establishes a correspondence between these fields and the initial power consumption feature data after removing sudden interference signals to form a feature analysis trigger record. The feature analysis trigger record includes the scan start time position, scan end time position, segment source flag, port voltage smoothing unit index, and stationary point coordinate writing position. The scan start time position and scan end time position are determined by the access timing stamp, the segment source flag is inherited from the initial power consumption feature data after removing sudden interference signals, the port voltage smoothing unit index is used to locate the port voltage smoothing unit after removing sudden interference signals within the time-domain smoothing track, and the stationary point coordinate writing position is used to save the stationary point coordinates located later. The feature analysis unit scans the initial power consumption feature data after removing sudden interference signals item by item along the access timing stamp according to the feature analysis trigger record, and reads the changes in the rising and falling direction, the duration of the amplitude changes, and the segment source change position between adjacent port voltage discrete values during the scanning process to form a charging behavior change trajectory. The technical essence of the charging behavior change trajectory is a time-series record formed by the continuous change of port voltage amplitude with the access time stamp. This charging behavior change trajectory provides the time and location source and port voltage amplitude source for subsequent positioning of the stationary point coordinates.
[0021] Preferably, after the charging behavior change trajectory is formed, the feature parsing unit performs stationary point coordinate positioning processing based on the charging behavior change trajectory. The feature parsing unit first identifies the rising / falling direction reversal position, long-term stable position, and segment boundary position in the charging behavior change trajectory. The rising / falling direction reversal position indicates the time position where the port voltage amplitude changes from rising to stable, from stable to falling, or from falling to stable. The long-term stable position indicates the time position where the port voltage amplitude maintains a relatively low change in adjacent amplitudes within a continuous time range. The segment boundary position indicates the transition position between the pre-access reference segment, the access climb segment, the stable output segment, and the access exit segment. The feature parsing unit binds the rising / falling direction reversal position, the long-term stable position, and the segment boundary position with the access timing stamp, the port voltage discrete value, and the segment source identifier, respectively, to form candidate stationary point coordinates. Subsequently, the feature parsing unit performs segment source verification and continuity verification on the candidate stationary point coordinates. The segment source verification is used to confirm whether the candidate stationary point coordinates originate from the access climb segment, the stable output segment, or the access exit segment. The continuity verification is used to confirm whether the port voltage change before and after the candidate stationary point coordinates is consistent with the continuous change direction of the charging behavior change trajectory. Candidate stationary point coordinates, verified by fragment source and continuity, are written to the stationary point coordinate writing position to form stationary point coordinates. The technical essence of stationary point coordinates is two-dimensional charging behavior indexing data composed of time position, port voltage amplitude, and fragment source identifier. The two-dimensional charging behavior indexing data comes from the initial power consumption characteristic data after removing abrupt interference signals, and directly participates in subsequent formatting and reconstruction in the form of stationary point coordinates.
[0022] Preferably, the user charging behavior pattern in this application is represented by the recurring port voltage change rhythm of the local charging pile within a historical control cycle, rather than user identity information or user personal attribute information. The port voltage change rhythm includes the starting time position of the port voltage entering the load ramp-up state after the vehicle connects, the duration range of the power output interface entering the stable output state, the decreasing time position of the port voltage change before the vehicle exits, and the time interval relationship between adjacent charging connection processes. The feature parsing unit records the port voltage change rhythm through stationary point coordinates, so that the user charging behavior pattern can be expressed as the arrangement relationship between time position, port voltage amplitude, and segment source identifier. This arrangement relationship is subsequently entered into formatted reconstruction processing without uploading the port voltage sampling sequence or initial electricity consumption feature data to the cloud collaborative processing server. Thus, the source of the local electricity consumption preference representation parameter is limited to the initial electricity consumption feature data within the local charging pile after removing abrupt interference signals. The subsequent encrypted conversion operation deals with the local electricity consumption preference representation parameter and its change direction, not with the plaintext underlying sampling content corresponding to the user charging behavior pattern. The plaintext underlying sampling content includes the port voltage sampling sequence, the access time stamp, and the initial power consumption characteristic data formed by the port voltage sampling sequence and the access time stamp. The plaintext underlying sampling content does not enter the cloud collaborative processing server, thereby maintaining data form isolation between the encrypted gradient vector received by the cloud collaborative processing server and the plaintext underlying sampling content.
[0023] Preferably, when performing formatted reconstruction based on the acquired multiple stationary point coordinates, the feature parsing unit first performs fragment placement processing on the multiple stationary point coordinates according to the fragment source identifier carried by the stationary point coordinates, to form access climb stationary point coordinates, stable output stationary point coordinates, and access exit stationary point coordinates. The access climb stationary point coordinates are used to express the time amplitude position of the port voltage entering the load climb state from the no-load reference after vehicle access; the stable output stationary point coordinates are used to express the time amplitude position of the port voltage amplitude continuously changing at a low level during charging; and the access exit stationary point coordinates are used to express the time amplitude position of the port voltage entering the port recovery state before and after vehicle exit. The feature parsing unit then performs sequential encoding on the access climb stationary point coordinates, stable output stationary point coordinates, and access exit stationary point coordinates according to the access time stamp, to form a stationary point coordinate sequence chain. The stationary point coordinate sequence chain includes multiple stationary point coordinates arranged chronologically, and a time interval field and a port voltage amplitude change field are written between adjacent stationary point coordinates. The time interval field originates from the difference in access time stamps between adjacent stationary point coordinates, and the port voltage amplitude change field originates from the difference in port voltage amplitude between adjacent stationary point coordinates. The stationary point coordinate sequence chain then serves as the direct input for format reconstruction, enabling the format reconstruction to preserve the temporal sequence and port voltage variation relationships in the user's charging behavior patterns.
[0024] Preferably, the formatted reconstruction process includes field expansion processing, field order encapsulation processing, and numerical standardization processing. The feature parsing unit first performs field expansion processing on the stationary point coordinate sequence chain to extract the access start position, climb duration range, stable output duration range, access exit position, time interval between adjacent stationary point coordinates, and port voltage amplitude change field. These fields all originate from the stationary point coordinate sequence chain and maintain a correspondence with the access timing stamp, port voltage discrete value, and segment source identifier. Subsequently, the feature parsing unit writes each field that has undergone field expansion processing into the preference representation bearer record according to a unified field order; this writing process is the field order encapsulation processing. The preference representation bearer record serves as intermediate bearer data, used to carry the field arrangement relationship of the stationary point coordinate sequence chain after field expansion and field order encapsulation processing. After the preference representation bearer record is formed, the feature parsing unit performs numerical standardization processing on the time position field, time interval field, port voltage amplitude field, and port voltage amplitude change field in the preference representation bearer record based on the sampling cycle and port voltage amplitude standard of the local charging pile, to form a unified preference bearer record. The normalized preference record is further encapsulated according to the field source relationship to form a local electricity consumption preference representation parameter. The technical essence of the local electricity consumption preference representation parameter is the local load preference description data formed by the arrangement relationship of stationary point coordinates in the time dimension, port voltage amplitude dimension, and fragment source dimension. In the next processing stage, this local electricity consumption preference representation parameter is compared with the historical electricity consumption preference representation parameter of the previous control cycle to identify feature differences, so as to output the gradient update vector of the evolution direction of the representation data.
[0025] Preferably, when multiple local charging piles exist within the target power supply area, each local charging pile independently generates a local electricity consumption preference representation parameter, and retains the local source relationship in the local electricity consumption preference representation parameter. The local source relationship includes the local charging pile identifier, the historical control cycle identifier, the power output interface identifier, and the source relationship of the local electricity consumption preference representation parameter fields. The local charging pile identifier is used to limit the local charging pile to which the local electricity consumption preference representation parameter belongs; the historical control cycle identifier is used to limit the historical control cycle corresponding to the local electricity consumption preference representation parameter; the power output interface identifier is used to limit the power output interface corresponding to the local electricity consumption preference representation parameter; and the source relationship of the local electricity consumption preference representation parameter fields is used to refer back to the source relationship between the stationary point coordinate sequence chain, the initial electricity consumption characteristic data after removing abrupt interference signals, the initial electricity consumption characteristic data, the port voltage sampling sequence, and the access time stamp. This local source relationship is continued to be read when determining the gradient update vector, so that the gradient update vector can be formed by the difference relationship between the local electricity consumption preference representation parameters of the same local charging pile in different control cycles, without mixing in the plaintext sampling content of other local charging piles. Thus, a continuous data source chain is formed between the port voltage sampling sequence, access time stamp, initial power consumption characteristic data, initial power consumption characteristic data after removing sudden interference signals, stationary point coordinates, stationary point coordinate sequence chain, and local power consumption preference representation parameters. This data source chain continues to be constrained by the local source relationship in the subsequent ciphertext conversion operation. What is subsequently uploaded to the cloud collaborative processing server is the encrypted gradient vector formed by the gradient update vector through the ciphertext conversion operation, rather than the port voltage sampling sequence, initial power consumption characteristic data, or initial power consumption characteristic data after removing sudden interference signals itself.
[0026] Optionally, the feature parsing unit is activated to scan the initial power consumption feature data after removing abrupt interference signals, locate the stationary point coordinates representing the user's charging behavior pattern, and format and reconstruct the acquired multiple stationary point coordinates to generate local power consumption preference representation parameters. This includes: reading the envelope change data of the initial power consumption feature data after removing abrupt interference signals in the time domain coordinate system through the feature parsing unit, extracting the periodic peak nodes and periodic trough nodes in the envelope change data; determining the stationary point coordinates based on the physical timestamps mapped by the periodic peak nodes and periodic trough nodes and the corresponding instantaneous absolute power values; extracting the association weight feature codes of each stationary point coordinate, performing multidimensional tensor transformation on all stationary point coordinates according to the association weight feature codes, and generating local power consumption preference representation parameters stored in tensor format.
[0027] Preferably, the specific implementation process of waking up the feature parsing unit to scan the initial power consumption feature data after removing abrupt interference signals, locating the stationary point coordinates representing the user's charging behavior pattern, and formatting and reconstructing the acquired multiple stationary point coordinates to generate local power consumption preference representation parameters is as follows: After receiving the filtering completion flag, the feature parsing unit first reads the historical control cycle flag, segment source flag, and feature parsing unit entry flag from the filtering completion flag, and then reads the initial power consumption feature data after removing abrupt interference signals from the output reserved field based on the historical control cycle flag. The feature parsing unit reads the access timing stamp, port voltage discrete value, segment source flag, sampling sequence position, and power output interface flag from the initial power consumption feature data after removing abrupt interference signals, and reads the power amplitude field corresponding to the same access timing stamp from the power output interface operation record. The power output interface operation record is generated synchronously during the operation of the local charging pile driving power output interface. The power output interface operation record includes the power output interface identifier, sampling sequence position, access time stamp, and power amplitude field. The power amplitude field contains the output power amplitude of the power output interface at the corresponding access time stamp, and maintains a common time correspondence with the port voltage discrete values in the initial power consumption characteristic data after removing abrupt interference signals. The feature parsing unit writes the port voltage discrete values, power amplitude field, access time stamp, segment source identifier, sampling sequence position, and power output interface identifier into the parsing input carrier record, so that subsequent envelope change data reading, periodic peak node extraction, periodic trough node extraction, stationary point coordinate determination, associated weight feature code extraction, and multidimensional tensor transformation all use the same data source.
[0028] Preferably, the feature parsing unit establishes a time-domain coordinate system based on the parsed input carrying record. This time-domain coordinate system is not simply a graphical coordinate system, but rather a data index structure used to organize the correspondence between time positions and amplitude positions. The horizontal time index of the time-domain coordinate system is formed by converting the access time stamp, which expresses the relative time position of the port voltage discrete value relative to the vehicle access event. The vertical amplitude index of the time-domain coordinate system includes the port voltage amplitude index corresponding to the port voltage discrete value and the instantaneous power absolute value index corresponding to the power amplitude field. The instantaneous power absolute value is formed by the feature parsing unit reading the power amplitude field and performing absolute amplitudeization processing. Absolute amplitudeization processing ensures that the output power amplitude of the power output interface participates in the subsequent stationary point coordinate determination according to a non-negative amplitude caliber, avoiding the influence of charging / discharging direction markings or sampling direction markings on the comparison of power amplitude magnitudes. The feature parsing unit writes the discrete port voltage value and the absolute instantaneous power value under the same access time stamp to the same time position in the time-domain coordinate system. This allows port voltage changes and power amplitude changes to be read under the same time index, thus ensuring that subsequent periodic peak nodes and periodic trough nodes have both port voltage sources and absolute instantaneous power value sources. Each time position in the time-domain coordinate system is linked back to the access time stamp, sampling sequence position, and power output interface identifier in the parsing input bearer record, enabling the data indexing results in the time-domain coordinate system to trace back to the initial power consumption characteristic data after eliminating abrupt interference signals.
[0029] Preferably, the technical essence of envelope change data is amplitude boundary time-series data formed by boundary tracking processing of the initial power consumption characteristic data after removing abrupt interference signals in the time domain coordinate system. Envelope change data includes the upper boundary amplitude trajectory, the lower boundary amplitude trajectory, the start and end access timing stamps of the sliding readout window, the segment source identifier, and the boundary amplitude change direction. The upper boundary amplitude trajectory characterizes the boundary of higher port voltage amplitude changes within a continuous time range, the lower boundary amplitude trajectory characterizes the boundary of lower port voltage amplitude changes within a continuous time range, the start and end access timing stamps of the sliding readout window limit the time range for each boundary tracking process, the segment source identifier distinguishes whether the boundary amplitude originates from a pre-access reference segment, an access ramp-up segment, a stable output segment, or an access exit segment, and the boundary amplitude change direction records the rise and fall of the upper and lower boundary amplitude trajectories between adjacent sliding readout windows. By encapsulating the above fields into envelope change data, the feature parsing unit can identify periodic peak nodes and periodic trough nodes based on boundary changes within a continuous time range, rather than making isolated judgments based on discrete values of a single port voltage. After the envelope variation data is formed, it continues to serve as a common input for the extraction of periodic peak nodes and periodic trough nodes, so as to avoid the periodic peak nodes and periodic trough nodes deviating from the same boundary time series source.
[0030] Preferably, when the feature parsing unit reads the envelope change data, it first arranges the discrete port voltage values in the parsing input bearer record continuously according to the access time stamp order to form a port voltage time sequence arrangement record. Then, the feature parsing unit reads a pre-configured window configuration record, which includes the sliding window width and sliding step interval. The sliding window width is pre-configured based on the sampling rate of the local charging pile and the rate of change of charging access status, and the sliding step interval is pre-configured based on the degree of overlap that needs to be retained between adjacent sliding windows. Based on the sliding window width and sliding step interval in the window configuration record, the feature parsing unit sequentially selects multiple consecutive adjacent discrete port voltage values in the port voltage time sequence arrangement record to form a sliding window. For example, the sliding window width can be configured to cover multiple consecutive sampling positions, and the sliding step interval can be configured to be smaller than the sliding window width, so that adjacent sliding windows share some discrete port voltage values. Within each sliding readout window, the feature parsing unit performs amplitude sorting on the discrete port voltage values, writing the discrete port voltage values with higher amplitudes into the upper boundary candidate record and the discrete port voltage values with lower amplitudes into the lower boundary candidate record. The upper boundary candidate records are connected according to the access time stamp to form the upper boundary amplitude trajectory, and the lower boundary candidate records are connected according to the access time stamp to form the lower boundary amplitude trajectory. The upper boundary amplitude trajectory, the lower boundary amplitude trajectory, and the corresponding sliding readout window start and end access time stamps are then encapsulated into envelope change data, ensuring that the envelope change data maintains a source connection with the port voltage time sequence arrangement record, window configuration record, upper boundary candidate record, and lower boundary candidate record.
[0031] Preferably, after forming the envelope change data, the feature parsing unit performs boundary continuity verification processing on the envelope change data. The boundary continuity verification processing first reads the direction of change of the upper boundary amplitude trajectory and the direction of change of the lower boundary amplitude trajectory between adjacent sliding reading windows, and then reads whether the segment source identifiers between adjacent sliding reading windows are continuous. When a short-term reverse jump occurs in the upper or lower boundary amplitude trajectory between adjacent sliding reading windows, and this short-term reverse jump does not continue in subsequent sliding reading windows, the feature parsing unit marks this short-term reverse jump as a boundary residual disturbance point and writes the boundary residual disturbance point into the boundary residual disturbance point record. The boundary residual disturbance point record stores the access timing stamp, segment source identifier, and source field of the upper or lower boundary amplitude trajectory corresponding to the boundary residual disturbance point. Using the boundary amplitude change directions of the previous and next sliding reading windows, the feature parsing unit performs boundary continuation processing on the boundary residual disturbance points in the boundary residual disturbance point record to form the envelope change data after boundary continuation. The envelope change data after boundary alignment retains the original access time stamp and segment source identifier, so that the subsequent extraction of periodic peak nodes and periodic trough nodes can use the time source relationship of the initial power consumption characteristic data after removing abrupt interference signals.
[0032] Preferably, when extracting periodic peak nodes from the envelope change data, the feature parsing unit first reads the upper boundary amplitude trajectory in the envelope change data after boundary concatenation, and then reads adjacent upper boundary amplitude points in the upper boundary amplitude trajectory in the order of access timing stamps. The feature parsing unit writes the amplitude change direction between adjacent upper boundary amplitude points into the upper boundary direction record, which includes a continuously rising direction, a continuously falling direction, and a stable holding direction. Subsequently, the feature parsing unit identifies the amplitude inflection point in the upper boundary direction record where the continuously rising direction turns into a continuously falling direction, and the amplitude inflection point where the continuously rising direction turns into a stable holding direction, and writes the upper boundary amplitude point corresponding to the amplitude inflection point into the peak candidate node record. The peak candidate node record includes the access timing stamp, port voltage discrete value, instantaneous power absolute value, segment source identifier, and upper boundary direction record source corresponding to the peak candidate node. The upper boundary direction record source in the peak candidate node record is used to indicate that the peak candidate node is formed by the directional inflection of the upper boundary amplitude trajectory, rather than being directly specified by the single-point port voltage discrete value. The candidate peak node record then serves as intermediate data before the formation of periodic peak nodes, and continues to undergo periodic verification processing.
[0033] Preferably, after the peak candidate node record is formed, the feature parsing unit performs periodic verification processing on the peak candidate node record. Periodic verification processing includes time interval reproduction verification, segment source consistency verification, and power amplitude direction verification. Time interval reproduction verification reads the access timing stamp interval between adjacent peak candidate nodes and compares it with the access timing stamp interval between other adjacent peak candidate nodes within the same historical control cycle to identify whether the peak candidate nodes exhibit repeatable time interval relationships within multiple sliding judgment windows. Segment source consistency verification reads the segment source identifier corresponding to the peak candidate node and confirms whether the peak candidate node originates from an access ramp-up segment or a stable output segment. Power amplitude direction verification reads the instantaneous absolute power value corresponding to the peak candidate node and confirms whether the direction of change of the instantaneous absolute power value before and after the peak candidate node matches the upper edge of the load ramp-up or stable output. Peak candidate nodes that pass the time interval reproduction verification, segment source consistency verification, and power amplitude direction verification are confirmed as periodic peak nodes and written into the periodic peak node record. The technical essence of periodic peak nodes is that they represent the time amplitude nodes corresponding to the upper edge of load ramp-up or the upper edge of stable output during the local charging pile charging access process. They can express the position of higher power demand of the local charging pile within the historical control cycle. The periodic peak node record continues to save the access timing stamp, port voltage discrete value, instantaneous power absolute value, segment source identifier, upper boundary direction record source, and periodic verification processing result corresponding to the periodic peak node, so as to facilitate the sequential recording and reading of subsequent periodic nodes.
[0034] Preferably, when extracting periodic trough nodes from the envelope change data, the feature parsing unit reads the lower boundary amplitude trajectory from the envelope change data after boundary concatenation, and reads adjacent lower boundary amplitude points in the lower boundary amplitude trajectory in chronological order of access timing stamps. The feature parsing unit writes the amplitude change direction between adjacent lower boundary amplitude points into the lower boundary direction record, which includes a continuously decreasing direction, a continuously increasing direction, and a stable holding direction. Subsequently, the feature parsing unit identifies the amplitude inflection points in the lower boundary direction record where the continuously decreasing direction turns into a continuously increasing direction, and where the continuously decreasing direction turns into a stable holding direction, and writes the lower boundary amplitude points corresponding to these inflection points into the trough candidate node record. The trough candidate node record includes the access timing stamp, port voltage discrete value, instantaneous power absolute value, segment source identifier, and lower boundary direction record source corresponding to the trough candidate node. The lower boundary direction record source in the trough candidate node record is used to indicate that the trough candidate node is formed by the directional inflection of the lower boundary amplitude trajectory, rather than being directly specified by a single-point port voltage discrete value. The candidate trough node records then serve as intermediate data before the formation of periodic trough nodes, and continue to undergo periodic verification processing.
[0035] Preferably, after the valley candidate node record is formed, the feature parsing unit performs periodic verification processing on the valley candidate node record. Periodic verification processing includes time interval reproduction verification, segment source consistency verification, and power amplitude direction verification. Time interval reproduction verification reads the access timing stamp interval between adjacent valley candidate nodes and compares it with the access timing stamp interval between other adjacent valley candidate nodes within the same historical control period using the same dimensions to identify whether the valley candidate nodes exhibit repeatable time interval relationships within multiple sliding judgment windows. Segment source consistency verification reads the segment source identifier corresponding to the valley candidate node and confirms whether the valley candidate node originates from a pre-access reference segment, a stable output segment, or an access exit segment. Power amplitude direction verification reads the instantaneous absolute power value corresponding to the valley candidate node and confirms whether the direction of change of the instantaneous absolute power value before and after the valley candidate node matches the no-load reference, the lower edge of stable output, or the access exit recovery position. Valley candidate nodes that pass the time interval reproduction verification, segment source consistency verification, and power amplitude direction verification are confirmed as periodic valley nodes and written into the periodic valley node record. The technical essence of periodic trough nodes is that, during the local charging pile charging access process, they correspond to the no-load reference, the lower edge of stable output, or the access exit and recovery position. Together with periodic peak nodes, they describe the fluctuation relationship between port voltage amplitude and instantaneous power absolute value within the historical control cycle. The periodic trough node record continues to save the access timing stamp, port voltage discrete value, instantaneous power absolute value, segment source identifier, lower boundary direction record source, and periodic verification processing result corresponding to the periodic trough node, so as to facilitate the sequential recording and reading of subsequent periodic nodes.
[0036] Preferably, after the periodic peak nodes and periodic trough nodes are formed, the feature parsing unit reads the periodic peak node records and periodic trough node records in the order of access timing stamps, and writes the periodic peak nodes and periodic trough nodes into the periodic node sequence record. The periodic node sequence record includes a node type field, an access timing stamp field, a segment source identifier field, a port voltage discrete value field, an instantaneous power absolute value field, a boundary direction record source field, and a periodic verification processing result field. The node type field distinguishes between periodic peak nodes and periodic trough nodes. The access time stamp field retains the time source of the initial power consumption characteristic data of the periodic peak node or periodic trough node after removing abrupt interference signals. The segment source identifier field identifies the pre-access reference segment, access climb segment, stable output segment, or access exit segment to which the periodic peak node or periodic trough node belongs. The port voltage discrete value field retains the port voltage amplitude corresponding to the periodic peak node or periodic trough node. The instantaneous power absolute value field retains the power amplitude corresponding to the periodic peak node or periodic trough node. The boundary direction record source field indicates the upper or lower boundary direction record. The periodic verification processing result field indicates the periodic verification processing passed by the periodic peak node or periodic trough node. The periodic node sequence record then participates in the stationary point coordinate determination process, so that the stationary point coordinates are jointly limited by the time amplitude correspondence between the periodic peak node and the periodic trough node.
[0037] Preferably, when determining the stationary point coordinates based on the physical timestamps mapped from periodic peak nodes and periodic trough nodes, and the corresponding instantaneous absolute power values, the feature parsing unit first converts the access timing stamps in the periodic node sequence records into physical timestamps. The technical essence of a physical timestamp is a sampling time position formed with a local clock reference; the access timing stamp expresses the relative time relationship between the port voltage discrete value and the vehicle access event, while the physical timestamp expresses the actual sampling position of the port voltage discrete value in the local charging pile's operating timeline. The feature parsing unit reads the access trigger position and the local clock reference, and based on the relative time relationship between the access trigger position and the access timing stamp, maps the access timing stamps of periodic peak nodes to the physical timestamps corresponding to the periodic peak nodes, and maps the access timing stamps of periodic trough nodes to the physical timestamps corresponding to the periodic trough nodes. After the physical timestamps are generated, the feature parsing unit writes the physical timestamps corresponding to the periodic peak nodes, the instantaneous absolute power values corresponding to the periodic peak nodes, the physical timestamps corresponding to the periodic trough nodes, the instantaneous absolute power values corresponding to the periodic trough nodes, the node type field, and the segment source identifier into the stationary point coordinate determination record. The stationary point coordinate determination record is used to carry the time source, power amplitude source, node type source, and segment source required for the stationary point coordinate determination process, and continues to serve as input data for node pairing processing.
[0038] Preferably, the stationary point coordinate determination process specifically includes node pairing processing, time and position verification processing, power amplitude verification processing, and stationary point field encapsulation processing. The node pairing processing first reads adjacent periodic nodes from the stationary point coordinate determination record and the periodic node sequence record, and establishes node pairing relationships between adjacent periodic trough nodes and periodic peak nodes according to the order of access time stamps, or between adjacent periodic peak nodes and periodic trough nodes, to form a periodic node pairing record. The periodic node pairing record includes a preceding periodic node field, a following periodic node field, a preceding node physical timestamp, a following node physical timestamp, an preceding node instantaneous power absolute value, a following node instantaneous power absolute value, and a segment source identifier. After the periodic node pairing record is formed, it enters the time and position verification processing. The time and position verification processing reads the preceding node physical timestamp and the following node physical timestamp, and confirms whether the preceding node physical timestamp and the following node physical timestamp are located within the access climb segment, stable output segment, or access exit segment corresponding to the same charging access process based on the segment source identifier. Periodic node pairing records processed by time and position verification are then processed by power amplitude verification. This process reads the instantaneous absolute power values of the preceding and following nodes and determines whether the direction of change between these values matches the charging state corresponding to the segment source identifier. The periodic node pairing records processed by both time and position verification and power amplitude verification are then encapsulated in the stationary point field to form stationary point coordinates.
[0039] Preferably, during the stationary point field encapsulation process, the feature parsing unit does not directly use the periodic node pairing records as stationary point coordinates. Instead, it extracts the stationary point physical timestamp field, stationary point instantaneous power absolute value field, node type field, segment source identifier, and pairing source field from the periodic node pairing records and writes these fields into the stationary point coordinate carrying record. The stationary point physical timestamp field is derived from the temporal position relationship between the physical timestamps of the preceding and following nodes. The stationary point instantaneous power absolute value field is derived from the power amplitude relationship between the instantaneous power absolute values of the preceding and following nodes. The node type field is used to indicate that the stationary point coordinates originate from a periodic peak node, a periodic trough node, or a periodic node pairing record. The segment source identifier is used to indicate the pre-access reference segment, access climb segment, stable output segment, or access exit segment to which the stationary point coordinates belong. The pairing source field is used to point back to the periodic node pairing record that forms the stationary point coordinates. After the stationary point field encapsulation process is completed, the stationary point coordinates are formed in the stationary point coordinate carrying record. The technical essence of stationary coordinates is local charging behavior indexing data jointly defined by physical timestamps, instantaneous absolute power values, node type fields, fragment source identifiers, and paired source fields. Stationary coordinates do not represent user identity information, but rather represent the time-power indexing results extracted from envelope change data of local charging piles within historical control periods. The stationary coordinate records continue to serve as input data for the extraction of associated weight feature codes, enabling the source relationship of stationary coordinates to enter subsequent formatted reconstruction.
[0040] Preferably, when extracting the associated weight feature code for each stationary coordinate, the feature parsing unit first reads the physical timestamp, instantaneous absolute power value, node type field, segment source identifier, and paired source field from the stationary coordinate carrying record, and establishes an associated weight carrying record based on the above fields. The associated weight carrying record is used to carry the field source before the formation of the associated weight feature code, and it includes the stationary coordinate, physical timestamp, instantaneous absolute power value, node type field, segment source identifier, and paired source field. The technical essence of the associated weight feature code is a structured encoded data used to express the degree of participation of the stationary coordinate in the formation of local electricity preference characterization parameters. The associated weight feature code does not represent a commercial evaluation or a user level, but rather the time stability, power amplitude range, segment effect, and adjacent correlation of the stationary coordinate in the port voltage change rhythm. In specific implementation, the feature parsing unit performs time stability indexing on the physical timestamp of the stationary coordinate to form a time stability field; the time stability field is generated based on the time position reproduction of the same type of stationary coordinate in multiple sliding judgment windows. The feature parsing unit performs power amplitude segment indexing on the instantaneous absolute power value of the stationary point coordinates to form a power amplitude segment field. This field is generated based on the power amplitude distribution of the instantaneous absolute power value within the historical control cycle of the local charging pile. The feature parsing unit also performs segment role indexing on the segment source identifier of the stationary point coordinates to form a segment role field. This field distinguishes the technical role of the stationary point coordinates in accessing a climbing segment, stabilizing an output segment, or accessing an exit segment. Furthermore, the feature parsing unit performs adjacent association indexing on the physical timestamp interval and instantaneous absolute power value changes between the stationary point coordinates and adjacent stationary point coordinates to form an adjacent association field. The time stability field, power amplitude segment field, segment role field, and adjacent association field are collectively encapsulated into an association weight feature code.
[0041] Preferably, after the associated weight feature code is formed, the feature parsing unit establishes a one-to-one correspondence between the associated weight feature code and the corresponding stationary point coordinates to form a stationary point coordinate weight binding record. The stationary point coordinate weight binding record includes the stationary point coordinates, associated weight feature code, node type field, fragment source identifier, physical timestamp, instantaneous power absolute value, and paired source field. The stationary point coordinate weight binding record is used to ensure that each stationary point coordinate enters its corresponding tensor position in subsequent multidimensional tensor transformations according to its time stability field, power amplitude range field, fragment effect field, and adjacent association field, rather than simply being arranged linearly according to temporal order. For stationary coordinates originating from access ramp-up segments where the instantaneous absolute power value transitions from a lower amplitude to a higher amplitude, the associated weight feature code aligns these stationary coordinates into the load ramp-up related position during multidimensional tensor transformation. For stationary coordinates originating from stable output segments with high time stability, the associated weight feature code aligns these stationary coordinates into the stable output related position during multidimensional tensor transformation. For stationary coordinates originating from access exit segments where the instantaneous absolute power value transitions from a higher amplitude to a lower amplitude, the associated weight feature code aligns these stationary coordinates into the access exit related position during multidimensional tensor transformation. Thus, the stationary coordinate weight binding record establishes a field-level mapping relationship between the stationary coordinates and the multidimensional tensor transformation. This field-level mapping relationship continues to serve as the basis for dimension writing processing in the tensor-carrying coordinate record.
[0042] Preferably, when performing multidimensional tensor transformation on all stationary coordinates according to the associated weight feature code, the feature parsing unit first establishes a tensor-carrying coordinate record. The tensor-carrying coordinate record includes a time dimension, a power amplitude dimension, a node type dimension, and a segment source dimension. Specifically, the time dimension carries the physical timestamp corresponding to the stationary coordinate; the power amplitude dimension carries the instantaneous absolute power value corresponding to the stationary coordinate; the node type dimension carries periodic peak nodes, periodic trough nodes, and the stationary coordinate source type formed by pairing periodic nodes; and the segment source dimension carries the pre-access baseline segment, access climb segment, stable output segment, and access exit segment. Each position in the time dimension corresponds to a time range, each position in the power amplitude dimension corresponds to a power amplitude range, each position in the node type dimension corresponds to a node type field, and each position in the segment source dimension corresponds to a segment source identifier. The feature parsing unit determines the writing position of the stationary coordinates in the time dimension according to the time stability field in the associated weight feature code, the writing position in the power amplitude dimension according to the power amplitude segment field in the associated weight feature code, the writing position in the node type dimension according to the node type field, and the writing position in the fragment source dimension according to the fragment effect field in the associated weight feature code. Through the above dimension writing processing, the stationary coordinates are entered into the tensor-carrying coordinate record according to the correspondence between time, power amplitude, node type, and fragment source. The tensor-carrying coordinate record then participates in the tensor field filling process, so that the dimension position in the tensor-carrying coordinate record can carry the stationary coordinate weight binding record.
[0043] Preferably, after the tensor-bearing coordinate record is formed, the feature parsing unit continues to perform tensor field filling processing. Tensor field filling processing does not simply write the stationary coordinates into the same data object and directly use them as local electricity preference representation parameters. Instead, it first writes the stationary coordinate weight binding record into the preference tensor-bearing record, and then performs field arrangement processing and field source verification processing based on the preference tensor-bearing record. Each tensor unit in the preference tensor-bearing record stores the physical timestamp, instantaneous absolute power value, associated weight feature code, node type field, fragment source identifier, and pairing source field corresponding to the stationary coordinates. When multiple stationary coordinates fall into the same tensor unit, the feature parsing unit performs intra-unit ordinal arrangement on the multiple stationary coordinates based on the time stability field and adjacent association field in the associated weight feature code, forming an intra-unit stationary coordinate arrangement record. The intra-unit stationary coordinate arrangement record is then written back to the preference tensor-bearing record, so that the preference tensor-bearing record retains both the multi-dimensional position of the stationary coordinates and the sequential and adjacent relationships between multiple stationary coordinates within the same multi-dimensional position. The field source verification process reads the paired source field, the sequential record of periodic nodes, and the envelope change data after boundary concatenation from each tensor unit. It confirms that the stationary point coordinates in the tensor unit can point back to the initial electricity consumption characteristic data after eliminating abrupt interference signals, thus preventing stationary point coordinates without a source from entering the subsequent local electricity consumption preference representation parameters. After completing the field arrangement and field source verification processes, the preference tensor carrying the record continues to enter the tensor format storage process.
[0044] Preferably, after the preference tensor carrying record completes the tensor field filling process, the feature parsing unit performs tensor format storage processing based on the preference tensor carrying record to form a local electricity consumption preference representation parameter stored in tensor format. The tensor format storage processing includes tensor cell sequential encoding, tensor cell empty space marking, and tensor cell source indexing. Tensor cell sequential encoding is used to arrange the tensor cells in the preference tensor carrying record in a fixed order according to the time dimension, power amplitude dimension, node type dimension, and fragment source dimension; tensor cell empty space marking is used to mark tensor cells without stationary coordinates written, so that the tensor cell maintains a fixed position in subsequent feature difference identification; tensor cell source indexing is used to save the source relationship between stationary coordinates, periodic node sequential records, envelope change data after boundary concatenation, and initial electricity consumption feature data after removing abrupt interference signals. After completing the tensor format storage processing, the preference tensor carrying record is encapsulated into a local electricity consumption preference representation parameter stored in tensor format. The technical essence of the local electricity consumption preference representation parameter is local load preference description data formed by arranging multiple stationary coordinates according to physical timestamps, instantaneous power absolute values, node type fields, fragment source identifiers, and associated weight feature codes. The tensor unit source index in the local electricity consumption preference representation parameter is further used for subsequent feature difference identification, enabling the local electricity consumption preference representation parameter to point back to its corresponding stationary coordinate source.
[0045] Preferably, after the local electricity consumption preference characterization parameters are formed, the feature parsing unit establishes a local source relationship between the local electricity consumption preference characterization parameters and the local charging pile identifier, historical control cycle identifier, and power output interface identifier. The local source relationship is used to limit the local electricity consumption preference characterization parameters to originate from the initial electricity consumption characteristic data of the same local charging pile within the same historical control cycle after removing abrupt interference signals. It is also used to subsequently identify feature differences between the local electricity consumption preference characterization parameters and the historical electricity consumption preference characterization parameters of the previous control cycle. Since the local electricity consumption preference characterization parameters have already undergone multi-dimensional tensor transformation of stationary point coordinates through associated weighted feature codes, subsequent feature difference identification can focus on changes in time position, power amplitude, node type, and fragment source between tensor units, without needing to reread the port voltage sampling sequence or the envelope change data after boundary concatenation. Thus, a continuous data processing relationship is formed between the initial power consumption characteristic data after removing abrupt interference signals, the parsed input bearing record, the time domain coordinate system, the port voltage time sequence arrangement record, the envelope change data, the envelope change data after boundary connection, the periodic peak node, the periodic trough node, the periodic node sequence record, the stationary point coordinate, the associated weight feature code, the stationary point coordinate weight binding record, the tensor bearing coordinate record, the preference tensor bearing record, and the local power consumption preference representation parameter. The subsequent encrypted conversion operation deals with the change result of the local power consumption preference representation parameter, rather than the plaintext underlying sampling content of the local charging pile.
[0046] Optionally, the gradient update vector of the local electricity consumption preference representation parameter in the current control cycle is determined, and a ciphertext transformation operation is performed on the gradient update vector to generate an encrypted gradient vector that hides the dimension of the initial electricity consumption feature data. This includes: reading the historical electricity consumption preference representation parameter of the previous control cycle from the cache space; calling a comparator to identify the feature differences between the local electricity consumption preference representation parameter and the historical electricity consumption preference representation parameter; and outputting the gradient update vector representing the evolution direction of the representation data. The encrypted public key string configured in the corresponding local charging pile is extracted from the preset security key library, and the encrypted public key string is loaded into the key register of the homomorphic encryption engine so that the homomorphic encryption engine performs a polynomial obfuscation operation on the gradient update vector according to the encrypted public key string to generate an encrypted gradient vector with a ciphertext state distribution.
[0047] Preferably, the specific implementation process of determining the gradient update vector of the local electricity consumption preference representation parameter in the current control cycle and performing a ciphertext conversion operation on the gradient update vector to generate an encrypted gradient vector that hides the dimension of the initial electricity consumption feature data is as follows: After each local charging pile forms the local electricity consumption preference representation parameter for the current control cycle, it first reads the current control cycle identifier, the start time position of the current control cycle, the end time position of the current control cycle, and the scheduling refresh frequency of the charging pile group in the target power supply area. Based on the current control cycle identifier, it searches for the previous control cycle adjacent to the current control cycle in the local control cycle index record. The local control cycle index record is continuously written by the local charging pile according to the scheduling refresh frequency. It includes the control cycle identifier, the start time position of the control cycle, the end time position of the control cycle, the local charging pile identifier, the power output interface identifier, the local electricity consumption preference representation parameter writing status, and the local electricity consumption preference representation parameter cache address. The previous control cycle is not an arbitrary historical time period, but rather the previous control cycle that is continuously adjacent to the current control cycle on the time axis and whose local electricity consumption preference representation parameter writing status is completed. If multiple candidate previous control cycles exist in the local control cycle index record, the local charging pile selects the candidate previous control cycle with the smallest time interval and whose local electricity consumption preference characterization parameter writing status is completed, based on the adjacency relationship between the end time position of the current control cycle and the start time position of the current control cycle. In this way, the local electricity consumption preference characterization parameter of the current control cycle can be compared with historical electricity consumption preference characterization parameters formed within the same local charging pile, the same power output interface, and the previous control cycle, avoiding the misuse of data from other local charging piles or data from earlier control cycles as the basis for feature difference identification.
[0048] Preferably, the cache space is used to store the local electricity consumption preference representation parameters formed in each control cycle and the local source relationships corresponding to the local electricity consumption preference representation parameters. The cache space is pre-configured with preference parameter cache records, which include the local charging pile identifier, control cycle identifier, power output interface identifier, local electricity consumption preference representation parameters, tensor unit sequence code, tensor unit source index, tensor unit empty slot marker, local source relationship, and write completion identifier. After the local electricity consumption preference representation parameters for the current control cycle are formed, they are first written to the preference parameter cache record corresponding to the current control cycle identifier, and the write completion identifier is set to a valid state. After the previous control cycle is determined, the local charging pile, based on the control cycle identifier of the previous control cycle, reads the preference parameter cache record with the valid write completion identifier from the cache space and extracts the historical electricity consumption preference representation parameters from that preference parameter cache record. The technical essence of historical electricity consumption preference characterization parameters is local load preference description data formed by the same local charging pile in the previous control cycle based on the initial electricity consumption characteristic data after removing abrupt interference signals. Its tensor unit sequential encoding, tensor unit source indexing, and tensor unit empty space marking maintain the same field caliber as the local electricity consumption preference characterization parameters of the current control cycle. Therefore, historical electricity consumption preference characterization parameters are not external input data, but rather local load preference description data that has already undergone tensor format storage processing in the previous control cycle and is stored in the cache space. Subsequent feature difference identification uses historical electricity consumption preference characterization parameters as the same source reference object as the local electricity consumption preference characterization parameters of the current control cycle.
[0049] Preferably, after reading the historical electricity consumption preference representation parameters, the comparator first performs a source consistency check on the local electricity consumption preference representation parameters of the current control cycle and the historical electricity consumption preference representation parameters of the previous control cycle. The source consistency check reads the local charging pile identifier, power output interface identifier, tensor unit sequence code, and tensor unit empty space marker of the current control cycle, and also reads the same information from the previous control cycle. When the corresponding local charging pile identifier, power output interface identifier, and tensor unit sequence code are consistent, the comparator sends the local electricity consumption preference representation parameters of the current control cycle and the historical electricity consumption preference representation parameters of the previous control cycle into the same-source difference identification channel. The same-source difference identification channel carries the local electricity consumption preference representation parameters of the current control cycle and the historical electricity consumption preference representation parameters of the previous control cycle after passing the source consistency check, and is used to limit the comparison objects for subsequent feature difference identification. If a tensor cell vacancy mark exists in the local electricity consumption preference representation parameter of the current control cycle or the historical electricity consumption preference representation parameter of the previous control cycle, the comparator retains the tensor cell position corresponding to the vacancy mark according to the tensor cell sequence encoding, and writes a vacancy retention field to that tensor cell position to form a peer comparison reference record. The peer comparison reference record carries the peer comparison relationship between the local electricity consumption preference representation parameter of the current control cycle and the historical electricity consumption preference representation parameter of the previous control cycle, ensuring that subsequent feature difference identification only occurs between the same local charging pile, the same power output interface, and the same tensor cell caliber, avoiding comparisons of inconsistent dimensions between data from different sources.
[0050] Preferably, the comparator is not merely a simple component for performing numerical comparisons, but rather a data comparison unit used to identify the differences in corresponding fields between the local electricity consumption preference representation parameter and the historical electricity consumption preference representation parameter, according to the tensor unit source index and tensor unit sequence encoding. The comparator first reads each current tensor unit in the corresponding comparison reference record, and then reads the corresponding historical tensor unit from the historical electricity consumption preference representation parameter according to the tensor unit sequence encoding. Subsequently, the comparator reads the physical timestamp, instantaneous power absolute value, node type field, fragment source identifier, associated weight feature code, and tensor unit source index from the current tensor unit, and also reads the physical timestamp, instantaneous power absolute value, node type field, fragment source identifier, associated weight feature code, and tensor unit source index from the historical tensor units. The comparator compares fields with the same name, but does not directly compare the physical timestamp with the absolute value of instantaneous power, nor does it directly compare the node type field with the fragment source identifier. For the associated weight feature code, the comparator further reads the time stability field, power amplitude segment field, fragment effect field, and adjacent association field from the associated weight feature code, and compares subfields with the same name. Through the above field splitting and comparison of fields with the same name, feature difference identification maintains the same dimensions and semantic caliber.
[0051] Preferably, the feature difference identification specifically includes time position difference identification, power amplitude difference identification, node type difference identification, fragment source difference identification, and associated weight difference identification. The comparator performs time position difference identification on the physical timestamp in the current tensor unit and the physical timestamp in the historical tensor unit to form a time position change field; the comparator performs power amplitude difference identification on the instantaneous power absolute value in the current tensor unit and the instantaneous power absolute value in the historical tensor unit to form a power amplitude change field; the comparator performs node type difference identification on the node type field in the current tensor unit and the node type field in the historical tensor unit to form a node type change field; the comparator performs fragment source difference identification on the fragment source identifier in the current tensor unit and the fragment source identifier in the historical tensor unit to form a fragment source change field; and the comparator performs associated weight difference identification on the associated weight feature code in the current tensor unit and the associated weight feature code in the historical tensor unit to form an associated weight change field. For tensor cells with empty slot markers, the comparator configures the corresponding time position change field, power amplitude change field, node type change field, fragment source change field, and associated weight change field to an empty slot hold state based on the empty slot hold field. This avoids misjudging tensor cells without stationary coordinates as load changes. All of these change fields are written to the same differential identification load record. This record retains the corresponding tensor cell sequence code, tensor cell source index, and empty slot hold field so that subsequent gradient update vectors can be arranged according to the tensor cell order representing the local electricity consumption preference parameters.
[0052] Preferably, the time position difference identification does not directly output the time difference value. Instead, it determines the chronological relationship between the physical timestamps in the current tensor unit and the physical timestamps in the historical tensor units under the same time indexing caliber. The comparator first reads the relative time position of the physical timestamp of the current tensor unit in the current control cycle and reads the relative time position of the physical timestamp of the historical tensor unit in the previous control cycle. Then, it aligns the time references according to the start time positions of the current and previous control cycles to form a time reference alignment record. The time reference alignment record stores the physical timestamps of the current tensor unit, the physical timestamps of the historical tensor units, the start time position of the current control cycle, the start time position of the previous control cycle, and the tensor unit sequence code, and serves as intermediate data before the formation of the time position change field. Based on the time reference alignment record, the comparator determines whether the stationary point coordinates corresponding to the current tensor unit are ahead, behind, or remain the same relative to the stationary point coordinates corresponding to the historical tensor units, and writes the determination result into the time position change field. The time position change field continues to be used as input for directional indexing, enabling the gradient update vector to express the time position changes of the user's charging behavior pattern in adjacent control cycles, rather than simply saving the original values of two physical timestamps.
[0053] Preferably, the power amplitude difference identification does not mix power amplitude with time position. Instead, it places the instantaneous absolute power value in the current tensor unit and the instantaneous absolute power value in the historical tensor unit under the same power amplitude caliber for amplitude change determination. The comparator first reads the power amplitude segment field to which the instantaneous absolute power value of the current tensor unit belongs, and then reads the power amplitude segment field to which the instantaneous absolute power value of the historical tensor unit belongs. Based on the power amplitude segment field, it determines whether the current tensor unit and the historical tensor unit are in the same segment or across segments to form a power amplitude segment alignment record. The power amplitude segment alignment record saves the instantaneous absolute power value of the current tensor unit, the instantaneous absolute power value of the historical tensor unit, the power amplitude segment field of the current tensor unit, the power amplitude segment field of the historical tensor unit, and the tensor unit sequence code, serving as intermediate data before the formation of the power amplitude change field. The comparator determines whether the instantaneous absolute power value corresponding to the current tensor cell has increased, decreased, or remained constant relative to the instantaneous absolute power value corresponding to the historical tensor cells based on the power amplitude segment alignment record, and writes the determination result into the power amplitude change field. The power amplitude change field continues to serve as input for directional indexing processing, enabling the gradient update vector to express the power amplitude change of the local load preference description data in adjacent control cycles, rather than exposing the original power sampling sequence.
[0054] Preferably, node type difference identification, fragment source difference identification, and association weight difference identification are performed around non-continuous numerical fields. When performing node type difference identification, the comparator reads the node type field in the current tensor unit and the node type field in the historical tensor units, and determines whether the source of the stationary point coordinates corresponding to the current tensor unit has been replaced between periodic peak nodes, periodic trough nodes, or periodic node pairing records, thus forming a node type change field. When performing fragment source difference identification, the comparator reads the fragment source identifier in the current tensor unit and the fragment source identifier in the historical tensor units, and determines whether the pre-access reference fragment, access climb fragment, stable output fragment, or access exit fragment to which the current tensor unit belongs has changed, thus forming a fragment source change field. When performing association weight difference identification, the comparator reads the time stability field, power amplitude segment field, fragment action field, and adjacent association field in the current tensor unit and the historical tensor units respectively, and performs change determination on each of the above-mentioned sub-fields with the same name, thus forming an association weight change field. The node type change field, fragment source change field, and associated weight change field are all included in the difference identification carrying record, and together with the time location change field and power amplitude change field, they describe the preference change structure between adjacent control cycles.
[0055] Preferably, after the difference identification bearer record is formed, the comparator performs directional indexing processing on the difference identification bearer record. The directional indexing processing does not perform a general naming of the difference identification bearer record, but reads the time position change field, power amplitude change field, node type change field, fragment source change field, and association weight change field respectively, and configures a corresponding change direction mark for each change field. For the time position change field, the change direction marker indicates whether the corresponding stationary point coordinates in the current control cycle are ahead, behind, or remain the same compared to the previous control cycle. For the power amplitude change field, the change direction marker indicates whether the corresponding instantaneous power absolute value in the current control cycle is up, down, or remains the same compared to the previous control cycle. For the node type change field, the change direction marker indicates whether the source of the periodic peak node, the source of the periodic trough node, or the source of the periodic node pairing record in the corresponding tensor unit has been replaced in the current control cycle. For the segment source change field, the change direction marker indicates whether the pre-access reference segment, access climb segment, stable output segment, or access exit segment to which the corresponding tensor unit belongs has changed in the current control cycle. For the association weight change field, the change direction marker indicates whether the participation of the corresponding stationary point coordinates in the formation process of the local electricity consumption preference representation parameter has increased, decreased, or remained the same in the current control cycle. The change direction markers, together with the difference identification carrying record, form gradient candidate records. The gradient candidate records store the tensor unit sequence code, tensor unit source index, each change field, and each change direction marker, and then enter the gradient update vector encapsulation processing.
[0056] Preferably, the gradient update vector encapsulation process takes gradient candidate records as input and arranges them sequentially according to tensor unit order encoding. Each gradient candidate record, upon entering the gradient update vector encapsulation process, is split into a time position change component, a power magnitude change component, a node type change component, a fragment source change component, and an associated weight change component. Specifically, the time position change component originates from the time position change field and its change direction marker; the power magnitude change component originates from the power magnitude change field and its change direction marker; the node type change component originates from the node type change field and its change direction marker; the fragment source change component originates from the fragment source change field and its change direction marker; and the associated weight change component originates from the associated weight change field and its change direction marker. The comparator arranges these components into a gradient update vector representing the data evolution direction according to tensor unit order encoding. The technical essence of gradient update vectors is the directional incremental description data of the changes in local electricity consumption preference parameters in the current control cycle relative to the historical electricity consumption preference parameters in the previous control cycle. Gradient update vectors do not carry the plaintext low-level sampled content of port voltage sampling sequences or initial electricity consumption characteristic data; instead, they carry the evolution direction of local load preference description data between adjacent control cycles. Gradient update vectors retain tensor unit sequence encoding and tensor unit source indexing, enabling subsequent encrypted conversion operations to read the changing components in the gradient update vector based on these encodings.
[0057] Preferably, after the gradient update vector is formed, the local charging pile performs a pre-encryption check on the gradient update vector. The pre-encryption check reads the time position change component, power amplitude change component, node type change component, fragment source change component, and associated weight change component from the gradient update vector, and confirms that each component has a corresponding tensor unit sequence code, tensor unit source index, and local source relationship. If a component lacks a tensor unit sequence code, tensor unit source index, or local source relationship, the local charging pile resends the corresponding gradient candidate record to the difference identification carrier record reading position, and completes the corresponding tensor unit sequence code, tensor unit source index, or local source relationship based on the same-position comparison reference record. After completing the pre-encryption check, the local charging pile writes the gradient update vector into the encrypted conversion carrier record. The encrypted conversion carrier record includes the local charging pile identifier, the current control cycle identifier, the power output interface identifier, the gradient update vector, the tensor unit sequence code, the tensor unit source index, and the local source relationship. The ciphertext transformation bearer record serves as intermediate bearer data before the gradient update vector enters the homomorphic encryption engine. This enables the homomorphic encryption engine to read the gradient update vector item by item according to the tensor unit sequence encoding, instead of directly reading the local electricity preference representation parameter or the historical electricity preference representation parameter.
[0058] Preferably, the secure key repository is pre-configured before the local charging piles participate in the collaborative scheduling of the charging pile group within the target power supply area. When pre-configuring the secure key repository, a key configuration record is first established for each local charging pile. The key configuration record includes a local charging pile identifier, a power output interface identifier, a key version field, a public key body field, a homomorphic parameter index field, a confusion parameter index field, a key activation status field, and a key usage field. The local charging pile identifier is used to limit the local charging pile to which the key configuration record belongs; the power output interface identifier is used to limit the local data source corresponding to the key configuration record; the key version field is used to distinguish key configuration records enabled within different control cycle ranges; the public key body field is used to store the publicly encrypted data participating in the ciphertext conversion operation; the homomorphic parameter index field is used to store the parameter reading positions required by the homomorphic encryption engine to perform ciphertext state operations; the confusion parameter index field is used to store the perturbation parameter reading positions required by the homomorphic encryption engine to perform polynomial confusion operations; the key activation status field indicates whether the key configuration record can be invoked; and the key usage field limits the key configuration record to only being used for ciphertext conversion operations of gradient update vectors. The secure key store establishes a correspondence between local charging piles and encrypted public key strings through key configuration records, enabling subsequent extraction of encrypted public key strings to be determined based on the local charging pile identifier, power output interface identifier, and key version field.
[0059] Preferably, the encrypted public key string is formed by encapsulating the public key body field, homomorphic parameter index field, obfuscation parameter index field, key version field, and key purpose field from the secure key store in a fixed reading order. Specifically, the local charging pile first retrieves a valid key configuration record in the secure key store based on the local charging pile identifier, power output interface identifier, and current control cycle identifier in the ciphertext conversion bearer record. Then, it reads the key version field matching the current control cycle based on the current control cycle identifier and extracts the public key body field, homomorphic parameter index field, obfuscation parameter index field, key version field, and key purpose field from this key configuration record to form the encrypted public key string configured for the corresponding local charging pile. The technical essence of the encrypted public key string is the ordered encoded data of the public key data, homomorphic parameter reading information, and obfuscation parameter reading information required to convert the gradient update vector into a ciphertext state. The encrypted public key string is only used by the homomorphic encryption engine to perform ciphertext conversion operations and does not carry decryption private key data; therefore, the encrypted public key string can be called on the local charging pile side to generate encrypted gradient vectors, but cannot be used to reverse-parse the plaintext gradient content in the encrypted gradient vectors. After the encrypted public key string is formed, it continues to enter the key register loading process so that the homomorphic encryption engine can read the encrypted public key string in the polynomial obfuscation operation.
[0060] Preferably, when loading the encrypted public key string into the key register of the homomorphic encryption engine, the local charging pile first performs version matching, purpose matching, and source matching processing on the encrypted public key string. Version matching reads the key version field in the encrypted public key string and confirms that the key version field corresponds to the current control cycle identifier; purpose matching reads the key purpose field in the encrypted public key string and confirms that the key purpose field corresponds to the ciphertext transformation operation of the gradient update vector; source matching reads the local charging pile identifier and power output interface identifier in the ciphertext transformation bearer record and confirms that the local charging pile identifier and power output interface identifier are consistent with the key configuration record corresponding to the encrypted public key string. After version matching, purpose matching, and source matching processing, the local charging pile writes the public key body field from the encrypted public key string to the public key cache location of the key register, writes the homomorphic parameter index field to the homomorphic parameter index cache location of the key register, writes the obfuscation parameter index field to the obfuscation parameter index cache location of the key register, and writes the key version field to the version cache location of the key register. The key register, in essence, is a local storage area used by the homomorphic encryption engine to temporarily store the encrypted public key string, homomorphic parameter index field, and obfuscation parameter index field before performing polynomial obfuscation operations. The key register does not store historical electricity preference representation parameters, nor does it store local electricity preference representation parameters; it only stores fields from the encrypted public key string related to the ciphertext transformation operation. After loading, the key register continues to serve as the key reading location between the encoding caliber transformation process and the polynomial obfuscation operation, enabling the homomorphic encryption engine to simultaneously read the encrypted public key string while reading the gradient-encoded bearer record.
[0061] Preferably, before reading the gradient update vector, the homomorphic encryption engine first performs encoding caliber conversion processing on the gradient update vector according to the tensor unit sequence encoding in the ciphertext transformation bearer record. The encoding caliber conversion processing reads the time position change component, power amplitude change component, node type change component, fragment source change component, and associated weight change component respectively, and converts each component into gradient encoded components that the homomorphic encryption engine can read. The time position change component is encoded using time caliber to form a time gradient encoded component; the power amplitude change component is encoded using power caliber to form a power gradient encoded component; the node type change component is encoded using type caliber to form a node type gradient encoded component; the fragment source change component is encoded using fragment caliber to form a fragment source gradient encoded component; and the associated weight change component is encoded using weight caliber to form an associated weight gradient encoded component. These gradient encoded components are then written into the gradient encoding bearer record according to the tensor unit sequence encoding. The gradient-encoded record continues to store the local charging pile identifier, current control cycle identifier, power output interface identifier, tensor unit source index, and local source relationship, and serves as the input for polynomial obfuscation operation, so that the variation components from different sources are first converted into the same ciphertext conversion caliber, and then enter the homomorphic encryption engine.
[0062] Preferably, time-based encoding, power-based encoding, type-based encoding, segment-based encoding, and weight-based encoding are performed according to the technical meaning of different fields. Time-based encoding reads the advance, delay, or hold direction in the time position change component and writes this direction into the time direction position in the time gradient encoding component; power-based encoding reads the rise, fall, or hold direction in the power amplitude change component and writes this direction into the power direction position in the power gradient encoding component; type-based encoding reads whether the source of periodic peak nodes, periodic trough nodes, or periodic node pairing records has been replaced in the node type change component and writes this replacement relationship into the type change position in the node type gradient encoding component; segment-based encoding reads the change relationship of the pre-access reference segment, access climb segment, stable output segment, or access exit segment in the segment source change component and writes this change relationship into the segment change position in the segment source gradient encoding component; weight-based encoding reads the enhancement, weakening, or hold direction in the associated weight change component and writes this direction into the weight direction position in the associated weight gradient encoding component. The above encoding processes all focus on the direction of change and the source of the field, and do not directly write the plaintext fields of the port voltage sampling sequence, initial power consumption characteristic data, or local power consumption preference representation parameters. The time gradient encoding components, power gradient encoding components, node type gradient encoding components, fragment source gradient encoding components, and associated weight gradient encoding components continue to be encoded into the gradient encoding carrying record in tensor unit order, so that the gradient encoding carrying record can completely carry the directional incremental information of the gradient update vector.
[0063] Preferably, the polynomial obfuscation operation is not a simple encrypted replacement of the gradient update vector. Instead, the homomorphic encryption engine performs polynomial slot embedding, perturbation term filling, and public key constraint transformation on each gradient encoding component in the gradient encoding bearer record based on the encrypted public key string in the key register. Specifically, the homomorphic encryption engine first allocates polynomial slots to each gradient encoding component according to the tensor unit sequential encoding, and writes the time gradient encoding component, power gradient encoding component, node type gradient encoding component, fragment source gradient encoding component, and associated weight gradient encoding component into the corresponding polynomial slots to form a slotted gradient encoding record. The slotted gradient encoding record continues to retain the internal correspondence between the tensor unit sequential encoding and the polynomial slots. This internal correspondence only participates in the polynomial obfuscation operation on the local charging pile side and is not uploaded as plaintext fields to the cloud collaborative processing server. Subsequently, the homomorphic encryption engine reads the homomorphic parameter index field and the obfuscation parameter index field from the encrypted public key string, and reads the homomorphic parameter corresponding to the current key version field according to the homomorphic parameter index field, and reads the obfuscation parameter corresponding to the current key version field according to the obfuscation parameter index field. The homomorphic parameter configures the reading path of the public key constraint transformation, while the obfuscation parameter configures the slot range for perturbation term filling and the perturbation term generation path. The homomorphic encryption engine then writes perturbation terms into the slotted gradient encoding record to mask the original arrangement of the gradient encoding components in the polynomial slots. Based on the public key body field, it performs a public key constraint transformation on the slotted gradient encoding record after writing the perturbation terms to form a ciphertext slot record. The ciphertext slot record continues to store the key version field and the current control period identifier, enabling subsequent ciphertext encapsulation processing to establish a correspondence between the ciphertext slot record and the current control period and the version source of the encrypted public key string.
[0064] Preferably, in the polynomial obfuscation operation, perturbation term padding and public key constraint transformation have different data functions. Perturbation term padding is used to mask the visible arrangement of gradient encoded components in the polynomial slots, preventing the external receiver from deducing the dimensional arrangement of the initial power consumption characteristic data from the ciphertext slot records. Public key constraint transformation is used to enable the ciphertext slot records to participate in subsequent ciphertext state aggregation operations on the cloud-based collaborative processing server side. The perturbation term does not participate in representing the user's charging behavior pattern, nor is it part of the local power consumption preference representation parameter. Instead, it is used in the polynomial obfuscation operation to mask the direct correspondence between the gradient encoded components and the original tensor unit sequential encoding. Public key constraint transformation does not read the port voltage sampling sequence, the initial power consumption characteristic data after removing abrupt interference signals, or the envelope change data. Instead, it only reads the encrypted public key string in the gradient encoded bearer record and the key register. Therefore, the polynomial obfuscation operation deals with the encoding result of the gradient update vector, not the local plaintext underlying sampled content. The ciphertext slot record, formed by perturbation term filling and public key constraint transformation, continues to serve as input for ciphertext encapsulation processing, so that the homomorphic encryption engine can generate an encryption gradient vector based on the ciphertext slot record.
[0065] Preferably, after the ciphertext slot record is formed, the homomorphic encryption engine continues to perform ciphertext encapsulation processing to generate an encrypted gradient vector with a ciphertext state distribution. The ciphertext encapsulation processing reads the ciphertext slot record, the current control cycle identifier, the local charging pile identifier, the power output interface identifier, the key version field, and the local source relationship from the ciphertext conversion bearer record, and writes these fields into the encrypted gradient bearer record according to a fixed encapsulation order. The encrypted gradient bearer record is not the final upload object, but rather intermediate bearer data used to carry the ciphertext slot record and the source field; the homomorphic encryption engine then performs vectorized encapsulation processing on the encrypted gradient bearer record to form an encrypted gradient vector. The encrypted gradient vector includes multiple ciphertext components, each corresponding to one or more gradient encoding components that have undergone polynomial obfuscation operations; the ciphertext components maintain an indirect ciphertext arrangement relationship with the tensor unit sequential encoding, but do not expose the direct correspondence between the original tensor unit sequential encoding and the initial power consumption characteristic data dimension. The encrypted gradient vector continues to carry the current control cycle identifier, local charging pile identifier, power output interface identifier, and key version field, enabling the cloud collaborative processing server to receive the encrypted gradient vector according to the control cycle and key version field, without needing to read the plaintext gradient content corresponding to the encrypted gradient vector.
[0066] Preferably, the technical essence of the encrypted gradient vector is that it is a ciphertext state gradient description data formed by the gradient update vector through encoding caliber conversion, polynomial slot embedding, perturbation term filling, public key constraint transformation, and vectorization encapsulation. The encrypted gradient vector is used to express the data evolution direction of the local electricity consumption preference characterization parameter in the current control cycle relative to the historical electricity consumption preference characterization parameter. However, its ciphertext components do not directly present the plaintext content of time location change components, power amplitude change components, node type change components, fragment source change components, or associated weight change components. The encrypted gradient vector also does not contain plaintext fields such as port voltage sampling sequences, access time stamps, envelope change data, periodic peak nodes, periodic trough nodes, or stationary point coordinates. Therefore, the subsequent cloud-based collaborative processing server receives the encrypted gradient vector, rather than the initial electricity consumption characteristic data or the local electricity consumption preference characterization parameter itself, enabling the change direction required for multi-node collaborative scheduling to participate in subsequent ciphertext state aggregation operations in a ciphertext state. The correspondence between the encrypted gradient vector and the current control cycle identifier, local charging pile identifier, power output interface identifier, and key version field will continue to be used by the cloud collaborative processing server to perform ciphertext aggregation operations on the encrypted gradient vectors uploaded by multiple local charging piles within the same current control cycle.
[0067] Optionally, within the cloud-based collaborative processing server, a secure multi-party computation protocol is triggered to perform ciphertext-state aggregation operations on all received encrypted gradient vectors to generate a global load gradient compensation vector for the target power supply area. This includes: defining multiple hardware-isolated virtual computing sandboxes in the memory space of the cloud-based collaborative processing server, and routing the received encrypted gradient vectors to different virtual computing sandboxes; establishing ciphertext-state communication links between different virtual computing sandboxes according to the interaction rules of the secure multi-party computation protocol, and executing cross-sandbox joint operation instructions through the ciphertext-state communication links while maintaining the ciphertext state of the encrypted gradient vectors; capturing the ciphertext aggregation vector result output by the joint operation instructions, and using a pre-configured decryption private key string to deobfuscate and parse the ciphertext aggregation vector result in the trusted execution environment of the cloud-based collaborative processing server to generate a global load gradient compensation vector.
[0068] Preferably, the specific implementation process of triggering a secure multi-party computation protocol within the cloud-based collaborative processing server to perform ciphertext-state aggregation operations on all received encrypted gradient vectors to generate a global load gradient compensation vector for the target power supply area is as follows: After receiving the encrypted gradient vectors sent by each local charging pile within the current control cycle, the cloud-based collaborative processing server first performs encrypted gradient reception cataloging processing on each encrypted gradient vector. The encrypted gradient reception cataloging processing reads the target power supply area identifier, current control cycle identifier, local charging pile identifier, power output interface identifier, key version field, encrypted gradient vector reception time and position, ciphertext component arrangement information, and ciphertext component quantity field carried by the encrypted gradient vector, and writes the above fields into the encrypted gradient reception cataloging record. The encrypted gradient reception catalog record carries the source relationships of encrypted gradient vectors participating in the ciphertext aggregation operation within the current control cycle. Specifically, the target power supply area identifier limits the regional scheduling range for the encrypted gradient vector, the current control cycle identifier limits the aggregation cycle for the encrypted gradient vector, the local charging pile identifier limits the upload source of the encrypted gradient vector, the power output interface identifier limits the power output interface corresponding to the encrypted gradient vector, the key version field limits the key type corresponding to the encrypted gradient vector, and the ciphertext component arrangement information and ciphertext component quantity fields limit the arrangement of the ciphertext components within the encrypted gradient vector. The cloud-based collaborative processing server then performs cycle merging processing on the encrypted gradient reception catalog record based on the target power supply area identifier and the current control cycle identifier to form the current cycle ciphertext input queue. Each queue item in the current cycle ciphertext input queue corresponds to an encrypted gradient vector uploaded by a local charging pile, and retains the local charging pile identifier, power output interface identifier, key version field, ciphertext component arrangement information, and ciphertext component quantity fields corresponding to the encrypted gradient vector, ensuring that subsequent virtual computing sandbox allocation can use the same source type and the same ciphertext arrangement.
[0069] Preferably, after forming the current period's encrypted input queue, the cloud-based collaborative processing server does not immediately perform encrypted state aggregation operations. Instead, it first performs encrypted input consistency verification on the current period's encrypted input queue. The encrypted input consistency verification reads the target power supply area identifier, current control period identifier, key version field, encrypted component arrangement information, and encrypted component quantity field of each queue item in the current period's encrypted input queue, and compares these fields with the aggregation task configuration record for the current control period. The aggregation task configuration record is pre-generated by the cloud-based collaborative processing server based on the number of local charging piles registered in the target power supply area, the current control period identifier, the key version field, and the encrypted component arrangement information. It includes the target power supply area identifier, current control period identifier, identifier of the local charging pile to be received, key version field, encrypted component arrangement information, encrypted component quantity field, and aggregation trigger status field. If the target power supply area identifier, current control period identifier, or key version field of a queue item is inconsistent with the aggregation task configuration record, the cloud-based collaborative processing server writes the queue item into the abnormal encrypted input record and prevents the queue item from entering the virtual computing sandbox allocation. The abnormal ciphertext input record includes an encryption gradient vector identifier, a target power supply area identifier, a current control cycle identifier, a key version field, an anomaly source field, and an exclusion status field. The abnormal ciphertext input record maintains a correspondence with the encryption gradient reception catalog record and serves as the basis for excluding the queue item from ciphertext aggregation operations within the current control cycle. If the ciphertext component arrangement information or ciphertext component quantity field of a queue item is inconsistent with the aggregation task configuration record, the cloud collaborative processing server writes the queue item into the arrangement caliber anomaly record and prevents the queue item from entering the virtual computing sandbox allocation. The arrangement caliber anomaly record includes an encryption gradient vector identifier, ciphertext component arrangement information, ciphertext component quantity field, the ciphertext component arrangement information in the aggregation task configuration record, the ciphertext component quantity field in the aggregation task configuration record, and an exclusion status field. The arrangement caliber anomaly record maintains a correspondence with the encryption gradient reception catalog record and serves as the basis for excluding the queue item from ciphertext aggregation operations within the current control cycle. Queue entries that pass the ciphertext input consistency check are written to the valid ciphertext input queue. This valid ciphertext input queue serves as the direct input for subsequent sandbox routing allocation processing, ensuring that the encrypted gradient vectors entering the virtual computing sandbox remain consistent across target power supply areas, current control cycles, key versions, and ciphertext component arrangement. After the valid ciphertext input queue is formed, the cloud-based collaborative processing server sets the aggregation trigger status field in the aggregation task configuration record to a triggerable state, enabling subsequent sandbox routing allocation processing to read this trigger status field and enter the virtual computing sandbox allocation phase.
[0070] Preferably, when defining multiple hardware-isolated virtual computing sandboxes in the memory space of the cloud collaborative processing server, the cloud collaborative processing server first reads the sandbox configuration record. The sandbox configuration record includes a virtual computing sandbox identifier, a sandbox session identifier, a memory page range identifier, a memory page start position, a memory page end position, an access permission identifier, a encrypted input capacity field, a sandbox running status field, a current control cycle identifier, and a target power supply area identifier. The memory page range identifier, the memory page start position, and the memory page end position together define the range of memory addresses that each virtual computing sandbox can access. The access permission identifier defines the read and write permissions of the corresponding virtual computing sandbox to its memory address range. The encrypted input capacity field defines the number of encrypted gradient vectors that the corresponding virtual computing sandbox can receive within the current control cycle. The sandbox running status field indicates whether the corresponding virtual computing sandbox is in a receptive state. The technical essence of hardware isolation is to limit the encrypted input data of different virtual computing sandboxes to a non-shared memory page range by using memory address translation permissions, memory page range identifiers, and access permission identifiers, preventing one virtual computing sandbox from directly reading the encrypted gradient vectors in another virtual computing sandbox. After the virtual computing sandbox is defined, the cloud-based collaborative processing server writes the virtual computing sandbox identifier, sandbox session identifier, memory page range identifier, memory page start position, memory page end position, access permission identifier, and sandbox running status fields into the sandbox isolation mapping record. The sandbox isolation mapping record then participates in the routing allocation process for encrypted gradient vectors and is used to limit the memory page range when each encrypted gradient vector is written to the virtual computing sandbox.
[0071] Preferably, when routing multiple received encrypted gradient vectors to different virtual computing sandboxes, the cloud-based collaborative processing server first reads the local charging pile identifier, power output interface identifier, key version field, encrypted component arrangement information, and encrypted component quantity field of each encrypted gradient vector according to the valid encrypted input queue. Then, based on the sandbox isolation mapping record, it reads the virtual computing sandbox identifier whose sandbox running status field is in an acceptable state. Subsequently, the cloud-based collaborative processing server establishes a sandbox routing allocation record, which includes the encrypted gradient vector identifier, local charging pile identifier, power output interface identifier, key version field, encrypted component arrangement information, encrypted component quantity field, virtual computing sandbox identifier, sandbox session identifier, memory page range identifier, and routing write status. The sandbox routing allocation record does not simply record the receiving order of encrypted gradient vectors, but rather establishes a one-to-one or grouped correspondence between encrypted gradient vectors from different local charging piles and different virtual computing sandboxes. When the number of encrypted gradient vectors in the valid ciphertext input queue does not exceed the number of virtual computing sandboxes in the receiveable state, the cloud collaborative processing server writes each encrypted gradient vector into a different virtual computing sandbox according to the cataloging order of the local charging pile identifier. When the number of encrypted gradient vectors in the valid ciphertext input queue exceeds the number of virtual computing sandboxes in the receiveable state, the cloud collaborative processing server segments the encrypted gradient vectors according to the ciphertext input capacity field, and writes the encrypted gradient vectors in the same segment into the same virtual computing sandbox. Simultaneously, the sandbox routing allocation record retains an independent local charging pile identifier and power output interface identifier for each encrypted gradient vector within the same virtual computing sandbox. The cloud collaborative processing server writes the encrypted gradient vectors into the memory page range of the corresponding virtual computing sandbox according to the sandbox routing allocation record and sets the routing write status to complete, thus forming the sandbox ciphertext input record. The sandbox ciphertext input record continues to serve as the basis for ciphertext input before the execution of the secure multi-party computation protocol.
[0072] Preferably, after the sandbox encrypted input record is formed, the cloud-based collaborative processing server performs sandbox write verification processing on the sandbox encrypted input record. The sandbox write verification processing reads the encrypted gradient vector identifier, virtual computing sandbox identifier, sandbox session identifier, memory page range identifier, encrypted component arrangement information, encrypted component quantity field, and routing write status from the sandbox encrypted input record, and also reads the memory page start position, memory page end position, and access permission identifier from the sandbox isolation mapping record. The cloud-based collaborative processing server confirms whether the encrypted gradient vector has been written to the memory page range of the corresponding virtual computing sandbox based on the memory page range identifier, confirms whether the virtual computing sandbox has permission to read the encrypted gradient vector based on the access permission identifier, and confirms whether the encrypted components of the encrypted gradient vector have been completely written based on the encrypted component quantity field. The sandbox encrypted input record that has passed the sandbox write verification processing is written to the protocol input ready record, which includes the current control cycle identifier, target power supply area identifier, virtual computing sandbox identifier, sandbox session identifier, encrypted gradient vector identifier, encrypted component arrangement information, and protocol input ready status. The protocol input ready record then participates in the generation of the protocol interaction orchestration record, ensuring that the secure multi-party computation protocol only reads the encrypted gradient vector that has completed sandbox write verification. Sandbox ciphertext input records that fail sandbox write verification do not enter the protocol input ready record, but continue to point back to the sandbox routing allocation record, so that the cloud collaborative processing server can re-execute the route write status verification or re-execute the encrypted gradient vector write processing based on the sandbox routing allocation record.
[0073] Preferably, the technical essence of the interaction rules of the secure multi-party computation protocol lies in the data interaction constraints that limit the order of ciphertext input exchange, ciphertext component alignment, cross-sandbox joint operation order, intermediate ciphertext result write-back position, and sandbox session advancement conditions between different virtual computing sandboxes. The secure multi-party computation protocol does not require any virtual computing sandbox to decrypt the ciphertext components of the encrypted gradient vector. Instead, it requires each virtual computing sandbox to perform ciphertext component alignment reading on the encrypted gradient vector entering its own memory page range, according to the same current control cycle identifier, the same key version field, and the same ciphertext component arrangement information. Specifically, the cloud-based collaborative processing server generates a protocol interaction orchestration record based on the protocol input readiness record. This record includes the current control cycle identifier, target power supply area identifier, identifiers of the participating virtual computing sandboxes, sandbox session identifier, ciphertext component alignment field, sandbox interaction order field, joint operation instruction identifier, intermediate ciphertext result write-back field, and sandbox session advancement field. The ciphertext component alignment field ensures that ciphertext components in different virtual computing sandboxes participate in subsequent cross-sandbox joint operations according to the same ciphertext component position. The sandbox interaction order field limits the order of ciphertext data exchange between different virtual computing sandboxes. The joint operation instruction identifier limits the type of ciphertext-state operation that the virtual computing sandbox needs to perform in the current round. The intermediate ciphertext result write-back field limits the write position of the intermediate ciphertext result formed by the cross-sandbox joint operation. The sandbox session advancement field limits the conditions for entering the next round after the current round is completed. After the protocol interaction orchestration record is formed, the cloud collaborative processing server establishes a ciphertext-state communication link based on the protocol interaction orchestration record and passes the ciphertext component alignment field, sandbox interaction order field, joint operation instruction identifier, intermediate ciphertext result write-back field, and sandbox session advancement field from the protocol interaction orchestration record to the subsequent ciphertext-state communication link establishment processing.
[0074] Preferably, when establishing encrypted communication links between different virtual computing sandboxes, the cloud-based collaborative processing server first reads the virtual computing sandbox identifier, sandbox session identifier, sandbox interaction order field, and encrypted component alignment field from the protocol interaction orchestration record, and then establishes an encrypted message buffer queue among the participating virtual computing sandboxes. The encrypted message buffer queue includes the sending sandbox identifier, receiving sandbox identifier, sandbox session identifier, current control cycle identifier, encrypted component position, encrypted message sequence number, joint operation instruction identifier, and encrypted message write status. The technical essence of the encrypted communication link is a cross-sandbox encrypted transmission channel jointly defined by the encrypted message buffer queue, access permission identifier, sandbox session identifier, and encrypted component alignment field; this cross-sandbox encrypted transmission channel only allows the transmission of encrypted components, encrypted component positions, sandbox session identifiers, and joint operation instruction identifiers, and does not allow the transmission of plaintext fields such as port voltage sampling sequences, initial power consumption characteristic data, local power consumption preference representation parameters, or gradient update vectors. The cloud-based collaborative processing server writes the ciphertext components from the sending sandbox to a readable ciphertext message cache location in the receiving sandbox based on the ciphertext message cache queue, and uses the ciphertext message writing status to mark whether the ciphertext component has been successfully transmitted across sandboxes. A correspondence is established between the ciphertext message cache queue and the sandbox session identifier, ensuring that ciphertext-state communication links corresponding to different current control cycles do not use the same ciphertext message cache location. After the ciphertext-state communication link is established, the ciphertext message cache queue continues to serve as the cache source for cross-sandbox joint operation instructions to read incoming ciphertext components.
[0075] Preferably, when executing cross-sandbox joint operation instructions via the encrypted state communication link while maintaining the encrypted gradient vector ciphertext state, the cloud collaborative processing server first generates a joint operation task record based on the protocol interaction orchestration record. The joint operation task record includes a joint operation instruction identifier, the identifier of the virtual computing sandbox participating in the operation, the sandbox session identifier, the ciphertext component alignment field, the ciphertext message cache queue identifier, the intermediate ciphertext result write-back field, the sandbox session progress field, and the joint operation completion status. The joint operation instruction is not an instruction to sum the plaintext gradient values, but rather a set of instructions to perform homomorphic addition, homomorphic merging, or ciphertext slot alignment processing on the ciphertext components in multiple virtual computing sandboxes. Homomorphic addition is used to form a ciphertext summation result without decrypting the ciphertext content; homomorphic merging is used to merge the ciphertext summation results in different virtual computing sandboxes according to the ciphertext component positions; and ciphertext slot alignment processing is used to allow ciphertext components in different encrypted gradient vectors to participate in the same joint operation instruction at the same ciphertext component position. The cloud-based collaborative processing server drives each virtual computing sandbox to read ciphertext components within its own memory page range based on the joint computation task record. It also receives ciphertext components from other virtual computing sandboxes via ciphertext-state communication links to execute cross-sandbox joint computation instructions. The joint computation task record continuously saves the joint computation completion status during the execution of cross-sandbox joint computation instructions, enabling the cloud-based collaborative processing server to determine whether to proceed to intermediate ciphertext result reading and processing based on the joint computation completion status.
[0076] Preferably, during the execution of cross-sandbox joint operation instructions, each virtual computing sandbox performs ciphertext-state operations only on its own ciphertext components and the ciphertext components received through the ciphertext-state communication link. The virtual computing sandbox first reads the local ciphertext component from the sandbox ciphertext input record based on the ciphertext component alignment field, then reads the incoming ciphertext component from the adjacent virtual computing sandbox based on the ciphertext message cache queue, and writes the local ciphertext component and the incoming ciphertext component into the ciphertext component operation bearer record. The ciphertext component operation bearer record includes the virtual computing sandbox identifier, sandbox session identifier, ciphertext component position, local ciphertext component, incoming ciphertext component, joint operation instruction identifier, and intermediate ciphertext result write-back field. Subsequently, the virtual computing sandbox performs ciphertext-state operations on the local ciphertext component and the incoming ciphertext component in the ciphertext component operation bearer record according to the joint operation instruction identifier to form an intermediate ciphertext aggregation record. The intermediate ciphertext aggregation record does not display the plaintext content of the gradient update vector of any individual local charging pile; it stores the intermediate ciphertext result processed by the cross-sandbox joint operation instructions. The intermediate ciphertext aggregation record continues to be written back to the memory page range of the corresponding virtual computing sandbox according to the intermediate ciphertext result write-back field. Based on the sandbox session advancement field, it is then transmitted to the next virtual computing sandbox via the ciphertext-state communication link, enabling the next virtual computing sandbox to continue reading the intermediate ciphertext result and executing the cross-sandbox federated operation instructions for the corresponding round. After being written back to the memory page range of the corresponding virtual computing sandbox, the intermediate ciphertext aggregation record continues to serve as input for the federated operation round record, participating in the state marking processing of subsequent rounds.
[0077] Preferably, when intermediate encrypted aggregation records are transferred between different virtual computing sandboxes, the cloud-based collaborative processing server performs round status marking processing on the intermediate encrypted aggregation records. Round status marking processing reads the virtual computing sandbox identifier, sandbox session identifier, encrypted component position, intermediate encrypted result, and joint operation instruction identifier from the intermediate encrypted aggregation records, and writes these fields into the joint operation round record. The joint operation round record includes the sandbox session identifier, round sequence, identifiers of participating virtual computing sandboxes, identifiers of virtual computing sandboxes to be participated in, encrypted component position, intermediate encrypted result, and round completion status. Once the round completion status of the current round is set to "completed," the cloud-based collaborative processing server writes the intermediate encrypted result into the encrypted message cache queue of the next round based on the identifiers of the virtual computing sandboxes to be participated in. Through the joint operation round record, the cloud-based collaborative processing server can confirm whether each virtual computing sandbox has participated in the encrypted state aggregation operation of the current control cycle, avoiding the same virtual computing sandbox from repeatedly participating in the same round, and also preventing a virtual computing sandbox from directly entering the encrypted aggregation vector result formation process without participating in the current control cycle aggregation. The joint operation round record continues to serve as the round source for the sequential arrangement of ciphertext components after all virtual computing sandboxes have participated in the ciphertext state aggregation operation of the current control cycle.
[0078] Preferably, after all participating virtual computing sandboxes have completed their joint computation instructions, the cloud-based collaborative processing server reads the intermediate ciphertext results from each intermediate ciphertext aggregation record and, based on the ciphertext component alignment field in the protocol interaction arrangement record, organizes the ciphertext components of the intermediate ciphertext results into a ciphertext aggregation vector result. The ciphertext component order organization includes ciphertext component position reading, round sequence verification, and ciphertext aggregation component sorting. Ciphertext component position reading confirms the ciphertext component position corresponding to each intermediate ciphertext result; round sequence verification confirms that the intermediate ciphertext result has undergone cross-sandbox joint computation instructions from all participating virtual computing sandboxes; and ciphertext aggregation component sorting arranges the intermediate ciphertext results into ciphertext aggregation components according to the ciphertext component arrangement information. The ciphertext aggregation vector result includes a target power supply area identifier, a current control cycle identifier, a key version field, ciphertext component arrangement information, and source indexes for the ciphertext aggregation components and intermediate ciphertext results. The encrypted aggregated component is a data component formed by aggregating encrypted gradient vectors uploaded from multiple local charging piles in encrypted state through cross-sandbox joint operation instructions. The intermediate encrypted result source index is used to refer back to the virtual computing sandbox identifier, sandbox encrypted input record, intermediate encrypted aggregation record, and joint operation round record that participated in the formation of this encrypted aggregated component. The encrypted aggregated vector result does not expose the gradient update vector corresponding to a single local charging pile, nor does it expose the local electricity consumption preference representation parameter corresponding to a single local charging pile. Instead, it serves as the encrypted input data for deobfuscation parsing in the trusted execution environment. After the encrypted aggregated vector result is formed, the cloud collaborative processing server writes the encrypted aggregated vector result into the deobfuscation parsing call queue of the trusted execution environment, enabling the encrypted aggregated vector result to enter the trusted execution environment for deobfuscation parsing.
[0079] Preferably, the Trusted Execution Environment (TEE) is pre-established before the cloud-based collaborative processing server executes the deobfuscation parsing for the current control cycle. The TEE includes a protected memory area, a trusted call entry point, a key read permission table, a parsing task record area, and a trusted running status field. The protected memory area stores the ciphertext aggregation vector results entering the deobfuscation parsing process; the trusted call entry point receives deobfuscation parsing call requests from within the cloud-based collaborative processing server; the key read permission table limits the read permissions for the decrypted private key string; the parsing task record area stores the deobfuscation parsing task status for the current control cycle; and the trusted running status field indicates whether the TEE is in a parsable state. The cloud-based collaborative processing server pre-configures a private key configuration record within the TEE. This private key configuration record includes a target power supply area identifier, a key version field, a private key body field, a deobfuscation parameter index field, a key activation status field, and a key purpose field. The private key body field stores the decryption private key data corresponding to the encrypted public key string. The deobfuscation parameter index field is used to read the reverse parsing parameters of the polynomial obfuscation operation. The key activation status field indicates whether the private key configuration record can be invoked in the current control cycle. The key purpose field restricts the private key configuration record to be used only for deobfuscating the ciphertext aggregation vector result. The decryption private key string is encapsulated by the private key body field, deobfuscation parameter index field, key version field, and key purpose field in a fixed reading order and is only read within a trusted execution environment. A correspondence is established between the private key configuration record and the key version field and the target power supply area identifier, so that subsequent reading of the decryption private key string can be determined according to the key version field and the target power supply area identifier in the ciphertext aggregation vector result.
[0080] Preferably, when deobfuscating the ciphertext aggregation vector result using a pre-configured decryption private key string in the Trusted Execution Environment (TEE), the TEE first reads the target power supply area identifier, current control cycle identifier, key version field, and ciphertext component arrangement information from the ciphertext aggregation vector result. Based on the target power supply area identifier and key version field, it then reads the decryption private key string matching the current control cycle from the private key configuration record. Subsequently, the TEE performs purpose verification, version verification, and region verification on the decryption private key string. Purpose verification confirms that the key purpose field of the decryption private key string corresponds to the deobfuscated ciphertext aggregation vector result; version verification confirms that the key version field in the decryption private key string matches the key version field in the ciphertext aggregation vector result; and region verification confirms that the target power supply area identifier in the decryption private key string matches the target power supply area identifier in the ciphertext aggregation vector result. After passing purpose verification, version verification, and region verification, the TEE writes the ciphertext aggregation vector result to a protected memory area and writes the decryption private key string to the key reading location within the protected memory area. The key reading location is restricted by the key reading permission table; only deobfuscation and parsing tasks can read this key reading location after registering it in the parsing task record area. This process ensures that deobfuscation and parsing are completed within a trusted execution environment, preventing the decryption private key string from being separated from the ciphertext aggregation vector result in ordinary memory space. The trusted execution environment writes the decryption private key string, which has passed usage verification, version verification, and region verification, and the ciphertext aggregation vector result into the same deobfuscation and parsing task record, enabling subsequent ciphertext component unpacking processing to read the ciphertext aggregation vector result and the decryption private key string based on this deobfuscation and parsing task record.
[0081] Preferably, the deobfuscation parsing specifically includes ciphertext component unpacking, private key constraint inverse transformation, perturbation term reverse stripping, and aggregated gradient component reset. The ciphertext component unpacking process reads the ciphertext component arrangement information and the ciphertext aggregated components from the ciphertext aggregation vector result, and writes the ciphertext aggregated components into the parsing slot bearer record according to the ciphertext component arrangement information. The parsing slot bearer record includes the target power supply area identifier, the current control cycle identifier, the key version field, the parsing slot position, the ciphertext aggregated components, and the ciphertext component arrangement information. The private key constraint inverse transformation process reads the ciphertext aggregated components from the parsing slot bearer record and reads the private key body field from the decrypted private key string, performing a private key constraint inverse transformation corresponding to the public key constraint transformation on the ciphertext aggregated components to form an inverse transformation slot record. The inverse transformation slot record includes the parsing slot position, the inverse transformation slot components, the key version field, and the inverse transformation completion status. The perturbation term reverse stripping process reads the deobfuscation parameter index field from the decrypted private key string and reads the deobfuscation parameter corresponding to the key version field based on the deobfuscation parameter index field. Subsequently, the trusted execution environment performs perturbation term reverse stripping on the inverse-transformed slot components in the inverse-transformed slot record based on the deobfuscation parameters to form an aggregated gradient slot record. The aggregated gradient component reset process reads the slot position relationship in the aggregated gradient slot record and resets the aggregated gradient components in each slot position according to the ciphertext component arrangement information of the current control cycle to form an aggregated gradient component record. The aggregated gradient component record continues to serve as the direct input for generating the global load gradient compensation vector. The parsed slot bearer record, inverse-transformed slot record, aggregated gradient slot record, and aggregated gradient component record are all written to a protected memory area, ensuring that the intermediate data generated during the deobfuscation parsing process does not enter the ordinary memory space of the cloud collaborative processing server.
[0082] Preferably, after the aggregated gradient component record is formed, the trusted execution environment performs regional load compensation encapsulation processing on the aggregated gradient component record. The regional load compensation encapsulation processing first reads the time location aggregated component, power amplitude aggregated component, node type aggregated component, segment source aggregated component, and associated weight aggregated component from the aggregated gradient component record. Specifically, the time location aggregated component expresses the charging time location change trend of multiple local charging piles within the target power supply area in the current control cycle relative to the previous control cycle; the power amplitude aggregated component expresses the load amplitude change trend of multiple local charging piles within the target power supply area; the node type aggregated component expresses the change source corresponding to periodic peak nodes, periodic trough nodes, or periodic node pairing records within the target power supply area; the segment source aggregated component expresses that the change mainly originates from the pre-access reference segment, access climb segment, stable output segment, or access exit segment; and the associated weight aggregated component expresses the participation degree of various stationary point coordinates in regional load changes. The trusted execution environment writes the above aggregated components into the compensation vector carrying record and establishes a correspondence between the compensation vector carrying record and the target power supply area identifier, the current control cycle identifier, and the key version field. The compensation vector carrying record is not the final distribution object, but rather intermediate carrying data that carries the field transformation relationship between the aggregated gradient component record and the global load gradient compensation vector. The trusted execution environment then performs vector field encapsulation processing based on the compensation vector carrying record to form the global load gradient compensation vector. The vector field encapsulation processing writes the target power supply area identifier, current control cycle identifier, time location aggregated component, power amplitude aggregated component, node type aggregated component, segment source aggregated component, and associated weight aggregated component into the same vector carrying structure in a fixed field order, so that the global load gradient compensation vector can be read by the subsequent distribution processing in a fixed field order.
[0083] Preferably, the technical essence of the global load gradient compensation vector is that it is formed by aggregating the encrypted gradient vectors of multiple local charging piles within the target power supply area in ciphertext, and then deobfuscating and parsing them in a trusted execution environment to create regional load adjustment direction data. The global load gradient compensation vector is not the single-pile power consumption data of any local charging pile, nor is it the result of splicing together the plaintext initial power consumption characteristic data of multiple local charging piles. Instead, it is scheduling compensation data formed around the overall load change trend of the target power supply area within the current control cycle. The global load gradient compensation vector includes the target power supply area identifier, the current control cycle identifier, a time location aggregation component, a power amplitude aggregation component, a node type aggregation component, a segment source aggregation component, and an associated weight aggregation component. The time location aggregation component, power amplitude aggregation component, node type aggregation component, segment source aggregation component, and associated weight aggregation component all originate from the deobfuscated parsing result of the ciphertext aggregation vector and are subsequently distributed to each local charging pile so that each local charging pile can correct its local load scheduling instructions according to the global load gradient compensation vector. Since the global load gradient compensation vector only expresses the overall load change trend within the target power supply area, the initial electricity consumption characteristic data, local electricity consumption preference representation parameters, and gradient update vector of a single local charging pile are still not entered into the ordinary memory space of the cloud collaborative processing server in plaintext field form. After the global load gradient compensation vector is formed, a correspondence is established with the compensation vector carrying record, enabling the cloud collaborative processing server to read the global load gradient compensation vector from the trusted execution environment and distribute the global load gradient compensation vector to each local charging pile.
[0084] Preferably, after generating the global load gradient compensation vector, the trusted execution environment also writes the parsing task status formed during the deobfuscation process into the parsing task record area. The parsing task status includes the current control cycle identifier, target power supply area identifier, key version field, ciphertext aggregation vector result reading status, decryption private key string reading status, ciphertext component unpacking completion status, private key constraint inverse transformation completion status, disturbance term reverse stripping completion status, aggregated gradient component reset completion status, deobfuscation parsing completion status, and global load gradient compensation vector encapsulation status. The parsing task status records the processing path of the ciphertext aggregation vector result from entering the trusted execution environment to generating the global load gradient compensation vector, and establishes a correspondence with the compensation vector carrying record. The cloud-based collaborative processing server then reads the global load gradient compensation vector from the trusted execution environment, without reading the decryption private key string, deobfuscation parameters, or the gradient update vector corresponding to a single local charging pile. After establishing a correspondence between the parsing task status and the global load gradient compensation vector, it continues to serve as the status basis for the global load gradient compensation vector within the current control cycle having completed deobfuscation parsing and vector field encapsulation processing. Through the above processing, the cloud-based collaborative processing server can obtain regional-level scheduling compensation data while maintaining the encrypted isolation of the initial electricity consumption characteristic data of a single pile, the local electricity consumption preference representation parameters, and the gradient update vector.
[0085] Optionally, a ciphertext-state communication link is established between different virtual computing sandboxes according to the interaction rules of the secure multi-party computation protocol. Through this ciphertext-state communication link, joint operation instructions across sandboxes are executed while maintaining the ciphertext state of the encrypted gradient vector. This includes: issuing instructions to control each virtual computing sandbox to randomly generate a pseudo-random noise array; within any virtual computing sandbox, logically fusing the received and allocated encrypted gradient vector with the pseudo-random noise array to generate a corresponding noisy ciphertext data packet; and performing homomorphic vector fusion processing on all noisy ciphertext data packets generated by all virtual computing sandboxes via the ciphertext-state communication link. During the homomorphic vector fusion process, symmetric cancellation rules are used to clear all pseudo-random noise arrays, and the output data corresponding to the joint operation instructions is exported as the ciphertext aggregation vector result.
[0086] Preferably, the specific implementation process of establishing encrypted communication links between different virtual computing sandboxes according to the interaction rules of the secure multi-party computation protocol, and executing cross-sandbox joint operation instructions through the encrypted communication links while maintaining the encrypted gradient vector encrypted state, is as follows: After the protocol input ready record is formed, the cloud collaborative processing server first reads the target power supply area identifier, current control cycle identifier, sandbox session identifier, participating virtual computing sandbox identifier, encrypted component alignment field, and sandbox interaction order field from the protocol interaction orchestration record, and generates a sandbox noise pairing record based on the participating virtual computing sandbox identifier. The sandbox noise pairing record includes the target power supply area identifier, current control cycle identifier, sandbox session identifier, forward write sandbox identifier, reverse write sandbox identifier, encrypted component position field, round sequence field, and noise cancellation direction field. The forward write sandbox identifier is used to limit the virtual computing sandbox that writes forward noise slot elements in subsequent logical fusion operations. The reverse write sandbox identifier is used to limit the virtual computing sandbox that writes reverse noise slot elements in subsequent logical fusion operations. The ciphertext component position field is used to limit the ciphertext component position where forward and reverse noise slot elements interact. The round sequence field is used to limit the cross-sandbox joint operation rounds in which forward and reverse noise slot elements participate. The noise cancellation direction field is used to limit the cancellation direction of forward and reverse noise slot elements in homomorphic vector fusion processing. After the sandbox noise pairing record is formed, the cloud collaborative processing server issues noise generation control commands to all virtual computing sandboxes under the current sandbox session identifier based on the sandbox noise pairing record, so that the pseudo-random noise arrays subsequently generated by each virtual computing sandbox have the same current control cycle, the same sandbox session identifier, the same ciphertext component arrangement information, and the same round sequence field source.
[0087] Preferably, the noise generation control command is not a simple random trigger command, but a data configuration command used to control the row and column structure, pairing relationship, and cancellation direction of the pseudo-random noise array. The noise generation control command includes a target power supply area identifier, a current control cycle identifier, a sandbox session identifier, a virtual computing sandbox identifier, ciphertext component arrangement information, a ciphertext component quantity field, a round sequence field, a sandbox noise pairing record identifier, and a noise cancellation direction field. The target power supply area identifier is used to limit the area scheduling range in which the pseudo-random noise array participates; the current control cycle identifier is used to limit the aggregation cycle in which the pseudo-random noise array participates; the sandbox session identifier is used to limit the cross-sandbox joint operation session to which the pseudo-random noise array belongs; the virtual computing sandbox identifier is used to limit the generation location of the pseudo-random noise array; the ciphertext component arrangement information is used to limit the alignment relationship between the pseudo-random noise array and the ciphertext components in the encrypted gradient vector; the ciphertext component quantity field is used to limit the row range of the pseudo-random noise array; the round sequence field is used to limit the cross-sandbox joint operation round in which the pseudo-random noise array participates; the sandbox noise pairing record identifier is used to indicate the pairing source between the forward and reverse sandbox identifiers; and the noise cancellation direction field is used to limit the forward or reverse writing relationship of the pseudo-random noise array in the subsequent symmetric cancellation rules. Noise generation control commands are written to the noise generation control record, which continues to serve as the unified input for each virtual computing sandbox to generate the pseudo-random noise array.
[0088] Preferably, when each virtual computing sandbox randomly generates a pseudo-random noise array, the random generation is not the generation of arbitrary data without a source. Instead, each virtual computing sandbox establishes a sandbox noise seed record based on the noise generation control record, and the sandbox noise seed record is then subjected to pseudo-random expansion processing to form a pseudo-random noise array. The sandbox noise seed record includes a target power supply area identifier, a current control cycle identifier, a sandbox session identifier, a virtual computing sandbox identifier, a sandbox noise pairing record identifier, a round sequence field, a ciphertext component position field, a noise cancellation direction field, and a noise seed status field. The target power supply area identifier, current control cycle identifier, and sandbox session identifier jointly define that the sandbox noise seed record is only read in the current area aggregation session; the virtual computing sandbox identifier is used to distinguish sandbox noise seed records generated within different virtual computing sandboxes; the sandbox noise pairing record identifier is used to enable forward and reverse write sandbox identifiers to generate corresponding noise slot elements; the round sequence field is used to distinguish sandbox noise seed records generated by the same virtual computing sandbox in different cross-sandbox joint operation rounds; the ciphertext component position field is used to ensure that each row of the subsequent pseudo-random noise array corresponds to a ciphertext component position in the encrypted gradient vector; the noise cancellation direction field is used to ensure that the subsequent pseudo-random noise array can form a cancellation correspondence with the pseudo-random noise arrays generated by other virtual computing sandboxes during homomorphic vector fusion processing; the noise seed status field is used to mark whether the sandbox noise seed record has been read by the current virtual computing sandbox. After each virtual computing sandbox reads the sandbox noise seed record, it performs pseudo-random expansion processing on the sandbox noise seed record according to the ciphertext component arrangement information and the ciphertext component quantity field to form the corresponding pseudo-random noise array.
[0089] Preferably, the specific process of pseudo-random expansion processing is as follows: The virtual computing sandbox first reads the current control cycle identifier, sandbox session identifier, virtual computing sandbox identifier, sandbox noise pairing record identifier, and round sequence field from the sandbox noise seed record, and encapsulates the above fields into a noise expansion input record according to a fixed field order; then, the virtual computing sandbox configures the row count position for the noise expansion input record according to the ciphertext component quantity field, and configures the column count position for the noise expansion input record according to the pairing quantity in the sandbox noise pairing record; then, the row count position, column count position, and noise cancellation direction field are written into the noise expansion input record together, so that the noise expansion input record can be read slot by slot according to the row count position and column count position. The virtual computing sandbox generates noise slot elements one by one according to the noise expansion input records. Specifically, the forward-write sandbox identifier and the reverse-write sandbox identifier corresponding to the same sandbox noise pairing record identifier, the same ciphertext component position field, and the same round sequence bit field generate mutually canceling noise slot elements. The noise slot element corresponding to the forward-write sandbox identifier is written to the forward noise slot, and the noise slot element corresponding to the reverse-write sandbox identifier is written to the reverse noise slot. The forward and reverse noise slots use the same ciphertext operation domain slot aperture, enabling subsequent homomorphic vector fusion processing to perform positional fusion on the forward and reverse noise slots without decrypting the ciphertext content. The noise slot elements formed by the above pseudo-random expansion process are written to a pseudo-random noise array, and the pseudo-random noise array is written within the memory page range of the corresponding virtual computing sandbox, ensuring that the pseudo-random noise array only participates in logical fusion operations within the corresponding virtual computing sandbox.
[0090] Preferably, the technical essence of the pseudo-random noise array is that it generates ciphertext perturbation-carrying data according to the arrangement information of the ciphertext components of the encrypted gradient vector. This data is used to mask the arrangement relationship of the ciphertext components of the encrypted gradient vector within a single virtual computing sandbox, and is subsequently removed through symmetric cancellation rules during the homomorphic vector fusion process. The pseudo-random noise array consists of multiple rows and columns: each row corresponds to the position of a ciphertext component in the encrypted gradient vector, with the row order derived from the arrangement information of the ciphertext components; each column corresponds to a set of noise pairing relationships formed between the current virtual computing sandbox and another virtual computing sandbox within a cross-sandbox joint computation round, with the column order derived from the sandbox noise pairing record identifier and the round sequence field; the element at the intersection of rows and columns is a noise slot element, which is formed by pseudo-random expansion processing of the sandbox noise seed record and carries a noise cancellation direction field. Noise slot elements do not represent port voltage sampling sequences, initial power consumption characteristic data, local power consumption preference representation parameters, or the plaintext content of gradient update vectors. Noise slot elements are only used to form a cancelable perturbation cover before the ciphertext components of the encrypted gradient vector enter the cross-sandbox joint operation instruction. After generating the pseudo-random noise array, the virtual computing sandbox writes the pseudo-random noise array, sandbox noise seed record, sandbox noise pairing record identifier, ciphertext component arrangement information, and noise cancellation direction field into the noise array carrying record. The noise array carrying record continues to serve as input for subsequent logical fusion operations.
[0091] Preferably, within any virtual computing sandbox, when performing a logical fusion operation between the received and allocated encrypted gradient vector and the pseudo-random noise array, the virtual computing sandbox first reads the encrypted gradient vector from the sandbox ciphertext input record and splits it into multiple ciphertext components to be fused according to the ciphertext component arrangement information. Each ciphertext component to be fused retains its corresponding ciphertext component position, current control cycle identifier, key version field, local charging pile identifier, and power output interface identifier. Subsequently, the virtual computing sandbox reads the pseudo-random noise array from the noise array carrier record and reads all noise slot elements corresponding to the same row as the ciphertext component to be fused from the pseudo-random noise array according to the ciphertext component position. Since the same row may include multiple column positions, the virtual computing sandbox first performs row-level noise synthesis processing on the noise slot elements in the same row according to the noise cancellation direction field to form a row-level noise synthesis component; the row-level noise synthesis component retains the ciphertext component position, noise cancellation direction field, and sandbox noise pairing record identifier. The virtual computing sandbox then writes the ciphertext component to be fused and the row-level noise synthesis component at the same ciphertext component position into the same fusion slot carrying record, and performs ciphertext state superposition processing on the fusion slot carrying record according to the slot aperture of the same ciphertext operation domain to form a noisy ciphertext component.
[0092] Preferably, the ciphertext state superposition processing in the logical fusion operation does not decrypt the ciphertext content of the ciphertext component to be fused, nor does it read the plaintext field of the gradient update vector. Instead, it embeds the row-level noise synthesis component into the fusion slot corresponding to the ciphertext component to be fused within the same ciphertext operation domain slot. Specifically, the virtual computing sandbox reads the ciphertext component to be fused, the row-level noise synthesis component, the ciphertext component position, and the noise cancellation direction fields from the fusion slot carrying record, and performs ciphertext state superposition processing within the fusion slot corresponding to the ciphertext component position, so that the ciphertext component to be fused and the row-level noise synthesis component form a same-slot binding relationship. The same-slot binding relationship is written to the fusion status field in the fusion slot carrying record, which indicates that the ciphertext component to be fused at that ciphertext component position has completed noise embedding. Multiple noisy ciphertext components that have completed noise embedding are re-encapsulated according to the ciphertext component arrangement information to form a corresponding noisy ciphertext data packet. Therefore, each noisy ciphertext component in the noisy ciphertext data packet can refer back to its corresponding ciphertext component to be fused, row-level noise synthesis component, noise slot element, and sandbox noise pairing record. Subsequent homomorphic vector fusion processing can execute the symmetric cancellation rule along this source relationship.
[0093] Preferably, the technical essence of the noisy ciphertext data packet is temporary ciphertext interaction data formed by logical fusion of the ciphertext component in the encrypted gradient vector and the noise slot elements in the pseudo-random noise array. The noisy ciphertext data packet includes a target power supply area identifier, a current control cycle identifier, a sandbox session identifier, a virtual computing sandbox identifier, a key version field, ciphertext component arrangement information, the noisy ciphertext component, a row-level noise synthesis component source index, a noise cancellation direction field, and a noisy ciphertext data packet source index. The noisy ciphertext component is used to participate in cross-sandbox joint operation instructions in the ciphertext-state communication link. The row-level noise synthesis component source index is used to indicate the row and column positions of the pseudo-random noise array that formed the noisy ciphertext component. The noise cancellation direction field is used to define the cancellation direction of the noisy ciphertext component in the homomorphic vector fusion process. The noisy ciphertext data packet source index is used to indicate the sandbox ciphertext input record, the noise array carrying record, and the fusion slot carrying record. Because the noisy encrypted data packets retain the source index of the noisy encrypted data packets, subsequent homomorphic vector fusion processing can track which virtual computing sandbox each noisy encrypted component comes from and which encrypted component is located; because the noisy encrypted data packets do not carry plaintext fields such as port voltage sampling sequences, initial power consumption characteristic data, local power consumption preference representation parameters or gradient update vectors, the plaintext underlying sampling content of a single local charging pile will not be exposed to other virtual computing sandboxes during cross-sandbox interaction.
[0094] Preferably, when performing homomorphic vector fusion processing on noisy ciphertext data packets generated by all virtual computing sandboxes via the ciphertext-state communication link, the cloud-based collaborative processing server first reads the ciphertext component alignment field, sandbox interaction order field, and joint operation instruction identifier according to the protocol interaction arrangement record. Then, based on the ciphertext component alignment field, it aligns the noisy ciphertext data packets in different virtual computing sandboxes according to the same ciphertext component position. This alignment arrangement forms a noisy ciphertext alignment record, which includes the ciphertext component position, the identifier of the virtual computing sandbox participating in the fusion, the noisy ciphertext component, the row-level noise synthesis component source index, the noise cancellation direction field, and the noisy ciphertext data packet source index. After the noisy ciphertext alignment record is formed, the cloud-based collaborative processing server distributes the noisy ciphertext alignment record to the virtual computing sandboxes participating in the current round via the ciphertext-state communication link. Each virtual computing sandbox performs homomorphic vector fusion processing on the noisy ciphertext components at the same ciphertext component position according to the joint operation instruction identifier to form a noisy intermediate fusion record. The essence of homomorphic vector fusion processing is to perform ciphertext-state alignment fusion on noisy ciphertext components from different virtual computing sandboxes at the same ciphertext component location without decrypting the ciphertext component content. This allows encrypted gradient vectors uploaded from multiple local charging piles to form a regional-level ciphertext aggregated input in ciphertext state. The regional-level ciphertext aggregated input retains the ciphertext component location, sandbox session identifier, and joint operation instruction identifier, serving as the direct data basis for the subsequent noisy intermediate fusion record formation.
[0095] Preferably, the specific execution process of homomorphic vector fusion processing is as follows: The virtual computing sandbox participating in the current round first reads the positions of the ciphertext components in the noisy ciphertext alignment record, and writes multiple noisy ciphertext components at the same ciphertext component position into the noisy fusion slot record; subsequently, the virtual computing sandbox reads the joint operation instruction identifier, and performs ciphertext-state alignment fusion on multiple noisy ciphertext components in the noisy fusion slot record according to the joint operation instruction identifier to form a noisy intermediate fusion record. The noisy intermediate fusion record includes the ciphertext component position, the noisy intermediate fusion component, the identifier of the virtual computing sandbox participating in the fusion, the row-level noise synthesis component source index, the noise cancellation direction field, and the joint operation instruction identifier. The noisy intermediate fusion component is still in the ciphertext state, and its internal structure includes the ciphertext aggregation relationship of multiple encrypted gradient vectors and the perturbation relationship introduced by the pseudo-random noise array. The noisy intermediate fusion record continues to be written into the memory page range of the current virtual computing sandbox and transmitted to the next virtual computing sandbox via the encrypted communication link according to the sandbox interaction order field, so that the next virtual computing sandbox can continue to perform homomorphic vector fusion processing on the noisy intermediate fusion record.
[0096] Preferably, the technical essence of the symmetric cancellation rule is to utilize sandbox noise pairing records and noise cancellation direction fields to ensure that noise slot elements with the same source but opposite directions at the same ciphertext component position are paired and canceled out during the homomorphic vector fusion process. This removes the perturbation effect of the pseudo-random noise array on the final ciphertext aggregation vector result while preserving the encrypted gradient vector aggregation result. Specifically, when generating sandbox noise pairing records, the cloud-based collaborative processing server configures the same sandbox noise pairing record identifier, the same ciphertext component position field, and the same round sequence field for both the forward write sandbox identifier and the reverse write sandbox identifier, and configures noise cancellation direction fields with opposite directions. Noise slot elements generated by the forward write sandbox identifier enter the noisy ciphertext component with a forward write entry path, and noise slot elements generated by the reverse write sandbox identifier enter the noisy ciphertext component with a reverse write entry path. During homomorphic vector fusion processing, noisy ciphertext alignment records are read according to the positions of the ciphertext components, including the forward and reverse write entry points. Ciphertext alignment fusion is then performed within the same ciphertext component position, causing the noise slot elements corresponding to the forward and reverse write entry points to cancel each other out during the fusion process. The symmetric cancellation rule does not require reading the plaintext noise values corresponding to the pseudo-random noise array, nor does it require decrypting the noisy ciphertext components. Instead, it utilizes the correspondence between sandbox noise pairing records, the noise cancellation direction field, and the ciphertext component positions to complete the cancellation process.
[0097] Preferably, during the homomorphic vector fusion process, when using symmetric cancellation rules to remove all pseudo-random noise arrays, the virtual computing sandbox first reads the ciphertext component position, the noisy intermediate fusion component, the row-level noise synthesis component source index, and the noise cancellation direction field from the noisy intermediate fusion record. Then, it reads the corresponding cancellation direction pairing record based on the row-level noise synthesis component source index. The cancellation direction pairing record includes a sandbox noise pairing record identifier, a forward write sandbox identifier, a reverse write sandbox identifier, the ciphertext component position, a round sequence field, and a noise cancellation completion status. The virtual computing sandbox performs alignment fusion on the noisy ciphertext components with forward and reverse write apertures at the same ciphertext component position according to the cancellation direction pairing record, and writes the aligned fused ciphertext component into the canceled ciphertext component record. The canceled ciphertext component record includes the ciphertext component position, the canceled ciphertext component, the noise cancellation completion status, the noisy ciphertext data packet source index, and the cancellation direction pairing record source index. The noise cancellation completion status indicates whether the pseudo-random noise array corresponding to the ciphertext component position has completed symmetrical cancellation; the source index of the noisy ciphertext data packet is used to refer back to the noisy ciphertext data packet that participated in this cancellation process; the source index of the cancellation direction pairing record is used to refer back to the sandbox noise pairing record and the cancellation direction pairing record on which this cancellation process is based. After the above processing is completed, the pseudo-random noise array is no longer used as an independent disturbance in the subsequent ciphertext aggregation vector result, and the canceled ciphertext component record continues to be used as the direct input of the output data.
[0098] Preferably, the pseudo-random noise array needs to be cleared during the homomorphic vector fusion process because its function is to mask the ciphertext component arrangement of the encrypted gradient vector within a single virtual computing sandbox, rather than altering the regional load variation trend of multiple local charging piles within the target power supply area. If the pseudo-random noise array remains in the ciphertext result after homomorphic vector fusion, the subsequent trusted execution environment will read the aggregated gradient component containing the disturbance when performing deobfuscation parsing on the ciphertext aggregated vector result. This will cause the time position aggregated component, power amplitude aggregated component, node type aggregated component, fragment source aggregated component, and associated weight aggregated component in the global load gradient compensation vector to deviate from the regional variation direction. Based on this, the symmetric cancellation rule clears the pseudo-random noise array while maintaining the ciphertext state of the encrypted gradient vector, ensuring that the ciphertext component record after cancellation only retains the ciphertext state aggregation relationship of multiple encrypted gradient vectors at the same ciphertext component position. The ciphertext component record after cancellation then enters the runtime output data encapsulation process to prevent the pseudo-random noise array from continuing to affect the ciphertext aggregated vector result as an irrelevant disturbance.
[0099] Preferably, when exporting the runtime output data corresponding to the joint operation instruction as the encrypted aggregation vector result, the cloud collaborative processing server first reads all the ciphertext component records formed by the virtual computing sandboxes after cancellation, and performs ciphertext component order sorting on the ciphertext component records according to the ciphertext component arrangement information. The ciphertext component order sorting reads the ciphertext component position, the ciphertext component after cancellation, the noise cancellation completion status, the source index of the noisy encrypted data packet, and the source index of the cancellation direction pairing record in each ciphertext component record, and confirms that all virtual computing sandboxes participating in the current control cycle under the same ciphertext component position have completed noise cancellation. The ciphertext component after cancellation confirmed by noise cancellation completion is written into the runtime output data bearer record according to the ciphertext component arrangement information. The runtime output data bearer record includes the target power supply area identifier, the current control cycle identifier, the sandbox session identifier, the key version field, the ciphertext component arrangement information, the ciphertext component after cancellation, the source index of the noisy encrypted data packet, the source index of the cancellation direction pairing record, and the joint operation instruction identifier. The runtime output data carrier record is not a plaintext aggregation result, but rather a ciphertext aggregate carrier data formed by encapsulating the ciphertext components after homomorphic vector fusion processing and symmetric cancellation rules. The cloud-based collaborative processing server then performs vectorization encapsulation processing on the runtime output data carrier record to encapsulate it into a ciphertext aggregate vector result.
[0100] Preferably, the technical essence of the ciphertext aggregation vector result is regional-level ciphertext aggregation data formed after all noisy ciphertext data packets generated by the virtual computing sandboxes are transmitted through ciphertext-state communication links, processed by homomorphic vector fusion, and processed by symmetric cancellation rules. The ciphertext aggregation vector result includes a target power supply area identifier, a current control cycle identifier, a sandbox session identifier, a key version field, ciphertext component arrangement information, ciphertext aggregation components, a noisy ciphertext data packet source index, a cancellation direction pairing record source index, and a joint operation instruction identifier. The ciphertext aggregation components originate from the canceled ciphertext component records. The noisy ciphertext data packet source index is used to refer back to the noisy ciphertext data packets generated by each virtual computing sandbox. The cancellation direction pairing record source index is used to refer back to the cancellation direction pairing record on which the symmetric cancellation rule is based. The joint operation instruction identifier is used to refer back to the cross-sandbox joint operation instruction executed to generate this ciphertext aggregation vector result. The encrypted aggregation vector result does not carry the pseudo-random noise array itself, nor does it carry the plaintext fields of any local charging pile's port voltage sampling sequence, initial electricity consumption characteristic data, local electricity consumption preference representation parameters, or gradient update vector. The encrypted aggregation vector result is then used as input for de-obfuscation parsing in the trusted execution environment so as to generate a global load gradient compensation vector for the target power supply area.
[0101] Optionally, to instruct each local charging pile to parse the global load gradient compensation vector and then correct its own local load scheduling command to control the power output interface of each local charging pile, the method includes: when the communication bus of the local charging pile receives the global load gradient compensation vector, sending a wake-up interrupt signal to the instruction update module arranged in the microprocessor; reading the default output power preset configuration information of the current control cycle cached in the storage unit through the instruction update module; performing offset correction on the control baseline of the default output power preset configuration information according to the load adjustment step size contained in the global load gradient compensation vector; and confirming the instruction code that has completed the offset correction as the corrected local load scheduling command to drive the power output interface to run.
[0102] Preferably, the specific implementation process of instructing each local charging pile to parse the global load gradient compensation vector and then modify its local load scheduling command to control the power output interface of each local charging pile is as follows: When the encrypted communication bus of a local charging pile receives the global load gradient compensation vector issued by the cloud collaborative processing server, the encrypted communication bus first performs compensation vector reception verification processing. The compensation vector reception verification processing reads the target power supply area identifier, current control cycle identifier, key version field, time location aggregation component, power amplitude aggregation component, node type aggregation component, segment source aggregation component, and associated weight aggregation component carried by the global load gradient compensation vector, and writes the above fields into the global compensation vector reception record. The global compensation vector reception record carries the source relationship, periodic relationship, and field integrity relationship formed when the local charging pile receives the global load gradient compensation vector. Specifically, the target power supply area identifier limits the distribution scheduling range corresponding to the global load gradient compensation vector; the current control cycle identifier limits the execution cycle corresponding to the global load gradient compensation vector; the key version field limits the ciphertext conversion method corresponding to the global load gradient compensation vector; and the time location aggregation component, power amplitude aggregation component, node type aggregation component, fragment source aggregation component, and associated weight aggregation component limit the regional load adjustment direction required for subsequent local load scheduling instruction correction. After the global compensation vector reception record is formed, the encrypted communication bus reads the local charging pile identifier and power output interface identifier, and writes these identifiers, along with the current control cycle identifier, into the compensation vector reception verification result. The compensation vector reception verification result continues to serve as the basis for generating the wake-up interrupt signal, ensuring that the instruction update module subsequently only performs local load scheduling instruction corrections based on the global load gradient compensation vector that has already undergone compensation vector reception verification processing.
[0103] Preferably, the wake-up interrupt signal is not a regular start-up prompt signal, but rather periodic trigger data used to establish a correspondence between the global compensation vector reception record and the local instruction update process of the instruction update module. The encrypted communication bus generates the wake-up interrupt signal based on the compensation vector reception verification result. The wake-up interrupt signal includes the target power supply area identifier, the current control cycle identifier, the local charging pile identifier, the power output interface identifier, the global compensation vector reception record identifier, the compensation vector reception verification result identifier, and the instruction update module entry identifier. The power output interface identifier originates from the power output interface configuration record formed when the local charging pile registers locally. The power output interface configuration record includes the local charging pile identifier, the power output interface identifier, the rated output power range field, the power output upper limit field, the power output lower limit field, the power change limit field, the instruction code format field, and the interface enable status field. After receiving the wake-up interrupt signal, the instruction update module reads the global compensation vector reception record and the compensation vector reception verification result, and establishes an instruction update session record based on the current control cycle identifier, the local charging pile identifier, the power output interface identifier, and the instruction update module entry identifier. The instruction update session record is used to limit the local load scheduling instruction correction to the current control cycle, the same local charging pile, and the corresponding power output interface. Subsequent reading of default output power preset configuration information, forming load adjustment step size, determining control baseline, performing offset correction, and generating corrected local load scheduling instructions all use the current control cycle identifier, local charging pile identifier, and power output interface identifier in the instruction update session record.
[0104] Preferably, when the instruction update module reads the default output power preset configuration information for the current control cycle cached in the storage unit, the instruction update module does not simply read the most recently written data based on the local clock. Instead, it first reads the local control cycle index record based on the current control cycle identifier in the instruction update session record. The local control cycle index record is continuously written by the local charging pile according to the scheduling refresh frequency of the charging pile group in the target power supply area. The local control cycle index record includes the control cycle identifier, control cycle start time position, control cycle end time position, local charging pile identifier, power output interface identifier, default output power preset configuration information cache address, default output power preset configuration information enable status field, and control cycle execution status field. The current control cycle is determined as follows: The instruction update module reads the current control cycle identifier carried by the global load gradient compensation vector and matches it with the control cycle identifier in the local control cycle index record. When the start time position of the control cycle corresponding to the matched control cycle identifier has been reached, the end time position of the control cycle has not been reached, the default output power preset configuration information enable status field is readable, and the control cycle execution status field is pending or in execution, the instruction update module confirms the control cycle corresponding to that control cycle identifier as the current control cycle. If the current control cycle identifier carried by the global load gradient compensation vector is inconsistent with the control cycle identifier in the local control cycle index record, the instruction update module writes the global compensation vector receiving record into the cycle mismatch record and stops the current offset correction. The cycle mismatch record includes the global compensation vector receiving record identifier, the current control cycle identifier, the control cycle identifier in the local control cycle index record, the power output interface identifier, and the stop offset correction status field. The cycle mismatch record is used to carry the cycle source for stopping the current offset correction, preventing the global load gradient compensation vector from entering the local load scheduling instruction correction process corresponding to the incorrect control cycle. Therefore, the reading of the default output power preset configuration information is limited by the current control cycle identifier and the local control cycle index record, rather than by fuzzy time judgment.
[0105] Preferably, the default output power preset configuration information is pre-configured with basic fields before the local charging pile enters the target power supply area for coordinated scheduling. Before the start of each control cycle, the local charging pile generates a cache entry corresponding to the current control cycle based on the power output interface configuration record and the local operating status record. The local operating status record includes the current power supply access status field, the power output interface temperature status field, the vehicle access status field, the power output interface activation status field, the local safety limit status field, and the output feedback field from the previous control cycle. The instruction update module reads the rated output power range field, the power output upper limit field, the power output lower limit field, the power change limit field, and the instruction code format field from the power output interface configuration record, and reads the current power supply access status field, the power output interface temperature status field, the vehicle access status field, the power output interface activation status field, the local safety limit status field, and the output feedback field from the previous control cycle from the local operating status record. These fields are then written into the default power configuration generation record. After field arrangement processing, the default power configuration generation record forms the default output power preset configuration information, which is then written into the cache address corresponding to the current control cycle identifier within the storage unit. The default output power preset configuration information includes the current control cycle identifier, local charging pile identifier, power output interface identifier, default output power field, power output upper limit field, power output lower limit field, power change limit field, execution time slice field, control baseline field, default command code field, and default output power preset configuration information enable status field. The default output power preset configuration information is used to provide a locally executable basic power control approach when a global load gradient compensation vector is not received. Subsequent offset corrections are based on the default output power preset configuration information.
[0106] Preferably, the default output power field is not an arbitrarily set single power value, but rather a default power field formed jointly by the rated output power range field, vehicle access status field, current power supply access status field, and output feedback field of the previous control cycle. The instruction update module first reads the vehicle access status field to confirm whether a valid vehicle is connected to the power output interface. If a valid vehicle is connected, the instruction update module reads the current power supply access status field to determine whether the power output interface is in a power-available state, a waiting state, or a derating state. Subsequently, the instruction update module reads the output feedback field of the previous control cycle to obtain the output power feedback field that the power output interface has executed in the previous control cycle. Then, it performs range assignment processing on the output power feedback field according to the rated output power range field to form the default output power field. After the default output power field is formed, it is written into the default output power preset configuration information and participates in the formation of the control baseline together with the power output upper limit field, power output lower limit field, and power change limit field. Through the above processing, the default output power field can inherit the local execution state of the power output interface in the previous control cycle and serve as the power basis field for offset correction in the current control cycle.
[0107] Preferably, the technical essence of the control baseline is local instruction reference data in the default output power preset configuration information, used to limit the basic output level and adjustable boundaries of the power output interface within the current control cycle, rather than an actual physical line. The control baseline is formed by the default output power field, the power output upper limit field, the power output lower limit field, the power change limit field, and multiple execution time slice positions within the current control cycle. The instruction update module reads the execution time slice field from the default output power preset configuration information and divides the current control cycle into multiple execution time slice positions according to the execution time slice field. Subsequently, the instruction update module writes the default output power field into the baseline carrier record according to the execution time slice position to form the default output power position field. Next, the instruction update module reads the power output upper limit field and the power output lower limit field to form the output boundary field in the baseline carrier record; then, it reads the power change limit field to form the change restriction field between adjacent execution time slices in the baseline carrier record. After the baseline carrier record completes field encapsulation, it forms the control baseline. The control baseline retains the default output power field in the default output power preset configuration information, and retains the boundary and range of adjustment allowed for the power output interface within the current control cycle. Therefore, the subsequent load adjustment step size can only participate in offset correction within the scope defined by the control baseline.
[0108] Preferably, before performing offset correction on the control baseline of the default output power preset configuration information based on the load adjustment step size contained in the global load gradient compensation vector, the instruction update module first performs compensation component parsing processing on the global load gradient compensation vector. The compensation component parsing processing reads the time position aggregation component, power amplitude aggregation component, node type aggregation component, segment source aggregation component, and associated weight aggregation component, and converts the time position aggregation component into an execution time slice adjustment direction field, the power amplitude aggregation component into a power amplitude adjustment direction field, the node type aggregation component into a change source type field, the segment source aggregation component into a charging stage effect field, and the associated weight aggregation component into a regulation participation degree field. The execution time slice adjustment direction field, power amplitude adjustment direction field, change source type field, charging stage effect field, and regulation participation degree field are jointly written into the load adjustment step size generation record. The load adjustment step size generation record is then used to form the load adjustment step size, ensuring that the load adjustment step size originates from the regional-level aggregation component in the global load gradient compensation vector, rather than from the plaintext initial electricity consumption characteristic data of any local charging pile.
[0109] Preferably, the technical essence of the load adjustment step size is local power correction amplitude data formed based on the regional load adjustment direction in the global load gradient compensation vector. This data is used to indicate whether the control baseline shifts in the direction of increase, decrease, or maintenance within the current control cycle. The load adjustment step size includes fields for execution time slice adjustment direction, power amplitude adjustment direction, change source type, charging phase effect, adjustment participation level, and step size. The execution time slice adjustment direction field is used to limit the load adjustment step size to the target execution time slice identifier in the current control cycle. The power amplitude adjustment direction field is used to limit the control baseline to move closer to the upper limit of power output, closer to the lower limit of power output, or maintain its original position. The change source type field is used to limit the change source corresponding to the load adjustment step size to a periodic peak node, a periodic trough node, or a periodic node pairing record. The charging stage action field is used to limit the load adjustment step size to whether it is connected to the pre-connection reference segment, the connection to the climb segment, the stable output segment, or the connection to the exit segment. The adjustment participation level field is used to limit the strength of the load adjustment step size's participation in offset correction within the current control cycle. The step size field is used to carry the adjustment magnitude after local power conversion. After the load adjustment step size is formed, it is written to the load adjustment step size carrying record. The load adjustment step size carrying record includes the current control cycle identifier, the local charging pile identifier, the power output interface identifier, the execution time slice adjustment direction field, the power amplitude adjustment direction field, the change source type field, the charging stage action field, the adjustment participation level field, and the step size field. The load adjustment step size and load record continue to participate in the offset correction of the control baseline.
[0110] Preferably, the step size field does not directly use the original content of the power amplitude aggregation component, but is formed by the instruction update module according to the local power caliber conversion process. The local power caliber conversion process first reads the power output upper limit field, power output lower limit field, and power change limit field from the power output interface configuration record, and then reads the power amplitude adjustment direction field and adjustment participation level field from the load adjustment step size generation record. Subsequently, the instruction update module forms an adjustable amplitude range field based on the adjustable range between the power output upper limit field and the power output lower limit field. Next, the instruction update module performs amplitude limiting processing on the adjustable amplitude range field according to the power change limit field to form a limited adjustable amplitude field. Finally, it performs participation level configuration processing on the limited adjustable amplitude field according to the adjustment participation level field to form the step size field. The step size field has the same power instruction unit caliber as the control baseline, thus enabling offset correction with the same dimensions as the control baseline. If the global load gradient compensation vector expresses an upward trend in load within the target power supply area, the power amplitude adjustment direction field causes the step size field to participate in offset correction along the direction of reducing local output power; if the global load gradient compensation vector expresses a downward trend in load within the target power supply area, the power amplitude adjustment direction field causes the step size field to participate in offset correction along the direction of restoring local output power. The adjustable amplitude range field, the adjustable amplitude field after limiting, and the step size field are all written back to the load adjustment step size carrying record, so that the source, limiting process, and degree of participation of the load adjustment step size can be pointed back to by the subsequent instruction code carrying record.
[0111] Preferably, the formation process of the execution time slice adjustment direction field is used to limit the specific time position of the load adjustment step size in the current control cycle. The instruction update module reads the time position aggregation component and the execution time slice field in the default output power preset configuration information; subsequently, the instruction update module matches the regional-level time change direction corresponding to the time position aggregation component with the execution time slice field to form an execution time slice matching record. The execution time slice matching record includes the current control cycle identifier, execution time slice position, time position aggregation component source identifier, time slice action status field, and target execution time slice identifier. The time slice action status field is used to indicate whether the corresponding execution time slice position participates in this offset correction, and the target execution time slice identifier is used to limit the execution time slice position for subsequent same-dimensional offset processing. After the execution time slice matching record is formed, the instruction update module writes the target execution time slice identifier into the load adjustment step size carrying record, so that the load adjustment step size does not indiscriminately correct all execution time slices in the current control cycle, but acts on the execution time slice position corresponding to the target execution time slice identifier according to the regional-level time change direction corresponding to the time position aggregation component.
[0112] Preferably, when performing offset correction on the control baseline of the default output power preset configuration information, the instruction update module first reads the execution time slice position, default output power position field, output boundary field, and change limit field from the control baseline, and reads the target execution time slice identifier, power amplitude adjustment direction field, charging stage action field, adjustment participation level field, and step size field from the load adjustment step size bearing record. Subsequently, the instruction update module performs correspondence processing between the execution time slice position and the target execution time slice identifier to determine the target execution time slice identifier in which the load adjustment step size acts within the current control cycle; then, it performs dimensional offset processing between the default output power position field and the step size field corresponding to the target execution time slice identifier to form the initial offset power field. After the initial offset power field is formed, the instruction update module performs boundary truncation processing on the initial offset power field based on the output boundary field to form the truncated power field; then, it performs change amplitude constraint processing on the truncated power field corresponding to the adjacent target execution time slice identifier based on the change limit field to form the corrected control baseline. The corrected control baseline retains the current control cycle identifier, local charging pile identifier, power output interface identifier, target execution time slice identifier, power field after boundary truncation, and change amplitude constraint processing results, so that subsequent instruction code generation can correspond to the execution cycle, execution object, and power correction results.
[0113] Preferably, the offset correction does not directly overwrite the global load gradient compensation vector with the local output power. Instead, it performs a restricted correction on the default output power preset configuration information within the output boundary field and change limit field defined by the control baseline. For the charging phase action field pointing to the target execution time slice identifier of the access climb segment, the instruction update module prioritizes reading the power change limit field to limit the output power climb amplitude corresponding to the target execution time slice identifier, and writes the limited step size field into the access climb segment offset record. For the charging phase action field pointing to the target execution time slice identifier of the stable output segment, the instruction update module prioritizes reading the default output power field and the adjustment participation level field to form the stable output segment offset record. For the charging phase action field pointing to the target execution time slice identifier of the access exit segment, the instruction update module prioritizes reading the power output lower limit field and the change limit field to form the access exit segment offset record. The access climb segment offset record, stable output segment offset record, and access exit segment offset record all include the current control cycle identifier, power output interface identifier, target execution time slice identifier, step size field, power field after boundary truncation, and change amplitude constraint processing result. The offset records of the access ramp segment, the offset records of the stable output segment, and the offset records of the access exit segment are all written back to the corrected control baseline, so that the corrected control baseline can form the corresponding local output power correction result according to the load change characteristics of different charging stages.
[0114] Preferably, after the corrected control baseline is formed, the instruction update module also performs pre-instruction verification processing on the corrected control baseline. This pre-instruction verification process reads the current control cycle identifier, local charging pile identifier, power output interface identifier, target execution time slice identifier, boundary-truncation power field, and change amplitude constraint processing result from the corrected control baseline. It also reads the instruction code format field and interface enable status field from the power output interface configuration record. After confirming that the interface enable status field is executable, the instruction update module performs field format matching processing between the boundary-truncation power field and the instruction code format field to form an instruction field matching record. The instruction field matching record includes the target execution time slice identifier, the boundary-truncation power field, the instruction code format field, the format matching status field, and the instruction generation permission field. The format matching status field indicates whether the boundary-truncation power field can be written to the instruction position defined by the instruction code format field, and the instruction generation permission field limits whether subsequent generation of instruction codes that have completed offset correction is allowed. After the instruction field matching record is formed, it continues to participate in the generation of the instruction code carrying record to avoid directly forming corrected local load scheduling instructions from power correction results that have not undergone format matching.
[0115] Preferably, after the corrected control baseline is formed and processed through pre-instruction verification, the instruction update module does not directly drive the power output interface to run. Instead, it first generates an instruction code carrier record based on the corrected control baseline and instruction field matching record. The instruction code carrier record includes the current control cycle identifier, local charging pile identifier, power output interface identifier, target execution time slice identifier, corrected control baseline, output boundary field, change limit field, power field after boundary truncation, change amplitude constraint processing result, instruction code format field, instruction enable field, and instruction source field. The instruction source field is used to refer back to the global compensation vector receiving record, default output power preset configuration information, load adjustment step size carrier record, execution time slice matching record, and corrected control baseline and instruction field matching record, so that the instruction code carrier record can retain the source relationship from the global load gradient compensation vector to the local instruction correction. Subsequently, the instruction update module performs instruction code field encapsulation processing on the instruction code carrier record to form the instruction code that completes the offset correction. The instruction code for completing offset correction includes the current control cycle identifier, local charging pile identifier, power output interface identifier, target execution time slice identifier, output power field corresponding to the corrected control baseline, output boundary field, change limit field, and instruction enable field. The instruction code for completing offset correction is identified as the corrected local load dispatch instruction.
[0116] Preferably, after the revised local load dispatching instruction is generated, the instruction update module writes the revised local load dispatching instruction into the local dispatching instruction cache record. The local dispatching instruction cache record includes the local charging pile identifier, the current control cycle identifier, the power output interface identifier, the revised local load dispatching instruction, the instruction activation field, the instruction issuance status field, the power output interface instruction cache location, and the power output interface feedback field. The instruction update module reads the local control cycle index record based on the current control cycle identifier. After confirming that the current control cycle is still within the executable time range, it sets the instruction issuance status field to the pending issuance state. Subsequently, the instruction update module writes the revised local load dispatching instruction into the power output interface instruction cache location based on the power output interface identifier and sets the instruction issuance status field to the issued state. The power output interface reads the revised local load dispatching instruction from the power output interface instruction cache location and adjusts the output status according to the target execution time slice identifier and the output power field corresponding to the revised control baseline. The power output interface feedback field is then written back to the local dispatching instruction cache record to indicate that the revised local load dispatching instruction has participated in the power output interface operation control.
[0117] Preferably, during the operation of the power output interface according to the modified local load dispatching command, the local charging pile continues to read the power output interface feedback field, the current control cycle identifier, the power output interface identifier, and the target execution time slice identifier to form a command execution feedback record. The command execution feedback record includes the current control cycle identifier, the local charging pile identifier, the power output interface identifier, the target execution time slice identifier, the modified local load dispatching command, the power output interface feedback field, the execution time slice feedback field, and the output power feedback field. The execution time slice feedback field indicates whether the power output interface reads the modified local load dispatching command according to the target execution time slice identifier, and the output power feedback field indicates whether the output state of the power output interface under the corresponding target execution time slice identifier falls within the range defined by the output boundary field. The command execution feedback record continues to establish a correspondence with the local dispatching command cache record, enabling the network monitor to establish a time correspondence between the real-time grid-connected current feedback parameters in the target power supply area and the local execution state of the modified local load dispatching command when acquiring real-time grid-connected current feedback parameters. Thus, a continuous data processing relationship is formed between the global load gradient compensation vector, the global compensation vector reception record, the compensation vector reception verification result, the wake-up interrupt signal, the instruction update session record, the default output power preset configuration information, the load adjustment step size, the control baseline, the corrected control baseline, the corrected local load scheduling instruction, and the power output interface.
[0118] Optionally, after controlling the power output interface of each local charging pile according to the modified local load dispatching command to make the concurrent charging load in the target power supply area converge within the preset power distribution safety node, the method further includes: activating the network monitor deployed at the power supply inlet, continuously acquiring the real-time grid-connected current feedback parameters generated by the target power supply area under the drive of the modified local load dispatching command; determining whether the real-time grid-connected current feedback parameters are within the preset safe operation reference zone; when it is detected that the real-time grid-connected current feedback parameters exceed the boundary of the safe operation reference zone, sending an abnormal dispatching warning signal to the cloud collaborative processing server to control the cloud collaborative processing server to extract the encrypted gradient vector of the next control cycle and restart the encrypted state aggregation operation.
[0119] Optionally, determining whether the real-time grid-connected current feedback parameter is within a preset safe operation reference zone includes: reading the dynamic capacity limit threshold issued by the external distribution network as the first verification boundary, and simultaneously reading the maintenance energy limit threshold of the local energy storage device deployed in the target distribution area as the second verification boundary; using the first verification boundary and the second verification boundary as the endpoints of the determination range, generating a safe operation reference zone within a closed interval; performing interval assignment determination on the real-time grid-connected current feedback parameter; when it is determined that the real-time grid-connected current feedback parameter falls within the closed interval defined by the first verification boundary and the second verification boundary, outputting a determination signal that conforms to the preset safe operation reference zone; when it is determined that the real-time grid-connected current feedback parameter does not fall within the closed interval, outputting a determination signal that exceeds the safe operation reference zone.
[0120] Preferably, after controlling the power output interfaces of each local charging pile according to the modified local load dispatching command, so that the concurrent charging load in the target power supply area converges within the preset power distribution safety node, the local charging pile first performs local feedback writing processing on the execution status of the modified local load dispatching command. The local feedback writing processing reads the current control cycle identifier, local charging pile identifier, power output interface identifier, target execution time slice identifier, modified local load dispatching command, command activation field, command issuance status field, power output interface feedback field, and output power feedback field, and writes these fields into the command execution feedback record. The power output interface feedback field is formed by the power output interface's read status, execution status, and output status of the modified local load dispatching command under the corresponding target execution time slice identifier; the output power feedback field is formed by encapsulating the power output interface's local output power sampling result, command code execution result, and output limiting result under the corresponding target execution time slice identifier. After the instruction execution feedback record is formed, the local charging pile sends the instruction execution feedback record to the network monitor deployed at the power supply inlet. This enables the network monitor to establish the regional execution feedback source within the current control cycle based on the instruction execution feedback records uploaded by each local charging pile, rather than solely relying on the status of the global load gradient compensation vector issued by the cloud collaborative processing server to determine whether the scheduling is effective.
[0121] Preferably, before sending the instruction execution feedback record to the network monitor, the local charging pile further performs feedback message encapsulation processing on the instruction execution feedback record. The feedback message encapsulation processing reads the current control cycle identifier, local charging pile identifier, power output interface identifier, target execution time slice identifier, power output interface feedback field, and output power feedback field from the instruction execution feedback record, and reads the network monitor receiving address field, feedback message sequence field, and feedback transmission status field from the local communication session record. The local charging pile writes the instruction execution feedback record, local communication session record, and feedback message sequence field into the instruction execution feedback message, enabling the instruction execution feedback message to be recognized as a local execution feedback message within the current control cycle on the network monitor receiving side. After the instruction execution feedback message is sent, the local charging pile sets the feedback transmission status field to the "sent" state and writes the feedback transmission status field back to the instruction execution feedback record, ensuring that the instruction execution feedback record has a transmission status source when the network monitor performs feedback source verification processing subsequently.
[0122] Preferably, before receiving and executing the feedback record, the network monitor first reads the power supply inlet monitoring configuration record. The power supply inlet monitoring configuration record is pre-configured when the network monitor is deployed at the power supply inlet and is refreshed before the start of each control cycle based on the power supply inlet status of the target power supply area. The power supply inlet monitoring configuration record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice field, grid-connected current sampling channel identifier, power supply inlet voltage field, real-time grid-connected current feedback parameter cache address, safe operation reference band configuration record identifier, network monitor enable status field, and monitoring data write status field. The power supply inlet voltage field is used to subsequently convert the dynamic capacity limit threshold and maintenance energy limit threshold to a current field consistent with the real-time grid-connected current feedback parameter. The safe operation reference band configuration record identifier is used to associate with the pre-formed safe operation reference band configuration record. The monitoring data write status field is used to mark whether the real-time grid-connected current feedback parameter has been written to the real-time grid-connected current feedback record. When the network monitor enable status field is enabled, the network monitor establishes a network monitor activation record based on the current control cycle identifier and the sampling time slice field. The network monitor activation record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice field, grid-connected current sampling channel identifier, power supply inlet voltage field, and monitoring activation status field. The network monitor activation record then serves as the direct basis for continuously acquiring real-time grid-connected current feedback parameters, establishing a source-to-source correspondence between the real-time grid-connected current feedback parameters and the current control cycle, power supply inlet, grid-connected current sampling channel, and power supply inlet voltage.
[0123] Preferably, the current control cycle identifier in the network monitor is not directly estimated from a single local time, but is jointly defined by the power supply inlet monitoring configuration record and the cloud control cycle synchronization record. The cloud control cycle synchronization record is sent to the network monitor synchronously by the cloud collaborative processing server when issuing the global load gradient compensation vector. The cloud control cycle synchronization record includes the target power supply area identifier, the current control cycle identifier, the current control cycle start time position, the current control cycle end time position, the next control cycle candidate identifier, and a synchronization write status field. After reading the cloud control cycle synchronization record, the network monitor performs a consistency check between the current control cycle identifier and the current control cycle identifier in the power supply inlet monitoring configuration record. After the consistency check passes, the network monitor writes the current control cycle start time position, the current control cycle end time position, and the sampling time slice field into the control cycle monitoring window record. The control cycle monitoring window record continues to participate in the formation of the network monitor activation record, ensuring that the network monitor only reads the power supply inlet current sampling value within the time range defined by the current control cycle start time position and the current control cycle end time position.
[0124] Preferably, the safe operation reference band configuration record is not generated temporarily during the interval attribution determination, but is pre-configured by the network monitor before the start of the current control cycle based on the power supply inlet constraint data, local energy storage device operation data, and sampling time slice field within the target power supply area. The safe operation reference band configuration record includes the target power supply area identifier, current control cycle identifier, power supply inlet identifier, sampling time slice field, dynamic capacity limit threshold field, sustaining energy limit threshold field, boundary unit caliber field, power supply inlet voltage caliber field, local energy storage device status field, safe operation reference band activation status field, and safe operation reference band cache address. The dynamic capacity limit threshold field carries the dynamic capacity limit threshold issued by the external distribution network; the sustaining energy limit threshold field carries the sustaining energy limit threshold formed by the local energy storage devices deployed within the target power supply area; the boundary unit caliber field records the unit source of the dynamic capacity limit threshold and sustaining energy limit threshold before they enter the boundary caliber conversion process; and the power supply inlet voltage caliber field converts the power caliber or energy caliber into a current caliber that can be compared with the power supply inlet current sampling value. After the safe operation reference band configuration record is formed, the network monitor writes the safe operation reference band configuration record identifier into the power supply inlet monitoring configuration record, so that the power supply inlet monitoring configuration record and the safe operation reference band configuration record maintain the same target power supply area, the same power supply inlet end, and the same sampling time slot source within the current control cycle.
[0125] Preferably, the dynamic capacity limit threshold is determined through dynamic capacity constraint reception processing. Before the start of the current control cycle, the network monitor reads the dynamic capacity constraint message sent by the external distribution network. The dynamic capacity constraint message includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, feeder capacity field, transformer capacity occupancy field, power supply inlet reserved capacity field, capacity issuance time and location, and capacity scope field. The network monitor first performs a consistency check between the target power supply area identifier, power supply inlet identifier, and current control cycle identifier in the dynamic capacity constraint message and the power supply inlet monitoring configuration record. After the consistency check passes, the network monitor reads the feeder capacity field, transformer capacity occupancy field, and power supply inlet reserved capacity field, and performs capacity boundary encapsulation processing on these fields to form a dynamic capacity threshold reception record. The dynamic capacity threshold reception record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, capacity scope field, dynamic capacity limit threshold, and dynamic capacity threshold reception status field. The dynamic capacity limit threshold is used to express the source of the regional grid-connected current that the power supply inlet can bear under the constraints of the external distribution network within the current control cycle. The dynamic capacity threshold receiving record is then written into the dynamic capacity limit threshold field in the safe operation reference band configuration record.
[0126] Preferably, the capacity boundary encapsulation process does not simply store the feeder capacity field, transformer capacity occupancy field, and power supply inlet reserved capacity field side-by-side. Instead, it first reads the feeder capacity field to form a candidate field for available capacity at the power supply inlet, then reads the transformer capacity occupancy field to form a capacity occupancy field for the current control cycle, and finally reads the power supply inlet reserved capacity field to form a capacity reserve field at the power supply inlet. The network monitor performs capacity availability boundary processing based on the candidate field for available capacity at the power supply inlet, the capacity occupancy field for the current control cycle, and the capacity reserve field at the power supply inlet to form a dynamic capacity limit threshold. After the dynamic capacity limit threshold is formed, the network monitor writes the dynamic capacity limit threshold, the capacity caliber field, and the capacity issuance time position together into the dynamic capacity threshold receiving record. Through the above processing, the dynamic capacity limit threshold has sources from feeder capacity, transformer capacity occupancy, and power supply inlet reserved capacity, and will not directly use a single field issued by the external distribution network as the subsequent first verification boundary.
[0127] Preferably, the maintenance energy limit threshold is determined through local energy storage status parsing. Before the start of the current control cycle, the network monitor reads the local energy storage device operation records sent by the local energy storage devices deployed in the target power supply area. The local energy storage device operation records include the target power supply area identifier, power supply inlet identifier, current control cycle identifier, local energy storage device status field, remaining energy field, minimum reserved energy field, allowed release power field, energy storage output enable status field, and energy storage data write time position. The network monitor first performs a consistency check between the target power supply area identifier, power supply inlet identifier, and current control cycle identifier in the local energy storage device operation records and the power supply inlet monitoring configuration record. After the consistency check passes, the network monitor reads the remaining energy field, minimum reserved energy field, allowed release power field, and energy storage output enable status field, and performs energy storage boundary encapsulation processing on the above fields to form a maintenance energy threshold generation record. The maintenance energy threshold generation record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, local energy storage device status field, maintenance energy limit threshold, and maintenance energy threshold generation status field. The maintenance energy limit threshold is used to express the lower boundary source that the local energy storage device needs to retain in order to maintain the stability of the power supply to the target power supply area during the current control cycle. The maintenance energy threshold generation record is then written into the maintenance energy limit threshold field in the safe operation baseline configuration record.
[0128] Preferably, the energy storage boundary encapsulation process first reads the remaining energy field and the minimum reserved energy field, and then performs energy storage available margin processing on the remaining energy field and the minimum reserved energy field to form the energy storage available margin field. Subsequently, the network monitor reads the allowed release power field and the energy storage output enable status field, and forms an energy storage compensation status field based on the energy storage available margin field, the allowed release power field, and the energy storage output enable status field. The energy storage compensation status field is used to indicate whether the local energy storage device can participate in maintaining the lower boundary of the grid-connected current at the power supply inlet during the current control cycle. The network monitor performs maintenance boundary encapsulation processing on the energy storage available margin field based on the energy storage compensation status field to form a maintenance energy limit threshold. After the maintenance energy limit threshold is formed, the network monitor writes the maintenance energy limit threshold, the energy storage data write time position, and the energy storage compensation status field together into the maintenance energy threshold generation record, so that the maintenance energy limit threshold can point back to the energy source and output status source in the local energy storage device operation record.
[0129] Preferably, the dynamic capacity limit threshold and sustaining energy limit threshold are not directly used as the first and second verification boundaries in the interval assignment determination. Instead, the network monitor first performs boundary conversion processing. The boundary conversion processing reads the dynamic capacity limit threshold field, sustaining energy limit threshold field, boundary unit diameter field, power supply inlet voltage diameter field, sampling time slice field, and power supply inlet identifier from the safe operation reference band configuration record, and writes these fields into the boundary conversion record. The boundary conversion record is used to carry the source field and conversion field before different boundary sources enter the same current diameter, avoiding direct comparison of capacity diameter, power diameter, or energy diameter with real-time grid-connected current feedback parameters. The network monitor performs the first verification boundary conversion processing and the second verification boundary conversion processing according to the boundary conversion record. The first verification boundary conversion processing forms the first verification boundary, and the second verification boundary conversion processing forms the second verification boundary. Both the first and second verification boundaries are written into the safe operation reference band carrying record so that subsequent safe operation reference bands are generated under the same current diameter.
[0130] Preferably, the first verification boundary conversion process specifically involves: the network monitor reading the dynamic capacity limit threshold, boundary unit diameter field, power supply inlet voltage diameter field, power supply inlet identifier, and sampling time slice field from the boundary diameter conversion record, and identifying the original unit diameter of the dynamic capacity limit threshold based on the boundary unit diameter field. When the dynamic capacity limit threshold is already in current diameter, the network monitor writes the dynamic capacity limit threshold into the first verification boundary candidate field; when the dynamic capacity limit threshold is in power diameter, the network monitor performs current diameter conversion processing on the dynamic capacity limit threshold based on the power supply inlet voltage diameter field to form the first verification boundary candidate field. The first verification boundary candidate field is bound to the sampling time slice field to form the first verification boundary. The first verification boundary is used to limit the upper boundary that the real-time grid-connected current feedback parameter should not cross within the current control cycle. After the first verification boundary is formed, the network monitor writes the first verification boundary, the dynamic capacity threshold receiving record identifier, and the boundary diameter conversion record identifier together into the safe operation reference band carrying record, so that the first verification boundary can point back to the source and conversion process of the dynamic capacity limit threshold.
[0131] Preferably, the current caliber conversion process in the first verification boundary conversion process converts the dynamic capacity limit threshold into current boundary data that can be compared with the current sampling values at the power supply inlet. Specifically, the network monitor reads the voltage caliber field at the power supply inlet to obtain the voltage reference caliber for power caliber conversion at the power supply inlet within the current control cycle; then it reads the capacity caliber field to identify whether the dynamic capacity limit threshold corresponds to the allowable power or allowable current at the power supply inlet; subsequently, the network monitor performs power-to-current conversion processing on the dynamic capacity limit threshold under the same sampling time slice based on the voltage caliber field and the capacity caliber field at the power supply inlet, to form the first verification boundary candidate field. After the first verification boundary candidate field is formed, the network monitor establishes a correspondence between the first verification boundary candidate field and the sampling time slice field, so that the first verification boundary has an upper boundary caliber that can be used for interval assignment determination in each sampling time slice.
[0132] Preferably, the second verification boundary conversion process specifically involves: the network monitor reading the sustaining energy limit threshold, boundary unit diameter field, power supply inlet voltage diameter field, power supply inlet identifier, and sampling time slice field from the boundary diameter conversion record, and reading the local energy storage device status field, allowed release power field, and energy storage output enable status field from the local energy storage device operation record. Based on the local energy storage device status field and energy storage output enable status field, the network monitor determines the energy storage compensation status of the local energy storage device within the current control cycle that can be used to maintain the power supply stability of the target power supply area, and converts the sustaining energy limit threshold into a sustaining power diameter field based on the energy storage compensation status. Subsequently, the network monitor performs current diameter conversion processing on the sustaining power diameter field based on the power supply inlet voltage diameter field to form the second verification boundary candidate field. The second verification boundary candidate field, after being bound by the sampling time slice field, forms the second verification boundary, which is used to limit the lower boundary that the real-time grid-connected current feedback parameter should not fall below within the current control cycle. After the second verification boundary is formed, the network monitor writes the second verification boundary, the maintenance energy threshold generation record identifier, and the boundary caliber conversion record identifier into the safe operation reference band carrying record, so that the second verification boundary can point back to the source and conversion process of the maintenance energy limit threshold.
[0133] Preferably, the current caliber conversion process in the second verification boundary conversion process converts the sustaining energy limit threshold from the energy retention caliber of the local energy storage device to the lower boundary caliber of the power supply inlet current. Specifically, the network monitor first reads the sampling time slice field to determine the duration range corresponding to each sampling time slice within the current control cycle; then it reads the energy storage compensation status field to determine the range within which the sustaining energy limit threshold can be converted into the sustaining power caliber field within the current control cycle; subsequently, the network monitor performs energy-to-power conversion processing on the sustaining energy limit threshold based on the sampling time slice field and the energy storage compensation status field to form the sustaining power caliber field. After the sustaining power caliber field is formed, the network monitor performs power-to-current conversion processing based on the power supply inlet voltage caliber field to form the second verification boundary candidate field. After the second verification boundary candidate field is formed, the network monitor establishes a correspondence between the second verification boundary candidate field and the sampling time slice field, so that the second verification boundary has a lower boundary caliber that can be used for interval assignment determination within each sampling time slice.
[0134] Preferably, when generating a safe operating reference band for a closed interval using the first and second verification boundaries as endpoints of the judgment range, the network monitor first reads the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice field, first verification boundary, second verification boundary, boundary unit diameter field, and power supply inlet voltage diameter field from the safe operating reference band carrying record, and performs boundary sequence verification processing on the first and second verification boundaries. Boundary sequence verification processing is used to confirm that the first verification boundary is higher than the second verification boundary, and to confirm that the first and second verification boundaries are within the same current diameter that can be compared with the current sampling value at the power supply inlet. If the boundary sequence verification processing passes, the network monitor uses the second verification boundary as the lower endpoint of the closed interval, the first verification boundary as the upper endpoint of the closed interval, and writes the lower endpoint of the closed interval, the upper endpoint of the closed interval, the sampling time slice field, and the current control cycle identifier into the safe operating reference band field encapsulation record. The secure operation baseline band field encapsulation record is formed after field encapsulation processing; if the boundary sequence verification process fails, the network monitor will write the secure operation baseline band bearer record into the boundary configuration anomaly record and stop using the secure operation baseline band bearer record in the interval attribution determination.
[0135] Preferably, the safe operation reference band field encapsulation record not only stores the endpoints of the closed interval, but also stores the interaction relationship between the endpoints of the closed interval and each sampling time slice. The safe operation reference band field encapsulation record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice field, lower endpoint of the closed interval, upper endpoint of the closed interval, first verification boundary source identifier, second verification boundary source identifier, boundary unit diameter field, power supply inlet voltage diameter field, and field encapsulation status field. The first verification boundary source identifier is used to refer back to the dynamic capacity threshold receiving record, the second verification boundary source identifier is used to refer back to the maintenance energy threshold generation record, and the field encapsulation status field is used to mark whether the lower endpoint and upper endpoint of the closed interval have completed field encapsulation under the same current diameter. After the field encapsulation status field is in the encapsulated state, the network monitor writes the safe operation reference band field encapsulation record to the safe operation reference band cache address to form the safe operation reference band.
[0136] Preferably, the technical essence of the safe operation reference band is interval-type judgment data used to constrain the grid-connected current feedback status of the target power supply area within the current control cycle. The safe operation reference band includes a target power supply area identifier, a power supply inlet identifier, a current control cycle identifier, a sampling time slice field, a first verification boundary, a second verification boundary, a boundary unit diameter field, a power supply inlet voltage diameter field, a safe operation reference band enable status field, a dynamic capacity threshold receiving record identifier, a sustaining energy threshold generation record identifier, and a boundary diameter conversion record identifier. After the network monitor writes the safe operation reference band to the safe operation reference band cache address, it sets the safe operation reference band enable status field to a determineable state. The safe operation reference band then participates in the interval assignment determination of the real-time grid-connected current feedback parameters, ensuring that the determination process is based on the same target power supply area, the same power supply inlet, the same current control cycle, the same sampling time slice, and the same current diameter, rather than directly comparing the original dimensions of the dynamic capacity limit threshold or sustaining energy limit threshold with the real-time grid-connected current feedback parameters.
[0137] Preferably, when the network monitor continuously acquires the real-time grid-connected current feedback parameters generated by the target power supply area under the modified local load dispatch command, the network monitor first reads the grid-connected current sampling channel identifier according to the network monitor activation record, and then reads the power supply inlet current sampling value from the sampling channel corresponding to the grid-connected current sampling channel identifier according to the sampling time slice field. The network monitor writes the power supply inlet current sampling value into the grid-connected current sampling record, which includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, grid-connected current sampling channel identifier, power supply inlet current sampling value, sampling write status field, and sampling validity field. The sampling validity field is used to mark whether the power supply inlet current sampling value comes from a grid-connected current sampling channel identifier that is in a sampleable state within the current control cycle. If the sampling validity field is invalid, the network monitor will write the grid-connected current sampling record into the sampling anomaly bearer record and stop using the grid-connected current sampling record to participate in the formation of real-time grid-connected current feedback parameters; if the sampling validity field is valid, the network monitor will continue to read the instruction execution feedback record within the same current control cycle so as to perform time-slice correspondence processing between the power supply inlet current sampling value and the local execution status of the corrected local load dispatch instruction.
[0138] Preferably, after reading the instruction execution feedback records within the same current control cycle, the network monitor first performs feedback source verification processing on the instruction execution feedback records. The feedback source verification processing reads the current control cycle identifier, local charging pile identifier, power output interface identifier, target execution time slice identifier, power output interface feedback field, and output power feedback field from the instruction execution feedback records. It then matches the current control cycle identifier with the current control cycle identifier in the grid-connected current sampling record, and matches the target execution time slice identifier with the sampling time slice identifier in the grid-connected current sampling record to form a time slice correspondence. After establishing the time slice correspondence, the network monitor writes the power supply inlet current sampling value, instruction execution feedback record, target execution time slice identifier, and sampling time slice identifier together into the grid-connected current feedback source record. The grid-connected current feedback source record indicates that the power supply inlet current sampling value within a certain sampling time slice is a regional-level feedback result formed at the power supply inlet after multiple local charging piles execute the corrected local load scheduling instructions. Based on the grid-connected current feedback source record, the network monitor performs the same time slice encapsulation processing on the power supply inlet current sampling value to form real-time grid-connected current feedback parameters.
[0139] Preferably, after the grid-connected current feedback source record is formed, the network monitor also performs feedback integrity verification processing on multiple instruction execution feedback records within the same sampling time slice. The feedback integrity verification process reads the target power supply area identifier and the current control cycle identifier from the power supply inlet monitoring configuration record, and reads the registered local charging pile identifier and the corresponding power output interface identifier from the local charging pile registration record. Subsequently, the network monitor performs corresponding processing on the local charging pile identifiers that have uploaded instruction execution feedback records within the same sampling time slice, matching them with the registered local charging pile identifiers in the local charging pile registration record to form a feedback coverage status field. The feedback coverage status field indicates which local charging piles have provided execution feedback for the corrected local load dispatching instruction within the sampling time slice corresponding to the real-time grid-connected current feedback parameter, and which local charging piles have not yet provided execution feedback. The feedback coverage status field is written into the grid-connected current feedback source record, enabling subsequent interval attribution determination to distinguish between the regional-level current feedback data at the power supply inlet end and the local charging pile feedback coverage status at the record level.
[0140] Preferably, the technical essence of the real-time grid-connected current feedback parameter is the regional-level current feedback data formed at the power supply inlet after multiple local charging piles operate according to the modified local load dispatching instructions within the current control cycle of the target power supply area. The real-time grid-connected current feedback parameter includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, power supply inlet current sample value, grid-connected current sampling channel identifier, power supply inlet voltage field, and grid-connected current feedback source record identifier. The real-time grid-connected current feedback parameter is not the single-pile output power of any local charging pile, nor is it a repeated field of the global load gradient compensation vector; rather, it reflects the regional-level grid-connected status of the target power supply area after the execution of the modified local load dispatching instructions. The network monitor writes the real-time grid-connected current feedback parameter into the real-time grid-connected current feedback record, which includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, real-time grid-connected current feedback parameter, safe operation reference band configuration record identifier, safe operation reference band identifier, and feedback parameter write status field. The real-time grid-connected current feedback record is then correlated with the safe operation reference band to determine whether the real-time grid-connected current feedback parameter is within the safe operation reference band.
[0141] Preferably, when performing interval assignment determination on the real-time grid-connected current feedback parameters, the network monitor first reads the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, real-time grid-connected current feedback parameters, and power supply inlet current sampling value from the real-time grid-connected current feedback record. It then reads the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice field, first verification boundary, second verification boundary, boundary unit caliber field, power supply inlet voltage caliber field, and safe operation reference band activation status field from the safe operation reference band. The network monitor first performs consistency verification on the target power supply area identifier, power supply inlet identifier, and current control cycle identifier, then performs time slice consistency verification on the sampling time slice identifier and sampling time slice field, and confirms that the safe operation reference band activation status field is in a determineable state. After the above verification, the network monitor performs interval assignment determination on the power supply inlet current sampling value against the first and second verification boundaries using the same caliber. If the current sampling value at the power supply inlet is not lower than the second verification boundary and not higher than the first verification boundary, the network monitor determines that the real-time grid-connected current feedback parameter falls within the closed interval defined by the first and second verification boundaries, and outputs a judgment signal that conforms to the safe operation reference band; if the current sampling value at the power supply inlet exceeds the first verification boundary or is lower than the second verification boundary, the network monitor determines that the real-time grid-connected current feedback parameter does not fall within the closed interval defined by the first and second verification boundaries, and outputs a judgment signal that exceeds the safe operation reference band.
[0142] Preferably, the same-caliber interval attribution determination further includes an object locking process. The object locking process reads the power supply inlet current sampling value from the real-time grid-connected current feedback parameters and writes it into the interval attribution determination record. The network monitor then reads the first and second verification boundaries from the safe operation reference band and writes them into the same interval attribution determination record. The interval attribution determination record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, power supply inlet current sampling value, first verification boundary, second verification boundary, boundary unit caliber field, and interval attribution determination status field. The network monitor first performs lower endpoint attribution determination on the power supply inlet current sampling value and the second verification boundary to form a lower endpoint attribution field; then it performs upper endpoint attribution determination on the power supply inlet current sampling value and the first verification boundary to form an upper endpoint attribution field. The lower endpoint attribution field and the upper endpoint attribution field are jointly written into the interval attribution determination record, and the interval attribution determination record triggers a determination signal that conforms to the safe operation reference band or a determination signal that exceeds the safe operation reference band.
[0143] Preferably, the judgment signal conforming to the safe operation reference band is not a standalone prompt data, but is written into the judgment record within the reference band and continues to establish a correspondence with the real-time grid-connected current feedback record. The judgment record within the reference band includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, real-time grid-connected current feedback parameter, first verification boundary, second verification boundary, judgment signal conforming to the safe operation reference band, real-time grid-connected current feedback record identifier, and safe operation reference band identifier. The judgment signal conforming to the safe operation reference band is used to indicate that the real-time grid-connected current feedback parameter in the current sampling time slice is within the safe operation reference band. After the judgment record within the reference band is formed, the network monitor establishes a correspondence between the judgment record within the reference band and the instruction execution feedback record, so that the area-level current feedback status of the target power supply area in the current control cycle can refer back to the local execution status of each local charging pile. The judgment record within the reference band does not trigger abnormal scheduling warning signaling, but serves as the feedback basis for continuing to execute the corrected local load scheduling instruction in the current control cycle.
[0144] Preferably, the judgment signal for exceeding the safe operation reference band is written into the reference band boundary exceedance judgment record and continues to serve as the triggering basis for abnormal scheduling warning signaling. The reference band boundary exceedance judgment record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, real-time grid-connected current feedback parameter, first verification boundary, second verification boundary, exceedance direction field, exceedance judgment signal for exceeding the safe operation reference band, real-time grid-connected current feedback record identifier, and safe operation reference band identifier. The exceedance direction field is used to distinguish whether the current sampling value at the power supply inlet exceeds the first verification boundary or is lower than the second verification boundary. The exceedance judgment signal for exceeding the safe operation reference band is used to indicate that the real-time grid-connected current feedback parameter in the current sampling time slice has exceeded the safe operation reference band. After the reference band boundary exceedance judgment record is formed, the network monitor establishes a correspondence between the reference band boundary exceedance judgment record, the real-time grid-connected current feedback record, and the safe operation reference band, so that a continuous data processing relationship is formed between the judgment source, the judgment object, and the judgment result.
[0145] Preferably, after the reference band boundary crossing determination record is formed, the network monitor does not directly change the operating state of the power output interface of any local charging pile. Instead, it first performs boundary crossing cause field encapsulation processing. This process reads the power supply inlet current sampling value, first verification boundary, second verification boundary, boundary crossing direction field, sampling time slice identifier, and current control cycle identifier from the reference band boundary crossing determination record. It also reads the corrected local load scheduling instruction, target execution time slice identifier, power output interface feedback field, and output power feedback field from the instruction execution feedback record. Subsequently, the network monitor performs mapping processing between the sampling time slice identifier and the target execution time slice identifier to form a boundary crossing time slice correspondence record. This record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, target execution time slice identifier, local charging pile identifier, power output interface identifier, corrected local load scheduling instruction, power output interface feedback field, output power feedback field, and boundary crossing direction field. The out-of-bounds time slice corresponding record is used to indicate which target execution time slice's corrected local load dispatching instructions have participated in the power output interface operation control when the real-time grid-connected current feedback parameter exceeds the safe operation reference band. The network monitor generates an abnormal dispatching warning bearer record based on the out-of-bounds time slice corresponding record, and the abnormal dispatching warning bearer record continues to serve as the encapsulation basis for abnormal dispatching warning signaling.
[0146] Preferably, the abnormal scheduling warning bearer record includes the target power supply area identifier, power supply inlet identifier, current control cycle identifier, sampling time slice identifier, real-time grid-connected current feedback parameter, first verification boundary, second verification boundary, out-of-bounds direction field, reference band out-of-bounds judgment record identifier, out-of-bounds time slice corresponding record identifier, abnormal scheduling warning signaling generation status field, and next control cycle trigger identifier. The abnormal scheduling warning signaling generation status field is used to mark whether the abnormal scheduling warning bearer record has completed signaling encapsulation, and the next control cycle trigger identifier is used to instruct the cloud collaborative processing server to extract a new encrypted gradient vector and restart the encrypted state aggregation operation in the next control cycle. After the abnormal scheduling warning bearer record is formed, the network monitor performs signaling field encapsulation processing on the abnormal scheduling warning bearer record to form an abnormal scheduling warning signaling. The technical essence of the abnormal scheduling warning signaling is to notify the cloud collaborative processing server that the regional-level grid-connected current feedback status of the current control cycle has deviated from the safe operation reference band, which is the scheduling restart trigger data.
[0147] Preferably, the abnormal scheduling warning signaling includes a target power supply area identifier, a power supply entry point identifier, a current control cycle identifier, a sampling time slice identifier, a real-time grid-connected current feedback parameter, a first verification boundary, a second verification boundary, an out-of-bounds direction field, a reference band out-of-bounds judgment record identifier, an out-of-bounds time slice corresponding record identifier, and a next control cycle trigger identifier. The abnormal scheduling warning signaling does not carry plaintext fields of any local charging pile's initial power consumption characteristic data, local power consumption preference representation parameters, or gradient update vectors. Instead, it carries the regional-level feedback judgment result formed at the power supply entry point, enabling the cloud-based collaborative processing server to reorganize the encrypted aggregation operation for the next control cycle based on the regional-level grid-connected status. The out-of-bounds direction field also allows the cloud-based collaborative processing server to distinguish whether the real-time grid-connected current feedback parameter crosses the first verification boundary or falls below the second verification boundary, thus preserving the regional-level feedback direction during the global load gradient compensation vector generation process in the next control cycle. The regional-level feedback direction does not contain the plaintext underlying sampling content of a single charging pile but is used to limit the feedback trigger source when restarting the encrypted aggregation operation in the next control cycle.
[0148] Preferably, when sending an abnormal scheduling warning signal to the cloud-based collaborative processing server, the network monitor first reads the abnormal scheduling warning signal transmission configuration record. This record includes the target power supply area identifier, power supply inlet identifier, cloud-based collaborative processing server connection identifier, current control cycle identifier, abnormal scheduling warning signal cache address, transmission status field, restart trigger field, and transmission confirmation status field. The network monitor writes the abnormal scheduling warning signal to the abnormal scheduling warning signal cache address and sets the transmission status field to "pending transmission." Subsequently, the network monitor sends the abnormal scheduling warning signal to the cloud-based collaborative processing server based on the connection identifier, and sets the transmission status field to "transmitted" after transmission. Upon receiving the abnormal scheduling warning signal, the cloud-based collaborative processing server sends back the abnormal scheduling warning signal reception status field to the network monitor. After reading the reception status field, the network monitor sets the transmission confirmation status field to "confirmed" and establishes a correspondence between the abnormal scheduling warning signal, the reference band out-of-bounds judgment record, and the abnormal scheduling warning signal transmission configuration record. The above-described sending process enables the abnormal scheduling warning signaling to receive the regional-level feedback judgment result from the power supply input end, which continues to be transmitted as the basis for the next control cycle aggregation and restart on the cloud collaborative processing server side.
[0149] Preferably, after receiving an abnormal scheduling warning signal, the cloud-based collaborative processing server first performs a restart trigger verification process on the abnormal scheduling warning signal. The restart trigger verification process reads the target power supply area identifier, power supply entry point identifier, current control cycle identifier, out-of-bounds direction field, reference band out-of-bounds judgment record identifier, and next control cycle trigger identifier from the abnormal scheduling warning signal. It then matches the target power supply area identifier with the target power supply area scheduling record stored in the cloud-based collaborative processing server, and matches the current control cycle identifier with the control cycle identifier corresponding to the completed encrypted state aggregation operation. After successful matching, the cloud-based collaborative processing server reads the cloud control cycle index record. The cloud control cycle index record includes the target power supply area identifier, control cycle identifier, control cycle start time position, control cycle end time position, key version field, local charging pile identifier to be received, and control cycle aggregation status field. Based on the current control cycle identifier, the cloud-based collaborative processing server searches for the adjacent subsequent control cycle on the timeline in the cloud control cycle index record, and confirms the subsequent control cycle whose control cycle start time position is later than the current control cycle's end time position and whose control cycle aggregation status field is in the pending aggregation state as the next control cycle. After the next control cycle is confirmed, the cloud-based collaborative processing server writes the next control cycle trigger identifier and the next control cycle identifier into the next control cycle aggregated restart record.
[0150] Preferably, the next control cycle aggregation restart record includes a target power supply area identifier, a power supply entry point identifier, a current control cycle identifier, a next control cycle identifier, an out-of-bounds direction field, a reference band out-of-bounds judgment record identifier, a local charging pile identifier to be received, a key version field, and a encrypted aggregation operation restart status field. The next control cycle identifier is derived from the subsequent control cycle adjacent to the current control cycle in the cloud control cycle index record, rather than being arbitrarily specified by the cloud collaborative processing server; the local charging pile identifier to be received is derived from the charging pile registration relationship corresponding to the next control cycle identifier in the cloud control cycle index record; and the key version field is derived from the key usage caliber corresponding to the next control cycle identifier. The next control cycle aggregation restart record is used to limit the cloud collaborative processing server to re-extract a new encrypted gradient vector in the next control cycle, rather than repeatedly using an encrypted gradient vector that has already completed encrypted aggregation operations within the current control cycle. The out-of-bounds direction field continues to be written into the next control cycle aggregation restart record, enabling the cloud collaborative processing server to retain the regional-level direction source of this out-of-bounds feedback during the encrypted aggregation operation triggering process in the next control cycle.
[0151] Preferably, when the cloud-based collaborative processing server extracts the encrypted gradient vector for the next control cycle based on the next control cycle aggregation restart record, it first reads the next control cycle identifier, the target power supply area identifier, the identifier of the local charging pile to be received, the key version field, and the encrypted aggregation operation restart status field, and generates the next control cycle encrypted input waiting record accordingly. The next control cycle encrypted input waiting record includes the target power supply area identifier, the next control cycle identifier, the identifier of the local charging pile to be received, the key version field, the encrypted gradient vector reception status field, the encrypted gradient vector reception quantity field, and the encrypted aggregation operation restart status field. After each local charging pile forms a new encrypted gradient vector in the next control cycle, it sends the new encrypted gradient vector to the cloud-based collaborative processing server. The cloud-based collaborative processing server performs reception cataloging processing on the new encrypted gradient vector based on the next control cycle encrypted input waiting record, and restarts the encrypted aggregation operation after the encrypted gradient vector reception status field and the encrypted gradient vector reception quantity field meet the current aggregation triggering conditions. Therefore, the abnormal scheduling warning signal will not cause the cloud-based collaborative processing server to generate a temporary plaintext scheduling result, but will instead transform the out-of-bounds feedback into the basis for restarting the encrypted aggregation operation in the next control cycle.
[0152] Preferably, after restarting the encrypted aggregation operation, the cloud-based collaborative processing server establishes a correspondence between the next control cycle aggregation restart record and the new encrypted aggregation vector result. After generating a new global load gradient compensation vector, it distributes the new global load gradient compensation vector to each local charging pile. Each local charging pile continues to correct its local load scheduling instructions based on the new global load gradient compensation vector. The network monitor continues to obtain new real-time grid-connected current feedback parameters based on the new corrected local load scheduling instructions and performs interval assignment determination between the new real-time grid-connected current feedback parameters and the new safe operation reference band. Through the above processing, a continuous data processing relationship is formed between the instruction execution feedback record, instruction execution feedback message, power supply inlet monitoring configuration record, cloud control cycle synchronization record, dynamic capacity threshold reception record, maintenance energy threshold generation record, boundary caliber conversion record, safe operation reference band, grid-connected current feedback source record, real-time grid-connected current feedback parameter, interval affiliation determination record, reference band boundary crossing determination record, abnormal scheduling warning signaling, next control cycle aggregation restart record, and the encrypted gradient vector of the next control cycle. This enables the target power supply area to adjust the encrypted state aggregation operation of the next control cycle based on the regional feedback status at the power supply inlet end without uploading the plaintext bottom-level sampling content of a single pile.
Claims
1. A method for collaborative scheduling and privacy governance of charging pile groups based on secure multi-party computation, characterized in that, The method includes the following processing steps: Acquire initial electricity consumption characteristic data of multiple local charging piles located within the target power supply area, and extract local electricity consumption preference characterization parameters from the initial electricity consumption characteristic data; Determine the gradient update vector of the local electricity consumption preference representation parameter in the current control cycle, and perform a ciphertext transformation operation on the gradient update vector to generate an encrypted gradient vector that hides the dimension of the initial electricity consumption feature data. The encrypted gradient vectors generated by each of the local charging piles are sent to the cloud collaborative processing server. Inside the cloud collaborative processing server, a secure multi-party computation protocol is triggered to perform ciphertext state aggregation operation on all the received encrypted gradient vectors to generate a global load gradient compensation vector for the target power supply area. The global load gradient compensation vector is sent to each of the local charging piles to instruct each local charging pile to parse the global load gradient compensation vector and then correct its local load scheduling command, so as to control the power output interface of each local charging pile and make the concurrent charging load in the target power supply area converge within the preset power distribution safety node.
2. The method according to claim 1, characterized in that, The process of acquiring initial electricity consumption characteristic data of multiple local charging piles located within the target power supply area, and extracting local electricity consumption preference characteristics from the initial electricity consumption characteristic data, includes: Collect the port voltage sampling sequence and corresponding access time stamp of each local charging pile in the historical control period, and generate the initial power consumption characteristic data based on the port voltage sampling sequence and access time stamp; A time-domain smoothing track is constructed within the configured adaptive filtering node, and the initial electricity consumption characteristic data is pushed into the time-domain smoothing track to perform abrupt interference signal removal operation; The wake-up feature parsing unit scans the initial power consumption feature data after removing abrupt interference signals, locates the stationary point coordinates representing the user's charging behavior pattern, and performs formatted reconstruction based on the acquired multiple stationary point coordinates to generate the local power consumption preference representation parameters.
3. The method according to claim 2, characterized in that, The wake-up feature parsing unit scans the initial power consumption feature data after removing abrupt interference signals, locates the stationary point coordinates representing the user's charging behavior pattern, and formats and reconstructs the acquired multiple stationary point coordinates to generate the local power consumption preference representation parameters, including: The feature parsing unit reads the envelope change data of the initial power consumption feature data after removing abrupt interference signals in the time domain coordinate system, and extracts the periodic peak nodes and periodic trough nodes in the envelope change data. The stationary point coordinates are determined based on the physical timestamps mapped from the periodic peak nodes and the periodic trough nodes, as well as the corresponding instantaneous absolute power values. Extract the associated weight feature code of each of the stationary point coordinates, and perform multidimensional tensor transformation on all the stationary point coordinates according to the associated weight feature code to generate the local electricity preference representation parameter stored in tensor format.
4. The method according to claim 1, characterized in that, The step of determining the gradient update vector of the local electricity consumption preference representation parameter in the current control cycle, and performing a ciphertext transformation operation on the gradient update vector to generate an encrypted gradient vector that hides the dimension of the initial electricity consumption feature data, includes: Read the historical electricity consumption preference representation parameters of the previous control cycle from the cache space, call the comparator to identify the feature differences between the local electricity consumption preference representation parameters and the historical electricity consumption preference representation parameters, and output the gradient update vector representing the evolution direction of the data. Extract the encrypted public key string configured for the corresponding local charging pile from the preset security key library, load the encrypted public key string into the key register of the homomorphic encryption engine, so that the homomorphic encryption engine performs a polynomial obfuscation operation on the gradient update vector according to the encrypted public key string, and generates the encrypted gradient vector with a ciphertext state distribution.
5. The method according to claim 1, characterized in that, The step involves triggering a secure multi-party computation protocol within the cloud-based collaborative processing server to perform ciphertext-state aggregation operations on all received encrypted gradient vectors, generating a global load gradient compensation vector for the target power supply area, including: Multiple virtual computing sandboxes, which are hardware isolated from each other, are defined in the memory space of the cloud-based collaborative processing server, and the received multiple encrypted gradient vectors are routed and assigned to different virtual computing sandboxes respectively. According to the interaction rules of the secure multi-party computation protocol, a ciphertext communication link is established between different virtual computing sandboxes, and cross-sandbox joint operation instructions are executed through the ciphertext communication link while maintaining the ciphertext state of the encrypted gradient vector. The encrypted aggregation vector result of the joint operation instruction is captured, and the encrypted aggregation vector result is de-obfuscated and parsed using a pre-configured decryption private key string in the trusted execution environment of the cloud collaborative processing server to generate the global load gradient compensation vector.
6. A charging pile group collaborative scheduling and privacy governance device based on secure multi-party computation, characterized in that, The device includes: The feature extraction module is configured to acquire initial electricity consumption feature data of multiple local charging piles located within the target power supply area, and extract local electricity consumption preference representation parameters from the initial electricity consumption feature data. The ciphertext conversion module is configured to determine the gradient update vector of the local electricity consumption preference representation parameter in the current control cycle, and perform a ciphertext conversion operation on the gradient update vector to generate an encrypted gradient vector that hides the dimension of the initial electricity consumption feature data. The cloud aggregation computing module is configured to send the encrypted gradient vectors generated by each of the local charging piles to the cloud collaborative processing server, and trigger a secure multi-party computation protocol within the cloud collaborative processing server to perform ciphertext-state aggregation operations on all the received encrypted gradient vectors to generate a global load gradient compensation vector for the target power supply area. The scheduling instruction correction module is configured to send the global load gradient compensation vector to each of the local charging piles, so as to instruct each of the local charging piles to parse the global load gradient compensation vector and correct their respective local load scheduling instructions, so as to control the power output interface of each of the local charging piles and make the concurrent charging load in the target power supply area converge within the preset power distribution safety node.
7. An electronic device, characterized in that, The electronic device includes a microprocessor and a cache memory. Machine-executable instruction code is written into the cache memory. The microprocessor is configured to read and execute the machine-executable instruction code through hardware addressing, so that the electronic device controls and executes the operation steps of the charging pile group collaborative scheduling and privacy governance method based on secure multi-party computation as described in any one of claims 1 to 9.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium contains physical program logic instructions. When these instructions are loaded and run by the underlying hardware processor, they force the processor to execute the operation steps of the charging pile group collaborative scheduling and privacy governance method as described in any one of claims 1 to 5.
9. A charging pile, characterized in that, The charging pile is deployed as an independent hardware endpoint within the target power supply area. The charging pile includes a data acquisition probe, a power output interface, an encrypted communication bus, and an embedded local microcontroller. The local microcontroller establishes electrical connections with the data acquisition probe, the power output interface, and the encrypted communication bus, respectively. The local microcontroller is configured to: acquire initial power consumption characteristic data through the data acquisition probe; extract local power consumption preference representation parameters from the initial power consumption characteristic data; determine the gradient update vector of the local power consumption preference representation parameters in the current control cycle; perform a polynomial obfuscation operation on the gradient update vector to generate an encrypted gradient vector; drive the encrypted communication bus to send the encrypted gradient vector to the cloud collaborative processing server; receive the global load gradient compensation vector issued by the cloud collaborative processing server via the encrypted communication bus; parse the global load gradient compensation vector in local memory to overwrite and refresh the local load scheduling instruction; and output a hardware-level drive level to the power output interface according to the refreshed local load scheduling instruction.
10. A charging pile group collaborative scheduling and privacy governance system based on secure multi-party computation, characterized in that, The system is constructed by physically isolated cloud collaborative processing servers and multiple charging piles as described in claim 9, distributed within the target power supply area. The cloud-based collaborative processing server maintains a secure connection link with the encrypted communication bus of each of the charging piles. The cloud-based collaborative processing server is equipped with a trusted execution environment and is configured to: receive the encrypted gradient vectors sent by each of the charging piles; invoke a secure multi-party computation protocol within the trusted execution environment to perform ciphertext aggregation operations on all the encrypted gradient vectors in a non-decrypted state; and parse and output the global load gradient compensation vector. The global load gradient compensation vector is then distributed to each of the charging piles through the secure connection link to support each charging pile in correcting its local load scheduling instructions and controlling the corresponding power output interface at the hardware level, thereby establishing a hard threshold suppression convergence for the concurrent charging load within the target power supply area.