Network security monitoring and control method and system for distributed acquisition device
By using digital twin technology and multi-source parameter analysis, combined with baseline deviation dynamic assessment and mutation characteristic calculation, the problem of the correlation between health status assessment and network security risk determination in distributed acquisition devices was solved, realizing collaborative monitoring and control in distributed energy storage scenarios and improving the system's monitoring accuracy and self-recovery capability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- JIANGSU SIJI TECH SERVICE CO LTD
- Filing Date
- 2026-06-18
- Publication Date
- 2026-07-21
AI Technical Summary
In existing technologies, distributed acquisition devices lack a connection between health status assessment and network security risk determination in terms of monitoring and control, cannot dynamically adjust protection strength, have limited anomaly tracing capabilities, and are difficult to adapt to the needs of large differences in the operating status of each unit in distributed energy storage scenarios.
By employing digital twin technology combined with multi-source parameter analysis, the physical state parameters, electrical parameters, and network data of the energy storage unit are acquired through the acquisition terminal. Data transmission is carried out using encryption algorithms. Based on the degree of deviation from the baseline and the characteristics of sudden changes, the types of anomalies are distinguished and the potential hazards are classified. The acquisition frequency and operating power are dynamically adjusted.
It enables coordinated monitoring and control of the health status of energy storage units and network security, improves the accuracy and response speed of the monitoring system, can accurately distinguish the root causes of anomalies, and enhances the system's self-recovery capability when facing mixed threats.
Smart Images

Figure CN122437249A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of distributed power station network security monitoring technology, and more specifically, relates to a network security monitoring and control method and system for distributed acquisition devices. Background Technology
[0002] With the rapid development of distributed energy systems, the large-scale application of energy storage devices is becoming increasingly widespread, and the deployment of various distributed data acquisition devices is becoming more and more dispersed. During their operation, these devices need to handle a large amount of data transmission and status monitoring in real time. To ensure the stable operation of distributed data acquisition devices, achieve full-process security management of energy storage units, and meet the core needs of data acquisition, status monitoring, and risk prevention in distributed scenarios, a network security monitoring and control system for distributed data acquisition devices is constructed.
[0003] Existing technology, such as the invention application patent with announcement number CN112987604B, discloses a network security monitoring and real-time alarm method and system for power generation equipment, including a power generation equipment control system and a detection and alarm system; the power generation equipment control system includes a power generation equipment controller and several engineering stations and operator stations connected to the power generation equipment controller; the detection and alarm system includes a network security microprocessor unit and an alarm microprocessor unit that communicate via dual-port RAM; the dual-port RAM has two completely independent sets of data lines, address lines and read / write control lines on a single SRAM memory, allowing two independent systems to simultaneously perform random access to the memory.
[0004] The aforementioned technologies have at least the following technical problems: In existing technologies, distributed acquisition devices often only monitor network data or the physical parameters of energy storage units from a single dimension, failing to correlate the health status assessment results of energy storage units with network security risk judgment and protection strategy generation. This results in a lack of specificity in security strategies, an inability to dynamically adjust the protection intensity based on the differentiated health status and operating conditions of energy storage units, difficulty in achieving coordinated management and control of network security protection and the operational safety of the energy storage units themselves, and an inability to fully adapt to the actual needs of large differences in the operating status of each unit in distributed energy storage scenarios.
[0005] Existing systems have significant limitations in their anomaly tracing capabilities, with most only able to trace a single trajectory. Most systems can only trace a single dimension of network attack or physical fault trajectory, making it difficult to cross-verify physical, network, and battery mechanism trajectories. This makes it impossible to accurately distinguish whether an anomaly is induced by a network attack or caused by aging or physical faults of the energy storage unit itself, thus hindering the precise identification of the anomaly's root cause, triggering point, and spread range. Summary of the Invention
[0006] To address the shortcomings of existing technologies, this invention provides a network security monitoring and control method and system for distributed data acquisition devices.
[0007] The present invention adopts the following technical solution.
[0008] The first aspect of this invention proposes a network security monitoring and control method for distributed data acquisition devices, comprising: The data acquisition terminal is used to collect the physical state parameters, electrical parameters and network data of each energy storage unit in the distributed energy storage power station. Based on the SOH, energy storage battery voltage and battery aging degree included in the electrical parameters and the set corresponding threshold, the health status is initially determined to be healthy, sub-healthy or abnormal. For energy storage units whose initial health status is determined to be sub-healthy or abnormal, a final abnormality judgment is made. For physical state parameters and electrical parameters, the degree of deviation between the real-time acquired value of each corresponding parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit is used as the deviation from the baseline of the corresponding parameter. Combined with the deviation from the baseline and the corresponding volatility, the mutation characteristics are calculated. If the mutation characteristics of any physical state parameter or electrical parameter exceed the set mutation threshold, the health status is finally judged to be abnormal. Based on network data, determine whether network attack characteristics have appeared, and distinguish the types of anomalies according to the presence and correspondence of mutation characteristics exceeding the set mutation threshold and network attack characteristics. The types of anomalies include anomalies caused by network attacks or anomalies caused by precursors of physical failures. The potential hazards are classified according to the degree of parameter deviation from the baseline and the number of abnormal energy storage units. The acquisition frequency of the acquisition terminal and the operating power of the energy storage units are adjusted in combination with the type of anomaly and the hazard classification.
[0009] Preferably, the physical state parameters, electrical parameters, and network data are as follows: Physical state parameters include: battery casing temperature, internal pressure, and electrolyte concentration; Electrical parameters include: energy storage battery voltage, current, SOC value, SOH value, charge / discharge status, battery aging level, and fault codes; Network data includes: communication data packets, handshake information, access requests, and link status; The acquisition terminal uses an encryption algorithm to encrypt the received data. When the acquisition terminal uploads physical status parameters, electrical parameters and network data to the edge processing device, the edge processing device performs decoding and verification.
[0010] Preferably, the health status is initially determined as healthy, sub-healthy, or abnormal based on electrical parameters including SOH, energy storage battery voltage, battery aging degree, and a set corresponding threshold. Specifically: Calculate the maximum difference between the voltage of each energy storage battery and the voltages of all other energy storage batteries as the energy storage battery voltage difference; Set warning thresholds and fault thresholds for SOH, energy storage battery voltage difference, and battery aging degree; If the SOH is less than the corresponding warning threshold, the voltage difference of the energy storage battery is greater than the corresponding warning threshold, the battery aging degree is less than the corresponding warning threshold, the temperature change rate is less than the set temperature change threshold, the internal pressure is within the set pressure range and there is no fault code, then it is initially determined that the health status is normal. If any one of the following conditions is met: SOH is greater than or equal to the corresponding warning threshold, energy storage battery voltage difference is less than or equal to the corresponding warning threshold, and battery aging degree is greater than or equal to the corresponding warning threshold, and SOH is less than the corresponding fault threshold, energy storage battery voltage difference is greater than the corresponding fault warning threshold, and battery aging degree is less than the corresponding fault threshold, and temperature change rate is less than the set temperature change warning threshold, internal pressure is within the set pressure range and there are no fault codes, then it is initially determined to be in a sub-healthy state. Otherwise, it is preliminarily determined that the person is in an abnormal health condition.
[0011] Preferably, the mutation characteristics are calculated by combining the degree of deviation from the baseline and the corresponding volatility, specifically as follows: The deviation from the baseline is obtained by dividing the difference between the real-time acquired value of each physical state parameter and electrical parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit by the corresponding value generated by the digital twin of the corresponding energy storage unit. The absolute value of subtracting the previous sliding window standard deviation from the current sliding window standard deviation is used as the input of the hyperbolic tangent function, and then 1 is added to represent the fluctuation of the parameter. Using the natural base as the base, the rate of change of the parameter per unit time as the exponent is used for exponential operation. The result of the exponential operation is multiplied by the instantaneous change amplitude of the corresponding parameter, then multiplied by the sum of the deviation from the baseline and 1, and then multiplied by the volatility to obtain the abrupt change characteristics of the corresponding parameter.
[0012] Preferably, determining whether network attack characteristics are present based on network data specifically involves: When network data access requests are abnormal, communication data packets are tampered with, handshake information contains illegal instructions, link status is abnormal, or verification fails during decoding, network attack characteristics are considered to have occurred.
[0013] Preferably, the anomaly types are distinguished based on the presence and correspondence of mutation features exceeding a set mutation threshold and network attack features, specifically: When there are no mutation features exceeding the set mutation threshold but there are network attack features, it is determined to be an anomaly caused by a network attack in the early stage of the attack. When both mutation features exceeding the set mutation threshold and network attack features exist simultaneously, all mutation features exceeding the set mutation threshold within the first set period are extracted. If only mutation features exceeding the set mutation threshold exist, all mutation features exceeding the set mutation threshold within the second set period are extracted. The first period is longer than the second period. If, within the corresponding period, only one electrical parameter or physical state parameter exhibits a sudden change characteristic exceeding the set sudden change threshold, or if the instantaneous sudden change in the battery casing temperature, internal pressure, and electrolyte concentration exceeds the set normal physical response limit of the battery, or if multiple electrical parameters or physical state parameters exhibit sudden change characteristics simultaneously exceeding the set sudden change threshold with no time delay between the times exceeding the set sudden change threshold, or if the changing trends of the electrical parameters and physical state parameters do not conform to the set battery fault evolution law, then it is considered an anomaly caused by a network attack; otherwise, it is considered an anomaly caused by a precursor to a physical fault. If the anomaly is considered to be caused by a network attack, and there are no network attack characteristics at this time, then it is considered to be caused by a covert network attack. When there are neither mutation characteristics nor network attack characteristics, the health status is determined to be healthy.
[0014] Preferably, the established battery failure evolution law is as follows: If the temperature change characteristics of the energy storage battery casing exceed the set change threshold, the aging degree change rate will be positive and the change rate will increase within the corresponding period, and the SOH change rate will be negative and less than the set normal SOH change amount. If the sudden change characteristics of the energy storage battery voltage and / or current exceed the set sudden change threshold, the outer shell temperature of the energy storage battery will rise, the internal pressure will increase, and the rate of change of aging degree will be positive and the rate of change will increase within the corresponding period.
[0015] Preferably, the potential hazard is classified according to the degree of parameter deviation from the baseline and the number of abnormal energy storage units, specifically as follows: The hidden dangers are classified into three levels: general hidden dangers, major hidden dangers, and critical hidden dangers. The deviation of the corresponding parameters is obtained when the sudden change characteristics of physical state parameters and electrical parameters exceed the set sudden change threshold. If the parameter deviation is less than the set first deviation threshold and only a single energy storage unit is judged as abnormal within the set third cycle, it is classified as a general hidden danger. If the parameter deviation is greater than the set second deviation threshold and multiple energy storage units are abnormal within the set third cycle, it is classified as a major hidden danger, with the first deviation threshold being greater than the second deviation threshold. Other situations are classified as major hidden dangers.
[0016] Preferably, the acquisition frequency of the acquisition terminal and the operating power of the energy storage unit are adjusted according to the type of anomaly and the classification of potential hazards, specifically as follows: For energy storage units in normal health condition, maintain normal operating power and set the data acquisition frequency according to the original standard; When an anomaly is caused by a network attack, the data acquisition, decision-making, and transmission tasks of the abnormal energy storage unit's acquisition terminal, cluster-level security decision-making node, and communication node are automatically taken over by the acquisition terminal, cluster-level security decision-making node, and communication node of the normal energy storage unit in the same cluster as the abnormal energy storage unit; the wireless mesh communication link is replanned, and the node roles and data transmission paths of the abnormal energy storage unit are adjusted. When an anomaly is caused by a precursor to a physical fault, electrical and communication isolation is performed on the faulty unit of the energy storage unit. When the level of the abnormal hazard is a general hazard, the acquisition frequency and power are not changed. When it is a major hazard, the operating power of the remaining working energy storage units is reduced and the data acquisition frequency of the acquisition terminal is increased. For major hazard, the operating power is further reduced, the data acquisition frequency is increased, and the encryption key update cycle is shortened.
[0017] The second aspect of this invention proposes a network security monitoring and control system for distributed acquisition devices based on the method described in the first aspect of this invention, including a preliminary judgment module, an anomaly judgment module, an anomaly type differentiation module, and an anomaly recovery module, specifically as follows: Preliminary assessment module: The data acquisition terminal collects the physical state parameters, electrical parameters and network data of each energy storage unit in the distributed energy storage power station. Based on the SOH, energy storage battery voltage and battery aging degree included in the electrical parameters and the set corresponding thresholds, the health status is initially determined to be healthy, sub-healthy or abnormal. Anomaly Detection Module: For energy storage units whose initial health status is determined to be sub-healthy or abnormal, the module performs the final anomaly detection. For physical state parameters and electrical parameters, the deviation between the real-time acquired value of each corresponding parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit is used as the deviation from the baseline of the corresponding parameter. The module calculates the mutation characteristics by combining the deviation from the baseline and the corresponding volatility. If the mutation characteristics of any physical state parameter or electrical parameter exceed the set mutation threshold, the health status is finally determined to be abnormal. Anomaly type differentiation module: Based on network data, it determines whether network attack characteristics appear, and differentiates anomaly types according to the presence and correspondence of mutation characteristics exceeding a set mutation threshold and network attack characteristics. The anomaly types include anomalies caused by network attacks or anomalies caused by precursors of physical failures. Anomaly Recovery Module: Based on the degree of parameter deviation from the baseline and the number of abnormal energy storage units, the module classifies potential hazards and adjusts the acquisition frequency of the acquisition terminal and the operating power of the energy storage units in combination with the type of anomaly and the hazard classification.
[0018] A third aspect of the present invention provides an apparatus comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, the processor performing steps of the network security monitoring and control method for a distributed acquisition device as described in the first aspect of the present invention.
[0019] The fourth aspect of the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, uses the steps of the network security monitoring and control method for distributed acquisition devices described in the first aspect of the present invention.
[0020] The beneficial effects of this invention are that, compared with existing technologies, it achieves collaborative monitoring and intelligent control of energy storage unit health status and network security by integrating digital twins, multi-source parameter analysis, and network security awareness. First, a preliminary health status assessment is performed to quickly screen out potentially abnormal units, improving the overall efficiency and response speed of the monitoring system. Employing a digital twin-based dynamic assessment of baseline deviations and a method for calculating mutation characteristics that integrates volatility, it can sensitively identify early anomalies in physical and electrical parameters. By establishing a logical correspondence between network attack characteristics and parameter mutation characteristics, and combining this with battery fault evolution mechanisms, it can accurately distinguish whether the root cause of the anomaly is induced by a network attack or a precursor to a physical fault. Furthermore, based on the hazard classification and anomaly type, the acquisition frequency and operating power are dynamically adjusted, achieving closed-loop management from status awareness to adaptive protection. This effectively improves the accuracy of monitoring, the timeliness of early warning, and the targeted nature of protection, strengthening the system's self-recovery capability when facing mixed threats. Attached Figure Description
[0021] Figure 1 This is a flowchart of the present invention. Detailed Implementation
[0022] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this invention. The embodiments described in this application are merely some embodiments of this invention, and not all embodiments. Based on the spirit of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of this invention.
[0023] like Figure 1 As shown, Embodiment 1 of the present invention proposes a network security monitoring and control method for distributed acquisition devices, including: S1. Use the acquisition terminal to collect the physical state parameters, electrical parameters and network data of each energy storage unit in the distributed energy storage power station; It should be noted that each energy storage unit has a corresponding data acquisition terminal for data collection. That is, for the target distributed energy storage power station, each energy storage unit of the target distributed energy storage power station is bound to a corresponding distributed energy storage data acquisition terminal. Each data acquisition terminal autonomously builds a security cluster through a distributed blockchain networking method. After each data acquisition terminal is started, it automatically scans the surrounding data acquisition terminals with the same type of bound energy storage units, and autonomously initiates a networking request according to the preset networking trigger conditions, and completes the autonomous construction of the security cluster using a distributed blockchain networking method. After each data acquisition terminal is powered on, its built-in self-organizing scanning unit is immediately activated. Using radio frequency broadcast scanning mode, it continuously sends broadcast signals containing its own device identifier, the unique ID of the bound energy storage unit, and the network ready status. At the same time, it receives response signals from surrounding data acquisition terminals in real time, analyzes and processes the received response signals, and extracts key information such as the device model, bound energy storage unit type, communication link quality, and operating status of the surrounding data acquisition terminals. It accurately selects data acquisition terminals of the same type as its own device model, which have completed the corresponding binding of energy storage units and whose communication quality meets the network requirements. This completes the automatic scanning of surrounding data acquisition terminals with the same type of bound energy storage units.
[0024] It should also be noted that after completing the scanning of surrounding nodes, each acquisition terminal compares the number of valid nodes, communication signal strength, node operation stability, and other information obtained from its own scanning with the preset networking trigger conditions. When the preset node number threshold, communication quality threshold, and networking legality conditions are met, it automatically generates and broadcasts a networking request message to the surrounding acquisition terminals of the same type that have passed the screening. The message carries its own device identifier, bound energy storage unit number, node role, and communication parameters. The receiving node parses and verifies the legality of the networking request message. After the verification is passed, it sends back a networking confirmation response, thus completing the autonomous initiation and interactive confirmation of the networking request.
[0025] During the networking process, each acquisition terminal acts as an independent blockchain node, possessing data storage, communication verification, and node consensus functions. Simultaneously, from all blockchain nodes, one acquisition terminal within the cluster is selected as the cluster-level security decision node through a comprehensive screening process based on node computing power, operational stability, and data processing capabilities. This node also assumes the responsibilities of a blockchain consensus node, handling communication coordination between cluster nodes, data consensus verification, and the issuance of security decision commands. Nodes establish dynamic communication connections through a wireless mesh network. These connections can be dynamically adjusted according to the operational status of each acquisition terminal. When communication is interrupted at one node, link relay can be achieved through other nodes, ensuring uninterrupted communication within the cluster. Ultimately, through the coordinated efforts of all these components, autonomous networking within the cluster is achieved.
[0026] In this preferred embodiment, the physical state parameters, electrical parameters, and network data are specifically as follows: Physical state parameters include: battery casing temperature, internal pressure, and electrolyte concentration; Electrical parameters include: energy storage battery voltage, current, SOC value, SOH value, charge / discharge status, battery aging level, and fault codes; Network data includes: communication data packets, handshake information, access requests, and link status; Among them, SOH value is the ratio of the battery's current capacity to its rated capacity, indicating the degree of battery aging. The calculation formula is:
[0027] in, This refers to the SOH value; The relative growth rate of internal resistance is the difference between the current internal resistance and the initial internal resistance divided by the initial internal resistance. This is the current number of iterations divided by the maximum allowed number of iterations.
[0028] The acquisition terminal uses an encryption algorithm to encrypt the received data. When the acquisition terminal uploads physical state parameters, electrical parameters and network data to the edge processing device, the edge processing device performs decoding verification. Specifically, the received data is decrypted and verified using a dynamic key of battery physical characteristics and the national cryptographic SM10 algorithm. The dynamic key is generated by combining the physical characteristics of the corresponding energy storage unit collected in real time by each acquisition terminal with the unique physical identifier of the battery.
[0029] S2. Based on electrical parameters including SOH, energy storage battery voltage, battery aging degree, and the set corresponding threshold, a preliminary judgment is made as to whether the health status is healthy, sub-healthy, or abnormal. In this preferred embodiment, the health status is initially determined as healthy, sub-healthy, or abnormal based on electrical parameters including SOH, energy storage battery voltage, battery aging degree, and a set corresponding threshold. Specifically: Calculate the maximum difference between the voltage of each energy storage battery and the voltages of all other energy storage batteries as the energy storage battery voltage difference; Set warning thresholds and fault thresholds for SOH, energy storage battery voltage difference, and battery aging degree; If the SOH is less than the corresponding warning threshold, the voltage difference of the energy storage battery is greater than the corresponding warning threshold, the battery aging degree is less than the corresponding warning threshold, the temperature change rate is less than the set temperature change threshold, the internal pressure is within the set pressure range and there is no fault code, then it is initially determined that the health status is normal. If any one of the following conditions is met: SOH is greater than or equal to the corresponding warning threshold, energy storage battery voltage difference is less than or equal to the corresponding warning threshold, and battery aging degree is greater than or equal to the corresponding warning threshold, and SOH is less than the corresponding fault threshold, energy storage battery voltage difference is greater than the corresponding fault warning threshold, and battery aging degree is less than the corresponding fault threshold, and temperature change rate is less than the set temperature change warning threshold, internal pressure is within the set pressure range and there are no fault codes, then it is initially determined to be in a sub-healthy state. Otherwise, it is preliminarily determined that the person is in an abnormal health condition.
[0030] S3. For energy storage units whose health status is initially judged to be sub-healthy or abnormal, a final abnormality judgment is made. For physical state parameters and electrical parameters, the degree of deviation between the real-time acquired value of each corresponding parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit is used as the degree of deviation from the baseline of the corresponding parameter. Combined with the degree of deviation from the baseline and the corresponding volatility, the mutation characteristics are calculated. If the mutation characteristics of any physical state parameter or electrical parameter exceed the set mutation threshold, the health status is finally judged to be abnormal. It should be noted that the digital twin has a built-in 1:1 replica of the battery structure, operating mechanism and aging trajectory model, which completes the real-time state mapping between the physical and virtual entities.
[0031] In this preferred embodiment, the mutation characteristics are calculated by combining the degree of deviation from the baseline and the corresponding volatility, specifically as follows: The deviation from the baseline is obtained by dividing the difference between the real-time acquired value of each physical state parameter and electrical parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit by the corresponding value generated by the digital twin of the corresponding energy storage unit. The absolute value of subtracting the previous sliding window standard deviation from the current sliding window standard deviation is used as the input of the hyperbolic tangent function, and then 1 is added to represent the fluctuation of the parameter. Using the natural base as the base, the rate of change of the parameter per unit time as the exponent is used for exponential operation. The result of the exponential operation is multiplied by the instantaneous change amplitude of the corresponding parameter, then multiplied by the sum of the deviation from the baseline and 1, and then multiplied by the volatility to obtain the abrupt change characteristics of the corresponding parameter.
[0032] Mutation characteristics The formula is:
[0033] in, The instantaneous change amplitude; The rate of change of the parameter per unit time; The degree of deviation from the baseline; , These are the standard deviations of the sliding window for the corresponding parameters at this time and the standard deviations of the sliding window at the previous time, respectively.
[0034] S4. Determine whether network attack characteristics appear based on network data, and distinguish the types of anomalies based on the presence and correspondence of mutation characteristics exceeding the set mutation threshold and network attack characteristics. The types of anomalies include anomalies caused by network attacks or anomalies caused by precursors of physical failures. In this preferred embodiment, determining whether network attack characteristics have appeared based on network data specifically involves: When network data access requests are abnormal, communication data packets are tampered with, handshake information contains illegal instructions, link status is abnormal, or verification fails during decoding, network attack characteristics are considered to have occurred.
[0035] In this embodiment, the anomaly types are distinguished based on the presence and correspondence of mutation features exceeding a set mutation threshold and network attack features, specifically: When there are no mutation features exceeding the set mutation threshold but there are network attack features, it is determined to be an anomaly caused by a network attack in the early stage of the attack. When both mutation features exceeding the set mutation threshold and network attack features exist simultaneously, all mutation features exceeding the set mutation threshold within the first set period are extracted. If only mutation features exceeding the set mutation threshold exist, all mutation features exceeding the set mutation threshold within the second set period are extracted. The first period is longer than the second period. If, within the corresponding period, only one electrical parameter or physical state parameter exhibits a sudden change characteristic exceeding the set sudden change threshold, or if the instantaneous sudden change in the battery casing temperature, internal pressure, and electrolyte concentration exceeds the set normal physical response limit of the battery, or if multiple electrical parameters or physical state parameters exhibit sudden change characteristics simultaneously exceeding the set sudden change threshold with no time delay between the times exceeding the set sudden change threshold, or if the changing trends of the electrical parameters and physical state parameters do not conform to the set battery fault evolution law, then it is considered an anomaly caused by a network attack; otherwise, it is considered an anomaly caused by a precursor to a physical fault. If the anomaly is considered to be caused by a network attack, and there are no network attack characteristics at this time, then it is considered to be caused by a covert network attack. When there are neither mutation characteristics nor network attack characteristics, the health status is determined to be healthy.
[0036] It should be noted that for the corresponding types of anomalies, three-dimensional tracing can be further performed to trace the attack source address, abnormal access path, illegal command delivery link and data packet tampering node along the network trajectory; and to trace the starting time, diffusion location and conduction path of the abnormal temperature, pressure, voltage and current of the energy storage battery along the physical trajectory.
[0037] In this preferred embodiment, the established battery failure evolution law is specifically as follows: If the temperature change characteristics of the energy storage battery casing exceed the set change threshold, the aging degree change rate will be positive and the change rate will increase within the corresponding period, and the SOH change rate will be negative and less than the set normal SOH change amount. If the sudden change characteristics of the energy storage battery voltage and / or current exceed the set sudden change threshold, the outer shell temperature of the energy storage battery will rise, the internal pressure will increase, and the rate of change of aging degree will be positive and the rate of change will increase within the corresponding period.
[0038] S5. Classify potential hazards based on the degree of parameter deviation from the baseline and the number of abnormal energy storage units. Adjust the acquisition frequency of the acquisition terminal and the operating power of the energy storage units in combination with the type of abnormality and the hazard classification.
[0039] In this preferred embodiment, the potential hazards are classified according to the degree of parameter deviation from the baseline and the number of abnormal energy storage units, specifically as follows: The hidden dangers are classified into three levels: general hidden dangers, major hidden dangers, and critical hidden dangers. The deviation of the corresponding parameters is obtained when the sudden change characteristics of physical state parameters and electrical parameters exceed the set sudden change threshold. If the parameter deviation is less than the set first deviation threshold and only a single energy storage unit is judged as abnormal within the set third cycle, it is classified as a general hidden danger. If the parameter deviation is greater than the set second deviation threshold and multiple energy storage units are abnormal within the set third cycle, it is classified as a major hidden danger, with the first deviation threshold being greater than the second deviation threshold. Other situations are classified as major hidden dangers.
[0040] In this preferred embodiment, the acquisition frequency of the acquisition terminal and the operating power of the energy storage unit are adjusted according to the type of anomaly and the classification of potential hazards. Specifically: For energy storage units in normal health condition, maintain normal operating power and set the data acquisition frequency according to the original standard; When an anomaly is caused by a network attack, the data acquisition, decision-making, and transmission tasks of the abnormal energy storage unit's acquisition terminal, cluster-level security decision-making node, and communication node are automatically taken over by the acquisition terminal, cluster-level security decision-making node, and communication node of the normal energy storage unit in the same cluster as the abnormal energy storage unit; the wireless mesh communication link is replanned, and the node roles and data transmission paths of the abnormal energy storage unit are adjusted. When an anomaly is caused by a precursor to a physical fault, electrical and communication isolation is performed on the faulty unit of the energy storage unit. When the level of the abnormal hazard is classified as a general hazard, the sampling frequency and power remain unchanged. Specifically, the sampling frequency is once every 5 minutes. When the hazard is classified as a major hazard, the operating power of the remaining working energy storage units is reduced, and the data sampling frequency of the sampling terminal is increased (specifically, once every 3 minutes). For major hazard, the operating power is further reduced, the data sampling frequency is increased, and the encryption key update cycle is shortened, specifically adjusted to once every 1 minute, thereby enhancing the security protection strength and shortening the encryption key update cycle to 12 hours.
[0041] Embodiment 2 of the present invention proposes a network security monitoring and control system for distributed acquisition devices based on the method described in Embodiment 1 of the present invention, including a preliminary judgment module, an anomaly judgment module, an anomaly type differentiation module, and an anomaly recovery module, specifically as follows: Preliminary assessment module: The data acquisition terminal collects the physical state parameters, electrical parameters and network data of each energy storage unit in the distributed energy storage power station. Based on the SOH, energy storage battery voltage and battery aging degree included in the electrical parameters and the set corresponding thresholds, the health status is initially determined to be healthy, sub-healthy or abnormal. Anomaly Detection Module: For energy storage units whose initial health status is determined to be sub-healthy or abnormal, the module performs the final anomaly detection. For physical state parameters and electrical parameters, the deviation between the real-time acquired value of each corresponding parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit is used as the deviation from the baseline of the corresponding parameter. The module calculates the mutation characteristics by combining the deviation from the baseline and the corresponding volatility. If the mutation characteristics of any physical state parameter or electrical parameter exceed the set mutation threshold, the health status is finally determined to be abnormal. Anomaly type differentiation module: Based on network data, it determines whether network attack characteristics appear, and differentiates anomaly types according to the presence and correspondence of mutation characteristics exceeding a set mutation threshold and network attack characteristics. The anomaly types include anomalies caused by network attacks or anomalies caused by precursors of physical failures. Anomaly Recovery Module: Based on the degree of parameter deviation from the baseline and the number of abnormal energy storage units, the module classifies potential hazards and adjusts the acquisition frequency of the acquisition terminal and the operating power of the energy storage units in combination with the type of anomaly and the hazard classification.
[0042] Embodiment 3 of the present invention proposes a device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor performs the steps of the network security monitoring and control method for distributed acquisition devices described in Embodiment 1 of the present invention.
[0043] Embodiment 4 of the present invention proposes a computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the steps of the network security monitoring and control method for distributed acquisition devices described in Embodiment 1 of the present invention are used.
[0044] This disclosure can be a system, method, and / or computer program product. A computer program product may include a computer-readable storage medium having computer-readable program instructions loaded thereon for causing a processor to implement various aspects of this disclosure.
[0045] Computer-readable storage media can be tangible devices capable of holding and storing instructions for use by an instruction execution device. Computer-readable storage media can be, for example—but not limited to—electrical storage devices, magnetic storage devices, optical storage devices, electromagnetic storage devices, semiconductor storage devices, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of computer-readable storage media include: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital multifunction disc (DVD), memory sticks, floppy disks, mechanical encoding devices, such as punch cards or recessed protrusions storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage media used herein are not to be construed as transient signals themselves, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through waveguides or other transmission media (e.g., light pulses through fiber optic cables), or electrical signals transmitted through wires.
[0046] The computer-readable program instructions described herein can be downloaded from computer-readable storage media to various computing / processing devices, or downloaded via a network, such as the Internet, local area network, wide area network, and / or wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards them to the computer-readable storage media in the respective computing / processing device.
[0047] Computer program instructions used to perform the operations of this disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or may be connected to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuitry, such as programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), is personalized by utilizing the status information of the computer-readable program instructions to implement various aspects of this disclosure.
[0048] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.
Claims
1. A network security monitoring and control method for distributed data acquisition devices, characterized in that, include: The data acquisition terminal is used to collect the physical state parameters, electrical parameters and network data of each energy storage unit in the distributed energy storage power station. Based on the SOH, energy storage battery voltage and battery aging degree included in the electrical parameters and the set corresponding threshold, the health status is initially determined to be healthy, sub-healthy or abnormal. For energy storage units whose initial health status is determined to be sub-healthy or abnormal, a final abnormality judgment is made. For physical state parameters and electrical parameters, the degree of deviation between the real-time acquired value of each corresponding parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit is used as the deviation from the baseline of the corresponding parameter. Combined with the deviation from the baseline and the corresponding volatility, the mutation characteristics are calculated. If the mutation characteristics of any physical state parameter or electrical parameter exceed the set mutation threshold, the health status is finally judged to be abnormal. Based on network data, determine whether network attack characteristics have appeared, and distinguish the types of anomalies according to the presence and correspondence of mutation characteristics exceeding the set mutation threshold and network attack characteristics. The types of anomalies include anomalies caused by network attacks or anomalies caused by precursors of physical failures. The potential hazards are classified according to the degree of parameter deviation from the baseline and the number of abnormal energy storage units. The acquisition frequency of the acquisition terminal and the operating power of the energy storage units are adjusted in combination with the type of anomaly and the hazard classification.
2. The network security monitoring and control method for distributed acquisition devices according to claim 1, characterized in that: Physical state parameters, electrical parameters, and network data, specifically: Physical state parameters include: battery casing temperature, internal pressure, and electrolyte concentration; Electrical parameters include: energy storage battery voltage, current, SOC value, SOH value, charge / discharge status, battery aging level, and fault codes; Network data includes: communication data packets, handshake information, access requests, and link status; The acquisition terminal uses an encryption algorithm to encrypt the received data. When the acquisition terminal uploads physical status parameters, electrical parameters and network data to the edge processing device, the edge processing device performs decoding and verification.
3. The network security monitoring and control method for distributed acquisition devices according to claim 2, characterized in that: Based on electrical parameters including SOH, energy storage battery voltage, and battery aging level, as well as the set corresponding thresholds, a preliminary assessment is made as to whether the health status is healthy, sub-healthy, or abnormal. Specifically: Calculate the maximum difference between the voltage of each energy storage battery and the voltages of all other energy storage batteries as the energy storage battery voltage difference; Set warning thresholds and fault thresholds for SOH, energy storage battery voltage difference, and battery aging degree; If the SOH is less than the corresponding warning threshold, the voltage difference of the energy storage battery is greater than the corresponding warning threshold, the battery aging degree is less than the corresponding warning threshold, the temperature change rate is less than the set temperature change threshold, the internal pressure is within the set pressure range and there are no fault codes, then it is initially determined that the health status is normal. If any one of the following conditions is met: SOH is greater than or equal to the corresponding warning threshold, energy storage battery voltage difference is less than or equal to the corresponding warning threshold, and battery aging degree is greater than or equal to the corresponding warning threshold, and SOH is less than the corresponding fault threshold, energy storage battery voltage difference is greater than the corresponding fault warning threshold, and battery aging degree is less than the corresponding fault threshold, and temperature change rate is less than the set temperature change warning threshold, internal pressure is within the set pressure range and there are no fault codes, then it is initially determined to be in a sub-healthy state. Otherwise, it is preliminarily determined that the person is in an abnormal health condition.
4. The network security monitoring and control method for distributed acquisition devices according to claim 2, characterized in that: The mutation characteristics are calculated by combining the degree of deviation from the baseline and the corresponding volatility, specifically as follows: The deviation from the baseline is obtained by dividing the difference between the real-time acquired value of each physical state parameter and electrical parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit by the corresponding value generated by the digital twin of the corresponding energy storage unit. The absolute value of subtracting the previous sliding window standard deviation from the current sliding window standard deviation is used as the input of the hyperbolic tangent function, and then 1 is added to represent the fluctuation of the parameter. Using the natural base as the base, the rate of change of the parameter per unit time as the exponent is used for exponential operation. The result of the exponential operation is multiplied by the instantaneous change amplitude of the corresponding parameter, then multiplied by the sum of the deviation from the baseline and 1, and then multiplied by the volatility to obtain the abrupt change characteristics of the corresponding parameter.
5. The network security monitoring and control method for distributed acquisition devices according to claim 2, characterized in that: Determining whether network attack characteristics are present based on network data includes: When network data access requests are abnormal, communication data packets are tampered with, handshake information contains illegal instructions, link status is abnormal, or verification fails during decoding, network attack characteristics are considered to have occurred.
6. The network security monitoring and control method for distributed acquisition devices according to claim 2, characterized in that: Anomalies are categorized based on the presence and corresponding relationships of mutation features exceeding a set mutation threshold and network attack features. Specifically: When there are no mutation features exceeding the set mutation threshold but there are network attack features, it is determined to be an anomaly caused by a network attack in the early stage of the attack. When both mutation features exceeding the set mutation threshold and network attack features exist simultaneously, all mutation features exceeding the set mutation threshold within the first set period are extracted. If only mutation features exceeding the set mutation threshold exist, all mutation features exceeding the set mutation threshold within the second set period are extracted. The first period is longer than the second period. If, within the corresponding period, only one electrical parameter or physical state parameter exhibits a mutation characteristic exceeding the set mutation threshold, or if the instantaneous mutation amount of the battery casing temperature, internal pressure, and electrolyte concentration exceeds the set normal physical response limit of the battery, or if the mutation characteristics of multiple electrical parameters or physical state parameters simultaneously exceed the set mutation threshold, with no time delay between the times when the set mutation threshold is exceeded, or if the changing trends of electrical parameters and physical state parameters do not conform to the set battery fault evolution law, then it is considered an anomaly caused by a network attack. Otherwise, it is an abnormality caused by a precursor to a physical malfunction; If the anomaly is considered to be caused by a network attack, and there are no network attack characteristics at this time, then it is considered to be caused by a covert network attack. When there are neither mutation characteristics nor network attack characteristics, the health status is determined to be healthy.
7. The network security monitoring and control method for distributed acquisition devices according to claim 6, characterized in that: The established battery failure evolution rules are as follows: If the temperature change characteristics of the energy storage battery casing exceed the set change threshold, the aging degree change rate will be positive and the change rate will increase within the corresponding period, and the SOH change rate will be negative and less than the set normal SOH change amount. If the sudden change characteristics of the energy storage battery voltage and / or current exceed the set sudden change threshold, the outer shell temperature of the energy storage battery will rise, the internal pressure will increase, and the rate of change of aging degree will be positive and the rate of change will increase within the corresponding period.
8. The network security monitoring and control method for distributed acquisition devices according to claim 6, characterized in that: The potential hazards are classified according to the degree of parameter deviation from the baseline and the number of abnormal energy storage units, as follows: The hidden dangers are classified into three levels: general hidden dangers, major hidden dangers, and critical hidden dangers. The deviation of the corresponding parameters is obtained when the sudden change characteristics of physical state parameters and electrical parameters exceed the set sudden change threshold. If the parameter deviation is less than the set first deviation threshold and only a single energy storage unit is judged as abnormal within the set third cycle, it is classified as a general hidden danger. If the parameter deviation is greater than the set second deviation threshold and multiple energy storage units are abnormal within the set third cycle, it is classified as a major hidden danger, with the first deviation threshold being greater than the second deviation threshold. Other situations are classified as major hidden dangers.
9. The network security monitoring and control method for distributed acquisition devices according to claim 8, characterized in that: The sampling frequency of the data acquisition terminal and the operating power of the energy storage unit are adjusted according to the type of anomaly and the classification of potential hazards, specifically as follows: For energy storage units in normal health condition, maintain normal operating power and set the data acquisition frequency according to the original standard; When the anomaly is caused by a network attack, the data acquisition, decision-making and transmission tasks of the abnormal energy storage unit's acquisition terminal, cluster-level security decision-making node and communication node are automatically taken over by the acquisition terminal, cluster-level security decision-making node and communication node of the normal energy storage unit in the same cluster as the abnormal energy storage unit. The wireless mesh communication link was redesigned, and the node roles and data transmission paths of abnormal energy storage units were adjusted. When an anomaly is caused by a precursor to a physical fault, electrical and communication isolation is performed on the faulty unit of the energy storage unit. When the level of the abnormal hazard is a general hazard, the acquisition frequency and power are not changed. When it is a major hazard, the operating power of the remaining working energy storage units is reduced and the data acquisition frequency of the acquisition terminal is increased. For major hazard, the operating power is further reduced, the data acquisition frequency is increased, and the encryption key update cycle is shortened.
10. A network security monitoring and control system for distributed acquisition devices based on the method of any one of claims 1-9, comprising a preliminary judgment module, an anomaly judgment module, an anomaly type differentiation module, and an anomaly recovery module, characterized in that: Preliminary assessment module: The data acquisition terminal collects the physical state parameters, electrical parameters and network data of each energy storage unit in the distributed energy storage power station. Based on the SOH, energy storage battery voltage and battery aging degree included in the electrical parameters and the set corresponding thresholds, the health status is initially determined to be healthy, sub-healthy or abnormal. Anomaly Detection Module: For energy storage units whose initial health status is determined to be sub-healthy or abnormal, the module performs the final anomaly detection. For physical state parameters and electrical parameters, the deviation between the real-time acquired value of each corresponding parameter at the acquisition terminal and the corresponding value generated by the digital twin of the corresponding energy storage unit is used as the deviation from the baseline of the corresponding parameter. The module calculates the mutation characteristics by combining the deviation from the baseline and the corresponding volatility. If the mutation characteristics of any physical state parameter or electrical parameter exceed the set mutation threshold, the health status is finally determined to be abnormal. Anomaly type differentiation module: Based on network data, it determines whether network attack characteristics appear, and differentiates anomaly types according to the presence and correspondence of mutation characteristics exceeding a set mutation threshold and network attack characteristics. The anomaly types include anomalies caused by network attacks or anomalies caused by precursors of physical failures. Anomaly Recovery Module: Based on the degree of parameter deviation from the baseline and the number of abnormal energy storage units, the module classifies potential hazards and adjusts the acquisition frequency of the acquisition terminal and the operating power of the energy storage units in combination with the type of anomaly and the hazard classification.
11. An apparatus comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: The processor performs the steps of the network security monitoring and control method for distributed acquisition devices according to any one of claims 1 to 9.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program that, when executed by a processor, uses the steps of the network security monitoring and control method for distributed acquisition devices as described in any one of claims 1 to 9.