Substation remote operation and maintenance method, system and computer device

CN122763779APending Publication Date: 2026-09-15SHENZHEN POWER SUPPLY BUREAU
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611073890.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-20
Publication Date
2026-09-15

Smart Images

  • Figure CN122763779A_ABST
    Figure CN122763779A_ABST
Patent Text Reader

Abstract

The application relates to a substation remote operation and maintenance method, system and computer equipment. The method is applied to a substation remote operation and maintenance terminal, and comprises the following steps: receiving a negotiation message sent by a master station remote operation and maintenance server through an established encryption tunnel; wherein the negotiation message is used to represent a remote connection instruction of the master station to an operation and maintenance object of the substation; establishing a transmission layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object based on the negotiation message; and performing an operation and maintenance operation on the operation and maintenance object based on the transmission layer connection. The method can improve the operation and maintenance efficiency of the substation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of power operation and maintenance technology, and in particular to a method, system and computer equipment for remote operation and maintenance of substations. Background Technology

[0002] With the accelerated construction of a "new power system with new energy as the mainstay," the power grid is undergoing profound changes. Trends such as high-proportion distributed energy integration, AC / DC hybrid operation, and active distribution networks are leading to increasingly complex power grid operating characteristics, placing higher demands on system reliability, flexibility, and control precision. As the nerve center of the power grid, substations are experiencing exponential growth in the scale of their internal secondary equipment, including relay protection, measurement and control, and fault recorders, resulting in increased equipment heterogeneity and tighter functional logic coupling.

[0003] In related technologies, on-site operation and maintenance (O&M) is used to perform O&M operations on the secondary equipment of substations. However, this model heavily relies on O&M personnel traveling long distances to dispersed substation sites to perform the work. This process is time-consuming, resulting in low O&M efficiency and making it difficult to meet the high-timeliness O&M requirements of substations under the aforementioned circumstances. Summary of the Invention

[0004] Therefore, it is necessary to provide a method, system, and computer equipment for remote operation and maintenance of substations that can improve the efficiency of substation operation and maintenance, in response to the above-mentioned technical problems.

[0005] Firstly, this application provides a method for remote operation and maintenance of substations, applied to a remote operation and maintenance terminal for substations, the method comprising:

[0006] The master station receives negotiation messages sent by the remote operation and maintenance server through the established encrypted tunnel; wherein the negotiation messages are used to represent the master station's remote connection instructions to the operation and maintenance objects of the substation.

[0007] A transport layer connection is established between the substation remote operation and maintenance terminal and the operation and maintenance object based on the negotiation message;

[0008] Operations are performed on the object to be maintained based on the transport layer connection.

[0009] In one embodiment, the negotiation message includes: the network address, port information, transport layer protocol type, and terminal password of the maintenance object; establishing a transport layer connection between the substation remote maintenance terminal and the maintenance object based on the negotiation message includes: parsing the negotiation message to obtain the network address, the port information, the transport layer protocol type, and the terminal password; performing consistency verification based on the terminal password, and establishing the transport layer connection according to the network address, the port information, and the transport layer protocol type after the consistency verification is successful.

[0010] In one embodiment, the operation and maintenance of the maintenance object based on the transport layer connection includes: receiving a remote maintenance message sent by the master station remote maintenance server through the encrypted tunnel; performing maintenance and maintenance operations on the maintenance object based on the remote maintenance message and the transport layer connection; wherein the remote maintenance message is used to characterize the maintenance and maintenance operation of the master station on the maintenance object, and the remote maintenance message is sent by the master station remote maintenance server after determining that the transport layer connection has been established.

[0011] In one embodiment, performing maintenance operations on the maintenance object based on the remote maintenance message and the transport layer connection includes: forwarding the remote maintenance message to the maintenance object through the transport layer connection so that the maintenance object can perform the maintenance operation; receiving the execution response message returned by the maintenance object through the transport layer connection, and forwarding the execution response message to the master station remote maintenance server through the encrypted tunnel.

[0012] In one embodiment, the method further includes: receiving an encrypted tunnel establishment request sent by the master station remote operation and maintenance server when the remote operation and maintenance channel between the master station remote operation and maintenance server and the substation remote operation and maintenance terminal is already open; in response to the encrypted tunnel establishment request, establishing the encrypted tunnel between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server based on a preset secure communication protocol; and after the encrypted tunnel is established, sending confirmation information to the master station remote operation and maintenance server, the confirmation information indicating that the encrypted tunnel has been established.

[0013] In one embodiment, the method further includes: after establishing the transport layer connection, sending a negotiation response message to the master station remote operation and maintenance server through the encrypted tunnel; the negotiation response message is used to indicate the establishment result of the transport layer connection.

[0014] Secondly, this application also provides a method for remote operation and maintenance of substations, applied to a master station remote operation and maintenance server, the method comprising:

[0015] Once it is determined that an encrypted tunnel has been established between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server, a negotiation message is sent to the substation remote operation and maintenance terminal through the encrypted tunnel; wherein, the negotiation message is used to represent the master station's remote connection instruction to the substation's operation and maintenance object;

[0016] Once it is determined that a transport layer connection has been established between the substation remote operation and maintenance terminal and the operation and maintenance object, a remote operation and maintenance message is sent to the substation remote operation and maintenance terminal through the encrypted tunnel; wherein, the remote operation and maintenance message is used to characterize the operation and maintenance operation of the master station for the operation and maintenance object.

[0017] In one embodiment, the method further includes: receiving a negotiation response message sent by the substation remote operation and maintenance terminal through the encrypted tunnel; the negotiation response message is used to indicate the establishment result of the transport layer connection; if the establishment result of the transport layer connection is determined to be successful, the transport layer connection is determined to be established.

[0018] Thirdly, this application also provides a substation remote operation and maintenance device, applied to a substation remote operation and maintenance terminal, comprising:

[0019] The first receiving module is used to receive negotiation messages sent by the master station remote operation and maintenance server through an established encrypted tunnel; wherein, the negotiation message is used to represent the master station's remote connection instruction to the operation and maintenance object of the substation.

[0020] The first establishment module is used to establish a transport layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object based on the negotiation message;

[0021] The operation and maintenance module is used to perform operation and maintenance operations on the operation and maintenance object based on the transport layer connection.

[0022] Fourthly, this application also provides a substation remote operation and maintenance device, applied to a master station remote operation and maintenance server, comprising:

[0023] The third sending module is used to send a negotiation message to the substation remote operation and maintenance terminal through the encrypted tunnel when it is determined that an encrypted tunnel has been established between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server; wherein, the negotiation message is used to represent the master station's remote connection instruction to the substation operation and maintenance object.

[0024] The fourth sending module is used to send a remote maintenance message to the substation remote maintenance terminal through the encrypted tunnel when it is determined that a transport layer connection has been established between the substation remote maintenance terminal and the maintenance object; wherein the remote maintenance message is used to characterize the maintenance operation performed by the master station on the maintenance object.

[0025] Fifthly, this application also provides a remote operation and maintenance system for substations, including:

[0026] The main station remote operation and maintenance server is used to execute the substation remote operation and maintenance method provided in the first aspect of this application;

[0027] A substation remote operation and maintenance terminal is used in the substation remote operation and maintenance method provided in the second aspect of this application.

[0028] Sixthly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the substation remote operation and maintenance method provided in the first and / or second aspects of this application.

[0029] In a seventh aspect, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the substation remote operation and maintenance method provided in the first and / or second aspects of this application.

[0030] Eighthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the substation remote operation and maintenance method provided in the first and / or second aspects of this application.

[0031] The aforementioned remote operation and maintenance method, device, system, computer equipment, computer-readable storage medium, and computer program product for substations utilize an encrypted tunnel between the master station remote operation and maintenance server and the substation remote operation and maintenance terminal to transmit negotiation messages, preventing eavesdropping or tampering and improving message transmission security. Based on the negotiation messages, a transport layer connection is established between the substation remote operation and maintenance terminal and the maintenance object, opening a data path between the station-end agent and the maintenance object within the station. After the transport layer connection is established, the station-end agent is instructed to perform operation and maintenance operations on the maintenance object through the transport layer connection. Therefore, it ensures that operation and maintenance personnel can perform operation and maintenance operations remotely without being physically present at the substation, eliminating the time consumption and response delays caused by on-site operation and maintenance, thereby improving operation and maintenance efficiency and reducing manpower and time costs. Moreover, the encrypted tunnel and transport layer connection work in a layered and collaborative manner; the former ensures secure communication at the remote end, while the latter carries data communication within the station. Their cooperation ensures both security and efficient data forwarding within the station. Therefore, this application can improve both operation and maintenance efficiency and guarantee operation and maintenance security. Attached Figure Description

[0032] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0033] Figure 1 This is an application environment diagram of a substation remote operation and maintenance method in one embodiment;

[0034] Figure 2 This is a flowchart illustrating a remote operation and maintenance method for a substation in one embodiment;

[0035] Figure 3 This is a flowchart illustrating step 202 in one embodiment;

[0036] Figure 4 This is a flowchart illustrating step 203 in one embodiment;

[0037] Figure 5 This is a schematic diagram of the process for enabling a remote operation and maintenance channel in one embodiment;

[0038] Figure 6 This is a schematic diagram of the work order management process in one embodiment;

[0039] Figure 7 This is a schematic diagram illustrating the process of establishing an encrypted tunnel in one embodiment;

[0040] Figure 8 This is a sequence diagram of the entire process of remote operation and maintenance protocol proxy forwarding in one embodiment;

[0041] Figure 9 This is a flowchart illustrating a remote operation and maintenance method for substations in another embodiment;

[0042] Figure 10 This is a structural block diagram of a substation remote operation and maintenance device in one embodiment;

[0043] Figure 11 This is a structural block diagram of a substation remote operation and maintenance device in another embodiment. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0045] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.

[0046] The operation and maintenance solutions for substations in related technologies have the following problems:

[0047] The operation and maintenance (O&M) efficiency bottleneck is prominent, and resource costs are high: the O&M model heavily relies on O&M personnel traveling long distances to dispersed substation sites to perform operations. This process not only consumes a lot of time and transportation costs, but also, due to delays in fault response and equipment maintenance, may lead to extended equipment downtime, directly affecting the reliability of power grid supply. As the number of devices surges, the marginal benefits of O&M resource investment under this model diminish, making it difficult to achieve economies of scale.

[0048] The low level of digitalization in the operation and maintenance process, coupled with a lack of effective supervision and traceability mechanisms, means that on-site operation and maintenance heavily rely on personnel skills and experience. The issuance, execution, and feedback of operation and maintenance instructions are mostly transmitted verbally or through paper documents, lacking standardized electronic processes. The entire operation and maintenance process cannot be recorded and monitored in real time and accurately, making it difficult to guarantee operational standardization. Once a misoperation or safety incident occurs, subsequent traceability and responsibility determination are extremely difficult, hindering the accumulation of experience and continuous improvement.

[0049] Existing remote operation and maintenance technologies have a narrow service coverage, making it difficult to support integrated and centralized management. Most existing remote operation and maintenance solutions are isolated, point-to-point implementations (such as protocol proxies that only support specific models or functions), resulting in inconsistent security, weak protocol adaptability, and incomplete service coverage. This makes it impossible to achieve full-service, standardized remote access and control of heterogeneous secondary equipment groups within a site under a unified security strategy, thus hindering the construction of a truly centralized operation and maintenance system.

[0050] In other words, while the industry has seen initial attempts at remote operation, such as point-to-point remote control and application-specific protocol proxy forwarding, aimed at improving operational efficiency, these technical solutions have significant limitations. Firstly, in terms of security, if the underlying channels for point-to-point remote control are not deeply integrated with the power monitoring system's security protection framework, they may introduce unauthorized access risks, creating new security vulnerabilities. Secondly, regarding the coverage of operational services, existing methods are mostly point-to-point solutions with poor protocol compatibility, making it difficult to support integrated and intensive operational management of diverse secondary equipment within the station, resulting in persistent low operational efficiency. Therefore, there is an urgent need to construct a new paradigm for remote operation and maintenance that integrates unified security management and comprehensive business coverage to overcome the multi-dimensional dilemmas in efficiency, quality, and security within the current operational and maintenance system.

[0051] Therefore, this application proposes a remote operation and maintenance method for substations, which achieves the following:

[0052] Collaborative control between management and operations channels: This system implements a secure operations architecture that logically separates and enables collaborative work between management and operations channels. The management channel is dedicated to high-strength authentication, access control, and commands to start / stop operations sessions, while the operations channel, once a secure session is established, focuses on efficient business data transmission. This decouples and unifies security control and business efficiency at the system level, fundamentally overcoming the inherent shortcomings of traditional single-channel systems that must balance security and performance.

[0053] Unified Interface for Centralized Operation and Maintenance of Heterogeneous Devices: This architecture enables unified management of secondary devices from multiple vendors and of various types without altering the existing on-site network structure. By deploying a unified interface and protocol adaptation layer at the site, the heterogeneity of the underlying devices is shielded, allowing the remote master station to perform one-stop remote operation and maintenance on all secondary devices across the site using standardized commands. This completely solves the problems of narrow business coverage and inability to achieve integrated management inherent in previous technical solutions.

[0054] Digitalization and closed-loop auditing of the entire operation and maintenance process: The entire remote operation and maintenance process is transformed into traceable structured digital events or visual videos. From session initiation and command execution to operation completion, all key steps, screen outputs, and logs are fully recorded and correlated to form an immutable audit loop. This achieves full transparency and accurate traceability of the operation and maintenance process, providing core data support for security compliance, responsibility definition, and operation and maintenance quality improvement.

[0055] The remote operation and maintenance method for substations provided in this application can be applied to, for example... Figure 1The application environment shown is as follows. The substation remote operation and maintenance system includes a substation remote operation and maintenance terminal 101 located at the substation side and a master station remote operation and maintenance server 102 located at the master station side, as well as an operation and maintenance management server 103. The substation remote operation and maintenance terminal 101 is directly connected to the secondary equipment (i.e., the objects under maintenance) within the substation. The operation and maintenance management server 103 and the master station remote operation and maintenance server 102 on the master station side establish operation and maintenance management channels and remote operation and maintenance channels respectively with the substation remote operation and maintenance terminal 101. These two channels work together to achieve remote operation and maintenance for the objects under maintenance within the substation. The operation and maintenance management channel is responsible for the start and stop management of the remote operation and maintenance channel, while the remote operation and maintenance channel is responsible for proxy forwarding specific remote operation and maintenance coordination. There is no direct network routing between the operation and maintenance master station and the substation objects under maintenance. All traffic must pass through the proxy programs at both ends of the master station (master station remote operation and maintenance server and substation remote operation and maintenance terminal) and be encrypted and decrypted by the TLCP tunnel, forming a strong logical isolation. This is similar to deep security isolation at the master station. The operation and maintenance management channel uses a long-lived Transmission Control Protocol (TCP) connection, and secure data transmission is achieved through whitelisting, two-way security authentication, and data encryption. The remote operation and maintenance channel is a normally closed connection; the operation and maintenance agent service on the operation and maintenance terminal only starts and allows connection establishment after the operation and maintenance management channel is activated. At the transport layer, the connection is encrypted using Transport Layer Cryptography Protocol (TLCP) to build a dedicated encrypted tunnel. Within the tunnel, the remote operation and maintenance protocol is forwarded, enabling secure and efficient remote operation and maintenance of automation equipment within the substation. Secondary equipment within the substation includes, but is not limited to, monitoring backends, gateways, switches, measurement and control devices, and clocks.

[0056] In one exemplary embodiment, such as Figure 2 As shown, a remote operation and maintenance method for substations is provided, which is applied to... Figure 1 The substation remote operation and maintenance terminal 101 includes the following steps 201 to 203. Wherein:

[0057] Step 201: Receive the negotiation message sent by the master station remote operation and maintenance server through the established encrypted tunnel; wherein, the negotiation message is used to represent the master station's remote connection instruction to the operation and maintenance object of the substation.

[0058] The encrypted tunnel is established based on a preset secure communication protocol, such as the TLCP protocol. The use of the national cryptographic TLCP protocol satisfies the mandatory requirements for data transmission security in power monitoring system security regulations and critical information infrastructure security protection.

[0059] For example, firstly, the substation remote maintenance terminal 101 establishes a remote maintenance channel between itself and the master station remote maintenance server 102, and then establishes an encrypted tunnel between them. Finally, after confirming that the encrypted tunnel between the substation remote maintenance terminal 101 and the master station remote maintenance server 102 has been established, the master station remote maintenance server 102 sends a negotiation message to the substation remote maintenance terminal 101 through the established encrypted tunnel, indicating the on-site maintenance objects that the terminal needs to remotely connect to.

[0060] The negotiation message includes a header and a negotiation application service data unit (ISP). The negotiation header, always located at the beginning, contains two bytes of synchronization characters (0xAF, 0xAF) for frame start positioning and synchronization, and a four-byte length identifier indicating the length of the ISP data unit following the header. The ISP data unit carries the specific negotiation parameters, including, in sequence, the network addresses (e.g., IP addresses) used to establish connections between the remote maintenance terminal and the maintenance master station and on-site maintenance objects, four bytes of source IP, four bytes of destination IP, and two bytes of destination port, followed by a one-byte transport layer protocol type (TCP or UDP), and finally a one-byte terminal password length and N bytes of terminal password content. The terminal password is used for secondary authentication in this proxy session, enhancing session-level security.

[0061] Step 202: Establish a transport layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object based on the negotiation message.

[0062] Among them, transport layer connection refers to the end-to-end logical communication link established by the two communicating parties at the transport layer.

[0063] For example, after receiving the negotiation message, the substation remote operation and maintenance terminal 101 parses and verifies the message. Upon successful verification, the substation remote operation and maintenance terminal 101, acting as a proxy, actively initiates a transport layer connection to the specified operation and maintenance object (such as a monitoring backend or gateway device) within the substation, based on the parsed content. This establishes a data path between the substation proxy and the operation and maintenance object, enabling the substation proxy to perform operation and maintenance operations on the object. This transport layer connection (which can be a TCP connection) is maintained during the operation and maintenance session and is used to carry the plaintext forwarding of operation and maintenance protocol messages such as VNC / SSH after decryption through the encrypted tunnel, ensuring the orderly and reliable transmission of business data on the substation's local area network side.

[0064] Step 203: Perform maintenance operations on the maintenance object based on the transport layer connection.

[0065] Operation and maintenance (O&M) refers to the remote management and maintenance actions performed by O&M personnel on O&M objects (such as secondary equipment) within the substation.

[0066] For example, the substation remote operation and maintenance terminal 101, under the instruction of the master station remote operation and maintenance server 102, performs operation and maintenance operations on the operation and maintenance object based on the transport layer connection, such as parameter configuration, log retrieval, fault query, and fault handling.

[0067] In the above-mentioned remote operation and maintenance method for substations, the remote operation and maintenance terminal of the substation receives a negotiation message sent by the master station's remote operation and maintenance server through an established encrypted tunnel; wherein, the negotiation message is used to represent the master station's remote connection instruction to the operation and maintenance object of the substation; a transport layer connection is established between the remote operation and maintenance terminal of the substation and the operation and maintenance object based on the negotiation message; and operation and maintenance operations are performed on the operation and maintenance object based on the transport layer connection. As can be seen, transmitting negotiation messages through an encrypted tunnel between the main station remote maintenance server and the substation remote maintenance terminal prevents eavesdropping or tampering, thus improving message transmission security. Establishing a transport layer connection between the substation remote maintenance terminal and the maintenance object based on the negotiation message opens a data path between the station agent and the maintenance object within the station. After the transport layer connection is established, the station agent is instructed to perform maintenance operations on the maintenance object through the transport layer connection. Therefore, maintenance personnel can perform maintenance operations remotely without being physically present at the substation, eliminating the time consumption and response delays caused by on-site maintenance. This improves maintenance efficiency and reduces manpower and time costs through remote maintenance. Moreover, the encrypted tunnel and transport layer connection work in a layered and collaborative manner; the former ensures secure communication at the remote end, while the latter carries data communication within the station. Their cooperation ensures both security and efficient data forwarding within the station. Therefore, this application can improve both maintenance efficiency and security.

[0068] In one exemplary embodiment, the negotiation message includes: the network address of the maintenance object, port information, transport layer protocol type, and terminal password steps. For example... Figure 3 As shown, step 202 includes steps 301 and 302. Wherein:

[0069] Step 301: Parse the negotiation message to obtain the network address, port information, transport layer protocol type, and terminal password.

[0070] For example, the master station remote operation and maintenance server 102 sends a negotiation message to the substation remote operation and maintenance terminal 101 through the established TLCP encrypted tunnel.

[0071] After receiving the negotiation message, the substation remote operation and maintenance terminal 101 first parses the negotiation message and extracts the network address (such as the target IP), port information, transport layer protocol type and terminal password of the operation and maintenance object.

[0072] Step 302: Perform consistency verification based on the terminal password, and after the consistency verification is successful, establish a transport layer connection according to the network address, port information and transport layer protocol type.

[0073] For example, the substation remote operation and maintenance terminal 101 compares the extracted terminal password with the locally stored base password. If the comparison matches, the consistency verification passes, and the terminal initiates a transport layer connection (such as a TCP three-way handshake) to the maintenance object within the station based on the parsed network address, port information, and transport layer protocol type. If the comparison does not match, the negotiation message is discarded, an error log is recorded, and an alarm message can be reported through the management channel, indicating that the transport layer connection has failed.

[0074] Optionally, to establish a transport layer connection, the substation remote operation and maintenance terminal 101 initiates a TCP three-way handshake with the maintenance object based on the IP address, port information, and transport layer protocol type in the negotiation message: First, it sends a Synchronize Sequence Numbers (SYN) message to request the connection. Upon receiving this, the maintenance object replies with a SYN-ACK message to indicate agreement. Then, the substation remote operation and maintenance terminal 101 sends an ACK (Acknowledgment) message to complete the confirmation. At this point, the transport layer connection between the two is established. A clean TCP connection without any application layer data exchange is established simply by completing the standard TCP three-way handshake. The key to this design is that the terminal agent never actively sends any application-layer handshakes or data packets belonging to Virtual Network Console (VNC), Remote Desktop Protocol (RDP), or Secure Shell (SSH) during this stage. This avoids triggering any response from internal devices without instructions from the master station, which conforms to the security principle of "least initiative": only establish a connection, do not send any application-layer data, and wait for instructions from the master station before forwarding data.

[0075] Therefore, in this embodiment, the terminal password serves as a secondary authentication credential, ensuring that only negotiation messages carrying the correct password can trigger the establishment of a transport layer connection, thus preventing the injection of illegal messages. Simultaneously, the target IP, port, and protocol type carried in the negotiation message enable the site-side agent to accurately locate the maintenance target. Furthermore, it supports any standard or proprietary maintenance protocol based on TCP / UDP (VNC, RDP, SSH, etc.) without requiring modification of existing device protocols, demonstrating strong versatility and wide protocol adaptability.

[0076] It should be noted that after the terminal responds to the negotiation message to establish a transport layer connection, the terminal needs to notify the master station of the establishment result.

[0077] In one exemplary embodiment, the method further includes: after establishing a transport layer connection, sending a negotiation response message to the master station remote operation and maintenance server through an encrypted tunnel; the negotiation response message is used to indicate the result of the establishment of the transport layer connection.

[0078] For example, the substation remote operation and maintenance terminal 101 encapsulates the establishment result of the transport layer connection into a negotiation response message and returns the negotiation response message through an encrypted tunnel. The master station remote operation and maintenance server 102 receives the negotiation response message through the encrypted tunnel, parses it, and extracts the establishment result. The establishment result includes establishment success, establishment failure, connection rejection, or timeout. If the establishment result is successful, it is determined that the transport layer connection at the station end has been established, and the remote operation and maintenance stage begins. That is, when the transport layer connection at the master station remote operation and maintenance server 102 has been established, it obtains all operation and maintenance protocol data messages sent by the operation and maintenance workstation on the master station side through the VNC / RDP / SSH client (e.g., VNC RFB protocol frames, RDP TPKT packets, SSH version exchange and key exchange messages, etc.) and sends remote operation and maintenance messages to the substation remote operation and maintenance terminal 101 according to them, so that the substation remote operation and maintenance terminal 101 acts as a station-end agent to perform operation and maintenance operations.

[0079] Therefore, in this embodiment, when the transport layer connection is successfully established, the master station is triggered to send a remote operation and maintenance message to realize remote operation and maintenance and ensure communication reliability.

[0080] In one exemplary embodiment, such as Figure 4 As shown, step 203 involves performing maintenance operations on the object based on the transport layer connection, including steps 401 and 402. Wherein:

[0081] Step 401: Receive remote maintenance messages sent by the master station's remote maintenance server through an encrypted tunnel.

[0082] Among them, the remote operation and maintenance message is used to characterize the operation and maintenance operation of the main station for the operation and maintenance object. The remote operation and maintenance message is sent by the remote operation and maintenance server of the main station after determining that the transport layer connection has been established.

[0083] Step 402: Perform maintenance operations on the maintenance object based on remote maintenance messages and transport layer connections.

[0084] In one example, step 401 includes: forwarding a remote operation and maintenance message to the operation and maintenance object via a transport layer connection so that the operation and maintenance object can perform operation and maintenance operations; receiving an execution response message returned by the operation and maintenance object via a transport layer connection, and forwarding the execution response message to the main station remote operation and maintenance server via an encrypted tunnel.

[0085] For example, after the encrypted tunnel and transport layer connection are established, all operation and maintenance protocol messages between the master station and the substation are no longer sent in plaintext. Once the master station remote operation and maintenance server 102 confirms that the transport layer connection has been established, it directly uses the original operation and maintenance protocol messages sent by the operation and maintenance workstation as the application layer payload. After the TLCP protocol layer performs security processing such as encryption and integrity protection, the remote operation and maintenance message is sent to the substation remote operation and maintenance terminal 101 through the encrypted tunnel of the dispatch data network.

[0086] The substation remote maintenance terminal 101 receives remote maintenance messages through a TLCP encrypted tunnel, decrypts and verifies their integrity, and extracts the verified original maintenance protocol message from the TLCP payload. The substation remote maintenance terminal 101 then transparently and byte-by-byte sends the original maintenance protocol message to the maintenance target through an established transport layer connection (such as a TCP connection). Upon receiving the original maintenance protocol message, the maintenance target executes the corresponding maintenance operations according to the maintenance instructions. After completion, it returns an execution response message through the transport layer connection. Upon receiving the execution response message, the substation remote maintenance terminal 101 sends it to the master station remote maintenance server 102 through the TLCP encrypted tunnel to notify the maintenance personnel at the maintenance workstation that the remote maintenance has been completed.

[0087] Therefore, in this embodiment, the substation remote operation and maintenance terminal acts as a terminal agent, performing operation and maintenance operations on objects within the substation based on encrypted tunnels, transport layer connections, and remote operation and maintenance messages, thus realizing remote operation and maintenance. The substation remote operation and maintenance terminal only opens one TLCP service port and only responds to authenticated sources. The internal equipment of the substation does not expose any service ports to the dispatch data network, greatly reducing and minimizing the network attack surface.

[0088] It should be noted that this application completes remote operation and maintenance after both the encrypted tunnel and the transport layer connection have been established. However, before establishing the encrypted tunnel, it is necessary to open the remote operation and maintenance channel between the master station and the substation, that is, to enable the remote operation and maintenance service in the substation's remote operation and maintenance terminal.

[0089] In one possible implementation, a remote maintenance channel is established through interaction between the main station's maintenance management server 103 and the substation's remote maintenance terminal 101. Specifically, as follows... Figure 5 As shown, follow these steps to enable the remote maintenance channel:

[0090] Step 501: The channel administrator prepares to start the remote operation and maintenance channel through the operation and maintenance management server;

[0091] Step 502: The operation and maintenance management server determines whether the current time is within the time allowed by the approved work order of the substation; otherwise, the remote operation and maintenance channel is not allowed to be started.

[0092] Step 503: The operation and maintenance management server associates with the corresponding remote operation and maintenance terminal in the remote operation and maintenance channel and verifies whether the IP address of the remote operation and maintenance terminal matches the whitelist address. If yes, proceed to step 504; otherwise, return to step 501.

[0093] Step 504: The operation and maintenance management server initiates a dedicated TCP connection to the substation remote operation and maintenance terminal;

[0094] Step 505: The remote operation and maintenance terminal verifies the IP of the operation and maintenance management server. If it is not in the whitelist, the connection is disconnected. If it is in the whitelist, proceed to step 506.

[0095] Step 506: The operation and maintenance management server initiates a security authentication request: generates a random factor r1, and uses its own private key and sm2 (elliptic curve public key cryptography algorithm, which belongs to asymmetric encryption algorithm) to generate an sm2 signature for the request message and the random factor r1;

[0096] Step 507: The remote operation and maintenance terminal receives the security authentication request message, uses the operation and maintenance management server public key and sm2 to verify whether the signature of the request message is valid. If it is valid, it replies with a security authentication response message: it takes r1 from the security authentication request message, generates a random factor r2, and uses its own private key and sm2 to generate an sm2 signature for the authentication response message and r1 and r2.

[0097] Step 508: The operation and maintenance management server receives the security authentication response message and uses the public key of the remote operation and maintenance terminal and sm2 to verify whether the signature of the security authentication response message is valid. If it is valid, it replies with a security authentication confirmation message: extract r2 from the security authentication response message and use its own private key and sm2 to generate an sm2 signature for the security authentication response message and r2.

[0098] Step 509: The remote operation and maintenance terminal receives the security authentication confirmation message and uses the public key of the operation and maintenance management server and sm2 to verify whether the signature of the security authentication confirmation message is valid. If it is valid, the security authentication process is successful.

[0099] Step 510: The remote operation and maintenance terminal generates a random factor r3 as a random factor for negotiating the symmetric encryption key with the operation and maintenance management server. The remote operation and maintenance terminal uses the public key of the operation and maintenance management server and sm2 to encrypt r3 and send it to the operation and maintenance management server.

[0100] Step 511: The operation and maintenance management server uses its own private key and sm2 to decrypt r3;

[0101] Step 512: Both the remote operation and maintenance terminal and the operation and maintenance management server have three random factors, r1, r2 and r3. Both use these three random factors to generate a symmetric key sm4 (block cipher algorithm, which belongs to symmetric encryption algorithm) encryption key.

[0102] Step 513: The remote operation and maintenance management server uses sm4 to encrypt and send the channel control verification password, timestamp, and channel start command entered by the channel administrator to the remote operation and maintenance terminal.

[0103] Step 514: The remote operation and maintenance terminal uses sm4 to decrypt the channel control verification password, timestamp, and channel start command, and verifies the channel control verification password and timestamp.

[0104] Step 515: After successful verification, execute the remote operation and maintenance channel startup logic to open the remote operation and maintenance channel.

[0105] In step 502, it is necessary to determine whether there are any approved maintenance work orders associated with this site. Remote maintenance is constrained by the work order; it is only permitted to perform remote maintenance on substation secondary equipment after initiating the remote maintenance channel through the maintenance management channel within the working hours specified in the work order. Work orders are securely transferred between the operator, administrator, and supervisor, and the roles and permissions of these three individuals meet security protection principles.

[0106] Work order management process as follows Figure 6 As shown, the roles of the three parties involved in the work order binding are defined as follows:

[0107] Team members (operators): Responsible for creating work tasks and submitting work orders for approval; modifying and resubmitting work orders that have been rejected for approval; performing remote maintenance on time for work orders that have been approved and are pending execution; voluntarily abandoning the remote maintenance for work orders that have been approved and are pending execution, and closing the work order; requesting an extension for work orders that are in progress and submitting it to the work administrator for approval.

[0108] Reviewer (Work Administrator): Review the content of the work order and approve whether the work order is approved; for work orders that are not approved, they can be returned to the creator or the work order can be closed directly; approve work orders that are in the process of requesting an extension.

[0109] Supervisor (Guardian): Monitors the operator's operation and maintenance process and verifies whether the operation and maintenance content is consistent with the work order plan; when the operator performs remote operation and maintenance, the supervisor needs to verify and log in to the system at the same time to carry out the operation and maintenance work.

[0110] The work order content is defined as follows:

[0111] The work order includes the following fields: work order number, work order name, substation name, work plan start and end time, list of remote login hosts, list of maintenance objects, operator, work supervisor, approver, co-participants, work content, risk items and safety measures, etc.

[0112] The status definitions for each node of a work order are as follows:

[0113] Pending Approval: The operator has submitted a new work order, which is pending administrator approval.

[0114] Approval rejection: If the administrator does not approve the work order, the operator is given permission to modify the work order and resubmit it for approval.

[0115] Pending execution: The administrator has approved the work order, and it is awaiting execution by the operator.

[0116] During execution: The operator begins execution, which requires monitoring and verification of system login, and the opening of the channel to start maintenance; during execution, the operator is allowed to apply for a work order extension. The extension application is submitted to the administrator for approval. If the approval is granted, the termination time is postponed; if the approval is denied, the termination time remains unchanged.

[0117] Execution Pause: During operation, remote maintenance can be paused. The remote maintenance channel will be closed during the pause, but the work order termination time remains unchanged. Operators can continue to execute work orders that have been paused but have not expired.

[0118] Request for extension: If an operator needs to extend the execution time, they should submit an extension request to the administrator for approval. If the approval is granted, the termination time will be postponed; if the approval is denied, the termination time will remain unchanged.

[0119] Work interruption: The work order needs to be routed to the administrator to inform him, and the operator needs the administrator's approval to restart the execution.

[0120] Request to continue execution: If you need to continue working across days after an interruption, you need to "request to continue execution". If the approval is granted, you can continue working. If the approval is not granted, you will be in a work interruption state.

[0121] End: Completed (the end point of the process after the normal completion of the operation and maintenance process); Completed but not completed (the end point of the process where there is no operation and maintenance process or the process has an anomaly).

[0122] This completes the control over the opening of the remote operation and maintenance channel from the operation and maintenance management channel. Subsequently, a secure, efficient, and dedicated encrypted tunnel is established to carry specific remote operation and maintenance protocol data. The establishment of the encrypted tunnel and data transmission strictly adhere to national cryptographic standards, ensuring the construction of a trusted end-to-end encrypted tunnel on the scheduling data network.

[0123] In one exemplary embodiment, such as Figure 7As shown, the method for establishing an encrypted tunnel includes steps 701 to 703. Wherein:

[0124] Step 701: If the remote operation and maintenance channel between the master station remote operation and maintenance server and the substation remote operation and maintenance terminal has been opened, receive the encrypted tunnel establishment request sent by the master station remote operation and maintenance server.

[0125] Step 702: In response to the encrypted tunnel establishment request, an encrypted tunnel is established between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server based on a preset secure communication protocol.

[0126] The default secure communication protocol can be the TLCP protocol.

[0127] Step 703: After the encrypted tunnel is established, send a confirmation message to the main station remote operation and maintenance server. The confirmation message is used to indicate that the encrypted tunnel has been established.

[0128] For example, after the remote operation and maintenance channel has been opened, the master station remote operation and maintenance server 102 sends an encrypted tunnel establishment request (i.e., a TLCP ClientHello handshake request) to the substation remote operation and maintenance terminal 101.

[0129] In response to the handshake request, the substation remote operation and maintenance terminal 101 performs a handshake process with the master station remote operation and maintenance server 102 based on the TLCP protocol. Specifically, the terminal replies with a ServerHello message and sends its own digital certificate (containing the SM2 public key) to the master station remote operation and maintenance server. Simultaneously, it receives and verifies the master station remote operation and maintenance server's digital certificate, achieving two-way authentication based on digital certificates to ensure the legitimacy of both parties' identities and prevent unauthorized access. After successful two-way authentication, both parties complete session key negotiation based on the SM2 algorithm, using the exchanged random numbers to generate a unique SM4 symmetric encryption key for this session.

[0130] After the handshake process is completed, the terminal sends a handshake confirmation message (Finished message) to the main station's remote operation and maintenance server to confirm that the encrypted tunnel has been successfully established. Thereafter, all operation and maintenance protocol messages are encrypted and transmitted within this TLCP encrypted tunnel using the sm4 algorithm, and integrity verification information is attached to ensure the confidentiality, integrity, and authenticity of the data.

[0131] Therefore, the Transport Layer Security Protocol (TLCP) (GB / T 38636-2020 Information Security Technology) is adopted to construct a dedicated encrypted security tunnel between the operation and maintenance master station and the operation and maintenance terminal. Based on this dedicated encrypted security tunnel built between the operation and maintenance master station and the remote operation and maintenance terminal, all subsequent remote operation and maintenance protocol messages are transmitted within this tunnel, achieving secure "pipeline-like" transmission. National cryptographic algorithms (such as SM2 / SM4) are used to encrypt all application layer data transmitted within the channel, ensuring the confidentiality of operation and maintenance protocol messages (such as sensitive information like VNC, RDP, and SSH) and preventing eavesdropping during transmission. Digest information is generated for the transmitted data to ensure that the data has not been tampered with during transmission, guaranteeing the accuracy of operation and maintenance instructions.

[0132] The following detailed embodiment describes the substation remote operation and maintenance method of this application, including the following steps:

[0133] S1, with the remote operation and maintenance channel between the master station remote operation and maintenance server and the substation remote operation and maintenance terminal already opened, the master station remote operation and maintenance server sends an encrypted tunnel establishment request to the substation remote operation and maintenance terminal.

[0134] S2, the substation remote operation and maintenance terminal receives the encrypted tunnel establishment request and responds to the encrypted tunnel establishment request by interacting with the master station remote operation and maintenance server based on the TLCP protocol to establish an encrypted tunnel;

[0135] S3. After the encrypted tunnel is established, the substation remote operation and maintenance terminal sends a confirmation message to the master station remote operation and maintenance server. The confirmation message is used to indicate that the encrypted tunnel has been established.

[0136] S4. Once it is confirmed that the encrypted tunnel has been established, the master station remote operation and maintenance server sends a negotiation message to the substation remote operation and maintenance terminal through the encrypted tunnel; the negotiation message is used to represent the master station's remote connection command to the substation's operation and maintenance object.

[0137] S5, the substation remote operation and maintenance terminal receives negotiation messages sent by the master station remote operation and maintenance server through an encrypted tunnel;

[0138] S6, the substation remote operation and maintenance terminal parses the negotiation message to obtain the network address, port information, transport layer protocol type and terminal password;

[0139] S7, the substation remote operation and maintenance terminal performs consistency verification based on the terminal password, and after the consistency verification is successful, establishes a transport layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object according to the network address, port information and transport layer protocol type;

[0140] S8. After establishing the transport layer connection, the substation remote operation and maintenance terminal sends a negotiation response message to the master station remote operation and maintenance server through an encrypted tunnel; the negotiation response message is used to indicate the result of the establishment of the transport layer connection.

[0141] S9, the master station remote operation and maintenance server receives the negotiation response message sent by the substation remote operation and maintenance terminal through the encrypted tunnel;

[0142] S10, if the master station remote operation and maintenance server determines that the transport layer connection has been established successfully, the transport layer connection will be confirmed as established.

[0143] S11, after determining that the transmission layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object has been established, the master station remote operation and maintenance server sends a remote operation and maintenance message to the substation remote operation and maintenance terminal through an encrypted tunnel; wherein, the remote operation and maintenance message is used to characterize the operation and maintenance operation of the master station for the operation and maintenance object.

[0144] S12, the substation remote operation and maintenance terminal receives remote operation and maintenance messages sent by the master station remote operation and maintenance server through an encrypted tunnel;

[0145] S13, the substation remote operation and maintenance terminal forwards remote operation and maintenance messages to the operation and maintenance object through the transport layer connection, so that the operation and maintenance object can perform operation and maintenance operations;

[0146] S14, the substation remote operation and maintenance terminal receives the execution response message returned by the operation and maintenance object through the transport layer connection, and forwards the execution response message to the main station remote operation and maintenance server through the encrypted tunnel;

[0147] S15, return to S11, until the remote operation and maintenance session ends.

[0148] The complete timeline of the remote operation and maintenance protocol proxy forwarding in this embodiment is as follows: Figure 8 As shown, through the above steps, remote operation and maintenance of substations based on the collaboration of management and operation and maintenance channels has been realized.

[0149] To achieve traceability and auditability of the remote operation and maintenance process of substations, this application further proposes a closed-loop audit mechanism for the entire operation and maintenance process. Through a dual-modal recording mechanism, a complete audit evidence chain covering operation instructions and operation screens is constructed. On one hand, all application control messages (including start / stop instructions for the remote operation and maintenance channel, proxy negotiation messages, and session control information) are intercepted and parsed in the operation and maintenance management server and the remote operation and maintenance server, and converted into a structured log sequence, recording key elements such as operation time, operator, target equipment, and control actions. On the other hand, at the operation and maintenance workstation, the operation screen of the remote login session is synchronously recorded, and an immutable digital watermark is superimposed on the recording. The watermark information includes at least the operation and maintenance work time, operator identity, supervisor identity, operation and maintenance object identifier, and session identifier.

[0150] Structured control logs and visual screen recordings are linked and synchronized using unified timestamps and session identifiers. These two elements corroborate each other, forming a dual closed-loop evidence of "operation instructions - actual visuals." This method combines traditional discrete operation logs with continuous visual recording, effectively resolving potential issues of instruction ambiguity or missing visuals when using single auditing methods to trace complex operational operations. It provides complete and reliable technical support for accurate post-event retrospective analysis, accountability, and compliance assessment.

[0151] In summary, the substation remote operation and maintenance method of this application has achieved significant results in actual deployment and application, and has the following effects:

[0152] This fundamentally changes the operation and maintenance model, significantly improving operational efficiency: maintenance personnel can initiate safe remote operations on secondary equipment in any substation through the maintenance master station without having to travel to the site. The response time for maintenance tasks is reduced from hours to minutes, with significant efficiency improvements, especially when handling urgent defects or conducting routine inspections, greatly reducing labor and time costs.

[0153] A fully traceable operations and maintenance (O&M) security system was built to strengthen internal control and compliance: the O&M management channel, based on whitelists and two-way authentication, achieved strict control over the access end; the remote O&M channel adopted the national cryptographic TLCP protocol to build an end-to-end encrypted tunnel, ensuring the confidentiality and integrity of O&M data during transmission. Dual-channel collaboration achieved separation of authorization and operation, eliminating unauthorized access at the source. A dual-modal closed-loop audit, combining control flow logs and visual flow screen recording, fully recorded "who, when, through what command, on which device, and what effect." This audit mechanism provides a chain of evidence for every O&M operation, greatly enhancing internal control and post-event traceability capabilities.

[0154] A comprehensive and intensive operation and maintenance platform has been built to improve the efficiency of operation and maintenance management: the standardized channel interface and proxy forwarding mechanism have good protocol compatibility and can be smoothly expanded to support new intelligent devices and operation and maintenance protocols in the future, ensuring the long-term vitality of the platform.

[0155] In one exemplary embodiment, such as Figure 9 As shown, a remote operation and maintenance method for substations is provided, which is applied to... Figure 1 The main station remote operation and maintenance server 102 includes the following steps 901 and 902. Wherein:

[0156] Step 901: After confirming that an encrypted tunnel has been established between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server, a negotiation message is sent to the substation remote operation and maintenance terminal through the encrypted tunnel.

[0157] Among them, the negotiation message is used to represent the remote connection command of the master station to the operation and maintenance object of the substation.

[0158] For example, after the master station remote operation and maintenance server 102 determines that the encrypted tunnel has been established, it sends a negotiation message to the substation remote operation and maintenance terminal through the encrypted tunnel, indicating the on-site operation and maintenance object that the terminal needs to remotely connect to. After receiving the negotiation message, the substation remote operation and maintenance terminal 101 parses and verifies the negotiation message. After successful verification, the substation remote operation and maintenance terminal 101 acts as a proxy and actively initiates a transport layer connection to the specified on-site operation and maintenance object (such as the monitoring backend, gateway device, etc.) corresponding to the parsed content, establishing a data path between the station-end proxy and the on-site operation and maintenance object, enabling the station-end proxy to perform operation and maintenance operations on the object. This transport layer connection (which can be a TCP connection) is maintained during the operation and maintenance session and is used to carry the plaintext forwarding of operation and maintenance protocol messages such as VNC / SSH after being decrypted through the encrypted tunnel, ensuring the orderly and reliable transmission of business data on the on-site local area network side.

[0159] After establishing the transport layer connection, the terminal encapsulates the connection establishment result into a negotiation response message and sends it to the master remote operation and maintenance server 102. The master remote operation and maintenance server 102 determines whether the transport layer connection is successful based on the negotiation response message; if so, it proceeds to step 902.

[0160] Step 902: After confirming that the transmission layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object has been established, send a remote operation and maintenance message to the substation remote operation and maintenance terminal through an encrypted tunnel.

[0161] Among them, remote operation and maintenance messages are used to characterize the operation and maintenance operations performed by the main station on the operation and maintenance object.

[0162] For example, after the master station remote operation and maintenance server 102 determines that the transport layer connection has been successfully established, it sends a remote operation and maintenance message to the substation remote operation and maintenance terminal 101 through an encrypted tunnel, so that the substation remote operation and maintenance terminal can perform operation and maintenance operations on the operation and maintenance object based on the transport layer connection. That is, the substation remote operation and maintenance terminal 101 performs operation and maintenance operations on the operation and maintenance object according to the remote operation and maintenance message and the transport layer connection.

[0163] In the aforementioned remote operation and maintenance method for substations, after determining that an encrypted tunnel has been established between the remote operation and maintenance terminal of the substation and the remote operation and maintenance server, the master station remote operation and maintenance server sends a negotiation message to the remote operation and maintenance terminal of the substation through the encrypted tunnel. The negotiation message represents the master station's remote connection command to the object being maintained at the substation. After determining that a transport layer connection has been established between the remote operation and maintenance terminal of the substation and the object being maintained, a remote operation and maintenance message is sent to the remote operation and maintenance terminal of the substation through the encrypted tunnel. This remote operation and maintenance message represents the master station's operation and maintenance operation on the object being maintained. As can be seen, this application achieves the transmission of negotiation messages and remote maintenance messages through an encrypted tunnel between the main station remote maintenance server and the substation remote maintenance terminal, preventing message transmission from being eavesdropped on or tampered with, thus improving message transmission security. After the transport layer connection is established, the station-end agent is instructed to perform maintenance operations on the maintenance object through the transport layer connection. Therefore, it ensures that maintenance personnel can perform maintenance operations remotely without being physically present at the substation, eliminating the time consumption and response delays caused by the on-site maintenance mode. Consequently, remote maintenance can improve maintenance efficiency and reduce manpower and time costs. Therefore, this application can both improve maintenance efficiency and ensure maintenance security.

[0164] In an exemplary embodiment, the method further includes: receiving a negotiation response message sent by a remote operation and maintenance terminal of a substation through an encrypted tunnel; the negotiation response message is used to indicate the establishment result of the transport layer connection; if the establishment result of the transport layer connection is determined to be successful, the transport layer connection is determined to be established.

[0165] For example, the master station remote operation and maintenance server 102 receives the negotiation response message through the encrypted tunnel, parses it, and extracts the establishment result. The establishment result includes establishment success, establishment failure, connection rejection, or timeout. If the establishment result is successful, it is determined that the transport layer connection of the station has been established, and the remote operation and maintenance stage is entered. That is, when the transport layer connection of the master station remote operation and maintenance server 102 has been established, it obtains all operation and maintenance protocol data messages sent by the operation and maintenance workstation on the master station side through the VNC / RDP / SSH client (e.g., VNC RFB protocol frames, RDP TPKT packets, SSH version exchange and key exchange messages, etc.), and sends remote operation and maintenance messages to the substation remote operation and maintenance terminal 101 according to them, so that the substation remote operation and maintenance terminal 101 acts as a station agent to perform operation and maintenance operations.

[0166] This ensures that the master station can enter the remote operation and maintenance phase after the transport layer connection is successfully established.

[0167] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.

[0168] Based on the same inventive concept, this application also provides a substation remote operation and maintenance device for implementing the aforementioned substation remote operation and maintenance method. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more embodiments of the substation remote operation and maintenance device provided below can be found in the limitations of the substation remote operation and maintenance method described above, and will not be repeated here.

[0169] In one exemplary embodiment, such as Figure 10 As shown, a remote operation and maintenance device for substations is provided, applied to a remote operation and maintenance terminal for substations. The device includes: a first receiving module 1001, a first establishing module 1002, and an operation and maintenance module 1003, wherein:

[0170] The first receiving module 1001 is used to receive negotiation messages sent by the master station remote operation and maintenance server through an established encrypted tunnel; wherein, the negotiation message is used to represent the master station's remote connection instruction to the operation and maintenance object of the substation.

[0171] The first establishment module 1002 is used to establish a transport layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object based on the negotiation message;

[0172] The operation and maintenance module 1003 is used to perform operation and maintenance operations on the operation and maintenance object based on the transport layer connection.

[0173] In one embodiment, the negotiation message includes: the network address, port information, transport layer protocol type, and terminal password of the operation and maintenance object; the first establishment module 1002 is specifically used to: parse the negotiation message to obtain the network address, the port information, the transport layer protocol type, and the terminal password; perform consistency verification based on the terminal password, and establish the transport layer connection according to the network address, the port information, and the transport layer protocol type after the consistency verification is passed.

[0174] In one embodiment, the operation and maintenance module 1003 is specifically used to: receive a remote operation and maintenance message sent by the master station remote operation and maintenance server through the encrypted tunnel; perform operation and maintenance operations on the operation and maintenance object based on the remote operation and maintenance message and the transport layer connection; wherein, the remote operation and maintenance message is used to characterize the operation and maintenance operation of the master station on the operation and maintenance object, and the remote operation and maintenance message is sent by the master station remote operation and maintenance server after determining that the transport layer connection has been established.

[0175] In one embodiment, the operation and maintenance module 1003 is specifically used to: forward the remote operation and maintenance message to the operation and maintenance object through the transport layer connection, so that the operation and maintenance object can perform the operation and maintenance operation; receive the execution response message returned by the operation and maintenance object through the transport layer connection, and forward the execution response message to the master station remote operation and maintenance server through the encrypted tunnel.

[0176] In one embodiment, the apparatus further includes: a second receiving module, configured to receive an encrypted tunnel establishment request sent by the master station remote maintenance server when the remote maintenance channel between the master station remote maintenance server and the substation remote maintenance terminal is already open; a second establishing module, configured to establish the encrypted tunnel between the substation remote maintenance terminal and the master station remote maintenance server based on a preset secure communication protocol in response to the encrypted tunnel establishment request; and a first sending module, configured to send confirmation information to the master station remote maintenance server after the encrypted tunnel is established, the confirmation information indicating that the encrypted tunnel has been established.

[0177] In one embodiment, the apparatus further includes: a second sending module, configured to send a negotiation response message to the master station remote operation and maintenance server through the encrypted tunnel after the transport layer connection is established; the negotiation response message is used to indicate the establishment result of the transport layer connection.

[0178] In one exemplary embodiment, such as Figure 11 As shown, a substation remote operation and maintenance device is provided, applied to a master station remote operation and maintenance server. The device includes: a third transmitting module 1101 and a fourth transmitting module 1102, wherein:

[0179] The third sending module 1101 is used to send a negotiation message to the substation remote operation and maintenance terminal through the encrypted tunnel when it is determined that an encrypted tunnel has been established between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server; wherein, the negotiation message is used to represent the master station's remote connection instruction to the substation operation and maintenance object.

[0180] The fourth sending module 1102 is used to send a remote maintenance message to the substation remote maintenance terminal through the encrypted tunnel when it is determined that a transport layer connection has been established between the substation remote maintenance terminal and the maintenance object; wherein the remote maintenance message is used to characterize the maintenance operation performed by the master station on the maintenance object.

[0181] In one embodiment, the apparatus further includes: a third receiving module, configured to receive a negotiation response message sent by the substation remote operation and maintenance terminal through the encrypted tunnel; the negotiation response message is used to indicate the establishment result of the transport layer connection; and a determining module, configured to determine that the transport layer connection has been established if the establishment result of the transport layer connection is determined to be successful.

[0182] Each module in the aforementioned remote operation and maintenance device for substations can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of a computer device in software form, so that the processor can call and execute the corresponding operations of each module.

[0183] In one exemplary embodiment, a remote operation and maintenance system for substations is provided, referring to... Figure 1 The system includes a master station remote operation and maintenance server 102 and a substation remote operation and maintenance terminal 101. Among them:

[0184] The master station remote operation and maintenance server 102 is used to execute the substation remote operation and maintenance method applied to the master station remote operation and maintenance server; the substation remote operation and maintenance terminal 101 is used to execute the substation remote operation and maintenance method applied to the substation remote operation and maintenance terminal.

[0185] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement a method for remote operation and maintenance of a substation.

[0186] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements a method for remote operation and maintenance of a substation.

[0187] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements a method for remote operation and maintenance of a substation.

[0188] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processors, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0189] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0190] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A substation remote operation and maintenance method, characterized by, The method is applied to a substation remote operation and maintenance terminal, and the method comprises the following steps: Receiving a negotiation message sent by a master station remote operation and maintenance server through an established encrypted tunnel; wherein the negotiation message is used to represent a remote connection instruction of the master station to an operation and maintenance object of the substation; Establishing a transport layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object based on the negotiation message; Performing an operation and maintenance operation on the operation and maintenance object based on the transport layer connection.

2. The method of claim 1, wherein, The negotiation message comprises a network address, port information, a transport layer protocol type and a terminal password of the operation and maintenance object; The step of establishing the transport layer connection between the substation remote operation and maintenance terminal and the operation and maintenance object based on the negotiation message comprises the following steps: Analyzing the negotiation message to obtain the network address, the port information, the transport layer protocol type and the terminal password; Performing consistency verification based on the terminal password, and establishing the transport layer connection according to the network address, the port information and the transport layer protocol type after the consistency verification is passed.

3. The method of claim 1, wherein, The step of performing the operation and maintenance operation on the operation and maintenance object based on the transport layer connection comprises the following steps: Receiving a remote operation and maintenance message sent by the master station remote operation and maintenance server through the encrypted tunnel; Performing an operation and maintenance operation on the operation and maintenance object based on the remote operation and maintenance message and the transport layer connection; The remote operation and maintenance message is used to represent an operation and maintenance operation of the master station to the operation and maintenance object, and the remote operation and maintenance message is sent by the master station remote operation and maintenance server under the condition that the transport layer connection has been established.

4. The method of claim 3, wherein, The step of performing the operation and maintenance operation on the operation and maintenance object based on the remote operation and maintenance message and the transport layer connection comprises the following steps: Forwarding the remote operation and maintenance message to the operation and maintenance object through the transport layer connection, so that the operation and maintenance object performs the operation and maintenance operation; Receiving an execution response message returned by the operation and maintenance object through the transport layer connection, and forwarding the execution response message to the master station remote operation and maintenance server through the encrypted tunnel.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises the following steps: Receiving an encrypted tunnel establishment request sent by the master station remote operation and maintenance server under the condition that a remote operation and maintenance channel between the master station remote operation and maintenance server and the substation remote operation and maintenance terminal has been opened; Establishing the encrypted tunnel between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server based on a preset secure communication protocol in response to the encrypted tunnel establishment request; After the establishment of the encrypted tunnel is completed, sending confirmation information to the master station remote operation and maintenance server, wherein the confirmation information is used to indicate that the encrypted tunnel has been established.

6. The method according to any one of claims 1 to 4, characterized in that, The method further comprises the following steps: After the transport layer connection is established, sending a negotiation response message to the master station remote operation and maintenance server through the encrypted tunnel; the negotiation response message is used to indicate an establishment result of the transport layer connection.

7. A substation remote operation and maintenance method, characterized by, The method is applied to a master station remote operation and maintenance server, and the method comprises the following steps: Once it is determined that an encrypted tunnel has been established between the substation remote operation and maintenance terminal and the master station remote operation and maintenance server, a negotiation message is sent to the substation remote operation and maintenance terminal through the encrypted tunnel; wherein, the negotiation message is used to represent the master station's remote connection instruction to the substation's operation and maintenance object; Once it is determined that a transport layer connection has been established between the substation remote operation and maintenance terminal and the operation and maintenance object, a remote operation and maintenance message is sent to the substation remote operation and maintenance terminal through the encrypted tunnel; wherein, the remote operation and maintenance message is used to characterize the operation and maintenance operation of the master station for the operation and maintenance object.

8. The method of claim 7, wherein, The method further includes: The encrypted tunnel receives a negotiation response message sent by the substation remote operation and maintenance terminal; the negotiation response message is used to indicate the establishment result of the transport layer connection. If the establishment of the transport layer connection is determined to be successful, then the transport layer connection is determined to be established.

9. A substation remote operation and maintenance system, characterized by, include: The main station remote operation and maintenance server is used to execute the substation remote operation and maintenance method as described in claim 7 or 8; A substation remote operation and maintenance terminal is used to execute the substation remote operation and maintenance method as described in any one of claims 1 to 6. 10.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-9. When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 8.